Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Retrospectives

Articles in Retrospectives.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Multi-CloudIncident Teardowns

Colonial Pipeline (May 2021): One Legacy VPN Password Without MFA

On May 7, 2021, Colonial Pipeline — which carries a large share of the fuel supply for the US East Coast — shut down its pipeline operations after a...

Multi-CloudHow-To & Hardening

How to Find Remote Access Accounts That Bypass MFA

Colonial Pipeline and Change Healthcare were both breached through remote access accounts without MFA. Here is how to find accounts and access paths that...

Multi-CloudDetection & Response

Detecting VPN Logins Without MFA: Sentinel and GuardDuty Detections

Sign-ins without MFA to remote access systems are a leading ransomware entry point. These detections highlight them.

Multi-CloudCIO Briefings

CIO Brief: Colonial Pipeline and the Business Case for MFA on Everything

The short version: In 2021, Colonial Pipeline shut down fuel deliveries across the US East Coast after ransomware. The attackers got in through one old...

Multi-CloudPlatform Changes

Executive Order 14028 (May 2021): Zero Trust Becomes US Federal Policy

On May 12, 2021, President Biden signed Executive Order 14028, Improving the Nation's Cybersecurity, in response to SolarWinds, Microsoft Exchange...

Multi-CloudHow-To & Hardening

How to Build a Zero Trust Roadmap Using Microsoft and AWS Controls

"Zero trust" can sound abstract. In practice, it means verifying every access request based on identity, device and context — and limiting what each request...

Multi-CloudHow-To & Hardening

Zero Trust Maturity Self-Assessment Checklist

Use this self-assessment to estimate your zero trust maturity across five pillars. Score each item: 0 = not started, 1 = partial, 2 = complete.

Multi-CloudCIO Briefings

CIO Brief: What the Federal Zero Trust Mandate Means for Private Companies

The short version: In 2021, a US executive order made "zero trust" official federal policy and required multi-factor authentication, encryption and better...

Microsoft 365Incident Teardowns

ProxyLogon (Mar 2021): Exchange Server Zero-Days Exploited at Massive Scale

On March 2, 2021, Microsoft released emergency patches for four zero-day vulnerabilities in on-premises Microsoft Exchange Server, collectively known as...

Microsoft 365How-To & Hardening

How to Retire On-Premises Exchange or Harden the Hybrid Server You Must Keep

On-premises Exchange servers were exploited repeatedly from 2021 to 2022. If you've moved mailboxes to Exchange Online, you may be able to retire your last...

Microsoft 365Detection & Response

Detecting Exchange Server Exploitation: Defender XDR and Sentinel Hunting Queries

Exchange Server exploitation typically results in web shells and suspicious processes spawned by IIS worker processes. These are the key detections.

Microsoft 365CIO Briefings

CIO Brief: The Hidden Cost of Keeping Exchange On-Prem

The short version: In 2021, attackers exploited flaws in Microsoft Exchange email servers that companies ran themselves, compromising tens of thousands of...

Multi-CloudIncident Teardowns

Verkada Camera Breach (Mar 2021): A Super Admin Credential Left Exposed

In March 2021, a group of hackers gained access to Verkada, a cloud-based security camera company, and viewed live feeds from roughly 150,000 cameras at...

Multi-CloudHow-To & Hardening

How to Find and Vault Hardcoded Credentials Across Cloud Services

Hardcoded credentials in scripts, configuration files and repositories are one of the easiest ways for attackers to escalate. Here is how to find them...

Multi-CloudDetection & Response

Detecting Exposed Super Admin Credentials: Sentinel and GuardDuty Detections

Exposed administrator credentials are often used soon after discovery. Detecting both the exposure and the misuse helps you respond before damage spreads.

Multi-CloudCIO Briefings

CIO Brief: IoT and SaaS Admin Access — The Overlooked Privilege

The short version: In 2021, hackers accessed about 150,000 security cameras — in hospitals, schools and factories — by finding a single "super admin"...

Microsoft 365Incident Teardowns

Mimecast Certificate Compromise (Jan 2021): When a Security Vendor Holds Keys to Your Tenant

In January 2021, email security company Mimecast disclosed that a certificate it used to authenticate certain products to Microsoft 365 Exchange Online had...

Microsoft 365How-To & Hardening

How to Review Third-Party Apps With Access to Exchange Online

Third-party applications connected to Exchange Online can read, send or manage mail across your organization. Here is how to review them.

Microsoft 365Detection & Response

Detecting Third-Party App Tenant Access: Defender XDR and Sentinel Hunting Queries

A compromised third-party integration can access your tenant with the app's permissions. These detections focus on unusual behavior by third-party apps.

Microsoft 365CIO Briefings

CIO Brief: Security Vendors Are Part of Your Attack Surface

The short version: In 2021, Mimecast — an email security company — disclosed that a digital certificate its products used to connect to customers' Microsoft...

Entra ID & IdentityIncident Teardowns

SolarWinds and Golden SAML (Dec 2020): The Supply-Chain Attack That Reached the Cloud

On December 13, 2020, the world learned that attackers had compromised SolarWinds' Orion network monitoring software and inserted a backdoor — later called...

Entra ID & IdentityHow-To & Hardening

How to Move From AD FS to Cloud Authentication and Retire Token-Signing Risk

The SolarWinds attackers used stolen AD FS token-signing certificates to forge SAML tokens (Golden SAML) and access Microsoft 365. Moving authentication...

Entra ID & IdentityDetection & Response

Detecting Golden SAML: Entra Sign-In Logs and Sentinel KQL

Golden SAML attacks forge tokens with a stolen AD FS signing certificate, letting attackers sign in to Microsoft 365 as anyone. These detections help...

Entra ID & IdentityCIO Briefings

CIO Brief: Supply-Chain Risk After SolarWinds — What Boards Now Ask

The short version: In 2020, Russian intelligence hid malicious code inside updates for SolarWinds software used by thousands of organizations. For a smaller...

← NewerPage 11 of 20Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.