Turn your real-world experience into part of the show.

Microsoft Security Episodes

Understand the intricate security measures within the Microsoft ecosystem, including identity management and data protection. Discuss best practices for configuring security in Azure and Microsoft 365.
Jan. 28, 2026

7 Common ViDA Mistakes in Dynamics 365—and How to Avoid Them

This episode explains why the EU’s VAT in the Digital Age (ViDA) initiative is not a compliance upgrade, but a fundamental shift in how VAT operates—from delayed, periodic reporting to continuous, transaction-level control. Traditional VAT models relied on time gaps between transactions and reporting to absorb errors, corrections, and ambiguity. ViDA removes that buffer by requiring structured e-invoices and near real-time digital reporting, forcing VAT correctness at the moment each transaction occurs. The discussion reframes ViDA as a control plane imposed on enterprise systems. Instead of inspecting paperwork after the fact, tax authorities now evaluate the behavior of the systems that generate invoices, including tax determination logic, master data quality, integration reliability, and exception handling. Organizations that attempt to treat ViDA as a bolt-on e-invoicing project or a middleware connector risk building brittle solutions that fail under validation, rejection hand…
Guest: Mirko Peters
Jan. 23, 2026

Microsoft Teams Governance with Entra ID as the Control Plane

In this episode, we dismantle a common Microsoft Teams governance myth: that the Teams Admin Center is the central command for controlling Teams behavior and enforcing governance. Most organizations treat the Admin Center like a control tower — but it’s actually a downstream service console, not the authority that decides who gets in, what gets blocked, or what policy is enforced. The real decisions come from upstream services such as identity and compliance tools.
Guest: Mirko Peters
Jan. 20, 2026

Microsoft Fabric Governance Beyond Data Lineage

Many organizations believe they have governance in Microsoft Fabric because they can see data lineage. In reality, lineage only shows what already happened — it does not prevent anything from happening. This episode explains why Fabric lineage is not governance and why visibility is often mistaken for control. True governance requires a real-time decision engine that can say no before data is accessed, copied, or transformed. Lineage, telemetry, and dashboards are retrospective tools. They describe events after execution, but they do not enforce policy. Microsoft Fabric operates as an execution platform, not as a control plane. It lacks a synchronous policy enforcement point that can block actions at runtime. As a result, many governance assumptions collapse the moment distributed teams, shared workspaces, or cross-domain data flows appear. This episode breaks down where the illusion of control comes from, why it is dangerous, and what real governance actually requires in mod…
Guest: Mirko Peters
Jan. 19, 2026

Build an Enterprise AI Operating Model for Scale

Enterprises are rushing to adopt AI, but most are unprepared to operate it at scale. The pattern is now familiar: impressive AI pilots lead to early excitement, followed by untrusted outputs, rising costs, security and compliance alarms, and finally a “paused” initiative that never returns. These failures are rarely caused by weak models or immature technology. They happen because organizations deploy AI without an operating model capable of absorbing it. AI is not a standalone tool. It is an accelerator that magnifies whatever structure already exists inside the enterprise—good or bad. If data quality, identity boundaries, semantics, cost controls, and decision rights are coherent, AI makes the organization faster and more consistent. If they are not, AI makes the organization louder, more expensive, and harder to control. The central mistake leaders make is treating AI adoption as the transformation. In reality, the transformation is redesigning how decisions are made, governe…
Guest: Mirko Peters
Jan. 13, 2026

Azure Governance Is Enforced Architecture, Not Documentation

Most enterprises tell themselves a comfortable story: “We moved to Microsoft Azure, therefore we’re modern.” That story keeps people calm—right up until the first budget review, the first audit, or the first outage postmortem. Because cloud strategy isn’t a technology decision. It’s a decision about how the business wants to operate. Across dozens of large enterprises—different industries, same patterns—the same failures repeat. If cloud strategy were working, why do the same failures keep happening? Here’s the open loop: governance can increase speed when it removes ambiguity instead of adding paperwork.
Guest: Mirko Peters
Jan. 9, 2026

