top of page


Writing Security Policies That Executives Actually Read: How to Present Your M365 Security Posture to the Board
Most security policies get written for auditors, then copied unchanged into board packets, where they go unread. This piece gives security architects and CISOs a 4-question framework for translating any M365 technical control, Conditional Access, Intune, or beyond, into a 3-line executive summary a board will actually act on. Includes 2 worked examples and a free GitHub template kit.

Derek Morgan
5 days ago7 min read


The Architecture of a Secure M365 Tenant: Layers, Dependencies, and Decisions
A Conditional Access policy that required an app protection policy nobody deployed in Intune blocked mobile users on day one. For security architects and CISOs: a 7-layer dependency model for Microsoft 365 tenant security, Cloud Harbor Consulting's 5-step build sequence for Entra ID, Intune, Conditional Access, Purview, and Defender XDR, and the verification step that closes gaps like this before they ship.

Derek Morgan
Aug 167 min read


The Security Bridge™️- Identity Threat Protection in Microsoft 365 - Part 5: The Identity Threat Protection Scorecard
Most security teams can describe what's configured, not whether they're better off than 6 months ago. Part 5 closes The Security Bridge series with a 4-dimension scorecard, prevention, detection, governance, ownership, that turns identity security into one maturity number leadership can track and fund. Includes a real budget conversation that stalled without one, and a checklist to build your own this week. For architects, engineers, and CISOs who need identity security to co

Derek Morgan
Aug 124 min read


The Security Bridge™️- Identity Threat Protection in Microsoft 365 - Part 4: How to Prove Defender XDR Can See Identity Attacks
Microsoft scored 100% on the 2024 MITRE detection evaluations, then withdrew from the 2025 edition. A license, a deployed sensor, and a strong test score describe capability, not whether your tenant will alert when it matters. Part 4 of The Security Bridge series covers Coverage and maturity scoring, the sensor health issues that quietly limit visibility, and how to validate detection instead of assuming it. For security architects, engineers, and CISOs who treat deployment a

Derek Morgan
Aug 55 min read


Microsoft Defender for Endpoint Onboarding: What They Don't Tell You in the Docs
Onboarding a device to Microsoft Defender for Endpoint turns on the sensor that sends telemetry. It does not turn on the controls that stop an attack. A device can report "healthy" while nothing blocks files on disk. For the engineers who run MDE rollouts and the leaders who fund them: the five gaps that leave a finished onboarding exposed, and the post-onboarding checklist that closes them.

Derek Morgan
Jun 25 min read


If Every Alert Is Important, None Are: Designing Security Reports That Drive Decisions
Most security teams ship two versions of every report. The 40 page export the platform makes easy. The 1 page version someone sat down and designed for a specific reader and a specific decision. This piece walks through a 4 question rubric for separating reports that drive decisions from reports that exist because they always have. Includes an audience cadence matrix, outcome metrics by audience, and a kill list of the reports that almost always fail the test.

Derek Morgan
May 266 min read
Start Your Cloud Journey
bottom of page