Skip to content
Cloud Security DeskSearch
Menu

Evidence search

Search

Search titles, summaries, topics, providers, authors, and the full open-access corpus.

Results for “entra”

36 publications
Technical guideSource-based analysis

Protect and recover your AWS root account

Protect AWS root access with MFA, current recovery contacts, separate daily administration, and a clear plan for Organizations member accounts.

Identity & access · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Keep an S3 bucket private with Block Public Access

Enable S3 Block Public Access while preserving approved readers. Review the four settings, private CloudFront origins, and practical access tests.

Workload security · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Get an alert when Google Cloud project access changes

Build a Google Cloud log-based alert for project IAM changes, verify the filter and notification channel, and understand incident limits.

Detection & response · Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Give Azure readers access to one resource group

Assign Reader without granting write access or assuming it grants data access.

Identity & access · Azure · By Cloud Security Desk
Technical guideSource-based analysis

Read an Azure Key Vault secret from a VM without a password

Set up one system-assigned VM identity and a vault-scoped secret permission.

Identity & access · Azure · By Cloud Security Desk
Technical guideSource-based analysis

Get an Azure alert when a role assignment changes

Detect successful RBAC changes and test alert delivery without expanding a production role.

Detection & response · Azure · By Cloud Security Desk
Technical guideSource-based analysis

Check and stop anonymous access to Azure blobs

Understand account and container settings and prove both anonymous denial and intended app access.

Workload security · Azure · By Cloud Security Desk
Technical guideSource-based analysis

Connect to Azure OpenAI without an API key

Prove Entra-based inference with a scoped runtime identity before disabling local authentication.

AI systems · Azure · By Cloud Security Desk
Technical guideSource-based analysis

Recover a deleted Azure blob with soft delete

Choose the right recovery action for a blob, version or container and verify restored bytes.

Resilience · Azure · By Cloud Security Desk
Technical guideSource-based analysis

Design application authorization before writing Cedar policies

Define business actions, trustworthy entities and tenant boundaries before writing Cedar policies, then make the application responsible for enforcing the resulting decision.

Identity & access · AWS / Cedar · By Cloud Security Desk
Technical guideSource-based analysis

Bind confidential GPU inference to a verified key release

Require composite evidence, owner policy and verified recipient binding before confidential inference receives protected key material.

AI systems · NVIDIA / Azure · By Cloud Security Desk
Technical guideSource-based analysis

Set explicit trust boundaries for Entra partner access

Accepting another tenant’s authentication claims is a specific trust decision, not blanket approval of its users, devices or access to your applications.

Identity & access · Microsoft · By Cloud Security Desk
Technical guideSource-based analysis

Catch late security events without replaying every alert

Separate event time, ingestion time and execution health so delayed records can be evaluated without turning every broader lookback into a replay.

Detection & response · Microsoft Sentinel / Microsoft Defender · By Cloud Security Desk
Technical guideSource-based analysis

Diagnose NAT gateway port exhaustion before adding capacity

Match allocation errors to destination tuples and gateway mode before changing connection pools, addresses or routes.

Resilience · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Find the Purview audit history your investigation can still retrieve

Resolve Purview audit availability at the record level by separating actor eligibility, retention policy, collection status, investigator scope and export limits.

Detection & response · Microsoft Purview / Microsoft 365 · By Cloud Security Desk
Technical guideSource-based analysis

Restrict device code sign-in without breaking approved clients

Restrict device-code authentication through an explicit client and resource policy, and test the tracked sessions that can outlive the initial browser approval.

Identity & access · Microsoft / IETF · By Cloud Security Desk
Research reportSource-based analysis

Find the shared dependencies behind a cloud outage

Use the June 2025 Google Cloud and Cloudflare reports to review shared runtime, control, identity and recovery dependencies without turning one outage into a provider ranking.

Resilience · Google Cloud / Cloudflare / AWS · By Cloud Security Desk
Technical guideSource-based analysis

Passkey deployment needs a recovery design

A workforce passkey rollout needs a recovery contract before broad enforcement. Separate credential custody, enrollment evidence and application sessions.

Identity & access · NIST / FIDO Alliance / Microsoft Entra · By Cloud Security Desk
Technical guideSource-based analysis

Workload federation across clouds needs separate trust decisions

Cross-cloud federation adds trust decisions, not a portable permission system. Map each credential and resource grant before moving a runtime workload.

Identity & access · AWS / Google Cloud / Microsoft Entra · By Cloud Security Desk
Technical guideSource-based analysis

Recovery objectives that match the cloud service

Define the business function, outage clock, recoverable data and dependency assumptions before choosing a cloud disaster-recovery architecture.

Resilience · AWS / Azure / Google Cloud / NIST · By Cloud Security Desk
Technical guideSource-based analysis

Entra emergency access that survives normal sign-in failure

A second administrator account does not prove an independent recovery path. Test the credential, workstation, policy and alert dependencies together.

Identity & access · Microsoft Entra · By Cloud Security Desk
Technical guideSource-based analysis

Make secret rotation reach every running application

Secret managers, mounted files, application memory and connection pools can disagree about the active credential. Test each stage before calling rotation complete.

Workload security · Kubernetes / AWS / Azure / Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Rotate Entra application certificates with proof of adoption

A renewed certificate can exist in Key Vault while a running client still uses the old key. Define the evidence that makes application rotation complete.

Identity & access · Microsoft Entra / Azure Key Vault · By Cloud Security Desk
Technical guideSource-based analysis

Short SSH certificates still need explicit access boundaries

An SSH certificate supplies bounded identity claims. The issuer, server, client and incident operator still make separate access decisions.

Identity & access · OpenSSH · By Cloud Security Desk