Blog & Guides
Practical cybersecurity articles, step-by-step guides, and quick-reference cheat sheets — from Active Directory hardening to Microsoft 365 and zero trust. Written by someone who's done the work. No hype, no fluff.
16 results for “security” · Clear
PowerShell for Microsoft 365 Administration: Why the GUI Isn't Enough in 2026
The Microsoft 365 admin center is fine for one user, one mailbox, one policy. It falls apart at fifty — and it cannot do half of what the platform actually supports. PowerShell is where bulk operations, security auditing, incident response and automation live, and after the 2025 retirement of the MSOnline and AzureAD modules, the tooling map has been redrawn. Here is why PowerShell administration still matters for the Microsoft 365 and security suites, which modules to use now, what the portals cannot do, and how to automate without leaving credentials lying around.
Which Microsoft 365 Plan Do I Actually Need for My Business? Basic vs Standard vs Premium in 2026
Microsoft 365 Business Basic covers email, Teams and web apps; Business Standard adds the desktop Office suite; Business Premium adds the security and device-management layer most small businesses are missing — Entra ID P1, Intune, Defender for Business and Defender for Office 365. With the July 2026 price increase now in effect and new capabilities rolling into every tier, here is what each plan actually includes, what it costs, and a decision framework for picking the right one — including when to skip the Business plans entirely and go enterprise.
Windows 10 ESU Extended to October 2027: What Changed, What It Costs, and How to Decide
Microsoft has quietly extended the Windows 10 consumer Extended Security Updates program by a full year — coverage now runs through 12 October 2027, and enrollment stays open until the program ends. But the business ESU terms have not changed: Year 2 starts in October 2026 at $122 per device, and late joiners must buy Year 1 retroactively. Here is exactly what changed, what it costs for home users and organisations, the free paths most admins overlook, and a decision framework for the October deadline.
Ghost Phishing: How the EvilTokens Campaign Hides in the Browser to Hijack Microsoft 365 Accounts
A new "ghost phishing" wave from the EvilTokens kit is slipping past email security by keeping its payload AES-encrypted until it renders in the victim's browser, then using Microsoft device-code phishing to take over Microsoft 365 accounts without ever stealing a password. This guide breaks down how the technique works, why traditional URL and email controls miss it, who is being hit, and the concrete detection and hardening steps to defend your tenant.
Microsoft 365 E3 vs E5 vs E7: A Practitioner's Guide to Choosing the Right License in 2026
Microsoft 365 E3 covers core productivity and baseline security, E5 adds the advanced security, compliance and voice stack, and the new E7 'Frontier Suite' bundles E5 with Copilot, Agent 365 and the Entra Suite for AI-driven work. This guide breaks down what each tier includes, what it costs, and how to decide which one your organisation actually needs.
Zero Trust Architecture: The Practitioner's Cheat Sheet and Implementation Guide
A complete, practical reference for Zero Trust security — the NIST SP 800-207 principles, the five CISA pillars (Identity, Devices, Networks, Applications & Workloads, Data), the four-stage maturity model, a control-by-control cheat sheet, a Microsoft-stack mapping, a phased rollout roadmap, and the mistakes that quietly undermine most deployments.
Active Directory Hardening: A Practical Step-by-Step Guide
A practitioner's guide to hardening Active Directory — the tiered admin model, privileged access hygiene, Windows LAPS, killing legacy authentication, defending Kerberos against Kerberoasting and delegation abuse, service-account hygiene with gMSA, advanced audit policy, attack-surface reduction, and the free tools that find attack paths before attackers do.