Skip to the main content.

ABT Blog

Read about mortgage technology solutions topics

security

Microsoft 365 adversary in the middle attack chain ending in a registered Microsoft Entra ID device and an enrolled Windows Hello for Business credential

11 min read

Knight Office AiTM Kit: Persistence Past Password Reset

In This Article What Huntress found How this differs from the August Windows Hello research The step that survives your incident response Whether...

Read More
A written password policy binder showing 90-day expiration beside a Microsoft Graph PowerShell window showing PasswordValidityPeriodInDays 2147483647, labelled mismatch

15 min read

Microsoft 365 Password Policy for Financial Institutions

In This Article Start With the Tenant, Not the Policy Binder What the Cloud Password Policy Actually Enforces Two Gaps Between the Written Policy and...

Read More
Microsoft Entra ID Conditional Access exclusion list review for financial institutions

12 min read

Conditional Access Exclusions: The List Nobody Reviews

Every institution grants Conditional Access exceptions. Microsoft documents how those lists grow, names access reviews as the compensating control,...

Read More
Microsoft 365 shared mailbox security for banks, credit unions, and mortgage companies

15 min read

Shared Mailbox Security for Financial Institutions

Shared mailboxes run the wire desk and the servicing queue. Microsoft documents several behaviors, including that converting a departing employee's...

Read More
Windows Hello for Business key abuse and Microsoft Entra ID device registration

15 min read

Windows Hello for Business Key Abuse: What Financial Institutions Need to Verify

Malware already running in a signed-in Windows session can use that user's Windows Hello for Business key to authenticate to Microsoft Entra ID, with...

Read More
Dark editorial illustration of a hijacked Microsoft 365 session quietly reading payroll and finance mail while security alerts stay silent

13 min read

Payroll Pirates: The Microsoft 365 Attack Your Alerts Miss

A Microsoft 365 session-hijacking campaign is reading payroll and finance mail while deliberately avoiding the account-modification signals most...

Read More
Microsoft 365 and Copilot Studio agent authentication: end-user credentials versus maker-provided credentials

10 min read

Copilot Studio Agent Authentication: The August 25 Question

Microsoft is shipping an admin control that stops Copilot Studio agents from authenticating with their builder's stored credentials. It is off by...

Read More
Microsoft Entra ID legacy risk policies deactivated with an October 1 2026 deadline, replaced by Conditional Access protecting bank accounts

14 min read

Entra Risk Policies Retire Oct 1, 2026: What Banks Must Do

In This Article What actually changes on October 1 The self-service loop that goes away first The detections keep firing. No risk policy acts on...

Read More
Hotel conference room laptop showing a captive portal sign-in, with a stolen Microsoft 365 session token flowing to an attacker past Microsoft Entra ID controls

14 min read

Hotel Wi-Fi Is Stealing Microsoft 365 Sessions

In This Article What Microsoft Found on Hotel and Conference Wi-Fi Two Attack Paths, and Why the Difference Decides Your Controls The Part That...

Read More
Three-stage diagram showing a password-protected closing package that Microsoft Defender for Office 365 cannot scan, moving to a quarantine folder with an off-by-default admin toggle

15 min read

Defender's New Password-Protected Attachment Quarantine: What Lenders Should Decide

Microsoft is adding an opt-in Safe Attachments setting that quarantines password-protected attachments Defender cannot scan or detonate. It is off by...

Read More