The Security Insights Show

Rod Trent

Hosted by Edward Walton, Frank Grimberg and Rod Trent, THE "AI" Security Insights Show provides information, news, tips on security solutions to help protect AI, agents, SIEM solutions and XDR. www.microsoftsecurityinsights.com

  1. 2D AGO

    The "AI" Security Insights Show Episode 286 - Chris Stelzer Returns! Sentinel + XDR + MCP = SoC Automation Goodness!

    Edward gets someone else to do his homework. Rod returns...or does he? Franks can’t decide if he wants to live in Florida or Virginia. We will also do a run down about all the security and AI. Words of Wisdom: Speak confidently as if you are right, but listen carefully as if you are wrong. Cool Tools and Links: * XDR Convertor TOP AI and Security Links to take a look-see: * All the admin portal and API endpoints: 🖥 Home | [cmd.ms] * Microsoft Community Hub - Monthly news - February 2026 | Microsoft Community Hub Weekly Microsoft 365 Announced Changes: * Microsoft Teams: Multiple phone number assignment to a single userID: 557716 | Product: Microsoft Teams | Status: In developmentAdministrators will be able to assign multiple phone numbers (up to 10) to a single user. Users will be able to make and receive phone calls using any... Microsoft Teams: Flexible layout for meetings with resizable dividerID: MC1239934 | Service: Microsoft Teams | Tags: New feature, User impact, Admin impactMicrosoft Teams will introduce a resizable divider in meetings (April 2026) allowing users to adjust and swap the space between shared content and vid... Collaborate with Copilot in Outlook while drafting emailID: MC1239932 | Service: Microsoft Copilot (Microsoft 365) | Tags: New feature, User impact, Admin impactMicrosoft 365 Copilot will be integrated into Outlook’s compose window starting March 2026, enabling real-time collaboration for email drafting. Avail... Defender for Office 365 URL click alerts now include Microsoft TeamsID: MC1239187 | Service: Microsoft Defender XDR | Tags: New feature, User impact, Admin impactMicrosoft Defender for Office 365 URL click alerts will now include Microsoft Teams, enabling detection of malicious link clicks in Teams messages. Th... Microsoft 365 Copilot: Turn Copilot Pages into SharePoint News postsID: MC1239186 | Service: Microsoft 365 apps, Microsoft Copilot (Microsoft 365) | Tags: New feature, User impactMicrosoft 365 Copilot will enable users to transfer content from Copilot Pages directly into SharePoint News posts for seamless editing and publishing... Microsoft Purview | Data Lifecycle Management - Separate Retention policies for Copilots and AI AppsID: MC1238434 | Service: Microsoft Purview | Tags: New feature, User impact, Admin impactAdmins can now set separate retention policies for Copilot and AI app interactions in Microsoft Purview, allowing faster deletion if needed. This feat... Updates to filtered message viewing in Outlook for iOS and AndroidID: MC1238433 | Service: Microsoft 365 apps | Tags: Feature update, User impact, Admin impactOutlook for iOS and Android will add an option to search all filtered messages when more exist beyond locally synced items, improving clarity without ... Windows first sign-in restore experience now availableID: MC1238409 | Service: Windows | Tags: Admin impact New Roadmap