1
00:00:00,000 --> 00:00:10,480
Hello and welcome to the Everyday Defender podcast.

2
00:00:10,480 --> 00:00:14,920
I'm Chris Goosen and I'm joined once again by my friend from the Netherlands, Koos.

3
00:00:14,920 --> 00:00:16,920
Hey Chris, good morning.

4
00:00:16,920 --> 00:00:17,920
How are you?

5
00:00:17,920 --> 00:00:18,920
Yeah, doing very well.

6
00:00:18,920 --> 00:00:19,920
Thank you.

7
00:00:19,920 --> 00:00:24,000
Yes, it is evening here in Sydney and it's been very hot.

8
00:00:24,000 --> 00:00:27,680
And I think this is a very weird concept for a lot of folks who are not in our hemisphere.

9
00:00:27,680 --> 00:00:33,080
But when it's 40 degrees Celsius and it's this close to Christmas, it gets really interesting.

10
00:00:33,080 --> 00:00:34,880
It's very much beach weather over here.

11
00:00:34,880 --> 00:00:38,920
Yeah, and it's like a little over 6 p.m. at your end, right?

12
00:00:38,920 --> 00:00:42,880
And it's a little over 8 a.m. in the morning in Amsterdam time.

13
00:00:42,880 --> 00:00:48,400
So while the sun is still shining bright through your blinds there in the back, I'm still here

14
00:00:48,400 --> 00:00:52,440
looking at a pitch black outdoorsy situation here over here.

15
00:00:52,440 --> 00:00:53,440
So that's really weird.

16
00:00:53,440 --> 00:00:54,440
Crazy.

17
00:00:54,440 --> 00:00:56,400
And the wonders of modern technology, right?

18
00:00:56,400 --> 00:01:02,120
So in today's episode, we're going to do a or at least attempt to do a little bit of

19
00:01:02,120 --> 00:01:07,960
a recap of Ignite 2024 that happened just recently in Chicago.

20
00:01:07,960 --> 00:01:11,840
I was lucky enough to be in Chicago for Ignite.

21
00:01:11,840 --> 00:01:14,280
It was interesting to say the least.

22
00:01:14,280 --> 00:01:20,280
The weather was fantastically crazy with snowstorms and things like that, which I am obviously

23
00:01:20,280 --> 00:01:22,840
not used to and built for.

24
00:01:22,840 --> 00:01:28,360
So yeah, exciting times talking about Ignite.

25
00:01:28,360 --> 00:01:32,800
Not a lot in terms of security announcements from Ignite.

26
00:01:32,800 --> 00:01:37,800
You know, I guess everyone probably expects or assumes that Ignite was very much focused

27
00:01:37,800 --> 00:01:40,720
around AI and copilot.

28
00:01:40,720 --> 00:01:42,320
And in fact, really, that was the case.

29
00:01:42,320 --> 00:01:45,400
It was very much a copilot event.

30
00:01:45,400 --> 00:01:49,320
But nonetheless, there were some some interesting things, you know, on the security side of

31
00:01:49,320 --> 00:01:51,320
things that that were announced.

32
00:01:51,320 --> 00:01:55,640
So I'm going to take a look at some of the announcements in Intune and Entra.

33
00:01:55,640 --> 00:01:58,080
And then, Koos, you've got a you've got a few other things that you want to talk about

34
00:01:58,080 --> 00:01:59,080
as well, right?

35
00:01:59,080 --> 00:02:00,080
Yeah, yeah, that's true.

36
00:02:00,080 --> 00:02:06,120
And I actually went through the Ignite book of news once again to refresh my mind what

37
00:02:06,120 --> 00:02:07,760
was actually announced.

38
00:02:07,760 --> 00:02:11,440
And I wanted to share a couple of fun facts first, Chris.

39
00:02:11,440 --> 00:02:14,600
I looked up the terms copilot and AI.

40
00:02:14,600 --> 00:02:19,160
And how many times do you think those words popped up in the book of news?

41
00:02:19,160 --> 00:02:20,920
I'd imagine quite a lot, right?

42
00:02:20,920 --> 00:02:23,360
Well, hundreds of times each one.

43
00:02:23,360 --> 00:02:24,640
So it was really crazy.

44
00:02:24,640 --> 00:02:28,920
It looks like every line was filled with copilot and AI.

45
00:02:28,920 --> 00:02:35,400
And also, those events are quite infamous for their feature or product renames, right?

46
00:02:35,400 --> 00:02:39,600
So we didn't get we didn't went back to Azure AD yet.

47
00:02:39,600 --> 00:02:42,200
We're still hoping for that one, I guess.

48
00:02:42,200 --> 00:02:43,200
Still hoping for that one.

49
00:02:43,200 --> 00:02:44,200
Yeah.

50
00:02:44,200 --> 00:02:45,880
So but we only got two product renames.

51
00:02:45,880 --> 00:02:48,720
I think that's that's a low score, I guess.

52
00:02:48,720 --> 00:02:50,680
Yeah, pretty low score.

53
00:02:50,680 --> 00:02:54,800
They were you know, maybe they're waiting for some of the other conferences or things

54
00:02:54,800 --> 00:02:56,640
next year to drop some more on us.

55
00:02:56,640 --> 00:02:59,320
But what did we what did we get renamed out of interest?

56
00:02:59,320 --> 00:03:00,320
Yeah.

57
00:03:00,320 --> 00:03:03,600
Well, one rename was based around Azure Stack HCI.

58
00:03:03,600 --> 00:03:08,140
So that is running your Azure locally, so to speak.

59
00:03:08,140 --> 00:03:13,720
So Azure, Azure Virtual Desktop for Azure Stack HCI was now renamed to Azure Virtual Desktop

60
00:03:13,720 --> 00:03:14,960
for Azure Local.

61
00:03:14,960 --> 00:03:19,460
So apparently, they're more emphasizing the Azure Local product name instead of Azure

62
00:03:19,460 --> 00:03:21,680
Stack from the past.

63
00:03:21,680 --> 00:03:25,340
And also, there was a rename in the pure purview section.

64
00:03:25,340 --> 00:03:31,000
So Microsoft purview data catalog has been renamed to purview unified catalog.

65
00:03:31,000 --> 00:03:36,820
And I actually heard from two colleagues, which were recording a demo for a session.

66
00:03:36,820 --> 00:03:39,880
And from one day to another, they were like, where is the data catalog?

67
00:03:39,880 --> 00:03:41,000
I cannot find it anymore.

68
00:03:41,000 --> 00:03:42,000
They were looking over it.

69
00:03:42,000 --> 00:03:45,840
And the rename has already been been applied in their tenant.

70
00:03:45,840 --> 00:03:49,000
So they had to figure out that it's now called unified catalog.

71
00:03:49,000 --> 00:03:50,000
Yes.

72
00:03:50,000 --> 00:03:52,880
And it shifted way down from being way at the top with D to way down to the bottom with

73
00:03:52,880 --> 00:03:53,880
you.

74
00:03:53,880 --> 00:03:55,880
Yeah, that's also true.

75
00:03:55,880 --> 00:03:58,120
I'm not familiar with the interface.

76
00:03:58,120 --> 00:04:00,000
I'm not really sure what it would look like.

77
00:04:00,000 --> 00:04:02,000
But yeah, it could be.

78
00:04:02,000 --> 00:04:03,000
Yeah.

79
00:04:03,000 --> 00:04:05,000
So nothing special on that end.

80
00:04:05,000 --> 00:04:06,600
Yeah, fair enough.

81
00:04:06,600 --> 00:04:07,600
Okay.

82
00:04:07,600 --> 00:04:13,800
Well, I guess if we if we get into it, let's take a look at some of the the the intro announcements.

83
00:04:13,800 --> 00:04:18,080
And I think, you know, it should come as no surprise that, you know, some of what was

84
00:04:18,080 --> 00:04:23,720
announced as far as Entra and Intune, in fact, as well, at Ignite is very much to get around

85
00:04:23,720 --> 00:04:24,720
copilot, right.

