WEBVTT

00:00:11.799 --> 00:00:14.080
Hello, and welcome to the Everyday Defender podcast.

00:00:14.500 --> 00:00:17.000
My name is Chris Goosen, and I'm joined as always

00:00:17.000 --> 00:00:19.640
by my friend from the Netherlands and the man

00:00:19.640 --> 00:00:23.820
with the Sentinel plan, Kos. Hi, Chris. Thanks

00:00:23.820 --> 00:00:25.879
for the great introduction. Well, I'm going to

00:00:25.879 --> 00:00:27.859
talk a little bit about Sentinel, to be honest,

00:00:27.940 --> 00:00:31.519
but first of all, it's still dark outside here.

00:00:31.600 --> 00:00:33.560
It's eight o 'clock in the morning, and I see

00:00:33.560 --> 00:00:35.820
the sun shining at your end. I believe it's hot

00:00:35.820 --> 00:00:38.770
weather in Australia right now. It's actually

00:00:38.770 --> 00:00:41.729
manageable. We've had a lot of rain and stuff.

00:00:41.990 --> 00:00:45.030
Oh, really? Yeah. It's actually really sort of

00:00:45.030 --> 00:00:47.969
nice, not too hot. I think we'll have 30 degree

00:00:47.969 --> 00:00:51.149
plus tomorrow again. Hey, not complaining. I

00:00:51.149 --> 00:00:53.609
do prefer the heat over the cold. So everybody

00:00:53.609 --> 00:00:57.770
in Europe will recognize we had two weeks ago,

00:00:57.829 --> 00:01:00.530
we had, I don't know, the most snowfall since

00:01:00.530 --> 00:01:04.590
I don't know how long. It was like 20 centimeters

00:01:04.590 --> 00:01:07.590
of snow covered in the country. So it was a big

00:01:07.590 --> 00:01:10.579
mess. i saw on the news uh on our news they were

00:01:10.579 --> 00:01:12.519
talking about how amsterdam had sort of frozen

00:01:12.519 --> 00:01:14.560
over and people were like there was ice on all

00:01:14.560 --> 00:01:16.019
the streets and people were just like slipping

00:01:16.019 --> 00:01:18.079
all over the place yeah yeah that's funny that

00:01:18.079 --> 00:01:20.480
made the news over there well you know slow news

00:01:20.480 --> 00:01:24.500
day in australia right um i also i the funny

00:01:24.500 --> 00:01:26.640
thing is i still so for our american listeners

00:01:26.640 --> 00:01:30.000
i still get text messages from um like the the

00:01:30.000 --> 00:01:32.680
storm warning system in texas because uh they

00:01:32.680 --> 00:01:34.299
still have my phone number in their thing and

00:01:34.299 --> 00:01:36.500
and i just yesterday i got like some sort of

00:01:36.500 --> 00:01:39.500
really weird ice warning thing uh so they must

00:01:39.500 --> 00:01:41.159
be having some really cold weather over in uh

00:01:41.159 --> 00:01:43.920
in the us at the moment i guess too but uh anyway

00:01:43.920 --> 00:01:48.379
so um today's episode has a little bit of an

00:01:48.379 --> 00:01:51.359
ai flavor to it i guess and uh you know we we

00:01:51.359 --> 00:01:53.299
really don't want to have this be a sort of a

00:01:53.640 --> 00:01:56.920
you know an ai echo chamber but um we definitely

00:01:56.920 --> 00:01:59.439
do also want to bring sort of relevant things

00:01:59.439 --> 00:02:01.939
right so um i'm going to be talking a little

00:02:01.939 --> 00:02:06.140
bit about um this thing called agent 365 um confused

00:02:06.140 --> 00:02:09.379
me uh to no end when when i first heard the announcement

00:02:09.379 --> 00:02:11.300
and sort of started digging into what it was

00:02:11.300 --> 00:02:13.620
um and this announcement sort of comes from uh

00:02:13.620 --> 00:02:16.860
from microsoft ignite and then coast i believe

00:02:16.860 --> 00:02:19.639
you've got some some ai related uh news for us

00:02:19.639 --> 00:02:21.599
as well Yeah, it was actually a coincidence,

00:02:21.860 --> 00:02:24.900
right, Chris, that you and me separately came

00:02:24.900 --> 00:02:27.620
up with these topics and it was a great fit for

00:02:27.620 --> 00:02:30.259
today's episode. Yeah, so I talked a little bit

00:02:30.259 --> 00:02:32.620
about security co -pilot in the past and I was

00:02:32.620 --> 00:02:36.120
also slightly critical on some parts of it back

00:02:36.120 --> 00:02:39.699
then. But since our last episode, which aired

00:02:39.699 --> 00:02:43.240
in October last year, quite a few things, new

00:02:43.240 --> 00:02:45.599
things got announced and released. And I think

00:02:45.599 --> 00:02:47.520
now really is the time to start messing with

00:02:47.520 --> 00:02:49.879
it and see how it can make the lives of the bit

00:02:49.879 --> 00:02:53.180
easier of your uh security analyst so uh security

00:02:53.180 --> 00:02:57.020
co -pilot yeah v2 yeah i'm excited very cool

00:02:57.020 --> 00:02:59.620
um and so i guess yeah just you know jumping

00:02:59.620 --> 00:03:02.719
into it i think um i'd heard this announcement

00:03:02.719 --> 00:03:05.319
uh when i was igniting it was exactly two months

00:03:05.319 --> 00:03:08.219
ago now that i was i was at ignite um and sort

00:03:08.219 --> 00:03:10.520
of at first i thought agent 365 like what's the

00:03:10.520 --> 00:03:12.479
what's the big deal we have an agent for m365

00:03:12.479 --> 00:03:15.979
now uh yeah no that's not it at all right um

00:03:15.979 --> 00:03:18.229
and so if you think about it you know i'd like

00:03:18.229 --> 00:03:20.590
to think sort of 2024 was the the year of the

00:03:20.590 --> 00:03:23.090
llm right we had all this sort of the mainstream

00:03:23.090 --> 00:03:25.930
adoption really of of chat gpt and all of these

00:03:25.930 --> 00:03:28.590
sort of large language models and then last year

00:03:28.590 --> 00:03:31.750
2025 was very much the year of agentic ai right

00:03:31.750 --> 00:03:34.810
that that catchphrase and that buzzword of agents

00:03:34.810 --> 00:03:37.370
and agentic ai was sort of the thing and so i'm

00:03:37.370 --> 00:03:39.770
really hoping that 2026 is going to be the year

00:03:39.770 --> 00:03:43.110
of ai governance that would be my my hope and

00:03:43.110 --> 00:03:45.969
and i think kind of looking at what we're seeing

00:03:45.969 --> 00:03:49.669
with Agent 365, maybe I might be onto something

00:03:49.669 --> 00:03:52.969
there, right? So Microsoft Frames Agent 365 is

00:03:52.969 --> 00:03:56.629
sort of the foundation for that emerging agentic

00:03:56.629 --> 00:03:58.689
era, right? Because where we have these autonomous

00:03:58.689 --> 00:04:01.009
agents that are, they're not just assistants

00:04:01.009 --> 00:04:03.009
or chatbots, but they're actually participating

00:04:03.009 --> 00:04:07.719
in business processes. So Agent 365, what is

00:04:07.719 --> 00:04:10.180
that thing? It's not an agent for M365. It's

00:04:10.180 --> 00:04:13.979
actually a control plane for all the AI agents

00:04:13.979 --> 00:04:17.959
across M365 and teams and dynamics and sort of

00:04:17.959 --> 00:04:19.860
power platform, all of these different systems

00:04:19.860 --> 00:04:21.899
that, you know, that organizations use. So it

00:04:21.899 --> 00:04:25.759
provides that sort of central place for, you

00:04:25.759 --> 00:04:28.819
know, cataloging, but also registering and monitoring

