Field notes on Microsoft 365 security
Practical articles on auditing and securing your Microsoft environment — connectors, methodology, misconfigurations and compliance.
FedRAMP and Microsoft 365: auditing identity for federal cloud data
How the FedRAMP Low, Moderate and High baselines map onto Entra ID and Microsoft 365 configuration, and how to audit the identity controls.
Read article → SecurityAuditing Conditional Access: the policy gaps that matter
A practical checklist for auditing a Conditional Access estate in Entra ID — coverage, exclusions, and the gaps that quietly undo MFA.
Read article → SecurityGolden SAML and federation trust: the attack path your audit must cover
How the Golden SAML attack works against federated Entra ID, what an audit looks for, and why read-only simulation is the safe way to test it.
Read article → SecurityAttack simulation vs penetration testing: what a read-only simulator tells you
The difference between a penetration test and a read-only attack simulation, and where each fits in a Microsoft 365 security program.
Read article → ComplianceCJIS Security Policy 6.0 on Microsoft 365: auditing for criminal-justice agencies
How CJIS Security Policy 6.0 maps onto Entra ID and Microsoft 365 now that it aligns to NIST SP 800-53, and what evidence an assessor accepts.
Read article → SecurityAuditing privileged access: PIM, standing admin and just-in-time
How to audit privileged access in Entra ID — counting standing admin, what good PIM looks like, and the roles beyond Global Administrator.
Read article → MSPRunning Microsoft 365 security at scale: the multi-tenant MSP playbook
How MSPs run Microsoft 365 and Entra ID security across dozens of tenants profitably — house baselines, recurring cadence, and packaging.
Read article → SecurityToken theft and session hijacking: what to harden in Entra ID
Why token theft sidesteps MFA, and the Entra ID controls — phishing-resistant MFA, token protection, device compliance — that reduce the exposure.
Read article → ComplianceSOC 2 or ISO 27001 for your Microsoft tenant: where the evidence overlaps
How SOC 2 and ISO 27001 ask the same questions of your Entra ID and Microsoft 365 configuration, and how to audit the tenant once for both.
Read article → MSPPackaging and pricing Microsoft 365 security assessments as an MSP
How to turn a Microsoft 365 security assessment into a repeatable, profitable MSP service line — tiers, pricing anchors, and low-cost delivery.
Read article → MethodologyInstall and customize EntraGUARD: from setup to white-label
Step-by-step: install EntraGUARD on a workstation (even shared), then make it yours — white-label branding, per-tenant logos, offline licence, themes.
Read article → MSPThe Microsoft 365 security assessment checklist for MSPs
A repeatable checklist for MSPs running Microsoft 365 and Entra ID security assessments across multiple clients, and how to package it as a service.
Read article → ComplianceHIPAA and Microsoft 365: auditing the technical safeguards
How the HIPAA Security Rule's technical safeguards map to Entra ID and Microsoft 365 configuration, and how to evidence them.
Read article → ComplianceCMMC and NIST SP 800-171: auditing Microsoft identity for defense contractors
How the access control and authentication requirements of NIST SP 800-171 and CMMC map to Entra ID and Microsoft 365 configuration.
Read article → ComplianceMicrosoft 365 security audit for SOC 2 compliance
How a Microsoft 365 and Entra ID security audit produces the technical evidence auditors ask for under SOC 2 Trust Services Criteria CC6 and CC7.
Read article → ComplianceSecurity audits for NIS2 and ISO 27001 compliance
How a Microsoft 365 and Entra ID security audit supports NIS2 and ISO 27001 compliance with defensible, documented evidence.
Read article → SecurityTop 10 Entra ID misconfigurations to fix first
The ten most common and most dangerous Microsoft Entra ID misconfigurations, why they matter, and how to remediate each one.
Read article → MethodologyCustom baselines: adapting the audit to your context
How to build custom baselines in EntraGUARD: exclude irrelevant controls, adjust criticality, and make the compliance score reflect your real requirements.
Read article → MethodologyEntra ID audit vs Microsoft Secure Score: the differences
Microsoft Secure Score is useful but limited. Here's how a dedicated Entra ID and Microsoft 365 audit goes deeper, with a real action plan.
Read article → MethodologyUnderstanding the weighted compliance score (L1/L2)
Why a weighted compliance score reflects real risk better than a simple pass ratio, and how EntraGUARD weights level 1 and level 2 controls.
Read article → MethodologyThe 318 controls explained: CIS, ANSSI, NIST and ISO 27001
How EntraGUARD's 318 automated controls map to CIS, ANSSI, NIST and ISO 27001, and why framework alignment makes an audit defensible.
Read article → ConnectorsHow to configure the Entra ID connector: every authentication method explained
Set up the EntraGUARD Entra ID connector step by step: automatic provisioning, certificate vs client secret, and the read-only Graph permissions required.
Read article →