Guidance for Microsoft Intune app protection policies (MAM) — protecting corporate data inside mobile apps with or without device enrollment. Covers MAM-WE for BYOD vs APP on managed devices, data-relocation controls (cut/copy/paste, Save As, encryption), app PIN/biometric and offline grace, selective wipe of…
Guidance for governing and managing Microsoft 365 collaboration sprawl — Teams/group lifecycle, sharing and guest access governance, and SharePoint Advanced Management — to keep the data estate secure and Copilot-ready. WHEN: Microsoft 365 governance, Teams sprawl, group lifecycle, guest access governance, external…
Guidance for remediating oversharing across Microsoft 365 (SharePoint, OneDrive, Teams, Exchange) using the Secure & Governed Data Foundation blueprint - a three-pillar program (remediate oversharing, set up guardrails, meet regulations) built on SharePoint Advanced Management data access governance, sensitivity and…
Guidance for hardening macOS endpoints managed by Microsoft Intune — automated device enrollment via Apple Business Manager (ABM), platform single sign-on (PSSO) with Entra ID, FileVault disk encryption escrow, security configuration profiles (Gatekeeper, XProtect, system extensions allowlist, firewall, login window…
Guidance for managing AI agents at enterprise scale with Microsoft Agent 365 - the control plane that lets admins observe, govern, and secure every agent (Microsoft, Copilot Studio, and third-party) from a single registry, using Microsoft Entra Agent ID for identity, Microsoft Purview for data security, and Microsoft…
Guidance for Microsoft Priva — privacy risk management and subject rights requests. Covers Priva Privacy Risk Management and Priva Subject Rights Requests to find privacy risks and fulfill data subject requests (GDPR/CCPA). WHEN: Microsoft Priva, privacy risk management, subject rights request, DSAR, data subject…
Guidance for rolling out passkeys (device-bound and synced) and FIDO2 security keys in Microsoft Entra ID as the primary phishing-resistant authentication method. Covers passkey types (device-bound in Microsoft Authenticator, synced passkeys via platform providers, hardware security keys), Conditional Access…
Guidance for designing Privileged Access Workstations (PAW) and the Microsoft privileged access strategy (enterprise access model, clean source principle, tiered admin isolation). Covers when to use Enterprise vs Specialized vs Privileged device profiles, hardening (Entra-join, Intune, app allowlisting, Credential…
Guidance for designing public key infrastructure (PKI) and certificate management on Azure and hybrid environments. Covers CA strategy (offline root + issuing CAs, AD CS vs managed/third-party vs public CA), Azure Key Vault certificates, HSM key protection, Entra certificate-based authentication (CBA), certificate…
Instructions for vinayaklatthe/microsoft-security-agent-toolkit, covering read this first, what this repo is, hard rules, conventions and tool surface (the contract you are building toward).
Instructions for vinayaklatthe/microsoft-security-agent-toolkit, covering quick context, hard rules (do not violate), conventions, tool ids (do not rename without cross-repo update) and when stuck.