Microsoft 365
Insecure defaults and misconfigurations are an entry point into Microsoft 365 and Entra ID. A secure baseline configuration and the Defender products protect against that; afterwards the cloud logs show what happened.
All articles and events are in German.
Articles
Überprüfen von Cloud-UmgebungeniX 1/2024 · Sich selbst hacken 5/5
iX kompakt Sicheres Active Directory 2023iX Special 1/2023
iX kompakt Sicheres Active DirectoryiX Special 14/2022
Grundlagen von Azure Active Directory und Azure-DiensteniX 4/2022 · Azure Active Directory (heute Entra ID) 1/3
Azure Active Directory und Azure-Dienste absicherniX 4/2022 · Azure Active Directory (heute Entra ID) 3/3
Angriffe auf das Azure Active Directory und auf Azure-DiensteiX 4/2022 · Azure Active Directory (heute Entra ID) 2/3
Talks and panels
Azure und IT-Security: Angriffsziel Azure Active Directory (AAD)Talk · IT-Tage · 2022-12-13
Angriffsziel Azure und Azure Active DirectoryTalk · heise devSec · 2022-10-05
Workshops and webinars
Upcoming
M365 Security – Sicherer Einsatz der Microsoft-Cloud im UnternehmenWebinar series · heise academy · next date 2026-10-06
Archive
Fortgeschrittenes Ethical Hacking – Deep Dive ins Pentesting für AdminsWebinar series · heise academy · 2026-07-07
Angriffe auf und Absicherung von Azure Active Directory (heute Entra ID)Workshop · heise academy · 2024-03-11
Angriffe auf und Absicherung von Microsoft 365Webinar · Oneconsult · 2023-09-28
Angriffsziel Azure Active Directory – Hacken und HärtenWebinar · Oneconsult · 2022-11-29