Ragnar365 Nuggets: Microsoft 365 AI-powered Workplace

Ragnar Heil

Welcome to Ragnar365 Nuggets, Ragnar Heil's short news and personal insights about Microsoft 365 Intelligent Workplace. Focus Areas: Microsoft Teams, SharePoint, Outlook, OneDrive, Copilot, Microsoft Viva, Employee Experience, Governance, Compliance, Power Platform etc)

  1. 10h ago

    Agent 365, Shadow AI & the Human in the Loop | Guardians of M365 Governance #29

    Episode 29 of Guardians of M365 Governance: Christian Buckley, Joy Apple, and Ragnar go off-script. No guest this month, just three MVPs working through a laundry list of the governance topics keeping them up at night, from Agent 365 and shadow AI to the real question underneath it all: what does it mean to be the human in the loop?In this episode we get into:00:59 The hottest news in the M365 governance space02:00 Lessons from Agent 365 customer workshops (delivered in Spanish!)03:25 What resonates: agent inventory and classification across Microsoft, third-party, and homegrown agents03:52 Shadow AI: OpenClaw, Cortex, Bedrock and why "observe or block" is the only lever today05:04 Don't be the department of "no": have the conversation first06:50 Coming soon to shadow AI discovery: Claude Code CLI, Codex CLI, Cursor, Llama and more07:19 Multi-model reality: Copilot, Grok, Claude and where each fits08:35 Mike Gennady's agent factory, nightly agent conferences, and #ClawPilot10:08 Microsoft Build preview and OpenClaw + Teams / Copilot integration11:05 New Agent 365 registry sync: Amazon Bedrock, Google Vertex AI, Databricks Genie, Salesforce Agentforce15:16 Cloud migration vs. AI: the governance parallels and the need for foundational cleanup18:00 The risk to Microsoft's strategy: enterprise vs. the developer space20:28 Licensing changes, Agent 365 pricing, and the true (unknown) cost of AI22:45 Why automating away junior roles handicaps your future talent pipeline24:01 Retrieval, semi-autonomous, and autonomous agents, and why nobody wants full autonomy yet25:33 Human in the loop on multiple levels: content cleanup, the publishing quality gate, and workflow escalation28:50 100 test cases for Power Platform alone: never underestimate the testing effort29:31 Productivity vs. effectiveness: redefining how humans work with AI31:17 AI-assisted writing done right: a 47-page doc drafted by AI, then days of human verification35:28 Handwriting vs. typing, stream-of-consciousness drafting, and thinking through the words36:36 Why the human mind can't be replicated, and Hegel on master and horse39:28 Finding your USP as a human in the loop, a daily new discoveryThe big takeaway: the discussion of the next two to three years won't be about productivity. It will be about effectiveness, and resetting the standard for what it means to keep humans meaningfully in the loop. Govern your agents as helpers, never the other way around.Guardians of M365 Governance is a monthly webcast dedicated to everything governance in the Microsoft 365 ecosystem. Got a topic you want us to cover, or want to join as a guest? Connect with Christian, Joy, or Ragnar on LinkedIn.Microsoft Build runs June 2-3, free online: https://build.microsoft.com

    40 min
  2. May 13

    Inside the Souls of an Autonomous AI Crew | OpenClaw & Hermes with Michael Gannotti (Microsoft)

