<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Enric Díaz — blog</title><description>Microsoft 365 and identity engineer by trade, from Barcelona. This is my personal site: what I build, what I learn along the way, and the occasional opinion.</description><link>https://enricdiaz.com</link><language>en-gb</language><item><title>This is not a portfolio</title><link>https://enricdiaz.com/blog/not-a-portfolio</link><guid isPermaLink="true">https://enricdiaz.com/blog/not-a-portfolio</guid><description>The site started as a CV with pictures. It is now my personal site, and the portfolio is one room in it.</description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate><category>note</category><category>site</category></item><item><title>Credential expiry monitoring for Entra ID app registrations</title><link>https://enricdiaz.com/projects/app-credential-expiry</link><guid isPermaLink="true">https://enricdiaz.com/projects/app-credential-expiry</guid><description>Every mature tenant carries hundreds of app registrations whose secrets and certificates expire without warning. The alerting is the easy part. The hard parts are working out who owns each application and notifying only about credentials that are actually in use, so the owner hears first, in language they understand.</description><pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate><category>project</category><category>Entra ID</category><category>Logic Apps</category><category>Azure OpenAI</category><category>PowerShell</category></item><item><title>Licence usage report: one figure per country, evidence per seat</title><link>https://enricdiaz.com/projects/licence-usage-report</link><guid isPermaLink="true">https://enricdiaz.com/projects/licence-usage-report</guid><description>A monthly report that tells each country which seats it can reclaim, and shows the evidence behind every verdict. It began with what looked like the easiest saving of the year (around 40% of Visio and Planner seats apparently unused) and turned into a lesson about what a report should do when a data source quietly returns nothing.</description><pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate><category>project</category><category>Microsoft Graph</category><category>PowerShell</category><category>Licensing</category><category>Intune</category></item><item><title>Proofpoint in front of Exchange Online: what a mail gateway migration really costs</title><link>https://enricdiaz.com/projects/email-security-proofpoint</link><guid isPermaLink="true">https://enricdiaz.com/projects/email-security-proofpoint</guid><description>Phishing and impersonation were reaching inboxes, so the company put a dedicated gateway in front of Exchange Online. Changing an MX record takes five minutes. The three inventories that have to exist before anyone touches it took months, and they are the part worth writing down while the migration is still under way.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate><category>project</category><category>Exchange Online</category><category>Proofpoint</category><category>Mail flow</category><category>PowerShell</category></item><item><title>Designing on-premises and cloud audit reports for privileged accounts</title><link>https://enricdiaz.com/projects/privileged-access-report</link><guid isPermaLink="true">https://enricdiaz.com/projects/privileged-access-report</guid><description>A monthly audit report of every privileged account in Entra ID and in Active Directory, with what changed since the last one. Two automations, one report, sent encrypted to the people who need to read it, and a pattern small enough to copy in a week.</description><pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate><category>project</category><category>Entra ID</category><category>PIM</category><category>Active Directory</category><category>Logic Apps</category></item><item><title>Entra ID audit logs to CrowdStrike SIEM, one stream per country</title><link>https://enricdiaz.com/projects/siem-country-routing</link><guid isPermaLink="true">https://enricdiaz.com/projects/siem-country-routing</guid><description>Entra ID → Event Hubs → Stream Analytics → CrowdStrike NG-SIEM, with Azure Automation keeping the user-to-country lookup fresh. Beyond filtering: each country becomes a measurable unit, with its own events, volumes and security metrics.