WEBVTT

00:00:10.059 --> 00:00:12.679
Hello, and welcome to another episode of the

00:00:12.679 --> 00:00:15.539
Everyday Defender podcast. This time, real life.

00:00:16.300 --> 00:00:18.780
We're very, very excited. Coach and I got together

00:00:18.780 --> 00:00:22.600
and we're here from an undisclosed location somewhere

00:00:22.600 --> 00:00:26.640
on the Microsoft campus in Redmond, Washington.

00:00:26.800 --> 00:00:28.760
We're really excited to be recording today from

00:00:28.760 --> 00:00:34.240
the MVP Summit 2025. Maybe a little less technical

00:00:34.240 --> 00:00:36.719
episode today, but you know, we wanted to talk

00:00:36.719 --> 00:00:39.020
a little bit about summit We are reminded every

00:00:39.020 --> 00:00:41.479
five minutes do not take pictures do not share

00:00:41.479 --> 00:00:44.420
any of the content So that's why we should keep

00:00:44.420 --> 00:00:48.640
the location That's what that's right. So so

00:00:48.640 --> 00:00:51.960
yeah, just really sort of wanted to Talk a little

00:00:51.960 --> 00:00:54.640
bit about some of the insights I guess from from

00:00:54.640 --> 00:00:56.500
summit and a little bit about the experience,

00:00:56.859 --> 00:00:59.530
right? It is something I think We both probably

00:00:59.530 --> 00:01:02.329
would agree that it's not something that we take

00:01:02.329 --> 00:01:05.510
for granted. The ability and the fact that we

00:01:05.510 --> 00:01:07.650
get to come here every year and kind of meet

00:01:07.650 --> 00:01:09.530
the product groups and meet all of our peers

00:01:09.530 --> 00:01:12.329
from all around the world. It's amazing. Normally

00:01:12.329 --> 00:01:16.150
when we do these recordings, it's nighttime for

00:01:16.150 --> 00:01:18.469
Kos and it's morning time for me in Sydney or

00:01:18.469 --> 00:01:21.670
the other way around. I'm finishing my day and

00:01:21.670 --> 00:01:25.030
Kos is just having his first coffee. So it's

00:01:25.030 --> 00:01:27.510
great for us to be able to hang out and actually...

00:01:28.040 --> 00:01:31.280
be in person. Also much easier on the editing

00:01:31.280 --> 00:01:33.640
this time. Well we hope so. So the audio video

00:01:33.640 --> 00:01:35.799
is automatically in sync I hope this time. That's

00:01:35.799 --> 00:01:37.519
right. So we're trying something new with some

00:01:37.519 --> 00:01:41.480
different camera gear today and you know we'll

00:01:41.480 --> 00:01:43.640
see how it turns out I guess. It's fun nonetheless.

00:01:44.359 --> 00:01:46.400
So great to be here and great to see you in person

00:01:46.400 --> 00:01:49.819
again. Always good. And well to record here on

00:01:49.819 --> 00:01:52.799
Summit so if people are hearing some noises in

00:01:52.799 --> 00:01:55.140
the background those are actually people walking

00:01:55.140 --> 00:01:57.159
around working here printing some t -shirts.

00:01:57.260 --> 00:02:00.719
here in the back for the MVPs coming to pick

00:02:00.719 --> 00:02:04.939
up some swag. So very much the disclaimer, we

00:02:04.939 --> 00:02:07.299
are in a live environment with people walking

00:02:07.299 --> 00:02:09.500
around and hopefully we don't see vacuum cleaners

00:02:09.500 --> 00:02:12.500
or anything. Or a security guard removing us

00:02:12.500 --> 00:02:16.379
from the premises, right? That's right. So tell

00:02:16.379 --> 00:02:19.659
me, how's your week been? Today is Wednesday,

00:02:19.699 --> 00:02:22.840
we're recording this on a Wednesday. We've been

00:02:22.840 --> 00:02:25.020
here since Monday, or at least on campus since

00:02:25.020 --> 00:02:27.370
Monday. What's your week been? How's it been

00:02:27.370 --> 00:02:29.270
going for you? Yeah, great actually. So Summit

00:02:29.270 --> 00:02:31.590
started on Tuesday officially with a keynote

00:02:31.590 --> 00:02:35.030
from Jeff Teeper. But we had a pre -day. Well,

00:02:35.110 --> 00:02:37.110
I think everybody had a pre -day. Most of the

00:02:37.110 --> 00:02:40.069
tracks. Yeah. So I'm a Microsoft Security MVP.

00:02:40.490 --> 00:02:42.550
I'm in the security track and we had a pre -day

00:02:42.550 --> 00:02:46.150
on Monday as well where we had some initial sessions

00:02:46.150 --> 00:02:49.069
on some upcoming stuff, some roadmap stuff. And

00:02:49.069 --> 00:02:51.370
what's also cool is that we were handed out logins

00:02:51.370 --> 00:02:54.729
to a Capture the Flag assignment. So it's a little

00:02:54.729 --> 00:02:56.719
bit of a challenge. within the MVP community

00:02:56.719 --> 00:02:59.539
right now, who has the highest score, who is

00:02:59.539 --> 00:03:01.840
able to finish in time. I'd be willing to bet

00:03:01.840 --> 00:03:03.819
that the person who wins Capture the Flag is

00:03:03.819 --> 00:03:07.370
Dutch. That is, well, statistically, you're good

00:03:07.370 --> 00:03:09.650
there, right? That's right. Chris was already

00:03:09.650 --> 00:03:12.009
joking that if you want to become a security

00:03:12.009 --> 00:03:14.129
MVP, you have to learn Dutch, right? It's like

00:03:14.129 --> 00:03:16.229
you're in Holland when you're in the room. That's

00:03:16.229 --> 00:03:18.349
right. A lot of Dutchies over there. Yeah, that's

00:03:18.349 --> 00:03:20.449
true. Yeah, so the Capture the Flag is also a

00:03:20.449 --> 00:03:22.930
really nice initiative, not only from a gamification

00:03:22.930 --> 00:03:25.930
perspective, but I think it showcases really

00:03:25.930 --> 00:03:29.550
well what especially the XDR platform is capable

00:03:29.550 --> 00:03:33.050
of nowadays. So they spun up an environment,

00:03:33.210 --> 00:03:35.699
a tenant, where they apparently... took some

00:03:35.699 --> 00:03:39.479
red teamers and go wild on some machines with

00:03:39.479 --> 00:03:41.520
some malware and all kinds of malicious stuff

00:03:41.520 --> 00:03:45.240
and it's it's great to see in graphical visualization

00:03:45.240 --> 00:03:49.500
the entire attack how it took place how devices

00:03:49.500 --> 00:03:52.479
were confiscated how persistence was gained and

00:03:52.479 --> 00:03:55.740
how data was compromised but it was hard to be

00:03:55.740 --> 00:03:59.840
honest it's tough I thought I was well informed

00:03:59.840 --> 00:04:02.639
on the products but another security analyst

00:04:02.639 --> 00:04:05.639
that's clear it's tough right I am I find it

00:04:05.639 --> 00:04:07.740
super fascinating. I've been diving into that

00:04:07.740 --> 00:04:10.199
environment whenever I've had a few minutes all

00:04:10.199 --> 00:04:13.599
week. And it's one thing when you have those

00:04:13.599 --> 00:04:15.860
products, when you have everything deployed in

00:04:15.860 --> 00:04:17.819
a working environment and things are working,

00:04:18.079 --> 00:04:21.420
you're not under attack, right? There's no compromise.

