×
This Microsoft Entra ID Vulnerability Could Have Been Catastrophic

This Microsoft Entra ID Vulnerability Could Have Been Catastrophic

As businesses around the world have shifted their digital infrastructure over the last decade from self-hosted servers to the cloud, they’ve benefitted from the standardized, built-in security features of major cloud providers like Microsoft. But with so much riding on these systems, there can be potentially disastrous consequences at a massive scale if something goes wrong. Case in point: Security researcher Dirk-jan Mollema recently stumbled upon a pair of vulnerabilities in Microsoft Azure’s identity and access management platform that could have been exploited for a potentially cataclysmic takeover of all Azure customer accounts.

Known as Entra ID, the system stores each Azure cloud customer’s user identities, sign-in access controls, applications, and subscription management tools. Mollema has studied Entra ID security in depth and published multiple studies about weaknesses in the system, which was formerly known as Azure Active Directory. But while preparing to present at the Black Hat security conference in Las Vegas in July, Mollema discovered two vulnerabilities that he realized could be used to gain global administrator privileges—essentially god mode—and compromise every Entra ID directory, or what is known as a “tenant.” Mollema says that this would have exposed nearly every Entra ID tenant in the world other than, perhaps, government cloud infrastructure.

“I was just staring at my screen. I was like, ‘No, this shouldn’’t really happen,’” says Mollema, who runs the Dutch cybersecurity company Outsider Security and specializes in cloud security. “It was quite bad. As bad as it gets, I would say.”

“From my own tenants—my test tenant or even a trial tenant—you could request these tokens and you could impersonate basically anybody else in anybody else’s tenant,” Mollema adds. “That means you could modify other people’s configuration, create new and admin users in that tenant, and do anything you would like.”

Given the seriousness of the vulnerability, Mollema disclosed his findings to the Microsoft Security Response Center on July 14, the same day that he discovered the flaws. Microsoft started investigating the findings that day and issued a fix globally on July 17. The company confirmed to Mollema that the issue was fixed by July 23 and implemented extra measures in August. Microsoft issued a CVE for the vulnerability on September 4.

“We mitigated the newly identified issue quickly, and accelerated the remediation work underway to decommission this legacy protocol usage, as part of our Secure Future Initiative,” Tom Gallagher, Microsoft’s Security Response Center vice president of engineering, told WIRED in a statement. “We implemented a code change within the vulnerable validation logic, tested the fix, and applied it across our cloud ecosystem.”

Gallagher says that Microsoft found “no evidence of abuse” of the vulnerability during its investigation.

Both vulnerabilities relate to legacy systems still functioning within Entra ID. The first involves a type of Azure authentication token Mollema discovered known as Actor Tokens that are issued by an obscure Azure mechanism called the “Access Control Service.” Actor Tokens have some special system properties that Mollema realized could be useful to an attacker when combined with another vulnerability. The other bug was a major flaw in a historic Azure Active Directory application programming interface known as “Graph” that was used to facilitate access to data stored in Microsoft 365. Microsoft is in the process of retiring Azure Active Directory Graph and transitioning users to its successor, Microsoft Graph, which is designed for Entra ID. The flaw was related to a failure by Azure AD Graph to properly validate which Azure tenant was making an access request, which could be manipulated so the API would accept an Actor Token from a different tenant that should have been rejected.

Source link
#Microsoft #Entra #Vulnerability #Catastrophic

Microsoft is purchasing 650,000 metric tons of carbon removal credits from startup BioCirc, the company said today. 

As carbon removal deals go, it’s not a big buy. But this one is notable because last month, two reports said the tech giant was pausing its carbon removal deals. BioCirc confirmed for TechCrunch that the purchase agreement was signed in May, weeks after Microsoft reportedly paused new deals.

For the carbon removal industry — and the startups that depend on it — there’s a big difference between a pause and a recalibration. Microsoft is reportedly responsible for more than 90% of the carbon removal credit market, meaning its purchasing decisions alone can determine whether young companies in the space survive.

Microsoft repeatedly denied that it had paused its carbon removal purchases. “Our carbon removal program has not ended,” Melanie Nakagawa, chief sustainability officer at Microsoft, told TechCrunch in a statement. “At times we may adjust the pace or volume of our carbon removal procurement as we continue to refine our approach toward sustainability goals.”