00:04:28.819 --> 00:04:31.180
and governing that that word governance, I think,

00:04:31.180 --> 00:04:34.439
is so important. agents across the organizations,

00:04:35.000 --> 00:04:38.360
right? So if you think about it, we've had this

00:04:38.360 --> 00:04:41.279
for human identities for a while, right? In Entry

00:04:41.279 --> 00:04:43.959
ID, you can go to one place and you can see everything

00:04:43.959 --> 00:04:47.540
about a user and their identity. And this is

00:04:47.540 --> 00:04:51.160
kind of that sort of thing for agents. So agents

00:04:51.160 --> 00:04:55.959
get a unique agent ID, they're calling it, which

00:04:55.959 --> 00:05:00.509
then allows them to authenticate and... um you

00:05:00.509 --> 00:05:03.470
know follow uh least privileged access and have

00:05:03.470 --> 00:05:05.290
policies applied to them right so if you think

00:05:05.290 --> 00:05:07.889
about again integration into things like conditional

00:05:07.889 --> 00:05:10.790
access where you can actually now be sort of

00:05:10.790 --> 00:05:13.990
very very granular about what an agent can can't

00:05:13.990 --> 00:05:17.149
do things like that um so you know i really like

00:05:17.149 --> 00:05:20.769
what i see here i think it's it's um it's it's

00:05:20.769 --> 00:05:22.629
a good step forward because we've needed this

00:05:22.629 --> 00:05:25.230
right and if you you ask why well you know if

00:05:25.230 --> 00:05:27.310
you've anyone who's listening to this if you've

00:05:27.310 --> 00:05:30.720
played with ai and agents in your organization

00:05:30.720 --> 00:05:34.139
right through custom agents or workflow bots

00:05:34.139 --> 00:05:36.899
or sort of anything that is doing this sort of

00:05:36.899 --> 00:05:39.759
automated work you've probably seen that you

00:05:39.759 --> 00:05:43.519
can very quickly one there's sprawl like these

00:05:43.519 --> 00:05:46.600
things just multiply um and you can really really

00:05:46.600 --> 00:05:49.800
quickly lose track of what an agent is doing

00:05:49.800 --> 00:05:52.600
um you know does it exist what is it doing and

00:05:52.600 --> 00:05:55.350
and and all of that who owns the agent what project

00:05:55.350 --> 00:05:57.069
does it belong to, all of that type of stuff,

00:05:57.250 --> 00:06:00.470
right? And so Agent 365 really is that sort of,

00:06:00.490 --> 00:06:02.949
they're trying to counter this by providing this

00:06:02.949 --> 00:06:05.209
sort of centralized registry and inventory of

00:06:05.209 --> 00:06:08.769
agents and provide some sort of visibility, right?

00:06:08.850 --> 00:06:12.850
Because thinking about it, agents can act autonomously,

00:06:13.029 --> 00:06:15.149
right? They trigger workflows. They, in many

00:06:15.149 --> 00:06:17.290
cases, they have access to really sensitive data

00:06:17.290 --> 00:06:20.230
because you're giving them a data set to ground,

00:06:20.490 --> 00:06:23.490
right? And so they can access stuff that most

00:06:23.490 --> 00:06:26.660
users can't access. um and they're obviously

00:06:26.660 --> 00:06:30.379
running and acting continuously at scale so being

00:06:30.379 --> 00:06:34.319
able to have compliance center if you will right

00:06:34.319 --> 00:06:36.439
for for this i think makes a whole lot of sense

00:06:36.439 --> 00:06:39.899
um you know logging threat detection all of that

00:06:39.899 --> 00:06:42.120
really important stuff that we that we care about

00:06:42.120 --> 00:06:44.240
and making sure we sort of standardize that governance

00:06:44.240 --> 00:06:48.819
across um not only agents that are microsoft

00:06:48.819 --> 00:06:51.000
agents or third -party agents you know think

00:06:51.000 --> 00:06:54.300
of things like possibly service now I was going

00:06:54.300 --> 00:06:58.259
to host that, yeah. Yeah, yeah. Everyone, sort

00:06:58.259 --> 00:07:02.759
of every organization these days has an agent

00:07:02.759 --> 00:07:04.439
for something, right? The funny thing was I was

00:07:04.439 --> 00:07:08.300
looking at some tenants yesterday or today when

00:07:08.300 --> 00:07:09.879
I was sort of prepping for this, and I took a

00:07:09.879 --> 00:07:13.160
look at some customer tenants and also my own

00:07:13.160 --> 00:07:15.160
tenant. And even in my own tenant where I've

00:07:15.160 --> 00:07:16.879
not enabled any of the stuff and I have exactly

00:07:16.879 --> 00:07:21.040
one user. um there's like 126 different agents

00:07:21.040 --> 00:07:24.800
that are showing up in the in in agent 365 from

00:07:24.800 --> 00:07:27.699
different um you know vendors right so adp has

00:07:27.699 --> 00:07:30.439
an agent zero which is like um accounting software

00:07:30.439 --> 00:07:32.699
here in australia there's an agent um service

00:07:32.699 --> 00:07:34.779
now has an agent like everyone's building agents

00:07:34.779 --> 00:07:37.439
for all this stuff now in my environment they're

00:07:37.439 --> 00:07:40.019
not enabled um but you know they're visible to

00:07:40.019 --> 00:07:43.959
me there um so you know and then of course organizations

00:07:43.959 --> 00:07:45.939
are building their own right co -pilot studio

00:07:45.939 --> 00:07:48.560
is is a thing and it makes it really really simple

00:07:48.560 --> 00:07:51.139
for folks to dabble with the stuff and build

00:07:51.139 --> 00:07:54.300
agents and it's the same challenge i think we've

00:07:54.300 --> 00:07:57.779
always had when you think about um i guess what

00:07:57.779 --> 00:07:59.800
they used to call citizen development right or

00:07:59.800 --> 00:08:03.319
no low code development where you give business

00:08:03.319 --> 00:08:06.560
users the ability to to build stuff right right

00:08:06.560 --> 00:08:08.379
i mean this started with excel and people were

00:08:08.379 --> 00:08:11.660
building macros for excel um very quickly that

00:08:11.660 --> 00:08:14.699
stuff can get kind of out of control and there's

00:08:14.699 --> 00:08:17.199
one person who knows what it's doing and no one

00:08:17.199 --> 00:08:19.480
else does and no one understands it. And so the

00:08:19.480 --> 00:08:22.240
fact that we can kind of standardize our governance

00:08:22.240 --> 00:08:25.300
across all agents, regardless if they were built

00:08:25.300 --> 00:08:27.199
in -house or whether they come from a third party

00:08:27.199 --> 00:08:28.819
or whether they come from Microsoft, I think

00:08:28.819 --> 00:08:34.580
is really, really powerful. So from a feature

00:08:34.580 --> 00:08:37.759
perspective, they really sort of are talking

00:08:37.759 --> 00:08:40.639
about these sort of five pillars of functionality

00:08:40.639 --> 00:08:44.879
that... Agent 365 provides, right? And again,

00:08:45.000 --> 00:08:47.879
I want to call out this stuff is it's very, very

00:08:47.879 --> 00:08:49.980
new. It's still really, I think it's still considered

00:08:49.980 --> 00:08:54.259
to be in preview. So, you know, this is all very

00:08:54.259 --> 00:08:56.500
conceptual at the moment. I don't know anyone

00:08:56.500 --> 00:08:58.500
who's taking sort of full advantage of actually

00:08:58.500 --> 00:09:01.720
using and deploying this stuff. But I think what

00:09:01.720 --> 00:09:03.799
we are seeing is the framework for something

00:09:03.799 --> 00:09:05.159
that is going to be really, really interesting.

