RunAs Radio
Richard Campbell
0
RunAs Radio is a weekly Internet Audio Talk Show for IT Professionals working with Microsoft products.
Епизоди
-
Security Begins at Procurement with Jessie Schofer 22.07.2026 37минBringing new software or SaaS into your organization is a security risk - how do you assess it? Richard chats with Jessie Schofer about her experiences in HR software acquisition, which led to the creation of secureless.ai. Jessie tells the story of evaluating various SaaS and other software products and realizing that, while the website says they are compliant with GDPR and/or SOC 2, are they really? This leads to a conversation about the product procurement process and about actually understanding the security risk you take on every time a new product is added to your organization. At what point does security block an acquisition? And after being acquired, how often do you reassess? Supply chain security hygiene starts at procurement - are you part of the evaluation?
-
Finding Security Vulnerabilities using AI with Sami Laiho 15.07.2026 38минHow are large language models changing the way security vulnerabilities are found? Richard chats with Sami Laiho about the rapidly changing landscape in security exploits. Certain LLM models like Anthropic's Mythos and Microsoft MDASH are optimized to find software vulnerabilities - and potentially fix them. And so there is an arms race of sorts, repairing old vulnerabilities before LLMs in the hands of black hats can exploit them. But what about everyone else? Sami talks about getting LLMs working for your organization to test for potential security risks and assess the impact of new vulnerabilities as they appear.
-
Implementing Azure Policies with Barbara Forbes 08.07.2026 35минHow can Azure Policies help you? While at Techorama in Belgium, Richard sat down with Barbara Forbes to discuss how Azure Policies have evolved and the techniques sysadmins are using to improve security, cost controls, efficiency, and more. Barbara talks about how the default policies are designed to get folks started in Azure quickly - not necessarily optimally. And there are plenty of policy templates out there, but before you implement them, it's worthwhile to review each policy and ask the question "why?" Keeping good documentation on policies makes it easier to know intent, especially when it comes to changing them - and you'll need to change them! There are a number of ways to apply policies, but in the end, they are just more Infrastructure-as-Code, and so easily repeatable. Azure Policies are there to help you provide freedom with guardrails if you implement them carefully!
-
AI-Accelerated Supply Chain Attacks with Mackenzie Jackson 01.07.2026 36минHow are supply-chain attacks evolving? Richard chats with Mackenzie Jackson about his work helping companies protect their software supply chains from malware attacks. Mackenzie discusses the vulnerability of developers to attacks, since their accounts are often highly privileged and invariably contain access to exploitable secrets. The conversation digs into the challenges of securing various code distribution mechanisms like npm and how you can protect your organization - starting with, don't install packages as soon as they are released! There are effective tools for detecting malware in code, but they take time. Waiting 48 hours can eliminate a lot of risk!
-
Securing Developers with Tanya Janca 24.06.2026 34минHow can sysadmins help software developers work securely and make more secure applications? While at NDC in Toronto, Richard sat down with Tanya Janca of SheCodesPurple to discuss what admins can do to help address the security challenges software developers face. Tanya talks about securing development environment and pipelines - developers routinely work from high privilege accounts because their tools require it, and as a result, have become the targets of black hats to get access to accounts, keys, and other exploitable resources. There are plenty of tools available to help work through the issues, including the latest AI-powered tools. LLMs can also help generate more secure code in the first place, and Tanya has created a set of prompts you can use to create more secure software. The threat landscape is shifting with these tools, and we need to act quickly to resist the new attacks!
-
47 Day Certificates with Todd Gardner 17.06.2026 37минThe 47-day certificate is coming! While at NDC in Toronto, Richard received an update from Todd Gardner about his show last year: certificate authorities are moving toward SSL certificates that last only 47 days! Todd talks about the first decrease in duration that has already passed - as of March 2026, the longest duration certificate you can buy from certificate authorities is 200 days. At the core of these changes is the problem that certificate revocation just isn't working properly, so a short certificate lifespan is the effective solution. Short certificate lifespans make automation to replace certificates essential - and that's where CertKit and other tools come in!
