Category: Tenant Hardening

Why o why is Microsoft`s default to trust everybody and enable new stuff in all tenants ?

ADVISORY

please check for some serious risky settings in your tenants

This blogpost is a small rant (love you Microsoft) about the big company out of Redmond, and why they strayed from their motto in the 2000`s which was «secure by default» -> to Kumbaya, love everybody, Hare Krishna style – and ENABLE like every new feature in our tenants ?

Check for these settings on AdminCenter – https://admin.microsoft.com

  • CoPilot Agents for everybody (like Enterprise apps restricted, but
Read more

“To group or not to group” is the question – talking about Conditional Access and specifically exclude groups

In this blog i talk about if it`s a good idea to discuss using exclusion groups for conditional Access Policies or maybe why not. Topics contain Roles in Entra, External tools not being able to get group membership for an evergreen Dashboard and more…

Don`t lie, this happened to you too

I didn`t know, that this user was still excluded from a certain conditional access rule – somebody

Read more