Ops Log tag
#Zero Trust
Reviewed Ops Log notes tagged Zero Trust, written by Michal Jatczak with source links, test context and operational checks.
4 reviewed notes
Editing a Conditional Access custom control means deleting it, and creation stops in September 2026
Microsoft blocks the creation and editing of Conditional Access custom controls from September 2026, and the only editing procedure it documents is to delete the control and create a replacement. This note gives the read-only check that finds the affected policies, and the decision to take before the block lands.
A 30-second Conditional Access read and the four gaps it usually surfaces
Four Conditional Access controls decide most of a Microsoft 365 tenant identity posture: admin MFA, legacy-auth block, MFA for all, and a device gate. Here is the read-only check that scores them and what each gap means.
Conditional Access: a ten-policy baseline and the order to deploy it in
Ten Conditional Access policies, the Microsoft Learn control behind each one, the report-only order that surfaces breakage before a user hits it, and an emergency-access design that survives the mandatory MFA enforcement on the Microsoft admin portals.
Network segmentation for a 100 to 500 seat office: VLANs, policy as code and the identity overlay
A cutover runbook for turning a flat office LAN into purpose-based zones: the VLAN scheme, the 802.1X and RADIUS layer that actually places a device into a zone, firewall policy held in version control, host-level nftables, and an independent rollback path for every stage.