Items Microsoft Purview: Data Loss Prevention- Security Store now available within Purview DLP to browse, purchase, and enable partner integrationsID: 557977 | Product: Microsoft Purview | Status: In developmentSecurity Store is now integrated into the Microsoft Purview DLP experience, giving admins an in-product way to discover, purchase, and enable a curate... Microsoft Purview: Data Loss Prevention- New policy configuration options available for inline network and Edge for Business policiesID: 557976 | Product: Microsoft Purview | Status: In developmentAdmins can now scope Purview collection policies for unmanaged cloud apps based on the presence of sensitivity labels, enabling more precise discovery... Microsoft Copilot (Microsoft 365): Share agents to TeamsID: 557947 | Product: Microsoft Copilot (Microsoft 365) | Status: In developmentWith this feature, users will be able to share their agent with a Microsoft Teams team. Users can search for and find teams in the agent sharing dialo... Microsoft Teams: Multiple phone number assignment to a single userID: 557716 | Product: Microsoft Teams | Status: In developmentAdministrators will be able to assign multiple phone numbers (up to 10) to a single user. Users will be able to make and receive phone calls using any... Microsoft Copilot (Microsoft 365): Create Videos in the Clipchamp Start PageID: 553215 | Product: Microsoft Clipchamp, Microsoft Copilot (Microsoft 365) | Status: In developmentUsers can use Copilot to create videos directly from the Clipchamp Start page. Turn a simple prompt or existing document into a polished video in minutes Updated Roadmap Items Microsoft Teams: New SlimCore-based optimization for Microsoft Teams in VDI - support for Windows endpoints on Omnissa environmentsID: 518286 | Product: Microsoft Teams | Status: Rolling outThis feature allows Windows endpoints to optimize Microsoft Teams in VDI environments with the new SlimCore-based media engine, providing an expanded ... Outlook: New search folder typesID: 549286 | Product: Outlook | Status: LaunchedSearch Folders are being moved to the Settings experience in the new Outlook for Web and Windows, improving discoverability and alignment with modern ... Microsoft Teams: External Domains Anomalies ReportID: 536572 | Product: Microsoft Teams | Status: In developmentThis new report helps admins proactively spot unusual or risky interactions with external organizations. By analyzing communication trends and detecti... Outlook: New search folder typesID: 549287 | Product: Outlook | Status: LaunchedSearch folders are being moved to the Settings experience in the new Outlook for Windows and web, improving discoverability and alignment with modern ... Microsoft Defender for Office 365: Admins can hunt on calls in Microsoft TeamsID: 531761 | Product: Microsoft Defender for Office 365 | Status: In developmentSecurity admins with Defender for Office 365 Plan 2 can hunt on calls and meetings made inside Microsoft Teams for their organization New Message Center Items Retiring the Impala connectorID: MC1240748 | Service: Microsoft Power Automate in Microsoft 365 | Tags: User impact, Admin impact, RetirementThe Impala connector will be retired and removed from Copilot Studio, Logic Apps, Power Apps, and Power Automate between