Azure

Microsoft Azure guides from the perspective of someone who has deployed it in anger across public sector, consultancy, and MSP environments. Covers the infrastructure certification path (AZ-104, AZ-305), Entra ID and Conditional Access, networking with VNets and NSGs, Bicep and Terraform for IaC, cost management, and the security baselines that keep auditors happy. No vendor marketing, no course slides reheated. These are notes from real deployments, common failure modes, and the gaps the official documentation skips over. If you are taking certifications or running production Azure workloads, the guidance here is built to survive the Monday morning support call.

An illuminated security keypad mounted on a wall, representing deliberate access control

Least Privilege in Practice: Standing Access, Scope and Just-in-Time

Everybody in IT can define least privilege. Give every identity the minimum access needed to do its job, and no more. It appears in every security policy, every framework, and every interview answer. Almost nobody implements it properly. That is not because the principle is hard to understand. It is because the principle is free […]

Least Privilege in Practice: Standing Access, Scope and Just-in-Time Read More »

Azure Just Put Your Old VMs on the Clock: How to Find Out If You’re Affected (Before 31 July)

Azure dropped an email in my inbox this morning. It waves a comfortable 2028 retirement date at you, so most people will archive it and move on. The part that could actually bite lands next week. From 31 July 2026, a large chunk of the estate people are quietly running can no longer scale or

Azure Just Put Your Old VMs on the Clock: How to Find Out If You’re Affected (Before 31 July) Read More »

Scroll to Top