M365.FM - Modern work, security, and productivity with Microsoft 365

Mirko Peters - Founder of m365.fm, m365.show and m365con.net

Welcome to the M365.FM — your essential podcast for everything Microsoft 365, Azure, and beyond. Join us as we explore the latest developments across Power BI, Power Platform, Microsoft Teams, Viva, Fabric, Purview, Security, and the entire Microsoft ecosystem. Each episode delivers expert insights, real-world use cases, best practices, and interviews with industry leaders to help you stay ahead in the fast-moving world of cloud, collaboration, and data innovation. Whether you're an IT professional, business leader, developer, or data enthusiast, the M365.FM brings the knowledge, trends, and strategies you need to thrive in the modern digital workplace. Tune in, level up, and make the most of everything Microsoft has to offer. M365.FM is part of the M365-Show Network. Become a supporter of this podcast: https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support.

  1. 13 小時前

    Microsoft Purview Audit - Simply Explained

    Every day, employees open files, share documents, send emails, modify Microsoft Teams settings, update compliance policies, and perform countless actions across Microsoft 365. When a security incident, compliance investigation, or legal request occurs, organizations need clear answers about what happened, who performed the action, and when it took place. In this Microsoft Knowledge Nuggets episode, Mirko Peters explains Microsoft Purview Audit in plain English, showing how the Unified Audit Log helps organizations investigate user activity, administrative changes, and compliance events across Microsoft 365. Whether you're an IT administrator, compliance officer, security analyst, Microsoft consultant, or governance specialist, this episode provides a practical understanding of one of Microsoft's most important compliance services. UNDERSTANDING THE MICROSOFT PURVIEW UNIFIED AUDIT LOG Microsoft Purview Audit collects activity records from Microsoft 365 services into a centralized, searchable audit platform. Instead of searching separate logs across Exchange Online, SharePoint Online, OneDrive, Microsoft Teams, Microsoft Entra ID, and Microsoft Purview, investigators can analyze user actions from a single interface. Audit records capture events such as file access, document sharing, mailbox activity, sign-ins, administrative changes, sensitivity label modifications, retention policy updates, and Data Loss Prevention (DLP) policy changes. Rather than storing the actual contents of documents or emails, the Unified Audit Log records the activities surrounding those items, creating a reliable timeline for investigations and compliance reporting. BUILDING INCIDENT TIMELINES ACROSS MICROSOFT 365 One of the greatest strengths of Microsoft Purview Audit is its ability to reconstruct events across multiple Microsoft services. Security teams can trace how files were accessed, determine when content was shared externally, investigate mailbox rule modifications, review administrator activity, and correlate user actions with identity events recorded by Microsoft Entra ID. By filtering searches based on users, workloads, dates, activities, locations, and affected objects, investigators can quickly narrow large volumes of audit data into meaningful timelines. This centralized visibility dramatically reduces investigation time while improving incident response, internal reviews, and regulatory reporting. HOW PURVIEW AUDIT FITS WITH OTHER MICROSOFT PURVIEW SOLUTIONS Microsoft Purview Audit forms the investigative foundation for many other Microsoft Purview capabilities. While Audit records what happened, Content Search locates the associated emails, documents, and files. Microsoft Purview eDiscovery preserves, reviews, and exports that content for legal and regulatory investigations. Compliance Manager measures organizational compliance against industry standards, while Insider Risk Management analyzes behavioral patterns that may indicate risky activity. Communication Compliance focuses on reviewing communications that violate organizational policies. Together, these solutions create a complete Microsoft Purview compliance ecosystem where audit records provide the factual timeline that supports broader governance, legal, HR, and cybersecurity investigations. AUDIT STANDARD VS AUDIT PREMIUM Organizations can choose between Microsoft Purview Audit Standard and Audit Premium depending on their investigation and retention requirements. Audit Standard provides the core Unified Audit Log with activity retention suitable for most day-to-day investigations across Microsoft 365. Audit Premium extends these capabilities with longer retention periods, custom audit retention policies, richer event details, higher-volume API access, and enhanced investigation capabilities designed for highly regulated industries, enterprise security operations, legal investigations, and long-running compliance cases. Selecting the appropriate licensing strategy ensures organizations retain critical evidence for the period required by regulatory obligations, contractual commitments, and internal governance policies. BUILDING A STRONG MICROSOFT 365 AUDIT STRATEGY Successful auditing extends beyond simply enabling the Unified Audit Log. Organizations should regularly verify that audit events are being collected, assign dedicated Audit Reader and Audit Manager roles, establish clear investigation procedures, define retention requirements, and document repeatable search processes for common security and compliance scenarios. Testing audit searches before incidents occur allows security teams to validate workflows, improve response times, and ensure investigators know how to correlate Audit with Microsoft Defender, Insider Risk Management, eDiscovery, Compliance Manager, and other Microsoft Purview services. By building these processes early, organizations create a strong governance foundation that improves security visibility, regulatory compliance, and operational resilience across the Microsoft 365 environment. Become a supporter of this podcast: https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support.

