<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Archives - MODIVA</title>
	<atom:link href="https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/category/security/</link>
	<description>Become a Tech Leader with Guided Learning</description>
	<lastBuildDate>Mon, 22 Dec 2025 16:42:19 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.2</generator>

<image>
	<url>/wp-content/uploads/2025/02/cropped-fav-150x150.webp</url>
	<title>Security Archives - MODIVA</title>
	<link>https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/category/security/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>What is Passwordless Authentication?</title>
		<link>https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/what-is-passwordless-authentication/</link>
					<comments>https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/what-is-passwordless-authentication/#respond</comments>
		
		<dc:creator><![CDATA[Patrick]]></dc:creator>
		<pubDate>Tue, 31 Oct 2023 13:00:56 +0000</pubDate>
				<category><![CDATA[Modern Work]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://modiva.org/?p=8272</guid>

					<description><![CDATA[<p>Passwordless authentication is an authentication method that allows a user to gain access to an application or IT system without [&#8230;]</p>
<p>The post <a href="https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/what-is-passwordless-authentication/">What is Passwordless Authentication?</a> appeared first on <a href="https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net">MODIVA</a>.</p>
]]></description>
			<style id="elementor-post-8272">.elementor-8272 .elementor-element.elementor-element-12061f30{--display:flex;}.elementor-widget-text-editor{font-family:var( --e-global-typography-text-font-family ), Sans-serif;font-weight:var( --e-global-typography-text-font-weight );color:var( --e-global-color-text );}.elementor-widget-text-editor.elementor-drop-cap-view-stacked .elementor-drop-cap{background-color:var( --e-global-color-primary );}.elementor-widget-text-editor.elementor-drop-cap-view-framed .elementor-drop-cap, .elementor-widget-text-editor.elementor-drop-cap-view-default .elementor-drop-cap{color:var( --e-global-color-primary );border-color:var( --e-global-color-primary );}</style>							<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="8272" class="elementor elementor-8272">
				<div class="elementor-element elementor-element-12061f30 e-con-full e-flex e-con e-parent" data-id="12061f30" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-699d177e exad-sticky-section-no exad-glass-effect-no elementor-widget elementor-widget-text-editor" data-id="699d177e" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									
<p class="wp-block-paragraph">Passwordless authentication is an authentication method that allows a user to gain access to an application or IT system without entering a password or answering security questions. It uses other alternative methods to verify the user&#8217;s identity. </p>



<p class="wp-block-paragraph">Passwordless Authentication is often used in conjunction with Multi-Factor Authentication (MFA) and Single Sign-On solutions to improve the user experience, strengthen security, and reduce IT operations expense and complexity.&nbsp;</p>



<p class="wp-block-paragraph">The several common methods of passwordless authentication are:&nbsp;</p>



<ol class="wp-block-list" start="1">
<li><strong>Windows Hello for Business:</strong> Ideal for information workers who have their own designated Windows PC. It uses biometric and PIN credentials tied directly to the user’s PC, ensuring access only to the owner.&nbsp;</li>
</ol>



<ol class="wp-block-list" start="2">
<li><strong>Email or SMS-Based Authentication:</strong> In this method, a one-time code is sent to the user&#8217;s email address or mobile phone via SMS. The user then enters this code to verify their identity.&nbsp;</li>
</ol>



<ol class="wp-block-list" start="3">
<li><strong>Mobile App Authentication:</strong> Many passwordless systems rely on mobile apps to authenticate users. Users install an authentication app on their smartphones, and when they attempt to log in, they receive a notification or a one-time code on their device, which they approve to complete the authentication.&nbsp;</li>
</ol>



<ol class="wp-block-list" start="4">
<li><strong>Hardware Tokens:</strong> Passwordless authentication can involve the use of hardware tokens or security keys, which are physical devices that users carry with them. These devices generate one-time codes or cryptographically sign authentication requests, adding a strong layer of security.&nbsp;</li>
</ol>



<ol class="wp-block-list" start="5">
<li><strong>QR Codes:</strong> A QR code is displayed on the login screen, and users scan it using a mobile app to authenticate themselves.&nbsp;</li>
</ol>



<p class="wp-block-paragraph"></p>



<h3 class="wp-block-heading"><strong>Navigating the Password Challenge</strong> </h3>



