Azure Bastion: diagnose native client access before opening RDP or SSH
A production runbook for separating local client, SKU, tunneling, RBAC, NSG and guest-service failures when Azure Bastion native access breaks.
Read article
Tag
224 articles connected to this technical signal.
A production runbook for separating local client, SKU, tunneling, RBAC, NSG and guest-service failures when Azure Bastion native access breaks.
Read articleA production runbook for separating expiration, audience, Grafana role and deployed-secret drift when Azure Managed Grafana automation receives a 401 or 403.
Read articleA production runbook for detecting MCP tool collisions, proving which tool the agent actually selected and validating a canary catalog before any sensitive action.
Read articleA production runbook for separating source, tracking, skillset and document failures in Azure AI Search before rerunning, targeting recovery or resetting the indexer.
Read articleA production runbook for reconstructing the effects of a canceled Azure DevOps deployment, proving target state, and choosing an idempotent resume, compensation or rollback.
Read articleA production runbook for bounding a leak in agent traces, locating the unsafe field, canarying redaction and restoring useful observability.
Read articleA production runbook for tying expiry, scope, assignment and compliance together before renewing an Azure Policy exemption or disabling the guardrail.
Read articleA production runbook for measuring VNet Integration subnet capacity, separating address pressure from delegation and path failures, then validating resize or migration with rollback.
Read articleA production runbook for separating ARM rollout, WAF associations, rule priority and request variance before a global Application Gateway policy rollback.
Read articleA production runbook for quarantining a suspicious Azure DevOps self-hosted agent, preserving evidence, bounding exposed identities and validating a clean replacement before the pool receives production jobs again.
Read articleA production runbook for separating legitimate automation, spoofed identities and hostile bot traffic before changing Azure WAF Bot Manager actions.
Read articleA production runbook for proving watchlist freshness, schema, SearchKey, deletions and KQL behavior before allowing it to influence automated response.
Read articleA production runbook for separating DNS, remote dependency, network policy, conntrack and Azure SNAT pressure on AKS before changing the cluster outbound path.
Read articleA production runbook for separating inherited Azure management locks, RBAC, Policy and deny assignments, then validating a bounded unlock, deployment and rollback.
Read articleA production runbook for separating noisy metrics, miscalibrated requests, slow startup and node capacity before changing Horizontal Pod Autoscaler bounds on AKS.
Read articleA production runbook for comparing the service connection, federated credential, issuer, subject, audience and RBAC before repairing, migrating or rolling back an Azure DevOps identity.
Read articleA production runbook for proving that an agent fallback model preserves structured outputs, tool boundaries, refusals and traceability before routing live traffic.
Read articleA production runbook for separating processing time, connection loss, renewal failure and late settlement before extending an Azure Service Bus message lock.
Read articleA production runbook for isolating hostile instructions carried by MCP tool output, preserving provenance, enforcing policy outside the model, and validating or rolling back write access.
Read articleA production runbook for turning intermittent Azure connectivity into continuous evidence with Connection Monitor, then isolating DNS, routing, filtering and service health before changing network policy.
Read articleA production runbook for separating APIM counters, policy scope, token estimation, backend throttling and client retries before expanding an AI token limit.
Read articleA production runbook for tying an Azure DevOps artifact to its source, build run, digest and approval before promotion, quarantine or rollback.
Read articleA production runbook for measuring split-by dimension cardinality, containing notification noise, canarying stable grouping and rolling back an Azure Monitor log alert without losing coverage.
Read articleA production runbook for tying source commit, sync job, draft, published version, no-effect test and rollback together before allowing Azure Automation to act.
Read articleA production runbook for separating redelivery, splitOn, concurrency and ambiguous retries, then enforcing idempotency without removing workflow resilience.
Read articleA production runbook for qualifying an Azure Firewall IDPS signature in alert mode, measuring impact, canarying deny and retaining a targeted rollback.
Read articleA production runbook for separating agent regression from evaluator drift by freezing outputs, replaying an adjudicated anchor set, measuring disagreement and keeping promotion rollbackable.
Read articleA production runbook for separating parallel-job capacity, pool authorization, demands, capabilities and agent eligibility before scaling an Azure DevOps self-hosted pool.
Read articleA production runbook for separating pod resolver, CoreDNS, service path, upstream DNS and node-specific failures before restarting or rolling back AKS DNS.
