Aug. 19, 2026

Licensing, Security & Management: Making Microsoft 365 Defender and Intune Work Together with Videsh Chavan

Licensing, Security & Management: Making Microsoft 365 Defender and Intune Work Together with Videsh Chavan
Licensing, Security & Management: Making Microsoft 365 Defender and Intune Work Together with Videsh Chavan
M365 FM Podcast
Licensing, Security & Management: Making Microsoft 365 Defender and Intune Work Together with Videsh Chavan

Key Takeaways

  • Microsoft 365 licensing should be treated as a core architecture decision rather than a simple procurement task to avoid unexpected security gaps and wasted expenses.
  • A practical five-step framework helps organizations transition from disconnected tools to a unified strategy by starting with a licensing audit and ending with continuous cost and coverage reviews.
  • Identity serves as the essential foundation of modern enterprise security, especially as hybrid work and cloud devices replace the traditional corporate network boundary.
  • Microsoft Intune has evolved far beyond traditional mobile device management into a robust security enforcement layer handling compliance, policies, and rapid device provisioning.
  • Organizations should regularly audit their assigned versus actively used licenses to identify overlapping third-party products and leverage built-in capabilities effectively.

Microsoft 365 licensing is often treated as a procurement problem: choose E3, E5, E7 or a collection of add-ons, assign the licenses, and move on. But licensing decisions directly influence security architecture, endpoint management, identity protection, and operational costs. In this episode of M365 FM, Mirko Peters talks with Videsh Chavan about building a unified Microsoft 365 strategy where licensing, Microsoft Intune, Microsoft Defender, identity, and endpoint security work together instead of operating as separate silos. ㅤ

MICROSOFT 365 LICENSING IS AN ARCHITECTURE DECISION
One of the central ideas of the conversation is that Microsoft 365 licensing shouldn't be treated purely as procurement. Organizations frequently purchase licenses without mapping the capabilities those licenses actually unlock. The result can be expensive features that nobody uses, duplicated security products, and security gaps that only become visible after an incident. Videsh recommends looking at licensing, Intune, Defender, and identity as parts of one connected architecture. Organizations should understand which capabilities they own, which capabilities they actually use, and where third-party products duplicate functionality already included in Microsoft licensing. ㅤ

A FIVE-STEP MICROSOFT 365 SECURITY FRAMEWORK
The discussion introduces a practical five-step approach for moving from disconnected Microsoft 365 tools toward a unified strategy. It starts with a licensing audit and capability mapping, followed by establishing an identity-first security baseline. Intune then becomes the enforcement layer, while Defender serves as the detection and response layer. The final component is continuous cost and coverage review, ensuring that licensing, security controls, and actual organizational requirements remain aligned. ㅤ

IDENTITY AS THE FOUNDATION OF MODERN SECURITY
As employees work from offices, homes, personal devices, mobile platforms, and Cloud PCs, the traditional corporate network becomes less useful as the primary security boundary. Identity therefore becomes a critical foundation. Users, groups, applications, connectors, access controls, and other resources depend heavily on identity. The conversation explores why organizations need strong identity controls, Conditional Access, MFA, and appropriate security guardrails as part of their Microsoft 365 architecture. ㅤ

AUDIT WHAT YOU ACTUALLY OWN
Before purchasing additional Microsoft security products, organizations should understand their existing entitlements. Videsh recommends inventorying assigned versus actively used licenses and mapping license tiers such as E3 and E5 against the Intune, Defender, identity, and security capabilities they unlock. This can expose features the organization already pays for but doesn't use. Regular reviews can also identify unused add-ons, capability gaps, and situations where upgrading or downgrading particular users makes more sense than applying the same licensing tier to everybody. ㅤ

WHY INTUNE IS MORE THAN MDM
Microsoft Intune has evolved far beyond traditional mobile device management. In the architecture discussed in this episode, Intune acts as an enforcement layer covering device configuration, application management, security policies, patching, provisioning, and endpoint security. Rather than maintaining large numbers of disconnected policies, organizations should consider structured security baselines and manageable policy architectures. The objective is to make endpoint management easier to understand, maintain, and continuously improve. ㅤ

WINDOWS AUTOPILOT AND ZERO-TOUCH PROVISIONING
Windows Autopilot fundamentally changes traditional corporate device provisioning. Instead of IT departments manually building and imaging every laptop before handing it to an employee, devices can be shipped directly from suppliers to users. The employee can unpack the device, connect it to the internet, authenticate, and allow organizational policies and configurations to provision the endpoint. This approach became particularly valuable as remote and hybrid work increased and organizations needed to onboard employees without requiring them to physically visit an office. ㅤ

INTUNE AS A SECURITY ENFORCEMENT LAYER
Intune increasingly sits at the intersection of endpoint management and cybersecurity. Security baselines, antivirus configurations, application policies, device configurations, and other endpoint controls can be centrally managed and enforced. This makes Intune an important part of the broader Microsoft security architecture rather than simply a tool for configuring laptops and smartphones. ㅤ

MICROSOFT DEFENDER AS DETECTION AND RESPONSE
Microsoft Defender represents a broader family of security capabilities rather than a single antivirus product. Organizations need to understand which Defender capabilities their licenses provide and how those capabilities fit into the wider endpoint security architecture. The episode discusses a practical security loop: detect suspicious activity, evaluate what happened, restrict the affected device or access when necessary, and restore normal operations after the problem has been addressed. Security teams remain responsible for investigating alerts and determining whether activity represents a genuine threat or a false positive. ㅤ

ZERO TRUST IS A STRATEGY, NOT A PRODUCT
Zero Trust isn't another Microsoft product organizations can simply purchase and enable. It is a cybersecurity strategy built around continuously verifying access instead of automatically trusting users, devices, or connections. Identity verification, application context, security controls, and least-privilege access all contribute to this model. Zero Trust therefore needs to influence architectural decisions across the organization rather than becoming another isolated security project. ㅤ

AI AND THE FUTURE OF ENDPOINT MANAGEMENT
AI introduces another layer to modern endpoint operations. Instead of waiting until users report that their device has a problem, telemetry and AI-assisted analysis can potentially identify deteriorating device health, recurring crashes, or other problems earlier. This creates an opportunity for more predictive and proactive IT operations. Videsh doesn't suggest handing endpoint management entirely to AI, but sees opportunities to shift some repetitive Level 1 activities toward AI-assisted operations while people remain responsible for more complex decisions. ㅤ

MODERNIZING A LARGE ENTERPRISE
For an enterprise operating Windows, macOS, iOS, Android, Windows 365, Active Directory, existing SCCM infrastructure, thousands of applications, BYOD, multiple Microsoft licensing tiers, and third-party security products, modernization should begin with discovery. Organizations need to understand their users, business requirements, existing technologies, licensing, regional restrictions, security requirements, and future use cases before redesigning the architecture. Modernization should then be controlled through documentation, peer review, architecture standards, and carefully managed implementation to minimize disruption. ㅤ

THE KEY TAKEAWAY
Microsoft 365 licensing, Intune, Defender, identity, Conditional Access, device health, and security policies shouldn't be managed as unrelated technologies. Together, they form a connected architecture in which identity and device signals influence access while Intune enforces policies and Defender provides detection and response. The starting point is understanding what the organization already owns and how those capabilities are being used. From there, organizations can identify security gaps, eliminate unnecessary licensing duplication, modernize endpoint management, and build a more coherent Microsoft 365 security strategy. As Mirko summarizes at the end of the conversation: licensing isn't simply procurement, Intune isn't simply device management, Defender isn't simply antivirus, and identity isn't simply a username and password.

Become a supporter of this podcast: https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support.

🚀 Want to be part of m365.fm?

Then stop just listening… and start showing up.

👉 Connect with me on LinkedIn and let’s make something happen:

  • 🎙️ Be a podcast guest and share your story
  • 🎧 Host your own episode (yes, seriously)
  • 💡 Pitch topics the community actually wants to hear
  • 🌍 Build your personal brand in the Microsoft 365 space

This isn’t just a podcast — it’s a platform for people who take action.

🔥 Most people wait. The best ones don’t.

👉 Connect with me on LinkedIn and send me a message:
"I want in"

Let’s build something awesome 👊

Frequently Asked Questions

Why should Microsoft 365 licensing be treated as an architecture decision?

Treating licensing as an architecture decision ensures that the capabilities you pay for directly align with your identity, endpoint management, and security strategies instead of operating in expensive silos.

What role does Microsoft Intune play in modern security?

Microsoft Intune acts as a central security enforcement layer that manages device configurations, application policies, security baselines, and seamless zero-touch provisioning via Windows Autopilot.

How can organizations stop wasting money on unused Microsoft 365 features?

Organizations can conduct regular licensing audits to inventory assigned versus actively used licenses, mapping tiers like E3 and E5 to actual organizational requirements and eliminating duplicate third-party software.

