Turn your real-world experience into part of the show.

Microsoft Security Episodes

Understand the intricate security measures within the Microsoft ecosystem, including identity management and data protection. Discuss best practices for configuring security in Azure and Microsoft 365.
Dec. 7, 2025

Automate Intune Device Cleanup with Azure Automation

Stop patching ghosts and start running a self-healing workplace. This Podcast reveals why Microsoft Intune alone can’t scale your endpoint management – and how pairing Intune with Azure, Automation, Functions, Microsoft Graph, managed identities and Log Analytics turns chaos into a quiet, secure estate. You’ll see how configuration drift, stale devices, manual reports and “global admin for everything” culture silently open the door to attackers, then watch how event-driven automation cleans the graveyard, enforces zero trust, and fixes non-compliant devices before users even notice. Real enterprise scenarios show 40%+ fewer ghost devices, onboarding times dropping from days to minutes, and mean time to remediate falling from days to under an hour. If you manage thousands of Windows laptops, kiosks and mobile devices, this Intune and Azure architecture guide is your blueprint for scalable compliance, predictable conditional access and truly automatic security hardening.
Guest: Mirko Peters
Dec. 7, 2025

Harden Azure Backup with Soft Delete, MUA, and Vault Lock

Think your Azure backups are safe by default? They’re not. In this episode, we uncover how a single over-privileged identity can quietly kill “immutable” backups in Azure. You’ll hear real-life attack paths using compromised automation, shadow admins, and broad Contributor or Owner roles that delete items, purge soft-deleted points, and quietly zero out retention. Then we walk through a three-step hardening blueprint: enable soft delete on every vault, enforce multi-user authorization on destructive changes, and weld safety in with Vault Lock and least-privilege IAM. Learn how to isolate backup vaults, use PIM and Azure Policy, and monitor critical events with Sentinel so your recovery points survive ransomware, panic clicks, and misconfigurations in real Azure environments, especially for admins and security teams.
Guest: Mirko Peters
Dec. 5, 2025

Harden Intune Deployment for Zero Trust Compliance

Microsoft Intune is a powerful endpoint management solution — but improper deployment can introduce serious security risks. Misconfigured policies, over-permissioned roles, and weak compliance settings often create hidden vulnerabilities that attackers can exploit. In this guide, we break down the most common Intune deployment security risks, configuration mistakes organizations make, and how to harden your environment using best practices. From device compliance policies to role-based access control, this walkthrough helps you secure your Intune tenant before problems arise. If you’re managing endpoints at scale, prevention starts with correct configuration.
Guest: Mirko Peters
Dec. 4, 2025

Turn Microsoft Threat Analytics into Real Security Action

You’re letting attackers stroll through your Microsoft tenant because you treat Threat Analytics like a newsletter instead of a weapon. In this episode, we show security leaders and SOC analysts how to turn Microsoft Threat Analytics into a living playbook that actually reduces time to detect and closes real attack paths. We explain what Threat Analytics is, how Microsoft’s own security researchers map global telemetry, MITRE ATT&CK techniques and indicators of compromise into guidance written in your tenant’s language, and why skimming the overview while ignoring exposure panels silently keeps you vulnerable. You’ll hear a simple rhythm: read, test, act, verify. We walk a focused 60 minute workflow that pulls techniques into Advanced Hunting, links findings to incidents in Microsoft Defender, and converts recommendations into Secure Score actions with clear owners, SLAs and evidence. Using phishing to token theft and living off the land persistence scenarios, we expose common detecti…
Guest: Mirko Peters
Dec. 4, 2025

Build a Zero Trust Incident Timeline with Microsoft 365 Audit Logs

What if your Zero Trust stack is silently greenlighting a perfect data heist in Microsoft 365? In this episode, we dissect how one “compliant” account quietly pulled 12,000 SharePoint files in 20 minutes—no malware, no DLP alerts, and all your Entra ID and conditional access policies saying “allowed.” You’ll learn why Zero Trust without audit evidence is just policy theater, and how to turn Entra risk signals, the Unified Audit Log, Purview policy edits, and Copilot interaction logs into a single, defensible incident timeline. We break down risky sign-ins, workload identity anomalies, mass download deltas, silent policy tampering, and AI-powered data exfiltration that looks like normal collaboration. Discover the one log pivot that exposes data staging every time and the KQL detection recipes that connect identity, privilege, data movement, and egress into a kill chain you can actually interrupt. If you run Microsoft 365 security, SecOps, or compliance, this is your practical gui…
Guest: Mirko Peters
Dec. 3, 2025

