Just a nerd, with a stage.
I am Fabio. I have spent years deep in the Microsoft Modern Workplace: Microsoft 365, Azure, Intune and security โ๏ธ. My favourite trick is taking the complicated stuff and making it simple enough that people actually use it.
That is also why I got on a stage ๐ค. I speak at events, stream live, host a podcast and teach as a Microsoft Certified Trainer. Passing on what I figure out is the best part of my week, and it keeps me sharp too.
You will recognise my work by the emojis. I even drop them straight into Conditional Access policy names and Intune settings, on purpose, so the Microsoft cloud stays approachable whether it is your first policy or your thousandth ๐. Bringing everyone along, from complete beginner to seasoned pro, is the whole point.
Consulting and training, making content, and running goldenmaster.cloud and the Modern Nerdplace community.
Went from doing the work to talking about it: speaking, streaming, and picking up my Microsoft Certified Trainer badge.
Fell for the Microsoft cloud early and never really stopped nerding out.
The stuff with my name on it.
goldenmaster.cloud โ๏ธ →
My Microsoft 365, Intune and Entra blueprint. A knowledge hub for MSPs who want one consistent, deployable baseline across every client tenant, with the reasoning behind every setting spelled out.
nerd.ms ๐ →
A searchable launcher for every Microsoft admin portal. Hundreds of shortcuts to Azure, Entra, Intune, the Microsoft 365 admin center, Defender, Purview and more, so you stop hunting for the right URL.
Modern Nerdplace ๐ค →
The user group I help run for IT enthusiasts and MSPs. Passionate nerds who do not just manage the tech but embrace and transform it, with a wink to the nerd universe. Meetups, virtual events and blogs where you share your nerdy discoveries with people shaping the future. Get ready to nerd out ๐โจ
Streams, podcast & talks ๐ฅ →
Live on Twitch, a podcast on Spotify, and talks on stage. Microsoft news, hands on demos and honest takes, like my breakdown of the axios supply chain attack.
The scripts do not stay on my laptop ๐งฐ. I put them on GitHub so you can read them before you run them.
Microsoft-Community-Scripts →
Community scripts for Microsoft admins. PowerShell for Microsoft 365, Intune, Entra, Exchange and SharePoint, one folder per script with a README that tells you where it bites.
Conditional-Access →
Een leuk framework voor Conditional Access. In mijn Blogs kan je mijn beredenering volgen en een stukje instructie.๐ฅฐ
github.com/vdBurgIT →
The rest of what I keep in the open, work in progress included.
Where to find me.
On a stage, on a stream, or in your headphones ๐ง. Here is what is coming up, and everywhere I have already been. The rows marked Speaker are sessions I presented myself, 52 of them so far.
Pick one, or ask for a mix. All of them work in Dutch or English, on a stage, in a webinar or as a hands on workshop.
๐๐ฆ๐ก๏ธ Conditional Access, but make it readable
Open the Conditional Access blade in a random tenant and you get forty policies called "CA001 - Block legacy", "CA001 - Block legacy (new)" and "test do not delete". Nobody knows what they do. Nobody dares to touch them. ๐ฌ Mine are full of emojis, and that is not a joke. A policy you can read at a glance is a policy you can maintain. After the naming system we get to the part that really keeps you safe: device settings, compliance and Conditional Access as one chain. Settings harden the device, compliance proves it, Conditional Access enforces it at every sign in. Break one link and the rest is decoration. Live, in a real tenant. ๐ฆ
Your MFA just got phished: stopping AiTM attacks
You rolled out MFA. Everybody got the app. You felt safe. ๐ Then an adversary in the middle kit sits between your user and the real sign in page, lets MFA succeed like a polite doorman, and walks off with the session cookie. Wait. What. I show the attack live, then close the doors one by one: authentication strengths, a compliant device requirement, token protection, risk based policies and continuous access evaluation. And then the fun part: why passkeys make the whole trick fall apart, and how to roll them out without starting a help desk riot. ๐
๐ฐ The modern secure workplace: stop building castles