00:04:21.800 --> 00:04:24.199
It's completely a different situation when you

00:04:24.199 --> 00:04:27.189
see what... you know the capability of all of

00:04:27.189 --> 00:04:29.930
these tools when you're in that mode of trying

00:04:29.930 --> 00:04:32.350
to do an investigation and looking at an incident

00:04:32.350 --> 00:04:34.829
um and trying to you know follow the bouncy ball

00:04:34.829 --> 00:04:39.269
um you know for me that was a very um very interesting

00:04:39.269 --> 00:04:43.310
uh sort of uh aspect of it yeah i've really enjoyed

00:04:43.310 --> 00:04:45.009
it and i'm not gonna lie it's been very difficult

00:04:45.009 --> 00:04:47.589
yeah and to be honest i i also gained a lot more

00:04:47.589 --> 00:04:50.009
respect than i already had for my colleagues

00:04:50.009 --> 00:04:53.430
uh uh i have working in the sock yeah because

00:04:53.430 --> 00:04:57.060
when you see when you when You get answers as

00:04:57.060 --> 00:04:59.959
part of the capture the flag rights, name the

00:04:59.959 --> 00:05:02.839
file which was dropped on the confiscated machine,

00:05:03.019 --> 00:05:05.319
stuff like that. But obviously, that machine

00:05:05.319 --> 00:05:09.220
is gaining so much. It has so much sensors. There's

00:05:09.220 --> 00:05:10.899
so much going on in the machine. A lot of the

00:05:10.899 --> 00:05:13.620
stuff isn't malicious. It's just Windows installing

00:05:13.620 --> 00:05:15.839
an update or starting a service or whatever.

00:05:16.060 --> 00:05:18.279
And you have to sift through all of the events

00:05:18.279 --> 00:05:20.879
in the timeline to see, okay, so this is something.

00:05:21.399 --> 00:05:23.579
that i need to figure out and then copy paste

00:05:23.579 --> 00:05:25.920
a file name or something like that and and paste

00:05:25.920 --> 00:05:27.720
it so you really have to recognize what's malicious

00:05:27.720 --> 00:05:30.019
and what's not yeah it's just it's a trick skill

00:05:30.019 --> 00:05:32.920
right and i agree with you um you know to those

00:05:32.920 --> 00:05:34.860
folks listening to this who kind of work in that

00:05:34.860 --> 00:05:36.939
sort of sock space right as an analyst i really

00:05:36.939 --> 00:05:39.420
i really do commend that that uh you know that

00:05:39.420 --> 00:05:41.600
skill set it's very different to you know what

00:05:41.600 --> 00:05:43.459
i do as a consultant where really i'm helping

00:05:43.459 --> 00:05:45.680
customers you know deploy this stuff and make

00:05:45.680 --> 00:05:47.240
sure they make the right decisions around the

00:05:47.240 --> 00:05:49.360
logging and the capabilities and the things that

00:05:49.360 --> 00:05:51.300
they're they're implementing But yeah, when the

00:05:51.300 --> 00:05:54.980
rubber meets the road, it's hard and it's tough.

00:05:55.300 --> 00:05:57.160
So that's been really interesting, been a really

00:05:57.160 --> 00:05:59.600
interesting part. Yeah, it was a fun diversion,

00:05:59.920 --> 00:06:04.319
so to speak, but also informative. And yeah,

00:06:04.420 --> 00:06:06.000
something I learned a lot from. And especially

00:06:06.000 --> 00:06:09.120
also when you cannot answer the questions, there's

00:06:09.120 --> 00:06:11.379
an explanation video of how you could have found

00:06:11.379 --> 00:06:14.019
the evidence, which is really useful for me as

00:06:14.019 --> 00:06:15.019
well. They've put a lot of effort into that.

00:06:15.060 --> 00:06:18.060
And I really appreciate the various groups that

00:06:18.060 --> 00:06:20.290
were involved in that from Microsoft. the effort

00:06:20.290 --> 00:06:22.670
into that i have to contact some people to see

00:06:22.670 --> 00:06:24.689
if we can get a copy of it or something because

00:06:24.689 --> 00:06:27.149
i think my colleagues and everybody wants to

00:06:27.149 --> 00:06:28.670
learn can really enjoy you know i think it would

00:06:28.670 --> 00:06:30.350
be a really great community project actually

00:06:30.350 --> 00:06:32.889
to be able to get something like that um you

00:06:32.889 --> 00:06:35.389
know we already have the concept of canary tenants

00:06:35.389 --> 00:06:38.569
and demo tenants and things like that right it'd

00:06:38.569 --> 00:06:40.569
be a really good good way and that might be some

00:06:40.569 --> 00:06:43.050
good feedback for for the team is you know how

00:06:43.050 --> 00:06:45.290
do we make this available in a more sort of permanent

00:06:45.290 --> 00:06:48.730
way for for folks to to kind of get uh get a

00:06:48.730 --> 00:06:50.670
feel for it right because i can see many scenarios

00:06:50.670 --> 00:06:53.589
not only folks um that work in the industry wanting

00:06:53.589 --> 00:06:55.269
to gain some more knowledge and understanding

00:06:55.269 --> 00:06:58.189
but also think about um graduates and you know

00:06:58.189 --> 00:07:00.689
folks coming into the industry right this could

00:07:00.689 --> 00:07:02.209
be a really good way for them to kind of get

00:07:02.209 --> 00:07:05.029
to get some exposure so uh very cool not sure

00:07:05.029 --> 00:07:07.629
i cannot promise our listeners anything but we'll

00:07:07.629 --> 00:07:11.129
look into the options yes definitely so um to

00:07:11.129 --> 00:07:13.329
go straight to an official announcement also

00:07:13.329 --> 00:07:16.850
took place yesterday i believe so uh this is

00:07:16.850 --> 00:07:18.959
not nda so that's why we can talk about it so

00:07:18.959 --> 00:07:21.100
Microsoft announced security co -pilot agents

00:07:21.100 --> 00:07:26.180
so security co -pilot is also already there it's

00:07:26.180 --> 00:07:28.779
around for a while and now it got extended with

00:07:28.779 --> 00:07:31.939
agents similar to what the regular co -pilot

00:07:31.939 --> 00:07:35.259
got a while ago and I think this is really a

00:07:35.259 --> 00:07:39.199
big and important change inside the security

00:07:39.199 --> 00:07:41.680
co -pilot yeah and I think it's in line with

00:07:41.680 --> 00:07:43.579
what we've been seeing right we've been seeing

00:07:43.579 --> 00:07:50.060
co -pilot be more sort of tightly sort of integrated

00:07:50.060 --> 00:07:52.040
into all of the services, right? And I think

00:07:52.040 --> 00:07:53.939
we talked about this in one of our previous episodes

00:07:53.939 --> 00:07:56.600
where Copilot was providing more insights into

00:07:56.600 --> 00:07:59.399
the conditional access portal and the engine

00:07:59.399 --> 00:08:02.480
portal where you can get some more natural language

00:08:02.480 --> 00:08:04.879
type information about your policies, right?

00:08:05.339 --> 00:08:08.800
And of course, agent and agentic seems to be

00:08:08.800 --> 00:08:12.120
the buzzword. Yeah, agentic AI. That's it. That's

00:08:12.120 --> 00:08:15.519
the word for 2025. It is. So I'm not surprised

00:08:15.519 --> 00:08:18.660
that we're seeing sort of agents being integrated

00:08:18.660 --> 00:08:21.759
into security copilot as well. And I think what

00:08:21.759 --> 00:08:23.720
makes this really interesting for me, right,

00:08:23.819 --> 00:08:27.959
is, you know, You have done work in the space

00:08:27.959 --> 00:08:32.899
of using some of the older mechanisms and power

00:08:32.899 --> 00:08:35.799
automate and things like that, where you've taken

00:08:35.799 --> 00:08:38.980
security alerts and enriched them, for example,

00:08:39.000 --> 00:08:42.039
where maybe a malicious file has been found in

00:08:42.039 --> 00:08:44.500
the environment, and you've built some power

00:08:44.500 --> 00:08:47.980
automate flows. There's a logic app, technically,

00:08:48.159 --> 00:08:50.480
but I'll give you the nomenclature. Fair enough.

