Turning on MFA is the easy part. Getting Conditional Access right — without locking yourself out — is the actual work.
Security, identity, AI
I write about security, identity, and the strange, useful edges of AI.
I'm a Microsoft 365 consultant — identity, security and compliance, and the practical side of rolling out Copilot and other AI tools. This is where I think out loud about it.
Most of what's here started as something I had to work out properly myself: a policy with no clean explanation anywhere, a rollout that could have gone wrong, a check I wanted to run and couldn't. The write-ups and the tools are the result.
I hold Microsoft certifications in information protection and compliance (SC-400) and Microsoft 365 administration (MS-102), with applied skills in securing AI in the cloud. I'm also dyslexic — a lot of how I explain this comes from needing to make it make sense to myself first.
What I'm thinking about
Most incidents aren't clever. They're a legacy protocol nobody turned off, or a service account with a password from 2019.
The interesting question isn't whether Copilot can draft the email. It's what happens to everything it read to do it.
An interactive Conditional Access Policy Builder — plain-English input, live Microsoft Graph-style JSON out.
Open the builder →A private, browser-only readiness check across data, identity, governance, agents and human oversight.
Check your readiness →Build correct SPF, DKIM and DMARC records and a staged path from monitoring to enforcement.
Open the builder →The tools are the same instinct, made clickable — the thing I wanted to exist while I was working it out.
Writing
I write about identity, security, and where AI fits in — usually working something out in public rather than reporting back once it's tidy.
Longer writing lives at the blog, hosted here rather than anywhere else.
Say hello
I'm on LinkedIn — happy to talk identity, security, compliance, or where AI fits into any of them.