DSE security knowledge hub

Cybersecurity
Knowledge

Page 25 of the DSE Cybersecurity knowledge center, with source-backed guidance and practical next steps.

DSE-authoredOfficial sourcesReviewed guidance
Explore this topic

Cybersecurity knowledge center

Source-backed guidance for identity, vulnerability reduction, ransomware readiness, detection, response, and recovery.

Start with the cornerstone guide
DSE post stream

Cybersecurity

262 articles
DSE visual briefIdentity & cloud

Microsoft Entra Conditional Access: plan controls without locking out the tenant

Conditional Access can combine identity, device, application, and location signals to enforce access controls. Report-only evaluation, emergency access, test users, licensing checks, and phased activation are essential to avoid unintended lockout.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefIdentity & cloud

SharePoint and OneDrive external sharing: reduce exposure without stopping collaboration

SharePoint and OneDrive sharing is governed by tenant, site, link, group, and Microsoft Entra settings. A safer model uses intentional collaboration sites, authenticated guests where practical, restrictive defaults, ownership, and recurring access review.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the guide
DSE visual briefIdentity & cloud

Microsoft 365 offboarding: secure access and preserve business records in the right order

Offboarding is an identity, device, records, and continuity workflow. Blocking sign-in is urgent, while mailbox, OneDrive, ownership, legal hold, forwarding, licensing, and account deletion decisions must follow an approved sequence.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the checklist
DSE visual briefIdentity & cloud

Microsoft 365 Copilot permissions readiness: fix oversharing before rollout

Microsoft 365 Copilot works within a user's existing permissions. That boundary does not correct excessive access: content already visible to a user may become easier to discover, so SharePoint, OneDrive, Teams, ownership, labels, and sharing need review first.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the guide
DSE visual briefContinuity & recovery

Ransomware first response: a calm containment checklist

When ransomware or destructive encryption is suspected, activate the incident plan, isolate affected systems in a coordinated way, preserve evidence, use known-safe communications, protect identities and backups, and involve qualified responders before rebuilding.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the checklist