IAMinerva
HomeBlogAbout
m3M365 NewscoMicrosoft CopilotteMicrosoft TeamsshSharePoint & OneDriveinIntune & SecurityexExchange & OutlookpoPower PlatformazAzure & Entra IDtuTutorials & GuidesevEvents & ConferencesseSecuritywiWindows
IAMinerva

Professional blog dedicated to the Microsoft 365 ecosystem.

Quick links

HomeBlogAboutNewsletter

Stay informed

Get the latest Microsoft 365 news delivered straight to your inbox.

© 2026 IAMinerva. All rights reserved.

Built withNext.js&Tailwind
Quatre portes dorées avec des icônes de profils utilisateurs se connectant.
BlogM365 NewsBaseline Scopes in Entra ID and Conditional Access
M365 News#Entra ID#Conditional Access#Microsoft 365

Baseline Scopes in Entra ID and Conditional Access

Baseline scopes now handled by conditional access policies in Entra ID. Prepare your tenant now to avoid interruptions.

Houssem MAKHLOUF
June 26, 2026
3 min read

TL;DR par Minerva

généré par IA

Baseline scopes now handled by conditional access policies in Entra ID. Prepare your tenant now to avoid interruptions.

Introduction

Microsoft Entra ID is adjusting the management of baseline scopes (baseline scopes), directly affecting how conditional access policies function. Starting in June 2026, applications requesting these scopes will have their access evaluated through these policies. This means uniform processing for all resources, regardless of the scope requested.

Baseline scopes include OpenID Connect (OIDC) permissions and directory permissions such as openid, email, profile, User.Read, People.Read, and many others considered low-risk.

Why this change is important

Baseline scopes and their role

Baseline scopes group together low-risk permissions, widely used for signing into Entra ID via third-party applications. Before this change, when these scopes were requested by an application, conditional access policies with resource exclusions were not applied.

Now, Microsoft ensures that policies are uniformly applicable, even for applications requesting only baseline scopes. This includes popular scenarios such as using Visual Studio Code, often limited to the User.Read permission.

Impact for administrators

Microsoft indicates that the majority of customers will require no adjustments, as applications typically request broader permissions, such as those related to Microsoft Graph. However, administrators should be vigilant about:

  • Applications relying solely on baseline scopes.
  • Scenarios where these applications cannot meet policy requirements (for example, mandatory MFA).

Use the principal services analysis report to identify applications in your tenant that could be affected by this change.

Configuration in Entra ID

New page for baseline scopes configuration

Microsoft now offers a dedicated page in the Entra administration center, accessible via a specific link. This new tool helps administrators:

  • Configure baseline scopes application policies.
  • Enable the recommended "Enforcement" option for enhanced security.
  • Monitor applications that might fail after this change.

Entra ID Permissions

Steps to prepare your tenant

Run analyses via Entra ID or use a third-party report to list the permissions requested by each application.

Access the Entra administration center page via the dedicated link: https://aka.ms/BaselineScopesSettingsUX.

In the baseline scopes management section, enable the "Enforcement" option to ensure application compliance.

Pending deployment

Progressive deployment has been underway since June 15, 2026 and should be fully completed by August 2026. Tenants will receive:

  • A first notification two weeks before the new rules are applied.
  • A final confirmation once deployment is complete.

Microsoft uses telemetry to detect if your tenant is affected and sends messages via the Entra ID notification center. In the event that no notification is received, this indicates that your policies are not affected.

Rigorous monitoring of conditional access logs is essential to avoid unexpected interruptions.

Conclusion

This change marks a key step in harmonizing security across Microsoft 365. Entra ID now ensures universal application of conditional access policies, strengthening application security and their interactions with tenants. Prepare your environment now to ensure a smooth transition.

Baseline scopes configuration

Share:
HM

Houssem MAKHLOUF

Microsoft 365 enthusiast & IT professional.

Previous article

Add Agendas and Meeting Notes to Teams with Loop

Jun 25, 2026
Next article

Windows 11 Updates from July 14: Essential New Features

Jun 26, 2026

Related articles

Cadenas stylisé avec des éléments graphiques abstraits et du texte sur la sécurité.securite

New Microsoft 365 Security Adoption Model

Discover the Microsoft 365 security adoption guide based on Zero Trust principles: modular approaches and modern strategies.

Jun 29, 20264 min
Main d'homme interagissant avec une interface numérique lumineuse et dynamique.copilot

Agents: Transforming Work with AI in Microsoft 365

Intelligent agents are redefining work in Microsoft 365 by automating complex and extended tasks. Discover their impact and adoption.

Jun 28, 20263 min
Exécution de scripts PowerShell pour auditer des applications AI et gérer leurs enregistrements.copilot

Audit and Manage AI Applications with PowerShell

Audit unauthorized AI applications in Entra ID with PowerShell and Microsoft Graph to strengthen control and security.

Jun 28, 20264 min