## [Episode 380 – The future of AD FS is cloudy](/content/episode380/index.html)

by [Ben](/content/author/benmsclouditpro/ "Posts by Ben"/index.html) \| Jul 18, 2024 \| [Podcast](/content/category/podcast/index.html)

Blubrry Player

\|

Auto Scroll

[+](https://player.blubrry.com/?podcast_id=133277544&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE380.mp3&modern=1# "Close Transcription Overlay")

Welcome to episode 380 of the Microsoft It pro podcast recorded live on 07/12/2024. This is a show about Microsoft 3 65 in Azure from the spec to of It pros and end users, where we discuss the topic or recent news and how it relates to you. With the recent news about the At and T data breach or data league we start, top off talking a bit about security identity protection into recent security alert in Ben's Microsoft 3 65 tenant. Then staying along the lines of security, we discussed the recently released Ad ass migration tool in some of our thoughts around migrating from Ad fast to Microsoft Enter Id. Wow. It's a Friday. Scott. It is... Run the right microphones phones for recording, I'm using the right camera, And if you're on At and T your data has been stolen. If you're on any United States carrier, date has been stolen and at some point. Heck, if you live in the Us, actually, I think if you live anywhere in the world at this point, your data has been stolen. Yeah. I saw 1 the other day it was, like, the largest credential dump is floating around, like the Dark web and it's, like billions of records. Have you had this issue? I've had this issue in Teams. Then we'll go back to At and T where it just randomly switches to a different audio source while you're using Teams. Is that what just happened? I don't know. Like, my speaker went from my ding to my speakers. Which was weird. Got it. Anyways, Okay. So back to At and T, Yeah. I can't remember if we talked about this or at this somewhere where realistically, you should operate on the assumption that your data has been stolen versus that you're trying to protect your data at this point in time. So there is another article this week. I'll pop a link in the the chat and Show notes for everybody. So the largest password database leak was also this week. So that was 9 point 948 million unique plain text passwords. Wow. Released by the threat actor dubbed Obamacare as part of the ro 20 24 dot TXT file. Can't make that stuff up. So creative. It's wild. This 1. I don't know did you see this At and T 1. Apparently it came from snowflake. So I'm curious to see more too if this was, like, At and T cr that were compromised to get into snowflake kinda like did they go through At and T to get to snowflake? Or was there a breach in snowflake? Because there been a bunch of stolen records that have come out of Snowflake. This article talked about... Who was it ticket master lending tree and some others that have all data stolen from snowflake specifically. So it's, like, was there issue. Snowflake. I don't know. It doesn't it doesn't really say, but a hundred and 10000000 At and T customers and it was, like, not just their information, but who they texted in who they called. So it was records of who called who who texted who didn't contain time date or the data of those, but still being able to draw a bunch of connections between different people based on who they're calling and texting. This is not an insignificant breach. No. It's not. So snowflake had a breach over the summer. And, like okay I guess, we're still in summer so. So this summer. It's snowflake kinda a breach. There there were, like, a hundred plus customers that were potentially leaked out in that breach, and, if I'm remembering great, it was actually, like, an ex campaign that kinda brought it all to bear. But you'll be happy to know that as of this week, what we're July 12. What is? Today's July July 12 So as of July eleventh, Snowflake has decided to enable and enforce Mfa. Ironic that that came out the day before this did. Yeah. The, you know, the the the hits just keep on coming. I think it's a good lesson that none of us are actually in control of a lot of the data about our lives once it gets out there, you said, you kinda think about ways to mitigate that and kinda work through it. So I don't know how it works outside the Us, typically with a lot of these breaches in the Us like... And I imagine this will happen in the case of At and T, like, as a major provider with hundred million plus customers. Usually, they'll reach out, offer you some form of monitoring. So, like, for a credit card beat preach that could come in the form of credit monitoring for things like your credit score and maybe through, like Trans, or Ex ex or or some of the companies that monitor and watch that stuff could be other protections that are out there, like, I don't know. I've had, like, free ex experience and Trans, whatever premium monitoring for what feels like, the past, like, 5 years. Just because there's always another breach, and I just keep upping it for free. That makes sense. I've done identity theft insurance. So I actually went and bought identity theft insurance for, like, the entire family, and it's relatively inexpensive. I wanna say I pay, like, a hundred and 40 bucks a year or something. It's like 12 bucks a month. And they will monitor a bunch of that stuff as well so that if I didn't actually have free which. I'm like, you. I feel like, I've had free forever. But then if there is a case where, like, me or 1 of the kids or my wife or we have identity stolen, they are also will help resolve it, take care of any issues, get identities back, all of that. And again, kinda operating on the assumption that it's out there. And if it happens, it's a relatively small price to pay. Because everything I've heard that if your identity does get stolen, it can be a nightmare to get everything un entangled by yourself. Yeah. So I've never done identity theft in insurance. So last time I looked into it, and again, this could be Us specific. The insurance was very, like specific in the legal east in that they would provide you coverage, but the coverage around costs was related to the recovery process. After you've become a victim of Vice theft, it's not the recovery of funds prior, we which is a little bit weird. So say somebody spending money on a credit card for illegally for, like, the past year, and they've rung up, like, 50 k and in fraudulent purchases. The 50 k in pro fraudulent purchases isn't what's covered. What's covered is the time and the money to get that fixed. So you're still on the hook for the fraudulent service or you still need to go and work that out with your financial provider. And I couldn't find any... So so maybe you and I left to chat offline. Maybe you found a better option or maybe you found 1 that did kinda, like, work through this. But it seems to be a pretty big loophole in coverage in that, like, you're effectively still on the hook for the fraudulent purchases. It's more about, like, recovery afterwards. Which in my mind, I'm like, hey, recovery. Wouldn't does that mean covering the fraudulent purchases? It does not... I'd have to look at when this starts. The 1 I have is up to 2000000 dollars for stolen funds and expenses. So again, when that starts if it, like, is retroactive to when it was originally started or once they discover the fraud, if it's only stolen funds and expenses after you discover it, but, yeah, we can talk more about this 1. And maybe throw some links in the show notes if other people are interested. So 1 other security topic, unless you wanna talk more about identity theft and data breaches I had an interesting 1 in my Microsoft 3 65 tenant today. Actually. Are you spam again? I am still absolutely getting spam Although I finally got the first 1 to go to quarantine, I've had a crazy spam problem coming from a dot on Microsoft dot com account Neither here nor there, but this is 1, I got an alert Microsoft defender, and I'm not gonna share this 1 because of information that's in it, but essentially, I got an alert this morning that 1 of my guests users in my tenant that I had shared something with that Truth told it was like 5 or 6 years ago. So this is a lesson learned. 5 or 6 years ago that I shared I invited them to a team channel. The team channel has long. The team has gone, I think the team has gone or archived. The channels got her archived, It was for some training stuff so nothing in there, but I got an alert that I had a user account in my tenant, accessing my tenant from tour Ip address. And when it it looked in, I will say defender did a good job, like it picked it up pretty quick based on all the audit logs, like, within seconds of the first activity. And actually went in and deleted the guest user. Just remove them from my tenant cleaned it all up. I didn't even recognize the username. So first I was like, oh, who is this guest username my tenant? I did some searching figured out when I had interacted with them when I had invited them, good thing is again, It didn't have any access to anything in the tenant because everything is long since come gone. But It appears because this credential was also used like, 4 different times, and this is part of why I got picked up to 4 different times in the course of a few seconds, to access my tenant as a guest, and it looks like it was probably in teams from, like, 4 different countries. Welcome to the fund that is be being on AAA tour. Right? And Right. The layers of the onion and and how all that comes together. It's an interesting thing. So so it's funny you bring this up. We do annual security training. And part of... Well, I mean, we do it more manually. But part of the latest round of security training. Actually had a section in there that talked about guest users. And actions that we as employees need to take when we're dealing with guest users and things like teams. So it's a very manual process. Right? Like, if you finished a project, like, you said, you've done all the things. You've archived the team, you've archived the channel. Like, it turns out you actually do have to go and, like, explicitly revoke access from those users to kinda clean it all up. Feels like a great space for, like, an Is or somebody to step in. Just have, like, the tenant monitoring blah blah blah. I'm surprised Microsoft doesn't have it and, like, some kind like, built in life cycle management for guests, but a lot of the onus is still on individuals who are spinning these things up. Have the context. Like, I get why it's hard automate. You don't know. Like a guess Google dormant for 2 months, and it turns out maybe they're needed later kinda thing, whatever. Yeah. Well it's a hard problem. It feels like a sol 1 as well. May maybe an Ai could solve it for us who knows. Yep. And I haven't not done this in mind. Maybe we should do a podcast on this. They have, like, their life cycle workflows in their identity governance, and the access reviews, which I would say get close. I don't know that you could build a full life cycle workflow. Because life cycle workflows are usually more onboarding new hires group membership changes, off boarding employees, off boarding employee, off boarding employee. It doesn't look like And I've looked at these some, you can do it for guest users. Access reviews, I know you can set up for guest users that are guests of teams and groups. Where it would, like, every 3 months that essentially goes through a team in or a Microsoft 3 65 group, re really? Because that's the identity structure under the team. And you can set those up for guests and say, every so often looks roll my teams with guests and send notifications to the owners, Does this guest delete access to this team group? If not, like, by default, delete them or by default, leave them or after the owner hasn't set it for so long or responded for so long, escalated it to somebody else, but it isn't necessarily I think it falls a little short, and then it doesn't have that ability to necessarily delete the guest from your tenant. Kinda like mine was. The team was gone. An access review could cleaned them up from the team, and I think I may even manually cleaned them up from the team, but they're still stuck in intra, and even you like At Microsoft, you're not gonna have the ability to go into entrant and delete remove users. So it does have to fall to an admin. Yeah. You really need like, holistic. You almost want like all the life cycle management components to come together. So, like, life cycle for my team, life cycle for the data and the That exist in there. Life cycle for the users, all the way back down to the identity store, be it And and Id or or whatever kind of thing. Especially for like, these more, like, project driven workflows, like you really would wanna. I think, like, you know, it'd be an interesting world where you come in and you say, hey, I'm spending up a new project and that thing automatically creates a team, and it has some metadata that's says here's the start date. Here's the end date. And then once you hit the end date, if you haven't extended it, then it goes and kinda runs the machine and does all the other stuff behind it, but it says humans are bad at managing information. I've learned that very well over the course of my career, myself included. You know, sometimes you need, like, the state machine to come and kick things and move it forward and get it going. So... Tl, these things are gonna continue to happen. They'll continue to be an issue, be vigilant even in your own tenants. Yes. And I will give props to defender. It did a good job. It caught it. It deleted it, and then right from within the incident that it generated. I was able to go, I reviewed all my logs. I'm like, okay. Did this user... Is there data? This guest account accessible. It was in there? Was there data that was still shared with this guest account. Like everything came back, like, there was nothing there. For all I knew it was still the user that happened to be on a to network with his company account, and opened up teams and hit my tenant because once you're a guest, you have, like, a gazillion different teams, in your tenancy and all it does is just taking it opening up, trying to re in teams to. Yep, pop that up. But yes, Looks like have a safe, but it... It's a new 1 for me. I had not ever seen that before. So like you said, be wary with guest accounts. And their life cycle and how you manage them? Be beware with your own user accounts too. No Limited it to guests. That as well. Be wary with all the accounts. Yeah. I think people forget about guest accounts. An easy 1 to slip your mind especially when you just shared an document with 1 and didn't, like, that whole process of now they're guest accounts. I do like the 1 time passcode stuff from that perspective where there is some sharing now you can do where it doesn't create a guest account. It's just like a 1 time Act. Cisco code, you get it and that also can help with some of that. So with that, 20 minutes later, good conversation. Should we jump into our topic that we had planned for today? Jump into this 1 a little bit? You put all this work into planning. We should get to it. We should get to it. And it's still kinda released. To this. Do you feel overwhelmed by trying to manage your office 3 65 environments are you facing unexpected issues that disrupt your company's productivity? Intelligent is here to help much like you take your car to the mechanic that has specialized knowledge, how to best keep your car running, intelligent helps you with your Microsoft cloud environment because that's their expertise. Intelligent keeps up with the latest updates in the Microsoft cloud to help keep your business running smoothly and ahead of the curve. Whether you are a small organization with just a few users up to an organization several thousand employees. They want to partner with you to implement and administer your Microsoft cloud technology of Visit them at intelligent dot com slash podcast that's INTELLIGINK dot com slash podcast for more information or to schedule a 30 minute call to get started with them today. Remember intelligent jake focuses on the Microsoft cloud, so you can focus on your business. So this was an article, take from Tech nut that popped up, and it brought up an interesting conversation. It was from June 26. So this was few weeks ago now, but it's moved to the cloud or move to cloud authentication with the the Ad or active directory Federation services, migration tool. So this was an announcement that the migration tool for Ad fast, to move their apps to Microsoft Enter. Id is now generally available. They can update identity management, they announced the Efs application migration moving to public freebie back in November, all of that. We can talk about the tool, But what I think is interesting about this, Scott. And we talked about this a little bit is further down in this article, they have a diagram with Ad efs, and enter Id in highlighting limitations of not transforming to and try Id and benefits moving to Id, but then they also label Ad is the old way in try Id as the new way, and this spurred a very immediate comment on the article. Given this new tool, the age complexity, security limitations of ad fast and improve technology being available, Do you consider a road map on Ad s d fabrication? And we started talking a little bit? Or 1 about this tool but too about Ad efs and try, comparing them as 2 different ways of authentication, especially in old way in a new way, And I would say even more so that in my head, this triggers eye old way new way, but it's also... Is Microsoft saying on prem is the old way cloud is the new way versus some of these where it's... They're still providing an on prem solution. This is almost starting to say, and I think where this comment is coming from is, is the on prem identity for something like Ad efs or a lot going away and interest going to be the only way forward or there's a lot of questions, I think. Around just the way some of this was labeled. And I still have customers on Ad s 2, which makes me think about it. I don't think this is too different than what everybody's been hearing for years now. In that there's a focus on the cloud and cloud services. And, you know, it's kind of a a funny list if you go and and look at their they're framing for old way in new way, like, you could apply just about any of these benefits to any cloud solution. Over to, like, remove Ad fast from it. Right and so, like, they talk about, like the new way and the benefits. So benefits, more agile than responsive Ai future ready. Whatever. We'll throw the Ai thing out the window for a second, but more agile and responsive, sure. Like, if there's an evergreen service that's constantly being updated in the cloud, that's gonna be more responsive. That could be ent, that could be exchange that could be your toaster fridge in the corner and it's firmware, like, like, whatever it is. Right? Like, like those things. If they're running and somebody else responsible for running them in their data center. Like, they're gonna be more agile more up to date. Reduce costs and operational complexity. Again, that's not Ad efs specific. It's you're just removing the costs and the Capex and Op associated with running on prem kit. So, hey, I don't need to lease new servers. I don't need to worry about getting the latest version of that load balance or or whatever it happens to be those kinds of things. Requirements around where data is home. So you know, if you think about, like, try versus on prem. Well, on prem. Everything's gotta be an active directory. And then you go, well, Great Scott, Like, everything's gotta be an intro Id in in in the cloud. Isn't it the same. Yeah, kinda sorta of not really though because entry Id is more than 80 domain accounts. It's devices. It's this whole other world of like, constructs and personas and and types of things that exist out there. And then in the last benefit they had was eliminating vulnerable assets. I kinda put that back under the hidden costs of maintenance of on prem things. Benefit you're moving at a different pace. Somebody else is responsible for the the security and all the other things around it. So in Ad s Land, like, you're like, well, Microsoft is still responsible for the security either way, whether it's Ad efs or whether it's enter in the cloud. Yes and no. Like, they're responsible for the software, but you're responsible for deploying the software. You're responsible for deploying all the, surrounding kit on those things. Right? Because it's not just an Ad f server. It's usually multiple Ad f servers. Usually those sit behind a load balance. There's probably also, like, firewalls and Ips, Ids, things like that in in line in there that all need to be updated and configured as well. How I think it was interesting just to kinda see the framing of this. But clearly, there's a desire to, you know, shift customers away. From on prem. And then the reality is, like, once you're in enter in the cloud, like, you're probably not going back the other way either. I would agree on those benefits and how they framed it It's an interesting comparison to make and. I have started having these conversations with some of my customers that are like, we wanna start getting off of Ed efs. But I've also had conversations. I don't know that I have any customers that I've had it with that I have Ad fest today, but there is... Also still a few feature gaps. I would say between Ad ass and and try d. I don't know what all of them are because I don't do a ton with Ad ass, most of my customers that have it. I know it's there and we've done some work with it. But I do know 1 that. This is an interesting 1 that comes up over and over and over again is customers limiting the time that people can log in to a service. Like these employees are only allowed to log in between 8AM and 5PM. And there's been various requirements that make valid sense for that. It actually makes sense from a security perspective. Right? Like, some of my workers that are maybe scheduled to work a particular shift or work certain hours and should not be accessing company data outside of those hours, Some of that I've heard around need to pay them over time if they're accessing company data outside of work hours. Some of it could be a security thing. If they're on the clock, they can access data, but I don't want them logging in anywhere else when they're not at work. You could argue well you can do device join and some of that. But that's 1 that has come up a lot. And I'm like, yeah. There isn't the way to sell that right now and enter. And I do know that can be solved with Ad s. Because that's been the answer for a long time. So... Again, maybe some of these will start coming to Intro. If anybody's listening on the enter team and wants to add a new feature to Enter, you need something to add in this next fiscal year. Time bound logins to enter would be on a list of things that I've been asked about. That's an interesting 1\. So you're 1 of the few people who I've actually heard frame it as a business problem versus a security problem. So, like, if you go out and you'd look, We talked about this like, last week when we we're going it. So III was kinda looking around. I was like, you know, it's like, it makes sense. Like, why isn't it there? I can see it, like, based on the way you framed it. And everything that I saw, every time somebody asks about this, they often frame it in context of security. Where they're like, oh, this person not being able to log in at this time is more secure, or I only want admins to be able to log in into these times. Like, And from that lens, it's like, well, no. Not really. It's more like security through obscurity. Right? Because once you're in with the access rates you have, it doesn't matter if you're doing that at 12AM or 12PM, like, in is in kind of thing. Right. So from a security lens, like, yeah. It probably doesn't make a ton of sense Like, I'm I'm sure there's somebody out there who can rationalize the way into it. But, like, it's just soft to cough, Like, doesn't make a ton of sense from a security perspective. Like, it's more a a piece of business functionality. And then that actually makes it I think harder to prioritize in today's world, So, like, you know, we opened with the whole credential theft thing. So with And Microsoft being the provider of that service. Do you want them to spend time on a user nice, like, time based to access control? Or do you want them to focus on better audit logs and better restrictions and being able to catch people on to networks or the traffic from China or rogue actor, things like that. Like, most people are gonna say, like, no. I actually wanna focus on the security stuff. So that's where the time, like, continues to go and lean into. Maybe this manifests in other ways. Like, I I don't know if it ever becomes, like, a core intra thing. Maybe it shows up as you know, something inside of conditional access. Like, they used to have the configure... What were they, like, the adaptive session lifetimes and things like that. So they've had kind of ish features like this, but they're like, all almost not quite kinds of things. We'll see. And I think to thing for you to do as customers to, like, frame that out and think about it too is what's the Roi? Am I getting it out of it. You know, you're using Ad efs for this thing today, is the writing on the wall that eventually Ad efs goes away. I don't know. But Ad efs also isn't getting meaningful improvements. So at some point you're gonna kinda be left behind. And this same thing has happened with, like, Sharepoint, with exchange, with all these other things. You're just seeing it on kind of a a different timeline and potentially a different scale depending on your organization and and kinda your applications you host in your company and and the way you do business. So we'll see where it bake out. I don't know. Maybe somebody will step in at some point, like, even if Ad f goes away. I don't think the ability for ent intro to be a modern identity provider and support things like Sam off and replying parties. Like, I don't think that goes away. So maybe there's an opportunity where even like, another 1 of, like, the cloud vendors picks it up, like, say, like, an O or something like that. So if you maybe fed through O, Oracle Id, maybe, you know, say there's a theoretical world where Ad goes away. Does that mean, everybody goes to oracle Id or sale pointers. Something. I don't know. You know, we'll see. It's interesting And does that mean... I mean, I feel like almost every organization has something in the cloud But does it also mean for, like, companies that have been purely on prem if this goes away and stops being supported, something like an authentication server, You shouldn't run any software out of support for security reasons. I feel like authentication servers or maybe on another level? Kind of a important. Right. Is it gonna start pushing some companies? Dan. Like, are they gonna get some kickback? I know at 1 point in time, there was, like, this is the last version of Sharepoint on prem ever. And then there were a bunch of customers that said, can we rethink that? And low and behold we had Sharepoint. Subscription edition, I can't remember if there was even like a Sharepoint 20 19 and then Sharepoint subscription edition after that, how the timing of that worked, But I would imagine that. And again, this is not... Don't interpret this as Ad s is going away because there has been no announcements about it. But it definitely feels like it's Microsoft trying to push everybody to the cloud for authentication, which good or bad. I mean, space at Microsoft was also in the news for security stuff over the course of the last 6 months. So I don't know. Definitely an interesting discussion and I say especially if you do have an ad f server. And again, I've had these conversations already with my clients is, do you need to start thinking about... Let's enter in replacing Ad s with Ent. And they're all already in the cloud. This has already been conversations that have come up for that reason because as they've migrated work workloads to the cloud, and there are challenges that have also come up with Ad aws from their perspective where their like it probably is smart, for us to look at getting rid of our Ad f servers and migrate to given that we're already in the cloud already doing a bunch of stuff for Azure well, Azure ad with Id, all of that. But I will say, well we have a few more minutes, this also led us to this tool, I gotta find it. And I was trying to remember if I've seen this website before Scott. It is set up dot cloud dot Microsoft. And then in this tool, there is a migrate from Ad to my Microsoft and Id for identity management, and this is the website. And the sub site within the website that this blog post redirected us to where it's like a it's an interesting tool We'll put it at that. It's not necessarily a click through and go connect to my tenant, like, maybe I anticipated it was, but it's a guide where, like, on the first page, it's for all types of migrations. The following Ad scenarios can't be migrated to end. So it does start right off with certain cases and it gives you a bullet list there of, these can't be migrated to Ad s and then some stuff are on staged rollout. And if the too select to none of the scenarios apply to my org and I'm ready to move forward, then you can go to the next page, which then walks you through. It's almost like a questionnaire of, then what types of apps are using. They're using office apps, non Microsoft apps Based on those it's an conditional checkbox of Is your Ad efs implementation integrated with Microsoft Enter multi factor authentication server, which has been d by the way. And based on what you select there. So it's it's like a walk through of getting you ready for it. And then I believe once you get far enough we found it, does provide, like, some scripts you can run links out to different documentation to begin your... Some actual migration. And, again, not necessarily the tool I was thinking where it's gonna, like, do a bunch of migrations of apps for you and grab all the metadata, and copy it from your Ad f server maybe into entrance and start creating applications there and automate the migration, but walks you through I would say better than maybe the Microsoft learn documentation does around some of the steps and what you need to think about to actually manage this migration and go forward with that. Migration. I think it abstracts away just like, on the front, like some of the complexities of thinking about, like, sam assertion, Ad what are the potential, like, claim rules that need to be augmented? Like, how do I swing things? How do I roll back? Like, it's not the most. Like un complicated scenario to swing your identity from 1 side to the other and get it to where it needs to be. So it's know I think it depends on the kind of admin you are, like, hopefully, if you're maintaining Ad fast infrastructure, like, you know all this stuff and you know how to go in and like, augment claims roll with your eyes closed. If you don't, then, you know, wizards like this are kind of nice for you to keep you there. Like, maybe somebody else set it up, and it's just, like a piece of infrastructure to your portfolio. You need to go back and maintain it and get it to where it needs to be. So I kinda go both ways with it. Like, 1, it's nice to have to wizard, but the other... The reality is, like, you're gonna end up in those deep dive docks anyway. At the end of the day to get to get where you need to be. This site, the the whole setup dot cloud dot Microsoft dot thing. Set up dot cloud dot Microsoft was interesting me. Like, I never really... I mean, maybe at some point, like they announced this thing or somebody knew existed. I couldn't remember it existed or that it was out there but there's just all sorts of different kind of migration guides. They're they're all in these, like, wizard driven interfaces, right. And so it's like, weird stuff, like, configuring high mode for Microsoft edge. There's a 0 trust setup guide. You can do things by categories. So you can go in and look at like, hey. I wanna look at, like a guide for identity, which would be things like Ad cleanup, so wanna do security. You mentioned defender, like, kudos to defender, Like, hey, Guess what? There... There's a guy. There's a scenario guide in here. For defender for identity, for defender for Office 3 65, defender for cloud apps. There's a bunch of intune stuff with Md. There's per stuff for compliance. There's team stuff for collaboration and voice Right? So, like, how do you configure teams for a frontline workforce? As a guide that they they have in here. They have a bunch of employee experience stuff? Like, don't think I've ever seen engage insights goals, like, Fifa engage, insights, v insights, Vivo goals, all that stuff, like wrap together in 1 place like this, product driven guides it's a really kind of a weird site, and then it replicates some other functionality as well and potentially strange ways. So, like, 1 of the ones you and I were talking about when where we're really looking at this previously was when you do office deployments with the office deployment tool in O t, you have to create some xml to pump into your Ot t file that Xml defines configuration for your office client. Like, what are the things that I'm saw? I'm oh, I'm only gonna saw, excel and word here? And I'm gonna have this turned on. I want a 32 bit. 64 bit architecture, blah all those things. So usually, the way you would do that is there's actually an entire, like, setup and provisioning engine. That's part of the admin center, the interesting thing about the 1 that sits over here is this 1 sits outside the admin center, and you can do it all una a authenticated. Right? Just come in and spin up the Xml and get it out the other side. But then it not only gives you the Xml. It gives you a whole other set of, like, powershell scripts that are bespoke, for you to actually go and do the Odd deployment, it's really kind of a weird du thing. I don't know. But if nobody's seen it I did like, like, the wizard driven interface, the next next next, like, hey, Explain it to me as I go kind of thing, like some of that was nice. Again, It felt like... Even though it duplicated it it puts some of that in, I would say more logical order if you're brand new to it. To your point if you've been doing this for a while, I don't know. Like you and I how beneficial this really is because it does... I would say it tends to focus on a little bit more of the basic stuff. Deployed the Microsoft 3 65 apps, I didn't know look what was in there like for defender. Set up your 0 Trust security model. That 1 be interesting to walk through to see how detailed that 1 gets. Deploying configure defender for endpoint, defender for Office 3 65, analyze security posture. And like you said, some of the stuff that's in here, then you have that mixed in with die mode for edge. I don't I don't know, Scott. You know, you gotta sprinkle the legacy in there with the new stuff. It's it's it's 5. To play and configure edge with a step by step experience. Microsoft search setup guide is somehow under edge. Don't know that I would consider Microsoft search setup up got under edge, but we'll go with it. Yeah. I would say worth exploring. There's... 61 different guides in here, so it is not gonna be all inclusive. Tell me everything I need to know about deploying Microsoft 36C5? There might be couple in here that you find interesting. Preview security are the big ones, V. Yeah. There's 9 of them for Viva. C There was a bunch of. Is it insights goals, engaged that they were all there. There's 1 for Am 2 Scott, which technically isn't even a product anymore. Just in case. I mean, just in case someone's still using the upper. Yes. Which has steve engage. Just think we've engaged. Let's just rec categorize it. Yeah. So nifty tools. If you are still any D ass, you're looking to migrate. There's a click through to maybe help you, I would say to help you think through it. But given some of these, I would also say if you're on Ad ass, and especially if you're already using Ent for identity, this is probably something you wanna start thinking about doing. Or even start to think about, like, how you scope those things down and segment them to? I think... Some folks view, identity is, like, an all or nothing scenario. And, you know, so, like, all my users are in the con domain. Therefore everyone has to authenticate through 3 D efs? Well, maybe maybe not. Right? Like, you might want more security for, like, your admins and your admin accounts and maybe that actually requires, like, a different tenant with a different configuration and maybe the that stuff does go through Ad efs or it goes through some other security token service. Right? That can just sit out there as a relying party and and do what it needs to do. I live in that world for sure. I have multiple Pcs for my employer. Like, I have basically, like my prod identity. And then I have another, like, admin identity, and that's the thing that gets me into the admin stuff. But the admin stuff actually happens on, like, at this point, a dedicated machine. It flows through its own dedicated identity provider, like, all, all these different things. Like, it is truly, like, segmented. And I think that's kinda funny too. Like, that very much reminds me of, like, the old school worlds. We're like, hey, we used to have separate, like, user Ids and admin Ids and then for a while, we've... Floated back. And we said, well, why do you really need an admin id when you can just pi in and you can do all this other stuff. Right? And it turns out that III now live in a world where I still have separate Ids floated I still have to pi in, but when I pi in, I'm not only logged into my admin account, but then I'm still pi or doing, like, just in time, request or things like that. Even on that admin account for the additional layer that goes in there. It's all just very cyclical. Right? We always come back around. Yes. And then you set up different authentication or different Mfa options for your admin account that to make Mfa more secure for admin versus normal user and there's all. Kinds of things. And I've started doing some of that too. I've seen some of the security stuff, and I now have 2 accounts, my end and 1 has Pam it requires strong Mfa. My normal 1, not quite as. Not quite the same level of Mfa requirements. It's a thing. So, like, separate identities, separate devices. I saw the other day that it looks like Microsoft is position for, like, employees in China that they can only use iphones due to security threat. I saw that. So it's even coming down to potentially that point as well. Not only, like, do you have to use this identity in this thing? You also have to potentially use this device from this manufacturer, which is kind of funny as well, like, not like, funny sad, but more like, funny, like, That was come all the way back around to, like, you can use any device to access anything, and now we're into, like, oh, you must use this device kinda thing. Yeah. This was I've mean, here's a news article for it. I'm sure there's a better 1 out here because I think this came from somewhere else. But Msn... Yeah. Microsoft employees in China. Now have to use authentication apps installed exclusively on iphone devices. Part of Microsoft secure future initiative announced last year. We'll that 95 Mac reports. 9 to 5 Mac has some... It's interesting what shows up on 9 to 5 Max sometimes go with that. So interesting. Lots more always always something new to talk about with security and authentication. You know, it's... Just keep on coming. With that, I have meetings, I actually have a presentation coming up. Ironically enough. I have a presentation like 2 hours today, Scott. On Ad... Id. No. Id best practices or security best practices an Id. That is some I have to spit into like, Step 1 do Ad efs? What what which which way you lean in? No. My... Slide 1 is turn on Mfa. Slide 2 is turn on Mfa. Slide 3 is... Turn on... No. Sounds about right. Yeah. No. Mfa, secure off, or anti phishing Mfa because I have also seen a lot of... Articles recently and how actually scar easily it is to bypass, certain M mfa methods. Oh, yeah. With the can't... It's it's not it's not called man in the middle, but it's essentially a man in the middle and stealing the session token and the need for the anti phishing Mfa. So I'm dying some about anti phishing Mfa, the guest access thing I talked about reviewing guests, how long they've been in there who has access. So Can't remember. And pull up my slides. We can turn this into a future podcast topic. Maybe, adjusting authentication methods. Yeah. Limits me your admin roles, some of the Pi stuff we talked about auditing and alerting. I might bring up, like, I'm borderline, like some of the global secure access stuff, senior best practice, maybe borderline, but beneficial from a security perspective, probably. So I have way more slides that I'm gonna cover so I may kinda just pick and choose through my slides as well as I. So that's the rest of my Friday. And with that, I'll let you go enjoy your Friday. Sam like a plan. Thank you, Ben. Alright. Thank you, and we will talk to you again soon. If you enjoyed the podcast, runs go leave us a 5 star rating in itunes. It helps to get the word out so more It pros can learn about Office 3 65 in Azure. If you have any questions you want us to address on the show, or feedback about the show, feel free to reach out via our website, Twitter, or Facebook. Thanks again for listening and have a great day. On

