Stay ahead with Daily CyberSecurity. We deliver rapid zero-hour alerts and expert analysis on critical vulnerabilities, CVEs, and emerging cyber threats.
Daily CyberSecurity
@DailyCyberSecurity@infosec.exchange
infosec.exchange
Proofpoint details OAuth client ID spoofing, a stealthy account enumeration technique that probes Microsoft Entra ID without a successful sign-in event.
#OAuthSpoofing #EntraID #AccountEnumeration #CloudSecurity #Proofpoint
http://securityonline.info/oauth-client-id-spoofing/?utm_source=mastodon&utm_medium=jetpack_social
Tony Redmond
@TonyRedmond@techhub.social
Writer for Practical365.com. Lead author of the Office 365 for IT Pros eBook. Microsoft MVP.
techhub.social
Microsoft to Stop Providing Telephony-Based Authentication Methods for MFA in February 2027
In an important announcement for all tenants, Microsoft revealed that Entra ID will no longer provide SMS one-time codes or voice calls for MFA challenges after February 1, 2027. Tenants can continue to use telephony-based authentication methods after that date, but only by purchasing a service from a telecom provider. This is arguably the biggest change in Entra ID authentication since mandatory MFA for administrative interfaces – and we have a PowerShell script to help identify the affected accounts.
https://office365itpros.com/2026/07/14/entra-sms-one-time-code/
#EntraID
Frank Carius
@msxfaq@infosec.exchange
Age: 50+ , Microsoft MVP: 20+, IT-Pro, www.msxfaq.de. Lucky finding: CVE-2019-11095
infosec.exchange
#MSXFAQ Simple SAML Sample https://www.msxfaq.de/cloud/authentifizierung/simple_saml_sample.htm - wollten Sie schon immer mal wissen, wie Sie ihre Webseite mit #EntraID #SAML-Tokens absichern können? Eine minimale BeispielApp fordert Token an und zeigt sie an. Was Sie danach weiter draus machen, ist ihre Phantasie.
Frank Carius
@msxfaq@infosec.exchange
Age: 50+ , Microsoft MVP: 20+, IT-Pro, www.msxfaq.de. Lucky finding: CVE-2019-11095
infosec.exchange
#MSXFAQ BreakGlassApp https://www.msxfaq.de/cloud/admin/breakglassapp.htm - Wie wäre eine App mit Secret oder Zertifikat, mit welchem Sie einen vorhandenen #EntraID User zum #GlobalAdmin machen könnten? Quasi als #Notfall-Zugang, wenn der Global Admin nicht mehr funktioniert?
Brian Clark
@deepthoughts10@infosec.exchange
#InfoSec #Cybersecurity #threatintel and Politics. I try my best. Also @deepthoughts10@twitter.com Searchable
infosec.exchange
RE: https://infosec.exchange/@CDubbs/116847680945065797
Create a group called "Device Code Users" and a CA policy that blocks the use of the Device Code authentication flow except for those in the group. #cybersecurity #entraID
Quoting
EntraID PSA: Disable OAuth Device Code flow in your default conditional access policy.
You can search sign-on logs for people using this method to baseline and manage exceptions where appropriate.
Open quoted post
iX Magazin
@iX_Magazin@social.heise.de
IT-News von iX, dem Heise-Magazin für professionelle IT Offizieller Account 🤖 Die meisten Posts sind automatisiert +++ https://www.heise.de/ix/impressum.html
social.heise.de
heise+ | POSIX-Attribute für Entra ID mit Himmelblau anlegen
Werden vor einer Entra ID-Umstellung Linux-Clients und -Fileserver genutzt, gelten dort POSIX-Berechtigungen. Ein eigenes ID-Mapping kann sinnvoll sein.
https://www.heise.de/ratgeber/POSIX-Attribute-fuer-Entra-ID-mit-Himmelblau-anlegen-11316718.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon
#EntraID #IT #Linux #Unix #news
You've seen all posts