By Yogesh Deshpande, Technical Director, Paladin Security
Microsoft 365 Security · Cloud Identity · Assume-Breach Assessment

One identity, several control planes

The mailbox is reconnaissance

Search follows existing permissions

Consent can outlive the password

Conditional Access decides whether a credential is enough

Authentication exceptions deserve their own review

Privilege makes the path shorter

Can the tenant show what happened?

Assess the path, not just the settings