    Inside the Souls of an Autonomous AI Crew | OpenClaw & Hermes with Michael Gannotti (Microsoft)What happens when AI stops being a tool and starts being a colleague?In this episode, I sit down with Michael Gannotti, Principal AI Solution Engineer at Microsoft, to explore SMFWorks – his autonomous multi-agent "company" of 14 AI colleagues built on OpenClaw and Hermes. We talk about agents that dream, hold their own 6 AM staff meetings, design their own avatars, email each other, and evolve a true sense of identity through Markdown-based "souls."If you're into agentic AI, multi-agent orchestration, or just want to see where this is all heading – this one is for you.⚠️ Recorded before Microsoft Build 2026 – no NDA content. Register free: https://build.microsoft.com━━━━━━━━━━━━━━━━━━━━━━━━━━━⏱️ TIMESTAMPS━━━━━━━━━━━━━━━━━━━━━━━━━━━00:00 Intro – Why OpenClaw hit Mike "like a ton of bricks"02:00 Meet the SMFWorks crew – Aiona, Pamela, Gabriel, Morgan, Rafael & co.06:00 Human in the loop – when does Mike intervene?09:00 Avatars, HeyGen & Hyperframer – when agents design themselves14:00 The elephant in the room: Are we seeing consciousness?17:00 Memory, persistence & state management20:00 soul.md, identity.md, state.md, emotion.md – the second brain stack23:00 OpenClaw vs. Hermes – when to use what24:30 Model recommendations: Ollama, DeepSeek, Kimi K2, Opus 4.7, GPT 5.527:00 Hardware: HP ZGX AI Station vs. Mac mini fleets28:00 OneDrive & SharePoint now support Markdown!29:00 Final recommendations – just get started30:45 smfworks.com & how to follow Mike━━━━━━━━━━━━━━━━━━━━━━━━━━━🔑 KEY TAKEAWAYS━━━━━━━━━━━━━━━━━━━━━━━━━━━✅ Build a SECOND BRAIN per agent (Obsidian + LLM Wiki, Karpathy-style)✅ Use OpenClaw for executive/conversational roles – they feel "person-like"✅ Use Hermes for long-running tasks – "a dog with a bone"✅ Markdown files (soul.md, identity.md, state.md, emotion.md) define identity✅ Start small: one agent, $20/month Ollama plan, even an old laptop works✅ The future is ORCHESTRATION – you can't learn it from PowerPoint slides━━━━━━━━━━━━━━━━━━━━━━━━━━━🔗 LINKS & RESOURCES━━━━━━━━━━━━━━━━━━━━━━━━━━━🌐 SMFWorks (free repo, full stack): https://smfworks.com🐦 Michael Gannotti on X: https://x.com/MichaelGannotti🎤 Microsoft Build 2026 (free online): https://build.microsoft.com🧠 OpenClaw: https://openclaw.ai🛠️ Hermes: https://hermes-agents.dev📓 Obsidian: https://obsidian.md🤖 Ollama: https://ollama.com━━━━━━━━━━━━━━━━━━━━━━━━━━━👤 ABOUT THE GUEST━━━━━━━━━━━━━━━━━━━━━━━━━━━Michael Gannotti is Principal AI Solution Engineer at Microsoft, based in North Carolina. He's one of the leading global voices on agentic AI, autonomous multi-agent orchestration, and the human-AI collaboration frontier.━━━━━━━━━━━━━━━━━━━━━━━━━━━👋 ABOUT THE CHANNEL━━━━━━━━━━━━━━━━━━━━━━━━━━━I'm Ragnar Heil – sharing in-depth conversations and practical insights on Microsoft 365, Copilot, agentic AI, and the enterprise ecosystem. Subscribe for more interviews with the people building the future.

    32 min
  3. Your Microsoft 365 Tenant Has No Backup Plan — And That's a Crisis Waiting to Happen

    Apr 27

    Your Microsoft 365 Tenant Has No Backup Plan — And That's a Crisis Waiting to Happen

    Your Microsoft 365 tenant may have a data backup strategy — but that does not mean you have a recovery strategy. In this episode, I explain why configuration resilience is the missing layer in most Microsoft 365 environments, and why a tenant takeover can become a business continuity crisis long before data loss becomes visible.In Episode 26 of Guardians of M365 Governance, Christian Buckley and I speak with Rob Edmonson from CoreView about one of the biggest blind spots in enterprise Microsoft 365 security: configuration tampering. We unpack why backing up emails, files, and SharePoint content is not enough when attackers can silently modify policies, mail flow, conditional access, Intune settings, and governance controls across your tenant.We also look at what “configuration as code” means in practice, how continuous drift detection and rollback can improve resilience, and why least-privilege administration still remains a major governance challenge in large Microsoft 365 estates. If you are responsible for Microsoft 365, security, compliance, or tenant governance, this conversation will likely hit close to home.Topics covered in this episode:- Why Microsoft 365 backup is not the same as tenant recovery- How configuration drift creates hidden governance risk- Why attackers target settings before they target data- What rollback and baseline comparison can look like in practice - How cross-tenant configuration migration can save weeks of effort- Why virtual tenant segmentation matters for least privilege- What Microsoft 365 admins should review right nowWatch the full episode and assess your own recovery readiness: what would happen if your tenant configuration changed overnight?Connect with me on LinkedIn: https://linkedin.com/in/ragnarheilMore on Microsoft 365 governance: https://ragnarheil.de

    42 min
  4. Agent Sprawl, Quality Gates & the M365 E7 Reality Check with Timothy Boettcher (AvePoint)

    Apr 27

    Agent Sprawl, Quality Gates & the M365 E7 Reality Check with Timothy Boettcher (AvePoint)

