← Previous day

Next day →
Day in brief

Tenant Restrictions V2 cross-cloud behavior clarified; Entra security and Global Secure Access guidance refreshed

25 March was primarily a documentation-maintenance day: all 36 recorded changes were updates, with no new or removed items and no Message Center notices. The most consequential clarification concerns Tenant Restrictions V2: cross-cloud requests can be permitted at authentication while being blocked at the data plane, with a specific Windows Group Policy consequence. Other substantive updates provide app-credential escalation guidance for the Privileged Authentication Administrator role, passkey deployment guidance, compliant-network Conditional Access guidance, and documentation for Global Secure Access prompt-injection protection, which is explicitly marked preview. The evidence does not establish a new launch, general-availability milestone, or retirement.

  • The updated External ID guidance states that TRv2 does not enforce cross-cloud restrictions at the authentication plane, so authentication is permitted, but blocks cross-cloud requests at the data plane. It specifically says Windows Group Policy users cannot access TRv2-enlightened resources across cloud boundaries. This is a documentation clarification of compatibility behavior, not evidence that a new control launched on 25 March.

  • The updated Entra ID role guidance notes that Application Registration and Enterprise Application owners can manage credentials for apps they own, and those apps may have privileged permissions. It describes how updating credentials can allow an Authentication Administrator to assume an application-owner identity and then a privileged application identity. This is security and permission-boundary guidance; the record does not say that the role permissions changed.

  • The updated article explains how to require known compliant network locations for connections to secured resources through Conditional Access. It is configuration guidance for Global Secure Access; the supplied item does not establish a new availability milestone or a change to existing tenant behavior.

  • The updated Entra ID authentication article describes using the Conditional Access Optimization Agent to safely deploy a passkey program and roll out phishing-resistant authentication methods. It is rollout guidance; no new capability announcement or preview-to-general-availability transition is evidenced.

  • The updated Global Secure Access security article describes Microsoft's AI Gateway prompt-injection protection for enterprise generative AI apps. The title explicitly labels the capability as preview, so this supports evaluation and configuration guidance only—not a general-availability claim.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

37 updates

5
2

Helpdesk Administrator

Updated

>- Application Registration and Enterprise Application owners, who can manage credentials of apps they own. Those apps may have privileged permissions in Microsoft Entra ID and elsewhere not granted to Helpdesk Administrators. Through this path a Helpdesk Administrator may be able to assume the identity of an application owner and then further assume the identity of a privileged application by updating the credentials for the application.

User Administrator

Updated

>- Application Registration and Enterprise Application owners, who can manage credentials of apps they own. Those apps may have privileged permissions in Microsoft Entra ID and elsewhere not granted to User Administrators. Through this path a User Administrator may be able to assume the identity of an application owner and then further assume the identity of a privileged application by updating the credentials for the application.

1

Privileged Authentication Administrator

Updated

>* Application Registration and Enterprise Application owners, who can manage credentials of apps they own. Those apps may have privileged permissions in Microsoft Entra ID and elsewhere not granted to Authentication Administrators. Through this path an Authentication Administrator can assume the identity of an application owner and then further assume the identity of a privileged application by updating the credentials for the application.

1
1
2

Security Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role have permissions to manage security-related features in the Microsoft Defender portal, Microsoft Entra ID Protection, Microsoft Entra Authentication, Azure Information Protection, and Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).

Security Reader

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role have global read-only access on security-related feature, including all information in Microsoft Defender portal, Microsoft Entra ID Protection, Privileged Identity Management, and the ability to read Microsoft Entra sign-in reports and audit logs, and in Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).

1

Security Operator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role can manage alerts and have global read-only access on security-related features, including all information in Microsoft Defender portal, Microsoft Entra ID Protection, Privileged Identity Management, and Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).

1
1

Tenant Restrictions V2

Updated

- TRv2 does not enforce restrictions on cross-cloud requests at the authentication plane, so access is permitted during authentication. However, TRv2 does block cross-cloud requests at the data plane. As a result, when using Windows Group Policy (GPO), users will be unable to access TRv2-enlightened resources across cloud boundaries.

4
3

Traffic Forwarding

Updated

With the internet access profile, you can route traffic to the public internet, including traffic to SaaS apps. This traffic forwarding profile consists of a prepopulated list of regular expressions for fully qualified domain names (FQDNs) and IP addresses representing the public internet.

Clients

Updated

Learn about the Global Secure Access clients for Microsoft Entra Private Access and Microsoft Entra Internet Access.

1

Connectors

Updated

After a connector is enrolled, it establishes outbound TLS tunnels to the Private Access cloud infrastructure. These tunnels handle all data path traffic. In addition, the control plane channel uses minimal bandwidth to drive keep-alive heartbeat, health reporting, connector updates, and other functions.

8

Configure Quick Access

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) with the appropriate roles.

2

Target Resource Microsoft Profile

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../identity/role-based-access-control/permissions-reference.md#conditional-access-administrator).

2
2

Troubleshoot Connectors

Updated

![Screenshot showing an example of the expected final configuration file.](media/troubleshoot-connectors/connector-logging-config-final-example.png)

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…