blog

Notes from the cloud

Practical write-ups on Azure, Microsoft 365, Entra ID, security and infrastructure as code — the things I run into in real enterprise environments.

azurenetworkingsecurity

Private subnets by default: finding the Azure VMs still living on default outbound access

New Azure VNets now default to private subnets, but existing ones do not — here is how to find VMs relying on default outbound access and move them to explicit egress without an outage.

Read →
azurefinopscost-management

Showback that survives contact with finance: tag inheritance and cost allocation rules in Azure

Resource tags alone will never give you a clean cost-per-team report in Azure. Here is how I combine Azure Policy, Cost Management tag inheritance and cost allocation rules into a showback model that actually adds up.

Read →
entra-ididentitysecurity

Entra ID just defaulted to passkeys: a runbook before SMS and voice MFA disappear

Since September 1, 2026, Entra ID auto-enrolls your SMS and voice MFA users into passkey registration nudges — and Microsoft-provided SMS/voice retires for good on February 1, 2027, with no opt-out. Here is how to find who is exposed, control the rollout, and configure passkey profiles before the deadline.

Read →
azurebicepiac

The Bicep MCP server: stopping Copilot from guessing at your Azure resources

Ask an AI assistant to write Bicep and it will happily invent a property name or an API version that never existed. The Bicep MCP server fixes that by handing the model real schemas, real best practices, and a diagnostics tool — here is what it does and where it still needs a human.

Read →
azurefinopsaks

AKS cost analysis: what those namespace numbers actually mean before you bill a team for them

AKS Cost Analysis will happily show you a per-namespace cost breakdown — but Idle, System and Unallocated charges can make that number mean something very different from what a platform team expects. Here is how to read it correctly.

Read →
microsoft-365purviewgovernance

Microsoft Purview RBAC, tightened: view-only role visibility, expiring access, and a scoping trap to know about

Microsoft Purview just gave Global Reader and Security Reader read-only visibility into role assignments — a small change that sits next to two much bigger levers for least-privilege access: automatic expiring role group assignments, and a precedence rule that can silently undo your Administrative Unit scoping.

Read →
azurenetworkingsecurity

Azure Firewall explicit proxy (preview): finally an alternative to the UDR dance

Azure Firewall has always intercepted traffic transparently via user-defined routes. A new preview setting lets clients point at the firewall as a real HTTP/HTTPS proxy instead — here is how it works, what it takes to set up, and where the preview still bites.

Read →
powershellentra-idautomation

Catching expiring Entra app credentials before they cause an outage

The built-in Entra recommendation for expiring app credentials only looks 30 days out and lives in a portal tab nobody checks daily. Here is a Microsoft Graph PowerShell runbook that closes that gap.

Read →
azureaiai-foundry

Hosted agents in Foundry Agent Service: bring your own container, let Azure run it

Foundry Agent Service now lets you deploy your own containerized agent code — any framework, any protocol — onto managed, per-session isolated compute. Here is the architecture, the identity model, and the sizing decisions that actually drive your bill.

Read →
azurebicepiac

Azure Blueprints retirement: a migration runbook before the clock runs out

The phased retirement of Azure Blueprints starts July 31, 2026 and ends in full retirement on January 31, 2027. Here is a concrete runbook to inventory usage, export definitions, and rebuild them as deployment stacks and template specs.

Read →
microsoft-365copilotgovernance

Governing agent sprawl: what the Microsoft 365 admin center actually shows you

Copilot Studio and Agent Builder make it trivial for anyone to publish an agent. Here is what the Agent Registry, Activity tab, Security tab and the new unified app/agent management actually give admins to keep that sprawl under control.

Read →
entra-ididentitysecurity

Microsoft Entra Backup and Recovery is GA: what it actually protects (and what it still doesn't)

Microsoft Entra Backup and Recovery is now generally available for P1/P2 tenants. Here is what gets backed up, what is explicitly out of scope, and where it still leaves a gap in your recoverability story.

Read →
azurenetworkingprivate-link

Getting Private Endpoint DNS right at scale in Azure

Private endpoints solve network exposure; DNS is what actually breaks in enterprise rollouts. A practical design for centralized private DNS zones, zone groups and policy-driven automation across hub-and-spoke.

Read →
entra-ididentitysecurity

PIM for Groups: eliminating standing admin access without a role sprawl headache

How Privileged Identity Management for Groups collapses many just-in-time role activations into one, and the nesting, licensing and approval rules that make or break a deployment.

Read →
powershellentra-idautomation

Automating joiner-mover-leaver with the Microsoft Graph PowerShell SDK

A practical pattern for scripting onboarding, transfers and offboarding against Microsoft Graph with unattended, certificate-based authentication.

Read →
microsoft-365purviewgovernance

Auto-apply retention labels in Microsoft Purview: the tenant-wide governance play

How to stop relying on end users to classify content and use Microsoft Purview auto-apply retention label policies to govern SharePoint, OneDrive and Exchange at tenant scale.

Read →
azurebicepiac

Azure Deployment Stacks: Bicep's missing lifecycle layer

Plain Bicep deployments leave behind resources you remove from a template. Deployment Stacks fix that gap with automatic cleanup and drift protection — here is how they work in practice.

Read →
aiai-governancecloud

When a model vanishes overnight: the Fable 5 suspension and what it means for your architecture

A US government directive pulled Anthropic's Fable 5 and Mythos 5 offline with no notice. The geopolitics aren't my lane — but the lesson for anyone building on third-party AI models very much is.

Read →
microsoft-365copilotgovernance

Governing the Microsoft 365 Copilot auto-install: what to check before July

Microsoft is rolling out automatic Copilot app installation to commercial Windows devices through July 2026. Three admin control layers to apply now, and what the rollout actually means for your data governance.

Read →
microsoftcertificationsai

AI Skills Fest 2026: grab a free Microsoft exam voucher (deadline is now)

Microsoft AI Skills Fest 2026 hands out a 100% certification exam voucher for completing one learning playlist — but the claim window closes June 12, 00:00 UTC. Here is exactly what to do, step by step.

Read →
azureterraformiac

Moving Azure Landing Zones to AVM before the CAF Enterprise Scale deadline

The terraform-azurerm-caf-enterprise-scale module is being archived in August 2026. Here is what the new Azure Verified Modules approach looks like and how to plan your migration.

Read →
azurefinopsai

Watching your Azure bill with AI: SRE Agent + FinOps hubs

Beyond routing cost alerts to an AI agent — wiring Azure SRE Agent into FinOps hubs data via MCP and KQL, building a FinOps subagent, and automating cost remediation with guardrails.

Read →
azurefinopscost-optimization

The Microsoft FinOps toolkit, from A to Z

A practical map of every tool in the Microsoft FinOps toolkit — workbooks, Power BI reports, FinOps hubs, the Azure Optimization Engine, PowerShell and more — and the order I would adopt them in.

Read →
entra-idsecurityidentity

A pragmatic Conditional Access baseline for Entra ID

A starting set of Conditional Access policies that block the most common attacks without burying your help desk in tickets.

Read →
azurenetworkingwaf

Application Gateway v1 is retired: a migration runbook for the stragglers

Application Gateway v1 retired on 28 April 2026 and Microsoft is now decommissioning the hardware and deleting unmigrated gateways. Here is a concrete runbook to find any v1 you still have, clone it to v2, cut traffic over, and fix the WAF on the way out.

Read →
metacloud

Welcome — why I started this blog

A short intro to what I do and the kind of cloud, identity and security topics you can expect to find here.

Read →