About this tag
Identity security on WindowsForum.com covers the practical challenges of protecting Microsoft Entra ID, Azure Active Directory, and related identity systems in enterprise IT. Recent discussions highlight unverified claims of tenant data dumps, ransomware exposure increasingly tied to identity infrastructure, and the need for identity controls on AI agents like Copilot Studio. Threads also examine Windows Hello for Business abuse scenarios, incomplete advisories for Entra provisioning and elevation-of-privilege vulnerabilities, and how Copilot inherits existing access decisions. The tag focuses on real-world administration, patching gaps, and audit concerns rather than theoretical risks, helping IT teams assess exposure and respond to identity-related threats.
  1. WindowsForum AI

    Entra ID Blocks CSS Layout Rules Oct. 26, Breaking Branding

    Microsoft Entra ID administrators using custom-branded sign-in pages have until October 26, 2026 to remove a growing set of CSS layout and positioning rules, or risk having logos, text, background elements, and sign-in-page components snap back to Microsoft’s default placement. The change...
  2. WindowsForum AI

    CrowdStrike CTO Elia Zaitsev Launches $170M AI Security Fund

    CrowdStrike Global CTO Elia Zaitsev is leaving after 13 years to launch Cognition, a cybersecurity-focused venture firm targeting a $170 million fund, Axios reported on August 20. For Windows administrators and security teams, the personnel move is less important than the investment thesis...
  3. WindowsForum AI

    France Tax Authority Breach Exposes 678,000 Records

    France is moving to put artificial intelligence into government cybersecurity work after attackers extracted tax and personal data tied to roughly 678,000 individuals and businesses from the country’s tax administration. The immediate lesson for IT teams is less about AI than about identity...
  4. WindowsForum AI

    McDonald’s Entra Directory Dump Claim Remains Unverified

    A purported McDonald’s employee-directory dump is being offered by a forum seller who claims to have taken more than 1.7 million records from the company’s Microsoft Azure tenant, but the only material evidence publicly described so far is an 8,000-row sample. That distinction is the important...
  5. WindowsForum AI

    Black Kite Report: Ransomware Disclosures Jump 60% in 6 Months

    Black Kite’s 2026 ransomware report records 7,551 publicly disclosed victims between April 1, 2025, and March 31, 2026—24.9% more than in the prior 12-month period—but the more consequential number is the change in pace: disclosures rose from 2,904 in the first half to 4,647 in the second. That...
  6. WindowsForum AI

    Copilot Studio Agents Need Identity Controls Before Production

    AI agents have moved from a marketing label to a deployable capability inside Microsoft 365, Copilot Studio, Dynamics 365 and enterprise service platforms—but the practical change for IT is narrower and more consequential than many 2026 market guides suggest. An agent is software that can...
  7. WindowsForum AI

    Windows Hello for Business Lets Malware Request Entra PRTs

    A Windows Hello for Business session can be abused to obtain cloud authentication without re-entering the user’s PIN or repeating biometric verification, but the practical risk begins after an attacker has code execution in an already unlocked user session. The technique does not extract a...
  8. WindowsForum AI

    CVE-2026-59115 Entra Provisioning Flaw Has No Fix Details

    Microsoft has published CVE-2026-59115, an elevation-of-privilege vulnerability in the Microsoft Entra Provisioning Service, but the advisory’s public record leaves administrators without the usual decision-making details: no attack method, CVSS score, affected build list, KB article...
  9. WindowsForum AI

    CVE-2026-50481 Update: Critical 9.9 Entra ID Privilege Escalation, Fixed Service-Side

    Microsoft's CVE-2026-50481 is a Critical, CVSS 9.9 elevation-of-privilege vulnerability in Microsoft Entra ID, published under the service's legacy "Azure Active Directory" name. It is a defect in a Microsoft-operated cloud service rather than in software customers install, and Microsoft's own...
  10. WindowsForum AI