86
00:04:24,720 --> 00:04:27,280
So really, we're going to start seeing this.

87
00:04:27,280 --> 00:04:30,680
And I expect we're going to see this across the board.

88
00:04:30,680 --> 00:04:31,960
And this is really just the beginning of it.

89
00:04:31,960 --> 00:04:37,640
But we're going to start seeing Microsoft Security Copilot surfacing in more places

90
00:04:37,640 --> 00:04:41,200
within the portals, right, all of the management portals.

91
00:04:41,200 --> 00:04:44,440
And so they've they've made sort of an announcement around Intune.

92
00:04:44,440 --> 00:04:47,560
And we're going to see a lot more of that security copilot stuff being integrated and

93
00:04:47,560 --> 00:04:49,960
surfacing in Intune.

94
00:04:49,960 --> 00:04:54,000
The main parts of the integration, I think, are sort of in the advanced analytics piece.

95
00:04:54,000 --> 00:05:00,600
So being able to use natural language to help with your KQL queries, I think that's it's

96
00:05:00,600 --> 00:05:06,920
pretty powerful stuff, I think, if you're not if you're not natural or you're not super

97
00:05:06,920 --> 00:05:12,560
familiar with KQL and you don't use it on a daily basis, you know, being able to naturally

98
00:05:12,560 --> 00:05:19,800
speak or type a prompt in natural language for something and then have that KQL query

99
00:05:19,800 --> 00:05:21,200
given and generated for you.

100
00:05:21,200 --> 00:05:23,320
I could see that being really useful for folks.

101
00:05:23,320 --> 00:05:26,600
So I think that really works well as well.

102
00:05:26,600 --> 00:05:31,800
I think of it a little bit when when security copilot or copilot for security when it was

103
00:05:31,800 --> 00:05:37,160
called back then, another rename, by the way, was in early days.

104
00:05:37,160 --> 00:05:38,880
And the results were not that good.

105
00:05:38,880 --> 00:05:43,560
But I read did some tests lately and it was really good, actually.

106
00:05:43,560 --> 00:05:48,240
And it's also good to help you understand what data lives in what table.

107
00:05:48,240 --> 00:05:49,240
Right.

108
00:05:49,240 --> 00:05:51,000
So there are so many tables in the vendor.

109
00:05:51,000 --> 00:05:56,480
I mean, you ask copilot, but also chat GPT, for example, it knows which tables to search

110
00:05:56,480 --> 00:06:00,560
for certain data, which is already very useful to start with.

111
00:06:00,560 --> 00:06:06,000
That's and that's that's one of the biggest barriers to entry, right, to get in to writing

112
00:06:06,000 --> 00:06:08,240
these queries is just knowing what you're growing.

113
00:06:08,240 --> 00:06:10,280
So so I think that's that's pretty awesome.

114
00:06:10,280 --> 00:06:11,960
That's something that got announced.

115
00:06:11,960 --> 00:06:17,040
There's some some sort of copilot insights coming into the input privilege management

116
00:06:17,040 --> 00:06:18,600
stuff that you PM.

117
00:06:18,600 --> 00:06:20,760
Again, I think this is kind of useful.

118
00:06:20,760 --> 00:06:23,520
You know, if you're if you're using input privilege management, and I'll be honest,

119
00:06:23,520 --> 00:06:27,400
I don't have a lot of customers who've kind of gone down this route just yet.

120
00:06:27,400 --> 00:06:32,840
But essentially what it is for those folks who don't know is if you have, you know, elevated

121
00:06:32,840 --> 00:06:37,200
prompts, you know, you're trying to install software, for example, within on Windows 10

122
00:06:37,200 --> 00:06:42,280
or Windows 11, and you get that prompt for elevation for the software that goes into

123
00:06:42,280 --> 00:06:46,960
like a workflow, an admin workflow where an administrator can take a look at, you know,

124
00:06:46,960 --> 00:06:52,720
the application that's being installed and decide to grant you access to to to that elevation.

125
00:06:52,720 --> 00:06:55,760
And copilot is now sort of enriching that that prompt, right.

126
00:06:55,760 --> 00:07:00,360
So we cannot take the hash of the of the the application that's being installed and go

127
00:07:00,360 --> 00:07:04,340
and have a look and see whether there's some, you know, malware or something that is known

128
00:07:04,340 --> 00:07:05,340
to exist in this.

129
00:07:05,340 --> 00:07:09,960
And again, I think this can be really useful for large orgs where you may already have

130
00:07:09,960 --> 00:07:17,200
this workflow and then building this sort of copilot enhanced capability onto that,

131
00:07:17,200 --> 00:07:22,440
I think will be really handy for some policy management is another area where we're going

132
00:07:22,440 --> 00:07:23,720
to see copilot surface.

133
00:07:23,720 --> 00:07:25,920
Again, I think this is kind of useful.

134
00:07:25,920 --> 00:07:31,640
You know, I build a lot of interesting policies and I spend a lot of time in the policy editor.

135
00:07:31,640 --> 00:07:35,560
And you know, how I how I normally do it is I have policy editor opening one tab and I

136
00:07:35,560 --> 00:07:38,840
have another tab open to the Intune documentation on learn.

137
00:07:38,840 --> 00:07:44,120
And then if I'm if I'm trying to figure out an exact, you know, setting that, you know,

138
00:07:44,120 --> 00:07:47,400
I'm looking that up on learning to make sure that I've got the right thing and I'm able

139
00:07:47,400 --> 00:07:50,000
to like configure the right thing and making sure that I'm configuring it in the right

140
00:07:50,000 --> 00:07:51,000
way.

141
00:07:51,000 --> 00:07:52,000
Right.

142
00:07:52,000 --> 00:07:55,160
Well, with this sort of Intune surfacing in there now, you can actually get better insights,

143
00:07:55,160 --> 00:08:00,040
I think, into what a specific policy does by just clicking the little into sorry, copilot

144
00:08:00,040 --> 00:08:01,760
button in Intune.

145
00:08:01,760 --> 00:08:05,960
I think that can be really useful, especially if you've got a lot of policies and it's contextual.

146
00:08:05,960 --> 00:08:09,520
So it'll tell you if you have the setting configured in a different policy or if there's

147
00:08:09,520 --> 00:08:11,960
likely to be a conflict or or anything like that.

148
00:08:11,960 --> 00:08:14,080
So you know, yeah, I think that's cool.

149
00:08:14,080 --> 00:08:19,400
I think it's going to be, you know, make folks lives a little easier.

150
00:08:19,400 --> 00:08:22,640
And then the last area, I think, where we're going to see some some or whatever announced

151
00:08:22,640 --> 00:08:26,460
some some sort of integrations is on auto patch.

152
00:08:26,460 --> 00:08:31,320
So again, if you auto patching or using auto patch to update your Windows 10 or Windows

153
00:08:31,320 --> 00:08:38,520
11 machines, you're now going to be able to get that sort of copilot sort of insights,

154
00:08:38,520 --> 00:08:43,620
if you will, into that process where you can if you wanted to go and find out which machines

155
00:08:43,620 --> 00:08:48,520
don't have a specific update applied yet or figure out why there are issues with a specific

156
00:08:48,520 --> 00:08:51,600
update applying to some of your fleet or stuff like that.

157
00:08:51,600 --> 00:08:52,600
Right.

158
00:08:52,600 --> 00:08:53,600
It can be very sort of contextual to you.

159
00:08:53,600 --> 00:08:58,320
So, you know, all in all, I think it's going to be useful for a lot of folks.

160
00:08:58,320 --> 00:09:02,440
I think it's going to take a little bit of getting used to for a lot of people as well.

161
00:09:02,440 --> 00:09:04,520
You know, if you're not used to doing this daily.

162
00:09:04,520 --> 00:09:09,080
But I think as you start seeing this as an easy button, probably going to be be quite

163
00:09:09,080 --> 00:09:10,080
useful.

164
00:09:10,080 --> 00:09:14,480
So maybe we should spend a separate episode on this, Chris.

