Intune in Practice, Part 4: Conditional Access + Intune, the Real Perimeter

Part 3 ended on a deliberately uncomfortable note: a compliance policy by itself doesn’t block anything. It grades a device and moves on. This post is the other half of that pairing — Conditional Access is the piece that actually turns “this device is noncompliant” into “this device doesn’t get in.” ...

July 23, 2026 · 4 min · Jason, Cyber Professional

The New Perimeter, Part 2: SASE, ZTNA, and Policy as Code

Part 1 traced the firewall from stateless packet filters through NGFWs — four generations, each one built to close the previous generation’s blind spot. This part covers what happened once there was no longer a single perimeter to defend at all. ...

July 10, 2026 · 3 min · Jason, Cyber Professional

Zero Trust Access for the Homelab: Securing Self-Hosted Services with Tailscale

If you run self-hosted services at home, you’ve probably hit the remote access problem at some point. You want to reach something — a dashboard, a tool, an API — from outside your home network. The path of least resistance is to open a port on your router and point it at the service. It works. It also quietly puts that service on the internet, discoverable by anyone running a scanner. ...

April 15, 2026 · 11 min · Jason, Cyber Professional

Secure by Design: The Principles Every Practitioner Should Know

April 4, 2026 · 0 min · Jason, Cyber Professional

Trust but Verify vs. Zero Trust

April 4, 2026 · 0 min · Jason, Cyber Professional