00:08:50.919 --> 00:08:53.879
That takes that and pushes it to VirusTotal and

00:08:53.879 --> 00:08:55.639
does some information there. and enriches the

00:08:55.639 --> 00:09:00.080
alerts. So to me, this is sort of that next evolution

00:09:00.080 --> 00:09:02.200
of that type of automation, isn't it? Yeah, true.

00:09:02.200 --> 00:09:04.580
Yeah, I was always, to be honest, a bit critical

00:09:04.580 --> 00:09:08.039
on security co -pilot from the get -go, summarizing

00:09:08.039 --> 00:09:11.500
incidents, well, descriptions or something like

00:09:11.500 --> 00:09:15.799
that, has not perhaps that much added value against

00:09:15.799 --> 00:09:18.539
what it's also costing you. You're right. And

00:09:18.539 --> 00:09:21.820
with agents, like you said, you can create agents

00:09:21.820 --> 00:09:27.220
beforehand. to examine phishing triage or do

00:09:27.220 --> 00:09:29.720
some vulnerability remediation. Those are a couple

00:09:29.720 --> 00:09:32.179
of examples which Security Co -Pilot now comes

00:09:32.179 --> 00:09:34.919
out of the box with. And a lot of partners are

00:09:34.919 --> 00:09:36.879
also already contributing and creating their

00:09:36.879 --> 00:09:39.340
own agents. And with an agent, you just have

00:09:39.340 --> 00:09:42.220
a separate AI, sort of a containerized AI, if

00:09:42.220 --> 00:09:44.600
you will, and you tell them specific instructions

00:09:44.600 --> 00:09:47.620
like, okay, you will be asked information to

00:09:47.620 --> 00:09:50.419
triage a phishing alert, for example, and it

00:09:50.419 --> 00:09:53.019
knows where to find all kinds of data and you

00:09:53.019 --> 00:09:55.799
don't have to bring all the logic into it. That

00:09:55.799 --> 00:09:57.860
was the big problem with the Logic Apps. Well,

00:09:57.879 --> 00:10:00.539
was, is the big problem. You have to put a lot

00:10:00.539 --> 00:10:02.860
of effort in it. So you really have to go through

00:10:02.860 --> 00:10:06.240
the whole if this, then that scenario. And when

00:10:06.240 --> 00:10:10.299
an alert enters the Logic App and it misses some

00:10:10.299 --> 00:10:14.740
entities, like for phishing an email or an IP

00:10:14.740 --> 00:10:18.120
address, it breaks or fails. So you have to create

00:10:18.120 --> 00:10:20.700
some error handling inside the Logic App. And

00:10:20.700 --> 00:10:22.690
now with the agents, you can just hand them It's

00:10:22.690 --> 00:10:25.919
tough and it will go to work for you. while you're

00:10:25.919 --> 00:10:28.179
not noticing it and it will bring you back the

00:10:28.179 --> 00:10:30.139
information afterwards yeah i think that's gonna

00:10:30.139 --> 00:10:32.100
that's gonna add a lot of value to some of these

00:10:32.100 --> 00:10:34.320
these um sort of operational workflows right

00:10:34.320 --> 00:10:37.419
that folks are doing so um interested to see

00:10:37.419 --> 00:10:40.360
again i you know um it's still very new but i

00:10:40.360 --> 00:10:42.019
think as as we start seeing it it's great to

00:10:42.019 --> 00:10:43.340
see the partners are already starting to help

00:10:43.340 --> 00:10:45.940
with this right yeah and and again i will i was

00:10:45.940 --> 00:10:49.200
very critical on it uh uh at start not agents

00:10:49.200 --> 00:10:51.679
but critical part in general and i really think

00:10:51.679 --> 00:10:54.659
this is the is a big driving factor to to revisit

00:10:54.759 --> 00:10:57.259
visit the product, enable it again, because they

00:10:57.259 --> 00:10:59.519
also have some dashboards which give you insight

00:10:59.519 --> 00:11:03.779
in how much time each specific agent saved you

00:11:03.779 --> 00:11:06.980
gathering the information yourself. So this is

00:11:06.980 --> 00:11:09.460
also really good to get some business decisions

00:11:09.460 --> 00:11:13.059
done, right? To start after a trial period or

00:11:13.059 --> 00:11:15.000
something like that, if you want to continue

00:11:15.000 --> 00:11:17.779
and keep, if the savings are higher than the

00:11:17.779 --> 00:11:20.360
costs. That's a good deal, right? I mean, look,

00:11:20.440 --> 00:11:22.960
I think that's a very real problem for a lot

00:11:22.960 --> 00:11:24.679
of organizations when it comes to AI, right,

00:11:24.759 --> 00:11:29.919
is how do we demonstrate or prove the value of

00:11:29.919 --> 00:11:31.919
what we're paying for? Yeah, measure the value,

00:11:32.039 --> 00:11:33.840
quantify the value of what we're paying for,

00:11:33.899 --> 00:11:36.159
right? It's one thing when you're a developer

00:11:36.159 --> 00:11:40.080
and you use GitHub Copilot and you can very easily

00:11:40.080 --> 00:11:43.419
say GitHub Copilot has saved me four hours a

00:11:43.419 --> 00:11:45.580
day, right, because there's math there and it's

00:11:45.580 --> 00:11:47.419
easy to do, but I think it becomes a lot harder

00:11:47.419 --> 00:11:50.370
for... an information worker or a SOC analyst

00:11:50.370 --> 00:11:53.070
to be able to sort of derive that value. Agree.

00:11:53.190 --> 00:11:56.370
So metrics and telemetry and stuff is really

00:11:56.370 --> 00:11:59.269
helpful. Yeah, and like you said, I build a lot

00:11:59.269 --> 00:12:01.470
of these automation workflows in the past for

00:12:01.470 --> 00:12:04.350
my own company and the companies that I work

00:12:04.350 --> 00:12:08.049
for from that. But a lot of effort goes into

00:12:08.049 --> 00:12:10.629
that. And that's sometimes forgotten. In the

00:12:10.629 --> 00:12:13.690
end, it might be very useful, but 40 hours to

00:12:13.690 --> 00:12:16.470
build a single workflow, for example, is also

00:12:16.470 --> 00:12:19.230
costly. costly yeah 100 so i'm looking forward

00:12:19.230 --> 00:12:21.990
to revisit this product and uh and giving it

00:12:21.990 --> 00:12:24.629
a closer look yeah definitely more on that i

00:12:24.629 --> 00:12:26.169
think in some future episodes there'll be some

00:12:26.169 --> 00:12:28.850
be some things i think um you know for me i think

00:12:28.850 --> 00:12:31.309
one of the the things that have been that was

00:12:31.309 --> 00:12:35.330
really great was getting to spend some time with

00:12:35.330 --> 00:12:37.710
one of the Microsoft sort of threat hunting groups,

00:12:37.909 --> 00:12:40.309
right? And you were in that session too, right?

00:12:40.309 --> 00:12:43.389
Yeah, I was, yeah. You already had a catchy title.

