Autonomous agents that read mail, post in Teams and edit SharePoint are arriving in enterprise tenants faster than the controls around them. An agent is a new kind of non-human user that takes instructions from any text it reads, so it needs the same containment you would give an untrusted contractor with admin tools, designed in before it is switched on.
Read Moreazure
Most of a Microsoft Sentinel bill is ingestion, and the usual ways to cut it are cheaper table plans, ingest-time filtering and moving old data out of the workspace. For a regional healthcare group we found that each of these can do exactly what its change record says while quietly damaging something else: in one case, 33 of the workspace’s 83 detections were running against no data. Measure the detections and the whole bill after every change, not only the setting you changed.
Read MoreA failover exercise we ran for a client hit three defects, and any one of them would have stopped a real recovery. All three had already been found in the previous exercise fifteen months earlier, worked around on a tag that sat on no branch, and never fixed. A workaround that does not merge is not a fix: it is a known defect waiting for the next disaster.
Read MoreA voice agent’s tools fail in ways a chat agent’s don’t: the caller hangs up mid-sentence, a setting is missing, or the phone network refuses a transfer while someone is listening. The lesson from building our own AI receptionist is that every tool needs a safe fallback that still captures the caller, and that telephony features need proof on live calls, not just passing unit tests.
Read MoreWhen the one engineer who understood a platform leaves, the risk is rarely the code. It is the operational knowledge and access that lived with that person: which keys unseal the secrets store, where the infrastructure state is, and which credential quietly expires next month.
Read MoreTwice on the same SQL Server estate on Azure VMs, the database engine kept running while the service around it failed. In the first incident, customers lost access for 71 minutes because a backup job was retrying against a credential that did not exist. In the second, seven databases went without full backups, and nothing alerted until their transaction-log backups stopped and point-in-time recovery was already lost. In both cases “is the service running?” was the wrong check.
Read More