WEBVTT

00:00:11.129 --> 00:00:13.269
Hello, and welcome to another episode of the

00:00:13.269 --> 00:00:15.609
Everyday Defender podcast. We're back again.

00:00:15.669 --> 00:00:17.649
It's been a month. I can't believe the time has

00:00:17.649 --> 00:00:19.670
gone by so quickly, but here we are back again.

00:00:19.789 --> 00:00:21.870
And I'm joined as always by my friend from the

00:00:21.870 --> 00:00:24.329
Netherlands. How are you doing, Koos? Hey, Chris.

00:00:24.530 --> 00:00:27.449
How are you doing? Yeah, it's August already.

00:00:28.030 --> 00:00:30.809
Summer has almost passed here in the Netherlands.

00:00:31.529 --> 00:00:34.530
I do still have my holiday in front of me. I'm

00:00:34.530 --> 00:00:37.070
leaving in October, actually. So quite a late

00:00:37.070 --> 00:00:41.630
holiday for the European listeners. But yeah,

00:00:41.750 --> 00:00:44.600
nice to see you again. Yeah, we're actually getting

00:00:44.600 --> 00:00:46.759
some better weather too. It's warming up for

00:00:46.759 --> 00:00:49.079
us. So spring is here, which also means lots

00:00:49.079 --> 00:00:51.500
of farm chores and, you know, all of that type

00:00:51.500 --> 00:00:55.000
of stuff. But hey, not complaining with the nice,

00:00:55.119 --> 00:00:56.560
well, it's raining today, but not complaining

00:00:56.560 --> 00:00:58.579
with the nice weather in general. I saw you and

00:00:58.579 --> 00:01:02.039
your wife washing the donkey the other day outside.

00:01:02.659 --> 00:01:05.799
Yes, washing a donkey is not the easiest of things

00:01:05.799 --> 00:01:10.459
to do. I saw that. That's funny. Yes, it was.

00:01:10.700 --> 00:01:13.140
Her Instagram is full of interesting things.

00:01:14.859 --> 00:01:17.500
But not talking about donkeys or llamas or anything

00:01:17.500 --> 00:01:20.519
like that today. Yeah, really interested, Kosta,

00:01:20.519 --> 00:01:23.519
to hear about Project Perception today. This

00:01:23.519 --> 00:01:25.719
is going to be one I'm super excited to hear

00:01:25.719 --> 00:01:28.180
your thoughts on that and sort of sit back and

00:01:28.180 --> 00:01:30.879
just have you go through all of that type of

00:01:30.879 --> 00:01:35.000
stuff. I wanted to talk just a little bit about

00:01:35.000 --> 00:01:38.980
some changes to authentication methods in Entra.

00:01:39.379 --> 00:01:41.719
You know, it's a very small announcement that

00:01:41.719 --> 00:01:44.060
happened, you know, last month or I think it

00:01:44.060 --> 00:01:47.840
was last month. But it is, you know, the potential

00:01:47.840 --> 00:01:50.040
to impact some folks. And I've also heard some

00:01:50.040 --> 00:01:53.299
confusion. I sort of wanted to jump into that,

00:01:53.400 --> 00:01:57.420
and then I'll have you tackle the big topic,

00:01:57.579 --> 00:01:59.620
right? And then, you know, as to close out the

00:01:59.620 --> 00:02:02.519
show again, I promised on the last episode that

00:02:02.519 --> 00:02:05.599
I'd talk about Connect 365, so I have something

00:02:05.599 --> 00:02:08.639
to share about that as well as we close out later.

00:02:08.740 --> 00:02:11.560
Well, don't call SMS MFA a small topic because

00:02:11.560 --> 00:02:14.080
I think it has some large impact. I don't know

00:02:14.080 --> 00:02:17.780
the details myself, so let us hear what you have

00:02:17.780 --> 00:02:19.439
to say on that, but I think people are still

00:02:19.439 --> 00:02:22.639
using it a lot. lot on scale and that's that's

00:02:22.639 --> 00:02:25.939
true right so so um essentially for for folks

00:02:25.939 --> 00:02:28.780
who are not aware who may have missed it um sort

00:02:28.780 --> 00:02:32.099
of somewhere mid july around the 13th of july

00:02:32.099 --> 00:02:35.759
microsoft had sort of announced that um it was

00:02:35.759 --> 00:02:39.379
going to deprecate SMS and voice authentication

00:02:39.379 --> 00:02:43.439
methods, right? So if you possibly still have

00:02:43.439 --> 00:02:45.699
MFA enabled for folks, but they're using, I guess,

00:02:45.719 --> 00:02:48.199
legacy methods and you receive maybe a text message

00:02:48.199 --> 00:02:51.699
or a voice phone call, which used to be an option

00:02:51.699 --> 00:02:55.560
or still is an option, those methods are now

00:02:55.560 --> 00:02:57.979
sort of being phased out and deprecated, right?

00:02:58.080 --> 00:03:00.400
And we've talked to it. I mean, we're going to

00:03:00.400 --> 00:03:02.180
have to go back to like season one on this show

00:03:02.180 --> 00:03:05.620
where we talked about. multi -factor authentication

00:03:05.620 --> 00:03:07.919
and conditional access. And we talked about,

00:03:07.919 --> 00:03:10.400
you know, why SMS isn't the greatest anymore

00:03:10.400 --> 00:03:13.439
anyway, right? So I think everyone understands

00:03:13.439 --> 00:03:16.240
that text messaging and voice calls and stuff

00:03:16.240 --> 00:03:19.680
are easily spoofable and just are not good mechanisms

00:03:19.680 --> 00:03:24.280
or methods for MFA. But there are still organizations

00:03:24.280 --> 00:03:28.819
that use it, right? And so... I guess my concern,

00:03:28.919 --> 00:03:31.500
and I actually just went through this process

00:03:31.500 --> 00:03:36.139
with a client, and actually today was the big

00:03:36.139 --> 00:03:39.360
day that they made all the changes within their

00:03:39.360 --> 00:03:41.919
environment to actually catch all of the last

00:03:41.919 --> 00:03:44.759
users that were still using SMS and stuff. So

00:03:44.759 --> 00:03:47.800
literally, this is very new for me. And incidentally,

00:03:47.800 --> 00:03:50.800
they had made the decision to move away from

00:03:50.800 --> 00:03:53.969
these methods. before Microsoft announced it.

00:03:54.009 --> 00:03:55.430
So they've been planning it now for two or three

00:03:55.430 --> 00:03:58.090
months that they've been sort of working on moving

00:03:58.090 --> 00:04:02.650
away from text messaging and voice. It just so

00:04:02.650 --> 00:04:04.469
happens that, you know, whilst this was going

00:04:04.469 --> 00:04:06.129
on, Microsoft also announced that they were going

00:04:06.129 --> 00:04:08.729
to sort of drop support. And so there's actually

00:04:08.729 --> 00:04:10.780
quite a lot. involved in this right and so i

00:04:10.780 --> 00:04:12.580
thought you know what this is really topical

00:04:12.580 --> 00:04:14.639
i originally i was going to talk a little bit

00:04:14.639 --> 00:04:16.560
more about vulnerability management but i thought

00:04:16.560 --> 00:04:18.819
let me bring this one um sort of forward and

00:04:18.819 --> 00:04:20.860
talk about this because this is happening right

00:04:20.860 --> 00:04:24.339
now so um as i said microsoft announced this

00:04:24.339 --> 00:04:28.759
in july immediately i've sort of seen um picked

00:04:28.759 --> 00:04:31.240
up on some confusion uh sort of out in the industry

00:04:31.240 --> 00:04:33.620
and i've also seen some interesting commentary

00:04:33.620 --> 00:04:37.899
right through blogs and online about this and

00:04:38.329 --> 00:04:40.029
I guess the first thing to sort of set straight

00:04:40.029 --> 00:04:44.290
is sort of what actually is happening. So SMS

00:04:44.290 --> 00:04:48.430
MFA is not being banned in Entra. Like that's

00:04:48.430 --> 00:04:50.250
one of the headlines that I saw somewhere is

00:04:50.250 --> 00:04:53.189
like SMS MFA is being banned. Like that's not

00:04:53.189 --> 00:04:54.709
actually what's happening. What Microsoft is

00:04:54.709 --> 00:04:57.709
doing is they're retiring the Microsoft provided

00:04:57.709 --> 00:05:01.089
text messaging and voice sort of capability.

00:05:01.410 --> 00:05:04.310
So, you know, up until now, those text messages

00:05:04.310 --> 00:05:06.879
that were sent. voice calls that happen, it's

00:05:06.879 --> 00:05:09.240
all Microsoft's sort of telephony stuff, right?

00:05:09.720 --> 00:05:11.600
They're essentially just phasing that out and

00:05:11.600 --> 00:05:14.160
you will no longer be able to do that in intro.

00:05:14.259 --> 00:05:17.660
There will not be options for you anymore. I

00:05:17.660 --> 00:05:19.839
know that there are still organizations that

00:05:19.839 --> 00:05:25.620
use text messaging, right? In my mind, I struggle

00:05:25.620 --> 00:05:29.000
to come up with scenarios and use cases anymore

00:05:29.000 --> 00:05:32.199
where text messaging is the only option, right?

