Identity Security Blog

Expert insights on Active Directory and Azure security vulnerabilities, hardening guides, and remediation best practices.

123 articles
Entra ID Passwordless MFA Registration Change: What Microsoft Simplified and Why It Matters for Rollout
AzureIdentityConditional Access

Entra ID Passwordless MFA Registration Change: What Microsoft Simplified and Why It Matters for Rollout

Microsoft is letting users register a passkey as their first MFA method in Entra ID, dropping the SMS/voice-first requirement. Here's the rollout timeline and how to check your tenant's exposure.

Entra ID Break Glass Emergency Access Accounts: Missing, Unmonitored, Unexcluded
AzurePrivileged AccessConditional Access

Entra ID Break Glass Emergency Access Accounts: Missing, Unmonitored, Unexcluded

Most Entra ID tenants either have no break-glass account, or have one that Conditional Access can lock out and nobody watches. Here's the governance gap, how to detect it, and how to fix it.

DCShadow Attack Rogue Domain Controller Registration: How It Bypasses AD Change Auditing
ADAdvancedPermissions

DCShadow Attack Rogue Domain Controller Registration: How It Bypasses AD Change Auditing

DCShadow forges a rogue domain controller to push Active Directory changes via replication rather than a write API, bypassing the audit trail Domain Admin abuse normally leaves.

Active Directory Audit Policy Configuration Gaps: The Categories Nobody Enables Before They Need the Logs
ADMonitoringAdvanced

Active Directory Audit Policy Configuration Gaps: The Categories Nobody Enables Before They Need the Logs

Most Active Directory environments leave Account Logon, Account Management, and Policy Change auditing off or half-configured. Here's why the gap exists, how to check for it, and how to close it.

CVE-2025-55241: Entra ID Actor Token Impersonation Could Compromise Any Global Admin
AzureIdentityPrivileged Access

CVE-2025-55241: Entra ID Actor Token Impersonation Could Compromise Any Global Admin

CVE-2025-55241 let an undocumented Actor token bypass MFA and Conditional Access to impersonate any Global Admin across Entra ID tenants. How it worked, and what to fix.

Entra ID MemberOf Dynamic Group Rule Operator Retirement: What Breaks on November 3
AzureGroupsIdentity

Entra ID MemberOf Dynamic Group Rule Operator Retirement: What Breaks on November 3

Microsoft is retiring the preview memberOf dynamic-group rule operator in Entra ID on November 3, 2026 — here's what breaks, how to find every affected rule, and how to migrate first.

Active Directory Privileged Accounts: Protected Users, Delegation, and Service Account Gaps
ADAccountsPrivileged Access

Active Directory Privileged Accounts: Protected Users, Delegation, and Service Account Gaps

Domain Admins left out of Protected Users, delegation flags never set, and service accounts sitting in privileged groups are three separate, additive gaps that widen credential-theft blast radius. Here's how to find and close them.

CVE-2026-56155 ADFS Elevation of Privilege: The Actively Exploited Flaw Sysadmins Still Haven't Patched
ADPermissionsPrivileged Access

CVE-2026-56155 ADFS Elevation of Privilege: The Actively Exploited Flaw Sysadmins Still Haven't Patched

CVE-2026-56155 lets a low-privileged local user escalate to admin via AD FS's DKM container ACLs. Actively exploited pre-patch — what to detect and fix.

Entra ID AiTM Token Replay, Impossible Travel Detection, and MFA Push Fatigue
AzureRisk ProtectionIdentity

Entra ID AiTM Token Replay, Impossible Travel Detection, and MFA Push Fatigue

Entra ID's sign-in risk detections catch AiTM token replay, impossible travel, and MFA push abuse — but only if you know which signal to read. Here is what to watch and how to respond.

Entra ID SMS MFA Retirement Passkeys: The Migration Timeline
AzureIdentityConditional Access

Entra ID SMS MFA Retirement Passkeys: The Migration Timeline

Microsoft is retiring Microsoft-provided SMS and voice MFA in Entra ID by February 1, 2027, auto-enrolling remaining users into passkeys starting September 1, 2026. Here is the exact timeline, how to find who is exposed, and how to migrate before the blocking prompt hits.

Entra SAML Signing Certificate Expired: Why Federated Sign-In Breaks
AzureApplicationsMonitoring

Entra SAML Signing Certificate Expired: Why Federated Sign-In Breaks

An expired SAML signing certificate doesn't just weaken security — it breaks federated sign-in tenant-wide. Learn how Entra certificate rotation works, how to detect expiring or long-lived certs, and how to renew without downtime.

Active Directory Computer Objects Attack Surface: The Machine Identity Risk Nobody Audits
ADComputersAttack Paths

Active Directory Computer Objects Attack Surface: The Machine Identity Risk Nobody Audits

The Active Directory computer objects attack surface — unconstrained delegation, RBCD abuse, DCSync rights on machine accounts, computers in admin groups, and obsolete OS — covers the attack, detection, and remediation for each.