Read articleA production runbook for inventorying Azure Automation webhook consumers, introducing a second endpoint, proving one execution per event, cutting over and revoking the old URL with a tested rollback.
Read articleA production runbook for bounding a secret leak in Azure DevOps logs, preserving evidence, revoking access, validating redaction and deciding recovery or rollback.
Read articleA production runbook for qualifying Azure Virtual WAN Routing Intent across private flows, internet egress, effective routes, Azure Firewall, canaries, validation and rollback.
Read articleA production runbook for inventorying Key Vault access, staging data-plane roles, cutting over to Azure RBAC with real probes, validating workloads and rolling back without broadening permissions.
Read articleA production runbook for qualifying OpenTelemetry tail sampling across trace affinity, late spans, memory pressure, policy coverage, Azure Monitor evidence, canary rollout and rollback.
Read articleA production runbook for inventorying Docker Content Trust, dual-signing with Notation, validating digests, and cutting over CI/CD gates with an explicit rollback.
Read articleA production runbook for proving Azure Resource Graph scope, identity, pagination and result completeness before an inventory drives automated changes.
Read articleA production runbook for separating blocked prompts, filtered outputs, application errors and policy drift before changing Microsoft Foundry guardrails.
Read articleA production runbook for separating source ingestion, latency, analytics-rule execution, KQL windows and incident creation before changing a Microsoft Sentinel detection.
Read articleA production runbook for separating image pull, startup, probes, configuration, secrets, resources and platform state when a Container Apps revision never becomes healthy.
Read articleA production runbook for measuring replication, checking the listener and secondary capacity, then deciding planned failover, forced failover or hold.
Read articleA production runbook for proving whether AKS traffic is denied by Kubernetes or Cilium policy, using selectors, both flow directions, DNS checks, bounded evidence and rollback.
Read articleA production runbook for separating PIM eligibility, activation, approval, Conditional Access, RBAC propagation and effective ARM access before any permanent bypass.
Read articleA production runbook for qualifying circuit breakers, Retry-After, Microsoft Foundry backend pools, canary traffic, observability and rollback before enabling AI API failover.
Read articleA production runbook for validating App Service all-traffic VNet routing across application calls, image pulls, content storage, backups, managed identity, firewall evidence and rollback.
Read articleA production runbook for proving token audience, delegation, scopes and runtime identity across an MCP tool chain before restoring state-changing actions.
Read articleA production runbook for separating ACR replication, regional routing, digests, identity and network paths before retrying or rolling back a container rollout.
Read articleA production runbook for proving that a recreated Azure resource has a new principalId, finding orphaned roles and restoring least privilege without broadening RBAC.
Read articleA production runbook to separate health signal, grace period, service state, VMSS model and local data before changing Replace, Reimage or Restart.
Read articleA production runbook for testing an Azure VM recovery point in isolation, validating the system and application, measuring recovery, then deciding readiness, remediation or rollback.
Read articleA production runbook for isolating the metric, target and labels behind an AKS time-series spike before filtering collection, adding capacity or rolling back.
Read articleA production runbook for separating a faulty health endpoint, instance degradation, redirects, authentication and dependency failures before restarting or changing App Service Health Check.
Read articleA production runbook for replacing MCP Roots with tool parameters, resource URIs or server configuration while preserving path controls, canary evidence and rollback.
Read articleA production runbook for qualifying a new Azure Automation runtime environment across versions, packages, Hybrid Workers, no-effect tests, canary execution, validation and rollback.
Read articleA production runbook for qualifying a reusable GitHub Actions workflow through permissions, secrets, OIDC, environments, traces, canary validation and rollback before an Azure deployment.
Read articleA production runbook for separating application health, probe contract, endpoint state, DNS answers, TTL and secondary capacity before forcing Traffic Manager failover.
Read articleA production runbook for bounding evidence age across retrieval, telemetry and tool results before an AI agent proposes, executes or rolls back an operational action.
Read articleA production runbook for separating demand, concurrency, scale groups, the instance ceiling, regional quota and downstream saturation before changing Function App capacity.
Read articleA production runbook for inventorying references, versioning an APIM policy fragment, testing it on a canary API revision, correlating traces and deciding promotion or rollback.
