Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

What an AD/Entra Hybrid Audit Actually Looks For & Why Most Teams Fail the First One

Most AD cleanup processes stop at the domain boundary, but hybrid audits don’t. Here’s what auditors actually check across Active Directory and Entra ID, and the gaps that trip up teams in their first review. Ask a few IT teams how they handle offboarding and you’ll hear the same answer: disable the account in Active Directory, close the ticket, and move on.

How can organizations enforce separation of duties in access controls?

Separation of duties, also called segregation of duties, is a control that splits a sensitive business process across more than one person so no single user can both execute and approve the same action. Organizations enforce it by mapping conflicting duties into a matrix, applying role-based access control and least privilege, requiring independent approval on high-risk transactions, and reviewing access on a set cadence.

Ask your PAM vendor this one question

Here's a test you can run in about five minutes. Pull up a privileged account in your directory, one that was used in a session yesterday. Is the account still there? Does it still hold the same privileged group memberships it had yesterday? I'd bet good money the answer to both is yes. That's not a criticism of your PAM tool. It's what traditional credential rotation was built to do, and more importantly, what it was never designed to do.

What is HIPAA compliance: Guidelines for becoming compliant

HIPAA compliance requires healthcare providers and their business associates to safeguard protected health information (PHI) through privacy and security rules, risk assessments, and breach notifications. Covered entities must implement administrative, technical, and physical safeguards, including access controls, encryption, auditing, and workforce training. Noncompliance can result in steep fines and reputational damage, making strong data governance and adherence to NIST-aligned safeguards essential.

What Is Identity Governance and Administration (IGA)? A Complete Guide

Disconnected identity systems create the access risk, audit friction, and IT overhead that identity governance and administration (IGA) is built to close. The 2026 Verizon Data Breach Investigations Report found credential abuse in 39% of breaches. IGA combines policy, certification, and compliance evidence with automated provisioning, deprovisioning, and access requests to keep access aligned with business needs and reduce that risk.

How to reduce DLP false positives

DLP false positives bury real incidents under benign alerts and push teams to switch off the controls they bought. Most of that noise is configuration. Classify sensitive data before enforcement, pair content matches with identity and destination context, phase policies from simulation to blocking, and read override reasons as a tuning signal. Track the trend per policy, and you can show an auditor what the controls do.

A guide to API key management

Unmanaged, long-lived keys weaken visibility, audit readiness, operational continuity, and cyber resilience, making API key management critical across non-human identities. An effective program maintains inventory and ownership, enforces least privilege and secure storage, and automates rotation, monitoring, and revocation across each key's lifecycle.

Copilot broke your insider threat detection, and MITRE wrote the proof

MITRE ATT&CK's detection analytic for adversaries mining SharePoint describes bulk access to files and metadata in a short window by privileged or rarely used accounts. That is also a description of Microsoft 365 Copilot answering a question. The technique hasn't changed, but the baseline has, and the exposure now happens with no vulnerability, no compromised credential, and no malicious intent anywhere in the chain.

Uncovering indirect attack paths to virtualized domain controllers in Azure

Within Netwrix Security Research, we were helping a customer with an Entra ID assessment and knew they'd already done AD tiering on-prem. We also knew they had domain controllers virtualized in Azure, but it was hard to tell which Windows Server was actually a DC. We figured out that Azure Run Command lets you run commands as SYSTEM, so we used that to do reconnaissance and identify the DCs.

AI Governance in healthcare: Compliance and security

AI governance in healthcare has become a question boards and auditors ask directly. They want to know which AI tools reach protected health information, who's accountable for each one, and what evidence shows the controls are holding. Most health systems have a written policy and no way to produce those three answers on request, which is precisely what an auditor tests. Healthcare organizations adopted AI faster than they built the governance to account for it.