WEBVTT

00:00:10.259 --> 00:00:12.740
Hello, everybody, and welcome to another episode

00:00:12.740 --> 00:00:16.100
of Everyday Defender, the podcast with Koos and

00:00:16.100 --> 00:00:18.780
Chris. My name is Koos, and I'm joined once again

00:00:18.780 --> 00:00:21.460
with my co -host, Chris Goosen. Hi, Chris. How

00:00:21.460 --> 00:00:23.039
are you doing? Hey, Koos. How are you doing?

00:00:23.059 --> 00:00:25.500
Good to see you, mate. Good to see you as well.

00:00:26.019 --> 00:00:29.039
Episode eight already. Time flies, right? It

00:00:29.039 --> 00:00:31.359
really does, doesn't it? It's kind of crazy if

00:00:31.359 --> 00:00:35.259
you think about how we spent months working on

00:00:35.259 --> 00:00:37.060
this before we even published the first episode.

00:00:37.200 --> 00:00:39.079
So it's probably been about a year since we first

00:00:39.079 --> 00:00:41.420
started. kind of going back and forth and talking

00:00:41.420 --> 00:00:42.840
about this. Because I think actually we spoke

00:00:42.840 --> 00:00:47.039
about it at MVP Summit 2024, or maybe very shortly

00:00:47.039 --> 00:00:50.859
after that. And so it's been a year of kind of

00:00:50.859 --> 00:00:52.100
working on this with you, man. And it's been

00:00:52.100 --> 00:00:54.820
a really good journey so far. So yeah, super

00:00:54.820 --> 00:00:57.859
happy to be back again, recording episode eight.

00:00:58.140 --> 00:01:00.429
And I think we have some... I think we have some

00:01:00.429 --> 00:01:02.850
interesting topics to talk about today. Yeah,

00:01:02.950 --> 00:01:05.489
that's true. And I wanted to say I already learned

00:01:05.489 --> 00:01:07.810
a lot in the last couple of episodes, the last

00:01:07.810 --> 00:01:09.790
eight episodes, making those episodes with you.

00:01:10.269 --> 00:01:13.549
Well, like we said earlier, we want to dive into

00:01:13.549 --> 00:01:16.909
new stuff and discover new stuff on our own as

00:01:16.909 --> 00:01:19.230
well, because Microsoft security is so broad,

00:01:19.349 --> 00:01:21.930
right? And I think especially today, again, we

00:01:21.930 --> 00:01:24.769
have some new topics. And especially when I'm

00:01:24.769 --> 00:01:27.370
talking for myself, I want to talk about security

00:01:27.370 --> 00:01:32.370
co -pilot. It is maybe a bit of a controversial

00:01:32.370 --> 00:01:35.290
topic because I think copilot and AI in general

00:01:35.290 --> 00:01:38.909
is hyped about a lot. And we as tech guys, we

00:01:38.909 --> 00:01:40.989
poke through a lot of the marketing nonsense

00:01:40.989 --> 00:01:44.409
most of the times, I guess. But I really wanted

00:01:44.409 --> 00:01:47.230
to read. revisit Security Copilot because there

00:01:47.230 --> 00:01:52.609
were some new features added. And I think it

00:01:52.609 --> 00:01:55.510
is at the stage where I really want to advise

00:01:55.510 --> 00:01:57.489
everybody to just try it out. And that's what

00:01:57.489 --> 00:02:00.430
I want to touch on. And you dug yourself into

00:02:00.430 --> 00:02:03.980
the Entra suite. Yeah, yeah. You know, originally

00:02:03.980 --> 00:02:06.400
I was going to do a bit of a deep dive into some

00:02:06.400 --> 00:02:09.439
of the components of EntraSuite, looking specifically

00:02:09.439 --> 00:02:11.960
at the private access stuff and maybe the internet

00:02:11.960 --> 00:02:14.439
access. But then I thought, you know what, EntraSuite

00:02:14.439 --> 00:02:17.280
as a concept is a bit new to folks. It's only

00:02:17.280 --> 00:02:19.259
really something that's been around for maybe

00:02:19.259 --> 00:02:21.740
a year, just a little less than a year. So I

00:02:21.740 --> 00:02:23.439
thought, you know what, let's take an episode

00:02:23.439 --> 00:02:26.219
to just introduce folks to... EntraSuite, what

00:02:26.219 --> 00:02:28.219
actually is EntraSuite, what are the components

00:02:28.219 --> 00:02:31.159
of EntraSuite? And then next episode, we'll dive

00:02:31.159 --> 00:02:33.060
into some of the, you know, a little bit more

00:02:33.060 --> 00:02:35.360
specific use cases and maybe some configuration

00:02:35.360 --> 00:02:38.039
tips and things like that on some of the components.

00:02:38.599 --> 00:02:41.280
Yeah, sounds good. I think most people know Entra

00:02:41.280 --> 00:02:43.479
from EntraID, right? But you're probably touching

00:02:43.479 --> 00:02:46.949
on how that's related to EntraSuite. Right, right.

00:02:47.050 --> 00:02:49.310
And I think it's very easy because Microsoft

00:02:49.310 --> 00:02:53.310
Marketing, they help us with this and don't help

00:02:53.310 --> 00:02:56.270
us with this very often, right? So I think a

00:02:56.270 --> 00:02:58.050
lot of folks go, Entra Suite, oh, that's just

00:02:58.050 --> 00:03:00.289
everything in Entra. Well, no, there are some

00:03:00.289 --> 00:03:03.689
specific things and we'll dive into that just

00:03:03.689 --> 00:03:05.770
a little bit. And I think I'm really excited

00:03:05.770 --> 00:03:08.650
to hear more about Copilot and Security Copilot

00:03:08.650 --> 00:03:11.889
from your perspective because I think it's our

00:03:11.889 --> 00:03:15.710
job to be a little bit... uh what's what's the

00:03:15.710 --> 00:03:17.650
word just to to look at these things a little

00:03:17.650 --> 00:03:19.669
bit more skeptically i guess and be skeptical

00:03:19.669 --> 00:03:21.889
about some of these things you know obviously

00:03:21.889 --> 00:03:24.469
you see folks in the industry everyone just jumps

00:03:24.469 --> 00:03:26.889
on these things straight away and and and sort

00:03:26.889 --> 00:03:29.349
of pushes the the generic message but i think

00:03:29.349 --> 00:03:32.050
i really think it is it is our responsibility

00:03:32.050 --> 00:03:33.870
to look at these things through a little bit

00:03:33.870 --> 00:03:36.389
of skepticism and and sort of dive into it and

00:03:36.389 --> 00:03:39.199
really let folks know where things are mature

00:03:39.199 --> 00:03:42.400
enough or where things are lacking. So I'm excited

00:03:42.400 --> 00:03:44.659
to see this. I've been having some really interesting

00:03:44.659 --> 00:03:47.300
conversations with customers on the security

00:03:47.300 --> 00:03:50.539
co -pilot side, especially when it comes to sort

00:03:50.539 --> 00:03:53.340
of layering multiple tools together and sort

00:03:53.340 --> 00:03:56.259
of this whole agentic AI thing that Microsoft

00:03:56.259 --> 00:03:59.560
has been talking about. So I'm excited. I think

00:03:59.560 --> 00:04:01.789
it's gonna be another great episode. Yeah, and

00:04:01.789 --> 00:04:04.930
to get started right away with the topic, I was

00:04:04.930 --> 00:04:07.669
actually, as part of the MVP Summit earlier this

00:04:07.669 --> 00:04:12.490
year, there was a post -MVP day, if you will,

00:04:12.610 --> 00:04:15.449
an extra day at the end where you were able to

00:04:15.449 --> 00:04:18.790
join some workshops Microsoft had provided. And

00:04:18.790 --> 00:04:21.269
some of those workshops were regarding EntraSuite,

00:04:21.389 --> 00:04:23.490
for example, but they also had a security co

00:04:23.490 --> 00:04:25.970
-pilot workshop. And because I was a little bit

00:04:25.970 --> 00:04:30.850
skeptical, and that was more or less... based

00:04:30.850 --> 00:04:33.269
primarily around the cost aspect, but I'll touch

00:04:33.269 --> 00:04:36.490
on that later. I did want to give it another

00:04:36.490 --> 00:04:40.149
shot by, well, as you say, we need to be skeptical,

00:04:40.329 --> 00:04:42.350
but also we want to be early adopters, right?

00:04:42.410 --> 00:04:44.569
So we also want to know what's happening and

00:04:44.569 --> 00:04:47.829
what's new, because I think we all agree that

00:04:47.829 --> 00:04:50.689
the whole AI stuff and co -pilot, security co

00:04:50.689 --> 00:04:53.569
-pilot, is really the future. And we already

00:04:53.569 --> 00:04:58.850
saw glimpses of it working in demos. doing some

00:04:58.850 --> 00:05:02.069
amazing stuff, which will save you a lot of time

00:05:02.069 --> 00:05:06.129
in your day -to -day job. So that's why I, well,

00:05:06.290 --> 00:05:09.110
I can remain skeptical, but I also want to give

00:05:09.110 --> 00:05:12.470
it a shot whenever things get improved. So during

00:05:12.470 --> 00:05:15.779
the workshop, I was actually surprised by all

00:05:15.779 --> 00:05:19.160
the capabilities Security Copilot has. When I

00:05:19.160 --> 00:05:22.720
started, it was just Security Copilot as a standalone

00:05:22.720 --> 00:05:26.439
web portal. And I was like, oh boy, we're going

00:05:26.439 --> 00:05:30.860
different portals again. Back to the early days.

