{"record":"Microsoft Entra ID evidence record","url":"https://nexalign.io/vendors/microsoft-entra-id","vendor":{"slug":"microsoft-entra-id","name":"Microsoft Entra ID","domain":"microsoft.com","category":"iam","categoryLabel":"Identity and access management"},"lastChecked":"2026-07-17T10:22:56.943Z","coverage":{"earliest":"2025-06-05T22:29:40.000Z","latest":"2026-07-17T10:22:56.943Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":41,"kindsOfSource":6,"attributedAdvisories":5,"knownExploited":0,"registerEntriesNotAttributable":23,"practitionerThreads":4,"independentItems":4,"vendorPublishedItems":0,"shareFromSourcesTheVendorDoesNotControl":1},"sources":[{"source":"National Vulnerability Database","operator":"NIST, United States Department of Commerce","classification":"authoritative","items":21,"latest":"2026-07-16T16:19:13.360Z"},{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":5,"latest":"2026-06-24T20:54:13.000Z"},{"source":"CERT-Bund security advisories","operator":"BSI, Federal Republic of Germany","classification":"authoritative","items":2,"latest":"2026-05-26T12:17:29.663Z"},{"source":"Practitioner discussions","operator":"Reddit, public threads","classification":"independent","items":5,"latest":"2026-04-01T10:57:05.000Z"},{"source":"Engineering discussions","operator":"Hacker News, public threads","classification":"independent","items":4,"latest":"2026-07-15T12:11:02.000Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":4,"latest":"2026-07-17T10:22:56.943Z"}],"advisories":{"shown":5,"total":5,"truncated":false,"items":[{"id":"CVE-2026-32208","description":"Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an authorized attacker to perform spoofing over a network.","severity":"high","cvss":8.8,"knownExploited":false,"date":"2026-06-19T21:16:41.883Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2026-32208"]},{"id":"WID-SEC-2026-1636","description":"Affected products: Microsoft Entra, Microsoft Azure","severity":"high","cvss":10,"knownExploited":false,"date":"2026-05-26T12:17:29.663Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1636"]},{"id":"CVE-2026-42901","description":"Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.","severity":"critical","cvss":10,"knownExploited":false,"date":"2026-05-22T23:16:55.670Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2026-42901"]},{"id":"WID-SEC-2026-1273","description":"Affected products: Microsoft Entra","severity":"high","cvss":10,"knownExploited":false,"date":"2026-04-27T10:09:01.528Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1273"]},{"id":"CVE-2026-35431","description":"Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network.","severity":"critical","cvss":10,"knownExploited":false,"date":"2026-04-23T22:16:38.510Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2026-35431"]}]},"practitionerThreads":{"shown":4,"total":4,"truncated":false,"items":[{"title":"Microsoft Entra ID Will Retire SMS and Voice Authentication","context":"Hacker News","url":"https://news.ycombinator.com/item?id=48919589","date":"2026-07-15T12:11:02.000Z"},{"title":"Microsoft introduces Backup and Recovery for Microsoft Entra ID!","context":"r/sysadmin","url":"https://www.reddit.com/r/sysadmin/comments/1ryeakf/microsoft_introduces_backup_and_recovery_for/","date":"2026-03-19T22:17:10.000Z"},{"title":"Microsoft Entra ID Vulnerability Could Have Been Catastrophic","context":"Hacker News","url":"https://news.ycombinator.com/item?id=45305269","date":"2025-09-19T19:11:44.000Z"},{"title":"New downgrade attack can bypass FIDO auth in Microsoft Entra ID","context":"Hacker News","url":"https://news.ycombinator.com/item?id=44892701","date":"2025-08-13T19:26:02.000Z"}]},"independentCoverage":{"shown":4,"total":4,"truncated":false,"items":[{"title":"Microsoft Entra ID (Azure AD) reviews, pricing and features 2026","host":"peerspot.com","url":"https://www.peerspot.com/products/microsoft-entra-id-reviews","date":null},{"title":"Microsoft Entra ID Reviews & Ratings 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/product/microsoft-entra-id","date":null},{"title":"Top Microsoft Entra ID Alternatives & Competitors 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/product/microsoft-entra-id/alternatives","date":null},{"title":"Microsoft Entra ID Reviews, Ratings & Features 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/identity-governance-administration/vendor/microsoft/product/microsoft-entra-id","date":null}]},"vendorPublished":{"shown":0,"total":0,"truncated":false,"items":[]},"openQuestions":["A further 23 register entries mention Microsoft Entra ID without naming a product of Microsoft Entra ID as affected. They are excluded rather than counted as vulnerabilities.","Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}