CIA Brief 20250315

image

How-To Sync EntraID Group Memberships Into Any System –

https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/how-to-sync-entraid-group-memberships-into-any-system/4383082

Microsoft Security Implementation Proof of Concept by Lighthouse with Microsoft 365 Defender –

https://www.youtube.com/watch?v=rxiVirns1D4

Announcing a Limited Preview of GPT-4.5 in Copilot Studio –

https://www.microsoft.com/en-us/microsoft-copilot/blog/copilot-studio/announcing-limited-preview-gpt-4-5-microsoft-copilot-studio/

Phishing campaign impersonates Booking .com, delivers a suite of credential-stealing malware –

https://www.microsoft.com/en-us/security/blog/2025/03/13/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware/

Copilot supports communication in every style –

https://techcommunity.microsoft.com/blog/Microsoft365InsiderBlog/copilot-supports-communication-in-every-style/4386393

Securing Your Nonprofit Environment (Part 2): Best Practices to Secure Your Admin Accounts –

https://techcommunity.microsoft.com/blog/nonprofittechies/securing-your-nonprofit-environment-part-2-best-practices-to-secure-your-admin-a/4385305

Jailbreaking is (mostly) simpler than you think –

https://msrc.microsoft.com/blog/2025/03/jailbreaking-is-mostly-simpler-than-you-think/

Improve your DLP maturity with DLP Analytics –

https://techcommunity.microsoft.com/blog/microsoft-security-blog/improve-your-dlp-maturity-with-dlp-analytics/4392655

Take Flight with Microsoft Security Copilot Flight School –

https://techcommunity.microsoft.com/blog/securitycopilotblog/take-flight-with-microsoft-security-copilot-flight-school/4391712

Defending Against OAuth-Based Attacks with Automatic Attack Disruption –

https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/defending-against-oauth-based-attacks-with-automatic-attack-disruption/4384381

Boost customer engagement with live chat in Microsoft Teams –

https://www.youtube.com/watch?v=y_fTX0E08BU

Introducing Microsoft Entra Health alerts: An enhancement to tenant health monitoring –

https://techcommunity.microsoft.com/blog/microsoft-entra-blog/introducing-microsoft-entra-health-alerts-an-enhancement-to-tenant-health-monito/4352583

New XCSSET malware adds new obfuscation, persistence techniques to infect Xcode projects –

https://www.microsoft.com/en-us/security/blog/2025/03/11/new-xcsset-malware-adds-new-obfuscation-persistence-techniques-to-infect-xcode-projects/

Built-in report button is available in Microsoft Outlook across platforms –

https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/built-in-report-button-is-available-in-microsoft-outlook-across-platforms/4388434

Blog Series: Charting Your Path to Cyber Resiliency –

https://techcommunity.microsoft.com/blog/microsoft-security-blog/blog-series-charting-your-path-to-cyber-resiliency/4390355

After hours

Gemini Robotics: Bringing AI to the physical world – https://www.youtube.com/watch?v=4MvGnmmP3c0

Editorial

If you found this valuable, the I’d appreciate a ‘like’ or perhaps a donation at https://ko-fi.com/ciaops. This helps me know that people enjoy what I have created and provides resources to allow me to create more content. If you have any feedback or suggestions around this, I’m all ears. You can also find me via email director@ciaops.com and on X (Twitter) at https://www.twitter.com/directorcia.

If you want to be part of a dedicated Microsoft Cloud community with information and interactions daily, then consider becoming a CIAOPS Patron – www.ciaopspatron.com.

Watch out for the next CIA Brief next week

Need to Know podcast–Episode 341

In this episode I provide the benefits that become available once you add and Azure subscription to your Microsoft environment. From pay as you go options with Copilot and SharePoint all the way through adding more security to your environment, Azure contain a range of features that you should consider. I’ll also bring you up to date with all the latest news from the Microsoft Cloud, so listen along and enjoy.

Brought to you by www.ciaopspatron.com

you can listen directly to this episode at:

https://ciaops.podbean.com/e/episode-341-why-add-azure/

Subscribe via iTunes at:

https://itunes.apple.com/au/podcast/ciaops-need-to-know-podcasts/id406891445?mt=2

or Spotify:

https://open.spotify.com/show/7ejj00cOuw8977GnnE2lPb

Don’t forget to give the show a rating as well as send me any feedback or suggestions you may have for the show.

