The blog
One blog for the two referentials. The methodology and compliance articles apply to Entra ID & M365 and Active Directory alike; the others are specific to one tool and say so. Each one states at the end which pillars it covers.
Methodology
Reading a simulation result: kill-chain, viable path, exposure score
How to read a simulation: the kill-chain of a scenario, what makes a path viable, the break point, and how the exposure score is built.
MethodologyInstall and customize EntraGUARD: from setup to white-label
Step by step: install EntraGUARD on a workstation, then make it yours — white-label branding, per-client logos, offline licence, themes.
MethodologyInstall and customize AdGUARD: from setup to white-label
Step by step: install AdGUARD on a workstation, then make it yours — white-label branding, per-client logos, offline licence, themes.
MethodologyDetecting drift between two audits
An identical score can hide an estate that has moved. Comparing findings resource by resource reveals what the verdict does not say.
MethodologyANSSI maturity in five tiers, and why it beats the percentage
A percentage treats every gap as equal. The five-tier maturity model says what is achieved and what blocks the next tier.
MethodologyCustom baselines: adapting the audit to your context
Building a baseline: set aside out-of-scope controls, adjust criticality, and make the score reflect your real requirements.
MethodologyDedicated audit vs Microsoft Secure Score: what changes
Microsoft Secure Score is useful but limited. What a dedicated audit goes on to find, and the action plan it produces.
MethodologyUnderstanding the weighted compliance score (L1/L2)
Why a weighted score reflects real risk better than a simple pass ratio, and how level 1 and level 2 controls are weighted in the calculation.
MethodologyThe 494 controls explained: CIS, ANSSI, NIST and ISO 27001
How the 494 automated controls of the two GUARD tools map to CIS, ANSSI, NIST and ISO 27001, and why that alignment makes an audit defensible.
Connectors
Configuring the Active Directory connector: LDAP, LDAPS and Negotiate
Connect a domain read-only: port 389 or 636, integrated authentication or a dedicated account, and the rights actually required.
ConnectorsConfiguring the Entra ID connector: every authentication method explained
Connect the audited tenant step by step: automatic provisioning, certificate vs client secret, and the read-only Graph permissions required.
Security
Mapping the simulated attacks to MITRE ATT&CK
Every simulated attack links to its MITRE ATT&CK technique. Why that mapping matters, and how the 35 scenarios line up against the framework.
SecurityThe EntraGUARD attack simulator: 35 known attacks, replayed read-only
EntraGUARD replays 35 known Entra ID & M365 attacks against the tenant, strictly read-only — each a kill-chain with a verdict and an exposure score.
SecurityReading an Active Directory attack path graph
Target, principal, right: how a path reads, how it is scored severity × breadth, and why a right held by “Domain Users” changes everything.
SecurityTop 10 Active Directory misconfigurations to fix first
Kerberoasting, DCSync, forgotten ACL delegations, permissive AD CS: the ten gaps that open a path to domain administration.
SecurityTop 10 Entra ID misconfigurations to fix first
The ten most common and most dangerous Entra ID misconfigurations, why they matter, and how to remediate each one.
Compliance
HIPAA: auditing the technical safeguards on the Microsoft side
How the HIPAA Security Rule's technical safeguards map to Microsoft configuration, and how to evidence them.
ComplianceCMMC and NIST SP 800-171: auditing Microsoft identity
How the access control and authentication requirements of NIST SP 800-171 and CMMC map to Microsoft configuration.
ComplianceMicrosoft security audit for SOC 2 compliance
How a configuration audit produces the technical evidence auditors ask for under SOC 2 Trust Services Criteria CC6 and CC7.
ComplianceSecurity audits for NIS2 and ISO 27001 compliance
How a Microsoft configuration audit supports a NIS2 or ISO 27001 programme with dated, defensible evidence.
Reports
MSP
The security assessment checklist for MSPs
A repeatable checklist for running Microsoft security assessments across several clients, and packaging it as a service.
MSPBuilding a recurring audit offer rather than a one-off audit
Framing, initial audit, remediation plan, follow-up audit, quarterly committee: the sequence that turns an engagement into a subscription.