Tag Incident Response

Exploring Conditional Access Bypasses in Microsoft Entra ID

Swiss cheese model applied to identity security

Conditional Access is the backbone of Zero Trust in Microsoft Entra ID, yet real world attacks increasingly demonstrate how it can be bypassed. From device and token abuse to built in exclusions and misunderstood session controls, attackers exploit gaps that many organisations assume are protected.

Triggered by Microsoft’s upcoming change in February 2026, where session revocation will finally behave as expected during incident response, this blog analyses observed Conditional Access bypass techniques from real incidents in 2024 and 2025. More importantly, it explains why a strong security baseline is essential to compensate for what Conditional Access was never designed to solve alone.

Mastering Microsoft Sentinel: 25 KQL Queries for Powerful Threat Detection

Interian | Securing Insights

Unlock the power of Microsoft Sentinel with this comprehensive guide featuring 25 essential KQL queries for potent threat detection. In this post, you'll discover expertly crafted queries designed to identify a range of adversary tactics—from password spraying and suspicious PowerShell executions to unusual login patterns and obfuscated scripts. Whether you're looking to refine your current security operations or embark on a new journey with Sentinel, this guide offers practical insights, customisation tips, and real-world scenarios to help you stay ahead of evolving cyber threats.