The patch that isn't yours: what to do with Entra ID's CVE-2026-69836
On 20 August Microsoft published a critical remote code execution flaw in Entra ID, and the next day corrected the exploitation field to "No". There is nothing to install: the record says "customerActionRequired: false". What is yours is the ability to answer "were we affected?", and on an Entra ID Free licence that lasts seven days. How to read the record from Microsoft's own API, and the checklist we apply to the tenant.