Vue normale

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.
Aujourd’hui — 14 septembre 2026IT

Entra blocks self-disable attempts with a misleading Graph error

Par : IT News
14 septembre 2026 à 11:31
Entra blocks self-disable attempts with a misleading Graph error
Microsoft Entra ID prevents a signed-in administrator from disabling the account currently being used, but reports the failure as “Property accountEnabled is invalid.” The restriction applies in both Microsoft Graph PowerShell and the Entra admin center, meaning administrators should not waste time troubleshooting the SDK or request body.

Source

À partir d’avant-hierIT

Android can now move passwords and passkeys without CSV files

Par : IT News
10 septembre 2026 à 19:27
Android can now move passwords and passkeys without CSV files
Google has introduced an Android-level password manager switching feature that transfers passwords and passkeys directly between supported apps, removing the need to handle unencrypted CSV exports. The transfer flow is available on Android 8 and newer and currently supports Google Password Manager, 1Password, Bitwarden, and Dashlane.

Source

Windows 11 build 29661 turns on IAKerb and fixes update failures

Par : IT News
9 septembre 2026 à 12:19
Windows 11 build 29661 turns on IAKerb and fixes update failures
Windows 11 Insider build 29661.1000 enables IAKerb by default, giving client devices another way to authenticate when they cannot directly reach a domain controller. The Experimental (Future Platforms) release also fixes cursor glitches and Windows Update error 0x80070005, which had blocked some Insiders from receiving newer builds.

Source

Critical FreeIPA flaw lets anonymous LDAP clients become administrators

Par : IT News
8 septembre 2026 à 16:04
Critical FreeIPA flaw lets anonymous LDAP clients become administrators
A critical FreeIPA vulnerability lets an unauthenticated LDAP client create a new Kerberos identity and place it in the administrators group on an otherwise default installation. The attack combines CVE-2026-76578 with a 389 Directory Server access-control flaw, CVE-2026-76560, and carries a preliminary CVSS score of 9.8.

Source

Entra ID CAE covers far fewer Microsoft 365 sign-ins than expected

Par : IT News
8 septembre 2026 à 10:55
Entra ID CAE covers far fewer Microsoft 365 sign-ins than expected
Microsoft’s Continuous Access Evaluation (CAE) can revoke access before a normal one-hour token expires, but its protection is far from universal across Microsoft 365. An analysis of 740 first-party resource tokens found that only 33 included the CAE claim, while some Microsoft clients still request ordinary tokens even when connecting to CAE-capable services.

Source

An infostealer log can bypass MFA—respond within the first hour

Par : IT News
3 septembre 2026 à 19:26
An infostealer log can bypass MFA—respond within the first hour
A corporate password found in an infostealer log should be treated as a possible live identity compromise, not just an old credential leak. Security teams need to determine within minutes whether the data includes active browser sessions, identity-provider access, VPN or RDP credentials, and then revoke sessions and reset passwords before attackers can use them.

Source

CrowdStrike’s Agentic Identity Provider gives AI agents an identity

Par : IT News
3 septembre 2026 à 19:26
CrowdStrike’s Agentic Identity Provider gives AI agents an identity
CrowdStrike has introduced its Agentic Identity Provider, a system designed to identify and manage autonomous AI agents before they receive access to enterprise resources. Announced at Fal.Con 2026, the service uses Falcon Guardian to discover agents as they appear and replaces improvised service accounts and API keys with identities that can be evaluated continuously.

Source

New identity governance and access features in Microsoft Entra

Par : IT Experts
2 septembre 2026 à 23:05
MCP firewall discovered tools rule (image Microsoft)
Microsoft released several generally available and preview updates for Microsoft Entra in September 2026. The changes focus on tenant governance, user-centric access reviews, lifecycle workflow management, passwordless Teams device identities, hybrid identity provisioning, and AI traffic controls. You should also plan for three upcoming changes that affect dynamic group rules, API permissions, and the Security Administrator role.

Source

❌
❌