Categories
Cloud advice Service announcements

Microsoft Entra ID Authentication Methods Migration Guidance

 Overview Microsoft is retiring the legacy MFA and SSPR policies by 30th September 2025 as part of its modernisation path. Migrating to the new Authentication Methods policy offers more precision, central control, and futureproof cloud environment.  The new Microsoft Entra ID authentication method policy offers a unified, modern way to manage your organisation’s authentication methods, […]

Categories
Cloud advice Cloud Security

Securing Break Glass Accounts in Microsoft 365

Introduction Break glass accounts are your emergency lifeline, providing privileged access when the identity system fails and no one can sign in to access organisation resources due to outages, breaches, lockouts, or misconfiguration. These accounts are critical for maintaining control and continuity but must be tightly secured, rarely used, and continuously monitored. ⚠️ Why They […]

Categories
Cloud advice

VM Hardening: Finding the Sweet Spot Between Security and Functionality

Introduction In today’s threat landscape, cloud based VM hardening is a best practice that’s actively recommended by industry frameworks and security tools, including CIS Benchmarks, vulnerability scanners like Nessus, cloud-native tools/frameworks such as AWS Inspector, Azure’s Defender for Cloud and more! Just to clarify, virtual machine hardening is essentially the process of securing virtualized environments […]

Categories
Cloud advice

Ransomware – a clear and present danger

I am hearing increasing reports of UK academic institutions suffering from ramsomware attacks. These are now happening much more frequently than in the past and the consequences, in some cases at least, can be devastating. It is no longer a question of if you will be attacked but when you will be attacked and how […]

Categories
Cloud advice

Easily secure your application with Jisc’s Managed Website Protection

A recording of the recent session run by Paul Martin of Fortinet at the Jisc Security Conference. The session covers Jisc’s Managed Website Protection service and how that helps institutions and organizations mitigate against the evolving security threat landscape.

Categories
Cloud advice

The public cloud shared responsibility model – what does it mean in practice?

A recording of the recent session run by Simon Dix of the Jisc cloud solutions team at the Jisc Security Conference. The session covers the public cloud shared responsibility model in relation to the roles and responsibilities of both cloud vendors and cloud consumers.

Categories
Cloud advice

Optimising Microsoft 365 security and governance

A recording of the recent session run by Richard Jackson and Colm Blake of the Jisc cloud solutions team at the Jisc Security Conference. The session covers best practices for the configuration of Office 365, Windows 10/11 and the Enterprise Mobility and Security (EMS) suite.

Categories
Service announcements

Managed Website Protection – a Jisc cloud WAF

In Jisc Cloud Solutions one of our most common recommendations for securing web applications is to ensure that you use a Web Application Firewall in order to block malicious attacks. Of course Web Application Firewalls are not silver bullets – they should be deployed alongside services such as IPS and traditional firewalls to ensure defence […]

Categories
Cloud advice

Azure Active Directory – Issues with User Consent

This blog has been written in collaboration with the Jisc Trust & Identity and Cyber Security teams. Jisc has recently become aware of a potential security risk associated with the default Azure Active Directory (AAD) security settings that are commonly in place across our membership. If your organisation uses AAD (or plans to use it), […]

Categories
Cloud advice

Remote access and Zero Trust

Zero Trust is a concept which has been around for at least the last decade. Whilst organisations were aware of it and implementing aspects of a Zero Trust architecture, it was not until 2020, for obvious reasons, that pretty much every organisation was forced into thinking about its adoption; responding to a distributed and fragmented […]