Yesterday’s headline about a CVSS 10.0 remote code execution vulnerability in Microsoft Entra ID traveled fast. Today brings an important correction: Microsoft has revised the exploitation status of CVE-2026-69836 from “Yes” to “No” following an inquiry from The Hacker News. The vulnerability remains critical — unauthenticated, network-accessible, zero-click — but it was not exploited in the wild as initially reported. Beyond this correction, this update covers confirmed rollout dates for B2B guest passkey support, a new public preview for multi-tenant agent management in the Microsoft 365 admin center, tightened GitHub federated identity credential requirements, and a new migration guide for Global Secure Access web filtering policies.
CVE-2026-69836: Exploitation Status Corrected to “No”
On August 20, 2026, Microsoft disclosed CVE-2026-69836, a Critical remote code execution vulnerability in Microsoft Entra ID with a CVSS 3.1 base score of 10.0. The vulnerability stems from deserialization of untrusted data (CWE-502) — Entra ID’s backend could process specially crafted serialized data without sufficient validation, potentially allowing an unauthenticated attacker to execute arbitrary code over the network with no user interaction.
What Changed on August 21
Microsoft’s original security bulletin marked the “Exploited” field as “Yes” in the exploitability assessment table. Following an inquiry from The Hacker News, Microsoft corrected the status to “No” on August 21, 2026. A Microsoft spokesperson provided this statement:
“We identified and addressed this issue with a fix and released CVE-2026-69836 for greater transparency. There are no additional actions customers need to take.”
The NVD record was subsequently updated, and CISA’s SSVC assessment now shows “exploitation: none.” Multiple security publications — including BleepingComputer, Cybersecurity News, and The Register — updated their stories to reflect the correction.
Technical Details
The CVSS vector tells the full story: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
- Attack vector: Network (remotely exploitable)
- Attack complexity: Low
- Privileges required: None
- User interaction: None (zero-click)
- Scope: Changed (could impact resources beyond the vulnerable component)
- Impact: High confidentiality, high integrity, high availability
- Temporal score: 8.7 (lower than base 10.0 due to Microsoft’s remediation)
Microsoft has not disclosed the specific vulnerable endpoint, serialization technology, or internal exploit path. The vulnerability was discovered by Robert Fitzpatrick, Microsoft Principal Security Engineer. No public proof-of-concept code exists. EPSS probability score is 1.4% (Low).
What This Means for Organizations
Since Entra ID is a fully managed cloud service, Microsoft applied the fix directly to their infrastructure. There is no patch to install, no KB article to deploy, and no configuration change required. The CVE was published purely for transparency — giving security teams visibility into a vulnerability that touched their environment.
However, the incident underscores an important reality: cloud identity platforms are not immune to critical vulnerabilities. Organizations should:
- Review Entra ID sign-in logs for anomalous activity in the 30 days preceding disclosure (August 20, 2026). Look for unusual sign-in patterns, unexpected service principal authentications, or suspicious application consent grants.
- Audit privileged role assignments — verify no unauthorized changes to Global Administrator, Privileged Role Administrator, or other high-privilege roles.
- Review new service principal creations and credential additions — an attacker with code execution in Entra ID could issue tokens, impersonate service principals, and reach downstream resources with credentials that look entirely authorized.
- Export logs to independent infrastructure (SIEM, Azure Storage) — Entra ID Free retains sign-in logs for 7 days, P1/P2 for 30 days. Upgrading a license later does not restore expired log data.
- Update incident response runbooks to include cloud identity platform compromise scenarios.
Same Patch Batch: 22 Total Updates
Microsoft released 22 security updates on August 20, including several other CVSS 10.0 vulnerabilities:
- CVE-2026-69851 — Elevation of privilege in Entra ID (CVSS 10.0)
- CVE-2026-65801 — Elevation of privilege in Exchange Online (CVSS 10.0)
- CVE-2026-69555, CVE-2026-65816 — Elevation of privilege in Azure Arc (CVSS 10.0)
- CVE-2026-65770 — RCE in Azure Managed Instance for Apache Cassandra (CVSS 10.0)
- Multiple Azure SQL Database, Microsoft Fabric, Azure Logic Apps, and Azure Data Factory vulnerabilities
All were patched server-side with no customer action required.
B2B Guest Passkey Registration and Sign-In Confirmed for October 2026
Microsoft has confirmed that passkey registration and sign-in for B2B guest users will be enabled by default, with a phased rollout from October 2026 through February 2027. This extends the passkey-by-default initiative — announced July 13 for internal users — to external and guest users.
Why This Matters
B2B collaboration is central to how many organizations work with partners, suppliers, and customers. Until now, guest users have relied on SMS, voice, or Microsoft Authenticator push for MFA — methods that are either being retired (SMS/voice by February 2027) or remain vulnerable to phishing. Extending passkey support to B2B guests means:
- Guest users can register passkeys and use them to satisfy resource-tenant MFA requirements
- Phishing-resistant authentication becomes available for external collaborators, not just employees
- No administrator action required — the feature is enabled by default
- Aligns with the broader authentication modernization timeline:
- September 1, 2026: Passkeys become default for internal users with SMS/voice
- October 2026: B2B guest passkey support begins rollout
- February 1, 2027: Microsoft-provided SMS/voice fully retired
Recommendations
- Review B2B guest user populations and their current MFA methods
- Communicate upcoming changes to external collaborators who may need to register passkeys
- Update onboarding documentation for new guest users to mention passkey enrollment
- Review Conditional Access policies that target guest users to ensure passkey-compatible authentication strength requirements
MC1456781: Multi-Tenant Agent Management in M365 Admin Center (Public Preview)
Microsoft announced multi-tenant agent management in the Microsoft 365 admin center, now in public preview (MC1456781). This capability allows partners and enterprise administrators to view and manage AI agents across connected tenants from a single experience.
