<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Entra-Id on CuraSec</title><link>https://curasec.metacog.co.kr/tags/entra-id/</link><description>Recent content in Entra-Id on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 27 Aug 2026 21:01:55 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/entra-id/index.xml" rel="self" type="application/rss+xml"/><item><title>Auditing Admin Rights in Microsoft Entra ID</title><link>https://curasec.metacog.co.kr/insights/2026-08-27-who-has-admin-rights-in-your-entra-id-directory-x3f-wed-aug/</link><pubDate>Thu, 27 Aug 2026 21:01:55 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-27-who-has-admin-rights-in-your-entra-id-directory-x3f-wed-aug/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Run an Entra ID privileged role audit this quarter: export current role assignments, flag stale accounts from departed staff, and scope down over-provisioned roles (e.g. helpdesk accounts holding Global Admin) to least-privilege equivalents.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Useful framing for why excessive Entra admin roles expand blast radius during identity-based intrusions, but no new TTPs, IOCs, or detection content here.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Excess admin accounts are a recurring audit finding (CIS Control 4); scheduling a formal privileged-access review and documenting results strengthens posture for SOC 2 / ISO 27001 auditors asking exactly this question.&lt;/li>
&lt;/ul></description></item><item><title>Microsoft Entra ID CVSS 10.0 RCE Flaw Exploited in the Wild</title><link>https://curasec.metacog.co.kr/insights/2026-08-21-microsoft-entra-id-flaw-cvss-10-0-exploited-in-wild-allows-r/</link><pubDate>Fri, 21 Aug 2026 11:38:25 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-21-microsoft-entra-id-flaw-cvss-10-0-exploited-in-wild-allows-r/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Microsoft has applied a server-side fix requiring no customer patch, but active exploitation occurred before remediation — audit Entra ID sign-in and audit logs for anomalous authentication, new service principals, or privilege escalation events from the period prior to the fix, and verify no credential or token abuse persists.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Confirmed in-the-wild exploitation of an identity provider with a public PoC warrants an immediate hunt — query Entra ID audit and sign-in logs for suspicious app registrations, delegated permission grants, and admin role assignments occurring in the exploitation window, and tune detections for anomalous OAuth consent flows.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> A CVSS 10.0 actively exploited RCE on the organization&amp;rsquo;s cloud identity plane is a board-level event analogous to Log4Shell in blast radius — brief leadership this week on the pre-patch exposure window and confirm with the security team that no evidence of compromise was found in Entra ID logs before Microsoft&amp;rsquo;s server-side fix landed.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-69836 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub&lt;/li>
&lt;/ul></description></item><item><title>Microsoft Entra ID max-severity flaw patched, actively exploited</title><link>https://curasec.metacog.co.kr/insights/2026-08-21-microsoft-warns-of-max-severity-entra-id-flaw-exploited-in-a/</link><pubDate>Fri, 21 Aug 2026 11:38:25 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-21-microsoft-warns-of-max-severity-entra-id-flaw-exploited-in-a/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Max-severity flaw in Microsoft Entra ID with confirmed active exploitation makes this immediate-action territory regardless of missing EPSS/KEV signals. Apply Microsoft&amp;rsquo;s Entra ID patch now and review sign-in and audit logs for anomalous authentication activity around and before the disclosure date.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active exploitation of an IAM platform means compromise may have already occurred in unpatched environments. Hunt for anomalous Entra ID authentication events (unexpected sign-ins, token grants, role assignments) and check whether Microsoft has published associated IOCs or TTPs to tune detections.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Entra ID underpins identity for the vast majority of enterprise environments, and confirmed active exploitation of a maximum-severity flaw is a board-question-level event. Confirm patching status with your engineering team this week and be ready to brief leadership before customers or auditors raise it.&lt;/li>
