How Microsoft Entra Conditional Access now evaluates AI agents: subjects vs audiences, the three agent access patterns, and how to scope policies to agents with custom security attributes instead of managing them one by one.
I've been breaking down Microsoft's security stack since before Entra ID was even called Entra ID. No fluff, no paywalls — just technical depth on Entra, Sentinel, Defender, Purview, and Azure Security that the official docs rarely give you.

Discussion on technical topics and MVP path exploration. Pick the intensity that fits your timeline. Only for Individuals.
How Microsoft Entra Conditional Access now evaluates AI agents: subjects vs audiences, the three agent access patterns, and how to scope policies to agents with custom security attributes instead of managing them one by one.
What changed with passkeys in Microsoft Entra External ID, when it was released, how it compares with workforce tenants, and what can be automated with PowerShell.
How to set up Request Files in SharePoint and OneDrive, why it is safer than normal external sharing, and what to check when the option is missing.
Part 2 of the Agent ID governance series: practical design patterns for combining Microsoft Entra Agent ID access packages with Privileged Identity Management (PIM) for privileged access.
How to assign access packages to Microsoft Entra Agent IDs, including agent self-request, sponsor on-behalf requests, direct admin assignments, and time-bound access lifecycle patterns.
Azure Files Entra-Only identities are now GA for SMB. This guide explains what changed, how Entra Kerberos works, and which identity types are involved in real-world access and authorization.