Ops Log tag
#IAM
Reviewed Ops Log notes tagged IAM, written by Michal Jatczak with source links, test context and operational checks.
4 reviewed notes
A 30-second Conditional Access read and the four gaps it usually surfaces
Four Conditional Access controls decide most of a Microsoft 365 tenant identity posture: admin MFA, legacy-auth block, MFA for all, and a device gate. Here is the read-only check that scores them and what each gap means.
Onboarding automation: the role profile, the joiner event, and the five parts that break
An operator runbook for automated joiner provisioning in Microsoft Entra ID: the role-profile file, a normalised joiner event, a poll-for-readiness Graph sequence, the Temporary Access Pass trap that locks out day-one starters, and the formula to compute your own time saving.
A 47-point offboarding checklist and the three tiers that decide how fast to run it
A 47-point leaver checklist derived from ISO/IEC 27001:2022 Annex A control text and current vendor documentation, with three escalation tiers, a runnable Microsoft Graph identity block, and the token-lifetime arithmetic that decides when revocation has actually landed.
Conditional Access: a ten-policy baseline and the order to deploy it in
Ten Conditional Access policies, the Microsoft Learn control behind each one, the report-only order that surfaces breakage before a user hits it, and an emergency-access design that survives the mandatory MFA enforcement on the Microsoft admin portals.