00:05:32.240 --> 00:05:36.779
I feel like a YubiKey. can replace any you know

00:05:36.779 --> 00:05:39.399
any text messaging sort of solution right if

00:05:39.399 --> 00:05:41.639
you've got offline type scenarios or no internet

00:05:41.639 --> 00:05:44.660
type scenarios where maybe you've got a cell

00:05:44.660 --> 00:05:47.399
service but you don't have the internet those

00:05:47.399 --> 00:05:49.339
are some of the scenarios historically but i

00:05:49.339 --> 00:05:51.920
feel like ubiquis can sort of cater to that now

00:05:51.920 --> 00:05:55.160
um i know that you know in the past i've had

00:05:55.160 --> 00:06:00.139
clients where they have um minors or young people

00:06:00.139 --> 00:06:02.240
logging into the environment if you think about

00:06:02.240 --> 00:06:04.699
schools and things like that they can't always

00:06:04.699 --> 00:06:08.079
rely on those you know younger generation um

00:06:08.079 --> 00:06:11.779
or minors having smartphones right and so text

00:06:11.779 --> 00:06:14.019
messaging was a was sort of an answer or a solution

00:06:14.019 --> 00:06:16.779
to giving them mfa and i and i see that i think

00:06:16.779 --> 00:06:19.100
there are other solutions for sort of that cater

00:06:19.100 --> 00:06:21.959
to the education space and the sort of kids or

00:06:21.959 --> 00:06:24.759
children's space these days so i in my mind i

00:06:24.759 --> 00:06:28.220
struggle to to come up with like real proper

00:06:28.220 --> 00:06:31.779
scenarios that still require text messaging where

00:06:31.779 --> 00:06:35.720
i hear heard it a lot uh years ago where employees

00:06:35.720 --> 00:06:38.339
were complaining that when companies started

00:06:38.339 --> 00:06:42.060
uh embracing mfa in general and they were forcing

00:06:42.060 --> 00:06:45.839
that's how how employees sometimes felt and forcing

00:06:46.649 --> 00:06:49.589
an app on their private phones, right? So they

00:06:49.589 --> 00:06:51.730
were like, this is my private phone. If the company

00:06:51.730 --> 00:06:53.769
wants me to do something, then they hand me out

00:06:53.769 --> 00:06:57.550
a business phone and I'll use that for it. But

00:06:57.550 --> 00:07:00.850
like you said, with physical YubiKeys, MFA pass

00:07:00.850 --> 00:07:03.610
keys, physical pass keys, I don't think that

00:07:03.610 --> 00:07:06.850
argument really stands anymore. And I think that's

00:07:06.850 --> 00:07:08.750
a very good one because I think that is a very

00:07:08.750 --> 00:07:11.550
valid argument that still happens possibly in

00:07:11.550 --> 00:07:15.930
Europe. I think your laws around ability to disconnect,

00:07:16.009 --> 00:07:20.290
and using personal devices and things for work

00:07:20.290 --> 00:07:22.670
functions is a lot more strict, I think, than

00:07:22.670 --> 00:07:25.029
other parts of the world. I think California

00:07:25.029 --> 00:07:27.310
also has some very interesting laws that may

00:07:27.310 --> 00:07:31.490
sort of, you know, sort of come into play here.

00:07:31.670 --> 00:07:33.750
But you're right, like the YubiKey answer just

00:07:33.750 --> 00:07:36.050
solves that problem, right? And it's a lot cheaper

00:07:36.050 --> 00:07:40.310
to give someone a YubiKey that costs $100 than

00:07:40.310 --> 00:07:42.769
to give them an iPhone that costs $1 ,000, right?

00:07:43.160 --> 00:07:46.199
It's not even $100 if you buy them in bulk and

00:07:46.199 --> 00:07:49.620
you go for the less expensive non -biometric

00:07:49.620 --> 00:07:51.980
versions. It's only a couple of, I don't know,

00:07:52.060 --> 00:07:55.439
$20 or something. Yeah, no, absolutely. So look,

00:07:55.620 --> 00:07:59.519
I think we sort of understand and agree that's

00:07:59.519 --> 00:08:02.660
probably very few sort of real scenarios where

00:08:02.660 --> 00:08:06.379
text messaging is still really needed. But Microsoft

00:08:06.379 --> 00:08:10.399
are not removing... you know, saying you can't

00:08:10.399 --> 00:08:11.920
use it. They're just saying they're no longer

00:08:11.920 --> 00:08:14.959
going to provide that service, right? So essentially,

00:08:15.139 --> 00:08:18.680
if you do need that capability, Microsoft are

00:08:18.680 --> 00:08:21.819
going to have partners, sort of telco partners

00:08:21.819 --> 00:08:25.920
that will provide that, right? Now, I went and

00:08:25.920 --> 00:08:27.660
had a look today to see if I could track down.

00:08:28.170 --> 00:08:30.990
a list of these partners and i cannot so that

00:08:30.990 --> 00:08:34.470
list is not available online yet um i believe

00:08:34.470 --> 00:08:36.610
it's only being really the list itself is only

00:08:36.610 --> 00:08:39.909
being released on the 18th of september i would

00:08:39.909 --> 00:08:43.110
expect we would see folks like twilio and and

00:08:43.110 --> 00:08:45.549
you know those types of telco as a service you

00:08:45.549 --> 00:08:48.850
know api as a service type vendors um on that

00:08:48.850 --> 00:08:52.940
list so the takeaway is Microsoft's going to

00:08:52.940 --> 00:08:55.820
stop providing the service, SMS and voice services,

00:08:55.879 --> 00:08:58.500
but you could, if you still desperately need

00:08:58.500 --> 00:09:04.000
it, you can. come up with ways to engage third

00:09:04.000 --> 00:09:06.100
parties. And ultimately, you're going to be paying

00:09:06.100 --> 00:09:08.100
for those text messages yourself now, right?

00:09:08.200 --> 00:09:10.500
So it's not going to be Microsoft funding or

00:09:10.500 --> 00:09:14.039
footing the bill for the messages and voice calls

00:09:14.039 --> 00:09:15.659
and stuff being sent. If you're going to sign

00:09:15.659 --> 00:09:17.080
up to something like Twilio, you're going to

00:09:17.080 --> 00:09:20.360
end up paying for it. So that's the first piece

00:09:20.360 --> 00:09:22.080
I wanted to kind of clarify on this because I

00:09:22.080 --> 00:09:24.039
feel like that got lost a little bit in translation

00:09:24.039 --> 00:09:26.840
with this announcement. But the second piece

00:09:26.840 --> 00:09:28.700
and probably the more important piece is that

00:09:29.529 --> 00:09:31.450
Passkeys are going to become the default experience

00:09:31.450 --> 00:09:35.789
now, right? And I feel like this is probably

00:09:35.789 --> 00:09:40.549
more likely to cause folks issues and have a

00:09:40.549 --> 00:09:43.070
bigger user impact in organizations if you don't

00:09:43.070 --> 00:09:45.750
plan for it, right? So we all know Passkeys,

00:09:45.850 --> 00:09:49.309
it's a great solution. Some organizations, I

00:09:49.309 --> 00:09:51.549
think, are slower to adopt Passkeys than others.

00:09:51.830 --> 00:09:55.200
And with this change, there is definitely the

00:09:55.200 --> 00:09:57.340
potential where you're going to get users who

00:09:57.340 --> 00:09:58.899
are going to get sort of forced down this path

00:09:58.899 --> 00:10:01.820
key route. And if you don't get ahead of it and

00:10:01.820 --> 00:10:03.840
plan it with, you know, comms and all the rest

00:10:03.840 --> 00:10:06.259
of the things, there's going to be a challenge,

00:10:06.360 --> 00:10:09.259
right? So if we look at the timeline here on

00:10:09.259 --> 00:10:12.019
how this is supposedly going to play out, so

00:10:12.019 --> 00:10:14.460
the 1st of September, which, you know, as we

00:10:14.460 --> 00:10:17.700
sit here recording, it's going to be in, you

00:10:17.700 --> 00:10:19.379
know, just over a week's time. It's the 1st of

00:10:19.379 --> 00:10:23.230
September. Actually, it's exactly a week, is

00:10:23.230 --> 00:10:27.309
the 1st of September. So as you listen to this,

00:10:27.429 --> 00:10:29.549
it's probably yesterday, right, that this happened

00:10:29.549 --> 00:10:33.269
or a couple of days ago. But 1st of September

00:10:33.269 --> 00:10:36.350
is when essentially what's going to happen is

00:10:36.350 --> 00:10:39.190
users that are enabled for SMS or voice authentication

00:10:39.190 --> 00:10:42.330
methods are going to be auto -enabled for passkeys.

00:10:42.809 --> 00:10:45.389
So you're probably going to find if you don't

00:10:45.389 --> 00:10:47.450
get ahead of this and you have users that are

00:10:47.450 --> 00:10:50.029
using... you know, text messaging as a primary

00:10:50.029 --> 00:10:52.169
authentication method, they're going to start

00:10:52.169 --> 00:10:55.129
getting nudged for passkey registration, right?

00:10:55.350 --> 00:10:57.830
Now, initially, they're going to be able to skip

00:10:57.830 --> 00:10:59.950
that passkey registration and they can skip the

00:10:59.950 --> 00:11:02.629
prompt. But, you know, as time goes by, that...

00:11:02.799 --> 00:11:05.080
the ability to do that is going to go away. So

00:11:05.080 --> 00:11:07.940
that happens first of September. So you don't

00:11:07.940 --> 00:11:10.799
have much time. On the 18th, apparently, is when

00:11:10.799 --> 00:11:12.960
we'll start seeing the supported list of telco

00:11:12.960 --> 00:11:15.519
providers and what the deployment guidance looks

00:11:15.519 --> 00:11:19.720
like, you know, for all of this pricing, all

00:11:19.720 --> 00:11:21.980
of that type of stuff in the Microsoft Security

00:11:21.980 --> 00:11:24.539
Store. That's where we'll see that. And then

00:11:24.539 --> 00:11:27.299
I think 30th of October is when you can actually

00:11:27.299 --> 00:11:29.639
start configuring these sort of third -party

00:11:29.639 --> 00:11:33.509
providers. Now, you know... I don't know how

00:11:33.509 --> 00:11:37.549
concrete these dates are. This is stuff that

00:11:37.549 --> 00:11:39.350
I've sort of pieced together, you know, reading

00:11:39.350 --> 00:11:42.149
various articles and looking at various sources.