    Microsoft Purview Audit - Simply Explained
  2. 17 小時前

    AVD vs Windows 365: Which Virtual Desktop Strategy Wins: with Shabaz Darr [MVP]

    Choosing the right virtual desktop platform has become one of the most important decisions for organizations modernizing their workplace. Although Azure Virtual Desktop (AVD) and Windows 365 are often compared, they solve different business challenges. In this episode of M365.FM, Microsoft MVP Shabaz Darr explains the architecture, licensing, deployment strategies, and real-world use cases for both platforms. The discussion provides practical guidance for IT leaders, cloud architects, Microsoft administrators, and consultants looking to build secure, scalable, and cost-effective end-user computing environments. WHEN TO CHOOSE AZURE VIRTUAL DESKTOP OR WINDOWS 365 Every successful virtual desktop deployment begins with understanding user personas. Shabaz explains why organizations should evaluate how employees work before selecting a platform. Azure Virtual Desktop excels for multi-session environments where many users share cloud resources efficiently, making it ideal for general office workers, call centers, education, and enterprise-scale deployments. Windows 365, on the other hand, delivers dedicated Cloud PCs that are perfectly suited for developers, power users, engineers, and professionals requiring predictable performance, dedicated resources, and simplified management through Microsoft Intune. BUILDING A SECURE AND SCALABLE VIRTUAL DESKTOP ARCHITECTURE Successful Azure Virtual Desktop implementations rely on strong architectural foundations. The conversation explores Azure Landing Zones, Cloud Adoption Framework principles, identity, networking, storage, Azure Files, Azure NetApp Files, FSLogix profile containers, host pools, workspaces, autoscaling, monitoring, and performance optimization. Shabaz explains why proper planning, governance, and infrastructure design have a far greater impact on long-term success than simply deploying virtual machines. Organizations that invest in architecture from the beginning gain better security, lower operational costs, improved user experiences, and easier long-term maintenance. OPTIMIZING COSTS, PERFORMANCE, AND USER EXPERIENCE Managing cloud costs remains one of the biggest concerns for enterprise IT teams. This episode explains how Azure Virtual Desktop automatically scales resources based on demand, reducing unnecessary infrastructure costs while maintaining excellent performance for users. Shabaz also discusses monitoring strategies using Azure Monitor and Nerdio, workload optimization, storage performance, session host sizing, bandwidth considerations, and continuous tuning based on real usage data. Rather than guessing infrastructure requirements, organizations can use performance analytics to optimize environments over time while delivering consistent user experiences. MODERN SECURITY FOR CLOUD DESKTOPS Security is built into every layer of Microsoft's virtual desktop platforms. The discussion covers Conditional Access, Microsoft Entra ID, Zero Trust, Microsoft Defender, multifactor authentication, compliance policies, identity protection, and secure remote access. Shabaz explains why identity has become the new security perimeter in cloud computing and why organizations should balance strong security controls with user productivity. Instead of creating friction through excessive authentication prompts, modern security focuses on intelligent risk-based protection that safeguards users without interrupting their daily work. THE FUTURE OF END-USER COMPUTING IN THE AI ERA Artificial Intelligence is beginning to reshape virtual desktop environments through automation, intelligent management, and AI-powered administration. The conversation explores Windows 365 Frontline, Windows 365 Reserve, GPU-enabled Cloud PCs, AI workloads, automation, Infrastructure as Code, Nerdio management capabilities, and the future evolution of Azure Virtual Desktop and Windows 365. Listeners also gain insight into how organizations can prepare for next-generation cloud desktops while balancing performance, cost optimization, governance, and the growing role of AI in enterprise computing. Become a supporter of this podcast: https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support.

