< ciso
brief />
Tag Banner

All news with #azure entra id tag

44 articles

Microsoft patches critical Entra ID deserialization flaw

๐Ÿ” Microsoft patched a maximum-severity vulnerability in Entra ID that was exploited in attacks, tracked as CVE-2026-69836. Discovered by Microsoft engineer Robert Fitzpatrick, the flaw allowed unauthenticated actors to achieve code execution via deserialization of untrusted data. Microsoft states the issue is fully mitigated and no user action is required, and said exploit code is not publicly available. The company provided limited additional details on the incidents.
read more โ†’

Research reveals practical weaknesses in passkey deployments

๐Ÿ” Three research teams disclosed attacks that bypass passkey protections without breaking FIDO cryptography. SpecterOps showed Windows-exposed signatures chained through Microsoft Entra ID to impersonate privileged users. Unit 42 demonstrated methods to recover synced passkey private keys in Chrome's Google Password Manager, and Dirk-jan Mollema showed malware in a signed-in Windows session could use a Windows Hello for Business key without a fresh PIN. Vendors issued patches and mitigations with differing impacts.
read more โ†’

SOC playbook for OAuth client ID spoofing detection

๐Ÿ”Ž This article explains how OAuth client ID spoofing can evade per-application volume thresholds by rotating or fabricating the client ID field, turning valid credential checks into stealthy attacks. It outlines key Entra ID error codes (AADSTS50034, AADSTS50126, AADSTS700016) and shows why AADSTS700016 paired with many distinct client IDs is a critical triage signal. The piece describes two large campaigns that produced millions of spoofed IDs, provides a Kusto detection query to correlate cardinality and error sequences, and recommends a short response runbook (reset, revoke, review) plus long-term mitigation by retiring ROPC.
read more โ†’

Malware can abuse Windows Hello to gain cloud access

๐Ÿ”’ Entra ID researcher Dirk-jan Mollema demonstrated that malware running in a signed-in Windows session can silently invoke the victim's Windows Hello for Business key to authenticate to Microsoft Entra ID. The technique lets an attacker obtain tokens, register devices, and gain long-term cloud access without extracting private keys, recovering PINs, or prompting biometrics on TPM-backed systems. Mollema published PoC scripts and recommends hunting for Hello sign-ins with empty device IDs while noting potential false positives.
read more โ†’

Microsoft Security: July 2026 innovations and updates

๐Ÿ”’ Microsoft announced new AI-native security capabilities across Defender, Entra, Purview, and Intune to help organizations secure AI environments, accelerate SecOps, and protect data and identities. Highlights include Project Perception, expanded Defender protections like prompt injection blocking, tenant governance and passkey defaults in Entra, Purview network-level DLP for shadow AI apps, and Intune Suite inclusion in Microsoft 365 E5 to strengthen endpoint management.
read more โ†’

AWS Managed Microsoft AD supports in-place upgrade

๐Ÿ”” AWS Directory Service now lets you upgrade an AWS Managed Microsoft AD directory from Standard Edition to Enterprise Edition directly via the AWS Management Console, AWS CLI, or API. The upgrade preserves trust relationships, application integrations, and group policies without requiring DNS changes or workload re-joins. Standard supports up to 5,000 objects while Enterprise supports up to 500,000 objects for larger deployments. This capability is available in all Regions where AWS Directory Service is offered.
read more โ†’

Microsoft makes passkeys default for Entra ID

๐Ÿ”’ Microsoft Entra ID will begin rolling out passkeys as the default phishing-resistant authentication method starting September 1, 2026. Users currently using SMS or voice for MFA will be auto-enabled for passkeys and prompted to register on their next sign-in. Microsoft will retire native SMS and voice delivery on February 1, 2027, after which telecom partners via the Microsoft Security Store will be required for those methods.
read more โ†’

Novel OAuth Client ID Spoofing Targets Cloud

๐Ÿ”’ Cyber-attackers are increasingly using OAuth client ID spoofing to access cloud environments by abusing Microsoft Entra ID (formerly Azure AD). Proofpoint researchers found threat actors issuing ROPC token requests to the OAuth 2.0 endpoint, producing AADSTS error codes that reveal valid usernames and authentication controls. The technique produces blank or spoofed application IDs in Entra signโ€‘in logs, making detection difficult and enabling large-scale campaigns targeting millions of accounts.
read more โ†’

Vishing campaign abuses Entra passkey enrollment

๐Ÿ”” A threat actor is using voice-based fake security calls to trick Microsoft 365 users into enrolling a malicious Entra passkey. The attacker directs victims to realistic phishing pages that mimic the Microsoft enrollment flow and uses an operator-controlled PHP kit to capture credentials and MFA responses in real time. Okta attributes the campaign to O-UNC-066, linked to the extortion group Pink, which targets multiple industries and quickly exfiltrates data after account takeover.
read more โ†’

Microsoft switches Windows backup to default-on for orgs

๐Ÿ›ก๏ธ Microsoft will enable the Windows settings backup and restore tool by default on Microsoft Entra-joined and Entra hybrid-joined enterprise devices when they upgrade to Windows 11 version 26H2. The feature, introduced as opt-in at Ignite 2024 and GA in August 2025, previously required admins to turn it on after installing the September 2025 cumulative update. Default-on applies only to eligible devices outside DMA-regulated regions and not in sovereign cloud environments, and explicit admin policies via Intune or Group Policy still take precedence. Restore remains disabled by default and requires explicit admin configuration.
read more โ†’

