top of page
Threat Detection & Response


The Security Bridge™️- Identity Threat Protection in Microsoft 365 - Part 4: How to Prove Defender XDR Can See Identity Attacks
Microsoft scored 100% on the 2024 MITRE detection evaluations, then withdrew from the 2025 edition. A license, a deployed sensor, and a strong test score describe capability, not whether your tenant will alert when it matters. Part 4 of The Security Bridge series covers Coverage and maturity scoring, the sensor health issues that quietly limit visibility, and how to validate detection instead of assuming it. For security architects, engineers, and CISOs who treat deployment a

Derek Morgan
Aug 55 min read


Defender for Identity: Detecting Lateral Movement in Hybrid Environments
A single unflagged service account and an unaudited AD trust relationship turned into a $1M, multi-forest incident. This piece is for security architects and engineers running hybrid Active Directory: how lateral movement actually happens, how Microsoft Defender for Identity detects it now that the old path map is gone, and the validation checklist to run before it happens to you.

Derek Morgan
Aug 46 min read


Microsoft Defender for Cloud Apps: Governance Policies That Actually Work
Most Microsoft Defender for Cloud Apps deployments turn on Cloud Discovery and stop there. This piece walks security architects and engineers through the four MDCA policy layers that actually enforce governance, the build order that avoids alert fatigue, and the file-policy retirement (January 6, 2027) that changes where new governance work belongs. Includes the client trap that turns Cloud Discovery data into noise, and the CFO-ready business case for fixing it.

Derek Morgan
Jul 215 min read
Start Your Cloud Journey
bottom of page