July 31, 2026

ENTRA PIM EXPLAINED: Securing Privileged Access with Mark Orr [MVP]

ENTRA PIM EXPLAINED: Securing Privileged Access with Mark Orr [MVP]
ENTRA PIM EXPLAINED: Securing Privileged Access with Mark Orr [MVP]
M365 FM Podcast
ENTRA PIM EXPLAINED: Securing Privileged Access with Mark Orr [MVP]

Mark Orr shares his extraordinary journey from serving three combat tours in Iraq as a United States Marine Corps radio and satellite communications specialist to becoming a Microsoft MVP, enterprise architect, and respected Microsoft security expert. He explains how military experience introduced him to networking, satellite communications, IP protocols, and infrastructure management before eventually leading him into Microsoft technologies, Microsoft Intune, Entra ID, automation, and cloud security. His career demonstrates how discipline, resilience, and continuous learning can create entirely new opportunities in enterprise IT.

WHY IDENTITY IS THE NEW SECURITY PERIMETER
Organizations often invest heavily in AI, Copilot, endpoint management, and advanced compliance while overlooking the single most important attack surface: identity. Mark explains why every security strategy should begin with protecting identities before implementing more advanced technologies. According to him, strong authentication, phishing-resistant credentials, and properly secured privileged accounts form the foundation upon which every modern Microsoft security solution depends. Without a secure identity layer, every additional security investment becomes significantly less effective.

WHY IDENTITY ATTACKS DOMINATE MODERN CYBERSECURITY
More than ever, attackers target identities instead of infrastructure. Mark explains that passwords remain one of the weakest links because people frequently reuse credentials across personal and business accounts. Once a password becomes compromised through another service, attackers often gain access to enterprise environments using the same credentials. This is why Microsoft continues pushing organizations toward passwordless authentication and phishing-resistant sign-in methods that dramatically reduce the attack surface.

PASSWORDLESS AUTHENTICATION SHOULD BE EVERY ORGANIZATION'S FIRST GOAL
Mark has been running passwordless authentication since long before it became mainstream. Drawing on years of practical experience, he strongly recommends moving organizations toward Windows Hello for Business, passkeys, Microsoft Authenticator passwordless sign-in, and hardware security keys such as YubiKeys. Besides improving security, passwordless authentication actually creates a better user experience by eliminating forgotten passwords while protecting users from phishing attacks and credential theft.

COMMON MISTAKES WITH PRIVILEGED ACCOUNTS
One of the biggest security mistakes Mark repeatedly encounters is administrators using the same account for both daily productivity and privileged administration. He explains why administrative identities should always be isolated cloud-only accounts without Exchange mailboxes, Teams licenses, or normal productivity workloads. Separating privileged identities dramatically reduces phishing exposure and prevents attackers from gaining administrative access through compromised user activities.

ZERO TRUST IS A JOURNEY, NOT A DESTINATION
Zero Trust is often treated as a final objective, but Mark argues that organizations never truly "finish" Zero Trust. Instead, security teams should focus on continuously improving their security posture rather than waiting for perfection. He recommends combining compliant devices, known networks, phishing-resistant authentication, Conditional Access policies, and trusted administrator workstations while continuously strengthening remaining gaps over time. Progress matters far more than chasing an impossible end state. HOW MICROSOFT INTUNE AND MICROSOFT ENTRA ID WORK TOGETHER Rather than viewing Microsoft Intune and Microsoft Entra ID as separate products, Mark explains how both platforms complement each other to create a unified security architecture. Entra ID protects identities through authentication, Conditional Access, and role-based access control, while Intune continuously evaluates endpoint health using compliance policies, encryption, antivirus protection, Secure Boot, and device configuration. Together they allow organizations to grant access only when both the user identity and the device satisfy security requirements.

ENTRA PIM EXPLAINED
Privileged Identity Management (PIM) introduces the concept of Just-in-Time administration. Instead of permanently assigning highly privileged roles, administrators elevate only when necessary to complete a specific task. Mark explains how temporary elevation dramatically reduces security risks by minimizing the amount of time privileged permissions remain active. Organizations embracing least privilege significantly reduce the opportunity for attackers to abuse compromised administrative accounts.

WHY ADMINISTRATORS SHOULD STOP LEAVING ROLES ACTIVE
Many administrators prefer keeping privileged roles active throughout an entire workday because it feels more convenient. Mark argues that this convenience creates unnecessary risk. His recommendation is to activate administrative roles only when performing a specific task and deactivate them immediately afterward. Even where organizations permit longer elevation windows, he prefers limiting sessions to four hours or less to ensure elevated permissions never remain active while administrators are away from their workstations.

BUILDING INTREPID TO SIMPLIFY PRIVILEGED ACCESS
To solve the inconvenience of repeatedly activating multiple privileged roles, Mark developed Intrepid, a PowerShell tool that automates bulk activation of Microsoft Entra PIM roles while fully respecting Conditional Access policies and Authentication Context requirements. Every

Become a supporter of this podcast: https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support.

🚀 Want to be part of m365.fm?

Then stop just listening… and start showing up.

👉 Connect with me on LinkedIn and let’s make something happen:

  • 🎙️ Be a podcast guest and share your story
  • 🎧 Host your own episode (yes, seriously)
  • 💡 Pitch topics the community actually wants to hear
  • 🌍 Build your personal brand in the Microsoft 365 space

This isn’t just a podcast — it’s a platform for people who take action.

🔥 Most people wait. The best ones don’t.

👉 Connect with me on LinkedIn and send me a message:
"I want in"

Let’s build something awesome 👊

1
00:00:00,000 --> 00:00:14,500
Yeah, hello everybody and welcome back to the MC65s and podcasts today's guest combines military discipline enterprise architecture and passion for helping IT professionals mastering Microsoft technologies.

