Graph Api
The latest Graph Api coverage — news, analysis, and updates from the WindowsNews.AI desk.
Microsoft Purview 558681 Pours DLP Context Into Graph API Alerts
Microsoft is rolling out a change that security teams have been awaiting for years: DLP rule-match details will now flow directly into Graph API security alerts. The update, tracked as Microsoft...
ControlUp Migrate for Windows 365: Free Tool Automates Cloud PC Migration
ControlUp has launched a groundbreaking free migration utility called ControlUp Migrate for Windows 365, designed to streamline the transition of Azure-based virtual machines and Azure Virtual...
PowerShell Script to Reclaim Unused Microsoft 365 Licenses and Save Costs
Microsoft 365 license management represents one of the most overlooked areas for cost optimization in enterprise IT environments. Organizations frequently continue paying for licenses that remain...
Entra ID Cross-Tenant Admin Takeover: How Actor Tokens and Graph API Flaw Nearly Broke Cloud Security
In mid-2025, a critical vulnerability in Microsoft Entra ID, formerly Azure Active Directory, exposed a fault line in cloud identity security that could have allowed attackers to compromise virtually...
Archived but Not Forgotten: The Story of Microsoft’s Facebook SDK for Windows 10 and HoloLens
The GitHub repository for Microsoft’s official Windows SDK for Facebook now sits in archived, read-only state—a silent monument to an ambitious 2015 push to make Universal Windows apps more...
48-Hour Exchange Hybrid Free/Busy Blackout Hits Unprepared Tenants September 16
At 07:00 UTC on September 16, 2025, Microsoft will flip a switch that breaks free/busy lookups, MailTips, and profile picture sharing between on-premises Exchange and Exchange Online for any hybrid...
Exposed appsettings.json Files Unleash 'Master Key' to Azure Tenants via OAuth Token Abuse
A single, publicly exposed appsettings.json file containing Azure Active Directory (now Entra ID) application credentials can act as a master key to an organization’s entire cloud estate, security...
Exchange Online's New Message Trace Hits GA, Legacy Tools Deprecated September 2025
Microsoft has moved the overhauled Message Trace experience in Exchange Online to general availability, bringing a faster UI, new PowerShell cmdlets, and a firm September 1, 2025 deadline for the...
Microsoft and CISA Demand Hybrid Exchange Overhaul: October 31 Permanent Cutoff After Vulnerability Alert
Microsoft has drawn a hard line in the sand for hybrid Exchange administrators: after October 31, 2025, any on-premises server still relying on the legacy shared service principal for rich...
NetApp Connector for Microsoft 365 Copilot Delivers On-Prem Data Access with Item-Level Security
Microsoft 365 Copilot can now ground its responses in on-premises NetApp file shares without requiring a full cloud migration, thanks to a new connector that preserves granular access controls....
Chemist Warehouse Cuts 1,950 HR Hours with AI Assistant Built on Azure AI Foundry
Chemist Warehouse’s six-person HR advisory team now has a digital colleague that drafts responses to hundreds of routine queries each week, reclaiming an estimated 1,950 hours of staff time...
Microsoft’s August Patches Fix Kerberos dMSA Vulnerability That Lets Attackers Escalate to Domain Admin
A newly disclosed vulnerability in Windows Server 2025’s delegated Managed Service Accounts (dMSA) feature allows an attacker with initial access to specific Kerberos secrets to escalate to full...