Skip to content

Ops Log by Michal Jatczak

Operational answers you can verify in your own tenant.

Microsoft 365, Azure, security, and production AI notes built from primary sources, controlled tests, and clear operator decisions.

Michal Jatczak

Written and reviewed by Michal Jatczak

ITSailor founder, operating from Malta

Editorial series

Choose the evidence you need.

The format tells you what evidence to expect before you open a note.

Change Notes

What changed, who it affects, and the tenant check to run now.

Delivers

Act, schedule, monitor, or ignore

Operator Runbooks

Admin paths, commands, expected output, side effects, and rollback.

Delivers

A task you can execute and reverse

Lab Notes

Test conditions, screenshots, results, failures, and limits.

Delivers

Evidence with enough context to challenge it

Decision Memos

A direct recommendation, the trade-offs, and where it stops applying.

Delivers

A decision and its reversal trigger

Archive

Field notes

Search the archive or browse by operational topic.

Latest field note

47 notes
Operator RunbookSecurity & Infrastructure

The Google Workspace scope for reading a leaver's app grants is not read-only

Listing a Google Workspace user's third-party app tokens needs admin.directory.user.security, the same scope that deletes them, and Google lists no read-only variant. Microsoft Graph lists the equivalent grants with Directory.Read.All. Treat the Google credential as a revocation key.

By Michal JatczakRead field note

More field notes

Decision MemoSecurity & Infrastructure

A daily offboarding check can prove closure only as a bound

A leaver check that runs once a day can report closure only as a bound between two runs. A Graph 429, including one inside a batch that returns 200, and a membership read that returns nulls can each make a degraded run look clean, so an absence counts only from a run that read cleanly.

By Michal Jatczak

Decision MemoSecurity & Infrastructure

Under a Microsoft Customer Agreement, Azure credits sit on the billing profile and a budget does not stop spend past them

Under a Microsoft Customer Agreement, Azure credits are applied to a billing profile invoice and a Cost Management budget only notifies. Read the billing profile spendingLimit property before trusting anything to stop spend, and use an Azure Policy deny rule where new spend must be refused.

By Michal Jatczak

Lab NoteSecurity & Infrastructure

An Azure vCPU family quota can show ten cores free while every size in that family is restricted for the subscription

az vm list-usage reports vCPU quota per VM size family. Measured 2026-09-15 on one subscription: a family read 0 of 10 vCPUs used while all 10 of its sizes carried a NotAvailableForSubscription restriction in the same region. Check az vm list-skus with --all before planning.

By Michal Jatczak

Operator RunbookSecurity & Infrastructure

A Microsoft 365 DKIM CNAME target has two documented formats: read it per domain, never build it

Microsoft documents two DKIM CNAME target formats for Microsoft 365 custom domains, one ending in onmicrosoft.com and one in dkim.mail.microsoft. The page splits them by new versus existing custom domain and never mentions tenant age. Read each domain's values with Get-DkimSigningConfig.

By Michal Jatczak

Decision MemoModern Workspace

A CSP partner may not sell to itself or an affiliate: Microsoft names two own-use routes instead

Microsoft's CSP documentation says partners are barred by contract from selling Microsoft or third-party offers to themselves or an affiliate as end customer. The same page names two own-use routes: a Shared Services tenant for Azure, or a separate tenant bought through another CSP partner.

By Michal Jatczak

Decision MemoSecurity & Infrastructure

The Azure role called Cost Management Reader is not read-only

Cost Management Reader is described as able to view cost data, yet its action list carries a Microsoft.Support wildcard that includes creating and updating support tickets. The built-in Reader role matches it on every Cost Management feature and cannot write a ticket.

By Michal Jatczak

Decision MemoSecurity & Infrastructure

Google's admin.directory.user.security scope has no read-only form

Google publishes no read-only form of the admin.directory.user.security scope. The scope that lists a user's OAuth tokens and app passwords is the same scope that deletes them, so treat any grant of it as a write permission when reviewing a third-party app.

By Michal Jatczak

Lab NoteSecurity & Infrastructure

Azure Cost Management can return 429 with 597 of 600 tenant queries unused: the exhausted bucket is the client type

A Cost Management query returned 429 on 2026-08-14 while the response header for the documented per tenant quota still reported 597 of 600 hourly queries left. The exhausted bucket belonged to the caller's client type, and the same request body with a ClientType header returned 200 seconds later.

