KQL

Conditional Access, Part Six: Turning Twenty-Five Queries Into an Operating Model

All right class. Five posts, twenty-five queries. If you

Fixing the "Rare Subscription-level Operations in Azure" Analytic Rule

Alright class. Back on the Azure control plane, and a

Conditional Access, Part Five: Cross-Tenant Access, MFA Trust, and the Partner Problem

All right class. Part two left a loose end and

Conditional Access, Part Four: Tokens, Sessions, and the Control You Do Not Have

All right class. Three posts in. We designed the estate,

Conditional Access, Part Three: Device Controls, and What Compliant Actually Proves

All right class. Two posts in. We built the estate,

Conditional Access, Part Two: Authentication Strengths and the Road to Phishing-Resistant

All right class. Conditional Access, Part One: Design the EstatePart

Conditional Access, Part One: Design the Estate Before You Write Another Policy

All right class. Open your tenant. Go to Entra ID,

Fixing the "Multiple Password Reset by User" Analytic Rule

Alright class. Another rule from the content hub today: "

Fixing the "Attempts to Sign In to Disabled Accounts" Analytic Rule

Alright class. Seventh lesson in this series. Back to the

Operation Silent Ledger: A SOC Tabletop Exercise for Adversary in the Middle Phishing

Alright class. Every tabletop exercise I have sat in ended
Consent Preferences