2
00:00:14,500 --> 00:00:27,500
Here's the Microsoft MVP Microsoft focused architect technologist with as marine cops combat veteran community culture, speaker mentor and open source advocate after certain three.

3
00:00:27,500 --> 00:00:39,500
Truus in Iraq, he built a career healthy organization world, the size identity and point management and security with Microsoft into Microsoft and try to power shell and automation.

4
00:00:39,500 --> 00:00:59,500
Now for turning during complex Microsoft concepts into practical guidance scripts and real good solutions, he dedicated called us hours to sharing knowledge with the Microsoft community today real deep dive into my windows device management Microsoft into Microsoft and try to.

5
00:00:59,500 --> 00:01:18,500
And especially and sharp public identity management, one of the most important technologies for implementing zero trust and protecting up and stuff access mark or well it's absolute pleasure to have you here on the on the podcast black onto the show.

6
00:01:18,500 --> 00:01:41,500
Hey, I appreciate you having me join and excited talk anything and everything Microsoft cloud, whether it's an intra ID and indoor in soon, I'm done a little bit of everything in my career and so I love it and I love to talk about it.

7
00:01:41,500 --> 00:01:53,500
Yeah, you work at the marine corpse and now you're in at heat professional can you little bit tell us about your journey.

8
00:01:53,500 --> 00:01:59,500
Yeah, so sort of my journey into where I am today.

9
00:01:59,500 --> 00:02:16,500
I joined the United States Marine Corps in 2005 and at that point, I was a radio operator and so we did wine of site communication and so that line of sight communication.

10
00:02:16,500 --> 00:02:30,500
You think of it like an FM radio is you drive through town you you lose signal and then you come to another town and then you may gain signal on a different radio station.

11
00:02:30,500 --> 00:02:52,500
So it was exactly what you would would think it's wine of site if you can see the antenna you can talk. But with that pivoted to rather quickly in the midst of operation Iraqi freedom and operation and during freedom was IP based communication.

12
00:02:52,500 --> 00:03:03,500
And what this meant was satellite communication and so we started to get into the realm of on the move satcom.

13
00:03:03,500 --> 00:03:21,500
And so I did from that calm for a time, but where my IP career really started was in satellite internet concept of zipper nipper very small aperture terminal and so it's a really long acronym for satellite internet.

14
00:03:21,500 --> 00:03:33,500
And so kind of what this looked like is I'd be either I'd obtain a satellite antenna.

15
00:03:33,500 --> 00:03:39,500
We would point the satellite antenna at a.

16
00:03:39,500 --> 00:04:04,500
Asmith in the sky so satellite and then so then you would have your commercial internet you'd have your secure internet and you're very secure internet and then that's when I started to learn IP protocols and you know how to tip a cat five cable.

17
00:04:04,500 --> 00:04:30,500
How to you know manage a subnet and I kind of took that's and ran with it and when I came back to the United States they basically ball and told me and said as the ring for does basically made me the director of IT.

18
00:04:30,500 --> 00:04:39,500
And so I managed all of the network infrastructure end point share point all of that sort of stuff.

19
00:04:39,500 --> 00:04:45,500
And that's how I kind of got introduced into the Microsoft cloud.

20
00:04:45,500 --> 00:05:01,500
And they wanted to do an on-prem share point migration to the cloud and so that was my first first introduction into Microsoft cloud services.

21
00:05:01,500 --> 00:05:13,500
Yeah in the military have you learned something like skills or habits that that helps you are today and working in enterprise at.

22
00:05:13,500 --> 00:05:36,500
Yeah for sure I've got a friend of mine who's in the sheriff's department for 25 plus years and when I got out of the Marine Corps sometimes he'd give me a hard time and he'd say I'm walking around with a chisel and a hammer and we're going to knock some of that marine off.

23
00:05:36,500 --> 00:05:58,500
I think the thing is right like so if an application service endpoint is down you know in most commonly an end user can't do what they need to do in the Marine Corps.

24
00:05:58,500 --> 00:06:24,500
When a service was down it might have been like or death you didn't really have a choice you had to get it back up and be operational in in in some way right and so whether that was scrapping the whole thing and doing it the way you knew could work or just trying to get the existing system back up there was no.

25
00:06:24,500 --> 00:06:50,500
Like having having a system down was not an answer that was acceptable and so I think that I've kind of taken that with me is like gone into the private sector and into enterprise like the one that I managed the day we just don't take no for an answer and we're going to make sure that the service is up as quickly as humanly possible.

26
00:06:50,500 --> 00:07:15,500
My boss kind of jokes you know and says nobody's going to get hurt nobody's going to you know lose life limb or eyesight but we got to get it back up and we got to get the system no matter what it is back in operational inside I take pride in up time if that makes sense.

27
00:07:15,500 --> 00:07:42,500
Yeah one week but I think a little bit it's not really true because when you get hacked or or identity gets stolen I say it's called the we say in Germany in the army we say blue land for the red land and so on when red land gets the information it's also not so so good but the yeah.

28
00:07:42,500 --> 00:08:00,500
That's a deep dive in identity topic I think we often hear especially from Microsoft and other experts identities in new party major what does it actually mean from your perspective.

29
00:08:00,500 --> 00:08:29,500
Well I think that I'm trying to think about where I want to start here and so when I when I come into an organization or I listen to friends in the industry or I did sit and contract the roles and I do an evaluation I hear things all the time right like we want to do this day I model and we want to do bad a I model and.

