Sam: Hello and welcome to the Let's Talk Azure podcast with your host Sam Foote. And Anne Armstrong. If you're new here, we're a pair of Azure and Microsoft 365 focused IT security professionals. It's episode nine of season seven. In this episode, Alan and I will dive into the new releases in May. Here are a few things that we're going to cover. So we'll go through the key Microsoft Entra, Intune, and Defender XDR features, any updates and new announcements. We're also gonna cover any Azure changes, Defender for Cloud, ⁓ and also any retirements in that space as well. We've noticed that a large number of you aren't subscribed, so if you do enjoy our podcast, please do consider subscribing. It would mean a lot to us for you to show your support to the show. It's gonna be a really great episode, so let's get started. Hey Alan, how are you this week? Hey Sam, not doing too bad. How are you? Yeah, not bad. I should have said how are you this month, actually, because we ⁓ we just about found our ⁓ our our passwords again, didn't we, to get on for this for this podcast. Yeah. We've been had some leave and stuff, haven't we? Came come back yesterday. Yeah, Alan's been swallowing it on holiday, haven't you, Alan? So ⁓ yeah. And we we had like a mini heat wave, didn't we, in the UK. So we got distracted by other things, shall we say. ⁓ Yeah. Any any Any big updates from you over the last month? ⁓ you know, ⁓ bar the news that we're gonna go through, but anything that's sort of jumped out at you? Microsoft build is happening at the moment, isn't it? This week. Yes, I know that from the the amount of news that we're gonna have next month. Yes. Yeah. No, exciting times. Yeah, we ⁓ I I do build in ign Ignite ⁓ To really good, you know, build from I would say more from well, I I call it like the engineering side, but the engineering for clients, if that makes sense on that side. But ⁓ but yeah, always some really cool updates, you know, f from from build as well as ignite. So yeah. I don't really I I don't really have too much to to really update on, I don't think. Has anything exciting happened over the past month? ⁓ co-worker came out, didn't it? ⁓ yes. Yeah. Been using that. That's ⁓ definitely interesting. And obviously there's a new one that's come out of build now, isn't there? Scout looks like an interesting thing as well. Yeah, somebody was saying it's like ⁓ Microsoft's open claw equivalent, isn't it, Scout? That's ⁓ Yeah. Like a hyper I'll call it like a hyper agent basically. That's yeah. ⁓ so that'd be cool to see. I haven't seen anything more than that, ⁓ about it though. No, I did install it earlier today, but Yeah. Other stuff with it, like ⁓ copilot GitHub copilot business or enterprise license. Ooh, okay. So that's that ⁓ Got it installed and I gotta get it activated. It's like, ⁓ you need this as well. I I do have I do have like OpenClaw running on a like VM on its own separate like isolated VLAN but it's it's not got any network connectivity. And I I I kind of I got it installed and everything, ⁓ 'cause I listened to Lex Friedman's ⁓ podcast with the creator of OpenClaw because I do think it's got like a bit of a like a bad rep. Do you know what I mean? Like as in I think it was ⁓ y you know, so I wanted to understand like you know, why the guy that built it built it and, you know, what he uses it for and stuff like that. But ⁓ so yeah, I've I I created it, I I got it all up and running and everything, and then I've just kind of like abandoned it, but in its own like its own VLAN because I don't like dare I I I do dare, but I just yeah it's just gonna go back in there and it's gonna be like Rock in corner or something. She's Yeah, exactly. Why did you leave me? Why did you leave me? You said you would just be two minutes. no, but ⁓ it's funny because ⁓ it gets like it it did get a built real real bad rep for people like, you know, publicly exposing it and stuff like that. And and when you when you install it, the amount of warnings that you get about what it's gonna do, like every every single step, it's like, we're gonna do this, do not do this, and we're gonna do this. Do not do this. Please, please, please, do not do this, basically. So ⁓ but it's ⁓ but the way that like they get you to describe like, you know, how it's gonna act is you give it like a soul and it's just a markdown file that's called soul dot md. And I like at that point I was like, I've gotta just disconnect now because like this is too this is like too much for me. ⁓ basically now. So ⁓ but no, ⁓ I okay, it's this is kind of bad news, but it it was it was kind of coming that ⁓ I don't know if you heard but Microsoft changed the GitHub co-pilot billing model ⁓ for Claude. ⁓ so I'm probably the reason why this happened, b basically, because for the last for the last six months or so I've been maxing my GitHub co pilot ⁓ what was it called? It wasn't ⁓ it was n the number of premium requests or premium chats, I think they called it before, wasn't it? ⁓ but I worked this out quite a long time ago actually because like I was I was like vibe coding a lot of stuff and ⁓ and and I don't know if you I I don't know if you use it day to day, but well the way you could do it before is you could pick your model. So what is it? It's Claude, Opus, and Sonnet, isn't it? The la the the next ⁓ the their current like latest iterations, right? But s I think it was Sonnet was like one times like usage. Do you know what I mean? So for every one request, one one chat would cost one chat, basically. But ⁓ Opus would cost three chats per one chat, right? But the chats lasted forever, basically. And the context window was huge. So you could just be like, right, so I'm thinking about building this feature. And then you would just keep You could just keep AI in that, you know, in that ch ⁓ chain of context. You could even archive it and, you know, move forward with it. Do you know what I mean? And it could persist, essentially. And you would never like up your ⁓ things. And and and so I haven't I okay, so