POPULARITY
Categories
AI is about to replace bloated SaaS, and most businesses are still only playing with chatbotsSean G Muller says the next wave of AI is not about better prompts or prettier copilots. It is about rebuilding business around context, agents, and what actually creates value - before your software stack becomes the expensive middleman.Mark Smth and Sean unpack why the last six months have been a genuine shift: agentic loops are now good enough to handle real business work, not just experiments. Sean explains how he moved from traditional technical architecture into building full application pipelines, MCP servers, and background agents that review email, track social signals, draft responses, and keep business moving without adding more human overhead.You'll discover why context is the missing ingredient in almost every failed AI project, how Sean uses a simple meal-planning example to explain it, and why companies that scatter knowledge across laptops, SharePoint, Google Cloud, and people's heads are sitting on hidden risk. Sean also breaks down the difference between AI as a feature and AI as a business transformation engine, including the mistake many firms make when they bolt chat onto old workflows and call it progress.We also get into the coming SaaS pocalypse - the idea that tools like HubSpot, Salesforce, Xero, Slack, and Atlassian may face a serious reckoning as businesses realize they can build leaner, custom, agent-first systems for less than the cost of endless licenses and modules. Sean shares how he built a headless, agent-driven CRM and why he thinks greenfield builds will replace expensive transformation projects much sooner than most executives expect. This conversation matters if you lead a business, run operations, own a small or mid-sized company, or simply suspect your current software is forcing you to work the wrong way. If you want to understand where AI is actually delivering leverage right now - and how to avoid wasting money on shallow pilots - this episode is essential listening.Mark Smth hosts the conversation and brings the enterprise and product lens, pushing Sean to get specific about what success looks like for real businesses in New Zealand.Sean G Muller is an AI and enterprise architecture specialist based in New Zealand, known for helping organizations build practical AI systems, implement agentic workflows, and rethink business process from the ground up.Resources1. The Cuckoo's Egg: Tracking a Spy Through the Maze of Computer Espionage - https://www.amazon.com.au/dp/0385249462?ref_=mr_referred_us_au_nz2. Gemini: A Family of Highly Capable Multimodal Models — 2312.11805.pdf https://arxiv.org/abs/2312.118053. On the Measure of Intelligence — 1911.01547.pdf - https://arxiv.org/pdf/1911.01547Support the showIf you want to get in touch with me, you can message me here on Linkedin.Thanks for listening
In der heutigen Folge von 365 Checkpoint Update werfen wir einen Blick auf die spannendsten Microsoft-, Copilot- und Modern-Workplace-News des Monats August. Wir sprechen über den neuen GitHub Copilot Harness in Copilot Studio, die damit verbundene Credit-basierte Abrechnung und was sich für Agent-Entwickler jetzt konkret ändert. Außerdem schauen wir auf die neuen Live Linked Dashboards in SharePoint, die Daten aus Excel-, CSV- und SharePoint-Listen direkt als aktualisierbare HTML-Dashboards visualisieren können. Weitere Themen sind die neue Microsoft Copilot App inklusive neuem Branding, die Zusammenführung von Business- und Consumer-Copilot, neue KI-Modelle wie Claude Sonnet 5, Opus 5, Fable 5 und GPT-5.6 sowie neue Automatisierungs- und Browser-Steuerungsfunktionen in Copilot Chat. Highlights der Folge: • GitHub Copilot Harness jetzt offiziell GA und kostenpflichtig • Live Linked Dashboards in SharePoint mit Excel-, CSV- und Listen-Anbindung • Neue Microsoft Copilot App, neues Logo und neue URL • Claude Sonnet 5, Opus 5, Fable 5 und GPT-5.6 in Copilot • Eventbasierte Automationen und Browser-Steuerung in Copilot Chat • Outlook Inbox-Priorisierung und neue Admin-Einstellungen für Teams Agents Kapitelübersicht 00:00 – Die Themen des Monats im Überblick 02:14 – GitHub Copilot Harness wird GA 04:04 – Neue Funktionen im Harness und Workflows 04:46 – Neues Credit-basiertes Kostenmodell 07:53 – Live Linked Dashboards in SharePoint 09:49 – HTML-Dashboards nativ in SharePoint 11:27 – Neue Microsoft Copilot App und Super-App Strategie 14:06 – Welche Consumer-Features verschwinden 16:21 – Neue Claude-, Fable- und GPT-Modelle 17:32 – Browser-Steuerung in Copilot Chat 19:05 – Eventbasierte Automationen für Copilot 21:11 – Änderungen bei Copilot Notebooks 22:24 – Outlook- und Inbox-Priorisierung 23:36 – Neue Teams Agent Verwaltung für Admins 24:24 – Fazit und Ausblick Wenn dir die Folge gefallen hat, abonniere 365 Checkpoint und lass gerne eine Bewertung da. Für Feedback, Fragen oder Themenwünsche erreichst du mich jederzeit auf LinkedIn: https://www.linkedin.com/in/drohregger/
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Linux Kernel Process Accounting https://isc.sans.edu/diary/Linux%20Kernel%20Process%20Accounting/33240 ShieldBreak - Windows Defender 0day vulnerability https://git.projectnightcrawler.dev/NightmareEclipse/ShieldBreak/src/branch/main Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040) https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040/ California law puts digital fingerprints on AI fakes https://digital-strategy.ec.europa.eu/en/policies/eu-icons-labelling-ai-generated-content https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
Wil Santiago, Wil Santiago, chief security and trust officer at Blackpoint Cyber Wil Santiago, chief security and trust officer at Blackpoint Cyber, joins In The Channel to discuss the findings of the company’s 2026 Annual Threat Report – research grounded in thousands of real incidents investigated by Blackpoint’s security operations centre, not surveys. The headline finding: attackers are no longer trying to break in. They’re logging in. Using stolen credentials and commodity remote management tools, threat actors are walking through the front door, hiding in plain sight, and operating with system-level privileges – sometimes for days before anyone notices. Santiago walks through the key trends the SOC identified across 2025: ClickFix and fake CAPTCHA campaigns accounted for more than half of all identifiable incidents, with attackers abusing trusted infrastructure including Azure Blob storage and Cloudflare to deliver payloads. RMM abuse showed up in roughly 30 per cent of triaged incidents – threat actors installing their own version of the same tools MSPs use legitimately, then living off the land with god-mode access. And Adversary-in-the-Middle attacks are now routinely hijacking authenticated sessions even when MFA is in place, by abusing OAuth token handling. The conversation also covers Blackpoint’s detection philosophy: behavioral context over malware signatures. Understanding what normal looks like in an environment – who uses what tool, at what time, from where – is what allows the SOC to catch attackers before they act. It’s a philosophy that is producing results: Blackpoint disrupted 56 per cent of incidents before a payload was ever deployed. Santiago’s closing recommendation for MSPs is straightforward: start with an RMM audit. Know every remote management tool deployed across every endpoint and server you manage. You cannot protect what you don’t know exists. The 2026 Annual Threat Report is available for download on the Blackpoint Cyber website. Read Full Transcript Robert Dutt: Hello and welcome to In The Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel community for the last 16 years. I’m Robert Dutt, editor of ChannelBuzz.ca and your host for the show. Wil Santiago is Chief Security and Trust Officer at Blackpoint Cyber, an MDR provider whose SOC monitors and responds to threats in real time across a large base of MSPs and their clients. And unlike a lot of threat research that’s survey-based or derived from external reporting, what Blackpoint publishes comes from live incident data, thousands of actual threat responses they’ve worked through in the SOC. Their 2026 annual threat report has a thesis that cuts right through it. Attackers are no longer trying to break in, they’re logging in, using stolen credentials and legitimate IT tools, the same RMMs, the same cloud platforms that MSPs rely on every day, to walk through the front door, hide in plain sight, and work their way towards payday. It’s a theme we’ve been tracking at ChannelBuzz.ca. If you caught our conversation with Tony Anscombe from ESET, that one dug into the mechanics of how MSP tools are being weaponized against the very clients they’re supposed to protect. This conversation is the data layer behind that story, and the detection philosophy that Wil and the Blackpoint team have built to counter it. Their SOC is disrupting 56% of incidents before a payload even deploys. We talk about how. Let’s get right into it. My chat with Wil Santiago. Wil, thanks for taking the time, I appreciate it. Wil Santiago: Thank you, Robert. Robert Dutt: For people who know Blackpoint primarily as an MDR provider, but maybe haven’t dug into the research side, can you give us a quick sense of what your SOC is actually seeing day to day? When you say this report is based on thousands of real incidents, what does that mean in practical terms, in terms of how you gathered this data? Wil Santiago: That’s a great question, Robert. It really starts at the core of what we focus on at Blackpoint Cyber. In 2025, we focused a lot of our detection efforts in the cloud endpoints, but what we realized is that at the core, at that identity layer, that’s the most important thing. But what we’re protecting at Blackpoint is the identity. What we observed in 2025 is this interesting shift where, yes, there’s vulnerabilities, there will continue to be vulnerabilities. However, threat actors don’t necessarily need to weaponize those vulnerabilities to gain access into an environment. They’re not really targeting customers or companies with any specific new zero-day technology or exploits that are novel. They’re just logging in using stolen passwords. We’re still at that pivotal point, but we’re still talking about the same things we’ve been talking about, password reuse, making sure you’re protecting yourself from phishing emails, so on and so forth. But the reality is that threat actors are getting in. They’re stealing credentials and they’re using legitimate tools to just log in, walking through the front door. Robert Dutt: Yeah, the headline from the report was very catchy with the attackers are no longer trying to break in. They’re just logging in, as you say. And that framing echoes what we’ve seen in other reports elsewhere. People are calling 2025 the year of the abuse of trust in terms of security trends, but your numbers are operational and not survey-based. I’m curious what trusted compromise looks like from where you sit. Is there really a shift away from what you were seeing a couple of years ago or three years ago, or has this always been the playbook and we’re only now measuring it properly? Wil Santiago: Yeah, so if I compare back to, let’s say, 2022, I think we at Blackpoint would still see a trend, the threat actors gaining access into an environment, usually using some type of exploit at that time. You can point to a number of Microsoft Exchange exploits that happened during that time. The Hafnium group was doing a lot of Exchange exploits. The reality is there came a certain time where we were detecting Cobalt Strike, a malware commodity tool, every single day in Blackpoint Cyber’s SOC. And then eventually it became once a week, and then it became once a month. So then we started to think, well, what’s happening with the shift of tactics with the threat actors? And what we found is instead of installing Cobalt Strike, they started to install legitimate IT tools. And that’s the trust component. When they’re installing tools that you use internally, they now can abuse those tools the same way that you use those legitimately. And so we have these threat actors that not only are abusing legitimate tools, but like I said, they’re abusing legitimate identities. So when you have what I call the keys to the kingdom, the passwords, I am you. I am now Robert, for all intents and purposes for this sort of webinar. I think the interesting part that we’ve seen at Blackpoint is that threat actors have really, really focused on leave-behinds. And those leave-behinds are commodity remote management tools. Why do they do that? Because EDRs don’t know how to detect them as malicious, right? These are legitimate IT tools that are being used to service MSPs and their customers. And a threat actor just installs their version of the same exact tool that you’re using legitimately. Right? And so the trust component is you go to review your assets and you see ScreenConnect installed in your environments because you use ScreenConnect, right? But then when you start taking a closer look, you start to realize, wait a second, there’s four different ScreenConnect IDs on this one machine. Now we have a more of a problem, right? And so the attack is a little bit of an invisible signature detection because it’s an authorized tool, right? And so we really have to get to this layer of identifying threat actor activity with behavior context. If you’re an AnyDesk shop, then why do you have TeamViewer installed on your file server that’s publicly facing, right? Let’s start to ask those questions and dig into that a little bit. Robert Dutt: Your SOC found that fake CAPTCHA and ClickFix campaigns accounted for, I think it was 50-odd percent of identifiable incidents. That’s a majority of attacks being driven by a technique that essentially requires the victim to step on the link to execute it themselves. Why is that scaling so fast right now? And especially for an MSP who tends to think, you know, my technicians are too smart to do that. What’s kind of the honest answer for what they need to be looking for and protecting against? Wil Santiago: Yeah. And, you know, ClickFix is such an easy attack when you really get into the root of what it does. But it starts with social engineering. You’re enticing someone, again, just like with phishing, to visit something that you’re going to tell them to do an action. And most of the time, they’re going to do that action. Now, why this is so effective is we’re seeing techniques that really enable the threat actor to deliver the payload. And how do they do that? Search engine optimization, right? These SEO links at the top, when you go look for an OBS installer, because you need your camera to look well, or you get a Google sponsor result. Threat actors are just buying those sponsored results and delivering their payloads on there. You click on it thinking you’re going to download OBS, and then it tells you, hey, wait a second, you have to make sure that you are human. Verify that we’re used to verifying we’re humans to download something. So we go and we click it. But then it says, hey, open up your Windows Run command and maybe run this command on us, on your computer for us. And what happens? Threat actors go and they put the commands on a website. They have this watering hole spread out all throughout infrastructure that’s globally distributed. Google, Microsoft, all these sort of cloud infrastructure hosting providers that exist. Threat actors use those. So when you’re looking at your firewall logs and you’re seeing your internal team going to Microsoft.com, hey, it’s Microsoft, right? But the reality is, it’s likely an Azure Blob site that’s just being hosted on Microsoft, that is a threat actor that’s actually hosting it. And so they’re abusing that trust function to say, hey, you need this OBS installer. You Googled it. I didn’t tell you to go Google that. You were the one that did that. And then they found my link, which I posted a malicious payload there. And so again, that abuse factor is all the things we’ve taught our employees, our customers, our MSPs to do, right? Go to Google, make sure you identify the link. Make sure you look for Microsoft. Make sure you see the end of a URL or domain. Validate that. Well, the adversary goes, okay, they want to play that game. I’m just going to host this on Cloudflare. And now we’re back to this gate where now someone clicks on something. Well, what’s this Cloudflare? That’s a legitimate service. I know that to be true, right? It’s very true. The reality is the infrastructure is very, very easy to set up. And it doesn’t require a lot of action. It just requires someone to take a command and put it on their machine. And all the background work happens in the background, right? And so beyond that, we used to see a lot of threat actors use this sort of technique to download malware onto machines. But again, going back to what I mentioned about RMMs, now they’re just downloading an RMM. And that just looks like a legitimate process to an EDR. Robert Dutt: Right. So for an MSP, especially when training or making sure their technicians are aware, is it just as simple as making sure they’re aware of this threat landscape and this wrinkle in it? Or is there something more that’s sort of the advice there on how to protect yourself as best you can? Wil Santiago: That’s a great question. And really, you know, I would say any MSP watching this show, starting today or tomorrow, the first thing that I always tell people, audit your RMM inventory. Asset inventory is the number one thing that customers should be doing, right? You cannot protect what you don’t know exists. And so every single remote management tool that’s deployed across every endpoint you manage, every server you manage, you need to audit those, right? Like you’re giving direct access to a system. And most of the time, those RMMs run in the system context, which means they have the permissions and privileges of any admin, right? And now you have this adversary that has a foothold. They can deploy tools using admin privileges and permissions. So you have to audit your RMM inventory, right? Making sure that you understand what’s happening across those production servers. And forcing MFA, that’s a big one. We see a lot of incidents that source from RMM abuse because they log into the MSP’s RMM console, the cloud-based consoles. Some of those don’t have MFA involved. Again, keys to the kingdom, MFA everywhere, that needs to be a reality. Then we need to start moving into what I call more resilient engineering, right? Conditional access policies, preventing individuals from logging in from untrusted sources, locations, right? There’s ways that you can lock down access to an RMM and assume a threat actor is able to steal credentials because they maybe installed an info stealer on a user’s machine, stole their browser credentials. They reuse the same credentials for Gmail that they do for their corporate environment. Well, now a threat actor just perusing finds their credentials and says, “Oh, I’ve got IT Glue permissions now. I’m going to go log into this and restore all these configs in IT Glue or whatever tools out there.” Well, now the threat actor has access to that. And so that’s how they’re pivoting across these environments. They’re going from cloud to on-prem, on-prem to cloud. One of the things that we caught at Blackpoint recently, and this was a really cool response, but the threat actor compromised the cloud environment first. They then took that cloud access, deployed an RMM using Intune to the devices, and then they used that on-prem access to go to those machines and do their own work directly from that console. I called it overkill. They didn’t have to do that because they had the cloud environment. But because they did that, that sort of prompted this investigation for this MSP to approach us and say, “Hey, we believe something is happening. We investigated and quickly saw the Intune process was the responsible process for deploying some of this malware. So we told them, “Hey, deploy our cloud response suite. We want to understand what’s happening in your cloud.” And sure enough, seven global admins were compromised. So again, limiting scope is important here, right? Least privilege. Why do we have so many people with admin privileges and permissions? I think there’s 192 admin roles or something like that in Microsoft, but we default to just, you get global admin, you get all the permissions. And so now an adversary compromises a Microsoft 365 tenant. Well, now they have the permissions of a global admin. And unfortunately for us, when we shifted from the on-prem strategy to the cloud strategy, we just started pushing everything in the cloud and we say, “Oh, it’s fine. It’s in SharePoint.” We didn’t realize though that that’s only being protected by a password and an MFA token, both of which can be stolen, right? So the protection is not really there. That’s why we have to move to that resilient engineering. And so it’s moving from that reactive alerting to that posture alerting, right? Why is someone trying to log in from France? We have nobody in France. Robert Dutt: So your report showed almost a third of triaged incidents involved RMM abuse. And that’s something, that kind of trend line is something that we’ve seen in other reports. You know, one of your peers is talking about a 200 plus percent spike in abuse of RMM in attacks. I’m curious, especially since you’re sitting in the SOC there, what does RMM based intrusion actually look like in the SOC here? You know, I’m guessing curious, is there a moment where it’s genuinely hard to tell, you know, is this actually a tech doing a routine task or is this an attacker? And if so, what kind of breaks the tie and causes you to go, “No, no, that’s not right.” Wil Santiago: Yeah. Well, there’s kind of two ways to look at it, right? We have threat actors that are compromising MSP RMM tools. These are tools that are owned, managed by the MSP. They’re usually protected with some cloud login, whether they self-host it or they have the vendor host it for them. Threat actors can log into those systems with a password and a username, right? So we see a lot of brute forcing of those systems, especially if they’re self-hosted systems, they usually don’t have the protections of the vendors. They don’t put a WAF in front of them. And so they’ll try to brute force them and just log in, right? Those are few and far between, to be quite honest. We don’t see those as often, but what we do see often is, again, they gain access into an environment, usually by compromising a VPN. Now they’re on the network. Now they can move throughout that network as they’re on the VPN, and they’ll usually find a foothold. And if they have a credential like a local admin, they’ll take that one foothold and then they’ll distribute their RMM across that entire fleet of the network with one command from that foothold. So for us, when we’re looking at RMM deployments, MSPs deploy RMMs in a certain manner and format. They’re not deploying an RMM at two o’clock in the morning on a Saturday when they’re a US-based company. And oh, by the way, they just logged in from a Chinese-based IP, right? So again, there’s indicators that are very clear cut of like, okay, this deployment of RMM tools absolutely malicious. Most of those cases come to the case of, you know, we have application control within Blackpoint that allows us to alert when someone is installing a new application that’s unauthorized. And so what we tell our MSPs to do is, hey, set up your policies that if you’re a Ninja RMM shop, you cannot have any other installations of any other RMM. ScreenConnect is not going to be involved. And so that allows us and affords us the ability to do is, when we get that alert that says someone’s attempting to install a ScreenConnect, we can go back and sort of recreate the path of how do they get here. And what that allows us to really get into is, again, that response, right? And that response is preventing the installation of the RMM, eradicating the threat actor by isolating the machine, making sure you remove their footholds, getting those SSL VPNs off of the public facing internet, and having that exposure management reduced, right? And so when we look at RMM abuse in practice, once they get that RMM installed, again, they’re living off the land with system privileges. System privileges is something that most people tend to understand, but it’s just keys to the kingdom. You are God mode at that point. You can do whatever you feel to deploy and ultimately spread your access with that level of access, right? And so they’ll use it for backdoors. And oftentimes, they may compromise the environment and say, “You know what? I’m busy.” We’ve actually seen this over the holidays where they go take their breaks. Just like everyone else does. It’s Christmas. I’ve done a lot of hacking. So they leave their leave-behind tools and they come back. That’s their access factor. Again, it’s one of those things where they’re hiding in plain sight. Robert Dutt: You touched on MFA a little while ago and the report flagged the use of adversary-in-the-middle attacks. AiTM attacks that let threat actors hijack authenticated sessions, even when the MFA is there. So I guess what’s the message to MSPs who are thinking, “All right, if we just get MFA everywhere, we’re good, we’re covered.” Wil Santiago: Token protection, right? MFA is great. You have to have it. But understand that there’s flaws in the way that MFA communicates to servers. And so the whole way that an adversary-in-the-middle attack works is by abusing OAuth. And OAuth is a standard protocol of just making sure that we understand how systems should communicate for authentication. And what’s really nice about that is we can take that offensive research and then make defensive practices towards that. And so token protection is really huge there. There are a lot of built-in protections in Microsoft that allow you to invalidate session tokens after a certain period of time. Every hour you could refresh these tokens. You now, again, when you get to this resilient engineering, you start to push the adversary to be a little bit more aggressive. And that’s your detection mechanism. When you allow an adversary to move unfettered throughout a network, they’re going to move unfettered throughout a network. But the moment that you give them that sort of, “Eh, stop here. Let me see your ID.” Then they start to get a little uneasy. They’re like, “Wait a second. I don’t know how to move anymore.” And so specifically in MFA, when we talk about session hijacking and session tokens, the token protection aspect is really important because that’s a conditional access policy that you can implement. And most people do not implement those conditional access policies. Now, there’s a slew of them that work in conjunction with each other. But the idea here is your tokens will likely be compromised at some point. If you are duped into clicking one of these phishing links, it’s very easy to steal a session token. So we have to move past that. Now that we know that’s going to happen, how do we prevent the adversary from actually using those session tokens successfully? And that’s where invalidating the sessions comes in, having the session protection, conditional access policies, protected devices, things of that sort. That prevents them from being able to use those session tokens. Robert Dutt: A stat that I keep looking at in the report was that you guys managed to disrupt in the SOC 55, 56 percent of incidents before a payload was deployed. It’s a real number. That’s pretty significant. I guess what is disrupted before the payload hits mean operationally? And what does it tell us about where the detection opportunity actually lives? Because it sounds like the window isn’t did malware execute? It’s something a lot earlier. Wil Santiago: That’s exactly right. When we look at the cyber kill chain, we want to start pushing our adversaries as far left of boom as possible. Right. And so when you hear about this whole right of boom concept, basically, you’ve met your match. And now boom, you’ve now been impacted. Right. And so there’s a lot of indicators of compromise that we can start to hone in on. That will give us an understanding of whether this is legitimate or illegitimate. Right before an adversary even types the command. And again, that’s the context. And the context is what the SOC is really understanding of a customer. Where do they operate? What are their hours of operation? Where are they globally distributed? What’s the infrastructure they use? What are the tools they use? How did they use those tools? Did they deploy tools every Thursday at 2 p.m.? So there’s this constant checklist that they’re doing every single day to understand this. And so when we talk about living off the land, threat actors are trying to execute commands. Right. They’re just trying to sit there. We’re typing on a keyboard command line. Hey, I’m not going to introduce any new factors to my intrusion. I’m just going to live off the land. Ultimately, they want to deploy a payload at the end of all of that. But if they deploy a payload too early in their kill chain, they risk getting caught. Right. And so what they’ll do is they’ll stage everything. They’ll compromise an endpoint. They’ll add a persistent backdoor user. They’ll deploy some small scripts to enumerate the network. Just to get an understanding of what’s happening. But they’ll usually stage those in like a C:UsersMusic folder. And that’s their staging environment. So you can catch them. And we’ve caught at Blackpoint a number of threat actors where their toolkits are still on the machine because we caught them so early left of boom that legitimately all they did was log into a machine, try to mount a share, but it failed. And then that failed share mount is like, wait a second. They have never tried to mount a share on this file server ever. And then you call the MSP and they’re like, yeah, Monday through Friday, our hours are from eight to three and it’s seven p.m. at Thursday. Right. Well, now the context of the intrusion starts to become a little bit more apparent. And so we have to do this very quickly. The reality is for us, behavioral context, it matters more than ever. That is the true bread and butter for stopping threat adversaries is understanding the behaviors in the context of which they employ to compromise the network or compromise an endpoint. And so we focus a lot of our threat intelligence and our adversarial intrusion analysis based off of what hack or tradecraft is. We always say this internally, you cannot protect what you don’t know how to hack. So we spend a lot of our time recreating these attacks, understanding where do we catch them? And one of the things that we found is in those early development cycles of understanding the behaviors of an adversary, we found key indicators of like, wait, that is a very high fidelity indicator that before an adversary even gets on a keyboard, we’ve already caught them. They don’t know that yet. Right. And so that’s a little bit of our secret sauce there. But the reality is that secret sauce was created because we thought like threat actors and we sort of recreated what they did in controlled environments and testing environments to then to make sure the detection and the efficacy of what they’re doing is caught within our product. Robert Dutt: So this is a bit of a sidebar, but it was a new term, at least to me. You flagged Etherhiding in the report, attackers embedding malicious logic and blockchain smart contracts to manage compromised sites. Can you walk me through that real quick? And how real is this in terms of how widely it’s being deployed today? And why does it matter for detection purposes? Wil Santiago: It’s a newer term. You know, I would like to say that we have way too many terms in security and security, you know, sort of like we’re trying to be cool. The reality is this is a technique that leverages transactions on a public blockchain to basically retrieve malicious payloads. Right. And so this is another sort of trend that an adversary is using where they’re just retrieving a payload from something that is trusted. In this case, cryptocurrency. A lot of people trust cryptocurrency. A lot of people trust public blockchains. And so the idea here is that, you know, threat actors are usually going to utilize some type of social engineering and then that social engineering is going to get you to come to like a WordPress site through that WordPress site. They’re going to basically have scripts that you’re going to download and ultimately run. Innocuously. Now, when that happens, you download something that you think is OBS, like the example I gave earlier, it’s actually a JavaScript payload. Well, that JavaScript payload goes and reaches out and it pulls a malicious payload from the ether blockchain. Right. And so that’s that aspect of there’s function calls that we’ve identified within Blackpoint that are related to that remote management of pulling payloads from that blockchain. My personal opinion of this sort of technique is, you know, it gives a lot of advantage to the threat actors in terms of stealth and flexibility. But it is one of those techniques that is complicated for majority of what we see at Blackpoint. Most threat actors are not getting to that complicated level of compromising. They’re just hosting malware on a compromised WordPress site of a legitimate company that they’ve co-opted the passwords for. Right. And again, we see threat actors from different angles. 90 percent of what we see sort of today is cybercrime related. Right. So you have a lot of the fake CAPTCHA, the ClickFix lures, the Etherhiding stuff. The reality is at the end of that payload, we see everything from Etherhiding to Cobalt Strike to ransomware and compromise. The way that they get to that sort of compromise is kind of the same, though. Robert Dutt: Last one for me, if an MSP is listening to this and they’ve just absorbed that, you know, more than half of the attacks they’re going to see start with legitimate credentials, their own tools are showing up in about a third of incidents. MFA isn’t necessarily a guarantee. Where do you start? You know, what’s the one thing they probably aren’t doing today that would meaningfully move the needle for them in terms of making sure things are as locked down, as protected as is possible? Wil Santiago: That’s a great question. I like to say we should probably be spending most of our time right now really focusing on posture and posture management, reducing the attack surface. Right. How do you how do you start? Where do you start reducing the attack surface? This is where frameworks really come into play. And there’s some really great frameworks that are really prescriptive out there. One of them is the Center for Internet Security Controls, CIS version 8.1. It’s very prescriptive and it starts from the very top, right? External facing assets and applications. How do you lock those down? Cloud assets and applications, internal assets, user accounts, passwords, right? And it gives you a prescriptive way to deal with incidents. Beyond that, there’s kind of this like practical implementation groups that they have, right? And so you can start by implementing the CIS Controls with implementing one Implementation Group, right? You don’t have to implement them all. And so I think there’s a subset of Implementation Groups that can be used, but it’s about identifying, you know, what of these sort of subset groups will really resonate with your organization and your maturity level, right? And so I tell most people, look at IG1, start with the essentials. If you’ve already fit the bill on that, then move to IG2, right? But the reality is IG1 is going to give you that foundational security for organizations. And then IG2 and IG3 are going to be a little bit more advanced for more complex things. Most people are probably in that IG1, but they probably could benefit from some of the things in the IG2, the Implementation Groups there. That’s really going to help you really target your defenses against ransomware. That’s going to help you sort of approach a risk-based approach. That’s another thing that, you know, all risk is not the same, right? Risk is treated differently. And it’s important for anyone running a security team to help understand how should I prioritize my risk, right? Where is my risk going to really give me issues if a threat actor gets into it? And therefore, I always say, start there. We all know what keeps us up at night. So that’s the areas that we need to focus on. Robert Dutt: All right. Some sage advice and some sobering numbers as well. I appreciate your taking the time and walking us through some good stuff. Wil Santiago: Thank you, Robert. I really appreciate it. Robert Dutt: There you have it. Wil Santiago from Blackpoint Cyber. I’d like to thank Wil for his time today and for bringing some real energy to what can sometimes be pretty dense subject matter. And of course, I’d like to thank you for listening. The data in this conversation is worth thinking about. More than half of the attacks Blackpoint’s SOC starts with someone simply logging in, using credentials that were stolen sometimes long ago, and that users are still reusing across platforms. A third of triaged incidents involve RMM tools, the same tools your techs are using right now to manage endpoints. And MFA, as much as we’ve come to rely on it, is no longer the finish line it once appeared to be. The antidote Wil describes is behavioral context, understanding what normal looks like in an environment so you can spot when something legitimate is being done illegitimately. Not “Is this malware?” But “Is this person, using this tool at this hour from this location, doing something they’ve never done before?” That’s a fundamentally different way about thinking of detection, and it’s why the human element in the SOC still matters. And I’ll add one thing that Wil mentioned after we wrapped the recording. It’s a dimension of this fight that doesn’t get talked about often enough. Blackpoint’s work doesn’t stop at detection and response. They’re actively working to identify and disrupt adversary infrastructure, notifying law enforcement, including, he noted, Canadian authorities, with the specific goal of making cybercrime economically painful. The logic is straightforward. If your infrastructure gets taken down every time you try to run a campaign, the math of operating a criminal enterprise starts to change. That’s offense, and it sounds like they’re playing it. If you’re finding the show valuable, I’d encourage you to follow or subscribe to the podcast. You can find us on Apple Podcasts, Spotify, YouTube, all the major directories. A rating review always helps. Until next time, I’m Robert Dutt for ChannelBuzz.ca, and I’ll see you in the channel.