Stop Teams Phishing and Social Engineering in Microsoft 365

Your Microsoft 365 tenant might already be compromised—and your MFA is effectively useless because of one misconfiguration you’ve probably left on. In this episode, the Office of Corrective Doctrine walks you through five brutal real-world attack paths inside Microsoft 365 and Entra ID: Teams phishing posing as IT support, device code vishing that launders MFA-resistant tokens, malicious OAuth consent that turns “productivity apps” into silent data siphons, SharePoint “anyone with the link” exfiltration, and adversary-in-the-middle token theft that replays your sessions at scale. You’ll hear precise failure analysis and opinionated fixes: how to shut down broad user consent, lock down Teams external federation, constrain SharePoint and OneDrive sharing, enforce phishing-resistant authentication, bind tokens to devices, and turn Conditional Access, Defender for Cloud Apps, Safe Links, and App Governance into a coherent Microsoft 365 security strategy. If you own identity, coll…
Guest: Mirko Peters
Dec. 3, 2025

Harden Microsoft Teams Security and Guest Access

Your “private” Microsoft Teams channels are quietly bleeding data – and default settings are to blame. In this episode, we walk through real-world incidents where dormant guest accounts, synced libraries, and careless PII pastes turned Teams into a silent leak. You’ll see how to harden Microsoft Teams security with Entra ID conditional access, tenant-wide MFA for guests and users, and strict device compliance. Then we wire Purview DLP for Teams chat and channels, lock down SharePoint external sharing, and use Entra ID governance to expire guests and automate access reviews. Finally, we cover audit logs, retention, and legal hold so you can prove what happened, not guess. If you run Teams for your org, this is your step-by-step playbook to stop data walking out the side door.
Guest: Mirko Peters
Dec. 2, 2025

Unify Hybrid Security with Microsoft Defender XDR

Stop Buying Security Tools: The Shocking ROI of One XDR Timeline Drowning in alerts across M365, endpoints, and cloud apps? This video shows why your hybrid security stack is a Rube Goldberg machine that screams and still misses real attacks. You’ll see the four blind spots in Microsoft 365, identities, endpoints, and SaaS, and how attackers live in the gaps between your tools. Then we show how Microsoft Defender XDR fuses email, identity, device, and cloud telemetry into one incident story and one timeline, slashing dwell time, false positives, and audit pain. If you’re tired of swivel-chair investigations, alert fatigue, and paying three times for the same breach, this breakdown shows how consolidation flips Defender XDR from expense to savings.
Guest: Mirko Peters
Dec. 2, 2025

Detect Microsoft 365 Attack Chains with Entra and Sentinel

MFA is not your shield – it’s already broken. In this episode, we walk the bridge of a real M365 tenant breach, step-by-step, from the attacker’s cockpit to your shattered inbox. You’ll hear how one phishing click plus an AitM proxy and a “benign” OAuth app stole live cookies, hijacked mailboxes, and quietly vacuumed SharePoint at 2 a.m. No brute force, just borrowed badges, stolen tokens, and app consent abuse. Then we flip the script: the exact Entra logs, Sentinel KQL, UEBA analytics, and one killer policy combo that makes stolen tokens useless off-device. If you run M365 and still trust MFA alone, this briefing might be the most important hour of your year.
Guest: Mirko Peters
Dec. 1, 2025

Stop OAuth Consent Attacks in Microsoft Entra ID

The podcast explains how attackers bypass MFA by abusing OAuth consent instead of stealing passwords. When a user or admin approves a malicious “productivity” app, it gets tokens with scopes like mail or files read and offline_access. That lets the attacker quietly read email, files and chats for months, even after password resets and new MFA devices. Normal identity events don’t revoke these grants; you must remove the OAuth grant or service principal itself. The host stresses three Entra controls: lock down user consent to low-risk scopes, only allow verified publishers, and route risky permissions through an admin consent workflow. Combined with rigorous logging, reviews and revocation, these steps eliminate most consent-based attacks in modern cloud identity environments today.
Guest: Mirko Peters
Nov. 30, 2025

