Security Areas

The layers that protect the environment.

Identity & Access

Authentication, Conditional Access, MFA, identity risk, external identities, and the controls that define who can get in and under what conditions.

Privileged Access

PIM, administrative roles, separation of duties, emergency access, service accounts, and reducing standing privilege across the tenant.

Threat Protection

Defender, Safe Links, Safe Attachments, anti-phishing, threat intelligence, and the controls that detect and stop active attacks.

Endpoint Security

Intune, compliance, device risk, Defender for Endpoint, application controls, and connecting device posture to access decisions.

Data Security

Sensitivity, DLP, encryption, sharing controls, information barriers, and protecting data after identity access has already been granted.

Detection & Response

XDR, alerts, incidents, audit signals, investigation, response workflows, and making sure security telemetry leads to action.

Security Articles

Security from the field.


No Security articles have been published yet.

How I Approach Security

Start with identity, then build defense in layers.

My security approach starts with identity, access, and the actual threat surface. From there, I layer endpoint, email, collaboration, data protection, and detection controls based on risk and operational reality. The goal is not simply to enable more security features — it is to create controls that work together, generate useful signals, and can be supported when something goes wrong.