21790
Updated**Remediation action**
Daily.Entra.NewsTwo announced retirements are the period’s main admin actions: the Conditional Access “Require approved client app” control is scheduled to retire in June 2026, and custom greetings in voice-call authentication retire on 28 February 2026. Beyond those notices, the week is mostly documentation maintenance rather than a feature-release cycle; many remaining Entra entries are numbered troubleshooting pages whose supplied summary is only “Remediation action.” The substantive exceptions clarify Connect Sync deployment constraints, Conditional Access Optimization Agent identity behavior, External ID MAU billing scope, and security risks around workload identities, guests, session controls, and provisioning scope. The lone new entry is an EcoOnline Info Exchange SSO configuration guide—not evidence of a new Entra capability, preview, or GA release. The three removed Purview workload-content pages have no retirement rationale in the supplied record.
The Microsoft 365 Message Center reminder says this control retires in June 2026 and will no longer be enforceable afterward. Organizations are directed to update policies to use “Require application protection policy,” described as providing equivalent and enhanced protection. This is a planned policy transition, not a preview or GA announcement.
Custom greetings retire on 28 February 2026. Afterward, voice calls for multifactor authentication will use Microsoft’s default recordings. The notice specifically calls for preparing users and reviewing relevant MFA configurations.
The Connect Sync troubleshooting update says cloning a server with Entra Connect installed into another production server is unsupported because the clone shares the machine identifier and conflicts with the application registration identity. It also explains that the wizard normally uses unique accounts per server and the server name—not the connector service account—to identify the application registration. Separately, the Optimization Agent guidance says agents enabled after 17 November 2025 no longer use the20
Updated material warns that privileged roles on service principals or managed identities can create significant risk if compromised, including reconnaissance, privilege escalation, lateral movement, persistence, and data manipulation or exfiltration. Other updates identify open application assignment without provisioning scoping, compromised or dormant guest accounts, and inadequate session controls as exposure paths. Identity Governance documentation also describes using business groups to determine which guests;
The updated External Identities Pricing page says MAU billing applies to every user in an external tenant, including consumers, business guests without directory roles, and administrators with directory roles, regardless of UserType. This clarifies billing scope; no rate or effective date is supplied.
Inventory Conditional Access policies that use “Require approved client app” and move them to “Require application protection policy” ahead of the June 2026 retirement; the old control will no longer be enforceable afterward. For voice MFA, prepare users for Microsoft’s default recordings and review relevant MFA configurations before 28 February. If a Connect Sync deployment plan relies on cloning a production server, revisit it because the updated guidance calls that method unsupported. If an Optimization Agent enabled before Microsoft Ignite 2025 is failing, check whether the activating account depended on PIM role activation and lacked the required permissions when the agent ran. Include all users in external tenants in MAU billing assumptions regardless of UserType. The security edits
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
author: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
If this check passes, your tenant has a TRv2 policy configured but more steps are required to validate the scenario end-to-end.
Without proper session controls, threat actors can achieve lateral movement across the organization's infrastructure, accessing critical data and systems that extend far beyond the original guest account's intended scope of access.
A Microsoft Entra documentation page was updated: Purview Workload Content Administrator.
A Microsoft Entra documentation page was updated: Purview Workload Content Reader.
A Microsoft Entra documentation page was updated: Purview Workload Content Writer.
Learn how to configure single sign-on between Microsoft Entra ID and EcoOnline Info Exchange.
In this article, you configure and test Microsoft Entra single sign-on in a test environment.
These Microsoft-managed policies allow administrators to make simple modifications like excluding users or turning them from report-only mode to on or off. Organizations can't rename or delete any Microsoft-managed policies. As administrators get more comfortable with Conditional Access policy, they might choose to duplicate the policy to create custom versions.
The "Require approved client app" control in Microsoft Entra Conditional Access will retire in June 2026. Organizations should update policies to use the "Require application protection policy" control for equivalent and enhanced protection. After retirement, the old control will no longer be enforceable.
It's possible that the agent was enabled before Microsoft Ignite 2025 with an account that required role activation with Privileged Identity Management (PIM). So when the agent attempted to run, it failed because the account didn't have the required permissions at that time. Conditional Access Optimization Agents that were turned on after November 17, 2025 no longer use the identity of the user who activated the agent.
