A twice-monthly podcast dedicated to all things relating to Security, Privacy, Compliance and Reliability on the Microsoft Cloud Platform. Hosted by Microsoft security experts, Michael Howard, Sarah Young, Gladys Rodriguez and Mark Simos. https://aka.ms/azsecpod ©2020-2024 Michael Howard, Sarah Young, Gladys Rodriquez, and Mark Simos.
…
continue reading
In this show I introduce the roles of sociology and poetry in our lives, from co-existing and conveying messages to social norms and behaviors.
…
continue reading
In this episode, Michael talks to Nic Fillingham about the recent Microsoft Bluehat Security conference held at the Microsoft HQ in Redmond, WA. We also discuss how to tell the NZ and Australian accents apart. This alone is worth listening too :) This is a follow-on from episode 103 when we talked about what was coming up for Bluehat. No news, as t…
…
continue reading
1
Episode 103: Security Conferences and Bluehat
48:17
48:17
Play later
Play later
Lists
Like
Liked
48:17
In this episode we speak to Nic Fillingham who is a Senior Program Manager at Microsoft about security conferences and mainly about the Microsoft Bluehat conference he runs. We also discuss security about PostgreSQL, Cosmos DB, IP address management, containers and AI Studio. https://aka.ms/azsecpod
…
continue reading
1
Episode 102: Entra ID Purple-teaming with Dr Azure AD
36:42
36:42
Play later
Play later
Lists
Like
Liked
36:42
In this episode Michael and Sarah talk to Nestori Syynimaa about Entra ID security and his purple-team tool, AADInternals. We also cover the latest security news about Secure Future Initiative (SFI), MFA for Azure Portal, Playright, WordPress, NSG, Bastion, Azure Functions, MS Ignite, App Service, Defender for Cloud, Containers, Azure Monitor, AKS,…
…
continue reading
1
Episode 101: The GHOST Threat Hunting Team
22:39
22:39
Play later
Play later
Lists
Like
Liked
22:39
In this episode Michael, Mark and Sarah talk to Matt Zorich and Waymon Ho of the Microsoft GHOST team. We discuss the role GHOST plays in protecting both Microsoft and our customers from nation-state threat actors. We also cover the latest security news about Event Grid, NetApp Files, Chaos Studio and AKS. https://aka.ms/azsecpod…
…
continue reading
In this episode Michael, Sarah, Gladys and Mark talk about our careers so far, explain some funny stories and our wishes for a more secure future. Our stories Mark at the start Sarah 4m 5s Gladys 6m 50s Michael 12m 22s Funny Stories Mark 19m 31s Sarah 20m 33s Gladys 22m 46s Michael 24m 39s Career Advice Mark 26m 58s Sarah 29m 18s Gladys 31m 48s Mic…
…
continue reading
1
Episode 99: Securing Copilot AI Data and Purview
37:29
37:29
Play later
Play later
Lists
Like
Liked
37:29
In this (late) episode, we chat to Andrew McMurray, a Principal Product Manager at Microsoft about securing Copilot data as well as how Purview can play a role in doing so. We also cover news about MFA access to the Azure Portal (Important), PostgreSQL, Entra ID and Windows authn metadata, Backup Vaults, Conditional Access Policy, ADFS, and Azure C…
…
continue reading
1
Episode 98: Secure Future Initiative and Rust at Microsoft
37:19
37:19
Play later
Play later
Lists
Like
Liked
37:19
In this episode Michael and Gladys talk with guest Dave Weston about Secure Future Initiative and the growing use of the Rust programming language at Microsoft. On the topic of Rust, Michael and Dave nerd out, and we make no apologies! https://aka.ms/azsecpod
…
continue reading
In this episode Michael and Sarah talk with guest Richard Diver about securing solutions that use AI and LLMs. Richard also talks about his new book on AI Security, and Michael and Richard talk about what it takes to write a book. We also discuss Azure Security news about Chaos Studio, API Management, Azure Bastion, Front Door, AKS and Copilot for …
…
continue reading
1
Episode 96: Cloud Native Applications Protection Platform (CNAPP)
21:23
21:23
Play later
Play later
Lists
Like
Liked
21:23
In this episode Michael, Sarah, and Mark talk with guest (and good friend of the podcast) Yuri Diogenes about CNAPP - Cloud Native Application Protection Platform and announce the release of a CNAPP e-book.
