Stop Waiting for Perfect Conditions

image

I hear versions of the same story all the time.

Someone wants to learn Microsoft 365 Copilot. Start a side project. Improve their business processes. Clean up their Microsoft 365 tenant. Build a new service offering for their clients.

But not yet.

They’re waiting for a quieter week. Waiting for a project to finish. Waiting for school holidays to end. Waiting for the inbox to settle down.

The problem is that week never arrives.

I’ve been in technology long enough to know that there is always another project. Another client request. Another issue needing attention. If you’re running an MSP or managing an SMB, the workload doesn’t magically disappear one day and leave you with hours of spare time.

That’s why I’ve come to believe that constraints aren’t the thing stopping you.

More often than not, they’re the thing that should be driving you forward.

The Reality of Limited Time

A lot of people treat constraints like roadblocks.

“I don’t have enough time.”

“I don’t have enough money.”

“I don’t have enough people.”

Those things may all be true. But they’re also true for almost everyone else.

The difference is how you respond to them.

When I work with organisations deploying Microsoft 365 Copilot, the most successful ones rarely have unlimited resources. They’re not sitting around with spare staff and empty calendars. They’re already busy.

What they do have is a willingness to work within the constraint rather than waiting for it to disappear.

Instead of trying to train every employee at once, they start with five people.

Instead of redesigning every process in the business, they pick one recurring task in Outlook or Teams and improve it.

Instead of creating the perfect governance framework, they begin with the basics and build from there.

The constraint forces focus.

And focus is often worth more than freedom.

Small Boundaries Create Better Decisions

One thing I’ve noticed over the years is that too many options can be just as dangerous as too few.

Give someone unlimited time and unlimited resources and they often spend months planning.

Give them one hour a week and suddenly they become remarkably efficient.

I’ve seen MSPs create entirely new AI service offerings because they only had a few hours available each week. The limited time meant they ignored all the distractions and concentrated on the activities that actually mattered.

The same applies to personal growth.

If you’ve only got thirty minutes available on a Friday afternoon, use it.

Open Copilot in Word and draft an article.

Use Copilot in Teams to summarise a meeting you missed.

Explore a new automation in Power Automate.

Read one Microsoft Learn article.

Thirty minutes won’t change your business overnight. But thirty minutes every week for a year absolutely will.

The point isn’t the amount of time.

It’s the consistency.

Stop Negotiating With the Future

What worries me most about the “I’ll start when things settle down” mindset is that it quietly trains us to delay action.

We convince ourselves we’re being sensible.

We’re really just postponing the uncomfortable part.

Learning something new feels hard.

Changing a process feels risky.

Starting a project creates uncertainty.

So we strike a deal with ourselves and push it into the future.

The future, of course, never objects.

It just keeps moving.

I’ve found that progress usually begins when we stop asking whether conditions are ideal and start asking what can be done with the resources available today.

That’s true whether you’re adopting Copilot, building an MSP business, improving your security posture, or simply trying to learn a new skill.

The Constraint Is the Opportunity

When I look back at the projects that made the biggest difference in my career, very few started under perfect conditions.

Most began when time was short, money was limited, or other priorities were competing for attention.

The limitation wasn’t the problem.

It was the catalyst.

So if you’re waiting for a quieter month, a bigger budget, or fewer commitments, I’d encourage you to rethink the situation.

The constraint you’re looking at today might not be the obstacle.

It might be the thing that finally forces you to focus on what matters most.

That’s usually where the real progress starts.

Writing Is Still Thinking (Even in the Age of Copilot)

image

A few weeks ago I caught myself doing something I suspect a lot of people are doing right now.

I had an idea. Instead of opening a blank document, I opened Microsoft 365 Copilot and started asking questions.

Within minutes I had summaries, suggestions, outlines, and options. It was impressive. It was also a little unsettling.

The reason was simple. I had an answer before I had really worked out what I thought about the question.

That’s something I’ve been reflecting on more as AI becomes a bigger part of our daily work. We often talk about AI helping us write, but I think the more important question is whether we’re still using writing to think.