April 1-14, 2026. Existing co... SharePoint page template gallery improvements and new templatesID: MC1240743 | Service: SharePoint Online | Tags: New feature, User impactSharePoint is enhancing its page template gallery with 31 new templates, improved browsing, filtering, search, and unified Pages and News creation. En... Microsoft Viva – Microsoft 365 Copilot adoption (Power BI) report update with power user insightsID: MC1240742 | Service: Microsoft Viva, Microsoft Copilot (Microsoft 365) | Tags: New feature, User impact, Admin impactThe Microsoft 365 Copilot adoption (Power BI) report in Viva Insights will be updated by mid-March 2026 with a streamlined layout and new power user i... Microsoft Viva – Copilot Analytics: “All” licensed user page added to the Copilot DashboardID: MC1240741 | Service: Microsoft Viva, Microsoft Copilot (Microsoft 365) | Tags: New feature, User impact, Admin impactThe Copilot Dashboard will add an “All” view combining licensed Microsoft 365 Copilot and unlicensed Copilot Chat usage, enabled by default with no ad... Copilot entry point changes in Word and handoff to Agent in chatID: MC1240704 | Service: Microsoft 365 apps | Tags: Feature update, User impact, Admin impactCopilot entry points in Word are being unified and moved to a consistent corner, with contextual access via selection floatie (Windows/Web) or right-c... Updated Message Center Items Microsoft Teams | VDI for Azure Virtual Desktops/Windows 365 and Citrix: macOS support with new SlimCore optimizationID: MC1151241 | Service: Microsoft Teams | Tags: Updated message, New feature, User impactMicrosoft Teams now supports macOS with a new SlimCore media engine for Azure Virtual Desktop, Windows 365, and Citrix, improving performance, meeting... (Updated) Microsoft 365 Copilot: Add web links as references in Copilot NotebooksID: MC1193414 | Service: Microsoft Copilot (Microsoft 365) | Tags: Updated message, New feature, User impact, Admin impactMicrosoft 365 Copilot Notebooks will allow users with a Copilot license to add public web links as references, expanding beyond file types like Word a... (Updated) Microsoft Teams: Hiding inactive channelsID: MC804771 | Service: Microsoft Teams | Tags: Updated message, New feature, User impactMicrosoft Teams paused the rollout of automated hiding of inactive channels, now offering opt-in suggestions for users to review and hide inactive cha... (Updated) Microsoft Teams: Private channels increased limits and transition to group complianceID: MC1134737 | Service: Microsoft Teams | Tags: Updated message, New feature, User impact, Admin impactMicrosoft Teams is updating private channels by increasing limits to 1000 channels per team and 5000 members per channel, enabling meeting scheduling,... (Updated) Microsoft Teams: Choose to hide inactive channelsID: MC1141958 | Service: Microsoft Teams | Tags: Updated message, Feature update, User impact, Admin impactMicrosoft Teams paused the rollout of automated hiding of inactive channels, now offering opt-in suggestions instead. Users can review and hide inactivity Microsoft Security News and Events: * Active Directory Hardening Series * Protect the Browser Watch the live show: This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.microsoftsecurityinsights.com