00:11:42.269 --> 00:11:44.850
So some of the stuff isn't from Microsoft officially.

00:11:45.070 --> 00:11:47.049
So again, you know, take it with a grain of salt

00:11:47.049 --> 00:11:50.029
in terms of when telcos are going to be providing

00:11:50.029 --> 00:11:52.049
stuff, when the partners will be released, all

00:11:52.049 --> 00:11:53.590
of that stuff. But hopefully this gives you a

00:11:53.590 --> 00:11:55.110
little bit of an indication as like the change

00:11:55.110 --> 00:11:57.409
is happening soon. You need to actually start

00:11:57.409 --> 00:12:00.360
looking at it. And then the 1st of February is

00:12:00.360 --> 00:12:02.320
sort of the next really big milestone date on

00:12:02.320 --> 00:12:03.639
the Microsoft side. That's when they're officially

00:12:03.639 --> 00:12:06.759
retiring that service in intro, right? So after

00:12:06.759 --> 00:12:12.220
the 1st of February, you know... Users are going

00:12:12.220 --> 00:12:15.639
to be forced to register their pass keys. There's

00:12:15.639 --> 00:12:19.360
not going to be a skip option anymore or a snooze

00:12:19.360 --> 00:12:22.080
option on that registration. So that prompt will

00:12:22.080 --> 00:12:24.399
essentially be forced for them to be logging

00:12:24.399 --> 00:12:26.120
in. So you've got to really get ahead of your

00:12:26.120 --> 00:12:30.139
registration campaigns and comms processes and

00:12:30.139 --> 00:12:33.779
all of that stuff to make sure that you're informing

00:12:33.779 --> 00:12:36.460
your user base of what's happening. And I think

00:12:36.460 --> 00:12:40.200
this is really the key message that... I wanted

00:12:40.200 --> 00:12:44.379
to get out for this today. If you have a large

00:12:44.379 --> 00:12:46.179
environment and every single one of your users

00:12:46.179 --> 00:12:49.779
is going to be affected by this, well, you've

00:12:49.779 --> 00:12:51.480
got a week, so that's not really a lot of time.

00:12:51.539 --> 00:12:57.279
There is an opt -out capability sort of to opt

00:12:57.279 --> 00:12:59.080
out of this between that 1st of September and

00:12:59.080 --> 00:13:02.039
1st of February window. It does delay that auto

00:13:02.039 --> 00:13:04.360
-enrollment, and it's sort of a one -time only

00:13:04.360 --> 00:13:07.779
thing. Once February hits, though, there's no

00:13:07.779 --> 00:13:10.240
more opt -out, right? So very important to know

00:13:10.240 --> 00:13:12.019
that you've got, you know, potentially between

00:13:12.019 --> 00:13:13.919
now and February to try and solve this problem.

00:13:15.080 --> 00:13:17.779
There are some great resources available. So

00:13:17.779 --> 00:13:20.919
I've put some links in the show notes to a PowerShell

00:13:20.919 --> 00:13:22.799
script that actually can help you identify this.

00:13:22.879 --> 00:13:26.299
So if you don't actually know, and I would encourage

00:13:26.299 --> 00:13:28.279
you to run this, even if you think everyone in

00:13:28.279 --> 00:13:30.899
your organization is running, you know, Authenticator

00:13:30.899 --> 00:13:34.889
or Passkeys or something. I still run this just

00:13:34.889 --> 00:13:38.590
to make sure, right? With my client, we have

00:13:38.590 --> 00:13:40.950
been running this sort of script over the last

00:13:40.950 --> 00:13:44.029
little while to identify people. And we actually

00:13:44.029 --> 00:13:46.730
noticed in the last month, some people who had

00:13:46.730 --> 00:13:49.769
previously been using Authenticator had all of

00:13:49.769 --> 00:13:52.309
a sudden switched to text messaging again. So

00:13:52.309 --> 00:13:54.610
just because you think that you had it under

00:13:54.610 --> 00:13:57.870
control last week or last month. may not be the

00:13:57.870 --> 00:13:59.970
case right now. So there is a link to a script

00:13:59.970 --> 00:14:02.470
on GitHub that Microsoft has published for this.

00:14:02.529 --> 00:14:04.590
We'll help you identify the scale and the scope

00:14:04.590 --> 00:14:07.889
of the change in your environment. There's some

00:14:07.889 --> 00:14:11.129
interesting information about comms and the process

00:14:11.129 --> 00:14:13.610
and all of that type of stuff on Microsoft Learn.

00:14:13.690 --> 00:14:16.070
So I've linked to that as well. And I'm hoping

00:14:16.070 --> 00:14:18.889
that this will kind of help folks, you know,

00:14:18.889 --> 00:14:21.549
just try and get ahead of this a little bit if

00:14:21.549 --> 00:14:26.000
you can. Not a lot of time here. So, yeah. I

00:14:26.000 --> 00:14:28.860
was surprised about the timelines, actually,

00:14:28.980 --> 00:14:31.559
Chris. I'm not sure if we have seen Microsoft

00:14:31.559 --> 00:14:36.860
announce something which was forced on everybody

00:14:36.860 --> 00:14:39.779
in such short notice. That's right, yeah. Usually

00:14:39.779 --> 00:14:41.720
you would think there's at least nine months

00:14:41.720 --> 00:14:43.799
or a year or whatever it is, right? But this

00:14:43.799 --> 00:14:45.419
is very, very sudden, and I think that's the

00:14:45.419 --> 00:14:48.139
thing. It was only announced in July, and it's

00:14:48.139 --> 00:14:51.480
taken that long. just for people to become aware

00:14:51.480 --> 00:14:54.799
of it right um so if you know um yeah definitely

00:14:54.799 --> 00:14:58.230
is is a very very short runway on this um and

00:14:58.230 --> 00:15:00.769
of course most people in the community the mvps

00:15:00.769 --> 00:15:03.230
everybody who's working with microsoft identity

00:15:03.230 --> 00:15:07.289
solutions very uh intensively they already saw

00:15:07.289 --> 00:15:09.450
this coming of course one day and they probably

00:15:09.450 --> 00:15:12.429
already moved away from sms authentication but

00:15:12.429 --> 00:15:14.610
i can imagine especially a lot of larger customers

00:15:14.610 --> 00:15:17.309
who uses its scale when they announce something

00:15:17.309 --> 00:15:20.429
in july and only six weeks later they are forced

00:15:20.429 --> 00:15:23.929
uh with prompts to the user which they can opt

00:15:23.929 --> 00:15:26.720
out of but six weeks is short notice i would

00:15:26.720 --> 00:15:30.240
say yeah yeah i mean a lot of organizations you

00:15:30.240 --> 00:15:33.539
can't get comms out to your entire business in

00:15:33.539 --> 00:15:36.500
six weeks right if you think about the the process

00:15:36.500 --> 00:15:38.580
and i mean for right for you know whether it's

00:15:38.580 --> 00:15:41.299
right or wrong or whatever it's just the reality

00:15:41.299 --> 00:15:44.399
is that it takes a while for the the information

00:15:44.399 --> 00:15:46.919
to filter through you know you have to engage

00:15:47.629 --> 00:15:49.690
you know, change management people, comms people,

00:15:49.850 --> 00:15:52.190
draft up the comms, review the comms, make sure

00:15:52.190 --> 00:15:54.289
the comms go out to all the right people, make

00:15:54.289 --> 00:15:55.929
sure that all the distribution lists are up to

00:15:55.929 --> 00:15:57.870
date so that everyone actually receives the comms.

00:15:57.909 --> 00:16:00.669
Like it's a, you know, it's not so easy when

00:16:00.669 --> 00:16:03.370
you're trying to do this at large scale. So hopefully

00:16:03.370 --> 00:16:05.629
this helps some folks. Yeah, and on the other

00:16:05.629 --> 00:16:07.990
hand, we're talking about cybersecurity here,

00:16:08.110 --> 00:16:12.990
and maybe companies should realize that they

00:16:12.990 --> 00:16:17.330
should adapt to have a faster way to implement

00:16:17.330 --> 00:16:20.669
changes. Because, well, nowadays with everything

00:16:20.669 --> 00:16:23.190
that's going on, with all the cyber attacks going

00:16:23.190 --> 00:16:26.450
on everywhere, you have to adapt quickly. Same

00:16:26.450 --> 00:16:28.409
as with patching, vulnerability management we

00:16:28.409 --> 00:16:31.429
talked about earlier. You can't have a server

00:16:31.429 --> 00:16:34.730
patch four times a year anymore. Because you

00:16:34.730 --> 00:16:37.149
don't get the comms out quicker to employees

00:16:37.149 --> 00:16:41.190
or whatever. It's something you have to adapt

00:16:41.190 --> 00:16:44.169
to, I guess, in this modern world. No, you're

00:16:44.169 --> 00:16:45.870
not wrong. That's a very good point. That is

00:16:45.870 --> 00:16:48.970
a very, very good point. Yeah. Yeah, and that

00:16:48.970 --> 00:16:52.330
maybe also allows me to bridge this a little

00:16:52.330 --> 00:16:55.129
bit into the next topic, project perception.

00:16:56.299 --> 00:17:01.419
Also an announcement in July, Monday 27th, Microsoft

00:17:01.419 --> 00:17:04.680
made a big announcement where they launched Project

00:17:04.680 --> 00:17:08.519
Perception to the world. I saw it all over my

00:17:08.519 --> 00:17:10.859
LinkedIn feed. Everybody was talking about it.

