Skip to main content
Jerrad Dahlager
Jerrad Dahlager, CISSP, CCSP Cloud Security Architect Β· Adjunct Instructor
About me β†’

Microsoft Security Fall 2026: Five Changes to Prepare For

Microsoft’s fall security updates change several assumptions that are easy to leave buried in an old runbook: what a Security Administrator can do during an incident, whether Sentinel automation needs Security Copilot capacity, which risk-policy …

Entra SSPR and Passkey Readiness for Microsoft-Provided SMS/Voice Delivery Retirement

Microsoft is advancing three related parts of the Entra authentication and recovery experience between now and next March: On September 1, 2026, users enabled for SMS or voice begin moving into the Microsoft-managed passkey Registration Campaign. …

From Authorization to Action: Operationalizing CISA's Microsoft Cloud Logs Playbook in Sentinel

CISA released the Microsoft Expanded Cloud Logs Implementation Playbook on January 15, 2025. Its implementation guidance remains a practical baseline for deciding which Microsoft cloud audit signals belong in a defensible logging program. That is …

Block Device Code Phishing in Entra Without Breaking Legit Workflows

Device code phishing is nasty because the user does not hand over a password. They hand over a session. The lure sends the victim to a legitimate Microsoft device sign-in page. The victim enters a short code. Entra ID issues tokens to the attacker’s …

Detecting Infostealer Session Hijacking with Microsoft Sentinel

Nearly 70% of incidents in the Americas now begin with stolen or misused accounts. Infostealers are the engine behind that number – families like Lumma, RedLine, and Vidar export browser cookies and session tokens directly from the victim’s machine, …

Investigate Hidden Privilege Paths with Microsoft Sentinel Data Federation and Custom Graphs

After a compromised service principal incident, the first triage question is always the same: β€œWhat else can this identity reach?” The answer usually lives outside Sentinel, buried in entitlement exports, RBAC snapshots, or asset inventories that …

Detecting OAuth Redirect Abuse with Microsoft Sentinel and Entra ID

On March 2, 2026, Microsoft published an advisory on OAuth redirection abuse enabling phishing and malware delivery. Microsoft described phishing-led campaigns where attackers register OAuth apps with attacker-controlled redirect URIs, then send …

The February 2026 Microsoft Sentinel Drop: UEBA Essentials, Copilot Connector, and 9 New GA Connectors

February 2026 brought one of the more substantial Sentinel drops in recent memory. UEBA Essentials hit v3.0.6 with a refined workbook and more than 30 hunting queries (including multi-cloud detections shipped in earlier releases), the M365 Copilot …

March–June 2026 Entra ID Changes: Passkey Profiles and Conditional Access Enforcement

Microsoft made passkey profiles and synced passkeys generally available in March 2026, then adjusted a separate Conditional Access enforcement rollout to begin June 15, 2026. Both changes entered tenants through Microsoft-managed schedules, although …

Just-In-Time Access for AI Agents: Building a ZSP Gateway in Azure

AI coding assistants may need scoped deployment permissions. Backup automation needs Key Vault secrets at 2 AM. Security scanners need Reader access on a schedule. The easy answer is standing permissionsβ€”give each service principal what it needs and …