Explains requirements to prepare FIDO2 hardware for attestation with Microsoft Entra ID
Entra’s main change on 9 December: updated Microsoft-managed app-consent guidance; FIDO2 attestation documentation also revised
The period contained two Entra ID documentation updates and no new feature, preview, general-availability, retirement, or Message Center announcement. The more consequential update concerns the Microsoft-managed app-consent policy; the FIDO2 entry is primarily a hardware-attestation documentation clarification.
The updated Manage App Consent Policies guidance says that “Let Microsoft manage your consent settings” uses a Microsoft-managed policy that will update with Microsoft’s latest recommended default consent settings and is also the default for a new tenant. The documented rules exclude broad delegated permissions from end-user consent, including examples covering Files, Sites, Mail, and Calendars. Treat this as updated policy guidance rather than evidence of a same-day service rollout, and review the setting if your-
- FIDO2 security-key attestation requirements were revised
Entra ID · Authentication
Microsoft updated the guidance explaining what FIDO2 hardware vendors must do to prepare security keys for attestation with Microsoft Entra ID. This is relevant to administrators whose security-key procurement or rollout depends on attestation, but the supplied change does not identify a new Entra tenant setting, availability milestone, or changed enforcement behavior.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
2 updates
Microsoft Entra ID
2 updatesManage App Consent Policies
UpdatedThe setting labeled "Let Microsoft manage your consent settings," the Microsoft managed policy, will update with Microsoft's latest recommended default consent settings. This is also the default for a new tenant. The setting's rules are currently: End users can consent for any user consentable delegated permissions EXCEPT: `Files.Read.All`, `Files.ReadWrite.All`, `Sites.Read.All`, `Sites.ReadWrite.All`, `Mail.Read`, `Mail.ReadWrite`, `Mail.ReadBasic`, `Mail.Read.Shared`, `Mail.ReadBasic.Shared`, `Mail.ReadWrite.Shared`, `MailboxItem.Read`, `Calendars.Read`, `Calendars.ReadBasic`, `Calendars.ReadWrite`, `Calendars.Read.Shared`, `Calendars.ReadBasic.Shared`, `Calendars.ReadWrite.Shared`, `Chat.Read`, `Chat.ReadWrite`, `ChannelMessage.Read.All`, `OnlineMeetings.Read`, `OnlineMeetings.ReadWrite`, `OnlineMeetingTranscript.Read.All`, `OnlineMeetingsRecording.Read.All`. Updates to this consent policy will have at least 30 days of given notice.
