Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Retrospectives

Articles in Retrospectives.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Entra ID & IdentityPlatform Changes

Microsoft Entra Launches (May 2022): Identity Becomes Its Own Product Family

In May 2022, Microsoft announced Microsoft Entra, a new product family for identity and access. Azure Active Directory became part of Entra, and in July...

Entra ID & IdentityHow-To & Hardening

How to Map Entra Products to Your Identity Security Roadmap

Microsoft Entra now includes many products. Here is a practical way to map them to an identity security roadmap for a mid-sized organization.

Entra ID & IdentityHow-To & Hardening

Identity Security Program Checklist for Mid-Market Companies

Use this checklist to assess an identity security program for a mid-sized organization.

Entra ID & IdentityCIO Briefings

CIO Brief: Identity Is the New Perimeter — Now It Has a Brand

The short version: In 2022, Microsoft reorganized its identity products under a new brand, Entra — reflecting a shift the whole industry made: who you are...

Multi-CloudIncident Teardowns

Heroku and Travis CI OAuth Tokens Stolen (Apr 2022): Hijacking GitHub Access

In April 2022, GitHub disclosed that an attacker had used stolen OAuth user tokens issued to two third-party integrators — Heroku and Travis CI — to...

Multi-CloudHow-To & Hardening

How to Secure CI/CD Pipelines With OIDC Federation Instead of Stored Secrets

Stored cloud credentials in CI/CD systems are a prime target. OIDC federation lets pipelines get short-lived credentials from AWS or Azure on demand — with...

Multi-CloudDetection & Response

Detecting Stolen OAuth Tokens: Sentinel and GuardDuty Detections

Stolen OAuth tokens let attackers act as a trusted app without passwords or MFA. Detection focuses on token use that doesn't fit the app's normal behavior.

Multi-CloudCIO Briefings

CIO Brief: Your Build Pipeline Has the Keys to Production

The short version: In 2022, attackers stole the digital access passes that Heroku and Travis CI used to connect to customers' GitHub code repositories, and...

Entra ID & IdentityIncident Teardowns

Lapsus$ (Mar 2022): Teenagers, MFA Fatigue and Breaches at Okta and Microsoft

Between late 2021 and March 2022, a loosely organized group calling itself Lapsus$ breached some of the world's largest technology companies, including...

Entra ID & IdentityHow-To & Hardening

How to Enable MFA Number Matching and Stop Push Fatigue Attacks

MFA fatigue (or push bombing) floods a user with approval requests until they accept. Number matching and additional context make blind approvals much...

Entra ID & IdentityDetection & Response

Detecting MFA Fatigue Attacks: Entra Sign-In Logs and Sentinel KQL

MFA fatigue attacks generate distinctive patterns: many MFA prompts, many denials, then sometimes an approval. Detecting them early lets you lock down the...

Entra ID & IdentityCIO Briefings

CIO Brief: Insider Recruitment and Social Engineering — The Lapsus$ Playbook

The short version: In 2022, a group of teenagers called Lapsus$ breached Microsoft, Nvidia, Samsung and Okta — not with advanced hacking tools, but by...

Entra ID & IdentityPlatform Changes

Continuous Access Evaluation Arrives (2022): Revoking Sessions in Near Real Time

Continuous Access Evaluation (CAE) changed how quickly Microsoft Entra ID can cut off access. Microsoft announced general availability in early 2022 after a...

Entra ID & IdentityHow-To & Hardening

How to Enable Continuous Access Evaluation and Strict Location Enforcement

Continuous Access Evaluation (CAE) lets Entra ID revoke access in near real time. It's on by default for many tenants, but strict location enforcement and...

Entra ID & IdentityHow-To & Hardening

CAE Compatibility Checklist for Apps and Clients

Use this checklist to confirm your applications and clients work well with Continuous Access Evaluation, especially before enabling strict location enforcement.

Entra ID & IdentityCIO Briefings

CIO Brief: Why Revoking Access Used to Take an Hour

The short version: Until a few years ago, if you disabled a compromised employee account in Microsoft 365, the attacker could keep using it for up to an...

Multi-CloudIncident Teardowns

Log4Shell (Dec 2021): The Vulnerability in Everything

On December 9, 2021, a critical vulnerability in Apache Log4j 2 — a Java logging library used in countless applications — became public. Tracked as...

Multi-CloudHow-To & Hardening

How to Find Vulnerable Libraries in Azure and AWS Workloads

When a library vulnerability like Log4Shell hits, the first question is "where are we affected?" Here is how to answer it across Azure and AWS workloads.

Multi-CloudDetection & Response

Detecting Log4j Exploitation: Sentinel and GuardDuty Detections

Log4Shell exploitation attempts appear in web logs and network traffic, and successful exploitation often produces outbound connections and unusual processes.

Multi-CloudCIO Briefings

CIO Brief: Software Bills of Materials After Log4Shell

The short version: In December 2021, a flaw was found in Log4j, a small piece of free software used inside thousands of products. Companies spent weeks just...

AWSIncident Teardowns

The AWS us-east-1 Outage of December 2021: When the Control Plane Fails

On December 7, 2021, AWS's US-EAST-1 region experienced a major disruption lasting much of the day. Services including Disney+, Netflix, Slack, Venmo,...

AWSHow-To & Hardening

How to Plan Multi-Region Failover for Critical AWS Workloads

Regional outages are rare but real. Here is how to plan multi-region failover for the AWS workloads that truly need it.

AWSHow-To & Hardening

Multi-Region Disaster Recovery Test Checklist

Use this checklist to plan and run a multi-region disaster recovery test for an AWS workload.

AWSCIO Briefings

CIO Brief: Concentration Risk in a Single Cloud Region

The short version: In December 2021, a problem in one AWS region disrupted major services like Netflix, Disney+ and Amazon's own deliveries for much of a...

← NewerPage 9 of 20Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.