From Shadow AI to Runtime Protection: Governing Claude Code and Codex with Microsoft Defender

A field implementation for discovering local AI coding agents, scoping the affected Windows devices, and deploying Microsoft Defender AI agent runtime protection through an audit-first rollout.

October 5, 2026 · 9 min · Robel Mehari

OneDrive Moving to onedrive.cloud.microsoft: What Admins Should Check First

OneDrive web URLs are moving to onedrive.cloud.microsoft. Existing links keep working, but admin-owned URL controls need a quick review.

June 17, 2026 · 5 min · Robel Mehari

Defender version compliance with Intune proactive remediations

A field note on using Intune proactive remediations to detect Microsoft Defender version drift, trigger updates, and keep evidence.

June 14, 2026 · 3 min · Robel Mehari

Hunting Zombie Software: How I Automate the Removal of Unauthorized and EOS Apps

Shadow IT is the natural enemy of a clean software inventory. In my environment, users with legacy local admin rights used to install whatever they wanted—unapproved browsers, outdated image editors, and “handy” utilities. These apps quickly became an IT headache, especially when Microsoft Defender for Endpoint flagged them as End-of-Life (EOL) or End-of-Support (EOS). Instead of playing whack-a-mole with individual apps in the portal, I developed a workflow that starts with a deep hunt in Defender and ends with an automated “kill” via Intune. ...

April 15, 2026 · 4 min · eriteach

Windows 11 Upgrade Control Plan: Shift from User-Centric to Device-Centric Servicing

A practical four-lane Windows 11 control plan that fixes mixed upgrade failures by moving servicing assignments from user groups to device groups.

March 6, 2026 · 4 min · Robel Mehari