M365.FM - Modern work, security, and productivity with Microsoft 365
Mirko Peters - Founder of m365.fm, m365.show and m365con.net
0
The M365.FM podcast covers the Microsoft 365 ecosystem and related cloud services, including Azure, Power BI, Power Platform, Teams, Viva, Fabric, and Purview. Each episode discusses the latest developments, real-world use cases, and best practices, with interviews featuring industry leaders. The show is aimed at IT professionals, business decision-makers, developers, and data enthusiasts who want to keep pace with cloud and collaboration technology. It also covers security and productivity topics within the Microsoft ecosystem. The podcast is part of the M365-Show Network.
Episoade
-
Microsoft Purview eDiscovery — Simply Explained 01.08.2026 20minWhat happens when a regulator requests company records, HR launches an investigation, or legal teams need to preserve critical evidence? Searching through Outlook mailboxes, Teams chats, SharePoint sites, and OneDrive folders manually is slow, error-prone, and often impossible at enterprise scale. In this episode of Microsoft Knowledge Nuggets on M365.fm, Mirko Peters explains Microsoft Purview eDiscovery in plain English. You'll learn how organizations can securely discover, preserve, review, and export Microsoft 365 data using a structured, case-based process that supports legal investigations, compliance requests, internal audits, HR matters, and security incidents. Whether you're an IT administrator, Microsoft 365 consultant, compliance officer, security professional, or simply preparing for Microsoft certifications, this episode provides a practical introduction to one of the most important Microsoft Purview capabilities.WHY eDISCOVERY MATTERS IN MICROSOFT 365Modern work is scattered across multiple Microsoft services. Business conversations no longer live only in Outlook. Critical evidence may be spread across:Exchange Online emailsMicrosoft Teams chats and meetingsSharePoint Online document librariesOneDrive for BusinessMicrosoft 365 GroupsViva Engage conversationsDuring an investigation, missing even one location can result in incomplete evidence. Microsoft Purview eDiscovery provides a centralized process that helps organizations collect the right information while maintaining security, privacy, and governance. Instead of searching every mailbox and document library, organizations create structured cases that define exactly what should be searched and who may access the results.HOW MICROSOFT PURVIEW eDISCOVERY WORKSRather than acting as a giant search engine, eDiscovery follows a carefully controlled workflow. The process begins by creating a case, which becomes the secure workspace for a specific investigation. Authorized users define the data sources, preserve evidence through Legal Hold when required, execute targeted searches, review the collected results, classify relevant documents, and finally export only the approved evidence. This structured workflow dramatically reduces risk compared to manually searching Microsoft 365 services while providing a clear audit trail for compliance and legal teams.EXPLORE THE COMPLETE eDISCOVERY WORKFLOWThis episode explains every major component of Microsoft Purview eDiscovery, including:Creating investigation casesSelecting Exchange, Teams, SharePoint and OneDrive data sourcesUnderstanding Legal HoldRunning targeted searchesUsing Keyword Query Language (KQL)Reviewing collected evidenceWorking with Review SetsApplying TagsExporting evidence securelyManaging permissions and access controlUnderstanding Standard vs Premium eDiscoveryEvery topic is illustrated using practical business scenarios that demonstrate how investigations typically unfold inside Microsoft 365 environmentsLEGAL HOLD EXPLAINEDOne of the most misunderstood concepts in Microsoft Purview is Legal Hold. A Legal Hold ensures that potentially relevant information remains preserved even if users delete emails, edit documents, or leave the organization during an active investigation. Unlike traditional retention policies, which enforce normal business record retention, Legal Hold protects data because of a specific legal or compliance matter. This episode explains:when Legal Hold should be used,how it differs from Microsoft 365 retention,why preservation must happen before searching,and why only authorized business stakeholders should decide when a hold is applied or released.SEARCH SMARTER — NOT... -
ENTRA PIM EXPLAINED: Securing Privileged Access with Mark Orr [MVP] 31.07.2026 1h 3minMark Orr shares his extraordinary journey from serving three combat tours in Iraq as a United States Marine Corps radio and satellite communications specialist to becoming a Microsoft MVP, enterprise architect, and respected Microsoft security expert. He explains how military experience introduced him to networking, satellite communications, IP protocols, and infrastructure management before eventually leading him into Microsoft technologies, Microsoft Intune, Entra ID, automation, and cloud security. His career demonstrates how discipline, resilience, and continuous learning can create entirely new opportunities in enterprise IT.WHY IDENTITY IS THE NEW SECURITY PERIMETER Organizations often invest heavily in AI, Copilot, endpoint management, and advanced compliance while overlooking the single most important attack surface: identity. Mark explains why every security strategy should begin with protecting identities before implementing more advanced technologies. According to him, strong authentication, phishing-resistant credentials, and properly secured privileged accounts form the foundation upon which every modern Microsoft security solution depends. Without a secure identity layer, every additional security investment becomes significantly less effective.WHY IDENTITY ATTACKS DOMINATE MODERN CYBERSECURITYMore than ever, attackers target identities instead of infrastructure. Mark explains that passwords remain one of the weakest links because people frequently reuse credentials across personal and business accounts. Once a password becomes compromised through another service, attackers often gain access to enterprise environments using the same credentials. This is why Microsoft continues pushing organizations toward passwordless authentication and phishing-resistant sign-in methods that dramatically reduce the attack surface. PASSWORDLESS AUTHENTICATION SHOULD BE EVERY ORGANIZATION'S FIRST GOALMark has been running passwordless authentication since long before it became mainstream. Drawing on years of practical experience, he strongly recommends moving organizations toward Windows Hello for Business, passkeys, Microsoft Authenticator passwordless sign-in, and hardware security keys such as YubiKeys. Besides improving security, passwordless authentication actually creates a better user experience by eliminating forgotten passwords while protecting users from phishing attacks and credential theft.COMMON MISTAKES WITH PRIVILEGED ACCOUNTS One of the biggest security mistakes Mark repeatedly encounters is administrators using the same account for both daily productivity and privileged administration. He explains why administrative identities should always be isolated cloud-only accounts without Exchange mailboxes, Teams licenses, or normal productivity workloads. Separating privileged identities dramatically reduces phishing exposure and prevents attackers from gaining administrative access through compromised user activities.ZERO TRUST IS A JOURNEY, NOT A DESTINATIONZero Trust is often treated as a final objective, but Mark argues that organizations never truly "finish" Zero Trust. Instead, security teams should focus on continuously improving their security posture rather than waiting for perfection. He recommends combining compliant devices, known networks, phishing-resistant authentication, Conditional Access policies, and trusted administrator workstations while continuously strengthening remaining gaps over time. Progress matters far more than chasing an impossible end state. HOW MICROSOFT INTUNE AND MICROSOFT ENTRA ID WORK TOGETHER Rather than viewing Microsoft Intune and Microsoft Entra ID as separate products, Mark explains how both platforms complement each other to create a unified security architecture. Entra ID protects identities through authentication, Conditional Access, and role-based... -