Fix Conditional Access Loopholes in Microsoft 365

This episode explains how to “calm down” a messy Conditional Access setup by removing blind spots and setting clear boundaries. It walks through three main trust problems—overbroad exclusions, unclear device compliance, and token theft—and shows how to replace permanent exceptions with time-bound authentication contexts, stronger MFA, and clear device tiers (compliant, hybrid joined, Azure AD joined, registered). The host outlines a simple baseline of five inclusive policies (all-users MFA, unmanaged device step-up, strong auth for admins, emergency bypass via auth context, and token hygiene/CAE) plus a safe rollout plan using report-only mode, waves, and rollback. Finally, it stresses ongoing monitoring with a few KPIs and alerts (coverage, strength, exclusion changes, high-risk sign-ins without CA) so Conditional Access stays consistent, visible, and predictable instead of chaotic.
Guest: Mirko Peters
Nov. 21, 2025

Fix Copilot Policy Hallucinations with Custom Engine Agents

Out-of-the-box Microsoft Copilot sounds like a genius—but in real enterprises it’s a dangerously confident intern. In this episode, we expose where default Copilot quietly fails on the questions that actually matter: “Can I share this file?”, “Who’s on-call right now?”, “Is this HIPAA-safe?” You’ll see how generic, Graph-only Copilot ignores your DLP exceptions, regional SOPs, escalation paths, and legal memos—and why that’s how incidents are born. Then we show you the fix: plug your own specialist engine agent straight into Microsoft 365 Copilot Chat with a simple manifest upgrade. You’ll learn the retrieval + actions + guardrails pattern, how to wire Azure AI Search, internal APIs, and tenant controls, and the exact schema 1.22 tweaks (copilotAgents + customEngineAgents) that flip Copilot from smooth-talking generalist to hard-edged policy enforcer. The before vs. after is brutal: vague essays and hallucinated “best practices” turn into crisp, cited decisions, “Page now” butto…
Guest: Mirko Peters
Nov. 21, 2025

Increase Microsoft 365 Copilot Adoption with Behavior Change

Your Copilot rollout is probably going to flop—and it won’t be the AI’s fault. Most organizations treat Microsoft 365 Copilot like a feature toggle: light up licenses, send a heroic memo, run one training… and three months later MAU is a rounding error. In this episode, we expose the five hidden failure modes that quietly kill Copilot adoption: vague “be more productive” use cases, governance theater that stalls everything, launch-and-ghost comms, license confetti with no telemetry, and users who were never actually taught how to talk to the model. You’ll learn the brutal truth that deployment is not adoption, the week-one leadership decision that predicts your long-term MAU, and why your real product isn’t Copilot—it’s behavior change. We walk through the C4 prompting pattern (Context, Constraint, Critique, Continue), the 10/30/60 “Tuesday task” model that kills blank-page syndrome, how to stop governance panic without freezing the rollout, and a practical 90-day adoption playb…
Guest: Mirko Peters
Nov. 19, 2025

Build Multi-Channel Agents with the Microsoft 365 Agent SDK

Your M365 AI agent isn’t failing because the model is bad—it’s failing because your plumbing is. This episode exposes why DIY agents that “work in dev” die the second real users and security show up. You’ll hear how app-only auth quietly nukes permission fidelity and audit trails, why stateless bots forget context the moment you add a second node, and how hand-rolled Teams/Slack/Outlook adapters create glitchy, untrustworthy UX that feels cheap and amateur. The host then reveals the real unlock: the Microsoft 365 Agent SDK as the non-optional backbone for identity, state, channels, and governance. You get act-as-user auth, durable conversation state across clusters, real adapters for Teams/web/Slack/Copilot, streaming that just works, and built-in hooks for Purview, DLP, Defender, and eDiscovery—so security says “yes” instead of “absolutely not.” If you’re gluing LangChain, SK, and custom tools together and hoping it passes review, this episode is the wake-up call: stop shipping…
Guest: Mirko Peters
Nov. 17, 2025

Build Traceable Copilots with Agentic RAG on Azure

Your Copilot isn’t smart – it’s a very expensive autocomplete. In this episode, we break down why classic RAG (retrieve-augment-generate) quietly fails the moment your truth lives in more than one system, and how “agentic RAG” on Azure turns Copilot from a context tourist into an actual reasoning engine. You’ll hear how Planner, Retriever, and Verifier agents running on Azure AI Agent Service can roam Microsoft Fabric, SharePoint, and external data, cross-check their own answers, and deliver evidence-linked insights that auditors, CISOs, and data leaders can actually trust. We dig into On-Behalf-Of auth, RLS/CLS, and Purview labels so your AI respects the same permissions as your humans, instead of leaking CFO forecasts to interns. If you’re a CIO, CDO, architect, BI lead, or security/GRC owner who’s tired of hallucinated KPIs and pretty-but-useless dashboards, this is your blueprint. Learn how to cut decision latency from months to minutes, turn SharePoint chaos into a semantic…
Guest: Mirko Peters
Nov. 16, 2025

