<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Microsoft Security in Practice</title><description>Practical Microsoft infrastructure, identity and security guidance from Palanikumar Annamalai.</description><link>https://www.palanikumar.net/</link><language>en-gb</language><item><title>Build a two-node Hyper-V cluster without a SAN using Storage Spaces Direct</title><link>https://www.palanikumar.net/articles/two-node-hyper-v-cluster-without-san/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/two-node-hyper-v-cluster-without-san/</guid><description>How a small business or remote office can combine two Windows servers into a highly available Hyper-V cluster without purchasing a separate shared-storage appliance.</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>Storage Spaces Direct</category><category>Windows Server</category><category>Hyper-V</category><category>High Availability</category><author>mail@palanikumar.net</author></item><item><title>Active Directory administrative tiering, and why implementations stall</title><link>https://www.palanikumar.net/articles/active-directory-administrative-tiering/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/active-directory-administrative-tiering/</guid><description>Tiering fails as a diagram and succeeds as an enforcement mechanism. This is the dependency order that decides which one you end up with.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Active Directory</category><category>Privileged access</category><category>Security architecture</category><author>mail@palanikumar.net</author></item><item><title>Active Directory DNS design decisions that outlive their authors</title><link>https://www.palanikumar.net/articles/active-directory-dns-design-decisions/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/active-directory-dns-design-decisions/</guid><description>Namespace, zone storage and forwarder choices are made once and inherited for twenty years. These are the ones that are expensive to reverse, and the ones that are not.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Active Directory</category><category>DNS</category><category>Architecture</category><author>mail@palanikumar.net</author></item><item><title>Planning an Active Directory forest recovery before you need it</title><link>https://www.palanikumar.net/articles/active-directory-forest-recovery-planning/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/active-directory-forest-recovery-planning/</guid><description>Forest recovery is not restoring a domain controller. It is rebuilding the authentication layer that every other recovery plan quietly assumes is already working.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Active Directory</category><category>Disaster recovery</category><category>Resilience</category><author>mail@palanikumar.net</author></item><item><title>Attack surface reduction rules without breaking a business application</title><link>https://www.palanikumar.net/articles/attack-surface-reduction-rules/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/attack-surface-reduction-rules/</guid><description>ASR rules block the behaviours malware relies on — and some of the behaviours a twenty-year-old line-of-business application relies on. Audit mode is the entire deployment strategy.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Microsoft Defender</category><category>Endpoint security</category><category>Hardening</category><author>mail@palanikumar.net</author></item><item><title>Designing Azure backup and recovery around a tested restore</title><link>https://www.palanikumar.net/articles/azure-backup-tested-restore/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/azure-backup-tested-restore/</guid><description>A backup job reporting success is a claim about a job. The only evidence that matters is a restore you performed, timed, and validated against what the business actually needs.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Azure</category><category>Backup</category><category>Resilience</category><author>mail@palanikumar.net</author></item><item><title>Hub-and-spoke in Azure, and when it stops being the answer</title><link>https://www.palanikumar.net/articles/azure-hub-and-spoke-networking/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/azure-hub-and-spoke-networking/</guid><description>Peering is not transitive, which is the fact the whole topology is built around. Knowing why it is chosen also tells you the point at which Virtual WAN replaces it.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Azure</category><category>Networking</category><category>Architecture</category><author>mail@palanikumar.net</author></item><item><title>Azure landing zones without the platform team you do not have</title><link>https://www.palanikumar.net/articles/azure-landing-zones-small-team/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/azure-landing-zones-small-team/</guid><description>The reference architecture assumes a dedicated platform function. Most organisations do not have one. The subset that still earns its keep is smaller than the diagram suggests.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Azure</category><category>Landing zones</category><category>Architecture</category><author>mail@palanikumar.net</author></item><item><title>Azure Policy as a guardrail: audit, deny and deployIfNotExists</title><link>https://www.palanikumar.net/articles/azure-policy-as-guardrail/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/azure-policy-as-guardrail/</guid><description>Policy is the only control that stops a permitted action producing an unacceptable resource. Deploying it in the wrong order is how you break a platform team&apos;s deployments on a Monday.