Resources

@directorcia

Join my shared channel

CIAOPS merch store

Become a CIAOPS Patron

CIAOPS Blog

CIAOPS Brief

CIAOPSLabs

Support CIAOPS

Microsoft 365 E5 Security is now available as an add-on to Microsoft 365 Business Premium

Microsoft Technical Takeoff: Windows + Intune

Azure Lighthouse support for MSSP use of Security Copilot Sentinel scenarios in Public Preview

Get the most out of OneNote with these little-known features

Edit your name in Teams meetings

Rethinking remote assistance security in a Zero Trust world

Introducing Exchange Online Tenant Outbound Email Limits

CIA Brief 20250308

image

Microsoft Technical Takeoff: Windows + Intune –

https://techcommunity.microsoft.com/event/techcommunitylive/microsoft-technical-takeoff-windows–intune/4304008

Strengthening Cloud Compliance and Governance with Microsoft Defender CSPM –

https://techcommunity.microsoft.com/blog/MicrosoftDefenderCloudBlog/strengthening-cloud-compliance-and-governance-with-microsoft-defender-cspm/4385215

6 ways AI is making a difference in the world –

https://news.microsoft.com/source/features/ai/6-ways-ai-is-making-a-difference-in-the-world/?ocid=msftnews_x

Azure Lighthouse support for MSSP use of Security Copilot Sentinel scenarios in Public Preview –

https://techcommunity.microsoft.com/blog/SecurityCopilotBlog/azure-lighthouse-support-for-mssp-use-of-security-copilot-sentinel-scenarios-in-/4384386

Malvertising campaign leads to info stealers hosted on GitHub –

https://www.microsoft.com/en-us/security/blog/2025/03/06/malvertising-campaign-leads-to-info-stealers-hosted-on-github/

Edit your display name in Teams meetings –

https://techcommunity.microsoft.com/blog/Microsoft365InsiderBlog/edit-your-display-name-in-teams-meetings/4389359

Who’s Using Copilot? | HYPE Customer Story –

https://www.youtube.com/watch?v=nD9YZjARVWk

Business efficiency: How a small business operates like a corporation –

https://www.youtube.com/watch?v=Zwl6z6UZgeQ

Microsoft 365 E5 Security is now available as an add-on to Microsoft 365 Business Premium –

https://techcommunity.microsoft.com/blog/microsoft365businessblog/microsoft-365-e5-security-is-now-available-as-an-add-on-to-microsoft-365-busines/4388436

Silk Typhoon targeting IT supply chain –

https://www.microsoft.com/en-us/security/blog/2025/03/05/silk-typhoon-targeting-it-supply-chain/

What is cybersecurity analytics? –

https://www.microsoft.com/en-us/security/business/security-101/what-is-cybersecurity-analytics

Evolving small business with Microsoft Teams and Copilot –

https://www.youtube.com/watch?v=lDJzF0lZ-7A

Newsletters in Outlook (Preview) –

https://support.microsoft.com/en-us/office/newsletters-in-outlook-preview-b35566e6-d319-450d-8930-86e483cda3ee

Windows 365 Disaster Recovery Plus extends Cloud PC resilience –

https://techcommunity.microsoft.com/blog/windows-itpro-blog/windows-365-disaster-recovery-plus-extends-cloud-pc-resilience/4387492

Available today: DeepSeek R1 7B & 14B distilled models for Copilot+ PCs via Azure AI Foundry – further expanding AI on the edge –

https://blogs.windows.com/windowsdeveloper/2025/03/03/available-today-deepseek-r1-7b-14b-distilled-models-for-copilot-pcs-via-azure-ai-foundry-further-expanding-ai-on-the-edge/

Disrupting a global cybercrime network abusing generative AI –

https://blogs.microsoft.com/on-the-issues/2025/02/27/disrupting-cybercrime-abusing-gen-ai/

After hours

Formula 1: Drive To Survive Season 7 Official Trailer | Netflix – https://www.youtube.com/watch?v=rZlzeKPFTco

Editorial

If you found this valuable, the I’d appreciate a ‘like’ or perhaps a donation at https://ko-fi.com/ciaops. This helps me know that people enjoy what I have created and provides resources to allow me to create more content. If you have any feedback or suggestions around this, I’m all ears. You can also find me via email director@ciaops.com and on X (Twitter) at https://www.twitter.com/directorcia.