Microsoft Fabric Apps - Simply Explained 30.07.2026 16minMicrosoft Fabric Apps are a new way to build modern, data-driven web applications directly inside Microsoft Fabric. Rather than managing servers, APIs, databases, authentication, and hosting separately, Fabric provides these services automatically, allowing developers and data professionals to focus on creating business applications instead of infrastructure. A Fabric App can either connect to an existing Power BI semantic model or include its own managed SQL database, making it suitable for everything from interactive dashboards to operational business applications. This significantly lowers the barrier to building enterprise-grade solutions while keeping security, governance, and scalability within the Microsoft ecosystem.HOW MICROSOFT FABRIC APPS WORK Every Fabric App combines several managed services into a single application platform. When you create a new app, Microsoft Fabric automatically provisions a SQL database, GraphQL API, Microsoft Entra ID authentication, and static web hosting. Developers no longer need to configure backend infrastructure manually. Instead, they can concentrate on designing user experiences, building forms, creating dashboards, and implementing business logic. Fabric handles the underlying platform, making application development significantly faster than traditional full-stack approaches. FABRIC APPS VS POWER BI One of the biggest misconceptions is that Fabric Apps replace Power BI. They do not. Instead, both products solve different problems while sharing the same governed data foundation. Power BI remains Microsoft's leading business intelligence platform for analytics, reporting, dashboards, drill-through analysis, natural language queries, and executive reporting. Fabric Apps extend these capabilities by enabling custom web applications that can both display and write data. This makes them ideal for operational workflows such as inventory management, approval systems, CRM solutions, and internal business tools where users need to interact with data rather than simply analyze it. REAL-WORLD USE CASES FOR FABRIC APPS Fabric Apps are designed for business scenarios that require custom user experiences while still leveraging trusted enterprise data. Organizations can build inventory management systems with write-back capabilities, HR onboarding portals, expense approval applications, operational dashboards, customer feedback systems, and rapid business prototypes. Because Fabric Apps can connect directly to Power BI semantic models, organizations reuse existing DAX calculations, relationships, and governance policies without rebuilding business logic. This creates a single source of truth across both analytical reports and operational applications. CURRENT LIMITATIONS OF MICROSOFT FABRIC APPS Since Fabric Apps are currently in Public Preview, organizations should understand their current limitations before adopting them in production. Authentication currently supports only Microsoft Entra ID users, making the platform suitable for internal applications rather than customer-facing solutions. Applications also consume Microsoft Fabric Capacity Units (CUs), meaning performance and cost planning remain important considerations. In addition, advanced transactional scenarios, stored procedures, and highly complex business workflows may still require traditional development approaches. While AI-assisted development accelerates application creation, developers still benefit from understanding frontend technologies such as JavaScript and TypeScript. SHOULD YOU START LEARNING FABRIC APPS? If you're already working with Microsoft Fabric or Power BI, Fabric Apps represent one of the most important additions to the Microsoft data platform. They expand what organizations can build without replacing existing reporting investments, allowing the same semantic models and governed... -
Beyond the Prompt: Mastering Microsoft Copilot for Real Productivity with Jess Stratton [MVP] 30.07.2026 53minJess Stratton shares her unique career journey from independent Lotus Notes developer to one of the world's most recognized Microsoft 365 educators. After joining LinkedIn Learning, she created training for millions of learners while continuously adapting to Microsoft's rapidly evolving ecosystem. Today, as a Microsoft MVP, TEDx speaker, author, and founder of Nerd Girl Jess LLC, she focuses on helping organizations move beyond simply using Microsoft Copilot toward fundamentally changing the way people work. Her story highlights how continuous learning, curiosity, and community can create extraordinary career opportunities in technology.WHY COPILOT ADOPTION FAILS IN MANY ORGANIZATIONSBuying Microsoft Copilot licenses is only the beginning. Jess explains that many organizations invest heavily in AI but struggle to demonstrate measurable business value because employees are taught where Copilot's buttons are instead of learning how AI actually improves their daily work. Successful adoption requires showing employees practical productivity gains, helping them solve real business problems, and demonstrating why Copilot makes their jobs easier rather than simply introducing another piece of software. Organizations that focus on outcomes instead of features consistently achieve better long-term adoption.HUMAN BEHAVIOR IS THE BIGGEST OBSTACLEWhile many organizations assume governance or technology limits Copilot adoption, Jess believes the real challenge is people. Microsoft already provides strong governance capabilities, security controls, pilot programs, and enterprise protections. The real issue is convincing employees to change established habits and trust AI as part of their daily workflow. Until users understand how Copilot benefits their individual responsibilities, even the best technical deployment will fail to achieve widespread adoption.TRAINING MUST EVOLVE BEYOND FEATURESTraditional software training focuses on explaining menus and features. AI requires a completely different approach. Jess explains that modern Copilot training should answer a different question: How will this improve my work? Instead of showing every feature inside Word, Excel, Teams, or Outlook, trainers should demonstrate concrete productivity improvements, realistic business scenarios, and repeatable workflows that employees can immediately apply. Helping users experience small wins early dramatically increases long-term adoption.THE POWER OF CUSTOM PROMPT GALLERIESOne of Jess's favorite new Microsoft Copilot capabilities is the ability for organizations to build department-specific Prompt Galleries. Rather than forcing employees to invent prompts from scratch, IT teams can provide reusable prompts tailored for HR, Finance, Marketing, Legal, Customer Service, Sales, or Operations. Because every company has unique terminology, business processes, and workflows, these curated prompts significantly reduce the learning curve while helping users experience immediate business value.WHY MOST PEOPLE STILL PROMPT POORLY Many users expect Copilot to generate perfect results after entering a single sentence. Jess explains that this misconception leads to disappointment. The best prompts clearly define four key elements: the goal, the business context, relevant source information, and detailed expectations about the desired output. Instead of simply asking Copilot to "write a report," users should specify the audience, tone, length, formatting, business purpose, and constraints. The more clearly expectations are communicated, the better Copilot performs.CHOOSING THE RIGHT MODEL MATTERSModern Microsoft Copilot offers access to multiple AI models, yet many users leave the default setting unchanged. Jess encourages people to experiment with different models using identical prompts to understand how dramatically... -
The Death of the Chatbot: Why Your Dataverse Strategy Is Broken 29.07.2026 1h 41minMicrosoft Copilot has transformed how organizations interact with AI, making conversational experiences more accessible than ever. But while chat-based AI delivers immediate productivity gains, it does not provide the architectural foundation required for enterprise-scale autonomous agents. As organizations deploy more AI solutions across departments, they quickly encounter governance challenges, identity issues, fragmented integrations, and uncontrolled costs. Copilot is an excellent interface—but it is only one layer of a much larger AI ecosystem.AGENT IDENTITY, GOVERNANCE, AND SECURITY FOR ENTERPRISE AI One of the biggest challenges in enterprise AI is identity. Many organizations still allow AI agents to operate under shared service accounts or even employee credentials, making auditing nearly impossible. Every autonomous agent should have its own dedicated identity, least-privilege permissions, and complete traceability. Combined with centralized governance, organizations gain full visibility into who—or what—accessed sensitive data, ensuring compliance with standards such as GDPR, SOC 2, and industry-specific regulations. FROM RAG TO ONTOLOGIES: BUILDING AGENTS THAT UNDERSTAND BUSINESS CONTEXTTraditional Retrieval-Augmented Generation (RAG) systems retrieve documents and generate answers based on matching text. While useful, they rarely understand how a business actually operates. Agent Mesh architectures replace document-centric reasoning with ontologies that model customers, products, suppliers, policies, and business relationships. Instead of searching for words, AI agents reason over structured knowledge, dramatically improving accuracy, consistency, and decision-making across the enterprise. THE AI LANDING ZONE: CENTRALIZED CONTROL FOR AGENT MESHScaling dozens or even hundreds of AI agents requires more than good prompts. Organizations need a dedicated AI Landing Zone that combines identity management, governance policies, model gateways, observability, cost controls, and centralized approval processes. Every model request flows through a governance layer where security, regional compliance, budget limits, and policy enforcement are applied automatically. This approach transforms isolated AI projects into a standardized enterprise platform capable of supporting large-scale autonomous operations. AGENT 365, OBSERVABILITY, AND FINOPS FOR RESPONSIBLE AIManaging AI at scale requires complete operational visibility. A centralized control plane such as Agent 365 enables organizations to inventory agents, monitor usage, assign ownership, retire unused "ghost agents," and analyze every model invocation. Combined with comprehensive observability and FinOps practices, businesses can optimize token consumption, enforce budgets, detect abnormal behavior, and maintain continuous compliance while significantly reducing operational costs. THE FUTURE OF MICROSOFT AI: FROM COPILOT TO THE AGENT MESHThe next generation of enterprise AI is no longer about individual chatbots—it is about interconnected, governed, autonomous systems working together. Organizations that invest early in Agent Mesh architectures, centralized governance, ontology-driven reasoning, secure identities, and AI operating platforms will be able to scale hundreds of intelligent agents safely and efficiently. The future belongs to businesses that treat AI not as a feature, but as enterprise infrastructure capable of supporting continuous automation, intelligent decision-making, and long-term digital transformation.Become a supporter of this podcast: -
