// Blog
Writing
Notes on identity, access, and security engineering.
-
Conditional Access Without the Lockouts
How to roll out Conditional Access policies aggressively without locking yourself — or 2,000 colleagues — out of production.
-
SCIM Provisioning: The Part Everyone Forgets
Provisioning gets the demo; deprovisioning gets the audit finding. A short argument for designing the offboarding path first.
-
Designing a Conditional Access baseline you can defend
Most CA tenants drift into a tangle of overlapping policies. Here's the small baseline I use as a starting point — and the policies I deliberately do not enable on day one.
-
Joiner-Mover-Leaver, actually automated
JML programs fail because the 'mover' step is invisible. Here's the queue-driven design I use to make every lifecycle event reversible and auditable.
-
Why network segmentation still matters in a Zero Trust world
'Identity is the new perimeter' is true and incomplete. Segmentation is what keeps a compromised identity from owning everything.