This week’s Microsoft Entra ID update brings a stark reminder that even fully managed cloud identity platforms can have critical vulnerabilities. Microsoft disclosed a CVSS 10.0 remote code execution flaw in Entra ID that was actively exploited in the wild — though thankfully already patched server-side. Alongside this security event, Microsoft expanded the list of CSS properties being retired from custom branding, and provided new detail on Windows Hello for Business and macOS Platform SSO serving as standalone MFA factors. Third-party tooling from Netwrix also deserves attention, with PingCastle 4.0 bringing 102 Entra ID risk checks and AI agent identity discovery.
CVE-2026-69836: Critical Entra ID RCE Exploited in the Wild
The headline story this week is serious. On August 20-21, 2026, Microsoft disclosed CVE-2026-69836, a CVSS 10.0 Critical remote code execution vulnerability in Microsoft Entra ID that was actively exploited in the wild before being patched.
What Happened
The vulnerability is a deserialization of untrusted data issue (CWE-502) in Entra ID’s backend. The service was processing specially crafted serialized data objects without proper validation. An unauthenticated attacker could send malicious serialized data to a vulnerable endpoint and trick the service into executing arbitrary code — over the network, with no credentials, and no user interaction required. This is what security researchers call a zero-click, network-reachable RCE.
The vulnerability was discovered by Robert Fitzpatrick, Microsoft Principal Security Engineer. Microsoft published the security advisory on August 21, 2026, and confirmed that exploitation had already occurred.
The Good News
Because Entra ID is a fully managed cloud service, Microsoft was able to fix the vulnerability on their own infrastructure — no customer-deployed patch is needed. Microsoft stated:
“This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.”
There is no KB article to install, no configuration change to make, and no update to apply. The fix was rolled out server-side before most organizations even knew the flaw existed.
What Security Teams Should Still Do
Even though no customer action is required for remediation, the confirmed in-the-wild exploitation means security teams should investigate whether their tenant was targeted during the exploitation window:
Within 24 hours: Review Entra ID audit logs and sign-in logs for anomalous activity in the 30 days preceding August 21, 2026. Microsoft has not disclosed the exploitation window, so treat it as unknown. Verify that no on-premises or hybrid infrastructure components (Entra Connect sync servers, pass-through authentication agents, Application Proxy connectors) were affected by related vulnerabilities.
Within 72 hours: Validate Conditional Access policies and privileged role assignments for any unauthorized changes. Confirm all Azure and Entra ID services are current with security updates — several other critical vulnerabilities were patched in the same batch (CVE-2026-69851, another CVSS 10.0 Elevation of Privilege in Entra ID, plus critical flaws in Azure SQL, Exchange Online, Azure Arc, and Microsoft Fabric).
Within 7 days: Review third-party application registrations and service principal credentials for unauthorized additions or modifications. Update incident response runbooks to include cloud identity platform compromise scenarios.
Why This Matters
This is a landmark event in cloud security. Confirmed in-the-wild exploitation of a CVSS 10.0 vulnerability in the world’s most widely used cloud identity platform underscores that:
- Cloud services can have critical vulnerabilities too — “managed by Microsoft” does not mean “immune to flaws”
- Transparency matters — Microsoft’s decision to publish a CVE for a server-side fix gives security teams the visibility they need to investigate potential compromise
- Identity is the new perimeter — a vulnerability in the identity platform is effectively a vulnerability in everything that relies on it
For organizations using Entra ID as their core identity provider (which is most Microsoft 365 customers), this event should trigger a review of identity-centric incident response procedures.
Expanded CSS Property Retirement for Custom Branding (MC1485474 / MC1458474)
Microsoft has significantly expanded the list of CSS properties being retired from Entra ID custom branding and sign-in pages. The original announcement in July (MC1435782) covered about 10 positioning properties. The expanded list, documented August 18 and notified via Message Center as MC1485474 and MC1458474, adds approximately 28 more properties.
Newly Added Properties
The expanded retirement list now includes:
- Offset properties:
offset,offset-path,offset-distance - Logical margin properties:
margin-block,margin-block-start,margin-block-end,margin-inline,margin-inline-start,margin-inline-end - Flexbox ordering:
order - CSS Grid properties:
grid-area,grid-column,grid-column-start,grid-column-end,grid-row,grid-row-start,grid-row-end - Isolation:
isolation - Directional overflow:
overflow-x,overflow-y,overflow-block,overflow-inline - Visibility control:
content-visibility,clip - Masking:
mask,mask-image,-webkit-mask,-webkit-mask-image
Timeline (Unchanged)
- July 21, 2026: Tenants not already using these properties can no longer configure them
- October 26, 2026: All listed CSS layout and positioning properties retired globally — branding elements remain visible but revert to default placement
- Later 2027: Full custom CSS retirement (advance notice promised)
What to Do
- Download your current custom CSS file from the Entra admin center
- Search for usage of any of the retired properties (the full list includes both the original July properties and the new August additions)
- Update branding to remove or replace affected properties
- Test the sign-in experience after changes
- Communicate changes to users and stakeholders
This expansion is part of Microsoft’s Secure Future Initiative (SFI) to reduce phishing risks from deceptive sign-in page layouts. The message is clear: custom CSS for Entra ID sign-in pages is on borrowed time. Organizations that have invested in elaborate custom branding should begin planning for a future without any custom CSS at all.
