Aaron

Aaron

[2.1.3] Licensing

Licensing conversations in Microsoft environments are uncomfortable because they’re usually happening at the wrong time – after someone has already designed a deployment around capabilities that turn out to require a higher license tier than the organization has. This article…

[1.1.1] How Intune Evaluates Configuration Profiles

Understanding how Intune actually processes and evaluates configuration profiles changes how you design them. Not just conceptually – it changes specific decisions about how many profiles to create, how to structure assignments, and how to troubleshoot when something doesn’t apply…

[7.2] Packaging Models: Win32, LOB, MSIX, and When to Use Each

Intune supports multiple application packaging models and the choice between them is consequential. Not because one is universally better, but because each model makes different assumptions about installer behavior, detection capability, and deployment reliability – and choosing wrong produces failures…

[6.2] Designing Compliance Rules That Mean Something

The most common compliance policy failure I see isn’t misconfiguration – it’s compliance theater. Rules that look thorough on paper but don’t actually reflect meaningful trust requirements. Environments where the compliance dashboard is green, but the signal feeding Conditional Access…

[5.5] Updates: Autopatch as Default, Rings as the Alternative.

Patch management has a reputation for being a maintenance task. In a cloud-managed environment it’s a security control – and the distinction matters for how you design it. Devices that aren’t current aren’t just inconvenient. They’re non-compliant, and non-compliant devices…