Turn your real-world experience into part of the show.

Microsoft Security Episodes

Understand the intricate security measures within the Microsoft ecosystem, including identity management and data protection. Discuss best practices for configuring security in Azure and Microsoft 365.
Sept. 7, 2025

Fix Microsoft Purview Information Protection Rollouts

This episode takes you deep into the world of Microsoft Purview Information Protection and explains why it has become one of the most important pillars of modern data security. We walk through what information protection really means, why sensitive data is getting harder to control, and how Purview steps in with the structure, automation, and intelligence organizations desperately need. You’ll hear how Purview discovers and classifies data across Microsoft 365, on-premises servers, and cloud apps, how sensitivity labels drive encryption and access control, and why its integration with Microsoft Defender for Cloud Apps and Azure Information Protection creates a unified safety net around your entire data estate. We explore what it actually looks like to deploy information protection in the real world, from scanning legacy file shares to enforcing DLP policies that stop data from leaking through email, Teams messages, or cloud uploads. The episode also digs into advanced tools like th…
Guest: Mirko Peters
Sept. 7, 2025

Close the Microsoft Teams Channel Governance Gap

This episode breaks down the often-overlooked security implications behind something as simple as hiding or showing a channel in Microsoft Teams. It goes far beyond basic interface cleanup and focuses on how channel visibility ties directly into cybersecurity, threat detection, and organizational governance. We explore how Teams channels structure communication, why they matter for reducing noise, and why they can also become a weak point if not managed with the right security mindset. The conversation highlights how Microsoft Security Copilot and threat intelligence tools can spot anomalies inside channels, detect suspicious file activity, and help admins stay ahead of vulnerabilities or malware hiding inside everyday collaboration spaces. We walk through the real meaning of hiding a channel—why it’s a user-level visibility choice rather than a security control—and why relying on hidden channels for confidentiality is a mistake. Instead, the episode digs into the security layers t…
Guest: Mirko Peters
Sept. 6, 2025

Use Minecraft for Workplace Team Building

This episode explores a surprisingly powerful idea: that Minecraft, the block-building game millions already love, can actually teach real teamwork and team-building skills. Instead of treating Minecraft as just another video game, the discussion reframes it as a collaborative digital world where communication, coordination, and cooperation become the keys to success. Players quickly learn they can’t survive alone, can’t build big projects in isolation, and can’t reach ambitious goals without leaning on each other. The game’s open world becomes a training ground where shared purpose, role clarity, problem-solving, and planning naturally emerge. You start with “who gathers materials,” “who designs the structure,” “who explores,” and before long, you’re watching genuine collaboration unfold inside a virtual landscape. The episode highlights how educators and workplaces are harnessing this dynamic to build stronger teams. By setting up group challenges inside Minecraft—things like tim…
Guest: Mirko Peters
Sept. 5, 2025

Microsoft Defender vs Sentinel: When You Need Both

This episode breaks down the confusion many organizations face when trying to understand the difference between Microsoft Defender and Microsoft Sentinel, two tools that sound similar but play very different roles in the Azure security landscape. We walk through how Defender focuses on real-time protection at the endpoint, in Microsoft 365, and across cloud workloads, acting like an automated guard that detects threats the moment they appear. Sentinel, on the other hand, steps back and looks at the entire enterprise, pulling in signals from Azure, on-prem systems, and third-party tools to create a unified picture of what’s happening across the environment. While Defender reacts, Sentinel investigates. While Defender stops attacks at the source, Sentinel connects the dots and helps security teams understand the bigger story behind alerts. The conversation highlights why teams often struggle to choose between them—and how the choice isn’t really either-or. Defender excels in scenario…
Guest: Mirko Peters
Sept. 4, 2025

Prepare Microsoft 365 for German KRITIS Requirements

This episode takes a critical look at whether Microsoft 365 is truly ready for KRITIS environments, the highly regulated sectors where security, reliability, and compliance aren’t just important but mandatory. We explore why so many organizations in critical infrastructure struggle with adopting M365, even though the platform promises modern collaboration, flexibility, and cloud-driven productivity. The discussion highlights that the biggest challenge isn’t the technology itself but the gap between Microsoft’s default configurations and the strict requirements set by German KRITIS regulations and the BSI. Throughout the episode, we talk through the recurring concerns raised by auditors and IT leaders. Security limitations in standard M365 deployments remain a major sticking point, especially where identity management, conditional access, and privileged roles aren’t configured with maximum rigor. Licensing complexity adds another layer of frustration, as many of the security feature…
Guest: Mirko Peters
Sept. 2, 2025

