Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Retrospectives

Articles in Retrospectives.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Entra ID & IdentityPlatform Changes

Microsoft Ignite 2018: Passwordless Sign-In and Microsoft Threat Protection Arrive

At Microsoft Ignite in September 2018, Microsoft made identity and threat protection central themes. Two announcements stood out: passwordless sign-in for...

Entra ID & IdentityHow-To & Hardening

How to Plan a Passwordless Rollout With Windows Hello and Authenticator

Passwordless sign-in removes the most attacked credential and improves user experience. Here is a practical rollout plan using Windows Hello for Business,...

Entra ID & IdentityHow-To & Hardening

Passwordless Readiness Checklist for Windows and Mobile

Use this checklist to check whether your organization is ready to roll out passwordless sign-in.

Entra ID & IdentityCIO Briefings

CIO Brief: Passwordless Is a Productivity Win, Not Just Security

The short version: In 2018, Microsoft started pushing businesses toward signing in without passwords, using phones, fingerprints and security keys instead....

Entra ID & IdentityIncident Teardowns

Reddit's Breach via SMS Interception (Aug 2018): Why SMS MFA Isn't Enough

On August 1, 2018, Reddit disclosed that an attacker had accessed some of its systems, including an old database backup with user data from 2007 and email...

Entra ID & IdentityHow-To & Hardening

How to Migrate Users From SMS to Authenticator App and FIDO2 MFA

SMS and voice codes are the weakest forms of MFA. Here is how to migrate Microsoft 365 users to the Microsoft Authenticator app and, for higher-risk users,...

Entra ID & IdentityDetection & Response

Detecting SMS MFA Interception: Entra Sign-In Logs and Sentinel KQL

SMS codes can be intercepted through SIM swaps and phishing. You often can't see the interception itself, but you can detect what happens next: a sign-in...

Entra ID & IdentityCIO Briefings

CIO Brief: Not All MFA Is Equal — The Case for Phishing-Resistant Methods

The short version: In 2018, Reddit was breached even though its employees used two-factor authentication — the attacker intercepted text message codes. All...

Entra ID & IdentityPlatform Changes

Azure AD Password Protection Preview (2018): Banning Bad Passwords in the Cloud and On-Prem

In June 2018, Microsoft announced a public preview of Azure AD Password Protection, bringing its banned-password technology to customers' cloud accounts and...

Entra ID & IdentityHow-To & Hardening

How to Deploy Entra Password Protection to On-Premises Domain Controllers

Microsoft Entra Password Protection blocks weak and commonly attacked passwords. In the cloud it works automatically for Entra ID accounts; extending it to...

Entra ID & IdentityHow-To & Hardening

Custom Banned Password List Checklist for Entra ID

A custom banned password list blocks the terms attackers are most likely to try against your organization. Use this checklist to build one that works.

Entra ID & IdentityCIO Briefings

CIO Brief: Password Policy Is Still a Security Control

The short version: Most password rules produce predictable passwords like "Summer2018!", which attackers try first. In 2018, Microsoft introduced a way to...

Microsoft 365Platform Changes

GDPR Enforcement Begins (May 2018): What It Changed for Microsoft 365 Data Governance

On May 25, 2018, the European Union's General Data Protection Regulation (GDPR) became enforceable. It applied to any organization processing personal data...

Microsoft 365How-To & Hardening

How to Use Microsoft Purview to Find and Govern Personal Data

Privacy laws such as GDPR require you to know where personal data lives and to control it. In Microsoft 365, Microsoft Purview provides the tools. Here is a...

Microsoft 365How-To & Hardening

GDPR Data Inventory Checklist for Microsoft 365

A data inventory is the foundation of GDPR compliance and of any serious data protection program. Use this checklist to build one for Microsoft 365.

Microsoft 365CIO Briefings

CIO Brief: GDPR Fines and Your Cloud Data Map

The short version: GDPR, enforceable since 2018, made organizations legally responsible for knowing where personal data lives and protecting it — with fines...

Microsoft 365Incident Teardowns

Cambridge Analytica (Mar 2018): What App Permissions Mean for Your Microsoft 365 Tenant

In March 2018, reporting by The Observer and The New York Times revealed that the political consultancy Cambridge Analytica had obtained data on up to 87...

Microsoft 365How-To & Hardening

How to Lock Down User Consent to Third-Party Apps in Entra ID

By default, Microsoft 365 users can grant third-party apps access to their data. Malicious apps use that to steal mail and files without ever needing a...

Microsoft 365Detection & Response

Detecting OAuth App Over-Permission: Defender XDR and Sentinel Hunting Queries

OAuth apps with excessive permissions can read mail and files across your tenant without a password. Detecting risky consent grants is a core identity...

Microsoft 365CIO Briefings

CIO Brief: Who Approved That App? Governing OAuth Permissions

The short version: Cambridge Analytica obtained data on tens of millions of Facebook users through an app most of them never used. The same mechanism — apps...

Microsoft 365Incident Teardowns

The Mabna Institute Indictment (Mar 2018): Password Spraying Against Cloud Email

In March 2018, the US Department of Justice indicted nine Iranian nationals associated with the Mabna Institute for a long-running hacking campaign against...

Microsoft 365How-To & Hardening

How to Block Legacy Authentication to Stop Password Spraying in Microsoft 365

Password spraying succeeds most often through legacy authentication protocols that cannot perform MFA. Blocking legacy authentication closes that door. Here...

Microsoft 365Detection & Response

Detecting Password Spraying: Defender XDR and Sentinel Hunting Queries

Password spraying tries a small number of common passwords against many accounts, staying below lockout thresholds. Detecting it requires looking across...

Microsoft 365CIO Briefings

CIO Brief: Password Spraying Is Cheap for Attackers — Is Your Tenant Ready?

The short version: In 2018, the US indicted Iranian hackers who stole large volumes of data by trying common passwords against thousands of accounts. It is...

← NewerPage 17 of 20Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.