Compliance
Practical guidance on Microsoft 365 security, Azure protection, Sentinel SIEM, and managed detection and response. Written by security engineers who configure, harden, and monitor Microsoft environments every day.
Is Outlook HIPAA Compliant? Email Rules, Encryption, and the BAA
Outlook with Exchange Online is in Microsoft's BAA scope; Outlook.com is not. When emailing PHI is permitted and the settings that make it defensible.
Read moreIs OneDrive HIPAA Compliant? BAA Coverage and Required Settings
OneDrive for Business is in Microsoft's BAA scope; personal OneDrive is not. The sharing, DLP, and device settings that make it defensible for PHI.
Read moreIs Microsoft Copilot HIPAA Compliant? BAA Scope and Setup Guide
Microsoft 365 Copilot is in Microsoft's BAA scope, but only a configured tenant supports HIPAA compliance. What to set up before rollout.
Read moreNIS2 Article 21 Mapped to Microsoft Sentinel: What Detection Requirements Actually Mean
Complete mapping of all 10 NIS2 Article 21 requirements to Microsoft Sentinel capabilities. Learn what Sentinel covers, where gaps remain, and how to configure
Read moreNew Microsoft security guidance, when it lands.
One email when we publish. Practitioner analysis on detection, response, and hardening. No product pitches, unsubscribe anytime.



