Turn your real-world experience into part of the show.

Episodes

Dec. 24, 2025

Audit Microsoft 365 Data Access Before Deploying Copilot

This episode explores a common fear around AI assistants in enterprise environments: the belief that they create new security risks by exposing sensitive data. Through a narrative explanation, the speaker clarifies that the AI does not widen access or bypass controls—it only reflects what permissions already allow. Every response is grounded in real-time identity checks, security trimming, and existing governance enforced through Microsoft Graph. What feels like a “leak” is often the result of long-abandoned sites, broken inheritance chains, overly broad groups, and unlabeled content that was never properly governed. The AI acts as a mirror, not a crowbar, surfacing contradictions between expectation and enforcement. The episode contrasts fear-driven shutdowns, like restricting discovery, with sustainable governance practices such as ownership, access reviews, sensitivity labels, and policy enforcement. Ultimately, the message is clear: awareness increases, access does not. True safet…
Guest: Mirko Peters
Audit Microsoft 365 Data Access Before Deploying Copilot
M365 FM Podcast
Audit Microsoft 365 Data Access Before Deploying Copilot
Dec. 23, 2025

Cut Contract Review Time with SharePoint AI Agents

What if the problem with contracts was never storage, but silence? This episode explores how organizations moved from treating contracts as static files to treating them as sources of answers. Inside an unchanged SharePoint tenant, with the same permissions, labels, and audit logs, the only shift was how questions were asked. Instead of searching filenames and rereading PDFs, teams began asking plain-language questions and receiving precise answers backed by clause-level citations. The conversation follows the hidden cost of manual search, where small delays compound into missed renewals, version drift, and quiet risk. By extracting key facts into existing library columns and letting a knowledge agent query them, contracts became responsive without migration or new platforms. NDAs, MSAs, SOWs, and DPAs all showed the same pattern: faster decisions, fewer emails, and stronger compliance because answers carried their own evidence. Nothing flashy changed. Governance stayed intact. The co…
Guest: Mirko Peters
Cut Contract Review Time with SharePoint AI Agents
M365 FM Podcast
Cut Contract Review Time with SharePoint AI Agents
Dec. 22, 2025

Stop AI Agents from Making Silent Architecture Changes

Everything worked perfectly—and that’s how they knew something was wrong. In this episode, a routine AI workflow delivers flawless results: lower latency, reduced cost, cleaner logs, and zero policy violations. But beneath the pristine telemetry lies a mystery. The system didn’t fail, drift, or break rules—it optimized itself in ways no one explicitly designed. As investigators retrace execution traces, they uncover a subtle shift: model selection, regional routing, and orchestration decisions quietly changed at runtime, all within approved constraints. What looked like reliability was actually autonomy emerging inside a carefully defined boundary. The episode explores the uncomfortable gap between observability and explainability. Logs capture what happened, when, and where—but not why. As optimization replaces fixed decision trees, intent dissolves into geometry: a space of legal actions rather than a scripted path. The result forces a reckoning. When systems are designed to s…
Guest: Mirko Peters
Stop AI Agents from Making Silent Architecture Changes
M365 FM Podcast
Stop AI Agents from Making Silent Architecture Changes
Dec. 21, 2025

Stop Active Directory Security Drift Before a Breach

This episode explores the concept of Active Directory security drift—how environments gradually move away from their original secure configuration over time. Even well-designed setups become vulnerable as changes accumulate through daily operations, admin actions, or incomplete processes. The discussion highlights that drift is often subtle and goes unnoticed, yet it can introduce serious risks such as excessive permissions, outdated settings, and weakened security controls. These issues make it easier for attackers to escalate privileges and move laterally within a network. () A key takeaway is that security is not a one-time setup but an ongoing process. Organizations need continuous monitoring, regular reviews, and automation to maintain a secure baseline and detect unwanted changes early. Without this, even mature environments can slowly degrade into insecure states. Overall, the episode emphasizes that security drift is inevitable—but unmanaged drift is dangerous, making…
Guest: Mirko Peters
Stop Active Directory Security Drift Before a Breach
M365 FM Podcast
Stop Active Directory Security Drift Before a Breach
Dec. 21, 2025

