Microsoft Entra Launches (May 2022): Identity Becomes Its Own Product Family
In May 2022, Microsoft announced Microsoft Entra, a new product family for identity and access. Azure Active Directory became part of Entra, and in July...
Insights
Articles in Retrospectives.
In May 2022, Microsoft announced Microsoft Entra, a new product family for identity and access. Azure Active Directory became part of Entra, and in July...
Microsoft Entra now includes many products. Here is a practical way to map them to an identity security roadmap for a mid-sized organization.
Use this checklist to assess an identity security program for a mid-sized organization.
The short version: In 2022, Microsoft reorganized its identity products under a new brand, Entra — reflecting a shift the whole industry made: who you are...
In April 2022, GitHub disclosed that an attacker had used stolen OAuth user tokens issued to two third-party integrators — Heroku and Travis CI — to...
Stored cloud credentials in CI/CD systems are a prime target. OIDC federation lets pipelines get short-lived credentials from AWS or Azure on demand — with...
Stolen OAuth tokens let attackers act as a trusted app without passwords or MFA. Detection focuses on token use that doesn't fit the app's normal behavior.
The short version: In 2022, attackers stole the digital access passes that Heroku and Travis CI used to connect to customers' GitHub code repositories, and...
Between late 2021 and March 2022, a loosely organized group calling itself Lapsus$ breached some of the world's largest technology companies, including...
MFA fatigue (or push bombing) floods a user with approval requests until they accept. Number matching and additional context make blind approvals much...
MFA fatigue attacks generate distinctive patterns: many MFA prompts, many denials, then sometimes an approval. Detecting them early lets you lock down the...
The short version: In 2022, a group of teenagers called Lapsus$ breached Microsoft, Nvidia, Samsung and Okta — not with advanced hacking tools, but by...
Continuous Access Evaluation (CAE) changed how quickly Microsoft Entra ID can cut off access. Microsoft announced general availability in early 2022 after a...
Continuous Access Evaluation (CAE) lets Entra ID revoke access in near real time. It's on by default for many tenants, but strict location enforcement and...
Use this checklist to confirm your applications and clients work well with Continuous Access Evaluation, especially before enabling strict location enforcement.
The short version: Until a few years ago, if you disabled a compromised employee account in Microsoft 365, the attacker could keep using it for up to an...
On December 9, 2021, a critical vulnerability in Apache Log4j 2 — a Java logging library used in countless applications — became public. Tracked as...
When a library vulnerability like Log4Shell hits, the first question is "where are we affected?" Here is how to answer it across Azure and AWS workloads.
Log4Shell exploitation attempts appear in web logs and network traffic, and successful exploitation often produces outbound connections and unusual processes.
The short version: In December 2021, a flaw was found in Log4j, a small piece of free software used inside thousands of products. Companies spent weeks just...
On December 7, 2021, AWS's US-EAST-1 region experienced a major disruption lasting much of the day. Services including Disney+, Netflix, Slack, Venmo,...
Regional outages are rare but real. Here is how to plan multi-region failover for the AWS workloads that truly need it.
Use this checklist to plan and run a multi-region disaster recovery test for an AWS workload.
The short version: In December 2021, a problem in one AWS region disrupted major services like Netflix, Disney+ and Amazon's own deliveries for much of a...