July 20th, 2024 → 3:16 am @ kamind // No Comments
In the wee hours of Friday morning, July 19th, the world succumbed to what is now possibly the world’s largest security breach. In fact, it is deemed to be even larger than that of the Solar Winds Attack, in which thousands of individuals and businesses were impacted. But with this one that happened today, countries all over the world were impacted by a cataclysmic chain of events. So, you may be wondering, what exactly happened? Although details are still emerging, and will continue to do so even into next week, it appears that this is a “Supply Chain Attack”. This is where the Cyberattacker exploits just one or two points of weaknesses in a software package, and deploys the malicious payload. Once this has been achieved, it spreads like wildfire in just a matter of minutes, crippling businesses both large and small, as we are seeing so far. A Supply […]
July 10th, 2024 → 8:53 pm @ kamind // No Comments
Introduction For those of use in the technology world, Artificial Intelligence (AI) has become the biggest buzzword of late, as well as the hottest trend. Microsoft is a pioneer in this field, driven by its partnership with OpenAI (the creators of ChatGPT). They have just announced a new product called the “Purview AI Hub”, and will be reviewed in further detail in this article. What Is It? The technical definition of the Microsoft Purview AI Hub is as : “Microsoft Purview to mitigate and manage the risks associated with AI usage, and implement corresponding protection and governance controls.” (SOURCE: 1). In other words, it is an all-encompassing tool deployed into your Azure Cloud Environment so that you can keep a visual eye on what is happening with all of the AI based applications that run from within it. From there, it will allow you to into compliance easily comply with […]
July 10th, 2024 → 10:17 am @ kamind // No Comments
Conditional Access (CA) is a security policy enforcement solution available with your Azure AD Premium P1 or Microsoft 365 Business Premium subscription. Once users initiate the log-in process with a password, the application employs If/Then logic to grant access or deny access based on certain conditions or “signals.” Common Conditions Correct Username and Password Location of Login Device itself is Compliant Common Actions Present MFA Challenge Bypass MFA Deny Access Examples If employee logs in with a device that’s assigned to them, in the correct country, and on a compliant network, they bypass MFA If employee logs in with a device that’s assigned to them, in the correct country, but they are not on a compliant network they must complete an MFA challenge. If employee logs in with a device that’s assigned to them, but not in the correct country, they are denied access. Conditional Access Data Hierarchy Guard+ View Conditional Access […]
June 6th, 2024 → 10:54 pm @ kamind // No Comments
There is no doubt that Microsoft has a lot of licensing and subscription plans for their various M365 products, and it can cause quite a bit of confusion for the end user. In this article, we attempt to resolve some of these issues by focusing on the Defender Vulnerability Management package. What Is Defender Vulnerability Management? Before we get started into the details of the licensing, it is first important to review what the actual package is. It is technically defined as follows: “Defender Vulnerability Management delivers asset visibility, intelligent assessments, and built-in remediation tools for Windows, macOS, Linux, Android, iOS, and network devices.” (SOURCE: 1). In other words, this is an all-encompassing package that takes all of the following in order to give you and your IT Security team a holistic view of all the Cyber vulnerabilities that your business could be facing: Threat Intelligence; The statistical odds of […]
June 5th, 2024 → 6:43 am @ kamind // No Comments
At the present time, M365 is predominantly being used by both businesses and even the Federal Government. But, there are many different flavors of it that exist, especially between the private and the public sectors. In this article, we take a closer look at two of them: The Commercial M365 and the M365 for the GCC. The Commercial M365 This is the version of M365 that most people know about. With this kind of subscription, long gone are the days when you had to get the standalone versions of Microsoft Office anytime that you purchased a new device. With the M365, everything is now available in the Cloud, and you can download whatever apps that you think may need, either for personal or business usage. In fact, the most popular apps are as follows: Word PowerPoint Excel Access Publisher With a typical M365 Commercial Subscription, you or your business can […]
June 4th, 2024 → 10:22 pm @ kamind // No Comments
If your business is large enough, it is quite possible that you will require many licenses to procure for your end users. Getting them in bulk, or even using just a couple of licenses on many wireless devices and/or computers is known as “Volume Licensing”. In this article, we examine some ways in which you can do this straight from your M365 Administrative Center. Assigning The End Users For Volume Licensing To get started with the management of Volume Licensing, you first need to take a look at your employee roster in your M365 subscription, and from there, decide who will need to have licenses assigned them. To do this, follow these steps: Log into the Admin Center, at this link: https://admin.microsoft.com/ Once you are logged in, follow these steps: Go to the “Navigation Menu”. Select “Billing”, then “Your Product” Then hover over to “Volume Licensing”. This is illustrated below: […]
February 28th, 2024 → 11:44 am @ axionadmin // No Comments
Backdoor Attacks We all have heard, and perhaps even been a victim of a Cyberattack (hopefully that is not the case). Some of the most common types of attacks that we hear of today are things like Phishing, Ransomware, Insider Threats, etc. But there is another one that lurks out there, which has not appeared too much in the news headlines. That is Backdoor Attacks, and they are the focal point of this article. What Is A Backdoor Attack? This happens when the Cyberattacker deploys a malicious payload on the backend of a system. Through this, they will attempt to gain access to whatever they can via bypassing all of the normal authentication and authorization methods. So rather than trying to waste time in hijacking your password, the Cyberattacker will try to penetrate in this “brute force” way so that they can get in as quickly as possible, without being […]
November 15th, 2023 → 10:55 pm @ kamind // No Comments
As businesses are moving towards the Cloud, especially that of Microsoft Azure, the need for centralization is becoming of paramount importance. Whether it is your security policies, or even your Microsoft 365 apps, you need to make sure that you and your IT Security team can access critical information and data in just a matter of minutes in order to avoid becoming the victim of a Cyberattack. In this article, we provide an overview of this. What Is Recommended Microsoft recommends that only one tenant of Entra should be used (this is the new name for the Azure Active Directory). The primary reason for this is that it greatly simplifies policy management, and more importantly, it can help a business to save any kind of CapEx or OpEx expenditures that may occur. But there are other reasons why you might need more than one tenant, and these are the following […]
November 13th, 2023 → 8:27 pm @ axionadmin // No Comments
One of the greatest risks to businesses today is the over-assignment of rights, permissions, and privileges to employees. Therefore, CISOs, managers, etc. are all taught to adopt the concept of “Least “Privilege”. This is where you give your employees just enough of what they need to conduct their daily job tasks, no more and no less. To make this more effective to organizations, Microsoft has created a new tool called the “Permissions Management Dashboard”, and is further examined in this article. What Is It??? Essentially, it provides you with an overview of all of the permissions and even privileged accounts that your IT Security team has assigned to all of the employees in your company, What is unique about this tool is that it is not just native to Microsoft Azure, you can also use it to check the level of permissions that have been assigned in all of the […]
October 24th, 2023 → 8:54 pm @ kamind // No Comments
In today’s Cybersecurity world, awareness is a hot topic. Whether it is being aware of your physical surroundings, or when you are online, one has to be proactive to help insure that they do not become the next victim of a Cyberattack. In order to promote the sheer importance of this, October has been designated aas the “Official Cybersecurity Awareness Month”. What It Is All About Believe it or not, the concept of having October for this special occasion was thought of and officially declared by the United States Government back in 2004. So, this October 2023 marks its 20th anniversary. It is important to keep in mind that during this time frame, great efforts are taken between all levels of the US Government, Corporate America, and the educational sector to educate the American public about the importance of being aware. Many Cyber vendors are offering free resources to anyone […]