00:09:06.940 --> 00:09:08.820
So, you know, looking at those capabilities,

00:09:08.879 --> 00:09:10.460
we're looking sort of at registry that I talked

00:09:10.460 --> 00:09:12.139
about, right? That sort of central inventory

00:09:12.139 --> 00:09:14.500
of all the agents within the environment where

00:09:14.500 --> 00:09:17.139
you can provide access control to these things,

00:09:17.200 --> 00:09:20.299
you know, least privilege, get a really good

00:09:20.299 --> 00:09:22.240
snapshot really quickly of like, what is the

00:09:22.240 --> 00:09:25.259
agent actually, what data is it acting on? What

00:09:25.259 --> 00:09:27.379
data does it have access to? What permissions,

00:09:27.559 --> 00:09:29.860
what things, what systems can it feed into? All

00:09:29.860 --> 00:09:32.779
of that type of stuff, right? Visualization.

00:09:34.029 --> 00:09:35.690
dashboards, telemetry, all of the stuff that

00:09:35.690 --> 00:09:38.950
IT folks need to kind of be able to track things,

00:09:39.029 --> 00:09:42.490
track risk. And I guess report on ROI because

00:09:42.490 --> 00:09:44.649
the other thing with this is everyone's running

00:09:44.649 --> 00:09:47.970
towards this AI thing, spending massive amounts

00:09:47.970 --> 00:09:52.450
of dollars on AI or Euro on AI. But if you don't

00:09:52.450 --> 00:09:54.210
actually have a way or a metric to be able to

00:09:54.210 --> 00:09:57.389
track the value that it's providing, you're just

00:09:57.389 --> 00:09:59.450
throwing money at something, right? So it's really

00:09:59.450 --> 00:10:03.389
important to be able to do that as well. Interoperability

00:10:03.389 --> 00:10:06.070
is another one of those things. Connecting agents

00:10:06.070 --> 00:10:08.029
between multiple apps and different organizational

00:10:08.029 --> 00:10:10.230
data, different third party platforms, stuff

00:10:10.230 --> 00:10:12.490
like that. And then, of course, security, which

00:10:12.490 --> 00:10:14.110
is the thing that we really, really care about

00:10:14.110 --> 00:10:17.830
as well. And this is kind of where it extends

00:10:17.830 --> 00:10:20.830
defender protections into agents as well. So

00:10:20.830 --> 00:10:23.450
being able to detect misconfigurations and vulnerabilities,

00:10:23.750 --> 00:10:25.929
threats, prompt injection, that type of stuff

00:10:25.929 --> 00:10:29.700
using the defender platform. But, you know, across

00:10:29.700 --> 00:10:32.039
agents as well. So treating an agent very much

00:10:32.039 --> 00:10:34.740
like we've always treated a human identity or,

00:10:34.820 --> 00:10:37.179
you know, a service principle or those types

00:10:37.179 --> 00:10:40.340
of things. But Chris, this is not only Microsoft

00:10:40.340 --> 00:10:45.320
agents then, I believe, right? Correct. So third

00:10:45.320 --> 00:10:47.139
-party agents, ones that you build yourself,

00:10:47.340 --> 00:10:49.759
sort of all agents in the environment, you know,

00:10:49.759 --> 00:10:53.679
under one sort of... People like to use Claude

00:10:53.679 --> 00:10:57.200
or any of the other tools. They benefit from

00:10:57.200 --> 00:11:00.320
this as well. Well, yes, if it's an agent that's

00:11:00.320 --> 00:11:02.799
running in your M365 environment, right? So if

00:11:02.799 --> 00:11:06.259
it's something outside of the M365 ecosystem,

00:11:06.500 --> 00:11:08.960
then no, it's not likely going to be covered

00:11:08.960 --> 00:11:11.500
here. But anything that's connected to or attached

00:11:11.500 --> 00:11:14.960
to or operating within your M365 environment

00:11:14.960 --> 00:11:20.919
will be visible here. So what about licensing?

00:11:21.019 --> 00:11:23.000
I think it was your next question, right, Kos?

00:11:24.320 --> 00:11:27.840
You know, as always... Well, it probably will,

00:11:27.940 --> 00:11:29.879
yes. Now, how much it will cost you, we don't

00:11:29.879 --> 00:11:32.200
actually know at this point because that information

00:11:32.200 --> 00:11:35.120
is not, yeah, it's not available yet for us,

00:11:35.220 --> 00:11:38.179
or at least not that I can find. But, you know,

00:11:38.200 --> 00:11:40.240
and as always, it's complicated, right? So I

00:11:40.240 --> 00:11:43.080
think the intent here is that there will be an

00:11:43.080 --> 00:11:47.559
Agent 365 SKU. which will apply to agents. And

00:11:47.559 --> 00:11:50.399
so it will very much treat agents like digital

00:11:50.399 --> 00:11:53.879
workers, right? Where you would apply sort of

00:11:53.879 --> 00:11:58.620
an A365 SKU license to an agent. It doesn't mess

00:11:58.620 --> 00:12:03.399
or interfere with your existing M365 or copilot.

00:12:03.460 --> 00:12:06.879
Or if you're using Azure OpenAI for anything

00:12:06.879 --> 00:12:08.940
like that, licensing stays the same. This does

00:12:08.940 --> 00:12:11.659
not affect that in any way. It's really important

00:12:11.659 --> 00:12:14.539
to just think of it as it's a governance tool.

00:12:15.049 --> 00:12:18.509
um uh for for your your agents and so you're

00:12:18.509 --> 00:12:20.950
paying for the governance functionality of it

00:12:20.950 --> 00:12:23.570
right so again you know agents require their

00:12:23.570 --> 00:12:25.750
own licensing there's no you know it's a sort

00:12:25.750 --> 00:12:29.029
of a dedicated skew pricing is not available

00:12:29.029 --> 00:12:32.950
yet that i've seen um but this stuff is definitely

00:12:32.950 --> 00:12:34.870
showing up in tenants right and i think it's

00:12:34.870 --> 00:12:38.070
because if you um you can sign up through the

00:12:38.070 --> 00:12:41.210
frontier preview program uh and and be sort of

00:12:41.930 --> 00:12:44.110
a preview tester for this stuff and you can you

00:12:44.110 --> 00:12:46.230
can get access to it and i think microsoft are

00:12:46.230 --> 00:12:49.529
obviously giving it um to folks or to organizations

00:12:49.529 --> 00:12:52.090
you know at the moment as just as part of the

00:12:52.090 --> 00:12:54.210
preview program but at some point in time there

00:12:54.210 --> 00:12:56.769
will be a license ad a license cost to it so

00:12:56.769 --> 00:12:59.210
think about that too i guess if you are going

00:12:59.210 --> 00:13:01.450
to jump into this because if you've got you know

00:13:01.450 --> 00:13:04.169
2 000 agents in your environment you go and sort

00:13:04.169 --> 00:13:06.230
of enable all of the stuff um at some point in

00:13:06.230 --> 00:13:07.610
time you're going to have to pay the piper for

00:13:07.610 --> 00:13:10.779
that so yeah um you know like i said these things

00:13:10.779 --> 00:13:12.620
the the agents will appear so they sort of appear

00:13:12.620 --> 00:13:15.240
in android just like a digital employee right

00:13:15.240 --> 00:13:18.559
with a an agent linked to it so they'll show

00:13:18.559 --> 00:13:20.740
up in all charts you can have permissions they

00:13:20.740 --> 00:13:23.360
can um interact with other systems like a user

00:13:23.360 --> 00:13:25.500
will and and that also means you know you can

00:13:25.500 --> 00:13:27.740
govern them yeah in a way that you would typically

00:13:27.740 --> 00:13:31.539
govern your user accounts um but as i said it

00:13:31.539 --> 00:13:34.899
doesn't replace um your your microsoft licenses

00:13:34.899 --> 00:13:37.990
right your human users still need a co -pilot

00:13:37.990 --> 00:13:39.990
license if they want to use co -pilot, for example,

00:13:39.990 --> 00:13:44.190
or a Dynamics license for D365. This is really

00:13:44.190 --> 00:13:46.750
just a governance thing. It covers that governance

00:13:46.750 --> 00:13:49.450
plane, and it's not really there for execution.

