RunAs Radio

Follow RunAs Radio
Share on
Copy link to clipboard

RunAs Radio is a weekly Internet Audio Talk Show for IT Professionals working with Microsoft products.

Richard Campbell and Greg Hughes


    • Jun 4, 2025 LATEST EPISODE
    • weekly NEW EPISODES
    • 35m AVG DURATION
    • 1,001 EPISODES


    Search for episodes from RunAs Radio with a specific topic:

    Latest episodes from RunAs Radio

    Fixing a Security Vulnerability in Active Directory with Steve Syfuhs

    Play Episode Listen Later Jun 4, 2025 49:33


    Why would a security vulnerability take more than two years to fix? Richard chats with Steve Syfuhs about the evolution of the response to KB5015754. Originally published in 2022, the issue involved vulnerabilities in the on-premises certificate authority for Active Directory. Pushing a fix to force the immediate replacement of the certificates could have left users unable to log into Active Directory entirely. Steve explains how the gradual rollout of the fix allowed folks concerned (and paying attention!) to fix it immediately. At the same time, for everyone else, the fix happened as the existing certificates expired. But not every scenario is automatic - some require sysadmin intervention. So, how do you get their attention? The story leads to the February 11, 2025 update that could knock some users off Active Directory, but had an easy and quick fix. The final phase should be September 2025; hopefully, the last stragglers will be ready!LinksKB5014754Microsoft Security Response CenterCreate and Assign SCEP Certificate Profiles in IntuneRecorded April 10, 2025

    How to Talk to Security with Sarah Young

    Play Episode Listen Later May 28, 2025 35:48


    How do you talk to security? While at NDC Melbourne, Richard chatted with Sarah Young about her approaches to helping folks work with the security team. Often seen as an impediment to business, Sarah talks about what motivates security teams, how to use language to help them understand that you are taking security seriously, and how to get more things done! Ultimately, the DevOps mantra of providing value to the customer still works - working with people to improve the processes that lead to secure systems helps everyone!LinksDaniel Pink's DriveManaged Identities for AzureTenerife Airport DisasterRecorded April 30, 2025

    PowerShell 7.5 and DSC 3.0.0 with Jason Helmick

    Play Episode Listen Later May 21, 2025 36:47


    What's new in PowerShell 7.5? Richard talks to Jason Helmick about the latest version of PowerShell. Jason talks about 7.5 being a version with plenty of community contributions and what that means for everyone. He also discusses 7.6, which will be released as a long-term support version of PowerShell synchronized with .NET 10. Then, on to Desired State Configuration 3.0.0, which makes DSC work effectively across platforms, with or without PowerShell itself! 7.5 is a great version - are you up to date?LinksPowerShell 7.5PowerShell on GitHubDesired State Configuration 3.0.0WinGet ConfigurationSystem Configuration Tools in WindowsRecorded April 4, 2025

    Active Directory in 2025 with Liz Tesch

    Play Episode Listen Later May 14, 2025 34:38


    Active Directory is 25 years old - are you still managing it like it's 1999? Richard talks to Liz Tesch about her excellent blog post on the subject and the challenge many sysadmins have with Active Directory today. Liz talks about how WAN bandwidth was a concern in the early 2000s, so we organized Active Directory into Organizational Units to minimize the amount of AD traffic over the WAN - today, that is irrelevant. The challenge today is ensuring AD is not a vector for blackhats to attack the organization. Raising your functional level and utilizing some great free tools (check the links in the show notes) are all you need to use Active Directory like it's 2025!LinksActive Directory is 25 Years Old. Do you still manage it like it's 1999?mimikatzWindows Local Administrator Password SolutionMicrosoft Entra Privileged Identity ManagementKara Lawson - Handle Hard BetterEndpoint Detection and ResponseRecorded April 4, 2025

    Building a Career in Cybersecurity with Yuri Diogenes

    Play Episode Listen Later May 7, 2025 36:29


    How do you make a career in cybersecurity? Richard talks to Yuri Diogenes about his work in cybersecurity, including his book on building a career in cybersecurity. Yuri talks about the inquisitive mindset that works well in cybersecurity - wanting to understand why things happen and get to the root cause. The conversation also explores the value of experimentation and practical experience as well as certifications and training - they all have value. However, it is also recognized that cybersecurity encompasses a vast area of work - it's not one kind of job, so you have a lot of choices to make!LinksBuilding a Career in CybersecurityRecorded March 14, 2025

    Modern Work in 2025 with Karoliina Kettukari

    Play Episode Listen Later Apr 30, 2025 34:55


    So what does modern work look like today? Richard talks to Karoliina Kettukari about her new role as the Head of Modern Work for a financial services company in Finland, and what modern work has evolved. Karoliina talks about how the pandemic accelerated modern work, such as being able to work anywhere and collaborating with whomever you need to. Post-pandemic, there is a push for more work from the office, but remote work is still essential - and now artificial intelligence is changing the landscape again. The rapid evolution of AI technologies is a challenge for admins, but the productivity benefits are becoming obvious - you need some good governance!LinksMicrosoft 365 Copilot OverviewThe EU Artificial Intelligence ActEuropean Collaboration SummitRecorded March 6, 2025

