Skip to content

Ops Log tag

#Security

Reviewed Ops Log notes tagged Security, written by Michal Jatczak with source links, test context and operational checks.

17 reviewed notes

Operator RunbookSecurity & Infrastructure

The Google Workspace scope for reading a leaver's app grants is not read-only

Listing a Google Workspace user's third-party app tokens needs admin.directory.user.security, the same scope that deletes them, and Google lists no read-only variant. Microsoft Graph lists the equivalent grants with Directory.Read.All. Treat the Google credential as a revocation key.

By Michal Jatczak
Operator RunbookSecurity & Infrastructure

A Microsoft 365 DKIM CNAME target has two documented formats: read it per domain, never build it

Microsoft documents two DKIM CNAME target formats for Microsoft 365 custom domains, one ending in onmicrosoft.com and one in dkim.mail.microsoft. The page splits them by new versus existing custom domain and never mentions tenant age. Read each domain's values with Get-DkimSigningConfig.

By Michal Jatczak
Decision MemoSecurity & Infrastructure

The Azure role called Cost Management Reader is not read-only

Cost Management Reader is described as able to view cost data, yet its action list carries a Microsoft.Support wildcard that includes creating and updating support tickets. The built-in Reader role matches it on every Cost Management feature and cannot write a ticket.

By Michal Jatczak
Decision MemoSecurity & Infrastructure

Google's admin.directory.user.security scope has no read-only form

Google publishes no read-only form of the admin.directory.user.security scope. The scope that lists a user's OAuth tokens and app passwords is the same scope that deletes them, so treat any grant of it as a write permission when reviewing a third-party app.

By Michal Jatczak
Decision MemoSecurity & Infrastructure

The Graph site permissions endpoint lists application grants: Sites.FullControl.All buys an empty array

GET /sites/{siteId}/permissions lists the grants held by applications on a site, not the people who can open it, and returns an empty array on any tenant that never used Sites.Selected. Microsoft documents Sites.FullControl.All as its least privileged permission. Two cheaper reads answer the real question.

By Michal Jatczak
Decision MemoSecurity & Infrastructure

Editing a Conditional Access custom control means deleting it, and creation stops in September 2026

Microsoft blocks the creation and editing of Conditional Access custom controls from September 2026, and the only editing procedure it documents is to delete the control and create a replacement. This note gives the read-only check that finds the affected policies, and the decision to take before the block lands.

By Michal Jatczak
Operator RunbookSecurity & Infrastructure

Microsoft 365 E3 gained Defender Plan 1 in July and impersonation protection is still off by default

Microsoft 365 E3 has included Defender for Office 365 Plan 1 since 1 July 2026, but user and domain impersonation protection stays applied to nobody until an administrator configures it. This runbook gives the read-only check that settles whether anything in the tenant is actually enforcing it.

By Michal Jatczak
Operator RunbookSecurity & Infrastructure

An empty Baseline scopes settings page proves nothing about the enforcement rollout

A Conditional Access policy targeting All resources with a resource exclusion now enforces on sign-ins requesting only baseline scopes, and the Baseline scopes settings page renders empty whether or not the rollout reached the tenant. Inventory the policy shape, the only part a read-only call can measure.

By Michal Jatczak
Operator RunbookSecurity & Infrastructure

DMARC at p=none is not protection: what a deliverability check reads from public DNS

A DMARC record at p=none observes spoofing without blocking it. A free deliverability check reads SPF, DKIM, and DMARC from public DNS and tells you exactly which of those three is only watching. Here is how to run it and read it.

By Michal Jatczak
Lab NoteSecurity & Infrastructure

The delegated OAuth grant that outlives the employee

Disabling an Entra account does not delete the delegated OAuth grants the person consented to. A third-party app can keep acting on a former employee until the grant itself is revoked. Here is how to read them and which scopes to treat as high risk.

By Michal Jatczak
Operator RunbookSecurity & Infrastructure

Mailbox forwarding rules survive the leaver: the offboarding check most runbooks skip

An enabled inbox forwarding or redirect rule keeps sending a departed employee mail long after the account is disabled. Here is how to find every one from Microsoft Graph and shut it before it becomes an exfiltration path.

By Michal Jatczak
Change NoteSecurity & Infrastructure

July 2026 Exchange Server security updates: confirm the build before removing the interim mitigation

The July 2026 Exchange SUs withdraw Microsoft's advice to keep the CVE-2026-42897 mitigation applied, but installing the update does not remove it. This note gives the per-SKU July build numbers, the PowerShell that reads the real SU level rather than the CU level, and the documented M2 rollback in an order that keeps the exposure window at zero, given that the code fix itself shipped in the June 2026 SU.

By Michal Jatczak

Adjacent tags

Ops Log briefing

Evidence you can inspect.

Michal's field notes on Microsoft 365, Azure and AI operations for regulated European teams.

  • Primary-source analysis
  • Tenant checks and tested configuration paths
  • Named author, test context, and visible limits

We send a confirmation link first. No briefing is scheduled before you confirm.