00:05:31.540 --> 00:05:33.759
Then they added it into the Defender portal,

00:05:33.879 --> 00:05:36.279
the security portal, if you will, and added it

00:05:36.279 --> 00:05:40.000
into the Defender XDR stuff. But now they also

00:05:40.000 --> 00:05:44.199
integrated it into Entra suite and also Intune.

00:05:45.529 --> 00:05:48.149
And I was able to play with it a bit during that

00:05:48.149 --> 00:05:50.829
workshop. They had all kinds of exercises in

00:05:50.829 --> 00:05:53.589
a lab environment running Security Copilot, and

00:05:53.589 --> 00:05:56.790
you were able to dig into the features. And,

00:05:56.870 --> 00:06:00.569
well, that's why I said to myself, I need to

00:06:00.569 --> 00:06:02.149
play around with it a little bit more when I

00:06:02.149 --> 00:06:04.589
get home because there's some good stuff here,

00:06:04.709 --> 00:06:06.790
and that's what I wanted to share with everybody

00:06:06.790 --> 00:06:10.250
here on this episode. So I said Security Copilot

00:06:10.250 --> 00:06:15.540
is a bit... controversial and that's more on

00:06:15.540 --> 00:06:18.680
the cost aspect because to run security co -pilot

00:06:18.680 --> 00:06:21.000
it works a little bit different than regular

00:06:21.000 --> 00:06:25.959
co -pilot for m365 you have to deploy scus so

00:06:25.959 --> 00:06:29.170
security compute units, security copilot units.

00:06:29.290 --> 00:06:31.470
I'm not sure what the exact acronym is, to be

00:06:31.470 --> 00:06:35.069
honest. But the SCUs act as your compute units

00:06:35.069 --> 00:06:38.470
to run security copilot. And the weird thing

00:06:38.470 --> 00:06:41.589
is you have to deploy those SCUs in your Azure

00:06:41.589 --> 00:06:44.310
environment. And then you're built for them accordingly

00:06:44.310 --> 00:06:47.649
on your Azure will. And once SCUs are available

00:06:47.649 --> 00:06:50.949
in your tenant, Microsoft notices that you have

00:06:50.949 --> 00:06:53.550
them. And then all of a sudden in the Intune,

00:06:53.649 --> 00:06:56.540
Entra portal and the Defender portal. additional

00:06:56.540 --> 00:06:59.439
co -pilot panes and buttons pop up so that you

00:06:59.439 --> 00:07:04.120
can actually use and leverage those SUs. Before

00:07:04.120 --> 00:07:08.920
you had to deploy SCUs a certain amount of SCUs,

00:07:08.959 --> 00:07:11.740
let's say four or eight SCUs, and then you had

00:07:11.740 --> 00:07:15.519
to stuck with them. And there were now some recent

00:07:15.519 --> 00:07:19.339
changes where you can more freely manipulate

00:07:19.339 --> 00:07:21.319
those SCUs. And that's one of the things I wanted

00:07:21.319 --> 00:07:24.720
to touch on. But with the SCUs, if you had those

00:07:24.720 --> 00:07:27.959
SCUs running, they're running 24 -7 and they're...

00:07:28.279 --> 00:07:31.240
consuming a lot of resources an seo costs four

00:07:31.240 --> 00:07:34.519
dollars per hour each so if you have four of

00:07:34.519 --> 00:07:37.319
them that's already sixteen dollars an hour times

00:07:37.319 --> 00:07:40.839
720 hours something in a month that and and then

00:07:40.839 --> 00:07:43.819
in a year it quickly adds up right so um and

00:07:43.819 --> 00:07:45.660
then when you when you consider that microsoft

00:07:45.660 --> 00:07:48.139
wasn't caching any of the output coming from

00:07:48.139 --> 00:07:51.699
those seos it really made a worse a really bad

00:07:51.699 --> 00:07:54.040
business case i believe so when you go to the

00:07:54.040 --> 00:07:56.980
defender portal into the incidents and a summary

00:07:56.980 --> 00:07:59.959
of the incident is generated, which is great.

00:08:00.079 --> 00:08:02.060
You get a great summary of all the things that

00:08:02.060 --> 00:08:04.639
was happening within all the alerts in the incident.

00:08:04.920 --> 00:08:07.480
But when you revisit that page, or if another

00:08:07.480 --> 00:08:11.459
security analyst visits that same page, the prompt

00:08:11.459 --> 00:08:15.220
runs again, SCUs are triggered, you consume compute

00:08:15.220 --> 00:08:18.220
units, and then you get probably the same output

00:08:18.220 --> 00:08:20.939
or similar output. And that's why I think it

00:08:20.939 --> 00:08:23.100
was a little bit too expensive to have it running

00:08:23.100 --> 00:08:27.889
24 -7. So when I wanted to revisit this, I had

00:08:27.889 --> 00:08:33.710
to work around a bit, if you will. So I thought,

00:08:33.830 --> 00:08:35.909
well, if there are Azure resources, I can just

00:08:35.909 --> 00:08:38.429
deploy them and remove them afterwards when they

00:08:38.429 --> 00:08:40.929
don't need them anymore. You can do that. But

00:08:40.929 --> 00:08:43.750
it was surprisingly hard to deploy these with

00:08:43.750 --> 00:08:46.029
PowerShell because I thought, well, everybody's

00:08:46.029 --> 00:08:48.529
already doing this. I couldn't find an existing

00:08:48.529 --> 00:08:52.870
PowerShell script. And ironically, ChatGPT wasn't

00:08:52.870 --> 00:08:55.480
able to help me with it. fully working PowerShell

00:08:55.480 --> 00:08:58.559
script from the get -go. So a lot of... Parameters

00:08:58.559 --> 00:09:01.759
and properties in the JSON were incorrect. It's

00:09:01.759 --> 00:09:04.019
not documented in any way. So I had to go in

00:09:04.019 --> 00:09:07.179
with API request, deploy it in the portal, and

00:09:07.179 --> 00:09:09.720
then look through the API and retrieve some stuff

00:09:09.720 --> 00:09:13.139
to see what was actually deployed. Because for

00:09:13.139 --> 00:09:15.500
some reason, the Azure portal will not provide

00:09:15.500 --> 00:09:18.159
you an export template button, which they do

00:09:18.159 --> 00:09:20.919
with all the other resources, but not with SUs

00:09:20.919 --> 00:09:23.259
for some reason. So I made a PowerShell script.

00:09:23.340 --> 00:09:25.000
And that's one thing I wanted to share in this

00:09:25.000 --> 00:09:28.840
podcast. It's in the show notes. as a gist on

00:09:28.840 --> 00:09:31.320
my GitHub so everybody can start using it. And

00:09:31.320 --> 00:09:33.399
you can just run the PowerShell script, type

00:09:33.399 --> 00:09:36.080
in the amount of SCUs you want, it will deploy

00:09:36.080 --> 00:09:38.059
it, and then you can remove it with the same

00:09:38.059 --> 00:09:40.220
script as well afterwards. And then you're only

00:09:40.220 --> 00:09:42.860
charged with the hours that you are actively

00:09:42.860 --> 00:09:45.919
using the SCUs in your environment. And that's

00:09:45.919 --> 00:09:48.259
why I think you really need to revisit it if

00:09:48.259 --> 00:09:51.720
you haven't already. You can deploy those SCUs.

00:09:52.269 --> 00:09:55.169
make use of them in Intune, in Entra, in Defender,

00:09:55.250 --> 00:09:56.809
and then you can just remove them afterwards.

00:09:57.730 --> 00:10:00.330
And you can obviously also script this. There

00:10:00.330 --> 00:10:03.450
were some logic apps and other automation things

00:10:03.450 --> 00:10:07.769
I found on Google of people who had some automated

00:10:07.769 --> 00:10:11.230
process where they spun up SEUs when the SOC

00:10:11.230 --> 00:10:13.710
started at the beginning of the day. And then

00:10:13.710 --> 00:10:15.529
at the end of the working day, they removed the

00:10:15.529 --> 00:10:20.509
resources again. That's one way to do it. Another

00:10:20.509 --> 00:10:23.429
thing that's that's new that they now have overage

00:10:23.429 --> 00:10:27.509
capacity before. If you deploy two issues and

00:10:27.509 --> 00:10:30.269
your capacity is depleted, everything stops working.

00:10:30.470 --> 00:10:33.169
So you get all kinds of error messages that copilot

00:10:33.169 --> 00:10:35.490
isn't available anymore. And then you had to

00:10:35.490 --> 00:10:38.970
go in the measure, increase the issues, and then

00:10:38.970 --> 00:10:42.039
you can use it again. But you're probably. spending

00:10:42.039 --> 00:10:45.360
too much because you're increasing SCUs, but

00:10:45.360 --> 00:10:47.740
you're not using those SCUs every hour of the

00:10:47.740 --> 00:10:51.360
day. So now with overage SCUs, you can say, let's

00:10:51.360 --> 00:10:54.820
deploy two SCUs and deploy two or four overage

00:10:54.820 --> 00:10:58.460
units. So then it can increase up to six and

00:10:58.460 --> 00:11:00.759
goes back to two again once they're not used

00:11:00.759 --> 00:11:03.240
anymore. And I think the combination of those

00:11:03.240 --> 00:11:06.980
things. So almost like auto scaling type of functionality,

00:11:07.059 --> 00:11:10.490
right? Yeah, yeah, true. Yeah, true. But still

00:11:10.490 --> 00:11:13.409
be cautious with costs because if you keep them

00:11:13.409 --> 00:11:15.690
running, if you keep four issues, eight issues

00:11:15.690 --> 00:11:17.990
running in your environment, it will still cost

00:11:17.990 --> 00:11:20.309
you. So be careful with that. But at least now

00:11:20.309 --> 00:11:23.029
I think you have a very low bar to get started

00:11:23.029 --> 00:11:26.470
and try it out because I'll touch on it later.

