Security Fundamentals

DNS, encryption, MFA, threat modelling

An illuminated security keypad mounted on a wall, representing deliberate access control

Least Privilege in Practice: Standing Access, Scope and Just-in-Time

Everybody in IT can define least privilege. Give every identity the minimum access needed to do its job, and no more. It appears in every security policy, every framework, and every interview answer. Almost nobody implements it properly. That is not because the principle is hard to understand. It is because the principle is free […]

Least Privilege in Practice: Standing Access, Scope and Just-in-Time Read More »

A pile of metal keys on a dark surface, representing access accumulated across a career

Joiners, Movers and Leavers: Why Movers Break Your Permission Model

Every organisation has a joiners, movers and leavers process. Almost none of them run all three legs. The joiner leg gets done well, because somebody is standing in reception on Monday morning unable to work, and that failure is loud, immediate and embarrassing. The leaver leg gets done adequately, because HR chases it, because there

Joiners, Movers and Leavers: Why Movers Break Your Permission Model Read More »

Rows of old file folders in a dimly lit archive room, representing content nobody ever navigates to

Agent Access and the Permissions You Forgot You Granted

Every competent person running a Microsoft estate already knows the permissions are wrong. They do not need a tool to tell them that. Ask anyone who has administered SharePoint for more than a couple of years whether there is content in the tenant reachable by people who have no business reaching it, and you will

Agent Access and the Permissions You Forgot You Granted Read More »

Scroll to Top