    Agentic AI for IT Pros with Tim Warner

    Play Episode Listen Later Apr 23, 2025 34:44


    What can agentic AI do for you? Richard talks to Tim Warner about his work utilizing next generation agentic AI technologies to help with sysadmin tasks. Tim talks about the early lead that Cursor AI took with AI agents capable of writing and executing scripts on your behalf - as opposed to just creating code you can cut-and-paste. Today, GitHub Copilot has caught up with Agent Mode in Copilot Edits, although still in preview, it speaks to a future where sysadmins use these tools to write better scripts for work - and get more done in less time!LinksCursor AIOpenAI OperatorGitHub CopilotCopilot EditsRecorded February 17, 2025

    How to Not Hate PowerShell with Barbara Forbes

    Play Episode Listen Later Apr 16, 2025 36:54


    Are some of your team members starting to hate PowerShell? Richard talks to Barbara Forbes about her experiences with teams frustrated by PowerShell. Barbara talks about overcomplicating PowerShell scripts—the kind the most senior folks can create but no one else can maintain. Eventually, nobody will want to touch those scripts. Then there is the question of business value—does everything need to be automated? And by how much? Often, the appropriate solution solves 80% of the cases; the other 20% are best done by hand because the cost and complexity of the last 20% are too high. Focus on the return on investment for the business, and you'll keep the love of PowerShell alive! LinksPowerShellPester TestingGitHub CopilotBicepRecorded February 24, 2025

    Application Risk in Security Copilot with Ari Schorr

    Play Episode Listen Later Apr 9, 2025 34:02


    How can Security Copilot help you secure your applications? Richard talks to Ari Schorr about assessing application risk with Microsoft Security Copilot - a new feature in preview in Security Copilot that focuses on application roles and entities. Ari talks about the sheer array of resources that applications depend on, and the many security risks that exist in that space - how do you even get started on the problem? Security Copilot helps to sort through potential risks and help a sysadmin focus in on the most significant risks, especially the low-hanging fruit weak authentication and unused resources. The conversation also explores some of the future potential of a tool like this to detect supply chain attacks, find ways to strengthen and simplify applications so their attack surface is smaller. It's a great time to get familiar with these tools!LinksMicrosoft Security CopilotMidnight Blizzard Attack on MicrosoftSecure Future InitiativeAssess Application Risk with Microsoft Security CopilotMicrosoft SentinelRecorded February 18, 2025

    GitHub Copilot for SysAdmins with Jessica Deen

    Play Episode Listen Later Apr 2, 2025 38:32


    What can GitHub Copilot do for SysAdmins in 2025? Richard talks to Jessica Deen from GitHub about her experiences using Copilot for her work. Jessica talks about Copilot being the first stop for most tasks - describing the task to Copilot helps you think through the problem, and often the tool can generate code or information to get that task done fast. Today's GitHub Copilot can handle everything from explaining existing code to writing something new, debugging a problem, or even writing documentation!LinksGitHub CopilotChanging the AI Model for Copilot ChatVisual Studio Code InsidersAzure ExtensionsGitHub SparkLaunch DarklyRecorded March 13, 2025

    Writing Better PowerShell with Jeff Hicks

    Play Episode Listen Later Mar 26, 2025 36:37


    How do you write better PowerShell? Richard talks to Jeff Hicks about his latest book, Behind the PowerShell Pipeline, and his efforts to promote writing PowerShell scripts that are easy to understand, use, and maintain! Jeff talks about how making a script work is not enough anymore - you can use GitHub Copilot. The goal is to make the output as usable as possible, whether that is consistent output that is pipe-able or using color coding and column controls to make the results as actionable as possible. This is especially true as your team grows and more than one person works on scripts. Now, you'll want testing and source control, too!LinksPowerShell 7.5Behind the PowerShell PipelineGitHub CopilotPesterPowerShell SummitRecorded February 20, 2025

    Managing AI Costs with Sonia Cuff

    Play Episode Listen Later Mar 19, 2025 37:28


    How are you managing your AI costs? Richard chats with Sonia Cuff about how she's been helping sysadmins understand how AI technology is billed out and how to measure them within a given application and across the organization. Sonia starts with some definitions since the term AI is so broad. It's not just about large language models! The conversation also dives into carbon footprints, and using the FinOps models to help with costing for your cloud infrastructure, whether you're using AI or not!LinksOpenAI TokenizerManage Cost for Azure OpenAI ServiceSustainable Software Engineering with AKSAzure Carbon OptimizationFinOps FoundationFinOps FOCUSPhoenix ProjectRecorded February 19, 2025

    Strong Certificate Mapping in Active Directory with Richard Hicks

    Play Episode Listen Later Mar 12, 2025 39:33


    Are you using strong certificate mapping in Active Directory? Richard Hicks returns to the show to talk about the impacts of KB5015754, issued way back in 2022, and how it turned into an enforcement event on February 11, 2025 that might have caused some serious problems for folks trying to authenticate to Active Directory. For most sites, the upgrade to strong certificates was pretty much automatic. But if you're using Intune SCEP, you needed to do some configuration - and if that was missed, there is trouble. There are workarounds for now, but come September 2025, enforcement will be mandatory and everything gets harder, so it's worth looking into it now!LinksKB5015754: Certificate-based Authentication Changes on Windows Domain ControllersRichard's Blog Post on Strong Certificate Mapping EnforcementActive Directory Certificate ServicesCreate and Assign SCEP Certificate Profiles in IntuneHeartbleedRecorded February 17, 2025

