Aaron

Aaron

[5.5] Updates: Autopatch as Default, Rings as the Alternative.

Patch management has a reputation for being a maintenance task. In a cloud-managed environment it’s a security control – and the distinction matters for how you design it. Devices that aren’t current aren’t just inconvenient. They’re non-compliant, and non-compliant devices…

[5.2] Configuration Profiles and the OIB Approach

The previous article established why Microsoft’s monolithic baselines create operational friction and introduced the two policy surfaces – Configuration Profiles and Endpoint Security – as distinct tools doing different jobs. This article focuses on the Configuration Profiles layer and how…

[1.0] What Intune Is (and What I Had to Re-Anchor)

The instincts I relied on for years still worked – just enough to be misleading. I didn’t come into Microsoft Intune green. I came into it with years of experience managing Windows devices in environments where authority was clear, timing…

[1.1.3] Naming, Scope, and Assignment Discipline

Once configuration is separated into modular policies, the next problem is obvious: how do you keep that structure understandable six months from now, when you’re not the only one looking at it? Intune doesn’t give you hierarchy. It gives you…

[1.1.2] Why I Design Baselines in Modular Sections

Microsoft’s security baselines exist for a good reason. The intent behind them is solid – consolidate recommended settings, reduce decision fatigue, give teams a defensible starting point. On paper, that’s exactly what a baseline should do. Where I’ve found consistent…

[1.3] Why the Trust Model Changed

The move to cloud management didn’t just change where policy lives. It changed what trust means and how it’s established. In a traditional model, trust is largely implied. A device is joined to the domain. It sits on the corporate…