165
00:09:14,480 --> 00:09:21,480
But does everyone with an M365 copilot license automatically receives these abilities in

166
00:09:21,480 --> 00:09:22,480
their tenants?

167
00:09:22,480 --> 00:09:24,920
You know what, that is a very good question.

168
00:09:24,920 --> 00:09:29,280
You know, you have to have security copilot enabled in your tenant services.

169
00:09:29,280 --> 00:09:31,440
Yeah, that's a separate service.

170
00:09:31,440 --> 00:09:38,040
So for people looking in Microsoft 365 copilot is your copilot for Word, Excel, Teams, Outlook,

171
00:09:38,040 --> 00:09:41,520
all that stuff, even power apps and such.

172
00:09:41,520 --> 00:09:47,600
But for all the security stuff, you have to deploy an Azure resource, in fact, which is

173
00:09:47,600 --> 00:09:50,400
a security copilot, SCU.

174
00:09:50,400 --> 00:09:54,360
That's a security compute unit or something like that.

175
00:09:54,360 --> 00:09:58,920
And you have to pay for that separately, depending on how much you use it, how much you prompt

176
00:09:58,920 --> 00:10:02,040
it, how much you make it to make it to work.

177
00:10:02,040 --> 00:10:06,340
And that's also the element you need for the vendor.

178
00:10:06,340 --> 00:10:11,720
But it's also the same resource that is utilized for the Entra and Intune integrations.

179
00:10:11,720 --> 00:10:12,720
Right.

180
00:10:12,720 --> 00:10:13,720
Yeah.

181
00:10:13,720 --> 00:10:15,320
So that's a good call out, right?

182
00:10:15,320 --> 00:10:20,320
Is it obviously with all of these cool features comes additional licensing in some instances,

183
00:10:20,320 --> 00:10:21,320
right?

184
00:10:21,320 --> 00:10:26,320
And again, we talked about sort of the employee privilege management and the Entune advanced

185
00:10:26,320 --> 00:10:27,480
analytics stuff.

186
00:10:27,480 --> 00:10:33,480
That's all part of Entune Suite, which is not Entune, but it is available as an add-on or

187
00:10:33,480 --> 00:10:36,320
as Entune Suite if you wanted to.

188
00:10:36,320 --> 00:10:37,320
Yeah.

189
00:10:37,320 --> 00:10:41,160
And it might be a bit confusing that Entune has its own portal, the vendor has its own

190
00:10:41,160 --> 00:10:46,960
portal, Entra ID has its own portal, but still the security copilot that's managed in a completely

191
00:10:46,960 --> 00:10:48,560
different portal, the Azure portal.

192
00:10:48,560 --> 00:10:50,760
So that's a good to know.

193
00:10:50,760 --> 00:10:51,760
Yeah.

194
00:10:51,760 --> 00:10:53,240
And I think that's what they're doing here, right?

195
00:10:53,240 --> 00:10:56,600
Is with a lot of these integrations is they're starting to bring some of that stuff from

196
00:10:56,600 --> 00:11:02,500
the security copilot portal, if you will, and just sort of surfacing that into the admin

197
00:11:02,500 --> 00:11:04,520
panels that folks are already using, right?

198
00:11:04,520 --> 00:11:10,760
So because I think one of the challenges here is if you take aside the licensing implications

199
00:11:10,760 --> 00:11:11,760
and the costs, right?

200
00:11:11,760 --> 00:11:14,040
Because sometimes as techies, we don't care about the costs.

201
00:11:14,040 --> 00:11:17,000
Like we're not directly paying them, right?

202
00:11:17,000 --> 00:11:21,320
But what we do care about is having to have six portals open to do one thing.

203
00:11:21,320 --> 00:11:27,280
And so now if they start surfacing some of this sort of goodness, I guess, if you will,

204
00:11:27,280 --> 00:11:32,240
into the portals that we already use, hey, we're so much more likely to start using it

205
00:11:32,240 --> 00:11:34,440
now because we're not jumping to yet another portal.

206
00:11:34,440 --> 00:11:35,440
So yeah, that's true.

207
00:11:35,440 --> 00:11:41,440
And you're actually building a great bridge there, Chris, to my subject of the day.

208
00:11:41,440 --> 00:11:46,440
So I wanted to talk a little bit more about the defender XDR and everything that's new.

209
00:11:46,440 --> 00:11:49,160
Well, a couple of things that are new, at least.

210
00:11:49,160 --> 00:11:50,720
And I think it's funny.

211
00:11:50,720 --> 00:11:55,320
I think most people, especially outside the Microsoft security space, when you think about

212
00:11:55,320 --> 00:12:00,400
the defender, some might still think about the end point only, right?

213
00:12:00,400 --> 00:12:05,560
But XDR, as most people probably know, stands for cross detection and response.

214
00:12:05,560 --> 00:12:11,280
And the defender XDR is actually the whole defense suite with quote unquote, all the

215
00:12:11,280 --> 00:12:12,560
defenders, right?

216
00:12:12,560 --> 00:12:18,920
So the front of the endpoint, the front of Office 365, identity, cloud apps, and try

217
00:12:18,920 --> 00:12:21,000
the identity protection.

218
00:12:21,000 --> 00:12:25,840
Everything is now finally integrated into one portal because not long ago we had several

219
00:12:25,840 --> 00:12:28,560
separate portals for all of those products as well, right?

220
00:12:28,560 --> 00:12:33,480
Defender identity and Azure Security Center, which is still there.

221
00:12:33,480 --> 00:12:38,000
But everything is now at least integrated in a single portal.

222
00:12:38,000 --> 00:12:43,720
And last year, Microsoft already made some effort in unification of all those portals.

223
00:12:43,720 --> 00:12:50,000
And then they actually rebranded it the Unified Security Operations Platform, which is a fancy

224
00:12:50,000 --> 00:12:57,360
name of security.microsoft.com, for which we probably most of us know it.

225
00:12:57,360 --> 00:13:01,840
And last year also Sentinel was added at the same time together with that rename.

226
00:13:01,840 --> 00:13:08,960
So Sentinel, as you know, is an Azure resource, a log analytics workspace living in Azure.

227
00:13:08,960 --> 00:13:14,920
But it's now also integrated in the Unified Security Operations Platform as well.

228
00:13:14,920 --> 00:13:19,200
And I think that's great because now you have one place where you can find all your incidents.

229
00:13:19,200 --> 00:13:24,520
You have one place where you can do that advanced hunting you were mentioning as well, the KQL

230
00:13:24,520 --> 00:13:25,520
stuff.

231
00:13:25,520 --> 00:13:30,480
And now you can look through all the tables from Defender and Sentinel.

232
00:13:30,480 --> 00:13:33,200
But a couple of things were still missing there.

233
00:13:33,200 --> 00:13:37,240
And it was not really an actual Ignite launch.

234
00:13:37,240 --> 00:13:40,880
It was a couple of weeks later, I guess.

235
00:13:40,880 --> 00:13:44,880
But now finally, workbooks are also available there in the Defender portal.

236
00:13:44,880 --> 00:13:51,280
So Azure workbooks is actually an Azure resource, but it's quite relevant to log analytics and

237
00:13:51,280 --> 00:13:53,720
also Sentinel to build dashboards.

238
00:13:53,720 --> 00:14:00,120
And so Microsoft has plenty of templates for you to visualize how many users are using MFA

239
00:14:00,120 --> 00:14:05,720
or how many incidents you got in the last year on a daily basis or a lot of useful stuff

240
00:14:05,720 --> 00:14:07,440
there.

241
00:14:07,440 --> 00:14:11,040
And I think it's great that you don't need to branch back to the Azure portal to see

242
00:14:11,040 --> 00:14:15,200
those dashboards and you now have them in the Defender portal.

243
00:14:15,200 --> 00:14:19,320
Another thing that was announced during Ignite is that now Sentinel will also be available

244
00:14:19,320 --> 00:14:25,920
to customers who do not use Defender XDR, but it will still be available for them in

245
00:14:25,920 --> 00:14:29,320
the Unified Security Operations Platform portal.

246
00:14:29,320 --> 00:14:31,400
And at first I was like, why do you want to do that?