The Future of IT Is Agentic: Inside Windows 365, Intune & Microsoft's AI Vision with Christiaan Brinkhoff 29.07.2026 1h 29minChristiaan Brinkhoff shares the remarkable career path that took him from speaking at community events and writing technical blogs to becoming one of the key people behind Microsoft's modern cloud desktop strategy. After joining FSLogix, which was later acquired by Microsoft, he helped shape Azure Virtual Desktop before becoming part of the secret development team behind Windows 365. He discusses working in Redmond during one of the most transformative periods in Microsoft's history, contributing to innovations including Windows 365 Boot, Windows 365 Switch, the Windows App, multiple patents, and the evolution of Cloud PCs. Today, he continues driving innovation as VP of Product at Nerdio, helping organizations simplify enterprise endpoint management.WHY CLOUD PCS ARE BECOMING THE FUTURE OF ENTERPRISE COMPUTINGCloud PCs are no longer just a niche virtualization technology. Christiaan explains how Windows 365 fundamentally changes enterprise computing by moving Windows into the cloud while maintaining the familiar user experience. Instead of thinking about remote desktops as a complex virtualization platform, organizations can now manage Cloud PCs through Microsoft Intune just like traditional physical devices. This dramatically lowers the barrier to adoption while making remote work, device replacement, and endpoint security significantly easier to manage. AZURE VIRTUAL DESKTOP VS. WINDOWS 365 One of the biggest discussions in modern endpoint management is understanding where Azure Virtual Desktop ends and Windows 365 begins. Christiaan explains that Azure Virtual Desktop remains the highly customizable Platform-as-a-Service offering for organizations needing maximum flexibility, while Windows 365 delivers a fully managed Software-as-a-Service experience where Microsoft handles much of the underlying complexity. Rather than replacing each other, both services complement one another, allowing organizations to choose the right solution based on workloads, management capabilities, and business requirements. HOW COVID ACCELERATED THE CLOUD PC REVOLUTIONThe pandemic completely transformed the adoption of virtual desktops. Christiaan reflects on how Azure Virtual Desktop evolved from a relatively small service into one of Microsoft's fastest-growing enterprise platforms almost overnight. Organizations suddenly needed secure remote access for thousands of employees, and Microsoft's virtualization technologies became a critical foundation for enabling remote work around the world. This massive adoption also created the demand for an even simpler cloud-native experience, ultimately accelerating the development and success of Windows 365. THE STORY BEHIND WINDOWS 365 BOOT AND WINDOWS 365 SWITCHFew people know the design decisions behind some of Windows 365's most innovative features. Christiaan explains how Windows 365 Boot was created to remove the complexity of traditional virtual desktop logins by allowing users to boot directly into a Cloud PC. He also shares how Windows 365 Switch enables users to seamlessly move between their local device and their Cloud PC as naturally as switching between Windows virtual desktops. Both features were designed to hide technical complexity and create an experience that feels completely native to Windows users. WHY MICROSOFT INTUNE BECAME THE FOUNDATION OF WINDOWS 365One of the smartest strategic decisions Microsoft made was integrating Windows 365 directly into Microsoft Intune rather than building an entirely separate management platform. Christiaan explains how this allows IT administrators to manage Cloud PCs using the same policies, security settings, compliance controls, and deployment processes they already use for physical devices. This unified management experience significantly reduced adoption barriers and made Windows 365 attractive to organizations of every... -
How Do You Successfully Deploy Microsoft 365 Copilot Across an Enterprise? 29.07.2026 1h 32minA successful Microsoft 365 Copilot deployment begins long before licenses are assigned. Organizations should first define measurable business outcomes, identify high-value use cases, and secure executive sponsorship across IT, security, finance, and business leadership. Rather than treating Copilot as another software rollout, enterprises need an AI operating model that aligns governance, adoption, security, and ROI with real business processes. Starting with targeted scenarios creates faster wins while reducing risk and establishing a repeatable framework for future AI initiatives.ASSESS MICROSOFT 365 READINESS BEFORE ENABLING COPILOTOne of the biggest mistakes organizations make is assuming their Microsoft 365 tenant is AI-ready simply because they own the licenses. Before deployment, businesses should assess identity management, SharePoint permissions, Teams collaboration spaces, OneDrive sharing, Microsoft Entra ID, Conditional Access, and overall information architecture. Existing oversharing, outdated permissions, unmanaged guest accounts, and poor data ownership become significantly more visible once Copilot can surface enterprise knowledge through natural language. A structured readiness assessment identifies critical risks before they become security incidents during rollout. SECURE YOUR DATA WITH GOVERNANCE, PERMISSIONS, AND MICROSOFT PURVIEWMicrosoft 365 Copilot never creates new permissions—it simply works with the permissions users already have. That makes governance, Microsoft Purview, sensitivity labels, Data Loss Prevention, lifecycle management, and permission cleanup essential parts of every deployment. Organizations should prioritize high-risk content, establish clear ownership of SharePoint sites and Teams, implement strong information protection policies, and continuously review access rights. AI success depends as much on data quality and governance as it does on the underlying technology. RUN A CONTROLLED COPILOT PILOT BEFORE SCALING ACROSS THE ENTERPRISEEnterprise AI should expand through carefully planned pilot programs instead of company-wide deployments. Successful pilots focus on repeatable business workflows, measurable productivity improvements, and clearly defined success criteria. Business owners, IT, security, and finance should jointly evaluate business outcomes, adoption rates, governance findings, and user feedback before approving additional rollout phases. Every pilot should generate practical lessons that improve future deployments rather than simply proving that Copilot can generate content. DRIVE MICROSOFT 365 COPILOT ADOPTION WITH CHANGE MANAGEMENT Technology alone does not transform an organization—people do. Successful Copilot adoption requires executive communication, role-based enablement, workflow-specific training, AI champions, ongoing coaching, and continuous learning. Employees need practical guidance on when to trust Copilot, when human review remains mandatory, and how AI supports rather than replaces professional judgment. Measuring adoption should focus on changed business behavior and improved workflows instead of simple prompt counts or login statistics. MEASURE COPILOT ROI AND BUILD A SCALABLE ENTERPRISE AI PLATFORM The true return on Microsoft 365 Copilot comes from measurable business improvements rather than AI usage alone. Organizations should track workflow efficiency, quality improvements, reduced rework, employee productivity, governance maturity, and financial outcomes across every deployment phase. A successful rollout creates more than a productive workforce—it establishes the governance, architecture, operating model, and organizational experience required to scale future AI capabilities such as Copilot Studio, AI agents, Microsoft Graph integrations, and enterprise automation.Become a supporter of this podcast: -
