home.social

#microsoftentra — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #microsoftentra, aggregated by home.social.

fetched live
  1. I also wanted to implement some optional or new #OIDC aspects, in particular enforcement of phishing-resistant authentication using RFC8176 Auth Method Reference and proprietary #MicrosoftEntra Conditional Access AuthContext.

    Also a fully-automated testing pipeline with live #OPNsense, #Keykloak, and #Authentik instance is something I am really exciteted about!

    On that way multiple minor improvements went into the OPNsense core project as well so everyone wins 🙃

  2. I also wanted to implement some optional or new #OIDC aspects, in particular enforcement of phishing-resistant authentication using RFC8176 Auth Method Reference and proprietary #MicrosoftEntra Conditional Access AuthContext.

    Also a fully-automated testing pipeline with live #OPNsense, #Keykloak, and #Authentik instance is something I am really exciteted about!

    On that way multiple minor improvements went into the OPNsense core project as well so everyone wins 🙃

  3. I also wanted to implement some optional or new #OIDC aspects, in particular enforcement of phishing-resistant authentication using RFC8176 Auth Method Reference and proprietary #MicrosoftEntra Conditional Access AuthContext.

    Also a fully-automated testing pipeline with live #OPNsense, #Keykloak, and #Authentik instance is something I am really exciteted about!

    On that way multiple minor improvements went into the OPNsense core project as well so everyone wins 🙃

  4. I also wanted to implement some optional or new #OIDC aspects, in particular enforcement of phishing-resistant authentication using RFC8176 Auth Method Reference and proprietary #MicrosoftEntra Conditional Access AuthContext.

    Also a fully-automated testing pipeline with live #OPNsense, #Keykloak, and #Authentik instance is something I am really exciteted about!

    On that way multiple minor improvements went into the OPNsense core project as well so everyone wins 🙃

  5. Microsoft has fixed CVE-2026-69836 in Entra ID, a CVSS 10.0 vulnerability tied to insecure deserialization.

    According to Microsoft, an unauthorised attacker could have executed code remotely over the network, without prior privileges or user interaction.

    The flaw was found and fixed before the CVE was published, and the company reports no evidence of exploitation in real-world attacks.

    Entra ID customers do no…

    en.hacks.gr/i-microsoft-ekleis

    #MicrosoftEntra #CVE #CloudSecurity #ApplicationSecurity

  6. A critical deserialization vulnerability (CVE-2026-69836) has been actively exploited in Microsoft Entra ID. The flaw could allow unauthorized access to identity and access management functions across Azure, M365, and Dynamics CRM Online.

    #CriticalVulnerability #MicrosoftEntra #IdentitySecurity #Deserialization

    cyberworldops.eu/en/cve-2026-6

  7. A critical deserialization vulnerability (CVE-2026-69836) has been actively exploited in Microsoft Entra ID. The flaw could allow unauthorized access to identity and access management functions across Azure, M365, and Dynamics CRM Online.

    #CriticalVulnerability #MicrosoftEntra #IdentitySecurity #Deserialization

    cyberworldops.eu/en/cve-2026-6

  8. A critical deserialization vulnerability (CVE-2026-69836) has been actively exploited in Microsoft Entra ID. The flaw could allow unauthorized access to identity and access management functions across Azure, M365, and Dynamics CRM Online.

    #CriticalVulnerability #MicrosoftEntra #IdentitySecurity #Deserialization

    cyberworldops.eu/en/cve-2026-6

  9. Millions of Microsoft Entra accounts have been targeted in OAuth client ID spoofing campaigns, allowing attackers to probe usernames, test credentials, and evade common sign-in detections without registering an app or exploiting a vulnerability.

    Listen to this news: hackread.com/microsoft-entra-a

  10. Millions of Microsoft Entra accounts have been targeted in OAuth client ID spoofing campaigns, allowing attackers to probe usernames, test credentials, and evade common sign-in detections without registering an app or exploiting a vulnerability.

    Listen to this news: hackread.com/microsoft-entra-a

    #MicrosoftEntra #OAuth #Cybersecurity #Microsoft #Vulnerability

  11. Millions of Microsoft Entra accounts have been targeted in OAuth client ID spoofing campaigns, allowing attackers to probe usernames, test credentials, and evade common sign-in detections without registering an app or exploiting a vulnerability.

    Listen to this news: hackread.com/microsoft-entra-a

    #MicrosoftEntra #OAuth #Cybersecurity #Microsoft #Vulnerability

  12. Millions of Microsoft Entra accounts have been targeted in OAuth client ID spoofing campaigns, allowing attackers to probe usernames, test credentials, and evade common sign-in detections without registering an app or exploiting a vulnerability.

