Microsoft Domain Services is a technology platform tracked across 2 threat clusters and 1 intelligence report mention on ThreatCluster. First observed November 11, 2025; most recent activity November 11, 2025.
Microsoft Domain Services (commonly understood as Azure AD Domain Services) is a cloud-based managed domain platform that provides domain join, Kerberos/NTLM authentication, and group policy without on-premises domain controllers. It serves as a core identity/authentication layer for Windows workloads in cloud environments, making its security posture critical for defending against identity-driven threats and abuse of Microsoft 365 services. Recent coverage highlights defensive measures targeting phishing vectors that exploit calendar invites within Microsoft-era ecosystems, underscoring the importance of protecting identity surfaces tied to these services.
Sublime Security has reported a significant increase in phishing attacks utilizing calendar invites, specifically targeting users of Google Workspace and Microsoft 365. These attacks exploit social engineering tactics…
Sublime Security reported a significant increase in phishing attacks using calendar invites to bypass security measures. These attacks primarily target users of Google Workspace and Microsoft 365, leveraging social…