Guide
Entra ID
Identity is the control plane that everything else in this library depends on. The Entra ID series walks the platform from tenant foundations to governance: how identities get in, how they authenticate, how risk is measured, how privilege is granted and reviewed, and how you watch all of it. Conditional Access follows as its own series, because the policy engine that decides every access request needs more room than a chapter inside another guide. Global Secure Access closes the page, where those same policies reach the network. Each series is written to be read in order.
Entra ID Deep Dive
12 articles
Entra ID in 2026: Getting Started and the Baseline You No Longer Set
Microsoft has moved the Entra ID security baseline from recommendations you implement to a floor it enforces. Getting started in 2026 is knowing what is already switched on, and deciding everything the floor does not: privilege, structure, break-glass done the new way, and access that expires.

Identities and How They Get There
Every account arrived from somewhere, and where it came from decides where you can change it. Source of authority, the three origins of an identity, the Connect-Sync-to-Cloud-Sync transition now underway, and the slow migration of authority to the cloud.

Tenant Foundations and the Shape of the Directory
The shape of a directory is decided before the first policy and ages badly when improvised. One tenant or several, the population-versus-entitlement group model, and the restricted management administrative unit that protects your core from your own administrators.

Authentication Methods and the Road to Passwordless
Authentication is becoming a ranking the system enforces, steering every user to their strongest credential and asking for the password only when nothing better exists. One policy, system-preferred authentication, registration as the real work, and retiring the weak on purpose.

Passkeys, WHfB, and Phishing-Resistant Credentials
A small portfolio of phishing-resistant credentials, held one device-bound and one portable, chosen deliberately.

Identity Protection: Risk as a Signal
A strong credential proves who is signing in; it cannot prove the sign-in is safe. Identity Protection is the sensor for that gap, and its value depends on being honest about what a risk engine can and cannot see.

Privileged Identity Management in Depth
Privilege is the one thing you want people to have and not hold. PIM separates being entitled to a role from possessing it, so power is reached for deliberately, briefly, and on the record.

Roles, Custom Roles, and Delegated Administration
Delegation is giving people exactly the authority their job requires and not a scrap more, because the width of a role assignment is the width of a breach.

Entitlement Management: Access as a Governed Object
Most access is granted by hand and never taken back. Entitlement management turns access into a governed object with a requester, an approver, a reason, and an expiry.

Access Reviews and Lifecycle Workflows
Access is not an event, it is a lifespan. Access reviews and lifecycle workflows make provisioning, recertification, and deprovisioning something the platform runs rather than something people remember to do.

External Identities: B2B, Cross-Tenant Access, and Direct Connect
Bringing an outsider into your directory is a trust decision wearing the clothes of a convenience feature. External identity is deciding how much of someone else's security posture you will inherit as your own.

Watching Identity: Sign-in Logs, Audit, and Health
Every control produces a record, and a control whose record no one keeps is one you are only assuming works. Watching identity turns the directory's exhaust into something you can alert on and answer questions with later.
Conditional Access
9 articles
Conditional Access: The Real Control Plane
Why Conditional Access Matters More Than Any Single Policy

Conditional Access Frameworks and Policy Design
Once you accept that Conditional Access is the real control plane, the next question is how to organize it, and this is where most…

Testing Conditional Access: What-If Analysis and Safe Rollout
Two instruments make a Conditional Access change safe: What If for a single hypothetical, and report-only for the whole population. How to use both, read the four report-only results, and promote a policy to enforcement without locking anyone out.

Named Locations, Risk Policies, and Identity Protection
Device compliance and authentication strength are the most common inputs to Conditional Access policies. They're not the only ones. Named locations, sign-in risk, user…

The VCIO CA Framework
Earlier this year I sat down and took apart the published Conditional Access baselines the way I'd audit a customer tenant. Every policy definition…

Building the Framework: From Zip to Green Gate
The design paper made the case. This is the part where you actually stand up the framework in a tenant, and it is where…

Enabling in Rings: An Order That Doesn’t Break Things
At the end of the build you have a tenant full of Conditional Access policies that do nothing. Every one of them is in…

Day One: TAP, Autopilot, and Protecting the Bootstrap
Most of a Conditional Access deployment is about people who already exist. The harder problem, and the one baselines almost never address, is the…

Operating the Framework: Exclusions, Reviews, and Drift
A Conditional Access framework is not a project you finish, it is a system you operate. The reviews, the break-glass test nobody wants to run, the monthly drift check, and the change discipline that keeps a snapshot true a year later.
Global Secure Access
4 articles
Global Secure Access: Identity at the Network Edge
For years the network and the identity were governed separately, and the seam between them was where attackers lived. Global Secure Access closes that seam by making the network path itself something the identity system authorizes.

Paying for the Edge: Licensing Without the Fog
Global Secure Access licensing follows the traffic forwarding profile, which makes the whole model easier to reason about than the SKU list suggests. Here is what each profile costs, what the free tier really includes, and the three meters that are not on the price page.

The Microsoft Profile and Conditional Access: The Cheapest Security Win You Own
The compliant network check turns network position into something your identity system asserts rather than something you maintain a list of. It is included with the licence you already hold, and it stops at a boundary that shapes every decision later in this series.

Build Sheet: The Microsoft Profile and the Compliant Network Policy
From a tenant with nothing to an enforced compliant network Conditional Access policy, with the client packaged, the co-requisite device settings deployed, every exclusion argued for, and an end-to-end test that proves the block instead of assuming it.



