< ciso
brief />
Tag Banner

All news with #azure entra id tag

50 articles

Microsoft enables Windows settings backup by default

πŸ› οΈ Microsoft has enabled the Windows settings backup and restore feature by default for enterprise devices that are Microsoft Entra-joined or hybrid-joined and upgraded to Windows 11 26H2. The tool, originally introduced as an opt-in feature and later made generally available, backs up users' Windows settings and Microsoft Store app lists after device resets, replacements, upgrades, or reimages. The default-on policy applies only where admins have not explicitly configured the setting and excludes devices in DMA-regulated regions, sovereign clouds, or restricted environments. Restore remains admin-controlled and can be managed or disabled via Intune or Group Policy.
read more β†’

Microsoft to enforce CSP for Entra ID sign-ins

πŸ”’ Microsoft will begin enforcing stricter Content Security Policy (CSP) protections for Entra ID sign-ins starting mid-October 2026, allowing only scripts from trusted Microsoft CDN domains. The rollout will complete by late October 2026 and aims to block external script injection and cross-site scripting risks during browser-based authentication. Enterprise customers are urged to remove or test browser extensions and code-injection tools to avoid sign-in disruptions. MSAL and API-based flows are not affected because CSP applies only to browser-based sign-ins.
read more β†’

Rogue external MFA providers can steal passwords

πŸ”’ Security researchers at Varonis Threat Labs have demonstrated an attack, dubbed TrustSink, that lets an attacker with a highly privileged Microsoft Entra account register a rogue external MFA provider to capture users' passwords during legitimate logins. The malicious provider displays a convincing copy of Microsoft's password prompt during the MFA step, captures credentials in plaintext, then returns a valid signed token so the login completes normally. The technique requires post-compromise access to Global Administrator or Authentication Policy Administrator privileges and can persist across password resets until the rogue provider is removed.
read more β†’

Microsoft urges Entra ID migration to passkeys

πŸ” Microsoft reminded administrators to migrate Entra ID users to phishing-resistant authentication methods, such as passkeys, ahead of the retirement of SMS first-factor sign-ins in February 2027. Admins can also use QR code authentication, FIDO2 security keys, or other Entra ID-supported methods. The retirement affects workforce tenant authentication and not Azure AD B2C or Entra External ID scenarios. Microsoft provided guidance and tools, including a PowerShell scanner, to help identify impacted users.
read more β†’

GhostCode device-code phishing targets Microsoft 365

πŸ”’ Researchers at eSentire discovered GhostCode, a phishing kit that abuses Microsoft’s OAuth 2.0 device authorization flow to trick users into granting attacker-controlled devices access to Microsoft 365 accounts. Victims are lured via procurement-themed social engineering to enter device codes on legitimate Microsoft sign-in pages, completing MFA for the attacker’s session. Stolen tokens enabled automated device registration, Intune enrollment and acquisition of Primary Refresh Tokens (PRTs), persisting access even after token revocation. eSentire recommends restricting device-code flow via Conditional Access, monitoring device registrations and Python-based user agents, and auditing Entra ID for suspicious device patterns.
read more β†’

Amazon Redshift adds IAM Identity Center via EVR

πŸ”’ Amazon Redshift now supports AWS IAM Identity Center authentication for provisioned clusters and serverless workgroups configured with enhanced VPC routing (EVR). This enables single sign-on using corporate credentials while keeping traffic inside your Amazon VPC and on the AWS network, meeting data residency and network-isolation requirements. Redshift validates and exchanges IAM Identity Center tokens over AWS PrivateLink interface VPC endpoints inside the VPC and supports multi-Region Identity Center replication.
read more β†’

Microsoft patches critical Entra ID deserialization flaw

πŸ” Microsoft patched a maximum-severity vulnerability in Entra ID that was exploited in attacks, tracked as CVE-2026-69836. Discovered by Microsoft engineer Robert Fitzpatrick, the flaw allowed unauthenticated actors to achieve code execution via deserialization of untrusted data. Microsoft states the issue is fully mitigated and no user action is required, and said exploit code is not publicly available. The company provided limited additional details on the incidents.
read more β†’

Research reveals practical weaknesses in passkey deployments

πŸ” Three research teams disclosed attacks that bypass passkey protections without breaking FIDO cryptography. SpecterOps showed Windows-exposed signatures chained through Microsoft Entra ID to impersonate privileged users. Unit 42 demonstrated methods to recover synced passkey private keys in Chrome's Google Password Manager, and Dirk-jan Mollema showed malware in a signed-in Windows session could use a Windows Hello for Business key without a fresh PIN. Vendors issued patches and mitigations with differing impacts.
read more β†’

SOC playbook for OAuth client ID spoofing detection

πŸ”Ž This article explains how OAuth client ID spoofing can evade per-application volume thresholds by rotating or fabricating the client ID field, turning valid credential checks into stealthy attacks. It outlines key Entra ID error codes (AADSTS50034, AADSTS50126, AADSTS700016) and shows why AADSTS700016 paired with many distinct client IDs is a critical triage signal. The piece describes two large campaigns that produced millions of spoofed IDs, provides a Kusto detection query to correlate cardinality and error sequences, and recommends a short response runbook (reset, revoke, review) plus long-term mitigation by retiring ROPC.
read more β†’

