Ops Log tag
#Audit
Reviewed Ops Log notes tagged Audit, written by Michal Jatczak with source links, test context and operational checks.
14 reviewed notes
The Google Workspace scope for reading a leaver's app grants is not read-only
Listing a Google Workspace user's third-party app tokens needs admin.directory.user.security, the same scope that deletes them, and Google lists no read-only variant. Microsoft Graph lists the equivalent grants with Directory.Read.All. Treat the Google credential as a revocation key.
A daily offboarding check can prove closure only as a bound
A leaver check that runs once a day can report closure only as a bound between two runs. A Graph 429, including one inside a batch that returns 200, and a membership read that returns nulls can each make a degraded run look clean, so an absence counts only from a run that read cleanly.
The Azure role called Cost Management Reader is not read-only
Cost Management Reader is described as able to view cost data, yet its action list carries a Microsoft.Support wildcard that includes creating and updating support tickets. The built-in Reader role matches it on every Cost Management feature and cannot write a ticket.
Google's admin.directory.user.security scope has no read-only form
Google publishes no read-only form of the admin.directory.user.security scope. The scope that lists a user's OAuth tokens and app passwords is the same scope that deletes them, so treat any grant of it as a write permission when reviewing a third-party app.
The Graph site permissions endpoint lists application grants: Sites.FullControl.All buys an empty array
GET /sites/{siteId}/permissions lists the grants held by applications on a site, not the people who can open it, and returns an empty array on any tenant that never used Sites.Selected. Microsoft documents Sites.FullControl.All as its least privileged permission. Two cheaper reads answer the real question.
The MFSA closes the DORA register window on 21 March, and only a submission that reaches Accepted counts
The MFSA sets the DORA Register of Information window at 1 January to 21 March each year, with 31 December of the preceding year as the reference date, and counts only a submission that reaches Accepted on the LH Portal. Here are the dates, the provider level fields, and the December work behind them.
Teams call records left chat retention policies in late April 2026: the replacement policy is PowerShell only
Since late April 2026 a new Teams call data record is covered only by a retention policy for the Teams call logs location, which exists only in PowerShell and reaches nothing created before it went active. The old chat policy stays green. This note gives the read-only check and the boundary of the gap.
A Graph meeting export can return an empty page that still carries a next link
During a planned Microsoft Graph service update, paginated calls to getAllRecordings or getAllTranscripts can return HTTP 200 with an empty collection alongside a next link, then restart and re-serve items. An export loop that exits on no items stops there and reports success over a short archive.
Microsoft 365 E3 gained Defender Plan 1 in July and impersonation protection is still off by default
Microsoft 365 E3 has included Defender for Office 365 Plan 1 since 1 July 2026, but user and domain impersonation protection stays applied to nobody until an administrator configures it. This runbook gives the read-only check that settles whether anything in the tenant is actually enforcing it.
A Purview hold does not stop an unpaid OneDrive being deleted at day 365
Since 1 July 2026 an unlicensed OneDrive that is neither relicensed nor covered by unlicensed-account billing is subject to deletion after 365 cumulative unpaid days, whatever Purview retention or hold sits on it, and it drops out of eDiscovery at day 275. This note gives the read-only check.
Shadow AI is a governance-readiness problem, not a deadline
The first artifact three separate AI frameworks all demand is the same: a register of the AI systems in use, their data posture, and an owner. Build that register now for the governance value, and let the shifting AI Act dates be a secondary driver.
The offboarding evidence pack, control by control
An auditor does not ask whether an offboarding SOP exists. They ask for the artifact that proves each control ran. Here are the twelve controls I build the evidence pack around and the proof each one needs.