Episode 423 – Non-Human Identities in Microsoft Entra with Eric Woodruff and Chris Brumm
by [Scott](/content/author/scottmsclouditpro/ "Posts by Scott"/index.html) | Mar 12, 2026 | Podcast
Blubrry Player
|
Auto Scroll
Welcome to episode 423 of the Microsoft Cloud IT Pro podcast recorded live from Workplace Ninjas US in December 2025. This is a show about Microsoft three sixty five and Azure from the perspective of IT pros and end users, where we discuss a topic or recent news and how it relates to you. In this episode, Ben sits down with fellow security MVPs, Eric Woodruff and Chris Brum, to discuss the often overlooked world of nonhuman identities in Microsoft EntraID. We cover service principles, why they tend to fly under the radar, and how attackers actively exploit that gap. They also spend time talking about credential management best practices, challenges around nonhuman identities, and how you should be thinking about them, especially with the growing challenges of how they relate to AI. Let's dive in. I'm sitting here with another episode of Microsoft Cloud IT Pro podcast at Workplace Ninjas, the first one in 2025. We all get to be honorary attendees, so Scott, who I normally do the podcast with, if you guys if people listen, is not here once more. But instead, I have Eric Woodruff and Chris Brum. And, we are going to talk about non human identities in Entra. So, this is an interesting topic because, yeah, I'm excited to dive into it. But first, do you guys wanna tell us a little bit about who you are, where you are, company that you work for? Yeah. Sure. Yeah. So I'm Eric Woodruff. Currently, I'm the chief identity architect at Semperis. I I do a whole mixed bag of things, which I I won't sorta go down the rabbit hole on there. But, yeah, MVP in security focused on identity, so all things, Entra, some active directory thrown in the mix. Yeah. And it's just it's, you know, great to be here. You know, I will say you can find me on the socials as Eric on Identity. It's maybe not super hackery sounding, but it's hopefully easy to remember. Okay. Yeah. There you go. Easy to remember is good. Hi. I'm Chris Broom. I'm from Germany, and I'm a cybersecurity architect with Glucanje. And, yeah, I'm doing cybersecurity for, I don't know, sixteen years or so. I think I did everything that you could do there, but my main topic is identity security. And like Eric, I'm also an MVP in that area. So my company is doing, yeah, managed SOC services mainly. Okay. And, yeah, we are protecting our customers, and I think identity is one of the main main topics there. Alright. So no red teaming? Are my devices safe around you? Yeah. Yeah. Yeah. I'm I'm in the blue team. Absolutely. So Yeah. That's kind of funny. Like security conferences are like, don't ever connect to the WiFi because you never know who you can connect. Yeah. You just have to scan this QR code. Yeah. So that's been funny. This conference, the amount of QR codes and everybody's like, this is a security conference. Yeah. Yeah. And we just found here USB sticks. Have you plugged it in yet? No. I don't do this in general. Oh, good times. So moving on to non human identity. It's like when I kinda reached out and said, who wants to talk on the podcast? Who wants to do some interviews? You guys were like, well, we did a session on non human identities in Entra. And this is an interesting one because a lot of times when people think Entra, they think, oh that's how I log in. I have my username, my password, I'm doing MFA whatever Entra. But there's a whole another component to it around non human identities and Entra that maybe sometimes gets forgotten and I think that was some of the premise of your presentation. Kind of what we wanna talk about today. Yeah. Our basic idea was to to just collect all the stuff that should become a knowledge by an intro admin and just to make sure that everyone knows it. So about permissions and credential handling and all the stuff that yeah. What could go possibly go wrong? Yeah. What are our topic? Yeah. Yeah. And I'll just say, like, I think, really mean the the term is new, but nonhuman identities have been in Entra for as long as it's been Azure AD. Right? I mean, like, we've been talking about service principles and stuff. They've always been there. But, yes, it's like a a hot topic in the industry now with nonhuman or workload identities, whatever you wanna call them. But yeah. And for as long as these have they have existed, there's abuses on them that attackers love. So trying to talk about those things. Yeah. So if somebody's newer to this because sometimes I think we even make the assumption, oh, everybody to your point, everybody should know about non human identities. When you start talking about non human identities, we're talking about SPNs. What are those? For somebody that may be newer to enter is like, wait a minute, I need to think about non human identities in Entra. Where do you kinda start with those when you talk to people about non human identities in Entra? I mean, I would say Chris is like, oh, no, not this topic. I mean, I guess it depends if they know AD. Right? If they know AD, I would try to relate it to, you know, GMSA's service accounts. Right? And if they don't know anything in general, I guess not that they don't know stuff. Right? I guess I'd be saying that this is like for you know, you think of applications that might go do stuff. You have SaaS apps that are doing things behind the scenes with, you know, data and like SharePoint or OneDrive or, you know, Exchange. Right? There's still identities to all those things. Right? Those services under the covers and that's essentially what, like, service principles are that are operating, like, without people. That's the the non human part. Yeah. And a lot of those have access to data. And I think that was a big part of your talk is or part of your talk, and I'll let you guys kind of direct it is managing those SPNs and to your point, they have access to data much like a user would, but yet I don't think they maybe get us necessarily as much attention as users and what they have access to. Yeah. I think there are two big topics that we have to talk about. And the first thing is what permissions can f apps have. So and apps can have huge permissions. So and we should if an app has the same permissions like a global administrator, we should handle it like a global administrator. And the other part is, okay, who has permissions on apps? And there are some really bad practices out there. So as an example, yeah, a lot of companies are assigning owners at at the app registration and the service principles, and they are assigning that owner permission to normal user accounts. So and an owner is such, yeah, is a person who can do everything with that app. So including adding new secrets and log in as that app and use the permission of the app. So there's a big potential for stuff that could go wrong. Yeah. So as you're working at identity then, you're working with this SPNs and the owner rights and doing all of that. How do you start guiding people through some of that management of those SPNs? Yeah. I mean, I'll I'll say it's tricky at times because but there's always places where customers love Microsoft docs and customers want to do nothing against Microsoft. Right? They wanna do things as, like, this is what Microsoft wrote. That's what we wanna do. And occasionally, right, the rest of the industry disagrees. And and, like, owners is a thing. In particular, like, when I worked at Microsoft, I would tell people, go add, you know, Joe, you know, owns Salesforce in the business. Right? Go make Joe an owner. So that way you sort of know, right, we gotta go bother Joe about Salesforce. Not realizing that again, if an attacker targets Joe who's not treated as a privileged user. Right? That now attacker, right, compromises Joe, phishes him, whatever. And now attacker can move into Salesforce. And and to your point about data. Right? You see in the news that data is the thing attackers want. Yeah. But identity So it's a little bit. Yeah. Yeah. And but the I mean, I think to what we were saying about the permissions that they have on data. Right? Like, obviously, like, it's very broad. Right? Like, if an application has permissions to exchange, right, many times, it's like it has permissions to everyone's mailbox and can do whatever it wants with all that. So, yeah. Yeah. I think about that. Like, I've I've done migrations before. Right? Whenever you start migrating email, they're like, oh, go create the migration tool, the exchange web I think it's exchange web services Yep. In the SPN. Go create an SPN for it. Go create access so it can migrate all the email and it is it's that concept of wait a minute if this is migrating all the email it's touching all the email which means it's going to have access to all of the email and am I treating this in that way? Yep. And in this case, it's not only about write permission. So people don't usually, when when I talk to people, say relax when they heard say, it's only read permission. So, yeah, but read permission to your whole file system or your whole mailbox is, yeah, also. But Yeah. Pricing. Data data exfiltration is a is a huge problem right now. So yeah. And I think we you maybe have or we see better practices regarding authentication method policies and conditional access rule set, but it doesn't affect work nonhuman identities usually. So there are other policies. There are application management policies, and there is conditional access for workloads by yeah. But I rarely see this. Yeah. Yeah. And I mean I think it's almost like right like workloads, service principles, they're treated like a sort of second class citizen. And and I get like as a sys admin right you might feel like you already have too much to do. So it's easy to say you have to do more. But on the other hand, attackers love going after service principles because they they tend to know that assist admins don't have a strong understanding of what they do or what they have access to. And and again, if you see a tax on, you know, Microsoft three sixty five going after, you know, OneDrive, SharePoint, Exchange, many times it is using those, you know, enterprise apps as your service principles that they'll they'll leverage. So This episode is brought to you by Trusted Tech. If you're managing Microsoft three sixty five, you already know licensing isn't simple. E three versus e five, the brand new e seven licenses, Copilot security bundles, and with price changes coming in July 2026, the stakes are getting higher. Trusted tech helps IT leaders make sense of their Microsoft three sixty five environment with a free licensing consultation. Their engineers analyze what you're licensed for and what you're actually using and where you can optimize, whether that means consolidating security tools, preparing for copilot, or eliminating wasted spend. Plus, they offer proactive and reactive support, which has been awarded yet another solution partner designation from Microsoft for support services. If you want a clear, data backed plan that has helped over seven five hundred subscribing customers save up to 20% on Microsoft three sixty five before your next renewal, visit trustedtech.team/mscloudprom365 and schedule your free consultation today. We talk about security risk for unused user accounts. Right? Like, you have an unused user account that's active. Part of the reason that's a security risk is it's not monitored or watched as closely because the user's not using it. I feel like service principles can kind of fall in that boat as, yeah, they're being used, but they're probably not being watched Yeah. Quite as closely as a normal user account Yeah. So to speak. And attackers probably tend they don't wanna be seen. Yeah. Yeah. They're gonna go after things that aren't as visible. Yep. Yep. Yeah. I mean, I would say, you know, using service principles for persistent. Right? Persistence, like, assigning credentials to them, but in the way that they can dwell. Right? Like, they might get access to something and then wait and see if they're detected. Right? And then after some time, then they go on to do their their nasty Yes. So yeah. And as I said, my team is running SOC services. So and monitoring credential addition to a service principle in a bigger environment, that's so loud. We see a lot of modifications. We'll see a lot of credential adding and so on. You really have to correlate this with the permissions of the app to get a reasonable signal to noise ratio. So Right. So do you have guidelines, Chris, in, like, how you guys do that from a SOC perspective that if end users are doing this or not end users, but other sysadmins, companies are doing it internally is how do you go about even starting to monitor things you maybe watch for? You have to do both. You have to do prevention and detection. And I always start with, okay, do you have any life cycle processes? So companies usually have managed to have life cycle processes for their users. Admins is getting more rare and for non human identities. So, yeah, it's lost in vain. There are some good practices. So there are a lot of good practices around how to implement OpenID Connect. So this is for the developers. You have to be the go to person for your developers regarding identity. And there are some good practices how to configure the applications. And you should leverage that. Yeah, that workload ID features. Is that it's a separate license, but, yeah, we for powerful apps, I think it's reasonable to protect them. And if you want to monitor your apps, you have to rely on on the intro audit logs and you can adjust them in Sentinel. A good starting point is Microsoft has has a repository full of detections. But yet, to be honest, this is very noisy because it's just detecting, yeah, someone added a reply URL. Someone added a credential. So without context, it's very, very hard. So and this is what yeah. This is what what SOC providers are doing. So someone added a credential. Okay. We have a sign in risk. Okay. But if we have a sign in risk and then this person is adding, credential to an app. This is interesting. So it's regarding context. And another context is, okay, are we talking about an app without big permissions or are we talking about an app with very high permissions? And bringing all that stuff together. But, say, yes, there's it's hard to do a one on one on this. Yeah. There's a lot of data there. And it was interesting you mentioned developers and because I do IT pro stuff, I like to pick on developers and probably pushing that because developers probably have a tendency too to say, oh, I'm writing an app. It needs a service principle. Just give it these permissions versus really trying to narrow down and really hone what does it really need versus what makes a developer's job easier. Yep. Yeah. I mean, it's it's easy to sort of dump on developers and, you know, no offense to them. And I get that they have a job. Right? Like, if Yep. If you're a software company and you're not making software, then you'd have no reason to be there. But, yeah, there it it's I think the problem is finding in the business, like, the balance. Right? And it's not the same across the board. Again, companies just wanna be sort of told what to do, but it's it's more of an art, I'd say, than a than a science because, you know, like, developers, right, you need to make sure that if if you create too much friction they'll go spin up their own tenants their own subscriptions right and they'll go do all their developer stuff possibly with like real data and now you have shadow IT things going on. Right. So yeah, you definitely have to like configure things in a way where you can let developers do their stuff, but I think I'll just say also security people tend not to like to talk to anyone. Right? Yeah. Yeah. We really don't. But but I mean it is one of the the points we try to drive home in our talk is like you need to work with your developers, right? Like you you can't expect everyone to be an expert in like OpenID Connect. I mean barely security people in the industry. But you need to work with them, right, to make sure that when they're implementing things that they're doing it right and not, I'd say, almost like shaming them for not, like, understanding every OAuth flow out there. Yeah. Yeah. And and I think another important thing is, so, yeah, people make mistakes. We don't know stuff. Yeah. We know today maybe stuff that we didn't know two years ago. So and it's a good idea to make regular reviews. And there's a lot of open source community tools out there. So stuff like, entra ops. So greetings to Thomas Nalheim. And, yeah, just use it and review your environment and find that stuff. Yeah. Yeah. And another thing that kinda goes with developers, and I know another thing you touched on in your talk was not just these SPNs and the permissions they have, but there's secrets and certificates and how these how you actually authenticate to these applications Yeah. And managing some of that. Do you want to talk a little bit about what you guys touched on best practices, things that people should be aware of when it comes to credential management for non human identities. Yeah. I mean, that that is a ball in itself. Right? Like, I mean, if you're talking about credentials, I mean, you have secrets which are the easy thing, but it essentially is just a password. Right? It is a password for an application. It's a better name. Yeah. Right. Yeah. We should just call it app passwords or something. Although we used to have those in Entra. Well, I think in graphs, either on app registrations or service principles somewhere, like, it It's a lot of secrets in the UI, but you then you have certificates, right, which are better, but certificates also, right, people can still do silly things, leaving them laying around. Yep. Like that. Save them to their documents so they sync it up to OneDrive. Yeah. So I mean, Lori, the the North Star is is like federated credentials, which, again, is something that's difficult to understand for some people. But in if you're, like, solely like a Microsoft shop, right, like, it's manage identities, which are easier to deploy. Right? Because then you don't have credential management. Nobody's having to hold secrets or Right. Use them. And another advantage of the managed identities is that you have an integrated life cycle. If you delete that function, the, the managed identity is also gone, including its permissions. So Yep. Yep. And I mean, I I will say, right, there's security research out there that will show there's sometimes cracks in sort of hybrid things like with ARC relative to manage identities. But I think if you sort of zoom out, right, and look at all the issues people have with secrets, right, it's still better to use manage identities whenever, you know, possible than, you know, certificates or or secrets. So yeah. And and I think we have to talk about this secret password. So if we if the time comes, we have to get rid of it because I know it's hard to do it, and it's even harder than with end users. But we see attacks where attackers are phishing developers and or attacking developers to get their secrets. So there is an attack out there that's called, ShyHulu, and it's leveraging that NPM packages. So they're they're targeting developers for NPM packages, then they are distributing malicious NPM packages to the max of the developers. And then there are tools like TruffleHawk that are scanning for secrets in GitHub repositories. And then you see an a login of an of an application with a correct password out of nothing, with a correct secret and so on. And it's, yeah, almost impossible to monitor. So and and even on the endpoint perspective, so yeah. Developers are not the best protected part of most environments and lock in lock ingestion into your theme from the GitHub and so on. This is also not very common. So yeah. And at the end, we have also as I said, we have to do some preventive stuff and we have to do some detection and prepare for response. But as the best prevention is to get rid of these secrets or passwords. When I think of nonhuman identities, I probably tend to hear the most is, to your point, someone leaving a secret in their code or they go in and check some code that has that secret into a public repo and it's like, oh, but I pulled it down five minutes later after I realized it. You don't know who saw that in those five minutes. Yeah. I feel like that's where I hear the most compromises when it comes to SPNs is due to those secrets and just I don't know that I wanna say carelessness, but just accidents happen. Right? Probably everyone whether they want to admit it or not. Right? Is guilty of like sending a password or something over Teams and be like, I'll delete it right after. Right? But I mean, there there's absolutely, you know, risk in there. I mean, and I I've been guilty of the these things, you know, myself. Right? Yeah. I mean, the secret part I think is also tough. Just just made me think of earlier when you were asking Chris about detection. It's one of the other things with secret management as we we now are also starting to talk about, like, well, let's lower the lifetime. Right? Because it it'd be like, well, I'll go ahead the certificate as a secret, and I'll just have it not expire until I'm retiring. Right? I'll make it somebody else's problem because we all hate rotating search. But now we're we're going down this path of saying like short lifetimes whether it's certificates or secrets which is awesome but now it creates I mean, in my eyes, right, even more noise if we're saying every every week, right, that that credential should be rotated. Yeah. And if we have different policies for lifetime, for secrets, and for certificates, maybe we are nudging the developers to rethink if a certificate would be an alternative. Yeah. Yeah. So when you work with customers, do you it I'm sure it varies customer to customer, but do you guys kinda have like a recommended, you should maybe we're not gonna go till you retire, but it's okay to go a year, two years, or I know passwords like the NIST is now saying, oh, just rotate it when there's a risk detected. Yep. Yep. I mean, I don't know, like, I think certificates like the Microsoft recommendation now what I think is six months for the lifetime on them. I mean, I I would say in ways, right, you could be more aggressive than that. I mean, honestly, like, I'm not a developer so I don't wanna pretend that coding is easy. But in other ways, right, like, I think sometimes people don't put the effort into the fact that, like, if you own if you have control over the currency graph, it's just like a few graph API calls to ask for a new one. Right? And and I mean, if you see a big identity systems where they have certain workload stuff like, I think Spiffy Inspire do things where it's like, you know, they're they're like rotating the secret like daily. Like that is used behind the covers for some of this stuff. I'd like to pick up the point, change password only if you have a reason. So this is something for user accounts, not for admin accounts. And we should delete workload nonhuman identities more than admin accounts than as user accounts. And I think that don't share don't rotate passwords is there is a yeah. I think we all think or come to the conclusion, a password is not enough. And we have additional stuff like MFA, device compliance, and all of those things. And, yeah, we don't have it in place in most environments for nonhuman identities. So the only things that is between an attacker and the and the resources is just a password at that point. Yeah. And I think, yeah, we should try to get rid of passwords. We should decrease the lifetime. And and, yes, we should introduce stuff like conditional access for workloads. So Yep. Yeah. I mean, I was just saying not not to increase my my Microsoft stock value but like for like a lot of people don't do workload identity protection. Right? Because it's like a pay for thing. But I would just say and I try to tell people like if you can identify what is considered like the high privileged risky workloads. Right? I mean, it's, like, $3 a month or something. So say you have 10 or 15 service principles, like, start there. Right? It's only, you know, maybe a $100 a month to protect those. Right? But you could be potentially protecting the keys to your kingdom with, you know, conditional access for workloads and the identity protection features. So That's an interesting one too. Is Microsoft starting to do There's a couple aspects there. They're starting to do a lot more with conditional access for non human identities. Around SPNs, Ignite, couple weeks ago they said you can start doing conditional access now for agents which are just Yeah. Yeah. Look, agents are exploding in creating just a massive new influx of additional nonhuman identities. Do you work with clients around the conditional access and around some of the how do we start thinking about agents? Kinda two questions in there. It it it starts. So I think we are in the beginning of that. So there's just a big interest out there. So and our first message is the building blocks for agent IDs are human and non human identities. So they are not reinventing the wheel. They're reusing the building blocks that we already have. And if you have a good practice for protecting your human and not non human identities, you have a very good starting point for all that agents. But, I mean, I would just say with agent IDs and and workloads specific to conditional access, I think it's so when it's like being open minded. Right? Like, in for a long time, we say zero trust does not, you know, network. And people are like, well, I'm just gonna make my conditional access policy for users say, well, if you're coming from corporate network, like, don't MFA. And we're like, that's an awful idea. Right. But if you look at workload, right, like, workload because it's different and agent ID included here. Right? If you have the ability to say, if it's coming from, you know, this, you know, data center, the this egress. Right? Network location is one of the few things that you can use. Right? So it's like, in these cases, it's better than nothing. Right. You can't really MFA a SPN. That would be Right. Right. And I mean Certificates are MFA. Yeah. I mean, but I see I've seen people ask, like, weird things like, can you assign FIDO two keys to you know Yeah. And and yeah. But it like sometimes I think I'll see people say well we're not supposed to do network for users so why would we do it for workloads and and almost like right maybe we've caused the own problem as security people by saying don't do that so much. But I think it's like looking at it right well, it's it's better than nothing. Right. It's one of the few things we have. So Yeah. And I'd like to add something. I think so we will see what happens with that agent IDs, but I think we will have a lot more non human identities. So there will be much more agents and applications, and we already have in many environments more applications and user. So just from the quantity, we have a bigger problem there. And I think the permissions of agents will be a little broader because you don't exactly know what is really needed. So and I think over time, the permissions of the agents will extend. So we have more of them. They