The long-form guides that anchor this site. Each one is a complete series written in order: the architecture and the decisions first, the build instructions underneath. Pick the product area you are working in and start at the top.

Intune Deployment Guide

The flagship. A complete guide to designing, deploying, and operating a Microsoft Intune environment, organized into thirteen phases from orientation to the Intune Suite. Windows, Mac, mobile, compliance, the device side of Conditional Access, and day-two operations.

Start the guide · Browse all Intune articles

Entra ID Deep Dive

Identity is the control plane everything else in this library depends on. Twelve articles on tenant foundations, authentication and passwordless, identity protection, PIM, governance, external identities, and monitoring. Conditional Access and Global Secure Access sit beside it on the same page as their own series.

Start the series · Browse all Entra ID articles

Conditional Access

The policy engine that decides every access request. What a framework is actually for and why the naming convention is the documentation, how to test a policy before it can lock anyone out, named locations and risk as inputs rather than decorations. Then the framework I publish and maintain: the persona and resource-tier model, the build from zip to a green prerequisite gate, the ring order that enables it without breaking a tenant, the day-one bootstrap problem, and the operating cadence that keeps exclusions from quietly becoming permanent. Nine articles: the anchor, three doctrine and five build sheets.

Start the series · Browse all Conditional Access articles

Global Secure Access

Where identity reaches the network. What Global Secure Access is and why the compliant-network signal changes what Conditional Access can promise, the product split across Microsoft traffic, Private Access and Internet Access, and the implementation. Four articles today.

Start the series · Browse all Global Secure Access articles

Defender XDR

The Microsoft Defender suite from the ground up: what your license actually turned on, the endpoint as the spine, then identity, mail, the SaaS estate, and the exposure picture underneath them all, outward toward the correlation fabric. Seven pillars are live across forty-four articles, and the series is complete.

Start the series · Browse all Defender XDR articles

Azure Arc

Extending the Azure management plane to servers anywhere, domain-joined or not: onboarding as a trust decision, policy and patching as the GPO and WSUS successors, the licensing reality including Extended Security Updates, and the decision of what belongs on Arc versus the domain.

Start the series · Browse all Azure Arc articles

Azure Files

Replacing the on-prem file server with a managed SMB share: identity now that Entra-only Kerberos is generally available, the honest risk model for reaching a share over the internet, provisioned v2 billing, Azure File Sync for the hybrid cache, migration at both estate sizes, and the backup and monitoring that make it operable. Whether to replace, cache, or keep, argued workload by workload.

Start the series · Browse all Azure Files articles

Azure Landing Zones

The subscription estate underneath everything else in this library: management groups and the starting point, governance and policy, network and DNS, identity for Azure itself, security baseline and logging, and the operating rhythm that keeps it defensible as it grows. Eight stages, each with its build sheet.

Start the series · Browse all Azure Landing Zones articles

Azure SQL

Four ways to run SQL Server with Azure in the picture, arranged on a control gradient: Azure SQL Database where the instance disappears, Managed Instance where it has to survive the move, SQL Server on an Azure VM where you need full control and will pay for it, and Arc-enabled SQL Server for what stays. Licensing decides more of the answer than architecture does.

Start the series · Browse all Azure SQL articles

Windows 365

Cloud PCs done properly. The architecture decisions, the provisioning and networking builds, restore, and a privileged access workstation pattern that treats the Cloud PC as a security boundary.

Start the series · Browse all Windows 365 articles

Governance

Where an estate stops handing out authority and starts lending it. Built in waves, starting with Privileged Identity Management: standing privilege as the risk, eligibility as the design response, the April 2026 arrival of Conditional Access enforcement on activation, and the operating loop that keeps a just-in-time estate honest. Access reviews, entitlement management, lifecycle workflows, and data governance follow in later waves.

Start the series · Browse all Governance articles

Best Practices

Best Practices is the cross-product pillar: what a defensible baseline looks like, argued rather than listed. Each series covers one product area in tiers, from the controls I will not hand over a tenant without, through the ones I would want a reason for skipping, to the ones worth a decision but not an argument. Every series ends in a terse quick checklist you can run down, with each row pointing back to the article that defends it. Twenty articles across three series, three anchors, fourteen doctrine and three build sheets. The Entra ID series covers privileged access, authentication, application and external trust, and the sequencing decisions you make once when a tenant is created. The Exchange Online series covers mail authentication end to end, the threat policies worth running, and the retirements and one-way doors that are coming on published dates. The Collaboration Apps series covers external sharing now that it runs through Entra, what to fix before Copilot makes existing oversharing legible, and the October deadline that arrives whether or not anybody did the work.

Start the series · Browse all Best Practices articles

On-Prem

The private certificate authority, designed rather than installed. The handful of decisions that are permanent from the first signature, the offline root and the single thing it actually buys, revocation treated as the distribution problem it is, the issuing CA and the templates that decide who gets to be trusted, and the maintenance calendar almost nobody produces. Doctrine and build sheet in pairs, closing where the on-premises estate meets Cloud PKI, then three companion articles on post-quantum signing, on when a second issuing CA is genuinely the answer, and on why the shrinking public certificate lifetimes are not your problem, and a closing pair on retiring an authority without taking the estate with it. Nineteen articles, eleven doctrine and eight build sheets.

Start the series · Browse all PKI articles

The second series takes the other direction: retiring the domain itself. How an SMB with a healthy hybrid reaches zero on-premises domain controllers, staged and pausable, measuring what actually pins the domain before touching anything, cutting the sync on a pilot wave you can roll back, rebuilding the devices because no in-place conversion exists, replacing files, print, certificates and Wi-Fi with what does not need a directory, working the ladder down on the one application that will not move, and the decommission itself with the go or no-go a consultant would sign. Twelve articles, one anchor, seven doctrine and four build sheets.

Start the series · Browse all AD to Azure articles

Zero Trust

Zero Trust is the strategy the rest of this library implements, and it is the one thing in here nobody can sell you. This series is its map: what Zero Trust actually is and why it is not a product, where the idea came from and where it takes you, what it changes about the working day for the people signing in and the people running the estate, and what the market honestly looks like beyond Microsoft. Four articles, the anchor and three doctrine pieces, with the deeper clusters to follow.

Start the series · Browse all Zero Trust articles

New guides are added as each series completes.