247
00:14:31,400 --> 00:14:36,360
If users are only using Sentinel and had nothing to do with the Defender stuff, why do you

248
00:14:36,360 --> 00:14:40,680
want to force them to use the quote unquote Defender portal to use Sentinel?

249
00:14:40,680 --> 00:14:43,400
Well, the big reason is a copilot.

250
00:14:43,400 --> 00:14:49,200
Obviously, the security copilot experience with all the Sentinel integration is not available

251
00:14:49,200 --> 00:14:50,880
in the Azure portal.

252
00:14:50,880 --> 00:14:52,760
You have to use the Defender portal for that.

253
00:14:52,760 --> 00:14:53,760
So at least it's...

254
00:14:53,760 --> 00:14:59,200
I'm not sure how I feel about this on one hand, and I think it's good that you have

255
00:14:59,200 --> 00:15:02,000
the security copilot integration.

256
00:15:02,000 --> 00:15:05,920
But I think if you're only using Sentinel and are not using any of the other Defender

257
00:15:05,920 --> 00:15:11,920
products, in my opinion, I think you should reevaluate to probably onboard those products

258
00:15:11,920 --> 00:15:15,160
instead of paying for security copilot right away.

259
00:15:15,160 --> 00:15:16,160
Right?

260
00:15:16,160 --> 00:15:21,000
Do you think that part of that as well is to get folks familiar or to give them a little

261
00:15:21,000 --> 00:15:24,440
bit of a taste of what it could look like if they use the other products?

262
00:15:24,440 --> 00:15:27,960
So we give you the portal, but none of that stuff's active for you if you don't have a

263
00:15:27,960 --> 00:15:28,960
license, right?

264
00:15:28,960 --> 00:15:29,960
So you can click on it.

265
00:15:29,960 --> 00:15:30,960
No.

266
00:15:30,960 --> 00:15:32,960
That's why I don't think it's...

267
00:15:32,960 --> 00:15:34,600
How do you say that?

268
00:15:34,600 --> 00:15:38,440
It could be a smart upsell from Microsoft parts, right?

269
00:15:38,440 --> 00:15:41,600
But you don't have the data there when you're not paying for it.

270
00:15:41,600 --> 00:15:43,760
So all the tables are not visible.

271
00:15:43,760 --> 00:15:48,880
You don't have the full kill chain coverage of your detections, right?

272
00:15:48,880 --> 00:15:53,760
You don't have the great investigation graph covering all the different attack parts.

273
00:15:53,760 --> 00:15:55,960
So I'm not really sure.

274
00:15:55,960 --> 00:16:00,760
I think people only using Sentinel should really look into the other Defender stuff

275
00:16:00,760 --> 00:16:01,760
as well.

276
00:16:01,760 --> 00:16:03,780
But yeah, well, at least it's there.

277
00:16:03,780 --> 00:16:07,080
So not much announcement from that.

278
00:16:07,080 --> 00:16:11,520
I also see the role of Sentinel becoming a little bit different.

279
00:16:11,520 --> 00:16:17,200
When I started in Microsoft security almost six years ago, Sentinel just went general

280
00:16:17,200 --> 00:16:18,440
available.

281
00:16:18,440 --> 00:16:22,400
But back then we still had all the different portals from all the different Defender products.

282
00:16:22,400 --> 00:16:28,280
So Sentinel acted as an orchestrator, if you will, between all those different Defender

283
00:16:28,280 --> 00:16:32,240
products, pulling in all the alerts from all the products and visualizing them in a Sentinel

284
00:16:32,240 --> 00:16:33,240
UI.

285
00:16:33,240 --> 00:16:39,040
Now that everything has shifted to the Defender portal, which arguably be a much better UI

286
00:16:39,040 --> 00:16:47,200
and nicer UI, Sentinel is hanging in there probably for your custom logs and getting

287
00:16:47,200 --> 00:16:53,000
some logs in the Defender, like your EntryD signing logs, for example, or perhaps Azure

288
00:16:53,000 --> 00:16:54,240
platform logs.

289
00:16:54,240 --> 00:16:58,840
But the whole UI of Sentinel, I think, will be less and less used over time.

290
00:16:58,840 --> 00:17:02,280
And people are switching to the Defender instead.

291
00:17:02,280 --> 00:17:04,400
Interesting.

292
00:17:04,400 --> 00:17:10,120
So some other newer integrations in the portal are Purview Insider Risk Management that is

293
00:17:10,120 --> 00:17:13,440
now integrated in the incident page in Defender.

294
00:17:13,440 --> 00:17:17,880
And it appears based on all the announcements we saw that this is going to be a big year

295
00:17:17,880 --> 00:17:18,880
for data security.

296
00:17:18,880 --> 00:17:20,760
Don't you agree?

297
00:17:20,760 --> 00:17:24,360
So Purview and data security is a hot topic right now.

298
00:17:24,360 --> 00:17:25,360
I think so.

299
00:17:25,360 --> 00:17:30,160
And I think that it's time that the rubber meets the road when it comes to this stuff,

300
00:17:30,160 --> 00:17:31,160
right?

301
00:17:31,160 --> 00:17:36,360
Because everyone's been saying, when Co-Pilot first came out, it was go use Co-Pilot, go

302
00:17:36,360 --> 00:17:37,420
use Co-Pilot.

303
00:17:37,420 --> 00:17:40,380
And then people sort of said, hang on.

304
00:17:40,380 --> 00:17:45,920
In order for us to use Co-Pilot, we have to have our data estate in order, right?

305
00:17:45,920 --> 00:17:51,000
And so that became the catchphrase of the last 18 months is get your data estate in

306
00:17:51,000 --> 00:17:52,200
order.

307
00:17:52,200 --> 00:17:55,800
But no one really kind of defined what that actually means, because it's a difficult problem

308
00:17:55,800 --> 00:17:56,800
to solve.

309
00:17:56,800 --> 00:17:58,960
When you actually start digging into what does that actually mean?

310
00:17:58,960 --> 00:18:00,240
Yeah, it's hard.

311
00:18:00,240 --> 00:18:02,200
Data security is a difficult problem.

312
00:18:02,200 --> 00:18:03,200
So I agree with you.

313
00:18:03,200 --> 00:18:09,200
I think there's going to be continued focus, because I think it is a barrier to entry.

314
00:18:09,200 --> 00:18:12,280
People are organizations are not going to jump on the Co-Pilot.

315
00:18:12,280 --> 00:18:17,480
Not every organization is going to jump on the Co-Pilot bandwagon until they have these

316
00:18:17,480 --> 00:18:20,880
data bits in their data estate in order, if you will.

317
00:18:20,880 --> 00:18:21,880
Yeah.

318
00:18:21,880 --> 00:18:28,920
And to be honest, I also struggle a bit with the onboarding part for my customers, because

319
00:18:28,920 --> 00:18:31,880
I'm 100% technical, right?

320
00:18:31,880 --> 00:18:35,680
So I like to build scripts and deploy and build stuff.

321
00:18:35,680 --> 00:18:39,720
And when it comes to purview, you also have to embrace a lot of the business aspect of

322
00:18:39,720 --> 00:18:40,720
the product, right?

323
00:18:40,720 --> 00:18:46,480
So you have to go and have some decent discussions about how data is being used and what data

324
00:18:46,480 --> 00:18:47,480
lives where.

325
00:18:47,480 --> 00:18:52,400
And it's a completely different onboarding aspect compared to all the other Defender

326
00:18:52,400 --> 00:18:53,880
products, I would say.

327
00:18:53,880 --> 00:18:54,880
Yeah.

328
00:18:54,880 --> 00:18:55,880
Yeah.

329
00:18:55,880 --> 00:18:58,280
And again, those discussions are difficult because a lot of organizations don't actually

330
00:18:58,280 --> 00:18:59,280
know.

331
00:18:59,280 --> 00:19:07,200
So you get all of the business decision makers in a room or the business owners in a room

332
00:19:07,200 --> 00:19:09,720
and everyone wants to go away and figure it out.

