Tag

Microsoft Entra

All articles tagged with #microsoft entra

Entra Agent ID Flaw Lets Attackers Seize Privileged Service Principals
cybersecurity1 month ago

Entra Agent ID Flaw Lets Attackers Seize Privileged Service Principals

A critical flaw in Microsoft Entra’s Agent Identity Platform allowed users with the Agent ID Administrator role to take ownership of any service principal, generate new credentials, and impersonate high-privilege apps, enabling tenant-wide compromise; Microsoft patched the issue across cloud environments by April 2026. Security teams should identify and secure privileged service principals, using Azure CLI and the Microsoft Graph API to audit configurations and prevent abuse.

Entra passkeys enable phishing-resistant sign-ins on Windows
technology2 months ago

Entra passkeys enable phishing-resistant sign-ins on Windows

Microsoft is rolling out Entra passkeys on Windows to enable phishing-resistant, passwordless sign-in via Windows Hello. The opt-in public preview runs mid-March to late April 2026 for worldwide tenants (government-cloud timelines differ) and extends passwordless sign-in to unmanaged Windows devices. Passkeys are device-bound and per-account (no cross-device syncing), with multiple accounts able to coexist on one machine; each Entra account must register its own passkey. Admins must enable Passkeys (FIDO2) in Entra, create a Windows Hello profile with required AAGUIDs, and assign it to groups.

LinkedIn introduces free and easy job and identity verification.
technology3 years ago

LinkedIn introduces free and easy job and identity verification.

LinkedIn is partnering with CLEAR to offer identity verification features that allow users to confirm their name and employer. The platform is rolling out three ways for members to confirm their identity, including a free process that requires sharing a U.S phone number and government-issued ID. LinkedIn is also partnering with Microsoft Entra to allow some users to verify both their identity and employer at once. The verification field will appear on the user's LinkedIn profile once the process is complete, offering an extra layer of protection against fake accounts and scammers.