Practical guides on Cyber Essentials Plus, application packaging, endpoint management and Microsoft 365 licensing - written for the people who actually have to do the work. Every claim is sourced and dated.
Mandatory MFA as an auto-fail, two new auto-fail patching questions, cloud services always in scope, and CE Plus retesting that now covers every in-scope device rather than the sample. Already in force - and most organisations have not re-certified against it yet.
Cyber EssentialsWhat counts as high-risk or critical, when the 14-day clock actually starts, what falls inside the assessment boundary, and why "we patch on the second Tuesday" is no longer a defensible policy on its own.
Endpoint managementIntune reports devices with no policy assigned as compliant by default and keeps a dark device compliant for 30 days. Configuration Manager calls a device Active on one signal a week. What the defaults mean, what CcmEval never checks, and the four deadlines that land in October 2026.
PackagingMSIX won on virtual desktops and lost ground on physical endpoints. What it still cannot package, why its tooling has not shipped since May 2024, the signing rules that catch enterprises out, and a triage rule you can apply at intake.
Microsoft 365The tenant setting that hashes every username in every report, which Graph endpoints to use, why usage data produces false negatives, the seven-day seat reduction window, and what actually happens to mailbox and OneDrive data. With July 2026 UK pricing.
Looking for downloadable checklists, playbooks and webinars? Those live on the resources page.
UK-based onboarding · No procurement friction