← Previous day

Next day →
Day in brief

13 June 2025: Entra security guidance leads a documentation-focused update day

All 12 recorded changes are Microsoft Learn updates; there are no new or removed items and no Message Center entries. The strongest content is updated Entra ID security guidance on orphaned OAuth redirect URIs and persistent Global Administrator access to Azure subscriptions. A Workload ID/Conditional Access page clarifies cloud-app targeting semantics, while an ID Governance page clarifies where Azure-resource and Entra-role access reviews are handled. The evidence supports documentation clarification and security guidance—not a preview, GA launch, retirement, or confirmed service-behavior change.

  • The updated guidance explains that unmaintained redirect URIs pointing to abandoned domains can be exploited through dangling DNS entries, allowing attackers to provision resources at those domains and intercept OAuth 2.0 tokens or credentials. This is security guidance, not evidence of a newly deployed protection; review app registrations for stale redirect endpoints.

  • The updated guidance says standing Global Administrator access to Azure subscriptions can let a compromised account enumerate resources, modify configurations, assign roles, and exfiltrate data. It presents just-in-time elevation as a way to add detectable signals and observable control points. This describes security posture guidance, not a new enforcement change; review standing access where applicable.

  • The updated Conditional Access Cloud Apps documentation says Microsoft cloud apps can be targeted when their service principal is present in the tenant. It also clarifies that picker entries such as Office 365 and Windows Azure Service Management API can represent multiple child apps or services, and that newly supported Microsoft cloud applications appear in the picker. The supplied evidence does not establish that these behaviors changed on this date.

  • The updated Create Access Review page directs administrators reviewing Azure resources or Microsoft Entra roles to the corresponding Privileged Identity Management procedure. This is a documentation and process-routing clarification, not evidence of a new Access Reviews capability or licensing change.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

12 updates

2

userimpact: Low

Updated

Unmaintained or orphaned redirect URIs in app registrations create significant security vulnerabilities when they reference domains that no longer point to active resources. Threat actors can exploit these "dangling" DNS entries by provisioning resources at abandoned domains, effectively taking control of redirect endpoints. This vulnerability enables attackers to intercept authentication tokens and credentials during OAuth 2.0 flows, which can lead to unauthorized access, session hijacking, and potential broader organizational compromise.

2
2

userimpact: Low

Updated

Global Administrators with persistent access to Azure subscriptions expand the attack surface for threat actors. If a Global Administrator account is compromised, attackers can immediately enumerate resources, modify configurations, assign roles, and exfiltrate sensitive data across all subscriptions. Requiring just-in-time elevation for subscription access introduces detectable signals, slows attacker velocity, and routes high-impact operations through observable control points.

2

Create Access Review

Updated

- To review Azure resource or Microsoft Entra roles, see [Create an access review of Azure resource and Microsoft Entra roles in Privileged Identity Management](privileged-identity-management/pim-create-roles-and-resource-roles-review.md).

1
2
1

Conditional Access Cloud Apps

Updated

Administrators can assign a Conditional Access policy to cloud apps from Microsoft as long as the service principal appears in their tenant. Some apps like [Office 365](#office-365) and [Windows Azure Service Management API](#windows-azure-service-management-api) include multiple related child apps or services. When new supported Microsoft cloud applications are created, they appear in the app picker list.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…