    Listen to this news: hackread.com/microsoft-entra-a

    #MicrosoftEntra #OAuth #Cybersecurity #Microsoft #Vulnerability

  13. Millions of Microsoft Entra accounts have been targeted in OAuth client ID spoofing campaigns, allowing attackers to probe usernames, test credentials, and evade common sign-in detections without registering an app or exploiting a vulnerability.

    Listen to this news: hackread.com/microsoft-entra-a

    #MicrosoftEntra #OAuth #Cybersecurity #Microsoft #Vulnerability

  14. Device Code Phishing via une page Microsoft légitime — l'URL est correcte, le domaine est réel, et pourtant l'attaque fonctionne. Ça illustre bien pourquoi "vérifier l'URL" ne suffit plus comme réflexe de sécurité : le flux d'authentification lui-même devient le vecteur. La surface d'attaque s'est déplacée vers les protocoles. #infosec #phishing #MicrosoftEntra
    securelist.com/microsoft-devic

  15. If you’ve ever wondered whether your identity architecture is truly your own, you need to see what Spec Kit does with Microsoft Entra. Stop delegating, and start orchestrating decisions that reflect your values and vision.

    Read more 👉 lttr.ai/Ar7ma

    #M365ShowPodcast #MicrosoftEntra #M365Show

  16. 🥩🥩Mr T-Bone tip!🥩🥩[New from Tech Community]
    Fresh Entra updates are here from MrTbone_se 🎉 Dive into June 2026 highlights, smarter security wins, and admin-friendly improvements 🚀🔐

    #MicrosoftEntra #CyberSecurity #MVPBuzz #Security #MicrosoftTechCommunity
    👉👉 tip.tbone.se/LSd2EK [AI generated, Human reviewed]

  17. ----------------

    🎯 Threat Intelligence
    ===================

    Device Code Lab (DCL) is a professional-grade Phishing-as-a-Service (PhaaS) platform designed to exploit the Microsoft Entra OAuth device code flow. The analysis reveals a mature toolkit with extensive post-exploitation and defense evasion capabilities.

    🔹 Technical Overview

    DCL automates device code phishing against Microsoft Entra. Once a victim completes device code authentication, the platform captures tokens and provides operators with a full post-exploitation suite.

    Key Backend API Endpoints (distinctive signatures for log hunting):
    • /api/tokens/{id}/capture-prt — Primary Refresh Token capture via virtual device registration
    • /api/tokens/{id}/prt-refresh — PRT reactivation after token revocation
    • /api/tokens/{id}/ertsauth-cookies — 14-day ESTSAUTH session cookie generation
    • /api/tokens/{id}/refresh-to-resource — FOCI cross-resource pivot
    • /api/tokens/refresh-all — Bulk token refresh across all captured sessions
    • /api/tokens/{id}/message-search — Cross-mailbox KQL sweep
    • /api/landing/deploy/cloudflare — Cloudflare Worker landing page deployment
    • /api/cloaker/{id}/status — Redirector kill switch
    • /api/tokens/dedupe-archive — Deduplication of multi-capture accounts
    • /api/tokens/import/txt — Bulk token import from Telegram notification format

    Infrastructure:
    • api.controltkeusa[.]com — IPs: 104[.]219[.]239[.]125, 172[.]81[.]130[.]130
    • api.babalfashion[.]com — IPs: 67[.]215[.]253[.]44; front: babalfashion[.]com (104[.]21[.]78[.]8, 172[.]67[.]214[.]105)
    • api.skysharegroup[.]com — IPs: 192[.]3[.]225[.]100; front: skysharegroup[.]com (104[.]21[.]85[.]226)

    The platform protects operator accounts with TOTP 2FA. The login flow returns 403 with totp_required: true if TOTP is omitted, mirroring legitimate security practices.

    🔹 Detection Opportunities

    1. First-Time Device Code Authentication (hunt-2025-043): Flags users with no device code auth history in 30 days. Strong behavioral indicator where device code is rarely used legitimately.

    2. FOCI Multi-Resource Token Exchange Burst (hunt-2025-044): Single FOCI-capable client_id exchanging refresh tokens against 3+ distinct resource endpoints within 10 minutes. Direct post-exploitation signature.

    3. Device Code Auth + FOCI Burst (hunt-2025-045): Successful device code auth correlated with FOCI burst for same user within 20 minutes. Highest-confidence signal for completed token theft.

