Michał Machniak (MCT)
mmachniak.bsky.social
Michał Machniak (MCT)
@mmachniak.bsky.social
MCT/MCSA/MCSE, Microsoft Specialist ... Admin from begin of life :) … long live Admins ! I love automation #PowerShell #Azure #M365 #sysOps #PanMichal #MCT #AzOps #DevOps
🔐 Managing hybrid servers with #AzureArc?
Stop giving full Contributor rights!
Check out this custom Azure Arc VM Operator role perfect for least-privilege access 👇
mmachniak.net/2025/09/22/A...

#Azure #HybridCloud #IAM #Security #AzOps #Microsoft #Arc #AzureArc #Windows
Delegate for Azure ARC least-privilege access for hybrid servers - Custom role
This blog post explains why organizations using Azure Arc–enabled servers should implement least-privilege access through custom roles. It walks through real-world scenarios where built-in Azure roles...
mmachniak.net
November 10, 2025 at 9:46 PM
🚀 New in #Azure: Machine Configuration now supports custom security baselines for server OS settings!
✅ Customize #Windows/#Linux OS baselines
✅ Enforce via Azure Policy
✅ Monitor + auto-remediate drift
Big step for compliance & governance automation. 💪
#CloudSecurity
November 2, 2025 at 11:12 AM
🚀 Master Azure Networking !
Learn how to build scalable, secure cloud infrastructure with hub-and-spoke design, solid IP planning, & key Azure security controls.
mmachniak.net/2025/10/20/M...

#Azure #CloudNetworking #AzureArchitecture #CloudSecurity #MicrosoftAzure #AzOps
October 20, 2025 at 4:09 PM
🌟 Excited to share a new open-source project!
I’ve just published bicep-ext-PassWordGenerator a small extension for Azure Bicep. here 👉 github.com/mimachniak/b...
#Azure #Bicep #InfrastructureAsCode #OpenSource #Cloud #AzOps #DevOps #IaaC #Microsoft #community #csharp #extension
GitHub - mimachniak/bicep-ext-PassWordGenerator
Contribute to mimachniak/bicep-ext-PassWordGenerator development by creating an account on GitHub.
github.com
September 11, 2025 at 9:53 PM
🚀 Hi my new blog post include code example of bicep creation of security and roles assignment in Azure Landing Zone
🚀 Create Entra ID security groups
🛡️ Assign Azure roles directly to groups
👉 Link to blog mmachniak.net/2025/08/11/B...
#AzOps #IaaC #Bicep #Azure #EntraID #Secuirty #Microsoft #DevOps
Using the Microsoft Azure Bicep Graph Extension to Create Security Groups and Assign Roles in an Azure Landing Zone
In large, multi-subscription environments, such as Azure Landing Zones, managing identity and access at scale is a constant challenge. Security groups are a key component of Azure RBAC (Role-Based Acc...
mmachniak.net
August 11, 2025 at 8:37 AM
🚀 Bicep Microsoft Entra (Graph) Extension is GA!
You can now deploy & manage Entra (Azure AD) resources natively in Bicep.
See my blog for details + example:
🔗 mmachniak.net/2025/08/01/B...

#Azure #Bicep #MicrosoftEntra #IaC #CloudAutomation #AzOps #PowerShell #Microsoft
Bicep Microsoft Entra (Graph) Extension - GA
The Microsoft Entra (Graph) Bicep Extension allows you to provision and manage Microsoft Entra ID (formerly Azure AD) resources using Bicep, extending Infrastructure as Code beyond Azure resources int...
mmachniak.net
August 1, 2025 at 5:12 AM
Loging into a Linux Server Connected to Azure Arc Using Entra ID from the Portal & OpenSSH client
🔹 Azure Arc-connected Linux servers
🔹 Entra ID auth
🔹 Secure access via Portal & SSH
Read 👉 mmachniak.net/2025/07/30/A...
#AzureArc #Linux #EntraID #Azure #Security #AzOps #Microsoft
Loging into a Linux Server Connected to Azure Arc Using Entra ID from portal and OpenSSH client
Azure Arc extends the power of Azure to your on-premises and multi-cloud environments. One great feature it enables is logging into Linux servers using Entra ID (formerly Azure AD). This provides cent...
mmachniak.net
July 30, 2025 at 7:06 AM
#Azure Resource Manager allow to overview all resources and create k-ql query

