Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Entra ID & Identity

Articles in Entra ID & Identity.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Entra ID & IdentityIncident Teardowns

0ktapus and the Twilio Breach (Aug 2022): SMS Phishing Against 130+ Companies

In August 2022, researchers at Group-IB described a phishing campaign they named 0ktapus. It targeted employees of more than 130 organizations — many of...

Entra ID & IdentityHow-To & Hardening

How to Deploy FIDO2 Security Keys for High-Risk Users

FIDO2 security keys provide phishing-resistant MFA: they won't authenticate to a fake site. Here is how to deploy them in Entra ID for high-risk users.

Entra ID & IdentityDetection & Response

Detecting SMS Phishing Credential Harvesting: Entra Sign-In Logs and Sentinel KQL

SMS phishing campaigns like 0ktapus harvest credentials and MFA codes through fake sign-in pages. Detection focuses on the sign-ins that follow.

Entra ID & IdentityCIO Briefings

CIO Brief: The Case for Hardware Security Keys

The short version: In 2022, attackers sent text messages to employees at more than 130 companies, tricking them into entering passwords and MFA codes on...

Entra ID & IdentityPlatform Changes

Microsoft Entra Launches (May 2022): Identity Becomes Its Own Product Family

In May 2022, Microsoft announced Microsoft Entra, a new product family for identity and access. Azure Active Directory became part of Entra, and in July...

Entra ID & IdentityHow-To & Hardening

How to Map Entra Products to Your Identity Security Roadmap

Microsoft Entra now includes many products. Here is a practical way to map them to an identity security roadmap for a mid-sized organization.

Entra ID & IdentityHow-To & Hardening

Identity Security Program Checklist for Mid-Market Companies

Use this checklist to assess an identity security program for a mid-sized organization.

Entra ID & IdentityCIO Briefings

CIO Brief: Identity Is the New Perimeter — Now It Has a Brand

The short version: In 2022, Microsoft reorganized its identity products under a new brand, Entra — reflecting a shift the whole industry made: who you are...

Entra ID & IdentityIncident Teardowns

Lapsus$ (Mar 2022): Teenagers, MFA Fatigue and Breaches at Okta and Microsoft

Between late 2021 and March 2022, a loosely organized group calling itself Lapsus$ breached some of the world's largest technology companies, including...

Entra ID & IdentityHow-To & Hardening

How to Enable MFA Number Matching and Stop Push Fatigue Attacks

MFA fatigue (or push bombing) floods a user with approval requests until they accept. Number matching and additional context make blind approvals much...

Entra ID & IdentityDetection & Response

Detecting MFA Fatigue Attacks: Entra Sign-In Logs and Sentinel KQL

MFA fatigue attacks generate distinctive patterns: many MFA prompts, many denials, then sometimes an approval. Detecting them early lets you lock down the...

Entra ID & IdentityCIO Briefings

CIO Brief: Insider Recruitment and Social Engineering — The Lapsus$ Playbook

The short version: In 2022, a group of teenagers called Lapsus$ breached Microsoft, Nvidia, Samsung and Okta — not with advanced hacking tools, but by...

Entra ID & IdentityPlatform Changes

Continuous Access Evaluation Arrives (2022): Revoking Sessions in Near Real Time

Continuous Access Evaluation (CAE) changed how quickly Microsoft Entra ID can cut off access. Microsoft announced general availability in early 2022 after a...

Entra ID & IdentityHow-To & Hardening

How to Enable Continuous Access Evaluation and Strict Location Enforcement

Continuous Access Evaluation (CAE) lets Entra ID revoke access in near real time. It's on by default for many tenants, but strict location enforcement and...

Entra ID & IdentityHow-To & Hardening

CAE Compatibility Checklist for Apps and Clients

Use this checklist to confirm your applications and clients work well with Continuous Access Evaluation, especially before enabling strict location enforcement.

Entra ID & IdentityCIO Briefings

CIO Brief: Why Revoking Access Used to Take an Hour

The short version: Until a few years ago, if you disabled a compromised employee account in Microsoft 365, the attacker could keep using it for up to an...

Entra ID & IdentityIncident Teardowns

SolarWinds and Golden SAML (Dec 2020): The Supply-Chain Attack That Reached the Cloud

On December 13, 2020, the world learned that attackers had compromised SolarWinds' Orion network monitoring software and inserted a backdoor — later called...

Entra ID & IdentityHow-To & Hardening

How to Move From AD FS to Cloud Authentication and Retire Token-Signing Risk

The SolarWinds attackers used stolen AD FS token-signing certificates to forge SAML tokens (Golden SAML) and access Microsoft 365. Moving authentication...

Entra ID & IdentityDetection & Response

Detecting Golden SAML: Entra Sign-In Logs and Sentinel KQL

Golden SAML attacks forge tokens with a stolen AD FS signing certificate, letting attackers sign in to Microsoft 365 as anyone. These detections help...

Entra ID & IdentityCIO Briefings

CIO Brief: Supply-Chain Risk After SolarWinds — What Boards Now Ask

The short version: In 2020, Russian intelligence hid malicious code inside updates for SolarWinds software used by thousands of organizations. For a smaller...

Entra ID & IdentityIncident Teardowns

After SolarWinds (Dec 2020): Attackers Abuse Azure AD Application Credentials

After SolarWinds was discovered in December 2020, Microsoft and incident responders described a key technique the attackers used in Microsoft 365: abusing...

Entra ID & IdentityHow-To & Hardening

How to Audit Service Principal and App Registration Credentials in Entra ID

Service principals and app registrations can hold powerful permissions with little oversight. Here is how to audit them in Entra ID.

Entra ID & IdentityDetection & Response

Detecting Service Principal Credential Abuse: Entra Sign-In Logs and Sentinel KQL

Attackers who compromise applications or service principals can access data across a tenant without user sign-ins. Detecting credential and permission...

Entra ID & IdentityCIO Briefings

CIO Brief: Non-Human Identities Are Your Fastest-Growing Risk

The short version: In the SolarWinds attack, intruders read email by hijacking applications connected to Microsoft 365 rather than user accounts. Apps and...

← NewerPage 3 of 5Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.