Microsoft 365
Security and admin
The Microsoft 365 work I spend time around: identity, endpoint management, email security, and sharing controls.

Junior Security Analyst
Microsoft 365, security operations, SAL1 study, small tools
I’m a Junior Security Analyst in the UK with five years of combined IT and security experience. After two years supporting 10 schools, I joined SOCOTEC, where I progressed into security in September 2024. I use this site to document what I’m learning, share notes, and publish small security tools I’ve built.
Most of my day-to-day work sits around Microsoft 365 security, endpoint management, identity, email security, vulnerability remediation, and security operations. I’m also currently working towards TryHackMe Security Analyst Level 1 (SAL1).
The site brings together research notes, safe work write-ups, and small tools I have built while learning and working in security.
Snapshot
These are the areas I’m currently working on and learning through my role, home lab, tools, and write-ups.
Microsoft 365
The Microsoft 365 work I spend time around: identity, endpoint management, email security, and sharing controls.
Operations
Alert review, vulnerability remediation, phishing awareness, incident support, and reporting.
Tooling
Browser tools, workflow helpers, and scripts for things I find myself checking more than once.
Tools I’ve built
Threat Intelligence
Check IP location, ASN, RDAP registration, reverse DNS, and possible hosting indicators.
Launch tool →Networking
Look up common DNS records using Google Public DNS.
Launch tool →Identity Security
Calculate the percentage of inactive guest accounts.
Launch tool →Research
Technical notes on Microsoft Defender for Office 365 Plan 1, Safe Links behaviour, policy overlap, and operational checks after the E3 rollout.
While investigating unexpected URL rewriting in Exchange Online, we discovered Microsoft had enabled Defender for Office 365 Plan 1 as part of its rollout to Microsoft 365 E3 tenants.
An update on the development of SecToolBox, a personal PowerShell-based security toolkit I'm building to consolidate common triage, investigation, and report generation tasks into a single tool.
Learning
TryHackMe
I use TryHackMe to keep practising the fundamentals and to fill gaps as I move deeper into security work.
View TryHackMe profile →Latest certification
Issued 15 August 2026 and valid until 15 August 2029. An entry-level certification validating core cyber security, networking, operating system, and security principle knowledge.
View credential →Currently studying
Working towards TryHackMe SAL1. This is not yet awarded; I’m using it to strengthen alert triage, threat detection, SOC simulation, and analyst report-writing skills.
View SAL1 certification →About
Hi, I'm Elliot, a Junior Security Analyst based in the UK with a background spanning five years across multi-site IT support, senior service desk work, and security. I spent two years supporting 10 schools before joining SOCOTEC, where I have worked for three years and moved into security in September 2024. I focus on Microsoft 365 security and automation, and I like understanding how systems work, investigating security problems, and building small tools that make repeat tasks easier.
My experience includes endpoint security, governance, Microsoft 365 administration, phishing awareness, automation, and incident response. Outside of work, I use labs, write-ups, and side projects to keep improving.
This site is where I keep that work in one place.