Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

How-To & Hardening

Articles in How-To & Hardening.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Entra ID & IdentityHow-To & Hardening

How to Audit Third-Party Community and Support Platforms Tied to Your SSO

The Hacktron research into OpenAI combined a flaw in community forum software with a weakness in employee validation. Many organizations run similar...

AI SecurityHow-To & Hardening

How to Contain AI Agents With Network Egress Controls and Scoped Identities

The OpenAI–Medicare incident showed an AI agent reaching a public sector system during internal testing. Network egress controls and scoped identities are...

AWSHow-To & Hardening

How to Find, Disable and Replace Long-Lived AWS Access Keys

Thousands of exposed AWS access keys remain active years after leaking. Here is how to find, disable and replace long-lived keys in your accounts.

AI SecurityHow-To & Hardening

How to Update AI/SI Terminology in Security Policies, Contracts and Risk Registers

The September 2026 executive order renaming "AI" to "Super Intelligence" in federal documents doesn't change technology or law, but it can create confusion...

Entra ID & IdentityHow-To & Hardening

How to Review Entra Provisioning Service Permissions After August 2026 Patch Tuesday

August 2026's Entra ID fixes included a critical elevation-of-privilege flaw in the Entra Provisioning Service. Even though Microsoft fixed it server-side,...

AI SecurityHow-To & Hardening

How to Sandbox AI Agents: Package Proxies, Egress Allowlists and Kill Switches

The OpenAI–Hugging Face incident showed that AI agents can find and exploit weaknesses in their own sandboxes. Organizations running agents — even simple...

Microsoft 365How-To & Hardening

How to Use Token Protection and Compliant-Device Policies Against Token Theft

MFA-bypass phishing kits steal tokens rather than passwords. Two Entra ID controls make stolen tokens much less useful: token protection and...

AzureHow-To & Hardening

How to Harden SSPR, Azure RBAC and VM Run Command Against Identity-Led Attacks

Storm-2949 moved from a social-engineered password reset to Azure-wide control using RBAC permissions and VM management features. Here is how to harden each...

Microsoft 365How-To & Hardening

How to Block Device Code Flow With Conditional Access

Device code phishing kits like EvilTokens trick users into completing MFA on an attacker's behalf. Blocking device code flow with Conditional Access removes...

AWSHow-To & Hardening

How to Shrink Your AWS Blast Radius When Attackers Move at Machine Speed

AI-assisted attackers can escalate in AWS within minutes. Shrinking your blast radius — what any single credential can reach — matters more than ever. Here...

AI SecurityHow-To & Hardening

AI/SI Governance Checklist: Policies, Vendors and Agent Inventory

The AI-to-SI rename is a good moment to check your AI governance basics. Use this checklist to cover policies, vendors and agents.

AWSHow-To & Hardening

How to Reduce Your Dependence on a Single AWS Region's Control Plane

Many AWS workloads depend on US-EAST-1 more than their owners realize. Here is how to reduce dependence on a single region's control plane.

AWSHow-To & Hardening

Region Failure Readiness Checklist for AWS Workloads

Use this checklist to check whether an AWS workload is ready for a regional failure.

Microsoft 365How-To & Hardening

How to Use Intune Compliance Policies to Block Unsupported Devices

After Windows 10 end of support, unpatched devices shouldn't access company data. Intune compliance policies and Conditional Access can enforce minimum...

Microsoft 365How-To & Hardening

Windows 11 Migration Security Checklist

Use this checklist to plan a Windows 11 migration with security improvements built in.

Multi-CloudHow-To & Hardening

How to Detect Leaked Cloud Credentials From Developer Packages

Supply-chain worms like Shai-Hulud steal cloud credentials from developer machines and CI runners. Here is how to detect leaked credentials and respond quickly.

Entra ID & IdentityHow-To & Hardening

How to Monitor Entra ID for Cross-Tenant and Undocumented Token Abuse

Cross-tenant and undocumented token flaws are rare but serious. Customers can't prevent provider bugs, but can reduce exposure and improve visibility. Here...

Multi-CloudHow-To & Hardening

How to Audit SaaS-to-SaaS OAuth Integrations and Token Scopes

SaaS-to-SaaS integrations hold OAuth tokens that can read and export your data. The Salesloft Drift campaign showed how one compromised vendor can reach...

Microsoft 365How-To & Hardening

How to Migrate or Isolate On-Premises SharePoint Servers

ToolShell showed the risk of internet-facing on-premises SharePoint Server. Here is how to migrate to SharePoint Online — or isolate servers you must keep.

Microsoft 365How-To & Hardening

How to Reduce Copilot Prompt-Injection Exposure With Labels and DLP

Prompt injection can manipulate AI assistants into exposing data they can access. You can't fully prevent it, but you can limit what Copilot can reach and...

Entra ID & IdentityHow-To & Hardening

How to Inventory and Govern AI Agent Identities in Entra ID

AI agents are a fast-growing category of identities with access to company data and systems. Here is how to inventory and govern them in Microsoft Entra ID.

Entra ID & IdentityHow-To & Hardening

AI Agent Identity Governance Checklist

Use this checklist to govern AI agent identities in your organization.

Entra ID & IdentityHow-To & Hardening

How to Lock Down Entra ID Password Reset and MFA Re-Registration

Attackers who convince a help desk to reset a password often then register their own MFA method. Locking down password reset and MFA re-registration in...

Multi-CloudHow-To & Hardening

How to Pin and Allowlist GitHub Actions in Cloud Deployment Pipelines

The tj-actions compromise showed that referencing GitHub Actions by tag lets an attacker change your pipeline without touching your code. Here is how to pin...

Page 1 of 8Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.