Insights
The security blog
Field notes on Microsoft 365 security — identity, endpoints, data protection, detections and the occasional war story. Practical, opinionated, and free of fluff.
Conditional Access That Won't Get You Fired
A pragmatic baseline set of Microsoft Entra Conditional Access policies that block the common attacks without flooding your helpdesk on Monday morning.
Conditional AccessEntra IDMFA
Read articleZero Trust for Microsoft 365, Explained Without the Buzzwords
Zero Trust isn't a product you buy — it's a set of decisions about identity, devices and data. Here's what it actually means inside a Microsoft 365 tenant.
Zero TrustIntunePurview
Read articleHunting MFA Fatigue Attacks with KQL
Attackers don't always crack MFA — sometimes they just spam it until someone taps approve. Here's a KQL detection to catch MFA fatigue in Microsoft Sentinel.
KQLSentinelDefender XDR
Read article