1
00:00:00,000 --> 00:00:06,320
Welcome back to the M665FM podcast. Today we are tackling a problem almost every Microsoft 365

2
00:00:06,320 --> 00:00:10,800
organization you've been doing in context. You bought the licenses but

3
00:00:10,800 --> 00:00:17,680
you actually using what you paid for. Microsoft 365 license can become

4
00:00:17,680 --> 00:00:25,920
complicated very quickly. Organization build stage, Microsoft 365, E3, E5, E7, business premium,

5
00:00:26,480 --> 00:00:32,720
security add-ons, Intune capabilities, Defender, products, and identity features,

6
00:00:32,720 --> 00:00:38,960
but chance, letting those license into a current security and device management architecture

7
00:00:38,960 --> 00:00:46,080
and the knowledge challenge, and that's where we go today in this conversation. My guest is

8
00:00:46,080 --> 00:00:56,560
Windesh Shavan, head of AUC engineering and identity at PerkkingAlmer. Windesh brings 18 years of

9
00:00:56,560 --> 00:01:02,400
experience across end-user computing device management, Microsoft 365, identity and security. He has

10
00:01:02,400 --> 00:01:09,840
built a let enterprise scale MC65 device management and identity security program and was recognized

11
00:01:09,840 --> 00:01:19,360
with the next, what, the next tunnel, CIO award for 2015. His central argument is straightforward.

12
00:01:19,360 --> 00:01:25,600
Organization should treat licensing and management identity security as separate decision. They

13
00:01:25,600 --> 00:01:32,800
need to work together. So today we are going to explore how organization can align Microsoft

14
00:01:32,800 --> 00:01:39,120
licensing, Microsoft Intune, and Microsoft Defender to raise security gaps, control costs, and create

15
00:01:39,120 --> 00:01:44,400
an only five endpoint entity, when they come to the NS65 podcast.

16
00:01:44,400 --> 00:01:51,440
Hey, thank you. Thanks, Michael. Thanks for inviting and having just on this.

17
00:01:51,440 --> 00:01:59,760
Looking forward for this session. And as you have nicely described about the oral experience,

18
00:01:59,760 --> 00:02:06,320
yeah, hopefully this will be helpful for someone somewhere and keep bringing on the overall experience.

19
00:02:06,320 --> 00:02:10,400
Yeah, so it would be good to start with. Really excited.

20
00:02:10,400 --> 00:02:17,760
Yeah, Windesh before we get into the licensing and security, let's start with you. You spent

21
00:02:17,760 --> 00:02:24,080
around 18 years working in endpoint computing. What did you see look like when you started?

22
00:02:24,080 --> 00:02:33,600
Yeah, that's a good question. And if I go back like when I started my journey somewhere around 2008,

23
00:02:33,600 --> 00:02:38,720
okay, at that point of time, like we didn't had specifically into sort of competing as a concert.

24
00:02:38,720 --> 00:02:43,520
Or let's say we didn't had digital work with as a concert. So it was more like desktop engineering,

25
00:02:43,520 --> 00:02:49,920
or we were just trying to involve or like evolve more into the desktop engineering code concepts,

26
00:02:49,920 --> 00:02:56,640
more of most of the tools that we have with the UC or digital workplace. It was like quite

27
00:02:56,640 --> 00:03:03,040
legal C1, like maybe for SCCM, SCCM was like market leader at that point of time. And then everyone

28
00:03:03,040 --> 00:03:09,760
were looking at SCCM as one of the management tools. But the way it has been evolved now, it has been

29
00:03:09,760 --> 00:03:18,880
pretty much shaped into a digital era. And now UC or the digital workplace is a core area of the IT,

30
00:03:18,880 --> 00:03:23,200
where we are managing the device management, we are working on the cloud management, deployment,

31
00:03:23,200 --> 00:03:27,760
and everything all together. So that we are making our end result experience quite good.

32
00:03:27,760 --> 00:03:33,360
Right, so this is how I can see, like how it has been developed from like typical managing the

33
00:03:33,360 --> 00:03:38,640
fleet of the stops, like hardware part and now moving from the hardware to more like a cloud

34
00:03:38,640 --> 00:03:44,160
PCs or virtual devices. And then we move over all dependency from the physical devices.

35
00:03:44,160 --> 00:03:54,640
What are their particular moments when traditional end-pile management start becoming more on end-pile

36
00:03:54,640 --> 00:04:02,320
from your perspective? So I think the way Microsoft have introduced

37
00:04:02,320 --> 00:04:09,920
tool or feature called Intune, right, I can see that as a turning point here, like how the

38
00:04:09,920 --> 00:04:16,960
devices management has been improved drastically. And how we are able to really use the overall

39
00:04:16,960 --> 00:04:24,400
M-thestifies in tune as a suit to manage our devices all together. Like earlier, we had SICM,

40
00:04:24,400 --> 00:04:30,960
but I think SICM was more like managing the physical devices, less virtual devices, and mostly

41
00:04:30,960 --> 00:04:38,800
it was like a bit time consuming, the way the APIs were discovered, the way the task were delivered.

42
00:04:38,800 --> 00:04:44,320
So there were less APIs that were actually involved, but the way Intune has been developed,

43
00:04:44,320 --> 00:04:49,120
it is directly working with Graph APIs, which is quite quick. And the way the devices are sinking

44
00:04:49,120 --> 00:04:54,800
back the way devices are managed, it is pretty much easy to any administrator who is able to

45
00:04:54,800 --> 00:04:59,680
learn about the Intune and their able to manage. Like in SICM, I know you need a typical

46
00:04:59,680 --> 00:05:05,760
10 or 12 years of experience just to start with as an architecture. But here I think given the

47
00:05:05,760 --> 00:05:10,560
Intune, it is quite easy to navigate, it is quite easy to manage and the way Microsoft

48
00:05:10,560 --> 00:05:17,680
to do it, I think it is easy for any of the administrator to handle the overall architect management of the devices.

49
00:05:17,680 --> 00:05:28,320
Yeah, awesome. So let's just define what endpoint actually means today. I say 10 years ago, people

50
00:05:28,320 --> 00:05:35,760
primarily thought about, to cooperate with those PCs, what's an enterprise endpoint in 2000?

51
00:05:38,000 --> 00:05:47,600
26. So yeah, like we have two cases, mostly one is physical devices. We still need some physical

52
00:05:47,600 --> 00:05:54,240
devices, but most of the teams are now moving from physical devices to the cloud devices. Now from

53
00:05:54,240 --> 00:06:01,520
cloud devices to more like cloud desktop devices. So we had like the phase goes like this,

54
00:06:01,520 --> 00:06:06,160
like it started with physical devices, then we moved to virtual devices, like we wanted to have some

55
00:06:06,160 --> 00:06:13,040
dependency on physicals and onto to remove that dependency by utilizing some cloud devices.

56
00:06:13,040 --> 00:06:17,600
But now the way it has been evolved, now we should go as a desktop as a service.

57
00:06:17,600 --> 00:06:22,960
Right, it's most like a dust that everyone should go or we should try to adopt a desktop as a

58
00:06:22,960 --> 00:06:27,680
service where we are going to windows 365 to start with like again, you deny Microsoft tool,

59
00:06:27,680 --> 00:06:33,920
like it is pretty much again effortless the way you just plug any of the thing.

60
00:06:34,880 --> 00:06:42,240
Maybe things are devices, right? And then you should be able to use it just with your normal

61
00:06:42,240 --> 00:06:49,360
own device. You don't need any, you know, high configuration device to use this set of devices

62
00:06:49,360 --> 00:06:55,760
already. So that is anyway cutting down the overall cost and the device management cost that is

63
00:06:55,760 --> 00:07:01,280
involved, like and the way we are evolving now into the windows pieces, the desktop, cloud pieces,

64
00:07:01,920 --> 00:07:07,120
you will see like the connectivity, the end user experience and the way we are interacting with

65
00:07:07,120 --> 00:07:14,880
the applications, it is much better. Yeah, that's interesting. So we have Fauley R,

66
00:07:14,880 --> 00:07:24,560
windows 55, but I like to stay a little bit more actually at the hardware part,

67
00:07:24,560 --> 00:07:36,240
our windows, macOS, iOS, Android and Linux. Now, effectively, part of the same management problem.

68
00:07:36,240 --> 00:07:48,720
Yes, so with Intu1, right, I think we have that very much wide acceptance of the given devices.

69
00:07:48,720 --> 00:07:53,840
It's not only like you are able to enroll or you're able to manage the windows devices,

70
00:07:53,840 --> 00:07:58,480
you are also able to match some of the immersive devices, right? Like maybe windows,

71
00:07:58,480 --> 00:08:05,600
macOS of HoloLens, for example, MetaQuest devices, like them, it's like some of the devices which

72
00:08:05,600 --> 00:08:12,320
are able to enroll and it comes as part of the AOSP configuration, like Android Open Source Project.

