# SchmitdySec > Real World Microsoft Security ## Posts - [Token Protection for Web Apps First Look and Wackiness](https://cloudboundsecurity.com/token-protection-for-web-apps-wackiness/): Remember the asterisk back in Part 1? Token Protection earned one in the mitigation table, right next to a note that it doesn’t do much for you in a browser. I said we’d come back to later on. While here we are. I know you’ve been waiting for this. While wait no longer, because unlike […] - [Agent Identities Are Not Service Principals](https://cloudboundsecurity.com/agent-identities-are-not-service-principals/): Head on over to your audit logs and filter the last 30 days on “Add service principal.” Some of those are not service principals. Microsoft Entra ID logs agent activity under the base identity type the activity originates from. Creating an agent identity blueprint logs as Add application. Creating an agent identity logs as Add […] - [Breaking Up with Your IdP: A Practical Guide to De-Federating from Third-Party Identity Providers](https://cloudboundsecurity.com/breaking-up-with-your-idp/): It seems like weekly now, I’m being pulled into conversations with customers who want to “break up” with their third-party identity provider (IdP). And honestly? I don’t blame them. Some organizations are seeing price increases of 20-50% on IdP renewals, and when you’re already paying for a Microsoft E3 or E5 license, it gets hard […] - [Conditional Access Boot Camp](https://cloudboundsecurity.com/conditional-access-boot-camp/): Conditional Access is one of the best tools in your Microsoft environment for securing access. With it, you can control who, what, where, when, someone or something tries to get in. And sort of why, though it’s really more like the opposite of why. We’ll get there later. I promise. But let’s start at the […] - [AiTM attack mitigation in M365 - Part 1](https://cloudboundsecurity.com/aitm-attack-mitigation-in-m365-part-1/): AiTM attacks have always been that annoying mosquito that just won’t go away. In 2025 and into 2026, that mosquito got a lot bigger. AiTM phishing attacks grew 146% over the past year, and thanks to AI, that number is only heading in one direction. There is a new arms race underway between attackers and […] - [Why Scoping Phishing-Resistant MFA to the Admin Portal Isn't Enough](https://cloudboundsecurity.com/why-scoping-phishing-resistant-mfa-to-the-admin-portal-isnt-enough/): Woohoo! You implemented phishing-resistant MFA for access to the admin portal. That’s great! But… did you actually improve your situation at all? It depends. Do you still have other MFA methods that can be used to sign in to non-admin areas, such as Outlook, SharePoint, or perhaps your profile’s Security Info page? I’m going to […] - [Guest Access in Entra ID: The Tenant's Junk Drawer](https://cloudboundsecurity.com/guest-access-in-entra-id-the-tenants-junk-drawer/): Have you ever looked at your tenant, seen all the guest accounts, and had this reaction? Well, it’s not your fault…. Mostly. There are some default settings within the M365 tenant that kinda set you up for failure. These default settings allow this behavior unless you change them. These settings can be found under Identity […] - [Token Protection Conditional Access Won't Save You From AiTM](https://cloudboundsecurity.com/token-protection-aitm/): A while back, Microsoft released a feature called Token Protection in Microsoft Entra ID. It’s a Conditional Access policy designed to help reduce token theft replay attacks, and if you’re not familiar with token theft, it’s worth a quick explainer before we dig in. Token theft is exactly what it sounds like. An attacker gets […] - [Why EDR alone is not enough for a Domain Controller](https://cloudboundsecurity.com/why-edr-alone-is-not-enough-for-a-domain-controller/): Ahh EndPoint Detection and Response (EDR), the thing that solves everything… oh wait. Oftentimes when I’m meeting with customers, whether they’re big or small, I always ask one question when we’re talking about security: “What security solutions do you have installed on your domain controllers?” Shockingly, I’ve discovered that the answer is either ‘Nothing’ (insert […] - [The whacky behavior of Intune’s retire option (Part 2)](https://cloudboundsecurity.com/the-whacky-behavior-of-intunes-retire-option-part-2/): In my previous article, we explored what happens when you retire an Entra Joined device from Intune. If you didn’t read it, here’s a quick spoiler: it caused some seriously weird behavior. This time, we’re going to approach it properly with an Entra Registered Device that’s being retired from Intune. This could be a BYOD […] - [The whacky behavior of Intune's retire option](https://cloudboundsecurity.com/intunes-retire-option/): Intune offers a handful of ways to offboard a device, whether it’s being booted out of the company for good or just getting repurposed for another user or task. The options are: Retire, Wipe, Fresh Start, and Autopilot Reset. For this article, we’re focusing in on Retire. Microsoft describes Retire like this: “The Retire action […] - [Strings and Win32 deployment in Intune](https://cloudboundsecurity.com/strings-and-win32-deployment-in-intune/): Today, we’re going to talk about “Strings” and how they can simplify deploying Win32 apps. Strings have been a lifesaver for me when dealing with applications that lack proper documentation. You might be wondering, “What are Strings?” Strings are embedded UNICODE data that aren’t easily visible with standard ASCII tools or search programs like grep. […] ## Pages - [Contact Me](https://cloudboundsecurity.com/contact-me/): Connect with me on LinkedIn or email. Whether it is career advice, technical questions, or cat pics, I am always happy to hear from you. Nick Schmitz Principal Security Consultant Email LinkedIn Download Resume I do security things and stuff - [Why you clicking things?](https://cloudboundsecurity.com/gottem/) - [Blog](https://cloudboundsecurity.com/blog/): All Articles A Microsoft cloud security blog focused on real world identity, endpoint, and Zero Trust, mixed with stories from consulting and the occasional chaos of breaking things for fun, or from pure, honest incompetence. Technical depth balanced with humor, curiosity, and lessons learned the hard way. - [Home](https://cloudboundsecurity.com/): Hi, I’m Nick Schmitz Principal Microsoft Security Consultant I design and implement modern security architectures across Microsoft cloud environments, with a focus on identity, endpoint security, and Zero Trust. I am equally passionate about mentoring teams and helping organizations build lasting security capability. Latest Articles Thoughts, tutorials, and insights on building a personal brand online. - [Hi there, I'm Nick](https://cloudboundsecurity.com/about/): My full name is Nick Schmitz, but growing up everyone called me “Schmitdy”. I am a Principal Microsoft Security Architect, hence the name SchmidySec. I’ve spent over six years deep in the Microsoft 365 world helping organizations secure their cloud environments before things go sideways. I work at GuidePoint Security, which has been a great […] ## Optional - [Agent (MCP protocol)](websites-agents.hostinger.com/cloudboundsecurity.com/mcp) [comment]: # (Generated by Hostinger Tools Plugin)