Passwordless Readiness Checklist for Windows and Mobile
Use this checklist to check whether your organization is ready to roll out passwordless sign-in.
Insights
Articles in How-To & Hardening.
Use this checklist to check whether your organization is ready to roll out passwordless sign-in.
SMS and voice codes are the weakest forms of MFA. Here is how to migrate Microsoft 365 users to the Microsoft Authenticator app and, for higher-risk users,...
Microsoft Entra Password Protection blocks weak and commonly attacked passwords. In the cloud it works automatically for Entra ID accounts; extending it to...
A custom banned password list blocks the terms attackers are most likely to try against your organization. Use this checklist to build one that works.
Privacy laws such as GDPR require you to know where personal data lives and to control it. In Microsoft 365, Microsoft Purview provides the tools. Here is a...
A data inventory is the foundation of GDPR compliance and of any serious data protection program. Use this checklist to build one for Microsoft 365.
By default, Microsoft 365 users can grant third-party apps access to their data. Malicious apps use that to steal mail and files without ever needing a...
Password spraying succeeds most often through legacy authentication protocols that cannot perform MFA. Blocking legacy authentication closes that door. Here...
An exposed Kubernetes dashboard gave attackers a path into Tesla's cloud in 2018. Here is how to secure Kubernetes management interfaces and cluster...
When a major vulnerability affects cloud hosts, providers patch the hypervisor — but your virtual machines are still yours to patch. Here is how to track...
Long-lived AWS access keys in source code have caused breaches at companies of every size, from Uber in 2016 to the extortion campaigns of the 2020s. Here...
AWS Config continuously evaluates resource settings against rules. For S3, a handful of rules catches most of the misconfigurations behind past data...
Amazon GuardDuty should be enabled in every account and every region you use. With AWS Organizations, you can do that in an afternoon. Here is how.
GuardDuty generates findings; your team turns them into decisions. This runbook gives small security teams a consistent way to triage GuardDuty findings.
Equifax was breached through a known vulnerability in a web framework that had a patch available for two months. A vulnerability management program makes...
Global Administrators can change every setting, read every mailbox and create new admins in Microsoft 365. Protecting those accounts is the highest-value...
Amazon Macie scans S3 buckets for sensitive data such as names, financial information and credentials. Here is how to run it effectively without a surprise...
Use this checklist before and after enabling Amazon Macie to get value quickly while keeping costs predictable.
Bucket policies decide who can access data in Amazon S3. Written loosely, they leak data; written tightly, they make many attacks impossible. Here is how to...
Microsoft 365 E3 and E5 both include significant security capabilities, but they are packaged differently and named inconsistently over the years. Here is...
New and long-neglected Microsoft 365 tenants share the same weaknesses. This checklist covers the baseline settings that stop the most common attacks. Treat...
NotPetya spread by stealing administrator credentials from memory and reusing them across the network. Tiering your Active Directory admin accounts stops...
Public S3 buckets were behind dozens of data leaks in 2017. AWS has since made buckets private by default, but older accounts, older buckets and deliberate...
SMBv1 is a decades-old file-sharing protocol with known critical flaws, and it was the doorway for WannaCry and NotPetya. Here is how to remove it from...