Governing BYOAI on managed devices: from visibility to a defensible block
13 August 2026
BYOAI is usually framed as shadow IT with a better user experience. Someone has a question, a deadline, or a document that needs improving. A public AI tool is one browser tab away. The risk is real, but the human need is real too.
Guest access hygiene: review the relationship, not only the account
19 February 2026
A guest account is the technical trace of a business relationship. Removing old guests can be useful, but a date field alone cannot tell you whether a supplier engagement, project, legal matter, or shared workspace is still active.
Start with the resource
The useful question is not “when did this guest last sign in?” It is “what does this person still have access to, who sponsored it, and when should that access end?” A guest can be inactive and still be the only external owner of a shared artefact. A recently active guest can still have access that is no longer justified.
Entra application hygiene: investigate the workload identity, not the display name
22 January 2026
An Entra application called test, old, or do-not-use is not evidence that it is safe to remove. The same is true in reverse: a reassuring display name does not make an application safe. Start with what the workload identity can do, how it authenticates, and who can explain its purpose.