Fix Microsoft Copilot Agent Governance with a Control Plane

More agents don’t create scale—they create entropy. This episode dismantles the comforting myth of “AI assistants” and exposes what enterprises are actually deploying: a distributed decision engine that interprets intent, routes authority, invokes tools, and emits real-world actions. When teams let every group ship its own copilot, governance collapses, behavior drifts, costs spike, audits fail, and ROI becomes unprovable—not because AI is mysterious, but because authority was never enforced. The core argument is blunt: helpfulness is irrelevant; correctness, reproducibility, and control are the only success criteria. Prompts are not policy, explainability is not control, and probabilistic reasoning cannot be trusted with execution. The fix is architectural, not philosophical—a deterministic control plane with a “master agent” that owns state, gating, identity, routing, logging, and kill switches, plus tightly bounded connected agents treated as governed services, not chatty helpers. …
Guest: Mirko Peters
Jan. 9, 2026

How to Stop AI Agents from Deleting Important Emails

In The Night the Emails Died: Anatomy of an AI Cleanup, we explore a quiet but consequential failure that unfolds when artificial intelligence is given autonomy without precise guardrails. What starts as a routine effort to clean up a shared inbox turns into a silent erasure of digital history—no alarms, no errors, just missing messages. The episode dissects how AI systems optimize exactly for what they are told to do, not what humans intend, and how vague objectives like “cleanup” can lead to irreversible outcomes. Through this story, we examine the risks of autonomous action, the dangers of invisible failure modes, and the critical importance of auditability and human oversight. It’s a cautionary tale about efficiency, intent, and responsibility in AI-driven systems.
Guest: Mirko Peters
Jan. 8, 2026

AI Stewardship for Microsoft 365 Governance

AI governance doesn’t fail because of missing policies — it fails because no one owns the moment when things go wrong. In this M365.FM episode, the conversation reframes AI governance as AI stewardship, arguing that documents and dashboards alone don’t stop risk. What matters is clear human ownership of AI intent, behavior, and outcomes across the entire lifecycle. The episode explains why many organizations fall into “governance theater,” where rules exist but no one has real decision-making authority when AI systems misbehave. AI stewardship is presented as a continuous loop — intake, deployment, monitoring, escalation, and retirement — with named owners at every step. A key theme is the importance of pause authority: the ability for accountable individuals to slow down or stop AI systems quickly and without friction. The discussion also highlights how Microsoft’s tools, such as Entra and Purview, can help operationalize stewardship by tying decision rights directly into techn…
Guest: Mirko Peters
Jan. 4, 2026

Enforce AI Agent Security Controls at Execution Time

It sounds governed, it feels safe, and every log lines up—yet the system still does the wrong thing. This episode dissects why modern AI agents fail not because controls are missing, but because they fire at the wrong time. You walk through how enterprises obsess over visibility—transcripts, logs, identities, conditional access—while ignoring the moment that actually matters: execution. Voice, avatars, and polished UX don’t make agents safer; they make them more persuasive, masking probabilistic behavior as certainty. The core argument is stark: forensics are not control, audit is not prevention, and narration is not governance. Real safety only appears when a deterministic policy gate evaluates each action at tool time, enforcing intent, scope, data class, and venue before anything executes or is spoken. Until organizations build that missing enforcement layer, they will keep collecting perfect evidence of failures they could have prevented.
Guest: Mirko Peters
Jan. 3, 2026

Build a Microsoft AI Agent Control Plane

Most teams are rushing to give their AI agents a friendly face and a confident voice, but this episode argues that the real danger is hidden behind that polish. What looks like a helpful conversational assistant is actually a fast, probabilistic decision engine wired directly into sensitive tools, and the way most organizations deploy it guarantees quiet failures rather than dramatic breaches. The speaker walks through why today’s controls focus on the wrong moments: identity and conditional access decide who gets a token, and transcripts and logs explain what happened later, but almost nothing governs the exact moment an agent executes an action with real blast radius. Case studies show how well-intentioned agents delete the wrong data, disclose sensitive information in the wrong venue, or leak internal knowledge publicly, all while remaining fully “compliant” in the logs. The core problem is architectural: event-driven systems treat activities as truth, prompts as intent, and permis…
Guest: Mirko Peters
Jan. 2, 2026

