DSE security knowledge hub

IT
Knowledge

Page 13 of the DSE IT knowledge center, with source-backed guidance and practical next steps.

DSE-authoredOfficial sourcesReviewed guidance
Explore this topic

IT knowledge center

Production-minded guidance for endpoints, servers, updates, cloud services, administration, and supportable operations.

Start with the cornerstone guide
DSE post stream

IT

199 articles
DSE visual briefNetworks & infrastructure

Finish the Windows Secure Boot trust-chain transition from 2011 certificates

Windows devices can keep booting after the 2011 Secure Boot certificates expire yet miss future early-boot protections. Inventory status, update OEM firmware, pilot by hardware family, and verify the 2023 trust chain with evidence.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefIdentity & cloud

Move Exchange Online SMTP AUTH clients off Basic authentication with evidence

Microsoft now plans to disable SMTP AUTH Basic authentication by default for existing Exchange Online tenants at the end of December 2026. Find every sender, choose a supported replacement, pilot it, and prove the legacy path is quiet.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefIdentity & cloud

Deploy SMB over QUIC only after identity, port, and fallback testing

SMB over QUIC protects Windows file access with TLS 1.3 over UDP 443, but Windows clients can still prefer TCP and external authentication can fall back to NTLM. Prove transport, identity, certificates, and renewal before production.

Published Reviewed 4 min readBy DSE Security Editorial Team
Read the checklist
DSE visual briefContinuity & recovery

Treat Terraform state as production data with locking and recovery

Terraform state binds configuration to real infrastructure and can contain sensitive data. A team needs controlled remote storage, supported locking, restricted access, serialized changes, versioned recovery, and a tested process for failed writes.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the checklist
DSE visual briefNetworks & infrastructure

Design Azure Private Endpoint DNS before the first private link

An approved Azure Private Endpoint can still fail when clients resolve the public address or a private zone returns NXDOMAIN. Design service-specific zones, VNet links, hybrid forwarding, fallback, ownership, and tests before deployment.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the guide
DSE visual briefNetworks & infrastructure

Test Path MTU across tunnels and cloud edges before applications stall

VPN, overlay, encapsulation, and cloud paths can carry less payload than an endpoint interface suggests. Validate bidirectional Path MTU, ICMP behavior, transport adaptation, and representative applications before intermittent stalls reach production.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook