Néstor Reverón

Nestor Reveron

Technical Trainer Dedicado a la tecnología. aka.ms/nestor

  1. 03/26/2025

    MS-4017 - Microsoft 365 Copilot: Security, Compliance, and Implementation

    The session kicked off with an introduction to the MS-4017 course, focused on managing Microsoft 365 Copilot at the tenant level. It's a technical course aimed at administrators who have experience with Microsoft Entra ID and Microsoft 365. The goal is to understand how to configure Copilot, manage expectations, and cover a mix of technical and conceptual aspects. A significant portion of the session was dedicated to security and compliance, highlighting the critical role of Microsoft Purview. Purview, formerly known as the compliance center, is a powerful solution for information protection, including sensitivity labeling and data loss prevention. It helps ensure that sensitive information used by Copilot is identified and protected. The importance of aligning with regulations like GDPR and ISO standards was also emphasized, with Purview offering assessment tools to help organizations achieve compliance. The concept of Zero Trust was discussed as a central pillar for security, emphasizing "never trust, always verify". This includes explicit verification, the principle of least privilege, and assuming breaches. Applying "just-in-time access" and "just-enough access" principles were highlighted as key to reducing the risk of data leaks. The session then moved to SharePoint Advanced Management. It's crucial to ensure data in SharePoint is well-organized, secure, and has the correct permissions before fully leveraging Copilot. The importance of managing content governance, limiting oversharing, and cleaning up unused sites with potentially sensitive information was underscored. SharePoint Administrators play a key role and require specific permissions to manage these settings. Permissions can be set at the site, page, folder, and even individual file level. Preparing your data for Copilot is another critical step. This involves eliminating redundant, outdated, and trivial data (ROT). Cleaning up old versions of documents and ensuring consistent naming conventions are essential for Copilot to provide accurate and relevant responses. Tagging files with keywords acts as metadata, making it easier for Copilot to retrieve specific information. Establishing clear governance and security policies for Microsoft 365 and Copilot is also vital, with designated individuals or teams responsible for data quality. Understanding Copilot licensing is crucial for implementation. Copilot is an add-on to existing Microsoft 365 licenses, requiring at least a Microsoft 365 Enterprise E3 or E5 license, or specific Office Enterprise E3 or E5 licenses. Best practices for license assignment involve monitoring usage and ensuring that licenses are allocated to those who actively benefit from Copilot. The session also touched upon extending Copilot capabilities. Copilot Studio allows for the creation of custom copilots and agents with specific functionalities, connecting to various data sources and automating processes. This is distinct from the core Microsoft 365 Copilot, which focuses on employee productivity within Microsoft 365 applications. Connectors and plugins can further extend Copilot's reach to external data sources like Salesforce and Service Now. Finally, the discussion clarified the different types of Copilot: Microsoft Copilot (personal): Free or paid (Pro), uses public Bing data, limited integration with personal Microsoft 365.Microsoft 365 Copilot (enterprise): Integrated with corporate Microsoft 365 data (SharePoint, OneDrive, Exchange, etc.), requires specific enterprise licensing.Microsoft Copilot Studio: For creating custom chatbots and agents for business processes.Specialized Copilots: Like Microsoft Copilot for Security, Microsoft Fabric Copilot, and Copilot in Dynamics 365, tailored for specific Microsoft services.

    19 min
  2. 03/24/2025

    Beyond Compliance: Navigating the EU AI Act and the Future of Ethical Artificial Intelligence

    In this episode, we explore one of the most transformative regulatory frameworks in the world of technology: the EU Artificial Intelligence Act. As AI systems rapidly evolve and integrate into every aspect of our lives—from healthcare and education to justice and cybersecurity—the need for robust governance, transparency, and ethical oversight has never been more urgent. Join Néstor Reverón, cloud and AI educator at Microsoft and certified Expert in Law and Artificial Intelligence (University of Barcelona), as he unpacks the key provisions of the EU AI Act, its alignment with the GDPR, and what it means for developers, organizations, and governments. We discuss risk classifications, conformity assessments, transparency requirements, AI ethics, and the emerging challenges of General Purpose AI (GPAI). This episode is a must-listen for professionals at the intersection of law, cloud computing, and emerging technologies. Learn how to build and deploy AI responsibly in a way that respects fundamental rights, promotes innovation, and ensures legal compliance. 🔍 Topics covered: Risk-based classification of AI systems Role of the European AI Office, AESIA, and regulatory sandboxes Data governance, transparency, and accountability AI Liability Directive and cybersecurity obligations Practical steps for building AI compliance programs The role of AI trainers and cloud educators in this new era 🎙️ Let’s move beyond compliance — toward a future where AI is responsible, explainable, and human-centered. #AIRegulation #EUAIAct #EthicalAI #GDPR #AICompliance #ResponsibleInnovation #CloudTraining #ArtificialIntelligence #MicrosoftTrainer #Podcast