00:17:11.359 --> 00:17:13.700
Only a couple of people were actually at the

00:17:13.700 --> 00:17:15.779
launch event, but it was a big launch event.

00:17:15.819 --> 00:17:18.200
There were also some international press there,

00:17:18.339 --> 00:17:22.839
and they made quite some headlines there. What

00:17:22.839 --> 00:17:25.059
is Project Perception? Well, in short, it's marketing.

00:17:25.099 --> 00:17:28.160
Microsoft's agentic AI cybersecurity platform.

00:17:28.460 --> 00:17:30.420
And I know what you're thinking. You're hearing

00:17:30.420 --> 00:17:33.079
AI and you're probably already reaching out to

00:17:33.079 --> 00:17:35.220
the knob of your radio to turn off this podcast.

00:17:35.339 --> 00:17:39.440
Don't do it. It's no AI slop or AI marketing

00:17:39.440 --> 00:17:43.740
speak going on here. So Microsoft hasn't been

00:17:43.740 --> 00:17:45.940
very subtle about the framing either. So attackers

00:17:45.940 --> 00:17:50.630
now also. use ai and ai agents to attack companies

00:17:50.630 --> 00:17:55.190
and we mentioned being faster with your changes

00:17:55.190 --> 00:17:57.670
and that is actually something that you have

00:17:57.670 --> 00:18:01.789
to apply on defending for cyber attacks as well

00:18:03.309 --> 00:18:06.170
According to Microsoft, reactive security is

00:18:06.170 --> 00:18:10.789
over. Their answer boils down to it takes agents

00:18:10.789 --> 00:18:14.250
to fight agents. Well, you might think this is

00:18:14.250 --> 00:18:16.769
a lot of marketing speak by Microsoft, and it

00:18:16.769 --> 00:18:19.390
probably is a little bit. But if you look at

00:18:19.390 --> 00:18:22.130
the research, there are quite some figures to

00:18:22.130 --> 00:18:26.329
back this up. If you look at the results from

00:18:26.329 --> 00:18:30.029
a threat report from CrowdStrike, they measured

00:18:30.029 --> 00:18:33.680
an 89 % year -over -year increase. in AI -enabled

00:18:33.680 --> 00:18:38.900
adversary operations. And there's also an international

00:18:38.900 --> 00:18:42.759
AI safety report, which is a report written up

00:18:42.759 --> 00:18:45.480
by more than 90 authors. And they report that

00:18:45.480 --> 00:18:49.420
AI agents are already finding 77 % of all software

00:18:49.420 --> 00:18:52.799
vulnerabilities. The number that even surprised

00:18:52.799 --> 00:18:57.140
me more is that that capability is doubling every

00:18:57.140 --> 00:19:00.519
seven months. So if you look at how AI is being

00:19:00.519 --> 00:19:02.599
capable of finding software vulnerabilities,

00:19:03.079 --> 00:19:05.859
you can imagine that if you just let people loose

00:19:05.859 --> 00:19:08.019
with their AI agents are probably attacking you

00:19:08.019 --> 00:19:10.880
and abusing those, exploiting those vulnerabilities

00:19:10.880 --> 00:19:14.180
faster than you can patch them or defend against

00:19:14.180 --> 00:19:17.240
them. Like I said, Microsoft really wants to

00:19:17.240 --> 00:19:19.859
have something in place to coordinate the defense

00:19:19.859 --> 00:19:23.319
around such. attacks. What they kind of do, they

00:19:23.319 --> 00:19:25.859
use signals and perception, which they already

00:19:25.859 --> 00:19:29.059
have from your endpoints, your servers, your

00:19:29.059 --> 00:19:32.380
identity. That's Defender XDR as we know it,

00:19:32.380 --> 00:19:35.559
right? A lot of signals going in there. A lot

00:19:35.559 --> 00:19:38.859
of those signals are stored into tables and Microsoft

00:19:38.859 --> 00:19:43.420
is trying to have with AI agents, they want to

00:19:44.319 --> 00:19:46.660
Apply security context on top of that and have

00:19:46.660 --> 00:19:50.099
a continuously monitoring of your state, so to

00:19:50.099 --> 00:19:52.819
speak. So like I said, they work with agents.

00:19:52.920 --> 00:19:55.839
Well, not just separate agents, but actually

00:19:55.839 --> 00:19:58.900
entire teams of agents. And they divided them

00:19:58.900 --> 00:20:00.779
into separate teams. And I think this is quite

00:20:00.779 --> 00:20:03.299
a unique approach. They have red, blue, and green

00:20:03.299 --> 00:20:08.000
teams. The red teams sound familiar. They uncover

00:20:08.000 --> 00:20:11.069
attack parts and they should... be able to expose

00:20:11.069 --> 00:20:16.430
some attack parts in your environment before

00:20:16.430 --> 00:20:18.910
the attackers do, hopefully. The blue agents

00:20:18.910 --> 00:20:21.589
are there to do the triage on the incidents,

00:20:21.869 --> 00:20:24.950
but they can also correlate signals and come

00:20:24.950 --> 00:20:28.750
up with new detections to help you find things

00:20:28.750 --> 00:20:31.430
faster in the future. And then you have the green

00:20:31.430 --> 00:20:34.789
agents, and they are there to remediate findings

00:20:34.789 --> 00:20:40.059
and harden your posture. That concept of green

00:20:40.059 --> 00:20:44.470
agents and green teaming, it's not the... First

00:20:44.470 --> 00:20:46.549
time I've heard it, but it certainly is a new

00:20:46.549 --> 00:20:48.089
concept, isn't it? It's something we're starting

00:20:48.089 --> 00:20:50.690
to hear more and more now is that third line

00:20:50.690 --> 00:20:53.210
of defense, the green agents and the green team

00:20:53.210 --> 00:20:55.589
stuff. Yeah. Yeah. And it's funny that you mentioned

00:20:55.589 --> 00:20:57.869
that because the technology behind these green

00:20:57.869 --> 00:21:01.529
agents is not that new. I haven't covered this

00:21:01.529 --> 00:21:04.009
on this podcast yet. It was on my to -do list.

00:21:04.410 --> 00:21:07.650
It was called Project M -. Probably maybe you

00:21:07.650 --> 00:21:10.630
have heard of this. I have. It is an M and then

00:21:10.630 --> 00:21:14.180
dash, but it pronounces M -. It's an acronym

00:21:14.180 --> 00:21:16.900
apparently. It stands for multi -model agentic

00:21:16.900 --> 00:21:19.220
scanning harness. But sometimes I think these

00:21:19.220 --> 00:21:21.980
acronyms are just made up after the fact. I don't

00:21:21.980 --> 00:21:25.200
know. Well, it began as an internal project at

00:21:25.200 --> 00:21:27.519
Microsoft to hunt down vulnerabilities in software.

00:21:27.779 --> 00:21:30.619
And it even uncovered a batch of previously unknown

00:21:30.619 --> 00:21:34.960
bugs in Windows itself. And in July, MDash was

00:21:34.960 --> 00:21:37.359
actually released in private preview and integrated

00:21:37.359 --> 00:21:41.619
into the Defender exposure management pane. So

00:21:41.619 --> 00:21:43.869
as part of Defender... of XDR exposure management,

00:21:44.069 --> 00:21:48.289
they were already applying AI to help you finding

00:21:48.289 --> 00:21:50.750
some hardening improvements in your environment

00:21:50.750 --> 00:21:53.630
and through exposure management. And now they

00:21:53.630 --> 00:21:56.490
took MDash and they equipped the harness with

00:21:56.490 --> 00:21:59.490
an in -house cybersecurity model. And this was

00:21:59.490 --> 00:22:01.869
the second time. This was also a part of the

00:22:01.869 --> 00:22:04.410
big announcement, to be honest. So Microsoft

00:22:04.410 --> 00:22:08.930
has an in -house Microsoft AI division and they...

00:22:09.720 --> 00:22:12.240
are working and developing all kinds of specific

00:22:12.240 --> 00:22:15.420
LLMs for specific tasks. And for cybersecurity,

00:22:15.559 --> 00:22:19.480
they created a new model called MAI Cyber One

00:22:19.480 --> 00:22:23.099
Flash. Try to say that 10 times faster, Chris.

00:22:23.980 --> 00:22:27.779
Well, the MAI stands for Microsoft AI. So that

00:22:27.779 --> 00:22:32.349
is the... depicting that it is an in -house model

00:22:32.349 --> 00:22:37.309
from the AI division inside Microsoft. They also

00:22:37.309 --> 00:22:40.970
released a transcribed voice image and now Cyber

00:22:40.970 --> 00:22:48.690
1 Flash. I think Flash is added to... to let

00:22:48.690 --> 00:22:51.509
you know that this is a fast model. There will

00:22:51.509 --> 00:22:54.569
probably be larger cyber models that are working

00:22:54.569 --> 00:22:58.910
on as well. So again, with the combination with

00:22:58.910 --> 00:23:01.710
this new cyber model and the MDash capabilities

00:23:01.710 --> 00:23:05.190
they already created, that has now become the

00:23:05.190 --> 00:23:09.349
green agent, the green teams in Project Perception.

