Skip to the main content.

ABT Blog

Read about mortgage technology solutions topics

Microsoft Entra ID legacy risk policies deactivated with an October 1 2026 deadline, replaced by Conditional Access protecting bank accounts

14 min read

Entra Risk Policies Retire Oct 1, 2026: What Banks Must Do

In This Article What actually changes on October 1 The self-service loop that goes away first The detections keep firing. No risk policy acts on them. The license question most institutions have not asked How to migrate before October 1 Three things...

Read More
Microsoft Entra ID External Identities panel showing four external guest accounts with MFA, beside an Anyone with the link card outside the directory perimeter

14 min read

Microsoft 365 Guest Access for Financial Institutions

In This Article What changed in your tenant this summer Guest access, external access, and Anyone links are three different doors The blind spot...

Read More
Hotel conference room laptop showing a captive portal sign-in, with a stolen Microsoft 365 session token flowing to an attacker past Microsoft Entra ID controls

14 min read

Hotel Wi-Fi Is Stealing Microsoft 365 Sessions

In This Article What Microsoft Found on Hotel and Conference Wi-Fi Two Attack Paths, and Why the Difference Decides Your Controls The Part That...

Read More
Microsoft Entra ID access reviews console replacing a manual access review spreadsheet, showing that a 500 member group reviewed by 3 owners requires 503 licenses

13 min read

Entra ID Access Reviews for Financial Institutions

Your examiner expects two layers of user access review: resource owners verifying that access matches job roles, plus a periodic independent check....

Read More
Where is your Microsoft 365 data stored, showing four services with a durable United States commitment and four without

11 min read

Where Is Your Microsoft 365 Data Stored? Data Residency for US Financial Institutions

A vendor questionnaire asks where your Microsoft 365 data is stored. For a United States tenant, four services carry a durable commitment and four do...

Read More
Three-stage diagram showing a password-protected closing package that Microsoft Defender for Office 365 cannot scan, moving to a quarantine folder with an off-by-default admin toggle

15 min read

Defender's New Password-Protected Attachment Quarantine: What Lenders Should Decide

Microsoft is adding an opt-in Safe Attachments setting that quarantines password-protected attachments Defender cannot scan or detonate. It is off by...

Read More
Microsoft 365 identity security concept illustrating AD FS federation token signing key protection for financial institutions

13 min read

AD FS Key Container Hardening: What Changes for Financial Institutions on October 13

The October 2026 Windows security update changes permissions on the AD FS Distributed Key Manager container by default. Here is what it removes,...

Read More
ABT's 30-Day Copilot Sprint for financial institutions: kickoff, champions, office hours, and the Day 30 ROI readout

9 min read

The 30-Day Copilot Sprint for Financial Institutions

In This Article Why Copilot Rollouts Stall Inside the 30-Day Copilot Sprint Readiness Comes Before Day 1 What You Walk Away With The Day 30 ROI...

Read More
Microsoft 365 profile card with lower directory fields glowing orange, beside the headline The staff directory fills in, sign-in names included, late August

13 min read

Microsoft 365 Profile Cards: 11 Properties Go Visible

Microsoft is flipping eleven Microsoft 365 profile card properties from hidden to visible by default in late August 2026, including user principal...

Read More
Microsoft 365 audit log timeline dissolving at the 180 day mark, with the Microsoft 365 logo, illustrating audit log retention limits for financial institutions

12 min read

Microsoft 365 Audit Log Retention for Financial Institutions

In This Article Your tenant keeps two audit logs, on two different clocks What each license actually retains The Audit Premium gap: one year, but...

Read More