The new deal generates carbon removal credits from five BioCirc biogas projects. The biogas plants take biomass waste — frequently from agriculture — and use industrial bioreactors to turn it into methane and carbon dioxide. BioCirc captures the carbon dioxide and stores it in an underground reservoir offshore. The methane is then burned in a power plant. 

Microsoft’s sustainability goals have been strained by the company’s push into AI. To power its data centers in Texas, Microsoft last month said it was working with Chevron and Engine No. 1 to build a natural gas power plant in the state that could eventually generate 5 gigawatts of electricity. Emissions from that project alone promise to dwarf the deal with BioCirc.

Internally, Microsoft employees have also been debating whether to abandon the company’s goal of matching zero emissions electricity with its energy use on an hourly basis. Today, the company matches on an annual basis. That approach gives the company more flexibility to, say, use more natural gas to power its data centers at night, but it also makes the company’s clean energy claims harder to verify.

If Microsoft continues to pursue fossil fuel power plants, it’ll need to ramp up its carbon removal purchases to meet its 2030 target of becoming a carbon negative company (one that removes more greenhouse gases from the atmosphere than it generates). 

Last year, Microsoft signed several deals worth millions of tons of carbon removal credits. The program’s reported pause set off alarm bells throughout the carbon removal industry, which is still in its infancy.

The new deal suggests that Microsoft is, in fact, recalibrating its carbon removal program — not abandoning it. Whether that remains true as AI drives its energy consumption higher is something the industry will be watching.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

#Microsofts #carbon #removal #plans #arent #dead #TechCrunchMicrosoft,biogas,Exclusive,carbon credits,carbon removal">Microsoft’s carbon removal plans aren’t dead after all | TechCrunch
Microsoft is purchasing 650,000 metric tons of carbon removal credits from startup BioCirc, the company said today. 

As carbon removal deals go, it’s not a big buy. But this one is notable because last month, two reports said the tech giant was pausing its carbon removal deals. BioCirc confirmed for TechCrunch that the purchase agreement was signed in May, weeks after Microsoft reportedly paused new deals.







For the carbon removal industry — and the startups that depend on it — there’s a big difference between a pause and a recalibration. Microsoft is reportedly responsible for more than 90% of the carbon removal credit market, meaning its purchasing decisions alone can determine whether young companies in the space survive.

Microsoft repeatedly denied that it had paused its carbon removal purchases. “Our carbon removal program has not ended,” Melanie Nakagawa, chief sustainability officer at Microsoft, told TechCrunch in a statement. “At times we may adjust the pace or volume of our carbon removal procurement as we continue to refine our approach toward sustainability goals.”

The new deal generates carbon removal credits from five BioCirc biogas projects. The biogas plants take biomass waste — frequently from agriculture — and use industrial bioreactors to turn it into methane and carbon dioxide. BioCirc captures the carbon dioxide and stores it in an underground reservoir offshore. The methane is then burned in a power plant. 

Microsoft’s sustainability goals have been strained by the company’s push into AI. To power its data centers in Texas, Microsoft last month said it was working with Chevron and Engine No. 1 to build a natural gas power plant in the state that could eventually generate 5 gigawatts of electricity. Emissions from that project alone promise to dwarf the deal with BioCirc.

Internally, Microsoft employees have also been debating whether to abandon the company’s goal of matching zero emissions electricity with its energy use on an hourly basis. Today, the company matches on an annual basis. That approach gives the company more flexibility to, say, use more natural gas to power its data centers at night, but it also makes the company’s clean energy claims harder to verify.


If Microsoft continues to pursue fossil fuel power plants, it’ll need to ramp up its carbon removal purchases to meet its 2030 target of becoming a carbon negative company (one that removes more greenhouse gases from the atmosphere than it generates). 

Last year, Microsoft signed several deals worth millions of tons of carbon removal credits. The program’s reported pause set off alarm bells throughout the carbon removal industry, which is still in its infancy.

