Entra Administrative Units for CMMC Level 2
Most CMMC trouble starts with a simple identity mistake, too many admins with tenant-wide reach. In Microsoft 365, that creates more access than the job requires, and it makes audits…
Most CMMC trouble starts with a simple identity mistake, too many admins with tenant-wide reach. In Microsoft 365, that creates more access than the job requires, and it makes audits…
A spoofed message can undo months of security work in one click. That is why I treat Microsoft 365 DMARC setup as a core security task, not a mail admin…
When I advise defense contractors, I start with a blunt point: casual screen sharing is hard to defend in a CMMC review. If a system can display CUI, every remote…
An assessor won’t accept “we monitor Entra ID” on faith. I need records that show who signed in, what changed, when it happened, and whether the control worked. That is…
A messy Azure tenant can turn a CMMC review into a scavenger hunt. Small contractors rarely have extra staff, spare budget, or time to clean up cloud decisions after the…
A CMMC gap often starts as a small mismatch. The policy says one thing, the endpoint does another, and the reporting still looks fine until someone checks the real device…
A missing VPN log can turn a simple assessor question into a long week. For small contractors, CMMC VPN logging is less about fancy dashboards and more about proving remote…
One bad sign-in can punch a hole through an otherwise well-managed admin workstation. In a CMMC Level 2 environment, that matters because privileged devices sit close to your identity plane,…
If Wi-Fi can reach Controlled Unclassified Information, it can widen your CMMC exposure fast. I see small contractors miss this because wireless feels informal, while the assessor sees it as…
A weak internal audit shows up late, usually when a contract is on the line and the evidence binder is thin. When I build a CMMC internal audit checklist for…