Nyxgeek discovered four Azure Entra ID sign-in log bypasses in the last three years, including GraphNinja, GraphGhost, GraphGoblin, and a fourth bypass involving a long user-agent string. These bypasses allowed attackers to validate passwords without generating log entries, and Microsoft fixed them in record time, but initially downplayed the severity of the issues.