<p class="wp-block-paragraph">Modern digital workers use a wide range of applications to carry out their duties. Users are compelled to remember and keep track of an overwhelming variety of regularly changing passwords. Due to password sprawl, many users take risky shortcuts like using the same password for all applications, using weak passwords, repeating passwords, or posting passwords on sticky notes. Bad actors can mount cyberattacks and steal sensitive data by taking advantage of careless password management procedures. In fact, compromised account credentials are a leading cause of data breaches.&nbsp;</p>



<p class="wp-block-paragraph">Simple authentication methods that require only username and password combinations are inherently vulnerable. Attackers can guess or steal credentials and gain access to sensitive information and IT systems using a variety of techniques, including:&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Phishing</strong> – using bogus emails or text messages to trick a victim into replying with their credentials. </li>



<li><strong>Keylogging</strong> – installing malware on a computer to capture username/password keystrokes. </li>



<li><strong>Brute force methods</strong> &#8211; Using software to create random username/password combinations or taking advantage of widely used weak passwords like 123456. </li>



<li><strong>Credential stuffing</strong> – Using compromised or leaked credentials from one account to access another (users frequently use the same login and password across many accounts). </li>



<li><strong>Man-in-the-middle attacks</strong> – intercepting communications streams (over public Wi-Fi, for example) and replaying credentials. </li>
</ul>



<p class="wp-block-paragraph"></p>



<h3 class="wp-block-heading"><strong>Benefits of Passwordless Authentication</strong> </h3>



<p class="wp-block-paragraph">Passwordless Authentication provides a variety of functional and business benefits. It helps organizations:&nbsp;</p>



<p class="wp-block-paragraph"><strong>Improved Security:</strong> Passwordless methods are often more secure than traditional passwords, as they are less susceptible to common attacks like phishing and credential stuffing.&nbsp;</p>



<p class="wp-block-paragraph"><strong>User Convenience:</strong> Passwordless authentication is often more convenient for users, as they don&#8217;t need to remember or reset passwords.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Reduced Password-Related Issues:</strong> It reduces the need for password resets and the risk of users choosing weak or easily guessable passwords.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Enhanced User Experience:</strong> Users can authenticate quickly and easily, leading to a smoother user experience.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Reduced Password Management Costs:</strong> Organizations can save on the costs associated with password management and support.&nbsp;</p>
								</div>
				</div>
				</div>
				</div>
		<p>The post <a href="https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/what-is-passwordless-authentication/">What is Passwordless Authentication?</a> appeared first on <a href="https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net">MODIVA</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/what-is-passwordless-authentication/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>MFA Fatigue Attacks: How to Safeguard Your Data and Network</title>
		<link>https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/mfa-fatigue-attacks-how-to-safeguard-your-data-and-network/</link>
					<comments>https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/mfa-fatigue-attacks-how-to-safeguard-your-data-and-network/#respond</comments>
		
		<dc:creator><![CDATA[Patrick]]></dc:creator>
		<pubDate>Tue, 31 Oct 2023 12:51:11 +0000</pubDate>
				<category><![CDATA[Modern Work]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://modiva.org/?p=8269</guid>

					<description><![CDATA[<p>Cybersecurity is a never-ending battle, with network protection and data security at its core. In an era marked by digital [&#8230;]</p>
<p>The post <a href="https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/mfa-fatigue-attacks-how-to-safeguard-your-data-and-network/">MFA Fatigue Attacks: How to Safeguard Your Data and Network</a> appeared first on <a href="https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net">MODIVA</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Cybersecurity is a never-ending battle, with network protection and data security at its core. In an era marked by digital advancements and evolving cybersecurity threats, the significance of Multi-Factor Authentication (MFA) in safeguarding sensitive information cannot be overstated. MFA is a robust security practice that mandates users to provide multiple authentication factors before accessing a system, application, or account. These authentication methods primarily include an exclusive information the user knows (typically a password), the user data (such as biometric data), and something the user possesses (like an authentication code or a mobile device).&nbsp;</p>



<p class="wp-block-paragraph">MFA extends beyond traditional username and password combinations, offering an additional layer of security to ascertain the user&#8217;s identity. The ultimate objective of MFA is to bolster security by introducing complexity, making it considerably more challenging for unauthorized individuals to gain access, even if they&#8217;ve compromised or guessed the user&#8217;s password. </p>