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Azure</category><category>Governance</category><category>Azure Policy</category><author>mail@palanikumar.net</author></item><item><title>Private endpoints, service endpoints and the DNS work that decides both</title><link>https://www.palanikumar.net/articles/azure-private-endpoints-and-dns/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/azure-private-endpoints-and-dns/</guid><description>A private endpoint is a network interface and a DNS problem. Almost every failure I have seen was the DNS half, resolving the public address from somewhere nobody checked.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Azure</category><category>Networking</category><category>DNS</category><author>mail@palanikumar.net</author></item><item><title>Azure RBAC scope decisions you cannot easily undo</title><link>https://www.palanikumar.net/articles/azure-rbac-scope-decisions/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/azure-rbac-scope-decisions/</guid><description>Role assignments inherit downward and there is no deny. Where you assign a role matters more than which role you assign, and the subscription limit is closer than you think.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Azure</category><category>RBAC</category><category>Architecture</category><author>mail@palanikumar.net</author></item><item><title>Certificate auto-enrolment stopped working, and nothing told anybody</title><link>https://www.palanikumar.net/articles/certificate-autoenrolment-failures/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/certificate-autoenrolment-failures/</guid><description>Auto-enrolment fails silently until certificates expire and authentication breaks. A read-only script that finds the certificates about to lapse, tests the certification authorities and reports who actually holds enrol rights.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Active Directory</category><category>Security</category><category>PowerShell</category><category>Troubleshooting</category><author>mail@palanikumar.net</author></item><item><title>Co-management workloads, and moving one slider at a time</title><link>https://www.palanikumar.net/articles/co-management-workload-sliders/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/co-management-workload-sliders/</guid><description>Co-management lets Configuration Manager and Intune manage the same device. Each workload has exactly one authority, and moving a slider transfers it for every device in scope.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Intune</category><category>Configuration Manager</category><category>Co-management</category><author>mail@palanikumar.net</author></item><item><title>Conditional Access baselines that survive contact with users</title><link>https://www.palanikumar.net/articles/conditional-access-baselines/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/conditional-access-baselines/</guid><description>A policy set that works in a demo tenant and locks out a real organisation is the normal outcome. Report-only mode, exclusion design and a deliberate rollout order prevent it.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Microsoft Entra ID</category><category>Conditional Access</category><category>Zero Trust</category><author>mail@palanikumar.net</author></item><item><title>Defender XDR and Sentinel: what to collect, and what to ignore</title><link>https://www.palanikumar.net/articles/defender-xdr-and-sentinel-collection/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/defender-xdr-and-sentinel-collection/</guid><description>Two products that overlap enough to confuse the boundary. Defender XDR covers the Microsoft estate; Sentinel is for everything else and for correlation across it.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Microsoft Defender</category><category>Microsoft Sentinel</category><category>Security operations</category><author>mail@palanikumar.net</author></item><item><title>Directory synchronisation errors: duplicate attributes and soft matches that never resolve</title><link>https://www.palanikumar.net/articles/directory-sync-error-triage/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/directory-sync-error-triage/</guid><description>A user exists on-premises, does not exist in the cloud, and sync reports success. A read-only triage script that finds the objects Entra ID quarantined and explains which attribute caused it.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Microsoft Entra ID</category><category>Hybrid identity</category><category>Microsoft Graph</category><category>PowerShell</category><category>Troubleshooting</category><author>mail@palanikumar.net</author></item><item><title>The client secret nobody renewed: auditing Entra ID application credentials</title><link>https://www.palanikumar.net/articles/entra-app-credential-expiry/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/entra-app-credential-expiry/</guid><description>Application secrets expire quietly and fail loudly, usually out of hours. A read-only script that lists every credential in the tenant with its expiry, owner and blast radius.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Microsoft Entra ID</category><category>Microsoft Graph</category><category>PowerShell</category><category>Troubleshooting</category><author>mail@palanikumar.net</author></item><item><title>Application consent in Microsoft Entra ID, and the permissions people over-grant</title><link>https://www.palanikumar.net/articles/entra-application-consent-permissions/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/entra-application-consent-permissions/</guid><description>Delegated and application permissions are not two settings on the same dial. One is bounded by the signed-in user and one is not, and the difference decides your exposure.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Microsoft Entra ID</category><category>Microsoft Graph</category><category>Security</category><author>mail@palanikumar.net</author></item><item><title>Choosing between Microsoft Entra Connect Sync and Cloud Sync</title><link>https://www.palanikumar.net/articles/entra-connect-sync-versus-cloud-sync/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/entra-connect-sync-versus-cloud-sync/</guid><description>Two provisioning engines with overlapping names and genuinely different architectures. The decision turns on transformation complexity and forest topology, not on which is newer.