Episodios

  • THE Security Insights Show Episode 281: Jingle Hack '25: Elves on the Shelf (Watching Your Wi-Fi)
    Dec 5 2025

    After a pre-Ignite cliffhanger, we welcome back the illustrious James Key. This episode, James is back to fill us in on the Ignite announcements around Security Copilot that he couldn’t talk about last time.

    Show Notes/Links

    * Learn about Security Copilot inclusion in Microsoft 365 E5 subscription https://learn.microsoft.com/en-us/copilot/security/security-copilot-inclusion

    * Microsoft 365 adds advanced Microsoft Intune solutions at scale https://techcommunity.microsoft.com/blog/microsoftintuneblog/microsoft-365-adds-advanced-microsoft-intune-solutions-at-scale/4474272

    * What is Microsoft Entra Agent ID? https://learn.microsoft.com/en-us/entra/agent-id/identity-professional/microsoft-entra-agent-identities-for-ai-agents

    * The Microsoft Security Store: https://SecurityStore.Microsoft.com



    This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.microsoftsecurityinsights.com
    Más Menos
    1 h y 22 m
  • THE Security Insights Show Episode 280: Turkey-Day Trojans
    Nov 25 2025

    As the Thanksgiving turkey roasts and the family gathers, cybercriminals are lurking in the digital shadows, ready to crash your holiday feast. In Episode 280 of THE Security Insights Show, hosts serve up a timely platter of cybersecurity wisdom to keep your “gravy secrets”—those juicy credentials, financial data, and personal info—safe from opportunistic hackers.Dive into the rising tide of “Turkey-Day Trojans”: sneaky malware disguised as festive deals, phishing emails from “Aunt Edna” demanding urgent wire transfers, and smart home devices turned into spy cams by unsecured Wi-Fi. We’ll unpack real-world holiday hacks, from ransomware gobbling up your shopping carts to social engineering tricks exploiting family chit-chat. Plus, get actionable Microsoft Security tips—like leveraging Defender for endpoint protection, Entra ID for secure guest access during virtual toasts, and Copilot-powered threat hunting to spot the bad stuffing before it sours the meal.Whether you’re a CISO stress-testing your perimeter or just a home user dodging Black Friday bait, this episode arms you with the tools to feast worry-free. Tune in now on YouTube, Apple Podcasts, Spotify, or your favorite platform—because nothing ruins a holiday like a data breach on dessert. Don’t forget to subscribe for more bites of security insight!

    This episode of “THE Security Insights Show” covers a range of topics, starting with personal updates and discussions about cybersecurity certifications. The hosts delve into the role of Artificial Intelligence (AI) in cybersecurity, specifically debating the necessity of learning KQL (Kusto Query Language) from scratch given the advent of natural language to KQL models (16:01). They discuss the importance of understanding underlying data and language nuances even with AI assistance (18:56).

    The conversation then pivots to key announcements from Microsoft Ignite, including:

    * Work IQ: An intelligent layer that enhances productivity by connecting organizational and personal data, enabling AI-driven insights and recommendations within Microsoft 365 applications (31:31).

    * Proactive Attack Disruption and Predictive Shielding: Microsoft’s new capabilities to anticipate attacker moves during ongoing attacks, dynamically hardening targets in real-time (35:59).

    * Expanded Automatic Attack Disruption: This feature extends to work across third-party services like AWS, Okta, and Proofpoint, allowing Microsoft Defender to take decisive actions on external systems even if the threat originates from a non-Microsoft system (39:06).

    * Rebranding of Defender XDR to Borg XDR: Indicating a consolidation of more Defender for Cloud functionality and assimilation of Sentinel into the unified Defender portal (42:00).

    * Native Sysmon in Windows 11: A significant announcement for security professionals (42:35).



    This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.microsoftsecurityinsights.com
    Más Menos
    1 h y 4 m
  • THE Security Insights Show Episode 279: Security Copilot Updates
    Nov 7 2025

    In this electrifying episode, we sit down with James Key, Principal Product Manager for Microsoft Security Copilot, to unpack the groundbreaking advancements shaping the future of AI-driven security. With over nine years of expertise in cloud architecture, technical training, and product innovation, James is at the forefront of empowering security teams worldwide through intelligent, partner-led solutions.As cyber threats evolve at breakneck speed, Microsoft Security Copilot is supercharging defenses with its latest fall updates. James breaks down the integration with the new Sentinel data lake and graph, enabling seamless data querying and real-time threat hunting like never before. We’ll explore the debut of ready-made and custom agents that automate complex workflows, from incident response to vulnerability management, freeing up pros to focus on strategy.But it’s not just tech—James shares how the newly launched Microsoft Security Store is uniting partners in a bold ecosystem for innovation, fostering collaborative AI tools tailored to enterprise needs.

