Sam: Hello and welcome to Let's Talk Azure podcast with your host Sam Foot. And I'm strong. If you're new here, we're a pair of Azure and Microsoft 365 focused IT security professionals. It's episode eight of season seven. Alan and I on this episode will dive into the new releases in March, April. Not March, April. Here are a few things that we covered. Key Microsoft Entra Intune Defender XDR features with updates and announcements. All the new changes and new features and retirements in Azure. We've noticed that a larger review aren't subscribed. If you do enjoy our podcast, please do consider subscribing. It would mean a lot to us for you to show your support to the show. It's going to be a really great episode. So let's get started. Hey Alan, how are you doing this week or this month? Should I Hey Sam, not doing too bad. You can, you can tell that we've only just found our, you know, our passwords to log back into. podcasting. Hey, I just saw that you ninja edited March to April. All right. Don't try and blame me on that one. I realize this. said it. That's brilliant. Yeah, we do have to start for an apology. I don't know what happened in March, ⁓ yeah, no April. March. I, ⁓ yeah, I'm a bit rusty. Yeah. April was a bit of a blur. think, I think we only did news in April, didn't we? So, ⁓ yeah, just a busy time, I think, ⁓ for both. So yeah, you had a new roof to your conservatory and stuff. You had a new roof as well. you as well? Wow. Yeah. You make it sound like the hat in the house roof. No, not as, not as mental as that. Yeah. No, it's been, ⁓ yeah, it's been pretty, I must admit it's been pretty busy for me over the last couple of months, to be fair. So. Yeah, that's my excuses out of the way. Anyway, any, any, um, cool updates for us, Alan? We have got a whole month to talk about. Uh, there's some, some interesting ones on that we're going to talk about later. Um, but, uh, submitted my MVP renewal. Let's see how that goes. Yeah. And it's like a month or two, I can't remember. It's like ended either beginning of June or. beginning of July. can't remember. Nice. Just the waiting game. Yeah. Yeah. That's the, ⁓ yeah, that's the, that's the thing, isn't it? You know, Yeah, I don't. ⁓ I don't really have much to really update on. I don't think ⁓ I've been using copilot's coworker. ⁓ yeah. So it's quite good. Quite interesting. Got it to change my put my app off us on when I'm with a customer for the full day and then take it off based on my calendar. That's pretty cool. Yeah. I did ask it to change my team's notification, but needed a graph permission to do it. So it said, you know, I need this and it even set even prep the email for me for my IT. I say, yeah, give, give, give access, please. This was interesting. ⁓ yeah, no, really good so far and building content and things like that seems really good. I found the other day. that's, mean, copilot, ⁓ ignoring sort of coworker stuff, but you can actually build a brand kit and you can put your guide in there and your fonts and everything. And you can do it centrally. then when you generate content, it uses that as the, can use it as the base. ⁓ that's really good. Yeah. Yeah. So yeah, right. Colors, maybe the templates or the documents kind of thing, but yeah. And also the way I think you can also say how the style of right, your writing and stuff like that as well. So just these little things that you don't know about, you know, because, you know, we don't want to say running it. we're using copilot and things like that, but we're not, ⁓ like diving into all the settings and stuff and what you can do because we're just, well, we're busy and we're doing security stuff. So doesn't really, we're not looking at that from that angle, but yeah, I, not in the same vein, but I have got, I haven't told you about this, but I've got open claw, ⁓ isolated in its own network on one of my VM hosts basically. And it is, ⁓ It is highly scary what it's actually capable of doing. Cause I listened to a podcast of its creator. ⁓ And yeah, it's really interesting why he created it and how he created it. And it's really weird because when you set it up, one of the configuration files is a sol.md, right? So it's like a prompt. you teach like, you know, your OpenClaw agent, like what its soul is basically, like it's a human essentially. And it's like, it's just sitting there waiting to be used. You know what mean? But it's just like completely isolated in its own like sandbox. So yeah, I am trying, I'm trying, yeah, I am trying loads of different stuff. did fire up, I did stick some money on like the Claude, like API console. But like, man, Claude models are so expensive to run compared to like, like, like peasant grok is only like, is like, I don't know, a 10th of the price basically of Claude. So, well, so yeah, I'm, it's, it's really good for coding. But, but yeah, I, I was talking to somebody about this at work yesterday, actually. It feels like a, like an arm race at the moment, arms race, do know what mean? And. and a discovery race, you know, because, you know, to your point, it's not until you really take some time to sit