Tiering fails as a diagram and succeeds as an enforcement mechanism. This is the dependency order that decides which one you end up with.
Article collection
Microsoft security and governance
Security architecture, operations and governance guidance across Microsoft identity, Defender, Sentinel and Purview.
Published guidance
ASR rules block the behaviours malware relies on — and some of the behaviours a twenty-year-old line-of-business application relies on. Audit mode is the entire deployment strategy.
Auto-enrolment fails silently until certificates expire and authentication breaks. A read-only script that finds the certificates about to lapse, tests the certification authorities and reports who actually holds enrol rights.
A policy set that works in a demo tenant and locks out a real organisation is the normal outcome. Report-only mode, exclusion design and a deliberate rollout order prevent it.
Two products that overlap enough to confuse the boundary. Defender XDR covers the Microsoft estate; Sentinel is for everything else and for correlation across it.
Delegated and application permissions are not two settings on the same dial. One is bounded by the signed-in user and one is not, and the difference decides your exposure.
An agent acting on a user's behalf inherits that user's access, including everything they could reach but never did. The oversharing problem stops being theoretical.
Three delegation models, one of which should not exist in your directory any more. The differences decide who can impersonate whom, and who gets to configure it.
An Owner who cannot read a secret, a firewall that looks open, and a private endpoint resolving to the wrong address all produce the same status code. A script that separates them.
Enforcing LDAP signing and channel binding is a five-minute change that breaks printers, scanners and appliances nobody documented. A script that finds them first, from the domain controllers' own evidence.
Audits, incidents and reviews all ask the same questions about a tenant. Collecting the answers the same way every time turns an ad-hoc scramble into a comparable record.
Classification tells you where sensitive data is. It does not reduce who can reach it. Deploying labels over broken permissions produces an accurate map of a problem you still have.
NTLM is deprecated, NTLMv1 is already removed from the newest Windows releases, and nobody has an inventory. A read-only script that collects what is actually authenticating with NTLM, from the machines that know.
Two distinct protections with overlapping names, both now on by default in recent Windows. Knowing which one blocks which attack tells you what remains exposed.
A read-only assessment that collects privileged membership, delegation, stale accounts and password policy exposure — and changes nothing, deliberately.
The defaults optimise for collaboration, which is the right default for Microsoft and the wrong one for most organisations. Six settings change the exposure considerably.
Ingestion is charged by volume and most of what Windows logs has no investigative value. A small, deliberate set of events answers the questions an incident actually asks.
A shared local administrator password across an estate is one compromised machine away from being every machine's password. Windows LAPS is built in, and the deployment is four steps.
A practical guide to governing AI agents with Entra Agent ID, Conditional Access, Defender and Purview, including PowerShell, Graph requests and validation.