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Microsoft Entra ID</category><category>Hybrid identity</category><category>Architecture</category><author>mail@palanikumar.net</author></item><item><title>Emergency access accounts that still work during an outage</title><link>https://www.palanikumar.net/articles/entra-emergency-access-accounts/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/entra-emergency-access-accounts/</guid><description>Break-glass accounts fail for the same reason everything else fails during an incident: they were configured once and never exercised. The controls that keep them usable are specific.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Microsoft Entra ID</category><category>Privileged access</category><category>Resilience</category><author>mail@palanikumar.net</author></item><item><title>From Exchange 5.5 to Exchange Online: what three decades of messaging taught me</title><link>https://www.palanikumar.net/articles/exchange-5-5-to-exchange-online/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/exchange-5-5-to-exchange-online/</guid><description>Six generations of Exchange, and the same four problems each time. The products changed completely; the design questions barely moved.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Exchange</category><category>Microsoft 365</category><category>Architecture</category><author>mail@palanikumar.net</author></item><item><title>Exchange hybrid, still running in 2026</title><link>https://www.palanikumar.net/articles/exchange-hybrid-in-2026/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/exchange-hybrid-in-2026/</guid><description>The last Exchange server is no longer a licensing footnote. Subscription Edition, the dedicated hybrid app and the Graph transition have changed what hybrid coexistence actually requires.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Exchange</category><category>Microsoft 365</category><category>Hybrid</category><author>mail@palanikumar.net</author></item><item><title>Failover cluster witness choices, compared honestly</title><link>https://www.palanikumar.net/articles/failover-cluster-witness-choices/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/failover-cluster-witness-choices/</guid><description>Quorum is a voting problem, and the witness is the vote that breaks ties. Each of the three options fails in a different way, and the right choice depends on what you expect to lose.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Windows Server</category><category>Failover clustering</category><category>Architecture</category><author>mail@palanikumar.net</author></item><item><title>Microsoft Graph PowerShell: authentication, scopes and least privilege</title><link>https://www.palanikumar.net/articles/graph-powershell-authentication-and-scopes/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/graph-powershell-authentication-and-scopes/</guid><description>The SDK asks for the permissions you name, and most people name too many. Two discovery cmdlets tell you exactly what a command needs, which makes least privilege straightforward.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Microsoft Graph</category><category>PowerShell</category><category>Automation</category><author>mail@palanikumar.net</author></item><item><title>Reporting on Entra ID sign-ins and risk with Microsoft Graph</title><link>https://www.palanikumar.net/articles/graph-sign-in-and-risk-reporting/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/graph-sign-in-and-risk-reporting/</guid><description>The sign-in log answers questions the portal makes awkward: legacy authentication by application, failures by error code, and which accounts are risky right now.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Microsoft Entra ID</category><category>Microsoft Graph</category><category>PowerShell</category><author>mail@palanikumar.net</author></item><item><title>Group Policy processing order, and the settings that quietly lose</title><link>https://www.palanikumar.net/articles/group-policy-processing-order/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/group-policy-processing-order/</guid><description>A setting that does not apply is rarely a broken GPO. It is usually a GPO that applied and was then overwritten by one you forgot was linked. Here is how to prove which.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Active Directory</category><category>Group Policy</category><category>Troubleshooting</category><author>mail@palanikumar.net</author></item><item><title>Hybrid identity failure modes nobody tests for</title><link>https://www.palanikumar.net/articles/hybrid-identity-failure-modes/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/hybrid-identity-failure-modes/</guid><description>Directory synchronisation works for years and then fails in a way the pilot never covered. These are the failures I check for, and the evidence that identifies each one.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Microsoft Entra ID</category><category>Hybrid identity</category><category>Troubleshooting</category><author>mail@palanikumar.net</author></item><item><title>Microsoft Entra hybrid join: reading dsregcmd instead of guessing</title><link>https://www.palanikumar.net/articles/hybrid-join-failure-triage/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/hybrid-join-failure-triage/</guid><description>Hybrid join failures are diagnosed by a tool that prints eighty lines of state nobody reads. A script that parses it, names the failing phase and checks the service connection point.