Engineering the
Modern Workplace
Deep dives into Microsoft Intune, Azure Automation, PowerShell scripting, Exchange Online and M365 security hardening — written by practitioners, for practitioners.
Featured Articles
View all →Mastering Autopilot Device Preparation (Autopilot v2): Enterprise Setup, ESP Fixes & Architecture
An exhaustive, field-tested engineering guide to implementing Microsoft Intune Autopilot Device Preparation (Autopilot v2), featuring v1 vs v2 architecture, Service Principal ownership, Win32 App packaging, ESP reboot loop fixes, and KQL log analytics.
EntraPhishing-Resistant Authentication: Deploying FIDO2 Passkeys & Conditional Access Auth Strength in M365
An exhaustive engineering blueprint for eliminating adversary-in-the-middle (AiTM) phishing attacks by enforcing FIDO2 Passkeys, AAGUID attestation restrictions, Temporary Access Pass (TAP), and Conditional Access Authentication Strengths.
M365Securing Microsoft 365 Copilot & LLM Data Governance: Purview Information Protection & Agent Guardrails
An exhaustive technical blueprint for securing enterprise data before deploying Microsoft 365 Copilot, featuring Purview Information Protection, Restricted Access Control (RAC), SharePoint audit scripts, and Copilot Interaction audit logging.
Latest Posts
View all →Elevating Azure & M365 Management: Azure Copilot Unlocks Direct Agent Access for Architects
Azure Copilot now offers direct access to specialized AI agents, empowering M365 & Azure architects with accelerated, task-specific management for cost, security, Intune, and more.
IntuneMastering Autopilot Device Preparation (Autopilot v2): Enterprise Setup, ESP Fixes & Architecture
An exhaustive, field-tested engineering guide to implementing Microsoft Intune Autopilot Device Preparation (Autopilot v2), featuring v1 vs v2 architecture, Service Principal ownership, Win32 App packaging, ESP reboot loop fixes, and KQL log analytics.
EntraPhishing-Resistant Authentication: Deploying FIDO2 Passkeys & Conditional Access Auth Strength in M365
An exhaustive engineering blueprint for eliminating adversary-in-the-middle (AiTM) phishing attacks by enforcing FIDO2 Passkeys, AAGUID attestation restrictions, Temporary Access Pass (TAP), and Conditional Access Authentication Strengths.
M365Securing Microsoft 365 Copilot & LLM Data Governance: Purview Information Protection & Agent Guardrails
An exhaustive technical blueprint for securing enterprise data before deploying Microsoft 365 Copilot, featuring Purview Information Protection, Restricted Access Control (RAC), SharePoint audit scripts, and Copilot Interaction audit logging.
M365M365 Next-Gen Sharing: Secure by Default, Governed by Design
Microsoft 365's new sharing experience is here, fundamentally changing how files and folders are shared. As M365/Intune engineers, understanding this shift to a 'secure by default' model is critical for robust data governance and external collaboration, driven by Entra ID, Purview, and granular SharePoint controls.
TeamsMicrosoft Teams: App centric management in Teams Admin Center to manage the Apps access for tenants, end-users, and groups in GCC High
For years, managing Microsoft Teams app access in GCC High felt like navigating a labyrinth built on layers of App Permission Policies. Global policies, custom policies, user assignments – it was a complex beast, espe...
AzureGA: Pre-upgrade Validation Checks for Azure PostgreSQL Flexible Server
Microsoft has made pre-upgrade validation checks generally available for Azure Database for PostgreSQL Flexible Server, letting you catch breaking changes before committing to a major version upgrade.
AzurePublic Preview: Markdown for Agents in Azure App Service
Azure App Service now supports Markdown rendering for AI agents in public preview, letting LLM-backed apps deliver clean, formatted responses natively.
M365OneNote Copilot Notebooks for Gov Clouds: Persistent AI Workspaces
Explore the new Copilot Notebooks design in the Microsoft 365 Copilot app, now rolling out for DoD, GCC, and GCC High. This deep dive covers compliance, prerequisites, and technical implementation for persistent AI-driven context aggregation.