73
00:08:12,320 --> 00:08:16,960
So you would be able to also configure those devices, which was a bit problematic while we had

74
00:08:16,960 --> 00:08:26,000
other legacy tools in our environment. Okay, and what's your perspective on the

75
00:08:26,000 --> 00:08:31,520
I think it's its upcoming especially at Corona at personally owned devices?

76
00:08:31,520 --> 00:08:42,720
Sorry, there was a bit network pledge. Yeah, what did you think about personal owned devices? I think

77
00:08:43,680 --> 00:08:49,440
with Corona, a lot of people start working with their own devices.

78
00:08:49,440 --> 00:08:57,200
Definitely, the way in the Corona era, right, we adopted the work from home,

79
00:08:57,200 --> 00:09:01,680
like most of the companies and the way we started to look and do

80
00:09:01,680 --> 00:09:06,480
effortlessly, we can provide the work from home opportunities.

81
00:09:09,680 --> 00:09:13,200
Our end result without coming to office, of course, then,

82
00:09:13,200 --> 00:09:26,160
this one, you're getting all the time on mute, yeah, sorry, it was a bit domestic. Yeah, so

83
00:09:26,160 --> 00:09:30,960
what I'm saying, like with the BYUOD stuff, right, we were able to actually

84
00:09:30,960 --> 00:09:38,000
bring out the policy, we were able to see like how effortlessly we can plug into devices and

85
00:09:38,000 --> 00:09:45,040
make end result life easy. It's not also about asking the existing users to use this service,

86
00:09:45,040 --> 00:09:49,440
it was also a bit challenge to onboard the users, like how the onboarding would work,

87
00:09:49,440 --> 00:09:55,200
like normally onboarding was done earlier, someone would come to the office, they would

88
00:09:55,200 --> 00:10:01,040
collect the laptop and then the local IT team would configure, but the way Corona has said,

89
00:10:01,040 --> 00:10:06,960
it has been changed. Like now users are getting the devices shipped to their home,

90
00:10:06,960 --> 00:10:12,400
with Windows Autopilot as one of the major key components where we configure it as a wrapper,

91
00:10:12,400 --> 00:10:17,280
and then user is able to configure their devices on their own. So I think it's pretty much

92
00:10:17,280 --> 00:10:24,080
modernized as compared to what we had and also the overall imaging time that we had before

93
00:10:24,080 --> 00:10:30,720
Corona era. I think that has been really been decreased, like earlier, I know if you need to

94
00:10:30,720 --> 00:10:34,960
manage or if you need to image a device, right, it would take somewhere around two or three us,

95
00:10:34,960 --> 00:10:41,280
but now it's not more than 20 minutes. Right, which one? Yeah. Okay. And then now we'll a little bit

96
00:10:41,280 --> 00:10:54,480
join the area of Cloud PCs, we talk about Windows 365 or AVD. Do the traditional idea of

97
00:10:54,480 --> 00:11:03,040
a corporate network still matter? Yes, the reason is like there are some of the applications,

98
00:11:03,040 --> 00:11:08,400
which are like quite dependent on the on-premises and those are legacy applications.

99
00:11:08,400 --> 00:11:14,160
Like when we do the application migrations, right, let's say when we move from Windows 10 to 11,

100
00:11:14,160 --> 00:11:19,440
and we wanted to move most of our devices to AVD or the Cloud PCs, we weren't able to do that

101
00:11:19,440 --> 00:11:26,000
at a scale for like let's say, a car getting 95% or 100% the reason is there are too many legacy

102
00:11:26,000 --> 00:11:31,520
applications and those legacy applications are sitting there from years. Like maybe someone

103
00:11:31,520 --> 00:11:35,200
have built those applications, he have left the organization probably vendor have delivered,

104
00:11:35,200 --> 00:11:40,640
they are no more working with us. And then probably the IT managing those applications,

105
00:11:40,640 --> 00:11:44,800
they are not aware about those application at all and they're sitting there from years.

106
00:11:44,800 --> 00:11:51,840
So we cannot really move them and those are also tied to the some of the on-premises applications

107
00:11:51,840 --> 00:11:56,160
or the configurations where we need to be hosted them on the on-premises. So I think that is one

108
00:11:56,160 --> 00:12:00,160
of the biggest challenges like when we wanted to see like why we want to have that physical

109
00:12:00,720 --> 00:12:10,880
infrastructure in place. Yeah, we have, I think, yeah, with Corona, we have this homework and

110
00:12:10,880 --> 00:12:21,600
accurate trend is the location. So if user can work from anywhere, where does the security boundary

111
00:12:21,600 --> 00:12:30,640
actually exist? Like when you say about the users, right, the security bond that I say

112
00:12:30,880 --> 00:12:37,680
like it's mostly related to the MFA part, right? So I think that's one of the security area where

113
00:12:37,680 --> 00:12:44,960
everyone would be having a boundary. And the way nowadays like everything is connected to

114
00:12:44,960 --> 00:12:51,520
internet, right? And we do not need something like a physical access in some cases.

115
00:12:51,520 --> 00:12:55,360
Any person who is connected on the internet, they can easily access our resources,

116
00:12:55,360 --> 00:13:00,880
given they are able to proceed with the security, authentication or like configurations, they

117
00:13:00,880 --> 00:13:04,720
pass the security configuration and they're able to access. So I think that is one of the thing

118
00:13:04,720 --> 00:13:09,120
which is still there and that is something it would be there. And I guess that is also beneficial

119
00:13:09,120 --> 00:13:14,800
because we have to protect our resources. And of course having any of the ATAX or any of the

120
00:13:14,800 --> 00:13:24,560
threats, it is good to have that. Yeah, and this is identity become the new

121
00:13:24,560 --> 00:13:30,000
perimeter or will you say identity plus device health is a real perimeter?

122
00:13:30,000 --> 00:13:38,080
Yes, like nowadays the focus is more on the identity. The reason like why? Because again,

123
00:13:38,080 --> 00:13:45,200
it is like hurt of any of the IT environment. Everything goes from there, right? Like without

124
00:13:45,200 --> 00:13:50,720
identity, you won't be able to create users, you won't be able to create or manage the groups,

125
00:13:50,720 --> 00:13:55,120
you're not able to manage the connectors, applications, everything. So everything

126
00:13:55,120 --> 00:14:00,160
is tied with the identity. So if you're able to manage your identity properly, having all the

127
00:14:00,160 --> 00:14:06,240
security controls, the guard rails, everything in place, then I think identity is one of the areas

128
00:14:06,240 --> 00:14:12,000
where you need to focus it. Like let's say for example, if someone is doing assessment of

129
00:14:12,000 --> 00:14:18,000
the identity, the first thing that comes to my mind is identity, like how much secure we are

130
00:14:18,000 --> 00:14:23,680
from the identity perspective, the security score that adopts it is having a huge advantage for the

131
00:14:23,680 --> 00:14:29,040
identity as well because it is having like conditional policies, everything, right? Groups,

132
00:14:29,040 --> 00:14:36,160
users, groups, then how the people are connected, how people are utilizing that is, so says how the

133
00:14:36,160 --> 00:14:41,920
applications are actually connected to each other. So everything is coming from identity all together.

134
00:14:43,760 --> 00:14:50,960
And yeah, let's get into someone, everybody loves to talk about Microsoft licensing.

135
00:14:50,960 --> 00:14:58,320
Why is Microsoft licensing so difficult to understand for organizations?

136
00:14:58,320 --> 00:15:06,560
So maybe what we can do, we can focus on the problem here. Okay, so the problem is like licenses

137
00:15:06,560 --> 00:15:13,280
licensing, it is always treated as procurement. It's not architecture, okay? Like sometimes you see

138
00:15:13,280 --> 00:15:18,640
licenses are bought without nothing, I don't know, okay? Those are purchased without knowing exactly

139
00:15:18,640 --> 00:15:23,760
like what are the capabilities, they unlock, then there are some tools operating in silos,

140
00:15:23,760 --> 00:15:28,240
right? Like maybe there are some of the, let's say for example, into your defend,

141
00:15:28,240 --> 00:15:32,720
their identity policies, those are on the very end independently, instead of having a one

142
00:15:32,720 --> 00:15:37,280
connected system, right? So those are operating in silos here. And then third is mostly like the

143
00:15:37,280 --> 00:15:42,400
reactive security position, like team, discover gap after an incident rather than designing controls,

144
00:15:43,040 --> 00:15:48,480
around what's already licensed, right? So that's again one of the reactive security posters that we have.

145
00:15:48,480 --> 00:15:53,600
So if you say like this is how I would take as a problem, right? The core idea I do today should be like

146
00:15:53,600 --> 00:16:00,160
quick licensing into a defender or everything as a one connected system, rather than having three

147
00:16:00,160 --> 00:16:07,920
separate line items. Okay, once you have this connected as a one system, then like let's say we

148
00:16:07,920 --> 00:16:13,840
have a practical framework as well, like how we wanted to go with the typical five step practical

149
00:16:13,840 --> 00:16:19,680
framework. Let's say you want to see how you want to go from a disconnected tools to one unified

150
00:16:19,680 --> 00:16:25,840
step. So the first point here would be like we need to do the licensing audit and the capability mapping.

