Turn your real-world experience into part of the show.

Microsoft Security Episodes

Understand the intricate security measures within the Microsoft ecosystem, including identity management and data protection. Discuss best practices for configuring security in Azure and Microsoft 365.
July 15, 2026

Azure Firewall - Simply Explained

Azure Firewall is Microsoft's cloud-native, fully managed network security service that protects Azure workloads from both internal and external threats. Instead of deploying and maintaining traditional firewall appliances, Azure Firewall provides centralized traffic filtering, threat intelligence, and application-aware security that automatically scales with your environment. In this episode, you'll learn what Azure Firewall is, how it works, and why it's a critical component of a secure Azure architecture. The discussion explains key concepts including network rules, application rules, NAT rules, threat intelligence, and the differences between the Basic, Standard, and Premium SKUs. You'll also discover how Azure Firewall fits into hub-and-spoke network designs and complements services like Network Security Groups (NSGs). The episode explores practical scenarios such as securing virtual machines, controlling outbound internet access, protecting hybrid cloud environments, filte…
Guest: Mirko Peters
July 15, 2026

Azure Policy - Simply Explained

Azure Policy is Microsoft's governance and compliance service for Azure, helping organizations enforce standards, prevent misconfigurations, and keep cloud environments secure at scale. Instead of relying on administrators to manually follow best practices, Azure Policy automatically evaluates resources against defined rules and can deny, audit, modify, or automatically remediate deployments that don't meet organizational requirements. In this episode, you'll learn what Azure Policy is, how it works, and why governance should be built into your Azure environment from day one. The discussion explains the core concepts of policy definitions, assignments, initiatives, scopes, exemptions, and compliance reporting, showing how they work together to enforce consistent standards across subscriptions, resource groups, and management groups. You'll also discover the difference between Azure Policy, Azure RBAC, and Azure Blueprints, helping you understand when each service should be used. …
Guest: Mirko Peters
July 14, 2026

Azure Sphere - Simply Explained

Azure Sphere is Microsoft's end-to-end security platform for Internet of Things (IoT) devices. Instead of focusing only on software security, Azure Sphere protects connected devices from the silicon chip all the way to the cloud. It combines three core components: certified secure hardware, a custom Linux-based operating system, and a cloud security service that continuously authenticates devices and delivers automatic security updates throughout their lifetime. Think of Azure Sphere as a security guard that never leaves your smart device. Whether it's a factory sensor, a connected coffee machine, medical equipment, or industrial machinery, Azure Sphere constantly verifies that the device is running trusted software, communicates securely, and stays protected against newly discovered threats. Unlike traditional embedded systems that may never receive updates after deployment, Azure Sphere devices are continuously patched without requiring manual intervention. Imagine a manufactu…
Guest: Mirko Peters
July 13, 2026

Zero Trust AI Security with Microsoft Copilot and Azure – Mourtaza Fazlehoussen [MVP]

Artificial Intelligence is transforming cybersecurity—but it is also creating new attack surfaces. In this episode of the M365 FM Podcast, Mirko Peters is joined by Microsoft MVP Mourtaza Fazlehoussen to explore how organizations can secure AI-powered environments using Microsoft Copilot, Azure, Microsoft 365, and Zero Trust principles. Rather than treating AI as an isolated technology, the discussion explains why identity, permissions, governance, and continuous verification are now the foundation of enterprise security. The conversation covers how attackers exploit weak identities, excessive permissions, misconfigured cloud services, and unmanaged AI workloads. You'll learn how Microsoft Entra ID, Microsoft Defender, Microsoft Sentinel, Azure security services, and Microsoft Security Copilot work together to detect threats, automate investigations, and reduce risk across modern Microsoft environments. The episode also explores the importance of least privilege, Conditional Access…
July 12, 2026

Microsoft Security Copilot - Simply Explained

Microsoft Security Copilot is Microsoft's AI-powered cybersecurity assistant designed to help security teams detect, investigate, and respond to threats faster. Instead of replacing security analysts, it automates repetitive work such as analyzing alerts, correlating events, summarizing incidents, and generating remediation recommendations, allowing experts to focus on higher-value decisions. This episode explains how Security Copilot integrates with Microsoft Defender, Microsoft Sentinel, Entra ID, and other Microsoft security services to provide contextual insights across an organization's environment. Through practical examples, you'll learn how AI accelerates incident response, reduces alert fatigue, and helps teams uncover attacks that might otherwise be overlooked. The episode also discusses where Security Copilot delivers the greatest value, its current limitations, and why it should be viewed as a force multiplier rather than a replacement for experienced security profes…
Guest: Mirko Peters
July 11, 2026

