Mapping real controls to real config — no consultants, no fluff.
Most SOC 2 guides are written by auditors. This one is written by the person who actually had to build the evidence folder, sign the policies, and keep the lights on at the same time. I ran the full SOC 2 programme at Nablon — solo — covering identity, endpoint, cloud infrastructure, and HR controls across all five Trust Service Criteria.
- 01
Deploying Microsoft Defender for macOS via Intune — The Real Troubleshooting Path
“No license found” on a correctly licensed tenant is almost never a licensing problem. The profile stack, the gotchas, and how to validate at three layers.
Intermediate6 min - 02
What SOC 2 actually wants from your endpoints
Compliance policies, encryption, EDR — and how to prove all three with Intune screenshots alone.
Coming soon - 03
Building your evidence folder from scratch
How I structured 11 folders, named every file, and never once said a flat “No” to an auditor question.
Coming soon - 04
Conditional Access as a SOC 2 control
CA001 through CA006 — what each policy covers, and which TSC criteria it satisfies.
Coming soon - 05
40 policies, one person, Zoho Sign
How to get policies written, approved, and signed without a legal team or a week of your life.
Coming soon - 06
The N/A trap — and how to avoid it
Why “we don’t do that” kills your audit, and how to write justifications that actually hold up.
Coming soon
More lessons coming. Follow along on LinkedIn →