…
continue reading
In this episode Michael, Sarah and Mark talk with guest Sherrod DeGrippo, Director of Threat Intelligence Strategy at Microsoft about the current state of Threat Intelligence. We also discuss Azure Security news about Tampa BSides, Virtual Networks, Azure Database for MySQL and PostgreSQL, and SQL Server on Linux. The Microsoft Azure Security Podca…
…
continue reading
In this episode Michael, Sarah and Mark talk with guest Ryan Munsch about the newly released Copilot for Security. We also discuss Azure Security news about Azure SQL DB, SSMS 20, Change Actor, Copilot for Azure SQL DB, Azure Container Apps, AI Prompt Shields, AI Groundedness Detection and BlueHat India and Israel. New tab (azsecuritypodcast.net)…
…
continue reading
1
Episode 93: Continuous Security Development Lifecycle
39:12
39:12
Play later
Play later
Lists
Like
Liked
39:12
In this episode Michael, Sarah, and Mark talk with guests Tony Rice and David Ornstein about insights into the Continuous SDL (Security Development Lifecycle). We also discussed Azure Security news about Azure Key Vault, Cloud PKI, OAuth2, updated SQL Server password verifiers, Memory Safety and Azure SQL DB. The Microsoft Azure Security Podcast (a…
…
continue reading
1
Episode 92: Global Azure is soon, sign up and give a security presentation!
42:07
42:07
Play later
Play later
Lists
Like
Liked
42:07
In this episode Michael and Sarah talk to Martin Abbott about the Global Azure event that starts soon, https://globalazure.net/. We talk about how to successfully fill out a Call for Papers (CFP) so YOU can present to a global audience about security topics that interest you. We also cover security news SQL Always Encrypted, SymCrypt and Rust, SQL …
…
continue reading
In this episode, Michael talks with Rigel Carlson from the Chaos Studio development team about Chaos Studio through a security lens. Michael also discusses news about Midnight Blizzard and \has some advice about using Azure's DefaultAzureCredential() The Microsoft Azure Security Podcast (azsecuritypodcast.net)…
…
continue reading
This is a MUST LISTEN episode for anyone involved in products using AI, or for people who want to learn some of the latest attacks against large language models. Make sure you peruse the exhaustive list of AI security links at The Microsoft Azure Security Podcast (azsecuritypodcast.net), We cover news about Azure SQL DB, Trusted VMs, NetApp Files, …
…
continue reading
In this episode we look back at what stood out for each of us and what we go up to. We also cover something not security-related, but of interest to all your geeks out there - EQ vs IQ. So make sure you stay until the end!
…
continue reading
1
Episode 88: Securing SQL Databases though the eyes of an attacker
45:53
45:53
Play later
Play later
Lists
Like
Liked
45:53
In this episode Michael talks with colleagues in the Azure Data Platform Security Team, Sharath Unni and Raul Garcia about securing Azure SQL DB, SQL MI and SQL Server through the eyes of an attacker.
…
continue reading
1
Episode 87: Advances in Always Encrypted and Transparent Data Encryption
21:07
21:07
Play later
Play later
Lists
Like
Liked
21:07
In this episode, Michael talks with his colleagues Pieter Vanhove and Mirek Sztajno about updates to Always Encrypted and Transparent Data Encryption in SQL Server and Azure SQL DB.
…
continue reading
1
Episode 86: Zero Trust Playbook Series Zero Trust Overview and Playbook Introduction
34:20
34:20
Play later
Play later
Lists
Like
Liked
34:20
In this episode Michael talks with guest Nikhil Kumar and our own Mark Simos about a new book they have co-authored named "Zero Trust Playbook Series Zero Trust Overview and Playbook Introduction: Actionable Guidance for Business, Security, and Technology Leaders and Practitioners."
