#microsoft-entra

[ follow ]
#cybersecurity
fromTechCrunch
4 days ago
Information security

Hackers are abusing unpatched Windows security flaws to hack into organizations | TechCrunch

Information security
fromThe Hacker News
3 weeks ago

Device Code Phishing Hits 340+ Microsoft 365 Orgs Across Five Countries via OAuth Abuse

An active device code phishing campaign targets Microsoft 365 identities across over 340 organizations in multiple countries, utilizing various deceptive techniques.
fromTNW | Data-Security
4 weeks ago
Information security

The passwordless future is years away.

The cybersecurity industry still heavily relies on legacy passwords despite the promise of passwordless solutions.
fromSecuritymagazine
1 month ago
Information security

Document Protection: Why Hybrid Storage Is the Future of Security

A hybrid approach combining digital storage for frequently accessed documents and physical storage for sensitive historical information provides optimal security and efficiency.
Information security
fromTechCrunch
4 days ago

Hackers are abusing unpatched Windows security flaws to hack into organizations | TechCrunch

Hackers exploited Windows vulnerabilities published by a researcher, affecting Windows Defender and allowing high-level access.
Information security
fromThe Hacker News
3 weeks ago

Device Code Phishing Hits 340+ Microsoft 365 Orgs Across Five Countries via OAuth Abuse

An active device code phishing campaign targets Microsoft 365 identities across over 340 organizations in multiple countries, utilizing various deceptive techniques.
Information security
fromSecuritymagazine
1 month ago

Document Protection: Why Hybrid Storage Is the Future of Security

A hybrid approach combining digital storage for frequently accessed documents and physical storage for sensitive historical information provides optimal security and efficiency.
Privacy professionals
fromSecuritymagazine
5 hours ago

The Privacy-Security Partnership: How We Bend Risk in a Resource Crunch

Fewer privacy practitioners feel confident in meeting laws, while resource shortages and compliance challenges increase stress in the field.
#microsoft
Marketing tech
fromAxios
14 hours ago

Microsoft wants to build the infrastructure behind the AI internet

Microsoft is creating a two-sided marketplace to compensate publishers for content used by AI products, ensuring fair use and collaboration.
World news
fromTheregister
1 week ago

Microsoft hints at bit bunkers for war zones

Microsoft is redesigning datacenters in conflict-prone regions due to Iranian attacks targeting Middle Eastern facilities linked to US military operations.
DevOps
fromInfoWorld
5 days ago

Ease into Azure Kubernetes Application Network

Microsoft has introduced an ambient-based service network for AKS to simplify service mesh scaling and management.
Marketing tech
fromAxios
14 hours ago

Microsoft wants to build the infrastructure behind the AI internet

Microsoft is creating a two-sided marketplace to compensate publishers for content used by AI products, ensuring fair use and collaboration.
Privacy technologies
fromThe Verge
6 days ago

Microsoft faces fresh Windows Recall security concerns

A new tool, TotalRecall Reloaded, extracts data from Microsoft's redesigned Recall feature, raising ongoing security and privacy concerns.
European startups
fromTechRepublic
6 days ago

Microsoft Takes Over Key Stargate Site in Latest OpenAI Pullback

Microsoft has taken over data center capacity in Norway originally intended for OpenAI's Stargate project amid OpenAI's spending reductions.
Information security
fromTheregister
4 days ago

Microsoft closes book on rogue Windows Server 2025 upgrades

Microsoft has resolved the Windows Server 2025 upgrade issue, but new problems have emerged with the cumulative update KB5082063.
World news
fromTheregister
1 week ago

Microsoft hints at bit bunkers for war zones

Microsoft is redesigning datacenters in conflict-prone regions due to Iranian attacks targeting Middle Eastern facilities linked to US military operations.
DevOps
fromInfoWorld
5 days ago

Ease into Azure Kubernetes Application Network

Microsoft has introduced an ambient-based service network for AKS to simplify service mesh scaling and management.
DevOps
fromInfoWorld
4 days ago

