top of page
All Posts


5 Essential Security Measures for Microsoft 365 You Shouldn't Ignore
5 Essential Security Measures for Microsoft 365 You Shouldn't Ignore
Kyle Cira
Jul 30, 20253 min read


New in CIS Microsoft 365 Benchmark v7: Periodic Reauthentication for All Users
For years, Microsoft 365 security guidance has focused heavily on protecting administrative accounts. That makes sense—administrators have elevated privileges and represent some of the highest-value targets in an organization. But with the release of CIS Microsoft 365 Benchmark v7, the guidance has expanded.
CIS now recommends that all users—not just administrators—periodically reauthenticate.
Kyle Cira
May 293 min read


Top 5 Most Important New Security Controls in the CIS Microsoft 365 Benchmark v7
The CIS Microsoft 365 Benchmark continues to evolve alongside the threat landscape, and Version 7 introduces several important new controls that reflect where attackers—and Microsoft—are headed.
This release continues the trend of strengthening Microsoft 365 against modern identity attacks, AI-related data leakage, and automated threat containment.
Here are five of the most impactful additions organizations should be paying attention to.
Kyle Cira
May 213 min read


Legacy Authentication in Microsoft 365: Mostly Dead—But Still a Risk
For years, legacy authentication was one of the easiest ways for attackers to bypass security controls in Microsoft 365.
Even in environments with Multi-Factor Authentication (MFA) enabled, legacy protocols allowed attackers to authenticate using only a stolen username and password—no second factor required.
The result? Attackers could quietly access mailboxes, download data, and gain valuable data for their next move.
Kyle Cira
Apr 242 min read
bottom of page
