Blog

Practical M365 security and licensing guidance for solo consultants and small MSPs.

August 14, 2026

What to Include in a Client-Facing IT Security Report (Free Template)

The structure of a good client security report, what to leave out, and how to translate a raw technical finding into something a client actually understands.

August 7, 2026

Microsoft 365 Admin Checklist for Beginners (What to Check First)

Just inherited Microsoft 365 admin duties with no documentation? Here's an ordered first-week checklist covering the four things that matter most.

July 30, 2026

How Many Global Admins Should Your Company Actually Have?

The short answer is 2-4, backed by Microsoft's own guidance and independent research. Here's why, and why 'admins without MFA' is the more urgent version of this question.

July 22, 2026

The Hidden Cost of Unused Microsoft 365 Licenses (And How to Find Them)

Unused Microsoft 365 licenses are a quiet, ongoing cost. Here's where the waste actually hides, real industry data on how common it is, and a worked example.

July 14, 2026

A Plain-English Guide to Legacy Authentication (and Why It's Still Enabled)

What legacy authentication actually is, why it's a real security risk, and why it's still switched on in most Microsoft 365 tenants by default.

July 3, 2026

How to Audit Conditional Access Policies Across Multiple M365 Tenants

A practical walkthrough of what good Conditional Access looks like, the most common real-world gaps, and why checking it by hand doesn't scale past a few tenants.

June 24, 2026

What Microsoft Secure Score Doesn't Tell Your Clients

Secure Score is a solid internal metric, but it wasn't built to hand to a client. Here's the gap, and what a client-facing security report actually needs.

June 12, 2026

CIPP vs. Microsoft 365 Lighthouse vs. ScopedIQ: Which Fits a Solo Consultant?

An honest comparison of CIPP, Microsoft 365 Lighthouse, and ScopedIQ for solo IT consultants and small MSPs managing 5-25 client tenants.