Microsoft Azure Security Posts

Discover the latest insights, best practices, and security research related to Microsoft Azure cloud platform.

Search Azure Posts

Filter Posts

Posts

SignToolGUI 2.1.0.0 Released 🎉

by Michael Morten Sonne
azure azure-adentra-id c code-repository code-sign

Last Updated on December 16, 2025 by Michael Morten Sonne Introduction I’m happy to announce the release of… The post SignToolGUI 2.1.0.0 Rel...

Read Article →

Mastering Certificate Rotation in Entra ID

by Tim Groothuis
application-registration azure security entra-id devops

Recently I posted a blog about Entra ID Application Registration secret management, in which I explained how to rotate Application Registration sec...

Read Article →

Real-time protection for ‘AI Agents’

by Derk van der Woude
azure entra-id security defender identity

Microsoft Copilot Studio is a graphical, low-code/no‑code (LCNC) platform to build AI agents to support human tasks.Microsoft Copilot Studio — AI A...

Read Article →

Finding Seamless SSO usage

by Nathan McNulty
azure entra-id

A brief history Seamless Single Sign On was first introduced in late 2016 and provided a way for users to authenticate to Entra ID (Azure AD at the...

Read Article →

Microsoft Pushes European Sovereign Solutions

by Tony Redmond
microsoft-365 azure-local exchange-server microsoft-365-local sharepoint-server

On June 16, Microsoft announced European sovereign solutions, including a new offering called Microsoft 365 Local that has nothing to do with Micro...

Read Article →

Hunting Through APIs

by Bert-Jan Pals
azure security defender

In today’s blog, we’re diving into the world of hunting through APIs. In the blog, the advantages, limitations, and scopes of the Graph...

Read Article →

Time for a new lab enviroment – Part 1

by Michael Morten Sonne
azure-local community home-lab lab microsoft

Last Updated on May 4, 2025 by Michael Morten Sonne Introduction 🧑‍💻 I’m excited to share that I’m… The post Time for a new lab envirom...

Read Article →

Creating a CCP connector: Part 4

by Tim Groothuis
data-connectors microsoft-sentinel sentinel security azure

Hi there! Welcome (back) to my blog series about building a connector using Microsoft’s Sentinel Codeless Connector Platform (CCP). In the previous...

Read Article →

Creating a CCP connector: Part 3

by Tim Groothuis
security sentinel data-connectors microsoft-sentinel azure

Hey there, glad to see you’re still with me on this journey! If this is your starting point, you might want to considered reading the previous part...

Read Article →

Creating a CCP connector: Part 2

by Tim Groothuis
security sentinel azure microsoft-sentinel data-connectors

Hey there, welcome back! In this blog series I’ll show you how you can make your own Sentinel Codeless Connector Platform (CCP) connector. If you h...

Read Article →

Creating a CCP connector: Part 1

by Tim Groothuis
azure microsoft-sentinel sentinel data-connectors security

Hey there! In this blog series I’ll be going to walk you through a step by step guide on how to build your own Codeless Connector Platform (CCP) da...

Read Article →

Signtool GUI  – v. 1.4.0.0 is out!

by Michael Morten Sonne
azure c code-repository code-sign cool-tools

Last Updated on March 17, 2025 by Michael Morten Sonne Introduction I’m thrilled to announce the latest release… The post Signtool GUI ...

Read Article →

Microsoft Graph PowerShell SDK Runs into Choppy Waters

by Tony Redmond
microsoft-graph azure-automation bugs-in-microsoft-graph-powershell-sdk graph-sdk-v226 microsoft-graph-powershell-sdk

A bunch of problems with V2.26 of the Microsoft Graph PowerShell SDK V2.26 make the software unusable. Not only did Microsoft do a horrible job of ...

Read Article →

How to Index and Search SharePoint Online Custom Columns

by Tony Redmond
sharepoint-online crawled-property custom-columns index-and-search-sharepoint-online-custom-columns managed-property

SharePoint Online is basically a big Azure SQL application. Custom columns for sites and libraries enhance metadata and are even better if they're ...

Read Article →

Super Advanced Auditing

by Nathan McNulty
azure

This solution provides automation that ensures all available auditable events are enabled for all users in a tenant. By default, not all events are...

Read Article →

KQL Sources - 2025 Update

by Bert-Jan Pals
azure entra-id security intune sentinel

What started as a single blog is now becoming a yearly trend. More and more KQL related repositories are created, not only with a focus on security...

Read Article →

Announcing the Netskope CCP connector!

by Tim Groothuis
azure security netskope sentinel microsoft-sentinel

Over the past couple of weeks I’ve been working in close collaboration with the Netskope team to build and design a new Sentinel data connector for...

Read Article →

MSEM | OT Security Initiative

by Derk van der Woude
azure security defender intune

From global tensions on nation-state level to cybercriminals and script-kiddies, cybersecurity for OT (Operational Technology) becomes more and mor...

