Nothing to Patch, Everything to Prove
Microsoft holds the only remediation lever for an exploited identity-plane flaw, which leaves your tenant's innocence as something you have to manufacture out of logs you may not still hold.
What the advisory removes, and what it leaves behind
Read precisely, "no customer action required" means the vulnerable code is Microsoft's and there is nothing on the customer side to apply. It does not mean the tenant went untouched, and it produces no artifact you can hand an auditor, a regulator, or a board. There is no published exploitation window, no customer-visible exposure telemetry and no tenant-level impact statement. The absence of a patch task is what converts this from a remediation ticket into a detection engagement.
The binding constraint is retention. Default sign-in and audit log windows in Entra are short, and Microsoft has not published the window they would need to cover. If those logs are not already flowing into the SIEM under retention you control, the evidence ages out before the question is ever asked. That is the first task, ahead of any query.
The hunt, ordered by what it closes
- New or modified service principals and app registrations. The durable foothold in a tenant compromise, and the one that survives password resets.
- Client secrets and certificates added to existing applications, which is how legitimate apps get quietly repurposed.
- Admin consent grants, especially to unverified or newly registered applications.
- Cross-tenant access settings and privileged role assignments changed inside the window.
- MFA and credential registration events that do not correlate to a help-desk ticket or a known device.
Record each hypothesis tested and how it was closed. In an incident with no vendor IOCs, that document is the evidence. No second source of truth is coming.
The same queries are your standing campaign detections
The identity-abuse tradecraft reported alongside this makes those queries permanent rather than incident-scoped. Google is tracking UNC6293 and UNC7005 as likely APT29 sub-clusters handling initial access. Separately, UNC5976 operates against Ukrainian and Armenian defence targets. None of them defeats MFA. Every path ends with the victim approving something the identity provider treats as ordinary.
| Approved action | What the adversary gains | Why it looks legitimate | Detection to ship |
|---|---|---|---|
| App password creation | Mailbox access outside conditional access | A legacy protocol feature, user-initiated | Alert on any creation; disable legacy app passwords tenant-wide |
| OAuth consent grant | Persistent, token-based data access | Consent is a normal user decision | Alert on grants to unverified or newly registered apps |
| Device-code authentication | Full session on an attacker-held device | Designed for input-constrained devices | Alert on the grant; restrict it via Conditional Access |
| WhatsApp device linking | Recorded audio and video from a "secure call" | Occurs entirely on a personal account | Not logged — briefing the high-risk cohort is the only control |
Note where the two readings converge. One frames the Entra flaw as a vendor-side problem the customer cannot fix; the other frames the espionage campaigns as authorized actions the customer cannot block. Both land in the same place: a control validation that asks "was this authorized?" keeps answering yes while the mailbox leaves the building. Three event types in that campaign are visible to a conventional SOC. The rest runs on personal accounts and encrypted messengers where corporate logging never reaches.
The structural fix is standing privilege
Quarterly access reviews cannot bound a compromise that unfolds in hours. Converting eligible-but-permanent privileged roles to just-in-time activation, expiring unused application credentials, and shortening high-privilege review cadence to monthly or continuous is what shrinks the blast radius the next time the only remediation lever sits with the vendor.
When the identity control plane gets an actively exploited CVSS 10.0 flaw and the vendor holds the only patch, your job moves from patching to hunting — and the hunt record is the only evidence you will ever have.
What to do
Export Entra ID sign-in and audit logs to the SIEM under your own retention as a first priority, then run and document the CVE-2026-69836 hunt across service principals, app credentials, consent grants, cross-tenant settings and role assignments.
Ship three identity-abuse detections into production this sprint — app-password creation, OAuth consent to unverified or newly registered apps, and device-code authentication — and disable legacy app passwords tenant-wide.
Open an MSRC case and escalate through your account team for the exploitation window, a tenant-level impact statement and any customer-available IOCs; treat a boilerplate reply as an unresolved item, not a close.