Intune in Practice, Part 7: Running Intune in a Lean Non-Profit IT Shop

Everything covered so far in this series works the same way regardless of company size — the mechanics of enrollment, compliance, Conditional Access, app deployment, and baselines don’t change because the org is a non-profit. What changes is the constraints: a much thinner budget, often a very small IT team (sometimes exactly one person wearing every hat), and a board that reasonably wants to know why any dollar isn’t going toward the mission. This post is about running Intune well inside those constraints, drawn from real lean-IT-shop experience rather than enterprise assumptions. ...

July 27, 2026 · 4 min · Jason, Cyber Professional

Intune in Practice, Part 4: Conditional Access + Intune, the Real Perimeter

Part 3 ended on a deliberately uncomfortable note: a compliance policy by itself doesn’t block anything. It grades a device and moves on. This post is the other half of that pairing — Conditional Access is the piece that actually turns “this device is noncompliant” into “this device doesn’t get in.” ...

July 23, 2026 · 4 min · Jason, Cyber Professional

Intune in Practice, Part 3: Compliance Policies That Actually Do Something

Here’s an uncomfortable fact about compliance policies that a lot of tenants learn the hard way: a compliance policy, on its own, doesn’t block anything. It evaluates a device against a set of rules and labels it Compliant or Not Compliant — that’s it. Nothing downstream actually happens unless something else is watching that label and acting on it. Get this wrong and you can have a fully built-out compliance policy that’s pure checkbox theater, catching real problems and doing absolutely nothing about them. ...

July 22, 2026 · 4 min · Jason, Cyber Professional

Intune in Practice, Part 1: What Intune Actually Is (and Isn't)

Kicking off a new series here on Intune — this one’s going to run long, because there’s a lot of ground worth covering: architecture and enrollment, compliance policy design, conditional access, app deployment, configuration baselines, real lessons from running it as a one-person shop, and the attack surface it introduces once it’s live. Part 1 starts with the boring-but-necessary step: being precise about what Intune actually is before deploying anything. ...

July 21, 2026 · 4 min · Jason, Cyber Professional

Kali365: The Phishing-as-a-Service Platform Weaponizing Microsoft's Own Authentication Against You

If you think MFA is your safety net, Kali365 just cut it. In May 2026, the FBI issued Public Service Announcement I-052126-PSA warning organizations about a rapidly emerging Phishing-as-a-Service (PhaaS) platform called Kali365. First observed in April 2026 and distributed openly through Telegram, Kali365 doesn’t steal your password. It doesn’t even need to. It steals something more valuable: your OAuth token, and with it, persistent, credential-free access to your entire Microsoft 365 environment. ...

June 16, 2026 · 9 min · Logan

Device Code Phishing — The Attack That Makes MFA Irrelevant

When most people think about phishing, they picture a fake login page harvesting credentials. Device code phishing doesn’t work that way. There’s no spoofed domain. No credential harvesting. No malware. The victim authenticates against real Microsoft infrastructure, completes their MFA challenge, and hands an attacker a fully valid Bearer token — all without knowing anything unusual happened. ...

June 2, 2026 · 10 min · Logan