Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Retrospectives

Articles in Retrospectives.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
AzureHow-To & Hardening

How to Govern Azure Storage SAS Tokens and Disable Shared Key Access

SAS tokens grant time-limited access to Azure Storage — but poorly scoped tokens can expose entire accounts for years. Here is how to govern them and remove...

AzureDetection & Response

Detecting SAS Token Exposure: Defender for Cloud and Sentinel KQL

Overly permissive or leaked SAS tokens provide direct access to Azure Storage. These detections help find token exposure and misuse.

AzureCIO Briefings

CIO Brief: AI Projects Create New Data Exposure Paths

The short version: In 2023, Microsoft's own AI researchers accidentally exposed 38 terabytes of internal data — including passwords and private messages —...

Entra ID & IdentityHow-To & Hardening

How to Harden Help Desk Identity Verification and Password Resets

The help desk is now a primary target for social engineering. Here is how to harden identity verification and password/MFA resets.

Entra ID & IdentityDetection & Response

Detecting Help Desk Social Engineering: Entra Sign-In Logs and Sentinel KQL

Help desk social engineering usually ends with a password or MFA reset followed by an attacker sign-in. These detections connect the two.

Entra ID & IdentityCIO Briefings

CIO Brief: Social Engineering the Help Desk Is the New Ransomware Entry Point

The short version: In 2023, a phone call to MGM's IT help desk reportedly led to a ransomware attack that shut down casinos and hotels for days and cost...

Microsoft 365Incident Teardowns

Midnight Blizzard Phishes Through Microsoft Teams (Aug 2023): External Chat as an Attack Vector

On August 2, 2023, Microsoft reported that Midnight Blizzard — the Russian state actor also known as APT29 or Nobelium, linked to SolarWinds — was using...

Microsoft 365How-To & Hardening

How to Restrict External Access and Federation in Microsoft Teams

Microsoft Teams external access lets users chat with people in other organizations. Attackers use it for phishing. Here is how to restrict it to what your...

Microsoft 365Detection & Response

Detecting Teams External Chat Phishing: Defender XDR and Sentinel Hunting Queries

Teams chat phishing arrives outside email defenses. These detections help spot suspicious external chats and their consequences.

Microsoft 365CIO Briefings

CIO Brief: Your Chat Tool Is an Email Inbox Without Spam Filters

The short version: In 2023, Russian state hackers used Microsoft Teams chat — not email — to trick people into approving login requests. Companies have...

Microsoft 365How-To & Hardening

How to Enable Expanded Audit Logging to Detect Mailbox Access

Storm-0558 was detected because a customer had detailed mailbox access logs. Here is how to make sure your Microsoft 365 audit logging captures what you'd...

Microsoft 365Detection & Response

Detecting Forged Token Mailbox Access: Defender XDR and Sentinel Hunting Queries

Forged or stolen tokens let attackers access mailboxes without normal sign-ins. Mailbox access audit events are often the only evidence.

Microsoft 365CIO Briefings

CIO Brief: Storm-0558 and Paying Extra for Security Logs

The short version: In 2023, Chinese hackers read US government email by forging digital keys in Microsoft's systems. A government agency caught it — because...

Entra ID & IdentityPlatform Changes

Azure AD Becomes Microsoft Entra ID (July 2023): What Actually Changed

On July 11, 2023, Microsoft announced that Azure Active Directory would be renamed Microsoft Entra ID. The change rolled out across portals, documentation...

Entra ID & IdentityHow-To & Hardening

How to Update Documentation, Scripts and Policies After the Entra ID Rename

The rename from Azure AD to Microsoft Entra ID didn't change functionality, but it's a good reason to update documentation and retire legacy tooling —...

Entra ID & IdentityHow-To & Hardening

Entra ID Configuration Health Checklist

Use this checklist to review the health of your Microsoft Entra ID configuration.

Entra ID & IdentityCIO Briefings

CIO Brief: Renames Don't Change Risk — But Licensing Might

The short version: In 2023, Microsoft renamed Azure Active Directory to Microsoft Entra ID. Nothing about security changed with the name. But renames are a...

Multi-CloudHow-To & Hardening

How to Inventory Internet-Facing File Transfer and Integration Services

Attackers repeatedly target internet-facing file transfer, integration and remote access services. Here is how to inventory them so you can patch, restrict...

Multi-CloudDetection & Response

Detecting File Transfer Zero-Day Exploitation: Sentinel and GuardDuty Detections

Mass exploitation of file transfer products typically targets web interfaces and ends with bulk data downloads. These detections help catch both stages.

Multi-CloudCIO Briefings

CIO Brief: Managed File Transfer — The Forgotten Crown Jewel

The short version: In 2023, a ransomware gang exploited a flaw in MOVEit, a file transfer product, stealing data from over 2,000 organizations — many of...

AWSPlatform Changes

S3 Block Public Access and ACLs Disabled by Default for New Buckets (Apr 2023)

In April 2023, AWS changed the default settings for all new S3 buckets: S3 Block Public Access is enabled, and access control lists (ACLs) are disabled...

AWSHow-To & Hardening

How to Migrate Legacy S3 Buckets Off ACLs to Bucket Owner Enforced

New S3 buckets have ACLs disabled by default, but older buckets may still rely on them. Migrating to "Bucket owner enforced" simplifies access control. Here...

AWSHow-To & Hardening

S3 Object Ownership and ACL Cleanup Checklist

Use this checklist to clean up legacy S3 ACLs and ownership settings.

AWSCIO Briefings

CIO Brief: Secure Defaults Help — But Only for New Resources

The short version: In April 2023, AWS changed the defaults so new cloud storage buckets are private and simpler to secure. That's a big improvement — but it...

← NewerPage 6 of 20Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.