  3. 23 小時前

    Global Secure Access - Simply Explained

    The way people work has fundamentally changed. Employees now access business applications from home offices, airports, customer sites, coffee shops, and mobile devices instead of sitting inside a corporate network. Traditional VPNs were designed for an era when applications lived inside company data centers and network boundaries provided the primary layer of security. In this Microsoft Knowledge Nuggets episode, Mirko Peters explains Microsoft Entra Global Secure Access (GSA) in plain English, showing how Microsoft replaces broad network connectivity with identity-driven Zero Trust access that grants users access only to the specific applications and services they need. UNDERSTANDING MICROSOFT ENTRA GLOBAL SECURE ACCESS Microsoft Entra Global Secure Access is Microsoft's cloud-delivered Security Service Edge (SSE) platform that secures access to both private enterprise applications and public internet resources. Instead of assuming that anyone connected to the company network should be trusted, Global Secure Access evaluates every connection using Microsoft Entra ID, Conditional Access, device compliance, user identity, application context, and real-time security signals. This Zero Trust approach continuously validates every request, helping organizations reduce lateral movement, simplify remote access, and strengthen security across hybrid work environments. MICROSOFT ENTRA PRIVATE ACCESS: THE MODERN VPN REPLACEMENT Microsoft Entra Private Access introduces Zero Trust Network Access (ZTNA) for internal business applications without exposing entire corporate networks. Rather than connecting users to broad network segments, Private Access creates secure, identity-based connections directly to specific applications, file shares, remote desktops, databases, and on-premises services. The episode explains how Private Access connectors securely bridge internal resources to Microsoft Entra without requiring public exposure while allowing organizations to replace complex VPN infrastructures with application-centric access policies. Contractors, remote workers, consultants, and hybrid employees receive only the permissions required for their assigned business tasks, dramatically reducing unnecessary network exposure. MICROSOFT ENTRA INTERNET ACCESS AND SECURE WEB PROTECTION Enterprise security extends beyond private applications to the public internet. Microsoft Entra Internet Access functions as a cloud-based Secure Web Gateway (SWG), applying organizational security policies before users access websites, SaaS applications, AI services, and cloud platforms. The discussion explores URL filtering, SaaS visibility, AI governance, Microsoft Purview integration, TLS inspection, file protection, and cloud application discovery. Organizations gain greater visibility into internet usage while protecting sensitive business information from unauthorized uploads, malicious websites, shadow IT, and emerging AI services that may introduce compliance or data protection risks. ZERO TRUST IDENTITY, CONDITIONAL ACCESS, AND CONTINUOUS VERIFICATION Identity sits at the center of every access decision. Microsoft Entra ID verifies user identity while Conditional Access evaluates additional factors such as device compliance, Microsoft Intune management, Microsoft Defender security signals, multifactor authentication, user risk, session risk, and organizational policies. Instead of granting permanent trust after a VPN connection is established, Global Secure Access continuously evaluates whether users should maintain access based on changing conditions throughout their session. This adaptive security model allows organizations to respond immediately when devices become non-compliant, accounts show suspicious behavior, or security risks increase. BUILDING A MODERN ZERO TRUST ACCESS STRATEGY Microsoft Entra Global Secure Access represents a fundamental shift from network-centric security toward identity-first access control. By combining Microsoft Entra Private Access, Microsoft Entra Internet Access, Conditional Access, Microsoft Intune, Microsoft Defender, Microsoft Purview, Zero Trust principles, and Security Service Edge architecture, organizations can secure both private applications and internet traffic through a unified cloud platform. Businesses beginning their Zero Trust journey should start with a focused pilot involving a single user group and business application before gradually expanding secure identity-based access across the enterprise. The result is a simpler, more scalable, and significantly more secure approach to modern hybrid work. Become a supporter of this podcast: https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support.

