Vue normale

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.
À partir d’avant-hier4sysops

Microsoft will enforce WAM for delegated Graph PowerShell sessions

Par : IT News
28 août 2026 à 10:10
Microsoft will enforce WAM for delegated Graph PowerShell sessions
Microsoft is preparing to eliminate browser-based delegated sign-ins for interactive Microsoft Graph PowerShell sessions that use the Microsoft Graph Command Line Tools application. Administrators who rely on this workflow should move to the Web Account Manager (WAM), app-only authentication, or tenant-specific app registrations before Microsoft applies the service-side enforcement.

Source

Microsoft seeks feedback on Exchange Online’s legacy identifiers

Par : IT News
28 août 2026 à 10:10
Microsoft seeks feedback on Exchange Online’s legacy identifiers
Microsoft is asking customers how they use `ObjectGuid`, `SamAccountName`, and `DistinguishedName` before deciding whether to continue supporting all three in Exchange Online. The directory modernization review could affect scripts, provisioning systems, reporting, integrations, and administrative workflows, but Microsoft has not yet decided.

Source

Microsoft Graph permissions get narrower

Par : IT News
26 août 2026 à 11:28
Microsoft Graph permissions get narrower
Microsoft is adding narrower Microsoft Graph permissions that can reduce the damage from over-privileged Microsoft 365 applications, but the security benefit depends on administrators discovering and adopting them. The new scopes include separate permissions for creating users, updating existing users, and registering applications, replacing broader access such as `User.ReadWrite.All` and `Application.ReadWrite.All`.

Source

ChatGPT Work can now log in to websites without seeing your passwords

Par : IT News
26 août 2026 à 11:28
ChatGPT Work can now log in to websites without seeing your passwords
ChatGPT Work can now cross website login screens on the web and mobile, allowing its cloud browser to complete tasks inside authenticated accounts. Users enter credentials and two-factor codes directly into a secure form, while ChatGPT remains unable to see or store them—a change that expands the security boundary from public web browsing to active account sessions.

Source

Entra CAE gives service principals an instant token kill switch

Par : IT News
26 août 2026 à 11:28
Entra CAE gives service principals an instant token kill switch
Microsoft Entra administrators can now use Continuous Access Evaluation (CAE) to invalidate a service principal’s bearer token on the next resource request instead of waiting up to 90 minutes for it to expire. The most practical emergency option is disabling the service principal itself, which returns HTTP 401 without requiring a Workload Identity Premium license.

Source

Apple keeps Hide My Email on icloud.com after pushback

Par : IT News
25 août 2026 à 19:18
Apple keeps Hide My Email on icloud.com after pushback
Apple has abandoned its planned domain change for iCloud+ Hide My Email after users and developers warned that moving aliases to private.icloud.com would make them easier for websites to block. Sign in with Apple will still adopt private.icloud.com for new relay addresses later this year.

Source

Mirage2FA hijacks 4,500 Microsoft 365 organizations despite MFA

Par : IT News
25 août 2026 à 17:42
Mirage2FA hijacks 4,500 Microsoft 365 organizations despite MFA
Mirage2FA has potentially compromised 4,532 organization email domains between 2024 and 2026, using phishing-as-a-service infrastructure to steal Microsoft 365 credentials, 2FA codes, and active session cookies. The campaign’s estimated 48% compromise rate shows why conventional MFA may not protect accounts when attackers proxy the entire sign-in process.

Source

Entra ID memberOf retirement exposes silent group and agent-account risks

Par : IT News
25 août 2026 à 12:33
Entra ID memberOf retirement exposes silent group and agent-account risks
Microsoft Entra will retire the `memberOf` operator on November 3, 2026, and affected dynamic groups, administrative units, and entitlement policies will freeze without an obvious error. Organizations already know the deadline from the warning that Entra ID dynamic memberships will freeze; the latest migration guidance highlights less visible risks involving nested groups, agent accounts, and attribute permissions.