From Pilot to Production: Building Enterprise AI That Actually Delivers with Leon Gordon [MVP] 28.07.2026 59minLeon Gordon explains why most enterprise AI initiatives never reach production and introduces the concept of the Pilot Tax—the hidden cost organizations pay when AI projects remain stuck in proof-of-concept mode. He shares practical strategies for moving from experimentation to measurable business outcomes through governance, Microsoft Fabric, and structured AI adoption.FROM FOOTBALL TO MICROSOFT MVPLeon shares his unconventional career journey, from leaving school early to pursue professional football to becoming a five-time Microsoft MVP, founder of Onyx Data, and one of the leading voices in Microsoft Fabric and enterprise AI. His story demonstrates how continuous learning and real-world experience can outperform traditional career paths. BUILDING AI THAT DELIVERS BUSINESS VALUE Rather than focusing on flashy AI demonstrations, Leon explains why organizations must begin with measurable business outcomes. Every AI initiative should start by defining success metrics, expected ROI, and governance requirements before writing a single prompt or deploying an agent. WHY MOST AI PROJECTS FAILDespite billions being invested worldwide, most generative AI projects never reach production. Leon explores the biggest reasons behind these failures, including weak governance, poor data quality, unrealistic expectations, insufficient testing, and a lack of long-term strategy. He argues that organizations often rush to implement AI before preparing the necessary foundations.THE PILOT TAX EXPLAINED Leon introduces his Pilot Tax methodology, designed to help organizations escape endless proof-of-concept cycles. By focusing on small, measurable Proof of Value projects instead of isolated pilots, companies can validate business impact quickly and create a structured path toward production-ready AI. MICROSOFT FABRIC AS THE AI FOUNDATION Microsoft Fabric is more than a data platform. Leon explains how it unifies data engineering, analytics, semantic models, AI, real-time intelligence, and application development into a single ecosystem. This dramatically simplifies enterprise architecture while accelerating AI adoption across organizations.FABRIC APPS AND THE FUTURE OF BUSINESS APPLICATIONS Fabric Apps represent one of Microsoft's newest innovations. Leon discusses how they bring application development directly into the Fabric ecosystem, enabling developers to build AI-powered business applications that interact seamlessly with semantic models, analytics, and enterprise data. GOVERNANCE IS THE REAL COMPETITIVE ADVANTAGE Strong governance is the difference between successful AI deployments and expensive failures. Leon explains why governance must cover security, permissions, ownership, data quality, lineage, metadata, compliance, and continuous monitoring from day one instead of being added later. WHY METADATA AND MICROSOFT PURVIEW MATTERMetadata often receives little attention until organizations begin implementing AI. Leon explains how Microsoft Purview helps organizations catalog, classify, govern, and secure enterprise data while making it easier for AI systems to understand business context and maintain trust in generated answers. THE GROWING IMPORTANCE OF SEMANTIC MODELS Semantic models are becoming one of the most valuable assets in modern data platforms. Leon explains how they provide business context, reusable calculations, relationships, and definitions that enable AI agents to deliver accurate, explainable, and trustworthy business insights. GOVERNANCE SHOULD NEVER WAIT Many organizations prioritize dashboards before governance, promising to "fix it later." Leon argues this almost always creates technical debt. Instead, governance should be embedded throughout the development lifecycle so... -
Microsoft Purview is a Trap: The Hard Truth About Data Governance 28.07.2026 1h 1minMicrosoft Purview is included with many Microsoft 365 subscriptions, making it incredibly easy to enable. That convenience is also its biggest danger. Because there is no procurement process or large implementation project, many organizations activate Purview without defining clear business goals, ownership, or governance. The result is often a catalog filled with thousands of scanned assets, confusing permissions, and business users who abandon the platform after their first experience. This episode explains why Purview itself is not the problem—the real challenge is how organizations approach data governance. Governance must begin with business objectives, ownership, and change management before any scans are executed or collections are created.STOP BUILDING A CATALOG — START SOLVING BUSINESS PROBLEMSOne of the biggest mistakes organizations make is attempting to catalog their entire data estate from day one. Instead of asking, "What data do we have?", they should ask, "What business question are we trying to answer?" Every successful Microsoft Purview deployment should begin with a single, measurable use case such as fraud detection, customer churn prediction, or regulatory reporting. That single question determines which data sources need to be scanned, who should own the data, which governance domain is required, and what success looks like. Building one valuable data product first creates trust, enables rapid feedback, and provides a repeatable blueprint for future governance initiatives. A focused rollout consistently delivers better adoption than a large-scale "Big Bang" implementation.DESIGNING MICROSOFT PURVIEW FOR SCALEThe episode provides a deep architectural walkthrough of Microsoft Purview's governance model, explaining the four permission layers that control access: the Tenant Layer, the Data Map, the Unified Catalog, and Governance Domains. Rather than assigning permissions directly to individuals, organizations should package permissions into role-based Microsoft Entra groups aligned with real business personas. The discussion also covers how to organize collections around business domains instead of technical platforms, why governance domains should mirror business ownership, and how data products become the bridge between raw technical assets and meaningful business outcomes. By structuring Purview around people, business processes, and ownership rather than databases and technologies, organizations create a catalog that employees can actually understand and use.DATA PRODUCTS, OWNERSHIP, AND THE MEDALLION ACCOUNTABILITY MODELGovernance only succeeds when ownership is clearly defined. The episode explains how data products bring together assets from multiple platforms under a single business purpose, complete with owners, glossary terms, policies, and approval workflows. It also explores how accountability shifts throughout a modern data platform using the Medallion Architecture. Bronze data remains the responsibility of source system owners, Silver data belongs to engineering teams responsible for transformations, and Gold data becomes the responsibility of business-facing data product owners. Explicit ownership at every stage eliminates ambiguity during audits, improves trust in analytics, and ensures someone is always accountable when business-critical data or AI models produce unexpected results.SECURING MICROSOFT PURVIEW WITHOUT CREATING CHAOSBecause Microsoft Purview administrators can elevate their own permissions and control nearly every aspect of the platform, privileged access requires special attention. The episode explains why Privileged Identity Management (PIM) should always protect high-privilege roles using just-in-time access, approval workflows, multi-factor authentication, limited activation windows, and full auditing. Beyond security, the rollout strategy itself determines long-term... -
From Excel Expert to Microsoft MVP: Empowering Millions with Data, Dashboards & AI with Karen Abecia [Microsoft MVP] 27.07.2026 59minaren Abecia shares the remarkable journey that transformed a passion for Microsoft Excel into a global career as one of the world's best-known Excel educators. She explains how discovering creative spreadsheet design early in her career led her to help thousands of professionals improve their work, build confidence, and communicate data more effectively. Her story demonstrates that technical expertise combined with genuine passion can create opportunities far beyond traditional career paths.WHY EXCEL CHANGED HER LIFEFor Karen, Excel represents much more than software. It gave her financial independence, allowed her to support her family, opened international opportunities, and became a tool for empowering others. She even has two Excel tattoos to symbolize how profoundly the application influenced both her personal and professional life. Rather than viewing Excel as spreadsheets, she sees it as a platform that gives people confidence, recognition, and career growth. LEARNING WITHOUT A TRADITIONAL EDUCATIONKaren discusses building her career without a university degree and explains why continuous learning has always been essential. She believes that formal education is only one path to success and encourages people to study what genuinely excites them. Her philosophy is simple: lifelong curiosity matters more than traditional credentials. IS EXCEL REALLY DYING? Despite years of headlines claiming that Excel is becoming obsolete, Karen strongly disagrees. She argues that most people predicting Excel's demise do not truly understand how widely it is used across businesses worldwide. Instead of worrying about these predictions, she focuses on helping people solve real problems with the tools they already rely on every day. THE SECRET OF A GREAT DASHBOARDCreating dashboards is no longer just about technical skills. Karen believes AI can generate standard dashboards for almost anyone, making creativity and presentation more valuable than ever. She explains that outstanding dashboards create a genuine "wow effect" through thoughtful design, visual storytelling, layout, colors, alignment, and attention to detail rather than simply displaying charts and numbers. COMMON DASHBOARD MISTAKESMany users focus entirely on calculations while overlooking presentation. Karen explains that inconsistent alignment, poor spacing, mismatched colors, incorrect font sizes, and even spelling mistakes can significantly reduce a dashboard's impact. Small visual improvements often make a much larger difference than adding additional formulas or charts. TEACHING MILLIONS THROUGH SIMPLICITYHaving trained more than 15,000 students, Karen believes effective teaching is not about demonstrating advanced technical knowledge. Instead, it is about helping people become more productive and confident using practical techniques they can immediately apply. Her students come from virtually every industry because almost anyone using a computer can benefit from Excel. EXCEL, AI, AND THE FUTURE OF PRODUCTIVITYKaren discusses how AI is changing Excel workflows and why she actively experiments with multiple AI assistants, including Microsoft Copilot and Claude. Rather than expecting AI to replace expertise, she uses it to accelerate her own creative process while maintaining her personal design style. She also shares her growing interest in Copilot Agents and Microsoft's rapidly evolving AI ecosystem. EXCEL VS. POWER BI Rather than viewing Excel and Power BI as competitors, Karen now considers them complementary tools. Different organizations require different solutions depending on their size, budget, and reporting needs. While Excel remains her preferred environment for flexibility and creativity, she recognizes that Power BI provides capabilities Excel cannot easily... -