    Global Secure Access - Simply Explained
  4. 1 天前

    Entra Workload Identities - Simply Explained

    Modern cloud environments are no longer accessed only by people. Applications, automation workflows, Azure services, DevOps pipelines, AI agents, and background jobs all require secure access to business resources without relying on human interaction. In this Microsoft Knowledge Nuggets episode, Mirko Peters explains Microsoft Entra Workload Identities in plain English, showing how software securely authenticates to Microsoft 365, Azure, Microsoft Graph, and enterprise services without storing usernames and passwords inside code. Whether you're an Azure administrator, cloud architect, developer, DevOps engineer, or Microsoft consultant, this episode provides a practical foundation for understanding secure application authentication. UNDERSTANDING USER IDENTITIES VS WORKLOAD IDENTITIES Microsoft Entra ID manages both human users and software identities, but they operate very differently. Human identities authenticate using passwords, passkeys, Windows Hello, and multi-factor authentication, while applications require non-interactive authentication methods that operate continuously without user involvement. Workload identities provide applications with their own unique digital identity, allowing Microsoft Entra ID to authenticate software independently from human accounts. This separation improves security, eliminates shared service accounts, increases auditing capabilities, and allows every application, automation, or AI workload to receive only the permissions required for its specific business purpose. APP REGISTRATIONS, SERVICE PRINCIPALS, AND MANAGED IDENTITIES EXPLAINED Three Microsoft Entra concepts frequently confuse administrators: Application Registrations, Service Principals, and Managed Identities. This episode clearly explains the relationship between these components. Application Registrations define the global identity of an application and describe the permissions it may request. Service Principals represent the application's local identity within an individual Microsoft Entra tenant, where administrators grant permissions and enforce security controls. Managed Identities extend this model by allowing Azure resources such as Azure Functions, Logic Apps, Virtual Machines, and App Services to authenticate automatically without developers managing secrets, passwords, or certificates. Together, these identity models create the secure authentication foundation for modern cloud-native applications. HOW MANAGED IDENTITIES ELIMINATE PASSWORDS One of the most significant security improvements in Microsoft Azure is the ability to authenticate workloads without embedding credentials inside applications. Instead of storing passwords, client secrets, or connection strings within source code, Azure resources using Managed Identities request short-lived access tokens directly from Microsoft Entra ID. The episode explains how authentication and authorization work together, how Azure Key Vault integrates with Managed Identities, and why temporary access tokens dramatically reduce the risks associated with credential theft, secret leakage, source code exposure, and long-lived authentication credentials. SECURING WORKLOAD IDENTITIES IN MICROSOFT AZURE Workload identities require governance just like privileged user accounts. The discussion explores the importance of least privilege access, Conditional Access for workload identities, workload identity federation, certificate-based authentication, Microsoft Entra ID Protection, logging, monitoring, lifecycle management, and ownership. Mirko explains why every workload identity should have a clearly assigned owner, minimal permissions, continuous monitoring, and regular security reviews. Organizations that neglect application identities often leave behind unused service principals, forgotten secrets, excessive permissions, and automation that continues operating long after the original project has ended. CHOOSING THE RIGHT IDENTITY STRATEGY FOR EVERY WORKLOAD Selecting the correct authentication model depends largely on where the application executes. Azure-hosted services should generally use System-Assigned or User-Assigned Managed Identities whenever possible. Applications running outside Azure, including GitHub Actions and external cloud platforms, benefit from Workload Identity Federation instead of long-lived client secrets. Custom enterprise applications often require Application Registrations and Service Principals, while certificates provide a more secure alternative to client secrets when Managed Identities are unavailable. By combining Microsoft Entra Workload Identities, Azure Key Vault, Microsoft Graph, Zero Trust principles, and least privilege access, organizations can significantly strengthen application security while simplifying authentication across Microsoft 365 and Azure environments. Become a supporter of this podcast: https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support.