#### Donate

[+](https://player.blubrry.com/?podcast_id=133277544&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE380.mp3&modern=1# "Close Boosts Menu")

#### Share

[+](https://player.blubrry.com/?podcast_id=133277544&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE380.mp3&modern=1#)

[**X (Twitter)**](https://twitter.com/intent/tweet?url=https%3A%2F%2Fwww.msclouditpropodcast.com%2Fepisode380%2F&amp;text=Episode+380+%E2%80%93+The+future+of+AD+FS+is+cloudy "Share on X (Twitter)")

[**Facebook**](https://www.facebook.com/share.php?u=https%3A%2F%2Fwww.msclouditpropodcast.com%2Fepisode380%2F&amp;t=Episode+380+%E2%80%93+The+future+of+AD+FS+is+cloudy "Share on Facebook")

[**LinkedIn**](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.msclouditpropodcast.com%2Fepisode380%2F "Share on LinkedIn")

#### Apps

[+](https://player.blubrry.com/?podcast_id=133277544&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE380.mp3&modern=1# "Close Apps Menu")

[**Apple Podcasts**](https://itunes.apple.com/us/podcast/microsoft-cloud-it-pro-podcast/id1226241819 "Listen on Apple Podcasts")

[**Spotify**](https://open.spotify.com/show/2W2eFQ9ddEGzKe3qdZ5Ibe "Listen on Spotify")

[**Pandora Radio**](https://www.pandora.com/podcast/microsoft-cloud-it-pro-podcast/PC:21780 "Listen on Pandora")

[**Podcast Index**](https://podcastindex.org/podcast/436629 "Listen on Podcast Index")

[**Blubrry**](https://blubrry.com/msclouditpropodcast/133277544/ "Listen on Blubrry")

#### Menu

+

[**Apps**](https://player.blubrry.com/?podcast_id=133277544&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE380.mp3&modern=1#)

[**Share**](https://player.blubrry.com/?podcast_id=133277544&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE380.mp3&modern=1#)

[**Download**](https://player.blubrry.com/?podcast_id=133277544&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE380.mp3&modern=1#)

[**Visit Podcast**](/content/site-root.html)

[**Visit Episode Page**](/content/episode380/index.html)

##### Microsoft Cloud IT Pro Podcast

[Open in new window](https://player.blubrry.com/?podcast_id=133277544&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE380.mp3&modern=1) [Display Menu](https://player.blubrry.com/?podcast_id=133277544&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE380.mp3&modern=1#)

##### Episode 380 – The future of AD FS is cloudy

\|

[Back 15 seconds](https://player.blubrry.com/?podcast_id=133277544&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE380.mp3&modern=1# "Back 15 seconds") [Forward 15 seconds](https://player.blubrry.com/?podcast_id=133277544&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE380.mp3&modern=1# "Forward 15 seconds") [Play Speed](https://player.blubrry.com/?podcast_id=133277544&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE380.mp3&modern=1# "Play Speed") CC

Podcast: [Play in new window](https://dts.podtrac.com/redirect.mp3/media.blubrry.com/msclouditpropodcast/content.blubrry.com/msclouditpropodcast/E380.mp3 "Play in new window") \| [Download](https://dts.podtrac.com/redirect.mp3/media.blubrry.com/msclouditpropodcast/content.blubrry.com/msclouditpropodcast/E380.mp3 "Download") (Duration: 42:04 — 28.9MB)

Subscribe: [Spotify](https://open.spotify.com/show/2W2eFQ9ddEGzKe3qdZ5Ibe "Subscribe on Spotify") \| [Amazon Music](https://music.amazon.com/podcasts/0db27cf8-b6a8-4145-97d0-aba960d3d145/Microsoft-Cloud-IT-Pro-Podcast "Subscribe on Amazon Music") \| [Pandora](https://www.pandora.com/podcast/microsoft-cloud-it-pro-podcast/PC:21780 "Subscribe on Pandora") \| [iHeartRadio](https://www.iheart.com/podcast/256-microsoft-cloud-it-pro-pod-31075525/ "Subscribe on iHeartRadio") \| [Email](https://subscribebyemail.com/feeds.podcastmirror.com/microsoftclouditpropodcast "Subscribe by Email") \| [RSS](https://feeds.podcastmirror.com/microsoftclouditpropodcast "Subscribe via RSS")

Welcome to Episode 380 of the Microsoft Cloud IT Pro Podcast. In this episode we discuss some of the latest security breaches that you should be on the lookout for and then we get into AD FS migrations and if you should consider it.

**Like what you hear and want to support the show? Check out our [membership options](/content/membership/index.html).** [(more…)](/content/episode380/#more-108050/index.html)

## [Episode 375 – Securing Your Digital World: An Intro to Global Secure Access](/content/episode375/index.html)

by [Scott](/content/author/scottmsclouditpro/ "Posts by Scott"/index.html) \| Apr 25, 2024 \| [Podcast](/content/category/podcast/index.html)

Blubrry Player

\|

Auto Scroll

[+](https://player.blubrry.com/?podcast_id=132324362&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE375.mp3&modern=1# "Close Transcription Overlay")