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Microsoft Entra ID</category><category>Hybrid identity</category><category>Windows</category><category>PowerShell</category><category>Troubleshooting</category><author>mail@palanikumar.net</author></item><item><title>Hyper-V live migration failures and the delegation behind them</title><link>https://www.palanikumar.net/articles/hyper-v-live-migration-failures/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/hyper-v-live-migration-failures/</guid><description>Live migration fails in a small number of reproducible ways. The most confusing one is authentication, where migrating from the console works and migrating remotely does not.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Hyper-V</category><category>Windows Server</category><category>Troubleshooting</category><author>mail@palanikumar.net</author></item><item><title>Identity controls for AI agents in Microsoft 365</title><link>https://www.palanikumar.net/articles/identity-controls-for-ai-agents/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/identity-controls-for-ai-agents/</guid><description>An agent acting on a user&apos;s behalf inherits that user&apos;s access, including everything they could reach but never did. The oversharing problem stops being theoretical.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>AI security</category><category>Microsoft Entra ID</category><category>Governance</category><author>mail@palanikumar.net</author></item><item><title>Intune app deployment: detection rules, requirements and supersedence</title><link>https://www.palanikumar.net/articles/intune-app-deployment-detection-rules/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/intune-app-deployment-detection-rules/</guid><description>The detection rule is the part that decides whether an application is installed. Get it wrong and Intune reinstalls forever, or reports success for software that is not there.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Intune</category><category>Application deployment</category><category>Implementation</category><author>mail@palanikumar.net</author></item><item><title>Compliance policies, grace periods and the Conditional Access link</title><link>https://www.palanikumar.net/articles/intune-compliance-and-conditional-access/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/intune-compliance-and-conditional-access/</guid><description>Compliance is only a report until Conditional Access reads it. Connecting the two is a single checkbox and the most effective way to lock out your entire organisation.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Intune</category><category>Compliance</category><category>Conditional Access</category><author>mail@palanikumar.net</author></item><item><title>Why is this device non-compliant? Intune compliance triage at scale</title><link>https://www.palanikumar.net/articles/intune-compliance-triage/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/intune-compliance-triage/</guid><description>The Intune portal tells you a device is non-compliant. It takes several clicks to learn which policy, and there is no clicking your way through nine hundred devices. A script that answers it in one pass.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Intune</category><category>Microsoft Graph</category><category>PowerShell</category><category>Troubleshooting</category><author>mail@palanikumar.net</author></item><item><title>Intune policy conflicts, and how to find which policy won</title><link>https://www.palanikumar.net/articles/intune-policy-conflicts/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/intune-policy-conflicts/</guid><description>Intune does not arbitrate conflicts. Two policies setting the same value differently means neither applies, which is the opposite of what most administrators assume.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Intune</category><category>Device management</category><category>Troubleshooting</category><author>mail@palanikumar.net</author></item><item><title>Kerberos delegation: unconstrained, constrained and resource-based</title><link>https://www.palanikumar.net/articles/kerberos-delegation-explained/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/kerberos-delegation-explained/</guid><description>Three delegation models, one of which should not exist in your directory any more. The differences decide who can impersonate whom, and who gets to configure it.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Active Directory</category><category>Kerberos</category><category>Security architecture</category><author>mail@palanikumar.net</author></item><item><title>Key Vault returns 403: which of the four causes is it?</title><link>https://www.palanikumar.net/articles/key-vault-access-denied/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/key-vault-access-denied/</guid><description>An Owner who cannot read a secret, a firewall that looks open, and a private endpoint resolving to the wrong address all produce the same status code. A script that separates them.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Azure</category><category>Security</category><category>PowerShell</category><category>Troubleshooting</category><author>mail@palanikumar.net</author></item><item><title>Before you enforce LDAP signing: find the clients that will break</title><link>https://www.palanikumar.net/articles/ldap-signing-channel-binding-readiness/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/ldap-signing-channel-binding-readiness/</guid><description>Enforcing LDAP signing and channel binding is a five-minute change that breaks printers, scanners and appliances nobody documented. A script that finds them first, from the domain controllers&apos; own evidence.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Active Directory</category><category>Security</category><category>Windows Server</category><category>PowerShell</category><category>Troubleshooting</category><author>mail@palanikumar.net</author></item><item><title>A repeatable Microsoft 365 evidence collection script</title><link>https://www.palanikumar.net/articles/microsoft-365-evidence-collection/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/microsoft-365-evidence-collection/</guid><description>Audits, incidents and reviews all ask the same questions about a tenant. Collecting the answers the same way every time turns an ad-hoc scramble into a comparable record.