since they made the pricing change, I haven't tested it, right? But I've seen people saying that some of their singular chats and even prompts are costing like ten dollars worth of credits basically now. So I dread to think ⁓ what it was costing Microsoft before because ⁓ I could never make clo clo clawed code or clawed what do they call it chat or is it API work 'cause it's so expensive compared, right? So yeah, sorry, go on. Yeah. I've I've seen a GIF where there's different types of weapons were say. I mean like you know, like a ⁓ machine gunner, missile launcher or whatever it might be. Yeah. And they're just it's just ⁓ underneath it they've got the model and they're going, you know, chat GPT five point five Cortex or whatever it is and bang, you know, it's cost you, you know, a thousand dollars. And then, you know, there's a l another one where it's like a machine gun, it's just like bang bang bang, you ten dollars, twenty dollars, thirty dollars, and then another one is like I don't know, I think it was might have been one of the clawed ones and it's just like bang four and a half grand. Like Yeah. And and and and and I only pay for like the I think it's ten dollars a month for like ⁓ co pilot. I don't know what it is, but what level it is, right? But I pay for the cheapest one. And what you could basically do is if you if you paid for the pro or whatever the next sorry, I don't know the next tier, whatever the next tier is, you got four thousand requests per month. basically. And I'm not joking, the amount of code that you could like get it to generate, like and good code that you could get it to generate in a single request was like nuts before. But they've kind of pooped on it a bit because now ⁓ yeah it's all it's all now gonna be, you know, tokens in, tokens out, build against, you know, and you're you're essentially going to get like ten dollars worth of credits or whatever, you know, whatever you pay. Which I suppose is fair. But the most annoying thing is I can't select Opus anymore. I can only select Sonnet. So I can't use you have to be on the next tier up to even use the next premium model of tier, which which leads me to believe that they are still subsidizing the use of it, if that makes sense. Because why would you why would you limit me like in terms of nuking my own credit? Do you know what I mean? Or maybe they just thought that I'm gonna get through my credit so quickly. Like I'm gonna ask it like two questions and then I'm gonna get absolutely nuked. So ⁓ so yeah, so that was a bit of a bummer. ⁓ but I suppose I kind of had it coming because yeah, it was far too generous for quite a long time actually, to to be fair. So ⁓ but yeah. Yeah, no I mean the new copilot or co pilot aid the new copilot app today. ⁓ intrigued me a little bit. Does intrigue a word? I don't know. Maybe it is a word but where it's the right context. But I was talking to a colleague of mine about something and I just used ⁓ co-pilot to ask it a question about whether something could do something in a certain way in this context sort of thing and it started like give me a response back going, well based on your conversation with X and that the issues that you're having This is, you know, this is how you would get around it. It so it brought the context from my Teams chat straight away. Yeah. Which was like you know, without me asking it because I was generally just asking like an a a web search in effect at that point. Yeah. But using Copilot, but it actually brought in the other context. And it's never really done that before. Well not without me saying, you know, something, you know, relating to the current conversations I've been having or something, if that makes sense. Yeah, like prompting it to go and find that. Yeah, or yeah, based on the chat I had with X, you know, can you help me work out what the answer might be or XYZ it I didn't even ask that. So So yeah. It's inter interesting. Yeah. No ⁓ AI over the definitely yeah. And the fact I literally just had that chat as well. It's not like it's been sat there for like half an hour or anything like that. It was literally like I finished my conversation with him and then did a quick search. Yeah, exactly. It was near real time almost. It's just constantly it's just constantly building that index, isn't it? It's not all that model or semantic index, right? It's just it's doing it constantly. So Yeah, no, it's really cool. ⁓ Yeah, all right. Al do you wanna yeah, what what are we gonna what are we gonna talk about? Do you wanna kick us off ⁓ news, you know, ⁓ for May? Yeah, sure. So away from AI. Well Well sure how long AI, I say. Twelve minutes of of talking about AI. ⁓ let's talk around ⁓ Defender product intra and in tune and purview. ⁓ So if we look at ch the general Defender XDR ⁓ for this month in May, let's just make sure. Yeah, that's right. Defender Experts, the Microsoft sort of service or the managed service on top of that you can buy on top of Defender XDR, ⁓ has now got a new subcategorice called Defender Experts for Servers. ⁓ I was gonna talk about this. Okay, I suppose it kind of ties into it's plastered everywhere, yeah. So we might as well talk about it now. Yeah. Okay. ⁓ yeah, new offering to for customers wish to you know ⁓ have a managed extension detect and response for s servers for on prem multi-cloud services. Yeah. interesting. So expanding that service is good. ⁓ what what is it they cover at the moment? Well to be f fair, it's just called Defender Microsoft Defender Experts, isn't it, f in the XDR pool. So it was just generally everything in XDR. So it I to be fair, I thought sales were probably covered under it. But I'm guessing not. I'm guessing it's now looking at more of the vulnerability side of things. And some of the other config from Defender for Cloud, maybe. Rather than just being Defender for endpoint capability, if that makes sense. Yeah, whilst whilst we're here, let me look 'cause I did it was in the Azure updates. ⁓ let me just see if they added added any