Category Archives: LinkedIN

Closer Look at Sentinel Automation in the Defender Portal

I was recently asked, how are automation rules managed in the Defender portal when multiple Sentinel workspaces are connected? I expected the answer to be simple. After all, I’ve spent a significant amount of time working with Sentinel, and not many things in this space come as a surprise anymore. I opened the Defender portal… Read More: Closer Look at Sentinel Automation in the Defender Portal »

Waiting for Sentinel Data Lake?

Microsoft first announced Sentinel Data Lake in July 2025 and immediately generated a lot of interest across the security community. The value proposition was compelling: For many organizations, especially those collecting hundreds of gigabytes or even terabytes of data per day, Sentinel Data Lake looked like the next logical evolution of the platform. Then reality… Read More: Waiting for Sentinel Data Lake? »

Enterprise AI Connectors for Purview

Have you heard about Microsoft’s new Claude Enterprise connector for Purview. At a high level, enterprise AI connectors are designed to collect and govern activity occurring within enterprise AI platforms. Depending on the platform and integration, that can include information such as user activity, utilization, prompts, responses, uploaded content, administrative actions, and other telemetry generated… Read More: Enterprise AI Connectors for Purview »

Microsoft Security and AI Certification Roadmap

Recently, I found myself thinking about certification exams again. It had been several months since I last sat for a major certification exam, and while reviewing some of Microsoft’s newer AI certifications, I started asking myself a simple question: What should I take next? That led me down a rabbit hole of reviewing Microsoft’s current… Read More: Microsoft Security and AI Certification Roadmap »

Building a YouTube Statistics Tracker at 35,000 Feet

I was flying home from a security conference in Boston on a Friday evening, enjoying an unexpected complimentary upgrade to business class, listening to Dungeon Crawler Carl, and reflecting on some of the conversations I had over the previous few days. During one of those conversations, I had confidently stated that a YouTube channel I… Read More: Building a YouTube Statistics Tracker at 35,000 Feet »

Sentinel TVM Snapshot Data Connector V2

Why I Started Building This Several weeks ago, I set out to create a proper Microsoft Defender Vulnerability Management (TVM) data connector for Microsoft Sentinel. What started as a relatively simple side project turned into a much larger effort involving API comparisons, ingestion architecture, scaling limitations, and a deeper understanding of how Defender exposure-management data… Read More: Sentinel TVM Snapshot Data Connector V2 »

Understanding Microsoft’s Growing AI Ecosystem

Over the last two years, Microsoft’s AI ecosystem has expanded incredibly fast. What initially started as a relatively straightforward launch of Microsoft 365 Copilot has rapidly evolved into a much broader platform involving enterprise grounding, semantic intelligence, multi-model orchestration, AI agents, delegated workflows, governance platforms, and enterprise AI security controls. Along the way, Microsoft has… Read More: Understanding Microsoft’s Growing AI Ecosystem »

Securing AI Depends on How AI Is Being Used

The phrase “AI Security” is becoming increasingly difficult to define because the risks change dramatically depending on how organizations interact with AI. Sometimes employees are simply using public AI services to summarize documents or generate content. Sometimes organizations deploy enterprise copilots grounded on internal data. Increasingly, organizations are building AI workflows and agents capable of… Read More: Securing AI Depends on How AI Is Being Used »

Authorized Access Unauthorized Destinations

Security teams are starting to use and pay closer attention to tools like MCP servers, AI agents, GitHub Copilot, VS Code integrations, and other AI-assisted operational tooling. As organizations become more familiar with these tools, it naturally raises questions around the privacy and security implications of connecting them to enterprise systems. The real issue is… Read More: Authorized Access Unauthorized Destinations »

AI-Driven SOC Series Overview

What started as a simple idea, exploring how AI could support a modern Security Operations Center, has grown into a structured series that documents both real solutions and the learning journey behind them. This collection of articles is intended to walk through the evolution from traditional, deterministic automation toward more adaptive, agent-driven approaches, while sharing… Read More: AI-Driven SOC Series Overview »

Intro and Initial Deployment of a Foundry Agent

Introduction This series started with a simple question: what does an agentic SOC actually look like in practice? Early on, I focused on making that idea tangible. Instead of staying theoretical, I built out a working approach using Azure AI Foundry and Azure Logic Apps. The goal was not to prescribe a single “right” architecture,… Read More: Intro and Initial Deployment of a Foundry Agent »

Sentinel TVM Snapshot Data Connector

This started as a straightforward idea. I wanted to get Defender Threat and Vulnerability Management (TVM) data into Microsoft Sentinel for long-term retention and dashboarding. The data potentially has value, and Sentinel is designed to ingest large volumes of security data, so on the surface it felt like something that should already exist. After building… Read More: Sentinel TVM Snapshot Data Connector »