Source

Microsoft Entra August 2026: Windows SSO control, Exchange attribute writeback, Lifecycle Workflows, and Cloud Sync

Par : IT Experts
25 août 2026 à 00:17
Cloud-managed Exchange attributes architecture (image Microsoft)
Microsoft published its August 2026 Microsoft Entra roundup on 10 August 2026. The generally available items cover Windows single sign-on (SSO) prompt control, Exchange Online attribute writeback through Microsoft Entra Cloud Sync, Lifecycle Workflows testing and cancellation, and optional email during External ID sign-up. Three capabilities remain in public preview: Active Directory device sync with Cloud Sync, automated cleanup of guest accounts that have no sponsor, and Group Policy Object (GPO) backups in Microsoft Entra Domain Services. Lifecycle Workflows, Cloud Sync, and Domain Services are Entra features for joiner-mover-leaver automation, hybrid directory synchronization, and a managed Active Directory domain in Azure.

Source

Entra ID will disable custom CSS layouts: admins face an October 2026 deadline

Par : IT News
21 août 2026 à 15:58
Entra ID will disable custom CSS layouts: admins face an October 2026 deadline
Microsoft will retire a range of custom CSS layout and positioning properties in Entra ID company branding on October 26, 2026. Organizations using those properties must update branded sign-in pages before the deadline or risk elements returning to their default positions.

Source

CVSS 10 Entra ID flaw was exploited, but Microsoft needs no customer action

Par : IT News
21 août 2026 à 11:54
CVSS 10 Entra ID flaw was exploited, but Microsoft needs no customer action
Microsoft has disclosed a CVSS 10.0 remote-code-execution vulnerability in Entra ID, its cloud identity service, and confirmed that attackers exploited it in the wild. CVE-2026-69836 has already been fixed within Microsoft’s service, leaving customers with no patches or configuration changes to apply.

Source

Cloudflare OAuth now lets users reject unnecessary app permissions

Par : IT News
20 août 2026 à 19:54
Cloudflare OAuth now lets users reject unnecessary app permissions
Cloudflare has introduced optional OAuth scopes, allowing users to approve only the permissions an application needs for a specific task instead of accepting or rejecting the entire request. The change is especially useful for MCP servers and other AI agents that may request broad access but do not need every capability in each session.

Source

Microsoft’s Entra SMS warning hides a temporary passkey delay

Par : IT News
19 août 2026 à 16:59
Microsoft’s Entra SMS warning hides a temporary passkey delay
Microsoft’s latest warning to Entra ID administrators omits an important detail: the automatic passkey rollout can be temporarily delayed. This option matters for organizations already planning to migrate away from SMS and voice MFA, which Microsoft has announced will become the default target of a broader Entra SMS authentication cutoff.

Source

81 million Azure login attempts exposed an MFA blind spot

Par : IT News
19 août 2026 à 16:59
81 million Azure login attempts exposed an MFA blind spot
A password-spraying campaign generated more than 81 million login attempts against Azure CLI users in two weeks, compromising 78 accounts while exploiting an authentication path that bypassed MFA. Huntress recorded a 155-fold increase in password spraying during the first half of 2026, with attackers using breached credentials and legacy OAuth behavior rather than simply guessing passwords.

Source

PowerShell finds Entra users missing Conditional Access licenses

Par : IT News
18 août 2026 à 12:16
PowerShell finds Entra users missing Conditional Access licenses
A PowerShell method now gives administrators a practical way to investigate the Entra Conditional Access licensing-gap warning. It compares accounts covered by enabled policies with users holding an Entra ID P1 or P2 service plan, helping identify possible gaps without assuming that Microsoft has begun blocking sign-ins or automatically charging tenants.

Source

TheHatman claims 3.64 million employee records stolen from Azure tenants

Par : IT News
17 août 2026 à 23:06
TheHatman claims 3.64 million employee records stolen from Azure tenants
The alleged theft of 3.64 million employee records from nine companies’ Azure and Entra environments appears more consistent with compromised identities than an Azure vulnerability, Hudson Rock’s analysis suggests. TheHatman is selling the data, but the claims remain unconfirmed: Tata Consultancy Services and Gap say they found no evidence that their corporate systems were breached.

Source

❌
❌