    Entra Workload Identities - Simply Explained
  5. 1 天前

    Azure Platform Engineering, Azure Landing Zones, Cloud Adoption Framework & Building Enterprise Cloud Platforms Jev Suchoi [MVP]

    Moving workloads into Microsoft Azure is only the beginning of a successful cloud journey. Building a cloud platform that is secure, scalable, automated, and developer-friendly requires a completely different mindset. In this episode of M365.FM, Microsoft MVP Jev Suchoi explains how Platform Engineering helps organizations build reusable cloud foundations that enable innovation while maintaining governance, security, and operational excellence. The discussion explores Azure Landing Zones, Infrastructure as Code, Cloud Adoption Framework, DevOps, automation, and modern enterprise cloud architecture through practical real-world experience. UNDERSTANDING AZURE LANDING ZONES AND CLOUD FOUNDATIONS Azure Landing Zones provide the standardized architecture that allows organizations to deploy workloads consistently across Microsoft Azure. Jev explains how Landing Zones establish networking, identity, security, governance, subscriptions, policies, and management services before application teams begin deploying workloads. Rather than treating Azure like a traditional datacenter, organizations should build cloud-native platforms designed for scalability, automation, and self-service. The conversation also explains why Microsoft's Enterprise Landing Zone architecture serves as an excellent starting point while still requiring customization for individual business requirements. MICROSOFT CLOUD ADOPTION FRAMEWORK AND WELL-ARCHITECTED DESIGN The Microsoft Cloud Adoption Framework offers far more than technical guidance. It provides a comprehensive roadmap covering business strategy, governance, security, organizational change, operations, and cloud architecture. Jev discusses how organizations should gradually introduce the framework without overwhelming teams, allowing architects, operations teams, and security specialists to focus on the areas most relevant to their roles. The episode also explores how the Azure Well-Architected Framework complements Cloud Adoption Framework by helping architects design highly available, secure, reliable, performant, and cost-optimized cloud workloads. AUTOMATION, INFRASTRUCTURE AS CODE, AND MODERN GOVERNANCE Automation sits at the center of every successful Azure platform. Infrastructure as Code enables organizations to deploy consistent environments, improve compliance, reduce configuration drift, and implement security earlier in the deployment lifecycle. Jev explains how Bicep, Terraform, Azure Verified Modules, Azure Policy, and automated guardrails allow platform teams to create repeatable cloud environments while reducing operational risk. Listeners also learn how proactive governance replaces traditional reactive operations through policy enforcement, remediation, monitoring, and standardized deployment practices. BUILDING SELF-SERVICE PLATFORMS DEVELOPERS LOVE Platform Engineering is ultimately about creating internal platforms that enable development teams to deliver business value faster. Instead of becoming operational bottlenecks, platform teams should provide self-service capabilities, reusable templates, deployment pipelines, standardized environments, and automated security controls. Jev explains why developers should be viewed as customers of the platform and how organizations can balance flexibility with governance by providing clear guardrails rather than unnecessary restrictions. The discussion also covers GitHub, Azure DevOps, Internal Developer Platforms, and why successful platforms focus on enabling developers instead of competing with the Azure Portal. AI, CLOUD OPERATIONS, AND THE FUTURE OF ENTERPRISE AZURE Artificial Intelligence is rapidly changing the daily work of cloud engineers and platform architects. Jev shares how GitHub Copilot accelerates Infrastructure as Code development, improves productivity, and assists experienced engineers while emphasizing the importance of architectural knowledge and critical thinking. The conversation concludes with practical advice on cloud adoption, governance, platform engineering, Azure security, automation, developer experience, and why organizations should automate repetitive tasks while allowing engineers to focus on solving complex business challenges. The key takeaway is simple yet powerful: automate the boring work so people can concentrate on innovation. Become a supporter of this podcast: https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support.

