Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Azure

Articles in Azure.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
AzureIncident Teardowns

OMIGOD (Sept 2021): Hidden Azure Agents Running as Root

In September 2021, Wiz researchers disclosed OMIGOD, four vulnerabilities in Open Management Infrastructure (OMI), a software agent that Microsoft silently...

AzureHow-To & Hardening

How to Inventory and Patch Azure VM Extensions and Management Agents

Azure VM extensions and management agents add capabilities — and attack surface. Here is how to inventory and patch them.

AzureDetection & Response

Detecting VM Agent Exploitation: Defender for Cloud and Sentinel KQL

Management agents and VM extensions run with high privilege. Attackers exploit vulnerable agents or abuse extensions to run code. These detections cover both.

AzureCIO Briefings

CIO Brief: The Software Your Cloud Provider Installs on Your Servers

The short version: In 2021, researchers found serious flaws in a management program Microsoft quietly installed on many Linux servers in Azure. Many...

AzureIncident Teardowns

ChaosDB (Aug 2021): A Cosmos DB Flaw Exposed Thousands of Azure Customers' Keys

In August 2021, researchers at Wiz disclosed ChaosDB, a vulnerability in Microsoft Azure Cosmos DB that could have allowed an attacker to obtain the primary...

AzureHow-To & Hardening

How to Rotate Cosmos DB Keys and Move to Entra ID Authentication

Cosmos DB primary keys grant full access to a database. ChaosDB showed how damaging a leaked key can be. Here is how to rotate keys and move to Entra ID...

AzureDetection & Response

Detecting Cosmos DB Key Misuse With Defender for Cloud and Sentinel

Database keys and connection strings, once leaked, are used like legitimate access. Monitoring data plane activity helps you spot misuse.

AzureCIO Briefings

CIO Brief: When the Cloud Provider's Own Service Is Vulnerable

The short version: In 2021, researchers found a flaw in one of Microsoft's own Azure database services that could have let attackers access thousands of...

AzureIncident Teardowns

Zerologon (Aug–Sept 2020): Taking Over a Domain Controller in Seconds

In August 2020, Microsoft patched CVE-2020-1472, a critical flaw in the Netlogon Remote Protocol used by Windows domain controllers. In September,...

AzureHow-To & Hardening

How to Patch and Monitor Domain Controllers in Hybrid Azure Environments

Domain controllers hold the keys to your on-premises identity — and, in hybrid environments, a path to the cloud. Here is how to patch and monitor them...

AzureDetection & Response

Detecting Netlogon Exploitation: Defender for Cloud and Sentinel KQL

Attacks on Active Directory — including Zerologon exploitation, DCSync and Kerberos abuse — leave specific traces. Microsoft Defender for Identity and...

AzureCIO Briefings

CIO Brief: Hybrid Identity Means On-Prem Flaws Become Cloud Flaws

The short version: In 2020, a flaw called Zerologon let attackers take over a company's core identity system — Active Directory — in seconds, without a...

AzureIncident Teardowns

Microsoft's 250 Million Support Records Exposed (Jan 2020): A Misconfigured Azure Database

In January 2020, Microsoft disclosed that a customer support database containing about 250 million records had been exposed on the internet without password...

AzureHow-To & Hardening

How to Prevent Public Database Exposure With Azure Policy and Private Endpoints

A single network rule change exposed a Microsoft database to the internet in 2019. Azure Policy and private endpoints let you prevent that class of mistake...

AzureDetection & Response

Detecting Exposed Cloud Database: Defender for Cloud and Sentinel KQL

Exposed databases are often found by internet scanners within hours. Detecting public exposure — and unexpected access — quickly is critical.

AzureCIO Briefings

CIO Brief: If Microsoft Can Misconfigure Azure, So Can You

The short version: In 2020, Microsoft disclosed that a customer support database had been left exposed to the internet after a network setting change. If...

AzureIncident Teardowns

BlueKeep (May 2019): Wormable RDP and the Risk of Internet-Exposed Azure VMs

In May 2019, Microsoft patched CVE-2019-0708, a critical vulnerability in Remote Desktop Services that became known as BlueKeep. It affected older Windows...

AzureHow-To & Hardening

How to Replace Public RDP With Azure Bastion and Just-in-Time Access

Exposed RDP and SSH ports are among the most attacked entry points in the cloud. Azure Bastion and just-in-time (JIT) VM access let administrators reach...

AzureDetection & Response

Detecting Exposed RDP Exploitation: Defender for Cloud and Sentinel KQL

Even with patches, exposed RDP invites brute force, credential stuffing and exploitation. Detecting both the exposure and attacks against it is essential...

AzureCIO Briefings

CIO Brief: Exposed Remote Access Is Still the Front Door for Ransomware

The short version: In 2019, Microsoft warned about BlueKeep, a flaw that could let attackers take over older Windows computers through remote desktop...

AzurePlatform Changes

Azure Sentinel Preview (Feb 2019): Microsoft Enters the Cloud SIEM Market

On February 28, 2019, Microsoft announced Azure Sentinel in preview — a cloud-native security information and event management (SIEM) service built on Azure...

AzureHow-To & Hardening

How to Plan a Microsoft Sentinel Deployment: Workspaces, Connectors and Costs

A good Microsoft Sentinel deployment starts with planning workspaces, data sources and costs before turning anything on. Here is the sequence Microsoft's...

AzureHow-To & Hardening

Sentinel Data Connector Priority Checklist

Data connectors determine both what Microsoft Sentinel can detect and what it costs. Use this checklist to prioritize them.

AzureCIO Briefings

CIO Brief: Cloud-Native SIEM vs. Legacy SIEM — The Cost and Coverage Trade-Off

The short version: In 2019, Microsoft released Sentinel, a security monitoring service that runs in the cloud. It made centralized security monitoring...

← NewerPage 2 of 3Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.