00:11:26.490 --> 00:11:28.330
But I think there's some amazing functionality

00:11:28.330 --> 00:11:32.129
in there. One thing on the overage is that you

00:11:32.129 --> 00:11:35.620
pay a little bit more. for an overage su so if

00:11:35.620 --> 00:11:38.840
you have four su's they cost four dollars each

00:11:38.840 --> 00:11:42.200
and if you have an overage su they charge six

00:11:42.200 --> 00:11:45.299
dollars for an overage su so if you have two

00:11:45.299 --> 00:11:47.899
normal and two overage you pay more than just

00:11:47.899 --> 00:11:50.639
four regulars but well the four regulars you

00:11:50.639 --> 00:11:54.110
pay whenever they're running and the overreach

00:11:54.110 --> 00:11:56.350
is scaled back, right? So you have to do a little

00:11:56.350 --> 00:11:58.110
bit of math. And what's also new is that they

00:11:58.110 --> 00:12:01.269
now finally have a nice dashboard to get insights

00:12:01.269 --> 00:12:04.490
in this. So I put in the show notes an example

00:12:04.490 --> 00:12:08.090
screenshot where you can see exactly how much

00:12:08.090 --> 00:12:11.529
SEUs you used over the day, how much overreach

00:12:11.529 --> 00:12:14.090
you had to use, and where they were spent on.

00:12:14.210 --> 00:12:17.389
So you see all the individual sessions by users,

00:12:17.470 --> 00:12:20.750
not what they did, but that they were doing stuff

00:12:20.750 --> 00:12:23.419
in. standalone portal the final portal insurance

00:12:23.419 --> 00:12:26.419
entra whatever and then you can see okay so this

00:12:26.419 --> 00:12:29.179
much of the compute is going to this or that

00:12:29.179 --> 00:12:34.399
um lastly i want to touch on permissions so you

00:12:34.399 --> 00:12:37.700
can also uh well you can you can create multiple

00:12:37.700 --> 00:12:41.639
seo sets in azure so you can delegate those permissions

00:12:41.639 --> 00:12:44.179
so for example you can delegate a couple of seos

00:12:44.179 --> 00:12:47.639
to the security operations team but you can also

00:12:47.639 --> 00:12:49.940
delegate a separate set to different departments

00:12:50.759 --> 00:12:52.919
I'm not sure if that's really something a lot

00:12:52.919 --> 00:12:55.139
of companies are doing right away, again, due

00:12:55.139 --> 00:13:00.980
to cost. But this lets you have, let's say, the

00:13:00.980 --> 00:13:04.320
Intune people responsible for Intune and Entra

00:13:04.320 --> 00:13:07.639
have a go with SEUs without them taking away

00:13:07.639 --> 00:13:10.100
all the compute units from the security team,

00:13:10.159 --> 00:13:16.820
right? Is there a way now to sort of capacity

00:13:16.820 --> 00:13:20.429
plan? how many issues you need or is this something

00:13:20.429 --> 00:13:23.649
that you would deploy it, see how it's working

00:13:23.649 --> 00:13:25.850
for you? And then now that you can come back

00:13:25.850 --> 00:13:27.710
and change it, you can you can always tweak it

00:13:27.710 --> 00:13:29.789
later. How do you because I know you're very

00:13:29.789 --> 00:13:32.470
big on being able to plan stuff ahead of time,

00:13:32.529 --> 00:13:34.789
right? And you have some tools for Sentinel on

00:13:34.789 --> 00:13:36.549
how to cost plan and stuff like that. Is there

00:13:36.549 --> 00:13:38.350
anything like this available yet for for these?

00:13:39.259 --> 00:13:41.799
no and and with sentinel i was already wanting

00:13:41.799 --> 00:13:44.879
to make the the little bridge uh the the sentinel

00:13:44.879 --> 00:13:47.279
thing is also really hard people ask me how much

00:13:47.279 --> 00:13:49.899
does it cost but you don't know up front how

00:13:49.899 --> 00:13:52.379
many amounts of logs you're going to ingest there

00:13:52.379 --> 00:13:55.100
so a lot of the times with customers i just did

00:13:55.100 --> 00:13:57.980
a poc a proof of concept i deployed stuff we

00:13:57.980 --> 00:13:59.940
connected stuff and then we monitored it for

00:13:59.940 --> 00:14:03.059
a week two weeks and then we were able to extrapolate

00:14:03.059 --> 00:14:05.200
that into the future right to get a little bit

00:14:05.200 --> 00:14:08.399
of a guesstimation on the cost i think the same

00:14:08.559 --> 00:14:12.679
applies here regarding the central cost aspect.

00:14:12.940 --> 00:14:15.500
I did some stuff with the auto scaling of the

00:14:15.500 --> 00:14:18.960
commitment tiers. Indeed, that's right. And that

00:14:18.960 --> 00:14:21.259
you can do here with a simple PowerShop script

00:14:21.259 --> 00:14:24.679
I made as well. But you can extend into it and

00:14:24.679 --> 00:14:27.779
make it an auto scaling script, if you will.

00:14:27.899 --> 00:14:30.960
But yeah, again, I'm not sure if you want to

00:14:30.960 --> 00:14:34.840
auto scale this up because people can go through

00:14:34.840 --> 00:14:38.059
the issues like candy and you won't be happy

00:14:38.059 --> 00:14:41.480
with the bill. But yeah, I think just deploy

00:14:41.480 --> 00:14:44.000
a couple of them, see how it works for you. I

00:14:44.000 --> 00:14:46.620
think is the best approach for now. That makes

00:14:46.620 --> 00:14:51.049
sense. So. Regarding the actual usage, once you

00:14:51.049 --> 00:14:54.169
have the SCUs running, like I said, you get a

00:14:54.169 --> 00:14:57.049
co -pilot button in a couple of portals. And

00:14:57.049 --> 00:14:59.370
with Defender, I think there are already a lot

00:14:59.370 --> 00:15:02.929
of obvious benefits there. So like I mentioned,

00:15:03.009 --> 00:15:06.830
the incident is summarized as well. So you get

00:15:06.830 --> 00:15:09.289
a nice summarization of what happened. But you

00:15:09.289 --> 00:15:11.830
can also go into and use predefined prompts,

00:15:11.970 --> 00:15:15.090
like show me exact command line, which was executed

00:15:15.090 --> 00:15:17.190
by the user in the incident or something, or

00:15:17.190 --> 00:15:19.970
summarize. which lateral movement techniques

00:15:19.970 --> 00:15:22.269
were observed in this incident or something like

00:15:22.269 --> 00:15:25.789
that. And you can even branch out to the standalone

00:15:25.789 --> 00:15:28.269
security portal, which looks a little bit like

00:15:28.269 --> 00:15:31.889
the chat GPT interface where security copilot

00:15:31.889 --> 00:15:34.049
will gather, for example, your sign in logs,

00:15:34.190 --> 00:15:36.049
your security events from your domain controllers

00:15:36.049 --> 00:15:39.429
and will visualize and tell you anomalies and

00:15:39.429 --> 00:15:43.590
why stuff happened like it did. And again, this

00:15:43.590 --> 00:15:47.919
is really powerful stuff. I really see the benefits

00:15:47.919 --> 00:15:51.399
in there. So, yeah, that's why I think people

00:15:51.399 --> 00:15:53.820
should get started with it. And with Entra as

00:15:53.820 --> 00:15:56.159
well. So, for example, conditional access policies,

