The Azure Security Podcast

Michael Howard, Sarah Young, Gladys Rodriguez and Mark Simos

About

A twice-monthly podcast dedicated to all things relating to Security, Privacy, Compliance and Reliability on the Microsoft Cloud Platform. Hosted by Microsoft security experts, Michael Howard, Sarah Young, Gladys Rodriguez and Mark Simos. https://azsecuritypodcast.net/ ©2020-2023 Michael Howard, Sarah Young, Gladys Rodriquez, and Mark Simos.

Available on

Community

94 episodes

Episode 94: Copilot for Security

In this episode Michael, Sarah and Mark talk with guest Ryan Munsch about the newly released Copilot for Security. We also discuss Azure Security news about Azure SQL DB, SSMS 20, Change Actor, Copilot for Azure SQL DB, Azure Container Apps, AI Prompt Shields, AI Groundedness Detection and BlueHat India and Israel. New tab ( https://azsecuritypodcast.net/azsecuritypodcast.net http://azsecuritypodcast.net) https://azsecuritypodcast.net/

35m
Apr 01, 2024
Episode 93: Continuous Security Development Lifecycle

In this episode Michael, Sarah, and Mark talk with guests Tony Rice and David Ornstein about insights into the Continuous SDL (Security Development Lifecycle). We also discussed Azure Security news about Azure Key Vault, Cloud PKI, OAuth2, updated SQL Server password verifiers, Memory Safety and Azure SQL DB. The Microsoft Azure Security Podcast ( https://azsecuritypodcast.net/azsecuritypodcast.net http://azsecuritypodcast.net) https://azsecuritypodcast.net/

39m
Mar 25, 2024
Episode 92: Global Azure is soon, sign up and give a security presentation!

In this episode Michael and Sarah talk to Martin Abbott about the Global Azure event that starts soon, https://globalazure.net/. We talk about how to successfully fill out a Call for Papers (CFP) so YOU can present to a global audience about security topics that interest you. We also cover security news SQL Always Encrypted, SymCrypt and Rust, SQL Security Fundamentals, and free Security 101 material.

42m
Mar 15, 2024
Episode 91: Azure Chaos Studio

In this episode, Michael talks with Rigel Carlson from the Chaos Studio development team about Chaos Studio through a security lens. Michael also discusses news about Midnight Blizzard and \has some advice about using Azure's DefaultAzureCredential() The Microsoft Azure Security Podcast ( https://azsecuritypodcast.net/azsecuritypodcast.net http://azsecuritypodcast.net) https://azsecuritypodcast.net/

32m
Feb 13, 2024
Episode 90: AI Red Teaming

This is a MUST LISTEN episode for anyone involved in products using AI, or for people who want to learn some of the latest attacks against large language models. Make sure you peruse the exhaustive list of AI security links at The Microsoft Azure Security Podcast ( https://azsecuritypodcast.net/azsecuritypodcast.net http://azsecuritypodcast.net) https://azsecuritypodcast.net/, We cover news about Azure SQL DB, Trusted VMs, NetApp Files, Azure Load Testing and Front Door. Mark covers further details about Zero Trust and the CISO Workshop.

38m
Jan 29, 2024
Episode 89: We Look Back on 2023

In this episode we look back at what stood out for each of us and what we go up to. We also cover something not security-related, but of interest to all your geeks out there - EQ vs IQ. So make sure you stay until the end!

40m
Dec 18, 2023
Episode 88: Securing SQL Databases though the eyes of an attacker

In this episode Michael talks with colleagues in the Azure Data Platform Security Team, Sharath Unni and Raul Garcia about securing Azure SQL DB, SQL MI and SQL Server through the eyes of an attacker.

45m
Dec 01, 2023
Episode 87: Advances in Always Encrypted and Transparent Data Encryption

In this episode, Michael talks with his colleagues Pieter Vanhove and Mirek Sztajno about updates to Always Encrypted and Transparent Data Encryption in SQL Server and Azure SQL DB.

21m
Nov 15, 2023
Episode 86: Zero Trust Playbook Series Zero Trust Overview and Playbook Introduction

In this episode Michael talks with guest Nikhil Kumar and our own Mark Simos about a new book they have co-authored named "Zero Trust Playbook Series Zero Trust Overview and Playbook Introduction: Actionable Guidance for Business, Security, and Technology Leaders and Practitioners."

