Detecting Remote Access Without MFA: Sentinel and GuardDuty Detections
Remote access without MFA is a top ransomware entry point. These detections look for single-factor access and the activity that typically follows.
Insights
News, breach teardowns, how-to guides, detections and CIO briefings for Microsoft 365, Entra ID, Azure, AWS and AI agents.
Remote access without MFA is a top ransomware entry point. These detections look for single-factor access and the activity that typically follows.
The short version: In February 2024, ransomware shut down Change Healthcare, disrupting pharmacies and medical billing across the US for weeks. The...
Midnight Blizzard got into Microsoft through a forgotten test tenant and a legacy OAuth app with production access. Here is how to find similar risks in...
OAuth application abuse lets attackers access mailboxes and data with app-level permissions that bypass user MFA. These detections focus on privilege...
The short version: In January 2024, Russian state hackers read email of Microsoft's senior leaders. They got in through an old test account that didn't...
On November 2, 2023, Microsoft announced the Secure Future Initiative (SFI), a company-wide security commitment following a series of high-profile...
Microsoft automatically creates Conditional Access policies in many tenants. Here is how to review them, customize them safely and make sure they fit with...
Use this checklist to review your Conditional Access policies.
The short version: In November 2023, Microsoft announced a major security push — the Secure Future Initiative — and began automatically adding security...
Copilot surfaces any content a user can access. Before broad rollout, fix the SharePoint and OneDrive permissions that would expose sensitive data. Here is...
Use this checklist before expanding Microsoft 365 Copilot beyond a pilot.
The short version: Microsoft 365 Copilot, available since late 2023, can find and summarize anything an employee has access to — instantly. In most...
In October 2023, Okta disclosed that an attacker had used stolen credentials to access its customer support case management system and view files uploaded...
HAR files shared with support teams can contain live session tokens. Token protection and device-bound sessions limit what a stolen token can do. Here is...
Session tokens taken from HAR files, infostealer logs or phishing proxies are used to access accounts without signing in. Detection focuses on session reuse...
The short version: In 2023, attackers broke into Okta's customer support system and stole login sessions from files customers had uploaded for...
SAS tokens grant time-limited access to Azure Storage — but poorly scoped tokens can expose entire accounts for years. Here is how to govern them and remove...
Overly permissive or leaked SAS tokens provide direct access to Azure Storage. These detections help find token exposure and misuse.
The short version: In 2023, Microsoft's own AI researchers accidentally exposed 38 terabytes of internal data — including passwords and private messages —...
The help desk is now a primary target for social engineering. Here is how to harden identity verification and password/MFA resets.
Help desk social engineering usually ends with a password or MFA reset followed by an attacker sign-in. These detections connect the two.
The short version: In 2023, a phone call to MGM's IT help desk reportedly led to a ransomware attack that shut down casinos and hotels for days and cost...
On August 2, 2023, Microsoft reported that Midnight Blizzard — the Russian state actor also known as APT29 or Nobelium, linked to SolarWinds — was using...
Microsoft Teams external access lets users chat with people in other organizations. Attackers use it for phishing. Here is how to restrict it to what your...