Purview Workload Content roles Entra ID are now automatically synced from Microsoft Purview into Entra, causing unexpected PIM alerts and audit log activity. This MC1199765 update creates direct role mapping between Purview and Entra ID. Here’s what’s changing, why it matters, and what you’ll see in your tenant.
Sensitivity label groups are replacing parent and child labels in Microsoft Purview. This post covers what changes, how the migration works, what Microsoft documents, what I have seen in testing and production, and why I would be careful before migrating widely adopted labels in a live environment.
A practical AI governance overview for organisations that are either rushing into AI or panicking over every new feature. This post explains why strong fundamentals, identity, device security, permissions and data protection matter more than chasing every shiny AI setting.
Blocking bring your own Copilot on work documents is something more organisations should be looking at. Microsoft allows multiple account access by default unless you explicitly block it, which means employees may be able to use personal Copilot entitlements on work files in supported Microsoft 365 apps. This post explains what BYOC is, why it matters, what Microsoft allows by default, what the…
Learn how to enable Microsoft Purview Endpoint DLP Always-On Diagnostics and simplify troubleshooting by collecting logs directly from Windows devices without user involvement. This guide covers setup, permissions, prerequisites, and how to request diagnostic logs to speed up investigations and resolve issues faster.
Struggling with DLP issues in Microsoft Purview? This guide breaks down Microsoft Purview Data Loss Prevention Diagnostics, including new endpoint diagnostics updates, built-in troubleshooting scenarios, and how to quickly identify and fix policy issues across your Microsoft 365 environment.
I had the privilege of meeting these inspiring scholars in Dallas, and their passion for technology left a lasting impression. In this feature, they share their journeys into IT, what the conference meant to them, their career ambitions, and the impact they hope to make in the next five years. Meet the scholars shaping the future of tech.
Becoming a Microsoft MVP in Security wasn’t a straight line. From rejection on April Fool’s Day to battling imposter syndrome and self-doubt, this is the honest story behind my journey into cybersecurity and the Microsoft MVP Program. No polished highlight reel - just resilience, community, Microsoft Purview, and learning to water your own grass.
Discover how to use PIM with RBAC roles to provide just-in-time access for users. Learn setup for Purview, Exchange, and more, plus the pros, cons, and gotchas.
I was recently asked if I knew a way to export Microsoft Purview RBAC roles with members. I couldn’t find a ready solution, so I wrote a PowerShell script. You can get it from my new GitHub Purview repository. Perfect for auditing and managing Purview permissions easily!
Moving Conditional Access policies from report-only to enforced mode can secure your environment - or lock everyone out. This post walks through safe rollout strategies using ring deployments, the What If tool, Policy Impact, Log Analytics, Workbooks, Gap Analyzer, and real KQL queries. Learn how to monitor, test, adjust and confidently turn policies on without breaking access or business…
Learn how to use custom security attributes in Entra ID to target apps that don’t appear in Conditional Access. This step-by-step guide covers attribute sets, names, and values, plus real scenarios like legacy authentication, persona-based targeting, and enforcing MFA. We’ll also explore cross-tenant access settings to securely trust MFA and device claims from partner tenants.
Conditional Access Essentials aren’t just about writing policies – it’s about managing real-world scenarios. In this guide, I show how to handle tricky exclusions with Temporary Access Pass (TAP) for seamless onboarding, and Identity Governance with Access Packages for secure travel and exception management. Whether you’re new to Conditional Access or already designing enterprise-grade policies,…
This instalment of Conditional Access Essentials explores authentication contexts, PIM, and securing sensitive resources. Learn how to enforce step-up MFA, apply authentication contexts to SharePoint sites, and protect privileged roles with real-world policy examples, limitations, and best practices.
Strengthen your Conditional Access strategy with practical essentials. Explore how RMAUs, Named Locations, Authentication Strengths, and Service Principals protect sensitive accounts, secure apps, and enforce the right access for every persona. Real-world guidance for building resilient, manageable policies.
Master Conditional Access with a Zero Trust, persona-based approach. Learn how to structure policies, avoid security gaps, and keep everything organised with clear naming conventions. From discovery workshops to practical use cases, this guide helps you design scalable, secure policies that work in the real world.
Discover how Microsoft Conditional Access protects your Microsoft 365, Entra, and Azure environments. Learn the essentials, explore real-world use cases, and see the art of the possible with practical examples. From securing identities to controlling device access, this guide is your starting point for mastering Conditional Access in a modern Zero Trust security strategy.
Learn how to migrate MFA and SSPR policy settings to the Authentication methods policy in Microsoft Entra before the legacy settings are retired. This guide walks IT pros through the step-by-step process, gotchas to avoid, and key recommendations to ensure a smooth and secure transition to modern authentication methods.
Company branding isn’t just about creating a visual identity - it’s a key security measure for reducing phishing risks. In this post, I dive into how configuring your Microsoft 365 login page with your company’s logo, colours, and even a recognisable background image can help users easily spot fake login pages. Spoiler: there are ducks involved, and you’ll have to read on to understand why!