Conditional Access Policy Review Checklist
Use this checklist to review your Conditional Access policies.
Insights
Articles in How-To & Hardening.
Use this checklist to review your Conditional Access policies.
Copilot surfaces any content a user can access. Before broad rollout, fix the SharePoint and OneDrive permissions that would expose sensitive data. Here is...
Use this checklist before expanding Microsoft 365 Copilot beyond a pilot.
HAR files shared with support teams can contain live session tokens. Token protection and device-bound sessions limit what a stolen token can do. Here is...
SAS tokens grant time-limited access to Azure Storage — but poorly scoped tokens can expose entire accounts for years. Here is how to govern them and remove...
The help desk is now a primary target for social engineering. Here is how to harden identity verification and password/MFA resets.
Microsoft Teams external access lets users chat with people in other organizations. Attackers use it for phishing. Here is how to restrict it to what your...
Storm-0558 was detected because a customer had detailed mailbox access logs. Here is how to make sure your Microsoft 365 audit logging captures what you'd...
The rename from Azure AD to Microsoft Entra ID didn't change functionality, but it's a good reason to update documentation and retire legacy tooling —...
Use this checklist to review the health of your Microsoft Entra ID configuration.
Attackers repeatedly target internet-facing file transfer, integration and remote access services. Here is how to inventory them so you can patch, restrict...
New S3 buckets have ACLs disabled by default, but older buckets may still rely on them. Migrating to "Bucket owner enforced" simplifies access control. Here...
Use this checklist to clean up legacy S3 ACLs and ownership settings.
AI assistants for security operations can speed up triage and investigation — or add cost and noise. Here is a practical way to evaluate them.
Use this checklist before and during a pilot of an AI security assistant.
All new S3 objects are encrypted by default with SSE-S3. For sensitive data, you may want more control. Here is how to choose between SSE-S3, SSE-KMS and...
KMS key policies decide who can decrypt your sensitive S3 data. Use this checklist to audit encryption and key policies.
When a provider tells you to rotate everything, the hardest part is knowing what "everything" is. A rotation fire drill — practiced in advance — makes it...
In the LastPass breach, attackers stole backups from cloud storage using credentials taken from an engineer's home computer. Backups need their own...
Amazon Security Lake centralizes and normalizes security logs from AWS and other sources into OCSF format in your own S3 buckets. Here is how to set it up.
Use this checklist to plan which data goes into Amazon Security Lake and how long you keep it.
Microsoft retired Basic Authentication for most Exchange Online protocols in 2022, but legacy authentication can still appear through SMTP AUTH, other...
After Basic Authentication was turned off in Exchange Online, many organizations found lingering dependencies. Use this checklist to clean up.
Azure Storage accounts can be exposed through anonymous blob access, overly permissive shared keys and SAS tokens, or public network endpoints. Here is how...