Blog

Practical Microsoft security guidance from Patriot Consulting's engineers and MVPs — Defender XDR, Sentinel, Entra, Intune, Purview, and Exchange Online.

NIST Proves It: AI Security Is Never "One and Done"

NIST has published a mathematical proof that no finite set of AI guardrails can stop every adversarial prompt. The takeaway for defenders: AI security is never "one and done" — it demands continuous monitoring and updating.
Read more

Microsoft vs Proofpoint: 2026 Fortune 500 Email Security Update

Microsoft email security continues its steady march through the Fortune 500. Since 2019, we have run our DNS-based email recon tool against the Fortune 500 public DNS records to track who's handling inbound mail — and the trend lines are clear.
Read more

Unable to find type [short] Set-OrganizationConfig -RejectDirectSend $true

If you don't have a valid use of DirectSend in Exchange Online, Microsoft recommends that you disable it with this Exchange Online PowerShell cmdlet below. This is a follow-up post to our previous post.
Read more

An improved approach to blocking Direct Send Abuse

Guest post by Chris Lehr Executive Summary If you are a Microsoft 365 customer and you are seeing an uptick of spam and phish emails sent to your domain, but also from your domain that seem to be getting through.
Read more

Federating Identities between two MS365 Tenants for Collaboration

A customer asked me for guidance to federate identities between two Microsoft 365 organizations for the purpose of document collaboration. My approach was to start off with the Claude4 AI LLM then I im...
Read more

The Clock is Ticking on Windows 10: Are You Intune with What Comes Next?

By Joe Stocker, Founder & Microsoft Security MVP, Patriot Consulting Windows 10 support officially ends on October 14, 2025. And while your devices won’t suddenly stop working, the protection behind them...
Read more

Microsoft vs Proofpoint

Microsoft Email Security picks up 13 new Fortune 500 companies in the past 10 months, growing at 11%. Between Microsoft and Proofpoint, they have captured 76% of the email security market.
Read more

Migrating from OKTA to Microsoft Entra can pay for the entire XDR Suite

When I meet customers using OKTA as their Identity and Access Management, the following three questions often come up: 1 is Microsoft as good or better? 2 Can I save money by consolidating to Microsoft?
Read more

Mitigating AiTM Token Theft in 2025: Why It’s Time to Adopt Passkeys

Mitigating MiTM Token Theft in 2025: Why It’s Time to Adopt Passkeys Introduction: Rising Threat of Token Theft Attacks Adversary-in-the-middle AiTM phishing attacks have evolved to target even multi-level authentication.
Read more

Top misconfigurations in Microsoft Email Security

This is a guest post by Chris Lehr, Patriot’s top email security expert. 1 Configuration of Allow Lists in an insecure manner If you have usage of an Antispam Allow List.
Read more

Microsoft Copilot for Security (6 months later)

Since I last wrote about Microsoft Security Copilot on launch day in April, I have gained insight into its impact and usability.
Read more

Microsoft gains on Email Security Market

Microsoft has gained 9% market share in the email security among the Fortune 500 since I last checked in August 2023.
Read more

First Impression of the unified Sentinel and Defender XDR Portal

On April 3rd, 2024, Microsoft’s new Unified Portal became public preview, where anyone running their Sentinel SIEM can connect to the Microsoft Defender XDR Portal.
Read more

Purchase and Deploy Microsoft Security Copilot

Beginning April 1st, 2024, you can now purchase and deploy Microsoft Security Copilot. The setup process takes less than 5 minutes to complete.
Read more

The Novelty Effect of Copilot for Microsoft 365 (Part one of two)

In our recent analysis of Copilot for Microsoft 365, we observed a notable trend: a 64% decrease in user interactions with Copilot over a 9-week period. This decline suggests a concerning "Novelty Effect".
Read more

Microsoft Copilot for Security Pricing

Microsoft Secure 2024 was a digital two-hour event held on 3/13/2024. If you missed the event, you can watch the recording on demand here.
Read more

Error: "You don't have access to this" could be from Device Code CA Policy

I consider myself an early adopter of most Microsoft security controls, not just to protect our own organization, but with the goal to help the community understand the potential benefits and impacts of these solutions.
Read more

Guarding the Gatekeepers: Combatting UEFI-Bypassing Bootkits with Practical Cybersecurity Measures

Imagine wiping your computer clean, thinking you've washed away every digital threat. But what if the infection persisted, hidden deep within the very core of your system? That's the chilling reality of modern cyber threats.
Read more