A rule that will accelerate your career: If you bring a problem, bring context. If you bring context, bring options. If you bring options, bring a recommendation. People trust people who help them think. Anyone can spot an issue, few can actually help move things forward.
Protect Malicious Apps acces to Mail:
-Disable user consent - require admin approval
-Audit & remove unused apps regularly, especially those with mail permissions
-Enforce Conditional Access
-Enable admin consent workflow to review all permission requests
-Monitor OAuth grants
🚨#BREAKING: Chinese hackers linked to the group known as Salt Typhoon have breached the email systems of U.S. congressional committee staff, gaining access to internal communications.
Understanding permission context before executing is critical. Always verify that permissions match the intended execution before taking action.
Peek Before You Poke, Operator: https://t.co/ovzicGDsFj
You really should consider requiring assignment for all the CLI tools like Graph, Azure, Exchange, etc.
You can even license devs/admins and allow access via PIM for Groups or Access Packages
I may even have automated setup for that here 😏
https://t.co/4d2PNP04gQ
#MDE custom collection is finally in public preview! It's a centrally managed solution to improve visibility and detection opportunities.
We're releasing a management tool and rule repository in YAML format to share new rules with the community.
https://t.co/kxit8fFjhU