<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Announcements | Cloud Computing | Cloud Technology News</title>
	<atom:link href="https://blog.machsol.com/announcements/feed" rel="self" type="application/rss+xml" />
	<link>https://blog.machsol.com/announcements</link>
	<description>Multi-Cloud Service Orchestration &#38; Delivery Platform</description>
	<lastBuildDate>Fri, 11 Sep 2026 05:10:05 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1</generator>
	<item>
		<title>Self-Hosted MFA for Dynamics 365 On-Premises and AD FS</title>
		<link>https://blog.machsol.com/announcements/crm-mfa</link>
		
		<dc:creator><![CDATA[Jameel]]></dc:creator>
		<pubDate>Wed, 09 Sep 2026 07:33:40 +0000</pubDate>
				<category><![CDATA[Announcements]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Dynamics 365]]></category>
		<category><![CDATA[Hosting & SaaS]]></category>
		<category><![CDATA[AD FS authenticator enrollment]]></category>
		<category><![CDATA[Dynamics 365 on-premises two-factor authentication]]></category>
		<category><![CDATA[Dynamics CRM on-premises MFA]]></category>
		<category><![CDATA[Self-hosted MFA for Dynamics CRM]]></category>
		<guid isPermaLink="false">https://blog.machsol.com/?p=6038</guid>

					<description><![CDATA[<p>Fully Self-hosted MFA for Dynamics 365 On-Premises and AD FS Strengthening on-premises CRM security without introducing an external MFA cloud dependency. Many organizations continue to operate business-critical deployments of Microsoft Dynamics CRM or Dynamics 365 Customer Engagement on-premises. These environments typically rely on on-premises Active Directory Federation Services, claims-based authentication, and Internet-Facing Deployment (IFD) to [&#8230;]</p>
<p>The post <a href="https://blog.machsol.com/announcements/crm-mfa">Self-Hosted MFA for Dynamics 365 On-Premises and AD FS</a> appeared first on <a href="https://blog.machsol.com">MachSol Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><!-- ============================================================
MachSol — Self-Hosted MFA for Dynamics 365 On-Premises & AD FS
WordPress blog post — SINGLE BLOCK, 100% INLINE STYLES.
Works in: Gutenberg "Custom HTML" block, Classic "Text" tab,
Elementor "HTML" widget. No



