Refoundry Blog

Where bold ideas meet practical strategies. Our blog explores how to reduce complexity, strengthen security, and deliver better experiences across identity, cloud, and device management. Discover insights that empower your business to lead with purpose and stay ahead in a rapidly evolving digital world.

TL;DR: Trustworthy Agents Need Governance, and That’s Where the Real Work Starts

By Mike Gribble | Jun 5, 2026

The short version:AI agents don’t just answer questions anymore. They plan, act, use your tools, and run in a self-directed loop with a lot less human oversight than a chatbot. That autonomy is what makes them valuable. It’s also what makes them risky. Anthropic’s latest piece, Trustworthy agents in practice, does a good job explaining…

What Agent 365 Actually Unlocks and Why Timing Matters

By Rich Lilly | May 7, 2026

Most organizations think Agent 365 is for later. After pilots. After use cases. After value is proven. That instinct is understandable and often wrong. Agent 365 matters most at the point where things start working, not before. Agent 365 Is Not an Agent Builder It is a control plane. A registry for every agent, including…

Agent 365 and The Microsoft Frontier Suite: The Missing Piece in Your Agentic Strategy

By Stephen Christiansen | May 4, 2026

Frequently when I’m with clients, we’ll talk about the reasons why most of their AI projects are floundering — and 9 times out of 10 it’s not because of the technology, but because of their inability to manage that technology. So today I want to dig into something specific: why the Microsoft Frontier Suite (E5…

SIEM is Not Dead — But It’s No Longer the Center of Gravity

By Rich Lilly | Apr 23, 2026

For years, the playbook was simple: Centralize everything into a SIEM. Security logs. Application logs. Performance telemetry. Network noise. If it could produce a log… it got shipped. Platforms like Splunk and QRadar became the catch-all data sinks for the enterprise. And for a while, that made sense. But that model doesn’t hold up anymore.…

Governing AI Requires More Than Controls — It Requires Visibility

By Rich Lilly | Apr 20, 2026

Last week, I wrote about why blocking AI is easy—but governing it is where most organizations fail. That post focused on permissioning: what really happens the moment a user flips an AI connector from Needs approval to Always allow. This article is about what comes next. Because once you allow it… you need to see…

Refoundry Earns the Microsoft Threat Protection Specialization

By Refoundry | Apr 13, 2026

The Refoundry team has earned the Microsoft Threat Protection Specialization, a designation that verifies proven, hands-on expertise in deploying Microsoft Threat Protection and Microsoft Cloud App Security workloads.   What the specialization actually means To earn a Threat Protection Specialization, Microsoft requires partners to demonstrate real-world deployment experience (verified by customers who can speak to…

Blocking AI is easy. Governing it is where most organizations fail.

By Rich Lilly | Apr 8, 2026

Most organizations are not ready for what “Always allow” actually means in tools like Claude Cowork. By default, it’s set to Needs approval. That’s intentional. But the moment a user flips that to Always allow, they’ve effectively delegated their identity. Not just access… authority. Now you have: AI operating with user-level permissions Access to email,…

The New Insider Threat Isn’t a Person. It’s Your AI. (with PoC)

By Rich Lilly | Apr 3, 2026

Most organizations still think about risk the old way: Phishing. Malware. Endpoint compromise.   But we’re entering a different era. The next wave of enterprise risk sits at the intersection of AI + access. And most organizations aren’t ready. AI Is Not Just a Tool. It’s an Operator. Whether it’s Copilot, ChatGPT, or Claude—these aren’t…

The Security Platform Shift Is Here — And It’s Not Subtle (RSA 2026 Recap)

By Rich Lilly | Mar 31, 2026

For years, security leaders have operated under a familiar assumption: “Best of breed always wins.” Buy the best SIEM. Buy the best EDR. Buy the best identity tool. Integrate everything later.   That model made sense in a world where: Data was fragmented Tooling was siloed Humans were the primary operators That world is changing…