Microsoft has fixed a maximum-severity vulnerability in Entra ID that could have allowed an unauthorised attacker to execute code remotely through unsafe deserialization.