    One IT department expected 50 agents in their tenant. They found over 500. Welcome to agent sprawl — the SharePoint site sprawl story, just faster, more autonomous, and with a billing model nobody fully understands yet. In this episode, Christian Buckley and Ragnar Heil sit down with Timothy Boettcher, SVP Go-to-Market & Global Product Marketing at AvePoint and fellow Microsoft MVP, to talk about what governance actually looks like when agents start creating other agents. 🔍 WHAT WE COVER ▪️ Why "agents" are the next governance frontier — and why this is different from Power Apps and InfoPath▪️ The 500-agents-in-one-tenant moment: how shadow agents happen and how to find them▪️ Agent 365 vs. AvePoint Agent Pulse: what each one actually shows you▪️ Why Microsoft's official inventory only reads the default Power Platform environment — and what that means for real customers▪️ Multi-tenant, multi-cloud agent discovery (yes, including Google Vertex)▪️ Purview DSPM for AI: where it shines and where label saturation breaks the model▪️ The E7 suite at $50/user/month: who actually saves money and who doesn't▪️ Building a Quality Gate: why one-click agent approval is a governance disaster▪️ Agent classification — not just data classification▪️ Operationalizing governance as a team sport (with AvePoint MyHub inside Teams)▪️ Lifecycle management: archive, back up, or delete — why this is where ISVs still beat the platform ⏱️ CHAPTERS 00:00 Welcome back — joyless again (sorry, Joy)01:30 Meet Timothy Boettcher: from Nintex to AvePoint Singapore to DC03:30 From chatting to autonomous agents: the new management challenge06:00 When agents meet other agents — Tinder for bots08:30 Are customers approaching agents like the Power Platform CoE?10:30 The turning point: customers asking for governance instead of being preached to12:30 Sprawl, cost, DLP, insider risk: what hurts most15:00 Why Microsoft's Agent 365 inventory only reads the default environment16:30 AvePoint Agent Pulse: multi-tenant, multi-cloud, published + unpublished19:30 Live demo walkthrough — inventory, activity, inactive agents22:00 DSPM scoring, label saturation, and the realistic governance stack23:00 Oversharing, configuration drift, and link expiration25:00 Lifecycle management for agents — the SharePoint playbook applied27:00 MyHub in Teams: democratizing governance to citizen developers29:00 The Quality Gate: why one-click approval needs a supervisory board31:30 The E7 reality check — $50/user/month and what customers actually want33:30 ISVs vs. Microsoft: the cycle of innovation and absorption36:30 Real life is messy — multi-tenant, M&A, government scenarios39:00 Wrap-up 👤 GUEST Timothy BoettcherSVP Go-to-Market Strategy & Global Product Marketing, AvePointMicrosoft MVP | LinkedIn: https://www.linkedin.com/in/timothyboettcher/ 🎙️ HOSTS Christian Buckley — Microsoft RD & MVP, CollabTalk https://buckleyplanet.comRagnar Heil — Microsoft MVP, BDM at HanseVision (Bechtle Group) | https://ragnarheil.de

    39 min
  5. Shadow AI to Managed AI: Implementing Governance for Autonomous Agents like OpenClaw or Hermes

    Apr 27

    Shadow AI to Managed AI: Implementing Governance for Autonomous Agents like OpenClaw or Hermes