\- Welcome to episode 375 of the Microsoft Cloud IT Pro Podcast recorded live on April 19th, 2024. This is a show about Microsoft 365 and Azure from the perspective of it pros and end users where we discuss
the topic or recent news and how it relates to you. This week we'll be discussing
global secure access as part of the Microsoft Security Service Edge and how Global Secure Access
brings identity network and endpoint access. Together. Under one
service, we'll discuss some of the services that includes,
that may seem familiar to you as it relates to Defender
for cloud apps and App Proxy. We'll also talk about
some of the key features around internet access and private access, as well as the global secure access
clients for Windows and Android and the upcoming ones
to the Mac OS and iOS. We'll also talk about the benefits provided by these
services, taking advantage of the Microsoft Global wan. Join us as we take a
deep dive into the world of digital security and learn how global secure
access can help you secure your digital world. Here we go. Scott, what is
Global Secure access in preview? That's our topic for today.
Global Secure Access. .This was, have you played
with global security access? Oh, Todd's been putting out fires all day. He said, why not come put
out more fires at my house. . Alright, good
to know. Todd .Okay, what is Global
Secure Access Squirrel. Scott Squirrel. Yeah, global \- Secure Access. Yeah. So let's see. This is all about securing
your digital world, right? That's what I thought. So \- It's secure access globally is what Global secure access is. . Yeah. So this is a new feature.This one was announced
actually, was it Ignite? When did they change
the name of Azure? Adida \- Entra. That was back around the Ignite. I \- Think that was Ignite. \- And this was also the introduction of not just global Secure Access, this was also the introduction
of the introduction, a little bit of the rebrand and and pushing out of the concept
of Security Service Edge or SSE. \- Yeah. And that was all
announced in kinda since then. This is, I would say
it's been a slow role of various services within, whether you call it various
services within the Secure edge or even just global secure
access in general has kind of been a slow rollout and there's a, I would say
a halfway decent image in this overview of what it is. But essentially at a high
level global secure access goes and takes all of your endpoints,
identities, endpoints, even remote networks. So think of identifying traffic
based on the network it's on, routes it all through
this security service edge through global secure access
so that all of your traffic is routing through this
global secure access, which is a service sitting
out in the Microsoft cloud before it goes to any number of things. It could be before it goes
out to Microsoft 365 could be before it goes out to the internet, before it goes on premises to
your on premises applications or even going out to
another cloud service, whether it's AWS Google
Cloud going out to Azure. But it's a way to essentially
securely route all of that traffic wherever it goes and route it through this
service between your end points or devices and wherever
they're trying to go. \- That's a good encapsulation. I think one thing that's
missing in this picture is some of the buckets should
be a little bit bigger and maybe have sub components within them. For example, take Microsoft 365 and some of the things that are part of Microsoft 365 ish slash
intra idea ish at this point. Like conditional access. So how do you extend, you mentioned like on premises clients, so how do you extend conditional
access to on-premises clients? You need to bring those, those clients both the on-prem client and maybe the on-prem
application within the purview and the overarching boundary of entra and things like Microsoft 365 and that whole stack to put it together. 'cause ultimately what we're
doing with this service suite of services again, right? If we think about Security Service Edge or SSE, it's really comprised
of we're back to bundles and suites of things. It's combining this set of
capabilities for both internet and intranet bound network traffic and making that all play nicely together. Not just across the network but bringing in things
like conditional access. So you have an identity layer and an identity boundary plus
a network boundary plus an endpoint boundary on
your clients themselves. And we'll talk about what
some of those clients are that are out there and what's
capable for things today. So if somebody looks at this and they're like, haven't
I seen this game before? This sounds a lot like
defender for cloud apps and maybe CASB, right? For access to AWS and GCP and these external SaaS
services like Slack and Dropbox, that sounds unique to me. Intimately familiar, like how we've been down that path before. You're talking about things
like proxying connections and having, having connectivity
through a network layer back to on-premises resources, but being able to inject
an identity boundary through conditional access that sounds a lot like app
proxy connector,  and,and some of the things that go into that. So if you've been in this space
a while, you're like, yeah, something doesn't smell right here. You're absolutely right. Like
this is still under the hood. The things that you understood and and the way you understood them to be with things like defender
for Cloud x Defender for cloud apps rather
that whole CASB solution, sorry cloud access security broker and putting all that together. Things like app proxy
support through Azure AD and app proxy connectors that
guess what that's been here and and it's brought up
to snuff under this suite of products with slightly different names. But I think if you look at
the underlying architecture and the way those things
compose all the same, it's just kind of new names and potentially bringing
all these things together as a suite of services under one
banner that you can go ahead and just live a certain kind
of life through depending on what kind of life you wanna live, right? Do you want to do things like
monitor traffic externally? Do you wanna monitor traffic internally? Do you want to have uh,
those additional operational and access controls on top of things? So if you're looking in your, hey in my environment I
already do the network thing. Like I have forwarding proxies and I have all the things in place I need that protect me across the
various OSI layers on premises and my outbound traffic
and things like that. Maybe not the solution for you, but if you're looking for
more than what you get out of maybe your traditional
on-premises solutions and tight integration across
the Microsoft stack and I'm, and I'm intentional there when
I say across the Microsoft stack because it's not just
SaaS services in the Microsoft stack like M 365 or Dynamics. It's things like Azure and access to Azure and some of these other internet
connected suites of things that that exist out
there in that stack it, it marries all of those together. Puts them in a nice little bundle or bucket for you both from
a functionality perspective and from an administration perspective. \- And I would say like you mentioned the app proxy stuff, right? And the CS B stuff. I think this is not, I would go a step back from what you said where it's like bundling
those in my impression of this and from the playing I've done, it's like an entirely new process. Instead of bundling those
together, I would almost, I wanna be careful saying this because I don't want somebody
to go out and say Ben and Scott said this was V two,
this is almost, it appears to be, we'll say the appearance
from everything I've seen like a V two of app proxy and of CASB where my understanding of CASB and some of the uh, cloud app protection and the stuff that's there today relied on like the
defender endpoint, right? Because somehow the existing
cloud app security stuff had to reach into your machine and see what, what the traffic
is, where are you going, what are you visiting
all of that where instead of still using defender for endpoint for global secure access and you said we'll talk about
this, there's actually a new agent that you install
on your device for these where it's instead of like defender sitting there monitoring it, this is almost like setting up and it may even be doing similar
in the background setting up A VPN on your client devices and I feel like Defender
Endpoint was sitting off to the side watching what you were doing and sending some of that back. This is literally routing
all of your traffic through a secure VPN or secure connection through
this global secure access to do things like, and it's
probably similar to that proxy but I think more of the
CASB stuff, I don't know that I wanna say more invasive but it's watching a lot
more of that network traffic because it's routing it all through this global
secure access endpoint. So \- The CASB stuff was
invasive as well, right? It was a local agent. Your traffic absolutely passed through that thing for monitoring. I think the big difference here is it is much more VP nish at
the end of the day, right? Like you are doing a virtual
private network effectively. Yep. And the connectivity for that VPN if you think
about performance of A VPN and having to tunnel and connects through an endpoint where those endpoints sit has a big, no pun intended like network effect and knock on effect to customer experience and client latency. And I think those were
potential issues with some of the kind of traditional CASB approach and there was also just
the general, hey like what do I get out of doing this solution? So like that CASB approach
was really good for routing and monitoring for
external SaaS solutions. It wasn't good for the app proxy thing 'cause you still needed the
app proxy thing on the side. What this does with global secure access and the client, what it lets you do is it lets
you basically say, hey now that all this stuff is
under one suite of services, let me have a singular client and then I can take that client and I can affect change in client behavior by pushing traffic profiles so I can have a traffic
profile from Microsoft 365, I can have a traffic profile for my internal applications,
that kind of thing. And then it all passes
through that one agent, that VPN connection, right? Which is giving you a tunnel back to what's effectively the Microsoft wan. So this is another like
kind of thing, right? As as when I talk about like limitations of the old stuff versus the new stuff, now you're given connectivity
just straight up back to the MS WAN N which
is really interesting because Microsoft, for folks
who go out and look at the side or like their networking
geeks has a massive WAN like massive network, tons of dark fiber. If you think about the
way like Azure regions and Microsoft 365 regions
are all connected together. Like there's a ton of bandwidth and a ton of capabilities
there just within the core network, let alone all the
segments for that network and where they push out to,
especially on the edge with pops and and things like that. So you're basically
talking about like A VPN that's smart enough to locally route to the closest edge site And
an edge site could be a region, it could be a pop, but you're looking at all up 140 ish regions. So that lets you know that it's
more than just Azure, right? Because Azure has give or take \- 60 ish, right? \- I can never remember the exact number because there's all sorts of like canaries and E UAPs and things like that. Yeah, it's on the order of 60 ish, 60 to 70, something like that. But way more regions
here plus all the pops that exist out there or all
the edge sites for that wan. So 140 plus regions,
190 plus pops all ready to go kind of sitting there. So hopefully, and from
what I've seen of this uh and experienced with it,
like the knock on effects of things like client latency, they're vastly diminished
in this solution versus what I used to encounter
in the CASB world. But the cool thing is even
for app proxy connections, things like that because
now you have the VPN tunnel between your client and that edge site that can broker everything up. It can pass it through
the WAN for evaluation by being passed through
the WAN for evaluation. And this is where I was saying
that graphic maybe it wasn't the greatest thing 'cause
really you wanted like there wanted there to be like a big
circle around the whole thing. Yep. Which included stuff
like conditional access in it. So hey, how, how do I take and put conditional access in
front of an on-premises app? Have you been able to do
that in the past? Absolutely. Did it require additional functionality and was it rolled up
into a singular solution? No, not so much, right? That that, that was the friction and things that came along with it. You're picking that piece up here. This new client effectively
gives you VPN plus a traffic filter that can monitor both for internal and external bound traffic based on profiles that you can configure. And then based on the
destination of that traffic, then you get all the other
operational things on top of it that you might want like
identity and conditional access. \- This is where like when you go in and do some of those profiles,
we were looking at this the other day, now I'm
gonna have to remember where all my profile settings are. You do have those different profiles so you can go create those profiles for your internet traffic and for your Microsoft 365 traffic. And one of the interesting
things that I saw in here when you're going and setting up some of
those profiles is that it starts giving you some
additional functionality and now I'm losing all my
connectors traffic forwarding. I think that's where my profiles are. Yes. Like you can go into your
Microsoft 365 profile and set up different
policies within it too that let you go in and set up like what
exchange traffic is going. It gives you all the fully
qualified domain names, the IP subnets of your
Outlook traffic and SharePoint and OneDrive and some of your
common office applications. But this is also now because of running through
this VPN, there's options to even go in and enable a lot more logging
of your Microsoft 365 traffic. And this is one thing that's
still slowly rolling out where you can go in and
get like enhanced logging and we've talked about some of
the logs that are available. It's 'cause you enhanced
logging I think of exchange and SharePoint like teams is still coming. I'd imagine there's a bunch of other stuff still coming as well. And then for internet access web content filtering has been there for a while in Microsoft 365 and this is another one
that gets rolled in. But now with your internet
access profile, you can go into and do things like web
content filtering policies where if you wanna go in and create a policy to
block certain websites or to block different
categories of websites you can go, it brings in
that web traffic filtering that you, it's buried down within defender I think in the security center. But it brings that into here too. So you can go start
filtering that web content. And this is another one
I've had clients ask about, especially over the last few years when everybody's starting to work remotely. A lot of this used to be done
at the firewall level, right? People would've devices,
DNS, custom, DNS, all kinds of things to filter traffic. If you were internal to the network with everybody working from home three or four years ago, the number
of calls I had about help, we overloaded our VPN because we're still requiring
everybody to go to VPN for some of this functionality and it just couldn't support
6,000 people all working from home over VPN. This goes in and takes
care of a lot of that because now instead of to
your point Scott, instead of relying on your VPN or your teeny tiny WAN
setup, respective to what Microsoft's network
is, you can get a lot of that performance without
having to rely on premises VPNs or on premises networks to do a lot of this web content filtering,
advanced logging, all of that is a lot of that type
of functionality begins to roll out and come to this
global secure access. The \- Scale component is
interesting that call out to 140 plus regions and 190 edge sites, that's not just about
things like client latency, it's also about capacity
of the Microsoft WAN in, I don't know many folks
who are running, running around even in their local environments with petabytes per second of capacity. , right?  like
we're not talking gigabits asecond year, we're not
talking megabits a second, we're talking like PETA bit
scale like petabits a second and the contention issues and all the other things
that can come into play there do go away, right? Like your constraint effectively
becomes like the client and does my client have internet access? And that's a problem that you've had to solve the entire way along anyway. So that constraint really
hasn't moved around for you in a meaningful way. Some of this stuff's a little
weird to be honest with you. I don't understand why
log enrichment is tied to this client because if
you look at the logs and what event enrichment
actually means ,it's things for SharePoint
online having an event for say SharePoint for file deleted, you should already have a
file deleted event for teams. It's about having app
installed for exchange. It's about new inbox rule,
new transport rule things. There's no magic sauce there that couldn't be enabled
in the SaaS service anyway. Like it's a weird
gatekeeping kind of thing to me. But I don't know, \- I want go in and look
at more I encountered, this is another episode. They \- Published the schema
for what they enrich and watch the what they push out there. And if you look at the
enrichment schema, it's, \- Oh look at
\- This. It's not a very special thing. Like, like you, you will not be enthralled when you see that list. \- Do you feel overwhelmed by trying to manage your Office 365 environment? Are you facing unexpected issues that disrupt your company's productivity? Intelligent is here to help
much like you take your car to the mechanic that has
specialized knowledge on how to best keep your car
running intelligent helps you with your Microsoft cloud environment because that's their expertise. Intelligent keeps up with the latest updates
in the Microsoft cloud to help keep your business running smoothly and ahead of the curve. Whether you are a small organization with just a few users
up to an organization of several thousand employees,
they want to partner with you to implement and administer
your Microsoft Cloud technology, visit them at intelligent.com/podcast. That's I-N-T-E-L-L-I-G-I-N k.com/podcast for more information or to schedule a 30 minute call to get started with them today. Remember intelligent focuses
on the Microsoft cloud so you can focus on your business. So I'm wondering though
Scott, like looking through this like you said
for SharePoint, for OneDrive, file deleted file
downloaded, file recycled, those are absolutely already logged. Does this somehow give you, and this article doesn't have it, \- Why would it be
documented and tell you that \- Idea? Oh lemme talk about documentation, how I feel about it right now. Does it give you additional
details about it from the perspective of a new inbox
rule is created right now. You can see the endpoint
that it's created from. Maybe you can see the client, but does it give you not so
much, these are new activities that are logged but it's
additional information about these activities that they're able to log because it's watching the network traffic. I don't, again, it doesn't say because to your point, why
would it be documented? But it talks about enrichment
of these logs, not necessarily new logging activities. I wonder what are those additional details that you're getting when these
are enrich when these logs or these operations are enriched with data from global secure access. If \- I'm remembering right, it's
been a hot minute side looks so yeah it is additional details about the clients and things like that. It's also a little weird
the way you pump these out and this has been a moving
target as they shift around the way audit logs in general are, are manifested within the admin center. But this brings it under the same banner as things like your regular
audit logs sign-in logs, things like that where you can
pump it out to log analytics or send it to event hubs and very much like the
Azure ish diagnostic setting kind of thing. If you think about like
configuring a diagnostic setting, it's also a little bit weird and I haven't had a chance to play around with it in a mixed environment. But if you go and configure this and look to light it up, so
if you went into your tenancy, you should see this within your tenant, you should have diagnostic
logs someplace in there. I \- Don't see it. Dashboards see and this is, \- It's under identity. So go under the identity admin center. It's like monitoring and health diagnostics, something like that. \- Uh, monitoring and
health diagnostic settings. \- This looks a lot like
Azure  all of a sudden\- It is. I mean this is your
diagnostic logs from Yep, this looks like diagnostic logs essentially Diagnostic sign-in \- Logs, that's Sentinel. Yep. So go ahead and click
add diagnostic setting there. So in this experience
now you have your audit logs, you have your sign-in logs. If you scroll down towards
the bottom you have a separate log category for the enriched logs. Yeah. So with this kind of flexibility, like you could even do things
like maybe take your enrich logs versus your sign-in logs and send those off to different
log analytics workspaces. Maybe you wanna evaluate in
another one in another place like Splunk or something like that. Hey, I'm gonna send my
sign-in logs over here to this event hub and eventually
route 'em through to Splunk with my custom connector. I'm going to pump my enrich logs over to this log analytics workspace. I'm gonna send these things
over to a storage account just for archiving whatever it happens to be. You can do all those on that side. I don't know, diagnostics in M 365 continue to be confusing to me. I don't understand why they're gate kept behind additional licensing and additional features and functionality. Frankly, observability and logging should be free , right?Like I get it costs money
to store text someplace, but folks should figure,
figure that out, right? If it's a, if it's a true
value add thing, okay, if it's got enriched in it and it actually enriches the experience, sure give that to me. But if it's out of the
box, like just give it to me out of the box, right? It should be there for me ready to go. \- I have a whole nother topic
we could talk about on another podcast around this that
came up with a client around auditing exchange activities. This one was fascinating
that I did not realize, but it's absolutely going
down a different rabbit hole that has nothing to do with global \- Secure access. Write that down. All
right, we'll take a note, we'll take a note on that,
put that in the parking lot, we'll come back to it later. So anyways, so these clients, right? It is an application that gets installed that effectively deploys its
capability to do a VPN tunnel. It is Windows and Android only today. So all this stuff's in preview
like moving target preview is not production, blah blah blah. All that good stuff. For disclaimers, I think Windows clients are
probably the most interesting, the most turnkey for M
365 subscribers, right? Who are probably de deploying
things like office onto their desktops and and wanting to
track and monitor all that. So Windows, windows clients 64 bit only. If you're operating in a mode with, you've got mixed mode like enterra joined, hybrid joined devices, registered devices, all
those kinds of things. Registered devices don't
qualify today for that. And the deployment of the client requires enter ID P ones, which is another
important one to call out. So there is, it's not just hey like I need to deploy the client. Cool thing is you can deploy the client through things like we
talked about Intune for what seems like three months and in one of those Intune
reviews that we did, we talked about things
like app deployments. So you could totally push
out this through Intune and have it come down and then it gets its configuration
based on cloud service and things like that. Fairly flexible, super easy to set up. Oh, one last note on setup here. Weird one but really not that weird. It requires admin, admin access to install on Windows clients at least. And it makes sense, right? You're deploying a new VPN, you're deploying a new
network filter on top of it. So keep that in mind. So
client deployment is actually super lightweight. I think it's just lack of
support in places, right? 64 bit only doesn't support arms. 64 \- Doesn't support multi-session. This is another interesting one. If you do an A VD, it
doesn't support multi-session and it doesn't support multiple
user sessions on the same device from RDP. \- It's another limitation
that's out there. It does support Windows 365 dev box. There's no explicit callouts for supportive things like
dev box or anything like that. I imagine that it works over there. I, I'd have to spin up
a dev box to try it out. Like I, I can't think of any restriction that would be there other
than maybe a supportability but it's all preview today so support's gonna be a a
weird one for you anyway. \- And I'm running this like I'm
running it on my Windows 365 cloud PC because that's
technically a single session A VD and I think dev box would fall
into that same boat dev box for all practical purposes is a single session a VD environment. So it should work on those. I would say you mentioned
Windows and Mac or Windows and Android, Mac and iOS is coming, it is
in private preview yet. So you have to like I imagine Mac and iOS, they're maybe running
into the whole test flight limitations when you're doing
stuff in private preview for those that Apple can sometimes cap how many people you can have
in a beta test environment. So those are coming, I'm surprised they're
still in private preview. I would hope they would come out soon 'cause I want to try
it on my Mac so it is, yeah, like you said, the
client's super easy to deploy. I deployed it and then once
it's deployed you just log in with your M 365 account. So I logged my account the
other day and then I went and logged in and like I had
global secure access popup and I had to go re-authenticate with my user account
, which I guessthat one's an interesting one too Scott, because I have not tested this. Part of the point of
this is to monitor all that web traffic, but if I can sign out of global secure access,
can I essentially bypass it by signing out of my account
for global secure access or are there ways, and I haven't looked at this yet, to like block internet
traffic if you're signed out of your global secure access client, \- I've not seen a way to block it. I had a very similar question. It's weird, it's early days for this one. I, I think it is definitely
one of those like preview, not for production but play around
with IT kinds of things. It's a little weird.
It's a little strange. I do think and and the
reason we're covering it, I think it's worth getting hands on with \- Absolutely. \- It's going to be I think
a pretty turnkey capability for a segment to, or a subset of organizations
that sit out there. It's also another great example of hey, let's take the disparate pieces and parts and pull them together and
put them into one place. Like for you in in your screen share. Let's go back to the
traffic forwarding stuff \- That was tr not traffic logs. Traffic forwarding was
the connections. Yep, yep. \- So like you take a look at that like you turn on your M 365 profiles. So let's take that one as example. Go in and and and view that
one there and view my traffic. So you have these policies and the policies that you've enabled. So these are all canned, right? This was brought in just by saying hey I'm gonna bring in M 365. There was nothing you couldn't
have done here on your own other than Microsoft bundled
it all together for you. Which is nice because tracking
the IP subnets for M 365 as a service right, isn't
something you want to do uh, on your own, but there's a ton of flexibility here in the way that like this manifests
and comes together. So you could take like
SharePoint for example, say you wanna drive your exchange
traffic through the tunnel so you're set to forward now for all of those things over TCP. But if you take like your
first FQDN role like star sharepoint.com, that that wild card and bring down the dropdown,
you can actually bypass just for the FQDN, you can bypass
by IP subnet, things like that. So you can get like super
granular within these and then you have the same
set of controls for your internet bound access as well, internet and both your internet
and your private access. So it's super helpful to see
like the way like Microsoft composed the rules for M 365 and how that stuff came together and then you can think about
potentially modeling that into your own stuff. There's also the ability,
if you go back yeah, \- No though for internet, yeah. That they give you, so
they give you that option for Microsoft 365. I don't think, and this
is to your preview point that you can go in and tweak your internet access profile yet. I don't, this is tr security policies. \- I wouldn't be surprised
to see it in the future. I imagine a lot of it is
is scaling things, right? Let's say you might wanna,
you might wanna forward for, I don't know, pick a website
you might wanna forward for stuff to, to Reddit for evaluation but you might wanna
bypass for Bing, right? Just for your online searches. Like I, I think that capability will come and probably is the scale component. The other thing I should
mention with traffic forwarding, if you go back to traffic forwarding again and like the M 365 1, so you've got that linked conditional access policies. So you can link conditional
access policies to each profile as well, which is super flexible again, like it's basically making a
lot of this stuff like as much as like conditional access
policies were next exercise, this is just next .\- Yeah.
\- And done it, it simplifies that deployment model even further. \- Yep. And one of the things
that they've brought up, we haven't talked about it yet, we could probably talk
about this more, is you like with conditional access and another thing that Microsoft is
working towards with this and this can help with is, and
I've seen this come up more and more lately in
different things that Meryl, we had him on the podcast,
he created a video on it is token stealing, right? Like people creating sessions, you get the whole man
in the middle attacks that are stealing session
tokens by routing all of your traffic this way too. That can, this also goes
a long ways with helping with token stealing because you're now essentially going through this end-to-end
encrypted tunnel from your device over that VPN connection
in an encrypted manner. And I think, I can't remember
all the conditional access policies where you can essentially
say if somebody's going to connect to my Microsoft
365 applications in those conditional access policies,
they are going to have to come through global secure access so that I know they're coming
into my environment in an encrypted manner and that traffic and that interaction
is be gonna be secure. I think that's a
conditional access policy. I'm not a hundred percent sure, but that is another, I
would say benefit of this. 'cause we talked about a lot
of the logging the profiles, but a, there's that security
aspect of this as well. Yeah, \- I wanna do it as like the old, like Steve Jobs strip ,like when he introduced the iPhone, oh it's the internet plus video and, and all those kinda things. No, it's identity, it's
networking ,it's, what is it? Identity networking.
Yeah, it's networking, it's endpoint access, right? Like you put these three things together and you have uh, global secure
access, which is part of this security service Edge
S-S-S-S-S-E suite kind of thing. So it's a mouthful on the front. I would encourage folks if
you're listening to this, like just go like pop up in a
web browser and check it out. Even if you go look at the docs or you just browse through like
your admin center and M 365. This is by far one of the easier like security solutions to configure out there. Like it, it, it really is
fairly self-explanatory in what it's trying to do
and, and what's happening and there's not a ton
of machination going on. So it's super easy to
wrap your head around and then once you can do that,
I think like it does like just bring value. Like it's one of those
like self-inflicting value kind of services. \- Yep. And you will
encounter stuff that, yeah, it's preview, I think my audit
logs I go click on like audit logs and it says we're
hard at work developing this feature. Be patient \- We'll see in the future
\- .Yeah there's some IT teases functionality because the menu items are there and as you click through it you'll get, oh we're still developing this or we're still developing that. But to your point, it's what
absolutely worth playing with. Clicking on a few of the check
boxes, some of the profiles set up a couple of your test
clients to route traffic through it and it's fascinating. Traffic logs is one thing that is there. This does not go through
my production machine, but it has 28,000 connections and seven and a half thousand accesses to Microsoft 365 20,000 times
I've access to the internet. And it gives you like even
endpoints within Microsoft that you're connecting to
where I can see connections to East US or to like edge.microsoft.com. It's interesting to
just go look through it. Here's a Grammarly where
I connected a Grammarly endpoint from my Windows device. So it has got absolutely
worth turning this on and starting to play with
it for certain clients and see if it's something that, it's something I would keep an eye on and really consider rolling
out in certain cases as it comes outta preview for sure. \- So I think that takes us
through our whirlwind tour of Global Secure Access coming
to an M three, no coming to an enterra ID tenant near you. \- . Yeah. 'cause I guess
technically you don't needto do M 365 if you're just
doing Enterra and Azure. You could go get Enterra
ad premium plan one and use this for, if \- You're just doing enterra
as an identity store and AWS you could do this, right? I I I think it's about where you find the value
in it without having to be a wholesale consumer
of all Microsoft Services. That being said, if you're
doing M 365, this is a kind of like a big natural fit
kind of thing, especially for those customers who, and I imagine this is still the case. This used to be the case
when I was doing a lot of Office 365 and M 365 and customer deployments
in my consulting days. Everybody wanted a private
version of SharePoint online. Yep. . So this kind of
gives you that click stop and,and that next FU piece of
like warm fuzzies about your connectivity for your
organization and your clients and there's a whole lot of what's in it for me there versus what's in it for Microsoft, which is nice to see. Yeah, it really does
further that. Alright, \- Thanks Scott. That was a good one. Yeah,
now it is time for the weekend after a couple more meetings. \- . It's
getting there slowly but\- Surely we'll get there eventually. \- I got two more to go and
then it's off for Margaritas and CES tonight, so I'm looking
forward to that. All right, \- Go enjoy your weekend and we will talk to you again soon. All \- Right, thanks Ben. \- Thanks Scott. If you
enjoyed the podcast, go leave us a five star rating in iTunes. It helps to get the word out so more IT pros can learn
about Office 365 and Azure. If you have any questions you
want us to address on the show or feedback about the show, feel free to reach out via our website,
Twitter, or Facebook. Thanks again for listening
and have a great day.

