Knowledge and News on Microsoft 365 Security

Entra CAE: Revoke service principal tokens faster

Microsoft Entra CAE - revoke service principal tokens

Microsoft describes an important Entra update for automated access: access tokens issued to service principals can be made unusable faster with Continuous Access Evaluation when a workload identity is disabled, deleted, or detected as risky. For small and midsize organizations, this matters because scripts and integrations often run with broad application permissions. If a secret … Read more

Review reverse tunnels with Defender

TerminalFix - Review reverse tunnels with Microsoft Defender

Microsoft Threat Intelligence is warning about a TerminalFix campaign that extends the familiar ClickFix tactic: a fake Cloudflare CAPTCHA page tricks users into running a copied terminal command themselves. For small and midsized businesses, this matters because the attack does not stop at a simple infostealer after first execution. Microsoft describes a multistage chain with … Read more

Microsoft Entra: Review custom CSS by October

Microsoft Entra - CSS review for branded sign-ins

Microsoft Entra ID is restricting custom branding for sign-in pages. Beginning October 26, 2026, custom CSS layout and positioning properties will be blocked globally. Organizations that styled their Microsoft 365 sign-in experience with custom CSS should review it now. Logos, images, and text generally remain available, but affected rules for positioning, spacing, visibility, or overlapping … Read more

Microsoft Purview: Use temporary permissions

Microsoft Purview - temporary permissions

Microsoft added a small but useful change to the August overview for Microsoft Purview: role group assignments can now be configured with an expiration date. When that date is reached, the assignment is removed automatically and access is revoked. For small and midsize organizations, this matters because Purview work is often temporary: an external specialist … Read more

MacSync Stealer: Defender XDR hunting pivots

MacSync Stealer - Defender hunting for macOS

Microsoft Defender Experts have published new details on MacSync Stealer. The macOS-focused information stealer uses changing infrastructure to deliver payloads, communicate with compromised devices, and exfiltrate data. For companies that run Macs, the important point is that Microsoft does not only list domains. It describes recurring behavioral pivots that security teams can hunt for in … Read more