    22 min
  3. 01/16/2025

    Secure Communication & Risk Management with Microsoft Purview

    In this episode, we dive deep into the critical world of corporate data security and compliance within the Microsoft 365 environment. Our expert guide, Nestor Reveron, walks us through the essential pillars of safeguarding sensitive information and fostering a secure workplace: •Communication Compliance: Discover how to monitor and manage communication channels like email and Microsoft Teams to ensure they align with regulatory standards and internal policies. Learn to identify risky keywords and patterns, set up alerts for potential violations, and train your team on responsible communication practices. •Insider Risk Management: Uncover the proactive steps to identify and mitigate potential threats from within your organization. Explore tools and strategies for detecting data leaks, unauthorized access, and suspicious activities. Understand how to leverage real-time signals, machine learning, and integrated workflows to protect your most valuable assets. •Information Barriers: Explore the concept of creating secure data silos within your organization. Learn how to set up information barriers to restrict communication between specific departments or groups, preventing conflicts of interest, safeguarding sensitive data, and ensuring compliance with regulations like GDPR. •Microsoft Privacy: Delve into the features and functionalities of Microsoft Privacy, a powerful solution within Microsoft Purview for protecting employee data. Understand how to configure policies to automatically identify and safeguard personal information, empower individuals to manage their data, and maintain compliance with privacy regulations.Join us for this insightful session as we unravel the complexities of corporate security and compliance in the digital age. Learn to implement practical solutions and strategies to fortify your organization's defenses and cultivate a culture of security awareness

    19 min
  4. 01/16/2025

    Microsoft 365 Compliance Management and eDiscovery

    In this episode, explore the intricacies of data retention and compliance within the Microsoft Purview ecosystem. •Retention based on events: Learn how to leverage event-based retention policies, enabling the automatic retention or deletion of data based on specific triggers like project closure or employee departure. •Service-based retention: Delve into the concept of service-based retention, such as mailbox holds, to preserve critical data and prevent loss, particularly in scenarios involving legal matters or sensitive information. •Compliance Manager: Discover the power of Compliance Manager, a centralized and automated solution for evaluating and enhancing your organization's compliance posture. Understand how to create assessments based on industry regulations like the Gramm-Leach-Bliley Act. •Content Search: Explore the capabilities of content search within Microsoft Purview. Learn how to perform targeted searches, refine results using keywords and filters, and export findings for further analysis. Understand the limitations of content search as a recovery tool. •eDiscovery: Discover the advanced features of eDiscovery, particularly in its premium iteration, offering enhanced capabilities for custodian management, advanced integrations for complex data, and sophisticated filtering and analysis tools. •Case Management: Gain insights into managing legal or investigative cases within Microsoft Purview. Learn about creating, closing, and reopening cases, applying legal holds to preserve data, and exporting results for review and analysis.By mastering these concepts, you'll be well-equipped to navigate the complexities of data retention, compliance, and eDiscovery within Microsoft Purview, ensuring your organization remains secure and compliant

    30 min
  5. 01/15/2025

    Data Loss Prevention Deep Dive: Safeguarding Your Sensitive Information with Microsoft Purview

    This podcast episode delves into the crucial topic of data loss prevention (DLP) within the Microsoft Purview ecosystem. DLP policies are essential for organizations to identify, monitor, and protect sensitive information from unauthorized access, use, or disclosure. The episode explores the various components of DLP within Microsoft Purview: •Sensitive Information Types: Learn how to define and customize sensitive information types like credit card numbers, employee IDs, and passport information to tailor protection to specific needs. •Policy Creation and Customization: Explore the process of creating custom DLP policies and rules to define conditions and actions based on the detected sensitive information. The podcast explains how to configure policies to block sharing of credit card numbers in emails and Teams chats, notify users attempting to share sensitive data, and even quarantine files containing specific information. •Endpoint DLP: Discover the capabilities of endpoint DLP to extend protection to Windows and macOS devices. Understand how to configure policies to restrict data transfer via Bluetooth, prevent printing of sensitive documents, and control data sharing with cloud storage services like Dropbox or Google Drive. •Integration with Microsoft Defender for Endpoint: Learn how integrating DLP policies with Microsoft Defender for Endpoint provides comprehensive protection by monitoring and controlling activities related to sensitive data on devices. •File Plan and Retention Labels: Explore the concept of a file plan within record management to structure and document data classification, retention, and deletion policies. The podcast explains how to create and apply retention labels to ensure compliance with industry regulations and legal requirements, using examples like retaining financial records for a specific period. This episode is essential listening for IT professionals, security administrators, and anyone responsible for protecting sensitive data within their organization. By understanding and implementing the robust DLP features offered by Microsoft Purview, you can significantly strengthen your organization's security posture and ensure compliance with data protection regulations.

    18 min

About

Technical Trainer Dedicado a la tecnología. aka.ms/nestor