00:12:43.669 --> 00:12:46.470
Yes. So something with Boo, because the team

00:12:46.470 --> 00:12:49.990
calls themselves Ghosts. And they acknowledged

00:12:49.990 --> 00:12:53.970
that the acronym was thought of afterwards. So

00:12:53.970 --> 00:12:57.250
it stands for Global Hunting Oversight and Strategic

00:12:57.250 --> 00:13:00.289
Triage. So they just had to figure out some words

00:13:00.330 --> 00:13:03.929
which fits the the gh ost gotcha letters i guess

00:13:03.929 --> 00:13:06.490
yes but it's a cool name yeah it's a it's a team

00:13:06.490 --> 00:13:09.330
within microsoft uh which specialized like you

00:13:09.330 --> 00:13:12.750
said on hunting yeah are you the hunting concept

00:13:12.750 --> 00:13:15.269
it might be good to explain i think it's a yeah

00:13:15.269 --> 00:13:18.700
i mean i you know i'm personally i'm i'm somewhat

00:13:18.700 --> 00:13:20.919
familiar with the the concept of hunting but

00:13:20.919 --> 00:13:23.240
i know this is really an area where you you know

00:13:23.240 --> 00:13:25.120
you have a lot more more sort of experience but

00:13:25.120 --> 00:13:26.639
so i don't know if you want to kind of dig into

00:13:26.639 --> 00:13:28.879
yeah of course so so within the defender portal

00:13:28.879 --> 00:13:31.000
for example you can also find advanced hunting

00:13:31.000 --> 00:13:33.860
right right so proactive hunting advanced hunting

00:13:33.860 --> 00:13:38.759
is just a terminology of having a assume breach

00:13:38.759 --> 00:13:43.480
concept where the attacker might already be inside

00:13:43.480 --> 00:13:46.139
your organization and it might have been undetected

00:13:46.139 --> 00:13:50.820
there and you start with a hypothesis to hunt

00:13:50.820 --> 00:13:54.039
for. Like, for example, let's see if there might

00:13:54.039 --> 00:13:59.820
be any outgoing email traffic by a non -email

00:13:59.820 --> 00:14:02.879
client process, for example. If we can find perhaps

00:14:02.879 --> 00:14:06.000
PowerShell or whatever sending out emails. That

00:14:06.000 --> 00:14:09.259
could be a possible data exfiltration. And then

00:14:09.259 --> 00:14:11.740
you go along with that idea and you hunt inside

00:14:11.740 --> 00:14:14.299
the data. You go hunt for the attacker, potentially,

00:14:14.480 --> 00:14:17.080
and see if you can find any malicious activities

00:14:17.080 --> 00:14:19.940
in your logs. So by, in this case, looking at

00:14:19.940 --> 00:14:22.080
process events from Defender or network events

00:14:22.080 --> 00:14:24.460
from Defender, you could potentially spot some

00:14:24.460 --> 00:14:29.240
weird behavior. Like I said, the PowerShell emailing

00:14:29.240 --> 00:14:31.220
is just a simple example. And then afterwards,

00:14:31.360 --> 00:14:32.840
you can determine, well, hopefully you won't

00:14:32.840 --> 00:14:36.080
find anything, but it might result at least in

00:14:36.080 --> 00:14:38.980
additional new detections. So one of the outputs

00:14:38.980 --> 00:14:40.779
from the hunting team is better and improved

00:14:40.779 --> 00:14:45.259
detections. And next time you can detect if PowerShell

00:14:45.259 --> 00:14:47.070
is sending an email. for example, instead of

00:14:47.070 --> 00:14:49.350
having to hunt for it after the fact. And of

00:14:49.350 --> 00:14:51.509
course, you know, you have that as part of that

00:14:51.509 --> 00:14:53.970
process is if you identify that PowerShell is...

00:14:54.399 --> 00:14:56.500
as you know to use the example sending out email

00:14:56.500 --> 00:14:58.200
well then you might want to dig into that a little

00:14:58.200 --> 00:14:59.919
bit and say well why is powershell sending out

00:14:59.919 --> 00:15:01.840
anything and you know are there legit causes

00:15:01.840 --> 00:15:04.539
and reasons for it yeah and all of that works

00:15:04.539 --> 00:15:06.700
into building those detections yeah and then

00:15:06.700 --> 00:15:09.419
obviously you will find that one sysadmin who

00:15:09.419 --> 00:15:12.460
built a script to send himself an email on certain

00:15:12.460 --> 00:15:15.200
metrics or whatever and that is fine then you

00:15:15.200 --> 00:15:17.220
found that and you need to exclude that in as

00:15:17.220 --> 00:15:19.080
part of your detection to make sure you don't

00:15:19.080 --> 00:15:21.720
get any false positives right but that's in general

00:15:21.720 --> 00:15:24.519
what a hunting means and And yeah, again, this

00:15:24.519 --> 00:15:27.179
team focuses on hunting on all the data Microsoft

00:15:27.179 --> 00:15:30.919
has. And well, we obviously cannot go into detail

00:15:30.919 --> 00:15:33.080
of things they shared, but one of the great things

00:15:33.080 --> 00:15:35.460
was that they shared a couple of basics, right?

00:15:35.559 --> 00:15:37.799
Some best practices, if you will. Yeah, and I

00:15:37.799 --> 00:15:39.620
think, I mean, I think you've, you know, if you

00:15:39.620 --> 00:15:40.980
listen to this, you've probably already guessed,

00:15:41.100 --> 00:15:44.759
right, that hunting can be really valuable. if

00:15:44.759 --> 00:15:47.240
you have the data sources to support that, right?

00:15:47.419 --> 00:15:49.740
And I think, so definitely one of the really

00:15:49.740 --> 00:15:52.179
sort of important things I think that I learned

00:15:52.179 --> 00:15:56.080
from that session was to look at the graph logs,

00:15:56.220 --> 00:16:00.019
right? And again, I think it becomes an interesting

00:16:00.019 --> 00:16:01.720
discussion because we've had discussion even

00:16:01.720 --> 00:16:04.289
on this podcast before about... how much data

00:16:04.289 --> 00:16:08.110
do you need and how much data is worth it and

00:16:08.110 --> 00:16:11.169
do you want to be... Because in an ideal scenario,

00:16:11.370 --> 00:16:13.389
in an ideal world, we all keep all of our data

00:16:13.389 --> 00:16:16.549
forever, right? But the reality is that as soon

00:16:16.549 --> 00:16:18.769
as you start attaching a dollar value or a euro

00:16:18.769 --> 00:16:22.230
value to the data or to storing that data...

00:16:22.750 --> 00:16:26.730
maybe it's not always as good to be storing all

00:16:26.730 --> 00:16:29.590
of the stuff forever, right? And I think this

00:16:29.590 --> 00:16:30.889
is something that I'm definitely going to be

00:16:30.889 --> 00:16:33.830
taking away with me is graph logs, looking at

00:16:33.830 --> 00:16:37.330
those things. I know that you need a P1 license

00:16:37.330 --> 00:16:39.450
to be able to get to them to begin with. You

00:16:39.450 --> 00:16:41.470
need a log analytics workspace to be able to

00:16:41.470 --> 00:16:44.110
store them. So there's some cost there if you

00:16:44.110 --> 00:16:45.750
don't already have those things or access to

00:16:45.750 --> 00:16:48.490
those things in your environment. But the benefit

00:16:48.490 --> 00:16:50.570
of being able to do that and, like you said,

00:16:50.669 --> 00:16:53.570
use that information. usefully in your environment

00:16:53.570 --> 00:16:56.809
may actually outweigh the cost of doing that.

