
Zürich, Switzerland · on Azure since 2019
I build Azure infrastructure that survives production.
This is where I write down what happened after the deployment — the patterns that held up, the things that broke, and the tools I built along the way.

- RoleCloud Engineer, enterprise Azure
- CertifiedAZ-104 · GPCS
- FocusIaC · Identity · Governance
- Status● Open to chat
Latest article
Fresh out of production.
169.254.169.254: The Cloud Metadata Endpoint
Read article →: 169.254.169.254: The Cloud Metadata EndpointManaged Identity solves credential storage problems. It does not eliminate identity abuse. Managed Identity is one of those Azure features almost everyone recommends — and honestly, for good reason. No secrets in…
From the blog
Recently written.


Stop letting your AI guess Azure RBAC
azure-rbac-advisor — a prompt skill that researches least-privilege RBAC for your IaC and doesn’t make up permission strings.* How this started This didn’t start with an…aiazuresecurity
App Lifecycle Analysis for Entra ID
Every large Entra tenant has the same problem: hundreds of app registrations, most of them forgotten. Here’s a tool to find them and act on what…complianceentraidprojectsWhat I work on
Six things I go deep on.
Not one hub per tag — these are the areas where the writing actually stacks up into something you can work through.
Terraform & IaC on Azure
Modules, state, secrets and the file layout that survives a second engineer. Terraform first, ARM and Bicep where they still win.Entra ID & Least Privilege
Almost every Azure environment grants more than it can justify, because Contributor was faster than reading the role definitions. This is about getting the permissions right and keeping them right.Azure Automation & PowerShell
Work that should not need a human: runbooks, Logic Apps, Functions and the scripts that make a request turn into a machine.Azure Governance & Compliance
Proving the tenant is in the state you claim it is: policy, logging, agents and the audits that find what nobody deployed on purpose.Azure Landing Zones
Structure a subscription estate before it structures itself: management groups, network design and the platform decisions that are expensive to reverse.Azure Cost Optimization
Machines that switch themselves off, and the spend nobody signed off on. Mostly tagging, schedules and the gap between stopped and deallocated.Things I build
Tools & projects.
TenantThrift
● LiveProductFinds the Azure spend nobody signed off on — idle, oversized and orphaned resources, each with a euro amount and a guided fix.

Least Privilege Studio
● LiveFreePick the actions you need for Azure RBAC or Entra ID and get the narrowest roles that cover them — or just paste in your Terraform.

Plus 3 scanners and 4 blueprints, and three Claude Code skills. See all tools →
About me
Cloud engineer in Zürich. Most of what’s here came from problems I had to solve at work.
Where the documentation ran out and I had to figure things out the hard way. If something here saved you a few hours, that’s the whole point.
