Skip to content

Ops Log tag

#Compliance

Reviewed Ops Log notes tagged Compliance, written by Michal Jatczak with source links, test context and operational checks.

12 reviewed notes

Decision MemoSecurity & Infrastructure

Google's admin.directory.user.security scope has no read-only form

Google publishes no read-only form of the admin.directory.user.security scope. The scope that lists a user's OAuth tokens and app passwords is the same scope that deletes them, so treat any grant of it as a write permission when reviewing a third-party app.

By Michal Jatczak
Decision MemoSecurity & Infrastructure

The Graph site permissions endpoint lists application grants: Sites.FullControl.All buys an empty array

GET /sites/{siteId}/permissions lists the grants held by applications on a site, not the people who can open it, and returns an empty array on any tenant that never used Sites.Selected. Microsoft documents Sites.FullControl.All as its least privileged permission. Two cheaper reads answer the real question.

By Michal Jatczak
Decision MemoSecurity & Infrastructure

The MFSA closes the DORA register window on 21 March, and only a submission that reaches Accepted counts

The MFSA sets the DORA Register of Information window at 1 January to 21 March each year, with 31 December of the preceding year as the reference date, and counts only a submission that reaches Accepted on the LH Portal. Here are the dates, the provider level fields, and the December work behind them.

By Michal Jatczak
Change NoteSecurity & Infrastructure

Teams call records left chat retention policies in late April 2026: the replacement policy is PowerShell only

Since late April 2026 a new Teams call data record is covered only by a retention policy for the Teams call logs location, which exists only in PowerShell and reaches nothing created before it went active. The old chat policy stays green. This note gives the read-only check and the boundary of the gap.

By Michal Jatczak
Lab NoteAI & Automation

A Graph meeting export can return an empty page that still carries a next link

During a planned Microsoft Graph service update, paginated calls to getAllRecordings or getAllTranscripts can return HTTP 200 with an empty collection alongside a next link, then restart and re-serve items. An export loop that exits on no items stops there and reports success over a short archive.

By Michal Jatczak
Operator RunbookModern Workspace

A Purview hold does not stop an unpaid OneDrive being deleted at day 365

Since 1 July 2026 an unlicensed OneDrive that is neither relicensed nor covered by unlicensed-account billing is subject to deletion after 365 cumulative unpaid days, whatever Purview retention or hold sits on it, and it drops out of eDiscovery at day 275. This note gives the read-only check.

By Michal Jatczak
Change NoteAI & Automation

Anthropic in Excel and PowerPoint is a separate setting, on by default for EU tenants created after 25 March 2026

Copilot in Word, Excel and PowerPoint has its own Anthropic setting, a different object from the global Anthropic subprocessor control, and it defaults to on for EU, EFTA and UK tenants created after 25 March 2026. Whether anything actually leaves the EU Data Boundary turns on the second control, so read the tenant creation date and then read both.

By Michal Jatczak
Decision MemoAI & Automation

Shadow AI is a governance-readiness problem, not a deadline

The first artifact three separate AI frameworks all demand is the same: a register of the AI systems in use, their data posture, and an owner. Build that register now for the governance value, and let the shifting AI Act dates be a secondary driver.

By Michal Jatczak
Operator RunbookAI & Automation

Self-hosted LLM serving in the EU: runtime choice, GPU sizing, and the sovereignty argument

A runbook for deciding whether to self-host an open-weights model in the EU: the runtime field after TGI entered maintenance mode, GPU sizing computed from the model config instead of copied from a table, a corrected token-throughput cost model, and the DORA, NIS2 and AI Act record you will be asked for.

By Michal Jatczak
Operator RunbookSecurity & Infrastructure

A 47-point offboarding checklist and the three tiers that decide how fast to run it

A 47-point leaver checklist derived from ISO/IEC 27001:2022 Annex A control text and current vendor documentation, with three escalation tiers, a runnable Microsoft Graph identity block, and the token-lifetime arithmetic that decides when revocation has actually landed.

By Michal Jatczak
Decision MemoSecurity & Infrastructure

DORA in practice: the three report clocks, the major-incident gate, and the evidence pack

DORA has been enforceable since 17 January 2025, and under Article 5 of Commission Delegated Regulation (EU) 2025/301 each of the three reports on a major incident runs from a different event. This memo rebuilds the deadlines against that article, ships a PowerShell function that computes them, separates the Article 35 penalty on critical third-party providers from the Article 50 regime that applies to financial entities, and lists the evidence the regulation requires you to hold.

By Michal Jatczak
Operator RunbookSecurity & Infrastructure

NIS2 for managed service providers: who is actually in scope, and what Article 21 requires

A clause-by-clause scoping runbook for managed service providers under Directive (EU) 2022/2555: the size test that lives in the SME Recommendation, the closed Article 2(2) list that does not name MSPs, the Article 21(2) control set as expanded by Implementing Regulation (EU) 2024/2690, and the Article 23 reporting clock with the MSP-specific significance thresholds.

By Michal Jatczak

Adjacent tags

Ops Log briefing

Evidence you can inspect.

Michal's field notes on Microsoft 365, Azure and AI operations for regulated European teams.

  • Primary-source analysis
  • Tenant checks and tested configuration paths
  • Named author, test context, and visible limits

We send a confirmation link first. No briefing is scheduled before you confirm.