have more permissions. So, yeah. We have to take care of it. Yeah. Because I think especially with agents, to your point people are like an agent's not any good if it doesn't have access to data. Right. People are like I want it to have the access to the most amount of data so my agent's good or this data or that data. And we've already seen, right? Copilot came out and everybody's like, Oh, all these security issues. And it's, no, it doesn't create new security issues. It just It identifies. It highlights quicker Yes. The security issues you already had. Yep. Yep. And we're gonna continue to see that and I think to your point it's just going to create a whole new security issues are gonna become more easily quickly visible. Yeah. But yeah, I mean that's like I feel like I'd see so many people you you had the similar problem with with Delve. Right? But like Yep. You know, point at SharePoint and then all of a sudden people like, how come I can see all this corporate data I'm not supposed to because it's indexed and you can just go write query. But that's not, like, AI's fault. It's that you have, like, everyone has access to everything permissions going on. Right. If you would've used SharePoint search or Microsoft three sixty five search, you probably could've found them. It would've just taken a little longer. But no. I mean, it it's definitely, like, not even just a Microsoft, but industry thing that I feel like people are noodling on. Right? Because we have this issue where, yes, you wanted to have permissions, but then you say, well, you only wanted to have permissions when it needs them. But also if if you're hammering a user constantly saying, like, do you want the AI to still have permissions? Like, you have fatigue and people just start hitting yes all the time to things. Right? I mean, that's like a lot of consent grant issues where because nobody reads the thing. Right? You're just like, I just want it to work. Yes. Yeah. Yeah. So it's like trying to figure out how how can you let AI do its thing, but also not let it just, like, run away with access that is, you know, out of control. So and I don't know if there is, like, an answer out there yet for a lot of this. So Yeah. I think we can be happy that Microsoft has just launched that that AirBad stuff, and we will have conditional access and all of that stuff so that we we can, yeah, build good practices and guardrails and all of that stuff. Yeah. Do you feel overwhelmed by trying to manage your Office three sixty five environment? Are you facing unexpected issues that disrupt your company's productivity? Intelligink is here to help. Much like you take your car to the mechanic that has specialized knowledge on how to best keep your car running, Intelligent helps you with your Microsoft cloud environment because that's their expertise. Intelligent keeps up with the latest updates in the Microsoft cloud to help keep your business running smoothly and ahead of the curve. Whether you are a small organization with just a few users up to an organization of several thousand employees. They want to partner with you to implement and administer your Microsoft cloud technology. Visit them at inteligync.com/podcast. That's intelligink.com/podcast for more information or to schedule a thirty minute call to get started with them today. Remember, Intelligink focuses on the Microsoft cloud so you can focus on your business. Anything else that you wanna talk about, you wanna make users aware of when it comes to managing those nonhuman identities and and try. I think we covered some of that credential management, the permissions. I think we touched on ownership a little bit, some of the agents. Anything else? I think when I look at our presentation from yesterday, there are two things that are, yeah, problematic. And we already discussed the first thing that was the owner assignment, get rid of it. Yep. So use administrative roles for this. So like a cloud application admin, scope it to the dev. And the other part was, yeah, multi tenant apps are really challenge. So and we see we we saw a funny incident with, yeah, multi tenant apps by accident. So I think the Bing Bang story was one of the more known or someone it's just a radio button. Who is able to sign in? And Yeah. I mean, I I I tell you like with that. Right? So Bing Bang was when Wiz did research and found they could basically they they got into, like, some Bing back end and they could edit, like, search results. Got it. But yeah. Right. It it's like a radio button, but a lot of times you'll see devs again maybe sort of jumping on dev. See, right? They'll they'll pull up basically all the authorization sort of checks on enter. Right? And, like, people conflate authentication and authorization. So they won't have any logic in their app and they're just like, well, if they've authenticated, then I guess they should be here. Right? And now it's a multi tenant app that shouldn't be. And so you end up with anyone. Right? If they stumble across a thing, can go sign into it. And interestingly enough, you'll see a lot of times devs won't invest effort on, like, an admin sort of interface. Right? So maybe they have all this authorization stuff on a front end where all their customers are logging in and then there's some other admin portal thing that if you can get into it, right, you just have free reign to do whatever you want. And again, that's like basically what Wizz found in a lot of their the research. I mean, they were going after Microsoft stuff specifically. So Got it. I think the common the main problem with multi tenant apps is that we have a lot of controls in the app that where is the service principle, not in the app where the app registration is. And the attacker can have its own service principle and has control over assignment and role mappings and all of that stuff. And, yeah, Eric just yesterday showed those in no hours attacks, so you can find it also on, it's on your on your blocks. Right? Yeah. And and we know of, is on the December's blog. I I would spend an hour trying to explain it because I ramble about I mean, I I think I think a simple thing with with multi tenant apps is like, if you are not a software developer, like, as a business, you probably shouldn't have the app there. And and that is something again that you could use, you know, free tooling, paid tooling, right, to go find those sorts of things. So Yeah. So and if you are troubleshooting and switching configurations of your app I've seen that a lot. Don't touch this. It won't solve your problem, but bring you new problems. Yeah. Yeah. And and as I was saying, again, it's good to do reviews. When I I'm doing re entra reviews, so we are selling this as a as a package to customers. So and one of the main things I'm looking for, okay, do you have I'm always upfront asking, do you have any multitenant apps? No. We don't have. So and then I just turn turn on the tools. Okay. We found 20 of them. And usually, you just can turn them off. And when there are some that are not by accident, you have to endure that people running the application are doing additional stuff. Yeah. So Yeah. And I think that highlights again, like we talked about earlier, the need for security and developers to talk to each other. Yeah. Whether developers don't even, some developers may not even know, I don't even know what the difference is between single tenant and multi tenants. And really having that conversation and I've seen this across all of Microsoft March is one thing I feel like the cloud has done is it's caused IT people that don't typically like to talk to each other Yep. To have to talk Yep. Because all this stuff is so tightly integrated and has some of those broader reaching effects. Yep. No. I mean, absolutely right. Like, you start to see conversations about soft skills and communication, all that. Right? Like, coming into the industry because, like, sometimes the best security person isn't because you have the biggest brain. It's because you can work across the organization, right, to help implement strong security practices amongst your developers, amongst your end users. Right? This isn't like the old days where you could be that bastard operator from hell, you know, and just tell people to do this thing. Right? Because then you get shadow IT and and all sorts of stuff. So, yep. Awesome. Well, thanks guys. Yeah. I I appreciate the conversation, talking a little bit more about non human identities. We'll include a bunch of links in the show notes. I'll get links from you guys to social media where you want, if people wanna connect with you there, websites. If you have links to tools, I'll get some of those that we can put in the show notes as well. Any last things you wanna share, highlights, telling people to come to this conference next year or 2027, I guess. It was really a nice event, so Yeah. No. I mean, this has been great being at the inaugural Workplace Ninjas and hopefully I mean, we're a little ahead. I'm I'm hoping I can claim now that I will become the intra idol from the inaugural workplace Oh, do I need to go I have not voted yet. Do I need to go vote for You need to go vote for me, Ben. You have to you have to vote for Eric. Yeah. But, no, I mean, as far as myself, I'll be actually over in Europe at MC2MC and then Hip Europe a couple days after that and then Experts Live Denmark. We're co presenting Chris and I at MC two MC so Okay. Are you gonna go most important question if you're going to Denmark. Are you gonna go to the Lego headquarters while you're in Denmark? Oh, I do. Are you a Lego guy? Yeah. Yeah. It's not really close to Kommang. Is it? Oh, I I have no idea. But, yeah, I I am a Lego guy, so You can go get those secret Lego sets. There's what? The two LEGO sets that you can only get at LEGO headquarters in Denmark. Oh, I did. Oh. I'll have to how far is it? I think for for Americans it's not that far. I will go rent the biggest SUV in all of Denmark. Go buy Allego. Right? We're in Texas. We're like Texas is huge over there. Everything's closer than driving across Texas. So, yeah, I'm really looking forward. So this year was also was already a cool event in in Copenhagen, but and and next year will be a really huge, I think. So Yeah. And but I also in enjoyed this web with New Year's US. It was also a very nice event. And, yeah, we have a full second day. So Yeah. Yeah. Alright. Well, I will let you guys go enjoy your second day. Thanks again. Enjoy the rest of the conference. Awesome. Talk to you guys later. Thank you. Bye. If you enjoyed the podcast, go leave us a five star rating in iTunes. It helps to get the word out so more IT pros can learn about Office three sixty five and Azure. If you have any questions you want us to address on the show or feedback about the show, feel free to reach out via our website, Twitter, or Facebook. Thanks again for listening, and have a great day.
Donate
Share
Apps
Menu
Microsoft Cloud IT Pro Podcast
Open in new window Display Menu
Episode 423 – Non-Human Identities in Microsoft Entra with Eric Woodruff and Chris Brumm
|
Back 15 seconds Forward 15 seconds Play Speed CC
Podcast: Play in new window | Download (Duration: 38:41 — 26.6MB)
Subscribe: Spotify | Amazon Music | Pandora | iHeartRadio | Email | RSS
Welcome to Episode 423 of the Microsoft Cloud IT Pro Podcast. In this episode, Ben is live from Workplace Ninjas, joined by Eric Woodruff, Chief Identity Architect at Semperis and Microsoft MVP in Security focused on identity, and Chris Brumm, Cyber Security Architect at glueckkanja and Microsoft MVP in Security with over 16 years of experience in cybersecurity. Together they dig into the often-overlooked world of non-human identities in Microsoft Entra ID. They cover what service principals are, why they tend to fly under the radar compared to user accounts, and how attackers actively exploit that gap. The conversation spans credential management best practices, the risks of improper owner assignments, the challenges of multi-tenant app configurations, and why managed identities should be your go-to wherever possible. They also discuss the growing challenge of AI agent identities and what IT pros need to start thinking about now before that surface area explodes.
Episode 422: Back to the Terminal: The Rise of AI CLI Interfaces
by [Scott](/content/author/scottmsclouditpro/ "Posts by Scott"/index.html) | Feb 26, 2026 | Podcast
Blubrry Player
|
Auto Scroll
Welcome to episode 422 of the Microsoft Cloud IT Pro podcast recorded live on 02/09/2026. This is a show about Microsoft three sixty five and Azure from the perspective of IT pros and end users, where we discuss a topic or recent news and how it relates to you. In this episode, Scott and Ben discuss their growing use of AI CLI tools and their daily workflows, particularly, Claude Code, GitHub Copilot CLI, and Gemini CLI. They explore how these command line interfaces offer powerful ways to interact with local files and MCP servers beyond traditional desktop desktop AI chat interfaces. They share how they are using these tools in their day to day roles to perform different tasks and accelerate their workflows. Kinda funny, Scott. We're in the same city, but we still record this remotely from our offices. But we'll go out and hang out for breakfast. And we had this conversation the other day too even around AI of, like I don't I'm curious what listeners think. Like, if there's other stuff that listeners are seeing that we're just missing or not talking about that they wanna hear about. But both you and I have had this feeling of, like, all we talk about is AI because that's 95% of the news, and all the other stuff is just like, there's I've been struggling, and I think you have too, of coming up with non AI topics to talk about new features and functionality. So I am curious. If there is stuff that other listeners wanna hear, like, let us know because we would love to know what others are interested in that maybe we haven't covered or haven't covered in a while outside of AI. LinkedIn is the best place to let us know, or you if you're looking for something a little more anonymous, we have a contact us form, m s cloud I t pro dot com. Re reach out and let us know what's on your mind. To your point about, like, the news Or I couldn't find us at a conference. Like, we've done some interviews. We have some coming, but this was on the recording before it crashed, is we'll be at MVP Summit. So if you're an MVP and wanna talk to us about something or have something, find both of us at MVP Summit. I'll be down in Orlando at the m three sixty five conference in April. So, yeah, that's another way you can find out a find reach out to us, talk to us, tell us what you want us to talk about. Sorry. Now I'll let you talk, Scott. So you had mentioned kinda news is slow. There's not a lot of new features, thing things like that coming. We keep ending up on this AI thing. But I think for me, what I'm finding is I'm also using these tools more and more, more and more in my day to day life. And That's fair. And a lot of that is definitely a function of my role in running through things, but I think you use these tools a whole bunch too. And I've been on this path lately where I even see lots of, like, sorry, the normals out there, like, big air quotes, like, the normal people who aren't in tech who are also using these things. Like, I was having a conversation, over the weekend. We went to it was Super Bowl, so we went to a Super Bowl party. So I was having a conversation with somebody, and they go, oh, hey. Like, you're at Microsoft, this Copilot, AI stuff, blah blah blah. I use ChatGPT, and I'm paying $20 a month for it. Is there anything better? I've heard about I I heard about ClaudeBot, which then became Maultbot, which then became OpenClaw, blah blah. Like, in the news kind of thing, should I do that? And I was like, I'm of the opinion at this point that if you're not in, like, the m three sixty five ecosystem and, like, you're not doing, like, Microsoft Copilot, things like that, and you're just looking for, like, general, like, AI chat for business, like, man, if you're gonna spend $20 on something, spend it on Claude. Like, switch what you're doing with ChatGPT and push over to Claude where you have access to all these tools even in, like, their $20 a month plan. So you get, like, Claude Cowork as part of Claude Pro. You get access to MCP servers. Like, we still don't have, like, broad access to, like, local MCP servers within ChatGPT. You cert ChatGPT desktop, I'm talking about, or, Copilot desktop. Microsoft three sixty five. So these things become super powerful. But then the geek in me has also, like, turned and I don't know how this is going for you. So I've been on this natural progression of things like Claude or ChatGPT or Copilot just through their desktop interfaces and doing that, and then kind of moving I started moving a bunch of stuff over, what, the past two, three months maybe into Versus Code where I could have native access to MCP servers. But then I got to this point where and I I've been chatting about this with a couple of people too. I've gotten to this point where I'm opening Versus Code, but a lot of the things that I do are kinda aggregations and chats that go between MCPs. I wanna run them in different models, things like that, but I don't need full access to Versus Code. Like, I'm in this window that has takes up a big portion of my screen, and I'm using, like, a little slice of the window for the agent chat, things like that. So I've started moving from the agent chat into the CLIs. And I've been playing around with Cloud Code, Gemini code, Gemini CLI, and then you've also got GitHub Copilot CLI that sits out there and is and is an option ready to go. So I'm kinda using GitHub Copilot CLI at work in my day to day job, and then I I subscribe to Cloud Pro. I think you do as well. So, you know, kinda Cloud Code, but then I've also been playing around even with just Gemini code with the free version of Gemini and some of the like the Gemini fast and things like that that are available out there. So I think it'd be fun to just kind of talk through, like, how we're using these things and what you're kind of finding in your day to day. I know for me, like, I'm actually really having fun going back to terminal life. It reminds me of like being like my career like twenty years ago when I started doing like Raul deployments, and I was in Linux land for customers and having fun there. So I figured maybe we start with, like, Cloud Code and what we're doing, like, with that, and then I can talk a little bit about maybe, like, GitHub Copilot CLI and what I'm seeing there because I don't think you've played around with that one too much. No. I haven't done Copilot CLI much. I've been, if you're one of my customers, don't hate me, but Microsoft three sixty five Copilot has its advantages. I'm spending way more time in Claude to the point of I had this discussion with somebody earlier today. I have Microsoft three sixty five Copilot as part of I can't remember where it came from, but I would probably still pay $30 a month for it. I get a few licenses for free through different partnerships and some of that. But the other day, I actually just upgraded beyond the $20 a month plan for Claude to the $100 a month plan for Claude. Oh, you've gone there. I haven't gone there yet. I have gone there. I have absolutely gone there. And I, like, I legitimately have tried to get Copilot to do some of this stuff, and it's gonna be interesting to see how this all plays out over the next year. But I have found way more benefits in Claude and even capabilities. So I'll give you an example talking about how we're using it. Going into kind of the first example was in what pushed me to the $100 plan. I was working on a presentation, and I had the presentation all done. I went into my slides and did, like, bullet points. So it was the first two or three slides, then I had, like, five or six slides of just black and white bullet points. This is what I wanna talk about, and then, like, the outro slide. So the intro slide had some of the theming, some of the pictures on it, all of that. I actually told Copilot, I'm like, go in and make my PowerPoint look good. Like, keep the colors from the banner, keep the colors from the header. Just clean up those bullet point slides to make them kinda match the theme on the beginning and closing slides, rearrange the text. Like, I want it to look good. I can come up with the content. I'm not a designer. And the first pass, it came up with something just completely off the wall. Didn't match any of the colors. Just it didn't work. And then I tried it two or three more times, and it actually wasn't changing anything. I went in and did the exact same thing with Claude. I can't remember if I used Claude code and used the CLI version of it because then I can point it to, like, the physical PowerPoint presentation on that was synced down via OneDrive or if I did it in the desktop chat, but I ran out of tokens when it was trying to process the PowerPoint and reformat it. So I just paid to upgrade. I'm like, you know what? Let's just see what this does. It did a really good job. Like, all I had to do was go in and adjust some font sizes. Like, colors were different shades, matched the banner. Everything was formatted nice. It split stuff up into two columns where it made sense. It put little icons in there. Yeah. I know I should be talking about my accessories as FabQuote, but it yeah. Claude did way better. That PowerPoint add in, it's in beta. They released a I can't remember. It feels like a Yes. It might have been a little while ago, but it is a good one. I did not I didn't even use the plugin. I couldn't get the plugin to work yet, so I just did it in native Claude, but I wanna try the plugin because I have one for Excel and one for PowerPoint now. It's an interesting one. So I think that's one of the nice things about when I think about Claude in particular, like as a desktop experience, like Claude desktop automatically, you can just go flip the switch and have desktop integrations and things like that. You can do similar things, yes, with, with ChatGPT as well on on the desktop. But some things like m three sixty five Copilot, like, they're very much built around, like, hey, use my files that are already stored up in SharePoint or in OneDrive, things like that. So it's a little bit of, like, a disaggregated experience there. So one of the cool things you do with, like, Claude or, like, particularly on Claude code on the desktop side is just go fire up a terminal, and you can do things like say, hey, create maybe you've got like a bunch of markdown or a bunch of other like artifacts that you're gonna build into something, you can just point it at those. It can enumerate your file system, pick those back up, get you into a good starting space. The other cool thing you can do with Claude, particularly with the these things, I guess, we get into talking about the CLIs, is you have these concepts of things around, like, agents and sub agents and skills and different plugins and different MCPs that you can bring in. But you could potentially, like, go and create like, if you're doing this all the time, hey. I'm creating PowerPoint presentations for maybe customers around the same things, things like that, you could go and create yourself an agent where an agent is just a markdown file that just describes the set of functionality that I want this thing to do. Hey, go create an agent for maybe PowerPoint presentations on the value of IntelliJunk, and then you can go and spin that for customer by customer or have agents compete with each other. Like, it it it's really cool stuff. My my only limitation, I'm a little jealous that I've created, is the $100 plan, is burning through the tokens very fast. And it does burn through the tokens. So I just did something kinda where we were getting ready for this. And this is one of the nice things I like about the CLI is you can go see your context usage, how many tokens you're using. So I have some MCP servers. So I popped open Cloud Code, CLI, and just ran, like, two or three, just asked two or three questions, like, overdue tasks and it goes and pulls them from Asana using the Asana MCP server. It goes in and I asked for, like, emails that I got in the last week, and it used the WorkIQ MCP server. And I asked it about meeting notes and Notion, and it used the Notion MCP server. I have content in all three of those. That alone between the prompts, loading the MCP tools, I do have some custom skills that I've created in the CLI that we can talk about. And the prompts, like, I ran it went ran, like, the slash context to see just how much those three questions, all the MCP servers, and everything took up. And I'm already at 63,000 of my 2,000 token or 200,000. 