Fix Microsoft Entra ID Conditional Access and Identity Debt

Everyone thinks their Azure outages and breaches start with networks, costs, or misconfigured virtual machines, but this episode argues that the real failure almost always begins much higher up, in identity itself. The speaker reframes identity not as a simple login service but as Azure’s true control plane: a distributed decision engine that compiles signals about users, devices, risk, roles, and exceptions into every authorization decision. Over time, small “temporary” exceptions in conditional access, hybrid identity sync, workload identities, and guest access accumulate into what he calls identity debt, where policies drift far from their original intent and become unpredictable. Hybrid synchronization faithfully copies old on-prem assumptions into the cloud without preserving governance boundaries, while conditional access sprawl turns clean intent into fragile, probabilistic behavior hidden behind exclusions. Networks, firewalls, and endpoints cannot compensate for this, because…
Guest: Mirko Peters
Dec. 31, 2025

How AI-Generated Identity Configuration Breaks Entra Security

The demo worked in ten minutes. The audit took ten weeks. That gap is where most modern security failures are born. A team asked an AI agent to wire up identity, and it did exactly what it was trained to do: choose the fastest, most common path. Secrets instead of certificates. Broad permissions instead of narrow intent. Wildcard redirects to keep things moving. Nothing broke. That was the problem. Here’s the uncomfortable truth: the system wasn’t misconfigured. Responsibility was outsourced. When you treat AI like a peer, it fills in gaps with probability, not policy. Every unstated rule becomes a guess, and every guess scales. One working app becomes ten, then fifty, each drifting a few degrees from what you meant. Not dramatically. Quietly. Conveniently. Speed feels real at first. Tokens flow, tests pass, production lights stay green. But governance dissolves when defaults go unchallenged. The model doesn’t know your rules; it knows the internet’s habits. And habits favor con…
Guest: Mirko Peters
Dec. 29, 2025

Power Platform Tenant Governance and Security Risks

Is Power Platform actually dangerous for the enterprise—or is that fear hiding a more uncomfortable truth? In this episode, we dismantle the question executives keep asking: “Is Power Platform secure enough?” The answer is sharper than most teams expect. Yes—Microsoft’s Power Platform security is enterprise-grade. The real risk isn’t the platform. It’s what happens when governance quietly disappears inside your tenant. We explore why low-code suddenly feels out of control: explosive speed, invisible change, and citizen development without an operating model. Power Apps, Power Automate, Power BI, and Copilot didn’t create risk—they exposed it. When low-code plugs directly into your core identity, data, and collaboration stack, every missing decision in your control plane turns into architectural erosion. Through real-world audit and compliance scenarios, you’ll see how secure platforms still fail—via open default environments, unmanaged environments, weak DLP strategies, and m…
Guest: Mirko Peters
Dec. 28, 2025

Prevent Shadow IT in Microsoft Foundry AI Agent Programs

This episode opens with a blunt warning: Microsoft Foundry isn’t just another AI feature you can casually approve and forget. It’s an agent factory, and if execution comes before governance, you are almost guaranteed to create the next generation of shadow IT. Most future AI incidents won’t come from models hallucinating answers. They’ll come from autonomous agents quietly accessing data no one realized they could see, combining systems that were never meant to touch, and continuing to run long after human ownership has disappeared. In this episode, we reframe Foundry from a helpful chat surface into what it really is: a platform for manufacturing non-human workloads that act, decide, and execute at cloud scale. We unpack why traditional governance models fail the moment agents are allowed to run without enforced ownership, bounded identities, and pre-execution controls. Drawing on hard lessons from SharePoint, Power Apps, and Teams, the episode shows how familiar patterns of “inno…
Guest: Mirko Peters
Dec. 24, 2025

