Knowledge Base

Blog & Guides

Practical cybersecurity articles, step-by-step guides, and quick-reference cheat sheets — from Active Directory hardening to Microsoft 365 and zero trust. Written by someone who's done the work. No hype, no fluff.

16 posts

16 results for “security” · Clear

Article Aug 28, 2026

Passkeys by Default and the Retirement of Microsoft SMS and Voice MFA: The Entra Migration Playbook

Microsoft Entra ID is making passkeys the default sign-in experience and retiring Microsoft-provided SMS and voice authentication. Two dates matter: on 1 September 2026 passkeys are auto-enabled for every user still on SMS or voice and a Microsoft-managed registration campaign starts nudging them; on 1 February 2027 Microsoft-provided SMS and voice telecom delivery is retired, and after that any user whose only MFA method is SMS or voice hits a blocking passkey-registration prompt with no opt-out. This playbook covers who is in scope, how to find your exposed users, how to move them to passkeys, when a customer-managed telecom provider is worth it, the temporary Graph opt-out and its limits, and how it all ties into your Conditional Access baseline. Dates and behaviours validated against Microsoft Learn, August 2026.

TheAdminStack Read →
Article Aug 13, 2026

Securing AI Agent Identities in Microsoft Entra: Governance, Conditional Access and Least Privilege in 2026

Copilot and low-code agents now get their own identities in Microsoft Entra. This guide covers Entra Agent ID — the sponsor/owner model, blueprints, Conditional Access and ID Protection for agents, least-privilege connector governance, and the lifecycle controls that stop agent sprawl — in the order a security team should apply them.

TheAdminStack Read →
Article Aug 6, 2026

Securing Microsoft 365 Copilot: The Oversharing Remediation Playbook

Copilot inherits your permissions — including the broken ones. A practitioner's classify-restrict-monitor sequence for finding and fixing data oversharing before you enable AI across the tenant.

TheAdminStack Read →
Article Aug 2, 2026

Govern Microsoft 365 Copilot with Purview DSPM: Stop Oversharing Before You Deploy

Microsoft 365 Copilot governance means controlling what Copilot can surface, not just who can use it. Copilot does not break your permissions — it exposes them, turning a decade of overshared SharePoint sites into plain-English answers. This guide walks the actual Purview and SharePoint controls that fix it, in the order a security team should apply them: DSPM for AI to find overshared data, sensitivity labels plus DLP to stop Copilot processing it, and SharePoint Restricted Content Discovery to keep high-risk sites out of Copilot answers. Licence and GA/preview status validated against Microsoft Learn, August 2026.

TheAdminStack Read →
Article Aug 1, 2026

Conditional Access Baseline Policies Every Microsoft 365 Tenant Needs in 2026

Every Microsoft 365 tenant should run a baseline of roughly eight to ten Conditional Access policies — block legacy authentication, require MFA for all users, phishing-resistant MFA for admins, compliant or managed devices, block device code flow, sign-in and user-risk policies, session controls, guest MFA, and a break-glass exclusion group — deployed in report-only first, piloted with a ring group, then enforced. This guide gives the named set, the safe rollout order, the P1/P2 licensing reality, the enforcement changes that landed in June and July 2026, and the production gotchas that lock teams out of their own tenant.

TheAdminStack Read →
Article Jul 23, 2026

ISO 27001 vs SOC 2 vs NIST CSF: Which Compliance Framework Does Your Business Actually Need?

ISO 27001 is a certification, SOC 2 is an attestation report, and NIST CSF 2.0 is a voluntary framework — three different answers to "prove you are secure," each favoured by different customers and geographies. This guide compares them head to head on what they are, who asks for them, cost, timeline and effort, then gives a decision framework for choosing one (or sequencing several), and shows how to build a single control set that satisfies all three at once.

TheAdminStack Read →
Article Jul 23, 2026

NIST CSF 2.0 Explained: The Six Functions, Tiers, and Profiles — A Practical Guide

The NIST Cybersecurity Framework 2.0, released in February 2024, is a voluntary framework for organising, assessing and communicating cybersecurity risk. Version 2.0 added a sixth function — Govern — and widened the framework beyond critical infrastructure to organisations of every size. This guide explains the six Functions and their Categories, the Core / Tiers / Profiles structure, how to run a Current-to-Target gap assessment, the new Govern function and CSF Tiers, and how CSF maps to ISO 27001 and SOC 2 so it becomes the connective tissue of a single compliance programme.

TheAdminStack Read →
Article Jul 23, 2026

SOC 2 Explained: Trust Services Criteria, Type 1 vs Type 2, and How to Pass Your First Audit

SOC 2 is a US attestation report, written by a licensed CPA firm, that tells your customers whether the controls protecting their data are designed well (Type 1) and operating effectively over time (Type 2). This guide explains the five Trust Services Criteria, how the Security "Common Criteria" map to the COSO framework, the difference between Type 1 and Type 2, how to choose your scope and observation window, what evidence auditors sample, a realistic timeline and cost, and how SOC 2 lines up with ISO 27001 and NIST CSF so one control set can satisfy all three.

TheAdminStack Read →
Article Jul 23, 2026

ISO 27001 Explained: A Complete Guide to the ISMS and Certification in 2026

ISO/IEC 27001 is the international standard for an information security management system (ISMS) — a risk-based, auditable way to prove you manage security as a system, not a checklist. This guide covers what the standard actually requires (Clauses 4–10 plus the 93 Annex A controls of the 2022 revision), the 2024 climate amendment, how certification works, a realistic timeline and cost, the evidence auditors expect, and how ISO 27001 maps to SOC 2 and NIST CSF so you can satisfy more than one framework at once.

TheAdminStack Read →