Microsoft has announced the integration of Microsoft Defender Threat Intelligence (MDTI) into Defender XDR and Microsoft Sentinel. The goal is to provide threat intelligence directly within security analysts’ workflow rather than requiring a separate platform. Previously, security teams often had to switch between separate MDTI, Microsoft Sentinel, and Defender interfaces to collect threat actor information,…
Microsoft has made hybrid Exchange management easier with the general availability of Writeback for Cloud-Managed Remote Mailboxes in Exchange Online. The new capability enables administrators to manage mailbox attributes in the cloud while automatically synchronizing key changes back to on-premises Active Directory. According to Microsoft, many organizations with hybrid Exchange environments still have mailbox identities…
Microsoft has released version 7.9 of the Teams PowerShell module. This release strengthens authentication and introduces new governance controls for Microsoft Teams collaboration and meetings. The biggest platform change is that Connect-MicrosoftTeams now uses Web Account Manager (WAM) by default for authentication. Web Account Manager (WAM) is a built-in authentication broker for Windows that securely…
Entra Connect is well known as the application responsible for synchronizing on-premises Active Directory (AD) identities to the Entra Cloud. This service is not only integral to an environment’s operational health, it must be on your security radar as it straddles two trust boundaries and is the authority for your hybrid identities. All too commonly,…
Generative AI is reshaping enterprise IT spending, driving the strongest growth in cloud infrastructure services since 2018. As organizations race to build AI capabilities and expand computing capacity, cloud platforms have become the foundation of this transformation. According to new data from Synergy Research, worldwide spending on cloud infrastructure services reached $143.4 billion in the…
Microsoft is making passwordless sign-ins more secure and accessible for desktop users by extending Windows Hello Enhanced Sign-in Security (ESS) to compatible external fingerprint readers. This update enables hardware-backed biometric authentication on more Windows 11 devices, which helps protect sensitive data from sophisticated cyberattacks. Windows Hello Enhanced Sign-in Security (ESS) is an advanced security feature…
Seasonal hiring for many organizations means creating large numbers of workforce identities in a short space of time. New starters need immediate access to systems and data, often before IT has had an opportunity to get to know them. That pressure can introduce gaps in the onboarding process, not because IT teams don’t care about…
Microsoft’s July 2026 update for Sentinel introduces new capabilities to streamline detections-as-code workflows for commercial customers. The release also improves data lake visibility and expands data connector coverage, giving security teams broader access to security signals through a unified platform. Microsoft introduced a new feature that allows security teams to manage custom detections as code…
In this episode of First Ring Daily, Brad Sams and Paul Thurrott discuss Microsoft’s earnings results for the fourth quarter of its fiscal year 2026, in which the company’s spending on AI infrastructure increased dramatically.
Many organizations are rushing to adopt artificial intelligence (AI), but according to Troy Norcross, AI Governance Advisor and Founder of SERTeam, they are approaching the challenge from the wrong direction. In a recent episode of Petri Dish, Norcross explained that too many companies are starting with AI and looking for places to use it, rather…
Microsoft is making Linux security compliance significantly easier by bringing CIS Benchmark auditing directly into Microsoft Azure. This new feature gives organizations a built-in way to continuously assess and track security posture across cloud and hybrid environments. CIS Security Benchmarks are a set of globally recognized security best practices designed to help organizations securely configure…
Microsoft has introduced a new Exposure Resolution dashboard experience in Microsoft Security Exposure Management. This new feature is designed to help security teams focus on the most important risks instead of sorting through large volumes of findings and disconnected dashboards. Security teams are overwhelmed by a growing number of vulnerabilities, exposure findings, and security alerts…