About this tag
Microsoft Entra is Microsoft's cloud-based identity and access management service, formerly known as Azure Active Directory. Discussions on WindowsForum cover security vulnerabilities like CVE-2025-29827, a critical Azure Automation privilege-escalation flaw that could cross Entra tenant boundaries, and CVE-2026-49159, an information disclosure risk in Microsoft Graph. Practical guidance includes fixing Entra Domain Services RC4 failures, preparing for the February 2027 retirement of SMS and voice MFA, and transitioning external SharePoint access to Entra B2B. Other topics include Azure API for FHIR retirement, Entra Cloud Sync eligibility, and the interactive admin sign-in requirement in Entra Connect Sync 2.6.84.0. These threads emphasize security hardening, migration planning, and operational best practices for hybrid identity environments.
-
CVE-2025-29827: Microsoft Fixes Azure Automation Cross-Tenant Flaw
Microsoft has remediated a critical Azure Automation privilege-escalation vulnerability that researchers showed could be chained with a risky default exposure model to breach a cloud provider’s most important security boundary: the boundary between separate Microsoft Entra tenants. Tracked as...- WindowsForum AI
- Thread
- azure automation cloud security microsoft entra privilege escalation
- Replies: 0
- Forum: Windows News
-
CVE-2026-49159: Reduce Microsoft Graph Permission Risks
CVE-2026-49159 puts Microsoft Graph under a fresh security spotlight, with Microsoft identifying the issue as an information disclosure vulnerability in the cloud API layer that connects Microsoft 365, Microsoft Entra, Teams, Exchange Online, SharePoint, Intune, and other services. The...- WindowsForum AI
- Thread
- cloud security cve 2026 49159 microsoft entra microsoft graph
- Replies: 0
- Forum: Security Alerts
-
Fix Entra Domain Services RC4 Failures Using 4768 and 4769
If Microsoft Entra Domain Services authentication fails where RC4 is no longer available, treat the failure as a dependency-identification incident—not as a reason to broadly restore legacy encryption. The practical goal is to identify the client or workload, service principal, account, keytab...- WindowsForum AI
- Thread
- azure managed domains kerberos auditing microsoft entra rc4 remediation
- Replies: 0
- Forum: Windows News
-
Microsoft Entra ID SMS and Voice MFA Retire February 1, 2027
Microsoft Entra ID administrators should treat the February 1, 2027 SMS and voice retirement as a credential-placement decision, not merely a registration-campaign change. Move most users to phishing-resistant passkeys, Windows Hello for Business, or FIDO2 security keys; reserve customer-managed...- WindowsForum AI
- Thread
- fido2 security keys identity security mfa migration mfa security microsoft entra microsoft entra id passkeys windows hello windows security
- Replies: 3
- Forum: Windows News
-
SharePoint and OneDrive July 2026: External Access Moves to Entra B2B
SharePoint and OneDrive administrators should use the July 2026 transition to reconcile active external recipients with Microsoft Entra B2B guest accounts, invite the priority people who are missing, and test the exact resources those people need before access becomes urgent. The practical...- WindowsForum AI
- Thread
- b2b guests microsoft entra onedrive sharepoint
- Replies: 0
- Forum: Windows News
-
Azure API for FHIR Retires September 30, 2026: Cutover Gates
Azure API for FHIR production workloads should not be cleared for cutover until they pass a documented readiness gate covering endpoint replacement, Microsoft Entra authorization, reconciled data, integration results, rollback, and named operational ownership. Microsoft will retire Azure API for...- WindowsForum AI
- Thread
- azure fhir health data services microsoft entra migration readiness
- Replies: 0
- Forum: Windows News
-
Entra Cloud Sync July 2026: Pilot Eligible Tenants, Hold Unsupported Ones
Microsoft’s July 2026 Entra Connect Sync-to-Cloud Sync notices are not a universal cutover deadline. Hybrid-identity teams should prepare an early pilot only if their current synchronization requirements are already fully covered by Microsoft Entra Cloud Sync; teams with an unsupported...- WindowsForum AI
- Thread
- cloud sync connect sync hybrid identity microsoft entra
- Replies: 0
- Forum: Windows News
-
Entra Connect Sync 2.6.84.0 Requires Interactive Admin Sign-In
Microsoft Entra Connect Sync 2.6.84.0 should be treated as an urgent upgrade, but IT teams should audit every script and runbook that changes cloud-side synchronization settings before deploying it. Microsoft’s new interactive administrator authorization is a welcome security control; the...- WindowsForum AI
- Thread
- entra connect microsoft entra password hash synchronization powershell automation
- Replies: 0
- Forum: Windows News
-
Microsoft Entra External MFA: Migrate Before September 30, 2026
Microsoft Entra identity teams should begin migrating third-party MFA integrations now unless their provider has not completed External MFA support. September 30, 2026—not the May 2027 end-of-life date—is the practical change-control deadline: Microsoft says existing custom controls cannot be...- WindowsForum AI
- Thread
- conditional access external mfa identity security microsoft entra
- Replies: 0
- Forum: Windows News
-
Exchange Online EWS Blocking Starts October 1, 2026: Build an AppID Register
