Microsoft 365 Security
Blog
Practical articles on Entra ID, Intune, Conditional Access, and device security.
-
Require approved client app is retired on June 30: migrate now
Require approved client app is deprecated June 30. After that date, existing policies stop enforcing. Here is what to configure before the deadline.
-
Intune Multiple Managed Accounts: what admins need to know
Intune's MMA feature, rolling out in June 2026, lets users hold multiple MAM accounts in one app. Here's what admins managing external access need to know.
-
Conditional Access enforcement changes June 15: check your exceptions now
Apps could bypass Conditional Access by requesting minimal sign-in scopes. Non-excluded apps slipped through silently for years. Starting June 15, that stops.
-
AiTM Phishing Exposed (2/2): Stop Session Hijacking
Stop AiTM session hijacking with FIDO2, CAE, and token protection. Microsoft 365 configuration guide with 2 Sentinel queries and 7-step incident response.
-
Unmanaged Devices with Microsoft Intune (3/3): iOS
iOS MAM covers the full M365 app suite but requires Microsoft Authenticator as broker. 3 BYOD paths, the CA gap most organizations miss, and what goes wrong.
-
AiTM Phishing Exposed (1/2): How Session Hijacking Works
AiTM phishing doesn't bypass MFA. It waits for MFA to succeed, then takes what comes next. This is how the attack works and why standard MFA provides no protection against it.
-
Unmanaged Devices with Microsoft Intune (2/3): Android
Android MAM protects all Microsoft 365 apps on mobile, not just Edge. 3 BYOD paths, different control levels, and the CA gap most organizations miss.
-
Shadow AI Exposed (2/2): Building a Governance Program That Actually Works
Technical controls catch the visible surface. This part covers what a shadow AI governance program looks like in practice: approved AI catalog, the personal account problem, and a maintenance cycle that doesn't erode.
-
Unmanaged Devices with Microsoft Intune (1/3): Windows
Windows BYOD with Intune has three distinct paths. Most organizations configure the wrong one. MAM, MDM enrollment, Conditional Access, and the enrollment pitfalls clients hit in practice.
-
Social Engineering Exposed (3/3): Defence That Works
MFA alone won't stop a helpdesk attack. Here's what actually does: the process changes, Entra ID settings, and monitoring that holds up under pressure.