Let's Talk Azure!

Alan Armstrong & Sam Foot
undefined
Aug 8, 2025 • 38min

S6E19 - Microsoft updates July - new products and features released

This week, Alan and Sam talk about new features and services that have gone into Public Preview or General Available status in the last month. We dive into a couple of these updates that peaked our interest. Some of the Microsoft product features and update we covered: Key Microsoft Entra, Intune and Defender features and updates Lots of Azure changes and new features What did you think of this episode? Give us some feedback via our contact form, or leave us a voice message in the bottom right corner of our site.Read transcript
undefined
Jul 18, 2025 • 56min

S6E18 - Securing Access to Your Virtual Machines with Azure Bastion

In this episode, we explore Azure Bastion, Microsoft’s fully managed Platform-as-a-Service (PaaS) solution designed to provide secure Remote Desktop Protocol (RDP) and Secure Shell Protocol (SSH) access to Azure virtual machines (VMs). This Q&A-style episode dives deep into how Azure Bastion strengthens cloud security by eliminating the need for public IP addresses on VMs, reducing exposure to external threats like port scanning or protocol exploits. Alan poses critical questions about Azure Bastion’s functionality, architecture, deployment options, and integration with Azure’s security ecosystem, while our consultant delivers actionable insights tailored for IT administrators, security professionals, and cloud architects. We cover: Core Functionality: How Azure Bastion enables secure, clientless RDP/SSH access via the Azure portal or native clients, protecting VMs by removing public IP dependencies. Architecture Breakdown: The role of the dedicated AzureBastionSubnet, private IP connectivity, and TLS-based sessions, including support for zonal deployments for high availability. SKU Options: A detailed look at Developer, Basic, Standard, and Premium SKUs, highlighting features like session recording, Private Link integration, and host scaling for different organizational needs. Security Integrations: How Azure Bastion works with Microsoft Defender for Cloud, Microsoft Entra ID (with MFA and conditional access), Azure Private Link, and Azure Monitor to enforce Zero Trust principles and ensure compliance. Real-World Use Cases: Practical scenarios, such as secure admin access for global teams, compliance for regulated industries (e.g., healthcare, finance), and streamlined dev/test environments, with examples like Metinvest’s global VM management. Best Practices: Tips for deployment (e.g., subnet sizing, VNet peering), security (e.g., MFA, NSG configuration), monitoring (e.g., Azure Monitor logs), and cost management (e.g., SKU selection, scaling strategies). Limitations and Considerations: Key factors like SKU constraints, regional availability for zonal deployments, performance considerations, and cost implications, with guidance on mitigating challenges. What did you think of this episode? Give us some feedback via our contact form, Or leave us a voice message in the bottom right corner of our site.Read transcript
undefined
Jul 4, 2025 • 44min

S6E17 - Microsoft updates June - new products and features released

Alan and Sam explore exciting new features from Microsoft, including updates in Microsoft Entra, Intune, and Defender. They discuss the recent Azure changes, highlighting a notable retirement of a feature. The conversation dives into security enhancements, especially the integration of Sentinel into Defender XDR, and AI improvements across platforms. Listeners will also learn about new functionalities in Microsoft 365, such as AI-driven retention policies. The episode wraps up with insights on navigating Azure Local and its relationship with Microsoft 365.
undefined
Jun 20, 2025 • 55min

S6E16 - Monitor and Protect Generative AI services using Microsoft Tooling

Alan and Sam discuss the topic of Generative AI usage and it should be monitored by organisations. Alan talks about some of the Microsoft tooling that can help monitor these services and protect data being consumed. The importance of monitoring Generative AI usage. How Microsoft tooling can help monitor and protect Gen AI usage What did you think of this episode? Give us some feedback via our contact form, Or leave us a voice message in the bottom right corner of our site.Read transcript
undefined
Jun 13, 2025 • 1h 8min