Your users work from the kitchen table, the train and that one coffee place with suspiciously good WiFi. โ The office network stopped being your perimeter years ago. Identity is. So stop building castles and start checking every door: who is signing in, from which device, and is that device actually healthy? I show how Entra ID, Intune and Conditional Access click together into a workplace that is secure by default and still nice to work in, using the baseline I deploy at customers. And yes, the mistakes too. Especially the ones that page you at 2AM. ๐งฏ
Axios got owned: from supply chain attack to unified SOC
One compromised npm package. More than 100 million systems. And not a single firewall rule that cared. ๐ฆ I walk through how the attackers got in through Axios, step by step, from the poisoned release to the first foothold on a developer machine. Then the question that actually matters: how could we have stopped this inside a Microsoft environment? The right set of policies, awareness that sticks longer than the quarterly phishing test, and Defender with a unified SOC that connects the dots before the attacker does. You leave with a list of things to turn on tomorrow. ๐ ๏ธ
๐ค Cybersecurity in the age of AI: the bad guys got Copilot too
Remember when you could spot a phishing mail by the spelling? Those days are gone. ๐จ Attackers use AI too: flawless phishing in perfect Dutch, faster reconnaissance, and more attempts than any human could type. So what changes for small and midsize organisations? Less than the vendors want you to believe, and more than your current setup can handle. I show what these attacks look like today, why yet another tool on the shelf will not save you, and why detection and response around the clock is the part you cannot skip. ๐
โ๏ธ Azure as your security foundation: start small, build it right
Most Azure environments I meet started with one quick VM "just for testing". Three years later it runs payroll. ๐ In this session we do it the other way around. Landing zones, identity and governance first, the boring bits that save you later. Then workloads like Azure Virtual Desktop and migrations on top, without tearing everything down in two years. A practical path to Azure for organisations that want to start small and still sleep at night. ๐งฑ
๐ Get your data AI ready before Copilot reads everything
Here is the thing nobody tells you in the Copilot demo: it finds everything the user can open. Everything. That salary sheet someone shared with "Everyone except external users" in 2019? Copilot found it. ๐ Copilot does not create a data problem, it just shows you the one you already had, very quickly and very politely. I show how to spot oversharing, clean up permissions and put sensitivity labels to work before you roll out Microsoft 365 Copilot, so your pilot does not turn into a data leak with a chat window.
โก Working harder and smarter with AI
AI will change everything, the slides say. Great. What do I do on Monday morning? โ This session is all demo and no strategy deck. I show what Copilot and other AI tools do really well in a normal working day, where they still fall flat on their face, and how to tell the difference before you forward that summary to your boss. For people who want to start tomorrow, not after the next steering committee. ๐
Van supply chain attack tot Unified SOC met Defender
Cybersecurity in het AI-tijdperk - KPN MDR
Azure Migrate
Azure Virtual Desktop
The Axios Supply Chain Attack
Panelsessie: Een werkplekstrategie die meebeweegt met je organisatie
Azure Migrate
Azure Virtual Desktop
Azure Migrate
Azure Virtual Desktop
Hoe begin je met Azure? Start klein, creรซer grote waarde
Cybersecurity - Adversary in the Middle @ Payroll Totaal
It's Show Time - Live Radioshow
Versnel je Cloudstrategie met Azure: Innovatie, Migratie en Groei @ KPN Partner Network
SuperVision MDR @ Vision Unfold 2025
SuperVision MDR @ Vision Unfold 2025
SuperVision MDR @ Vision Unfold 2025
SuperVision MDR @ Vision Unfold 2025
Experts Live: Meet me @ the stand
Modern Nerdplace Meetup @ The Farm Edition
Microsoft Azure: De Volgende Stap naar een Veiligere Moderne Werkplek @ RELEASE
Microsoft Azure: De Volgende Stap naar een Veiligere Moderne Werkplek @ RELEASE
Microsoft Azure: De Volgende Stap naar een Veiligere Moderne Werkplek @ RELEASE
