Security Verdict
Index
Every guide, in one list
All 55 guides. Press the slash key anywhere on the site to search instead.
Tools and buyer guides21
- The Microsoft 365 backup tools worth paying forNative retention is not backup. What that actually means, what separates the products, and the seat count below which none of them are worth buying.14 min
- Zero Trust network access for teams that outgrew the VPNWhen the old concentrator becomes the bottleneck, what to replace it with, and why most Zero Trust projects stall at the identity layer rather than the network one.12 min
- Defender for Business or Defender for Endpoint P1: the honest comparisonTwo Microsoft products with overlapping licensing, a 300-seat cliff that catches people out, and a decision most organisations get wrong by exactly one tier.9 min
- Microsoft 365 email security: when the built-in tier is not enoughExchange Online Protection is included and is genuinely decent. What the paid tiers add, and the specific attack it is worth paying to stop.11 min
- Password managers for IT teams: what changes above 50 peopleThe consumer products work fine until you need provisioning, shared vaults with real boundaries, and an answer for what happens when someone leaves.10 min
- Microsoft Sentinel gets expensive fast. Here is where the money goesIngestion pricing punishes exactly the logs people connect first. What to keep hot, what to send cheap, and the settings that cut a bill without cutting detection.13 min
- Managed detection and response, or build your own SOCThe honest cost comparison, including the part vendors leave out: what a 24 hour rota actually costs once you account for people leaving.12 min
- Entra ID P1 or P2: what the extra tier actually buysP1 gives you Conditional Access. P2 gives you the ability to prove who has privilege and take it back. Which one you need depends on one question.9 min
- Microsoft 365 E3 with add-ons, or E5: the security mathsThe jump to E5 is large and the add-on route looks cheaper. Where that stops being true, and the trap of buying three add-ons.11 min
- Which MFA method to standardise onSMS is still the most deployed and the weakest. What to move to, in what order, and how to handle the people who cannot use an app.10 min
- Removing local admin rights without breaking everyoneThe highest-value endpoint control and the one most often abandoned halfway. Why it fails, and the sequence that gets it done.11 min
- Getting DMARC to enforcement without breaking your mailAlmost every domain publishes a DMARC record at p=none and stops. The path to reject, and the two sources of legitimate mail that always break it.11 min
- Defender for Cloud Apps: bought often, deployed rarelyIt is in E5, most organisations have it, and a large share have never configured a policy. What it is genuinely good at, and the two things to switch on first.10 min
- Patching the software Microsoft does not patchWindows Update covers Microsoft. The browser plugins, PDF readers and Java runtimes that get exploited are somebody else's problem, and usually nobody's.9 min
- Security awareness training: what actually reduces clicksAnnual video training does not change behaviour. What does, and why punishing people who click makes your next incident worse.10 min
- Microsoft 365 Copilot: what to fix before you turn it onCopilot inherits every permission mistake in your tenant and makes it searchable. The oversharing problem, and the work that has to happen first.12 min
- Securing Microsoft Teams external access without blocking the businessExternal access, guest access and anonymous meeting joins are three different settings that get conflated. What each one actually controls.10 min
- BYOD or managed devices: the honest cost comparisonPersonal devices look cheaper because the hardware is free. The costs are real, they are just somewhere else on the balance sheet.10 min
- Windows 365 or Azure Virtual DesktopOne is a fixed price per user, the other is infrastructure you run. The choice is about who you want owning capacity planning.10 min
- Defender for Cloud: which plans are worth enablingThe free tier does more than people realise. Which paid plans earn their per-resource cost, and which quietly do not.11 min
- Privileged access workstations: worth it or theatre?A dedicated hardened device for administrative work. When it genuinely reduces risk, and when it becomes an expensive laptop nobody uses.10 min
Certification guides13
- AZ-500 retired on 31 August 2026What happens to the certification you already hold, why it can no longer be renewed, and what SC-500 changes about the scope.7 min
- SC-500 study guide: Cloud and AI Security EngineerEvery skill area broken down, including the AI security objectives that no existing study material covers properly.18 min
- SC-200 study guide: Security Operations AnalystSentinel, Defender XDR and KQL, weighted the way the exam weights them rather than the way training courses order them.16 min
- SC-300 study guide: Identity and Access AdministratorEntra ID end to end. The exam that maps most directly to the thing that actually gets organisations compromised.15 min
- Which Microsoft security certification to take firstThere are six, they overlap, and the recommended order depends entirely on the job you do rather than on the numbering.9 min
- SC-100 study guide: Cybersecurity ArchitectAn expert-level design exam that punishes product knowledge without architectural judgement. What it actually tests, and why people who know the tools still fail it.14 min
