Posts by Charles McBride
Microsoft Entra Hybrid Join: The New Kerberos Method Changes Everything for Education & Government IT
If your organization still runs Active Directory on-premises while using Microsoft 365 or Azure-based services, Hybrid Join is likely central to your device management strategy. Microsoft has now introduced a new Kerberos-based method for completing Hybrid Join — and for IT teams in education and government, it solves some very real, very persistent problems. What…
Read MoreHow Education Organizations Can Secure Sensitive Data and AI with Microsoft Purview
Protecting Student, Staff, and Institutional Data in a Modern Education Environment Across K–12 districts and higher education institutions alike, data is growing faster than ever—and so is the risk associated with it. From student records and financial data to HR files and research, education organizations manage vast amounts of sensitive information across cloud platforms like…
Read MoreStrengthening Cybersecurity in Education with Microsoft Defender XDR, Entra ID, and Sentinel
In the first session of our three-part webinar series, Forsyte IT Solutions explored how K–12 schools, school districts, and higher education institutions can strengthen their cybersecurity posture using Microsoft Security tools. This session focused on practical, real-world guidance for optimizing Microsoft Defender XDR, Microsoft Entra ID, and Microsoft Sentinel—helping education IT teams get more value…
Read MoreDefending Against “Legitimate Infrastructure” File-Sharing Phishing Campaigns
K‑12 school districts, colleges and universities, and public sector agencies operating in Microsoft 365 are increasingly being targeted by phishing campaigns that abuse legitimate cloud collaboration infrastructure. These attacks exploit native file‑sharing features in SharePoint Online, OneDrive for Business, and Google Drive to deliver malicious content while evading traditional email security controls. For education and…
Read MoreGuardian 365 IOC Bulletin: Monitoring Emerging Cyber Activity Linked to Iranian Threat Actors
Geopolitical events often influence the global cyber threat landscape. In recent weeks, security researchers and government agencies have been closely monitoring emerging cyber activity originating from Iran following renewed regional conflict. While overall activity levels remain moderate, historical patterns suggest that threat activity can escalate quickly as conditions evolve. As part of our ongoing commitment…
Read MoreDefender for Endpoint Effective Settings: See What’s Really Applied on Your Devices
When it comes to endpoint security, knowing what policies you intended to deploy isn’t always the same as knowing what’s actually applied on a device. Between Intune, Group Policy, SCCM, and local configurations, security settings can quickly become difficult to validate—especially in complex or transitioning environments. That’s where the Effective Settings page in Microsoft Defender…
Read MoreStrengthening Cyber Defense at Speed: Guardian 365, Inforcer, and the New IOC Feed
Cyber threats are evolving faster than ever — and the ability to respond quickly, consistently, and at scale has become a core requirement for modern security operations. As part of ongoing enhancements to Guardian 365, Forsyte is introducing the Guardian 365 IOC Feed, a new capability powered by Inforcer that enables rapid deployment of defensive…
Read MoreEnhancing Microsoft Teams Security: Integrating Tenant Allow/Block List and Preparing for Source of Authority Migration
Proactive Security and Threat Intelligence for Collaboration Tools As organizations increasingly rely on Microsoft Teams for real-time collaboration and communication, maintaining a secure environment is paramount. Threat actors are constantly seeking new vectors to compromise sensitive data, making proactive security and robust threat intelligence essential. The integration of Microsoft Teams with the Tenant Allow/Block List…
Read MoreWhen “Free” PDF Tools Become a Persistent Threat: Inside a Recurring NSteal Malware Campaign
A Simple Download with Lasting Consequences What starts as a routine PDF download can quickly turn into a recurring security headache. Several organizations have recently reported persistent detections of Trojan:Win32/NSteal.SA—even after endpoint protection appeared to successfully block the threat. Digging deeper revealed a consistent and troubling pattern: seemingly legitimate PDF utilities, malicious shortcuts, and cloud…
Read MoreGuardian 365 Monthly Bulletin: Major M365 Updates & Retirements – February 2026
Guardian 365 personnel perform a monthly review of the updates provided by Microsoft in the M365 Admin Message Center. Updates identified to have an impact on the services delivered by Guardian 365 and/or the applications on which those services rely are noted below for your reference and planning.
PLEASE NOTE, however, that reading this bulletin does not guarantee that other messages will not impact your environment. Forsyte recommends performing regular checks of the message center (requires admin account to access) to ensure preparedness for and understanding of upcoming Microsoft-driven changes.
Read More