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Microsoft 365</category><category>PowerShell</category><category>Security assessment</category><author>mail@palanikumar.net</author></item><item><title>Microsoft 365 tenant-to-tenant migration: what breaks first</title><link>https://www.palanikumar.net/articles/microsoft-365-tenant-to-tenant-migration/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/microsoft-365-tenant-to-tenant-migration/</guid><description>A tenant move is an identity project wearing a migration costume. The mailboxes are the easy part; the domain name can only exist in one tenant at a time.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Microsoft 365</category><category>Migration</category><category>Architecture</category><author>mail@palanikumar.net</author></item><item><title>Microsoft Purview and the permissions work that has to come first</title><link>https://www.palanikumar.net/articles/microsoft-purview-permissions-first/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/microsoft-purview-permissions-first/</guid><description>Classification tells you where sensitive data is. It does not reduce who can reach it. Deploying labels over broken permissions produces an accurate map of a problem you still have.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Microsoft Purview</category><category>Data governance</category><category>Security</category><author>mail@palanikumar.net</author></item><item><title>Finding NTLM before you turn it off</title><link>https://www.palanikumar.net/articles/ntlm-usage-discovery/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/ntlm-usage-discovery/</guid><description>NTLM is deprecated, NTLMv1 is already removed from the newest Windows releases, and nobody has an inventory. A read-only script that collects what is actually authenticating with NTLM, from the machines that know.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Active Directory</category><category>Security</category><category>Windows Server</category><category>PowerShell</category><category>Troubleshooting</category><author>mail@palanikumar.net</author></item><item><title>Writing PowerShell that other administrators can safely run</title><link>https://www.palanikumar.net/articles/powershell-other-admins-can-run/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/powershell-other-admins-can-run/</guid><description>A script that works is not the same as a script someone else can run at two in the morning. The difference is a small number of habits, and they cost almost nothing to adopt.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>PowerShell</category><category>Automation</category><category>Operations</category><author>mail@palanikumar.net</author></item><item><title>Preparing Microsoft Entra ID for passkey-first authentication</title><link>https://www.palanikumar.net/articles/preparing-entra-id-for-passkeys/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/preparing-entra-id-for-passkeys/</guid><description>Moving to phishing-resistant authentication is mostly not a passkey problem. It is a recovery, enrolment and exception problem, and those need solving first.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Microsoft Entra ID</category><category>Authentication</category><category>Passkeys</category><author>mail@palanikumar.net</author></item><item><title>Privileged Identity Management: eligibility, approval and the audit trail</title><link>https://www.palanikumar.net/articles/privileged-identity-management-in-practice/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/privileged-identity-management-in-practice/</guid><description>PIM turns standing administrative access into time-bound, justified and reviewable access. Most deployments stall because the role inventory was never done.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Microsoft Entra ID</category><category>Privileged access</category><category>Governance</category><author>mail@palanikumar.net</author></item><item><title>Protecting LSASS: LSA protection, Credential Guard and what each stops</title><link>https://www.palanikumar.net/articles/protecting-lsass-credential-guard/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/protecting-lsass-credential-guard/</guid><description>Two distinct protections with overlapping names, both now on by default in recent Windows. Knowing which one blocks which attack tells you what remains exposed.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Windows</category><category>Credential protection</category><category>Security</category><author>mail@palanikumar.net</author></item><item><title>Auditing Active Directory with PowerShell, without writing to it</title><link>https://www.palanikumar.net/articles/read-only-active-directory-audit/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/read-only-active-directory-audit/</guid><description>A read-only assessment that collects privileged membership, delegation, stale accounts and password policy exposure — and changes nothing, deliberately.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Active Directory</category><category>PowerShell</category><category>Security assessment</category><author>mail@palanikumar.net</author></item><item><title>Reading Active Directory replication failures before they become outages</title><link>https://www.palanikumar.net/articles/reading-active-directory-replication-failures/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/reading-active-directory-replication-failures/</guid><description>Replication rarely fails suddenly. It fails quietly for weeks, then becomes an outage on the day a tombstone lifetime expires. This is how to read the evidence early.