00:13:49.889 --> 00:13:53.190
So I think it's really early days. But like I

00:13:53.190 --> 00:13:55.370
was saying, I think governance is something that

00:13:55.370 --> 00:14:00.269
we really need to think about in 2026. And I

00:14:00.269 --> 00:14:02.210
really like that there's something sort of...

00:14:02.490 --> 00:14:05.230
being worked on very actively here for us to

00:14:05.230 --> 00:14:07.309
help orgs. And it's not going to be this, you

00:14:07.309 --> 00:14:09.429
know, what it's going to cost us, that's going

00:14:09.429 --> 00:14:12.149
to be interesting to see. But, you know, organizations

00:14:12.149 --> 00:14:15.429
that are making that sort of investment in agent

00:14:15.429 --> 00:14:17.710
adoption are probably going to be fine to, you

00:14:17.710 --> 00:14:19.490
know, to pay for the governance side of this.

00:14:19.570 --> 00:14:23.590
And I'm also sort of encouraged to see, I had

00:14:23.590 --> 00:14:25.190
some really good conversations at Ignite with

00:14:25.190 --> 00:14:27.070
folks, consultants and folks who are building

00:14:27.070 --> 00:14:30.759
governance frameworks, right? uh for ai across

00:14:30.759 --> 00:14:32.580
the business and i think that's really good because

00:14:32.580 --> 00:14:34.120
i think we need that i think this stuff's going

00:14:34.120 --> 00:14:35.879
to get away from us if we if we don't have it

00:14:35.879 --> 00:14:38.419
so i'm very encouraged to see go check it out

00:14:38.419 --> 00:14:40.860
um if this is you know if you are dabbling i

00:14:40.860 --> 00:14:42.440
think every company at this point is dabbling

00:14:42.440 --> 00:14:46.039
with ai and copilot and agents and stuff so go

00:14:46.039 --> 00:14:47.779
and have a look if you you know if you're logging

00:14:47.779 --> 00:14:49.500
to the microsoft admin center you'll see the

00:14:49.500 --> 00:14:53.899
uh agents sort of um uh menu option sort of show

00:14:53.899 --> 00:14:55.940
up for you in your tenant now and you can have

00:14:55.940 --> 00:14:57.759
a look it's a pretty interesting information

00:14:57.759 --> 00:14:59.919
there but you know what agents you have in the

00:14:59.919 --> 00:15:01.539
environment, who's using them, what the usage

00:15:01.539 --> 00:15:03.919
of these things are, who owns the agent, that

00:15:03.919 --> 00:15:07.340
type of stuff. So go check it out. Yeah, great

00:15:07.340 --> 00:15:10.980
stuff. I already noticed, Chris, that in a lot

00:15:10.980 --> 00:15:14.259
of different places, agent support popped up.

00:15:14.379 --> 00:15:17.740
So EntraID identity protection, for example,

00:15:17.899 --> 00:15:23.379
a P2 feature, now also is providing risk statuses

00:15:23.379 --> 00:15:27.120
to agent logins, which you can, again, use in

00:15:27.120 --> 00:15:29.460
conditional access. And also in conditional access

00:15:29.460 --> 00:15:31.620
policies, I noticed there is an option now to

00:15:31.620 --> 00:15:34.820
block agent usage, for example, on certain resources.

00:15:36.139 --> 00:15:38.980
access packages. So not only now a user can request

00:15:38.980 --> 00:15:41.679
an access package, but also an agent can request

00:15:41.679 --> 00:15:44.360
one or you can decline the ability for agents

00:15:44.360 --> 00:15:46.759
to request certain access packages. So it's great

00:15:46.759 --> 00:15:48.759
to see that Microsoft is implementing it. It

00:15:48.759 --> 00:15:52.200
is confusing, however. Those features, as far

00:15:52.200 --> 00:15:55.159
as I know, are part of the P2 license. And now

00:15:55.159 --> 00:15:57.500
there's also an agent -based license. So it might

00:15:57.500 --> 00:15:59.720
be because it is in preview that Microsoft is

00:15:59.720 --> 00:16:02.059
also still figuring out. Figuring out the licensing.

00:16:02.299 --> 00:16:04.019
Yeah, fair enough. And, you know, I think that

00:16:04.019 --> 00:16:06.320
stuff all kind of ties together to the sort of

00:16:06.320 --> 00:16:09.080
agent ID, right? That, you know, is that sort

00:16:09.080 --> 00:16:12.279
of source of truth for what an agent is within

00:16:12.279 --> 00:16:14.519
the environment. So you're right. The stuff lights

00:16:14.519 --> 00:16:17.279
up kind of everywhere. um and and kind of keeping

00:16:17.279 --> 00:16:20.100
track of all of the moving bits is a bit a bit

00:16:20.100 --> 00:16:21.840
interesting so but we'll keep you know we'll

00:16:21.840 --> 00:16:23.879
keep you up to date here as as things progress

00:16:23.879 --> 00:16:26.039
and as we kind of learn more about the stuff

00:16:26.039 --> 00:16:28.399
as well we can we can always you know uh dig

00:16:28.399 --> 00:16:31.679
into it a little bit more again yeah yeah Yeah,

00:16:31.740 --> 00:16:34.299
we probably should. And also there's always the

00:16:34.299 --> 00:16:37.340
discussion about data governance as well, right?

00:16:37.820 --> 00:16:42.500
And maybe companies don't want to have their

00:16:42.500 --> 00:16:46.139
users to use any LLM which is out there and share

00:16:46.139 --> 00:16:51.200
sensitive data. So we can probably cover that

00:16:51.200 --> 00:16:54.659
subject with Purview in a later episode in the

00:16:54.659 --> 00:16:59.269
future. Yeah, 100%. Yeah, so I mentioned security

00:16:59.269 --> 00:17:02.850
co -pilot, something I wanted to revisit. But

00:17:02.850 --> 00:17:05.269
before we do that, you already announced me as,

00:17:05.369 --> 00:17:07.650
what do you say, the Sentinel guy or Sentinel?

00:17:08.210 --> 00:17:11.210
The man with the Sentinel plan. The man with

00:17:11.210 --> 00:17:14.750
the Sentinel plan. Yeah, well, one thing I shortly

00:17:14.750 --> 00:17:17.490
want to touch on, normally we don't do news items

00:17:17.490 --> 00:17:22.130
in this podcast, but I think I discovered that

00:17:22.130 --> 00:17:24.470
something got introduced, which is really cool.