extra context. I can't. ⁓ that's typical, isn't it? There. I didn't actually click on the button to to to load it. I'll give you two seconds, I'll just gonna see. ⁓ Separy Sold Focus on instances that matter. ⁓ magic responses your way, access experts when you need it, and stay ahead of emerging threats. It's the kind of thing they're suggesting that service provides. You need a defender for serve plan one or plan two. And then try DP two. Right, okay. Yeah, interesting. ⁓ managed detective response, advanced proactive threat hunting, ask the experts, live dashboard ⁓ dashboard and reporting, third party network signal enrichment. Network signal enrichment. Third party network signal enrichment. Interesting. From Palos Fortignet Z Scalar. The game more comprehensive view of the attack pads. Yeah, so the those experts aren't just Microsoft experts anymore, are they? yes and no. It might be that gets standardized as it comes in. ⁓ yeah, yeah. I'm just yeah, I'm just I sort of made the point that they're they're ⁓ branching out, yeah. They're branching out, you know, which it kinda makes sense for them to do, right? You know. Yeah, and it's ⁓ obvious well, not obviously, but it is also covering Azure, AWS and G C P Providing that defender frame point is installed on the service. Yeah, okay. Yeah. Yeah, 'cause well, that's the thing with any sort of managed service, it's it's it's ultimately about what you can ingest, right? And what you can cover. That's what organizations are looking for, right? So you know. Yeah, and DNS alerts are excluded from coverage due to limited data availability for investigation. Until that's built. Until it's built. Yeah, exactly. Nice. ⁓ yeah. That's cool. Cool. Or is it I don't know. Yeah, it's cool. Yeah, sold s it's a separate license on top, so another module on top of the Defender Experts bit, so you don't have to have the whole service, you could just have it for servers. ⁓ yeah. True. Yeah. ⁓ Moving on, in preview, ⁓ automatic attack disruption can now isolate compromised devices from the network with high confidence incidence. Analysis indicates that the device is being used by an active foothold. So I think that is good. Automatic isol device isolation. From that side. Yeah, yeah, definitely. Yeah. We like device isolation, don't we, Alan? Yes. Yep. I mean there's that's obviously based on a real attack taking place. There may be other reason why you might want to build some automation to do ⁓ automatic isolation. And w who should they email our if they wes. in advance hunting. Take action wizard now lets customers allow or block top level domains and file attachment hashes in emails based on query results. ⁓ the hunting graph in advanced hunting now includes new identity focused predefined scenarios. These scenarios help you discover attack paths, privileged escalation routes, and credential access risks across on-premise and cloud environments, including curb curb roasting curb roasting is sorry, ⁓ and AS rep ⁓ roast paths. Domain compromise routes, OAuth. application risk and external user access to cloud resources. Nice. ⁓ Defender Chat Experience in Preview is an open prompt chat ⁓ assistant built into Defend in Microsoft. It helps SOC analysts investigate threats, explore in incidents, and answer security questions in plain language without the need to navigate to multiple screens or write con complex queries. So sorry, so that is Wha what's that? Is that separate? So that's moving the sta that's almost moving the standalone security copilot prompts into Defender Chat. So you've got it with you in the same pool to ask questions about an incident things like that. ⁓ sorry, okay. So you ⁓ so this does require security copilot, yeah? I would assume so, yeah. Okay. It was called something else for a minute there, do you know what I mean? So Microsoft Security Copart integration with Defender, yeah, yeah, it is. ⁓ it is, okay, cool. Defender chat experience is what it's called. Yeah, yeah, yeah. You just but w when you said it it was like it's Defender Chat Experience. I was like, what that sounds like a new SKU, a new license. But it's not. It's it's okay, that's cool. No, that's all right. Yeah, it's just moving it in so you don't have to move to another page and ask a question kind of thing. ⁓ yeah, because you only you have you still only got in security copart, have you still only got like kind of predefined responses back? In the inner Yeah, copilot and defender embedded skills is the one, isn't it? Where you can say, Yeah, yeah, check this, ⁓ investigate this ⁓ tell me ⁓ script, ⁓ tell me what the script does, that kind of thing. Script analysis, I say, isn't it? And a few other bits. So yeah. Yeah. Cool, so that is it I say that's it, but that is it for the Defender XDR portal generally. Unified Secure Operations hasn't had any updates since February, which is okay because it's every you know it's doing all the other bits as well. ⁓ Office 365 had nothing in May. It was April was the last sort of updates, which again is okay. ⁓ May for Defender for ⁓ points. Ooh, it's quite a in here, let's have a quick look. ⁓ defend endpoint security solution, Windows seven SP one and Windows seven two thousand eight R two SP one. Is now generally available. ⁓ so backwards compatibility all the way back to Windows seven. Wow. Defender A V? Yeah, it looks like it's most of the rich detection events attacked It looks like it's got a ⁓ No, I don't know. Let's Yeah. It's saying it's got attack disruption. To contain device slash IP, automatically disrupt the device. Rich detection, policy enforcement. Vulnerabilities. Next gen A V. Ooh. Advanced hunting stuff, yeah. Nice. Yeah. So when you ⁓ need to have a Windows seven and server two thousand eight R two in those in those Needs a Star Word, Alan, isn't it? Wow. There is that, but Yeah there are I suppose there are some requirements. We do see, you know, ⁓ the ATM space. Exactly what's And and displays and screens and whatever. When you're running your McDonald's, yeah, whatever. Yeah, can