    1h 5m
  2. FEB 23

    The "AI" Security Insights Show Episode 285 - Edward does his homework, lessons learned via MCP. Well sort of...!

    In this episode we discuss why Edward continues to go down AI generated rabbit holes instead completing the homework assignment given to him by Frank We talk about changes in how Sentinel data lake ingest XDR logs, AI rabbit holes and lots of other random security items. Words of Wisdom: The biggest lie we tell ourselves is, “I don’t need to write this down because I will remember it”. Cool Tools and Links: * https://cmd.ms/ - the Microsoft Cloud command line! TOP AI and Security Links to take a look-see: * Open AI ready made prompts: https://academy.openai.com/public/tags/prompt-packs-6849a0f98c613939acef841c * All the admin portal and API endpoints: 🖥 Home | [cmd.ms] * * Microsoft Community Hub - Monthly news - February 2026 | Microsoft Community Hub Weekly Microsoft 365 Announced Changes: * Microsoft Purview: Data Lifecycle Management- Azure PST ImportID: 557559 | Product: Microsoft Purview | Status: In developmentAzure PST Import is a migration method that enables PST files stored in Azure Blob Storage to be imported directly into Exchange Online mailboxes. It ... Microsoft 365 Copilot: xAI Grok 4.1 Fast now available in Copilot Studio for US customers (admin opt-in required)ID: MC1235017 | Service: Microsoft Copilot (Microsoft 365) | Tags: New feature, User impact, Admin impactStarting February 19, 2026, xAI Grok 4.1 Fast, a text-only large language model, will be available in Microsoft Copilot Studio for U.S. customers by a... Simplified Teams app bar to create a cleaner and more focused experienceID: MC1234559 | Service: Microsoft Teams | Tags: New feature, User impactMicrosoft Teams is simplifying the app bar to reduce clutter and improve focus, rolling out from mid-March to early April 2026. The app bar will show ... Microsoft Teams: Enable customers to book appointments from a live chat widget on your websiteID: 557172 | Product: Microsoft Teams | Status: In developmentThe Microsoft Teams live chat widget lets customers engage in one to one conversations with your business directly from your website, and now also ena... Coming soon to organizations: Customize the Start menu with updated policies * Microsoft Copilot (Microsoft 365): Explain slide selection during PowerPoint LiveID: 557256 | Product: PowerPoint, Microsoft Copilot (Microsoft 365) | Status: In developmentThis feature enhances the PowerPoint Live meeting experience by using Copilot to let attendees select slide text and get explanations for the content. Microsoft Viva: Copilot Analytics: Copilot adoption PBI version update including Power user insights.ID: 557674 | Product: Microsoft Viva, Microsoft Copilot (Microsoft 365) | Status: In developmentThe updated Copilot adoption Power BI report will come with a streamlined UX and new Power user insights. Outlook: Share Word, Excel, and PowerPoint local files via the new Outlook for WindowsID: 557675 | Product: Outlook | Status: In developmentWhen working in an open Word, Excel, or PowerPoint file, users will now be able to send a copy of the locally stored file by email through the new Out... OneDrive: Set a custom name for the OneDrive sync folderID: 557562 | Product: OneDrive | Status: In developmentIT admins can now customize the local OneDrive sync root folder name on users’ Windows computers. By default, the folder is named “OneDrive - {organiz... SharePoint: New SharePoint ExperienceID: 547732 | Product: SharePoint | Status: In developmentWe are introducing a reimagined SharePoint experience designed to be simple and intuitive, centered on the core jobs of discovering knowledge, publish... Outlook: Prepare for meetings with Copilot in classic Outlook for WindowsID: 542186 | Product: Outlook | Status: In developmentWith so many of us in back-to-back meetings, it can be a real struggle to stay on top of pre-reads, action items, and even what each meeting is about.... Microsoft Teams: Attend Microsoft webinars from Teams Rooms on AndroidID: 547824 | Product: Microsoft Teams | Status: In developmentYou can join a Microsoft webinar from a Teams Room on Android and interact seamlessly during the event. Available for Teams Rooms Pro. Microsoft Teams: Streamlined Microsoft 365 Certified App Management in Teams Admin CenterID: 485712 | Product: Microsoft Teams | Status: In developmentThis feature allows Microsoft 