…
continue reading
In this episode Michael and Sarah talk with guest Madeline Eckert about Security Bug Bounties.We also discuss Azure Security news about SQL Server 2022, Azure certificate changes, TLS 1.0 and 1.1 deprecation, GitHub security scanning, Ransomeware defenses, Zero Trust and more.; and by 'more' we mean lock-picking!…
…
continue reading
In this episode Michael, Sarah, Gladys, and Mark talk with guest Roberto Rodriguez about attack simulation, Cloud Katana, and AI.We also discuss Azure Security news about Azure SQL DB, Azure Key Vault, Cosmos DB, Trusted Launch VMs, Azure Artifacts, Zero Trust, Windows and TLS and Entra ID.
…
continue reading
1
Episode 83: PowerShell Automation and Scripting for Cybersecurity
36:48
36:48
Play later
Play later
Lists
Like
Liked
36:48
In this episode Michael and Sarah with guest Miriam Wiesner about her new book, "PowerShell Automation and Scripting for Cybersecurity" which comes out soon. We also discussed Azure Security news about: Azure SQL DB Always Encrypted improvements, Azure SQL Managed Instance, App Gateway for Containers and Bring your own Key for AKS Ephemeral Disks.…
…
continue reading
This week Michael and Mark talk to Microsoft Security MVP Truls Dahlsveen about his thoughts on Modern Security Strategy. It's a fascinating and practical discussion! We also cover security news about Application Gateway TLS policy, Defender for IoT and some new documentation from the OpenGroup about Zero Trust Commandments.…
…
continue reading
1
Episode 81: Audit logging in Azure SQL Database
26:33
26:33
Play later
Play later
Lists
Like
Liked
26:33
In this special episode Michael talks to his colleague Sravani Saluru about how to configure, monitor and manage audit logging in Azure SQL Database. She also shares some inside hints and tips!
…
continue reading
In this episode Michael and Sarah talk with guest Matt Zorich from the Microsoft Incident Response team. We also cover the latest Azure security news about Azure's Web Application Firewall and Azure Monitor RBAC.
…
continue reading
1
Episode 79: Threat Intelligence with MSTICPy
28:10
28:10
Play later
Play later
Lists
Like
Liked
28:10
In this episode, Michael and Sarah talk to Thomas Roccia about Threat Intelligence with MSTICPy. We also cover security news about Azure Files SMB, App Gateway, Event Hubs and Linux Containers.
…
continue reading
1
Episode 78: Entra Permissions Management updates
32:13
32:13
Play later
Play later
Lists
Like
Liked
32:13
In this episode Michael and Gladys talk with guests Marcelo di lorio and Neil Walker about all the latest news in Entra Permissions Management.We also cover the latest Azure security news about Microsoft Build, Confidential Computing, Key Vault, SQL MI, and Azure Content Safety and more.
