Press "Enter" to skip to content

Day: September 28, 2026

Operational Blind Spots in SQL Server Security

Fabiano Amorim offers some advice:

The SQL Server attack pattern is consistent: attackers do not always need a spectacular vulnerability. They often succeed by chaining normal features that were granted too broadly, trusted too much, or monitored too narrowly. 

In this article, I’ll focus on operational blind spots in SQL Server. These are the features DBAs use every day to keep SQL Server healthy: linked servers, traces, Dynamic Management Views, Extended Events, and session-management commands such as KILL.

These tools, while necessary, also create visibility, automation, and trust paths that attackers can abuse after compromising a low-privileged application account or a local database owner. 

Because of this, a SQL Server DBA should know the answer to the following questions at all times: where am I exposed, what should I monitor, and what should I change first? In this article, you’ll learn the answers to all three.

Click through for the advice.

Leave a Comment

Users, Licenses, and Guest Access in Microsoft Fabric

Paul Turley manages a tenant:

Fabric doesn’t have its own separate licensing screen — you assign every license, Fabric included, from the Microsoft 365 admin center, the same place you’d manage Exchange or Teams. Easy to miss if you came into this world through the Fabric admin portal. Save yourself a search: bookmark the Microsoft 365 admin center alongside the Fabric admin portal, since you’ll need both within your first week.

Click through for some more tips and tricks around user management in Microsoft Fabric.

Leave a Comment

Building Business versus Data Apps in Microsoft Fabric

Soheil Bakhshi builds an app:

While building that application, I came across a few gotchas and limitations around its architecture. But there is also another Fabric Apps pattern that takes a quite different approach. Instead of creating an operational database, it uses the relationships, measures and business logic we already have in a Power BI semantic model.

Microsoft calls this the Data App template. In this article, I compare it with the operational pattern from my previous exercise, which I refer to as a Business App. They both run on Fabric Apps, but what happens underneath is different. Their security requirements, sharing model and licensing are different too. So, let’s go through what I tested, what caught me out, and where I think each pattern makes sense.

Read on to learn more.

Leave a Comment