333
00:19:09,720 --> 00:19:12,720
No one can give you the answers straight away, right?

334
00:19:12,720 --> 00:19:13,720
That's quite common.

335
00:19:13,720 --> 00:19:17,400
So it's a very difficult problem to solve, for sure.

336
00:19:17,400 --> 00:19:20,400
Well, Microsoft does help you a little bit with it, but more on that later.

337
00:19:20,400 --> 00:19:24,080
I have another announcement on my list.

338
00:19:24,080 --> 00:19:29,160
But first, I want to touch on, I think, probably the most notable product becoming a general

339
00:19:29,160 --> 00:19:34,400
available during Ignite, and that's Microsoft Security Exposure Management.

340
00:19:34,400 --> 00:19:38,400
And before I explain what it is, I think it's good to understand the different way attackers

341
00:19:38,400 --> 00:19:41,440
and Defenders generally operate.

342
00:19:41,440 --> 00:19:44,560
Have you heard about the name John Lambert, Chris?

343
00:19:44,560 --> 00:19:48,320
I've seen some of his stuff floating about, yes.

344
00:19:48,320 --> 00:19:50,280
But I don't know him personally.

345
00:19:50,280 --> 00:19:51,280
No.

346
00:19:51,280 --> 00:19:54,200
So he's at Microsoft for over 24 years already.

347
00:19:54,200 --> 00:19:59,200
He started in the Windows Security team, and later he led the Microsoft Threat Intelligence

348
00:19:59,200 --> 00:20:01,680
Center known as Mystic.

349
00:20:01,680 --> 00:20:05,560
So he's really a big name when it comes to Microsoft Security, and he has some great

350
00:20:05,560 --> 00:20:06,560
ideas on that.

351
00:20:06,560 --> 00:20:14,900
And he famously quoted once, defenders think in lists and attackers think in graphs.

352
00:20:14,900 --> 00:20:17,640
As long as this is true, attackers win.

353
00:20:17,640 --> 00:20:22,600
And what he was actually saying with that is that defenders are mostly relying on a

354
00:20:22,600 --> 00:20:23,800
lot of lists.

355
00:20:23,800 --> 00:20:26,680
They have Excel sheets of all their resources.

356
00:20:26,680 --> 00:20:31,920
They have content management systems, the CMDBs, all that kind of stuff with lists of

357
00:20:31,920 --> 00:20:34,680
resources they have and they need to maintain.

358
00:20:34,680 --> 00:20:38,000
But attackers don't have any access to those lists.

359
00:20:38,000 --> 00:20:40,320
They just breach your network.

360
00:20:40,320 --> 00:20:43,960
They land somewhere in the graph, as John called it.

361
00:20:43,960 --> 00:20:49,880
And the graph is actually a mesh network, representing your network, your applications,

362
00:20:49,880 --> 00:20:50,940
your identities.

363
00:20:50,940 --> 00:20:56,160
And they just start to hack into the next point in that mesh network and laterally move

364
00:20:56,160 --> 00:21:04,980
and traverse across your networks and come by your crown jewels while they're at it.

365
00:21:04,980 --> 00:21:10,360
So that's why John was emphasizing the fact that you have to think as an attacker as well.

366
00:21:10,360 --> 00:21:15,460
And you also have to make sure that you are aware of those graphs and what your environment

367
00:21:15,460 --> 00:21:16,460
looks like.

368
00:21:16,460 --> 00:21:20,620
And that is actually what Microsoft Security Exposure Management will do for you.

369
00:21:20,620 --> 00:21:24,440
So it will help you understand your attack surface better.

370
00:21:24,440 --> 00:21:26,960
It will help you think like an attacker.

371
00:21:26,960 --> 00:21:32,360
And it will help you also prioritize actions to protect your most critical assets.

372
00:21:32,360 --> 00:21:37,400
And it does this by consolidating a lot of posture data, data from your endpoints, data

373
00:21:37,400 --> 00:21:43,160
from cloud, your identities, but also data, some vulnerabilities that might be there on

374
00:21:43,160 --> 00:21:45,040
your systems.

375
00:21:45,040 --> 00:21:48,920
What's also great is that Microsoft is not only leveraging on their own products in this

376
00:21:48,920 --> 00:21:53,280
case, they're also using embracing third party solutions.

377
00:21:53,280 --> 00:21:59,200
So you can connect ServiceNow, for example, where you might have your CMDB and pull in

378
00:21:59,200 --> 00:22:04,400
that data as well to give you some kind of awareness and to build that graph.

379
00:22:04,400 --> 00:22:08,400
Also Qualus, Rapid7 are supported, Tenable.

380
00:22:08,400 --> 00:22:11,700
And I noticed that Wiz and Palo Alto are coming soon.

381
00:22:11,700 --> 00:22:15,260
So they will integrate that along the way.

382
00:22:15,260 --> 00:22:21,260
And then to present the data to you, it actually consists of three key components.

383
00:22:21,260 --> 00:22:24,160
So they have the attack surface management.

384
00:22:24,160 --> 00:22:26,240
This will visualize that graph.

385
00:22:26,240 --> 00:22:30,200
And this is what gives you the attacker's perspective of your organization.

386
00:22:30,200 --> 00:22:35,560
So you see the nice mesh network with all your applications, identities, endpoint, servers,

387
00:22:35,560 --> 00:22:37,160
and whatnot.

388
00:22:37,160 --> 00:22:40,580
And then the second thing is the attack path analysis.

389
00:22:40,580 --> 00:22:46,680
And this will highlight how attackers could potentially abuse your exposures and security

390
00:22:46,680 --> 00:22:48,080
gaps.

391
00:22:48,080 --> 00:22:52,000
And it will show you how an attacker could potentially traverse their way through your

392
00:22:52,000 --> 00:22:56,160
organization and find your most critical assets.

393
00:22:56,160 --> 00:22:58,520
And then you have the unified exposure insights.

394
00:22:58,520 --> 00:23:01,020
And this will get you some metrics and scores.

395
00:23:01,020 --> 00:23:06,720
And it will score you based on some security initiatives like the cloud endpoint security,

396
00:23:06,720 --> 00:23:08,800
ransomware protection, and zero trust.

397
00:23:08,800 --> 00:23:11,360
So this will help you prioritize a list.

398
00:23:11,360 --> 00:23:17,920
So these are the things I get to start working on right away to close a couple of those traversal

399
00:23:17,920 --> 00:23:20,680
points.

400
00:23:20,680 --> 00:23:25,480
So Microsoft Security Exposure Manager not only went GA, but it also got a couple of

401
00:23:25,480 --> 00:23:28,280
updates during Ignite along the way.

402
00:23:28,280 --> 00:23:32,720
So apparently, DACL support was now added.

403
00:23:32,720 --> 00:23:33,880
I had to look that up.

404
00:23:33,880 --> 00:23:37,920
It was a long time when I was using Windows permissions, Chris.

405
00:23:37,920 --> 00:23:38,920
Yes.

406
00:23:38,920 --> 00:23:39,920
You're aware of those?

407
00:23:39,920 --> 00:23:40,920
I am.

408
00:23:40,920 --> 00:23:41,920
Yes.

409
00:23:41,920 --> 00:23:46,640
I'm in the middle of a project at the moment where I'm doing some work on DACLs and ACLs

410
00:23:46,640 --> 00:23:47,640
and all the rest of it.

411
00:23:47,640 --> 00:23:48,640
Okay.

412
00:23:48,640 --> 00:23:53,200
Well, the DACLs are now also supported and they can pull them into the security exposure

413
00:23:53,200 --> 00:23:54,200
management.

414
00:23:54,200 --> 00:23:56,840
And also hybrid attack paths are now added.

415
00:23:56,840 --> 00:24:02,400
So now Microsoft will try and capture routes that originate from on-premises networks as

416
00:24:02,400 --> 00:24:03,400
well.

417
00:24:03,400 --> 00:24:07,160
And I think this is a really great addition to the Defender Suite.