  6. 1 天前

    Microsoft Entra Verified ID - Simply Explained

    Modern identity security extends far beyond passwords and multi-factor authentication. While Microsoft Entra ID, passkeys, and MFA help verify that someone controls a sign-in method, they cannot prove important real-world facts such as employment status, completed security training, professional certifications, contractor relationships, or verified identity during account recovery. In this Microsoft Knowledge Nuggets episode, Mirko Peters explains Microsoft Entra Verified ID in plain English, showing how organizations can replace manual document verification with secure, privacy-friendly digital credentials that improve trust while reducing administrative effort. UNDERSTANDING MICROSOFT ENTRA VERIFIED ID Microsoft Entra Verified ID enables organizations to issue, store, and verify digital credentials based on open standards for decentralized identity. Instead of emailing PDFs, screenshots, certificates, or identity documents, trusted organizations issue digitally signed credentials that individuals securely store inside the Microsoft Authenticator app. These credentials contain verified claims such as employee status, completed training, professional licenses, student enrollment, or supplier relationships. When another organization requests proof, users decide whether to share the required information while the verifier can validate the credential's authenticity, issuer, expiration date, and revocation status without relying on manual phone calls or email confirmations. ISSUERS, HOLDERS, AND VERIFIERS: THE VERIFIED ID MODEL Every Microsoft Entra Verified ID solution follows a simple three-party trust model. The issuer creates and digitally signs the credential after validating information from trusted business systems. The holder receives and securely stores the credential in their digital wallet within Microsoft Authenticator. The verifier requests specific claims to support a business decision such as granting access, approving onboarding, confirming qualifications, or validating identity during sensitive operations. This model significantly reduces document handling, minimizes unnecessary sharing of personal information, and creates a more secure verification process that scales across organizations. FACE CHECK AND HIGH-ASSURANCE IDENTITY VERIFICATION For higher-risk scenarios, Microsoft Entra Verified ID introduces Face Check to strengthen identity verification. Face Check compares a live selfie with the photo stored inside the verified credential, helping organizations confirm that the individual presenting the credential is the legitimate credential holder. The episode explores practical use cases including remote employee onboarding, privileged account recovery, contractor verification, privileged access requests, and high-security administrative operations. Combined with Microsoft Entra ID, Face Check provides stronger protection against impersonation attacks, deepfakes, stolen devices, and social engineering while supporting Zero Trust identity principles. PRACTICAL MICROSOFT 365 USE CASES FOR VERIFIED ID Microsoft Entra Verified ID integrates naturally with Microsoft 365 identity and governance scenarios. Organizations can automate remote onboarding, simplify secure account recovery, validate contractor relationships, confirm training completion before granting access to sensitive projects, and verify qualifications without exchanging physical documents. Combined with Microsoft Entra Access Packages, Microsoft Teams, SharePoint Online, enterprise applications, and Microsoft Entra role assignments, Verified ID enables organizations to make access decisions based on trusted business facts instead of manual document reviews. This reduces administrative overhead while improving both security and user privacy. BUILDING A TRUSTED DIGITAL IDENTITY STRATEGY Successfully implementing Microsoft Entra Verified ID requires careful planning around credential issuance, trusted issuers, claim definitions, expiration policies, revocation processes, governance, and user experience. Organizations should begin with a single business scenario that already involves manual identity verification, establish clear trust relationships, define credential lifecycles, and gradually expand their implementation. As digital identity continues evolving, Microsoft Entra Verified ID provides a scalable foundation for privacy-preserving verification that complements Microsoft Entra ID, MFA, passkeys, and Zero Trust architecture while helping organizations modernize identity proofing across employees, partners, contractors, students, and customers. Become a supporter of this podcast: https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support.

