Microsoft 365 & Cloud Security

Lock down your Microsoft 365 tenant. Sleep better at night.

I help teams design and secure modern Microsoft and cloud platforms — from identity and endpoints to data protection and 24/7 threat detection. Zero Trust done right, without slowing your people down.

Zero Trust architectureReduced MTTD / MTTRKQL detection engineering
the365nerd mascot — a friendly Microsoft 365 security expert
0
of breaches start with identity
0
detection & monitoring mindset
0
compliance frameworks aligned
0
clouds secured: M365, Azure, AWS
What I do

Security that covers your whole Microsoft 365 estate

From the first sign-in to the last audit log — identities, devices, data and detections, engineered as one Zero Trust system.

Identity & Entra ID (IAM)

Least-privilege access, PIM, lifecycle governance and a clean identity fabric that attackers can't walk through.

Entra IDPIMRBAC

Conditional Access & MFA

Phishing-resistant MFA and risk-based Conditional Access that block bad sign-ins without punishing your users.

MFARisk policiesPasswordless

Intune & Endpoint

Device compliance, app protection and hardened baselines so only healthy, managed endpoints touch your data.

IntuneComplianceMDM/MAM

Microsoft Purview

Data classification, DLP, retention and insider-risk controls that keep sensitive data where it belongs.

DLPSensitivity labelsCompliance

Security Hardening

Secure baselines, attack-surface reduction and tenant configuration mapped to CIS and Microsoft benchmarks.

BaselinesASRSecure Score

Defender XDR & Sentinel

Unified detection across identities, endpoints and cloud with SIEM/SOAR automation to cut dwell time.

SIEM/SOARKQLAutomation
The approach

Threat-informed defense, not checkbox security

I secure environments the way attackers try to break them. Every control maps back to a real technique, a real detection, and a measurable reduction in risk.

  • Zero Trust across identities, endpoints & workloads

    Verify explicitly, enforce least privilege, assume breach — applied to your real Microsoft 365 and cloud footprint.

  • MITRE ATT&CK-informed detections

    KQL analytics tuned to the techniques that actually target M365 tenants — mapped, tested and documented.

  • Automation that shrinks MTTD & MTTR

    SOAR playbooks contain incidents faster, so a compromised identity never becomes a compromised tenant.

detect-risky-signin.kql
// Flag impossible-travel + MFA fatigue
SigninLogs
| where ResultType == "0"
| where RiskLevelDuringSignIn in ("high","medium")
| summarize attempts=count(),
    countries=dcount(Location)
    by UserPrincipalName, bin(TimeGenerated,1h)
| where countries > 1 and attempts > 5
| order by attempts desc
How we work

A clear path from exposed to resilient

No 200-page reports that gather dust. Practical, prioritized, and built to be maintained by your team.

Assess

Deep review of your tenant, identities, devices and data flows against real-world attack paths.

Harden

Fix what matters first — identity, Conditional Access, endpoints and secure baselines.

Monitor

Stand up detections in Defender & Sentinel with tuned KQL analytics and SOAR playbooks.

Improve

Measure, report and iterate — driving Secure Score up and dwell time down over time.

Aligned to what matters

Compliance-ready by design

Security work mapped to the frameworks your auditors, customers and board already care about.

NIST CSFISO 27001GDPRHIPAACIS BenchmarksMITRE ATT&CKMicrosoft Zero Trust
Ready when you are

Let's find the gaps before attackers do

Start with a free, no-pressure Microsoft 365 security review. You'll walk away with your top risks and a prioritized action plan — whether or not we work together.