A lot moved over the weekend while we were trying to tune out the noise. We have Entra dropping passkeys on admins who didn’t ask for them, a Pentagon breach that feels entirely too familiar, and a massive national data leak out of Denmark.

Entra’s passkey surprise

Microsoft’s Entra passkey registration campaign is rolling out, and it is catching a lot of identity admins off guard. People are suddenly finding passkeys registered in their tenants that they never planned for.[1]

This is the double-edged sword of platform defaults. Pushing passkeys is generally the right move for the ecosystem, because phishing resistance shouldn’t be an opt-in luxury. But when a vendor flips the switch globally, it overrides the phased rollouts that enterprise teams planned. If your helpdesk isn’t trained on how to handle synced passkeys or account recovery for them, a sudden influx of registered users is a nightmare.

If you need more time, you can opt out via Graph API, but you have to actively do it. Otherwise, welcome to the passwordless future, ready or not.

OPM-scale flashbacks at the Pentagon

It has been a rough month for federal cybersecurity. The Pentagon is currently notifying over two million current and former military members that their personnel records were stolen.[2]

The data was sitting in a Defense Manpower Data Center system that hackers had access to for months. They pulled Social Security numbers, addresses, and occupational specialties.[2] That last one is the kicker. Knowing exactly what a person does—whether they are infantry, intelligence, or cyber ops—is a goldmine for foreign intelligence services trying to map out high-value targets.

Between this and the recent ShinyHunters breach at the FBI, it’s starting to feel like the 2015 OPM hack all over again. The scale of federal data exfiltration is staggering, and it’s a stark reminder that collecting massive amounts of sensitive data creates a target that is almost impossible to defend perfectly over long timelines.

Denmark’s national database leak

Speaking of massive central databases, Denmark just had a very bad weekend. Unauthorized actors exploited a private company’s legitimate access to the Danish Central Person Register (CPR) and pulled the personal details of about 8.8 million people.[3]

For context, Denmark’s living population is around six million. The 8.8 million number includes deceased individuals and former residents.[3] The attackers abused an existing, lawful API hook-in that a small company held, which means this wasn’t a sophisticated zero-day. It was credential abuse or a compromised endpoint on the third party’s side.

Centralized identity systems are incredibly efficient for governance, but they create a single point of catastrophic failure. When one API key or third-party integration is compromised, the blast radius is the entire country.

The thread connecting them

If there is a theme this weekend, it is the danger of scale. Microsoft forcing a global auth change, the Pentagon centralizing millions of personnel records, and Denmark putting its entire population in one searchable database. Scale brings efficiency, but it also means that when things go sideways, they do so spectacularly.

Lock down your Entra tenant, audit your third-party API connections, and think twice about how much data you actually need to store forever.

Sources

[1] https://entra.news/p/entra-news-168-this-week-in-microsoft [2] https://arstechnica.com/security/2026/10/hacks-of-2-federal-agencies-in-a-month-have-spilled-a-bonanza-of-sensitive-data [3] https://cphpost.dk/2026-10-05/life-in-denmark/cpr-data-breach-exposes-personal-details-of-8-8-million-people-in-denmark