Microsoft Azure: De Volgende Stap naar een Veiligere Moderne Werkplek @ RELEASE
Microsoft Azure: De Volgende Stap naar een Veiligere Moderne Werkplek @ RELEASE
Security isn't just a code @ Business Boost Live
VTM - Microsoft Copilot M365
Modern Nerdplace Meetup @ NDI
Training SuperVision @ Kpn Partner Network
Modern Nerdplace Meetup @ Kreuze
Training SuperVision @ Kpn Partner Network
Training SuperVision @ Kpn Partner Network
Microsoft & KPN inspiratiesessie Copilot @ Kpn Partner Network
Werken met Copilot @ Kpn Partner Network
Experts Live: Meet me @ the stand
Collabdays
Training SuperVision @ Kpn Partner Network
Let's build Nerd.ms @ Twitch
Modern Nerdplace Meetup @ Delta-N
Nerd Talkshow met Johan van der Hoeven @ MNP Radio
Nerd Talkshow met Paul van Boerdonk @ MNP Radio
Nerd Talkshow met Boyd Heeres @ MNP Radio
Training SuperVision @ Kpn Partner Network
Training SuperVision @ Kpn Partner Network
SuperVision DevDay @ KPN Partner Network
Modern Nerdplace Meetup @ The Farm Edition
Training SuperVision @ Kpn Partner Network
Get your data A.I. Ready @ RELEASE
Get your data A.I. Ready @ RELEASE
Get your data A.I. Ready @ RELEASE
Copilot Insights @ People Work Technology Podcast
Get your data A.I. Ready @ RELEASE
Get your data A.I. Ready @ RELEASE
Microsoft Copilot Techademy @ KPN Partner Network
Training SuperVision @ Kpn Partner Network
Microsoft Copilot M365 @ Delta-N
Training SuperVision @ Kpn Partner Network
Microsoft Copilot Techademy @ KPN Partner Network
Hoe verkoop je de waarde van Security @ Kpn Partner Network
SuperVision interview @ TBM
Training SuperVision @ Kpn Partner Network
Inspire Microsoft Copilot @ Techone
Training SuperVision @ Kpn Partner Network
Training SuperVision @ Kpn Partner Network
Webinar Microsoft Copilot @ DDX Zoetermeer
Training SuperVision @ Kpn Partner Network
Training SuperVision @ Kpn Partner Network
Training SuperVision @ Kpn Partner Network
SuperVision DeepDive @ KPN Partner Network
SuperVision DeepDive @ KPN Partner Network
Hoe verkoop je de waarde van Security @ Kpn Partner Network
OCW99 Deep Dive Cyber Security @ van der Valk Wassenaar
Hoe verkoop je de waarde van Security @ Kpn Partner Network
Hoe verkoop je de waarde van Security @ Kpn Partner Network
Hoe verkoop je de waarde van Security @ Kpn Partner Network
Azure als (Security) Fundament @ RELEASE
Azure als (Security) Fundament @ RELEASE
Azure als (Security) Fundament @ RELEASE
Azure als (Security) Fundament @ RELEASE
Br'hack fast @ Constant IT
Webinar: Verantwoord Beheer @ Webinar TV
Webinar: Authenticatie en Autorisatie
Notes from the trenches.
Most of what I write these days lives on goldenmaster.cloud ๐: real world Microsoft 365, Intune and Entra, written down so you can skip the headache I already had.
Everyone Wants to Build a Copilot Agent. Almost Nobody Should.
The pitch is intoxicating. Open Microsoft 365 Copilot, describe in two sentences what y...
Your Tenant Says Every Device Is Compliant. It's Lying.
You did everything right. Conditional Access requires a compliant device before anyone ...
๐ Autopilot โ One Framework to Manage Them All
Most organisations donโt just have one type of device. If you look closely, you can alm...
Wait... Standard Users Can Do *WHAT* Now?!
It started with a ticket: "Hi IT, I wiped my device because Teams stopped syncing. Can ...
All posts
The full blog over on goldenmaster.cloud.
The library is the bigger half of it ๐: 160 pages I write and keep up myself, where a setting gets explained instead of listed.
Entra ID baseline
Conditional Access, authentication, identity protection. Per policy: what it blocks, which licence you need for it, and how to get back out.
Intune baseline
Windows and macOS. Enrolment, configuration, compliance, endpoint security and update rings, the way I set them up at customers.
Admin center
The tenant wide switches that decide what everyone else is allowed to do.
Proof, on paper.
The badges behind the talks ๐. I keep adding to them, because the platform never sits still.
Let us build something, or just nerd out ๐ค
Book me as a speaker
Conference, user group, podcast or a workshop for your team. Tell me the audience and I will tailor it.
Reach out on LinkedInAdvisory & training
Need a hand with Microsoft 365, Azure, Intune or security? Let us grab a coffee, online or in person.
Join the Discord