63,000 of the 200,000 tokens, for that particular context window before it needs to go in and do things like starting to auto compact the buffer and compact the conversations and do some of that to make additional rooms. So I do like that about the CLI too that I can get some of that and even see it tells me how much of my context window am I using for system prompts, for system tools, for MCP tools, for skills, for messages, save some for the compaction, and then how much free space I have left. I've noticed it starts to drive me in different directions for some of these things, like token compaction. Like, hey. Let me save off this session or a specific subset of what was done in this session to, like, just just a markdown file. Like, hey. Just spit this out to a directory and have it come over for me, and then be able to reuse those sessions, save yourself tokens on spinning up the next one, things like that. So so I'm kinda interested. You said you're using MCPs, it sounds like, and kinda wrangling things together. Folks definitely go check out the WorkIQ MCP if they haven't done that yet and you're in the m three sixty five ecosystem. But you're using MCPs and kinda maybe wrangling that between various various models that are out there. Have you started playing around with, like, agents and skills or plug ins, any of that stuff? I've done some stuff with plug ins and skills. Agents are kinda next up on my list. But I would say from the plugins and skills perspective, I actually went in, and this is another cool thing. And I think you can do this with Visual Studio Copilot too. But I actually created my own custom plugins. So I created, like, Ben Stedjink's Claude plugins Yep. And published it out to GitHub repo. It's a private GitHub repo. And then in that plugin, I created a, like, a Ben Stedjink core plugin, just an overall core plug in, and then an intelligent core plug in or skill. So or no. Those are those are technically plug ins. And then inside of those different plug ins, I put skills. So, like, inside of the Ben Stedjink plug in, I have a skill for my voice and my tone and different things I wanna do or things I want to do. Like, I never use em dashes or frankly any dashes in any of my responses or anything I type ever. So in that skill, I'm like, just don't ever use em dashes. I don't use em dashes and dashes. It shouldn't be in anything that I ask you to generate for me. Like my core one, I went in and I created a whole, like, dictionary of Microsoft three sixty five terms. So m three sixty five is also Microsoft three sixty five. Office o three sixty five is Office three sixty five. AIP is equivalent to whatever they're calling it today. So that as I'm going in and maybe using different acronyms in my typing, it Claude can go in and kinda translate that to maybe the official definition or if I'm using the official one, it knows what the acronyms are for it. And then IntelliJinx, something similar to the Ben Stedjink one is maybe I wanna use IntelliJinx tends to be a little bit more professional, where Ben Stedjink tends to be a little bit more casual and conversational so that as I'm using Claude code, clogged in the CLI, to generate all this different stuff, because at this point in time, it's it is clogged code, but I use it for way more than coding. I just use it for all kinds of stuff in the CLI. It can know those different characteristics, those different traits, how I want it to behave using those different skills, writing styles. Oh, I put, like, background in there, professional background of IntelliJinc, my personal professional background, all those different things in these various skills. They're all bundled up in this plugin. And then for me, the nice thing about this and I did not come up with all of this to be fair. Andrew Connell and I were sitting down and talking about all this the other day, and he kinda got me, hooked on this too, was because I publish them up to GitHub, I can have all these plugins and skills come down to whatever computer. If I'm sitting at my desk, if I'm on my laptop, if I have to format my computer and wanna bring them all down. And there's even an update in there to automatically update these plugins and skills. So whenever I boot up Claude, it goes and looks at my private GitHub repo and will automatically update these skills and plugins from my GitHub repo without me even having to do anything. So it's super interesting once you start to kinda get in there, I think, get into the ecosystem a little bit of some of the plugins, the agents, the the skills, things like that. I I was really surprised at how approachable it was. I think maybe I was a little scared or tentative in the beginning to go in and go like, oh my gosh. Like, I have to build something. Like, I'm so far gone from the days of, like, coding things myself that, like, I would need the help of this thing to do it. But you can go in and you can do things. Like, yeah, you'll burn some context and some tokens to get it done, but you can do things like go in and say, like, hey. I want to build a new skill that does this and this. Help me stub it out. And then it'll actually go and create the skill markdown file for you. It'll generally put things together, and then you can go and fill in the details, or you can iterate on that. Because again, these things have access to your local desktop, so it's just writing out to markdown files and or whatever kind of artifact that you have it pushing out, PowerPoint, for example, and having that get to where it needs to be. So it's very powerful, and you can kind of walk this chain. So when I started, because I was coming over from Versus Code land where I was living so much in GitHub Copilot and kind of the agent chat mode in Versus Code, I actually started by bringing things over like my Copilot instructions. Those were just directly translatable to bringing them over as kind of like a subset of instructions and either a global set or like a per project kind of set like you were talking about in Claude. And then the nice thing is, if you start to get into some of the other CLI ecosystems that are out there, like let's say you are a GitHub Copilot subscriber or using GitHub Copilot for free, there's a GitHub Copilot CLI. Works very similar to the Cloud Code CLI to the point where you get an agents.md, and you get skills, and you get plugins, and you get MCP integrations. It turns out Gemini is the same way. So Gemini has a Gemini CLI as well. So if you're a Gemini subscriber and you're using that, or even if you're not a subscriber and you're just using kinda like the free versions of these, you can still tie them in and get going with them. So the funny thing is like Gemini CLI, like it does a Gemini. Md or Claude does like Claude. Md, things like that when you're in Cloud Code. But if you go into this ecosystem, like if you go into something like GitHub Copilot CLI, GitHub Copilot CLI respects claw. Md and gemini. Md because it knows that you might be using these things in, like, another ecosystem. So it's super nifty, like, in in regard to that and kind of being able to tie this stuff together. So if you are out there, the other thing that's happened, like I said, is like there's kind of portability between these things, so you're not locked into one. Like, you could start, like and I would encourage somebody, like, if you haven't been hands on in the terminal with one of these things today, go fire up probably Gemini CLI, a nice easy one to get started with. You can use Gemini fast, the one that you get access to for free. You don't have to pay anything. Kind of play around with it a little bit, set it up, see how far you get. And if you get to the point where you're like, oh, I wanna go try it in Claude now, or you're a GitHub Copilot subscriber, like I said, you can just kind of bring it over and carry that context and all these things with you. It's turned out to be a very kind of powerful ecosystem. And I find myself like this is the weird thing to me, is I find myself living in the CLI now more than any of the other desktop experiences that are out there. Like I don't even open like M365 Copilot anymore, unless I really need to. Like, I just try and do everything from, like, in in my case, like, my work stuff, like GitHub Copilot CLI, or my personal stuff. It's a mix of Gemini and Claw depending on what's going on. It's interesting. I'm curious to see how where Microsoft goes with this because the CLI, like you, I spend way more time in the CLI. I have a lot more flexibility there with loading in different MCP servers. And like you said, doing stuff with files on my file system. I would love to be able to do some of the same stuff with Microsoft three sixty five Copilot. Again, especially if it can save me a $100 a month. Indeed. But right now, this it feels like a huge gap and it's a huge limitation. And because I'm in one or in the CLI, I tend to just stay there. The one thing I would say, like, from a Microsoft three sixty five Copilot comparing them, there's still the security thing I think about too. Right? Like, working with client data or, in your case, working with internal company data, you do wanna be careful about pulling a bunch of that out, throwing it up into Quad or Gemini. Your company may have restrictions around it. So I think that's where I would love to see Microsoft come out with some type of alternative for this for the m three sixty five Copilot version of it, hopefully, before, in my opinion, they fall too far behind on this particular aspect of it. We can always talk about other aspects of it too, but I'm with you. I would at this point in time, I'd much rather load a bunch of MCPs into my CLI than just hang out in the CLI all day. I've spent more time in the terminal lately than ever before. Yeah. It's interesting. I feel like I'm only a throwback to, like, previous parts of my career, things like that along the way. Do you feel overwhelmed by trying to manage your Office three sixty five environment? Are you facing unexpected issues that disrupt your company's productivity? Intelligink is here to help. Much like you take your car to the mechanic that has specialized knowledge on how to best keep your car running, Intelligink helps you with your Microsoft cloud environment because that's their expertise. Intelligent keeps up with the latest updates in the Microsoft cloud to help keep your business running smoothly and ahead of the curve. Whether you are a small organization with just a few users up to an organization of several thousand employees, they want to partner with you to implement and administer your Microsoft cloud technology. Visit them at inteliginc.com/podcast. That's intelligink.com/podcast for more information or to schedule a thirty minute call to get started with them today. Remember, Intelligink focuses on the Microsoft cloud so you can focus on your business. So I'm curious. Like, these tools are out there. I think, like, they're they are very accessible for folks. Like, if you're on a Mac, you can use Homebrew, you can do Winget installs. Like, they make it super easy to to get this stuff spun up. So if you are like, you wanna play with it, I think that's easy enough to do. You mentioned things like PowerPoint. Is there, like, one business process or, like, one thing that you've solved that's been really, like, really good for you? Like, I can certainly describe one of my one of mine in, like, my day to day, but I'm curious, like, what's the one thing that's out there that you've done where it's like, oh, like, this is a real accelerator for me, or it's, like, genuinely, like, augmenting something else that was a lot of toil and friction before. One is gonna be just kind of a bucket. Writing PowerShell scripts, especially commenting, error checking, making them complete rather than, like Making them pretty. Yeah. Making them pretty and just making them, I would say, much more functional and that I can take it from client to client because it's a whole lot easier to build it out with a whole bunch of different parameters and error checking and all of that versus making them specific to a client and then having to alter it every time I go to another client. That process has gotten better. The other one that I did this the other day and super nice. I've I did some I've done some work for clients where I go in and look at their preparation for Copilot. I think we've talked about this. That PowerShell script, it'll generate like a CSV for every single site that contains URLs, sharing links, all of that. I was doing a presentation at it down in Miami this last weekend, and I'm like, damn, this would be really nice to show in the presentation, but I can't share all of my client data, usernames, UPNs, potential sensitive information where it's like, oh, this has the site, any of that. Anyways, again, it was a thousand CSVs. I actually went into Cloud Code, again, because it has access to the file system and said, go look at this folder with all these CSVs in it. Look for anything with this client name, this client abbreviation, anything that looks like it could potentially be sensitive. Go find all the usernames and create a company. Make up a company and change the company name to a fake company name. Change all of the usernames to fake usernames, change all of the FQDNs and all the usernames to match the company you made up in the URLs. And it what it ended up doing watching in the CLI, it went in and created, like, five or six different Python scripts to go through and analyze all of these files and update all of them. So it essentially anonymized a thousand different CSV files so that I felt comfortable using them in a presentation. And while there were, like, some site titles that were specific to the company, there was gonna be no way to tie them back to who this company actually was. So I was able to give real company data, real data from real projects that was completely anonymized, I never would have spent the time to go update a thousand CSVs even doing find and replace Never. Before this. So that was one of mine the other day that was like, this was it was awesome. It took maybe thirty or forty minutes to generate everything, and I went through a few iterations of, okay. Now go review it again. Let's go make sure. Let's go look for these the spellings. And then I just ask it, do you see anything else in there that looks potentially sensitive? And it would maybe come back with a couple other things. So it was a conversation, and it still took an hour, but doing that manually would have taken, like, a day Yeah. At least. You mentioned there was another one as well? Well and then the PowerShell scripts. Gotcha. Gotcha. It was those two. Alright. PowerShell scripts and then anonymizing data have been two of the big ones. Probably two of the bigger ones, bigger time savings. Let me talk a little bit maybe about, like, some of the ones I'm doing, which are helping me augment business process. So the nice thing about LLMs is they're very tuned around passing in text, like things like markdown. So I do a lot of Kusto queries in my day to day job, and I'm working with various databases. So one thing is, like, what's the schema of that database and its tables? Like, what's the actual schema of the tables, and what does those represent? So we we document those things as we build them out. We document them in markdown. They go in a they they go in one of our internal wikis. So I just went into that wiki, which is all markdown at the end of the day. I pulled out that subset of markdown files that said, here's the documented schema for table x, table y, table zed, right, to, like, walking down the thing. And then I built a custom agent around that understands the schema of those things. So when I'm talking to the Kusto MCP, the fabric MCP that integrates with Kusto and all that, it knows that when it's talking to this database and it's interacting with this database, here's the schema of all these things that are out there. So that's super powerful. It knows that this column is this name, and this is a string. This one's a GUID. Here's what the GUID represents. Here's the relationship of this GUID, this identifier maybe to, like, another table so we can do joins and things the right way. So that's super cool. Kusto, if you go out and you just read the documentation, there's a public Microsoft doc out there that says, here's all the best practices for Kusto. Again, Microsoft documentation for learn is just a markdown file. So if you go out to the GitHub repo, which is public, you just grab that markdown file, bring it over, pull it into your agent. Oh, hey. Now my agent knows not only the schema, but it knows the public best practices. Well, let me augment that with my best practices. So when I'm doing things like converting, a summary of bytes to gibibytes to megibytes to pebibytes, whatever it happens to be, I always want that conversion to be done in this way, not this way kind of thing. Or when you're doing joins, always make sure you're including, like, hint dot strategy equals shuffle. So I've got this whole set of things that are out there now where before, like, going in and writing Kusto queries sometimes was, like, a lot of ways of, like, just friction because I would have to go pull up, like, oh, what's the scheme of that table? How do I do the join? What's going on? So now I've got this just little agent out there that I can go and fire up quickly in Copilot CLI, and I can say, hey, agent at blah blah blah, go run, this query for me. Go find me the top whatever by petabytes in region x y z. So that that's super cool and super powerful. The other one that's out there that I've done is there's an MCP server for Azure DevOps. Ops. So you mentioned things like Asana and kinda work item management, Notion, things like that. So I live in ADO for a lot of my work item management. I've got epics and features and tasks and all sorts of things out there. Same thing. We publish a set of guidance internally, like, for our PMs to say, hey. Here's the way your epics should be structured. Here's how they should be named. Here's, like, the set of best practices. So I can take the ADOMCP, and I can take that markdown file that already exists as, like, internal documentation. Like, hey. So let me plunk this down and and plunk it down and create an agent around this that is now my ADO agent, which knows my best practices. It knows my business process. Hey. Go through and grab all my epics that are in this iteration path or this area path that are assigned to me or where I'm the PM owner for them, and make sure that they adhere to the best practices. Flag the ones that don't. What do you think? Like, what are some suggestions that I can improve and and make those better? And those are two things that I could absolutely do on my own, but they're so much better just having a thing there that can kinda constantly check them for me. It's almost like having a set of, like, unit tests that I can run on top of everything every time, but I'm not running unit tests against code that I've written. I'm running unit tests against business process or or other things that are out there. That's been just a, a super cool one to go through and have come together. And then you can start to combine these things. Like, I can take the ADO MCP and the WorkIQ MCP plus that agent or plus that skill or that plug in or whatever I've written out and have it come together and do what it needs to do. So you can get started with this stuff, like, super quick. Like I said, if you work with maybe like a Microsoft technology, be it something in Azure or m three sixty five, maybe what you can do is go out to GitHub, pull the markdown for, like, maybe like a feature area that you're interested, things like that, bring that markdown locally for you, put it in a directory, and then go and fire up one of these tools. Go fire up Cloud Code, go fire up Copilot CLI, go fire up Gemini CLI, go into that directory, and they all work the same. So once you've got like a bunch of context in there or artifacts, you can fire off a slash init, and slash init will go ahead and initialize effectively like a project in that directory for you, where then it can start to contextualize, and you can start to, like, build out those agents or skills or plugins or whatever you need to do just rapidly. So it's been really cool on that side, and maybe one of the other things that I've been doing I don't know if you've done this at all. I've been playing around more with the dictation engines that are out there and just being able to, like, dictate straight in. So even rather than me typing a lot of this stuff, I can just hit a set of hot keys on my keyboard, and all of a sudden, I can just start talking into the terminal and have it figure out my gibberish and come back the other way. It's starting to get really weird and wonky out there. I've thought about the voice. I haven't done it a ton yet. I should play with it more. I won't lie. Part of the problem is I also have family at home, and as soon as they hear me talking to my computer or Siri, all of a sudden, well, I'm crazy or I hear them from the background start yelling a bunch of gibberish to try to mess me up. And I'm like, come on, guys. Like, stop. My work Siri just started going. So I haven't done that. I wanna do that. I would say when you were talking about that, the other example I had just super quick, I had a client the other day that wanted to know some about a particular event that happened in their tenant, their Microsoft three sixty five tenant. They didn't have Sentinel, so all we had was, Microsoft three sixty five, like, the audit log, the unified audit log. You can go in and export that, but have you ever do you remember looking at an export of the unified audit log? It's just column after column of It's not even that. It's five columns of usable information or say four or five followed by a last column that's, like, data, and it's a massive JSON string because all of these different events, to your point earlier about schemas, have different schemas. So I went in and downloaded one around this event, like, four hour block. This user exported a 8,000 line CSV with all this gibberish. I said, go take the CSV, parse the JSON and the last end, and recreate a adequately formatted CSV. It turned six columns into a 197 columns in the CSV. Then I had to go in and duplicate it because I also found out in this some of the schemas don't use the same headers. One of them will use IP address, one will use client IP address. Stupid stuff like that. Claude actually separated stuff out based on case sensitivity, so I had to combine some where the case was cases were different. But then I was able to go in once I had all that done. I was able to have a whole conversation with Claude about, okay, find IP addresses that are uncommon in here, find activities where a bunch of files were downloaded that maybe look suspicious, or go look and see if there were any mail rules created in here. And instead of writing KQL or going through and analyzing this manually, I let Claude code have the first pass or maybe I didn't regular Claude. I can't remember. I let AI have the first pass at it to help me drill down to what information I might be looking for, things I wanna go look at a little bit closer. I find Claude in particular is very good at even if you ask it a basic question, it always comes back with a little bit of more, but not in the chat GPT way, which is very, I think, just over the top, sometimes, like, sycophantic, right, where it's, like, it's gotta, like, bleed in and say, like, oh, hey. Like, great job. We're all ready to go. Like, I can do things, like, any for example, with, like, the Cousteau stuff that I do, very similar. Like, I'm just querying off, trying to figure out, like, hey. Give me give me, like, a table back, and give me some columns that are summarized and things like that. But it's also, like, good at just saying and it because it's so enterprise oriented, I think, over things like Copilot, where it comes back and it just kinda says, oh, hey. Here's the data you wanted, and here's some insights about that data. Can I tell you more, or would you like to dig in more? Which is very different than, you know, I think my experiences in Copilot or things where, like, yeah, it'll come back and it'll say, like, do you want more? But usually, do you want more is something that's gonna, like, break down horribly or not generally work as part of the process. Yeah. I would agree. I feel like interactions in Claude, from my experience, tend to feel more, I would say, conversational in terms of that back and forth to get to where you wanna be. So I think TLDR. If you are somebody who's out there and you're using the desktop versions of Claude, ChatGPT, whatever it happens to be, there are these CLI experiences, and the CLIs, I think, tie together a set of capabilities. Like, if you are working with local files, local folders, you have just kind of you wanna publish, like, hard guidance through instructions, things like that. Build a custom agent, which has like I said, it's a markdown file. It's not like it's not like you're going in there and writing code. It's a markdown file with header one, header two, header three, just formatted in a way that shows, hey. Here's how you can do things, or here's how I want you to execute this piece of code. Like, you can go into an agent or a skill, and you can actually define, like, code blocks. You can say, like, oh, this is PowerShell, or this is Bash, and it'll go ahead. It'll figure it out. It'll run it and do what it needs to do. So I would encourage folks, like, if you haven't, get hands on with this. And then back to your earlier call out, like, if you are using this stuff and you found an interesting way to use it, we'd love to hear it and hear more about, what you're all doing with it. I found it to be, like, genuinely one of those things about AI that is helpful in my day to day job. I've been struggling there a little bit with Copilot lately, where this is M365 Copilot rather. So this has kind of reignited a bunch of things for me, and it's helpful in my world. You mentioned the things about, like, boundaries and internal versus external data. Like, if I'm doing something like iterating on writing PowerShell scripts or bash scripts or KQL, things like that, There's all this public documentation. Just go out and pull that stuff down. Like, that's all it's all you're doing is saying, like, hey. I wanna teach this thing to help me be better through the use of public artifacts and things like that. It's it's super cool. I'm having a ton of fun doing it, and it's not like, oh, this is just, like, geeking out. Like, it's genuinely helping me in my day to day job. Yeah. And don't let the I would say following up with that, don't let the code I'm putting it in their codes. The code part of all these scare you away because that kept me away for a little bit because it was Claude code or it was Visual Studio GitHub or it's Gemini code or it's all of these. It's like, no. I use this for way more than code and just because it says code, you don't need to use it for code and you don't have to be a developer or a coder to use the CLI version. It's just another way to leverage these AI engines. And from my perspective, they it's easier to access files on your file system through the CLI too versus the, desktop UI client based ones. So don't let the code label on these scare you away from trying them out and using them. They are super approachable at the end of the day. I've actually been impressed with things like just copy paste from, like, like, raw text into the terminal, things like that. Like, they they all of these CLI tools have done a very good job, with being able to wrap this stuff together and that experience. So, yeah, I think super cool stuff. Probably, as say, let's revisit it in a couple months and see what else is out there. The AI train continues to March, and, we'll continue to use it in our day to day roles here. Yeah. It'll be different a month from now. So Probably. I am. I'm curious to see where it goes over this course of 2026. So with that, I should probably go to a meeting that I just told everybody I'd be right there for. There you go. Back to work. Yeah. Right. It never stops. Alright. Well, thanks, Scott. Appreciate it. That was a fun conversation. I back to terminal days. Let's just get rid of the UI. Let's just go back to pure terminal days. Yeah. Everything's gonna be ASCII art. We're gonna love it. Absolutely. Oh, I haven't asked Claude to create ASCII art. Have you tried that? I have not. But maybe next time we chat, you can let me know how your experiment goes. Yep. Takeaway, test. See what we can create with ASCII art between this podcast and the next. Alright. Perfect. Thanks, Ben. Have fun. Thanks, Scott. Talk to you later. If you enjoyed the podcast, go leave us a five star rating in iTunes. It helps to get the word out so more IT pros can learn about Office three sixty five and Azure. If you have any questions you want us to address on the show, or feedback about the show, feel free to reach out via our website, Twitter, or Facebook. Thanks again for listening, and have a great day.
Donate
Share
Apps
Menu
Microsoft Cloud IT Pro Podcast
Open in new window Display Menu
Episode 422: Back to the Terminal: The Rise of AI CLI Interfaces
|
Back 15 seconds Forward 15 seconds Play Speed CC
Podcast: Play in new window | Download (Duration: 41:35 — 28.6MB)
Welcome to Episode 422 of the Microsoft Cloud IT Pro Podcast. In this episode, Scott and Ben discuss their growing use of in their daily workflows, particularly Claude Code, GitHub Copilot CLI, and Gemini CLI. They explore how these command-line interfaces offer powerful ways to interact with local files and MCP servers beyond traditional desktop AI chat interfaces. They share how they are using these tools in their day-to-day roles to perform different tasks and accelerate their workflows.
