microsoft entra id

  1. Hunting Entra ID Assistive Agent Abuse: Correlate Exchange, Graph, Entra Logs

    Microsoft Entra ID agent logs are becoming a practical threat-hunting source in June 2026 because assistive AI agents can use delegated OAuth access to act for signed-in users, making malicious Graph and Exchange activity look deceptively human. The uncomfortable lesson is that “on behalf of” is...
  2. Silverfort Runtime Identity Controls for Copilot Studio Agents: Secure AI Actions

    Silverfort on June 8, 2026 launched an early-access integration that applies real-time identity and access controls to AI agents built in Microsoft Copilot Studio, evaluating each agent action before it executes across enterprise systems. The announcement is narrow in product terms but broad in...
  3. Microsoft Scout: Always-On Workplace AI Agent for Teams, Email, and Microsoft 365

    Microsoft announced Scout at Build on Tuesday, June 2, 2026, as an always-on workplace AI agent for Teams, email, calendars, and Microsoft 365 tasks, initially launching with a small customer group and a Frontier-access desktop app tied to GitHub Copilot. That makes Scout less a chatbot than a...
  4. Microsoft Scout Autopilot: Governed Autonomous Agent for Microsoft 365

    Microsoft introduced Microsoft Scout on June 2, 2026, at Build in San Francisco and online as its first “Autopilot” agent for Microsoft 365, an always-on OpenClaw-based assistant that works through Teams, Outlook, OneDrive, SharePoint, the desktop, the browser, and governed Entra identity. The...
  5. TCS, Infosys and Wipro Scale Microsoft 365 Copilot to 300,000 Users

    India’s TCS, Infosys, and Wipro have each expanded Microsoft 365 Copilot deployments beyond 100,000 employees as of June 3, 2026, taking their combined rollout past 300,000 users in less than six months. That makes the Indian IT services sector one of Microsoft’s most important proving grounds...
  6. Entra ID SSPR Reset Deadline: Verify Recovery Methods by Sept 7, 2026

    Microsoft will require Microsoft Entra ID self-service password reset users to verify recovery with explicitly registered authentication methods starting September 7, 2026, after a registration campaign begins on July 6 across commercial and U.S. government cloud tenants. The move closes a quiet...
  7. Entra ID SSPR Update: Contact Data Won’t Count After Sep 7, 2026

    Microsoft will begin changing Microsoft Entra ID self-service password reset on July 6, 2026, and from September 7, 2026, SSPR will require users to have explicitly registered authentication methods instead of relying on unregistered directory contact fields. The shift sounds procedural, but it...
  8. Entra ID SSPR From Sept 7, 2026: Recovery Methods Must Be Explicitly Registered

    Microsoft has told Entra ID customers that, starting September 7, 2026, self-service password reset will accept only explicitly registered authentication methods, after a July 6 registration campaign begins prompting affected users to add trusted methods in the Microsoft Entra experience. The...
  9. Microsoft 365, Entra ID, Intune for Education: Senac-RS Identity & Device Resilience

    On May 21, 2026, Microsoft published a customer story detailing how Senac-RS in Rio Grande do Sul, Brazil, moved more than 120,000 annual students and over 5,000 academic devices onto Microsoft 365, Microsoft Entra ID, Intune, and Defender across more than 40 educational units. The headline is...
  10. Microsoft World Passkey Day 2026: Passwords and Weak Recovery Get Removed

    Microsoft used World Passkey Day on May 7, 2026, to announce a broader push across Microsoft Entra ID, Windows, consumer accounts, and account recovery that moves passkeys from optional security upgrade toward the default path for passwordless authentication. The headline is not that Microsoft...
  11. ConsentFix v3 Phishing: Steal OAuth Codes and Replay Tokens in Microsoft Entra ID

    ConsentFix v3 is a newly reported phishing toolkit and attack method that targets Microsoft Azure and Entra ID accounts by automating OAuth authorization-code theft, using services such as Cloudflare Pages and Pipedream to collect codes and exchange them for usable Microsoft access and refresh...
  12. Securely Access Redshift Serverless Workgroups via NLB and Microsoft Entra ID

    Amazon Web Services has published a detailed blueprint for securely fronting multiple Amazon Redshift Serverless workgroups with a Network Load Balancer while using Microsoft Entra ID for native authentication. The pattern is aimed at organizations that need one stable connection endpoint for...
  13. Microsoft Entra External MFA (OIDC): Policy Control Kept, Custom Controls Retire 2026

    Microsoft has quietly removed one of the biggest identity-management frictions for enterprise customers: the inability to cleanly use third-party MFA providers inside Microsoft Entra ID without sacrificing policy control. The new external MFA capability is now generally available, and Microsoft...
  14. KB5079473 Windows 11 Update Bugs: How Identity Failures Can Shake Azure Trust

    When Windows 11 misfires, Azure does not necessarily lose revenue the same day, but the damage can still travel far beyond the desktop. That is the uncomfortable strategic point behind Microsoft’s latest Windows 11 troubles: a client OS bug can shake confidence in the broader Microsoft stack...
  15. Adactin AFIVE: Trusted AI Knowledge Search Across Enterprise Documents

    Adactin’s launch of AFIVE lands squarely in one of the busiest corners of enterprise software: the race to make internal knowledge searchable, trustworthy and useful through natural language. The Sydney-based services firm is pitching the platform as an AI knowledge layer that can unify...
  16. Real-Time Microsoft Hybrid Identity Security: Why Snapshot Tools Fall Short

    Identity security in hybrid Microsoft estates is moving from a periodic compliance exercise to a continuous operational discipline, and that shift is exposing a hard truth: free, snapshot-based Microsoft identity tools are no longer enough for enterprises that need to see change as it happens...
  17. Defending Against Malicious Microsoft Entra OAuth Apps and Token Theft

    The discovery that attackers are weaponizing Microsoft Entra ID OAuth flows to gain long‑lived access to corporate mail and files is not theoretical—it’s a clear, recurring pattern that demands a rethink of how organizations govern third‑party applications, consent, and service principals across...
  18. Exchange Online Moderation Gets Actionable Messages and Fewer Approvals

    Microsoft is rolling out a pair of practical updates to Exchange Online moderation that should make life easier for moderators and admins alike: moderated messages will now use Actionable Messages adaptive cards so Approve | Reject controls appear inside the message body on every Outlook client...