Microsoft Ignite 2021: Azure Security Center Becomes Microsoft Defender for Cloud
At Microsoft Ignite in November 2021, Microsoft combined Azure Security Center and Azure Defender into a single product: Microsoft Defender for Cloud. It...
Insights
Articles in Retrospectives.
At Microsoft Ignite in November 2021, Microsoft combined Azure Security Center and Azure Defender into a single product: Microsoft Defender for Cloud. It...
Defender for Cloud's secure score measures how many security recommendations you've implemented. Here is a 30-day plan to raise it meaningfully — focusing...
Defender for Cloud includes a free foundational tier and several paid plans. Use this checklist to decide which to enable and keep costs predictable.
The short version: In 2021, Microsoft combined its Azure security tools into Defender for Cloud, promising one dashboard for security across Azure, AWS and...
In September 2021, Wiz researchers disclosed OMIGOD, four vulnerabilities in Open Management Infrastructure (OMI), a software agent that Microsoft silently...
Azure VM extensions and management agents add capabilities — and attack surface. Here is how to inventory and patch them.
Management agents and VM extensions run with high privilege. Attackers exploit vulnerable agents or abuse extensions to run code. These detections cover both.
The short version: In 2021, researchers found serious flaws in a management program Microsoft quietly installed on many Linux servers in Azure. Many...
In August 2021, researchers at Wiz disclosed ChaosDB, a vulnerability in Microsoft Azure Cosmos DB that could have allowed an attacker to obtain the primary...
Cosmos DB primary keys grant full access to a database. ChaosDB showed how damaging a leaked key can be. Here is how to rotate keys and move to Entra ID...
Database keys and connection strings, once leaked, are used like legitimate access. Monitoring data plane activity helps you spot misuse.
The short version: In 2021, researchers found a flaw in one of Microsoft's own Azure database services that could have let attackers access thousands of...
In August 2021, details emerged of ProxyShell, a chain of three vulnerabilities in on-premises Microsoft Exchange Server. Security researcher Orange Tsai...
When a critical vulnerability is exploited in the wild, normal monthly patching is too slow. Here is how to build an emergency patching process for...
Remote code execution against Exchange servers leaves traces in IIS logs, process activity and the file system. These detections complement patching.
The short version: In 2021, a second wave of attacks hit company-run Microsoft Exchange email servers, months after the first. Patches had been available...
In August 2021, UpGuard researchers disclosed that about 38 million records were exposed through Microsoft Power Apps portals belonging to 47 organizations,...
Power Platform lets anyone build apps, flows and now AI agents. Without governance, data can leak through connectors, public portals or overshared apps....
Low-code apps and portals can expose data without anyone noticing. These detections help surface risky configurations and unusual data access in Power Platform.
The short version: In 2021, about 38 million records — including vaccination data and Social Security numbers — were exposed through websites built with...
On July 2, 2021 — the start of a US holiday weekend — the REvil ransomware group exploited a zero-day vulnerability in Kaseya VSA, a remote monitoring and...
Managed service providers often have broad administrative access to customer Microsoft 365 tenants. Here is how to restrict and monitor that access.
MSP supply-chain attacks use legitimate management tools and access. Detection focuses on unusual use of those tools and partner accounts.
The short version: In 2021, ransomware spread through Kaseya — software that IT service providers use to manage their clients' computers — reaching up to...