Sign in

Lukas Beran

@lukasberan.com
1.6K followers 241 following 648 posts

Senior Security Researcher (DART) at Microsoft. Opinions are my own. #MSIncidentResponse #DART #Microsoft365 #EntraID #DefenderXDR #Sentinel

PostsRepliesMedia
Reposted by Lukas Beran
Ben Schorr @bschorr.bsky.social · 20/07/2026
If you're running #Windows #Server 2022 hopefully you're already aware of this, but good reminder than it will reach the end of mainstream support on October 13th. deltapulse.app/item/MC1429856
deltapulse.app
90-Day Reminder: Windows Server 2022 will reach end of mainstream support on October 13, 2026
Service: Windows. Category: Stay Informed. Microsoft 365 change intelligence and updates
012
Reposted by Lukas Beran
Microsoft Exchange @msftexchange.bsky.social · 20/07/2026
Reminder: Exchange 2016 and 2019 ESU Program Ends in October 2026 | Microsoft Community Hub! 🦋 techcommunity.microsoft.com/blog/exchang...
techcommunity.microsoft.com
Reminder: Exchange 2016 and 2019 ESU Program Ends in October 2026 | Microsoft Community Hub
We wanted to provide a reminder that Exchange 2016 and 2019 ESU program ends in October 2026.  
002
Lukas Beran @lukasberan.com · 16/03/2026
𝐇𝐨𝐰 𝐭𝐨 𝐜𝐫𝐞𝐚𝐭𝐞 𝐚 𝐖𝐏𝐀3 𝐖𝐢-𝐅𝐢 𝐩𝐫𝐨𝐟𝐢𝐥𝐞 𝐟𝐨𝐫 𝐖𝐢𝐧𝐝𝐨𝐰𝐬 𝐢𝐧 𝐌𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭 𝐈𝐧𝐭𝐮𝐧𝐞 Microsoft Intune still cannot natively create a Wi-Fi profile with WPA3-Personal security at this time. Within the configuration templates, there is only Wi-Fi with WPA/WPA2 security, but WPA3 is missing.
How to create a WPA3 Wi-Fi profile in Microsoft Intune
111
Lukas Beran @lukasberan.com · 18/02/2026
𝐇𝐨𝐰 𝐂𝐨𝐧𝐝𝐢𝐭𝐢𝐨𝐧𝐚𝐥 𝐀𝐜𝐜𝐞𝐬𝐬 𝐏𝐨𝐥𝐢𝐜𝐢𝐞𝐬 𝐀𝐫𝐞 𝐄𝐯𝐚𝐥𝐮𝐚𝐭𝐞𝐝 𝐢𝐧 𝐌𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭 𝐄𝐧𝐭𝐫𝐚 𝐈𝐃 Understanding how Conditional Access policies are evaluated in Microsoft Entra ID is absolutely essential if you are involved in their creation or management.
𝐇𝐨𝐰 𝐂𝐨𝐧𝐝𝐢𝐭𝐢𝐨𝐧𝐚𝐥 𝐀𝐜𝐜𝐞𝐬𝐬 𝐏𝐨𝐥𝐢𝐜𝐢𝐞𝐬 𝐀𝐫𝐞 𝐄𝐯𝐚𝐥𝐮𝐚𝐭𝐞𝐝 𝐢𝐧 𝐌𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭 𝐄𝐧𝐭𝐫𝐚 𝐈𝐃
110
Lukas Beran @lukasberan.com · 15/02/2026
Great to see my post on Microsoft Entra ID access packages shared in such a valuable newsletter - thanks for the shoutout, @merill.net
031
Lukas Beran @lukasberan.com · 08/02/2026
𝐇𝐨𝐰 𝐭𝐨 𝐮𝐬𝐞 𝐚𝐜𝐜𝐞𝐬𝐬 𝐩𝐚𝐜𝐤𝐚𝐠𝐞𝐬 𝐭𝐨 𝐦𝐚𝐧𝐚𝐠𝐞 𝐠𝐫𝐨𝐮𝐩 𝐦𝐞𝐦𝐛𝐞𝐫𝐬𝐡𝐢𝐩𝐬 Access packages allow you to dynamically manage group, Teams, application, and SharePoint site membership based on user requests.
Access package in Microsoft Entra ID
120
Lukas Beran @lukasberan.com · 05/01/2026
𝐇𝐨𝐰 𝐭𝐨 𝐠𝐞𝐭 𝐮𝐧𝐥𝐢𝐦𝐢𝐭𝐞𝐝 𝐦𝐚𝐢𝐥𝐛𝐨𝐱 𝐬𝐢𝐳𝐞 𝐢𝐧 𝐄𝐱𝐜𝐡𝐚𝐧𝐠𝐞 𝐎𝐧𝐥𝐢𝐧𝐞 Exchange Online Plan 1 licenses generally have a primary mailbox capacity of 50 GB. Exchange Online Plan 2 licenses have a capacity of 100 GB.