00:15:56.220 --> 00:15:59.279
I find it very confusing sometimes when customers

00:15:59.279 --> 00:16:02.299
have loads of conditional access policies. What

00:16:02.299 --> 00:16:04.940
is doing what and what is the actual net sum

00:16:04.940 --> 00:16:09.990
of results of all those policies? With Copilot

00:16:09.990 --> 00:16:12.529
enabled, it gets much easier. You can just ask

00:16:12.529 --> 00:16:15.370
it in natural language what's happening. You

00:16:15.370 --> 00:16:17.990
can say, for example, summarize all CA policies

00:16:17.990 --> 00:16:20.529
that apply to this user and describe their impact

00:16:20.529 --> 00:16:23.570
or show me the 10 most recent sign -ins from

00:16:23.570 --> 00:16:27.429
this user and summarize all the MFA methods that

00:16:27.429 --> 00:16:29.909
user used in those sign -ins. And then you just

00:16:29.909 --> 00:16:32.490
get the results gathered from all the individual

00:16:32.490 --> 00:16:36.149
log sources. And with Intune as well, you can

00:16:36.149 --> 00:16:38.960
list non -compliant devices. devices, missing

00:16:38.960 --> 00:16:42.519
disk encryptions just by asking copilot. And

00:16:42.519 --> 00:16:45.000
that's so much easier than going through all

00:16:45.000 --> 00:16:48.899
the information, of course. So again, powerful

00:16:48.899 --> 00:16:55.399
stuff. I advise everybody to revisit it, deploy

00:16:55.399 --> 00:16:58.259
a couple of issues. play around with it a bit,

00:16:58.360 --> 00:17:02.860
remove them. And I think you're quickly surprised

00:17:02.860 --> 00:17:05.599
how powerful it is. And then you can probably

00:17:05.599 --> 00:17:07.859
set up maybe a business case to have a couple

00:17:07.859 --> 00:17:10.180
of those issues running during business hours

00:17:10.180 --> 00:17:11.960
or something like that. Or maybe if you're working

00:17:11.960 --> 00:17:14.539
on a project or you're troubleshooting or you

00:17:14.539 --> 00:17:16.339
want to minimize your conditional access policies,

00:17:16.460 --> 00:17:19.759
for example, deploy a couple of issues, play

00:17:19.759 --> 00:17:21.880
around to copilot, get some insights, remove

00:17:21.880 --> 00:17:24.000
copilot again, and then get the rest of your

00:17:24.000 --> 00:17:27.710
project done. Yeah. Wow. Okay. Well, it definitely

00:17:27.710 --> 00:17:30.289
sounds like that's something worth re -looking

00:17:30.289 --> 00:17:35.609
at. And my hands -on with this outside of just

00:17:35.609 --> 00:17:40.710
labby stuff is limited. But yeah, the concern

00:17:40.710 --> 00:17:43.009
has always been around the cost, right? Like

00:17:43.009 --> 00:17:45.269
I said, we've had some very interesting customer

00:17:45.269 --> 00:17:47.089
conversations, but nothing that's kind of come

00:17:47.089 --> 00:17:50.390
to full -scale fruition just yet, right? I think

00:17:50.390 --> 00:17:52.230
a lot of folks, a lot of organizations are kind

00:17:52.230 --> 00:17:55.009
of dipping their toe here. um so nice to know

00:17:55.009 --> 00:17:57.430
that there's a more controlled way to to be able

00:17:57.430 --> 00:18:01.900
to see what it can do And I think if you run

00:18:01.900 --> 00:18:04.059
it for a couple of hours or maybe one or two

00:18:04.059 --> 00:18:06.440
hours and you have a couple of SCUs burned through,

00:18:06.539 --> 00:18:09.920
it's not that expensive. It's only a couple of

00:18:09.920 --> 00:18:13.700
tens of bucks, right? So you can probably validate

00:18:13.700 --> 00:18:17.400
that. But yeah, you still need to be careful

00:18:17.400 --> 00:18:19.799
and you're not charged on second or minute like

00:18:19.799 --> 00:18:22.220
with some other Azure units, you're charged by

00:18:22.220 --> 00:18:25.599
the hour. So even if you use it for one second

00:18:25.599 --> 00:18:27.420
within an hour, you're charged for that hour.

00:18:27.680 --> 00:18:31.430
But again, with $4 each, and if you keep if you

00:18:31.430 --> 00:18:33.910
keep the uptime as low as possible i think it's

00:18:33.910 --> 00:18:38.329
manageable and uh probably worth trying yeah

00:18:38.329 --> 00:18:41.509
that makes sense yeah and the second topic of

00:18:41.509 --> 00:18:43.890
today chris tell us everybody everything about

00:18:43.890 --> 00:18:47.390
the interest suite interest suite yeah so you

00:18:47.390 --> 00:18:49.769
know as i was saying sort of in the intro here

00:18:49.769 --> 00:18:52.200
i was i was really wanting to do a bit of a deep

00:18:52.200 --> 00:18:55.079
dive into the global secure access components,

00:18:55.440 --> 00:18:57.980
right? Which is really your private access, internet

00:18:57.980 --> 00:19:00.140
access. But I thought, you know what? Some folks

00:19:00.140 --> 00:19:03.519
may not have heard of IntraSuite or they may

00:19:03.519 --> 00:19:05.200
have heard of IntraSuite and may not actually

00:19:05.200 --> 00:19:07.400
understand exactly what we're talking about when

00:19:07.400 --> 00:19:09.079
we say IntraSuite, right? Because I feel like

00:19:09.079 --> 00:19:11.380
the word in the terminology suite could mean

00:19:11.380 --> 00:19:14.079
a bunch of things and maybe confuse folks where

00:19:14.079 --> 00:19:16.039
they may be thinking, well, we're just talking

00:19:16.039 --> 00:19:18.259
about Intra, right? Well, I mean, yes and no,

00:19:18.319 --> 00:19:21.559
we are. you know, in a sense, we are talking

00:19:21.559 --> 00:19:23.779
about Entra, but it's components of Entra, right?

00:19:23.839 --> 00:19:25.920
And I think Entra has, you know, I'm sure we're

00:19:25.920 --> 00:19:28.140
all kind of familiar with Entra, has grown into

00:19:28.140 --> 00:19:31.140
this platform now that is more than just what

00:19:31.140 --> 00:19:33.180
used to be called Azure AD, right? It's, you

00:19:33.180 --> 00:19:35.420
know, we have Entra ID, but it's just one component

00:19:35.420 --> 00:19:41.319
of a lot of different things. And so what Entra

00:19:41.319 --> 00:19:44.660
Suite is, is it's actually a sort of a separate,

00:19:44.839 --> 00:19:49.309
if you will, like... uh how do we call it we'll

00:19:49.309 --> 00:19:51.069
call it a skew if you will right because I think

00:19:51.069 --> 00:19:53.529
calling it a skew might actually help folks understand

00:19:53.529 --> 00:19:55.390
what we're talking about so when you think his

00:19:55.390 --> 00:20:00.230
um traditionally not fcu right Yeah, yeah, yeah.

00:20:03.150 --> 00:20:05.150
Traditionally, when you think of Entra, you think

00:20:05.150 --> 00:20:08.609
of Entra IDP1 or Entra IDP2, and those things

00:20:08.609 --> 00:20:12.349
still exist, right? So I would imagine most folks,

00:20:12.569 --> 00:20:15.289
unless you have a very basic and very small environment,

00:20:15.369 --> 00:20:21.500
you probably have some Entra IDP1. bits or licenses

00:20:21.500 --> 00:20:23.220
in your environment and that you know you can

00:20:23.220 --> 00:20:25.460
buy those obviously as standalone but if you

00:20:25.460 --> 00:20:28.140
if you have business premium or if you have um

00:20:28.140 --> 00:20:32.519
m365e3 then you know you get um enter idp1 right

00:20:32.519 --> 00:20:35.039
so it's a licensing model um and then you know

00:20:35.039 --> 00:20:37.160
the next one up from that is enter idp2 which

00:20:37.160 --> 00:20:40.759
again you know if you have m365e5 you'll be familiar

00:20:40.759 --> 00:20:44.339
with p2 it kind of layers on um some some advanced

00:20:44.339 --> 00:20:47.299
capabilities and advanced features um and so

00:20:47.299 --> 00:20:50.569
we can think of uh enter suite as sort of something

00:20:50.569 --> 00:20:54.230
similar where it's a a combination of multiple

00:20:54.230 --> 00:20:56.589
products that you could go off and buy these

00:20:56.589 --> 00:20:59.130
individually but you're better off if you license

00:20:59.130 --> 00:21:02.509
them together from a cost perspective. Right.

00:21:02.549 --> 00:21:05.589
So, for example, I think U .S. dollars, if you

00:21:05.589 --> 00:21:07.809
were to buy the interest rate, it's I think about

00:21:07.809 --> 00:21:11.349
12 bucks or $12 U .S. per per user per month.

00:21:12.009 --> 00:21:15.069
But what that gives you, though, is is, you know,

00:21:15.069 --> 00:21:17.609
a lot of capability. Right. So so the things

00:21:17.609 --> 00:21:20.450
that make up intro are what we would refer to

00:21:20.450 --> 00:21:22.569
as global secure access. So you may have also

00:21:22.569 --> 00:21:24.789
heard in the early days of this, it be referred

00:21:24.789 --> 00:21:28.289
to as SEC, the secure service edge, which is.

00:21:28.720 --> 00:21:31.240
um sort of microsoft solution for for zero trust

00:21:31.240 --> 00:21:35.059
network access so uh we have uh enter private

00:21:35.059 --> 00:21:40.220
access um which is really is is meant for providing

00:21:40.220 --> 00:21:43.099
secure access to applications that you own right

00:21:43.099 --> 00:21:45.680
if you think about um maybe you have some applications

00:21:45.680 --> 00:21:48.470
in your data center Historically, maybe those

00:21:48.470 --> 00:21:50.650
were published through a firewall or something.

00:21:51.029 --> 00:21:53.349
It's applications that you own that are in your

00:21:53.349 --> 00:21:55.390
data center that you now want to provide access

00:21:55.390 --> 00:21:58.210
to folks that are outside of the organization.