When cloud giants neglect resilience

Cloud outages highlight reliability issues as providers prioritize cost-cutting over service stability, raising questions about acceptable levels of unreliability.
fromComputerworld
5 days ago

Microsoft Teams cheat sheet: How to get started

Using the Mic button and dropdown, you can select your audio devices, including your speaker volume. In most cases, Teams selects this correctly, but if you want to switch to a Bluetooth or USB headset, for instance, choose the right device from the Speaker and Microphone section of the right pane.
Remote teams
DevOps
fromInfoQ
5 days ago

AWS Launches Agent Registry in Preview to Govern AI Agent Sprawl Across Enterprises

AWS Agent Registry provides a centralized catalog for managing AI agents, tools, and skills across organizations, addressing agent sprawl and compliance issues.
DevOps
fromAzure DevOps Blog
6 days ago

One-click security scanning and org-wide alert triage come to Advanced Security - Azure DevOps Blog

New capabilities in Azure DevOps simplify application security with one-click CodeQL setup and a unified alerts experience for security teams.
#ai-governance
Information security
fromComputerWeekly.com
5 days ago

Cyber Essentials closes the MFA loophole but leaves some organisations adrift | Computer Weekly

Multi-factor authentication becomes mandatory under Cyber Essentials v3.3, with no exceptions for organizations failing to implement it.
#ai
Privacy technologies
fromComputerWeekly.com
2 weeks ago

Identity and AI: Questions of data security, trust and control | Computer Weekly

AI-driven identity solutions improve access control but raise compliance, privacy, and ethical concerns that organizations must address.
fromSecurityWeek
3 weeks ago
Artificial intelligence

Silent Drift: How LLMs Are Quietly Breaking Organizational Access Control

AI assistance in policy as code can introduce serious flaws, leading to incorrect access permissions despite syntactically valid policies.
Privacy technologies
fromComputerWeekly.com
2 weeks ago

Identity and AI: Questions of data security, trust and control | Computer Weekly

AI-driven identity solutions improve access control but raise compliance, privacy, and ethical concerns that organizations must address.
Artificial intelligence
fromSecurityWeek
3 weeks ago

Silent Drift: How LLMs Are Quietly Breaking Organizational Access Control

AI assistance in policy as code can introduce serious flaws, leading to incorrect access permissions despite syntactically valid policies.
Information security
fromThe Hacker News
4 days ago

Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched

Threat actors are exploiting three vulnerabilities in Microsoft Defender for elevated privileges, with one flaw already addressed by Microsoft.
Information security
fromInfoWorld
1 week ago

Curity looks to reinvent IAM with runtime authorization for AI agents

Traditional IAM tools are inadequate for managing agent access, which is ephemeral and complex, requiring a new approach to runtime enforcement.
Information security
fromTheregister
6 days ago

Ancient Excel bug comes out of retirement for active attacks

A 17-year-old critical Excel vulnerability is actively being exploited, prompting CISA to issue a patch deadline for federal agencies.
DevOps
fromInfoWorld
3 weeks ago

Azure's new AI modernization tools

Microsoft's Azure Copilot aids in application migration and modernization, addressing technical debt and improving cloud infrastructure management.
#microsoft-365-copilot
Privacy professionals
fromArs Technica
1 month ago

Federal cyber experts called Microsoft's cloud a "pile of shit," approved it anyway

Microsoft's Government Community Cloud High received federal cybersecurity approval despite documented security concerns and inadequate documentation, following years of failed security assessments.
Privacy technologies
fromAzure DevOps Blog
1 month ago

Authentication Tokens Are Not a Data Contract - Azure DevOps Blog

Authentication tokens should only validate authorization, not serve as data interfaces; upcoming encryption will make token payloads unreadable, breaking applications that decode token claims.
#identity-management
fromThe Hacker News
1 week ago
Information security

Shrinking the IAM Attack Surface through Identity Visibility and Intelligence Platforms (IVIP)

Enterprise IAM faces fragmentation, leading to Identity Dark Matter and a significant gap in visibility and security oversight.
Information security
fromThe Hacker News
1 week ago

