Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Azure

Articles in Azure.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
AzureIncident Teardowns

Storm-2949 (May 2026): From a Fake IT Call to an Azure-Wide Breach

On May 18, 2026, Microsoft Threat Intelligence published details of Storm-2949, a threat actor that turned a single social-engineered identity into a breach...

AzureHow-To & Hardening

How to Harden SSPR, Azure RBAC and VM Run Command Against Identity-Led Attacks

Storm-2949 moved from a social-engineered password reset to Azure-wide control using RBAC permissions and VM management features. Here is how to harden each...

AzurePlatform Changes

Mandatory MFA for the Azure Portal Begins (Oct 2024)

From October 15, 2024, Microsoft began enforcing MFA for the Azure portal, Entra admin center and Intune admin center, and from 2025 for Azure CLI, PowerShell and infrastructure-as-code tools. Here is what it covers, what breaks, and how to migrate automation to workload identities.

AzureIncident Teardowns

Microsoft AI Researchers Expose 38TB via an Overly Permissive SAS Token (Sept 2023)

A single Azure SAS token in a public GitHub repository exposed 38TB of Microsoft data, including 30,000+ Teams messages, for nearly three years. Here is the timeline, why SAS tokens are hard to govern, and how to remove the risk.

AzureDetection & Response

Detecting SSPR Social Engineering: Defender for Cloud and Sentinel KQL

Storm-2949's attack produced signals across Entra ID, Azure Activity, Key Vault and endpoints. These detections connect them.

AzureCIO Briefings

CIO Brief: One Compromised Identity, Every Cloud Layer

The short version: In May 2026, Microsoft described an attack group, Storm-2949, that started by tricking employees into approving fake login requests...

AzurePlatform Changes

Microsoft Ignite 2024: Security Exposure Management and the Windows Resiliency Initiative

At Microsoft Ignite in November 2024, security announcements centered on resilience and exposure. Two stood out: the Windows Resiliency Initiative, a...

AzureHow-To & Hardening

How to Use Attack Path Analysis to Prioritize Cloud Fixes

Not all vulnerabilities and misconfigurations matter equally. Attack path analysis shows which ones an attacker could chain to reach your critical assets....

AzureHow-To & Hardening

Exposure Management Quick-Start Checklist

Use this checklist to start an exposure management program with Microsoft Defender tools.

AzureCIO Briefings

CIO Brief: From Alert Counts to Exposure Management

The short version: Security teams are drowning in alerts and vulnerability lists. In 2024, Microsoft and other vendors pushed a different approach:...

AzureHow-To & Hardening

How to Prepare Service Accounts and Automation for Azure Mandatory MFA

Microsoft's mandatory MFA for Azure breaks automation that signs in as a user with a password. Here is how to find and migrate those service accounts.

AzureHow-To & Hardening

Azure Mandatory MFA Readiness Checklist

Use this checklist to confirm your organization is ready for Azure's mandatory MFA.

AzureCIO Briefings

CIO Brief: Microsoft Now Requires MFA — Is Your Automation Ready?

The short version: Since October 2024, Microsoft requires multi-factor authentication for anyone managing Azure through its web portals, and from 2025 also...

AzureHow-To & Hardening

How to Govern Azure Storage SAS Tokens and Disable Shared Key Access

SAS tokens grant time-limited access to Azure Storage — but poorly scoped tokens can expose entire accounts for years. Here is how to govern them and remove...

AzureDetection & Response

Detecting SAS Token Exposure: Defender for Cloud and Sentinel KQL

Overly permissive or leaked SAS tokens provide direct access to Azure Storage. These detections help find token exposure and misuse.

AzureCIO Briefings

CIO Brief: AI Projects Create New Data Exposure Paths

The short version: In 2023, Microsoft's own AI researchers accidentally exposed 38 terabytes of internal data — including passwords and private messages —...

AzureIncident Teardowns

BlueBleed (Oct 2022): Misconfigured Azure Blob Storage Exposes Microsoft Customer Data

In October 2022, threat intelligence company SOCRadar reported a data leak it called BlueBleed: a misconfigured Microsoft-owned Azure Blob Storage container...

AzureHow-To & Hardening

How to Audit Azure Storage Accounts for Public Access and Shared Keys

Azure Storage accounts can be exposed through anonymous blob access, overly permissive shared keys and SAS tokens, or public network endpoints. Here is how...

AzureDetection & Response

Detecting Azure Blob Public Access: Defender for Cloud and Sentinel KQL

Public Azure Blob access is often discovered by outsiders scanning for open containers. Detecting both the configuration and anonymous access helps you find...

AzureCIO Briefings

CIO Brief: Storage Misconfiguration Is a Cloud-Agnostic Problem

The short version: In 2022, researchers reported that a misconfigured Microsoft storage location exposed business documents involving Microsoft's customers....

AzurePlatform Changes

Microsoft Ignite 2021: Azure Security Center Becomes Microsoft Defender for Cloud

At Microsoft Ignite in November 2021, Microsoft combined Azure Security Center and Azure Defender into a single product: Microsoft Defender for Cloud. It...

AzureHow-To & Hardening

How to Raise Your Defender for Cloud Secure Score in 30 Days

Defender for Cloud's secure score measures how many security recommendations you've implemented. Here is a 30-day plan to raise it meaningfully — focusing...

AzureHow-To & Hardening

Defender for Cloud Plan Selection and Cost Checklist

Defender for Cloud includes a free foundational tier and several paid plans. Use this checklist to decide which to enable and keep costs predictable.

AzureCIO Briefings

CIO Brief: One Dashboard for Multi-Cloud Posture — Hype or Help?

The short version: In 2021, Microsoft combined its Azure security tools into Defender for Cloud, promising one dashboard for security across Azure, AWS and...

Page 1 of 3Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.