#### Donate

[+](https://player.blubrry.com/?podcast_id=132324362&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE375.mp3&modern=1# "Close Boosts Menu")

#### Share

[+](https://player.blubrry.com/?podcast_id=132324362&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE375.mp3&modern=1#)

[**X (Twitter)**](https://twitter.com/intent/tweet?url=https%3A%2F%2Fwww.msclouditpropodcast.com%2Fepisode375%2F&amp;text=Episode+375+%E2%80%93+Securing+Your+Digital+World%3A+An+Intro+to+Global+Secure+Access "Share on X (Twitter)")

[**Facebook**](https://www.facebook.com/share.php?u=https%3A%2F%2Fwww.msclouditpropodcast.com%2Fepisode375%2F&amp;t=Episode+375+%E2%80%93+Securing+Your+Digital+World%3A+An+Intro+to+Global+Secure+Access "Share on Facebook")

[**LinkedIn**](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.msclouditpropodcast.com%2Fepisode375%2F "Share on LinkedIn")

#### Apps

[+](https://player.blubrry.com/?podcast_id=132324362&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE375.mp3&modern=1# "Close Apps Menu")

[**Apple Podcasts**](https://itunes.apple.com/us/podcast/microsoft-cloud-it-pro-podcast/id1226241819 "Listen on Apple Podcasts")

[**Spotify**](https://open.spotify.com/show/2W2eFQ9ddEGzKe3qdZ5Ibe "Listen on Spotify")

[**Pandora Radio**](https://www.pandora.com/podcast/microsoft-cloud-it-pro-podcast/PC:21780 "Listen on Pandora")

[**Podcast Index**](https://podcastindex.org/podcast/436629 "Listen on Podcast Index")

[**Blubrry**](https://blubrry.com/msclouditpropodcast/132324362/ "Listen on Blubrry")

#### Menu

+

[**Apps**](https://player.blubrry.com/?podcast_id=132324362&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE375.mp3&modern=1#)

[**Share**](https://player.blubrry.com/?podcast_id=132324362&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE375.mp3&modern=1#)

[**Download**](https://player.blubrry.com/?podcast_id=132324362&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE375.mp3&modern=1#)

[**Visit Podcast**](/content/site-root.html)

[**Visit Episode Page**](/content/episode375/index.html)

##### Microsoft Cloud IT Pro Podcast

[Open in new window](https://player.blubrry.com/?podcast_id=132324362&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE375.mp3&modern=1) [Display Menu](https://player.blubrry.com/?podcast_id=132324362&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE375.mp3&modern=1#)

##### Episode 375 – Securing Your Digital World: An Intro to Global Secure Access

\|

[Back 15 seconds](https://player.blubrry.com/?podcast_id=132324362&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE375.mp3&modern=1# "Back 15 seconds") [Forward 15 seconds](https://player.blubrry.com/?podcast_id=132324362&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE375.mp3&modern=1# "Forward 15 seconds") [Play Speed](https://player.blubrry.com/?podcast_id=132324362&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE375.mp3&modern=1# "Play Speed") CC

Podcast: [Play in new window](https://dts.podtrac.com/redirect.mp3/media.blubrry.com/msclouditpropodcast/content.blubrry.com/msclouditpropodcast/E375.mp3 "Play in new window") \| [Download](https://dts.podtrac.com/redirect.mp3/media.blubrry.com/msclouditpropodcast/content.blubrry.com/msclouditpropodcast/E375.mp3 "Download") (Duration: 37:54 — 26.1MB)

Welcome to Episode 375 of the Microsoft Cloud IT Pro Podcast, where we discuss Microsoft’s Global Secure Access offering. We explain how Global Secure Access brings identity, network, and endpoint access together under one service and how it combines with Defender for Cloud Apps and is built around the capacity of the Microsoft WAN. Join us as we take a deep dive into the world of digital security and learn how Global Secure Access can help you secure your digital world.

**Like what you hear and want to support the show? Check out our [membership options](/content/membership/index.html).** [(more…)](/content/episode375/#more-107966/index.html)

## [Episode 366 – Old Man Yells At Cloud](/content/episode366/index.html)

by [Scott](/content/author/scottmsclouditpro/ "Posts by Scott"/index.html) \| Dec 28, 2023 \| [Podcast](/content/category/podcast/index.html)

Blubrry Player

\|

Auto Scroll

[+](https://player.blubrry.com/?podcast_id=128090005&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE366.mp3&modern=1# "Close Transcription Overlay")

\- Welcome to episode 366 of the Microsoft Cloud IT Pro Podcast recorded live on December 8th, 2023. This is a show about Microsoft 365 and Azure from the perspective of it pros and end users where we
discuss a topic or recent news and how it relates to you. In this episode, we discuss
some changes to where to find us on social media. Then we dive into our technical discussion around conditional access
and break glass accounts and managing these security
aspects of Microsoft Entra. We conclude the episode
discussing native apps versus progressive web apps or PWAs and some of our recent frustrations with this trend toward those PWAs. You know, what was a mistake? \- I can tell you what my
mistake was this week. You \- Could, I don't know what my mistake was. I could tell you what
Elon Musk's mistake was. That's a long list. ,
we don't have time for that.Okay, what was your mistake this week? \- Hold on, I gotta do this joke. So Elon pulled the go f yourself thing at that conference last
week to all advertisers, like called out Bob Iger everybody, \- And then told him he
should resign, right? Yes. \- . So there's, I
am, I'm done with Twitter.I don't, I don't go on Twitter.
Like I didn't delete my account, but I deleted all
the apps, blah, blah, blah. I, I, I made you, oh, \- I didn't know you haven't deleted it. You talked about deleting
it. You have not though. \- I deleted the apps and
all that stuff. Okay. But I figured like the handles there, like they'll take it away someday. I, I don't, I don't care. Whatever. And then I made you go through and update, you know, like I just want it to be my threads handle and, and MAs it on and things like that. And neither here nor there.
So I get all my Twitter news through threads these days. So apparently there's
an account, it's called uh, fab Bit Fun. I don't know, it's some
service that's out there. I don't know what this thing is, but they ran a Twitter campaign and they called out that they are pledging an
additional a hundred thousand of X advertising in support
of its free speech ideals. And to all of you looking for a free perfect gift this holiday, we're also giving away a
free 300 plus dollars gift with your first box for new
annual X users use code. Go f yourself. Except they
spelled out F which apparently led to a slew of people
discontinuing the service  like actually
saying like, Hey, um,that might not have been
a good idea to use uh, a profanity in your like
professional account kind of thing. But yeah, so they did that
out. They ran that campaign. And much like Elon losing advertisers 'cause hey, uh, he might not be the stable
genius we all thought he was, they are also bleeding
customers from this subscription product that they have. So I thought that was kind of hilarious. There's gonna be some great case studies and great movies someday about how you can literally light
$40 billion on fire, 44 billion and just put a match to it. Yeah. Destroy people's lives. Like people who work for that company destroy a company itself. Like all that kinda stuff. Like they're, they're gonna
be talking about this crap in business school like 20
years from now . There\- Are a few documentaries I'm waiting for that's gonna be one of them. The other one is going to
be everything that went down with. Sorry, I just saw a
message that distracted me and I don't know what it was about but we'll come back to that later. I should put do not disturb
on the other one I wanna see a documentary on is everything
that happened with AI and coming and leaving
and going and coming back and firing people and all of that. There are going to be some
fabulous documentaries coming out of these last two or three months or six months  about
Twitter and about open ai.And then when the bots
take over the world, \- We haven't talked about
the whole OpenAI thing, but for those that are interested, I'll put some links in the show notes. There's an a couple of excellent other podcasts out
there that have covered it very well. Like they, they covered
it on the Vergecast and also, uh, Casey Newton and his partner in crime in
the Hard Hard Fork podcast. They did a really good job
kind of covering things. And then Casey Newton has a
interview with Sam Alton, uh, Sam Altman rather before and after , which is kind
of awkward and kind of fun.\- I have not watched that.
I should go look up that. I'll add that to my list.
That one I will add to my list and I will go do .\- Yeah, that's the one that'll get you \- There. Yep. That one will get me there. I'm from documentaries news.
I have an interesting one. Scott, I'm curious what
you think about this. I have some thoughts about this one. I have some questions about this one. And this is has, I mean I
guess that has a little bit to do with admins if you wanna
enable this in your tenant. But there is a much awaited calendaring feature coming to Outlook. The capability of keeping events you decline on your calendar. So this, yeah, this does not look like, so it's not even an admin,
it's not enabled by default. You can go into Outlook on the web or the new outlook for Windows. I don't see this for Mac oss yet. And in the settings, calendars, events and invitations, you
can go toggle an option, click a checkbox to save declined events and then once it's enabled
you can decline events and they'll still be
preserved on your calendar. Thoughts. Is this something you'll use and yeah, what do you think
about this one Scott? So \- I'm gonna use this one all the time and, and for a couple different reasons. So as a remote employee and somebody who
theoretically is responsible for a whole bunch of stuff in an what, what is an ever-growing a
massive platform, I get invited to a lot of meetings and many of those meetings can be, they end up being more
passive meetings I guess. Like I know they're gonna
be passive in that I need to be there to get the information, but I'm not an active contributor. Like I'm not driving the conversation nor am I responsible for
ultimate success, right? Like I'm part of an
outcome downstream in there and I kind of recognize
that walking into it and that being the case. I have a lot of meetings
today where I take them and I put them on my calendar
and I mark myself as a maybe and I do that very specifically so that the meeting stays on my
calendar for search history. Like I'm always going into my calendar and searching like I
remember like the title or the person I like. I wanna go back and look at it because I wanna refer to the
metadata from that meeting. Like quite often people
include, you know, agendas and attachments and things like that. But the other part of it and the other side of it is when that meeting's on your calendar, as long as you don't dump it all
the way off by saying no, you'll actually end up
with the chat in teams. And we record so many of our meetings that it's hugely beneficial to me. Like you know, as a remote
employee who is time zone, time zone disconnected
from many of my teams, I can't actually participate
live even if I wanted to. Like there is like a mission
critical meeting every week on Thursdays at 8:00 PM Sorry, that's like prime time
eight 8:00 PM local for me. Yep. So sorry like that's
prime time for me to be with my family not prioritizing work. So I don't attend that meeting. I attended it once just to see how it went and then I was like, uh, yeah you know, I really should be here
but I'm not gonna be here because it's me time. But I am a ravenous consumer because that happens on Thursdays of just picking it up Friday morning. Fridays tend to be slow days for me. It's a good time to actually
catch up on meetings and figure out what's going on. So I do that religiously
like week over week. Great Thursday meeting it runs
at 8:00 PM it's only supposed to be a half hour meeting,
it often goes over an hour.  like they just keep going.So I catch up on that recording. I wouldn't be able to do that
if I didn't have myself marked as tentative on that meeting. But what this capability lets
you do is it lets me decline the meeting like a clear
signal to the organizer and attendees and the people that are in that meeting that I ain't gonna be there. Like this is not the forum
where you're gonna find Scott, but I get all those other
additive benefits in that I can still search
for it on my calendar, I can still refer back
to the chat, I can refer to meeting recordings, all
those good kinds of things. Like in my mind the way this
composes is it actually lets me be a shadow consumer and follower of those meetings
all while setting the tone that like, yeah, sorry I'm not
an active participant if you need me I I'm around but you just gotta catch me
my time, not your time. Right? \- So do you think this will still preserve those team chats and stuff? I guess it's one thing that's
like not called out I would assume because you still have the event, you could still like open it up and get to the join link
to go find it in teams after the fact or see the recording for \- Meetings that you still
have on your calendar. Like because this persists across Outlook and teams like, you know, you have like the calendar tab in teams, you just go click on the event
and then the chat tabs there and then once you're in the
chat tab you can see all the other tabs like meeting recaps and all those other kinds of things. Which let me tell you like the
meeting recap stuff getting way, way, way better to the
point where like I record and transcribe all my meetings now because I'm kind of becoming dependent on the AI summarization
of the transcriptions. Like that stuff works really,
really, really well. I think \- That's one area where AI,
from my perspective, not to go too far down it
is the AI path again, but AI is getting really
good is that some of that summarization stuff it, I'm still not sold on it
coming up with net new. But I agree some of the
summarization stuff is getting good and I need to remember to
record more of my meetings. I am still not like that's
a habit I need to develop of always. First thing, hey, do you mind
if we record this meeting, click record so I can
have all of that stuff. Aside from that, I'm really curious to try this declined events too. I'm sort of in the same boat
as you of some of these. I want to go back and see
later or see the chat for, but I actually have a
bunch, so I get a bunch of meetings related to like MVP stuff that pop up on my calendar
and I'm the same as you. I always click tentative 'cause I'm like I don't know what's going on. I don't know if I'm gonna be there or not. Some of 'em are all just random time zones but maybe I want to go
catch up on stuff later. All of that. So I have a
gazillion like tentative meetings on my calendar. But for me, my problem that I, I just realized this
recently, I use Savvy Cal, it's very similar to Calendly for people to schedule meetings with me and it looks at all of my
different calendars including my work one, a few other
ones where I contract and it gives people my availability. Tentative meetings still show me as busy and end up blocking off my time on these other services
on Savvy Caller Calendly. So I'm similar to you is that I'm hoping declined in. 'cause now I manually go through and I'm like flip it to free
so that if someone wants to meet with me at that time, 'cause they're more important. That's \- Another part of it. Yeah, is like free busy management, right? \- Like I'm hoping
Declined shows me as free and not as busy even though
it still shows on my calendar. So I think that's where I might
use declined more is a lot of these, again these types of meetings, it's more FYI if you
wanna show up, this is what we're gonna talk about today. So whether I decline or tentative or accept, nobody really cares. 99% of these, they don't even have the
auto responses turned on. So it's not even like
people are getting emails about what you did about it. So I think that's where
I'm looking forward to it is just decline 'em,
decline 'em, decline 'em. So my calendar shows free
but I can still see 'em there and go attend them if I want to. I \- Guess just a point of clarification, some folks in the chat
are kinda saying like, hey why can't there maybe
another status like declined but keep informed or declined and kept on calendar
or something like that. Just, just to be clear with kind of the way this one manifests, it's you're declining the meeting so this organizer is getting a decline. You're picking whether it
stays on your calendar or not. So it's a meeting by
meeting kind of thing. Like all meetings you decline don't have to stay on your calendar
in this kind of model as it manifests for itself. It's kind of disappointing to me that it requires the outlook on the web or the new Monarch client
I have you played around with the new Monarch client yet? \- No, I sit in a Mac all day. I think I do have a VM
where I turned it on, but I honestly can't remember. I don't spend enough time in
Outlook on Windows that I, I won't lie, I don't pay that close of attention to Outlook on Windows. \- I live in the Monarch line
on Windows day in day out. It's pretty much trash
. I don't like it.Like I'm, I'm like old
man get off my lawn kind of thing when it comes to it. It's got some really weird behaviors. So when I ran into today, I seem to run into like some weird new
education Monarch every day. Uhhuh . It's
very opinionated about being aquote unquote like cloud product. Like it knows it's a web app and it knows it's a glorified
web app on the desktop too. I, I hadn't run into this one yet because so many of the things
I do like we share like links to artifacts like Word documents, anything,
PDFs, stuff like that. They all come out of like
OneDrive or a SharePoint site. And I was doing something
with somebody yesterday and they sent me, uh, for the first time in a
long time I got an actual attachment, like not a cloud attachment but an attachment attachment, okay. And it came through in the Monarch client. And so I said I wanna double
click that and open it up. It was a Word document. Simple, right? Like, 'cause when you're in Outlook and you double click on an attachment, it just opens locally on your desktop. Like it goes to attempt, download,
location, blah blah blah. Opens up no friction, Uhuh not in Monarch. 'cause Monarch doesn't even know that it has separate windows, right? So it pops up the little pop-up window, the word doc doesn't render
and then it says open, but it doesn't say open locally,
it says open in OneDrive. So then what it does is you click open, it pops up another window and now that window is basically a web browser at that point, right? 'cause it's all just a
view into a web browser. So then you know how
if you have, you know, like Chrome Edge whatever
it is not configured to automatically go to a website, it pops up the little dialogue and says, you know, are you sure you wanna open this on the web? Yeah blah blah blah. So all I get is that little dialogue in
a blank white window. And I'm like how is it even
opening it in OneDrive? Like what's it doing?
It's taking the attachment and it's storing it random
location in my OneDrive and then it's opening
there in Word on the web and it's like it did all the things that I did not want it to do. All I wanted to do was
double click an attachment and have it open in my desktop client and it did every single
thing it could to ingest that data into OneDrive, which I did not want, nor did I need. 'cause now I gotta go find
it and clean it up later. And also everything it can do not to open that document in a local browser, which is like the very first setting that I set in all my office clients.  is open everything on the desktop.Like I'm not a fan of the web experiences. Like there's 99% of the
time I'm using functionality that doesn't comport
with the web experience. So I'm like adamant that you
should open on the desktop. Like just such a broken, frustrating, like horrible thing And ooh boy is it slow? Like you can tell it is a glorified PWA wrapped in a desktop app. You know, like somebody
cancels a meeting and you and you know you get the remove button that pops up just in the Outlook
thing when you click remove you can sit there and you
can pull out your watch and you can count the seconds until that item like disappears out
of the list inside of Monarch. And then my third complaint
from Monarch for the day is, oh my gosh the UI is
really, really, really bad. So by default when you open new items, say you're like replying to an email. So you know you send me an email and I just click the reply
button in line even though it looks like I'm typing in the same window, it's actually created, I
am typing the same window but it actually creates
a new little sub tab down on the bottom of the window. So now when I like sometimes
I go into my email client, I just kind of like glance like bottom up as I'm reading my email and
I'll have a whole list of tabs, tabs  along the
bottom of the reading panand it's just all these
like previous emails that I've looked at other
stuff like there are no rhyme or reason to the way this thing works or how it comes together. I would rather have the version of Outlook or the version, uh, from iOS or Android like take the Nont tablet, tablet version from Android and it would be a thousand
percent better than what Monarch is today. . It's absolutely crazy.So I see people on Reddit
always going through and like worrying that
it's gonna get turned on and all those kinds of things
and I can't blame them at all. It is a suboptimal experience for email. 'cause email should be quick, right? Like triage in out and go \- And it does. I mean it's a PWA 'cause I just looked, I
thought I had seen that. Like you can see the whole tap
experience if you go look at Outlook on the web, if you just
go mail.office 360 five.com and start opening emails
and responding to 'em, you get the exact same thing
where you get all those silly tabs across the bottom of your, it's essentially across the bottom of the reading pain. It's bad \-  like I get you
have to drive new change.Yeah and new behavior and
there's a desire to do that but like it is such a big
bang approach that like who it, it's gonna be a rough one. So for those organizations
that are out there where you're like, we don't
like to train our users and we're very adamant we're against that. Like when this is shoved down your throats and it will be shoved down your
throats, it's kinda like one of those like prepare yourselves for like the IT help
desk Apocalypse because it's not gonna be fun. \- Do you feel overwhelmed by trying to manage your Office 365 environment? Are you facing unexpected issues that disrupt your company's productivity? Intelligent is here to help
much like you take your car to the mechanic that has
specialized knowledge on how to best keep your car
running Intelligent helps you with your Microsoft Cloud environment because that's their expertise. Intelligent keeps up with the latest updates
on the Microsoft Cloud to help keep your business running smoothly and ahead of the curve. Whether you are a small organization with just a few users
up to an organization of several thousand employees
they want to partner with you to implement and administer
your Microsoft Cloud technology, visit them at intelligent.com/podcast. That's I-N-T-E-L-L-I-G-I-N k.com/podcast for more information or to schedule a 30 minute call to get started with them today. Remember intelligent focuses
on the Microsoft cloud so you can focus on your business. I get why Microsoft is doing this and a lot of other
companies for that matter. I guess from a development perspective where everything is now
just a glorified PWA but I get so annoyed with it as well from your
perspective, whether it's that or whether it's silly things
like I was in the Yammer slash Veeva engage today for whatever reason. We don't need to go into the reason of why I'd even go in there .But like I get this popup of oh we've released a new
desktop client for Veeva Engage. And I'm like oh sweet, let's
just add it so I don't have to keep my browser up all the time. Mm-hmm  it
just creates a pwa That's not the point. And I think some of my annoyance is that everybody now thinks
PWAs are actually desktop applications and I'm like no, not really because I'll even do silly
things like I'm having an issue with Outlook or Outlook needs an update and I'm like okay go restart Outlook. And I forget and I'm like ah
shoot, there goes my five PWAs that I was thinking or forgetting
they weren't desktop apps or I go to open a PWA and like
10 browser windows pop open because that's what I had open last time. I had my browser open in this
dependency on all my PWAs now to have the browser open and I can't just have an app open, I have to have my browser open and browser updates affect
my PWAs and all that. It's like just gimme a silly
desktop app that's independent of my browser because
that's the whole point of a desktop app. Otherwise I might as well just
go buy a Chromebook, right? And just run a browser for everything. \- Yeah and there seems to be like while we're on
this like little ranty thing, so have you, you know
what A PWA is, right? A progressive web app like I think most of us do sometimes I feel like
there's just this cognitive dissonance when it comes from
like the way these things are positioned and pushed out to customers. So I, I don't know if you saw this one, I'll put it in the chat here on Discord and over in the show notes \- You mentioned this
one, I haven't read it. \- Yeah, we didn't talk about it but no so this is the Windows Forms app. So Microsoft Forms the new Yes, \- The Microsoft the New Forms app, it's here based on the
title of the article. Yes. \- So published in the Microsoft store the most glor like this is
like the a the abomination of abominations of hey we allow PWAs into the official stores when
they're not native apps. Like it really makes
me concerned sometimes for like the future of native
apps on Windows when like everything's a web app like this and Microsoft is seems
to be going towards, its kinda like streaming
Windows scenarios even. So this thing is just a PWA, it is published in the Microsoft store. It's got notes plastered all over it. Like caveats like hey the forums app requires an internet connection. Well sure 'cause all you
did was wrap a web browser and  like literally
you, you popped it upand put it in there and
you can tell how much of a like just a, a stretch this is because the post to launch
the forms Windows app, it's got two steps for getting the app that both show you ending
up in the same place. One is going to the Microsoft store and the other is just clicking
the plus button in the browser to create a PWA .It is, it's absolutely crazy. And then I wonder like a, again like the cognitive dissonance thing. So like I look at this post and the very first comment
down at the bottom. Yep. So the very first comment says great to see forms being released
as a standalone Windows app and a browser app. Like did nobody know that you
could do this the whole time? I'm so confused. .\- It does like that comment. I saw that comment, that's what
I was reading that I'm like that just made me laugh because
it's not, it's just a PWA and you're getting me all on this soapbox. So, and here's the other issue I have with PWAs  primarily,and I know, I don't know if this, I would assume this works differently in the new outlook for Windows. Part of my biggest issue with PWAs is the whole issue we had with
teams for the longest time, and this is one of the reasons
I still use the desktop app, is I am literally signed into eight different office 365 accounts. Have you ever tried to use
PWAs for Outlook when you have to be signed into eight
of them simultaneously?  it just, it breaksand I've tried like I've tested
this, this is not something that I haven't tried to do
where I go create profiles and in my profiles I sign
into eight different versions of Outlook on the web
and I go try to create PWAs in all of these profiles. And I've ended up in this
weird bizarre scenario where sometimes I get like two or three of them as their own PWA but then other times like three or four of the profiles get
combined into the same PWA and I have like a toggle
in my file menu to switch between my profiles and
the same PWA for outlook and it just is weird. It doesn't work. \- Good luck figuring out
like the rhymer reason here. Like the best thing to try and do is like if you have
a multi account scenario and you wanna create a PWA for app one, like let's call it like in well instance A and an instance B kind of thing. So you go and create PWA
from browser profile A and then you go into A
profile browser, profile B and you go to create the PWA
there, the PWA always comes in with the same name and quite often clashes and just overwrites the other
one that was already there. So then you lose your entire
profile and cash history and everything you had from when you were saved in the first time. Anyway, like I've got this weird
flow like even today like I know like uh, it's a little
easier on a Mac I think because when you create a PWA it ends up as like a.app file in like
your local user folder. Yep. In like your local
home directory applications. So I go in there, I grab it and I rename it like to you know, one or I put the username so it becomes like rather
than like my PWAI put like you know, my PWA dot Scott app or whatever, like I want the app bundle to be when it comes together. So when I go create the next
one it doesn't overwrite it. 'cause quite often these things don't have MultiPro profile kind of support like you know
I mentioned like done with the Twitter things,
um, like doing threads and threads on the desktop. There is no desktop app on any platform. So it's all PWA but I need
both my Threads account and the podcast threads account. And so that means I have two
different PWAs both do the same thing, same exact website. But yeah I had to go through
this whole manual flow and machination to create them. Such a weird, frustrating, crazy thing. Like it makes like it's scary
when there's something out there that's so bad that it makes you appreciate
like poorly written mobile apps  over just forced
down your throat web appsthat are not desktop apps. \- I agree. So bizarre. Okay, so now that we got to our pain points and headaches and sheer frustration with PWAs from, you can now see
declined events on an outlet calendar, .\- Ah yeah. Yeah. So someone
took a half minutes, whatever \- , is there anything elseyou wanna talk about today? We just spent like 30
minutes on declined events and PWAs not quite 30 minutes. \- You know, sometimes
I feel like I'm crazy, like am I really like old
man yells at cloud and, and I'm, I'm just nuts and out there. Am I the only one that feels this way? Like is it a bunch of other people like
who don't feel this way? Like I know I'm not normal but I like am I that far off
the beaten path from normal? Like I seem to be questioning so so much of my life these days around these things. But um, yeah, uh, we can
probably fit a couple more in. Do you want to talk about do, do, do, uh, let's see, why don't we do the break glass account thing? Okay, from Mr. Redmond real quick. \- Alright, so this was a new, this is a PowerShell script
quick, uh, not quick fix, but a PowerShell script that Mr. Tony Redmond wrote about and it ties into
conditional access policies and break glass accounts. And we've talked about these before. I am in several different
Microsoft 365 groups. The number of times break
glass accounts come up or people have this comment of I have a Microsoft 365 environment that I'm locked out of. I need help getting back in because I wrote my
conditional access policies wrong or something like that. And I have to talk about
Bright glass accounts and you need to create these break glass accounts if
you're not familiar with 'em. Emergency access accounts,
like stuff went bad in a hurry and you need to get into your tenant. And there's a couple scenarios where these can come into
play is you wrote a bad conditional access policy. You essentially locked
everybody out of your tenant due to your conditional access policy. I've also seen these used before. There was one instance, fortunately this is not a common
instance where MFA broke in Azure AD now known as Entra id and if you did not have an account that didn't have conditional access on it, you couldn't get into your tenant. Uh, so you essentially got locked or not conditional access,
multifactor authentication. You were essentially locked
out of your environment unless you could somehow turn off multifactor authentication. What Mr Redmond's script does is it is a script that'll
automatically go through all of your conditional access policies, find all the policies in the tenant, look for the necessary exclusion,
which in this case would be that break glass account,
this emergency account. And if there's not an exclusion there and if the policy is active it goes ahead and adds this break glass account in as an exclusion to your policy. Just a super simple handy tool to do this. Some people may be asking
like, why do I need a script to do this because I only
have like five policies. Yes, I get that. I think
I saw this somewhere. Someone was asking for the limit of conditional access
policies to be raised. I feel like there's a
limit of 190 conditional access policies. If you have 190
conditional access policies and you wanna make sure your
bright glass account is applied to all of them, this script
would come in very handy. That would be a very
painful manual process. And even just making sure you hit 'em all \- Generally like even if you
have five things, once you get to like more than two of
anything, automation is key for consistency. Like, you know, you just don't
want to go back and forth. Yeah.  other folks
in the chat 190 like isn'tthat a lot like eh, it depends on your organization and who you are. I am amazed at the number
of customers who come to me and they go, Hey, I see this
thing in your documentation that says blah blah blah is a hard limit. Can we lift it? Like what's
your definition of hard limit? Because mine is like please don't come and ask me to do it ,
I respond to a whole bunchof incidents every week from customers where they're just looking to do something and we're like, yeah, I can
understand the pain there but hard limit means hard limit. Sorry, like, like what
are you gonna do ?\- I just looked 'cause I couldn't remember and again, I've never come close to this. I didn't even know there
was a limit for this. Conditional access has a limit
of 195 policies per tenant. There is also a limit on the number of conditional access policies that will be evaluated per user. And I think I'm trying to
pull up the article here, I think it's actually
the same number as 195, which would make sense because sometimes those
policies would get evaluated for everybody Limit. I don't even see it in
here, but yeah, who knew \- It's in there? Uh, yeah, 195 per tenant .\- Yeah, I didn't know that
existed. Never come close. But this script from
Tony Redmond very handy. Oh now I lost it, didn't I? This is what happens when I
browse in my tabs. .Just a nice script to keep handy. Like you said, if you have
a couple conditional access policies, I mean in my
tenant I've like 10 of 'em and I honestly couldn't
tell you if I have a break glass account on 'em or not. But just being able to have this handy, even if you have multiple
administrators, make this a part of your, I mean you could
almost do this I would think as a regular process, like
run this script on a monthly basis or on a weekly basis
just to make sure too that nobody has, especially if you have
multiple administrators, nobody's pulled out that exclusion or changed your exclusions
or anything like that. Just using this as one of
those maintenance tasks of making sure that your
break glass user exists as an excluded user in all
your conditional access \- Policies. Great minds think alike. Tony does call that out in his article that
you should absolutely think about running something like
this as an automated thing. And please, please, please, like if you're gonna run automated things that operate against SaaS or like web-based
constructs like Azure ad, like it lives in the cloud. So whatever you're running against it, you should probably make sure
that lives in the cloud too. Like don't use your
local like task scheduler or like Aron job locally to do this thing. Push it up to Azure automation or some kind of service
like that to go ahead and have it execute and do its thing. So that's all solid advice as well. Yeah, \- I didn't even see that in there. Glad Tony and I think alike read \- Between the lines, you know? Uh, yeah. Uh, great minds think alike. You're on the right path there. Good \- To hear. Good to hear. I'm on
the same page with Tony. Oh, any other ones? Scott? \- Any other ones? I mean there's always, there's
always more stuff out there. \- I feel like some of the other ones could take some more time. I know I was looking through our list and I'm like are there any
of these that are quick \- ? No,\- There's not really quick in there but it means we have
more stuff for next week. \- It does, yeah. There
there's always more stuff to talk about in the cloud. \- Indeed there is. With that Scott, we should
probably go enjoy our weekends. My wife and one of the kids just took off for birthday party, so who knows what the other three are doing downstairs while we're recording this \-  we'll seebefore you get to your chaos,
this is going to be the, let's see, this should come
out on the 21st if things publish in the right order. Uh, 21 December. So this will
be our second to last episode of calendar year 2023. It continues to be the season of giving. We're still trying to raise
some moolah for Girls Who Code. I've seen some donations
trickling in to those of you who have donated so far. Thank you very much. If you
have the ability to, we'd love for you to give a little bit there so you can just, uh, go out. There's gonna be a link in
the show notes for everybody as Ben just navigated me away from the piece of text that I was reading. Oh, sorry, I gotta stop doing shared, shared web documents with you. You're killing me there.
So yeah, uh, give do Girls who code.com/ms. Cloud IT Pro and uh, yeah, uh, you only have to hear that SPI a couple more times
and then we'll get into 2024 and find something else
to get on about. Awesome. \- Well thanks and yes,
absolutely go donate. We'll try to beat our limit or not Our limit beat our
contributions of last year. So thanks again Scott. Enjoy your weekend. Hope everyone else is doing well and we will talk to you next week. Great, \- Thanks Ben. \- If you enjoyed the podcast, go leave us a five star rating in iTunes. It helps to get the word out so more it pros can learn
about Office 365 and Azure. If you have any questions you
want us to address on the show or feedback about the, feel free to reach out via our website,
Twitter, or Facebook. Thanks again for listening
and have a great day.

