1. 32 min read

    ASC Default, simply

    A security checklist assigned in Azure Policy, with a saved policy-by-policy reference.

  2. 3 min read

    ASC Default Policies: Audit to Apply

    Apply selected security controls identified by ASC Default, with VM guest configuration as one example.

  3. 2 min read

    Defender for Cloud, simply

    How Microsoft finds cloud security risks, detects threats, and separates free checks from paid protection.

  4. 1 min read

    Azure Policy assignments at management-group scope

    A hands-on exploration of assignment scope, visible metadata, RBAC, and cleanup in the Azure portal.

  5. 6 min read

    Logic App to private storage, simply

    How a Standard Logic App reaches a locked-down storage account: VNet integration, two subnets, private endpoints, and why a service endpoint is not this path.

  6. 4 min read

    Logic Apps pricing, simply

    What you pay on Consumption, Standard WS1–WS3, ASE v3, Hybrid, and the preview Automation option, using Sweden Central list prices.

  7. 8 min read

    Logic Apps, simply

    Understand Logic Apps hosting plans and how a workflow connects to private storage.

  8. 12 min read

    Machine Configuration, simply

    Understand the Azure Policy view that reports settings inside your machines.

  9. 7 min read

    Private VM configuration through a hub, simply

    A shared private download point for VM configuration packages, with automatic setup for new subscriptions.

  10. 3 min read

    VNet peering, simply

    Connect two Azure private networks and understand what that connection allows.

  11. 8 min read

    Windows password age through policy, simply

    Follow the code from a Windows password setting to a package, Azure Policy and automatic correction.

  12. 3 min read

    MCSB managed centrally, simply

    One security baseline assignment across subscriptions: why it helps, how inheritance works, and where ASC Default overlaps.

  13. 7 min read

    Storage account, simply

    A storage account walkthrough: the setup choices, private endpoints, and the exception hiding behind disabled public access.

  14. 3 min read

    Azure naming conventions, simply

    Choose a readable naming pattern, handle Azure's exceptions, and record the decision.

  15. 4 min read

    Azure Policy as code: Terraform or Bicep?

    A decision record for choosing a policy deployment tool, including state, remediation, and when to consider EPAC.

  16. 30 min read

    Azure Windows baseline, simply

    One Azure Policy, many Windows security checks.

  17. 2 min read

    DSC, simply

    Describe the settings you want. Let the machine check and apply them.