The new deal suggests that Microsoft is, in fact, recalibrating its carbon removal program — not abandoning it. Whether that remains true as AI drives its energy consumption higher is something the industry will be watching.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.#Microsofts #carbon #removal #plans #arent #dead #TechCrunchMicrosoft,biogas,Exclusive,carbon credits,carbon removal

two reports said the tech giant was pausing its carbon removal deals. BioCirc confirmed for TechCrunch that the purchase agreement was signed in May, weeks after Microsoft reportedly paused new deals.

For the carbon removal industry — and the startups that depend on it — there’s a big difference between a pause and a recalibration. Microsoft is reportedly responsible for more than 90% of the carbon removal credit market, meaning its purchasing decisions alone can determine whether young companies in the space survive.

Microsoft repeatedly denied that it had paused its carbon removal purchases. “Our carbon removal program has not ended,” Melanie Nakagawa, chief sustainability officer at Microsoft, told TechCrunch in a statement. “At times we may adjust the pace or volume of our carbon removal procurement as we continue to refine our approach toward sustainability goals.”

The new deal generates carbon removal credits from five BioCirc biogas projects. The biogas plants take biomass waste — frequently from agriculture — and use industrial bioreactors to turn it into methane and carbon dioxide. BioCirc captures the carbon dioxide and stores it in an underground reservoir offshore. The methane is then burned in a power plant. 

Microsoft’s sustainability goals have been strained by the company’s push into AI. To power its data centers in Texas, Microsoft last month said it was working with Chevron and Engine No. 1 to build a natural gas power plant in the state that could eventually generate 5 gigawatts of electricity. Emissions from that project alone promise to dwarf the deal with BioCirc.

Internally, Microsoft employees have also been debating whether to abandon the company’s goal of matching zero emissions electricity with its energy use on an hourly basis. Today, the company matches on an annual basis. That approach gives the company more flexibility to, say, use more natural gas to power its data centers at night, but it also makes the company’s clean energy claims harder to verify.

If Microsoft continues to pursue fossil fuel power plants, it’ll need to ramp up its carbon removal purchases to meet its 2030 target of becoming a carbon negative company (one that removes more greenhouse gases from the atmosphere than it generates). 

Last year, Microsoft signed several deals worth millions of tons of carbon removal credits. The program’s reported pause set off alarm bells throughout the carbon removal industry, which is still in its infancy.

The new deal suggests that Microsoft is, in fact, recalibrating its carbon removal program — not abandoning it. Whether that remains true as AI drives its energy consumption higher is something the industry will be watching.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

#Microsofts #carbon #removal #plans #arent #dead #TechCrunchMicrosoft,biogas,Exclusive,carbon credits,carbon removal">Microsoft’s carbon removal plans aren’t dead after all | TechCrunch

Microsoft is purchasing 650,000 metric tons of carbon removal credits from startup BioCirc, the company said today. 

As carbon removal deals go, it’s not a big buy. But this one is notable because last month, two reports said the tech giant was pausing its carbon removal deals. BioCirc confirmed for TechCrunch that the purchase agreement was signed in May, weeks after Microsoft reportedly paused new deals.

For the carbon removal industry — and the startups that depend on it — there’s a big difference between a pause and a recalibration. Microsoft is reportedly responsible for more than 90% of the carbon removal credit market, meaning its purchasing decisions alone can determine whether young companies in the space survive.

Microsoft repeatedly denied that it had paused its carbon removal purchases. “Our carbon removal program has not ended,” Melanie Nakagawa, chief sustainability officer at Microsoft, told TechCrunch in a statement. “At times we may adjust the pace or volume of our carbon removal procurement as we continue to refine our approach toward sustainability goals.”

The new deal generates carbon removal credits from five BioCirc biogas projects. The biogas plants take biomass waste — frequently from agriculture — and use industrial bioreactors to turn it into methane and carbon dioxide. BioCirc captures the carbon dioxide and stores it in an underground reservoir offshore. The methane is then burned in a power plant. 

Microsoft’s sustainability goals have been strained by the company’s push into AI. To power its data centers in Texas, Microsoft last month said it was working with Chevron and Engine No. 1 to build a natural gas power plant in the state that could eventually generate 5 gigawatts of electricity. Emissions from that project alone promise to dwarf the deal with BioCirc.