Your support makes this show possible! Please consider becoming a premium member for access to live shows and more. Check out our membership options. (more…)
Episode 421: Microsoft 365 Mergers and Divestitures with Frank Lesniak
by [Scott](/content/author/scottmsclouditpro/ "Posts by Scott"/index.html) | Feb 16, 2026 | Podcast
Blubrry Player
|
Auto Scroll
Welcome to episode 421 of the Microsoft Cloud IT Pro podcast recorded live from Workplace Ninjas US, December 2025. This is a show about Microsoft three sixty five and Azure from the perspective of IT pros and end users, where we discuss a topic or recent news and how it relates to you. We're back to another interview when Ben sits down for a conversation with Frank Lesniak, the lead of the Microsoft three sixty five team at West Monroe. In this episode, they dive into the intricacies of mergers and divestitures within Microsoft three sixty five environments. They discuss the initial due diligence phase, planning and approach, building and configuring new environments, and the final migration and cutover phase. Frank shares insights on common challenges such as integration of different licensing models, the handling of workstations and applications, as well as the importance of security assessments. The episode provides a detailed look at the methodology and tools used by Frank's team to streamline these complex processes. We're here for another Microsoft Cloud IT Pro podcast. Another one without Scott. I have left him behind once more and came to Workplace Ninjas US twenty twenty five. So this is the first one of these in The US. And I'm sitting down here with Frank Lesniak. Said the name right, right? You got it. Alright, perfect. And you're the lead for the Microsoft three sixty five team at West Monroe Yeah. Microsoft three sixty five Consulting. Yep. So happy to sit down and talk with you, and I think we have a super interesting topic today, it's something I have done some of. Sounds like you guys do a ton of these, so fascinated to talk about our topic. But before we do that, do you wanna give a little intro about you, whether it's work or personal or fun or whatever you feel so inclined? Sure, yeah. So I describe myself as a tech enthusiast. I like to nerd out on various technology things. Home on me. So tech is fun and work and like there's a lot more Yeah. I'm one of these rare people that actually likes work. Like it's kind of it's kind of messed up to say that out loud but it is it's true. I do actually really like what I do. So I I feel blessed about that. Yeah. I'm a tech enthusiast. I've it at the heart of it, if anybody follows me on socials, I post about general tech, not just Microsoft stuff. Okay. But, yeah. At work, like you said, I lead our Microsoft three sixty five team. It's a team of 45 people that have different sort of sub disciplines within Microsoft three sixty five. Not everybody's technical. We've also got project managers and other stuff. Alright. But, yeah, like you said, one of the things we focus on is corporate m and a corporate m and a and doing divestitures and integrations, and that is its own special type of project that I'm excited to dig into. Those are super interesting. And again, I've done a few of these. But you have done way more than I have, so I'm curious to hear some of your approaches. And we'll make sure, like you said, socials, we'll make sure anybody listening, we'll post all your socials Awesome. Awesome. In the show notes. Speedbook can go find you, follow you, all of that. Okay. But we were talking about this, the merging and divestitures. And I feel like this has gotten a lot more common in terms of at least what I've seen from Microsoft three sixty five projects in the last few years of companies buying a bunch of companies, and Microsoft three sixty five has been around long enough now that it seems like whenever you buy a company, you both have Microsoft three sixty five. Copy. Or you also have on the opposite side the divestitures where these two companies a big one that just split was it Discovery and HBO? Just split or Warner Brothers? Yes. I just know. There was a split there, and I think they had Microsoft three sixty five. So it's like Yeah. And I know I projects like that where it's how do you start looking at these? And we were talking, you gave me some bullet points that we'll try to stick to is you have three phases. And I think it would be interesting to kinda dive through when you start thinking about these three phases and kinda how you approach this from that perspective and how you help some of your clients with that. Yeah. So before we dive into that, one thing I forgot to mention, we were chatting before this is, there's sort of a pre phase that I may or may not be or somebody on my team may or may not be involved in, and that's called the due diligence phase. Okay. So before this is all kind like, at this point, it'd be super confidential. Nobody knows about the deal, this acquisition or divestiture. Right. And there's this like, kind of pre phase where typically the buyer you can do this on the sell side too. If you're the seller, you might wanna do, like, kind of a tabletop sort of exercise where you Okay. Do a fake diligence to see, like, how you would score and maybe make some improvements before you go to market. But typically it's on the buy side where we're helping the buyer assess the company that's being purchased and looking at how they might go about the divestiture. Okay. And so and also are there any risks in the environment? Like maybe there's a glaring MFA issue or something like that, right? So we're out there. But there's MFA issues that Microsoft three sixty five? Well, talk to Merrill and get Maestro up and ready. Yeah. There you go. Yeah. But anyway, there's this sort of like pre phase where we might do some like kind of initial triage of the situation. But then that gets us into Once the transaction occurs, people sign the paperwork or they're about to sign the paperwork, we start talking about the first phase of of these projects, divestiture project, the actual execution project, which is called we call it an approach and plan project. Okay. Where we basically get we simply start working with the buyer and we figure out, okay, what is it that we want to do here? Because these projects always are like drinking from the fire hose, everybody's like, let's go and there's not really a plan usually. Right. So the first thing we do is it's not very sexy, but we sit down and we build that plan and the specifics about what it is we're going to do. And we work with the seller as well to get agreement on, like, hey, this is going to be the approach. This is precisely how we're gonna migrate email, SharePoint, Teams, even old school file shares maybe, identities, workstations. Here's the plan. Here's how we're going to do this. Do you agree? If so, great. If not, okay. Let's figure out something that is agreeable. And then also, what tools are we using? Are we gonna use bit tight migration ways? Are we gonna use Quest on Demand? What are we doing? And what sort of permissions are implied or what sort of connectivity might be implied with that approach? Yep. Do you ever have I've come across this with some of the I would say more the mergers that I've done, but it'd be interesting. I haven't done a lot of divestitures Mhmm. Where you even have a merger and the buyer of the company is like, we're buying this other company. Mhmm. We need to migrate. And we're like, okay. Great. What are we migrating? They're like, well, we know they use Teams. We don't really know about other stuff. Do you also build in, like, I would say almost a discovery of it? Let's go into the company you're buying and actually figure out what it is we need to migrate. Yes. Exactly. Yes. Scoping the migration is so like people don't really I think clearly appreciate this. We spend a lot of time in this upfront phase. First of all, figuring out who are even the employees that are coming across. Yeah. Because not everybody might come across. I've seen that too where it's like a portion of the company is being bought. Yeah. Like let's say it's 200 That's like that's the churn merger all in one. Right. Right. Exactly. Let's say it's 200 people that are conveying. Well who are those 200 people? Like let's get a definitive list. You'd be surprised at how challenging that is sometimes. Just getting the damn list together. Once we have a list though, we've got some automations and some tools written. Unfortunately these are not publicly available. Okay. We basically You gotta have some IP, right? Exactly. Yeah. We do. I'll describe what happens. Basically what we do is we work with the seller to do a full inventory of Exchange and SharePoint, and we keep that data in their environment because there's no way in hell the seller is gonna give us a full inventory of their environments. We just say seller run this tool, keep the data, and then we've got a separate so it's like basically that does a full dump of Exchange and full dump of sorry, metadata. Not Got it. Not the actual data, but just the data about the data. Yeah. Exactly. Yeah. Like here are all the recipients in Exchange and here's all the information about them. Basically that's what we're doing. Okay. And the SharePoint front, here's a list of all the SharePoint sites and the permissions associated with them, the URLs and all that sort of stuff. Alright. I'm being I'm overstintheling a little bit, but basically that's what that looks like. Right. And it's a huge CSV as the output. Got it. We then have a second script that basically does an ETL on the data set. And it it walks through the permission set to recursively find all of the, in the case of Exchange, that are related to that list of definitive people that are coming across. Got it. Okay. So we find all the mailboxes that have some sort of involvement or distribution list, whatever. Right. Share mailboxes. Exactly. Yeah. We find the things that are related definitively to these 200 people. And it typically is a superset. There's like usually some junk in there that doesn't need to convey. But this gives us like sort of the universe of what might need to migrate. And then there's some adjudication on that list with both the buyer and the seller. Like, buyer, do you really want this to come across? Yes or no? Right. What even is it? They might need to go investigate with whoever has permission to it. And then the seller might say, no. You're not getting that data for x y z reasons. So this is an adjudication process that is not something you can automate, but Okay. Yeah. That that all kicks off in this Do you ever look at and get involved into and again, one that I've seen come up is all the enter apps that are registered. Like they're when they do a merger and it's, oh, by the way, you have DocuSign that's set up with SSO, and you have Yep. Adobe Creative Cloud, and you have Calendly, and you have I mean, it's not uncommon to see hundreds of registered applications that are in Entra. Yep. It's like you realize that this merger, that entry timing goes away. Yep. How are we gonna handle all of those registered applications? Yeah. So if it's a divestiture or carve out, right, that's got one of pressure. We typically would wanna understand what are they actually using, and what also like This is I'm getting ahead of myself a little bit, but there's like a question about some the timing of some of these things. Right? So like, let's say that you let's say that the selling company has 2,000 apps. They're a huge enterprise, but the divesting entity only uses two only air quotes uses 200 of those. Right. Right? Then we have a question of, okay, do these apps need to convey yes or no? Something like DocuSign, they might be able to continue to use the selling company's iteration of that app for some period of time. And the access and ability for the divesting folks to continue to use the selling companies applications is covered under an explicit legal agreement. Okay. We're getting a little off tech here, but but it's actually important. Well, but it's all yeah. It's all part of this. So this is an agreement called the transaction services agreement or TSA. Okay. It describes in detail, here are the services that are gonna be provided by the seller for this amount of time, and here are the fees associated with those services. So it's typically a monthly fee for email, a monthly fee for SharePoint, a monthly fee or whatever. Yep. And those things are typically enumerated. The ideal situation is we help the buyer negotiate that transaction services agreement during the diligence phase that I mentioned that I'll put in the pre phase. Okay. So you help with that part of it too then? Not me personally, but we have But you have people. Specialists. Yeah. People on your team. Yeah. They're working with lawyers and stuff too. Right? That's right. Those lawyers. I know. I mean, the thing about these TSA's though that's so important is that monthly fee for service. And we, West Monroe and my team, we focus a lot on speed. And so what ends up it's sort of funny in a way. Maybe I shouldn't say this. But these companies that are selling these divisions or whatever, they're divesting these entities. They structure these transaction services agreements to make money. Like, they're they're basically I mean, sometimes these fees are crazy. Right? Or sometimes the fees escalate. That's the other thing. They might divide the service for a certain number of months, and then the fee escalates if you're not off in a certain month. Got it. Right? So it's sort of the build versus buy mentality a little bit. Like, let's say the company that's acquiring this organization has a team. Maybe they technically have the capability to do the business for themselves. That's fine. And and what they may have the sort of wherewithal to do that, but they may not have the capacity to do it relative to their other op day to day operational expenses. Or not expenses, but day to day operational Right. Because of the speed and the timing and all of that. Yeah. Yeah. So so let's say a typical IT team can do a divestiture in nine to twelve months. I think that's reasonable if you've got a decent team who's maybe done it before, but don't have a dedicated resource pool that that can do this. And they're sort of splitting this with their day job. Nine to twelve months might be typical for like a mid sized sort of divestiture. My team can get it done in probably three months. Okay. If you think about that, right, relative to the TSA and the monthly fees Oh, yeah. We have an automated automatic business case for even though, like, our fees aren't small. Like, we come in and we do this quickly and we sort of in in some ways, it's I think it's sort of funny because we end up doing a little bit of a bait and switch sometimes with these selling companies. They think they're expecting to earn nine months of monthly revenue from providing these services. And then we come in and get it done in three. They're like, oh, crap. Right. They're done. But I don't feel bad about that, actually. Like, I to me, it's like, hey, man. Like, you're kind of price gouging. It's sort of a captive audience. Oh, for sure. You're sort of price gouging this. But it's all part of the negotiations and the sale anyway. So Yeah. Yeah. So once you get that's kind of the approach and plan where you're doing the discovery, you're running all your tools, figuring out the data. Exactly. You have to know what's migrating. This is probably where you also develop a little bit of the project plan of we're gonna do it in this order. A percent. Yeah. This is the timing. Yeah. Exactly. So going back to, like, your question about the applications, I guess I didn't really fully address that. There's discussion about, okay, so when are we migrating email? Are we migrating workstations at the same time as emails? Depending on the size of the company, that may be reasonable you may wanna do that. You may want a big bang email workstation on the same weekend, let's say. Right. And then the question is, okay, what about applications? When are those migrating? They might migrate at the same time depending on what they are. If there's software as a service applications, maybe we're just getting new contracts put up with DocuSign, to use your example earlier. Oh, really? We do DocuSign contract. We connect that to entry ID. When we provision identities and they register for MFA, they're they have access to it and they're off to the races. Right? Simple example, but, like, we may cut over some applications in that way. Other applications may take longer and they may need access they may need to be accessible under the TSA for some period of time. Like, in the case of manufacturing, for example, they might have an ER, an ERP platform, that's running all their manufacturing and shipping and all the logistics and everything. I mean, you're not gonna spin that thing up Right. Immediately. You can't disrupt their business for several months either. You're probably not I mean, even if you're a superpower, a super nerd at ERP. Because you're not spinning up an ERP that reflects their business operations in three months. Yeah. It's not gonna happen. That's probably more like a year to eighteen month project. Okay. So typically, there's some applications that are sort of left behind Mhmm. In some way that has to be sort of negotiated for the migrated users to get back to those applications depending on their architecture. Right. Yeah. It's interesting. And I was one of the ones I'm thinking through now and working on as well is like both companies have AD, all the workstations are joined to AD, both ADs are synced to different entry tenants. Like, there's a lot of moving parts when you're planning this out to think through. To your point, the timing, it's if you just move identities and SharePoint and email, but you leave the workstations in the old domain for a period of time, now you have two identities and it's Right. Exactly. There's a lot of different, I would say, a lot of nuances that you really do need to sit down and figure out this plan. Exactly. Yeah. Like, we have a standard playbook that we we try and follow, but there's none of these are the same. There always some there's always some unique wrenches. Like, I I didn't mention this, but the other thing that comes up in these approaching plans sometimes is a seller that just says no to everything. Like, sometimes these folks are just really difficult. I get it. Like, people are worried about cybersecurity. They're worried about they're talking to if we're on the buy side. Right? Like, if the buyer is the one who hired us, the seller didn't hire us. Right. They don't wanna work with us necessarily. And some of the employees don't want it. They're like, no. The CEO sold the company. I'm mad that we're getting sold to the buyer. Exactly. Exactly. Exactly. Or they're mad they weren't sold. Maybe they wanted to convey. Like, there there's all kinds of politics that go into this. But also the sometimes there's that that remember I told you that bait and switch thing where we're kinda getting they're realizing we're gonna get this car done a lot faster than they were expecting. Sometimes they introduce roadblocks to slow things down. Got it. Whether they say that explicitly or it's understood or not, I that's what's happening in a lot of cases. Yeah. And I was imagining too, it kinda goes to something we might touch on later, is you also could probably have MSPs involved with the seller where the MSPs are worried they're gonna lose Yes. Their client Yeah. That's right. Because they're being acquired by the buyer who has a different MSP. And MSPs can be a little difficult when you're trying to pull stuff away from them. So Yeah. We've heard that happen a few times where they just aren't I mean, they're not teach people how to cooperate, but they also have to They're not helpful. Yes. You get that whole approach, you've planned it out, you have it set up, and then you move into phase two. We'll call it phase two. You kinda have the pre phase. We got a pre phase, phase one, phase two. Yep. Yep. Exactly. So this is where so in most situations, this I'm gonna totally agree with specific circumstances. But in a lot of situations where we're working on divestiture, that divesting entity is getting spun up as its own standalone company. Okay. I think about it. You're going from relying on probably a centralized IT function. You're you're part of a big company, like a huge enterprise. You're relying on a centralized IT function at that large company. Now you're getting carved out or spun off as your own entity, and you don't have an IT function. So we're building that for them. Right? A lot of times these these investors don't have IT staff that are conveying. Well, maybe they have one IT leader. That's fairly common work. Somebody is sort of nominated as the new CIO or thereabouts. Do you get to go leave and be the new IT guy at the new company? Yeah. Which is fine. That's a pretty good perk. You become the CIO. Right. Get a promotion due to it. Exactly. So sometimes that's the case where we have a director who's there, but usually there's no other conveying. Okay. Nobody actually do the work because we all know what directors do. It's like they there isn't necessarily even someone who's a decision maker. Okay. Right? Like, they may not maybe they're in charge of IT, but they may not be maybe they're more of an application person. For example. There's a lot of different permutations there, but basically they may not be able to make all the decisions that need to be made. So we have a a templatized playbook for spinning up new m three sixty five tenants and new Azure subscriptions and all the infrastructure that goes along with that. So for Microsoft three sixty five, we use m three sixty five DSC today. Alright. And one of my coworkers, a shout out that like Cherry built a he built a very robust, very and others do our involved. I shouldn't change that. They built out a very robust, that that saves a ton of time and reduces a lot of risk. And then we also have something similar on the Azure side. We use Terraform, like so many other companies too. And there's a co kind of a complicated chicken and egg situation that you'd have to talk more to, like, Danny Stutz or Blake Cherry about. Uh-huh. There's there's a chicken and egg situation where they don't have a, an Azure DevOps environment yet, and we need them to have one, so we have, like, just to kind of rebuild that and kind of seed everything and then and then launch this. And then you can go push it all out. Okay. We're setting up kind of a corporate IT, back office IT style subscription that meets all the best leading practices and all that sort of stuff. It's like we're doing hybrid identity by default so we're getting domain controllers spun up, we're getting some utility servers spun up. Basically, the for infrastructure you need to run any business, getting all that spun up, and and the same eventual I venture it, connect, and all these things. Got it. Do you feel overwhelmed by trying to manage your Office three sixty five environment? Are you facing unexpected issues that disrupt your company's productivity? IntelliJunk is here to help. Much like you take your car to the mechanic that has specialized knowledge on how to best keep your car running, Intelligent helps you with your Microsoft cloud environment because that's their expertise. Intelligent keeps up with the latest updates in the Microsoft cloud to help keep your business running smoothly and ahead of the curve. Whether you are a small organization with just a few users up to an organization of several thousand employees, they want to partner with you to implement and administer your Microsoft cloud technology. Visit them at inteligync.com/podcast. That's intelligink.com/podcast for more information or to schedule a thirty minute call to get started with them today. Remember, Intelligink focuses on the Microsoft cloud so you can focus on your business. That's in a divestiture. How do you think about it when it's a merger? Because then some of that you're not building from scratch because the parent company has it. Yeah. I'm assuming there's still gonna be maybe stuff to build based on some of that planning. Yeah. But do you approach that then a little or how do you approach that, I guess, from the build and configure? It's a lot more bespoke. I mean, to be honest, like, I like to give benefits of doubt to any client I work with. There are a lot of smart a lot of smart people out there, and nobody intends to make egregious security mistakes. Yep. But not everybody does a good job of testing their security and one of the first things we do, I used to do this years ago because they're one of my clients had a security incident unrelated to our work, but like, it was while we were doing a project. You always have put that disclaimer on there. Right? They had a security incident, but it wasn't us. No. For real. Because I've had that too. But it was it just happened while we were doing all their work, man. Yep. And they were mad at us because we had administrative access to their tenant. Well, it didn't have And they got it. Why didn't you look at us? And it's like, we didn't have any scope to look at. Why would Right. Why would I You didn't hire us to do a security analysis of your environment. Not gonna I'm like, go away on my way to see poke around in your tenant, which we might raise other alarms. Why is Frank looking at all these security settings? Yeah. Let's Frank do it in the HR SharePoint site. Right. Right. So I instituted a rule, and we stick with this now. We're we have any sizable m three sixty five project. Doesn't matter if it's the best of your integration, whatever. Always do an m three sixty five. Alright. Even if the client doesn't want us to do it, we're still doing it and we might maybe not make a big show out of it, but I still wanna know what the security posture of the market is. Right. And so we do that to the target organization of the place where we're migrating to the next situation. And along with that, we're also kind of examining the general MFA posture of the divesting entity or or the entity to be integrated, I should say. And what we're looking for is, like, are there differences in MFA behavior that we need to sort of adjudicate and figure out, like, maybe resolve differences on? Whether that's because there's a security hole or because something is too lax or too aggressive and and, like, basically, what are the impacts these employees are gonna experience when they come in? And is there anything we need to fix because there's a glaring security problem? Yeah. The other one I've seen too that's become more interesting especially with mergers is different licenses. Yes. Like if if the the selling company has e fives and the buying company only has e threes Right. Like, you can run into some and I'm assuming that actually comes out in the approach and plan, but then Yeah. Building out how are we gonna handle this because we're losing certain functionality. Yeah. Exactly. Actually, we had that situation earlier. Was it this year? I think it was earlier this year. Yeah. We wrapped up this project in January where we were working with two very large manufacturing companies. They're global. Alright. I can't say the name on it, but I know it's fine. If I told you the name, you would know who they are. We were working with them on basically an approach and plan and that situation was exactly right. They had one company had M365E5, the other one had M365E3 and they were coming together as a new organization and really trying to figure out what's the and the e three organization had a bunch of third party tools in the mix. CrowdStrike and all that, you know, I mean, they were sort of augmenting the gap there with other stuff. Yep. And there was a sort of there was a lot of discussion and consternation around, like, what's the right at at the end of the day, this is just, like, part of the planning, part of the adjudication. It's, like, okay. Let's come together and resolve these differences. You're gonna be one team, etcetera, etcetera. Yep. Actually, that situation was kind of interesting too because they were two public companies, and we were working before the transaction was closed. So before the legal documents were signed. Oh. And they were competitors. And so they weren't legally allowed to talk to each other about this sort of stuff. Oh, wow. So