Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Retrospectives

Articles in Retrospectives.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
AzurePlatform Changes

Azure Sentinel Preview (Feb 2019): Microsoft Enters the Cloud SIEM Market

On February 28, 2019, Microsoft announced Azure Sentinel in preview — a cloud-native security information and event management (SIEM) service built on Azure...

AzureHow-To & Hardening

How to Plan a Microsoft Sentinel Deployment: Workspaces, Connectors and Costs

A good Microsoft Sentinel deployment starts with planning workspaces, data sources and costs before turning anything on. Here is the sequence Microsoft's...

AzureHow-To & Hardening

Sentinel Data Connector Priority Checklist

Data connectors determine both what Microsoft Sentinel can detect and what it costs. Use this checklist to prioritize them.

AzureCIO Briefings

CIO Brief: Cloud-Native SIEM vs. Legacy SIEM — The Cost and Coverage Trade-Off

The short version: In 2019, Microsoft released Sentinel, a security monitoring service that runs in the cloud. It made centralized security monitoring...

AWSPlatform Changes

S3 Block Public Access Launches (Nov 2018): The Feature That Should Have Existed Day One

In November 2018, AWS launched S3 Block Public Access, a set of four settings that override bucket policies and access control lists to prevent public...

AWSHow-To & Hardening

How to Enforce S3 Block Public Access at the AWS Organization Level

Account-level S3 Block Public Access protects every bucket in an account. With AWS Organizations, you can apply it everywhere and prevent anyone from...

AWSHow-To & Hardening

S3 Public Access Audit Checklist

Use this checklist to audit S3 public access across your AWS organization.

AWSCIO Briefings

CIO Brief: One Setting That Prevents the Most Common Cloud Breach

The short version: In 2018, AWS added a setting that prevents cloud storage from being made public at all. Turned on across an account, it stops the most...

AWSPlatform Changes

re:Invent 2018: AWS Security Hub and Control Tower Previews Change Multi-Account Security

At re:Invent in November 2018, AWS announced previews of two services that reshaped multi-account security: AWS Security Hub and AWS Control Tower.

AWSHow-To & Hardening

How to Design a Multi-Account AWS Landing Zone With Security Guardrails

A multi-account AWS landing zone separates workloads, centralizes security tools and protects logs. Here is how to design one using AWS's own reference...

AWSHow-To & Hardening

AWS Security Hub Standards Triage Checklist

AWS Security Hub can produce hundreds of failed controls on day one. This checklist helps you triage them without drowning.

AWSCIO Briefings

CIO Brief: Why One Big AWS Account Is a Security Liability

The short version: AWS recommends running your cloud as many separate accounts — one per application or environment — instead of one big account. In 2018,...

Entra ID & IdentityIncident Teardowns

The Azure AD MFA Outage of November 2018: When Sign-In Itself Goes Down

On November 19, 2018, Azure Active Directory's multi-factor authentication service suffered a major outage. For much of a working day, many users in Europe,...

Entra ID & IdentityHow-To & Hardening

How to Create and Monitor Break-Glass Emergency Access Accounts in Entra ID

Emergency access accounts — often called break-glass accounts — let you regain administrative access to Entra ID and Microsoft 365 when normal sign-in...

Entra ID & IdentityHow-To & Hardening

Identity Outage Runbook: What to Do When MFA Is Down

When your identity provider or MFA service fails, every minute of confusion costs productivity. This runbook outlines what to do.

Entra ID & IdentityCIO Briefings

CIO Brief: Planning for the Day Your Identity Provider Is Unavailable

The short version: In 2018, Microsoft's multi-factor authentication service had a major outage, and many organizations couldn't sign in to their email and...

Multi-CloudIncident Teardowns

Marriott-Starwood (Nov 2018): A Four-Year Intrusion Inherited Through Acquisition

On November 30, 2018, Marriott International announced that attackers had accessed the guest reservation database of its Starwood brands. The intrusion had...

Multi-CloudHow-To & Hardening

How to Run a Cloud Security Due Diligence Review During M&A

When you acquire a company, you acquire its cloud environments, identities and possibly its attackers. Here is how to run a cloud security due diligence...

Multi-CloudDetection & Response

Hunting for Long-Dwell Intruders in Cloud and Hybrid Environments

Marriott's attackers stayed inside Starwood's network for about four years. Long-dwell intruders are quiet by design. Hunting for them means looking for...

Multi-CloudCIO Briefings

CIO Brief: When You Buy a Company, You Buy Its Breaches

The short version: When Marriott bought Starwood in 2016, it also bought a hacker who had been inside Starwood's systems since 2014. The breach wasn't...

Entra ID & IdentityIncident Teardowns

Facebook's 'View As' Breach (Sept 2018): 50 Million Access Tokens Stolen

On September 28, 2018, Facebook announced that attackers had exploited a vulnerability in its "View As" feature to steal access tokens. Facebook initially...

Entra ID & IdentityHow-To & Hardening

How to Configure Token Lifetimes and Sign-In Frequency in Conditional Access

Stolen tokens let attackers bypass passwords and MFA. Conditional Access session controls limit how long tokens stay useful and when users must...

Entra ID & IdentityDetection & Response

Detecting Access Token Theft: Entra Sign-In Logs and Sentinel KQL

Token theft lets an attacker act as a user without their password or MFA. Detection focuses on tokens being used in ways that don't match the device and...

Entra ID & IdentityCIO Briefings

CIO Brief: Stolen Tokens Bypass Passwords and MFA — What That Means for You

The short version: In 2018, a Facebook bug let attackers steal the digital "keys" that keep users signed in, giving access to millions of accounts without...

← NewerPage 16 of 20Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.