…
continue reading
1
Episode 77: Securing Infrastructure as Code (IaC)
40:57
40:57
Play later
Play later
Lists
Like
Liked
40:57
This week, Michael, Mark and Gladys talk to Anthony Shaw about some of the best practices and tooling for securing Infrastructure as Code (IaC) solutions. Sarah is away in Singapore, presenting at BlackHat.We also cover security news about DDoS, Cosmos DB, Microsoft Defender for APIs, Load Balancer, Zero Trust and discovering Internet-facing device…
…
continue reading
1
Episode 76: Microsoft Security Research Insights
26:42
26:42
Play later
Play later
Lists
Like
Liked
26:42
In this episode Michael, Sarah, and Mark talk with guest Negar Shabab. We also discuss Azure Security news about new Confidential Computing VMs, SQL Server, T-SQL Parsing, Auditing in Azure SQL DB, Sentinel and more. Make sure you go to The Microsoft Azure Security Podcast (azsecuritypodcast.net), because Mark ordered pizza during the recording.…
…
continue reading
1
Episode 75: What's new in Microsoft Defender for Cloud
36:02
36:02
Play later
Play later
Lists
Like
Liked
36:02
In this episode Michael, Sarah, Gladys, and Mark talk with a good friend of the Podcast, Yuri Diogenes, about the latest Microsoft Defender for Cloud news.We also discuss Azure Security news about Trusted VM Launch, Chaos Studio, Azure SQL DB, DDoS protection, Confidential Containers, Firewall and more.…
…
continue reading
Michael and Mark talk to Kemley Nieva from the Azure Governance team about some of the recent updates and improvements to Azure Policy. We also cover the latest Azure security news covering Microsoft Security Copilot, Azure Functions, SQL Managed Instance, Azure Backup, Ephemeral OS disks, Azure Cache for Redis, Azure SQL Database, Azure Monitor, A…
…
continue reading
1
Episode 73: Microsoft Defender for Cloud as Code
27:42
27:42
Play later
Play later
Lists
Like
Liked
27:42
In this episode Michael and Gladys talk with guests Sean Wesonga and Bojan Magusic about using Infrastructure as Code (IaC) with Microsoft Defender for Cloud. We also discuss Azure Security news about new Azure SQL Database migration abilities for authentication and Transparent Data Encryption (TDE).…
…
continue reading
1
Episode 72: What's top of mind for the hosts and career advice!
1:01:25
1:01:25
Play later
Play later
Lists
Like
Liked
1:01:25
In this episode Michael, Sarah, Gladys and Mark interview each other! The Podcast is almost three years old, and things have changed for each of us, so we thought we'd re-introduce ourselves, reflect, give career advice, and talk about what's top of mind for each of us! We also discuss Azure Security news about SQL Server and Azure SQL DB, MFA and …
…
continue reading
1
Episode 71: Azure SQL Database and Always Encrypted using Virtualization-Based Security Enclaves
28:13
28:13
Play later
Play later
Lists
Like
Liked
28:13
In this special episode, Michael sits down with Pieter Vanhove about a new addition to the SQL Server 'Always Encrypted' family. The new addition, Virtualization-Based Security Enclaves (VBS), is now in Preview and allows for more scalability and lower cost when using secure enclaves compared to the current SGX-based enclaves.…
…
continue reading
In this episode Michael and Sarah talk with guests Beau Faull and Lou Mercuri about some new features and updated naming in Microsoft Purview. Beau and Lou are also co-hosts of the Coast2Coast Podcast on YouTube. We also discuss Azure Security news about Trusted Boot VMs, Sentinel and Defender for Cloud.…
…
continue reading
1
Episode 69: Secured Supply Chain and Software Bill of Materials (SBOM)
27:20
27:20
Play later
Play later
Lists
Like
Liked
27:20
In this episode, Michael and Mark talk to Adrian Diglio about Software Bill of Materials and its role in helping secure the software supply chain. We also have news items about SQL Server, Azure SQL DB, Azure Database for PostgreSQL, Azure Database for MySQL and Application Secure Groups and Private Endpoints. Mark goes over MCRA, Immutable Laws of…
…
continue reading
Michael sits down with Ajay Jagannathan who is the Principal Group PM Manager for SQL Server. Michael also covers a couple of SQL Server related news items.
…
continue reading
Michael and Sarah talk to Bronwyn Mercer from Microsoft Australia about Privileged Access as well as some ideas and processes to help you succeed. Also, the latest security news about Managed HSM, Defender for DevOps, TLS and ARM, SQL Server 2022, Application Gateway. Finally, 'Designing and Developing Secure Azure Solutions' is now available. http…
…
continue reading
In this episode Michael, Sarah and Mark talk with guest Joey Snow about Workload Identities in Azure. We also chat about least privilege and privileged accounts in general. Finally, the latest Azure Security news about: Azure Front Door, Log Analytics, Web Application Firewall and AKS SSH keys.