How Ransomware Moves Through Active Directory

Security drift in Active Directory and Azure AD isn’t a single bug — it’s the slow, invisible decay of identity, permissions, and governance posture that happens when environments aren’t routinely managed and remediated. Over time, this drift increases risk, weakens access controls, and creates blind spots that attackers can exploit. In this episode, we break down what security drift really means in the context of Microsoft Entra Active Directory and Entra ID, how it develops, what causes it, and what you can do to prevent it — not just detect it.
Guest: Mirko Peters
How Ransomware Moves Through Active Directory
M365 FM Podcast
How Ransomware Moves Through Active Directory
Dec. 20, 2025

Stop SharePoint Sprawl with Data and Automation Governance

In this episode, we walk through how platform systems fail quietly long before they fail loudly, and how to stop that drift with discipline instead of heroics. The discussion starts with early warning signals: inconsistent SharePoint design, fragile Power Apps, and Power Automate flows that succeed until a small change pushes them over the edge. None of these are outages by themselves, but together they create instability that compounds over time. The episode breaks the problem down layer by layer. SharePoint is treated as a collaboration substrate that requires clear schemas, indexed columns, restrained relationships, and clean permission models. Power Apps are framed as deterministic systems, not improvisational interfaces, with strict control over state, delegation, and data writes. Power Automate flows are examined as operational systems that need scoped triggers, concurrency limits, checkpoints, and explicit failure handling to remain reliable. AI and copilots are positione…
Guest: Mirko Peters
Stop SharePoint Sprawl with Data and Automation Governance
M365 FM Podcast
Stop SharePoint Sprawl with Data and Automation Governance
Dec. 19, 2025

Detect Impossible Travel and Token Replay in Microsoft Entra ID

This episode plays out like a cybercrime thriller, exposing how today’s most dangerous breaches don’t smash doors—they’re invited inside. The investigation opens with a single click on January 12th. A polished phishing email doesn’t steal a password; it steals a session token. Within minutes, that identity reappears from impossible locations, inbox rules quietly erase executive emails, and an attacker reads everything without ever being noticed. The breach is clean, fast, and devastating—until Zero Trust guardrails snap shut mid-stride. But just when the case feels solved, the real twist lands. No phishing. No forced login. Instead, a forged badge. An OAuth consent screen convinces a user to grant access to a malicious app. The permissions are real. The trust is real. The damage is real. With legitimate keys in the wrong hands, data is sampled, skimmed, and harvested quietly enough to avoid alert thresholds. The logs don’t shout—they whisper. Across both cases, the message is bl…
Guest: Mirko Peters
Detect Impossible Travel and Token Replay in Microsoft Entra ID
M365 FM Podcast
Detect Impossible Travel and Token Replay in Microsoft Entra ID
Dec. 19, 2025

Build a Bronze-Silver-Gold Data Pipeline in Microsoft Fabric

You think Power BI performance problems are a dashboard issue? Think again — the real problem is hiding upstream. In this episode, we break down Microsoft Fabric as a living data ecosystem and explain why Power BI only thrives when the entire architecture beneath it is healthy. Using a clear, story-driven analogy, we explore how OneLake acts as the unified data foundation, why domains and workspaces define responsibility and governance, and how the bronze–silver–gold data layering model keeps analytics trustworthy and scalable. You’ll learn the real difference between Lakehouse and Warehouse, when to use each, and how shortcuts, mirroring, and Dataflows Gen2 move data without duplication or chaos. We dive deep into semantic models as the shared language of analytics, showing how clean star schemas, Direct Lake, and certified models eliminate refresh pain and metric confusion. The episode also covers governance that actually works: capacity management, lineage, sensitivity lab…
Guest: Mirko Peters
Build a Bronze-Silver-Gold Data Pipeline in Microsoft Fabric
M365 FM Podcast
Build a Bronze-Silver-Gold Data Pipeline in Microsoft Fabric
Dec. 18, 2025