Windows Hello for Business and macOS Platform SSO as Standalone MFA (Roadmap ID 568076)
Microsoft 365 Roadmap item 568076, published August 20, 2026, provides important new operational detail on the previously announced (MC1450134, August 7) capability for Windows Hello for Business and macOS Platform SSO to serve as standalone MFA factors.
What Changed
Before: WHfB and macOS PSSO only counted as MFA during primary sign-in. For step-up prompts, Authentication Strength policies, and sign-in frequency checks, users needed a separate passkey.
After: WHfB and macOS PSSO can now satisfy multifactor authentication as a standalone second factor across all MFA scenarios. Users who have only WHfB or macOS PSSO are now treated as MFA-capable and will no longer be automatically prompted to register another method.
Important Caveat
WHfB and macOS PSSO are device-tied credentials — they only work on the specific device where they’re registered. Microsoft recommends that organizations still have users register a portable method (such as a passkey or Microsoft Authenticator) during onboarding, so they can complete MFA from any device.
Timeline: October CY2026, Worldwide and GCC.
This is a meaningful friction reduction for organizations with managed device fleets. Users on Windows Hello or macOS Platform SSO environments will no longer need to register a separate method just to satisfy step-up authentication prompts, reducing onboarding complexity while maintaining phishing-resistant MFA standards.
PingCastle 4.0: Third-Party Entra ID Assessment Comes of Age
Netwrix released PingCastle 4.0 on August 18, 2026, extending the popular open-source Active Directory assessment tool to cover Microsoft Entra ID with 102 risk checks. Alongside this, Netwrix Threat Manager 3.3 adds AI agent identity visibility and Azure Files ransomware monitoring.
PingCastle 4.0 Highlights
- 102 Entra ID risk assessments — previously PingCastle only assessed on-premises Active Directory
- Unified assessment across both on-premises AD and cloud Entra ID with the same fast, prioritized approach
- Available now
Netwrix Threat Manager 3.3 Highlights
- AI agent identity inventory — discovers AI agents operating in Entra ID and shows the access they hold
- Azure Files monitoring — ransomware behavioral detection, unusual behavior alerts, risky configuration change detection
- Agent-specific threat detection planned for a later release
- Available now
Why This Matters
A Netwrix report found that only 19% of organizations fully govern non-human identities such as service accounts and AI agents. Microsoft’s Agent ID and Agent 365 are the first-party approach to this problem, but independent third-party assessment tools provide valuable validation and broader coverage.
PingCastle’s expansion to Entra ID also validates a broader industry trend: identity security can no longer be divided into “on-premises AD” and “cloud Entra ID” silos. Organizations need unified visibility across both planes, and tools that bridge that gap are becoming essential.
August 2026 Security Patch Batch
The CVE-2026-69836 disclosure was part of a larger batch of 22 security updates for Azure, Entra ID, and Exchange released August 20-21, 2026. Notable critical fixes include:
| CVE | Product | Type | CVSS |
|---|---|---|---|
| CVE-2026-69836 | Entra ID | RCE (exploited) | 10.0 |
| CVE-2026-69851 | Entra ID | Elevation of Privilege | 10.0 |
| CVE-2026-69502 | Azure SQL Database | Elevation of Privilege | 10.0 |
| CVE-2026-65801 | Exchange Online | Elevation of Privilege | 10.0 |
| CVE-2026-65770 | Azure Managed Instance for Apache Cassandra | RCE | 10.0 |
| CVE-2026-69555 | Azure Arc | Elevation of Privilege | 10.0 |
| CVE-2026-63509 | Microsoft Fabric | Elevation of Privilege | Critical |
| CVE-2026-69400 | Azure Logic Apps | Elevation of Privilege | Critical |
| CVE-2026-62834 | Azure Data Factory | Elevation of Privilege | Critical |
For cloud-managed services (Entra ID, Exchange Online), fixes are applied server-side. For customer-managed components (Entra Connect servers, on-premises Exchange), apply the relevant updates immediately.
Summary
This week’s Entra ID updates span the full spectrum from critical security to UX improvements:
- CVE-2026-69836 — A CVSS 10.0 RCE in Entra ID exploited in the wild, patched server-side but demanding security team review of audit logs
- Expanded CSS retirement — 28 additional CSS properties being retired from custom branding, with October 26 deadline
- WHfB/macOS PSSO standalone MFA — Device-native biometrics now satisfy MFA across all scenarios starting October 2026
- PingCastle 4.0 — Third-party Entra ID assessment with 102 risk checks plus AI agent identity discovery
The CVE-2026-69836 disclosure is the most significant item. While no customer action is required for remediation, the confirmed in-the-wild exploitation of a zero-click RCE in the world’s most widely used cloud identity platform is a wake-up call. Security teams should treat this as an opportunity to review their identity-centric incident response procedures, audit their Entra ID environment for signs of compromise, and ensure their monitoring covers the signals that would indicate identity platform abuse.
Follow Kevin on X at https://x.com/kkaminsk for daily Microsoft Entra ID and security updates.