365 administrators to enable Microsoft 365 certified SaaS applications within their tenant through org-wide settings for... Microsoft Teams: Branded Meeting ReactionsID: 541830 | Product: Microsoft Teams | Status: In developmentWith new branded reactions, organizations can now extend their visual identity directly into meetings. IT admins simply upload custom reaction icons r... Microsoft 365 app: Microsoft Loop - Admin usage reports for LoopID: 421611 | Product: Microsoft 365 app | Status: In developmentView and monitor Loop usage in the tenant through existing M365 admin usage dashboards. Microsoft 365 Copilot: Ground Chat in SharePoint Lists using Context IQID: MC1235746 | Service: Microsoft Copilot (Microsoft 365) | Tags: New feature, User impactMicrosoft 365 Copilot will allow users to search for and insert SharePoint Lists into chat prompts via Context IQ, enhancing response accuracy. This f... Plan for Windows Server 2016 and Windows 10 2016 LTSB end of supportID: MC1235720 | Service: Windows | Tags: Admin impact Microsoft Teams: Upcoming changes to Microsoft Places licensing and feature accessID: MC1235124 | Service: Microsoft Teams, Microsoft 365 for the web | Tags: Feature update, User impact, Admin impactStarting April 1, 2026, Microsoft Places licensing will shift from user-based to space-based, making core features widely available without Teams Prem... OneNote for iOS: Introducing automatic local backupsID: MC1235123 | Service: Microsoft 365 apps | Tags: New feature, User impact, Admin impactOneNote for iOS will automatically create local backups of notebooks stored in the iOS Files app, enabling self-service recovery via PC or Mac. This f... (Updated) Microsoft Teams: Reduced automatic updates in Meet Now channel meeting threadsID: MC1235118 | Service: Microsoft Teams | Tags: Updated message, Feature update, User impactMicrosoft Teams will reduce automatic updates in Meet Now channel meeting conversations, showing only a single “Meeting started” message in the channe... Microsoft Security News and Events: * Defender for AI https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/defender-for-ai-services-threat-protection-and-ai-red-team-workshop/4464771 * https://aka.ms/AgentID/ITPro - Entra Agent ID for IT Pros * https://aka.ms/AgentID/ITPro/CreationChannels - Creation Channels for Entra Agent IDs * https://aka.ms/AgentID/Developers - Entra Agent ID Platform for Developers * https://aka.ms/AgentID/Developers/Concepts - Key Concepts for Entra Agent ID Developers * https://aka.ms/AgentID/GraphAPI - Microsoft Graph API for Entra Agent ID, including the new permissions for Entra Agent ID * https://aka.ms/AgentID/Foundry - Agent ID Integration with Foundry * https://aka.ms/AgentID/CopilotStudio - Agent ID Integration with Copilot Studio * https://aka.ms/AgentID/CAAgent - Agent ID Integration of Conditional Access Optimization Agent * https://aka.ms/AgentID/ARAgent - Agent ID Integration with Access Review Agent * https://aka.ms/AgentID/MCSAgents - Copilot Studio Agents (old Agent IDs – SPs) * https://aka.ms/AgentID/D365Agents - Dynamics 365 Agents overview – the main source of Agent IDs in our customers’ tenant * https://aka.ms/AgentID/BRK243 - Ignite on-demand BRK243 (Microsoft Entra: What’s New in Secure Access on the AI Frontier) * https://aka.ms/AgentID/BRK265- Ignite on-demand BRK265 (Secure access for AI agents with Microsoft Entra) Enjoyed this recent blog post from Microsoft Threat Intel team detailing a threat actors TTPs to compromise cloud-based data storage. What I found interesting is their on-prems to cloud lateral movements. Across multiple domains and across multiple Entra ID tenants within a single customer. A lot of you deal with this due to your business conducting multiple M&As over many years. Just goes to show the basics matter, hygiene matters, full visibility which mean full coverage matters. (off soap box) Also, had a fun time watching a YouTube video of AzureHound being used to help easily identify relationships and permissions in an Azure environment. For example, to locate a user who had elevated privileges on a non-human identity (Service Principle) which had assigned global admin 🙄😐😑. This was one of the tools the threat actors used for recon. Hope everyone has a great weekend and enjoys the read! Click Here for Blog Watch the live replay: This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.microsoftsecurityinsights.com

