Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Retrospectives

Articles in Retrospectives.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Microsoft 365How-To & Hardening

How to Hold Your Cloud Providers Accountable With Security Contract Terms

Cloud provider security failures can affect your data — but your contract often gives you little recourse. Here are security terms to negotiate or verify...

Microsoft 365How-To & Hardening

Annual Cloud Provider Security Review Checklist

Use this checklist to review each major cloud provider's security each year.

Microsoft 365CIO Briefings

CIO Brief: What the CSRB Findings Mean for Microsoft Customers

The short version: In April 2024, a US government review board concluded that a Chinese hack of Microsoft's email systems "should never have happened" and...

Multi-CloudIncident Teardowns

The XZ Utils Backdoor (Mar 2024): A Multi-Year Open-Source Supply-Chain Plot

On March 29, 2024, Microsoft engineer Andres Freund disclosed that he had found a backdoor in XZ Utils, a compression library included in many Linux...

Multi-CloudHow-To & Hardening

How to Scan Cloud Images and Containers for Compromised Packages

When a compromised package like XZ Utils is discovered, you need to know quickly whether it's in your cloud images and containers. Here is how to scan...

Multi-CloudDetection & Response

Detecting Compromised Open Source Packages: Sentinel and GuardDuty Detections

Compromised open-source packages are hard to detect by behavior — they're designed to look legitimate. Detection relies on inventory, threat intelligence...

Multi-CloudCIO Briefings

CIO Brief: Open-Source Dependencies Are Third-Party Risk

The short version: In 2024, a hidden backdoor was discovered in XZ Utils, a small but widely used piece of free software in Linux systems. Someone had spent...

Multi-CloudHow-To & Hardening

How to Enforce MFA on Every Remote Access Portal

Change Healthcare and Colonial Pipeline were both breached through remote access without MFA. Here is how to enforce MFA on every remote access portal.

Multi-CloudDetection & Response

Detecting Remote Access Without MFA: Sentinel and GuardDuty Detections

Remote access without MFA is a top ransomware entry point. These detections look for single-factor access and the activity that typically follows.

Multi-CloudCIO Briefings

CIO Brief: Change Healthcare and the Systemic Risk of One Missing Control

The short version: In February 2024, ransomware shut down Change Healthcare, disrupting pharmacies and medical billing across the US for weeks. The...

Microsoft 365How-To & Hardening

How to Find Forgotten Test Tenants and Over-Privileged OAuth Apps

Midnight Blizzard got into Microsoft through a forgotten test tenant and a legacy OAuth app with production access. Here is how to find similar risks in...

Microsoft 365Detection & Response

Detecting OAuth App Abuse: Defender XDR and Sentinel Hunting Queries

OAuth application abuse lets attackers access mailboxes and data with app-level permissions that bypass user MFA. These detections focus on privilege...

Microsoft 365CIO Briefings

CIO Brief: The Test Environment Nobody Remembered

The short version: In January 2024, Russian state hackers read email of Microsoft's senior leaders. They got in through an old test account that didn't...

Entra ID & IdentityPlatform Changes

Secure Future Initiative and Microsoft-Managed Conditional Access Policies (Nov 2023)

On November 2, 2023, Microsoft announced the Secure Future Initiative (SFI), a company-wide security commitment following a series of high-profile...

Entra ID & IdentityHow-To & Hardening

How to Review and Customize Microsoft-Managed Conditional Access Policies

Microsoft automatically creates Conditional Access policies in many tenants. Here is how to review them, customize them safely and make sure they fit with...

Entra ID & IdentityHow-To & Hardening

Conditional Access Policy Review Checklist

Use this checklist to review your Conditional Access policies.

Entra ID & IdentityCIO Briefings

CIO Brief: Microsoft Is Changing Your Defaults — Here's What to Know

The short version: In November 2023, Microsoft announced a major security push — the Secure Future Initiative — and began automatically adding security...

Microsoft 365How-To & Hardening

How to Prepare SharePoint Permissions Before Turning On Copilot

Copilot surfaces any content a user can access. Before broad rollout, fix the SharePoint and OneDrive permissions that would expose sensitive data. Here is...

Microsoft 365How-To & Hardening

Copilot Readiness Checklist: Permissions, Labels and Pilot Groups

Use this checklist before expanding Microsoft 365 Copilot beyond a pilot.

Microsoft 365CIO Briefings

CIO Brief: Copilot Will Find Everything Your Users Can Access

The short version: Microsoft 365 Copilot, available since late 2023, can find and summarize anything an employee has access to — instantly. In most...

Entra ID & IdentityIncident Teardowns

Okta Support System Breach (Oct 2023): Session Tokens in Uploaded HAR Files

In October 2023, Okta disclosed that an attacker had used stolen credentials to access its customer support case management system and view files uploaded...

Entra ID & IdentityHow-To & Hardening

How to Sanitize Support Uploads and Bind Tokens to Devices

HAR files shared with support teams can contain live session tokens. Token protection and device-bound sessions limit what a stolen token can do. Here is...

Entra ID & IdentityDetection & Response

Detecting Session Token Theft HAR Files: Entra Sign-In Logs and Sentinel KQL

Session tokens taken from HAR files, infostealer logs or phishing proxies are used to access accounts without signing in. Detection focuses on session reuse...

Entra ID & IdentityCIO Briefings

CIO Brief: Your Identity Provider's Breach Is Your Breach

The short version: In 2023, attackers broke into Okta's customer support system and stole login sessions from files customers had uploaded for...

← NewerPage 5 of 20Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.