S6E15 - Microsoft updates May - new products and features released

Discover the latest buzz from Microsoft as the hosts dive into exciting updates like features from Entra, Intune, and Defender. AI's transformative role in marketing takes center stage, discussing personalized content amidst authenticity concerns. Barclays Bank's adoption of Microsoft's Copilot aims to boost productivity for 100,000 employees. Key enhancements to Microsoft Defender XDR are unveiled, alongside discussions on integrating Azure Purview with third-party services and addressing data security in the generative AI era. Finally, learn about Azure's ongoing evolution with fresh features and improved security management.
undefined
May 30, 2025 • 46min

S6E14 - Securing M365 with ScubaGear: A Deep Dive into CISA’s Assessment Tool

In this episode, we dive deep into ScubaGear, an open-source tool developed by the Cybersecurity and Infrastructure Security Agency (CISA) as part of the Secure Cloud Business Applications (SCuBA) project. Designed to assess Microsoft 365 (M365) tenant configurations, ScubaGear helps organizations align with CISA’s Secure Configuration Baselines (SCBs) to prevent costly misconfigurations. From setup to real-world applications, we unpack how ScubaGear strengthens M365 security and share practical tips for IT admins and security teams. What You’ll Learn: Why ScubaGear Matters: Learn how ScubaGear addresses the growing threat of cloud misconfigurations, which accounted for 30% of cloud attacks in early 2024. We discuss its origins in CISA’s SCuBA project, and its value for US federal agencies, private organizations, and critical infrastructure. How ScubaGear Works: A technical breakdown of ScubaGear’s PowerShell-based workflow, using Microsoft Graph APIs and Open Policy Agent (OPA) to compare tenant settings against SCBs. We cover setup requirements. Common Misconfigurations: Examples like disabled MFA or weak DLP policies, and how ScubaGear’s HTML, JSON, and CSV reports provide actionable remediation steps. Best Practices: Tips for integrating ScubaGear into security workflows, including regular scans, policy customization, and combining with tools like Microsoft Secure Score. Real-World Insights: Sam shares experiences from consulting. What did you think of this episode? Give us some feedback via our contact form, Or leave us a voice message in the bottom right corner of our site.Read transcript
undefined
May 16, 2025 • 1h 8min

S6E13 - Security Copilot - Your Security Analyst's Assistant

Alan and Sam discuss the benefits and use cases of Security Copilot. Alan Dives into how Security Pilot works and what some of the capabilities are. Here are a few things we covered: What is Generative AI What is Security Copilot What are Agents How much does it cost? What did you think of this episode? Give us some feedback via our contact form, Or leave us a voice message in the bottom right corner of our site.Read transcript
undefined
May 2, 2025 • 53min

S6E12 - Microsoft updates April - new products and features released

Explore the latest Microsoft updates, including exciting features from Entra, Intune, and Defender. Discover insights into recent cybersecurity incidents and the vital enhancements in Microsoft Defender, particularly around privileged access management. Delve into advancements in Azure services, from security improvements to expanded functionalities. The conversation also covers Azure pricing nuances and hints at future topics like the security copilot. Stay tuned for the evolution of Microsoft's security landscape!
undefined
Apr 25, 2025 • 54min

S6E11 - Insights into Microsoft Secure 2025

The hosts dive into fresh innovations unveiled at Microsoft Secure 2025. Key highlights include the powerful Security Copilot Agents and advancements in Microsoft Entra. They discuss the critical challenge of protecting against emerging AI threats. Insights on navigating phishing reports reveal how organization size affects user vigilance. Additionally, there's a focus on enhancing data security tools and the complexities of responding to privacy breaches. AI's role in streamlining security operations also sparks intriguing conversations throughout.
undefined
Apr 11, 2025 • 41min

S6E10 - Microsoft updates March - new products and features released

This week, Alan and Sam talk about new features and services that have gone into Public Preview or General Available status in the last month. We dive into a couple of these updates that peaked our interest. Some of the Microsoft product features and update we covered: Key Microsoft Entra, Intune and Defender features and updates Lots of Azure changes and new features What did you think of this episode? Give us some feedback via our contact form, Or leave us a voice message in the bottom right corner of our site.Read transcript

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app