Skip to content

Ops Log topic

Security & Infrastructure

Reviewed Security & Infrastructure field notes by Michal Jatczak. Each public note includes its evidence, test context and a check you can run.

18 reviewed notes

Operator RunbookSecurity & Infrastructure

The offboarding runbook and the MTTFAR clock

Offboarding is a race against the access a leaver still holds. This is the order of operations I run and the mean-time-to-full-access-revocation targets I hold each departure to, from a standard leaver to a hostile termination.

By Michal Jatczak
Decision MemoSecurity & Infrastructure

The offboarding evidence pack, control by control

An auditor does not ask whether an offboarding SOP exists. They ask for the artifact that proves each control ran. Here are the twelve controls I build the evidence pack around and the proof each one needs.

By Michal Jatczak
Operator RunbookSecurity & Infrastructure

DMARC at p=none is not protection: what a deliverability check reads from public DNS

A DMARC record at p=none observes spoofing without blocking it. A free deliverability check reads SPF, DKIM, and DMARC from public DNS and tells you exactly which of those three is only watching. Here is how to run it and read it.

By Michal Jatczak
Operator RunbookSecurity & Infrastructure

A 30-second Conditional Access read and the four gaps it usually surfaces

Four Conditional Access controls decide most of a Microsoft 365 tenant identity posture: admin MFA, legacy-auth block, MFA for all, and a device gate. Here is the read-only check that scores them and what each gap means.

By Michal Jatczak
Lab NoteSecurity & Infrastructure

The delegated OAuth grant that outlives the employee

Disabling an Entra account does not delete the delegated OAuth grants the person consented to. A third-party app can keep acting on a former employee until the grant itself is revoked. Here is how to read them and which scopes to treat as high risk.

By Michal Jatczak
Operator RunbookSecurity & Infrastructure

Mailbox forwarding rules survive the leaver: the offboarding check most runbooks skip

An enabled inbox forwarding or redirect rule keeps sending a departed employee mail long after the account is disabled. Here is how to find every one from Microsoft Graph and shut it before it becomes an exfiltration path.

By Michal Jatczak
Lab NoteSecurity & Infrastructure

What a Microsoft 365 offboarding scan finds after the account is disabled

Disabling an Entra account is the start of offboarding, not the end. Here are the eight access residues a read-only Microsoft Graph scan reads back, and why each one matters to an auditor.

By Michal Jatczak
Change NoteSecurity & Infrastructure

July 2026 Exchange Server security updates: confirm the build before removing the interim mitigation

The July 2026 Exchange SUs withdraw Microsoft's advice to keep the CVE-2026-42897 mitigation applied, but installing the update does not remove it. This note gives the per-SKU July build numbers, the PowerShell that reads the real SU level rather than the CU level, and the documented M2 rollback in an order that keeps the exposure window at zero, given that the code fix itself shipped in the June 2026 SU.

By Michal Jatczak
Operator RunbookSecurity & Infrastructure

An incident-response playbook for a team without a security operations centre

A first-hours runbook for a 4 to 15 person technical team on Microsoft 365: the three EU reporting clocks and the event that actually starts each one, a containment sequence that captures evidence before it cuts access, and the documented side effects and rollback for every high-blast-radius action.

By Michal Jatczak
Operator RunbookSecurity & Infrastructure

A 47-point offboarding checklist and the three tiers that decide how fast to run it

A 47-point leaver checklist derived from ISO/IEC 27001:2022 Annex A control text and current vendor documentation, with three escalation tiers, a runnable Microsoft Graph identity block, and the token-lifetime arithmetic that decides when revocation has actually landed.

By Michal Jatczak
Decision MemoSecurity & Infrastructure

DORA in practice: the three report clocks, the major-incident gate, and the evidence pack

DORA has been enforceable since 17 January 2025, and under Article 5 of Commission Delegated Regulation (EU) 2025/301 each of the three reports on a major incident runs from a different event. This memo rebuilds the deadlines against that article, ships a PowerShell function that computes them, separates the Article 35 penalty on critical third-party providers from the Article 50 regime that applies to financial entities, and lists the evidence the regulation requires you to hold.

By Michal Jatczak
Operator RunbookSecurity & Infrastructure

Eight Azure cost levers, and how to size each one on your own bill

Eight Azure cost levers with the formula for each, so the figure comes from your own consumption data rather than someone else's case study: an inventory script, the Advisor thresholds that actually apply, the retention and rehydration penalties on blob tiering, what a Basic log plan costs in detection capability, and a rollback order ranked by reversibility.

By Michal Jatczak
Ops Log briefing

Evidence you can inspect.

Michal's field notes on Microsoft 365, Azure and AI operations for regulated European teams.

  • Primary-source analysis
  • Tenant checks and tested configuration paths
  • Named author, test context, and visible limits

We send a confirmation link first. No briefing is scheduled before you confirm.