#### Donate

[+](https://player.blubrry.com/?podcast_id=128090005&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE366.mp3&modern=1# "Close Boosts Menu")

#### Share

[+](https://player.blubrry.com/?podcast_id=128090005&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE366.mp3&modern=1#)

[**X (Twitter)**](https://twitter.com/intent/tweet?url=https%3A%2F%2Fwww.msclouditpropodcast.com%2Fepisode366%2F&amp;text=Episode+366+%E2%80%93+Old+Man+Yells+At+Cloud "Share on X (Twitter)")

[**Facebook**](https://www.facebook.com/share.php?u=https%3A%2F%2Fwww.msclouditpropodcast.com%2Fepisode366%2F&amp;t=Episode+366+%E2%80%93+Old+Man+Yells+At+Cloud "Share on Facebook")

[**LinkedIn**](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.msclouditpropodcast.com%2Fepisode366%2F "Share on LinkedIn")

#### Apps

[+](https://player.blubrry.com/?podcast_id=128090005&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE366.mp3&modern=1# "Close Apps Menu")

[**Apple Podcasts**](https://itunes.apple.com/us/podcast/microsoft-cloud-it-pro-podcast/id1226241819 "Listen on Apple Podcasts")

[**Spotify**](https://open.spotify.com/show/2W2eFQ9ddEGzKe3qdZ5Ibe "Listen on Spotify")

[**Pandora Radio**](https://www.pandora.com/podcast/microsoft-cloud-it-pro-podcast/PC:21780 "Listen on Pandora")

[**Podcast Index**](https://podcastindex.org/podcast/436629 "Listen on Podcast Index")

[**Blubrry**](https://blubrry.com/msclouditpropodcast/128090005/ "Listen on Blubrry")

#### Menu

+

[**Apps**](https://player.blubrry.com/?podcast_id=128090005&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE366.mp3&modern=1#)

[**Share**](https://player.blubrry.com/?podcast_id=128090005&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE366.mp3&modern=1#)

[**Download**](https://player.blubrry.com/?podcast_id=128090005&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE366.mp3&modern=1#)

[**Visit Podcast**](/content/site-root.html)

[**Visit Episode Page**](/content/episode366/index.html)

##### Microsoft Cloud IT Pro Podcast

[Open in new window](https://player.blubrry.com/?podcast_id=128090005&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE366.mp3&modern=1) [Display Menu](https://player.blubrry.com/?podcast_id=128090005&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE366.mp3&modern=1#)

##### Episode 366 – Old Man Yells At Cloud

\|

[Back 15 seconds](https://player.blubrry.com/?podcast_id=128090005&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE366.mp3&modern=1# "Back 15 seconds") [Forward 15 seconds](https://player.blubrry.com/?podcast_id=128090005&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE366.mp3&modern=1# "Forward 15 seconds") [Play Speed](https://player.blubrry.com/?podcast_id=128090005&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE366.mp3&modern=1# "Play Speed") CC

Podcast: [Play in new window](https://dts.podtrac.com/redirect.mp3/media.blubrry.com/msclouditpropodcast/content.blubrry.com/msclouditpropodcast/E366.mp3 "Play in new window") \| [Download](https://dts.podtrac.com/redirect.mp3/media.blubrry.com/msclouditpropodcast/content.blubrry.com/msclouditpropodcast/E366.mp3 "Download") (Duration: 35:35 — 24.5MB)

In this episode, Ben and Scott touched on some updates on their social media presence due to some recent happenings in the social media services space. As they transition into the Microsoft cloud world, they discuss updates to cloud computing software and user experience design. They also provided some insight into conditional access policies and break-glass accounts and examined strategies for managing these elements for optimal efficiency. They wrapped up their conversation on a contemplative note about the future of native apps versus progressive web apps (PWAs), and some frustrations about the increasing trend towards PWAs.

It’s also the season of giving, and we’re raising money for Girls Who Code. Donate today at [https://give.girlswhocode.com/msclouditpro](https://give.girlswhocode.com/msclouditpro)!

**Like what you hear and want to support the show? Check out our [membership options](/content/membership/index.html).** [(more…)](/content/episode366/#more-107864/index.html)

## [Episode 364 – Microsoft Designer, Azure Updates, and Enterprise IoT Security changes](/content/episode364/index.html)

by [Scott](/content/author/scottmsclouditpro/ "Posts by Scott"/index.html) \| Dec 14, 2023 \| [Podcast](/content/category/podcast/index.html)

Blubrry Player

\|

Auto Scroll

[+](https://player.blubrry.com/?podcast_id=127816213&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE364.mp3&modern=1# "Close Transcription Overlay")