they talked we were hired as sort of an intermediary. It was a unique situation. We were they were able to talk with us, and we were able to kind of mediate and figure out, okay. Like, here's what you guys should be. Like, if you're a consultative sort of way, here's what you all should be thinking about. Is this agreeable person a? Is this agreeable person b? Person b. Yeah. And that would have been fascinating. It was it was pretty interesting. Yeah. Yeah. Very cool. What else? So, yeah. We talked about NetNewell tools, automating it, building out those landing zones, Terraform, DSC. We spent all the time in the Workstations. Yeah. Deployments and workstations. That's another interesting one because we talked about their domain joined. Like, it's not just a, hey, let's go change the domain or the enter domain that the enter ID Yeah. And here's the thing, like, you can't technically, you can flip these machines in place from being traditionally domain joined to being enter ID joined with and then autopilot enabled should they need to be reset or something. Yeah. You can do that technically. Like, QuestODM supports some of that functionality. We've had clients that that employ that functionality very well. I had a client use UK based, and this is before we got involved, but they big bang migrated I think 5,000 workstations in like an evening or a weekend. Wow. I mean, when they tell me this story, I thought they were lying to be honest. That just makes me It makes me so nervous. Yeah. Yeah. Personally, I would not stand up for that. But I mean the technology is there. The issues that we have to figure out though is more on this like, I'm talking about divestitures a lot because that's mostly what we have to deal with. Okay. Because integrations are a little different. Like when you're if you're buying a company in a Folsom sort of way, like you bought an entire entity and there's no carve out taking place. Yep. You kinda have full control of the environment and you can do whatever you want. So you might be able to do that in place migration. But when you're doing a carve out, you're not typically getting admin rights to that selling organization's environment. Yeah. So it becomes, you can't do what you might wanna do, I guess, is what I'm trying to say. Right? So our typical approach for workstations is actually to de autopilot enroll with them from the parent or the selling company's side Okay. And then autopilot enroll them on the acquiring organization side and either reset them or reimage them. Yeah. Depending on that's our typical sort of playbook, but It's in my experience, that's the easiest way to do it. It's a if you do But it causes consternation. You're wiping the device. What's the situation with the date on the device? It away. Exactly. Because at that point in time, you don't have anything spun up like OneDrive with no folder move that's gonna move it into the Exactly. We have to like we have to kind of hope, pray, plan, and assume with communications that that the selling organization has that stuff turned on and it's syncing correctly and we're getting telemetry and there's communication to users to make sure that they're checking that OneDrive icon to make sure there's no To make sure. There's no red x's or anything like that. Like, so many people ignore that the OneDrive sync client. Yeah. It does make me nervous and this is always a big point of concern when we come in and say, hey. Let's wipe all the workstages. Everybody freaks out. Right? So it takes some Right. Takes some most organizational change management, so to speak, to And then I'm assuming too when you're doing the migration, it's probably also, to a certain extent, like, what data are we allowed to take, what data has to stay behind Yeah. Yeah. Making sure that we're only migrating what we're supposed to and that we're not missing anything. We're also supposed to migrate. Yeah. Yeah. I mean, on the workstation side, we don't worry about that so much. It's typically assumed and agreeable that anything on the workstation can convey. Okay. And anything in people's OneDrives can convey typically. I think I haven't had a seller, knock on wood. I don't I don't like this adjudication stuff. It's annoying. Good to call. Tomorrow. You're right. Like, I mean, this may come up. But generally speaking, they kinda give people the benefit of the doubt that, hey, people aren't stealing or trying to actual trade stuff. Yeah. Where that comes more into play is, like, on the SharePoint team's file share side of the house where we maybe extend a bit more time. And that's we try and we start that process in the approaching plan where we sort of draw the boundary around the what possibly might migrate. Yeah. But there's usually ongoing adjudication about okay what exactly is gonna I like that word adjudication by the way. It's a fun word. But there's ongoing sort of debate about what is and isn't migrating and sometimes a reversal of decisions too, which is always fun. Anyway, yeah. Wow. So that's you got it all built, configured Yeah. Ready to go. Like, at this point in time Yeah. The end of this, you haven't ready to migrate. Right. You haven't actually migrated anything. You've just prepped. Okay. It's all ready. It's here to go. We're gonna move it over now. I've heard this say, we're also staging the data in this space. Okay. Yeah. So So you can set up a free migration of some of the mailboxes. Yeah. We pre stage the data, like, for example, with migration was mid time migration was used you precede email data that's, like, t minus thirty days old, typically. Yep. You get all that sort of stuff staged, and you fix errors, and you deal with all that. And that's it's kind of kinda works in the background. Same thing with SharePoint we use. I mean, it depends. We typically use Sharegate. Sharegate. Okay. And and same thing for Teams. And we can also use Quest and we do sometimes. It depends on the situation. So anyway, we we precede as much data as we can during this phase. Alright. And then you get to the cut over where everybody's probably Yeah. All hands on deck. All hands on deck. And Yeah. There's a couple different approaches here. Like, you have the big bang, the one you talked about, where maybe you're migrating 5,000 users in a night or in a weekend. Yep. Or there's probably also scenarios where you may try to do things a little bit more gradual and probably pros and cons to both of those. Yeah. We almost always big bang identity and email. Okay. Because it's just not feasible in my opinion. I mean, it technically, I get that you can make this work. But, like, again, with the divestiture kind of situation in mind, the selling company doesn't want us to screw around with their email flow. Yep. Makes sense. They do not want us putting tools in place that messaged through. That's just that's not an option realistically speaking. Yeah. So we are typically doing a big bang migration out of necessity on at least on email and identities. Alright. Just because otherwise it gets confusing as to how do you even email this person. I know you use forwarders and other stuff, but like it just becomes a Yeah. It gets messy. Yeah. And then the other actually the sticking point is usually calendars and trying to see, like, trying to schedule meetings accurately with people and understand their availability. If we I didn't mention this, but when we do a final cut over of email using, like, for example, migration whiz, that final cut over is what brings the calendar over. There are no calendar items brought over Okay. Until that point. So it's not That's right. Because calendar doesn't come over to pre stage Correct. With the type. Correct. And actually if you do, like, if you do bring it over for whatever reason, it causes it, it can cause issues. You wanna do that in one fell swoop at the end. Yeah. Calendar point, like, getting edits, deletions, changes. Yeah. I've seen the major issues of recurring meetings. There's all kinds of problems if you do that. So, yeah. So you have to bring that over at the end. So if you got some people migrating, some people now, you can't see calendars accurately unless you set up calendar, like, federation and stuff. You're not doing that in a situation. So so it's a big bang email cut over typically. And then in the typical big bang cut over is also kind of group SharePoint teams. Those are also typically big bang cut over. Okay. To the extent that we've successfully adjudicated or agreed upon what's migrating, there's usually some subset of sites where the selling company is insisting on doing a deep review or maybe lawyers need to get involved to data data. I can imagine some of those probably more sensitive sites. Yeah. Yeah. Again, it depends on the business side. Understand some of those Some people just sometimes, like, I I understand, like, security, and I definitely appreciate that. But sometimes, like, sometimes you kinda wish, like, can we just agree to be adults here and, like, business professionals and, the new company that's being created like we'll just delete stuff that isn't relevant. We just agree to this is like a business agreement. It sometimes works, sometimes doesn't. But anyway, sometimes stuff doesn't migrate for that reason. We kind of leave it behind and we migrate it later. But generally speaking we try to bring those SharePoint team sites over the scene. And OneDrive as well. Sorry. I forgot the message now. Sorry. Actually, that's not entirely true. We bring OneDrives over with people's workstations. Oh, okay. Right? It makes sense with a known folder. Yeah. Because otherwise, if we brought OneDrives over ahead of time, they're on their workstation that's connected to the selling organization. Their OneDrive is gonna get us sick. Right. So we timed OneDrives with the migrate with the workstations, and that's kind of the big the workstations is really the big question mark in terms of big bang or not. It really depends a lot on the logistics and what can be supported and what's agreeable to the business. We I would like to big bang workstations the same weekend. It just makes everything easier if everybody sort of wakes up on Monday morning and they're on their new stuff. Yeah. That's the best scenario if we can do it. But sometimes if if they have a large number, on-site, like a manufacturing plant or something like that Okay. Right, we have to dispatch a small army to kind of facilitate some of this stuff because, again, the the organization doesn't typically have IT staff. So we're sending a small army at these locations. And depending on how many there are and how where they're located in the world, we may or may not be able to do that all on the same weekend. Got it. So we just have to kind of think through some of that stuff. And sometimes we big bang it, sometimes we don't. Alright. Yeah. Very cool. Well, thanks. Yeah. At the end, we're at the end of all that, that's typically the work my team's doing. We might bring over applications like we were talking about earlier too at the same time. Alright. But at the end of all this, typically, there's they're online in the new environment. They're working on their new either they're newly issued I forgot to mention. Sometimes we issue new workstations because Okay. Maybe the workstation the hardware sometimes isn't conveying as part of the transaction. Like, the buyer has not bought the workstation. With the seller. Yeah. It has to be sent back to the seller or something. That's ridiculous. I think, but that's what that's sometimes what happens. So either we've given them new machines or they're using newly reset or newly released provisions. Yep. Yep. They're on their new email. Everybody's happy. At least within a couple of days, everybody's happy. And but sometimes there's some applications that are sort of leaving behind, like, those ERPs and other big big behemoth type applications that just take more time and effort focusing on the migrate. Got it. So yeah. That's it. Awesome. Well, very cool. Thanks, Frank. Yeah. I appreciate it. Yeah, man. It's always fascinating. I haven't I have not encountered anybody that's focused this much on mergers and investitures. So it was This is really one of our one of our key one of our team's key focus areas is this kind of project. Alright. Perfect. Well, we'll put links in the episodes, company website, your social media, Anything else you wanna share with people, socials if they wanna get in touch with you or websites, LinkedIn, best places to find you? I'm pretty easy to find, to be honest. Pretty much on all the socials, you can find me my first and last name. Okay. I know you have links, but just to say that out loud in case somebody's Perfect. While they're listening. Yes. Exactly. Yeah. So I'm on x blues guy, LinkedIn, Macedon. I don't use it that much when I'm on there. Okay. I'm on GitHub. So there's all kinds of ways to get All of them. Are you the only Frank Lesniak? No. You'll find one other Frank Lesniak that comes up when you Google Alright. Name. He's, funny enough, he lives in Chicago area, which is where I'm where which is where I live. But he's, I think, either an administrator or, like, a long tenure teacher at a public school. Okay. So that's not me. I'm not a teacher. So Chicago, are you a Bears fan? Are you a football fan? I like the Bear. I'm not a I'm not like a mega Bears fan. Like, I'm not on if you ever seen SNL skits, the Supermans, I'm not one of those guys. You know? I do like the Bears. I watched them the other night. Alright. Yeah. I grew up in Michigan, so I'm a Lions fan. Okay. I'm still a little mad at you for taking Ben Johnson. Sorry, man. Yeah. That's fair. It happens. Yep. Alright. Well, I will let you go. I saw the drink cart go by Yes, I see. The Expo Hall. So right now this episode is standing between us and a party in the Expo Hall. Okay. So thanks again for joining us. Yeah. All the links for stuff. I'll get any other links too that you wanna put in the show notes, and enjoy the rest of the conference. Yeah. Thank you. Thanks for having me. Thank you. If you enjoyed the podcast, go leave us a five star rating in iTunes. It helps to get the word out so more IT pros can learn about Office three sixty five and Azure. If you have any questions you want us to address on the show, or feedback about the show, feel free to reach out via our website, Twitter, or Facebook. Thanks again for listening, and have a great day.
Donate
Share
Apps
Menu
Microsoft Cloud IT Pro Podcast
Open in new window Display Menu
Episode 421: Microsoft 365 Mergers and Divestitures with Frank Lesniak
|
Back 15 seconds Forward 15 seconds Play Speed CC
Podcast: Play in new window | Download (Duration: 34:19 — 23.6MB)
Welcome to Episode 421 of the Microsoft Cloud IT Pro Podcast. In this episode Ben sits down for a conversation with Frank Lesniak, the lead of the Microsoft 365 team at West Monroe. In this episode, they dive into the intricacies of mergers and divestitures within Microsoft 365 environments. They discuss the initial due diligence phase, planning and approach, building and configuring new environments, and the final migration and cutover phase. Frank shares insights on common challenges such as integration of different licensing models, the handling of workstations and applications, and the importance of security assessments. The episode provides a detailed look at the methodology and tools used by Frank’s team to streamline these complex processes.
Your support makes this show possible! Please consider becoming a premium member for access to live shows and more. Check out our membership options. (more…)
Episode 420 – Ben convinces Scott to buy a 3D printer
by [Scott](/content/author/scottmsclouditpro/ "Posts by Scott"/index.html) | Jan 29, 2026 | Podcast
Blubrry Player
|
Auto Scroll
Welcome to episode 420 of the Microsoft Cloud IT Pro podcast recorded live on 01/16/2026. This is a show about Microsoft three sixty five in Azure from the perspective of IT pros and end users, where we discuss a topic or recent news and how it relates to you. It's that time of year again, though, when Ben and Scott actually take a bit of a break from Microsoft three sixty five and Azure and talk about gadgets. You know, those things we purchased or maybe had purchased for us throughout the year that we've enjoyed playing with and experimenting with. Essentially, this episode solidifies us as full blown geeks who have way too much fun with various tech gadgets. So without further ado, what did we spend our money on this year? Hopefully, we can remember how to do this thing. It's been a little bit. We're gonna ease our way into it because when I talk about Microsoft three sixty five and Azure, Given the holidays and the timing and things like that, and, you know, frankly, it's our show, let's hop in and talk about our kinda yearly tech review and maybe some of the fun stuff that we got for Christmas that we've bought. Tentative title for this custom for this episode, and spoiler for those listening, is Ben convinces Scott to buy a three d printer. A 100%. You need to do this, Scott. Yeah. Should we start with that one since you just said that? It's either that or Scott convinces Ben to buy a five k monitor or six k monitor. We'll see. Or Ben convinces Scott's wife to let him buy a three d printer. That's gonna be the uphill battle. Like like, really, the like, we've talked about the wife acceptance factor in the past. Yep. I can tell you, I did float this idea for the last couple weeks, like, hey, look at this cool fidget toy that Ben printed out at home and sent me a thing of, hey, look at this grid system that he put in his office and how organized everything is. And you look at my desk and it's a mess. Like, maybe that would help him do it. It hasn't really resonated yet, so I'm gonna kinda dig in a little bit and and look for some tips here since you convinced your wife, or maybe your wife convinced you. Or maybe I just kind of bought it and asked for forgiveness. There might have been a little bit of that too of, I need a Christmas present for me, and there's no big LEGO sets I want. So let's buy a three d printer. There's no big LEGO sets because you hadn't seen CES yet and the LEGO smart bricks and all that. Yeah. We'll get into that. So let's start with three d printers. So so you got a three d printer. Yes. The first one you've ever had new to this. What kind of printer did you get? And let's talk a little bit about your experience. I got the Bamboo Labs. I went with them. The P2S. So this is one that I've kinda had my eye on it. I have a friend that has the p one s, which was the predecessor to the p two s. Shocker. Yeah. I know. Right? And then the p two s was announced, saw a bunch of reviews, and there was, based on the reviews I saw talking to my friend, there was a very big feature update, a lot of improvements from the p one s to the p two s for a very marginal, if any, price increase. So I saw the notes. I actually went to go buy it, and I couldn't buy it in The US. We are not going to spend a bunch of time on this. Tariffs were affecting their ability to ship it, sell it in The US. So I was watching all these videos. Everybody was buying it, raving about it, loving it, and I'm like, I can't buy it because I live in The US. Eventually, they got it all figured out, was able to purchase it. I may have gone a little bit of overboard or a little overboard because You? Never. Yeah. Never. No. So I got that. I also got the package with the AMS two Pro, which is like a filament feeder. So I can put four spools of filament in and it kinda automatically, if I'm printing multicolor, will switch between them. I've done that a little bit, but the other big advantage of that is this is all stuff I'm learning. The filament certain filaments need to be dried. We live in Florida, which is very humid, so I wanted a good way to dry this filament. And there's ways you can do it, like, in the oven or go build filament dryers or all of this. I'm like, you know, this serves two purposes. It can dry the filament. It can also feed the filament into the printer. So I got that with it, and then I maybe bought a little bit too much filament. Like, I got glow in the dark filament. I have transparent filament. I have matte filament. And then there's different like, the different types of filament you can get, the PLA and the PET g and, like, 30 other ones. So that I would say has probably been the biggest learning curve for me is not so much how to use it. Like, it's super simple to print stuff. You go to Maker World, you download models, upload them, hit, like, three buttons, and you can start printing. But it's been a lot more learning around what filaments should I get, how do you print most effectively with different filaments because different heats and whether you have to dry it or you don't have to dry it. I've had some where, like, it doesn't stick to the plate that it prints on, and it's like, I forgot to clean it, and then I have to go clean all my greasy fingerprints off of it and reprint. So a bunch of that type of stuff, but, overall, I mean, I'm up to, like, two hundred and fifty to three hundred hours printing on it now. Like, you just got this thing. They're like you've been printing twenty four seven since Right. It just runs all night. Like, I find a printer, I'm like, oh, this one takes thirteen hours. I'll start this one at, like, 8PM tonight, so it'll be done in the morning. But, no, like you said, it's been a mix of some fidget toys. The kids have loved the fidget toys, whether it's infinite cubes that just kinda keep folding or there were, like, little spiral of Christmas trees, and I sent you a video of this where you can drop it through and spin it and fidget with it. And the kids had so much fun with them. They're like, this is part of it. They're like, dad, we wanna give these to all of our friends for Christmas for their different coop classes. I ended up printing, like, 50 of these Christmas trees so the kids could give them to their different friends and all that. And realistically, I mean, each one is like a buck and a half to print it if you don't count the cost of the printer itself. I was gonna say, like, filament Yeah. And your time for what that's worth Right. To go in To do it. Get all that stuff done. Yeah. I mean, I've been looking at three d printers forever. I've tried to I think I have, like, some of the same hesitations around, like, the humidity, where you print it, what does that look like. But I've heard really good things about the Bamboo Labs stuff. Do you see them all the time on YouTube and things like that as you're going through? Yeah. I've been impressed. Yeah. The filament itself, like you said, I did the fidget toys, and then I did do containers for one of my drawers. I have some IKEA drawers in my office. And I could just go on and I'm like, I wanna make bins for these drawers. And someone made it's the Gridfinity system, made models already where you can just go print, like, the base plate for the system and then print stackable bins. And the one thing I like about it, my wife gives me a hard time about it. She's like, this feels like dollar store stuff. If you could just go buy it at the dollar store. I'm like, yeah. I could. But at the dollar store, I can't go in and say I want this to be a 140 millimeters by a 170 millimeters by 50 millimeters. So I can very much the customization of it, whether it's that or all the cable management under my desk now is all done with stuff I three d printed. I've printed Lego storage containers. And I think we'll have to try and, like, include some pictures in the show notes or things like that of some Yeah. I'll put some pictures in. Doctor. Some of the stuff that you've done there because it does have me enthralled. And I think it's less convincing me, like I said, than it is convincing my wife to get this done. But funny enough, you and I were chatting a little bit and you were talking about like, Oh, like maybe you'll need to go get a set of calipers, like digital calipers or something like that for measuring all this stuff. Maybe I didn't even mean to do this. Maybe it was purely subconscious on my part, but I did ask my wife, like, on my wish list for Christmas, I asked for a pair of digital calipers, and she bought me one. So I'm already ahead of the game. I have the calipers, just like, I Yeah. I'm so close. Almost ready to go and get there. We'll see. It's too bad the printer's like 80 times the price of the calipers. Like you said, my wife doesn't need to know that. Like, she doesn't listen to this podcast, thankfully. Okay. So we're safe. I might just, oops, look at this new thing that appeared on my desk here, which funny enough, maybe if we can move on to the five ks or six ks monitor thing. Yeah. You had stuff appear on your desk that you're telling me I should order. So I've been looking at a you and I are both like unabashed Apple fans, Mac fans, we both got MacBook Pros, and you've gone further with like the studios and things like that, but one of the things that I've never experienced is a five ks or a six ks monitor. So I spent some time at the Apple store at like a retail store over the holidays, like looking at the studio displays, things like that. Not so much because I wanted to buy a studio display, but I was just interested in the whole five ks aspect and people gushing at like, you know, like, It's kind of like Christmas vacation, can't see the lines, Russ, except, Oh, look, can't see the pixels, can you? And they're going to go figure that piece out. So one of the nice benefits that I get at work is we get a benefit where we get a certain amount of spend every year for all sorts of things, for health, personal health, I could buy gym membership, get it reimbursed, things like that. But it also does desktop things, so like if it's like ergonomic desktop. So over the years, I have this nice like Haworth Fern chair, It's a $1,500 office chair. I would never buy that chair for myself, or I would never spend that much money on a chair. I'm the guy who like goes down the corner and is like, Oh, it's $20 at the dollar store. Let's get it. And then I'm miserable. But so I've done that. I've done a standing desk over the years, things like that. So I've kitted out my desk based on that benefit and just having it there, and it's kind of like free money. So I was looking at some five ks monitors, things like that, and I was like, you know what? Like, I just need to like pull the bullet and like bite the bullet, get this done. Doctor. And go get one. Doctor. I picked one up and I didn't even really like pay attention when I was doing this, when I was ordering, but I probably should have thought about it a little bit more. But I ended up picking up a it's a ViewSonic monitor. So like the panel is what it is. Five k on a Mac, I just gotta say, like, the hype is there. I'm not somebody who notices, like, the difference between 60 hertz and 75 hertz or 120, things like that, but just the pixel density, things like that clean cleans it up all great. So so that's all good. But the nice thing, and or maybe one of the kinda hidden benefits and drivers here, was that at five ks resolutions or six ks resolutions, things like that, you need a lot of bandwidth. So you're typically talking, or I think in most cases for everything I've seen, at least in the Mac ecosystem, you're talking about monitors that include things like Thunderbolt four connectivity. Uh-huh. I didn't even know this when I picked this particular model up, but it has a full KVM, all that stuff built into it. So it turns out that not only did I pick up, like, this monitor that was like, oh, let me swap out my 32 inches four k for a 27 inches five k, and that's been all good. But also just simplifying my setup, like I've had like a USB KVM here for a long time for switching between like my personal laptop and the work one, so that's another box that sits on the desk. It has all sorts of cables running into it because it needs to go out to other things. So now I've been able to consolidate all that down just into this one monitor and this one thing that sits in front of me. So five ks monitors remain pretty expensive. But if you're somebody who's out there and you're looking for something, the prices are pretty good, at least for like you and I in The US, like you can get them from like US sellers like Amazon or B and H photo, that good stuff. So if somebody's been looking for one of those and you're looking to like bite like just place it, bite the bullet and do it, like