<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Pete Newcombe | newcombe.dev</title><description>Identity · Security · Cloud · Automation</description><link>https://newcombe.dev/</link><item><title>Troubleshooting Active Directory Account Lockouts with PowerShell</title><link>https://newcombe.dev/articles/ad-account-lockouts-powershell/</link><guid isPermaLink="true">https://newcombe.dev/articles/ad-account-lockouts-powershell/</guid><description>Use events 4740 and 4625 together to move from &apos;the account keeps locking&apos; to a timeline that identifies the source device, logon type and stale credential.</description><pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Finding Missing Active Directory Sites and Services Subnets from Netlogon</title><link>https://newcombe.dev/articles/ad-missing-sites-services-subnets/</link><guid isPermaLink="true">https://newcombe.dev/articles/ad-missing-sites-services-subnets/</guid><description>NO_CLIENT_SITE entries in Netlogon logs are useful evidence that client networks are not mapped cleanly to Active Directory sites. PowerShell can turn the logs into a subnet-hygiene report.</description><pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Browser-Centric vs Network-Centric Zero Trust</title><link>https://newcombe.dev/articles/browser-centric-vs-network-centric-zero-trust/</link><guid isPermaLink="true">https://newcombe.dev/articles/browser-centric-vs-network-centric-zero-trust/</guid><description>Enterprise browsers move enforcement into the user session. Network-centric Zero Trust still owns critical controls such as DNS, routing and non-browser traffic. The interesting architecture is often the combination.</description><pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Designing Zero Trust for Failure</title><link>https://newcombe.dev/articles/designing-zero-trust-for-failure/</link><guid isPermaLink="true">https://newcombe.dev/articles/designing-zero-trust-for-failure/</guid><description>Zero Trust is not resilient just because it is cloud-hosted. Identity, posture, policy, tunnels, DNS and SaaS authentication all create failure domains that need deliberate recovery paths.</description><pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Keeping Cloudflare Zero Trust Lists in Sync with Dynamic Cloud Provider IP Ranges</title><link>https://newcombe.dev/articles/dynamic-cloudflare-lists-from-cloud-provider-ranges/</link><guid isPermaLink="true">https://newcombe.dev/articles/dynamic-cloudflare-lists-from-cloud-provider-ranges/</guid><description>A practical pattern for consuming AWS/Azure network feeds, calculating desired state and safely synchronising Cloudflare Zero Trust lists with PowerShell.</description><pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Treating Cloudflare WARP Split Tunnels and Fallback Domains as Generated Configuration</title><link>https://newcombe.dev/articles/generated-warp-split-tunnels-and-fallback-domains/</link><guid isPermaLink="true">https://newcombe.dev/articles/generated-warp-split-tunnels-and-fallback-domains/</guid><description>When private sites and DNS exceptions multiply, WARP device-profile configuration becomes data. Source control can become the input and PowerShell the generator.</description><pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate></item><item><title>How I Prepared for CISSP and CCSP — and Passed Both First Time</title><link>https://newcombe.dev/articles/how-i-prepared-for-cissp-and-ccsp/</link><guid isPermaLink="true">https://newcombe.dev/articles/how-i-prepared-for-cissp-and-ccsp/</guid><description>The study approach I used for CISSP and CCSP: ISC2 official material, instructor-led training, practice questions, Pete Zerger&apos;s Last Mile resources, and more than 20 years of practical experience.</description><pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Building Safe Cloudflare Zero Trust Deployment Pipelines</title><link>https://newcombe.dev/articles/safe-cloudflare-zero-trust-deployment-pipelines/</link><guid isPermaLink="true">https://newcombe.dev/articles/safe-cloudflare-zero-trust-deployment-pipelines/</guid><description>As Zero Trust policy grows, the engineering problem shifts from configuring a dashboard to safely compiling, validating and deploying policy across environments.</description><pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Why IP-Based Egress Steering Does Not Scale</title><link>https://newcombe.dev/articles/why-ip-based-egress-steering-does-not-scale/</link><guid isPermaLink="true">https://newcombe.dev/articles/why-ip-based-egress-steering-does-not-scale/</guid><description>Static IP and subnet rules become fragile when SaaS platforms and CDNs move underneath you. Domain-aware egress policy aligns network controls with application intent.</description><pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate></item></channel></rss>