Remix.run Logo
▲ verst 3 hours ago

There is an internal library at Microsoft that reliably avoids all these JWT problems - Microsoft Identity Service Essentials (MISE). Adopting MISE and upgrading to the latest versions of it have been part of the Secure Future Initiative (SFI) that can be read about in the news of previous years. Unfortunately it sounds like the service team intentionally deferred the compliance alerts they will have received.

▲jhfdbkofdchk 3 hours ago | parent [-]

There is so much work to do for SFI that is still being ignored. The only way that some of these services will update is by being the target of the red team, security researcher, or threat actor.

▲verst 3 hours ago | parent [-]

And all of that is definitely happening.

That being said, just last night I observed that the identity team is now opening up agent-assisted PRs against individual service team repos to force MISE adoption and upgrade to the latest version and best practices. I think that's a great thing because many individual service teams simply lack the bandwidth or knowledge. Prior to GenAI availability I wasted many cycles on this kind of work. While GenAI made it easier - internal source documentation still does not unambiguously address every use case. So having the identity team drive this now with the help of agent sessions initiated by them is great.