
When Your "Trusted Location" MFA Bypass Meets an AI Agent
A location-based MFA bypass built for humans quietly waved an AI agent through to Microsoft 365. The Conditional Access changes that fixed it, and the audit worth doing in your tenant.
Four articles from a team that runs both the CMS and the IT underneath it — incident write-ups, not marketing.
Because most production incidents cross the line between them. When the CMS vendor and the IT provider are different companies, the handoff is where the outage lives.
We published an actual Sunday-morning response rather than a policy: the containment order, what we had prepared in advance, and which calls had to be made by the client.
Yes. Location and IP-based exemptions assume a human at a desk. Scope access to device and workload identity, and treat agent credentials as service principals with their own lifecycle.

A location-based MFA bypass built for humans quietly waved an AI agent through to Microsoft 365. The Conditional Access changes that fixed it, and the audit worth doing in your tenant.

Splitting Sitefinity managed services and IT infrastructure between two vendors costs you performance, deployment speed, and budget. Why consolidating with one partner pays off.

A Monday morning Blackpoint alert that looked like an OAuth attack turned out to be an AI assistant connecting to Microsoft 365. Why illicit consent grants are the new attack surface, and what to do about it.

Inside a real ransomware incident — the first hour, the role of cyber insurance, three weeks of recovery work, and five lessons that apply to every organization.
One email, twice a month. No vendor pitches.
Coming soon