Govern Microsoft Fabric Data Agents in Copilot Studio

This episode dives into the growing role of Fabric Data Agents inside Microsoft Copilot Studio and how they’re reshaping the way organizations interact with their data. The hosts start by breaking down what a Fabric Data Agent actually is—an AI-driven intermediary that gives users controlled access to selected data stored in Microsoft Fabric. Instead of digging through semantic models or navigating complex databases, users can query their data conversationally through an agent that understands both the structure of the data and the rules that govern it. It’s a major step toward making enterprise data more accessible without compromising security or governance. The conversation then expands into how Microsoft Fabric and Copilot Studio complement each other. Fabric serves as the unified analytics backbone, while Copilot Studio becomes the interface where custom agents are built, trained, and deployed. When these two worlds meet, organizations get a powerful, AI-enhanced layer that le…
Guest: Mirko Peters
Aug. 30, 2025

Harden Microsoft 365 Security Without User Friction

This episode dives deep into the foundations of Microsoft 365 security and why locking down your M365 tenant has never mattered more. The conversation opens with a look at what “Microsoft 365 security” truly means today: a constantly evolving mix of policies, controls, and intelligent protection layers designed to defend identity, data, devices, and collaboration spaces across the cloud. As the hosts point out, M365 may come packed with powerful tools, but those tools only work when organizations configure them intentionally. Without strong baselines, attackers exploit weak MFA, lax external access, and poorly monitored environments long before anyone notices. The episode highlights how Microsoft Defender for Office 365 plays a starring role in stopping modern threats, with anti-phishing policies, safe links, safe attachments, real-time alerts, and analytics that reveal attacks before users even fall for them. They stress that pairing Defender for Office 365 with Defender for Endpo…
Guest: Mirko Peters
Aug. 28, 2025

Scale Copilot Agents Safely in Microsoft 365

AI agents are powerful—and risky—when they run without guardrails. In this session, we show how Microsoft 365 Admin Center + Copilot Studio give you a practical control tower: who can build, who can publish, what data agents can touch, and how you monitor everything in one place. You’ll leave with a governance blueprint that unlocks Copilot without losing oversight.
Guest: Mirko Peters
Aug. 28, 2025

Manage Microsoft 365 Update Overload

Microsoft 365 pushes 300–400 changes every month. For most IT teams, the raw volume makes “staying aware” impossible — and pretending to read everything is fantasy. The danger isn’t the noise — it’s the 5% of updates that actually trigger outages, compliance exposure, licensing surprises, new reporting visibility, or destroyed workflows. This episode lays out the problem of update overload, and then gives a four-layer solution: 1. Filter — not every change matters to you 2. Assess — who actually feels impact (IT? legal? users?) 3. Strategize — move from reaction to repeatable triage 4. Communicate — without drowning people in useless patch-note text The takeaway: you don’t need to know everything — you need a system that spotlights the small fraction of changes that have real-world business impact.
Guest: Mirko Peters
Aug. 28, 2025

Govern Microsoft 365 Guest Access and Offboarding

Your Microsoft 365 tenant is probably full of “guests who never left.” Contractors, vendors, and partners get invited for short projects—and their accounts quietly live on for years. That sprawl creates hidden risk: lingering access to SharePoint and Teams, easy entry for attackers via compromised external identities, and avoidable compliance findings (ISO 27001, SOC 2, GDPR) for missing offboarding controls. This episode exposes the scope of the “silent guest pile-up,” why it’s dangerous, how audits uncover it, and the practical blueprint to move from chaos to lifecycle control: discover, triage, expire by default, and recertify only what’s still needed.
Guest: Mirko Peters
Aug. 23, 2025

Fix Microsoft 365 Guest Access Risks Across Services

Guest access in M365 isn’t a switch—it’s three identity layers and four services that don’t always agree. That mismatch creates silent exposure: a guest “allowed” in Teams can inherit broader SharePoint access; Purview often spots it after the fact. The fix isn’t a single toggle—it’s lifecycle + least-privilege + evidence. In this workshop, we give you a scalable framework to invite, govern, review, and retire guests—without strangling collaboration.
Guest: Mirko Peters
Aug. 22, 2025