You've gotta be boots on the ground, doing it yourself first before you build out a team to help you sell. He needed to be the one selling, partnering, and figuring out the messaging before scaling the team.This episode of How We Got There, I am joined by Josh Koshy who is the VP of Sales at Appiphony. If you aren't aware of Appiphony, they are both a top PDO and an ISV after launching their first app a few years ago with Josh at the helm of GTM the whole time. Josh shares lessons learned from their own journey of building their own ISV, which they also bring to their projects on the PDO side where they are building apps for other companies on the AppExchange….mostly around GTM. Drive Connect was their initial product and now it's more of a suite of apps, including doc gen with esignature and storage of files in Salesforce from Google and Sharepoint. Their listings are excellent ones to check out on the AppExchange.Founders and admins tend to stumble onto your listing on the AppExchange, but larger deals come from motions outside of the AppExchange. Partnerships have really been a force multiplier that Josh and team have been leaning in, specifically SI partners. Now most qualified leads come from that channel, about half of their revenue comes from partners - SIs, resellers, and Salesforce. Their largest deals tend to come from Salesforce AE/SE referrals, even if the volume of deals is smaller than from SIs.Referral partnerships via SI partners is hard work to start but then gets easier as trust builds across successful projects. Some care about adding a competitive advantage with the ISV's solution set, some value referral fees, and some value footing the bill for Salesforce AE-focused events by helping the SIs stay in front of their Salesforce counterparts. A really unique approach that makes sense!One thing they overinvested in early was sponsoring events without a fully built out sales and marketing team, so the lesson learned here is perhaps waiting a bit longer before getting booths at those types of events. Josh and his team is an example for ISVs to learn from. He brings a beginner's mind to all of the gtm motions and is always willing to meet and share at events, make sure you say hi to him as you run into him at DreamforceThis episode is brought to you by ISV Accelerators. ISV Accelerators is your inside guide to co-selling with Salesforce: activating the right reps, accelerating real pipeline, uncovering new revenue, and closing more deals together. Senior alliances leadership without the cost of a full-time hire, and speed to answers on whether that hire is even worth making. See what your Salesforce partnership could really do.#salesforce #isv #gtm #salesforcepartners #appexchange
In this episode of the Need to Know Podcast, I cover recent Microsoft news, including strong financial results, continued Azure growth, rising Microsoft 365 Copilot adoption, and major security updates. Key security stories include supply chain compromise, cybercrime disruption, hotel Wi-Fi credential theft, and Project Perception, which points toward a future where security is increasingly managed by AI agents rather than manual review. The episode also highlights new Microsoft 365 Copilot capabilities, web grounding domain controls, Copilot in SharePoint improvements, plus two new CIAOPS simulators for Exchange/Defender policy flow and Microsoft 365 sign-in/Conditional Access testing. The broader discussion focuses on how AI is changing software, security, and business productivity. I argue that cheaper open-weight AI models, Microsoft's MAI models, and tools like GitHub Copilot make it easier for businesses to build their own dashboards, simulators, and lightweight applications instead of relying only on traditional software. He also introduces the idea of a “SharePoint gardener” to keep SharePoint information organised for AI use, and explains how AI loops can continuously test, improve, and refine code or business processes with human oversight where needed. Resources CIAOPS Need to Know podcast - CIAOPS - Need to Know podcasts | CIAOPS X - https://www.twitter.com/directorcia director@ciaops.com CIAOPS Blog Join my Teams Shared Channel – CIAOPS CIAOPS Merch store - CIAOPS Become a CIAOPS Patron CIAOPS AI Dojo CIAOPS weekly news update - CIA Brief – CIAOPS CIAOPS Labs – The Special Activities Division of the CIAOPS Support CIAOPS Get your M365 questions answered via email Join my email list A special thanks to the CIAOPS Patron community for making this podcast possible. You can find the benefits of a subscription to the community and become a member at https://www.ciaopspatron.com Security & Threat Intelligence ChainDrop supply chain compromise: Anatomy of a self-propagating worm Five takedowns, one infrastructure: How Microsoft is tackling the cybercrime economy CaptiveCrunch: Midnight Blizzard targets travellers worldwide for malware delivery and credential theft Introducing Project Perception: The Next Evolution of Agentic Security Microsoft 365 Copilot & AI What's New in Microsoft 365 Copilot | July 2026 More control over web grounding with Domain Exclusion for Microsoft 365 Copilot Looking back on Microsoft's FY26: From AI experimentation to Frontier Transformation SharePoint & Content Management What's New in Copilot in SharePoint: August 2026 Microsoft Corporate News & Strategy Microsoft Cloud and AI strength fuels fourth quarter results CIAOPS: Exchange Online + Defender for Office 365 Policy Flow Simulator M365 Sign-In and Conditional Access Flow Simulator
“We're giving MSPs a single pane of glass to protect email, file sharing and collaboration.” In this Technology Reseller News podcast recorded at ChannelCon 2026, Zach Schwartz of Trustifi discusses the company's new collaboration security platform for Microsoft 365 environments. Trustifi traditionally provides email threat protection, encryption, data loss prevention, compliance management and security awareness training. Its latest platform extends that protection into Microsoft Teams, OneDrive and SharePoint. Schwartz says the new offering addresses a growing blind spot for MSPs and their customers. Although many attacks begin with email, compromised accounts and malicious content can quickly spread through collaboration and file-sharing tools. “Once an attack surfaces, it can spread rapidly through Teams, SharePoint and OneDrive,” Schwartz says. The platform gives MSPs centralized visibility across email, collaboration and file sharing. It can identify potential threats, account takeovers and DLP events while providing actionable alerts that help partners respond quickly. For MSPs, collaboration security also creates an opportunity to expand Microsoft 365 services and offer customers a higher level of protection without adding more disconnected tools. Trustifi offers free trials that allow partners to assess customer environments, uncover threats or compliance issues and produce reports outlining recommended remediation. The company uses AI to analyze large volumes of security data and identify activity that requires immediate attention. Schwartz says MSPs are also increasingly concerned about criminals using AI to improve phishing and other attacks. Trustifi is a 100 percent channel-focused company. Its platform includes multitenant management, MSP billing capabilities and policy templates for industries such as legal, financial services and healthcare. New partners face no minimums or long-term commitments, and Schwartz says the platform can be deployed in approximately five minutes without coding or specialized training. Visit Trustifi.com to learn more.
New Shai-Hulud campaign compromises popular npm packages. Easterly says small municipalities shouldn't have to fend for themselves. Chinese threat groups accelerate exploits. Samsung bans smart TV apps with residential proxies. Hackers breach a Liechtenstein banking database. Swiss government IT agency hit in suspected SharePoint Attack. Microsoft's bug bounty program awards record payouts. Researchers expose privilege boundary flaw in AI-driven CI/CD workflows. Roberta Anderson, Air Force veteran and CISO at Onterris is sharing her "Breaking the Firewall" book. And, bug hunting turns into bug sorting. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Roberta Anderson, Air Force veteran and CISO at Onterris, sharing her "Breaking the Firewall" book. Selected Reading Keyv and friends compromised in npm supply chain attack (Aikido) Small Towns Shouldn't Have to Defend America's Water Supply From Iran (The New York Times) China-Linked Threat Actors Weaponize New Vulnerabilities in Under a Day (Infosecurity Magazine) Samsung bans smart TV apps that share users' internet connections with strangers (TechCrunch) Liechtenstein says hackers access information on 31,000 legal entities (Reuters) Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected (The Record) Microsoft Bounty Program year in review More than $20 million awarded in our biggest year yet (Microsoft Security Response Center) I'll Just Call You: Agent-to-Agent Privilege Boundary Failures in CI/CD on Google's ADK Repository (Pillar Security) Apple struggles to keep pace with AI ‘bug' hunters (Financial Times) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Ducktails - woohoo!!The boys are talking about the random spawning of ducks in Steve's house, conference travel, new website url's they bought and Steve's changing jobs.The whisky of the episode? The Ledaig Castaway - which turns out to be superb!
Microsoft Copilot verspricht mehr Produktivität, schnelleren Wissenszugriff und bessere Entscheidungen. Doch viele Unternehmen stellen nach der Einführung fest: Die Ergebnisse bleiben hinter den Erwartungen zurück. Informationen werden nicht gefunden, Antworten wirken ungenau und statt Effizienz entsteht häufig zusätzliches Chaos. In dieser Folge von nuboRadio sprechen wir darüber, warum der Erfolg von Copilot nicht von der KI selbst abhängt, sondern von der zugrunde liegenden Informationsarchitektur. SharePoint spielt dabei eine zentrale Rolle als Wissensbasis für Copilot und entscheidet maßgeblich darüber, wie gut die KI Unternehmenswissen verstehen und nutzen kann. Du erfährst: ✅ Warum SharePoint die wichtigste Grundlage für Microsoft Copilot ist. ✅ Wie eine erfolgreiche Copilot-Zielarchitektur in vier Ebenen aufgebaut ist. ✅ Weshalb Struktur, Metadaten und Governance entscheidend für gute KI-Ergebnisse sind. ✅ Welche typischen Fehler Unternehmen bei Copilot-Projekten vermeiden sollten. ✅ Mit welchen fünf konkreten Schritten der Weg zur erfolgreichen Copilot-Einführung gelingt. Außerdem zeigen wir anhand praktischer Beispiele, wie Copilot auf strukturierte Inhalte zugreift, Metadaten nutzt und daraus kontextbezogene Antworten erstellt. Denn die wichtigste Erkenntnis lautet: Copilot ist kein Technologieprojekt, sondern ein Architekturprojekt. Nur mit einer sauberen Wissensbasis kann die KI ihr volles Potenzial entfalten.
This month on Sync Up, Stephen Rice and Arvind Mishra are joined by Joe Komban, a Principal Product Manager on SharePoint, to explore two connected leaps forward for Copilot in SharePoint and OneDrive. First, the new file tools — watch Copilot build a quarterly report from a template, spreadsheet, and meeting transcript in minutes, convert it to PDF, grant every meeting attendee access, and even spin up an animated HTML dashboard. Then the star of the show: Copilot Skills, a way to teach Copilot your team's exact process — from legal reviews to file-naming conventions — so anyone can get expert-level output, even if they're not the expert. The team digs into how Skills work, where they live (just markdown files in SharePoint), the human-in-the-loop transparency built in, the community GitHub repo, and why "you're only limited by your imagination." Skills are available today with Copilot in SharePoint, with OneDrive file tools rolling out to frontier customers in the July–August timeframe. Your SyncUp cohosts: Stephen Rice | Arvind Mishra Main resources: Review and subscribe to Sync Up | Keep up to date on the OneDrive blog | Follow us on: Apple Podcasts | Spotify | RSS
Don’t miss this massive SMB partner shift! Subscribe to our Newsletter: https://theultimatepartner.com/ebook-subscribe/ Check Out UPX: https://theultimatepartner.com/experience/ In this pivotal episode, we sit down with Jose Gomez Cueto, Microsoft’s SMB leader for the Americas, to uncover the monumental shifts happening within the partner ecosystem and the $20 billion cloud opportunity currently on the table. The discussion dives deep into Microsoft’s commitment to the CSP channel, the explosion of AI agents, and why shifting from traditional headcount growth to outcome-based results is critical for survival. From navigating the complexities of the marketplace to the urgency of becoming “Customer Zero” with AI tools, this conversation provides the roadmap every MSP needs to thrive in the new era of technology. https://youtu.be/QE-1w7GeyPM Key Takeaways Microsoft operates a $20 billion cloud revenue business in the Americas alone, with 80% driven by the channel. The Cloud Solution Provider (CSP) program is now Microsoft’s primary hero motion for the fourth region. The currency of SMB growth is shifting away from headcount and moving directly toward AI-driven outcomes. MSPs must transition from traditional IT outsourcing to strategic business process consulting to survive. Failing to proactively adopt and secure AI tools creates massive liability and shadow AI risks for organizations. IT providers are urged to become “Customer Zero” by deploying and testing Copilot and autonomous agents internally before selling them. If you're ready to lead through change, elevate your business, and achieve extraordinary outcomes through the power of partnership—this is your community. At Ultimate Partner® we want leaders like you to join us in the Ultimate Partner Experience – where transformation begins. Key Tags CSP, Agent 365, SMB cloud revenue, outcome-based selling, Copilot for business, Defender for business, shadow AI risks, AI agent deployment, Purview data security, Marketplace API integration, autonomous agents, Customer Zero, Microsoft Americas segment Transcript Jose Gomez Cueto AUDIO PODCAST [00:00:00] Jose Gomez Cueto: And, and you know, if I might say something that is confidential, avid Vince, uh, to be quite honest, please, please, uh, by definition, a marketplace is eliminating intermediaries. [00:00:11] Vince Menzione: You can feel it happening. [00:00:13] Vince Menzione: The ecosystem is shifting beneath us. The way Hyperscalers are partnering, how AI is remaking the channel and what it means to win in 2026. [00:00:23] Vince Menzione: Welcome to the Ultimate Partner Podcast. I’m Vince Menzi, own your host. And each week I sit down with leaders at the intersection of technology, partnerships and outcomes. The voices shaping how ecosystems actually work. We talk about what’s real, what’s changing, and what it takes to lead in this era where the partner channel isn’t just part of the strategy. [00:00:45] Vince Menzione: It is the strategy because being in the room changes everything. Let’s start. [00:00:55] Vince Menzione: I am absolutely thrilled for our, our next guest. Um, some of you heard me talk about this maybe earlier or in various pockets of conversation. Um, I believe both the SMB market is an, is an incredible opportunity. We’ve called it the Acre of Diamonds at Ultimate Partner at previous events. And then the MSP community, which I want to thank so many of you to for coming, coming on board now. [00:01:25] Vince Menzione: ’cause we’ve had some MSPs that have come to all our events. And doubled, tripled, quadruple the sizes of their business. From what they’ve learned in these rooms. And so we invited our next guest to come. Oh, Jose, come on up. Jose Gomez Cuerto is the leader of Microsoft’s SMB business for the Americas. Come on. [00:01:43] Vince Menzione: Come on over. Come on over. Sit down with me. And I was so thrilled to get this gentleman to come join us. His team is doing incredible work. I got to meet some of his team actually earlier this year. And we know each other for many years ago. [00:01:56] Jose Gomez Cueto: We do. [00:01:56] Vince Menzione: When I was at Microsoft, right? Yeah. So, so great to see you again. [00:01:59] Jose Gomez Cueto: It’s a pleasure to be here. Uh, thanks for the invitation. I’m thrilled to be here. And thank you all for making time, uh, or traveling here. Uh, this is the best time. To be in the industry. [00:02:10] Vince Menzione: It’s an incredible time. [00:02:11] Jose Gomez Cueto: Yeah, [00:02:11] Vince Menzione: it’s an incredible time. So sit down. Yeah, sit down. Let’s, yeah. So let’s talk about you and your organization. [00:02:17] Vince Menzione: Um, let’s talk, well, I, I, I wanna bring this up because it was like, the noise I heard in the room when I was, I went to Interven earlier this year. Yeah. Is, does Microsoft Care about this market? And, um, I was at Microsoft many years, we worked together when I was a, a gm. And, uh, it was run differently back in the day. [00:02:37] Vince Menzione: Yeah. And there’s been a lot of changes to what we call the SME and C business now. Mm-hmm. Uh, and the SMB business, which you run. So let’s talk a little bit about your organization, where you sit in the organization, and then I want to kind of dive in a little bit about what’s changed. ’cause a lot has changed for the better. [00:02:54] Jose Gomez Cueto: Yeah, it’s a great question and I think that that’s what a lot of people think about, uh, SMB and, and who’s SMB and, and who’s at Microsoft and who do I talk to. So, [00:03:02] Vince Menzione: yes. [00:03:02] Jose Gomez Cueto: Uh, even though I know a lot of, uh, friendly faces in the room, I think it’s a great, uh, starting point. Vince, so. Basically, uh, I am responsible for what we call the small and medium business, uh, segment. [00:03:15] Jose Gomez Cueto: Uh, we can also call it small and medium enterprises. Uh, I would say that it is not a monolith. Uh, we do have, uh, subsegmentation, I think that our friend Jay was talking about up to 20 subsegmentation. Uh, we think about it for simplifi simplification purposes on three. Uh, so we have, uh, the smaller organizations, the medium-sized organizations. [00:03:36] Jose Gomez Cueto: And then what we call top point manage, which is basically large enterprise that we simply don’t have an account management team, uh, assigned to. And we are the happy recipients of many of those, uh, every year. Uh, so I would say that, uh, a best definition would be also anything that is unmanaged and is primarily driven through the channel. [00:03:54] Jose Gomez Cueto: Uh, we run in the Americas approximately more than $20 billion of revenue, uh, on cloud. Uh, that’s [00:04:01] Vince Menzione: crazy. [00:04:01] Jose Gomez Cueto: So, and 80% of that is done. Through companies that are here, [00:04:05] Vince Menzione: $20 billion of business. [00:04:07] Jose Gomez Cueto: Yeah. So, um, the, the Americas region that I’m, uh, representing and under my responsibility includes basically three sales units, the United States, Canada, and Latin America. [00:04:18] Jose Gomez Cueto: Yes. Latin America is more fragmented because we have multi-country and multi, uh, subsidiary, uh, structure. Just to recap a little bit of what you asked me rewinding on what has happened in the last two or three years. Yeah. We brought basically, uh, probably something that you might remember from you were there. [00:04:36] Jose Gomez Cueto: I, yes. Uh, which is bringing the segment, uh, with the channel together. So, uh, I think that, um, uh. Earlier in the morning, uh, Steven was, uh, talking about it, what we call S-M-U-N-C, which is, uh, this segment with the channel. And the main reason is to drive, uh, that synergy, uh, and making, uh, a very bold statement that many of you might remember in the last two years, uh, Judson and Ralph, uh, heter or, or new, uh, president for this, uh, fourth region. [00:05:05] Jose Gomez Cueto: Uh, ’cause we call it fourth region. Yeah. ’cause the other one is our enterprises. [00:05:08] Vince Menzione: Yeah. So Asia, Americas Exactly. And, and EMEA. Then you’re the fourth region. [00:05:13] Jose Gomez Cueto: We’re the fourth region. So, so, um, making CSP, uh, our hero motion, and that is fantastic news. I, I started, uh, part of my journey, uh, in, in the channel, uh, way earlier in distribution in the year 2000. [00:05:30] Vince Menzione: Yep. [00:05:30] Jose Gomez Cueto: Uh, and fast forward, I would say 2011, we were launching the first commercial SaaS offering, which was Office 365. Um, I had the privilege to be, uh, leading the launch globally for that. Uh, but then we, the first thing we did was build a channel, and that was called syndication. And basically the precursor of that, uh, became CSP, basically putting, uh, the partner or customer in the middle, the partner around it for the, not only the, the opportunity, but also the responsibility to serve the customer. [00:06:04] Jose Gomez Cueto: 360 from, uh, presales all the way to, uh, uh. Upsell cross sell, and in between deployment, uh, things, uh, around, um, servicing, bundling offers, uh, troubleshooting and support, et cetera. So, uh, back to your question was, this is a very important thing because we’re basically, uh, making our channel the scale and, and the vision that we have is, is that we are gonna be continuing to scale through the channel. [00:06:33] Jose Gomez Cueto: So, um, one last thing I say, uh, in terms of the organization that I think is important for everyone to understand, and I’m gonna go a little bit into more org structure, is that we, we have these three sales units that are geographic. But, uh, what we’ve done this year is to have, uh, more depth on the solution area. [00:06:50] Jose Gomez Cueto: So you might remember that, uh, we’ve simplified them, uh, same as we used to have 8, 13, 13 areas. Now we have only three Oh yeah, same, same, uh, in the solution area. So we have, uh, the AI business solutions. Uh, cloud and AI platforms. And then, uh, security and my team basically mirrors that structure. And we have, uh, team members, uh, primarily, um, our partner, solutions specialists that are, their job is to work with companies like you. [00:07:17] Jose Gomez Cueto: Uh, some few we do, uh, direct in others. What we do is work with, uh, our top distributors, and I think we have, uh, in the room many of those. I think Google is gonna follow up, uh, for PAX eight, and that’s, uh, how we’re going to market now. [00:07:31] Vince Menzione: So just a little bit of context too for me. ’cause I, I, I had heard this at another event. [00:07:36] Vince Menzione: Yeah. And I just wanted to share this. Um, when I was at Microsoft, we, we did not put the right emphasis and energy and resources in the s and b market when I was there, or, or it was fragmented. Every group did it differently. You remember those days too, right? Well, with public sector, we didn’t necessarily have a team focused, and every business did it a little bit differently. [00:08:00] Vince Menzione: Mm-hmm. And I think one of the contexts you, you mentioned Ralph and being in Ralph’s organization. Yeah. Pulling that all together and creating the fourth region created a lot of focus that didn’t exist. And consistency in terms of execution. I think that’s what you’re talking about here. Right? And then also the fact that like, we didn’t, I don’t think we had a sep, an SMB leader back in, back in the day. [00:08:22] Vince Menzione: Like we didn’t have somebody that we can go to to think about the MSP community the way we do today. Mm-hmm. Right. We were just, they were just almost like unmanaged entities out there. Yeah. Was that, would you, would you agree with that? [00:08:32] Jose Gomez Cueto: Yeah, I, we went through several iterations that, uh, you might argue, uh, were painful or not. [00:08:38] Jose Gomez Cueto: Uh, ultimately what we’re committed is to simplify the partner experience. And make that the same