    Secure by Design with Karinne Bessette

    Play Episode Listen Later Mar 5, 2025 40:04


    What does it mean to be secure by design? Richard chats with Karinne Bessette about the scope of the problem around making more secure software. Karinne talks about the US government's Cybersecurity and Infrastructure Security Agency (CISA) push to promote more secure software products. The conversation digs into some of the more famous exploits in recent years and some of the challenges of dealing with development tools that require super-user privileges, getting security testing done promptly and responding to exploits effectively when they happen.LinksWomen in TeamsCISA Secure by DesignAzure Kubernetes ServiceMicrosoft Security Response CenterRecorded February 21, 2025

    Exchange Server in 2025 with Michel de Rooij

    Play Episode Listen Later Feb 26, 2025 31:42


    What is it like to take care of an Exchange Server in 2025? Richard chats with Michel de Rooij about his work with Exchange, including the many scripts he has written and published over the years to help sysadmins solve problems. Michel discusses how staying on-premises with Exchange is getting harder - the new version will be subscription-based! The conversation also digs into the new version of Outlook, the challenges of securing email, and Michel's latest book Pro Exchange Administration.LinksRemove DuplicateItems ScriptUnarchive ScriptPro Exchange AdministrationOffice 365 for IT ProsMicrosoft Defender for Office 365Recorded January 9, 2025

    Managed DevOps Pools with Eliza Tarasila

    Play Episode Listen Later Feb 19, 2025 32:19


    How do you manage your CI/CD pipeline resources? Richard chats with Eliza Tarasila about Managed DevOps Pools in Azure DevOps. Eliza tells the story of discovering that teams were using Azure DevOps internally at Microsoft but would need to build their tooling to stand up the resources for testing and deployment. Managed DevOps Pools became the standard way to specify resources like virtual machines and assign them to projects so that they would start up automatically. The resources in the pool can be custom resources in Azure or even on-premises servers! And, more importantly, you don't need to care and feed for the infrastructure used in the pipelines, Azure DevOps will do it for you.LinksAzure DevOpsCreate and Manage PoolsManaged DevOps Pool Origin StoryAzure DevOps PricingAzure Spot Virtual MachinesManaged DevOps Pools DocumentationRecorded January 6, 2025

    Upgrading to Windows Server 2025 with Robert Smit

    Play Episode Listen Later Feb 12, 2025 37:51


    Ready to upgrade to Windows Server 2025? Richard talks to Robert Smit about his experiences doing an upgrade—with a few important dos and don'ts! Robert talks about dusting off your Active Directory setup and ensuring you're at the Server 2016 functional level. The conversation also dives into the new-build-versus-upgrade options, taking advantage of SMB over QUIC and SMB Compression, and much more!LinksWindows Server 2025Upgrading to Windows Server 2025Azure ArcWindows Admin CenterSMB CompressionWindows ToolsRemote Server Administration ToolsConfiguration ManagerAzure Arc-enabled System Center Virtual Machine ManagerLive Migration with Workgroup ClusterRecorded January 7, 2025

    Microsoft Entra ID Protection with Corissa Koopmans

    Play Episode Listen Later Feb 5, 2025 38:20


    How can Entra ID Protection help keep your organization resist security breaches? Richard talks to Corissa Koopmans about thinking beyond authentication and authorization and into conditional access - knowing what is normal and abnormal behavior for your users. Corissa recommends looking at the Entra ID Protection Dashboard - whether you have configured anything or not - to see what potential risks you have today. Whether it's logins from places where you have no workers or some "impossible travel" or weird browser connections, ID Protection detects and identifies those events. When combined with conditional access, Defender for Cloud, or even Microsoft Intune - you get a "better together" effect that makes it easier to know when something bad is happening!LinksMicrosoft Entra ID ProtectionAzure Active Directory Conditional AccessEntra ID Protection DashboardLog Analytics AgentMicrosoft IntuneMicrosoft Defender for CloudMicrosoft SentinelRecorded December 10, 2024

    Querying for Breaches with Mark Morowcyznski

    Play Episode Listen Later Jan 29, 2025 34:07


    Do you Kusto? Richard talks to Mark Morowczynski about his new book, The Definitive Guide to KQL, and the power of Kusto to look across your Azure tenant and understand operational and security issues. Mark talks about being able to query across all log sets, telemetry, the M365 graph, and more - to help understand issues. The book provides example queries you could run today, including knowing the first and last time a user logged on and what devices they used. There are examples of calculating baseline behavior for an account so that you can see when unusual activity starts. There are a ton of excellent queries for operational excellence and cybersecurity - get started today! And for RunAs listeners, you can use code KUSTO to get 30% off the book!LinksThreat Intelligence BlogPhishing-Resistant Passwordless AuthenticationKusto Query LanguageMicrosoft SentinelMicrosoft Security CopilotKQL Guide on GitHubRecorded December 19, 2024