The Value of a Blank Page

For most of my career, writing has been one of the ways I clarified my thinking.

Whether it was a client proposal, a blog post, meeting notes, or an internal strategy document, the process worked because it was slow enough to force decisions. You couldn’t hide gaps in your logic. When you sat staring at an empty page, every weak assumption became obvious.

That’s still true today.

When I open a Word or OneNote document and start typing, I often discover that the idea I thought was clear in my head isn’t quite as solid as I imagined. The act of putting words on a page exposes the fuzzy edges.

The danger with AI is that it can smooth over those edges too quickly. Copilot can generate something that sounds complete before you’ve done the hard work of deciding what you actually believe.

The output may be polished. Your thinking may not be.

Copilot Works Best as a Thinking Partner

This isn’t an argument against Microsoft 365 Copilot. Far from it.

What I’m seeing in organisations is that the most successful users don’t treat Copilot as a replacement for thinking. They use it as a way to challenge and refine their thinking.

A practical example might be drafting a proposal in Word. I often start with rough notes of my own. They are messy and incomplete. Only after I’ve worked through the problem do I ask Copilot to review the draft, identify gaps, suggest alternative approaches, or summarise the key points.

The sequence matters.

Thinking first. AI second.

If you reverse the order, there’s a risk that you’re evaluating someone else’s answer rather than exploring your own understanding.

That’s a subtle difference, but it’s an important one.

Faster Answers Aren’t Always Better Answers

Many of us spend our days moving between Outlook, Teams meetings, client conversations, and project work. The attraction of having instant answers everywhere is obvious.

The challenge is that genuine understanding usually takes longer than information retrieval.

Copilot can tell you what happened in a Teams meeting you missed. It can summarise a lengthy email thread in Outlook. It can pull key points from a SharePoint document in seconds.

That’s incredibly useful.

What it can’t do is decide what those things mean for your business, your clients, or your next decision.

That responsibility still sits with you.

I think that’s why many people who try AI for the first time are both impressed and disappointed. They’re impressed by the speed. They’re disappointed when speed alone doesn’t solve the problem they were really facing.

Knowledge is easy to access. Judgement is still hard work.

The Skill Worth Protecting

The organisations getting the most value from AI aren’t abandoning traditional skills. They’re strengthening them.

Clear writing. Critical thinking. Good questioning. Sound decision-making.

Those capabilities become more important as AI becomes more capable, not less.

The people who ask the best questions get better results from Copilot. The people who understand a problem deeply can spot when an AI-generated answer misses the point. The people who can write clearly can guide AI more effectively.

That’s what I’m watching most closely.

AI is changing how we work, but I don’t believe it changes the need to think carefully. If anything, it raises the value of that skill.

The blank page still matters.

Copilot may help us fill it faster, but the real value comes from understanding what deserves to be written there in the first place.

The Login Screen Looks Simple. The Decision Behind It Is Not.

image

I worry that sign-in security is still treated like a mystery box in too many Microsoft 365 environments.

A user enters a password. Something happens behind the scenes. Maybe MFA appears. Maybe Conditional Access blocks the request. Maybe the sign-in works because the policy did not apply as expected. Then, when something goes wrong, the first question is usually, “Why did Microsoft let that happen?”

That is the wrong question.

The better question is: did we understand the path that sign-in actually took?

That is why I like simple visual tools such as the Microsoft 365 login simulator. Not because they replace proper testing in Entra. They do not. I like them because they make the invisible visible. They let people walk through authentication logic without starting inside a dense admin portal.

Authentication is where theory meets reality

Most businesses think they have secure login because they have MFA turned on. That is a start, but it is not the full story.

In the real world, sign-in decisions are messy. A user might be on a managed device, a personal laptop, or public Wi-Fi. They might be coming from a known location, a strange location, or through a service that does not behave like a normal browser session.

This is where Microsoft Entra ID, Conditional Access, MFA, device compliance and sign-in risk start to matter. They are not isolated controls. They are a decision chain.

For an MSP, that chain needs to be explainable.

