Skip to the main content.

ABT Blog

Read about mortgage technology solutions topics

Regulatory Compliance

Microsoft 365 hero image: four laptops, each with its own padlock, backing up to Microsoft Entra ID, labeled Windows LAPS and Microsoft Intune

12 min read

Windows LAPS: A Unique Local Admin Password on Every Managed Device

In This Article What Windows LAPS does Why a shared admin password puts every device at risk Windows LAPS vs. legacy Microsoft LAPS Is Windows LAPS...

Read More
Calendar showing October 13, 2026 beside Windows 10, Office 2021, Windows Server 2012 R2 and Windows 11 24H2 cards marked updates end, with the Microsoft 365 logo

13 min read

Microsoft End of Support October 2026: Windows 10 and Office

Microsoft end of support in October 2026 hits Windows 10 ESU Year 1, Office 2021, Windows Server 2012 R2. What banks, credit unions, and lenders do...

Read More
Microsoft Entra Connect Sync bridge between Active Directory and Microsoft Entra ID breaking at the September 30 2026 deadline, with sync engine and health agent version panels

11 min read

Entra Connect Sync Stops Sept 30: Check Both Versions

In This Article What stops on September 30, and what does not The alarms are on the same list The floor expires 23 days after the deadline What...

Read More
A standard perimeter penetration test stops at the network edge while session token theft, mailbox forwarding and malicious app consent happen inside the Microsoft 365 tenant

14 min read

Microsoft 365 Penetration Testing for Financial Institutions

In This Article What a penetration test is, in your regulator's words What your regulator actually requires What Microsoft permits you to test The...

Read More
Microsoft Power Pages admin panel showing Anonymous Access set to Allowed, with customer records flowing out of an open vault

11 min read

Power Pages Misconfiguration: No CVE, No Patch

Two financial regulators flagged a Microsoft Power Pages setting that exposes Dataverse records. No CVE, no patch, and your scanner will not see it.

Read More
An open manila vendor file folder on a desk holding printed audit reports, with a card bearing the Microsoft 365 logo resting on top and a tab labeled VENDOR FILE

17 min read

Vendor Due Diligence on Microsoft 365: What Goes in the File

In This Article The Questionnaire That Comes Back Empty The Passage That Answers This Step One: Document the Limitation Step Two: Obtain Alternative...

Read More
Microsoft Entra ID legacy risk policies deactivated with an October 1 2026 deadline, replaced by Conditional Access protecting bank accounts

14 min read

Entra Risk Policies Retire Oct 1, 2026: What Banks Must Do

In This Article What actually changes on October 1 The self-service loop that goes away first The detections keep firing. No risk policy acts on...

Read More
Microsoft Entra ID External Identities panel showing four external guest accounts with MFA, beside an Anyone with the link card outside the directory perimeter

14 min read

Microsoft 365 Guest Access for Financial Institutions

In This Article What changed in your tenant this summer Guest access, external access, and Anyone links are three different doors The blind spot...

Read More
Microsoft Entra ID access reviews console replacing a manual access review spreadsheet, showing that a 500 member group reviewed by 3 owners requires 503 licenses

13 min read

Entra ID Access Reviews for Financial Institutions

Your examiner expects two layers of user access review: resource owners verifying that access matches job roles, plus a periodic independent check....

Read More
Where is your Microsoft 365 data stored, showing four services with a durable United States commitment and four without

11 min read

Where Is Your Microsoft 365 Data Stored? Data Residency for US Financial Institutions

A vendor questionnaire asks where your Microsoft 365 data is stored. For a United States tenant, four services carry a durable commitment and four do...

Read More