Dana EppOct 25, 20181 minGetting started for Azure IT operatorsIts pretty common that I get asked by IT professionals just where should they start when it comes to Azure. Simple enough question. Have ...
Dana EppOct 10, 20181 minBaking security in with the Secure DevOps for Azure KitOne of the cool things I see coming out of Microsoft these days is the investment in educating everyone on how to bake security in. Not j...
Dana EppSep 25, 20182 minUsing Azure AD for password-based single sign-on (SSO)If you have followed my career at all, you know that in a previous life I built an Identity Provider (IdP) called AuthAnvil that delivere...
Dana EppSep 11, 20181 minApproaches for a more secure Azure KeyVaultAzure Key Vault is a cloud service that safeguards encryption keys and secrets (such as certificates, connection strings, passwords) for ...
Dana EppSep 1, 20181 minHacker Hunting in AzureMicrosoft Azure provides a secure foundation for customers to host their infrastructure and applications. Microsoft’s secure foundation s...
Dana EppAug 16, 20181 minBuilding Zero Trust networks with Microsoft 365 The Microsoft Offensive Security Research team published some guidance on Building Zero Trust networks with Microsoft 365. In it, they de...
Dana EppAug 10, 20182 minWhy you should not allow direct RDP to your Azure infrastructureSo last month McAfee had a great article on how organizations leave backdoors open to cheap Remote Desktop Protocol (RDP) attacks. While ...
Dana EppJul 30, 20181 minNIST SP 800-171, Azure Security and YouMicrosoft has released the Azure Security and Compliance Blueprint for NIST SP 800-171. This Azure Security and Compliance Blueprint prov...
Dana EppJul 18, 20181 minSecuring privileged access across the Microsoft Cloud should be child's playThe security of most or all business assets in the modern organization depends on the integrity of the privileged accounts that administe...
Dana EppJun 28, 20181 minServerless platform security in Azure FunctionsI'm a big fan of serverless compute, especially in Azure with Azure Functions. The idea of using serverless computing is so appealing as ...
Dana EppJun 11, 20181 minLog into your Linux VMs with Azure ADOMG is this awesome. Microsoft has now added support to log into your Linux VMs in Azure using Azure Active Directory. Think of the possi...
Dana EppMay 18, 20181 minUsing Azure AD Easy Auth with AngularOne of the cool things about Azure AD is how easy they make it to act as an Identity Provider (IdP) for your app services in Azure. One o...
Dana EppMar 30, 20182 minHow to quickly detect if your SQL Azure databases are encrypted at restSo I was recently discussing how to best protect data at rest in Azure with an IT pro from a major bank in the US. There was a misconcept...
Dana EppMar 21, 20182 minCatch up on the latest Azure security whitepapersSo I saw Dr. Tom started indexing all the different Azure security whitepapers published my Microsoft. Here is a quick list so you have e...
Dana EppMar 16, 20181 minHow to integrate Azure Functions with an Azure Security Center PlaybookLet's imagine a scenario where a threat actor has triggered an alert in Security Center. This alert has the attacker's source IP and you w...
Dana EppMar 6, 20183 minWhat you need to know about Azure Network WatcherHave you ever felt the need to diagnose a critical problem and you needed access to packet data from a virtual machine? What if you could...
Dana EppFeb 28, 20181 minMicrosoft releases attack simulation guidance to help learn Azure Security Center.Now this could be useful if you are just getting into how alerts in Azure Security Center work. Yuri was recently saying Microsoft has now...
Dana EppFeb 19, 20181 minNeed to know where to find Azure security best practices and patterns? Look no furtherListen, you don't have to be a super hero to secure your Azure cloud workloads. But I also know that if there is one thing about Azure se...
Dana EppFeb 10, 20181 minAzure Identity Management and access control security best practicesMany consider identity to be the new boundary layer for security, taking over that role from the traditional network-centric perspective....
Dana EppFeb 3, 20182 minHow Microsoft is helping you NOT screw up your Azure Secrets on GitHubOK, so you are building this awesome cloud application and running it on Azure. You are doing a great job of using source control and the...