Identity & Access Management
Deep dives into Entra ID, Active Directory, MFA, Conditional Access, and modern identity architectures for enterprise environments.
Independent cybersecurity research, hands-on labs and unbiased product reviews. Exploring the frontlines of enterprise security so you don't have to.
Hi, I'm Michal Merta — a cybersecurity professional focused on identity security, zero trust architecture, and AI-driven threats. Through MMCyberLab, I share hands-on research, real-world lab setups, and honest product reviews.
My work bridges the gap between vendor marketing and operational reality — testing security products in realistic environments to give practitioners the insights they actually need.
Building security from the attacker's perspective to stay ahead of real threats — not just compliance checkboxes.
Every review and lab is backed by real testing — no recycled vendor datasheets, no marketing fluff.
Insights built from years of incident response, cloud security transformations, Zero Trust programs, and large-scale enterprise environments.
Exploring modern security challenges across cloud platforms, identity systems, AI workloads, and emerging technologies.
Mentoring security professionals, sharing practical knowledge, and helping build subject-matter expertise through dozens — and sometimes hundreds — of real-world security cases.
Practical research environments where I test real-world security scenarios, configurations, and attack paths — no theory without proof.
Deep dives into Entra ID, Active Directory, MFA, Conditional Access, and modern identity architectures for enterprise environments.
Implementing never-trust-always-verify principles with the Microsoft security stack, network segmentation, and device compliance policies.
Exploring LLM security, prompt injection attacks, AI governance frameworks, and securing AI-powered enterprise applications against emerging threats.
Enterprise-grade security at home — physical servers, Proxmox, network segmentation, monitoring stack, and realistic attack simulation.
Hands-on with Defender XDR, Microsoft Sentinel, Defender for Identity, and the full Microsoft security ecosystem in real attack scenarios.
PAM solutions, tiered administration models, just-in-time access, and protecting the most sensitive accounts in the organization.
Real-world testing of security products — not sponsored content, just honest assessments from hands-on experience.
Enterprise Security Platform
Recommended for EnterpriseComprehensive security ecosystem that delivers outstanding value for Microsoft-centric organizations. Defender XDR, Sentinel, and Entra ID together form an unmatched integrated platform with world-class threat intelligence.
Open-source, self-hosted password manager with excellent team sharing and a GPG-based trust model. Ideal for security-conscious teams wanting full control over their credential vault.
Solid for Teams
Feature-rich enterprise password manager with strong compliance reporting and polished admin controls. Keeper Secrets Manager adds solid CI/CD secret injection capabilities.
Enterprise Ready
Specialized secure content collaboration platform excelling in highly regulated industries. ITAR, CMMC, and FedRAMP compliance built-in with granular audit trails and DRM controls.
Compliance Champion
In-depth articles on cybersecurity architecture, hands-on lab findings, and lessons learned from real-world security testing.
Step-by-step guide to implementing enterprise-grade zero trust in a home lab using Entra ID, Intune, and Conditional Access policies with real traffic.
An exploration of prompt injection attack vectors in enterprise AI deployments, with practical detection strategies and mitigation patterns for production systems.
Clarifying the overlap, synergies, and gaps between Microsoft Defender for Identity and Microsoft Sentinel across hybrid Active Directory environments.
More in-depth articles in progress. Drop your email to be notified.
Have a question, collaboration idea, or want to discuss cybersecurity? Reach out through any of these channels.