Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Entra ID & Identity

Articles in Entra ID & Identity.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Entra ID & IdentityIncident Teardowns

The Twitter Hack (July 2020): Phone Spear-Phishing Against Internal Admin Tools

On July 15, 2020, the Twitter accounts of Barack Obama, Joe Biden, Elon Musk, Bill Gates, Apple and others posted a cryptocurrency scam. Attackers had taken...

Entra ID & IdentityHow-To & Hardening

How to Protect Internal Admin Tools With Privileged Identity Management

Microsoft Entra Privileged Identity Management (PIM) makes administrative access temporary, approved and audited. Here is how to use it to protect admin...

Entra ID & IdentityDetection & Response

Detecting Admin Tool Social Engineering: Entra Sign-In Logs and Sentinel KQL

Attackers who social-engineer employees often go straight for administrative tools. Detecting unusual admin access helps you catch them before they act.

Entra ID & IdentityCIO Briefings

CIO Brief: Social Engineering Your Employees Beats Hacking Your Systems

The short version: In 2020, attackers took over the Twitter accounts of world leaders and celebrities — not by hacking Twitter's systems directly, but by...

Entra ID & IdentityPlatform Changes

Azure AD Security Defaults Arrive (Oct 2019): Free Baseline Protection for Every Tenant

In October 2019, Microsoft introduced Security Defaults for Azure Active Directory (now Entra ID). It replaced earlier "baseline policies" with a single...

Entra ID & IdentityHow-To & Hardening

How to Choose Between Security Defaults and Conditional Access

Entra ID offers two ways to enforce baseline identity security: Security Defaults (free, simple) and Conditional Access (requires Entra ID P1, flexible)....

Entra ID & IdentityHow-To & Hardening

Security Defaults Rollout Checklist and User Communication Template

Use this checklist to enable Security Defaults with minimal disruption, especially for smaller organizations.

Entra ID & IdentityCIO Briefings

CIO Brief: The Free Setting That Blocks Most Identity Attacks

The short version: In 2019, Microsoft released Security Defaults: a free, one-click setting that turns on multi-factor authentication and blocks older,...

Entra ID & IdentityIncident Teardowns

The Azure AD MFA Outage of November 2018: When Sign-In Itself Goes Down

On November 19, 2018, Azure Active Directory's multi-factor authentication service suffered a major outage. For much of a working day, many users in Europe,...

Entra ID & IdentityHow-To & Hardening

How to Create and Monitor Break-Glass Emergency Access Accounts in Entra ID

Emergency access accounts — often called break-glass accounts — let you regain administrative access to Entra ID and Microsoft 365 when normal sign-in...

Entra ID & IdentityHow-To & Hardening

Identity Outage Runbook: What to Do When MFA Is Down

When your identity provider or MFA service fails, every minute of confusion costs productivity. This runbook outlines what to do.

Entra ID & IdentityCIO Briefings

CIO Brief: Planning for the Day Your Identity Provider Is Unavailable

The short version: In 2018, Microsoft's multi-factor authentication service had a major outage, and many organizations couldn't sign in to their email and...

Entra ID & IdentityIncident Teardowns

Facebook's 'View As' Breach (Sept 2018): 50 Million Access Tokens Stolen

On September 28, 2018, Facebook announced that attackers had exploited a vulnerability in its "View As" feature to steal access tokens. Facebook initially...

Entra ID & IdentityHow-To & Hardening

How to Configure Token Lifetimes and Sign-In Frequency in Conditional Access

Stolen tokens let attackers bypass passwords and MFA. Conditional Access session controls limit how long tokens stay useful and when users must...

Entra ID & IdentityDetection & Response

Detecting Access Token Theft: Entra Sign-In Logs and Sentinel KQL

Token theft lets an attacker act as a user without their password or MFA. Detection focuses on tokens being used in ways that don't match the device and...

Entra ID & IdentityCIO Briefings

CIO Brief: Stolen Tokens Bypass Passwords and MFA — What That Means for You

The short version: In 2018, a Facebook bug let attackers steal the digital "keys" that keep users signed in, giving access to millions of accounts without...

Entra ID & IdentityPlatform Changes

Microsoft Ignite 2018: Passwordless Sign-In and Microsoft Threat Protection Arrive

At Microsoft Ignite in September 2018, Microsoft made identity and threat protection central themes. Two announcements stood out: passwordless sign-in for...

Entra ID & IdentityHow-To & Hardening

How to Plan a Passwordless Rollout With Windows Hello and Authenticator

Passwordless sign-in removes the most attacked credential and improves user experience. Here is a practical rollout plan using Windows Hello for Business,...

Entra ID & IdentityHow-To & Hardening

Passwordless Readiness Checklist for Windows and Mobile

Use this checklist to check whether your organization is ready to roll out passwordless sign-in.

Entra ID & IdentityCIO Briefings

CIO Brief: Passwordless Is a Productivity Win, Not Just Security

The short version: In 2018, Microsoft started pushing businesses toward signing in without passwords, using phones, fingerprints and security keys instead....

Entra ID & IdentityIncident Teardowns

Reddit's Breach via SMS Interception (Aug 2018): Why SMS MFA Isn't Enough

On August 1, 2018, Reddit disclosed that an attacker had accessed some of its systems, including an old database backup with user data from 2007 and email...

Entra ID & IdentityHow-To & Hardening

How to Migrate Users From SMS to Authenticator App and FIDO2 MFA

SMS and voice codes are the weakest forms of MFA. Here is how to migrate Microsoft 365 users to the Microsoft Authenticator app and, for higher-risk users,...

Entra ID & IdentityDetection & Response

Detecting SMS MFA Interception: Entra Sign-In Logs and Sentinel KQL

SMS codes can be intercepted through SIM swaps and phishing. You often can't see the interception itself, but you can detect what happens next: a sign-in...

Entra ID & IdentityCIO Briefings

CIO Brief: Not All MFA Is Equal — The Case for Phishing-Resistant Methods

The short version: In 2018, Reddit was breached even though its employees used two-factor authentication — the attacker intercepted text message codes. All...

← NewerPage 4 of 5Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.