I have sat in enough client conversations to know that saying “we enabled MFA” does not always land. A business owner wants to know what happens when an account is attacked. A help desk person wants to know whether the issue is identity, device, location, policy, licensing or behaviour.

A simulator gives you a conversation starter. It turns the abstract into something you can point at.

Copilot still depends on identity hygiene

Microsoft 365 Copilot does not remove the need for clean identity controls. If anything, it raises the stakes. When someone asks Copilot in Teams to summarise a channel, or uses Copilot in Word to draft from files in SharePoint, the experience depends on the access that user already has.

That means sign-in is not just a security event. It is the front door to organisational knowledge.

If a compromised account gets through that front door, the issue is no longer just email. It may include documents, chats, meetings and shared files. For an SMB, that is a business risk, not a technical footnote.

So when I look at a login simulation, I am thinking about what the user can reach after access is granted.

Use the simulator to teach judgement

The best use of a tool like this is not to frighten people. It is to build judgement.

Run through a few scenarios with a client or your own team. What should happen for a global administrator? What should happen for a user on an unmanaged device? What should happen for a login from a location the organisation never normally uses? Where does the policy catch the risk?

Then compare that ideal path with what your tenant is configured to do.

That gap is where the work is.

For MSPs, this is a better advisory conversation. You are not just selling another security setting. You are helping the client understand how identity, access and data exposure connect. That moves the discussion away from checkbox compliance and towards resilience.

My view is simple. If you cannot explain the sign-in path, you probably do not control it as well as you think.

The login screen looks simple. The decision behind it is anything but.

Screenshot 2026-08-04 111503

The simulator is here – https://directorcia.github.io/Office365/m365-login-sim.html

and the documentation is here – https://github.com/directorcia/Office365/wiki/M365-Sign%E2%80%90In-and-Conditional-Access-Flow-Simulator

The Skill That Matters Most in the Age of Copilot: Asking Better Questions

image

The people getting the most value from Microsoft 365 Copilot today aren’t necessarily the most technical. They’re not the fastest typists, the best PowerShell writers or the ones with the biggest AI budget.

They’re the people who ask better questions.

That might sound obvious, but I think it’s one of the biggest mindset shifts happening right now. For years, many of us have been trained to search for information using a few keywords. Type something into Google, scan the results, click a link, repeat. The skill was finding information.

With Copilot, the skill is becoming framing the problem.

I see this regularly when working with SMBs and MSPs. Two people sit in front of the same Microsoft 365 Copilot environment. One gets a generic answer that doesn’t really help. The other gets a detailed summary, actionable recommendations and a useful first draft. The difference is rarely the technology.

It’s the question.

Most People Stop Too Early

A common pattern I see is someone opening Copilot in Teams or Outlook and typing a very short request:

“Summarise this.”

“Write an email.”

“Analyse this document.”

Copilot will do something, but not necessarily something valuable.

The better approach is to provide context. Why do you need the information? Who is the audience? What decision are you trying to make? What concerns do you already have?

The quality of the answer often improves dramatically when the question becomes more specific.

Think about a conversation with a trusted employee. If you walked into their office and said, “Help me with sales”, you’d get a confused look. If you said, “Review the last quarter of sales reports and identify the three biggest opportunities in our existing customer base”, you’d be much closer to getting a useful result.

Copilot works in a similar way.

Copilot Rewards Curiosity

One of the biggest mistakes I see is treating Copilot like a command-line interface.

People issue instructions instead of having a conversation.

The real value appears when you start exploring.

For example, after Copilot produces a meeting summary in Teams, don’t stop there. Ask what wasn’t discussed. Ask what risks were mentioned only briefly. Ask which actions have no assigned owner. Ask which topics are likely to create issues next month.

Each follow-up question improves your understanding.

What fascinates me is that the process starts to resemble working with a highly capable colleague. The first answer is rarely the destination. It’s often the starting point.

The people who get the best outcomes are usually the people who are naturally curious. They’re willing to ask one more question.

Then another.

Then another.

