Notes
Working notes on Azure cost and security, Microsoft 365, automation and ISO 27001. Written from running all of it for one small company.
Topics
- Azure cost7 notes
Disk tiers, the things nobody deleted, and numbers that survive a finance meeting.
- Azure security7 notes
Detections you can prove work, NSG rules that were definitely temporary, and stale access.
- Microsoft 365, Entra and Intune6 notes
Conditional Access, break-glass accounts, Intune config as code, and guests nobody can name.
- Automation4 notes
PowerShell and Graph for the work that should not need a person, and scripts that fail loudly.
- ISO 27001 and compliance13 notes
Getting an SME certified single-handed: scope, risk, policies, audits and the year two surprise.
- AI and regulation3 notes
The EU AI Act at SME scale, an AI system inventory, and where LLM tools actually help.
- Running IT alone3 notes
Triage when everything is priority one, documentation people read, and when to call someone.
Latest
AI tools for security teams of one: what to hand over and what to keep
Where LLM tools genuinely help, where they produce confident nonsense about your own estate, and rules for what goes into a chat window.
ISO 27001 evidence automation: exported in February, asked for in March
Turning recurring evidence into scheduled exports with timestamps, and being honest about how much of an evidence pack a script can produce.
Azure Advisor recommendations need triage rather than obedience
What Advisor is genuinely good at, where its cost advice misleads on a small estate, and how to triage the list instead of obeying or ignoring it.
Read only Azure scripts: why these tools never write to Azure
Blast radius, the consultant trust problem, and why found nothing and could not look have to be different outcomes.
A business continuity tabletop exercise that does not need a conference room
Two hours, five people, one scenario, and the finding that comes out every single time.
When to hire an IT consultant, and what to make them leave behind
The three situations where outside help pays, the ones where it produces a document instead of an outcome, and the test that matters.
Microsoft 365, Entra and Intune
Microsoft 365 audit log retention: there right up until you needed it
What the unified audit log captures, how long by licence, and what an investigation looks like when the window has already closed.
An AI system inventory: finding out which features are AI before a customer asks
Where the AI in your product actually is, the eight columns worth recording, and why the register outlasts any version of the rules.
Microsoft Graph API permissions least privilege, not the first result
Application versus delegated, why ReadWrite gets granted by accident, and certificate auth over secrets.
Turning a CSV of findings into an Azure cost report finance will act on
Caveats before numbers, findings ranked by monthly cost, and three output formats because three different people need to read it.
Azure app registration secret expiry: they will go at 3am on a Saturday
Finding secrets and certificates due to expire, why a ten-year expiry is a different problem, and moving to managed identity.
Supplier risk assessment ISO 27001 wants, without a procurement department
Building the register, tiering by data access, and why obtaining their assurance beats sending your own questionnaire.