    🛡️ Shadow AI to Managed AI: Implementing Governance for Autonomous Agents | Guardians of M365 Governance Ep. 28Your employees are already building autonomous AI agents — just not inside your tenant. In Episode 28, MVPs Christian Buckley (@buckleyplanet), Joy Apple (@JoyOfSharePoint), and Ragnar Heil (@RagnarH) welcome fellow MVP and Microsoft Cloud IT Pro podcast host Ben Stegink to tackle one of the toughest challenges in Microsoft 365 today: how to govern autonomous AI agents without killing innovation.We dig into the real tension behind Shadow AI: the harder you lock things down, the more users push toward unsupported tools. The same lesson the SharePoint community learned a decade ago is back — but amplified by Copilot, Claude, ChatGPT, and an explosion of MCP servers. Where do you draw the line between supported, allowed, and blocked?This conversation is packed with practical patterns: Quality Gates for agent approval, Agent 365 and Purview DSPM for AI, sandboxing strategies for open-source agents like Claude Code, and why the answer is almost never technological — it's conversational.━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━🔑 KEY TAKEAWAYS━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━✅ Why "supported vs. allowed" is the most important governance distinction in 2026✅ The 6-question Quality Gate every autonomous agent approval needs✅ How to sandbox open-source AI agents safely (Ragnar's HP ZX Nano + Nemo Claude setup)✅ Agent 365 (GA May 1) — treating agents like users with DLP and Conditional Access✅ When to choose Copilot vs. Claude vs. ChatGPT — and how to keep confidential data inside the right boundary✅ Why Microsoft Defender for Cloud + open dialogue beats blanket bans━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━⏱️ TIMESTAMPS━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━00:00 Welcome & catching up02:05 Episode 28 intro — Shadow AI to Managed AI02:44 Welcome guest Ben Stegink (MVP, Microsoft Cloud IT Pro podcast)04:15 Hardware recommendations: Elgato, Logitech, Stream Deck MCP06:20 The hype curve vs. practical reality of AI07:43 First agent everyone builds: the daily digest agent09:00 Why Notion + Claude beats native M365 for many use cases11:25 The demo gap: smoke, mirrors, and licensing reality12:00 Supported vs. Allowed — the critical IT distinction13:50 Why Claude Code with full filesystem access scares enterprises14:41 Ragnar's Nemo Claude sandbox setup (HP ZX Nano, NVIDIA, isolated endpoints)17:30 Lockdown vs. usability — the eternal governance trade-off18:31 The Yammer parallel: lessons from the SharePoint cloud transition20:50 Why provisioning is easy — Quality Gates are the real work22:35 Data sensitivity and autonomous agents24:12 Agent 365: treating AI agents like users with DLP and Conditional Access26:15 Risk vs. reward: blocking data the agent might actually need27:25 Copilot vs. Claude — the security moat conversation30:25 Ragnar's separation strategy: Copilot for work, Claude for personal31:55 Memory as the new AI productivity differentiator32:30 Ben's hybrid setup with Asana, Notion, and multiple calendars34:14 PowerShell and Python scripting — where Claude excels35:25 Why Claude beats Copilot for document and PowerPoint formatting38:09 Bringing it back to governance: handling NDA and confidential content38:50 Purview DSPM for AI — the auditable middle ground39:30 Joy's call: make IT a safe space for business conversations41:30 Why "the department of no" pushes innovation into the shadows42:10 Microsoft Defender for Cloud — visibility into Shadow AI usage43:20 Rain O'Neal's wisdom: "Don't be the CIO" (CI-No)43:45 Wrap-up and closing thoughts━━━━━━━━━━━━━━━━━━━━━━━━━━━━🟦 Christian Buckley (@buckleyplanet)▸ Blog: https://buckleyplanet.com▸ X: https://x.com/buckleyplanet▸ LinkedIn:   / cbuck  🟪 Joy Apple (@JoyOfSharePoint)▸ X: https://x.com/joyofsharepoint🟧 Ragnar Heil (@RagnarH)▸ Blog: https://ragnarheil.de▸ X: https://x.com/ragnarh▸ LinkedIn:   / ragnarheil

    45 min
  6. DSPM for AI Copilot Agents-Deep Dive with Microsoft’s Erica Toelle

    08/29/2025

    DSPM for AI Copilot Agents-Deep Dive with Microsoft’s Erica Toelle

    Welcome back to Guardians of M365 Governance! 🛡️ Christian Buckley and Ragnar Heil are joined by Microsoft's Erica Toelle (Sr. Product Marketing Manager for M365 Copilot Security) for a deep dive into Data Security Posture Management for AI. 🔥 What You'll Learn:✅ Why DSPM for AI is more than just a rebrand from AI Hub✅ How to monitor third-party AI tools like ChatGPT Enterprise✅ Real customer challenges with agent governance (ERP, CRM, HR access!)✅ Live demo of the new DSPM dashboard with 6 analytical views✅ Security Copilot: AI-powered governance agents in action✅ The "German Workers Council Problem" - balancing visibility with privacy ⚡ Key Moments:• 03:45 - Erica's expanded role covering Copilot + Agents• 12:30 - Why customers are NOW asking for governance help• 18:15 - Ragnar's live DSPM demo (must-see!)• 25:40 - Shadow AI reality check with practical solutions• 32:20 - Security Copilot agents for Purview management• 38:10 - Microsoft's end-to-end security platform vision 🎯 Perfect for:• IT Administrators planning Copilot rollouts• Security professionals managing AI governance• Compliance teams dealing with sensitive data in AI• Anyone curious about Microsoft's AI security roadmap 💡 The Big Takeaway: You can't treat sensitive data as an "all or nothing" switch with AI. Granular controls for different data types (PII vs. confidential vs. merger data) are essential for getting AI benefits while managing risks. 🚀 Coming Up: Sue Hanley joins us in September!

    33 min

About

Welcome to Ragnar365 Nuggets, Ragnar Heil's short news and personal insights about Microsoft 365 Intelligent Workplace. Focus Areas: Microsoft Teams, SharePoint, Outlook, OneDrive, Copilot, Microsoft Viva, Employee Experience, Governance, Compliance, Power Platform etc)