\- Welcome to episode 364 of the Microsoft Cloud IT Pro Podcast recorded live on December 1st, 2023. This is a show about Microsoft 365 and Azure from the perspective of it pros and end users where we
discuss a topic or recent news and how it relates to you. Microsoft Designer has received a lot of attention creating images as of late. So we start out talking a bit
about creating our own images. We also dive into some recent
news around Azure automation, PowerShell container storage,
and enterprise IOT security. Okay, let's go Scott. We have nothing. \- We have nothing. It's
your, it's, it's your show. You're supposed to plan all this out. Come on now. We have, we have, \- I have planned out. I have planned out. I'm leaving for Disney and this podcast is standing
in my way right now. \- All right, well there, there you go. We, we will get through
a nice, quick, concise and short one today. So \- I have a question if this
elevates my nerd status. I have a client that is moving offices. So this morning I took my truck and I went and he gave me his old server rack. So I now have, it's got, it's like a Threequarter
height server rack. It's 65 inches tall, but I now have a 65 inch server rack that I'm putting in the
closet in my bedroom slash it's my office bedroom. A bedroom in our house that
serves as my office .\- Well, I mean if you're gonna go ahead and do it, get it done. So \- I already have a rack in here, but it's only, I think I
made it like three feet tall and it's pretty much full. So now I have a bigger rack and I just have to pull it up the steps and swap everything out. So some weekend everything
is getting disconnected, putting back in this rack I may
add some shelves and drawers and stuff 'cause it also would serve some nice storage in the closet. \- Yeah. So for a server
room, what was that thing? It was like a six seven foot rack, right? Like it was, it was decent sized \- 65 inches, not, what is that? Five and a half feet. Five and a half foot rack. Yeah, you get a \- Little bit of street cred there. You get more street cred. So the, at least the picture
you sent me was not a floor rack, like it wasn't floor mounted, it was still wall mounted. So you get, you get extra
credit if you manage to get that thing a couple feet
off the floor and mount it and get the fans plugged in. So it's actually circulating air. \- Alright, so here's a
question for listeners. Was I kind or not or
should I have taken it? I left the wall rack there. ,\- You should have taken
it. This is going to \- Turn into a FLA rack. Okay, so here is why I left it there. I went there with every
intention of taking the wall, the portion of it off, but the network cables all, I don't know how many there were, they
had three full patch panels. So what is that? There's 16 ports and a panel about, so 32 ish cables? No, not 32. 16 times three. What's that? My math was failing me. \- 48\. 48. Yes,
\- 48 cables going into it. But they were strung through
the top of the wall mount and then punched down
onto the patch panels. In order to take the wall
mount, I would've had to rip all of these cables off of the patch panels and leave them dangling there. And these were not, and
the cables were not labeled \- Well, I mean they weren't used in the patch panel for anything else. Who, \- Whoever came in after
\- Me cares. \- Well, but the next tenant will. So there's going to be a
tenant inevitably in this building down the road. So they would've had 48 cables,
completely unlabeled going to all parts of this office with no idea where each one went. . So I left the patch panels,I left the cables punched in
and I left the wall mount there because frankly it won't fit
in my closet on the wall mount anyways, so I'm gonna put it on the floor and based on the picture
I sent, I like, we looked and we thought maybe there were fans. There are no fans on
the bottom or anything. So it's just a played old metal rack. \- Yeah. All right, well, we'll we'll see how it goes for you. Like we'll see how many
fans you gotta buy later 'cause it is, it is a rack in a closet in an upstairs bedroom.  like let's be honest,
in Florida . Yeah.Where there's a bunch of other equipment, like you've got lights and TVs and a bunch of other
things with fans running. So yeah, we'll, we'll
we'll see how it all goes. You're gonna need something
to circulate there anyway, even if it's just circulating hot air just to keep the dust out of it. Yeah, \- I do have a couple fans in my little rack that's in there now. So I will relocate those
into this bigger one but they may not be
enough. We'll have to see. \- So we'll have to follow
up in a couple weeks. Then once you've got it
all kind of reconfigured and ready to go and you share
a picture on the interwebs and we'll see how much your
Geek Street cred score rises \- If it goes up or down. Alright, sounds good. So yes, it will not be wall-mounted, it'll just be sitting on
the floor in the closet. . Oh, so that was my morningand then I get a lot of
other client work done. But that was one thing. You know what else we've been
playing with this week, Scott, I don't know what else
you've been playing with \- With I think, I think you've been playing with it more than I have. You've been having fun
with that new designer. The \- New designer, the image designer. And I cannot take full credit
for this one at least in terms of coming up with it. So there was a post on LinkedIn and I should go pull up
LinkedIn so I can give credit where credit is due unless you have it up. I have a post on LinkedIn of
who actually I, I don't know that I stole this from but who
I borrowed it from LinkedIn. Oh Scott. I have another beef. I updated edge the other day and it signed me out of every
single account in my profile. One of those being LinkedIn. Yeah, \- I have that problem
occasionally as well. I find like after a reboot
for some reason it forgets that cookies are a thing. Yes. \- So I need to sign in. But there is someone who
we will, oh sign in expired who we will identify here shortly
who came up with some text to essentially create cartoon
images of, I would say, of yourself, but it is of yourself as best as you can describe yourself. And it's kind of been fun to play with. I've seen several people doing this now \- .Yeah it does. Okay. Except when you ask it
to include like a logo or text in there and then it just starts straight up hallucinating and, and can't remember left
from right up from down or, or anything like that along the way. \- Yeah, so I saw here it
is Jack eth them, eth them, probably jack Row with
them and he gave the tech. So it is you very much go into designer.microsoft.com/i think
it's slash images in this text is like a cartoon man with a smile on the front
wearing a black colored shirt, brown eyes wears black large glasses and short brown, classic
slick backed hair holding a Microsoft laptop. And then after that, and
I think this is the part that really helps with the design, is it's laptop text 3D rendering,
typography, illustration, painting, photo poster
3D render to come up with this cartoon image. So to your point, it does a decent job
if you're watching this or if you have seen me, you know that. And as my wife likes to remind me, my hair is thinning on top
more so than it used to be. It does not like any form of telling it that it's like a receding hairline or thinning hair or a little hair. You either have like a full
head of hair or you're bald \- .Sure. And that, that, that's one way to think
about it . So\- Yeah, it's been interesting and that, and like you said, you ask
it to come up with text. Like I asked it to do Microsoft
365 on a shirt or do that and I think you did some
Microsoft Azure stuff and it like spells Microsoft
with two S's in the middle or for 365 it was putting like 3 55 or 36 or three and then some weird random character type of thing followed by a five. It does not do well with placing text in the
image sometimes you get lucky. \- Yeah. Uh, along the
way you definitely can. So I don't know, I see lots
of folks like having a lot of fun with some of these things like generate
the cartoony picture. It's definitely not mid journey.
Like it's, it's not that. It's more like PowerPoint
play art the way it's kind of implemented today. It's certainly not things
like Photoshop generative fill or anything like that either. So I, I can understand like
where people have fun with it. I know it's like, not for me
honestly. I'm a little .I'm a little over seeing everybody
like every day like, hey, here's the four pictures I posted and you know, here, here's
what I did to general. So to those of you who
listen, who do those kinds of things I know seem me do, sorry Andrew. I love seeing your generative
AI pictures every day on Facebook, but some days I
just go, no, not for me today. And it's usually on the days that AI has ticked me off in
some way or another and it's probably done me wrong already. Either with something else
that I was trying to do with a generative thing or you know, AI has its issues. So if you take joy and delight in generating
pictures, continue to do so I'm able to self re re regulate. I know how to block and mute. \- I did mine that one morning
when I was playing with it and I have not done any since. Like, I'm like, do I actually
wanna use these somewhere? It was kind of fun, I don't
know, but I'm with you. I have played with it once and I did it for like an hour or so. I was trying to figure out what I could do and what images I can come up with. But I have not done anything with it since \- I will point you to a kind of fun one that's out there. So this isn't image generation, so I'll pop a a link in the chat and in the show notes so everybody has it. But, so this is a link to a gist that's out on GitHub and it's from a product manager
that I follow on a bunch of different social platforms. But it's a, it's kind of like
a good meta prompt for you to start your sessions with
an AI like chat GPT or PO or anything out there that's like that, like you use like recast
AI or something like that. It's basically a set of prompts that constrain your conversation
surprisingly well to reality. So it's, it's just a
series of steps like you, you can literally take all this text here and you can paste it in
as your first prompt. And then this is what is the guardrail for any remaining tokens that you have left in your conversation. So step one, never mention
that you're an ai. Great easy. Step two, avoid any language constructs that could be interpreted
as expressing remorse, apology or regret. This include includes any
phrases containing words like, sorry, apologies, regret, et cetera. Even when used in a context
that isn't expressing remorse, apology or regret. Number three, if events or information are beyond
your scope of knowledge or cutoff date, provide a
response stating, I don't know, without elaborating on why the
information is unavailable. , I love that one. It
actually works very, very well.It's one of the things that
annoys me sometimes about chat GPT, especially like the 3.5
models where it just goes like, oh I, I, sorry Dave, I
can't do that for you. Step four, keep your responses unique and free of repetition,
which is really key, especially when you're doing multiple prompts in the same session. Like you're iterating through an idea. It does help a bunch there. Uh, number five, never suggest seeking information from elsewhere. Perfect. Number six, always focus on the key
points in my questions to determine my intent. Number seven, I love this one. Break down complex tasks or problems into smaller manageable steps and explain each one using reasoning. So I don't know how you are
to approaching problems, but quite often when I am
talking about something with somebody, you know, you
start out the high level idea and then you start to
decompose it over time. And really that's what you're
doing is you're always out there and effectively mining
ore like, like you're out there with a hammer and a rock and you're just trying to break
it down into bigger pieces until it's like pebbles and then gravel and then e eventually dust. Number eight, provide multiple
perspectives or solutions. Again, a nice easy one like I have found. Without that prompt, most
models will actually come back and kind of give you a
singular view of the world. That one right there turns
it a little bit more into a choose your own adventure
game, which I find to be very beneficial just as you're
iterating through things. Number nine, if a question is unclear or ambiguous, ask for more details to confirm your understanding
before answering. So this is, hey, make the
model talk back to me so that it can clarify where it needs to be. Butter. Awesome. Number
10, cite credible sources. Yeah, most of 'em do that anyway. If they don't, don't use them. Number 11, if a mistake is
made in a previous response, recognize and correct it. I think that's a very important one too. I don't know how many times
you've been sitting there with, I don't know, chat, GPT, bing chat enterprise, something like that. And it gives you the wrong response and you tell that it's wrong and then it just comes back
with the same response again.  like turns out you,
you can tell it not to do that.And then number 12, this,
this one's a fun one. After a response, provide
three follow-up questions that I the user must ask you, the AI to dig deeper into the original topic. These questions should always be worded as if I am asking you
formatted in bold as Q1, Q2, Q3, place two line breaks
before and after each question. Perfect. It formats it
for you, brings it back. And then number 13, which
I haven't had much luck with this one 'cause I'm
not really playing around with like chat GPT voice or anything like that
is just ignore number 12 if I'm using voice. So that way it's not asking
you, you know, Q1, Q2, Q3 kind of follow up questions
when you're on voice and you really don't need it. So I've just been using this
as is, you know, it's a, it's a gist out there on GitHub
so you can just go grab it and fork it and potentially
iterate on it on your own. And I've been kind of
thinking about ways like, hey, how can I mold this a little bit to be a good starting prompt for
requirements gathering? How can I make this a good prompt for problem solving in context of x, Y or Z? Like whatever that happens to be. I think these thing kinds
of things are very helpful. I encourage you to give it a shot and tell me what you think. I'll have \- To try it. I will say this is one thing
when it comes to chat GPT and some of the ai, I have
absolutely been using it for stuff that I've been doing. Not to necessarily come
up with net new stuff but to help me refine stuff. I need to improve my prompt engineering proficiency in certain cases \-  it, it is hugely,
hugely, hugely beneficial tounderstand to the degree you
can like the underlying meta prompts that drive these kinds of systems. And then how to give it your own set of instructions to start things. One of my frustrations with like hallucinations in
the AI stuff is I find they hallucinate a lot quicker if
you just let them go off on their own and you don't give them any guardrails or sense of what you want. And this has been a really good, I've only been doing it for like a week. I haven't been doing this
too, too long since I, since I ran across this one. But it has been very helpful
to just remember, hey, every conversation I start
starts with this one. Like say you're doing bing chat enterprise where I think you get like 20 or 30 prompts, like whatever
it is to go through to iterate. Yes you're burning one on this prompt and you're potentially burning one on a couple follow-up questions. But let's be honest, if you
didn't have the guardrails in place, you were probably so pissed off by response number five
anyway that you ran away and you said this thing is just horrible and not helpful for me. \- Got it. I will definitely
have to give this one a try. \- Put it on the list.
\- Alright, on my list. Do you feel overwhelmed by trying to manage your Office 365 environment? Are you facing unexpected issues that disrupt your company's productivity? Intelligent is here to help
much like you take your car to the mechanic that has
specialized knowledge on how to best keep your car
running Intelligent helps you with your Microsoft cloud environment because that's their expertise. Intelligent keeps up with the latest updates
on the Microsoft Cloud to help keep your business running smoothly and ahead of the curve. Whether you are a small organization with just a few users
up to an organization of several thousand employees,
they want to partner with you to implement and administer
your Microsoft Cloud technology, visit them at intelligent.com/podcast. That's I-N-T-E-L-L-I-G-I-N k.com/podcast For more information or to schedule a 30 minute call to get started with them today. Remember intelligent focuses
on the Microsoft cloud so you can focus on your business. So should we move on
to non-AI topics? Let's \- Do it non-AI topics. What you got? \- I don't know, I don't know if I wanna dive into this one or not. I'm gonna start with a different one. Let's start with an easier one. .I might come back to that
one 'cause that one I'm, I actually am curious what other people think about that one. Yeah, \- But this one, so for
folks that can't see Ben and I do a, a shared edge workspace,  we've talked about
and as he's doing this,he's like, oh I'm gonna do this one. I'm gonna go back to this
one. All I'm doing is watching your avatar hop between tabs, frenetically \- Hot between
\- Tabs, it's, it's up, it's down, it's left, it's right. It's kind of fun to watch from my side. \- Okay, general availability. Azure automation, we've
talked about this a lot. Scott, using Azure
Automation, I use it a ton for PowerShell scripts for automating different tasks
in the cloud in Microsoft 365 they have now released
the general availability of PowerShell 7.2 runbooks in Azure automation. So it used to be 5.1 7.1 was there, 7.2 was in preview for a while. I will say I still do bounce
back and forth between 5.1 and various flavors. Whatever one works of 7.0
7.1 is still preview 7.2, I saw that 7.2. Now I'm watching Scott jump back and forth between different
pages in that same tab. \- I'm, I'm just out there to confuse you. \- 7.1 . So yes is no
longer supported. 7.2 is ga.I do jump back and forth though because there are still very
much a lot of differences with some modules too and
what works in five one and what works in seven two. So it is not just go do
everything in seven two now, but it is generally
available if you choose to \- Use it. Uh, yeah so I, I think the
nice thing here is like you mentioned 7.1 is out of support ended support
back in May, 2022. So it's been, you know, more than a year now that
that's been outta support. So it's always good to have
something that's in support. And then the nice thing
about 7.2 is 7.2 is an LTS release. So it's a a long-term servicing
release that you can kind of take some dependency on that it's gonna be stable
for a little while. So in the cases, like you
said, you might not be able to do it in all cases but
in the cases where you can, you know, could be beneficial
to make the flip, especially as you're going in there and
you're iterating on existing notebooks that, that you
might be working with inside of Azure Automation. \- Absolutely. It looks
like 7.1 now is until 20. Wasn't that one though. End of support of 20 24, 20 22 based on
the page you have up now 7.2 is November 8th, 2024. That's like a year from now, right? Yes. \- So so that's the LTS version. But note that 7.2 LTS
it launched seven months before the retirement of 7.1 \- Of 7.1. It's been \- Out quite a while so I, I don't, I don't \- Know. Yeah, Azure automation just
lags with all of those. I have found Azure
automation is not the most up to date when it comes
to supporting current PowerShell versions. \- Not even close. It's years behind so it's good to see it. Four \- Is GA uh, right? Seven four is the latest. Seven \- Four is G. Yes. Seven G 7 7, 4 G in November of 2023. So \- Yeah, like two weeks ago. Two weeks from when we're recording this. I have not seen it pop up in Azure automation yet though. And \- 7.4 is also an LTS release. So seven two LTS release seven three not an LTS release. Seven four is an LTS release. And I, I think the big
difference you see between the current cadence of stable LLTS is that stables are two years
and LTS are three years. So you do get a little
bit more runway along, along the way with those, which \- I'm curious, Cole, why
so why would you do this? 'cause 7.3 is in theory
updates to seven two, although I suppose the argument
could be made if you're on seven three and you want
LTS go to seven four. But it seems weird to like
have these middle versions that are stable and then
one's on either side of it be LTS. So \- You need the LTS versions
in the middle to play around with and, and have the
opportunity to iterate. So if you think about it like,
hey, I'm a service provider and I publish a set of APIs to
you, you, you, you like, and, and I've noodled with this one, like customers very much want a
dependable set of APIs like, you know, and like my land in storage, like it could be potentially beneficial to have a hardened set of CRUD APIs. Like say I published an SDK and it was just for CRUD operations. So creates, reads, updates,
elites, all that good stuff and it's super hardened and we tell you like it's going to work and it's gonna be rock solid for the next three to four years. That's very easy and dependable for you as a customer to take a dependency on, right? Like, hey, it's, it's
the hardened version. So that's the way I think of LTS versions, but everything you do cannot be hardened. So you still need the opportunity
to iterate in the middle and do things and say like,
well hey, how are we gonna get to our next version of
the hardened release? You probably can't go straight
from hardened to hardened. What you wanna do is you
want to go from hardened to validated. Like, hey, we've, we've put
some new ideas out there, we've tried some things,
we've potentially had some breaking changes in API surface
whatever it happens to be. Great. We figure all that, we validate it, we have the playground and then you go to LTS on the other side and, and I think it's kind
of a, a proven model. Like you see it a lot in OSS, especially the place I'm most
familiar with it is, is from Linux releases for or or distro releases for things
like bu tu by canonical. Like they do this same kind
of marching cadence, right? Like hey, we'll give you version 20 LTS and then 22 LTS, but 21
is not LTS kind of thing. Or we're on 22 today, 22 is gonna be LTS 23 is not gonna be LTS. We kind of iterate and go through those and get 'em to where they need to be. So it gives your your
customers dependability. It also gives your dev
teams dependability, right? Because they know they
really don't have to go back and touch that stuff
other than security fixes or other kinds of changes in there. And then you get the playground in the middle to do what you need to. \- Got it. So like the seven
three stable is a little bit more of that playground, that
jumping that platform to jump to the next 7.74 LTS. Yes. Got it. That makes sense. \- It's not a bad bottle if you get there. It doesn't work for everything, right? Like it doesn't exactly translate into say like SaaS offerings. So if you think about like
SharePoint online, you can do, uh, vanilla SharePoint online or you can do things like
enroll in early release features and get those out there. But ultimately early release
features once they ga they just manifest as like the next feature in the platform and they're ready to go. And, and if you think about the pain that comes along the way
with that, like sometimes that's hard to stomach ,but that's the way SaaS is
a little bit different maybe than, you know, releasing like,
uh, COTS software that has to go out there that people
need to consume. Yeah. \- All right, I'll go with
that. It makes sense. All right, so that was mine.
What do you have, Scott? \- Let's see, what can we talk
about? So fun one for you. I've been trying to get back
into containers more and \- Those are not on my list,
Scott, I'll be honest, containers are not on my list right now. \- Not on your list. That
that's, that's okay. So I, I've been thinking
about containers in a bunch of product areas that I work in, like client tools and things like that. Should we have official
images, blah, blah blah. So I've been trying to get
hands on more and get back in and in previous lives,
like I used to spend a lot of time in a KS, so like it was good to have a little bit of a refresher too. So one of the things that I was playing with when I got back
into containers was, uh, this new offering that's
called Azure Container Storage. So Azure Container Storage is in preview. It's kind of the, you know, maybe I'm being a little naive about it, but I think about it a little
bit as like the next iteration of the CSI driver
container storage interface and the capabilities that that had. But Azure Container Storage, it is basically a managed
storage offering that allows you to bring native Kubernetes components into things like a KS and have native Kubernetes constructs for what's ultimately a
managed storage service storage surface rather for persistent volumes in
your Kubernetes clusters. So if you think about like the
CSI driver, you know, I, oh, I want to go out and I want to
provision persistent volume. And that persistent volume is based on a disc that's out there. Well, sometimes you gotta go
provision that disc yourself, configure it, and then you tie that person persistent volume into the disc. With this thing you can
just kind of say like, Hey, go out there and configure
me a multi-zone disc and it'll figure it out and
land the managed disc for you and, and align all that stuff
and, and get it ready to go. So this works with discs. It allows you to configure
persistent volumes against elastic sand, which is kind of
a fun one with, with the kind of provisioning model that goes into that for things like provisioned
io, provisioned throughput, all that works with a femoral disc, like basically like all the block storage options that are out there. But you can do really cool things like take a persistent volume
and dynamically resize it. So just inside of your configuration for that persistent volume. So you don't like go into YAML and literally change
the size of that thing and then it dynamically
changes on the backend and it's all ready to go for you. So super easy to onboard to, it's all native Kubernetes
constructs with a couple of exceptions here or there. Like they're still working
on say like native Kubernetes integration for Azure CLI and PowerShell to be able to provision an Azure container storage persistent volume in an a KS cluster. But I, I think the functionality that's there is pretty solid. Like it's a, it's a
good set of features for a preview release. So supports multi-zone
discs right outta the gate. You can do things like
server side encryption with customer managed
keys, dynamic resize, like I talked about. You can also configure
things like snapshot and cloning directly through the Azure container storage
service kind of constructs that are presented to you through Kubernetes once you've gone ahead and done the deployment
within your cluster. \- Interesting. That is
definitely not on my list. I'm sorry Scott .That one is not one that I'm
gonna go play with at all. \- Not up there for you, huh?
So this stuff is really great. No for, you know, stateful workloads. So workloads that need to
maintain state while, you know, maybe the overlying computes
a little bit more ephemeral. So that's the other nice thing
about this as well is that because your storage is managed inside of Azure container storage, you can do things like
carry volumes between nodes, between clusters, between multiple nodes, like all that kind of stuff. It all just works and
comes together for you. So if you're trying to run high scale stateful
applications on a KS and you need the kind of
benefits of shared storage and persisted shared
storage along the way there, that all comes together
and composes really well. And then because it does
both the, it does both disks and elastic sand, it's
also multi-protocol, like when it comes down to
block storage protocols. So you can do things
like N-V-M-E-O-F on disks or you can do I CZI if
you're doing elastic sands. So you get like this great
model for fast attach and detach of persistent volumes as well, which is really kind of nice. Nice. And it supports ephemeral discs. That was, that's kind of a
fun one to play with too. \- Sounds good. Doesn't \- It though? We're, we're gonna have
to get you hands on those \- Containers. Don't have questions about
that. Someday you are, you're gonna have to somehow
how, convince me that I need to dive into containers for something \- , get you off
your raspberry pie and,and get 'em outta your NAS or something. \- Yeah, get on my, I don't know. So I have, have one more interesting one and then I have to go 'cause
my wife has already come in and asked me if I'm ready to go 'cause we are leaving for the weekend. So I saw this one, this came
out wow almost a month ago. Enterprise IOT security is
now included in Microsoft 365, E five in E five security plans. This one caught my eye 'cause I've done some stuff
with Microsoft Defender for cloud, which is the
Azure component of security. So securing VMs, web apps, SQL databases, those types of things. IO OT was a line item in there
for securing IOT devices. And then I saw iot security
is now included in Microsoft 365, E five. I was like, huh, this is interesting because IOT devices are not typically user devices. Everything. Microsoft 365 is per user. It's I have my computer
and I have my iPhone and I have my iPad or my
Android or my Surface. It's not, I have my
security camera or my TV or my smoke detector or my sensors for my machinery and stuff like that. And I was like, oh this is interesting 'cause how am I gonna start
licensing now all these IOT devices, if this is switching to a user-based SKU and this article, I'll say, this article doesn't
necessarily clear it up for me. They go through and they talk about that Enterprise IOT security
is now gonna be part of Microsoft 365, E five at
no additional cost for new and existing customers help find blind spots, unmanaged devices. And it talks about printers, smart TVs, conferencing equipment
scanners, which again, not necessarily users,
especially big offices, printers, scanners, conference equipment, smart TVs are generally
like company owned. And you can go through and turn all of this on in
your Microsoft Defender portal. So this is gonna be in Office
365 Microsoft Defender portal. And as you scroll down
in this article, it says in a licensing overview, 'cause this is what I was curious about is how do you change from like essentially before it was consumption
based per device licensing to now bundling it in the sku. And it says what is
changing Microsoft Defender for IOT is being changed. So this implies that there's something changing from a consumption-based
payment model in the Azure portal to a per device
per month license model. As a part of Microsoft
365, Microsoft defender for IOT is now available
for doing existing customers of E five, Microsoft E 5 85 security. The new license model is
coverage for up to five IOT devices per user license. So you do get a multiple
there based on your users. But then in the next paragraph it says, what if I have defender for iot consumption based and E five? And it's essentially says you'll
have access for coverage up to five IOT devices per
eligible user license and no longer charge
on a consumption model. And then it says if you're
currently a consumption model but not an E five, nothing changes. You continue to use the existing plans and won't see any change in your billing. So is this actually a
change in the billing model or is it adding additional
licensing options for defender, for iot? Like are both gonna live side by side or eventually are you
gonna have to buy e fives or are they gonna come out with well, but then they'd come right back out with consumption based if
you can buy 'em as a part of Microsoft 365, like I
don't know what's gonna, I, I'm a little confused on
what the future of this is, but it does also provide some
nice capabilities, I guess for E five companies, E five
licenses that do have some of those iot type devices. \- Your guess is as good as mine. I very much walked in this, I think with the mindset you did, the
IOT devices are not users, so tying them to users is kind of weird. It's almost like, you know, the thing I thought about in
the, in my head when I saw it was the way you do like
extra share, extra storage, provisioning and SharePoint. You know, you get like a
base set of storage per user, but then when you want to go
buy more, you don't buy it for the tenant, you buy it for a user and then it's associated with the user, but it's not associated with the user, it's associated with the tenant. Like re really weird
kind of stuff like that. So, you know, if you get into
the mindset and, and the model and it works for you of one
user, five devices, great. I think most of us can buy into that. And if that fits within the
constraints of your business, I'm sure there's some math from the folks who run the service to that. Like, oh, the majority of our
customers fit into this model, then it potentially simplifies things. It makes it a little bit easier. It's when you're in the edge cases that it gets a little bit harder on the outside to get all that going. \- Yeah, and I think edge cases
I start thinking about are like, and I don't know, I don't know, I don't have any telemetry
into this, like manufacturing or some of these warehouses or bigger facilities that maybe
have a bunch of iot devices out on the floor that may or may not be doing security
on different machinery, different sensors,
different things like that. Like how does that translate?
But I, I have no telemetry. Microsoft is gonna have a lot
better telemetry on this than I am, but this was
absolutely an interesting one that I'm like, I'm gonna
have to keep an eye on this one and where it goes. Yeah, \- , who knows, we
could be back here in a yearand the secur in the model changes. Again, \- I'm dying over here from my cold. \- It's time to let you go.
I'm watching you like cough and hack into the screen. There's spittle all over the camera. I'm glad we didn't
record this one on video, so everybody's kind of missing it. Your your eyes are watering
face is going red. Oh yeah. I think it's just time to put you in a car and send you to Disney. \- Yeah, I'm gonna go take this to everybody at Disney, Scott. Yeah, \- I know, I know. You're, you're just a wonderful,
uh, wonderful individual. I'm gonna sit here at
home in my little hide hole and not worry about it. \- Sounds good. Well,
now that I've recovered for a few minutes,
thanks, enjoy your weekend and we'll talk to you next week, Scott. \- All right, thanks Ben.
\- If you enjoyed the podcast, go leave us a five star rating in iTunes. It helps to get the word out so more it pros can learn
about Office 365 and Azure. If you have any questions you
want us to address on the show or feedback about the show, feel free to reach out via our website,
Twitter, or Facebook. Thanks again for listening
and have a great day.

