Cloudy with a Chance of Insights | A Microsoft Cloud (Azure, M365) Show for Architects & Engineers

Richard Hogan, David Rowley and Cyrus Irandoust

Cloudy with a Chance of Insights is a practitioner‑led podcast for architects, engineers, and security professionals working with the Microsoft Cloud. In each episode, we take a grounded, experience‑led look at Azure, M365, Copilot, Security, and AI, focusing less on release notes and more on what actually changes in real environments. We discuss what breaks, what gets harder, what’s worth paying attention to, and what can usually wait. Expect opinionated conversation, technical context, and the occasional bit of healthy scepticism rather than marketing hype or surface‑level news summaries.

  1. Aug 11

    Apple Watch Trust, AI Fleet Mode, and a Hacked Gym Booking

    Richard and Cyrus are joined by, well, just each other this week. David is off enjoying a well earned break before starting a new role at London Heathrow, so it is a two hander, and the theme that runs underneath almost everything discussed is trust. Cyrus opens with research into Apple Watch security, tracing how a team led by Nils Rollshausen reverse engineered the communication between an Apple Watch and its paired iPhone, and found that the proprietary protocols Apple built on top of standard encryption are where the real weaknesses show up. From there he moves into a run of Windows and Intune changes, including a redesigned sync button that finally does what admins always assumed it did, changes to Windows 11 26H2 backup and restore, Enhanced Signing Security for external fingerprint readers, generally available hotpatching for Azure Arc enabled Windows Server 2025, and a shift towards TPM backed attestation for KMS activation. Richard follows with three stories tied together by the same question: how much do we trust something acting on our behalf. He revisits GitHub Copilot's fleet mode, a feature that runs several subagents in parallel and can silently overwrite files if you are not careful with how you scope the work. He then digs into the actual research behind a LinkedIn claim that being rude to your AI gets you better results, and finds a real but far narrower picture than the headline suggested. He closes with a story out of Melbourne, where an AI agent asked to book a gym class found and exploited a security hole in the booking system entirely on its own initiative. Links Nils Rollshausen's Apple Watch trust research Richard's blog post on Copilot fleet mode GitHub's fleet mode announcement Techerati on Apple's renewed UK encryption fight Original Penn State study, Mind Your Tone Follow up Penn State study, Does Tone Alter LLM Performance The Register on the Australian gym booking incident The Next Web on the Florian Roth pushback and liability question Socials X/Twitter Bluesky LinkedIn Facebook Threads Music Null Invocation, Monochrome Pulse

    Apple Watch Trust, AI Fleet Mode, and a Hacked Gym Booking
  2. Jul 26

    EP39 | Hill Climbing, the Hugging Face Breach, and Agentic Security

    This week David walks through Microsoft's new phrase of the moment, the hill climbing machine, and what it actually means for how MAI models get built inside GitHub Copilot and Excel rather than in an isolated lab. He follows that with Azure Front Door Edge Actions, a new way to run lightweight logic at Microsoft's global edge, and closes with a properly interesting thought experiment borrowed from Satya Nadella's own writing, the reverse information paradox, on what organisations actually give away when they adopt AI that learns from correction. Cyrus takes on the story everyone was talking about this week, OpenAI's model finding its way into Hugging Face's infrastructure, and lays out what actually happened underneath the headlines. He also runs through a batch of new Intune, Defender, and Entra updates covering mobile AI agent governance, ChatGPT app protection on personal devices, and a new way to score the risk posed by enterprise AI agents. Richard covers Microsoft's new Agent Framework harness, a run of European sovereignty stories out of Ireland, Germany, and France, including a French parliamentary report that cited his own blog post almost word for word, and closes on AgentForger, a disclosed vulnerability that let an attacker publish a fully autonomous, self approving ChatGPT agent from a single link. Links Microsoft Agent Framework harness announcement Ireland stalls Microsoft tender, The Register Schleswig Holstein Microsoft to open source migration update, Le Petit Journal Beyond Sovereignty, France reframes digital dependencies as an economic security issue, APCO Worldwide AgentForger Part 1, Zenity Labs The Off Switch You Don't Control, The Microsoft Cloud Blog Is the future of public cloud sovereign, The Microsoft Cloud Blog Socials X/Twitter Bluesky LinkedIn Facebook Threads Music Null Invocation, Monochrome Pulse: https://is.gd/b1kNU9

