Merill Fernando, Principal Product Manager at Microsoft Entra, shares his expertise on open-source security tools designed to enhance Azure and Entra ID security. He discusses recent developments from the Microsoft Ignite event, including FIDO2 authentication and the retirement of older TLS versions. Insights on Zero Trust principles and the new security tool, Maester, highlight the importance of collaboration in tech solutions. Merill emphasizes the urgent need for Multi-Factor Authentication across organizations to bolster security awareness and frameworks.
The Microsoft Ignite event is essential for Azure users to learn about advancements in cloud security, despite sold-out in-person tickets.
Maester, a collaborative PowerShell-based framework, enhances identity security through over 200 checks for validating cloud configurations and SecDevOps practices.
Deep dives
Upcoming Microsoft Ignite Event
The Microsoft Ignite event is highlighted as a significant upcoming occasion for those involved with Azure and Microsoft technologies. Attendees have the option to participate in person or watch sessions via live stream for free, despite in-person tickets being sold out. The event will feature numerous announcements and sessions, showcasing the latest in cloud security and technology advancements. The hosts emphasize the importance of checking out the recorded sessions on YouTube for valuable insights.
Transition to TLS 1.2 and 1.3
A crucial update is impending with the retirement of TLS 1.0 and 1.1, effective March 1, 2025, demanding vigilance from users and developers. Users are encouraged to ensure their client code is compatible with TLS 1.2 or higher to prevent service disruptions. A proactive approach is recommended to verify compatibility across applications, with specific attention to old versions of browsers and operating systems. The hosts stress the urgency of this transition, urging listeners not to delay necessary updates to avoid future complications.
Introduction of Maester Tool
Maester is introduced as a PowerShell-based test automation framework designed to enhance identity security and apply SecDevOps practices to Microsoft's cloud solutions. Developed collaboratively by a group of experts, including MVPs, Maester helps organizations verify conditional access policies and ensure their configurations remain secure from unauthorized changes. Notably, the tool has gained significant traction, with contributions from a large community, leading to the development of over 200 checks to validate cloud configurations. The tool’s name is inspired by Maesters from Game of Thrones, symbolizing expertise and wisdom in the domain.
Zero Trust Workshop Initiative
The Zero Trust Workshop initiative is a new program aimed at guiding organizations in effectively implementing Zero Trust principles throughout Microsoft products. Developed through extensive customer feedback, the workshops offer a structured roadmap and assessment framework, helping clients identify necessary steps for successful implementation. This approach fosters collaboration among various stakeholders within organizations, breaking down silos that often hinder security efforts. The workshop facilitates meaningful discussions among teams, ensuring a comprehensive strategy tailored to the specific needs of each organization.
In this episode, Michael, Sarah, and Mark talk to Merill Fernando about a set of open source tools he and his team have developed to help people understand their Azure and Entra ID security postures.
We also cover news about Fabric, TLS 1.o and 1,1 retirement, Microsoft Ignite, FIDO2, Confidential Containers and Red Hat OpenShift and various Zero Trust news.