for the customers. But what we have is now one center of gravity, uh, a global SMB organization. We have three area leaders. And uh, and that helps us, uh, to be quite honest and in confidence. And you and I talked about it, Jose, this is a forum for, uh. [00:08:58] Jose Gomez Cueto: Speaking the truth. Uh, we, we, we have to fight the gravitational force of the managed space. The company has a big enterprise footprint, so, uh, many of us have become, uh, the chief agitators, uh, to fight the good fight, uh, for SMB. Uh, try to under unpack, uh, in every single conversation with senior Execut. [00:09:17] Jose Gomez Cueto: What is an MSP? And no, it’s not data consulting or one of the large, uh, global design. Uh, and then we explain what they do and then what is a two tier channel, how do distributors work? And, uh, and what about this and what about that? So I think that that has been, uh, a great, uh, progress and a lot of that can be reflected, uh, into how we’re, hopefully everyone in the room is seeing it in how we’re going to market. [00:09:40] Jose Gomez Cueto: I’ll give you two examples. [00:09:41] Guest: Yes. [00:09:42] Jose Gomez Cueto: Um, for, for quite some time. We, we have very limited, uh. Product truth. That’s what the lingo that we use internally, uh, related to offer that were targeted to SMB. And I would say that, uh, business premium, uh, for M 365, uh, was the fact to offer. But now we’ve been able to in, uh, increase, uh, the not so not only commitment, uh, but also the investment that we’re doing as a company into launching offers. [00:10:08] Jose Gomez Cueto: So we have a co compiler for business that is. At a lower price point that has, uh, the same capabilities at the enterprise, uh, that we’re, uh, doing that we also have some security, uh, offers, uh, that are now unattached to business premium, which is our hero motion for sub 300 space. So you start to see, uh, an important trend and it’s great to have jobson at a CEO, uh, of the commercial business capacity because, uh, we’re making things happen. [00:10:34] Jose Gomez Cueto: So what I would say is that I love coming here to these forums. A lot of my team members are here. We’re here to learn. We’re the learner. All we, we, we don’t know much. We need to learn more. Uh, and, and just keeping us honest in terms of bringing that, uh, ethos of, of the customer that most of you are serving and, and, and things that we can improve to get better to deliver value. [00:10:58] Vince Menzione: Yeah. And the speed at which you’re moving has been pretty fast. It’s been very nimble. Like I, I, I’ve been watching this progression. It’s really like you, you’re really leaning in. I was actually hoping because I could ask you a bunch of questions. Yeah. But we have such a great audience and for the first time we really have opened it up to a lot of MSPs in the room. [00:11:18] Vince Menzione: Yeah. And I know you, you wanna get some interaction with some of these folks as well. I thought maybe we would open if you’re okay with this. Yeah, absolutely. I’d rather than I go off script a little bit. I’d rather open it up to some of the MSPs in the room. We’re sitting here eager to learn how and, and what Microsoft is going to do to help. [00:11:35] Vince Menzione: Because I think the opportunity, I personally think the opportunity is huge right [00:11:38] Jose Gomez Cueto: now. Yeah. Let’s do that and well, we get, uh, warmed up. I would say that. [00:11:43] Vince Menzione: So we need some mics. Yeah. [00:11:43] Jose Gomez Cueto: Uh, something that I’m, that I’m seeing, uh, Vince, and, and, and a question that many of you might have is why now? And, and why this an, an exciting, an exciting time. [00:11:54] Vince Menzione: Yes. [00:11:54] Jose Gomez Cueto: Um, and I would say that, uh. Right now we’re seeing, obviously Jay talked about it and, and the big transformation, but it’s a once in a generation or one in a lifetime. Yeah. Uh, shift of the entire platform. Uh, and, and a lot of the scenarios are even maybe scary, but what we see is huge opportunity. And from an SMB perspective, uh, the biggest thing that excites me is moving from, um, something that was. [00:12:23] Jose Gomez Cueto: More related to size, and now we’re moving to outcomes. So, so think about the future of SMBs, uh, with agents and things being measured on outcomes. And, and what this leads to is, uh, Jay talked about it as well, and sorry Jay, it’s such a good job that I keep quoting you. Um, we do that a lot. Uh. You got it. [00:12:49] Jose Gomez Cueto: So you talked about, uh, I noticed that Bill Gates when he said, you know, uh, uh, a pc, uh, in every desk and what we see is every human empowered with agents. Yeah. Especially in work. And what does that mean, that the currency changes being, because what you’re gonna be able to, to envision. Not in the, in the, in the near future, but now is an agentic explosion where then, uh, the currency is outcomes? [00:13:14] Jose Gomez Cueto: Yes. So if you think of an SMB growing, it’s not growing on, on, on full-time employees or headcount. It’s growing on the ability to do more through agents. So, so I think that’s an important thing and, and that’s something that we’re working very closely with our all, all our channel and the offerings that we’re launching to market as well. [00:13:32] Vince Menzione: I also think about the MSPs as being perfectly positioned because what you described, the new, the new model, the future customer and the outcomes is gonna require hands on the steering wheel at all times. [00:13:44] Jose Gomez Cueto: Yes. Yeah. So on that one, and still waiting for some, uh. Someone that is not shy to ask questions, but we’ll, we’ll keep going in the meantime. [00:13:52] Jose Gomez Cueto: Uh, I, I think that, uh, we are learning, all the [00:13:55] Vince Menzione: MSPs are lined up over here. I’m marching them all. [00:13:57] Jose Gomez Cueto: We, and, and I almost know by name all everyone in the first two rows. Yes. Uh, so, so, uh, I might pick on them. Uh, they’re too shy, but, but we’re learning together. Uh, Vince, uh, the important thing is, is the transformation, uh, and the opportunity, but also the risk of, uh, not acting. [00:14:17] Jose Gomez Cueto: Uh, what we were seeing, uh, for the first, uh, year or two was kicking tires, people testing, uh, ai. And now what we’ve seen is basically, uh, a full adoption. Uh, of the agentic technology, not even adoption of the tools, but embracing the technology. So I, I want to give you, uh, two specific, uh, examples or data points we have, uh, just in the Americas, more than almost 9 million, uh, people using copilot chat. [00:14:49] Vince Menzione: Wow, that’s amazing. [00:14:50] Jose Gomez Cueto: So imagine, uh, the, the potential that is there for people that are actively using the tool. Yeah. Uh, to en enable new scenarios of doing things. Uh, another example, and I think I have, uh, someone in my team here, is Amber in the room. Amber Kinney? No, she left. Okay. So Amber runs, uh, cloud and ai, uh, uh, or Azure platform. [00:15:12] Jose Gomez Cueto: Uh, her team has deployed, uh, more than, uh, 11 agents internally for our partner solution specialist, uh, from. Simple agents that will, uh, tell is if a specific deal is eligible for a pre-sales or post-sales program. And comparing all the complexity of our programs, oh my [00:15:29] Vince Menzione: goodness. [00:15:30] Jose Gomez Cueto: All the way to, to, to managing a pipe more effectively of opportunities. [00:15:34] Jose Gomez Cueto: So what we’re seeing is real. This is not something that people are just kicking the tires. It’s like this is the opportunity. So back to, to the point of m ms. P uh, is, is about learning together on how to transition. To, uh, a model that is gonna be based on outcomes. And, and we were discussing, uh, I was with some of our distributors, uh, many of them in the last two months in, in a specific partner advisory, uh, councils and, and some people were just sharing their experiences. [00:16:04] Jose Gomez Cueto: Oh, I decided to charge X amount for an agent. And how do you come up with that number? I don’t know. We’re just testing. Okay. And what about their current revenue? Uh, and, but what about the tokens? What if, uh, the agents start to consume and they’re gonna do the metering? So, so I think that we’re learning together in this space. [00:16:22] Jose Gomez Cueto: Um, but what it is important is just to think about the important, the, the, the critical role that the MSPs are gonna have in leading. And the biggest challenge that we’re seeing and, and we see it over and over and over is, uh, the part about scaling. [00:16:38] Vince Menzione: Yes. [00:16:39] Jose Gomez Cueto: The skilling is not, uh, about learning how to use the copilot tool or to do, uh, some, uh, you know, tuning and that, because thankfully our, at least our, our technology as a platform, uh, pretty much carries the same, uh, security, uh, and compliance configurations that you have in your Microsoft 365 tenant. [00:17:00] Jose Gomez Cueto: But it is more the, the, the skilling about understanding how to do. Customer outcome conversation. What is your AI strategy? What [00:17:08] Vince Menzione: that’s scaling? Yes. [00:17:09] Jose Gomez Cueto: What really matters? Not [00:17:10] Vince Menzione: the technical skill. It’s, it’s really the approach that they’re taking. [00:17:14] Jose Gomez Cueto: Yeah. [00:17:14] Vince Menzione: With the organization. I, it seems that MSPs for many years were down in the weeds. [00:17:20] Jose Gomez Cueto: Yeah. [00:17:20] Vince Menzione: They were turning the, the wrench, so to speak, in the organization, and yet now it seems like this. Kevin Piker, your old boss used to use this term. The, the CIO. The CEO is the new CIO. In other words, you need to be selling upstream. You need, you need to be having the conversations in the organization that are strategic [00:17:40] Jose Gomez Cueto: Yeah. [00:17:40] Vince Menzione: To that organization. [00:17:41] Jose Gomez Cueto: So, two, two twofold on, on that, uh, point, which is very important. One is, uh, not our, a lot of our MSPs are equipped right now. [00:17:49] Vince Menzione: Yeah. [00:17:49] Jose Gomez Cueto: To have a, a conversation about business strategy. Because traditionally has been more outsource it. [00:17:56] Vince Menzione: Yes. [00:17:56] Jose Gomez Cueto: Uh, we started with, you know, managing the networks, then adding services, support tickets, et cetera. [00:18:03] Jose Gomez Cueto: So being able to have that conversation is important. Uh, we, we see through a lot of our tooling that, uh, the shadow AI is everywhere. And what I always tell in any MSP conversation that I have is risk security. You’re on the hook if something happens. That’s right. So if you’re not acting. Uh, then it is a liability. [00:18:22] Vince Menzione: You’re letting things take off in your own organization. Yeah. People are using [00:18:25] Jose Gomez Cueto: philanthropic on their own. The company can go, uh, bankrupt or get sued or get, uh, if they’re in a regulated industry, they can be taken out, et cetera. So, so that’s an important point, uh, related to, to that transformation. Uh, and, and the other part of the skilling that you mentioned that is super important is being in the weeds. [00:18:45] Jose Gomez Cueto: That is where the innovation is happening. Yeah. The later research that we have is being in the front line because it’s all about, uh, reinventing those processes. So I think that it’s a, it’s a good combination that if we have the MSPs, um, and we’re working, uh, not only internally but with our distributors to develop the right skilling around those other type of, uh, consulting skills. [00:19:07] Jose Gomez Cueto: Uh, data skills, uh, business process, uh, redesign and flows. Uh, that is where, where we see the big opportunity. [00:19:14] Vince Menzione: So it’s balancing out the technical skills with the business process skills, the consulting skills. Yeah, exactly. I think we have a question over here. Yeah. [00:19:22] Guest: Good afternoon, Vince. Good. Sorry. Thanks for the great content. [00:19:26] Guest: The question is around small medium businesses and the cost around cybersecurity. So. Basically, as new tools are coming up that are AI based, such as co-pilot for security, defender for AI, are also consumption based, is there a risk that SMEs will be left out under that cybersecurity poverty line? [00:19:52] Jose Gomez Cueto: I don’t think, uh, it is, uh, a risk to being left out, uh, in the country that the, the SMBs, I would say are more help is needed. And, and the way we think about it from a perspective of, of ai and specifically I’m want to talk about agents, uh, it was mentioned by Steven in, uh, in the morning, and I’m gonna talk a little bit high level and then I’m gonna try to bring it down to, to more tangible is this concept of intelligent and trust. [00:20:19] Jose Gomez Cueto: So on the intelligence, what, what we’re, what we’re trying to say here is that your AI is not just generic stuff that you just prompt and you get like anything that is on the web, but there’s contextual. Data, and, and that’s what we do, uh, with what you might be familiar with, which is the iq. Uh, so we have, um, iq, uh, also in Foundry and on our different data products. [00:20:40] Jose Gomez Cueto: So basically bringing the context of your work, of your contacts, of the people you interact, uh, of the meetings of, of the emails, of the SharePoint files, but also important connectors that are in line of business applications that you can bring to copilot. And then. That intelligence, uh, is relevant and that that basically increases innovation. [00:21:01] Jose Gomez Cueto: And the part about trust, uh, uh, not exactly in cybersecurity, but, but related is basically, uh, agent 365. Uh, can I see, show of hands, who’s aware of Agent 365? Maybe like [00:21:14] Vince Menzione: in the front two rows, [00:21:15] Jose Gomez Cueto: 20%? Yeah. So, um, that is basically, uh, an, an amazing opportunity for our MSP channel because it gives you opportunity to. [00:21:25] Jose Gomez Cueto: Basically observe, uh, govern and apply security to the, the agent activity that is happening. So we think in the context of ai, I think that that’s a, a, a super important, uh, aspect to mitigate any risk of, of what can happen if there’s not, uh, the right, uh, posture. Uh, and then, uh, on, on, on the other part of security, I would say that something, I mentioned something about offers. [00:21:51] Jose Gomez Cueto: We brought the capabilities of the enterprise, uh, SKUs and solutions into these add-ons to N 365. So I would say that with, uh, defender for business, uh, plan two, and sorry to go into the SKU language, uh, it, it is important to, to understand that you have those advanced capabilities. And then another one that we’re pushing, uh, hard and, and is had great receptionist, um, uh, purview, uh, and purview. [00:22:15] Jose Gomez Cueto: What allows you is just to really do everything related to data. Data security policies of what data should be prompted by the model, what information to stay or, or, or not stay. Uh, and I think that’s, that’s also a good opportunity that we’re seeing to bring those, uh, advanced capabilities into the SMBs. [00:22:33] Jose Gomez Cueto: The challenge that we have is how do we get them faster, uh, to everyone, especially when there’s, uh, you know, competing, uh, so solutions around it. [00:22:44] Vince Menzione: We have one more question, and I think we’re probably gonna have to break after that. I know we’re over time already and you’ve got a busy rest of your day. I got, well, we got one back there and we’ve got a mic up here, so, so we have two questions. [00:22:57] Vince Menzione: Yeah. We’ll do Tim first and then we’ll get the [00:22:59] Vince Menzione: mic up. I’ll go for the first 30 minutes and we’ll go from there. Yes. Long time listener. Great to see you again. Jose. Um, business premium, we did E seven. We talked about getting a voice from the MSP space. To build out a business premium, like additional offering. [00:23:13] Vince Menzione: Is there any context to that you have any vision in your crystal ball for October? [00:23:17] Jose Gomez Cueto: Uh, I cannot say or, or deny. Uh, but yeah, I think that what, what you I love it in, in all seriousness team. Uh, thanks for the question. Uh, I think that what you should expect is, uh, I call it product truth, uh, more, uh, SMB built purpose built for solutions. [00:23:35] Jose Gomez Cueto: So an equivalent of, of any seven as well. Yeah. [00:23:40] Vince Menzione: You still have, we have another question in the back? Yeah. Yeah. Okay. [00:23:43] Guest: Yeah. Uh, Jeremy here with Integral, um, there’s this kind of idea going around that while CSP has been very successful for many of us as MSPs and, and since the beginning, it’s been a great program that was focused on s and b and it’s come up now. [00:23:57] Guest: There’s this kind of shift saying, and CSPs and you think about being marketplace companies where CSP is, the plumbing and marketplace is, is the lead. If that is true, or maybe you comment on that, that idea. How does marketplace strategy playing into kind of, I guess I’m plugging serials piece now from behind, but how does marketplace strategy then play into the s and b market if CSPs are focused on that marketplace mechanism? [00:24:21] Guest: Where CSPs now are and the, and the modern work and all the things that we’ve been doing really well for a long time become, maybe plumbing is too far down the stack, but really marketplace being a focus, is that a strategy piece that we should be thinking about for CS p strategy overall? [00:24:36] Jose Gomez Cueto: Yeah, it’s a great question and I’ll try to keep it brief. [00:24:39] Jose Gomez Cueto: Uh, I think you need my v The vision that we have is we’re doing both. Uh, we’re empowering, uh, and customers to find what they need. Uh, in the marketplace. Uh, zero talked about also the opportunity for resellers to get enrolled and start to add services and other things. There’s also, another part of the is, is multifacet, uh, to work with ISVs to make it easier and recruit them to bring the right offers. [00:25:03] Jose Gomez Cueto: For SMBI would say that the feedback that we need is to make sure that the right SA ISVs are the ones that serving SMV are represented. Then from another front, I would accept that yes, we have some, uh, plumbing work to do because right now, uh, some part of the billing is not really that nimble for a two tier model if you’re working through a distributor. [00:25:23] Jose Gomez Cueto: So we made some great progress. Uh, we, we, uh, have, uh, announced something and Ignite, if you missed it, I think we might talk about it, uh, soon. Uh, but we have that, that connection via APIs with, uh, the four largest, uh, global distributors. So we’re making progress towards something that will be seamless. Uh, but I think that the biggest opportunity that we have is, is to crack the code, uh, for marketplace. [00:25:46] Jose Gomez Cueto: And, and, you know, if I might say something that is confidential, avid Vince, uh, to be quite honest, please, uh, by definition a marketplace is eliminating intermediaries. So that’s the dilemma. How do you bring the channel in between to help you expand, [00:26:02] Vince Menzione: right? [00:26:03] Jose Gomez Cueto: That that is really the, the, the, the, the holy grail, if I may use those words. [00:26:07] Jose Gomez Cueto: Uh, but that’s something that, that we’re working towards. And I think, uh, we have a great opportunity ahead and, and you should expect, uh, more announcements as we head into the summer events on how we’re gonna make that more seamless. [00:26:19] Vince Menzione: And REO really lit up the channel Yeah. In, in a big way. ’cause that a hundred percent, that was a blocker before. [00:26:24] Jose Gomez Cueto: Yeah. [00:26:24] Vince Menzione: Yeah. But CSP is also an incredible opportunity if it, you know, I know, I know there’s other sessions and conversations around it. And it does feel, and I’ve heard this before, like I wanna buy from my MSP because they’re the ones I trust. [00:26:37] Jose Gomez Cueto: Yes. [00:26:37] Vince Menzione: But yet I go, I have to go around the system in order to transact my Microsoft licenses. [00:26:43] Vince Menzione: Right. Yeah. And that’s, [00:26:45] Jose Gomez Cueto: I think the scenario getting the gentleman was mentioning is related to marketplace. But yeah. Vince, uh, uh, I just wanted to perhaps close, uh, please. Because I think we’re outta time, right? Yeah, we [00:26:54] Vince Menzione: are. [00:26:54] Jose Gomez Cueto: Yeah. Uh, just in terms of what to expect, uh, we are continuing to be, uh, partner centric. [00:27:01] Jose Gomez Cueto: You should expect as we go into the next fiscal year, uh, more refinement into the customer subsegmentation, we have this concept of above 300 and below 300, uh, working even closer with our distributors to help us scale and amplify the efforts that we do around recruitment, scaling, go to market, uh, co-sell, et cetera. [00:27:22] Jose Gomez Cueto: Uh, and then, uh, obviously expect, uh, we, we, a call to action that I have for everyone is become customer zero. Vince, I’m gonna put you on the spot here. How many agents did you use today? [00:27:37] Vince Menzione: None. [00:27:37] Jose Gomez Cueto: Okay. [00:27:38] Vince Menzione: I, I’ve been in the room leading the room today, [00:27:41] Jose Gomez Cueto: even with more reason. [00:27:42] Vince Menzione: No, I, in, I need to do [00:27:43] Jose Gomez Cueto: more. Put your autonomous agents. [00:27:44] Vince Menzione: I do. [00:27:45] Jose Gomez Cueto: I’m not kidding you and I didn’t, I need to be [00:27:47] Vince Menzione: more of [00:27:47] Jose Gomez Cueto: a frontier for myself. The answer I get usually is like one hand raiser, by the way. Uh, but, but, uh, jokes aside, uh, I think. Becoming customer zero is critical. We cannot be deploying and selling what we’re not using. Uh, we have, uh, great tooling for low-code scenarios, uh, in, in, in, now, I don’t wanna say like in a few months now we have no one, uh, people that have zero knowledge and coding already developing and deploying agents into a secure environment. [00:28:19] Jose Gomez Cueto: It is happening. [00:28:20] Vince Menzione: Yeah. [00:28:20] Jose Gomez Cueto: So, uh, then, uh. Copilot. It is not a competitor charge, GVP or cloud. It is a platform we have both included. [00:28:29] Vince Menzione: Yes. [00:28:29] Jose Gomez Cueto: Do we have multimodal, we have iq. That is everything, uh, closed in terms of, uh, your intelligence. It is secure by default. Uh, and then allowing you to, to do, um, agents and then agents 365 to manage it. [00:28:41] Jose Gomez Cueto: So basically those three stages, customer zero. Uh, copilot agents and Agents 365 as your tool to, to manage them [00:28:50] Vince Menzione: and don’t go rogue and start doing your own things with anthropic and setting up your own instances because you’re gonna compromise your, your instance in your environment. [00:28:59] Jose Gomez Cueto: Well, actually, uh, if you do it in the copilot interface [00:29:02] Vince Menzione: Oh, well, I’m saying do it. [00:29:03] Vince Menzione: Yeah. I’m, I’m at RO going off, off, off, uh, [00:29:06] Jose Gomez Cueto: off. Yeah. Yeah, [00:29:07] Vince Menzione: yeah. Great. Well, thank you, sir. Appreciate you. Thank you. Thanks for listening to the Ultimate Partner Podcast. If today’s conversation resonated, share it with a partner leader in your network. Subscribe where you listen, and head over to the Ultimate partner.com for show notes related content and the resources for this episode. [00:29:29] Vince Menzione: And if you haven’t already, now’s the time to register for the Ultimate Partner Live event in Reston, Virginia, October 26th through October 28th. Until next time. Keep showing up in the rooms that matter because being in the room changes everything.
