About
I’ve spent over a decade in the parts of enterprise IT where things quietly go wrong: the seams between on-premises and cloud, the permissions nobody cleaned up, the identity plumbing everyone assumes someone else is watching. Security engineering, hybrid cloud, and large-scale infrastructure delivery, mostly in environments where getting it wrong is expensive enough that you learn to be careful.
This site is where I write about that work. Nothing clever, nothing that only makes sense in a slide deck: just the controls that hold up under pressure, the detections you can actually read and defend at 2am, and the unglamorous discipline that separates a system you understand from one you’re just hoping is fine. I write it the way I’d explain it to a colleague who already knows the field, because that’s the only version worth reading.
Everything here stays generic and educational. Nothing refers to a specific employer, tenant, or real incident, and nothing confidential ever appears. The point is to be useful to whoever’s dealing with the same problem right now, not to talk about any one environment.
Ongoing series
- Entra Identity: Conditional Access, break-glass accounts, and getting identity hardening right without locking yourself out
- KQL Hunting: building real Sentinel detections one line at a time, from a from-zero primer up through MFA fatigue, impossible travel and beyond
- Security Copilot: the setup, permissions and capacity side that the marketing skips
Alongside the writing, I build ready-to-run prompts for the tools I use most: KQL for Sentinel and Defender, Conditional Access policy templates, Microsoft 365 PowerShell, and defensive DAX for Power BI.
This site is the home for everything. The same posts syndicate to Medium, the prompts live on PromptBase, the query packs are on Gumroad, and you can connect with me on LinkedIn.