Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Retrospectives

Articles in Retrospectives.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
AzurePlatform Changes

Microsoft Ignite 2021: Azure Security Center Becomes Microsoft Defender for Cloud

At Microsoft Ignite in November 2021, Microsoft combined Azure Security Center and Azure Defender into a single product: Microsoft Defender for Cloud. It...

AzureHow-To & Hardening

How to Raise Your Defender for Cloud Secure Score in 30 Days

Defender for Cloud's secure score measures how many security recommendations you've implemented. Here is a 30-day plan to raise it meaningfully — focusing...

AzureHow-To & Hardening

Defender for Cloud Plan Selection and Cost Checklist

Defender for Cloud includes a free foundational tier and several paid plans. Use this checklist to decide which to enable and keep costs predictable.

AzureCIO Briefings

CIO Brief: One Dashboard for Multi-Cloud Posture — Hype or Help?

The short version: In 2021, Microsoft combined its Azure security tools into Defender for Cloud, promising one dashboard for security across Azure, AWS and...

AzureIncident Teardowns

OMIGOD (Sept 2021): Hidden Azure Agents Running as Root

In September 2021, Wiz researchers disclosed OMIGOD, four vulnerabilities in Open Management Infrastructure (OMI), a software agent that Microsoft silently...

AzureHow-To & Hardening

How to Inventory and Patch Azure VM Extensions and Management Agents

Azure VM extensions and management agents add capabilities — and attack surface. Here is how to inventory and patch them.

AzureDetection & Response

Detecting VM Agent Exploitation: Defender for Cloud and Sentinel KQL

Management agents and VM extensions run with high privilege. Attackers exploit vulnerable agents or abuse extensions to run code. These detections cover both.

AzureCIO Briefings

CIO Brief: The Software Your Cloud Provider Installs on Your Servers

The short version: In 2021, researchers found serious flaws in a management program Microsoft quietly installed on many Linux servers in Azure. Many...

AzureIncident Teardowns

ChaosDB (Aug 2021): A Cosmos DB Flaw Exposed Thousands of Azure Customers' Keys

In August 2021, researchers at Wiz disclosed ChaosDB, a vulnerability in Microsoft Azure Cosmos DB that could have allowed an attacker to obtain the primary...

AzureHow-To & Hardening

How to Rotate Cosmos DB Keys and Move to Entra ID Authentication

Cosmos DB primary keys grant full access to a database. ChaosDB showed how damaging a leaked key can be. Here is how to rotate keys and move to Entra ID...

AzureDetection & Response

Detecting Cosmos DB Key Misuse With Defender for Cloud and Sentinel

Database keys and connection strings, once leaked, are used like legitimate access. Monitoring data plane activity helps you spot misuse.

AzureCIO Briefings

CIO Brief: When the Cloud Provider's Own Service Is Vulnerable

The short version: In 2021, researchers found a flaw in one of Microsoft's own Azure database services that could have let attackers access thousands of...

Microsoft 365Incident Teardowns

ProxyShell (Aug 2021): Exchange Server Exploited Again

In August 2021, details emerged of ProxyShell, a chain of three vulnerabilities in on-premises Microsoft Exchange Server. Security researcher Orange Tsai...

Microsoft 365How-To & Hardening

How to Build an Emergency Patching Process for Internet-Facing Servers

When a critical vulnerability is exploited in the wild, normal monthly patching is too slow. Here is how to build an emergency patching process for...

Microsoft 365Detection & Response

Detecting Exchange Server RCE: Defender XDR and Sentinel Hunting Queries

Remote code execution against Exchange servers leaves traces in IIS logs, process activity and the file system. These detections complement patching.

Microsoft 365CIO Briefings

CIO Brief: Repeated Exchange Zero-Days — A Signal to Move to the Cloud

The short version: In 2021, a second wave of attacks hit company-run Microsoft Exchange email servers, months after the first. Patches had been available...

Microsoft 365Incident Teardowns

38 Million Records Exposed by Power Apps Portals (Aug 2021): Low-Code, High Risk

In August 2021, UpGuard researchers disclosed that about 38 million records were exposed through Microsoft Power Apps portals belonging to 47 organizations,...

Microsoft 365How-To & Hardening

How to Govern Power Platform Environments, Portals and Data Policies

Power Platform lets anyone build apps, flows and now AI agents. Without governance, data can leak through connectors, public portals or overshared apps....

Microsoft 365Detection & Response

Detecting Low-Code Data Exposure: Defender XDR and Sentinel Hunting Queries

Low-code apps and portals can expose data without anyone noticing. These detections help surface risky configurations and unusual data access in Power Platform.

Microsoft 365CIO Briefings

CIO Brief: Citizen Developers Need Guardrails

The short version: In 2021, about 38 million records — including vaccination data and Social Security numbers — were exposed through websites built with...

Multi-CloudIncident Teardowns

Kaseya VSA (July 2021): Ransomware Delivered Through an MSP Tool

On July 2, 2021 — the start of a US holiday weekend — the REvil ransomware group exploited a zero-day vulnerability in Kaseya VSA, a remote monitoring and...

Multi-CloudHow-To & Hardening

How to Restrict and Monitor MSP Access to Your Microsoft 365 Tenant

Managed service providers often have broad administrative access to customer Microsoft 365 tenants. Here is how to restrict and monitor that access.

Multi-CloudDetection & Response

Detecting MSP Supply Chain Attack: Sentinel and GuardDuty Detections

MSP supply-chain attacks use legitimate management tools and access. Detection focuses on unusual use of those tools and partner accounts.

Multi-CloudCIO Briefings

CIO Brief: Your MSP Has Admin Rights — Are You Watching?

The short version: In 2021, ransomware spread through Kaseya — software that IT service providers use to manage their clients' computers — reaching up to...

← NewerPage 10 of 20Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.