00:21:59.730 --> 00:22:04.339
The second component of that is... internet access,

00:22:04.700 --> 00:22:06.680
which is the other way around, right? If you

00:22:06.680 --> 00:22:08.740
think about it, it's providing and controlling

00:22:08.740 --> 00:22:13.259
access to resources and maybe applications that

00:22:13.259 --> 00:22:15.799
you don't own. You may own them, but they are

00:22:15.799 --> 00:22:18.519
not in your data center. There may be SaaS platforms

00:22:18.519 --> 00:22:21.740
or SaaS products, or it could just be web traffic

00:22:21.740 --> 00:22:23.920
in general, right? So you could think of things

00:22:23.920 --> 00:22:26.799
like that. In that way, it's a little bit similar,

00:22:26.859 --> 00:22:29.640
I think, compared to Zscaler, for example. You're

00:22:29.640 --> 00:22:31.660
just tunneling out all the outbound internet

00:22:31.660 --> 00:22:36.440
access. 100%, yes. It is definitely similar to

00:22:36.440 --> 00:22:38.680
what you would think of traditionally maybe as

00:22:38.680 --> 00:22:42.380
a proxy server or a more modern version of that,

00:22:42.420 --> 00:22:45.119
which is Zscaler. It's a way to control that

00:22:45.119 --> 00:22:48.740
sort of outbound internet access. on networks

00:22:48.740 --> 00:22:51.519
that you don't own right and i think that's where

00:22:51.519 --> 00:22:55.839
zscaler has become so um popular is that uh a

00:22:55.839 --> 00:22:58.500
lot of folks are working on remote networks home

00:22:58.500 --> 00:23:00.880
networks things like that grandma's house is

00:23:00.880 --> 00:23:02.720
the scenario that we use very often when we talk

00:23:02.720 --> 00:23:05.259
to customers um because you're working on a network

00:23:05.259 --> 00:23:07.220
that you have no control over but you're still

00:23:07.220 --> 00:23:09.240
accessing resources that you want to be you know

00:23:09.240 --> 00:23:11.720
certain about the security of the connection

00:23:11.720 --> 00:23:15.799
so so Perfectly summarized there. And then there

00:23:15.799 --> 00:23:17.940
are a few other things that sort of form part

00:23:17.940 --> 00:23:22.059
of the Entra suite, which is your identity governance

00:23:22.059 --> 00:23:24.859
stuff. So if you think about identity lifecycle

00:23:24.859 --> 00:23:28.039
management and onboarding, that type of thing,

00:23:28.119 --> 00:23:34.210
you have identity protection, which is... risk

00:23:34.210 --> 00:23:38.130
-based access. So if you think about, you know,

00:23:38.150 --> 00:23:39.950
conditional access, if you use conditional access,

00:23:40.230 --> 00:23:42.430
you can enable risk -based conditional access

00:23:42.430 --> 00:23:45.190
where dynamically, whether there's a, you know,

00:23:45.190 --> 00:23:47.650
based on user sign -in risk or things like that,

00:23:47.690 --> 00:23:53.029
right? That stuff is part of Entra Sweden. I'm

00:23:53.029 --> 00:23:54.950
pretty sure that's also something that is part

00:23:54.950 --> 00:24:00.019
of Entra IDP2 as well. And then... something

00:24:00.019 --> 00:24:03.539
called verified ID or verified ID premium. And

00:24:03.539 --> 00:24:07.859
this is the concept of decentralized IDs or DIDs,

00:24:07.960 --> 00:24:12.039
which you may have heard about. It's been a lot

00:24:12.039 --> 00:24:14.859
of talk about that in the past and recently.

00:24:15.240 --> 00:24:19.000
And in fact, a fellow MVP, Michael Van Horenbeek.

00:24:19.849 --> 00:24:22.509
recently launched his own podcast um and i think

00:24:22.509 --> 00:24:25.289
he's calling it uh uh the zero trust zone podcast

00:24:25.289 --> 00:24:27.589
and um one of the first episodes of the first

00:24:27.589 --> 00:24:29.710
episode was very much covering this topic of

00:24:29.710 --> 00:24:33.710
decentralized ids and and why we need them right

00:24:33.710 --> 00:24:37.309
and um verified id uh premium is that sort of

00:24:37.309 --> 00:24:42.829
um validation and face ID type stuff that Entra

00:24:42.829 --> 00:24:44.730
provides, right? So you've got those sort of

00:24:44.730 --> 00:24:47.230
five things, private access, internet access,

00:24:47.809 --> 00:24:49.509
governance protection, and then the verified

00:24:49.509 --> 00:24:53.769
ID bits, right? And like I said, from a licensing

00:24:53.769 --> 00:24:55.809
perspective, those are sort of bundled into a

00:24:55.809 --> 00:24:58.990
bundle that we call Entra Suite. And you could

00:24:58.990 --> 00:25:04.210
kind of buy those as a sort of set of functionalities,

00:25:04.250 --> 00:25:06.089
right? Instead of buying them one at a time.

00:25:06.170 --> 00:25:09.289
And I think, again, you know, from a cost perspective,

00:25:09.430 --> 00:25:13.789
I think to get private access by itself, I think

00:25:13.789 --> 00:25:15.789
it's about half the price of what you would pay

00:25:15.789 --> 00:25:17.589
for the whole suite, right? Where you get all

00:25:17.589 --> 00:25:21.569
of the capabilities. So it almost is a, you know,

00:25:21.589 --> 00:25:23.690
I don't carry the organization's checkbook, but

00:25:23.690 --> 00:25:25.650
it is almost a bit of a no -brainer when you

00:25:25.650 --> 00:25:30.829
think about it in those terms. So to look at

00:25:30.829 --> 00:25:33.650
some of these from like a real world use case

00:25:33.650 --> 00:25:36.940
perspective, right? You know, I think... um to

00:25:36.940 --> 00:25:39.160
tackle the the internet access one as you said

00:25:39.160 --> 00:25:42.019
coast very much a z scalar play and you know

00:25:42.019 --> 00:25:43.599
what we'll find is that it's probably never going

00:25:43.599 --> 00:25:45.779
to be z scalar but it's probably going to be

00:25:45.779 --> 00:25:48.700
what most organizations need from that perspective

00:25:48.700 --> 00:25:51.119
so you know you're looking at your sort of um

00:25:51.119 --> 00:25:53.980
web content filtering right being able to create

00:25:53.980 --> 00:25:57.420
policies that um restrict or block access to

00:25:58.109 --> 00:26:00.609
uh websites and things like that um for for your

00:26:00.609 --> 00:26:03.450
users what i really like about this is is is

00:26:03.450 --> 00:26:04.789
a couple of things the way you would actually

00:26:04.789 --> 00:26:07.890
deploy this is um there's a global secure access

00:26:07.890 --> 00:26:10.670
client that you can run on devices so if you

00:26:10.670 --> 00:26:15.990
think about um maybe you have a fleet of um you

00:26:15.990 --> 00:26:18.529
know Surface laptops or devices or things like

00:26:18.529 --> 00:26:21.670
that that you manage through Intune, you can

00:26:21.670 --> 00:26:25.230
push the client down to those devices. And wherever

00:26:25.230 --> 00:26:27.769
those users go, whether they're at Starbucks

00:26:27.769 --> 00:26:32.329
or grandma's house or wherever, you can push

00:26:32.329 --> 00:26:34.170
the same policies and enforce the same policies

00:26:34.170 --> 00:26:37.269
on what they're connecting to and how they connect.

00:26:37.450 --> 00:26:40.569
And this layers in with conditional access. So

00:26:40.569 --> 00:26:43.910
it can be really powerful as far as restricting.

00:26:44.559 --> 00:26:47.160
access to applications from only certain networks

00:26:47.160 --> 00:26:49.579
and all that type of thing. If you think about

00:26:49.579 --> 00:26:53.640
how granular conditional access can be, it's

00:26:53.640 --> 00:26:57.779
really, really powerful stuff. If we look at

00:26:57.779 --> 00:27:00.559
the private access piece, I really like this

00:27:00.559 --> 00:27:02.099
because I think this solves a lot of challenges

00:27:02.099 --> 00:27:06.180
for businesses who have applications in their

00:27:06.180 --> 00:27:08.619
environment that are old, right? If you think

00:27:08.619 --> 00:27:12.670
about all of those crusty button. and everyone

00:27:12.670 --> 00:27:16.650
has those yes those exactly now you may be thinking

00:27:16.650 --> 00:27:18.210
if you listen to this and you've been around

00:27:18.210 --> 00:27:19.670
for a while you might be going well this sounds

00:27:19.670 --> 00:27:22.170
very much like something called azure app proxy

00:27:22.170 --> 00:27:25.829
right and and you'd be right in that it is very

00:27:25.829 --> 00:27:28.150
much built on on that technology of azure app

00:27:28.150 --> 00:27:31.009
proxy where you know you could essentially take

00:27:31.009 --> 00:27:33.569
any web service in azure and you could publish

00:27:33.569 --> 00:27:36.109
that through azure as a front door and then you're

00:27:36.109 --> 00:27:39.460
layering in modern security on top of that. Now

00:27:39.460 --> 00:27:41.480
with this, this kind of extends it where it's

00:27:41.480 --> 00:27:44.700
no longer just limited to applications that are

00:27:44.700 --> 00:27:47.740
web apps, right? You can take this a little bit

00:27:47.740 --> 00:27:49.720
more granular. And like I said, we'll dig into

00:27:49.720 --> 00:27:52.680
some of these in future episodes, but it really

00:27:52.680 --> 00:27:55.440
does buy you time. And I want to stress that

00:27:55.440 --> 00:27:58.339
if you're an organization that has legacy applications

00:27:58.339 --> 00:28:00.680
that don't support MFA and things like that,

00:28:00.779 --> 00:28:04.460
this will buy you time to fix those applications

00:28:04.460 --> 00:28:07.579
because you can... provide access to your workforce

