Skip to the main content.

ABT Blog

Read about mortgage technology solutions topics

Microsoft 365

An open manila vendor file folder on a desk holding printed audit reports, with a card bearing the Microsoft 365 logo resting on top and a tab labeled VENDOR FILE

17 min read

Vendor Due Diligence on Microsoft 365: What Goes in the File

In This Article The Questionnaire That Comes Back Empty The Passage That Answers This Step One: Document the Limitation Step Two: Obtain Alternative...

Read More
Microsoft 365 adversary in the middle attack chain ending in a registered Microsoft Entra ID device and an enrolled Windows Hello for Business credential

11 min read

Knight Office AiTM Kit: Persistence Past Password Reset

In This Article What Huntress found How this differs from the August Windows Hello research The step that survives your incident response Whether...

Read More
FTC Safeguards Rule shield covering a CPA firm, title agency, and auto dealer, with a Microsoft 365 security dashboard

9 min read

You Might Be Running a Financial Institution. The FTC Thinks So.

In This Article The Label You Did Not Choose Who Is Covered? The List Is Longer Than You Think What the Safeguards Rule Actually Requires What...

Read More
Dark editorial illustration of a hijacked Microsoft 365 session quietly reading payroll and finance mail while security alerts stay silent

13 min read

Payroll Pirates: The Microsoft 365 Attack Your Alerts Miss

A Microsoft 365 session-hijacking campaign is reading payroll and finance mail while deliberately avoiding the account-modification signals most...

Read More
Microsoft 365 and Copilot Studio agent authentication: end-user credentials versus maker-provided credentials

10 min read

Copilot Studio Agent Authentication: The August 25 Question

Microsoft is shipping an admin control that stops Copilot Studio agents from authenticating with their builder's stored credentials. It is off by...

Read More
Microsoft Entra ID legacy risk policies deactivated with an October 1 2026 deadline, replaced by Conditional Access protecting bank accounts

14 min read

Entra Risk Policies Retire Oct 1, 2026: What Banks Must Do

In This Article What actually changes on October 1 The self-service loop that goes away first The detections keep firing. No risk policy acts on...

Read More
Microsoft Entra ID External Identities panel showing four external guest accounts with MFA, beside an Anyone with the link card outside the directory perimeter

14 min read

Microsoft 365 Guest Access for Financial Institutions

In This Article What changed in your tenant this summer Guest access, external access, and Anyone links are three different doors The blind spot...

Read More
Microsoft Entra ID access reviews console replacing a manual access review spreadsheet, showing that a 500 member group reviewed by 3 owners requires 503 licenses

13 min read

Entra ID Access Reviews for Financial Institutions

Your examiner expects two layers of user access review: resource owners verifying that access matches job roles, plus a periodic independent check....

Read More
Where is your Microsoft 365 data stored, showing four services with a durable United States commitment and four without

11 min read

Where Is Your Microsoft 365 Data Stored? Data Residency for US Financial Institutions

A vendor questionnaire asks where your Microsoft 365 data is stored. For a United States tenant, four services carry a durable commitment and four do...

Read More
Microsoft 365 identity security concept illustrating AD FS federation token signing key protection for financial institutions

13 min read

AD FS Key Container Hardening: What Changes for Financial Institutions on October 13

The October 2026 Windows security update changes permissions on the AD FS Distributed Key Manager container by default. Here is what it removes,...

Read More