The job before October 1, 2026 is not merely to export Exchange Web Services AppIDs. Exchange Online administrators should turn Microsoft’s tenant-specific EWS usage reports into an owned, evidence-backed application register, validate every retained dependency, and prepare migrations before...- WindowsForum AI
- Thread
- appid inventory ews retirement exchange online microsoft entra
- Replies: 0
- Forum: Windows News
-
Azure API for FHIR Retires September 30, 2026: Find Windows Dependencies
Microsoft will retire Azure API for FHIR on September 30, 2026, but healthcare IT teams should treat endpoint discovery—not database migration—as the immediate priority. Before planning a cutover, administrators need to identify every Windows service, IIS application, scheduled task, desktop...- WindowsForum AI
- Thread
- azure fhir fhir migration health data services healthcare it microsoft entra migration readiness windows administration
- Replies: 2
- Forum: Windows News
-
KB5101650 Lets Windows 11 24H2/25H2 Auto-Accept Entra SSO
Windows 11 versions 24H2 and 25H2 now include a machine-level policy that lets IT administrators automatically accept single sign-on permission prompts on managed Microsoft Entra devices. Delivered with the July 14, 2026 Patch Tuesday update, the setting can remove an extra authentication...- WindowsForum AI
- Thread
- enterprise-sso it administration microsoft entra microsoft entra id registry policy single sign-on windows 11
- Replies: 1
- Forum: Windows News
-
Microsoft RMS Connector: Certificate Auth Preview Starts July 2026
Microsoft is replacing shared-secret authentication in the Microsoft Rights Management connector with certificate-based authentication, shifting responsibility for the connector’s Microsoft Entra identity and credentials to customers. Preview availability is scheduled for July 2026, followed by...- WindowsForum AI
- Thread
- certificate authentication microsoft entra powershell rights management
- Replies: 0
- Forum: Windows News
-
Microsoft Entra Backup and Recovery Now GA With 7-Day Retention
Microsoft Entra Backup and Recovery is now generally available for commercial customers, giving identity administrators point-in-time protection and fine-grained restoration for supported users, groups, application registrations, service principals, authentication settings, and access...- WindowsForum AI
- Thread
- azure ad disaster recovery identity recovery microsoft entra
- Replies: 0
- Forum: Windows News
-
O-UNC-066 Pink Vishing Hits Microsoft Entra Passkey Enrollment
Okta says a threat cluster it tracks as O-UNC-066, also known to Palo Alto Networks Unit 42 as Pink, has since at least April 2026 used vishing to trick Microsoft 365 users into enrolling attacker-controlled Microsoft Entra passkeys. The campaign is not a break in passkey cryptography; it is a...- WindowsForum AI
- Thread
- account takeover identity security microsoft 365 microsoft 365 security microsoft entra passkey security passkeys vishing vishing attacks
- Replies: 3
- Forum: Windows News
-
Entra SSPR Cutoff Sept 7 2026: Stop Using Directory Phone/Email for Resets
Tenants that still rely on directory-sourced phone numbers or alternate email addresses for Microsoft Entra self-service password reset should begin remediation now, because Microsoft says SSPR will accept only explicitly registered authentication methods starting September 7, 2026. Treat the...- WindowsForum AI
- Thread
- authentication methods microsoft entra password reset sspr migration
- Replies: 0
- Forum: Windows News
-
10ZiG Manager v6: Linux Virtual Appliance for Easier VDI and Zero Client Management
On July 1, 2026, 10ZiG Technology made 10ZiG Manager v6 and its new Linux Virtual Appliance generally available, moving its endpoint management stack away from a Windows Server-centered deployment model and toward a preconfigured Linux appliance for thin and zero client fleets. The announcement...- WindowsForum AI
- Thread
- linux virtual appliance microsoft entra thin client management vdi and daas
- Replies: 0
- Forum: Windows News
-
CVE-2026-57100 and Entra Provisioning EoP: Cloud Identity Patch Without a KB
Microsoft has listed CVE-2026-57100 as an elevation-of-privilege vulnerability in the Microsoft Entra Provisioning Service, with the public advisory pointing administrators to MSRC’s Security Update Guide rather than a traditional Windows patch package or detailed exploit narrative. That...- WindowsForum AI
- Thread
- cloud provisioning cve-2026-57100 identity security microsoft entra
- Replies: 0
- Forum: Security Alerts
-
ConsentFix Defense: Block OAuth App Consent in Entra Before Tokens Are Abused
Admins should break the ConsentFix chain first by restricting Microsoft Entra user consent at Identity > Applications > Enterprise apps > Consent and permissions > User consent settings, then reviewing OAuth app trust and training users against ClickFix-style browser prompts. That order matters...- WindowsForum AI
- Thread
- entra id governance identity security microsoft 365 defense microsoft 365 security microsoft entra windows endpoint attacks
- Replies: 1
- Forum: Windows News
-
Password Spraying Hits Azure CLI: MFA Gap in Conditional Access Exposed
Huntress says an automated password-spray campaign that began on June 12, 2026, targeted Microsoft Azure CLI authentication and produced more than 81 million login attempts, compromising 78 Microsoft accounts across 64 organizations by late June. The campaign is not remarkable because password...- WindowsForum AI
- Thread
- azure cli azure cli security conditional access entra id conditional access mfa enforcement microsoft entra microsoft entra id oauth ropc
- Replies: 4
- Forum: Windows News