DSE security knowledge hub

Cybersecurity
Knowledge

Page 3 of the DSE Cybersecurity knowledge center, with source-backed guidance and practical next steps.

DSE-authoredOfficial sourcesReviewed guidance
Explore this topic

Cybersecurity knowledge center

Source-backed guidance for identity, vulnerability reduction, ransomware readiness, detection, response, and recovery.

Start with the cornerstone guide
DSE post stream

Cybersecurity

164 articles
DSE visual briefIdentity & cloud

Use authentication context to require stronger proof only when the action deserves it

Microsoft Entra authentication context can invoke Conditional Access for a sensitive action inside a capable application. Use it to add risk-appropriate step-up without assuming it protects unsupported paths or replaces baseline access policy.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the guide
DSE visual briefIdentity & cloud

Design cross-tenant access settings before B2B collaboration scales

Microsoft Entra cross-tenant access settings govern inbound and outbound B2B relationships and trust in external MFA or device claims. Inventory real partners, defaults, applications, and lifecycle before broad collaboration becomes the policy.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefIdentity & cloud

Revoke Microsoft 365 sessions with evidence—not assumptions about token expiry

Blocking sign-in and revoking refresh tokens are important, but existing access and application sessions can end on different timelines. Run a documented containment workflow and verify effective loss of access across supported services and independent applications.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefIdentity & cloud

Give every shared mailbox an owner, sign-in boundary, and review cadence

Shared mailboxes outlive projects and teams unless someone owns membership, direct sign-in, forwarding, retention, licensing, automation, and closure. Govern each mailbox as a business service, not a permanent bucket of delegated access.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the checklist
DSE visual briefIdentity & cloud

Build a defensible Microsoft Purview retention and legal-hold decision tree

Retention policies, retention labels, records controls, and eDiscovery holds answer different questions. Route each requirement through legal, records, privacy, workload, license, scope, deployment, validation, exception, and release decisions.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the guide
DSE visual briefIdentity & cloud

Move Windows services from reusable passwords to managed service identities where supported

Group Managed Service Accounts let supported domain services use domain-managed passwords and simplified SPN management. Migration still requires application support, dependency discovery, least privilege, host authorization, staged testing, and rollback.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefIdentity & cloud

Harden Active Directory Certificate Services before templates become privilege paths

AD CS can issue credentials used for authentication, signing, and encryption. Treat certification authorities, templates, enrollment rights, web endpoints, keys, revocation, and recovery as high-value identity infrastructure.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefIdentity & cloud

Enable Credential Guard only after testing authentication dependencies

Windows Credential Guard isolates selected secrets with virtualization-based security, but legacy protocols, delegation, security packages, remote access, firmware, virtualization, and applications can change behavior. Discover and pilot before enforcement.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefNetworks & infrastructure

Protect Layer 2 edges with explicit spanning-tree guardrails

A misplaced switch or unexpected bridge can change Layer 2 topology and disrupt a site. Define the intended spanning-tree root, classify ports, apply platform-appropriate protections, monitor topology changes, and test recovery.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook