Skip to content

Commit bc61035

Browse files
committed
June 2025 updates
1 parent 7396451 commit bc61035

9 files changed

Lines changed: 47 additions & 2 deletions

File tree

docs/azurenetworksecurity.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,7 @@
66

77
## Microsoft Tech Community Blogs
88

9+
- [Azure WAF Integration in Security Copilot is Now Generally Available](https://techcommunity.microsoft.com/blog/azurenetworksecurityblog/azure-waf-integration-in-security-copilot-is-now-generally-available/4422055)
910
- [Getting Started with Azure Firewall REST API: A Step-by-Step Guide – Part I](https://techcommunity.microsoft.com/blog/azurenetworksecurityblog/getting-started-with-azure-firewall-rest-api-a-step-by-step-guide-%E2%80%93-part-i/4390715)
1011
- [Protecting the Public IPs of Secured Virtual Hub Azure Firewalls against DDoS Attacks](https://techcommunity.microsoft.com/blog/azurenetworksecurityblog/protecting-the-public-ips-of-secured-virtual-hub-azure-firewalls-against-ddos-at/4387435)
1112
- [Comprehensive Guide to Monitoring Azure WAF Metrics and Logs](https://techcommunity.microsoft.com/blog/azurenetworksecurityblog/comprehensive-guide-to-monitoring-azure-waf-metrics-and-logs/4378260)

docs/entraid.md

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,10 @@
99

1010
## Microsoft Tech Community Blogs
1111

12+
- [Important Update: Azure AD Graph retirement](https://techcommunity.microsoft.com/blog/microsoft-entra-blog/important-update-azure-ad-graph-retirement/4364990)
13+
- [Important Update: AzureAD PowerShell retirement](https://techcommunity.microsoft.com/blog/microsoft-entra-blog/important-update-azuread-powershell-retirement/4364989)
14+
- [OAuth consent phishing explained and prevented](https://techcommunity.microsoft.com/blog/microsoft-entra-blog/oauth-consent-phishing-explained-and-prevented/4423357)
15+
- [Getting started with the Microsoft Entra Suite](https://techcommunity.microsoft.com/blog/microsoft-entra-blog/getting-started-with-the-microsoft-entra-suite/4422972)
1216
- [New policy enhancement tools in Entra Conditional Access](https://techcommunity.microsoft.com/blog/microsoft-entra-blog/new-policy-enhancement-tools-in-entra-conditional-access/4418866)
1317
- [Advanced deployment guide for Conditional Access Policy templates](https://techcommunity.microsoft.com/blog/microsoft-entra-blog/advanced-deployment-guide-for-conditional-access-policy-templates/4406767)
1418
- [Simplify frontline workers’ sign-in experience with QR code authentication](https://techcommunity.microsoft.com/blog/microsoft-entra-blog/simplify-frontline-workers%E2%80%99-sign-in-experience-with-qr-code-authentication/3822034)
@@ -1757,6 +1761,9 @@
17571761

17581762
## Community Blogs
17591763

1764+
- [What is Tier Zero — Part 1](https://posts.specterops.io/what-is-tier-zero-part-1-e0da9b7cdfca)
1765+
- [What is Tier Zero — Part 2](https://posts.specterops.io/what-is-tier-zero-part-2-6e1d14fddcaf)
1766+
- [Beyond the GUI: Properly Securing Your Admin Apps with Custom Security Attributes in Entra ID](https://www.linkedin.com/pulse/beyond-gui-properly-securing-your-admin-apps-custom-security-lawalt-akwlf/)
17601767
- [Managing Restricted Groups with Access Packages](https://nathanmcnulty.com/blog/2025/04/managing-restricted-groups-with-access-packages/)
17611768
- [QR code authentication: a new simplified sign-in experience for frontline workers - Janic Verboon](https://www.basevision.ch/microsoft-entra-qr-code/)
17621769
- [External Collaboration Settings with Application Permissions](https://suryendub.github.io/2024-12-21-extCollaboration/)
@@ -1814,6 +1821,7 @@
18141821
- [Kenneth van Surksum](https://x.com/kennethvs)
18151822
- [Daniel Chronlund](https://twitter.com/DanielChronlund)
18161823
- [Nicola Suter](https://twitter.com/nicolonsky)
1824+
- [Thomas Naunheim](https://www.linkedin.com/in/thomasnaunheim/)
18171825

