<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Entra ID on HackingPassion.com : root@HackingPassion.com-[~]</title><link>https://hackingpassion.com/tags/entra-id/</link><description>Recent content in Entra ID on HackingPassion.com : root@HackingPassion.com-[~]</description><generator>Hugo</generator><language>en</language><lastBuildDate>Tue, 11 Aug 2026 14:15:01 +0200</lastBuildDate><atom:link href="https://hackingpassion.com/tags/entra-id/index.xml" rel="self" type="application/rss+xml"/><item><title>Pass the Passkey Attack Bypasses Entra ID MFA Using a Windows Log</title><link>https://hackingpassion.com/pass-the-passkey-windows-entra-mfa-bypass/</link><pubDate>Tue, 11 Aug 2026 14:15:01 +0200</pubDate><guid>https://hackingpassion.com/pass-the-passkey-windows-entra-mfa-bypass/</guid><description>&lt;p>&lt;strong>Someone could sign in as a company&amp;rsquo;s top admin by reading one Windows log file.&lt;/strong> The admin&amp;rsquo;s password and passkey were never touched. Microsoft called it medium severity and paid the finder 1,000 dollars. 🧐&lt;/p>
&lt;p>Passkeys were supposed to make this impossible. Instead of a password you type, your device holds a secret key and proves who you are with it. The key is never typed and never sent to a website, so a fake login page has nothing to grab. That is why they are called &lt;strong>phishing-resistant&lt;/strong>, and Microsoft is pushing them hard. On &lt;strong>September 1, 2026&lt;/strong> it switches passkeys on by default and starts nudging users still on text or voice codes to register one. That nudge can be snoozed. The hard deadline is &lt;strong>February 1, 2027&lt;/strong>. After that, if a text or voice code is your only way in, you have to register a passkey before you can sign in, and companies cannot opt out.&lt;/p></description></item></channel></rss>