Solorigate: rethinking supply-chain trust in a Microsoft estate
Solorigate response, week one: what the SolarWinds supply chain attack means for ADFS token-signing certs, federation trust, and what we audited across client estates.
12 notes from 2020. Product names and recommendations reflect that year — not today's catalog. Current notes (2024–)
// 2020 · 12 posts · archive year page
Solorigate response, week one: what the SolarWinds supply chain attack means for ADFS token-signing certs, federation trust, and what we audited across client estates.
Azure AD Connect monitoring, PTA agent redundancy, and staging servers: how we run hybrid identity health as a tier-0 service after this year's 3 a.m. lessons.
Exchange 2010 end of life arrived October 13. A post-mortem on why estates lag — app dependencies, relay sprawl, budget cycles — and what the late migrations taught us.
The Exchange 2010 October 2020 deadline is four weeks out. Our last-call triage: minimal hybrid express paths, what unsupported means, and compliance.
Conditional Access best practices Azure AD: named locations, device compliance, break-glass accounts, report-only mode, and the legacy-auth kill switch.
WVD spring update ARM and Windows Virtual Desktop 2020: Azure portal objects, RBAC, autoscale improvements, migration from classic fall-2019 deployment.
FSLogix best practices and profile container tuning: sizing, Azure Files vs file servers, Outlook cache, exclusions, and the profile-load metric we watch.
Split tunnel VPN Office 365 and Teams: forced tunnel failure under media load, implement optimize paths, latency wins, security objections answered.
Microsoft Teams governance rollout under surge: pilot to company-wide in two weeks, sprawl control, external access, meeting hygiene, deliberate deferrals.
Remote work infrastructure COVID surge: VPN at 4x load, emergency WVD and Citrix capacity, prioritizing critical workers, decisions in 72 hours.
WVD host pool sizing and Windows Virtual Desktop cost field notes: users-per-vCPU by workload, load balancing, autoscale, and telemetry over vendor ratios.
CVE-2019-19781 Citrix ADC mitigation field notes: what we ran on internet-facing NetScaler gateways, indicator sweeps, and trusting an appliance mid-crisis.