Read articleA production runbook for qualifying an Azure NSG rule based on a Service Tag using regional scope, real prefixes, effective rules, flow tests, canary rollout and rollback.
Read articleA production runbook for separating trust chain, hostname, SNI, expiry, TLS protocol and APIM configuration before disabling backend certificate validation.
Read articleA production runbook for separating file upload limits, request body size, inspection depth, WAF rules and backend rejection before a reversible change.
Read articleA production runbook for qualifying an AI agent regional failover across model deployment, state, retrieval, tools, identity, traces, canary traffic, validation and rollback.
Read articleA production runbook for separating persistent sources, outputs, caches and machine state on a self-hosted Azure DevOps agent before cleanup, quarantine or recreation.
Read articleA production runbook for detecting and revalidating stale human approval across state drift, request fingerprints, expiry, traces, refusal tests and rollback before an AI agent resumes an action.
Read articleA production runbook to separate disk limits, VM I/O caps, burst credits and guest contention before resizing a disk or changing its performance tier.
Read articleA production runbook for identifying an Azure Virtual Network Manager Security Admin rule, separating Allow, Always Allow and Deny, then validating or rolling back the deployment without blindly opening NSGs.
Read articleA production runbook for bounding a Microsoft Sentinel playbook across trigger, entities, identity, dry run, approval, traces, canary and rollback before any remediation action.
Read articleA production runbook to separate certificate issuance, Key Vault version, App Service import and hostname binding before syncing, rebinding or rolling back TLS.
Read articleA production runbook for qualifying an incomplete Azure Update Manager campaign across dynamic scope, orchestration, window budget, installation, reboot and validation before any out-of-window retry.
Read articleA production runbook for detecting context leaks across AI agent sessions, separating memory, caches, retrieval, tools and identity, then enabling or rolling back persistence without losing audit traces.
Read articleA production runbook to separate health probes, DNS/TLS, Private Link, backend capacity and routing before draining, failing over or rolling back.
Read articleA production runbook to identify the principal that actually executes an Azure Automation job, bound its permissions, validate with a canary and retain rollback.
Read articleA production runbook to qualify Azure Database for PostgreSQL read replica lag, prove the achievable RPO, and choose repair, planned switchover, or forced promotion.
Read articleA production runbook to separate client reconnects, server pressure, DNS/TLS and network saturation, then validate a fix, scaling decision or rollback.
Read articleA production runbook to prove that an alert processing rule suppresses notifications, bound its scope, validate recovery, and keep a rollback path.
Read articleA production runbook for reconstructing an AI agent's context, isolating history, retrieval and tool outputs, then validating compaction or rolling back.
Read articleA production runbook for qualifying inconsistent feature flag evaluations across instances by separating version, refresh, cache, targeting, telemetry and rollback.
Read articleA production runbook for separating Logic Apps limits, connector throttling and downstream saturation, then reducing concurrency, validating a canary or rolling back without amplifying 429 responses.
Read articleA production runbook for tying commit, workflow, digest, attestation, approval and Azure identity together before promoting a GitHub Actions artifact.
Read articleA production runbook for locating an AKS rollout stalled across Deployment, ReplicaSet, scheduling, image and readiness, then resuming or returning to a known revision with explicit stop conditions.
Read articleA production runbook for proving which Terraform writer owns an Azure Blob state lease, stopping competing pipelines, recovering a stale lock and validating state before another apply.
Read articleA production runbook for proving that an AgentOps score is not inflated by leakage across evaluations, prompts, retrieval or tuning data before promoting an AI agent.
Read articleA production runbook for pinning an ACR digest, verifying its Notation signature, scoping trust policy, promoting by digest, and rolling back without disabling provenance controls.
Read articleA production runbook for inventorying NSG flow logs, enabling virtual network flow logs in parallel, validating the new KQL schema, and cutting over with an explicit rollback.
Read articleA production runbook for proving retry amplification in Azure API Management, protecting an overloaded backend, and choosing a bounded policy change, circuit breaker or rollback.
Read articleA production runbook to test a Toolbox version, its MCP tools, identities, approvals and traces before promotion, then return to the previous version without redeploying agents.
Read articleA production runbook to qualify a Key Vault secret deletion, recover the soft-deleted object, validate its consumers and decide whether to keep or roll back recovery without exposing the value.