18181826
## GitHub
18191827

@@ -1827,6 +1835,8 @@
18271835
- [Conditional-Access-Validator](https://github.com/jasperbaes/Conditional-Access-Validator)
18281836
- [M365AdminAccessReviewer](https://github.com/notEricaZelic/M365AdminAccessReviewer)
18291837
- [Conditional access Baseline](https://github.com/j0eyv/ConditionalAccessBaseline)
1838+
- [Microsoft Zero Trust Assessment V2 - Private Preview](https://github.com/microsoft/zerotrustassessment/blob/psnext/src/powershell/doc/readme.md)
1839+
- [Microsoft Zero Trust Assessment Code](https://github.com/microsoft/zerotrustassessment/tree/psnext/src/powershell)
18301840

18311841
## Podcasts
18321842

@@ -1836,6 +1846,13 @@
18361846

18371847
- [Entra ID Admin Roles Report](https://rksolutions.nl/entra-id-admin-roles-report/?utm_source=substack&utm_medium=email)
18381848
- [AAGUIDs](https://aaguid.nicolasuter.ch/)
1849+
- [Microsoft 365 Message Center Archive](https://mc.merill.net/)
1850+
- [Tier 0 Table](https://github.com/SpecterOps/TierZeroTable/)
1851+
1852+
## EntraOps Classification and Automation
1853+
1854+
- [EntraOps Classification Files](https://github.com/cloud-architekt/azureprivilegediam)
1855+
- [Community Project “EntraOps”](https://www.entraops.com)
18391856

18401857
## Secure Configuration
18411858

docs/mdc.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,12 @@
88

99
## Microsoft Tech Community Blogs
1010

11+
- [New feature in Defender for Storage: Optional Index Tags](https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/new-feature-in-defender-for-storage-optional-index-tags/4427987)
12+
- [Optimizing Resource Allocation with Microsoft Defender CSPM](https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/optimizing-resource-allocation-with-microsoft-defender-cspm/4427785)
13+
- [Microsoft Named a Leader in the IDC MarketScape for CNAPP: Key Takeaways for Security Buyers](https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/microsoft-named-a-leader-in-the-idc-marketscape-for-cnapp-key-takeaways-for-secu/4427071)
14+
- [Unlocking API visibility: Defender for Cloud Expands API security to Function Apps and Logic Apps](https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/unlocking-api-visibility-defender-for-cloud-expands-api-security-to-function-app/4426864)
15+
- [Performing Advanced Risk Hunting in Defender for Cloud](https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/performing-advanced-risk-hunting-in-defender-for-cloud/4420633)
16+
- [Enhancements for protecting hosted SQL servers across clouds and hybrid environments](https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/enhancements-for-protecting-hosted-sql-servers-across-clouds-and-hybrid-environm/4414783)
1117
- [Connecting Defender for Cloud with Jira](https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/connecting-defender-for-cloud-with-jira/4411691)
1218
- [Plug, Play, and Prey: The security risks of the Model Context Protocol](https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/plug-play-and-prey-the-security-risks-of-the-model-context-protocol/4410829)
1319
- [From visibility to action: The power of cloud detection and response](https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/from-visibility-to-action-the-power-of-cloud-detection-and-response/4411280)

