SecurityBrief India - Technology news for CISOs & cybersecurity decision-makers
India
CoreView launches Microsoft 365 security research lab

CoreView launches Microsoft 365 security research lab

Tue, 6th Oct 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

CoreView has launched Intelligence Labs, an initiative focused on Microsoft 365 security research.

The launch follows company research that found a gap between how IT leaders rate their Microsoft 365 security posture and the controls they have in place.

According to CoreView, 62% of IT leaders describe their Microsoft 365 security posture as established or advanced. At the same time, 54% lack at least one foundational control, such as full multi-factor authentication coverage for administrators, privileged access management, or configuration tamper detection.

Intelligence Labs will publish technical research and practical guidance for Microsoft 365 security teams. It will also analyse newly disclosed attacks and their implications for organisations securing Microsoft environments.

The initiative is led by Kasper Lindgaard, Vice President of Security Strategy at CoreView. He previously led Secunia Research and has served as a Chief Information Security Officer in regulated services environments.

At launch, available material covers authentication methods in Entra ID and non-human identities. It also includes guidance on enterprise application authentication and Microsoft's passkey rollout.

Security gap

The findings point to a disconnect between IT teams' confidence and the practical state of their security controls. In particular, the absence of core protections for administrator accounts and privileged access suggests some organisations may still be exposed despite rating their posture highly.

Microsoft 365 remains a major operational environment for many companies, and security teams often manage a mix of identities, applications, and settings across tenants. That complexity can make basic controls difficult to verify and maintain, especially when configuration changes affect security posture over time.

Lindgaard said Intelligence Labs would focus on visibility and technical explanation for practitioners. "Microsoft 365 is incredibly complex, and even experienced teams can get some of the fundamentals wrong," said Kasper Lindgaard, Vice President of Security Strategy at CoreView.

"Intelligence Labs is designed to help practitioners understand what's actually happening inside their tenants and provide engineering context on how changes affect their security posture. Our ambition is for it to become the reference point for Microsoft 365 security practitioners," he said.

Research focus

The new unit expands CoreView's public-facing work on Microsoft 365 security beyond software and administration into research and technical commentary. It will examine both existing weaknesses and emerging issues affecting tenants.

Its early research agenda reflects current concerns in cloud identity management, where administrator protection, non-human identities, and application authentication have become central issues for defenders. Passkeys have also drawn attention as organisations assess how newer authentication approaches fit into established access policies.

For security teams, the aim is to provide more concrete guidance on what is happening inside Microsoft 365 environments rather than relying on broad maturity assessments. CoreView's survey findings suggest those assessments do not always align with the presence of baseline controls.

CoreView says more than 4,000 organisations use its products to manage Microsoft 365 environments, including large and complex tenants.