151
00:16:25,840 --> 00:16:33,840
Second is identify the first baseline. Third is have in tune as an enforcement layer, okay? Then

152
00:16:33,840 --> 00:16:38,800
defend us the detection and response layer and fifth is of course continuous cost to coverage to be.

153
00:16:38,800 --> 00:16:44,240
So this is pretty much important and this is how I would take a five step practical framework to

154
00:16:44,240 --> 00:16:50,640
you know get a one unified strategy which is missing I guess in some of the organizations that I have

155
00:16:50,640 --> 00:16:55,760
seen and this would be really helpful for someone who wanted to build that one unified strategy.

156
00:16:55,760 --> 00:17:01,520
And then before because of this we have seen like licensing cost has been huge, okay? We discovered

157
00:17:01,520 --> 00:17:08,080
when we do the overall Microsoft 365 through or licensing review and then it's already

158
00:17:08,080 --> 00:17:17,120
late, right? We cannot do much over there. So I think that's that's what I would I would

159
00:17:17,120 --> 00:17:24,160
say is just from the licensing perspective, like how it would be useful like when we see it as

160
00:17:24,160 --> 00:17:29,280
overall one connected system. But if you say like what would be the typical key database from this

161
00:17:29,280 --> 00:17:35,920
particular particular framework then I think like again licensing is nothing like not a procurement

162
00:17:35,920 --> 00:17:40,000
but it's more like an architecture decision, right? So that's something we need to be very much

163
00:17:40,000 --> 00:17:46,560
sure. And identity again this is the foundation in to a defender they are both built on it like we

164
00:17:46,560 --> 00:17:53,120
know how to work upon it and in most of the cases you know organization is not really really

165
00:17:53,120 --> 00:17:59,200
exploring all the features that has been added to those particular add-ons, okay? Sometimes it

166
00:17:59,200 --> 00:18:06,240
is just purchased and we are not utilizing or leveraging any of those features or probably a

167
00:18:06,240 --> 00:18:13,200
best classic example. So we have defender as part of our maybe M35E file license and then we also

168
00:18:13,200 --> 00:18:19,600
have Sentinel one or CrowdStrike as our idea. So if you wanted to go with that then why we have

169
00:18:19,600 --> 00:18:25,840
the licensing on e5? We should be on e3, right? Why we are paying licenses for both of the tools,

170
00:18:25,840 --> 00:18:30,240
where the both of the tools have the same functionality. I know there could be some specific use cases

171
00:18:30,240 --> 00:18:35,280
but I think that can be in a time they are closed out by doing a close review like what was

172
00:18:35,280 --> 00:18:40,640
net and what is not net. But overall this is the typical situation that I have seen for most of

173
00:18:40,640 --> 00:18:44,080
the organizations. Yeah. Yeah. Yeah.

174
00:18:44,080 --> 00:18:55,360
I think a little bit is the biggest challenge to understand what the company

175
00:18:55,840 --> 00:19:00,960
own all the licenses or is this understanding what you need.

176
00:19:00,960 --> 00:19:08,640
So as I said like the first thing that I would see like we need to inventory what all are assigned

177
00:19:08,640 --> 00:19:17,280
then versus active licenses then we need to map each tire like let's say e3 versus e5 defender p1

178
00:19:17,280 --> 00:19:23,440
versus p2 right the Internet defender features that is unlocking unlocking itself then we need to

179
00:19:23,440 --> 00:19:28,720
flag the shelter paid for features like who is nobody is using it. So that will help us with the

180
00:19:28,720 --> 00:19:36,480
initial licensing audit and capability mapping then the second boss is like of course identifying

181
00:19:36,480 --> 00:19:42,080
the first baseline. Like here we should make conditional access and identity protection as the

182
00:19:42,080 --> 00:19:48,720
foundation not enough to talk of course then enforcing fish resistant MFA risk-based signing policies

183
00:19:48,720 --> 00:19:53,120
which is coming as part of the M file licenses it is something like not everyone is using

184
00:19:53,760 --> 00:19:59,440
like just in the past Microsoft have forcefully started now to push the fishing resistant MFA

185
00:19:59,440 --> 00:20:06,400
and until that point of name none of the organizations were using it right so that's why I can say

186
00:20:06,400 --> 00:20:13,680
like how the licensing has been discovered and how we are really leveraging all the tools because

187
00:20:13,680 --> 00:20:20,000
in some cases you know some of the organizations has started to go and check with Microsoft

188
00:20:20,000 --> 00:20:25,360
hey are we really licensed with this feature is this something that is coming into our licensing

189
00:20:25,360 --> 00:20:31,040
coverage right so this is something you can do when you know like you treat licensing as

190
00:20:31,040 --> 00:20:36,640
architecture and not as a procurement solution okay and then of course every device and app policy

191
00:20:36,640 --> 00:20:42,800
it should be like key of identity signals when we do the identity first baseline right and then

192
00:20:42,800 --> 00:20:48,800
ensuring like the tools that we have like into a defender those are like in fourth layer right

193
00:20:48,800 --> 00:20:55,440
those are built on the maybe the one that we discussed like corporate versus BIOD like segmenting

194
00:20:55,440 --> 00:21:01,760
the policy by ownership because of course not one size fits all yeah correct and then of course

195
00:21:01,760 --> 00:21:07,040
up in the end point security baseline ASR rules there are multiple features like how we wanted to

196
00:21:07,040 --> 00:21:12,560
really to this but yeah there should be an uh uh a quarterly check as well if you wanted to see

197
00:21:12,560 --> 00:21:18,000
how we are going with the cost of coverage review like maybe do a quarterly check uh see if you are

198
00:21:18,000 --> 00:21:25,280
a license for maybe identify gaps just to maybe a tie or maybe waste from onions add-ons and then maybe

199
00:21:25,280 --> 00:21:31,440
a simple score card like like how much is the licenses percentage policy coverage and then open

200
00:21:31,440 --> 00:21:38,960
gaps so I think this is how we would really work on this licensing one what's wrong with uh simply

201
00:21:38,960 --> 00:21:47,600
saying okay well buy SE7 and then we have everything right so that's that's that's the problem right

202
00:21:47,600 --> 00:21:55,760
like uh as we know with e7 uh we have this AI capability okay we have all the features

203
00:21:55,760 --> 00:22:03,040
but the question remains again unanswered are we really utilizing all the features are we really

204
00:22:03,040 --> 00:22:08,720
having any of these such huge cases where we need all the e7 features or components as part of

205
00:22:08,720 --> 00:22:14,320
the e7 licenses because e7 licensing is like a hefty price for organization right so when we are

206
00:22:14,320 --> 00:22:21,760
doing that we should see the overall forecast we should also review what all our uh use cases and

207
00:22:21,760 --> 00:22:27,760
how would typically this fit into our environment because I've seen this uh quite uh blindly like some

208
00:22:27,760 --> 00:22:32,640
organizations they would say like no no that is e7 it means it is covering something so we should go

209
00:22:32,640 --> 00:22:39,200
with that but then no one really looks from the architecture point of view like e7 really

210
00:22:39,200 --> 00:22:45,920
needed for organization if if we needed do we have the supporting use cases for it okay and when we

211
00:22:45,920 --> 00:22:50,560
do the use cases we should thoroughly check each and every business when it because in some cases

212
00:22:50,560 --> 00:22:56,000
it might be possible like there are some of the use cases which are having e7 feature component

213
00:22:56,000 --> 00:23:00,880
so we can buy specifically e7 license for those which are rather than purchasing for all the

214
00:23:00,880 --> 00:23:08,480
uses and making a default we can have those uh mixed licensing okay or I know like from Microsoft

215
00:23:08,480 --> 00:23:15,520
perspective they are giving uh you know uh challenge for these compliance from the compliance

216
00:23:15,520 --> 00:23:21,440
perspective there is a mixed licensing but I think from the organization benefit right it is a

217
00:23:21,440 --> 00:23:28,000
really good to pay how do you really license the overall strategy right and then how do you

218
00:23:28,000 --> 00:23:32,560
architect the overall strategy with respect to the licensing and then how we are really utilizing it

219
00:23:32,560 --> 00:23:37,520
I think the Microsoft compliance is just one thing like we need to if you if you are sure like you

220
00:23:37,520 --> 00:23:42,000
know what has been used how it is been used and if you are able to map the respective licenses to

221
00:23:42,000 --> 00:23:49,680
the respect users I don't think that could be any way problem yeah um I think there are some some

222
00:23:49,680 --> 00:23:59,920
interesting architectural questions here a lot of companies uh three licensing as yeah procurement

223
00:24:02,160 --> 00:24:08,000
the first thing is who should own Microsoft license in decision i.e security, pro