down with all of these like AI systems and models and agents that you really understand how powerful they can be with like a little bit of effort. you know what mean? ⁓ and I've been, ⁓ I, I've been sort of, I've, I've been, I've been, you know, I've been five coding because I, know, I used to be a developer. So. vibe coding to me is actually really quite powerful. And one thing that like the guy that created OpenClaw really suggests, because he uses seven, I think it was seven Claude subscriptions to vibe code with, because apparently there's a limit on direct Claude code, I believe. I don't know, I don't use it. I use GitHub Copilot, but I can get Claude via that. he was saying that ⁓ He's being interviewed and he's, you know, the guy was like, you know, do you not like get bored just writing prompts all day? Do you not mean not actually coding? Right. You know, he's like, I don't write. I just talk to them like they're people basically. Right. So, so I tried it the other day and, and actually it's really good because, know, you know, if you think about it, like you've got context, like you've got a chat window, you know, with your AI and you're talking to it. Right. You can just respond, ⁓ you know, like how, how you would in like natural language. And it kind of like works it out. I don't have it that it, it speaks to me, if that makes sense, like an actual, you know, like output, but in terms of me, like prompting it and asking it, you know, information. ⁓ cause I always used to think like sometimes I'd be like, it's just quicker for me to find it than to write the prompt. If that makes sense to find it sometimes. Right. But with voice, it's just. Yeah. It's just like the way to go. And it doesn't really matter if you don't get it exact. Do you know what mean? It's not like dictation, you know, from years ago where you have to like, kind of get everything exact. If you've got some like, ⁓ zinars and pauses in there and stuff like that, you know, the bottle just works it out. ⁓ yeah, so I that was really cool. So yeah, I might not make it to the next podcast because open call might have like escaped out of its prison and like taken over everything. But, yeah, I promise I won't, you know, publish it to the internet so I should be fine basically. No, but really cool. think, yeah, the change in AI and I think the demonstrable value is there now as well, right? These models are so like effective at what they do. They still need oversight. Like they're not, you know, they haven't taken our knowledge jobs yet, but it's only a matter of time, I think, but who knows? Who knows? ⁓ I got a LinkedIn spam email the other day going, recruiters are searching for these key skills and it was AI foundry and Copilot Studio, stuff like that. Even LinkedIn were on it telling me, by the way, you should probably get some AI foundry certs. It's coming. I'm probably here to stay. Yes. Right. Alan, do you want to kick us off with, yeah, so we're going to do news. Sorry, we haven't really introduced it. So for people that are new here, we do the news every month for the previous month's news. We are, I'm going to call it a week late for this, set of news. So yeah, typically the first episode of each month will be the previous month's news. So yeah, as we're recording this, it's around mid May at the moment. So we're going to cover April and then. ⁓ I might promise you that we'll do it the first week of June for May. So yeah, Alan, do you want to kick us off? Yeah, sure. Okay. So I normally cover the Defender products, Entra, a few things like that. So let's go in. So, if we talk about Defender XTR itself, so that's May, so we'll go ahead of ourselves. So in April in preview, you can now view the current status of automatic disruption and predictive shielding actions related to a specific incident. It's now under the activities. You can see those actions taking place. So that's good to be able to see that. ⁓ It's now GA for the built in alert tuning rules. So there's a section in the XDR portal now that allows you where you commonly get benign, defensive for endpoint or defensive for office, can now, in effect, get the automatic investigation response to kind of, yeah, just tune it to say, you know, these are always benign, et cetera. So reduce noise. So that's good. Moving on Defender for Office 365 didn't get any updates in April. We move on again. What's this? So the unified SecOps didn't get any updates. The last one was February. ⁓ Defender for endpoint. Okay, so I had to double check this because March had a similar thing. But in April, there's some new secure score recommendations. One of them is ensure devices are updated to secure boot 2023 certs and boot manager as being one of them. So that's the latest issue in June. Well, next month, the the expired this the safe boot certs expire. So you have to make sure you get it updated. I was looking at this actually and there's there's a blog around it. But also within Intune now with Windows, you can get it to automatically update if you want to by a couple of policies, which I thought was good. So I think I seen some commands