#Microsoft #Azure #AzOps #kql #monitoring #logs
July 22, 2025 at 7:42 AM
🚀 #PowerShell script to automate #Azure #DevOps user cleanup:
✅ Email inactive & never-logged-in users
📊 Console & email reports
📁 Logs to Table Storage
🗑️ Auto-remove
#Microsoft #AzOps #Cloud
github.com/mimachniak/s...
sysopslife-scripts/ADO/ADO-Inactive-User-report.ps1 at master · mimachniak/sysopslife-scripts
Contribute to mimachniak/sysopslife-scripts development by creating an account on GitHub.
github.com
July 16, 2025 at 6:47 PM
🎉 STAGED ROLLOUT OF CLOUD AUTHENTICATION 🎉

This feature allows you to test cloud authentication and migrate gradually from federated authentication to other. #Azure #M365 #AzOps #EntraID #Secuirty #Microsoft #Idenity
July 1, 2025 at 3:20 PM
😮 By default, #Azure blocks outbound traffic on port 25 (SMTP) for new #VM
⁉️ PowerShell (Test-NetConnection), you will failed without any information
⁉️ Azure Network Watcher, your test may show error but in details all will be green ✅ in the Connection Troubleshoot tool
#Security #Microsoft #AzOps
June 27, 2025 at 5:51 AM
Bookable time is available in #outlook in GA , wow, team members can come to the Bookings page and book time for a 1:1 meeting without any back-and-forth conversation #Microsoft #M365 #meeting
April 26, 2025 at 9:57 AM
🔧 Just released a handy #PowerShell script for generating #Azure #cost reports with aggregation!
It pulls cost data from Azure and lets you group and export it to #Excel
💡 Aggregations supported:
Subscription, RG, ResourceType, #Tags
⁉️It support: CSP
#Microsoft #AzOps
github.com/mimachniak/s...
sysopslife-scripts/Azure/Azure-Cost-Export-API-v5.ps1 at master · mimachniak/sysopslife-scripts
Contribute to mimachniak/sysopslife-scripts development by creating an account on GitHub.
github.com
April 10, 2025 at 6:39 AM
💰 #Azure #DevOps Basic usage included with #GitHub Enterprise

Finally price get lower, now we need AzureDevOps basic to allow use Github !!

devblogs.microsoft.com/devops/azure...

#AzOps #Microsoft #Azure #cost
Azure DevOps Basic usage included with GitHub Enterprise - Azure DevOps Blog
Many customers want to use both GitHub and Azure DevOps together. Until now, unless you purchased Visual Studio subscriptions with GitHub Enterprise, you had to pay separately for both products. With ...
devblogs.microsoft.com
March 11, 2025 at 7:45 AM
👑Export to #bicep using #Azure Portal is live !!!

⬇️⬇️⬇️⬇️⬇️

We can now export from portal to bicep code existing resources !!!

#Microsoft #Azure #AzOps #DevOps #IaaC #automation
March 6, 2025 at 11:17 AM
⚙️ AzureDay Poland 2025 ! Już się zbliża !!!

📅 Kiedy? 13 marca 2025
📍 Gdzie? Warszawa, Airport Hotel Okęcie

🗺️Link: azureday.pl

💰Promo code: AzureDay2025Speaker

#AzureDayPoland #MicrosoftAzure #Implementation #CloudSolutions #AzureDayPoland #AzureDay2025 #AzOps #Microsoft
March 3, 2025 at 8:29 AM
Enhancing #Azure #DevOps Traceability: Tracking Pipeline-Driven Resource Changes ad tags to you deployment to get better traceability between pipeline executions and modifications

#Microsoft #security #AzOps #MCTbuzz #automation #AzureDevOps

github.com/jvargh/azure...
github.com
February 12, 2025 at 8:54 AM
Did you know that #Windows 2025 have built in OS security configuration base on #Microsoft Security baseline

#Ops #Security #AzOps

learn.microsoft.com/en-us/window...
Configure security baselines for Windows Server 2025
Learn how to deploy security baselines using OSConfig to enforce granular security settings to better protect and harden your Windows Server 2025 environment.
learn.microsoft.com
February 12, 2025 at 7:39 AM
🎉 Great News !!! 🎉
#PowerShell DSC v.3.0 is now on release cadidate
#Microsoft #Azure #AzOps #DevOps #dsc #cloud #atomation

github.com/PowerShell/D...
February 9, 2025 at 4:19 PM
#Azure Advisor Workbooks have new work books to help gether and review information specialy one will be very helpfull
👉 Services Retirement - This workbook displays #Azure services that are being phased out, allowing you to mitigate affected resources
#Microsoft #AzOps #Cloud
February 8, 2025 at 6:21 AM