Microsoft Ignite 2019: Insider Risk Management and the Microsoft Defender Rebrand
At Microsoft Ignite in November 2019, Microsoft announced Insider Risk Management in preview as part of Microsoft 365 compliance, alongside updates across...
Insights
News, breach teardowns, how-to guides, detections and CIO briefings for Microsoft 365, Entra ID, Azure, AWS and AI agents.
At Microsoft Ignite in November 2019, Microsoft announced Insider Risk Management in preview as part of Microsoft 365 compliance, alongside updates across...
Microsoft Purview Insider Risk Management can detect data theft and leaks by insiders, but it needs careful setup and governance. Here is how to run a pilot.
Insider risk monitoring touches employee privacy. This checklist helps make sure policies have the right sign-off before you enable them.
The short version: In 2019, Microsoft introduced tools to detect when employees might be taking or leaking company data — for example, downloading large...
In November 2019, four months after the Capital One breach, AWS released version 2 of the EC2 Instance Metadata Service (IMDSv2). It was designed...
IMDSv2 protects instance credentials from SSRF attacks, but enforcing it across a large EC2 fleet can break older applications if done carelessly. Here is a...
Use this checklist to make IMDSv2 mandatory across your AWS organization and keep it that way.
The short version: After Capital One's 2019 breach, AWS released a setting — IMDSv2 — that blocks the technique the attacker used to steal cloud...
In October 2019, Microsoft introduced Security Defaults for Azure Active Directory (now Entra ID). It replaced earlier "baseline policies" with a single...
Entra ID offers two ways to enforce baseline identity security: Security Defaults (free, simple) and Conditional Access (requires Entra ID P1, flexible)....
Use this checklist to enable Security Defaults with minimal disruption, especially for smaller organizations.
The short version: In 2019, Microsoft released Security Defaults: a free, one-click setting that turns on multi-factor authentication and blocks older,...
In September 2019, Microsoft announced that it would turn off Basic Authentication in Exchange Online for Exchange ActiveSync, POP, IMAP, Exchange Web...
Legacy (basic) authentication bypasses MFA. Even after Microsoft's retirement of basic authentication in Exchange Online, many organizations still find...
Use this checklist to find every remaining dependency on legacy authentication in Exchange Online and Microsoft 365.
The short version: In 2019, Microsoft announced it would switch off older sign-in methods for its cloud email because they couldn't use multi-factor...
In August 2019, Imperva, a security company known for its cloud web application firewall (formerly Incapsula), disclosed a data exposure affecting customers...
Long-lived IAM user access keys are one of the most common causes of AWS breaches. IAM roles and IAM Identity Center provide short-lived credentials...
Stolen AWS API keys are frequently used for reconnaissance, data theft and resource abuse. These detections help you spot misuse quickly.
The short version: In 2019, Imperva — a company that sells security protection — disclosed that customer data was exposed after an attacker stole a cloud...
On July 29, 2019, Capital One disclosed a breach affecting about 100 million people in the US and 6 million in Canada. It became the defining cloud breach...
IMDSv2 protects EC2 instance credentials from server-side request forgery, the technique used in the Capital One breach. Combined with least-privilege...
The Capital One attack path — SSRF to the metadata service, then stolen role credentials used to read data — leaves traces in CloudTrail and GuardDuty if...
The short version: Capital One's 2019 breach exposed data on about 106 million people. It was caused by a misconfigured firewall combined with a server that...