Skip to content

Ops Log tag

#Microsoft 365

Reviewed Ops Log notes tagged Microsoft 365, written by Michal Jatczak with source links, test context and operational checks.

12 reviewed notes

Operator RunbookSecurity & Infrastructure

DMARC at p=none is not protection: what a deliverability check reads from public DNS

A DMARC record at p=none observes spoofing without blocking it. A free deliverability check reads SPF, DKIM, and DMARC from public DNS and tells you exactly which of those three is only watching. Here is how to run it and read it.

By Michal Jatczak
Decision MemoModern Workspace

Annual or month-to-month: the New Commerce term is a 20 percent decision

Under Microsoft New Commerce, the same Microsoft 365 seat costs about 20 percent more on a month-to-month term than on the annual term. The term you pick is a pricing decision on its own, before any tier change.

By Michal Jatczak
Decision MemoModern Workspace

The licence you keep paying for after the seat goes dark

License waste in Microsoft 365 has two honest layers: seats you can reclaim from hard data today, and a term premium you can model but not read from Graph. Here is how I separate them so the number I quote is defensible.

By Michal Jatczak
Change NoteModern Workspace

The Microsoft 365 July 2026 price change is really about commitment term

Microsoft reset Microsoft 365 list prices on 1 July 2026. The headline seat numbers moved a little; the commitment term moved a lot. Here are the confirmed figures and the tenant check to run before the next renewal.

By Michal Jatczak
Operator RunbookSecurity & Infrastructure

A 30-second Conditional Access read and the four gaps it usually surfaces

Four Conditional Access controls decide most of a Microsoft 365 tenant identity posture: admin MFA, legacy-auth block, MFA for all, and a device gate. Here is the read-only check that scores them and what each gap means.

By Michal Jatczak
Lab NoteSecurity & Infrastructure

The delegated OAuth grant that outlives the employee

Disabling an Entra account does not delete the delegated OAuth grants the person consented to. A third-party app can keep acting on a former employee until the grant itself is revoked. Here is how to read them and which scopes to treat as high risk.

By Michal Jatczak
Operator RunbookSecurity & Infrastructure

Mailbox forwarding rules survive the leaver: the offboarding check most runbooks skip

An enabled inbox forwarding or redirect rule keeps sending a departed employee mail long after the account is disabled. Here is how to find every one from Microsoft Graph and shut it before it becomes an exfiltration path.

By Michal Jatczak
Lab NoteSecurity & Infrastructure

What a Microsoft 365 offboarding scan finds after the account is disabled

Disabling an Entra account is the start of offboarding, not the end. Here are the eight access residues a read-only Microsoft Graph scan reads back, and why each one matters to an auditor.

By Michal Jatczak
Change NoteSecurity & Infrastructure

July 2026 Exchange Server security updates: confirm the build before removing the interim mitigation

The July 2026 Exchange SUs withdraw Microsoft's advice to keep the CVE-2026-42897 mitigation applied, but installing the update does not remove it. This note gives the per-SKU July build numbers, the PowerShell that reads the real SU level rather than the CU level, and the documented M2 rollback in an order that keeps the exposure window at zero, given that the code fix itself shipped in the June 2026 SU.

By Michal Jatczak
Operator RunbookAI & Automation

Onboarding automation: the role profile, the joiner event, and the five parts that break

An operator runbook for automated joiner provisioning in Microsoft Entra ID: the role-profile file, a normalised joiner event, a poll-for-readiness Graph sequence, the Temporary Access Pass trap that locks out day-one starters, and the formula to compute your own time saving.

By Michal Jatczak
Operator RunbookSecurity & Infrastructure

Fifteen Microsoft 365 tenant settings that need an explicit decision

Fifteen tenant-wide Microsoft 365 controls, each with the licence tier it actually needs, a read-only Graph, Exchange and SharePoint audit script, the side effects to plan for, and the rollback path. Six pieces of pre-2024 guidance in this area are corrected, five of them attached to numbered rows.

By Michal Jatczak
Operator RunbookSecurity & Infrastructure

Conditional Access: a ten-policy baseline and the order to deploy it in

Ten Conditional Access policies, the Microsoft Learn control behind each one, the report-only order that surfaces breakage before a user hits it, and an emergency-access design that survives the mandatory MFA enforcement on the Microsoft admin portals.

By Michal Jatczak

Adjacent tags

Ops Log briefing

Evidence you can inspect.

Michal's field notes on Microsoft 365, Azure and AI operations for regulated European teams.

  • Primary-source analysis
  • Tenant checks and tested configuration paths
  • Named author, test context, and visible limits

We send a confirmation link first. No briefing is scheduled before you confirm.