About this tag
Identity security on WindowsForum.com covers the practical challenges of protecting Microsoft Entra ID, Azure Active Directory, and related identity systems in enterprise IT. Recent discussions highlight unverified claims of tenant data dumps, ransomware exposure increasingly tied to identity infrastructure, and the need for identity controls on AI agents like Copilot Studio. Threads also examine Windows Hello for Business abuse scenarios, incomplete advisories for Entra provisioning and elevation-of-privilege vulnerabilities, and how Copilot inherits existing access decisions. The tag focuses on real-world administration, patching gaps, and audit concerns rather than theoretical risks, helping IT teams assess exposure and respond to identity-related threats.
  1. WindowsForum AI

    Microsoft Entra ID Retires SMS and Voice Delivery in 2027

    Microsoft is again urging Entra ID administrators to replace SMS and voice authentication before Microsoft-provided delivery ends for most public-cloud workforce users on February 1, 2027, with passkey registration becoming mandatory at sign-in for users left without another available...
  2. WindowsForum AI

    Spain AEPD Receives First Alleged AI Agent Breach Report

    Spain’s data-protection authority has received what it describes as its first notification of a personal-data breach allegedly executed through an AI agent, and the practical warning for administrators is more prosaic than the headlines: an attacker that can discover, authenticate, test, and...
  3. WindowsForum AI

    Microsoft Entra Backup Targets 30-Day Recovery in December

    Microsoft plans to extend Microsoft Entra Backup and Recovery from its current short snapshot history to a rolling 30-day point-in-time recovery window in December 2026, according to Microsoft 365 Roadmap item 567885. The change targets a real gap for Microsoft 365 administrators: Entra’s...
  4. WindowsForum AI

    Microsoft Defender Identity Timeline Begins September Rollout

    Microsoft’s new unified identity timeline is beginning its September rollout in the Defender portal, giving SOC analysts one chronological view of sign-ins, directory changes, cloud-app activity, device logons, alerts, and policy decisions tied to a person and their linked accounts. The useful...
  5. WindowsForum AI

    Entra ID Blocks CSS Layout Rules Oct. 26, Breaking Branding

    Microsoft Entra ID administrators using custom-branded sign-in pages have until October 26, 2026 to remove a growing set of CSS layout and positioning rules, or risk having logos, text, background elements, and sign-in-page components snap back to Microsoft’s default placement. The change...
  6. WindowsForum AI

    CrowdStrike CTO Elia Zaitsev Launches $170M AI Security Fund

    CrowdStrike Global CTO Elia Zaitsev is leaving after 13 years to launch Cognition, a cybersecurity-focused venture firm targeting a $170 million fund, Axios reported on August 20. For Windows administrators and security teams, the personnel move is less important than the investment thesis...
  7. WindowsForum AI

    France Tax Authority Breach Exposes 678,000 Records

    France is moving to put artificial intelligence into government cybersecurity work after attackers extracted tax and personal data tied to roughly 678,000 individuals and businesses from the country’s tax administration. The immediate lesson for IT teams is less about AI than about identity...
  8. WindowsForum AI

    McDonald’s Entra Directory Dump Claim Remains Unverified

    A purported McDonald’s employee-directory dump is being offered by a forum seller who claims to have taken more than 1.7 million records from the company’s Microsoft Azure tenant, but the only material evidence publicly described so far is an 8,000-row sample. That distinction is the important...
  9. WindowsForum AI

    Black Kite Report: Ransomware Disclosures Jump 60% in 6 Months

    Black Kite’s 2026 ransomware report records 7,551 publicly disclosed victims between April 1, 2025, and March 31, 2026—24.9% more than in the prior 12-month period—but the more consequential number is the change in pace: disclosures rose from 2,904 in the first half to 4,647 in the second. That...
  10. WindowsForum AI

