Blog & Guides
Practical cybersecurity articles, step-by-step guides, and quick-reference cheat sheets — from Active Directory hardening to Microsoft 365 and zero trust. Written by someone who's done the work. No hype, no fluff.
2 results for “phishing-resistant mfa” · Clear
Conditional Access Baseline Policies Every Microsoft 365 Tenant Needs in 2026
Every Microsoft 365 tenant should run a baseline of roughly eight to ten Conditional Access policies — block legacy authentication, require MFA for all users, phishing-resistant MFA for admins, compliant or managed devices, block device code flow, sign-in and user-risk policies, session controls, guest MFA, and a break-glass exclusion group — deployed in report-only first, piloted with a ring group, then enforced. This guide gives the named set, the safe rollout order, the P1/P2 licensing reality, the enforcement changes that landed in June and July 2026, and the production gotchas that lock teams out of their own tenant.
Ghost Phishing: How the EvilTokens Campaign Hides in the Browser to Hijack Microsoft 365 Accounts
A new "ghost phishing" wave from the EvilTokens kit is slipping past email security by keeping its payload AES-encrypted until it renders in the victim's browser, then using Microsoft device-code phishing to take over Microsoft 365 accounts without ever stealing a password. This guide breaks down how the technique works, why traditional URL and email controls miss it, who is being hit, and the concrete detection and hardening steps to defend your tenant.