Skip to content
View 0125joel's full-sized avatar

Organizations

@Microsoft-EMS-Community

Block or report 0125joel

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
.github/profile/README.md

👋 Hey there, I'm Joël

Microsoft 365 security consultant who builds identity, device, and access solutions with security baked in from the design, not bolted on afterwards.

Website LinkedIn X

"Security that fits, not security that fights."

🔐 The stack I live in

  • Microsoft Entra ID: Conditional Access and PIM, tied together so access follows the role, not the person's mood that day
  • Microsoft Intune: devices that are compliant without anyone noticing they are
  • Microsoft Defender: catching the stuff Conditional Access didn't block
  • PowerShell & Microsoft Graph: if I do it twice by hand, it becomes a script
  • Azure Logic Apps: for whatever native Microsoft 365 just can't do on its own

Microsoft Entra ID   Microsoft Intune   Microsoft Defender   PowerShell   Azure

🚀 Focus areas

  • Building Zero Trust solutions that actually work in the real world: pros, cons, and lessons learned
  • Exploring the balance between usability and security, because blocking everything isn't strategy 😉
  • Moderator on the Microsoft EMS Discord, co-organizer of the Microsoft EMS Community Summit

Microsoft EMS Community   Join us on Discord

🛠️ What I build

Most of what I write about ends up running somewhere: a script, a module, a Logic App tucked into a client's tenant. These are the ones worth sharing publicly.

PIM Manager Open source dashboard for visualizing and managing Entra ID PIM assignments. Self-hosted by other organisations too, which still surprises me every time someone mentions it.

PIM Monitor My own interpretation of Enterprise Access Management model classifying Entra roles across control plane, management plane, and data plane. Built because I was tired of guessing which role belonged where, and so was everyone I asked.

IntoTheCloud Where the tools and scripts from actual client work land once they're clean enough to share. First up: a Logic App that tags PIM-eligible admins so Conditional Access can pull them out of standard end-user SSPR, because eligible isn't the same as harmless.

IntuneLaps PowerShell module that pulls the Intune LAPS username and password straight from the tenant. Small, does one thing, does it fast.

🧩 What drives me

Helping teams get clarity, stay secure, and move fast, without vendor noise or buzzwords.

Let's connect if you care about Microsoft 365 security, real-life automation, and learning together.

Pinned Loading

  1. PIM-Manager PIM-Manager Public

    TypeScript 5 1

  2. IntuneLaps IntuneLaps Public

    Powershell module to get the Intune LAPS Username and Password easily from the tenant

    PowerShell 5 1

  3. PIM-Monitor PIM-Monitor Public

    Continuous monitoring of Microsoft Entra ID PIM changes via Azure DevOps Pipelines

    PowerShell 1

  4. IntoTheCloud IntoTheCloud Public

    Tools and scripts from real Microsoft 365 and Azure consulting work.

    PowerShell

  5. Microsoft-EMS-Community/Cloudhour Microsoft-EMS-Community/Cloudhour Public

    Cloudhour topic suggestions and links go here

    3