Graph Api
The latest Graph Api coverage — news, analysis, and updates from the WindowsNews.AI desk.
Microsoft’s August Patches Fix Kerberos dMSA Vulnerability That Lets Attackers Escalate to Domain Admin
A newly disclosed vulnerability in Windows Server 2025’s delegated Managed Service Accounts (dMSA) feature allows an attacker with initial access to specific Kerberos secrets to escalate to full...
Microsoft Begins Silent Rollout of 365 Companion Apps to Windows 11 Taskbars
Starting in late October 2025, Microsoft began automatically installing three new companion apps onto the Windows 11 taskbar for devices that already have Microsoft 365 Apps. Dubbed Calendar, File...
Microsoft Details Entra ID Custom Claims Method That Injects Sponsor IDs into Tokens Using Directory Extensions
Microsoft has outlined a practical, five-step method for issuing custom SAML and OIDC claims from Entra ID, using directory extension attributes to inject organization-specific data like sponsor IDs...
HID Launches Next-Gen FIDO2 Keys, Cards, and Centralized Passkey Management as Passwordless Deployments Top 87%
Almost nine in ten enterprises have already started rolling out passkeys, but complexity and cost still hold back full-scale deployments. HID aims to smash those last barriers with a new wave of...
CISA Orders Federal Agencies to Patch Critical Exchange Hybrid Flaw by August 11
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive on Friday mandating all federal agencies with Microsoft Exchange hybrid environments to patch a critical...
Microsoft Entra ID Privilege Escalation Vulnerability: Risks and Mitigation in Hybrid Cloud Environments
In the rapidly evolving landscape of cloud infrastructure and identity management, Microsoft Entra ID (previously known as Azure Active Directory) has become a foundational piece for countless...
Streamlining Windows Updates: Mastering Microsoft's Enhanced Tools for Efficient IT Management
The challenge of managing Windows updates has significantly evolved, transitioning from a reactive, often cumbersome process to a proactive, integral aspect of modern IT administration. Microsoft's...
Microsoft 365 PDF Export Flaw: LFI Vulnerability Exposes Sensitive Data
Microsoft 365's PDF export functionality recently suffered a critical Local File Inclusion (LFI) vulnerability, allowing attackers to access sensitive server-side data. This vulnerability,...
Microsoft 365 PDF Export Flaw: A Critical Vulnerability and SaaS Security Implications
A recently patched critical vulnerability in Microsoft 365's PDF export functionality highlights significant security risks within Software as a Service (SaaS) environments. Discovered by security...
Synology Active Backup for Microsoft 365 Vulnerability: Risks and Mitigation
A critical security flaw in Synology's Active Backup for Microsoft 365 (ABM) has been uncovered, potentially exposing sensitive tenant data to unauthorized access. The vulnerability, tracked as...
Native macOS App Brings 40% Faster Drafts, Enterprise SSO to Microsoft 365 Copilot
Microsoft has officially brought its AI-powered productivity assistant, Microsoft 365 Copilot, to macOS, marking a significant expansion of its AI-driven tools beyond Windows. This native app...
Microsoft Entra ID 2025 Adds Device-Bound Passkeys for Enterprise Passwordless Security
Microsoft's recent announcement of expanded passkey (FIDO2) support in Microsoft Entra ID marks a significant advancement in enterprise security. The 2025 update introduces device-bound passkeys,...