    1h 5m
  3. FEB 7

    The "AI" Security Insights Show Episode 284 - Microsoft Sentinel Pricing....it's like MAAGIC!

    In this episode we have the good folks from the security company - LockBase Cyber. Leonard Volling and Charlie Smith will come on and talk about their new Microsoft Sentinel pricing tool. Also Ed talks about how this work travel kept him from doing his homework and messed up the last show, Frank is still trying to decide if he would rather teach security or AI and Rod has finished his No Pop-Tarts January. Oh, we also talked about AI security, Sentinel data lake, AI chips from Google and how we will pivot the show in 2026 to have a deep focus on all things that help secure AI, blah, blah, blah. Words of Wisdom: The biggest lie we tell ourselves is, “I don’t need to write this down because I will remember it”. Cool Tools and Links: * https://cmd.ms/ - the Microsoft Cloud command line! TOP AI and Security Links to take a look-see: * Link to New Microsoft Security and AI Architect Certification - Survey | Qualtrics Survey Software * LockBase Cyber: - Sentinel Log Planner by LockBase - Plan Your Microsoft Sentinel Data Strategy * Open AI ready made prompts: https://academy.openai.com/public/tags/prompt-packs-6849a0f98c613939acef841c * All the admin portal and API endpoints: 🖥 Home | [cmd.ms] * Sentinel and XDR portal: UPDATE: New timeline for transitioning Sentinel experience to Defender portal | Microsoft Community Hub * Microsoft Community Hub - Monthly news - February 2026 | Microsoft Community Hub Weekly Microsoft 365 Announced Changes: * (Updated) Upcoming Conditional Access change: Improved enforcement for policies with resource exclusionsID: MC1223829 | Service: Microsoft Entra | Tags: Updated message, Feature update, User impact, Admin impactStarting March 27, 2026, Conditional Access policies targeting All resources will be enforced even if they have resource exclusions, affecting sign-in... * Microsoft 365 Copilot: User-day export for Copilot dashboard metrics in public previewID: MC1222978 | Service: Microsoft Copilot (Microsoft 365) | Tags: Feature update, User impact, Admin impactMicrosoft 365 Copilot dashboard adds a public preview of a new user-day export option, allowing company-level users to download de-identified daily us... * Microsoft Defender for Android: End of support for Android 10 devicesID: MC1222977 | Service: Microsoft Defender XDR | Tags: User impact, Admin impact, RetirementMicrosoft Defender for Android will end support for Android 10 devices on March 31, 2026. After this date, these devices will no longer receive update... Microsoft General: * Latest progress update on Microsoft’s Secure Future Initiative | Microsoft Security Blog * ​​Whisper Leak: A novel side-channel attack on remote language models | Microsoft Security Blog * New IDC research highlights a major cloud security shift | Microsoft Security Blog AI Security: * Public Preview: Entra ID support for RDP connections in portal * DNS flow trace logs in Azure Firewall are now generally available * General Availability of JavaScript Challenge in Azure Front Door WAF * Using Packet Capture for troubleshooting Azure Firewall flows * Public Preview: Custom WAF Block Status & Body for Azure Application Gateway Azure Security & Defender for Cloud News: * Microsoft Defender for Cloud Innovations at Ignite 2025 * Announcing Microsoft cloud security benchmark v2 (public preview) * Fast-Start Checklist for Microsoft Defender CSPM: From Enablement to Best Practices * Unlocking Business Value: Microsoft’s Dual Approach to AI for Security and Security for AI * Check This Out! (CTO!) Guide (October 2025) * Update Coverage Workbook in Microsoft Defender for Cloud to Include Defender for AI Plan status Purview - Compliance & Governance: * Consolidate & Conquer: Driving Business Transformation with Integrated Security (Part 1 of 2) | Microsoft Community Hub Microsoft Entra: * Microsoft named a Leader in the Gartner® Magic Quadrant™ for Access Management for the ninth consecutive year | Microsoft Security Blog ICYMI: Watch replays of Microsoft Entra sessions at Microsoft Ignite 2025 | Microsoft Community Hub Copilot for Security: * Agents built into your workflow: Get Security Copilot with Microsoft 365 E5 | Microsoft Security Blog Sentinel: * The Microsoft Copilot Data Connector for Microsoft Sentinel is Now in Public Preview | Microsoft Community Hub * Turn Complexity into Clarity: Introducing the New UEBA Behaviors Layer in Microsoft Sentinel | Microsoft Community Hub * Strategies for Threat Awareness and Response - Not product focused. Threat Actor focused and actional-able guidance. * Sentinel & Defender XDR Ninja Training - Product focused. What’s new, deep dives, best practices ...etc. Defender XDR: * Monthly news - November 2025 * Strengthening calendar security through enhanced remediation * Microsoft Ignite 2025: Transforming Phishing Response with Agentic Innovation * Microsoft Defender for Office 365: Fine-Tuning * You may be right after all! Disputing Submission Responses in Microsoft Defender for Office 365 * Ensure your ICES solution works seamlessly alongside Microsoft Defender * Using the Microsoft Defender for Endpoint Files API to Validate Malware Hashes | Microsoft Community Hub * MDE for Non‑Persistent VDI — Implementation Guide & Best Practices. Watch the live replay This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.microsoftsecurityinsights.com