30
00:08:29,500 --> 00:08:58,500
We want co pilot and we want device compliance and we want these 14 criteria for device compliance and I say okay I hear you understand what are we doing for multifactor authentication and they say well we have some users on SMS we have some users that do authenticator plus number matching some of the things that we do.

31
00:08:58,500 --> 00:09:18,500
Some of our privileged users have passed ease and I'm I think that I'm going to say well we need to stop before we can go do anything with sophisticated device compliance or custom device compliance let's focus on the identity planning.

32
00:09:18,500 --> 00:09:40,500
Oh but we have to have AI we have to have a share point readiness well if you're if you're not going to protect the identity we're approaching us backward we have to protect the identity plane first right and more more importantly then an end user we have to protect.

33
00:09:40,500 --> 00:10:09,500
So the first place I start is an amit them we get to password this authentication right and so what the what the desired goal here is is to get to a compliant device that uses fishing resistant authentication and you can you can even take it a step further but I'll hold on to that until we start talking about.

34
00:10:09,500 --> 00:10:35,500
We start talking about intrapam the the issue that I see and it's seen multiple times across multiple clients is well we don't want to inhibit the end user it's too much of a lift to get to pass keys or password list and my response back is once you get to password list once you get to pass keys.

35
00:10:35,500 --> 00:10:55,500
So you're protecting your identity plane and you're making it more convenient for the end user at the same time so so it's a win win and so from my perspective the identity is the most important vector that exists.

36
00:10:55,500 --> 00:11:23,500
I see a study in Europe any form a person of all attacks are identity attacks yeah why did the take us choose identity is more often than I say attack the infrastructure well people have habits and people are the point of entry right and so I don't know how many times I've seen people.

37
00:11:23,500 --> 00:11:43,500
I use the same password the network that they use for their eye cloud they come across their eye cloud and then to their personal Microsoft account and so if one account get attacked that entire password repository for lack of better term is essentially.

38
00:11:43,500 --> 00:12:12,500
I'll be open internet and then so bad behavior process right and then that net clicks password that is hacked ends up in an enterprise right so even if you do take the extra step and you say I'm going to do number matching plus password if not really that hard to grab a code right and it's really not that hard to grab.

39
00:12:12,500 --> 00:12:41,500
And as a hard to grab an SMS you see YouTube videos of people cracking SMS all the time and in the starting point is a password and so if humans are continue going to continue to be humans and have bad behavior identities will always be the number one attack vector until they're not right until passwords aren't a thing anymore.

40
00:12:41,500 --> 00:13:06,500
And so I've been doing password with authentication since 2019 since before it was cool or trendy and so we're coming up on my seventh year of password was authentication whether that windows will open for business password was an authenticator UBT.

41
00:13:06,500 --> 00:13:16,500
And the number one thing I would spell any organization is to get passwords out and get passwordless in.

42
00:13:16,500 --> 00:13:24,500
Yeah we see where we look at the end to the danger.

43
00:13:24,500 --> 00:13:36,500
You were have a lot of experience what did companies doing wrong with privileged accounts what's the mistakes you often see often.

44
00:13:36,500 --> 00:13:53,500
Yeah the the biggest mistake that I see in lots of organizations make this mistake right is I see I'm a global admin right on on a medium size or small business and so the global admin does lots of things they manage teams.

45
00:13:53,500 --> 00:14:01,500
They manage exchange they manage the whole m through 65 stack whether that.

46
00:14:01,500 --> 00:14:21,500
That's a per view power app you name it right but they also manage in tune they also manage Azure and so in those types of organizations the primary thing that I see is we're managing those administrative accounts with our productivity account.

47
00:14:21,500 --> 00:14:40,500
And so we we don't practice best practice and having a cloud only active directory disconnected into a heart and account that only interacts with admin and admin task.

48
00:14:40,500 --> 00:15:04,500
And so what you're essentially doing is you're not broadcasting to the world that that has credentials but if it does have if it does have the ability to either access administrative task if you're sending emails sending teams that's a fishing opportunity right.

49
00:15:04,500 --> 00:15:16,500
And so what we want to do is create a cloud only isolated account with no productivity license at all and then in privilege.

50
00:15:16,500 --> 00:15:32,500
And I think when we look at the security groups and so on there it's one word or towards zero trust we have a year every time how do zero trust influence identity architecture today for your perspective.

51
00:15:32,500 --> 00:16:01,500
So from my perspective you're never going to get to zero trust you're never going to get there zero trust is a is a moving moving target and every time we discuss zero trust which say well what about this vector and what about that vector and so the thing that I push folks to is don't let perfect get in the way of better right.

52
00:16:01,500 --> 00:16:29,500
And so when we when we look at that zero trust architecture and we start talking about device compliance lost password was authentication or plus fishing resistant authentication from a zero trust perspective you want to take a device from a known network right a network that we trust right on a.

53
00:16:29,500 --> 00:16:58,500
client VPN or inter private access or reverse proxy what you want to say we have the set of device compliance criteria right whether that's a bit walker enforcement and I virus whatever fits best for your environment and we could probably have a whole podcast on that topic plus plus fishing resistant authentication plus.

54
00:16:58,500 --> 00:17:15,500
Another layer to that is when you're doing administrative task you do what's the what's called device filtering right and so you say if I have an administrative account the device has to be compliance.

55
00:17:15,500 --> 00:17:44,500
It has to be unknown workstation and we have to do fishing resistant right and so if you can if you can accomplish that right if you can accomplish that objective a compliant device on a known network with fishing resistant and a known good workstation don't let the overwhelming portion of zero trust get in the way of good and great.