- SC-401 study guide: Information Security AdministratorThe exam that replaced SC-400 in 2025. Purview end to end, with a heavier weighting toward data security than the exam it replaced.13 min
- AZ-104 study guide: Azure AdministratorThe most useful non-security exam in the catalogue, and a prerequisite in practice for everything that follows in Azure.14 min
- MS-102 study guide: Microsoft 365 AdministratorTenant, identity, threat protection and compliance in one exam. Broad rather than deep, and that breadth is what people underestimate.12 min
- Microsoft certification renewals: what the free assessment actually asksRole-based certifications expire annually and renew free online. What the assessment is like, when to take it, and what happens if you miss it.7 min
- AZ-305 study guide: Azure Solutions Architect ExpertA design exam that assumes AZ-104. Where the security content sits, and why administrators who know Azure well still fail it.13 min
- Is SC-900 worth taking?It depends entirely on who you are. For one group it is genuinely valuable, for another it is an afternoon that proves nothing.6 min
- Building a home lab for Microsoft security exams without a big billMost of what you need is free. What to use, what actually costs money, and how to avoid the Azure bill people get caught by.10 min
Compliance and governance11
- Mapping ISO 27001 controls to Microsoft PurviewWhich Annex A controls Purview genuinely satisfies, which it only partly evidences, and the ones your auditor will still want to see you doing by hand.15 min
- Cyber Essentials or ISO 27001: which one firstA UK-specific answer, including what each one actually costs in time rather than in certification fees, and when doing both is the wrong idea.10 min
- GDPR in a Microsoft 365 tenant: what actually needs configuringMost GDPR work is documentation, not configuration. The parts that genuinely are technical, and where Microsoft 365 helps rather than hinders.13 min
- NIST CSF 2.0 mapped to Microsoft capabilitiesThe framework everyone claims to follow. What each function means in a Microsoft estate, including the one added in 2.0 that most organisations have not addressed.13 min
- DORA for Microsoft estates: what changes if you are in scopeEU financial entities and their critical ICT providers. The obligations that translate into tenant work, and the register that catches people out.12 min
- Cyber Essentials Plus: what the audit actually checksThe self-assessment gets you the basic certificate. Plus adds a hands-on technical audit, and the failures are predictable.9 min
- Where your Microsoft 365 data actually livesTenant region, Advanced Data Residency, and the services that process outside your chosen geography regardless. The answer is more nuanced than the sales conversation.10 min
- ISO 27001 or SOC 2: which one your customers actually wantThey overlap heavily and they are not interchangeable. Which one to pursue depends almost entirely on where your customers are.11 min
- Answering security questionnaires without lyingThe 200-question spreadsheet from a prospect's procurement team. How to answer honestly, quickly, and in a way that does not commit you to something you cannot do.9 min
- Records retention that survives an auditKeeping everything forever is not caution, it is a liability. What retention actually has to prove, and why deletion is the hard part.11 min
- Insider risk management: what it actually detectsIt is not surveillance and it is not a lie detector. What the signals really are, what it catches, and the governance you need before turning it on.11 min
Architecture notes10
- Identity is the control plane, everything else is downstreamWhy buying another security product rarely fixes what a weak identity design broke, and the four decisions that determine whether the rest of your controls can work at all.11 min
- Conditional Access policies that survive year twoEvery tenant starts with a clean policy set. What turns it into an unauditable pile of exclusions, and the structure that prevents it.12 min
- Intune device compliance that people can live withCompliance policy is where Zero Trust becomes real or becomes theatre. The settings that matter, and the ones that only generate support tickets.11 min
- Break-glass accounts: the control everyone has and nobody testsTwo emergency accounts excluded from every policy. How to build them so they work when you need them, and monitor them so they are not a back door.8 min
- What breaks security during a tenant-to-tenant migrationMergers move mailboxes and forget policy. The controls that silently do not come with you, and the window where nobody owns security.12 min
- App registrations and service principals: the identities nobody reviewsThey have no multi-factor authentication, no device state, frequently no owner, and permissions granted by someone who left three years ago.11 min
- What to log, and for how longRetention decisions made on cost end up made against you during an investigation. The sources worth keeping, and the periods that actually matter.11 min
- Azure landing zones: the security decisions that are hard to reverseSubscription topology, management groups and network design get set once and inherited forever. Which choices you can revisit, and which you cannot.13 min
- Hybrid identity: which authentication method survives which failurePassword hash sync, pass-through authentication and federation fail in different ways. The comparison that matters is what happens when something breaks.11 min
- Guest accounts: the population nobody removesExternal collaborators accumulate, projects end, and nobody deprovisions. What a guest can actually see, and the review that fixes it.9 min