00:16:56.929 --> 00:16:58.690
Microsoft actually has some really good information

00:16:58.690 --> 00:17:01.649
about cost analysis and cost prediction and stuff

00:17:01.649 --> 00:17:05.190
like that, specifically for this. So what we'll

00:17:05.190 --> 00:17:07.490
do is, as part of the show notes, we'll share

00:17:07.490 --> 00:17:11.779
that as well. Some other insights that came out

00:17:11.779 --> 00:17:13.900
of the team, out of the discussion with the team

00:17:13.900 --> 00:17:15.859
that I, you know, that we can share, you know,

00:17:15.859 --> 00:17:19.440
as Coach said, non -NDA stuff, right? And surprise,

00:17:19.559 --> 00:17:22.819
surprise, identity still is the primary target,

00:17:22.880 --> 00:17:24.779
right? The bad actors are still continuing to

00:17:24.779 --> 00:17:31.519
go after identity and really MFA by itself. probably

00:17:31.519 --> 00:17:34.059
not enough anymore, right? Yeah, and we touched

00:17:34.059 --> 00:17:36.299
on this in an earlier episode. People are still

00:17:36.299 --> 00:17:39.880
enrolling MFA, oddly enough, and they already

00:17:39.880 --> 00:17:42.460
need to look at more advanced stuff like the

00:17:42.460 --> 00:17:45.579
pass keys and other phishing -resistant methods.

00:17:46.099 --> 00:17:49.259
Yes, so definitely, you know, hard push on phish

00:17:49.259 --> 00:17:51.839
-resistant MFA, phish -resistant authentication

00:17:51.839 --> 00:17:54.140
mechanisms, pass keys, things like that. That

00:17:54.140 --> 00:17:55.640
stuff really is starting to become ready for

00:17:55.640 --> 00:17:58.660
primetime now. So, you know, definitely something

00:17:58.660 --> 00:18:02.579
to focus on. Yeah, one of the things I also remembered

00:18:02.579 --> 00:18:07.960
from those advices was the fact that you should

00:18:07.960 --> 00:18:10.700
not just simply exclude it sounds silly right

00:18:10.700 --> 00:18:12.920
of course you should not exclude people from

00:18:12.920 --> 00:18:16.119
MFA but there are sometimes is a need to exclude

00:18:16.119 --> 00:18:18.059
certain accounts maybe service accounts or whatever

00:18:18.059 --> 00:18:21.200
but don't use a regular group for that because

00:18:21.200 --> 00:18:24.119
you might end up using the group also for permissions

00:18:24.119 --> 00:18:26.839
to an application something else and you're adding

00:18:26.839 --> 00:18:28.920
users to that and without you knowing you're

00:18:28.920 --> 00:18:31.579
excluding people from MFA right yeah yeah it's

00:18:31.579 --> 00:18:33.039
an interesting concept right because we've always

00:18:33.039 --> 00:18:35.839
been taught that permission assignments should

00:18:35.839 --> 00:18:37.619
go through groups right you don't direct the

00:18:37.619 --> 00:18:39.339
science stuff yeah but in this case it's almost

00:18:39.339 --> 00:18:42.299
better to do your exclusions that specifically

00:18:42.299 --> 00:18:44.480
where you're actually just excluding things,

00:18:44.740 --> 00:18:46.960
you know, on a per user basis so that you don't

00:18:46.960 --> 00:18:49.619
fall into the trap of inadvertently using an

00:18:49.619 --> 00:18:51.819
ops group that is being used for something else.

00:18:51.960 --> 00:18:54.200
Or very specifically perhaps use a prefix or

00:18:54.200 --> 00:18:56.059
something in the group when it's only used for

00:18:56.059 --> 00:18:57.819
conditional access purposes, for example. Yeah,

00:18:58.000 --> 00:19:01.380
that's a really good idea as well. So that was

00:19:01.380 --> 00:19:03.480
a really, really, really good one. I think the

00:19:03.480 --> 00:19:05.579
other thing that was fascinating, and it's not

00:19:05.579 --> 00:19:06.799
something I've thought about for a very long

00:19:06.799 --> 00:19:10.579
time, at least in the early days of MFA, there

00:19:10.579 --> 00:19:13.240
used to be this very common trend of excluding

00:19:13.240 --> 00:19:16.700
your office location, right? Yes. Excluding the

00:19:16.700 --> 00:19:20.140
public -facing IPs of your work location or locations

00:19:20.140 --> 00:19:23.900
so that users within the office don't get prompted

00:19:23.900 --> 00:19:26.319
for MFA. Yeah. Yeah, that ship has sailed, folks.

00:19:26.480 --> 00:19:27.819
We don't want to be doing that. Stop doing that,

00:19:27.900 --> 00:19:31.509
people. Yeah. yeah and it it goes along with

00:19:31.509 --> 00:19:34.230
the zero trust principles right um you cannot

00:19:34.230 --> 00:19:36.589
trust anything also you can also not trust your

00:19:36.589 --> 00:19:39.029
corporate network it might be compromised your

00:19:39.029 --> 00:19:41.130
endpoint might be compromised and then when you're

00:19:41.130 --> 00:19:43.890
on at the office of course it's it might be easy

00:19:43.890 --> 00:19:46.549
for you that you do not have to accept an mfa

00:19:46.549 --> 00:19:49.450
request or stick in that fido key or whatever

00:19:49.450 --> 00:19:53.049
um but yeah it's and i do think that it also

00:19:53.049 --> 00:19:57.279
there is a behavioral and cultural element to

00:19:57.279 --> 00:20:00.000
this as well right if your users are are conditioned

00:20:00.000 --> 00:20:04.650
to using MFA correctly all the time, they're

00:20:04.650 --> 00:20:06.829
less likely to fall for things. I think there's

00:20:06.829 --> 00:20:09.829
an importance there. The opposite is true. If

00:20:09.829 --> 00:20:11.529
you have users who work in the office all the

00:20:11.529 --> 00:20:13.750
time, they never get an MFA prompt. That's a

00:20:13.750 --> 00:20:15.809
good point. Then once they go to Starbucks for

00:20:15.809 --> 00:20:19.490
that one meeting, they're more likely to fall

00:20:19.490 --> 00:20:22.410
for a phishing scam where they're not familiar

00:20:22.410 --> 00:20:25.549
with what the workflow looks like. I think it's

00:20:25.549 --> 00:20:27.470
really important to think about that. If you

00:20:27.470 --> 00:20:30.009
are doing that, it may be something that as you

00:20:30.009 --> 00:20:35.539
start moving away from non -fish resistant MFA

00:20:35.539 --> 00:20:37.519
methods, maybe this is something that you want

00:20:37.519 --> 00:20:40.000
to look at as well, like hardening up those conditional

00:20:40.000 --> 00:20:42.160
access policies. Yeah, that's a good point. Same

00:20:42.160 --> 00:20:45.640
as with people having to change their passwords

00:20:45.640 --> 00:20:47.720
all the time so they don't memorize them. They

00:20:47.720 --> 00:20:49.240
write them down on a note and put them under

00:20:49.240 --> 00:20:52.380
the keyboard. That's right. It's an old practice

00:20:52.380 --> 00:20:55.940
that we really shouldn't be doing today anymore.

