Microsoft Digital Defense Report 2026: what it means for Entra ID

In short: The Microsoft Digital Defense Report 2026 calls identity the primary control plane for defense, covering people, apps, and AI agents, and names "gaps in visibility, access, and governance" as what attackers exploit. Microsoft's first priority for leadership is to report identity exposure and agent permissions. Below are the key findings, and five numbers you can pull from Entra ID to answer them.
What is the Microsoft Digital Defense Report 2026?
The Microsoft Digital Defense Report (MDDR) is Microsoft's yearly analysis of the global threat landscape. The 2026 edition covers July 2025 to June 2026. You can read the full report at aka.ms/MDDR2026.
This year's theme is interconnected risk: "the expanding complexity of modern digital environments continues to create opportunities for adversaries to exploit gaps in visibility, access, and governance" (p.5).
What are the key identity findings in MDDR 2026?
Identity compromise remains the leading threat Microsoft's incident responders see (p.63), and identity is now "the primary control plane for defense" (p.8). The methods are familiar. What has changed is scale, speed, and the target: attackers now go after sessions, tokens, and non-human identities as well as passwords (pp.63-65).
Finding | Number | Page |
|---|---|---|
Initial access through valid accounts, using legitimate credentials | 20% | 44 |
Valid-account intrusions followed by more credential theft | 52.2% | 44 |
Password attacks, year over year | Down 26% | 64 |
Share of AiTM phishing and token theft attacks, first half of 2026 | More than doubled (still comparatively small) | 64 |
Password spray as a share of observed cloud initial access, December 2025 to June 2026 | Over 99% | 73 |
Weekly confirmed malicious vishing over cross-tenant Teams calls, year over year | Up 502% | 46 |
Enterprises already experimenting with AI agents | 88% | 22 |
Once inside with a valid account, attackers harvest more credentials: "one compromised identity fuels the compromise of many more" (p.44). Password spray still dominates by volume. Token theft is growing from a small base, and it gets past MFA in a way a sprayed password can't.
Device code phishing also stands out. Once niche, it is now "a preferred credential theft method for both nation-state and financially motivated actors" (p.65). The user signs in on Microsoft's real device sign-in page. The attacker collects the access and refresh tokens. No password is stolen, and MFA is bypassed.
Why are non-human identities the new target?
Apps, service principals, and agents often hold broad permissions, can't use MFA the way people do, and collect access that is rarely revoked (p.23). That makes them a fast route from one compromised account to company-wide data.
Microsoft's incident response team describes a consistent pattern (p.63):
A human identity is compromised.
The attacker discovers credentials for non-human identities, such as service principals and API keys.
Privileges are escalated using access that already exists.
The attacker acts on the objective, such as exfiltrating data.
The report's Storm-2885 case shows how far one identity reaches (p.61). The attacker compromised a highly privileged cloud identity, used a legitimate Entra ID app with Graph access to read hundreds of thousands of emails, and closed alerts in the security tooling along the way. Everything looked like normal behavior. Microsoft also found that organizations took longer to detect attackers this year (p.35).
Persistence follows the same path. The report lists new app secrets and OAuth consent grants, service principal provisioning, dormant or hidden cloud apps, and long-lived credentials as common ways attackers stay in (p.72).
What does Microsoft recommend for AI agents?
Microsoft recommends that every agent have its own identity, a human sponsor, and only the access it needs, with automated cleanup when that access is no longer needed (pp.22-24).
The report names three risks (p.23):
Agent sprawl. Agent identities grow faster than teams can track them.
Overprivileged access. Agents collect access that is rarely revoked.
No human accountability. Without a sponsor, no one answers when something goes wrong.
One line from the report is worth keeping on file: "No environment should ever have an agent without a human to answer for it" (p.23).
What should companies measure?
Start with five identity numbers you can get from Entra ID. Microsoft's first priority for organizations is to report "identity exposure, patch latency, agent permissions, critical dependencies, dwell time, and recovery readiness" to leadership (p.7). These five are our pick for the identity part:
Apps that can read mail or files across the organization
Apps with no owner, or with long-lived secrets
Agents without an active human sponsor
Admins who can still be phished
Time to revoke a compromised identity
Large enterprises have dedicated identity teams to produce numbers like these. In many organizations, the same IT team that runs Entra ID runs everything else too.
How do you check these in Entra ID?
Four of the five numbers come from pages in the Microsoft Entra admin center. The fifth comes from a timed drill. For each, here is where to look and what good looks like.
1. Apps that can read mail or files across the organization
Look for apps with application permissions such as Mail.Read, Files.Read.All, or Sites.Read.All. These apps act without a signed-in user. In the Storm-2885 case, an Entra ID app with Graph access was the route to hundreds of mailboxes (p.61). Entra ID shows these one app at a time, under Entra ID > Enterprise apps and each app's Permissions page, so the tenant-wide picture takes some assembling.
What good looks like: a short list, each app with a known business purpose. Where an app only needs a few mailboxes, scope it with RBAC for Applications in Exchange Online and remove the tenant-wide permission. For SharePoint, Sites.Selected does the same job.
2. Apps with no owner, or with long-lived secrets
Ownerless apps have no one to review them. Long-lived secrets give attackers lasting access, and the report recommends short-lived tokens and automated rotation (p.63). Treat any secret with a total lifetime over a year as long-lived. Each app's Owners and Certificates & secrets pages are under Entra ID > App registrations.
