Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Microsoft 365

Articles in Microsoft 365.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Microsoft 365Incident Teardowns

The Mabna Institute Indictment (Mar 2018): Password Spraying Against Cloud Email

In March 2018, the US Department of Justice indicted nine Iranian nationals associated with the Mabna Institute for a long-running hacking campaign against...

Microsoft 365How-To & Hardening

How to Block Legacy Authentication to Stop Password Spraying in Microsoft 365

Password spraying succeeds most often through legacy authentication protocols that cannot perform MFA. Blocking legacy authentication closes that door. Here...

Microsoft 365Detection & Response

Detecting Password Spraying: Defender XDR and Sentinel Hunting Queries

Password spraying tries a small number of common passwords against many accounts, staying below lockout thresholds. Detecting it requires looking across...

Microsoft 365CIO Briefings

CIO Brief: Password Spraying Is Cheap for Attackers — Is Your Tenant Ready?

The short version: In 2018, the US indicted Iranian hackers who stole large volumes of data by trying common passwords against thousands of accounts. It is...

Microsoft 365Incident Teardowns

Deloitte's Email Breach (Sept 2017): An Admin Account Without MFA

In September 2017, The Guardian reported that Deloitte, one of the world's largest accounting and consulting firms, had suffered a breach of its global...

Microsoft 365How-To & Hardening

How to Protect Global Admin Accounts in Microsoft 365 and Entra ID

Global Administrators can change every setting, read every mailbox and create new admins in Microsoft 365. Protecting those accounts is the highest-value...

Microsoft 365Detection & Response

Detecting Compromised Admin Account: Defender XDR and Sentinel Hunting Queries

Compromised administrator accounts give attackers control of an entire Microsoft 365 tenant. Detecting unusual admin behavior early is one of the...

Microsoft 365CIO Briefings

CIO Brief: Privileged Accounts Are the Keys to the Kingdom

The short version: Deloitte's 2017 email breach reportedly started with one administrator account protected only by a password. Admin accounts are the keys...

Microsoft 365Platform Changes

Microsoft 365 Arrives (July 2017): Security Bundled Into the Productivity Suite

In July 2017, Microsoft announced Microsoft 365: a single subscription bundling Office 365, Windows 10 Enterprise and Enterprise Mobility + Security. For...

Microsoft 365How-To & Hardening

How to Map Microsoft 365 E3 vs. E5 Security Features to Your Real Risks

Microsoft 365 E3 and E5 both include significant security capabilities, but they are packaged differently and named inconsistently over the years. Here is...

Microsoft 365How-To & Hardening

Microsoft 365 Security Baseline Checklist for New Tenants

New and long-neglected Microsoft 365 tenants share the same weaknesses. This checklist covers the baseline settings that stop the most common attacks. Treat...

Microsoft 365CIO Briefings

CIO Brief: E3 or E5? Making the Microsoft 365 Security Licensing Decision

The short version: Microsoft 365 E3 includes solid security basics. E5 adds advanced threat protection, risk-based identity controls and stronger compliance...

← NewerPage 6 of 6
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.