Azure Managed Grafana: diagnose API access before recreating a token
A production runbook for separating expiration, audience, Grafana role and deployed-secret drift when Azure Managed Grafana automation receives a 401 or 403.
Read article
Tag
56 articles connected to this technical signal.
A production runbook for separating expiration, audience, Grafana role and deployed-secret drift when Azure Managed Grafana automation receives a 401 or 403.
Read articleA production runbook for quarantining a suspicious Azure DevOps self-hosted agent, preserving evidence, bounding exposed identities and validating a clean replacement before the pool receives production jobs again.
Read articleA production runbook for comparing the service connection, federated credential, issuer, subject, audience and RBAC before repairing, migrating or rolling back an Azure DevOps identity.
Read articleA production runbook for inventorying Key Vault access, staging data-plane roles, cutting over to Azure RBAC with real probes, validating workloads and rolling back without broadening permissions.
Read articleA production runbook for separating PIM eligibility, activation, approval, Conditional Access, RBAC propagation and effective ARM access before any permanent bypass.
Read articleA production runbook for proving token audience, delegation, scopes and runtime identity across an MCP tool chain before restoring state-changing actions.
Read articleA production runbook for proving that a recreated Azure resource has a new principalId, finding orphaned roles and restoring least privilege without broadening RBAC.
Read articleA production runbook for proving which Terraform writer owns an Azure Blob state lease, stopping competing pipelines, recovering a stale lock and validating state before another apply.
Read articleA production runbook to test a Toolbox version, its MCP tools, identities, approvals and traces before promotion, then return to the previous version without redeploying agents.
Read articleA production runbook for running an Azure Site Recovery test failover in an isolated network, validating dependencies, measuring application recovery and cleaning up unambiguously.
Read articleA production runbook for qualifying an Azure Key Vault secret consumed by Azure Pipelines through a variable group, isolating version, mapping, identity, network and precedence, then validating or rolling back without exposing the value.
Read articleA production runbook for qualifying AI agent permission drift with the real identity, RBAC, tool scopes, traces, expected denials, human validation and rollback before widening access.
Read articleA production runbook for qualifying an Azure DevOps self-hosted agent that no longer picks up jobs by separating runner service, identity, network, disk, cache, pool, logs and rollback.
Read articleA production runbook for qualifying the handoff from a Microsoft Foundry agent to Azure Automation, AWX, Azure DevOps or an MCP tool with contract, identity, traces, dry run, human validation and rollback.
Read articleA production runbook for qualifying an Azure API Management self-hosted gateway with configuration sync, token or Workload Identity, Kubernetes, logs, backend reachability, validation and rollback before moving traffic.
Read articleA production runbook for qualifying Azure Container Apps 401/403 failures with Managed Identity, token evidence, RBAC scope, Key Vault, ACR, logs, validation and rollback before widening permissions.
Read articleA production runbook for qualifying a Conditional Access block on a workload identity with service principal logs, policy scope, risk, CI identity, KQL evidence, bounded exception and rollback.
Read articleA production runbook for qualifying MCP server drift with tool manifests, schemas, identity, secrets, network path, traces, evaluations, validation and rollback before reauthorizing an AI agent.
Read articleA production runbook for qualifying an internal MCP server with tool inventory, scopes, identities, secrets, audit, dry runs, evaluations, human validation and rollback before agent access.
Read articleA production runbook for qualifying Azure API Management mTLS failures with client certificate chain, hostname, policy, gateway logs, backend identity, validation and rollback before changing API policies.
Read articleA production runbook for qualifying a failed AI agent tool call with trace evidence, idempotence, identity, backend state, approvals, validation and rollback before retrying.
Read articleA production runbook for qualifying AI agent memory with sources, traces, aging, permissions, evaluations, guardrails, human validation and rollback before it influences real actions.
Read articleA production runbook for qualifying an Azure Backup restore point with application consistency, dependencies, identity, networking, test restore, evidence, decision and rollback before cutover.
Read articleA production runbook for qualifying an Azure App Service Managed Identity failure with IMDS endpoint, Entra ID, RBAC, Key Vault or target API evidence, logs, validation and rollback before reintroducing a client secret.
Read articleA production runbook for qualifying an Azure DevOps failure on a self-hosted agent with disk, workspace, cache, local services, identity, logs, controlled cleanup, validation and rollback.