<p class="wp-block-paragraph"></p>



<h3 class="wp-block-heading"><strong>How Multifactor-Authentication (MFA) Works</strong>&nbsp;</h3>



<p class="wp-block-paragraph">Once Multifactor-Authentication (MFA) is enabled, the user encounters a second authentication step after logging in with their username and password. This second layer of authentication may involve a number-matching process, requiring the user to enter a matching PIN. Users can receive this PIN via SMS or email, an authenticator app like Microsoft Authenticator (Include a backlink if available) or by utilizing biometric data, such as fingerprint or facial recognition. Authenticator apps generate time-sensitive codes, ensuring that the code provided remains valid for only a brief window, making it extremely difficult for attackers to crack.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Understanding MFA Fatigue: </strong></p>



<p class="wp-block-paragraph">MFA fatigue attacks, also known as push spam, prompt spam, or authentication bombing, represent a relatively unsophisticated hacking technique that exploits a significant vulnerability—the human factor. Once a malicious actor acquires a victim&#8217;s credentials, they initiate a barrage of push notifications to the victim&#8217;s mobile device, incessantly requesting sign-in approval. The attacker&#8217;s aim is to overwhelm the victim, leading them to approve a prompt out of sheer frustration, subsequently granting access to the resources protected by MFA.&nbsp;</p>



<p class="wp-block-paragraph">To break down the workings of MFA fatigue attacks:&nbsp;</p>



<ul class="wp-block-list">
<li>The threat actor obtains credentials through social engineering or theft.&nbsp;</li>



<li>The threat actor enters the credentials and sends an MFA prompt to the unsuspecting user.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>If the user doesn&#8217;t immediately accept the prompt, the threat actor sends repeated prompts, inducing &#8220;fatigue.&#8221;&nbsp;</li>



<li>Once the user accepts the prompt, the threat actor gains access to all applications and assets beyond that access point.&nbsp;</li>
</ul>



<p class="wp-block-paragraph"><strong>Preventing MFA Fatigue Attacks</strong>&nbsp;</p>



<p class="wp-block-paragraph">Both organizations and individual users can take proactive steps to avoid falling victim to MFA fatigue attacks. Build consistent cybersecurity practice to stay one step ahead of these sophisticated threats.&nbsp;</p>



<ul class="wp-block-list">
<li>Maintain Suspicion: If you receive unsolicited MFA notifications, especially during odd hours or from unusual locations, exercise caution and avoid responding to them.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>Implement Threshold Limits: Organizations can set limits on the number of MFA requests per user within a specified time frame to prevent prompt bombardment and deter attackers.&nbsp;</li>



<li>Opt for Number Matching Authentication: Choose MFA methods that require users to select the correct number for authentication, rather than providing a simple &#8220;allow&#8221; or &#8220;deny&#8221; option in push messages.&nbsp;</li>



<li>Use Unique Passwords: Avoid using identical passwords across multiple platforms to minimize the damage that could result from a compromised credential.&nbsp;</li>



<li>Enhance User Awareness: Educate users about the existence and tactics of MFA fatigue attacks. Informed users are more likely to recognize suspicious activity and respond appropriately.&nbsp;</li>



<li>Employ Proactive Cybersecurity Measures: While preventing MFA fatigue attacks entirely may not be feasible due to their reliance on human error, sophisticated cybersecurity technology can help detect and thwart suspicious behavior, allowing quick action to stop threat actors from causing further damage to your network.&nbsp;</li>
</ul>



<p class="wp-block-paragraph">In a digital landscape where the balance of power between cybersecurity and cyber threats is ever-shifting, comprehending the nuances of MFA and employing vigilant measures are key to safeguarding your network and critical data.&nbsp;</p>
<p>The post <a href="https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/mfa-fatigue-attacks-how-to-safeguard-your-data-and-network/">MFA Fatigue Attacks: How to Safeguard Your Data and Network</a> appeared first on <a href="https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net">MODIVA</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/mfa-fatigue-attacks-how-to-safeguard-your-data-and-network/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Demystifying Identity and Access Management</title>
		<link>https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/demystifying-identity-and-access-management/</link>
					<comments>https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/demystifying-identity-and-access-management/#respond</comments>
		
