Azure Bastion: diagnose native client access before opening RDP or SSH
A production runbook for separating local client, SKU, tunneling, RBAC, NSG and guest-service failures when Azure Bastion native access breaks.
Read article
Tag
74 articles connected to this technical signal.
A production runbook for separating local client, SKU, tunneling, RBAC, NSG and guest-service failures when Azure Bastion native access breaks.
Read articleA production runbook for separating expiration, audience, Grafana role and deployed-secret drift when Azure Managed Grafana automation receives a 401 or 403.
Read articleA production runbook for detecting MCP tool collisions, proving which tool the agent actually selected and validating a canary catalog before any sensitive action.
Read articleA production runbook for bounding a leak in agent traces, locating the unsafe field, canarying redaction and restoring useful observability.
Read articleA production runbook for separating ARM rollout, WAF associations, rule priority and request variance before a global Application Gateway policy rollback.
Read articleA production runbook for quarantining a suspicious Azure DevOps self-hosted agent, preserving evidence, bounding exposed identities and validating a clean replacement before the pool receives production jobs again.
Read articleA production runbook for separating legitimate automation, spoofed identities and hostile bot traffic before changing Azure WAF Bot Manager actions.
Read articleA production runbook for proving watchlist freshness, schema, SearchKey, deletions and KQL behavior before allowing it to influence automated response.
Read articleA production runbook for comparing the service connection, federated credential, issuer, subject, audience and RBAC before repairing, migrating or rolling back an Azure DevOps identity.
Read articleA production runbook for isolating hostile instructions carried by MCP tool output, preserving provenance, enforcing policy outside the model, and validating or rolling back write access.
Read articleA production runbook for tying an Azure DevOps artifact to its source, build run, digest and approval before promotion, quarantine or rollback.
Read articleA production runbook for qualifying an Azure Firewall IDPS signature in alert mode, measuring impact, canarying deny and retaining a targeted rollback.
Read articleA production runbook for inventorying Azure Automation webhook consumers, introducing a second endpoint, proving one execution per event, cutting over and revoking the old URL with a tested rollback.
Read articleA production runbook for bounding a secret leak in Azure DevOps logs, preserving evidence, revoking access, validating redaction and deciding recovery or rollback.
Read articleA production runbook for inventorying Key Vault access, staging data-plane roles, cutting over to Azure RBAC with real probes, validating workloads and rolling back without broadening permissions.
Read articleA production runbook for separating blocked prompts, filtered outputs, application errors and policy drift before changing Microsoft Foundry guardrails.
Read articleA production runbook for separating source ingestion, latency, analytics-rule execution, KQL windows and incident creation before changing a Microsoft Sentinel detection.
Read articleA production runbook for proving whether AKS traffic is denied by Kubernetes or Cilium policy, using selectors, both flow directions, DNS checks, bounded evidence and rollback.
Read articleA production runbook for separating PIM eligibility, activation, approval, Conditional Access, RBAC propagation and effective ARM access before any permanent bypass.
Read articleA production runbook for proving token audience, delegation, scopes and runtime identity across an MCP tool chain before restoring state-changing actions.
Read articleA production runbook for proving that a recreated Azure resource has a new principalId, finding orphaned roles and restoring least privilege without broadening RBAC.
Read articleA production runbook for replacing MCP Roots with tool parameters, resource URIs or server configuration while preserving path controls, canary evidence and rollback.
Read articleA production runbook for qualifying a reusable GitHub Actions workflow through permissions, secrets, OIDC, environments, traces, canary validation and rollback before an Azure deployment.
Read articleA production runbook for inventorying references, versioning an APIM policy fragment, testing it on a canary API revision, correlating traces and deciding promotion or rollback.
Read articleA production runbook for qualifying an Azure NSG rule based on a Service Tag using regional scope, real prefixes, effective rules, flow tests, canary rollout and rollback.
Read articleA production runbook for separating trust chain, hostname, SNI, expiry, TLS protocol and APIM configuration before disabling backend certificate validation.
Read articleA production runbook for separating file upload limits, request body size, inspection depth, WAF rules and backend rejection before a reversible change.
Read articleA production runbook for separating persistent sources, outputs, caches and machine state on a self-hosted Azure DevOps agent before cleanup, quarantine or recreation.
Read articleA production runbook for detecting and revalidating stale human approval across state drift, request fingerprints, expiry, traces, refusal tests and rollback before an AI agent resumes an action.
Read articleA production runbook for identifying an Azure Virtual Network Manager Security Admin rule, separating Allow, Always Allow and Deny, then validating or rolling back the deployment without blindly opening NSGs.
Read articleA production runbook for bounding a Microsoft Sentinel playbook across trigger, entities, identity, dry run, approval, traces, canary and rollback before any remediation action.
Read articleA production runbook to separate certificate issuance, Key Vault version, App Service import and hostname binding before syncing, rebinding or rolling back TLS.
Read articleA production runbook for detecting context leaks across AI agent sessions, separating memory, caches, retrieval, tools and identity, then enabling or rolling back persistence without losing audit traces.
Read articleA production runbook to identify the principal that actually executes an Azure Automation job, bound its permissions, validate with a canary and retain rollback.
Read articleA production runbook to prove that an alert processing rule suppresses notifications, bound its scope, validate recovery, and keep a rollback path.
Read articleA production runbook for tying commit, workflow, digest, attestation, approval and Azure identity together before promoting a GitHub Actions artifact.
Read articleA production runbook to qualify a Key Vault secret deletion, recover the soft-deleted object, validate its consumers and decide whether to keep or roll back recovery without exposing the value.
