Three Threads Through 2024

Endpoint resilience after July, AI becoming a line item, identity under sustained attack — what held up in 2024 and what we are budgeting for next year.

Most year-end reviews list a dozen trends. 2024 needed three. A content update blue-screened eight and a half million Windows machines in a single morning. Generative AI stopped being a pilot and became a budget line with an owner and a renewal date. And the year's most instructive breach began with a password spray against a test tenant nobody remembered owning. Resilience, AI, identity — every consequential engagement we ran this year files under one of them, usually within the first meeting.

Here is what each taught, what our clients changed that actually stuck, and where our 2025 budget advice is landing — with one discipline enforced throughout: nothing below depends on anything unannounced as of this writing. Planning built on roadmap rumors is wishing with a spreadsheet.

Resilience: July as an involuntary audit

We wrote in July about the recovery itself and in August about the engineering that should follow, so this is only the year-end scoring. The outage functioned as an audit nobody scheduled. It tested BitLocker escrow coverage, asset inventory accuracy, deskside surge capacity, and whether recovery decisions had owners — and it graded harshly, publicly, and in a single weekend.

What actually stuck across our client base, four months on. Security-agent content now rides update rings wherever vendors expose the control — and vendors mostly do now; the category-wide contrition of August turned into real configuration surface by autumn. Escrow coverage is a standing quarterly report with a measured minutes-to-key drill attached, not an assumption with a dashboard. Recovery media exists per site and gets refreshed on a calendar, by a named person. And fleet-wide simultaneous failure is now a rehearsed scenario rather than a hypothetical:

2024 drill scorecard, across clients who ran one
live recovery exercise completed        9 of 11
found at least one show-stopper         9 of 9
median time to fix the findings         3 weeks
repeat exercise scheduled for 2025      11 of 11

Every show-stopper was cheap: a bridge number locked inside a dead laptop, key-read rights held by three people in one time zone, a reimage decision with no owner. The expensive part was never the fix. It was going years without the drill that finds it.

Worth recording what did not stick, too. The dual-EDR debate that consumed August steering committees quietly died everywhere we watched it — the management cost became legible within one workshop, and content rings plus rehearsed recovery bought more resilience for less money. The honest risk for 2025 is decay: drill calendars survive their first year on adrenaline and their second on ownership, so the exercise needs a person's name attached, not a team's.

November added the platform half: the Windows resiliency features announced at Ignite — remote recovery of unbootable machines chief among them — are the operating system conceding that July's manual-touch arithmetic was unacceptable. They are previews and commitments, so they sit in our 2025 pilot column, not the 2024 scorecard.

AI: the year it acquired a cost center and a test suite

The Copilot conversation matured the way software conversations eventually do: it became about money and evidence. A 2,200-employee hospitality group we support bought six hundred seats in the spring on enthusiasm. By October, telemetry told the real story — roughly a third of assigned users were weekly actives, a third were occasional, and a third had not opened it in ninety days. We cut to the seats with demonstrated use, wrote down what earning a seat means — weekly activity plus a named workflow — and redeployed the savings toward the two departments with measurable wins, where proposal drafting and month-end close narratives had visibly compressed. The renewal conversation went from religious to actuarial in one meeting, which is the correct direction for renewal conversations.

Two other patterns defined the year. First, every serious Copilot deployment included a permissions and oversharing remediation phase, because grounding search over your tenant is a floodlight pointed at two decades of SharePoint sprawl; the deployments that skipped this step got to run it later, as an incident response. Second, the late-year pivot from assistants to agents — September's Wave 2, November's announcements — moved the governance question from what can it read to what can it do. The position we published in September survived the autumn intact: the systems that work in production are workflows with bounded model steps, scoped tools, and human gates on consequential actions, whatever the marketing calls them. The agent registers and maker permissions we scoped with clients after Ignite extend the same discipline forward: treat every agent as an application with an owner, a scope, and a review date, and the 2025 wave becomes inventory management instead of a new incident class.

The habit we pushed hardest all year: evaluation sets as the new unit test. No prompt, model, or grounding change ships without a scored run against a golden set, and the platform's own version drift makes the harness earn its keep even in weeks nobody changes anything. Clients who adopted this stopped having the it-got-worse-and-nobody-knows-why conversation. That alone justified the build.