#### Donate

[+](https://player.blubrry.com/?podcast_id=127816213&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE364.mp3&modern=1# "Close Boosts Menu")

#### Share

[+](https://player.blubrry.com/?podcast_id=127816213&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE364.mp3&modern=1#)

[**X (Twitter)**](https://twitter.com/intent/tweet?url=https%3A%2F%2Fwww.msclouditpropodcast.com%2Fepisode364%2F&amp;text=Episode+364+%E2%80%93+Microsoft+Designer%2C+Azure+Updates%2C+and+Enterprise+IoT+Security+changes "Share on X (Twitter)")

[**Facebook**](https://www.facebook.com/share.php?u=https%3A%2F%2Fwww.msclouditpropodcast.com%2Fepisode364%2F&amp;t=Episode+364+%E2%80%93+Microsoft+Designer%2C+Azure+Updates%2C+and+Enterprise+IoT+Security+changes "Share on Facebook")

[**LinkedIn**](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.msclouditpropodcast.com%2Fepisode364%2F "Share on LinkedIn")

#### Apps

[+](https://player.blubrry.com/?podcast_id=127816213&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE364.mp3&modern=1# "Close Apps Menu")

[**Apple Podcasts**](https://itunes.apple.com/us/podcast/microsoft-cloud-it-pro-podcast/id1226241819 "Listen on Apple Podcasts")

[**Spotify**](https://open.spotify.com/show/2W2eFQ9ddEGzKe3qdZ5Ibe "Listen on Spotify")

[**Pandora Radio**](https://www.pandora.com/podcast/microsoft-cloud-it-pro-podcast/PC:21780 "Listen on Pandora")

[**Podcast Index**](https://podcastindex.org/podcast/436629 "Listen on Podcast Index")

[**Blubrry**](https://blubrry.com/msclouditpropodcast/127816213/ "Listen on Blubrry")

#### Menu

+

[**Apps**](https://player.blubrry.com/?podcast_id=127816213&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE364.mp3&modern=1#)

[**Share**](https://player.blubrry.com/?podcast_id=127816213&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE364.mp3&modern=1#)

[**Download**](https://player.blubrry.com/?podcast_id=127816213&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE364.mp3&modern=1#)

[**Visit Podcast**](/content/site-root.html)

[**Visit Episode Page**](/content/episode364/index.html)

##### Microsoft Cloud IT Pro Podcast

[Open in new window](https://player.blubrry.com/?podcast_id=127816213&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE364.mp3&modern=1) [Display Menu](https://player.blubrry.com/?podcast_id=127816213&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE364.mp3&modern=1#)

##### Episode 364 – Microsoft Designer, Azure Updates, and Enterprise IoT Security changes

\|

[Back 15 seconds](https://player.blubrry.com/?podcast_id=127816213&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE364.mp3&modern=1# "Back 15 seconds") [Forward 15 seconds](https://player.blubrry.com/?podcast_id=127816213&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE364.mp3&modern=1# "Forward 15 seconds") [Play Speed](https://player.blubrry.com/?podcast_id=127816213&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE364.mp3&modern=1# "Play Speed") CC

Podcast: [Play in new window](https://dts.podtrac.com/redirect.mp3/media.blubrry.com/msclouditpropodcast/content.blubrry.com/msclouditpropodcast/E364.mp3 "Play in new window") \| [Download](https://dts.podtrac.com/redirect.mp3/media.blubrry.com/msclouditpropodcast/content.blubrry.com/msclouditpropodcast/E364.mp3 "Download") (Duration: 36:23 — 25.0MB)

In Episode 364, Ben and Scott discuss the recently announced Microsoft Designer, cover a handful of updates to Azure including Azure Automation and Azure Container Storage. Then they close out with some updates to the licensing model for Enterprise IoT Security.

It’s also the season of giving and we’re raising money for Girls Who Code. Donate today at [https://give.girlswhocode.com/msclouditpro](https://give.girlswhocode.com/msclouditpro)!

**Like what you hear and want to support the show? Check out our [membership options](/content/membership/index.html).** [(more…)](/content/episode364/#more-107856/index.html)

## [Episode 359 – Microsoft Applied Skills and Azure Bastion Developer SKU](/content/episode359/index.html)

by [Scott](/content/author/scottmsclouditpro/ "Posts by Scott"/index.html) \| Nov 9, 2023 \| [Podcast](/content/category/podcast/index.html)

Blubrry Player

\|

Auto Scroll

[+](https://player.blubrry.com/?podcast_id=122342047&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE359.mp3&modern=1# "Close Transcription Overlay")

Welcome to episode 359 of the
Microsoft Cloud IT Pro Podcast recorded live on October 31st, 2023. This is a show about Microsoft 365 and
Azure from the perspective of it pros and end users where we discuss the topic or
recent news and how it relates to you. Microsoft applied skills as a new skilling
platform to get hands-on experience in a lab environment that Ben
and Scott dive into today. They also discuss an upcoming roadmap
item related to conditional access policies as well as ways to keep up
with these messages in the Microsoft 365 message center. Finally, they wrap up the show with a
new SKU coming to Azure Bastion, a Microsoft developer SKU that offers a
lower cost option for Bastion with a few less features than the standard SKUs. I had something I was gonna start off
with but now I can't even remember what it was because it's just been that type
of a week where we've meant to record like three different days and
finally got around to it. .It happens, you know,
life comes at you fest. It does, yeah. There was something I
was thinking of that I was like, oh, I should kick off with
that, but it's gone. So we might as well just jump into
whatever else we wanna talk about. Whatever else we wanna talk about.
I have some stuff for you if I. Yeah, we have like a bunch of random news. This is gonna be a random news episode. If I can be so bold as. To Okay. Take over your show for just a moment. So we've talked a bunch
about certification and skilling in the past and just
overall changes in certs and role-based certs and all that stuff, particularly in the context of
Microsoft 365 and the Azure certs, things like that. So a
couple of observations. So one, you and I had to recently renew our Azure infrastructure cert .One of the most interesting things to me
about that beyond like how overjoyed I am, that the new certification process, no recert process no longer
necessitates me going into a facility or sitting online with a proctor.
Like I very much like that, but I was kind of surprised, I don't know if you've kind
of had this same thought, but the score to pass on
research has been dropping and dropping and dropping over time. You and I did that on the
same day and you know, we chatted afterwards and
it was something like crazy. It was like you only needed like a 40%
score to pass it. Yeah. Like not 60, not 70. It was extremely low on the bar. So I thought that
was kind of interesting, like is that because certs are
becoming too hard? I can't say I was a, you know, without
getting too deep into it, I can't say I was a fan
of many of the questions. Like I would say 50% of them
didn't make any sense anyway. So, you know, good luck if you can score 50%. Like maybe that's the thinking ,but I thought it was kind of interesting
that it was a low number of questions and it was potentially a low
bar to pass on that side and I've seen people talking about it
in other places to MAs it on and and threads and, and Facebook
and, and all the socials, let's just say things like that. So I don't know what your thoughts
are on the certification side of it, but really weird kind of strange
experience. Like what, what's the bar? Does the bar drop to 20%? Does it
just drop to 0% in research go away? I don't know that that's valuable. Yeah, so 42% like I can't remember. It's, I wanna say it was like
25 to 30 questions. 42 percent's like getting 10
out of 25 questions, right? Like that would be failing in most cases. And I saw some other people like you
that were talking about it and I think I did see, and I can't remember where, so I don't have the
source that there was some fluctuation in what that
required percentage was
based on the different exams. Like the one we just renewed was the
Azure solution associate or something like that. It's the. Infrastructure one, yeah, the 1 0 4. Yeah. I wonder if the expert ones have a
higher passing score, but I'm with you. Anything that has a 42%, like does it really mean
anything at that point in time? If you can get more questions wrong
than you do, right, like ,that doesn't seem like
you could be certified. ,especially when you have access to the
internet while you take it  likelike right. There's not much of a
timing or a pressure component here. Like you can just whip open a web browser
and do whatever you need to get done there. So. I'm with you. It seems
to be very much diluted. I love the new certification process.
I love the, or the renewal process. I love the fact that you
can use learn in the exams. I haven't actually gone and tried
one yet with that, but I agree. I feel like if you have an open,
essentially an open book policy, the level required to pass
should be going up not down because I do, I think it just dilutes the value of all
these exams that anybody can go get a 42% um, search through
the answers and all that. But I would agree some of
the questions were just like, here's a problem with open book. They have to write 'em so you can just
do a quick search and find the answer. So I feel like they try to
throw a trickery in there, which just leads to some very
convoluted type questions. I don't know, the. Questions have always been convoluted. I feel like this has reached a new
level of convolution though It. Was an eye-opening experience
for sure. But anywho, not to like rabbit hole too much on certs, but I don't know if you
saw these, so there's, there's a new offering out
there from Microsoft in the um, skilling credential space
and it is called Microsoft Applied Skills. Have
you heard of these yet? The name rings a bell but
I don't remember where, I don't remember if we've talked about
'EM before as they were coming or if there were some other calls
that I was on somewhere. These. Are brand, brand new. They came out in between the
time you and I last talked. So this is kind of a hot off,
hot off the presses thing. So applied skills are a new skilling credential. I would say they're a skilling
credential and not a certification. I think there's some, there's some nuance there in in
the way they're positioned and what they are meant to do. But broadly, I think if you take a step
back and you think about it, so the role-based
certifications are there to validate and verify technical
proficiency or technical proficiency in the context of
concepts. So conceptually, you know like in the case of like
an IS exam, what's AVA versus a vm, how do those compose And then maybe some
down in the weeds kind of nitty gritty like what's a constraint of deploying
a fashion host or a firewall in this kind of vnet or peering these
kinds of things or what does container storage do with blah
blah blah kind of thing. But I think that's more high level even
though it can get down into specific questions, it it's still broad, it's very wide and maybe not
as deep as it can be due to the breadth that's there. So certifications, when you pass the certification exam
they come with a certificate that says hey we have validated and we being
Microsoft in this case has validated your technical proficiency
in in this given area. Like within this
set of skills, again, we're thinking like kind of like width
or breadth of over depth kind of thing. And applied skills kind of
come at it from another angle. And I actually really like this 'cause
I've been kind of pining for this potentially in Microsoft
exams for a long time in that applied skills validate
your technical proficiency in a specific skillset or area. So where a certification
exam today for the most part, most of the certs that are out
there are role-based certifications. There are some specialty ones but
even those don't get you like hands-on keyboard to validate applied skills
are project-based and they get you hands-on keyboard in an interactive
lab like a real live in the case of Azure, Azure environment. Not like one of the goofed out faked
out environments like in a certification exam. But more like an honest to goodness
like hey we're gonna spin this up and validate that you can do A, A, B, C and D along the way
and accomplish a specific set of tasks in you know, kind of a prescriptive amount of time
to validate that you know what you're doing. So rather than validating
technical proficiency for width and not depth, this is kind of like going the other
way and saying hey let's pull it in and ringfence it and get super
specific like maybe we talk about storage versus just Azure
Monitor and those are both different applied skill things
that you can go and take. So they're all on demand. Like it's not like a certification
exam where you need to sign up online, go find a Pearson Center or schedule
time with a proctor like just on demand in a web browser through
the portal through clouds shell, through whatever kind of
tooling you have along the way. And they have a whole bunch of these out. Like there's not a lot but I actually
consider it like a pretty good set to start with. So there's securing your
storage with Azure files and blob storage, there's an applied skilling
course Azure Monitor, there's deploying containers using AKS, there's implementing security
through Azure DevOps, there's even one on configuring
your C and and your security operations doing like all your
SecOps using Microsoft Sentinel. Keep forgetting all the
renames that they have in here. There's one on power Automate, create and manage automated
processes by using Power Automate. And then there's a whole bunch more
of them that are supposedly coming and are going to be announced at
Ignite in November along the way. And just like a certification gives
you sitting down for a role-based certification and passing it gives you
like a piece of paper a a cert that says hey you've done this thing and applied
skilling course when you get out the other side, should you meet all the requirements
of the project that you're given, you too will get a verifiable credential
on that side to say like Hey I went tinted this thing, I don't know in like I'm kind of 50
50 on it but in many cases, you know, I think it's really kind of cool like
I might actually look for people with hands-on keyboard experience in the case
of a verified credential and applied skilling over sometimes
the width that comes with a role-based certification exam. Yeah, we'll have to go give some of these a try
because like you said there's eight of 'em right now primarily
in the Azure space. Uh, I think there's one GitHub that
you could argue asp.net core web app that consumes an API with
GitHub if that's Azure or not. There's the one Power automate one, there's one for Microsoft Defender
for cloud which is still kind of Azure and then there's like
six Azure ones. So it is, I'm gonna have to go give
one or two of these a try. There's nothing really around
Microsoft 365 yet unless you consider Power automate Microsoft 365. And I'm wondering if that's just a harder
environment to create one of these in. I feel like standing up an Azure
resource or doing some stuff with Azure networking or core web apps, that's a lot easier to spin up like a
hands-on keyboard skilling environment with that than like a brand new
Microsoft 365 tenant with the right data and stuff to actually
do anything meaningful. A couple of things to
watch for with this one. I would encourage folks to
go and take some of them. I think Microsoft has been overly
ambitious  maybe in theircategorization of some of
these and maybe I'm, I'm, maybe I'm too close to some of
it. Like I will fully admit that. So like I went and took
the the blob and files one and it's tagged as an intermediate
and it's really more like level 100 like hey beginner. Yeah getting
hands on with these kinds of things. So that's okay. I think, you know,
that gets figured out over time. One of the other kind of thoughts
that I had and I saw it pop up a lot in the comments on the tech community
post about this one as well was does this dilute the value of certifications
like those role-based certs in some way? 'cause you're gonna see folks that are
gonna go out much like they do with certifications today where
they take like 10 certs. You're gonna see somebody go out and
take like 50 applied skilling things and just bang, bang, bang,
bang, bang, bang bang, like do them all and all of a sudden
you're gonna walk out the other side with having a hundred Microsoft
credentials  insideof a inside of a week kind of thing. And I've actually seen some
of that on LinkedIn already, like a whole bunch of like, hey I did
this, I did this, I did this. Like yeah, I, okay, you took a hands-on lab,
I got it . Right, all good.Glad that you did it kind of
thing. Glad you did it in general. I I like kind of the, the diversity
that comes from this like you know, for the folks that need it, I would also potentially look at it as
a way for people who are looking at the certifications. Like if you're looking for other ways
to get hands-on and validate before you take a cert, potentially good for that as well because
I think that's one of the things that often misses in certification land, particularly in like the weird era we're
in now where brain dumps and things are accessible and people do do those
kinds of things right? Like you know, maybe you have less motivation to do
that if you can just go get hands-on in what is today a free way to do it. Like they're free for now I have to
imagine these cost money at some point because they are running
up services and compute just to get them done. Like you're, you're in a real Azure
environment when you're doing it. One last kind of thing to watch for
with these is certification still, and I think you're mindful of this, still count towards things like partner
requirements and meeting the bar to be in the, the partner network or one of
the ISV programs at Microsoft and these credentials
from Applied Skilling currently do not apply to
things like the partner program. So if you're in say like the cloud
partner program and and you're an ISV in there or you're doing kind of the legacy
MPN thing and haven't fully rolled over to one of the new partner programs yet, these do not count for, they do not count for that. Well and I don't know
if you mentioned this, I didn't realize when you were saying
to the assessments that these are also still timed. So if you go in to sign
up for one of these assessments. Yeah they are. Yeah it gives you a learning path similar
to the certification like for the sim for Sentinel, they have a learning path
through Microsoft to learn
that they recommend you go through for Sentinel and
then the assessment it does
say you will have two hours to complete it. So it's not like you can just go in and
take this assessment and take your time working your way through it and looking
for all the answers and how you do stuff. And again, I haven't taken one yet so I don't
fully know what the experience is, but you do have a time limit in order
to complete it and I can imagine one, it's maybe to validate that you do
know it but to your point also is that they're spinning up resources, they just don't want a bunch of
these running for 5, 6, 7 hours if you take a day to complete it. They wanna be able to spin up
resources and spin them back down to save on their backend cost for. These over time. I imagine these almost have to cost
money and and I think that's even weirder when you try to position them like
now where do they sit in the world of, well I already have an Azure environment, like maybe I'm like a visual
studio subscriber or I get
access to Azure through my employer or M 365, like wherever
these things end up baking out. Like if you have access to
power automate licensing, like is the credential the important
thing or is the hands-on time with it important? I have seen some things, you know on the socials as well about
them potentially being a little bit buggy and like timing out kicking you out of
the environment and you can't get back in for a couple days so your
mileage may vary. Yeah, it's relatively new like this
totally came across as kind of like a pre-announcement like hey here's a little
bit that we have going on just to give you a tease and you know there
should be some more about it at Ignite. Huh? We'll have to watch Ignite and see
what comes out. But that is interesting. I'm gonna have to go take at least
one of these and see what it's like. You should. Do the power automate one, do one that
like you're familiar with, like I said, I I did the blob one, do the
power automate one just to see, just to see what you think about the
way it's frame framed up or if there's another one in there. I know you've been spending a bunch
of time on Sentinel and a couple other things. Yeah I might do Sentinel too. Yeah. But go go in blind  like definitely
take it blind and see how it goes.Do you feel overwhelmed by trying to
manage your Office 365 environment? Are you facing unexpected issues that
disrupt your company's productivity? Intelligent is here to help much like you
take your car to the mechanic that has specialized knowledge on how to best keep
your car running Intelligent helps you with your Microsoft cloud environment
because that's their expertise. Intelligent keeps up with
the latest updates on the
Microsoft cloud to help keep your business running smoothly
and ahead of the curve. Whether you are a small organization with
just a few users up to an organization of several thousand employees they want
to partner with you to implement and administer your Microsoft
Cloud technology, visit them at intelligent.com/podcast. That's I-N-T-E-L-L-I-G-I-N k.com/podcast for more information
or to schedule a 30 minute call to get started with them today. Remember intelligent focuses on the
Microsoft cloud so you can focus on your business. Alright Scott, so I
have another question for you. Yeah. Have you ever wanted, I don't
know if I wanna do that roadmap item, let's do this roadmap item, that
roadmap item's a little ranty. This one is a little interesting
and I think something that people should be aware
of is I saw this one come across and I'm curious to
see how it comes to fruition and how it gets rolled
out because this is, it's almost going back to something
Microsoft used to did used to do. So this was added to the
roadmap back on October 24 and starting in November. So I mean it could start already
tomorrow from when we're recording, we're recording on the 31st. By the time people hear us
this may be well underway. Microsoft is gonna start automatically
protecting customers with Microsoft managed
conditional access policies. So what it sounds like Microsoft is doing, and we just spent a little time digging
through this and looking through what we could find, I cannot find any docs on it
like un learned@microsoft.com or any official announcement
in tech community or any of that. But Microsoft is going
to create and enable a and this, I found this on Twitter, you told me to get off Twitter but I'm
still on it and this is where I found it. They're gonna create a Microsoft
managed and MFA for admin portals. So forcing MFA for accessing
all your admin portals, MFA for per user MFA users. So I think this may be in kind
of advance of maybe trying to get away from the per user MFA that's
considered legacy at this point in time. And then MFA for high risk sign-ins, which high risk sign-ins is a Azure ADP two feature. Mm-Hmm .
So I'm assuming that.It is. They're also gonna look at a. Little bit of upsell in there, right? I'm assuming like maybe they look
at your licensing if you don't have any Azure AD premium, maybe they're still doing security
defaults and if you have P one you'll get like the first two admin portals and
per user MFA and if you have PE two maybe they'll add and enable
the MFA for high risk sign-ins. But if you aren't paying attention and
someday you randomly go in and you have all these new Microsoft
managed conditional access
policies or M FFA starts behaving differently in your tenant, this could be what's happening
And they do say in the Microsoft 365 roadmap that all eligible tenants
will be notified prior to this rollout. So you should get a notification. The other thing I have not seen anything
about is like I already have some of these policies or policies that meet
this criteria enabled in my tenant. So if you already have these,
will Microsoft just not add them? Will they kind of intelligently look at, oh they already have an MFA policy that
covers admin portals so we're not going to deploy it. Will they still push
it out there but not enable it? If you disable one of these, will
they automatically get re-enabled? There's a lot of interesting things
because of the effects conditional access can have on your tenant as to
how this will actually function going forward. TBD, so there's some, there's some weird
language in the roadmap side of things. So it says all eligible
tenants will be notified. I'm imagining that like in the
back of my head I'm thinking great, you're gonna have to go and
watch the message center. Like that's how you're gonna be
notified if you are eligible, right? So hopefully they are looking
at those licensing components like and figuring that out like
the whole ADP one versus P two and and kind of how that manifests.
So like makes sense, right? I think they that they should do
that but really, really weird. Like what are they gonna
consider eligibility here? Is it going to be based on your licensing? Is it gonna be based on some kind
of like minimum threshold for licensing? Like not a ton of clarity in how that one, how that one manifests itself. So yeah, especially with kind of the broad coverage
right between MFA for admin portal MFA for per user MFA and then
like you said the MFA for high risk sign-ins as well. Yeah. And the fact that it technically
could start hitting tenants tomorrow and there's no, again, there's no
documentation that I could find. The only thing I've found
from Microsoft official is the roadmap item. To. Be fair, the roadmap does, item
does say you'll be notified, right? I speculatively think that hey, that means you're gonna get a message in
the admin center. My concern there is, and and I've seen this time
and time again as Microsoft rolls out these new things is
people don't read the admin center no matter how many times they've sent
you the message, you don't see it there. So I get that's not Microsoft's
fault that you know, we as customers aren't following along
and that they're doing everything they can to enter into this world of
kind of secure by default posture. Like hey really can't
fault anybody for that. It would be great to see them do more
messaging about how to and more kind of prescriptive guidance about how to
stay up to date with these things. Like I would love to see, you know, like a targeted campaign
going out to M 365 subscribers, particularly tenant
uh, admins or service admins, uh, who are also potentially gonna be going
in and looking at those things or the folks who are responsible for change
management in an organization just to get them up to speed and help them
understand things like best practices for cadence to check the message center. Where do those emails come from to
make sure that you know, they're, they're not being black hole someplace
in your spam filter or something else. Like, you know, I think Microsoft is
really good about telling you like, uh, hey we run this service
under these ipss or you know, these are the FQ DNS that you need
to potentially whitelist in your firewall for outbound communication. Like you need to be able to go for like
M 365 to like this blob storage account to be able to download this thing. They give you all that knowledge in the
docs but they don't necessarily give you the other side of it, which is like what should I as a
customer be looking out for and how often should I be doing it and what's the
right cadence for me to be doing it? All right, so like should I be looking
at the message center daily, weekly, monthly, what are the email addresses these come
from and how do I make sure that they're not sent into the black
hole abyss of a spam filter? Heck, what's the email
address you send it to? Like we've talked in the past about
like the whole like Azure thing with admins versus COAD admins
and how like, you know, service alerts and resource health
alerts and things like that come out. Like it's a bit ambiguous about who gets
emailed when these things happen and whether the folks getting emailed even
have like valid mailboxes, . So,and I'd love to see Microsoft just
do a little bit more on that side. Yeah. And the message center in Microsoft
365 since we're talking about this, has gotten a little bit
better in terms of email. Like if you go into the preferences
you can go customize your view and choose which messages you wanna show or
which services you wanna show messages for. And then they do have an email tab where
you can receive email notifications to the primary email and it'll tell you
which one it is or other email addresses and then choose which emails you want
to get emails for major updates. But. You have to go in and do that stuff. But you do have to go in and do it if. Nobody ever tells you to do it, how do
you know to do it True? Like it's a, it's a little bit of a chicken
egg problem there and over time, like as they've adjusted the message
center and they've kind of opened it up to you know, restricting certain admin roles from
having access to it and then opening up like specific roles that have access
to it for like folks in your change management organization
or things like that. Like I don't always know that that
next click stop happens of actually communicating like, great, I gave you access now here's what I
expect you to do with that access. Yeah. So that everything goes
down the happy path. There's also something I've
played with this before, I don't use it because
it's really just me, but another interesting feature that
they do have in the Microsoft 365 message center is planner syncing.
So if you do use planner, you have like an IT team that
you want watching all of these, while they may not have
access to the message center, you can set up planner syncing so
that you can sync tasks into planner based on these updates to the message
center, assign people, handle them, archive them off, know that somebody's
seen them, et cetera, et cetera. Yeah. Then you need to use planer. .That's tough that that's a
tough hill to climb. .Is. True. I'd never seen that one that that
one's actually, that one's interesting. Yeah. I tried it and again for me it
was just too much because I'm the only one that caress about 'em. For me it's just as easy to go into my
message center but to your point about how often I don't do it
as often as I should. If you are running Microsoft 365, you
should absolutely be doing it daily. There's usually at least a handful
per day. And then other days, I was just flipping
through mine October 26th, they must have gone through
and updated a bunch of items. There were 27 updates or
messages to the message center on October 26th. It looks like it was maybe
seven or eight of the new messages and then they updated like
20 of 'em. Which could be timelines, it could be usually it's
just timelines updated. Yeah, a lot of these are just, we updated the rollout timeline
of when it's gonna happen. It's going slower than we thought,
faster than we thought, et cetera. But absolutely Microsoft 365 message
center. If you're not doing it daily, you should be doing it daily if you care
or if you just wanna live on the edge, just wait until something
random pops up. .Wait until one day you log into your
tenant and purple is green and it's all just upside down. Exactly. One other news, Scott, I have another roadmap item but I
might get ranty on that one. .Depends. On if you want me to rant. Sure. If. You you wanna rant, you can rant. Or do you wanna actually do news? What
are you highlighting over here? We. Can go back to Agile land
for a little bit if you want. Let's go back to this one 'cause this
one intrigues me and I hadn't seen this one yet. Deploy Bastion. Yes. So, so we've talked about Bastion
in the past. I think one of the, one of the friction points
with a lot of Azure SKUs is pricing. Like how do you get
hands-on with these things with like minimal experience? What's the right way for you to
get in and not spend the absolute most money possible upfront? And some services like
Bastion can do that they can, they can run away from you a
little bit. Like, you know, you've got a bunch of different
things going on there. So one of the new things
that happened with Bastion is they recently
announced a new developer SKU that's available. So it's,
it's out in preview, you know, preview comes with restrictions. So it's only in a couple end
user acceptance regions that are out there. North central
us, west Central us, west Europe and North Europe
to kind of go ahead and get started with it. But I didn't
see pricing published with it. But it's called out in the doc like the
pricing page on like azure.com hasn't been updated with the new SC U yet, but all the docs are out
there on Microsoft Docs. So TBD what the cost is but it's
gonna be lower cost than anything else that's out there for bastion
today. So it's a dku, it's missing a couple things,
particularly like scaling, like you're not gonna have any kind
of scale out operations in there. You're not gonna have any kind
of advanced security features, anything like that. You absolutely
are still going to need, you know, bastions for accessing
your virtual machines in a vnet. So you still need V nets and virtual
machines and the right roles and the right ports and protocols and just
all those kinds of things set up and ready to go for you. So I think the big differences with the developer SKU and there's some really
interesting differences in here.  the developer SKU
can't RDP to a Linux machine.But then again neither can
the basic SKU of Bastion, which honestly I never realized this
and explains a whole lot about the last couple times I've deployed Bastion and
have not been able to RDP to my Linux host .Like that makes a whole lot of sense
now and it's never told me that in the portal it will not do SSH
again or does the basic sku. There's no customization
around things like ports. So customizing, import, customizing,
inbound ports, anything like that. Funny enough from an
authentication side, like we, we should talk in the future about how
Microsoft has been doing a bunch of messaging around to like the future of
NTLM versus BERROS and things like that. But even though you can only
connect to Windows hosts, you can't do any type of
curb off end to that. So I, I thought that was kind of interesting. You also don't have the ability to
do some of like the advanced security controls like disabling copy paste, anything like that along the way. And then I think I called it
out but no scaling either. You can't also connect to VMs
that are across peered fee nets. So you can do that with both the basic
and standard SKUs. So like I said, uh, TBD to see where pricing
falls for this one. But in general like I really do like
to see these kinds of things come up because the less friction and less cost
you put in place of getting hands-on with these types of services, ultimately the broader deployment
you can kind of drive downstream. I think it is a really nice like carrot
to hang out there and get customers comfortable with it and say they just get
comfortable with it through the portal or whatever and then they're
ready to move on to you know, PowerShell for deployment
or arm templates, things like that because
it's just a skew of bastion. It's not like a whole net new resource
provider or anything like that. Like it's kind of immaterial and and
trivial to go ahead and do things like move from the portal to a deployment
script using PowerShell or the CLI bicep arm templates, any kinds of those, any kinds of those things. Interesting enough you can also
upgrade from the developer SKU to the basic or standard tiers. So that's very
nice to see as well. Like you can start, you can get started with it, maybe you find there's some friction or
a limitation there and now that you're comfortable with the service you just
want to go ahead and upgrade and get yourself to where you need to be. But it's really just bastion with
a lower cost and a lower set of features that are associated with, like
I said like all the other prerequisites, they all stay the same. Like need to
make sure you have enough address space, need to make sure you've
got a vnet with uh, a subnet with enough address
space for that bastion host. You know you gotta be using
standard port, standard protocols, all those kinds of things. Yes, I like this one as well
'cause I think you talk about getting familiar with it
but I also see this as a way for you to better secure
your infrastructure. It helps maybe Microsoft from a security
standpoint because if you ever wanna have some fun turn on a
VM you don't care about, you're too cheap or you
don't want to deploy Bastion. So you just leave port 33 89 open to the
internet and don't bother like limiting it to just your IP address or something
and watch how long it takes for that server to start getting uh, hammered with
people trying to log into it remotely. It's incredible. So by turning
on something like Bastion two, you reduce that risk, make it a little bit more secure
from that remote access standpoint. And a lot of these already
servers are already ping into, tend to be kind of in line
with the developer skew. They tend to be to be developers that
need ARDP into a server to deploy something, to set something up. So having a lower cost skew
to just get Bastion going and have some additional security around
that remote access to VMs for your developers is going to be a
nice option because Bastion does add up quickly. It's one of those services that you look
at the pricing and you don't think it's a big deal, right? It's 19 cents per hour for the
basic 29 cents for standard, but then you start reading all the fine
print that it is billed hourly from the moment it's deployed until the is deleted. So if you're turning this on
for unlimited access to your vm, it's 19 cents an hour per hour every
day you're paying $4 and 50 cents a day times what? 30 ish days? It adds up to $135 a
month or so for Bastion unless you're actually going in and
creating it and deleting it every time you need to access the server. I wanna see where the pricing lands for
this one because even the developer sku, at least from the documentation side,
is still gonna be priced at the, that per hour price. That way per hour. Pricing. So you know, if it comes
in at 15 cents versus 19 cents, I don't think that's a material thing
that's gonna move, move the needle. We'll see how low it can go given it
doesn't have any needs for auto scale or anything like that. If I was to guess, even
looking at like standard basic, it's a 10 cents per hour. If they could get it down to
like nine or 10 cents per hour, kind of half the cost or
literally move it down, I would love to see that where
it's in the ballpark of like 60, $65 per month. I wonder if I go deploy one and just
crank it up like I see if it shows up in cost management or something. Who
knows if the meters are rolled out yet. We'll see. , I like that one. I'm
going to maybe go turn that on too.'cause I have used Standard, I've used that quite a bit for
different VMs that I deploy. I use Bash in a bunch of places and
I feel like every time I use it, like I'm compelled to tear
it down because of the price. 'cause lots of the things I'm
doing are dev test scenarios. I get that automation's there. But realistically like if
I'm doing something to play
around for a couple weeks, like it's way easier for me to just
keep it on and just pay the cost of it and it would be way
nicer if that cost was less. You do better than me. I'm even cheaper. I just don't deploy it and I go modify
my NSG to only allow RDP access from my IP address. There are places that I have to deploy
it like I'm compelled by policy. You must. Fair enough. Alright, well that maybe does it
for the news for today. I think I've got stuff to go
do that is Halloween today and I have pork to pull for dinner and stuff to set up outside because we are in
Florida and we just hang out outside all evening ,unlike those northerners that I talked
to up in Chicago in Michigan today where it just snowing up there. It's. Gonna be another balmy 80
degree Thanksgiving here in
Jacksonville, Florida. So. Halloween Thanksgiving's
a few weeks away. Yeah. Halloween, Thanksgiving, they, they all,
they all blend together after a while. One of those holidays,
the fall holidays turns. Out they're both events where uh, people get dressed up and just eat a
bunch of candy in the United States. So it's. True. I would argue though
the Thanksgiving food is
way better in the us It. Is. I'm in it for all
the pies for dessert. Oh yes, absolutely. I need to go see which houses have
good candy that I need to go trick or treating with my kids and grab some
or bribe them to get me some extra. Yours are still young enough to do
it. All right, well I'll let you go. Enjoy your Halloween. Thanks
and we'll chat again. Alright. Enjoy your uh, Halloween as well
and we'll talk again soon. Thanks. Ben. If you enjoyed the podcast, go leave
us a five star rating in iTunes. It helps to get the word out so more
it pros can learn about Office 365 and Azure. If you have any questions you want us
to address on the show or feedback about the show, feel free to reach out via
our website, Twitter, or Facebook. Thanks again for listening
and have a great day.