Compliance as Code: The Architect’s Blueprint for Automated Trust

Compliance is often treated as a documentation exercise—something organizations prepare for audits rather than embed into their daily operations. In this episode, we challenge that mindset by exploring the concept of Compliance as Code and why modern enterprises must shift from manual governance to automated, architecture-driven trust. You'll learn how compliance requirements can be translated into technical controls that are continuously enforced instead of relying on policies, checklists, and periodic reviews. We explain how infrastructure, identity, security policies, and governance rules can become executable code that validates systems in real time, reducing human error while improving consistency and audit readiness. The episode also explores how Microsoft technologies such as Microsoft Entra ID, Microsoft Purview, Azure Policy, Infrastructure as Code, and Power Platform governance contribute to building environments where compliance becomes part of the platform itself rat…
Guest: Mirko Peters
July 7, 2026

Secure Azure Networking with Rex de Koning [MVP-MCT]

Azure networking has evolved far beyond simply connecting virtual machines. In this episode, we explore how modern Azure networking enables organizations to build secure, scalable, and fully automated cloud environments using Azure Functions, Azure Virtual Network Manager, and Infrastructure as Code. We begin by discussing how Azure Functions can securely access private resources without exposing services to the public internet. You'll learn how Virtual Network integration, private endpoints, and network isolation help organizations protect sensitive workloads while maintaining the flexibility of serverless computing. These capabilities are becoming essential for building secure cloud-native applications. We also cover the networking options available for Azure Functions across different hosting plans and the architectural decisions behind them. Next, we dive into Azure Virtual Network Manager and how it simplifies enterprise-scale networking. Instead of manually configuring hun…
July 5, 2026

Microsoft Graph Security Automation for Microsoft 365

Microsoft Graph is often seen as a reporting and management API—but what if it could become one of your most powerful security tools? In this episode, we explore how Microsoft Graph can be leveraged to uncover hidden risks, automate governance, and continuously improve the security posture of an entire Microsoft 365 tenant. Rather than relying solely on traditional security dashboards, Graph provides direct access to identities, permissions, groups, applications, devices, and collaboration data, enabling organizations to detect problems before they become incidents. You'll learn how to use Microsoft Graph to identify excessive permissions, orphaned resources, inactive accounts, risky application consents, external sharing, and configuration drift across Microsoft 365. The episode explains why security is ultimately a data problem and how Graph serves as the unified interface that makes tenant-wide visibility and automation possible. We also discuss practical automation scenarios…
Guest: Mirko Peters
July 2, 2026

Microsoft Graph and PowerShell for Enterprise Automation

Microsoft Graph is far more than just another API—it is the operational backbone of Microsoft 365. This episode explains why relying solely on admin portals limits scalability, visibility, and automation, while Microsoft Graph provides a unified interface for managing identities, users, groups, Teams, SharePoint, security, compliance, and business data across the entire Microsoft ecosystem. The discussion explores how Microsoft Graph PowerShell enables administrators to automate repetitive tasks, manage large environments consistently, and build governance processes that simply cannot be achieved through manual portal administration. Understanding authentication, OAuth, delegated and application permissions, service principals, and least-privilege access is presented as essential for building secure enterprise automation. The episode also highlights Microsoft's AI strategy, explaining that services such as Microsoft Copilot, Copilot Studio, AI agents, and future intelligent work…
Guest: Mirko Peters
July 2, 2026

Microsoft Security Exposure Management with Uros Babic [MVP-MCT]