Malware can abuse Windows Hello to gain cloud access

πŸ”’ Entra ID researcher Dirk-jan Mollema demonstrated that malware running in a signed-in Windows session can silently invoke the victim's Windows Hello for Business key to authenticate to Microsoft Entra ID. The technique lets an attacker obtain tokens, register devices, and gain long-term cloud access without extracting private keys, recovering PINs, or prompting biometrics on TPM-backed systems. Mollema published PoC scripts and recommends hunting for Hello sign-ins with empty device IDs while noting potential false positives.
read more β†’

Microsoft Security: July 2026 innovations and updates

πŸ”’ Microsoft announced new AI-native security capabilities across Defender, Entra, Purview, and Intune to help organizations secure AI environments, accelerate SecOps, and protect data and identities. Highlights include Project Perception, expanded Defender protections like prompt injection blocking, tenant governance and passkey defaults in Entra, Purview network-level DLP for shadow AI apps, and Intune Suite inclusion in Microsoft 365 E5 to strengthen endpoint management.
read more β†’

AWS Managed Microsoft AD supports in-place upgrade

πŸ”” AWS Directory Service now lets you upgrade an AWS Managed Microsoft AD directory from Standard Edition to Enterprise Edition directly via the AWS Management Console, AWS CLI, or API. The upgrade preserves trust relationships, application integrations, and group policies without requiring DNS changes or workload re-joins. Standard supports up to 5,000 objects while Enterprise supports up to 500,000 objects for larger deployments. This capability is available in all Regions where AWS Directory Service is offered.
read more β†’

Microsoft makes passkeys default for Entra ID

πŸ”’ Microsoft Entra ID will begin rolling out passkeys as the default phishing-resistant authentication method starting September 1, 2026. Users currently using SMS or voice for MFA will be auto-enabled for passkeys and prompted to register on their next sign-in. Microsoft will retire native SMS and voice delivery on February 1, 2027, after which telecom partners via the Microsoft Security Store will be required for those methods.
read more β†’

Novel OAuth Client ID Spoofing Targets Cloud

πŸ”’ Cyber-attackers are increasingly using OAuth client ID spoofing to access cloud environments by abusing Microsoft Entra ID (formerly Azure AD). Proofpoint researchers found threat actors issuing ROPC token requests to the OAuth 2.0 endpoint, producing AADSTS error codes that reveal valid usernames and authentication controls. The technique produces blank or spoofed application IDs in Entra sign‑in logs, making detection difficult and enabling large-scale campaigns targeting millions of accounts.
read more β†’

Vishing campaign abuses Entra passkey enrollment

πŸ”” A threat actor is using voice-based fake security calls to trick Microsoft 365 users into enrolling a malicious Entra passkey. The attacker directs victims to realistic phishing pages that mimic the Microsoft enrollment flow and uses an operator-controlled PHP kit to capture credentials and MFA responses in real time. Okta attributes the campaign to O-UNC-066, linked to the extortion group Pink, which targets multiple industries and quickly exfiltrates data after account takeover.
read more β†’

Microsoft switches Windows backup to default-on for orgs

πŸ›‘οΈ Microsoft will enable the Windows settings backup and restore tool by default on Microsoft Entra-joined and Entra hybrid-joined enterprise devices when they upgrade to Windows 11 version 26H2. The feature, introduced as opt-in at Ignite 2024 and GA in August 2025, previously required admins to turn it on after installing the September 2025 cumulative update. Default-on applies only to eligible devices outside DMA-regulated regions and not in sovereign cloud environments, and explicit admin policies via Intune or Group Policy still take precedence. Restore remains disabled by default and requires explicit admin configuration.
read more β†’

AI-Driven Identity Security: Microsoft Entra Updates

πŸ”’ AI is accelerating cyberattacks, increasing speed and scale across the attack chain while identity remains a primary entry point. Microsoft highlights integrated visibility and response through Microsoft Entra and Microsoft Defender, including a unified identity risk score and an updated Entra ID Protection experience. New features aim to reduce fragmentation, enable least-privilege response roles, and automate policy optimization to help teams prevent, detect, and respond faster.
read more β†’

Amazon S3 Access Grants Arrive in Germany Region

πŸ›ˆ Amazon S3 Access Grants are now available in the AWS European Sovereign Cloud (Germany) Region. The feature maps identities from directories like Microsoft Entra ID and AWS IAM principals to S3 datasets, enabling automated, scalable data permission management. This simplifies granting S3 access to end users based on corporate identities. Check the AWS Region Table for full regional availability and refer to the product page for details.
read more β†’

FBI alert: Kali365 OAuth phishing risks rise

πŸ”’ The FBI warns of phishing campaigns using Kali365 to harvest Microsoft 365 OAuth access tokens and bypass multi-factor authentication. Attackers trick users into entering a code on a legitimate Microsoft page, which instead authorizes the attacker’s device to access the victim’s account. The FBI advises IT teams to deploy conditional access policies and block authentication transfer to reduce exposure.
read more β†’

ROADtools misuse in cloud identity attacks

πŸ” ROADtools is an open-source Python toolkit for red teams and researchers that attackers have repurposed to target Microsoft Entra ID. It enumerates tenants, registers devices, and acquires or manipulates OAuth2/OpenID Connect tokens while using legitimate Microsoft APIs and configurable request attributes to evade detection. Nation-state actors have used ROADtools for discovery, persistence and defense evasion, and Palo Alto Networks outlines detection queries, mitigation recommendations and protections available via Cortex Cloud, Cortex XDR and Unit 42 services.
read more β†’