Posts

How Entra Private Access Can Stop Hotel Hackers

Checking-in to your hotel soon? You may have read recently that hackers have unleashed a campaign against various hotels, resulting in compromise of work accounts. In this attack, hackers take advantage of manipulating users into providing their credentials and hijacking their session. Albeit this is nothing new, it is a reminder that strong authentication and security throughout the pipeline is crucial to ensure a user's security. What is different however, is Microsoft Entra Private Access. In this article, I'll explain what happened, and how Entra Private Access could've protected these end users. What Happened? On July 24th, a report from BleepingComputer highlighted that various hotel chains have become victim of attackers compromising Microsoft 365 accounts through DNS Poisoning. Attackers first gained admin access to hotel or conference-center Wi-Fi appliances through exposed management interfaces, weak or reused credentials, and unpatched firmware. Once they we...

HEADS UP: The 2027 Microsoft MFA Shift Is Coming - What You Need To Do Now

Microsoft is making one of its most significant identity security changes in years: retiring Microsoft‑provided SMS and voice authentication on February 1, 2027 . For many organizations, this will be a major transition and the timeline is tighter than it looks. If you’re an IT admin, identity engineer, or security leader, this shift isn’t just a technical update. It’s a strategic moment to modernize your authentication stack, reduce risk, and prepare your users for a passwordless future. Below is a clear, actionable breakdown of what’s changing and how to get ahead of it. Why Microsoft Is Retiring SMS & Voice MFA SMS and voice codes have long been the “easy button” for MFA enrollment. But they’re also the least secure : Vulnerable to SIM swapping Easily intercepted through phishing Increasingly targeted by AI‑powered social engineering Difficult to guarantee across global telecom networks Microsoft’s data shows that modern phishing kits can bypass SMS/voice MFA with alarming s...

Windows BYOD Is Awesome- Here's Why and How

Image
For years, organizations have asked a simple question: Why can every platform except Windows do lightweight BYOD? In July 2026, Microsoft finally delivered the missing piece. The new BYOD Support for Windows (now generally available) brings Windows into the modern identity era. No domain join. No Intune enrollment. No heavy-handed device management. Just clean, identity-first access for unmanaged Windows devices. And it’s a bigger shift than most people realize. Why This Matters Organizations have been stuck between two extremes: Fully managed Windows devices (great security, heavy overhead) Guest access with no device context (lightweight, but limited and risky) The new BYOD Windows model creates a third path: Identity-driven access with lightweight device registration. This means users-internal or external can register their Windows device with Entra and securely access corporate resources without being forced into full management. It’s the same model that’s worked for iOS, Andro...