Graph API, PowerShell, GitOps, configuration as code, and CI/CD pipelines.
13 articles
A default member in Entra ID can enumerate the whole directory: every user, group, service principal and role assignment. The controls that narrow it.
Control M365 add-on costs: a five-question framework for Intune Suite, Entra ID Governance, Copilot, and Purview, plus a PowerShell audit script.
What an M365 Solution Architect actually does: standards ownership, security architecture, licensing strategy, and delivery oversight. Beyond diagrams.
Compare Intune security baselines against CIS benchmarks with a PowerShell export-and-diff workflow: ASR deployment and deviation tracking included.
M365 E3 vs E5 decision framework for architects: TCO breakpoints, cost comparison scripts, and the rule for when E5 actually beats E3 plus add-ons.
Microsoft 365 tenant health audit checklist: detect orphaned groups, expired app secrets, CA policy sprawl, and SharePoint chaos with Graph API scripts.
Production-ready PowerShell scripts for M365 tenant assessment via Graph API: discovery, identity auditing, security posture, governance, licensing.
Automated M365 licensing audit using Graph API and PowerShell: find unused Copilot seats and reclaim licences from disabled accounts still on E5.
How I built a self-maintaining Intune app catalogue: Graph API pulls inventory, AI classifies it, and surfaces your MSIX migration shortlist automatically.
How AI changes Intune endpoint management: Copilot agents, API-driven policy configuration, and intelligent drift detection instead of manual clicks.
Win32 vs MSIX vs Microsoft Store for Intune: a decision framework covering COM interoperability, kernel drivers, deployment rings, and MSIX App Attach.
Configuration as Code for Intune with Microsoft365DSC: version control, drift detection, and automated deployment via Git, without becoming a developer.
How to build a repeatable, auditable Windows estate using Intune, Autopilot, and GitOps: the foundation for Zero Trust and Copilot-ready endpoints.