Microsoft 365 · Entra ID · Intune · Security

Microsoft 365 Security

Practical guidance for IT teams managing Entra ID, Intune, and Conditional Access.

  1. Donny van Huizen 23 min read Blog

    Unmanaged Devices with Microsoft Intune (1/3): Windows

    Windows BYOD with Intune has three distinct paths. Most organizations configure the wrong one. MAM, MDM enrollment, Conditional Access, and the enrollment pitfalls clients hit in practice.

    byodwindowsintunemammdmconditional accessunmanaged devicesendpoint management
  2. Danny Vorst 13 min read Blog

    Social Engineering Exposed (3/3): Defence That Works

    MFA alone won't stop a helpdesk attack. Here's what actually does: the process changes, Entra ID settings, and monitoring that holds up under pressure.

    securitysocial engineeringconditional accessmfaentra idmicrosoft 365
  3. Danny Vorst 13 min read Blog

    Shadow AI Exposed (1/2): What organizations don't know about the AI tools their employees use

    Most shadow AI incidents start with a legitimate task. What actually ends up in those tools, why security controls miss it, and what the NSW government breach tells us.

    securityshadow aiai governancemicrosoft 365data protection
  4. Donny van Huizen 17 min read Blog

    How to configure Intune compliance policies: step-by-step guide for all platforms

    Configure Microsoft Intune compliance policies for Windows, macOS, iOS, and Android. Includes recommended settings per platform, Conditional Access wiring, report-only testing, and monitoring.

    microsoft intuneendpoint compliancecompliance policiesconditional accessmdmdevice managementmicrosoft 365endpoint security
  5. Donny van Huizen 7 min read Blog

    Intune compliance policies: what they actually change in your organization

    Most organizations running Microsoft 365 have devices connecting without any enforced security requirements. Intune compliance policies close that gap, and the impact goes further than the security team.

    microsoft intuneendpoint compliancecompliance policiesconditional accessdevice managementmicrosoft 365endpoint security
  6. Danny Vorst 13 min read Blog

    Social Engineering Exposed (2/3): The Helpdesk Attack

    Attackers don't break MFA. They call your helpdesk and get it reset. Here's what that looks like in Entra ID, and why most tenants aren't built to catch it.

    securitysocial engineeringhelpdeskmfaentra idmicrosoft 365
  7. Danny Vorst 15 min read Blog

    Shadow AI in Microsoft 365: Find and Block It with Purview

    Shadow AI leaks data without triggering a single alert. Use Entra Internet Access, Defender for Cloud Apps, and Microsoft Purview to find and block it in 4 steps.

    securityshadow aimicrosoft purviewdefender for cloud appsentra id
  8. Donny van Huizen 13 min read Blog

    Intune MDM vs MAM: When to use which approach

    MDM controls the device, MAM controls the data. A decision matrix for IT admins, including the June 30 Conditional Access deadline you can't miss.

    intunemdmmambyodmicrosoft 365conditional accessmobile security
  9. Danny Vorst 7 min read Blog

    Social Engineering Exposed (1/3): How attackers get in without breaking anything

    MGM lost $100M. Odido lost 6.2M records. Uber's systems went dark. None required a technical exploit. Just a phone call. Here's how it works.

    securitysocial engineeringidentity securitymfaphishingmicrosoft 365