<style><span style="display: inline-block; width: 0px; overflow: hidden; line-height: 0;" data-mce-type="bookmark" class="mce_SELRES_start"></span><span style="display: inline-block; width: 0px; overflow: hidden; line-height: 0;" data-mce-type="bookmark" class="mce_SELRES_start"></span> tag, so no theme/CSS
conflicts and no white-background issues.
HOW TO USE: paste ALL of this code into the HTML block.
============================================================ --></p>
<table style="margin: 0; border-color: #fff; padding: 0;" role="presentation" border="0" width="100%" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td style="padding: 0; border-color: #fff;">
<div style="max-width: 760px; width: 100%; margin: 0 auto; font-family: 'Segoe UI',Helvetica,Arial,sans-serif; color: #45546a; font-size: 17px; line-height: 1.85; text-align: left;">
<p><!-- HERO --></p>
<div style="background: linear-gradient(135deg,#0c1c2e 0%,#12314f 55%,#0a4d8c 100%); border-radius: 18px; padding: 56px 52px 50px; margin: 0 0 42px;">
<div style="font-size: 12px; letter-spacing: 3px; text-transform: uppercase; font-weight: bold; color: #c9a24b; margin: 0 0 20px;">Fully Self-hosted</div>
<h1 style="font-family: Segoe UI,'Times New Roman',serif; color: #ffffff; font-size: 36px; line-height: 1.25; font-weight: bold; letter-spacing: -0.5px; margin: 0 0 18px;">MFA for Dynamics 365 On-Premises and AD FS</h1>
<p style="font-size: 19px; color: #c6d5e5; line-height: 1.65; margin: 0;">Strengthening on-premises CRM security without introducing an external MFA cloud dependency.</p>
</div>
<p style="font-size: 19px; color: #14202e; font-weight: 500; line-height: 1.7; margin: 0 0 22px;">Many organizations continue to operate business-critical deployments of Microsoft Dynamics CRM or Dynamics 365 Customer Engagement on-premises. These environments typically rely on on-premises Active Directory Federation Services, claims-based authentication, and Internet-Facing Deployment (IFD) to provide secure access for internal and remote users.</p>
<p style="margin: 0 0 22px;">Microsoft supports AD FS as the security token service for Dynamics 365 Customer Engagement on-premises. Dynamics 365 can use claims-based authentication for internal access and IFD for external access, with AD FS issuing the security tokens consumed by CRM.</p>
<p style="margin: 0 0 22px;">However, organizations that want to add modern multifactor authentication to this architecture face a difficult choice. Many MFA products are designed primarily for cloud services, rely on an external authentication platform, or provide only a general AD FS integration without addressing the operational requirements of Dynamics CRM on-premises.</p>
<p><!-- CALLOUT --></p>
<div style="background: #f4f7fb; border: 1px solid #e6ebf1; border-left: 4px solid #0a4d8c; border-radius: 0 12px 12px 0; padding: 22px 26px; margin: 32px 0;">
<p style="margin: 0; color: #45546a;"><strong style="color: #14202e;">MachSol has addressed this long-awaited requirement</strong> by developing a fully self-hosted multifactor authentication solution for Dynamics CRM and Dynamics 365 Customer Engagement on-premises through on-premises AD FS.</p>
</div>
<p style="margin: 0 0 22px;">
<p><!-- SECTION --></p>
<h2 style="font-family: Georgia,'Times New Roman',serif; color: #14202e; font-size: 30px; line-height: 1.25; font-weight: bold; margin: 44px 0 16px;">The exact scenario we addressed</h2>
<div style="width: 44px; height: 3px; background: linear-gradient(90deg,#c9a24b,rgba(201,162,75,0.15)); border-radius: 2px; margin: 0 0 24px;"></div>
<p style="margin: 0 0 22px;">The solution was designed for the following architecture:</p>
<p><!-- FLOW DIAGRAM --></p>
<div style="background: linear-gradient(180deg,#10233a,#0c1c2e); border-radius: 16px; padding: 34px 28px; margin: 32px 0; text-align: center; box-shadow: 0 18px 40px -22px rgba(12,28,46,0.55);">
<div style="display: inline-block; max-width: 430px; color: #eaf1fa; font-family: Consolas,Menlo,monospace; font-size: 14px; background: rgba(255,255,255,0.06); border: 1px solid rgba(255,255,255,0.13); border-radius: 9px; padding: 12px 16px;">Dynamics CRM or Dynamics 365 CE On-Premises</div>
<div style="color: #c9a24b; font-size: 14px; margin: 7px 0;">▼</div>
<div style="display: inline-block; max-width: 430px; color: #eaf1fa; font-family: Consolas,Menlo,monospace; font-size: 14px; background: rgba(255,255,255,0.06); border: 1px solid rgba(255,255,255,0.13); border-radius: 9px; padding: 12px 16px;">Claims-Based Authentication or IFD</div>
<div style="color: #c9a24b; font-size: 14px; margin: 7px 0;">▼</div>
<div style="display: inline-block; max-width: 430px; color: #eaf1fa; font-family: Consolas,Menlo,monospace; font-size: 14px; background: rgba(255,255,255,0.06); border: 1px solid rgba(255,255,255,0.13); border-radius: 9px; padding: 12px 16px;">Active Directory Federation Services On-Premises</div>
<div style="color: #c9a24b; font-size: 14px; margin: 7px 0;">▼</div>
<div style="display: inline-block; max-width: 430px; color: #eaf1fa; font-family: Consolas,Menlo,monospace; font-size: 14px; background: rgba(255,255,255,0.06); border: 1px solid rgba(255,255,255,0.13); border-radius: 9px; padding: 12px 16px;">MachSol MFA Adapter</div>
<div style="color: #c9a24b; font-size: 14px; margin: 7px 0;">▼</div>
<div style="display: inline-block; max-width: 430px; color: #eaf1fa; font-family: Consolas,Menlo,monospace; font-size: 14px; background: rgba(255,255,255,0.06); border: 1px solid rgba(255,255,255,0.13); border-radius: 9px; padding: 12px 16px;">Customer-Controlled SQL Server and Encryption</div>
</div>
<p style="margin: 0 0 22px;">This is an important distinction. Generic AD FS MFA products can potentially protect browser-based relying parties.</p>
<p style="margin: 0 0 22px;">MachSol’s implementation is focused specifically on environments where Dynamics CRM, AD FS, MFA processing, authenticator records, recovery state, and encryption controls must all remain on-premises.</p>
<h2 style="font-family: Georgia,'Times New Roman',serif; color: #14202e; font-size: 30px; line-height: 1.25; font-weight: bold; margin: 44px 0 16px;">How the solution works</h2>
<div style="width: 44px; height: 3px; background: linear-gradient(90deg,#c9a24b,rgba(201,162,75,0.15)); border-radius: 2px; margin: 0 0 24px;"></div>
<p style="margin: 0 0 22px;">The MachSol MFA Adapter integrates with the external authentication-provider framework in AD FS. Microsoft supports custom external authentication providers and documents the interfaces required to participate in the AD FS authentication pipeline.</p>
<h3 style="font-family: Georgia,'Times New Roman',serif; color: #14202e; font-size: 21px; font-weight: bold; margin: 34px 0 12px;">The user journey</h3>
<table style="margin: 28px 0; border-color: #fff;" role="presentation" border="0" width="100%" cellspacing="0" cellpadding="0">
<tbody style="border: 1px solid #fff !important;">
<tr>
<td style="width: 40px; border-color: #fff; vertical-align: top; padding: 2px 12px 16px 0;">
<div style="width: 32px; height: 32px; border-radius: 50%; border: 2px solid #0a4d8c; color: #0a4d8c; font-weight: bold; font-size: 13px; text-align: center; line-height: 30px; background: #ffffff;">1</div>
</td>
<td style="padding: 4px 0 16px; border-color: #fff;">The user opens Dynamics CRM.</td>
</tr>
<tr>
<td style="vertical-align: top; border-color: #fff; padding: 2px 12px 16px 0;">
<div style="width: 32px; height: 32px; border-radius: 50%; border: 2px solid #0a4d8c; color: #0a4d8c; font-weight: bold; font-size: 13px; text-align: center; line-height: 30px; background: #ffffff;">2</div>
</td>
<td style="padding: 4px 0 16px; border-color: #fff;">Dynamics CRM redirects the user to AD FS.</td>
</tr>
<tr>
<td style="vertical-align: top; padding: 2px 12px 16px 0; border-color: #fff;">
<div style="width: 32px; height: 32px; border-radius: 50%; border: 2px solid #0a4d8c; color: #0a4d8c; font-weight: bold; font-size: 13px; text-align: center; line-height: 30px; background: #ffffff;">3</div>
</td>
<td style="padding: 4px 0 16px; border-color: #fff;">AD FS completes the existing primary authentication process.</td>
</tr>
<tr>
<td style="vertical-align: top; padding: 2px 12px 16px 0; border-color: #fff;">
<div style="width: 32px; height: 32px; border-radius: 50%; border: 2px solid #0a4d8c; color: #0a4d8c; font-weight: bold; font-size: 13px; text-align: center; line-height: 30px; background: #ffffff;">4</div>
</td>
<td style="padding: 4px 0 16px; border-color: #fff;">AD FS invokes the MachSol MFA Adapter.</td>
</tr>
<tr>
<td style="vertical-align: top; padding: 2px 12px 16px 0; border-color: #fff;">
<div style="width: 32px; height: 32px; border-radius: 50%; border: 2px solid #0a4d8c; color: #0a4d8c; font-weight: bold; font-size: 13px; text-align: center; line-height: 30px; background: #ffffff;">5</div>
</td>
<td style="padding: 4px 0 16px; border-color: #fff;">A new user is guided through authenticator registration using a QR code.</td>
</tr>
<tr>
<td style="vertical-align: top; padding: 2px 12px 16px 0; border-color: #fff;">
<div style="width: 32px; height: 32px; border-radius: 50%; border: 2px solid #0a4d8c; color: #0a4d8c; font-weight: bold; font-size: 13px; text-align: center; line-height: 30px; background: #ffffff;">6</div>
</td>
<td style="padding: 4px 0 16px; border-color: #fff;">The user enters the current code generated by a compatible authenticator application.</td>
</tr>
<tr>
<td style="vertical-align: top; padding: 2px 12px 16px 0; border-color: #fff;">
<div style="width: 32px; height: 32px; border-radius: 50%; border: 2px solid #0a4d8c; color: #0a4d8c; font-weight: bold; font-size: 13px; text-align: center; line-height: 30px; background: #ffffff;">7</div>
</td>
<td style="padding: 4px 0 16px; border-color: #fff;">The adapter verifies the code and records the enrollment securely.</td>
</tr>
<tr>
<td style="vertical-align: top; padding: 2px 12px 16px 0; border-color: #fff;">
<div style="width: 32px; height: 32px; border-radius: 50%; border: 2px solid #0a4d8c; color: #0a4d8c; font-weight: bold; font-size: 13px; text-align: center; line-height: 30px; background: #ffffff;">8</div>
</td>
<td style="padding: 4px 0 16px; border-color: #fff;">AD FS issues the authentication token required by Dynamics CRM.</td>
</tr>
<tr>
<td style="vertical-align: top; padding: 2px 12px 16px 0; border-color: #fff;">
<div style="width: 32px; height: 32px; border-radius: 50%; border: 2px solid #0a4d8c; color: #0a4d8c; font-weight: bold; font-size: 13px; text-align: center; line-height: 30px; background: #ffffff;">9</div>
</td>
<td style="padding: 4px 0 16px; border-color: #fff;">Returning users are prompted only for the current authenticator code.</td>
</tr>
</tbody>
</table>
<p style="margin: 0 0 22px;">The enrollment and verification experience is embedded directly into the AD FS authentication journey. No separate cloud enrollment portal is required.</p>
<h2 style="font-family: Georgia,'Times New Roman',serif; color: #14202e; font-size: 30px; line-height: 1.25; font-weight: bold; margin: 44px 0 16px;">Production capabilities</h2>
<div style="width: 44px; height: 3px; background: linear-gradient(90deg,#c9a24b,rgba(201,162,75,0.15)); border-radius: 2px; margin: 0 0 24px;"></div>
<p><!-- FEATURE CARDS --></p>
<table style="margin: 0 0 8px;" role="presentation" border="0" width="100%" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td style="padding: 0 8px 16px 0; vertical-align: top;" width="50%">
<div style="border: 1px solid #e6ebf1; border-radius: 14px; padding: 24px 22px; background: #ffffff; height: 100%;">
<div style="width: 22px; height: 2px; background: #c9a24b; border-radius: 2px; margin: 0 0 10px;"></div>
<h4 style="font-family: Georgia,'Times New Roman',serif; color: #14202e; font-size: 16px; font-weight: bold; margin: 0 0 8px;">Standards-based authenticators</h4>
<p style="margin: 0; font-size: 14px; line-height: 1.65; color: #5f7085;">Time-based one-time passwords (TOTP) let users register any compatible authenticator app by scanning a QR code.</p>
</div>
</td>
<td style="padding: 0 0 16px 8px; vertical-align: top;" width="50%">
<div style="border: 1px solid #e6ebf1; border-radius: 14px; padding: 24px 22px; background: #ffffff; height: 100%;">
<div style="width: 22px; height: 2px; background: #c9a24b; border-radius: 2px; margin: 0 0 10px;"></div>
<h4 style="font-family: Georgia,'Times New Roman',serif; color: #14202e; font-size: 16px; font-weight: bold; margin: 0 0 8px;">Encrypted secret storage</h4>
<p style="margin: 0; font-size: 14px; line-height: 1.65; color: #5f7085;">Authenticator secrets are encrypted before storage, using a certificate maintained in the customer’s own infrastructure.</p>
</div>
</td>
</tr>
<tr>
<td style="padding: 0 8px 16px 0; vertical-align: top;" width="50%">
<div style="border: 1px solid #e6ebf1; border-radius: 14px; padding: 24px 22px; background: #ffffff; height: 100%;">
<div style="width: 22px; height: 2px; background: #c9a24b; border-radius: 2px; margin: 0 0 10px;"></div>
<h4 style="font-family: Georgia,'Times New Roman',serif; color: #14202e; font-size: 16px; font-weight: bold; margin: 0 0 8px;">Inline enrollment</h4>
<p style="margin: 0; font-size: 14px; line-height: 1.65; color: #5f7085;">QR setup, manual setup-key support, clear privacy guidance, code confirmation, and responsive screens — all inside AD FS sign-in.</p>
</div>
</td>
<td style="padding: 0 0 16px 8px; vertical-align: top;" width="50%">
<div style="border: 1px solid #e6ebf1; border-radius: 14px; padding: 24px 22px; background: #ffffff; height: 100%;">
<div style="width: 22px; height: 2px; background: #c9a24b; border-radius: 2px; margin: 0 0 10px;"></div>
<h4 style="font-family: Georgia,'Times New Roman',serif; color: #14202e; font-size: 16px; font-weight: bold; margin: 0 0 8px;">SQL-backed state</h4>
<p style="margin: 0; font-size: 14px; line-height: 1.65; color: #5f7085;">Enrollment status, encrypted active and pending secrets, counters, lockout state, recovery challenges, and audit events.</p>
</div>
</td>
</tr>
</tbody>
</table>
<h3 style="font-family: Georgia,'Times New Roman',serif; color: #14202e; font-size: 21px; font-weight: bold; margin: 34px 0 12px;">SQL-backed authentication state</h3>
<p style="margin: 0 0 14px;">SQL Server maintains:</p>
<table style="margin: 0 0 24px;" role="presentation" border="0" width="100%" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td style="vertical-align: top; padding-right: 20px;" width="50%">
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  User enrollment status</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Encrypted active and pending secrets</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Last accepted TOTP counter</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Failed-attempt state</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Temporary lockout state</p>
</td>
<td style="vertical-align: top;" width="50%">
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Enrollment expiration</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Recovery challenges</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Notification processing state</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Audit events</p>
</td>
</tr>
</tbody>
</table>
<h3 style="font-family: Georgia,'Times New Roman',serif; color: #14202e; font-size: 21px; font-weight: bold; margin: 34px 0 12px;">TOTP replay protection</h3>
<p style="margin: 0 0 22px;">A mathematically valid code should not automatically be accepted more than once. The adapter records the last accepted TOTP counter and uses an atomic SQL update to require:</p>
<div style="background: linear-gradient(180deg,#10233a,#0c1c2e); border-radius: 16px; padding: 30px 28px; margin: 32px 0; text-align: center;">
<div style="display: inline-block; color: #eaf1fa; font-family: Consolas,Menlo,monospace; font-size: 15px; background: rgba(255,255,255,0.06); border: 1px solid rgba(255,255,255,0.13); border-radius: 9px; padding: 14px 22px;">New counter &gt; Last accepted counter</div>
</div>
<p style="margin: 0 0 22px;">This helps prevent the same authenticator code from being reused within its validity period and supports consistent behavior across multiple AD FS nodes.</p>
<h3 style="font-family: Georgia,'Times New Roman',serif; color: #14202e; font-size: 21px; font-weight: bold; margin: 34px 0 12px;">Failed-attempt controls and lockout</h3>
<p style="margin: 0 0 22px;">The solution tracks unsuccessful verification attempts within a configured time window. When the configured threshold is reached, the MFA record can be temporarily locked to reduce repeated guessing attempts.</p>
<h3 style="font-family: Georgia,'Times New Roman',serif; color: #14202e; font-size: 21px; font-weight: bold; margin: 34px 0 12px;">Secure email-assisted recovery</h3>
<p style="margin: 0 0 14px;">An enrolled user who can no longer use the registered authenticator can request a temporary, single-use recovery code through the email address associated with the account. The recovery design includes:</p>
<table style="margin: 0 0 24px;" role="presentation" border="0" width="100%" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td style="vertical-align: top; padding-right: 20px;" width="50%">
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Configurable code length</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Configurable expiration</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Maximum verification attempts</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Resend cooldown</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Hourly request limits</p>
</td>
<td style="vertical-align: top;" width="50%">
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Hashed recovery-code verification</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Single-use challenge consumption</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Auditable recovery events</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Customer-controlled email delivery via SQL Server Database Mail</p>
</td>
</tr>
</tbody>
</table>
<div style="background: #f4f7fb; border: 1px solid #e6ebf1; border-left: 4px solid #0a4d8c; border-radius: 0 12px 12px 0; padding: 22px 26px; margin: 32px 0;">
<p style="margin: 0; color: #45546a;">Email recovery is used to authorize authenticator replacement. It is not intended to become a permanent alternative to normal authenticator verification.</p>
