Skip to main content
Falstech.
Field notes

Short reads from inside real Microsoft cloud environments.

Technical field notes on the architecture, governance, cost, and identity problems Falstech focuses on.

8 min read

How to stage a Conditional Access rollout without locking out the team

A staged rollout framework for report-only evidence, workload identities, emergency access, pilot criteria, and rollback.

Read it
6 min read

Five common Azure cost leaks in mid-market environments

Idle resources, oversized SKUs, forgotten dev environments — and the policy patterns that plug them.

Read it
8 min read

Microsoft 365 + Entra: a practical day-one governance baseline

Conditional access, named locations, emergency access, and review questions for a context-dependent baseline.

Read it
5 min read

When your MSP isn't enough: signs you need a fractional cloud engineer

Three signs that ticket-based support may not resolve the underlying architecture problem.

Read it
5 min read

What must be decided before a cloud modernization project can move

A modernization project needs explicit decisions about business constraints, dependencies, target architecture, migration sequence, rollback, ownership, and acceptance criteria before execution can proceed with controlled risk.

Read it
6 min read

When to centralize Azure Log Analytics—and when not to

A practical point of view on Azure Log Analytics workspace design. The article explains why one workspace is a useful starting point, then shows when tenancy, access, region, data residency, retention, ownership, billing, cost, or resilience requirements justify separation.

Read it
5 min read

Azure Policy: moving from audit findings to safe enforcement

A staged decision path from inventory and exemptions through remediation, testing, and controlled enforcement — and why an incomplete evidence base is a reason to stay in audit.

Read it