Check service principals too, since attackers add credentials to them directly (p.73). Those credentials don't show on the app registration, and Microsoft's guidance points to Microsoft Graph to find them.
What good looks like: every app has at least one active owner. Certificates or workload identity federation replace client secrets. Any secret on a service principal has a known reason.
3. Agents without an active human sponsor
Microsoft Entra Agent ID requires a sponsor for each agent identity, and if a sponsor leaves the organization, sponsorship moves to their manager. The risk is quieter: a sponsor who has changed roles, or a manager who inherited an agent they have never heard of.
In the Microsoft Entra admin center, go to Entra ID > Agents > Agent identities and add the Owners and Sponsors column. Agents built on ordinary app registrations don't always appear there, so checks 1 and 2 cover them.
What good looks like: every agent has a sponsor who knows it exists, and sponsor changes trigger a review.
4. Admins who can still be phished
Microsoft recommends device-bound passkeys for admins (p.64). It also warns that weaker methods kept for onboarding and account recovery, such as SMS or email codes, leave the account phishable even when sign-in is strong. The goal is to make "the account itself phishing-resistant" (p.64). If SMS and voice are still in use in your tenant, our guide to retiring SMS and voice in Microsoft Entra ID walks through the change. In Entra ID, Entra ID > Authentication methods > Activity shows the methods each user has registered (Entra ID P1 or P2 required).
What good looks like: every admin has a device-bound passkey, Conditional Access requires it, and no admin has a phishable method left to fall back on. That includes SMS, voice, and email codes, but also Authenticator push and one-time codes.
While you are there, check device code flow. In its critical infrastructure recommendations, the report advises disabling high-risk authentication flows, including unmanaged device code flow (p.87), and Microsoft's Conditional Access guidance is to block it wherever possible. Confirm a Conditional Access policy blocks Authentication flows > Device code flow, with documented exceptions only.
5. Time to revoke a compromised identity
For agents, the report makes revocation speed a measured outcome: "When an agent or its owner is compromised, the time to revoke ... is the operational metric that determines incident impact" (p.24).
The same logic holds for people and apps. Run a drill on a test user, a test app, and a test agent identity, since the drill makes real changes. Time how long it takes to revoke the user's sessions, disable the app and the agent, and remove their secrets and consent grants. Revoking stops new tokens. Tokens already issued can stay valid for 60 to 90 minutes unless the app and resource support Continuous Access Evaluation. Count that in your number.
What good looks like: the full sequence is documented, owned, and done in minutes.
Level up: from checklist to scoreboard
The checks above give you each number once. Modern tenants are secured the modern way, with an identity visibility and intelligence platform that keeps the score. Bsure is that platform for Microsoft: one place to see every identity in Entra ID (people, guests, apps, and agents) and who answers for it. It reads your tenant through read-only Microsoft Graph permissions, runs inside your own Azure subscription, and ranks what it finds by the priorities you set. Here is what each of the five looks like in Bsure:
Apps that read mail or files. Every app with tenant-wide access sits in one list, ranked from critical to low, with where it signs in from.
Ownerless apps and secrets. Bsure flags secrets and certificates before they expire, and every app gets a named owner, notified from the same screen.
Agents without a sponsor. Bsure finds the agents nobody has claimed, the ones left behind when their owner moved on, and the ones that can send data out of the organization, for example by mail. For the ones left behind, it suggests the former owner's manager.
Phishable admins. You see every admin next to the sign-in methods they have registered, including who can still fall back to SMS or a code.
Time to revoke. Bsure never changes your tenant, so the drill stays yours. Knowing which apps, secrets, and agents are in play makes it shorter.
Each finding goes to a named owner, who answers without a Bsure account. Leadership follows the trend on one screen, and a risk you choose to accept gets a reason and a review date.
If you are a Bsure customer, start with the agents nobody has claimed. If not, book a demo and see your own five numbers.
Frequently asked questions
When was the Microsoft Digital Defense Report 2026 published?
Microsoft released the 2026 edition on October 1, 2026. It covers the reporting period from July 2025 to June 2026.
What is the biggest identity threat in MDDR 2026?
Identity compromise remains the leading threat. In Microsoft Defender XDR incidents from December 2025 to June 2026, password spray made up over 99% of observed cloud initial access efforts. Token-based attacks such as AiTM phishing and device code phishing are smaller in volume but growing.
What is device code phishing?
Device code phishing tricks a user into entering a code on Microsoft's real device sign-in page. The attacker receives the user's access and refresh tokens, bypassing passwords and MFA. Microsoft's Conditional Access guidance recommends blocking device code flow wherever possible.
What is an agent sponsor in Entra ID?
A sponsor is the human user or group accountable for an AI agent's purpose, lifecycle decisions, and access reviews. Microsoft Entra Agent ID requires a sponsor for each agent identity.
What are non-human identities?
Non-human identities are accounts used by software rather than people, such as app registrations, service principals, managed identities, and AI agents. MDDR 2026 shows attackers increasingly use them to escalate access and exfiltrate data.
What should a board ask about identity risk?
Microsoft recommends leadership track identity exposure, patch latency, agent permissions, critical dependencies, dwell time, and recovery readiness. For identity, start with the five numbers in this article, and ask for the trend as well as today's number.
Resources
Get the latest from Bsure
Subscribe to newsletter






