manager: CelesteDG
12 June: Entra guidance spotlights rapid PIM escalation and workload-identity credential risk
The period was dominated by Microsoft Learn maintenance: 21 pages were updated, one was added, one was removed, and there were no Message Center notices. The most consequential content concerns privileged-role activation, credentials on Microsoft service principals, and external collaboration with unverified organizations. Microsoft Entra ID Governance documentation also clarifies a billing trigger for guest access-package requests that use custom extensions. The supplied evidence shows no preview, general-availability announcement, product retirement, or confirmed service-behavior change. The new “Tenant restrictions v2 policy is configured” record contains only author metadata, while the removed “27193” record provides no subject detail, so neither supports a rollout or retirement conclusion.
- PIM guidance emphasizes approval before privileged activation
Workload ID · Conditional Access
An updated security guidance page explains that, without approval workflows, compromised Global Administrator credentials can activate an eligible privileged role without additional oversight, with activation possible within seconds. It also describes persistence tactics such as creating privileged accounts and excluding them from Conditional Access. This is guidance about the risk of the PIM configuration, not evidence that PIM activation timing changed.
- Service-principal credentials are called out as a workload-identity attack surface
Workload ID · Authentication
Updated Workload ID guidance notes that Microsoft services applications appear as service principals in the tenant and that configured credentials can be abused. Credentials added by administrators but no longer needed, or credentials added maliciously, can allow authentication as the service principal. Administrators should use the guidance to verify credential necessity, ownership, and authorization; no new credential-control feature is evidenced.
- External collaboration guidance flags unverified organizations
Entra ID · Security
Updated Entra ID security content warns that unrestricted collaboration with unverified organizations can admit guests from tenants without adequate security controls. Attackers may use legitimate collaboration paths and misconfigured permissions to gain access or escalate privileges. This is a security-risk clarification, not a stated change to external-collaboration policy behavior.
- Guest access-package licensing trigger is clarified
ID Governance · Governance
The updated ID Governance licensing documentation states that an Entitlement Management guest policy using a custom extension is billed on successful request creation. It identifies access-package assignment and user-update request scenarios, along with the documented assignmentRequests Graph endpoint. This is a licensing documentation clarification, not evidence that a new billing rule was introduced.
- Security Copilot documentation makes the Entra tenant prerequisite explicit
Security Copilot · Fundamentals
The updated Security Copilot article describes identity-related Microsoft Entra scenarios and states that using the feature requires a tenant with Microsoft Security Copilot enabled. This clarifies scope and prerequisites; it is not evidence of a new capability, preview, or general-availability change.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
23 updates
Microsoft Entra ID
13 updatesauthor: shlipsey3
author: HULKsmashGithub
category: Access control
Updatedauthor: HULKsmashGithub
To evaluate the rule for dynamic membership groups, the administrator must be at least a [Groups Administrator](~/identity/role-based-access-control/permissions-reference.md#groups-administrator).
Mysdworxcom Tutorial
Updated* Enable your users to be automatically signed-in to my.sdworx.com with their Microsoft Entra accounts.
27193
RemovedA Microsoft Entra documentation page was updated: 27193.
Mfa Regional Opt In
UpdatedWhen a transaction is flagged as potentially abusive:
author: HULKsmashGithub
author: HULKsmashGithub
Custom Extension Overview
Updateduserimpact: Low
UpdatedAllowing unrestricted external collaboration with unverified organizations can increase the risk surface area of the tenant because it allows guest accounts that might not have proper security controls. Threat actors can attempt to gain access by compromising identities in these loosely-governed external tenants. Once granted guest access, they can then leverage legitimate collaboration pathways to infiltrate resources in your tenant and attempt to gain sensitive information. Threat actors can also exploit misconfigured permissions to escalate privileges and try different types of attacks.