56
00:17:44,500 --> 00:18:10,500
Don't I feel like zero trust is a is a moving target and I see so many organizations get paralyzed trying to be perfect let's get let's get as good as we can get within reason and then narrow our focus towards the five or 10% that were missing right so many organizations don't do things like

57
00:18:10,500 --> 00:18:22,500
enter a hardened accounts device compliance enforcement known workstation that we missed before us through the trees.

58
00:18:22,500 --> 00:18:39,500
I think when we Microsoft had a lot of solutions especially in cybersecurity but when we talk about identity management there are say two tools they stand out it's one of the one size in tune and the others and

59
00:18:39,500 --> 00:18:41,500
the others enter ID.

60
00:18:41,500 --> 00:18:49,500
How come yeah how complete meant these to which each other from your perspective.

61
00:18:49,500 --> 00:19:08,500
Yeah so I'm supposed to compliment one another right and so I don't feel like you can do one without the other and so what I have always pushed push people to do is to manage their identity doing

62
00:19:08,500 --> 00:19:29,500
the things that I've already previously mentioned right and so if you're doing fishing or this is an authentication then you pivot to the device right and so when you when you pivot to the device a couple of things that I look at to support the identity

63
00:19:29,500 --> 00:19:55,500
of the first thing that I do is I would look at windows hello for business are we using windows hello for business yes or no and so once we establish windows hello for business then we're fishing resistant at the end point right and so you want to be fishing resistant in an interactive browser right when you go to

64
00:19:55,500 --> 00:20:02,500
the bottom of the window you sign in but you also want to be fishing resistant on the device.

65
00:20:02,500 --> 00:20:24,500
But then when you get law bent of the device the things that we're looking for from a device compliance perspective is is secure secure boot enabled do we have an antivirus protection enabled and you can even go as far as saying are you coming from a known work station and

66
00:20:24,500 --> 00:20:53,500
tie that into a compliance rule and those compliance rules are governed by Microsoft into and so what Microsoft into does is you apply a compliance policy and you say you have to meet these criteria in order to be compliant and then it sends that compliance signal back to enter ID and it basically says yes or no for each one of those criteria and so at that point

67
00:20:53,500 --> 00:21:18,500
what what you're evaluating is conditional access right and you're saying this device has to be compliant in order to act as company for resources and in any of those things aren't true then the device can access those resources so when you utilize things like fishing resistant MFA at the identity

68
00:21:18,500 --> 00:21:30,500
plan and you can bind it with conditional access and device compliance in Microsoft into you get the best of those worlds.

69
00:21:30,500 --> 00:21:44,500
Yeah Mark you you are really knowing or famous for the Microsoft adra pin topic what exactly is Microsoft and Republic identity management.

70
00:21:44,500 --> 00:22:13,500
Yeah so when you look at it in intrapim you're talking about it the it the root of it you're talking about just in time access right and so when we're talking about just in time access we're we're talking about I have an intra ID role that doesn't administrative task right and so when I first came into the industry

71
00:22:13,500 --> 00:22:38,500
I saw lots of bad practices right Microsoft says five global admin or last I would come into some client and I would have 12 global admin and they would all have persistent permissions and so at some juncture in my career Microsoft introduced privilege identity management

72
00:22:38,500 --> 00:23:07,500
and so what what that says is we no longer have persistent permissions and so the account isn't privileged statically and so what that does is through hand enabled security groups right you can activate your role as needed and so when you activate

73
00:23:07,500 --> 00:23:36,500
you can activate your role for specific period of time and so what we try to do right is practice least privileged access and so what that kind of looks like is what role am I in as an administrator what am I doing right and so things that stick out to me is I will have somebody who is an into an administrator

74
00:23:36,500 --> 00:23:54,500
or a global admin need to remove someone from a group and so they will elevate to global admin in the privilege identity management console to global admin or into an admin to go remove a user from a group

75
00:23:54,500 --> 00:24:17,500
all all the meanwhile they've got group administrator why on earth did we just elevate a significantly more powerful role when you add the role assigned to you and so when you when you look at him and just in time access

76
00:24:17,500 --> 00:24:43,500
and one of the things that I guide organizations to is to have a tightly coupled elevation windows right and so I hear from administrators all the time well when I elevate my role it should be for nine hours it should be for eight hours I don't want to elevate it to three times a day and I say

77
00:24:43,500 --> 00:25:11,500
well your shift is eight hours of never going to give you more than eight but really what we should do for my perspective is we should be elevating doing a ticket or a task and then we should be deactivating our role but humans are humans and so the Institute of technology actually just agrees with me on this but this is a kill that I will die on

78
00:25:11,500 --> 00:25:34,500
I set roles should elevate no greater than four hours so if you simulate your day and you start your day at eight a.m. we typically take a break at 12 and we go eat some food so my goal with a four hour elevation is that the session never goes unattended

79
00:25:34,500 --> 00:25:53,500
and what I mean by that is you're typically in front of your machine for that four hour period before you go step away for lunch and at that point in the little expire and when you come back you re elevate it approximately one p.m. and you've got your permission for the remainder of the shift

80
00:25:53,500 --> 00:26:17,500
but in practice even that is a bad practice just in time elevation should be task driven and when the task is complete deactivate your role because you're opening yourself up to risk not only to yourself but to the organization

81
00:26:17,500 --> 00:26:34,500
and sometimes it just boils down it boils down to I don't want to be inconvenienced and we can we can talk about a tool that I've built to help with that inconvenience if you if you want

82
00:26:34,500 --> 00:26:56,500
yeah yeah that's how was this call to tool yeah so when you manage multiple modalities inside of intra and office 365 whether that's teams groups

83
00:26:56,500 --> 00:27:22,500
or it's in tune different blades inside intra you can accumulate several roles right and so lots of people have six seven eight roles and so they tell me well mark I've got to activate this role and then I have to do my UB key and then I have to come back can I have to activate that role