Read articleA production runbook for qualifying missing logs after a Data Collection Rule change, separating source, stream, KQL transformation and destination, then validating or rolling back with a canary.
Read articleA production runbook for separating app ID, Dapr sidecars, application port, mTLS, resiliency and revisions when service invocation fails in Azure Container Apps.
Read articleA production runbook to separate connection leaks, SQL saturation, network latency and identity renewal before increasing the service tier.
Read articleA production runbook for classifying dead-lettered messages, proving the cause, checking idempotency and replaying with a canary without creating a second incident.
Read articleA production runbook for isolating a Microsoft Entra Workload ID failure across the pod, ServiceAccount, webhook, OIDC token, managed identity and RBAC, then validating or rolling back without a client secret.
Read articleA production runbook to separate Bastion sessions, NSGs, routing, target ports, identity and VM health before exposing SSH or RDP.
Read articleA production runbook for separating queueing, heartbeat, extension, network, capacity, identity and runtime failures before retrying a Hybrid Worker job.
Read articleA production runbook for validating the target set, identity, roles, canary, logs and rollback of an Azure Policy remediation before scaling it out.
Read articleA production runbook to separate ingestion pressure, throttling, hot partitions, consumer failures and checkpoint drift before adding capacity or replaying events.
Read articleA production runbook to separate effective routes, next hop, NVA health, IP forwarding, policy and return path before fixing a UDR or bypassing inspection.
Read articleA production runbook for detecting an agent delegation loop, containing side effects, rebuilding traces, and deciding controlled recovery or a single-agent rollback.
Read articleA production runbook for reconstructing an interrupted Terraform apply on Azure, comparing configuration, state and live resources, then choosing rerun, targeted import, rollback or state repair.
Read articleA production runbook for separating Arc connectivity, effective proxy settings, extension service failures and handler errors before reinstalling the agent or widening outbound access.
Read articleA production runbook to isolate AMPLS, DCE, DCR, DNS, associations and Azure Monitor Agent when telemetry disappears after network hardening, then validate or roll back without broadly reopening public access.
Read articleA production runbook for controlling blast radius, execution identity, evidence, abort criteria and recovery for an Azure Chaos Studio scenario.
Read articleA production runbook for finding an Azure change with Resource Graph Change Analysis, connecting it to its actor and impact, then validating or rolling it back without reverting blindly.
Read articleA production runbook for mapping an ACR vulnerability signal to AKS pods, freezing promotion, returning to a known digest, validating the rollout, then retaining or deleting the suspect image.
Read articleA production runbook for running an Azure Site Recovery test failover in an isolated network, validating dependencies, measuring application recovery and cleaning up unambiguously.
Read articleA production runbook for comparing a candidate agent with the active runtime on the same requests without duplicating actions, then deciding promotion, canary or rollback.
Read articleA production runbook for qualifying an Azure Key Vault secret consumed by Azure Pipelines through a variable group, isolating version, mapping, identity, network and precedence, then validating or rolling back without exposing the value.
Read articleA production runbook for proving which Azure Firewall rule handles a flow, separating routing from policy order, and applying a targeted fix with validation and rollback.
Read articleA production runbook for building and qualifying an Azure Monitor burn-rate alert by separating the SLI, error budget, short and long windows, telemetry quality, notification, validation and rollback.
Read articleA production runbook for qualifying poisoned Queue trigger messages, separating deterministic and transient failures, proving idempotency, then replaying or rolling back without duplicating business side effects.
Read articleA production runbook for locating telemetry loss across receivers, processors, queues and exporters, then validating capacity changes or rolling back safely.
Read articleA production runbook for attributing token and tool-call growth, isolating amplification, enforcing an execution budget, and validating or rolling back an AI agent release.
Read articleA production runbook for diagnosing concurrent GitHub Actions deployments, serializing writes, validating the active version, and resuming or rolling back without adding another race.
Read articleA production runbook for canarying a KQL transformation in an Azure Monitor Data Collection Rule, comparing volume and schema, detecting rejected records, then validating or rolling back without an observability gap.
Read articleA production runbook for qualifying a Terraform provider upgrade with a lockfile, baseline plan, canary, operational evidence and an explicit rollback.
Read articleA production runbook for defining latency budgets, idempotency, retries, circuit breakers, traces and rollback for an MCP tool called by an AI agent.
