Skip to content

Ops Log by Michal Jatczak

Operational answers you can verify in your own tenant.

Microsoft 365, Azure, security, and production AI notes built from primary sources, controlled tests, and clear operator decisions.

Michal Jatczak

Written and reviewed by Michal Jatczak

ITSailor founder, operating from Malta

Editorial series

Choose the evidence you need.

The format tells you what evidence to expect before you open a note.

Change Notes

What changed, who it affects, and the tenant check to run now.

Delivers

Act, schedule, monitor, or ignore

Operator Runbooks

Admin paths, commands, expected output, side effects, and rollback.

Delivers

A task you can execute and reverse

Lab Notes

Test conditions, screenshots, results, failures, and limits.

Delivers

Evidence with enough context to challenge it

Decision Memos

A direct recommendation, the trade-offs, and where it stops applying.

Delivers

A decision and its reversal trigger

Archive

Field notes

Search the archive or browse by operational topic.

More field notes

Decision MemoSecurity & Infrastructure

The Graph site permissions endpoint lists application grants: Sites.FullControl.All buys an empty array

GET /sites/{siteId}/permissions lists the grants held by applications on a site, not the people who can open it, and returns an empty array on any tenant that never used Sites.Selected. Microsoft documents Sites.FullControl.All as its least privileged permission. Two cheaper reads answer the real question.

By Michal Jatczak

Decision MemoSecurity & Infrastructure

The MFSA closes the DORA register window on 21 March, and only a submission that reaches Accepted counts

The MFSA sets the DORA Register of Information window at 1 January to 21 March each year, with 31 December of the preceding year as the reference date, and counts only a submission that reaches Accepted on the LH Portal. Here are the dates, the provider level fields, and the December work behind them.

By Michal Jatczak

Change NoteSecurity & Infrastructure

Teams call records left chat retention policies in late April 2026: the replacement policy is PowerShell only

Since late April 2026 a new Teams call data record is covered only by a retention policy for the Teams call logs location, which exists only in PowerShell and reaches nothing created before it went active. The old chat policy stays green. This note gives the read-only check and the boundary of the gap.

By Michal Jatczak

Decision MemoSecurity & Infrastructure

Editing a Conditional Access custom control means deleting it, and creation stops in September 2026

Microsoft blocks the creation and editing of Conditional Access custom controls from September 2026, and the only editing procedure it documents is to delete the control and create a replacement. This note gives the read-only check that finds the affected policies, and the decision to take before the block lands.

By Michal Jatczak

Lab NoteAI & Automation

A Graph meeting export can return an empty page that still carries a next link

During a planned Microsoft Graph service update, paginated calls to getAllRecordings or getAllTranscripts can return HTTP 200 with an empty collection alongside a next link, then restart and re-serve items. An export loop that exits on no items stops there and reports success over a short archive.

By Michal Jatczak

Decision MemoSecurity & Infrastructure

Leaving a general-purpose v1 storage account alone is treated as consent, and the unattended upgrade lands in Hot

Azure retires general-purpose v1 storage accounts on 13 October 2026 and migrates whatever is left. Microsoft records that inaction as consent. The upgrade is permanent, transaction pricing differs, and an upgrade that names no access tier lands in Hot. Inventory the accounts and decide the tier per account.

By Michal Jatczak

Change NoteModern Workspace

Windows 11 24H2 stops receiving updates a year earlier on Pro than on Enterprise, from the identical build

Windows 11 version 24H2 ends updates on 2026-10-13 for the Pro family and on 2027-10-12 for the Enterprise family, from one table row and one identical build. Count the fleet by edition, not by build, before the earlier date arrives.

By Michal Jatczak

Operator RunbookSecurity & Infrastructure

Microsoft 365 E3 gained Defender Plan 1 in July and impersonation protection is still off by default

Microsoft 365 E3 has included Defender for Office 365 Plan 1 since 1 July 2026, but user and domain impersonation protection stays applied to nobody until an administrator configures it. This runbook gives the read-only check that settles whether anything in the tenant is actually enforcing it.

By Michal Jatczak

Change NoteModern Workspace

Auto-renew off without an explicit cancel bills as an Extended Service Term

In the Microsoft CSP program, setting an EST-eligible subscription to auto-renew false with no explicit cancel instruction converts it to a paid Extended Service Term that renews monthly. The API confirms the cancelled state first and a background job reverses it, so the read-back has to happen the next day.

By Michal Jatczak

Ops Log briefing

Evidence you can inspect.

Michal's field notes on Microsoft 365, Azure and AI operations for regulated European teams.

  • Primary-source analysis
  • Tenant checks and tested configuration paths
  • Named author, test context, and visible limits

We send a confirmation link first. No briefing is scheduled before you confirm.

Architecture Workshop

Apply the same method to your own environment.

Two hours in your tenant. You leave with a Microsoft 365 security baseline, a deployable architecture plan, and an Exit Kit you own.

Review the €499 workshop