Notes from the engagement floor.
Field notes, checklists and control matrices on Microsoft 365 security, Copilot readiness, AI governance and regulated-FinTech compliance — from the engineers doing the work. Free, no form, no gate.
Note
Six consoles, and nobody with an hour a day to check them
Microsoft 365 security is spread across six admin portals, and in one of them the record of who signed in survives seven days. Why nobody checks all six, what that quietly costs, and what a single read-only view changes.
Read it →Matrix
Microsoft Sentinel data tiers: what they cost, and what they cost you
The widely quoted Sentinel per-GB price is gone, two Microsoft pages publish different commitment ladders, and some rates cannot be found at all. What each tier costs, and which one silently turns your alerting off.
Read it →Guide
What an AI agent actually costs: seats, credits and consumption units
Microsoft prices AI in three incompatible units, and nothing is priced per agent. What a Copilot seat really zero-rates, which spend draws down your Azure commitment, and the three enforcement thresholds nobody shows you together.
Read it →Matrix
Claude in Microsoft Foundry: hosted on Azure, governed by Anthropic
Claude went GA in Microsoft Foundry hosted on Azure. That moves the silicon, not the accountability. Which four models are actually Azure-hosted, why there is no EU data zone, and where prompts go across Foundry, Copilot, Copilot Studio and GitHub.
Read it →Guide
Intune device compliance policy: the control that never blocks anything
An Intune device compliance policy evaluates a device and reports a boolean. It blocks nothing by itself. What enrolment establishes, what profiles write, which layer really denies access, and the tenant default that marks unmanaged devices compliant.
Read it →Checklist
NYDFS 23 NYCRR 500 on Microsoft 365: what the controls actually map to
Every phase of the amended NYDFS cybersecurity regulation is now in force. What Microsoft actually attests to, which Part 500 controls your licence tier can evidence, why your audit horizon is shorter than you think, and the two 72-hour clocks.
Read it →Guide
Microsoft Copilot security: what actually happens to your business data
Where a Copilot prompt goes, what is kept and for how long, what Microsoft commits to contractually, and which certifications actually name Microsoft 365 Copilot in scope — including the model-hosting change in July 2026 that most security reviews have not caught up with.
Read it →Guide
Microsoft Copilot governance: identity, data, security and compliance
Microsoft Copilot governance in practice: the two frameworks Microsoft publishes and the gap between them, which administrative roles actually hold authority, a control mapping to the NIST AI Risk Management Framework, and when to bring in help.
Read it →Checklist
A Microsoft Copilot readiness assessment you can run yourself
A Copilot readiness assessment asks three things: can Copilot run, can it see what it should, and can it not see what it should not. The first-party reports that answer each one, the exact SharePoint reports and cmdlets, and the requirement-versus-recommendation distinction most checklists get wrong.
Read it →Guide
Microsoft 365 Copilot implementation: what has to be true before you buy
A Microsoft 365 Copilot implementation is a permissions project with a licence attached. What Copilot actually inherits, which prerequisites stall pilots in week one, where the official guidance assumes an enterprise a 300-seat business does not have, and what the independent evidence says about outcomes.
Read it →Guide
Making a mailbox migration boring
Migration is one of the few operations where the failure mode is not downtime but loss. How EMaigrator removes the dangerous options from the tool — streaming pass-through, an idempotency ledger, and per-account rate coordination.
Read it →Guide
Every deploy is a commit
Three cloud consoles, three mental models, and no shared record of who changed what. How Mirsat makes the audit trail a by-product of the operation rather than a discipline someone has to maintain.
Read it →Guide
Microsoft 365 Copilot deployment: the four control planes of a secure rollout
A secure Microsoft 365 Copilot deployment is four control planes, and one of them did not exist a year ago. What Purview DLP for Copilot actually blocks, why encryption rights stop agents reading files, how agent identity changed the boundary, and where your data goes when the region is busy.
Read it →
Tell us what'skeeping you upat night.
Most engagements start with a Cloud Health Check — one week, full audit, top-10 findings, 90-day roadmap. Many turn into a longer engagement; either way, you walk away with a prioritized plan you own.