Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Retrospectives

Articles in Retrospectives.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
AWSPlatform Changes

IAM Access Analyzer Launches (Dec 2019): Finding Unintended Public and Cross-Account Access

In December 2019, AWS launched IAM Access Analyzer. It used automated reasoning — mathematical analysis of policies — to identify resources that were shared...

AWSHow-To & Hardening

How to Use IAM Access Analyzer to Find Unused and External Access

IAM Access Analyzer finds two kinds of risky access: resources shared outside your organization, and permissions nobody uses. Here is how to use both to...

AWSHow-To & Hardening

Quarterly External Access Review Checklist for AWS

External access to your AWS resources should be known and approved. This quarterly review checklist keeps it that way.

AWSCIO Briefings

CIO Brief: Who Outside Your Company Can Reach Your AWS Resources?

The short version: Companies routinely share cloud resources with vendors and partners. Over time, nobody remembers who has access to what. AWS released a...

Multi-CloudIncident Teardowns

Travelex Ransomware (Dec 2019): Unpatched VPN Servers and a Business Standstill

On December 31, 2019, foreign exchange company Travelex was hit by Sodinokibi (REvil) ransomware. Its websites and systems went offline for weeks, and banks...

Multi-CloudHow-To & Hardening

How to Retire Legacy VPNs in Favor of Zero Trust Access

Traditional VPNs give users broad network access once connected and present a constantly targeted appliance on the internet. Zero trust access replaces that...

Multi-CloudDetection & Response

Detecting VPN Vulnerability Exploitation: Sentinel and GuardDuty Detections

Attackers exploiting VPN and remote access appliances often look like legitimate users. Detection focuses on suspicious sessions and what happens after them.

Multi-CloudCIO Briefings

CIO Brief: When Ransomware Stops Revenue — The Travelex Timeline

The short version: On New Year's Eve 2019, ransomware shut down Travelex's systems for weeks. Attackers reportedly got in through a remote access device...

Microsoft 365Platform Changes

Microsoft Ignite 2019: Insider Risk Management and the Microsoft Defender Rebrand

At Microsoft Ignite in November 2019, Microsoft announced Insider Risk Management in preview as part of Microsoft 365 compliance, alongside updates across...

Microsoft 365How-To & Hardening

How to Pilot Microsoft Purview Insider Risk Management

Microsoft Purview Insider Risk Management can detect data theft and leaks by insiders, but it needs careful setup and governance. Here is how to run a pilot.

Microsoft 365How-To & Hardening

Insider Risk Policy Checklist: Privacy, HR and Legal Sign-Off

Insider risk monitoring touches employee privacy. This checklist helps make sure policies have the right sign-off before you enable them.

Microsoft 365CIO Briefings

CIO Brief: Insider Risk Without Spying on Employees

The short version: In 2019, Microsoft introduced tools to detect when employees might be taking or leaking company data — for example, downloading large...

AWSPlatform Changes

AWS Launches IMDSv2 (Nov 2019): Closing the Capital One Attack Path

In November 2019, four months after the Capital One breach, AWS released version 2 of the EC2 Instance Metadata Service (IMDSv2). It was designed...

AWSHow-To & Hardening

How to Migrate an EC2 Fleet to IMDSv2 Without Breaking Applications

IMDSv2 protects instance credentials from SSRF attacks, but enforcing it across a large EC2 fleet can break older applications if done carelessly. Here is a...

AWSHow-To & Hardening

IMDSv2 Enforcement Checklist With SCPs and Launch Templates

Use this checklist to make IMDSv2 mandatory across your AWS organization and keep it that way.

AWSCIO Briefings

CIO Brief: How One AWS Setting Answers the Capital One Breach

The short version: After Capital One's 2019 breach, AWS released a setting — IMDSv2 — that blocks the technique the attacker used to steal cloud...

Entra ID & IdentityPlatform Changes

Azure AD Security Defaults Arrive (Oct 2019): Free Baseline Protection for Every Tenant

In October 2019, Microsoft introduced Security Defaults for Azure Active Directory (now Entra ID). It replaced earlier "baseline policies" with a single...

Entra ID & IdentityHow-To & Hardening

How to Choose Between Security Defaults and Conditional Access

Entra ID offers two ways to enforce baseline identity security: Security Defaults (free, simple) and Conditional Access (requires Entra ID P1, flexible)....

Entra ID & IdentityHow-To & Hardening

Security Defaults Rollout Checklist and User Communication Template

Use this checklist to enable Security Defaults with minimal disruption, especially for smaller organizations.

Entra ID & IdentityCIO Briefings

CIO Brief: The Free Setting That Blocks Most Identity Attacks

The short version: In 2019, Microsoft released Security Defaults: a free, one-click setting that turns on multi-factor authentication and blocks older,...

Microsoft 365Platform Changes

Microsoft Announces Basic Auth Retirement for Exchange Online (Sept 2019)

In September 2019, Microsoft announced that it would turn off Basic Authentication in Exchange Online for Exchange ActiveSync, POP, IMAP, Exchange Web...

Microsoft 365How-To & Hardening

How to Inventory and Migrate Apps Off Basic Authentication in Exchange Online

Legacy (basic) authentication bypasses MFA. Even after Microsoft's retirement of basic authentication in Exchange Online, many organizations still find...

Microsoft 365How-To & Hardening

Legacy Authentication Discovery Checklist for Exchange Online

Use this checklist to find every remaining dependency on legacy authentication in Exchange Online and Microsoft 365.

Microsoft 365CIO Briefings

CIO Brief: Legacy Protocols Are a Legacy Risk

The short version: In 2019, Microsoft announced it would switch off older sign-in methods for its cloud email because they couldn't use multi-factor...

← NewerPage 14 of 20Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.