Find a story
Search Spins
Search titles, summaries, and missing voices across published articles — press releases, announcements, and media coverage.
4 results for “Entra ID”
Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
A security researcher demonstrated that malware with existing access to a signed-in Windows session can abuse Windows Hello for Business cryptographic keys to gain persistent, unauthorized access to Microsoft Entra ID—including device registration and Primary Refresh Token acquisition—bypassing intended authentication safeguards.
Aug 7, 2026
Microsoft Entra ID gets passkeys default authentication starting September
Microsoft will make passkeys the default authentication method for its Entra ID enterprise identity service beginning September 2026, shifting away from legacy multi-factor authentication (MFA) methods.
Jul 14, 2026
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
Attackers are exploiting OAuth client ID spoofing to validate stolen Microsoft Entra ID credentials without triggering standard sign-in telemetry, enabling stealthy account enumeration and credential validation.
Jul 14, 2026
Breach at the Beach: Play the Ultimate Entra ID CTF
Varonis launched a free, hands-on Capture the Flag (CTF) exercise called 'Breach at the Beach' to teach cybersecurity defenders how to detect and investigate real-world Entra ID (formerly Azure AD) attack techniques.
Jul 13, 2026