Skip to content

Ops Log by Michal Jatczak

Operational answers you can verify in your own tenant.

Microsoft 365, Azure, security, and production AI notes built from primary sources, controlled tests, and clear operator decisions.

Michal Jatczak

Written and reviewed by Michal Jatczak

ITSailor founder, operating from Malta

Editorial series

Choose the evidence you need.

The format tells you what evidence to expect before you open a note.

Change Notes

What changed, who it affects, and the tenant check to run now.

Delivers

Act, schedule, monitor, or ignore

Operator Runbooks

Admin paths, commands, expected output, side effects, and rollback.

Delivers

A task you can execute and reverse

Lab Notes

Test conditions, screenshots, results, failures, and limits.

Delivers

Evidence with enough context to challenge it

Decision Memos

A direct recommendation, the trade-offs, and where it stops applying.

Delivers

A decision and its reversal trigger

Archive

Field notes

Search the archive or browse by operational topic.

More field notes

Operator RunbookSecurity & Infrastructure

An incident-response playbook for a team without a security operations centre

A first-hours runbook for a 4 to 15 person technical team on Microsoft 365: the three EU reporting clocks and the event that actually starts each one, a containment sequence that captures evidence before it cuts access, and the documented side effects and rollback for every high-blast-radius action.

By Michal Jatczak

Operator RunbookSecurity & Infrastructure

A 47-point offboarding checklist and the three tiers that decide how fast to run it

A 47-point leaver checklist derived from ISO/IEC 27001:2022 Annex A control text and current vendor documentation, with three escalation tiers, a runnable Microsoft Graph identity block, and the token-lifetime arithmetic that decides when revocation has actually landed.

By Michal Jatczak

Decision MemoSecurity & Infrastructure

DORA in practice: the three report clocks, the major-incident gate, and the evidence pack

DORA has been enforceable since 17 January 2025, and under Article 5 of Commission Delegated Regulation (EU) 2025/301 each of the three reports on a major incident runs from a different event. This memo rebuilds the deadlines against that article, ships a PowerShell function that computes them, separates the Article 35 penalty on critical third-party providers from the Article 50 regime that applies to financial entities, and lists the evidence the regulation requires you to hold.

By Michal Jatczak

Operator RunbookSecurity & Infrastructure

Eight Azure cost levers, and how to size each one on your own bill

Eight Azure cost levers with the formula for each, so the figure comes from your own consumption data rather than someone else's case study: an inventory script, the Advisor thresholds that actually apply, the retention and rehydration penalties on blob tiering, what a Basic log plan costs in detection capability, and a rollback order ranked by reversibility.

By Michal Jatczak

Operator RunbookSecurity & Infrastructure

Fifteen Microsoft 365 tenant settings that need an explicit decision

Fifteen tenant-wide Microsoft 365 controls, each with the licence tier it actually needs, a read-only Graph, Exchange and SharePoint audit script, the side effects to plan for, and the rollback path. Six pieces of pre-2024 guidance in this area are corrected, five of them attached to numbered rows.

By Michal Jatczak

Operator RunbookSecurity & Infrastructure

NIS2 for managed service providers: who is actually in scope, and what Article 21 requires

A clause-by-clause scoping runbook for managed service providers under Directive (EU) 2022/2555: the size test that lives in the SME Recommendation, the closed Article 2(2) list that does not name MSPs, the Article 21(2) control set as expanded by Implementing Regulation (EU) 2024/2690, and the Article 23 reporting clock with the MSP-specific significance thresholds.

By Michal Jatczak

Decision MemoSecurity & Infrastructure

Backup after 3-2-1: immutability modes, drill cadence, and the evidence an auditor accepts

3-2-1 describes the shape of a backup estate but says nothing about its blast radius. This memo settles four decisions: compliance-mode retention over governance mode, two retention tiers sized separately, a second party on destructive operations, and a drill that leaves a dated artefact behind.

By Michal Jatczak

Operator RunbookSecurity & Infrastructure

Running Prometheus, Loki and Alertmanager on one VM: configuration, retention and cost

A single-VM Prometheus, Loki, Alertmanager and Grafana deployment that starts on the first attempt: the retention flags that belong on the command line, the disk-sizing formula that decides the machine class, alert rules with the false-page guards in place, and a cost model built from published list prices instead of asserted savings.

By Michal Jatczak

Decision MemoAI & Automation

Choosing a workflow engine: what a self-hosted n8n actually costs to run

A decision memo comparing Power Automate licence-and-request-ceiling pricing against the real running cost of a self-hosted n8n, with vendor list prices checked on 2026-07-28, the figures from one operated instance, and a break-even script you fill in with your own flow counts and operator hours.

By Michal Jatczak

Ops Log briefing

Evidence you can inspect.

Michal's field notes on Microsoft 365, Azure and AI operations for regulated European teams.

  • Primary-source analysis
  • Tenant checks and tested configuration paths
  • Named author, test context, and visible limits

We send a confirmation link first. No briefing is scheduled before you confirm.

Architecture Workshop

Apply the same method to your own environment.

Two hours in your tenant. You leave with a Microsoft 365 security baseline, a deployable architecture plan, and an Exit Kit you own.

Review the €499 workshop