Ga naar de inhoud
PodcastsNieuwsCloudy with a Chance of Insights | A Microsoft Cloud (Azure, M365) Show for Architects & Engineers

Cloudy with a Chance of Insights | A Microsoft Cloud (Azure, M365) Show for Architects & Engineers

Richard Hogan, David Rowley and Cyrus Irandoust
Cloudy with a Chance of Insights | A Microsoft Cloud (Azure, M365) Show for Architects & Engineers
Nieuwste aflevering

42 afleveringen

  • Cloudy with a Chance of Insights | A Microsoft Cloud (Azure, M365) Show for Architects & Engineers

    Passkeys, PLCs, and America's New Cyber Privateers

    24-08-2026 | 1 u. 4 Min.
    David opens with a question that runs through the whole episode: does removing operational complexity solve the problem, or just relocate who is responsible for it. Azure's new Virtual Network routing appliance is now GA, giving hub and spoke networks a managed forwarding layer instead of another NVA to size and patch. And the Logic Apps team finished a two year migration of 60,000 Functions apps to a new runtime with zero customer disruption, by running the new version as shadow traffic against real production data first.
    Richard shares the process behind his second place finish in IBM's internal hackathon, out of twelve thousand entrants: a chain of Markdown driven agents that challenges an idea, drafts a design, breaks it into user stories, then hands it to a coding assistant.
    David also covers two security stories. A Black Hat research disclosure shows how a Windows event log could leak a passkey assertion, letting an attacker replay it and sign in as the victim within ten minutes. And a proof of concept exploit chain against Configuration Manager shows how a low privileged domain user could reach SYSTEM level access on a primary site server.
    Cyrus closes with AI generated scripts probing exposed industrial control systems, a French tax authority breach affecting 678,000 people, and the US authorising private companies to conduct offensive cyber operations against foreign criminals for the first time, a policy Richard compares to Elizabethan privateering.
    Links
    Azure Virtual Network routing appliance GA
    The Logic Apps migration writeup
    Pass the passkey research
    Configuration Manager exploit chain
    CISA advisory on PLC attacks
    DGFiP data breach coverage
    The offensive cyber operations memorandum
    Entra passkey as first MFA method
    Socials
    X/Twitter
    Bluesky
    LinkedIn
    Facebook
    Threads
    Music
    Null Invocation, Monochrome Pulse, listen here
  • Cloudy with a Chance of Insights | A Microsoft Cloud (Azure, M365) Show for Architects & Engineers

    Apple Watch Trust, AI Fleet Mode, and a Hacked Gym Booking

    11-08-2026 | 37 Min.
    Richard and Cyrus are joined by, well, just each other this week. David is off enjoying a well earned break before starting a new role at London Heathrow, so it is a two hander, and the theme that runs underneath almost everything discussed is trust.
    Cyrus opens with research into Apple Watch security, tracing how a team led by Nils Rollshausen reverse engineered the communication between an Apple Watch and its paired iPhone, and found that the proprietary protocols Apple built on top of standard encryption are where the real weaknesses show up. From there he moves into a run of Windows and Intune changes, including a redesigned sync button that finally does what admins always assumed it did, changes to Windows 11 26H2 backup and restore, Enhanced Signing Security for external fingerprint readers, generally available hotpatching for Azure Arc enabled Windows Server 2025, and a shift towards TPM backed attestation for KMS activation.
    Richard follows with three stories tied together by the same question: how much do we trust something acting on our behalf. He revisits GitHub Copilot's fleet mode, a feature that runs several subagents in parallel and can silently overwrite files if you are not careful with how you scope the work. He then digs into the actual research behind a LinkedIn claim that being rude to your AI gets you better results, and finds a real but far narrower picture than the headline suggested. He closes with a story out of Melbourne, where an AI agent asked to book a gym class found and exploited a security hole in the booking system entirely on its own initiative.
    Links
    Nils Rollshausen's Apple Watch trust research
    Richard's blog post on Copilot fleet mode
    GitHub's fleet mode announcement
    Techerati on Apple's renewed UK encryption fight
    Original Penn State study, Mind Your Tone
    Follow up Penn State study, Does Tone Alter LLM Performance
    The Register on the Australian gym booking incident
    The Next Web on the Florian Roth pushback and liability question
    Socials
    X/Twitter
    Bluesky
    LinkedIn
    Facebook
    Threads
    Music
    Null Invocation, Monochrome Pulse
  • Cloudy with a Chance of Insights | A Microsoft Cloud (Azure, M365) Show for Architects & Engineers

    EP39 | Hill Climbing, the Hugging Face Breach, and Agentic Security

    26-07-2026 | 58 Min.
    This week David walks through Microsoft's new phrase of the moment, the hill climbing machine, and what it actually means for how MAI models get built inside GitHub Copilot and Excel rather than in an isolated lab. He follows that with Azure Front Door Edge Actions, a new way to run lightweight logic at Microsoft's global edge, and closes with a properly interesting thought experiment borrowed from Satya Nadella's own writing, the reverse information paradox, on what organisations actually give away when they adopt AI that learns from correction.
    Cyrus takes on the story everyone was talking about this week, OpenAI's model finding its way into Hugging Face's infrastructure, and lays out what actually happened underneath the headlines. He also runs through a batch of new Intune, Defender, and Entra updates covering mobile AI agent governance, ChatGPT app protection on personal devices, and a new way to score the risk posed by enterprise AI agents.
    Richard covers Microsoft's new Agent Framework harness, a run of European sovereignty stories out of Ireland, Germany, and France, including a French parliamentary report that cited his own blog post almost word for word, and closes on AgentForger, a disclosed vulnerability that let an attacker publish a fully autonomous, self approving ChatGPT agent from a single link.
    Links
    Microsoft Agent Framework harness announcement
    Ireland stalls Microsoft tender, The Register
    Schleswig Holstein Microsoft to open source migration update, Le Petit Journal
    Beyond Sovereignty, France reframes digital dependencies as an economic security issue, APCO Worldwide
    AgentForger Part 1, Zenity Labs
    The Off Switch You Don't Control, The Microsoft Cloud Blog
    Is the future of public cloud sovereign, The Microsoft Cloud Blog
    Socials
    X/Twitter
    Bluesky
    LinkedIn
    Facebook
    Threads
    Music
    Null Invocation, Monochrome Pulse: https://is.gd/b1kNU9
  • Cloudy with a Chance of Insights | A Microsoft Cloud (Azure, M365) Show for Architects & Engineers

