Practical field guides for modern endpoint operations.
Step-by-step technical runbooks for Intune, security, identity, certificates, endpoint privilege, device lifecycle, data security, and operational governance.
Conditional Access Naming Convention & Implementation Standard
A unified naming convention, numbering ranges, policy examples, and a safe rollout process for Microsoft Entra
Open Guide →Endpoint Privilege Management
Deploy and operate Microsoft Intune EPM with elevation settings, rules, support-approved workflows, reporting, and rollout practices.
Open Guide →PKI & Certificate Management
Enterprise certificate delivery with SCEP, PKCS, Trusted Root profiles, Certificate Connector, Wi-Fi/VPN, S/MIME, renewal, and monitoring.
Open Guide →Apple Device Management
Manage iOS, iPadOS, macOS, enrollment, ADE, ABM, compliance, app deployment, certificates, and Apple-specific Intune operations.
Open Guide →Windows Autopilot
Design and operate Autopilot enrollment, device preparation, profiles, ESP, hardware hashes, deployment scenarios, and troubleshooting.
Open Guide →Compliance & Proactive Remediation
Build compliance policy, custom compliance, remediation scripts, detection logic, reporting, and operational device health workflows.
Open Guide →Conditional Access
Design Conditional Access policies with Intune compliance, device state, identity risk, session controls, exclusions, and safe rollout practices.
Open Guide →Defender for Endpoint with Intune
Onboard and govern MDE with Intune, security baselines, ASR, endpoint detection, reporting, and operational response.
Open Guide →Microsoft Purview & DSPM
Implement Purview and data security posture management with classification, DLP, insider risk, sensitivity labels, and data governance.
Open Guide →Microsoft Sentinel
Build Sentinel operations with connectors, analytics rules, workbooks, automation, KQL, incidents, and SOC governance.
Open Guide →Windows Update & Autopatch
Operate Windows Update for Business, Autopatch, rings, deadlines, reporting, rollback strategy, and servicing governance.
Open Guide →API Security Design Field Guide
Cover OWASP API Top 10, Azure APIM policies, OAuth 2.0 best practices, and Defender for APIs — everything you need to secure your API surface.
Open Guide →Azure App Service Security
Securing Azure Web Apps: VNet Integration for private connectivity, Managed Identity for passwordless access to Azure resources, Easy Auth for built-in authentication, and Key Vault References.
Open Guide →BitLocker Encryption Management with Intune – Complete Guide
Deploy, escrow, and enforce BitLocker at scale through Intune — silent encryption, Conditional Access tie-in, self-service recovery, and the failure modes that actually happen.
Open Guide →SMS and Voice Authentication Is Being Retired. Here's Your Migration Plan.
Microsoft is retiring native SMS and voice OTP from Entra ID on February 1, 2027 — with no opt-out. This guide covers every deadline, the passkey migration path, and the admin checklist to get every user moved before enforcement hits.
Open Guide →Mass File Deletion Alerts: OneDrive & SharePoint Detection Layers
Four detection layers for mass file deletion in OneDrive and SharePoint: E3 Alert Policies, E5 Insider Risk Management, DLP, and Intune Conditional Access automation. Covers required licensing, configuration steps, and an incident response playbook.
Open guide �����Azure Firewall – Complete Guide
Azure Firewall SKU selection, Hub-Spoke architecture, rule collection processing, IDPS with 58,000+ signatures, TLS inspection, and KQL threat hunting queries.
Open Guide →Microsoft Entra Passwordless Authentication — Complete Field Guide
Deploy FIDO2 security keys, Windows Hello for Business, and Microsoft Authenticator passkeys. Covers Authentication Methods Policy, pilot group scoping, Conditional Access enforcement, and monitoring sign-in fallback to passwords.
Open Guide →Migrate Defender for Cloud Apps File Policies to Microsoft Purview
File policies in Defender for Cloud Apps retire January 6, 2027. This guide covers inventory, condition mapping, capability gaps, staged rollout to Purview DLP and auto-labeling — with portal mockups at every step.
Open Guide →Shadow AI Governance in Microsoft 365 — Detection, Blocking, and Network-Level Controls
A complete field guide to detecting, blocking, and governing unauthorized AI tools in your Microsoft 365 environment — covering Defender for Cloud Apps, Entra Internet Access, Conditional Access, Purview DLP, and KQL threat hunting.
Open Guide →Azure Copilot Agents Are Being Enabled in Your Tenant on August 1 — Audit Checklist and Governance Controls
Microsoft is enabling AI agents in Azure Copilot for all tenants on August 1, 2026. This guide covers the risk matrix for each agent, how to audit your exposure, RBAC scoping, and the step-by-step controls to put in place before the deadline.
Open Guide →The Voicemail Backdoor Into Your MFA
A real account takeover used nothing but a default voicemail PIN and phone-based MFA -- here's how to audit and close the gap in Entra ID.
Open Guide ->Intune Can Finally See What's Actually Sitting in the Registry
Microsoft's new Device Inventory feature reads registry values straight off managed Windows devices — no scripts, no CMPivot queries. Here's how it works, its hard limits, and how to use it for real drift and compliance checks.
Open Guide →