Read articleA production runbook for bounding a BGP change, comparing learned and advertised routes, checking effective routes, canarying one prefix, then validating or withdrawing it without destabilizing the Azure hub.
Read articleA production runbook for diagnosing an AKS drain blocked by a PodDisruptionBudget, recovering disruption headroom, fixing capacity or readiness, then validating or postponing the upgrade without removing safeguards.
Read articleA production runbook for recovering Application Insights and OpenTelemetry correlation across Azure Service Bus, qualifying W3C propagation, sampling and message processing, then validating or rolling back the fix.
Read articleA production runbook for qualifying structured AI agent tool output with schema, sources, diff, idempotence, policy, traces, human validation and rollback before writing to production.
Read articleA production runbook for reviewing managed resources, unmanage behavior, deny settings, excluded identities, validation and rollback before updating an Azure Deployment Stack.
Read articleA production runbook for qualifying AI agent permission drift with the real identity, RBAC, tool scopes, traces, expected denials, human validation and rollback before widening access.
Read articleA production runbook for qualifying an Azure Container Apps Job that no longer consumes correctly with KEDA scale rule, backlog, managed identity, secrets, logs, idempotency, validation and rollback before rerunning workers.
Read articleA production runbook for qualifying an Azure DevOps self-hosted agent that no longer picks up jobs by separating runner service, identity, network, disk, cache, pool, logs and rollback.
Read articleA production runbook for qualifying a blocked Azure flow with Network Watcher, NSG Flow Logs, effective security rules, routes, firewall, KQL evidence, validation and rollback before opening a broad rule.
Read articleA production runbook for qualifying the handoff from a Microsoft Foundry agent to Azure Automation, AWX, Azure DevOps or an MCP tool with contract, identity, traces, dry run, human validation and rollback.
Read articleA production runbook for qualifying Azure Firewall Threat Intelligence with logs, false positives, critical flows, targeted exceptions, deny decision and rollback before enabling Deny.
Read articleA production runbook for qualifying an Azure API Management regression with APIM traces, policy diff, headers, cache, backend, identity, logs, validation and rollback before changing the API or target service.
Read articleA production runbook for qualifying an Azure WAF OWASP/CRS managed rule upgrade with logs, false positives, Detection mode, policy diff, application validation, Prevention decision and rollback.
Read articleA production runbook for qualifying an Azure API Management self-hosted gateway with configuration sync, token or Workload Identity, Kubernetes, logs, backend reachability, validation and rollback before moving traffic.
Read articleA production runbook for qualifying a stuck Azure Durable Functions orchestration with instance history, activity state, storage, idempotency, KQL, validation and rollback before replay, terminate or purge.
Read articleA production runbook for qualifying Azure Container Apps 401/403 failures with Managed Identity, token evidence, RBAC scope, Key Vault, ACR, logs, validation and rollback before widening permissions.
Read articleA production runbook for qualifying an Azure Storage lifecycle policy with Blob inventory, versions, snapshots, delete or tiering rules, evidence, validation and rollback before removing data.
Read articleA production runbook for qualifying an Azure Container Apps incident after deployment by separating active revisions, traffic weights, labels, logs, probes, dependencies, validation and rollback.
Read articleA production runbook for qualifying a Conditional Access block on a workload identity with service principal logs, policy scope, risk, CI identity, KQL evidence, bounded exception and rollback.
Read articleA production runbook for qualifying MCP server drift with tool manifests, schemas, identity, secrets, network path, traces, evaluations, validation and rollback before reauthorizing an AI agent.
Read articleA production runbook for qualifying a failed Azure Functions Timer Trigger with execution history, schedule locks, storage, Application Insights, idempotency, validation and rollback before manual replay.
Read articleA production runbook for qualifying Azure DevOps Variable Group drift with variables, secrets, Key Vault, scopes, logs, validation and rollback before rerunning a pipeline.
Read articleA production runbook for qualifying Azure Workbooks drift with KQL, Log Analytics, Application Insights, dimensions, ingestion latency, validation and rollback before changing alerts or dashboards.
Read articleA production runbook for qualifying Azure Front Door origin health with probes, routing, DNS, TLS, WAF evidence, backend logs, validation and rollback before forcing failover.
Read articleA production runbook for qualifying Azure WAF rate limiting with logs, counting key, real clients, false positives, load checks, threshold decision and rollback.