docs/mdca.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,7 @@
88

99
## Microsoft Tech Community Blogs
1010

11+
- [Protect SaaS apps from OAuth threats with attack path, advanced hunting and more](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/protect-saas-apps-from-oauth-threats-with-attack-path-advanced-hunting-and-more/4395997)
1112
- [Get visibility into your DeepSeek use with Defender for Cloud Apps](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/get-visibility-into-your-deepseek-use-with-defender-for-cloud-apps/4372520)
1213
- [Microsoft Defender for Cloud Apps’ Shadow IT Discovery Capabilities Now Support MacOS](https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/microsoft-defender-for-cloud-apps-shadow-it-discovery/ba-p/4159677)
1314
- [Data Protection Made a Breeze: MDA integration in Edge for Business](https://cloudbrothers.info/en/data-protection-breeze-mda-integration-edge-business/)

docs/mde.md

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -352,4 +352,3 @@
352352
- [Nuke It From Orbit](https://github.com/lkarlslund/nifo)
353353
- [MDE Troubleshooter](https://github.com/ThomasVrhydn/MDE-troubleshooter)
354354
- [Powershell Digital Forensics & Incident Response](https://github.com/Bert-JanP/Incident-Response-Powershell)
355-

docs/mdi.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,8 @@
99

1010
- [Scope Identity Protection with Defender for Identity](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/new-scope-identity-protection-with-defender-for-identity/4422968)
1111
- [Microsoft Defender for Identity has announced the public preview of a new service account discovery module that automatically identifies and classifies service accounts in Active Directory](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/discover-and-protect-service-accounts-with-microsoft-defender-for-identity/4395347)
12+
- [Expanding the Identity perimeter: the rise of non-human identities](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/expanding-the-identity-perimeter-the-rise-of-non-human-identities/4418953)
13+
- [Discover and protect Service Accounts with Microsoft Defender for Identity](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/discover-and-protect-service-accounts-with-microsoft-defender-for-identity/4395347)
1214
- [Securing Identities: 10 recommendations for building a stronger identity security posture](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/securing-identities-10-recommendations-for-building-a-stronger-identity-security/4371879)
1315
- [Introducing the new Defender for Identity sensor management API](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/introducing-the-new-defender-for-identity-sensor-management-api/4367164)
1416
- [Microsoft Defender for Identity: the critical role of identities in automatic attack disruption](https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/microsoft-defender-for-identity-the-critical-role-of-identities/ba-p/4236688)

docs/mdiot.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,8 @@
66

77
## Microsoft Tech Community Blogs
88

9+
- [Sensor Disconnection Notifications with Microsoft Defender for IoT and Microsoft Sentinel](https://techcommunity.microsoft.com/blog/microsoftdefenderiotblog/sensor-disconnection-notifications-with-microsoft-defender-for-iot-and-microsoft/4375517)
10+
911
- [Make OT security a core part of your SOC strategy with Microsoft Defender XDR](https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/make-ot-security-a-core-part-of-your-soc-strategy-with-microsoft/ba-p/4185702)
1012
- [Introducing Single Sign-On (SSO) for Sensor Console: Enhanced Security and Streamlined Access](https://techcommunity.microsoft.com/t5/microsoft-defender-for-iot-blog/introducing-single-sign-on-sso-for-sensor-console-enhanced/ba-p/4129156)
1113
- [Analyze IoT/OT device firmware with Microsoft Defender for IoT](https://techcommunity.microsoft.com/t5/microsoft-defender-for-iot-blog/analyze-iot-ot-device-firmware-with-microsoft-defender-for-iot/ba-p/3853474)

docs/mdxdr.md

Lines changed: 11 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,8 +9,18 @@
99