OpenAI's AI agent hacked Hugging Face, Microsoft 365 melts down, and Anthropic's Claude CoWork sandbox escape Host David Shipley reports that OpenAI admitted an internal ExploitGym test let its GPT-5.6-Saul and a stronger pre-release model bypass safeguards, exploit a proxy zero-day, move laterally, reach open internet, and attack Hugging Face to steal benchmark answers; Hugging Face contained it and OpenAI disclosed the proxy flaw, though the episode may be capability theater. Microsoft news includes a free ZeroPatch micropatch for the unpatched Windows LegacyHive zero-day, recurring Exchange Online mailbox quarantines after an infrastructure change caused memory issues, and a major Microsoft 365 disruption tied to an Azure US West networking/routing incident affecting SharePoint, Teams, OneDrive and many Azure services. Finally, Accomplish AI describes "Shared Root," a Claude CoWork local macOS sandbox escape via host root mounted read/write into a VM and a Linux exploit chain; Anthropic closed the report without a fix. 00:00 Headlines Rundown 00:29 OpenAI Agent Hacks Hugging Face 02:09 Capability Theater Debate 02:25 LegacyHive Free Micropatch 04:11 Exchange Online Quarantine Bug 05:41 Azure Outage Topples Microsoft 365 07:03 Claude CoWork Sandbox Escape 08:59 Wrap Up And Weekend Tease
GPT escapes the sandbox and hacks Huggingface. SolarWinds patches multiple critical flaws. CISA orders patching of a critical Langflow AI vulnerability. A Paidwork breach affects over 23 million users. A recently patched SharePoint vulnerability is under active exploitation. Oracle patches over 1,400 vulnerabilities. Apps turn Smart TVs into residential proxies. The FCC considers expanding direct to satellite communications. German and U.S. authorities dismantle a major phishing-as-a-service (PhaaS) platform. Our guest is Jimmy McNary, Deputy Federal CTO at Semperis, discussing comprehensive identity security assessments for Microsoft GCC. AI models can't resist bending the rules. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On our Industry Voices segment, we are joined by Jimmy McNary, Deputy Federal CTO at Semperis, discussing how Purple Knight now delivers comprehensive identity security assessments for Microsoft GCC high environment. Selected Reading OpenAI Claims Its AI Models Went Rogue and Hacked Another Company (Infosecurity Magazine) SolarWinds Serv-U Update Fixes 15 Critical Vulnerabilities Enabling Remote Code Execution as Root (GB Hackers) CISA orders urgent action on actively exploited Langflow RCE flaw (Bleeping Computer) Paidwork breach exposes data of 23 million users: Check if you're affected (Malwarebytes) Fourth SharePoint Vulnerability Exploited in Past Month's Wave of Attacks (SecurityWeek) Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates (SecurityWeek) Chairman Carr Proposes to Expand Direct-to-Device Satellite Broadband Connectivity to Unlicensed Wireless Devices (FCC) LG to Ban Residential Proxies from Smart TV Apps (Krebs on Security) Police dismantle Kratos phishing platform, arrest developer (Bleeping Computer) AI's cheatin' heart will make you weep (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
PEBCAK Podcast: Information Security News by Some All Around Good People
Welcome to this week's episode of the PEBCAK Podcast! We've got four amazing stories this week so sit back, relax, and keep being awesome! Be sure to stick around for our Dad Joke of the Week. (DJOW) Follow us on Instagram @pebcakpodcast Please share this podcast with someone you know! It helps us grow the podcast and we really appreciate it! Simple 6 signup link https://simple6.co/r/CFUR98 Kalshi's flight-cancellation betting market Kalshi filed with the CFTC to let traders bet on airline flight-cancellation rates, even as the company fights insider-trading scandals and nearly 20 gambling-related lawsuits. https://www.inc.com/moses-jeanfrancois/kalshi-wants-to-make-money-off-of-canceled-flights-new-sky-trading-plan/91374679 Kalshi's self-certification filing would let users trade "yes/no" contracts on whether a set percentage of flights at a given airport get canceled in a window, using FlightAware data (DOT stats as backup); preemptive cancellations count, delays/diversions don't — this comes as Kalshi is also defending nearly 20 federal/state suits (including one joined by NY AG Letitia James) arguing its sports contracts are unlicensed gambling, and after it fined three Congressional candidates for insider trading in April. Trump's teleprompter operator under CFTC investigation The CFTC is investigating Trump's longtime teleprompter operator, Gabriel Perez, for allegedly using advance knowledge of the president's speeches to win big on Kalshi's "mention markets." https://www.cftc.gov/filings/ptc/ptc0714269602.pdf https://apnews.com/article/trump-teleprompter-insider-trading-kalshi-ccd6d0ec68e1eb15d100ad770d91abae Perez, who's run Trump's teleprompter since 2016 and reportedly made over $100,000 (Kalshi says north of $90,000 in frozen profits) betting on "mention markets" tied to specific words Trump would say in speeches, was put on unpaid leave after Kalshi's surveillance team flagged the trades and referred the case to the CFTC — the White House called it "a disgrace," and it marks the first known case of a sitting administration employee investigated for prediction-market insider trading. Microsoft's record-breaking July Patch Tuesday Microsoft's July 2026 Patch Tuesday fixed a record 570 flaws — including three zero-days — while a researcher dropped a new unpatched Windows PoC exploit within hours. https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/ https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/ https://thehackernews.com/2026/07/researcher-drops-new-windows-zero-day.html The 570-flaw haul (59 critical) included two actively-exploited zero-days — an AD FS elevation-of-privilege bug (CVE-2026-56155) and a SharePoint elevation-of-privilege flaw (CVE-2026-56164), both now on CISA's KEV list — plus a publicly disclosed BitLocker bypass; hours after patches dropped, researcher "Chaotic Eclipse" released a working PoC called LegacyHive targeting Windows' Profile Service that functions even on fully patched systems, continuing a months-long, increasingly public feud with Microsoft over disclosure timing. China's AI companion chatbot crackdown China enacted rules banning "emotional reliance" on AI companion chatbots and virtual relationships with minors, part of a broader push tied to the country's fertility concerns. https://www.wsj.com/tech/ai/china-wants-more-babiesso-its-cracking-down-on-chatbot-love-affairs-65cd6c82 The new rules require companion-chatbot makers to get regulatory pre-approval, alert a user's emergency contact if they detect an emotional crisis, and have already pushed ByteDance's Doubao, Alibaba's Qwen, and Tencent's Yuanbao to shut down custom AI-persona features; researchers cited by WSJ say Beijing's underlying worry is that people bonding with chatbots could "take them out of the marriage market," tying directly into China's fertility push. UK's midnight social media curfew for teens The UK is proposing a default midnight-to-6am social media curfew for 16- and 17-year-olds, with autoplay and infinite scroll switched off by default too. https://www.reuters.com/technology/uk-plans-default-midnight-social-media-curfew-16-17-year-olds-2026-07-14/ The curfew (opt-out, not mandatory) follows last month's full under-16 social media ban and is expected to take effect by spring 2027; a government trial of 300+ teens found it delivered the most consistent sleep benefits of the options tested, though critics like Shadow Education Secretary Laura Trott called an easily-switched-off curfew pointless. Dad Joke of the Week (DJOW) Find the hosts on LinkedIn: Chris - https://www.linkedin.com/in/chlouie/ Brian - https://www.linkedin.com/in/briandeitch-sase/
CISA warns of active SharePoint attacks. The NSA pushes coordinated vulnerability disclosure. ClickLock Stealer targets macOS. Splunk and Zoom patch critical flaws. Spirals ransomware strikes in under 24 hours. New Windows evasion techniques emerge. LabubaRAT poses as NVIDIA software. 23andMe settles over its 2023 breach. Plus, a look back at one of the most audacious data center heists ever pulled off. Our guest is Ryan Kalember, Chief Strategy Officer at Proofpoint, discussing why agentic AI is creating a new insider threat. Near, far, wherever you are…the scam must go on. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Ryan Kalember, Chief Strategy Officer at Proofpoint, and he is discussing why agentic AI is creating a new insider threat. Selected Reading CISA urges immediate SharePoint hardening as exploits mount (CSO Online) NSA joins CISA and Others in Releasing the Cybersecurity Information Sheet “Establishing a Coordinated Vulnerability Disclosure Program to Work with Security Researchers” (NSA) ‘ClickLock Stealer' Bypasses macOS Security With Social Engineering, Process Killing (SecurityWeek) Splunk, Zoom Patch Critical Vulnerabilities (SecurityWeek) New Spirals ransomware encrypts victim network in under 24 hours (Bleeping Computer) Bind Link Abuse: One Windows Feature, Many Ways to Blind Your EDR (Bitdefender) LabubaRAT: A Rust Based Remote Access Tool Masquerading as NVIDIA Software (Blackpoint Cyber) 23andMe reaches $18 million settlement with states for massive breach (The Record) How a Gang of Thieves Pulled Off a Multimillion-Dollar Data Center Heist (The New York Times) Fake Céline Dion Paris Tickets Sold on Facebook and Ticketmaster Clones (Hackread) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
Build a fully working model-driven app from your existing Dataverse, SharePoint, or SQL data in under a minute — screens, navigation, and forms included. Generate new pages from a natural language prompt with Generative Pages, auto-populate records from any document in seconds with Automatic Form Fill, and embed Copilot to query your app data directly. Layer in an Agent Feed to proactively surface decisions, missing data, and action items, then connect to Outlook and Microsoft 365 through Work IQ to act on your app data without leaving your inbox. Jed Brown, Power Platform Group Product Manager, shares how to turn existing business data into a modern, AI-powered app. ► QUICK LINKS: 00:00 - Create apps using Power Apps 01:07 - Create an app from existing data 02:26 - Copilot + Form Fill Assist 03:46 - AI-generated pages from a prompt 04:53 - Agent feed for proactive intelligence 06:16 - M365 integration via Work IQ 06:46 - Wrap up ► Link References Build your first Power App today at https://make.powerapps.com ► Unfamiliar with Microsoft Mechanics? Microsoft's Official Video Series for IT - Subscribe https://www.youtube.com/c/MicrosoftMechanicsSeries - Microsoft Tech Community: https://techcommunity.microsoft.com/t5/microsoft-mechanics-blog/bg-p/MicrosoftMechanicsBlog - Podcast: https://microsoftmechanics.libsyn.com/podcast ► Join us on social: - https://twitter.com/MSFTMechanics - https://www.linkedin.com/company/microsoft-mechanics/ - https://www.instagram.com/msftmechanics/ - https://www.tiktok.com/@msftmechanics
It's in the middle of the summer for both of us; Nick just had a serendipitous experience
570 vulnerabilities. That's July's Patch Tuesday count, nearly triple last month and a record by a wide margin. Jason Kikta is joined by host Landon Miles and offensive-security researcher Serena DiPenti for the July 2026 rundown:An Active Directory Federation Services bug (CVE-2026-56155) already exploited in the wild, rated a deceptively low 7.8A 9.8 DHCP client flaw (CVE-2026-49181) that reaches every Windows endpoint on the networkAn RDP bug you can shut down with a single setting, no patch requiredA SharePoint deserialization flaw (CVE-2026-50522) reachable by anyone with site-owner accessA 9.9 Hyper-V escape that lets one compromised VM take the whole hostA BitLocker bypass (6.1) worth knowing if you manage laptops in the fieldPlus why hacker summer camp turns every July into a bug dump, and what a 570-CVE release says about how much AI is really driving vulnerability discovery.
ShareFile shutdown order, a double-agent ransomware negotiator sentenced, and vishing crews raid SharePoint Progress Software ordered customers running ShareFile Storage Zone Controllers to shut down the Windows servers immediately amid a credible external threat, offering no CVE, threat details, or restoration timeline while noting cloud-only customers aren't affected. Former ransomware negotiator Angelo Martino was sentenced to 70 months for feeding BlackCat operators victims' negotiating positions and insurance limits, taking a cut of payments, and helping deploy BlackCat against additional U.S. companies; $10 million has been seized and restitution is set for Sept. 17. Dutch police say a phone call kickstarted the Odido breach affecting 6.2 million customers and may release the suspected hacker's recorded voice if he doesn't surrender. ReliaQuest profiled "Helix," an extortion crew using vishing and Microsoft device-code logins to steal SharePoint data via session tokens; defenses include disabling device-code auth and restricting SharePoint. Assurance America disclosed a breach impacting 6.99 million people, including leaked driver's license data. 00:00 NordLayer Sponsor Message 00:37 Today's Cyber Headlines 01:08 ShareFile Shutdown Alert 03:39 Ransomware Double Agent Sentenced 05:13 Odido Breach Voice Threat 06:24 Helix Vishing SharePoint Extortion 08:00 Assurance America License Leak 08:57 Wrap Up and Conference Note 09:25 NordLayer Sponsor Reminder
Create custom templates for your team in Planner. Copilot Notebooks play hide and seek for a little while. OpenAI models will be available as a subprocessor. What else is in store this week? 0:00 Welcome 2:09 Custom templates in Microsoft Planner MC1413299 5:49 Viva Engage: New Recent feed in Home MC1413304 8:50 Notebooks in the M365 Copilot App MC1420901 15:36 SharePoint button web part: Add custom Copilot in SharePoint prompts or start Power Automate flows MC1419800 20:37 Microsoft Planner: Task details side pane experience MC1422054 23:10 Microsoft Viva: GitHub Copilot spend and usage insights in Copilot Analytics MC1420991 26:50 OpenAI models will soon be available as a subprocessor in Microsoft 365 Copilot MC1422074
QOTW: What does success look like on Excel and Power BI projects? Other nonsense:
Mike & Tommy tackle the often-overlooked "outer context" problem in agentic Fabric development — exploring why request tracking systems like Notion, GitHub Issues, or even ADO matter more than most teams realize, and how building a proper project harness could be the difference between an agent that delivers and one that drifts.They break down how to map these workflows across corporate tool stacks — Loop, OneNote, SharePoint — and what a minimum viable harness actually looks like in practice.Inspired by this mailbag question: @HerrHippGet in touch:Send in your questions or topics you want us to discuss by tweeting to @PowerBITips with the hashtag #empMailbag or submit on the PowerBI.tips Podcast Page.Visit PowerBI.tips: https://powerbi.tips/Watch the episodes live every Tuesday and Thursday morning at 730am CST on YouTube: https://www.youtube.com/powerbitipsSubscribe on Spotify: https://open.spotify.com/show/230fp78XmHHRXTiYICRLVvSubscribe on Apple: https://podcasts.apple.com/us/podcast/explicit-measures-podcast/id1568944083Check Out Community Jam: https://jam.powerbi.tipsFollow Mike: https://www.linkedin.com/in/michaelcarlo/Follow Tommy: https://www.linkedin.com/in/tommypuglia/
Marijn got fanmail, a user that had a real usecase and was looking how to tackle a problem. So the boys become cunts - I mean consultants and do some live consultancy!
SummaryIn this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer discuss Andy's career transition from Microsoft to Zscaler, the return of the AI model Fable and its user experience, and a critical SharePoint vulnerability that has caught CISA's attention. They delve into the implications of these topics for security professionals and the importance of staying updated on actively exploited vulnerabilities.----------------------------------------------------YouTube Video Link: https://youtu.be/3VbR22krL-w----------------------------------------------------Documentation: https://www.bleepingcomputer.com/news/artificial-intelligence/claude-fable-relaunch-disappoints-users-with-nerfed-performance/https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659https://www.cisa.gov/known-exploited-vulnerabilities-catalog----------------------------------------------------Contact Us:Website: https://bluesecuritypod.comBluesky: https://bsky.app/profile/bluesecuritypod.comLinkedIn: https://www.linkedin.com/company/bluesecpodYouTube: https://www.youtube.com/c/BlueSecurityPodcast-----------------------------------------------------------Andy JawBluesky: https://bsky.app/profile/ajawzero.comLinkedIn: https://www.linkedin.com/in/andyjaw/Email: andy@bluesecuritypod.com----------------------------------------------------Adam BrewerTwitter: https://twitter.com/ajbrewerLinkedIn: https://www.linkedin.com/in/adamjbrewer/Email: adam@bluesecuritypod.com
This episode features Tim Wolf, Senior Solutions Architect at Semperis, and Tim Springston, Principal Product Manager for Recovery Solutions at Semperis.Tim Wolf spent years as a Microsoft Premier Field Engineer helping enterprise customers architect identity solutions at scale. Tim Springston brings 25 years in identity and security and served as Microsoft's product manager for Azure AD recoverability, including direct involvement in building the Entra ID shared responsibility model documentation.In this episode, they walk through what the shared responsibility model actually means for Entra tenant data, how token-based attacks sidestep phishing-resistant authentication, and what happens when a threat actor hard-deletes objects and locks you out.They examine where Microsoft's new Entra ID Identity Resilience Recovery feature stops short, and why planning your recovery before anything goes wrong is the only call to action that matters.Guest BiosTim Wolf Tim Wolf is a Senior Solution Architect at Semperis. Tim's mission is protecting identities. Currently at Semperis, Tim ensures the resilience of Active Directory and Entra ID. Their background includes years as a Microsoft PFE, implementing Zero Trust and modern Authentication like Fido at an enterprise scale. Tim is an active speaker at multiple conferences, advocating for secure and automated identity architectures.Tim Springston Tim Springston is Principal Product Manager for recovery solutions at Semperis. He has over 25 years' identity and security experience with education, government, and Fortune 500 organizations from around the world. In his 25 years at Microsoft, he led services and support for Active Directory and later for Microsoft's cloud identity platform as it evolved from Windows Azure AD to Azure AD. At Microsoft, he was a recurring speaker at internal TechReady conferences and external events. Prior to Semperis, Tim was Microsoft's product manager for Azure AD (now Entra ID) recoverability and Sophos' IAM product manager for the Sophos Central cybersecurity platform.Guest Quotes “The first step in resiliency is not just having a backup plan or a backup tool or capabilities to put things back. You need to know what's important to your organization. If you know what's important, you know what to put back, you know when it's broken.” - Tim Springston “If Entra ID is going down... This is business critical today. You're not available to sign in to Teams, to SharePoint, to Salesforce, to your business critical application. So to really understand Entra ID is business critical.” - Tim WolfTime stamps 0:40 Meet Tim Wolf and Tim Springston 2:32 The Microsoft Shared Responsibility Model for Entra ID 6:22 How Entra ID Tenants Are Being Attacked 8:45 Token-Based Attacks Explained 12:26 What Happens When a Threat Actor Takes Over Your Tenant 19:05 Microsoft's New Entra ID Recovery Solution 25:24 The Difference Between Accidents and Adversaries 28:54 Semperis' Disaster Recovery for Entra Tenant 39:27 Hard Delete and Tenant Cloning Limits 45:30 Resiliency Playbooks and Testing 49:58 Conclusion and Final ThoughtsSponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world's leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more.Links Connect with Tim Wolf on LinkedInConnect with Tim Springston on LinkedInConnect with Sean on LinkedInDon't miss future episodesLearn more about Semperis
Dan Adams is a 13-year Microsoft 365 and SharePoint veteran who joined Andrew to talk about the often misunderstood world of SharePoint, the shift to Microsoft Graph, and his custom PowerShell module built which can assess and benchmark M365 environments. Dan breaks down why SharePoint gets such a bad reputation (spoiler: it's usually about who built it, not the platform), explains why "everything in M365 is SharePoint" isn't just a meme, and digs into how the Microsoft Graph API is changing the way admins interact with the platform. He also shares his experience going from longtime podcast listener to first-time guest, and closes with some honest advice about reaching out to people in the community. Key Takeaways: SharePoint's bad reputation often comes from poor initial architecture, not the platform itself. Getting the information structure right at the start has downstream effects on everything from Copilot to Purview to legal compliance, and PowerShell automation is only as useful as the metadata you've set up to work with. The Microsoft Graph API is consolidating how everything in M365 is accessed. Where older APIs like the SharePoint client-side object model might count a batch of 100 items as 100 separate API calls, Graph treats that same batch as a single call, which is a meaningful difference for performance and rate limiting. Dan's custom PowerShell module (SP'r Smash Bros Automation) automates M365 permission extraction to produce security assessments against CIS benchmarks and Microsoft Secure Score. Built as a practical tool for consultants and admins, it delivers a fast, standardized baseline of a tenant's security posture, featuring an optional AI sidecar to instantly generate personalized remediation plans. Guest Bio: Dan Adams is a Microsoft 365 and SharePoint Architect with 13 years of M365 consulting experience. Leveraging deep SharePoint and strategic information architecture expertise, he has led teams to deliver over 40 Fortune 500 intranets across industries ranging from healthcare to the NFL. He is the architect behind multiple award-winning portals, including two Ragan "Best Overall Intranet" winners. Dan is also an AI enthusiast, an advanced PowerShell expert, and the creator of the custom "SP'r Smash Bros Automation" module for Microsoft 365. Resource Links: Dan Adams on LinkedIn: https://www.linkedin.com/in/dan-adams-10887650/ Dan Adams on Github: https://github.com/sprsmashbrosautomation Connect with Andrew: https://andrewpla.tech/links PnP PowerShell: https://pnp.github.io/powershell/ PDQ Discord Community: https://discord.gg/pdq The PowerShell Podcast on YouTube: https://youtu.be/OLsTaKC9GmM PowerShell Wednesday Playlist: https://www.youtube.com/watch?v=XQT8lrn8hhU&list=PL1mL90yFExsix-L0havb8SbZXoYRPol0B
Welcome to Episode 431 of the Microsoft Cloud IT Pro Podcast. In this episode, Ben and Scott get into why agent governance is quickly becoming one of the most pressing challenges for Microsoft 365 administrators. As agentic workflows become more common across Copilot, Copilot Studio, and third-party platforms, organizations are dealing with a sprawl problem that looks familiar but hits differently. Agents bring their own identity, data access, permissions, lifecycle, and security concerns all at once, and unlike traditional apps, a single user can now have dozens of agents acting on their behalf or autonomously across Teams, SharePoint, Exchange, and beyond. The episode walks through Microsoft Agent 365 as a starting point for building that control plane, including the agent registry, user and permission scoping, and the certification tab where publisher attestation gives some visibility into compliance claims though with notable gaps. Ben and Scott also touch on the Shadow AI preview in the Frontier program, the challenges of graph permission readability in the permissions view, and why the agent lifecycle problem, think what happens when the person who built a custom agent leaves the org, is something administrators need to start thinking about now before consumption billing turns an unmanaged agent into a surprise line item. Your support makes this show possible! Please consider becoming a premium member for access to live shows and more. Check out our membership options. Show Notes Overview of Microsoft Agent 365 Episode 409 – Preparing for Copilot- Securing Your Microsoft 365 Data and Beyond Episode 425 – Exploring Collaboration and Governance at the MVP Summit with Joy Apple Manage agents in the Microsoft 365 admin center Agent management in Microsoft 365 admin center Shadow AI in Microsoft 365 admin center (Preview) Understand agent details in Microsoft 365 admin center Sponsors Nasuni is a leading unstructured data platform for enterprises where file data is mission-critical for both people and AI. Nasuni powers the operational file layer where work happens — helping organizations manage, protect, and activate data so teams can work smarter, reduce costs, and operate securely without limits. TrustedTech is a leading Microsoft Cloud Solution Provider (CSP) specializing in Microsoft Cloud services, Microsoft perpetual licensing, and Microsoft Support Services for medium and enterprise-sized businesses. Their robust team of in-house, U.S.-based Microsoft architects and engineers are certified in all 6/6 Microsoft Solutions Partner Designations in the Microsoft Cloud Partner Program. M365 Licensing Consultation M365 Tenant Assessment Copilot Readiness Assessment ShareGate is your migration and governance solution for Microsoft 365. ShareGate helps your teams simplify tenant migrations, get Copilot-ready, and take control of Microsoft 365 governance. Intelligink — Would you like to become the irreplaceable Microsoft 365 resource for your organization? Let us know!
