Back

Explore every episode of the podcast The Azure Security Podcast

Dive into the complete episode list for The Azure Security Podcast. Each episode is cataloged with detailed descriptions, making it easy to find and explore specific topics. Keep track of all episodes from your favorite podcast and never miss a moment of insightful content.

Rows per page:

1–50 of 131

TitlePub. DateDuration
Episode 132 - Windows Server 2025 Security26 Aug 202600:40:30

In this episode, Michael and Sarah talk to Orin Thomas about security improvements in Windows Server 2025. We realize this is an Azure podcast, but many people deploy Windows VMs!

We also security news about CosmosDB, GitHub Copilot and Quantum development, ASP.NET and PQ hybrid TLS 1.3 and more!

https://aka.ms/azsecpod

Episode 131: What is MDASH?27 Jul 202600:34:09

In this packed episode, Michael, Sarah and Mark talk to Taesoo Kim about the new MDASH. We have lots of news this week, too, including Certificate Services in Window now support Post-Quantum ML-DSA certificates, Microsoft moving its Q-Day up to 2029, and lot more PQ news, Mark has a YouTube channel, securing AI agents, and a lot more!

https:/aka.ms/azsecpod

Episode 130: The Security Adoption Framework (SAF)10 Jul 202600:36:20

In this episode, Michael talks with podcast cohost Mark Simos about big updates to the Security Adoption Frame (SAF).

We also cover news about Secure Boot for Trusted Launch VMs, and the Microsoft HSM Toolkit.

https://aka.ms/azsecpod

Episode 129: John Savill's Top of Mind12 Jun 202600:42:35

In this episode, Michael and Sarah interview a man who needs no introduction, John Savill, the CTO of America's Markets and Industries at Microsoft. In this episode, John talks about a few security items that are top of mind for him, and what he is hearing from customers.

We also covered news from Microsoft Build, Michael's new book, as well as the latest post-quantum crypto news.

https://aka.ms/azsecpod

Episode 128: Post Quantum Cryptography02 Jun 202600:55:21

In this episode Mark talks with guest Jack Richins and co-host Michael Howard about post-quantum cryptography and the upcoming 'Q-Day'.

Jack and Michael explain what steps Microsoft is taking and what steps customers can take to reduce exposure to this looming threat.

This episode was prompted because Michael has moved from the Microsoft Red Team to the Post Quantum team in Azure Security.

There is no security news in this episode. It's also the longest episode to date!

https://aka.ms/azsecpod

Episode 127: Threat intel update and AI30 Apr 202600:35:42

In this episode, Michael, Sarah and Mark talk with Sherrod DeGrippo about some of the latest tactics and strategies used by modern threat actors, we also wander into the AI security weeds!

We only have one news item related to Azure SQL databases.

https://aka.ms/azsecpod

Episode 126: Microsoft Baseline Security Mode21 Mar 202600:36:01

In this episode, Michael and Sarah talk to Sophie Ke and Dave Minasyan about Microsoft Baseline Security Mode, a new feature to help ease security settings. We also cover the latest Azure security news including Microsoft 365 E7, Microsoft 365 Copilot, Azure Blob Storage SFTP, Azure Database for PostgreSQL, and new Confidential VM types.

https://aka.ms/azsecpod

Episode 125: Origins of MITRE ATT&CK27 Feb 202600:34:39

In this episode Michael and Mark talk with guest Blake Strom about the origins of the MITRE ATT&CK framework, how it was developed, and how it has evolved over time. We also discuss how the framework is used in the industry and its impact on cybersecurity.

We also discuss Azure Security news about Azure Monitor, Azure Application Gateway, AKS, Azure Front Door, AMD v6 Confidential VMs, and xxx

https://aka.ms/azsecpod

Episode 124: Microsoft Security Response Center for AI30 Jan 202600:29:05

In this episode Michael talks to Raji Vanninathan about the Microsoft Security Response Center for AI.

We also cover security news about AKS Deployment Safeguards policies.

https://aka.ms/azsecpod

Episode 123: Agentic Identity21 Jan 202600:36:17

In this episode, Michael, Sarah and Mark talk to Nick Wryter about agentic AI identity, with a big focus on least privilege issues. We also cover news about:

  • Microsoft AI Tour
  • Azure Database for PostgresSQL
  • Azure MCP Server for Azure Confidential Ledger
  • Application Gateway, FIPS 140-2 and TLS
  • Outbound internet access from VMs
  • Azure NetApp Files and Ransomware protection
  • Azure Cosmos DB Mirroring

https://aka.ms/azsecpod

Episode 122: Microsoft Ignite 2025 Wrap-up15 Dec 202500:32:54

In this episode Michael, Sarah and Mark discuss security-related topics from the recent Microsoft Ignite 2025 event. Lots of AI-related security topics, including using AI for security and defending AI systems. Bitlocker, Windows and so much more!

