tenant@msp:~/journal — bash

ls -la ./posts/

tenant@msp:~/journal find . -name "*.md" | sort -r
shared-mailbox-forwarding-after-offboarding.md -rw-r--r--

Where the Mail Goes After Someone Leaves

Converting a departed employee’s mailbox to a shared mailbox and forwarding it to a distribution group keeps their address alive without handing anyone a second inbox to monitor. Here’s the flow, the four steps, and the one setting to confirm before you close the ticket.

quarantine-policies-defender-office-365.md -rw-r--r--

Two Variables and a Trap: Quarantine Policies in Defender for Office 365

The three built-in quarantine policies differ on exactly two settings, and one of them is a silent ticket generator sitting in every tenant by default. Here’s the decision map, the override that ignores your permissions, and the PowerShell to audit it.

entra-passkey-dynamic-migration-opt-out.md -rw-r--r--

Buying Time Before September 1: The Entra Passkey Opt-Out

On September 1, 2026, Microsoft auto-enables passkeys and flips your registration campaign to Microsoft-managed. There is a tenant-level opt-out — passkeyDynamicMigration — that delays it. Here’s what it actually buys you, why setting it safely needed a script rather than a one-line PATCH, and why February 1, 2027 is the date that can’t be postponed.

fsmo-recovery-when-a-domain-controller-dies.md -rw-r--r--

The DC That Never Came Back: Seizing FSMO Roles Without a Backup

A domain controller dies, it held every FSMO role, and there is no usable backup. It feels like the domain is gone. It usually isn’t — here’s the shape of the recovery, and the one mistake that turns a bad day into a rebuild.

passkeys-by-default-entra-sms-voice-retirement.md -rw-r--r--

Passkeys by Default: What MC1426371 Actually Asks of MSPs

Microsoft is making passkeys the default sign-in and retiring native SMS and voice MFA. MC1426371 sets the clock: passkeys auto-enable September 1, 2026, and Microsoft-provided telecom delivery ends February 1, 2027. Here’s what changes on its own, what quietly changes underneath you, and the two decisions every MSP has to make before the dates arrive.

windows-11-hotpatch-intune.md -rw-r--r--

Let the RMM Go: Why I'd Patch Windows with Intune Hotpatch Instead

Most MSPs patch Windows through their RMM — detect, push, force a reboot. Intune’s hotpatch does the same monthly security work in-memory, no reboot, honoring your rings. Here’s the case for moving Windows quality updates off the RMM and onto the platform built for them.

disable-chrome-password-manager-intune.md -rw-r--r--

Turning Off Chrome's Password Manager with Intune — and Why It's Not as Simple as a Toggle

Disabling Chrome’s built-in password manager through Intune’s settings catalog takes about a minute. Understanding what it actually does — and the two ways it quietly doesn’t do what people assume — is the part that saves you a ticket later.

teams-external-file-sharing-csteamsfilespolicy.md -rw-r--r--

The Missing Attach Button: External File Sharing in Teams and CsTeamsFilesPolicy

When a client says they can’t attach files to an external Teams chat, it usually isn’t broken — it’s working exactly as Microsoft intended. Here’s what’s really happening, and why the fix lives in PowerShell instead of the admin center.

android-app-protection-policy.md -rw-r--r--

How to Find an Android App's Package ID for Intune App Protection Policies

When Intune asks for a Bundle ID to apply an App Protection Policy to a third-party Android app, here’s exactly where to find it — using Vonage as a real-world example.

the-eternal-sprint-claude-mythos-and-the-race-that-never-ends.md -rw-r--r--

The Eternal Sprint: Claude Mythos and the Race That Never Ends

Zeno’s Paradox says you should never cross the room. Defenders have always felt that way. A new class of AI might finally change the math.