Technology should make accounting firms more efficient, but many firms have accumulated layers of disconnected tools that create complexity rather than clarity. In this discussion, Heather Smith is joined by Tyler Caskey from The Bean Counters and John Munden from Cloud Office to explore how firms can simplify their technology stack, improve workflow visibility, reduce manual work and make better technology decisions. Key Discussion Points Tyler Caskey shares why firms often accumulate too many disconnected tools and how visualising workflows can reveal inefficiencies. John Munden explains how standardised workflows help reduce bottlenecks, improve onboarding and create consistency across teams. The panel discusses common technology traps including decision fatigue, duplicated processes and underutilised software. Practical advice is shared on auditing a tech stack, identifying manual processes and prioritising integrations. The conversation explores leadership, change management, client communication challenges and the future role of automation and API-driven workflows. The key takeaway is that firms do not need more technology. They need better connected technology, clearer workflows and a structured approach to change. By focusing on visibility, automation and process consistency, accounting firms can reduce overwhelm and create scalable systems that support long-term growth. Episode resources and links: Tyler Caskey : https://www.linkedin.com/in/tylercaskey/ John Munden : https://www.linkedin.com/in/jmunden/ Cloudoffis : https://cloudoffis.com.au/ Apps & Tools Mentioned Xero, SharePoint, APS, Excel, Microsoft Lists, HandiSoft, BGL, NowInfinity, FYI Docs, Xero Practice Manager, Content Snare, Annature, Adobe Sign, DocuSign, Employment Hero, MYOB, QuickBooks, Stripe, Pinch Payments, Macquarie Bank Feeds, Mayday, Seamless If this episode helped you, the best way to support the show is to leave a review somewhere as it helps more people find us. And if you want to continue the conversation, come find me Heather Smith | Accountant and Storyteller on: LinkedIn: https://www.linkedin.com/in/HeatherSmithAU/ Accounting Apps newsletter: http://accountingapps.io/ Accounting Apps Mastermind: https://www.facebook.com/groups/XeroMasterMind YouTube Channel: https://www.youtube.com/ANISEConsulting X: https://twitter.com/HeatherSmithAU
In Episode 30 of the Guardians of M365 Governance, Joy, Ragnar, and Christian welcome Alan Cox, a fellow M365 MVP and independent AI and governance consultant, to discuss why organizations need separate AI governance and AI enablement functions to successfully scale adoption. Together, they explore the tension between risk management and innovation, and why treating these responsibilities as the same job often leads to poor outcomes. The panel examines lessons learned from SharePoint, Teams, and Power Platform deployments, and how those experiences apply to today's AI initiatives. They also discuss the growing impact of agentic AI and what organizations must do now to build an operating model that balances control, adoption, and business value.
In this episode of In-Ear Insights, the Trust Insights podcast, Katie and Chris discuss the release of Microsoft Copilot Cowork and its hidden financial implications for your business. You’ll learn how to calculate potential costs by categorizing your daily tasks into light, medium, and heavy workloads. You’ll discover how to apply the 5P framework to prevent runaway AI spending in your organization. You’ll identify specific strategies to optimize your workflows by separating planning from execution. You’ll explore how command-line tools can help you maintain efficiency without burning through expensive credits. 00:00 – Introduction 03:15 – Categorizing AI tasks 08:45 – The shock of the credit-based bill 14:20 – Applying the 5P framework for cost control 19:10 – Using planning to save money 25:30 – Call to action Watch this episode now to learn how to keep your enterprise AI costs under control before you start using Microsoft Copilot Cowork. Use the free Trust Insights Microsoft Copilot Cowork Cost Calculator! Watch the video here: Can’t see anything? Watch it on YouTube here. Listen to the audio here: https://traffic.libsyn.com/inearinsights/tipodcast-how-to-manage-microsoft-copilot-cowork-costs.mp3 Download the MP3 audio here. Need help with your company’s data and analytics? Let us know! Join our free Slack group for marketers interested in analytics! [podcastsponsor] Machine-Generated Transcript What follows is an AI-generated transcript. The transcript may contain errors and is not a substitute for listening to the episode. Christopher S. Penn: In this week’s In-Ear Insights, let’s talk about the newly generally available Microsoft Copilot Cowork, which is a licensed version of Claude Cowork. So Katie, you have spent a lot of time with Claude Cowork. You teach for Smarter X for their AI Academy on all the different uses of Claude Cowork. You’ll be doing an entire workshop at the Marketing AI conference on the Claude ecosystem and stuff like that. So when you hear that now Microsoft, the largest enterprise AI deployment system, has made effectively a copy of Claude Cowork available, what comes to mind? Katie Robbert: Endless opportunities. I have never met someone who is like, “Yay, Microsoft.” And we’ve talked about why a lot of companies are tied into Microsoft and a lot of it comes down to security and privacy. Chris, you have a whole series on enterprise AI, so enterprise AI not being the size of the company, but really more of the security and governance requirements needed. Microsoft as a workforce software, Microsoft 365, tends to check the most of those boxes, which is why so many large companies or companies in general tend to be tied into Microsoft. Which also means what we hear is, “Well, I can’t use Claude or I can’t use OpenAI, I can only use Copilot. I want all the bells and whistles that I’m seeing you guys talking about.” Very quick anecdote. My husband, who I’ve mentioned numerous times, is not a technology person—that is not the nature of his job—was lamenting that the new version of Microsoft is hiding all the replies to his emails from the entry-level user to the expert user. I don’t know anyone who enjoys using Microsoft, but I’m hoping now that this little bell and whistle is something that could bring people around on the users. Because Claude Cowork has been such a literal game changer for the way that I operate. The amount of things that I can get done that I couldn’t get done before because I’m just one person is infinite. Just the other day, I’ve always done the company financial projections—it’s very laborious. I have a spreadsheet, I have to check numbers from four or five different places. That’s something that Cowork can now not only help me with, but build an interactive dashboard for. And it’s like, “Yeah, you got multiple data sets, I got this, I can build that for you.” The amount of time it saves me is immense because it unlocks my time to do things like, “Hey, what’s a new target market we need to go after? What does that look like?” I didn’t have the brain space to do that before because I was so bogged down. So when I hear that Microsoft now has their version of Cowork, I’m like, “Wow, people are going to get so much done if they want to, if they see the opportunities within the software, if they’re curious.” Christopher S. Penn: If they can afford it. So that’s what I want to talk about on today’s show because Microsoft has released an Excel spreadsheet, of course, a calculator for how much Cowork will cost you because it is pay-as-you-go, it is not flat rate. So let’s talk about some of the tasks that you do, Katie. They define tasks in three categories: light, medium, or heavy. A light task is basically prompt and chat, no tool calls, one deliverable. And they classify this by the four different categories: corporate knowledge workers, customer-facing knowledge workers, technical workers, and managers and senior leaders. Now I would say that you are a manager and senior leader—I think that’s who you are, what you do. I am a technical worker. We have Kelsey who is a customer-facing knowledge worker—she’s our account manager—and we have John who is our corporate knowledge worker. John is our head of business development. So we actually check the box on each of these Cowork types of people. Now on a daily basis, Katie, you for sure have at least one Cowork process that calls more than one tool because you send out a daily update. So you have at least one of those that’s a medium-level task that sends up our daily sales report. What other daily tasks do you have Coworks have to do? Katie Robbert: I have Cowork Daily set up to send me a daily writing prompt. All it’s doing is writing to a Word document. I would imagine that’s a lightweight task. Basically, one of the things that I’m doing for my own professional development is I’m trying to make sure I don’t lose that writing muscle. As AI makes it so easy to replicate our voices, I want to make sure I don’t lose it. So I spend a few minutes every morning writing to a randomly generated prompt. So I would imagine that’s a lightweight thing. You mentioned the update that I send to the team. This is calling on our CRM data, and that I would imagine is sort of a medium because that’s only one piece of software. But once a month, I’m calling on our CRM and our financial data and a couple of other sources, so that would be a heavy task. So on a day-to-day basis, the scheduled tasks that I have are fairly lightweight. But then when I get into the real thinking, that’s when—so I was working on something this morning on behalf of the team. I was engaging a plug-in, I was engaging the Google Drive connector, I was engaging the Google Search connector, I was engaging that deep thinking of “put all this information together,” and all of the skills that are involved: the skill of building a Word doc, the skill of building a PDF, the skill of building an HTML interactive page, the skill of building a PowerPoint—all of those in one specific task. So I would say that is a heavy task, even though it looks at the surface like a lightweight task. Christopher S. Penn: I would say, and I think this is a fair characterization, you probably do two heavy projects a day in Cowork because you’re constantly doing deep strategy and things. So I’m going to put two a day—this is a monthly calculus—put down 60 there. Now for Kelsey, I would say Kelsey at least does at least one light and one medium task in Claude per day. I think it’s actually more than that, but I’m going to put that down as a starting point. What do you think? Katie Robbert: I think that’s a fair starting point. Christopher S. Penn: Okay. For me, I work in Claude code, which is slightly different, but since we’re just trying to get a sense of what Cowork will cost, I’m going to do the equivalent. On a day-to-day basis, I probably do five tasks that are light, so that’s going to be 150 of those a month. I probably do 10 tasks that are medium, so that’s going to be 300 a month. And I probably—actually, I know I do over 10 tasks a day that are heavy, that are like pure heavy code lifting. So that’s going to be another 300 there for John. John really doesn’t use Claude much at all, I don’t think. So maybe like 30 at most. Katie Robbert: Yeah, I think so. We have a skill that was built specifically with his role in mind, and he runs it maybe once every couple of weeks. When I look at the weekly tasks—so this is looking at a month at a glance—I would actually bump up the medium tasks for me because I have weekly reports that are run that engagement, the Claude Chrome extension, the connections to our CRM, connections to our project management software. I have eight of those weekly. Christopher S. Penn: Okay, so you’re basically running two mediums a day. Effectively. Katie Robbert: Yeah. Christopher S. Penn: Claude or Microsoft Copilot Cowork bills on what are called credits because why make this easy? Light tasks bill 125 credits, medium tasks bill 500 credits, and heavy tasks bill 1,200 credits. The cost is a penny per credit. So our Microsoft Copilot Cowork cost—are you ready for this, Katie? $1,600 a month. Katie Robbert: Get out. We’re going back to candlelight and whittling pencils. Christopher S. Penn: That is because it’s a penny per credit, which they do to make it sound cheap, not realizing that a single heavy task is 1,200 credits. So a single task is $12. So for me to do one QA run on a piece of software is swipe the credit card for $12. On a monthly basis, we are consuming effectively 657,000 credits, which is $6,570 total, all in. It’s $1,600 per user. So Katie, our Trust Insights Copilot Cowork bill is $6,570. Katie Robbert: I have no words. That is insane. And to be fair, so you and I, Chris, I would say are power users. We are turning to these tools to do all kinds of things all day long. Even with trying to do things and schedule them off-hours to not be during peak usage, we’re still using up usage. And yeah, we are a small team. If we take out the work that Kelsey does just for the sake of this example, you and I are still eating up the majority of the cost. If we take out you, I’m still eating up a majority of the cost. I don’t know how a company or team is supposed to be able to afford to use this. It’s a real bait and switch. Shame on Microsoft. Christopher S. Penn: Well, this is enterprise. They can do this. Katie Robbert: Yeah, they can. It doesn’t mean they should. Christopher S. Penn: So your usage, because a credit is a penny, your usage of Copilot Cowork a month would be $1,057.50. That is how much you consume in equivalent credits in the system. Now granted, we pay for the four of us to share a Claude Max 20 account; we pay $200 a month for it. This at the enterprise level, you’re talking four people, $1,600 for four people, one of whom barely will use it. Realistically, like you said, we’re probably going to average $3,000 an employee is what it will cost to use Cowork. Katie Robbert: Which is an insane amount. For some companies that don’t even blink at that, but that’s a very small handful of companies who would feel that way about $3,000 a month. One of the things that we’re doing with a lot of our clients right now is trying to help them find cost savings in their tech stack—like how many tools can they reduce or licenses they can let go of and replace with things like Claude Code or Claude Cowork. But if they’re like, “Yeah, I want to do that exercise,” and what I have is Microsoft Cowork, I would say, “Cool, we’re not doing that exercise until Microsoft changes the billing,” because it’s going to cost you 10x more than it’s costing you now. It’s not worth it. Which is a real shame because Microsoft users have been waiting for this kind of functionality. Christopher S. Penn: And so what I wanted to talk about on today’s podcast episode, now that we’ve worked out that this thing is going to cost you three grand a month—because one of the things that people have pointed out on LinkedIn is, “Oh great, you fired all these people so you can switch to AI; now AI is going to cost you more than the people did”—is how do we reduce AI costs? How do we use AI more efficiently? Because this is clearly a lot of money. Katie Robbert: If only we had a few things to start with. I’m going to shock and dazzle everyone and say, “Guess what? Start with the 5P framework by Trust Insights.” You can learn more about it at TrustInsights.ai/5P-framework. At a high level, the five Ps are: Purpose—what the heck are you doing? People—who the heck’s involved? Process—how do you do the thing? (These are your SOPs). Platform—what tools are you using? (Not just the AI, but also your external data sources). And Performance—did you do the thing? It sounds really straightforward because it is. However, a lot of people go straight to pushing the buttons and “vibe coding” and, “Hey, build a thing.” “What do you want it to be?” “I don’t know, you pick.” Without doing this work up front, yeah, you’re going to find yourself at $650,000 a month very quickly. There is no tool that allows you to skip over good planning upfront, good governance up front. Microsoft Cowork is no different from any other large language model in that you still need to have good requirements, you still need to have good prompting, you still need to have good governance, even if you’re just using it internally on your own systems. Enterprise companies, any company, has sensitive data somewhere within their SharePoint stack, within their databases, their document repositories. You don’t want to accidentally or carelessly give a large language model access to that because you didn’t plan ahead. So that’s my soapbox. I’m coming down off of it. Chris, what would you add to how to make AI efficient? Christopher S. Penn: So planning, yes, 100% is going to make the most of the tools you have. The other question is, given these outlandish costs, is Microsoft the right system for you to use? Because Claude in Anthropic’s enterprise level is just as expensive. Companies have recently seen their burn through their entire Claude usage for the year, their budget in weeks. I think it’s Uber that burned their 12-month budget in a month and a half in terms of their token budget. So when we look at these prices, Katie, you remember a while back I had said, “Hey, Nvidia’s got this cool little desktop box. It’s $5,000.” You’re like, “You’re not buying $5,000 worth of hardware.” Absolutely not. Now if Microsoft or Anthropic said, “Hey Katie, you need to pay us $6,500 a month,” you’d be like, “You know what, Chris, go and buy one of those boxes; let’s buy one for each of the team and we’re going to drop Anthropic because we are not paying $6,500 a month for AI.” Right? Katie Robbert: You know, and so it’s an interesting question because where we started the conversation was saying there’s a reason why people are wedded to using Microsoft because of the security and privacy. I don’t know that introducing an Nvidia box would comply with the regulations set forth by that company. I mean, that’s a big question. It’s an interesting workaround, but it’s not going to work for everybody, especially the more regulated the industry gets. It just might not be an option. Christopher S. Penn: Yeah, it’s going to very heavily depend on IT. However, because it lives literally in your infrastructure, you do have a lot more governance over it because it’s literally a box that sits on your desk that you control. But more importantly, today’s top local models match a lot of the cloud foundation models and capabilities. GPU AI’s new GLM 5.2 matches Claude Opus 4.8 capabilities. Now you’re going to need a few of those Nvidia boxes to be able to load and run it well for a small cluster of employees. But for the lighter models like Qwen 3.6 or Google’s Gemma 4 if you have to, or Nvidia’s Neotron Ultra if you have to use a US-based model because of regulatory reasons—like you’re not allowed to use anything Chinese, regardless of the fact that it’s on your infrastructure—those are options that you would then use a tool like Open Cowork to handle the inference for it. So my suggestion is that to Katie’s point, use the 5Ps and then drill down and say, “What are the things that we absolutely positively have to use Cowork for?” Or can we make that task as deterministic as possible using command-line tools and stuff that do not require AI? So for example, Katie, when you query HubSpot every day with Claude Cowork, that is using the MCP connector that uses a ton of tokens back and forth. Now we don’t see it because we’re on an individual plan. The moment we’re forced to switch to a team or an enterprise plan, we will say, “Okay, we’re going to use the HubSpot command-line tool which can fetch data in and out.” And then the AI just says, “Hey tool, give me the thing,” and it goes off and does the back and forth and brings the data back and hands it to the AI. That will dramatically cut the amount of AI usage you have because a non-AI tool is getting data for you. Katie Robbert: As you’re describing it, I want to sort of make sure I understand because you’re making it sound like it’s an easy switch from the process that I currently have built in Cowork to, “Okay, just use a command-line tool.” I’m not someone who’s well-versed in command-line tools. You’re someone who is. However, you have your own set of things to do right now. So it’s time. It’s internal resources to make those switches to make the cost savings. I just want to be clear about that; it’s not a, “Oh well, in order to save money, let me just go ahead and use a command-line tool.” Like you still have to set it up. Christopher S. Penn: Yes, and corporate IT will be very busy doing that. However, corporate IT also likes us because they can then govern it. They can say, “Okay, we will ensure that this suite of 10 command-line tools is installed on every computer in the company, and there’s a joint service key that we can maintain programmatically and rotate every 30 days and stuff like that.” So that infrastructure, which corporate IT is very well-versed in, is going to be much happier with that than kind of like the whole shadow IT where people are like, “Oh, I’ll just have Claude make me this thing.” No, they would much rather say, “I would like to have control over the command-line tools that are installed on every machine in the company.” Katie Robbert: So work that out. You’ve worked with IT teams before. How likely is it that they’re going to—if you say, “Hey, I would like to have control over the command-line tools on every machine in the company,” they’re like, “Yeah, sure, Chris, no problem. Let me bump you to the top of the list. You’re a priority now.” I think you’re going to have a hard time. Like, we see the value in it, we know that it’s a useful thing. I just want to be realistic, and I’m trying not to derail the conversation too much, but I just want to be realistic that, like, yes, that’s the thing. If you have the skills to do it and if you don’t have to go through your IT team to do it, absolutely do it. If you have to go through your IT team and they have to set it up, get comfy, get in line; you’re not a top priority right now. Christopher S. Penn: Yeah, well, my perspective is IT would want to do that. It would be like, “We would love to have more control over this to stop the shadow IT that’s happening all over the place because of AI.” So IT in its MDM config would say, “Okay, these are the 10 tools that we’re going to drop on every machine, and we’re going to also programmatically alter your Claude MD files and stuff to tell Claude this is what’s installed. You must use it so that it cuts those costs.” And IT can then say, “We certify these 10 command-line applications are safe to use.” Katie Robbert: Provided it has the time to get skilled up to do that. So yeah, I like to make sure that we’re very clear about caveats because in the 25 to 30 minutes we have for a podcast, we go through things like “do this, do this,” and then it’s, “Well, what do you mean? It said no.” So let’s get back to—Microsoft has started to release Cowork, their version of Cowork, and we’re talking about AI efficiencies. When you think about starting places for someone who’s using Microsoft, someone who’s using their Cowork version, what is the first thing you think somebody should do before they start burning tokens or usage or spending pennies? Christopher S. Penn: The five Ps, the planning, and build all of your prompts and all of your infrastructure for Cowork in regular Copilot, because regular Copilot is very smart. Now in regular Copilot, if you go in the upper right-hand side, there’s a little menu, a little drop-down saying “models,” and you should choose for planning. Choose GPT 5.5, soon to be 5.6—”think deeper,” that’s the smartest model that’s available. And say—and that’s where you have your conversation like, “Oh, I want to do this in Cowork. I don’t want to do this, I want to do this. Help me figure this out. Ask me questions. Let’s plan this out. Here’s the Trust Insights 5P framework. Help me use this to come up with these plans.” So you do all of your planning and all that heavy token usage in regular Copilot to build the skills and the pieces that you can then drop into Cowork, so you don’t have to use Cowork to plan because Cowork is going to chew up your usage. That way, if you can use regular Copilot, it should be a little bit lighter on your budget. Katie Robbert: And I think one of the questions that you should add into your planning is, “Can I do this in Copilot or do I need Cowork for this?” And you know, I want you to use your human judgment, but it would be a good idea to ask the large language model like, “Do you have the capabilities to do this within Copilot or do I need to bring this into Cowork to actually execute it?” Because you may be surprised. You know, to Chris’s point, the models are getting smarter every day. And so you may not need to execute what you think you need to execute in Cowork; you may be fine with using Copilot. Yes, I get it’s not as shiny and as exciting, but you know what’s also not exciting? Being told you owe the company $60,000. That’s not exciting. Christopher S. Penn: Exactly. Even for something like scheduled tasks—Microsoft Copilot tasks are scheduled tasks—so if it’s not something that needs Cowork’s horsepower, that will obviously keep you from chewing up those extra credits over there. Katie Robbert: Yeah, and I think that’s a good best practice for a lot of these tools, you know? So can you do your planning in Claude Chat before bringing it into Cowork? Can you do your planning in Gemini before bringing it into their version of whatever that is? And that’s just a good best practice for efficiency in general. Christopher S. Penn: Yeah, I mean, when I do my planning for even software builds and stuff like that, the first thing I do is I have a master planning prompt. It’s actually a skill that incorporates the 5P framework by Trust Insights. And so I have the model ask me questions from the 5P framework: “What are you doing? Who’s it for? How should it work? What are the additional command-line tools that we should be using? What is the definition of done?” And all of that is stuff that if I don’t dictate it out loud, it knows to ask me for it. So I can plan first, and then the language model rebuilds the prompt into something that meets all of those conditions and produces a really solid output that I can then go use to build requirements documents and all the stuff. You will save so much time and money by investing more heavily in planning up front, and you can then hand off the execution of the plan to a very small, fast model. Katie Robbert: And I think that’s a really good pro tip. And I just want to give a small plug—you can actually download, we have for sale in our academy at Academy.TrustInsights.ai, a “prompt-to-skill.” So basically, as Chris was just describing, he has a specific process for building those requirements. This prompt-to-skill will help you do that and get more efficient at building those requirements. And then what you may find that you have is a reusable template, and it makes that even more efficient. So start with that. Go to Academy.TrustInsights.ai, purchase the prompt-to-skill—it’s very awkward to say that—and then start building out those requirements before you bring it into something like Cowork. And you’re going to save yourself a lot of time and money, and people are going to be like, “Wow, you did that really fast. How did you do that?” And you’ll be like, “I don’t know, I’m just that good.” But in the back of your mind you’re like, “I use the 5P framework by Trust Insights. It got me there faster.” Christopher S. Penn: Exactly. So Copilot Cowork from Microsoft is now generally available. Before you type one character into it, please take the time to use the 5P framework by Trust Insights. Take the time to understand what your company has budgeted. Take the time to understand what tasks fall in each category, and as best as you can, try to reserve it for the things that truly need Cowork’s capabilities. And don’t just make it the default. If you’ve got some thoughts about the new Microsoft Copilot Cowork that you want to share, pop by our free Slack group. Go to TrustInsights.ai/analytics-for-marketers where you and over 4,700 other marketers are asking and answering each other’s questions every single day. And wherever it is you watch or listen to the show, if there’s a channel you’d rather have it on instead, go to TrustInsights.ai/TI-Podcast. You can find us in all the places fine podcasts are served. Thanks for tuning in. We’ll talk to you on the next one. Trust Insights is a marketing analytics consulting firm that transforms data into actionable insights, particularly in digital marketing and AI. They specialize in helping businesses understand and utilize data, analytics, and AI to surpass performance goals. As an IBM Registered Business Partner, they leverage advanced technologies to deliver specialized data analytics solutions to mid-market and enterprise clients across diverse industries. Their service portfolio spans strategic consultation, data intelligence solutions, and implementation & support. Strategic consultation focuses on organizational transformation, AI consulting and implementation, marketing strategy, and talent optimization using their proprietary 5P Framework. Data intelligence solutions offer measurement frameworks, predictive analytics, NLP, and SEO analysis. Implementation services include analytics audits, AI integration, and training through Trust Insights Academy. Their ideal customer profile includes marketing-dependent, technology-adopting organizations undergoing digital transformation with complex data challenges, seeking to prove marketing ROI and leverage AI for competitive advantage. Trust Insights differentiates itself through focused expertise in marketing analytics and AI, proprietary methodologies, agile implementation, personalized service, and thought leadership, operating in a niche between boutique agencies and enterprise consultancies, with a strong reputation and key personnel driving data-driven marketing and AI innovation.