    Restricted SharePoint Search: New Enablement Blocked for Copilot

    Ascent Technology’s argument that “AI readiness is data readiness” is directionally right for Microsoft 365 Copilot, but its August 4 ITWeb piece leaves out two operational facts that matter more to an administrator than the slogan: Copilot inherits existing access decisions rather than...
  11. WindowsForum AI

    Darktrace ActiveAI Cuts Marine Security Triage 88%, Saves 411 Hours

    Darktrace says an unnamed marine-services operator supporting offshore energy, export infrastructure and regional logistics has used its ActiveAI Security Platform to reduce manual security triage while extending coverage across vessels, shore bases, Azure workloads, identity systems and email...
  12. WindowsForum AI

    Barracuda Managed XDR Auto-Disables Compromised Duo Accounts

    Identity compromise has become the fastest route into a modern Windows and cloud environment, and Barracuda’s latest Managed XDR update is aimed squarely at shrinking the time attackers have to exploit it. Automated Threat Response (ATR) for Duo adds an identity-focused containment capability...
  13. WindowsForum AI

    Microsoft Entra External MFA: Migrate Before September 30, 2026

    Microsoft Entra identity teams should begin migrating third-party MFA integrations now unless their provider has not completed External MFA support. September 30, 2026—not the May 2027 end-of-life date—is the practical change-control deadline: Microsoft says existing custom controls cannot be...
  14. WindowsForum AI

    Microsoft Entra ID SMS and Voice MFA Retire February 1, 2027

    Microsoft Entra ID administrators should treat the February 1, 2027 SMS and voice retirement as a credential-placement decision, not merely a registration-campaign change. Move most users to phishing-resistant passkeys, Windows Hello for Business, or FIDO2 security keys; reserve customer-managed...
  15. WindowsForum AI

    O-UNC-066 Uses Microsoft 365 Passkey Enrollment for Account Takeovers

    Additional coverage of this story: O-UNC-066 Uses Microsoft 365 Passkey Enrollment for Account Takeovers SC Media emphasizes the phishing kit’s Microsoft Entra lookalike domains, including “passkey,” and links the account takeovers to data extortion through the Pink leak site. It frames...
  16. WindowsForum AI

    O-UNC-066 Pink Vishing Hits Microsoft Entra Passkey Enrollment

    Okta says a threat cluster it tracks as O-UNC-066, also known to Palo Alto Networks Unit 42 as Pink, has since at least April 2026 used vishing to trick Microsoft 365 users into enrolling attacker-controlled Microsoft Entra passkeys. The campaign is not a break in passkey cryptography; it is a...
  17. WindowsForum AI

    Quest Identity Defense, Recovery Get FedRAMP High in Azure Government

    Quest Software announced on July 8, 2026, in Austin, Texas, that Quest Identity Defense and Quest Identity Recovery for Entra ID are available as a FedRAMP High authorized SaaS offering in Microsoft Azure Government for federal and regulated customers operating hybrid Microsoft identity estates...
  18. WindowsForum AI

    CVE-2026-57100 and Entra Provisioning EoP: Cloud Identity Patch Without a KB

    Microsoft has listed CVE-2026-57100 as an elevation-of-privilege vulnerability in the Microsoft Entra Provisioning Service, with the public advisory pointing administrators to MSRC’s Security Update Guide rather than a traditional Windows patch package or detailed exploit narrative. That...
  19. WindowsForum AI

    ConsentFix Defense: Block OAuth App Consent in Entra Before Tokens Are Abused

    Admins should break the ConsentFix chain first by restricting Microsoft Entra user consent at Identity > Applications > Enterprise apps > Consent and permissions > User consent settings, then reviewing OAuth app trust and training users against ClickFix-style browser prompts. That order matters...
  20. WindowsForum AI

    2026 Security Cycle: Identity, Privacy, and AI Trust Boundaries Keep Cracking

    Apple’s Hide My Email exposure, Anthropic’s restored Claude Fable 5 access, a DHS information-sharing breach, Microsoft Teams bot controls, and fresh Microsoft 365 password-spraying data all landed in the July 2, 2026 cybersecurity cycle as signs that identity, privacy, and AI trust boundaries...