Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Microsoft 365

Articles in Microsoft 365.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Microsoft 365Platform Changes

Exchange Online Basic Auth Turned Off (Oct 2022): The End of an Era

Beginning October 1, 2022, Microsoft started permanently disabling Basic Authentication in Exchange Online for Exchange ActiveSync, POP, IMAP, Remote...

Microsoft 365How-To & Hardening

How to Verify Legacy Authentication Is Fully Blocked in Your Tenant

Microsoft retired Basic Authentication for most Exchange Online protocols in 2022, but legacy authentication can still appear through SMTP AUTH, other...

Microsoft 365How-To & Hardening

Post-Basic-Auth Cleanup Checklist: SMTP AUTH, Service Accounts and Scripts

After Basic Authentication was turned off in Exchange Online, many organizations found lingering dependencies. Use this checklist to clean up.

Microsoft 365CIO Briefings

CIO Brief: What Broke When Basic Auth Died — and What Got Safer

The short version: In October 2022, Microsoft permanently turned off older sign-in methods for its cloud email after a three-year warning. Some printers,...

Microsoft 365Incident Teardowns

ProxyNotShell (Sept 2022): The Third Major Exchange Zero-Day Wave

On September 29, 2022, Microsoft confirmed two zero-day vulnerabilities in on-premises Microsoft Exchange Server being exploited in limited, targeted...

Microsoft 365How-To & Hardening

How to Decommission the Last Exchange Server in a Hybrid Deployment

Many organizations moved all mailboxes to Exchange Online but kept one Exchange server for recipient management. Microsoft now supports removing it in many...

Microsoft 365Detection & Response

Detecting Exchange Zero-Day: Defender XDR and Sentinel Hunting Queries

Even after patching, exploited Exchange servers may still be compromised. These detections focus on post-exploitation behaviors common to ProxyNotShell and...

Microsoft 365CIO Briefings

CIO Brief: When to Finally Leave On-Prem Exchange

The short version: In late 2022, a third major wave of attacks hit company-run Microsoft Exchange email servers. Microsoft took about six weeks to release...

Microsoft 365Incident Teardowns

Adversary-in-the-Middle Phishing Hits 10,000 Organizations (July 2022): MFA Bypassed at Scale

On July 12, 2022, Microsoft published research on a large-scale adversary-in-the-middle (AiTM) phishing campaign that had targeted more than 10,000...

Microsoft 365How-To & Hardening

How to Defeat AiTM Phishing With Compliant-Device and Phishing-Resistant MFA Policies

Adversary-in-the-middle phishing steals session cookies after users complete MFA. Two controls stop it: phishing-resistant authentication and...

Microsoft 365Detection & Response

Detecting AiTM Session Cookie Theft: Defender XDR and Sentinel Hunting Queries

AiTM phishing produces a valid session from an attacker's infrastructure. Detection focuses on session anomalies and the business email compromise that...

Microsoft 365CIO Briefings

CIO Brief: Why Standard MFA No Longer Stops Phishing

The short version: In 2022, Microsoft reported a phishing campaign that hit more than 10,000 organizations and got past multi-factor authentication by...

Microsoft 365Incident Teardowns

Follina (May–June 2022): Office Documents That Ran Code Without Macros

In late May 2022, researchers identified a malicious Word document that executed code without macros. The vulnerability it exploited, nicknamed Follina...

Microsoft 365How-To & Hardening

How to Configure Attack Surface Reduction Rules in Defender for Endpoint

Attack surface reduction (ASR) rules in Microsoft Defender for Endpoint block behaviors commonly used by malware — such as Office apps launching child...

Microsoft 365Detection & Response

Detecting Office Document Exploitation: Defender XDR and Sentinel Hunting Queries

Malicious Office documents remain a top initial access method. Detecting Office applications launching unusual processes catches many techniques, from...

Microsoft 365CIO Briefings

CIO Brief: Attackers Adapt When You Block Macros

The short version: For years, the main defense against malicious Office documents was blocking macros. In 2022, attackers used a new flaw, Follina, to run...

Microsoft 365Incident Teardowns

ProxyShell (Aug 2021): Exchange Server Exploited Again

In August 2021, details emerged of ProxyShell, a chain of three vulnerabilities in on-premises Microsoft Exchange Server. Security researcher Orange Tsai...

Microsoft 365How-To & Hardening

How to Build an Emergency Patching Process for Internet-Facing Servers

When a critical vulnerability is exploited in the wild, normal monthly patching is too slow. Here is how to build an emergency patching process for...

Microsoft 365Detection & Response

Detecting Exchange Server RCE: Defender XDR and Sentinel Hunting Queries

Remote code execution against Exchange servers leaves traces in IIS logs, process activity and the file system. These detections complement patching.

Microsoft 365CIO Briefings

CIO Brief: Repeated Exchange Zero-Days — A Signal to Move to the Cloud

The short version: In 2021, a second wave of attacks hit company-run Microsoft Exchange email servers, months after the first. Patches had been available...

Microsoft 365Incident Teardowns

38 Million Records Exposed by Power Apps Portals (Aug 2021): Low-Code, High Risk

In August 2021, UpGuard researchers disclosed that about 38 million records were exposed through Microsoft Power Apps portals belonging to 47 organizations,...

Microsoft 365How-To & Hardening

How to Govern Power Platform Environments, Portals and Data Policies

Power Platform lets anyone build apps, flows and now AI agents. Without governance, data can leak through connectors, public portals or overshared apps....

Microsoft 365Detection & Response

Detecting Low-Code Data Exposure: Defender XDR and Sentinel Hunting Queries

Low-code apps and portals can expose data without anyone noticing. These detections help surface risky configurations and unusual data access in Power Platform.

Microsoft 365CIO Briefings

CIO Brief: Citizen Developers Need Guardrails

The short version: In 2021, about 38 million records — including vaccination data and Social Security numbers — were exposed through websites built with...

← NewerPage 3 of 6Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.