This Changes How We Learn

I think we’re moving into a world where knowing everything becomes less important than knowing how to investigate effectively.

In the past, expertise often meant storing large amounts of information in your head. Today, much of that information can be surfaced instantly from SharePoint, OneDrive, Teams conversations and Outlook messages through Copilot.

The challenge becomes directing that capability effectively.

When I use Copilot in Word to help draft content or in Outlook to analyse a long email thread, I rarely accept the first result. I refine it. I challenge it. I ask for alternatives. I request different viewpoints.

In many cases, my role is becoming less about generating information and more about guiding the process that generates it.

That’s a different skill set altogether.

The Real Competitive Advantage

I don’t think the winners in the AI era will be the organisations with the most AI tools.

I think they’ll be the organisations that teach their people how to think clearly, define problems accurately and ask better questions.

Microsoft 365 Copilot is already showing us this reality. The technology is becoming easier to access every month. The differentiator isn’t the tool. It’s the person using it.

A poor question gives you a poor starting point.

A thoughtful question opens entirely different possibilities.

That’s why, when people ask me what skill they should develop to get more value from Copilot, my answer is increasingly simple:

Learn to ask better questions. Everything else gets easier from there.

Mail Security Is Easier to Understand When You Can See It

image

One of the recurring problems with Microsoft 365 mail security is that too many people treat it like a checklist. SPF. DKIM. DMARC. Spoof intelligence. Anti-phishing. Safe Links. Quarantine. Transport rules. Tick the boxes, move on, hope the tenant is safer than it was before.

I understand why that happens. Email security in Microsoft 365 has a lot of moving parts, and most of them are hidden until something goes wrong. A message lands in junk. A phishing email reaches a user. A legitimate invoice disappears into quarantine. Then everyone starts asking the same uncomfortable question: why did that happen?

That is why I like building simple simulation tools, like the one I just created here:

https://directorcia.github.io/Office365/m365-mail-security-sim.html

The value is not the button. It is the model.

The point of a mail security simulator is not to replace the Microsoft Defender portal. It is to help people build a clearer mental model before they start changing live settings.

When I work with SMBs and MSPs, I often see the same pattern. Someone knows one part of the stack very well, usually Exchange Online mail flow or DNS authentication, but they are less confident about how that choice affects the next decision. Enforcing DMARC sounds sensible. Tightening spoof handling sounds sensible. Adjusting user reporting sounds sensible. The problem is that sensible settings can still create poor outcomes if you do not understand how they interact.

A simulator gives you a low-risk way to explore that. Change the assumptions. Watch the likely outcome. Ask what would happen if the sender fails authentication, if the domain is aligned, if policy handling changes, or if the user has been trained to report suspicious mail through Outlook. You are not learning by breaking production. You are learning by testing the shape of the decision.

Copilot still needs clean security thinking.

This becomes even more important as Copilot becomes part of the working day. People are asking Copilot in Outlook to summarise long email threads, draft replies, and pull meaning from busy inboxes. That only works if the mailbox environment is trustworthy enough in the first place.

Copilot does not remove the need for Defender for Office 365, Exchange Online Protection, authentication alignment, or sensible quarantine handling. If anything, it raises the standard. The more value we expect people to get from their Microsoft 365 data, the more responsibility we have to make sure the signals around that data are well managed.

That is the message I want administrators and MSPs to take seriously. AI does not excuse messy security. It exposes it.

Training beats guessing.

Good security administration is not just knowing where the settings are. It is knowing what trade-offs you are making when you change them.

A tool like this can help an MSP have a better client conversation. Instead of saying, “we should improve your mail security,” you can show the client how different conditions affect message handling. Instead of turning a policy into an abstract recommendation, you can make the risk visible enough for a business owner to understand.

It also helps junior technicians. I would much rather see someone experiment with a simulation than make random changes inside the Defender portal because they found a setting that sounded important. Curiosity is good. Production tenants are a poor classroom.

