The NSX Microsegmentation Vault: Designing Distributed Firewall Policy Around Applications, Not Perimeters
Designing NSX microsegmentation with distributed firewall policy around applications, using a vault metaphor for workload isolation.
Designing NSX microsegmentation with distributed firewall policy around applications, using a vault metaphor for workload isolation.
Explains why AI agents with shell access and credentials must be secured using zero-trust architecture, treating them as privileged insiders.
Applying zero trust security principles to AI agents in cloud environments, addressing challenges and compliance requirements.
Guide to restricting guest invitation permissions in Microsoft Entra ID for better security and zero trust compliance.
Best practices for managing Global Admin accounts in Microsoft 365, including recommended numbers and PIM usage.
Microsoft Entra Private Access now allows secure, Zero Trust-aligned access for external users to internal resources, moving beyond traditional VPN.
Microsoft Entra Private Access now supports BYOD, allowing registered devices to securely access internal resources without requiring full device management.
Practical guide applying Azure Well-Architected Framework Security pillar principles to real IaaS/hybrid architectures for improved resilience and reduced blast radius.
A developer's journey migrating from Cloudflare Zero-trust Tunnels to Tailscale for a private mesh VPN, detailing setup and benefits.
A developer's 2025 review: transitioning to a DevRel role at Pomerium, diving into security and AI agents via MCP, and giving numerous tech conference talks.
A guide to implementing a Zero Trust security architecture for web applications in Microsoft Azure, covering network security and identity management.
Explores built-in Microsoft Entra Conditional Access bypasses, focusing on device compliance vulnerabilities and security implications.
A guide to setting up Microsoft Intune's Endpoint Privilege Management (EPM) to enforce least-privilege security by allowing controlled, auditable application elevations.
A guide to implementing Zero Trust security principles within Microsoft Azure, covering identity management, network segmentation, and continuous monitoring.
Kubernetes 1.34 focuses on security enhancements, including short-lived registry tokens, scoped anonymous API access, and improved mTLS for pods.
Explores how zero-trust environments like defense and finance can securely adopt AI using local-first agents and semi-autonomous workflows.
A technical guide on enabling and configuring the Microsoft Traffic Profile within Entra ID Global Secure Access, including Conditional Access policies.
Explains the critical role of micro-segmentation in Azure network security, using analogies and Microsoft's zero-trust principles to advocate for proactive defense.
Developer shares their new role as a Developer Advocate at Pomerium, a Zero Trust access control platform, and discusses the company's open-source approach.
A guide to building a personal 'AppRunner' on a single EC2 instance using Cloudflare Zero Trust for secure, internal app hosting.