Year-end 2023: AI, identity, and hybrid lessons
2023 year-end: Azure OpenAI landings, Copilot permissions reality, Storm-0558, MOVEit, Entra rename, and funded priorities for the next year.
NotesArchive
Microsoft infrastructure, migrations, identity, VDI, Azure, and security — written as we ran the work (2016–2023). Current practice lives on the main notes page.
// 96 posts across 8 years · pick a year above or scroll the full archive.
2023 year-end: Azure OpenAI landings, Copilot permissions reality, Storm-0558, MOVEit, Entra rename, and funded priorities for the next year.
Microsoft Secure Future Initiative 2023: engineering culture signals, customer logging expectations, identity hardening, and questions for your QBR.
Microsoft 365 Copilot readiness 2023: oversharing cleanup, labels, pilot cohorts, network, and why buying seats before ACL hygiene is backwards.
Microsoft Entra ID 2023 rename field notes: portal labels, Conditional Access, app registrations, and identity ops discipline under a new brand.
MOVEit Cl0p 2023 lessons: file transfer surfaces, vendor inventory, isolation, and how Microsoft estates still get burned by non-Microsoft edges.
Storm-0558 July 2023 field notes: consumer key abuse, mailbox access lessons, logging gaps, and what customer tenants should verify and demand.
AVD FinOps 2023: host pool unit economics, autoscale pitfalls, reservations, FSLogix storage cost, and chargeback that changes behavior.
Phishing-resistant MFA 2023: number matching is not enough, FIDO2 and WHfB for admins, legacy exceptions, and measuring authentication strength coverage.
Data governance for AI 2023: labeling, DLP, retention, dataset inventories, and readiness work before Copilot or Azure OpenAI touch sensitive corpora.
Microsoft 365 Copilot March 2023 field read: permissions are the product, SharePoint hygiene, DLP, pilot design, and why oversharing becomes an AI incident.
Azure OpenAI Service 2023 landing: subscriptions, private networking, logging, abuse monitoring questions, RBAC, and a responsible first workload.
Enterprise generative AI January 2023: shadow usage, approved Azure OpenAI paths, data boundaries, and pilot metrics that survive the board.
2022 year-end lessons: passwordless progress, AVD vs Citrix honesty, landing zones, token theft, and the generative AI governance wake-up.
ChatGPT November 2022 IT response: data leakage policy, approved tools, shadow AI, and a sober 90-day plan before the hype cycle eats governance.
Token theft defenses 2022: CA continuous access, device compliance, admin protection, legacy auth, and detection when cookies and tokens walk away.
Azure Arc 2022 field notes: servers, Kubernetes, policy at scale, and when Arc is platform leverage versus dashboard sprawl.
Microsoft Purview 2022 field guide: information protection, DLP, retention, eDiscovery — what to configure first without boiling the ocean.
Exchange hybrid residual risk 2022: last servers, internet publish, CU discipline, and why “temporary hybrid” remains a security program.
Windows 11 enterprise deployment 2022: hardware blocks, app compat, Autopilot, VDI images, and why rings still beat big-bang OS flips.
Conditional Access hardening 2022: authentication strengths, legacy auth zero, device filters, continuous access evaluation, and VIP-safe rollout rings.
Azure Virtual Desktop vs Citrix 2022 decision matrix: multi-session Windows, FSLogix, HDX needs, cost models, and when hybrid brokers still win.
Azure landing zones 2022: management groups, platform vs app landing, policy, connectivity, and how mid-market avoids CAF cargo-cult while staying governable.
Hybrid work networking 2022: forced-tunnel debt, Teams media, split tunnel permanence, Secure Web Gateway conflicts, and measuring quality after the emergency.
Passwordless FIDO2 enterprise rollout field notes: Conditional Access, Windows Hello, security keys, break-glass, and phishing-resistant MFA without locking out the business.
2021 hybrid cloud lessons: ProxyLogon urgency, AVD rename, SfB Online end, Zero Trust basics, and what Microsoft estates should fund in the year ahead.
Exchange Online security after ProxyLogon year: reduce on-prem surface, MFA, legacy auth, external forwarding, and hybrid server hardening.
Azure landing zone mid-market minimum: management groups, identity, network hub, policy, and FinOps without enterprise bureaucracy theater.
Windows 11 VDI and Azure Virtual Desktop testing: hardware readiness, image strategy, FSLogix, and when not to rush multi-session estates.
Zero Trust practical steps on Azure AD and Microsoft 365: identity first, legacy auth, device trust, admin tiering — without boiling the ocean.
Skype for Business Online retirement aftermath: residual tickets, hybrid leftovers, rooms still broken, and closing the Teams migration properly.