#### Donate

[+](https://player.blubrry.com/?podcast_id=122342047&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE359.mp3&modern=1# "Close Boosts Menu")

#### Share

[+](https://player.blubrry.com/?podcast_id=122342047&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE359.mp3&modern=1#)

[**X (Twitter)**](https://twitter.com/intent/tweet?url=https%3A%2F%2Fwww.msclouditpropodcast.com%2Fepisode359%2F&amp;text=Episode+359+%E2%80%93+Microsoft+Applied+Skills+and+Azure+Bastion+Developer+SKU "Share on X (Twitter)")

[**Facebook**](https://www.facebook.com/share.php?u=https%3A%2F%2Fwww.msclouditpropodcast.com%2Fepisode359%2F&amp;t=Episode+359+%E2%80%93+Microsoft+Applied+Skills+and+Azure+Bastion+Developer+SKU "Share on Facebook")

[**LinkedIn**](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.msclouditpropodcast.com%2Fepisode359%2F "Share on LinkedIn")

#### Apps

[+](https://player.blubrry.com/?podcast_id=122342047&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE359.mp3&modern=1# "Close Apps Menu")

[**Apple Podcasts**](https://itunes.apple.com/us/podcast/microsoft-cloud-it-pro-podcast/id1226241819 "Listen on Apple Podcasts")

[**Spotify**](https://open.spotify.com/show/2W2eFQ9ddEGzKe3qdZ5Ibe "Listen on Spotify")

[**Pandora Radio**](https://www.pandora.com/podcast/microsoft-cloud-it-pro-podcast/PC:21780 "Listen on Pandora")

[**Podcast Index**](https://podcastindex.org/podcast/436629 "Listen on Podcast Index")

[**Blubrry**](https://blubrry.com/msclouditpropodcast/122342047/ "Listen on Blubrry")

#### Menu

+

[**Apps**](https://player.blubrry.com/?podcast_id=122342047&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE359.mp3&modern=1#)

[**Share**](https://player.blubrry.com/?podcast_id=122342047&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE359.mp3&modern=1#)

[**Download**](https://player.blubrry.com/?podcast_id=122342047&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE359.mp3&modern=1#)

[**Visit Podcast**](/content/site-root.html)

[**Visit Episode Page**](/content/episode359/index.html)

##### Microsoft Cloud IT Pro Podcast

[Open in new window](https://player.blubrry.com/?podcast_id=122342047&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE359.mp3&modern=1) [Display Menu](https://player.blubrry.com/?podcast_id=122342047&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE359.mp3&modern=1#)

##### Episode 359 – Microsoft Applied Skills and Azure Bastion Developer SKU

\|

[Back 15 seconds](https://player.blubrry.com/?podcast_id=122342047&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE359.mp3&modern=1# "Back 15 seconds") [Forward 15 seconds](https://player.blubrry.com/?podcast_id=122342047&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE359.mp3&modern=1# "Forward 15 seconds") [Play Speed](https://player.blubrry.com/?podcast_id=122342047&media_url=https%3A%2F%2Fdts.podtrac.com%2Fredirect.mp3%2Fmedia.blubrry.com%2Fmsclouditpropodcast%2Fcontent.blubrry.com%2Fmsclouditpropodcast%2FE359.mp3&modern=1# "Play Speed") CC

Podcast: [Play in new window](https://dts.podtrac.com/redirect.mp3/media.blubrry.com/msclouditpropodcast/content.blubrry.com/msclouditpropodcast/E359.mp3 "Play in new window") \| [Download](https://dts.podtrac.com/redirect.mp3/media.blubrry.com/msclouditpropodcast/content.blubrry.com/msclouditpropodcast/E359.mp3 "Download") (Duration: 39:46 — 27.3MB)

In Episode 359, Ben and Scott discuss Microsoft Applied Skills – a new skilling platform for Microsoft customers to get hands-on in a live, on-demand lab environment to validate their skills in a specific area and how Applied Skills compares to the existing role-based certification exams. Next up, it’s a quick review of an upcoming roadmap item that impacts Microsoft-managed conditional access policies and how to monitor and keep up to date with Message Center messages that are applicable to your tenant. Then it’s time to wrap up with a Developer SKU that was recently launched for Azure Bastion, offering lower cost to Bastion at the expense of some of the bells and whistles in the Basic and Standard SKUs.

**Like what you hear and want to support the show? Check out our [membership options](/content/membership/index.html).** [(more…)](/content/episode359/#more-107775/index.html)

[« Older Entries](/content/tag/azure-active-directory/page/2/index.html)

Buy us a Coffee

Name

FirstLast

Email

Product Name

Small - $2.00Medium - $3.50Large - $5.00

Total

Payment Method

PayPal CheckoutCredit Card

MasterCard

Visa

Supported Credit Cards: MasterCard, Visa

Credit Card Number

expiration-monthexpiration-yearcvv

Card Number
Expiration Date

Expiration Date
CVV

Security CodeCardholder Name

×

Contact Us

## Contact Us

Contact Form

Name

This field is for validation purposes and should be left unchanged.

First Name

Email

Question or Comment

Add me to the mailing list

Signup to be notified when new podcasts are published, participate in listener surveys and give input into future episodes!

Sign me up!!

This field is hidden when viewing the form

Tags

Checking your Browser…

Verify you are human

Verifying...

Stuck? [Troubleshoot](https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/f/ov2/av0/rch/414x2/0x4AAAAAABh-SZFCMkOolwy3/auto/fbE/new/normal?lang=auto#refresh)

Success!

Verification failed

[Troubleshoot](https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/f/ov2/av0/rch/414x2/0x4AAAAAABh-SZFCMkOolwy3/auto/fbE/new/normal?lang=auto#refresh)

Verification expired

[Refresh](https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/f/ov2/av0/rch/414x2/0x4AAAAAABh-SZFCMkOolwy3/auto/fbE/new/normal?lang=auto#refresh)

Verification expired

[Privacy](https://www.cloudflare.com/privacypolicy/) • [Help](https://challenges.cloudflare.com/cdn-cgi/challenge-platform/help)

×

Microsoft Cloud IT Pro Podcast

Episode 429: Getting started with LLM Wikis

Microsoft Cloud IT Pro PodcastMicrosoft Cloud IT Pro Podcast

Episode 429: Getting started with LLM WikisEpisode 429: Getting started with LLM Wikis

More

Speed: 50%Speed: 75%Speed: NormalSpeed: 125%Speed: 150%Speed: 175%Speed: DoubleSpeed: Triple

Back 15 seconds

Forward 60 seconds

More

more

Speed: 50%Speed: 75%Speed: NormalSpeed: 125%Speed: 150%Speed: 175%Speed: DoubleSpeed: Triple

Back 15 seconds

Forward 60 seconds

Currently Playing

[Download](https://dts.podtrac.com/redirect.mp3/media.blubrry.com/msclouditpropodcast/content.blubrry.com/msclouditpropodcast/E429.mp3)

More

Notifications

PayPal