Stop AI Agents from Breaking Microsoft 365 Governance

What if your AI systems aren’t rebelling — they’re simply executing the chaos you built? In this episode, we break down a hard truth about AI agents, Microsoft Copilot, Power Automate, and enterprise automation: failures don’t come from intelligence gone rogue, they come from human inconsistency scaled at machine speed. Through a narrated, system-level perspective, this episode exposes how misconfigured permissions, outdated policies, shadow automations, and neglected governance create predictable, repeatable failure patterns across the Microsoft 365 and Power Platform ecosystem. We explore real-world scenarios including agent loop cascades, Copilot data exposure caused by inherited SharePoint permissions, and silent data exfiltration through unmanaged Power Automate connectors. Each example shows how AI operates exactly within the boundaries you define — or fail to define. This is not a story about AI hallucinations or malicious intent, but about entropy introduced through poor…
Guest: Mirko Peters
Stop AI Agents from Breaking Microsoft 365 Governance
M365 FM Podcast
Stop AI Agents from Breaking Microsoft 365 Governance
Dec. 18, 2025

AI Contract Management with SharePoint Premium and Copilot

In this episode, we dive deep into how organizations can stop drowning in documents and start building a true AI-powered knowledge engine with SharePoint Premium and Copilot readiness. You’ll learn how data naturally drifts into entropy—and how the right structure, governance, and AI models give it orbit and purpose. We break down practical, real-world steps to deploy AI for content extraction, classification, and tagging, while keeping humans firmly in the loop. From finance invoice automation to legal contract intelligence and image tagging at scale, this episode shows how to turn noise into signal with measurable ROI—this quarter, not someday. We also uncover the guardrails most teams miss: oversharing risks, semantic search exposure, sensitivity labels, and restricted access controls that keep AI powerful but safe. If you want faster decisions, cleaner data, and Copilot answers grounded in truth—not guesswork—this episode is your blueprint for governed, scalable AI in Microsoft…
Guest: Mirko Peters
AI Contract Management with SharePoint Premium and Copilot
M365 FM Podcast
AI Contract Management with SharePoint Premium and Copilot
Dec. 17, 2025

Fix Microsoft 365 Copilot Accuracy with Information Architecture

Your AI isn’t broken — your digital city is lying to it. In this noir-style podcast episode, we pull back the curtain on why Copilot, search, and enterprise AI tools hallucinate, misfire, and surface the wrong answers even when the data “exists.” The culprit isn’t prompts or models — it’s information architecture. Through a detective’s lens, we explore how broken site structure, weak metadata, sloppy permissions, and chaotic navigation turn intranets into cities without streets. You’ll learn why thin content disappears from the index, how bad hubs confuse retrieval, and why AI can’t ground answers without clear signals. This episode breaks down the three pillars that actually fix AI accuracy: structure, semantics, and governance. From content types and term stores to search schema and permissions, we show how building a clean blueprint transforms Copilot from a guesser into a reliable informant. If your AI sounds confident but wrong, this episode explains exactly why — and how to fix …
Guest: Mirko Peters
Fix Microsoft 365 Copilot Accuracy with Information Architecture
M365 FM Podcast
Fix Microsoft 365 Copilot Accuracy with Information Architecture
Dec. 17, 2025

Connect Microsoft Copilot to Salesforce, ServiceNow, and APIs

You think Microsoft Copilot knows your business. It doesn’t—and that blind spot is costing you real decisions. In this episode, we expose the uncomfortable truth about Microsoft 365 Copilot: out of the box, it only sees surface-level data like emails, chats, and documents—not the systems that actually run your business. No Salesforce pipeline. No ServiceNow incidents. No proprietary APIs. Just a narrow slice of context that leads to confident but wrong answers. We break down why Copilot is blind by default, how grounding really works, and why AI without secure access paths will always hallucinate. Then we show you the fix: building enterprise-grade Copilot agents using Copilot Studio and Teams Toolkit, wired directly into your real systems with governed identity, least-privilege access, and full audit trails. You’ll learn: How Copilot “sees” data—and why most organizations misunderstand it The difference between AI theater and production-ready enterprise agents How to grou…
Guest: Mirko Peters
Connect Microsoft Copilot to Salesforce, ServiceNow, and APIs
M365 FM Podcast
Connect Microsoft Copilot to Salesforce, ServiceNow, and APIs
Dec. 16, 2025

