Abhilash Kankanawadi, Author at Microsoft Security Blog http://approjects.co.za/?big=en-us/security/blog/author/v-abhilashk/ Expert coverage of cybersecurity topics Fri, 05 Dec 2025 20:15:22 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.4 What is a trusted device? http://approjects.co.za/?big=en-us/security/blog/2014/08/14/what-is-a-trusted-device/ Thu, 14 Aug 2014 08:10:00 +0000 When you try to view or edit your credit card details or other sensitive information in your Microsoft account, you might need to enter a security code first, to make sure that only you can get in to your account. But you can designate a computer or other device as a trusted device.

The post What is a trusted device? appeared first on Microsoft Security Blog.

]]>
When you try to view or edit your credit card details or other sensitive information in your Microsoft account, you might need to enter a security code first, to make sure that only you can get in to your account. But you can designate a computer or other device as a trusted device. On trusted devices, you don’t need to enter a security code each time you try to access sensitive information.

How many trusted devices can I have?

You can trust as many devices as you want. There is no limit. If you don’t sign in to a particular trusted device at least once every two months, it’s automatically removed from your Microsoft account. This safeguard helps keep your account more secure in the event that a trusted device is lost or stolen without you realizing it. You can always trust a device again later.

The post What is a trusted device? appeared first on Microsoft Security Blog.

]]>
Strengthening encryption for Microsoft Azure customers http://approjects.co.za/?big=en-us/security/blog/2014/08/07/strengthening-encryption-for-microsoft-azure-customers/ Thu, 07 Aug 2014 18:47:12 +0000 In July, we published a blog post which talked about the advancements Microsoft had made in encryption for Outlook.com and OneDrive to further increase the security of our customers data.   Today, Microsoft Azure has taken additional steps toward our commitment to protecting customer data with the announcement of encryption improvements for Microsoft Azure guest OS.

The post Strengthening encryption for Microsoft Azure customers appeared first on Microsoft Security Blog.

]]>
In July, we published a blog post which talked about the advancements Microsoft had made in encryption for Outlook.com and OneDrive to further increase the security of our customers data.   Today, Microsoft Azure has taken additional steps toward our commitment to protecting customer data with the announcement of encryption improvements for Microsoft Azure guest OS.

The encryption improvements, which apply to Microsoft Azure cipher solution for hosted guest virtual machines, provide customers with enhanced protection when connecting and transmitting data. For example, the enhancements to the default Transport Layer Security (TLS)/Secure Socket Layer (SSL) cipher suites helps ensure that connections are better encrypted during transmission.  In addition, enabling Perfect Forward Secrecy (PFS) helps ensure a different encryption key is used for every connection, making it more difficult for attackers to decrypt connections.

As technology advances and attackers continue to adjust their tactics, it’s essential that cloud providers evolve their security protections to keep pace with the changing landscape. Over the years as cipher suites become compromised, staying diligent and nimble is essential. The latest advancements implemented by Microsoft Azure is an important step in the ongoing chain of evolution in our security commitment, and helps provide customers with additional layers of protection that reduce the risk of an attacker being able to successfully decrypt a connection.

By providing PFS, it will help ensure that connection keys remain fresh, and that attackers who may have a compromised key, are not able to reuse it in future sessions when trying to decrypt traffic going to and from a guest virtual machine. These advancements are another important step in the journey to helping ensure our customers get the best in class security protections as they become available.

The post Strengthening encryption for Microsoft Azure customers appeared first on Microsoft Security Blog.

]]>
How to sign into devices that don’t accept security codes http://approjects.co.za/?big=en-us/security/blog/2014/07/31/how-to-sign-into-devices-that-dont-accept-security-codes/ Thu, 31 Jul 2014 13:55:00 +0000 Two-step verification makes it more difficult for hackers to access your account, even when they have your password. If you turn on two-step verification, you’ll see an extra page every time you sign in on a device that isn’t trusted. The extra page prompts you to enter a security code to sign in.

The post How to sign into devices that don’t accept security codes appeared first on Microsoft Security Blog.

