- Zen IT Technologies
- Technical notes
Technical notes
The thinking behind the work.
These notes come from the way we design, troubleshoot and run real environments. Each one takes a recurring technical problem and explains what is actually happening, what we look for and how we approach it in practice.
Problems we see again and again.
Short, practical notes on problems we encounter in the field.
-
Network & Infrastructure
Why office Wi-Fi fails at capacity, not coverage
Adding access points to a congested floor usually makes it slower.
-
Identity & Access Management
Single sign-on is the easy half
Authentication is solved. Knowing which accounts should exist is not.
-
Endpoint Management & MDM
What zero-touch actually requires
Registration, managed enrollment, identity, and security state all have to line up before the device is ready.
-
Security Readiness & Response
Reading a fleet-wide detection spike
The shape of the spike identifies it faster than the file analysis does.
-
Email Deliverability
When DKIM passes at the sender and fails at the receiver
A signature covers canonicalized content. Downstream changes can invalidate it.
-
AI Platform Governance
Six questions to ask about an AI platform
The same platform controls as everything else, asked in the right order.
-
Email Security
Authenticated is not authentic
Three passing checks tell you a domain authorized the message. They do not tell you it was yours.
Deeper dives
More specific controls, edge cases and implementation details.
Network & Infrastructure
-
What breaks when a site loses its clock
The symptoms look like authentication and certificate failures, not a time problem.
-
Eleven VLANs and one flat network
Separating the broadcast domain is the easy part. Where the gateway sits determines where the boundary can actually be enforced.
-
The deny rule that never fires
A firewall rule can remain in the configuration while policy order makes it ineffective.
Identity & Access Management
-
Continue with Google is two decisions
The button asks to identify the user. The consent screen asks for the data. Most environments only ever answer the first.
-
Link sharing is the permission nobody revokes
Some sharing grants outlive the person who created them, the review that missed them, and the identity lifecycle around them.
-
The accounts that own everything and belong to no one
Every lifecycle process is built around a person. These accounts do not have one.
-
The file server nobody provisioned
Nobody decided where external work should live, so it collected in My Drive and stayed there.
-
On-call is an access state
Responsibility for production is temporary. The access attached to it usually is not.
-
Your Okta logs are already a security feed
The System Log records the administrator change. Whether anybody sees it is a separate decision.
-
The login path that survived the migration
Federating an application does not remove every way users could get in before the migration.
-
The push succeeded and nothing changed
An account can be provisioned correctly on day one and still stop receiving profile updates afterwards.
Endpoint Management & MDM
-
Your identity provider and your MDM are two control planes
Identity and MDM can both hold facts about the same person and device. Authority is which one decides when they conflict.
-
Managed identity, unmanaged device
A strongly managed identity does not imply a managed or trusted endpoint.
Security Readiness & Response
-
You cannot investigate what you did not retain
Identity, endpoint, mail and application platforms each stop answering at a different point. The shortest one is your real horizon.
-
The vendor with nothing to assess
No certification, no report and no security page does not end the review. It changes the question you need to answer.
-
Half the report is about you
The vendor's controls can depend on things you are expected to do. SOC 2 reports have a section that tells you what they are.
-
A clean opinion is not a clean report
The opinion answers an important question. It does not tell you whether the report covers everything you need it to cover.
Email Deliverability
-
The message is full of other people's domains
Your sending domain can be healthy while links, images and tracking services inside the message introduce reputation you do not control.
-
Your own systems are the ones getting caught
A business platform can send legitimate mail using your visible domain while authenticating as somebody else.
AI Platform Governance
-
Where data actually leaves through an AI platform
The prompt box is the visible path. The connectors and action tools are the larger ones.
-
Set the ceiling before Claude can act
Users can make Claude stricter. They cannot widen connector permissions past the organization policy.
-
The allowlist entry is a hostname, not a destination
A network exception that looks like one workflow may authorize much more, depending on what the control actually matches.
-
Just-in-time is half a lifecycle
SSO decides who can log in. On Team with JIT, deprovisioning is still manual.
-
Four paths around the ceiling
Connector permissions govern connector tools. Extensions, local MCP, Console keys and personal accounts sit on other control planes.
-
Tested as someone who cannot change it
A ceiling that has only been seen from the Owner account is an assumption.
-
The log is in the other system
Team has no single audit trail across every Claude surface. Build the picture from telemetry, exports and the systems Claude touched.
-
Raise the seat, not the limit
A low overuse cap is a detector. The seat tier is the budget.
Email Security
-
The inspection service is a mail hop
Adding a detector to the mail path changes routing, authentication and failure behavior before it changes any policy.
-
A signature covers the message, not the route
DMARC enforcement stops mail that fails its checks. It cannot make legitimately authenticated mail harmless.
-
The impersonation policy nobody populated
Turning on impersonation protection is only the start. Check who and what the platform is actually protecting today.
-
The mail settings nobody files under security
Delegation decides who can read a mailbox. Send-as decides who can speak for it. Forwarding decides where its mail can leave.
-
Nothing requires anyone to encrypt mail to you
Opportunistic TLS usually works. MTA-STS tells supporting senders when falling back to an untrusted connection is no longer acceptable.
-
Quarantine is a queue, not custody
Holding a message creates an operational responsibility. Check retention, reviewers, sender visibility and the release path before trusting the queue.