Shrinking the IAM Attack Surface through Identity Visibility and Intelligence Platforms (IVIP)

Enterprise IAM faces fragmentation, leading to Identity Dark Matter and a significant gap in visibility and security oversight.
DevOps
fromInfoWorld
3 weeks ago

Rethinking VM data protection in cloud-native environments

KubeVirt enables Kubernetes to manage both VMs and containers, requiring new strategies for VM lifecycle management and data protection.
fromTechzine Global
1 month ago

DataBahn and Microsoft accelerate SIEM deployment through integration

DataBahn's AI-driven connectors automatically normalize, enrich, and route telemetry from more than 500 sources to Microsoft Sentinel. DataBahn's Cruz AI engine determines which data to send to the analytics tier and which to the Sentinel data lake for long-term storage. Customers report cost savings of up to 60 percent on Sentinel ingestion thanks to this intelligent tiering mechanism.
Business intelligence
Artificial intelligence
fromComputerWeekly.com
1 month ago

Microsoft Cowork: One data store for all your M365 assets | Computer Weekly

Microsoft launches Cowork, an AI tool combining Anthropic's agentic model with Microsoft 365 in a new E7 subscription tier priced at $99 per user, featuring Work IQ context engine for enterprise data access.
fromMedium
1 month ago

Mastering Azure Governance: Why It Matters and How to Get Started

Azure Governance is the set of policies, processes, and technical controls that ensure your Azure environment is secure, compliant, and well-managed. It provides a structured approach to organizing subscriptions, resources, and management groups, while defining standards for naming, tagging, security, and operational practices.
DevOps
Privacy technologies
fromTheregister
1 month ago

Microsoft tightens Authenticator checks on Android and iOS

Microsoft automatically removes Entra credentials from jailbroken and rooted iOS and Android devices, with enforcement beginning on Android now and iOS in April 2026, completing by July 2026.
European startups
fromTechzine Global
1 month ago

Microsoft 365 E7 unveiled: biggest licensing change in ten years

Microsoft launches Microsoft 365 E7 Frontier Worker Suite on May 1, combining Microsoft 365 E5, Microsoft 365 Copilot, and Agent 365 for $99 per user per month, representing the largest release since E5 in 2015.
Information security
fromTechRepublic
3 weeks ago

Microsoft 365 Under Siege: Phishing Campaign Bypasses MFA Across 5 Countries

A sophisticated phishing campaign exploiting Microsoft 365 accounts has affected over 340 organizations across five countries using a legitimate OAuth feature.
Privacy technologies
fromTechzine Global
1 month ago

Windows Hello gets passkey support for Entra accounts

Microsoft is introducing passkey support with Windows Hello for Microsoft Entra sign-in, enabling passwordless authentication resistant to phishing attacks on Windows devices.
European startups
fromTheregister
1 month ago

Microsoft 365 confirms new premium tier with a premium price

Microsoft launches E7 subscription tier at $99 per user per month on May 1, bundling Microsoft 365 E5, Copilot, and Agent 365 for enterprise AI agent management.
DevOps
fromComputerWeekly.com
1 month ago

Azure Local Disconnected looks the part for sovereignty. It isn't. | Computer Weekly

Microsoft's Azure Local 'Disconnected Operations' General Availability announcement masks a controlled-access preview requiring Microsoft approval, validated business need, approved hardware, and enterprise agreements rather than true production-ready availability.
Tech industry
fromTechRepublic
2 months ago

Microsoft Overhauls Security Leadership as AI Expands Enterprise Attack Surface

Microsoft reorganized security leadership, placing security and engineering quality directly under CEO oversight to strengthen core system protection amid accelerating AI adoption.
#ai-security
Information security
fromTechzine Global
4 weeks ago

Microsoft Secures AI Agents with Defender, Entra, and Purview

Microsoft introduces new features to secure AI agents, emphasizing the need for a dedicated security layer for their management and protection.
Information security
fromTechzine Global
4 weeks ago