]]>
Two-step verification makes it more difficult for hackers to access your account, even when they have your password. If you turn on two-step verification, you’ll see an extra page every time you sign in on a device that isn’t trusted. The extra page prompts you to enter a security code to sign in.

When you turn on two-step verification for your Microsoft account, it turns on two-step verification for all the places where you sign in with your Microsoft account. However, some apps (like the email apps on some smartphones) or devices (like the Xbox 360 console) can’t prompt you to enter a security code when you try to sign in, so they display an incorrect password or account error.

For example, if you’ve just turned on two-step verification, you might see the following error code and message when you try to sign in to Xbox Live:

Account does not exist.
Status Code: 8015D002

Create a unique app password to sign in

If you get an error like the one above with an app or device, you’ll need to create a unique app password to sign in. Once you’ve signed in with your app password, you can use that app or device. You’ll need to create and sign in with an app password one time for each app or device that can’t prompt you for a security code.

  1. Sign in to your Microsoft account.
  2. Under Password and security info, tap or click Edit security info.

If you’re prompted for a security code here, enter it and tap or click Submit.

  1. Under App passwords, tap or click Create a new app password.

A new app password is generated and appears on your screen.

  1. Switch to the app or device for which you need the password, and enter the app password that was generated.

To learn more about signing in to specific devices, see App passwords and two-step verification.

Get more answers to your questions about two-step verification

The post How to sign into devices that don’t accept security codes appeared first on Microsoft Security Blog.

]]>
Microsoft Interflow: a new Security and Threat Information Exchange Platform http://approjects.co.za/?big=en-us/security/blog/2014/06/23/microsoft-interflow-a-new-security-and-threat-information-exchange-platform/ Mon, 23 Jun 2014 05:36:58 +0000 http://marcbook.local/wds/playground/cybertrust/2014/06/23/microsoft-interflow-a-new-security-and-threat-information-exchange-platform/ Today, the Microsoft Security Response Center (MSRC) announced the private preview of Microsoft Interflow. This is a security and threat information exchange platform for cybersecurity analysts and researchers.

Interflow provides an automated machine-readable feed of threat and security information that can be shared across industries and community groups in near real-time. This platform provides this information using open specifications STIX™ (Structured Threat Information eXpression), TAXII™ (Trusted Automated eXchange of Indicator Information), and CybOX™ (Cyber Observable eXpression standards). This enables Interflow to integrate with existing operational and analytical tools that many organizations use through a plug-in architecture. It has the potential to help reduce the cost of defense by automating processes that are currently performed manually. 

You can get more information on Microsoft Interflow on the MSRC blog, and as well as in this FAQ and at www.microsoft.com/interflow.

The post Microsoft Interflow: a new Security and Threat Information Exchange Platform appeared first on Microsoft Security Blog.

]]>
Today, the Microsoft Security Response Center (MSRC) announced the private preview of Microsoft Interflow. This is a security and threat information exchange platform for cybersecurity analysts and researchers.

Interflow provides an automated machine-readable feed of threat and security information that can be shared across industries and community groups in near real-time. This platform provides this information using open specifications STIX™ (Structured Threat Information eXpression), TAXII™ (Trusted Automated eXchange of Indicator Information), and CybOX™ (Cyber Observable eXpression standards). This enables Interflow to integrate with existing operational and analytical tools that many organizations use through a plug-in architecture. It has the potential to help reduce the cost of defense by automating processes that are currently performed manually.

You can get more information on Microsoft Interflow on the MSRC blog, and as well as in this FAQ and at www.microsoft.com/interflow.

Tim Rains
Director
Trustworthy Computing

The post Microsoft Interflow: a new Security and Threat Information Exchange Platform appeared first on Microsoft Security Blog.

]]>
Microsoft is building a global online safety community, one tweet at a time http://approjects.co.za/?big=en-us/security/blog/2014/06/12/microsoft-is-building-a-global-online-safety-community-one-tweet-at-a-time/ Thu, 12 Jun 2014 06:00:00 +0000 http://marcbook.local/wds/playground/cybertrust/2014/06/12/microsoft-is-building-a-global-online-safety-community-one-tweet-at-a-time/ Some say, “It takes a village to raise a child.” Extending this notion, it takes an entire global community to make the Internet a safer and better place. Microsoft is committed to fostering digital citizenship—the safer, responsible, and more appropriate use of devices and technology.