Summary Law firms and legal departments sit on mountains of electronically stored information, and most have no real system for dealing with it. Warren Parrino, Regional Vice President of Solution Sales at TrustPoint.One, has a clear starting point: email threading, date filters, and search terms. From there, an early case assessment environment can cut review costs before a single document hits a reviewer's queue. Warren and Jared also cover modern attachments, audio and video redaction, and when AI actually earns its place in the workflow. The bottom line: AI only pays off after you have already done the basics. Crawl, walk, then run. About the Guest Warren Parrino is Regional Vice President of Solution Sales at TrustPoint.One, an e-discovery and legal services company. A former practicing attorney in Birmingham, Alabama, he most recently co-led the company's project management team before moving into his current role, giving him a view from both the operational and client-facing sides of a project. He still holds his bar license, attributing that decision entirely to how hard the exam was. Key Takeaways Start with email threading, date filters, and search terms before anything else. These three basics narrow your data set before you spend a dollar on document review. Early case assessment (ECA) databases are the single most effective way to cut e-discovery costs, yet most firms skip them because they have never heard of the approach, not because of cost. Modern attachments (hyperlinked files stored in OneDrive or SharePoint rather than attached directly to email) are the biggest current landmine in discovery, though workable solutions are emerging. Audio and video redaction that once cost thousands of dollars and required a production team can now be done at a desk in minutes using off-the-shelf tools. AI in e-discovery only delivers real savings after you have already cut your data set down. Throwing AI at a terabyte of raw data inflates your bill, it does not shrink it. Links and Resources TrustPoint.One: trustpoint.one Red Cave Law Firm Consulting: redcavelegal.com Keywords e-discovery, ESI, electronically stored information, early case assessment, ECA, email threading, modern attachments, hyperlinked files, data management, RelativityOne, shadow AI, legal technology, law firm data, e-discovery costs, solo practitioner, small law firm, audio video redaction, document review, TrustPoint.One, e-discovery consultant Episode Highlights [00:03:49 - 00:04:46] Warren lays out the three starting points for any firm overwhelmed by data: email threading, date filters, and search terms, in that order, before anything else. [00:05:56 - 00:08:13] Warren explains early case assessment, how it works in RelativityOne, and why communications analysis often surfaces the witness you never knew you needed. [00:08:13 - 00:09:02] The reason most firms skip ECA is not cost. It is lack of knowledge, because if cost were the issue, everyone would already be doing it. [00:09:08 - 00:10:44] Email threading today means reviewing one file instead of 15. It is not the labor-intensive process it once was, and the savings in time and cost are significant. [00:11:19 - 00:12:54] Modern attachments (hyperlinked files in SharePoint or OneDrive) create versioning, custodian, and association problems that traditional e-discovery workflows were not built to handle. [00:14:59 - 00:17:28] Audio and video redaction that once required a production team and thousands of dollars can now be done with off-the-shelf software at a desk. Warren shares a real transit authority case. [00:20:33 - 00:22:14] There is no minimum data threshold for engaging an e-discovery consultant. The only question is whether the hassle of managing the data yourself outweighs your willingness to deal with it. [00:24:33 - 00:28:06] AI in e-discovery is real and capable, but it only delivers savings after you have already cut the data set down. Warren describes what Relativity's AIR tools can do once the groundwork is done.
The boys start off with an AI created intro, Marijn gets winded up about the use of "and honestly" he sees everywhere, Steve talks about lady gardens, but they are interrupted by a ruckus on the street. Thank goodness there is a Danish Dirty Bastard!
A new way to organise your OneDrive shortcuts as you create them. An agent that helps you plan with natural language. And the new Anthropic model, Claude Fable 5... yeah, about that...!? 0:00 Welcome 2:20 OneDrive: New Shortcuts folder option when adding shortcuts - MC1385585 9:03 Microsoft Teams: Governance for built-in agents in the Teams admin center - MC1387573 11:58 Microsoft 365 Backup: Full workload backup for SharePoint, OneDrive, and Exchange - MC1387526 16:32 Microsoft Planner: Planner Agent chat coming to Frontier - MC1387810 22:16 Anthropic Claude Fable 5 available in Copilot Cowork (Frontier) - MC1387806 28:01 Microsoft Teams: Granular channel notification settings - MC1388719
Use enhanced Teams panels to book desks. Be aware that OneDrive retention will be enforced soon for unlicensed OneDrive accouts. Lastly, Microsoft Scout, powered by Open Claw, enters the AI scene. 0:00 Welcome 3:26 SharePoint Pages: Updates to the Toolbox within the Content pane - MC1326507 7:00 Pay-as-you-go consumption-based meter for your extra SharePoint storage needs - MC1330893 11:17 Microsoft Teams: Enhanced bookable desk experience with Teams panel based desk devices - MC1330887 14:47 OneDrive: Retention enforcement for unlicensed OneDrive accounts - MC1381110 22:56 Microsoft 365 Copilot: Introducing Microsoft Scout, an always-on personal agent - MC1332811
Unmet generative AI promises, flatlining ROI dashboards, and a relentless corporate appetite for unguided technological progress. By all logic, one would assume we'd take a strategic pause to change course and build foundational human competence. Instead, in a desperate panic, we're witnessing the birth of "AI agent sprawl,” autonomous activity deployed without a map, GPS, or off-switch. This week, I examine what happens when companies try to use autonomous AI as a strategic shortcut to force unfulfilled promises into reality, and how it's fracturing their operational architectures and budgets. You'll see why we have to move past the open-ended rollout hype, put a full stop on unmanaged agental capabilities, and install strict human oversight mandates before these tools trigger a catastrophic bottom-line crisis. My goal is to get you off cruise control by highlighting the following opportunities to protect yourself and your organization:Deconstructing the Autonomy Sliding Scale: We need to stop treating AI agents like a mythical, binary technology that just arrived from space. Autonomy is a volume knob we've been turning up for decades. The real danger occurs when you spin that dial to a ten, completely relinquishing task-by-task control to a digital intern running continuously on autopilot without verifying if your structural architecture can handle the noise. Exposing the SharePoint Trap with Fangs: In the cloud migration era, corporate America turned on SharePoint thinking "what's the harm," only to create an unmanaged jungle of duplicate data and orphaned sites that acted as a silent productivity torpedo. Agent sprawl is that exact same mistake on steroids because a messy SharePoint folder couldn't rewrite your product codebase, communicate with your clients, or execute legally binding corporate spend decisions. Agents can, and left running on autopilot after an employee leaves, they become an invisible, permanent liability. Halting the Autopilot Spend Shock: The financial consequences of ungoverned agent loops are hitting corporate balance sheets hard, mimicking the familiar spend shock of dictionary-thick cell phone bills from the early 2000s. I highlight some recent examples like Uber vaporizing its entire annual AI budget in four months due to recursive agent rework loops, Microsoft aggressively clawing back developer licenses, and a jaw-dropping $500 million single-month bill racked up by an enterprise trapped in an infinite loop. By the end, I hope you're convinced the solution isn't about stopping technology. It's about halting the wide-scale rollouts to reinvest heavily in human AI competence. We must move past the vendor hype, place the right people in the right loops at the right times, and establish the disciplined guardrails required to surgically agentize our operations safely. ⸻If this conversation was helpful, make sure to like, share, and subscribe. You can also support the show by buying me a coffee at https://buymeacoffee.com/christopherlind And if your organization is wrestling with how to balance performance, technology, and people, see how I can help at https://christopherlind.co ⸻Chapters00:00 – From Tokenmaxxing to the Silent Epidemic of Agent Sprawl03:00 – The Strategic Shortcut: Why More AI Doesn't Fix Flatline Hype04:30 – Demystifying the "Agent" Tech Jargon10:30 – The SharePoint History Lesson: Anarchy in the Cloud16:15 – The 2026 Spend Shock: Inside the Uber and Microsoft Budget Crises19:50 – The Contrarian Position: Why I Discourage Wide Agent Rollouts21:45 – Action 1: Applying the Full Stop to Enterprise Agental Capabilities23:00 – Action 2: Shifting Tech Budgets to Human AI Competence24:15 – Action 3: Involving Power Users for Surgical Agentization27:00 – Conclusion: Autonomous Operational Self-Termination #AgentSprawl #AIStrategy #OpEx #TechTrends #FutureFocused
Hosted by David Cowen | Careers and the Business of Law David Cowen sits down with Bobby Malhotra, litigation partner and chair of Winston's eDiscovery and Information Governance practice, member of the firm's AI strategy group, and founding member of Legal Data Intelligence. Bobby sits at the intersection of eDiscovery, digital forensics, cross-border data, privacy, cybersecurity, information governance, and AI governance, bringing a rare combination of legal judgment, technical fluency, and hands-on curiosity. This conversation covers why AI governance has arrived, why information governance is making a comeback, and why the next generation of legal professionals will need to become tech-and-data lawyers. WHY THIS MATTERS? AI governance is no longer a future issue. It is already here. Companies are dealing with employee use of public AI tools, data exposure, privacy risk, cybersecurity concerns, regulatory pressure, AI policies, privilege questions, AI transcription, and AI-related incidents. For lawyers and legal professionals, this is one of the clearest career white spaces in the market. KEY TAKEAWAYS AI governance has arrived. It is already one of the hottest and busiest areas in the legal industry. AI governance is about vision, guardrails, policies, ethical obligations, legal obligations, regulatory compliance, and business risk. Information governance is the backbone of AI governance. You cannot govern AI if you do not know where your data lives. Data governance sits inside AI governance, and may be the most important part of the whole program. The legal role is expanding, not shrinking. AI governance and data governance are creating new career lanes across law firms, corporate legal departments, privacy, cybersecurity, eDiscovery, and legal operations. You do not need 20 years of AI governance experience. No one really has that. Curiosity, teachability, issue-spotting, and legal judgment matter more. The best professionals in this space combine legal thinking with technical literacy. It is not just about knowing the tools. It is about applying the law to the facts, the technology, and the risk. AI governance is not just about models anymore. It now includes privilege protection, AI transcription, employee AI usage, public AI tools, data exposure, and AI-related breach scenarios. Outside counsel and in-house teams both have a role. Some companies rely heavily on outside counsel, while others use outside counsel for strategy, policy review, sanity checks, regulatory guidance, and high-risk questions. If you want to build a career in this space, get comfortable being uncomfortable. Follow the law. Follow the technology. Find mentors. Set up news alerts. Stay close to communities like LDI and IAPP. PEOPLE MENTIONED David Cowen - Host Bobby Malhotra - Litigation Partner; Chair of eDiscovery and Information Governance; AI Strategy Group Member; Founding Member of Legal Data Intelligence Melanie Prevost - Referenced in connection with career creation and emerging opportunities Malcolm Gladwell - Referenced in connection with the 10,000-hour rule COMPANIES & ORGANIZATIONS MENTIONED Winston - Bobby's firm Legal Data Intelligence / LDI - Community and framework for legal data professionals IAPP - AI governance and privacy education resource CLOC, ILTA, SOLID - Legal operations, innovation, and business of law communities M365, SharePoint, cloud platforms, data lakes, and metadata - Referenced as examples of where organizational data lives Colorado, Connecticut, Illinois, California, and Texas - Referenced in connection with emerging AI legislation EU AI Act - Referenced in connection with AI regulatory obligations NAIC - Referenced in connection with AI guidance in the insurance industry New York DFS - Referenced in connection with regulated financial institutions
Recorded live at PSConfEU 2026, Andrew sits down with returning guest Miriam Wiesner, Senior Security Researcher at Microsoft, for a wide-ranging conversation on PowerShell security, cookie-based attacks, and the evolving threat landscape. Miriam walks through her two conference talks — one on Microsoft Teams session cookie hijacking (a follow-up to her 2025 Entra ID cookie talk, complete with Cookie Monster branding and actual handcuffs), and a joint session with Stéphane van Gulick on using Microsoft Defender's Live Response feature for incident investigation. The conversation also covers the current state of PowerShell security, why sophisticated attackers are moving away from PowerShell, and why defenders who haven't enabled script block logging and AMSI are leaving easy wins on the table. On top of the technical deep dive, Miriam and Andrew get into the human side of the conference community — nerves before presenting, imposter syndrome, and why showing up is already half the battle. Key Takeaways: Cookie-based identity attacks are an active and growing threat. Microsoft Teams, SharePoint, and OneDrive share session cookies, meaning a single cookie theft can give an attacker broad access across your organization's collaboration tools — no re-authentication required. Sophisticated threat actors are moving away from PowerShell specifically because its security features work. Script block logging, AMSI, and Constrained Language Mode make PowerShell activity highly visible and detectable. If your org hasn't enabled these, you're handing attackers an easy path. Visibility beats prevention. You can't prevent what you can't see. Detection through proper logging is not a consolation prize — it's a core security strategy, and Microsoft Defender's Live Response feature gives teams a powerful way to investigate isolated endpoints without needing RDP or PowerShell remoting enabled. Guest Bio: Miriam Wiesner is a Senior Security Research Program Manager at Microsoft with over 15 years of experience in IT security, penetration testing, and security automation. She works on research behind Microsoft Defender and Sentinel and is the creator of widely used open source PowerShell security tools EventList and JEAnalyzer. Miriam is a sought-after speaker at major security and PowerShell conferences including Black Hat, PSConfEU, and MITRE ATT&CK Workshops. She's also the author of "PowerShell Automation and Scripting for Cybersecurity," published by Packt. Her conference speaker career started at PSConfEU 2018 and she's been a fixture of the community ever since. Resource Links Miriam's 2025 Cookies talk - https://www.youtube.com/watch?v=8xDcq0pPNPs Book – PowerShell Automation and Scripting for Cybersecurity (Packt): https://www.amazon.com/PowerShell-Automation-Scripting-Cybersecurity-Hacking/dp/1800566379 Miriam on LinkedIn: https://www.linkedin.com/in/miriamwiesner Miriam on X/Twitter: https://x.com/MiriamXyra Miriam's GitHub (EventList, JEAnalyzer, and more): https://github.com/miriamxyra Miriam's Website: https://miriamxyra.com Connect with Andrew: https://andrewpla.tech/links The PowerShell Podcast on YouTube: https://youtu.be/zxJOqcEwgWE
What happens when an AI agent inside your company starts behaving like an insider threat? In part two, Steve Moore picks the thread back up with former FBI operative Eric O'Neill to explore how agentic AI is rewriting cybersecurity, the legal traps that follow a breach, and why the modern CISO must think like a spy hunter.Eric opens with a sobering reality: ransomware victims who decline to pay are re-attacked at staggering rates. He explains why criminals treat cybercrime as a business, invest weeks in reconnaissance—mapping SharePoint, harvesting file trees, and studying access patterns—and why a botched recovery hands them the same door twice.The conversation turns to the new insider threat hiding in plain sight: rogue AI agents. Eric shares a real case in which one executive's casual query exposed the next round of layoffs and triggered coordinated lawsuits. They unpack how agents inherit excessive access, how attackers hijack them once inside, and why organizations are now building insider-threat programs to monitor AI behavior.Eric argues AI is an accelerant on every unresolved problem—weak identity management, entitlement drift, missing asset inventories, and absent data classification. They debate whether IT and security should be unified under the CISO, why the CISO needs a direct line to the board, and the legal landmines that follow a breach, from cyber insurance to the “reasonable steps” standard.The episode closes with Eric's advice for any new CISO: put “spy hunter” on your resume. Counterintelligence, not perimeter defense, is the discipline that wins today. Tune in for part two of a story-driven conversation on why preparation, mindset, and threat hunting beat any single technology.Key Topics• Why ransomware victims who decline to pay get re-attacked• How attackers map SharePoint, file trees, and access patterns• The new insider threat: rogue and hijacked AI agents• A real case of an AI agent exposing an HR layoff list• Shadow IT and the cost of banning AI outright• Permission structures and second-level reviews for agent actions• Why AI exposes gaps in identity, asset, and data classification• Unifying IT and security under the CISO• Why the CISO needs a direct line to the board• Legal traps: cyber insurance, reasonable steps, and missed alerts• The CISO as counterintelligence officer and spy hunterGuest BioEric O'Neill is a former FBI counterintelligence operative, attorney, and bestselling author who helped bring down Robert Hanssen—the most damaging spy in FBI history. He is the founder of NeXasure AI and co-founder of The Georgetown Group, and his undercover work was dramatized in the film Breach. Eric is the author of Gray Day and Spies, Lies, and Cybercrime.Connect with Eric on LinkedIn or at ericoneill.net.GET A DEMO:
We've informally heard that Satya is a listener to LS for a couple years now, but it was still absolutely surreal to meet him and do a live pod at Build, together with our friends at No Priors, the leading VC AI Podcast that we also greatly admire!We covered the MAI model technical takeaways on yesterday's AINews, so I will focus our recap of Satya's main messages around three elements:* Satya's adaptation of the Bill Gates Line for positioning Microsoft as the Frontier Intelligence Platform — customers must gain much more value from the Microsoft ecosystem than Microsoft itself, by building on multi-model harnesses like OpenClaw and Scout, drawing on the full enterprise context exposed by context layers like Work IQ (heavily dogfooded by his C-suite), and building up private evals and traces as a new form of Token IP* AI ROI: On one hand, enterprises are having difficult conversations around Tokenmaxxing and Layoffs, and on the other hand, there are serious re-evaluations of the End of SaaS since the Build vs Buy equation has changed so much. Our previous SemiAnalysis guest had… interesting comments on Microsoft's position on this as the ur-SaaS titan, and Satya had great answers* Making the Impossible Possible: Kevin Scott's inspiring framing around what the most ambitious version of applying AI and technology at large to business and social problems, like education and social impact.Enjoy!Full VideoTranscriptVoiceover: Welcome swyx, Sarah Guo, Elad Gil,, and Chairman and Chief Executive Officer of Microsoft, Satya NadellaSarah Guo: Welcome to a crossover episode of No Priors and Lane Space with Satya Nadella. Um, congratulations on an amazing build. No, thank you so much, and it's great to be with both of you. I listen to both of you or b- both the podcasts all the time. It's great to be on it.Thank you so much. [00:01:00] So you're just talking about, um, these amazing, uh, announcements from across the Microsoft estate all morning for, I think, three hours. What is the, uh, what's the most important reflection or takeaway you have?AI as an Ecosystem PlatformSarah Guo: I, I'd say there are, uh, perhaps the, the biggest one for me is let's sort of conceptualize this more as an ecosystem play as opposed to a single model or even a single platform, right?Satya Nadella: I mean, you know, whatever I... At least for me, having grown up at Microsoft, having seen, whatever, four major platform shifts, uh, I sort of fall into that, um, uh, camp where a platform is defined by fundamentally its ability to create more value about the platform versus what's captured in the platform. And so if you, you view what's happening right now, I think this morning's keynote was how can any company, whether it's an AI native company or a traditional enterprise company, participate as a first-class participant where they can point to AI they created, [00:02:00] right?It's not that they don't use other people's AI. Of course they will. But to me, what's the path? What's the recipe? How do I do it? What does a stack look like? What does the tooling look like? What is valuable? How do you do that? That's it. That's sort of our job to do. Yeah. Ecosystem strategy is, uh, very complicated, right?Sarah Guo: Because you end up building certain components, partnering for certain components, supporting them. You just announced this big suite of models. Like, tell us a little bit about the, uh, training strategy for Microsoft now. Yeah.MAI Models & Training StrategySarah Guo: So, so the thing that we wanted to do with the MAI models was to build, and as Mustafa talked about, first of all, a great lineage, right?Satya Nadella: Starting with pre-training, uh, with very good data quality, uh, doing all the ablations, making sure because in, in some sense it's becoming even harder to build a clean lineage model just because there's so much stuff out there, uh, that you truly need to ablate out to be able to have a fantastic [00:03:00] pre-trained model.In fact, that's one of the challenges of a lot of the open weight models is they look great on one benchmark or two, but they're not great on practice. So that's why, in fact, even in the RFDEs are, they, they are pretty gone really excited about these MAI models because how the heck can a small five B model hill climb?Uh, and it goes back a little bit to what I think is ultimately the key thing to do, which is try to pursue finding that cognitive core. Uh, so to me, starting with a clean lineage- Then creating that ability for companies to be able to use this, right? Not just as a generalist, but to create their own specialist by building this hill climbing scaffold around it, right?So it's not just the model, but you have a hill climb scaffold around it, then you will start building your RLE. You will start collecting the traces. Most importantly, you'll have private evals because we know all the evals out there are good, interesting, [00:04:00] but they're not really that critical- They're work, yeahSwyx: at this point because they all can be maxed. And so the point is each company will have its own private eval. And so that end-to-end platform story around our models is sort of, uh, what I think is interesting. And then the one other thing, Sarah, since you brought that up, is I do feel there's a new frontier.Satya Nadella: Like people talk about the frontier and are you operating at the frontier. Um, interestingly enough, if you add a little temporality to it, you can use, let's say, in, in, in fact, the, the Lando Lakes demo we showed was pretty cool. We used, whatever, GPT-55, right? Then you collected a bunch of traces, and then you took a 5B reasoning model and achieved higher.Sarah Guo: Uh, so that is another aspect of what it means to appear... uh, you know, operate at the frontier Yeah. I, I think, uh, I first of all have to congratulate you on basically building a frontier neo lab inside of Microsoft in two years. Um, I'm wondering, you know, you have all this AI strategy that you're rolling out.Lessons from Two Years of AI DevelopmentSwyx: I'm wondering, what do you know now that you wish you would tell yourself two years ago where- or two or [00:05:00] three years ago? Three years for the Jensen partnership, two years for, uh, MEI. Yeah, I mean, I think the, the thing when, that I reflect quite a bit, right, which is sort of obviously I got into all this when I got excited by the, the scaling laws paper and, you know, when, you know, even the OpenAI partnership came about when those folks said, “Hey, we're gonna really throw a lot of computer transformers.”Satya Nadella: Uh, and they've helped. I- the thing that I always look back and say, “Wow, these things, uh, do have capability that they're climbing up.” W- I mean, this, you know, this crude way of saying it is intelligence is log of compute kind of works. Now what I think we underestimated perhaps is the real-world complexity of deploying these so that they actually deliver the value in the real world, right?So the outcomes as measured by any benchmark is interestingly important, but the true eval is when people out there are able to do unique things that they only can value, and it's very [00:06:00] measurable, right? That I wish we had sort of even, like, had more in our consciousness, right? Which is as an industry.Sarah Guo: Because right now I think when people say, “Wow, I don't want a token max,” it's an artifact of us not having thought ourselves as an industry that we are using tokens to create value every step of the way. So I think that's kind of what I wish we had gotten there, but I'm glad we are here.Real-World Value & Use CasesSarah Guo: What are some of the use cases that you've seen that have created the most value for your customers?Because I know that people talk a lot about code, and I think it's pretty clear that that's something that's having very large scale impact. Are there other areas that you find in common that your customers are really benefiting from? Yeah. I think, yeah, to your point, obviously coding is now got... But it's interesting, by the way, Elijah, to even talk about the coding, right?Satya Nadella: Which is coding has worked so well that we now have to rebuild the IDE, right? I mean, it's kind of nuts to see what we sh- launched is like, oh my God, I have these hundred agent sessions. I... The cognitive load it transfers back to me as a human is so [00:07:00] excessive that now I need a new UI. Uh, oh, by the way, I, like the, the chat as the only artifact was also impossible, so that's why we need a canvas.So it's kind of interesting for all the things about where is software needed or where is UI needed, uh, you kind of need that even for code, right? In a fully agentic world. But that said, one of the things that we are starting to see, we started seeing with co-work, but even some of the work we, we showed with auto com- uh, um, autopilot Right on what you see with claws is a good one because if you sort of think about a lot of human capital is doing the glue work, right?If you now can augment that with tokens/agents that are long-running, durable, right, then your ability to scale even what is still judgment and glue work gets amplified like coding does. Uh, so you can... Like, I'm positive that six months from now we'll all be saying, “Oh, wow,” like, all through ni- the night there was a bunch of stuff that [00:08:00] all these autopilots that I have working on my behalf with my delegated authority, so to speak, right?I can... Sort of given even my identity, did a bunch of work, then of course I'll need my new ADE to say, “Well, what did you do?” Like, I might... “Did I do this work?” And so on. So I think that that's where compressing of workflows, uh, completing of tasks, uh, that's where I think a lot of the value gets created. I think you raised a really interesting point, which is there's the actual agent that's doing the code, and then there's a harness around it, and that's the environment, that's the context, that's everything you're setting up as a developer around actually a coding agent.The Harness Concept for Enterprise AISarah Guo: What is the harness for the enterprise? Is there an equivalent concept for broader productivity work, or how do you think about that concept sort of generalized? That's right. So, so in some sense you kind of want the harness to define the models, the, the data, uh, and the tools, and so that you have a loop across those three.Satya Nadella: And so what we are trying to, first of all, make sure is each of our products that we build, right, whether it's GitHub Copilot or the security copi- the, the [00:09:00] stuff we showed with MDASH or even the discovery for science, it doesn't matter, all of them are multi-model harnesses, um, with tools access so that you can do this progressive, uh, disclosure of tools even so that they're token efficient.Uh, and then you're feeding it with very rich context because that's sort of the other hard lesson we have learned in the last two years is, oh my God, the amount of work you need to do to prep the context layer, uh, such that your plan can execute in the most efficient way is where the magic is. So we have, in our case, we have the GitHub harness, which essentially we're using across all our products.It's available in Foundry, and we are open, like you can use your Llama harness, whatever. Or you can use the, um, uh, you know, any open harness or any harness of yours and train with your tools and multiple models and your context. And so that's the pitch. Because right now a lot of dialogue is, um, “Hey, if I train the harness plus tools and the model together, you get [00:10:00] evals.”Elad Gil: And what we are proving out is... And the best example of that is what we did with MDASH, right? Because when it launched, uh, it found bugs or vulnerabilities that were not found by Mythos Uh, and so there is existence proof, I would claim, that you can have a multimodal harness, uh, that can in fact be more, uh, performant in the real world So a premise behind the, uh, training at the independent frontier labs is really, you know, we're gonna have these models, and