00:20:57.000 --> 00:21:00.119
So yeah another thing I wanted to touch on is

00:21:00.119 --> 00:21:03.740
maybe also very familiar for a lot of people

00:21:03.740 --> 00:21:06.500
but I wasn't aware of all the intricate details

00:21:06.500 --> 00:21:10.160
on conditional access and the controls you have

00:21:10.160 --> 00:21:13.799
in there. It's a very easy way to just require

00:21:13.799 --> 00:21:15.759
device compliance for example on your construction

00:21:15.759 --> 00:21:18.119
policy. Yes and it's interesting that you know

00:21:18.119 --> 00:21:21.089
I think we are getting to a place now where A

00:21:21.089 --> 00:21:23.250
lot of organizations have that device information

00:21:23.250 --> 00:21:27.109
available to them in Entra, but maybe they're

00:21:27.109 --> 00:21:29.309
not using that to make decisions about access,

00:21:29.509 --> 00:21:31.509
right? I think it's really time to start looking

00:21:31.509 --> 00:21:33.470
at that and going, well, we know we can make

00:21:33.470 --> 00:21:35.710
decisions, use conditional access to make decisions

00:21:35.710 --> 00:21:38.490
around the identity, but let's also use the device,

00:21:38.609 --> 00:21:42.109
the device state and things like that for these

00:21:42.109 --> 00:21:43.910
decisions, right? Then at least if an account

00:21:43.910 --> 00:21:47.250
is compromised, it cannot log in anyway. Unless

00:21:47.250 --> 00:21:51.309
the device is compromised. and the chances of

00:21:51.309 --> 00:21:53.930
that happening is even less. Yes, and I think

00:21:53.930 --> 00:21:56.130
we're definitely at a place now where with Windows

00:21:56.130 --> 00:21:59.230
10, Windows 11 adoption where it is, there's

00:21:59.230 --> 00:22:00.990
more information available to folks, right? And

00:22:00.990 --> 00:22:03.029
it's just a matter of revisiting these policies

00:22:03.029 --> 00:22:06.130
that maybe you implemented a year or 18 months,

00:22:06.250 --> 00:22:08.470
two years ago, and seeing how you can enrich

00:22:08.470 --> 00:22:10.769
the policy. You don't have to change the whole

00:22:10.769 --> 00:22:13.130
policy, just enrich the policy. Make it a little

00:22:13.130 --> 00:22:16.029
bit harder for the bad guy to knock in. Yeah,

00:22:16.069 --> 00:22:18.650
the same as with risky user status, right? Yeah.

00:22:18.920 --> 00:22:22.380
so when when a user does something which is perhaps

00:22:22.380 --> 00:22:25.920
a bit dubious some weird sign in from a different

00:22:25.920 --> 00:22:29.240
country all of a sudden or maybe in regards to

00:22:29.240 --> 00:22:30.980
an impossible travel or something like that yeah

00:22:30.980 --> 00:22:33.779
an account gets a different risk status yeah

00:22:33.779 --> 00:22:35.539
and within the conditional access you can say

00:22:35.539 --> 00:22:40.539
okay only allow people or uh uh uh when the risk

00:22:40.539 --> 00:22:43.119
status is low for example yeah and risk status

00:22:43.119 --> 00:22:46.099
um account risk in account signing status those

00:22:46.099 --> 00:22:48.359
policies are i i don't see them very and use

00:22:48.359 --> 00:22:51.240
very often. If you're not pretty sure, they require

00:22:51.240 --> 00:22:54.720
a P2 license, I think, for those, which I think

00:22:54.720 --> 00:22:57.210
it does. you know somewhat restrict folks from

00:22:57.210 --> 00:23:00.349
from using them but you know if you are looking

00:23:00.349 --> 00:23:02.450
at some of the compliance frameworks for example

00:23:02.450 --> 00:23:06.369
cis one of the cis levels you know kind of mandates

00:23:06.369 --> 00:23:08.509
you know risky signing policies and stuff like

00:23:08.509 --> 00:23:10.609
that so they're very very useful and i think

00:23:10.609 --> 00:23:13.250
they can really save your bacon if you know in

00:23:13.250 --> 00:23:15.049
the event where you have something compromised

00:23:15.049 --> 00:23:16.950
so something completely different i know that

00:23:16.950 --> 00:23:21.289
quite recently e3 licenses are now able to also

00:23:21.289 --> 00:23:24.529
incorporate the security stuff okay without having

00:23:24.529 --> 00:23:27.880
you to buy e5 immediately i'm not sure if p2

00:23:27.880 --> 00:23:30.500
is then also immediately part of that but that's

00:23:30.500 --> 00:23:32.140
maybe something people should look into yeah

00:23:32.140 --> 00:23:34.039
you should be able to get a p2 on lane three

00:23:34.039 --> 00:23:35.980
yeah because it's just the interest queue so

00:23:35.980 --> 00:23:37.940
i'm pretty sure you can yeah um but you know

00:23:37.940 --> 00:23:40.579
there's a lot of value to it i think uh with

00:23:40.579 --> 00:23:43.200
the p2 stuff um especially when you look at other

00:23:43.200 --> 00:23:45.839
areas right like um privilege that in their management

00:23:45.839 --> 00:23:48.660
yeah the ability for you yeah stuff like that

00:23:48.660 --> 00:23:51.500
access reviews right right yeah so so really

00:23:51.500 --> 00:23:54.099
i think p2 is uh there's a lot of value there

00:23:54.160 --> 00:23:55.680
And I think, you know, if you're going through

00:23:55.680 --> 00:23:58.619
a budget cycle, take a look at that stuff and

00:23:58.619 --> 00:24:01.160
see how much value that can add. Because I think

00:24:01.160 --> 00:24:04.559
a small spend on P2 can add significant value

00:24:04.559 --> 00:24:07.920
to the organization and really, really kind of

00:24:07.920 --> 00:24:11.700
strengthen your posture. And speaking of conditional

00:24:11.700 --> 00:24:14.619
access policies, and you touched on applications

00:24:14.619 --> 00:24:19.819
earlier, as you know, the company I work for

00:24:19.819 --> 00:24:21.759
run a managed detection and response service.

00:24:23.369 --> 00:24:25.650
We have a lot of customers and we had a first

00:24:25.650 --> 00:24:28.890
time recently that a customer asked for us to

00:24:28.890 --> 00:24:32.369
provide information so they could set up conditional

00:24:32.369 --> 00:24:35.329
access for workload identities because we use

00:24:35.329 --> 00:24:38.450
apps in their environment to bring in the incidents

00:24:38.450 --> 00:24:41.089
and alerts from their tenant into our incident

00:24:41.089 --> 00:24:45.009
response system. And we normally just use an

00:24:45.009 --> 00:24:47.630
app with a secret and we did nice key rotation

00:24:47.630 --> 00:24:49.789
on it. But this customer specifically wanted

00:24:49.789 --> 00:24:51.589
to onboard it or make it part of conditional

00:24:51.589 --> 00:24:55.150
access. by enforcing only access for that application

00:24:55.150 --> 00:24:58.450
from our endpoint IP address, for example. Which

00:24:58.450 --> 00:25:00.410
was great, and it was great that the customer

00:25:00.410 --> 00:25:03.869
actually asked us to improve security posture

00:25:03.869 --> 00:25:06.670
on that. And now we're looking into standardizing

00:25:06.670 --> 00:25:09.190
that. And I think that's also something I'd like

00:25:09.190 --> 00:25:12.829
to touch on. Applications can be a very weak

00:25:12.829 --> 00:25:16.329
entry in an organization regularly. And I don't

00:25:16.329 --> 00:25:18.410
see it used a lot, the workload and entities

00:25:18.410 --> 00:25:21.210
in conditional access. I think a lot of folks

00:25:21.210 --> 00:25:23.740
don't really dig into it because there's definitely

00:25:23.740 --> 00:25:28.099
a little bit of confusion around enterprise apps

00:25:28.099 --> 00:25:30.039
versus service principles of all of these other

00:25:30.039 --> 00:25:32.140
things and how they hang together in the tenant.

