๐ Hi, Merill and Joshua here with this weekโs roundup of the latest news on Microsoft Entra from around the globe ๐.
Apologies for the slightly late newsletter this week. I had way too much fun at the HIP Conference in Nashville, managed to pick up a bug on the way home, and Iโm only just recovering from all the excitement ๐
Donโt forget to check out this weeks podcast with none other than the โYoda of Microsoft Entraโ Tarek Dawoud, sharing some deep insights into AD and Entra.
Microsoft Security Architect: Active Directory Is 10x Harder to Defend Than Entra
At Black Hat USA 2026, Microsoftโs David Weston put three numbers on a slide that anyone still running domain controllers should sit with. The Microsoft Security Response Center went from 80 patches in February to 1,142 at the July Patch Tuesday. The fastest observed breakout time dropped from 98 minutes to 27 seconds. And mean time-to-exploit flipped fโฆ
Enjoy!
Sponsored by:
EasyEntra: Empower First-Level Support to Work Efficiently
Managing standard first-level user support in a hybrid environment is overly complex. To handle even basic tasks, your team needs expertise across multiple platforms like ADUC, Exchange on-premises Admin Center, M365 Admin Center, Entra Admin Center, EXO Admin Center, EXO PowerShell, and Entra Connect PowerShell.
EasyEntra eliminates this complexity and allows first-level support to work without headaches:
โ Intuitive - The interface mimics the familiar AD Users & Computers layout.
โ Consolidated - Manage all user settings from a single-pane-of-glass.
โ Responsive - Preloads all properties for lightning-fast navigation of settings.
โ Reduces junior IT training - Onboard junior IT staff in minutes.
โ Protects senior IT staff - Prevent first-level support tickets from escalating.
โก๏ธ Microsoft
๐ Read
Passkey-themed social engineering leads to identity and cloud compromise โข Microsoft Security Research
Protecting organizations from AI-assisted executive impersonation and invoice fraud โข Microsoft Security Research
๐ฃ๏ธ Message Center
Sponsored by:
Retiring MIM? Modernise identity sync with DirSync
Microsoft Identity Manager (MIM) is approaching end of life in 2029, leaving many organisations searching for a modern, supported approach to directory synchronisation even in complex and disconnected environments. If youโre still relying on MIM, now is the time to start planning your transition.
PowerSyncPro DirSync is a low-maintenance alternative designed for modern identity environments. Synchronise users, groups, contacts, passwords, and SID history across Active Directory, Microsoft Entra ID and Google Workspace, supporting coexistence, mergers, acquisitions, and large-scale transformation projects.
With advanced matching, attribute rewriting, What-If reporting and near real-time synchronisation, DirSync helps reduce operational overhead while giving IT teams greater control and visibility.
Learn more about PowerSyncPro DirSync or read our blog.
See how PowerSyncPro DirSync can help you move beyond MIM.
From the communityโฆ
๐ Most popular posts from last week
๐ฅ Passkey as first MFA method: What could go wrong? โข Per-Torben Sorensen
๐ฅ How to Block Personal Windows Devices in Microsoft Intune โข Mark Oldham
๐ฅ The magic of Agent Identities in Microsoft Entra โข Gabe Corsini
โ๏ธ Learn
๐ฉโโ๏ธ AI & Copilot
AI Agents as Non-Human Identities: Why Autonomy Changes the Governance Problem โข Sameer Bhanushali
Blueprint Inheritance Abuse in Entra Agent ID โข Elli Shlomo
๐งฐ Workload ID
Entra ID Continuous Access Evaluation and Microsoft 365 โข Tony Redmond
Run a PowerShell Workload on a Local Kubernetes Cluster That Talks to Microsoft Graph โข Ben Reader
๐ฎโโ๏ธ ID Governance
The Lazy Way to Bulk Access Packages โข Sandra Saluti
New feature in PIM - fire custom extensions on role activation โข Stian A. Strysse
๐ฆ Apps
Managing Permissions for Cloud-only Identities on Azure Files SMB โข Brian Veldman
๐ซ Authentication
Switching password managers is easy and safe on Android โข Jean-Pierre Pralle
Microsoft Entra expands passkey registration campaigns โข Daniel Bradley
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data โข The Hacker News
๐บ How to Map Out the Entra Passkey Registration Campaign [Demo] โข Ru Campbell
๐ฅ User & Group Management
Accessing Content of Microsoft 365 Group Mailboxes Through Microsoft Graph โข Martin Heusser
๐ค DevOps & PowerShell
Microsoft closes a data access gap for Graph API permission โข Daniel Bradley
Why Entra Administrators Cannot Disable Their Own Accounts โข Tony Redmond
๐ฆ Conditional Access
Microsoft Entra Conditional Access GPS Location: Why Authenticator Asks to Enable Location โข Sreejith Reghunathan Pillai
๐ฅท Security
๐ ๏ธ Audit Entra ID for privilege escalation paths through application permissions, role assignments, and app ownership โข Nicolas Blank
Microsoft Security Architect: Active Directory Is 10x Harder to Defend Than Entra โข Merill Fernando
Are Your Microsoft Entra Extensions Actually Being Used? โข Sebastian Flaeng Markdanner
๐ Tenant Configuration
๐บ Episode 436: Finding the Entra Tenants You Didnโt Know You Had โข Microsoft Cloud IT Pro Podcast
๐ฅ Maester
You ran Maester 200 times. Now what? โข Mateusz Jendza
Sam Erde and I had the opportunity to present on Maester with a deep dive into creating custom tests with Maester. Weโll include the link to the recording once it is published.
๐จ๐ฝโ๐ป Merillโs corner
Want to get featured on Entra.News? โ Submit your content ๐
Want us to say nice things about your company? Sponsor entra.news ๐คฉ
Love the newsletter? Tell us ๐โค๏ธ๐
๐ช Acknowledgement of Country
Entra.News is created on Wurundjeri land and acknowledges the traditional owners of country throughout Australia, recognising their continuing connection to land, water and community. We pay our respect to them and their cultures and to elders both past and present.