The post Microsoft is building a global online safety community, one tweet at a time appeared first on Microsoft Security Blog.

]]>
Some say, “It takes a village to raise a child.” Extending this notion, it takes an entire global community to make the Internet a safer and better place.

Microsoft is committed to fostering digital citizenship—the safer, responsible, and more appropriate use of devices and technology. Although it’s impossible to be all things to all people, by using digital and social media, we can more efficiently reach those interested in educating themselves, their community, and the youth in their lives, on the proactive habits and practices needed to have safer digital experiences.

Earlier this year, Microsoft surpassed 100,000 followers on its @Safer_Online Twitter channel. This growth is due to the involvement and enthusiasm of our active community. From sharing our online safety news, research, and guidance, to connecting with other online safety experts and participating in our live social media events, you are what drives us to do more. Thank you for your support and engagement!

We all have a role to play in helping create a safer digital world.  What will yours be?

  • Educate yourself and your social circles about the benefits of, risks to, and proactive steps to take when going online.
  • Join the online safety conversation with your own tips and questions for our community.
  • Participate in any of our upcoming live Twitter chats. You never know, there could be prizes to be won!

Connect with us on all of our online channels!

Web: Microsoft.com/Safety  Twitter: @Safer_Online  Facebook: SaferOnline  YouTube: MSFTOnlineSafety  

The post Microsoft is building a global online safety community, one tweet at a time appeared first on Microsoft Security Blog.

]]>
New Guidance for Securing Public Key Infrastructure http://approjects.co.za/?big=en-us/security/blog/2014/06/11/new-guidance-for-securing-public-key-infrastructure/ Wed, 11 Jun 2014 11:06:14 +0000 http://marcbook.local/wds/playground/cybertrust/2014/06/11/new-guidance-for-securing-public-key-infrastructure/ Public Key Infrastructure (PKI) is used as a building block to provide key security controls, such as data protection and authentication for organizations. Many organizations operate their own PKI to support things like remote access, network authentication and securing communications.

The threat of compromise to IT infrastructures from attacks is evolving. The motivations behind these attacks are varied, and compromising an organization’s PKI can significantly help an attacker gain access to the sensitive data and systems they are after.

To help enterprises design PKI and protect it from emerging threats, Microsoft IT has released a detailed technical reference document - “Securing Public Key Infrastructure.” New Guidance for Securing Public Key Infrastructure appeared first on Microsoft Security Blog.

]]>
Public Key Infrastructure (PKI) is used as a building block to provide key security controls, such as data protection and authentication for organizations. Many organizations operate their own PKI to support things like remote access, network authentication and securing communications. The threat of compromise to IT infrastructures from attacks is evolving. The motivations behind these attacks are varied, and compromising an organization’s PKI can significantly help an attacker gain access to the sensitive data and systems they are after. To help enterprises design PKI and protect it from emerging threats, Microsoft IT has released a detailed technical reference document – “Securing Public Key Infrastructure.” The document provides recommendations for numerous aspects of PKI, including:

  • Common vectors for PKI compromise
  • Planning cryptographic algorithms and certificate usages
  • Designing physical security
  • Implementing technical controls to secure PKI
  • Protecting PKI artifacts and assets
  • Monitoring PKI for malicious activity
  • Recovering from a compromise

The document is recommended for enterprise security professionals who have responsibility for designing, implementing, maintaining or governing a PKI. The recommendations discussed in the document are largely based on Microsoft’s Information Security and Risk Management (ISRM) organization’s experience, which is accountable for protecting the assets of Microsoft IT and other Microsoft business divisions, and advising a selected number of Microsoft’s Global 500 customers.

The post New Guidance for Securing Public Key Infrastructure appeared first on Microsoft Security Blog.