Identity: the floor rose, the attacks climbed

January's breach disclosure set the agenda — non-production identity is production attack surface, OAuth grants are durable backdoors, and password spray still finds the one account without MFA. October's note covered the finishing work: standing privilege eliminated through PIM, break-glass on hardware keys with rehearsals, workload-identity hygiene with owners and expiry clocks. The closing months confirmed the direction. Mandatory MFA for the Azure portal and admin centers began enforcement in October; the right response was mild embarrassment that a platform mandate beat some tenants to it, followed by treating it as a floor rather than an achievement.

The attacker adaptation was equally visible. With password attacks increasingly blocked at the front door, the phishing that worked in 2024 was adversary-in-the-middle token theft, and the persistence that lasted was application credentials and consent grants. Hence the rollout order we held to all year: phishing-resistant methods for admins first — effectively done across our clients — with broad user rollout as a 2025 project carrying the hardware-key edge cases. And hence application-identity reviews moving from annual to quarterly in every estate we touch. The one-sentence version of the year: identity attacks stopped being about passwords, and most identity programs have not finished catching up.

The passkey rollouts taught their own small lesson: enrollment is the hard mile, not the technology. The estates that completed admin coverage treated it like an event — keys handed over in person, enrolled on the spot, weaker methods removed the same week — rather than an email campaign with a deadline nobody feared. Broad user rollouts in 2025 will live or die on the same logistics, multiplied by every employee who has never heard the word passkey and is in no hurry to.

The 2025 budget, as we're writing it

Line itemWhat it buysWhy now
Agent governanceregistration, tool scoping, eval gates, kill switchesmaker tools ship before controls; the wave arrives in 2025 with tool access attached
AI platform consolidationnew projects on the rebranded Azure AI stack, standardized eval toolingconsolidation is real but preview-grade; migrate on feature need, never on naming
Windows resiliency adoptionremote-recovery pilot, hotpatch ring, drill cadenceturns July's lesson into platform capability as the previews land
Phishing-resistant completionpasskeys beyond admins, hardware keys for break-glassin the token-theft era, method strength is the control that matters
Workload identity cleanupmanaged identities, certificate migration, orphan deletion clocksthe year's biggest breach lived exactly here
Copilot seat governanceusage-based true-ups, quarterlyseat math beats seat faith, and Finance has learned to ask

Deliberately absent: anything that requires a 2025 announcement to exist. Every line is buildable with what is shipped or in preview today, which remains our test for whether a budget item is planning or wishing. Sequencing matters more than sizing: governance lines land in Q1 while the platform pieces are still previews, platform pilots land mid-year as things reach general availability, and nothing enters Q4 that requires organizational change management, because Q4 absorbs exactly none.

Boring controls won the year

Strip the branding from 2024's marquee failures and the pattern is uncomfortable for an industry that loves novelty: every one was decided by controls that are at least a decade old. Key escrow determined who recovered in a weekend and who recovered in a fortnight. Change rings — extended to one more class of update — determined blast radius. MFA on one forgotten account would have changed January's headline; least privilege on one OAuth app would have contained it. Inventories, drills, owners, expiry dates.

The new technology is genuinely new. The governance is not. Agents will be governed like applications, evals will be run like test suites, and AI platforms will be consolidated like every platform before them. 2025 will bring capability we cannot schedule from here — but the estates that absorb it well will be the ones that spent 2024 practicing the old moves until they became reflexes. That, more than any announcement, is what this year was for.

One prediction we will risk, because it follows from the threads rather than from a roadmap: the workload-identity lesson is about to replay one layer up. Every agent someone ships next year is a new non-human identity holding credentials, and the estates that just spent 2024 hunting ownerless app registrations should recognize the shape of what is coming. The cleanup muscle transfers directly. Start by putting an owner on everything.

If you're facing this

If your 2025 plan currently has more adjectives than line items, December is the month to fix that, and the three threads above make a serviceable table of contents. We build these roadmaps with clients every year about now. Come talk to us.

// related notes
// still relevant?

Facing a migration, platform, or AI build like this one?

If you are shipping something adjacent — RAG, agents, evals, Azure platform — send a brief. We reply within one business day with an honest read on fit.

Start a project →

← Back to notes