</description><pubDate>Wed, 01 Apr 2026 00:00:00 GMT</pubDate><category>project</category><category>Entra ID</category><category>Event Hubs</category><category>Stream Analytics</category><category>Azure Automation</category><category>CrowdStrike</category></item><item><title>A reliable device inventory: one endpoint, several objects, three automations</title><link>https://enricdiaz.com/projects/intune-device-hygiene</link><guid isPermaLink="true">https://enricdiaz.com/projects/intune-device-hygiene</guid><description>A recurring question in device management: why does the inventory never quite match reality? Because one physical endpoint can exist as several objects across Entra ID and Intune, and nothing cleans that up by itself. Three automations keep it honest.</description><pubDate>Mon, 01 Sep 2025 00:00:00 GMT</pubDate><category>project</category><category>Intune</category><category>Entra ID</category><category>Microsoft Graph</category><category>Inventory</category></item><item><title>Turning SOC findings into a remediation process the Workplace team could run</title><link>https://enricdiaz.com/projects/soc-remediation-process</link><guid isPermaLink="true">https://enricdiaz.com/projects/soc-remediation-process</guid><description>The security operations centre detects and analyses; the Workplace team has the hands on the devices. Without an agreed process between the two, every alert was a conversation. With one, it became a playbook, and playbooks can be automated.</description><pubDate>Sun, 01 Jun 2025 00:00:00 GMT</pubDate><category>project</category><category>SOC</category><category>Defender for Endpoint</category><category>CrowdStrike</category><category>Process</category></item><item><title>Redesigning Intune enrollment for classrooms, meeting rooms and staff laptops</title><link>https://enricdiaz.com/projects/intune-enrollment-profiles</link><guid isPermaLink="true">https://enricdiaz.com/projects/intune-enrollment-profiles</guid><description>At a business school where a lecture cannot stop because a PC asks for a password, every kind of device got its own enrollment profile, baseline and slice of the application catalogue. Onboarding became a matter of picking the right profile.</description><pubDate>Sat, 01 Mar 2025 00:00:00 GMT</pubDate><category>project</category><category>Intune</category><category>Autopilot</category><category>Endpoint</category><category>Classrooms</category></item><item><title>Intune group, assignment and maintenance window design</title><link>https://enricdiaz.com/projects/intune-group-design</link><guid isPermaLink="true">https://enricdiaz.com/projects/intune-group-design</guid><description>In Intune there is almost always more than one way to reach a result, and the documentation stops short of telling you which to pick. A design that stays maintainable as the tenant grows: how to structure groups and assignments, which targeting method to use where, and how to decide when change is allowed to land.</description><pubDate>Sat, 01 Jun 2024 00:00:00 GMT</pubDate><category>project</category><category>Intune</category><category>Entra ID</category><category>Governance</category><category>Design</category></item><item><title>NAC with Intune and Aruba ClearPass: a certificate, a query, and a maturity exam</title><link>https://enricdiaz.com/projects/intune-clearpass-nac</link><guid isPermaLink="true">https://enricdiaz.com/projects/intune-clearpass-nac</guid><description>Network access control sounds like a product you switch on. It is actually two teams meeting at one interface (a certificate carrying the Intune Device ID and a Graph query) plus a set of questions about your own maturity that decide whether the project should run at all.</description><pubDate>Fri, 01 Dec 2023 00:00:00 GMT</pubDate><category>project</category><category>Intune</category><category>Aruba ClearPass</category><category>NAC</category><category>802.1X</category></item><item><title>Intune Health Status: monitoring Apple certificates, tokens and connectors with Logic Apps</title><link>https://enricdiaz.com/projects/intune-connector-expiry</link><guid isPermaLink="true">https://enricdiaz.com/projects/intune-connector-expiry</guid><description>Intune device management depends on seven external certificates, tokens and connectors, each with its own expiry and failure mode. Miss the APNs renewal window and every iOS device has to be re-enrolled by hand. Two Logic Apps recurrences check all seven against Microsoft Graph and alert 30 days ahead, with the values and the console link needed to act on it.</description><pubDate>Tue, 01 Nov 2022 00:00:00 GMT</pubDate><category>project</category><category>Intune</category><category>Logic Apps</category><category>Microsoft Graph</category><category>Monitoring</category></item></channel></rss>