Turn your real-world experience into part of the show.

Microsoft Security Podcast – Identity, Cloud & Enterprise Protection Episodes

Security within the Microsoft ecosystem is deeply integrated across identity, endpoints, cloud services, and data platforms. Security Talk focuses on understanding Microsoft security architecture as an interconnected system rather than isolated tools and dashboards.

In this category, we examine identity security using Entra ID, Conditional Access, and privileged access models, alongside Microsoft Defender, Purview, and security controls across Microsoft 365 and Azure. Episodes explore how attackers exploit misconfigurations, how security signals propagate across services, and why many security incidents stem from architectural assumptions rather than missing features.

Security Talk emphasizes why breaches happen, not just how to configure protection. We discuss threat models, attack paths, lateral movement, and the operational trade-offs between security, usability, and automation. Particular focus is given to identity-centric security, which has become the primary control plane for modern Microsoft environments.

This category is intended for security professionals, architects, and IT decision-makers who need to understand Microsoft security beyond checklists and best-practice documents. If you are responsible for protecting identities, data, and cloud workloads within Microsoft platforms, Security Talk provides clear, experience-based insight into building and maintaining resilient security architectures.
May 23, 2026

Secure-by-Design AI: Protecting MLOps in the Microsoft Cloud with Mar…

In this episode of the m365.fm podcast, Mirko Peters speaks with Microsoft MVP and cloud security expert Martin Dimovski about securing AI workloads and MLOps environments in Microsoft Cloud. The conversation focuses on why AI security must be treated as a core business requirement instead of an af…

Listen to the Episode
May 23, 2026

Inside Enterprise Security: AD Tiering & Privileged Access with Vikto…

In this episode of the m365.fm podcast, host Mirko Peters speaks with cybersecurity expert Viktor Hedberg about the importance of securing enterprise environments through Active Directory (AD) tiering and privileged access management.The discussion explores how attackers commonly target privile…

Listen to the Episode
May 18, 2026

AI Meets Security: A Conversation with Danilo Nogueira [Microsoft]

“AI Meets Security” is a deep-dive conversation between Mirko Peters and Microsoft Senior Product Manager Danilo Nogueira about how AI is reshaping enterprise security, governance, and compliance. The episode explains that the biggest challenge with Microsoft Copilot and AI adoption is not the tech…

Listen to the Episode
May 13, 2026

Protecting Microsoft Copilot with Purview, DLP & Insider Risk with Al…

In this episode of the M365.fm podcast, Microsoft MVP Alan Cox joins us to discuss how organizations can securely adopt Microsoft 365 Copilot using Microsoft Purview, Data Loss Prevention (DLP), and Insider Risk Management.As AI becomes increasingly integrated into daily work, protecting sensit…

Listen to the Episode
May 12, 2026

Beyond the Firewall: Why Your Azure SQL Security Is Obsolete

In this episode of the M365.FM Podcast, the discussion focuses on a critical shift happening in cloud security: the collapse of the traditional network perimeter. The episode explains why Azure SQL firewall rules, static IP allowlists, VPN-based trust models, and long-standing “inside the network e…

Listen to the Episode
May 11, 2026

Red Teaming Multi-Model AI: Why Manual Testing Fails in Finance

In this episode of the m365.fm podcast, Mirko Peters explores why traditional AI security testing is no longer enough in modern enterprise environments. The discussion focuses on “red teaming” for multi-model AI systems, especially in highly regulated industries like finance, where multiple AI mode…

Listen to the Episode
May 8, 2026

The Truth About Microsoft Security and Copilot Readiness with Åsne Ho…

In this episode of the M365 FM Podcast, Åsne Holtklimpen joins Mirko Peters to discuss the real challenges behind Microsoft Copilot adoption and AI readiness in Microsoft 365 environments. The core message is clear: Copilot does not create security problems — it exposes the governance and security …

Listen to the Episode
May 5, 2026

Is Your Copilot Safe: Stop Prompt Injections with Azure Logic Apps

In this episode of the M365.fm podcast, the discussion focuses on one of the biggest hidden risks in Microsoft Copilot environments: prompt injection attacks. The episode explains that the real security problem is not weak prompts or missing filters, but the architecture behind how AI models proces…

Listen to the Episode
May 5, 2026

Stop Deepfake BEC: The Verified ID Strategy

This episode explores how deepfake-enabled Business Email Compromise (BEC) attacks are becoming more convincing and dangerous for organizations. Traditional trust signals like email addresses, writing style, or even voice messages are no longer reliable because attackers can now imitate executives …

Listen to the Episode
April 30, 2026

Your Sensitivity Labels Are A Lie: The Collaborative AI Silo Crisis

This episode argues that sensitivity labels are widely misunderstood and often give organizations a false sense of security. While they appear to enforce governance, in reality they are static, incomplete, and poorly maintained—making them ineffective in dynamic, AI-driven environments.The core…

Listen to the Episode
April 24, 2026

The Copilot Coworker: Why Your AI Strategy is Building Digital Debt

This episode explains that treating AI like a simple add-on tool—especially Microsoft Copilot—can quietly create “digital debt” inside organizations. The problem isn’t the AI itself, but the messy, ungoverned Microsoft 365 environments it relies on. Copilot acts as a powerful coworker that instantl…

Listen to the Episode
April 21, 2026

Stop Selling Security: How to Pitch a Strategic Business Asset

Ever wonder why your Security Pitch Fails, even when you know the risks? You talk about security, but the board wants to hear about business value. Today, security is more than just stopping threats. Leaders want proof that s...

