Service Principal
The latest Service Principal coverage — news, analysis, and updates from the WindowsNews.AI desk.
48-Hour Exchange Hybrid Free/Busy Blackout Hits Unprepared Tenants September 16
At 07:00 UTC on September 16, 2025, Microsoft will flip a switch that breaks free/busy lookups, MailTips, and profile picture sharing between on-premises Exchange and Exchange Online for any hybrid...
Microsoft Sentinel UEBA Now Ingests AWS, GCP, Okta Logs for AI-Driven Threat Detection
Microsoft has quietly rolled out a major update to its cloud-native SIEM, Microsoft Sentinel, significantly expanding the data sources its User and Entity Behavior Analytics (UEBA) engine can digest....
Microsoft Ships September 2025 Exchange Hotfixes to Keep Hybrid Apps Running as October 31 Deadline Looms
Microsoft released a targeted set of Hotfix Updates (HUs) for Exchange Server this September, delivering a non‑security fix while ensuring the newly engineered dedicated Exchange hybrid application...
Mandatory MFA Hits Azure CLI and IaC Tools This Autumn: Brace for Impact
Microsoft is set to roll out Phase 2 of its mandatory multi-factor authentication (MFA) enforcement for Azure this autumn, and this time the net is cast far wider than the portal. Starting...
Mandatory MFA Comes to Azure CLI, PowerShell, and IaC Tools—What You Need to Know Before October
Starting in October, Microsoft will begin enforcing multifactor authentication for all write operations performed through the Azure Resource Manager control plane—including Azure CLI, PowerShell,...
Microsoft Confirms Two Azure Bot Service Elevation-of-Privilege Flaws, Urges Immediate Patching
Security teams responsible for Azure Bot Service deployments are grappling with a double-barreled set of improper authorization vulnerabilities that could let unauthenticated attackers hijack cloud...
Microsoft Gives Partners Automated Billing Powers and Slashes Firewall Log Costs
Enterprise Agreement indirect partners can now pull cost data from every customer enrollment programmatically, without sharing a single user password. Microsoft quietly shipped a handful of Cost...
Exposed appsettings.json Files Unleash 'Master Key' to Azure Tenants via OAuth Token Abuse
A single, publicly exposed appsettings.json file containing Azure Active Directory (now Entra ID) application credentials can act as a master key to an organization’s entire cloud estate, security...
Microsoft enforces Azure MFA by October 2025 as Meta patches zero-click WhatsApp flaw CVE-2025-55177, making identity the new enterprise perimeter.
Meta has patched a zero-click vulnerability in WhatsApp that could let attackers execute code without any user interaction, while Microsoft will begin enforcing multi-factor authentication (MFA) for...
MFA Mandate Expands to Azure CLI, PowerShell, and IaC: The Clock Ticks for DevOps Migration
Microsoft is extending mandatory multi-factor authentication (MFA) beyond the Azure portal and into the command-line tools and automation interfaces that power cloud operations. Starting with its...
Microsoft and CISA Demand Hybrid Exchange Overhaul: October 31 Permanent Cutoff After Vulnerability Alert
Microsoft has drawn a hard line in the sand for hybrid Exchange administrators: after October 31, 2025, any on-premises server still relying on the legacy shared service principal for rich...
CVE-2025-53763: Microsoft Flags Azure Databricks Privilege Escalation Flaw, Urges Immediate Defensive Actions
Microsoft has disclosed a new privilege escalation vulnerability in Azure Databricks, tracked as CVE-2025-53763, which could allow an attacker with network access to elevate their privileges within...