34m
Oct 31, 2023
Episode 85: Security Bug Bounties

In this episode Michael and Sarah talk with guest Madeline Eckert about Security Bug Bounties.We also discuss Azure Security news about SQL Server 2022, Azure certificate changes, TLS 1.0 and 1.1 deprecation, GitHub security scanning, Ransomeware defenses, Zero Trust and more.; and by 'more' we mean lock-picking!

24m
Oct 11, 2023
Episode 84: Attack Simulation

In this episode Michael, Sarah, Gladys, and Mark talk with guest Roberto Rodriguez about attack simulation, Cloud Katana, and AI.We also discuss Azure Security news about Azure SQL DB, Azure Key Vault, Cosmos DB, Trusted Launch VMs, Azure Artifacts, Zero Trust, Windows and TLS and Entra ID.

44m
Sep 22, 2023
Episode 83: PowerShell Automation and Scripting for Cybersecurity

In this episode Michael and Sarah with guest Miriam Wiesner about her new book, "PowerShell Automation and Scripting for Cybersecurity" which comes out soon. We also discussed Azure Security news about: Azure SQL DB Always Encrypted improvements, Azure SQL Managed Instance, App Gateway for Containers and Bring your own Key for AKS Ephemeral Disks.

36m
Aug 14, 2023
Episode 82: Modern Security Strategy

This week Michael and Mark talk to Microsoft Security MVP Truls Dahlsveen about his thoughts on Modern Security Strategy. It's a fascinating and practical discussion! We also cover security news about Application Gateway TLS policy, Defender for IoT and some new documentation from the OpenGroup about Zero Trust Commandments.

35m
Aug 08, 2023
Episode 81: Audit logging in Azure SQL Database

In this special episode Michael talks to his colleague Sravani Saluru about how to configure, monitor and manage audit logging in Azure SQL Database. She also shares some inside hints and tips!

26m
Jul 28, 2023
Episode 80: Microsoft Incident Response

In this episode Michael and Sarah talk with guest Matt Zorich from the Microsoft Incident Response team. We also cover the latest Azure security news about Azure's Web Application Firewall and Azure Monitor RBAC.

33m
Jul 14, 2023
Episode 79: Threat Intelligence with MSTICPy

In this episode, Michael and Sarah talk to Thomas Roccia about Threat Intelligence with MSTICPy. We also cover security news about Azure Files SMB, App Gateway, Event Hubs and Linux Containers.

28m
Jun 13, 2023
Episode 78: Entra Permissions Management updates

In this episode Michael and Gladys talk with guests Marcelo di lorio and Neil Walker about all the latest news in Entra Permissions Management.We also cover the latest Azure security news about Microsoft Build, Confidential Computing, Key Vault, SQL MI, and Azure Content Safety and more.

32m
Jun 02, 2023
Episode 77: Securing Infrastructure as Code (IaC)

This week, Michael, Mark and Gladys talk to Anthony Shaw about some of the best practices and tooling for securing Infrastructure as Code (IaC) solutions. Sarah is away in Singapore, presenting at BlackHat.We also cover security news about DDoS, Cosmos DB, Microsoft Defender for APIs, Load Balancer, Zero Trust and discovering Internet-facing devices.

40m
May 19, 2023
Episode 76: Microsoft Security Research Insights

In this episode Michael, Sarah, and Mark talk with guest Negar Shabab. We also discuss Azure Security news about new Confidential Computing VMs, SQL Server, T-SQL Parsing, Auditing in Azure SQL DB, Sentinel and more. Make sure you go to The Microsoft Azure Security Podcast ( https://azsecuritypodcast.net/azsecuritypodcast.net http://azsecuritypodcast.net) https://azsecuritypodcast.net/, because Mark ordered pizza during the recording.

26m
May 03, 2023
Episode 75: What's new in Microsoft Defender for Cloud

In this episode Michael, Sarah, Gladys, and Mark talk with a good friend of the Podcast, Yuri Diogenes, about the latest Microsoft Defender for Cloud news.We also discuss Azure Security news about Trusted VM Launch, Chaos Studio, Azure SQL DB, DDoS protection, Confidential Containers, Firewall and more.

