Articles

vcio-ca-framework

[CA 4] The VCIO CA Framework

Earlier this year I sat down and took apart the published Conditional Access baselines the way I’d audit a customer tenant. Every policy definition at the JSON level, every group reference resolved, every grant control checked against what it actually…

[5.1.2] CIS Level 1 vs Level 2 in an Intune World

CIS Level 1 and Level 2 are profiles, not difficulty tiers. A practitioner's view of what the distinction means, what it takes to operationalize either in Intune, and how the available options - Microsoft baselines, build-your-own, and OpenIntuneBaseline - actually compare.

[7.1.2] Microsoft 365 Apps: Channels and Configuration

Deploying Microsoft 365 Apps through Intune is straightforward. The channel decision is not. It determines how often your users get new features, how long security updates are supported, and how much testing overhead your team carries. Get it right once…

[6.1.1] Building Compliance Policies in Practice

Compliance policies are the bridge between Intune configuration and Conditional Access enforcement. Before you build individual policies, two tenant-wide settings need to be set correctly – and most environments have them wrong by default. Tenant-wide compliance settings first In Intune,…

[5.3.2] ASR Rules: Staged Enforcement From Audit to Block

ASR rules are one of the highest-value security controls available in a Microsoft Defender environment. They’re also one of the easiest ways to break legitimate applications if you deploy them without understanding what you’re doing. The staged approach – Audit,…