Security

Identity and Access Architecture for Azure Landing Zones: Entra ID, RBAC, and PIM

Identity and Access Architecture for Azure Landing Zones: Entra ID, RBAC, and PIM

The security team’s Slack message arrives on a Tuesday afternoon: “We’re seeing resource deletions in prod. Investigating.” Your heart rate goes up. You pull the Azure Activity Log. The deletions are attributed to a service principal—one your team created eight months ago for …

The Enterprise Case: Security and Privacy with Local AI

The Enterprise Case: Security and Privacy with Local AI

Your team completes a three-month migration to an air-gapped environment to satisfy new compliance requirements. Two security audits. Significant budget. Two weeks after go-live, someone discovers the developers are using personal phone hotspots to access GitHub Copilot — because the local …

Expression Security: Preventing Injection and Hardening Your YAML

Expression Security: Preventing Injection and Hardening Your YAML

“Enter your environment name: prod; rm -rf /”. If that input reached your pipeline, would it crash your production server? Most DevOps engineers worry about network firewalls and SSH keys, but they leave a massive back door open: Expression Injection. In the rush to build …

Security Baseline: Defender for Cloud and Microsoft Sentinel in a Landing Zone

Security Baseline: Defender for Cloud and Microsoft Sentinel in a Landing Zone

The compliance report lands in your inbox on a Tuesday morning. One finding: a production subscription had diagnostic logs disabled for 47 days. No one noticed because no one was watching. The subscription was vended six weeks ago, the app team started deploying workloads a week after that, and …