Blog & Guides
Practical cybersecurity articles, step-by-step guides, and quick-reference cheat sheets — from Active Directory hardening to Microsoft 365 and zero trust. Written by someone who's done the work. No hype, no fluff.
12 results for “microsoft 365” · Clear
The Microsoft 365 2026 Deprecation Deadline Tracker
Every material Microsoft 365, Exchange Online and Entra ID deprecation landing in 2026 — EWS, SMTP AUTH basic auth, Identity Protection risk policies, Azure ACS and more — in date order, with what breaks and the one fix that keeps you ahead of each deadline.
Anatomy of a Device Code Phishing Email: A Real Investigation
A phishing email with no malware, no cloned login page and a clean URL reputation would still have handed an attacker a fully authenticated Microsoft 365 session — without ever seeing the password, and without the victim's MFA slowing them down. This is a captured, screen-by-screen walkthrough of a device code phishing email (the Cloudflare hold-to-continue gate, the copied Microsoft device code, the genuine sign-in page) plus the detection, hardening, and full mitigating and compensating controls to stop it.
Securing AI Agent Identities in Microsoft Entra: Governance, Conditional Access and Least Privilege in 2026
Copilot and low-code agents now get their own identities in Microsoft Entra. This guide covers Entra Agent ID — the sponsor/owner model, blueprints, Conditional Access and ID Protection for agents, least-privilege connector governance, and the lifecycle controls that stop agent sprawl — in the order a security team should apply them.
Securing Microsoft 365 Copilot: The Oversharing Remediation Playbook
Copilot inherits your permissions — including the broken ones. A practitioner's classify-restrict-monitor sequence for finding and fixing data oversharing before you enable AI across the tenant.
Govern Microsoft 365 Copilot with Purview DSPM: Stop Oversharing Before You Deploy
Microsoft 365 Copilot governance means controlling what Copilot can surface, not just who can use it. Copilot does not break your permissions — it exposes them, turning a decade of overshared SharePoint sites into plain-English answers. This guide walks the actual Purview and SharePoint controls that fix it, in the order a security team should apply them: DSPM for AI to find overshared data, sensitivity labels plus DLP to stop Copilot processing it, and SharePoint Restricted Content Discovery to keep high-risk sites out of Copilot answers. Licence and GA/preview status validated against Microsoft Learn, August 2026.
Conditional Access Baseline Policies Every Microsoft 365 Tenant Needs in 2026
Every Microsoft 365 tenant should run a baseline of roughly eight to ten Conditional Access policies — block legacy authentication, require MFA for all users, phishing-resistant MFA for admins, compliant or managed devices, block device code flow, sign-in and user-risk policies, session controls, guest MFA, and a break-glass exclusion group — deployed in report-only first, piloted with a ring group, then enforced. This guide gives the named set, the safe rollout order, the P1/P2 licensing reality, the enforcement changes that landed in June and July 2026, and the production gotchas that lock teams out of their own tenant.
PowerShell for Microsoft 365 Administration: Why the GUI Isn't Enough in 2026
The Microsoft 365 admin center is fine for one user, one mailbox, one policy. It falls apart at fifty — and it cannot do half of what the platform actually supports. PowerShell is where bulk operations, security auditing, incident response and automation live, and after the 2025 retirement of the MSOnline and AzureAD modules, the tooling map has been redrawn. Here is why PowerShell administration still matters for the Microsoft 365 and security suites, which modules to use now, what the portals cannot do, and how to automate without leaving credentials lying around.
Which Microsoft 365 Plan Do I Actually Need for My Business? Basic vs Standard vs Premium in 2026
Microsoft 365 Business Basic covers email, Teams and web apps; Business Standard adds the desktop Office suite; Business Premium adds the security and device-management layer most small businesses are missing — Entra ID P1, Intune, Defender for Business and Defender for Office 365. With the July 2026 price increase now in effect and new capabilities rolling into every tier, here is what each plan actually includes, what it costs, and a decision framework for picking the right one — including when to skip the Business plans entirely and go enterprise.
Ghost Phishing: How the EvilTokens Campaign Hides in the Browser to Hijack Microsoft 365 Accounts
A new "ghost phishing" wave from the EvilTokens kit is slipping past email security by keeping its payload AES-encrypted until it renders in the victim's browser, then using Microsoft device-code phishing to take over Microsoft 365 accounts without ever stealing a password. This guide breaks down how the technique works, why traditional URL and email controls miss it, who is being hit, and the concrete detection and hardening steps to defend your tenant.