1. Ensure that you have your Enterprise URL before you begin. The ENTITY field mentioned below is the Enterprise name of your EMU-enabled Enterprise URL. For example, https://github.com/enterprises/contoso - **contoso** is the ENTITY. On the **Basic SAML Configuration** section, if you wish to configure the application in **IDP** initiated mode, enter the values for the following fields:
Microsoft Entra ID Protection
1 updateauthor: HULKsmashGithub
Microsoft Entra ID Governance
3 updates| Entitlement Management | [Guest policy assigned with custom extension](entitlement-management-logic-apps-integration.md) | Bill on successful request creation when a custom extension is included in the assignment policy.<br>**API**<br> https://graph.microsoft.com/v1.0/identityGovernance/entitlementManagement/assignmentRequests when a custom extension is included in the assignment policy. | User requests access package assignment, Create access package assignment user update request. |
Licensing Governance
Updated|[Entitlement management - Mark guest as governed](~/id-governance/entitlement-management-access-package-manage-lifecycle.md)|||| :white_check_mark: | :white_check_mark: |
Microsoft Entra ID Governance applies the capabilities of [Microsoft Security Copilot](/security-copilot/microsoft-security-copilot) to save identity administrators time and effort when configuring custom workflows to manage the lifecycle of users across JML scenarios. It also helps you to customize workflows more efficiently using natural language to configure workflow information including custom tasks, execute workflows, and get workflow insights.
Microsoft Entra External ID
1 updateGoogle Federation
Updated**To configure Google federation in the Microsoft Entra admin center**
Microsoft Entra Workload ID
4 updates21774
UpdatedMicrosoft services applications that operate in your tenant are identified as service principals with the owner organization ID "f8cdef31-a31e-4b4a-93e4-5f571e91255a". When these service principals have credentials configured in your tenant, they might create potential attack vectors that threat actors can exploit. If the credentials were added by an administrator and are no longer needed, they can become a target for attackers. Although less likely when proper preventive and detective controls are in place on privileged activities, credentials can also be added maliciously by threat actors. In either case, threat actors can use these credentials to authenticate as the service principal, gaining the same permissions and access rights as the Microsoft service application. This initial access can lead to privilege escalation if the application has high-level permissions, allowing lateral movement across the tenant. Attackers can then proceed to data exfiltration or persistence establishment through creating additional backdoor credentials.
userimpact: Low
UpdatedWithout approval workflows, threat actors who compromise Global Administrator credentials through phishing, credential stuffing, or other authentication bypass techniques can immediately activate the most privileged role in a tenant without any additional verification or oversight. Privileged Identity Management (PIM) allows eligible role activations to become active within seconds, so compromised credentials can allow near-instant privilege escalation. Once activated, threat actors can use the Global Administrator role to gain persistent access by creating new privileged accounts, modifying Conditional Access policies to exclude those new accounts, and establishing alternate authentication methods such as certificate-based authentication or application registrations with high privileges. The Global Administrator role provides access to administrative features in Microsoft Entra ID and services that use Microsoft Entra identities, including Microsoft 365 Defender, Microsoft Purview, Exchange Online, and SharePoint Online. Without approval gates, threat actors can rapidly escalate to complete tenant takeover, exfiltrating sensitive data, compromising all user accounts, and establishing long-term backdoors through service principals or federation modifications that persist even after the initial compromise is detected.
Jason starts his assessment and signs in to [Microsoft Security Copilot](https://securitycopilot.microsoft.com/) or the Microsoft Entra admin center. In order to view application and service principal details, he signs in as at least a [Security Reader](/entra/identity/role-based-access-control/permissions-reference#security-reader) and needs an [Microsoft Entra role assignment](../identity/role-based-access-control/permissions-reference.md) of Application Administrator, Cloud Application Administrator, or similar Microsoft Entra administrator role that has permissions to manage application/workload identities in Microsoft Entra.
author: HULKsmashGithub
Security Copilot + Entra
1 updateMicrosoft Security Copilot is a powerful tool that can help you manage and secure your Microsoft Entra identity environment. This article describes how to use Microsoft Security Copilot with Microsoft Entra in identity related scenarios to enhance your identity protection efforts. Using this feature requires a tenant with Microsoft Security Copilot enabled.