00:28:07.579 --> 00:28:10.220
through, again, the beauty of conditional access

00:28:10.220 --> 00:28:14.180
and, you know, conditional access policies and

00:28:14.180 --> 00:28:16.799
layer in multifactor authentication and all of

00:28:16.799 --> 00:28:20.559
that step up stuff that you want to do onto an

00:28:20.559 --> 00:28:22.519
old application that isn't necessarily aware

00:28:22.519 --> 00:28:27.460
of. of of of those modern protocols um the connection

00:28:27.460 --> 00:28:29.640
is is outbound only so you're not punching all

00:28:29.640 --> 00:28:31.980
these holes in your firewall um and it buys you

00:28:31.980 --> 00:28:34.339
time to be able to then start working on refactoring

00:28:34.339 --> 00:28:36.460
those applications and being able to turn those

00:28:36.460 --> 00:28:38.259
things into things that are a little bit more

00:28:38.259 --> 00:28:40.680
modern and maybe support modern uh modern protocols

00:28:40.680 --> 00:28:44.180
so those two things also a great vpn replacement

00:28:44.180 --> 00:28:47.440
but we we i think we should devote a separate

00:28:47.440 --> 00:28:50.839
episode on this but uh people would say i already

00:28:50.839 --> 00:28:53.970
have a vpn but i think this is in much aspects

00:28:53.970 --> 00:28:57.509
much better. Yes, 100%. Because again, your VPN

00:28:57.509 --> 00:29:00.809
is that once you're connected to the VPN, generally

00:29:00.809 --> 00:29:02.750
you have access to whatever's on the network,

00:29:02.869 --> 00:29:05.690
right? Whereas with this, you're publishing those

00:29:05.690 --> 00:29:07.769
applications one at a time, you're layering conditional

00:29:07.769 --> 00:29:11.210
access onto each application, and it can be targeted

00:29:11.210 --> 00:29:13.549
to completely different groups. So you've got

00:29:13.549 --> 00:29:16.009
that segmentation going on as well. So if you

00:29:16.009 --> 00:29:18.029
believe in sort of zero trust and zero trust

00:29:18.029 --> 00:29:20.150
principles, this really is something that should

00:29:20.150 --> 00:29:22.940
excite you. And then we're not even touching

00:29:22.940 --> 00:29:26.980
on admins not upgrading the VPN appliance firmware

00:29:26.980 --> 00:29:29.579
or forgetting that they still have an account

00:29:29.579 --> 00:29:33.059
called Cisco with a password Cisco on it and

00:29:33.059 --> 00:29:35.380
granting everybody access. Yes, I think that

00:29:35.380 --> 00:29:39.759
sounds very familiar, Colonial Pipeline, or any

00:29:39.759 --> 00:29:41.460
number of other hacks that have happened in the

00:29:41.460 --> 00:29:44.019
last few years. But you're absolutely right.

00:29:44.180 --> 00:29:46.640
The security risks with the older technologies

00:29:46.640 --> 00:29:49.559
is fraught, right? Look, I don't know about you.

00:29:49.599 --> 00:29:51.720
I work with lots of different... customers and

00:29:51.720 --> 00:29:54.319
every customer i work with has a different vpn

00:29:54.319 --> 00:29:56.920
solution so i end up you know now fortunately

00:29:56.920 --> 00:30:00.000
i don't i i don't often work on multiple engagements

00:30:00.000 --> 00:30:02.839
at the same time so usually i you know i have

00:30:02.839 --> 00:30:04.759
the any connect client installed and then when

00:30:04.759 --> 00:30:06.940
the next customer rolls around that gets removed

00:30:06.940 --> 00:30:09.160
and the next thing gets put on and the palo alto

00:30:09.160 --> 00:30:11.759
client goes on but i've always got some client

00:30:11.759 --> 00:30:15.059
uh vpn client on my on my devices because that's

00:30:15.059 --> 00:30:19.299
how we we get access on remote access um so yeah

00:30:19.930 --> 00:30:25.029
Very, very good VPN replacement. So just to kind

00:30:25.029 --> 00:30:29.769
of patch off and finish off on the other parts

00:30:29.769 --> 00:30:31.670
of the suite, which I think are just as important

00:30:31.670 --> 00:30:35.509
to think about is, so ID governance or intra

00:30:35.509 --> 00:30:38.769
-ID governance. Think about that sort of lifecycle

00:30:38.769 --> 00:30:41.470
management piece. How do we automate our onboarding?

00:30:41.910 --> 00:30:45.890
How do we deal with role transitions when folks

00:30:45.890 --> 00:30:48.619
have had... a particular set of permissions they

00:30:48.619 --> 00:30:50.960
move into a different role and they need to now

00:30:50.960 --> 00:30:53.579
sort of assume um you know permissions for whatever

00:30:53.579 --> 00:30:56.480
that new role is right right through to off -boarding

00:30:56.480 --> 00:31:00.559
those folks right oftentimes um one or all of

00:31:00.559 --> 00:31:04.140
these steps uh are kind of missing in a in an

00:31:04.140 --> 00:31:05.900
organization's process right it's really easy

00:31:05.900 --> 00:31:08.640
for them to find um to onboard they onboard stuff

00:31:08.640 --> 00:31:11.839
they have scripts that pull you know, user info

00:31:11.839 --> 00:31:14.039
out of the HR system and they PowerShell stuff

00:31:14.039 --> 00:31:15.859
and they create user accounts with passwords

00:31:15.859 --> 00:31:19.559
and off you go. But the cleanup and the operational

00:31:19.559 --> 00:31:23.619
management of that is often left behind. So that's

00:31:23.619 --> 00:31:25.299
where sort of ID governance comes in. If you

00:31:25.299 --> 00:31:27.839
think about things like access reviews and managing

00:31:27.839 --> 00:31:30.460
access for guests, you know, guests into your

00:31:30.460 --> 00:31:33.500
environment, probably identity management is

00:31:33.500 --> 00:31:35.599
another part of that, which obviously we've talked

00:31:35.599 --> 00:31:38.380
about that a lot in the past. And I think, again,

00:31:38.460 --> 00:31:43.359
to me, PIM is a no -brainer for any business,

00:31:43.500 --> 00:31:47.000
right? Your administrators and your privileged

00:31:47.000 --> 00:31:51.539
users absolutely should have PIM. Yes, you've

00:31:51.539 --> 00:31:54.279
deployed MFA. This is the next thing for you

00:31:54.279 --> 00:31:56.759
to go do is PIM. And that's part of the enter

00:31:56.759 --> 00:32:00.819
ID governance piece. Enter ID protection, which

00:32:00.819 --> 00:32:04.000
I mentioned is very much around sort of risk

00:32:04.000 --> 00:32:07.119
-based conditional access, being able to determine

00:32:07.119 --> 00:32:12.519
based on the users. um uh whether they can access

00:32:12.519 --> 00:32:15.819
data based on on on their user identity or um

00:32:15.819 --> 00:32:18.619
based on their device um and so being able to

00:32:18.619 --> 00:32:20.940
do that type of some sort of threat detection

00:32:20.940 --> 00:32:24.839
piece right um and many instances it can be auto

00:32:24.839 --> 00:32:27.819
uh automatically remediated right so you know

00:32:27.819 --> 00:32:29.200
if you think about a conditional access policy

00:32:29.200 --> 00:32:33.480
where um If you see a sign in that doesn't look

00:32:33.480 --> 00:32:36.759
right, or maybe it's, you know, Coase is usually

00:32:36.759 --> 00:32:38.380
signing in from the Netherlands, but all of a

00:32:38.380 --> 00:32:40.200
sudden Coase is now signing in from Australia.

00:32:40.980 --> 00:32:43.880
Maybe we want to just do another multi -factor

00:32:43.880 --> 00:32:46.200
check on to make sure that this is actually Coase

00:32:46.200 --> 00:32:49.170
and not, you know, someone who might have. stolen

00:32:49.170 --> 00:32:51.549
Coase's identity or what have you right but then

00:32:51.549 --> 00:32:53.410
security co -pilots will just tell the security

00:32:53.410 --> 00:32:55.549
analyst that Coase is probably having fun at

00:32:55.549 --> 00:32:59.250
Chris's place finally he made the trip over that's

00:32:59.250 --> 00:33:03.410
right that's right but yeah so really the anti

00:33:03.410 --> 00:33:05.509
-ID protection stuff really really cool from

00:33:05.509 --> 00:33:07.390
that perspective if you think about risk -based

00:33:07.390 --> 00:33:12.269
access and things like that and then you know

00:33:12.269 --> 00:33:14.869
I had mentioned the verified ID stuff this is

00:33:14.869 --> 00:33:16.569
an area where I think we're going to hear and

00:33:16.569 --> 00:33:19.579
see a lot of a lot more noise this is going to

00:33:19.579 --> 00:33:21.940
really be a sort of a it's it's a um evolving

00:33:21.940 --> 00:33:25.980
area right because the whole concept of decentralized

00:33:25.980 --> 00:33:30.480
identities and and identity validation um is

00:33:30.480 --> 00:33:32.900
is is a big one right and and your scenarios

00:33:32.900 --> 00:33:37.359
here are thinking thinking about uh how do you

00:33:37.359 --> 00:33:39.579
validate that someone is who they say they are

00:33:39.579 --> 00:33:43.000
without having to maintain um you know all of

00:33:43.000 --> 00:33:45.740
their information right so uh if you take the

00:33:45.740 --> 00:33:48.000
the scenario where let's say you're starting

00:33:48.000 --> 00:33:50.960
a new job And as part of your onboarding process,

00:33:51.180 --> 00:33:54.099
your employer needs to see that. So here in Australia,

00:33:54.259 --> 00:33:56.099
you can't work unless you have something called

00:33:56.099 --> 00:33:58.380
work authorization, which means you're legally

00:33:58.380 --> 00:34:00.819
allowed to work in Australia. Or in order for

00:34:00.819 --> 00:34:04.380
me to prove that when I join a company, will

00:34:04.380 --> 00:34:06.339
I have to give them my passport or my birth certificate?