    Attack chain: phishing lure → victim completes device code auth → token captured → FOCI pivot across Microsoft services → persistent access via PRT refresh and ESTSAUTH cookies even after revocation.

    Defenders should note that PRT refresh specifically bypasses token revocation, making detection before the FOCI pivot window the most effective defensive position.

    🔹 ThreatIntel #DeviceCodePhishing #PhaaS #MicrosoftEntra #FOCI

    🔗 Source: newtonpaul.com/blog/device-cod

  18. 🟦 Entra Tenant Governance | Find Configuration Drift

    New preview lets admins detect tenant configuration drift natively across Entra and related services. 🔹

    Define JSON baselines as configuration as code and create scheduled monitors. Monitors run every six hours and produce run summaries and detailed drift objects with property level diffs. Govern external tenants via B2B signals and role based templates from a single admin center. 💡

    💡 Configuration as code baseline
    🔍 Six hour monitor interval
    ⚖️ Cross tenant governance via B2B signals

    ▶︎ hubsite365.com/en-ww/pro-offic

    #MICROSOFTENTRA #IDENTITYSECURITY #ZEROTRUST #CLOUDSECURITY

  19. 🟦 Entra Tenant Governance | Find Configuration Drift

    New preview lets admins detect tenant configuration drift natively across Entra and related services. 🔹

    Define JSON baselines as configuration as code and create scheduled monitors. Monitors run every six hours and produce run summaries and detailed drift objects with property level diffs. Govern external tenants via B2B signals and role based templates from a single admin center. 💡

    💡 Configuration as code baseline
    🔍 Six hour monitor interval
    ⚖️ Cross tenant governance via B2B signals

    ▶︎ hubsite365.com/en-ww/pro-offic

    #MICROSOFTENTRA #IDENTITYSECURITY #ZEROTRUST #CLOUDSECURITY

  20. 🟦 Entra Tenant Governance | Find Configuration Drift

    New preview lets admins detect tenant configuration drift natively across Entra and related services. 🔹

    Define JSON baselines as configuration as code and create scheduled monitors. Monitors run every six hours and produce run summaries and detailed drift objects with property level diffs. Govern external tenants via B2B signals and role based templates from a single admin center. 💡

    💡 Configuration as code baseline
    🔍 Six hour monitor interval
    ⚖️ Cross tenant governance via B2B signals

    ▶︎ hubsite365.com/en-ww/pro-offic

    #MICROSOFTENTRA #IDENTITYSECURITY #ZEROTRUST #CLOUDSECURITY

  21. 🟦 Entra Tenant Governance | Find Configuration Drift

    New preview lets admins detect tenant configuration drift natively across Entra and related services. 🔹

    Define JSON baselines as configuration as code and create scheduled monitors. Monitors run every six hours and produce run summaries and detailed drift objects with property level diffs. Govern external tenants via B2B signals and role based templates from a single admin center. 💡

    💡 Configuration as code baseline
    🔍 Six hour monitor interval
    ⚖️ Cross tenant governance via B2B signals

    ▶︎ hubsite365.com/en-ww/pro-offic

  22. ⚠️ CRITICAL: CVE-2026-42901 in Microsoft Entra (CVSS 10) enables remote privilege escalation via origin validation error. Patch now to prevent full system compromise! Fix: radar.offseq.com/threat/cve-20 #OffSeq #MicrosoftEntra #Vulnerability #Cybersecurity

  23. ⚠️ CRITICAL: CVE-2026-42901 in Microsoft Entra (CVSS 10) enables remote privilege escalation via origin validation error. Patch now to prevent full system compromise! Fix: radar.offseq.com/threat/cve-20 #OffSeq #MicrosoftEntra #Vulnerability #Cybersecurity

  24. ⚠️ CRITICAL: CVE-2026-42901 in Microsoft Entra (CVSS 10) enables remote privilege escalation via origin validation error. Patch now to prevent full system compromise! Fix: radar.offseq.com/threat/cve-20 #OffSeq #MicrosoftEntra #Vulnerability #Cybersecurity

  25. ⚠️ CRITICAL: CVE-2026-42901 in Microsoft Entra (CVSS 10) enables remote privilege escalation via origin validation error. Patch now to prevent full system compromise! Fix: radar.offseq.com/threat/cve-20 #OffSeq #MicrosoftEntra #Vulnerability #Cybersecurity

  26. MFA werkt. Maar niet als de aanvaller nooit om je wachtwoord vraagt.

    EvilTokens is een platform dat phishing als dienst aanbiedt en in vijf weken meer dan 340 Microsoft 365-organisaties in Europa en de VS heeft gecompromitteerd.

