top of page
Identity and Access Management


Conditional Access Named Locations: Common Mistakes and How to Audit Them
A client's Conditional Access policy looked correct while sign-ins quietly bypassed MFA. The cause: a Named Location built from a CIDR list gone stale, entries inaccurate, missing, or pointing at ranges no longer controlled. This walks security architects and engineers through six ways Named Locations fail silently, what each costs in dwell time and false confidence, and the PowerShell and KQL checks to audit yours before an incident finds the gap.

Derek Morgan
Aug 116 min read


The Security Bridge™️- Identity Threat Protection in Microsoft 365 - Part 3: Conditional Access is a Gate, Not a Guard Dog
Conditional Access evaluates a sign-in once, then stops evaluating it. A 2025 phishing campaign confirmed a 50%+ success rate against Microsoft 365 accounts that already had MFA enabled, by capturing session tokens right after MFA succeeded. Part 3 of The Security Bridge series covers the fix: authentication strength, Token Protection, and what to validate this week. For security architects, engineers, and CISOs who assume MFA enrollment closes the risk on its own.

Derek Morgan
Jul 286 min read


The Security Bridge™️- Identity Threat Protection in Microsoft 365 - Part 2: Your Tenant Has More Identities Than Employees
Machine identities outnumber humans 109 to 1 in the average Microsoft 365 tenant, and most are ungoverned. Part 2 of The Security Bridge series breaks down why service principal ownership, not directory roles alone, is the real takeover path: how a stolen credential inherits every permission an app holds, and why 99% of tenants already have at least one privileged service principal exposed. Includes 3 real examples and a validation checklist for security architects, engineers

Derek Morgan
Jul 225 min read


The Security Bridge™️- Identity Threat Protection in Microsoft 365 - Part 1: Identity Threat Protection Starts After the Login
Most Microsoft 365 environments treat the sign-in event as the finish line for identity security. Part 1 of The Security Bridge series breaks down where the real exposure lives after a successful login: standing privilege, unmanaged token handling, and over-permissioned app access. Includes 3 examples from real client engagements and a validation checklist for security architects, engineers, and CISOs.

Derek Morgan
Jul 154 min read


The 5 Entra ID Settings Every Admin Gets Wrong
MFA is on, Security Defaults are on, the audit passed, and the tenant still has an identity-shaped gap. This walks security admins and architects through the five Entra ID settings most often left at an insecure default, plus the break-glass account people get wrong in both directions. For each one: the attack it enables, the business cost when it stays open, and the exact admin-center fix. Written for the engineer configuring it and the CISO funding it.

Derek Morgan
Jun 249 min read


Part 2 of 3: Your Pro-Code Agent Has an Identity Too. Here Is How Conditional Access Governs It
Publishing a Copilot Studio agent creates an Entra identity in the same minute. As of March 18, 2026, every Copilot Studio agent in a default-on tenant gets a Microsoft Entra Agent ID: a service principal with the 'Agent' subtype, governable through the same Entra admin center and Microsoft 365 admin center your IAM team already operates. A walkthrough of what the Agent ID is, how Agent 365 governs it, the connected dual-agent pattern from a defensive SecOps PoC, and a 7-step

Derek Morgan
Jun 197 min read


Identity Governance Architecture: Building Lifecycle Workflows in Entra ID
When someone leaves, can you prove every one of their accounts is actually closed? Most teams can't, because offboarding runs on manual steps across Active Directory, Entra ID, and SaaS apps. This deep-dive shows security architects and the leaders who fund them how to build lifecycle workflows in Microsoft Entra ID Governance: the joiner-mover-leaver architecture, the deployment order that works, and the ROI case for automating it.

Derek Morgan
Jun 178 min read


Part 1 of 3: Your Copilot Studio Agent Has An Identity. Here Is How To Govern It
Publishing a Copilot Studio agent creates an Entra identity in the same minute. As of March 18, 2026, every Copilot Studio agent in a default-on tenant gets a Microsoft Entra Agent ID: a service principal with the 'Agent' subtype, governable through the same Entra admin center and Microsoft 365 admin center your IAM team already operates. A walkthrough of what the Agent ID is, how Agent 365 governs it, the connected dual-agent pattern from a defensive SecOps PoC, and a 7-step

Derek Morgan
May 268 min read


PIM vs Service Accounts: When Privileged Identity Management is the Right Answer
Three things get called "service account" in Microsoft Entra ID. Most incidents involve only one of them. This article gives security architects and CISOs a framework for picking the right control: PIM-eligible roles for human admins, managed identities and service principals for workloads. Two diagnostic questions, four patterns, and a 5-step checklist for converting a tenant from standing privilege to a controlled model.

Derek Morgan
May 197 min read


The Business Case for Account Discovery in Entra ID Governance
App owners can't always answer who has access to their app right now. Mid-market enterprises run about 200 SaaS apps; large enterprises closer to 350. Account Discovery (preview) in Microsoft Entra ID Governance reads each connected app and classifies every account as Local, Unassigned, or Assigned. This post covers the business case, the three categories, and a three-phase rollout worked through SAP.

Derek Morgan
May 66 min read


The Business Case for Microsoft Defender for Identity
Identity attacks don't start with malware — they start with a perfectly valid sign-in. Microsoft Defender for Identity is the monitoring and early-warning system for your organization's "control room." This article breaks down the business case: what you're buying, how it reduces identity exposure, why earlier detection compresses cost, and how identity signals correlate into unified incidents for faster response. Includes an ROI model, executive and engineer checklists, and

Derek Morgan
Apr 168 min read


Why Entra ID Conditional Access Fails in Practice (And How to Fix It)
I've never investigated a breach where Conditional Access failed — only where expectations did. Most CA breakdowns aren't technical. They're architectural: wrong exclusions, forgotten accounts, policies that evaluate risk but never enforce it. This article covers the four most common failure patterns — and the three-phase approach to fix them.

Derek Morgan
Apr 76 min read
Start Your Cloud Journey
bottom of page