    Microsoft Entra Verified ID - Simply Explained
  7. 2 天前

    Windows 365 Link - Simply Explained

    Windows 365 Link is Microsoft's purpose-built access device for Windows 365 Cloud PCs, designed to deliver a secure, simplified desktop experience without storing applications, files, or user profiles locally. Rather than functioning as a traditional Windows PC, Windows 365 Link acts as a secure gateway that connects employees directly to their personal Cloud PC running in Microsoft's cloud. In this Microsoft Knowledge Nuggets episode, Mirko Peters explains Windows 365 Link in plain English, covering its architecture, hardware, licensing, identity management, security features, and the business scenarios where it provides the greatest value. Whether you're an IT administrator, Microsoft consultant, solution architect, or business decision-maker, this episode explains how Microsoft's cloud-first desktop strategy is reshaping modern workplace computing. UNDERSTANDING THE DIFFERENCE BETWEEN WINDOWS 365 LINK AND WINDOWS 365 CLOUD PCS One of the biggest misconceptions is that Windows 365 Link is simply another compact Windows computer. In reality, the Link device and the Cloud PC perform two completely different roles. The Link hardware serves as the secure connection point, while the actual Windows operating system, installed applications, user settings, documents, and workloads execute inside a Windows 365 Cloud PC hosted in Microsoft Azure. This separation allows employees to move between desks, offices, and shared workspaces while maintaining the same personalized Windows experience every time they sign in with their Microsoft Entra ID account. HOW MICROSOFT DELIVERS A SECURE CLOUD DESKTOP EXPERIENCE Security sits at the heart of the Windows 365 Link architecture. The device is intentionally designed with a minimal local footprint, eliminating traditional risks associated with locally stored files, installed applications, administrator accounts, and unmanaged software. The episode explores how Microsoft Entra ID, Microsoft Intune, Trusted Platform Module (TPM), Secure Boot, BitLocker encryption, Microsoft Defender, and strict application controls work together to protect both the access device and the cloud-hosted desktop environment. Combined with Zero Trust identity verification and centralized device management, organizations gain a highly secure endpoint while significantly reducing operational complexity. MODERN DEVICE MANAGEMENT WITH MICROSOFT INTUNE Windows 365 Link simplifies endpoint management by separating device administration from user computing. Microsoft Intune manages the Link hardware by enforcing security policies, deploying updates, monitoring compliance, and maintaining device configuration, while Windows 365 manages the Cloud PC assigned to each employee. This dual-management approach enables organizations to support hot-desking, shared workspaces, contact centers, healthcare environments, training facilities, retail operations, and frontline workers without maintaining a unique Windows installation on every physical device. The result is simplified lifecycle management, faster hardware replacement, and greater operational consistency across enterprise environments. WHO SHOULD DEPLOY WINDOWS 365 LINK? Windows 365 Link is best suited for organizations that have already standardized on Windows 365 Cloud PCs and Microsoft Entra ID. Shared desks, shift workers, call centers, reception areas, branch offices, training rooms, and secure office environments benefit most from the device's cloud-first design. However, the episode also explains where traditional laptops remain the better option. Mobile employees, field workers, developers requiring local software installations, creative professionals using high-performance applications, and users who frequently work offline continue to benefit from full Windows devices. Understanding these deployment scenarios helps organizations choose the right endpoint strategy for each user persona. BUILDING THE FUTURE OF CLOUD-FIRST END USER COMPUTING Windows 365 Link represents Microsoft's long-term vision for cloud-based desktop computing. Instead of managing complex local devices, organizations can centralize Windows environments in the cloud while providing employees with secure, purpose-built access hardware. Combined with Windows 365 Cloud PCs, Microsoft Intune, Microsoft Entra ID, Microsoft Teams optimization, and modern endpoint management, Windows 365 Link enables businesses to simplify IT operations, improve security, support flexible workplaces, and prepare for the next generation of enterprise computing. For organizations embracing cloud-first infrastructure, Windows 365 Link provides a practical foundation for scalable, secure, and highly manageable digital workspaces. Become a supporter of this podcast: https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support.

    Windows 365 Link - Simply Explained
  8. 2 天前

    Building Modern Microsoft 365 Solutions with SharePoint Framework, Microsoft Graph, PnPjs & Great User Experiences with Julie Turner [MVP]