If you want to be part of a dedicated Microsoft Cloud community with information and interactions daily, then consider becoming a CIAOPS Patron – www.ciaopspatron.com.

Watch out for the next CIA Brief next week

CIAOPS Need to Know Microsoft 365 Webinar – March

laptop-eyes-technology-computer_thumb

Join me for the free monthly CIAOPS Need to Know webinar. Along with all the Microsoft Cloud news we’ll be taking a look at Purview (aka Compliance) in Microsoft 365.

Shortly after registering you should receive an automated email from Microsoft Teams confirming your registration, including all the event details as well as a calendar invite.

You can register for the regular monthly webinar here:

March Webinar Registrations

(If you are having issues with the above link copy and paste – https://bit.ly/n2k2503)

The details are:

CIAOPS Need to Know Webinar – March 2025
Friday 28th of March 2025
11.00am – 12.00am Sydney Time

All sessions are recorded and posted to the CIAOPS Academy.

The CIAOPS Need to Know Webinars are free to attend but if you want to receive the recording of the session you need to sign up as a CIAOPS patron which you can do here:

http://www.ciaopspatron.com

or purchase them individually at:

http://www.ciaopsacademy.com/

Also feel free at any stage to email me directly via director@ciaops.com with your webinar topic suggestions.

I’d also appreciate you sharing information about this webinar with anyone you feel may benefit from the session and I look forward to seeing you there.

CIA Brief 20250301

image

Disrupting a global cybercrime network abusing generative AI –

https://blogs.microsoft.com/on-the-issues/2025/02/27/disrupting-cybercrime-abusing-gen-ai/

Microsoft completes landmark EU Data Boundary, offering enhanced data residency and transparency –

https://blogs.microsoft.com/on-the-issues/2025/02/26/microsoft-completes-landmark-eu-data-boundary-offering-enhanced-data-residency-and-transparency/

Announcing Free, Unlimited Access to Think Deeper and Voice –

https://www.microsoft.com/en-us/microsoft-copilot/blog/2025/02/25/announcing-free-unlimited-access-to-think-deeper-and-voice/

Maximizing AI’s potential: Insights from Microsoft leaders on how to get the most from generative AI –

https://www.microsoft.com/en-us/microsoft-cloud/blog/2025/02/18/maximizing-ais-potential-insights-from-microsoft-leaders-on-how-to-get-the-most-from-generative-ai/

Move files to OneDrive –

https://www.youtube.com/watch?v=a2hq63Yfj3Y

Safeguarding AI against ‘jailbreaks’ and other prompt attacks –

https://news.microsoft.com/source/features/ai/safeguarding-ai-against-jailbreaks-and-other-prompt-attacks/

Focus on what matters most with Microsoft 365 Copilot –

https://www.youtube.com/watch?v=0-_xncOsEds

After hours

Gibberlink – https://www.youtube.com/watch?v=Z3yQHYNXPws

Editorial

If you found this valuable, the I’d appreciate a ‘like’ or perhaps a donation at https://ko-fi.com/ciaops. This helps me know that people enjoy what I have created and provides resources to allow me to create more content. If you have any feedback or suggestions around this, I’m all ears. You can also find me via email director@ciaops.com and on X (Twitter) at https://www.twitter.com/directorcia.

If you want to be part of a dedicated Microsoft Cloud community with information and interactions daily, then consider becoming a CIAOPS Patron – www.ciaopspatron.com.

Watch out for the next CIA Brief next week

Need to Know podcast–Episode 340

I take a look at something many overlook when it comes to security in their Microsoft 365 environment – Exposure score. In essence it is like a targeted Secure Score for a particular threat like Business Email Compromise. There is also news and updates from the Microsoft Cloud so listen along and review the show notes for more information.

Brought to you by www.ciaopspatron.com

you can listen directly to this episode at:

https://ciaops.podbean.com/e/episode-340-exposure-management/

Subscribe via iTunes at:

https://itunes.apple.com/au/podcast/ciaops-need-to-know-podcasts/id406891445?mt=2

or Spotify:

https://open.spotify.com/show/7ejj00cOuw8977GnnE2lPb

Don’t forget to give the show a rating as well as send me any feedback or suggestions you may have for the show.

