Skip to content

Ops Log tag

#Identity

Reviewed Ops Log notes tagged Identity, written by Michal Jatczak with source links, test context and operational checks.

7 reviewed notes

Operator RunbookSecurity & Infrastructure

The Google Workspace scope for reading a leaver's app grants is not read-only

Listing a Google Workspace user's third-party app tokens needs admin.directory.user.security, the same scope that deletes them, and Google lists no read-only variant. Microsoft Graph lists the equivalent grants with Directory.Read.All. Treat the Google credential as a revocation key.

By Michal Jatczak
Decision MemoSecurity & Infrastructure

A daily offboarding check can prove closure only as a bound

A leaver check that runs once a day can report closure only as a bound between two runs. A Graph 429, including one inside a batch that returns 200, and a membership read that returns nulls can each make a degraded run look clean, so an absence counts only from a run that read cleanly.

By Michal Jatczak
Decision MemoSecurity & Infrastructure

Google's admin.directory.user.security scope has no read-only form

Google publishes no read-only form of the admin.directory.user.security scope. The scope that lists a user's OAuth tokens and app passwords is the same scope that deletes them, so treat any grant of it as a write permission when reviewing a third-party app.

By Michal Jatczak
Decision MemoSecurity & Infrastructure

Editing a Conditional Access custom control means deleting it, and creation stops in September 2026

Microsoft blocks the creation and editing of Conditional Access custom controls from September 2026, and the only editing procedure it documents is to delete the control and create a replacement. This note gives the read-only check that finds the affected policies, and the decision to take before the block lands.

By Michal Jatczak
Operator RunbookSecurity & Infrastructure

An empty Baseline scopes settings page proves nothing about the enforcement rollout

A Conditional Access policy targeting All resources with a resource exclusion now enforces on sign-ins requesting only baseline scopes, and the Baseline scopes settings page renders empty whether or not the rollout reached the tenant. Inventory the policy shape, the only part a read-only call can measure.

By Michal Jatczak
Lab NoteSecurity & Infrastructure

The delegated OAuth grant that outlives the employee

Disabling an Entra account does not delete the delegated OAuth grants the person consented to. A third-party app can keep acting on a former employee until the grant itself is revoked. Here is how to read them and which scopes to treat as high risk.

By Michal Jatczak
Lab NoteSecurity & Infrastructure

What a Microsoft 365 offboarding scan finds after the account is disabled

Disabling an Entra account is the start of offboarding, not the end. Here are the eight access residues a read-only Microsoft Graph scan reads back, and why each one matters to an auditor.

By Michal Jatczak

Adjacent tags

Ops Log briefing

Evidence you can inspect.

Michal's field notes on Microsoft 365, Azure and AI operations for regulated European teams.

  • Primary-source analysis
  • Tenant checks and tested configuration paths
  • Named author, test context, and visible limits

We send a confirmation link first. No briefing is scheduled before you confirm.