    SQL 2025 and Fabric SQL with Anna Hoffman

    Play Episode Listen Later Jan 22, 2025 34:11


    What about SQL Server in Microsoft Fabric? Richard chats with Anna Hoffman about the preview release of SQL 2025 in Microsoft Fabric and the power of having your data store where you are doing your analytics and machine learning! Anna talks about new applications being developed using AI technologies like large language models and that often those applications need a data store - so why not keep it with the application in a configuration ideally suited for that work? The conversation digs into the relationship between existing SQL data stores and Fabric, how interconnections can happen, and perhaps a future of motion between them - but for now, it's a preview, so take a look!LinksSQL Database in Microsoft FabricMicrosoft PurviewMicrosoft EntraAzure Private Link for Azure SQL DatabaseMicrosoft Copilot for Azure SQL Databasesp_invokeRecorded December 16, 2024

    DevOpsDocs with Mattias Karlsson

    Play Episode Listen Later Jan 15, 2025 36:15


    Are your docs part of your DevOps cycle? Richard chats with Mattias Karlsson about automating documentation for APIs, cloud resources, and more! Mattias talks about using tools to build text files that contain every Azure resource being utilized, hopefully per application, along with API info, NuGet packages, and more. He also digs into the different audiences for that documentation - business wants to know what website exist, both interior and publically facing. Operations need to know what resources are consumed on-premises and in the cloud. Development is always looking for versions of APIs, calling approaches, etc. Maintaining documentation by hand is tedious and perpetually out-of-date. But if you can get up to speed with the tooling, you can make your documentation generate at the speed of deployment!LinksBicepAzure Resource InventoryAzure CLIPulumiRecorded October 29, 2024

    Least Privilege in 2025 with Bailey Bercik

    Play Episode Listen Later Jan 8, 2025 39:05


    How is least privilege different in 2025? Richard talks to Bailey Bercik about the ongoing efforts to minimize users, administrators, and applications' privileges in 2025. Bailey talks about the power of Entra Permissions Management to help you see what permissions are going unused on various accounts so that you can tailor rights to individual accounts without things becoming unmanageable. Artificial intelligence is a forcing function for many permission issues, with these new tools potentially creating problems when given unnecessary rights. But those same tools can help you understand where permissions are being underutilized and help protect your systems!LinksPrinciple of Least PrivilegeEnable Permission ManagementEntra Permissions ManagementMicrosoft Security CopilotCopilot in Microsoft EntraSEC545: GenAI and LLM Application SecurityHow Attackers Use Apps to Attack VideoRecorded December 16, 2024

    Being a SysAdmin in 2025

    Play Episode Listen Later Jan 1, 2025 32:47


    For the first show of 2025, let's talk about being a sysadmin in the coming year. This is the sixth year of Richard going solo on the show to talk about the things he's seen in the past year and speculate a bit on the next year, at least for sysadmins. Economic uncertainty is still a thing, as is employment. The security situation continues to be tough - and getting worse. But remarkable new tools, including large language models, are on the horizon to make things a bit easier. The adoption rates for LLMs aren't as quick as some people would like, but things are happening, and they can provide value. However, you have to do your homework. Oh, and then there's Windows!LinksMicrosoft CopilotMicrosoft 365 CopilotMicrosoft Security CopilotGitHub CopilotPrivileged Identity ManagementExtended Security Updates program for Windows 10Plan for Windows 10 EOS with Windows 11, Windows 365, and ESULAPSMicrosoft FabricRecorded December 31, 2024

    A Very Windows Christmas with Paul Thurrott

    Play Episode Listen Later Dec 25, 2024 38:02


    What does Windows want for Christmas? Richard chats with Paul Thurrott about the crazy year that Windows has had and what 2025 holds. Paul starts with the Ignite keynote that focused on Windows being an open platform - which sounds funny on the surface, but has some logic to it! Security is a key part of that story, which brings up the issues around Crowdstrike and the Secure Future Initiative. And then there's Windows 10 going out of support in 2025 - what choices do you have going forward? Two grumpy old men ring out the year – have a great holiday season!LinksSecure Future InitiativeWindows Security and ResiliencyWhat's new in Windows Security, Productivity, and CloudWindows Server 2025Windows 10 End of SupportRecorded December 5, 2024

    Real-Time Intelligence in Microsoft Fabric with Yitzhak Kesselman

    Play Episode Listen Later Dec 18, 2024 36:57


    Ready for some real-time intelligence? Richard chats with Yitzhak Kesselman about Real-Time Intelligence in Microsoft Fabric. Yitzhak talks about what it means to be real-time - that your company has a data analytics need with an ROI affected by a short amount of time. Perhaps it's a factory making products incorrectly or even issues with response times in a call center. The process involves bringing streaming data sources into the real-time hub and then attaching dashboards to them to see data as it changes. Fabric simplifies this tooling so domain experts can do much of the exploration. Once you have valuable and actionable information coming in, you have the activator options, including messaging via email or Teams, all the way to Power Automate to affect almost anything!LinksReal-Time Intelligence in Microsoft FabricFabric Real-Time HubReal-Time DashboardReal-Time ActivatorPower AutomateRecorded October 29, 2024

    M365 Copilot in Government with Angela Dugan

    Play Episode Listen Later Dec 11, 2024 35:22


    Can government agencies use M365 Copilot? Soon! Richard chats with Angela Dugan about how government entities: federal, state, counties, and cities, are exploring the power of M365 Copilot. Angela talks about the US Government GCC process for making M365 Copilot available in the next few months. The conversation turns to the usual challenges of data governance and security - all the same problems any other organization would have with tools that explore every element of data. Getting your data estate in order isn't easy - but the potential benefits in government are tremendous - providing more services to constituents for less cost!LinksMicrosoft 365 Copilot GCCSharePointOneDrive for US GovernmentMicrosoft PurviewRecorded October 29, 2024