you had to run previously, but I think you can actually say, yeah, updates a kill boot. Yeah, that's good. Yeah. Yeah. So definitely check that out and check that recommendation and see if you've got any issues. Cause you only got a month to sort it out. Sorry. Where's that recommendation again? In secure score. Nice. Okay. ⁓ check. So they in preview, in effect, defender XTR, well, defender for endpoint, sorry, has that same thing about the automatic this attack disruption and predict predictive shielding actions being available in the instance. So just reiterating that for that. So that's that's a stuff in front point. Defender for identity. So In preview, you've got identity explorer. So the identity page now includes identity explorer tab, prior customers with Microsoft Sentinel data lake. It allows for advanced hunting, visualized identity attack paths and exposure scenarios as interactive graphs. That seems pretty interesting. ⁓ You've also now got custom account correlation rules. So if they, if you have a naming convention or a prefix or suffix, um, for various things, you can actually specify it. They are things like, uh, this isn't this, but I'll talk about this anyway, but service accounts. So you can say, you know, a social council always starts with S V C underscore as an example. Um, but this is, um, this is around being able to correlate the same identities for a user. say like you have. A standard user account and then admin account and the only differences is they got admin at the end or they start with ADM and then the username is the same. You can specify that to say it's the same user, just that there's the elevated identity. So instead of having it looking as two individual users, it just shows them as one, which I think is good. So you can see the attack path potential there for that user. The automatic Windows event auditing configuration for sensor version three for Defender for Identity is now generally available. So this is where you can in effect slide a toggle and save it. And then it will do your configuration locally on your domain controllers for all of your auditing requirements. So it can be really quick to be able to roll that out. In most cases that will probably work very well. I think it's just thinking about things like if you've already got group policy in place where there's going to be conflicts there. Just consider that or within your organization, you might want to build it into your core, your group policy, et cetera, and then roll it out. So yeah, that is identity. Defender of cloud apps didn't have any updates. Microsoft Sentinel. So there is a call to action update automations by the 1st of July, 2026 account name is now consistently the UPN prefix for analytic rule alerts. So Microsoft Center is updating how the account entity account name value is populated for analytic rules with the full UPN when, sorry, when the full UPN is mapped into the, into the account name. This change improves consistency from downstream automation rules and logic at playbooks. So when the full name or the full UPN is user at domain.com, it's mapped, it's mapped into the account name. The account name will always be the prefix, only the user bit. So it removes the domain in effect from it for you. That's cool. Microsoft Sentinel Data Federation in preview powered by Microsoft Fabric. Microsoft Sentinel Data Federation lets you analyze security data when it's already where it already lives without copying or duplicating it. You can federate data from the from Microsoft Fabric Azure Data Lake storage and Databricks into Microsoft Sentinel Data Lake. When the familiar Then use the familiar Microsoft Center experience, KQL, notebooks, custom graphs across both federate and native data. So again, another way to get data into Sentinel slash XDR ball. ⁓ In preview building custom graphs, so build tailored security graphs across the Sentinel data lake and third party data to uncover attack paths, blast radius and hidden relationships. These graphs also serve as foundations for advanced investigations and AI agents. So that's ⁓ good as well. Moving on into Microsoft Herview. ⁓ ⁓ collection policies in preview collection policy support sensitive label as a condition for scoping detections to items with specific sensitivity labels applied. This condition is supported with browser and network cloud app detections. ⁓ in under data loss prevention, ⁓ we've got, ⁓ re, they've been updating some of the documentation around just in time protections. there is a preview for unsaved file protection, which extends into just in time protection. So for files that haven't been saved yet, including brand new files and files with unsaved modifications. So I think that's quite interesting as well. Being able to see if someone attempts to print or tries to modify that data. I guess if they're copying and pasting into things like that. Yeah, that's interesting actually, isn't it? Yeah. So not even so it's not even, you know, endpoint DLP in effect, not just waiting for the file to be saved. It's actually scanning live. As you're sort of building it, I guess. I