Read articleA production runbook for qualifying Azure API Management 401/403 errors with subscription key, product, API, consumer, logs, validation and rollback before rotation.
Read articleA production runbook for qualifying Microsoft Foundry agent guardrails with sources, refusals, tools, identity, traces, canary, human validation and rollback before user exposure.
Read articleA production runbook for qualifying an Azure DevOps deployment blocked by approvals or checks with environment scope, identity, logs, audit evidence, validation and rollback before bypassing the guardrail.
Read articleA production runbook for qualifying an agent approval policy change with action scope, identity, traces, evaluation cases, guardrails, human validation and rollback.
Read articleA production runbook for qualifying a Terraform, Bicep or ARM plan before apply with drift, CI identity, Azure Policy, destructive changes, validation and rollback.
Read articleA production runbook for rotating or revoking an AI agent runtime identity with scoped permissions, dry-run tool calls, traces, approvals, validation and rollback before breaking production actions.
Read articleA production runbook for qualifying a new AI agent tool with contract review, scoped identity, dry run, traces, approvals, evaluation cases and rollback before enabling real actions.
Read articleA production runbook for qualifying an Azure App Configuration or feature flag regression with labels, identities, refresh, Key Vault references, logs, validation and rollback.
Read articleA production runbook for qualifying an ACR image pull failure with identity, network, DNS, firewall, logs, node cache, validation and rollback before rerunning deployment.
Read articleA production runbook for qualifying Azure RBAC drift with the real identity, scope, PIM, role assignments, deny assignments, logs, validation and rollback before adding permissions.
Read articleA short query to isolate write-capable tool calls, their execution identity and correlation before disabling an AI agent.
Read articleA production runbook for qualifying an Azure deployment failure from a private runner by separating identity, DNS, routing, NSG, NAT, dependency access, logs and rollback.
Read articleA short query to find federated principal sign-in failures before falling back to a client secret.
Read articleA production runbook for running Azure Policy remediation with impact preview, managed identity checks, controlled batches, exemptions, logs and rollback.
Read articleA runbook for validating an AI agent before real action by separating sources, tools, identity, evaluation cases, human approvals, logs and rollback.
Read articleA production runbook for exposing MCP tools to an AI agent while keeping action scope, approvals, identities, logs, evaluation and rollback under control.
Read articleAn operational runbook for Azure Service Bus private access incidents by separating DNS, Private Endpoint, identity, firewall, metrics, logs and rollback.
Read articleA short query to separate missing connection evidence, identity denial, expired SAS and processing errors during a private Service Bus incident.
Read articleAn operational runbook for Azure SQL private access failures by separating DNS, Private Endpoint, firewall, identity, SQL logs and rollback evidence.
Read articleA short query to separate firewall, authentication, public endpoint and missing connection evidence during a private Azure SQL incident.
Read articleAn operational runbook for Azure Storage private access failures by separating DNS, Private Endpoint, firewall, identity, logs and rollback evidence.
Read articleA short query to separate identity, firewall, public endpoint and wrong subresource when private Azure Storage access is denied.
Read articleBuild an operational runbook for App Service private access failures by separating DNS, Private Endpoint, access restrictions, Application Gateway, application logs and rollback evidence.
Read articleBuild an operational runbook for private Azure Functions failures by separating DNS, Private Endpoint, access restrictions, private storage, Application Insights logs and rollback evidence.
Read articleA short query to separate DNS, private access, Functions runtime and application exceptions during a private HTTP incident.
Read articleQualify a failure across Application Gateway, WAF, internal APIM and a private backend by separating DNS, routing, policy, identity and logs before any fix.
Read articleBuild a runbook for Key Vault, Storage or private API access failures with managed identity, RBAC, private DNS, logs and real execution evidence.
Read articleA short query to separate identity denial, network path and source address when an Azure workload can no longer access Key Vault.
Read articleBuild operable rotation for secrets, certificates, and application identities with dependency inventory, evidence, change windows, monitoring, and rollback.
Read articleA short query to watch 401, 403, and 500 errors after rotating an application secret or service identity.
Read articleA multi-distribution runbook for joining Linux to Active Directory with realmd, adcli, SSSD, Kerberos, validation steps, and the checks that catch fragile integrations before they reach production.
Read article