Work with me
Hands-on help securing Entra ID, Intune, Defender and Purview.
Migrating to Microsoft, federating with Microsoft, or working on something already running there? Security and identity are my focus, but send me a short description of whatever you’re dealing with and we’ll figure out the best path from here.
What I help with
Identity and access
Conditional Access designed around how your people actually work: phishing-resistant MFA, token protection, cleaning up guest access, and moving off Okta or Ping to Entra ID.
Related writing
Endpoint security
Intune enrollment, compliance and app deployment, plus Defender for Endpoint and Defender for Identity, rolled out without breaking the devices people depend on.
Related writing
Security assessments
A review of your tenant’s identity, device and data settings against the attacks that actually happen, ending in a written report and a list of fixes in priority order.
Related writing
Data protection
Purview sensitivity labels, data loss prevention and retention, introduced in stages so they protect your data without getting in people’s way.
Certified
SC-401: Information Security Administrator Associate
Projects
A recent client project, and three engagements I offer. Client names are left out, along with anything they wouldn’t want public.
From Google Workspace to Entra ID, with passkeys for everyone
The problemSign-in ran through Google Workspace, several people held permanent global admin rights, and the engineers’ accounts reached cloud infrastructure and source code.
What I didMoved sign-in to Entra ID with YubiKeys for engineering and passkeys for sales, then added a Conditional Access baseline, PIM for admin roles, break-glass accounts that alert when used, and single sign-on for their apps.
The resultAdmin rights are requested when needed instead of held all the time, new starters get their accounts and app access automatically, and the work carries on as an as-needed retainer.
Conditional Access review and rebuild
Good forTenants whose policies grew one exception at a time, or that have never been tested against token theft and device code phishing.
What I doReview every policy and exclusion against how attackers actually get in, then rebuild the gaps in report-only mode and switch them on once the sign-in logs look clean.
What you getA policy set where each policy has a written purpose, and a short list of the exclusions that are still justified.
Getting devices into Intune
Good forCompanies whose laptops aren’t managed yet, or that are moving to Intune from another device management tool.
What I doSet up enrollment, compliance policies and app deployment, pilot with a small group first, then tie device compliance into Conditional Access so only managed devices reach company data.
What you getManaged, compliant devices, apps that install cleanly, and a runbook for adding and retiring devices.
Microsoft 365 security assessment
Good forTeams that inherited a tenant, are preparing for an audit or an insurance renewal, or want to know where they stand.
What I doReview identity, device, email and data protection settings against the CIS benchmark and the attacks that actually happen, then walk your team through what I found.
What you getA written report that explains each finding, and a list of fixes in priority order.
Get in touch
Tell me what’s going on
Email is the best first step. Include roughly how many users you have, your licensing and your timeline, and I’ll reply with whether and how I can help.
Who you’d be working with
Nick Schmitz
I’m a Principal Microsoft Security Architect with over six years in Microsoft 365 security, across identity, endpoints and Microsoft cloud architecture. Before tech I was a sheriff’s deputy and then a police officer, which is where I learned to stay calm and explain things plainly when a situation is going sideways.
- SC-100
- SC-300
- SC-401
- SC-500
- MS-102
- MD-102