Read articleA production runbook for qualifying an internal MCP server with tool inventory, scopes, identities, secrets, audit, dry runs, evaluations, human validation and rollback before agent access.
Read articleA production runbook for qualifying Azure API Management mTLS failures with client certificate chain, hostname, policy, gateway logs, backend identity, validation and rollback before changing API policies.
Read articleA production runbook for qualifying apparent Application Insights telemetry loss with sampling, ingestion, SDK configuration, KQL, alerts, validation and rollback before changing thresholds.
Read articleA production runbook for qualifying an Azure Service Health or Resource Health signal with user impact, dependencies, routing, DNS, observability, failover decision and rollback.
Read articleA production runbook for qualifying a failed AI agent tool call with trace evidence, idempotence, identity, backend state, approvals, validation and rollback before retrying.
Read articleA production runbook for qualifying AI agent memory with sources, traces, aging, permissions, evaluations, guardrails, human validation and rollback before it influences real actions.
Read articleA production runbook for qualifying an Azure Backup restore point with application consistency, dependencies, identity, networking, test restore, evidence, decision and rollback before cutover.
Read articleA production runbook for qualifying an Azure Monitor Action Group by separating rules, receivers, webhooks, escalation paths, KQL evidence, validation and rollback before reducing notifications.
Read articleA production runbook for qualifying an AI agent evaluation set with business cases, retrieval, tool calls, traces, thresholds, human validation and rollback before promotion.
Read articleA production runbook for qualifying an Azure App Service Managed Identity failure with IMDS endpoint, Entra ID, RBAC, Key Vault or target API evidence, logs, validation and rollback before reintroducing a client secret.
Read articleA production runbook for qualifying an Azure DevOps failure on a self-hosted agent with disk, workspace, cache, local services, identity, logs, controlled cleanup, validation and rollback.
Read articleA production runbook for tightening an Azure Firewall rule without breaking useful traffic, with inventory, KQL evidence, dependencies, controlled validation and rollback.
Read articleA production runbook for qualifying Azure API Management 401/403 errors with subscription key, product, API, consumer, logs, validation and rollback before rotation.
Read articleA production runbook for qualifying a delayed Azure Monitor alert by separating application timestamps, Log Analytics ingestion, KQL query windows, evaluation frequency, action groups, validation and rollback.
Read articleA production runbook for qualifying App Service egress IP drift with VNet Integration, NAT Gateway, DNS, UDRs, destination logs, validation and rollback before changing a partner allowlist.
Read articleA production runbook for qualifying a failed Azure Logic Apps execution with trigger, connectors, managed identity, payload, logs, validation and rollback before resubmit.
Read articleA production runbook for qualifying Cosmos DB 429 throttling with RU consumption, hot partitions, query shape, SDK retries, indexing, KQL evidence, scaling decision and rollback.
Read articleA production runbook for qualifying Microsoft Foundry agent guardrails with sources, refusals, tools, identity, traces, canary, human validation and rollback before user exposure.
Read articleA production runbook for qualifying suspected prompt injection in an AI agent retrieval corpus with sources, traces, evaluation, tools, guardrails, validation and rollback.
Read articleA production runbook for qualifying Key Vault degradation by separating latency, throttling, identity, network path, application cache, logs and rollback before starting a secret rotation.
Read articleA production runbook for qualifying an Azure DevOps deployment blocked by approvals or checks with environment scope, identity, logs, audit evidence, validation and rollback before bypassing the guardrail.
Read articleA production runbook for qualifying an Azure Policy deployment deny with assignment, initiative, deny effect, compliance, scoped exemption, validation and rollback.
Read articleA production runbook for qualifying an agent approval policy change with action scope, identity, traces, evaluation cases, guardrails, human validation and rollback.
Read articleA production runbook for qualifying an unhealthy Azure Load Balancer backend with probe behavior, NSGs, routing, logs, pool configuration, validation and rollback before changing the rule or redeploying.
Read articleA production runbook for qualifying an Application Gateway TLS certificate rotation from Key Vault with managed identity, listener checks, WAF evidence, probes, logs, validation and rollback.
Read articleA production runbook for qualifying a Terraform, Bicep or ARM plan before apply with drift, CI identity, Azure Policy, destructive changes, validation and rollback.