00:17:24.829 --> 00:17:27.650
I talked in episode 10. In September of last

00:17:27.650 --> 00:17:30.069
year, I talked a little bit about Sentinel Data

00:17:30.069 --> 00:17:32.589
Lake, and the topic came back several times,

00:17:32.710 --> 00:17:34.710
I believe. And one of the major shortcomings

00:17:34.710 --> 00:17:39.349
back then is now resolved, and that is the ability

00:17:39.349 --> 00:17:43.210
to extend your Defender XDR data natively in

00:17:43.210 --> 00:17:45.930
Data Lake. So before, when you had Defender data

00:17:45.930 --> 00:17:48.170
for Defender for Endpoint, for example, where

00:17:48.170 --> 00:17:51.890
you have very tables with a lot of logs, like

00:17:51.890 --> 00:17:54.390
the device network events, for example, or process

00:17:54.390 --> 00:17:57.420
events, if you wanted to, keep them for longer

00:17:57.420 --> 00:17:59.240
than 30 days, you had to store them in Sentinel

00:17:59.240 --> 00:18:01.740
with high costs involved and everything. And

00:18:01.740 --> 00:18:04.859
because Data Lake was part of Sentinel, you had

00:18:04.859 --> 00:18:07.539
to ingest it through Sentinel in the Data Lake.

00:18:08.279 --> 00:18:10.799
And there wasn't a native option to do that for

00:18:10.799 --> 00:18:13.319
Defender Log. So long story short, it is now

00:18:13.319 --> 00:18:15.920
possible. You can just go into your table, like

00:18:15.920 --> 00:18:19.240
device network events, extend the retention beyond

00:18:19.240 --> 00:18:22.000
30 days, and then it gets stored in the Data

00:18:22.000 --> 00:18:24.980
Lake for, I believe, only two and a half cents

00:18:24.980 --> 00:18:26.690
per gigabyte. gigabytes per month or something

00:18:26.690 --> 00:18:30.089
like that. It's quite cost effective. Obviously,

00:18:30.230 --> 00:18:34.430
these will generate lots of gigabytes and large

00:18:34.430 --> 00:18:38.170
environments. So still be careful. But it's much,

00:18:38.269 --> 00:18:41.150
much cheaper than it wasn't really feasible to

00:18:41.150 --> 00:18:43.269
store it in central before. And now it is. And

00:18:43.269 --> 00:18:45.910
a lot of MVPs and other people in the community.

00:18:46.569 --> 00:18:49.009
created all kinds of elaborate stuff. I was also

00:18:49.009 --> 00:18:51.430
guilty of that by using ADX, for example, in

00:18:51.430 --> 00:18:54.569
the past for this. And I saw others now streaming

00:18:54.569 --> 00:18:58.170
stuff in an intermediary service and then put

00:18:58.170 --> 00:19:00.130
it into Sentinel Data Lake. But then you have

00:19:00.130 --> 00:19:02.130
a lot of different resources you have to maintain

00:19:02.130 --> 00:19:04.230
and everything. So great to see that Microsoft

00:19:04.230 --> 00:19:06.930
now has this natively included in the product.

00:19:07.710 --> 00:19:09.910
Simple is always better too, right? It's a lot

00:19:09.910 --> 00:19:13.269
easier to manage simple than it is complex and

00:19:13.269 --> 00:19:17.369
all this other stuff. And I bet Microsoft was

00:19:17.369 --> 00:19:19.809
aware of this shortcoming from the get -go, but

00:19:19.809 --> 00:19:23.750
they also need to take into account the impact

00:19:23.750 --> 00:19:26.490
on hardware and performance and everything. So

00:19:26.490 --> 00:19:29.769
they probably want to introduce features more

00:19:29.769 --> 00:19:32.309
granularly. And you see that with Copilot now

00:19:32.309 --> 00:19:36.480
as well, by the way. So, yeah. That Sentinel

00:19:36.480 --> 00:19:41.079
for now, security co -pilot, is now free for

00:19:41.079 --> 00:19:44.559
E5 customers, Chris. What do you think about

00:19:44.559 --> 00:19:48.960
that? Hey, that was one of the really big announcements

00:19:48.960 --> 00:19:51.380
from Ignite as well, right? And I think this

00:19:51.380 --> 00:19:53.339
is great because I think a lot of organizations

00:19:53.339 --> 00:19:56.660
have been interested but have been very cautious

00:19:56.660 --> 00:19:59.039
about dipping their toes because of the cost

00:19:59.039 --> 00:20:03.740
aspect, right? And so I think... um the way they've

00:20:03.740 --> 00:20:06.039
done it and i'm really glad you're sort of you're

00:20:06.039 --> 00:20:08.960
the one breaking down how this uh the the su

00:20:08.960 --> 00:20:11.839
stuff works because man it breaks my brain sometimes

00:20:11.839 --> 00:20:14.039
trying to trying to figure it out a little bit

00:20:14.039 --> 00:20:17.119
confusing right yeah yeah so i'm glad you're

00:20:17.119 --> 00:20:18.880
the one breaking it down but yes i do think this

00:20:18.880 --> 00:20:21.079
is great and i do think we are going to see um

00:20:21.079 --> 00:20:25.119
an uptake in in organizations now sort of giving

00:20:25.119 --> 00:20:27.420
security copilot a try why wouldn't you now right

00:20:27.420 --> 00:20:30.460
if you've got e5 um why wouldn't you try and

00:20:30.460 --> 00:20:33.339
uh sort of use it now and and take advantage

00:20:33.339 --> 00:20:36.579
of the stuff yeah Yeah, and before I break down

00:20:36.579 --> 00:20:40.619
how it works and what is free and how it gets

00:20:40.619 --> 00:20:44.940
charged, you mentioned the announcements on Ignite,

00:20:44.960 --> 00:20:48.859
and sometimes it's too bad that we put AI on

00:20:48.859 --> 00:20:53.160
everything nowadays, and it brings down the actual

00:20:53.160 --> 00:20:55.740
value of some really cool stuff, I believe, because

00:20:55.740 --> 00:20:59.079
I'm not sure how it is with you, but I'm getting

00:20:59.079 --> 00:21:02.700
a little bit of AI fatigue at times. When you

00:21:02.700 --> 00:21:04.799
hear that your washing machine, and your your

00:21:04.799 --> 00:21:07.599
refrigerator now has ai as well right it's like

00:21:07.599 --> 00:21:10.599
what's up with that it's well i saw marketing

00:21:10.599 --> 00:21:13.500
yeah i saw a hearing aid there's an ad for a

00:21:13.500 --> 00:21:16.009
local aussie ad here for hearing aids and the

00:21:16.009 --> 00:21:19.910
hearing aids now have ai right yeah so yes you're

00:21:19.910 --> 00:21:21.849
right i think i think everything is just you

00:21:21.849 --> 00:21:24.230
know and we have machine learning and automation

00:21:24.230 --> 00:21:27.109
for ages now it's that's great but don't just

00:21:27.109 --> 00:21:30.250
rename it ai i think it's a new invention and

00:21:30.250 --> 00:21:32.349
the same with these kinds of announcements sometimes

00:21:32.349 --> 00:21:35.069
it's like okay it's ai everything and i'm starting

00:21:35.069 --> 00:21:37.910
to ignore some of the announcements and and also

00:21:37.910 --> 00:21:39.710
to be honest with this one i was a little bit

00:21:39.710 --> 00:21:42.730
skeptical at first because microsoft says customers

00:21:42.730 --> 00:21:46.799
with microsoft e5 will now get 400 security co

00:21:46.799 --> 00:21:49.480
-pilot units. So those are those SCUs, those

00:21:49.480 --> 00:21:52.960
costly compute units, each month for every 1

00:21:52.960 --> 00:21:57.240
,000 paid user licenses. So if you have, for

00:21:57.240 --> 00:22:00.640
example, 400 users with an E5 license, you get

00:22:00.640 --> 00:22:04.599
160 SCUs. If you have 4 ,000 users, you get 1

00:22:04.599 --> 00:22:10.589
,600 SCUs. Per month, that is. But then at first

00:22:10.589 --> 00:22:12.970
I was like, ah, there's the catch. This is Microsoft