By Michal Jatczak

Every field note

47 notes
  1. The Google Workspace scope for reading a leaver's app grants is not read-only
  2. A daily offboarding check can prove closure only as a bound
  3. Under a Microsoft Customer Agreement, Azure credits sit on the billing profile and a budget does not stop spend past them
  4. An Azure vCPU family quota can show ten cores free while every size in that family is restricted for the subscription
  5. A Microsoft 365 DKIM CNAME target has two documented formats: read it per domain, never build it
  6. A CSP partner may not sell to itself or an affiliate: Microsoft names two own-use routes instead
  7. The Azure role called Cost Management Reader is not read-only
  8. Google's admin.directory.user.security scope has no read-only form
  9. Azure Cost Management can return 429 with 597 of 600 tenant queries unused: the exhausted bucket is the client type
  10. The Graph site permissions endpoint lists application grants: Sites.FullControl.All buys an empty array
  11. The MFSA closes the DORA register window on 21 March, and only a submission that reaches Accepted counts
  12. Teams call records left chat retention policies in late April 2026: the replacement policy is PowerShell only
  13. Editing a Conditional Access custom control means deleting it, and creation stops in September 2026
  14. A Graph meeting export can return an empty page that still carries a next link
  15. Leaving a general-purpose v1 storage account alone is treated as consent, and the unattended upgrade lands in Hot
  16. Windows 11 24H2 stops receiving updates a year earlier on Pro than on Enterprise, from the identical build
  17. Microsoft 365 E3 gained Defender Plan 1 in July and impersonation protection is still off by default
  18. Auto-renew off without an explicit cancel bills as an Extended Service Term
  19. An empty Baseline scopes settings page proves nothing about the enforcement rollout
  20. A Purview hold does not stop an unpaid OneDrive being deleted at day 365
  21. Anthropic in Excel and PowerPoint is a separate setting, on by default for EU tenants created after 25 March 2026
  22. Shadow AI is a governance-readiness problem, not a deadline
  23. The offboarding runbook and the MTTFAR clock
  24. The offboarding evidence pack, control by control
  25. DMARC at p=none is not protection: what a deliverability check reads from public DNS
  26. Annual or month-to-month: the New Commerce term is a 20 percent decision
  27. The licence you keep paying for after the seat goes dark
  28. The Microsoft 365 July 2026 price change is really about commitment term
  29. A 30-second Conditional Access read and the four gaps it usually surfaces
  30. The delegated OAuth grant that outlives the employee
  31. Mailbox forwarding rules survive the leaver: the offboarding check most runbooks skip
  32. What a Microsoft 365 offboarding scan finds after the account is disabled
  33. July 2026 Exchange Server security updates: confirm the build before removing the interim mitigation
  34. Onboarding automation: the role profile, the joiner event, and the five parts that break
  35. Self-hosted LLM serving in the EU: runtime choice, GPU sizing, and the sovereignty argument
  36. Retrieval over a permissioned corpus: ACL handling, the update pipeline, and what to measure
  37. An incident-response playbook for a team without a security operations centre
  38. A 47-point offboarding checklist and the three tiers that decide how fast to run it
  39. DORA in practice: the three report clocks, the major-incident gate, and the evidence pack
  40. Eight Azure cost levers, and how to size each one on your own bill
  41. Fifteen Microsoft 365 tenant settings that need an explicit decision
  42. NIS2 for managed service providers: who is actually in scope, and what Article 21 requires
  43. Backup after 3-2-1: immutability modes, drill cadence, and the evidence an auditor accepts
  44. Running Prometheus, Loki and Alertmanager on one VM: configuration, retention and cost
  45. Choosing a workflow engine: what a self-hosted n8n actually costs to run
  46. Conditional Access: a ten-policy baseline and the order to deploy it in
  47. Network segmentation for a 100 to 500 seat office: VLANs, policy as code and the identity overlay
Ops Log briefing

Evidence you can inspect.

Michal's field notes on Microsoft 365, Azure and AI operations for regulated European teams.

  • Primary-source analysis
  • Tenant checks and tested configuration paths
  • Named author, test context, and visible limits

We send a confirmation link first. No briefing is scheduled before you confirm.

Architecture Workshop

Apply the same method to your own environment.

Two hours in your tenant. You leave with a Microsoft 365 security baseline, a deployable architecture plan, and an Exit Kit you own.

Review the €499 workshop