<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Cyphora.io</title>
    <link>https://cyphora.io</link>
    <description>Azure and Microsoft security operations insights.</description>
    <language>en</language>
    <atom:link href="https://cyphora.io/rss.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Microsoft Foundry Logging: Entra ID Diagnostic Settings and the Identity Plane</title>
      <link>https://cyphora.io/blog/microsoft-foundry/microsoft-foundry-entra-id-agent-identity-logging/</link>
      <guid isPermaLink="true">https://cyphora.io/blog/microsoft-foundry/microsoft-foundry-entra-id-agent-identity-logging/</guid>
      <description>Entra ID diagnostic settings are the foundation for AI Foundry agent logging, not a nice-to-have and not replaceable by Advanced Hunting tables. This post covers what to configure, what each table delivers for security operations, how to correlate identity plane data with Foundry resource logs, and includes KQL detection queries for agentic sign-in activity, agent identity lifecycle events, and cross-table correlation patterns.</description>
      <pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Microsoft Foundry Logging: Control Plane, Data Plane, and Application Insights</title>
      <link>https://cyphora.io/blog/microsoft-foundry/microsoft-foundry-logging-overview/</link>
      <guid isPermaLink="true">https://cyphora.io/blog/microsoft-foundry/microsoft-foundry-logging-overview/</guid>
      <description>A breakdown of every logging layer available in Microsoft Foundry: what each captures, which sources security operations teams need to enable, and why the routing decisions matter before anything goes to production.</description>
      <pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>