Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Entra ID & Identity

Articles in Entra ID & Identity.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Entra ID & IdentityPlatform Changes

Azure AD Password Protection Preview (2018): Banning Bad Passwords in the Cloud and On-Prem

In June 2018, Microsoft announced a public preview of Azure AD Password Protection, bringing its banned-password technology to customers' cloud accounts and...

Entra ID & IdentityHow-To & Hardening

How to Deploy Entra Password Protection to On-Premises Domain Controllers

Microsoft Entra Password Protection blocks weak and commonly attacked passwords. In the cloud it works automatically for Entra ID accounts; extending it to...

Entra ID & IdentityHow-To & Hardening

Custom Banned Password List Checklist for Entra ID

A custom banned password list blocks the terms attackers are most likely to try against your organization. Use this checklist to build one that works.

Entra ID & IdentityCIO Briefings

CIO Brief: Password Policy Is Still a Security Control

The short version: Most password rules produce predictable passwords like "Summer2018!", which attackers try first. In 2018, Microsoft introduced a way to...

Entra ID & IdentityIncident Teardowns

Yahoo's Billion-Account Breach Disclosure (Dec 2016): The Case for MFA Everywhere

In December 2016, Yahoo disclosed that data from roughly one billion user accounts had been stolen in 2013. Months earlier it had disclosed a separate 2014...

Entra ID & IdentityHow-To & Hardening

How to Roll Out MFA to Every Microsoft 365 User Without a Help Desk Meltdown

Turning on multi-factor authentication for every Microsoft 365 user is the single most effective identity control you can deploy. It is also the change most...

Entra ID & IdentityDetection & Response

Detecting Credential Stuffing Attacks: Entra Sign-In Logs and Sentinel KQL

Credential stuffing uses username and password pairs leaked from other breaches to try to sign in to your Microsoft 365 tenant. Detection is about spotting...

Entra ID & IdentityCIO Briefings

CIO Brief: Credential Breaches at Other Companies Are Your Problem Too

The short version: When a big company like Yahoo loses billions of passwords, your company is also at risk. Your employees reuse passwords, and attackers...

← NewerPage 5 of 5
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.