    Links/Notes

    * Microsoft Security Store: https://securitystore.microsoft.com/agents

    * Agent YAML Builder: https://github.com/rod-trent/JunkDrawer/tree/main/AgentBuilder

    * Microsoft Ignite Security Copilot sessions: https://ignite.microsoft.com/en-US/sessions?filter=&search=Security+Copilot&sortBy=relevance

    * glueckkanja AG: https://www.linkedin.com/company/glueckkanja/

    * adaQuest: https://www.linkedin.com/company/adaquest-inc/



    This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.microsoftsecurityinsights.com
    Más Menos
    1 h y 10 m
  • THE Security Insights Show Episode 278: Pumpkin Patch Phishers: Carving Out Your Data This Halloween
    Oct 24 2025

    Picture this: It’s the witching hour of cybersecurity, where jack-o’-lanterns glow with malevolent code and candy corn conceals keyloggers. In this spine-tingling episode of The Security Insights Show, we dive headfirst into the ghoulish guts of seasonal phishing scams – those crafty creeps who lure you in with “Free Zombie Apocalypse Prep Kits” emails, only to carve up your credentials like a deranged pie maker at a harvest festival.

    Join our hosts as they unmask the tricks-or-treats of spear-phishing spooks, ransomware pumpkins that explode in your inbox, and why your two-factor auth is the garlic necklace against digital Dracula. We’ll roast real-world horror stories – like the exec who traded his soul (and SSO login) for a “haunted house discount” – and arm you with tricks to keep your data from doing the monster mash.

    This episode of “THE Security Insights Show” discusses the risks and security challenges associated with artificial intelligence (AI), particularly concerning phishing scams during the Halloween season (0:21). The hosts, Rodney and Franklin, touch on various aspects of AI, its adoption, and the evolving landscape of cybersecurity.

    Key discussion points include:

    * The hosts’ return and show changes: Rodney and Franklin discuss their return to the show after a summer break, moving to a bi-weekly Thursday schedule to allow more time for content creation and guest planning (1:02-6:54).

    * October as Cybersecurity Awareness Month: They emphasize the importance of cybersecurity awareness, noting a lack of guest speakers this year compared to previous years (4:17-4:33).

    * Artificial Intelligence (AI) and its security implications: A significant portion of the discussion revolves around AI, specifically the challenges of securing and governing it (7:47). They highlight the increasing use of AI in creating sophisticated phishing campaigns and the alarming potential for “non-human entities” or “agentic offerings” to be compromised or act as “double agents” in an environment (10:10-10:57).

    * Understanding AI architecture and threats: Franklin argues that securing AI is fundamentally about securing compute, identity, data, and networks, with the Large Language Model (LLM) being a new threat (11:31-12:29). They discuss the role of the MCP (Microsoft Collaboration Protocol) server in providing context between chatbots and data sources, acknowledging that generative AI can sometimes provide inaccurate responses (13:03-15:41).

    * Challenges in AI security and training: The hosts express concern about the lack of fundamental understanding of AI among security professionals and the trend of training courses merely adding “with AI” to existing content without real value (28:41-31:21). They also discuss the emergence of highly specialized roles in AI security, like the “Chief Artificial Intelligence Risk Officer (CAIRO),” and the potential for a “corporate fear of missing out” driving quick, potentially insecure, AI adoption (36:06-38:29).

    * The CISO’s role and application expectations: Franklin suggests that CISOs have the necessary tools for AI security, viewing it as another application to secure, while Rodney believes many are unprepared due to rapid adoption and an “outnumbered” feeling in defense (37:42-43:52).



    This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.microsoftsecurityinsights.com
    Más Menos
    1 h y 2 m
  • THE Security Insights Show Episode 277: Is this thing on???
    Oct 18 2025

    After the first-ever summer break, the crew is back! New crew. New format. Listen or watch to hear about what’s coming.

    We also welcome Alistair Pugin. Microsoft MVP for M365 + Security, Blogger, Podcaster and Speaker.

    Key Highlights

    * Return of the Show (1:38): The hosts are back after a three-month summer break, during which they experienced new jobs, roles, and duties. They thank their listeners and confirm the original cast of Edward Walton, Rod Trent, and Franklin Grimberg are back, though Brody is still on hiatus.

    * Focus on AI and Security (0:52, 1:02): Frank highlights the current “crazy” world of AI, particularly Microsoft’s efforts to secure and manage it. He expresses concern that many people are unaware of the tools available to them.

    * Guest Introduction - Alistair Pugan (5:57): Alistair Pugan, from Cape Town, South Africa, is introduced as an expert in compliance and information protection, having worked with Microsoft on shaping exams like SC400 and even co-designing a board game about deception.

