- Zen IT Technologies
- Technical notes
Technical notes
The thinking behind the work.
These notes come from the way we design, troubleshoot and run real environments. Each one takes a recurring technical problem and explains what is actually happening, what we look for and how we approach it in practice.
Problems we see again and again.
Short, practical notes on problems we encounter in the field.
-
Network & Infrastructure
Why office Wi-Fi fails at capacity, not coverage
Adding access points to a congested floor usually makes it slower.
-
Identity & Access Management
Single sign-on is the easy half
Authentication is solved. Knowing which accounts should exist is not.
-
Endpoint Management & MDM
What zero-touch actually requires
Registration, managed enrollment, identity, and security state all have to line up before the device is ready.
-
Security Readiness & Response
Reading a fleet-wide detection spike
The shape of the spike identifies it faster than the file analysis does.
-
Email Deliverability
When DKIM passes at the sender and fails at the receiver
A signature covers canonicalized content. Downstream changes can invalidate it.
-
AI Platform Governance
Six questions to ask about an AI platform
The same platform controls as everything else, asked in the right order.
Deeper dives
More specific controls, edge cases and implementation details.
-
Network & Infrastructure
What breaks when a site loses its clock
The symptoms look like authentication and certificate failures, not a time problem.
-
Endpoint Management & MDM
Your identity provider and your MDM are two control planes
Identity and MDM can both hold facts about the same person and device. Authority is which one decides when they conflict.
-
Security Readiness & Response
You cannot investigate what you did not retain
Identity, endpoint, mail and application platforms each stop answering at a different point. The shortest one is your real horizon.
-
AI Platform Governance
Where data actually leaves through an AI platform
The prompt box is the visible path. The connectors and action tools are the larger ones.
-
AI Platform Governance
Set the ceiling before Claude can act
Users can make Claude stricter. They cannot widen connector permissions past the organization policy.
-
Identity & Access Management
Continue with Google is two decisions
The button asks to identify the user. The consent screen asks for the data. Most environments only ever answer the first.
-
Identity & Access Management
Link sharing is the permission nobody revokes
Some sharing grants outlive the person who created them, the review that missed them, and the identity lifecycle around them.
-
Email Deliverability
Authenticated is not authentic
Three passing checks tell you a domain authorized the message. They do not tell you it was yours.
-
Identity & Access Management
The accounts that own everything and belong to no one
Every lifecycle process is built around a person. These accounts do not have one.
-
Endpoint Management & MDM
Managed identity, unmanaged device
A strongly managed identity does not imply a managed or trusted endpoint.
-
Identity & Access Management
The file server nobody provisioned
Nobody decided where external work should live, so it collected in My Drive and stayed there.
-
Identity & Access Management
On-call is an access state
Responsibility for production is temporary. The access attached to it usually is not.