Read articleA production runbook for qualifying Azure OpenAI or Microsoft Foundry throttling with quota, deployment capacity, agent traces, retries, fallback, validation and rollback before changing models.
Read articleA production runbook for qualifying an Azure Managed Grafana dashboard or alert with Azure Monitor datasource, managed identity, Log Analytics permissions, variables, traces, validation and rollback before changing KQL queries.
Read articleA production runbook for rotating or revoking an AI agent runtime identity with scoped permissions, dry-run tool calls, traces, approvals, validation and rollback before breaking production actions.
Read articleA production runbook for qualifying an Azure Front Door failure with origin groups, health probes, TLS, Private Link, DNS, WAF, logs, validation and rollback before changing routing.
Read articleA production runbook for qualifying Azure Event Grid delivery failures with subscription filters, endpoint health, dead-letter storage, diagnostics, replay scope, validation and rollback before reprocessing events.
Read articleA production runbook for qualifying a Key Vault reference failure with managed identity, RBAC, secret version, diagnostics, KQL, validation and rollback before rotating or broadening access.
Read articleA production runbook for qualifying an Azure Monitor alert that fired but did not notify anyone, with action groups, receivers, processing rules, webhooks, evidence, validation and rollback.
Read articleA production runbook for qualifying Azure asymmetric routing with effective routes, UDRs, Azure Firewall, NAT Gateway, flow logs, validation and rollback before changing route tables.
Read articleA production runbook for qualifying an Azure Automation failure with managed identity, parameters, modules, Hybrid Worker, webhooks, logs, validation and rollback before rerun.
Read articleA production runbook for qualifying a scheduled Azure Automation job with trigger, managed identity, parameters, dry-run, logs, validation and rollback before allowing real action.
Read articleA production runbook for qualifying a new AI agent tool with contract review, scoped identity, dry run, traces, approvals, evaluation cases and rollback before enabling real actions.
Read articleA production runbook for qualifying an APIM secret rotation with Named Values, Key Vault, managed identity, private backend, logs, application validation and rollback.
Read articleA production runbook for qualifying a retrieval index update with source diff, metadata, chunking, evaluations, traces, human validation and rollback before changing an AI agent's answers.
Read articleA production runbook for qualifying an Azure App Configuration or feature flag regression with labels, identities, refresh, Key Vault references, logs, validation and rollback.
Read articleA production runbook for qualifying an Azure App Service slot swap with configuration drift, warmup, identity, dependencies, logs, validation and rollback before promotion.
Read articleA production runbook for qualifying an Azure egress failure with Firewall DNS proxy, FQDN resolution, UDRs, application rules, logs, validation and rollback before broadening traffic.
Read articleA production runbook for qualifying incomplete AI agent traces with conversation events, sources, tool calls, identities, approvals, evaluations and rollback before restoring an action.
Read articleA production runbook for qualifying an AWX dynamic inventory change with source, host diff, variables, identities, limits, validation and rollback before execution.
Read articleA production runbook for qualifying an ACR image pull failure with identity, network, DNS, firewall, logs, node cache, validation and rollback before rerunning deployment.
Read articleA production runbook for qualifying missing Azure Monitor logs with Diagnostic Settings, DCRs, ingestion, KQL, cost controls, validation and rollback before changing alerts.
Read articleA production runbook for qualifying Azure RBAC drift with the real identity, scope, PIM, role assignments, deny assignments, logs, validation and rollback before adding permissions.
Read articleA production runbook for exposing Azure DevOps to an AI agent through MCP with project scope, permissions, allowed actions, evidence, logs, human validation and rollback.
Read articleA production runbook for qualifying an Azure Private DNS change with workload-side resolution, VNet links, Private Resolver, TTL, logs, application validation and rollback.
Read articleA production runbook for qualifying a failed AWX job with Ansible events, changed tasks, affected hosts, variables, limited rerun, validation and rollback.
Read articleA production runbook for qualifying an Azure OIDC authentication failure in a CI pipeline with federated credentials, claims, roles, logs, validation and rollback.
Read articleA production runbook for qualifying AI agent contract drift with prompts, tool manifests, sources, evaluations, traces, human validation and rollback.
Read articleA production runbook for qualifying Azure hybrid DNS incidents with Private DNS Resolver, forwarding rulesets, private zones, caches, evidence, validation and rollback.
