Skip to content

Endpoint Security

CIS benchmarks, LAPS, Defender for Endpoint, BitLocker, Conditional Access

mid 10 min read

Security Copilot Agents in the Intune Admin Center: What They Do and What They Don't

A practitioner's guide to the three active Security Copilot agents in Intune: Change Review, Policy Configuration, and Vulnerability Remediation. Covers how each agent works, its real-world limits, and what it actually costs in SCUs.

mid 9 min read

Microsoft Agent 365 Is Now GA: What IT Teams Need to Know

Microsoft Agent 365 hit general availability on May 1, 2026. Here's a practical breakdown of what the control plane does, how it integrates with Intune and Defender, and where shadow AI governance stands today.

mid 10 min read

Security Copilot Agents in Intune: What They Actually Do (and Where They Fall Short)

Microsoft embedded Security Copilot agents directly into the Intune admin center in 2026. Here's a practitioner's honest look at the Change Review Agent, Policy Configuration Agent, Vulnerability Remediation Agent, SCU costs, and what you should watch out for before going all-in.

mid 10 min read

Microsoft Agent 365 Is Now GA: What IT Admins Need to Know About Shadow AI and Intune Controls

Microsoft Agent 365 reached general availability on May 1, 2026. Here's what IT and security teams need to understand about shadow AI discovery, local agent management via Intune, and the new network controls shipping in June.

mid 11 min read

Blocking Shadow AI on Windows Endpoints: A Practical Guide to the Agent 365 Shadow AI Page

Step-by-step guide for IT admins to detect and block unmanaged local AI agents like OpenClaw on Intune-managed Windows devices using the new Agent 365 Shadow AI page, including prerequisites, detection workflow, policy deployment, and what to watch for as coverage expands.

mid 9 min read

Replacing Your Corporate VPN with Microsoft Entra Private Access: A Practical Guide

A step-by-step guide to replacing traditional VPN infrastructure with Microsoft Entra Private Access and Global Secure Access. Covers Quick Access setup, Private Network Connector deployment, Conditional Access integration, and the real gotchas that MS Learn doesn't warn you about.

senior 9 min read

Conditional Access 'All Resources' Enforcement Change (MC1223829): What Desktop Engineers Must Audit Before May 13, 2026

Microsoft is closing a long-standing Conditional Access loophole on May 13, 2026. Here's a practical audit workflow for desktop engineers to find affected policies, excluded apps, and custom clients before enforcement begins.

mid 9 min read

Endpoint Privilege Management in Intune: Setting Up Support-Approved Elevations

How to configure Endpoint Privilege Management's support-approved workflow in Intune so standard users can request elevation on demand without permanent admin rights.

mid 4 min read

Endpoint Privilege Manager Part 1: Introduction & Setup

Learn what Intune Endpoint Privilege Manager is and how to set it up in your environment.

mid 5 min read

Endpoint Privilege Manager Part 2: Creating Policies & Rules

Step-by-step guide to creating and configuring Endpoint Privilege Manager policies.

mid 5 min read

Endpoint Privilege Manager Part 3: Management & Troubleshooting

Monitor EPM activity, generate reports, and fix common issues.

mid 2 min read

BitLocker Recovery Keys: The Complete Guide

Managing BitLocker recovery keys in enterprise environments. Backup, recovery, and automation with Intune.

mid 1 min read

Certificate Management in Windows

Managing certificates in Windows. SSL, code signing, and enterprise PKI. PowerShell certificate operations.

senior 1 min read

CIS Benchmark Hardening for Windows

Apply CIS Microsoft Windows 10/11 Enterprise Benchmark. Secure your Windows devices with proven security settings.

mid 2 min read

Intune Compliance Policies Explained

Configure Intune device compliance policies. Set up conditions for access, conditional access, and device health.

junior 2 min read

Intune Device Restriction Profiles Explained

Complete guide to Intune device restriction profiles. Configure Windows security settings, firewall, and more.