Entra ID governance
Access packages, entitlement management, lifecycle workflows, and Privileged Identity Management — designed, then pushed until the edge cases show up.
Prestige Worldwide is an independent lab built around Microsoft 365, Entra ID, and Microsoft Defender. Access packages, conditional access, detection rules, hybrid identity — configured, attacked, and measured in a tenant nobody depends on. A local AI thread runs alongside it, on the same footing as everything else here: nothing ships until it's been tested.
Mostly Microsoft security and identity, with an AI thread that keeps intersecting it. Six areas, all tested against a tenant built to be broken.
Access packages, entitlement management, lifecycle workflows, and Privileged Identity Management — designed, then pushed until the edge cases show up.
Defender for Endpoint, Defender for Identity, Defender for Cloud Apps — tuned, correlated through XDR, and tested against activity that looks like an attacker.
KQL against Sentinel and Defender schemas. Every detection gets a false-positive rate, not just a true-positive demo.
Conditional access design, device compliance, and the segmentation decisions that determine whether "trust nothing" actually holds under load.
AD DS to Entra ID, hybrid join, sync engine behavior, and the migration patterns that hold up outside a whitepaper.
Graph and PowerShell automation, plus agent-security work that borrows heavily from the identity threat model above.
Each project page carries the tenant configuration, what was measured, and what broke first.
active
Access packages and lifecycle workflows built the way a real directory would need them, then load-tested against the approval and expiry cases that don't show up in a demo.
active
KQL detections written against Defender and Sentinel telemetry, then run against simulated attacks to find the false-positive rate before anything reaches a real queue.
ongoing
Moving a legacy AD DS domain onto native Entra ID Governance — hybrid join, sync behavior, and the parts of a directory migration that only surface once real objects are in motion.
Reference material worth the read, sorted by what it's actually good for.
Governance documentation, the Graph PowerShell SDK, and Zero Trust guidance that survives contact with a real tenant.
Product documentation and the open-source detection content worth reading before you write your own.
ATT&CK, Atomic Red Team, Sigma, and the KQL reference — the toolkit behind every rule on this site.
If you're deep in Entra ID, Defender, or detection engineering, I'm glad to compare notes — or talk through how this applies to your environment.