like it. It's good. Yeah. ⁓ DLP for unmanaged cloud app supports for a new URL contains text condition that detects when the URL of the cloud app contains specific texturing. You can use it as a condition to scope DLP rules to specific URLs or as an exception to exclude specific URLs for policy enforcement. Well, that sounds interesting as well. Be able to do that. ⁓ a key one in preview, ⁓ data loss prevention, policy tips reference, ⁓ for outlook for iOS, Android and Mac OS. A reference article covering DLP policy tips, support conditions, oversharing dialogue and override capabilities for outlook and Android iOS and Mac. Outlook on iOS, Android, iOS and Mac. I get my words right. So that's interesting. Um, so it's telling you in effect that, I mean, that is just what I say a reference article, but actually I quit, did have a look on it and it's just going through, um, how you enable it in the admin center to be able to, to, for the apps to get it from the, um, Android and non windows basically. So that's definitely a key thing I need to go and test out because, uh, you know, potential has been a gap for a long time. ⁓ I that is it for that. Moving on into Entra. So, ⁓ Public Preview Account Discovery. Microsoft Entry ID governance now supports account discovery for connected applications public preview. This capability provides administrators with visibility into all accounts that exist within a connected application, including orphan accounts. By generating discovery reports direct from the provisioning experience, organizations can identify counts in connected applications that are not assigned to the Enterprise app in Entra and simplify onboarding the application. That sounds interesting itself. That's only when you've got provisioning on to a SAS application. ⁓ But interesting nonetheless. Now this seems like a big change, upcoming change. Migrate from Microsoft Entra Connect Sync to Microsoft Entra Cloud Sync. As organizations look to strengthen identity security above the zero trust strategy and to look to make things simpler, more reliable with their managed entities. the shift is a key. So that Microsoft looks like they're starting to in effect push towards going to the cloud sync. They must be saying that everything is pretty much covered now from a parity perspective, which you need to validate. Beginning in July 2026, Microsoft will begin to notify customers through the Microsoft 365 admin center, Entry Connect Health and targeted emails about their individual transition timelines. The decision will be rolled out in phases and will be reached out directly to each organization on their assigned transition window begins. This phased approach ensuring that we can provide tailored guidance and support for all customers. Initial phase is in the first wave we'll focus on tents with for whole CloudSync Connect already meets all their identity synchronization needs. If your organization relies on advanced features or has a large directory, you will not be amongst the initial targeted groups. We'll prioritize every only transitions for customers with the straightforward configuration that are fully supported by the Cloud, Intra CloudSync. Capacity and then subsequent phases As entry sync capability expands we will progressively notify the The later groups and ensure they can transition successfully once this all the support is available. Okay So yeah, they're in effect trying to get you to move over You know, if you've got everything if cloud sync can do everything for you. So that's quite good Because the new the new the cloud sync is definitely a lot like more lightweight and easy to manage. Yeah. The big thing was devices though, wasn't it? Yes. Device sync or the hybrid join. Yeah. I can't see. Yeah, the only thing is it might be that whole last month's hybrid join straight from 2025 thing we found. I think that was implying that you didn't have to sync the identity because it all did it basically fire a call, but yeah. So we'll see. It's interesting that there's now a push to get everyone off of Entra Connect sync. Well, I suppose there is feature parity difference, but it doesn't really make sense for Microsoft to have to support two different solutions to kind of the same problem. Yeah. the problem, well, not the problem, but the... Entra connect sync is a service that runs on prem. It's not a, it's not an agent or a client, you know, an agent that sits and gets commands from the cloud. Yeah. That makes sense. Yeah. It is something that needs updating can go wrong. You need two of them in theory and, know, inactive and standby kind of thing to make sure the sinks. Okay. Where with the cloud sync, you can have a couple of agents, you know, around and they're lightweight. they update themselves, it's frictionless almost for management and that. here. checking what else is in here. I don't know how, there seems to be loads of different changes. So generally available slightly on topic, off topic, Microsoft Identity Manager, 2026 Service Pack 3 is now generally available. So the MEMS service is getting upgrades. ⁓ there is one here for January available