Technical Writing
Tech Blog
Cloud security, identity, infrastructure, and research. Deep dives, tools, and practical guidance.
'A Human Should Check It' is Not an Agentic Security Control
MSRC assessed an indirect prompt injection into Security Copilot as Low severity because consequential action still required downstream automation or human approval. That rationale gets much more interesting once security systems are explicitly designed to perceive, reason, and act autonomously.
Continuous Access Evaluation: Is it really tho?
An investigation into Outlook Mobile continuing to access Exchange Online mailbox data after Conditional Access and Continuous Access Evaluation say the session should no longer be authorised.
Daddy Issues: When APIM Workspaces Inherit the Parent Identity
How a dedicated Azure API Management Workspace Gateway can still use the managed identity of its parent APIM service.
What The Entra Fudge?! Tenant Restrictions v1 Doesn't Mean What You Think It Means
Tenant Restrictions v1 can block access to unapproved Entra tenants while still allowing Microsoft consumer accounts unless a second header is injected into a different authentication endpoint.
We Automated Dave: Security Debt at Machine Speed
The recent wave of agent sandbox escapes is being treated as something fundamentally new. Mostly, it is not. We spent decades accumulating security debt, brittle trust, overprivilege and accidental reachability. Agents are making the exploration of those decisions cheap, persistent, parallel and very, very fast.
Prompting Was Never the Control Plane
AADLC started as a way to stop coding agents rediscovering the same truths every session. The evidence now points somewhere bigger: cARL as durable agent governance, CopeLimit and cARRIE as the FinOps feedback loop, Headroom as the optimisation layer, and cARLy Gates as a possible CI control for delegated cognition.