Mostly: Entra, Defender, Intune, Purview, and Microsoft 365
Also: dad, metal, lifting, wrestling, cars
Mostly on Twitter rather than here: @rucam365
• excessive directory visibility
• ignored cross-tenant defaults
• untrusted MFA & device states
• open SharePoint sharing
• no guest lifecycle
There's tons more! But here's a starter
WATCH: youtu.be/AXuj-U9p3jU
• excessive directory visibility
• ignored cross-tenant defaults
• untrusted MFA & device states
• open SharePoint sharing
• no guest lifecycle
There's tons more! But here's a starter
WATCH: youtu.be/AXuj-U9p3jU
• Phase 1 (warn mode) begins February '26
• followed by Phase 2 (block mode)
• then Phase 3 (wipes Entra creds)
• expected to be completed ~April '26
• Phase 1 (warn mode) begins February '26
• followed by Phase 2 (block mode)
• then Phase 3 (wipes Entra creds)
• expected to be completed ~April '26
Docs: learn.microsoft.com/...
Docs: learn.microsoft.com/...
- @JoanneCKlein & Anna Bordioug: Two Sides of the Data Coin: Data Protection vs. Data Retention in Practice
- @brand_gefahr: How Much is the Phish? An End-to-End Perspective on Phishing Operation
REGISTER: www.meetup.com/m365s...
- @JoanneCKlein & Anna Bordioug: Two Sides of the Data Coin: Data Protection vs. Data Retention in Practice
- @brand_gefahr: How Much is the Phish? An End-to-End Perspective on Phishing Operation
REGISTER: www.meetup.com/m365s...
• recap on what jailbreaks and prompt injections are (examples)
• how they show up in Defender for Cloud Apps/hunting and Purview
WATCH: youtu.be/iCRYJ32fwro
• recap on what jailbreaks and prompt injections are (examples)
• how they show up in Defender for Cloud Apps/hunting and Purview
WATCH: youtu.be/iCRYJ32fwro
• why so many baselines are just plain bad
• balancing security / usability
• when to customise
• how OIB makes it practical
WATCH: youtu.be/Xe32TzHgueA
• why so many baselines are just plain bad
• balancing security / usability
• when to customise
• how OIB makes it practical
WATCH: youtu.be/Xe32TzHgueA
See them all: microsoft.design/art...
See them all: microsoft.design/art...
• why identity is the front door
• sources of authority (HR vs AD)
• joiner/mover/leaver workflows
• PowerShell scripts vs governance at scale
WATCH: youtu.be/VVU2UhYaGzk
• why identity is the front door
• sources of authority (HR vs AD)
• joiner/mover/leaver workflows
• PowerShell scripts vs governance at scale
WATCH: youtu.be/VVU2UhYaGzk
2hr Entra security deep dive for blue teams.
Note this is exclusively for in-house security teams rather than other partners, MSSPs, etc.
REGISTER: www.eventbrite.ie/e/...
2hr Entra security deep dive for blue teams.
Note this is exclusively for in-house security teams rather than other partners, MSSPs, etc.
REGISTER: www.eventbrite.ie/e/...
Two killer sessions and lots of prizes:
Denis Mutlu - Optimizing Log Management for Sentinel & MDXDR
@ThomasVrhydn - Proactive Exposure Hunting with Enterprise Exposure Graph
REGISTER: www.meetup.com/m365s...
Two killer sessions and lots of prizes:
Denis Mutlu - Optimizing Log Management for Sentinel & MDXDR
@ThomasVrhydn - Proactive Exposure Hunting with Enterprise Exposure Graph
REGISTER: www.meetup.com/m365s...
• personas + policy merge
• rings and “critical time delay”
• Live Response + RBAC
• Effective settings
WATCH: youtu.be/IvLNLcXRlrY
• personas + policy merge
• rings and “critical time delay”
• Live Response + RBAC
• Effective settings
WATCH: youtu.be/IvLNLcXRlrY
- update types: engines, platforms, intelligence
- what is Microsoft’s 'Safe Deployment Practices' (SDP)?
- update rings in Defender (not just Windows)
- balancing rollout risk vs. protection
WATCH: youtu.be/trQv__-Z9-8
- update types: engines, platforms, intelligence
- what is Microsoft’s 'Safe Deployment Practices' (SDP)?
- update rings in Defender (not just Windows)
- balancing rollout risk vs. protection
WATCH: youtu.be/trQv__-Z9-8
Defender for Endpoint In Depth 2nd Ed (w/ @Threatzman)
Mastering Defender XDR 2nd Ed (w/ @Headburgh)
So, drop your great MDE, MDO, MDI, MDA, and XDR tips here. Best get featured.
Defender for Endpoint In Depth 2nd Ed (w/ @Threatzman)
Mastering Defender XDR 2nd Ed (w/ @Headburgh)
So, drop your great MDE, MDO, MDI, MDA, and XDR tips here. Best get featured.
- what every one really does
- what “good” looks like
- gotchas
- nuances
And why some of the important ones are “hidden”.
Watch: youtu.be/R8btJ_SjwVk
- what every one really does
- what “good” looks like
- gotchas
- nuances
And why some of the important ones are “hidden”.
Watch: youtu.be/R8btJ_SjwVk
So, charged on API events that include guests separate to usual 50K allowance. Max 1 charge guest/month even if multiple events.
learn.microsoft.com/...
So, charged on API events that include guests separate to usual 50K allowance. Max 1 charge guest/month even if multiple events.
learn.microsoft.com/...
On-demand classification (PAYG) was previously limited to SPO + ODfB.
Partially addresses a gap a lot of my customers ask about... will auto labelling follow? 🤔
On-demand classification (PAYG) was previously limited to SPO + ODfB.
Partially addresses a gap a lot of my customers ask about... will auto labelling follow? 🤔
Covering nuanced scenarios like app allow listing, missing app management, and really stretching CA into some cool and uncommon uses.
WATCH: youtu.be/DkCq8wWN9Sc
Covering nuanced scenarios like app allow listing, missing app management, and really stretching CA into some cool and uncommon uses.
WATCH: youtu.be/DkCq8wWN9Sc
Watch: youtu.be/drO5YFxZDyU
Watch: youtu.be/drO5YFxZDyU