Blog

Security hero image

Hackers Exploit Publicly Leaked ASP.NET Keys for Code Injection Attacks — Are You at Risk?

Microsoft has disclosed that threat actors are exploiting publicly exposed ASP.NET machine keys to execute ViewState code injection attacks. The company warns that web developers are inadvertently putting their organizations at risk by using these keys from online repositories and documentation in their applications. In December, Microsoft first observed the attacks that involved an unknown…

View Article
Windows-11-notebook-tablet

New Policy to Let IT Admins Manage Windows 11 Updates During OOBE

Microsoft has announced a major change that will give organizations greater control over how updates are installed on new Windows 11 devices. A new policy will soon allow administrators to decide whether quality updates are applied during the out-of-box experience (OOBE). Previously, users had to manually check for updates through Windows Update after setting up…

View Article
Teams hero approved 2

Microsoft Teams to Get New Facebook-Inspired Storyline Feature to Boost Employee Engagement

Microsoft has started testing a new Facebook-style Storyline news feed internally within Microsoft Teams. According to a new report from The Verge, this feature will allow users to share updates, post news, and engage with colleagues by liking and sharing content. “Storyline enables leaders to communicate directly with their organizations, delivering personalized updates to amplify,…

View Article
Azure Cloud Hero Server Devices

What is Azure RBAC?

Last Update: Feb 26, 2025

Azure Role-Based Access Control (RBAC) is Microsoft Azure’s primary authorization system for managing access to cloud resources. By assigning specific permissions to users, service principals, and managed identities, Azure RBAC ensures that access is both controlled and aligned with the principle of least privilege. Whether you’re securing a single subscription or governing a hybrid cloud…

View Article
1725501059 powershell hero

Microsoft Releases PowerShell Script to Counter BlackLotus UEFI Bootkit Threat

Microsoft has released a new PowerShell script that enables administrators to update bootable media with the “Windows UEFI CA 2023” certificate to boost system security. This update specifically targets vulnerabilities exploited by the BlackLotus UEFI bootkit, which is a sophisticated threat capable of bypassing Secure Boot protections. What is BlackLotus UEFI? BlackLotus UEFI is a…

View Article
Cloud Computing

Microsoft Extends Testing for Final Exchange Server 2019 Update – What it Means for Businesses

Microsoft has yet to release the final cumulative update (CU15) for Exchange Server 2019 due to technical issues. The company has outlined some of the reasons for the delay, but it has not provided a new expected release date for the update. In December, Microsoft announced plans to push the final cumulative update for Exchange…

View Article
Microsoft Teams

New Microsoft Teams PowerShell Setting Enables Federation with Specific Trial Tenants

Microsoft has introduced a new PowerShell setting within Tenant Federation Configuration, offering administrators enhanced flexibility to tailor their federation posture. The company announced on the Micrososoft 365 admin center that this setting is now available to commercial users through Microsoft Teams PowerShell. Last year, Microsoft added a new PowerShell setting (called -ExternalAccessWithTrialTenants) to the Set-CsTenantFederationConfiguration…

View Article
Windows-11-notebook-tablet

Understanding Group Policy WMI Filtering

Group Policy WMI Filtering is a powerful feature that allows administrators to apply Group Policy Objects (GPOs) and Group Policy preferences based on specific attributes of target computers, servers, and users. By leveraging Windows Management Instrumentation (WMI) queries, IT professionals can create highly targeted and dynamic GPOs that respond to the unique needs of their…

View Article
Security – 4

Hackers Use Fake ADFS Login Pages to Steal Credentials — Is Your Organization at Risk?

Security researchers have discovered a sophisticated phishing campaign targeting organizations that rely on Active Directory Federation Services (ADFS) for secure access. This attack has already compromised over 150 organizations across critical sectors, including healthcare, education, government, and technology. Active Directory Federation Services (ADFS) is a software component that gives users sign-on (SSO) access to systems…

View Article
Network Security

Latest Microsoft Entra Connect Sync Update Brings New Auditing Capabilities

Microsoft has recently rolled out a new update (version 2.4.129.0) of its Entra Connect Sync service. The latest release brings new auditing capabilities, enhancements, as well as bug fixes to improve user experience and boost the overall stability of the system. What is Microsoft Entra Connect Sync? Microsoft Entra Connect Sync enables organizations to synchronize…

View Article
Datacenter networking servers

What is SQL Server Reporting Services?

SQL Server Reporting Services (SSRS) is a set of on-premises tools and services that enable you to create, deploy, and manage printed, web, email and mobile reports from SQL Server databases. Let’s look at its evolution and capabilities in more detail. When SQL Server was first released it was a simple relational database but as…

View Article
Cloud Computing

Microsoft Entra to Add New People Administrator Role

Microsoft is about to add a new People administrator role in Microsoft Entra, allowing organizations to securely delegate people-related tasks. This update helps streamline user management while minimizing security risks associated with high-level admin roles. In Microsoft Entra ID, built-in roles offer pre-defined permissions for efficient access control, but they don’t always match common user…

View Article
Go to page