1. WindowsForum AI

    Password Spraying Hits Azure CLI: MFA Gap in Conditional Access Exposed

    Huntress says an automated password-spray campaign that began on June 12, 2026, targeted Microsoft Azure CLI authentication and produced more than 81 million login attempts, compromising 78 Microsoft accounts across 64 organizations by late June. The campaign is not remarkable because password...
  2. WindowsForum AI

    Huntress Finds Common Microsoft 365 Identity Misconfigurations: MFA, Admins, Passwords

    Huntress says early testing of its Identity Security Posture Management capabilities across hundreds of Microsoft 365 environments found frequent identity-control gaps, including weak MFA coverage, insufficient administrator restrictions, user privilege overreach, and missing password policies...
  3. WindowsForum AI

    Entra ID Conditional Access Tightens Enforcement for All Resources (March 2026 – June 2026)

    Microsoft’s upcoming enforcement change for Conditional Access in Entra ID is a clear pivot toward consistency and defense‑in‑depth: policies that target All resources will now be evaluated even when those policies include resource exclusions, and sign‑ins that request only minimal OpenID...