Replace expiring client secrets in GitHub Actions with Workload Identity Federation. This walkthrough sets up an Entra ID App Registration, scoped federated credentials, and a clean azure/login step so your pipelines authenticate to Azure with short lived OIDC tokens.
Azure
Entra ID PIM Role Activations with PowerShell
Skip the Entra admin portal clicks for routine maintenance windows. This walkthrough shows how to list, activate, and deactivate PIM role assignments in PowerShell with the Microsoft Graph SDK, including a batch helper for change tickets.
Leveraging AGENTS.md for smarter prompting
AGENTS.md is more than a cross-tool fallback config. Structured well for your Azure and Microsoft 365 environment, it eliminates the repetitive context you type at the start of every session and makes every prompt shorter and more precise.
Azure infrastructure with Bicep and GitHub Actions
Introduction ARM templates have long been the go-to for declarative Azure infrastructure, but their verbose JSON syntax makes them painful to read and maintain. Bicep is Microsoft's answer: a cleaner domain-specific language that compiles down to ARM JSON. Pair it...
Automated Azure Alert Triage
Azure Monitor can generate hundreds of alerts per day in a busy environment — many of them repetitive, low-priority, or duplicates of each other. Feeding those alerts into Claude via a Logic App workflow lets you automatically triage them, group related issues, and...
Deploying Azure Landing Zones with Terraform and GitHub Actions
An Azure Landing Zone is the foundation of every well-governed cloud environment — it defines management groups, subscriptions, networking, policies, and RBAC in a consistent, repeatable way. Using Terraform alongside GitHub Actions gives you a fully automated,...
Bulk Managing SharePoint Online Permissions with PnP PowerShell
SharePoint Online permissions tend to accumulate over time — stale site memberships, over-privileged guest accounts, and broken inheritance chains create both compliance risk and confusion. PnP PowerShell gives you a concise, cross-site toolset for auditing and...
Deploying Azure Monitor Workbooks with Bicep
Azure Monitor Workbooks provide rich, interactive dashboards for operational data — but creating them manually through the portal means they live outside your deployment pipeline. By defining workbooks as Bicep resources you can version-control, peer-review, and...
Implementing Azure Policy as Code with GitHub Actions
Azure Policy is a powerful governance tool, but when policies are created manually through the portal they quickly become undocumented and inconsistent across environments. By storing policy definitions in a Git repository and deploying them through GitHub Actions,...
Managing Azure RBAC Assignments at Scale with PowerShell
As Azure environments grow, keeping role assignments consistent and compliant becomes a significant operational challenge. Drifted permissions, orphaned identities, and undocumented manual assignments all create security risk. Using PowerShell to audit and enforce...