Read Article →

UAL = Unaligned Activity Logs

by Bert-Jan Pals
azure entra-id defender sentinel cloud

The unified audit log is a centralized repository for M365 user and admin activities. The activities originate from different applications, such as...

Read Article →

How to Force Users to Sign in Weekly

by Tony Redmond
administration entra-id revoke-access-to-user-account revoke-mgusersigninsession schedule-reauthentication-for-user-account

A recent question asked how to force users to reauthenticate at 7AM every Monday. The solution seems to revoke access for user accounts. This artic...

Read Article →

Hardening Entra ID

by Truls Dahlsveen
azure entra-id

This is an update to a previous article I wrote on hardening Azure Active Directory. The idea of this update is to provide a table of default setti...

Read Article →

Azug @ Noest

by Robbe Van den Daele
azure entra-id identity

At a recent community event, I presented a deep dive into various authentication flows in Entra Id, showcasing how to retrieve an ARC server from a...

Read Article →

Detect Impact MFA Enforcement

by Morten Knudsen
azure entra-id identity microsoft-graph microsoft-security

You may have noticed that Microsoft will enforce MFA requirement per October 15, 2024 for Azure/Entra/Intune. If this is new ... Read more

Read Article →

Comparing Microsoft Cloud Email Services

by Tony Redmond
azure exchange-online microsoft-365 ecs email-collaboration-service

HVE and ECS are two competing Microsoft Cloud Email Services. At least, they seem to compete. In reality, HVE and ECS serve different target audien...

Read Article →

Sentinel & SOAR: Part 4 - Error handling

by Tim Groothuis
soar security sentinel microsoft-sentinel azure

IntroductionHello there, welcome back to part 4 of my Sentinel & SOAR series! If you’re new to this series you might want to check out any earl...

Read Article →

0x80072f8f : A BitLocker Odyssey

by rudyooms
intune 2147954575 azure bitlocker intune

This time, a simple blog about a BitLocker escrow error (0x80072f8f )that started happening (all of a sudden) on multiple devices when you were try...

Read Article →

Secure your Azure Management portal

by Michael Morten Sonne
entra-id identity security

Last Updated on June 25, 2023 by Michael Morten Sonne How secure your Azure Management Portal?. By default,… The post Secure your Azure Manag...

Read Article →

Microsoft icons

by Jan Bakker
knowledgebase

Check out this article via web browser: Microsoft icons That’s the post for today. Just a bunch of sources with icons from Microsoft 365, Azu...

Read Article →

Master Azure Logging in depth

by Morten Knudsen
ama azure azure-arc azure-data-collection-rules azure-data-ingestion-pipeline

I am really passioned about the logging capabilities in M365 Defender and Azure with the power to bring data back from cli...

Read Article →

Understanding Azure Data Collection Endpoint

by Morten Knudsen
ama azure azure-arc azure-data-collection-rules azure-data-ingestion-pipeline

Azure Data Collection Endpoint (DCE) provide a connection for certain data sources of Azure Monitor. This article gives you an ... Read more

Read Article →

Choosing a FIDO2 Security Key

by Eric Woodruff
fido2 passwordless

Choosing a FIDO2 Security Key As I’ve been keeping up with my FIDO2 Security Key roundup, which you can find here, Azure AD: FIDO2 Security Key Rou...

Read Article →

Night of the Autopilot of the Dawn of the Temporary Access Pass of the MFA of the Return of the RebootRequired of the WUFB of the Attack of the Evil, Mutant, Hellbound, Flesh-Eating SSO Zombified Living Conditional Access, Part 2: In Azure 2-D

by rudyooms
autopilot entra-id intune privileged-access-workstation uncategorized

After a nice talk with Yannick Van Landeghem, who made me aware of a “possible” security gap when using a Temporary Access Pass (TAP), I decided to...

Read Article →

Kusto Gym

by Gianni Castaldi
kusto-knight

Welcome to the Kusto Gym, On your road to become a Kusto Knight, there are some exercises to put the theory into action. Where do we store the data...

Read Article →

Self Service in Microsoft 365

by Jan Bakker
entra-id delegation groups it-staff microsoft-365

Check out this article via web browser: Self Service in Microsoft 365 One of the great things about Azure Active Directory is the capability of sel...

Read Article →

Azure AD Identity Protection deep dive

by Kenneth Van Surksum
entra-id conditional-access identity-protection security identity

One of the advantages of Microsoft having many customers using its services is that Microsoft can leverage data from those customers and apply some...

Read Article →

Secure your Azure Management portal

by Jan Bakker
security administrators azure manangement portal

Check out this article via web browser: Secure your Azure Management portal Today a quick tip to secure your Azure Management Portal. By default, t...

Read Article →