84
00:27:22,500 --> 00:27:47,500
and so I developed a power shell tool called intrapen that's on the power shell gallery and so what intrapen what you do is use power shell seven to bulk activate roles with justifications that follow your conditional access policy right so it'll never let you go over what the policy is

85
00:27:47,500 --> 00:28:08,500
and it handles a concept called authentication context inside your conditional access so what that means is you have to prove you are who you say you are every time you elevate a role it does not save the token the off token

86
00:28:08,500 --> 00:28:36,500
and so those off context and conjunction with conditional access makes you authenticate with a UB key or password matching on every role elevation so even if a even if a bad actor got your account in your credential they'd have to be able to satisfy MFA to gain access to your account

87
00:28:36,500 --> 00:28:40,500
and we do all of that through power shell

88
00:28:40,500 --> 00:29:08,500
yeah awesome so yeah then I say to all the people that listen to this episode you find all the stuff and links in the show notes on the M365 podcasts so you can find the link from like or still there so yeah and will this or can organization require justification before innovation

89
00:29:08,500 --> 00:29:10,500
is this possible?

90
00:29:10,500 --> 00:29:37,500
yeah so the way that I have seen most organizations handle privilege identity management is with self activation right so I'm an administrator I need to go do a task I write a justification I'm able to auto elevate right and so one of the things that I see leverage the

91
00:29:37,500 --> 00:30:05,500
least amount is requiring a ticket and an approver right and so at big fortune pot of 100 companies a lot of them require a service first ticket back to their ITFM so there have to be a task associated with the elevation and then there's an approver especially for high privilege roles like global admin and

92
00:30:05,500 --> 00:30:33,500
administrators especially in the lake of the striker attack where they deleted all of those machines right we started to look a little bit more closely at how we were doing elevations because they were able to get access to an account and then create another account and if there would have been an approval work flow that might not have happened

93
00:30:33,500 --> 00:30:49,500
and so yes you can require approvals I recommend every organization require approvals and part of the reason that a lot of organizations don't require approvals is because there's a gap

94
00:30:49,500 --> 00:31:18,500
and the only way that the approver is notified of a request for approval is through email and so because of that what happens oftentimes is a junior administrator will request elevation and then marks in a meeting or mark went to the grocery store he didn't see it and then the administrators saying to me mark

95
00:31:18,500 --> 00:31:38,500
you're going to approve my request can you please review it and it's stuck somewhere in an email and so I see a lot of a lot of push back on that but where there's a well there's a way you can get those out to Microsoft teams and make that a little more user friendly

96
00:31:38,500 --> 00:31:53,500
yeah and there's also a topic I think every company loves it's to be out of it. What's the out of capabilities to us to pin provide say one more time?

97
00:31:53,500 --> 00:32:05,500
yeah I think what out of capabilities to us pin provide is just a outage I apologize.

98
00:32:05,500 --> 00:32:31,500
yeah audition audition when when some comes to to approve. Oh gotcha so it's highly audible right so you can do an access review on privileged identity management request and so a lot of organizations when somebody writes a justification for the elevation.

99
00:32:31,500 --> 00:33:00,500
I you sometimes you could just write cat's cat's cats because no one's reading what that justification is and so I've worked really closely with administrators across multiple roles right a good justification because if when you elevate right then you go out and you do a thing right we may need that audit trail to say hey you elevated to remove someone from the group but that's not the only way to do it.

100
00:33:00,500 --> 00:33:20,500
that's not the only thing you did when you elevated right and so if you can have task based driven justifications it makes it more highly audible and then if you can layer approvals on top of it it gives you another layer of

101
00:33:20,500 --> 00:33:32,500
other ability and protection of something where to go wrong you can you can trace an event or an outage back to an elevation.

102
00:33:32,500 --> 00:33:49,500
and yeah there's especially in Europe we have one thing we all love it's to be compliant what compliance requirements become easier with Microsoft and try to pin.

103
00:33:49,500 --> 00:34:16,500
yeah and so every industry has different regulatory compliance requirements right whether that's frb with the federal reserve board whether that's hip whether that's gdpr those sort of things my my message is it pertains to this right is.

104
00:34:16,500 --> 00:34:45,500
to have a paper trail right and so if you can go from point of elevation to point of action or outage or events and go backwards from event to action to elevation and you can show the audit trail with the rationale and the justification your you may not make every auditor happy but you'll.

105
00:34:45,500 --> 00:35:13,500
it least be able to tell your side of the story you'll be able to provide each piece of the puzzle and auditors is difficult as they can be to work with in a highly regulated inden's industry where specific compliance rules are enforced.

106
00:35:13,500 --> 00:35:33,500
they don't lose common sense and so they can see the thought process all the way through and then they can trace it back to an elevation and it can help with compliance and audit reviews as they happen quarterly by annually and annually.

107
00:35:33,500 --> 00:36:01,500
did you see common deployment mistakes when company start with thin yeah i think i think the most common one is they read the document and then they put it in and they're like oh it says multi factor authentication but then i go review and we never looked at authentication context so when you enforce.

108
00:36:01,500 --> 00:36:30,500
mfa it only requires mfa one time and the token continues to be satisfied and so each prerequisite elevation doesn't require an mfa challenge and so i i've done that it wasn't until i think 24 that i was kind of told by a k this is what an off context is.

109
00:36:30,500 --> 00:36:56,500
we need to enforce authentication every time and tie it to the conditional access policy that way your force to verify you are who you say you are and every elevation that's a big one and then the next one i see right is everybody says well we want to use device compliance as our.

