Sign in

EricaZelic

@ericazelic.bsky.social
1.9K followers 1.1K following 192 posts

Security Engineer / IAM Security. Defending against people like me.

PostsRepliesMedia
EricaZelic @ericazelic.bsky.social · 16/03/2025
Some nuances to look out for: Depending on tenant settings (some orgs are very complex), you may need to check both *@yourdomain.yourtopleveldomain and *@yourdomainmoera.onmicrosoft.yourtopleveldomain. This depends on your DNS records and mail gateways. Another gotcha is the UTC time. Be careful.
140
EricaZelic @ericazelic.bsky.social · 16/03/2025
You can also run Exchange Message Trace reports from either Exchange Online Admin Center or Security Admin Center. There is a selection the Message Trace that allows you to search for failed/bounced messages or all messages in the past 1 day. You can update the search time to look back further.
110
EricaZelic @ericazelic.bsky.social · 16/03/2025
The first thing you can check is the NDR report in Exchange Online Admin Cetner: admin.exchange.microsoft.com --> Reports --> Mail Flow --> Non-delivery details report.
110
EricaZelic @ericazelic.bsky.social · 16/03/2025
As many people are aware, there have been ongoing issues with Exchange the past few weeks. The latest *incident* (not advisory) is about NDRs. We have been seeing tons of NDRs but do not match the NDR codes in the Incident. /1
160
EricaZelic @ericazelic.bsky.social · 16/03/2025
Interesting.
140
EricaZelic @ericazelic.bsky.social · 16/03/2025
for clarity, I'm talking about this part: learn.microsoft.com/en-us/entra/...
120
EricaZelic @ericazelic.bsky.social · 16/03/2025
It always has this configuration. There is never a client certificate or secret, no redirect URI, and the APP ID URI is a certificate.
100
EricaZelic @ericazelic.bsky.social · 16/03/2025
Can someone tell me what this app registration is that I see absolutely everywhere?
380
EricaZelic @ericazelic.bsky.social · 02/03/2025
Before enabling B2B collaboration, a security plan is required based on your vertical and compliance needs. See steps 1-11 below for a quick start guide. This only pertains to B2B. There are many changes that need to made across the tenant admin centers. learn.microsoft.com/en-us/entra/...
110
EricaZelic @ericazelic.bsky.social · 01/03/2025
This is why I don't like Guests or Anonymous Users
251
EricaZelic @ericazelic.bsky.social · 01/03/2025
From the reference above, this is a Microsoft recommendation of where the CAP comes in for managing authentication strengths for B2B Guests
110
EricaZelic @ericazelic.bsky.social · 01/03/2025
110
EricaZelic @ericazelic.bsky.social · 01/03/2025
For orgs that allow Guests, the tenant-wide configurations that are required to secure controlled data are numerous and include creation of attribute based dynamic groups to enforce authentication strengths and other CAPs, as well as Teams, SPO/OneDrive, and Exchange hardening.
120
EricaZelic @ericazelic.bsky.social · 01/03/2025
External Access deviates from traditional IAM controls. Most organizations DO NOT UNDERSTAND THIS.
120
EricaZelic @ericazelic.bsky.social · 01/03/2025
This is SUPER IMPORTANT for orgs who store controlled data in their tenants
140
EricaZelic @ericazelic.bsky.social · 01/03/2025
Guest Access should NEVER be without Entra ID B2B in Zero Trust. This requires approval from both business tenants and is managed via External Identities in Entra ID AS WELL AS Teams Admin Center.
120
EricaZelic @ericazelic.bsky.social · 01/03/2025
Teams dependent services architecture:
120
EricaZelic @ericazelic.bsky.social · 01/03/2025
130
EricaZelic @ericazelic.bsky.social · 01/03/2025
If your org's approved architecture is based on Zero Trust and you use Teams, here is a nifty chart from Microsoft which lays out your plan. If you store any type of controlled data in your tenant, anywhere, you will fall into the Specialized Security Category. learn.microsoft.com/en-us/securi...
65015
EricaZelic @ericazelic.bsky.social · 23/02/2025
Sydney Sweeney approves this idea
020