Entra Patched CAP Bypasses, But You Might Have to Opt-In

Thanks to this fantastic post by Dirk-Jan Mollema, we know about how a lot of Entra OAuth scopes were secret for Microsoft Apps, and how Conditional Access Policies with resources exclusions could be bypassed.

The new enforcement policy fixing this went into effect on June 15, but admins may have to opt-in from legacy policies. This is explained in detail here:

Finally, as a gift to Azure shops around the world, Dirk-Jan and Fabian Bader build EntraScopes, a mapping of first-party Entra App IDs, scopes, and CA Bypasses.

The site pulls from big JSON files on GitHub, if you were interested in automating lookups for some reason.