Microsoft Ignite 2018: Passwordless Sign-In and Microsoft Threat Protection Arrive
At Microsoft Ignite in September 2018, Microsoft made identity and threat protection central themes. Two announcements stood out: passwordless sign-in for...
Insights
Articles in Retrospectives.
At Microsoft Ignite in September 2018, Microsoft made identity and threat protection central themes. Two announcements stood out: passwordless sign-in for...
Passwordless sign-in removes the most attacked credential and improves user experience. Here is a practical rollout plan using Windows Hello for Business,...
Use this checklist to check whether your organization is ready to roll out passwordless sign-in.
The short version: In 2018, Microsoft started pushing businesses toward signing in without passwords, using phones, fingerprints and security keys instead....
On August 1, 2018, Reddit disclosed that an attacker had accessed some of its systems, including an old database backup with user data from 2007 and email...
SMS and voice codes are the weakest forms of MFA. Here is how to migrate Microsoft 365 users to the Microsoft Authenticator app and, for higher-risk users,...
SMS codes can be intercepted through SIM swaps and phishing. You often can't see the interception itself, but you can detect what happens next: a sign-in...
The short version: In 2018, Reddit was breached even though its employees used two-factor authentication — the attacker intercepted text message codes. All...
In June 2018, Microsoft announced a public preview of Azure AD Password Protection, bringing its banned-password technology to customers' cloud accounts and...
Microsoft Entra Password Protection blocks weak and commonly attacked passwords. In the cloud it works automatically for Entra ID accounts; extending it to...
A custom banned password list blocks the terms attackers are most likely to try against your organization. Use this checklist to build one that works.
The short version: Most password rules produce predictable passwords like "Summer2018!", which attackers try first. In 2018, Microsoft introduced a way to...
On May 25, 2018, the European Union's General Data Protection Regulation (GDPR) became enforceable. It applied to any organization processing personal data...
Privacy laws such as GDPR require you to know where personal data lives and to control it. In Microsoft 365, Microsoft Purview provides the tools. Here is a...
A data inventory is the foundation of GDPR compliance and of any serious data protection program. Use this checklist to build one for Microsoft 365.
The short version: GDPR, enforceable since 2018, made organizations legally responsible for knowing where personal data lives and protecting it — with fines...
In March 2018, reporting by The Observer and The New York Times revealed that the political consultancy Cambridge Analytica had obtained data on up to 87...
By default, Microsoft 365 users can grant third-party apps access to their data. Malicious apps use that to steal mail and files without ever needing a...
OAuth apps with excessive permissions can read mail and files across your tenant without a password. Detecting risky consent grants is a core identity...
The short version: Cambridge Analytica obtained data on tens of millions of Facebook users through an app most of them never used. The same mechanism — apps...
In March 2018, the US Department of Justice indicted nine Iranian nationals associated with the Mabna Institute for a long-running hacking campaign against...
Password spraying succeeds most often through legacy authentication protocols that cannot perform MFA. Blocking legacy authentication closes that door. Here...
Password spraying tries a small number of common passwords against many accounts, staying below lockout thresholds. Detecting it requires looking across...
The short version: In 2018, the US indicted Iranian hackers who stole large volumes of data by trying common passwords against thousands of accounts. It is...