- [Define certificate based application configuration](https://devblogs.microsoft.com/identity/app-management-policy/)
The prolonged dormancy of these accounts provides attackers with extended dwell time to conduct reconnaissance, exfiltrate sensitive data, and establish backdoors without detection, as organizations typically focus monitoring efforts on active internal users rather than external guest accounts.
The email notifications provide a basic summary of the specific recommendation with a link to the related area of the Microsoft Entra admin center. The email also includes a link to related documentation so you can learn more about the recommendation and how to resolve it. These emails are enabled by default, aren't promotional or marketing emails, and don't contain any upselling content. These emails are purely informational and designed to help you act quickly when a new recommendation is available.
- [Deploy a privileged access workstation solution](/security/privileged-access-workstations/privileged-access-deployment)
Additionally, compromised guest identities can be used to establish credential persistence and potentially escalate privileges. Attackers can exploit trust relationships between guest accounts and internal resources, or use the guest account as a staging ground for lateral movement toward more privileged organizational assets.
In Microsoft Entra ID, if another administrator or nonadministrator needs to manage Microsoft Entra resources, you assign them a Microsoft Entra role that provides the permissions they need. For example, you can assign roles to allow adding or changing users, resetting user passwords, managing user licenses, or managing domain names.
Custom greetings in voice call authentication will retire on February 28, 2026. After this date, voice calls for multifactor authentication will use Microsoft’s default recordings. Organizations should prepare users for this change and review their MFA configurations accordingly.
Adding a work or school account to macOS is a straightforward process that enhances your access to organizational resources and services. This article provides an overview and answers to some Frequently Asked Questions (FAQs) about adding a work or school account to your macOS device using applications such as Microsoft Outlook or Microsoft Edge.
While an application with open assignment but proper provisioning scoping (such as department-based filters or group membership requirements) maintains security controls through the provisioning layer, applications lacking both controls create unrestricted access pathways that threat actors can exploit. When applications provision accounts for all users without assignment restrictions, threat actors can abuse compromised accounts to conduct reconnaissance activities, enumerate sensitive data across multiple systems, or use the applications as staging points for further attacks against connected resources. This unrestricted access model is dangerous for applications that have elevated permissions or are connected to critical business systems. Threat actors can use any compromised user account to access sensitive information, modify data, or perform unauthorized actions that the application's permissions allow. The absence of both assignment controls and provisioning scoping also prevents organizations from implementing proper access governance. Without proper governance, it's difficult to track who has access to which applications, when access was granted, and whether access should be revoked based on role changes or employment status. Furthermore, applications with broad provisioning scopes can create cascading security risks where a single compromised account provides access to an entire ecosystem of connected applications and services.
The same issue occurs when a server with Microsoft Entra Connect installed is cloned into another production server, which isn't a supported method of deploying this product as these servers with share the same machine identifier. In short, the server's identity conflicts because they get tied to one app registration. The Microsoft Entra Connect wizard by default uses unique accounts per server because it uses the server's name to identify the application registration instead of the Microsoft Entra connector's service account, which avoids this issue.
In Microsoft Entra ID Governance, you can enable business groups to determine which of these guests should have access, and for how long, using:
A Microsoft Entra documentation page was updated: Delegate Approvals My Access.
- External users in Microsoft Entra [external tenants](tenant-configurations.md#external-tenants), which includes consumers and business guests (users without directory roles), and admins (users with directory roles). MAU billing applies to all users in an external tenant regardless of their **UserType** setting.
- [Microsoft Global Secure Access deployment guide for Microsoft Traffic](gsa-deployment-guide-microsoft-traffic.md)
If administrators assign privileged roles to workload identities, such as service principals or managed identities, the tenant can be exposed to significant risk if those identities are compromised. Threat actors who gain access to a privileged workload identity can perform reconnaissance to enumerate resources, escalate privileges, and manipulate or exfiltrate sensitive data. The attack chain typically begins with credential theft or abuse of a vulnerable application. Next step is privilege escalation through the assigned role, lateral movement across cloud resources, and finally persistence via other role assignments or credential updates. Workload identities are often used in automation and might not be monitored as closely as user accounts. Compromise can then go undetected, allowing threat actors to maintain access and control over critical resources. Workload identities aren't subject to user-centric protections like MFA, making least-privilege assignment and regular review essential.
manager: dougeby