Traditional cybersecurity often focuses on vulnerability counts, alerts, and compliance dashboards. Attackers don’t. They look for weak identities, excessive permissions, exposed cloud resources, forgotten devices, and misconfigurations they can combine into a successful attack. In this episode, Mirko Peters is joined by Microsoft Security MVP and MCT Uros Babic to explore cybersecurity from an attacker’s perspective and explain how Microsoft Security Exposure Management helps organizations stay ahead of modern threats. Rather than discussing security in theory, the conversation walks through a realistic attack chain—from reconnaissance and phishing to credential theft, privilege escalation, lateral movement, ransomware, and data exfiltration. Uros demonstrates how Microsoft Defender XDR, Microsoft Sentinel, Security Copilot, Microsoft Entra ID, and Zero Trust principles work together to detect, prevent, and disrupt attacks before they reach critical assets. A major focus is Mic…
June 26, 2026

AI Agent Identity Security: Beyond Service Accounts

AI agents are often managed like traditional service accounts—but that mindset creates serious security and governance risks. This episode explains why AI agents should be treated as autonomous digital identities with their own lifecycle, permissions, and accountability instead of static technical accounts. The discussion highlights that agents don't just authenticate to services—they make decisions, access business data, trigger workflows, and interact with multiple systems. Because of this, identity becomes the primary security boundary. Organizations should assign every agent its own identity, apply least-privilege access, enforce Zero Trust principles, and continuously monitor behavior rather than relying on broad, long-lived permissions. The episode also covers the importance of lifecycle management for non-human identities. Just like employees, AI agents require onboarding, role assignments, permission reviews, auditing, and secure decommissioning. Without proper governanc…
Guest: Mirko Peters
June 23, 2026

Dataverse Business Skills for Scalable Power Platform Solutions

In this episode of the M365.FM Podcast, we explore why mastering Dataverse business skills is becoming one of the most important capabilities for organizations building scalable solutions on Microsoft Power Platform. The discussion goes far beyond tables and columns, focusing on how Dataverse can be used to capture business knowledge, processes, and operational intelligence in a way that supports long-term growth and automation. You’ll learn why successful Power Apps, Power Automate solutions, and AI-powered business processes depend on strong data modeling foundations rather than simply creating forms, workflows, or user interfaces. The episode highlights how well-designed Dataverse structures help organizations maintain consistency, improve governance, and reduce technical debt as applications scale across departments and business units. The conversation also examines the emerging role of Dataverse business skills, showing how organizations can transform business processes int…
Guest: Mirko Peters
June 23, 2026

Security Agent Fabric: Autonomous AI for Cyber Defense

In this episode of M365.fm, we explore why the future of cybersecurity is no longer centered around dashboards, alerts, and manual investigations—but around autonomous security agents working together as a coordinated Security Agent Fabric. As modern enterprises generate billions of security signals across cloud platforms, identities, endpoints, and applications, traditional Security Operations Centers (SOCs) are reaching their limits. Human analysts simply cannot keep pace with the volume, speed, and complexity of today's threat landscape. The episode introduces the concept of Agentic Defense: a new security architecture where specialized AI agents continuously monitor, validate, investigate, and respond to threats while remaining governed by human oversight. Instead of relying on a single security copilot, organizations will deploy networks of collaborating agents that handle identity protection, threat hunting, incident triage, compliance validation, vulnerability management,…
Guest: Mirko Peters
June 20, 2026

Private RAG Security: Authorization-Aware Data Retrieval

veryone is talking about Private RAG, sovereign AI, regional hosting, and keeping enterprise data inside controlled environments. But in this episode of M365 FM, Mirko Peters explores a critical security gap that many organizations overlook: data sovereignty is not the same as data security. The episode examines what happens when documents leave systems like SharePoint and Microsoft 365 and are ingested into vector databases for Retrieval-Augmented Generation (RAG) solutions. While organizations often focus on where data is stored, they frequently ignore what happens to permissions, access controls, and authorization models during the indexing process. The result can be a highly capable AI system that unintentionally exposes sensitive information to users who should never have access to it. A major focus is the concept of authorization-aware retrieval. Listeners learn why self-hosting, VPN access, or private infrastructure alone do not guarantee security. The episode breaks down…
Guest: Mirko Peters
June 19, 2026