110
00:36:56,500 --> 00:37:16,500
enforcement mechanism right but we're not to device compliance yet and they say well what do i do and i say well there's a concept called device filtering right so even though you're not.

111
00:37:16,500 --> 00:37:38,500
at a place where you're ready to enforce device compliance by conditional access you can use an object ID from from a device and you can say if you're not coming from this device we're not going to allow you right and so that's a that's a shortcut to device compliance and so.

112
00:37:38,500 --> 00:38:07,500
If you're not doing device compliance use authentication context use device filtering and tie them into conditional access and if you are using device compliance layer that device filtering on top right that way each admin has a primary workstation and if a bad actor were to compromise some credentials or did get a whole of an account.

113
00:38:07,500 --> 00:38:21,500
If they're in another city state from an unknown device there's nothing that they can do it's a full stop they're just blocked.

114
00:38:21,500 --> 00:38:35,500
A lot of companies also I heard often it's the CFO or the fine ups dudes how did the licensing works on on enter ID.

115
00:38:35,500 --> 00:39:02,500
So I never think that security should be restrictive but for intrapem I believe you need a p2 license which comes at an additional cost but it while it's an additional cost that I my perspective is is it not cost prohibitive it doesn't it's not a full stop but it's if you're in a csp it's per user per month per year.

116
00:39:02,500 --> 00:39:23,500
And then if you're in an EA work with your value added reseller when you have an e3 or an e5 with e5 would be included and then with e3 I'm sure that they could work something out with you to give you some step up pricing but there is a cost consideration there.

117
00:39:23,500 --> 00:39:40,500
Yeah also passionate about the power shell why is automation such an important skill I think a little bit about the infrastructure code as keyboard.

118
00:39:40,500 --> 00:40:08,500
Yeah so so I I went and got my graduate degree in information technology right and so I thought I was God's gift IT and got a good GPA I graduated I kind of told my manager I want a promotion my manager came back and said well you're going to need the

119
00:40:08,500 --> 00:40:32,500
power shell first and I had no earthly idea of the what power shell even was right and so the whole concept around windows 10 and windows 11 is if you can click it you can automate it right and so the mechanism by which you automate it is power shell and so for me I don't

120
00:40:32,500 --> 00:40:59,500
have a graphical user interfaces and so my my boss will give me a hard time or my co-workers will give me a hard time and they'll say like mark created another power shell modular mark created another terminal user interface tool cool but there's some real world limitations to graphical user interfaces right and I'll give you an example I

121
00:40:59,500 --> 00:41:02,500
message from a client.

122
00:41:02,500 --> 00:41:27,500
Pim is down and I said I know and they said back to me well we've got to employ the acting a fool right now I said okay I said did you try to activate your role using power shell and they said no how do you do that and I said deep breath go grab this power shell

123
00:41:27,500 --> 00:41:51,500
module and see if you can elevate and low and behold they could and then they said but interest down how do I block them and I said well let me give you some commands to kill their last session change their password and log them out and the client came back to me and kind of said how on earth did you even know to do that and they said well how did you know that it

124
00:41:51,500 --> 00:42:15,500
worked would work and I said because the API never went down the graphical user interface did so you're interacting directly with the API through Microsoft graph and that service never went down so power shells going to work now that's not 100% no technology is but in this particular instant the graphical user

125
00:42:15,500 --> 00:42:36,500
interface crashed and died the power show worked and we saved that particular client a lot of reputation damage because the employee was just simply disgruntled and was going to swing mud in a wall until something stock and so we got them out of the environment and

126
00:42:36,500 --> 00:43:01,500
off-boarded through power show and that is the one real world example that I give repeatedly because I don't know how many times the guise had a delay or the guise had a problem but I go to power show and it works and then I just kind of move on with my day but that's the example that I like to call out often.

127
00:43:01,500 --> 00:43:14,500
Yeah so you have to do go for the hard way to learn power shell can you give some advice to add in the structure letting power shell today a little bit more easier.

128
00:43:14,500 --> 00:43:43,500
Yeah for sure so when I start to talk about my journey into power shell I wrote a blog and I kind of made fun of myself and I titled the block bro I don't know how to code my power shell journey and so when I first started power shell looked a lot like this I would go to a stack of workflow I would go Google something I would go ask a developer

129
00:43:43,500 --> 00:43:59,500
hey how do you do this right and so I got to stop myself and I said if there's a task and the guise that I have to do three or more times the first time what's

130
00:43:59,500 --> 00:44:15,500
the power shell right and so I would go out to a stack overflow I'd find a GitHub I'd find a command it worked right but then I would be like what was that command what was that script where did I save it what did I do.

131
00:44:15,500 --> 00:44:42,500
And so one of the ways that where my power shell journey kind of took off was what the tool called PS red line it's a power shell module that stores your history in your terminal so when you do it connect MG graph or you do a start dash intrapem or you type a big long graph query right it stores it to memory

132
00:44:42,500 --> 00:45:08,500
and then all you have to do is remember the first couple of characters of the command and it will show you all the history of the things that you've done successfully in the past and then all of a sudden right I started to be like I remember this we can make a pattern out of this we can repeat over and over again and then it just became second nature

133
00:45:08,500 --> 00:45:26,500
and so I started with ps red line and I'm just going to call a spade a spade and take two seconds to use your platform to talk about something that meaningful and powerful to me and that's the use of AI.

134
00:45:26,500 --> 00:45:55,500
The use of AI to learn how to code make the AI work for you don't have the AI do your job when when you do it's really easy to say right this code for me push it to get up and so what I do is I say I want to get these device details from into I want to get a detail about a user from intrapem.

