<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>#GSA on Daniyal Ahmed | Red Team &amp; Cloud Security</title><link>https://daniyalahmed.dev/tags/%23gsa/</link><description>Recent content in #GSA on Daniyal Ahmed | Red Team &amp; Cloud Security</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><managingEditor>daniyal.ahmed@microtechx.com (Daniyal Ahmed)</managingEditor><webMaster>daniyal.ahmed@microtechx.com (Daniyal Ahmed)</webMaster><lastBuildDate>Sun, 12 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://daniyalahmed.dev/tags/%23gsa/index.xml" rel="self" type="application/rss+xml"/><item><title>Building an EnterpriseGrade Zero Trust Azure Landing Zone (2026 Standards)</title><link>https://daniyalahmed.dev/posts/building-an-enterprisegrade-zero-trust-azure-landing-zone-2026-standards/</link><pubDate>Sun, 12 Jul 2026 00:00:00 +0000</pubDate><author>daniyal.ahmed@microtechx.com (Daniyal Ahmed)</author><guid>https://daniyalahmed.dev/posts/building-an-enterprisegrade-zero-trust-azure-landing-zone-2026-standards/</guid><description>If you&amp;rsquo;ve built Azure infrastructure before, you already know what the default posture looks like public IPs everywhere, storage accounts quietly exposed to the internet, NSGs that &amp;ldquo;allow all&amp;rdquo; because someone needed to test something and never reverted it. This blog tears all of that down and rebuilds it correctly: a five-phase Zero Trust landing zone designed specifically to frustrate lateral movement, eliminate data exfiltration paths, and force every workload through a central inspection chokepoint.</description></item></channel></rss>