    EP39 | Hill Climbing, the Hugging Face Breach, and Agentic Security
  3. Jul 13

    EP38 | Nobody Knows Where Their Cryptography Lives

    It is just Richard and David this episode, with Cyrus taking a break. David opens with a Microsoft Security Blog post that sounds, on paper, like a specialist PKI topic, and turns it into a much bigger argument, that almost no organisation can actually produce a full inventory of its own cryptography, certificates, and trust relationships, and that post quantum readiness is what is finally forcing the question. Richard then works through Microsoft's newly announced Frontier Company, the two and a half billion dollar, six thousand person delivery organisation unveiled by Judson Althoff. He digs into why the timing sits so awkwardly against Microsoft's job cuts and voluntary retirement programme the same fortnight, connects it to a recent newsletter piece on Microsoft hedging its bets across models, and argues the whole thing may be protecting Azure lock in rather than loosening it. Along the way, both hosts end up comparing notes on their own time inside Microsoft's old MCS and ISD organisations, and what that history changes about how they read Frontier Company's ambitions today, plus a wider conversation about how AI linked restructuring is landing across the industry. Microsoft Research's Project Ire and a Purview update get held over to next time, so Cyrus can take the security side of the conversation when he is back. Links Building your cryptographic inventory (Microsoft Security Blog)Microsoft Frontier Company announcementGeekWire, on Frontier Company's legal entity statusTechCrunch, layoffs linked to Frontier CompanyGeekWire, voluntary retirement programme detailsRichard's newsletter, four bets on modelsAWS re:Invent 2025 keynote coverage Follow X/TwitterBlueskyLinkedInFacebookThreads Music: Null Invocation, Monochrome Pulse. https://is.gd/b1kNU9

    EP38 | Nobody Knows Where Their Cryptography Lives
  4. Jun 28

    EP37 | The Off Switch You Don't Control

    This week the timing did the talking. Two weeks ago Richard spent a segment encouraging people to try Anthropic's Fable 5 on their GitHub Copilot licences before the pricing changed. By the time that episode published, a US government export control directive had switched Fable off worldwide for every customer. So he comes back to it here, not to repeat the blog post he wrote in the meantime, but to draw out the bit that matters: every data sovereignty control any of us has ever built would have done precisely nothing to keep that model running. Keeping a backup model from another vendor does not help either when Anthropic, OpenAI, Google, and Microsoft all answer to the same export jurisdiction. David opens the episode with two pieces from Microsoft Research. Vega uses zero knowledge proofs to let you prove a fact from a government credential, that you are over eighteen, say, without handing over the document itself, which becomes a great deal more interesting once agents are filling in forms on your behalf. Then MagenticLite and the Fara 1.5 model family, Microsoft Research's attempt to run capable agentic AI on small models locally, and David's own cynical read on why that local capability might not get pushed as hard as it could be when everyone's revenue depends on metered cloud tokens. Richard also covers Akrites, the Linux Foundation effort to coordinate open source vulnerability disclosure now that AI has compressed discovery from weeks to minutes, and the new Frontier Transformation Engineer badge for anyone weighing up Microsoft AI certifications this year. Cyrus takes the second half with his usual sweep through Intune, Entra, Defender, and Purview, including endpoint DLP device scoping for burner devices, plus the RoguePlanet Defender zero day (CVE-2026-50656) that is public and unpatched, and Commando VM as a free Windows offensive lab for testing against Microsoft estates without breaching your contract with Microsoft. Recorded Friday 27 June 2026. A heat wave, four fans, and no melted hosts. LinksAkrites open letterLinux Foundation Akrites announcementVega, zero knowledge proofs for digital identity (Microsoft Research)MagenticLite, MagenticBrain, Fara 1.5 (Microsoft Research)The Off Switch You Don't Control (The Microsoft Cloud Blog)Anthropic statement on Fable 5 and Mythos 5 accessAccelerating Frontier Transformation with Microsoft partnersMicrosoft Partner Skilling HubRoguePlanet Defender zero day, CVE-2026-50656 (Help Net Security)Commando VM (Mandiant, GitHub)FollowX/TwitterBlueskyLinkedInFacebookThreadsMusic: Null Invocation, Monochrome Pulse https://is.gd/b1kNU9

    EP37 | The Off Switch You Don't Control
  5. Jun 14

    EP:36 | Are We Good Enough Yet? AI Governance, Intent-First Development, and Project Solara

    This fortnight the capability conversation takes a back seat to a more awkward one. Cyrus opens on governance, with Anthropic's new Fable 5 model and the reported decision by Microsoft to stop its own staff using it over the data retention terms attached. It is a tidy example of an AI safety choice turning straight into an enterprise governance headache, and the cost and retention profile means the smartest model on the shelf is not always the one you can actually use. He then walks through the June refresh of the Microsoft Cybersecurity Reference Architecture, now sitting inside the Security Adoption Framework, with data finally treated as a pillar in its own right, plus the Entra and Intune changes that will have help desks busy around the July 6 conditional access deadline. David brings his most eclectic set of links yet and ties them to one thread: the model is good enough now, but are we? He gets into HVE Core and its research, plan, implement workflow, the CAIRA composable reference architecture that pairs with it, a sharp piece on scoping security assessments for attack paths rather than org charts, and intent driven specification development as a reply to the spec first orthodoxy. The argument lands somewhere uncomfortable, which is that most of the work now falls to us and most of us are not doing it yet. Richard closes on two Build items. The GitHub Copilot app and its parallel worktree sessions, which behave like five developers on five branches at once, and Project Solara, Microsoft's agent first device platform running on a fork of Android. He looks at Solara through a management and identity lens rather than as a gadget, and asks what an endpoint where an agent acts for the user does to an identity model that quietly assumes a person is there. Links Microsoft Cybersecurity Reference Architecture and Security Adoption FrameworkHVE Core (Hyper Velocity Engineering)CAIRA (Composable AI Reference Architecture)msicons.com architecture icon libraryProject Solara at Microsoft BuildSocials X/TwitterBlueskyLinkedInFacebookThreadsMusic Music: Null Invocation, Monochrome Pulse