Read articleA production runbook for isolating a Microsoft Entra Workload ID failure across the pod, ServiceAccount, webhook, OIDC token, managed identity and RBAC, then validating or rolling back without a client secret.
Read articleA production runbook to separate Bastion sessions, NSGs, routing, target ports, identity and VM health before exposing SSH or RDP.
Read articleA production runbook for mapping an ACR vulnerability signal to AKS pods, freezing promotion, returning to a known digest, validating the rollout, then retaining or deleting the suspect image.
Read articleA production runbook for qualifying an Azure Key Vault secret consumed by Azure Pipelines through a variable group, isolating version, mapping, identity, network and precedence, then validating or rolling back without exposing the value.
Read articleA production runbook for proving which Azure Firewall rule handles a flow, separating routing from policy order, and applying a targeted fix with validation and rollback.
Read articleA production runbook for qualifying structured AI agent tool output with schema, sources, diff, idempotence, policy, traces, human validation and rollback before writing to production.
Read articleA production runbook for qualifying AI agent permission drift with the real identity, RBAC, tool scopes, traces, expected denials, human validation and rollback before widening access.
Read articleA production runbook for qualifying a blocked Azure flow with Network Watcher, NSG Flow Logs, effective security rules, routes, firewall, KQL evidence, validation and rollback before opening a broad rule.
Read articleA production runbook for qualifying Azure Firewall Threat Intelligence with logs, false positives, critical flows, targeted exceptions, deny decision and rollback before enabling Deny.
Read articleA production runbook for qualifying an Azure WAF OWASP/CRS managed rule upgrade with logs, false positives, Detection mode, policy diff, application validation, Prevention decision and rollback.
Read articleA production runbook for qualifying Azure Container Apps 401/403 failures with Managed Identity, token evidence, RBAC scope, Key Vault, ACR, logs, validation and rollback before widening permissions.
Read articleA production runbook for qualifying a Conditional Access block on a workload identity with service principal logs, policy scope, risk, CI identity, KQL evidence, bounded exception and rollback.
Read articleA production runbook for qualifying Azure WAF rate limiting with logs, counting key, real clients, false positives, load checks, threshold decision and rollback.
Read articleA production runbook for qualifying an internal MCP server with tool inventory, scopes, identities, secrets, audit, dry runs, evaluations, human validation and rollback before agent access.
Read articleA production runbook for qualifying Azure API Management mTLS failures with client certificate chain, hostname, policy, gateway logs, backend identity, validation and rollback before changing API policies.
Read articleA production runbook for tightening an Azure Firewall rule without breaking useful traffic, with inventory, KQL evidence, dependencies, controlled validation and rollback.
Read articleA production runbook for qualifying Azure API Management 401/403 errors with subscription key, product, API, consumer, logs, validation and rollback before rotation.
Read articleA production runbook for qualifying Microsoft Foundry agent guardrails with sources, refusals, tools, identity, traces, canary, human validation and rollback before user exposure.
Read articleA production runbook for qualifying suspected prompt injection in an AI agent retrieval corpus with sources, traces, evaluation, tools, guardrails, validation and rollback.
Read articleA production runbook for qualifying a Key Vault reference failure with managed identity, RBAC, secret version, diagnostics, KQL, validation and rollback before rotating or broadening access.
Read articleA production runbook for qualifying an APIM secret rotation with Named Values, Key Vault, managed identity, private backend, logs, application validation and rollback.
Read articleA production runbook for qualifying incomplete AI agent traces with conversation events, sources, tool calls, identities, approvals, evaluations and rollback before restoring an action.
Read articleA production runbook for qualifying Azure RBAC drift with the real identity, scope, PIM, role assignments, deny assignments, logs, validation and rollback before adding permissions.
Read articleA production runbook for exposing Azure DevOps to an AI agent through MCP with project scope, permissions, allowed actions, evidence, logs, human validation and rollback.
Read articleA production runbook for qualifying an Azure OIDC authentication failure in a CI pipeline with federated credentials, claims, roles, logs, validation and rollback.
Read articleA production runbook for qualifying AI agent contract drift with prompts, tool manifests, sources, evaluations, traces, human validation and rollback.
Read articleA production runbook for documenting an Azure WAF change with KQL evidence, policy diff, application probes, security validation, merge decision and rollback.
Read articleA short query to isolate rule, field, URI and examples before proposing a targeted WAF exclusion.
Read articleA production runbook for qualifying an AI agent action with traces, sources, tools, identity, KQL, human validation and rollback without disabling the whole assistant.
Read articleA production runbook for qualifying an Azure WAF policy before switching to Prevention with KQL evidence, change scope, application validation, rollback window and an operable decision.
Read articleA production runbook for qualifying blocked Azure traffic by separating NSG, UDR, Azure Firewall, DNS, effective routes, logs and rollback before opening access too broadly.
Read articleApply a temporary Azure WAF custom rule with priority, KQL evidence, business validation and rollback, without permanently hiding managed-rule signals.
Read articleA short command to list custom rules in an Azure WAF policy with priority, action and type before an urgent change.
Read articleBuild operable rotation for secrets, certificates, and application identities with dependency inventory, evidence, change windows, monitoring, and rollback.
Read articleA short KQL query to identify the most blocked URIs by Azure Web Application Firewall on Application Gateway.
Read articleBuild useful KQL queries to identify requests blocked by Azure Web Application Firewall on Application Gateway, with action, ruleId, URI, client IP, hostname and time window.
Read articleClarify the roles of Private Endpoint, VNet Integration, Application Gateway, API Management, DNS, routing and application authentication in a private Azure architecture.
Read article