Balance Microsoft 365 Zero Trust Security and Usability

“Zero Trust everywhere” and “freedom for everyone” both fail in production. One grinds work to a halt; the other invites disaster. In this workshop we show how top M365 orgs hit the operating sweet spot—where CISO, GDPR officer, and everyday users all win. You’ll learn how small portal changes cascade into big workflow pain, how to write Conditional Access that protects without breakage, and how to use PIM for just-in-time admin without bottlenecks. We’ll leave you with battle-tested guardrails, policy templates, and a 30/60/90 rollout plan so your tenant runs quiet, audits pass, and users stop noticing security—because it just works.
Guest: Mirko Peters
Aug. 21, 2025

Microsoft Entra as a Complete IAM Platform

Active Directory was built for office networks that barely exist anymore. Today, identities — not networks — are the real perimeter. Microsoft Entra isn’t “AD in the cloud”; it’s a suite designed for a hybrid, perimeter-less world: Entra ID for auth and conditional access, Permissions Management for multi-cloud least-privilege, Verified ID for portable credentials, and Identity Governance to kill access creep. This episode explains how Entra bridges legacy AD with cloud-first needs without breaking what already works, and how to move from static, network-based trust to adaptive, identity-first security aligned to Zero Trust.
Guest: Mirko Peters
Aug. 21, 2025

Automate Microsoft 365 Compliance Tasks with Power Automate

Compliance fails when it’s static. Checklists freeze rules in time, but regulations keep moving. In this episode, you’ll learn how to turn compliance from a brittle, manual checklist into a self-updating, feedback-driven system using Power Automate + SharePoint/Dataverse + Power BI. We cover recurrence triggers, adaptive workflows, centralized logging, escalation, governance at scale, and future-proofing via metadata and modular flow design — so your compliance process learns and updates itself instead of breaking every time a rule changes. Primary keywords: Power Automate compliance, automated compliance workflows, compliance governance, feedback loops, adaptive automation, SharePoint compliance library, Dataverse audit log, Power BI compliance dashboard, recurring flows, escalation policies, metadata-driven automation.
Guest: Mirko Peters
Aug. 20, 2025

Configure Microsoft 365 DLP Policies in Purview

This episode examines the real return on Copilot by focusing on outcomes rather than features. It argues that the biggest cost in modern organizations isn’t failed projects or bad strategy, but the quiet drain of routine work—emails, meetings, drafts, reports, and administrative tasks that create the appearance of progress without delivering meaningful impact. Copilot’s value comes from collapsing this everyday friction and returning time to people who rarely realize how much they’re losing. The episode explains how small time savings, while unimpressive in isolation, compound dramatically at scale. A few hours reclaimed per person each month becomes significant capacity across large teams. Whether that capacity produces value depends on intent: reclaimed time must be deliberately reinvested into higher-impact work instead of dissolving back into busyness. It also explores where these gains show up most clearly. In sales and marketing, reduced preparation and cleaner focus impro…
Guest: Mirko Peters
Aug. 20, 2025

Monitor Compliance in Microsoft Defender for Cloud

Most teams “pass” audits yet miss real misconfigurations between reviews. Microsoft Defender for Cloud changes that by turning compliance into a live posture: map your estate to frameworks (ISO/NIST/PCI), tailor controls to your own standards, auto-remediate drift, and surface results in Power BI for leadership. This episode shows how to build continuous, system-wide assurance—assessment → automation → evidence—across Azure, AWS, GCP and on-prem (Arc) without drowning in tickets. Keywords: Microsoft Defender for Cloud compliance, continuous compliance, Azure Policy, auto-remediation, regulatory compliance dashboard, Power BI security reporting, multi-cloud compliance, Azure Arc, NIST 800-53, ISO 27001, PCI DSS, governance at scale.
Guest: Mirko Peters
Aug. 18, 2025

Microsoft Purview vs Azure Information Protection

Think Purview and Azure Information Protection are “enterprise-only”? Think again. If you’re already on Microsoft 365 (E3 or Business Premium), you likely have sensitivity labels, baseline DLP, and email encryption ready to use—no extra spend. This episode debunks the biggest myth about data protection and shows a simple, fast path to label → protect → prevent leaks that small teams can deploy in an afternoon and big orgs can scale later.
Guest: Mirko Peters
Aug. 18, 2025

What Is Microsoft Intune Used For?