    1h 13m
  4. JAN 9

    The "AI" Security Insights Show Episode 283 - AI Revolution in Cybersecurity

    In this episode, Ed talks about this travel adventures, Frank confesses that he is addicted to life on a cruise ship and Rod was out because of Pop Tart overdose. Oh, we also talked about AI security, Sentinel datalake, AI chips from Google and how we will pivot the show in 2026 to have a deep focus on all things that help secure AI, blah, blah, blah. Words of Wisdom: The best way to get a correct answer on the internet is to post an obviously wrong answer and wait for someone to correct you. Show Links: Learning: Secure your data for AI with Microsoft Purview Tuesday, January 27, 2026, 1:00 – 2:00 PM ET (GMT-05:00) Register now Strengthen Your Security Posture with Advanced Identity Solutions Wednesday, January 28, 2026, 2:00 – 3:00 PM ET (GMT-05:00) Register now Dive into a simulation of Microsoft 365 Defender and Microsoft Sentinel Wednesday, February 04, 2026, 11:00 AM – 6:00 PM (GMT-05:00) Register now General: * Microsoft Ignite: ​​Ambient and autonomous security for the agentic era​​ | Microsoft Security Blog * SesameOp: Novel backdoor uses OpenAI Assistants API for command and control | Microsoft Security Blog * How to build forward-thinking cybersecurity teams for tomorrow | Microsoft Security Blog AI Security: * ​​Learn what generative AI can do for your security operations center | Microsoft Security Blog * Microsoft Entra: What’s New in Secure Access on the AI Frontier * Riding the AI Wave: How Microsoft Entra is Evolving for the Agentic Era * Defender for AI services: Threat Protection and AI red team workshop Azure Security & Defender for Cloud News: * Microsoft Defender for Cloud Innovations at Ignite 2025 * Announcing Microsoft cloud security benchmark v2 (public preview) * Fast-Start Checklist for Microsoft Defender CSPM: From Enablement to Best Practices * Unlocking Business Value: Microsoft’s Dual Approach to AI for Security and Security for AI * Unlocking Business Value: Microsoft’s Dual Approach to AI for Security and Security for AI Fast-Start Checklist for Microsoft Defender CSPM: From Enablement to Best Practices Announcing Microsoft cloud security benchmark v2 (public preview) Microsoft Defender for Cloud Innovations at Ignite 2025 Defender for AI services: Threat protection and AI red team workshop Purview - Compliance & Governance: * Consolidate & Conquer: Driving Business Transformation with Integrated Security (Part 1 of 2) | Microsoft Community Hub Device Management & Protection (Intune): * What’s new in Microsoft Intune at Ignite Microsoft Entra: * Enhance protection of Microsoft Entra ID authentication by blocking external script injection * Building defense in depth: Simplifying identity security with new partner integrations * Driving cloud-first identity: User SOA is now Public Preview and Group SOA is Generally Available * Platform SSO for macOS Threat Intelligence: * What’s New at Ignite: Powerful Enhancements in Unified Threat Intelligence Copilot for Security: * Agents built into your workflow: Get Security Copilot with Microsoft 365 E5 | Microsoft Security Blog Defender XDR & Sentinel: * Ignite 2025: What’s new in Microsoft Defender? * New Compliance Solutions in Microsoft Sentinel: HIPAA & GDPR Reports | Microsoft Community Hub * Ignite 2025: New Microsoft Sentinel Connectors Announcement * Detect more, spend less: the future of threat intelligence correlation * Operationalizing the Sentinel data lake: A Practitioner’s Guide * Automating IOC hunts in Microsoft Sentinel data lake * What’s New in Microsoft Sentinel: November 2025 * Security Copilot for SOC: bringing agentic AI to every defender * Enhancing visibility into your identity fabric with Microsoft Defender * Detect more, spend less: the future of threat intelligence correlation Watch the live replay This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.microsoftsecurityinsights.com

