Skip to content

Ops Log topic

Security & Infrastructure field notes

Reviewed Security & Infrastructure field notes by Michal Jatczak. Each public note includes its evidence, test context and a check you can run.

33 reviewed notes

Operator RunbookSecurity & Infrastructure

The Google Workspace scope for reading a leaver's app grants is not read-only

Listing a Google Workspace user's third-party app tokens needs admin.directory.user.security, the same scope that deletes them, and Google lists no read-only variant. Microsoft Graph lists the equivalent grants with Directory.Read.All. Treat the Google credential as a revocation key.

By Michal Jatczak
Decision MemoSecurity & Infrastructure

A daily offboarding check can prove closure only as a bound

A leaver check that runs once a day can report closure only as a bound between two runs. A Graph 429, including one inside a batch that returns 200, and a membership read that returns nulls can each make a degraded run look clean, so an absence counts only from a run that read cleanly.

By Michal Jatczak
Decision MemoSecurity & Infrastructure

Under a Microsoft Customer Agreement, Azure credits sit on the billing profile and a budget does not stop spend past them

Under a Microsoft Customer Agreement, Azure credits are applied to a billing profile invoice and a Cost Management budget only notifies. Read the billing profile spendingLimit property before trusting anything to stop spend, and use an Azure Policy deny rule where new spend must be refused.

By Michal Jatczak
Lab NoteSecurity & Infrastructure

An Azure vCPU family quota can show ten cores free while every size in that family is restricted for the subscription

az vm list-usage reports vCPU quota per VM size family. Measured 2026-09-15 on one subscription: a family read 0 of 10 vCPUs used while all 10 of its sizes carried a NotAvailableForSubscription restriction in the same region. Check az vm list-skus with --all before planning.

By Michal Jatczak
Operator RunbookSecurity & Infrastructure

A Microsoft 365 DKIM CNAME target has two documented formats: read it per domain, never build it

Microsoft documents two DKIM CNAME target formats for Microsoft 365 custom domains, one ending in onmicrosoft.com and one in dkim.mail.microsoft. The page splits them by new versus existing custom domain and never mentions tenant age. Read each domain's values with Get-DkimSigningConfig.

By Michal Jatczak
Decision MemoSecurity & Infrastructure

The Azure role called Cost Management Reader is not read-only

Cost Management Reader is described as able to view cost data, yet its action list carries a Microsoft.Support wildcard that includes creating and updating support tickets. The built-in Reader role matches it on every Cost Management feature and cannot write a ticket.

By Michal Jatczak
Decision MemoSecurity & Infrastructure

Google's admin.directory.user.security scope has no read-only form

Google publishes no read-only form of the admin.directory.user.security scope. The scope that lists a user's OAuth tokens and app passwords is the same scope that deletes them, so treat any grant of it as a write permission when reviewing a third-party app.

By Michal Jatczak
Lab NoteSecurity & Infrastructure

Azure Cost Management can return 429 with 597 of 600 tenant queries unused: the exhausted bucket is the client type

A Cost Management query returned 429 on 2026-08-14 while the response header for the documented per tenant quota still reported 597 of 600 hourly queries left. The exhausted bucket belonged to the caller's client type, and the same request body with a ClientType header returned 200 seconds later.

By Michal Jatczak
Decision MemoSecurity & Infrastructure

The Graph site permissions endpoint lists application grants: Sites.FullControl.All buys an empty array

GET /sites/{siteId}/permissions lists the grants held by applications on a site, not the people who can open it, and returns an empty array on any tenant that never used Sites.Selected. Microsoft documents Sites.FullControl.All as its least privileged permission. Two cheaper reads answer the real question.

By Michal Jatczak
Decision MemoSecurity & Infrastructure

The MFSA closes the DORA register window on 21 March, and only a submission that reaches Accepted counts

The MFSA sets the DORA Register of Information window at 1 January to 21 March each year, with 31 December of the preceding year as the reference date, and counts only a submission that reaches Accepted on the LH Portal. Here are the dates, the provider level fields, and the December work behind them.

By Michal Jatczak
Change NoteSecurity & Infrastructure

Teams call records left chat retention policies in late April 2026: the replacement policy is PowerShell only

Since late April 2026 a new Teams call data record is covered only by a retention policy for the Teams call logs location, which exists only in PowerShell and reaches nothing created before it went active. The old chat policy stays green. This note gives the read-only check and the boundary of the gap.

By Michal Jatczak
Decision MemoSecurity & Infrastructure

Editing a Conditional Access custom control means deleting it, and creation stops in September 2026

Microsoft blocks the creation and editing of Conditional Access custom controls from September 2026, and the only editing procedure it documents is to delete the control and create a replacement. This note gives the read-only check that finds the affected policies, and the decision to take before the block lands.

By Michal Jatczak
Ops Log briefing

Evidence you can inspect.

Michal's field notes on Microsoft 365, Azure and AI operations for regulated European teams.

  • Primary-source analysis
  • Tenant checks and tested configuration paths
  • Named author, test context, and visible limits

We send a confirmation link first. No briefing is scheduled before you confirm.