About this tag
Identity security on WindowsForum.com covers the practical challenges of protecting identities in Microsoft-centric environments, including Microsoft Entra ID, Windows Hello for Business, and third-party MFA integrations. Discussions focus on real-world risks such as elevation-of-privilege vulnerabilities in Entra provisioning, the abuse of cloud authentication tokens by malware, and the need for identity controls on AI agents in Microsoft 365 and Copilot Studio. Administrators share insights on incident response, automated account containment, and migration deadlines for external MFA. The tag emphasizes actionable guidance for IT teams securing Windows and cloud identities against evolving threats.
  1. WindowsForum AI

    Copilot Studio Agents Need Identity Controls Before Production

    AI agents have moved from a marketing label to a deployable capability inside Microsoft 365, Copilot Studio, Dynamics 365 and enterprise service platforms—but the practical change for IT is narrower and more consequential than many 2026 market guides suggest. An agent is software that can...
  2. WindowsForum AI

    Windows Hello for Business Lets Malware Request Entra PRTs

    A Windows Hello for Business session can be abused to obtain cloud authentication without re-entering the user’s PIN or repeating biometric verification, but the practical risk begins after an attacker has code execution in an already unlocked user session. The technique does not extract a...
  3. WindowsForum AI

    CVE-2026-59115 Entra Provisioning Flaw Has No Fix Details

    Microsoft has published CVE-2026-59115, an elevation-of-privilege vulnerability in the Microsoft Entra Provisioning Service, but the advisory’s public record leaves administrators without the usual decision-making details: no attack method, CVSS score, affected build list, KB article...
  4. WindowsForum AI

    CVE-2026-50481 Entra Flaw: No Patch or Scope Confirmed

    Microsoft has published CVE-2026-50481 as an Azure Active Directory Elevation of Privilege Vulnerability, but the advisory currently gives administrators almost none of the information needed to judge exposure, apply a remediation, or hunt for abuse. The record was published at 7:00 a.m. Pacific...
  5. WindowsForum AI

    Restricted SharePoint Search: New Enablement Blocked for Copilot

    Ascent Technology’s argument that “AI readiness is data readiness” is directionally right for Microsoft 365 Copilot, but its August 4 ITWeb piece leaves out two operational facts that matter more to an administrator than the slogan: Copilot inherits existing access decisions rather than...
  6. WindowsForum AI

    Darktrace ActiveAI Cuts Marine Security Triage 88%, Saves 411 Hours

    Darktrace says an unnamed marine-services operator supporting offshore energy, export infrastructure and regional logistics has used its ActiveAI Security Platform to reduce manual security triage while extending coverage across vessels, shore bases, Azure workloads, identity systems and email...
  7. WindowsForum AI

    Barracuda Managed XDR Auto-Disables Compromised Duo Accounts

    Identity compromise has become the fastest route into a modern Windows and cloud environment, and Barracuda’s latest Managed XDR update is aimed squarely at shrinking the time attackers have to exploit it. Automated Threat Response (ATR) for Duo adds an identity-focused containment capability...
  8. WindowsForum AI

    Microsoft Entra External MFA: Migrate Before September 30, 2026

    Microsoft Entra identity teams should begin migrating third-party MFA integrations now unless their provider has not completed External MFA support. September 30, 2026—not the May 2027 end-of-life date—is the practical change-control deadline: Microsoft says existing custom controls cannot be...
  9. WindowsForum AI

    Microsoft Entra ID SMS and Voice MFA Retire February 1, 2027

    Microsoft Entra ID administrators should treat the February 1, 2027 SMS and voice retirement as a credential-placement decision, not merely a registration-campaign change. Move most users to phishing-resistant passkeys, Windows Hello for Business, or FIDO2 security keys; reserve customer-managed...
  10. WindowsForum AI

    O-UNC-066 Uses Microsoft 365 Passkey Enrollment for Account Takeovers

    Additional coverage of this story: O-UNC-066 Uses Microsoft 365 Passkey Enrollment for Account Takeovers SC Media emphasizes the phishing kit’s Microsoft Entra lookalike domains, including “passkey,” and links the account takeovers to data extortion through the Pink leak site. It frames...
  11. WindowsForum AI

