Part 2 of the real-time Entra ID series. Stream sign-in logs through diagnostic settings to an Event Hub, consume them in the same Azure Function App, and page on duty the moment a break-glass UPN signs in or sign-in risk crosses a threshold.
Security
Real-time Entra ID Group Alerts with Azure Functions (Part 1)
Get notified the moment someone joins your Global Admins or a Tier 0 access group. Part 1 of a two-part series builds an Azure Function App that consumes Microsoft Graph change notifications, validates the webhook, and posts Teams alerts on every membership change.
End-to-End User Offboarding with Microsoft Graph PowerShell
Leavers retaining residual access is a chronic security risk. This walkthrough turns one HR row into a fully offboarded user with sessions revoked, mailbox converted to shared, OneDrive transferred to the manager, groups cleared, and licences released, all with a clean audit trail.
Conditional Access Policy Backups via PowerShell
Conditional Access policies are critical Entra ID security controls, but many tenants have no backup or version history. This walkthrough builds a short PowerShell script that exports every CA policy to JSON and commits it to Git, giving you an auditable, restorable baseline you can schedule in Azure Automation or GitHub Actions.
Automating MFA Audits in Entra ID with PowerShell
Learn how to audit MFA registration status across your entire Microsoft Entra ID tenant using PowerShell and the Microsoft Graph API. Includes filtering, CSV export, and a fully automated scheduled reporting script.
App-Only Auth for Microsoft Graph with PowerShell
A step-by-step guide to creating an Entra ID app registration, generating a self-signed certificate, assigning Microsoft Graph API permissions, and connecting with PowerShell for fully unattended automation.
Automating Microsoft Defender for Endpoint Onboarding with PowerShell
Onboarding devices to Microsoft Defender for Endpoint individually through the Security Center is time-consuming and difficult to track at scale. Using PowerShell and the Microsoft Graph Security API, you can automate onboarding, verify sensor health, and generate...
Configuring Conditional Access Policies with Microsoft Entra ID
Conditional Access is the cornerstone of Zero Trust security in Microsoft Entra ID. Rather than managing dozens of policies by hand through the Azure portal, you can use PowerShell and the Microsoft Graph API to define, deploy, and version-control your policies with...
SCCM Baselines: Update Compliance
There are numerous of ways to measure update compliance in an enterprise. Some prefer to just compare the compliance of a Software Update Group against a collection. The issue I’ve found with this is that when you release updates the compliance falls down to 0%…
SCCM Baselines: Intrusion and Theft Protection
This article focuses on the scenario where the laptop/desktop has been lost or stolen, and how to make sure that the local data/credentials are secured/encrypted.






