Identity Security
Lessons from the field. Always landing on my feet.
Microsoft Security Fall 2026: Five Changes to Prepare For
Microsoftβs fall security updates change several assumptions that are easy to leave buried in an old runbook: what a Security Administrator can do during an incident, whether Sentinel automation needs Security Copilot capacity, which risk-policy β¦
Entra SSPR and Passkey Readiness for Microsoft-Provided SMS/Voice Delivery Retirement
Microsoft is advancing three related parts of the Entra authentication and recovery experience between now and next March: On September 1, 2026, users enabled for SMS or voice begin moving into the Microsoft-managed passkey Registration Campaign. β¦
From Authorization to Action: Operationalizing CISA's Microsoft Cloud Logs Playbook in Sentinel
CISA released the Microsoft Expanded Cloud Logs Implementation Playbook on January 15, 2025. Its implementation guidance remains a practical baseline for deciding which Microsoft cloud audit signals belong in a defensible logging program. That is β¦
Block Device Code Phishing in Entra Without Breaking Legit Workflows
Device code phishing is nasty because the user does not hand over a password. They hand over a session. The lure sends the victim to a legitimate Microsoft device sign-in page. The victim enters a short code. Entra ID issues tokens to the attackerβs β¦
Detecting Infostealer Session Hijacking with Microsoft Sentinel
Nearly 70% of incidents in the Americas now begin with stolen or misused accounts. Infostealers are the engine behind that number β families like Lumma, RedLine, and Vidar export browser cookies and session tokens directly from the victimβs machine, β¦
Investigate Hidden Privilege Paths with Microsoft Sentinel Data Federation and Custom Graphs
After a compromised service principal incident, the first triage question is always the same: βWhat else can this identity reach?β The answer usually lives outside Sentinel, buried in entitlement exports, RBAC snapshots, or asset inventories that β¦
Detecting OAuth Redirect Abuse with Microsoft Sentinel and Entra ID
On March 2, 2026, Microsoft published an advisory on OAuth redirection abuse enabling phishing and malware delivery. Microsoft described phishing-led campaigns where attackers register OAuth apps with attacker-controlled redirect URIs, then send β¦
The February 2026 Microsoft Sentinel Drop: UEBA Essentials, Copilot Connector, and 9 New GA Connectors
February 2026 brought one of the more substantial Sentinel drops in recent memory. UEBA Essentials hit v3.0.6 with a refined workbook and more than 30 hunting queries (including multi-cloud detections shipped in earlier releases), the M365 Copilot β¦
MarchβJune 2026 Entra ID Changes: Passkey Profiles and Conditional Access Enforcement
Microsoft made passkey profiles and synced passkeys generally available in March 2026, then adjusted a separate Conditional Access enforcement rollout to begin June 15, 2026. Both changes entered tenants through Microsoft-managed schedules, although β¦
Just-In-Time Access for AI Agents: Building a ZSP Gateway in Azure
AI coding assistants may need scoped deployment permissions. Backup automation needs Key Vault secrets at 2 AM. Security scanners need Reader access on a schedule. The easy answer is standing permissionsβgive each service principal what it needs and β¦

