Author Archives: Andrew Blumhardt

The Strange Economics of Artificial Intelligence

I started thinking about the economics of artificial intelligence on the flight home from DEF CON. I had spent the week talking with security researchers, developers, technology companies, and vendors, nearly all of whom were discussing AI in one form or another. Some were using it to improve existing products. Others were building entirely new… Read More: The Strange Economics of Artificial Intelligence »

Closer Look at Sentinel Automation in the Defender Portal

I was recently asked, how are automation rules managed in the Defender portal when multiple Sentinel workspaces are connected? I expected the answer to be simple. After all, I’ve spent a significant amount of time working with Sentinel, and not many things in this space come as a surprise anymore. I opened the Defender portal… Read More: Closer Look at Sentinel Automation in the Defender Portal »

Waiting for Sentinel Data Lake?

Microsoft first announced Sentinel Data Lake in July 2025 and immediately generated a lot of interest across the security community. The value proposition was compelling: For many organizations, especially those collecting hundreds of gigabytes or even terabytes of data per day, Sentinel Data Lake looked like the next logical evolution of the platform. Then reality… Read More: Waiting for Sentinel Data Lake? »

Sentinel and Defender Incident Correlation

This is a topic I find myself explaining regularly, especially when customers are migrating to the unified Defender experience and trying to understand how existing automation, ITSM integrations, and incident workflows will be affected. It’s one of my longer articles, but understanding alerts, incidents, and correlation is an important part of understanding how Microsoft Sentinel… Read More: Sentinel and Defender Incident Correlation »

Enterprise AI Connectors for Purview

Have you heard about Microsoft’s new Claude Enterprise connector for Purview. At a high level, enterprise AI connectors are designed to collect and govern activity occurring within enterprise AI platforms. Depending on the platform and integration, that can include information such as user activity, utilization, prompts, responses, uploaded content, administrative actions, and other telemetry generated… Read More: Enterprise AI Connectors for Purview »

Microsoft Security and AI Certification Roadmap

Recently, I found myself thinking about certification exams again. It had been several months since I last sat for a major certification exam, and while reviewing some of Microsoft’s newer AI certifications, I started asking myself a simple question: What should I take next? That led me down a rabbit hole of reviewing Microsoft’s current… Read More: Microsoft Security and AI Certification Roadmap »

Building a YouTube Statistics Tracker at 35,000 Feet

I was flying home from a security conference in Boston on a Friday evening, enjoying an unexpected complimentary upgrade to business class, listening to Dungeon Crawler Carl, and reflecting on some of the conversations I had over the previous few days. During one of those conversations, I had confidently stated that a YouTube channel I… Read More: Building a YouTube Statistics Tracker at 35,000 Feet »

Sentinel TVM Snapshot Data Connector V2

Why I Started Building This Several weeks ago, I set out to create a proper Microsoft Defender Vulnerability Management (TVM) data connector for Microsoft Sentinel. What started as a relatively simple side project turned into a much larger effort involving API comparisons, ingestion architecture, scaling limitations, and a deeper understanding of how Defender exposure-management data… Read More: Sentinel TVM Snapshot Data Connector V2 »

Understanding Microsoft’s Growing AI Ecosystem

Over the last two years, Microsoft’s AI ecosystem has expanded incredibly fast. What initially started as a relatively straightforward launch of Microsoft 365 Copilot has rapidly evolved into a much broader platform involving enterprise grounding, semantic intelligence, multi-model orchestration, AI agents, delegated workflows, governance platforms, and enterprise AI security controls. Along the way, Microsoft has… Read More: Understanding Microsoft’s Growing AI Ecosystem »

Securing AI Depends on How AI Is Being Used

The phrase “AI Security” is becoming increasingly difficult to define because the risks change dramatically depending on how organizations interact with AI. Sometimes employees are simply using public AI services to summarize documents or generate content. Sometimes organizations deploy enterprise copilots grounded on internal data. Increasingly, organizations are building AI workflows and agents capable of… Read More: Securing AI Depends on How AI Is Being Used »