Microsoft Secures AI Agents with Defender, Entra, and Purview

Microsoft introduces new features to secure AI agents, emphasizing the need for a dedicated security layer for their management and protection.
Tech industry
fromTheregister
2 months ago

Microsoft's shift to cloud management sw brings concerns

Microsoft will deprecate SCOM management packs for SQL Server Reporting Services, Power BI Report Server and Analysis Services; support and updates end January 2027.
Business intelligence
fromBusiness Insider
1 month ago

Microsoft is considering a new AI-loaded software bundle for Microsoft 365, sources say

Microsoft is considering launching E7, a premium AI-enhanced enterprise productivity bundle priced up to $99 per user monthly, featuring Copilot and Agent 365.
Artificial intelligence
fromTheregister
1 month ago

Microsoft reportedly eyes E7 tier for AI agents

Microsoft plans to introduce an E7 subscription tier bundling Copilot and Agent 365 tools, priced at approximately $99 monthly, to license AI agents as digital employees requiring identities, email accounts, and policy controls.
fromTheregister
2 months ago

Microsoft sets Copilot agents loose on your OneDrive files

Microsoft has made OneDrive agents generally available, allowing users to query multiple documents simultaneously through Copilot instead of just one at a time. Users can select up to 20 files and create an agent, saved as a .agent file in OneDrive. Rather than teasing information out of individual documents, Microsoft says users can make cross-document queries, including "What decisions have we made so far?" and "What risks keep coming up?" The agent then generates a response based on the documents' content.
Tech industry
#microsoft-intune-security
Information security
fromTechzine Global
1 month ago

Major warning: Secure your Microsoft environment

CISA warns organizations to strengthen Microsoft Intune security after attackers exploited the platform in a Stryker cyberattack, gaining administrative access and disrupting healthcare operations.
Information security
fromTheregister
1 month ago

Microsoft Intune: Lock it down, warn feds after Stryker

Iran-linked Handala attacked Stryker using compromised Microsoft Intune to wipe devices; CISA urges companies to implement least privilege access controls and follow Microsoft security best practices.
Tech industry
fromInfoWorld
2 months ago

Azure outage disrupts VMs and identity services for over 10 hours

A policy change blocking public read access on Microsoft-managed storage caused an over-10-hour Azure outage affecting VM deployments, managed identities, and developer pipelines.
fromTheregister
1 month ago

MS update kills Microsoft account sign-ins in Windows 11

This issue occurs when the device enters a specific network connectivity state, and may resolve on its own. A restart should also fix it, provided the device is online at the time.
Information security
Tech industry
fromTheregister
2 months ago

Microsoft ends some standalone SharePoint and OneDrive plans

Microsoft is retiring standalone SharePoint Online and OneDrive for Business Plan 1 and Plan 2 SKUs, urging customers toward Microsoft 365 suites.
Information security
fromComputerWeekly.com
1 month ago

Beyond integration theatre: Building stronger cyber platforms | Computer Weekly

Integration layers between security platforms, not the platforms themselves, have become the primary enterprise security risk requiring rigorous governance of delegated trust.
#microsoft-teams
Tech industry
fromTheregister
2 months ago

Microsoft rushes out cloud storage fix after January update

Out-of-band Windows update fixes Outlook and other apps becoming unresponsive when using cloud-backed storage after the January 2026 Security Update; administrators should install it.
fromTechzine Global
1 month ago

Okta launches platform to secure AI agents

Only 22 percent of organizations treat AI agents as independent, identity-bearing entities, while 88 percent have already dealt with suspected or confirmed security incidents involving AI agents. Ninety percent of AI usage occurs through unauthorized personal accounts, with an average of 223 shadow AI incidents per month.
Information security
Tech industry
fromThe Mirror US
2 months ago

Microsoft users fume as 365 and Outlook down for thousands in middle of work day

Microsoft 365 suffered widespread outages affecting Outlook, Microsoft Defender, and Purview, with over 12,000 reports at 4:30 p.m. EST and Microsoft investigating infrastructure issues.
DevOps
fromSecurityWeek
1 month ago

