How to Write Conditional Access Policies for Contractors and Guests
Contractors and guests often have less oversight than employees but similar access. Conditional Access lets you apply consistent — or stricter — controls....
Insights
Articles in How-To & Hardening.
Contractors and guests often have less oversight than employees but similar access. Conditional Access lets you apply consistent — or stricter — controls....
Many organizations moved all mailboxes to Exchange Online but kept one Exchange server for recipient management. Microsoft now supports removing it in many...
FIDO2 security keys provide phishing-resistant MFA: they won't authenticate to a fake site. Here is how to deploy them in Entra ID for high-risk users.
Adversary-in-the-middle phishing steals session cookies after users complete MFA. Two controls stop it: phishing-resistant authentication and...
Attack surface reduction (ASR) rules in Microsoft Defender for Endpoint block behaviors commonly used by malware — such as Office apps launching child...
Microsoft Entra now includes many products. Here is a practical way to map them to an identity security roadmap for a mid-sized organization.
Use this checklist to assess an identity security program for a mid-sized organization.
Stored cloud credentials in CI/CD systems are a prime target. OIDC federation lets pipelines get short-lived credentials from AWS or Azure on demand — with...
MFA fatigue (or push bombing) floods a user with approval requests until they accept. Number matching and additional context make blind approvals much...
Continuous Access Evaluation (CAE) lets Entra ID revoke access in near real time. It's on by default for many tenants, but strict location enforcement and...
Use this checklist to confirm your applications and clients work well with Continuous Access Evaluation, especially before enabling strict location enforcement.
When a library vulnerability like Log4Shell hits, the first question is "where are we affected?" Here is how to answer it across Azure and AWS workloads.
Regional outages are rare but real. Here is how to plan multi-region failover for the AWS workloads that truly need it.
Use this checklist to plan and run a multi-region disaster recovery test for an AWS workload.
Defender for Cloud's secure score measures how many security recommendations you've implemented. Here is a 30-day plan to raise it meaningfully — focusing...
Defender for Cloud includes a free foundational tier and several paid plans. Use this checklist to decide which to enable and keep costs predictable.
Azure VM extensions and management agents add capabilities — and attack surface. Here is how to inventory and patch them.
Cosmos DB primary keys grant full access to a database. ChaosDB showed how damaging a leaked key can be. Here is how to rotate keys and move to Entra ID...
When a critical vulnerability is exploited in the wild, normal monthly patching is too slow. Here is how to build an emergency patching process for...
Power Platform lets anyone build apps, flows and now AI agents. Without governance, data can leak through connectors, public portals or overshared apps....
Managed service providers often have broad administrative access to customer Microsoft 365 tenants. Here is how to restrict and monitor that access.
Colonial Pipeline and Change Healthcare were both breached through remote access accounts without MFA. Here is how to find accounts and access paths that...
"Zero trust" can sound abstract. In practice, it means verifying every access request based on identity, device and context — and limiting what each request...
Use this self-assessment to estimate your zero trust maturity across five pillars. Score each item: 0 = not started, 1 = partial, 2 = complete.