Azure Virtual Desktop rename and AVD vs WVD: from XenDesktop and RDS through WVD preview and GA to AVD — lessons from a decade of desktop delivery.
Skype for Business Online end of life checklist: 90 days to July 31, 2021 — voice stragglers, rooms, contact centers, assisted upgrade, if you do nothing.
SCVMM to Azure skills map: clouds and host groups to subscriptions, templates to ARM/Bicep, orchestration to Automation — what transfers and what to unlearn.
HAFNIUM Exchange vulnerability and ProxyLogon response: patch vs mitigate vs isolate, IOC hunting, why hybrid-minimal paid off, the last-server conversation.
Zero data loss migration architecture for multi-domain Office 365: inventory as contract, delta-sync cutovers, verification, chain-of-custody for government.
Cloud migration cost savings analysis: five years of programs — hardware avoidance, licensing, DR, ops hours — and where costs move instead of vanish.
Solorigate response, week one: what the SolarWinds supply chain attack means for ADFS token-signing certs, federation trust, and what we audited across client estates.
Azure AD Connect monitoring, PTA agent redundancy, and staging servers: how we run hybrid identity health as a tier-0 service after this year's 3 a.m. lessons.
Exchange 2010 end of life arrived October 13. A post-mortem on why estates lag — app dependencies, relay sprawl, budget cycles — and what the late migrations taught us.
The Exchange 2010 October 2020 deadline is four weeks out. Our last-call triage: minimal hybrid express paths, what unsupported means, and compliance.
Conditional Access best practices Azure AD: named locations, device compliance, break-glass accounts, report-only mode, and the legacy-auth kill switch.
WVD spring update ARM and Windows Virtual Desktop 2020: Azure portal objects, RBAC, autoscale improvements, migration from classic fall-2019 deployment.
FSLogix best practices and profile container tuning: sizing, Azure Files vs file servers, Outlook cache, exclusions, and the profile-load metric we watch.
Split tunnel VPN Office 365 and Teams: forced tunnel failure under media load, implement optimize paths, latency wins, security objections answered.
Microsoft Teams governance rollout under surge: pilot to company-wide in two weeks, sprawl control, external access, meeting hygiene, deliberate deferrals.
Remote work infrastructure COVID surge: VPN at 4x load, emergency WVD and Citrix capacity, prioritizing critical workers, decisions in 72 hours.
WVD host pool sizing and Windows Virtual Desktop cost field notes: users-per-vCPU by workload, load balancing, autoscale, and telemetry over vendor ratios.
CVE-2019-19781 Citrix ADC mitigation field notes: what we ran on internet-facing NetScaler gateways, indicator sweeps, and trusting an appliance mid-crisis.
Migration project best practices from a decade of mail, directory, desktop, and datacenter moves: ten rules on pilots, rollback, comms, and cutovers.
Microsoft Ignite 2019 takeaways for Microsoft-shop CIOs: Arc, Edge Chromium, Teams momentum, and hybrid as strategy for 2020 planning.
Basic authentication deprecation Exchange Online: discovering legacy clients, ActiveSync fleets, service accounts, and staged modern auth enforcement.
Windows Virtual Desktop GA deployment field notes: host pool sizing, image management, FSLogix in production, and cost model vs on-prem VDI.
Windows 7 end of life plan and ESU field notes: five months out, app-compat blockers, VDI containment, and network isolation for stragglers.
Skype for Business Online retirement and Teams migration plan: coexistence modes, meeting-first moves, and why voice is the long pole.
VDI high availability design field notes: where the nines are lost, N+1 pool math, user-experience monitoring, and the SLA post-mortem habit.
Azure Site Recovery Hyper-V and DR testing field notes: recovery plans as code, real RTO measurements, and cost versus a second datacenter.
SCOM alert tuning field notes from a 400-server Hyper-V estate: management pack overrides, maintenance mode automation, and the 20 alerts that matter.
Windows Virtual Desktop preview setup notes from week one: tenant and host pool model, Windows 10 multi-session behavior, FSLogix, and the gaps vs Citrix.
A G Suite to Office 365 migration field guide: Gmail and calendar fidelity, Drive to OneDrive mapping, the Sites and Forms gaps, and coexistence that works.
Exchange 2010 end of support lands January 14, 2020. A field-tested triage matrix for the migration: hybrid to Office 365, Exchange 2016, or decommission.
Tenant to tenant migration Office 365 and M&A IT integration: domain cutover sequencing, mail flow, BitTitan vs bodies, and identity re-homing.
FSLogix acquisition Microsoft field notes: why VDI profiles break, what profile containers fix versus UPD and roaming, and what it means for WVD.
Exchange 2019 vs Office 365 decision field notes: who still needs on-prem Exchange, Windows Server 2019 S2D, and the hybrid-minimal vs cloud-first fork.