Fixing the SharePoint Metadata Gap for AI and Governance

SharePoint has become the central repository for business knowledge, documents, contracts, policies, and operational records. Yet many organizations are sitting on a hidden problem: their content lacks the metadata needed to make that information truly discoverable, governable, and AI-ready. In this episode of M365 FM, Mirko Peters explores the growing “metadata gap” and why it has become one of the biggest risks in modern Microsoft 365 environments. While organizations invest heavily in SharePoint, Copilot, search, and automation, many still rely on inconsistent folder structures, poor document classification, and manual filing processes that create data chaos over time. The discussion explains how missing or inconsistent metadata impacts far more than search. It affects compliance, records management, retention policies, security controls, business process automation, and the quality of AI-generated results. As Microsoft Copilot and other AI services depend on context to under…
Guest: Mirko Peters
June 19, 2026

Conditional Access and Identity as Code with Jonathan Hope [MVP]

In this episode of M365 FM, Mirko Peters sits down with Microsoft MVP Jonathan Hope to explore why identity has become the most critical security boundary in modern cloud environments. As organizations move deeper into Microsoft 365, Azure, and cloud-native architectures, traditional network-based security models are no longer enough. Jonathan explains how Microsoft Entra ID acts as the control plane for security and why mismanaged identities, excessive permissions, and poorly maintained Conditional Access policies create significant risk. The conversation dives into the concept of “identity debt” — the gradual accumulation of exceptions, legacy configurations, guest accounts, workload identities, and hybrid synchronization issues that weaken an organization’s security posture over time. The episode covers practical strategies for implementing Zero Trust principles, designing effective Conditional Access policies, enforcing least-privilege access, and protecting privileged accou…
June 18, 2026

How to Run Local Llama on SharePoint Files Securely

Artificial Intelligence is transforming the way organizations manage knowledge, documents, and collaboration. Yet as companies rush to adopt AI assistants and large language models, one question continues to dominate every conversation: how can you benefit from AI without exposing sensitive business information to external services? In this episode of M365 FM, Mirko Peters explores how organizations can run Local Llama models directly against SharePoint content while maintaining complete control over their data. Instead of sending confidential documents, intellectual property, customer information, and internal knowledge to cloud-hosted AI platforms, organizations can build private AI solutions that keep processing inside their own environment. The episode breaks down the architecture behind local AI deployments, explaining how open-source LLMs, retrieval-augmented generation (RAG), semantic search, and document embeddings can be combined with SharePoint to create intelligent kn…
Guest: Mirko Peters
June 16, 2026

Indirect Prompt Injection Security for Enterprise AI

Most organizations believe hallucinations are the biggest risk in enterprise AI. In reality, one of the most dangerous threats is something far less visible: Indirect Prompt Injection. In this episode, we explore how trusted documents, emails, SharePoint content, Teams conversations, and knowledge bases can become attack vectors that manipulate AI systems without ever compromising the underlying infrastructure. The episode examines why Retrieval-Augmented Generation (RAG), the foundation behind Microsoft 365 Copilot, Azure AI Foundry solutions, and many enterprise AI assistants, introduces an entirely new security challenge. Unlike traditional software, large language models cannot reliably separate data from instructions. Every piece of retrieved content becomes part of the model's context, allowing hidden commands, poisoned documents, metadata, and embedded instructions to influence AI behavior. Listeners will learn how indirect prompt injection works, why system prompts are n…
Guest: Mirko Peters
June 14, 2026

Private LoRA for Secure AI on Proprietary Enterprise Data

The rise of enterprise AI has created a fundamental challenge: how can organizations leverage powerful language models without exposing their most valuable proprietary data? In this episode of M365.fm, we explore the growing adoption of Private LoRA (Low-Rank Adaptation) as a practical architecture for secure AI systems built on sensitive enterprise information. Rather than sending confidential documents, intellectual property, customer records, or internal knowledge to public AI services, Private LoRA enables organizations to adapt and customize foundation models while keeping their data within controlled environments. The discussion explains why traditional fine-tuning approaches are often expensive, difficult to govern, and introduce significant security and compliance concerns. The episode breaks down how LoRA works by modifying only a small subset of model parameters, allowing organizations to create specialized AI capabilities without retraining entire large language model…
Guest: Mirko Peters
June 13, 2026

