Change Notes
What changed, who it affects, and the tenant check to run now.
Delivers
Act, schedule, monitor, or ignore
Ops Log by Michal Jatczak
Microsoft 365, Azure, security, and production AI notes built from primary sources, controlled tests, and clear operator decisions.
Written and reviewed by Michal Jatczak
ITSailor founder, operating from Malta
Editorial series
The format tells you what evidence to expect before you open a note.
What changed, who it affects, and the tenant check to run now.
Delivers
Act, schedule, monitor, or ignore
Admin paths, commands, expected output, side effects, and rollback.
Delivers
A task you can execute and reverse
Test conditions, screenshots, results, failures, and limits.
Delivers
Evidence with enough context to challenge it
A direct recommendation, the trade-offs, and where it stops applying.
Delivers
A decision and its reversal trigger
Archive
Search the archive or browse by operational topic.
Listing a Google Workspace user's third-party app tokens needs admin.directory.user.security, the same scope that deletes them, and Google lists no read-only variant. Microsoft Graph lists the equivalent grants with Directory.Read.All. Treat the Google credential as a revocation key.
A leaver check that runs once a day can report closure only as a bound between two runs. A Graph 429, including one inside a batch that returns 200, and a membership read that returns nulls can each make a degraded run look clean, so an absence counts only from a run that read cleanly.
By Michal Jatczak
Under a Microsoft Customer Agreement, Azure credits are applied to a billing profile invoice and a Cost Management budget only notifies. Read the billing profile spendingLimit property before trusting anything to stop spend, and use an Azure Policy deny rule where new spend must be refused.
By Michal Jatczak
az vm list-usage reports vCPU quota per VM size family. Measured 2026-09-15 on one subscription: a family read 0 of 10 vCPUs used while all 10 of its sizes carried a NotAvailableForSubscription restriction in the same region. Check az vm list-skus with --all before planning.
By Michal Jatczak
Microsoft documents two DKIM CNAME target formats for Microsoft 365 custom domains, one ending in onmicrosoft.com and one in dkim.mail.microsoft. The page splits them by new versus existing custom domain and never mentions tenant age. Read each domain's values with Get-DkimSigningConfig.
By Michal Jatczak
Microsoft's CSP documentation says partners are barred by contract from selling Microsoft or third-party offers to themselves or an affiliate as end customer. The same page names two own-use routes: a Shared Services tenant for Azure, or a separate tenant bought through another CSP partner.
By Michal Jatczak
Cost Management Reader is described as able to view cost data, yet its action list carries a Microsoft.Support wildcard that includes creating and updating support tickets. The built-in Reader role matches it on every Cost Management feature and cannot write a ticket.
By Michal Jatczak
Google publishes no read-only form of the admin.directory.user.security scope. The scope that lists a user's OAuth tokens and app passwords is the same scope that deletes them, so treat any grant of it as a write permission when reviewing a third-party app.
By Michal Jatczak
A Cost Management query returned 429 on 2026-08-14 while the response header for the documented per tenant quota still reported 597 of 600 hourly queries left. The exhausted bucket belonged to the caller's client type, and the same request body with a ClientType header returned 200 seconds later.
By Michal Jatczak
Architecture Workshop
Two hours in your tenant. You leave with a Microsoft 365 security baseline, a deployable architecture plan, and an Exit Kit you own.