ABOUT US
About
I’m Kimberly Henry, Founder and Principal Consultant of ForgeNorth Advisory. I’m a senior Microsoft 365 and identity engineer with experience leading IT operations and designing and securing production environments across global organizations.
My work has centered on Microsoft Entra ID, Conditional Access, Exchange Online, Intune, SharePoint, and Microsoft Defender, identifying risk, responding to threats, and making practical improvements to real-world tenant security.
I founded ForgeNorth Advisory because I’m passionate about helping businesses protect what they’ve worked so hard to build. Smaller organizations face a particular challenge. They often lack the staffing, tools, or capacity to continuously monitor their Microsoft 365 environments because they’re already balancing countless priorities just to serve their customers and remain profitable (not because security isn’t important to them).

Kimberly Henry | Founder & Principal Consultant
Protecting What You’ve Built
Unfortunately, a compromise can remain undetected for weeks or months while causing financial loss, disrupting operations, or damaging a company’s reputation. And businesses that use Microsoft 365 primarily for email are not immune; email itself is one of the the most frequently targeted entry points. According to the FBI’s 2024 Internet Crime Report, Business Email Compromise (BEC) accounted for more than $2.77 billion in losses. I explore this false sense of security and what businesses can do about it in “The ‘We Just Use Email’ Security Myth“.
And AI has fundamentally changed how we conduct and protect our businesses. The CrowdStrike 2026 Global Threat Report identifies an 89% increase in attacks from AI-enabled adversaries, underscoring how quickly the threat landscape continues to evolve.
My goal isn’t to create fear or overwhelm you with technical findings. It’s to provide clarity on what matters most, what can wait, and what practical steps will meaningfully reduce your risk.
I look forward to working with you to protect your business and accomplish your goals.
Experience
My experience comes from hands-on responsibility for Microsoft 365 and hybrid identity environments where security is more than theoretical; it’s operational. I’ve investigated suspicious activity, responded to compromised accounts, and addressed common attack paths involving inconsistent MFA coverage, excessive administrative access, and misconfigured policies.
My background also includes Active Directory, hybrid identity, and on-premises infrastructure. That broader perspective helps me understand how environments evolve, how older systems affect cloud security, and where risk is most likely to be introduced.
Earlier in my career, I worked as an independent consultant within the Microsoft ecosystem, delivering infrastructure and cloud solutions across a variety of client environments. This work provided direct exposure to how organizations actually build and manage technology, and not always under ideal conditions, but while balancing budgets, staffing limitations, legacy dependencies, and immediate business needs. It also taught me that security recommendations must be practical if they’re going to be implemented successfully.
Why ForgeNorth Advisory
Even well-managed Microsoft 365 environments can accumulate risk over time. Business requirements change, administrators come and go, new services are introduced, and policies that once made sense may no longer provide adequate protection. I created ForgeNorth Advisory to help organizations understand those risks without immediately committing to a large or open-ended consulting engagement.
At ForgeNorth Advisory, we approach every engagement with practical judgment, clear communication, and respect for each client’s priorities. Our recommendations are grounded in meaningful risk reduction and designed to be both practical and achievable.