    'Peter's Analyse'. Elke dag een nieuwe vraag die je kunt beantwoorden op ccinfo.nl

    Heeft uw organisatie al gecontroleerd of sessietokens een maximale geldigheidsduur hebben?

    #Cybersecurity #Phishing #MicrosoftEntra #ThreatIntelligence #Cyberbeveiliging

  27. MFA werkt. Maar niet als de aanvaller nooit om je wachtwoord vraagt.

    EvilTokens is een platform dat phishing als dienst aanbiedt en in vijf weken meer dan 340 Microsoft 365-organisaties in Europa en de VS heeft gecompromitteerd.

    'Peter's Analyse'. Elke dag een nieuwe vraag die je kunt beantwoorden op ccinfo.nl

    Heeft uw organisatie al gecontroleerd of sessietokens een maximale geldigheidsduur hebben?

    #Cybersecurity #Phishing #MicrosoftEntra #ThreatIntelligence #Cyberbeveiliging

  28. MFA werkt. Maar niet als de aanvaller nooit om je wachtwoord vraagt.

    EvilTokens is een platform dat phishing als dienst aanbiedt en in vijf weken meer dan 340 Microsoft 365-organisaties in Europa en de VS heeft gecompromitteerd.

    'Peter's Analyse'. Elke dag een nieuwe vraag die je kunt beantwoorden op ccinfo.nl

    Heeft uw organisatie al gecontroleerd of sessietokens een maximale geldigheidsduur hebben?

    #Cybersecurity #Phishing #MicrosoftEntra #ThreatIntelligence #Cyberbeveiliging

  29. MFA werkt. Maar niet als de aanvaller nooit om je wachtwoord vraagt.

    EvilTokens is een platform dat phishing als dienst aanbiedt en in vijf weken meer dan 340 Microsoft 365-organisaties in Europa en de VS heeft gecompromitteerd.

    'Peter's Analyse'. Elke dag een nieuwe vraag die je kunt beantwoorden op ccinfo.nl

    Heeft uw organisatie al gecontroleerd of sessietokens een maximale geldigheidsduur hebben?

    #Cybersecurity #Phishing #MicrosoftEntra #ThreatIntelligence #Cyberbeveiliging

  30. 📢⚠️ Microsoft Entra Agent ID flaw allowed privilege escalation and tenant takeover via Service Principal abuse, now fully patched by Microsoft.

    Read: hackread.com/microsoft-entra-a

  31. 📢⚠️ Microsoft Entra Agent ID flaw allowed privilege escalation and tenant takeover via Service Principal abuse, now fully patched by Microsoft.

    Read: hackread.com/microsoft-entra-a

    #CyberSecurity #Vulnerability #Microsoft #MicrosoftEntra #AI

  32. 📢⚠️ Microsoft Entra Agent ID flaw allowed privilege escalation and tenant takeover via Service Principal abuse, now fully patched by Microsoft.

    Read: hackread.com/microsoft-entra-a

    #CyberSecurity #Vulnerability #Microsoft #MicrosoftEntra #AI

  33. 📢⚠️ Microsoft Entra Agent ID flaw allowed privilege escalation and tenant takeover via Service Principal abuse, now fully patched by Microsoft.

    Read: hackread.com/microsoft-entra-a

    #CyberSecurity #Vulnerability #Microsoft #MicrosoftEntra #AI

  34. 📢⚠️ Microsoft Entra Agent ID flaw allowed privilege escalation and tenant takeover via Service Principal abuse, now fully patched by Microsoft.

    Read: hackread.com/microsoft-entra-a

    #CyberSecurity #Vulnerability #Microsoft #MicrosoftEntra #AI

  35. Sicherheitslücke in Microsoft Entra ID: Agent-ID-Administratoren konnten beliebige Dienstprinzipale übernehmen

    Angreifer konzentrieren sich in Microsoft-Entra-ID-Umgebungen zunehmend nicht mehr ausschließlich auf menschliche Administratorkonten. Stattdessen rücken Dienstidentitäten und Rollen der mittleren Verwaltungsebene in den Fokus.

    all-about-security.de/sicherhe

    #microsoft #entraid #agentid #MicrosoftEntra

  36. Microsoft Bolsters Entra with Passkey Support on Windows

    Say goodbye to passwords! Microsoft is bolstering Entra with passkey support on Windows, allowing users to authenticate with a face scan, fingerprint, or PIN for added security and convenience.

    osintsights.com/microsoft-bols

    #PasskeySupport #WindowsHello #MicrosoftEntra #PasswordlessAuthentication #Mfa