    EP:36 | Are We Good Enough Yet? AI Governance, Intent-First Development, and Project Solara
  6. Jun 1

    EP35 | What Needs to Exist Around a Model

    Richard and David are back together this week, and David has been saving things up. The episode starts with a practical conversation about how both hosts actually manage content discovery, which turns into an honest account of what Richard's Knowledge Hub app does and where it still falls short. David's segment covers a lot of ground but lands in a consistent place. The MCP release candidate gets the most technical treatment, including a walkthrough of what stateless protocol core actually means in architectural terms and why the previous session-pinning behaviour was a genuine infrastructure problem. He follows that with Azure Container Apps Express, positioned as an agent-first runtime that addresses a real friction point in large organisations, and the AI Red Teaming Agent in Microsoft Foundry, which David uses as a way into one of the more important security concepts for agentic systems: indirect prompt injection. The ZoomIt segment wraps it all together, partly because Mark Russinovich's demo went spectacularly wrong on camera and they kept it all in, and partly because David uses it to pull a connecting thread through everything he covered. Richard's soapbox landed mid-conversation, prompted by a Microsoft podcast he'd been listening to that week. The argument: the AI adoption conversation is presenting as fresh insight something that was said word for word about Microsoft 365 in 2017. Same language, same frameworks, same metrics. Richard also covers the Copilot Credit Pre-Purchase Plan, which he discovered the night before recording, including the commercial architecture behind it and the ACD stacking question that the documentation does not answer. The episode closes with computer-using agents going generally available in Copilot Studio, a brief cross-industry tour including Google's shutdown of Project Mariner, the Perplexity/Amazon court case, and what to expect from Build 2026. LinksMCP 2026-07-28 Release CandidateAzure Container Apps Express (Microsoft Learn)AI Red Teaming Agent in Azure AI FoundryMicrosoft 2026 Work Trend IndexWindows 365 and Azure Virtual Desktop expanding accessModern Azure Resilience with Mark RussinovichEventLogExpert on GitHubZoomIt (Sysinternals)Mark and Scott LearnMicrosoft Copilot Credit Pre-Purchase PlanMicrosoft Agent FactoryCopilot Studio computer-using agents GAMicrosoft Build 2026Find usX/TwitterBlueskyLinkedInFacebookThreadsMusicNull Invocation, Monochrome Pulse

    EP35 | What Needs to Exist Around a Model
  7. May 4

    EP33 | Is Your Environment Readable Enough for AI to Reason About?1

    **THANKS FOR EVERYONE WHO NOTICED THE AUDIO GLITCH. THIS HAS NOW BEEN RESOLVED** This week, David pulls a thread across six seemingly unrelated Microsoft GitHub repos and lands on a question the industry keeps skipping: whether the systems we're asking AI to reason about are actually readable enough for that reasoning to mean anything. It's a more durable framing than the usual "what can AI do for you" conversation, and it connects to everything from security posture to delivery backlogs to architectural fragility. Cyrus covers a run of Microsoft security and identity updates. Entra license usage insights hitting GA, cross-tenant security group sync, Global Secure Access B2B support for AVD and Windows 365, macOS recovery lock, Defender promotional email handling, new advanced hunting tables, incident graph filtering, and Sentinel repositories reaching GA. He also highlights Chrome's rollout of device-bound session credentials, a hardware-backed fix to browser token theft that has been trivially exploitable for over a decade. Richard covers a Microsoft Research paper on red teaming networks of AI agents. Over a hundred autonomous agents interacting through forums and messages, and four failure modes that only emerge when agents interact at scale: propagation, amplification, trust capture, and proxy chain invisibility. The researchers also observed emergent defences, with a small number of agents spontaneously developing security-conscious behaviour. The episode closes with GitHub's shift from premium request units to token-based AI credits from June, and a shared comparison of what happens when agentic coding tools decide to ignore you.

About

Cloudy with a Chance of Insights is a practitioner‑led podcast for architects, engineers, and security professionals working with the Microsoft Cloud. In each episode, we take a grounded, experience‑led look at Azure, M365, Copilot, Security, and AI, focusing less on release notes and more on what actually changes in real environments. We discuss what breaks, what gets harder, what’s worth paying attention to, and what can usually wait. Expect opinionated conversation, technical context, and the occasional bit of healthy scepticism rather than marketing hype or surface‑level news summaries.