Skip to the main content.

ABT Blog

Read about mortgage technology solutions topics

Microsoft Entra Connect Sync bridge between Active Directory and Microsoft Entra ID breaking at the September 30 2026 deadline, with sync engine and health agent version panels

11 min read

Entra Connect Sync Stops Sept 30: Check Both Versions

In This Article What stops on September 30, and what does not The alarms are on the same list The floor expires 23 days after the deadline What changed on September 16 Why this is a control problem, not just an IT chore The nine-day check Connect...

Read More
Outlook shows an email with its appraisal PDF attachment blocked, beside Microsoft Entra ID Conditional Access reporting a non-compliant device and Microsoft Intune showing the device out of compliance.

8 min read

Conditional Access Now Covers Outlook Attachments

Microsoft moved Outlook attachment operations behind a separate internal application, and the Conditional Access policies you already scoped to...

Read More
A standard perimeter penetration test stops at the network edge while session token theft, mailbox forwarding and malicious app consent happen inside the Microsoft 365 tenant

14 min read

Microsoft 365 Penetration Testing for Financial Institutions

In This Article What a penetration test is, in your regulator's words What your regulator actually requires What Microsoft permits you to test The...

Read More
Microsoft Power Pages admin panel showing Anonymous Access set to Allowed, with customer records flowing out of an open vault

11 min read

Power Pages Misconfiguration: No CVE, No Patch

Two financial regulators flagged a Microsoft Power Pages setting that exposes Dataverse records. No CVE, no patch, and your scanner will not see it.

Read More
An open manila vendor file folder on a desk holding printed audit reports, with a card bearing the Microsoft 365 logo resting on top and a tab labeled VENDOR FILE

17 min read

Vendor Due Diligence on Microsoft 365: What Goes in the File

In This Article The Questionnaire That Comes Back Empty The Passage That Answers This Step One: Document the Limitation Step Two: Obtain Alternative...

Read More
Microsoft 365 Exchange Online SMTP AUTH basic authentication deadline, December 2026, with legacy sender devices

13 min read

The Last Basic Authentication Deadline: SMTP AUTH Changes in December 2026

In This Article What actually changes at the end of December 2026 What in your institution still sends mail this way How to find every dependency...

Read More
Microsoft 365 adversary in the middle attack chain ending in a registered Microsoft Entra ID device and an enrolled Windows Hello for Business credential

11 min read

Knight Office AiTM Kit: Persistence Past Password Reset

In This Article What Huntress found How this differs from the August Windows Hello research The step that survives your incident response Whether...

Read More
A written password policy binder showing 90-day expiration beside a Microsoft Graph PowerShell window showing PasswordValidityPeriodInDays 2147483647, labelled mismatch

15 min read

Microsoft 365 Password Policy for Financial Institutions

In This Article Start With the Tenant, Not the Policy Binder What the Cloud Password Policy Actually Enforces Two Gaps Between the Written Policy and...

Read More
Shadow IT discovery dashboard showing sanctioned and unsanctioned cloud apps for a financial institution, with Microsoft 365 branding

15 min read

Shadow IT in Financial Institutions: Find It, Govern It

Your staff already told you which tools they need. They just did not ask first. How to find unsanctioned apps in a Microsoft 365 tenant with Defender...

Read More
Cyber incident reporting deadlines for financial institutions, showing the 36 hour, 72 hour and 30 day regulatory clocks

12 min read

The 36-Hour, 72-Hour, and 30-Day Incident Reporting Clocks

Three federal rules, three deadlines, and three different definitions of the moment the clock starts. What triggers each one, and what Microsoft 365...

Read More