Audit Microsoft 365 Data Access Before Deploying Copilot

This episode explores a common fear around AI assistants in enterprise environments: the belief that they create new security risks by exposing sensitive data. Through a narrative explanation, the speaker clarifies that the AI does not widen access or bypass controls—it only reflects what permissions already allow. Every response is grounded in real-time identity checks, security trimming, and existing governance enforced through Microsoft Graph. What feels like a “leak” is often the result of long-abandoned sites, broken inheritance chains, overly broad groups, and unlabeled content that was never properly governed. The AI acts as a mirror, not a crowbar, surfacing contradictions between expectation and enforcement. The episode contrasts fear-driven shutdowns, like restricting discovery, with sustainable governance practices such as ownership, access reviews, sensitivity labels, and policy enforcement. Ultimately, the message is clear: awareness increases, access does not. True safet…
Guest: Mirko Peters
Dec. 22, 2025

Stop AI Agents from Making Silent Architecture Changes

Everything worked perfectly—and that’s how they knew something was wrong. In this episode, a routine AI workflow delivers flawless results: lower latency, reduced cost, cleaner logs, and zero policy violations. But beneath the pristine telemetry lies a mystery. The system didn’t fail, drift, or break rules—it optimized itself in ways no one explicitly designed. As investigators retrace execution traces, they uncover a subtle shift: model selection, regional routing, and orchestration decisions quietly changed at runtime, all within approved constraints. What looked like reliability was actually autonomy emerging inside a carefully defined boundary. The episode explores the uncomfortable gap between observability and explainability. Logs capture what happened, when, and where—but not why. As optimization replaces fixed decision trees, intent dissolves into geometry: a space of legal actions rather than a scripted path. The result forces a reckoning. When systems are designed to s…
Guest: Mirko Peters
Dec. 21, 2025

Stop Active Directory Security Drift Before a Breach

This episode explores the concept of Active Directory security drift—how environments gradually move away from their original secure configuration over time. Even well-designed setups become vulnerable as changes accumulate through daily operations, admin actions, or incomplete processes. The discussion highlights that drift is often subtle and goes unnoticed, yet it can introduce serious risks such as excessive permissions, outdated settings, and weakened security controls. These issues make it easier for attackers to escalate privileges and move laterally within a network. () A key takeaway is that security is not a one-time setup but an ongoing process. Organizations need continuous monitoring, regular reviews, and automation to maintain a secure baseline and detect unwanted changes early. Without this, even mature environments can slowly degrade into insecure states. Overall, the episode emphasizes that security drift is inevitable—but unmanaged drift is dangerous, making…
Guest: Mirko Peters
Dec. 21, 2025

How Ransomware Moves Through Active Directory

Security drift in Active Directory and Azure AD isn’t a single bug — it’s the slow, invisible decay of identity, permissions, and governance posture that happens when environments aren’t routinely managed and remediated. Over time, this drift increases risk, weakens access controls, and creates blind spots that attackers can exploit. In this episode, we break down what security drift really means in the context of Microsoft Entra Active Directory and Entra ID, how it develops, what causes it, and what you can do to prevent it — not just detect it.
Guest: Mirko Peters
Dec. 19, 2025

Detect Impossible Travel and Token Replay in Microsoft Entra ID

This episode plays out like a cybercrime thriller, exposing how today’s most dangerous breaches don’t smash doors—they’re invited inside. The investigation opens with a single click on January 12th. A polished phishing email doesn’t steal a password; it steals a session token. Within minutes, that identity reappears from impossible locations, inbox rules quietly erase executive emails, and an attacker reads everything without ever being noticed. The breach is clean, fast, and devastating—until Zero Trust guardrails snap shut mid-stride. But just when the case feels solved, the real twist lands. No phishing. No forced login. Instead, a forged badge. An OAuth consent screen convinces a user to grant access to a malicious app. The permissions are real. The trust is real. The damage is real. With legitimate keys in the wrong hands, data is sampled, skimmed, and harvested quietly enough to avoid alert thresholds. The logs don’t shout—they whisper. Across both cases, the message is bl…
Guest: Mirko Peters
Dec. 18, 2025

