The Sites.Selected 403 that started it all
How one stubborn permission error led to an architecture where the AI never touches a live system.
Coming soonI'm Ketan — a Microsoft Modern Workspace architect. I build endpoint-management tooling in the open, and write about how it actually works underneath the portal.

The project I'm best known for — an AI agent that answers questions about an endpoint fleet while holding no access to any live system.
Scheduled read-only jobs export sanitized, pre-aggregated snapshots. The agent answers only from those — the permission boundary is enforced by architecture, not by asking a model to behave.
Posts, tools and projects — all in one place, added as I go.
"The Graph call behind the portal click" — decoding what the portal actually fires, and the permission it needs.
The read-only AI agent pattern — full docs, ten collectors, and a synthetic fleet you can run with no tenant.
Battle-tested PowerShell for Intune, Entra and Graph — each script standalone, each explained.
The endpoint reports I build on top of the read-only snapshots — screenshots, templates and how they're wired.
An occasional note when something's worth your time — new posts, new tools, lessons learned.
What I work on, how I work in the open, and how to get in touch.
First posts landing soon — here's what's on deck.
How one stubborn permission error led to an architecture where the AI never touches a live system.
Coming soonDecoding what the Intune / Entra portal actually fires against Microsoft Graph — and which permission it needs.
Coming soonBuilding a Power BI report on sanitized CSVs — no live tenant connection required.
Coming soonEverything here comes from a personal lab, reproduced before it's published — including what I got wrong. Follow along on GitHub, or subscribe for the occasional signal.