00:25:32.299 --> 00:25:36.779
But also by default, users can consent to any

00:25:36.779 --> 00:25:40.569
app. And this is one of my biggest frustrations

00:25:40.569 --> 00:25:44.650
with new tenant configurations within M365 is

00:25:44.650 --> 00:25:46.750
that users can do this. Because the very first

00:25:46.750 --> 00:25:48.549
thing I do when I work with a customer to do

00:25:48.549 --> 00:25:53.470
security hardening on M365 is go and remove users'

00:25:53.569 --> 00:25:56.069
ability to consent to third -party apps and build

00:25:56.069 --> 00:26:00.069
workflows for admins. So I think this is a big

00:26:00.069 --> 00:26:02.829
lesson here is that the bad actors are coming

00:26:02.829 --> 00:26:05.589
after your apps. They're going to try and trick

00:26:05.589 --> 00:26:07.289
your users into consenting. consenting to stuff

00:26:07.289 --> 00:26:10.920
that that can give them access and give them

00:26:10.920 --> 00:26:14.599
a foothold. And it's really hard once they've

00:26:14.599 --> 00:26:16.480
got access to an app that you've consented to

00:26:16.480 --> 00:26:19.240
in the environment. It's hard to get rid of that

00:26:19.240 --> 00:26:21.200
unless you really know where to go look for it.

00:26:21.319 --> 00:26:23.480
Yeah, and you can also move laterally, so to

00:26:23.480 --> 00:26:25.880
speak, to other apps with higher privileges.

00:26:26.460 --> 00:26:29.019
And I think, well, people probably know, I heard

00:26:29.019 --> 00:26:31.380
of Midnight Blizzard. It was an attack on Microsoft

00:26:31.380 --> 00:26:33.839
a couple of months or a year ago. Yeah, about

00:26:33.839 --> 00:26:35.400
a year ago, I think. Yeah, but there's a lot

00:26:35.400 --> 00:26:37.500
of documentation on that stuff, how an application

00:26:37.500 --> 00:26:40.059
from one tenant got compromised and then they

00:26:40.059 --> 00:26:42.140
were able to move laterally to different apps

00:26:42.140 --> 00:26:45.980
and get persistence in the actual production

00:26:45.980 --> 00:26:48.779
tenant of Microsoft and get access to mailboxes.

00:26:48.799 --> 00:26:51.059
And it's also a bit scary if you think about

00:26:51.059 --> 00:26:53.519
it. People are still guarding their networks

00:26:53.519 --> 00:26:55.900
and their endpoints now, hopefully, finally.

00:26:56.220 --> 00:26:59.579
And while data is also, a lot of the data is

00:26:59.579 --> 00:27:02.160
in the cloud. which your applications have access

00:27:02.160 --> 00:27:05.180
to. You don't even need access to any corporate

00:27:05.180 --> 00:27:07.220
network or endpoints. You can just go through

00:27:07.220 --> 00:27:10.480
an application, compromise the clouds, compromise

00:27:10.480 --> 00:27:12.539
the cloud identities and the cloud data. That's

00:27:12.539 --> 00:27:16.059
right. I mean, I think there's a lot of, you

00:27:16.059 --> 00:27:18.960
know, I have a demo that I've done in talks before

00:27:18.960 --> 00:27:21.759
where if you think about a, you know, a kill

00:27:21.759 --> 00:27:24.109
chain of how you would make this work is. All

00:27:24.109 --> 00:27:26.809
you need to do is get a user to click a link

00:27:26.809 --> 00:27:29.910
to grant access to an app that you've created.

00:27:30.450 --> 00:27:35.109
And now you have access. So I agree. I think

00:27:35.109 --> 00:27:37.470
apps are a weakness. And I think Microsoft is

00:27:37.470 --> 00:27:40.650
starting to realize as well that we can put all

00:27:40.650 --> 00:27:42.130
of this effort into securing the user identities.

00:27:42.410 --> 00:27:44.430
We also need to be able to give our customers

00:27:44.430 --> 00:27:48.410
the ability to secure their apps. And app identities

00:27:48.410 --> 00:27:50.950
is part of that. Being able to actually monitor

00:27:50.950 --> 00:27:53.509
and report on what's going on in that app. structure

00:27:53.509 --> 00:27:56.829
is yeah is something as well so it also surprises

00:27:56.829 --> 00:28:00.660
me that well On one hand, it does not surprise

00:28:00.660 --> 00:28:03.160
me that much, but Microsoft should facilitate,

00:28:03.299 --> 00:28:06.279
I think, some solution to that. The secrets of

00:28:06.279 --> 00:28:09.359
the apps, for example. People just regularly

00:28:09.359 --> 00:28:12.079
set a secret, maybe keep the same secret for

00:28:12.079 --> 00:28:15.240
two years, and suddenly it stops working, and

00:28:15.240 --> 00:28:16.799
then they renew it again for two years, right?

00:28:16.880 --> 00:28:22.019
Yeah, that's right. Why Microsoft does not provide

00:28:22.019 --> 00:28:24.859
any auto key rotation, perhaps together with

00:28:24.859 --> 00:28:27.039
an Azure Key Vault or something, beats me. I

00:28:27.039 --> 00:28:29.170
think that would be a very good. feature to uh

00:28:29.170 --> 00:28:32.230
yeah to release yeah that's that's not a that's

00:28:32.230 --> 00:28:34.190
not a that's that's a good point yeah now you

00:28:34.190 --> 00:28:36.130
have to build stuff yourself that's up yourself

00:28:36.130 --> 00:28:38.609
that's complex people don't do it well and maybe

00:28:38.609 --> 00:28:41.049
that's where we'll we'll see some you know uh

00:28:41.049 --> 00:28:44.509
security co -pilot agents uh at work oh yes yeah

00:28:44.509 --> 00:28:48.170
right maybe that's a use case for for something

00:28:48.170 --> 00:28:51.089
like that so um you know i think that's there's

00:28:51.089 --> 00:28:52.509
some really good insights that we've sort of

00:28:52.509 --> 00:28:54.549
taken away we wanted to share some of these some

00:28:54.549 --> 00:28:57.650
of these things i think um you know at their

00:28:57.650 --> 00:29:00.690
core they all seem very basic but when you think

00:29:00.690 --> 00:29:02.809
about um you know how these things are being

00:29:02.809 --> 00:29:05.730
observed over and over and over in the wild it

00:29:05.730 --> 00:29:07.630
does tell us a story and it tells us a story

00:29:07.630 --> 00:29:09.630
that you know there's work to be done in our

00:29:09.630 --> 00:29:11.589
environments in our customer environments and

00:29:11.589 --> 00:29:15.250
in in in sort of securing um all of these things

00:29:15.250 --> 00:29:18.250
so yeah unfortunately the attackers still gain

00:29:18.250 --> 00:29:21.710
access through those basic things the unpatched

00:29:21.710 --> 00:29:25.369
machines the open networks the ports the the

00:29:25.369 --> 00:29:28.269
applications with too much privileges. That's

00:29:28.269 --> 00:29:30.549
how they get in. So really cover your basics.

00:29:32.670 --> 00:29:34.609
any any other insights i think from the week

00:29:34.609 --> 00:29:36.329
um that you wanted to kind of cover off before

00:29:36.329 --> 00:29:39.509
we we look at a community project yeah i know

00:29:39.509 --> 00:29:41.930
i think we have we we discussed all all of the

00:29:41.930 --> 00:29:44.309
stuff on the notes this was a little bit of an

00:29:44.309 --> 00:29:47.269
impromptu uh get together of course yes we just

00:29:47.269 --> 00:29:50.150
hacked together some uh some notes yeah put up

00:29:50.150 --> 00:29:52.289
some tripods and do the recording yeah it's fun

00:29:52.289 --> 00:29:55.329
i like these chairs i mean it does look like

00:29:55.329 --> 00:29:57.329
we're you know having a nap yeah you know may

00:29:57.329 --> 00:29:59.569
have a nap later well we were discussing if we

00:29:59.569 --> 00:30:02.259
should have the the foot the footrest yeah footrest.