AWS Expands Security Hub Into a Cross-Domain Security Platform

AWS Security Hub Extended integrates AWS security tools and curated third-party solutions into a unified mini-SOC platform for simplified enterprise security management across multiple domains.
fromAzure DevOps Blog
1 month ago

Temporary rollback: build identities can access Advanced Security: read alerts again - Azure DevOps Blog

We restricted API access for build identities as a security improvement but failed to provide an early notice for customers that relied upon this for various automations. We're rolling it back temporarily. The restriction will be re-enforced on April 15, 2026.
Information security
Information security
fromTechzine Global
1 month ago

Red Access turns any firewall into a full SSE platform

Red Access launches firewall-native SSE that adds Security Service Edge capabilities to existing firewalls without requiring replacement, agents, or browser changes, deploying up to 80 percent faster than traditional SSE platforms.
Information security
fromTechRepublic
1 month ago

Hackers Pose as IT Staff in Microsoft Teams to Install Malware

Attackers impersonate Microsoft Teams and IT personnel to deliver A0Backdoor malware through malicious MSI installers, using social engineering and DLL sideloading techniques to establish persistent network access.
Information security
fromSecurityWeek
2 months ago

Microsoft Moves Closer to Disabling NTLM

NTLM authentication will be disabled by default in upcoming Windows Server and client releases, requiring explicit re-enablement and migration to Kerberos.
Information security
fromTechCrunch
2 months ago

Microsoft 365 hit by outage, preventing access to emails and files | TechCrunch

A Microsoft cloud outage in North America blocks enterprise access to email, files, Teams meetings, and administrator security dashboards.
Information security
fromComputerworld
2 months ago

Microsoft to roll out a 'consent first' model to protect Windows

Microsoft will default Windows to a consent-first model, allowing only explicitly approved, properly signed apps while giving users visibility and control over permissions.
Information security
fromComputerworld
2 months ago

New phishing campaign tricks employees into bypassing Microsoft 365 MFA

Attackers trick employees into registering a hacker-controlled device via OAuth device authorization, granting persistent access to Microsoft accounts and bypassing MFA.
Information security
fromthehackernews.com
2 months ago

Orchid Security Introduces Continuous Identity Observability for Enterprise Applications

Continuous identity observability uncovers embedded credentials, application-level authorization, and unmanaged identity paths to eliminate Identity Dark Matter and reduce unseen identity risk.
fromThe Hacker News
2 months ago

Microsoft Patches 59 Vulnerabilities Including Six Actively Exploited Zero-Days

Of the 59 flaws, five are rated Critical, 52 are rated Important, and two are rated Moderate in severity. Twenty-five of the patched vulnerabilities have been classified as privilege escalation, followed by remote code execution (12), spoofing (7), information disclosure (6), security feature bypass (5), denial-of-service (3), and cross-site scripting (1). It's worth noting that the patches are in addition to three security flaws that Microsoft has addressed in its Edge browser since the release of the January 2026 Patch Tuesday update,
Information security
Information security
fromSecuritymagazine
1 month ago

From the Outside In: A Smarter Approach to Vendor Access

Organizations should shift from employee-centric access control to perimeter-focused security strategies to better manage risks from external vendors, contractors, and temporary workers.
fromTechRepublic
2 months ago

Microsoft: Critical Windows Admin Center Flaw Allows Privilege Escalation

A newly disclosed Windows Admin Center flaw carries a CVSS score of 8.8 and could let an authorized user quietly escalate privileges across enterprise environments. The vulnerability affects WAC version 2.6.4 and, if exploited, may grant sweeping administrative control over the very systems it was built to manage. "Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network," Microsoft said in its advisory.
Information security
Information security
fromComputerworld
2 months ago

Microsoft handed over BitLocker keys to law enforcement, raising enterprise data control concerns

Recovery keys backed up to Microsoft's cloud can be provided to law enforcement under warrant, enabling access to BitLocker-encrypted devices.
[ Load more ]