…
continue reading
1
Microsoft Defender for Threat Intelligence
38:14
38:14
Play later
Play later
Lists
Like
Liked
38:14
EDIT: Nov 11th, there was an error at around 27m; Gladys and Rijuta were talking over each other. In this episode Michael, Sarah, Gladys and Mark talk with guests Rijuta Kapoor and Brandon about Microsoft Defender for Threat Intelligence. We also discuss Azure Security news about Azure Service Bus and TLS, PostgreSQL, VMs, SQL Server and Confidenti…
…
continue reading
1
The SQL Server Permission Model Explained
46:15
46:15
Play later
Play later
Lists
Like
Liked
46:15
In this special, out of band episode, Michael talks to Andreas Wolter about the SQL Server and Azure SQL Database permission model. To many, the model is a mystery, but Andreas explains how it works as Michael poses security challenges.
…
continue reading
In this episode we talk to Nick Wryter about Microsoft Entra Permissions Management. We also cover the latest security news about Azure Firewall, Azure Database for MySQL, NetApp files, ADLS Gen2, AKS, Conditional Access and Identity Federation.
…
continue reading
1
Microsoft Defender for Endpoint Tamper Protection
29:15
29:15
Play later
Play later
Lists
Like
Liked
29:15
In this episode, Josh Bregman discusses a critically important feature in MDE - Tamper Protection which helps prevent unwanted changes to your security and essential functions. We also cover the latest security news about Synapse SQL, Service Bus, Storage, Redis, Azure SQL, MySQL, AKS, Managed Disks and Microsoft Defender.…
…
continue reading
In this episode we speak to Elizabeth Stephens about practices and philosophies for protecting OT. We also cover news about SQL MI, Private Endpoints, Load Testing, TLS 1.3, AKS and Confidential VMs and Azur Firewall. Also, this is the first episode to use the phrase "things that are not supposed to blow up!"…
…
continue reading
1
Microsoft Defender for Cloud - AWS and GCP
45:02
45:02
Play later
Play later
Lists
Like
Liked
45:02
In this episode, we talk to Safeena about Begun about Microsoft Defender for Cloud to monitor multi-cloud environments including Azure, on-prem, AWS and GCP. We also talk about changes coming to Azure's root CA certificates, Microsoft Entra and more.
…
continue reading
1
Chief Information Security Officer (CISO) Workshop
37:03
37:03
Play later
Play later
Lists
Like
Liked
37:03
In this episode Michael and Sarah talk to Mark about the newly version of the CISO Workshop. We also have news about Confidential Ledger, Gateway Load Balancer (new!), Azure Database for MySQL and Trust Launch.
…
continue reading
1
Innovations in Azure Confidential Computing
29:28
29:28
Play later
Play later
Lists
Like
Liked
29:28
In this episode, Michael talks to Run Cai and Vikas Bhatia about some of the latest Confidential Computing services available on Azure including new Confidential VMs from AMD.
…
continue reading
In this episode, Michael, Sarah and Mark talk to Roey Ben Chaim about Microsoft Sentinel Content Hub. We also cover the latest security news about Exchange Online, Microsoft Entra Permissions Manager, MSTICPy, Purview DLP, Azure Monitor, Backup and App Insights.
…
continue reading
1
Advanced Threat Hunting with Microsoft 365 Defender
21:17
21:17
Play later
Play later
Lists
Like
Liked
21:17
Michael sits down with Michael Melone to discuss hunting for adversaries using Microsoft 365 Defender's Advanced hunting capabilities. Azure security news this week includes Azure Advisor for MySQL, using custom CAs with AKS, App Gateway Private Link, continuous backup in Cosmos DB, and API Management CSP and CORS support.…
…
continue reading
Michael and Sara talk to Matt Soseman about his take on practical Zero Trust and Michael goes on a rant about Zero Trust's Assume Breach pillar. We also cover Azure news about Azure SQL DB, Container Apps, Bastion, Sentinel and Microsoft Entra.
…
continue reading