Skip to content

other

Microsoft Entra ID

Microsoft Entra ID (formerly Azure Active Directory) is Microsoft's cloud-based identity and access management service for enterprise applications.

Known aliases

  • Azure Active Directory
  • Azure AD
  • Entra
  • Entra ID
  • Microsoft Entra

Relationships

No evidence-backed relationships are recorded.

Current stories

build2 publishers

CloudWatch Omni opens incident investigation to staff without AWS console access

AWS's CloudWatch Omni, generally available since September 23, lets Okta and Entra ID users investigate incidents without AWS console access. CloudWatch dashboard sharing has let outsiders view prebuilt graphs since 2020, so what Omni adds is the investigation itself, one of the reasons teams paid for third-party platforms.

Publishers:dev.toinfoq.com

Reality

Evidence50
Adoption
Insufficient
Hype gap+20
Incentives60
Confidence55
security5 publishers

Stolen logins, not a SaaS breach: nine enterprises' Entra directories are now for sale

A seller using the name TheHatman is offering employee directory exports from nine named enterprises. Hudson Rock ties the theft to infostealer credentials, not a compromise of the provider.

Perspective Coverage

5 publishers
Builder
Builder 25%
Operator
Operator 61%
Investor
Investor 14%

Reality

Evidence55
Adoption
Insufficient
Hype gap+30
Incentives50
Confidence60
security5 publishers

Six 10.0s in the control plane, and nothing in your patch queue to show for it

Microsoft shipped 22 updates, six of them scored 10.0, mostly in Entra ID, Exchange Online and Azure. Fixed server-side is not the same as verified in your tenant.

Perspective Coverage

5 publishers
Builder
Builder 20%
Operator
Operator 65%
Investor
Investor 15%

Reality

Evidence62
Adoption
Insufficient
Hype gap+40
Incentives55
Confidence55
security5 publishers

CISA ran the same tradecraft at two organisations; only the water utility caught it

Detection at the first hop forced CISA's red team onto donated access at Organization B. It did not stop the team reaching the same sensitive systems it reached at Organization A.

Perspective Coverage

5 publishers
Builder
Builder 39%
Operator
Operator 53%
Investor
Investor 8%

Reality

Evidence76
Adoption
Insufficient
Hype gap+12
Incentives35
Confidence72
security3 publishers

PREY-0058 phones executives to harvest Microsoft 365 session tokens

Arctic Wolf says the cluster it tracks as PREY-0058 deploys no malware at all. A call from fake IT leads to a proxied login page, and the stolen session token comes back from inside the victim's own ASN.

Perspective Coverage

3 publishers
Builder
Builder 17%
Operator
Operator 75%
Investor
Investor 8%

Reality

Evidence62
Adoption
Insufficient
Hype gap+15
Incentives
Insufficient
Confidence60
security6 publishers

Storm-3121 callers demand an urgent passkey update to harvest Microsoft 365 session tokens

Microsoft has tracked passkey- and SSO-themed help desk impersonation since May 2026, with the calls steering employees into adversary-in-the-middle proxies and device-code grants that hand over live Microsoft 365 sessions.

Perspective Coverage

6 publishers
Builder
Builder 28%
Operator
Operator 62%
Investor
Investor 10%

Reality

Evidence58
Adoption
Insufficient
Hype gap+10
Incentives45
Confidence60

Earlier coverage

  1. Revoking the stolen tokens left GhostCode's Intune device inside the tenant

    Leadership · September 20, 2026 · 1 publisher

  2. Defender for Identity scores dormant AD accounts against a 90-day logon threshold

    Security · September 20, 2026 · 1 publisher

  3. Six OAuth steps run before an MCP client makes its first tool call

    Build · September 18, 2026 · 1 publisher

  4. Protected Resource Metadata lets an MCP client discover the sign-in flow behind a 401 -- but Entra can still block the token

    Build · September 18, 2026 · 1 publisher

  5. AWS runs four JWT claim gates in one Lambda before an MCP tool call reaches its data

    Build · September 17, 2026 · 1 publisher

  6. MRH Trowe ran 400 employees on self-service agents for about $14 a seat in month one

    Build · September 17, 2026 · 1 publisher

  7. Rolling back the update that broke RDS also removes September's 9.8-rated RDS fix

    Build · September 14, 2026 · 1 publisher

  8. Oracle 26ai moves row and cell authorisation out of application code and into data grants

    Build · September 14, 2026 · 1 publisher

  9. Windows 365 flags a Cloud PC Provisioned before Intune has installed Teams

    Build · September 13, 2026 · 1 publisher

  10. An external app with user consent reads mail without holding an account in the tenant

    Build · September 13, 2026 · 1 publisher

  11. Claude for Windows ships Entra Continuous Access Evaluation switched on by default

    Build · September 10, 2026 · 1 publisher

  12. Session cookies outnumber plaintext passwords four to one in BigBear 2.0's panel

    Leadership · September 10, 2026 · 1 publisher

  13. Scattered Spider talks help desks into moving MFA onto attacker-controlled devices

    Security · September 9, 2026 · 1 publisher

  14. BigBear 2.0 breaks WebAuthn in the browser to force a relayable MFA fallback

    Build · September 8, 2026 · 1 publisher

  15. Slim Spider lifted crypto custody keys out of a Brazilian bank's cloud secret manager

    Security · September 8, 2026 · 1 publisher

  16. Flare puts 46 percent of corporate stealer-log credentials on likely unmanaged devices

    Security · September 4, 2026 · 1 publisher

  17. A GTK app fetches the per-resource .rdp files FreeRDP needs to reach Azure Virtual Desktop

    Build · September 4, 2026 · 1 publisher

  18. Microsoft patched an exploited Entra ID RCE on its own side of the tenant boundary

    Security · August 28, 2026 · 1 publisher

  19. NovaCookies turns an MFA approval into a live Microsoft 365 session for $320

    Build · August 27, 2026 · 1 publisher

  20. Same-day GPT-5.6 on Azure kills the parity argument, leaving auth and residency to decide

    Build · August 25, 2026 · 1 publisher

  21. Bind the consent policy, not the admin role: Entra's answer to the agent consent queue

    Build · August 25, 2026 · 1 publisher

  22. Kubernetes Secrets are a distribution problem, and the database is where it shows

    Product · August 24, 2026 · 1 publisher

  23. Enterprise security reviews went from 20 questions to hundreds of rows, and vendors pay first

    Leadership · August 21, 2026 · 1 publisher

  24. A CVSS 10.0 RCE in Entra ID was exploited in the wild, and there was nothing to patch

    Security · August 21, 2026 · 1 publisher

  25. CrowdStrike buys SGNL, and standing privilege becomes a line item you have to defend

    Leadership · August 20, 2026 · 1 publisher

  26. 81 million attempts, 78 accounts: ROPC is where "we have MFA" stops being true

    Build · August 19, 2026 · 1 publisher

  27. AWS moves agent authorization out of the agent and into the plumbing

    Build · August 19, 2026 · 1 publisher

  28. "Work PC" beats DESKTOP-XXXXXXXX: Entra device-join detection needs a new anchor

    Security · August 18, 2026 · 1 publisher

  29. Storm-0501's first move is deleting your resource locks, not encrypting your disks

    Security · August 18, 2026 · 1 publisher

  30. Cavern's DNS Coin-Flip: When Google Apps Script Becomes Rotatable C2 Plumbing

    Security · August 18, 2026 · 1 publisher

  31. Three permission problems wearing one service principal: why published agents return 403

    Build · August 15, 2026 · 1 publisher