This is the last episode of 2025! It was a blast, and thanks for listening! We hope you find this material useful!

https://aka.ms/azsecpod

@AzureSecPod

See you in 2026!

Episode 121: New Open Group Security Standards Documentation21 Nov 202500:47:52

In this episode Michael and Sarah talk with co-host Mark Simos about new security standards documentation from the Open Group. It's a long episode but worth it!

We also discuss Azure Security news about Private Endpoints, Azure Front Door, Azure WAF CAPTCHA, Azure Sphere, Private Link Service Direct Connect, Azure Integrated HSM, Azure Firewall pre-scaling and observed capacity metric, and Microsoft Ignite.

https://aka.ms/azsecpod

Episode 120: The Zero Trust Workshop (and so much more!)29 Oct 202500:58:51

In this episode Michael talks with guest Merill Fernando about the Zero Trust Workshop, but we also spend time talking about all things identity! Merill's final thought is pure gold, too!

The only bit of news is about Azure SQL DB and how TDE key management during restore,

Episode 119: Pedantic Security Wording and Taxonomies09 Oct 202500:39:59

In this episode Michael, Sarah and Mark talk with guest Ryen Macababbad, Principal Security Program Manager at Microsoft about her current work on standardizing security terminology and taxonomy across Microsoft.

Also, how getting terminology right is important to security, especially for those with neurodiverse conditions, such as autism.

We also discuss Azure Security news about the Microsoft AI tour Sarah is doing, Cosmos DB, and Michael goes on a rant about TLS certificate checking.

https://aka.ms/azsecpod

Episode 118 - Quantum Cryptography and Quantum Computing with Mark Russinovich19 Sep 202500:33:31

In this episode Michael and Mark talk with guest Mark Russinovich, Technical Fellow, Deputy CISO and Chief Technology Officer of Microsoft Azure about quantum cryptography and quantum computing and its implications for security and the future.

NOTE: There's a portion where Mark and Michael talk about a quote made by Richard Feynman about understanding technical topics, but this is actually attributed to Albert Einstein. However, there is no definitive record of Einstein writing or saying this exact phrase in his published works or speeches.

We decided to not cover any Azure Security news in this episode.

Episode 117: Cloud Gaming Security29 Aug 202500:43:29

In this episode Michael and Sarah talk to Russ Rogers from the Xbox team about gaming security in general and Xbox specifically. This is the first time we have covered the topic! There is also so much news, we really list all the announcements here! It's about 9 mins of security news!

https://aka.ms/azsecpod

Episode 116: Microsoft Sentinel Data Lake31 Jul 202500:40:03

In this episode Michael, Sarah and Mark talk to Mark Kendrick about Microsoft Sentinel Data Lake. We also cover news about The Open Group - Roles and Glossary standards, Security Adoption Module 5 - Data Security, Microsoft Azure Cloud HSM, WAF and Containers, PostgreSQL and PowerBI, Azure Managed Lustre, and more. Also, Sarah mentions some Developer Security YouTube videos coming out from MS Build!

https://aka.ms/azsecpod

Episode 115: Security in Model Context Protocol (MCP)10 Jul 202500:51:58

In this episode, Michael, Sarah and Mark talk to Den Delimarksy about the current posture of Model Context Protocol. Den serves on the committee that oversees MCP.

We also cover the latest security news about Azure Firewall, OpenTelemetry, Azure Front Door, Azure Database for PostgreSQL and Azure Kubernetes Service.

https://aka.ms/azsecpod

Episode 114: SQL Server 2025 Security Improvements09 Jun 202500:25:21

In this episode, Michael talks to Pieter Vanhove and Pratim Dasgupta about the new security changes in SQL Server 2025.

The news includes updates on MCP, Private Link and Microsoft Build 2025 security sessions presented by Michael and Sarah.

https://aka.ms/azsecpod

Episode 113: Microsoft Red Team16 May 202500:35:48

In this episode, Michael, Sarah, and Mark talk to Craig Nelson, VP of the Microsoft Red Team about how the Red Team works to help secure Microsoft and its customers.

