Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Microsoft 365

Articles in Microsoft 365.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Microsoft 365Platform Changes

Microsoft Ignite 2019: Insider Risk Management and the Microsoft Defender Rebrand

At Microsoft Ignite in November 2019, Microsoft announced Insider Risk Management in preview as part of Microsoft 365 compliance, alongside updates across...

Microsoft 365How-To & Hardening

How to Pilot Microsoft Purview Insider Risk Management

Microsoft Purview Insider Risk Management can detect data theft and leaks by insiders, but it needs careful setup and governance. Here is how to run a pilot.

Microsoft 365How-To & Hardening

Insider Risk Policy Checklist: Privacy, HR and Legal Sign-Off

Insider risk monitoring touches employee privacy. This checklist helps make sure policies have the right sign-off before you enable them.

Microsoft 365CIO Briefings

CIO Brief: Insider Risk Without Spying on Employees

The short version: In 2019, Microsoft introduced tools to detect when employees might be taking or leaking company data — for example, downloading large...

Microsoft 365Platform Changes

Microsoft Announces Basic Auth Retirement for Exchange Online (Sept 2019)

In September 2019, Microsoft announced that it would turn off Basic Authentication in Exchange Online for Exchange ActiveSync, POP, IMAP, Exchange Web...

Microsoft 365How-To & Hardening

How to Inventory and Migrate Apps Off Basic Authentication in Exchange Online

Legacy (basic) authentication bypasses MFA. Even after Microsoft's retirement of basic authentication in Exchange Online, many organizations still find...

Microsoft 365How-To & Hardening

Legacy Authentication Discovery Checklist for Exchange Online

Use this checklist to find every remaining dependency on legacy authentication in Exchange Online and Microsoft 365.

Microsoft 365CIO Briefings

CIO Brief: Legacy Protocols Are a Legacy Risk

The short version: In 2019, Microsoft announced it would switch off older sign-in methods for its cloud email because they couldn't use multi-factor...

Microsoft 365Incident Teardowns

Outlook.com Support Agent Account Compromised (Apr 2019): The Help Desk Attack Surface

In April 2019, Microsoft notified some users of its consumer email services — Outlook.com, Hotmail and MSN — that a support agent's credentials had been...

Microsoft 365How-To & Hardening

How to Secure Help Desk and Support Roles in Microsoft 365

Help desk and support staff can reset passwords, change MFA methods and see user data. Here is how to scope those roles tightly in Microsoft 365 and Entra ID.

Microsoft 365Detection & Response

Detecting Help Desk Account Compromise: Defender XDR and Sentinel Hunting Queries

A compromised help desk account — or a manipulated help desk agent — can reset credentials across your organization. Detecting unusual support activity...

Microsoft 365CIO Briefings

CIO Brief: Your Help Desk Is a Target — Protecting Support Workflows

The short version: In 2019, attackers got into Microsoft's consumer email support systems by compromising a single support agent's account. Help desks are...

Microsoft 365Incident Teardowns

Citrix Breached via Password Spraying (Mar 2019): Weak Passwords at Enterprise Scale

In March 2019, Citrix disclosed that the FBI had informed it of a breach of its internal network. The FBI's assessment, according to Citrix, was that...

Microsoft 365How-To & Hardening

How to Use Entra ID Smart Lockout and Identity Protection Against Spraying

Entra ID includes two built-in defenses against password spraying: smart lockout and Identity Protection. Here is how to configure both.

Microsoft 365Detection & Response

Detecting Password Spray Attacks: Defender XDR and Sentinel Hunting Queries

Password spray attacks distribute attempts to avoid detection. Combining Entra ID's built-in detections with your own queries gives you the best chance of...

Microsoft 365CIO Briefings

CIO Brief: Your Security Vendor Can Be Breached — Plan for It

The short version: In 2019, Citrix — a company that sells remote access technology to enterprises — was breached, likely through attackers trying common...

Microsoft 365Platform Changes

GDPR Enforcement Begins (May 2018): What It Changed for Microsoft 365 Data Governance

On May 25, 2018, the European Union's General Data Protection Regulation (GDPR) became enforceable. It applied to any organization processing personal data...

Microsoft 365How-To & Hardening

How to Use Microsoft Purview to Find and Govern Personal Data

Privacy laws such as GDPR require you to know where personal data lives and to control it. In Microsoft 365, Microsoft Purview provides the tools. Here is a...

Microsoft 365How-To & Hardening

GDPR Data Inventory Checklist for Microsoft 365

A data inventory is the foundation of GDPR compliance and of any serious data protection program. Use this checklist to build one for Microsoft 365.

Microsoft 365CIO Briefings

CIO Brief: GDPR Fines and Your Cloud Data Map

The short version: GDPR, enforceable since 2018, made organizations legally responsible for knowing where personal data lives and protecting it — with fines...

Microsoft 365Incident Teardowns

Cambridge Analytica (Mar 2018): What App Permissions Mean for Your Microsoft 365 Tenant

In March 2018, reporting by The Observer and The New York Times revealed that the political consultancy Cambridge Analytica had obtained data on up to 87...

Microsoft 365How-To & Hardening

How to Lock Down User Consent to Third-Party Apps in Entra ID

By default, Microsoft 365 users can grant third-party apps access to their data. Malicious apps use that to steal mail and files without ever needing a...

Microsoft 365Detection & Response

Detecting OAuth App Over-Permission: Defender XDR and Sentinel Hunting Queries

OAuth apps with excessive permissions can read mail and files across your tenant without a password. Detecting risky consent grants is a core identity...

Microsoft 365CIO Briefings

CIO Brief: Who Approved That App? Governing OAuth Permissions

The short version: Cambridge Analytica obtained data on tens of millions of Facebook users through an app most of them never used. The same mechanism — apps...

← NewerPage 5 of 6Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.