Skip to content

Ops Log topic

Security & Infrastructure

Reviewed Security & Infrastructure field notes by Michal Jatczak. Each public note includes its evidence, test context and a check you can run.

18 reviewed notes

Operator RunbookSecurity & Infrastructure

Fifteen Microsoft 365 tenant settings that need an explicit decision

Fifteen tenant-wide Microsoft 365 controls, each with the licence tier it actually needs, a read-only Graph, Exchange and SharePoint audit script, the side effects to plan for, and the rollback path. Six pieces of pre-2024 guidance in this area are corrected, five of them attached to numbered rows.

By Michal Jatczak
Operator RunbookSecurity & Infrastructure

NIS2 for managed service providers: who is actually in scope, and what Article 21 requires

A clause-by-clause scoping runbook for managed service providers under Directive (EU) 2022/2555: the size test that lives in the SME Recommendation, the closed Article 2(2) list that does not name MSPs, the Article 21(2) control set as expanded by Implementing Regulation (EU) 2024/2690, and the Article 23 reporting clock with the MSP-specific significance thresholds.

By Michal Jatczak
Decision MemoSecurity & Infrastructure

Backup after 3-2-1: immutability modes, drill cadence, and the evidence an auditor accepts

3-2-1 describes the shape of a backup estate but says nothing about its blast radius. This memo settles four decisions: compliance-mode retention over governance mode, two retention tiers sized separately, a second party on destructive operations, and a drill that leaves a dated artefact behind.

By Michal Jatczak
Operator RunbookSecurity & Infrastructure

Running Prometheus, Loki and Alertmanager on one VM: configuration, retention and cost

A single-VM Prometheus, Loki, Alertmanager and Grafana deployment that starts on the first attempt: the retention flags that belong on the command line, the disk-sizing formula that decides the machine class, alert rules with the false-page guards in place, and a cost model built from published list prices instead of asserted savings.

By Michal Jatczak
Operator RunbookSecurity & Infrastructure

Conditional Access: a ten-policy baseline and the order to deploy it in

Ten Conditional Access policies, the Microsoft Learn control behind each one, the report-only order that surfaces breakage before a user hits it, and an emergency-access design that survives the mandatory MFA enforcement on the Microsoft admin portals.

By Michal Jatczak
Operator RunbookSecurity & Infrastructure

Network segmentation for a 100 to 500 seat office: VLANs, policy as code and the identity overlay

A cutover runbook for turning a flat office LAN into purpose-based zones: the VLAN scheme, the 802.1X and RADIUS layer that actually places a device into a zone, firewall policy held in version control, host-level nftables, and an independent rollback path for every stage.

By Michal Jatczak
Ops Log briefing

Evidence you can inspect.

Michal's field notes on Microsoft 365, Azure and AI operations for regulated European teams.

  • Primary-source analysis
  • Tenant checks and tested configuration paths
  • Named author, test context, and visible limits

We send a confirmation link first. No briefing is scheduled before you confirm.