Tenant architecture, Entra ID, conditional access, licensing, and governance.
10 articles
A default member in Entra ID can enumerate the whole directory: every user, group, service principal and role assignment. The controls that narrow it.
Control M365 add-on costs: a five-question framework for Intune Suite, Entra ID Governance, Copilot, and Purview, plus a PowerShell audit script.
What an M365 Solution Architect actually does: standards ownership, security architecture, licensing strategy, and delivery oversight. Beyond diagrams.
Compare Intune security baselines against CIS benchmarks with a PowerShell export-and-diff workflow: ASR deployment and deviation tracking included.
M365 E3 vs E5 decision framework for architects: TCO breakpoints, cost comparison scripts, and the rule for when E5 actually beats E3 plus add-ons.
Microsoft 365 tenant health audit checklist: detect orphaned groups, expired app secrets, CA policy sprawl, and SharePoint chaos with Graph API scripts.
A baseline Conditional Access policy set built from 20 deployments: common mistakes, circular dependencies, and the patterns that survive production.
Production-ready PowerShell scripts for M365 tenant assessment via Graph API: discovery, identity auditing, security posture, governance, licensing.
Automated M365 licensing audit using Graph API and PowerShell: find unused Copilot seats and reclaim licences from disabled accounts still on E5.
A practical look at Microsoft's Global Secure Access SSE solution: what it does, how it works, and where it fits in a zero-trust architecture.