Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

How-To & Hardening

Articles in How-To & Hardening.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Entra ID & IdentityHow-To & Hardening

Passwordless Readiness Checklist for Windows and Mobile

Use this checklist to check whether your organization is ready to roll out passwordless sign-in.

Entra ID & IdentityHow-To & Hardening

How to Migrate Users From SMS to Authenticator App and FIDO2 MFA

SMS and voice codes are the weakest forms of MFA. Here is how to migrate Microsoft 365 users to the Microsoft Authenticator app and, for higher-risk users,...

Entra ID & IdentityHow-To & Hardening

How to Deploy Entra Password Protection to On-Premises Domain Controllers

Microsoft Entra Password Protection blocks weak and commonly attacked passwords. In the cloud it works automatically for Entra ID accounts; extending it to...

Entra ID & IdentityHow-To & Hardening

Custom Banned Password List Checklist for Entra ID

A custom banned password list blocks the terms attackers are most likely to try against your organization. Use this checklist to build one that works.

Microsoft 365How-To & Hardening

How to Use Microsoft Purview to Find and Govern Personal Data

Privacy laws such as GDPR require you to know where personal data lives and to control it. In Microsoft 365, Microsoft Purview provides the tools. Here is a...

Microsoft 365How-To & Hardening

GDPR Data Inventory Checklist for Microsoft 365

A data inventory is the foundation of GDPR compliance and of any serious data protection program. Use this checklist to build one for Microsoft 365.

Microsoft 365How-To & Hardening

How to Lock Down User Consent to Third-Party Apps in Entra ID

By default, Microsoft 365 users can grant third-party apps access to their data. Malicious apps use that to steal mail and files without ever needing a...

Microsoft 365How-To & Hardening

How to Block Legacy Authentication to Stop Password Spraying in Microsoft 365

Password spraying succeeds most often through legacy authentication protocols that cannot perform MFA. Blocking legacy authentication closes that door. Here...

AWSHow-To & Hardening

How to Secure Kubernetes Dashboards and Cluster Credentials on AWS

An exposed Kubernetes dashboard gave attackers a path into Tesla's cloud in 2018. Here is how to secure Kubernetes management interfaces and cluster...

Multi-CloudHow-To & Hardening

How to Track Hypervisor and Guest Patching for Azure and AWS VMs

When a major vulnerability affects cloud hosts, providers patch the hypervisor — but your virtual machines are still yours to patch. Here is how to track...

AWSHow-To & Hardening

How to Prevent Hardcoded AWS Keys With Secret Scanning and IAM Roles

Long-lived AWS access keys in source code have caused breaches at companies of every size, from Uber in 2016 to the extortion campaigns of the 2020s. Here...

AWSHow-To & Hardening

How to Enforce S3 Guardrails With AWS Config Rules

AWS Config continuously evaluates resource settings against rules. For S3, a handful of rules catches most of the misconfigurations behind past data...

AWSHow-To & Hardening

How to Enable GuardDuty Across an AWS Organization in One Afternoon

Amazon GuardDuty should be enabled in every account and every region you use. With AWS Organizations, you can do that in an afternoon. Here is how.

AWSHow-To & Hardening

GuardDuty Finding Triage Runbook for Small Security Teams

GuardDuty generates findings; your team turns them into decisions. This runbook gives small security teams a consistent way to triage GuardDuty findings.

Multi-CloudHow-To & Hardening

How to Build a Vulnerability Management Program for Cloud-Hosted Apps

Equifax was breached through a known vulnerability in a web framework that had a patch available for two months. A vulnerability management program makes...

Microsoft 365How-To & Hardening

How to Protect Global Admin Accounts in Microsoft 365 and Entra ID

Global Administrators can change every setting, read every mailbox and create new admins in Microsoft 365. Protecting those accounts is the highest-value...

AWSHow-To & Hardening

How to Use Amazon Macie to Discover PII in Your S3 Buckets

Amazon Macie scans S3 buckets for sensitive data such as names, financial information and credentials. Here is how to run it effectively without a surprise...

AWSHow-To & Hardening

Amazon Macie Rollout Checklist: Cost Controls and Finding Triage

Use this checklist before and after enabling Amazon Macie to get value quickly while keeping costs predictable.

AWSHow-To & Hardening

How to Use S3 Bucket Policies and Access Points to Enforce Least Privilege

Bucket policies decide who can access data in Amazon S3. Written loosely, they leak data; written tightly, they make many attacks impossible. Here is how to...

Microsoft 365How-To & Hardening

How to Map Microsoft 365 E3 vs. E5 Security Features to Your Real Risks

Microsoft 365 E3 and E5 both include significant security capabilities, but they are packaged differently and named inconsistently over the years. Here is...

Microsoft 365How-To & Hardening

Microsoft 365 Security Baseline Checklist for New Tenants

New and long-neglected Microsoft 365 tenants share the same weaknesses. This checklist covers the baseline settings that stop the most common attacks. Treat...

AzureHow-To & Hardening

How to Tier Your Active Directory Admin Accounts to Contain Lateral Movement

NotPetya spread by stealing administrator credentials from memory and reusing them across the network. Tiering your Active Directory admin accounts stops...

AWSHow-To & Hardening

How to Find and Lock Down Public S3 Buckets Across Every AWS Account

Public S3 buckets were behind dozens of data leaks in 2017. AWS has since made buckets private by default, but older accounts, older buckets and deliberate...

AzureHow-To & Hardening

How to Disable SMBv1 and Enforce Patch Compliance on Azure VMs

SMBv1 is a decades-old file-sharing protocol with known critical flaws, and it was the doorway for WannaCry and NotPetya. Here is how to remove it from...

← NewerPage 7 of 8Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.