and you've got maybe the income to make that happen or a benefit at work or something similar to what I have, like, oh man, like it's been good. Like it looks really good. It definitely helps with like the eye strain thing. And at least if you're on a Mac and the way it does kind of display scaling, all those kinds of things, just awesome. Like really, really good for that stuff. And then like I said, they have all sorts of like weird features. Like this one, I wasn't looking for it, but it came with a KVM KVM. And that all works really good. It also has a light bar built into it. So, you know, like the BenQ light bars and things that sit at the top. Oh, yeah. Yeah. So this one has a light bar at the bottom, and so it's not built into the top of the monitor. But down at the bottom of the monitor, it has an extra light that you can go ahead and turn on and off. And it's not as nice like at least being in the Apple ecosystem, I think like the studio display or whatever it is would be a lot nicer just because the integrations and things like that. Like it's not as pretty as far as like the looking at it and the bezels and things like that, or like the way the wires are sticking out of it, super janky. Like, this is a ViewSonic five k monitor that I picked up. Like, it's dumb. Like, the power, like, when you plug it in on the bottom, the power button, like, it's not like a 90 degree cable, so it's basically, like, hanging, like, straight out the bottom of the monitor. So you gotta get by some, like, aesthetic things. But, you know, that aside, I've been really, really happy with it to the point where so I do a dual monitor setup. I do one landscape in front of me, and then I do a portrait monitor off to the side for long form reading code, all those kinds of things. So I'm actually debating, like, we just rolled into a new year, so I still get that benefit. So depending on how much of that I use this year for, like, like I said, like health, fitness benefits, things like that, if I maybe got like the extra kid at the end of the year, may maybe I'll go pick another one of these up and then just go dual dual five k. Do you feel overwhelmed by trying to manage your Office three sixty five environment? Are you facing unexpected issues that disrupt your company's productivity? Intelligink is here to help. Much like you take your car to the mechanic that has specialized knowledge on how to best keep your car running, Intelligink helps you with your Microsoft cloud environment because that's their expertise. Intelligent keeps up with the latest updates in the Microsoft cloud to help keep your business running smoothly and ahead of the curve. Whether you are a small organization with just a few users up to an organization of several thousand employees, they want to partner with you to implement and administer your Microsoft cloud technology. Visit them at inteliginc.com/podcast. That's intelliginnk.com/podcast for more information or to schedule a thirty minute call to get started with them today. Remember, Intelligink focuses on the Microsoft cloud so you can focus on your business. You know what else you could do, Scott? That'll be another interesting one. What else can I do? You could three d print some ergonomic stuff for your desk. You don't have to convince me. That might be a little bit of a stretch. I'm all in on the what's it called? The Gridfinity thing? Is that it? Yeah. The Gridfinity and then, like, the whole pegboard thing was the I did open grid, but there's a few different, like, hex board things. Gotcha. But on the monitor topic, if 27 inch isn't big enough for you and you want six k instead of five k, at CES, Dell I do not have this, but I'm not gonna lie. I kinda want it. Dell announced a 52 inch six k HDR 120 hertz monitor. It kinda made me drool. Yeah. But at 52 inches, like, you gotta be, like, pretty far back because I'm telling you, like, the sweet like, the pixel density thing, like, can't see the lines, Russ. Like, it's real. So I'd have to see something like that in person. At least you can go see, like, a 27 inches five k or you can go see a six k monitor up to, like, 32 inch, things like that. The like, I only call it out to say, like, the ecosystem's got a lot better. Like like, these things are there. A lot of them are limited to 60 hertz. Oh, another, like, little nice surprise. Like, this ViewSonic monitor, again, like, the panel's great. Maybe, like, the connectivity is weird to look at, things like that, but it also goes to 75 Hertz. I don't know. But I can't tell the difference between sixty and seventy five with my old man eyes. So that's a Got it. See, and I already work on a 43 inch, and I sit I'm probably just around three feet away from my monitor when I work. So for me, the jump to 52 wouldn't be that big a deal. But it does. You definitely need the right desk setup. Either that or or you do that 55 inch arc arc display or whatever that that Samsung makes. Right? I was trying to think. Like, I feel like I didn't buy as much tech. Is it bad that I'm, like, looking through my Amazon shopping list to see what I bought this year? Nah. It's never bad. Only good stuff. I mean, the Bamboo printer, I've gotten to the point, Scott. I I have a lot of tech. I like my tech, and I absolutely like my new toys, but I feel like my wife very well may disagree with this. I'm pretty happy with my setup, and and I'm trying to avoid just adding more clutter to my office because I want new tech toys. Oh, I bought new UPSs this year. I had some batteries go out in the UPSs, so I had to buy some new batteries, some new UPSs. You're tugging at my heartstrings because I need a new UPS. That was another one. I just had one die the other day. I'm like, do I get a new battery for it or and just replace the battery, like, off to eBay I go, or should I should I look at new ones? So I think what I wanna do next is I think I wanna do a rack mountable UPS so that I can then selfishly get a rack so that I can mount my UDM Pro in a rack and get it off the the bottom of the And then do you know what else you can do? You can three d print rack things too, mount other stuff in your rack that aren't naturally rack mountable. Look at this. I'm gonna fit this in everywhere this this episode. It all comes back to three d printing. It's funny how funny how circular the world is there. I should remember this. I also got, I am a Logitech mouse junkie, maybe? I love my Logitech mice probably as much as I love my Max, and they came out with the MX Master four this year. And, naturally, the day they came out with it, I bought two, one to go in my backpack and one to be at my desk with me. But I've had every version I think I have them. I have one, two, three, four, five. I, like, have my Logitech mice displayed. You can't really see them under the corner here. I think I have six Logitech mice as they've gone from the MX Master to the two to the two s to the three, three s. Three s. Yep. Four Four s, whenever that comes. Yeah. Are you liking the haptic feedback on it? I don't use it a ton. I do like so if people have used the Logitech Master mice before, they always had a thumb button underneath it, but you had to push down on the mouse, which was like a sideways movement with your thumb, which for me was a little bit unnatural. On the four, they kinda moved it so you can it's, like, on both sides of your thumb, so you can squeeze the mouse. Now to click that thumb button, which is much nicer. I do use that more, and they added shortcuts with it. So if I push that button, I get some of the haptic feedback, and I can have shortcuts to AI, to multimedia, to launch, like, finder. You can kinda customize what you want it to do. So it's like an extra mouse button with Stream Deck ish type functionality that just pops up on your screen. Kind of useful. The other thing they did is they switched if again, if you use the other ones, they had a little bit more of a rubbery surface under the palm of your hand that they tended to get a little sticky, grimy It disintegrates. It got gross. I would hold mine up and show you how just frankly nasty it is. And no matter how much you clean it or anything like, if you're somebody who like, I don't know, I have bad habits, like I eat lunch at my desk or things like that. So like like, yeah, if you have like a sandwich or like a potato chip or something, and then you touch that mouse afterwards, oh, it's in there. So the hard plastic is better for that, and I this is gonna be some personal preference. I feel like you compromise some of the comfort that the three s had when you go to the four, and I don't know if it's some of it might be the rubber. I also feel like, and I should compare it with a three s, the mouse is a little narrower. So I don't know if you ever have the problem where you're, like, moving your mouse and you bump into a Stream Deck or you run into your keyboard and you have to pick it up and just move it a quarter inch or a half inch or something. It's gonna sound weird, but the pickup and movability of it is not as comfortable. I feel like it takes more effort to just pick up the mouse and move it a little bit. And I don't know if it's narrower. I don't know if they changed the contour a little bit. I don't know if the rubber had a little bit more grippiness. But that's something I noticed right away was when I hit my keyboard and had to move it, it felt like it took more effort with the four than with the three s. This is such a niche situation, but what I really want them to do with this is I want them to make it a little bit taller. And the reason is I have an Ember mug. So I've got like that coffee mug on my desk that's always hot and charging. And because I keep the charging plate on my desk, the lip of the charging plate is perfect for the right click button on that mouse, and I'm right handed. So every time I move the mouse over by my coffee cup, it's not that I bump it. It's that the button goes underneath that lip, and it clicks. So sometimes I'll be in, like, meetings and they like, and I just, like, right clicks the screen or it does, like, a weird action. It's like like, people are like, oh, did you wanna talk? Like, no. Sorry. I didn't wanna talk. My mouse my my mouse was over the mute button, and I happened to go and grab my coffee mug, and I touched my mouse, and it unmuted me. Yeah. I've never had that. I've had the opposite problem sometimes with a coaster where the button goes right over it, and I go to click and I can't because the coaster's holding the button up. But, yes, a little bit taller, that would work. I don't know if it's taller or not. I don't think it is. But, yeah, that was something else I bought this year. Absolutely. Like, all the weird third world or first world problems we run into here. Yeah. So I got one more for you. I know you got to go to a meeting real quick and then we'll cut things off. So millimeter wave sensors, I picked Oh. And I was able to snag when and you got to watch these on like Camel or something like that. Okay. I've had an Aqara FP two for a long time. That's a millimeter wave sensor. I've got it up here on the wall by my desk. So what it does is when I sit down at my desk, I've got all my stuff plugged into smart plugs, and it just turns it on, turns it off. So if I get up, walk away, things like that. So I got an FP two, which you have to plug in via USB, so now I got a cord running up the wall, like it's janky, right? It doesn't look good. So they made the FP 300, which is a wireless five in one. So it's a millimeter wave PIR, light temperature and humidity sensor, but it's battery powered. I forget if they're like CR twenty thirty two's or twenty twenty five's, things like that. You just mount it up on the wall, no wires. The batteries are supposed to last about three months, so I was able to pull down my FP2, put this thing up there, and it's just a lot smaller, works with the whole Acara ecosystem, ties in with Home Assistant, Alexa, Google Home, just does all that stuff. If somebody's looking for, like, one of these and you're like, you're looking for, like, a turnkey one Uh-huh. Super cool. The FP2s are great. This one I love for the lack of wire, and as long as they like like, even at three months, if the battery dies, whatever, I'll just swap the batteries out. It's way easier. It's smaller, mounts easier, just a really good little device, and it's been rock solid for me so far. Haven't had any drops out from Wi Fi or things like that. Occasionally, I get those on, like, my f p two. But if you're looking for, like, room home automation, like I walked into the room, I walked out of the room, millimeter wave's great for that because if you're sitting down and watching TV, like, turn the TV on, but then you stop moving, typically, like, just a motion sensor might shut the room down. Like, maybe somebody's been in, like, an office building when the lights shut off, and you kinda wave your hand in the conference room to come back. You don't have to do that with millimeter wave sensors. They're just really good, excellent. There's a whole, like, ecosystem out there, but I I really love the Aqara ones. Like I said, the FP two has been great. The I've used that for, like, two years. Plus the FP 300 now. Been running it for a month, and it's been rock solid. I just picked some of these up because I'm in the Unifi since we're talking about it, and then I really should go. Unifi came out with their Superlink device, which brings in, like, environmental sensors and some of that. They just released their motion sensor or Unifi. I ordered two of them. I don't know if those are millimeter wavelength or not. I was just looking. They're all in one sensors that they put out there. They do do motion detection. No. It's not the all in ones. They have a specific motion one there. I just dropped a link in the chat. Oh, the motion sensor. Gotcha. Yeah. I don't know if that's millimeter wave. I have their environmental sensors, which are kinda nice. It's just something I've been playing with. Cool. Another thing for folks to look at. So we'll get back to our regularly scheduled program around, like, m three sixty five and Azure and all that stuff. But always like chatting about the new toys and everything that's out there, and now I gotta go convince my wife to Absolutely. Three d printer. Get a three d printer. Yep. Or come up with a health and ergonomic reason that you need one. Absolutely. Use your money. Your yearly budget for your three d printer. Alright. Thanks, Ben. Awesome. Thanks, Scott. Have a good one. You too. We'll talk to you later. Bye. If you enjoyed the podcast, go leave us a five star rating in iTunes. It helps to get the word out so more IT pros can learn about Office three sixty five and Azure. If you have any questions you want us to address on the show or feedback about the show, feel free to reach out via our website, Twitter, or Facebook. Thanks again for listening, and have a great day.
Donate
Share
Apps
Menu
Microsoft Cloud IT Pro Podcast
Open in new window Display Menu
Episode 420 – Ben convinces Scott to buy a 3D printer
|
Back 15 seconds Forward 15 seconds Play Speed CC
Podcast: Play in new window | Download (Duration: 26:41 — 18.4MB)
Welcome to Episode 420 of the Microsoft Cloud IT Pro Podcast. In this episode, Scott is back for a lighthearted discussion on some of the new tech and toys and that Ben and Scott picked up over the holidays. Listen in as Ben tries to convince Scott he needs a 3D printer and some feedback on the gadgets they both picked up.
Your support makes this show possible! Please consider becoming a premium member for access to live shows and more. Check out our membership options. (more…)
Episode 419 – Security and AI: Security Store, Security Copilot, and Agents
by [Scott](/content/author/scottmsclouditpro/ "Posts by Scott"/index.html) | Jan 15, 2026 | Podcast
Blubrry Player
|
Auto Scroll
Welcome to episode 419 of the Microsoft Cloud IT Pro podcast recorded live from Workplace Ninjas US in December 2025. This is a show about Microsoft three sixty five in Azure from the perspective of IT pros and end users, where we discuss a topic or recent news and how it relates to you. In today's episode, John Joyner, an eighteen year MVP, senior director of technology at Corsica Technologies, and a security professional extraordinaire joins Ben. They discuss some of the announcements from Microsoft Ignite focused around Microsoft security, as well as diving deep into the new security store, AI agents, security compute units or SCUs, and how Microsoft is making enterprise AI security more accessible and affordable than ever. Another interview from Workplace Ninjas. I have done more interviews here this week than I have for a while, so another one without my co host, without Scott. But I'm joined instead by Jon Joyner, another Microsoft MVP. I'm assuming in the security space given the nature of the conference and our topic today. But do you wanna introduce yourself a little bit, John? Tell us who you are, what you do. Do you like long walks on the beach? Yeah. Hi, Ben. Thanks for inviting me here today. I am a eighteen year Microsoft MVP. Oh, congratulations on that. So usually, you're like adding up the, like, the five year year bugs. Blue disk, like, everywhere. It's an amazing thing that you plan on it happening when you're early in your career, but it can happen. Right? And I am dual awarded right now in cloud security Okay. And Azure management. Oh, okay. So Right. And I'm here talking about Defender for IoT. It's the topic I'm presenting at here at Workplace Ninjas. Okay. Very cool. We might have to do another follow-up episode on that because that is not something I know much about either. Not our topic for today, but Okay. Yeah. No. Yeah. It's exciting. Mental note. Future episode. Yes, sir. So today, this is we're gonna talk about some of the announcements that came out of Microsoft Ignite. There were some really, I think, really exciting and really cool announcements there, specifically around in the general realm of Security Copilot and some things like the security store and it being included in e fives now. So we're gonna dive into that a little bit. So security store. Again, brand new at Ignite couple weeks ago. Do you wanna tell us a little bit about, like, what is the Security Store? How does this change some of the things even? Diving to some of those things. Yeah. Security Store is a effort by Microsoft to surface in the work space used by security professionals, services and products that that those cybersecurity people will find useful. Okay. There's currently until we had the security store, there was basically Azure Marketplace. And Azure Marketplace is as broad as can be. And there's tens of thousands of things in there. Okay? Yep. And Microsoft identified the primary of that marketplace. We're not the cyber staff. They were more like the contracting staff and the Okay. FinOps people and that kind of and they so we imagine place where security specific offer available. You define exactly. So they've created the security store. And the security store can be found in the Defender XDR portal. Okay. And also securitystore.microsoft.com. Okay. And So does that take you, like, if you go securitystore.microsoft.com, does it just take you into the security store in the security portal? There there's a there's a public public portal. Okay. Requires no login. Got it. Nice. Right? Right. So you can actually browse it and see some of these solutions that are available without even having a Yes. Subscription or having to And I think I think broadening access is was a good thing. Yeah. So I think about this store is security Copilot aware. Right? Okay. If you have security you have SCUs, security computes Yep. Allocated to your so things may become available to her. And this is also true in Defender XDR that if you have there's a new capability for remediations, like fix it fix it now buttons. Right? And the but they're only available if you Got it. If you don't have security Copilot, the button links to just a learn article. But if you have security Copilot, it links to shall I do it now. Right? Oh, is this Yeah. This is all quite new. And same with security store, you have SCUs, then you have a a different experience. Okay. Logged in and all those other Got it. And the security store is divided into categories like tabs at the top, and the newest one is agents. Okay? Surprise. Right? We get more agents. AI. I'm like, I don't think we're how many tattoo it on my forehead or my wrist? Yeah. And so the agents is a place to buy, and some of them are free. Okay. Like, some of them are free and some of them you buy, and they are partner created and Microsoft created, and they are AI agents. Okay. Right? And they do specific things. And so the concept is that you're a security profession, you're in the portal, and you're investigating a thing or you're doing a thing, and you're having trouble. It's taking a lot of time, a lot of friction. And you're like, gosh. I wish there was a way to automate this. And, like, you do the right searching and go to the right places, you're gonna see the partner offer. Click here to add this agent to your environment. And it'll do the thing. Okay. And in in the store right now, some agents have no charge to install essentially. Others have a monthly charge that is payable to partner that developed. Okay. It's a way for partners to start to monetize and share their IP as it relates to AI. It's a very lucrative potential for partners, and it's a great way for Microsoft to to democratize access to AI. To help you out. And so these agents these agents are paid for when they run by consuming security comps. Right? Okay. SCUs are the foundation for running SecurePilot. And when you have SCUs in your environment and you activate a Security Copilot instance, you are basically standing up a runtime, almost a rep an LLM replica that is just for you and is tuned to security and may or may not have access to your private company things you may have given Security Copilot access. So it's basically a copy of all the LLM goodness that you have just talking to BingChat. Uh-huh. But it also has this extra access to all of your stuff and access to all the threat and vulnerability stuff. So it's expensive to stand up this thing because it it's private to you. And Microsoft must allocate iron in its data center just for you. And so it costs them, and they've come up with a way to pay for it, SC. Got it. And SCUs have been around for a year or so since Security Copilot came out, and early adopters, did find that expensive site Yeah. To make it useful, to make it responsive twenty four seven, you had to run SCUs all the time. And there was multiple tens of thousands of dollars buy in, just start using Oh, yeah. It was wild. And some companies that went all in, they have found satisfaction. Many others said this is too much right now. K? And Microsoft recognized this. They're a smart company. Yep. And they came up with this way using this agentic model. And now SCUs went or rather, security agents, when they run, they tap into your SCU. Okay. And when you go to the security store today and you look at the offerings, they list how many SCUs or how many frac subs Okay. When you run them. And some of them consume point one SCU. Oh, wow. Yeah. Yeah. So we've gone we've gone from, like, I need to allocate a five digit check to run this thing to it's just a couple of dollars. Okay. Okay? And if that agent task that runs in that one tenth of an SCU, if it saves my analyst an hour or a day, it's well worth the three the $3 for that. Actually, they changed security comp unit purchase. You know, like, basically buy a discounted package of, like, $4, and then when you go over it, $6 over 6. So they have they've slightly changed it to make it slightly more Yeah. If you can predict how much you're gonna use. So they made it a little bit cheaper, but the model is yeah. You can still run it $24.07. You'll still use it as a replacement or augmentation asset for junior and middle level security engineers. Uh-huh. You can still do that. Now there's this new way to consume to take advantage of the Microsoft cloud. Okay. And so these and the most popular agent right now as I stand is a phishing triage. I Right? Yes. And I've heard a lot of people asking about that one and talking about one. Fishing is the number one vector for ransomware. Yep. And so anything that mitigates that is very high value. And the phishing triage agent, frankly, I have I solved either. Okay. But I I know that it basically responds real time to mitigate the consequences of a phishing. A phishing. Right. And, you know, we can do this now with logic apps, with Yeah. And I've tried to build some of those there. Thank you. It takes a little bit of work. It does. And, like, is mine better than yours? Like, is am I missing something? Did I spend enough dev time? Am I thought of everything? When when you do it your on your own, it's gonna work the best. And for example, the phishing triage agent was developed with Microsoft centrally to support many security professionals, and it's probably the best. Probably. It is I can guarantee you it's better than mine because I hit that with my logic app. Like, I would have somebody click on an email, and I'd be like, try to build the logic app. It's like, oh, well, this one didn't go to a user. This went to a group. So the data that came into the logic app was different to Microsoft three sixty five group before the user got it, or went through distribution list, or I had a Microsoft three sixty five group in the distribution list. So that JSON that came into Logic apps, it felt like it was different every time somebody clicked on a phishing link, and it I banged my head against the wall trying to account, to your point, every single scenario to make this logic app work the way I wanted to based on the incoming data when a phishing event happened. Exactly. And another way that these agents help, they don't require you to know. And, like, I know KQL. You probably know KQL. Yep. I can sit down and go, well, did, you know, filter a go pipe, like and I can answer questions like, has this happened before? Has this combination of things happened before? I can whip it out generally in KQL. But I'm a professional. I've studied a long time. Yeah. Even though that's for eighteen plus years, probably. Still, I have to go go check it out, and I may make mistakes. And so the first season of professional time is creating a complex query to answer an important question involving historical analysis compared to something happening today. It's possible, but it's requires a senior person. Yep. And they still may need a little time. Okay? So if now, like, you can write an agent yourself or as a partner and write an agent for other cost that does that thing without requiring any KQL. And it's not like in like, it's a crutch. You're like, oh, I don't wanna learn KQL. I'm gonna I'm gonna just talk to the LON. But when you think about it, we can't depend on every security analyst being a crack QL Right. Guy or gal. Right? It's a person dependent thing, but we need security analysts really bad. There's a shortage. Okay. Right? So if we can come up with a way to have these people just talk to the SIM Yep. Why not? Right. Makes sense. So there's there the Microsoft's approach to making AI more affordable and more approachable and more understandable. Again, when we cons when we buy an agent, we know exactly what we do. We know exactly what it's gonna cost. It's a box. Yeah. Our risk is minimal. Yeah. Whereas, like, oh, I'm gonna buy a stack of SCUs, and I'm gonna assign my developer two weeks, and we'll hope that he or she comes up with something that works afterwards. Right. Remove remove that doubt, remove that cost. It's a great thing. So check I encourage everybody to check out SecurityScore. Okay. Do you feel overwhelmed by trying to manage your Office three sixty five environment? Are you facing unexpected issues that disrupt your company's productivity? Intelligink is here to help. Much like you take your car to the mechanic that has specialized knowledge on how to best keep your car running, Intelligent helps you with your Microsoft cloud environment because that's their expertise. Intelligent keeps up with the latest updates in the Microsoft cloud to help keep your business running smoothly and ahead of the curve. Whether you are a small organization with just a few users up to an organization of several thousand employees, they want to