for Microsoft Entra certificate based authentication, CBA support on iOS and CBA as second factor. So interesting. So trying to move away another method of going away from passwords. ⁓ but yeah, finally still enter related, but Let's go to what close her access and the windows client. ⁓ there was an update in April, function functional changes. So the sign up button shows by default. they've made a lot of things about signing out and signing in. It's like four, four items there about signing outside and various different things. I'm not going to go through though. It's pretty much same thing. Traffic logs in the entry admin center include the device join type. Cross tenant access type and home tenant ID. Enhancements to the intelligent local access support for the ability to assign a private application to multiple private networks. Enhancements to the intelligent local access add private network section to the forwarding profile tab in the advanced dialog sense. There's a few bug changes, things like that in there. So. So that's me, I think. A few in there that are interesting. Okay, nice. Right. Yeah, so I generally cover, sorry, Azure updates, ⁓ not just on the security side, but also platform bits that I find interesting. ⁓ And I also do Defender for Cloud. So yeah, I'll start with Defender for Cloud. So only, I suppose the biggest one for me, I think is really the anti-malware detection and blocking is now generally available. That came in at the end of April. So this is for Defender for containers for Azure Kubernetes Service, Amazon Elastic Kubernetes Service and Google Kubernetes Engine. So this is really looking at runtime. ⁓ malware evaluation when a container runs. And if it finds an executable that the system identifies as malicious software, you set the conditions for alerting or blocking to decide how it should respond, essentially. There's a load of other specific ⁓ updates to Kubernetes, but I'm not going to go into them because ⁓ they're quite specific. So actually, I know it sounds pretty bad, but that's the only update that I think I actually want to take us through on the Defender for Cloud side. Sorry. Yeah. Everything else is pretty ⁓ niche and specific. on the Azure side, ⁓ good news. You know, something that we absolutely love is, you know, made its way back. Azure Data Box. now supports ingestion of data into Azure Files provisioned version two storage accounts. So Azure Files provisioned v2, I very recently set this up and it's actually quite cool. You provision and pay specifically for your capacity IOPS and throughputs values independently. It's actually quite nice to be able to tune it specifically. So yeah, if you are migrating a file share to into Azure, yeah, definitely check it out. Check it out. But with Azure Data Box now, and it's generally available, you can get a ⁓ box sent to you that you can fill up and then ⁓ freight back, you know, as long as you've got a forklift truck and then you can transfer data directly into Azure files. So yeah, and it works across most public regions. So yeah, check it out. It's been a while since we talked about an ⁓ Azure data box update, but wait, there's more. Azure Data Box now enhances compliance with automatic secure erasure certificates. Is that right? Erasure? Yeah, it's erasure. Yeah. So basically for every completed order, it now automatically generates a downloadable erasure certificate. So it provides verification that all data on the device has been securely erased in accordance with NIST. 800-88 revision two standards. So the certificate is created as part of the standard cleanup process and is available, is accessible directly from the Azure portal. So yeah, you can follow that in your audit log as you need. ⁓ Now in public preview, you can unlock client-side configuration at scale with Azure App Configuration and Azure Front Door. What this allows you to do is it allows you to deliver dynamic configuration directly into client-side applications via a securely via a CDN at scale. So what this really allows you to do is it allows you to change feature flags, settings, updates, you know, which would then trigger updates to flows in the app and, you know, changes to mobile apps in real time. And this is good for if you've got things like single page applications, mobile and desktop apps, JavaScript powers, you know, UI components and it's JavaScript. So any browser based application that can run, you know, JavaScript. Yeah. So have a look at. that because yeah, that can be a really complex thing to send configuration changes. Azure app configuration has really been around server-side applications previously, but this is really cool going down to the actual end client. I'd love to see this in action. ⁓ What is going to be my next one? ⁓ yes, talking of AI, Azure Functions now supports MCP or Model Context Protocol. Got it. Resource triggers. So you can enable developers to expose resources directly from Azure Functions. from an Azure Functions hosted model context protocol ⁓ server. So you can return either static or dynamic files, application metadata, ⁓ HTML-based widgets. So