Daniel 5/6/2026

App Instance Lock enabled by default for new applications

Read Original

This article details Microsoft's upcoming change to Microsoft Entra ID, where App Instance Lock will be enabled by default for all newly created applications starting June 2026. The feature aims to harden the identity perimeter by preventing sensitive properties, such as service principal credentials, from being modified outside the application's home tenant. It explains the security risks of unauthorized credential injection and privilege escalation, the deployment timeline, and the technical impact on administrators and developers managing multi-tenant environments or automation scripts. Existing applications remain unaffected, but new workflows may require explicitly disabling the lock to allow cross-tenant updates.

App Instance Lock enabled by default for new applications

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week

No top articles yet