In life, there are things you know you know, things you know you don't know, and finally, things you don't know you don't know. This episode is full of the latter.

We also cover security news about LLMs and MCP, TLS 1.1 and 1.0 deprecation, Private End Point Improvements, Containers and more.

https://aka.ms/azsecpod

Episode 112: Security Copilot Agents13 May 202500:29:53

In this episode Michael talks with guest Ran Munsch, Principal Product Manager at Microsoft about Security Copilot and Security Copilot Agents.

We also discuss Azure Security news about System.Data.SqlClient, April 2025 Secue Future Initiative progress report, Azure Database for PosrgreSQL, Azure DevTest Labs, VNets, Front Door WAF CAPTCHA, API management and more.

https://aka.ms/azsecpod

Episode 111: Securing Agentic AI 17 Apr 202500:23:26

In this episode Michael and Sarah talk with guest Amanda Minnich about securing agentic AI systems, the security challenges they face, and how to secure them.

We also discuss Azure Security news about Azure File Sync, Docker support in Azure and a new series of Secure Future Initiative videos with appearances from Michael, Sarah, and various guests.

Episode 110: Securing GenAI Applications with Entra (3 of 4): Monitoring and More01 Apr 202500:40:14

In this episode Michael and Gladys talk to Sharon Chahal who is a Principal Program Manager in the Identity team at Microsoft about monitoring and auditing when building GenAI applications. We also cover other related topics.

Michael and Gladys cover the latest security news about API Security Posture Management, Azure Key Vault in China, Azure Data Studio retirement, new least privilege permissions in Graph and more.

https://aka.ms/azsecpod

Episode 109: Securing GenAI Applications with Entra (2 of 4) - Overpermissioning19 Feb 202500:37:57

In this episode, Michael, Gladys and Mark talk to guest Bailey Bercik about the problem of overpermissioning and how to use Microsoft Entra Permissions Management to identify and manage over-permissioned identities in multi-cloud environments to reduce security risks, especially for AI apps.

We also cover the latest security news about AI red teaming, Azure SQL DB logging, Azure Confidential Ledger, Star Blizzard spear-phishing campaign and CISA Zero Trust Maturity Model.

https://aka.ms/azsecpod

Episode 108: Securing GenAI Applications with Entra20 Jan 202500:22:27

In this episode Michael, Gladys, Mark and Sarah talk to guest Diana Vicezar from the Microsoft Entra team about security Generative AI applications. Note, this is a short, simple intro episode to introduce three follow-on episodes.

We also cover security news about TLS 1.3 and Azure Event Grid, big updates to Microsoft Defender for Cloud, Azure Database for MySQL, SQL Managed Instance and Confidential Ledger.

Episode 107: Secure by default and Copilot Overshare Blueprints06 Jan 202500:37:19

Happy New Year!

In this episode Michael, Sarah and Mark talk to Maxime Bombardier and Emily Blundo about the Secure by default and Copilot overshare blueprints.

We also cover news about Always Encrypted Assessment in SQL Server Management Studio, MVP Summit, mapping Entra to the Open Group standard for Adaptive Access, and various CISO Workshop topics!

https://aka.ms/azsecpod

Episode 106: Microsoft Ignite Security Wrap-up10 Dec 202400:44:23

In this episode, Michael, Mark, and Sarah go over what they found interesting from Microsoft Ignite. Mark has a discount code for his Zero Trust Book, too.

https://aka.ms/aszecpod

Episode 105: Azure and Entra ID Security Tools22 Nov 202400:36:59

In this episode, Michael, Sarah, and Mark talk to Merill Fernando about a set of open source tools he and his team have developed to help people understand their Azure and Entra ID security postures.

We also cover news about Fabric, TLS 1.o and 1,1 retirement, Microsoft Ignite, FIDO2, Confidential Containers and Red Hat OpenShift and various Zero Trust news.

https://aka.ms/azsecpod

Episode 104: The Post Bluehat Wrap-up08 Nov 202400:37:17

In this episode, Michael talks to Nic Fillingham about the recent Microsoft Bluehat Security conference held at the Microsoft HQ in Redmond, WA. We also discuss how to tell the NZ and Australian accents apart. This alone is worth listening to :)

This is a follow-on from episode 103 when we talked about what was coming up for Bluehat.