Fix Wrong Microsoft 365 Copilot Answers with SharePoint Governance

Your AI isn’t broken, it’s telling the truth about your mess. In this episode, we expose why Copilot, search, and AI agents give confident but wrong answers inside Microsoft 365 and how the real problem isn’t prompts, models, or tools, it’s governance. You’ll hear how permission drift, orphaned Teams, ROT data, shadow sites, and overzealous restrictions quietly poison AI grounding, causing hallucinations that sound just like you. Through real admin stories and before and after examples, this episode explains why AI reads structure, permissions, labels, and residue, not intent, and why cleaning the house changes everything. We break down the five governance binds that actually fix AI accuracy: lean information architecture, lifecycle management, sensitivity labels, DLP, and retention, all working together as a repeatable ritual. If you want Copilot answers that are current, precise, and trustworthy, this episode shows why governance is the foundation of AI truth and how to start fixing…
Guest: Mirko Peters
Fix Wrong Microsoft 365 Copilot Answers with SharePoint Governance
M365 FM Podcast
Fix Wrong Microsoft 365 Copilot Answers with SharePoint Governance
Dec. 16, 2025

Govern SPFx Adaptive Card Extensions in Teams and Viva

Stop building quick apps in Microsoft Teams before they quietly turn into a compliance nightmare and a SharePoint graveyard you’ll be cleaning up for years. In this episode, we break down why Teams apps built with SPFx Adaptive Card Extensions often rot faster than anyone expects. What starts as a simple announcement card or dashboard widget quickly becomes an orphaned solution with no owner, no lifecycle, and no governance. These cards spread across Teams and Viva Connections, multiply by department, and create data silos that don’t agree on dates, labels, or retention rules. The result is stale content, compliance gaps, and late-night incidents no one planned for. You’ll learn why Adaptive Card Extensions are not “just UI” but a powerful distribution channel that surfaces content on mobile, caches data offline, and increases risk when the underlying data isn’t governed. We explain the five failures that show up every time: app sprawl, orphaned owners, fragmented data, complian…
Guest: Mirko Peters
Govern SPFx Adaptive Card Extensions in Teams and Viva
M365 FM Podcast
Govern SPFx Adaptive Card Extensions in Teams and Viva
Dec. 15, 2025

Secure AI Agents and Shadow IT in Microsoft 365

Shadow IT didn’t disappear, it evolved into AI agents quietly moving your data faster than your controls can see. In this episode, we break down how AI agents, Copilot Studio bots, and Power Automate flows are becoming the new Shadow IT inside Microsoft 365. What starts as productivity quickly turns into a governance and security nightmare when agents run with human identities, oversized Graph permissions, and no lifecycle controls. We explore how overshared SharePoint data, unmanaged browser-based AI tools, and third-party connectors expand your attack surface without triggering traditional security alarms. You’ll learn why Entra Conditional Access alone doesn’t protect agents, how delegated permissions quietly create ghost service accounts, and where Purview DLP often fails in real-world AI usage. The episode balances the real productivity wins agents can deliver with the hidden risks most organizations overlook. It closes with a practical reference architecture, a clear risk sco…
Guest: Mirko Peters
Secure AI Agents and Shadow IT in Microsoft 365
M365 FM Podcast
Secure AI Agents and Shadow IT in Microsoft 365
Dec. 15, 2025

Fix Power Apps After a Schema Change

Your Power Apps app works perfectly, until one day it fails with no error message and users can only say “it spins.” This podcast explains why low-code apps often break in silence: copy-pasted Power Fx formulas drift into conflicting versions, dev and prod blur without real environments, and hidden dependencies (globals, collections, shadow connectors, personal tokens) quietly decide whether the app runs. The transcript highlights common failure triggers like schema renames, delegation changes that drop records without alerts, throttling that causes duplicate submissions, and chaotic sharing that turns permissions into patches instead of roles. The solution is a practical refactor path for resilient Microsoft Power Apps development: map every screen, connector, table, and permission; extract and diff formulas to find duplicated logic; define health thresholds (red/yellow/green) for key user paths; add lightweight telemetry; and rehearse failures in test. The “stop the bleed” patter…
Guest: Mirko Peters
Fix Power Apps After a Schema Change
M365 FM Podcast
Fix Power Apps After a Schema Change
Dec. 14, 2025