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Active Directory</category><category>Replication</category><category>Troubleshooting</category><author>mail@palanikumar.net</author></item><item><title>Retiring stale Active Directory accounts without breaking an application</title><link>https://www.palanikumar.net/articles/retiring-stale-active-directory-accounts/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/retiring-stale-active-directory-accounts/</guid><description>Deleting a dormant account is easy. Knowing whether something still depends on it is the actual work, and LastLogonDate will not tell you.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Active Directory</category><category>Identity governance</category><category>PowerShell</category><author>mail@palanikumar.net</author></item><item><title>SharePoint and OneDrive sharing defaults worth changing on day one</title><link>https://www.palanikumar.net/articles/sharepoint-onedrive-sharing-defaults/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/sharepoint-onedrive-sharing-defaults/</guid><description>The defaults optimise for collaboration, which is the right default for Microsoft and the wrong one for most organisations. Six settings change the exposure considerably.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>SharePoint</category><category>OneDrive</category><category>Security</category><author>mail@palanikumar.net</author></item><item><title>SPF, DKIM and DMARC as an operational sequence</title><link>https://www.palanikumar.net/articles/spf-dkim-dmarc-operational-sequence/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/spf-dkim-dmarc-operational-sequence/</guid><description>Three DNS records that only work in a specific order. Publishing a strict DMARC policy before the inventory is complete is how organisations stop their own invoices arriving.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Exchange Online</category><category>Email authentication</category><category>DNS</category><author>mail@palanikumar.net</author></item><item><title>From Storage Spaces Direct to Azure Local: what changed, and what did not</title><link>https://www.palanikumar.net/articles/storage-spaces-direct-to-azure-local/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/storage-spaces-direct-to-azure-local/</guid><description>The storage engine is largely the same software. The operating model is not. Separating those two facts is what makes the platform decision answerable.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Azure Local</category><category>Storage Spaces Direct</category><category>Architecture</category><author>mail@palanikumar.net</author></item><item><title>Storage Spaces Direct: what actually breaks, and how it tells you</title><link>https://www.palanikumar.net/articles/storage-spaces-direct-what-breaks/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/storage-spaces-direct-what-breaks/</guid><description>The cluster reports its own health accurately. The difficulty is that a degraded volume, a stuck repair job and a failing drive produce overlapping symptoms and need different responses.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Storage Spaces Direct</category><category>Windows Server</category><category>Troubleshooting</category><author>mail@palanikumar.net</author></item><item><title>SYSVOL stopped replicating: dirty shutdowns and content freshness</title><link>https://www.palanikumar.net/articles/sysvol-dfsr-recovery/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/sysvol-dfsr-recovery/</guid><description>Group Policy applies differently depending on which domain controller a client used. A read-only health check for DFSR SYSVOL, and the one recovery step that is safe to automate.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Active Directory</category><category>Windows Server</category><category>PowerShell</category><category>Troubleshooting</category><author>mail@palanikumar.net</author></item><item><title>Tracing a message through Exchange Online mail flow</title><link>https://www.palanikumar.net/articles/tracing-exchange-online-mail-flow/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/tracing-exchange-online-mail-flow/</guid><description>Message trace answers where a message went. Getting a useful answer depends on knowing which tool covers which window, and on reading the event sequence rather than the final status.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Exchange Online</category><category>Mail flow</category><category>Troubleshooting</category><author>mail@palanikumar.net</author></item><item><title>Windows 11 readiness for an estate that is already out of support</title><link>https://www.palanikumar.net/articles/windows-11-readiness-inventory/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/windows-11-readiness-inventory/</guid><description>Windows 10 reached end of support in October 2025. A script that reports, per device, which Windows 11 requirement it fails — and says plainly which answers it cannot give you.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Windows</category><category>Intune</category><category>PowerShell</category><category>Troubleshooting</category><author>mail@palanikumar.net</author></item><item><title>Windows Admin Center as an operational front end</title><link>https://www.palanikumar.net/articles/windows-admin-center-operations/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/windows-admin-center-operations/</guid><description>A browser-based console that replaces a dozen MMC snap-ins, and a gateway that can reach every server you own. The second half is why its placement is a security decision.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Windows Server</category><category>Windows Admin Center</category><category>Operations</category><author>mail@palanikumar.net</author></item><item><title>Windows Autopilot enrolment failures: a diagnostic sequence</title><link>https://www.palanikumar.net/articles/windows-autopilot-enrolment-failures/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/windows-autopilot-enrolment-failures/</guid><description>Autopilot failures happen in front of the person receiving the device, which raises the stakes. Almost all of them fall into four categories, distinguishable within minutes.