blog
Notes from the cloud
Practical write-ups on Azure, Microsoft 365, Entra ID, security and infrastructure as code — the things I run into in real enterprise environments.
Private subnets by default: finding the Azure VMs still living on default outbound access
New Azure VNets now default to private subnets, but existing ones do not — here is how to find VMs relying on default outbound access and move them to explicit egress without an outage.
Showback that survives contact with finance: tag inheritance and cost allocation rules in Azure
Resource tags alone will never give you a clean cost-per-team report in Azure. Here is how I combine Azure Policy, Cost Management tag inheritance and cost allocation rules into a showback model that actually adds up.
Entra ID just defaulted to passkeys: a runbook before SMS and voice MFA disappear
Since September 1, 2026, Entra ID auto-enrolls your SMS and voice MFA users into passkey registration nudges — and Microsoft-provided SMS/voice retires for good on February 1, 2027, with no opt-out. Here is how to find who is exposed, control the rollout, and configure passkey profiles before the deadline.
The Bicep MCP server: stopping Copilot from guessing at your Azure resources
Ask an AI assistant to write Bicep and it will happily invent a property name or an API version that never existed. The Bicep MCP server fixes that by handing the model real schemas, real best practices, and a diagnostics tool — here is what it does and where it still needs a human.
AKS cost analysis: what those namespace numbers actually mean before you bill a team for them
AKS Cost Analysis will happily show you a per-namespace cost breakdown — but Idle, System and Unallocated charges can make that number mean something very different from what a platform team expects. Here is how to read it correctly.
Microsoft Purview RBAC, tightened: view-only role visibility, expiring access, and a scoping trap to know about
Microsoft Purview just gave Global Reader and Security Reader read-only visibility into role assignments — a small change that sits next to two much bigger levers for least-privilege access: automatic expiring role group assignments, and a precedence rule that can silently undo your Administrative Unit scoping.
Azure Firewall explicit proxy (preview): finally an alternative to the UDR dance
Azure Firewall has always intercepted traffic transparently via user-defined routes. A new preview setting lets clients point at the firewall as a real HTTP/HTTPS proxy instead — here is how it works, what it takes to set up, and where the preview still bites.
Catching expiring Entra app credentials before they cause an outage
The built-in Entra recommendation for expiring app credentials only looks 30 days out and lives in a portal tab nobody checks daily. Here is a Microsoft Graph PowerShell runbook that closes that gap.
Hosted agents in Foundry Agent Service: bring your own container, let Azure run it
Foundry Agent Service now lets you deploy your own containerized agent code — any framework, any protocol — onto managed, per-session isolated compute. Here is the architecture, the identity model, and the sizing decisions that actually drive your bill.
Azure Blueprints retirement: a migration runbook before the clock runs out
The phased retirement of Azure Blueprints starts July 31, 2026 and ends in full retirement on January 31, 2027. Here is a concrete runbook to inventory usage, export definitions, and rebuild them as deployment stacks and template specs.
Governing agent sprawl: what the Microsoft 365 admin center actually shows you
Copilot Studio and Agent Builder make it trivial for anyone to publish an agent. Here is what the Agent Registry, Activity tab, Security tab and the new unified app/agent management actually give admins to keep that sprawl under control.
Microsoft Entra Backup and Recovery is GA: what it actually protects (and what it still doesn't)
Microsoft Entra Backup and Recovery is now generally available for P1/P2 tenants. Here is what gets backed up, what is explicitly out of scope, and where it still leaves a gap in your recoverability story.
Getting Private Endpoint DNS right at scale in Azure
Private endpoints solve network exposure; DNS is what actually breaks in enterprise rollouts. A practical design for centralized private DNS zones, zone groups and policy-driven automation across hub-and-spoke.
PIM for Groups: eliminating standing admin access without a role sprawl headache
How Privileged Identity Management for Groups collapses many just-in-time role activations into one, and the nesting, licensing and approval rules that make or break a deployment.
Automating joiner-mover-leaver with the Microsoft Graph PowerShell SDK
A practical pattern for scripting onboarding, transfers and offboarding against Microsoft Graph with unattended, certificate-based authentication.
Auto-apply retention labels in Microsoft Purview: the tenant-wide governance play
How to stop relying on end users to classify content and use Microsoft Purview auto-apply retention label policies to govern SharePoint, OneDrive and Exchange at tenant scale.
Azure Deployment Stacks: Bicep's missing lifecycle layer
Plain Bicep deployments leave behind resources you remove from a template. Deployment Stacks fix that gap with automatic cleanup and drift protection — here is how they work in practice.
When a model vanishes overnight: the Fable 5 suspension and what it means for your architecture
A US government directive pulled Anthropic's Fable 5 and Mythos 5 offline with no notice. The geopolitics aren't my lane — but the lesson for anyone building on third-party AI models very much is.
Governing the Microsoft 365 Copilot auto-install: what to check before July
Microsoft is rolling out automatic Copilot app installation to commercial Windows devices through July 2026. Three admin control layers to apply now, and what the rollout actually means for your data governance.
AI Skills Fest 2026: grab a free Microsoft exam voucher (deadline is now)
Microsoft AI Skills Fest 2026 hands out a 100% certification exam voucher for completing one learning playlist — but the claim window closes June 12, 00:00 UTC. Here is exactly what to do, step by step.
Moving Azure Landing Zones to AVM before the CAF Enterprise Scale deadline
The terraform-azurerm-caf-enterprise-scale module is being archived in August 2026. Here is what the new Azure Verified Modules approach looks like and how to plan your migration.
Watching your Azure bill with AI: SRE Agent + FinOps hubs
Beyond routing cost alerts to an AI agent — wiring Azure SRE Agent into FinOps hubs data via MCP and KQL, building a FinOps subagent, and automating cost remediation with guardrails.
The Microsoft FinOps toolkit, from A to Z
A practical map of every tool in the Microsoft FinOps toolkit — workbooks, Power BI reports, FinOps hubs, the Azure Optimization Engine, PowerShell and more — and the order I would adopt them in.
A pragmatic Conditional Access baseline for Entra ID
A starting set of Conditional Access policies that block the most common attacks without burying your help desk in tickets.
Application Gateway v1 is retired: a migration runbook for the stragglers
Application Gateway v1 retired on 28 April 2026 and Microsoft is now decommissioning the hardware and deleting unmigrated gateways. Here is a concrete runbook to find any v1 you still have, clone it to v2, cut traffic over, and fix the WAF on the way out.
Welcome — why I started this blog
A short intro to what I do and the kind of cloud, identity and security topics you can expect to find here.