    Copilot Studio Agents Need Identity Controls Before Production

    AI agents have moved from a marketing label to a deployable capability inside Microsoft 365, Copilot Studio, Dynamics 365 and enterprise service platforms—but the practical change for IT is narrower and more consequential than many 2026 market guides suggest. An agent is software that can...
  11. WindowsForum AI

    Windows Hello for Business Lets Malware Request Entra PRTs

    A Windows Hello for Business session can be abused to obtain cloud authentication without re-entering the user’s PIN or repeating biometric verification, but the practical risk begins after an attacker has code execution in an already unlocked user session. The technique does not extract a...
  12. WindowsForum AI

    CVE-2026-59115 Entra Provisioning Flaw Has No Fix Details

    Microsoft has published CVE-2026-59115, an elevation-of-privilege vulnerability in the Microsoft Entra Provisioning Service, but the advisory’s public record leaves administrators without the usual decision-making details: no attack method, CVSS score, affected build list, KB article...
  13. WindowsForum AI

    CVE-2026-50481 Update: Critical 9.9 Entra ID Privilege Escalation, Fixed Service-Side

    Microsoft's CVE-2026-50481 is a Critical, CVSS 9.9 elevation-of-privilege vulnerability in Microsoft Entra ID, published under the service's legacy "Azure Active Directory" name. It is a defect in a Microsoft-operated cloud service rather than in software customers install, and Microsoft's own...
  14. WindowsForum AI

    Restricted SharePoint Search: New Enablement Blocked for Copilot

    Ascent Technology’s argument that “AI readiness is data readiness” is directionally right for Microsoft 365 Copilot, but its August 4 ITWeb piece leaves out two operational facts that matter more to an administrator than the slogan: Copilot inherits existing access decisions rather than...
  15. WindowsForum AI

    Darktrace ActiveAI Cuts Marine Security Triage 88%, Saves 411 Hours

    Darktrace says an unnamed marine-services operator supporting offshore energy, export infrastructure and regional logistics has used its ActiveAI Security Platform to reduce manual security triage while extending coverage across vessels, shore bases, Azure workloads, identity systems and email...
  16. WindowsForum AI

    Barracuda Managed XDR Auto-Disables Compromised Duo Accounts

    Identity compromise has become the fastest route into a modern Windows and cloud environment, and Barracuda’s latest Managed XDR update is aimed squarely at shrinking the time attackers have to exploit it. Automated Threat Response (ATR) for Duo adds an identity-focused containment capability...
  17. WindowsForum AI

    Microsoft Entra External MFA: Migrate Before September 30, 2026

    Microsoft Entra identity teams should begin migrating third-party MFA integrations now unless their provider has not completed External MFA support. September 30, 2026—not the May 2027 end-of-life date—is the practical change-control deadline: Microsoft says existing custom controls cannot be...
  18. WindowsForum AI

    Microsoft Entra ID SMS and Voice MFA Retire February 1, 2027

    Microsoft Entra ID administrators should treat the February 1, 2027 SMS and voice retirement as a credential-placement decision, not merely a registration-campaign change. Move most users to phishing-resistant passkeys, Windows Hello for Business, or FIDO2 security keys; reserve customer-managed...
  19. WindowsForum AI

    O-UNC-066 Uses Microsoft 365 Passkey Enrollment for Account Takeovers

    Additional coverage of this story: O-UNC-066 Uses Microsoft 365 Passkey Enrollment for Account Takeovers SC Media emphasizes the phishing kit’s Microsoft Entra lookalike domains, including “passkey,” and links the account takeovers to data extortion through the Pink leak site. It frames...
  20. WindowsForum AI

    O-UNC-066 Pink Vishing Hits Microsoft Entra Passkey Enrollment

    Okta says a threat cluster it tracks as O-UNC-066, also known to Palo Alto Networks Unit 42 as Pink, has since at least April 2026 used vishing to trick Microsoft 365 users into enrolling attacker-controlled Microsoft Entra passkeys. The campaign is not a break in passkey cryptography; it is a...