Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

How-To & Hardening

Articles in How-To & Hardening.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
AWSHow-To & Hardening

How to Migrate an EC2 Fleet to IMDSv2 Without Breaking Applications

IMDSv2 protects instance credentials from SSRF attacks, but enforcing it across a large EC2 fleet can break older applications if done carelessly. Here is a...

AWSHow-To & Hardening

IMDSv2 Enforcement Checklist With SCPs and Launch Templates

Use this checklist to make IMDSv2 mandatory across your AWS organization and keep it that way.

Entra ID & IdentityHow-To & Hardening

How to Choose Between Security Defaults and Conditional Access

Entra ID offers two ways to enforce baseline identity security: Security Defaults (free, simple) and Conditional Access (requires Entra ID P1, flexible)....

Entra ID & IdentityHow-To & Hardening

Security Defaults Rollout Checklist and User Communication Template

Use this checklist to enable Security Defaults with minimal disruption, especially for smaller organizations.

Microsoft 365How-To & Hardening

How to Inventory and Migrate Apps Off Basic Authentication in Exchange Online

Legacy (basic) authentication bypasses MFA. Even after Microsoft's retirement of basic authentication in Exchange Online, many organizations still find...

Microsoft 365How-To & Hardening

Legacy Authentication Discovery Checklist for Exchange Online

Use this checklist to find every remaining dependency on legacy authentication in Exchange Online and Microsoft 365.

AWSHow-To & Hardening

How to Replace Long-Lived AWS Access Keys With IAM Roles and Identity Center

Long-lived IAM user access keys are one of the most common causes of AWS breaches. IAM roles and IAM Identity Center provide short-lived credentials...

AWSHow-To & Hardening

How to Enforce IMDSv2 and Lock Down EC2 Instance Role Permissions

IMDSv2 protects EC2 instance credentials from server-side request forgery, the technique used in the Capital One breach. Combined with least-privilege...

AWSHow-To & Hardening

How to Set Up AWS Control Tower With Preventive and Detective Guardrails

AWS Control Tower sets up a governed multi-account environment with guard rails. Here is how to set it up and choose the right controls.

AWSHow-To & Hardening

Control Tower Guardrail Selection Checklist

Control Tower offers hundreds of controls. Use this checklist to choose a practical starting set.

AzureHow-To & Hardening

How to Replace Public RDP With Azure Bastion and Just-in-Time Access

Exposed RDP and SSH ports are among the most attacked entry points in the cloud. Azure Bastion and just-in-time (JIT) VM access let administrators reach...

Microsoft 365How-To & Hardening

How to Secure Help Desk and Support Roles in Microsoft 365

Help desk and support staff can reset passwords, change MFA methods and see user data. Here is how to scope those roles tightly in Microsoft 365 and Entra ID.

Microsoft 365How-To & Hardening

How to Use Entra ID Smart Lockout and Identity Protection Against Spraying

Entra ID includes two built-in defenses against password spraying: smart lockout and Identity Protection. Here is how to configure both.

AzureHow-To & Hardening

How to Plan a Microsoft Sentinel Deployment: Workspaces, Connectors and Costs

A good Microsoft Sentinel deployment starts with planning workspaces, data sources and costs before turning anything on. Here is the sequence Microsoft's...

AzureHow-To & Hardening

Sentinel Data Connector Priority Checklist

Data connectors determine both what Microsoft Sentinel can detect and what it costs. Use this checklist to prioritize them.

AWSHow-To & Hardening

How to Enforce S3 Block Public Access at the AWS Organization Level

Account-level S3 Block Public Access protects every bucket in an account. With AWS Organizations, you can apply it everywhere and prevent anyone from...

AWSHow-To & Hardening

S3 Public Access Audit Checklist

Use this checklist to audit S3 public access across your AWS organization.

AWSHow-To & Hardening

How to Design a Multi-Account AWS Landing Zone With Security Guardrails

A multi-account AWS landing zone separates workloads, centralizes security tools and protects logs. Here is how to design one using AWS's own reference...

AWSHow-To & Hardening

AWS Security Hub Standards Triage Checklist

AWS Security Hub can produce hundreds of failed controls on day one. This checklist helps you triage them without drowning.

Entra ID & IdentityHow-To & Hardening

How to Create and Monitor Break-Glass Emergency Access Accounts in Entra ID

Emergency access accounts — often called break-glass accounts — let you regain administrative access to Entra ID and Microsoft 365 when normal sign-in...

Entra ID & IdentityHow-To & Hardening

Identity Outage Runbook: What to Do When MFA Is Down

When your identity provider or MFA service fails, every minute of confusion costs productivity. This runbook outlines what to do.

Multi-CloudHow-To & Hardening

How to Run a Cloud Security Due Diligence Review During M&A

When you acquire a company, you acquire its cloud environments, identities and possibly its attackers. Here is how to run a cloud security due diligence...

Entra ID & IdentityHow-To & Hardening

How to Configure Token Lifetimes and Sign-In Frequency in Conditional Access

Stolen tokens let attackers bypass passwords and MFA. Conditional Access session controls limit how long tokens stay useful and when users must...

Entra ID & IdentityHow-To & Hardening

How to Plan a Passwordless Rollout With Windows Hello and Authenticator

Passwordless sign-in removes the most attacked credential and improves user experience. Here is a practical rollout plan using Windows Hello for Business,...

← NewerPage 6 of 8Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.