		<dc:creator><![CDATA[Patrick]]></dc:creator>
		<pubDate>Sun, 08 Oct 2023 12:05:55 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://modiva.org/?p=8201</guid>

					<description><![CDATA[<p>In the ever-evolving landscape of cybersecurity, few topics have gained as much prominence as Identity and Access Management (IAM). It&#8217;s [&#8230;]</p>
<p>The post <a href="https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/demystifying-identity-and-access-management/">Demystifying Identity and Access Management</a> appeared first on <a href="https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net">MODIVA</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"></p>



<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="1024" height="476" src="/wp-content/uploads/2023/10/image-1-1024x476.png" alt="" class="wp-image-8202" srcset="/wp-content/uploads/2023/10/image-1-1024x476.png 1024w, /wp-content/uploads/2023/10/image-1-300x140.png 300w, /wp-content/uploads/2023/10/image-1-768x357.png 768w, /wp-content/uploads/2023/10/image-1-1536x714.png 1536w, /wp-content/uploads/2023/10/image-1.png 1600w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">In the ever-evolving landscape of cybersecurity, few topics have gained as much prominence as Identity and Access Management (IAM). It&#8217;s a term that frequently appears in discussions about data breaches, compliance, and the protection of sensitive information. Yet, despite its critical role, IAM often remains shrouded in complexity, leaving many wondering: What exactly is Identity and Access Management, and why is it so essential in today&#8217;s digital world?&nbsp;</p>



<p class="wp-block-paragraph">Identity and Access Management (IAM) is a framework of business processes, policies, and technologies that enable the management of digital identities and their access to resources. IAM is essential for ensuring that only the right people have access to the right resources at the right time.&nbsp;</p>



<p class="wp-block-paragraph"></p>



<h2 class="wp-block-heading"><strong>Components of </strong><strong>Identity and Access Management</strong></h2>



<figure class="wp-block-image size-full"><img decoding="async" width="1000" height="913" src="/wp-content/uploads/2023/10/IAM_.jpg" alt="" class="wp-image-8208" srcset="/wp-content/uploads/2023/10/IAM_.jpg 1000w, /wp-content/uploads/2023/10/IAM_-300x274.jpg 300w, /wp-content/uploads/2023/10/IAM_-768x701.jpg 768w" sizes="(max-width: 1000px) 100vw, 1000px" /></figure>



<p class="wp-block-paragraph">IAM systems typically include the following components:&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Authentication:</strong> The process of verifying the identity of a user. This can be done using a variety of methods, such as passwords, two-factor authentication, and biometric authentication.</li>



<li><strong>Authorization:</strong> The process of determining what resources a user has access to based on their identity and role.&nbsp;</li>



<li><strong>User management:</strong> The process of creating, modifying, and deleting user accounts. This includes managing user attributes, such as name, email address, and job title.&nbsp;</li>



<li><strong>Central user repository:</strong> A database that stores all user information, including their identity, authentication credentials, and authorization information. </li>
</ul>



<h2 class="wp-block-heading"><strong>Benefits of </strong><strong>Identity and Access Management</strong></h2>



<p class="wp-block-paragraph">IAM provides a number of benefits to organizations, some of which includes:&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Improved security:</strong> IAM helps to protect organizations from unauthorized access to their resources. By verifying the identity of users and controlling their access privileges, IAM can help to prevent data breaches, malware infections, and other security incidents.&nbsp;</li>



<li><strong>Increased compliance:</strong> IAM can help organizations to comply with industry regulations and standards, such as<strong> GDPR</strong> and <strong>HIPAA</strong>. By implementing strong IAM controls, organizations can demonstrate that they are taking steps to protect their data and systems.&nbsp;</li>



<li><strong>Reduced IT</strong> <strong>costs</strong>: IAM can help organizations to reduce their IT costs by automating user management tasks and streamlining access control. IAM can also help to reduce the number of support tickets that IT departments receive.&nbsp;</li>
</ul>



<h3 class="wp-block-heading"><strong>Identity and Access Management</strong><strong> </strong><strong>Implementation</strong>&nbsp;</h3>



<p class="wp-block-paragraph">The implementation of IAM can be complex and challenging, but it is an essential investment for any organization that wants to protect its data and systems. There are a number of IAM solutions available, both on-premises and cloud-based. Organizations should choose an IAM solution that meets their specific needs and requirements.&nbsp;</p>