No news, as this is a special, smaller episode. It's also the least edited; other than some ums and ers getting removed and a small retake, the result is as was recorded. Let us know what you think, this feels a little more 'chatty' and personable.

https://aka.ms/azsecpod

Episode 103: Security Conferences and Bluehat17 Oct 202400:48:17

In this episode we speak to Nic Fillingham who is a Senior Program Manager at Microsoft about security conferences and mainly about the Microsoft Bluehat conference he runs.

We also discuss security about PostgreSQL, Cosmos DB, IP address management, containers and AI Studio.

https://aka.ms/azsecpod

Episode 102: Entra ID Purple-teaming with Dr Azure AD07 Oct 202400:36:42

In this episode Michael and Sarah talk to Nestori Syynimaa about Entra ID security and his purple-team tool, AADInternals.

We also cover the latest security news about Secure Future Initiative (SFI), MFA for Azure Portal, Playright, WordPress, NSG, Bastion, Azure Functions, MS Ignite, App Service, Defender for Cloud, Containers, Azure Monitor, AKS, Trustworthy AI and Azure AI Content Safety.

https://aka.ms/azsecpod

Episode 101: The GHOST Threat Hunting Team20 Sep 202400:22:39

In this episode Michael, Mark and Sarah talk to Matt Zorich and Waymon Ho of the Microsoft GHOST team. We discuss the role GHOST plays in protecting both Microsoft and our customers from nation-state threat actors.

We also cover the latest security news about Event Grid, NetApp Files, Chaos Studio and AKS.

https://aka.ms/azsecpod

Episode 100: Our stories so far29 Aug 202400:48:56

In this episode Michael, Sarah, Gladys and Mark talk about our careers so far, explain some funny stories and our wishes for a more secure future.

Our stories

  • Mark at the start
  • Sarah 4m 5s
  • Gladys 6m 50s
  • Michael 12m 22s

Funny Stories

  • Mark 19m 31s
  • Sarah 20m 33s
  • Gladys 22m 46s
  • Michael 24m 39s

Career Advice

  • Mark 26m 58s
  • Sarah 29m 18s
  • Gladys 31m 48s
  • Michael 34m 40s

Future

  • Mark 36m 27s
  • Sarah 38m 33s
  • Gladys 40m 34s
  • Michael 42m 24s

Behind the Scenes

  • Mark 43m 36s
Episode 99: Securing Copilot AI Data and Purview16 Aug 202400:37:29

In this (late) episode, we chat to Andrew McMurray, a Principal Product Manager at Microsoft about securing Copilot data as well as how Purview can play a role in doing so. We also cover news about MFA access to the Azure Portal (Important), PostgreSQL, Entra ID and Windows authn metadata, Backup Vaults, Conditional Access Policy, ADFS, and Azure Container Apps.

Episode 98: Secure Future Initiative and Rust at Microsoft21 Jun 202400:37:19

In this episode Michael and Gladys talk with guest Dave Weston about Secure Future Initiative and the growing use of the Rust programming language at Microsoft.

On the topic of Rust, Michael and Dave nerd out, and we make no apologies!

https://aka.ms/azsecpod

Episode 97: Securing AI06 Jun 202400:39:48

In this episode Michael and Sarah talk with guest Richard Diver about securing solutions that use AI and LLMs. Richard also talks about his new book on AI Security, and Michael and Richard talk about what it takes to write a book.

We also discuss Azure Security news about Chaos Studio, API Management, Azure Bastion, Front Door, AKS and Copilot for Security and lots more!

Also note, we have changed the URL for the show notes web site, so please use this from now on: https://aka.ms/azsecpod.

Episode 96: Cloud Native Applications Protection Platform (CNAPP) 03 May 202400:21:23

In this episode Michael, Sarah, and Mark talk with guest (and good friend of the podcast) Yuri Diogenes about CNAPP - Cloud Native Application Protection Platform and announce the release of a CNAPP e-book.

Episode 95: Threat Intelligence25 Apr 202400:31:28

In this episode Michael, Sarah and Mark talk with guest Sherrod DeGrippo, Director of Threat Intelligence Strategy at Microsoft about the current state of Threat Intelligence.

We also discuss Azure Security news about Tampa BSides, Virtual Networks, Azure Database for MySQL and PostgreSQL, and SQL Server on Linux.

The Microsoft Azure Security Podcast (azsecuritypodcast.net)

Episode 94: Copilot for Security01 Apr 202400:35:50

In this episode Michael, Sarah and Mark talk with guest Ryan Munsch about the newly released Copilot for Security. We also discuss Azure Security news about Azure SQL DB, SSMS 20, Change Actor, Copilot for Azure SQL DB, Azure Container Apps, AI Prompt Shields, AI Groundedness Detection and BlueHat India and Israel.