224
00:24:08,000 --> 00:24:17,600
presuming finance enterprise architecture so that's an organization wide question it's not like

225
00:24:17,600 --> 00:24:25,520
something only i'd be able to decide like also or not the security team as well so you need to connect

226
00:24:25,520 --> 00:24:31,760
with each and every team okay that we have we need to understand the typical use case of the business

227
00:24:32,240 --> 00:24:38,080
team use case of the internal IT team or use case of the customer as well right who are utilizing

228
00:24:38,080 --> 00:24:44,080
our infrastructure because this is how it is connected to each other and once we know like what

229
00:24:44,080 --> 00:24:50,800
is our typical use case how many uh users we need for top typical licenses or how many uh features

230
00:24:50,800 --> 00:24:56,720
we need to utilize when we wanted to go with the procurement decision so that's where the licensing

231
00:24:56,720 --> 00:25:02,880
architecture will place a important role because you know what you have added it you know what has been

232
00:25:02,880 --> 00:25:08,880
typically licensed you know what is the typical usage you know your users that's also important

233
00:25:08,880 --> 00:25:14,960
and the this is where the big decisions comes altogether and then I think when you work with everyone

234
00:25:14,960 --> 00:25:20,320
altogether you better understand your environment rather than asking one team to go ahead and do

235
00:25:20,320 --> 00:25:29,600
the decision um uh should should organizations main and tame uh capability map the showing exactly

236
00:25:29,600 --> 00:25:38,080
which Microsoft features they are painful uh so you mean like uh is that something organization should

237
00:25:38,080 --> 00:25:44,800
know or they should be able to figure it out yeah do do do i i don't know i think mapping it

238
00:25:44,800 --> 00:25:52,720
that's a really sensible show shall say doing this or yes yes that's what I said like if you want to do

239
00:25:52,720 --> 00:26:00,400
right as I said like at the moment the problem is three of the aspects by the first is like licensing

240
00:26:00,400 --> 00:26:06,400
or bought without mapping entitlement okay let's say for e3 e5 and there are some add-ons which are

241
00:26:06,400 --> 00:26:12,720
purchased without knowing exactly like what are the capabilities and how they unlock those capabilities

242
00:26:13,280 --> 00:26:18,480
this is a much one of the major points that second is again there are some tools which are already

243
00:26:18,480 --> 00:26:24,080
operating in silos right like for example there is defender there are identity policies there is

244
00:26:24,080 --> 00:26:31,200
purview right this are some of the features that or the add-ons that are already configured independently

245
00:26:31,200 --> 00:26:36,400
instead of one connected system so this is the second problem that we have and then third is again

246
00:26:36,400 --> 00:26:41,760
these reactive security questions like let's say there is a security team they are saying and uh

247
00:26:41,760 --> 00:26:46,560
now complaining like hey no no we are able to see like there is no maybe three policies there is

248
00:26:46,560 --> 00:26:52,640
no entice spam and then we want to cover it so what we do like we have this reactive security

249
00:26:52,640 --> 00:26:58,240
question and then team this course like there is a gap uh after any incidents rather than we had

250
00:26:58,240 --> 00:27:06,880
as part of the designing controls right so this is pretty much needed and then how often short

251
00:27:06,880 --> 00:27:17,120
license be reviewed daily weekly monthly yearly quarterly uh so like maybe as I said so it is really

252
00:27:17,120 --> 00:27:23,360
depends like how you wanted to do this altogether right like if you ask me so normally what I would do

253
00:27:23,360 --> 00:27:31,760
like I run a quarterly check okay like if you are using licenses right using the right licenses

254
00:27:31,760 --> 00:27:38,480
then identify the gaps okay maybe uh justify if there is a tie-up rate or that has any waste from

255
00:27:38,480 --> 00:27:44,480
unused add-ons right and then third is like maybe just drop a single uh simple square cut like

256
00:27:44,480 --> 00:27:50,720
how many license are used policy coverage and then open gaps what are the open gaps so the quarterly

257
00:27:50,720 --> 00:28:00,560
check is something like I would recommend for everyone yeah um before we go to ensuing um uh I think

258
00:28:00,560 --> 00:28:07,520
about your framework for for deciding keep it upgraded downgrade or remove it can you a little bit

259
00:28:07,520 --> 00:28:15,600
explain here uh yeah so as I said like there is a typical five step practical framework okay which I

260
00:28:15,600 --> 00:28:22,240
would really apply in any of your organization so first is like licensing or detain capability mapping

261
00:28:22,240 --> 00:28:28,880
okay this is one of the major things that we need to do and I know like most of the time is spent

262
00:28:28,880 --> 00:28:34,000
on this particular topic because this is the base right and this is where we identify the first

263
00:28:34,000 --> 00:28:40,560
baseline like we know now what are our users what is the typical first baseline and from there uh

264
00:28:40,560 --> 00:28:45,840
we should be able to map the actual capabilities uh looking at the first baseline now

265
00:28:45,840 --> 00:28:52,880
after that we need to ensure like in tune is our enforcement layer so everything should go via

266
00:28:52,880 --> 00:28:59,840
into okay as a first step so that it is our enforcement layer and if you wanted to move with the defender

267
00:28:59,840 --> 00:29:05,360
again uh defender is only acting as a detection and response layer okay and then you also have

268
00:29:05,360 --> 00:29:10,640
defender configured everything from in tune like let's say for ASR policies uh any of the security

269
00:29:10,640 --> 00:29:15,040
related policies right maybe baseline everything should go from in tune so that's why we say in tune

270
00:29:15,040 --> 00:29:19,520
as the enforcement layer defend the detection address per layer and then there should be the

271
00:29:19,520 --> 00:29:25,040
fifth one which is like continuous course to cover is a view like this is something you do as part of

272
00:29:25,040 --> 00:29:30,480
your continuous job or continuous review so that you know your environment much better and then

273
00:29:30,480 --> 00:29:35,760
you are able to identify the typical gaps or the overall licenses that you have in your environment

274
00:29:35,760 --> 00:29:48,960
and yeah now that's the governance with into into in um if someone still thinks

275
00:29:49,520 --> 00:29:55,600
of in tune as Microsoft mobile device management product what they are missing

276
00:29:55,600 --> 00:30:03,280
they are missing as I said they're missing done of things and that's why I wanted to say again

277
00:30:03,280 --> 00:30:09,200
like we should treat in tune as the enforcement layer for every configuration every settings every

278
00:30:09,200 --> 00:30:16,000
apps management anything right because in tune is again connected with each of every features

279
00:30:16,000 --> 00:30:22,320
that we have with Microsoft 365 and this is where you should act in tune as an enforcement layer

280
00:30:22,320 --> 00:30:29,600
and we should not fit into as only MDM solution right now with the features and the upgrades that

281
00:30:29,600 --> 00:30:35,600
are being delivered by in tune right it is pretty much one of the you know favorite tools for any

282
00:30:35,600 --> 00:30:40,240
of the administrator to manage the man device plates not only device plates but also you know

283
00:30:40,240 --> 00:30:44,960
you are managing managing the security posture you are managing the mobile devices

284
00:30:44,960 --> 00:30:49,040
that you are also managing the OEM updates everything right like patch management

285
00:30:49,040 --> 00:30:55,120
application management so all these features are now coming to engine which which makes in tune

286
00:30:55,120 --> 00:30:58,240
a better product as compared to what we have in the market

287
00:30:58,240 --> 00:31:08,000
and um what is the first workloads you normally move into in tune

288
00:31:10,480 --> 00:31:18,560
so yeah the first and most was like we moved the patch management okay this was one of the things

289
00:31:18,560 --> 00:31:23,920
that we wanted to get rid of from the ssm because the way in tune has the windows auto patch

290
00:31:23,920 --> 00:31:31,040
right we wanted to really utilize this as the feature because it is it is something like it is

291
00:31:31,040 --> 00:31:40,000
a bit less pinned or let's say a bit effective as compared to ssm then if you ask about the second

292
00:31:40,000 --> 00:31:46,240
thing it is the application management okay anyway like we could not move initially everything because

293
00:31:46,240 --> 00:31:51,360
there were some dependencies on the ssm but yeah for most of the cases like application deployment

294
00:31:51,360 --> 00:31:57,680
application management we were able to do that third is also about the devices management

295
00:31:57,680 --> 00:32:03,680
right like provisioning thing like windows auto pilot this is one of the major ideas I think which

296
00:32:03,680 --> 00:32:12,160
we really liked about the in tune because we started to deliver the cloud giant devices from in tune

297
00:32:12,160 --> 00:32:19,600
right in ssm or other blega city devices also we environment when it to be dependent on the on

298
00:32:19,600 --> 00:32:32,240
on devices but now it is something like when it to go with the cloud devices

299
00:32:32,880 --> 00:32:48,000
okay um what did you think about organizations do organizations create too many policies into

