Skip to main content
Cutting Microsoft Sentinel cost without blinding your detections

Most of a Microsoft Sentinel bill is ingestion, and the usual ways to cut it are cheaper table plans, ingest-time filtering and moving old data out of the workspace. For a regional healthcare group we found that each of these can do exactly what its change record says while quietly damaging something else: in one case, 33 of the workspace’s 83 detections were running against no data. Measure the detections and the whole bill after every change, not only the setting you changed.

Read More
Key-person risk after an engineer leaves

When the one engineer who understood a platform leaves, the risk is rarely the code. It is the operational knowledge and access that lived with that person: which keys unseal the secrets store, where the infrastructure state is, and which credential quietly expires next month.

Read More
Your Azure OpenAI private endpoint may still be using the public internet

A regional healthcare group had Azure OpenAI private endpoints in both development and production, and its architecture diagrams showed AI traffic staying inside the virtual network. In practice, every API call from those networks was going to a public IP address. A private endpoint only makes traffic private if DNS sends clients to it, and in this estate two separate DNS mistakes meant it did not.

Read More