PLAY PODCASTS
The Azure Security Podcast

The Azure Security Podcast

126 episodes — Page 2 of 3

S1 Ep 77Episode 77: Securing Infrastructure as Code (IaC)

This week, Michael, Mark and Gladys talk to Anthony Shaw about some of the best practices and tooling for securing Infrastructure as Code (IaC) solutions. Sarah is away in Singapore, presenting at BlackHat.We also cover security news about DDoS, Cosmos DB, Microsoft Defender for APIs, Load Balancer, Zero Trust and discovering Internet-facing devices.

May 19, 202340 min

S1 Ep 76Episode 76: Microsoft Security Research Insights

In this episode Michael, Sarah, and Mark talk with guest Negar Shabab. We also discuss Azure Security news about new Confidential Computing VMs, SQL Server, T-SQL Parsing, Auditing in Azure SQL DB, Sentinel and more.Make sure you go to The Microsoft Azure Security Podcast (azsecuritypodcast.net), because Mark ordered pizza during the recording.

May 3, 202326 min

S1 Ep 75Episode 75: What's new in Microsoft Defender for Cloud

In this episode Michael, Sarah, Gladys, and Mark talk with a good friend of the Podcast, Yuri Diogenes, about the latest Microsoft Defender for Cloud news.We also discuss Azure Security news about Trusted VM Launch, Chaos Studio, Azure SQL DB, DDoS protection, Confidential Containers, Firewall and more.

Apr 14, 202336 min

S1 Ep 74Episode 74: What's New in Azure Policy

Michael and Mark talk to Kemley Nieva from the Azure Governance team about some of the recent updates and improvements to Azure Policy. We also cover the latest Azure security news covering Microsoft Security Copilot, Azure Functions, SQL Managed Instance, Azure Backup, Ephemeral OS disks, Azure Cache for Redis, Azure SQL Database, Azure Monitor, API Management, Azure Maps and Storage.

Apr 7, 202335 min

S1 Ep 73Episode 73: Microsoft Defender for Cloud as Code

In this episode Michael and Gladys talk with guests Sean Wesonga and Bojan Magusic about using Infrastructure as Code (IaC) with Microsoft Defender for Cloud. We also discuss Azure Security news about new Azure SQL Database migration abilities for authentication and Transparent Data Encryption (TDE).

Mar 23, 202327 min

S1 Ep 72Episode 72: What's top of mind for the hosts and career advice!

In this episode Michael, Sarah, Gladys and Mark interview each other! The Podcast is almost three years old, and things have changed for each of us, so we thought we'd re-introduce ourselves, reflect, give career advice, and talk about what's top of mind for each of us!We also discuss Azure Security news about SQL Server and Azure SQL DB, MFA and AAD, AAD and IPv6, new SC-100 study guide and more.

Mar 8, 20231h 1m

S1 Ep 71Episode 71: Azure SQL Database and Always Encrypted using Virtualization-Based Security Enclaves

In this special episode, Michael sits down with Pieter Vanhove about a new addition to the SQL Server 'Always Encrypted' family. The new addition, Virtualization-Based Security Enclaves (VBS), is now in Preview and allows for more scalability and lower cost when using secure enclaves compared to the current SGX-based enclaves.

Feb 15, 202328 min

S1 Ep 70Episode 70: Microsoft Purview

In this episode Michael and Sarah talk with guests Beau Faull and Lou Mercuri about some new features and updated naming in Microsoft Purview. Beau and Lou are also co-hosts of the Coast2Coast Podcast on YouTube.We also discuss Azure Security news about Trusted Boot VMs, Sentinel and Defender for Cloud.

Feb 13, 202334 min

S1 Ep 69Episode 69: Secured Supply Chain and Software Bill of Materials (SBOM)

In this episode, Michael and Mark talk to Adrian Diglio about Software Bill of Materials and its role in helping secure the software supply chain.We also have news items about SQL Server, Azure SQL DB, Azure Database for PostgreSQL, Azure Database for MySQL and Application Secure Groups and Private Endpoints. Mark goes over MCRA, Immutable Laws of Cybersecurity and Security Architecture Design.

