Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Retrospectives

Articles in Retrospectives.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
AWSPlatform Changes

AWS Centralized Root Access Management (Nov 2024): Removing Root Credentials From Member Accounts

In November 2024, AWS launched centralized root access management for AWS Organizations. It lets security teams remove root user credentials from member...

AWSHow-To & Hardening

How to Remove Root User Credentials Across an AWS Organization

AWS centralized root access management lets you delete root credentials in member accounts. Here is how to enable it and lock down root across your...

AWSHow-To & Hardening

AWS Root User Lockdown Checklist

Use this checklist to lock down the AWS root user across your organization.

AWSCIO Briefings

CIO Brief: The Most Powerful AWS Credential — and How to Retire It

The short version: Every AWS account has a "root" login with unlimited power. Companies with many AWS accounts had many of these super-passwords to protect....

AzureHow-To & Hardening

How to Prepare Service Accounts and Automation for Azure Mandatory MFA

Microsoft's mandatory MFA for Azure breaks automation that signs in as a user with a password. Here is how to find and migrate those service accounts.

AzureHow-To & Hardening

Azure Mandatory MFA Readiness Checklist

Use this checklist to confirm your organization is ready for Azure's mandatory MFA.

AzureCIO Briefings

CIO Brief: Microsoft Now Requires MFA — Is Your Automation Ready?

The short version: Since October 2024, Microsoft requires multi-factor authentication for anyone managing Azure through its web portals, and from 2025 also...

Microsoft 365How-To & Hardening

How to Use Restricted SharePoint Search and Data Access Governance Reports

Restricted SharePoint Search and data access governance reports help you control Copilot exposure while you fix oversharing. Here is how to use them.

Microsoft 365How-To & Hardening

Copilot Oversharing Remediation Checklist

Use this checklist to remediate oversharing before and during Copilot rollout.

Microsoft 365CIO Briefings

CIO Brief: Scaling Copilot Safely Beyond the Pilot

The short version: In September 2024, Microsoft expanded Copilot with new features — and new tools to fix the "oversharing" problem that stalled many...

AWSIncident Teardowns

Exposed .env Files Fuel an AWS Extortion Campaign (Aug 2024)

In August 2024, researchers at Palo Alto Networks' Unit 42 described an extortion campaign that started with publicly exposed environment (.env) files on...

AWSHow-To & Hardening

How to Keep Secrets Out of Web Roots and Into AWS Secrets Manager

Exposed .env files led to an AWS extortion campaign in 2024. Here is how to keep secrets out of web-accessible locations and move them into AWS Secrets Manager.

AWSDetection & Response

Detecting Exposed Environment Variables: CloudTrail, GuardDuty and Athena Queries

Credential theft from exposed configuration files leads to predictable AWS activity. These detections target the patterns seen in .env-based extortion...

AWSCIO Briefings

CIO Brief: Leaked Configuration Files Are Leaked Keys

The short version: In 2024, attackers scanned the internet for websites accidentally publishing their configuration files — which contained cloud passwords...

Multi-CloudHow-To & Hardening

How to Recover BitLocker-Protected Azure VMs and Endpoints at Scale

The CrowdStrike outage showed how hard recovery is when thousands of BitLocker-encrypted devices won't boot. Here is how to prepare for recovering Azure VMs...

Multi-CloudHow-To & Hardening

Endpoint Agent Update Risk Checklist

Security agents and other kernel-level software can take down entire fleets. Use this checklist to manage the risk of endpoint agent updates.

Multi-CloudCIO Briefings

CIO Brief: When Your Security Tool Causes the Outage

The short version: On July 19, 2024, a faulty update to CrowdStrike's security software crashed about 8.5 million Windows computers worldwide. Airlines,...

Multi-CloudHow-To & Hardening

How to Enforce SSO and MFA on Every SaaS Data Platform

The Snowflake customer breaches happened because SaaS data platforms were accessed with stolen passwords and no MFA. Here is how to enforce SSO and MFA...

Multi-CloudDetection & Response

Detecting SaaS Credential Stuffing: Sentinel and GuardDuty Detections

Infostealer-sourced credentials are used against SaaS platforms in automated campaigns. These detections help catch SaaS account takeover and data theft.

Multi-CloudCIO Briefings

CIO Brief: SaaS Shared Responsibility — Snowflake Wasn't Hacked, Its Customers Were

The short version: In 2024, attackers stole data from about 165 companies' accounts on Snowflake, a cloud data platform — including Ticketmaster and AT&T....

Entra ID & IdentityHow-To & Hardening

How to Roll Out Device-Bound Passkeys in Entra ID

Passkeys in Microsoft Authenticator give users phishing-resistant MFA on their phones. Here is how to roll them out in Entra ID.

Entra ID & IdentityHow-To & Hardening

Passkey Rollout Checklist: Registration, Recovery and Help Desk

Use this checklist to roll out passkeys across your organization.

Entra ID & IdentityCIO Briefings

CIO Brief: Passkeys Make Phishing-Resistant MFA Affordable

The short version: Since 2024, Microsoft lets employees use passkeys on their phones to sign in — the strongest common form of authentication, and immune to...

Microsoft 365Platform Changes

The CSRB Report on Storm-0558 (Apr 2024): A 'Cascade of Security Failures' at Microsoft

On April 2, 2024, the US Cyber Safety Review Board (CSRB) published its report on the Storm-0558 intrusion, in which Chinese state actors used a stolen...

← NewerPage 4 of 20Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.