00:23:10.840 --> 00:23:13.640
So I saw quite some impressive demos, and I'm

00:23:13.640 --> 00:23:17.019
linking in the show notes also the original release

00:23:17.019 --> 00:23:19.319
with, I don't know, a one -hour video with a

00:23:19.319 --> 00:23:21.420
lot of demos in there. It's quite impressive

00:23:21.420 --> 00:23:23.779
how you can see that the red agents, for example,

00:23:23.779 --> 00:23:26.640
are hunting down vulnerabilities in some kind

00:23:26.640 --> 00:23:31.839
of web application or databases using legacy

00:23:31.839 --> 00:23:35.599
authentication, for example. The red teams will

00:23:35.599 --> 00:23:39.059
actually actively try and take advantage of these

00:23:39.059 --> 00:23:42.259
bugs and prove. that they are exploitable. And

00:23:42.259 --> 00:23:44.579
then the blue agents will propose new detections

00:23:44.579 --> 00:23:48.160
and hunting queries to make sure you're alerted

00:23:48.160 --> 00:23:50.900
when abuse happens. And the green agents for

00:23:50.900 --> 00:23:54.220
the whole MDash stuff is applying fixes. So they're

00:23:54.220 --> 00:23:57.880
proposing even literally GitHub or Azure DevOps

00:23:57.880 --> 00:24:02.519
pull requests to improve settings in your environment

00:24:02.519 --> 00:24:09.380
to fix those posture improvements. Okay, wow.

00:24:10.120 --> 00:24:13.599
With the whole new CyberOne Flash model they

00:24:13.599 --> 00:24:15.640
announced, they were quite proud, and I think

00:24:15.640 --> 00:24:19.279
rightfully so, that they were able to pair this

00:24:19.279 --> 00:24:24.200
with ChatGPT 5 .4 and achieve a score of 96 %

00:24:24.200 --> 00:24:28.609
on CyberGym. So Cybergym is a universal benchmark

00:24:28.609 --> 00:24:32.369
used by a lot of companies nowadays to prove

00:24:32.369 --> 00:24:37.150
how good a LLM model is into detecting software

00:24:37.150 --> 00:24:40.549
vulnerabilities. And I believe this was the highest

00:24:40.549 --> 00:24:45.269
score yet. They scored even 12 points above Anthropix

00:24:45.269 --> 00:24:51.480
Mythos. So Mythos was obviously... became quite

00:24:51.480 --> 00:24:56.400
famous lately. But they scored above that in

00:24:56.400 --> 00:24:59.420
the cyber gym and even with less power consumption.

00:24:59.799 --> 00:25:04.160
So this was... this was also a big thing and

00:25:04.160 --> 00:25:06.680
great to hear Microsoft thinking about this because

00:25:06.680 --> 00:25:08.779
we don't know what project perception is actually

00:25:08.779 --> 00:25:11.000
going to cost just to skip to the conclusion

00:25:11.000 --> 00:25:14.180
on this right now. It's a limited private preview

00:25:14.180 --> 00:25:16.660
right now. They're figuring out how they're going

00:25:16.660 --> 00:25:21.759
to make this happen cost -wise. But they did

00:25:21.759 --> 00:25:24.740
mention that they are aware that this whole security

00:25:24.740 --> 00:25:28.079
and AI defense isn't always on mission, right?

00:25:29.099 --> 00:25:32.519
So you have, to constantly be looking out for

00:25:32.519 --> 00:25:35.119
vulnerabilities and attacks and you're processing

00:25:35.119 --> 00:25:39.589
lots of tokens if you do that 24 -7. And these

00:25:39.589 --> 00:25:42.069
costs are a real constraint for the defenders.

00:25:42.210 --> 00:25:44.910
Because if you think of it, an adversary has

00:25:44.910 --> 00:25:48.009
the benefit here. They are only targeting a company

00:25:48.009 --> 00:25:50.970
or targeting a set of applications for a limited

00:25:50.970 --> 00:25:54.009
time. So they're spending tokens only for a limited

00:25:54.009 --> 00:25:56.269
time when they're using AI for that. And the

00:25:56.269 --> 00:25:59.349
defenders have to defend 24 -7. So Microsoft

00:25:59.349 --> 00:26:02.890
really recognizes this. And that's also why they

00:26:02.890 --> 00:26:06.730
shared some details on how they are actually

00:26:06.730 --> 00:26:09.990
routing different... models together so they

00:26:09.990 --> 00:26:13.089
use small models like the cyber one flash model

00:26:13.089 --> 00:26:18.359
for the day -to -day more more uh bulk of the

00:26:18.359 --> 00:26:21.279
ai operations and when it comes to harder tasks

00:26:21.279 --> 00:26:23.799
they're able to route it to a more expensive

00:26:23.799 --> 00:26:28.299
more elaborate bigger model um for for specific

00:26:28.299 --> 00:26:30.400
tasks and that would be the harness that's doing

00:26:30.400 --> 00:26:32.599
that right that's where you would use m dashes

00:26:32.599 --> 00:26:34.539
to make you know route between the models and

00:26:34.539 --> 00:26:36.619
stuff and yeah i'm i was going to ask you do

00:26:36.619 --> 00:26:39.299
you know if if the mai models are actually available

00:26:39.299 --> 00:26:43.440
for for use um like by themselves or do you have

00:26:43.440 --> 00:26:45.859
to use because i've i've heard of them obviously

00:26:45.859 --> 00:26:51.940
microsoft strategically they will be bit you

00:26:51.940 --> 00:26:54.579
know well served by developing their own models

00:26:54.579 --> 00:26:57.960
so they can be less reliant on open ai and and

00:26:57.960 --> 00:27:00.259
others right and so obviously for a while now

00:27:00.259 --> 00:27:02.200
they've been working on these mai models but

00:27:02.200 --> 00:27:04.640
i'm curious as to whether you could just use

00:27:04.640 --> 00:27:08.500
um one of the like the mai the cyber flash model

00:27:09.600 --> 00:27:12.500
itself in in stuff that you're doing you know

00:27:12.920 --> 00:27:17.039
Well, I can put some more research in that and

00:27:17.039 --> 00:27:21.920
maybe we can have this topic on a future episode

00:27:21.920 --> 00:27:24.440
because I think the whole discussion about open

00:27:24.440 --> 00:27:27.460
versus closed LLM models and running the models

00:27:27.460 --> 00:27:30.579
locally even without being depending on the big

00:27:30.579 --> 00:27:33.000
clouds and everything is a very interesting topic.

00:27:33.220 --> 00:27:35.880
I did a quick Google search and apparently the

00:27:35.880 --> 00:27:38.500
Microsoft MAI models are not open source. So

00:27:38.500 --> 00:27:41.549
they're a propriety in -house models. Just like,

00:27:41.549 --> 00:27:43.450
well, the Anthropic models are, for example,

00:27:43.450 --> 00:27:45.230
you can only use them through their services.

00:27:45.930 --> 00:27:49.490
I do see that the models can be used from Azure

00:27:49.490 --> 00:27:55.630
AI Foundry. So that's not the same as running

00:27:55.630 --> 00:27:59.450
them locally, of course, but then you can probably

00:27:59.450 --> 00:28:04.369
connect them. Foundry is expensive. I've been

00:28:04.369 --> 00:28:07.289
messing around with some of the GLM open models

00:28:07.289 --> 00:28:12.549
and GLM 5 .2. I think the Foundry cost to run

00:28:12.549 --> 00:28:16.289
that is something like $60 an hour. It's, you

00:28:16.289 --> 00:28:18.930
know, it's not nothing. But it's interesting

00:28:18.930 --> 00:28:21.630
because, you know, one of the challenges I think

00:28:21.630 --> 00:28:25.150
as a defender trying to defend things is that

00:28:25.150 --> 00:28:27.809
a lot of the commercial models have such big,

00:28:27.809 --> 00:28:30.390
like so many guardrails, right? You can't get,

00:28:30.470 --> 00:28:33.569
you know, Claude and Sonnet or any of the current

00:28:33.569 --> 00:28:37.309
Claude models to defend or do anything into in,

00:28:37.329 --> 00:28:41.690
you know. that's cyber -specific because it triggers

00:28:41.690 --> 00:28:45.190
the guardrails so quickly. And so you almost

00:28:45.190 --> 00:28:49.170
have to be looking at how can you use open models

00:28:49.170 --> 00:28:51.349
or use models where you can bring the processing

00:28:51.349 --> 00:28:54.210
of that stuff in -house or use it locally so

00:28:54.210 --> 00:28:57.259
that you can use the full... power of the model

00:28:57.259 --> 00:28:59.779
without tripping the guardrails right yeah so

00:28:59.779 --> 00:29:01.619
this whole thing is going to become very interesting

00:29:01.619 --> 00:29:03.500
because it's great to have the model but the

00:29:03.500 --> 00:29:05.500
model is not useful if if it doesn't allow you

00:29:05.500 --> 00:29:07.779
to do the things that you need it to do um so

00:29:07.779 --> 00:29:10.690
yeah Yeah, and that was also the main reason

00:29:10.690 --> 00:29:14.670
why Anthropic did not release the Mythos model

00:29:14.670 --> 00:29:18.170
a while ago. And then Fable launched, which was

00:29:18.170 --> 00:29:21.089
a more stripped down, a more secure version with

00:29:21.089 --> 00:29:24.369
a lot of guardrails, people noticed. So, yeah,

00:29:24.630 --> 00:29:27.970
that might be also the reason. I'm not sure if

00:29:27.970 --> 00:29:35.329
MAI… why CyberOne Flash is actually being available

00:29:35.329 --> 00:29:38.130
in AI Foundry to chat with and interactively

00:29:38.130 --> 00:29:43.930
interact with. When you look at Project Perception,

00:29:44.049 --> 00:29:46.549
and I put some screenshots also in the show notes,

00:29:46.650 --> 00:29:51.609
you have what they call playbooks. And these

00:29:51.609 --> 00:29:55.359
playbooks are now pre... But I can imagine there

00:29:55.359 --> 00:29:57.440
will be more and there will be probably some

00:29:57.440 --> 00:29:59.279
options where you create your own playbooks.