The Copilot Credit Trap- Why Your AI Economy is Already Broken 26.07.2026 1h 12minFor decades, enterprise software followed a predictable financial model. Organizations purchased licenses, assigned them to users, and budgeted annual IT spending with confidence. AI changes that completely. Modern AI platforms are no longer sold purely as software—they're becoming consumption-based services where autonomous agents perform work on your behalf. Every action, every reasoning cycle, every orchestration task, and every AI workflow consumes credits instead of simply using a fixed license. This episode explains why Copilot Credits fundamentally change enterprise budgeting, why governance becomes more important than licensing, and how organizations must rethink identity, permissions, auditing, FinOps, and AI compliance before autonomous agents become part of everyday business operations.FROM SOFTWARE LICENSES TO AI ECONOMICSTraditional enterprise software was easy to budget. Organizations counted employees, purchased licenses, and forecasted annual costs with relatively little uncertainty. AI introduces a completely different financial model. Instead of paying only for access, organizations increasingly pay for work performed. Every autonomous action performed by an AI agent consumes credits based on:Reasoning complexityRuntimeContext sizeTool usageModel selectionThis transforms AI from a predictable software expense into an operational resource similar to cloud compute. The presentation argues that organizations are no longer purchasing software—they're purchasing autonomous labor, and that fundamentally changes IT economics.THE COPILOT CREDIT TRAPThe biggest misconception surrounding Copilot Credits is that they simply represent another licensing model. They don't. Credits become the currency of AI work. A lightweight task may consume relatively few credits. Complex reasoning tasks involving multiple enterprise systems, long context windows, and autonomous orchestration consume dramatically more. Costs now scale according to:Agent behaviorTask complexityOrganizational adoptionWorkflow automationrather than simply employee count. Organizations may believe they have predictable AI costs because licensing appears fixed, while actual consumption grows continuously behind the scenes. This hidden variability creates what the presentation describes as the Copilot Credit Trap.WHY FINANCE CAN NO LONGER PREDICT COSTSFinance departments have traditionally planned annual software budgets using fixed subscription pricing. Consumption-based AI disrupts that model. Instead of budgeting for employees, organizations must now forecast:Daily agent activityDepartmental usageBusiness workflowsCredit consumptionSeasonal demandAutomation growthSmall changes in adoption can produce disproportionately large cost increases. The challenge isn't simply higher spending. It's the loss of financial predictability. Variable AI consumption introduces volatility that traditional IT budgeting processes were never designed to manage.VISIBILITY IS THE FIRST GOVERNANCE PROBLEMMany organizations cannot accurately answer basic questions such as:Which AI agents currently exist?Which departments deployed them?Which systems can they access?Which business processes do they automate?How much do they cost?The presentation describes this as the visibility crisis. Shadow AI deployments appear through:Copilot StudioPower AutomateDepartmental automationThird-party AI integrationsCustom workflowsWithout a complete inventory, governance becomes impossible because organizations cannot secure, monitor, or budget for systems they don't even know exist. -
The End of AI Bloat: Why Modern Agents Need Skills 26.07.2026 1h 13minMany AI agents start out fast, responsive, and surprisingly intelligent. But after a few months of real-world use, something changes. Response times increase, costs rise, prompts become enormous, and accuracy begins to decline. Organizations often respond by upgrading to larger models, expanding prompts, or adding more orchestration—but the underlying problem remains. The issue isn't the model. It's the architecture. This episode explains why monolithic prompts create what is known as the Context Tax, how modular Skills solve the problem through progressive disclosure, and why Skills are becoming the architectural foundation of modern AI agents across Microsoft Copilot Studio, GitHub Copilot, Claude Code, and the broader enterprise AI ecosystem.THE CONTEXT TAXEvery enterprise AI project eventually faces the same challenge. At first, an agent contains a relatively small system prompt describing its role, tone, business rules, and guardrails. As the organization grows, more instructions are added:PoliciesCompliance rulesBusiness proceduresExamplesEdge casesDepartment-specific workflowsEventually the prompt becomes thousands of tokens long. Every user request forces the model to process every instruction—even when ninety-five percent of them are completely irrelevant. This hidden processing overhead is called the Context Tax. Rather than making agents smarter, larger prompts increase latency, raise inference costs, introduce reasoning noise, and gradually reduce answer quality. The presentation argues that the real problem isn't insufficient AI capability—it is forcing the model to continuously reason over information it doesn't actually need.WHY AGENTS DEGRADE OVER TIMEAgent degradation is remarkably predictable. Organizations usually begin with one comprehensive instruction document that contains everything the AI should know. Initially this works well. Then new departments request additional functionality. Policies evolve. Compliance requirements expand. New workflows are added. Instead of restructuring the architecture, teams simply keep extending the same prompt. The result is context saturation. The model spends increasing amounts of effort searching through irrelevant guidance before finding the instructions that actually matter. This produces several side effects:Higher token consumptionSlower responsesIncreased hallucinationsMore inconsistent reasoningHigher operational costsThe AI hasn't become less intelligent. Its reasoning path has simply become overwhelmed by unnecessary context.ALWAYS-ON GUIDANCE VS SITUATIONAL EXPERTISEOne of the most important architectural distinctions introduced in this session is separating always-on guidance from situational expertise. Always-on guidance includes information that applies to every conversation:Agent identityTone of voiceUniversal compliance rulesSecurity requirementsCore behavioral instructionsSituational expertise is different. It only matters when specific scenarios occur. Examples include:Vendor onboardingLeave eligibilityTax regulationsRefund workflowsRegional complianceIncident response proceduresTraditional agents mix both categories into one enormous prompt. Modern agent architectures separate them. Only universal guidance remains permanently loaded. Everything else becomes modular Skills that activate only when required.WHAT IS A SKILL?A Skill is much more than a prompt. It is a reusable package containing:Structured instructionsMetadataTrigger descriptionsOptional scriptsReference documentsTemplatesSupporting assetsThe core of every... -
THE DEATH OF THE PROXY: Architecting Dataverse for the Agent Fabric 26.07.2026 59minFor years, Microsoft's recommended architecture for connecting AI assistants like Claude Desktop to Dataverse relied on a local STDIO proxy. It was simple, easy to install, and perfectly suited for individual developers experimenting with AI-powered workflows. But enterprise AI has evolved. Organizations are no longer connecting a single assistant to a single application. They're connecting hundreds—or even thousands—of AI agents across multiple clients, platforms, and business systems. That architectural shift changes everything. This episode explains why the traditional proxy model has reached its limits, why Streamable HTTP fundamentally changes enterprise AI integration, and how Dataverse is evolving from the database behind Power Apps into the governed data backbone for the entire Agent Fabric.WHY THE STDIO PROXY WAS CREATEDThe original STDIO proxy solved a very specific problem. Early MCP clients like Claude Desktop needed a simple way to communicate with cloud services while running locally on a developer's machine. Instead of exposing an internet-facing endpoint, developers launched a local process that translated communication between the AI client and Dataverse. The advantages were obvious:Simple installationNo HTTP server requiredNo certificatesMinimal infrastructureIsolated execution per userFor individual developers, this architecture worked remarkably well. Every proxy was independent, failures affected only one user, and deployment required little more