    1h 2m
  5. 11/25/2025

    THE Security Insights Show Episode 280: Turkey-Day Trojans

    As the Thanksgiving turkey roasts and the family gathers, cybercriminals are lurking in the digital shadows, ready to crash your holiday feast. In Episode 280 of THE Security Insights Show, hosts serve up a timely platter of cybersecurity wisdom to keep your “gravy secrets”—those juicy credentials, financial data, and personal info—safe from opportunistic hackers.Dive into the rising tide of “Turkey-Day Trojans”: sneaky malware disguised as festive deals, phishing emails from “Aunt Edna” demanding urgent wire transfers, and smart home devices turned into spy cams by unsecured Wi-Fi. We’ll unpack real-world holiday hacks, from ransomware gobbling up your shopping carts to social engineering tricks exploiting family chit-chat. Plus, get actionable Microsoft Security tips—like leveraging Defender for endpoint protection, Entra ID for secure guest access during virtual toasts, and Copilot-powered threat hunting to spot the bad stuffing before it sours the meal.Whether you’re a CISO stress-testing your perimeter or just a home user dodging Black Friday bait, this episode arms you with the tools to feast worry-free. Tune in now on YouTube, Apple Podcasts, Spotify, or your favorite platform—because nothing ruins a holiday like a data breach on dessert. Don’t forget to subscribe for more bites of security insight! This episode of “THE Security Insights Show” covers a range of topics, starting with personal updates and discussions about cybersecurity certifications. The hosts delve into the role of Artificial Intelligence (AI) in cybersecurity, specifically debating the necessity of learning KQL (Kusto Query Language) from scratch given the advent of natural language to KQL models (16:01). They discuss the importance of understanding underlying data and language nuances even with AI assistance (18:56). The conversation then pivots to key announcements from Microsoft Ignite, including: * Work IQ: An intelligent layer that enhances productivity by connecting organizational and personal data, enabling AI-driven insights and recommendations within Microsoft 365 applications (31:31). * Proactive Attack Disruption and Predictive Shielding: Microsoft’s new capabilities to anticipate attacker moves during ongoing attacks, dynamically hardening targets in real-time (35:59). * Expanded Automatic Attack Disruption: This feature extends to work across third-party services like AWS, Okta, and Proofpoint, allowing Microsoft Defender to take decisive actions on external systems even if the threat originates from a non-Microsoft system (39:06). * Rebranding of Defender XDR to Borg XDR: Indicating a consolidation of more Defender for Cloud functionality and assimilation of Sentinel into the unified Defender portal (42:00). * Native Sysmon in Windows 11: A significant announcement for security professionals (42:35). This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.microsoftsecurityinsights.com

    1h 4m
  6. 11/07/2025

    THE Security Insights Show Episode 279: Security Copilot Updates

    In this electrifying episode, we sit down with James Key, Principal Product Manager for Microsoft Security Copilot, to unpack the groundbreaking advancements shaping the future of AI-driven security. With over nine years of expertise in cloud architecture, technical training, and product innovation, James is at the forefront of empowering security teams worldwide through intelligent, partner-led solutions.As cyber threats evolve at breakneck speed, Microsoft Security Copilot is supercharging defenses with its latest fall updates. James breaks down the integration with the new Sentinel data lake and graph, enabling seamless data querying and real-time threat hunting like never before. We’ll explore the debut of ready-made and custom agents that automate complex workflows, from incident response to vulnerability management, freeing up pros to focus on strategy.But it’s not just tech—James shares how the newly launched Microsoft Security Store is uniting partners in a bold ecosystem for innovation, fostering collaborative AI tools tailored to enterprise needs. Links/Notes * Microsoft Security Store: https://securitystore.microsoft.com/agents * Agent YAML Builder: https://github.com/rod-trent/JunkDrawer/tree/main/AgentBuilder * Microsoft Ignite Security Copilot sessions: https://ignite.microsoft.com/en-US/sessions?filter=&search=Security+Copilot&sortBy=relevance * glueckkanja AG: https://www.linkedin.com/company/glueckkanja/ * adaQuest: https://www.linkedin.com/company/adaquest-inc/ This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.microsoftsecurityinsights.com

    1h 10m

Ratings & Reviews

5
out of 5
2 Ratings

About

Hosted by Edward Walton, Frank Grimberg and Rod Trent, THE "AI" Security Insights Show provides information, news, tips on security solutions to help protect AI, agents, SIEM solutions and XDR. www.microsoftsecurityinsights.com

You Might Also Like