Device code phishing is a clever Microsoft 365 attack that can steal an authenticated session without stealing your password.** An attacker starts a login, sends you the device code, and tricks you into completing the sign-in on Microsoft's genuine website. Even MFA may not save you because you're unknowingly approving the attacker's session. The best defence is simple: **if you didn't start the login, don't finish it.
Microsoft Is Removing SMS MFA in 2027: It’s Time to Move Users to Passkeys
That six-digit code you receive by text message when signing into Microsoft 365 feels secure because it arrives instantly. But SMS-based MFA is no longer considered a strong security method. Attackers can bypass SMS MFA through phishing websites, SIM swapping, or intercepting text messages. It is still better than having no MFA at all, but... Continue Reading →
Your Browser Is Now Your Office. So Why Isn’t It Secured?
When people think about Microsoft 365 security, they usually think about things like: Multi-Factor Authentication (MFA) Strong passwords Microsoft Defender Conditional Access Email protection All of these are important. But there is one piece of the puzzle that many businesses completely ignore. The web browser. Your Browser Has Become Your Workplace Think about your average... Continue Reading →
Choosing the Right Microsoft AI Tool Without Wasting Money
Microsoft offers a growing range of AI tools, but many businesses struggle to know which one they actually need. Terms like Copilot, Agentic AI, Copilot Studio, and MCP are often used interchangeably, even though they serve very different purposes. Choosing the wrong tool can lead to unnecessary costs and complexity. The key is to start with the simplest solution that meets your needs, then move to more advanced tools only as your business grows.
Stop Sharing Your Microsoft 365 Global Admin Account (Before It Costs You a Client)
Shared Microsoft 365 global admin accounts are a security risk. Learn how named accounts, phishing-resistant MFA, GDAP & LAPS protect your MSP clients.
Who Let That Device In? Managing Intune the Right Way
Your Intune device inventory should contain trusted company devices, not random personal hardware. In this article, we'll look at how Intune determines device ownership, why enrollment restrictions matter, and how to stop unmanaged devices from cluttering your environment. You'll also learn why Conditional Access alone isn't enough and how combining it with proper enrollment controls creates a cleaner, more secure Microsoft 365 tenant.
Who Did You Let In? Guest Access in Microsoft 365, Explained Properly
Guest access in Microsoft 365 is easy to grant and easy to forget. This post looks at why guest accounts quietly pile up in your Entra ID tenant, why "we trust them" isn't enough, and the one simple check every business should do today.
Why ‘We Have MFA’ Doesn’t Mean You’re Secure
Most MFA setups are not equally secure. Different authentication methods sit on a spectrum, from easily phished passwords and SMS codes to phishing-resistant passkeys and FIDO2 security. This visual breaks down how each method actually fails in real-world attacks, and why the strongest options eliminate entire attack categories instead of just reducing risk.
Passkeys: Strong Security That Only Works If People Actually Use It
Passkeys are a stronger, passwordless way to log in, but their real impact depends on one thing: people actually using them. Until adoption becomes the default, security improvements will remain limited.
Stop Token Theft: Why MFA Alone Is No Longer Enough for Microsoft 365
Most businesses believe MFA is enough to protect Microsoft 365 accounts. It isn’t. Attackers are now bypassing traditional authentication by stealing session tokens directly from user devices, giving them silent access to emails, files, and company data without triggering MFA prompts. In this article, we break down how token theft works, why it’s becoming one of the fastest-growing cyber threats, and the practical Microsoft 365 security strategies every organization should implement before it becomes a real incident.