00:22:12.970 --> 00:22:15.390
telling me it is free, but it's not actually

00:22:15.390 --> 00:22:17.650
that useless. And you're probably paying a lot

00:22:17.650 --> 00:22:21.160
instantly extra over it because. for example

00:22:21.160 --> 00:22:25.599
the 160 su's for 400 users or or even the 1600

00:22:25.599 --> 00:22:29.380
su's that's only two su's per hour and i remember

00:22:29.380 --> 00:22:31.660
how quickly i burned through those in no time

00:22:31.660 --> 00:22:33.539
a couple of months ago when i started messing

00:22:33.539 --> 00:22:35.400
with them and i was like okay they're giving

00:22:35.400 --> 00:22:38.319
away free two su's for an organization with 4

00:22:38.319 --> 00:22:40.880
000 users how is that really usable but first

00:22:40.880 --> 00:22:42.819
it's good to understand that it's not converted

00:22:42.819 --> 00:22:45.660
into an hourly rate you can actually have those

00:22:45.660 --> 00:22:49.200
su's so 1600 su's and you can spend them in a

00:22:49.200 --> 00:22:50.950
month or you can and even spend them within a

00:22:50.950 --> 00:22:53.750
day if you like. It's up to you. But it's not

00:22:53.750 --> 00:22:57.009
calculated back into an hourly rate and that

00:22:57.009 --> 00:23:00.529
it will be depleted constantly whenever you do

00:23:00.529 --> 00:23:06.410
a couple of simple queries. And the second point

00:23:06.410 --> 00:23:08.750
is something we talked about already in this

00:23:08.750 --> 00:23:12.509
episode, agents. So back when we discussed security...

00:23:12.680 --> 00:23:15.259
Copilot, when it was new, I was already a little

00:23:15.259 --> 00:23:17.039
bit complaining about the fact that when you

00:23:17.039 --> 00:23:18.900
went in, for example, into the Defender portal

00:23:18.900 --> 00:23:21.140
and you opened up an incident, it automatically

00:23:21.140 --> 00:23:23.599
generated a summary for me. And every time I

00:23:23.599 --> 00:23:26.180
revisited that incident, the same summary got

00:23:26.180 --> 00:23:29.480
regenerated and my SEUs were gone in no time

00:23:29.480 --> 00:23:32.539
just by browsing some portals, right? Now, obviously,

00:23:32.799 --> 00:23:36.000
Microsoft also acknowledges this. So now they

00:23:36.000 --> 00:23:39.640
give much more granular controls on what Copilot

00:23:39.640 --> 00:23:41.799
automatically does for you and what it does not.

00:23:41.960 --> 00:23:44.559
So one of my pro tips for this episode is already,

00:23:44.720 --> 00:23:48.079
if you have Copilot enabled, either through your

00:23:48.079 --> 00:23:50.259
own SCUs, which you have deployed already, or

00:23:50.259 --> 00:23:53.940
the free Copilot SCUs from Microsoft, go into

00:23:53.940 --> 00:23:57.269
the Defender portal. go to settings, co -pilot

00:23:57.269 --> 00:23:59.509
in Defender, preferences, and there you can now

00:23:59.509 --> 00:24:02.950
disable the auto generation of summary, summarizations

00:24:02.950 --> 00:24:05.130
and instance. And you can also, and you see a

00:24:05.130 --> 00:24:07.490
screenshot in show notes, you can also say, I

00:24:07.490 --> 00:24:10.009
only want automatic summarization whenever an

00:24:10.009 --> 00:24:12.230
incident has a severity of high, for example.

00:24:12.450 --> 00:24:15.329
So you can manage a little bit better. And also

00:24:15.329 --> 00:24:17.670
in the co -pilot portal, you can now also enable,

00:24:17.890 --> 00:24:20.390
disable, for example, if you want to use those

00:24:20.390 --> 00:24:23.750
co -pilot compute units for Intune or EntryD

00:24:23.750 --> 00:24:27.630
portal over. other solutions. So you have much

00:24:27.630 --> 00:24:29.750
more control on how you're going to spend those

00:24:29.750 --> 00:24:32.150
compute units. And there's also more elaborate

00:24:32.150 --> 00:24:35.170
permission controls now on it. And you can create

00:24:35.170 --> 00:24:37.809
even more multiple workspaces as they call them.

00:24:37.869 --> 00:24:40.069
It's not a log analytics workspace. It's more

00:24:40.069 --> 00:24:43.390
like a logical container for compute. And you

00:24:43.390 --> 00:24:47.529
can assign workspaces to, for example, your admins,

00:24:47.529 --> 00:24:51.109
your identity team separately from your security

00:24:51.109 --> 00:24:53.990
analysts, for example. But with agents, obviously,

00:24:54.170 --> 00:25:00.869
it might not be necessary to query and do a lot

00:25:00.869 --> 00:25:04.069
of compute throughout the day any longer because

00:25:04.069 --> 00:25:05.869
you want to be more, you can be more efficient

00:25:05.869 --> 00:25:09.750
with it that way. So the agents, I would advise

00:25:09.750 --> 00:25:13.430
starting by only using the SCUs for running security

00:25:13.430 --> 00:25:16.690
copilot agents. And if you want to do LLM stuff.

00:25:17.549 --> 00:25:20.329
Look into Microsoft Sentinel MCP server, for

00:25:20.329 --> 00:25:23.089
example, where you can connect your own LLM,

00:25:23.190 --> 00:25:26.549
like GitHub Copilot or Claude or any other solution

00:25:26.549 --> 00:25:30.869
and talk, so to speak, to your environment that

00:25:30.869 --> 00:25:32.970
way. It's a little bit slower, but that way you

00:25:32.970 --> 00:25:36.589
will not burn through those SUs because the compute

00:25:36.589 --> 00:25:40.430
is taken care of at a different level. And with

00:25:40.430 --> 00:25:43.670
agents, Microsoft also provides now a security

00:25:43.670 --> 00:25:46.730
store. So it's another app store -like, I think.

00:25:47.019 --> 00:25:50.359
or marketplace, so to speak. And there you can

00:25:50.359 --> 00:25:53.099
find some Microsoft predefined agents like the

00:25:53.099 --> 00:25:56.119
phishing triage agents, which will automatically

00:25:56.119 --> 00:26:01.500
perform otherwise manual tasks for triaging phishing

00:26:01.500 --> 00:26:04.279
incidents. But you can also now find a lot of

00:26:04.279 --> 00:26:07.460
third -party agents in the store and build your

00:26:07.460 --> 00:26:11.210
own, of course, with Copilot Studio. yeah so

00:26:11.210 --> 00:26:14.170
again disable generation of incident summaries

00:26:14.170 --> 00:26:17.109
and and try to use agents as much as possible

00:26:17.109 --> 00:26:21.250
and then you'll probably see that the seus will

00:26:21.250 --> 00:26:25.009
be might be even sufficient which you get for

00:26:25.009 --> 00:26:28.990
free from microsoft if they're not you can still

00:26:28.990 --> 00:26:33.150
deploy your own seus And the free amount of use

00:26:33.150 --> 00:26:35.509
is deducted at the end of the month, according

00:26:35.509 --> 00:26:39.009
to Microsoft. So that's great. But be careful

00:26:39.009 --> 00:26:41.670
with those pre provisioned issues, because if

00:26:41.670 --> 00:26:44.609
you pre provision an issue, it is running on

00:26:44.609 --> 00:26:46.730
an hourly rate. And if you're not using it, you

00:26:46.730 --> 00:26:48.849
still be paying for it because Microsoft has

00:26:48.849 --> 00:26:51.789
actually reserved some hardware in the back end

00:26:51.789 --> 00:26:56.390
for you. So if you have E five, check if the

00:26:56.390 --> 00:26:58.769
free issues are enabled on your tenant already.

