Change Notes
What changed, who it affects, and the tenant check to run now.
Delivers
Act, schedule, monitor, or ignore
Ops Log by Michal Jatczak
Microsoft 365, Azure, security, and production AI notes built from primary sources, controlled tests, and clear operator decisions.
Written and reviewed by Michal Jatczak
ITSailor founder, operating from Malta
Editorial series
The format tells you what evidence to expect before you open a note.
What changed, who it affects, and the tenant check to run now.
Delivers
Act, schedule, monitor, or ignore
Admin paths, commands, expected output, side effects, and rollback.
Delivers
A task you can execute and reverse
Test conditions, screenshots, results, failures, and limits.
Delivers
Evidence with enough context to challenge it
A direct recommendation, the trade-offs, and where it stops applying.
Delivers
A decision and its reversal trigger
Archive
Search the archive or browse by operational topic.
An enabled inbox forwarding or redirect rule keeps sending a departed employee mail long after the account is disabled. Here is how to find every one from Microsoft Graph and shut it before it becomes an exfiltration path.
By Michal Jatczak
Disabling an Entra account is the start of offboarding, not the end. Here are the eight access residues a read-only Microsoft Graph scan reads back, and why each one matters to an auditor.
By Michal Jatczak
The July 2026 Exchange SUs withdraw Microsoft's advice to keep the CVE-2026-42897 mitigation applied, but installing the update does not remove it. This note gives the per-SKU July build numbers, the PowerShell that reads the real SU level rather than the CU level, and the documented M2 rollback in an order that keeps the exposure window at zero, given that the code fix itself shipped in the June 2026 SU.
By Michal Jatczak
An operator runbook for automated joiner provisioning in Microsoft Entra ID: the role-profile file, a normalised joiner event, a poll-for-readiness Graph sequence, the Temporary Access Pass trap that locks out day-one starters, and the formula to compute your own time saving.
By Michal Jatczak
A runbook for deciding whether to self-host an open-weights model in the EU: the runtime field after TGI entered maintenance mode, GPU sizing computed from the model config instead of copied from a table, a corrected token-throughput cost model, and the DORA, NIS2 and AI Act record you will be asked for.
By Michal Jatczak
A bench specification for retrieval over a corpus that carries permissions: the four access-control failure modes, why post-filtering starves an approximate index, where the cache breakpoint belongs, and the six numbers to record on every run.
By Michal Jatczak
A first-hours runbook for a 4 to 15 person technical team on Microsoft 365: the three EU reporting clocks and the event that actually starts each one, a containment sequence that captures evidence before it cuts access, and the documented side effects and rollback for every high-blast-radius action.
By Michal Jatczak
A 47-point leaver checklist derived from ISO/IEC 27001:2022 Annex A control text and current vendor documentation, with three escalation tiers, a runnable Microsoft Graph identity block, and the token-lifetime arithmetic that decides when revocation has actually landed.
By Michal Jatczak
DORA has been enforceable since 17 January 2025, and under Article 5 of Commission Delegated Regulation (EU) 2025/301 each of the three reports on a major incident runs from a different event. This memo rebuilds the deadlines against that article, ships a PowerShell function that computes them, separates the Article 35 penalty on critical third-party providers from the Article 50 regime that applies to financial entities, and lists the evidence the regulation requires you to hold.
By Michal Jatczak
Architecture Workshop
Two hours in your tenant. You leave with a Microsoft 365 security baseline, a deployable architecture plan, and an Exit Kit you own.