The Problem This Solves
As organizations scale their use of AI agents — Copilot Studio agents, custom agents, third-party agents — managing them across multiple tenants has become a real operational challenge. Microsoft partners managing dozens of customer tenants, or enterprises with subsidiary tenants, previously had to sign into each tenant separately to review, install, or block agents.
Capabilities
- Consolidated agent inventory across all connected/governed tenants
- Add custom agents to the inventory
- Install agents in all eligible connected tenants or a selected subset
- Block agents or change their availability across selected tenants
- Review tenant-specific permissions and, when licensed, agent risk and activity insights
- Tenant switcher to enter a governed tenant through delegated access without maintaining a separate administrator account
Requirements
- Partners: GDAP (Granular Delegated Admin Privileges) relationship configured in Partner Center
- Enterprise admins: Tenant relationships established through Microsoft Entra Tenant Governance
- Admin roles: AI Administrator, Global Administrator, or Global Reader (view only for Global Reader)
- Licensing: No additional license for management; Microsoft Agent 365 license required for viewing agent risk and activity insights
Rollout Timeline
Public preview rollout began in early August 2026 and is expected to complete by mid-August 2026 for Worldwide tenants. General availability timeline has not yet been announced.
This capability complements the Entra Tenant Governance GA (August 10, 2026), which introduced multi-tenant agent management as a feature of Tenant Governance. The M365 Admin Center experience extends this to the admin console where day-to-day agent operations happen.
GitHub Flexible Federated Identity Credentials: Immutable Claims Now Required
Microsoft updated the preview documentation for flexible federated identity credentials in Entra Workload Identity ID. The updated guidance, dated August 14, 2026, now requires configurations to match the sub claim plus at least one immutable claim: repository_id or repository_owner_id.
What Changed
- Portal, Microsoft Graph, and CLI examples updated to include immutable repository claims
- Supported operators:
sub(eq, matches),job_workflow_ref(eq, matches),repository_id(eq),repository_owner_id(eq) - Requirement applies regardless of whether
subuses name-based, customized, or immutable format - Optional workflow matching supported
Context
This complements the MC1447671 migration notice (August 5, 2026) that told organizations to migrate GitHub Actions federated identity credentials to immutable OIDC subject formats by late July 2026. Since that deadline has passed, organizations with affected deployments should verify their configurations immediately to avoid token mismatches and reduce unauthorized-access risk.
The tightening is part of a broader Microsoft guidance push to harden GitHub and GitLab federated credentials, recommending immutable subject identifiers, restricting federation to specific repos/branches (not entire organizations), and applying least privilege to CI/CD applications.
Global Secure Access V1-to-V2 Web Filtering Migration Guide
A new how-to article published August 15, 2026 documents the guided migration experience for web content filtering policies from V1 to V2 in Microsoft Entra Global Secure Access.
Key Details
- Each V1 policy becomes a rule within one enabled V2 policy
- Destinations, actions, and priorities are preserved during migration
- Profiles that already contain V2 policies require manual handling
- Evaluation behavior differs between V1 and V2 across multiple security profiles — admins should review how policies interact when multiple security profiles are in play
- Eligible and ineligible security profiles are documented in the guide
Organizations using GSA web filtering should review this migration guide to plan their V1-to-V2 transition before V1 policies are deprecated.
Additional Documentation Updates (August 15-18, 2026)
Several documentation updates were published during the week that clarify existing behavior rather than introduce new features:
Authentication-strength policies cannot apply to MSA-authenticated external users — Updated guidance clarifies that authentication-strength policies cannot currently be applied to external users authenticating through Microsoft personal (MSA) accounts. Administrators should use the MFA grant control instead.
ID Protection device-block remediation behavior clarified — Disabling an Entra device blocks new token issuance, revokes user sessions, and prompts the user to sign in again. Previous documentation mentioning revocation of device-bound refresh tokens has been removed.
sAMAccountName synchronization with Entra Domain Services — Enhanced support documented for synchronizing sAMAccountName with Microsoft Entra Domain Services, with links to dedicated guidance.
Windows 10 ESU identifiers added to licensing reference — The Entra ID Licensing Service Plan Reference now includes Windows 10 Extended Security Updates service-plan identifiers for two Windows 365 plan entries.
Key Takeaways
CVE-2026-69836 was not exploited — Microsoft corrected the exploitation status, but the CVSS 10.0 rating and unauthenticated zero-click nature make this a significant disclosure. Review your Entra ID logs for the 30 days preceding August 20 as a precaution.
B2B passkeys arrive in October — Guest users gain phishing-resistant authentication with no admin action required. Communicate this to external collaborators and update guest onboarding documentation.
Multi-tenant agent management is here — Partners and multi-tenant enterprises can now manage agents from a single M365 Admin Center view. Verify GDAP configurations and role assignments to take advantage of the preview.
GitHub federated credentials need immutable claims — If you haven’t already migrated your GitHub Actions federated identity credentials to immutable subject formats, do it now. The deadline has passed.
GSA V2 migration guidance is available — If you’re using Global Secure Access web filtering, review the V1-to-V2 migration guide to plan your transition.
For ongoing coverage of Microsoft Entra ID updates, follow https://x.com/kkaminsk on X and check back here for regular analysis of what’s changing in Microsoft’s identity platform.