← Previous day

Next day →
Day in brief

7 June 2025: Cross-tenant access guidance calls out an OME exception; security and licensing guidance are the main admin takeaways

The period is chiefly documentation maintenance, with no Message Center notice supplied. The clearest operational update is in External ID: the cross-tenant access overview warns that a block-all-apps outbound policy can prevent users from reading encrypted mail and names the app exception to allow. ID Governance guidance distinguishes Monthly Active User licensing for guests from employee licensing, while Entra ID and Workload ID updates provide security guidance on privileged-role activation alerting and Logic Apps permissions. A new guest-licensing page and a removed Security Copilot policy page are documented, but the evidence does not establish a licensing-rule change, feature launch, or service retirement.

  • The updated overview says that blocking access to all apps by default prevents users from reading mail protected by Microsoft Rights Management Service, also called Office 365 Message Encryption. It recommends outbound access to app ID 00000012-0000-0000-c000-000000000000. This is documented behavior and configuration guidance, not evidence that the default policy behavior changed.

  • The updated guidance states that Microsoft Entra ID Governance uses Monthly Active User licensing for guest users, unlike licensing for employees, and points administrators to the licensing fundamentals page. The record describes a documentation clarification, not a newly announced licensing model.

  • The update warns that without proper activation alerts for highly privileged roles, privilege escalation, persistence, policy changes, audit changes, or disabled controls may go undetected. Review current activation-alert coverage; the evidence does not identify a new alert feature or a changed default.

  • The update describes risk from misaligned Logic Apps management roles and Entra directory roles: a compromised account could modify provisioning workflows and then use managed identities and existing connections for lateral movement. It supports a permissions review, but does not announce a new Workload ID control.

  • The updated guidance says access package approvers may be directly assigned or determined dynamically, including the requester's manager, second-level manager, or a sponsor from a connected organization. This is a documentation clarification of supported approval patterns, not evidence of a new rollout.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

14 updates

2

userimpact: Low

Updated

Organizations without proper activation alerts for highly privileged roles lack visibility into when users access these critical permissions. Threat actors can exploit this monitoring gap to perform privilege escalation by activating highly privileged roles without detection, then establish persistence through admin account creation or security policy modifications. The absence of real-time alerts enables attackers to conduct lateral movement, modify audit configurations, and disable security controls without triggering immediate response procedures.

Sla Performance

Updated

| February | 99.999% | 99.999% | 99.999% | 99.999% | 99.998% |

1
1
1
2

Copilot Entra Security Scenarios

Updated

- [Investigate insights within entitlements management](#investigate-insights-within-entitlements-management): Get quick access to information about access packages, policies, connected organizations, and catalog resources.

Microsoft Entra Id Governance Licensing For Guest Users

Updated

Microsoft Entra ID Governance utilizes Monthly Active User (MAU) licensing for guest users which is different than licensing for employees. See [Microsoft Entra ID Governance licensing fundamentals](/entra/id-governance/licensing-fundamentals) for complete details on licensing for employees.

2

Entitlement Management Dynamic Approval

Updated

In entitlement management, approvers for access package requests can either be directly assigned, or determined dynamically. Entitlement management natively supports approvers when they are the requestors manager, their second-level manager, or a sponsor from a connected organization:

1

Microsoft Accounts Federation Customers

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).

1

Cross Tenant Access Overview

Updated

- If you block access to all apps by default, users are unable to read emails encrypted with Microsoft Rights Management Service, also known as Office 365 Message Encryption (OME). To avoid this issue, we recommend configuring your outbound settings to allow your users to access this app ID: 00000012-0000-0000-c000-000000000000. If you allow only this application, access to all other apps is blocked by default.

1

userimpact: Low

Updated

Azure Logic Apps integrated with Microsoft Entra Identity Governance create a significant attack surface when access controls are inadequate. Threat actors can exploit misaligned permissions between Logic Apps management roles and Microsoft Entra directory roles to gain initial access through compromised accounts with excessive Azure RBAC permissions. With access, threat actors can modify workflow logic to insert malicious automation into provisioning processes, then use managed identities and existing connections for lateral movement across connected systems.

1
1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…