Kulbir Jaglan

Cybersecurity Consultant

Kulbir Jaglan

Welcome to my blog.

I’ve always been someone who likes to bridge the gap between high-level security and actual engineering. While I spend my days as a Security Architect, I’ve never lost that "builder" itch the kind of curiosity that makes me want to see exactly how a system works under the hood.

My background is a mix of cybersecurity and cloud engineering, and I’ve spent a lot of time deploying AI solutions across Azure, AWS, and Oracle Cloud. For me, it’s not just about making a tool work; it’s about making sure it’s secure, scalable, and actually worth the resources put into it.

My daily role focuses on the big picture, which doesn't always provide the space to experiment with every niche tool or idea I come across. That’s why I started this blog. It’s a place for me to document the projects I’m tinkering with, the logic behind the things I build, and the inevitable lessons I learn along the way.

Thanks for stopping by. I hope you find something here that helps with your own projects.

Latest Posts

Conditional Access Policy Linter
Open-Source Tool

July 25, 2026 · 6 min read

Conditional Access Policy Linter

Conditional Access as code: a read-only linter and drift detector for Microsoft Entra that tells you whether your policies actually enforce what you think they enforce, and what changed since your last review.

View Tool →
Entra ID Identity Attack-Surface Reporter
Open-Source Tool

July 22, 2026 · 4 min read

Entra ID Identity Attack-Surface Reporter

A read-only tool that scans a Microsoft Entra ID tenant for the identity misconfigurations attackers actually use and produces a prioritized, framework-mapped report an executive can act on.

View Tool →
Every Copilot Agent Is Two Identities. You're Probably Only Governing One.

June 24, 2026 · 13 min read

Every Copilot Agent Is Two Identities. You're Probably Only Governing One.

Someone in finance built an agent last week. They used Copilot Studio, described what they wanted in plain language, connected it to SharePoint and th…

Read More →
Entra Authenticates. Your Apps Authorize. That Gap Is Where Access Goes to Hide.

June 19, 2026 · 7 min read

Entra Authenticates. Your Apps Authorize. That Gap Is Where Access Goes to Hide.

A user leaves the sales team. Someone removes them from the "Sales" group in Entra. Clean off-boarding, ticket closed. Three weeks later, an audit fin…

Read More →
The Five Patterns of Cross-Cloud Identity (And Why You're Probably Not in the One You Think)

June 12, 2026 · 9 min read

The Five Patterns of Cross-Cloud Identity (And Why You're Probably Not in the One You Think)

Ask a room of engineers to name their identity architecture and you'll usually get a confident answer. "Hub and spoke. Entra is our source of truth." …

Read More →
Beyond Tool Comparison: The IAM Architecture Decision Matrix

May 28, 2026 · 11 min read

Beyond Tool Comparison: The IAM Architecture Decision Matrix

Last year I was asked to review the identity architecture for a mid-size enterprise. About 3,000 employees, a solid Azure footprint, Oracle HCM for HR…

Read More →