Build Hands-Free Copilot Voice Experiences with GPT-4o

Typing to Copilot is the new fax machine—and your thumbs are the bottleneck. In this episode we break down how to give Copilot an actual voice, a memory, and a legal department, so it can keep up with the way you think, not the way you type. You’ll hear how GPT-4o Realtime turns Copilot from a slow, QWERTY-bound chatbot into a true conversational partner that listens while you speak, lets you interrupt mid-answer, and responds in milliseconds. Then we plug that voice into a real brain: Azure AI Search with RAG, so every answer is grounded in your own policies, standards, and FAQs—fully cited, fully governed. We walk through the blueprint step by step: Blob Storage, Azure AI Search, a hardened proxy layer, and secure M365 voice integration in Copilot Studio, Power Apps, and Teams. No biometrics, no cowboy connectors, just Entra ID, Purview, DLP, and logs your CISO can sleep on. If you’re still typing into Copilot, you’re leaving productivity—and compliance-grade insight—on the…
Guest: Mirko Peters
Nov. 11, 2025

Copilot Studio Code Interpreter vs Azure Functions

Microsoft just made Python “run natively” inside Power Platform — and chaos followed. From Copilot Studio’s Code Interpreter to Azure Functions, everyone’s suddenly a Python dev… until the flows time out, the files hit 512 MB, and IT gets a heart attack. In this episode, we break down the great Python illusion: why “runs natively” ≠ “runs anywhere,” what the Code Interpreter actually is (a sealed glass terrarium for code), and when to stop pretending it’s production infrastructure. Then we contrast it with Azure Functions, the real grown-up runtime — scalable, governed, auditable — and explain how to move from prototype to production without setting your tenant on fire.
Guest: Mirko Peters
Nov. 11, 2025

Copilot in Office Apps: The Governance Checklist

Microsoft says Copilot is now free across Word, Excel, PowerPoint, Outlook, and OneNote. But here’s the twist: it’s not magic — it’s your data, orchestrated. In this episode we rip off the marketing gloss and show how Microsoft Graph pipes your emails, files, meetings, and notes into a single “AI brain.” You’ll see how Copilot actually works, where it really saves time, and why privacy, DLP, and audit workloads spike the moment you switch it on. Faster workflows? Yes. Free compliance? Not a chance.
Guest: Mirko Peters
Nov. 10, 2025

Reduce Defender False Positives with Security Copilot Analysts

Your “intern” just became your scariest, smartest coworker—and it’s made of code. In this episode, we unpack how Microsoft Security Copilot is quietly turning traditional Security Operations Centers into AI-driven defense factories. Forget drowning in alerts, phishing noise, and endless Patch Tuesday chaos. These synthetic analysts—autonomous agents baked into Defender, Entra, Intune, and Purview—are triaging phishing emails, tightening conditional access, and pre-planning vulnerability remediation before most humans finish their first coffee. You’ll meet three “interns” that: Read thousands of emails a day and never get alert fatigue Constantly patrol identities and access policies for silent privilege creep Act as a 24/7 digital medic for vulnerabilities across your endpoints Then we go a step further: you can build your own agents with plain English prompts, effectively staffing a synthetic workforce tailored to your environment. Is this the end of SOC analysts—or …
Guest: Mirko Peters
Nov. 9, 2025

Move Active Directory Groups to Microsoft Entra ID

Managing identity in 2025 shouldn’t feel like running a smartphone next to a rotary phone, but that’s exactly what happens when organizations rely on both on-prem Active Directory and Microsoft Entra ID. This episode breaks down the real cost of that dual-directory setup: mismatched policies, sync drift, failed Conditional Access checks, and endless “I can’t log in” tickets. We start by explaining the Source of Authority—who actually owns your users and groups—and why hybrid sync was meant to be a bridge, not a permanent home. You’ll learn how the IsCloudManaged property flips ownership from AD to Entra ID and why that shift is essential for Zero Trust, modern governance, and consistent authentication. Before moving anything, preparation is key. We walk through cleaning up stale AD objects, checking synchronization health, enforcing MFA, and documenting the attribute and app dependencies that can break during migration. Finally, we cover why groups should move first, how to i…
Guest: Mirko Peters
Nov. 2, 2025

