Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Entra ID & Identity

Articles in Entra ID & Identity.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Entra ID & IdentityDetection & Response

Detecting Cloud SSO Compromise: Entra Sign-In Logs and Sentinel KQL

When an SSO or identity provider is compromised, attackers may use stolen credentials or forged tokens to access connected applications. These detections...

Entra ID & IdentityCIO Briefings

CIO Brief: Acting on Unconfirmed Breach Reports

The short version: In 2025, a hacker claimed to have stolen login data from Oracle's cloud. Oracle denied it; researchers said the evidence looked real....

Entra ID & IdentityHow-To & Hardening

How to Roll Out Device-Bound Passkeys in Entra ID

Passkeys in Microsoft Authenticator give users phishing-resistant MFA on their phones. Here is how to roll them out in Entra ID.

Entra ID & IdentityHow-To & Hardening

Passkey Rollout Checklist: Registration, Recovery and Help Desk

Use this checklist to roll out passkeys across your organization.

Entra ID & IdentityCIO Briefings

CIO Brief: Passkeys Make Phishing-Resistant MFA Affordable

The short version: Since 2024, Microsoft lets employees use passkeys on their phones to sign in — the strongest common form of authentication, and immune to...

Entra ID & IdentityPlatform Changes

Secure Future Initiative and Microsoft-Managed Conditional Access Policies (Nov 2023)

On November 2, 2023, Microsoft announced the Secure Future Initiative (SFI), a company-wide security commitment following a series of high-profile...

Entra ID & IdentityHow-To & Hardening

How to Review and Customize Microsoft-Managed Conditional Access Policies

Microsoft automatically creates Conditional Access policies in many tenants. Here is how to review them, customize them safely and make sure they fit with...

Entra ID & IdentityHow-To & Hardening

Conditional Access Policy Review Checklist

Use this checklist to review your Conditional Access policies.

Entra ID & IdentityCIO Briefings

CIO Brief: Microsoft Is Changing Your Defaults — Here's What to Know

The short version: In November 2023, Microsoft announced a major security push — the Secure Future Initiative — and began automatically adding security...

Entra ID & IdentityIncident Teardowns

Okta Support System Breach (Oct 2023): Session Tokens in Uploaded HAR Files

In October 2023, Okta disclosed that an attacker had used stolen credentials to access its customer support case management system and view files uploaded...

Entra ID & IdentityHow-To & Hardening

How to Sanitize Support Uploads and Bind Tokens to Devices

HAR files shared with support teams can contain live session tokens. Token protection and device-bound sessions limit what a stolen token can do. Here is...

Entra ID & IdentityDetection & Response

Detecting Session Token Theft HAR Files: Entra Sign-In Logs and Sentinel KQL

Session tokens taken from HAR files, infostealer logs or phishing proxies are used to access accounts without signing in. Detection focuses on session reuse...

Entra ID & IdentityCIO Briefings

CIO Brief: Your Identity Provider's Breach Is Your Breach

The short version: In 2023, attackers broke into Okta's customer support system and stole login sessions from files customers had uploaded for...

Entra ID & IdentityHow-To & Hardening

How to Harden Help Desk Identity Verification and Password Resets

The help desk is now a primary target for social engineering. Here is how to harden identity verification and password/MFA resets.

Entra ID & IdentityDetection & Response

Detecting Help Desk Social Engineering: Entra Sign-In Logs and Sentinel KQL

Help desk social engineering usually ends with a password or MFA reset followed by an attacker sign-in. These detections connect the two.

Entra ID & IdentityCIO Briefings

CIO Brief: Social Engineering the Help Desk Is the New Ransomware Entry Point

The short version: In 2023, a phone call to MGM's IT help desk reportedly led to a ransomware attack that shut down casinos and hotels for days and cost...

Entra ID & IdentityPlatform Changes

Azure AD Becomes Microsoft Entra ID (July 2023): What Actually Changed

On July 11, 2023, Microsoft announced that Azure Active Directory would be renamed Microsoft Entra ID. The change rolled out across portals, documentation...

Entra ID & IdentityHow-To & Hardening

How to Update Documentation, Scripts and Policies After the Entra ID Rename

The rename from Azure AD to Microsoft Entra ID didn't change functionality, but it's a good reason to update documentation and retire legacy tooling —...

Entra ID & IdentityHow-To & Hardening

Entra ID Configuration Health Checklist

Use this checklist to review the health of your Microsoft Entra ID configuration.

Entra ID & IdentityCIO Briefings

CIO Brief: Renames Don't Change Risk — But Licensing Might

The short version: In 2023, Microsoft renamed Azure Active Directory to Microsoft Entra ID. Nothing about security changed with the name. But renames are a...

Entra ID & IdentityIncident Teardowns

Uber Breached via MFA Fatigue (Sept 2022): A Contractor, a Push Storm and Hardcoded Admin Secrets

On September 15, 2022, Uber disclosed a network security incident. An attacker had gained access to internal systems including its Slack workspace, cloud...

Entra ID & IdentityHow-To & Hardening

How to Write Conditional Access Policies for Contractors and Guests

Contractors and guests often have less oversight than employees but similar access. Conditional Access lets you apply consistent — or stricter — controls....

Entra ID & IdentityDetection & Response

Detecting MFA Push Bombing: Entra Sign-In Logs and Sentinel KQL

MFA push bombing generates bursts of MFA requests. Even with number matching, attackers try variations. These detections help catch attempts early.

Entra ID & IdentityCIO Briefings

CIO Brief: Contractors Need the Same Security as Employees

The short version: In 2022, Uber was breached through a contractor whose password had been stolen and who eventually approved one of many login prompts....

← NewerPage 2 of 5Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.