AWS Control Tower Goes GA (June 2019): Guardrails for Multi-Account AWS
In June 2019, AWS Control Tower became generally available. It automated the creation of a secure multi-account AWS environment — a landing zone — with...
Insights
News, breach teardowns, how-to guides, detections and CIO briefings for Microsoft 365, Entra ID, Azure, AWS and AI agents.
In June 2019, AWS Control Tower became generally available. It automated the creation of a secure multi-account AWS environment — a landing zone — with...
AWS Control Tower sets up a governed multi-account environment with guard rails. Here is how to set it up and choose the right controls.
Control Tower offers hundreds of controls. Use this checklist to choose a practical starting set.
The short version: AWS Control Tower, released in 2019, sets up your AWS cloud as a well-organized group of accounts with security rules built in. It is the...
In May 2019, Microsoft patched CVE-2019-0708, a critical vulnerability in Remote Desktop Services that became known as BlueKeep. It affected older Windows...
Exposed RDP and SSH ports are among the most attacked entry points in the cloud. Azure Bastion and just-in-time (JIT) VM access let administrators reach...
Even with patches, exposed RDP invites brute force, credential stuffing and exploitation. Detecting both the exposure and attacks against it is essential...
The short version: In 2019, Microsoft warned about BlueKeep, a flaw that could let attackers take over older Windows computers through remote desktop...
In April 2019, Microsoft notified some users of its consumer email services — Outlook.com, Hotmail and MSN — that a support agent's credentials had been...
Help desk and support staff can reset passwords, change MFA methods and see user data. Here is how to scope those roles tightly in Microsoft 365 and Entra ID.
A compromised help desk account — or a manipulated help desk agent — can reset credentials across your organization. Detecting unusual support activity...
The short version: In 2019, attackers got into Microsoft's consumer email support systems by compromising a single support agent's account. Help desks are...
In March 2019, Citrix disclosed that the FBI had informed it of a breach of its internal network. The FBI's assessment, according to Citrix, was that...
Entra ID includes two built-in defenses against password spraying: smart lockout and Identity Protection. Here is how to configure both.
Password spray attacks distribute attempts to avoid detection. Combining Entra ID's built-in detections with your own queries gives you the best chance of...
The short version: In 2019, Citrix — a company that sells remote access technology to enterprises — was breached, likely through attackers trying common...
On February 28, 2019, Microsoft announced Azure Sentinel in preview — a cloud-native security information and event management (SIEM) service built on Azure...
A good Microsoft Sentinel deployment starts with planning workspaces, data sources and costs before turning anything on. Here is the sequence Microsoft's...
Data connectors determine both what Microsoft Sentinel can detect and what it costs. Use this checklist to prioritize them.
The short version: In 2019, Microsoft released Sentinel, a security monitoring service that runs in the cloud. It made centralized security monitoring...
In November 2018, AWS launched S3 Block Public Access, a set of four settings that override bucket policies and access control lists to prevent public...
Account-level S3 Block Public Access protects every bucket in an account. With AWS Organizations, you can apply it everywhere and prevent anyone from...
Use this checklist to audit S3 public access across your AWS organization.
The short version: In 2018, AWS added a setting that prevents cloud storage from being made public at all. Turned on across an account, it stops the most...