Microsoft Entra ID: The Security Controls I Would Enable First
If you are tightening up Microsoft Entra ID security, the first wins are usually not exotic: they are the controls that reduce password abuse, shrink admin exposure, and…
14 articles
Articles, guides and practical notes about Microsoft & Cloud, with useful context on what matters, how it works and where the interesting details are.
4 articles · authority 33/100
If you are tightening up Microsoft Entra ID security, the first wins are usually not exotic: they are the controls that reduce password abuse, shrink admin exposure, and…
Azure Backup and Veeam are often compared as if they were interchangeable. They are not. Azure Backup is a Microsoft-native service with tight Azure integration and sensible protections for Microsoft-centric estates. Veeam is a broader backup platform built for mixed infrastructure, migration, and recovery control. The right choice depends less on branding and more on what you need to protect, where it lives, and how much operational flexibility you want.
If you are tightening up Microsoft Entra ID security, the first wins are usually not exotic: they are the controls that reduce password abuse, shrink admin exposure, and stop legacy sign-in paths from becoming an easy route in. The trick is to turn on the right controls in the right order, without breaking sign-in for the people who keep the business running.
AWS AI services address different jobs: Amazon Bedrock for generative applications, SageMaker AI for custom machine learning, pre-built APIs for recognised tasks, and Amazon Q for employee and developer assistance.
Ransomware exploitation of SharePoint flaws has sharpened the case for removing public access to on-premises farms. With SharePoint Server 2016 and 2019 unsupported, organisations must investigate historic compromise and choose migration, Subscription Edition or retirement.
In 2026 the choice is less about which hypervisor is “best” and more about which operating model matches your licensing, management, storage and exit strategy. Hyper-V suits Microsoft-heavy estates; Proxmox fits Linux-first teams, especially with clearer subscription handling and newer distributed management.
Time-based backup immutability is now available for Azure SQL Database LTR backups: once the policy is enabled and locked, protected backups can’t be deleted or modified until the retention window ends. But it only covers backups created after the lock.
Microsoft lists CVE-2026-58644 as exploited in the wild. SharePoint Server operators should verify every farm meets the June fixed-build threshold, install the latest August cumulative updates and assess any previously exposed unpatched host for compromise.
Azure Site Recovery is not a single line item you can read off a pricing page and forget about. The licence is only part of the bill. Storage, transactions, outbound data transfer, test failovers and the way you architect recovery all affect the real Azure disaster recovery cost.
Microsoft has marked two SharePoint Server vulnerabilities as actively exploited. Organisations with internet-facing or previously exposed farms should patch to current builds, preserve evidence and assess whether attackers gained access before remediation.
Mirage2FA phishing infrastructure shows how criminals can relay a genuine Microsoft 365 sign-in, capture the resulting session and retain access after MFA. Defending against it requires phishing-resistant authentication and stronger session controls.