yeah, check that out if you want resource triggers directly hosted in Azure Functions. There's absolutely loads of updates to Azure in April. There's been some enhancements to the maintenance notifications in Azure Service Health. So they've got some consolidated maintenance notifications for Azure Database for Postgres. you get, know, instead of getting one notification per server, you now receive a single notification per region that consolidates maintenance details for all of your Postgres servers across subscriptions. So yeah, I assume at scale that could be quite noisy, depending on how many instances you've got active. So yeah, okay. I've never come across that, but I can kind of see why ⁓ you would want that. ⁓ Right, let's keep... going. Sorry, I'm just going through the list actually. Oh yeah, now generally available Azure Monitor Pipeline. So I think we talked about this. It feels like last episode, but it might have been the previous episode to that. what it does is it gives you, it's a control system for telemetry and gestion. So it's designed to... help you to transform your ⁓ data as it comes into Azure Monitor. I think we talked about this previously, but it's essentially the ability to ⁓ filter and format and transform logs as it hits into Azure Monitor. Have a look and see if it's something ⁓ that you want to use and it is now generally available. What else? Now, generally available with dynamic data masking with Azure Cosmos DB. So it allows you to, yeah, to, as it sort of says, dynamically mask data on the server side via policies to make sure that you protect sensitive data from unauthorized access. So it will dynamically mask data for non-privileged users. ensuring that sensitive information is redacted in real time before being presented to applications while the original data is unchanged inside the actual database itself. So yeah, that's pretty cool. And that's supported on Cosmos DB. Because that's been part of SQL Server for, yeah, long time, I believe. ⁓ Yeah, now in public preview on the AI train is hosted agents in Foundry agent service. So hosted agents can run in an isolated execution sandbox. It sounds like my dev server. This provides a dedicated secure runtime per agent session. Sessions start with a clean environment with no shared state between sessions, no cross-section data leakage and strong compute boundaries between tenants. So yeah, if you want a completely isolated environment for your hosted agents. Yeah, take a look at that in Foundry Agents Service. Yeah. coming to the end of the month now. Um, yeah, actually I should say there was a lot actually, but there's a lot of stuff that no offense. I'm not that interested in. Um, got to remember build is the end of, it's beginning of June, isn't it? There's just, there's loads of like little updates. Do you know what I mean? There's like, it's not really. Yeah. ⁓ Yeah, no, I think I'm going to leave it there actually because everything else is. ⁓ wait, actually I can't do that because that's May. Yeah, I'm going to go with that actually. Yeah, I think that's that's my updates. Unfortunately, yeah, not. There has been a lot more than that, so I apologize to everybody that Microsoft that poured their heart and soul into the updates into ⁓ into into Azure. It's just yeah, there's a lot of. ⁓ actually, no, I just did miss completely one big one, actually. Now generally available. Azure NetApp Files now has advanced ransomware protection. It's now generally available. Again, I think we did look at this ⁓ previously. But it scans Azure NetApp Files volumes for suspicious activity using file extension profiling. Ends with dot lol. ⁓ entropy and IOPS patterns. When a threat is detected, the system creates a point in time snapshot enabling rapid evaluation and recovery. Notifications are sent via your activity log and attack reports retained for 30 days. There is no specific additional charge for the acronym is ANF ARP, which kind of makes sense as your NetApp files advance ransomware protection. So there is no specific additional charge for ANF ARP. But you need to look at the consideration sections when sizing your deployment to accommodate ANF ARP. And that's me, I think, for this month. Or last month. But yeah. That's cool. Yeah, it's definitely been a few things, isn't there, between us? Yeah. No, yeah, I think so. And like I said, there's been, I don't know how many updates, there's been absolutely loads. ⁓ Yeah. Yeah, definitely. Yeah. And you've got build as well. Like I said, you got build end of the month. True. Yeah. So it's probably this month's news where we're going to start hearing a load of things come out that are announced at that. So, yeah. Yeah, definitely. Cool. Okay. Did you enjoy this episode? If so, please do consider leaving us a review on Apple Spotify or YouTube. This really helps us reach out to more people like yourselves. If you do have any specific feedback or suggestions, we have a link in our show notes to get in contact with us. Yeah. And if you've made it this far, thanks ever so much for listening. We'll catch you on the next one. Yep. Thanks a lot.