Internally, Microsoft employees have also been debating whether to abandon the company’s goal of matching zero emissions electricity with its energy use on an hourly basis. Today, the company matches on an annual basis. That approach gives the company more flexibility to, say, use more natural gas to power its data centers at night, but it also makes the company’s clean energy claims harder to verify.

If Microsoft continues to pursue fossil fuel power plants, it’ll need to ramp up its carbon removal purchases to meet its 2030 target of becoming a carbon negative company (one that removes more greenhouse gases from the atmosphere than it generates). 

Last year, Microsoft signed several deals worth millions of tons of carbon removal credits. The program’s reported pause set off alarm bells throughout the carbon removal industry, which is still in its infancy.

The new deal suggests that Microsoft is, in fact, recalibrating its carbon removal program — not abandoning it. Whether that remains true as AI drives its energy consumption higher is something the industry will be watching.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

#Microsofts #carbon #removal #plans #arent #dead #TechCrunchMicrosoft,biogas,Exclusive,carbon credits,carbon removal
Garmin now wants to help address through a new initiative in partnership with MyKrida. The company has equipped seven emerging athletes from tribal regions across India with Garmin Forerunner smartwatches to help them access structured performance tracking and training insights.

Garmin Wants to Bring Data-Driven Training to More Athletes

Garmin Partners With MyKrida to Support Grassroots Athletes in India
	
Fitness wearables today are usually marketed toward marathon runners, cyclists, and people already deep into the fitness ecosystem. But for many talented athletes in India, especially those from remote or underrepresented regions, access to proper training tools remains a major challenge. That’s something Garmin now wants to help address through a new initiative in partnership with MyKrida. The company has equipped seven emerging athletes from tribal regions across India with Garmin Forerunner smartwatches to help them access structured performance tracking and training insights.



Garmin Wants to Bring Data-Driven Training to More Athletes







The idea behind the initiative is fairly straightforward. Garmin’s Forerunner smartwatches can track metrics like heart rate, pace, distance, recovery, sleep quality, and training load. For professional athletes, this kind of data is already standard. But for many young athletes in smaller regions, access to these tools can genuinely change how they train. Garmin says the watches are meant to help athletes train smarter and improve consistency through better recovery and performance monitoring rather than simply increasing training intensity.



According to Deepak Raina, Director at AMIT GPS & Navigation LLP:




India has immense untapped athletic potential, particularly in regions where access to structured training tools remains limited. At Garmin, our focus is on enabling athletes with reliable, performance-led technology that brings clarity to how they train, recover, and improve. Through this initiative, we aim to support long-term athletic development and help these athletes compete with greater confidence and consistency.




The on-ground implementation is being managed by MyKrida, which works across grassroots and elite sports development programs in India. The platform focuses heavily on identifying athletes early and connecting them with structured support systems. According to MyKrida founder Shubham Sharma, the collaboration with Garmin helps bring “world-class performance technology directly to these athletes.”

#Garmin #Partners #MyKrida #Support #Grassroots #Athletes #IndiaGarmin

The idea behind the initiative is fairly straightforward. Garmin’s Forerunner smartwatches can track metrics like heart rate, pace, distance, recovery, sleep quality, and training load. For professional athletes, this kind of data is already standard. But for many young athletes in smaller regions, access to these tools can genuinely change how they train. Garmin says the watches are meant to help athletes train smarter and improve consistency through better recovery and performance monitoring rather than simply increasing training intensity.

According to Deepak Raina, Director at AMIT GPS & Navigation LLP:

India has immense untapped athletic potential, particularly in regions where access to structured training tools remains limited. At Garmin, our focus is on enabling athletes with reliable, performance-led technology that brings clarity to how they train, recover, and improve. Through this initiative, we aim to support long-term athletic development and help these athletes compete with greater confidence and consistency.

The on-ground implementation is being managed by MyKrida, which works across grassroots and elite sports development programs in India. The platform focuses heavily on identifying athletes early and connecting them with structured support systems. According to MyKrida founder Shubham Sharma, the collaboration with Garmin helps bring “world-class performance technology directly to these athletes.”

