Skip to content

Ops Log by Michal Jatczak

Operational answers you can verify in your own tenant.

Microsoft 365, Azure, security, and production AI notes built from primary sources, controlled tests, and clear operator decisions.

Michal Jatczak

Written and reviewed by Michal Jatczak

ITSailor founder, operating from Malta

Editorial series

Choose the evidence you need.

The format tells you what evidence to expect before you open a note.

Change Notes

What changed, who it affects, and the tenant check to run now.

Delivers

Act, schedule, monitor, or ignore

Operator Runbooks

Admin paths, commands, expected output, side effects, and rollback.

Delivers

A task you can execute and reverse

Lab Notes

Test conditions, screenshots, results, failures, and limits.

Delivers

Evidence with enough context to challenge it

Decision Memos

A direct recommendation, the trade-offs, and where it stops applying.

Delivers

A decision and its reversal trigger

Archive

Field notes

Search the archive or browse by operational topic.

More field notes

Operator RunbookSecurity & Infrastructure

Mailbox forwarding rules survive the leaver: the offboarding check most runbooks skip

An enabled inbox forwarding or redirect rule keeps sending a departed employee mail long after the account is disabled. Here is how to find every one from Microsoft Graph and shut it before it becomes an exfiltration path.

By Michal Jatczak

Lab NoteSecurity & Infrastructure

What a Microsoft 365 offboarding scan finds after the account is disabled

Disabling an Entra account is the start of offboarding, not the end. Here are the eight access residues a read-only Microsoft Graph scan reads back, and why each one matters to an auditor.

By Michal Jatczak

Change NoteSecurity & Infrastructure

July 2026 Exchange Server security updates: confirm the build before removing the interim mitigation

The July 2026 Exchange SUs withdraw Microsoft's advice to keep the CVE-2026-42897 mitigation applied, but installing the update does not remove it. This note gives the per-SKU July build numbers, the PowerShell that reads the real SU level rather than the CU level, and the documented M2 rollback in an order that keeps the exposure window at zero, given that the code fix itself shipped in the June 2026 SU.

By Michal Jatczak

Operator RunbookAI & Automation

Onboarding automation: the role profile, the joiner event, and the five parts that break

An operator runbook for automated joiner provisioning in Microsoft Entra ID: the role-profile file, a normalised joiner event, a poll-for-readiness Graph sequence, the Temporary Access Pass trap that locks out day-one starters, and the formula to compute your own time saving.

By Michal Jatczak

Operator RunbookAI & Automation

Self-hosted LLM serving in the EU: runtime choice, GPU sizing, and the sovereignty argument

A runbook for deciding whether to self-host an open-weights model in the EU: the runtime field after TGI entered maintenance mode, GPU sizing computed from the model config instead of copied from a table, a corrected token-throughput cost model, and the DORA, NIS2 and AI Act record you will be asked for.

By Michal Jatczak

Lab NoteAI & Automation

Retrieval over a permissioned corpus: ACL handling, the update pipeline, and what to measure

A bench specification for retrieval over a corpus that carries permissions: the four access-control failure modes, why post-filtering starves an approximate index, where the cache breakpoint belongs, and the six numbers to record on every run.

By Michal Jatczak

Operator RunbookSecurity & Infrastructure

An incident-response playbook for a team without a security operations centre

A first-hours runbook for a 4 to 15 person technical team on Microsoft 365: the three EU reporting clocks and the event that actually starts each one, a containment sequence that captures evidence before it cuts access, and the documented side effects and rollback for every high-blast-radius action.

By Michal Jatczak

Operator RunbookSecurity & Infrastructure

A 47-point offboarding checklist and the three tiers that decide how fast to run it

A 47-point leaver checklist derived from ISO/IEC 27001:2022 Annex A control text and current vendor documentation, with three escalation tiers, a runnable Microsoft Graph identity block, and the token-lifetime arithmetic that decides when revocation has actually landed.

By Michal Jatczak

Decision MemoSecurity & Infrastructure

DORA in practice: the three report clocks, the major-incident gate, and the evidence pack

DORA has been enforceable since 17 January 2025, and under Article 5 of Commission Delegated Regulation (EU) 2025/301 each of the three reports on a major incident runs from a different event. This memo rebuilds the deadlines against that article, ships a PowerShell function that computes them, separates the Article 35 penalty on critical third-party providers from the Article 50 regime that applies to financial entities, and lists the evidence the regulation requires you to hold.

By Michal Jatczak

Ops Log briefing

Evidence you can inspect.

Michal's field notes on Microsoft 365, Azure and AI operations for regulated European teams.

  • Primary-source analysis
  • Tenant checks and tested configuration paths
  • Named author, test context, and visible limits

We send a confirmation link first. No briefing is scheduled before you confirm.

Architecture Workshop

Apply the same method to your own environment.

Two hours in your tenant. You leave with a Microsoft 365 security baseline, a deployable architecture plan, and an Exit Kit you own.

Review the €499 workshop