-
How Machine Learning Fails with Megan Robertson 10.06.2026 36минWhat can go wrong with machine learning? While at NDC in Toronto, Richard chatted with Megan Robertson about her experience with machine learning projects, often using retail datasets, and where they can go wrong. Megan talks about getting clear expectations and metrics for projects, so you know when you succeed, but then digs into the specifics of problems in machine learning, such as overfitting on test data. Your results are only as good as the data you put in, so a lot of focus goes into building good sets, carefully developing the model with those sets, and using techniques like cross-validation to ensure the model is behaving appropriately. There's a lot that can go wrong, but the results with an effective model can be very powerful - it is worth the effort!
-
Data API Builder and SQL MCP with Jerry Nixon 03.06.2026 36минHow do you intelligently surface access to your database? While at NDC Toronto, Richard spoke with Jerry Nixon about Data API Builder, Microsoft's tool that enables data professionals using Microsoft databases, including SQL Server, Postgres, CosmosDB, and MySQL, to provide an API layer with security, schema extraction, and governance policies. You can expose the API as a REST interface, a GraphQL interface, and an MCP server! This is a powerful tool for providing controlled access to data while still allowing for ad-hoc access. The potential is huge - you need to check it out!
-
Team Productivity using Loop with Karinne Bessette 27.05.2026 35минHow can Microsoft Loop make your team more productive? Richard chats with Karinne Bessette about the role that Loop components can play in making meetings where the agenda is live, generating work items in Microsoft Planner, and keeping key information up to date. Karinne talks about how Loop components can be connected to any M365 document, including Outlook, Word, Excel, and OneNote, but only for members of the M365 tenant. Loop is a powerful tool for productivity within the organization!
-
UEFI Secure Boot with Richard Hicks 20.05.2026 37минThe original Secure Boot certificate expires in June 2026! Richard talks to Richard Hicks about how Secure Boot works and how the expiration of the master certificate can leave PCs vulnerable to boot-related malware, such as rootkits. Richard discusses recent Microsoft communications on SecureBoot and how to check which certificate your machines have. Workstations using managed updates are likely already up to date, but servers are a different issue. When the certificate expires, you'll no longer receive updates to Secure Boot for known exploits, leaving your machines vulnerable. Update today!
-
Production LLMs with Vaishnavi Gudur 13.05.2026 35минWhat does a production-grade large language model look like? While at NDC Sydney, Richard talked with Vaishnavi Gudur from Microsoft about her work scaling LLMs for Teams transcriptions, summaries, and more! Vaishnavi discusses the underlying complexities of operating the Teams LLM infrastructure for a large array of customers across different countries and regulatory regimes. Data sovereignty also plays a large role: different countries have specific rules on where data must reside and how it can be accessed. As the scale increases and the tail gets longer, the rules set gets more complex! Lots of great thinking about what LLMs look like in a production environment.
-
Securing Active Directory with Spencer Alessi 06.05.2026 36минHow secure is your Active Directory infrastructure? While at Zero Trust World in Orlando, Richard chatted with Spencer Alessi about his work helping companies secure Active Directory, making it more difficult for black hats to exploit it for lateral moves during a breach attempt. Spencer talks about the increasing speed of these exploits, making it much harder to block them after the fact, so it's best to make AD too difficult to target. Jake Hildreth's Locksmith tools are a great place to start - free and open source. There are also Microsoft tools and Spencer's own AD Security Resource Kit to help evaluate your AD infrastructure and lock it down!
-
M365 Copilot vs Claude Cowork with Sharon Weaver 29.04.2026 38минThere's competition in the Office productivity space! Richard chats with Sharon Weaver about her experiences with M365 Copilot and Anthropic's Claude Cowork to improve information worker productivity. Sharon talks about the confusion around all the different copilots in the Microsoft space - including the chat tools, research agents, and more. But when it comes to helping with an Excel spreadsheet, M365 Copilot can't do what Claude Cowork can do. Sharon talks about describing the goals of a spreadsheet to Claude Cowork and having the tool generate the spreadsheet, make corrections, and add formatting. Cowork has similar capabilities for presentations, and with the Connector library, new functionality is being added routinely. There's some competition in the AI productivity space - things are getting interesting!
