Omzig Bytes

Our weekly email: one Microsoft 365, Copilot, Azure, or security move you can make this week, in plain English, for the people who run healthcare, legal, wealth, and CPA firms.

Microsoft 365 security

You're paying for security you never switched on

Most Microsoft 365 plans already include the protections firms buy twice — MFA, Conditional Access, Safe Links, Defender. They just ship dark.

1 min read

Read this edition

The move this weekOpen your Microsoft Secure Score and read what it says. It is a list of protections you already own, ranked by impact. Turning on the top three items typically does more for your security than any product you could buy this quarter.

Earlier editions

49 in the archive · newest first

  1. 1 min read

    Wealth management

    Over 99% of password spray attacks use legacy authentication

    Microsoft's own data says more than 99% of password spray attacks arrive through legacy authentication.

  2. 1 min read

    Legal

    They call your office pretending to be your IT department

    The FBI put out an alert this year about a crew that's been working U.S. law firms for about three years.

  3. 1 min read

    Healthcare

    Microsoft is retiring texted sign-in codes

    Microsoft is retiring text-message and phone-call sign-in codes. The clock started September 1.

  4. 1 min read

    Wealth management

    Microsoft is turning on sign-in rules in your tenant. Ready or not.

    Microsoft is now creating security policies inside your Microsoft 365 tenant for you — and it will turn them on whether you act or not.

  5. 1 min read

    CPA firms

    You're already paying for security you never turned on

    Most of the CPA firms I talk to are already paying for security tools nobody ever switched on.

  6. 1 min read

    CPA firms

    Attackers aren't hacking AI. They're using your team's curiosity about it.

    Microsoft says a single phishing campaign sent up to 100,000 emails in one day — every one of them dressed up as ChatGPT.

  7. 1 min read

    CPA firms

    Microsoft 365 doesn't publish your DMARC record for you

    Two weeks out from the October filing deadline, the worst email problem a CPA firm can have isn't a full inbox.

  8. 1 min read

    CPA firms

    Microsoft raised M365 prices July 1. Business Premium didn't move.

    Microsoft raised the price of most Microsoft 365 plans on July 1. Business Premium wasn't one of them.

  9. 1 min read

    Wealth management

    Nobody from IT will ever call to reset your sign-in

    Microsoft published something on September 9 that should change how you think about security training.

  10. 1 min read

    Wealth management

    Your firm's stolen login sells for $10 on the dark web

    Microsoft published research in June that puts a price on your firm's credentials.

  11. 1 min read

    Wealth management

    Client data rarely gets stolen. It gets shared.

    Microsoft shipped something last week that says a lot about where client data actually goes.

  12. 1 min read

    CPA firms

    Microsoft holds your deleted files for 93 days. Then they're gone.

    Most CPA firms I talk to assume the cloud-versus-server backup debate is settled.

  13. 1 min read

    Healthcare

    Microsoft retired the Virtual Appointments app in Teams

    Microsoft has retired the Virtual Appointments app in Teams, and most of the practices I talk to haven't noticed yet.

  14. 1 min read

    Wealth management

    Your audit trail probably stops at 180 days

    Here's the call nobody plans for: a client asks what an intruder saw in your email six months ago, and the honest answer is that the record is already gone.

  15. 1 min read

    Wealth management

    Your laptop says it's encrypted. That doesn't always mean it is.

    Windows now turns on drive encryption by itself on far more laptops than it used to.

  16. 1 min read

    Legal

    Your text-message login codes now have an expiration date

    Microsoft made passkeys the default sign-in for Microsoft 365 on September 1, and the six-digit text codes your firm logs in with now have an expiration date.

  17. 1 min read

    Healthcare

    A below-normal season still only takes one storm

    NOAA's updated outlook puts this Atlantic season at a 75% chance of finishing below normal.

  18. 1 min read

    Legal

    By default, Teams lets any outside organization message your firm

    Microsoft's threat researchers published findings on September 2 that should change how your firm thinks about Teams.

  19. 1 min read

    Legal

    Ending the contract doesn't end their admin access

    Most firms that switch IT providers assume the old company's access ends when the invoice does.

  20. 1 min read

    Wealth management

    MFA didn't stop it. Find out who clicks before an attacker does.

    A phishing service called BigBear 2.0 walked straight through multi-factor authentication at 258 organizations this month.

  21. 1 min read

    Wealth management

    Microsoft is phasing out text-message sign-in codes. Do you know who still relies on them?

    On September 1, Microsoft started moving Microsoft 365 users off text-message sign-in codes by default.

  22. 1 min read

    Healthcare

    Copilot reads everything your team can already see

    Microsoft's own playbook for turning on Copilot starts with a step almost everyone skips: fix who can see what, first.

