Lukas Beran
@lukasberan.com
1.5K followers 240 following 610 posts
Senior Security Researcher (DART) at Microsoft. Opinions are my own. #MSIncidentResponse #DART #Microsoft365 #EntraID #DefenderXDR #Sentinel
Posts Media Videos Starter Packs
Pinned
lukasberan.com
📺 𝐈 𝐡𝐚𝐯𝐞 𝐦𝐲 𝐨𝐰𝐧 𝐘𝐨𝐮𝐓𝐮𝐛𝐞 𝐜𝐡𝐚𝐧𝐧𝐞𝐥! 📺

I have started publishing detailed instructional videos primarily (but not exclusively) focused on cybersecurity and the Microsoft cloud.

If you don't want to miss out on interesting industry tips and tricks, be sure to subscribe. 👇 👇
www.youtube.com/@cswrldcom
Cybersecurity World
Reposted by Lukas Beran
simonjhudson.bsky.social
After yesterday's interesting #Copilot+#OneDrive event I took a much deeper look at the 'Add shortcut to OneDrive' #SharePoint feature.
Microsoft have declared this as the direction of travel.

At first it looked great. Until I dug deeper. What I found is pretty horrifying. Blog inbound...
Reposted by Lukas Beran
nathanmcnulty.com
Did you know Entra ID Protection never automatically clears Medium or High risk?

We either need to use Risk Based Conditional Access policies to remediate or an admin needs to manually remediate

User risk = password reset
Sign-in risk = require MFA

learn.microsoft.com/...
lukasberan.com
Microsoft introduced new Sentinel commitment tier for SMBs.

The 50 GB commitment tier is available in public preview, with promotional pricing starting October 1, 2025, until March 31, 2026. Customers who sign up during this period will lock in promotional pricing until March 31, 2027.
Reposted by Lukas Beran
nathanmcnulty.com
A 3 picture story of why you should default quarantine password protected files and enforce SmartScreen without allowing user bypass...
lukasberan.com
It's a year of increasing revenues.
lukasberan.com
And the new aluminum iPhones that are ugly and extremely susceptible to damage 🙄 This year is really not the best iPhone year.
lukasberan.com
Seriously, Apple?
That plastic-like white back on your silver flagship iPhone looks awful. This might be the ugliest iPhone ever, and I’m seriously thinking about returning it purely because of the design.
lukasberan.com
Hlavně bych řekl běžte k volbám a volte kohokoliv kromě Babiše, Okamury a komoušů. Jestli to budou Piráti, Spolu nebo STAN už v této situaci není až tak důležité. Hlavně ať sbírají body nějaké normální demokratické pro západní strany.
Reposted by Lukas Beran
nathanmcnulty.com
IMHO - Worry less about how long tokens are valid for, worry more about protecting the tokens, both on the client and during authentication

Obviously we need phishing resistant auth, but also focus on client hardening (app control, EDR, etc.) and VPN/ZTNA with enforced CAE
Reposted by Lukas Beran
nathanmcnulty.com
Wow, I totally missed this change!

Apparently since July, we've been able to use Asset rules management to use device details, like name, domain, OS, and other tags, to dynamically apply MDE-Management for MDE attach 😎

learn.microsoft.com/...
Reposted by Lukas Beran
nathanmcnulty.com
I love passkeys in Microsoft Authenticator, but rolling them out with Compliance and/or App Protection Policies has not been as easy as it should be...

But I have good news - we can create a better experience without introducing significant gaps :)
Improving passkey registration experiences
Lets see what we can do about minimizing passkey deployment issues with Compliance and App Protection Policy requirements :)
nathanmcnulty.com
lukasberan.com
If you want to update applications on managed computers, you must manually create a new version of the given application and deploy it to all computers. However, this is quite a lot of manual work, and you also have to monitor the availability of new versions of installed applications.
lukasberan.com
𝗛𝗼𝘄 𝘁𝗼 𝗮𝘂𝘁𝗼𝗺𝗮𝘁𝗶𝗰𝗮𝗹𝗹𝘆 𝘂𝗽𝗱𝗮𝘁𝗲 𝗮𝗽𝗽𝗹𝗶𝗰𝗮𝘁𝗶𝗼𝗻𝘀 𝗼𝗻 𝗰𝗼𝗺𝗽𝘂𝘁𝗲𝗿𝘀 𝗶𝗻 𝗠𝗶𝗰𝗿𝗼𝘀𝗼𝗳𝘁 𝗜𝗻𝘁𝘂𝗻𝗲

Microsoft Intune does not have any built-in options for updating installed applications on Windows computers.
How to update applications using Patch My PC
lukasberan.com
Why do more organizations choose Microsoft Defender for Endpoint every year?
- AI-powered protection across platforms — Windows, Linux, macOS, Android, iOS, IoT
- Pre-breach exposure management with attack path analysis and scoring
- Attack disruption that automatically contains threats in real time
lukasberan.com
Microsoft has been ranked #1 in the worldwide modern endpoint security market share for the third year in a row (IDC, 2024).
lukasberan.com
It is important for organizations to prioritize intrusion prevention but also ensure that the right configurations are in place to identify the source of any intrusion or incident.
lukasberan.com
For incident response to be successful, the proper tools and logging systems should be in place—but that is usually easier said than done.