Windows Virtual Desktop announcement 2018 field notes: multi-session Windows 10, licensing entitlement, and what it means for Citrix and RDS estates.
SCCM 2007 to Current Branch migration field notes: side-by-side hierarchy, client reassignment waves, package-to-application conversion, and boundary redesign.
How to reduce infrastructure costs with cloud migration, honestly itemized: retired Exchange and SharePoint farms, storage tiers, DR simplification — and what never shrinks.
Cutover vs hybrid migration for Office 365, decided by mailbox count, directory state, and coexistence needs — with real timelines from 500, 4,000, and 15,000 seats.
RDS 2012 R2 deployment with App-V is the unfashionable VDI that works: session host economics, packaging discipline, broker HA, and when Citrix earns its premium.
GDPR enforcement is five weeks out. A practitioner's checklist for Office 365 compliance: data residency, retention vs deletion, DSRs, and what the processor agreement covers.
Field notes from a Windows 10 migration with SCCM: in-place upgrade vs wipe-and-load, driver management, USMT, and task sequences that survive reality.
GPO cleanup consolidation and DFS namespace migration field notes: rationalizing 900 policies, DHCP failover cutover, and the plumbing between org charts.
Field notes, two weeks into Meltdown and Spectre: the antivirus registry gate, enabling Windows Server mitigations, and the hit to Hyper-V performance and density math.
Field notes on running an azure migration assessment before you commit to lift and shift sizing: measured load, right-sizing down, and what should stay put.
vSphere replication disaster recovery, field notes: honest RPO/RTO tiers, stretch vs re-IP, and the DR runbook that has to actually fail over.
Azure AD PTA reached general availability at Ignite. Our pass-through authentication vs ADFS decision tree for the multi-domain federation farms we operate.
Microsoft says Teams is replacing Skype for Business. What Ignite 2017 actually announced, what it means for SfB estates, and the migration math we run.
Why XenDesktop 7.15 LTSR is our standard Citrix VDI architecture for 10,000-user estates: MCS vs PVS, NetScaler HA, and profile strategy that holds.
Field notes on Active Directory forest consolidation: target forest design, trust topology, SID history, and ADMT migration phases from a real program.
A field-tested BitTitan MigrationWiz review vs native hybrid moves: which Office 365 migration tools win by scenario, with throughput and licensing math.
Field notes from the WannaCry weekend: MS17-010 patch management, SMBv1 eradication, and SCCM emergency deployment rings across a 700-server estate.
Lotus Notes to Office 365 migration field notes: NSF mail and calendar fidelity, Domino directory sync, coexistence, and triaging Notes applications.
Microsoft Teams vs Skype for Business in 2017: what Teams can and cannot do at GA, and what we tell clients running SfB 2015 estates to actually do.
Exchange hybrid configuration in the field: HCW quirks, autodiscover priority, why free/busy stops working, mail flow choices, and public folder access.
Field notes from a SharePoint 2010 to 2013 migration: database attach upgrade order, Test-SPContentDatabase triage, claims conversion, deferred site upgrades.
Lessons from a Hyper-V P2V migration program spanning 400+ servers: candidate triage, where the utilization gains came from, cluster sizing, and the refusals.
System Center 2016 upgrade field notes: sequencing SCVMM 2016, SCOM, and SCCM Current Branch from 2012 R2, coexistence gotchas, and what broke in our lab.
Windows Server 2016 GA field notes: Hyper-V 2016 features, Storage Spaces Direct, shielded VMs, and nested virtualization judged against a 400-server private cloud.
Skype for Business 2015 architecture field notes: front-end pool design, edge topology, SIP domain isolation, and load testing a multi-tenant platform.
Field notes on ADFS 3.0 federated authentication for Office 365: WAP proxies, certificate rollover, UPN suffix cleanup, and multi-domain federation.
Field notes from an Office 365 migration assessment: sizing a 15,000-mailbox Exchange 2010 estate, egress math, ADFS mapping, and why discovery wins.
Office 365 tenant readiness checklist: domains, identity, licensing, networking, and governance gates before a 15,000-mailbox migration assessment.
Hyper-V 2012 R2 cluster field notes: storage, networking, CSV, patching cadence, and build standards before Server 2016 private cloud work.
SharePoint 2010 farm health before migration: content DB inventory, customization debt, auth mode, and what blocks a clean 2013 or cloud path.
Skype for Business 2015 architecture decisions: topology, edge, HA, capacity for enterprise estates before multi-tenant complexity.
Azure AD Connect hybrid identity field notes: DirSync legacy, UPN cleanup, filtering, staging mode, and why identity leads every Office 365 program.
Exchange 2010 capacity planning field notes: mailbox growth, DAG reality, SAN pressure, and why you measure before any Office 365 pitch.