</div>
<h3 style="font-family: Georgia,'Times New Roman',serif; color: #14202e; font-size: 21px; font-weight: bold; margin: 34px 0 12px;">Authenticator replacement</h3>
<p style="margin: 0 0 22px;">After a recovery code is successfully verified, the user enters a controlled replacement workflow:</p>
<div style="background: linear-gradient(180deg,#10233a,#0c1c2e); border-radius: 16px; padding: 34px 28px; margin: 32px 0; text-align: center; box-shadow: 0 18px 40px -22px rgba(12,28,46,0.55);">
<div style="display: inline-block; max-width: 430px; color: #eaf1fa; font-family: Consolas,Menlo,monospace; font-size: 14px; background: rgba(255,255,255,0.06); border: 1px solid rgba(255,255,255,0.13); border-radius: 9px; padding: 12px 16px;">Recovery verified</div>
<div style="color: #c9a24b; font-size: 14px; margin: 7px 0;">▼</div>
<div style="display: inline-block; max-width: 430px; color: #eaf1fa; font-family: Consolas,Menlo,monospace; font-size: 14px; background: rgba(255,255,255,0.06); border: 1px solid rgba(255,255,255,0.13); border-radius: 9px; padding: 12px 16px;">Account enters replacement-pending state</div>
<div style="color: #c9a24b; font-size: 14px; margin: 7px 0;">▼</div>
<div style="display: inline-block; max-width: 430px; color: #eaf1fa; font-family: Consolas,Menlo,monospace; font-size: 14px; background: rgba(255,255,255,0.06); border: 1px solid rgba(255,255,255,0.13); border-radius: 9px; padding: 12px 16px;">New authenticator secret is generated</div>
<div style="color: #c9a24b; font-size: 14px; margin: 7px 0;">▼</div>
<div style="display: inline-block; max-width: 430px; color: #eaf1fa; font-family: Consolas,Menlo,monospace; font-size: 14px; background: rgba(255,255,255,0.06); border: 1px solid rgba(255,255,255,0.13); border-radius: 9px; padding: 12px 16px;">New QR code is displayed</div>
<div style="color: #c9a24b; font-size: 14px; margin: 7px 0;">▼</div>
<div style="display: inline-block; max-width: 430px; color: #eaf1fa; font-family: Consolas,Menlo,monospace; font-size: 14px; background: rgba(255,255,255,0.06); border: 1px solid rgba(255,255,255,0.13); border-radius: 9px; padding: 12px 16px;">User verifies a code from the new authenticator</div>
<div style="color: #c9a24b; font-size: 14px; margin: 7px 0;">▼</div>
<div style="display: inline-block; max-width: 430px; color: #eaf1fa; font-family: Consolas,Menlo,monospace; font-size: 14px; background: rgba(255,255,255,0.06); border: 1px solid rgba(255,255,255,0.13); border-radius: 9px; padding: 12px 16px;">New secret becomes active — previous authenticator replaced</div>
</div>
<p style="margin: 0 0 22px;">The new authenticator is not activated merely because the QR code was displayed. Activation occurs only after a valid code from the pending authenticator is confirmed.</p>
<h3 style="font-family: Georgia,'Times New Roman',serif; color: #14202e; font-size: 21px; font-weight: bold; margin: 34px 0 12px;">Notification queue and retention controls</h3>
<p style="margin: 0 0 14px;">Recovery messages are processed using a database-backed notification queue and an approved SQL Server Database Mail profile. The hardened processing design includes:</p>
<table style="margin: 0 0 24px;" role="presentation" border="0" width="100%" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td style="vertical-align: top; padding-right: 20px;" width="50%">
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Atomic notification claiming</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Delivery-attempt tracking</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Controlled retry behavior</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Prevention of duplicate active recovery challenges</p>
</td>
<td style="vertical-align: top;" width="50%">
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Plaintext recovery-message cleanup</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Retention-based deletion of completed operational records</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Separate audit retention</p>
</td>
</tr>
</tbody>
</table>
<h3 style="font-family: Georgia,'Times New Roman',serif; color: #14202e; font-size: 21px; font-weight: bold; margin: 34px 0 12px;">Operational logging</h3>
<p style="margin: 0 0 22px;">The adapter writes operational and security events to the Windows Application event log. Correlation IDs allow administrators to connect the user-facing support reference, AD FS activity, adapter events, recovery processing, and authentication success or failure. Sensitive authenticator secrets and recovery codes are not intended to be written to the audit log.</p>
<h2 style="font-family: Georgia,'Times New Roman',serif; color: #14202e; font-size: 30px; line-height: 1.25; font-weight: bold; margin: 44px 0 16px;">Controlled MFA exemptions for CRM integrations</h2>
<div style="width: 44px; height: 3px; background: linear-gradient(90deg,#c9a24b,rgba(201,162,75,0.15)); border-radius: 2px; margin: 0 0 24px;"></div>
<p style="margin: 0 0 14px;">Not every Dynamics CRM connection is an interactive browser session. CRM environments may include:</p>
<table style="margin: 0 0 24px;" role="presentation" border="0" width="100%" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td style="vertical-align: top; padding-right: 20px;" width="50%">
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Background services</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Scheduled integrations</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Email-processing components</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Monitoring systems</p>
</td>
<td style="vertical-align: top;" width="50%">
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Custom websites</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Deployment tools</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  SDK applications</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Approved service accounts</p>
</td>
</tr>
</tbody>
</table>
<p style="margin: 0 0 22px;">Some non-interactive processes cannot respond to a QR enrollment page or enter a one-time authenticator code. Dynamics 365 Customer Engagement on-premises supports several authentication models and client patterns, so each integration must be evaluated according to the protocol and client behavior it uses.</p>
<p style="margin: 0 0 14px;">MachSol’s solution includes the ability to support controlled, policy-based MFA exemptions for specifically approved users and integration scenarios. An exemption is not intended to disable MFA generally. Exemptions should be:</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Explicitly authorized</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Narrowly scoped</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Documented and auditable</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Regularly reviewed</p>
<p style="margin: 0 0 22px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Restricted to the required relying party or integration scenario</p>
<p style="margin: 0 0 22px;">Normal interactive CRM users continue to be protected by MFA.</p>
<h2 style="font-family: Georgia,'Times New Roman',serif; color: #14202e; font-size: 30px; line-height: 1.25; font-weight: bold; margin: 44px 0 16px;">Why this matters</h2>
<div style="width: 44px; height: 3px; background: linear-gradient(90deg,#c9a24b,rgba(201,162,75,0.15)); border-radius: 2px; margin: 0 0 24px;"></div>
<p style="margin: 0 0 14px;">Many organizations cannot move every identity, application, or security process to a public cloud platform. Common requirements include:</p>
<table style="margin: 0 0 24px;" role="presentation" border="0" width="100%" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td style="vertical-align: top; padding-right: 20px;" width="50%">
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Data-sovereignty restrictions</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Regulated customer environments</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Restricted internet connectivity</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Existing Dynamics CRM investments</p>
</td>
<td style="vertical-align: top;" width="50%">
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Customer-controlled encryption keys</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Local audit and recovery requirements</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Predictable service-provider operations</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  No dependency on an external MFA cloud service</p>
</td>
</tr>
</tbody>
</table>
<p><!-- KEY STATEMENT --></p>
<div style="border-top: 1px solid #e6ebf1; border-bottom: 1px solid #e6ebf1; padding: 30px 12px; margin: 40px 0; text-align: center;">
<p style="margin: 0; font-family: Georgia,'Times New Roman',serif; font-size: 22px; line-height: 1.6; color: #14202e; font-weight: 600;">The key achievement is not simply generating a six-digit code. <span style="color: #0a4d8c;">It is integrating enrollment, TOTP verification, replay protection, recovery, authenticator replacement, encryption, SQL concurrency, auditing, controlled exemptions, and an AD FS-compatible user experience</span> into an existing Dynamics CRM on-premises authentication environment.</p>
</div>
<h2 style="font-family: Georgia,'Times New Roman',serif; color: #14202e; font-size: 30px; line-height: 1.25; font-weight: bold; margin: 44px 0 16px;">More than a CRM-only technical component</h2>
<div style="width: 44px; height: 3px; background: linear-gradient(90deg,#c9a24b,rgba(201,162,75,0.15)); border-radius: 2px; margin: 0 0 24px;"></div>
<p style="margin: 0 0 14px;">The core technology is implemented as an AD FS external authentication provider. Architecturally, it can be evaluated for other compatible browser-based AD FS relying parties. Potential future application profiles may include:</p>
<table style="margin: 0 0 24px;" role="presentation" border="0" width="100%" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td style="vertical-align: top; padding-right: 20px;" width="50%">
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  SharePoint Server on-premises</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Internal business portals</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Custom ASP.NET applications</p>
</td>
<td style="vertical-align: top;" width="50%">
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  WS-Federation applications</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  SAML relying parties</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Applications published through Web Application Proxy</p>
</td>
</tr>
</tbody>
</table>
<p style="margin: 0 0 22px;">Each application still requires protocol, claims, client, service-account, and integration testing. The initial product focus remains Dynamics CRM and Dynamics 365 Customer Engagement on-premises, because that is the environment for which the solution was specifically developed and production deployed.</p>
<h2 style="font-family: Georgia,'Times New Roman',serif; color: #14202e; font-size: 30px; line-height: 1.25; font-weight: bold; margin: 44px 0 16px;">A specialized on-premises security capability</h2>
<div style="width: 44px; height: 3px; background: linear-gradient(90deg,#c9a24b,rgba(201,162,75,0.15)); border-radius: 2px; margin: 0 0 24px;"></div>
<p style="margin: 0 0 22px;">MachSol has now developed a purpose-built MFA capability for this exact scenario:</p>
<div style="background: linear-gradient(180deg,#10233a,#0c1c2e); border-radius: 16px; padding: 34px 28px; margin: 32px 0; text-align: center; box-shadow: 0 18px 40px -22px rgba(12,28,46,0.55);">
<div style="display: inline-block; max-width: 430px; color: #eaf1fa; font-family: Consolas,Menlo,monospace; font-size: 14px; background: rgba(255,255,255,0.06); border: 1px solid rgba(255,255,255,0.13); border-radius: 9px; padding: 12px 16px;">Dynamics CRM On-Premises</div>
<div style="color: #6f96bd; font-weight: bold; margin: 5px 0;">+</div>
<div style="display: inline-block; max-width: 430px; color: #eaf1fa; font-family: Consolas,Menlo,monospace; font-size: 14px; background: rgba(255,255,255,0.06); border: 1px solid rgba(255,255,255,0.13); border-radius: 9px; padding: 12px 16px;">AD FS On-Premises</div>
<div style="color: #6f96bd; font-weight: bold; margin: 5px 0;">+</div>
<div style="display: inline-block; max-width: 430px; color: #eaf1fa; font-family: Consolas,Menlo,monospace; font-size: 14px; background: rgba(255,255,255,0.06); border: 1px solid rgba(255,255,255,0.13); border-radius: 9px; padding: 12px 16px;">MFA Processing On-Premises</div>
<div style="color: #6f96bd; font-weight: bold; margin: 5px 0;">+</div>
<div style="display: inline-block; max-width: 430px; color: #eaf1fa; font-family: Consolas,Menlo,monospace; font-size: 14px; background: rgba(255,255,255,0.06); border: 1px solid rgba(255,255,255,0.13); border-radius: 9px; padding: 12px 16px;">Inline Authenticator Enrollment</div>
<div style="color: #6f96bd; font-weight: bold; margin: 5px 0;">+</div>
<div style="display: inline-block; max-width: 430px; color: #eaf1fa; font-family: Consolas,Menlo,monospace; font-size: 14px; background: rgba(255,255,255,0.06); border: 1px solid rgba(255,255,255,0.13); border-radius: 9px; padding: 12px 16px;">Customer-Controlled SQL Storage</div>
<div style="color: #6f96bd; font-weight: bold; margin: 5px 0;">+</div>
<div style="display: inline-block; max-width: 430px; color: #eaf1fa; font-family: Consolas,Menlo,monospace; font-size: 14px; background: rgba(255,255,255,0.06); border: 1px solid rgba(255,255,255,0.13); border-radius: 9px; padding: 12px 16px;">Customer-Controlled Encryption</div>
<div style="color: #6f96bd; font-weight: bold; margin: 5px 0;">+</div>
<div style="display: inline-block; max-width: 430px; color: #eaf1fa; font-family: Consolas,Menlo,monospace; font-size: 14px; background: rgba(255,255,255,0.06); border: 1px solid rgba(255,255,255,0.13); border-radius: 9px; padding: 12px 16px;">Secure Recovery and Replacement</div>
<div style="color: #6f96bd; font-weight: bold; margin: 5px 0;">+</div>
<div style="display: inline-block; max-width: 430px; color: #eaf1fa; font-family: Consolas,Menlo,monospace; font-size: 14px; background: rgba(255,255,255,0.06); border: 1px solid rgba(255,255,255,0.13); border-radius: 9px; padding: 12px 16px;">No External MFA Cloud Dependency</div>
</div>
<p style="margin: 0 0 22px;">Publicly available vendor documentation shows several generic AD FS MFA options, but the market appears to have limited purpose-built offerings that combine this complete Dynamics CRM on-premises operating model with local MFA processing and CRM-focused deployment support.</p>
<p style="margin: 0 0 22px;">For Dynamics CRM customers, hosting providers, and regulated organizations, this represents an opportunity to strengthen authentication without abandoning the existing on-premises platform or surrendering control of sensitive authentication data.</p>
<h2 style="font-family: Georgia,'Times New Roman',serif; color: #14202e; font-size: 30px; line-height: 1.25; font-weight: bold; margin: 44px 0 16px;">Next steps</h2>
<div style="width: 44px; height: 3px; background: linear-gradient(90deg,#c9a24b,rgba(201,162,75,0.15)); border-radius: 2px; margin: 0 0 24px;"></div>
<p style="margin: 0 0 14px;">MachSol is continuing to mature the solution through:</p>
<table style="margin: 0 0 24px;" role="presentation" border="0" width="100%" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td style="vertical-align: top; padding-right: 20px;" width="50%">
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Wider AD FS version validation</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Dynamics CRM compatibility testing</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Automated installation and rollback</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Farm deployment verification</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Administrative management tooling</p>
</td>
<td style="vertical-align: top;" width="50%">
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Security assessment and penetration testing</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Health monitoring and diagnostics</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Database migration and retention tooling</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Customer pilot planning</p>
<p style="margin: 0 0 8px; padding-left: 18px; text-indent: -18px;"><span style="color: #c9a24b;">●</span>  Product licensing and support documentation</p>
</td>
</tr>
</tbody>
</table>
<p><!-- CTA --></p>
<div style="background: linear-gradient(150deg,#12314f 0%,#0c1c2e 70%); color: #ffffff; border-radius: 18px; padding: 46px 40px; text-align: center; margin: 48px 0 0;">
<h3 style="font-family: Georgia,'Times New Roman',serif; color: #ffffff; font-size: 26px; font-weight: bold; margin: 0 0 12px;">Talk to MachSol about self-hosted MFA</h3>
<p style="color: #c6d5e5; max-width: 540px; margin: 0 auto 26px; font-size: 16px; line-height: 1.7;">Organizations operating Dynamics CRM or Dynamics 365 Customer Engagement on-premises can contact MachSol to discuss requirements for AD FS-integrated, fully self-hosted multifactor authentication.</p>
<p><!-- Replace the href with your contact or enquiry page URL --><br />
<a style="display: inline-block; background: linear-gradient(135deg,#1273c4,#0a4d8c); color: #ffffff; text-decoration: none; font-weight: 600; font-size: 15px; letter-spacing: 0.5px; padding: 15px 38px; border-radius: 99px;" href="https://www.machsol.com/contact-us/">Request a Consultation</a></p>
</div>
<p><!-- REFERENCES --></p>
<div style="font-size: 14px; color: #7c8a9d; border-top: 1px solid #e6ebf1; margin-top: 48px; padding-top: 22px; line-height: 1.7;">
<p style="margin: 0; font-size: 14px;">
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>The post <a href="https://blog.machsol.com/announcements/crm-mfa">Self-Hosted MFA for Dynamics 365 On-Premises and AD FS</a> appeared first on <a href="https://blog.machsol.com">MachSol Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>MachPanel v8.3 BUILD 25, Now Available!</title>
		<link>https://blog.machsol.com/announcements/machpanel-v8-3-25-multi-tenant-cloud-orchestration-gets-better</link>
		
