Tag

Entra Id

All articles tagged with #entra id

Entra ID RCE Flaw Prompts Cloud Security Scrutiny as Patch Goes Server‑Side
cyber-security6 days ago

Entra ID RCE Flaw Prompts Cloud Security Scrutiny as Patch Goes Server‑Side

Microsoft disclosed a critical remote code execution vulnerability in Entra ID (CVE-2026-69836) caused by deserialization of untrusted data (CWE-502) that could allow unauthenticated attackers to run arbitrary code on the identity service. Microsoft has deployed a server-side patch with no customer action required; initial reports of in‑the‑wild exploitation are now clarified as not currently active. Security teams should still review Entra ID sign-in logs, tighten conditional access, and monitor privileged roles across the Microsoft ecosystem.

Microsoft patches critical flaws across Entra ID, Arc, and Exchange Online that could enable remote code execution
security6 days ago

Microsoft patches critical flaws across Entra ID, Arc, and Exchange Online that could enable remote code execution

Microsoft has patched multiple maximum-severity vulnerabilities in Entra ID, Azure Arc, and Exchange Online that could let attackers with no privileges execute code remotely and escalate privileges. Key flaws include CVE-2026-69836 in Entra ID (deserialization of untrusted data), CVE-2026-65816 and CVE-2026-69555 in Azure Arc, CVE-2026-65801 in Exchange Online, and CVE-2026-65770 affecting an Azure Managed Instance for Apache Cassandra. Patches are in place and no action is required, with exploit code not publicly available. An August update notes CVE-2026-69836 was initially misflagged as exploited in the wild.

Entra ID Makes Passkeys the Default, Ditching SMS/Voice MFA by 2027
technology1 month ago

Entra ID Makes Passkeys the Default, Ditching SMS/Voice MFA by 2027

Microsoft will make passkeys the default authentication method for Entra ID starting September 2026, auto-enabling them for users currently on SMS/voice MFA; SMS/voice authentication will be retired across all tenants on February 1, 2027. Users already using passkeys, Windows Hello for Business, FIDO2 keys, or other phishing-resistant methods can continue. After rollout, organizations should ensure all users adopt phishing-resistant methods to avoid sign-in disruptions, with third-party telecom providers available via the Security Store if needed. Microsoft cites AI-enabled phishing risks and says passkeys reduce credential theft by replacing phishable factors.

Microsoft's Entra ID: The New Face of Azure AD and Security Service Edge
technology3 years ago

Microsoft's Entra ID: The New Face of Azure AD and Security Service Edge

Microsoft is rebranding Azure Active Directory (AD) to Entra ID as part of its efforts to simplify product naming and unify its product family. The capabilities, licensing plans, sign-in URLs, and APIs will remain unchanged, and existing deployments, configurations, and integrations will continue to work as before. The name change will be completed by the end of 2023. Additionally, the standalone license names for Azure AD Free, Azure AD Premium P1, Azure AD Premium P2, and Azure AD External Identities will also be changed to Microsoft Entra ID Free, Microsoft Entra ID P1, Microsoft Entra ID P2, and Microsoft Entra External ID, respectively. This rebranding marks a significant shift as Microsoft moves forward with Entra as its overall cloud offering for identity, secure access, and network access, cutting ties with its past.