top of page


The Security Bridge™️- Identity Threat Protection in Microsoft 365 - Part 4: How to Prove Defender XDR Can See Identity Attacks
Microsoft scored 100% on the 2024 MITRE detection evaluations, then withdrew from the 2025 edition. A license, a deployed sensor, and a strong test score describe capability, not whether your tenant will alert when it matters. Part 4 of The Security Bridge series covers Coverage and maturity scoring, the sensor health issues that quietly limit visibility, and how to validate detection instead of assuming it. For security architects, engineers, and CISOs who treat deployment a

Derek Morgan
Aug 55 min read


Defender for Identity: Detecting Lateral Movement in Hybrid Environments
A single unflagged service account and an unaudited AD trust relationship turned into a $1M, multi-forest incident. This piece is for security architects and engineers running hybrid Active Directory: how lateral movement actually happens, how Microsoft Defender for Identity detects it now that the old path map is gone, and the validation checklist to run before it happens to you.

Derek Morgan
Aug 46 min read


The Business Case for Microsoft Defender for Identity
Identity attacks don't start with malware — they start with a perfectly valid sign-in. Microsoft Defender for Identity is the monitoring and early-warning system for your organization's "control room." This article breaks down the business case: what you're buying, how it reduces identity exposure, why earlier detection compresses cost, and how identity signals correlate into unified incidents for faster response. Includes an ROI model, executive and engineer checklists, and

Derek Morgan
Apr 168 min read
Start Your Cloud Journey
bottom of page