<h3 class="wp-block-heading"><strong>Identity and Access Management Best Practices&nbsp;</strong></h3>



<p class="wp-block-paragraph">There are a number of best practices that organizations can follow when implementing and managing IAM, including:&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Use strong authentication methods</strong>: Organizations should use strong authentication methods, such as two-factor authentication, to verify the identity of users.&nbsp;</li>



<li><strong>Implement role-based access control:</strong> Organizations should implement role-based access control, which assigns permissions to users based on their roles. This helps to ensure that users only have access to the resources they need to do their jobs.&nbsp;</li>



<li><strong>Regularly review user permissions:</strong> Organizations should regularly review user permissions to ensure that they are still appropriate. This is especially important after changes to job roles or organizational structure. </li>



<li><strong>Use a central user repository:</strong> Organizations should use a central user repository to store all user information. This helps to simplify user management and improve security. </li>



<li><strong>Educate users about IAM:</strong> Organizations should educate their users about IAM and best practices for security. This includes teaching users how to create strong passwords, how to spot phishing emails, and how to report suspicious activity. </li>
</ul>



<p class="wp-block-paragraph">Identity and Access Management (IAM) is an essential framework for ensuring the security and compliance of organizations. By implementing and managing IAM effectively, your organization can protect its data and systems from unauthorized access and reduce its risk of cyberattacks. </p>
<p>The post <a href="https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/demystifying-identity-and-access-management/">Demystifying Identity and Access Management</a> appeared first on <a href="https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net">MODIVA</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/demystifying-identity-and-access-management/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Defender for Endpoint and Defender for Cloud- which dashboard should you use?</title>
		<link>https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/defender-for-endpoint-and-defender-for-cloud-which-dashboard-should-you-use/</link>
					<comments>https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/defender-for-endpoint-and-defender-for-cloud-which-dashboard-should-you-use/#respond</comments>
		
		<dc:creator><![CDATA[Patrick]]></dc:creator>
		<pubDate>Fri, 08 Apr 2022 11:58:12 +0000</pubDate>
				<category><![CDATA[Microsoft Defender]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">http://modivasite.azurewebsites.net/?p=7081</guid>

					<description><![CDATA[<p>Microsoft Defender for Servers is a plan that is part of Microsoft Defender for Cloud. When you enable Microsoft Defender [&#8230;]</p>
<p>The post <a href="https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/defender-for-endpoint-and-defender-for-cloud-which-dashboard-should-you-use/">Defender for Endpoint and Defender for Cloud- which dashboard should you use?</a> appeared first on <a href="https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net">MODIVA</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Microsoft Defender for Servers is a plan that is part of Microsoft Defender for Cloud. When you enable Microsoft Defender for Servers, you get a range of awesome functionality designed to protect your servers, including file integrity monitoring, adaptive application control, just in time access, among others.</p>



<p class="wp-block-paragraph">One additional capability that comes included with Defender for Servers is Microsoft Defender for Endpoint. See more details about the integrated solution here.</p>



<h2 class="wp-block-heading">Background</h2>



<p class="wp-block-paragraph">One advantage of this native integration is the centralization of alerts, in other words, when an alert is triggered by MDE, it will be surfaced in the Microsoft Defender for Cloud / Security Alerts dashboard</p>



<p class="wp-block-paragraph">If you select one alert, you can get more details about it and take action on the alert to start your investigation or remediation of it. You can also click on the link to be brought directly to the Microsoft 365 portal to investigate the alerts there.</p>



<p class="wp-block-paragraph">Which dashboard should you look at?</p>



<p class="wp-block-paragraph">As you can see, these alerts can be investigated from both dashboards of Microsoft Defender for Servers in the Azure Portal and from Microsoft Defender for Endpoint in Microsoft 365 Defender.</p>



<p class="wp-block-paragraph">So which dashboard should you use?</p>



<p class="wp-block-paragraph">The answer is your choice and lies entirely with how your Information Security Team is consuming the alerts and managing the devices.</p>



<p class="wp-block-paragraph">However, we can give you some guidance on best practises that we have seen to work with many customers.</p>



<p class="wp-block-paragraph">A SIEM is the recommended started point for investigation for all Defender for Cloud alerts (not just those coming from MDE).</p>