-
The Life and Death of Microsoft Deployment Toolkit with Michael Niehaus 22.04.2026 39минWhat does the world look like after Microsoft Deployment Toolkit? Richard talks to MDT creator Michael Niehaus about the life and death of MDT. Michael talks about his early days at Microsoft, when he created a better way to manage operating system images so you can build and rebuild Windows PCs for your organization. But MDT had been in maintenance since 2013, without specific support for Windows 11. And now, some security concerns have ended support entirely. So what happens next? Michael offers fixes to keep MDT safe to use, and some alternatives if you want to keep managing your own images!
-
Internal Corporate Communications in 2026 with Emily Mancini 15.04.2026 34минHow does your company communicate with its employees today? Richard chats with Emily Mancini about her work with companies that manage internal communications. Emily talks about the power of email, collaborative messaging like Teams, and the Microsoft Viva products Engage and Amplify. The conversation digs into knowing where your people look for info, how they communicate, and what they want to connect with. Being able to measure the response to different communication means helps you to work on better messages and methods - the goal is to enable employees to connect with and utilize the resources of the organization, creating a stronger company culture!
-
Securing AI Agents with Niall Merrigan 08.04.2026 37минAI Agents can be powerful tools for an organization - but are they a security risk? Richard talks to Niall Merrigan about his experiences dealing with the various ways that LLMs can be attacked, starting with prompt injection. While some attacks are humorous, others can be very serious, especially in the context of agents, where the right prompt can cause an agent to use its capabilities to access or affect data outside its expected behavior. This has already led to several well-publicized CVEs, including the ServiceNow Privilege Escalation advisory. New tools have emerged to help restrict prompts and keep agents on task - but as with all things security, this is another set of tools you need to get familiar with!
-
My Home Lab 01.04.2026 9минAre you ready to take a look at Richard's home lab? Richard goes solo to share insights about the new infrastructure, hardware, and automation in his seaside home. He discusses the challenges posed by its remote location, including unreliable power and connectivity. You'll find plenty of details about networking, computing infrastructure, automation, telemetry, and experiments with AI technologies. Get an exclusive behind-the-scenes look!
-
Unified Tenant Management with Nik Charlebois-Laprade 25.03.2026 33минConfiguration drift is real - how do you control it in your Azure tenant? Richard talks to Nik Charlebois-Laprade about his ongoing work on desired state configuration DSC for Microsoft 365 tenants. Microsoft365DSC has been an open-source tool for managing configuration for some time, but today it has become a preview product called Unified Tenant Configuration in Microsoft Graph. Nik talks about managing multiple tenants, including a single tenant, using reference configurations that help you detect and correct configuration changes. It's early days for the product, but there's a ton of power here to keep your tenant working the way you expect!
-
Sustainable AI with Darshna Shah 18.03.2026 43минHow does artificial intelligence become more sustainable? Richard chats with Darshna Shah about her experiences as Chief AI Officer at Elastic. Darshna discusses the resources required to run large language model experiments, the pressure this has put on the electrical grid, and more. The conversation turns to efficiency - and the idea that there is little incentive in the current land grab around LLMs to be more efficient - that the focus is on growing quickly. But as technologies mature, efficiency becomes a key competitive advantage!
-
SQL Server in 2026 with Bob Ward 11.03.2026 40минSQL Server 2025 is released - what's in it, and what happens next? Richard chats with Bob Ward about the huge array of announcements coming out of Ignite around SQL Server 2025, including AI-related features, new reliability and performance options, engine improvements, and more! The tooling for SQL Server also continues to evolve, including making Copilot available through SSMS and as part of the SQL extension to Visual Studio Code. And there's more to come - have a listen!
Популарен во
Овој подкаст се појавува и на подкаст-листите на овие земји.