<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Microsoft 365 security, from architecture to the battlefield. on Juan Pazó</title><link>https://www.juanpazo.com/</link><description>Recent content in Microsoft 365 security, from architecture to the battlefield. on Juan Pazó</description><generator>Hugo</generator><language>en</language><lastBuildDate>Thu, 13 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://www.juanpazo.com/index.xml" rel="self" type="application/rss+xml"/><item><title>Device cleanup in Intune: a stale record is not a retired device</title><link>https://www.juanpazo.com/posts/device-cleanup/</link><pubDate>Thu, 13 Aug 2026 00:00:00 +0000</pubDate><guid>https://www.juanpazo.com/posts/device-cleanup/</guid><description>&lt;p>The cleanest Intune portal is not necessarily the healthiest device estate. A record can be stale because a device was replaced, rebuilt, offline for legitimate reasons, or managed through a different channel. It can also be the only remaining evidence that a device still has a BitLocker recovery key or an Entra identity.&lt;/p></description></item><item><title>Entra application hygiene: investigate the workload identity, not the display name</title><link>https://www.juanpazo.com/posts/entra-app-hygiene/</link><pubDate>Thu, 13 Aug 2026 00:00:00 +0000</pubDate><guid>https://www.juanpazo.com/posts/entra-app-hygiene/</guid><description>&lt;p>An Entra application called &lt;code>test&lt;/code>, &lt;code>old&lt;/code>, or &lt;code>do-not-use&lt;/code> is not evidence that it is safe to remove. The same is true in reverse: a reassuring display name does not make an application safe. Start with what the workload identity can do, how it authenticates, and who can explain its purpose.&lt;/p></description></item><item><title>Governing BYOAI on managed devices: from visibility to a defensible block</title><link>https://www.juanpazo.com/posts/governing-byoai/</link><pubDate>Thu, 13 Aug 2026 00:00:00 +0000</pubDate><guid>https://www.juanpazo.com/posts/governing-byoai/</guid><description>&lt;p>BYOAI is usually framed as shadow IT with a better user experience. Someone has a question, a deadline, or a document that needs improving. A public AI tool is one browser tab away. The risk is real, but the human need is real too.&lt;/p></description></item><item><title>Guest access hygiene: review the relationship, not only the account</title><link>https://www.juanpazo.com/posts/guest-hygiene/</link><pubDate>Thu, 13 Aug 2026 00:00:00 +0000</pubDate><guid>https://www.juanpazo.com/posts/guest-hygiene/</guid><description>&lt;p>A guest account is the technical trace of a business relationship. Removing old guests can be useful, but a date field alone cannot tell you whether a supplier engagement, project, legal matter, or shared workspace is still active.&lt;/p>
&lt;h2 id="start-with-the-resource">Start with the resource&lt;/h2>
&lt;p>The useful question is not “when did this guest last sign in?” It is “what does this person still have access to, who sponsored it, and when should that access end?” A guest can be inactive and still be the only external owner of a shared artefact. A recently active guest can still have access that is no longer justified.&lt;/p></description></item><item><title>Orphaned OneDrives: prove ownership, retention, and recovery before changing scope</title><link>https://www.juanpazo.com/posts/orphaned-onedrive/</link><pubDate>Thu, 13 Aug 2026 00:00:00 +0000</pubDate><guid>https://www.juanpazo.com/posts/orphaned-onedrive/</guid><description>&lt;p>An unlicensed or inactive OneDrive is not automatically disposable. It can contain project evidence, personal working files required for a case, or content subject to retention. “Orphaned” should be a conclusion from evidence, not a label created by a storage report.&lt;/p></description></item><item><title>SharePoint archiving: select the access model before selecting the storage tier</title><link>https://www.juanpazo.com/posts/sharepoint-archival/</link><pubDate>Thu, 13 Aug 2026 00:00:00 +0000</pubDate><guid>https://www.juanpazo.com/posts/sharepoint-archival/</guid><description>&lt;p>Archiving a SharePoint site is a change to access, ownership, recovery, and compliance. Storage cost matters, but it is the last question I ask, not the first.&lt;/p>
&lt;h2 id="begin-with-a-decision-record">Begin with a decision record&lt;/h2>
&lt;p>For each site, document the business purpose, accountable owner, last meaningful activity, external sharing, sensitivity and retention state, eDiscovery considerations, expected retrieval time, and future disposition date. “No recent edits” is a useful signal. It is not an archival decision by itself.&lt;/p></description></item><item><title>When SharePoint storage grows, investigate retention before deleting files</title><link>https://www.juanpazo.com/posts/retention-storage/</link><pubDate>Thu, 13 Aug 2026 00:00:00 +0000</pubDate><guid>https://www.juanpazo.com/posts/retention-storage/</guid><description>&lt;p>Large files are visible. Retention side effects often are not. That is why a storage incident can become a compliance incident when somebody responds by changing a policy before understanding what is preserving the content.&lt;/p>
&lt;h2 id="deletion-and-storage-reclamation-are-different-events">Deletion and storage reclamation are different events&lt;/h2>
&lt;p>When SharePoint or OneDrive content is retained, Microsoft can preserve the original version in the Preservation Hold library after a user edits or deletes it. The user may see a file disappear while the tenant still retains a copy. Microsoft explains the workload-specific behaviour in &lt;a href="https://learn.microsoft.com/en-us/purview/retention-policies-sharepoint">retention for SharePoint and OneDrive&lt;/a>.&lt;/p></description></item><item><title>About</title><link>https://www.juanpazo.com/about/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.juanpazo.com/about/</guid><description>&lt;p>I am a Technology Specialist focused on making Microsoft 365 security work in
the real world.&lt;/p>
&lt;p>My route into tech was not a straight line. I have been a golf-course gardener,
flipped burgers at McDonald’s, opened a pub at 23, worked in Apple Support in
Ireland, and spent time in digital marketing before moving into technology. I
am a multipotentialite. I like learning widely, connecting ideas, and making
difficult things feel understandable.&lt;/p></description></item></channel></rss>