Feb 2, 202327 min

S1 Ep 68Episode 68: SQL Server 2022

Michael sits down with Ajay Jagannathan who is the Principal Group PM Manager for SQL Server. Michael also covers a couple of SQL Server related news items.

Dec 7, 202233 min

S1 Ep 67Privileged Access

Michael and Sarah talk to Bronwyn Mercer from Microsoft Australia about Privileged Access as well as some ideas and processes to help you succeed. Also, the latest security news about Managed HSM, Defender for DevOps, TLS and ARM, SQL Server 2022, Application Gateway.Finally, 'Designing and Developing Secure Azure Solutions' is now available. https://azsec.tech/get

Nov 24, 202232 min

S1 Ep 66Workload Identities

In this episode Michael, Sarah and Mark talk with guest Joey Snow about Workload Identities in Azure. We also chat about least privilege and privileged accounts in general. Finally, the latest Azure Security news about: Azure Front Door, Log Analytics, Web Application Firewall and AKS SSH keys.

Nov 11, 202231 min

S1 Ep 65Microsoft Defender for Threat Intelligence

EDIT: Nov 11th, there was an error at around 27m; Gladys and Rijuta were talking over each other. In this episode Michael, Sarah, Gladys and Mark talk with guests Rijuta Kapoor and Brandon about Microsoft Defender for Threat Intelligence. We also discuss Azure Security news about Azure Service Bus and TLS, PostgreSQL, VMs, SQL Server and Confidential VMs, Azure SQL DB, Workload Identities, Microsoft Entra and other security news from Ignite.

Nov 4, 202238 min

S1 Ep 64The SQL Server Permission Model Explained

In this special, out of band episode, Michael talks to Andreas Wolter about the SQL Server and Azure SQL Database permission model. To many, the model is a mystery, but Andreas explains how it works as Michael poses security challenges.

Oct 15, 202246 min

S1 Ep 63Microsoft Entra Permissions Management

In this episode we talk to Nick Wryter about Microsoft Entra Permissions Management. We also cover the latest security news about Azure Firewall, Azure Database for MySQL, NetApp files, ADLS Gen2, AKS, Conditional Access and Identity Federation.

Oct 7, 202235 min

S1 Ep 62Microsoft Defender for Endpoint Tamper Protection

In this episode, Josh Bregman discusses a critically important feature in MDE - Tamper Protection which helps prevent unwanted changes to your security and essential functions.We also cover the latest security news about Synapse SQL, Service Bus, Storage, Redis, Azure SQL, MySQL, AKS, Managed Disks and Microsoft Defender.

Sep 28, 202229 min

S1 Ep 61Securing Operational Technology (OT)

In this episode we speak to Elizabeth Stephens about practices and philosophies for protecting OT. We also cover news about SQL MI, Private Endpoints, Load Testing, TLS 1.3, AKS and Confidential VMs and Azur Firewall.Also, this is the first episode to use the phrase "things that are not supposed to blow up!"

Aug 26, 202234 min

S1 Ep 60Microsoft Defender for Cloud - AWS and GCP

In this episode, we talk to Safeena about Begun about Microsoft Defender for Cloud to monitor multi-cloud environments including Azure, on-prem, AWS and GCP. We also talk about changes coming to Azure's root CA certificates, Microsoft Entra and more.

Aug 23, 202245 min

S1 Ep 59Chief Information Security Officer (CISO) Workshop

In this episode Michael and Sarah talk to Mark about the newly version of the CISO Workshop. We also have news about Confidential Ledger, Gateway Load Balancer (new!), Azure Database for MySQL and Trust Launch.

Aug 9, 202237 min

S1 Ep 58Innovations in Azure Confidential Computing

In this episode, Michael talks to Run Cai and Vikas Bhatia about some of the latest Confidential Computing services available on Azure including new Confidential VMs from AMD.