00:26:59.170 --> 00:27:02.859
If not, start messing around with the SUs, but

00:27:02.859 --> 00:27:05.900
be careful. Either remove them once you're not

00:27:05.900 --> 00:27:09.380
using them or keep the amount very low. Microsoft

00:27:09.380 --> 00:27:11.220
says they're rolling out, they're still rolling

00:27:11.220 --> 00:27:13.460
out this feature. So they started actually at

00:27:13.460 --> 00:27:16.720
Ignite, as you mentioned to Chris. But due to

00:27:16.720 --> 00:27:20.480
some hardware constraints and performance constraints,

00:27:20.720 --> 00:27:24.819
they are now doing it in phases for customers.

00:27:26.039 --> 00:27:27.960
So that's actually the bad news. Unfortunately,

00:27:28.079 --> 00:27:31.160
some customers are still waiting for this. It's

00:27:31.160 --> 00:27:33.880
a capacity problem. And Microsoft will let you

00:27:33.880 --> 00:27:36.740
know 30 days in advance when they will enable

00:27:36.740 --> 00:27:39.680
it on your tenant and provide you those compute

00:27:39.680 --> 00:27:47.769
units. So we already touched on some. security

00:27:47.769 --> 00:27:51.990
attack factors, new attack factors on AI, right?

00:27:52.049 --> 00:27:54.730
Chris, you mentioned the agents with running

00:27:54.730 --> 00:27:57.390
on user privilege or high privileged access.

00:28:00.200 --> 00:28:04.339
I also saw some great blogs by some fellow MVPs

00:28:04.339 --> 00:28:08.000
a couple of weeks on this subject. Well, first

00:28:08.000 --> 00:28:10.279
of all, Entry ID identity protection now has

00:28:10.279 --> 00:28:14.680
an for agents capability. It is in preview. Like

00:28:14.680 --> 00:28:16.920
you said, agents can operate autonomously and

00:28:16.920 --> 00:28:19.859
on behalf of the user, but they have some different

00:28:19.859 --> 00:28:22.640
sign in behavior. Microsoft is now tapping into

00:28:22.640 --> 00:28:26.960
that to decide if an agent probably should have

00:28:26.960 --> 00:28:29.200
a certain risk status. And then obviously you

00:28:29.200 --> 00:28:32.519
can block that through conditional access once

00:28:32.519 --> 00:28:35.980
you know that. I will post a couple of links

00:28:35.980 --> 00:28:37.779
in the show notes, actually. There was an awesome

00:28:37.779 --> 00:28:41.359
blog from Dirk van der Wouden and also Raymond

00:28:41.359 --> 00:28:45.160
Ruthoff, both security MVPs. And you may guess,

00:28:45.160 --> 00:28:48.049
Chris, where they're from. Yes, I'm sure they're

00:28:48.049 --> 00:28:51.309
Dutch, right? Because all the great security

00:28:51.309 --> 00:28:56.329
work comes out. I don't know. I keep the running

00:28:56.329 --> 00:29:01.410
gag alive here. So actually, Raymond had a nice

00:29:01.410 --> 00:29:03.650
approach. He wrote an excellent blog about how

00:29:03.650 --> 00:29:06.029
you can protect the Copilot Studio, which people

00:29:06.029 --> 00:29:08.329
use to create their own agents, with the help

00:29:08.329 --> 00:29:11.109
of Defender for Cloud apps. So by leveraging

00:29:11.109 --> 00:29:13.369
Defender for Cloud apps, making sure that people

00:29:13.369 --> 00:29:16.420
are using Copilot Studio more. So definitely

00:29:16.420 --> 00:29:18.980
check that out. He also did some great security

00:29:18.980 --> 00:29:21.119
research on Defender of Identity in the past,

00:29:21.220 --> 00:29:24.160
by the way. So make sure to follow him and check

00:29:24.160 --> 00:29:28.700
out his articles. He's one MVP that I have not

00:29:28.700 --> 00:29:31.500
come across. So that's cool. I like that. Again,

00:29:32.000 --> 00:29:33.619
especially in the Defender of Identity space,

00:29:33.940 --> 00:29:36.480
he is very technical, but he's also a good speaker.

00:29:36.759 --> 00:29:42.019
I saw him several times and he really has a relaxing

00:29:42.019 --> 00:29:46.150
way of explaining stuff. So great guy. um And

00:29:46.150 --> 00:29:48.930
lastly, I want to touch on something that I thought

00:29:48.930 --> 00:29:51.130
was kind of fun. So I was actually part of the

00:29:51.130 --> 00:29:53.210
organization of Yellow Hat, which took place

00:29:53.210 --> 00:29:55.630
last week. And one of the things we did for the

00:29:55.630 --> 00:29:59.109
on -site attendees, we had a second hall, so

00:29:59.109 --> 00:30:02.109
to speak, where people could attend into a capture

00:30:02.109 --> 00:30:04.829
the flag. And the capture the flag was provided

00:30:04.829 --> 00:30:08.829
to us by Blue Raven, which is also already a

00:30:08.829 --> 00:30:11.569
great company because they provide KQL training

00:30:11.569 --> 00:30:15.890
and all kinds of lab environments. for security

00:30:15.890 --> 00:30:19.650
analysts to simulate all kinds of attacks and

00:30:19.650 --> 00:30:23.809
train staff in that way. And the people from

00:30:23.809 --> 00:30:25.549
Blue Raven provided us the Capture the Flag.

00:30:25.789 --> 00:30:29.349
And what's funny is it was originally meant for

00:30:29.349 --> 00:30:32.049
people on site as the attendees. And the Capture

00:30:32.049 --> 00:30:34.789
the Flag went open the night before Yellow had

00:30:34.789 --> 00:30:37.190
started and it closed the night after Yellow

00:30:37.190 --> 00:30:39.329
had started. So they had about 48 hours or something

00:30:39.329 --> 00:30:43.400
to compete. separately or in teams and find all

00:30:43.400 --> 00:30:45.960
the flags. But obviously, people are going to

00:30:45.960 --> 00:30:50.019
share login information across the world to invite

00:30:50.019 --> 00:30:52.819
other people into that, which was fine. We didn't

00:30:52.819 --> 00:30:55.059
account for that, but that's fine. Unfortunately,

00:30:55.880 --> 00:30:58.019
those people who actually solved the capture

00:30:58.019 --> 00:31:00.019
the flag outside of the venue were not able to

00:31:00.019 --> 00:31:02.460
participate in the prizes which we were handing

00:31:02.460 --> 00:31:05.660
out. But nevertheless, there was one guy, Nikola

00:31:05.660 --> 00:31:10.180
Suter. He's from Switzerland, and he thought

00:31:10.220 --> 00:31:13.660
but it would be fun to see how AI can assist

00:31:13.660 --> 00:31:16.720
him on the capture the flag. And he used Azure

00:31:16.720 --> 00:31:19.619
Fabric, a real -time intelligence MCP server

00:31:19.619 --> 00:31:22.440
to connect to the lab environment from Blue Raven

00:31:22.440 --> 00:31:25.900
and let AI assist him on his hunt. And he wrote

00:31:25.900 --> 00:31:28.240
down his experience and all of his lessons learned

00:31:28.240 --> 00:31:30.480
in a blog. And I think you should definitely

00:31:30.480 --> 00:31:32.380
check that out as well. The link is also in the

00:31:32.380 --> 00:31:34.660
show notes. Really cool stuff. He's definitely

00:31:34.660 --> 00:31:37.920
living in 2028, isn't he? That's pretty awesome.