#Garmin #Partners #MyKrida #Support #Grassroots #Athletes #IndiaGarmin">Garmin Partners With MyKrida to Support Grassroots Athletes in India
	
Fitness wearables today are usually marketed toward marathon runners, cyclists, and people already deep into the fitness ecosystem. But for many talented athletes in India, especially those from remote or underrepresented regions, access to proper training tools remains a major challenge. That’s something Garmin now wants to help address through a new initiative in partnership with MyKrida. The company has equipped seven emerging athletes from tribal regions across India with Garmin Forerunner smartwatches to help them access structured performance tracking and training insights.



Garmin Wants to Bring Data-Driven Training to More Athletes







The idea behind the initiative is fairly straightforward. Garmin’s Forerunner smartwatches can track metrics like heart rate, pace, distance, recovery, sleep quality, and training load. For professional athletes, this kind of data is already standard. But for many young athletes in smaller regions, access to these tools can genuinely change how they train. Garmin says the watches are meant to help athletes train smarter and improve consistency through better recovery and performance monitoring rather than simply increasing training intensity.



According to Deepak Raina, Director at AMIT GPS & Navigation LLP:




India has immense untapped athletic potential, particularly in regions where access to structured training tools remains limited. At Garmin, our focus is on enabling athletes with reliable, performance-led technology that brings clarity to how they train, recover, and improve. Through this initiative, we aim to support long-term athletic development and help these athletes compete with greater confidence and consistency.




The on-ground implementation is being managed by MyKrida, which works across grassroots and elite sports development programs in India. The platform focuses heavily on identifying athletes early and connecting them with structured support systems. According to MyKrida founder Shubham Sharma, the collaboration with Garmin helps bring “world-class performance technology directly to these athletes.”

#Garmin #Partners #MyKrida #Support #Grassroots #Athletes #IndiaGarmin

now wants to help address through a new initiative in partnership with MyKrida. The company has equipped seven emerging athletes from tribal regions across India with Garmin Forerunner smartwatches to help them access structured performance tracking and training insights.

Garmin Wants to Bring Data-Driven Training to More Athletes

Garmin Partners With MyKrida to Support Grassroots Athletes in India
	
Fitness wearables today are usually marketed toward marathon runners, cyclists, and people already deep into the fitness ecosystem. But for many talented athletes in India, especially those from remote or underrepresented regions, access to proper training tools remains a major challenge. That’s something Garmin now wants to help address through a new initiative in partnership with MyKrida. The company has equipped seven emerging athletes from tribal regions across India with Garmin Forerunner smartwatches to help them access structured performance tracking and training insights.



Garmin Wants to Bring Data-Driven Training to More Athletes







The idea behind the initiative is fairly straightforward. Garmin’s Forerunner smartwatches can track metrics like heart rate, pace, distance, recovery, sleep quality, and training load. For professional athletes, this kind of data is already standard. But for many young athletes in smaller regions, access to these tools can genuinely change how they train. Garmin says the watches are meant to help athletes train smarter and improve consistency through better recovery and performance monitoring rather than simply increasing training intensity.



According to Deepak Raina, Director at AMIT GPS & Navigation LLP:




India has immense untapped athletic potential, particularly in regions where access to structured training tools remains limited. At Garmin, our focus is on enabling athletes with reliable, performance-led technology that brings clarity to how they train, recover, and improve. Through this initiative, we aim to support long-term athletic development and help these athletes compete with greater confidence and consistency.




The on-ground implementation is being managed by MyKrida, which works across grassroots and elite sports development programs in India. The platform focuses heavily on identifying athletes early and connecting them with structured support systems. According to MyKrida founder Shubham Sharma, the collaboration with Garmin helps bring “world-class performance technology directly to these athletes.”

#Garmin #Partners #MyKrida #Support #Grassroots #Athletes #IndiaGarmin

The idea behind the initiative is fairly straightforward. Garmin’s Forerunner smartwatches can track metrics like heart rate, pace, distance, recovery, sleep quality, and training load. For professional athletes, this kind of data is already standard. But for many young athletes in smaller regions, access to these tools can genuinely change how they train. Garmin says the watches are meant to help athletes train smarter and improve consistency through better recovery and performance monitoring rather than simply increasing training intensity.