00:29:59.440 --> 00:30:03.000
So, for example, you can tell Project Perception

00:30:03.000 --> 00:30:05.960
that you want help with an investigation on an

00:30:05.960 --> 00:30:09.440
incident. And it has a blue icon telling you

00:30:09.440 --> 00:30:11.480
that the blue team will actually help you with

00:30:11.480 --> 00:30:13.720
that. And you point it to an incident and it

00:30:13.720 --> 00:30:16.099
will do the whole triage for you and it will

00:30:16.099 --> 00:30:19.160
write you a report. And if there are any remediating

00:30:19.160 --> 00:30:22.460
actions required, it will ask you for input.

00:30:22.509 --> 00:30:26.430
So it will never interact. It's always humanly

00:30:26.430 --> 00:30:29.390
driven on the decision part. But you can, for

00:30:29.390 --> 00:30:33.289
example, also ask it to protect against a specific

00:30:33.289 --> 00:30:37.670
threat. So there is from the... threat intelligence

00:30:37.670 --> 00:30:40.190
feed obviously a whole list of threats in there

00:30:40.190 --> 00:30:42.670
you can select a threat so i don't know some

00:30:42.670 --> 00:30:45.650
kind of storm or blizzard or you know all those

00:30:45.650 --> 00:30:47.890
you've seen those names before and you can say

00:30:47.890 --> 00:30:50.170
i want to protect my company against this threat

00:30:50.170 --> 00:30:52.950
and you can see a red a blue and green green

00:30:52.950 --> 00:30:55.890
icon stand next to there and there all the agent

00:30:55.890 --> 00:30:58.640
teams will actually come into play and try and

00:30:58.640 --> 00:31:00.980
see if you're actually vulnerable to that threat

00:31:00.980 --> 00:31:03.460
and what you can do to protect yourself against

00:31:03.460 --> 00:31:06.720
it. And also I really liked the green one, which

00:31:06.720 --> 00:31:09.000
is in the screenshot as well, plan for posture

00:31:09.000 --> 00:31:12.339
remediation. So then it will go across your estates,

00:31:12.339 --> 00:31:15.519
also your Azure cloud and all the Defender XDR

00:31:15.519 --> 00:31:20.059
stuff and give you a prioritized list of how

00:31:20.059 --> 00:31:22.619
you can improve your posture as well. And that

00:31:22.619 --> 00:31:26.140
is the MDash stuff you see now as part of perception.

00:31:26.990 --> 00:31:31.730
There goes my joke. Very new, of course. So it

00:31:31.730 --> 00:31:34.549
is in limited private preview, so you can request

00:31:34.549 --> 00:31:38.710
access, but I'm not sure how they will be giving

00:31:38.710 --> 00:31:40.769
out access right now. I can imagine there are

00:31:40.769 --> 00:31:43.849
a lot of constraints on hardware and costs in

00:31:43.849 --> 00:31:49.049
the back as well. Like I said, it's still read

00:31:49.049 --> 00:31:51.589
-only right now, so the agents are not actually...

00:31:51.960 --> 00:31:54.640
making changes for you. But I can't imagine a

00:31:54.640 --> 00:31:58.359
future where that will happen. It's only Azure

00:31:58.359 --> 00:32:00.480
for now when it comes to cloud reconnaissance.

00:32:01.099 --> 00:32:04.839
So no on -prem, no AWS or GCP or whatever. So

00:32:04.839 --> 00:32:08.619
there's a lot of stuff that will be added later.

00:32:08.819 --> 00:32:12.819
And it is expected that parts of this will be

00:32:12.819 --> 00:32:17.299
released during Ignite later this year. Okay.

00:32:17.380 --> 00:32:20.089
I mean, it's such an interesting... We're in

00:32:20.089 --> 00:32:23.390
this place now where things are changing so quickly,

00:32:23.470 --> 00:32:25.589
right? The rapid development in this is crazy.

00:32:25.789 --> 00:32:27.930
So it wouldn't surprise me if in a month from

00:32:27.930 --> 00:32:31.250
now, this has already matured significantly from

00:32:31.250 --> 00:32:33.769
where it is today, right? You know, we've definitely

00:32:33.769 --> 00:32:36.170
seen that type of improvements. And again, it

00:32:36.170 --> 00:32:38.049
goes back to your point that you made earlier

00:32:38.049 --> 00:32:42.000
of like, we really need... as organizations to

00:32:42.000 --> 00:32:44.380
be able to react more quickly to things right

00:32:44.380 --> 00:32:47.279
it doesn't help if you now look at this and you

00:32:47.279 --> 00:32:49.000
go hey this sounds like a good idea sounds like

00:32:49.000 --> 00:32:51.519
something i want to use in my organization and

00:32:51.519 --> 00:32:53.640
it takes you a year to plan to be able to implement

00:32:53.640 --> 00:32:56.519
it right because one year from now it's going

00:32:56.519 --> 00:32:58.440
to be a completely different landscape and and

00:32:58.440 --> 00:33:01.380
there's you know so the quick iteration you know

00:33:01.380 --> 00:33:04.359
fail fast mentality is is and mindset is really

00:33:04.359 --> 00:33:06.799
going to help um organizations stay ahead so

00:33:07.289 --> 00:33:11.289
Very cool. Yeah, and the company I work for has

00:33:11.289 --> 00:33:14.029
been a design partner on Project Perception for

00:33:14.029 --> 00:33:17.170
a while now. So we have access. So I was able

00:33:17.170 --> 00:33:20.140
to play around a little bit with it. Unfortunately,

00:33:20.180 --> 00:33:22.759
I couldn't take any screen captures or videos

00:33:22.759 --> 00:33:25.460
of that because it's obviously a private preview

00:33:25.460 --> 00:33:29.640
or limited public preview, I must say. But I

00:33:29.640 --> 00:33:32.200
really recommend looking at the introduction

00:33:32.200 --> 00:33:34.980
link in the show notes and watch the video there

00:33:34.980 --> 00:33:36.420
with some demos, and then you'll get a better

00:33:36.420 --> 00:33:40.400
understanding of how this is going to work. Yeah,

00:33:40.480 --> 00:33:43.980
and it's interesting times with all the AI stuff.

00:33:44.059 --> 00:33:47.119
I still sometimes have some hard times when it

00:33:47.119 --> 00:33:50.059
comes to... how we now interact with each other.

00:33:50.160 --> 00:33:54.079
I'm getting fully automated emails from HR by

00:33:54.079 --> 00:33:58.259
AI nowadays, and it makes me also sigh a little

00:33:58.259 --> 00:34:01.160
bit inside. But on the other hand, it's really

00:34:01.160 --> 00:34:04.880
interesting what AI can bring you. Not only it

00:34:04.880 --> 00:34:08.360
enables me to be a sort of programmer nowadays,

00:34:08.579 --> 00:34:11.360
I'm creating a lot of cool stuff I wasn't able

00:34:11.360 --> 00:34:13.639
to do in the past, but also with the whole defending

00:34:13.639 --> 00:34:17.260
stuff. I think it's really important to embrace

00:34:17.449 --> 00:34:20.010
the ai side of things there because otherwise

00:34:20.010 --> 00:34:23.090
like you said you're too late and the tackle

00:34:23.090 --> 00:34:26.550
has already taken place yeah and you're not you're

00:34:26.550 --> 00:34:29.590
not wrong um and i think that's a it's a good

00:34:29.590 --> 00:34:31.869
segue right because um well it's a good table

00:34:31.869 --> 00:34:34.409
for two reasons but let me comment is i i'm getting

00:34:34.409 --> 00:34:37.829
so much linkedin ai like i literally have people

00:34:37.829 --> 00:34:40.489
reaching out to me on linkedin um and it's all

00:34:40.489 --> 00:34:43.030
ai bots right because you know when you when

00:34:43.030 --> 00:34:44.980
you respond to say please know don't contact

00:34:44.980 --> 00:34:47.119
me again or thank you for the contact but you

00:34:47.119 --> 00:34:48.539
know because i like to try and be as polite as

00:34:48.539 --> 00:34:51.260
possible but after i've politely declined you

00:34:51.260 --> 00:34:53.219
three times and then you reach out to me a fourth

00:34:53.219 --> 00:34:55.380
time like that's just you know that's just rude

00:34:55.380 --> 00:34:58.179
right and it's because it's all ai so um you

00:34:58.179 --> 00:35:00.960
know um but i was gonna say uh it's a good segue

00:35:00.960 --> 00:35:03.239
because you know to talk about our community

00:35:03.239 --> 00:35:06.679
project i'd um i'd sort of said to everyone uh

00:35:06.679 --> 00:35:09.960
last month that i would i would update on uh

00:35:09.960 --> 00:35:12.320
connect 365 and kind of where we are and you

00:35:12.320 --> 00:35:14.139
know a lot of what i've been able to achieve

00:35:14.139 --> 00:35:17.940
working on this project has been because of the

00:35:17.940 --> 00:35:22.280
help of AI. And I conceptualized this stuff such

00:35:22.280 --> 00:35:27.380
a long time ago, but I struggle to find time

00:35:27.380 --> 00:35:30.360
to learn new things, right? And especially when

00:35:30.360 --> 00:35:32.579
it comes to learning to code in Rust, right?