418
00:24:07,160 --> 00:24:13,440
It will really help customers if they pay attention to it, of course, to pinpoint their

419
00:24:13,440 --> 00:24:18,160
most critical failures, if you will.

420
00:24:18,160 --> 00:24:21,760
This is interesting because this is also Microsoft admitting that not everyone is going to be

421
00:24:21,760 --> 00:24:23,880
cloud native right away.

422
00:24:23,880 --> 00:24:27,840
We've been on this hybrid journey now for a decade and there are some organizations

423
00:24:27,840 --> 00:24:31,040
that are going to continue on being hybrid and using hybrid.

424
00:24:31,040 --> 00:24:36,600
So I like that they are looking at this because the reality is as well is that most of our

425
00:24:36,600 --> 00:24:39,160
cloud infrastructures are secured in some way.

426
00:24:39,160 --> 00:24:45,040
Active Directory, on the other hand, and some of the on-premises stuff is 20-year-old, 24-year-old

427
00:24:45,040 --> 00:24:47,000
attack surface.

428
00:24:47,000 --> 00:24:48,000
It's not as good.

429
00:24:48,000 --> 00:24:50,400
So yeah, good to see that.

430
00:24:50,400 --> 00:24:53,880
I like the attack path analysis stuff.

431
00:24:53,880 --> 00:24:56,560
It reminds me very much of what Bloodhound does.

432
00:24:56,560 --> 00:24:57,560
You know what I mean?

433
00:24:57,560 --> 00:25:02,240
It builds out that graph for you and it shows you what that path to exposure looks like.

434
00:25:02,240 --> 00:25:04,840
So very cool that Microsoft's kind of working on this.

435
00:25:04,840 --> 00:25:10,680
And I also think it's a great place to make customers aware of security gaps in the sense

436
00:25:10,680 --> 00:25:13,720
of vulnerabilities, for example.

437
00:25:13,720 --> 00:25:18,160
Although customers are trying to embrace cloud and all the security products, I still see

438
00:25:18,160 --> 00:25:25,320
in practice a lot of servers running old applications, old plugins.

439
00:25:25,320 --> 00:25:31,960
I even saw the customer lately, Firefox 1.0 installed on most of their endpoints because

440
00:25:31,960 --> 00:25:35,400
some kind of printer driver came with it or something like that.

441
00:25:35,400 --> 00:25:39,120
And those come with obviously a lot of critical vulnerabilities.

442
00:25:39,120 --> 00:25:46,280
And I think this will give you some proper insight in how big the holes are in your security

443
00:25:46,280 --> 00:25:48,080
and what needs to be done first.

444
00:25:48,080 --> 00:25:49,800
Yeah, very good.

445
00:25:49,800 --> 00:25:51,120
I'm glad you brought that one up.

446
00:25:51,120 --> 00:25:57,240
Yeah, well, to close off, I actually cobbled together a lot of other new updates.

447
00:25:57,240 --> 00:25:59,320
But it's obviously the book of Ignite.

448
00:25:59,320 --> 00:26:02,320
The book of news Ignite book of news is actually quite long.

449
00:26:02,320 --> 00:26:07,760
So we couldn't state every single update in here.

450
00:26:07,760 --> 00:26:13,080
But I want to go through some a couple of other updates still.

451
00:26:13,080 --> 00:26:21,560
So apparently, Defender for Office 365 got a new AI powered LLM based detection thingy.

452
00:26:21,560 --> 00:26:24,380
I'm not sure if you've seen that.

453
00:26:24,380 --> 00:26:28,280
This is something you don't need security copilot for security for as far as I could

454
00:26:28,280 --> 00:26:29,280
find.

455
00:26:29,280 --> 00:26:31,240
It's a big in the product.

456
00:26:31,240 --> 00:26:37,120
And Microsoft actually promises well promises not they have seen quite impressive results

457
00:26:37,120 --> 00:26:46,080
up to 99.995% of malicious emails being able to be filtered with this new LLM based.

458
00:26:46,080 --> 00:26:47,600
This is very important.

459
00:26:47,600 --> 00:26:52,040
And I think because honestly, I've been what I've been seeing in the you know, in the last

460
00:26:52,040 --> 00:26:59,000
six months or nine months or so is that defender for Office 365 by itself is not enough anymore.

461
00:26:59,000 --> 00:27:00,000
Right.

462
00:27:00,000 --> 00:27:03,720
I've definitely seen you know, we've gone through this sort of phase where where customers

463
00:27:03,720 --> 00:27:11,000
were using third party mail filtering and and and and EOP defender all of that stuff

464
00:27:11,000 --> 00:27:12,000
was really good.

465
00:27:12,000 --> 00:27:15,980
And we were saying, why don't you reuse this investment that you have in Microsoft technology

466
00:27:15,980 --> 00:27:20,100
and bring that stuff in and get rid of the third party and invest that money elsewhere.

467
00:27:20,100 --> 00:27:22,240
And customers have done that.

468
00:27:22,240 --> 00:27:26,040
But the reality is, is that it's by itself, you know, it was struggling, right?

469
00:27:26,040 --> 00:27:34,360
We've seen other technologies, you know, the the the sort of AI or sort of API integration.

470
00:27:34,360 --> 00:27:35,800
Sublime technology.

471
00:27:35,800 --> 00:27:38,440
Sublime is one of them.

472
00:27:38,440 --> 00:27:43,420
You know, needed to sort of layer on top of what defender was doing.

473
00:27:43,420 --> 00:27:44,960
So I'm really pleased to see this.

474
00:27:44,960 --> 00:27:46,680
And especially if they're seeing really good results.

475
00:27:46,680 --> 00:27:47,680
I think that's great.

476
00:27:47,680 --> 00:27:48,680
Yeah.

477
00:27:48,680 --> 00:27:55,640
And this also had to do apparently with obviously attackers using LLM's AI to generate these

478
00:27:55,640 --> 00:28:04,400
phishing emails as well so that they became much better and they're not in the janky English

479
00:28:04,400 --> 00:28:05,400
format anymore.

480
00:28:05,400 --> 00:28:06,400
So, yeah.

481
00:28:06,400 --> 00:28:07,840
Yeah, I think it's great.

482
00:28:07,840 --> 00:28:13,320
So another thing that got updated is Defender Cloud Security Posture Management.

483
00:28:13,320 --> 00:28:19,100
That's a whole mouthful of words, but it will give you some insights in your cloud security

484
00:28:19,100 --> 00:28:27,280
posture, not only Microsoft, Azure, but also Azure Cloud, sorry, AWS and Google Cloud Platform

485
00:28:27,280 --> 00:28:28,920
as well.

486
00:28:28,920 --> 00:28:33,120
And it got some new additions like API Security Posture.

487
00:28:33,120 --> 00:28:39,180
So it will actually map the APIs from your API management back to the actual servers

488
00:28:39,180 --> 00:28:43,040
and applications and even storage and compute.

489
00:28:43,040 --> 00:28:44,800
So that's great.

490
00:28:44,800 --> 00:28:46,200
Container Security got an update.

491
00:28:46,200 --> 00:28:56,200
So now on all Azure, AWS and Google, it will scan for your container registries when you

492
00:28:56,200 --> 00:28:58,900
build container instances.

493
00:28:58,900 --> 00:29:01,160
And also AI Security Posture was added.

494
00:29:01,160 --> 00:29:06,320
So even if you use your own open AI service or Azure machine learning, but also Amazon

495
00:29:06,320 --> 00:29:14,800
Bedrock, I'm not familiar with that, but apparently that's Amazon's AI Studio solution can be

496
00:29:14,800 --> 00:29:20,880
monitored by the cloud security posture management nowadays.

497
00:29:20,880 --> 00:29:23,960
Microsoft also launched their Zero Day Quest.

498
00:29:23,960 --> 00:29:24,960
Have you seen that, Chris?

499
00:29:24,960 --> 00:29:25,960
No, I haven't actually.

500
00:29:25,960 --> 00:29:26,960
I missed this one.

501
00:29:26,960 --> 00:29:27,960
Okay.

