Skip to content

Ops Log by Michal Jatczak

Operational answers you can verify in your own tenant.

Microsoft 365, Azure, security, and production AI notes built from primary sources, controlled tests, and clear operator decisions.

Michal Jatczak

Written and reviewed by Michal Jatczak

ITSailor founder, operating from Malta

Editorial series

Choose the evidence you need.

The format tells you what evidence to expect before you open a note.

Change Notes

What changed, who it affects, and the tenant check to run now.

Delivers

Act, schedule, monitor, or ignore

Operator Runbooks

Admin paths, commands, expected output, side effects, and rollback.

Delivers

A task you can execute and reverse

Lab Notes

Test conditions, screenshots, results, failures, and limits.

Delivers

Evidence with enough context to challenge it

Decision Memos

A direct recommendation, the trade-offs, and where it stops applying.

Delivers

A decision and its reversal trigger

Archive

Field notes

Search the archive or browse by operational topic.

Latest field note

26 notes
Decision MemoAI & Automation

Shadow AI is a governance-readiness problem, not a deadline

The first artifact three separate AI frameworks all demand is the same: a register of the AI systems in use, their data posture, and an owner. Build that register now for the governance value, and let the shifting AI Act dates be a secondary driver.

By Michal JatczakRead field note

More field notes

Operator RunbookSecurity & Infrastructure

The offboarding runbook and the MTTFAR clock

Offboarding is a race against the access a leaver still holds. This is the order of operations I run and the mean-time-to-full-access-revocation targets I hold each departure to, from a standard leaver to a hostile termination.

By Michal Jatczak

Decision MemoSecurity & Infrastructure

The offboarding evidence pack, control by control

An auditor does not ask whether an offboarding SOP exists. They ask for the artifact that proves each control ran. Here are the twelve controls I build the evidence pack around and the proof each one needs.

By Michal Jatczak

Operator RunbookSecurity & Infrastructure

DMARC at p=none is not protection: what a deliverability check reads from public DNS

A DMARC record at p=none observes spoofing without blocking it. A free deliverability check reads SPF, DKIM, and DMARC from public DNS and tells you exactly which of those three is only watching. Here is how to run it and read it.

By Michal Jatczak

Decision MemoModern Workspace

Annual or month-to-month: the New Commerce term is a 20 percent decision

Under Microsoft New Commerce, the same Microsoft 365 seat costs about 20 percent more on a month-to-month term than on the annual term. The term you pick is a pricing decision on its own, before any tier change.

By Michal Jatczak

Decision MemoModern Workspace

The licence you keep paying for after the seat goes dark

License waste in Microsoft 365 has two honest layers: seats you can reclaim from hard data today, and a term premium you can model but not read from Graph. Here is how I separate them so the number I quote is defensible.

By Michal Jatczak

Change NoteModern Workspace

The Microsoft 365 July 2026 price change is really about commitment term

Microsoft reset Microsoft 365 list prices on 1 July 2026. The headline seat numbers moved a little; the commitment term moved a lot. Here are the confirmed figures and the tenant check to run before the next renewal.

By Michal Jatczak

Operator RunbookSecurity & Infrastructure

A 30-second Conditional Access read and the four gaps it usually surfaces

Four Conditional Access controls decide most of a Microsoft 365 tenant identity posture: admin MFA, legacy-auth block, MFA for all, and a device gate. Here is the read-only check that scores them and what each gap means.

By Michal Jatczak

Lab NoteSecurity & Infrastructure

The delegated OAuth grant that outlives the employee

Disabling an Entra account does not delete the delegated OAuth grants the person consented to. A third-party app can keep acting on a former employee until the grant itself is revoked. Here is how to read them and which scopes to treat as high risk.

By Michal Jatczak

Ops Log briefing

Evidence you can inspect.

Michal's field notes on Microsoft 365, Azure and AI operations for regulated European teams.

  • Primary-source analysis
  • Tenant checks and tested configuration paths
  • Named author, test context, and visible limits

We send a confirmation link first. No briefing is scheduled before you confirm.

Architecture Workshop

Apply the same method to your own environment.

Two hours in your tenant. You leave with a Microsoft 365 security baseline, a deployable architecture plan, and an Exit Kit you own.

Review the €499 workshop
Ops Log - Microsoft 365 and Azure field notes | ITSailor