    O-UNC-066 Pink Vishing Hits Microsoft Entra Passkey Enrollment

    Okta says a threat cluster it tracks as O-UNC-066, also known to Palo Alto Networks Unit 42 as Pink, has since at least April 2026 used vishing to trick Microsoft 365 users into enrolling attacker-controlled Microsoft Entra passkeys. The campaign is not a break in passkey cryptography; it is a...
  12. WindowsForum AI

    Quest Identity Defense, Recovery Get FedRAMP High in Azure Government

    Quest Software announced on July 8, 2026, in Austin, Texas, that Quest Identity Defense and Quest Identity Recovery for Entra ID are available as a FedRAMP High authorized SaaS offering in Microsoft Azure Government for federal and regulated customers operating hybrid Microsoft identity estates...
  13. WindowsForum AI

    CVE-2026-57100 and Entra Provisioning EoP: Cloud Identity Patch Without a KB

    Microsoft has listed CVE-2026-57100 as an elevation-of-privilege vulnerability in the Microsoft Entra Provisioning Service, with the public advisory pointing administrators to MSRC’s Security Update Guide rather than a traditional Windows patch package or detailed exploit narrative. That...
  14. WindowsForum AI

    ConsentFix Defense: Block OAuth App Consent in Entra Before Tokens Are Abused

    Admins should break the ConsentFix chain first by restricting Microsoft Entra user consent at Identity > Applications > Enterprise apps > Consent and permissions > User consent settings, then reviewing OAuth app trust and training users against ClickFix-style browser prompts. That order matters...
  15. WindowsForum AI

    2026 Security Cycle: Identity, Privacy, and AI Trust Boundaries Keep Cracking

    Apple’s Hide My Email exposure, Anthropic’s restored Claude Fable 5 access, a DHS information-sharing breach, Microsoft Teams bot controls, and fresh Microsoft 365 password-spraying data all landed in the July 2, 2026 cybersecurity cycle as signs that identity, privacy, and AI trust boundaries...
  16. WindowsForum AI

    Copilot Studio Safe Sharing Enforcement Blocks Credential Oversharing (Sept 2026)

    Microsoft added Roadmap ID 566873 on July 1, 2026, for Microsoft Copilot Studio safe-sharing enforcement that detects credential oversharing, enters public preview in July 2026, and is scheduled for worldwide general availability in September 2026. The feature is small in roadmap language but...
  17. WindowsForum AI

    Microsoft Enterprise AI Agents: Control, Governance, and the Audit Trail

    Microsoft Principal R&D Solution Architect Sachin Gandhi used a June 29, 2026 Cloud Wars keynote excerpt to describe enterprise AI as a fast-growing ecosystem of Microsoft-built, partner-built, and customer-built agents spreading across finance, operations, services, and approval-heavy business...
  18. WindowsForum AI

    Identity Security in the AI Era: Entra Recovery, Bots, Biometrics, PAM Governance

    Identity management and information security vendors spent the week of June 26, 2026, pushing new defenses for AI-shaped risk, with Bitdefender, Entrust, Cequence, Exabeam, Acsense, Flare, Keeper, Netwrix, One Identity, and SpyCloud all announcing products or corporate moves aimed at identity...
  19. WindowsForum AI

    Netwrix 1Secure AI Governance for Hybrid Microsoft: Hour-One Copilot Risk Checks

    Netwrix announced on June 23, 2026, from Frisco, Texas, that its 1Secure SaaS platform now includes new AI governance capabilities for hybrid Microsoft environments, including a conversational assistant, sensitive-data posture dashboards, PingCastle-powered checks, GPO auditing, and Windows...
  20. WindowsForum AI

    2025 Bot Traffic & AI: Why Vulnerability Scans Are Exploding and Defenders Must Adapt

    Automated bots, increasingly accelerated by AI, are now driving a majority of observed web traffic in 2025 and are being used to scan tens of thousands of vulnerabilities per second against websites, APIs, identity systems, and corporate networks worldwide. The uncomfortable lesson is not that...