Azure · Microsoft 365 · Security Operations
Practical cloud security, built for the real world.
Production-minded Azure and Microsoft 365 security walkthroughs for cloud engineers, platform teams, and security operations professionals.
Browse by focus area
Find the guidance that matches your next deployment.
Microsoft Sentinel
Architecture, ingestion, analytics, automation, governance, and SOC operations.
Microsoft Defender
Cloud, endpoint, XDR, APIs, storage, posture management, and threat protection.
Entra ID
Identity controls, MFA, legacy authentication, access governance, and Zero Trust.
Governance
Policy, compliance, change control, operational ownership, and secure cloud foundations.
KQL & Automation
PowerShell, KQL, Azure CLI, Logic Apps, playbooks, and repeatable operations.
Azure Updates
Curated Microsoft cloud releases and security changes without the search overhead.
Featured learning path
Microsoft Sentinel: from zero to an operational SOC.
Build a secure Sentinel foundation, connect data intentionally, establish analytics and governance, then automate the operational work.
Latest walkthroughs
Build, validate, and operate.
-

Protect Azure API Management APIs with Microsoft Defender for APIs
APIs often expose business logic directly to users, partners, mobile apps, and automation. When an API lacks authentication, exposes sensitive data, or carries unused legacy routes, the risk is not just infrastructure exposure; it is application behavior exposed through a managed gateway.
-

Deploy Microsoft Defender for Storage with Malware Scanning and Sensitive Data Threat Detection
Azure Storage often becomes the handoff point for partners, applications, automation jobs, exports, and user-generated files. That makes it a high-value security boundary: a malicious upload, exposed blob container, or unusual access pattern can turn a simple storage account into an incident source.
-

Microsoft Sentinel Baseline Deployment: From Zero to Operational SOC – Summer Bonus!
Microsoft Sentinel is powerful—but it can’t manage itself. Manual operations like onboarding data connectors, validating ingestion, monitoring workspace health, and auditing configuration changes quickly become a burden. This bonus article walks through building automation around your Sentinel foundations, so you can: Keep your workspaces healthy Ensure configuration compliance Alert on critical changes Free SOC engineers…
-

Microsoft Sentinel Baseline Deployment: From Zero to Operational SOC – Part 3 of 3
Sentinel does not fail because it lacks detections. It fails because alerts overwhelm analysts, automation hides context, and governance is treated as an afterthought. In this series-finale post, we establish a production operational baseline: analytics rules, incident handling, automation boundaries, and long-term governance. This is where Sentinel becomes usable—not just enabled. There is no secret…
-

Microsoft Sentinel Baseline Deployment: From Zero to Operational SOC
SIEM best practices are clear: connect data intentionally. In this post, we build a baseline ingestion strategy that prioritizes high-value telemetry, aligns with Zero Trust, and avoids the “enable everything” trap.
-

Microsoft Sentinel Baseline Deployment: From Zero to Operational SOC
Microsoft Sentinel can be enabled in minutes. A good Sentinel deployment takes planning. Most Sentinel pain does not come from missing detections or weak analytics. It comes from architectural shortcuts taken on day one: poorly scoped workspaces, uncontrolled access, unpredictable ingestion costs, and a lack of governance before the first alert ever fires. In this…
Azure Updates
Keep up without digging around.
-
Azure Updates – Number 142 – July 25, 2026
A summary update on Azure news that includes updates released from Microsoft Azure related to Azure, Architecture, Compute, Security Copilot and Sentinel…
-
Azure Updates – Number 141 – July 11, 2026
A summary update on Azure news that includes updates released from Microsoft Azure related to Azure, Architecture, Compute, Security Copilot and Sentinel…
-
Azure Updates – Number 140 – June 27, 2026
A summary update on Azure news that includes updates released from Microsoft Azure related to Azure, Architecture, Compute, Security Copilot and Sentinel…
Technical guidance with an operational point of view.
Andrew has worked in IT since 2001 and focuses on Azure, Microsoft 365, cloud security, migrations, and automation.