top of page
All Posts


Identity Governance Architecture: Building Lifecycle Workflows in Entra ID
When someone leaves, can you prove every one of their accounts is actually closed? Most teams can't, because offboarding runs on manual steps across Active Directory, Entra ID, and SaaS apps. This deep-dive shows security architects and the leaders who fund them how to build lifecycle workflows in Microsoft Entra ID Governance: the joiner-mover-leaver architecture, the deployment order that works, and the ROI case for automating it.

Derek Morgan
2 days ago8 min read


Microsoft Defender for Endpoint Onboarding: What They Don't Tell You in the Docs
Onboarding a device to Microsoft Defender for Endpoint turns on the sensor that sends telemetry. It does not turn on the controls that stop an attack. A device can report "healthy" while nothing blocks files on disk. For the engineers who run MDE rollouts and the leaders who fund them: the five gaps that leave a finished onboarding exposed, and the post-onboarding checklist that closes them.

Derek Morgan
Jun 25 min read


If Every Alert Is Important, None Are: Designing Security Reports That Drive Decisions
Most security teams ship two versions of every report. The 40 page export the platform makes easy. The 1 page version someone sat down and designed for a specific reader and a specific decision. This piece walks through a 4 question rubric for separating reports that drive decisions from reports that exist because they always have. Includes an audience cadence matrix, outcome metrics by audience, and a kill list of the reports that almost always fail the test.

Derek Morgan
May 266 min read


Part 1 of 3: Your Copilot Studio Agent Has An Identity. Here Is How To Govern It
Publishing a Copilot Studio agent creates an Entra identity in the same minute. As of March 18, 2026, every Copilot Studio agent in a default-on tenant gets a Microsoft Entra Agent ID: a service principal with the 'Agent' subtype, governable through the same Entra admin center and Microsoft 365 admin center your IAM team already operates. A walkthrough of what the Agent ID is, how Agent 365 governs it, the connected dual-agent pattern from a defensive SecOps PoC, and a 7-step

Derek Morgan
May 268 min read


PIM vs Service Accounts: When Privileged Identity Management is the Right Answer
Three things get called "service account" in Microsoft Entra ID. Most incidents involve only one of them. This article gives security architects and CISOs a framework for picking the right control: PIM-eligible roles for human admins, managed identities and service principals for workloads. Two diagnostic questions, four patterns, and a 5-step checklist for converting a tenant from standing privilege to a controlled model.

Derek Morgan
May 197 min read


Defender for Office 365 vs EOP — Decision Framework for Architects
Email is still the top entry point for ransomware, BEC, and credential theft. Architects choosing between Exchange Online Protection, Defender for Office 365 Plan 1, and Plan 2 have to answer one question: which tier, at what licensing cost, gets the organization to a defensible posture. This article covers what each tier does, the cost-of-breach math, and the 5 questions that decide Plan 1 versus Plan 2.

Derek Morgan
May 68 min read


The Business Case for Account Discovery in Entra ID Governance
App owners can't always answer who has access to their app right now. Mid-market enterprises run about 200 SaaS apps; large enterprises closer to 350. Account Discovery (preview) in Microsoft Entra ID Governance reads each connected app and classifies every account as Local, Unassigned, or Assigned. This post covers the business case, the three categories, and a three-phase rollout worked through SAP.

Derek Morgan
May 66 min read


Zero Trust Is Not a Product — It’s a Decision Framework (Microsoft 365 as the Reference Implementation)
Zero Trust isn’t a product—it’s a decision framework. This post explains how Microsoft 365 enforces consistent access decisions across identity, endpoints, apps, data, and unified security operations to reduce cost, risk, and improve compliance defensibility.

Derek Morgan
Apr 3010 min read


The Business Case for Microsoft Defender for Identity
Identity attacks don't start with malware — they start with a perfectly valid sign-in. Microsoft Defender for Identity is the monitoring and early-warning system for your organization's "control room." This article breaks down the business case: what you're buying, how it reduces identity exposure, why earlier detection compresses cost, and how identity signals correlate into unified incidents for faster response. Includes an ROI model, executive and engineer checklists, and

Derek Morgan
Apr 168 min read


Why Entra ID Conditional Access Fails in Practice (And How to Fix It)
I've never investigated a breach where Conditional Access failed — only where expectations did. Most CA breakdowns aren't technical. They're architectural: wrong exclusions, forgotten accounts, policies that evaluate risk but never enforce it. This article covers the four most common failure patterns — and the three-phase approach to fix them.

Derek Morgan
Apr 76 min read
Start Your Cloud Journey
bottom of page