Opinion

Notes from the field: Windows 10 Device Compliance

One of the coolest features in Microsoft 365 is the ability to measure device compliance, and based on that reading, grant, deny or limit access to cloud resources. For mobile devices this works really well, and most compliance policies are fairly simple: make sure the device isn't jail-broken/rooted, require a...
Read more...

Still waiting for full Azure AD Premium P1 in Microsoft 365 Business…and other Christmas wish list items.

Update March 2020: Spotted today in the message center: Thank you for listening, Microsoft! I had written on this topic a while ago, and many of the components that we were looking to get from Azure AD Premium P1 have in fact arrived since that time (such as password write-back and Conditional...
Read more...

Unpopular opinion: Do not restrict users from creating Teams (Office 365 Groups)

I realize that advocating for no (or very limited) boundaries on who can create Teams puts me in the minority. When I look out across the community, I mostly see consultants in this space suggesting the opposite is a superior approach for various reasons--that the privilege should be constrained heavily....
Read more...

When would I recommend Windows Virtual Desktop to a customer?

Call me crazy: I don't see the value in a Remote Desktop or Virtual Desktop experience for its own sake. The purpose of this kind of solution is to provide centralized management and remote access to specifically Windows-based applications. In short: Remove your dependency on Windows, and you've removed the...
Read more...

Windows Virtual Desktop (WVD) vs. traditional RDS or VDI

I want to talk about Windows Virtual Desktop (WVD) as the successor to on-prem deployments of Remote Desktop Services (RDS), and Virtual Desktop Infrastructure (VDI). Many small and mid-sized businesses are already familiar with using Remote Desktop or similar (e.g. Citrix, VMware View, etc.). Usually this type of service was...
Read more...

You give Encrypt button back NOW, Microsoft!!!!

Recently Sensitivity labels were brought to Outlook, across all the various apps now, including mobile, desktop and web access. This drama has certainly been worth watching. I think Sensitivity labels should gain a lot of traction in general over the next year or two. It's so much more powerful than most...
Read more...

iPadOS (iOS 13+) still not compatible with MAM enforced by Conditional access

Update 11/18/2019: This issue has now been fixed. I wrote about this before the update dropped, and in my testing since then I am afraid the situation has not improved. The setup Create a Conditional access policy for iOS that requires an approved client app. In other words, users cannot...
Read more...

Poser alert: Do you think this may be leveraged for Social engineering? Or what…?

Interesting thing appeared in my WordPress comments over the weekend: it appears that someone lifted content from my blog and re-posted it as their own. Why or how WordPress picked up on this and alerted me via my comments is unknown at this time (maybe some WordPress geeks out there...
Read more...

Should I set my password policy to never expire?

I had some people contact me about this after my Azure AD best practices guide for the SMB dropped. Microsoft has been saying to get rid of password expiration. They even award you more Secure Score points if you follow their advice and trash it. In fact, I personally have...
Read more...

Helping IT Consultants Succeed in the Microsoft Cloud

Have a Question? Contact me today.