Microsoft 365 security has become too important to be treated as a collection of isolated switches. Mail protection, user behaviour, reporting, policy tuning, and now Copilot readiness all sit together. If you cannot explain how the pieces connect, you are not really managing the system. You are just hoping the defaults are enough.

The next step for many organisations is not more noise, more dashboards, or more alerts. It is better understanding.

That starts by making the invisible parts of mail security visible enough to reason about.

You’ll find the simulation I just created here:

 https://directorcia.github.io/Office365/m365-mail-security-sim.html

it’s free to use but I’d always appreciate any support you can provide around this and upcoming simulation projects via – https://ko-fi.com/ciaops.

Screenshot 2026-08-03 093012

Also, feel free to provide me any feedback on the simulation so I can continue to improve it for all.

The Recurring Problem: A Managed Services Story–Chapter 9

Previously – https://blog.ciaops.com/2026/08/02/the-recurring-problem-a-managed-services-story-chapter-8/

image

Renata Cole called Dave in the spring, mostly to catch up, mostly out of professional curiosity about how the conversation she’d had with him two years earlier had landed. He walked her through the numbers without much ceremony, because for the first time in years he didn’t need to dress them up. Recurring revenue: 83 percent of total, closing in on the threshold she’d once told him buyers actually respected. Largest client concentration: down to 11 percent, after two years of deliberate diversification and the return of Lakeside. EBITDA margin: up to 24 percent, not because Bridgepoint had cut anything, but because AI-assisted service delivery had let the same headcount support 30 percent more client seats without a corresponding rise in labor cost. Two new verticals — healthcare and manufacturing security — accounted for nearly half of new sales, at price points 20 to 30 percent above the old generalist rate.

image

“You’d get a very different number from me today,” Renata said. “Somewhere in the eight-to-ten range, probably higher if you kept the trajectory going another year. What did it actually take?”

Dave thought about it for a moment before he answered, because he wanted to get it right, and because he’d had two years to think about what the honest answer actually was.

“It took losing a client I genuinely cared about,” he said, “and a woman with a spreadsheet telling me a number I didn’t want to hear, and a twenty-six-year-old who was right about something I didn’t want to admit she was right about. It took one of my best engineers deciding to stay and figure out who he was going to become instead of walking out the door defending who he already was. None of that was a strategy. It was just what it actually took to stop protecting a version of the business that the world had already stopped needing.”

image

He didn’t say it the way a case study would say it, with a tidy label like transformation or pivot. He said it the way it had actually happened: slowly, expensively, unevenly, with real people who had real doubts and real things to lose, arriving — later than any of them would have liked, but not too late — at a business built for the clients they actually had, instead of the ones they used to.

Jordan still drove a van some days, out of habit, same as Dave once had. But these days, when he pulled into a client’s lot, he wasn’t there because something had broken. More often than not, he was there to explain what Bridgepoint had already caught before it did.

image

The MSP industry Bridgepoint operates in today looks little like the one Dave Kessler started in. Recurring revenue quality, not relationship goodwill, now determines what a services business is worth. Vertical depth, not generalist breadth, commands premium pricing. And the providers thriving in the AI era are not the ones that resisted automation to protect familiar work, but the ones that used it to free their most experienced people for the judgment only they could offer — becoming, in the process, less like vendors who show up after something breaks, and more like advisors clients call before it does.

Stop Feeding the Algorithm. Start Changing Minds.

image

I see a lot of businesses obsessing over content calendars.

They sit in meetings asking questions like: What should we post next week? Or How many videos do we need this month? Or Should we start a podcast?

In my experience, that’s usually the wrong conversation.

The better question is this:

What belief are you trying to create in the mind of your audience?

Because content by itself doesn’t do much. Anyone can produce content. AI has made that even easier. A few prompts and you’ve got articles, videos, social posts and newsletters ready to go.

The problem is that information is everywhere.

Attention isn’t.

Most Content Is Just Noise

An average marketer focuses on output.

More emails. More posts. More videos. More activity.

The assumption is that if you produce enough material, eventually customers will notice.

Sometimes they do. Most of the time they don’t.

