Author name: Antonio Rennvick

Antonio Rennvick is an IT Infrastructure Manager with 15+ years running enterprise Active Directory, Microsoft 365, and Azure environments. He's Microsoft certified (AZ-104, MS-102) and writes Core365 Cloud to share what actually works in production—PowerShell automation, AD deep dives, and security hardening drawn from real-world work, not test labs.

DNS Networking

DNS Record Types Explained: A, AAAA, CNAME, MX, TXT, SRV, CAA, PTR, HTTPS/SVCB + Deep Troubleshooting – Part 1

DNS looks deceptively simple—names in, IPs out—but production DNS is a distributed database with caching, delegation boundaries, transport quirks, and cryptographic validation (DNSSEC) layered on top. This guide is written as a “field manual”: what each DNS record type does, when to use it, how to configure it, and what to check when it breaks.

Critical Microsoft Exchange Server vulnerability CVE-2026-42897 affecting Outlook Web Access exploited via malicious email
Cybersecurity Exchange Server Security

🚨 Critical Microsoft Exchange Server Vulnerability (CVE‑2026‑42897) Actively Exploited

⏱️ Estimated Read Time 6–8 minutes A newly disclosed critical Microsoft Exchange Server vulnerability (CVE‑2026‑42897) is being actively exploited in the wild, prompting urgent action from IT administrators worldwide. This high‑severity flaw directly targets on‑premises Exchange environments, allowing attackers to execute malicious code through Outlook Web Access (OWA) sessions. With a CVSS score of 8.1,

Find caller computer causing repeated Active Directory account lockouts using Event ID 4740 report
Active Directory Automation PowerShell Security

Stop Repeated Active Directory Lockouts: Find the Caller Computer (Event ID 4740) with a PowerShell HTML + Email Report

If you’ve ever dealt with “my account is locked again” tickets, you know the real pain isn’t unlocking the account — it’s finding what keeps locking it. When a user gets locked out in Active Directory, the key investigative signal is Windows Security Event ID 4740 (“A user account was locked out”). [techpress.net] 💻 Download

Cloud Identity Cloud Security Defensive Engineering (SOC / Blue Team) Microsoft Entra Security

Azure AD / Microsoft Entra Conditional Access “Bypass” via Phantom Device Registration & PRT Abuse — A Deep Technical Breakdown

Time to read: 10–12 minutes (technical deep dive) Conditional Access (CA) in Microsoft Entra ID (formerly Azure AD) is often treated as the enforcement point for MFA, compliant-device requirements, location rules, and risk-based policies.Recent red-team research shows how an attacker can still reach protected resources without touching a corporate endpoint by abusing the device trust

Cloud Security Identity & Access Management Microsoft 365 Security Threat Detection Engineering

ConsentFix v3 and OAuth Consent Abuse in Microsoft Entra ID: Deep‑Dive Detection & Hardening for Microsoft 365

ConsentFix v3 is the latest evolution of browser‑native OAuth abuse that turns user/admin consent into persistent API access in Microsoft 365—often without needing to defeat MFA at the credential prompt. The right defense is not “more MFA.” It is consent surface reduction, consent telemetry, app governance, and token‑centric incident response. [pushsecurity.com], [techcommun…rosoft.com], [docs.azure.cn] Table of

Scroll to Top
×