now have Defender. I'm only joking, I'm only joking. ⁓ yeah, didn't know about that one. I I knew they were looking to do it, but I didn't know it was G A. Yeah. Exactly, yeah. ⁓ not that I've seen a lot of it, but yeah, it's good to see it. in preview, enhanced exposure score in defender vulnerability management. ⁓ a news new model in defender volume management now available in preview. Improves risk prioritization and recommendations. Recommendation impact accuracy by incorporating exploit prediction data, EPSS, and asset context factors such as internet facing status and criticality. Okay. That sounds pretty cool. ⁓ preview schedule A V scans on Linux. says what it does on the tin. ⁓ attack structure. Welcome to nineteen ninety six. Yeah. Well is on Linux, you know, A V on Linux. Yeah, yeah. Yeah, that's true. Yeah. Welcome to 2026. ⁓ automatic device isolation we talked about. Custom data collection is now G A. So you can expand your telemetry collection data from the Devoc configuration with rule based filtering. That's quite cool as well. ⁓ configure offline security updates for Linux from the Defender portals. You can now configure offline security intelligence update settings for Linux directly from Defender. So if you've got a local file share with all the updates for Linux, you can now specify where it needs to go and get it from. That's cool. So let's just bring parity to Linux, it seems to be now. ⁓ a feature in preview, selective response action. ⁓ to tailor high impact security operations on devices during onboarding. ⁓ okay, so this is that if you didn't want to be able to ⁓ provides precise control over how response actions are applied to tier zero systems like domain controls, things like that, and other high volume assets helping to maintain operational stability where delivering strong protection. AKA ⁓ stops all from doing device isolation on a domain controller potentially. ⁓ so that's in preview. And that's it for May. ⁓ there are some June things, but anyway just skip past those for a minute. Till next month. ⁓ moving on. ⁓ defend for identity. ⁓ sensor sorry sensor version three, ⁓ the one that's baked into Defender for Endpoint supports all identity roles on domain controllers. Defender Identity Sensor 3 now supports domain controllers running all identity roles, including enter connect, ADFS, AD Connect ⁓ ADCS, identity roles. ⁓ so okay, so it's covering everything now. That is good. Increased sensor capacity, Defender for Identity now supports up to a thousand sensors per workspace. Wow. Increase from the previous limit of three hundred and fifty to add more than one thousand contact defender for identity support. Those those poor souls that needed that. Those poor souls. I salute you. A thousand censors. ⁓ my days. Mind you, that could be ADFS servers, it could be, you know, ADSS ADFS farms, could be certificate services farms, that kind of thing. Could be I suppose those that may be pushing it. I mean DC is probably your main thing, isn't it? But Yeah, that's insane. One to one DC to user ratio in some environments. Sorry, yeah, go on. ⁓ Well, I've I've I've worked with universities and they have some beefy domain controls when they're authenticating their Wi Fi as an example. Yeah. ⁓ they probably sort of split it out a little bit, but they only have like one or two just to do the whole Wi Fi and you're thinking. And they're like virtual ⁓ you know, Hyper V host like specs as a domain controller. Don't you want to spread this a little? No? Okay. ⁓ anyway, ⁓ new defender for identity security alerts. I guess So bear in mind that Defender for Identity isn't really just on prem AD anymore. So new alerts related to entry ID, guest user account promoted to member. User was created and assigned a global admin role. Failed credential abuse attempted in enter ID authentication Malicious sign in from a randomized user agent possible use of stolen session cookie stolen session cookie replay detected suspected conditional access bypass via non compliant device additional suspicious addition of default third part MFA method to user account. So yeah, they seem some of those seem quite interesting. ⁓ there's a known limit limitation. Migration of domain controls with Windows Server twenty twenty five from sensor two to three is not supported. ⁓ continue to use two ⁓ because domain control 26 is currently not supported of version three yet does that make sense at the moment okay moving on to cloud apps ⁓ yeah there is one in it disable informational alerts for unsanctioned app access you can now disable informational alerts generated when users access unsanctioned apps A new generated alert for blocked app access toggle in the Marcus Defender for endpoint settings lets you suppress these alerts while keeping blocking enforcement activity. Yeah, so that makes sense, doesn't it? Because every time if you have an unsection app and you're blocking it, you don't necessarily need to know that someone attempted to go to it per se. It is useful sort of information, but you don't It's very no I've I've seen that being very noisy. I think I I know somebody that I've got to email about that. Yeah. I've seen that being suppressed in places. Yeah, for sure. Yeah, that's cool. To to be fair, it might be like you s like if you're going to a website and it's like you've you've blocked app app websites or app category. Yeah. You know, that's you know, someone goes to a website, they get blocked. Yeah, it's gonna be noisy. Or they're using an AI service that's in the background and it's been blocked, etc. Or it's like ⁓ you know, ⁓ ⁓ cross site request that's done in the background that's blocked that they don't even know and then they're browsing some absolutely terrible news website with all these links to block but anyway you see what I'm saying like yeah exactly that's what I was getting at in effect it's not yeah it's not intentional access. Not intentional access. Yeah exactly yeah yeah. Cool. So yeah that's good. Moving on. smic