Start with Identity
This Week in Identity · Issue 4 · 2026-07-14 · Covers 2026-07-08 to 2026-07-14

This Week in Identity, Issue 4

Issue 4 of This Week in Identity. A big week for passkeys, in both directions.

In brief

  • Entra ID is making passkeys the default authentication method and retiring SMS and voice in 2027, the largest single push toward phishing-resistant credentials to date.
  • Attackers are already phishing the enrollment step rather than the login, because enrolling an attacker-controlled passkey is durable and looks legitimate afterwards.
  • A SharePoint JWT validation bug let an unauthenticated attacker become any user, with no password and no MFA prompt anywhere in the chain.

The big story

Microsoft is making passkeys the default in Entra ID, and phasing out SMS and voice in 2027. Announced alongside Google Workspace adding FIDO2 keys to Windows login the following week, this is the point at which phishing-resistant authentication becomes the path of least resistance rather than a project.

Why it matters: the attacks in the same news cycle tell you where the work moves next. Entra passkey enrollment vishing targets the registration flow, not the login. A passkey the attacker enrolled is a passkey that works forever, is phishing-resistant on their behalf, and raises no alerts. Enrollment is now the weakest link in a passwordless rollout, which means it needs the same rigor as a password reset: verified identity, an existing strong factor, and an alert on every new credential registered. Sources: Entra passkey default, enrollment vishing.

Patch this week

  • CVE-2026-55040 (CVSS 9.1), SharePoint. Four JWT validation weaknesses chain into an unauthenticated bypass: know a target's SID or UPN and you are them, up to farm administrator. Patched July 2026. Post.

The pattern

Three separate stories this week are token forgery or token theft rather than password compromise: the SharePoint JWT bypass, OAuth client ID spoofing used to validate stolen Entra credentials, and device-code phishing kits. The credential is increasingly beside the point. See token replay against unbound endpoints and device code phishing for the classes.

What else happened

  • A CISA contractor left AWS GovCloud admin keys in a public GitHub repo for six months. The lesson is not "developers leak keys," it is that nobody was scanning. Secrets in repositories and CI is the technique; automated detection at push time is the control. Post.
  • npm 12 disabled install scripts by default and began killing tokens that bypass 2FA, removing two of the supply chain's most reliable footholds. Post.
  • Jalisco and OmegaLord, two phishing kits built around device-code abuse, moved the technique from research to commodity. Post.
  • OAuth client ID spoofing let attackers test whether stolen Entra credentials are valid without triggering a sign-in. Post.

New from Start with Identity

  • Vendor internal linking is now editorial policy: every article, guide and ranking links first mentions to the vendor profile, which we applied across 57 articles this week.
  • An IAM interview questions repository and a refresh of every career guide.
  • A FIDO and passkey news hub, plus depth passes on the SAML, OIDC and WebAuthn standards pages.

From the community

Corrections are welcome and credited. Send them through the contact form.

That's Issue 4. Subscribe for the next one.

Free to read and share. Independent and community-driven, no sponsorship. Subscribe to get the next issue.