#entraid
10 posts · Last used 16d
Replying to
@14mission@sfba.social @morgan@sfba.social Microsoft (and Entra ID) is retiring SMS soon, so this won't be an option for a large number of orgs and folks in the near future. SMS is also not secure and does not meet the higher security standards that many organizations are now attempting to meet.
#MFA #SMS #EntraID #Microsoft
Replying to
@14mission@sfba.social @morgan@sfba.social for reference:
"From February 1, 2027, Microsoft-provided telecom delivery for SMS and voice will be retired for all users except Global Administrators and external users. For Global Administrators and external users, Microsoft-provided SMS and voice authentication will be retired on July 1, 2027."
https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sms-voice-retirement
#Microsoft #EntraID #MFA #Passkeys #SMS
Part 2 of our series on token theft in Microsoft Entra ID is live, accompanying ERNW White Paper 80.
This one puts Continuous Access Evaluation to the test empirically.
Of 740 first-party resources we checked for the CAE claim, 33 carried it.
Revocation timing ranged from 0 seconds for network-based policies to around 5 minutes at Exchange Online. In exchange for that, CAE tokens may live up to 28 hours rather than the usual 90 minutes.
https://insinuator.net/2026/09/token-theft-in-microsoft-entra-id-part-2-of-4-continuous-access-evaluation/ by Niklas Kerner
#EntraID #CAE #ZeroTrust #InfoSec
📦 Access Packages are super useful! They are part of the Entitlement Management feature in Microsoft Entra ID Governance.
Here's how to configure Access Packages.
https://thedxt.ca/2026/08/configure-microsoft-entra-id-governance-entitlement-management-access-packages/
#Microsoft #Entra #AccessPackage #Microsoft365 #EntraID #EntraIDGovernance #Governance
Proofpoint details OAuth client ID spoofing, a stealthy account enumeration technique that probes Microsoft Entra ID without a successful sign-in event.
#OAuthSpoofing #EntraID #AccountEnumeration #CloudSecurity #Proofpoint
http://securityonline.info/oauth-client-id-spoofing/?utm_source=mastodon&utm_medium=jetpack_social
Microsoft to Stop Providing Telephony-Based Authentication Methods for MFA in February 2027
In an important announcement for all tenants, Microsoft revealed that Entra ID will no longer provide SMS one-time codes or voice calls for MFA challenges after February 1, 2027. Tenants can continue to use telephony-based authentication methods after that date, but only by purchasing a service from a telecom provider. This is arguably the biggest change in Entra ID authentication since mandatory MFA for administrative interfaces – and we have a PowerShell script to help identify the affected accounts.
https://office365itpros.com/2026/07/14/entra-sms-one-time-code/
#EntraID
#MSXFAQ Simple SAML Sample https://www.msxfaq.de/cloud/authentifizierung/simple_saml_sample.htm - wollten Sie schon immer mal wissen, wie Sie ihre Webseite mit #EntraID #SAML-Tokens absichern können? Eine minimale BeispielApp fordert Token an und zeigt sie an. Was Sie danach weiter draus machen, ist ihre Phantasie.
#MSXFAQ BreakGlassApp https://www.msxfaq.de/cloud/admin/breakglassapp.htm - Wie wäre eine App mit Secret oder Zertifikat, mit welchem Sie einen vorhandenen #EntraID User zum #GlobalAdmin machen könnten? Quasi als #Notfall-Zugang, wenn der Global Admin nicht mehr funktioniert?
RE: https://infosec.exchange/@CDubbs/116847680945065797
Create a group called "Device Code Users" and a CA policy that blocks the use of the Device Code authentication flow except for those in the group. #cybersecurity #entraID
Quoting
EntraID PSA: Disable OAuth Device Code flow in your default conditional access policy.
You can search sign-on logs for people using this method to baseline and manage exceptions where appropriate.
Open quoted postheise+ | POSIX-Attribute für Entra ID mit Himmelblau anlegen
Werden vor einer Entra ID-Umstellung Linux-Clients und -Fileserver genutzt, gelten dort POSIX-Berechtigungen. Ein eigenes ID-Mapping kann sinnvoll sein.
https://www.heise.de/ratgeber/POSIX-Attribute-fuer-Entra-ID-mit-Himmelblau-anlegen-11316718.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon
#EntraID #IT #Linux #Unix #news
You've seen all posts