than installing a small application. The problem wasn't that the proxy stopped working. The problem was that enterprise AI completely outgrew the assumptions behind it.THE PROXY SCALING PROBLEMThe proxy architecture assumes one developer. Modern enterprises operate very differently. Instead of one Claude Desktop instance, organizations now deploy:Claude DesktopClaude CodeGitHub CopilotCopilot CLICustom orchestration servicesInternal AI assistantsEach proxy creates:Independent authenticationSeparate connection poolsIndividual infrastructureSeparate monitoringIsolated failure domainsAs organizations scale from ten developers to hundreds or thousands, operational complexity increases exponentially. Instead of managing one governed service, administrators find themselves maintaining hundreds of disconnected proxy processes with little centralized visibility or control. What began as a convenience gradually becomes operational debt.THE LATENCY MYTHOne of the strongest arguments for STDIO has always been performance. Microbenchmarks show local inter-process communication taking only a few milliseconds, while HTTP introduces network latency and TLS negotiation. On paper, STDIO appears dramatically faster. However, those benchmarks ignore the actual workload. Most Dataverse operations spend hundreds of milliseconds—or even more than a second—executing business logic, security checks, and database queries. When those execution times are included, HTTP overhead becomes relatively insignificant. Even more importantly, enterprise HTTP deployments benefit from:Connection poolingPersistent sessionsHorizontal scalingLong-lived servicesShared infrastructureMeanwhile, every new proxy instance pays startup costs, authentication overhead, and process initialization repeatedly. The presentation argues that organizations measuring end-to-end performance often find properly optimized HTTP deployments outperform local proxy architectures despite their higher transport latency.STREAMABLE HTTP CHANGES EVERYTHINGInstead of every AI client running its own proxy, Dataverse now exposes a single Streamable HTTP endpoint. Every supported AI client... -
The Death of the Pipeline: Why AI Agents are Replacing Traditional 25.07.2026 1h 9minFor more than two decades, CI/CD pipelines have been the backbone of modern software delivery. Developers commit code, automated builds run, tests execute, security scans complete, someone approves the deployment, and production is updated. This model transformed software engineering and enabled DevOps to become the industry standard. But the world has changed. Cloud-native applications, Kubernetes, AI, multi-cloud architectures, and thousands of daily deployments have pushed traditional pipelines beyond what they were designed to handle. The real bottleneck is no longer automation—it's the fact that automation still revolves around human decision-making and linear workflows. This episode explores a radical shift: replacing sequential CI/CD pipelines with intelligent, autonomous AI agents that reason, collaborate, and adapt in real time. We'll examine why traditional pipelines are reaching their limits, how agentic systems fundamentally change software delivery, and why governance—not autonomy—is becoming the defining architectural challenge of the next generation of DevOps.WHY THE TRADITIONAL PIPELINE IS BREAKINGTraditional CI/CD pipelines were designed around a simple assumption: Humans make the important decisions. A developer commits code. The pipeline builds. Tests execute. Security scans run. Then someone reviews. Someone approves. Someone decides whether deployment should continue. Every approval introduces waiting. Every handoff introduces latency. Every manual decision becomes another bottleneck. This worked perfectly when organizations deployed once every few weeks. Today's cloud-native organizations deploy hundreds or even thousands of times every day. At that scale, human approval is no longer primarily a safety mechanism. It becomes the slowest component in the entire delivery system. The pipeline itself isn't broken. Its underlying operating model is.AUTOMATION ISN'T THE SAME AS INTELLIGENCEMany organizations tried solving pipeline bottlenecks through automation. They built scripts. They created runbooks. They automated approvals. Initially this improved delivery speed. Eventually another problem appeared. Scripts only work inside predefined conditions. Whenever infrastructure changes, scripts begin failing. New Kubernetes versions... Changed APIs... Different deployment strategies... Updated security requirements... Every infrastructure evolution requires maintaining automation itself. Traditional automation has no understanding of context. It executes procedures. It doesn't reason. Organizations eventually spend enormous effort maintaining automation instead of benefiting from it. The presentation argues that static automation reaches a ceiling because modern infrastructure changes faster than rule-based systems can keep up.AI AGENTS CHANGE THE MODELAn AI agent is fundamentally different from a script. Scripts execute instructions. Agents reason. Instead of simply matching predefined rules, an agent continuously:Observes system stateUnderstands contextEvaluates possible actionsChooses the safest strategyLearns from previous outcomesImagine a degraded service. A script simply restarts it. An AI agent first investigates. Is this really a service failure? Is memory leaking? Is traffic unusually high? Would a canary rollout be safer than a restart? Could restarting actually make the situation worse? Rather than following procedures, AI agents operate using policies and objectives. That distinction fundamentally changes software delivery because the system adapts instead of merely executing instructions.FROM PIPELINES TO AGENT FABRICSPerhaps the biggest concept introduced in this session is that the future isn't a faster pipeline—it isn't a pipeline at all. Traditional delivery is sequential. Commit. Build. Test. Deploy. Each stage waits for the previous... -
The Productivity Illusion: Why AI is Breaking Your Engineering KPIs 25.07.2026 1h 15minAt first glance, the numbers look incredible. Deployment frequency is increasing, pull requests are being merged faster than ever, AI is generating more code, and engineering teams appear dramatically more productive. Executive dashboards are filled with green indicators suggesting software delivery has entered a new golden age. But beneath those impressive metrics lies a very different reality. AI has accelerated code generation, but it hasn't eliminated engineering work. Instead, it has shifted the bottlenecks from writing code to reviewing, validating, governing, and understanding it. Organizations are producing significantly more code while simultaneously experiencing more incidents, higher cognitive load, greater technical debt, and increased developer burnout.THE PRODUCTIVITY ILLUSIONThe central message of this session is simple: More code does not automatically mean more productivity. AI has dramatically increased engineering output, but many organizations are confusing output with value. According to the presentation:AI now generates a significant portion of production code.Pull request throughput has nearly doubled.Developers save substantial time on repetitive coding tasks.Yet production incidents, code churn, review times, and cognitive load have all increased.Rather than removing engineering constraints, AI has simply moved them further downstream into review, testing, operations, and governance. The dashboard still reports success—but the engineering system itself is becoming increasingly fragile.WHY TRADITIONAL KPIs ARE FAILINGMany engineering organizations still rely heavily on classic DevOps metrics such as:Deployment FrequencyLead TimeChange Failure RateMean Time To Recovery (MTTR)These metrics were designed for a world where humans wrote nearly all production code. AI fundamentally changes that assumption. Today's bottleneck is no longer writing software. It is understanding software. Deployment frequency may increase while review queues explode. Lead time may decrease while technical debt grows. Change failure rates may appear acceptable while code requires constant rewrites. The presentation argues that traditional engineering dashboards measure activity, not system health.WHEN MORE CODE CREATES MORE PROBLEMSOne of the strongest themes throughout the presentation is the unintended consequence of AI-generated software. Developers can now create thousands of lines of code within minutes. Human reviewers, however, still need to verify every important architectural, security, and business decision. As pull requests become larger and more complex:Review times increase dramatically.Senior engineers become bottlenecks.Production incidents rise.Technical debt accumulates faster.More code requires future maintenance.Instead of removing engineering work, AI shifts effort toward verification and understanding. The engineering organization appears faster while becoming increasingly overloaded.THE COGNITIVE LOAD CRISISPerhaps the most important concept discussed is cognitive load. AI reduces the effort required to write code. It dramatically increases the effort required to understand that code. Developers now spend increasing amounts of time:Reviewing AI-generated implementations.Understanding unfamiliar logic.Switching between contexts.Verifying correctness.Explaining code the AI never documented.The presentation distinguishes between productive engineering effort and unnecessary mental overhead. Instead of solving business problems, engineers increasingly spend their cognitive capacity validating machine-generated output. The result is lower developer satisfaction despite higher apparent... -