135
00:45:55,500 --> 00:46:23,500
I want to get a user from intrap id give me the commands let me execute the code and then there are multiple times when I'm doing something that I don't understand I will literally type it out from one screen to another and I'll follow a do while loop for all follow a try patch through the block of code

136
00:46:23,500 --> 00:46:52,500
and then I just kind of become is my senior developer because two three years ago I would have had to go on the phone and said hey senior developer I'm stock right and so what I've done with AI is instead of just having it right my code for me I've had it teach me and so if I don't remember something and I type it in for my power show seven terminal and ps red line doesn't know what I'm talking about I say

137
00:46:52,500 --> 00:47:20,500
hey quad hey code X what is the command for da da da da da da and then it says well here's here's the command and I say okay now I'm going to execute it in power shell seven here are the results and then I say things like why are these results this way what can we do differently how can we expand that data type stuff like that and and so

138
00:47:20,500 --> 00:47:38,500
a basketball code said this to me one time right if you want to get good at basketball play basketball if you want to get good at power show stop relying on the graphical user interface find a place to start

139
00:47:38,500 --> 00:48:03,500
and then do it repeatedly once you solve the small problem graduate to a slightly bigger one and a bigger one and a bigger one use ps red line use artificial intelligence but use it smartly to teach back and then over time you will develop skills and tools that you

140
00:48:03,500 --> 00:48:20,500
recognize until you just realized you entered 30 lines of code you didn't look at a single thing my clubs uh yeah I think this AI example is it's really good I have try out a tool I think it's called

141
00:48:20,500 --> 00:48:47,500
a store and you can check github's our secure there are and so on and more simply do it's it's use nine I think nine mm else and check the same code and then they say what's not more sort of cure and the funny thing is it's there there are some some really good scripts but a lot more than

142
00:48:47,500 --> 00:49:03,500
half have hard coded the the the the the pass keys the pass words it so so much for the community what community contribution are you most proud of

143
00:49:03,500 --> 00:49:19,500
yeah so from a tools perspective I think I'm proud of the autopilot clean up and so what that particular tool does is when you need to migrate or

144
00:49:19,500 --> 00:49:39,500
off board and autopilot device there's three records right there's an autopilot record an in tune record and an enter ID record and so what often happens is someone will forget to delete the in tune device or they'll remove the device hash or they'll maybe do both them and they'll forget right

145
00:49:39,500 --> 00:49:57,500
the remove the enter record and then we have a bunch of orphaned records and a mass but that project took me to a place where I really had to stop and think that a lot of a lot of people

146
00:49:57,500 --> 00:50:15,500
put me feedback on the tool and one person an IT professional reached out to me and said hey could you have the white function I said sure so we'll white the device will delete the autopilot registration the in tune record and the enter ID

147
00:50:15,500 --> 00:50:35,500
and then he said you think this could be used for migration nice that well what do you mean and he said well an autopilot device hash can't exist few places at once I said right and I said do you have the hashes and he said yes

148
00:50:35,500 --> 00:50:55,500
and I said well you could send a white command to all of your devices and bulk and then you could remove the autopilot record and the in tune record and the enter record and then upload the hashes into the new tenant and the way you go completely reset

149
00:50:55,500 --> 00:51:23,500
hash is uploaded the user turns the device on and it picks up the new enrollment in a way they go and so he called me and said I'm having some problems I said well I'm more than happy to jump on and we worked for it and he was able to bulk remove and clean up all the records and then import and then roll and then one day they went from one tenant to another tenant in a eight hour shift

150
00:51:23,500 --> 00:51:51,500
and I was super proud of it but it made me stop and think right so I wasn't an MVP at that point a lot of people post blogs content that type of thing and then it's cricket or ghosts right and so one of the things that I've sort of challenged myself was if you're going to write content or produce content

151
00:51:51,500 --> 00:52:11,500
and help people speak don't just talk about it be about it so if somebody has a question answer it help hop on a call and so from a contribution perspective I think that the thing that I'm most proud of is helping others being available

152
00:52:11,500 --> 00:52:31,500
living up to that MVP status that it's not just the three letters next to my LinkedIn that I actually care and we're actually going out and helping other people right and so I think that's my biggest contribution to the community because I don't know everything

153
00:52:31,500 --> 00:52:43,500
and I never will and so if I don't know the answer I'm going to go reach out to that community we're going to go find the answer I'm going to bring it back to you and I'm going to help you

154
00:52:43,500 --> 00:52:49,500
and if I'm not the right person to help you let's go find the person who is.

155
00:52:49,500 --> 00:53:04,500
Interesting you say something interesting so I'll go a little bit back you say from one to other pennant what capabilities have Android from multi tenant or geo tenant and my amons.

156
00:53:04,500 --> 00:53:32,500
Yeah so from a migration perspective cloud to cloud migrations works supported and you had to use third party tools to migrate from one tenant to the other right and so when you migrated workloads it looked like using a third party tool and then assessing your work loads and those

157
00:53:32,500 --> 00:53:57,500
and a variety of things right and that was kind of a solved problem and so Microsoft introduced very recently I can't remember the date but they have comprehensive tools now to migrate cloud to cloud but that doesn't solve the end point right Microsoft's guidance is still a wipe and reenroll

158
00:53:57,500 --> 00:54:25,500
you take a tool like autopilot cleanup you can wipe cleanup records and flip them all at the same time and so you can do it programmatically for power shell with the caveat that the device has to be up and online right has to be reachable info as long as it's reachable auto power cleanup gives you kind of a shortcut to move devices from one tenant to another

159
00:54:25,500 --> 00:54:38,500
a lot of people say active directory and in June are are that are they really dead or there are more excel that