00:35:32.639 --> 00:35:34.800
Stuff like that. I'm super interested in it,

00:35:34.900 --> 00:35:37.539
but I don't always have the time to spend. It's

00:35:37.539 --> 00:35:40.510
like learning to speak Dutch. love to do it don't

00:35:40.510 --> 00:35:43.409
always have the time to spend to um to uh to

00:35:43.409 --> 00:35:45.730
to commit to it right i'm not sure if i agree

00:35:45.730 --> 00:35:47.969
with that comparison chris because learning rushed

00:35:47.969 --> 00:35:51.889
you can use ai for that so you just tell ai to

00:35:51.889 --> 00:35:53.949
do that talking dutch you have to do yourself

00:35:53.949 --> 00:35:56.710
well both are equally useful though right so

00:35:56.710 --> 00:36:01.389
um but uh anyway so um Essentially, for those

00:36:01.389 --> 00:36:06.150
folks who don't know, Connect 365 is sort of

00:36:06.150 --> 00:36:08.190
a PowerShell -based, or it used to be a PowerShell

00:36:08.190 --> 00:36:10.530
-based tool that I put together. I think I wrote

00:36:10.530 --> 00:36:12.730
the first version of this thing back in sort

00:36:12.730 --> 00:36:17.130
of 2010 or 2012. And it was just a way to very

00:36:17.130 --> 00:36:19.630
quickly and easily, at the time, connect to Exchange

00:36:19.630 --> 00:36:22.409
Online. So, you know, you had to remember a whole

00:36:22.409 --> 00:36:24.449
sequence of commands in order to connect to Exchange

00:36:24.449 --> 00:36:28.510
Online via PowerShell back in the day. Instead

00:36:28.510 --> 00:36:32.449
of just stringing them together into a PS1 file,

00:36:32.650 --> 00:36:36.150
I wrapped a GUI around it so that you could execute

00:36:36.150 --> 00:36:38.190
it and then it would give you a login interface,

00:36:38.369 --> 00:36:42.429
basically. Now, back then, we used basic auth,

00:36:42.469 --> 00:36:44.610
so it was username and password. And so it was

00:36:44.610 --> 00:36:46.449
easy to just take the username and password,

00:36:46.530 --> 00:36:49.730
put it into the field on a GUI, and then just

00:36:49.730 --> 00:36:52.440
pass that through to... connect to login but

00:36:52.440 --> 00:36:54.679
over the years you know mfa became a thing and

00:36:54.679 --> 00:36:56.559
we we you know we don't use basic auth anymore

00:36:56.559 --> 00:36:59.239
and all of that type of stuff and so i've i've

00:36:59.239 --> 00:37:01.579
updated the script you know over the years to

00:37:01.579 --> 00:37:05.519
to include more modules and the most recent version

00:37:05.519 --> 00:37:08.340
now there's a few um out of date modules in it

00:37:08.340 --> 00:37:10.920
but it basically at one point in time had everything

00:37:10.920 --> 00:37:15.760
you needed to to administer m365 from from powershell

00:37:15.760 --> 00:37:18.820
so it had links to all the modules um and essentially

00:37:18.820 --> 00:37:22.340
you You launch the script, you get an interface

00:37:22.340 --> 00:37:24.760
and you tick the services you wanted to connect

00:37:24.760 --> 00:37:26.599
to. So if you want to connect to Exchange Online

00:37:26.599 --> 00:37:29.679
and, you know, Entra, tick those two things,

00:37:29.800 --> 00:37:32.440
pop in your username. It will then authenticate

00:37:32.440 --> 00:37:35.820
you through, you know, through Entra, MFA happens,

00:37:35.940 --> 00:37:38.420
all of that stuff. And you end up with a session

00:37:38.420 --> 00:37:41.000
that has all of the correct modules imported.

00:37:41.139 --> 00:37:43.280
So you can use one window to do all the stuff.

00:37:44.440 --> 00:37:46.400
That's kind of where we are. But, you know, the

00:37:46.400 --> 00:37:48.929
challenge with it. has been that it's always

00:37:48.929 --> 00:37:54.329
been native PowerShell. And originally it was

00:37:54.329 --> 00:37:59.670
using some WinForms UI components and the current

00:37:59.670 --> 00:38:03.110
version uses WPF, which none of the stuff works

00:38:03.110 --> 00:38:06.969
cross -platform. It doesn't work in PowerShell

00:38:06.969 --> 00:38:09.690
Core. So if you want to use it on Mac or Linux,

00:38:09.809 --> 00:38:12.789
you cannot. And so for probably the last three

00:38:12.789 --> 00:38:15.949
years, I've been wanting to rebuild this and

00:38:15.949 --> 00:38:18.909
make it cross -platform. I myself stopped using

00:38:18.909 --> 00:38:22.349
Windows many, many years ago. And so I haven't

00:38:22.349 --> 00:38:24.070
been using my own tool because I don't really

00:38:24.070 --> 00:38:26.170
use Windows anymore. And it's not really something

00:38:26.170 --> 00:38:30.110
I used. And so I wanted to redo this. And I've

00:38:30.110 --> 00:38:32.469
been sort of contemplating how I make this work.

00:38:32.869 --> 00:38:35.840
And I didn't want it to be... a script anymore

00:38:35.840 --> 00:38:38.800
for some reason. And I'm still playing with the

00:38:38.800 --> 00:38:40.960
idea of having a 2E version that is all text

00:38:40.960 --> 00:38:44.179
-based and PowerShell native still. So it's not

00:38:44.179 --> 00:38:46.840
impossible that that may happen. But I wanted

00:38:46.840 --> 00:38:50.800
to essentially build an app that handled all

00:38:50.800 --> 00:38:52.659
of the connectivity for you. And so that's essentially

00:38:52.659 --> 00:38:56.019
what I've done is I've spent the time to firstly

00:38:56.019 --> 00:38:58.960
update all the modules. So we are recent again

00:38:58.960 --> 00:39:02.960
with modules that you need. And there's a bunch

00:39:02.960 --> 00:39:04.980
of them now. So if you think about things like

00:39:04.980 --> 00:39:08.539
Graph and Entra, they're all there. Teams and

00:39:08.539 --> 00:39:10.460
Exchange Online, it's all there. But I've also

00:39:10.460 --> 00:39:12.940
included third -party modules. So PMP PowerShell,

00:39:13.000 --> 00:39:17.219
which is quite a popular one that is not a Microsoft

00:39:17.219 --> 00:39:19.800
module, but lots of folks use it. So that's included

00:39:19.800 --> 00:39:24.719
as well. One of the things I've also thought

00:39:24.719 --> 00:39:27.820
about that, you know, I know frustrates a lot

00:39:27.820 --> 00:39:32.260
of people is when you connect to Graph, you have

00:39:32.260 --> 00:39:34.860
to define your scope, right? The scope of the

00:39:34.860 --> 00:39:37.340
permissions and the rights that you want to use

00:39:37.340 --> 00:39:41.320
during that session. And so not everyone always

00:39:41.320 --> 00:39:43.300
understands or knows what exactly it is they

00:39:43.300 --> 00:39:47.320
want to do. And so what I've done is I've created

00:39:47.320 --> 00:39:50.079
some quick scopes so that if you are connecting

00:39:50.079 --> 00:39:54.019
and you click Graph, it will... prompt you to

00:39:54.019 --> 00:39:56.579
to select your scope so you can go if you if

00:39:56.579 --> 00:39:58.079
you want to there's an advanced option where

00:39:58.079 --> 00:39:59.840
you can go and pick exactly the scope that you

00:39:59.840 --> 00:40:02.440
want if you know it but if you don't let's say

00:40:02.440 --> 00:40:04.500
you just want to do a user administration i've

00:40:04.500 --> 00:40:07.150
got a user administration profile tick that and

00:40:07.150 --> 00:40:10.210
it's going to correctly get, you know, your user

00:40:10.210 --> 00:40:12.329
read -write -all, group read -write -all, directory

00:40:12.329 --> 00:40:14.309
read -all. So you're going to, you know, it's

00:40:14.309 --> 00:40:17.070
just a quick way to kind of help you get to the

00:40:17.070 --> 00:40:19.250
things that you need, right? So I've predefined

00:40:19.250 --> 00:40:21.530
five that I could think of were ones that were

00:40:21.530 --> 00:40:24.349
sort of commonly used. So there's some stuff

00:40:24.349 --> 00:40:26.869
for application management and device and Intune,

00:40:26.869 --> 00:40:31.059
stuff like that. So it handles sort of that heavy

00:40:31.059 --> 00:40:34.019
lifting or figuring that stuff out for you. And

00:40:34.019 --> 00:40:38.079
then the other thing that it does that I think

00:40:38.079 --> 00:40:40.500
is really, really helpful is it actually can

00:40:40.500 --> 00:40:44.539
manage modules for you and the module installation

00:40:44.539 --> 00:40:49.199
and module updates. So there's a prerequisite

00:40:49.199 --> 00:40:51.519
checker like there was on the PowerShell version.

00:40:52.159 --> 00:40:54.539
But now the great thing about this is, you know,

00:40:54.559 --> 00:40:59.150
you can actually install and update. the, you

00:40:59.150 --> 00:41:01.369
know, the required modules that you might want

00:41:01.369 --> 00:41:03.289
to use right from the app. And it will launch

00:41:03.289 --> 00:41:06.730
PowerShell and sort of do that all for you. So

00:41:06.730 --> 00:41:12.750
it is actually a native sort of app cross -platform.

00:41:12.989 --> 00:41:16.010
It's actually built in Rust, launches PowerShell.

00:41:16.050 --> 00:41:19.050
So you end up still being, you know, once executed.