		<dc:creator><![CDATA[Jameel]]></dc:creator>
		<pubDate>Tue, 08 Sep 2026 12:39:08 +0000</pubDate>
				<category><![CDATA[Announcements]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Hosting & SaaS]]></category>
		<category><![CDATA[Microsoft Exchange]]></category>
		<category><![CDATA[Microsoft Hyper-V]]></category>
		<guid isPermaLink="false">https://blog.machsol.com/?p=6033</guid>

					<description><![CDATA[<p>MachPanel v8.3.25 A Major Release for MSPs, Enterprises, Hosting, and Cloud Service Providers MachSol has released MachPanel v8.3.25, the latest build of its automation platform for teams running Hyper-V, Exchange, and Microsoft 365 environments across multiple tenants. This release adds Hyper-V cluster snapshot support, over 30 new REST API endpoints, a set of Exchange management [&#8230;]</p>
<p>The post <a href="https://blog.machsol.com/announcements/machpanel-v8-3-25-multi-tenant-cloud-orchestration-gets-better">MachPanel v8.3 BUILD 25, Now Available!</a> appeared first on <a href="https://blog.machsol.com">MachSol Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h2>MachPanel v8.3.25</h2>
<p><span style="color: #3366ff;"><strong>A Major Release for MSPs, Enterprises, Hosting, and Cloud Service Providers</strong></span></p>
<p>MachSol has released MachPanel v8.3.25, the latest build of its automation platform for teams running Hyper-V, Exchange, and Microsoft 365 environments across multiple tenants. This release adds Hyper-V cluster snapshot support, over 30 new REST API endpoints, a set of Exchange management improvements, and fixes for several critical security vulnerabilities</p>
<p><img fetchpriority="high" decoding="async" class="alignnone size-full wp-image-6063" src="https://blog.machsol.com/wp-content/uploads/MachPanel_CloudOrchestration-for-Service-Providers.png" alt="" width="2512" height="816" /></p>
<p>If you&#8217;re evaluating alternatives to VMware for VPS hosting, this is a build worth looking at.</p>
<p>Here&#8217;s what&#8217;s actually worth knowing, and how to get the most out of it.</p>
<p><strong>Security fixes you shouldn&#8217;t wait on</strong></p>
<p>Starting here because it matters most. This build patches SQL injection, stored cross-site scripting, insecure direct object reference, and an SSO bypass via an alternative login page. It also hardens authentication and authorization controls and updates several third-party components with known CVEs, including Bootstrap, Bootstrap-select, Chart.js, and Vue.js.</p>
<p>Hosting platforms are a real target, and every unpatched vulnerability is exposure you&#8217;re carrying. Updating to v8.3.25 applies all of these fixes in one pass, no separate configuration required.</p>
<p><strong>Not sure your current build or configuration is fully hardened?</strong> <a href="https://www.machsol.com/contact-us/">Talk to a technology expert</a> and we&#8217;ll review your MachPanel deployment to confirm it&#8217;s configured and optimized correctly, not just up to date on paper.</p>
<p><strong>Hyper-V cluster snapshot support: real disaster recovery for clustered VMs</strong></p>
<p>MachPanel now supports snapshots for Hyper-V cluster deployments, not just standalone VMs. Paired with the new cluster-aware VPS import and automatic owner node updates, this closes a real gap for providers running clustered Hyper-V environments. Protecting a VM that can move between nodes used to mean manual console work outside MachPanel. Now it&#8217;s handled inside the platform.</p>
<p>For providers building or scaling a Hyper-V based VPS business, an automation and orchestration platform, not manual console work, is what makes multi-tenant hosting sustainable at volume.</p>
<p><strong>Exchange management, tightened across the board</strong></p>
<p>This release doesn&#8217;t add one standout Exchange feature so much as it cleans up a long list of things administrators deal with regularly:</p>
<ul>
<li>Distribution list membership management rebuilt to handle very large lists, in the 10,000+ member range, without the slow loading that used to come with big DLs</li>
<li>Broader deadlock prevention across Exchange and AD management</li>
<li>Full access permissions now update automatically on resource and room mailboxes when the manager changes</li>
<li>A dedicated custom quota setting for personal archiving</li>
<li>Mailbox exports now include LegacyExchangeDN</li>
<li>Primary email addresses update automatically when an AD user&#8217;s UPN changes</li>
<li>New REST API coverage specific to mailboxes, including PATCH support for general and advanced settingsAlongside these, a set of fixes addresses issues admins have likely run into directly: shared mailbox permission handling, public folder mailboxes not being removed after a subscription cancellation, custom quota values not displaying correctly in the mailbox advanced tab, and an export error on the customer side.<strong>30+ new REST API endpoints for deeper automation</strong>
<p>For teams automating provisioning or integrating MachPanel with billing, CRM, or internal tooling, this build adds REST API coverage for mailbox type changes, calendar permissions, AD authentication, advanced settings, and mailbox add-on reports. More endpoint coverage means fewer workflows that still require manual clicks in the UI, which is the whole point of running an orchestration platform instead of managing Hyper-V, Exchange, and AD by hand across every tenant.</p>
<p><strong>Also in this release</strong></p>
<p>A long list of smaller improvements across VPS and Active Directory management, including:</p>
<ul>
<li>VM reinstall, without full re-provisioning</li>
<li>OS installation via ISO during VM creation, and OS type changes for existing VMs</li>
<li>Dynamic IP allocation for Linux VMs</li>
<li>A separate VLANs report for network auditing</li>
<li>Per-interface firewall reset</li>
<li>More granular staff, customer, and reseller permissions across AD, Hyper-V, and Exchange</li>
<li>Enhanced audit logging across Exchange, Hyper-V, and Skype for Business modules</li>
</ul>
<p>The <a href="https://kb.machsol.com/Knowledgebase/55812/">complete release notes</a> cover every change in this build, including items not listed here.</p>
<p><strong>Before you upgrade</strong></p>
<ul>
<li>Do not upgrade if you&#8217;re running Exchange 2010 or Exchange 2010 Hosted modules.</li>
<li>If you&#8217;re upgrading from a build older than 8.0.32, install .NET Framework 4.8 first.</li>
<li>Upgrade in order: Control Server, then Remote Server, then REST API if you use it.</li>
</ul>
<p>Full step by step instructions are in the <a href="https://kb.machsol.com/Knowledgebase/55812/">release notes</a>.</p>
<p><strong>Frequently asked questions</strong></p>
<p><strong>What&#8217;s new in MachPanel v8.3.25?</strong> Hyper-V cluster snapshot support, a set of Exchange management improvements including better handling of large distribution lists, 30+ new REST API endpoints, and fixes for several security vulnerabilities including SQL injection, XSS, and an SSO bypass issue.</p>
<p><strong>When was MachPanel v8.3.25 released?</strong> September 8, 2026.</p>
<p><strong>Is MachPanel v8.3.25 compatible with Exchange 2010?</strong> No. Customers running Exchange 2010 or Exchange 2010 Hosted modules should not update to this build.</p>
<p><strong>Do I need to do anything special to get the security fixes?</strong> No. Updating to v8.3.25 applies all the security patches automatically.</p>
<p><strong>How do I upgrade to MachPanel v8.3.25?</strong> Update in this order: Control Server, then Remote Server, then REST API if you use it. Install .NET Framework 4.8 first if you&#8217;re coming from a build older than 8.0.32.</p>
<p><strong>Is MachPanel a good alternative to VMware for VPS hosting?</strong> MachPanel is built for providers running Hyper-V based multi-tenant VPS hosting, with automation and orchestration designed for managing many customer environments from one platform. If you&#8217;re weighing a move off VMware, our <a href="https://www.machsol.com/contact-us/">team</a> can walk through what that looks like for your setup.</p>
<p><strong>Where can I see the complete list of changes?</strong> The <a href="https://kb.machsol.com/Knowledgebase/55812/">full release notes</a> cover every feature, improvement, and fix in this build.</p>
<p><strong>Get the most out of this release</strong></p>
<p><strong>Already running MachPanel?</strong> Our support team is at <a href="mailto:support@machsol.com">support@machsol.com</a> or through the <a href="https://support.machsol.com/">support portal</a> for anything related to the upgrade.</p>
<p><strong>Want a second set of eyes on your deployment?</strong> <a href="https://www.machsol.com/contact-us/">Talk to a technology expert</a> to verify your configuration, confirm you&#8217;re getting full value from features like this release&#8217;s Hyper-V and Exchange improvements, and optimize your setup rather than leaving it running on defaults.</p>
<p><strong>Evaluating MachPanel for the first time?</strong> If you&#8217;re running or planning a multi-tenant Hyper-V, Exchange, or Microsoft 365 hosting business, see how MachPanel fits with a <a href="https://view.ms/FreeTrial">free trial</a> or <a href="https://www.machsol.com/contact-us/">talk to our team</a>.</li>
</ul>
<div></div>
<p>To view the complete release notes, please visit:<br />
<a href="https://kb.machsol.com/Knowledgebase/55812/" target="_blank" rel="noopener noreferrer">MachPanel v8.3 Build 25 &#8211; Release Notes </a></p>
<p><strong>Have questions?</strong> Email us at <a href="mailto:support@machsol.com">support@machsol.com</a>  or  visit  <a href="https://support.machsol.com/">https://support.machsol.com/</a></p>
<p>The post <a href="https://blog.machsol.com/announcements/machpanel-v8-3-25-multi-tenant-cloud-orchestration-gets-better">MachPanel v8.3 BUILD 25, Now Available!</a> appeared first on <a href="https://blog.machsol.com">MachSol Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>MachPanel v8.2 BUILD 50, Now Available!</title>
		<link>https://blog.machsol.com/announcements/machpanel-v8-2-build-50-now-available</link>
		