&lt;/ul></description></item><item><title>MS Graph PowerShell: querying Entra risky login detections</title><link>https://curasec.metacog.co.kr/insights/2026-08-21-using-microsoft-graph-and-powershell-risk-detection-commands/</link><pubDate>Fri, 21 Aug 2026 11:38:25 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-21-using-microsoft-graph-and-powershell-risk-detection-commands/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Practical walkthrough on using MS Graph and PowerShell to surface Entra ID risk detections — useful reference if you&amp;rsquo;re building automated triage or identity monitoring pipelines.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Walk through the MS Graph risk-detection commands shown here and consider incorporating them into your Entra ID hunting runbooks or SIEM enrichment workflows.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>PowerShell + Graph script to find accounts missing MFA in Entra</title><link>https://curasec.metacog.co.kr/insights/2026-08-21-who-got-missed-in-the-mfa-rollout-x3f-more-powershell-x2b-gr/</link><pubDate>Fri, 21 Aug 2026 11:38:25 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-21-who-got-missed-in-the-mfa-rollout-x3f-more-powershell-x2b-gr/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Practical scripting technique for auditing MFA coverage gaps in Entra ID using Microsoft.Graph.Beta PowerShell; useful reference when validating rollout completeness but no vulnerability or patch action required.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>PowerShell guide for auditing Entra ID login logs and detecting password sprays</title><link>https://curasec.metacog.co.kr/insights/2026-08-21-even-moar-powershell-looking-at-entra-logins-the-good-the-ba/</link><pubDate>Fri, 21 Aug 2026 11:38:25 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-21-even-moar-powershell-looking-at-entra-logins-the-good-the-ba/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Practical reminder that cloud identity login logs (Entra ID sign-in logs) deserve the same daily scrutiny as on-prem logs; useful if you haven&amp;rsquo;t wired these into a monitoring workflow yet, but no patch or config change required.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Adopt or adapt the PowerShell queries shown to pull Entra successful/failed login data for routine password-spray hunting; worth scheduling as a log-source coverage improvement if Entra sign-in logs aren&amp;rsquo;t already feeding your SIEM.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Malware Can Abuse Windows Hello for Business Keys for Entra ID Persistence</title><link>https://curasec.metacog.co.kr/insights/2026-08-07-malware-can-abuse-windows-hello-for-business-keys-for-persis/</link><pubDate>Fri, 07 Aug 2026 11:54:55 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-07-malware-can-abuse-windows-hello-for-business-keys-for-persis/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> This post-exploitation technique lets malware silently leverage WHfB keys to register attacker-controlled devices and obtain PRTs in Entra ID tenants. Audit Conditional Access policies to enforce device compliance checks for sensitive operations and restrict who can register new devices in your tenant.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> The technique has a clear Entra ID audit-log surface: build detections on anomalous device registrations and PRT issuances in Microsoft Entra sign-in and audit logs, particularly where the registering session doesn&amp;rsquo;t match expected device inventory.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Published research reveals a persistence path through Microsoft&amp;rsquo;s cloud identity stack that could let an endpoint compromise extend into long-lived Entra ID access; no active exploitation or breach is reported, so no immediate leadership action is needed.&lt;/li>
&lt;/ul></description></item><item><title>Microsoft Entra ID makes passkeys the default auth method</title><link>https://curasec.metacog.co.kr/insights/2026-07-14-microsoft-entra-id-security-updates-passkeys-are-the-default/</link><pubDate>Tue, 14 Jul 2026 12:08:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-14-microsoft-entra-id-security-updates-passkeys-are-the-default/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> This is a breaking change to default authentication behavior in Entra ID — audit your tenant&amp;rsquo;s authentication policy, test passkey rollout for user flows, and review the updated SMS/voice auth model before it affects production sign-ins.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Passkey adoption changes the phishing-resistant auth landscape and may affect credential-based attack detections; no immediate hunt or detection work required, but worth understanding how login telemetry shifts.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> A platform-level auth default change from a major identity provider warrants a quarter-horizon review of helpdesk readiness, user communication plans, and any compliance attestations tied to MFA method specifics.&lt;/li>
&lt;/ul></description></item></channel></rss>