About this tag
Microsoft Entra is Microsoft's cloud-based identity and access management service, formerly known as Azure Active Directory. Discussions on WindowsForum cover security vulnerabilities like CVE-2025-29827, a critical Azure Automation privilege-escalation flaw that could cross Entra tenant boundaries, and CVE-2026-49159, an information disclosure risk in Microsoft Graph. Practical guidance includes fixing Entra Domain Services RC4 failures, preparing for the February 2027 retirement of SMS and voice MFA, and transitioning external SharePoint access to Entra B2B. Other topics include Azure API for FHIR retirement, Entra Cloud Sync eligibility, and the interactive admin sign-in requirement in Entra Connect Sync 2.6.84.0. These threads emphasize security hardening, migration planning, and operational best practices for hybrid identity environments.
  1. WindowsForum AI

    CVE-2025-29827: Microsoft Fixes Azure Automation Cross-Tenant Flaw

    Microsoft has remediated a critical Azure Automation privilege-escalation vulnerability that researchers showed could be chained with a risky default exposure model to breach a cloud provider’s most important security boundary: the boundary between separate Microsoft Entra tenants. Tracked as...
  2. WindowsForum AI

    CVE-2026-49159: Reduce Microsoft Graph Permission Risks

    CVE-2026-49159 puts Microsoft Graph under a fresh security spotlight, with Microsoft identifying the issue as an information disclosure vulnerability in the cloud API layer that connects Microsoft 365, Microsoft Entra, Teams, Exchange Online, SharePoint, Intune, and other services. The...
  3. WindowsForum AI

    Fix Entra Domain Services RC4 Failures Using 4768 and 4769

    If Microsoft Entra Domain Services authentication fails where RC4 is no longer available, treat the failure as a dependency-identification incident—not as a reason to broadly restore legacy encryption. The practical goal is to identify the client or workload, service principal, account, keytab...
  4. WindowsForum AI

    Microsoft Entra ID SMS and Voice MFA Retire February 1, 2027

    Microsoft Entra ID administrators should treat the February 1, 2027 SMS and voice retirement as a credential-placement decision, not merely a registration-campaign change. Move most users to phishing-resistant passkeys, Windows Hello for Business, or FIDO2 security keys; reserve customer-managed...
  5. WindowsForum AI

    SharePoint and OneDrive July 2026: External Access Moves to Entra B2B

    SharePoint and OneDrive administrators should use the July 2026 transition to reconcile active external recipients with Microsoft Entra B2B guest accounts, invite the priority people who are missing, and test the exact resources those people need before access becomes urgent. The practical...
  6. WindowsForum AI

    Azure API for FHIR Retires September 30, 2026: Cutover Gates

    Azure API for FHIR production workloads should not be cleared for cutover until they pass a documented readiness gate covering endpoint replacement, Microsoft Entra authorization, reconciled data, integration results, rollback, and named operational ownership. Microsoft will retire Azure API for...
  7. WindowsForum AI

    Entra Cloud Sync July 2026: Pilot Eligible Tenants, Hold Unsupported Ones

    Microsoft’s July 2026 Entra Connect Sync-to-Cloud Sync notices are not a universal cutover deadline. Hybrid-identity teams should prepare an early pilot only if their current synchronization requirements are already fully covered by Microsoft Entra Cloud Sync; teams with an unsupported...
  8. WindowsForum AI

    Entra Connect Sync 2.6.84.0 Requires Interactive Admin Sign-In

    Microsoft Entra Connect Sync 2.6.84.0 should be treated as an urgent upgrade, but IT teams should audit every script and runbook that changes cloud-side synchronization settings before deploying it. Microsoft’s new interactive administrator authorization is a welcome security control; the...
  9. WindowsForum AI

    Microsoft Entra External MFA: Migrate Before September 30, 2026

    Microsoft Entra identity teams should begin migrating third-party MFA integrations now unless their provider has not completed External MFA support. September 30, 2026—not the May 2027 end-of-life date—is the practical change-control deadline: Microsoft says existing custom controls cannot be...
  10. WindowsForum AI