partner with you to implement and administer your Microsoft cloud technology. Visit them at inteliginc.com/podcast. That's intelligink.com/podcast for more information or to schedule a thirty minute call to get started with them today. Remember, Intelligink focuses on the Microsoft cloud so you can focus on your business. So I have a question with Security Store too. Does this also provide any additional type of, like, third party integration? Right. Before with Security Copilot, you could go in and you could connect it to, like, Azure Firewalls and other services. Does this also extend some of that, or is this really just focused on agents? Well, the the agents can imagine. Okay. Imagine an Azure Logic app connect to a Security pilot prompt book of infinite Yep. Density. Like, anything you can imagine. So it's not some partner or a company vendor, like, could write agents that makes their connection so much Got it. And more meaningful. And so a third party company that right now is just a a lonely connector in the 350 or 400 in the Sentinel catalog Yeah. Can now become can stand out Okay. And be more attractive and more usable because it's not just connecting to Sentinel the way Microsoft thought it best to connect connect the way you, the author of the software, will work best. And you can put that into an agent, and then somebody get that agent in the security store and hit the button and maybe pay $2.02 s c two or three SCUs. This is gonna be an expensive workflow. It may cost $18 to run this workflow. But when I'm done, I would have created optimized connectors, playbooks, workbooks, everything in my environment. It's just gonna be aware of my environment. Think about it. I'd be able to Yeah. Like, you know, creating a custom workbook right now. Again, if if KQL Right. You can do it, but it's It still takes some work. Fifteen minutes on a good day for the simplest change, frankly, to crack open a workbook, find the widgets. Oh, yeah. Blah blah blah blah. So imagine an agent reconfiguring the work, tailoring it just to your environment, knowing how many employees you have, what industry you work in, what your time zone is. Right. Like, all this stuff. Asking all those questions and then building that knows these things because it lives you Yeah. So so the it it yeah. I think this I I haven't seen any of these yet. There may be some in the store, but I think that in answer to your question, third parties will love this because it makes their stuff easier to consume and a better experience. Yeah. So when the SCUs, kinda talking about this came out at Ignite. The announcement also came out with the SCUs now being included in Microsoft 55 e five, and like, I did the math, it comes up to like point four SCUs per month per e five user. I'm assuming that these agents, going back to the fractional, you don't even have to go spin up a $4 a month SCU or a $6 a month SCU. You're gonna be able to start leveraging the included SCUs to run these agents Yeah. For a for a 1,000 employee organization Uh-huh. 400 SCUs will magically appear in your subscription every month. Okay. And if you don't use them, you lose them. Yep. And at the And if you don't use them or you lose them Yep. And at the beginning of next month, you get another farm. Get another farm. And so in that scenario, if we have 400, you know, I was just talking this yesterday. Imagine that point one Right. SCU You can run a lot of things. Times Yeah. In one month. And and, like, so can and you it won't over consume. Like, when you try to run the four thousand first time, it'll say you're out of this. You Not let you go above that. Yeah. I I think you can actually tell it. Yeah. Go ahead go ahead and supercharge me, They're assuming that they normally you know, for most customers, they're gonna say, don't stop when I exhaust them. So in in this scenario where you only got 400 in a month, use them. I mean, this is a boom because Right. It's lost money. If you don't go to a security store and you don't find an agent that's attractive to you and affordable to you, you are missing the boat. Yeah. And you are going to become at an ever pretty competitive disadvantage to other people in your industry that that are seeing the light. Right? Yep. In in the security world, attacks are driven by AI. 60, I believe, 60% Is it really that high already? Of ransomware attacks are AI driven. Okay. I didn't realize that that high of a percentage of the statistic I learned at the security b day at Unite. Oh, okay. And, like, if you're not using AI, counter the 62% of the bad guys in AI against you, you will lose. It Yeah. It is foregone. So it's really important to be an early adopter, I think, in these times. In that space. Microsoft has made a way for TOW in the agentic AI world, assuming you have e five Yep. And at no risk. Right. So the combination, all these announcements is fantastic. It's cool. And I know the other agent, I would say, that I've started using or seen used a lot is I like the conditional access optimization agent. I actually logged into my tenant yesterday or today, and I had, like, new conditional access policies. They label them. It's like, this was a Microsoft conditional access optimization agent. I had new ones in my tenant already for agents. Like, also at Ignite, they announced conditional access for agents. This conditional access optimization agent is already going into my tenant and identifying, oh, you need to create a new initial access policy to help protect your agents. And it's that type of stuff that I feel like security professionals aren't always thinking of, I gotta go do this right away. Do you have these agents running? It's like it's helping those security professionals secure their environment. Absolutely. It's cool. So some of the road map, you talked about like the store was kind of the start at Ignite, but some benefits or some of the things you see with this release around just Microsoft's AI strategy in general, their road map. Yeah. The road map is exciting to talk about. Microsoft has a road map. Every known aspect to AI world today. Right? They have at the at the extreme high end using AI foundry and with the with developers on staff, you can create virtual instrumentality of an imagine, own it, cleat. So Microsoft has the tools for the big shops, big vision Yep. To build AI solutions properly, safe with guardrails of governance. So and and then in the middle end, they have Copilot, security copilot, office, etcetera. So Yeah. I heard a 192. It's like a 192 copilots or something. Well, they're The hope in this number goes down, like, who can tell? Maybe it's a little I'd rather have a 190 copilots. I don't know if that's the number. I don't either. Then then zero. Right? They are an approachable, double way in the Microsoft across the spectrum. And then and now we have at the level h Right. So so we have ways to consume and use AI at every step of the way, and we have ways to secure all that. Okay? You another, announcement at Ignite was Eviving, which is an agenda AI security agent. Right? So, like, how do I we can consume a third party agent, but how do we know that it's safe? As such, he has an answer. We have another little agent Another agent. That just looks at the AI agent. We have agents monitoring. If we have an answer, we have an answer because a legitimate reason to slow down AI adoption in an enterprise is the lack of governance. What are the agents doing? Who's getting shadow agents sprawl? Oh, yeah. So how do Microsoft has one c five agent. They have an answer to clear that. And then somewhere in that in above that middle layer of the existing Copilots and the advanced layer of you riding a custom solution in Foundry. We have we have the MCP server, Microsoft MP server, and you can cry you Microsoft has published guidance. In fact, I think there's prefab solutions. For example, MCP server for Sentinel. Yeah. I've played with the MCP server for Sentinel. It's it's it's cool stuff. And so the and you know that there's a Defender cloud MCP server offering that's very Oh, is there? I don't know that I've seen that one yet. Yeah. It's Ignite was, like, blasting full of announcements. So we have a security solution for the server and a security solution for the Genentech. For the API. And so not only have we created the entry ramps at all these different levels, but also really security and governance controls at all the levels too. And, again, I'm just nobody has this. Yeah. Nobody has this. And at a lot of companies, I think that AI road map and adoption is aspirational. It's a desired goal, but, like, concrete adapted day and not unless you're in the Microsoft model, there's legitimate concerns. So I I again, I think Oh, yeah. There's an opportunity to gain a cut by diving into the AI world. Stay ahead for the bad guys. Stay ahead for the Yep. Yeah. And it is. The governance, the controls, everything they're putting in place, from everything I've seen, far superior than what you're gonna get with some of the other third party AI services. So Exactly. Yeah. That's awesome, John. I'm thanks for walking through all of those. I've there was so much at Ignite. I've been able to digest some of it, looked at some of the headlines, but haven't had a chance to really dive into some of the security store, some of the security copilot stuff. So appreciate it. Anything else you wanna add to this security copilot, security store information that we've talked about so far before we wrap up and go find some more sessions? Well, I just have one last little comment, which is the migration offender SDR portal for air all services. Right? Yeah. I love this. So this is a big deal. It's very painful even for organizations that have invested heavily in Sentinel. Yep. And the other pieces of this resided outside the b.microsoft.com. And my understanding is that Microsoft felt that they needed to do this both for marketing and on the marketing side as competitors, CrowdStrike Yep. Have a single portal. Okay. And for some decision makers, that's that makes the decision. Oh, 100%. And so to be competitive with what customers expect, Microsoft is doing this consolidate. But then under the covers, and this is where I personally come to Congress because I'm one who have been planting all of my seeds on the Azure portal side rather than this. You don't like this as much as I do. I came from the m three sixty five side. So for me, it's like, oh, I finally get settled in with all my other Microsoft three sixty five security tools. What the thing is that Sentinel lives in Azure subscription. Yep. And Defender SDR lives. Right. And another thing is that Sentinel works on a log analytics Yes. Method. You have a data lake or log analytics repository, you know, where your data is in, like like, the classics Splunk and Splunk enterprise cloud security. You have a data reservoir that all your stuff works in, and then you run queries and stuff against it. That's how Sentinel and log analytics work. And that, Frank, has scaling limitations Yep. And is not, again, keeping up with the latest best things they've done. And so Defender XDR, number one, it lives in. And number two, it runs off Microsoft resource graph rather than Azure login. So for very large customers, scaling issues involving log analytics, having to decide what subscription, what region, what commitment model, all of these things were now abstracted from all of those because now all of our data stays in our tenant in Azure. And then another reason, technically, is that the Sentinel model today depends on time queries. Right? Uh-huh. It can go from one minute to one hour to one day. Right. It's not the real time alerting. It's based on when you schedule your queries to run. Correct. And the but resource graph continuous. It's always live. And the behind the scenes, the threat action technology at Microsoft, they talk about security graph, which is different from Azure resource graph. All the graphs. Security graph is this recognition is that if I'm just looking at my firewall traffic and I'm just looking at my server sign on traffic and if I'm these silos information, and they may surface in a common investigation area, but there's still the data resides, like, places that have to be actively, you know, addressed. Yep. And resource graph or rather than Azure Microsoft security is not doesn't work that way pattern. We're just looking for patterns because real security involved, like, a bad guy and a good guy. Yeah. A a protected destination and a hostile destination or a hostile behavior acting on a friendly so there there's always at least two components to every true security incident, and that Microsoft research security side is looking for those patterns. So those got it. Oh, it's looking for those patterns always, and that is much more meaningful than periodically searching stacks of data and looking for Right. Relying on your KQ and then get going back to relying on your KQL queries to properly write them so that when they run, they're looking at the right information and all that. Yeah. So just Microsoft made the really competitive and real, incredible in the modern world where we can't we can't use the Splunk model anymore. Yeah. We need a new model. Microsoft got one. Very cool. Well, awesome. Thanks, John. I appreciate it. We'll get for those listening, we'll we'll get a bunch of links to these different announcements, different resources. Any links you want to include, John, I'll get those from you. If people wanna find you on social media or wherever you feel like being found, we can include those in the show notes. Thank you very much. Alright. And we'll talk to you later. Thank you, Ben. Take care. If you enjoyed the podcast, go leave us a five star rating in iTunes. It helps to get the word out so more IT pros can learn about Office three sixty five and Azure. If you have any questions you want us to address on the show, or feedback about the show, feel free to reach out via our website, Twitter, or Facebook. Thanks again for listening, and have a great day.
Donate
Share
Apps
Menu
Microsoft Cloud IT Pro Podcast
Open in new window Display Menu
Episode 419 – Security and AI: Security Store, Security Copilot, and Agents
|
Back 15 seconds Forward 15 seconds Play Speed CC
Podcast: Play in new window | Download (Duration: 25:16 — 17.4MB)
Welcome to Episode 419 of the Microsoft Cloud IT Pro Podcast. In this episode, Ben is once again live from Workplace Ninjas and is joined by John Joyner, an 18-year Microsoft MVP in Cloud Security and Azure Management. They discuss some of the announcements from Microsoft Ignite focused around Microsoft Security as well as diving deep into the new Security Store, AI agents, Security Compute Units (SCUs), and how Microsoft is making enterprise AI security more accessible and affordable than ever.
Key topics include the phishing triage agent, conditional access optimization, E5 integration with included SCUs, and the strategic consolidation of security services into the Defender XDR portal. Whether you’re a security professional or IT administrator, this conversation provides valuable insights into Microsoft’s AI-driven security roadmap and how to stay ahead of AI-powered threats.
Your support makes this show possible! Please consider becoming a premium member for access to live shows and more. Check out our membership options. (more…)
Episode 418 – An Anti-AI Adventure with Cat Schneider: SharePoint, Power Automate, and Conference Shenanigans
by [Scott](/content/author/scottmsclouditpro/ "Posts by Scott"/index.html) | Jan 1, 2026 | Podcast
Blubrry Player
|
Auto Scroll
Welcome to episode 418 of the Microsoft Cloud IT Pro podcast, our first episode of 2026, recorded live from Workplace Ninjas US in December 2025. This is a show about Microsoft three sixty five and Azure from the perspective of IT pros and end users, where we discuss a topic or recent news and how it relates to you. In today's episode, Kat Schneider and I just sit down with a goal of having an anti AI chat with no real idea where this adventure might take us. In the end, we enjoyed a conversation about some of the solutions Kat has built using the Power Platform and SharePoint. We talk a bit about OneDrive sync and libraries in SharePoint, and just some of the fun times from the conference, which you should totally join us for in February 2027 in Arizona. Hope you enjoy the anti episode chat with Cat. We are sitting here with Kat Schneider. I said it right. Right? You're listening right? Perfect. Yeah. Kat Schneider at Workplace Ninjas again. This is like my third fourth? I think it's Forty third? Fourth? No. Fourth episode Oh. I've recorded while I'm here. Wow. It's been busy. It Yeah. It's been hopping around here. It has been it's been a good conference. Yeah. I've I've enjoyed it. I've never gone to a security conference before. How do you feel about a bunch of security people at a conference? I feel like there's not enough talk of security yet. Is it has it reached a new level of nerd? It definitely has been an interesting experience for sure. It's definitely not a Power Platform conference. No. Definitely not a Power Platform. And it is not an AI conference. Definitely not. Which is what we're doing. We came up with this. We did a hackathon a day. Monday. Yep. Monday. Monday. Today's Wednesday. Is that when we were talking about recording this? And we said we're gonna do an anti AI episode. Yeah. We did. It was at the speakers dinner on the way to speakers dinner. Something like that. It was That was probably the problem of coming up with this. Yeah. And we said We're gonna do an anti AI episode. So we're sitting down to record an anti AI episode. We're like, what do we talk about? I didn't tell somebody how to be asked. So What is the opposite of AI? What is the opposite of AI? Or what was life This is like a time capsule episode. What was life like back when I was a kid before we had a high? Back in my day. I had to walk uphill both ways to school in the snow. In snow. Yeah. My god. All the way back to my dad's days. Jesus. Right? Well, it's funny because I've been talking to people here and I'm like, I got my start in like, Cheerpoint 2003, 2007. I was still in school. Yeah. We were in the car the other day and Jay said, he's like, Ben, we're the old men in the car. Awesome. Oh. I think I was the youngest one in the car. I was like, is it really come to that that I'm now the old man at these conferences? I used to be the one that I go to these conferences at like, when I was doing SharePoint 2007 and they're like, they're talking about before SharePoint 2001. I'm like, I was in kindergarten when you did that. I'm on the opposite side of that now. Yeah. Now you're the guy that everybody talks about. In a good way. What are they saying about me? Because my sessions have got little we may have gotten a little wild this week in our sessions. Did you have you heard about any of our sessions? I have not heard a peep about any of the sessions, but I also have been a little off the rails myself. It was we may have so there's a bunch of people with Tim Tams here. Yes. Okay. So about this conference, so many Tim Tams here. So many. And another thing about this conference that as I look back, I I didn't know how it was gonna go going into it. I really like it. You have clippy bucks at this conference. So many clippy bucks. That we get as speakers and we can hand them out. And we get to make it rain. Yes. And we can use them to bribe attendees. Yes. 100%. Or incentivize them. Which I think one thing, it's definitely incentivized conversations. People here have talked way more freely, asked way more questions, been way more participatory, is that a word? Participants are. Yes. Designed sessions. Because of these, we tried to get attendees last night in our session to go steal Tim Tam's from the session next to ours with Clippy Bucks. Oh my god. It didn't work. Damn. But it would have been really funny Yeah. To see them, like, run out and try to run back in with Tim Tam's and hear the session next to ours. That would be fantastic. Yeah. Anyways, that's the type of sessions we've had this week. Yeah. No. I definitely have talked a lot about AI in sessions this week, which is why I was anti AI. Okay. But So what did we do? Anti AI back when we were kids Oh, my gosh. And we were doing this, you were talking about We don't know what we're gonna talk. We tried to come up with ideas. Flows, SharePoint, like, before AI. Yeah. We can't talk about AI, so we can't compare and contrast. Yeah. But I think some of these solutions, like you were talking about some of the flows you built Mhmm. Because it was flow back then. Yeah. It was We started talking about flow, and we both knew what we were talking about. Yeah. Even though it's power automate. And you were like, oh, wait. No. It's power automate. Definitely power automate. Definitely did not mix that one up. It I was like, we should just sit and talk about, like, some of what we did Yeah. Before AI because I think there's so many conversations about AI now that sometimes you we forget about Mhmm. Let's go do something that's not AI Yeah. That's anti AI. Because it's so refreshing to be, like, back to basics. Yeah. And one of them you were talking about that I'm, like, I never thought about this was SharePoint permissions with flows Yes. Was something you did. Yes. So tell us about SharePoint permissions and flows and the solution. Okay. Okay. What we were trying to do is we were trying to manage our SharePoint permissions. We were trying to identify who was in what cost center doing what job and how they were all involved and have a nice landing page for a call center so people knew, like, oh, okay. This is who I go to and this is where I can ask questions and whatnot. Okay. And so I was like, well, if we're gonna do that and we're gonna have this information already in SharePoint because it's associated with people pickers Yep. Like, why not just put it in a list that somebody can manage? They literally, the cost center manager will be like, oh, hey, I got a new manager. I'm gonna go put my new manager's name over here so people know that, hey, this is my new manager. Okay. Like, the managers can manage the people that work for them and below. Kinda makes sense. Right? Isn't that what they're supposed to do? It's so crazy idea. It was Mind blowing. Breaking technology. I'm like, why don't we just, I don't know, do what we're supposed to be doing and manage the permissions this way? And so I ended up building a list Yeah. Right. That incorporate, like, that that thing back in the day, the code called JSON. Yes. Yeah. Where you could, like, show the list in very specific format and, you know, there was tools that you could have in browser so that you could format your the SP formatter tool. Yep. Fantastic tool. I love that tool. And that's even newer than I mentioned SharePoint Designer and you laughed at me. Oh, I've used SharePoint Designer and I was like, oh, I hated that thing so much. Hated it. Okay. Anyways, back to Visual Studio Code and JSON. Yes. Well, no, because I'm still in the browser. I haven't even made it to Visual Studio Code yet. Oh, yes. That's right. Yeah. No. So JSON, we're managing that list in JSON. So I could have, like, their picture from their profile, like, show up nice and big. Doing the whole list formatting. Yeah. I was I was doing all kinds of fancy things. And then I was also incorporating the list on the front page, like, the home page. Okay. And so you could click on the person's or their picture or click on the little email icon that I incorporated with it, and then you could send them an email or you could open up a Teams chat and, like, you could do all these crazy things. And then when somebody moved in or out of a position, like, say, somebody moved on to another spot within the agency and I wasn't managing their SharePoint collection and they had to do their own thing Uh-huh. They just got moved out and they lost all their permissions to access anything in Teams or any of the SharePoint that it was being managed by. Like, I was managing lots of permissions, like, even for Teams groups and whatnot from the SharePoint list. From the SharePoint. So was that, like, one central SharePoint list that everybody was in there? Did you have separate SharePoint list for each call center? Or For each call center, I had their own site collection because I didn't want finance and accounting to be able to manage To change permissions for another department. For them to be changing permissions for HR and Yeah. Yeah. That's what I'm saying. It was all over the place. So I was like, you get a site collection and you get a site collection. I was just Oprah. Oh, yeah. Just handing out site collections left and right. Yeah. Even though the SharePoint team was like about governance of SharePoint sites. Yeah. So I ended up being really close friends with our SharePoint governance Why? Folks. And I was like, I need another site collection. I'm like, oh, would you please just use the form? And I'm like, I will, but just know it's coming and this is what I want it to be named and don't go naming it anything crazy. So, like, there was all of that. And then I would be the site collection administrator and go in there and do all of that fun stuff. Okay. But, yeah. The I would go in there. I would set it up for them. I would set up their teams and get this one single SharePoint list. And then every time it got updated, it would kick off a Power Automate instant flow. Okay. Like a, automated flow. That's a mouthful. A Power Automate instant flow. Yeah. And it would say, oh, hey. This list item changed. What was the change? And I actually got it to the point I was able to go back into the previous version of that list item to see what was the value of that people picker before Uh-huh. And what is the value of the people picker now and be able to revoke permissions and grant permissions based on which it was. So So you're just adding and removing people then from the SharePoint permission group SharePoint groups. Yeah. Yeah. Like, I would have individual specific permissions, and then I would make it so that, like, that specific list, I didn't use groups per se, but everywhere else, there were groups. There were groups. Yeah. And then managers could essentially manage their own users' permission. Were they owners of their own SharePoint sites, or did this let you manage their permissions without them being owners of the sites? So I would not allow them to be full owners. Okay. Because if you let them be full owners, then they'll go in and delete something, and you're like, what are you doing? Because while version history was a thing, you can still delete something and then not be able to recover it. And then I wanted to murder people. But, you know Yeah. Working for the state, murder's frowned upon. I'm I'm I'm glad you refrained that we get to sit here and have this conversation here versus in jail somewhere? She was having this conversation with barks between us. Why would I why are you incarcerated? Jail so I can interview Kat about her SharePoint work and Why were you incarcerated? Because I murdered somebody for their SharePoint permissions? Oh, that would be fantastic. My. That's like a whole other side quest that I feel like needs to be unlocked somewhere. Oh, god. This is going even more off the rails than my sessions this week. Too much caffeine, too little sleep. And way too many shenanigans. Too many shenanigans. Actually, it was the ninjas. I blame it on the ninjas. The ninjas? I got a selfie with the ninjas. Oh, did you? I did. Oh, you did? I did that. I was in the speaker room and they were like, oh, can we take a picture? Because there was a workplace Ninjas sign on the door. Yeah. They went on a picture with them behind the glass with a sign in front. So I'm like sitting here working away and they're off behind me and doing their photo op. And I'm like, Can I get a picture? A 100%, that was definitely required. Yes. And accidentally going out at night, that was something else that came up this week. Yeah. But we couldn't accidentally go out at night. But I I started to see how it happened because we came back from, we went out to watch the Dallas Stars game last night. We came back and Jay and I were both like, oh, we're tired we need to go to bed, we need to get work done. And we walked out of the lobby. And we accidentally sat down in the lobby with a bunch of other people and got up an hour later. Yeah. I heard there were a lot of sushi boats involved