Author: Harri Jaakkonen

Log4j explanation and Microsoft services (Mostly)

You don’t every day see a CVE with the amount of 10/10, but now the day came and in the form of Log4j and LogShell / LogJam vulnerability. What is log4j? log4j is a reliable, fast and flexible logging framework…

Continue Reading Log4j explanation and Microsoft services (Mostly)

Insider risk management, what, why and how

What is Insider risk management Insider risk management is a solutions for example to prevent leavers to take precious company data with them when to go. But there is also options to lower the risk for users, example anonymizing usernames….

Continue Reading Insider risk management, what, why and how

What is Azure B2C and how to use it?

Azure B2C is a authentication portal for social, personal and corporate accounts. The authentication is based on OpenID Connect. You can modify the login pages, add identity providers, give all Azure AD tenants the right to login thru your tenant….

Continue Reading What is Azure B2C and how to use it?

Mandatory one-time password is coming, are you ready?

Microsoft has statement in the in their docs saying. “Starting November 1, 2021, we’ll begin rolling out a change to turn on the email one-time passcode feature for all existing tenants and enable it by default for new tenants. At…

Continue Reading Mandatory one-time password is coming, are you ready?

Microsoft’s *new* certification tests and study material

Microsoft has deprecated old certification paths and released new ones, in this post I will cover what changed and how to prep for the exams or just for work. New certification tests Microsoft has had this certification poster for a…

Continue Reading Microsoft’s *new* certification tests and study material

Temporary Access Pass what and the how

What is Azure Temporary Access Pass? Passwordless authentication methods, such as FIDO2 and Passwordless Phone Sign-in through the Microsoft Authenticator app, enable users to sign in securely without a password. Users can bootstrap Passwordless methods in one of two ways:…

Continue Reading Temporary Access Pass what and the how

Firewall Manager | DDoS Protection Plans (Preview)

Azure DDoS Protection is currently in Preview. For those DDoS or DoS is not familiar, I will open it a bit before going thru Microsoft service. What is Denial-Of-Service attack? Denial Of Service means that the attacker will send malformed…

Continue Reading Firewall Manager | DDoS Protection Plans (Preview)

Azure Container Apps (Still in Preview?)

Microsoft has released Container Apps, it’s a serverless environment for running apps. Some Microsoft documents say it’s still in Preview but my Azure portal says differently. Azure Container Apps enables executing application code packaged in any container and is unopinionated…

Continue Reading Azure Container Apps (Still in Preview?)

Sign-in to Azure AD with email as an alternate login ID (still in Preview)

What will work? Only emails in verified domains for the tenant are synchronized to Azure AD. Each Azure AD tenant has one or more verified domains, for which you have proven ownership, and are uniquely bound to you tenant. One…

Continue Reading Sign-in to Azure AD with email as an alternate login ID (still in Preview)

Whats new with conditional access and Microsoft authenticator

Conditional access has some new cool features that will provide extra security for your user logins. In this post I will cover some of them. Will be digging deeper on these as they evolve but for now it’s important for…

Continue Reading Whats new with conditional access and Microsoft authenticator