Skip to content
CAMPUX
Field notes

One Azure idea at a time.

Short, honest write-ups of the ideas that come up in interviews and on the job. Each one teaches the concept properly, cites the Microsoft documentation, and points back to the class that drills it until it sticks.

Filter Latest Governance 14 Careers 134 AI 14 Cost 15 Networking 18 Identity 16 Migration 37 Databases 7 IaC 7 Certifications 1 Fundamentals 14 Storage 12 Compute 30 CI/CD 15 Security 17 Observability 5
Identity · Conditional Access MFA

Enforcing MFA with Conditional Access in Entra ID

By Captain O

Break-glass accounts first, then the canonical require-MFA policy, report-only mode before enforcement, and blocking legacy authentication. The rollout order that gets you to enforced MFA without the lockout story.

Read more
20 min readClass 8
Cross-cloud · identity & access

Entra ID + Azure RBAC vs AWS IAM vs GCP Cloud IAM

By Captain O

Azure splits identity from authorization; AWS IAM fuses both and hands you JSON policy; GCP binds roles to members on a resource. Same three letters, three genuinely different architectures — the biggest place the analogy leaks.

Read more
12 min readClass 9
Identity · Best practices

Privileged Identity Management (PIM), done right

By Captain O

Standing admin access is the risk. PIM makes privilege eligible, time-bound, and approved. Eligibility, activation controls, access reviews, and why to keep very few Global Admins.

Identity · How-to

Block legacy authentication in Entra ID

By Captain O

Legacy auth bypasses MFA entirely. Find it in the sign-in logs, block it with a Conditional Access policy, migrate the printers and service accounts that break. The other half of MFA.

Identity · Best practices

Azure MFA best practices that actually change your risk

By Captain O

Turning MFA on is step one. Enforce with Conditional Access, require phishing-resistant methods over SMS, block legacy auth, number matching, monitored break-glass. The handful that matter.

Identity · Explainer

App registration client secret alternatives, ranked

By Captain O

A client secret is a password that leaks and expires. Replace it: managed identity inside Azure, workload identity federation for external callers, a certificate only as a last resort.

Azure · Identity · Hybrid sign-in

What is Azure AD (Entra) pass-through authentication?

By Captain O

Pass-through Authentication (PTA) validates a user's password against your on-prem Active Directory via a lightweight agent — the password never lands in the cloud. Here's PTA vs Password Hash Sync vs federation, the agent, the tradeoffs, and how to actually choose.

Read more
17 min readClass 7
The Dispatch · No. LVII · delivered by email

Get new field notes as they ship.

One short, honest Azure note at a time — plus the occasional hiring signal. No spam, no card, unsubscribe in one click.