300
00:32:48,000 --> 00:32:58,240
in tune or is to less or what the typical mistakes um yeah like it should be organized type

301
00:32:58,240 --> 00:33:03,280
and that's what I can say if you want to have in tune policies it should be organized and it is

302
00:33:03,280 --> 00:33:08,800
very well connected with each and every other feature or component that we use in our environment

303
00:33:08,800 --> 00:33:14,480
right so when we design a policy we should see like which all areas are being covered and rather than

304
00:33:14,480 --> 00:33:21,440
making number of policies altogether try to make it like a baseline right like let's say for

305
00:33:21,440 --> 00:33:28,640
a security baseline if you have different policies different if you have maybe windows devices

306
00:33:28,640 --> 00:33:34,960
policies different maybe grow age all like browser specific policies so if you have different

307
00:33:34,960 --> 00:33:40,000
different policies right managing and maintaining is a bit problem so I would prefer like rather

308
00:33:40,000 --> 00:33:45,840
not having different policies n number of policies it is all time to look with the security

309
00:33:45,840 --> 00:33:52,400
baselines which has been almost like um introduced by Microsoft like it has been released by

310
00:33:52,400 --> 00:33:56,720
and we have a typical version updated from the Microsoft like what are the typical service

311
00:33:56,720 --> 00:34:00,800
baseline or the security baseline that needs to be there so I think someone should go and build

312
00:34:00,800 --> 00:34:07,840
those policies which is a better way to approach yeah and I think another interesting topping is

313
00:34:07,840 --> 00:34:16,800
provisioning and device provisioning and it says yeah I think change dramatically there then we

314
00:34:16,800 --> 00:34:23,840
talk about a tool when this auto pilot what problem do windows auto pilot actually solve

315
00:34:23,840 --> 00:34:33,040
yeah as I said like the important thing is with the windows auto pilot it is drastically reducing the

316
00:34:33,040 --> 00:34:41,360
overall imaging time okay the way image was done in the past it was taking somewhere around 3 years

317
00:34:41,360 --> 00:34:46,880
okay just to maybe starting from 1.5 or 3 years depending on upon the network again

318
00:34:46,880 --> 00:34:52,720
but yeah that was a typical time the imaging time that we had in the past but now it has been

319
00:34:52,720 --> 00:34:58,080
drastically reduced like let's say having the provisioning policies in place windows auto pilot you

320
00:34:58,080 --> 00:35:04,480
just copy devices and then with the auto pilot your device is provisioned okay it could be

321
00:35:04,480 --> 00:35:09,760
used for a vision device provision but normally it should not take more than 20 minutes 15 to 20 minutes

322
00:35:09,760 --> 00:35:16,320
is barely the time that we see with the windows auto pilot and that is where it auto pilot is helping

323
00:35:16,320 --> 00:35:20,480
all the organizations and the second motion but the thing where you they're just described

324
00:35:20,480 --> 00:35:25,760
earlier was related to Corona era right so windows auto pilot has came as one of the

325
00:35:25,760 --> 00:35:32,240
Savior for the IT team where they wanted to build the devices at the customer right now the user

326
00:35:32,240 --> 00:35:38,720
end okay without giving much of knowledge or let's say without having much of efforts from the iD

327
00:35:38,720 --> 00:35:44,320
side they are just you know connecting with the OEM they are getting in the windows auto pilot

328
00:35:44,320 --> 00:35:50,320
hooked to their environment they are able to you know add devices to the auto pilot and then the

329
00:35:50,320 --> 00:35:55,520
user is able to build the devices on their own which was quite missing earlier before Corona era

330
00:35:55,520 --> 00:36:01,680
right if you need to do that I know like you need to have some expertise you need to have that network

331
00:36:01,680 --> 00:36:07,920
connectivity that was one of the again dependency right but now it has been changed all together

332
00:36:07,920 --> 00:36:16,880
so the transition to the corporate device image is it's that yeah that's what I can say

333
00:36:16,880 --> 00:36:23,920
okay okay um i think a little bit about this idea

334
00:36:23,920 --> 00:36:31,120
again an organization realistic ship laptops directly from the supply at you and

335
00:36:31,120 --> 00:36:39,120
employee without Emma touched it yes that's what the windows auto pilot makes your life better

336
00:36:39,120 --> 00:36:45,600
like normally every organization has a tie up with the OEMs right and then we give

337
00:36:45,600 --> 00:36:51,520
we give normally a tenant access to them so that they can add those devices when they're ship

338
00:36:51,520 --> 00:36:56,960
from factory to end users so we don't need to do anything like as soon as the devices are added

339
00:36:56,960 --> 00:37:03,600
to our tenant the provision policies are attached to it and the way those are configured it's like

340
00:37:03,600 --> 00:37:11,200
like mostly like a zero touch right like user's need to unpack then you need to connect to

341
00:37:11,200 --> 00:37:17,120
internet and then then you to use their login email address password and that's it just wait for

342
00:37:17,120 --> 00:37:24,320
10 or 10 minutes and your system is built all together um i see where i think

343
00:37:24,320 --> 00:37:36,960
in tune it's it started as i say as as device configuration tool now it's it's an amazing

344
00:37:36,960 --> 00:37:42,720
or a really important part of of the security architecture what why is this happen

345
00:37:45,760 --> 00:37:55,120
regarding what yeah yeah in tune is this isn't just about configurable devices anymore

346
00:37:55,120 --> 00:38:03,120
how does it become a part of the security architecture right so as i say like we have this defender

347
00:38:03,120 --> 00:38:09,440
which is also tied with in tune and since in tune would be more like a enforcement layer

348
00:38:09,440 --> 00:38:15,200
for any of the policies configurations it could be security configurations it could be

349
00:38:15,200 --> 00:38:22,320
security baseline it could be any aspect of the security right so you have this all of the configuration

350
00:38:22,320 --> 00:38:27,200
policies that can be managed all together within in tune so you don't need to navigate all together

351
00:38:27,200 --> 00:38:32,080
to each and every portal you can do those all of the security configurations right away from

352
00:38:32,080 --> 00:38:38,320
into itself so that's why i think this is one of the biggest area that we can see as an improvement

353
00:38:38,320 --> 00:38:45,040
and the way it is attached to all the security systems is also really making it much better

354
00:38:45,600 --> 00:38:50,000
in the security posture right we improve the overall security posture so at the moment like

355
00:38:50,000 --> 00:38:54,880
let's say if i want to deploy any of the anti-war as policies i can do it from in tune if i want to

356
00:38:54,880 --> 00:39:00,000
do any of the it's the scalar policies right which is i can security i can do it from in tune

357
00:39:00,000 --> 00:39:06,560
like in tune is most like a management tool now where you can build any of the security policies

358
00:39:06,560 --> 00:39:11,840
just by creating the policies or importing the any of the adm templates that is available within

359
00:39:11,840 --> 00:39:16,800
the tools and you should be able to manage the overall policies so i think that's how it has been

360
00:39:16,800 --> 00:39:19,920
really improved overall as compared to what we had in the past.

361
00:39:19,920 --> 00:39:30,080
You have also bring defender to the architecture when someone says Microsoft defender that

362
00:39:30,080 --> 00:39:35,840
actually in entry family of products how do you explain the ecosystem?

363
00:39:38,720 --> 00:39:46,320
See defender is really big shark that's what i can say like it should be pretty much aware

364
00:39:46,320 --> 00:39:52,000
about all the protection layers that defender is providing and then you should be able to unlock

365
00:39:52,000 --> 00:39:59,040
all the features that defender is providing like as i said like when we did our licensing migration

366
00:39:59,040 --> 00:40:06,160
right we discovered like there are many features that are being not used as part of the defender

367
00:40:06,160 --> 00:40:11,680
and then there are some of the features which were over utilized as well right and then we need to

368
00:40:11,680 --> 00:40:15,760
be compliant from the Microsoft site like no no this is something we cannot use for e3 users

369
00:40:15,760 --> 00:40:20,000
probably we need to use it only for the e5 users because those functionality or those license

370
00:40:20,000 --> 00:40:25,680
components are not really provided as part of the service plan which has been provided by e3

371
00:40:25,680 --> 00:40:31,200
or e5 licenses so let's say from the defender right you have your Microsoft defender right as the

372
00:40:31,200 --> 00:40:38,000
anti-ware stool it works as a anti-ware stool it works as a defender for endpoint okay managing your

373
00:40:38,000 --> 00:40:44,640
endpoints it could be having like plan one plan two where you were really utilizing your defender

374
00:40:44,640 --> 00:40:50,160
capabilities okay like maybe from the security perspective from blocking from researching from

375
00:40:50,160 --> 00:40:55,360
developing or let's say also from this category you put face right so there is also something you

376
00:40:55,360 --> 00:41:01,360
can use it within the defender so these are the typical you know configurations or difficult

377
00:41:01,360 --> 00:41:06,560
layers that you have within the defender but unless and until you don't know you won't be able to