Fix Copilot Notebooks GDPR and Governance Risks

Copilot Notebooks feel magical — a conversational workspace that pulls context from SharePoint, OneDrive, Teams, decks, sheets, emails — and synthesizes answers instantly. But the moment users trust that illusion, they generate data that has no parents. Every Copilot output — a summary, paragraph, bullet list — is derived content that contains fragments of sensitive sources… but inherits none of the original sensitivity label, retention policy, audit trace, or Purview detection scope. Result: enterprises are silently creating a Shadow Data Lake — an ocean of unlabeled, untraceable derivative insight. The core problem isn’t Microsoft’s security model — it’s that governance frameworks assume lineage, and AI isn’t generating lineage. Solution: treat AI output as first-class content. Label by default. Apply Derived Data policies. Time-box Notebook containers. Limit sharing. Make AI summaries review-gated. AI productivity accelerates — and so does compliance debt — unless…
Guest: Mirko Peters
Oct. 31, 2025

GPT-5 Copilot vs Researcher Agent for Compliance

GPT-5 in Copilot is dazzling—but its fluency can fool you. It produces executive-ready prose fast, yet lacks defensible provenance. That makes it great for creation (drafts, outlines, brainstorming) and terrible for compliance (anything that must survive audit). The Researcher Agent is the counterweight: slower, source-driven, and methodical. It asks clarifying questions, fetches and cites sources, logs retrieval, and builds an auditable chain of reasoning. In regulated environments, that difference is existential: GPT-5 gives velocity; the Agent gives veracity. Use Copilot for momentum; use the Agent when lineage, citations, and reproducibility are mandatory—governance docs, financial/regulatory reporting, internal knowledge articles, Entra/security audits, and exec-level market analysis. The winning pattern is a hybrid workflow: ideate with Copilot → verify critical claims with the Agent → reintegrate citations and let Copilot polish language. Keep layers separate to avoid “governan…
Guest: Mirko Peters
Oct. 24, 2025

Use Entra ID Group Writeback for Legacy File Servers

Most orgs still treat on-prem AD groups as sacred, syncing them to Entra ID and calling it “hybrid.” In reality, those objects are zombies: visible in Entra but ruled by on-prem, which blocks modern governance (dynamic membership, access reviews, APIs) and slows HR-driven provisioning. The fix is recognizing Source of Authority (SoA) per object. Groups that matter to cloud workloads should be cloud-managed (isCloudManaged=true), with Group Writeback used only where legacy systems still need on-prem visibility. Entra brings dynamic rules, self-service, access reviews, and unified audit; AD brings inertia and gray, read-only fields. The path forward: inventory and purge “zombie” groups, classify what stays, finish Exchange migrations, convert eligible security groups to Entra authority, and enable writeback via Cloud Sync for any remaining on-prem dependencies. This isn’t rebellion; it’s alignment—put governance where work happens. Let AD retire into archival role; let Entra run identit…
Guest: Mirko Peters
Oct. 22, 2025

Speed Fabric and AKS Workloads with Local NVMe Storage

Your Fabric and Power Platform workloads aren’t slow because of Spark or DAX—they’re slow because your data lives far from your compute. Managed storage adds network hops, caps IOPS, and taxes every read/write with latency. The fix isn’t “more nodes”; it’s proximity. Azure Container Storage v2 (ACStor v2) puts hot data on local NVMe inside your AKS nodes, exposing silicon-speed via a lean, CSI-based, ephemeral driver that stripes across all NVMe disks for obscene throughput (multi-GB/s, ~M IOPS). No SANs, no LVM, no etcd—just raw speed you’re already paying for in L-series/Dv6/NC VMs. Use it for Spark shuffles, Dataflows Gen2 staging, Direct Lake caches, and AI model weights; keep durable truth in Blob/managed stores. Result: 3–5× faster pipelines and dashboards, lower Fabric capacity burn, and dramatically cheaper I/O. ACStor v2 reframes storage: NVMe = racetrack (hot, fast, disposable), Blob = archive (cold, durable, cheap). Bring the bytes to the CPU and watch “overnight jobs” fini…
Guest: Mirko Peters