]]>
5 ways to protect your Microsoft account http://approjects.co.za/?big=en-us/security/blog/2014/05/15/5-ways-to-protect-your-microsoft-account/ Thu, 15 May 2014 08:54:00 +0000 Your Microsoft account (formerly your Windows Live ID) is the combination of an email address and a password that you use to sign in to services such as Xbox LIVE and Outlook.com, as well as devices such as Windows Phone and computers running Windows 8.

The post 5 ways to protect your Microsoft account appeared first on Microsoft Security Blog.

]]>
Your Microsoft account (formerly your Windows Live ID) is the combination of an email address and a password that you use to sign in to services such as Xbox LIVE and Outlook.com, as well as devices such as Windows Phone and computers running Windows 8.

A Microsoft account is free and you can use it to:

  • Purchase apps from the Windows Store
  • Back up all your data using free cloud storage
  • Keep all your devices, photos, friends, games, settings, music, up to date and in sync.

5 ways to help protect your Microsoft account

  1. Create a strong password. Strong passwords use a combination of uppercase and lowercase letters, numerals, punctuation marks, and symbols. The longer the better, and don’t use personal information (such as a pet’s name, nickname, or driver’s license number) that can be easily guessed.
  2. Protect your password. Don’t use the same password you use on other sites, and remember to change your Microsoft account password (as well as other passwords) regularly. Watch out for email social engineering scams designed to trick you into turning over your password to a cybercriminal.
  3. Enable two-step verification. Two-step verification uses two ways to verify your identity whenever you sign in to your Microsoft account. Two-step verification is optional, but we recommend that you use it. Learn how to turn it on.
  4. Make sure the security information associated with your account is current. If the alternate email address or phone number you’ve given us changes, update the settings of your account so that we can contact you if there’s a problem.
  5. Watch out for phishing scams. If you receive an email message about the security of your Microsoft account, it could be a phishing scam. Don’t click links in any messages unless you trust or check with the sender.

Don’t have a Microsoft account yet? See How do I sign up for a Microsoft account?

The post 5 ways to protect your Microsoft account appeared first on Microsoft Security Blog.

]]>
Reliability Series #1: Reliability vs. resilience http://approjects.co.za/?big=en-us/security/blog/2014/03/24/reliability-series-1-reliability-vs-resilience/ Mon, 24 Mar 2014 15:52:00 +0000 http://marcbook.local/wds/playground/cybertrust/2014/03/24/reliability-series-1-reliability-vs-resilience/ Whenever I speak to customers and partners about reliability I’m reminded that while objectives and priorities differ between organizations and customers, at the end of the day, everyone wants their service to work. As a customer, you want to be able to do things online, at a time convenient to you.

The post Reliability Series #1: Reliability vs. resilience appeared first on Microsoft Security Blog.

]]>
Whenever I speak to customers and partners about reliability I’m reminded that while objectives and priorities differ between organizations and customers, at the end of the day, everyone wants their service to work. As a customer, you want to be able to do things online, at a time convenient to you. As an organization – or a provider of a service – you want your customers to carry out the tasks they want to, whenever they want to do so.

This article is the first in a four-part series on building a resilient service. In my first two posts, I will discuss the topic as it relates to business strategy, and then we’ll dive deeper into the technical details. The full series of four posts will cover:

  1. Reliability vs. resilience – What is the difference between reliability and resilience and why does it matter?
  2. Common reliability-related threats – DIAL (Discovery, Incorrectness, Authorization/Authentication, Limits/Latency) is a handy mnemonic to help teams brainstorm potential failures of interactions between components for their service in a structured way. Brainstorming about failure modes and failure points is a key phase in resilience modeling and analysis (RMA) and can help teams improve the reliability of their service.
  3. Reliability-enhancing techniques – Taking the “D” and “A” in DIAL, we’ll look at some reliability enhancing techniques you can incorporate into your design related to discovery and authentication.
  4. Reliability-enhancing techniques – Taking the “I” and “L” in DIAL, we’ll look at some reliability enhancing techniques you can incorporate into your design related to incorrectness and limits.

My intention is to provide insight into how Microsoft thinks about reliability and the processes and techniques we’re employing to improve the reliability of our services for our customers.