AI-Driven Identity Security: Microsoft Entra Updates

๐Ÿ”’ AI is accelerating cyberattacks, increasing speed and scale across the attack chain while identity remains a primary entry point. Microsoft highlights integrated visibility and response through Microsoft Entra and Microsoft Defender, including a unified identity risk score and an updated Entra ID Protection experience. New features aim to reduce fragmentation, enable least-privilege response roles, and automate policy optimization to help teams prevent, detect, and respond faster.
read more โ†’

Amazon S3 Access Grants Arrive in Germany Region

๐Ÿ›ˆ Amazon S3 Access Grants are now available in the AWS European Sovereign Cloud (Germany) Region. The feature maps identities from directories like Microsoft Entra ID and AWS IAM principals to S3 datasets, enabling automated, scalable data permission management. This simplifies granting S3 access to end users based on corporate identities. Check the AWS Region Table for full regional availability and refer to the product page for details.
read more โ†’

FBI alert: Kali365 OAuth phishing risks rise

๐Ÿ”’ The FBI warns of phishing campaigns using Kali365 to harvest Microsoft 365 OAuth access tokens and bypass multi-factor authentication. Attackers trick users into entering a code on a legitimate Microsoft page, which instead authorizes the attackerโ€™s device to access the victimโ€™s account. The FBI advises IT teams to deploy conditional access policies and block authentication transfer to reduce exposure.
read more โ†’

ROADtools misuse in cloud identity attacks

๐Ÿ” ROADtools is an open-source Python toolkit for red teams and researchers that attackers have repurposed to target Microsoft Entra ID. It enumerates tenants, registers devices, and acquires or manipulates OAuth2/OpenID Connect tokens while using legitimate Microsoft APIs and configurable request attributes to evade detection. Nation-state actors have used ROADtools for discovery, persistence and defense evasion, and Palo Alto Networks outlines detection queries, mitigation recommendations and protections available via Cortex Cloud, Cortex XDR and Unit 42 services.
read more โ†’

Microsoft Security updates and new capabilities โ€” May 2026

๐Ÿ”’ Microsoft announced a set of security enhancements designed to protect agents, data, and identities as organizations scale AI. Highlights include the general availability of Microsoft Purview DSPM, expanded investigation capabilities with OCR and custom examinations, and a new Entra ID Account recovery flow for restoring organizational access. Public preview of Windows 365 for Agents and integration with Microsoft Agent 365 aim to govern and secure agent workloads in managed Cloud PCs.
read more โ†’

Azure Files Entra-Only Identities Advance Cloud Security

๐Ÿ” Microsoft has reached general availability for Entra-Only identities for Azure Files SMB, enabling native Microsoft Entra ID authentication for SMB file shares using cloud-only identities. This eliminates the need for on-premises Active Directory, Entra Connect, or managed domain controllers, simplifying architecture and reducing operational overhead. Entra acts as the Kerberos Key Distribution Center (KDC), issuing Kerberos tickets while preserving SMB protocol compatibility, and supports VDI scenarios with FSLogix, Managed Identities, macOS clients, and NTFS ACL editing. The capability is supported across HDD and SSD shares, available at no extra cost, and is being extended to sovereign cloud regions.
read more โ†’

ABB OPTIMAX Azure AD SSO Authentication Bypass Vulnerability

๐Ÿ”’ A high-severity authentication bypass (CVE-2025-14510, CVSS 8.1) affects ABB Ability OPTIMAX systems that use Azure Active Directory Single Sign-On, potentially permitting an attacker to bypass user authentication remotely. Affected builds include all 6.1 and 6.2 releases and 6.3/6.4 builds prior to 6.3.1-251120 and 6.4.1-251120. ABB has published fixes (for example, 6.3.1-251120); administrators should follow the ABB PSIRT advisory, apply available updates, and implement network segmentation and secure remote access controls while performing impact analysis prior to changes.
read more โ†’

Eight Best Practices for CISOs Conducting Risk Reviews

๐Ÿ“‹ This blog by Rico Mariani outlines eight practical best practices for CISOs conducting risk reviews, focusing on identifying assets, applications, and access controls to shape review scope and priorities. It emphasizes good quality authentication (tokens and issuers like Microsoft Entra), robust authorization, network isolation, detection, and auditing to enable proactive security. The post also highlights commonly overlooked areas such as backups, support, and development systems to ensure comprehensive risk coverage.
read more โ†’

AWS Transfer Family Terraform Module Adds Okta and Entra

๐Ÿ”ง AWS updated the Transfer Family Terraform module to include end-to-end examples demonstrating integration with Okta and Microsoft Entra ID as custom identity providers. Built on the open-source Custom IdP solution and example repositories, the module automates deployment of Transfer Family endpoints while leveraging existing identity infrastructure. Included security controlsโ€”MFA, audit logging, and per-user IP allowlistingโ€”help organizations meet operational and compliance requirements; consult the Terraform Registry and the Transfer Family Custom IdP user guide for implementation details and regional availability.
read more โ†’

Access Control with IAM Identity Center Session Tags

๐Ÿ” AWS IAM Identity Center centralizes workforce access and can consume session tags from external SAML providers such as Microsoft Entra ID to enable fineโ€‘grained, attributeโ€‘based access control (ABAC) across multiple AWS accounts. By mapping directory group attributes to session tags, administrators can dynamically apply permissions and runtime configurationโ€”examples include selecting an AWS Glue usage profile or configuring Systems Manager Session Manager runโ€‘as behavior. The post walks through SAML and SCIM setup, creating a custom permission set, mapping claims (for example AccessControl:glue:UsageProfile), testing job creation in the Glue console, and validating session tags via CloudTrail AssumeRoleWithSAML events.
read more โ†’