sentinel you've got generate playbooks using AI. in Microsoft Sentinel is now generally available. ⁓ you can now generate playbooks using an AI. Yeah, ⁓ the Saw playbook generator creates Python based authentic automation workflow co authored through a conversation experience with with Klein. ⁓ an AI coding agent for yeah. So you can start building your automation. Yeah. That way. UBE enhancements, new settings Experience Okta version 2 support and more GCP anomaly detections. ⁓ introduced a new entry point and creation, a consolidated view of the UEBA settings. And there's the behavior settings. You can now access UBA settings. ⁓ You can now access UBA settings from the new UEBA tab in Microsoft Sentinel settings page. A lot of settings. Lot of settings and l a lot of ⁓ UEBA as well. Okta now supports Okta version two C L table alongside the existing table. yeah, it's just some updates to the connector. UBA now supports five new G C P audit log anomaly detections. ⁓ unusual login behaviour previous ⁓ Privileged actions, resource deployments, secrets, secret, KMS key access and infrastructure usage patterns. So yeah, that's cool. ⁓ again, that is gonna be, I'm gonna say assuming, but it is gonna be based on it being integrated with Defender XDR pool, ⁓ which you you can only do now when you create a new one. Microsoft Purview. ⁓ that's an interesting one for June. Can't talk about that one. ⁓ Agent 365. ⁓ general available data security and compliance protections from it for for agents 365 is in there. ⁓ data governance. Let's just took a look at that one actually, because they've changed how they present these. ⁓ okay, so they're saying ⁓ d D SPM Auditing, data classification, sensitivity labels, pretty much everything apart from encryption without sensitive without sensitivity labels. Is supported for agent three six five. So pretty much everything. data loss prevention added admin permissions. Directory role Microsoft Edge Administrator, Microsoft Intro Administrator required to activate DLP policies for unmanaged cloud apps in Microsoft Edge for Business. So you just need that role. You need one of those role you need one of those roles now as well. Okay, yeah. Well that kind of makes sense. Yeah, that's what I was thinking, yeah. That's right though, is it required to activate DLP policies for unmatched. So that to me implies that when you configure it, it's gonna com feels like it's gonna configure some inching policies for you. Yeah. Yeah, exactly. Was it doing that before? No. It was all it was all just defender. You have to do it manually actually. Maybe it's gonna auto do it for you now. Yeah, yeah, true. Yeah. Okay. Yeah, that's cool. Makes sense. update clarify edge browser profile scope for the cloud apps, DLP policies. Policies for unmanaged cloud apps on managed devices apply across all edge profiles. Work, personal, and private. Policies for managed apps apply only to edge work profile. Right, okay. So what I think this is actually, I think this is gonna be doing app protection policy. stuff for you in endpoint dlp. So but I should do the the yeah, the MAM side of things. ⁓ changed remove Deep L and Zapier from the list of unmanaged AI apps supported by browser policies at Nedge. Removed? Yeah, they if they gone. Not not not paid their money. ⁓ in preview, new block action for specific external domains or users. Sub option restrict access or encryption the content to Microsoft locations. Encrypt the content in Microsoft 365 locations. Actions let's DLP policies for SharePoint and OneDrive block access to sensitive files for specific external domains. or user SMTPs. Interesting. Okay. So let's bring in some different DLP then for SharePoint OneDrive to bring in the external domains rather than just being internal people sending stuff out or sharing it. ⁓ there's quite a few other things in here. Sensitivity labels in preview rolling out manual label support for MP4 files in SharePoint OneDrive. Say that again? Manual labeling support for MP4 files in SharePoint in OneDrive. In what client? Clipchamp? Probably. I don't know. I don't even know what the name is. I just guessed that. Is it Clipchamp still? I don't even know. It's not Windows Movie Maker anymore, is it? Well I'm g yeah, I'm guessing it's I've got clip job on my desktop, it must Well it's in SharePoint or OneDrive, isn't it? So if it in there you can label it. Yeah, yeah, yeah, true. Yeah. ⁓ so yeah, in its Or Teams, it'll be Teams recordings, won't it? ⁓ yeah, true, yeah. Yeah, okay. That's what it will be. That's what I just the main reason for it. But the other benefit is clip jar, yeah. in preview rollout of new label policy settings for meetings. Apply meeting labels for to artifact. Automatically apply the meeting sensitivity label to recordings and their transcripts. MP4 files. There we go. And other notes. Okay. ⁓ So yeah, that makes more sense. ⁓ in preview you can now see the sync status of your sensitivity label publishing policies on the label policy page, giving you this bit on when the label policy updates are fully synced across three six five. Yes. Being able to work out, you know, keep keep opening Outlook or something to see if you got a policy update to see if your new labels are there is it's not fun. ⁓ there's updated documentation on how to disable sensitivity labels for SharePoint OneDrive. Opt out. Now includes labeled behaviour. If you disable sensitivity labels for SharePoint OneDrive after they have been enabled. Okay. Cool. Generally available is the new version of the data security posture management is now GA. Partner solutions and non Microsoft data sources remain in preview. Yeah. So that's good. I can actually go and look at that because in my tent it was not in my region apparently. But Yeah. Yeah, I I yeah, but you're you're talking about stuff and thing. I tried that a week ago and I still couldn't do it. So It's weird 'cause I had another tent customer that was in I think the same region as me and they had it. Yeah, I I kind of feel like