    * Challenges with AI Adoption (7:58): Alistair discusses the “wild wild west” of AI adoption, where organizations are indiscriminately handing out AI, and users are not following guidelines. He notes the parallel to the Google search appliance debacle of 2008, where people are finding content they shouldn’t.

    * Microsoft’s AI Strategy and Data Training (20:08): The discussion touches on Microsoft’s stance that they do not train their AI models on customer data, emphasizing the importance of data classification for protection.

    * Copilot as Superized Search (24:15): Alistair explains that Copilot functions as a “superized search” within the Microsoft 365 tenant, using semantic indexing and security trimming to ensure users only access data they have permissions for.

    * Data Security Posture Management (DSPM) for AI (28:45): The hosts delve into DSPM for AI, a tool within Microsoft Purview (E3 or E5 licenses) that helps organizations monitor their AI usage. Key aspects include:

    * Components of Data Security (29:51): Frank and Alistair discuss how Microsoft defines data security, including information protection (sensitivity labels), data loss prevention (DLP), and insider risk management.

    * Monitoring AI Usage (31:25): DSPM allows organizations to monitor what users are doing with AI, including AI usage reports and integration with Defender for Cloud Apps.

    * Prompt Monitoring (32:28): It can monitor user prompts, especially for sensitive information requests (e.g., “give me the payroll for everyone”), using sensitive information types or trainable classifiers.

    * Shadow AI Detection (33:21): DSPM helps detect “shadow AI” by monitoring when users visit or upload sensitive information to third-party AI sites like Chat GPT, Gemini, or Perplexity.

    * Policy Automation (34:31): The tool can automatically spin up policies to detect sensitive information in AI prompts, visits to AI sites, and sensitive data uploads to AI sites.

    * Agent Sprawl and Non-Human Identities (15:50, 17:10): A significant concern raised is that anyone with a Microsoft 365 Copilot license can build an agent in Copilot Studio, which registers an application in Entra (Azure Active Directory) and creates “non-human identities.” This can lead to “agent sprawl” and uncontrolled API permissions if not properly managed by identity admins.

    * Mitigating Agent Sprawl (40:03): The solution involves having an application security posture management strategy and robust application onboarding and offboarding policies, as agents are essentially applications that require permissions to interact with data.

    * Copilot Studio Licensing (39:02): There are different licensing models for Copilot Studio: a free tenant license for building agents (for users without an M365 Copilot license) and a premium capacity license for deploying agents to users without a Copilot license.



    This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.microsoftsecurityinsights.com
    Más Menos
    59 m
  • The Security Insights Show Episode 270 - Just Us!
    Jul 30 2025

    Hello podcast listeners and supporters. Today we announced that we will start our late summer | early fall show slow down. After five years of producing the show, we are taking the months of August and September off to recharge, do some back-office updates and re-invent.

    We look forward to having fresh energy and lots of dad jokes upon our return. Keep an eye on the discord channel and website for tips and tidbits until we return.

    thanks

    Brodie, Edward, Frank, Rod

    Watch the live replay



    This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.microsoftsecurityinsights.com
    Más Menos
    25 m
  • The Security Insights Show Episode 269 - Ali Segovia - Microsoft Sr. Consultant - Data Security and Compliance
    Jul 23 2025

    In this episode we talk to Ali about the opportunity for customers to solve big problems and challenges using Purview. We also delve into what it means to have ownership of the scope of a Purview deployment.

    Show notes:

    Teams Channels

    Public Webinars & Training

    Welcome Guide

    Digital Badge Program

    Join the Community

    Feedback Opportunities

    Community Calls

    Recognition & Badges

    Discussion Groups

    Upcoming Public Webinars

    Security YouTube Channel

    Public Forums

    Ninja Training & Certification

    Ninja Show

    Watch the live replay



    This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.microsoftsecurityinsights.com
    Más Menos
    1 h y 8 m
  • The Security Insights Show Episode 268 - Purview Failures (Common Cases for Unsuccessful Deployments)
    Jul 16 2025

    In this episode, one of the leading Microsoft security partners -

    Cyclotron - https://cyclotron.com/ - discusses common and “uncommon” mistakes customers encounter while deploying Microsoft Purview.

    Show notes:

    Teams Channels

    Public Webinars & Training

    Welcome Guide

    Digital Badge Program

    Join the Community

    Feedback Opportunities

    Community Calls

    Recognition & Badges

    Discussion Groups

    Upcoming Public Webinars

    Security YouTube Channel

    Public Forums

    Ninja Training & Certification

    Ninja Show

    Need Assistance? Email our Team

    Microsoft respects your privacy. Review our online Privacy Statement. ​

    Microsoft Corporation | One Microsoft Way | Redmond, WA, USA 98052 ​

    At any point you may opt-out of the program by filling out this form.

    Watch the live replay



    This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.microsoftsecurityinsights.com
    Más Menos
    1 h y 16 m