Notes
Working notes on Azure cost and security, Microsoft 365, automation and ISO 27001. Written from running all of it for one small company.
All notes
How to answer security questionnaires: 240 questions, no lying
Building an answer library, mapping questions to controls and evidence, and the question that trips everyone up.
Microsoft 365, Entra and Intune
Intune configuration as code: export it, commit it, know what changed
Exporting policy via Graph, property-level diffs in nested settings catalog objects, and why this doubles as configuration management evidence.
ISO 27001 compliance automation platform: what it replaces and what it does not
Integrations and evidence collection are real. The risk assessment and the internal audit are still yours. A scorecard rather than a recommendation.
Idle Azure VMs: the servers that have been thinking about it since 2021
Defining idle with CPU, network and disk metrics rather than vibes, and the stopped-versus-deallocated distinction that costs people money.
The ISO 27001 surveillance audit nobody warns you about
What surveillance samples versus recertification, the controls that lapse in year two, and a calendar instead of a scramble.
Azure NSG rules audit: the any-any that was definitely temporary
Finding inbound from any source on management ports, and why the rule list is not the same as what actually flows.
ISO 27001 stage 1 and stage 2 audit: what the certification audit really tests
Stage 1 as readiness, Stage 2 as operation, what evidence means in practice, and minor versus major nonconformity.
Microsoft 365, Entra and Intune
Break glass account Entra setup: the fire extinguisher you never test
Two accounts, excluded from everything, monitored for any sign-in, and a password stored somewhere that is not a Teams chat.
ISO 27001 internal audit small company independence, without a second employee
Clause 9.2, why self-auditing fails, four routes to real independence, and the report format that feeds management review.
Orphaned Azure resources: an inventory of the things nobody remembers to delete
Disks are the obvious ones. Public IPs, empty load balancers and abandoned App Service plans are the ones that surprise people.
ISO 27001 policies list: shorter than the standard, longer than a tweet
The document set you actually need, one-page policies with linked procedures, and why length is what fails at interview.
Microsoft Sentinel cost: why the bill is bigger than the thing it protects
Which tables are worth ingesting on a small tenant, what basic logs cannot do, and how to check volume before the invoice arrives.