00:41:19.710 --> 00:41:21.590
you still are dropped into a PowerShell window

00:41:21.590 --> 00:41:25.309
with the correct modules and all the stuff as

00:41:25.309 --> 00:41:27.429
before. It's just the user interface and all

00:41:27.429 --> 00:41:32.929
the app logic now runs as a Rust app. So my goal

00:41:32.929 --> 00:41:39.070
is that this will be correctly assigned code

00:41:39.070 --> 00:41:43.829
as applications that you can download and install

00:41:43.829 --> 00:41:47.289
on Windows, Mac, and there's a Flatpak version

00:41:47.289 --> 00:41:51.530
for Linux as well. So still a few little bugs

00:41:51.530 --> 00:41:54.670
and things for me to test and tweak out. I've

00:41:54.670 --> 00:41:56.769
been testing it pretty thoroughly on my Mac,

00:41:56.909 --> 00:41:58.409
but I've still got to do some Windows testing

00:41:58.409 --> 00:42:01.989
and certainly Linux testing. But hopefully by

00:42:01.989 --> 00:42:04.010
the time you all are hearing this and listening

00:42:04.010 --> 00:42:07.949
to this, this will be available in GitHub and

00:42:07.949 --> 00:42:11.079
you'll be able to take it for a test drive. provide

00:42:11.079 --> 00:42:12.800
some feedback if there's anything you find that

00:42:12.800 --> 00:42:14.980
uh i'm sure there will be bugs and things that

00:42:14.980 --> 00:42:17.079
don't work this it's actually quite a complex

00:42:17.079 --> 00:42:20.699
um application now compared to um what it used

00:42:20.699 --> 00:42:23.360
to be right it used to just be you know a few

00:42:23.360 --> 00:42:25.380
hundred lines of powershell code now it's actually

00:42:25.380 --> 00:42:29.039
a very you know complex thing um but i'm thinking

00:42:29.039 --> 00:42:31.860
about all sorts of other things you know um being

00:42:31.860 --> 00:42:33.679
able to do session management and all sorts of

00:42:33.679 --> 00:42:36.619
things with it as well so um first version probably

00:42:36.619 --> 00:42:38.480
won't have everything all the bells and whistles

00:42:38.480 --> 00:42:42.380
but uh it will hopefully function well for what

00:42:42.380 --> 00:42:46.119
it needs to do. So I got some screenshots in

00:42:46.119 --> 00:42:50.119
the show notes. You even got dark mode, Chris.

00:42:50.639 --> 00:42:54.280
You know, I personally prefer the light mode,

00:42:54.440 --> 00:42:59.820
but I know that everyone else in the world likes

00:42:59.820 --> 00:43:01.800
dark mode, and I knew that I would be getting

00:43:01.800 --> 00:43:04.440
a lot of drama if I did not include dark mode.

00:43:04.480 --> 00:43:07.840
So dark mode was one of the first UI things I

00:43:07.840 --> 00:43:11.409
did. Great. Well, you have to make sure that

00:43:11.409 --> 00:43:15.690
you share this properly aside from mentioning

00:43:15.690 --> 00:43:17.869
it here in the podcast, because I think a lot

00:43:17.869 --> 00:43:20.670
of people will be very happy with what you did

00:43:20.670 --> 00:43:23.170
here. Yeah. Yeah. Look, we'll get it functioning

00:43:23.170 --> 00:43:25.610
and working properly first. And then, yeah, definitely

00:43:25.610 --> 00:43:29.050
get it shared out. It's been, you know, I've

00:43:29.050 --> 00:43:32.110
been working on this project now for, you know,

00:43:32.110 --> 00:43:35.150
15 years or so. So it's been my sort of labor

00:43:35.150 --> 00:43:37.869
of love. But I'm really sort of happy to be.

00:43:38.199 --> 00:43:40.679
um updating it and bringing it into the sort

00:43:40.679 --> 00:43:43.079
of you know some new functionality and giving

00:43:43.079 --> 00:43:45.900
folks on on max and linux uh the ability to do

00:43:45.900 --> 00:43:47.440
it too i'm i'm you know i'm hoping to eventually

00:43:47.440 --> 00:43:49.360
just have the thing be available in all the stores

00:43:49.360 --> 00:43:51.199
right so you can just download it from the store

00:43:51.199 --> 00:43:54.860
or whatever um but uh you know baby steps i guess

00:43:54.860 --> 00:43:58.719
yeah we'll make sure uh people you follow chris

00:43:58.719 --> 00:44:02.480
on linkedin and he'll uh he'll share his updates

00:44:02.480 --> 00:44:05.460
there i can imagine so we mentioned linkedin

00:44:05.460 --> 00:44:08.380
by the way earlier with with all ai content there

00:44:08.380 --> 00:44:11.139
i also saw that linkedin is now providing you

00:44:11.139 --> 00:44:13.579
an option in your feed when you click on the

00:44:13.579 --> 00:44:16.420
three dots you see an ai post you can click on

00:44:16.420 --> 00:44:18.940
the three dots and you can click on this seems

00:44:18.940 --> 00:44:22.119
like ai slop they even call it ai slop i like

00:44:22.119 --> 00:44:27.539
it so People know that this is there and fine

00:44:27.539 --> 00:44:30.519
-tune your timeline so that you only see some

00:44:30.519 --> 00:44:32.960
more human and relatable content there. And then

00:44:32.960 --> 00:44:37.159
that will ensure that Chris updates content will

00:44:37.159 --> 00:44:39.860
not get lost in the AI slot. Yeah, fair enough.

00:44:39.960 --> 00:44:41.679
That's a good one. You know what? Actually, while

00:44:41.679 --> 00:44:42.920
we're talking about social media, I've actually

00:44:42.920 --> 00:44:46.059
been thinking about going back. I haven't logged

00:44:46.059 --> 00:44:50.059
into Twitter or X. Oh, at least two and a half

00:44:50.059 --> 00:44:52.659
years, I think. I've been thinking recently that

00:44:52.659 --> 00:44:54.320
I should, because I don't have the app installed

00:44:54.320 --> 00:44:56.059
on my phone anymore or anything like that, but

00:44:56.059 --> 00:44:58.119
I've been thinking that I should log in and take

00:44:58.119 --> 00:45:01.360
a look. I do feel like I miss out on some news

00:45:01.360 --> 00:45:04.000
and stuff, right? I feel like I used to get a

00:45:04.000 --> 00:45:07.929
lot more interesting before. it got completely

00:45:07.929 --> 00:45:11.030
ruined. So I kind of wonder what the status or

00:45:11.030 --> 00:45:14.269
the state of, of Twitter is now. Um, because

00:45:14.269 --> 00:45:16.289
tech Twitter, especially cyber Twitter used to

00:45:16.289 --> 00:45:18.530
be really good, man. When you, if you follow

00:45:18.530 --> 00:45:21.150
the right people, you got some really good information

00:45:21.150 --> 00:45:23.590
there. And I try to recreate that on the other

00:45:23.590 --> 00:45:25.949
platforms, you know, um, blue sky and stuff,

00:45:26.010 --> 00:45:28.289
but I just never caught on quite the way Twitter

00:45:28.289 --> 00:45:30.690
did. So, you know, what is there? Yeah, well,

00:45:30.750 --> 00:45:33.309
that's it. So I might, um, I might do that in,

00:45:33.309 --> 00:45:37.159
excuse me, in the next month. Report back on

00:45:37.159 --> 00:45:38.860
what I find, right? Whether the thing is just

00:45:38.860 --> 00:45:42.280
all crap again or whether it's with a try. I

00:45:42.280 --> 00:45:45.619
did notice that a lot of my, when colleagues

00:45:45.619 --> 00:45:50.480
are sending me AI stuff about, like, for example,

00:45:50.480 --> 00:45:53.800
how to work with cloud code and how to implement

00:45:53.800 --> 00:45:58.579
loop and skills and tasks and whatever, a lot

00:45:58.579 --> 00:46:00.980
of the content they are sharing is through X.

00:46:01.139 --> 00:46:04.159
So a lot of videos on there, which I couldn't

00:46:04.159 --> 00:46:06.860
even find a YouTube account. part for so it made

00:46:06.860 --> 00:46:10.199
me log into twitter as well or x again to access

00:46:10.199 --> 00:46:12.380
the links they're sending me so apparently the

00:46:12.380 --> 00:46:15.659
whole ai technology development stuff is also

00:46:15.659 --> 00:46:19.480
hot on on x uh -huh well excellent well that's

00:46:19.480 --> 00:46:22.530
good We'll see where we go. But, you know, as

00:46:22.530 --> 00:46:24.809
we talk about that, here we go to the end of

00:46:24.809 --> 00:46:27.809
another episode. Man, time flies when you're

00:46:27.809 --> 00:46:30.630
having fun. Guys, thank you for sharing all about

00:46:30.630 --> 00:46:32.630
Perception and all of the cool stuff there. It'd

00:46:32.630 --> 00:46:34.389
be interesting to get my hands on that at some

00:46:34.389 --> 00:46:37.780
point. Thank you for sharing that. I think that

00:46:37.780 --> 00:46:40.519
looks very, very promising. Folks, thank you

00:46:40.519 --> 00:46:43.239
for listening. Really appreciate you taking time

00:46:43.239 --> 00:46:45.380
to listen to us. And, you know, of course, we're

00:46:45.380 --> 00:46:47.980
always open if you have any feedback or anything

00:46:47.980 --> 00:46:50.340
specific that you'd like us to look into and

00:46:50.340 --> 00:46:52.360
address for you, reach out to us, either one

00:46:52.360 --> 00:46:55.519
of us or both of us. We can be found pretty easily

00:46:55.519 --> 00:47:00.500
on the socials. And until next time, Cos, enjoy

00:47:00.500 --> 00:47:05.329
your remaining bits of summer. I will look forward

00:47:05.329 --> 00:47:07.190
to seeing you and speaking with you again very,

00:47:07.269 --> 00:47:10.050
very soon. Yeah, see you later, man. Thanks for

00:47:10.050 --> 00:47:11.050
listening, everybody. Bye -bye.