378
00:41:06,560 --> 00:41:12,880
unlock these features so you need to have that defender portion looked thoroughly thoroughly and then

379
00:41:12,880 --> 00:41:18,560
understand like what is the defender offering and what are the capabilities and how we can do a

380
00:41:18,560 --> 00:41:31,360
lot those who that's built a scenario a managed up top start behaving as a specifically defender

381
00:41:31,360 --> 00:41:37,120
detects a firm thing what is next in the major Microsoft environment

382
00:41:37,120 --> 00:41:47,200
so yeah so there could be multiple scenarios right like when we say my defender is detecting

383
00:41:47,200 --> 00:41:55,680
something so we have a typical let's say a ticket that has been created as part of the defender portal

384
00:41:55,680 --> 00:42:01,040
right like as for the detection and response so the security team is normal response equal if in

385
00:42:01,040 --> 00:42:10,160
case we see in the behavior which is you know having a threat altogether so that has been

386
00:42:10,160 --> 00:42:15,600
flat using the defender as part of the detection and response framework that we have where every

387
00:42:15,600 --> 00:42:21,760
ticket is been standardized every ticket has been really looked upon from the security team they block

388
00:42:21,760 --> 00:42:26,640
the devices if in case they feel like now this is a real security and there could be also some false

389
00:42:26,640 --> 00:42:33,360
alarm so we need to really see what is the actual impact what is the behavior where it is blocking

390
00:42:33,360 --> 00:42:39,440
what all models are been blocked and then how it has been really moved forward as part of the

391
00:42:39,440 --> 00:42:46,320
detection and this one strategy that we have within defender so could we essentially create a

392
00:42:46,320 --> 00:42:58,320
loop detect, evaluate, restrict, remake and then store okay what will you say from your perspective

393
00:42:58,320 --> 00:43:05,600
how many organizations actually implement the complete loop? I can like for every organization

394
00:43:05,600 --> 00:43:11,040
there is a different environment or behavior like how they treat the defender in some cases they might

395
00:43:11,040 --> 00:43:15,920
have don't they don't have the feature itself or the components itself some of them have

396
00:43:15,920 --> 00:43:21,600
eliminated and some of them have a full skill so whenever we have a full skill I'm pretty much sure

397
00:43:21,600 --> 00:43:28,160
they are using this feature but I cannot in a full way where it is explored where you do the

398
00:43:28,160 --> 00:43:34,000
overall discovery you do the overall detection at response and I think if you ask me like the

399
00:43:34,000 --> 00:43:39,360
recommendation is to use defender for detection and response and then you have your security team

400
00:43:39,360 --> 00:43:46,320
actual looking into those detections that we have from defender right that is a major

401
00:43:46,320 --> 00:43:59,040
yeah yeah my Microsoft talks extensively about zero trust but yeah the term can become very

402
00:43:59,040 --> 00:44:05,520
abstract what does zero trust actually mean to you operationally?

403
00:44:05,520 --> 00:44:14,240
see zero trust means again same thing like we should not allow anything which is outside our

404
00:44:14,240 --> 00:44:20,480
environment and if it has been allowed then we should have a proper security guard to it

405
00:44:20,480 --> 00:44:25,680
which would go and scrutinize to eat an over security aspect and only once it is been

406
00:44:25,680 --> 00:44:30,880
authenticate allowed right and then you have the proper necessary security tools,

407
00:44:30,880 --> 00:44:37,120
your confirmation security measures in place only then the device is allowed to an environment

408
00:44:37,120 --> 00:44:41,920
so I think that's where it comes as a zero trust like we won't be able to trust any of the

409
00:44:41,920 --> 00:44:46,240
outsiders without you go through any of the security mechanisms that we have in place.

410
00:44:49,440 --> 00:44:56,560
what is zero trust exactly is it's a Microsoft product, a service, a framework,

411
00:44:56,560 --> 00:44:59,520
how will you describe it?

412
00:44:59,520 --> 00:45:12,960
sorry it went for a minute okay yeah no so if you ask me like how we would really

413
00:45:14,400 --> 00:45:21,680
describe zero trust it says more like maybe modern cyber security strategy okay that's something

414
00:45:21,680 --> 00:45:29,120
we have as part of the modern modernization strategy so it is fundamentally you know changing

415
00:45:29,120 --> 00:45:35,760
like how organization approves the overall security so it just typically built on the principle of like

416
00:45:35,760 --> 00:45:41,600
never trusting anything on anyone or default like as I said never trusting any of the external things

417
00:45:42,160 --> 00:45:48,960
and then continuously verifying like there is a typical security pushchers,

418
00:45:48,960 --> 00:45:54,320
ability mechanism for every accessor request that has been given for us right so again this is

419
00:45:54,320 --> 00:46:02,560
typically based on our three core principles like maybe verification of identity then application

420
00:46:02,560 --> 00:46:08,880
context and then of course like enforcement of least rule age right like how we are doing that

421
00:46:08,880 --> 00:46:14,640
least rule age within our environment so yeah that's that's how I think we look with the zero trust

422
00:46:14,640 --> 00:46:21,280
again that's not something like it's a product it's more like a mindset that we have and this is

423
00:46:21,280 --> 00:46:27,120
something like we take care as part of the design like when we are thinking about a security aspect

424
00:46:27,120 --> 00:46:32,480
and then they should be implemented across an organization not only for specific maybe

425
00:46:32,480 --> 00:46:38,080
organized specific business, financial something so it should be more like an organization

426
00:46:38,080 --> 00:46:43,040
level adopted strategy that comes as part of the security and there are typical comprehensive

427
00:46:43,040 --> 00:46:48,720
frameworks that that has been there like how we really implement zero trust and nowadays like we

428
00:46:48,720 --> 00:46:55,520
have AI right that is also something evolving into this category like how we really include like

429
00:46:55,520 --> 00:47:01,200
AI driven attacks and then how we are connected all together so I think yeah this is how I would

430
00:47:01,200 --> 00:47:07,280
really say like how this zero trust is coming or it's more like a mindset rather than a product

431
00:47:07,680 --> 00:47:21,280
yeah yeah yeah we can't have 2006 2026 Microsoft con yeah conversion without talking about

432
00:47:21,280 --> 00:47:28,720
about AI I think where do you see AI changing endpoint management actually

433
00:47:28,720 --> 00:47:34,800
yeah the way AI has now evolved right it

434
00:47:34,800 --> 00:47:57,040
you have used it the way the way how it has been done for the AI right

435
00:47:57,040 --> 00:48:03,680
adapting the endpoints it should be now more like focused on the IT operations like the IT ops

436
00:48:03,680 --> 00:48:11,280
like how we wanted to have the AI enabled IT ops all together like let's say you have a prediction

437
00:48:11,280 --> 00:48:17,360
mechanism you have then a prior to mechanism all together that you can enable using AI right

438
00:48:17,360 --> 00:48:23,760
let's say maybe for example next thing is a good tool like for my experience where we were using it

439
00:48:23,760 --> 00:48:29,280
in the past for AI capabilities and then it was giving us a good feature like it was able to

440
00:48:29,280 --> 00:48:36,160
product what is happening with the endpoints it was also practically fix the issues okay using some

441
00:48:36,160 --> 00:48:43,200
of the data that we have as part of the telemetry okay so this is how I would say like how the AI

442
00:48:43,200 --> 00:48:48,640
is helping the endpoints when we wanted to work because earlier the problem was like let's say there is

443
00:48:48,640 --> 00:48:54,640
a user he's complaining like there is some issue now we come to know only when he's complaining

444
00:48:55,280 --> 00:49:02,400
but we never know before he had some issues right so this is where AI is helping like it will predict us

445
00:49:02,400 --> 00:49:09,520
looking at the logs looking at the given telemetry like how the device is able to work what is the

446
00:49:09,520 --> 00:49:15,200
typical desktop how the device is operating what is the typical health and then what are the

447
00:49:15,200 --> 00:49:20,800
typical issues that user had right it could be possible like user is having a biosodica as for maybe

448
00:49:20,800 --> 00:49:27,200
last couple of weeks okay he's not reporting in the issues but it just not like his devices in a good

449
00:49:27,200 --> 00:49:33,680
condition it could be possible like his device health status is quite bad or the desktop is quite

450
00:49:33,680 --> 00:49:40,000
not in a good shape so this is where AI is helping us to give that productive information and then

451
00:49:40,000 --> 00:49:45,040
we can practically fix those issues rather than user coming to us to fix the issues we would be

452
00:49:45,040 --> 00:49:49,440
going to them and then helping this practically so I think this is what it helps.

453
00:49:49,440 --> 00:49:56,400
It helps but it cannot handle the endpoint management.