    Modern Microsoft 365 development is about far more than writing code. Organizations expect solutions that integrate seamlessly across SharePoint, Microsoft Teams, Microsoft Graph, Azure, and Microsoft 365 while remaining scalable, secure, maintainable, and ready for future innovation. In this episode of M365.FM, Microsoft MVP Julie Turner shares decades of real-world experience designing enterprise-grade Microsoft 365 solutions. From SharePoint Framework (SPFx) and Microsoft Graph to PnPjs, open-source development, UX design, and AI-assisted coding, this conversation provides practical guidance for developers, solution architects, consultants, and technical decision makers building on the Microsoft platform. WHY MICROSOFT 365 EXTENSIBILITY MATTERS MORE THAN EVER Microsoft 365 has evolved into a powerful business platform that goes far beyond email and collaboration. Julie explains how extensibility enables organizations to transform Microsoft 365 into a tailored business platform by integrating external systems, automating business processes, extending SharePoint and Teams, and creating custom user experiences. Rather than replacing standard Microsoft functionality, modern development focuses on extending it through supported APIs, frameworks, and services that remain compatible with Microsoft's continuous cloud updates. SHAREPOINT FRAMEWORK AS THE FOUNDATION OF MODERN DEVELOPMENT SharePoint Framework has become the standard for building supported client-side solutions across Microsoft 365. Julie explains why SPFx remains the preferred development model for SharePoint Online, Microsoft Teams, and Microsoft 365 experiences. The discussion covers hosted deployment, simplified maintenance, supported customization, reusable components, and how developers can build scalable enterprise applications without maintaining complex infrastructure. The episode also highlights the best learning resources, Microsoft Learn content, and the extensive Patterns and Practices (PnP) community for developers getting started with SharePoint Framework. MICROSOFT GRAPH, PNPJS, AND THE FUTURE OF ENTERPRISE APIS Microsoft Graph has become the central gateway into Microsoft 365, but understanding when to use Graph versus native SharePoint REST APIs remains critical. Julie discusses the strengths and current limitations of Microsoft Graph, endpoint maturity, authentication, permissions, performance considerations, and enterprise security. She also explains how PnPjs dramatically simplifies development by eliminating repetitive boilerplate code, providing fluent APIs, simplifying authentication, retry logic, error handling, and API consumption. Listeners also gain insight into the future roadmap of PnPjs Version 5 and the importance of semantic versioning in large open-source projects. DESIGNING USER EXPERIENCES THAT PEOPLE ACTUALLY ENJOY USING Technology alone does not create successful solutions. Great user experience often determines whether employees embrace or avoid enterprise software. Julie shares practical examples from real customer projects, explaining how thoughtful UX design improves productivity, reduces friction, and increases adoption. Whether building mobile applications for field workers, internal business applications, or Microsoft 365 solutions, developers should focus on simplicity, responsiveness, accessibility, and minimizing unnecessary user interaction. Small UX decisions can have enormous impacts on employee satisfaction and business efficiency. OPEN SOURCE, AI, AND THE FUTURE OF MICROSOFT DEVELOPMENT The conversation concludes with an honest discussion about open-source software, AI-assisted development, GitHub Copilot, Claude Code, Microsoft Copilot, and the future relationship between low-code and pro-code development. Julie explains why AI should enhance—not replace—developer expertise, how experienced developers can use AI as a collaborative assistant rather than an automated replacement, and why logical thinking and software architecture remain essential skills. The episode finishes with rapid-fire questions covering favorite developer tools, coding preferences, Microsoft events, future improvements for Microsoft Graph, and practical advice for developers who want to start building modern Microsoft 365 solutions today. Become a supporter of this podcast: https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support.

評分與評論

5
(滿分 5 顆星)
3 則評分

簡介

Welcome to the M365.FM — your essential podcast for everything Microsoft 365, Azure, and beyond. Join us as we explore the latest developments across Power BI, Power Platform, Microsoft Teams, Viva, Fabric, Purview, Security, and the entire Microsoft ecosystem. Each episode delivers expert insights, real-world use cases, best practices, and interviews with industry leaders to help you stay ahead in the fast-moving world of cloud, collaboration, and data innovation. Whether you're an IT professional, business leader, developer, or data enthusiast, the M365.FM brings the knowledge, trends, and strategies you need to thrive in the modern digital workplace. Tune in, level up, and make the most of everything Microsoft has to offer. M365.FM is part of the M365-Show Network. Become a supporter of this podcast: https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support.

你可能也會喜歡