Compliance Administrator
UpdatedCompliance Administrator
Daily.Entra.News25 March was primarily a documentation-maintenance day: all 36 recorded changes were updates, with no new or removed items and no Message Center notices. The most consequential clarification concerns Tenant Restrictions V2: cross-cloud requests can be permitted at authentication while being blocked at the data plane, with a specific Windows Group Policy consequence. Other substantive updates provide app-credential escalation guidance for the Privileged Authentication Administrator role, passkey deployment guidance, compliant-network Conditional Access guidance, and documentation for Global Secure Access prompt-injection protection, which is explicitly marked preview. The evidence does not establish a new launch, general-availability milestone, or retirement.
The updated External ID guidance states that TRv2 does not enforce cross-cloud restrictions at the authentication plane, so authentication is permitted, but blocks cross-cloud requests at the data plane. It specifically says Windows Group Policy users cannot access TRv2-enlightened resources across cloud boundaries. This is a documentation clarification of compatibility behavior, not evidence that a new control launched on 25 March.
The updated Entra ID role guidance notes that Application Registration and Enterprise Application owners can manage credentials for apps they own, and those apps may have privileged permissions. It describes how updating credentials can allow an Authentication Administrator to assume an application-owner identity and then a privileged application identity. This is security and permission-boundary guidance; the record does not say that the role permissions changed.
The updated article explains how to require known compliant network locations for connections to secured resources through Conditional Access. It is configuration guidance for Global Secure Access; the supplied item does not establish a new availability milestone or a change to existing tenant behavior.
The updated Entra ID authentication article describes using the Conditional Access Optimization Agent to safely deploy a passkey program and roll out phishing-resistant authentication methods. It is rollout guidance; no new capability announcement or preview-to-general-availability transition is evidenced.
The updated Global Secure Access security article describes Microsoft's AI Gateway prompt-injection protection for enterprise generative AI apps. The title explicitly labels the capability as preview, so this supports evaluation and configuration guidance only—not a general-availability claim.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Compliance Administrator
Global Reader
Global Administrator
author: MicrosoftGuyJFlo
- Manage Teams external collaboration settings that govern the organization's interactions with external users in chats, meetings, and calls.
>- Application Registration and Enterprise Application owners, who can manage credentials of apps they own. Those apps may have privileged permissions in Microsoft Entra ID and elsewhere not granted to Helpdesk Administrators. Through this path a Helpdesk Administrator may be able to assume the identity of an application owner and then further assume the identity of a privileged application by updating the credentials for the application.
>- Application Registration and Enterprise Application owners, who can manage credentials of apps they own. Those apps may have privileged permissions in Microsoft Entra ID and elsewhere not granted to User Administrators. Through this path a User Administrator may be able to assume the identity of an application owner and then further assume the identity of a privileged application by updating the credentials for the application.
>* Application Registration and Enterprise Application owners, who can manage credentials of apps they own. Those apps may have privileged permissions in Microsoft Entra ID and elsewhere not granted to Authentication Administrators. Through this path an Authentication Administrator can assume the identity of an application owner and then further assume the identity of a privileged application by updating the credentials for the application.
Learn how to use the Conditional Access Optimization Agent to safely deploy a passkey program to roll out phishing-resistant authentication methods.
**What’s changing**
This is a [privileged role](../privileged-roles-permissions.md). Users with this role have permissions to manage security-related features in the Microsoft Defender portal, Microsoft Entra ID Protection, Microsoft Entra Authentication, Azure Information Protection, and Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
This is a [privileged role](../privileged-roles-permissions.md). Users with this role have global read-only access on security-related feature, including all information in Microsoft Defender portal, Microsoft Entra ID Protection, Privileged Identity Management, and the ability to read Microsoft Entra sign-in reports and audit logs, and in Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
This is a [privileged role](../privileged-roles-permissions.md). Users with this role can manage alerts and have global read-only access on security-related features, including all information in Microsoft Defender portal, Microsoft Entra ID Protection, Privileged Identity Management, and Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
Security Copilot will be included with Microsoft 365 E5 via a phased rollout from April 20 to June 30, 2026, providing 400 Security Compute Units per 1,000 users and core agentic features across Microsoft security products. Additional advanced capabilities may incur extra costs.
- TRv2 does not enforce restrictions on cross-cloud requests at the authentication plane, so access is permitted during authentication. However, TRv2 does block cross-cloud requests at the data plane. As a result, when using Windows Group Policy (GPO), users will be unable to access TRv2-enlightened resources across cloud boundaries.
Learn how to configure threat intelligence in Microsoft Entra Internet Access.
ai-usage: ai-assisted
ai-usage: ai-assisted
Use custom block pages to display organization-specific messaging internet access policies block users from accessing websites.
With the internet access profile, you can route traffic to the public internet, including traffic to SaaS apps. This traffic forwarding profile consists of a prepopulated list of regular expressions for fully qualified domain names (FQDNs) and IP addresses representing the public internet.
Learn about the Global Secure Access clients for Microsoft Entra Private Access and Microsoft Entra Internet Access.
ai-usage: ai-assisted
After a connector is enrolled, it establishes outbound TLS tunnels to the Private Access cloud infrastructure. These tunnels handle all data path traffic. In addition, the control plane channel uses minimal bandwidth to drive keep-alive heartbeat, health reporting, connector updates, and other functions.
Use the web category checker to find which web content category a URL belongs to via Microsoft Graph.
|Nudity | Sites that contain full or partial nudity that aren't necessarily overtly sexual in intent.|
> [!IMPORTANT]
|49152-65535 |UDP/TCP |Ephemeral ports |
1. Enter a name for the app.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) with the appropriate roles.
author: HULKsmashGithub
ai-usage: ai-assisted
Learn how to require known compliant network locations to connect to your secured resources with Conditional Access.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../identity/role-based-access-control/permissions-reference.md#conditional-access-administrator).
- A **Global Secure Access Administrator** role in Microsoft Entra ID.
Protect your enterprise generative AI apps from prompt injection attacks with Microsoft's AI Gateway prompt injection protection.

The proposed workaround for the above-mentioned scenario is as follows.