New tab (azsecuritypodcast.net)

Episode 93: Continuous Security Development Lifecycle25 Mar 202400:39:12

In this episode Michael, Sarah, and Mark talk with guests Tony Rice and David Ornstein about insights into the Continuous SDL (Security Development Lifecycle).

We also discussed Azure Security news about Azure Key Vault, Cloud PKI, OAuth2, updated SQL Server password verifiers, Memory Safety and Azure SQL DB.

The Microsoft Azure Security Podcast (azsecuritypodcast.net)

Episode 92: Global Azure is soon, sign up and give a security presentation!15 Mar 202400:42:07

In this episode Michael and Sarah talk to Martin Abbott about the Global Azure event that starts soon, https://globalazure.net/. We talk about how to successfully fill out a Call for Papers (CFP) so YOU can present to a global audience about security topics that interest you. We also cover security news SQL Always Encrypted, SymCrypt and Rust, SQL Security Fundamentals, and free Security 101 material.

Episode 91: Azure Chaos Studio13 Feb 202400:32:50

In this episode, Michael talks with Rigel Carlson from the Chaos Studio development team about Chaos Studio through a security lens. Michael also discusses news about Midnight Blizzard and \has some advice about using Azure's DefaultAzureCredential()

The Microsoft Azure Security Podcast (azsecuritypodcast.net)

Episode 90: AI Red Teaming29 Jan 202400:38:54

This is a MUST LISTEN episode for anyone involved in products using AI, or for people who want to learn some of the latest attacks against large language models. Make sure you peruse the exhaustive list of AI security links at The Microsoft Azure Security Podcast (azsecuritypodcast.net),

We cover news about Azure SQL DB, Trusted VMs, NetApp Files, Azure Load Testing and Front Door. Mark covers further details about Zero Trust and the CISO Workshop.

Episode 89: We Look Back on 202318 Dec 202300:40:56

In this episode we look back at what stood out for each of us and what we go up to. We also cover something not security-related, but of interest to all your geeks out there - EQ vs IQ. So make sure you stay until the end!

Episode 88: Securing SQL Databases though the eyes of an attacker01 Dec 202300:45:53

In this episode Michael talks with colleagues in the Azure Data Platform Security Team, Sharath Unni and Raul Garcia about securing Azure SQL DB, SQL MI and SQL Server through the eyes of an attacker.

Episode 87: Advances in Always Encrypted and Transparent Data Encryption15 Nov 202300:21:07

In this episode, Michael talks with his colleagues Pieter Vanhove and Mirek Sztajno about updates to Always Encrypted and Transparent Data Encryption in SQL Server and Azure SQL DB.

Episode 86: Zero Trust Playbook Series Zero Trust Overview and Playbook Introduction31 Oct 202300:34:20
In this episode Michael talks with guest Nikhil Kumar and our own Mark Simos about a new book they have co-authored named "Zero Trust Playbook Series Zero Trust Overview and Playbook Introduction: Actionable Guidance for Business, Security, and Technology Leaders and Practitioners."
Episode 85: Security Bug Bounties11 Oct 202300:24:47
In this episode Michael and Sarah talk with guest Madeline Eckert about Security Bug Bounties.We also discuss Azure Security news about SQL Server 2022, Azure certificate changes, TLS 1.0 and 1.1 deprecation, GitHub security scanning, Ransomeware defenses, Zero Trust and more.; and by 'more' we mean lock-picking!
Episode 84: Attack Simulation22 Sep 202300:44:10
In this episode Michael, Sarah, Gladys, and Mark talk with guest Roberto Rodriguez about attack simulation, Cloud Katana, and AI.We also discuss Azure Security news about Azure SQL DB, Azure Key Vault, Cosmos DB, Trusted Launch VMs, Azure Artifacts, Zero Trust, Windows and TLS and Entra ID.
Episode 83: PowerShell Automation and Scripting for Cybersecurity14 Aug 202300:36:48
In this episode Michael and Sarah with guest Miriam Wiesner about her new book, "PowerShell Automation and Scripting for Cybersecurity" which comes out soon. We also discussed Azure Security news about: Azure SQL DB Always Encrypted improvements, Azure SQL Managed Instance, App Gateway for Containers and Bring your own Key for AKS Ephemeral Disks.
© My Podcast Data · Independent project · Data from Apple & Spotify