Change Notes
What changed, who it affects, and the tenant check to run now.
Delivers
Act, schedule, monitor, or ignore
Ops Log by Michal Jatczak
Microsoft 365, Azure, security, and production AI notes built from primary sources, controlled tests, and clear operator decisions.
Written and reviewed by Michal Jatczak
ITSailor founder, operating from Malta
Editorial series
The format tells you what evidence to expect before you open a note.
What changed, who it affects, and the tenant check to run now.
Delivers
Act, schedule, monitor, or ignore
Admin paths, commands, expected output, side effects, and rollback.
Delivers
A task you can execute and reverse
Test conditions, screenshots, results, failures, and limits.
Delivers
Evidence with enough context to challenge it
A direct recommendation, the trade-offs, and where it stops applying.
Delivers
A decision and its reversal trigger
Archive
Search the archive or browse by operational topic.
GET /sites/{siteId}/permissions lists the grants held by applications on a site, not the people who can open it, and returns an empty array on any tenant that never used Sites.Selected. Microsoft documents Sites.FullControl.All as its least privileged permission. Two cheaper reads answer the real question.
By Michal Jatczak
The MFSA sets the DORA Register of Information window at 1 January to 21 March each year, with 31 December of the preceding year as the reference date, and counts only a submission that reaches Accepted on the LH Portal. Here are the dates, the provider level fields, and the December work behind them.
By Michal Jatczak
Since late April 2026 a new Teams call data record is covered only by a retention policy for the Teams call logs location, which exists only in PowerShell and reaches nothing created before it went active. The old chat policy stays green. This note gives the read-only check and the boundary of the gap.
By Michal Jatczak
Microsoft blocks the creation and editing of Conditional Access custom controls from September 2026, and the only editing procedure it documents is to delete the control and create a replacement. This note gives the read-only check that finds the affected policies, and the decision to take before the block lands.
By Michal Jatczak
During a planned Microsoft Graph service update, paginated calls to getAllRecordings or getAllTranscripts can return HTTP 200 with an empty collection alongside a next link, then restart and re-serve items. An export loop that exits on no items stops there and reports success over a short archive.
By Michal Jatczak
Azure retires general-purpose v1 storage accounts on 13 October 2026 and migrates whatever is left. Microsoft records that inaction as consent. The upgrade is permanent, transaction pricing differs, and an upgrade that names no access tier lands in Hot. Inventory the accounts and decide the tier per account.
By Michal Jatczak
Windows 11 version 24H2 ends updates on 2026-10-13 for the Pro family and on 2027-10-12 for the Enterprise family, from one table row and one identical build. Count the fleet by edition, not by build, before the earlier date arrives.
By Michal Jatczak
Microsoft 365 E3 has included Defender for Office 365 Plan 1 since 1 July 2026, but user and domain impersonation protection stays applied to nobody until an administrator configures it. This runbook gives the read-only check that settles whether anything in the tenant is actually enforcing it.
By Michal Jatczak
In the Microsoft CSP program, setting an EST-eligible subscription to auto-renew false with no explicit cancel instruction converts it to a paid Extended Service Term that renews monthly. The API confirms the cancelled state first and a background job reverses it, so the read-back has to happen the next day.
By Michal Jatczak
Architecture Workshop
Two hours in your tenant. You leave with a Microsoft 365 security baseline, a deployable architecture plan, and an Exit Kit you own.