    A SysAdmin Christmas with Rick Claus and Joey Snow

    Play Episode Listen Later Dec 4, 2024 38:23


    Need some gift ideas for your favorite sysadmin? We're here for you! Richard brings back Rick Claus and Joey Snow for another round of great gadgets that sysadmins love. There are some inexpensive options, some expensive options, some silly things, and some awesome toys! Share this show with your loved ones to help them get something great for you!LinksLinkTreeThe Help Desk Girl Stickers50th anniversary of D&D DiceNixie Tube ClockRGB Raspberry Pi 5 CaseSCRIB3DMeater Pro DuoXBox Series S 2-Slice ToasterSteamDeck OLEDROG Ally XBaby's Blogging KitEmber Baby Bottle SystemTryHackMeWiFiManElgato PrompterDual Arc Electric Candle LighterYoga Slim 7xOzloSleepLeatherman Wave PlusThe Ultimate Guide to Rebuilding a CivilizationRecorded November 29, 2024

    Incident Response with Mandi Walls

    Play Episode Listen Later Nov 27, 2024 36:01


    How does your organization respond to incidents? While at NDC Porto, Richard chatted with Mandi Walls about her experiences with different incidents, from corrupted files to data center failures. Mandi talks about detecting and determining the scope of an incident, whether it is specific to a customer (or group of customers), or possibly system wide. The conversation ranges over external attacks, bad software updates, unique configuration problems, and more. Keeping good records during the incident helps clean up after the event and provides for an effective retrospective.LinksPagerDutyRecorded October 17, 2024

    Testing Databases with Dan Mallott

    Play Episode Listen Later Nov 20, 2024 34:27


    How do you test your database? While at NDC Porto, Richard chatted with Dan Mallott about building unit tests for transactional databases like SQL Server. Dan talks about using testing frameworks constructed for the purpose, like TSQL-T, to make it easier to test individual database elements, from stored procedures to column constraints. The conversation digs into the challenges around testing, tolerating the changes to the database, and tweaking how you write your T-SQL code to be more testable. But the power of getting database tests into your CI/CD pipeline is enormous - catch more problems in testing before they become problems in production!LinkstsqltDbFitRecorded October 17, 2024

    SQL Server Management Studio with Erin Stellato

    Play Episode Listen Later Nov 13, 2024 42:23


    What's happening with SQL Server Management Studio? Richard chats with Erin Stellato, now at Microsoft, about the big jump coming for SSMS. Erin talks about how folks felt SSMS was a bit neglected when the reality is that there was a push to catch up with its parent codebase in Visual Studio. However, the next version of SSMS makes that jump, which opens the door to some excellent extension models. The conversation dives into the role of the Copilots in SQL Server through SSMS - helping you understand databases, write queries, and diagnose problems - eventually!LinksSQL Server Management StudioAzure SQL DatabaseSQL Server Integration ServicesSQL Server Data ToolsSQL FormatterRecorded September 26, 2024

    Software-Defined Networking using Azure Firewall with Aidan Finn

    Play Episode Listen Later Nov 6, 2024 40:05


    How does Software-Defined Networking in Azure work? Richard chats with Aidan Finn about his experiences working with the suite of Azure networking products, including Firewall and Route Server. Aidan talks about the training available on Microsoft Learn to get up to speed with the power of Azure Firewall, including building policy rule sets. The conversation also explores the power of defining how traffic can move within your network to clarify when potentially malicious software is active. LinksAzure FirewallSecure Networks with Zero TrustAzure Route ServerAzure Firewall TrainingAzure Firewall Policy Rule SetsRecorded September 24, 2024

    Updating Windows on ARM with Aria Hanson

    Play Episode Listen Later Oct 30, 2024 40:07


    ARM for Windows is here in the form of the Snapdragon Copilot+ PCs - how do you update them? Richard talks with Aria Hanson about how Windows Updates treat ARM like just another Windows device - all the updates! Aria talks about the transition time with Windows 24H2 update, which has some specific Copilot+ PC features. But when looking at ARM-based Windows devices, don't just focus on the Copilot part; check out the great battery life and the simpler architecture that should lead to long-life machines. The conversation also digs into the Windows Insider program, which now has four channels for updates, in order of likelihood to blue screen: Canary, Dev, Beta, and Release Preview.LinksWindows InsidersCopilot+ PCsWindows Insider BlogWindows AutopatchWindows AutopilotPlutonRecorded September 18, 2024

    Securing Data using Azure Virtual Desktop with Jim Duffy

    Play Episode Listen Later Oct 23, 2024 34:28


    How can you secure your company information with Azure Virtual Desktop? Richard talks to Jim Duffy about his work helping companies comply with NIST SP 800-171 security standards. These are the new standards required for Department of Defense contracting - including all subcontractors and suppliers. The security standard is thorough, with over 100 requirements. And you have to be audited to show that you comply! Even if you don't work with the government, the NIST security standard is excellent, and Jim talks about how you can use AVD to create a secure enclave for protecting data. And if you need help complying with NIST 800-171, Island Systems can help!LinksAzure Virtual DesktopNIST SP 800-171 Rev 3Secure Future InitiativeIsland SystemsRecorded August 12, 2024