that's ⁓ you're on an E five dev sub and we're not gonna give it to you until we're ready. Put to the back of the list. Yeah. Well it's now G A, so everyone should have it. ⁓ yeah, I suppose, yeah. Yeah. Yeah, okay, so moving on from purview and into entra. ⁓ so in po ⁓ this May, yep. Poet Preview ⁓ enable soft delete for Microsoft Entra device objects. So you can soft delete them and now recover them if you do accidentally delete the wrong ones. Cool. When he has multiple of the the different things. ⁓ intraconnect generally available. NetBARS name resolution test now in n now informational. The net bars name sysfold connectivity resolution test in the ADDS health monitor agent has been reclassified from ⁓ an alert test to an informational test. Okay. Cool. Yep. Enhanced admin authorization for enter connect. Sync configuration change. This says more on security posture. So interactive admin authorization for sync configuration changes. Alright, so if you want to enable disable features, there's an interactive authentication. greater consist ⁓ consistency in admin driven configuration. It's interesting because I think I think it was last month we were talking about them removing or moving pushing you towards the cloud sync? Yeah. Yeah, they've got a lot of this stuff. I suppose there's still gonna be some some bits to be missed. So yeah. Okay. Sorry, did we did we work out if cloud sync is gonna cover devices? I don't know. I didn't I didn't finish looking at that. Okay, I'm gonna Google that whilst you're talking. ⁓ public preview work workload identity based authentication ⁓ for SAP success factor provisioning integration. So workload ⁓ Microsoft ⁓ intro is introducing workload identity based authentication for SAP success factor provisioning. So it's just changing I'm guessing from a window ⁓ username password kind of thing to the workload identity base. That's cool. Public preview sensitivity labels for Microsoft Entra security groups. Microsoft Enter ID now supports applying a purview sensitive label to enter cloud security groups. Access using the same label and policies that apply to three six five groups today. ⁓ that's pretty cool. Yeah, that's good. You can stop guest users being added to a ⁓ privileged role group or something. Or to an internal only group. Yeah, that's cool. Yeah. Yeah. Never thought of that's that's cool. As cool as identity of purview would be. If you've got thousands of groups that now you need to label, I'm sorry. it's keeping people in the job until there's the ⁓ the intra purview group labeling agent. Automatic labeling intra group so now part of it, yeah, based on name. Service service Yeah. Yeah. Part of E seven service side intra labeling. Sorry. I sorry, we digress. ⁓ generally available account discovery. So I think I talked about this last time being ⁓ entry ID governance, they'll to look for orphaned accounts. ⁓ so you can identify those. ⁓ just looking else the sloads in here. Shall I find some just pick out a few 'cause it's like Slides. ⁓ public preview, Azure ⁓ yeah. I did read about this actually. I hope I'm in May. ⁓ Azure role assignment can now be governed via entitlement management, so you can now add Azure roles to access packages and things like that. Which I think is cool. You could do groups before, obviously, but now you can actually do the roles directly. And only provide it for maybe like contract yeah contract to be in for a certain amount time so yeah ⁓ that was May stuff I wasn't getting ahead of myself thank god there ⁓ okay finally because I feel like I've taken a hell of a lot of time on this ⁓ in tune let's just do one of these ⁓ in tune R back roles have access to co-pilot in in tune so When Microsoft Intune is enabled as a data source in security copilot, ⁓ my ⁓ Microsoft ⁓ entry ID, Intune administrative role automatically inherent security copilot owner access in in Intune. And all of the other built in role, custom roles, automatically inherit security copilot contributor to co pilot and engine as a role. Okay. Cool. Okay, I'll leave it there because I've just absolutely demolished the time. Well, we had twelve minutes of AI ramblings, didn't we? So True. But it's still only yes, okay. Cool. ⁓ yeah, Connect Sync still doesn't support hybrid join. But It just says not currently supported. Not that it'll so who knows. Right. ⁓ Let's start with ⁓ sorry. Let's start with Defender for Cloud. And what remind me what month we're on? This is May, yeah. Right. I'm just it confuses me because we're we're not in May, but we are in May. Anyway, right. So let's let's get started. yeah, now generally available. A big one is Defender for Cloud integration into the Defender portal. So this is on the 5th of May. ⁓ so this is really bringing together. This is the is this the last piece of the security.microsoft.com puzzle being brought in? You know, it it gobbled up everything, then it gobbled up Sentinel, and now is it gobbling up Defender for Cloud? Who knows? But yes, ⁓ we are now seeing, yeah, Defender for Cloud ⁓ being integrated into the Defender portal. So this this means that you bring together your Should we call your call it your cloud asset inventory? But with also with your what we're gonna call it, your enterprise inventory, I'd I'd I'd probably say. so yeah, you get integrated posture management through ⁓ security exposure management as well. ⁓ so yeah, instead of having to you know, 'cause Defender for Cloud has been well a completely separate portal, hasn't it? You have been able to synchronise like alerts, I suppose. Yeah, ⁓ whatever. But you so y you have had that, but really you have been going to that separate area. So yeah, so this is gonna well, in on one hand, it's one less place that you've got to navigate to and enrich data in one place, but also it makes that place more complex, I suppose, but you know, you are only in one place, so I would say that's overall less complex. On the same day, they also ⁓ made a change to how the daily score is calculated. ⁓ so apparently, I didn't