454
00:49:56,400 --> 00:50:04,800
It helps I can say like totally we cannot be relying on the AI but yeah at least you can

455
00:50:04,800 --> 00:50:10,400
left ship some of your L1 strategies or L1 task to AI I think this is where I would see AI

456
00:50:10,400 --> 00:50:16,960
fade into it most of the capabilities that they offer like we really cannot be dependent for

457
00:50:16,960 --> 00:50:24,240
everything on AI so if you say you wanted to inject AI into your IT labs then I think this is where

458
00:50:24,240 --> 00:50:28,800
I can see the opportunity where we are adding this as a one task.

459
00:50:34,560 --> 00:50:47,200
I think architecture really really big and I like to make it more practical so imagine a global

460
00:50:47,200 --> 00:50:55,680
enterprise was 50,000 employees been also at Mac IOS and Android, Windows 365, Android

461
00:50:55,680 --> 00:51:04,160
the regulatory, existing SCCM infrastructure, thousands of applications, employee work globally,

462
00:51:04,160 --> 00:51:13,760
contractors, bring your own device, e3, e5, e7, licensing, multi third party security tools.

463
00:51:13,760 --> 00:51:21,040
The CIO says we want modern managed stronger security, lower lives and cost.

464
00:51:21,040 --> 00:51:22,640
Where did you start?

465
00:51:22,960 --> 00:51:31,680
Again for me I think if I would go right I would go with the discovery procedure altogether

466
00:51:31,680 --> 00:51:37,680
okay that's what I said like if you want to define like what is the license strategy we need to

467
00:51:37,680 --> 00:51:43,760
do the licensing audit altogether and then we need to also have the capability map in we need to

468
00:51:43,760 --> 00:51:48,880
know our environment better I think that's where I'm coming from so if you want to have everything

469
00:51:48,880 --> 00:51:58,000
you need to know your use case and then you need to know what is there in future like let's say

470
00:51:58,000 --> 00:52:03,920
you need to also predict some of the things you should not be only dependent on what is current

471
00:52:03,920 --> 00:52:09,760
like in some cases let's say you have a security poster you need to improve your security poster

472
00:52:09,760 --> 00:52:15,280
but if you do not have that now as part of the designing architecture mind then you will lose

473
00:52:15,280 --> 00:52:22,000
that functionality when you want to have it in future right in in some cases we see like this is a bit

474
00:52:22,000 --> 00:52:29,600
missed decision from the architect or the licensing thing who do that and then later on they

475
00:52:29,600 --> 00:52:35,360
discover like that is a gap right so just to overcome you need to do that altogether and as I said

476
00:52:35,360 --> 00:52:40,160
for any licensing thing or any confusions what we need to do we need to have that audit we need to

477
00:52:40,160 --> 00:52:44,720
know our environment better and we need to map those specific use cases so that you know where

478
00:52:44,720 --> 00:52:49,520
we would be utilizing or leveraging all these tools or features like as I said for the BYOD

479
00:52:49,520 --> 00:52:54,640
concept as well you need to know what all your users are because BYOD again it is not accepted by

480
00:52:54,640 --> 00:52:59,040
each and every region like if you are working in a global company it's something like you cannot

481
00:52:59,040 --> 00:53:04,720
have this adoption in every company or any every organization or every location within your

482
00:53:04,720 --> 00:53:10,400
global company right so there might be some limitations so you need to also know like what are those

483
00:53:10,400 --> 00:53:14,960
limitations what are the typical use cases and how we wanted to avoid that.

484
00:53:14,960 --> 00:53:28,880
Awesome I think a little bit about the how we can go I can say

485
00:53:30,080 --> 00:53:35,840
how do we prevent the transformation from disrupting these thousands of employees.

486
00:53:35,840 --> 00:53:46,720
Distruption right like how we can avoid a disruption for the thousands of lives again like

487
00:53:46,720 --> 00:53:51,760
the discussion could be anything right like it's not like it is only licensing it could be anything

488
00:53:51,760 --> 00:53:56,480
the discussion is something where you are not actively monitoring your services you are not

489
00:53:56,480 --> 00:54:05,840
actively monitoring your deliveries okay most of the time like what we say in a typical you know

490
00:54:05,840 --> 00:54:13,840
environment if you someone is working in most of the cases the disruption is like when you are not

491
00:54:13,840 --> 00:54:19,760
following the typical standard procedures or typical standard architect designs right if you are

492
00:54:19,760 --> 00:54:24,320
not able to renew this with your peers if you are not able to handle it properly if you are not

493
00:54:24,320 --> 00:54:29,040
able to really implement as per the canvas then there is a possibility of having a disruption in

494
00:54:29,040 --> 00:54:34,960
year future right but something I would say like we should avoid altogether so that we are able to

495
00:54:34,960 --> 00:54:42,960
minimize the disruption okay wherever necessary of course we cannot really stop the disruption

496
00:54:42,960 --> 00:54:48,960
altogether but at least you can minimize by having the good reviews good decisions having the good

497
00:54:48,960 --> 00:54:53,920
high level level document you know everything is documented everything is a good and then

498
00:54:54,640 --> 00:55:01,120
everything is implemented as well we can't hold okay yeah that's it's cool so

499
00:55:01,120 --> 00:55:08,880
yeah thank you first for this I have a quick fire round so I give a short question and you give

500
00:55:08,880 --> 00:55:16,800
give a short answer okay Windows Windows or Mac OS Windows

501
00:55:17,920 --> 00:55:24,720
cloud native or hybrid hybrid compliance policy or conventional like this

502
00:55:24,720 --> 00:55:31,040
conditional axis one in tune feature more organization should use

503
00:55:31,040 --> 00:55:40,560
use tight yeah auto wallet most underestimated endpoint security risk

504
00:55:43,520 --> 00:55:50,720
business units like roaming users one technology in EUC you are most excited about

505
00:55:50,720 --> 00:55:59,600
modernizing the digital workplace and how we really adapt and connect to the cloud

506
00:55:59,600 --> 00:56:06,320
stops and then of course working with the AI adoption all together okay and finish the

507
00:56:06,320 --> 00:56:17,120
sentence the endpoint of the future will I sorry vote endpoint finish the sentence the endpoint of

508
00:56:17,120 --> 00:56:34,480
the future will no okay yeah so thank you for for the interview who shall I invite next and

509
00:56:34,480 --> 00:56:45,760
what a question should I ask yeah probably any of the MVP so any of the let's say the community

510
00:56:45,760 --> 00:56:52,320
masters where they are typically implying the overall end user experience so it could be someone who

511
00:56:52,320 --> 00:57:00,800
is you know working all together into the Windows as a core concept and then also implementing the

512
00:57:00,800 --> 00:57:08,720
air related strategies I think that's one I would say best you go with yeah so in this yeah

513
00:57:08,720 --> 00:57:16,720
what's that out from this conversation it's how closely connected these areas all have become

514
00:57:16,720 --> 00:57:24,000
Microsoft licensing isn't a simple pursuer man problem in tune isn't a simple device management

515
00:57:24,000 --> 00:57:30,000
but the defender isn't a simple anti-rear and identity isn't a simple user name in possible words

516
00:57:30,000 --> 00:57:37,200
yeah together they create an architecture where identity device health security signals

517
00:57:37,200 --> 00:57:44,640
accessible is licensing you buy all influence each other um yeah so this was really cool so

518
00:57:44,640 --> 00:57:51,440
so thank you for staying here with me for all the listeners the info are all on the MC 60

519
00:57:51,440 --> 00:57:58,400
part of the podcast page from Bindersh you think the links and yeah thank you so much for staying

520
00:57:58,400 --> 00:58:06,080
here with me thanks thanks we'll go thanks everyone thanks everyone listening you have

521
00:58:06,080 --> 00:58:14,240
looking forward thanks yeah thank you have a nice day bye

Mirko Peters Profile Photo

Founder of m365.fm, m365.show and m365con.net

Mirko Peters is a Microsoft 365 expert, content creator, and founder of m365.fm, a platform dedicated to sharing practical insights on modern workplace technologies. His work focuses on Microsoft 365 governance, security, collaboration, and real-world implementation strategies.

Through his podcast and written content, Mirko provides hands-on guidance for IT professionals, architects, and business leaders navigating the complexities of Microsoft 365. He is known for translating complex topics into clear, actionable advice, often highlighting common mistakes and overlooked risks in real-world environments.

With a strong emphasis on community contribution and knowledge sharing, Mirko is actively building a platform that connects experts, shares experiences, and helps organizations get the most out of their Microsoft 365 investments.

Videsh Chavan Profile Photo

Head - EUC Engineering and Identity

Videsh Chavan is the Head of EUC Engineering and Identity at PerkinElmer, bringing 18 years of experience in end-user computing, device management, and identity and security. Over his career, he has built and led enterprise-scale M365, device management, and identity security programs, and was recognized with the Next 100 CIO Award for 2025 in acknowledgment of his leadership and impact in the field. Based in Pune, Videsh is driven by a constant curiosity to learn and stay ahead in the fast-evolving EUC landscape, and enjoys engaging with the community on emerging trends in Microsoft 365, device management, and identity security.