<p class="wp-block-paragraph">Note: You might see duplicate alerts in Microsoft Sentinel, coming from Microsoft defender for Cloud and Defender for Endpoint. This is a known behaviour if Defender for Endpoint sensor was onboarded via Defender for Cloud.</p>



<p class="wp-block-paragraph">In the absence of a SIEM and if you’re a general SOC team doing the investigation (not focused on just endpoints), we recommend that you start your investigation of alerts on Microsoft Defender for Cloud, and you can easily go to Microsoft 365 Defender to further your hunt via Defender for Endpoint.</p>



<p class="wp-block-paragraph">On the other hand, if you’re a team who focuses entirely on endpoints who are doing the investigation of the alerts, then you can use just the Microsoft 365 Portal.</p>



<p class="wp-block-paragraph">In summary, you can use whichever dashboard or method you choose to investigate the alerts, but you can decide based on the criteria listed above.</p>



<p class="wp-block-paragraph"><strong><em>Culled from Microsoft Blogs</em></strong></p>



<p class="wp-block-paragraph"><a href="https://techcommunity.microsoft.com/t5/microsoft-defender-for-cloud/defender-for-endpoint-and-defender-for-cloud-which-dashboard/ba-p/3279558#"></a></p>
<p>The post <a href="https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/defender-for-endpoint-and-defender-for-cloud-which-dashboard-should-you-use/">Defender for Endpoint and Defender for Cloud- which dashboard should you use?</a> appeared first on <a href="https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net">MODIVA</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/defender-for-endpoint-and-defender-for-cloud-which-dashboard-should-you-use/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>New certification for Security Architects</title>
		<link>https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/new-certification-for-security-architects/</link>
					<comments>https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/new-certification-for-security-architects/#respond</comments>
		
		<dc:creator><![CDATA[Patrick]]></dc:creator>
		<pubDate>Fri, 08 Apr 2022 10:27:02 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">http://modivasite.azurewebsites.net/?p=7057</guid>

					<description><![CDATA[<p>We are looking for Microsoft cybersecurity architects to take our new beta exam. Microsoft cybersecurity architects have subject matter expertise [&#8230;]</p>
<p>The post <a href="https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/new-certification-for-security-architects/">New certification for Security Architects</a> appeared first on <a href="https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net">MODIVA</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">We are looking for Microsoft cybersecurity architects to take our new beta exam. Microsoft cybersecurity architects have subject matter expertise in designing and evolving the cybersecurity strategy to protect an organization’s mission and business processes across all aspects of the enterprise architecture. They design a Zero Trust strategy and architecture, including security strategies for data, applications, access management, identity, and infrastructure. They also evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies.</p>



<p class="wp-block-paragraph">Cybersecurity architects continuously collaborate with leaders and practitioners in IT security, privacy, and other roles across an organization to plan and implement a cybersecurity strategy that meets the business needs of an organization.</p>



<p class="wp-block-paragraph">If this is your skill set, we have a new certification for you. The certification validates your expertise in this area and offers you the opportunity to prove your skills. To earn this certification, pass SC-100: Microsoft Cybersecurity Architect exam (currently in beta) as well as any one of the following: SC-200, SC-300, AZ-500, OR MS-500.</p>



<p class="wp-block-paragraph">Is this the right certification for you?<br>This certification could be a great fit if you have significant experience in a wide range of security engineering areas including identity and access, platform protection, security operations, securing data and securing applications. You should also have experience with hybrid and cloud implementations.</p>



<p class="wp-block-paragraph">Ready to prove your skills?<br>Take advantage of the discounted beta exam offer. The first 300 people who take Exam SC-100 (beta) on or before May 5, 2022, can get 80 percent off market price!</p>



<p class="wp-block-paragraph">To receive the discount, when you register for the exam and are prompted for payment, use code SC100ARCH. This is not a private access code. The seats are offered on a first-come, first-served basis. As noted, you must take the exam on or before May 5, 2022.</p>



<p class="wp-block-paragraph"><strong><em>Culled from Microsoft Blog</em></strong>s</p>
<p>The post <a href="https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/new-certification-for-security-architects/">New certification for Security Architects</a> appeared first on <a href="https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net">MODIVA</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/new-certification-for-security-architects/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