00:31:38.200 --> 00:31:40.920
I'm feeling a little bit. when I read blogs like

00:31:40.920 --> 00:31:45.740
this, Chris, to be honest. And he also acknowledged,

00:31:45.859 --> 00:31:47.640
obviously, that the capture the flag is meant

00:31:47.640 --> 00:31:51.779
to train analytical capabilities from a person,

00:31:51.900 --> 00:31:54.859
obviously, and you can consider this cheating,

00:31:54.940 --> 00:31:57.579
of course, but I think it's still a very fun

00:31:57.579 --> 00:31:59.920
exercise, and especially because he wrote down

00:31:59.920 --> 00:32:04.519
his experiences. Thank you for providing that

00:32:04.519 --> 00:32:05.940
link. That's going to be a really interesting

00:32:05.940 --> 00:32:08.819
read, for sure. Yeah, yeah, it sure is. So a

00:32:08.819 --> 00:32:12.019
lot of links in the show notes this time. And

00:32:12.019 --> 00:32:15.039
this brings, I think, to the closing notes, our

00:32:15.039 --> 00:32:20.220
community project, Chris. This year, this time,

00:32:20.319 --> 00:32:24.599
I brought a community project from Overgesaf.

00:32:25.329 --> 00:32:28.869
He is, as he calls himself, the SIEM guy at Microsoft.

00:32:29.569 --> 00:32:32.250
People in the community probably know him as

00:32:32.250 --> 00:32:36.390
the father of Sentinel. He worked on ArcSight,

00:32:36.490 --> 00:32:39.250
a different SIEM solution from HP. And he came

00:32:39.250 --> 00:32:41.650
to Microsoft in 2019 to help create Microsoft

00:32:41.650 --> 00:32:44.369
Sentinel. And around that time, I started working

00:32:44.369 --> 00:32:46.930
with Microsoft Sentinel. So I've met and spoken

00:32:46.930 --> 00:32:48.910
to O for a couple of times. He's a cool guy.

00:32:48.990 --> 00:32:52.500
He's such a relaxed person, isn't he? Very chill,

00:32:52.619 --> 00:32:55.700
but such a very, very smart, nice guy. Yeah,

00:32:55.759 --> 00:32:58.000
and like you said, very knowledgeable. And he's

00:32:58.000 --> 00:33:02.140
also, you might not think of him this way, but

00:33:02.140 --> 00:33:04.539
he's also a very technical guy. And I think this

00:33:04.539 --> 00:33:06.819
community project proves it because he created

00:33:06.819 --> 00:33:10.700
an Azure Sentinel solutions analyzer. So as he

00:33:10.700 --> 00:33:13.839
stated himself, he said, I get asked all the

00:33:13.839 --> 00:33:16.259
time which tables each Sentinel connector writes

00:33:16.259 --> 00:33:19.059
to. Surprisingly, the answer isn't straightforward.

00:33:19.400 --> 00:33:21.200
And that's true. I encountered that couple. of

00:33:21.200 --> 00:33:24.259
times as well many connectors share tables and

00:33:24.259 --> 00:33:26.559
other rights to multiple tables and until now

00:33:26.559 --> 00:33:29.660
there hasn't been a single complete list so he

00:33:29.660 --> 00:33:32.319
built one well he must he also admitted that

00:33:32.319 --> 00:33:34.660
he got a lot of help from uh get a co -pilot

00:33:34.660 --> 00:33:38.119
agent with claude sonnet uh to do most of the

00:33:38.119 --> 00:33:41.299
heavy lifting he wrote a python script which

00:33:41.299 --> 00:33:43.099
you can run against your environment and it will

00:33:43.099 --> 00:33:46.700
retrieve all this information but he also published

00:33:46.700 --> 00:33:50.589
pre -compiled comma separated files on his GitHub

00:33:50.589 --> 00:33:54.309
with the current state of the environment. And

00:33:54.309 --> 00:33:56.950
I was actually doing an SAP integration this

00:33:56.950 --> 00:34:00.509
week for a customer. And there with SecurityBridge

00:34:00.509 --> 00:34:02.970
is a third -party solution. And I noticed that

00:34:02.970 --> 00:34:06.109
that was indeed listed in his overview. So very

00:34:06.109 --> 00:34:08.829
nice indeed, which was also a solution writing

00:34:08.829 --> 00:34:12.250
to multiple different tables. So it can be confusing

00:34:12.250 --> 00:34:14.469
sometimes. So if you're encountering, if you're

00:34:14.469 --> 00:34:16.869
working with Sentinel, with especially third

00:34:16.869 --> 00:34:20.139
-party connectors, definitely check it out. Yeah,

00:34:20.219 --> 00:34:22.340
very nice. That's awesome. Thanks for sharing

00:34:22.340 --> 00:34:25.719
that one. I don't do all that much work on Sentinel,

00:34:25.860 --> 00:34:29.079
but I do know Ofer, so that's a very cool thing.

00:34:29.239 --> 00:34:33.659
Very nice. Very cool project of him. Wow, that's

00:34:33.659 --> 00:34:36.760
very nice. That kind of wraps us up for the first

00:34:36.760 --> 00:34:41.539
episode of Season 2. If you're just listening

00:34:41.539 --> 00:34:43.659
to us for the first time or you've come back

00:34:43.659 --> 00:34:48.440
after listening to Season 1, welcome back. We

00:34:48.440 --> 00:34:52.460
have... uh deployed and uh published our our

00:34:52.460 --> 00:34:55.340
updated uh website so we've got some you know

00:34:55.340 --> 00:34:57.760
a bit of a cleaner look and feel there kind of

00:34:57.760 --> 00:35:00.320
makes reading all the the the content and the

00:35:00.320 --> 00:35:03.440
show notes stuff a lot easier now so um major

00:35:03.440 --> 00:35:06.559
kudos to chris by the way oh yeah look it was

00:35:06.559 --> 00:35:09.260
a little bit happy listing fun holiday project

00:35:09.260 --> 00:35:14.449
and did i create the website chris no no Certainly

00:35:14.449 --> 00:35:17.909
I can't claim that I did that, but it was a fun

00:35:17.909 --> 00:35:19.909
holiday project. AI did help with some imagery

00:35:19.909 --> 00:35:23.210
for sure on that. But yeah, no, it's been fun.

00:35:23.329 --> 00:35:25.949
I'm glad that it's there. So folks, if you haven't

00:35:25.949 --> 00:35:28.389
already checked it out, please do check that

00:35:28.389 --> 00:35:30.670
out. If you have any sort of questions or comments

00:35:30.670 --> 00:35:34.510
or feedback on, well, anything really, please

00:35:34.510 --> 00:35:37.110
do reach out to us on the socials or you can

00:35:37.110 --> 00:35:40.510
find either one of us on LinkedIn as well. All

00:35:40.510 --> 00:35:43.780
of our stuff is. pretty uh easily um you know

00:35:43.780 --> 00:35:47.940
available um and uh yeah we uh definitely look

00:35:47.940 --> 00:35:50.719
forward to uh episode two uh coming around again

00:35:50.719 --> 00:35:53.920
uh so yeah please leave a comment and uh like

00:35:53.920 --> 00:35:56.380
chris said if you have any feedback also negative

00:35:56.380 --> 00:35:59.579
feedback we're open to and also i many potential

00:35:59.579 --> 00:36:02.440
ids which we should cover in the future would

00:36:02.440 --> 00:36:05.380
be yes yes anything burning problems or challenges

00:36:05.380 --> 00:36:07.039
or anything you'd like to know more about you

00:36:07.039 --> 00:36:09.500
know definitely do reach out and and let us know

00:36:09.500 --> 00:36:13.000
yeah thanks for listening everybody we'll catch

00:36:13.000 --> 00:36:14.420
you next time bye
