All Posts


Explore every article across identity, security, governance, threat protection, and cloud‑native technologies — all in one unified place.

All Posts

  • Microsoft is moving beyond SMS-based MFA: Passkeys become the default authentication experience in Entra ID

    Microsoft végleg búcsút int az SMS-alapú MFA-nak – a Passkey lesz az új alapértelmezett az Entra ID-ban Microsoft is moving beyond SMS-based MFA: Passkeys become the default authentication experience in Entra ID SMS-based MFA has played an important role in improving security adoption, but in today’s threat landscape it is no longer considered a phishing-resistant…

    Read more

  • Microsoft Defender for Endpoint – Permission Model Part 3

    Microsoft Defender for Endpoint – Permission Model (Part 3) About this part In the previous section, we reviewed the basic configuration options for Microsoft Defender for Endpoint. In this section, we will examine permission management approaches, demonstrating how administrators and Security Operations Center team members can access the Microsoft Defender for Endpoint service. Introduction Access…

    Read more

  • Microsoft Defender for Endpoint – Defender for Endpoint configuration Part2

    Microsoft Defender for Endpoint – Defender for Endpoint configuration Part2 About this Part In Part 2, we will cover the following topics related to Microsoft Defender for Endpoint: Prerequisites The following prerequisites must be met: Note: When creating a new Microsoft Defender tenant, each component (Defender for Endpoint, Defender for Identity, Defender for Office 365,…

    Read more

  • Microsoft Defender for Endpoint – An Overview of Architecture, Capabilities, and the Ecosystem Part1

    Microsoft Defender for Endpoint (MDE) – architektúra, képességek és ökoszisztéma áttekintés Microsoft Defender for Endpoint (MDE) – An Overview of Architecture, Capabilities, and the Ecosystem Microsoft Defender for Endpoint is a comprehensive endpoint security platform designed to prevent, detect, investigate, and automatically respond to threats in modern environments. It is not a single product, but…

    Read more

  • Microsoft Defender XDR Deep Dive – Advanced Hunting and the Telemetry Architecture – Part2

    Microsoft Defender XDR Deep Dive – Advanced Hunting és a telemetry architektúra Microsoft Defender XDR Deep Dive – Advanced Hunting and the Telemetry Architecture – Part2 In the previous section, we looked at how Microsoft Defender XDR works at a high level and how it can correlate endpoint, identity, email, and cloud telemetry around a…

    Read more

  • Microsoft Defender XDR Deep Dive – Part1

    Microsoft Defender XDR Deep-To-Dive Microsoft Defender XDR Deep Dive – Part1 Microsoft Defender XDR is an integrated security platform that processes telemetry from different areas of an enterprise environment—endpoints, identity management, email traffic, SaaS applications, and cloud resources—in a unified way. Its goal is to interpret isolated events as coherent attack patterns and, based on…

    Read more

  • Getting Real Value from Microsoft Entra Licenses with License Usage Insights

    Getting Real Value from Microsoft Entra Licenses with License Usage Insights Getting Real Value from Microsoft Entra Licenses with License Usage Insights Introduction Licensing is one of those areas that most organizations deal with because they have to. It’s tracked, reviewed from time to time, maybe optimized during renewals, but rarely treated as something strategic.…

    Read more

  • Microsoft Sentinel Custom Graphs

    Microsoft Sentinel Custom Graphs – From SIEM to Relationship-Based Security Analytics For a long time, the event- and log-based approach dominated the field of security analysis. SIEM systems were based on this model: data collection, normalization, followed by queries and detections built on tabular structures. This approach still works today, but it has a structural…

    Read more

  • Password Protection in Microsoft Defender – Reducing Identity Risk at the Source

    Most cyberattacks don’t start with some sophisticated exploit. They start with something much simpler: a password. And in many cases, it’s not even hidden—it’s something users have been reusing for years. Not even a clever one either. Usually just a weak, reused, or slightly modified password that’s easy to guess. Even after years of enforcing…

    Read more