According to Deepak Raina, Director at AMIT GPS & Navigation LLP:

India has immense untapped athletic potential, particularly in regions where access to structured training tools remains limited. At Garmin, our focus is on enabling athletes with reliable, performance-led technology that brings clarity to how they train, recover, and improve. Through this initiative, we aim to support long-term athletic development and help these athletes compete with greater confidence and consistency.

The on-ground implementation is being managed by MyKrida, which works across grassroots and elite sports development programs in India. The platform focuses heavily on identifying athletes early and connecting them with structured support systems. According to MyKrida founder Shubham Sharma, the collaboration with Garmin helps bring “world-class performance technology directly to these athletes.”

#Garmin #Partners #MyKrida #Support #Grassroots #Athletes #IndiaGarmin">Garmin Partners With MyKrida to Support Grassroots Athletes in India

Fitness wearables today are usually marketed toward marathon runners, cyclists, and people already deep into the fitness ecosystem. But for many talented athletes in India, especially those from remote or underrepresented regions, access to proper training tools remains a major challenge. That’s something Garmin now wants to help address through a new initiative in partnership with MyKrida. The company has equipped seven emerging athletes from tribal regions across India with Garmin Forerunner smartwatches to help them access structured performance tracking and training insights.

Garmin Wants to Bring Data-Driven Training to More Athletes

Garmin Partners With MyKrida to Support Grassroots Athletes in India
	
Fitness wearables today are usually marketed toward marathon runners, cyclists, and people already deep into the fitness ecosystem. But for many talented athletes in India, especially those from remote or underrepresented regions, access to proper training tools remains a major challenge. That’s something Garmin now wants to help address through a new initiative in partnership with MyKrida. The company has equipped seven emerging athletes from tribal regions across India with Garmin Forerunner smartwatches to help them access structured performance tracking and training insights.



Garmin Wants to Bring Data-Driven Training to More Athletes







The idea behind the initiative is fairly straightforward. Garmin’s Forerunner smartwatches can track metrics like heart rate, pace, distance, recovery, sleep quality, and training load. For professional athletes, this kind of data is already standard. But for many young athletes in smaller regions, access to these tools can genuinely change how they train. Garmin says the watches are meant to help athletes train smarter and improve consistency through better recovery and performance monitoring rather than simply increasing training intensity.



According to Deepak Raina, Director at AMIT GPS & Navigation LLP:




India has immense untapped athletic potential, particularly in regions where access to structured training tools remains limited. At Garmin, our focus is on enabling athletes with reliable, performance-led technology that brings clarity to how they train, recover, and improve. Through this initiative, we aim to support long-term athletic development and help these athletes compete with greater confidence and consistency.




The on-ground implementation is being managed by MyKrida, which works across grassroots and elite sports development programs in India. The platform focuses heavily on identifying athletes early and connecting them with structured support systems. According to MyKrida founder Shubham Sharma, the collaboration with Garmin helps bring “world-class performance technology directly to these athletes.”

#Garmin #Partners #MyKrida #Support #Grassroots #Athletes #IndiaGarmin

The idea behind the initiative is fairly straightforward. Garmin’s Forerunner smartwatches can track metrics like heart rate, pace, distance, recovery, sleep quality, and training load. For professional athletes, this kind of data is already standard. But for many young athletes in smaller regions, access to these tools can genuinely change how they train. Garmin says the watches are meant to help athletes train smarter and improve consistency through better recovery and performance monitoring rather than simply increasing training intensity.

According to Deepak Raina, Director at AMIT GPS & Navigation LLP:

India has immense untapped athletic potential, particularly in regions where access to structured training tools remains limited. At Garmin, our focus is on enabling athletes with reliable, performance-led technology that brings clarity to how they train, recover, and improve. Through this initiative, we aim to support long-term athletic development and help these athletes compete with greater confidence and consistency.

The on-ground implementation is being managed by MyKrida, which works across grassroots and elite sports development programs in India. The platform focuses heavily on identifying athletes early and connecting them with structured support systems. According to MyKrida founder Shubham Sharma, the collaboration with Garmin helps bring “world-class performance technology directly to these athletes.”

#Garmin #Partners #MyKrida #Support #Grassroots #Athletes #IndiaGarmin

Post Comment