Identity, Governance & Security Writing
Practical thinking on Microsoft Entra ID, M365 Governance, and Conditional Access. No fluff, no vendor spin.
Mastering Groups: The Deep Dive
The complete reference to Microsoft 365 group types, creation controls, lifecycle governance, and the directory settings that underpin every workload in your tenant.
Identity
5 articlesMicrosoft Entra ID, authentication, identity architecture, and threat detection. The fundamentals that everything else builds on.
Identity Is Everything
Defense in depth, Zero Trust, RBAC, and ITDR explained through everyday life. Why signal correlation matters.
Authentication Methods: The Spectrum
From SMS OTP to phishing-resistant MFA — understanding the full range and when each matters.
Passkeys: Security Only Works If People Use It
The strongest authentication method doesn't matter if adoption fails. What makes passkeys stick.
Who Did You Let Into Your House?
Guest accounts, external identities, and the access you forgot you gave.
Groups: The Connective Tissue
Every MFA policy, CA exclusion, app assignment, and privileged role is enforced through group membership. Get groups wrong and everything else fails quietly.
Conditional Access
6 articlesConditional Access policy design, exclusions, service principal gaps, and the real-world decisions behind every rule.
10 CA Mistakes That Are Probably in Your Tenant Right Now
Not theory. These are the gaps that show up in real tenants — the ones that look configured but aren’t doing what the admin thought.
Baseline Scopes: Microsoft Closed the Side Door
A Conditional Access gap that sat open for years, the research that exposed it, and the new enforcement setting that closes it.
CA Policy Analyzer: July 2026 Update
Community-contributed fixes, new audit rules, and expanded coverage for real-world policy gaps — what shipped in the July 2026 release.
CA Policy Analyzer Update
What changed in the latest CA Policy Analyzer update and how to use it to validate exclusions, gaps, and policy coverage faster.
Conditional Access: The Safety Net
Why Azure is the foundation of every CA stack. Build the safety net first. Then build the stack on top of it.
MFA for All… But Not the Same
One foundational policy. Four excluded service principals. And the production scars that explain every decision.
Governance
2 articlesM365 governance, group lifecycle, ownership models, and the cleanup work that never makes it onto roadmaps — until something breaks.
Groups Are the Connective Tissue — and Nobody Owns the Scissors
A governance lens on groups: dynamic rules, naming policy, expiry, and why ungoverned groups become risk vectors.
The Governance Gap
Settings are the starting point. What separates a configured tenant from a controlled one is operationalisation.
The Cleanup Campaign That Never Ends
Lifecycle management isn't a one-time project — it's a countermeasure against the entropy of a living tenant.
Clean the House Before the Guests Arrive
Before Copilot goes live, you need to know what it will find. A practical audit framework for governance readiness.
The Ownership Operating Model
Governance doesn't fail because of technology. It fails because nobody owns anything. Building an operating model that sticks.
Entra
2 articlesDeep dives on Microsoft Entra groups, OAuth2, delegated and app permissions, and practical identity platform architecture.
Mastering Groups: The Deep Dive
The complete reference to Microsoft 365 group types, creation controls, lifecycle governance, and the directory settings that underpin every workload.
AUs vs RMAUs: What's That?
A practical deep dive on Administrative Units and role-assignable variants in Microsoft Entra — where each fits, where each breaks down, and how to use them safely in production.
Never miss a new article.
Subscribe via RSS or follow the full archive of 38 published articles on Medium.