Debugging DNS Resolution in Tailscale Exit Nodes: A dnsmasq Configuration Guide

The Problem: Selective Network Outages Over Tailscale When users reported that database access through a Tailscale exit node was failing while RDP connections remained functional, the initial symptoms suggested a routing or firewall issue. However, the real culprit was much more subtle: DNS resolution was being silently dropped at the exit node level. Why This Setup Exists at All: Azure Private Link Resolves Differently Depending on Where You’re Standing Before getting into the dnsmasq “bug” itself, it’s worth explaining why this infrastructure exists in the first place, because the root problem isn’t Tailscale or dnsmasq, it’s that Azure Private Link’s DNS behavior is context-dependent, and a VPN mesh network doesn’t naturally live in any single context. ...

July 17, 2026 · 12 min · Me

Migrating from Per-User MFA to Conditional Access: A Strategic Approach

The Problem: Conflicting MFA Configurations When your organization has both per-user Multi-Factor Authentication (MFA) and Conditional Access (CA) policies enabled simultaneously, per-user MFA takes precedence. This creates a cascading problem: users face excessive MFA prompts, support tickets increase, and your security posture becomes difficult to audit and control centrally. In one organization with ~200 users on per-user MFA and ~400 users on CA policies, this conflict was creating unnecessary friction and made it difficult to implement granular access controls based on risk and resource sensitivity. ...

June 26, 2026 · 3 min · Me

How My Terraform GitHub Actions Pipeline Works

This documents how our Terraform CI/CD pipeline is set up in GitHub Actions: specifically the auth model, the state backend, the two-file workflow structure, and how I close the loop on post-merge apply results showing up on the PR that triggered them. The Two-File Workflow Structure The pipeline is split into two files: a thin caller and a reusable template. terraform.yml — the caller. It defines the triggers and hands off to the template: ...

May 29, 2026 · 7 min · Zac Lohrenz

Azure Key Vault: Migrating from Access Policies to RBAC Before the 2027 Deadline

Microsoft sent an email this week that caught my attention: all Azure Key Vault API versions prior to 2026-02-01 retire on February 27, 2027. The new API makes Azure RBAC the default access control model for Key Vaults, and legacy access policies become an explicit opt-in. Time to migrate before the deadline forces your hand. The Change: What Microsoft Is Actually Doing Starting with API version 2026-02-01 (releasing February 2026): ...

February 5, 2026 · 9 min · Zac Lohrenz

Azure SQL Private Endpoints: Why Your VPN Users Can't Connect (And What Actually Works)

We deployed an Azure VPN Gateway to give remote users secure access to Azure SQL databases through private endpoints. The setup looked textbook perfect: private endpoints approved and connected, VNet peering configured, routes in place, TCP connectivity verified. Everything worked except the one thing that mattered—users couldn’t authenticate. Here’s what we learned fighting Azure’s DNS architecture. The Setup That Should Have Worked Standard Azure private endpoint architecture for SQL Server: ...

December 12, 2025 · 7 min · Zac Lohrenz