Jul 22, 202229 min

S1 Ep 57Microsoft Sentinel Content Hub

In this episode, Michael, Sarah and Mark talk to Roey Ben Chaim about Microsoft Sentinel Content Hub. We also cover the latest security news about Exchange Online, Microsoft Entra Permissions Manager, MSTICPy, Purview DLP, Azure Monitor, Backup and App Insights.

Jul 12, 202221 min

S1 Ep 56Advanced Threat Hunting with Microsoft 365 Defender

Michael sits down with Michael Melone to discuss hunting for adversaries using Microsoft 365 Defender's Advanced hunting capabilities.Azure security news this week includes Azure Advisor for MySQL, using custom CAs with AKS, App Gateway Private Link, continuous backup in Cosmos DB, and API Management CSP and CORS support.

Jul 8, 202221 min

S1 Ep 55Practical Zero Trust

Michael and Sara talk to Matt Soseman about his take on practical Zero Trust and Michael goes on a rant about Zero Trust's Assume Breach pillar. We also cover Azure news about Azure SQL DB, Container Apps, Bastion, Sentinel and Microsoft Entra.

Jun 28, 202242 min

S1 Ep 54Azure SQL Managed Instance Windows Authentication

In this episode Michael talks to Sravani Saluru who is a Senior Program Manager in the Azure Data Platform, about Azure SQL Managed Instance and Windows authentication support which is in preview. We talk about where SQL MI fits in the SQL family, as well as how to configure SQL MI so your one-prem client can access SQL MI in Azure seamlessly.

Jun 14, 202227 min

S1 Ep 53Azure SQL Database Ledger

In this special episode Sarah and Michael talk to Pieter Vanhove about Azure SQL Database Ledger.Ledger is a new feature built into Azure SQL DB and SQL Server 2022. that helps protect data from tampering from attackers or high-privileged users, including database administrators (DBAs), system administrators, and cloud administrators.

May 24, 202224 min

S1 Ep 52Microsoft Defender for Containers

In this episode we talk to Shay Amar about Microsoft Defender for Containers, we go into the weeds in places! Also, Azure security news about Confidential Compute VMs, Azure Arc, Sentinel and Ransomware. Michael and Sarah also discuss their experiences with the AZ-500 exam refresh.

May 18, 202243 min

S1 Ep 51Updates to CosmosDB Security

In this episode we speak to Thomas Weiss from the Azure Data team about new security capabilities in CosmosDB, specifically Always Encrypted and data-plane RBAC. We also have security news about Confidential Compute, Azure Data Explorer, Load Balancer, DNS Reservations, ZLoader malware, Azure Monitor, MSTICPy and NIST SP 800-40.

Apr 18, 202243 min

S1 Ep 50Microsoft Cybersecurity Reference Architectures

In this special episode, Mark chats about the MCRA as well as the Cloud Adoption Framework (CAF), and various related topics. We shied away from the news this week to focus on Mark's topic, but Michael couldn't resist talking about the fact that CosmosDB now supports Always Encrypted.

Apr 4, 202247 min

S1 Ep 49RiskIQ Explained

Gladys and Michael talk to Jason Zann, VP, Head of Platform about RiskIQ, a recent Microsoft acquisition. We also cover the latest security news about API Management, Azure Monitor, Defender for Cloud, Identity Protection and Sensitivity labels.

Mar 23, 202246 min

S1 Ep 48Microsoft Compliance Manager

We chat with Al Eardley about Compliance, Security and Microsoft Compliance Manager, as well as news about CosmosDB, Azure Load Testing, CodeQL, Azure Active Directory, Zero Trust, Sentinel and new cyber blog from Microsoft.

Mar 11, 202246 min

S1 Ep 47Microsoft Defender for IoT

We talk to Chris Hallum about all things Microsoft Defender for IoT. He also discusses IoT security in detail, as well as some new features on the horizon. Also, we cover the news for Microsoft Sentinel, Azure Active Directory, Azure SQL DB, new Azure Learning resources, Azure Monitor and Payment HSM.