		<dc:creator><![CDATA[Jameel]]></dc:creator>
		<pubDate>Thu, 02 Apr 2026 11:12:06 +0000</pubDate>
				<category><![CDATA[Announcements]]></category>
		<category><![CDATA[Hosting & SaaS]]></category>
		<category><![CDATA[Microsoft Exchange]]></category>
		<category><![CDATA[Microsoft Hyper-V]]></category>
		<guid isPermaLink="false">https://blog.machsol.com/?p=5947</guid>

					<description><![CDATA[<p>MachPanel v8.2.50 We at MachSol, are pleased to announce the immediate availability of the latest build of MachPanel Provisioning System (Multi-Cloud Service Orchestration &#38; Delivery Platform). This new build introduces a range of powerful new features, performance enhancements, and critical bug fixes, further strengthening the platform’s reliability, scalability, and overall capability. To view the complete [&#8230;]</p>
<p>The post <a href="https://blog.machsol.com/announcements/machpanel-v8-2-build-50-now-available">MachPanel v8.2 BUILD 50, Now Available!</a> appeared first on <a href="https://blog.machsol.com">MachSol Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h2>MachPanel v8.2.50</h2>
<p>We at MachSol, are pleased to announce the immediate availability of the latest build of <strong><a href="https://www.machsol.com/products/machpanel/" target="_blank" rel="noopener noreferrer">MachPanel</a></strong> Provisioning System (Multi-Cloud Service Orchestration &amp; Delivery Platform). This new build introduces a range of <strong data-start="364" data-end="389">powerful new features</strong>, <strong data-start="391" data-end="419">performance enhancements</strong>, and <strong data-start="425" data-end="447">critical bug fixes</strong>, further strengthening the platform’s reliability, scalability, and overall capability.</p>
<div><img decoding="async" class="size-full wp-image-5680 alignright" src="https://blog.machsol.com/wp-content/uploads/machpanel-v8-2.png" alt="MachPanel v8" width="170" height="269" /></div>
<p>To view the complete release notes, please visit:<br />
<a href="https://kb.machsol.com/Knowledgebase/55801/" target="_blank" rel="noopener noreferrer">MachPanel v8.2 Build 50 &#8211; Release Notes </a></p>
<p><strong>Have questions?</strong> Email us at <a href="mailto:support@machsol.com">support@machsol.com</a>  or  visit  <a href="https://support.machsol.com/">https://support.machsol.com/</a></p>
<p>The post <a href="https://blog.machsol.com/announcements/machpanel-v8-2-build-50-now-available">MachPanel v8.2 BUILD 50, Now Available!</a> appeared first on <a href="https://blog.machsol.com">MachSol Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>MachPanel v8.1 BUILD 22, Now Available!</title>
		<link>https://blog.machsol.com/announcements/machpanel-v8-1-build-22-now-available</link>
		
		<dc:creator><![CDATA[Jameel]]></dc:creator>
		<pubDate>Tue, 09 Dec 2025 05:12:40 +0000</pubDate>
				<category><![CDATA[Announcements]]></category>
		<category><![CDATA[Hosting & SaaS]]></category>
		<category><![CDATA[Microsoft Exchange]]></category>
		<category><![CDATA[Microsoft Hyper-V]]></category>
		<category><![CDATA[Build 8.1.22]]></category>
		<category><![CDATA[v8.1.22]]></category>
		<guid isPermaLink="false">https://blog.machsol.com/?p=5889</guid>

					<description><![CDATA[<p>MachPanel v8.1.22 We at MachSol, are pleased to announce the immediate availability of the latest build of MachPanel Provisioning System (Multi-Cloud Service Orchestration &#38; Delivery Platform). This new build introduces a range of powerful new features, performance enhancements, and critical bug fixes, further strengthening the platform’s reliability, scalability, and overall capability. To view the complete [&#8230;]</p>
<p>The post <a href="https://blog.machsol.com/announcements/machpanel-v8-1-build-22-now-available">MachPanel v8.1 BUILD 22, Now Available!</a> appeared first on <a href="https://blog.machsol.com">MachSol Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h2>MachPanel v8.1.22</h2>
<p>We at MachSol, are pleased to announce the immediate availability of the latest build of <strong><a href="https://www.machsol.com/products/machpanel/" target="_blank" rel="noopener noreferrer">MachPanel</a></strong> Provisioning System (Multi-Cloud Service Orchestration &amp; Delivery Platform). This new build introduces a range of <strong data-start="364" data-end="389">powerful new features</strong>, <strong data-start="391" data-end="419">performance enhancements</strong>, and <strong data-start="425" data-end="447">critical bug fixes</strong>, further strengthening the platform’s reliability, scalability, and overall capability.</p>
<div><img decoding="async" class="size-full wp-image-5680 alignright" src="https://blog.machsol.com/wp-content/uploads/machpanel-v8-2.png" alt="MachPanel v8" width="170" height="269" /></div>
<p>To view the complete release notes, please visit:<br />
<a href="https://kb.machsol.com/Knowledgebase/55798/" target="_blank" rel="noopener noreferrer">MachPanel v8.1 Build 22 &#8211; Release Notes </a></p>
<p><strong>Have questions?</strong> Email us at <a href="mailto:support@machsol.com">support@machsol.com</a>  or  visit  <a href="https://support.machsol.com/">https://support.machsol.com/</a></p>
<p>The post <a href="https://blog.machsol.com/announcements/machpanel-v8-1-build-22-now-available">MachPanel v8.1 BUILD 22, Now Available!</a> appeared first on <a href="https://blog.machsol.com">MachSol Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>MachPanel v8.0 BUILD 50, Now Available!</title>
		<link>https://blog.machsol.com/announcements/machpanel-v8-0-build-50-now-available</link>
		