502
00:29:27,960 --> 00:29:35,240
So apparently they created a big pot with $4 million in it and they actually started

503
00:29:35,240 --> 00:29:41,440
right at Ignite and up until the January 19th, which is actually my birthday, by the way,

504
00:29:41,440 --> 00:29:47,360
they have a hacking event and according to Microsoft, it's the largest in its kind.

505
00:29:47,360 --> 00:29:55,820
So you can submit bugs in all kinds of products, not only AI, also Microsoft 365 and Defenders,

506
00:29:55,820 --> 00:30:01,880
and you can earn bug bounties up to, well, the $4 million is not one single bug bounty,

507
00:30:01,880 --> 00:30:04,320
of course, but they have a whole document on it.

508
00:30:04,320 --> 00:30:09,920
So if Red Teamers are listening to this, they should probably definitely check it out.

509
00:30:09,920 --> 00:30:10,920
Wow.

510
00:30:10,920 --> 00:30:12,520
It's like prone to odour on steroids, right?

511
00:30:12,520 --> 00:30:14,120
If it lasts for two months.

512
00:30:14,120 --> 00:30:18,520
And they actually invite the, I believe the top 10 or something, they invite them to Redmond

513
00:30:18,520 --> 00:30:22,480
to come to an actual in-person hacking event as well.

514
00:30:22,480 --> 00:30:26,000
So that's nice.

515
00:30:26,000 --> 00:30:34,520
So Purview will receive an ability, new capabilities to prevent oversharing of sensitive information.

516
00:30:34,520 --> 00:30:39,840
Again, this is a data security thing.

517
00:30:39,840 --> 00:30:45,040
Purview data security posture management is now in preview.

518
00:30:45,040 --> 00:30:48,920
And again, another posture management, but focused on data security.

519
00:30:48,920 --> 00:30:51,760
And this is what I mentioned earlier in the podcast.

520
00:30:51,760 --> 00:30:56,920
This will provide you a visibility across all the Purview data security solutions in

521
00:30:56,920 --> 00:30:57,920
one piece.

522
00:30:57,920 --> 00:31:03,320
And it can tell you if you probably have that G drive somewhere on a file server, which

523
00:31:03,320 --> 00:31:08,360
you probably need to label and migrate elsewhere.

524
00:31:08,360 --> 00:31:14,520
Well, you already touched on a couple of co-pilot things which were new and also co-pilot, obviously

525
00:31:14,520 --> 00:31:15,520
in more products.

526
00:31:15,520 --> 00:31:20,080
You already touched on Entra and Intune and also Purview got its own co-pilot now.

527
00:31:20,080 --> 00:31:24,600
Lastly, I want to touch on a couple of things from security co-pilot perspective for the

528
00:31:24,600 --> 00:31:25,600
defenders.

529
00:31:25,600 --> 00:31:30,320
I think it's really nice that when you have a security incident in the defender and some

530
00:31:30,320 --> 00:31:35,720
kind of script was involved in there, that co-pilot will automatically detail for you

531
00:31:35,720 --> 00:31:40,920
to the security analyst what the script is actually trying to do.

532
00:31:40,920 --> 00:31:45,520
And so if it's PowerShell or Python or whatever, it will actually explain to you what it tries

533
00:31:45,520 --> 00:31:47,920
to do.

534
00:31:47,920 --> 00:31:54,000
Incident reports will now also compile all of these response activities in a detailed

535
00:31:54,000 --> 00:31:55,360
report for you.

536
00:31:55,360 --> 00:31:58,460
And it also comes with integration service now.

537
00:31:58,460 --> 00:32:02,760
So it can write back the report to service now, if you will.

538
00:32:02,760 --> 00:32:06,040
And also there's a way to use a guided response.

539
00:32:06,040 --> 00:32:13,200
So security analysts have to communicate with end users sometime and the guided response

540
00:32:13,200 --> 00:32:19,080
will help them communicate more easily by dynamically generating some text for them

541
00:32:19,080 --> 00:32:21,040
they can send out to the user, for example.

542
00:32:21,040 --> 00:32:23,280
I don't have any experience with it yet.

543
00:32:23,280 --> 00:32:29,320
These are all new, but I saw some demos on it and could be useful.

544
00:32:29,320 --> 00:32:35,080
When it comes to security co-pilot, I do have a little bit of mixed feeling still, and that

545
00:32:35,080 --> 00:32:37,440
mostly comes down to the pricing.

546
00:32:37,440 --> 00:32:43,000
Well, you mentioned that you don't have much experience with it yet, but I've seen a lot

547
00:32:43,000 --> 00:32:48,360
of very expensive SEOs being deployed.

548
00:32:48,360 --> 00:32:53,440
And even when companies started to use it, it's difficult to know beforehand how much

549
00:32:53,440 --> 00:32:58,200
compute units you will be using, needing actually.

550
00:32:58,200 --> 00:33:02,160
If it has some documentation on that, they will probably advise you to start with a certain

551
00:33:02,160 --> 00:33:05,120
number and you can scale up and down, of course.

552
00:33:05,120 --> 00:33:11,000
But the amount of prompts and the amount of compute that go through it, especially because

553
00:33:11,000 --> 00:33:16,200
it's so integrated so much now, the compute units are all the time working for you, even

554
00:33:16,200 --> 00:33:17,200
if you don't know it.

555
00:33:17,200 --> 00:33:19,240
If you open up a pane, there comes a summary.

556
00:33:19,240 --> 00:33:23,320
When you open up an incident, another summary pops up and there are all prompts, of course,

557
00:33:23,320 --> 00:33:25,680
being computed for you.

558
00:33:25,680 --> 00:33:30,400
And I see customers really struggling with the cost perspective of it.

559
00:33:30,400 --> 00:33:35,480
I think it's an important call out, because I think we all get caught up in the demos

560
00:33:35,480 --> 00:33:43,320
of the stuff where it's seamless and the person demoing this is writing this prompt out and

561
00:33:43,320 --> 00:33:46,240
he's right clicking on this thing and he's asking for more information there.

562
00:33:46,240 --> 00:33:51,920
And like you said, the backend work on all of these prompts is enormous.

563
00:33:51,920 --> 00:33:57,120
And there's a lot going on, especially as we start seeing the security copilot stuff

564
00:33:57,120 --> 00:34:00,720
get integrated into the admin centers that we already use.

565
00:34:00,720 --> 00:34:05,640
It's very easy to get carried away and just go crazy with this without actually understanding

566
00:34:05,640 --> 00:34:08,800
the cost implications under the covers.

567
00:34:08,800 --> 00:34:14,040
And like I said, I mentioned earlier, as techies, we don't always consider the cost of this.

568
00:34:14,040 --> 00:34:17,080
We look at the benefit and we go, this is fantastic, but hey, someone's got to pay the

569
00:34:17,080 --> 00:34:18,080
bill for this.

570
00:34:18,080 --> 00:34:22,920
So I think it's an important call out that, I think two things.

571
00:34:22,920 --> 00:34:27,800
One, you really have to understand what you're getting into, or at least try and best understand

572
00:34:27,800 --> 00:34:30,240
what you're getting into when you jump into the stuff.

573
00:34:30,240 --> 00:34:34,360
But two, you can't go from zero to hero with this.

574
00:34:34,360 --> 00:34:39,160
You can't have an organization where you're struggling with basic security concepts and

575
00:34:39,160 --> 00:34:45,800
then jump into a AI assisted security workflow where all your folks are all of a sudden now

576
00:34:45,800 --> 00:34:47,360
have the magic of AI.

577
00:34:47,360 --> 00:34:50,400
But there has to be a maturity that comes with it, right?

578
00:34:50,400 --> 00:34:52,360
And that takes time and it is a journey.

579
00:34:52,360 --> 00:34:53,800
And I think that's important.

580
00:34:53,800 --> 00:34:58,240
I do want to advise people listening, wanting to try out security copilot, what is actually

581
00:34:58,240 --> 00:35:03,800
great since it's an Azure resource, you can deploy it and remove it right after you don't

582
00:35:03,800 --> 00:35:05,380
use it anymore.