Resources

@directorcia

Join my shared channel

CIAOPS merch store

Become a CIAOPS Patron

CIAOPS Blog

CIAOPS Brief

CIAOPSLabs

Support CIAOPS

The way to control EWS usage in Exchange Online is changing

New Microsoft-managed policies to raise your identity security posture

Storm-2372 conducts device code phishing campaign

Block malicious command lines with Microsoft Defender for Endpoint

Clipchamp: Elevating work communication with seamless video creation in Copilot

Sharing with Microsoft Whiteboard

AI agents at work: The new frontier in business automation

Copilot learning hub

New Certification for Microsoft information security administrators

What is Security Exposure Managenet?

CIA Brief 20250222

image

Quick Setup – Microsoft Entra Verified ID –

https://www.youtube.com/watch?v=YnukKchoN28

Talk and translate on-the-go with Copilot –

https://www.youtube.com/watch?v=P4lKB5Yz9Sg

Amtrak improve efficiency and safety with Microsoft Power Platform –

https://www.youtube.com/watch?v=292tyXQLie0

The way to control EWS usage in Exchange Online is changing –

https://techcommunity.microsoft.com/blog/Exchange/the-way-to-control-ews-usage-in-exchange-online-is-changing/4383083

Enhanced data control while submitting Microsoft 365 Copilot feedback –

https://techcommunity.microsoft.com/blog/Microsoft365InsiderBlog/enhanced-data-control-while-submitting-microsoft-365-copilot-feedback/4382668

New Microsoft-managed policies to raise your identity security posture –

https://techcommunity.microsoft.com/blog/microsoft-entra-blog/new-microsoft-managed-policies-to-raise-your-identity-security-posture/4286758

Clipchamp: Elevating work communication with seamless video creation in Copilot –

https://techcommunity.microsoft.com/blog/microsoft_365blog/clipchamp-elevating-work-communication-with-seamless-video-creation-in-copilot/4375660

With Copilot agents, Pets at Home unleashes an AI revolution –

https://news.microsoft.com/source/emea/features/with-copilot-agents-pets-at-home-unleashes-an-ai-revolution/

Majorana 1 Explained: The Path to a Million Qubits –

https://www.youtube.com/watch?v=wSHmygPQukQ

Sharing with Microsoft Whiteboard –

https://www.youtube.com/watch?v=RXAo9JGZS44

Facilitating sessions with Microsoft Whiteboard –

https://www.youtube.com/watch?v=UNqtsIqNK7s

Get help or support as an admin –

https://www.youtube.com/watch?v=0s1Cof06VfA

Seamless Security: Smartcard Logon from Entra-Only Machines to domain-joined Servers or AVDs –

https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/seamless-security-smartcard-logon-from-entra-only-machines-to-domain-joined-serv/4381789

Minimize email drafts in Outlook for Android and iOS to easily task switch –

https://techcommunity.microsoft.com/blog/microsoft365insiderblog/minimize-email-drafts-in-outlook-for-android-and-ios-to-easily-task-switch/4375165

How to protect against Device Code Flow abuse (Storm-2372 attacks) and block the authentication flow –

https://jeffreyappel.nl/how-to-protect-against-device-code-flow-abuse-storm-2372-attacks-and-block-the-authentication-flow/

After hours

Introducing Helix – https://www.youtube.com/watch?v=Z3yQHYNXPws

Editorial

If you found this valuable, the I’d appreciate a ‘like’ or perhaps a donation at https://ko-fi.com/ciaops. This helps me know that people enjoy what I have created and provides resources to allow me to create more content. If you have any feedback or suggestions around this, I’m all ears. You can also find me via email director@ciaops.com and on X (Twitter) at https://www.twitter.com/directorcia.

If you want to be part of a dedicated Microsoft Cloud community with information and interactions daily, then consider becoming a CIAOPS Patron – www.ciaopspatron.com.

Watch out for the next CIA Brief next week

February Microsoft 365 Webinar resources

image

The slides from this month’s webinar are available at:

https://github.com/directorcia/general/blob/master/Presentations/Need%20to%20Know%20Webinars/202502.pdf

If you are not a CIAOPS patron you want to view or download a full copy of the video from the session you can do so here:

http://www.ciaopsacademy.com.au/p/need-to-know-webinars

Watch out for next month’s webinar.