160
00:54:38,500 --> 00:55:07,500
well I've got a friend on twitter that calls active directory hack what does she say she called it active directory and so if you're still on a D and you're in a hybrid state I would recommend getting to enter ID and evaluating those on-prem dependencies when and where you can and getting to interact with the cloud native

161
00:55:07,500 --> 00:55:17,500
and if you can't take a look at something like intraprivate access that way you can have cloud native end points back to active directory

162
00:55:17,500 --> 00:55:27,500
when we have well what did you think which role do defenda play as especially defender for a event identity actually

163
00:55:27,500 --> 00:55:45,500
yeah so I think that lots of organizations sort of do what they do with pet and so I actually notice you published something on cloud apps

164
00:55:45,500 --> 00:56:06,500
right and it really got my interest and I sat and listened to the podcast on on cloud apps defender for cloud apps because so many people don't know what applications are in their environments and defender for identity and cloud apps and MDE for or end points

165
00:56:06,500 --> 00:56:24,500
I see so many organizations that think said it and forget it but it's got to be finally tuned like you kind of talked about in some of your examples it's got to be finally tuned for the identity finally tuned for the application finally tuned for the end point

166
00:56:24,500 --> 00:56:44,500
right and so it's a defense and depth you have your identity management your multi factor patterns requirements conditional access you have your device compliance you have MDE on the device right

167
00:56:44,500 --> 00:57:07,500
and so as you add each layer it sort of creates a defense and depth and each one becomes a gate so from my perspective it all comes together and each one of those is a piece to the puzzle and leaving any one of those out of the puzzle leaves an incomplete picture

168
00:57:07,500 --> 00:57:25,500
yeah also I do everything a rapid fire round or a lightning round where I asked questions and for short answers so let us start coffee tea or energy during development

169
00:57:25,500 --> 00:57:38,500
Cubs zero is that okay it's also okay wind just tell a partial IC a Windows power show into your configuration manager

170
00:57:38,500 --> 00:57:46,500
Oh in tune for days I don't do config man or SCC and call this like us open

171
00:57:46,500 --> 00:57:56,500
oh I'd say conditional access because you can't do pen right without it

172
00:57:56,500 --> 00:58:12,500
your favorite power sign your dual my favorite power show module get windows autopilot in court due a most underrated Microsoft security feature

173
00:58:12,500 --> 00:58:22,500
I have to say cloud apps but you can do some amazing stuff with defender for cloud apps

174
00:58:22,500 --> 00:58:32,500
one Microsoft product everybody should learn today

175
00:58:32,500 --> 00:58:52,500
if you at this point if you're starting if you're starting off start with yet have learn get hub core principles because as we move into an

176
00:58:52,500 --> 00:59:12,500
authentic world get hub principles are going to become one of the most important scales through your military career what the one product you have it you say everybody should learn from a military career

177
00:59:12,500 --> 00:59:41,500
I think that from the military I would learn basic share point development because no matter if you're a power user or an administrator you can use a share point development across one drive and share point and ultimately if you're an information worker

178
00:59:41,500 --> 00:59:46,500
not an administrator it'll make you better regardless of the role

179
00:59:46,500 --> 00:59:57,500
okay and when Microsoft come to you mark and say okay mark yeah you get all the resources all the money you need what feature will you develop

180
00:59:57,500 --> 01:00:17,500
the feature that I would develop today so I would do two things and they're kind of you know lateral to each other so when you go into the into in portal you don't know if the devices online or not

181
01:00:17,500 --> 01:00:37,500
right so you just have the last check-in date so I would build out a real time response indicator that shows me whether devices online or offline whether I can interact with that device and then sort of a bridge on top of that is I would make

182
01:00:37,500 --> 01:01:02,500
into remediations I would develop those remediations a little bit more I would increase the number of remediations that we could do I would work on an instant response to the end point if it's online give me the data back immediately write it to an O data table or a JSON and give me the response

183
01:01:02,500 --> 01:01:24,500
and so we could somehow do I think it's called I I don't want to butcher the acronyms I'm not going to and so if the device is online and we can get a real time response from it we can get real time data back how valuable would that be

184
01:01:24,500 --> 01:01:43,500
okay then last question of a lie lightning round is when someone come to Kansas what should he try for food oh definitely Joe's barbecue or Q39 Kansas City's religious about their barbecue

185
01:01:43,500 --> 01:01:56,500
in Joe's and Q39 don't disappoint it doesn't matter if you want to turkey sandwich burnt ends or ribs Joe's won't disappoint

186
01:01:56,500 --> 01:02:12,500
oh so okay cool so then my final question is if every idea I'm just start listening today could remember one lesson from this talk today about identity security and privileges says what lesson should he take away

187
01:02:12,500 --> 01:02:32,500
yeah for sure the lesson is protect identity with multi factor authentication specifically fishing resistant off start there enforce fishing resistant authentication

188
01:02:32,500 --> 01:02:52,500
yeah awesome yeah Mark thank you so much joining me today we cover up I think in this our incredible range of topics from journey as marine and Microsoft MVP to modern identity Microsoft iTunes

189
01:02:52,500 --> 01:03:11,500
device management power shall automation and yeah deep exploring the Microsoft and job for the identity management one of the biggest take away from today's conversion is that security is no longer just protecting you by his or networks it's about protecting identities and

190
01:03:11,500 --> 01:03:35,500
engineering products success existing only once truly needed and yeah so yeah thank you for being here I think everybody to listen today share it I think it's a real important topic and yeah thank you Mark for for being here for spend is out with me and this was really cool session thank you so much

191
01:03:35,500 --> 01:03:42,500
thank you for having me I thoroughly enjoyed it bye bye