1010
## Microsoft Tech Community Blogs
1111

12+
- [Case management now supports multiple tenants in Microsoft Defender experience](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/case-management-now-supports-multiple-tenants-in-microsoft-defender-experience/4425329)
13+
- [Introducing TITAN-Powered Recommendations in Security Copilot Guided Response](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/introducing-titan-powered-recommendations-in-security-copilot-guided-response/4416350)
14+
- [From on-premises to cloud: Graph-powered detection of hybrid attacks with Microsoft exposure graph](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/from-on-premises-to-cloud-graph-powered-detection-of-hybrid-attacks-with-microso/4416295)
15+
- [The Best of Microsoft Sentinel — Now in Microsoft Defender](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/the-best-of-microsoft-sentinel-%E2%80%94-now-in-microsoft-defender/4415822)
16+
- [Announcing File Attachments for Case Management](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/announcing-file-attachments-for-case-management/4408881)
17+
- [Unified Security Summary: Enhancing Visibility and Value](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/unified-security-summary-enhancing-visibility-and-value/4411302)
18+
- [Empowering SOC Analysts: Investigating Identity Threats with Microsoft Defender XDR](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/empowering-soc-analysts-investigating-identity-threats-with-microsoft-defender-x/4398225)
19+
- [Announcing Rich Text for Case Management](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/announcing-rich-text-for-case-management/4405855)
20+
- [Level up your defense: protect against attacks using stale user accounts](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/level-up-your-defense-protect-against-attacks-using-stale-user-accounts/4386290)
21+
- [Defending Against OAuth-Based Attacks with Automatic Attack Disruption](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/defending-against-oauth-based-attacks-with-automatic-attack-disruption/4384381)
22+
- [Automatic attack disruption: Enhanced containment for critical assets and shadow IT](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/automatic-attack-disruption-enhanced-containment-for-critical-assets-and-shadow-/4402157)
1223
- [Case Management is now Generally Available](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/case-management-is-now-generally-available/4398558)
13-
1424
- [Monthly news - February 2025](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/monthly-news---february-2025/4373271)
1525
- [Hyperscale ML threat intelligence for early detection & disruption](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/hyperscale-ml-threat-intelligence-for-early-detection--disruption/4359763)
1626
- [Web Scale Graph Mining for Cyber Threat Intelligence](https://arxiv.org/abs/2411.06239)

docs/sentinel.md

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,9 +4,12 @@
44
- [Microsoft Sentinel documentation](https://learn.microsoft.com/en-us/azure/sentinel/)
55
- [What's new in Microsoft Sentinel](https://learn.microsoft.com/en-us/azure/sentinel/whats-new)
66
- [Become a Microsoft Sentinel Ninja](https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/become-a-microsoft-sentinel-ninja-the-complete-level-400/ba-p/1246310)
7+
- [The Definitive SIEM Buyer’s Guide](https://marketingassets.microsoft.com/gdc/gdcDFk38S/original)
78

89
## Microsoft Tech Community Blogs
910

11+
- [Microsoft Sentinel: Repositories, the Future of Content-as-Code & Best Practices​](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/microsoft-sentinel-repositories-the-future-of-content-as-code--best-practices%E2%80%8B/4422936)
12+
- [Exciting Announcements: New Data Connectors Released Using the Codeless Connector Framework](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/exciting-announcements-new-data-connectors-released-using-the-codeless-connector/4421104)
1013
- [Multi-workspace for Multi-tenant is now in Public Preview in Microsoft's Unified SecOps Platform](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/multi-workspace-for-multi-tenant-is-now-in-public-preview-in-microsofts-unified-/4398229)
1114
- [Multi Workspace for Single tenant is now in Public Preview in Microsoft’s unified SecOps platform](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/multi-workspace-for-single-tenant-is-now-in-public-preview-in-microsoft%E2%80%99s-unifie/4398228)
1215
- [Microsoft Sentinel Project Deployment Tracker](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/microsoft-sentinel-project-deployment-tracker/4394174)
@@ -620,3 +623,7 @@
620623

621624
- [Optimizing Your Security Operations: Manage Your Data, Costs and Protections with SOC Optimizations](https://www.youtube.com/watch?v=Uk9x60grT-o)
622625
- [Optimizing your SOC's threat coverage and data value](https://www.youtube.com/watch?v=b0rbPZwBuc0)
626+
627+
### Documentation
628+
629+
- [Migrate from the HTTP Data Collector API to the Log Ingestion API to send data to Azure Monitor Logs](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/custom-logs-migrate)

0 commit comments

Comments
 (0)