Microsoft Intune isn’t just device management—it’s the control plane for identity-aware access, protected apps, adaptive risk, and verifiable compliance across Microsoft 365. When Intune is wired into Azure AD (Entra ID), Microsoft Defender for Endpoint, and Microsoft Purview, you get conditional access that adapts in real time, app-level data protection on BYOD, automated threat-to-access responses, and governance evidence on tap. This episode shows how to move from GPO-era thinking to an identity-first, app-centric, zero-trust posture—without drowning users in friction.
Guest: Mirko Peters
Aug. 16, 2025

Audit Microsoft 365 User Activity with Purview

Auditing user activity in Microsoft 365 is no longer optional — it’s essential for security, compliance, and governance. Microsoft Purview provides powerful audit capabilities, but many organizations don’t use them correctly or fail to leverage advanced logging features. In this guide, we walk through how to enable auditing in Microsoft Purview, how to search and analyze audit logs effectively, and how to use audit data for threat detection, compliance investigations, and risk mitigation. Whether you're investigating suspicious behavior, preparing for a compliance review, or strengthening your security posture, this step-by-step breakdown shows you how to turn audit data into actionable insight.
Guest: Mirko Peters
Aug. 16, 2025

Secure and Govern Microsoft 365 Copilot

Copilot can overreach if Graph permissions are too broad. One mis-scoped app permission lets AI surface files, spreadsheets, and confidential client data users couldn’t normally access. Fix it by treating Copilot like any high-privilege app: lock Graph scopes to least privilege, segment access with Entra ID role groups, and extend DLP and sensitivity labels to AI-generated content in Exchange, SharePoint, OneDrive, and Teams. Use Purview Audit to trace who asked Copilot for what, from where, and when—and pipe signals to Sentinel for proactive alerts. Governed right, Copilot stays fast and useful without leaking sensitive data.
Guest: Mirko Peters
Aug. 15, 2025

Zero Trust Across Microsoft 365 and Dynamics 365

MFA isn’t Zero Trust. If Microsoft 365 and Dynamics 365 don’t enforce the same identity, device, and session checks, attackers walk through the side door. “Zero Trust by Design” treats M365 + D365 as one system: align Conditional Access and risk signals, apply just-in-time roles, segment identities by job, and continuously re-verify sessions across clouds. Tie it together with adaptive policies that cut MFA fatigue. Result: coordinated defenses, fewer blind spots, and strong security that doesn’t slow work.
Guest: Mirko Peters
Aug. 11, 2025

Microsoft Graph Permissions and Consent Models Explained

Most Graph-powered apps fail at rollout not because of code, but consent. Dev tenants allow broad testing; production enforces tight policies that block risky scopes. The fix is understanding Graph’s two models—delegated (user-in-context) vs. application (app-only, org-wide)—and requesting the minimum viable scopes that match how your app actually runs. Keep user data to delegated where possible; reserve app-only for unattended or cross-tenant jobs and plan for admin approval. Map tenant consent policies early, stage permissions (pilot → broaden), and document why each scope is required. Use least-privilege alternatives (e.g., Calendars.Read vs. Calendars.ReadWrite, Team.ReadBasic.All vs. full directory). Wrap with governance: pre-approval workflow, quarterly reviews, tagging, and audit logs. Result: fewer “admin consent required” popups, faster security sign-off, and a rollout that survives contact with real users.
Guest: Mirko Peters
Aug. 11, 2025

Power Platform DLP Policies for Developers

Power Platform Data Loss Prevention (DLP) policies don’t have to be mystery roadblocks. In this episode, we explain why Flows fail with cryptic DLP errors and show exactly how to prevent them—before production. You’ll learn how connector classifications (business, non-business, blocked), custom connectors, and tenant vs. environment policies interact; how to run pre-flight checks; and how to align dev/test/prod so migrations don’t silently break. We cover practical governance tactics: policy reviews, negative testing, alerts, and using the CoE toolkit—plus a clear checklist to keep Power Automate, Power Apps, and custom connectors compliant and reliable. Build faster, avoid midnight fire drills, and turn DLP into guardrails that protect data and keep your automations running.
Guest: Mirko Peters
Aug. 10, 2025

Secure Microsoft Fabric Data Pipelines

Microsoft Fabric pipelines often feel “secure by default,” but silent data exposure usually comes from misconfigured permissions, hardcoded secrets, and overbroad workspace roles. This episode shows how to harden end-to-end pipelines with managed identities (kill passwords), Azure Key Vault (centralize and audit secrets), and precise RBAC (least privilege at workspace, pipeline, and dataset layers). You’ll learn where Fabric inherits risky defaults, how tenant/workspace access quietly widens, and the exact steps to lock down connectors, notebooks, and pipelines—without slowing your teams. Walk away with a practical security playbook, audit-ready logging, and guardrails that let admins, analysts, and engineers move faster with less risk.
Guest: Mirko Peters