AI-Powered Metadata Classification for Microsoft 365 Governance

Manual tagging is dead—and it’s quietly undermining your Microsoft 365 governance strategy. In this episode, we explore why traditional metadata management based on dropdown menus, user-selected labels, and manual classification no longer works in modern organizations. The volume of content generated across SharePoint, Teams, OneDrive, Copilot, and Microsoft 365 has grown beyond what humans can reliably classify. The problem isn’t that users are unwilling to tag content—it’s that manual tagging is inconsistent, incomplete, and impossible to scale. When metadata quality declines, governance suffers. Search results become unreliable, retention policies lose effectiveness, compliance controls weaken, and AI tools like Microsoft Copilot struggle to understand and protect organizational data. The episode examines how Microsoft Purview and AI-powered classification are changing the game. Instead of relying on users to choose the correct label, modern governance systems can analyze …
Guest: Mirko Peters
June 12, 2026

Cryptographic Agility for Post-Quantum Security

As quantum computing moves from theory toward reality, many organizations are focusing on replacing RSA and ECC with post-quantum cryptography. But in this episode of M365.fm, Mirko Peters argues that simply choosing a new algorithm is not enough. The real challenge is cryptographic agility: the ability to rapidly adapt, replace, and evolve cryptographic systems as threats, standards, and technologies change. The discussion explores why most enterprise environments are deeply dependent on cryptography in ways many organizations don't fully understand. Certificates, identity systems, VPNs, TLS connections, APIs, cloud workloads, IoT devices, and long-lived data all rely on cryptographic foundations that may become vulnerable in a post-quantum world. The biggest risk is not that quantum computers arrive tomorrow—it is that organizations cannot adapt quickly when change becomes necessary. The episode examines how crypto-agility shifts the conversation from algorithm selection to ar…
Guest: Mirko Peters
June 12, 2026

Microsoft Purview for Copilot Security with Peter Rising [Microsoft]

As organizations rapidly adopt Microsoft 365 Copilot, AI agents, and generative AI technologies, one challenge stands above all others: ensuring data is secure, governed, and compliant. In this episode of M365 FM, Mirko Peters speaks with Peter Rising, Senior Partner Solution Architect at Microsoft, about how Microsoft Purview helps organizations prepare for AI at scale. The discussion explores why AI readiness is not just about deploying Copilot licenses but understanding and controlling the data that powers AI experiences. Peter explains how Microsoft Purview provides visibility into sensitive information, helps classify and protect business-critical data, and enables organizations to apply Zero Trust principles across their Microsoft 365 environment. The conversation covers key capabilities including Data Loss Prevention (DLP), sensitivity labels, information protection, insider risk management, auditing, compliance monitoring, and data governance. These tools help ensure tha…
June 7, 2026

Shadow Data Discovery and Governance with Microsoft Purview

In this episode of the M365 FM Podcast, we explore one of the biggest hidden risks in modern data governance: shadow data. While Microsoft Purview provides powerful visibility into governed data sources, many organizations assume that what Purview cannot see does not exist. That assumption creates a dangerous blind spot. The discussion explains how shadow data emerges across disconnected systems, unmanaged repositories, legacy platforms, third-party applications, personal storage locations, and forgotten workloads that sit outside normal governance processes. These hidden data stores often contain sensitive business information, intellectual property, customer records, and compliance-relevant content that never appears in standard Purview reporting. The episode breaks down why organizations frequently mistake data discovery for complete data visibility. Even with strong classification, labeling, and compliance controls in Microsoft 365, governance can only protect what it can ac…
Guest: Mirko Peters
June 4, 2026

Building a Synthetic Market for Microsoft 365 Strategy

In this episode, Mirko Peters explores why successful Microsoft 365 strategy should be approached like building a synthetic market rather than deploying technology in isolation. The core idea is that Microsoft 365 creates an internal economy where information, collaboration, automation, governance, and AI capabilities continuously interact. Organizations that focus only on individual tools such as Teams, SharePoint, Power Platform, or Copilot often miss the larger system dynamics that drive long-term value. The discussion highlights that every platform decision creates incentives and behaviors. Poor governance can encourage content sprawl, uncontrolled workspace growth, and fragmented knowledge, while well-designed governance creates trust, discoverability, and sustainable adoption. The episode argues that strategy is not about maximizing feature usage but about shaping the conditions that allow productive behaviors to emerge naturally across the organization. A key theme is tha…
Guest: Mirko Peters