Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

How-To & Hardening

Articles in How-To & Hardening.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Entra ID & IdentityHow-To & Hardening

How to Write Conditional Access Policies for Contractors and Guests

Contractors and guests often have less oversight than employees but similar access. Conditional Access lets you apply consistent — or stricter — controls....

Microsoft 365How-To & Hardening

How to Decommission the Last Exchange Server in a Hybrid Deployment

Many organizations moved all mailboxes to Exchange Online but kept one Exchange server for recipient management. Microsoft now supports removing it in many...

Entra ID & IdentityHow-To & Hardening

How to Deploy FIDO2 Security Keys for High-Risk Users

FIDO2 security keys provide phishing-resistant MFA: they won't authenticate to a fake site. Here is how to deploy them in Entra ID for high-risk users.

Microsoft 365How-To & Hardening

How to Defeat AiTM Phishing With Compliant-Device and Phishing-Resistant MFA Policies

Adversary-in-the-middle phishing steals session cookies after users complete MFA. Two controls stop it: phishing-resistant authentication and...

Microsoft 365How-To & Hardening

How to Configure Attack Surface Reduction Rules in Defender for Endpoint

Attack surface reduction (ASR) rules in Microsoft Defender for Endpoint block behaviors commonly used by malware — such as Office apps launching child...

Entra ID & IdentityHow-To & Hardening

How to Map Entra Products to Your Identity Security Roadmap

Microsoft Entra now includes many products. Here is a practical way to map them to an identity security roadmap for a mid-sized organization.

Entra ID & IdentityHow-To & Hardening

Identity Security Program Checklist for Mid-Market Companies

Use this checklist to assess an identity security program for a mid-sized organization.

Multi-CloudHow-To & Hardening

How to Secure CI/CD Pipelines With OIDC Federation Instead of Stored Secrets

Stored cloud credentials in CI/CD systems are a prime target. OIDC federation lets pipelines get short-lived credentials from AWS or Azure on demand — with...

Entra ID & IdentityHow-To & Hardening

How to Enable MFA Number Matching and Stop Push Fatigue Attacks

MFA fatigue (or push bombing) floods a user with approval requests until they accept. Number matching and additional context make blind approvals much...

Entra ID & IdentityHow-To & Hardening

How to Enable Continuous Access Evaluation and Strict Location Enforcement

Continuous Access Evaluation (CAE) lets Entra ID revoke access in near real time. It's on by default for many tenants, but strict location enforcement and...

Entra ID & IdentityHow-To & Hardening

CAE Compatibility Checklist for Apps and Clients

Use this checklist to confirm your applications and clients work well with Continuous Access Evaluation, especially before enabling strict location enforcement.

Multi-CloudHow-To & Hardening

How to Find Vulnerable Libraries in Azure and AWS Workloads

When a library vulnerability like Log4Shell hits, the first question is "where are we affected?" Here is how to answer it across Azure and AWS workloads.

AWSHow-To & Hardening

How to Plan Multi-Region Failover for Critical AWS Workloads

Regional outages are rare but real. Here is how to plan multi-region failover for the AWS workloads that truly need it.

AWSHow-To & Hardening

Multi-Region Disaster Recovery Test Checklist

Use this checklist to plan and run a multi-region disaster recovery test for an AWS workload.

AzureHow-To & Hardening

How to Raise Your Defender for Cloud Secure Score in 30 Days

Defender for Cloud's secure score measures how many security recommendations you've implemented. Here is a 30-day plan to raise it meaningfully — focusing...

AzureHow-To & Hardening

Defender for Cloud Plan Selection and Cost Checklist

Defender for Cloud includes a free foundational tier and several paid plans. Use this checklist to decide which to enable and keep costs predictable.

AzureHow-To & Hardening

How to Inventory and Patch Azure VM Extensions and Management Agents

Azure VM extensions and management agents add capabilities — and attack surface. Here is how to inventory and patch them.

AzureHow-To & Hardening

How to Rotate Cosmos DB Keys and Move to Entra ID Authentication

Cosmos DB primary keys grant full access to a database. ChaosDB showed how damaging a leaked key can be. Here is how to rotate keys and move to Entra ID...

Microsoft 365How-To & Hardening

How to Build an Emergency Patching Process for Internet-Facing Servers

When a critical vulnerability is exploited in the wild, normal monthly patching is too slow. Here is how to build an emergency patching process for...

Microsoft 365How-To & Hardening

How to Govern Power Platform Environments, Portals and Data Policies

Power Platform lets anyone build apps, flows and now AI agents. Without governance, data can leak through connectors, public portals or overshared apps....

Multi-CloudHow-To & Hardening

How to Restrict and Monitor MSP Access to Your Microsoft 365 Tenant

Managed service providers often have broad administrative access to customer Microsoft 365 tenants. Here is how to restrict and monitor that access.

Multi-CloudHow-To & Hardening

How to Find Remote Access Accounts That Bypass MFA

Colonial Pipeline and Change Healthcare were both breached through remote access accounts without MFA. Here is how to find accounts and access paths that...

Multi-CloudHow-To & Hardening

How to Build a Zero Trust Roadmap Using Microsoft and AWS Controls

"Zero trust" can sound abstract. In practice, it means verifying every access request based on identity, device and context — and limiting what each request...

Multi-CloudHow-To & Hardening

Zero Trust Maturity Self-Assessment Checklist

Use this self-assessment to estimate your zero trust maturity across five pillars. Score each item: 0 = not started, 1 = partial, 2 = complete.

← NewerPage 4 of 8Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.