00:34:06.519 --> 00:34:08.179
One of those things to prove that I actually

00:34:08.179 --> 00:34:10.639
am an Australian citizen, right? Now, instead

00:34:10.639 --> 00:34:14.739
of organizations having to keep... a photocopy

00:34:14.739 --> 00:34:17.760
or a picture or what have you of your passport.

00:34:19.079 --> 00:34:23.000
This scenario really is where you go to a third

00:34:23.000 --> 00:34:25.760
party and you say, hey, you guys are a third

00:34:25.760 --> 00:34:28.400
party that validates and verifies that people

00:34:28.400 --> 00:34:31.409
are who they say they are. You keep all of the

00:34:31.409 --> 00:34:33.489
passport stuff. You do passport checks. You know,

00:34:33.510 --> 00:34:36.150
just like you could see, use a third party that

00:34:36.150 --> 00:34:37.710
can do a background check for you, right? I'm

00:34:37.710 --> 00:34:41.409
not sure how in Europe, how often that's done.

00:34:41.610 --> 00:34:43.489
Here in Australia, we don't do background checks

00:34:43.489 --> 00:34:47.070
all that often, I guess. No, really? In the US,

00:34:47.289 --> 00:34:50.010
yeah, in the US, every single job you apply for,

00:34:50.110 --> 00:34:52.250
every single job, you know, they will always

00:34:52.250 --> 00:34:54.889
background check you. And in fact, when I worked

00:34:54.889 --> 00:34:57.409
over there, there were many industries where...

00:34:57.710 --> 00:35:01.949
um if you if you worked you know utilities oil

00:35:01.949 --> 00:35:04.269
and gas they would do another background check

00:35:04.269 --> 00:35:06.050
just before you before you could run with a project

00:35:06.050 --> 00:35:08.130
even even though you know your employer might

00:35:08.130 --> 00:35:10.570
have done one so different countries i think

00:35:10.570 --> 00:35:12.690
do different things but similar to how you would

00:35:12.690 --> 00:35:15.269
trust that the company doing the background check

00:35:15.269 --> 00:35:18.400
has done their their job properly you know you

00:35:18.400 --> 00:35:20.800
would similarly you would trust that uh you know

00:35:20.800 --> 00:35:23.059
third party would be able to validate that chris

00:35:23.059 --> 00:35:26.360
is in fact uh an australian citizen can and is

00:35:26.360 --> 00:35:28.900
allowed to work uh in australia and and so because

00:35:28.900 --> 00:35:32.340
of by virtue of that um you know you you you

00:35:32.340 --> 00:35:34.019
don't need to submit all these other things so

00:35:34.019 --> 00:35:36.619
it's a very interesting space i think it's evolving

00:35:36.619 --> 00:35:40.280
as i said um i think right now um intro will

00:35:40.280 --> 00:35:43.429
support i think 11 or 12 different you know third

00:35:43.429 --> 00:35:45.309
-party providers for these so if you think about

00:35:45.309 --> 00:35:48.130
uh again if you're in the US you might have seen

00:35:48.130 --> 00:35:50.969
might be familiar with clear who um you know

00:35:50.969 --> 00:35:53.190
if you go to any airport you can you can do the

00:35:53.190 --> 00:35:57.190
sort of um fast boarding or fast um uh passport

00:35:57.190 --> 00:35:59.829
check thing with with clear they're one of the

00:35:59.829 --> 00:36:01.989
the providers for example and I think they're

00:36:02.269 --> 00:36:04.809
10 or 12 other ones but it really anyone who

00:36:04.809 --> 00:36:07.730
has an api um you can kind of tie into that workflow

00:36:07.730 --> 00:36:10.849
right so um this sort of verified id thing is

00:36:10.849 --> 00:36:14.650
going to become i think um you know it's gonna

00:36:14.650 --> 00:36:16.969
it's gonna become more heavily used in in um

00:36:16.969 --> 00:36:21.289
in future hey in europe a lot of folks want sort

00:36:21.289 --> 00:36:23.809
of independence of stored identities and stuff

00:36:23.809 --> 00:36:25.969
like that right there's this real push at the

00:36:25.969 --> 00:36:30.480
moment um uh to get away from centralized uh

00:36:30.480 --> 00:36:34.420
databases of stuff right so yeah great he's a

00:36:34.420 --> 00:36:37.320
big concern and uh and also saw some great demos

00:36:37.320 --> 00:36:39.900
with verified id you can integrate it for example

00:36:39.900 --> 00:36:42.579
with uh i don't know if you want to provide your

00:36:42.579 --> 00:36:45.199
employers to have a discount on a with a local

00:36:45.199 --> 00:36:48.019
laptop shop or something like that you can actually

00:36:48.019 --> 00:36:50.239
have them use verified to verify that they're

00:36:50.239 --> 00:36:52.480
working for your company stuff like that that's

00:36:52.480 --> 00:36:54.719
right and i think the key the key thing here

00:36:54.719 --> 00:36:59.690
is because um your identity is so much the parameters

00:36:59.690 --> 00:37:01.769
that make up your identity can differ depending

00:37:01.769 --> 00:37:04.630
on the requirement right so like if you if you're

00:37:04.630 --> 00:37:07.869
going to um in that instance you're buying a

00:37:07.869 --> 00:37:10.329
laptop um and all you need to do is prove that

00:37:10.329 --> 00:37:14.210
you work for you know abc .com or abc you know

00:37:14.210 --> 00:37:17.510
inc um that's all that's the only piece of of

00:37:17.510 --> 00:37:20.250
your identity that they need to verify they don't

00:37:20.250 --> 00:37:22.989
also need to give them um you know your date

00:37:22.989 --> 00:37:25.230
of birth and and and all of these other things

00:37:25.230 --> 00:37:26.989
because those things may not be needed right

00:37:26.989 --> 00:37:29.130
similarly if you're going to the liquor store

00:37:29.130 --> 00:37:32.110
to buy you know a bottle of whiskey like you

00:37:32.110 --> 00:37:34.130
you only need to prove that you're over 21 or

00:37:34.130 --> 00:37:36.530
over 18 whatever your your drinking age is you

00:37:36.530 --> 00:37:38.590
don't also need to give them your financial statements

00:37:38.590 --> 00:37:41.269
and um you know your home address and all of

00:37:41.269 --> 00:37:43.789
those things so this is a really beautiful thing

00:37:43.789 --> 00:37:45.789
where you know being able to just provide the

00:37:45.789 --> 00:37:48.949
information that is needed um and it's not you

00:37:48.949 --> 00:37:52.550
know stored in you know by every organization

00:37:52.550 --> 00:37:54.909
out there that you interact with. So I think

00:37:54.909 --> 00:37:56.429
watch the space. It's going to be really good.

00:37:56.489 --> 00:37:58.550
And like I said, I think, you know, if you're

00:37:58.550 --> 00:38:00.489
interested in the verified ID stuff, definitely

00:38:00.489 --> 00:38:04.070
check out MBH's podcast. Maybe I'll put a link

00:38:04.070 --> 00:38:06.510
in the show notes. His episode on this is really,

00:38:06.530 --> 00:38:13.110
really great. Definitely. And outside of that,

00:38:13.190 --> 00:38:15.110
I think, you know, yeah, we'll definitely be

00:38:15.110 --> 00:38:17.510
doing some deeper dives into some of these in

00:38:17.510 --> 00:38:20.710
our next episode where, you know, we'll look

00:38:20.710 --> 00:38:23.030
at internet access and we'll look at private

00:38:23.030 --> 00:38:27.000
access as well. Yeah, I think we can fill individual

00:38:27.000 --> 00:38:30.619
episodes with each of those features. Absolutely.

