Two standards, one blind spot

Most orgs running M365 have at least one critical business process that relies on a third-party system logging in as a real user. It’s common, it’s convenient and it’s creating a supply chain risk.

June 8, 2026 · 15 min · 3093 words · Chris Beattie

Entra External ID Preso

I was invited to present on my previous blog post at the WATSSA technology in education conference in Perth

June 12, 2025 · 1 min · 125 words · Chris Beattie

Conditional Access for Education

Through implementing these policies, educational institutions can significantly enhance their security posture, protecting sensitive data and resources while maintaining usability for staff, students, and guests.

April 4, 2025 · 25 min · 5202 words · Chris Beattie

Entra External ID in Education

Introducing a new Microsoft identity solution which holds the answer to a longstanding need for a parent and guardian identity provider in schools.

November 4, 2024 · 10 min · 2117 words · Chris Beattie

Passing the buck with 'hacklore'

CISA’s Bob Lord coined the term ‘hacklore’ for ‘cybersecurity folklore’, the stories we tell ourselves and others about the nature of technological risks and ways to avoid them that are grounded in fear rather than fact, rumour rather than evidence, antiquity rather than the present day. I see this everywhere, even in high-end corporate ‘cyber awareness’ programmes. Beware of charging your phone from a public USB socket, beware of accepting browser cookies, beware of updating devices on untrusted networks and so on....

July 5, 2024 · 8 min · 1559 words · Chris Beattie

Secure cloud wifi for Entra/Intune devices with Mist

It’s been an incredibly long time coming but at last I have a working proof of concept for an end-to-end entirely cloud-based enterprise wireless network.

March 18, 2024 · 8 min · 1503 words · Chris Beattie

Combining user and device certificates for wifi authentication in Intune

Modern security and wifi standards say we have to move to certificates but that’s a tall order for many, particularly if we need to replicate the user-level identification of a humble password.

February 12, 2024 · 7 min · 1443 words · Chris Beattie

FIDO? Schmido!

A lack of mobile support for FIDO2 auth and Passkeys from Microsoft is hampering widespread adoption but some limited use cases can bring immediate benefit to securing high-risk activities.

April 5, 2023 · 7 min · 1451 words · Chris Beattie

SC-200 Notes

I’ve been tacking in the direction of cybersecurity in recent years and specifically within the Microsoft 365 suite. I took the Security Administrator track on my Enterprise Admin certification and didn’t find that too difficult as it was grounded in my day-to-day. This one was pushing the boat out as it’s more Azure-based and honestly I wasn’t expecting to pass first time, but it fairly soaked up these dull days between Christmas and New Year!...

December 30, 2022 · 4 min · 683 words · Chris Beattie

Code debt and custom sandboxes

Schools can hardly be the only organisations with legacy applications in regular use for vital ’line-of-business’ functions. Hopefully for the most part these are visible to IT, securely contained and have an end-of-life date with a succession plan rather than being adopted through choice into a modern desktop environment. A while ago I encountered a nasty and unavoidable case of the latter and had to figure out a solution. The application I was tasked to deploy was for processing sensitive financial data on our most heavily-secured devices and relied on Internet Explorer and Java....

September 2, 2022 · 6 min · 1160 words · Chris Beattie