Blog
Project write-ups and personal notes, newest first.
2026
- This is not a portfolioThe site started as a CV with pictures. It is now my personal site, and the portfolio is one room in it.
- Credential expiry monitoring for Entra ID app registrationsEvery mature tenant carries hundreds of app registrations whose secrets and certificates expire without warning. The alerting is the easy part. The hard parts are working out who owns each application and notifying only about credentials that are actually in use, so the owner hears first, in language they understand.
- Licence usage report: one figure per country, evidence per seatA monthly report that tells each country which seats it can reclaim, and shows the evidence behind every verdict. It began with what looked like the easiest saving of the year (around 40% of Visio and Planner seats apparently unused) and turned into a lesson about what a report should do when a data source quietly returns nothing.
- Proofpoint in front of Exchange Online: what a mail gateway migration really costsPhishing and impersonation were reaching inboxes, so the company put a dedicated gateway in front of Exchange Online. Changing an MX record takes five minutes. The three inventories that have to exist before anyone touches it took months, and they are the part worth writing down while the migration is still under way.
- Designing on-premises and cloud audit reports for privileged accountsA monthly audit report of every privileged account in Entra ID and in Active Directory, with what changed since the last one. Two automations, one report, sent encrypted to the people who need to read it, and a pattern small enough to copy in a week.
- Entra ID audit logs to CrowdStrike SIEM, one stream per countryEntra ID → Event Hubs → Stream Analytics → CrowdStrike NG-SIEM, with Azure Automation keeping the user-to-country lookup fresh. Beyond filtering: each country becomes a measurable unit, with its own events, volumes and security metrics.
2025
- A reliable device inventory: one endpoint, several objects, three automationsA recurring question in device management: why does the inventory never quite match reality? Because one physical endpoint can exist as several objects across Entra ID and Intune, and nothing cleans that up by itself. Three automations keep it honest.
- Turning SOC findings into a remediation process the Workplace team could runThe security operations centre detects and analyses; the Workplace team has the hands on the devices. Without an agreed process between the two, every alert was a conversation. With one, it became a playbook, and playbooks can be automated.
- Redesigning Intune enrollment for classrooms, meeting rooms and staff laptopsAt a business school where a lecture cannot stop because a PC asks for a password, every kind of device got its own enrollment profile, baseline and slice of the application catalogue. Onboarding became a matter of picking the right profile.