Exchange Online mailbox archive
110
Lukas Beran @lukasberan.com · 11/12/2025
Is there any way to create a Planner task directly from an email? Ideally including the email content and attachments. I assumed this would be basic functionality, but I can’t find such an option anywhere. #planner
200
Lukas Beran @lukasberan.com · 04/12/2025
Looks like Christmas is coming early this year 🤷‍♂️
010
Reposted by Lukas Beran
Ru Campbell @campbell.scot · 28/11/2025
New post: focusing on the key biggest Microsoft 365 security considerations. READ: campbell.scot/micros... When we talk about Microsoft 365 security, we are talking about two things: (a) securing Microsoft 365 the platform, (b) using Microsoft 365 security tooling.
campbell.scot
Microsoft 365: The Essential 10 Security Considerations - Ru Campbell MVP
When we talk about Microsoft 365 security, we are talking about two things: The latter can be used to achieve the former, as well as other (non-Microsoft 365) platforms. For example, using Defender for Endpoint on a Linux server in AWS, or using Entra for single sign on to Salesforce. Given its omnipresence in enterprise IT, Microsoft 365 security’s vastness (and value) needs to be front-of-mind for all tenant administrators. The Essential 10 is…
153
Lukas Beran @lukasberan.com · 18/11/2025
@cloudflare.social is so broken now that even their status page is broken 🧐 #cloudflaredown
Cloudflare status page
031
Reposted by Lukas Beran
Ru Campbell @campbell.scot · 31/10/2025
New video: 5 common Entra ID guests mistakes (Entra B2B) • excessive directory visibility • ignored cross-tenant defaults • untrusted MFA & device states • open SharePoint sharing • no guest lifecycle There's tons more! But here's a starter WATCH: youtu.be/AXuj-U9p3jU
041
Reposted by Lukas Beran
Simon Hudson | MVP @simonjhudson.bsky.social · 09/10/2025
After yesterday's interesting #Copilot+#OneDrive event I took a much deeper look at the 'Add shortcut to OneDrive' #SharePoint feature. Microsoft have declared this as the direction of travel. At first it looked great. Until I dug deeper. What I found is pretty horrifying. Blog inbound...
131
Lukas Beran @lukasberan.com · 09/10/2025
Chaos is exactly where our work begins. Our job is to bring clarity, calm, and momentum—fast. Watch the video from my colleague Adrian Hill on our Microsoft Security blog. www.microsoft.com/en-us/securi...
microsoft.com
Calm in the Chaos | Security Insider
When threat actors strike, Microsoft’s Incident Response team steps into the chaos, not as a cyber SWAT team, but as calm, collaborative partners.
010
Reposted by Lukas Beran
Nathan McNulty @nathanmcnulty.com · 07/10/2025
Did you know Entra ID Protection never automatically clears Medium or High risk? We either need to use Risk Based Conditional Access policies to remediate or an admin needs to manually remediate User risk = password reset Sign-in risk = require MFA learn.microsoft.com/...
2161
Lukas Beran @lukasberan.com · 06/10/2025
Microsoft introduced new Sentinel commitment tier for SMBs. The 50 GB commitment tier is available in public preview, with promotional pricing starting October 1, 2025, until March 31, 2026. Customers who sign up during this period will lock in promotional pricing until March 31, 2027.
110
Reposted by Lukas Beran
Nathan McNulty @nathanmcnulty.com · 25/09/2025
A 3 picture story of why you should default quarantine password protected files and enforce SmartScreen without allowing user bypass...
041
Lukas Beran @lukasberan.com · 20/09/2025
Seriously, Apple? That plastic-like white back on your silver flagship iPhone looks awful. This might be the ugliest iPhone ever, and I’m seriously thinking about returning it purely because of the design.
000
Reposted by Lukas Beran
Nathan McNulty @nathanmcnulty.com · 14/09/2025
IMHO - Worry less about how long tokens are valid for, worry more about protecting the tokens, both on the client and during authentication Obviously we need phishing resistant auth, but also focus on client hardening (app control, EDR, etc.) and VPN/ZTNA with enforced CAE
071
Reposted by Lukas Beran
Nathan McNulty @nathanmcnulty.com · 14/09/2025
Wow, I totally missed this change! Apparently since July, we've been able to use Asset rules management to use device details, like name, domain, OS, and other tags, to dynamically apply MDE-Management for MDE attach 😎 learn.microsoft.com/...