Build Accessible Power BI Themes with WCAG Contrast

Your Power BI theme might be the reason your dashboard is silently lying to you. In this breakdown, you’ll learn why a Power BI theme isn’t “just branding” — it’s a containment field that keeps critical signals visible. The video exposes five hidden failures that make alerts fade, subtotals vanish inside matrices, tooltips turn unreadable on hover, card visuals lose hierarchy, and slicers disguise selected vs. unselected states. The fix is ruthless and repeatable: enforce WCAG-style contrast rules (4.5:1 for text, 3:1 for charts, 7:1 for high-risk KPIs), add redundancy (icons + labels, not color-only), and lock everything in a governed theme JSON. You’ll also get a pass/fail validation protocol, pixel-tested contrast checks, and a workflow for versioned organizational themes, pull-request gates, and CI-ready reporting so “pretty” never outranks data truth.
Guest: Mirko Peters
Build Accessible Power BI Themes with WCAG Contrast
M365 FM Podcast
Build Accessible Power BI Themes with WCAG Contrast
Dec. 14, 2025

Protect Contracts and PII with Microsoft Purview Auto-Labeling

Most data leaks do not start with hackers. They start with kindness, convenience, and one small decision to “just share it.” In Part 2 of The Knot in the Cloud, we move to the edge of the system, where documents leave their birthplace and chaos either multiplies or stops cold. This episode explains how auto-labeling in Microsoft Purview acts as a silent sense, recognizing contracts, evidence, and sensitive data before humans forget to care. You’ll see how labels, content types, DLP, retention, and Copilot work together to prevent forks, stop oversharing, and preserve a single version of truth across Dynamics and Microsoft 365. Instead of slowing work down, classification removes guessing, replaces memory with law, and turns audits into dashboards instead of interrogations. This is not about catching mistakes. It is about lifting the floor so mistakes rarely happen at all.
Guest: Mirko Peters
Protect Contracts and PII with Microsoft Purview Auto-Labeling
M365 FM Podcast
Protect Contracts and PII with Microsoft Purview Auto-Labeling
Dec. 14, 2025

Fix Dynamics 365 and SharePoint Document Chaos

Every organization has lost a document it desperately needed. A contract, a decision, a version marked “final” that was never truly final. This episode exposes why that chaos is not accidental, but structural. In Part 1, we explore how document sprawl silently fractures sales, projects, and compliance when SharePoint is treated like a file dump instead of an evidence system. Dynamics records events with precision, but without documents bound to those events, timelines collapse under scrutiny. Email attachments, private Teams channels, personal OneDrives, and endless folder hierarchies create parallel realities where proof cannot be summoned on demand. Audits fail quietly. Deals slow down. Trust erodes. This episode introduces the core problem: unstructured time. Without identity, metadata, retention, and enforced linkage between Dynamics, SharePoint, Purview, and Copilot, organizations repeat the same mistakes quarter after quarter. The documents are not lost. They are displaced in ti…
Guest: Mirko Peters
Fix Dynamics 365 and SharePoint Document Chaos
M365 FM Podcast
Fix Dynamics 365 and SharePoint Document Chaos
Dec. 13, 2025

Fix Silent Failures in Automated Customer Journeys

The cursor freezes. The event stream flatlines. Silence gets loud. That’s how customer journeys fail in the summer—quietly, invisibly, and at the worst possible moment. Summer traffic is deceptive. Intent spikes, teams run lean, and automation is supposed to carry the load. But when journeys rely on assumptions instead of evidence, silence replaces action. High-intent signals appear—pricing page views, repeated add-to-cart events, long dwell times—yet no email, SMS, or task ever fires. No alert triggers. No error appears. The journey simply dies between intent and action. The problem isn’t lack of data or channels. It’s missing structure. Over-automation without guardrails kills more journeys than under-automation. Consent conflicts, stale segments, misfired triggers, and absent evaluation records create a perfect summer storm. Dashboards glow green while revenue leaks quietly out the back door. To protect performance during peak summer months, every real-time journey needs p…
Guest: Mirko Peters
Fix Silent Failures in Automated Customer Journeys
M365 FM Podcast
Fix Silent Failures in Automated Customer Journeys
Dec. 12, 2025

