You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
identity and access
About this tag
Discussions tagged with identity and access on WindowsForum.com cover the evolving security challenges around authentication, authorization, and identity governance in Microsoft 365 and Azure environments. Topics include device-code phishing attacks that bypass MFA, malicious logins from trusted regions, and the need to treat successful logins as investigative starting points. The tag also explores identity controls for AI agents in Copilot Studio, red-teaming identity layers in AI stacks, and how Azure Front Door outages exposed identity concentration risks. Recurring themes include hardening identity plumbing, moving beyond MFA as a sole defense, and integrating identity into broader enterprise security strategies.
Silverfort on June 8, 2026 launched an early-access integration that applies real-time identity and access controls to AI agents built in Microsoft Copilot Studio, evaluating each agent action before it executes across enterprise systems. The announcement is narrow in product terms but broad in...
ai agent governance
ai agent security
copilot studio
identityandaccessidentityandaccess management
identity governance
microsoft copilot studio
microsoft entra id
runtime authorization
runtime enforcement
runtime identity
Barracuda reported in late May 2026 that malicious Microsoft 365 logins from traditionally low-risk countries, including the United States and United Kingdom, rose by about 25 percent in April, as attackers used legitimate credentials and trusted-looking infrastructure to avoid obvious...
Microsoft is urging security teams to red-team AI systems across the entire application stack, not just the model, with Microsoft red teaming executive Craig Nelson emphasizing data connections, backend automation, credentials, and logging in a recent Microsoft Inside Track security video. The...
The FBI issued a May 21, 2026 public warning that a phishing-as-a-service platform called Kali365 is targeting Microsoft 365 accounts by abusing device-code authentication to capture OAuth tokens and bypass multi-factor authentication. That makes this less a story about one new phishing kit than...
The conversations at Microsoft Security Summit Days make one thing unmistakably clear: future-proofing enterprise security is no longer a checklist—it's a strategic operating model that must knit people, data, identity, tooling, and governance into a single, resilient fabric. Microsoft’s...
A sudden, global disruption to Microsoft’s cloud fabric late on October 29 laid bare a fragile dependency at the heart of many modern services: an inadvertent configuration change to Azure Front Door (AFD) produced widespread latency, authentication failures and portal downtime that—while...
Microsoft’s cloud backbone began to stabilize hours after a global outage on October 29 that left Microsoft 365, the Azure Portal, gaming services and dozens of customer websites intermittently unreachable — an incident engineers traced to an inadvertent configuration change in Azure Front Door...
Microsoft’s cloud backbone faltered on October 29, 2025, when a configuration error in Azure Front Door — Microsoft’s global edge and routing fabric — precipitated a broad Microsoft Azure outage that knocked Xbox Live, Minecraft authentication, Microsoft 365 admin portals and a raft of customer...
BlinkOps’ announced integration with Microsoft Sentinel brings a new class of agentic security automation into the Azure ecosystem — available today through the Azure Marketplace and supported by prebuilt content in the Sentinel Content Hub — and that combination has immediate operational...
Microsoft has pushed a significant upgrade to Microsoft Sentinel’s User and Entity Behavior Analytics (UEBA), embedding AI-driven behavioral detection, broader cross‑cloud data ingestion, and dynamic baselining that together aim to surface subtle account compromise and insider risk while...
ai-driven
anomaly detection
aws
behavioral analytics
cloud security
cross-cloud
data lake
defender for endpoint
gcp
identityandaccess
incident response
microsoft sentinel
multi-cloud
okta
service principal
siem
soc
threat detection
ueba
xdr
A high‑risk elevation‑of‑privilege vulnerability affecting Microsoft Azure Arc has been disclosed and patched — but the public tracking and identifier details are messy, and administrators must act now to confirm which of their Arc installations are affected, apply vendor fixes, and harden local...
Board’s Enterprise Planning Platform has been formally recognized as a Microsoft Solutions Partner with the Certified Software for Azure designation, a milestone that confirms the product has passed Microsoft’s technical, marketplace and customer-success gates and positions the vendor for deeper...
In a recent revelation, security consultant Haakon Gulbrandsrud of Binary Security uncovered a significant vulnerability within Microsoft Azure's API Connections functionality. This flaw potentially allowed users with minimal privileges to access sensitive data across various Azure services...
access control
api connection flaw
api security
azure api vulnerabilities
azure security
cloud access
cloud infrastructure
cloud vulnerabilities
cybersecurity awareness
cybersecurity risks
data breach
data security
identityandaccess
low-code security
microsoft azure
no-code platforms
security alert
security assessment
security best practices