00:38:30.639 --> 00:38:33.659
We can. Yeah. And maybe good to summarize again

00:38:33.659 --> 00:38:36.119
for the listeners that a lot of this stuff you

00:38:36.119 --> 00:38:38.420
touched on, they probably already have it available

00:38:38.420 --> 00:38:40.519
in their environment. Because if you have P1

00:38:40.519 --> 00:38:43.659
or P2, some of those features like identity protection,

00:38:44.039 --> 00:38:48.079
verified ID are already available. Some specific

00:38:48.079 --> 00:38:50.679
features and the private access is exclusive

00:38:50.679 --> 00:38:53.539
to the Entra suite license. But a lot of the

00:38:53.539 --> 00:38:56.500
stuff is already covered. p1 p2 yeah absolutely

00:38:56.500 --> 00:38:58.960
it is yeah and i think you know to really the

00:38:58.960 --> 00:39:01.099
only thing additional thing to call out there

00:39:01.099 --> 00:39:03.539
is that you know to get started with um enter

00:39:03.539 --> 00:39:06.579
id or the sorry the enter suite uh you need a

00:39:06.579 --> 00:39:10.239
intra idp one license that's your sort of minimum

00:39:10.239 --> 00:39:12.500
baseline but other than that um you may already

00:39:12.500 --> 00:39:15.480
have some of these things verify id i think is

00:39:15.480 --> 00:39:18.179
there is a free tier which i think does something

00:39:18.179 --> 00:39:23.159
like fifty thousand um uh fifty thousand what's

00:39:23.159 --> 00:39:26.360
the, is it lookups or validations per year or

00:39:26.360 --> 00:39:28.679
something like that? It's a very generous free

00:39:28.679 --> 00:39:31.440
tier. And I think the only thing that it doesn't

00:39:31.440 --> 00:39:34.860
include is the face check. So there's a, you

00:39:34.860 --> 00:39:37.699
know, the face check or face authentication piece

00:39:37.699 --> 00:39:41.380
that uses Azure Cognitive Services is part of

00:39:41.380 --> 00:39:46.260
the premium verified ID SKU. But the rest of

00:39:46.260 --> 00:39:48.670
that stuff. Yeah, very good call out. It's already

00:39:48.670 --> 00:39:51.050
probably available in your tenant. So have a

00:39:51.050 --> 00:39:55.210
look at it and see what sort of fantastic. We'll

00:39:55.210 --> 00:39:57.469
add a link to the show notes. Microsoft obviously

00:39:57.469 --> 00:40:02.250
has a nice table where it shows what feature

00:40:02.250 --> 00:40:06.289
is in which specific tier. Yes, and I have included

00:40:06.289 --> 00:40:12.630
a picture to the M365 maps sort of breakdown

00:40:12.630 --> 00:40:14.500
for this as well, just to kind of help. wrap

00:40:14.500 --> 00:40:17.199
your brain around it. Licensing is hard, man.

00:40:17.820 --> 00:40:22.900
It's difficult, isn't it? I wanted to say I want

00:40:22.900 --> 00:40:25.179
to stay away as much from that as possible because

00:40:25.179 --> 00:40:28.460
it's really complex. That's right. That's right.

00:40:28.619 --> 00:40:33.199
But that's Intro Suite. We'll look forward to

00:40:33.199 --> 00:40:35.440
diving into some of the other ones in future

00:40:35.440 --> 00:40:38.199
episodes. But yeah, before we sign off, tell

00:40:38.199 --> 00:40:41.409
us about our community project. Yeah, for this

00:40:41.409 --> 00:40:45.550
month's community project, I wanted to put fellow

00:40:45.550 --> 00:40:50.610
MVP Morten Knudsen in the spotlight. Or perhaps

00:40:50.610 --> 00:40:53.409
I'm butchering his name a bit. I was just going

00:40:53.409 --> 00:40:55.670
to say that I'm really glad you pronounced that

00:40:55.670 --> 00:40:57.690
and not me because I would have butchered it.

00:40:58.250 --> 00:41:03.550
Well, Morten is from Denmark, and he's all over

00:41:03.550 --> 00:41:06.150
the place. He's speaking at events. He's writing

00:41:06.150 --> 00:41:09.929
blogs. He's organizing Express Live Denmark as

00:41:09.929 --> 00:41:14.630
well, for example. So he's a big contribution

00:41:14.630 --> 00:41:18.429
to the community. But he actually demoed something

00:41:18.429 --> 00:41:20.449
on Express Live in the Netherlands a couple of

00:41:20.449 --> 00:41:22.210
weeks ago, and I really wanted to put this in

00:41:22.210 --> 00:41:24.190
the spotlight since I was talking about security

00:41:24.190 --> 00:41:27.599
co -pilot. And the fact that AI can be very expensive.

00:41:29.019 --> 00:41:31.599
Morten did the other way around. He showed us.

00:41:32.230 --> 00:41:35.829
how you can run your own AI in Azure AI Foundry

00:41:35.829 --> 00:41:39.530
and keep the cost as low as possible if you want

00:41:39.530 --> 00:41:41.969
and integrate it into PowerShell. And I think

00:41:41.969 --> 00:41:44.789
it was a nice project of him. He shared everything,

00:41:44.909 --> 00:41:46.929
obviously, online, the scripts and everything.

00:41:47.150 --> 00:41:51.510
And the thing that he did, he integrated AI in

00:41:51.510 --> 00:41:54.590
PowerShell and he made a, what was it called,

00:41:54.710 --> 00:41:59.760
a PIM role advisor. You touched on PIM, but you

00:41:59.760 --> 00:42:02.820
also remember that it sometimes can be hard to

00:42:02.820 --> 00:42:06.099
determine. what role you need as least privilege,

00:42:06.320 --> 00:42:09.159
right? To do something. You don't want to activate

00:42:09.159 --> 00:42:12.260
global admin whenever you're just doing some

00:42:12.260 --> 00:42:15.380
simple stuff. So the PIM role advisor script

00:42:15.380 --> 00:42:18.000
in PowerShell, you can just ask a natural language

00:42:18.000 --> 00:42:20.920
in PowerShell. I just want to do this or that,

00:42:21.059 --> 00:42:23.639
create an app or register this or make this change

00:42:23.639 --> 00:42:26.179
or whatever. And then the AI will look in your

00:42:26.179 --> 00:42:28.380
environment, see what roles you have, custom

00:42:28.380 --> 00:42:30.599
roles, which groups you assign to them. And then

00:42:30.599 --> 00:42:32.719
it will just come back with a result. Well, you

00:42:32.719 --> 00:42:34.510
need to... might have pimped this or that group

00:42:34.510 --> 00:42:38.250
and this one's least privileged. This is obviously

00:42:38.250 --> 00:42:41.670
just a bit of a tech demo, but it did trigger

00:42:41.670 --> 00:42:45.010
me that integrating AI and PowerShell can be

00:42:45.010 --> 00:42:47.449
really powerful because normally you have to

00:42:47.449 --> 00:42:50.309
go to a website, chat GPT or copilot, whatever,

00:42:50.510 --> 00:42:52.670
type your question in there. And I have a terminal

00:42:52.670 --> 00:42:55.550
open all day anyway, so why not just integrate

00:42:55.550 --> 00:42:57.929
it there and type in my questions there? Right.

00:42:57.969 --> 00:43:00.469
So I'm definitely going to take a look at this.

00:43:01.389 --> 00:43:03.670
What's great about this, it sounds very complex,

00:43:03.849 --> 00:43:06.809
setting up Azure AI Foundry and whatnot. He has

00:43:06.809 --> 00:43:09.969
guides on his blog, obviously, and he also showed

00:43:09.969 --> 00:43:13.809
the cost aspect. He did 77 requests in his demo.

00:43:13.969 --> 00:43:16.690
He burned through 2 million tokens, but he paid

00:43:16.690 --> 00:43:20.650
only 23 cents for all of that. So AI doesn't

00:43:20.650 --> 00:43:23.190
necessarily need to be expensive. That's awesome.

00:43:24.090 --> 00:43:26.010
yeah i must say this is awesome i'm gonna have

00:43:26.010 --> 00:43:28.929
a play with this i um i i met morton last year

00:43:28.929 --> 00:43:31.650
he came to australia for the experts live australia

00:43:31.650 --> 00:43:35.309
show and man he is he is a force he's a he's

00:43:35.309 --> 00:43:38.119
a great guy um i've never seen him not have a

00:43:38.119 --> 00:43:40.639
smile either which is also you know it says a

00:43:40.639 --> 00:43:43.800
lot right um no he's awesome so yeah folks go

00:43:43.800 --> 00:43:46.519
go check this out perm advisor uh enroll advisor

00:43:46.519 --> 00:43:50.719
very very cool like we said he's probably the

00:43:50.719 --> 00:43:52.820
most hard hard -working community member i've

00:43:52.820 --> 00:43:54.880
ever met he's also running his own business i

00:43:54.880 --> 00:43:57.710
don't know how much probably more hours in his

00:43:57.710 --> 00:44:00.989
day than in mine and your script. That's probably

00:44:00.989 --> 00:44:03.170
true. Denmark probably has a couple of extra

00:44:03.170 --> 00:44:08.650
hours in the day. Perhaps he's letting AI working

00:44:08.650 --> 00:44:13.670
for him. Well, I don't know. We'll ask him. Let's

00:44:13.670 --> 00:44:17.369
round off, Chris. Thank you so much again for

00:44:17.369 --> 00:44:22.570
your insights in EntraSuite. This concludes our

00:44:22.570 --> 00:44:25.489
eighth episode. And, well, I'm already looking

00:44:25.489 --> 00:44:28.409
for the next one. We have to figure out what

00:44:28.409 --> 00:44:32.190
the topics will be for the next one. Hey, it's

00:44:32.190 --> 00:44:35.610
always fun chatting to you. I really enjoy these

00:44:35.610 --> 00:44:38.230
chats. So thanks again, Kost, for everything.

00:44:38.859 --> 00:44:40.780
And thank you folks for listening. Make sure

00:44:40.780 --> 00:44:43.480
you like and subscribe if you like what we're

00:44:43.480 --> 00:44:45.599
doing. It really does help us out because we

00:44:45.599 --> 00:44:49.840
know that we can and should keep going. And also,

00:44:49.900 --> 00:44:51.320
if there's anything that you'd like for us to

00:44:51.320 --> 00:44:54.559
cover or dive into in the show, please reach

00:44:54.559 --> 00:44:57.219
out to us on the socials and we'll be sure to

00:44:57.219 --> 00:45:00.139
see what we can do. Yeah, please let us know.

00:45:00.260 --> 00:45:02.739
Thanks for listening. Thank you, Chris. Thanks

00:45:02.739 --> 00:45:04.099
a lot. Bye -bye.