0101
Reposted by Lukas Beran
Nathan McNulty @nathanmcnulty.com · 10/09/2025
I love passkeys in Microsoft Authenticator, but rolling them out with Compliance and/or App Protection Policies has not been as easy as it should be... But I have good news - we can create a better experience without introducing significant gaps :)
nathanmcnulty.com
Improving passkey registration experiences
Lets see what we can do about minimizing passkey deployment issues with Compliance and App Protection Policy requirements :)
0134
Lukas Beran @lukasberan.com · 29/08/2025
𝗛𝗼𝘄 𝘁𝗼 𝗮𝘂𝘁𝗼𝗺𝗮𝘁𝗶𝗰𝗮𝗹𝗹𝘆 𝘂𝗽𝗱𝗮𝘁𝗲 𝗮𝗽𝗽𝗹𝗶𝗰𝗮𝘁𝗶𝗼𝗻𝘀 𝗼𝗻 𝗰𝗼𝗺𝗽𝘂𝘁𝗲𝗿𝘀 𝗶𝗻 𝗠𝗶𝗰𝗿𝗼𝘀𝗼𝗳𝘁 𝗜𝗻𝘁𝘂𝗻𝗲 Microsoft Intune does not have any built-in options for updating installed applications on Windows computers.
How to update applications using Patch My PC
110
Lukas Beran @lukasberan.com · 28/08/2025
Microsoft has been ranked #1 in the worldwide modern endpoint security market share for the third year in a row (IDC, 2024).
110
Reposted by Lukas Beran
Microsoft Threat Intelligence @threatintel.microsoft.com · 27/08/2025
The financially motivated threat actor Storm-0501 has continuously evolved to achieve sharpened focus on cloud-based TTPs as their primary objective shifted from deploying on-premises endpoint ransomware to using cloud-based ransomware tactics. msft.it/63326sZC6E
msft.it
Storm-0501’s evolving techniques lead to cloud-based ransomware | Microsoft Security Blog
Financially motivated threat actor Storm-0501 has continuously evolved their campaigns to achieve sharpened focus on cloud-based tactics, techniques, and procedures (TTPs). While the threat actor has been known for targeting hybrid cloud environments, their primary objective has shifted from deploying on-premises endpoint ransomware to using cloud-based ransomware tactics.
2107
Lukas Beran @lukasberan.com · 27/08/2025
For incident response to be successful, the proper tools and logging systems should be in place—but that is usually easier said than done.
110
Reposted by Lukas Beran
Ru Campbell @campbell.scot · 27/08/2025
Convenient reminder to stop what you’re doing and enforce browser extension allow listing.
042
Lukas Beran @lukasberan.com · 26/08/2025
We’re excited to announce the general availability of Windows Backup for Organizations!
110
Lukas Beran @lukasberan.com · 26/08/2025
Seamless SSO is a legacy setting only for very old and unsupported systems. If you have it turned on, go and turn it off. If you must keep it on, ať least rotate the kerberos deception key every month.
020
Lukas Beran @lukasberan.com · 25/08/2025
Get the latest Windows quality updates during the out-of-box experience (OOBE) by default. This much awaited improvement is coming to your eligible Microsoft Entra joined or Microsoft Entra hybrid joined devices running Windows 11, version 22H2 and later.
110
Lukas Beran @lukasberan.com · 25/08/2025
As enterprise defenses continue to mature, threat actors are shifting toward quieter, more efficient techniques. Attackers are increasingly using native tools and stealthy methods to operate under the radar.
100
Reposted by Lukas Beran
Merill Fernando 💚 @merill.net · 23/08/2025
One thing I always recommend when it comes to designing conditional acesss policies. Never use a block policy when the same outcome can be achieved with a grant policy. This blog post by Rakhesh is a good walthrough why... 👇
rakhesh.com
Teams AOSP Phone; Conditional Access Blocks vs Grant
Had an interesting issue at work that we resolved today. It’s probably not relevant to most folks, but I enjoyed getting to the bottom of it with a colleague (who came up with the eventual fi…
1226
Reposted by Lukas Beran
Harm Veenstra @harmveenstra.bsky.social · 22/08/2025
I like my Lenovo hardware, and I want to keep it up to date with the latest drivers, firmware, and other software updates. In this small blog post, I will show you how you can do that using the LSUClient module from Jantari. powershellisfun.com/2025/08/22/u... #PowerShell #Lenovo #Update
powershellisfun.com
PowerShell is fun :)Update your Lenovo using the LSUClient PowerShell module
I like my Lenovo hardware, and I want to keep it up to date with the latest drivers, firmware, and other software updates. In this small blog post, I will show you how you can do that using the LSU…
032
Reposted by Lukas Beran
Fabian Bader @fabian.bader.cloud · 22/08/2025
Token Protection in Microsoft Entra Conditional Access for Windows is now GA! 🎉 #EntraID #Token learn.microsoft.com/en-us/entra/...