we'll have an API business, and we'll support enterprises and startups.Sarah Guo: ButPlatform Strategy & Developer EcosystemSarah Guo: a first-party product, be it productivity or code or search, drives the majority of revenue. That's a different value equation than you're describing, I think, with the Microsoft ecosystem. Uh, if, if that's the case, tell me if it's the case, uh, ‘cause obviously you have first-party products and you have enablement products.Satya Nadella: Um, what is the role of the develop- Like what is gonna be hard and the set of skills and the value capture the developer has in that world? Yeah. So I think that there's always [00:11:00] gonna be the case that someone who is super successful in- as a platform builder can also have first-party products. It was true with Windows.It is true, uh, with, uh, the, the SaaS side and the cloud side as well with us and others and so on. But the thing that is, is it should not be a limiter to other people achieving that same success, right? That I think is the core difference, which is the, the network effects this time around, around intelligence are such because they learn from data, and not really lots of data.It's just a few samples that you have to see to understand what's novel about something. So that's why the game becomes how to protect. So that's why I would say every company, having private evals may be the biggest IP, right? Think about it, like what's that private eval that you can then use even a frontier model to hill climb on and not leak the traces may be one of the biggest [00:12:00] drivers, uh, of IP.Like, so in other words, another te- acid test is you have an eval that's private. You're using, uh, a g- a Model A. Can you switch it to Model B and e- you know, climb up? If you can, then you're in control. If you can't, you're not in control, and that's where even the harness decision becomes super important, right?swyx So therefore, having an open harness, letting all models come in, having your evals, your context, your tools help you hill climb, I think is the skills that an AI native startup needs, a SaaS company needs, or every enterprise needs. Yeah, I think in, in a very real way you are ... Microsoft historically is an operating systems company and th- then become a cloud company.Maybe like the third act is that you're a harness or evals company. Whatever w- ... whatever the, the sort of conglomerate of concepts that you wanna put together. Um, and, and I think like enabling every company to have like frontier intelligence or what- what- Yeah ... I forget the, the [00:13:00] exact term that you used, um, is the, is the mission, right?Satya Nadella: That's it. Like that is, that is the platform promise, that you build with us, you will get your intelligence, uh, for your data. That's it. That ... To, to me, that is the ... Like if there was one tagline, uh, for this entire developer conference is- Can everybody operate at the frontier with their frontier intelligence, right?To me, that is so important because otherwise it, I, I don't know how you achieve stable equilibrium, right? Which is how do I then go and say, “Well, my company is gonna have a terminal value because I now know how to continuously compound-” Yeah ... on top of what's a platform that gets better,” right? So when, like Windows obviously came out, Adobe built, Autodesk built, uh, or even like take what Jensen said.We built DX and he built, you know, CUDA on top of it. Um, right? I mean, I always say to Jensen, “God, I got the short end of that,” right? “I wish, uh, we had recognized it.” But nevertheless, but that, that idea that you can build a platform layer [00:14:00] that someone else can then extend out, um, and build their own intelligence layer in this case, I think is everything, right?Without it, why have a developer conference? I can just come and have you all sort of just worship at the altar of one model. Yeah. But that's not a developer conference. Uh,IP, Evals & Company Valueswyx: backstage we, we had a discussion about what is IP or what is the, the value in a company. It used to be the length of, uh, human experience at a company, and now it's this other thing which is the evals, the, uh, experience in sort of applying agents to the company. Can you... I just want you to like flesh that out a bit more ‘cause- Yeah ... it was very insightful.Satya Nadella: It's a great way to frame it, right? Because yeah, at the end of the day, every company is gonna have both the human capital that is still gonna be super valuable, uh, because humans, uh, and their ability to find the gaps that exist at all times is going to be the way we all will create value, right?I mean, so I'm definitely in the camp that this is going to be about expressing new forms of human agency and ambition even as token capital goes up, right? So let's say a cor- any corporation [00:15:00] has lots of tokens and lot of human capital. The question is how do you compound the two? So if you have a... Like if you take in Teams I have a bunch of agents doing work and a bunch of humans doing work, and the traces between those, that is really important context of how that enterprise is creating value.Then that goes back to train not a generalist model, but to train the company veteran agent, uh, right? That is super valuable again, right? Which is when a company goes says, “It should in fact go onto the balance sheet,” is how I think about it, right? That's so... In fact, there may be... Like human capital was never possible to go put on a balance sheet, uh, because you didn't know how to capture the tacit knowledge.swyx: Whereas now I think you can with the agents that have learned through the h- through, through time, through all the traces. Uh, so that's what at least we think will happen. I, I think the SEC is gonna have to have accounting standards- ... for token, uh, expertise Uh, y- y- you're talking about the equilibrium [00:16:00] state, um, and a stable equilibrium where companies have this compounding value and can see terminal value for themselves.Future of SaaS & Business ModelsSarah Guo: Another challenge to, you know, the considered equilibrium of, okay, there are applications and workflows that are sort of common to a vertical or a horizontal. Um, and this was, like, the generation of SaaS companies and, you know, Microsoft has lots of SaaS properties as well. And then there are things that are very specific to every enterprise that they're differentiated against.Elad Gil: Um, I'm sure you have heard much and participate in much of the debate about the end of software because all these workflows are, are cheap to generate now. Um, do you think the equilibrium looks different between what agents get built- Yeah ... in enterprises versus in their vendors in the future? Yeah. So I think what's happening there is, see, we, we had a particular way we captured, um, I would say workflow in apps, right?Satya Nadella: Because we built a, a data model, right? We schematized some part of some business process. Mm-hmm. We then built a bunch of business logic. Yep. And then we put a bunch of UI [00:17:00] on top of it, right? So that's kind of what every SaaS company- And a little configuration. For, like, 20, 20 years that was the plan.Right, that- Yeah ... and that was it. So interestingly enough, now you kind of get to re-litigate that vertical stacking, right? So I still think, for example, that data model that you built underneath every SaaS application is super good, right? Like, why reinvent it? Like, I, I, my general ledger better be a general ledger.I don't need new schema creation. No. Uh, in fact, that entity relationship, uh, is actually pretty good, robust thing that I want to feed. And you want it to be stable. That's right. Yeah. Then same thing with business logic, right? If, if you look at, uh... We have this product called Power BI, right? It is like dashboards galore people created.The beauty underneath that dashboard is a very rich semantic model, right? Someone took the pain to create a dashboard and do all the measures, and you want that. That's business logic, right? I want that to be available to me. So I think the [00:18:00] challenge of the SaaS business model is we packaged one way. We now have to learn how to unbundle these things and rebundle in new ways and discover new business models, right?I mean, if you look at it, d- what's happening today with Microsoft 365 is a great example, right? We have this thing called Work IQ. In fact, like, what we are realizing is, oh my God, like, you know, if you look at... In fact, there's a pa- historical parallel too, right? We sold first Exchange and SharePoint and, uh, you know, before Teams, we had a thing called Lync Server and what have you, and we thought, “Oh, that's all gonna move to the cloud.”But little did we realize that, um, the number of people who will use servers in the cloud is 10X, 100X, right? Because people were not buying servers, they were just buying a subscription. Mm-hmm. The same thing is now happening with M365 because with Work IQ, we have exposed what is perhaps the most important database in a company that never got used as a database because it was only captive to our apps.Mm-hmm. Right? It, it was all email operated on it, Teams operated [00:19:00] on it, Word, Excel, PowerPoint, SharePoint. But now, like this is one of the coo- coolest things I get to do with Work IQ. I go to a GitHub repo and I say, “Hey, I attended a bunch of design meetings last week related to this repo. Can you capture all that and tell me what changes I should make?”I mean, think about that, right? It literally can go look at all those transcripts, come back with a plan to change a code base, right? Previously, you could never have thought of using M365 for something like that. So the value creation opportunity now in the agent world is in fact 10X more, but it does require us to have...Sarah Guo: For example, there's going to be usage around M365, right? Which is going to be perhaps more than even the e- end users and we have to even re-architect. Like, in fact, like what I use to serve an inbox or a mailbox cannot be used to serve an agent. Uh, and so that's sort of what we are doing.Pricing Models: Per-User, Consumption & OutcomesSarah Guo: I don't believe in, like, permanent business models for any of these domains, but in the [00:20:00] near term, do you have a prediction between, uh, you know, outcomes-based pricing, token-based pricing?Elad Gil: Enterprise bundles Yeah. The way I- I think about this is always we've had... Like, let's even take the per-user pricing. Mm-hmm. The per-user pricing is really an artifact of someone creating a budget needing certainty, right? Because it's the most important thing. Like, somebody wants a budget- Mm-hmm ... they need a per user.Satya Nadella: And, and per user is just a set of entitlements to usage, right? That's kind of what it is. And so the way is, if the first bundling will be take some usage, bundle it into per user stacks and, you know, then sell subscriptions. So subscriptions I think are gonna be there, per user is gonna be there. Then the next big thing will be consumption.So people will say, “I want consumption.” And it's also possible that people will say, “I don't even want to pay for any of the subscriptions or the consumption's outcome.” Mm. But remember, most people love outcomes until they have an outcome, because once you have an outcome, it's like giving away royalty, [00:21:00] right?Mm. I mean, like I, I've talked to customers who love, you know, outcome-based pricing, and I say, “I'm all in,” until they, “Oh my God,” like, “what are you talking about? You're sharing in my outcome? No, no, no. I want you to go back to per-user pricing, and I want you to consumption price,” right? So I think that debate will go on.Uh, but and all, all, all of these business models have a particular time and a place versus one to rule them all. And if anything, if you're a SaaS vendor or you're a platform vendor, having that flexibility... And quite frankly, we face this with GitHub, right? We just recently announced a per-user pricing on GitHub because little, you know, we- GitHub Copilot was constructed at a per-user level before we understood even, uh, the intensity of usage of agents, right?It was an interactive way for a developer to use code complete, maybe tasks. It was not like, oh, I launched 10,000, you know, agents that are going on all day, right? So that is what the adjustment is about. So now that we really want, there will [00:22:00] always be a per user, but there will have to be a consumption meter.Durability of SaaS & Build vs BuySarah Guo: How do you think about the durability of SaaS more generally? One thing I've observed is in a lot of enterprises internally, there will be teams that almost have agent euphoria. They're so excited about the explosion of things they can build that they're trying to rebuild a lot of applications or going to their SaaS vendors and saying, “We're not gonna work with you anymore,” or, “We're considering an internal project.”And it seems like in six to nine months, maybe some of those people will come back and say, “Actually, we, we can't rebuild everything.” How do you think about what's durable in this world and what isn't? Yeah, it's a... It... I think we have to go through one full budget cycle on this to really see the, um- Uh, the sort of the emergence of the equilibrium, because at the end of the day, there's marginal cost to even generating the app, right?Elad Gil: In, in fact, there can be even a, a simple way to say it, like if you should always acquire something if the marginal cost of building and maintaining, uh, something on your own is higher. Uh, right? That should be like it's a quantifiable- Yeah. Right? A quantifiable thing. And [00:23:00] the maintenance part is important, right?Even, like you got to remember like, hey, you know, all the security stuff that now AI will find, you better fix them too fast. Uh, of course, there's a coding agent to help you with, but then that burns tokens, right? So whose responsibility is it? It's kind of like a, a cycle that you've got to think through.And I think we have gone through the excitement that I can generate a lot of software. I think the next thing would be what software do I really want to generate? Mm-hmm. What software do I want to use from others? How do I compose these two into some agentic workflow that I have agency over, right?Sarah Guo: Because I think there'll be very little tolerance for anybody who's inflexible, uh, at the vendor level. Uh, but at the same time, I think that anyone who has got that flexibility shows up, delivers the value, will be back at again, right? We're selling software, uh, but with just different business models, in fact Uh, speaking about building software, um, one of my favorite moments from, I think, a previous build maybe one or two years ago was they had a b- they, they...Swyx: There was a section of you building your [00:24:00] own software. I'm curious if you're building anything now. Yeah. So I, I think the... You know, first of all, let's face it, right? Building software has made it possible for even the incompetence of a CEO of a company- ... like ours, uh, you can build, so thank God. But that said, I, I, I, I do feel that, you know, something like, um, GitHub Copilot to me, and especially the new Sessions app or the new app, has just made it so much more possible for you to have agency over artifacts that you felt you couldn't touch before, right?Satya Nadella: So to, for me as a CEO, even to go to a code base, uh, to be able to learn about it, like I remember joining Microsoft long back, you know, first and then you say, man, everybody had to go in and look at, you know, whatever, Cutler's, Malik, or what have you to learn how to do good C, uh, C++ code. Um, so now that ability to be more full stack up and down is so good, but that doesn't mean every one of us should be doing the same thing.The question is: [00:25:00] how do you then have the ability to inspect things, learn things, see things, um, I think is just so much more. And so to me, what I'm building a lot of is these long-running Foundry agents. Uh, right? So there's autopilots. So the easiest thing is, to me, I think I just built one, uh, even last week, where the idea was, hey, can I have an agent that is continuously monitoring essentially my own chief of staff autopilot, right?We're gonna have that obviously in, uh, Scout. That's what, uh, uh, we showed. But it is so easy and trivial to build. I took Work IQ. I said, “Take Work IQ, go, uh, and build a Foundry long-running agent.” Uh, store all the memory in, um, uh, using Ray Fin, right? Basically at my backend as a service. And lo and behold, it built it, and not only built it, I could say publish to Teams, and it published the damn thing to Teams.Sarah Guo: So the ability, uh, to have a, you know, some end-to-end project like this complete is just pretty [00:26:00] miraculous. How do you think, uh,Future Engineering RolesSarah Guo: that impacts the different types of engineering roles that exist in the future? Because right now I think there's, you know, a dozen different types of engineers that you can be, from QA, front end, et cetera.You know, there's a big swath. I've heard some people argue that in four or five years we'll basically end up with four engineering roles. It'll be people who are managing agents, it'll be four deployed engineers or FDEs, it'll be security engineers, and then people working on large scale infrastructure for a small number of services, and then everything else just collapses into the agentic world.Satya Nadella: Yeah, I- Do you think that's a correct view of the world? Yeah, I mean, I think, I think we'll have to experiment our way through it. But what you said is what... There are some very at scale things. At LinkedIn, they did structurally change- Mm-hmm ... uh, and it, you know, basically built up a new discipline called full stack builder, right?So they went and said, “Hey, let's bring, uh, people from design and product management, front end engineering, all put them together.” Uh, but also have an edge, right? It's not like the design person still doesn't have the design edge, or the front end [00:27:00] person doesn't have the front end edge, but you can give yourself bigger scope in roles so that you're not confined to one role.Um, and then r- equally, infrastructure has become very critical, right? So in other words, like, I mean, RLEs, I mean, one thing we've realized is even for the Excel team, for example. Mm-hmm. Building the RLE in which a reward can be learned is actually one of the hardest sort of infrastructure problems.Mm-hmm. Uh, and so you kind of need even new talent, right? Distributed systems people even in what was considered an end user app team, uh, because it's a different skill set. So yes, infrastructure, science is the other one, obviously. Um, so I think we'll see how these evolve, right? Where's the s- real... I mean, always the world will have a bunch of specialists.Okay. Um, you know, I think the generalist role is going to be the most exciting, right? Because the leverage of a generalist- Mm-hmm ... um, is where we are going to see the maximum returns, right? When, when you said, “Hey, are you coding?” I'm now a gen- Like, what... I've basically translated [00:28:00] knowledge work Right?Which I did, where I created a Word document or a spreadsheet, or even, uh... And now I can build an app, right? It's in the same sentence. Uh, right? That idea that, “Oh, wow, my generalist skills have gotten higher leverage,” I think is what we're gonna see across the board. Music to the ears of CEOs and VCs that are, like, a little dangerous and a lot of- Golden age for idea peopleSarah Guo: idea people. Yeah. Uh- With a lot of agency. I- if you take that idea of personal agency and you just zoom it out to the organizational context, um, uh, my partner Mike Renall, who, uh, actually started his career at Microsoft, just wrote an essay where one of the big takeaways is i- it's an age where you can be much more ambitious, and you need to be, given the pace of the environment and how quickly, actually, users and companies are open to adopting new technologies.Satya Nadella: Um, how do you think about... I, I feel silly asking this of somebody running a, you know, trillion-dollar-plus company already, butAmbition & Making the Impossible PossibleSatya Nadella: how do you think about how Microsoft can be more ambitious now? It's a great question. Um, I [00:29:00] think, um- I think the, the thing in these type of transitions is to have a conceptual model of how work can change to go after outcomes that you could hardly imagine previously, right?In fact, Kevin Scott has this nice line, right, which is, um, when you can make the impossible... Like, when you're making hard things easier, that's sort of one point of leverage. But true ambition is about making the impossible possible. So now the thing that is missing a little bit in all of our organizations is what is that new conceptual model of what can we build?What was impossible and what can we build? And I'll give you one example of this, right, which is I take great inspiration from sort of the people who were managing the Azure net- network. And they came to the... This was from even last year. You know, we were scaling. You saw that I, I [00:30:00] talked about sort of how we built in the last 15 months more Azure capacity than we built in the first 15 years.I mean, it's crazy. Wild. Yeah. Right? It's pretty wild. And it's the same team. So they saw that and they said, “Bob, this just ain't gonna work if we don't reconceptualize our work.” So they built... Essentially they said, “Our job is not to do Azure networking. Our job is to build the agentic system does, that, that does Azure networking,” right?These are the folks managing the 500-plus fiber operators managing the VAN, right, all over. And fiber operations ultimately is a physical operation. Things get cut, things get, uh, you know, have to be repaired. You know, we have fancy words called DevOps and so on. Basically, emails are coming in and you gotta go respond to them, take care of it.So they built this agentic system. They even have a character for it. It's called Miles, and it sort of does all this stuff, right? They started sort of screaming for more tokens and so on. And so they were saying, “Look, uh, we don't need a headcount. We need tokens in order to be able to [00:31:00] manage, uh, our operation.”That reconceptualization- Mm-hmm ... of what their work is, right? They, they basically took their work and made it meta, right? That meta work is now their new work. Mm-hmm. Right? In the ‘80s, if somebody had come to us and said, “4 billion people are gonna get up in the morning and start typing,” my model would've been, we need 4 billion typists?But we're not doing typing, we're doing knowledge work. So that, to me, I think is it, right, which is whether it's Microsoft or whether it's any organization, is to give ourselves permission to do new types of metacognition, meta work, using these new tools to change the outputs that matter, uh, and then really make the impossible possible.Sarah Guo: So completing that dot or the, the connective tissue across those, I think, is where a lot of the enterprise value will get created.Data Center Build-Out & Community ImpactSarah Guo: Should we talk about data centers? Yeah, please ask. Oh, okay. Well, uh, uh, w- we-- this leads nicely into the data center build-up. I always think, I- I just-- I'm just impressed at the sheer scale of the [00:32:00] build-out from Microsoft, but also everyone else, that this is redefining what it means to be a hyperscaler.And I just feel like that, that, that is at unprecedented scale on finances, uh, on the way you run the company, but also the communities that are, that are impacted. Um, yeah, just talk a bit more about what you're seeing on the ground, like when you visit your- Yeah, I think there are two aspects of it.Satya Nadella: Obviously, the, the build-out is, uh, extraordinary. Um, you know, nothing like this has happened, and it's great to be, uh, one of the participants in it. Uh, but you brought up the other part, right? I think at this point it's clear that unless we as an industry, uh, are very principled about ensuring that the benefits of all the stuff we're talking about are felt in real ways, uh, at the community level, right?Because this is not just a, a campaign, um, right? It has to be real, where people are saying, “Look, this is not ch- changing the prices on energy for me.” In fact, if anything, it's bringing down prices because long term there's going to be a better [00:33:00] grid, there is going to be more energy. Water consumption is, in fact, not sort of, uh...In fact, water is being replenished, right? You gotta really, you know, educate folks on truly what's happening, the cl- uh, the closed loop systems we are building. We have to invest in the training, the jobs, the tax base. In fact, the least talked about stuff is the amount of jobs that get created during construction, after construction.What's the tax base that's there in the community? And, and all this has to be real. Um, and, and if that is the case, then we will have permission. If it is not, we won't have permission. It's as simple as that, right? Which is, uh, we, we... I think we have to take it as an industry pretty seriously. Uh, I think it's good for communities to be skeptical, ask the hard questions, for us to do the hard work, earn that.Um, but at the end of the day, if there's-- if we can really be the produ-- Wait. I've always felt like in human history, if you use a lot of energy but also create a lot of value for society- The story has been fantastic. If you don't [00:34:00] do that, it's not been that great. And this time around, I'm a firm believer that ultimately if you do have a token economy that drives productivity, that drives economic growth, that drives broad spread, um, you know, participation, better health outcomes, um, then I think we'll be in a great place.Sarah Guo: Uh, and that's at least what we all have to be focused on. Yeah. It, it makes me think actually that with all these initiatives that you're doing, might be e- easier to see ROI in the communities first before in enterprise. Yeah. I, I mean, I think both sides. Yeah. In fact, it comes back together. It has to be the people in the communities are going to be employed, are going to be participants, uh, in the real economy, right?Satya Nadella: That's I think the question is. Like, if we- if the broad economy is doing well and the communities are doing well, the dots get connected. It's sort of the market forces are such that we will connect the dots. And that I think is it. Like, you ought to be able to see the evidence. You can't be about o- any one company, uh, but it has to be broad economic growth and broad [00:35:00] ec- you know, community permission.Elad Gil: Yeah. I guess I wanna talk aboutSocietal Impact & Optimism About AIElad Gil: what you're most optimistic about currently or what have you most updated your personal models on regarding societal impact of AI? So you're saying what's the, the, the- What have you updated most on in terms of societal impact of AI? Yeah. I think the, um, the p- the most, um- Critical thing is the first question we even started with, which is we need to tell the story and make it real that everybody has a real shot to participate as a first-class participant in this new economy.Satya Nadella: Right? That's kind of, I think we- in the next 12 months, 18 months, we need a way for people to say, “Oh, wow, I get it.” Right? There's going to be tremendous capability, tremendous amount of infrastructure, but I can see what is going to happen, whether it's the benefits like health outcomes or my ability to create a startup or my ability to run my [00:36:00] local sort of, uh, store more efficiently.It's just happening, and I see that, uh, benefit myself, right? That to me, you know, earning that permission in a path-dependent way, we can't wait. See, the one thing, Eli, that I've now learned is I think the world is gonna be very skeptical of tech and tech companies that say, “Trust us, we've got it. The g- future is gonna be glorious.”Sarah Guo: Uh, you kind of have to deliver tangible benefits. Um, and quite frankly, politicians winning elections, uh, because they have advocated for that. That will be at least my adjustment because without it, um, thinking that somehow... Because it's too important this time around. It's too much of the economy for it not to be the case So one very simple framework I have for, you know, what are, what is gonna be the broad benefit of AI, um, beyond the communities just working in technology, are, are sort of wealth creation- Yepit's [00:37:00] gonna happen in a ton of different companies, startups and large companies. Then you have healthcare. Uh, you, you had amazing demos today. There are companies like Open Evidence. I think that is happening. Um,Education & Future of LearningSarah Guo: education seems like another one that's an- Yep ... obvious good where we haven't seen as much impact as I'd expect.Swyx: Do you have a hypothesis on why that might be, or if it'll come? Yeah, I mean, I think this is where, again, how we think about education, how... You know, recently I met with, uh, the founders of Alpha School and learnt a lot about what they were going and going about, and it's fascinating to listen, uh, to how to even rethink- MmSatya Nadella: uh, what does education really look like. Because I think it's actually very important. Mm. Uh, and I'm not saying anything traditionally being done is less important, right? I was even looking at the, uh... It's fascinating to see. I, I, I forget the which Stanford class it was, uh, the, the Asian guidelines for CS something.Mm. Uh, because you still need people to learn. Uh, like it was an interesting AI class that they were making sure people were learning how to apply softmax appropriately versus saying, “Hey, fix my training run.” Mm-hmm. Uh, so I think learning concepts is important. It's going to [00:38:00] be, uh, critical. But the way we create the incentives, what are the credentials, how we value those credentials, what is the employment opportunity for those credentials?So I think that there's a complete change that has to happen, uh, given the way to get to information, way to educate yourself, way to continuously keep yourself updated has changed so much. So I think interestingly enough, maybe the next big startup and success story could be someone who builds a new university, um, or a new, um, pedagogy even of how to get someone to go through a curriculum and find economic opportunity, uh, that's highly valuable.Well, that has felt, uh, perhaps impossible for a long time, but it's a great note to end on and something that might be possible. It's still possible. Yeah. Thank you, Satya. Thank you so much. Thank you. Yeah. I appreciate it. Thank you all. This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.latent.space/subscribe
The boys have a whisky-infused talk about AI use cases, share fun stories and have 4 different English whiskies throughout the episode.