know this, ⁓ but the daily cloud secure score ⁓ were previously average values over the course of a single day. so, but now the daily scores ⁓ are now going to represent the end-of-day snapshot instead. I have Absolutely no idea why you would need that, you know, difference in calculation. ⁓ but maybe when you're actually making those changes, you want to see your score reflected ⁓ more consistently because you're gonna you're gonna make your change, it's gonna refresh, and then the next day it's gonna change again, isn't it? I suppose. So maybe that was confusing people. Don't know. Yeah, I suppose it wouldn't if you've by in the end of the day theory, unless you do change it at night, of course. But ⁓ you if it's the average, then it won't reflect what you've actually done, I suppose, will it? No, exactly. Yeah. Especially if you're making large amounts of changes as well, I suppose. ⁓ I spoke about this last time or was it the time before, but the the idea of removing grouped recommendations in Defender Cloud? You know, like ⁓ some like vulnerability assessments and and whatnot were grouped together. ⁓ now they've been separated into individual recommendations. ⁓ so that is now generally available with the retirement of what they're now call calling legacy groups recommendations. ⁓ you can now install the Defender for container sensors using Helm. If you know what Helm is, ⁓ that's going to be good for you. If you don't know what Helm is, ⁓ you can move on and never touch Kubernetes ⁓ for the rest of your life. now ⁓ in preview is the SQL Vulnerability Assessment Express configuration. ⁓ for it's now available for Azure SQL Managed Instance and Synapse. So what this does. is it gives you a ⁓ it's a Microsoft fully managed tool for vulnerability baselines and scan results. ⁓ so you can yeah you can spin this up ⁓ and get that visibility and also the storage of that visibility as well. And apparently it's available for as your SQL database at no extra cost. So yeah ⁓ check that out. ⁓ because yeah, that could be ⁓ really good if you're wanting to do vulnerability assessments, yeah, especially over time as well. Yeah, Alan mentioned the defender for experts for servers. ⁓ the only thing I you know, ⁓ the only big thing I think here is the response element of it, you know, that I'm just gonna comment on. Because Yeah, this is them actually responding as well, right? This is this goes more than just sort of threat hunting and like tier tier one, right? This is actual response actions that they're taking. ⁓ and also really cool to see that you could buy this separately as well and it's cross ⁓ cross cloud, like Alan mentioned. ⁓ not gonna talk about that one. so, ⁓ now in preview in the Defender Portal, there is now cloud security ⁓ reporting on the Defender Portal side. So there's built in reports such as the CNAP executive summary and cloud posture that provides predefined values of cloud security data. I haven't seen this, so I'd love to see this in action. See how you know, ⁓ rich it is. ⁓ You can create custom reports from scratch by defining your own sections and selecting relevant cards, and you can export the reports to PDF as well for yeah, for sharing with with other people. ⁓ I think I'm gonna leave it there for the Devent of the Cloud. ⁓ not so much on the Azure side this time. ⁓ but like I said, ⁓ the second of June, all my days, there was some drops ⁓ from Microsoft ⁓ on that side of things. So yeah, next month I'm I'm maybe gonna need a bit more timeout. Right, so ⁓ now generally available ⁓ is the Azure Functions durable task scheduler, but with a consumption skew. ⁓ so what this is really good for is it allows you to run a durable workflow, which is ⁓ essentially a ⁓ a set of steps that have their own state attached to them. and it's it can be really good for AI agent orchestration ⁓ over time. there's no idle costs or anything like that, and you're charge you're charged per ⁓ for a every action that's dispatched, so you don't have to provision. Like a you know, ⁓ a compute for it. It supports up to 500 actions per second, 30-day data retention ⁓ for your durable actions. It comes with built-in monitoring, and it's got ⁓ identity-based security, ⁓ so it's integrated with entry ID. So it works across Azure Functions, Azure Container Apps, ⁓ Azure Kubernetes service, ⁓ and any compute environment that uses the durable task SDKs. So yeah, cool to see. Right, so I included this one because it's a bit of a weird one, I would say. So a retirement in Azure. Azure reserved virtual machine instances for select virtual machine series are now going into retirement. So starting the first of July yeah, we haven't hit that yet. Sorry. I'm so confused with times and the dates at the moment. I don't even know when it is. ⁓ Purchases and renewals will no longer be available for one year Azure reserved VM instances for the A V two, AM V two, B V one, D D S, D V two, DS V two, F FS, FSV two, G G S, LS and LSV two VM series. Additionally, one year and three year reserved instances for the DV3, DVS V3, EV3, and ESV3 VM series will no longer be available for purchase or renewal. So, yeah, if you are utilizing one year reserved VM instances, ⁓ and you're coming up for a new one, I sorry, I just completely just said all of those series names out, but if you are using any of them with reservations, you're gonna have to plan around that for your next cycle. ⁓ Yeah, so if ⁓ if so to avoid unexpecting billing changes or lapses in commitment savings, ⁓ Microsoft is recommending your current reserved instances orders for impacted VMs and when they expire. If you don't take any take any action before the first of July, these VM workloads will be billed at pay as you go rates once their corresponding reserved instance is instances expire, even if they're set to auto-renew. ⁓ Existing reserved instances will continue through their term and aren't impacted by the july first date, so. yeah, now in public preview is bulk restore for Azure Virtual Machines using Azure