New Entra Chat! ποΈ Christina Morillo, Senior Director of InfoSec for the New York Giants, shares her journey from help desk to security leader.
Learn why a "learn-it-all" mindset & storytelling are essential for growth. π

| Website | https://merill.net/about/ |
| https://twitter.com/merill | |
| https://www.linkedin.com/in/merill | |
| GitHub | https://github.com/merill |
| Profile | He/Him |
| Newsletter | https://entra.news |
New Entra Chat! ποΈ Christina Morillo, Senior Director of InfoSec for the New York Giants, shares her journey from help desk to security leader.
Learn why a "learn-it-all" mindset & storytelling are essential for growth. π
π Check out this new Microsoft Entra blog post π
Run Global Secure Access with confidence: Introducing the GSA Operations Guide
π Check out this new Microsoft Entra blog post π
Build AI agents for production with secure identities from day one
This week I'm starting work on my micro startup: Jozra
Landing site is up at jozra.com
The name has a special meaning to me. It's a combo of my children's names.
Iβm excited, nervous, and very ready to build in public.
Iβll be sharing the founder journey here as I build.
Follow along.
π Check out this new Microsoft Entra blog post π
What's New in Microsoft Entra: June 2026
Have you had a chance to read this week's Entra.News?
Read at https://entra.news/p/entra-news-151-this-week-in-microsoft
Passkeys are easy to demo.
Rolling them out to millions of users? Thatβs where things get interesting.
In this episode of http://Entra.Chat, Vincent Delitz shares 5 practical lessons from large-scale passkey deployments.
Watch the full episode at https://entra.news/p/5-lessons-from-rolling-out-passkeys
The goal is simple:
π Make secrets rare.
π Make permissions least privileged.
π Make app authentication intentional.
π« Because attackers donβt need your usersβ passwords if they can get access to your app secrets.
14/14
Also make sure you have a process to regularly review:
App owners
Credential expiry
Unused apps
Graph/API permissions
High privilege service principals
Apps with secrets
Apps without recent sign-in activity
PS We'll go into these in upcoming tips...
13/14
Hardening actions I recommend:
β
Move apps away from shared secrets
β
Use Managed Identity for Azure resources
β
Use Workload Identity Federation where possible
β
Deploy Conditional Access for workload identities
β
Implement secret scanning
β
Monitor risky app credentials
12/14