		<dc:creator><![CDATA[Jameel]]></dc:creator>
		<pubDate>Tue, 09 Sep 2025 06:43:59 +0000</pubDate>
				<category><![CDATA[Announcements]]></category>
		<category><![CDATA[Hosting & SaaS]]></category>
		<category><![CDATA[Exchange Import Utility]]></category>
		<category><![CDATA[MachPanel REST API]]></category>
		<category><![CDATA[MachPanel v8 build 50]]></category>
		<category><![CDATA[MachPanle v8 Build 50]]></category>
		<category><![CDATA[v8.0.50]]></category>
		<category><![CDATA[VM Management]]></category>
		<guid isPermaLink="false">https://blog.machsol.com/?p=5870</guid>

					<description><![CDATA[<p>MachPanel v8.0.50 We at MachSol, are pleased to announce the immediate availability of the latest build of MachPanel Provisioning System (Multi-Cloud Service Orchestration &#38; Delivery Platform). This new build introduces a range of powerful new features, performance enhancements, and critical bug fixes, further strengthening the platform’s reliability, scalability, and overall capability. To view the complete [&#8230;]</p>
<p>The post <a href="https://blog.machsol.com/announcements/machpanel-v8-0-build-50-now-available">MachPanel v8.0 BUILD 50, Now Available!</a> appeared first on <a href="https://blog.machsol.com">MachSol Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h2>MachPanel v8.0.50</h2>
<p>We at MachSol, are pleased to announce the immediate availability of the latest build of <strong><a href="https://www.machsol.com/products/machpanel/" target="_blank" rel="noopener noreferrer">MachPanel</a></strong> Provisioning System (Multi-Cloud Service Orchestration &amp; Delivery Platform). This new build introduces a range of <strong data-start="364" data-end="389">powerful new features</strong>, <strong data-start="391" data-end="419">performance enhancements</strong>, and <strong data-start="425" data-end="447">critical bug fixes</strong>, further strengthening the platform’s reliability, scalability, and overall capability.</p>
<div><img loading="lazy" decoding="async" class="size-full wp-image-5680 alignright" src="https://blog.machsol.com/wp-content/uploads/machpanel-v8-2.png" alt="MachPanel v8" width="170" height="269" /></div>
<p>To view the complete release notes, please visit:<br />
<a href="https://kb.machsol.com/Knowledgebase/55794/" target="_blank" rel="noopener noreferrer">MachPanel v8.0 Build 50 &#8211; Release Notes </a></p>
<p><strong>Have questions?</strong> Email us at <a href="mailto:support@machsol.com">support@machsol.com</a>  or  visit  <a href="https://support.machsol.com/">https://support.machsol.com/</a></p>
<p>The post <a href="https://blog.machsol.com/announcements/machpanel-v8-0-build-50-now-available">MachPanel v8.0 BUILD 50, Now Available!</a> appeared first on <a href="https://blog.machsol.com">MachSol Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Critical SharePoint Zero-Day Exploit Targeting Enterprises</title>
		<link>https://blog.machsol.com/microsoft-sharepoint/critical-sharepoint-zero-day-exploit-cve-2025-53770-machsol-blog</link>
		
		<dc:creator><![CDATA[Jameel]]></dc:creator>
		<pubDate>Tue, 22 Jul 2025 15:48:01 +0000</pubDate>
				<category><![CDATA[Announcements]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Hosting & SaaS]]></category>
		<category><![CDATA[Microsoft SharePoint]]></category>
		<category><![CDATA[CVE-2025-53770]]></category>
		<category><![CDATA[CVE-2025-53771]]></category>
		<category><![CDATA[How to Safeguard Your SharePoint Environment]]></category>
		<category><![CDATA[Set-SPMachineKey]]></category>
		<category><![CDATA[SharePoint 2016]]></category>
		<category><![CDATA[SharePoint 2019]]></category>
		<category><![CDATA[SharePoint Subscription Edition (SE)]]></category>
		<category><![CDATA[Update-SPMachineKey]]></category>
		<guid isPermaLink="false">https://blog.machsol.com/?p=5804</guid>

