Skip to the main content.

ABT Blog

Read about mortgage technology solutions topics

Compliance

A written password policy binder showing 90-day expiration beside a Microsoft Graph PowerShell window showing PasswordValidityPeriodInDays 2147483647, labelled mismatch

15 min read

Microsoft 365 Password Policy for Financial Institutions

In This Article Start With the Tenant, Not the Policy Binder What the Cloud Password Policy Actually Enforces Two Gaps Between the Written Policy and...

Read More
Shadow IT discovery dashboard showing sanctioned and unsanctioned cloud apps for a financial institution, with Microsoft 365 branding

15 min read

Shadow IT in Financial Institutions: Find It, Govern It

Your staff already told you which tools they need. They just did not ask first. How to find unsanctioned apps in a Microsoft 365 tenant with Defender...

Read More
Cyber incident reporting deadlines for financial institutions, showing the 36 hour, 72 hour and 30 day regulatory clocks

12 min read

The 36-Hour, 72-Hour, and 30-Day Incident Reporting Clocks

Three federal rules, three deadlines, and three different definitions of the moment the clock starts. What triggers each one, and what Microsoft 365...

Read More
FTC Safeguards Rule shield covering a CPA firm, title agency, and auto dealer, with a Microsoft 365 security dashboard

9 min read

You Might Be Running a Financial Institution. The FTC Thinks So.

In This Article The Label You Did Not Choose Who Is Covered? The List Is Longer Than You Think What the Safeguards Rule Actually Requires What...

Read More
Microsoft 365 shared mailbox security for banks, credit unions, and mortgage companies

15 min read

Shared Mailbox Security for Financial Institutions

Shared mailboxes run the wire desk and the servicing queue. Microsoft documents several behaviors, including that converting a departing employee's...

Read More
Microsoft 365 Exchange Web Services retiring, with traffic migrating to the Microsoft Graph API ahead of the August 2026 action deadline

12 min read

Exchange Web Services Retires: The August 2026 Deadline

Microsoft begins blocking Exchange Web Services on October 1, 2026 and disables it permanently on April 1, 2027. For financial institutions still...

Read More
Microsoft Entra ID access reviews console replacing a manual access review spreadsheet, showing that a 500 member group reviewed by 3 owners requires 503 licenses

13 min read

Entra ID Access Reviews for Financial Institutions

Your examiner expects two layers of user access review: resource owners verifying that access matches job roles, plus a periodic independent check....

Read More
A Microsoft Teams AI meeting archive .meeting file flowing into a secure tenant storage vault with a five-year retention dial and Microsoft 365 branding, for financial institutions

13 min read

Microsoft Teams AI Meeting Archives Go Default-On for Financial Institutions

In This Article What Microsoft Teams Starts Doing by Default What a .meeting File Is, and What It Is Not The Five-Year Default Nobody at Your...

Read More
Microsoft-branded hero for the Microsoft Entra provisioning flaw CVE-2026-57100, identity control plane security for banks, credit unions, and mortgage companies

13 min read

Microsoft Entra Provisioning Flaw (CVE-2026-57100): What Financial Institutions Must Verify

Microsoft fixed a 9.9 elevation-of-privilege flaw (CVE-2026-57100) in the Microsoft Entra provisioning service server-side, with no customer patch....

Read More
Microsoft 365 incident response for financial institutions: alerts from endpoints, email, and identity correlate in Microsoft Defender XDR into a unified incident, with Microsoft Sentinel and Microsoft Purview carrying the response.

12 min read

Microsoft 365 Incident Response Plan for Financial Institutions: The Examiner-Ready Playbook

A written incident response plan is examiner-mandated for banks, credit unions, and mortgage companies. Here are the seven elements it must cover and...

Read More