Microsoft 365 Security · Email Security · Compliance
THE DATATECHS BLOG
Practical insight on Microsoft 365
and the Microsoft stack.
Guides, analysis, and practical advice for IT managers and business owners navigating the Microsoft ecosystem.
Latest articles
Microsoft 365 Security · Identity and Access
Governing AI Agents Across Client Tenants with Microsoft Agent 365
Microsoft Agent 365 reached general availability on 1 May 2026. The Shadow AI page in the Microsoft 365 admin centre now detects seven locally installed AI ...
Read more →Microsoft 365 Security · Identity and Access
How to Deploy Windows LAPS with Entra ID Backup
Windows LAPS puts a unique local administrator password on every device and backs it up to Entra ID. The tenant-level switch that allows that backup is off by ...
Read more →Microsoft 365 Security · Identity and Access
Deploying a Conditional Access Baseline to Any Tenant
Every MSP I know has a Conditional Access baseline. Most of them exist as a document somebody wrote once, a set of screenshots, and a memory of roughly what ...
Read more →Identity and Access · Compliance
Auditing Delegated Admin Access Across Client Tenants
Microsoft forced everyone off DAP and onto GDAP, most of us did the migration under time pressure, and the fastest way through was to grant broad roles and ...
Read more →Microsoft 365 Security · Identity and Access
Six Global Admins and Audit Logging Off: Inheriting a Three-Year-Old Tenant
You take on a new client. Somebody set the tenant up three years ago, it has worked fine since, and nobody has looked at it. You get Global Administrator, open ...
Read more →Governing AI Agents Across Client Tenants with Microsoft Agent 365
Microsoft Agent 365 reached general availability on 1 May 2026. The Shadow AI page in the Microsoft 365 admin centre now detects seven locally installed AI tools on managed Windows devices, and can ...
How to Deploy Windows LAPS with Entra ID Backup
Windows LAPS puts a unique local administrator password on every device and backs it up to Entra ID. The tenant-level switch that allows that backup is off by default, which is how a policy reports ...
Deploying a Conditional Access Baseline to Any Tenant
Every MSP I know has a Conditional Access baseline. Most of them exist as a document somebody wrote once, a set of screenshots, and a memory of roughly what was done on the last tenant.
Auditing Delegated Admin Access Across Client Tenants
Microsoft forced everyone off DAP and onto GDAP, most of us did the migration under time pressure, and the fastest way through was to grant broad roles and move on. That was a reasonable call at the ...
Six Global Admins and Audit Logging Off: Inheriting a Three-Year-Old Tenant
You take on a new client. Somebody set the tenant up three years ago, it has worked fine since, and nobody has looked at it. You get Global Administrator, open the portal, and start reading.
Legacy Authentication Walks Straight Past Your MFA
A client asks whether they are protected. You check the MFA registration report, see ninety-something per cent, and say yes. Three weeks later an account is compromised with nothing more ...