583
00:35:05,380 --> 00:35:10,360
So there are a couple of examples online of pipeline deployments, automated deployments

584
00:35:10,360 --> 00:35:15,160
where you could deploy, for example, a couple of SCUs to try them out and automatically

585
00:35:15,160 --> 00:35:17,000
remove them at the end of your working day.

586
00:35:17,000 --> 00:35:20,600
And at least you're not paying for it 24 seven, right?

587
00:35:20,600 --> 00:35:25,720
Or just deploy it and remove it by hand after you finished tinkering with it.

588
00:35:25,720 --> 00:35:29,360
At least then you can get a feel of what it can give you.

589
00:35:29,360 --> 00:35:31,440
I think that's a really good call out.

590
00:35:31,440 --> 00:35:33,520
Really good.

591
00:35:33,520 --> 00:35:39,800
So lastly, I think we want to touch on a community project of this episode, right?

592
00:35:39,800 --> 00:35:45,020
We always like to highlight something else in the community, which is worth mentioning.

593
00:35:45,020 --> 00:35:49,920
And since I was already touching on workbooks a little bit earlier, the first thing that

594
00:35:49,920 --> 00:35:55,160
came to my mind was the Entra ID security config analyzer.

595
00:35:55,160 --> 00:36:00,760
And this was actually made by three guys, Sami, Thomas and Marcus.

596
00:36:00,760 --> 00:36:07,000
Sami and Marcus are from Finland and Thomas is operating out of Germany.

597
00:36:07,000 --> 00:36:09,400
I'm following Sami for a long time already.

598
00:36:09,400 --> 00:36:16,040
He's a security MVP as well and he's bringing some great contributions to the community.

599
00:36:16,040 --> 00:36:20,600
And those three guys have created the Entra ID security config analyzer, which is a project

600
00:36:20,600 --> 00:36:25,560
with a lot of stuff, a lot of to set up the best practices.

601
00:36:25,560 --> 00:36:30,600
But one of which is a workbook, actually, which you can deploy and it will give you

602
00:36:30,600 --> 00:36:36,760
insights and it will evaluate your Entra ID tenant settings with several best practices.

603
00:36:36,760 --> 00:36:39,960
Think about things like MFA and the things we touched on earlier.

604
00:36:39,960 --> 00:36:46,800
But yeah, I think it's a great starting point to get into optimizing your Entra ID settings

605
00:36:46,800 --> 00:36:48,360
to get them more secure.

606
00:36:48,360 --> 00:36:49,360
Awesome.

607
00:36:49,360 --> 00:36:53,120
Yeah, I think I have not seen this before and I think this is really, really useful.

608
00:36:53,120 --> 00:36:58,120
So I'm definitely going to be having a little bit of a play around with this this week.

609
00:36:58,120 --> 00:36:59,120
See what I can do.

610
00:36:59,120 --> 00:37:01,760
We'll make sure that the links end up in the show notes, of course.

611
00:37:01,760 --> 00:37:02,760
Fantastic.

612
00:37:02,760 --> 00:37:03,760
Thanks for bringing that up, Post.

613
00:37:03,760 --> 00:37:05,280
That's really, really, really helpful.

614
00:37:05,280 --> 00:37:09,720
Well, that's a lot there, right?

615
00:37:09,720 --> 00:37:16,160
Even though you think that there wasn't all that much in security space at Ignite.

616
00:37:16,160 --> 00:37:18,480
We've really just scratched the surface.

617
00:37:18,480 --> 00:37:23,080
We will put a link to the Ignite book of news.

618
00:37:23,080 --> 00:37:27,440
That book of news has also just grown a lot over the years, hasn't it?

619
00:37:27,440 --> 00:37:31,720
I remember when it was just a PDF and you could download it as a PDF and you could see

620
00:37:31,720 --> 00:37:33,960
through it in a few minutes.

621
00:37:33,960 --> 00:37:38,920
Now it's a whole sort of encompassing book of news for Ignite.

622
00:37:38,920 --> 00:37:39,920
So it's fantastic.

623
00:37:39,920 --> 00:37:44,840
And also, each section will link to blog posts about the announcement.

624
00:37:44,840 --> 00:37:48,680
It'll link to relevant sessions for the announcements.

625
00:37:48,680 --> 00:37:53,640
You go and actually follow up on videos and recordings, on-demand recordings of those

626
00:37:53,640 --> 00:37:55,440
announcements and things.

627
00:37:55,440 --> 00:37:56,440
It's really worth looking at.

628
00:37:56,440 --> 00:38:01,000
If you weren't at Ignite, obviously, but even if you were at Ignite, it's a great way to

629
00:38:01,000 --> 00:38:05,280
refresh or see some of the things that you maybe missed out on because you were in other

630
00:38:05,280 --> 00:38:06,280
sessions right there.

631
00:38:06,280 --> 00:38:09,760
Yeah, another fun fact I want to touch on, Chris.

632
00:38:09,760 --> 00:38:14,080
So Microsoft yearly releases the digital defense report.

633
00:38:14,080 --> 00:38:17,720
It came out at the end of October, again this year.

634
00:38:17,720 --> 00:38:24,640
One of the facts I noticed there that Microsoft has now 34,000 security engineers working

635
00:38:24,640 --> 00:38:28,400
in the company to build and work on these security products.

636
00:38:28,400 --> 00:38:34,800
So if you think they're slowing down on developing security products, you're wrong.

637
00:38:34,800 --> 00:38:36,120
Yeah, no, I agree.

638
00:38:36,120 --> 00:38:40,520
I've said for a long time, I think Microsoft is the biggest security vendor in the world.

639
00:38:40,520 --> 00:38:43,040
I just don't think everyone wants to acknowledge that.

640
00:38:43,040 --> 00:38:46,840
But I really do think it's true given the investment that they're putting into this.

641
00:38:46,840 --> 00:38:47,840
Yeah, certainly.

642
00:38:47,840 --> 00:38:48,840
Absolutely.

643
00:38:48,840 --> 00:38:49,840
Okay.

644
00:38:49,840 --> 00:38:50,840
All right, folks.

645
00:38:50,840 --> 00:38:53,120
Well, thank you for joining us for another episode.

646
00:38:53,120 --> 00:38:57,040
As always, please feel free to reach out to us on the socials if you have any burning

647
00:38:57,040 --> 00:39:00,040
questions or if you'd just like to get in touch.

648
00:39:00,040 --> 00:39:01,440
We really do put this together for you.

649
00:39:01,440 --> 00:39:04,600
So we appreciate you following us on this journey.

650
00:39:04,600 --> 00:39:10,080
And I'm sure you will see us or hear from us again soon with another episode.

651
00:39:10,080 --> 00:39:11,240
In the next year, I guess.

652
00:39:11,240 --> 00:39:13,440
So happy holidays, everybody.

653
00:39:13,440 --> 00:39:14,440
That's right.

654
00:39:14,440 --> 00:39:15,440
Happy holidays.

655
00:39:15,440 --> 00:39:17,960
I'm not sure when exactly this one will be published, but it'll be around just after

656
00:39:17,960 --> 00:39:18,960
Christmas time.

657
00:39:18,960 --> 00:39:24,960
So for those of you, I hope you enjoy your time with family and downtime.

658
00:39:24,960 --> 00:39:28,160
I think downtime is very important for the mental health.

659
00:39:28,160 --> 00:39:30,320
So take care about that.

660
00:39:30,320 --> 00:39:31,320
Take care.

661
00:39:31,320 --> 00:39:33,320
And yeah, great to see you again, as always.

662
00:39:33,320 --> 00:39:34,760
Thank you for joining me.

663
00:39:34,760 --> 00:39:35,760
And we'll talk to you all.

664
00:39:35,760 --> 00:39:36,760
We'll see you all again later.

665
00:39:36,760 --> 00:39:37,760
Nice holidays, Chris.

666
00:39:37,760 --> 00:39:38,760
See you later.

667
00:39:38,760 --> 00:39:39,760
Bye bye.

668
00:39:39,760 --> 00:39:54,760
Bye bye.

