About
My name’s Carl. I’m an IT architect and security engineer in Boston, Massachusetts. I work closely with venture-backed biotech companies during stages where the science has to come first. Time to focus on security and technology becomes limited, and as a result, environments are built fast and cheap.
My goal here is not to write articles attempting to convince leaders to shift their focus away from the science. My intention is to provide guidance and resources to those of us trying to find the balance between novel science and enterprise security.
Most Microsoft writing isn’t aimed at that. It almost always assumes a large estate and teams that can handle large remediations. Early-stage biotech is harder, and bad decisions don’t hurt for two years.
Working with Entra ID, Conditional Access, and how device compliance feeds into access decisions, I’ll do my best to provide guidance for anyone thinking of properly securing their science.
What’s here
Decision records and design reviews, and a few step-by-step walkthroughs. Options considered, what was chosen, and what it cost. Most of it applies to anyone running Entra ID and endpoint management. Some is specific to regulated research.
Client work
I don’t name clients or the companies I’ve worked with. When I need a concrete example I use the same made-up company every time:
Vandelay Therapeutics. 42 people, Series B, Entra with no on-prem AD, 70/30 Windows/Mac, two CRO partners and an academic collaborator who need access, four lab workstations bolted to instruments that can’t be enrolled in anything, entering IND-enabling studies in eighteen months.
Vandelay isn’t real to anyone except George Costanza.
If I get something wrong
Please reach out. Microsoft changes behavior constantly and I would rather fix a post than leave it wrong. If I change something substantive I’ll note it on the post rather than editing quietly.