DSE security knowledge hub

Security knowledge,
without the noise.

Page 4 of the DSE Security Knowledge Hub, with source-backed guidance, checklists, explainers, and playbooks.

DSE-authoredOfficial sourcesReviewed guidance
DSE post stream

Guidance and analysis from DSE

254 articles
DSE visual briefIdentity & cloud

Give every shared mailbox an owner, sign-in boundary, and review cadence

Shared mailboxes outlive projects and teams unless someone owns membership, direct sign-in, forwarding, retention, licensing, automation, and closure. Govern each mailbox as a business service, not a permanent bucket of delegated access.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the checklist
DSE visual briefIdentity & cloud

Build a defensible Microsoft Purview retention and legal-hold decision tree

Retention policies, retention labels, records controls, and eDiscovery holds answer different questions. Route each requirement through legal, records, privacy, workload, license, scope, deployment, validation, exception, and release decisions.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the guide
DSE visual briefIdentity & cloud

Move Windows services from reusable passwords to managed service identities where supported

Group Managed Service Accounts let supported domain services use domain-managed passwords and simplified SPN management. Migration still requires application support, dependency discovery, least privilege, host authorization, staged testing, and rollback.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefIdentity & cloud

Harden Active Directory Certificate Services before templates become privilege paths

AD CS can issue credentials used for authentication, signing, and encryption. Treat certification authorities, templates, enrollment rights, web endpoints, keys, revocation, and recovery as high-value identity infrastructure.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefIdentity & cloud

Enable Credential Guard only after testing authentication dependencies

Windows Credential Guard isolates selected secrets with virtualization-based security, but legacy protocols, delegation, security packages, remote access, firmware, virtualization, and applications can change behavior. Discover and pilot before enforcement.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefNetworks & infrastructure

Protect Layer 2 edges with explicit spanning-tree guardrails

A misplaced switch or unexpected bridge can change Layer 2 topology and disrupt a site. Define the intended spanning-tree root, classify ports, apply platform-appropriate protections, monitor topology changes, and test recovery.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefNetworks & infrastructure

Plan for private Wi-Fi addresses before NAC and inventory lose the device

Modern devices can present private MAC addresses per Wi-Fi network and may rotate them. Inventory and network access designs that treat a hardware address as durable identity need stronger signals, documented exceptions, and tested support workflows.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the guide
DSE visual briefNetworks & infrastructure

Migrate monitoring to SNMPv3 without losing the alerts operations depend on

SNMPv3 can add authentication, integrity, privacy, and scoped access, but a rushed cutover can silently drop polling or notifications. Migrate by device class, verify manager support, test both directions, and retain rollback.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook