Enforcing Pod Security on AKS with Azure Policy and OPA Gatekeeper

Detecting insecure pods on Azure Kubernetes Service is not the same as preventing them. Here is how Azure Policy and OPA Gatekeeper move enforcement to admission time, so a misconfigured workload never reaches the cluster.

June 13, 2026 · 3 min · Yogesh Thanvi

From ITAF to Azure Controls: Operationalizing an IT Audit Framework on Microsoft Cloud

An audit framework tells you what to assure. It does not tell you how to enforce it in a live cloud. Here is how I map the IT Audit Framework onto concrete Azure controls, Azure Policy, Defender for Cloud, and Purview, so assurance objectives become running enforcement instead of a spreadsheet.

June 13, 2026 · 4 min · Yogesh Thanvi

Mapping CSPM to Microsoft Defender for Cloud: From Findings to Enforcement

Defender for Cloud is excellent at telling you what is misconfigured. A finding is not a fix. Here is how I turn cloud security posture management on Azure from a dashboard of alerts into enforcement that blocks and remediates, using Azure Policy deny effects and admission-time control on AKS.

June 13, 2026 · 4 min · Yogesh Thanvi

Securing Agentic AI on Azure: Guardrails for Azure OpenAI and AI Foundry Agents

An AI agent that can call tools and take actions is not a chatbot. It is a new identity and a new attack surface. Here are the guardrails I would put around agentic workloads on Azure OpenAI and AI Foundry, built from the same principle I apply everywhere: enforce at the point every request passes through.

June 13, 2026 · 4 min · Yogesh Thanvi

Securing AI Workloads on Azure: Governance Patterns for Azure OpenAI and AI Foundry

Generative AI on Azure introduces control points that traditional application security never had to handle. Here are practical governance patterns for Azure OpenAI and AI Foundry workloads, mapped to where the real risks live.

June 13, 2026 · 4 min · Yogesh Thanvi