Listen to the Episode
April 14, 2026

Why Your Compliance Strategy Is Your Only Real Competitive Advantage

In this episode of m365.fm, we explore why a strong compliance strategy is no longer just a regulatory requirement—but a true competitive advantage. Learn how traditional governance approaches fail at scale and why embedding compliance directly into Microsoft 365 workflows is key to enabling produc…

Listen to the Episode
April 13, 2026

I Audited 500 Microsoft 365 Tenants – Here’s the Real Maturity Formula

This episode explores the Microsoft 365 maturity model through real-world insights gathered from auditing over 500 tenants. Instead of relying on theoretical frameworks, it uncovers how most organizations struggle with Microsoft 365 governance maturity, hidden misconfigurations, and the growing gap…

Listen to the Episode
April 12, 2026

Why Your Governance Is Failing (Policies Are Not Code in Microsoft 36…

In this episode, we challenge a common misconception in Microsoft 365 governance: having policies in place does not mean your environment is truly governed. Many organizations rely on documented rules, guidelines, and compliance frameworks, assuming they will control user behavior and protect data.…

Listen to the Episode
April 10, 2026

Microsoft 365 Audit Readiness: Why Governance Debt Leads to Audit Pan…

Most Microsoft 365 environments don’t fail audits because of missing controls—they fail because of governance debt. Over time, quick fixes, unclear ownership, and poorly aligned operating models create hidden structural issues. These problems stay invisible until an audit exposes them, triggering l…

Listen to the Episode
April 4, 2026

Your Microsoft 365 Isn’t Secure: The Hidden Risks You’re Missing

In this episode, we explore why Microsoft 365 environments are often less secure than they appear. While most organizations focus on security tools and settings, the real risk lies in what we call the “invisible tenant” — a hidden layer of misconfigurations, excessive permissions, and missing gover…

Listen to the Episode
March 24, 2026

The Infrastructure Illusion: How to Map What Your People Actually Do …

Most organizations think they understand their infrastructure. They see tools, licenses, configurations… dashboards that suggest control. But none of that tells you what’s actually happening. In reality, your Microsoft 365 environment isn’t just infrastructure—it’s a living system of decisions, beh…

Listen to the Episode
March 22, 2026

Microsoft 365 Governance: The #1 Mistake 73% of Deployments Make (And…

This episode argues that the biggest governance mistake in Microsoft 365 isn’t misconfiguration—it’s timing. Most organizations treat governance as something to “add later,” but by doing that, they unintentionally design failure into the system from day one.The core idea is that governance isn’…

Listen to the Episode
March 13, 2026

Microsoft 365 Security: Why Accountability Is the Only Real Security …

This episode breaks down why Microsoft 365 governance and security are not just technical concerns but organizational responsibilities. It explains how a structured governance framework—built on security, compliance, data protection, and clear ownership—prevents chaos like permission sprawl, data l…

Listen to the Episode
Jan. 23, 2026

Microsoft Teams Admin Center Is Not the Control Plane: How Entra ID R…

In this episode, we dismantle a common Microsoft Teams governance myth: that the Teams Admin Center is the central command for controlling Teams behavior and enforcing governance.Most organizations treat the Admin Center like a control tower — but it’s actually a downstream service console, not…

Listen to the Episode
Dec. 29, 2025

Power Platform Governance: Why Your Tenant Is the Real Ris

Is Power Platform actually dangerous for the enterprise—or is that fear hiding a more uncomfortable truth?In this episode, we dismantle the question executives keep asking: “Is Power Platform secure enough?” The answer is sharper than most teams expect. Yes—Microsoft’s Power Platform security i…

Listen to the Episode
Dec. 28, 2025

How to Stop Shadow IT in Microsoft Foundry Before It Starts

This episode opens with a blunt warning: Microsoft Foundry isn’t just another AI feature you can casually approve and forget. It’s an agent factory, and if execution comes before governance, you are almost guaranteed to create the next generation of shadow IT. Most future AI incidents won’t come fr…

Listen to the Episode
Dec. 19, 2025

How to Detect Impossible Travel and Token Replay in Entra ID

This episode plays out like a cybercrime thriller, exposing how today’s most dangerous breaches don’t smash doors—they’re invited inside. The investigation opens with a single click on January 12th. A polished phishing email doesn’t steal a password; it steals a session token. Within minutes, that …

Listen to the Episode