Change Notes
What changed, who it affects, and the tenant check to run now.
Delivers
Act, schedule, monitor, or ignore
Ops Log by Michal Jatczak
Microsoft 365, Azure, security, and production AI notes built from primary sources, controlled tests, and clear operator decisions.
Written and reviewed by Michal Jatczak
ITSailor founder, operating from Malta
Editorial series
The format tells you what evidence to expect before you open a note.
What changed, who it affects, and the tenant check to run now.
Delivers
Act, schedule, monitor, or ignore
Admin paths, commands, expected output, side effects, and rollback.
Delivers
A task you can execute and reverse
Test conditions, screenshots, results, failures, and limits.
Delivers
Evidence with enough context to challenge it
A direct recommendation, the trade-offs, and where it stops applying.
Delivers
A decision and its reversal trigger
Archive
Search the archive or browse by operational topic.
Eight Azure cost levers with the formula for each, so the figure comes from your own consumption data rather than someone else's case study: an inventory script, the Advisor thresholds that actually apply, the retention and rehydration penalties on blob tiering, what a Basic log plan costs in detection capability, and a rollback order ranked by reversibility.
By Michal Jatczak
Fifteen tenant-wide Microsoft 365 controls, each with the licence tier it actually needs, a read-only Graph, Exchange and SharePoint audit script, the side effects to plan for, and the rollback path. Six pieces of pre-2024 guidance in this area are corrected, five of them attached to numbered rows.
By Michal Jatczak
A clause-by-clause scoping runbook for managed service providers under Directive (EU) 2022/2555: the size test that lives in the SME Recommendation, the closed Article 2(2) list that does not name MSPs, the Article 21(2) control set as expanded by Implementing Regulation (EU) 2024/2690, and the Article 23 reporting clock with the MSP-specific significance thresholds.
By Michal Jatczak
3-2-1 describes the shape of a backup estate but says nothing about its blast radius. This memo settles four decisions: compliance-mode retention over governance mode, two retention tiers sized separately, a second party on destructive operations, and a drill that leaves a dated artefact behind.
By Michal Jatczak
A single-VM Prometheus, Loki, Alertmanager and Grafana deployment that starts on the first attempt: the retention flags that belong on the command line, the disk-sizing formula that decides the machine class, alert rules with the false-page guards in place, and a cost model built from published list prices instead of asserted savings.
By Michal Jatczak
A decision memo comparing Power Automate licence-and-request-ceiling pricing against the real running cost of a self-hosted n8n, with vendor list prices checked on 2026-07-28, the figures from one operated instance, and a break-even script you fill in with your own flow counts and operator hours.
By Michal Jatczak
Ten Conditional Access policies, the Microsoft Learn control behind each one, the report-only order that surfaces breakage before a user hits it, and an emergency-access design that survives the mandatory MFA enforcement on the Microsoft admin portals.
By Michal Jatczak
A cutover runbook for turning a flat office LAN into purpose-based zones: the VLAN scheme, the 802.1X and RADIUS layer that actually places a device into a zone, firewall policy held in version control, host-level nftables, and an independent rollback path for every stage.
By Michal Jatczak
Architecture Workshop
Two hours in your tenant. You leave with a Microsoft 365 security baseline, a deployable architecture plan, and an Exit Kit you own.