    Pen Testing Yourself with Paula Januszkiewicz

    Play Episode Listen Later Oct 16, 2024 36:33


    Can you pen test yourself? Paula Januszkiewicz says yes! Richard talks to Paula about taking an active role in understanding your organization's security vulnerabilities. Paula talks about the low-hanging fruit she often finds as a professional penetration tester - typically on poorly maintained infrastructure like PKI servers. The conversation digs into tooling you can use to find vulnerabilities - just make sure you trust the source of those tools. Not everyone is a good guy in open source! And, of course, there's always a time to bring in professionals to do a deeper level of testing. Don't wait until the breach happens to take some action!LinksCqurePenetration TestingGitHub Secrets ScanningHaveIBeenPwnedRecorded August 22, 2024

    OpenAI for PowerShell with Doug Finke

    Play Episode Listen Later Oct 9, 2024 40:17


    How can OpenAI help you with PowerShell? Richard talks to Doug Finke about his experiences with ChatGPT and GitHub Copilot to help him write PowerShell and how he incorporated the OpenAI API into a PowerShell library to create a conversational interface in his PowerShell scripts! Doug talks about his productivity gains using OpenAI to write better quality PowerShell faster - helping him understand the code, automate test writing, and explore aspects of PowerShell he had never dug into. But beyond writing code for him, adding the conversational interface to a PowerShell script opens a whole new interactive opportunity to make it easier for folks to use scripts and do more with them!LinksGitHub CopilotPSAIGPT-4oDoug's BlogDoug's YouTube ChannelRecorded August 7, 2024

    Data Security and Governance in M365 with Nikki Chapple

    Play Episode Listen Later Oct 2, 2024 44:04


    Microsoft 365 Data Governance has always been critical - but it's only getting more important! Richard talks to Nikki Chapple about her experiences working with companies trying to get their "data estate in order." That phrase is what Microsoft recommends before turning on tools like Copilot for M365. Nikki talks about how hard the goal of data security is - that it is just as tricky as any other security goal. Data security is an endless process that needs refining and work on routinely as new data and classes of data arrive in the organization. In the meantime, users are taking advantage of LLMs like ChatGPT for their work whether we want them to or not - so there is a need to act quickly to provide secure capabilities!LinksData. Privacy, and Security for Microsoft Copilot for M365Exabeam Business Rewards vs Security Risks ReportMicrosoft 2024 Work Trend Index ReportMicrosoft Purview Data Security and Compliance Protections for Generative AI AppsMicrosoft Copilot Studio for M365Entra Entitlement ManagementShareable Links in OneDrive and SharePoint in M365Nikki's M365 Governance BlogAll Things M365 Governance on YouTubeRecorded August 16, 2024

    Windows Server 2025 and Active Directory with Orin Thomas

    Play Episode Listen Later Sep 25, 2024 43:26


    What does Windows Server 2025 bring to Active Directory? Richard chats with Orin Thomas about the new version of Windows Server coming and what to expect around Active Directory. Orin talks about how mature the Windows Server space is, so only incremental improvements are warranted, but they are important ones - like retiring NTLM once and for all. And when it comes to Active Directory, there are new secure features you're going to want, but you do need to up your functional level to get them, and that means getting to at least Server 2016 functional level first... then moving everything else. When was the last time you transferred a FSMO role? Orin also digs into the new certification practice options available, where instead of answering questions, you do the work and get evaluated - cool!LinksWhat's New in Server 2025SandwormActive Directory FSMO Roles in WindowsWindows Server Hybrid Administrator AssociateWindows LAPSRecorded August 6, 2024

    Asymmetric Encryption with Eli Holderness

    Play Episode Listen Later Sep 18, 2024 38:35


    Do you know how asymmetric encryption works? While at the Kansas City Developers Conference, Richard sat down with Eli Holderness to discuss many of the encryption technologies being used today—and the new options coming in the future! Eli talks about how symmetrical encryption and public key encryption have been the focus of modern encryption, especially on the web. But the ongoing security arms race means we have to keep tweaking encryption—what if we made a bigger leap? Asymmetric encryption offers huge potential - but there's still a long way to go!LinksPasswordless Identity with Eli HoldernessElliptic-Curve CryptographyShor's AlgorithmIsogeny Key ExchangeLearning with ErrorsChrome and Hybrid Kyber KEMliboqsLets EncryptRecorded June 27, 2024

    Microsoft 365 and PowerShell with Tony Redmond

    Play Episode Listen Later Sep 11, 2024 38:01


    What can you do to Microsoft 365 with PowerShell? Turns out - almost anything! Richard talks to Tony Redmond about his ongoing efforts to educate sysadmins about the vast array of capabilities in M365, including all the PowerShell cmdlets that can let you retrieve and control everything in M365. There's now so much information that Tony and his team have created a separate book explicitly focused on automating M365 with PowerShell. The conversation also turns to the role of Copilot - GitHub Copilot- in helping you write better PowerShell and the challenges around M365 Copilot. The goal is to take advantage of the Microsoft Graph - all that information about your M365 Tenant and what is happening inside it.LinksOffice 365 for IT ProsPractical 365 BlogAutomating Microsoft 365 with PowerShellMicrosoft Graph SDKCopilot for Microsoft 365Microsoft Entra PowerShellGitHub CopilotOverview of Microsoft GraphRecorded August 8, 2024

