Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Retrospectives

Articles in Retrospectives.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Entra ID & IdentityIncident Teardowns

After SolarWinds (Dec 2020): Attackers Abuse Azure AD Application Credentials

After SolarWinds was discovered in December 2020, Microsoft and incident responders described a key technique the attackers used in Microsoft 365: abusing...

Entra ID & IdentityHow-To & Hardening

How to Audit Service Principal and App Registration Credentials in Entra ID

Service principals and app registrations can hold powerful permissions with little oversight. Here is how to audit them in Entra ID.

Entra ID & IdentityDetection & Response

Detecting Service Principal Credential Abuse: Entra Sign-In Logs and Sentinel KQL

Attackers who compromise applications or service principals can access data across a tenant without user sign-ins. Detecting credential and permission...

Entra ID & IdentityCIO Briefings

CIO Brief: Non-Human Identities Are Your Fastest-Growing Risk

The short version: In the SolarWinds attack, intruders read email by hijacking applications connected to Microsoft 365 rather than user accounts. Apps and...

AWSPlatform Changes

AWS Network Firewall Goes GA (Nov 2020): Managed Stateful Inspection for VPCs

In November 2020, AWS Network Firewall became generally available — a managed, stateful network firewall and intrusion prevention service for Amazon VPCs.

AWSHow-To & Hardening

How to Deploy AWS Network Firewall in a Centralized Inspection VPC

A centralized inspection VPC lets one AWS Network Firewall deployment filter traffic for many VPCs. Here is the common architecture and setup sequence.

AWSHow-To & Hardening

VPC Egress Filtering Checklist

Egress filtering is one of the most effective controls against data exfiltration and malware. Use this checklist to put it in place across AWS VPCs.

AWSCIO Briefings

CIO Brief: Network Security Still Matters in the Cloud

The short version: Cloud servers can usually connect to anywhere on the internet by default. Attackers rely on that to steal data and control compromised...

AzureIncident Teardowns

Zerologon (Aug–Sept 2020): Taking Over a Domain Controller in Seconds

In August 2020, Microsoft patched CVE-2020-1472, a critical flaw in the Netlogon Remote Protocol used by Windows domain controllers. In September,...

AzureHow-To & Hardening

How to Patch and Monitor Domain Controllers in Hybrid Azure Environments

Domain controllers hold the keys to your on-premises identity — and, in hybrid environments, a path to the cloud. Here is how to patch and monitor them...

AzureDetection & Response

Detecting Netlogon Exploitation: Defender for Cloud and Sentinel KQL

Attacks on Active Directory — including Zerologon exploitation, DCSync and Kerberos abuse — leave specific traces. Microsoft Defender for Identity and...

AzureCIO Briefings

CIO Brief: Hybrid Identity Means On-Prem Flaws Become Cloud Flaws

The short version: In 2020, a flaw called Zerologon let attackers take over a company's core identity system — Active Directory — in seconds, without a...

Microsoft 365Platform Changes

Microsoft Ignite 2020: The Defender Rebrand and Unified XDR Strategy

At Microsoft Ignite in September 2020, Microsoft reorganized its security products under a single brand: Microsoft Defender. The change reflected its...

Microsoft 365How-To & Hardening

How to Map the Microsoft Defender Product Family to Your Environment

Microsoft's security product names have changed many times. Here is a practical map of the Microsoft Defender family — what each product does and how to...

Microsoft 365How-To & Hardening

Microsoft Defender XDR Onboarding Checklist

Owning Microsoft Defender licenses isn't the same as being protected. Use this checklist to onboard the Defender XDR products properly.

Microsoft 365CIO Briefings

CIO Brief: Consolidating Security Tools Around Microsoft Defender

The short version: Many companies pay for Microsoft 365 E5 or similar licenses that include a full suite of security tools — and use only part of it....

Entra ID & IdentityIncident Teardowns

The Twitter Hack (July 2020): Phone Spear-Phishing Against Internal Admin Tools

On July 15, 2020, the Twitter accounts of Barack Obama, Joe Biden, Elon Musk, Bill Gates, Apple and others posted a cryptocurrency scam. Attackers had taken...

Entra ID & IdentityHow-To & Hardening

How to Protect Internal Admin Tools With Privileged Identity Management

Microsoft Entra Privileged Identity Management (PIM) makes administrative access temporary, approved and audited. Here is how to use it to protect admin...

Entra ID & IdentityDetection & Response

Detecting Admin Tool Social Engineering: Entra Sign-In Logs and Sentinel KQL

Attackers who social-engineer employees often go straight for administrative tools. Detecting unusual admin access helps you catch them before they act.

Entra ID & IdentityCIO Briefings

CIO Brief: Social Engineering Your Employees Beats Hacking Your Systems

The short version: In 2020, attackers took over the Twitter accounts of world leaders and celebrities — not by hacking Twitter's systems directly, but by...

Microsoft 365Incident Teardowns

Illicit Consent Grant Phishing (July 2020): Attackers Stop Stealing Passwords

In July 2020, Microsoft warned about a rise in consent phishing (also called illicit consent grant) campaigns, many using COVID-19 themes. Instead of...

Microsoft 365How-To & Hardening

How to Detect and Remove Malicious OAuth Apps in Microsoft 365

Malicious OAuth apps can read mail and files without a password. Here is how to find and remove them in Microsoft 365.

Microsoft 365Detection & Response

Detecting Illicit Consent Grant: Defender XDR and Sentinel Hunting Queries

Illicit consent grants give attackers persistent access to Microsoft 365 data. Detecting them quickly is essential because password resets don't remove them.

Microsoft 365CIO Briefings

CIO Brief: The Phishing Attack MFA Can't Stop

The short version: In 2020, attackers began tricking employees into clicking "Accept" on a Microsoft permission screen for a fake app. The employee signs in...

← NewerPage 12 of 20Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.