00:30:02.480 --> 00:30:06.839
We could have kicked our feet up. But please

00:30:06.839 --> 00:30:11.779
tell us about the community. Yeah, so our community

00:30:11.779 --> 00:30:13.599
project that came across a couple of weeks ago,

00:30:13.720 --> 00:30:16.609
which is now, I'll say that I haven't personally

00:30:16.609 --> 00:30:19.430
used this yet, but I do this type of work all

00:30:19.430 --> 00:30:21.670
the time, and I definitely think that I will

00:30:21.670 --> 00:30:25.690
be using this. So it's called Device Offboarding

00:30:25.690 --> 00:30:29.509
Manager, and it's a project, a PowerShell sort

00:30:29.509 --> 00:30:33.490
of tool written by, and I believe he's a German

00:30:33.490 --> 00:30:36.150
MVP, and I'm going to probably get the pronunciation

00:30:36.150 --> 00:30:39.109
of this wrong, so I might ask you to do this.

00:30:39.809 --> 00:30:43.410
It's Ugo Koch. Well, I think you do a very nice

00:30:43.410 --> 00:30:45.869
job. But we already discussed your European pronunciation.

00:30:46.230 --> 00:30:48.490
It's getting better every month. It is. I've

00:30:48.490 --> 00:30:49.890
got to keep hanging out with all the Dutch guys.

00:30:51.119 --> 00:30:55.480
So, yeah, so Ugo has put together this PowerShell

00:30:55.480 --> 00:30:57.859
tool, Device Offboarding Manager, it's called.

00:30:58.019 --> 00:31:01.819
And it's a way to kind of manage and bulk manage

00:31:01.819 --> 00:31:06.579
devices. And if you're using devices in the Microsoft

00:31:06.579 --> 00:31:08.119
service, you'll know that, you know, there's

00:31:08.119 --> 00:31:10.759
devices in Intune, there's devices in Copilot,

00:31:10.859 --> 00:31:13.440
there's devices in Entra. They kind of live all

00:31:13.440 --> 00:31:14.880
over the place and different bits and pieces

00:31:14.880 --> 00:31:17.440
go different places. And so what he's done is

00:31:17.440 --> 00:31:18.740
he's kind of brought all this stuff together

00:31:18.740 --> 00:31:21.819
into a consolidated tool. and it really gives

00:31:21.819 --> 00:31:25.440
it the ability to just sort of bulk management

00:31:25.440 --> 00:31:30.000
of things and has some really nice looking dashboards

00:31:30.000 --> 00:31:33.779
and analytics and real -time reporting and stuff

00:31:33.779 --> 00:31:36.180
like that. It looks really, really cool for me.

00:31:36.220 --> 00:31:39.369
I think it solves some really... interesting

00:31:39.369 --> 00:31:41.069
issues especially if you're going to be doing

00:31:41.069 --> 00:31:43.910
bulk off -boarding for example of users and things

00:31:43.910 --> 00:31:46.109
like that right which if you think about it scenarios

00:31:46.109 --> 00:31:49.069
where I see this quite often is when you when

00:31:49.069 --> 00:31:51.150
you have customers who go through divestiture

00:31:51.150 --> 00:31:54.410
type projects where you know they've sold off

00:31:54.410 --> 00:31:57.470
part of a business or entire business and at

00:31:57.470 --> 00:32:00.400
some point in time All of the devices that are

00:32:00.400 --> 00:32:03.599
currently under management by the original owner

00:32:03.599 --> 00:32:05.799
of the business need to be off -boarded. And

00:32:05.799 --> 00:32:08.519
so this tool looks like this is the perfect way

00:32:08.519 --> 00:32:11.799
to do that. Yeah, you showed me before we started.

00:32:11.859 --> 00:32:15.160
It looks great. Also, great UI. Yes, very nice.

00:32:15.339 --> 00:32:17.880
I have a soft spot for UI. So do I. And I myself

00:32:17.880 --> 00:32:19.859
have built some PowerShell tools, so I can always

00:32:19.859 --> 00:32:23.259
appreciate when someone puts the effort into

00:32:23.259 --> 00:32:26.059
making that all work. So we'll put the GitHub

00:32:26.059 --> 00:32:29.799
link in the show notes. I would say if you work

00:32:29.799 --> 00:32:31.880
in the Intune space at all this is definitely

00:32:31.880 --> 00:32:34.019
one for you to go and check out and you know

00:32:34.019 --> 00:32:36.779
take a look at it and of course you know Igor

00:32:36.779 --> 00:32:40.359
being an MVP he's I'm sure open to feedback and

00:32:40.359 --> 00:32:42.400
suggestions and all sorts of stuff I'm not sure

00:32:42.400 --> 00:32:44.259
if he's around actually we should see if he is

00:32:44.259 --> 00:32:46.079
and we can say hello to him that would be great

00:32:46.079 --> 00:32:50.019
so Summit will end officially on Thursday tomorrow

00:32:50.019 --> 00:32:52.759
at the end of the day yes when are you going

00:32:52.759 --> 00:32:54.420
back to Australia I'm going back to Australia

00:32:54.420 --> 00:32:57.400
on Saturday but I'll be leaving leaving Seattle

00:32:57.400 --> 00:33:00.279
on the seattle area on friday okay i'm just heading

00:33:00.279 --> 00:33:01.880
to san francisco and then i'll be flying out

00:33:01.880 --> 00:33:04.740
from there um so you know it's been a quick just

00:33:04.740 --> 00:33:07.000
a quick trip in my body hasn't quite adjusted

00:33:07.000 --> 00:33:09.700
to the time zones just yet so so sleep has been

00:33:09.700 --> 00:33:12.940
very rare for me this last week yeah um for me

00:33:12.940 --> 00:33:15.700
as well and the problem is i'm almost getting

00:33:15.700 --> 00:33:18.180
acquainted now with the new time zone yeah and

00:33:18.180 --> 00:33:20.579
while i'm used to it then i need to go back and

00:33:20.579 --> 00:33:22.759
that's right we have the whole stuff going on

00:33:22.759 --> 00:33:25.819
again for a couple of days yeah but uh look it's

00:33:25.819 --> 00:33:27.990
been it's so far been great I think there's still

00:33:27.990 --> 00:33:29.589
a lot to come I think tomorrow's gonna be a packed

00:33:29.589 --> 00:33:32.670
day yes really packed day so I'm glad we're able

00:33:32.670 --> 00:33:34.349
to kind of make this work today as well yeah

00:33:34.349 --> 00:33:37.690
and totally yeah hopefully we'll get this through

00:33:37.690 --> 00:33:39.890
edits and and and published at our normal schedule

00:33:39.890 --> 00:33:42.150
so if you listen to this it's likely going to

00:33:42.150 --> 00:33:44.829
be you know early early part of april yeah so

00:33:44.829 --> 00:33:47.630
yeah very nice well thanks chris i appreciate

00:33:47.630 --> 00:33:49.849
it thank you time for this and i really enjoy

00:33:49.849 --> 00:33:53.589
it um i think especially the whole dynamic is

00:33:53.589 --> 00:33:56.569
is well better i would say yes but normally we

00:33:56.569 --> 00:33:58.589
cannot visit each other every year every month

00:33:58.589 --> 00:34:01.829
unfortunately so yeah we'll have to do this on

00:34:01.829 --> 00:34:04.029
the next conference we'll meet for sure for sure

00:34:04.029 --> 00:34:06.059
and thank you folks for listening to another

00:34:06.059 --> 00:34:08.519
episode please you know like subscribe do all

00:34:08.519 --> 00:34:12.519
the the usual things and yeah we appreciate you

00:34:12.519 --> 00:34:14.760
spending some time with us and we will catch

00:34:14.760 --> 00:34:17.539
you on the next episode see you later bye
