@BleepinComputer Device-code flow was built for TVs and printers. Tycoon2FA abuses the 15-min token window after just one click. Block it in Conditional Access for any user who doesn't need it. https://t.co/erqBhksJSn #ZeroTrust
An oldie, but still valuable way of finding inactive Exchange Online distribution lists. Use the message trace log to check for expand events and then use the unique email addresses found to know if a DL is active or not.
https://t.co/0s7QmVKKfn
#Microsoft365#PowerShell
Microsoft Defender for Office 365 has new LLMs that are able to detect attacker intent with 99.995% accuracy, and now blocking 140,000 BEC emails per day.
"These models have been trained on one of the largest datasets in the industry and enable more accurate identification of text-only attacks"
Available by default in Defender for Office 365 Plan 1, which is included in Microsoft 365 Business Premium.
Announcement: https://t.co/JAaeFqk2ZC
@rucam365 Yes I use Break Glass Accounts, normally 2. Super strong passwords, locked up in a safe or stored in Cyberarc or something similar.
• Global Admin (not PIM enabled)
• Password Never Expires
• No MFA
• Excluded from all Conditional Access policies
• Cloud-only
💥 BOOM! We just can't stop with all the Entra announcements 😂
Platform SSO for macOS is here!!!! 👏 🎉🥳🙌🍾
With Microsoft Entra Join for macOS you can now use Touch ID to unlock your device and be signed into Entra ID under the hood using a device-bound key.
🧵👇
It's here folks. 🎉 Microsoft really, really wants to eliminate passwords and the answer is passkeys!
Learn all about the announcement and how you can enable the preview and try it today.
https://t.co/BjrpKPZ1Tj
This is the way.
@RebeccaWUvell Kan väl finnas typ 1000 anledningar, som att ha kommit hem från resa eller vad som helst, men samtliga är helt oviktiga, det viktiga är att du inte har med saken att göra och att du ber dig fruktansvärt illa åt mot alla de som nu sörjer en tragisk olycka. Skäms
Important note! If you are using a trial license to test #msintune Cloud PKI your keys will be store in software, not HSM! HSM is available only for licensed deployments. Keep this in mind because you can't change it later! #PKI
@MSFT365Status So many helpful people here! It will for sure be fixed much faster because of your “down in Bigcity” comments. Or “going Slack” comments. Keep it up! Have a great weekend! 🕺🧠
As part of our work to remediate any residual impact, we’re removing affected false-positive spam messages from quarantine and replaying the messages. We're closely monitoring the service as our work progresses, more info is provided in the admin center under EX682041.
.@Office365#MicrosoftTeams will introduce a new Meet app to help people organize their meetings. The app is good for those working in large organizations. I just wonder about its usefulness for those who attend many meetings in other tenants https://t.co/6Y9BbguD6u
#Microsoft365
Are you into cloud hacking? Got an MS Graph token but unsure what to do with it? Do you want to forge your own primary refresh token with a malicious device registration. I got you covered. Bypass MFA like a boss with this guide. #Azure
https://t.co/bWeVvgIyjL
.@Office365 If you use MFA with #AzureAD, the introduction of system-preferred authentication is a big thing. Microsoft wants to get rid of SMS responses to MFA challenges and this is one way to assist in that process. More at https://t.co/iMae0pXcQD
#Office365#Microsoft365