Read articleA production runbook for qualifying Azure egress failures with UDR, NAT Gateway, NSG, firewall, DNS, KQL, validation and rollback before adding an overbroad rule.
Read articleA production runbook for documenting an Azure WAF change with KQL evidence, policy diff, application probes, security validation, merge decision and rollback.
Read articleA production runbook for qualifying an AI agent action with traces, sources, tools, identity, KQL, human validation and rollback without disabling the whole assistant.
Read articleA production runbook for qualifying an Azure deployment failure from a private runner by separating identity, DNS, routing, NSG, NAT, dependency access, logs and rollback.
Read articleA production runbook for qualifying Azure Container Apps outbound failures by separating DNS, UDR, NSG, NAT Gateway, firewall, identity, logs and rollback before changing the application.
Read articleA production runbook for deciding an Azure rollback after deployment with Azure Monitor, KQL, impact correlation, regression evidence, validation and controlled recovery.
Read articleA production runbook for running Azure Policy remediation with impact preview, managed identity checks, controlled batches, exemptions, logs and rollback.
Read articleA production runbook for qualifying an Azure WAF policy before switching to Prevention with KQL evidence, change scope, application validation, rollback window and an operable decision.
Read articleA production runbook for qualifying blocked Azure traffic by separating NSG, UDR, Azure Firewall, DNS, effective routes, logs and rollback before opening access too broadly.
Read articleA runbook for validating an AI agent before real action by separating sources, tools, identity, evaluation cases, human approvals, logs and rollback.
Read articleA production runbook for exposing MCP tools to an AI agent while keeping action scope, approvals, identities, logs, evaluation and rollback under control.
Read articleA production runbook for qualifying an Azure Monitor alert storm after deployment by separating real signal, noise, regression, threshold drift, action group behavior and rollback.
Read articleAn operational runbook for qualifying Azure outbound incidents involving NAT Gateway, SNAT ports, UDR, NSG, firewalls, allowlists and rollback.
Read articleAn operational runbook for qualifying Azure App Service or Functions outbound failures by separating VNet Integration, DNS, UDR, NSG, NAT, logs and rollback.
Read articleA production runbook for qualifying an AI agent that selects the wrong tool, acts without evidence or hides an action behind a plausible answer.
Read articleAn operational runbook for Azure Service Bus private access incidents by separating DNS, Private Endpoint, identity, firewall, metrics, logs and rollback.
Read articleAn operational runbook for Azure SQL private access failures by separating DNS, Private Endpoint, firewall, identity, SQL logs and rollback evidence.
Read articleAn operational runbook for Azure Storage private access failures by separating DNS, Private Endpoint, firewall, identity, logs and rollback evidence.
Read articleBuild an operational runbook for App Service private access failures by separating DNS, Private Endpoint, access restrictions, Application Gateway, application logs and rollback evidence.
Read articleBuild an operational runbook for private Azure Functions failures by separating DNS, Private Endpoint, access restrictions, private storage, Application Insights logs and rollback evidence.
Read articleBuild an operational runbook for AKS private ingress failures by separating DNS, Application Gateway, ingress controller, Kubernetes service endpoints, pod readiness and rollback evidence.
Read articleA short query to read ingress controller and application logs together when a private AKS route returns 502, timeouts or no endpoints.
Read articleBuild an operational runbook for Azure Container Apps private ingress failures by separating DNS, ingress mode, revision routing, application logs and rollback evidence.
Read articleA short query to correlate Azure Container Apps system and console logs when private ingress, probes or revision traffic fail.
Read articleQualify a failure across Application Gateway, WAF, internal APIM and a private backend by separating DNS, routing, policy, identity and logs before any fix.
Read articleBuild a runbook for Key Vault, Storage or private API access failures with managed identity, RBAC, private DNS, logs and real execution evidence.
Read articleApply a temporary Azure WAF custom rule with priority, KQL evidence, business validation and rollback, without permanently hiding managed-rule signals.
Read articleA short command to list custom rules in an Azure WAF policy with priority, action and type before an urgent change.
Read articleBuild operable rotation for secrets, certificates, and application identities with dependency inventory, evidence, change windows, monitoring, and rollback.
Read articleA short query to watch 401, 403, and 500 errors after rotating an application secret or service identity.
Read article