blog

Notes from the cloud

Practical write-ups on Azure, Microsoft 365, Entra ID, security and infrastructure as code — the things I run into in real enterprise environments.

azureaiai-foundry

Hosted agents in Foundry Agent Service: bring your own container, let Azure run it

Foundry Agent Service now lets you deploy your own containerized agent code — any framework, any protocol — onto managed, per-session isolated compute. Here is the architecture, the identity model, and the sizing decisions that actually drive your bill.

Read →
azurebicepiac

Azure Blueprints retirement: a migration runbook before the clock runs out

The phased retirement of Azure Blueprints starts July 31, 2026 and ends in full retirement on January 31, 2027. Here is a concrete runbook to inventory usage, export definitions, and rebuild them as deployment stacks and template specs.

Read →
microsoft-365copilotgovernance

Governing agent sprawl: what the Microsoft 365 admin center actually shows you

Copilot Studio and Agent Builder make it trivial for anyone to publish an agent. Here is what the Agent Registry, Activity tab, Security tab and the new unified app/agent management actually give admins to keep that sprawl under control.

Read →
entra-ididentitysecurity

Microsoft Entra Backup and Recovery is GA: what it actually protects (and what it still doesn't)

Microsoft Entra Backup and Recovery is now generally available for P1/P2 tenants. Here is what gets backed up, what is explicitly out of scope, and where it still leaves a gap in your recoverability story.

Read →
azurenetworkingprivate-link

Getting Private Endpoint DNS right at scale in Azure

Private endpoints solve network exposure; DNS is what actually breaks in enterprise rollouts. A practical design for centralized private DNS zones, zone groups and policy-driven automation across hub-and-spoke.

Read →
entra-ididentitysecurity

PIM for Groups: eliminating standing admin access without a role sprawl headache

How Privileged Identity Management for Groups collapses many just-in-time role activations into one, and the nesting, licensing and approval rules that make or break a deployment.

Read →
powershellentra-idautomation

Automating joiner-mover-leaver with the Microsoft Graph PowerShell SDK

A practical pattern for scripting onboarding, transfers and offboarding against Microsoft Graph with unattended, certificate-based authentication.

Read →
microsoft-365purviewgovernance

Auto-apply retention labels in Microsoft Purview: the tenant-wide governance play

How to stop relying on end users to classify content and use Microsoft Purview auto-apply retention label policies to govern SharePoint, OneDrive and Exchange at tenant scale.

Read →
azurebicepiac

Azure Deployment Stacks: Bicep's missing lifecycle layer

Plain Bicep deployments leave behind resources you remove from a template. Deployment Stacks fix that gap with automatic cleanup and drift protection — here is how they work in practice.

Read →
aiai-governancecloud

When a model vanishes overnight: the Fable 5 suspension and what it means for your architecture

A US government directive pulled Anthropic's Fable 5 and Mythos 5 offline with no notice. The geopolitics aren't my lane — but the lesson for anyone building on third-party AI models very much is.

Read →
microsoft-365copilotgovernance

Governing the Microsoft 365 Copilot auto-install: what to check before July

Microsoft is rolling out automatic Copilot app installation to commercial Windows devices through July 2026. Three admin control layers to apply now, and what the rollout actually means for your data governance.

Read →
microsoftcertificationsai

AI Skills Fest 2026: grab a free Microsoft exam voucher (deadline is now)

Microsoft AI Skills Fest 2026 hands out a 100% certification exam voucher for completing one learning playlist — but the claim window closes June 12, 00:00 UTC. Here is exactly what to do, step by step.

Read →
azureterraformiac

Moving Azure Landing Zones to AVM before the CAF Enterprise Scale deadline

The terraform-azurerm-caf-enterprise-scale module is being archived in August 2026. Here is what the new Azure Verified Modules approach looks like and how to plan your migration.

Read →
azurefinopsai

Watching your Azure bill with AI: SRE Agent + FinOps hubs

Beyond routing cost alerts to an AI agent — wiring Azure SRE Agent into FinOps hubs data via MCP and KQL, building a FinOps subagent, and automating cost remediation with guardrails.

Read →
azurefinopscost-optimization

The Microsoft FinOps toolkit, from A to Z

A practical map of every tool in the Microsoft FinOps toolkit — workbooks, Power BI reports, FinOps hubs, the Azure Optimization Engine, PowerShell and more — and the order I would adopt them in.

Read →
entra-idsecurityidentity

A pragmatic Conditional Access baseline for Entra ID

A starting set of Conditional Access policies that block the most common attacks without burying your help desk in tickets.

Read →
azurenetworkingwaf

Application Gateway v1 is retired: a migration runbook for the stragglers

Application Gateway v1 retired on 28 April 2026 and Microsoft is now decommissioning the hardware and deleting unmigrated gateways. Here is a concrete runbook to find any v1 you still have, clone it to v2, cut traffic over, and fix the WAF on the way out.

Read →
metacloud

Welcome — why I started this blog

A short intro to what I do and the kind of cloud, identity and security topics you can expect to find here.

Read →