author: justinha
Conditional Access hardening is the main Entra theme on 9 September 2025
The most consequential update is revised Entra ID guidance for protecting multifactor authentication and self-service password reset method registration with Conditional Access. It warns that unprotected registration flows can be intercepted and used to add an attacker’s authentication method. Related updates cover blocking device code flow and authentication transfer, restricting high-risk sign-ins in ID Protection, and protecting tokens from theft. This is a documentation-heavy period, not a feature rollout: all 18 supplied items are updates, with no new, removed, or Message Center entries. The evidence supports security guidance and integration documentation, but not a preview, general-availability announcement, retirement, or changed service behavior.
- Entra ID: updated protection guidance for MFA and SSPR registration
Entra ID · Conditional Access
The revised authentication guidance says that without Conditional Access protecting security-information registration, adversary-in-the-middle attacks or unmanaged devices from untrusted locations can expose MFA and self-service password reset registration. An attacker could then register their own authentication methods. This is security guidance, not evidence of a new registration capability or an automatic policy change; administrators should verify that the relevant registration flows are covered.
- Entra ID: Conditional Access procedures for device code flow and authentication transfer
Entra ID · Conditional Access
An updated fundamentals page covers creating Conditional Access policies to restrict device code flow and authentication transfer. The supplied record establishes procedural guidance, but does not say that these controls are newly introduced, generally available, or enabled by default. Treat it as configuration guidance rather than a rollout notice.
- ID Protection: emphasis on restricting high-risk sign-ins
ID Protection · Conditional Access
Updated ID Protection guidance warns that allowing high-risk sign-ins without appropriate Conditional Access restrictions can give compromised credentials a path to initial access, privilege escalation, and reconnaissance. This is risk-management guidance, not evidence of a change to risk detection. Review how existing policies restrict high-risk sign-ins.
- Entra ID: token protection is described as a token-binding defense
Entra ID · Security
The updated security content explains that token protection, also called token binding, uses cryptography and the client device key so a token is usable only from the intended device, helping reduce token-theft exposure. No implementation scope, rollout instruction, preview status, or availability change is supplied.
- Global Secure Access: Sentinel integration guidance points to preconfigured monitoring content
Global Secure Access · Security
Updated Global Secure Access documentation describes integration with Microsoft Sentinel using preconfigured workbooks and analytics rules. This gives administrators an integration path to review when both services are in use, but the supplied item does not establish a new release, availability state, or automatic deployment.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
18 updates
Microsoft Entra ID
16 updates21828
UpdatedBlocking authentication transfer in Microsoft Entra ID is a critical security control. It helps protect against token theft and replay attacks by preventing the use of device tokens to silently authenticate on other devices or browsers. When authentication transfer is enabled, a threat actor who gains access to one device can access resources to nonapproved devices, bypassing standard authentication and device compliance checks. When administrators block this flow, organizations can ensure that each authentication request must originate from the original device, maintaining the integrity of the device compliance and user session context.
21781
Updated- [Get started with a phishing-resistant passwordless authentication deployment](/entra/identity/authentication/how-to-plan-prerequisites-phishing-resistant-passwordless-authentication)
21782
Updated- [Get started with a phishing-resistant passwordless authentication deployment](/entra/identity/authentication/how-to-plan-prerequisites-phishing-resistant-passwordless-authentication)
21783
Updated- [Get started with a phishing-resistant passwordless authentication deployment](/entra/identity/authentication/how-to-plan-prerequisites-phishing-resistant-passwordless-authentication)
21800
Updated- [Deploy multifactor authentication](/entra/identity/authentication/howto-mfa-getstarted)
21801
Updated- [Deploy multifactor authentication](/entra/identity/authentication/howto-mfa-getstarted)
21796
Updated**Remediation action**
21808
Updated**Remediation action**
21851
Updated**Remediation action**
21872
Updated**Remediation action**
21806
UpdatedWithout Conditional Access policies protecting security information registration, threat actors can exploit unprotected registration flows to compromise authentication methods. When users register multifactor authentication and self-service password reset methods without proper controls, threat actors can intercept these registration sessions through adversary-in-the-middle attacks or exploit unmanaged devices accessing registration from untrusted locations. Once threat actors gain access to an unprotected registration flow, they can register their own authentication methods, effectively hijacking the target's authentication profile. The threat actors can bypass security controls and potentially escalate privileges throughout the environment because they can maintain persistent access by controlling the MFA methods. The compromised authentication methods then become the foundation for lateral movement as threat actors can authenticate as the legitimate user across multiple services and applications.
The following steps help create Conditional Access policies to restrict how [device code flow](concept-authentication-flows.md#device-code-flow) and [authentication transfer](concept-authentication-flows.md#authentication-transfer) are used within your organization.
Plan Conditional Access
UpdatedStart with a few core Conditional Access policies like the ones that follow. Many policies are available as [Conditional Access policy templates](concept-conditional-access-policy-common.md). By default, each policy created from a template is in report-only mode. Test and monitor usage, to ensure the intended result, before turning on each policy.
21786
UpdatedToken protection, also called token binding, helps prevent token theft by making sure a token is usable only from the intended device. Token protection uses cryptography so that without the client device key, no one can use the token.
userimpact: High
UpdatedAssume high risk users are compromised by threat actors. Without investigation and remediation, threat actors can execute scripts, deploy malicious applications, or manipulate API calls to establish persistence, based on the potentially compromised user's permissions. Threat actors can then exploit misconfigurations or abuse OAuth tokens to move laterally across workloads like documents, SaaS applications, or Azure resources. Threat actors can gain access to sensitive files, customer records, or proprietary code and exfiltrate it to external repositories while maintaining stealth through legitimate cloud services. Finally, threat actors might disrupt operations by modifying configurations, encrypting data for ransom, or using the stolen information for further attacks, resulting in financial, reputational, and regulatory consequences.
Microsoft Entra ID Protection
1 update21799
UpdatedWhen high-risk sign-ins are not properly restricted through Conditional Access policies, organizations expose themselves to security vulnerabilities. Threat actors can exploit these gaps for initial access through compromised credentials, credential stuffing attacks, or anomalous sign-in patterns that Microsoft Entra ID Protection identifies as risky behaviors. Without appropriate restrictions, threat actors who successfully authenticate during high-risk scenarios can perform privilege escalation by misusing the authenticated session to access sensitive resources, modify security configurations, or conduct reconnaissance activities within the environment. Once threat actors establish access through uncontrolled high-risk sign-ins, they can achieve persistence by creating additional accounts, installing backdoors, or modifying authentication policies to maintain long-term access to the organization's resources. The unrestricted access enables threat actors to conduct lateral movement across systems and applications using the authenticated session, potentially accessing sensitive data stores, administrative interfaces, or critical business applications. Finally, threat actors achieve impact through data exfiltration, or compromise business-critical systems while maintaining plausible deniability by exploiting the fact that their risky authentication was not properly challenged or blocked.
Strengthen your organization's security posture by integrating Global Secure Access with Microsoft Sentinel using preconfigured workbooks and analytics rules.