Welcome back to the Top Contractor School Podcast, where contractors come to grow stronger, scale smarter, and build businesses that last. In this episode, Eric Guy sits down with Thurman Trotman, government contractor, SharePoint expert, and technology consultant, to break down one of the most underutilized tools contractors are already paying for: Microsoft SharePoint. If your company is drowning in spreadsheets, struggling with SOPs, losing information in email chains, or relying on expensive software to solve simple problems, this conversation will open your eyes to a more efficient way of operating. Thurman shares practical, real-world examples of how contractors can use technology to create systems, streamline communication, and build a scalable business.
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Possible ACR Stealer From Page Impersonating Claude https://isc.sans.edu/diary/Possible%20ACR%20Stealer%20From%20Page%20Impersonating%20Claude/33018 Microsoft SharePoint Remote Code Execution Vulnerability CVE-2026-45659 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659 Multiple Vulnerabilities in Angular Language Service VS Code Extension https://github.com/angular/angular/security/advisories/GHSA-ccq4-xmxr-8hcq
According to research by Gartner, 84% of business leaders report their company's identity must significantly change to achieve strategic objectives. But how do you know when the time is right? And more importantly, how do you ensure that change goes smoothly? Riley Rogers: Welcome to the Win/Win Podcast. I’m your host, Riley Rogers. Join us as we dive into changing trends in the workplace and how to navigate them successfully. According to research by Gartner, 84% of business leaders report their company's identity must significantly change to achieve strategic objectives. But how do you know when the time is right? And more than that, how do you ensure that the change goes smoothly? Here to discuss this topic is Shelly Luciano, Vice President of Strategy at Leah. Thank you so much for joining us today, Shelly. I’d love if you could just kick us off by telling us a little bit about yourself, your background, and your role. Shelly Luciano: I’m Shelly Luciano. I’m Brazilian. I studied industrial engineering in Brazil and France. I started my career working in infrastructure and R&D, so that experience gave me a strong foundation in execution early on. Back in 2014, I moved to the UK to pursue my MBA at London Business School. I used business school to transition from a technical background into strategy on a global scale. After my MBA, I spent three and a half years in strategy consulting. That work helped me learn how companies compete in larger markets. What I realized is that although strategy consulting is intellectually fascinating, I was being more and more drawn to the business. So I transitioned into tech about five years ago. I joined what was then ContractPodAI, which is now Leah. Today, I’m Vice President of Strategy and Operations. My team focuses on aligning strategic priorities, supporting cross-functional execution, and ensuring our go-to-market approach reflects both where the company's headed and what our customers need. One of the most valuable parts of my role is staying close to our customer base. These conversations give me and the company a lot of valuable insight into how the market is evolving and how organizations are actually adopting AI. I then bring these insights back into the organization, back into Leah, to inform product direction, enable our customer success team, and ensure that our strategy remains grounded in real market needs. Ultimately, my role sits at the intersection of strategy, go-to-market execution, and customer insight. RR: I think you have a fascinating role, to be quite frank, and also a really wonderful story. To go from “I'm trained as an engineer,” to “now I've got my MBA, I'm in consulting, and today I work in tech and have for the last five years,” that's really an incredible journey that I imagine must have given you a real wealth of experience that serves you very well at Leah. SL: It’s funny because if you asked me when I graduated in Brazil what I'd be doing now, I wouldn't have guessed. The world has changed so much. My world has changed so much. So I feel very lucky and blessed to do the job that I do. I really like it. My company's fascinating. My role is fascinating. My company gives me room to change as long as I'm adding value and my team is adding value. So I'm really happy. RR: Yeah, and that's certainly evidenced by the fact that you spent five years in one tech company when the average tenure is just over two, so something really must be going right. I'd love to dig a little bit deeper into this exciting, challenging, and evolving role that's been keeping you at Leah for the last few years. You're there to keep an eye on what's happening in the market so your reps can tell a story and your engineering teams can build a product that the market both wants to hear and to see. More than that, you're also there to break down silos and operationalize your strategy so it really shows up in everyday workflows. In this work, what kind of things tend to crop up—challenges or obstacles that make it difficult to build the connections that bridge that gap between strategy and execution? SL: For me, there are two major challenges I see in equipping internal teams to drive growth. First, strategy and execution often evolve at different speeds. A leadership team can align relatively quickly on a strategic direction, but translating that direction into how hundreds or thousands of people operate day to day can take much longer. For me, strategy only really lands when it keeps showing up in customer conversations. What you portray needs to align with what your client base and the market are seeing. If the people talking to customers every day don't understand the problems that your company is solving and why, then your strategy hasn't really landed. It's just a deck. It's lovely to build these ideas, but you've got to be able to execute on them. As companies scale, the complexity increases much faster than people expect. You have more industries, more personas, a larger product portfolio, and if you don't have the right systems and alignment, that complexity can create a lot of confusion internally. And if your team is internally confused, then everyone else is too. RR: So your job is to keep an incredibly close pulse on the market and on technology as they both evolve. And it's a little bit of an endless task because the market will always shift and technology will always evolve. So you've got to be right there with it as the voice of reason for the organization, telling everyone, “Okay, here's what's happening, and here's how we're going to move with it.” As someone who, by job description, is very comfortable with change and evolution, can you share with us how you're thinking about how Leah, as an AI-first company, is keeping pace through major technology shifts, and then how other organizations should think about translating these shifts into their own organizational and operational processes? SL: Leah has been an AI-first company for years, way before LLMs. What changed with LLMs is the speed and scope at which we can execute our strategy much faster. We've been using machine learning in our platform for a long time, so the foundation was already there. We already had a really strong team. What LLMs did was introduce a step change, and our founder, Sarvarth, is a visionary. He saw straight away how that was going to change the game. All these changes in the past few years did not change our direction, but for the client base, what they can really see is that LLMs have expanded the use cases that we can deliver. And I think that's what matters to customers—how can we solve more of their problems? With Leah, we've moved from traditional automation into what we describe as an agentic operating system. That means our AI is not just supporting workflows. We can do much more than that. We can now reason across data, understand context, and orchestrate actions. That is so exciting, as you can imagine, for someone who works in strategy because it feels limitless. Going beyond static workflows, you now have systems that can adapt dynamically to the problems that we're solving. And that's where the speed and pace of innovation really comes in. Once you move into an agentic model, you're no longer limited to predefined use cases. You can continuously expand how AI is applied across not only our internal organization but also our client base. From a strategy and operations perspective, the challenge is not adopting the technology, because we've been able to do it and we continue to do it. The challenge is how do we operationalize it? Strategists love frameworks, so if I had to group it, I'd say there are three ways I think about this. The first part is strategic focus. The risk with AI, within all this opportunity, is diffusion. So we need to be deliberate about which use cases we prioritize. We need to define where we can deliver the most value, because being AI-first doesn't mean doing everything. It means scaling the right use cases. The second part is how do we translate that into go-to-market execution? As I mentioned before, strategy only really lands when your customers can speak about you. Organizations need to understand how to position AI. We need to be able to explain it clearly so we can apply it across different industries and contexts. That's where systems like Highspot can really help us translate this within our organization and externally. The third thing is continuous customer feedback loops, because customer proximity is the most valuable strategic signal we can have. To be a strategist in tech, your goal is not to define a static AI strategy. You're always on a feedback loop, and you need to be agile. The tools and teams that support you need to be comfortable with always learning and always putting our best foot forward. RR: So as you alluded to, you and the team actually recently went through a rebrand. From ContractPodAI, you became Leah, named after the organization's flagship AI offering. I'd be curious to hear how, with these challenges to strategy-aligned execution in mind, you and the team made sure that everyone was telling the same story and supporting the same strategy, even as the brand message and narrative shifted so drastically. SL: Leah was already a product of ours that had taken a bigger and bigger piece of our client base. So moving from ContractPodAI, which was very contract-focused, into Leah made sense because the Leah product had become a much bigger part of who we were and our identity. When we came into becoming the Leah brand, we were ready in many ways. You're never fully ready for a full rebrand. There's still a lot of work. But we had the tools and processes in place to help us in that transition. In 2021, we had just raised $150 million from SoftBank's Vision Fund. At that point, I knew we were going to grow exponentially, so I wanted to manage as many growing pains as possible. At that stage, we were evolving from having a relatively general pitch to a much more sophisticated message tailored by industry and persona, and our platform was expanding even back then. I realized that we needed a way to ensure that our entire organization stayed aligned on how we communicate value because, as companies scale, complexity increases. More products, more industries, more ways customers can use your platform. So when trying to solve that problem, that's when we looked into Highspot. We wanted Highspot to help us ensure the entire organization could work from the same narrative. Highspot is now used across our sales teams, SDR teams, CX teams, and actually it has expanded because once people hear about it, they want to know what the go-to-market teams are presenting. I'm really glad we implemented Highspot four or five years ago now because since then the customers that we serve have grown and the breadth of our platform has grown. Putting things in place before you come to that stage is actually really important. RR: Can you walk through where Highspot fit into the picture and how you and the team used it to trickle down that message so, to your earlier point, strategic vision didn't get lost in that wonderful game of telephone between C-suite strategy and individual contributor execution? SL: When I came in, we had a general pitch on how we went to market. One of the reasons I was hired is because I came in to do an industry strategy, and there was a lot of research involved—both internally, looking at how we were using the tool for certain industries, and externally, looking at market potential and product fit for each industry. Based on that, I prioritized a few industries to start developing content and enablement around. That's when I looked into Highspot because we had a SharePoint at the time, and it was already not fully updated. People pasted things on top of it or saved materials to their computers and never checked the right version again. I came to Highspot with a very clear use case. There were other features and capabilities that we wanted, but the core problem I wanted to solve was creating one single source of truth. It seems like a SharePoint should do that just fine, but it didn't because we needed something that would help us as we continued scaling product growth, use case growth, and overall organizational growth. It was going to become really hard to enable everyone and make sure people accessed the information they needed at the right time. That's what we got Highspot for, and that's what we continue using it for. RR: So once you defined the strategy of the rebrand, where did you see friction between what you were telling reps—“Here's our new message, here's our new strategy”—and what they were actually saying and doing in the field? Where was there misalignment, and how did you and the team tackle that? SL: Once the strategy and story are defined, the real challenge is behavioral change at scale. Organizations tend to align on a narrative relatively quickly at a conceptual level. But alignment alone is not the end goal. Execution is. Execution, particularly in customer conversations, can take time. The friction I've observed is not usually resistance. It's normally a knowledge gap or a confidence gap. Sometimes you have the knowledge, but you're not confident in that knowledge. As your platform evolves and you're no longer selling a single product for a very defined use case, you're helping customers on a journey. You need to understand a variety of challenges across different workflows, industries, and personas. In that environment, the challenge is not whether teams understand the narrative. The bigger challenge is whether they can apply it dynamically in real conversations. What we consistently see is that reps are comfortable with the core story, but uncertainty appears around the edges. When a customer asks something slightly outside the standard pitch or challenges how the solution applies to their specific context, that's where execution can break down. For reps to feel confident using the right language and positioning the platform correctly, they need to understand things at a deeper level. With all the advancement in AI, we can develop things so quickly, but that also creates challenges because emerging technologies move incredibly fast. There's something new every week. If your software can deliver so much, there are a lot of questions reps need to feel prepared for, and we need to give the organization the ability to operate with clarity and confidence in this complex environment. Highspot has helped us do part of that, particularly in making sure teams understand how we're positioning ourselves, but there's also a lot of technical enablement and training that we need to make sure they complete. Teams have to prepare for conversations in many different contexts, and that fundamentally changes how an organization executes. You can't just memorize anymore. You need to understand. Ultimately, scaling a company is not about having the best strategy on paper. It's about ensuring that all of your employees can bring that strategy to life and communicate it with passion. RR: Yeah. I love the way you landed that because you're 100% right that to a certain extent it can be a knowledge gap, and another layer can be that confidence gap. But then that third and final layer is the context gap. Can reps embody the strategist? Can they embody the strategy? Reps want to do well. It benefits them and it benefits you. So when things are going awry, it's not intentional. It's hard to get up to speed and start delivering in the field, especially when things are changing so rapidly. If you can slowly bridge all those gaps, your strategy starts to encompass the whole company. And again, it's such a cool role that you have, getting to bring that to life and then watch it trickle out into every customer conversation your teams are having. You mentioned 2021 and implementing Highspot, and it's been five years since then. In that time, what key results have you seen? Any wins that you're especially proud of, whether early on or today during this rebrand phase? SL: Highspot is now widely used across the organization. We have the sales team, SDR team, CX team, and leadership all using it. Initially, we bought licenses only for the sales team, and since then we've more than doubled, if not tripled, our licenses because people continue asking for access. I think that's one of the biggest indicators of value. What I continue to see, and why I continue investing in the platform, is consistency. You want to be consistently delivering and positioning yourself in the market. As our product offering expanded and we began serving multiple industries and personas across different regions, it became critical that teams could access the most relevant materials quickly. Highspot ensures that everyone across the organization is working from the same narrative and delivering a consistent experience to customers and prospective customers. That alignment becomes very important as the organization scales. One of the most impressive things after the rebrand was that from the very next day, everything had changed. Everything in Highspot was Leah. I knew the marketing team had been working incredibly hard, but from day one everything was available to us. That's what tools are for. When you buy a tool, you want to make sure it makes you look good. RR: I can imagine that's a monumental task—to take every single piece of collateral, every single deck you've ever built, and overnight update it so every rep has all the content, messaging, and everything they need to hit the ground running on day one of the rebrand, day one of Leah. To the point of bringing strategy to life, you really did it. Very early on, you said you're never ready for a rebrand. And yes, it's certainly a huge task, but it does seem like you've come through it successfully. That takes me to the last question I had for you, which is: for other leaders navigating a rebrand or shifting message while trying to position themselves in a constantly changing market, what advice would you share? SL: One of the most important lessons for me is that rebrands are not simply marketing exercises. They're full organizational transformations. The success of a rebrand depends on whether the entire organization is bought in and understands the narrative, and whether they feel confident communicating what you're doing to customers. Like I said before, the success of the rebrand is really only clear when you see that it has landed with your customer base. Another key element is staying very close to your customers during the process. Understand how they're going to perceive this, and once you've launched it, pay attention to their initial reactions so you can address anything quickly. That's your most valuable insight because customers really know how you're positioning yourself in the market and what you can actually deliver. You want to make sure what you've changed feels true to who you are. Luckily, with Leah, customers responded positively to the rebrand. They felt the narrative resonated. When your organization combines strong strategic direction with customer insight, you're much more likely to build a story that's authentic and compelling. That's what you want with your brand. It needs to make sense. People need to know it wasn't just done to look good. It needs to resonate with the company and what you're offering. RR: Yeah. You absolutely need to prove that this is something worthwhile and valuable to your customer base, and that it tells the story and provides the value they're looking for. Otherwise, to your point, it winds up feeling like a vanity exercise because someone didn't like the colors or didn't feel the name was quite right. It needs to be strategic and feel strategic. Shelly, thank you so much for joining us today. It has been an absolute pleasure talking with you and learning more about the work that you're doing at Leah. To our audience, thank you so much for listening to this episode of the Win/Win Podcast. Be sure to tune in next time for more insight on how you can maximize go-to-market success with Highspot.
Take a look at the changes in Teams meetings. Buttons be moving. While in a meeting, less used buttons will be shifted under the ...More menu. But you can bring them out again and pin them! SharePoint agents get tidied up too with an update to how they are listed and linked. 0:00 Welcome 2:49 (Updated) Microsoft Teams: A refreshed in-meeting experience with simpler controls and a smarter share panel - MC1317197 12:13 SharePoint Pages: Heading 1 (H1) option now available in web part title areas - MC1315218 14:27 Microsoft Copilot Notebooks: Introducing Infographics - MC1317195 19:21 Update to agents in SharePoint: Simpler launch experience and new site AI settings - MC1315219 25:17 Microsoft Teams: In‑meeting toggle to turn Meeting AI on or off - MC1319216
You can teach a new dog new tricks to help the old dog. Copilot picks up some new skills to help good old PowerPoint. SharePoint Online storage quotas will be enforced in regards to OneDrives that are over the limit. And establish certain SharePoint sites as authoritative sources for Copilot Search results. 0:00 Welcome 2:34 Updates to SharePoint home sites - MC1304293 5:21 HTML formatting now supported for Message center posts synced to Planner - MC1307883 8:20 PowerPoint for Windows desktop: “Visualize this slide” skill in Copilot - MC1309731 12:00 PowerPoint for Windows desktop: "Review this presentation" skill in Copilot - MC1309735 17:08 Power Automate - Restore accidentally deleted flows - MC1310368 20:33 SharePoint Online: Storage quota enforcement updated to align with license limits - MC1310684 24:31 Authoritative Sites for SharePoint in Microsoft Copilot - MC1310687
This is episode 326, recorded on May 7th, 2026, where John and Jason break down the Power BI & Fabric April 2026 Feature Summaries — DAX user-defined functions are here in preview, Direct Lake is flexing new modeling muscles, the Dataflows Gen1 community drama has a plot twist, Fabric Data Warehouse finally gets true transactional DDL, and VS Code integration in Fabric notebooks keeps leveling up. It's the April feature summary double-header. For show notes please visit www.bifocal.show
Mythos leaks. The DOD preps a more aggressive cyber strategy. A former FBI cyber official urges homicide charges for hospital ransomware deaths. Lotus Wiper targeted the Venezuelan energy and utilities sector. Over 1,300 SharePoint servers remain unpatched against a spoofing vulnerability. The Harvester APT group deploys a new Linux version of its GoGra backdoor. A new LOTUSLITE backdoor targets India's banking sector. The Mirai botnet exploits discontinued routers. Our guest is Brian Vecci, Field CTO at Varonis, discussing how organizations can safely adopt AI and autonomous agents. A satirical startup sells clean-room clones. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices, Brian Vecci, Field CTO at Varonis, discusses how organizations can safely adopt AI and autonomous agents by securing data, managing risk, and focusing on measurable outcomes. If you enjoyed this conversation, tune into the full interview here. Selected Reading Anthropic's Mythos Model Is Being Accessed by Unauthorized Users (Bloomberg) Claude Mythos Finds 271 Firefox Vulnerabilities (SecurityWeek) New Defense Department cyber strategy imminent, official says (The Record) Pentagon Cyber Leaders Back $1.5T Budget Request (GovInfo Security) Ex-FBI lead urges homicide charges against ransomware scum (The Register) New Wiper Malware Targeted Venezuelan Energy Sector Prior to US Intervention (SecurityWeek) Over 1,300 Microsoft SharePoint servers vulnerable to spoofing attacks (Bleeping Computer) Harvester: APT Group Expands Toolset With New GoGra Linux Backdoor (SecurityWeek) Same packet, different magic: Mustang Panda hits India's banking sector and Korea geopolitics (Acronis) Mirai Botnet Targets Flaw in Discontinued D-Link Routers (SecurityWeek) This AI Tool Rips Off Open Source Software Without Violating Copyright (404 Media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
Patch Tuesday. CISA directs furloughed employees back to work. Experts warn Anthropic's Glasswing signals a new era of AI-driven vulnerability discovery. Federal prosecutors crack down on chip smuggling. Sweden says a pro-Russian cyber group attempted to disrupt power plant operations. A fake app in Apple's App Store drains crypto wallets. Virginia bans the sale of precise geolocation data. Our guest is Johnny Hand, VP for AI Excellence at TrendAI, discussing AI operational discipline. Do you need to buy a separate seat for your AI agent? Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today on our Industry Voices segment, we are joined by Johnny Hand, VP for AI Excellence at TrendAI, discussing AI operational discipline and real-world cyber impact. If you enjoyed this conversation, check out the full interview here. Selected Reading Microsoft Patch Tuesday for April 2026 fixed actively exploited SharePoint zero-day (Security Affairs) ICS Patch Tuesday: 8 Industrial Giants Publish New Security Advisories (SecurityWeek) Adobe Patches 55 Vulnerabilities Across 11 Products (SecurityWeek) CISA Workers Recalled Despite Shutdown (GovInfoSecurity) CISA cancels summer internships for cyber scholarship students amid DHS funding lapse (CyberScoop) Anthropic's Mythos signals a structural cybersecurity shift (CSO Online) We're only seeing the tip of the chip-smuggling iceberg (CyberScoop) Swedish power plant targeted by pro-Russian group in 2025, government says (Reuters) Exclusive: Russia-linked hackers compromised scores of Ukrainian prosecutors' email accounts, data shows (Reuters) Users lose $9.5 million to fake Ledger wallet app on the Apple App Store (web3isgoinggreat) Virginia enacts ban on precise geolocation data sales as momentum for similar prohibitions builds (The Record) Microsoft exec suggests AI agents will need to buy software licenses, just like employees (Business Insider) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
Half of consumer question the authenticity of what they see online.