New Latest article: There’s no built-in policy for Entra VM login →Hi, I’m Simon. I build Azure
infrastructure in production.
This is where I write it down — the patterns that held up, the things that broke, and the tools I built along the way. Documented after deployment, not before.
Azure
Terraform
PowerShell
Security
Automation
The Archive
Latest writing
There’s no built-in policy for Entra VM login
Read article →: There’s no built-in policy for Entra VM loginAzure ships a built-in policy to disable local accounts on your VMs. It ships none to enable the Entra login that makes disabling them survivable. Here’s how the pieces actually fit —…
Stop letting your AI guess Azure RBAC
azure-rbac-advisor — a prompt skill that researches least-privilege RBAC for your IaC and doesn’t make up permission strings.* How this started This didn’t start…
App Lifecycle Analysis for Entra ID
Every large Entra tenant has the same problem: hundreds of app registrations, most of them forgotten. Here’s a tool to find them and act…
Find the Azure Updates That Affect You, With Claude
A Claude Code skill that stops you reading retirement notices for services you don’t use. How this started Azure publishes a lot of updates.…
Automate Azure Golden Image Builds
One Bicep deploy. Monthly builds. No manual sysprep. How this started Back when I was still heavily working in the Azure Virtual Desktop space,…
The Privileged Role Exposures Defender Misses
A look at Tier Zero exposure paths that don’t show up in the obvious places — and a tool to find them. How this started…
Least Privilege Studio: An Azure RBAC Tool
If you’ve ever set up a service principal in Azure and thought “I’ll just use Contributor for now” — this is for you. It’s…
Things I build
Tools & projects
Products and free tools I build for the Azure community, plus smaller automations and scripts I’ve open-sourced along the way.
TenantThrift
Find the money Azure is quietly wasting. TenantThrift scans your tenant for idle, oversized, and orphaned resources — and turns them into savings findings with exact amounts, in a dashboard and as PDF reports.
- Connects in minutes — admin consent, nothing to deploy, no agents
- Read-only by design — Reader role, no exportable secrets
- EU-hosted in Frankfurt by a Swiss company
Least Privilege Studio
Find exactly the Azure RBAC permissions you need — nothing more. Browse, search, and combine roles based on real Azure data.
- App Lifecycle Analysis for Entra ID→
- Automate Azure Golden Image Builds→
- Automated Azure VM Power Management with a Tag-Driven Runbook→
- VM Power Management in Azure Using Tags, Runbooks, and a Custom GUI→
- Self Service VM & AVD Order via Web Form→
- Deallocate VM based on Activity Log→
Built with
The stack I write about
Microsoft Azure
// Cloud platform
Terraform
// HCL & modules
Bicep
// Native Azure IaC
PowerShell
// Scripts & tooling
Identity
// Entra ID & RBAC
Security
// Hardening & policy
Automation
// CI/CD & runbooks
Networking
// VNets & firewalls
About
Cloud engineer based in Zürich, Switzerland.
I work on enterprise-scale Azure infrastructure with a focus on automation, security, and Infrastructure as Code. Most of what I write here comes from problems I had to solve at work — where the documentation ran out and I had to figure things out the hard way.
If something here saved you a few hours, that’s the whole point.
Years on Azure
6+
Articles published
29
Primary stack
Azure · Terraform
Location
Zürich, CH
Status
● Open to chat
