← Previous day

Next day →
Day in brief

15 July: TLS 1.0/1.1 enforcement and risky enterprise-app settings lead a documentation-only day

All 10 supplied records are Microsoft Learn updates; there are no new or removed items and no Message Center notice. The meaningful content is security and access guidance rather than a feature launch: Entra Domain Services documentation describes disabling TLS 1.0 and 1.1, an Entra ID provisioning page flags a dangerous combination of assignment and provisioning controls, Security Copilot access is clarified for Conditional Access Administrators, and FIDO2 key-vendor validation requirements are made explicit. The other edits are mainly maintenance—metadata, a licensing reference, a network command, a screenshot, and small troubleshooting or author changes.

  • The updated TLS enforcement page says Microsoft is disabling TLS 1.0 and 1.1, citing the 10 November 2023 communication, and explains that TLS 1.2 or later offers stronger security features such as perfect forward secrecy and stronger cipher suites. The supplied change is documentation evidence and does not state an effective date.

  • The updated provisioning guidance identifies the highest risk when Assignment required is No and provisioning is not required or scoped. It says a compromised user account could then gain immediate access to applications with broad user bases, increasing exposure and possible lateral movement. This is a security warning about configuration posture, not a reported enforcement change.

  • The Agent Optimization update states that Security Administrator and Global Administrator roles have Security Copilot access by default, while Conditional Access Administrators can be assigned access. It clarifies who may use the agent; the record does not say that this was a new feature, preview, or automatic role change on 15 July.

  • The Enable Passkey Fido2 update says metadata for FIDO2 security keys must be published and verified through the FIDO Alliance Metadata Service and must also pass Microsoft validation testing. The evidence points to Microsoft-compatible key-vendor requirements, not a new tenant configuration or passkey availability change.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

10 updates

1

Enable Passkey Fido2

Updated

- Metadata for FIDO2 security keys needs to be published and verified with the FIDO Alliance Metadata Service, and also pass another set of validation testing by Microsoft. For more information, see [Become a Microsoft-compatible FIDO2 security key vendor](/entra/identity/authentication/concept-fido2-hardware-vendor).

1
1
1

Licensing Service Plan Reference

Updated

- **Service plans included (friendly names)**: A list of service plans (friendly names) in the product that correspond to the string ID and GUID

1

21869

Updated

When enterprise applications lack both explicit assignment requirements AND scoped provisioning controls, threat actors can exploit this dual weakness to gain unauthorized access to sensitive applications and data. The highest risk occurs when applications are configured with the default setting: "Assignment required" is set to "No" *and* provisioning isn't required or scoped. This dangerous combination allows threat actors who compromise any user account within the tenant to immediately access applications with broad user bases, expanding their attack surface and potential for lateral movement within the organization.

1

Network Considerations

Updated

Get-AzNetworkSecurityGroup -Name "nsg-name" -ResourceGroupName "resource-group-name" | Add-AzNetworkSecurityRuleConfig -Name "new-rule-name" -Access "Allow" -Protocol "TCP" -Direction "Inbound" -Priority "priority-number" -SourceAddressPrefix "CorpNetSaw" -SourcePortRange "*" -DestinationPortRange "3389" -DestinationAddressPrefix "*" | Set-AzNetworkSecurityGroup

1

Domain Services Tls Enforcement

Updated

Microsoft is enhancing security by disabling TLS versions 1.0 and 1.1 as communicated on November 10, 2023. While the Microsoft implementation of TLS 1.0 and TLS 1.1 versions isn't known to have vulnerabilities, TLS 1.2 or later versions provide improved security features, including perfect forward secrecy and stronger cipher suites. This change helps protect customer data and ensures compliance with industry standards.

1

Pim Create Roles And Resource Roles Review

Updated

:::image type="content" source="./media/pim-create-azure-ad-roles-and-resource-roles-review/current-v-series-setting.png" alt-text="Screenshot of the settings page under access reviews." lightbox="./media/pim-create-azure-ad-roles-and-resource-roles-review/current-v-series-setting.png":::

1

Complete Access Review

Updated

> - User not found / other errors can also result in an apply result not being supported.

1

Agent Optimization

Updated

The Security Administrator and Global Administrator roles have access to Security Copilot by default. You can assign Conditional Access Administrators with Security Copilot access. This authorization gives your Conditional Access Administrators the ability to use the agent as well. For more information, see [Assign Security Copilot access](/copilot/security/authentication#assign-security-copilot-access).

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…