    Evolving Generative AI with Alison Cossette

    Play Episode Listen Later Sep 4, 2024 38:00


    How is generative AI evolving, and what can we do about it? While at NDC in Oslo, Richard chatted with Alison Cossette about her work as a data scientist before the ChatGPT explosion in November 2022 and what life has been like since the LLM came to town. Alison talks about the rigor of building AI models using generative AI before ChatGPT and how many of those efforts have diminished when confronted with a friendly, confident language model. Eventually, this rigor will be needed - as the dangers of not managing language models cause problems, and the need for rigor will re-appear. Alison describes steps you can take today to understand how the LLMs you are using are trained and how they are tested. Generative AI is evolving, and you can be part of making it better!LinksGitHub CopilotFairly TrainedRecorded June 12, 2024

    The Security Risks of AI with Steve Poole

    Play Episode Listen Later Aug 28, 2024 34:16


    Leadership wants to get on the AI bandwagon - what are the security risks? While at the Kansas City Developers Conference, Richard sat down with Steve Poole to talk about his experiences helping companies manage the risk of bringing AI into the company. Steve talks about the impact of introducing a new development stack, especially open-source stacks where you aren't sure of the providence of the code - sometimes there's malware in there! The conversation also moves to the various sources of language models and the potential risks. There's an urgency to move quickly on this technology, but don't allow that urgency to shortcut the safety your company will need - you can do this properly!LinksHugging FaceRecorded June 27, 2024

    Threat Modeling in the Cloud with Romina Druta & Daniela Cruzes

    Play Episode Listen Later Aug 21, 2024 36:24


    What are the threats your cloud application and infrastructure are facing? While at NDC Oslo, Richard chatted with Daniela Cruzes and Romina Druta about their work building threat models for cloud-based applications. Daniela discusses how modeling helps to understand security concerns before applications are deployed and attacked - often, security retrofits are time-consuming and expensive, so thinking them through beforehand has enormous benefits. Romina dives into the supply chain side of threats - open-source libraries with backdoors, even down to development tools with malware. There are a lot of threats - but when you look, there are often great solutions as well. You'll need to collaborate with development to secure things, but security isn't optional and is worth fighting for.LinksCloud-Native Application Protection PlatformArgoVSCode Malicious Extention ThreatsRecorded June 12, 2024

    Implementing Passkeys with Tarek Dawoud

    Play Episode Listen Later Aug 14, 2024 39:15


    Are you ready for passkeys? Richard talks to Tarek Dawoud from Microsoft about the evolution of passwordless access with passkeys. Tarek talks about the FIDO alliance and the ongoing effort to create authentication strategies that are mathematically impossible to phish - no password stuffing under the covers that might get exploited by a man-in-the-middle attack. The conversation also dives into the passkeys name and how it's a rebranding of passwordless authentication to make it easier for everyone to understand that you'd rather have a passkey than a password. The products involved are still evolving, but there's plenty you can take advantage of today and make your organization more phishing-resistant than ever!LinksFido AllianceYubicoWindows Hello for BusinessMicrosoft Digital Defense Report 2023Accenture Passwordless JourneyConditional AccessTemporary Access PassEnable Passkeys For Your OrganizationWeb AuthenCTAPMicrosoft Password GuidanceRecorded June 3, 2024

    Optimizing Cloud Recovery Costs with Natalie Serebryakova

    Play Episode Listen Later Aug 7, 2024 39:06


    What does it cost to recover from a disaster? While at NDC Oslo, Richard chatted with Natalie Serebryakova about her work helping companies understand their disaster recovery costs and what that process can teach you about your infrastructure. Natalie talks about different types of disasters, from the deletion of a production server to a major outage caused by a fire at a data center - and the power of working through the scenario to determine what needs to be backed up and what it takes to recover. The conversation also dives into the scrutiny of implementation - often, decisions are made that are no longer understood, or systems have changed enough that they could be improved. The result can be lowering DR costs, improving performance, and reducing operating overhead! LinksSOC2DataDogRecorded June 12, 2024

    Microsoft Cloud PKI with Richard Hicks

    Play Episode Listen Later Jul 31, 2024 44:31


    Ready to move your device certificate authority to the cloud? Richard chats with Richard Hicks about Microsoft Cloud PKI - certificate management for devices and people as part of the Intune Suite. Richard talks about it being early days for Cloud PKI, so not everything you want is there yet. The only way to get a certificate onto a device is through Intune, so some devices, like servers, don't have a way to play yet. However, there is a bridge between Active Directory certificates and Cloud PKI, so you can bring your new devices in through Intune and ultimately unload a lot of your on-premises certificate infrastructure. And that will make everyone's lives easier and more secure!LinksConditional AccessActive Directory Certificate ServicesMicrosoft Cloud PKIMicrosoft IntuneIntune and SCEPCertificate Connector for Microsoft IntuneBring Your Own CA in Cloud PKISCEPmanKeytosMicrosoft Entra Certificate-Based AuthenticationPKINIT in KerberosminikatzNetwork Policy ServerRecorded June 3, 2024