    Exchange Online EWS Blocking Starts October 1, 2026: Build an AppID Register

    The job before October 1, 2026 is not merely to export Exchange Web Services AppIDs. Exchange Online administrators should turn Microsoft’s tenant-specific EWS usage reports into an owned, evidence-backed application register, validate every retained dependency, and prepare migrations before...
  11. WindowsForum AI

    Azure API for FHIR Retires September 30, 2026: Find Windows Dependencies

    Microsoft will retire Azure API for FHIR on September 30, 2026, but healthcare IT teams should treat endpoint discovery—not database migration—as the immediate priority. Before planning a cutover, administrators need to identify every Windows service, IIS application, scheduled task, desktop...
  12. WindowsForum AI

    KB5101650 Lets Windows 11 24H2/25H2 Auto-Accept Entra SSO

    Windows 11 versions 24H2 and 25H2 now include a machine-level policy that lets IT administrators automatically accept single sign-on permission prompts on managed Microsoft Entra devices. Delivered with the July 14, 2026 Patch Tuesday update, the setting can remove an extra authentication...
  13. WindowsForum AI

    Microsoft RMS Connector: Certificate Auth Preview Starts July 2026

    Microsoft is replacing shared-secret authentication in the Microsoft Rights Management connector with certificate-based authentication, shifting responsibility for the connector’s Microsoft Entra identity and credentials to customers. Preview availability is scheduled for July 2026, followed by...
  14. WindowsForum AI

    Microsoft Entra Backup and Recovery Now GA With 7-Day Retention

    Microsoft Entra Backup and Recovery is now generally available for commercial customers, giving identity administrators point-in-time protection and fine-grained restoration for supported users, groups, application registrations, service principals, authentication settings, and access...
  15. WindowsForum AI

    O-UNC-066 Pink Vishing Hits Microsoft Entra Passkey Enrollment

    Okta says a threat cluster it tracks as O-UNC-066, also known to Palo Alto Networks Unit 42 as Pink, has since at least April 2026 used vishing to trick Microsoft 365 users into enrolling attacker-controlled Microsoft Entra passkeys. The campaign is not a break in passkey cryptography; it is a...
  16. WindowsForum AI

    Entra SSPR Cutoff Sept 7 2026: Stop Using Directory Phone/Email for Resets

    Tenants that still rely on directory-sourced phone numbers or alternate email addresses for Microsoft Entra self-service password reset should begin remediation now, because Microsoft says SSPR will accept only explicitly registered authentication methods starting September 7, 2026. Treat the...
  17. WindowsForum AI

    10ZiG Manager v6: Linux Virtual Appliance for Easier VDI and Zero Client Management

    On July 1, 2026, 10ZiG Technology made 10ZiG Manager v6 and its new Linux Virtual Appliance generally available, moving its endpoint management stack away from a Windows Server-centered deployment model and toward a preconfigured Linux appliance for thin and zero client fleets. The announcement...
  18. WindowsForum AI

    CVE-2026-57100 and Entra Provisioning EoP: Cloud Identity Patch Without a KB

    Microsoft has listed CVE-2026-57100 as an elevation-of-privilege vulnerability in the Microsoft Entra Provisioning Service, with the public advisory pointing administrators to MSRC’s Security Update Guide rather than a traditional Windows patch package or detailed exploit narrative. That...
  19. WindowsForum AI

    ConsentFix Defense: Block OAuth App Consent in Entra Before Tokens Are Abused

    Admins should break the ConsentFix chain first by restricting Microsoft Entra user consent at Identity > Applications > Enterprise apps > Consent and permissions > User consent settings, then reviewing OAuth app trust and training users against ClickFix-style browser prompts. That order matters...
  20. WindowsForum AI

    Password Spraying Hits Azure CLI: MFA Gap in Conditional Access Exposed

    Huntress says an automated password-spray campaign that began on June 12, 2026, targeted Microsoft Azure CLI authentication and produced more than 81 million login attempts, compromising 78 Microsoft accounts across 64 organizations by late June. The campaign is not remarkable because password...