blog
Notes from the cloud
Practical write-ups on Azure, Microsoft 365, Entra ID, security and infrastructure as code — the things I run into in real enterprise environments.
Hosted agents in Foundry Agent Service: bring your own container, let Azure run it
Foundry Agent Service now lets you deploy your own containerized agent code — any framework, any protocol — onto managed, per-session isolated compute. Here is the architecture, the identity model, and the sizing decisions that actually drive your bill.
Azure Blueprints retirement: a migration runbook before the clock runs out
The phased retirement of Azure Blueprints starts July 31, 2026 and ends in full retirement on January 31, 2027. Here is a concrete runbook to inventory usage, export definitions, and rebuild them as deployment stacks and template specs.
Governing agent sprawl: what the Microsoft 365 admin center actually shows you
Copilot Studio and Agent Builder make it trivial for anyone to publish an agent. Here is what the Agent Registry, Activity tab, Security tab and the new unified app/agent management actually give admins to keep that sprawl under control.
Microsoft Entra Backup and Recovery is GA: what it actually protects (and what it still doesn't)
Microsoft Entra Backup and Recovery is now generally available for P1/P2 tenants. Here is what gets backed up, what is explicitly out of scope, and where it still leaves a gap in your recoverability story.
Getting Private Endpoint DNS right at scale in Azure
Private endpoints solve network exposure; DNS is what actually breaks in enterprise rollouts. A practical design for centralized private DNS zones, zone groups and policy-driven automation across hub-and-spoke.
PIM for Groups: eliminating standing admin access without a role sprawl headache
How Privileged Identity Management for Groups collapses many just-in-time role activations into one, and the nesting, licensing and approval rules that make or break a deployment.
Automating joiner-mover-leaver with the Microsoft Graph PowerShell SDK
A practical pattern for scripting onboarding, transfers and offboarding against Microsoft Graph with unattended, certificate-based authentication.
Auto-apply retention labels in Microsoft Purview: the tenant-wide governance play
How to stop relying on end users to classify content and use Microsoft Purview auto-apply retention label policies to govern SharePoint, OneDrive and Exchange at tenant scale.
Azure Deployment Stacks: Bicep's missing lifecycle layer
Plain Bicep deployments leave behind resources you remove from a template. Deployment Stacks fix that gap with automatic cleanup and drift protection — here is how they work in practice.
When a model vanishes overnight: the Fable 5 suspension and what it means for your architecture
A US government directive pulled Anthropic's Fable 5 and Mythos 5 offline with no notice. The geopolitics aren't my lane — but the lesson for anyone building on third-party AI models very much is.
Governing the Microsoft 365 Copilot auto-install: what to check before July
Microsoft is rolling out automatic Copilot app installation to commercial Windows devices through July 2026. Three admin control layers to apply now, and what the rollout actually means for your data governance.
AI Skills Fest 2026: grab a free Microsoft exam voucher (deadline is now)
Microsoft AI Skills Fest 2026 hands out a 100% certification exam voucher for completing one learning playlist — but the claim window closes June 12, 00:00 UTC. Here is exactly what to do, step by step.
Moving Azure Landing Zones to AVM before the CAF Enterprise Scale deadline
The terraform-azurerm-caf-enterprise-scale module is being archived in August 2026. Here is what the new Azure Verified Modules approach looks like and how to plan your migration.
Watching your Azure bill with AI: SRE Agent + FinOps hubs
Beyond routing cost alerts to an AI agent — wiring Azure SRE Agent into FinOps hubs data via MCP and KQL, building a FinOps subagent, and automating cost remediation with guardrails.
The Microsoft FinOps toolkit, from A to Z
A practical map of every tool in the Microsoft FinOps toolkit — workbooks, Power BI reports, FinOps hubs, the Azure Optimization Engine, PowerShell and more — and the order I would adopt them in.
A pragmatic Conditional Access baseline for Entra ID
A starting set of Conditional Access policies that block the most common attacks without burying your help desk in tickets.
Application Gateway v1 is retired: a migration runbook for the stragglers
Application Gateway v1 retired on 28 April 2026 and Microsoft is now decommissioning the hardware and deleting unmigrated gateways. Here is a concrete runbook to find any v1 you still have, clone it to v2, cut traffic over, and fix the WAF on the way out.
Welcome — why I started this blog
A short intro to what I do and the kind of cloud, identity and security topics you can expect to find here.