DSE security knowledge hub

IT
Knowledge

Production-minded guidance for endpoints, servers, updates, cloud services, administration, and supportable operations.

DSE-authoredOfficial sourcesReviewed guidance
Explore this topic

IT knowledge center

Production-minded guidance for endpoints, servers, updates, cloud services, administration, and supportable operations.

Start with the cornerstone guide
DSE post stream

IT

86 articles
DSE visual briefCyber defense

CVE-2026-70329 in Outlook: What the 8.8 RCE Means and How to Respond

Microsoft has fixed CVE-2026-70329, an Outlook integer-overflow vulnerability rated CVSS 8.8. Exploitation requires a user to open a malicious Office file. Review the exact affected editions, deploy the August 11 security release, and verify the installed build by servicing channel.

Published Reviewed 5 min readBy Gavin Stewart
Read the briefing
DSE visual briefContinuity & recovery
GuideImportantBusiness ContinuityIT

Place a failover-cluster witness outside the failure domain it must arbitrate

A quorum witness is a deciding vote, not a decorative cluster setting. Select cloud, disk, or file share from the topology; isolate its dependencies from the failures it must resolve; validate access from every node; and retest after cluster or site changes.

Published Reviewed 3 min readBy Gavin Stewart
Read the guide
DSE visual briefNetworks & infrastructure
ChecklistImportantITNetworks & Infrastructure

Govern Windows DNS scavenging as a deletion change, not routine cleanup

Windows DNS aging can identify stale dynamic records, and scavenging can delete them. Inventory timestamps and registration owners, align intervals with DHCP and client behavior, restrict scavenging servers, pilot one zone, and prove recovery before enabling automation.

Published Reviewed 3 min readBy Gavin Stewart
Read the checklist
DSE visual briefNetworks & infrastructure

Finish the Windows Secure Boot trust-chain transition from 2011 certificates

Windows devices can keep booting after the 2011 Secure Boot certificates expire yet miss future early-boot protections. Inventory status, update OEM firmware, pilot by hardware family, and verify the 2023 trust chain with evidence.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefIdentity & cloud

Move Exchange Online SMTP AUTH clients off Basic authentication with evidence

Microsoft now plans to disable SMTP AUTH Basic authentication by default for existing Exchange Online tenants at the end of December 2026. Find every sender, choose a supported replacement, pilot it, and prove the legacy path is quiet.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefIdentity & cloud

Deploy SMB over QUIC only after identity, port, and fallback testing

SMB over QUIC protects Windows file access with TLS 1.3 over UDP 443, but Windows clients can still prefer TCP and external authentication can fall back to NTLM. Prove transport, identity, certificates, and renewal before production.

Published Reviewed 4 min readBy DSE Security Editorial Team
Read the checklist