CIO Brief: Server-Side Fixes, Shared Responsibility and Identity Risk
The short version: In August 2026, Microsoft fixed several critical flaws in Entra ID — its cloud sign-in system — including one with the maximum severity score of 10. Microsoft fixed them on its side, and customers didn't need to install anything. But "fixed by the provider" doesn't mean "no questions to ask."
Shared responsibility for cloud identity
Microsoft secures the Entra ID platform. You control who has access, what applications and automations can do, and whether you'd notice misuse. When a platform flaw appears, your configuration determines how much damage it could have caused — and your monitoring determines whether you'd know.
The business impact
- Potential exposure before a fix, even if no exploitation was found.
- Concentration risk: identity platforms protect everything else.
Questions to ask your team
- Do we review Microsoft's security advisories for cloud services, not just software we install?
- Would we have seen unauthorized changes to administrators, applications or account provisioning?
- Which automated systems can create or change user accounts, and what permissions do they have?
- How quickly can we confirm "we weren't affected" when a provider flaw is announced?
What good looks like
Monitoring for privileged changes, least-privilege automation, a process for reviewing provider advisories and a standard way to document whether you were affected.
The decision
For every critical cloud provider advisory, ask for a short written answer: could it have affected us, and how do we know? It builds a habit that pays off when a flaw is exploited.