Detecting Cloud SSO Compromise: Entra Sign-In Logs and Sentinel KQL
When an SSO or identity provider is compromised, attackers may use stolen credentials or forged tokens to access connected applications. These detections...
Insights
Articles in Entra ID & Identity.
When an SSO or identity provider is compromised, attackers may use stolen credentials or forged tokens to access connected applications. These detections...
The short version: In 2025, a hacker claimed to have stolen login data from Oracle's cloud. Oracle denied it; researchers said the evidence looked real....
Passkeys in Microsoft Authenticator give users phishing-resistant MFA on their phones. Here is how to roll them out in Entra ID.
Use this checklist to roll out passkeys across your organization.
The short version: Since 2024, Microsoft lets employees use passkeys on their phones to sign in — the strongest common form of authentication, and immune to...
On November 2, 2023, Microsoft announced the Secure Future Initiative (SFI), a company-wide security commitment following a series of high-profile...
Microsoft automatically creates Conditional Access policies in many tenants. Here is how to review them, customize them safely and make sure they fit with...
Use this checklist to review your Conditional Access policies.
The short version: In November 2023, Microsoft announced a major security push — the Secure Future Initiative — and began automatically adding security...
In October 2023, Okta disclosed that an attacker had used stolen credentials to access its customer support case management system and view files uploaded...
HAR files shared with support teams can contain live session tokens. Token protection and device-bound sessions limit what a stolen token can do. Here is...
Session tokens taken from HAR files, infostealer logs or phishing proxies are used to access accounts without signing in. Detection focuses on session reuse...
The short version: In 2023, attackers broke into Okta's customer support system and stole login sessions from files customers had uploaded for...
The help desk is now a primary target for social engineering. Here is how to harden identity verification and password/MFA resets.
Help desk social engineering usually ends with a password or MFA reset followed by an attacker sign-in. These detections connect the two.
The short version: In 2023, a phone call to MGM's IT help desk reportedly led to a ransomware attack that shut down casinos and hotels for days and cost...
On July 11, 2023, Microsoft announced that Azure Active Directory would be renamed Microsoft Entra ID. The change rolled out across portals, documentation...
The rename from Azure AD to Microsoft Entra ID didn't change functionality, but it's a good reason to update documentation and retire legacy tooling —...
Use this checklist to review the health of your Microsoft Entra ID configuration.
The short version: In 2023, Microsoft renamed Azure Active Directory to Microsoft Entra ID. Nothing about security changed with the name. But renames are a...
On September 15, 2022, Uber disclosed a network security incident. An attacker had gained access to internal systems including its Slack workspace, cloud...
Contractors and guests often have less oversight than employees but similar access. Conditional Access lets you apply consistent — or stricter — controls....
MFA push bombing generates bursts of MFA requests. Even with number matching, attackers try variations. These detections help catch attempts early.
The short version: In 2022, Uber was breached through a contractor whose password had been stolen and who eventually approved one of many login prompts....