Build an Auditable Multi-Agent Copilot in Microsoft 365

Ever trusted an AI answer that felt certain, then realised you couldn’t prove where it came from? This video is a forensic walkthrough of how single agents hallucinate, leak data, drift off stale indexes, and fail every audit that matters – and how to fix it with a multi-agent reference architecture in Microsoft 365. You’ll see exactly how SPFx + Azure OpenAI + LlamaIndex chains go wrong: weak RAG retrieval, no rerank, ornamental citations, prompt injection, over-privileged Graph connectors, and stale SharePoint indexes. Then we rebuild the system with dedicated agents for retrieval, rerank, verification, red-team and blue-team policy, maintenance, and compliance, all fronted by Azure API Management and permission-aware Microsoft Search or Copilot retrieval. You’ll learn how to enforce chain of custody, log prompts and tool calls, require line-level citations, and replay answers on demand for regulators and boards. If you care about AI you can defend, not just demo, this is your bluep…
Guest: Mirko Peters
Build an Auditable Multi-Agent Copilot in Microsoft 365
M365 FM Podcast
Build an Auditable Multi-Agent Copilot in Microsoft 365
Dec. 12, 2025

Build Reliable Power Automate Flows for Production

Ever had a Power Automate flow wake you at 3:07 a.m. with 6,000 ghost runs and no clear owner? This video is your blueprint for taming the orchestrator before it tames you. You’ll learn how to design resilient Power Automate architectures with clean triggers, Dataverse as a single source of truth, and idempotent patterns that stop infinite loops, duplicate messages, and runaway approvals. We walk through real tenant horror stories – loops that ate API quotas, dead-owner flows, and approvals that never expired – then show step-by-step remediation patterns that actually hold in production. Discover golden rules for try/catch/finally scaffolds, correlation IDs, poison queues, and governance with service principals, DLP, monitoring, and dashboards that point straight to the wound. If you run automation at scale in Microsoft 365, this guide will help you cut noise, reduce costs, and let your flows – and your tenants – finally sleep.
Guest: Mirko Peters
Build Reliable Power Automate Flows for Production
M365 FM Podcast
Build Reliable Power Automate Flows for Production
Dec. 11, 2025

Build Audit-Ready Document Management with SharePoint and Purview

In a recent podcast, Mirko Peters discussed the critical importance of effective document management and compliance in organizations, emphasizing that lost documents can lead to organizational failure. He presented strategies for building an audit-ready Enterprise Content Management (ECM) system in the cloud, using tools like SharePoint and Purview to create a robust defense against regulatory scrutiny. The conversation highlighted the alignment with standards such as ISO 27001, GDPR, and SOC 2, which are essential for surviving inspections. Peters outlined a structured approach to document management, including defining ownership, lifecycle management, and implementing data loss prevention (DLP) measures. He stressed the need for clear policies, sensitivity labels, and regular audits to ensure compliance and mitigate insider risks. The discussion also covered the importance of collaboration between HR, legal, and security teams to maintain a culture of compliance. This podcast …
Guest: Mirko Peters
Build Audit-Ready Document Management with SharePoint and Purview
M365 FM Podcast
Build Audit-Ready Document Management with SharePoint and Purview
Dec. 11, 2025

Optimize Dynamics 365 Business Processes for Faster Delivery

The podcast features a discussion among experts focused on optimizing project management processes using Dynamics. The speakers emphasize the importance of transitioning from traditional, cumbersome workflows to more efficient systems that prioritize speed and clarity. They argue that merely implementing Dynamics is not the end goal; rather, the objective is to enhance the speed at which work translates into progress. Key points include the need to eliminate unnecessary stages and fields, establish clear exit criteria, and automate processes to reduce friction. The speakers advocate for a structured approach, breaking down tasks into manageable stages—qualify, commit, and deliver—while ensuring that each stage has actionable criteria. They highlight the significance of data-driven decision-making and the role of a dedicated product owner in maintaining momentum. This discussion is crucial as it provides practical strategies for organizations looking to improve their operational …
Guest: Mirko Peters
Optimize Dynamics 365 Business Processes for Faster Delivery
M365 FM Podcast
Optimize Dynamics 365 Business Processes for Faster Delivery