The DevOps Tax: Why Your Platform is Failing 25.07.2026 1h 18minWelcome to another episode of Knowledge Nuggets with Mirko Peters. Today we're exploring The DevOps Tax—the hidden cost that silently reduces engineering productivity, increases cognitive overload, and prevents organizations from delivering software at scale. DevOps began with a simple but powerful vision: "You build it, you run it." Small, autonomous teams would own their applications from development through production, eliminating handoffs between developers and operations. For many organizations, this approach initially delivered faster releases and better accountability. But as companies grew, so did the complexity. Developers were expected to become experts in Kubernetes, cloud networking, Infrastructure as Code, observability, security, compliance, cost optimization, and CI/CD—all while still building business features. Instead of accelerating innovation, many teams found themselves spending more time managing infrastructure than delivering customer value. In this episode, we'll examine why the DevOps model struggles at enterprise scale, what the DevOps Tax really costs organizations, and how Platform Engineering, Golden Paths, Infrastructure as Code, Policy as Code, and AI-ready governance provide a practical path forward.WHAT IS THE DEVOPS TAX?The DevOps Tax isn't a software licensing cost or another cloud bill. It's the hidden productivity cost created when developers spend the majority of their time solving infrastructure problems instead of building products. Modern developers are expected to understand:KubernetesContainersCloud platformsNetworkingRBACCI/CDInfrastructure as CodeMonitoringDistributed tracingSecurityComplianceCost optimizationDisaster recoveryNone of these activities directly create customer value, yet they consume a significant percentage of engineering capacity. The presentation argues that this "tax" compounds over time through burnout, delayed releases, duplicated effort, and increased organizational complexity, ultimately reducing the return on engineering investment. Research referenced in the session suggests that roughly 74% of developer capacity is consumed by infrastructure toil instead of feature delivery.WHY DEVOPS BREAKS AT SCALEDevOps works remarkably well for small teams. When ten or fifteen engineers own an application, everyone understands the architecture, infrastructure decisions are shared, and feedback loops remain short. Enterprise organizations are different. As hundreds of teams emerge, every group begins selecting its own tools:Different CI/CD platformsDifferent monitoring stacksDifferent Infrastructure as Code frameworksDifferent deployment approachesDifferent security modelsEach individual decision appears reasonable. Collectively, however, they create enormous operational complexity. Documentation diverges. Runbooks become inconsistent. Senior engineers become bottlenecks. Developers spend increasing amounts of time coordinating infrastructure instead of delivering business functionality. The presentation argues that organizations eventually stop managing infrastructure and begin managing organizational chaos.THE COGNITIVE LOAD CRISISOne of the central themes of the session is cognitive load. Developers already need to understand complex business domains. Adding infrastructure decisions on top dramatically increases the amount of mental effort required before writing any business logic. The presentation introduces the concept of Concepts to Ship (CTS). A traditional DevOps environment often requires developers to understand fifteen to twenty different infrastructure concepts before deploying a service. These include:Kubernetes networkingService... -
Microsoft Purview Insider Risk Management - Simply Explained 24.07.2026 14minWelcome to another episode of Knowledge Nuggets with Mirko Peters. Today we're exploring Microsoft Purview Insider Risk Management, Microsoft's intelligent solution for identifying risky user behavior before it turns into a costly security incident. When organizations think about cybersecurity, they usually focus on external threats—hackers, malware, ransomware, and phishing attacks. But one of the biggest security risks often comes from inside the organization. Employees already have legitimate access to sensitive information. Whether through malicious intent or simple human error, that trusted access can become a significant business risk. Microsoft Purview Insider Risk Management helps organizations identify unusual patterns of user behavior, investigate potential insider threats, and respond appropriately while maintaining strong privacy protections. Rather than assuming every employee is a threat, it uses intelligent risk scoring and machine learning to distinguish between normal business activity and behavior that deserves closer attention. In this episode, we'll explore how Insider Risk Management works, how Microsoft calculates risk, and why privacy remains a central part of the entire solution.WHY INSIDER RISK IS DIFFERENTTraditional cybersecurity is designed to stop unauthorized users from gaining access. Firewalls block unwanted network traffic. Multi-factor authentication verifies identities. Endpoint protection detects malware. These technologies are extremely effective against external attacks. However, they all share one important assumption: Once users successfully authenticate, they are generally trusted. That assumption creates a significant blind spot. Insider threats don't involve breaking into the organization. They involve legitimate users performing activities that become risky over time. Insider risk generally falls into two categories. Malicious insider risk includes intentional activities such as data theft, intellectual property theft, sabotage, or unauthorized data exfiltration. Accidental insider risk includes users mistakenly sharing confidential information, forwarding sensitive emails, copying files to personal storage, or violating security policies without realizing it. Traditional security solutions rarely detect these behaviors because, technically, the user is authorized to perform many of the underlying actions. Microsoft Purview Insider Risk Management focuses on identifying risky behavior rather than simply validating user access.WHAT IS MICROSOFT PURVIEW INSIDER RISK MANAGEMENT?Microsoft Purview Insider Risk Management is a compliance capability within Microsoft Purview that helps organizations identify, investigate, and respond to potentially risky user behavior. Rather than monitoring individual activities in isolation, the system analyzes patterns across Microsoft 365. Signals are collected from multiple Microsoft services, including:Exchange OnlineSharePoint OnlineOneDriveMicrosoft TeamsMicrosoft Entra IDEndpoint activityData Loss PreventionSensitivity labelsMachine learning evaluates these signals over time to determine whether behavior differs significantly from normal activity. The objective is not to spy on employees. Instead, Microsoft focuses on identifying situations where organizations should perform additional review before a genuine security incident occurs. Human investigators always make the final decision. The platform simply highlights behavior that deserves attention.HOW RISK SCORING WORKSMicrosoft Purview Insider Risk Management does not generate alerts based on a single isolated action. Instead, it evaluates combinations of activities over time. Examples of monitored indicators include:Large file downloadsEmail forwardingPrinting sensitive documentsUSB file... -
Microsoft Purview Information Protection - Simply Explained 24.07.2026 15minWelcome to another episode of Knowledge Nuggets with Mirko Peters. Today we're exploring Microsoft Purview Information Protection, the foundation of Microsoft's data classification and protection strategy across Microsoft 365. Every day, organizations create thousands of documents, spreadsheets, emails, presentations, and Teams conversations. Some of that information is completely public, while other files contain financial records, customer information, legal contracts, intellectual property, or confidential business plans. The challenge isn't simply storing this data—it's ensuring every piece of information is handled appropriately wherever it travels. Microsoft Purview Information Protection solves this challenge by allowing organizations to classify sensitive information, apply persistent sensitivity labels, and automatically enforce protection policies across Microsoft 365. Instead of waiting until data is about to leave the organization, protection begins the moment the content is created. In this episode, we'll explore how Microsoft Purview Information Protection works, how sensitivity labels travel with your data, how automatic classification operates behind the scenes, and how it integrates with Data Loss Prevention, Microsoft Teams, and Microsoft 365 Copilot.WHY INFORMATION PROTECTION MATTERSMany organizations assume their information is secure simply because it resides in Microsoft 365. However, protecting data from hackers is only one part of the challenge. The larger risk often comes from accidental sharing, misclassification, or users unknowingly exposing confidential information. Traditional security approaches attempted to inspect files only when they were leaving the organization. Every outgoing email or shared document had to be scanned before determining whether it contained sensitive information. While effective, this approach introduces delays and only