From a Blog Series to a Book – The Unexpected Journey of The Privileged Path
If you’d told me a couple of years ago that I’d write a book, I’d have laughed.
I’m not a writer by nature.
I failed my English GCSE. I have ADHD and dyslexia, and for most of my career the hardest part wasn’t understanding technology, it was getting the ideas out of my head and onto a page in a way that others could follow.
But I’ve always enjoyed writing.
Not because I think I’m particularly good at it, but because writing forces me to slow down, organise my thoughts and challenge my own assumptions. Over the years that’s taken the form of blog posts, technical articles, conference sessions and the occasional LinkedIn post.
Back in 2024, I started planning what I thought would be a series of blog posts about privileged access, that was all it was ever meant to be.
It Started with an Observation
As a consultant, I spent years reviewing customer environments, designing new Microsoft 365 tenants and helping organisations strengthen their security posture.
Whether it was a small business with Microsoft 365 Business Premium or a large enterprise running Entra ID P2, I kept seeing the same pattern.
- The tools were there.
- The licences had been purchased.
- Conditional Access was configured.
- Privileged Identity Management (PIM) was enabled.
- Multi-Factor Authentication had been rolled out.
On paper, everything looked secure.
But privileged access still wasn’t being secured in the way I’d expect.
Time and time again I’d hear things like:
“We’ve got PIM, so we’re covered.”
“We’ve enabled Conditional Access.”
“All our administrators use MFA.”
Those are all important controls.
But they’re not a privileged access strategy.
They’re individual pieces of a much bigger picture.
And that was the observation that started everything.
The More I Wrote…
Originally I wanted to write about why Privileged Identity Management on its own isn’t enough.
Then I realised I needed to explain identity separation first.
That naturally led into Zero Trust.
Then Conditional Access.
Then authentication strength.
Then phishing-resistant authentication.
Then FIDO2 security keys.
Then Privileged Access Workstations.
Then monitoring.
Then governance.
Every article depended on another.
The more I wrote, the more I realised this wasn’t really a blog series anymore.
It had become something much bigger.
It had become The Privileged Path.
More Than Just Microsoft
One thing that became increasingly important while I was writing was making sure this wasn’t simply another Microsoft book.
Yes, the examples use Microsoft terminology.
You’ll read about Microsoft Entra, Conditional Access, Privileged Identity Management (PIM), Privileged Access Workstations (PAWs), RBAC and other Microsoft technologies because that’s the ecosystem I work in every day.
But the principles themselves aren’t Microsoft principles.
- They’re security principles.
- Identity.
- Trust.
- Least privilege.
- Isolation.
- Governance.
- Operations.
Whether you’re securing Microsoft Entra or another identity platform entirely, the same questions still apply. The technologies may differ, but the security principles remain the same.
- How do you separate privileged identities?
- How do you establish trust?
- How do you reduce standing privilege?
- How do you isolate privileged activity?
- How do you monitor privileged access?
- How do you ensure it remains secure over time?
Technology changes. Good security principles don’t.
That’s why, although the examples throughout the book are Microsoft-focused, the framework itself is intentionally platform agnostic. The technologies may differ, but the thinking remains the same.
What’s Inside the Book?
By the time I’d finished, the book had grown into sixteen chapters that take the reader through the complete lifecycle of privileged access.
It covers topics including:
- The foundations of privileged access and why so many organisations get it wrong.
- Zero Trust and what it really means for privileged identities.
- Designing identity separation and reducing the attack surface.
- Authentication, Conditional Access and phishing-resistant MFA.
- Privileged Identity Management (PIM) and just-in-time administration.
- Privileged Access Workstations (PAWs) and why isolation matters.
- RBAC and designing for least privilege.
- Monitoring, auditing and detecting privileged activity.
- Governance, access reviews and operational resilience.
- Building a practical roadmap for improving privileged access over time.
It isn’t intended to be another feature guide.
Microsoft already documents what these technologies do.
What I wanted to explain was how they fit together.
Because that’s the part I found organisations struggling with.
More Than Human Identities
While I started writing about privileged users, the identity landscape has continued to evolve.
Today we’re not just protecting people.
We’re protecting service principals.
Managed identities.
Applications.
Automation.
Machine identities often hold highly privileged permissions, and they’re becoming just as important to secure as human administrators.
That’s one of the reasons I’m already working on the second edition.
Not because the first edition is wrong.
But because our industry never stands still.
AI Changed the Way I Write
There’s another reason this book exists. AI.
Tools like ChatGPT, M365 Copilot and Claude haven’t written this book for me.
The ideas, opinions, designs and lessons all come from years of customer projects, lab work, research and experience.
But AI has made writing accessible in a way it never was before.
With my dyslexia and ADHD, AI has become an incredible partner.
It helps me organise thoughts, improve structure, refine wording and communicate ideas more clearly than I could have managed on my own.
For me, that’s one of the most exciting uses of AI, not replacing expertise, but helping people share it.
Looking Back
Looking back over the last eighteen to twenty-four months, what started as a few blog posts turned into one of the biggest professional challenges I’ve ever undertaken.
Writing the book forced me to question:
- Every recommendation.
- Every design decision.
- Every diagram.
- Every opinion.
And I genuinely believe it’s made me a better architect because of it.
The funny thing is…
I barely finished the first edition before I started making notes for the second.
Microsoft evolves.
Threats evolve.
Identity evolves.
My own thinking evolves.
Which brings me back to something I say regularly:
Zero Trust isn’t a destination. It’s a journey.
It turns out writing this book has been one as well.
I hope that The Privileged Path helps organisations, architects and administrators think a little differently about privileged access, not as a collection of features or checkboxes, but as a complete security strategy.
Because in my experience, the biggest challenge isn’t that organisations don’t have the right tools.
It’s that they haven’t yet connected them together in the right way.
For someone who failed English at school and has lived with ADHD and dyslexia throughout my career, seeing my name on the cover of a published book still feels a little surreal.
But if sharing what I’ve learned helps organisations, architects and administrators build a more secure approach to privileged access, every late night spent writing it was worth it.
The Journey Continues
What started as a handful of blog posts has become a published book.
The Privileged Path is now available on the Amazon Kindle Store for £9.99.
If you’ve enjoyed my blogs, LinkedIn posts, or found any of my content useful over the years, I’d be incredibly grateful if you’d consider picking up a copy.
Every purchase helps support the time I invest in creating free content for the community, sharing lessons learned from real customer engagements, and continuing to develop practical guidance around identity, Zero Trust and privileged access.
For someone who failed English at school and has lived with ADHD and dyslexia throughout my career, seeing my name on the cover of a published book still feels a little surreal.
If you’d told me a couple of years ago that I’d one day publish a book, I genuinely wouldn’t have believed you.
But if sharing what I’ve learned helps organisations, architects and administrators build a more secure approach to privileged access, then every late night spent writing it was worth it.
If you do pick up a copy, I’d genuinely love to hear what you think.
After all, the journey doesn’t end with the first edition.
https://www.amazon.co.uk/Privileged-Path-Building-Secure-Administrative-ebook/dp/B0GXFWBCZB/
Comments
No comments yet — be the first to leave one below.