Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

How-To & Hardening

Articles in How-To & Hardening.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Entra ID & IdentityHow-To & Hardening

Conditional Access Policy Review Checklist

Use this checklist to review your Conditional Access policies.

Microsoft 365How-To & Hardening

How to Prepare SharePoint Permissions Before Turning On Copilot

Copilot surfaces any content a user can access. Before broad rollout, fix the SharePoint and OneDrive permissions that would expose sensitive data. Here is...

Microsoft 365How-To & Hardening

Copilot Readiness Checklist: Permissions, Labels and Pilot Groups

Use this checklist before expanding Microsoft 365 Copilot beyond a pilot.

Entra ID & IdentityHow-To & Hardening

How to Sanitize Support Uploads and Bind Tokens to Devices

HAR files shared with support teams can contain live session tokens. Token protection and device-bound sessions limit what a stolen token can do. Here is...

AzureHow-To & Hardening

How to Govern Azure Storage SAS Tokens and Disable Shared Key Access

SAS tokens grant time-limited access to Azure Storage — but poorly scoped tokens can expose entire accounts for years. Here is how to govern them and remove...

Entra ID & IdentityHow-To & Hardening

How to Harden Help Desk Identity Verification and Password Resets

The help desk is now a primary target for social engineering. Here is how to harden identity verification and password/MFA resets.

Microsoft 365How-To & Hardening

How to Restrict External Access and Federation in Microsoft Teams

Microsoft Teams external access lets users chat with people in other organizations. Attackers use it for phishing. Here is how to restrict it to what your...

Microsoft 365How-To & Hardening

How to Enable Expanded Audit Logging to Detect Mailbox Access

Storm-0558 was detected because a customer had detailed mailbox access logs. Here is how to make sure your Microsoft 365 audit logging captures what you'd...

Entra ID & IdentityHow-To & Hardening

How to Update Documentation, Scripts and Policies After the Entra ID Rename

The rename from Azure AD to Microsoft Entra ID didn't change functionality, but it's a good reason to update documentation and retire legacy tooling —...

Entra ID & IdentityHow-To & Hardening

Entra ID Configuration Health Checklist

Use this checklist to review the health of your Microsoft Entra ID configuration.

Multi-CloudHow-To & Hardening

How to Inventory Internet-Facing File Transfer and Integration Services

Attackers repeatedly target internet-facing file transfer, integration and remote access services. Here is how to inventory them so you can patch, restrict...

AWSHow-To & Hardening

How to Migrate Legacy S3 Buckets Off ACLs to Bucket Owner Enforced

New S3 buckets have ACLs disabled by default, but older buckets may still rely on them. Migrating to "Bucket owner enforced" simplifies access control. Here...

AWSHow-To & Hardening

S3 Object Ownership and ACL Cleanup Checklist

Use this checklist to clean up legacy S3 ACLs and ownership settings.

Microsoft 365How-To & Hardening

How to Evaluate AI Assistants for Security Operations

AI assistants for security operations can speed up triage and investigation — or add cost and noise. Here is a practical way to evaluate them.

Microsoft 365How-To & Hardening

AI Security Tool Pilot Checklist: Data, Access and ROI

Use this checklist before and during a pilot of an AI security assistant.

AWSHow-To & Hardening

How to Choose Between SSE-S3, SSE-KMS and DSSE-KMS for S3

All new S3 objects are encrypted by default with SSE-S3. For sensitive data, you may want more control. Here is how to choose between SSE-S3, SSE-KMS and...

AWSHow-To & Hardening

S3 Encryption and KMS Key Policy Audit Checklist

KMS key policies decide who can decrypt your sensitive S3 data. Use this checklist to audit encryption and key policies.

Multi-CloudHow-To & Hardening

How to Run a Secrets Rotation Fire Drill Across AWS and Azure

When a provider tells you to rotate everything, the hardest part is knowing what "everything" is. A rotation fire drill — practiced in advance — makes it...

Multi-CloudHow-To & Hardening

How to Protect Cloud Backup Storage With Separate Credentials and Immutability

In the LastPass breach, attackers stole backups from cloud storage using credentials taken from an engineer's home computer. Backups need their own...

AWSHow-To & Hardening

How to Centralize AWS Security Logs With Amazon Security Lake

Amazon Security Lake centralizes and normalizes security logs from AWS and other sources into OCSF format in your own S3 buckets. Here is how to set it up.

AWSHow-To & Hardening

Security Lake Source and Retention Planning Checklist

Use this checklist to plan which data goes into Amazon Security Lake and how long you keep it.

Microsoft 365How-To & Hardening

How to Verify Legacy Authentication Is Fully Blocked in Your Tenant

Microsoft retired Basic Authentication for most Exchange Online protocols in 2022, but legacy authentication can still appear through SMTP AUTH, other...

Microsoft 365How-To & Hardening

Post-Basic-Auth Cleanup Checklist: SMTP AUTH, Service Accounts and Scripts

After Basic Authentication was turned off in Exchange Online, many organizations found lingering dependencies. Use this checklist to clean up.

AzureHow-To & Hardening

How to Audit Azure Storage Accounts for Public Access and Shared Keys

Azure Storage accounts can be exposed through anonymous blob access, overly permissive shared keys and SAS tokens, or public network endpoints. Here is how...

← NewerPage 3 of 8Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.