Identity & Entra ID (IAM)
Least-privilege access, PIM, lifecycle governance and a clean identity fabric that attackers can't walk through.
I help teams design and secure modern Microsoft and cloud platforms — from identity and endpoints to data protection and 24/7 threat detection. Zero Trust done right, without slowing your people down.
From the first sign-in to the last audit log — identities, devices, data and detections, engineered as one Zero Trust system.
Least-privilege access, PIM, lifecycle governance and a clean identity fabric that attackers can't walk through.
Phishing-resistant MFA and risk-based Conditional Access that block bad sign-ins without punishing your users.
Device compliance, app protection and hardened baselines so only healthy, managed endpoints touch your data.
Data classification, DLP, retention and insider-risk controls that keep sensitive data where it belongs.
Secure baselines, attack-surface reduction and tenant configuration mapped to CIS and Microsoft benchmarks.
Unified detection across identities, endpoints and cloud with SIEM/SOAR automation to cut dwell time.
I secure environments the way attackers try to break them. Every control maps back to a real technique, a real detection, and a measurable reduction in risk.
Verify explicitly, enforce least privilege, assume breach — applied to your real Microsoft 365 and cloud footprint.
KQL analytics tuned to the techniques that actually target M365 tenants — mapped, tested and documented.
SOAR playbooks contain incidents faster, so a compromised identity never becomes a compromised tenant.
// Flag impossible-travel + MFA fatigue SigninLogs | where ResultType == "0" | where RiskLevelDuringSignIn in ("high","medium") | summarize attempts=count(), countries=dcount(Location) by UserPrincipalName, bin(TimeGenerated,1h) | where countries > 1 and attempts > 5 | order by attempts desc
No 200-page reports that gather dust. Practical, prioritized, and built to be maintained by your team.
Deep review of your tenant, identities, devices and data flows against real-world attack paths.
Fix what matters first — identity, Conditional Access, endpoints and secure baselines.
Stand up detections in Defender & Sentinel with tuned KQL analytics and SOAR playbooks.
Measure, report and iterate — driving Secure Score up and dwell time down over time.
Security work mapped to the frameworks your auditors, customers and board already care about.
Start with a free, no-pressure Microsoft 365 security review. You'll walk away with your top risks and a prioritized action plan — whether or not we work together.