You Can’t MFA an AI Agent
MFA was built on something you have, know and are. AI agents have, know and are none of it, yet they act with your identity. Here’s why that breaks authentication.
You Can’t MFA an AI Agent Read More »
Free-tier builds, hybrid cloud experiments, and open-source hosting across Azure, AWS, GCP, and beyond.
MFA was built on something you have, know and are. AI agents have, know and are none of it, yet they act with your identity. Here’s why that breaks authentication.
You Can’t MFA an AI Agent Read More »
AI agents don’t need to borrow your credentials. Entra Agent ID, SPIFFE and five open-source Microsoft projects give agents their own identity. Here’s the toolbox.
The Agent Identity Toolbox: Stop Your AI Agents Signing In as You Read More »
We spent a decade teaching users never to approve a prompt they didn’t start. AI agents make unprompted prompts routine. Here’s the attack vector nobody sees coming.
The Approval Reflex: When Your Agent Triggers Your MFA Read More »
This is the practical page. If you want the argument about why this work is never finished, that is a separate piece. This one is just the list, ordered by risk rather than by product area, so you can work through it. It is deliberately short. There are longer guides than this and most of
The Permissions Work to Do Before You Deploy Microsoft 365 Copilot Read More »
Everybody in IT can define least privilege. Give every identity the minimum access needed to do its job, and no more. It appears in every security policy, every framework, and every interview answer. Almost nobody implements it properly. That is not because the principle is hard to understand. It is because the principle is free
Least Privilege in Practice: Standing Access, Scope and Just-in-Time Read More »
Azure dropped an email in my inbox this morning. It waves a comfortable 2028 retirement date at you, so most people will archive it and move on. The part that could actually bite lands next week. From 31 July 2026, a large chunk of the estate people are quietly running can no longer scale or
When should you create a new Azure subscription versus a new resource group – and why “more subscriptions” stopped being a bad idea. A cloud architect’s decision guide, with the history of what changed.
Azure Subscription vs Resource Group: A Decision Guide (2026) Read More »
“Landing zone” means four different things in Azure – from a single subscription to a full enterprise platform. A cloud architect explains the spectrum and how to scope the one you actually need.
Which Azure Landing Zone Do You Need? A Scoping Guide (2026) Read More »
The network perimeter dissolved and identity replaced it. Why machine identity now outnumbers humans, what the Cloud Adoption Framework says about who governs it, and how to learn every principle in a homelab for free.
Every EC2 Instance You’ve Ever Launched Uses 60-Year-Old Concepts Cloud computing feels modern. AWS launched EC2 in 2006. Azure went general availability in 2010. Kubernetes hit 1.0 in 2015. If you started your career in the last decade, cloud might feel like it’s always existed. It hasn’t. But the concepts behind it have existed since
The Birth of Cloud Computing: From MIT Time-Sharing to Hyperscalers Read More »