Work with me

Hands-on help securing Entra ID, Intune, Defender and Purview.

Migrating to Microsoft, federating with Microsoft, or working on something already running there? Security and identity are my focus, but send me a short description of whatever you’re dealing with and we’ll figure out the best path from here.

What I help with

Identity and access

Conditional Access designed around how your people actually work: phishing-resistant MFA, token protection, cleaning up guest access, and moving off Okta or Ping to Entra ID.

Related writing

Endpoint security

Intune enrollment, compliance and app deployment, plus Defender for Endpoint and Defender for Identity, rolled out without breaking the devices people depend on.

Related writing

Security assessments

A review of your tenant’s identity, device and data settings against the attacks that actually happen, ending in a written report and a list of fixes in priority order.

Related writing

Data protection

Purview sensitivity labels, data loss prevention and retention, introduced in stages so they protect your data without getting in people’s way.

Certified

SC-401: Information Security Administrator Associate

Projects

A recent client project, and three engagements I offer. Client names are left out, along with anything they wouldn’t want public.

Client project · software company, about 30 people

From Google Workspace to Entra ID, with passkeys for everyone

The problemSign-in ran through Google Workspace, several people held permanent global admin rights, and the engineers’ accounts reached cloud infrastructure and source code.

What I didMoved sign-in to Entra ID with YubiKeys for engineering and passkeys for sales, then added a Conditional Access baseline, PIM for admin roles, break-glass accounts that alert when used, and single sign-on for their apps.

The resultAdmin rights are requested when needed instead of held all the time, new starters get their accounts and app access automatically, and the work carries on as an as-needed retainer.

Engagement · identity

Conditional Access review and rebuild

Good forTenants whose policies grew one exception at a time, or that have never been tested against token theft and device code phishing.

What I doReview every policy and exclusion against how attackers actually get in, then rebuild the gaps in report-only mode and switch them on once the sign-in logs look clean.

What you getA policy set where each policy has a written purpose, and a short list of the exclusions that are still justified.

Engagement · endpoint

Getting devices into Intune

Good forCompanies whose laptops aren’t managed yet, or that are moving to Intune from another device management tool.

What I doSet up enrollment, compliance policies and app deployment, pilot with a small group first, then tie device compliance into Conditional Access so only managed devices reach company data.

What you getManaged, compliant devices, apps that install cleanly, and a runbook for adding and retiring devices.

Engagement · assessment

Microsoft 365 security assessment

Good forTeams that inherited a tenant, are preparing for an audit or an insurance renewal, or want to know where they stand.

What I doReview identity, device, email and data protection settings against the CIS benchmark and the attacks that actually happen, then walk your team through what I found.

What you getA written report that explains each finding, and a list of fixes in priority order.

Get in touch

Tell me what’s going on

Email is the best first step. Include roughly how many users you have, your licensing and your timeline, and I’ll reply with whether and how I can help.

Who you’d be working with

Nick Schmitz

I’m a Principal Microsoft Security Architect with over six years in Microsoft 365 security, across identity, endpoints and Microsoft cloud architecture. Before tech I was a sheriff’s deputy and then a police officer, which is where I learned to stay calm and explain things plainly when a situation is going sideways.

  • SC-100
  • SC-300
  • SC-401
  • SC-500
  • MS-102
  • MD-102

More about me