← Previous day

Next day →
Day in brief

Conditional Access hardening is the main Entra theme on 9 September 2025

The most consequential update is revised Entra ID guidance for protecting multifactor authentication and self-service password reset method registration with Conditional Access. It warns that unprotected registration flows can be intercepted and used to add an attacker’s authentication method. Related updates cover blocking device code flow and authentication transfer, restricting high-risk sign-ins in ID Protection, and protecting tokens from theft. This is a documentation-heavy period, not a feature rollout: all 18 supplied items are updates, with no new, removed, or Message Center entries. The evidence supports security guidance and integration documentation, but not a preview, general-availability announcement, retirement, or changed service behavior.

  • The revised authentication guidance says that without Conditional Access protecting security-information registration, adversary-in-the-middle attacks or unmanaged devices from untrusted locations can expose MFA and self-service password reset registration. An attacker could then register their own authentication methods. This is security guidance, not evidence of a new registration capability or an automatic policy change; administrators should verify that the relevant registration flows are covered.

  • An updated fundamentals page covers creating Conditional Access policies to restrict device code flow and authentication transfer. The supplied record establishes procedural guidance, but does not say that these controls are newly introduced, generally available, or enabled by default. Treat it as configuration guidance rather than a rollout notice.

  • Updated ID Protection guidance warns that allowing high-risk sign-ins without appropriate Conditional Access restrictions can give compromised credentials a path to initial access, privilege escalation, and reconnaissance. This is risk-management guidance, not evidence of a change to risk detection. Review how existing policies restrict high-risk sign-ins.

  • The updated security content explains that token protection, also called token binding, uses cryptography and the client device key so a token is usable only from the intended device, helping reduce token-theft exposure. No implementation scope, rollout instruction, preview status, or availability change is supplied.

  • Updated Global Secure Access documentation describes integration with Microsoft Sentinel using preconfigured workbooks and analytics rules. This gives administrators an integration path to review when both services are in use, but the supplied item does not establish a new release, availability state, or automatic deployment.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

18 updates

7

21828

Updated

Blocking authentication transfer in Microsoft Entra ID is a critical security control. It helps protect against token theft and replay attacks by preventing the use of device tokens to silently authenticate on other devices or browsers. When authentication transfer is enabled, a threat actor who gains access to one device can access resources to nonapproved devices, bypassing standard authentication and device compliance checks. When administrators block this flow, organizations can ensure that each authentication request must originate from the original device, maintaining the integrity of the device compliance and user session context.

21781

Updated

- [Get started with a phishing-resistant passwordless authentication deployment](/entra/identity/authentication/how-to-plan-prerequisites-phishing-resistant-passwordless-authentication)

21782

Updated

- [Get started with a phishing-resistant passwordless authentication deployment](/entra/identity/authentication/how-to-plan-prerequisites-phishing-resistant-passwordless-authentication)

21783

Updated

- [Get started with a phishing-resistant passwordless authentication deployment](/entra/identity/authentication/how-to-plan-prerequisites-phishing-resistant-passwordless-authentication)

21800

Updated

- [Deploy multifactor authentication](/entra/identity/authentication/howto-mfa-getstarted)

21801

Updated

- [Deploy multifactor authentication](/entra/identity/authentication/howto-mfa-getstarted)

4

21796

Updated

**Remediation action**

21808

Updated

**Remediation action**

21851

Updated

**Remediation action**

21872

Updated

**Remediation action**

3

21806

Updated

Without Conditional Access policies protecting security information registration, threat actors can exploit unprotected registration flows to compromise authentication methods. When users register multifactor authentication and self-service password reset methods without proper controls, threat actors can intercept these registration sessions through adversary-in-the-middle attacks or exploit unmanaged devices accessing registration from untrusted locations. Once threat actors gain access to an unprotected registration flow, they can register their own authentication methods, effectively hijacking the target's authentication profile. The threat actors can bypass security controls and potentially escalate privileges throughout the environment because they can maintain persistent access by controlling the MFA methods. The compromised authentication methods then become the foundation for lateral movement as threat actors can authenticate as the legitimate user across multiple services and applications.

Block authentication flows with Conditional Access policy

Updated

The following steps help create Conditional Access policies to restrict how [device code flow](concept-authentication-flows.md#device-code-flow) and [authentication transfer](concept-authentication-flows.md#authentication-transfer) are used within your organization.

Plan Conditional Access

Updated

Start with a few core Conditional Access policies like the ones that follow. Many policies are available as [Conditional Access policy templates](concept-conditional-access-policy-common.md). By default, each policy created from a template is in report-only mode. Test and monitor usage, to ensure the intended result, before turning on each policy.

1

21786

Updated

Token protection, also called token binding, helps prevent token theft by making sure a token is usable only from the intended device. Token protection uses cryptography so that without the client device key, no one can use the token.

1

userimpact: High

Updated

Assume high risk users are compromised by threat actors. Without investigation and remediation, threat actors can execute scripts, deploy malicious applications, or manipulate API calls to establish persistence, based on the potentially compromised user's permissions. Threat actors can then exploit misconfigurations or abuse OAuth tokens to move laterally across workloads like documents, SaaS applications, or Azure resources. Threat actors can gain access to sensitive files, customer records, or proprietary code and exfiltrate it to external repositories while maintaining stealth through legitimate cloud services. Finally, threat actors might disrupt operations by modifying configurations, encrypting data for ransom, or using the stolen information for further attacks, resulting in financial, reputational, and regulatory consequences.

1

21799

Updated

When high-risk sign-ins are not properly restricted through Conditional Access policies, organizations expose themselves to security vulnerabilities. Threat actors can exploit these gaps for initial access through compromised credentials, credential stuffing attacks, or anomalous sign-in patterns that Microsoft Entra ID Protection identifies as risky behaviors. Without appropriate restrictions, threat actors who successfully authenticate during high-risk scenarios can perform privilege escalation by misusing the authenticated session to access sensitive resources, modify security configurations, or conduct reconnaissance activities within the environment. Once threat actors establish access through uncontrolled high-risk sign-ins, they can achieve persistence by creating additional accounts, installing backdoors, or modifying authentication policies to maintain long-term access to the organization's resources. The unrestricted access enables threat actors to conduct lateral movement across systems and applications using the authenticated session, potentially accessing sensitive data stores, administrative interfaces, or critical business applications. Finally, threat actors achieve impact through data exfiltration, or compromise business-critical systems while maintaining plausible deniability by exploiting the fact that their risky authentication was not properly challenged or blocked.

1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…