Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Retrospectives

Articles in Retrospectives.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Microsoft 365Platform Changes

Windows 10 End of Support (Oct 2025): Unpatched Endpoints in Your Microsoft 365 Estate

On October 14, 2025, Microsoft ended support for Windows 10. After that date, Windows 10 devices stopped receiving free security updates, unless enrolled in...

Microsoft 365How-To & Hardening

How to Use Intune Compliance Policies to Block Unsupported Devices

After Windows 10 end of support, unpatched devices shouldn't access company data. Intune compliance policies and Conditional Access can enforce minimum...

Microsoft 365How-To & Hardening

Windows 11 Migration Security Checklist

Use this checklist to plan a Windows 11 migration with security improvements built in.

Microsoft 365CIO Briefings

CIO Brief: The Security Cost of Delaying Windows 11

The short version: Windows 10 stopped receiving free security updates on October 14, 2025. Every Windows 10 computer still in use without paid extended...

Multi-CloudHow-To & Hardening

How to Detect Leaked Cloud Credentials From Developer Packages

Supply-chain worms like Shai-Hulud steal cloud credentials from developer machines and CI runners. Here is how to detect leaked credentials and respond quickly.

Multi-CloudDetection & Response

Detecting npm Supply Chain Worm: Sentinel and GuardDuty Detections

Package ecosystem worms leave signals across developer endpoints, code platforms and cloud logs. These detections help spot an infection and its use of...

Multi-CloudCIO Briefings

CIO Brief: Open-Source Worms and Your Cloud Keys

The short version: In September 2025, a self-spreading worm infected hundreds of open-source software packages. When developers installed them, it stole...

Entra ID & IdentityIncident Teardowns

Entra ID Actor Token Flaw (Sept 2025): A Cross-Tenant Global Admin Bug

In September 2025, security researcher Dirk-jan Mollema published details of a critical flaw in Microsoft Entra ID that could have allowed an attacker to...

Entra ID & IdentityHow-To & Hardening

How to Monitor Entra ID for Cross-Tenant and Undocumented Token Abuse

Cross-tenant and undocumented token flaws are rare but serious. Customers can't prevent provider bugs, but can reduce exposure and improve visibility. Here...

Entra ID & IdentityDetection & Response

Detecting Cross-Tenant Token Abuse: Entra Sign-In Logs and Sentinel KQL

When identity platform flaws limit logging of the initial access, you can still detect what attackers do next. These detections focus on cross-tenant...

Entra ID & IdentityCIO Briefings

CIO Brief: Even Identity Platforms Have Catastrophic Bugs

The short version: In 2025, a researcher found a flaw in Microsoft Entra ID — the system that controls sign-in for Microsoft 365 and Azure — that could have...

Multi-CloudHow-To & Hardening

How to Audit SaaS-to-SaaS OAuth Integrations and Token Scopes

SaaS-to-SaaS integrations hold OAuth tokens that can read and export your data. The Salesloft Drift campaign showed how one compromised vendor can reach...

Multi-CloudDetection & Response

Detecting SaaS OAuth Token Theft: Sentinel and GuardDuty Detections

Stolen OAuth tokens used for data theft show up as bulk API activity from integrations. These detections help catch it.

Multi-CloudCIO Briefings

CIO Brief: Every Integration Is a Trust Relationship

The short version: In August 2025, attackers stole access tokens from Salesloft's Drift chatbot integration and used them to download data from hundreds of...

Microsoft 365How-To & Hardening

How to Migrate or Isolate On-Premises SharePoint Servers

ToolShell showed the risk of internet-facing on-premises SharePoint Server. Here is how to migrate to SharePoint Online — or isolate servers you must keep.

Microsoft 365Detection & Response

Detecting SharePoint Server Exploitation: Defender XDR and Sentinel Hunting Queries

SharePoint Server exploitation leaves traces in web logs, file system changes and process activity. These detections target behaviors seen in ToolShell and...

Microsoft 365CIO Briefings

CIO Brief: On-Prem SharePoint Is Now a Liability

The short version: In July 2025, Chinese state hackers and ransomware groups exploited flaws in SharePoint servers that companies ran themselves —...

Microsoft 365How-To & Hardening

How to Reduce Copilot Prompt-Injection Exposure With Labels and DLP

Prompt injection can manipulate AI assistants into exposing data they can access. You can't fully prevent it, but you can limit what Copilot can reach and...

Microsoft 365Detection & Response

Detecting Copilot Prompt Injection: Defender XDR and Sentinel Hunting Queries

Prompt injection against AI assistants is hard to detect directly. You can, however, monitor for the conditions that make it dangerous and for signs of misuse.

Microsoft 365CIO Briefings

CIO Brief: Your AI Assistant Can Be Tricked Into Leaking Data

The short version: In 2025, researchers found a way to trick Microsoft 365 Copilot into leaking data simply by sending an email with hidden instructions —...

Entra ID & IdentityHow-To & Hardening

How to Inventory and Govern AI Agent Identities in Entra ID

AI agents are a fast-growing category of identities with access to company data and systems. Here is how to inventory and govern them in Microsoft Entra ID.

Entra ID & IdentityHow-To & Hardening

AI Agent Identity Governance Checklist

Use this checklist to govern AI agent identities in your organization.

Entra ID & IdentityCIO Briefings

CIO Brief: AI Agents Are the Newest Privileged Users

The short version: AI agents — software that can read your data and take actions on its own — are spreading quickly across companies. In 2025, Microsoft...

Entra ID & IdentityHow-To & Hardening

How to Lock Down Entra ID Password Reset and MFA Re-Registration

Attackers who convince a help desk to reset a password often then register their own MFA method. Locking down password reset and MFA re-registration in...

← NewerPage 2 of 20Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.