36m
Apr 14, 2023
Episode 74: What's New in Azure Policy

Michael and Mark talk to Kemley Nieva from the Azure Governance team about some of the recent updates and improvements to Azure Policy. We also cover the latest Azure security news covering Microsoft Security Copilot, Azure Functions, SQL Managed Instance, Azure Backup, Ephemeral OS disks, Azure Cache for Redis, Azure SQL Database, Azure Monitor, API Management, Azure Maps and Storage.

35m
Apr 07, 2023
Episode 73: Microsoft Defender for Cloud as Code

In this episode Michael and Gladys talk with guests Sean Wesonga and Bojan Magusic about using Infrastructure as Code (IaC) with Microsoft Defender for Cloud. We also discuss Azure Security news about new Azure SQL Database migration abilities for authentication and Transparent Data Encryption (TDE).

27m
Mar 23, 2023
Episode 72: What's top of mind for the hosts and career advice!

In this episode Michael, Sarah, Gladys and Mark interview each other! The Podcast is almost three years old, and things have changed for each of us, so we thought we'd re-introduce ourselves, reflect, give career advice, and talk about what's top of mind for each of us! We also discuss Azure Security news about SQL Server and Azure SQL DB, MFA and AAD, AAD and IPv6, new SC-100 study guide and more.

1h 1m
Mar 08, 2023
Episode 71: Azure SQL Database and Always Encrypted using Virtualization-Based Security Enclaves

In this special episode, Michael sits down with Pieter Vanhove about a new addition to the SQL Server 'Always Encrypted' family. The new addition, Virtualization-Based Security Enclaves (VBS), is now in Preview and allows for more scalability and lower cost when using secure enclaves compared to the current SGX-based enclaves.

28m
Feb 15, 2023
Episode 70: Microsoft Purview

In this episode Michael and Sarah talk with guests Beau Faull and Lou Mercuri about some new features and updated naming in Microsoft Purview. Beau and Lou are also co-hosts of the Coast2Coast Podcast on YouTube. We also discuss Azure Security news about Trusted Boot VMs, Sentinel and Defender for Cloud.

34m
Feb 13, 2023
Episode 69: Secured Supply Chain and Software Bill of Materials (SBOM)

In this episode, Michael and Mark talk to Adrian Diglio about Software Bill of Materials and its role in helping secure the software supply chain. We also have news items about SQL Server, Azure SQL DB, Azure Database for PostgreSQL, Azure Database for MySQL and Application Secure Groups and Private Endpoints. Mark goes over MCRA, Immutable Laws of Cybersecurity and Security Architecture Design.

27m
Feb 02, 2023
SQL Server 2022

Michael sits down with Ajay Jagannathan who is the Principal Group PM Manager for SQL Server. Michael also covers a couple of SQL Server related news items.

33m
Dec 07, 2022
Privileged Access

Michael and Sarah talk to Bronwyn Mercer from Microsoft Australia about Privileged Access as well as some ideas and processes to help you succeed. Also, the latest security news about Managed HSM, Defender for DevOps, TLS and ARM, SQL Server 2022, Application Gateway. Finally, 'Designing and Developing Secure Azure Solutions' is now available. https://azsec.tech/get

32m
Nov 24, 2022
Workload Identities

In this episode Michael, Sarah and Mark talk with guest Joey Snow about Workload Identities in Azure. We also chat about least privilege and privileged accounts in general. Finally, the latest Azure Security news about: Azure Front Door, Log Analytics, Web Application Firewall and AKS SSH keys.

31m
Nov 11, 2022
Microsoft Defender for Threat Intelligence

In this episode Michael, Sarah, Gladys and Mark talk with guests Rijuta Kapoor and Brandon about Microsoft Defender for Threat Intelligence. We also discuss Azure Security news about Azure Service Bus and TLS, PostgreSQL, VMs, SQL Server and Confidential VMs, Azure SQL DB, Workload Identities, Microsoft Entra and other security news from Ignite.

38m
Nov 04, 2022