Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Microsoft 365

Articles in Microsoft 365.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Microsoft 365Incident Teardowns

ProxyLogon (Mar 2021): Exchange Server Zero-Days Exploited at Massive Scale

On March 2, 2021, Microsoft released emergency patches for four zero-day vulnerabilities in on-premises Microsoft Exchange Server, collectively known as...

Microsoft 365How-To & Hardening

How to Retire On-Premises Exchange or Harden the Hybrid Server You Must Keep

On-premises Exchange servers were exploited repeatedly from 2021 to 2022. If you've moved mailboxes to Exchange Online, you may be able to retire your last...

Microsoft 365Detection & Response

Detecting Exchange Server Exploitation: Defender XDR and Sentinel Hunting Queries

Exchange Server exploitation typically results in web shells and suspicious processes spawned by IIS worker processes. These are the key detections.

Microsoft 365CIO Briefings

CIO Brief: The Hidden Cost of Keeping Exchange On-Prem

The short version: In 2021, attackers exploited flaws in Microsoft Exchange email servers that companies ran themselves, compromising tens of thousands of...

Microsoft 365Incident Teardowns

Mimecast Certificate Compromise (Jan 2021): When a Security Vendor Holds Keys to Your Tenant

In January 2021, email security company Mimecast disclosed that a certificate it used to authenticate certain products to Microsoft 365 Exchange Online had...

Microsoft 365How-To & Hardening

How to Review Third-Party Apps With Access to Exchange Online

Third-party applications connected to Exchange Online can read, send or manage mail across your organization. Here is how to review them.

Microsoft 365Detection & Response

Detecting Third-Party App Tenant Access: Defender XDR and Sentinel Hunting Queries

A compromised third-party integration can access your tenant with the app's permissions. These detections focus on unusual behavior by third-party apps.

Microsoft 365CIO Briefings

CIO Brief: Security Vendors Are Part of Your Attack Surface

The short version: In 2021, Mimecast — an email security company — disclosed that a digital certificate its products used to connect to customers' Microsoft...

Microsoft 365Platform Changes

Microsoft Ignite 2020: The Defender Rebrand and Unified XDR Strategy

At Microsoft Ignite in September 2020, Microsoft reorganized its security products under a single brand: Microsoft Defender. The change reflected its...

Microsoft 365How-To & Hardening

How to Map the Microsoft Defender Product Family to Your Environment

Microsoft's security product names have changed many times. Here is a practical map of the Microsoft Defender family — what each product does and how to...

Microsoft 365How-To & Hardening

Microsoft Defender XDR Onboarding Checklist

Owning Microsoft Defender licenses isn't the same as being protected. Use this checklist to onboard the Defender XDR products properly.

Microsoft 365CIO Briefings

CIO Brief: Consolidating Security Tools Around Microsoft Defender

The short version: Many companies pay for Microsoft 365 E5 or similar licenses that include a full suite of security tools — and use only part of it....

Microsoft 365Incident Teardowns

Illicit Consent Grant Phishing (July 2020): Attackers Stop Stealing Passwords

In July 2020, Microsoft warned about a rise in consent phishing (also called illicit consent grant) campaigns, many using COVID-19 themes. Instead of...

Microsoft 365How-To & Hardening

How to Detect and Remove Malicious OAuth Apps in Microsoft 365

Malicious OAuth apps can read mail and files without a password. Here is how to find and remove them in Microsoft 365.

Microsoft 365Detection & Response

Detecting Illicit Consent Grant: Defender XDR and Sentinel Hunting Queries

Illicit consent grants give attackers persistent access to Microsoft 365 data. Detecting them quickly is essential because password resets don't remove them.

Microsoft 365CIO Briefings

CIO Brief: The Phishing Attack MFA Can't Stop

The short version: In 2020, attackers began tricking employees into clicking "Accept" on a Microsoft permission screen for a fake app. The employee signs in...

Microsoft 365Incident Teardowns

Zoom-Bombing (Apr 2020): What It Taught Us About Teams Meeting Security

In early 2020, as remote work exploded, "Zoom-bombing" entered the vocabulary: uninvited people joined online meetings and classrooms to disrupt them with...

Microsoft 365How-To & Hardening

How to Lock Down Microsoft Teams Meeting Policies and Lobby Settings

Microsoft Teams meeting policies decide who can join, present and record. Here is how to tighten them without making meetings painful.

Microsoft 365Detection & Response

Detecting Meeting Hijacking: Defender XDR and Sentinel Hunting Queries

Meeting disruption and eavesdropping are rare, but when they happen in sensitive meetings the impact is high. These detections help you spot unusual meeting...

Microsoft 365CIO Briefings

CIO Brief: Collaboration Tools Are Now Critical Infrastructure

The short version: In 2020, uninvited strangers began crashing online meetings — "Zoom-bombing." It was a wake-up call: video meetings had become as...

Microsoft 365Incident Teardowns

The COVID-19 Remote Work Shift (Mar 2020): Teams Sprawl, Guest Access and Shadow IT

In March 2020, the COVID-19 pandemic sent much of the global workforce home almost overnight. Microsoft Teams usage exploded as organizations rushed to keep...

Microsoft 365How-To & Hardening

How to Govern Teams Creation, Guest Access and Expiration Policies

Teams sprawl and forgotten guest access create real security risk. Here is how to put lightweight governance in place without slowing collaboration.

Microsoft 365Detection & Response

Detecting Teams Guest Access Risk: Defender XDR and Sentinel Hunting Queries

Guest accounts and broad Teams access can quietly expose sensitive data. These detections highlight risky guest activity and sharing.

Microsoft 365CIO Briefings

CIO Brief: Cleaning Up the Pandemic's Collaboration Mess

The short version: When COVID-19 sent everyone home in 2020, companies opened up collaboration tools as fast as possible. Many never tightened them again....

← NewerPage 4 of 6Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.