Microsoft will soon begin enforcing Multi-Factor Authentication (MFA) for all Azure resource management actions. The company has announced that this change will go into effect on October 1, 2025. In a support document, Microsoft detailed that the mandatory MFA enforcement will apply to Azure CLI, PowerShell, SDKs, REST APIs, Infrastructure as Code (IaC) tools, and…
Last Update: May 20, 2026
Microsoft Active Directory (AD) sits at the heart of most enterprise IT environments. When it goes down, employees can’t log in, applications stop working, and business grinds to a halt. Built‑in tools, like Windows Server Backup, offer only basic system‑state backups. And the AD Recycle Bin can recover deleted objects for a limited time but…
Cybersecurity researchers have discovered a new watering hole campaign orchestrated by a Russian state-sponsored hacking group. The operation exploits Microsoft’s device code authentication flow to trick users into authorizing attacker-controlled devices, granting them unauthorized access to Microsoft 365 accounts. How did Russian hackers exploit Microsoft authentication? According to Amazon’s threat intelligence team, the Russian threat…
In this episode of First Ring Daily, Brad Sams and Paul Thurrott discuss Anthropic releasing a Claude browser extension for Google Chrome at a time when Perplexity and OpenAI are developing AI-powered web browsers.
Microsoft has rolled out a range of new Intune capabilities for August 2025, including smarter app control, multi-admin approvals for sensitive actions, enhanced Apple update visibility, and more. These updates are designed to streamline IT management while strengthening security across organizations. App Control targeting Microsoft has made App Control for Business generally available to commercial…
Cybercriminal group Storm-0501 recently carried out a ransomware-style attack that breached both on-premises and cloud environments of an enterprise victim. The campaign highlights the group’s shift from traditional endpoint-focused tactics to more sophisticated cloud-based ransomware operations. Storm-0501 is a financially driven cybercriminal group that has been active since 2021. It’s known for launching ransomware attacks…
Last Update: Sep 08, 2025
Microsoft’s Active Directory Forest Recovery Guide outlines 29 steps for Active Directory disaster recovery of your environment. But here’s the key takeaway: It’s just a guide. Further, it explicitly states it “doesn’t cover security recommendations for how to recover a forest that has been hacked or compromised”. Following it without prior hands-on experience or preparation is a…
Windows Backup for Organizations, a new tool that launched in limited public preview, is now generally available for commercial customers. This new feature allows organizations to take a backup of their Windows PC settings and preferences and then restore them on a Microsoft Entra-joined device. Microsoft first announced Windows Backup for Organizations at its Ignite…
Security researchers have warned about a new attack campaign that targets Microsoft’s Remote Desktop Protocol (RDP) services. Nearly 2,000 malicious IPs have specifically hit RD Web Access and RDP Web Client authentication portals in recent days. Threat intelligence firm GreyNoise detected a significant increase in RDP scans from around 2,000 IP addresses on August 21….
Microsoft will soon introduce a new policy that will let administrators enable Windows quality updates by default during the Out-of-Box Experience (OOBE) on Windows 11 devices. Starting in September, this feature will be available on eligible Microsoft Entra-joined and hybrid-joined devices running Windows 11 version 22H2 or later. With this update, Windows 11 devices will…
This article explains the most common network devices, their functions, and how they work together in your network topologies. Network devices explained A network device is a hardware component that handles communication, the transfer of data, and connectivity within a computer-based network. These devices ensure that information flows between computers, endpoints, servers, and printers with…
Despite regular secure coding training, nearly 74% of enterprises experienced breaches or serious vulnerabilities in the past year. The findings from SecureFlag’s latest research expose a troubling gap between education efforts and real-world security outcomes. SecureFlag researchers found that insecure code continues to be a major challenge for organizations. In the past year, about 74%…