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Intune</category><category>Autopilot</category><category>Troubleshooting</category><author>mail@palanikumar.net</author></item><item><title>Windows event logs worth forwarding, and the ones that waste money</title><link>https://www.palanikumar.net/articles/windows-event-logs-worth-forwarding/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/windows-event-logs-worth-forwarding/</guid><description>Ingestion is charged by volume and most of what Windows logs has no investigative value. A small, deliberate set of events answers the questions an incident actually asks.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Security operations</category><category>Logging</category><category>Windows</category><author>mail@palanikumar.net</author></item><item><title>Local administrator password management with Windows LAPS</title><link>https://www.palanikumar.net/articles/windows-laps-implementation/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/windows-laps-implementation/</guid><description>A shared local administrator password across an estate is one compromised machine away from being every machine&apos;s password. Windows LAPS is built in, and the deployment is four steps.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Windows</category><category>LAPS</category><category>Security</category><author>mail@palanikumar.net</author></item><item><title>Windows Server storage performance: the counters that matter</title><link>https://www.palanikumar.net/articles/windows-server-storage-counters/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/windows-server-storage-counters/</guid><description>Disk queue length is the counter everyone quotes and the one that misleads most often. Latency is the number that corresponds to what users experience.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Windows Server</category><category>Performance</category><category>Troubleshooting</category><author>mail@palanikumar.net</author></item><item><title>Windows Server upgrade paths, and when in-place is the wrong instinct</title><link>https://www.palanikumar.net/articles/windows-server-upgrade-paths/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/windows-server-upgrade-paths/</guid><description>In-place upgrade is supported, faster and carries forward everything — including the accumulated configuration nobody understands. That last part is usually the deciding factor.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Windows Server</category><category>Upgrades</category><category>Implementation</category><author>mail@palanikumar.net</author></item><item><title>Microsoft Entra Connect Sync: the September 2026 upgrade deadline</title><link>https://www.palanikumar.net/articles/entra-connect-september-2026-upgrade/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/entra-connect-september-2026-upgrade/</guid><description>What identity teams should verify before the mandatory Entra Connect Sync upgrade deadline, and how to reduce cutover risk.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate><category>Microsoft Entra ID</category><category>Hybrid identity</category><category>Operations</category><author>mail@palanikumar.net</author></item><item><title>Exchange Online EWS retirement: an October 2026 readiness plan</title><link>https://www.palanikumar.net/articles/exchange-online-ews-retirement-2026/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/exchange-online-ews-retirement-2026/</guid><description>A practical readiness plan for discovering EWS dependencies, controlling temporary access and moving Exchange Online integrations forward.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate><category>Exchange Online</category><category>Microsoft 365</category><category>Microsoft Graph</category><author>mail@palanikumar.net</author></item><item><title>From radio experiments and MS-DOS to Microsoft cloud security</title><link>https://www.palanikumar.net/articles/from-radio-experiments-to-cloud-security/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/from-radio-experiments-to-cloud-security/</guid><description>How electronics, local computer support and successive Microsoft platforms shaped the way I approach infrastructure, identity and security.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate><category>Career</category><category>Architecture</category><category>Technical education</category><author>mail@palanikumar.net</author></item><item><title>From Windows NT and Exchange 5.5 to Azure Local and Microsoft 365</title><link>https://www.palanikumar.net/articles/from-windows-nt-to-azure-local/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/from-windows-nt-to-azure-local/</guid><description>An architectural view of what changes across Microsoft platform generations, and the operational questions that still need an answer.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate><category>Architecture</category><category>Windows Server</category><category>Azure Local</category><category>Microsoft 365</category><author>mail@palanikumar.net</author></item><item><title>Securing enterprise AI agents: a hands-on Microsoft implementation guide</title><link>https://www.palanikumar.net/articles/securing-enterprise-ai-agents/</link><guid isPermaLink="true">https://www.palanikumar.net/articles/securing-enterprise-ai-agents/</guid><description>A practical guide to governing AI agents with Entra Agent ID, Conditional Access, Defender and Purview, including PowerShell, Graph requests and validation.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate><category>AI security</category><category>Microsoft Entra ID</category><category>Microsoft Defender</category><author>mail@palanikumar.net</author></item></channel></rss>