What I’ve noticed when working with businesses is that content often becomes the goal rather than the vehicle. Teams celebrate publishing something without asking whether it changed how their audience thinks.

That’s a dangerous trap.

You can publish every day and still be invisible.

You can have thousands of followers and still struggle to generate sales.

Volume doesn’t create demand.

Changing beliefs does.

Leads Are Better. Beliefs Are Better Again.

A good marketer understands this and focuses on generating leads.

They want enquiries. Booked meetings. Website conversions. People entering the sales process.

That’s certainly an improvement.

But even then, many organisations are trying to persuade people who haven’t yet reached the point of wanting what they’re selling.

They are still fighting an uphill battle.

The strongest businesses I’ve observed create demand before the sales conversation even begins.

When a prospect turns up already convinced that a problem exists, already understands the cost of ignoring it, and already believes your approach is the right one, the sales process becomes dramatically easier.

The decision was largely made long before the sales call.

The content wasn’t there to inform.

It was there to shape perspective.

This Is Where Copilot Becomes Interesting

One of the reasons I’m paying close attention to Microsoft 365 Copilot isn’t because it helps create content faster.

Almost everyone talks about content production.

I think that’s the least interesting part.

The real opportunity is understanding what your audience already believes and what needs to change.

Imagine reviewing customer meeting notes stored in Teams, analysing recurring themes from emails in Outlook, and asking Copilot to identify the assumptions that repeatedly appear across conversations.

You might discover that clients believe AI is too expensive. Or too risky. Or only suitable for large enterprises.

Suddenly your next article isn’t chosen because somebody needed something to post on Tuesday.

It’s chosen because there’s a specific belief that needs challenging.

That’s a much more strategic use of both content and AI.

The Businesses Winning Attention Know Exactly What They’re Installing

The organisations that consistently attract customers don’t just share information.

They repeat ideas.

They reinforce viewpoints.

They help their audience see the world differently.

Over time those ideas compound.

Eventually prospects begin repeating those beliefs back to their colleagues, managers and peers.

That’s when demand starts appearing.

Not because your content reached more people.

Because it changed the way people think.

That’s a very different outcome.

The next time you’re planning content, I’d suggest stepping back from the calendar, the platform and the format.

Don’t start with the post.

Start with the belief.

Because when you know what belief you’re trying to create, the content becomes obvious.

And when enough people share that belief, demand tends to take care of itself.

The Recurring Problem: A Managed Services Story–Chapter 8

image

Previously – https://blog.ciaops.com/2026/08/01/the-recurring-problem-a-managed-services-story-chapter-7/

Denise Okafor called again in October, fourteen months after she’d left. Meridian Health IT, the healthcare specialist she’d switched to, had been acquired by a larger regional platform in the interim, and the transition had gone badly: her dedicated account team had been reassigned twice in five months, her monthly reporting had become generic boilerplate, and a recent phishing-simulation failure across two of her nine locations had gone unaddressed for three weeks.

image

“I saw your new compliance offering mentioned by another practice administrator at a conference,” she said, sounding almost embarrassed to be making the call. “I didn’t expect Bridgepoint to have become the thing I left Bridgepoint looking for.”

The proposal Jordan walked her through six weeks later bore almost no resemblance to the flat monthly bundle Lakeside had once had. It included a named security lead who would sit in on Lakeside’s own compliance committee meetings quarterly; documented incident-response procedures with contractual response-time guarantees, backed, for the first time in Bridgepoint’s history, by a real penalty clause; and an AI usage policy specifically written for a healthcare practice where several physicians had already started experimenting with AI transcription tools without anyone’s approval.

image

“What changed?” Denise asked Dave directly, at the contract signing.

“We stopped assuming that showing up mattered more than showing up for the right thing,” Dave said. “For a long time, I thought the job was being available. It turns out the job is knowing, better than the client does, what they’re actually going to need protection from next. We had to become the kind of company that could tell you that, instead of the kind that just answered the phone quickly after something already went wrong.”

Lakeside signed a three-year contract at a rate 34 percent higher than its original agreement. Denise didn’t blink.

image