urbanists.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
We're a server for people who like bikes, transit, and walkable cities. Let's get to know each other!

Server stats:

527
active users

#microsoft365

11 posts10 participants0 posts today

I'm officially calling working on shared documents in desktop versions of microsoft365 apps BROKEN.

I keep running into the problem where opening a shared doc in a desktop app overwrites the shared doc with whatever local version of the doc I have.

Thankfully I can roll back to the last version, but the risk of inadvertently wiping out someone's changes is still there.

I received an email from "Microsoft 365 security" notifying me that an email message was being held in quarantine. It was not, in fact, spam, so I clicked the "Release" button in the notification email. Below is the message I got as a result. There's a problem here. Can you see what it is?
#infosec #Microsoft365 #UX

Microsoft Copilot for SharePoint just made recon a whole lot easier. 🚨
 
One of our Red Teamers came across a massive SharePoint, too much to explore manually. So, with some careful prompting, they asked Copilot to do the heavy lifting...
 
It opened the door to credentials, internal docs, and more.
 
All without triggering access logs or alerts.
 
Copilot is being rolled out across Microsoft 365 environments, often without teams realising Default Agents are already active.
 
That’s a problem.
 
Jack, our Head of Red Team, breaks it down in our latest blog post, including what you can do to prevent it from happening in your environment.
 
📌Read it here: pentestpartners.com/security-b

#Microsoft #vendorLockIn rant…
My new job is a #Microsoft365 shop, so we use #OneNote.
I am on a MacBook.
I have a notebook with many pages.
I needed to generate a list of the page titles. There is no way to do that within the desktop or web app.
There's no way to export the notebook in another format (there supposedly is on PC, but not macOS).
I had to use the developer console in the web app to grab the page list HTML and edit it in a text editor to extract the page titles.
Ridiculous.

Replied in thread

@mollyanglin It's quite a paradox. For enterprise IT, everything is rolling out too fast and without necessary governance controls in place to build trust in #Copilot.

For the individuals who want to use Copilot, they can never be sure whether Microsoft has A) not yet shipped what they demonstrate, B) moved it to a different place, or whether it's their IT dept who have C) intentionally or D) accidentally stopped the feature in their #Microsoft365 tenant.

Bei #Hosteurope herrscht offenbar ein ziemlich hoher Lackkonsum. Ich höre gerade von einem Kunden, dass die ernsthaft und trotz der Entwicklungen in den USA Email zwangsweise auf #Microsoft365 umstellen. Dem entgehen kann man als Kunde nur durch Löschen der Emailkonten, also de facto Beenden der Geschäftsbeziehung (was der Kunde [KMU] auch tun wird). #Hetzner beispielsweise bietet schon Migrationspfade dafür, aber sind halt "ein paar" Adressen.

Un-fucking-fassbar.

⚠️ Cyber threat: “Cookie Bite” attack hijacks Microsoft 365 — no malware required. Researchers uncovered a new attack that abuses Azure Entra ID auth cookies (ESTSAUTH + ESTSAUTHPERSISTENT) to:
🍪 Hijack sessions in Outlook, Teams, and more
🚫 Bypass MFA
📥 Avoid traditional endpoint detection
🧩 Spread via malicious browser extensions

🛡️ Organizations must:
🔐 Audit browser extension permissions
📊 Monitor for persistent cloud session abuse
🧠 Train users to avoid risky browser behaviors

Invisible. Persistent. And just one stolen cookie away.

#CyberSecurity #Microsoft365 #MFABypass #EntraID #ThreatIntel #security #privacy #cloud #infosec
darkreading.com/remote-workfor

Microsoft 365 credential theft is evolving quickly!

Attackers are no longer just stealing your login—they’re using your own AI tools like Microsoft Copilot to accelerate fraud from inside your environment.

Our 4-minute video breaks down how threat actors are targeting Microsoft 365 accounts and weaponizing Copilot, Teams, SharePoint, and more to perform rapid reconnaissance, commit fraud, and exploit centralized trust systems.

Watch now to learn:

▪ How Copilot can be used against you
▪ Real phishing tactics mimicking Microsoft 365, Adobe & DocuSign
▪ Why SSO, OAuth, and poor access controls can make attacks worse
▪ What your organization must do to stay ahead

Watch the video! youtu.be/zaBwxy1Gjhc

Now I’ve got to scrape together about 90 dollars to start my business, Cogentiuum LLC. I bought the domain cogentiuum.com last night. I also have to get web and email setup. For web hosting, I’m going to use ServerCheap. I’ve had a good experience with them. For email and productivity, I’m going with #Google #Workspace because of the included feature to digitally sign documents. I don’t like Google though. They’re pretty damn evil and support is virtually nonexistent when problems do arise. But #Microsoft365 is arguably more of a quagmire. Thoughts?