					<description><![CDATA[<p>A critical zero-day vulnerability in Microsoft SharePoint Server, CVE-2025-53770, is being actively exploited in targeted attacks against enterprises and government systems. The exploit allows unauthenticated remote code execution (RCE), key theft, and persistent backdoor installation. Organizations running on-premises SharePoint (Subscription Edition, 2019, and 2016) face immediate operational, legal, and reputational risk if unpatched or misconfigured. [&#8230;]</p>
<p>The post <a href="https://blog.machsol.com/microsoft-sharepoint/critical-sharepoint-zero-day-exploit-cve-2025-53770-machsol-blog">Critical SharePoint Zero-Day Exploit Targeting Enterprises</a> appeared first on <a href="https://blog.machsol.com">MachSol Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p data-start="404" data-end="699">A <strong data-start="406" data-end="472">critical zero-day vulnerability in Microsoft SharePoint Server</strong>, CVE-2025-53770, is being actively exploited in targeted attacks against enterprises and government systems. The exploit allows <strong data-start="601" data-end="648">unauthenticated remote code execution (RCE)</strong>, key theft, and persistent backdoor installation.</p>
<p><img loading="lazy" decoding="async" class="size-full wp-image-5827 aligncenter" src="https://blog.machsol.com/wp-content/uploads/safeguard-sharepoint-Now.jpg" alt="" width="1000" height="400" srcset="https://blog.machsol.com/wp-content/uploads/safeguard-sharepoint-Now.jpg 1000w, https://blog.machsol.com/wp-content/uploads/safeguard-sharepoint-Now-350x140.jpg 350w, https://blog.machsol.com/wp-content/uploads/safeguard-sharepoint-Now-768x307.jpg 768w, https://blog.machsol.com/wp-content/uploads/safeguard-sharepoint-Now-720x288.jpg 720w, https://blog.machsol.com/wp-content/uploads/safeguard-sharepoint-Now-580x232.jpg 580w, https://blog.machsol.com/wp-content/uploads/safeguard-sharepoint-Now-320x128.jpg 320w" sizes="auto, (max-width: 1000px) 100vw, 1000px" /></p>
<p data-start="701" data-end="880">Organizations running <strong data-start="723" data-end="788">on-premises SharePoint (Subscription Edition, 2019, and 2016)</strong> face immediate operational, legal, and reputational risk if unpatched or misconfigured.</p>
<h2 data-start="887" data-end="911"><span style="font-size: 14pt; color: #3366ff;">Technical Overview</span></h2>
<ul>
<li><strong data-start="915" data-end="926">CVE IDs</strong>: CVE-2025-53770 (primary RCE), CVE-2025-53771 (chained)</li>
<li><strong data-start="985" data-end="1008">Vulnerability Class</strong>: .NET ViewState Deserialization + Path Traversal</li>
<li data-start="1060" data-end="1083"><strong data-start="1060" data-end="1082">Affected Platforms</strong>:
<ul>
<li data-start="1088" data-end="1130">SharePoint Server <strong data-start="1106" data-end="1130">Subscription Edition</strong></li>
<li data-start="1135" data-end="1161">SharePoint Server <strong data-start="1153" data-end="1161">2019</strong></li>
<li data-start="1166" data-end="1237">SharePoint Server <strong data-start="1184" data-end="1192"><strong data-start="1184" data-end="1192">2016</strong></strong></li>
</ul>
</li>
<li data-start="1240" data-end="1413"><strong data-start="1240" data-end="1257">Attack Vector</strong>: Unauthenticated HTTP(S) request to <code data-start="1294" data-end="1309">ToolPane.aspx</code> leveraging insecure ViewState + malicious path traversal to drop arbitrary code in server-side layouts.</li>
<li><strong data-start="1416" data-end="1427">Payload</strong>: <code data-start="1429" data-end="1446">spinstall0.aspx</code> web shell deployed for persistent control and exfiltration.</li>
</ul>
<h2 data-start="1508" data-end="1538"><span style="font-size: 14pt; color: #3366ff;">Technical Implications:</span></h2>
<ul>
<li data-start="1541" data-end="1639"><strong data-start="1541" data-end="1567">Machine key compromise</strong>: Allows attackers to sign payloads that bypass authentication controls.</li>
<li data-start="1642" data-end="1719"><strong data-start="1642" data-end="1667">Web shell persistence</strong>: Enables long-term command and control (C2) access.</li>
<li data-start="1722" data-end="1817"><strong data-start="1722" data-end="1760">Post-exploitation lateral movement</strong>: Via NTLM relay, LDAP harvesting, or credential dumping.</li>
<li data-start="1820" data-end="1920"><strong data-start="1820" data-end="1844">Detection challenges</strong>: Use of legitimate pages (<code data-start="1871" data-end="1886">ToolPane.aspx</code>) and tampering with AMSI logging</li>
</ul>
<h3 data-start="991" data-end="1032"></h3>
<p data-start="991" data-end="1032"><strong><span style="color: #3366ff; font-size: 14pt;"> Immediate Remediation Guide</span></strong></p>
<p data-start="991" data-end="1032"><strong>1. Patch All Versions Immediately</strong></p>
<ul>
<li style="list-style-type: none;">
<ul>
<li data-start="1035" data-end="1074"><span class="relative -mx-px my-[-0.2rem] rounded px-px py-[0.2rem] transition-colors duration-100 ease-in-out"><strong data-start="0" data-end="24" data-is-only-node="">Subscription Edition</strong> → <a href="https://www.microsoft.com/en-us/download/details.aspx?id=108285" target="_blank" rel="noopener">KB 5002768</a></span></li>
<li data-start="1077" data-end="1116"><span class="relative -mx-px my-[-0.2rem] rounded px-px py-[0.2rem] transition-colors duration-100 ease-in-out"><strong data-start="0" data-end="19" data-is-only-node="">SharePoint 2019</strong> → <a href="https://www.microsoft.com/en-us/download/details.aspx?id=108286" target="_blank" rel="noopener">KB 5002754 </a> AND  <a href="https://www.microsoft.com/en-us/download/details.aspx?id=108287" target="_blank" rel="noopener">KB 5002753 </a></span></li>
<li><span class="relative -mx-px my-[-0.2rem] rounded px-px py-[0.2rem] transition-colors duration-100 ease-in-out"><span class="relative -mx-px my-[-0.2rem] rounded px-px py-[0.2rem] transition-colors duration-100 ease-in-out"><span class="relative -mx-px my-[-0.2rem] rounded px-px py-[0.2rem] transition-colors duration-100 ease-in-out"><span class="relative -mx-px my-[-0.2rem] rounded px-px py-[0.2rem] transition-colors duration-100 ease-in-out"><span class="relative -mx-px my-[-0.2rem] rounded px-px py-[0.2rem] transition-colors duration-100 ease-in-out"><strong data-start="0" data-end="19" data-is-only-node="">SharePoint 2016</strong> →  <a href="https://www.microsoft.com/en-us/download/details.aspx?id=108288" target="_blank" rel="noopener">KB 5002760</a> (language pack), <a href="https://www.microsoft.com/en-us/download/details.aspx?id=108289" target="_blank" rel="noopener">KB 5002759</a> (core)</span></span></span></span></span></li>
</ul>
</li>
</ul>
<p><strong>2. Rotate SharePoint Server ASP.NET machine keys</strong></p>
<p style="padding-left: 40px;">After applying the latest security updates above, it is critical that to rotate SharePoint server ASP.NET machine keys and restart IIS on all SharePoint servers.</p>
<p style="padding-left: 40px;">To update the machine keys for a web application using <strong>PowerShell</strong>:</p>
<ul>
<li>Generate the machine key in PowerShell using<strong> Set-SPMachineKey</strong><br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-5811" src="https://blog.machsol.com/wp-content/uploads/set-spmachinekey.png" alt="" width="836" height="53" srcset="https://blog.machsol.com/wp-content/uploads/set-spmachinekey.png 836w, https://blog.machsol.com/wp-content/uploads/set-spmachinekey-350x22.png 350w, https://blog.machsol.com/wp-content/uploads/set-spmachinekey-768x49.png 768w, https://blog.machsol.com/wp-content/uploads/set-spmachinekey-720x46.png 720w, https://blog.machsol.com/wp-content/uploads/set-spmachinekey-580x37.png 580w, https://blog.machsol.com/wp-content/uploads/set-spmachinekey-320x20.png 320w" sizes="auto, (max-width: 836px) 100vw, 836px" /></li>
<li>Deploy the machine key to the farm in PowerShell using <strong>Update-SPMachineKey</strong><br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-5812" src="https://blog.machsol.com/wp-content/uploads/update-spmachinekey.png" alt="" width="842" height="52" srcset="https://blog.machsol.com/wp-content/uploads/update-spmachinekey.png 842w, https://blog.machsol.com/wp-content/uploads/update-spmachinekey-350x22.png 350w, https://blog.machsol.com/wp-content/uploads/update-spmachinekey-768x47.png 768w, https://blog.machsol.com/wp-content/uploads/update-spmachinekey-720x44.png 720w, https://blog.machsol.com/wp-content/uploads/update-spmachinekey-580x36.png 580w, https://blog.machsol.com/wp-content/uploads/update-spmachinekey-320x20.png 320w" sizes="auto, (max-width: 842px) 100vw, 842px" /></li>
</ul>
<p><strong>3. IIS &#8220;<code data-start="98" data-end="108">iisreset</code>&#8221; reset after the rotation has completed.</strong></p>
<p style="padding-left: 40px;"><code data-start="0" data-end="10" data-is-only-node="">iisreset</code> is required to ensure all SharePoint services<strong> immediately load the new machine</strong> keys from <code data-start="100" data-end="112">web.config</code> and prevent use of old keys left in memory.</p>
<p>&nbsp;</p>
<h3 data-start="517" data-end="558"><span style="color: #3366ff; font-size: 12pt;">Why <strong data-start="527" data-end="550">Machine Key Rotation</strong> matters</span></h3>
<ul>
<li data-start="562" data-end="642"><span class="relative -mx-px my-[-0.2rem] rounded px-px py-[0.2rem] transition-colors duration-100 ease-in-out"><strong data-start="0" data-end="32" data-is-only-node="">Patching alone is not enough</strong>:  Attackers who have already stolen validation/decryption keys can continue creating malicious ViewState payloads.</span></li>
<li data-start="645" data-end="725"><span class="relative -mx-px my-[-0.2rem] rounded px-px py-[0.2rem] transition-colors duration-100 ease-in-out"><strong data-start="0" data-end="34" data-is-only-node="">Microsoft guidance: </strong>The Microsoft Defender Vulnerability Management blog recommends rotating the machineKey twice, once before and once after applying patches to ensure complete protection.</span></li>
<li data-start="645" data-end="725"><span class="relative -mx-px my-[-0.2rem] rounded px-px py-[0.2rem] transition-colors duration-100 ease-in-out"><span class="relative -mx-px my-[-0.2rem] rounded px-px py-[0.2rem] transition-colors duration-100 ease-in-out"><strong data-start="0" data-end="19" data-is-only-node="">Double rotation:</strong> This practice helps eliminate lingering threats and prevents attackers from exploiting stolen cryptographic material.</span></span></li>
</ul>
<p data-start="1417" data-end="1427"><strong><span style="font-size: 14pt; color: #3366ff;">Summary</span></strong></p>
<ul>
<li data-start="1431" data-end="1537"><strong data-start="1431" data-end="1454">Exploit in-the-wild</strong>: The ToolShell exploit (CVE-2025-53770) is actively targeting on-premises SharePoint servers.</li>
<li data-start="1431" data-end="1537"><strong data-start="1540" data-end="1559">Patches ongoing</strong>: Subscription Edition, 2019 and 2016 have patches available</li>
<li data-start="1431" data-end="1537"><strong data-start="1622" data-end="1657">MachineKey rotation is critical</strong>: Machine key rotation is essential to invalidate stolen keys and stop persistent threats.</li>
<li><strong>Post Rotation:</strong> Always restart IIS on all SharePoint servers using <code data-start="3638" data-end="3652">iisreset.exe</code> to apply changes immediately.</li>
</ul>
<p>For comprehensive information, please refer to Microsoft&#8217;s official Common Vulnerabilities and Exposures (CVE) documentation for CVE-2025-53770 and related vulnerabilities</p>
<p><span style="font-size: 9pt;"><strong data-start="68" data-end="83">Disclaimer:</strong> Always back up your configuration (web.config and other) and test changes in a non-production environment before applying them to live systems.</span></p>
<p data-start="3689" data-end="3749"><span style="color: #3366ff;"><span style="font-size: 14pt; color: #3366ff;">→ </span><strong><span style="font-size: 14pt; color: #3366ff;">Securing SharePoint Against Current and Future Threats</span><span style="font-size: 14pt;"><br />
</span></strong><em><strong><span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="size-full wp-image-5842 aligncenter" src="https://blog.machsol.com/wp-content/uploads/Secure-SharePoint-1.jpg" alt="" width="1000" height="400" srcset="https://blog.machsol.com/wp-content/uploads/Secure-SharePoint-1.jpg 1000w, https://blog.machsol.com/wp-content/uploads/Secure-SharePoint-1-350x140.jpg 350w, https://blog.machsol.com/wp-content/uploads/Secure-SharePoint-1-768x307.jpg 768w, https://blog.machsol.com/wp-content/uploads/Secure-SharePoint-1-720x288.jpg 720w, https://blog.machsol.com/wp-content/uploads/Secure-SharePoint-1-580x232.jpg 580w, https://blog.machsol.com/wp-content/uploads/Secure-SharePoint-1-320x128.jpg 320w" sizes="auto, (max-width: 1000px) 100vw, 1000px" /></span></strong></em></span></p>
<p data-start="3751" data-end="3818">To protect your SharePoint deployment from this and future threats:</p>
<ul>
<li><strong data-start="328" data-end="359">Maintain Up-to-Date Systems</strong>: Ensure all SharePoint servers and related infrastructure are fully patched with the latest Microsoft security updates.</li>
<li><strong data-start="565" data-end="604">Rotate Cryptographic Keys Regularly</strong>: Periodically rotate machine keys, especially following security incidents to reduce the risk of key compromise.</li>
<li data-start="4100" data-end="4226"><strong data-start="760" data-end="810">Implement Comprehensive Logging and Monitoring</strong>: Enable detailed logging for SharePoint, including Antimalware Scan Interface (AMSI) and Windows Event Logs. Monitor for signs of tampering, suspicious activity.</li>
<li data-start="4229" data-end="4358"><strong data-start="147" data-end="185">Apply Network and Access Controls: </strong>Restrict access to SharePoint administrative interfaces, especially the <strong data-start="259" data-end="290">Central Administration site</strong> and other configuration pages by implementing network segmentation, VPNs, and firewall rules. Ensure that only authorized personnel can reach these sensitive areas by limiting access to trusted networks or through secure remote access solutions.</li>
<li data-start="4361" data-end="4477"><strong data-start="1277" data-end="1311">Backup and Test Configurations</strong>: Regularly back up key configuration files (e.g., <code data-start="1362" data-end="1374">web.config</code>, <code data-start="1376" data-end="1392">machine.config</code>) and test patches and updates in a controlled staging environment prior to production deployment.</li>
</ul>
<p><span style="font-size: 10pt;"> </span></p>
<p>The post <a href="https://blog.machsol.com/microsoft-sharepoint/critical-sharepoint-zero-day-exploit-cve-2025-53770-machsol-blog">Critical SharePoint Zero-Day Exploit Targeting Enterprises</a> appeared first on <a href="https://blog.machsol.com">MachSol Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>MachPanel v8.0 BUILD 32, Now Available!</title>
		<link>https://blog.machsol.com/announcements/machpanel-v8-0-build-32-now-available</link>
		
		<dc:creator><![CDATA[Jameel]]></dc:creator>
		<pubDate>Mon, 19 May 2025 05:24:45 +0000</pubDate>
				<category><![CDATA[Announcements]]></category>
		<category><![CDATA[Exchange Signature]]></category>
		<category><![CDATA[MachPanel API]]></category>
		<category><![CDATA[v8.0 Build 32]]></category>
		<category><![CDATA[v8.0.32]]></category>
		<guid isPermaLink="false">https://blog.machsol.com/?p=5741</guid>