Feb 22, 202259 min

S1 Ep 46Microsoft Sentinel Extensions

In this episode we speak to Matt Egen about how Microsoft Sentinel can pull in telemetry and threat intel data from various sources. He talks about the new Codeless Connectors as well as his views on IP-based filtering.

Feb 11, 202244 min

S1 Ep 45Lessons from moving to Zero Trust in a SOC

We talk to Kristin Burke about some of the lessons learned and best practices when moving to Zero Trust and how that affects the Security Operations Center or SOC.Lots of news too: Azure Cache for Redis, API Management, Kubernetes, PostgreSQL, Sentinel, KQL and Confidential Compute.

Jan 26, 202236 min

S1 Ep 44Security: The Boring Bits!

In this episode we talk to Jess Dodson about some of the basic security practices she sees Azure users do well and could improve. We also discuss the latest news about Log4j, Azure Key Vault and automatic key rotation, Storage and AD and ABAC and new security training.

Jan 14, 202251 min

S1 Ep 43Everything you need to know about Azure Policy

In this episode Michael, Sarah, Gladys and Mark talk to Liz Kim about the innards of Azure Policy as well as best practices for effective deployment of Policy. She also outlines some of the exciting new features coming soon.We also discuss news about App Service and Azure Functions, new Confidential Compute VMs, Azure Bastion, Microsoft Defender for Cloud, AKS, ExpressRoute and more.

Dec 29, 202141 min

S1 Ep 42Inside Azure Monitor

In this episode Michael and Mark talk to Dave Lubash about Azure Monitor. We also cover news about Zero Trust Commandments, Azure SQL DB, Logic Apps, Confidential Computing, AKS and Log Analytics.

Dec 10, 202143 min

S1 Ep 41MS Ignite Security Highlights

In this episode we chat with Abbas Kudrati about the latest security news and announcements from the recent Microsoft Ignite event. There were numerous announcement including naming changes for some of the products you know and love.

Nov 16, 202127 min

S1 Ep 40Jupyter Notebooks for Incident Response

We speak to Julie Koesmarno about Jupyter Notebooks on Azure generally, and specifically about using them to help with Incident Response. We also cover security news about .NET 6.0, Azure Monitor, HDInsight, Azure Static Web Apps, Azure Key Vault, Kubernetes, Firewall, Sentinel, Ransomware, IoT Solutions and more!

Nov 5, 202138 min

S1 Ep 39Microsoft Digital Defense Report

We talk to Mark McIntyre about the recent Microsoft Digital Defense Report. The two Marks discuss at length the report as well as cyber-crime, ransomware, digital currencies and more. We also cover security news about Azure Security Center, Windows 11, OWASP Top 10 2021 and the OWASP 20th anniversary, the recent 2.4Tbps DDoS against Azure Sentinel and Mark updates his 'Mark's List'

Oct 22, 202145 min

S1 Ep 38Azure Active Directory Conditional Access

In this episode we talk to Daniel Wood about Conditional Access in Azure Active Directory, some best practices and a few hints about future updates,We also discuss security news about Azure disks, Purview, Site Recovery, Azure SQL DB, Defender for IoT, Ransomware and more.Daniel and Michael discuss 'Do no Harm' in Security...

Oct 6, 202129 min

S1 Ep 37Attacker Tradecraft with Simuland

In this episode we talk to Roberto Rodriguez about a Microsoft open source tool to help researchers understand how attackers attack and compromise systems. Simuland lets you deploy labs to reproduce and learn from attack techniques and test your own detection and prevention tooling.We also have awesome news about NSG and UDR support in Private Link, Azure Virtual Desktop, SMB 3.1.1, Azure Monitor and Azure Data Explorer, Azure Security Center, Windows 11 and Microsoft Cloud Reference Architectures.