Backup. So it now ⁓ Azure Backup now supports a feature called bulk res bulk restore. This is for Azure Virtual Machines. ⁓ you can ⁓ restore up to 100 virtual machines in a single operation. ⁓ so you don't have to do it server by server anymore. You can ⁓ yeah, ⁓ you can you can deploy ⁓ you can go through your large scale ⁓ recovery scenario. So this could help you with your, you know, ⁓ return times. ⁓ you can select multiple VMs, choose the restore points, accom apply common restore parameters and track the restore progress in a s singular job function. ⁓ so yeah, ⁓ t take a look at that. ⁓ that could be good to look at your ⁓ your disaster recovery plans. Good news, now available. ⁓ new ⁓ virtual machine SKUs. ⁓ so yeah, the D I think it's D I. It could be DL. I think it's D I. D I D E ⁓ V7 virtual machines, which are powered by the latest Intel Xeon 6 granite rapids processors. ⁓ they are general purpose and memory optimized VMs, delivering up to 20% better general compute performance. so you can go up to and I just I just love the numbers and the ratios, to be totally honest with you. So customers can scale up to 372 virtual CPU cores, 2.8 TBytes of memory on the ESV7 and EDS V7 sizes, enabling larger and more demanding workloads. ⁓ They they utilize Azure Boost so they can go up to four hundred gigabits per second networking and eight hundred thousand IOPS and twenty gigabits gigabytes per second of remote storage throughput and up to nine point six million IOPS on local N VME. Crazy. ⁓ now generally available in central US and everybody will will follow if they can actually get hold of any of them. They didn't say that in the thing. I just added that because yeah, I'm just bitter about how much everything costs. now in public preview is Azure Container Apps Express. So this is ⁓ basically a way to ⁓ create ⁓ Azure containers ⁓ at scale. ⁓ but through so it it's really it gives you like a an opinionated production grade defaults, auto-scaling, per second billing, you get managed identity, secrets management, you can do custom domains, container registry integration, you get revisions and observability. ⁓ so you basically just bring your container and then Azure Container Apps does does the rest for you. So if you are looking to build upon as your container apps and you've ever been, you know, sort of overwhelmed or you you feel like the you know, setting up all of those we'll call it like, you know, tertiary or s secondary services that that go around it, ⁓ this could be really good. So I'm I'm definitely gonna ⁓ try this out and and see what it's like. ⁓ Azure NetApps now supports file sizes of up to sixty-four tibytes for regular volumes. That's file sizes, not storage sizes, file sizes. So yeah, again, you know, like we said earlier, if if if if you were the ⁓ customer that required that to be changed, ⁓ yeah. ⁓ I I pray for you. ⁓ ⁓ now generally available. Azure Front Door Standard and Premium now support WebSocket connectivity. If you don't know what WebSocket is, it allows ⁓ like ⁓ real-time fuel full duplex communication. ⁓ what it does is it opens like a single long-lived ⁓ long-lived DCP connection. So if you've ever like been to a website. And it's like updated on the fly. And I'm not just talking about like ads popping up, but like so you're getting real time data back into the browser without you having to refresh, it's typically using WebSockets. So it's quite a it's quite a big thing. And and and because it's used so ⁓ heavily, it's important that, you know, CDNs also support that on the edge ⁓ and support, you know, that caching layer ⁓ for those WebSockets as well. So yeah, such as ⁓ think of about things like chat applications, dashboards, financial data streaming, gaming uses it, any continuous data workloads. So yeah, it's really good to see. ⁓ we talked about this before, but now generally available is Azure Storage Mover, blob to blob migration. So you can transfer data between blob containers. ⁓ yes, fully managed. ⁓ it's really fast because it's on the you know the service side ⁓ to require that. So if you do need to move data rapidly between ⁓ blob ⁓ storage, then yeah, that is available to you ⁓ there. ⁓ nah, this is cool. ⁓ intra only identities now with Azure Files is now generally available. So it's finally moved out of preview. So yeah, so now you can use intra only identities for SMB access ⁓ into Azure files. So this is really good if organizations want to like lift and shift their on prem file ⁓ shares up into Azure. ⁓ so you could do this before, but it was in preview, so it's popped out into generally available. So yeah. yeah, really good to see. And that's it. That's it from me. Wow, we just hit an hit an hour, so yeah, that's not too bad with the ⁓ AI chat. Yeah. Dread to think what next month's gonna be. ⁓ my god. It I'm just gonna let you guys know that it's probably gonna be a two hour episode next month 'cause I have to scroll a lot in my RSS feed for June already and we're only on the fourth. So we're doing part one, part two? I d no, I think we're just gonna we're just gonna you know, go for it. Skip Defender, just do Azure. Should we just take next month off, Alan? Just take it off. Just just just nope out of it. Maybe when ignites on and when builds on, we just go, you know what? You can read the news by yourself. Maybe what we could do is we could do a text to audio like AI, you know, conversion of the book of news. Summarized book in a forty minute podcast episode. Nice. Cool. Yes, so lots of things and definitely a lot more things coming. So thanks for staying with us this long. ⁓ did you enjoy this episode? If so, please do consider leaving us a review on Apple, Spotify, YouTube. ⁓ this really helps us reach out to more people like yourselves. ⁓ if you do have any specific feedback or suggestions for our episodes, ⁓ we'll have a link in our show notes to get in contact with us. Yeah, and if you made it this far, thanks ever so much for listening and we'll catch you on the next one. Yep. Thanks so.