CoreView Intelligence Labs starts with Microsoft 365 administration fundamentals
CoreView describes Intelligence Labs as a public research and education program for Microsoft 365 administrators, security teams and IT leaders. Its stated subjects include identity and access risk, configuration drift, SharePoint permissions, Conditional Access, audit gaps, AI readiness and tenant recovery. That scope puts everyday configuration and governance decisions at the centre of the project.
The initiative is led by Kasper Lindgaard, CoreView’s vice president of security strategy and a former leader of Secunia Research. CoreView also names senior cloud security engineer Roberto D’Andrea among its authors. The company says each article has a named practitioner author and receives technical review; it further says it does not use AI to draft or edit Intelligence Labs content. Those are CoreView’s editorial commitments, not an external assessment of its research quality.
There is some continuity behind the launch. SecurityBrief reported Lindgaard’s appointment on June 9, 2026, and described a research initiative he would lead as “Security Labs.” September’s announcement and CoreView’s current website use “Intelligence Labs.” The earlier reporting establishes that the research effort was already part of his remit, although it does not explain the naming change.
For readers, the important boundary is ownership: this is CoreView’s research program. Its technical recommendations should be evaluated on their evidence and applicability, separately from the company’s commercial argument for additional Microsoft 365 management tooling.
The Entra catalogue gives the launch a concrete starting point
Intelligence Labs already has published material behind its announcement. CoreView’s catalogue lists an August 17 article on applications and non-human identities in Microsoft Entra, an August 27 passkey deployment guide, a September 3 passkey explainer, a September 4 article on enterprise application authentication and a September 7 authentication-methods guide. The September 22 launch therefore introduces a program with an existing body of work.
The distinction between human and application identities is a useful organising principle. The catalogue addresses both how people authenticate and how applications obtain access, giving administrators separate subjects to evaluate instead of treating all authentication as a single user sign-in problem.
CoreView’s September 3 explainer offers a more specific example of the intended depth. It describes passkeys as public-private key pairs: a service registers the public key, while the authenticator uses the private key to sign a challenge during authentication. It then separates device-bound passkeys, which remain tied to a particular device, from synced passkeys distributed through a credential provider.
That comparison leads to an operational decision. CoreView favours device-bound credentials for privileged or particularly sensitive access, while discussing synced credentials as a lower-friction option for general employees. Its reasoning combines security policy with the practical consequences of device availability and account recovery.
The article also makes claims about Microsoft’s passkey rollout and SMS/voice authentication retirement dates. Those deadlines are not corroborated by a Microsoft primary record in the available evidence and should not be treated here as established deployment requirements. The useful takeaway from this launch is the program’s technical coverage, not a newly verified Microsoft migration timetable.
Microsoft 365 teams can use Intelligence Labs selectively
Administrators can treat Intelligence Labs as an additional source of technical analysis, with the existing authentication articles offering a more concrete starting point than its broader research ambitions. The launch itself calls for no emergency configuration change.
- Start with a published article that matches an actual administration task, such as assessing passkey options or understanding application identities.
- Keep privileged-user authentication decisions separate from general employee convenience decisions; CoreView’s passkey analysis explicitly discusses different trade-offs.
- Include device loss and account recovery in passkey planning, because the choice of credential model affects access when a device becomes unavailable.
- Distinguish published technical guidance from declared research interests: listing audit gaps, tenant recovery or AI readiness does not itself establish a new finding in those areas.
- Treat Microsoft rollout dates, licensing requirements and enforcement deadlines as separate verification questions before turning vendor guidance into a change request.
CoreView has given Intelligence Labs a concrete starting point through its existing Entra authentication material. For Microsoft 365 teams, its value will come from individual articles that explain a control, expose a configuration assumption or support a better operational decision. The sensible response to the launch is selective use of that material, with deployment authority kept inside the organisation’s established security and change-management process.