Skip to main content
Jerrad Dahlager
Jerrad Dahlager, CISSP, CCSP Cloud Security Architect Β· Adjunct Instructor
About me β†’

Microsoft Security Fall 2026: Five Changes to Prepare For

Review update (September 25, 2026): The integration identity used for incident comments can require tenant-wide incident-write permission, not a comment-only grant. Keep a dedicated identity, narrowly selected integrations and documented credential …

Entra SSPR and Passkey Readiness for Microsoft-Provided SMS/Voice Delivery Retirement

Microsoft is advancing three related parts of the Entra authentication and recovery experience through July 2027: On September 1, 2026, Microsoft began gradually moving users enabled for SMS or voice into the Microsoft-managed passkey Registration …

From Authorization to Action: Operationalizing CISA's Microsoft Cloud Logs Playbook in Sentinel

Review update (September 25, 2026): The January 15, 2025 publication date is supported by CISA’s original release notice; the resource landing page now emphasizes the later revision date. Review update (September 25, 2026): For cost planning, …

Block Device Code Phishing in Entra Without Breaking Legit Workflows

Review update (September 26, 2026): The merged rules run every 15 minutes, retain their correlation lookbacks, and gate on recent ingestion from either relevant side. Rule 2 merges duplicate representations of a successful sign-in while retaining …

Detecting Infostealer Session Hijacking with Microsoft Sentinel

Review update (September 25, 2026): Cookie replay maps to T1550.004 separately from cookie theft (T1539); these rules provide investigative signals rather than proof of either technique. Keep the sign-in tables used by scheduled rules in the …

Investigate Hidden Privilege Paths with Microsoft Sentinel Data Federation and Custom Graphs

Review update (September 25, 2026): Modeling, persistence and query permissions differ. Review the current graph requirements before granting tenant-wide Security Operator or Administrator solely to persist a graph. An on-demand graph job and a …

Detecting OAuth Redirect Abuse with Microsoft Sentinel and Entra ID

Review update (September 26, 2026): The merged source preserves an already-disabled user-consent policy and refuses unrecognized custom self-consent policy replacement for manual review. Reports, manifest staging and request-body files are …

The February 2026 Microsoft Sentinel Drop: UEBA Essentials, Copilot Connector, and 9 New GA Connectors

Review update (September 25, 2026): The diagram and measured results describe February evidence. For current use, Defender-portal onboarding replaces Fusion incident correlation with the Defender XDR engine. Connector descriptions refer to what is …

March–June 2026 Entra ID Changes: Passkey Profiles and Conditional Access Enforcement

Review update (September 25, 2026): Resource links to older third-party rollout summaries are historical background. Use current Microsoft guidance and the actual tenant Message Center notice for dates/cloud scope. The Baseline scopes settings link …

Just-In-Time Access for AI Agents: Building a ZSP Gateway in Azure

Review update (September 25, 2026): The merged September 25 source rejects ambiguous/dot-segment scopes and mismatched ARM response identities, uses explicit managed identity with closed SDK clients, and moves synchronous operations off the async …