Slider 1 mini Slider 2 mini

Sunday, 26 July 2026

Filled under:

 Hi [Name],

The Tanium request for the lower environment is currently in progress, with the latest comment stating “A placeholder.”

Could you please clarify what this refers to and confirm the expected implementation timeline? If any additional information or action is required from our side, please let us know.

Thanks,
Nikhil

Posted By Nikhil02:02

Thursday, 23 July 2026

Filled under:

 

Emerging DB:
ITD SharePoint and Confluence Migration: Completed the migration of Emerging DB documentation from the existing SharePoint location to the secure ITD SharePoint repository. Confluence content has also been reviewed, classified, and copied to ITD. Following final validation, the original Confluence content will be removed to avoid duplication. This improves documentation governance, security, and controlled access across the portfolio.

Posted By Nikhil23:04
Filled under:

 

These items can be added to the release notes in the same format:

Platform Work Category Feature Key Value
Azure Cosmos DB Enabler Enhanced provisioning and governance controls Enhanced provisioning and governance controls have been implemented for serverless deployments, public endpoints, administrative access, resource tagging, and seven-day continuous backup configurations. These controls strengthen compliance and ensure that resources are provisioned according to approved platform standards.
Azure Managed Redis Enabler Policy update to enable Redis provisioning The Deny-Redis-Create policy effect has been changed from Deny to Audit. This enables users to provision Azure Managed Redis instances while retaining visibility and governance through policy compliance monitoring.
MongoDB vCore Enabler Automated role assignment and TPAC enablement in Red Zone Automated role assignment has been enhanced through the Red Zone Function App, enabling TPAC access for MongoDB vCore in the Red Zone. This provides authorized users with controlled and compliant access through the automated provisioning process.

For the first row, Azure Cosmos DB appears to be the applicable platform based on the serverless and continuous-backup controls.

Posted By Nikhil01:19

Wednesday, 22 July 2026

Filled under:

 

Database Scanning – Account Creation

Created a dedicated six-month sub-epic to design a secure and scalable database-access approach for increased scanning volumes across Emerging DB platforms. The work will assess the feasibility of a read-only scanning account and review the existing account-ordering process to improve reliability while maintaining ACS compliance.

Posted By Nikhil22:00
Filled under:

 

Database Product Adoption – Emerging DB

  • Completed MongoBleed vulnerability remediation across all supported native MongoDB DBaaS instances.
  • Completed the native MongoDB version-upgrade assessment and successfully tested patching in the development environment. Further rollout is pending application feedback on decommission plans.
  • Conducted enablement sessions for MongoDB users covering cost, platform overview, the Cyclops case study and practical comparisons between native MongoDB and Azure Cosmos DB for MongoDB (vCore).
  • Completed the initial Azure Managed Redis adoption analysis and progressed cost comparisons to identify potential savings and support migration from Redis before its planned retirement.
  • Conducted targeted one-to-one sessions with application teams to explain the cost and operational benefits of moving to Azure Cosmos DB for MongoDB (vCore).

Q3 focus: Finalize the native MongoDB decommission and patching approach, progress Azure Managed Redis migration opportunities, and continue application-specific adoption discussions for Azure Cosmos DB for MongoDB (vCore).

Posted By Nikhil21:53
Filled under:

 

Database Risk Engineering & Control Framework – Emerging DB

  • Strengthened security and compliance controls across Cosmos DB, Redis/AMR and DocumentDB through TLS 1.2 enforcement, Entra ID-based access, access-key restrictions and audit-to-deny policy updates.
  • Updated Cosmos DB ICC evidence and progressed privileged-access controls for controlled and monitored database access through CyberArk.
  • Introduced lower-environment governance policies covering autoscale restrictions, low-cost AMR SKUs and HA configuration auditing to support risk reduction and cost optimisation.
  • Rolled over to Q3: BigID scanning remediation, remaining HA audit-policy coverage for Redis, Cosmos DB and DocumentDB, and completion of the Azure Redis Cache deny-policy readiness checks.
  • The central CMK Key Vault removal and Cosmos NoSQL MIM-group enablement were initiated toward the end of Q2 and completed in early Q3.

Note: Unlike Q3, Q2 did not have a dedicated Cost Optimisation epic. Cost-related policy items were therefore included and tracked under the Risk Engineering & Control Framework epic from the outset.

Posted By Nikhil21:25
Filled under:

 

Based on this context, the summary should focus on the completed decommissioning and closure, rather than only the application engagement activities.

MongoDB Migration/Decommission – UBS Estate

  • Completed the exit of the Database crew-managed native MongoDB estate from the CS environment, in coordination with application and business stakeholders.
  • Created all required RFCs and completed the agreed closure activities, including the retirement of MongoDB-related tooling and supporting utilities.
  • The decommissioning removed the remaining infrastructure and tooling footprint, reducing associated operational and licensing costs.

The epic was closed in Q2 and is not carried over to Q3.

Posted By Nikhil07:32