Sep 22, 202142 min

S1 Ep 36Azure Defender for SQL - Vulnerability Assessment

Michael and David Trigano of the Azure Defender for SQL Vuln Assessment geek out about SQL security. Gladys discusses the ramifications of the recent Executive Order on Cybersecurity and Mark describes some new MS Cybersecurity Reference Architecture material. Sarah is still taking a break, but she'll be back soon.

Sep 10, 202143 min

S1 Ep 35A Deep Look at Azure Defender for SQL - Threat Protection

In this episode we talk to Michael Makhlevich about Azure Defender for SQL - Threat Protection. Michael Howard and our guest geek out about common SQL security issues and MichaelM gives some interesting philosophical insights into securing SQL databases - it's not just the data! We also cover security news from Managed Hardware Security Module (MSH), App Config, Sentinel, Machine Learning, Azure Security Center and much more.

Aug 24, 202133 min

S1 Ep 34Study Guide for SC-200: Microsoft Security Opertions Analyst

This episode is a little different; no news! Michael talks with Yuri Diogenes and Sarah about the various Azure Security certifications, and Sarah and Yuri talk about their upcoming study guide for SC-200: Microsoft Security Operations Analyst.

Aug 2, 202126 min

S1 Ep 33Zero Trust at Microsoft

In this episode Michael, Sarah, Gladys and Mark talk with guest Carmichael Patton, a Senior Security Architect in the Digital Security and Resiliency group at Microsoft about Microsoft's journey to Zero Trust and some of the lessons learned along the way.We also discuss Azure Security news about: Azure Sentinel, Azure Automation, Azure SQL DB and Always Encrypted withe Secure Enclaves, App Insights, App Service and Functions, Azure Active Directory, Azure Firewall, Azure Kubernetes Service, Azure Security Center, Azure Bastion. Mark also talks about some Open Group actitivites and recent Microsoft security acquisitions.

Jul 28, 202146 min

S1 Ep 32Azure Sentinel SOC Process Workbook

In this episode Michael, Sarah, Gladys and Mark talk with guest Rin Ure about the Azure Sentinel SOC Process Framework Workbook. We also discuss Azure Security news about Azure Web Application Firewall, Azure Front Door, Azure SQL DB, Azure Sphere, Confidential Compute VMs and episode 2 of the Spanish Azure Security Podcast is now out.

Jul 7, 202137 min

S1 Ep 31Azure Security Automation

In this episode we talk to Nicholas DiCola about automating security tasks in Azure. We also cover security news about Azure Monitor, Confidential Computing, Azure Key Vault, Visual Studio Code, Azure Sentinel, Azure Defender for MySQL, MariaDB, PostgreSQL and IoT, and more. Make a point of listening to Mark's comments about the state of Human-operated Ransomware.

Jun 29, 202140 min

S1 Ep 30Microsoft Threat Intelligence - MSTIC

In this episode we interview Pete Bryan from the Microsoft Threat Intelligence Center - MSTIC - about lessons learned from the recent highly-public nation-state attacks on US infrastructure. We also cover news about GitHub, CosmosDB, Storage account key rotation, Azure Functions, SimuLand, Gladys also announces that there is now a Spanish edition of the Azure Security Podcast.

Jun 15, 202141 min

S1 Ep 29Azure Data Explorer

In this episode Michael, Sarah, Gladys and Mark talk with Minni Walia about Azure Data Explorer, a fast and highly scalable data exploration service for log and telemetry data. We also discuss Azure Security news about Bicep, VPN Gateway, Azure Backup, Azure Security Center, AKS, Azure Sentinel, IoT Hub, API Management, SimuLand and Microsoft Cybersecurity Reference Architectures and Microsoft Cloud Adoption Framework.

Jun 4, 202134 min

S1 Ep 28Azure Purview

In this episode Michael, Gladys and Mark talk with guests Gopal Shankar and Arvind Chandaka discuss a new data governance product Azure Purview. We also discuss Azure Security news for the following: Azure Monitor, Storage, cryptography, Zero Trust, Incident Response, Azure Information Protection, Ransomware and more.

May 21, 202134 min