Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Microsoft 365

Articles in Microsoft 365.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Microsoft 365How-To & Hardening

How to Use Restricted SharePoint Search and Data Access Governance Reports

Restricted SharePoint Search and data access governance reports help you control Copilot exposure while you fix oversharing. Here is how to use them.

Microsoft 365How-To & Hardening

Copilot Oversharing Remediation Checklist

Use this checklist to remediate oversharing before and during Copilot rollout.

Microsoft 365CIO Briefings

CIO Brief: Scaling Copilot Safely Beyond the Pilot

The short version: In September 2024, Microsoft expanded Copilot with new features — and new tools to fix the "oversharing" problem that stalled many...

Microsoft 365Platform Changes

The CSRB Report on Storm-0558 (Apr 2024): A 'Cascade of Security Failures' at Microsoft

On April 2, 2024, the US Cyber Safety Review Board (CSRB) published its report on the Storm-0558 intrusion, in which Chinese state actors used a stolen...

Microsoft 365How-To & Hardening

How to Hold Your Cloud Providers Accountable With Security Contract Terms

Cloud provider security failures can affect your data — but your contract often gives you little recourse. Here are security terms to negotiate or verify...

Microsoft 365How-To & Hardening

Annual Cloud Provider Security Review Checklist

Use this checklist to review each major cloud provider's security each year.

Microsoft 365CIO Briefings

CIO Brief: What the CSRB Findings Mean for Microsoft Customers

The short version: In April 2024, a US government review board concluded that a Chinese hack of Microsoft's email systems "should never have happened" and...

Microsoft 365How-To & Hardening

How to Find Forgotten Test Tenants and Over-Privileged OAuth Apps

Midnight Blizzard got into Microsoft through a forgotten test tenant and a legacy OAuth app with production access. Here is how to find similar risks in...

Microsoft 365Detection & Response

Detecting OAuth App Abuse: Defender XDR and Sentinel Hunting Queries

OAuth application abuse lets attackers access mailboxes and data with app-level permissions that bypass user MFA. These detections focus on privilege...

Microsoft 365CIO Briefings

CIO Brief: The Test Environment Nobody Remembered

The short version: In January 2024, Russian state hackers read email of Microsoft's senior leaders. They got in through an old test account that didn't...

Microsoft 365How-To & Hardening

How to Prepare SharePoint Permissions Before Turning On Copilot

Copilot surfaces any content a user can access. Before broad rollout, fix the SharePoint and OneDrive permissions that would expose sensitive data. Here is...

Microsoft 365How-To & Hardening

Copilot Readiness Checklist: Permissions, Labels and Pilot Groups

Use this checklist before expanding Microsoft 365 Copilot beyond a pilot.

Microsoft 365CIO Briefings

CIO Brief: Copilot Will Find Everything Your Users Can Access

The short version: Microsoft 365 Copilot, available since late 2023, can find and summarize anything an employee has access to — instantly. In most...

Microsoft 365Incident Teardowns

Midnight Blizzard Phishes Through Microsoft Teams (Aug 2023): External Chat as an Attack Vector

On August 2, 2023, Microsoft reported that Midnight Blizzard — the Russian state actor also known as APT29 or Nobelium, linked to SolarWinds — was using...

Microsoft 365How-To & Hardening

How to Restrict External Access and Federation in Microsoft Teams

Microsoft Teams external access lets users chat with people in other organizations. Attackers use it for phishing. Here is how to restrict it to what your...

Microsoft 365Detection & Response

Detecting Teams External Chat Phishing: Defender XDR and Sentinel Hunting Queries

Teams chat phishing arrives outside email defenses. These detections help spot suspicious external chats and their consequences.

Microsoft 365CIO Briefings

CIO Brief: Your Chat Tool Is an Email Inbox Without Spam Filters

The short version: In 2023, Russian state hackers used Microsoft Teams chat — not email — to trick people into approving login requests. Companies have...

Microsoft 365How-To & Hardening

How to Enable Expanded Audit Logging to Detect Mailbox Access

Storm-0558 was detected because a customer had detailed mailbox access logs. Here is how to make sure your Microsoft 365 audit logging captures what you'd...

Microsoft 365Detection & Response

Detecting Forged Token Mailbox Access: Defender XDR and Sentinel Hunting Queries

Forged or stolen tokens let attackers access mailboxes without normal sign-ins. Mailbox access audit events are often the only evidence.

Microsoft 365CIO Briefings

CIO Brief: Storm-0558 and Paying Extra for Security Logs

The short version: In 2023, Chinese hackers read US government email by forging digital keys in Microsoft's systems. A government agency caught it — because...

Microsoft 365Platform Changes

Microsoft Security Copilot Announced (Mar 2023): Generative AI Comes to the SOC

On March 28, 2023, Microsoft announced Microsoft Security Copilot, a generative AI assistant for security teams built on OpenAI's GPT-4 and Microsoft's...

Microsoft 365How-To & Hardening

How to Evaluate AI Assistants for Security Operations

AI assistants for security operations can speed up triage and investigation — or add cost and noise. Here is a practical way to evaluate them.

Microsoft 365How-To & Hardening

AI Security Tool Pilot Checklist: Data, Access and ROI

Use this checklist before and during a pilot of an AI security assistant.

Microsoft 365CIO Briefings

CIO Brief: AI in the SOC — Productivity Gains vs. Real Risks

The short version: In 2023, Microsoft launched Security Copilot, an AI assistant for security teams. Many vendors followed. AI can make security analysts...

← NewerPage 2 of 6Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.