Identity is the control plane, everything else is downstream
Why buying another security product rarely fixes what a weak identity design broke, and the four decisions that determine whether the rest of your controls can work at all.
Read the guideArchitecture
Design decisions from real tenant builds: identity, segmentation, monitoring and the things that break in year two.
Buying another security product rarely fixes what a weak identity design broke. Most of the incidents worth writing about trace back to an architectural decision made years earlier by someone who had no reason to think it mattered.
These are notes from real tenant builds. They are opinionated, they name the trade-off that was accepted, and they say what went wrong afterwards.
Why buying another security product rarely fixes what a weak identity design broke, and the four decisions that determine whether the rest of your controls can work at all.
Read the guideEvery tenant starts with a clean policy set. What turns it into an unauditable pile of exclusions, and the structure that prevents it.
Read the guideCompliance policy is where Zero Trust becomes real or becomes theatre. The settings that matter, and the ones that only generate support tickets.
Read the guideTwo emergency accounts excluded from every policy. How to build them so they work when you need them, and monitor them so they are not a back door.
Read the guideMergers move mailboxes and forget policy. The controls that silently do not come with you, and the window where nobody owns security.
Read the guideThey have no multi-factor authentication, no device state, frequently no owner, and permissions granted by someone who left three years ago.
Read the guideRetention decisions made on cost end up made against you during an investigation. The sources worth keeping, and the periods that actually matter.
Read the guideSubscription topology, management groups and network design get set once and inherited forever. Which choices you can revisit, and which you cannot.
Read the guidePassword hash sync, pass-through authentication and federation fail in different ways. The comparison that matters is what happens when something breaks.
Read the guideExternal collaborators accumulate, projects end, and nobody deprovisions. What a guest can actually see, and the review that fixes it.
Read the guideNothing here yet that answers your question?
Tell us what you are trying to decide and it moves up the queue. The order these get written in is driven by what people ask for.
Ask for a guide