061
Reposted by Lukas Beran
Ru Campbell @campbell.scot · 18/08/2025
New video: Why your Defender update settings are risky - update types: engines, platforms, intelligence - what is Microsoft’s 'Safe Deployment Practices' (SDP)? - update rings in Defender (not just Windows) - balancing rollout risk vs. protection WATCH: youtu.be/trQv__-Z9-8
011
Lukas Beran @lukasberan.com · 17/08/2025
Microsoft has announced the public preview of the Phishing Triage Agent in Microsoft Defender!
100
Reposted by Lukas Beran
Nathan McNulty @nathanmcnulty.com · 16/08/2025
On 9/15, Microsoft starts enforcing mandatory MFA for Azure CLI, Azure PowerShell, Azure mobile app, and your IAC tools (non-Service Principal based) I created a CA template you can import (report-only) to audit these apps (add your IAC ones): github.com/nathanmcn...
1122
Reposted by Lukas Beran
Ru Campbell @campbell.scot · 14/08/2025
Folks, working on two Defender books out this year and want to feature the best community tips. Defender for Endpoint In Depth 2nd Ed (w/ @Threatzman) Mastering Defender XDR 2nd Ed (w/ @Headburgh) So, drop your great MDE, MDO, MDI, MDA, and XDR tips here. Best get featured.
021
Lukas Beran @lukasberan.com · 14/08/2025
Make sure you are actively blocking weaker authentication options.
010
Lukas Beran @lukasberan.com · 13/08/2025
Cloud Forensics Tip: In the Azure era, preparing for the worst means enabling forensic readiness now—not after a breach strikes.
130
Lukas Beran @lukasberan.com · 13/08/2025
Check Nathan's options for break-glass account exclusions in conditional access policies.
041
Reposted by Lukas Beran
Fabian Bader @fabian.bader.cloud · 12/08/2025
Defender AV Platform v4.18.25070.5 ◽Enhanced Passive Mode Scanning Behavior ◽Improved Tamper Protection Handling ◽Digital Signature Verification Performance Boost ◽Refined ASR Rule Exclusion Processing #MDAV #MDE #ASR
051
Reposted by Lukas Beran
BleepingComputer @bleepingcomputer.com · 12/08/2025
Microsoft announced today that systems running Home and Pro editions of Windows 11 23H2 will stop receiving updates in three months.
bleepingcomputer.com
Windows 11 23H2 Home and Pro reach end of support in November
Microsoft announced today that systems running Home and Pro editions of Windows 11 23H2 will stop receiving updates in three months.
063
Reposted by Lukas Beran
Merill Fernando 💚 @merill.net · 12/08/2025
👋 Check out this new Microsoft Entra blog post 👇 Now Generally Available: Platform SSO for macOS with Microsoft Entra ID techcommunity.microsoft.com/t5/microsoft...
techcommunity.microsoft.com
Now Generally Available: Platform SSO for macOS with Microsoft Entra ID
Platform SSO for macOS builds on the Microsoft Enterprise SSO plug-in for easier, more secure sign-ins.
272
Reposted by Lukas Beran
Tony Redmond @office365itpros.com · 11/08/2025
Heads-up. If you have #Office365 E5 or #Microsoft365 licenses and use Microsoft Defender for Office 365, shared mailboxes must be licensed, and all user mailboxes need MDO licenses. The service description is clear, but who reads these things? office365itpros.com/2025/08/11/m...
office365itpros.com
Unexpected Microsoft Defender for Office 365 Costs
A question about shared mailboxes brought up the topic of licensing requirements when a tenant has Microsoft Defender for Office 365. The news is not good
064
Lukas Beran @lukasberan.com · 08/08/2025
Defender defaults are not secure enough. Make it as hard as possible for the bad guys!
000
Reposted by Lukas Beran
Nathan McNulty @nathanmcnulty.com · 07/08/2025
This is amazing! We can now query Graph Sign-in logs for events based on the audience :D Sometimes we need to know all tokens that can be used with an app, like Exchange Online, even if that wasn't the target resource Undocumented so far, but it appears to take OData queries 😎
1172
Reposted by Lukas Beran
Nathan McNulty @nathanmcnulty.com · 02/08/2025
While I'm on the topic of CIS Benchmarks... If you follow this one for Edge, you won't be able to use device compliance in your Conditional Access policies :-/
3172
Lukas Beran @lukasberan.com · 02/08/2025
Don’t blindly follow benchmarks. They’re a great starting point — but not the finish line. Always make sure you understand what you’re configuring and why it matters in your specific environment.
0102
Lukas Beran @lukasberan.com · 01/08/2025
The latest version of Microsoft Entra Connect brings an important update — application-based authentication is now generally available (no longer in preview). Even better, it’s now the default option for all new Entra Connect installations. A great step forward in securing hybrid identity!
120