Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Entra ID & Identity

Articles in Entra ID & Identity.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Entra ID & IdentityIncident Teardowns

How Researchers Broke Into OpenAI in 72 Hours (Sept 2026): A Discourse Bug Plus an Employee-Validation Flaw

On September 18, 2026, NBC News reported that a small cybersecurity company, Hacktron, had broken into OpenAI earlier in the year — gaining access to...

Entra ID & IdentityHow-To & Hardening

How to Audit Third-Party Community and Support Platforms Tied to Your SSO

The Hacktron research into OpenAI combined a flaw in community forum software with a weakness in employee validation. Many organizations run similar...

Entra ID & IdentityIncident Teardowns

Microsoft Patches a CVSS 10.0 Entra ID Flaw (Aug 2026): What Customers Need to Know

In August 2026, Microsoft's Patch Tuesday included fixes for several critical vulnerabilities in Microsoft Entra ID, including one rated the maximum CVSS...

Entra ID & IdentityHow-To & Hardening

How to Review Entra Provisioning Service Permissions After August 2026 Patch Tuesday

August 2026's Entra ID fixes included a critical elevation-of-privilege flaw in the Entra Provisioning Service. Even though Microsoft fixed it server-side,...

Entra ID & IdentityPlatform Changes

Microsoft Entra Agent ID (May 2025): Giving AI Agents Their Own Identities

At Build in May 2025, Microsoft introduced Entra Agent ID, giving AI agents their own identities in the directory. A year later, agents escaping sandboxes made the idea urgent. Here is what Agent ID does and how to govern AI agents like privileged users.

Entra ID & IdentityIncident Teardowns

Marks & Spencer Ransomware (Apr 2025): Scattered Spider Returns to the Help Desk

The April 2025 attack on Marks & Spencer paused online orders for weeks and was expected to cut operating profit by about £300 million. M&S said attackers got in through human error at a third party. Here is the pattern — and how to lock down resets and MFA registration.

Entra ID & IdentityPlatform Changes

Passkeys in Microsoft Authenticator Preview (May 2024): Phishing-Resistant MFA for Everyone

In May 2024, Microsoft previewed device-bound passkeys in Microsoft Authenticator for Entra ID — making phishing-resistant MFA possible on phones employees already carry. Here is how passkeys work, why they defeat modern phishing kits, and how to roll them out.

Entra ID & IdentityIncident Teardowns

MGM Resorts and Scattered Spider (Sept 2023): A Help Desk Call That Cost $100 Million

A phone call to MGM's help desk reportedly led to a ten-day disruption and about $100 million in lost earnings. Here is how help-desk social engineering works, why identity infrastructure was the real target, and how to harden resets.

Entra ID & IdentityDetection & Response

Detecting Suspicious Activity From SSO-Connected Third-Party Platforms

Weaknesses in third-party platforms connected to your SSO can let attackers gain access as employees. These detections help spot misuse.

Entra ID & IdentityCIO Briefings

CIO Brief: Even AI Leaders Get Breached Through Third-Party Software

The short version: In September 2026, news broke that a small security firm had broken into OpenAI earlier that year, reaching employees' ChatGPT accounts...

Entra ID & IdentityDetection & Response

Hunting for Suspicious Entra Provisioning and Service Principal Changes

Identity platform flaws — and attackers who abuse provisioning — can create or modify accounts in ways that look automated. These detections focus on...

Entra ID & IdentityCIO Briefings

CIO Brief: Server-Side Fixes, Shared Responsibility and Identity Risk

The short version: In August 2026, Microsoft fixed several critical flaws in Entra ID — its cloud sign-in system — including one with the maximum severity...

Entra ID & IdentityIncident Teardowns

Entra ID Actor Token Flaw (Sept 2025): A Cross-Tenant Global Admin Bug

In September 2025, security researcher Dirk-jan Mollema published details of a critical flaw in Microsoft Entra ID that could have allowed an attacker to...

Entra ID & IdentityHow-To & Hardening

How to Monitor Entra ID for Cross-Tenant and Undocumented Token Abuse

Cross-tenant and undocumented token flaws are rare but serious. Customers can't prevent provider bugs, but can reduce exposure and improve visibility. Here...

Entra ID & IdentityDetection & Response

Detecting Cross-Tenant Token Abuse: Entra Sign-In Logs and Sentinel KQL

When identity platform flaws limit logging of the initial access, you can still detect what attackers do next. These detections focus on cross-tenant...

Entra ID & IdentityCIO Briefings

CIO Brief: Even Identity Platforms Have Catastrophic Bugs

The short version: In 2025, a researcher found a flaw in Microsoft Entra ID — the system that controls sign-in for Microsoft 365 and Azure — that could have...

Entra ID & IdentityHow-To & Hardening

How to Inventory and Govern AI Agent Identities in Entra ID

AI agents are a fast-growing category of identities with access to company data and systems. Here is how to inventory and govern them in Microsoft Entra ID.

Entra ID & IdentityHow-To & Hardening

AI Agent Identity Governance Checklist

Use this checklist to govern AI agent identities in your organization.

Entra ID & IdentityCIO Briefings

CIO Brief: AI Agents Are the Newest Privileged Users

The short version: AI agents — software that can read your data and take actions on its own — are spreading quickly across companies. In 2025, Microsoft...

Entra ID & IdentityHow-To & Hardening

How to Lock Down Entra ID Password Reset and MFA Re-Registration

Attackers who convince a help desk to reset a password often then register their own MFA method. Locking down password reset and MFA re-registration in...

Entra ID & IdentityDetection & Response

Detecting Help Desk MFA Reset Abuse: Entra Sign-In Logs and Sentinel KQL

After help desk social engineering, attackers typically reset MFA, register their own method and sign in. These detections connect those events.

Entra ID & IdentityCIO Briefings

CIO Brief: Retail Lessons From a £300 Million Cyber Attack

The short version: In 2025, attackers reportedly tricked an IT help desk into resetting access, then shut down Marks & Spencer's online store for weeks. The...

Entra ID & IdentityIncident Teardowns

Oracle Cloud Login Breach Claims (Mar 2025): When the Provider Denies and Customers Rotate

In March 2025, a threat actor using the name "rose87168" claimed to have stolen millions of records from Oracle Cloud's single sign-on (SSO) login...

Entra ID & IdentityHow-To & Hardening

How to Respond When Your Identity or Cloud Provider Is Allegedly Breached

When a credible report claims your identity or cloud provider was breached — but the provider hasn't confirmed it — you still need to act. Here is a...

Page 1 of 5Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.