reacts after data has already begun moving. Microsoft Purview Information Protection changes the model entirely. Instead of waiting until information leaves the organization, content is classified and labeled immediately. Once protected, every Microsoft 365 service instantly understands how that information should be handled without repeatedly scanning the content. Protection becomes proactive rather than reactive.WHAT IS MICROSOFT PURVIEW INFORMATION PROTECTION?Microsoft Purview Information Protection provides a centralized framework for classifying, labeling, and protecting sensitive information. The core concept is remarkably simple. Every document or email receives a sensitivity label that communicates its security requirements. Common examples include:PublicInternalConfidentialHighly ConfidentialThese labels aren't merely visual indicators. Each label contains metadata that permanently travels with the file wherever it goes. That metadata can automatically trigger:EncryptionAccess restrictionsWatermarksHeaders and footersPrinting restrictionsSharing controlsCopy protectionRather than relying on users to remember every security setting manually, one sensitivity label applies the correct protections automatically. Because Information Protection is built directly into Microsoft 365, users often interact with it through the Sensitivity dropdown available in Word, Excel, PowerPoint, Outlook, and other Office applications.CLASSIFICATION: FINDING SENSITIVE INFORMATIONBefore information can be protected, Microsoft Purview must first identify sensitive content. Microsoft uses two primary detection methods. The first is Sensitive Information Types (SITs). These recognize structured information such as:Credit card numbersPassport numbersNational identification numbersHealthcare identifiersBanking... -
Microsoft Purview Data Loss Prevention (DLP) - Simply Explained 24.07.2026 15minWelcome to another episode of Knowledge Nuggets with Mirko Peters. Today we're exploring Microsoft Purview Data Loss Prevention (DLP), one of the most important security capabilities in Microsoft 365 for preventing accidental data leaks. When most people think about cybersecurity, they imagine hackers breaking through firewalls or ransomware attacks encrypting company data. But the reality is often much simpler. Many of the largest data breaches happen because someone accidentally sends confidential information to the wrong recipient, shares a sensitive document externally, or copies company data to an unauthorized location. Microsoft Purview Data Loss Prevention isn't designed to stop hackers—it is designed to stop well-intentioned employees from making costly mistakes. By automatically identifying sensitive information, monitoring how it's being used, and enforcing security policies across Microsoft 365, DLP quietly protects your organization's most valuable information without preventing employees from getting their work done. In this episode, we'll explore how Microsoft Purview DLP works across email, SharePoint, OneDrive, Teams, endpoints, and Microsoft 365 Copilot, and why it has become a cornerstone of modern Microsoft security.WHY DATA LOSS PREVENTION MATTERSMany organizations focus heavily on defending against external cyberattacks while overlooking the largest source of data loss: accidental human error. Employees regularly send emails to the wrong recipients, upload confidential documents to inappropriate locations, or unintentionally expose sensitive information through everyday collaboration. Traditional approaches attempted to solve this by locking everything down—blocking USB drives, restricting file sharing, and preventing external communication altogether. Unfortunately, overly restrictive environments reduce productivity and often encourage employees to find unofficial workarounds. Microsoft Purview DLP takes a different approach. Instead of blocking everything, it evaluates three critical questions:What type of data is being handled?Who is handling it?Where is the data going?Based on those answers, DLP automatically decides whether to allow, warn, audit, or block the activity. The goal isn't to restrict users—it is to prevent honest mistakes before they become security incidents.UNDERSTANDING DLP THROUGH A SIMPLE ANALOGYImagine your organization as a large office building. Microsoft Entra ID acts as the reception desk, verifying everyone's identity before allowing entry. But verifying identity alone doesn't prevent sensitive documents from leaving the building. Microsoft Purview DLP acts like a team of intelligent security guards positioned throughout the organization. Some guards monitor outgoing mail. Others watch file storage rooms. Others supervise meeting rooms and conversations. Additional guards protect employee laptops, while newer guards even monitor interactions with AI assistants such as Microsoft 365 Copilot. Rather than simply checking who enters the building, these security guards continuously monitor what information people are carrying and where that information is going. If confidential information is about to leave inappropriately, the guards intervene before any damage occurs. This mental model makes it much easier to understand how Microsoft Purview DLP protects data throughout Microsoft 365.EXCHANGE ONLINE DLPEmail remains one of the most common ways sensitive information leaves an organization. Microsoft Purview DLP integrates directly with Exchange Online to inspect outgoing emails before they are delivered. Every email body and attachment can be analyzed using advanced detection techniques, including:Credit card detectionNational identification numbersHealthcare informationFinancial recordsMachine learning... -
Microsoft Entra Private Access - Simply Explained 24.07.2026 13minWelcome to another episode of Knowledge Nuggets with Mirko Peters. Today we're exploring Microsoft Entra Internet Access, Microsoft's modern cloud-native approach to secure internet connectivity that replaces traditional VPNs with identity-driven Zero Trust security. For decades, organizations relied on VPNs to give remote employees access to corporate resources. That model worked when applications lived inside company data centers and employees worked primarily from the office. Today's reality is completely different. Employees work from home, coffee shops, hotels, and airports while applications are spread across Microsoft 365, SaaS platforms, and cloud services. The traditional idea of "connecting to the corporate network" no longer fits the modern workplace. Microsoft Entra Internet Access addresses this challenge by shifting security away from network trust and toward identity trust. Instead of giving users broad access simply because they're connected through a VPN, every internet request is evaluated based on the user's identity, device health, location, and security posture. In this episode, we'll explore how Entra Internet Access works, its role within Microsoft Global Secure Access, its integration with Conditional Access, and why it's becoming a key component of Microsoft's Zero Trust strategy.WHY TRADITIONAL VPNS ARE NO LONGER ENOUGHTraditional VPNs were designed for a world where applications, users, and data all existed within the corporate network. When employees connected remotely, the VPN simply extended the corporate network to their device. While this model worked for many years, it introduces significant problems in today's cloud-first world. Once connected, users often receive broad access to internal resources far beyond what they actually need. File servers, databases, legacy applications, and internal systems become reachable simply because the user is "inside" the network. VPNs also generate ongoing operational challenges. Connection failures, certificate issues, client updates, forgotten credentials, and performance problems generate a continuous stream of help desk tickets for IT departments. More importantly, VPNs generally trust the connection after authentication. Once users successfully authenticate, they're typically trusted throughout the session regardless of changing device health or security risks. Modern cybersecurity requires continuous verification rather than one-time authentication. This shift forms the foundation of Microsoft's Zero Trust security model.FROM NETWORK TRUST TO IDENTITY TRUSTModern security no longer focuses on protecting a network perimeter. Instead, it focuses on protecting identities. This philosophy is known as Zero Trust, built around one simple principle: Never trust. Always verify. Every request is evaluated independently using multiple security signals. Microsoft Entra ID becomes the central identity platform that continuously evaluates:User identityDevice complianceGeographic locationSign-in riskUser riskAuthentication strengthConditional Access policiesRather than assuming trust because someone is connected through a VPN, every request is evaluated in real time. Whether users connect from the corporate office, home, or public Wi-Fi becomes far less important than proving they are who they claim to be while using a trusted device. Identity replaces the network as the primary security boundary.WHAT IS MICROSOFT ENTRA INTERNET ACCESS?Microsoft Entra Internet Access is Microsoft's cloud-native Secure Web Gateway (SWG). Instead of routing traffic through traditional VPN appliances, internet traffic passes through Microsoft's Global Secure Access platform where it can be authenticated, inspected, filtered, and authorized. Every request is evaluated using identity-driven security policies before reaching its...
Popular în
Acest podcast apare și în topurile de podcasturi din aceste țări.