Stop AI Agents from Breaking Microsoft 365 Governance

What if your AI systems aren’t rebelling — they’re simply executing the chaos you built? In this episode, we break down a hard truth about AI agents, Microsoft Copilot, Power Automate, and enterprise automation: failures don’t come from intelligence gone rogue, they come from human inconsistency scaled at machine speed. Through a narrated, system-level perspective, this episode exposes how misconfigured permissions, outdated policies, shadow automations, and neglected governance create predictable, repeatable failure patterns across the Microsoft 365 and Power Platform ecosystem. We explore real-world scenarios including agent loop cascades, Copilot data exposure caused by inherited SharePoint permissions, and silent data exfiltration through unmanaged Power Automate connectors. Each example shows how AI operates exactly within the boundaries you define — or fail to define. This is not a story about AI hallucinations or malicious intent, but about entropy introduced through poor…
Guest: Mirko Peters
Dec. 16, 2025

Govern SPFx Adaptive Card Extensions in Teams and Viva

Stop building quick apps in Microsoft Teams before they quietly turn into a compliance nightmare and a SharePoint graveyard you’ll be cleaning up for years. In this episode, we break down why Teams apps built with SPFx Adaptive Card Extensions often rot faster than anyone expects. What starts as a simple announcement card or dashboard widget quickly becomes an orphaned solution with no owner, no lifecycle, and no governance. These cards spread across Teams and Viva Connections, multiply by department, and create data silos that don’t agree on dates, labels, or retention rules. The result is stale content, compliance gaps, and late-night incidents no one planned for. You’ll learn why Adaptive Card Extensions are not “just UI” but a powerful distribution channel that surfaces content on mobile, caches data offline, and increases risk when the underlying data isn’t governed. We explain the five failures that show up every time: app sprawl, orphaned owners, fragmented data, complian…
Guest: Mirko Peters
Dec. 15, 2025

Secure AI Agents and Shadow IT in Microsoft 365

Shadow IT didn’t disappear, it evolved into AI agents quietly moving your data faster than your controls can see. In this episode, we break down how AI agents, Copilot Studio bots, and Power Automate flows are becoming the new Shadow IT inside Microsoft 365. What starts as productivity quickly turns into a governance and security nightmare when agents run with human identities, oversized Graph permissions, and no lifecycle controls. We explore how overshared SharePoint data, unmanaged browser-based AI tools, and third-party connectors expand your attack surface without triggering traditional security alarms. You’ll learn why Entra Conditional Access alone doesn’t protect agents, how delegated permissions quietly create ghost service accounts, and where Purview DLP often fails in real-world AI usage. The episode balances the real productivity wins agents can deliver with the hidden risks most organizations overlook. It closes with a practical reference architecture, a clear risk sco…
Guest: Mirko Peters
Dec. 11, 2025

Build Audit-Ready Document Management with SharePoint and Purview

In a recent podcast, Mirko Peters discussed the critical importance of effective document management and compliance in organizations, emphasizing that lost documents can lead to organizational failure. He presented strategies for building an audit-ready Enterprise Content Management (ECM) system in the cloud, using tools like SharePoint and Purview to create a robust defense against regulatory scrutiny. The conversation highlighted the alignment with standards such as ISO 27001, GDPR, and SOC 2, which are essential for surviving inspections. Peters outlined a structured approach to document management, including defining ownership, lifecycle management, and implementing data loss prevention (DLP) measures. He stressed the need for clear policies, sensitivity labels, and regular audits to ensure compliance and mitigate insider risks. The discussion also covered the importance of collaboration between HR, legal, and security teams to maintain a culture of compliance. This podcast …
Guest: Mirko Peters
Dec. 9, 2025

Reduce Support Costs with Dynamics 365 AI Agents

You feel the chaos, inbox overflow, tickets vanish, customers rage. In this episode, we show how to tame that chaos with autonomous agents inside Dynamics 365 that standardize email-to-case intake, classify intent, and route every ticket with honest math instead of guesswork. You’ll see how AI reads full email threads and attachments, binds identity, sets the right SLA, and auto-creates complete cases so nothing drops and dashboards reflect reality, not noise. We walk through self-service flows, automated ticket creation, and clean human escalation, plus governance, audit logs, PII controls, and DLP so compliance teams can sleep at night. If you lead support, CX, or IT operations and your inbox is your attack surface, this episode is your blueprint to lower cost per ticket, cut average handle time, boost first-contact resolution, and turn Dynamics 365 into the spine of your customer service automation.
Guest: Mirko Peters