last night. I saw a picture. I do not eat sushi, so I don't have the appreciation for it. But the pictures, it was a lot of sushi. I So I didn't see all of these pictures that apparently are going around, but I got one picture of one boat. One boat with 92 pieces of sushi in one boat? Yes. And there were I heard there were at least three boats. I heard somebody ate one boat all on their own. I wonder if they're here today or They are? Are they doing okay? They seem to be standing on their own two feet, but just fine. Alright. That was a lot of sushi. That's a lot of sushi. Wow. And our friend who may have accidentally gone out. Did he? He accidentally went out with them. Accidentally go out with them? I have I have not seen him yet today. Oh, there is a reason why. Okay. But he is a good boy. Same as said friend also was really mad yesterday that his session was at 9AM in the morning. He's like, nobody ever schedules me for sessions before 2PM because said friend apparently has a habit of accidentally going out. So many times. Accidentally going out. I love him to death though. Okay. He's fantastic. Yes. It is he has made for many adventures this weekend. Our Uber driver he had our Uber drive I'm glad our Uber driver could drive safely with how hard our Uber driver was laughing when we were hearing about shenanigans on the car. And as I was arguing with him to tell the story correctly. So many shenanigans. Okay. Anyway, SharePoint. For real. SharePoint. Do you feel overwhelmed by trying to manage your Office three sixty five environment? Are you facing unexpected issues that disrupt your company's productivity? Intelligink is here to help. Much like you take your car to the mechanic that has specialized knowledge on how to best keep your car running, Intelligent helps you with your Microsoft cloud environment because that's their expertise. Intelligent keeps up with the latest updates in the Microsoft cloud to help keep your business running smoothly and ahead of the curve. Whether you are a small organization with just a few users up to an organization of several thousand employees, they want to partner with you to implement and administer your Microsoft cloud technology. Visit them at inteliginc.com/podcast. That's intelligink.com/podcast for more information or to schedule a thirty minute call to get started with them today. Remember, Intelligink focuses on the Microsoft cloud so you can focus on your business. So that was flows in SharePoint. Another one we talked about, this is interesting. We're gonna go to another it's a pre AI topic that keeps coming up over and over again. Mhmm. I've had this conversation at least twice this week at a security conference Mhmm. And you and I were talking about it. You've had experience with this SharePoint and file shares Mhmm. And syncing Mhmm. And migrations and MSPs that are trying to Yes. Do file syncs for their clients and treat it like it's still a file share. Yes. And we've talked about this. I know we've had at least one. We've probably had two or three episodes already on the podcast about it, but we've been going for nine years and people still don't seem to get the message. So we're gonna talk about this again. Alright. I'm gonna get I'm gonna beat this horse and hopefully it doesn't end me up in jail. It'll probably end up in a co pilot. No. Anti AI. No AI. No co pilot. No co pilot. Okay. SharePoint lists. Yep. What has your experience been guidance from you. Scott and I have beat this horse. It's time for somebody else to beat the horse. Alright. SharePoint lists are just Library. Libraries. SharePoint libraries. Files. Syncing. Because, I mean, SharePoint is really just SharePoint's third listception. Okay. True. So we could phrase those lists, but technically, you can't sync a list. Well, you can't sync a list that's not a library. You can't sync a list to a library, but you can sync a list to an Excel. Oh. We could talk about that too. Mhmm. Have you done much with syncing list to Excel? Uh-huh. Does it still work? I don't know if it still works, but it definitely did work when I was doing it. Okay. Talk to me about your SharePoint syncing list to Excel. So it's one of these things where what is it? You you still have to so it's in the trust center where, like, you can turn on and off, like, macros, but it's not a macro per se. No. It's like whether hey, this is connected. Do you really wanna do this? Yep. It's an o date. Was it o date of queries? I think it was o date of queries. Yes. You're like But you could turn it on and off. Yeah. And then even if that didn't work, you could still use Power Query within Excel to access the list and generate the data in Excel, which is why I had so many issues with people like, no, I can't use like, all of my Excel data lives in it's I can't put it on SharePoint because then it doesn't sync. And then it I get so many problems with trying to access this because it says it wants to get into a local file share and I can't access and it's like, well, if you put it in SharePoint Mhmm. You can either put it in a list, like export it from Excel into a list Yep. Or put the file in a document library, and you can sync it from there and make sure you change every single location that you're pointing it to every other workbook that you're pointing to. And that is no longer listed in a file share because now it's all in SharePoint. And I I had one client, bless his heart, 62 Excel files that he would create every single year in order to manage all of the financials for his organization. Were they all linked together too? Every single one of them with macros, all point like, trying to open up one Excel, that took some patience. Because it's like, it would go to load, and then it was, like, waiting to connect to SharePoint. And then it was just spinning and spinning, and it's like, well, how's the kids? How are things going? Eventually, it would load. It opened. So did you help him get that into a SharePoint list? No. I ended up not getting the project because when we quoted them for how I was like, it's really not gonna cost that much for us to do it. But you're trying to make me put a number on it. And they almost croaked at the number Okay. Because they wanted everything moved for the last twenty years. Oh. Yeah. And And I was like, yo, that's not gonna be so whoever they end did end up going with, I was like, you undersold it, first of all. You did not think this went all the way through. Or there were lots of change orders. There had to have been. Happened before too. It had to have been. But, like, the guy so they call me a wizard. I don't call myself a wizard. I just ran with it. Okay. Like, they they told me, you're gonna get into tech. You're gonna need a name. And I was like, I don't know. Like, I don't know. Everybody just calls me a wizard. That's Whatever. You're a wizard cat. That's my name. But this guy was the CFO for his organization. He's Okay. The only one who touched this Excel document because he had to change it every year. He was very particular about this, like, to the point that the person who was supposed to be coming in after him when he retired Uh-huh. He wouldn't even share the password to get into the macros with her made her leave the room so that he could tell me by writing it on a piece of paper and showing me the camera showing it to the camera so that I could get into it and I could see what the macros were doing. I mean, at least he was security conscious and he wasn't. Trying to be Yeah. Very much. But I sat on a call I sat on two different calls with him for a grand total about six hours Okay. Where he explained the entire process The process of, oh, wow. Of this is what we have to do every year at the beginning of the year. This is what happens. This is where all the changes are made. Every quarter, we have to do this. We have to create this whole financial book. This all has to get printed out in very specific ways so that it can be then given to the CEO, and then all these decisions can be and it was six, six and a half hours straight, beginning to end. At one point in time, I was like, thank God we are able to record this, and I can get, like, transcripts, because there's no way I would have been able to do this. But after the first, like, two hour session that I had with him, of him just, like, explaining everything, and we went to go meet for the second session, and I was like, this is what I understood from the first session. He was like, yes. I'm supposed to retire in six months. Absolutely. I believe 100% without a doubt, if anything was to happen, that you guys could do it because you have the person there who understands it. And I was like, Excel is my jam, man. Like, I could fix this for you. Like, I re that was my biggest problem working at an MSP Okay. Was seeing people struggling with their Excels and being like, I could fix this for you right now. Like, I could make your life so much easier for you right now, and it would take me less than ten minutes. Like, can we please please stop hurting yourself? Yeah. Can I give you years back on your life? So yeah. No. I enjoy that work. But So what else did you do with SharePoint lists and Excel? Did you I did everything with them. I tried to get everybody off of using Excel. Okay. If you could use SharePoint and lists and you didn't want everybody to have access to every single list item Uh-huh. Like, I don't I can only share this much of this Excel with you, or I'm gonna have to split it up into six different Excels so they can share the information that's relevant from this one with that person, and this one with that person. Like, I was like, why why do that? Put it in a list. Yeah. You can provide individual permissions, and you can say, oh, hey. This is supposed to be for financial, and this is supposed to be for HR. Excuse me. That was a burp. You can check that out. I had a lot of Coke today. And cola. Coca cola. Pop. Yes. I'm from Michigan. It's pop. I'm from Florida. It's Coca Cola. It's No. I would try to get them off of it because I'm like, it's so much easier to manage your permissions using Flow. As long as you set the logic, it's not that difficult. Yep. And I was like, if it's gonna be, oh, I only need these three people to have access to it, you can either put a group together and put those three people in it and assign that group. Or if it's just, hey, this one time, I just need these people to have access to it, put them in a people picker field, give them the permission, and when they're not in the people picker field, take it away. Take it away and remove their permissions. Yeah. Like, I was using Flow to manage permissions all the time. Flow. Power automate. But it was Flow when you did it? I think it Probably? It was, like, right around the time between Flow and Power Automate name change. Okay. So it was I was, like, I don't understand why they called it Power Automate, but okay. And then it was like, oh, there's a Power Platform and everything's gonna be Power. And we've got Power Automate and Power Apps and Power BI. And then they're gonna take Power BI off the Chrome. Marketing had to justify their Yeah. Marketing needs to their existence. Every six months. Oh. So So the other one with an MSP. Yeah. Going back to syncing, OneDrive syncing. Mhmm. File syncing. Yep. Like, this is one that I Again, pre AI it's a problem. Post AI it's a problem. AI does nothing to help with this. Nope, absolutely not. And it just continues to be a problem is, I'm guessing with an MSP, you saw it as well, you go in and people are like, we need to migrate file shares to SharePoint because we're done with file shares. And they like take their entire file share and say And dump it in home. It's going in this SharePoint site and then everybody can sync it and life will be dandy because we don't have a file share and it's all in SharePoint. And then they wanted to immediately sync back to it so that everybody could access it? Yeah. They're like, why is this taking eight hours to sync back? Or why isn't everything staying updated? That's like, well, you understand there's a fundamental difference here between SharePoint and between file shares. Like, file shares, you're actually accessing it on the file share. SharePoint, you're doing it locally and syncing it. And if you try to sync 590,000 files, one, I'm surprised it would even work. And if it does, it will take hours to keep everything up to date. I might have had a client. I might have had a client who had 74 layers of files or seventy seventy four Folders? Folders. They didn't hit the, like, name blank. No. A whole whole whole whole whole whole whole whole whole whole whole, please. Okay. I'll be patient. 74 levels of folders in their document library. Okay. And there were over 672,000 files that were in here. And every time they would go to move a file in there, it would take forever for it to go or it would stop. Uh-huh. And then they were trying to automate this using Power Automate and not understanding why the flow would break. Oh my. And I was like, first of all, oh my god. Second of all, oh my god. Third of all, that's never going to work in a million years. Like, there's a limit on how deep you can go because there's a limit on the number of characters that are allowed. And 74 of those characters are already used by forward slashes. Wow. Which is also where I found out, don't use spaces. Dear God, do not put spaces Don't use in your folders. No. It's I feel like it they've done something. It's gotten a little bit better. Maybe? Maybe. I still don't like folders or spaces and folders. What was I gonna say about that? There was something else. Moving files I don't know. It's gone. I had something I was thinking of that I was gonna relate that to. Yeah. I don't know. Yeah. No. That was a fun project. I was like, you you guys do know that you don't need folders in order to store your files. Right? Like, you can have actual, like, views Like, yeah. Set up. And then we can set up filters because the first level was all of their clients, and then the next level was individual folders that they needed for those clients. And then it was like, well, this is for quarter one, and this is for quarter two, and this is for quarter three. And then it was just Got it. It was years and years of data. And I was like, oh, this is gonna be fun. And then Microsoft came up with channels and teams that created folders, and I said, I give up. I can't keep telling people to stop creating folders because Microsoft says to stop creating folders. And then they create folders. When they create folders and channels, they're like, it's a losing battle. Go create folders to your hard content. Oh, I remember what I was gonna ask. Okay. So have you ever seen this when you start getting that many files and folders? And I feel like I've seen this a couple times where, like, two people will sync it. Mhmm. One person will go to move it. And because it takes so long to sync, the other person's computer back in there. Gets confused and, like, puts it back as people are moving it out, and you end up with Multiple No. Multiple copies because it takes so long to sync that the two OneDrive clients on the two different computers That's awful. Lose track of what's going on. That's so awful. Like, this user will put I think this is the other one I've seen. User a will like add files to the folder. Mhmm. User b takes takes like the whole folder And while user a is still waiting to synchronize, so then user a recreates the folder and puts the new files in it. So now you have not duplicate files, but you have duplicate folders In different places. In different files. Yeah. User b is like, I'm missing files that user a was supposed to add and user a is like, where'd all the files go that were supposed to be in this folder that I added these other ones to? Oh. And then it's turned into a massive confusion and it's one of those things where it's, again, beating this horse of SharePoint is not a file share. Please, I get you want your users to feel comfortable with SharePoint and OneDrive and syncing and all that, but don't try to make OneDrive a file share. Yeah. No. What I have found really helpful is Power BI use with SharePoint. Okay. Because I can point a URL, like, in Power Query and Power BI to a document, like, a document library URL. Okay. And then I can see all of my files in that library. Like, I can break it down. Oh, because it flattens them all out? It flattens the whole thing. And so then you can see, oh, hey. Well, here's this file in this folder, and here's the same file in this other folder. But if you look at the URL for where these files are at, you can see there's a big difference in the URL length and how this is all set. It's fantastic. I haven't tried that yet. Dude, I 100% guarantee it's, like, mind blowing. When you get in there, you're like, this is beautiful. It's blowing my end right now. I'm gonna have to go try this. You should There are so many things that I've done with Power BI and that you probably should not have ever done or be able to do. But, like, I use Power BI to unzip files from Okay. Yeah. Explain. Okay. So I actually started on this project for PowerApps and Canvas apps Okay. Where I wanted to know the in internal guts of what was in a Canvas app. But when you export it, it comes out as an MS app file. Yep. Dot MS app. Well, inside the dot MS app file, like any other Microsoft file that is created, is a bunch of XML files and JSON files and all of that. So, like, if you change the extension of the file to dot zip and unzip it, you can now see all of the internal guts and glory. And so there are different tools that are out there. I think I found it somebody had it on GitHub, I think, for how do you decompress a file using Power BI. Okay. And so I have gone in and I've fiddled with that myself. Okay. And I've made it so that I can point it to a document library in OneDrive. Okay. And I can unzip every single file that is in that document library and see the internal contents of this file, so that I can then verify what's in the file, where it should be, how it's supposed to be set, like Can you actually unzip it too and have it go back to SharePoint as an unzipped file? Well, no. Because Power Query doesn't actually physically Doesn't go right back. You can actually do the reporting or the Yeah. Look at it. Yeah. So like if there was a like an Excel file, say, that's got a whole bunch of financial data in it, and you have another Excel file and another SharePoint list somewhere or SharePoint document library with some other financial data in it, and you wanted to compare the two, you could pull it into Power Query, Power BI, and and validate. And compare. Yeah. And never actually physically touch the files. To say, I have never done this. I'm gonna have to go start playing with it. This might be part of the reason why they call me a wizard. No. Because I find all these little hacks that nobody thinks about. Did you know you could do that with have you ever done that to an office document too? Change the name to that zip? Yeah. It's fascinating. Office document, Excel document, PowerPoint documents, every single one of them, even Power BI files. Are just zip files? Every single one of them is zip file. Everything after Office 2007. Yes. The when they added the x to the document extension. Yeah. Yep. Even the template files and everything is great. Very cool. It's how I wanted to start building crap. I'm like, oh, I can just change it to to dot zip and unpack it, and then I can just put whatever I want in it and zip it back up and change the extension to whatever it is. Just randomly tried it now with every file you get is just change it to dot zip to see what happens. Yep. A 100%. I've actually saved my bacon before because I was working on a Power BI report. Okay. I accidentally made a change in which it froze the whole thing up, and I forgot to save after working on this for twelve hours. Oh, no. Thank god I always turn on the auto save part. Yep. But then I tried to open up the backup file Okay. And it had saved it with the error in place so that it was frozen as soon as it opened. Oh. And I was like, oh, no. This is not good. Because the number of power query, like, changes that I had made Twelve hours worth. I was never going to remember exactly how I had done it. Yeah. And I was like, oh, wait. I can change this file to dot zip, and I can open it up and look at it in Versus Code, and I can get all of the Power Query Okay. Out of there and make sure that I change the one specific part that was freezing everything. No. You can't. Yes. You can. No Power Query. It's John. It's John. Very stupid. No. It is not. Blah blah blah. It is the Let's go do some KQL over at it. Christ. I talked about KQL earlier. I do? Yeah. You have to talk really loud, John, so you get picked up on the mic for the podcast. Oh, you're on a podcast? Yeah. Now you are too. Nice. We just got joined by John the mastermind behind the workplace ninjas conference. As you get all the feedback from my microphone. Hello. Just like I told him at the MVP summit, the only person that you have to learn KQL are people who do defender are, like, Nathan McNulty. Making everybody else learn it is cruel and evil. Now I'm gonna go away. You're gonna go away. Alright. Thanks, John. Can't wait for are we allowed to talk about next year? We are announcing Is it public? At 05:30PM, we are announcing the 2027 date and venue. Okay. So this podcast will come out after that, so we will talk about it. You can announce the fact that it is going to be at the Scott And Scottsdale The Scott? Next week of February Okay. 2027. The Scott And Scottsdale, last week, 2027. You should absolutely come and accidentally go out. Go out at night. Enjoy all the shenanigans at which 100% shenanigans. This is I don't know as many people at this conference as when I go to some of the other ones. Mhmm. This is by far the most fun I have ever had at a conference. To be fair, I found out today that I'm royalty. I did not know this. You're not only a wizard, but you're royalty. I'm apparently royalty. I'm MVP royalty, and I did not know this. Like, some of Congratulations. Yeah. I so, Ramona g Oh, yeah. I know. Ramona's awesome. Yeah. So I went down to her session before and, like, I only met her through WhatsApp chat, like, a few weeks ago. Okay. Two months ago, something like that. And I walked into her session and there's, like, there's a handful of people or whatever because they put her out in the middle of nowhere land like they did to me yesterday. I'm sorry. And definitely did not complain to John about that several times with a number of expletives. And so That never would have imagined. I went walked into her session, and she got, like, got all super excited and whatnot. And then, like, at at the end of her session, like, my friend, he wanted me to come introduce, like, him to her. He's like, she's fantastic. And I was like Is this the same friend that accidentally goes out? This is a different friend? Okay. And so he's like, you need to come introduce me. And I was like, I'm pretty sure she knows me, but sure. I'll come down there and I'll make an introduction. And so at the end, he, like, he jumps up and he's like, hey, I'm gonna do and so I was like, okay. Okay. And she's like, yeah. This is royalty right here. And I was like, what? This is the fun part. We just get random people stopping that. Yeah. Yeah. John I thought you were just shooting the shit now because No. This is that's the fun part of the podcast. Here's this is random Yeah. Just into the Lindsay came to say hi. We have Lindsay. We have Lindsay Shelton here from Epic with a q. So and Lindsay is epic. She is epic. She works at Epic and is epic. Exactly. Except I know how to spell epic. Oh my. But I love my work, I love my employer. Alright. Yes. In case they'll send to this case later. We'll make sure that is noted and Yes. Acknowledged. Alright. But we should probably wrap up. I don't even know how long we've been recording for. Anything else that's anti AI that we wanted? We did well for anti AI. We did. A little I mean off the wall on everything. I did mention CoPilot once, but, you know, I feel like that you have to as an MVP for anything that you're speaking at least mention it one time. It's yeah. It's an obligation. I think we signed something that says It's actually obligated. Time we talk, we will mention Copilot at least once. So I think we have done our contractual obligation. Well, thanks, guys. This was a lot of fun. It was. I will put links in the show notes to anybody that wants to meet Kat, the royal wizard. The royal wizard. You need a new handle. Half the royal wizard. I've added a dinosaur to my LinkedIn name. Now, like, what more can you ask? Perfect. Alright. Well, thank you so much. This was a lot of fun. Yeah. And we will have to do it again sometime. Yes. For sure. Alright. Alright. Thanks, Kat. We'll talk to you later. K. Bye. If you enjoyed the podcast, go leave us a five star rating in iTunes. It helps to get the word out so more IT pros can learn about Office three sixty five and Azure. If you have any questions you want us to address on the show, or feedback about the show, feel free to reach out via our website, Twitter, or Facebook. Thanks again for listening, and have a great day.
Donate
Share
Apps
Menu
Microsoft Cloud IT Pro Podcast
Open in new window Display Menu
Episode 418 – An Anti-AI Adventure with Cat Schneider: SharePoint, Power Automate, and Conference Shenanigans
|
Back 15 seconds Forward 15 seconds Play Speed CC
Podcast: Play in new window | Download (Duration: 38:20 — 26.4MB)
Welcome to Episode 418 of the Microsoft Cloud IT Pro Podcast. In this episode, Ben sits down with Cat Schneider during a lively conference to discuss a variety of topics, focusing on the theme of “anti-AI.” They reflect on life and technology before AI became prominent, sharing tales of conferences, hackathons, and explorations of older tech solutions. They also discuss some of Cat’s adventures in SharePoint and Power Platform, including managing SharePoint permissions with flows, the challenges of migrating file shares to SharePoint, syncing issues with OneDrive, and practical uses of Power BI for troubleshooting and managing SharePoint data. Additionally, they dive into humorous conference anecdotes from the inaugural Workplace Ninjas US, including accidental late-night adventures.
Cat Schneider is an experienced data specialist and Power Platform, SharePoint, and Teams enthusiast with a demonstrated history of innovation for almost 15 years in the public sector. Cat is skilled in Microsoft-based applications, quality assurance, and databases. She is a strong community and social services professional with a Bachelor of Science (B.S.) in Biology from Florida State University. In addition to being a self-taught coder with a never-ending thirst for learning more—and helping others learn and improve their coding skills—she is also co-leader of the Power Platform UX/UI and Accessibility (A11y) Global User Group.
Your support makes this show possible! Please consider becoming a premium member for access to live shows and more. Check out our membership options.
Buy us a Coffee
Name
FirstLast
Product Name
Small - $2.00Medium - $3.50Large - $5.00
Total
Payment Method
PayPal CheckoutCredit Card
MasterCard
Visa
Supported Credit Cards: MasterCard, Visa
Credit Card Number
expiration-monthexpiration-yearcvv
Card Number Expiration Date
Expiration Date CVV
Security CodeCardholder Name
×
Contact Us
Contact Us
Contact Form
This field is for validation purposes and should be left unchanged.
First Name
Question or Comment
Add me to the mailing list
Signup to be notified when new podcasts are published, participate in listener surveys and give input into future episodes!
Sign me up!!
This field is hidden when viewing the form
Tags
Checking your Browser…
Verify you are human
Verifying...
Stuck? Troubleshoot
Success!
Verification failed
Verification expired
Verification expired
×
Microsoft Cloud IT Pro Podcast
Episode 429: Getting started with LLM Wikis
Microsoft Cloud IT Pro PodcastMicrosoft Cloud IT Pro Podcast
Episode 429: Getting started with LLM WikisEpisode 429: Getting started with LLM Wikis
More
Speed: 50%Speed: 75%Speed: NormalSpeed: 125%Speed: 150%Speed: 175%Speed: DoubleSpeed: Triple
Back 15 seconds
Forward 60 seconds
More
more
Speed: 50%Speed: 75%Speed: NormalSpeed: 125%Speed: 150%Speed: 175%Speed: DoubleSpeed: Triple
Back 15 seconds
Forward 60 seconds
Currently Playing
More
Notifications
PayPal