    Data Risk Management using Purview with Joanne Klein

    Play Episode Listen Later Jul 24, 2024 36:55


    How are you protecting your organization's data? Richard chats with Joanne Klein about her work with Microsoft Purview to help with data protection, management, and governance. Joanne talks about a spike in data protection concerns from Microsoft Copilot - if you have been securing data through obscurity, you're in for a nasty surprise! Copilot has a knack for finding every nook and cranny of data. Proper data protection also means effective archiving - getting rid of out-of-date or irrelevant data. And then there are the security concerns around data retention - how do you need to keep, and for how long? Microsoft Purview can help with all these problems, but you must work with leadership to get things right!LinksMicrosoft PurviewAdaptive Prevention in PurviewRecorded June 10, 2024

    The Power of Data in the Cloud with Arun Ulag

    Play Episode Listen Later Jul 17, 2024 36:37


    How has the cloud transformed the way we work with data? While at Build in Seattle, Richard sat down with Arun Ulag, Microsoft CVP of Azure Data, to discuss how the cloud has transformed how we work with data. The pre-cloud practice of extract-transform-and-load into OLAP cubes has given way to the data lake - you don't need to pre-process data if you have all the compute you need on demand. Arun goes further into empowering analysts using tools like PowerBI - but the key is access to data. With Microsoft Fabric, data lives in OneLake - or anywhere through links! Today, the data analytics landscape spans different product stacks and clouds - but all are available to learn more about your business!Links:PowerBIPivot Tables in ExcelOne LakeApache IcebergSnowflakeDatabricksRecorded May 22, 2024

    The Hardware of Azure with Rani Borkar

    Play Episode Listen Later Jul 10, 2024 34:08


    What hardware runs Azure today and into the future? While at Build in Seattle, Richard sat down with Rani Borkar to discuss the hardware that makes up Azure Compute, including examples of the new Cobalt and Maia processors! Rani talks about Cobalt first, Microsoft's ARM processor designed for workloads in the cloud. Then, a look at the Maia processor, which focuses on neural net workloads like large language models. As Rani explains, the scale of the work coming to the cloud today allows for specialized hardware - you would likely not want to buy a machine this specialized for yourself, but you can rent it by the minute in Azure!Links:Azure Cobalt ProcessorAzure MaiaRecorded May 22, 2024

    NGINX as a Service with Buu Lam

    Play Episode Listen Later Jul 3, 2024 35:01


    More application platform pieces make your life better! While at Build in Seattle, Richard sat down with Buu Lam of F5 to discuss F5's latest offering, NGINX as a Service in Azure. Buu discussed how F5's products have evolved to run in the cloud, not just on their hardware. While you could run them as virtual machines or containers, providing them as services in Azure is better. You purchase the service in the marketplace and as part of your Azure billing. The conversation digs into the advantages of the services model in terms of updating and instrumentation, as well as reducing the complexity of your infrastructure as code. LinksNGINXKubernetesBIG-IP NextF5 Distributed CloudNGINX as a Service on AzureDevCentral at F5Recorded May 21, 2024

    The Hard Part of Machine Learning with Lynn Langit

    Play Episode Listen Later Jun 26, 2024 35:08


    What are the hard parts of machine learning? Richard chats with Lynn Langit about her work helping the Mayo Clinic improve patient outcomes using machine learning to understand patient data better. Lynn talks about the challenges of multi-modal data analytics - taking all the different data collected from a patient, like an X-ray or video, along with treatment notes, to create an overall picture of treatment and outcome. Then multiply that by thousands of patients, making a complicated data problem with huge challenges in testing and validation. How do you know that the machine learning model is correct? The key to practical machine learning is in the fundamentals - working on each step before you jump to the more complex goals!LinksLynn on GitHubBiomedCLIPEvaluation Metrics and Statistical Tests for Machine LearningGitHub Copilot WorkspaceGemini in BigQueryBasic Bioinformatics for ITHistoGPTRecorded May 17, 2024

    Microsoft Defender for Cloud with Yuri Diogenes

    Play Episode Listen Later Jun 19, 2024 36:52


    Have you rolled out Microsoft Defender for Cloud? Richard chats with Yuri Diogenes about the bundle of tools under the Defender for Cloud moniker. Yuri describes Defender for Cloud as a Cloud-Native Application Protection Platform (CNAPP). This Gartner term covers the various elements that go into a cloud-native application, including APIs, servers, containers, storage, resource manager, and more! Defender for Cloud integrates with Microsoft Purview to understand data sensitivity, and Microsoft Sentinel helps detect breaches or data misuse. It also offers attack path analysis and remediation so you can get ahead of the attackers to close off potential breach risks before they happen! Check the links in the show notes for great resources, including an ebook on CNAPP strategy!LinksDefender for CloudOWASP Top 10 API Security RisksDefender for APIsMicrosoft SentinelData Security DashboardAttack PathsMicrosoft PurviewCloud Security Posture ManagementMicrosoft Copilot for SecuritySecurity Remediation with GovernanceDefender for Cloud ServiceNow IntegrationCNAPP Strategy EbookRecorded May 13, 2024

    Claim RunAs Radio

    In order to claim this podcast we'll send an email to with a verification link. Simply click the link and you will be able to edit tags, request a refresh, and other features to take control of your podcast page!

    Claim Cancel