  23. 1 min read

    Legal

    Most cyber claims aren't ransomware. Check your wire fraud sublimit.

    Most of the cyber insurance conversations I have start with ransomware.

  24. 1 min read

    Legal

    Year two of Windows 10 support costs double

    Microsoft stopped supporting Windows 10 in October 2025. Plenty of firms around here didn't replace those machines.

  25. 1 min read

    Healthcare

    You can't secure what you can't see

    A Houston-based healthcare operator with 27 facilities across 12 states disclosed earlier this month that patient and employee information was stolen in an August…

  26. 1 min read

    Wealth management

    Antivirus can't stop someone who's already logged in

    Antivirus is still doing a job that stopped being the whole job about a decade ago.

  27. 1 min read

    Wealth management

    Standing admin rights turn one phished employee into a full breach

    In May, Microsoft published the breakdown of a breach that didn't involve a single piece of malware.

  28. 1 min read

    Legal

    The risk isn't the flaw. It's the gap before you patch.

    Microsoft shipped fixes for nearly a thousand security flaws last week.

  29. 1 min read

    Wealth management

    Geo-blocking tells you where a sign-in came from. Not who.

    In three days this past April, Microsoft tracked a phishing wave that reached more than 13,000 organizations.

  30. 1 min read

    Wealth management

    The gap isn't skill. It's coverage.

    Microsoft logged roughly 7.6 billion phishing attempts in a single quarter this year.

  31. 1 min read

    Healthcare

    Can you list every phone with practice email on it?

    Microsoft shipped something in Intune's late-August update that most medical practices should care about more than they'll realize.

  32. 1 min read

    Legal

    The attack your antivirus was never built to see

    A crew researchers call Silent Ransom Group has been calling law firms and pretending to be their IT department.

  33. 1 min read

    Healthcare

    The attacker didn't guess a password. He called your front desk.

    In July, Health-ISAC warned healthcare organizations about a rise in attacks that start with a phone call instead of a hacked password.

  34. 1 min read

    Legal

    Set up your break-glass admin account before you need it

    On September 1, Microsoft started making passkeys the default sign-in method in Microsoft 365.

  35. 1 min read

    Healthcare

    You bought the practice. Their logins don't come with it.

    Microsoft's own tooling for merging two Microsoft 365 tenants moves your content.

  36. 1 min read

    Healthcare

    MFA said yes. The attacker still got in.

    Over three days in April, one phishing campaign hit more than 35,000 people across 13,000 organizations.

  37. 1 min read

    Legal

    “Anyone with the link” is not a client portal

    The FBI warned in May that an extortion crew has been calling law firms while posing as their own IT help desk.

  38. 1 min read

    Legal

    Backups don't help when the thieves just copy your files

    The FBI put out an advisory this year about a crew that has been working U.S. law firms since 2023.

  39. 1 min read

    Legal

    Your team already approved the apps. Your password reset does nothing.

    In March, Microsoft's security team published a breakdown of attackers abusing OAuth apps — those "Sign in with Microsoft" permission screens.

  40. 1 min read

    Small business

    97% of identity attacks come down to passwords

    Microsoft's latest security report found that more than 97% of identity attacks are password attacks.

  41. 1 min read

    Legal

    One lost day costs a 20-person firm 160 working hours

    The FBI put out an alert this year about a crew that calls law firms pretending to be the IT department.

  42. 1 min read

    Wealth management

    The first email asks for nothing. That's the whole trick.

    On June 1, Microsoft tracked a single business email compromise campaign that reached more than 67,000 people across 42,000 organizations in about three hours.

  43. 1 min read

    Wealth management

    Attackers don't skip small firms. They start with them.

    Microsoft's most recent Digital Defense Report has a number in it that should change how small firms think about security.

  44. 1 min read

    Microsoft 365 Copilot

    Copilot will surface every file you forgot to lock down

    Copilot doesn't leak data — it reveals the oversharing that was already there. Fix permissions before rollout, not after.

  45. 1 min read

    Cyber insurance

    Why your cyber insurance application keeps getting denied

    Insurers now want MFA, EDR, and tested backups attested in writing — and they check. Underwriting is a security audit with a premium attached.

  46. 1 min read

    Healthcare compliance

    HIPAA-ready Microsoft 365 without the consultant markup

    The controls the HIPAA Security Rule expects — access control, encryption, audit logging — already live in your Microsoft 365 tenant.

  47. 1 min read

    Financial · CPA

    Send client tax docs without hoping nobody intercepts them

    Microsoft 365 email encryption is a setting, not a product. Turn it on and stop trusting plain email with Social Security numbers.

  48. 1 min read

    Legal

    Stop emailing privileged files — give clients a real portal

    A SharePoint client portal keeps privileged documents in one governed place — instead of scattered across inboxes you cannot control.