So what is reliability? When I ask customers and partners, the most common responses refer to consistency in performance, speed, availability – and perhaps most significantly –resilience. One thing we all agree on is that for a system or service to be reliable, the user has to believe ‘it just works’.

The Institute of Electrical and Electronics Engineers (IEEE) Reliability Society states reliability [engineering] is “a design engineering discipline which applies scientific knowledge to assure that a system will perform its intended function for the required duration within a given environment, including the ability to test and support the system through its total lifecycle.” For software, it defines reliability as “the probability of failure-free software operation for a specified period of time in a specified environment.”

A reliable cloud service is essentially one that functions as the designer intended it to, when it is expected to, and wherever the customer is connected. That’s not to say every component must operate flawlessly 100 percent of the time. This last point brings us to what I believe is the difference between reliability and resiliency.

Reliability is the outcome cloud service providers strive for – it’s the result. Resiliency is the ability of a cloud-based service to withstand certain types of failure and yet remain functional from the customer perspective.  In other words, reliability is the outcome and resilience is the way you achieve the outcome.  A service could be characterized as reliable simply because no part of the service has ever failed, and yet the service couldn’t be regarded as resilient because those reliability-enhancing capabilities may never have been tested.

The key takeaway here is the importance of focusing on resilience and designing and building resiliency into your service at every stage of the software development lifecycle. To find out more about the fundamentals of building a reliable online service, read our whitepaper ‘An introduction to designing reliable cloud services’.

**Next up: Reliability Series #2: Categorizing reliability threats to your service

The post Reliability Series #1: Reliability vs. resilience appeared first on Microsoft Security Blog.

]]>
Detect and remove spyware http://approjects.co.za/?big=en-us/security/blog/2013/12/17/detect-and-remove-spyware/ Tue, 17 Dec 2013 12:11:00 +0000 http://marcbook.local/wds/playground/cybertrust/2013/12/17/detect-and-remove-spyware/ Spyware is a general term used to describe software that performs certain actions—generally without appropriately obtaining your consent—such as: If your computer is running Windows 8, you can use the built-in Windows Defender to help you detect and get rid of spyware and other malware.

The post Detect and remove spyware appeared first on Microsoft Security Blog.

]]>
Spyware is a general term used to describe software that performs certain actions—generally without appropriately obtaining your consent—such as:

  • Advertising
  • Collecting personal information
  • Changing the configuration of your computer

If your computer is running Windows 8, you can use the built-in Windows Defender to help you detect and get rid of spyware and other malware. If your computer is running Windows 7, Windows Vista, or Windows XP, Windows Defender removes spyware.

To get rid of viruses and other malware, including spyware, on Windows 7, Windows Vista, and Windows XP, you can download Microsoft Security Essentials for free.

The post Detect and remove spyware appeared first on Microsoft Security Blog.

]]>
Check security settings in Windows Vista http://approjects.co.za/?big=en-us/security/blog/2013/09/03/check-security-settings-in-windows-vista/ Tue, 03 Sep 2013 08:39:00 +0000 The newest version of Windows is Windows 8, but we know that many of you still use Windows Vista. The best way to ensure that Windows Vista is as secure as it can be is to use the Windows Security Center, which is built into Windows Vista.

The post Check security settings in Windows Vista appeared first on Microsoft Security Blog.

]]>
The newest version of Windows is Windows 8, but we know that many of you still use Windows Vista.

The best way to ensure that Windows Vista is as secure as it can be is to use the Windows Security Center, which is built into Windows Vista.

The Windows Security Center can help you check the status of several security features on your computer, including firewall settings, Windows automatic updating, anti-malware software settings, Internet security settings, and User Account Control settings.

To get to the Window Security Center, click the Start button , click Control Panel, click Security, and then click Security Center. If Windows detects a problem (for example, if your antivirus program is out of date), Security Center displays a notification and places a Security Center icon  in the notification area. Click the notification or double-click the Security Center icon to open Security Center and get information about how to fix the problem.

Download Microsoft Security Essentials

Windows 8 comes with Windows Defender to help protect your PC from viruses and other kinds of malware.

Get more security information for Windows Vista

The post Check security settings in Windows Vista appeared first on Microsoft Security Blog.

]]>