					<description><![CDATA[<p>MachPanel v8.0.32 We at MachSol, are pleased to announce the immediate availability of the latest build of MachPanel Provisioning System (Multi-Cloud Service Orchestration &#38; Delivery Platform). Version 8.0.32 brings a range of new features, performance enhancements, and critical bug fixes, further strengthening the reliability and capabilities of the platform. You may review the complete list [&#8230;]</p>
<p>The post <a href="https://blog.machsol.com/announcements/machpanel-v8-0-build-32-now-available">MachPanel v8.0 BUILD 32, Now Available!</a> appeared first on <a href="https://blog.machsol.com">MachSol Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h2>MachPanel v8.0.32</h2>
<p>We at MachSol, are pleased to announce the immediate availability of the latest build of <strong><a href="https://www.machsol.com/products/machpanel/" target="_blank" rel="noopener noreferrer">MachPanel</a></strong> Provisioning System (Multi-Cloud Service Orchestration &amp; Delivery Platform). Version 8.0.32 brings a range of new features, performance enhancements, and critical bug fixes, further strengthening the reliability and capabilities of the platform.</p>
<div><img loading="lazy" decoding="async" class="size-full wp-image-5680 alignright" src="https://blog.machsol.com/wp-content/uploads/machpanel-v8-2.png" alt="MachPanel v8" width="170" height="269" /></div>
<p>You may review the complete list by visiting the following knowledge base Article.</p>
<div>
<div></div>
<p><a href="https://kb.machsol.com/Knowledgebase/55788/" target="_blank" rel="noopener noreferrer">MachPanel v8.0 Build 32 &#8211; Release Notes </a></p>
<p><strong><br />
Have questions?</strong> Email us at <a href="mailto:support@machsol.com">support@machsol.com</a>  or  visit  <a href="https://support.machsol.com/">https://support.machsol.com/</a></p>
</div>
<p>The post <a href="https://blog.machsol.com/announcements/machpanel-v8-0-build-32-now-available">MachPanel v8.0 BUILD 32, Now Available!</a> appeared first on <a href="https://blog.machsol.com">MachSol Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>MachPanel v7.3 BUILD 60, Now Available!</title>
		<link>https://blog.machsol.com/announcements/machpanel-v7-3-build-60-now-available</link>
		
		<dc:creator><![CDATA[Jameel]]></dc:creator>
		<pubDate>Mon, 09 Sep 2024 03:04:20 +0000</pubDate>
				<category><![CDATA[Announcements]]></category>
		<category><![CDATA[CSP]]></category>
		<category><![CDATA[Exchange]]></category>
		<category><![CDATA[Hyper-V]]></category>
		<category><![CDATA[v7.3 Build 60]]></category>
		<category><![CDATA[v7.3.60]]></category>
		<guid isPermaLink="false">https://blog.machsol.com/?p=5714</guid>

					<description><![CDATA[<p>MachPanel v7.3.60 We at MachSol, are pleased to announce the immediate availability of the latest build of MachPanel Provisioning System (Multi-Cloud Service Orchestration &#38; Delivery Platform). Latest build v7.3.60 includes an array of new features and performance improvements alongside bug fixes. You may review the complete list by visiting the following knowledge base Article. MachPanel [&#8230;]</p>
<p>The post <a href="https://blog.machsol.com/announcements/machpanel-v7-3-build-60-now-available">MachPanel v7.3 BUILD 60, Now Available!</a> appeared first on <a href="https://blog.machsol.com">MachSol Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h2>MachPanel v7.3.60</h2>
<p>We at MachSol, are pleased to announce the immediate availability of the latest build of <strong><a href="https://www.machsol.com/products/machpanel/" target="_blank" rel="noopener noreferrer">MachPanel</a></strong> Provisioning System (Multi-Cloud Service Orchestration &amp; Delivery Platform). Latest build v7.3.60 includes an array of new features and performance improvements alongside bug fixes.</p>
<div>
<div><img loading="lazy" decoding="async" class="size-full wp-image-5680 alignright" src="https://blog.machsol.com/wp-content/uploads/machpanel-v7.png" alt="MachPanel v7" width="170" height="269" /></div>
<p>You may review the complete list by visiting the following knowledge base Article.</p>
<p><a href="https://kb.machsol.com/Knowledgebase/55783/" target="_blank" rel="noopener noreferrer">MachPanel v7.3 Build 60 &#8211; Release Notes </a></p>
<p><strong><br />
Have questions?</strong> Email us at <a href="mailto:support@machsol.com">support@machsol.com</a>  or  visit  <a href="https://support.machsol.com/">https://support.machsol.com/</a></p>
</div>
<p>The post <a href="https://blog.machsol.com/announcements/machpanel-v7-3-build-60-now-available">MachPanel v7.3 BUILD 60, Now Available!</a> appeared first on <a href="https://blog.machsol.com">MachSol Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>MachPanel v7.3 BUILD 20, Now Available!</title>
		<link>https://blog.machsol.com/announcements/machpanel-v7-3-build-20-now-available</link>
		
		<dc:creator><![CDATA[Jameel]]></dc:creator>
		<pubDate>Tue, 19 Mar 2024 06:32:07 +0000</pubDate>
				<category><![CDATA[Announcements]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Microsoft Hyper-V]]></category>
		<category><![CDATA[MachPanel v7.3.20]]></category>
		<category><![CDATA[v.7.3.20]]></category>
		<category><![CDATA[v7.3 build 20]]></category>
		<guid isPermaLink="false">https://blog.machsol.com/?p=5659</guid>

					<description><![CDATA[<p>MachPanel v7.3.20 We at MachSol, are pleased to announce the immediate availability of the latest build of MachPanel Provisioning System (Multi-Cloud Service Orchestration &#38; Delivery Platform). Latest build v7.3.20 includes an array of new features and performance improvements alongside bug fixes. You may review the complete list by visiting the following knowledge base Article. MachPanel [&#8230;]</p>
<p>The post <a href="https://blog.machsol.com/announcements/machpanel-v7-3-build-20-now-available">MachPanel v7.3 BUILD 20, Now Available!</a> appeared first on <a href="https://blog.machsol.com">MachSol Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h2>MachPanel v7.3.20</h2>
<p>We at MachSol, are pleased to announce the immediate availability of the latest build of <strong><a href="https://www.machsol.com/products/machpanel/" target="_blank" rel="noopener noreferrer">MachPanel</a></strong> Provisioning System (Multi-Cloud Service Orchestration &amp; Delivery Platform). Latest build v7.3.20 includes an array of new features and performance improvements alongside bug fixes.</p>
<div>
<div><img loading="lazy" decoding="async" class="size-full wp-image-5680 alignright" src="https://blog.machsol.com/wp-content/uploads/machpanel-v7.png" alt="MachPanel v7" width="170" height="269" /></div>
<p>You may review the complete list by visiting the following knowledge base Article.</p>
<p><a href="https://kb.machsol.com/Knowledgebase/55769/" target="_blank" rel="noopener noreferrer">MachPanel v7.3 Build 20 &#8211; Release Notes </a></p>
<p><span style="font-size: 10pt;"><span style="font-size: 12pt;"><strong><br />
Have questions?</strong> Email us at <a href="mailto:support@machsol.com">support@machsol.com</a>  or </span></span><span style="font-size: 10pt;"><span style="font-size: 12pt;"> visit  </span><a href="https://support.machsol.com/"><span style="font-size: 12pt;">https://support.machsol.com/</span></a></span></p>
</div>
<p>The post <a href="https://blog.machsol.com/announcements/machpanel-v7-3-build-20-now-available">MachPanel v7.3 BUILD 20, Now Available!</a> appeared first on <a href="https://blog.machsol.com">MachSol Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>MachPanel v7.2 BUILD 35, Now Available!</title>
		<link>https://blog.machsol.com/announcements/machpanel-v7-2-build-35-now-available</link>
		
		<dc:creator><![CDATA[Jameel]]></dc:creator>
		<pubDate>Wed, 29 Nov 2023 06:47:22 +0000</pubDate>
				<category><![CDATA[Announcements]]></category>
		<category><![CDATA[CSP]]></category>
		<category><![CDATA[Exchange]]></category>
		<category><![CDATA[MachPanel v7.2 build 35]]></category>
		<category><![CDATA[REST API]]></category>
		<category><![CDATA[v7.2.35]]></category>
		<guid isPermaLink="false">https://blog.machsol.com/?p=5635</guid>

					<description><![CDATA[<p>MachPanel v7.2.35 We at MachSol, are pleased to announce the immediate availability of the latest build of MachPanel Provisioning System (Multi-Cloud Service Orchestration &#38; Delivery Platform). Latest build v7.2.35 includes an array of new features and performance improvements alongside bug fixes. You may review the complete list by visiting the useful link(s) mentioned as under: [&#8230;]</p>
<p>The post <a href="https://blog.machsol.com/announcements/machpanel-v7-2-build-35-now-available">MachPanel v7.2 BUILD 35, Now Available!</a> appeared first on <a href="https://blog.machsol.com">MachSol Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h2>MachPanel v7.2.35</h2>
<p>We at MachSol, are pleased to announce the immediate availability of the latest build of <strong><a href="https://www.machsol.com/products/machpanel/" target="_blank" rel="noopener noreferrer">MachPanel</a></strong> Provisioning System (Multi-Cloud Service Orchestration &amp; Delivery Platform). Latest build v7.2.35 includes an array of new features and performance improvements alongside bug fixes.</p>
<div>
<div>
<p><img loading="lazy" decoding="async" class="alignright" title="Product - Box" src="https://www.machsol.com/images/machpanel-v7.png" alt="" width="175" height="279" /></p>
</div>
<p>You may review the complete list by visiting the useful link(s) mentioned as under:</p>
<p><a href="https://kb.machsol.com/Knowledgebase/55755/" target="_blank" rel="noopener noreferrer">MachPanel v7.2 Build 35 &#8211; Release Notes </a></p>
<p>For more information about MachPanel, visit our website at: <a href="https://www.machsol.com" target="_blank" rel="noopener noreferrer">https://www.machsol.com</a> or call Toll free number: +1 877 622 4765. Our Sales &amp; Support teams are always available to assist you in every way possible.</p>
</div>
<p>The post <a href="https://blog.machsol.com/announcements/machpanel-v7-2-build-35-now-available">MachPanel v7.2 BUILD 35, Now Available!</a> appeared first on <a href="https://blog.machsol.com">MachSol Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