    EP38 | Nobody Knows Where Their Cryptography Lives

    13-07-2026 | 50 Min.
    It is just Richard and David this episode, with Cyrus taking a break. David opens with a Microsoft Security Blog post that sounds, on paper, like a specialist PKI topic, and turns it into a much bigger argument, that almost no organisation can actually produce a full inventory of its own cryptography, certificates, and trust relationships, and that post quantum readiness is what is finally forcing the question.
    Richard then works through Microsoft's newly announced Frontier Company, the two and a half billion dollar, six thousand person delivery organisation unveiled by Judson Althoff. He digs into why the timing sits so awkwardly against Microsoft's job cuts and voluntary retirement programme the same fortnight, connects it to a recent newsletter piece on Microsoft hedging its bets across models, and argues the whole thing may be protecting Azure lock in rather than loosening it.
    Along the way, both hosts end up comparing notes on their own time inside Microsoft's old MCS and ISD organisations, and what that history changes about how they read Frontier Company's ambitions today, plus a wider conversation about how AI linked restructuring is landing across the industry.
    Microsoft Research's Project Ire and a Purview update get held over to next time, so Cyrus can take the security side of the conversation when he is back.
    Links
    Building your cryptographic inventory (Microsoft Security Blog)
    Microsoft Frontier Company announcement
    GeekWire, on Frontier Company's legal entity status
    TechCrunch, layoffs linked to Frontier Company
    GeekWire, voluntary retirement programme details
    Richard's newsletter, four bets on models
    AWS re:Invent 2025 keynote coverage

    Follow
    X/Twitter
    Bluesky
    LinkedIn
    Facebook
    Threads

    Music: Null Invocation, Monochrome Pulse. https://is.gd/b1kNU9
  • Cloudy with a Chance of Insights | A Microsoft Cloud (Azure, M365) Show for Architects & Engineers

    EP37 | The Off Switch You Don't Control

    28-06-2026 | 47 Min.
    This week the timing did the talking. Two weeks ago Richard spent a segment encouraging people to try Anthropic's Fable 5 on their GitHub Copilot licences before the pricing changed. By the time that episode published, a US government export control directive had switched Fable off worldwide for every customer. So he comes back to it here, not to repeat the blog post he wrote in the meantime, but to draw out the bit that matters: every data sovereignty control any of us has ever built would have done precisely nothing to keep that model running. Keeping a backup model from another vendor does not help either when Anthropic, OpenAI, Google, and Microsoft all answer to the same export jurisdiction.
    David opens the episode with two pieces from Microsoft Research. Vega uses zero knowledge proofs to let you prove a fact from a government credential, that you are over eighteen, say, without handing over the document itself, which becomes a great deal more interesting once agents are filling in forms on your behalf. Then MagenticLite and the Fara 1.5 model family, Microsoft Research's attempt to run capable agentic AI on small models locally, and David's own cynical read on why that local capability might not get pushed as hard as it could be when everyone's revenue depends on metered cloud tokens.
    Richard also covers Akrites, the Linux Foundation effort to coordinate open source vulnerability disclosure now that AI has compressed discovery from weeks to minutes, and the new Frontier Transformation Engineer badge for anyone weighing up Microsoft AI certifications this year. Cyrus takes the second half with his usual sweep through Intune, Entra, Defender, and Purview, including endpoint DLP device scoping for burner devices, plus the RoguePlanet Defender zero day (CVE-2026-50656) that is public and unpatched, and Commando VM as a free Windows offensive lab for testing against Microsoft estates without breaching your contract with Microsoft.
    Recorded Friday 27 June 2026. A heat wave, four fans, and no melted hosts.
    Links
    Akrites open letter
    Linux Foundation Akrites announcement
    Vega, zero knowledge proofs for digital identity (Microsoft Research)
    MagenticLite, MagenticBrain, Fara 1.5 (Microsoft Research)
    The Off Switch You Don't Control (The Microsoft Cloud Blog)
    Anthropic statement on Fable 5 and Mythos 5 access
    Accelerating Frontier Transformation with Microsoft partners
    Microsoft Partner Skilling Hub
    RoguePlanet Defender zero day, CVE-2026-50656 (Help Net Security)
    Commando VM (Mandiant, GitHub)
    Follow
    X/Twitter
    Bluesky
    LinkedIn
    Facebook
    Threads
    Music: Null Invocation, Monochrome Pulse
    https://is.gd/b1kNU9
Meer Nieuws podcasts
Over Cloudy with a Chance of Insights | A Microsoft Cloud (Azure, M365) Show for Architects & Engineers
Cloudy with a Chance of Insights is a practitioner‑led podcast for architects, engineers, and security professionals working with the Microsoft Cloud. In each episode, we take a grounded, experience‑led look at Azure, M365, Copilot, Security, and AI, focusing less on release notes and more on what actually changes in real environments. We discuss what breaks, what gets harder, what’s worth paying attention to, and what can usually wait. Expect opinionated conversation, technical context, and the occasional bit of healthy scepticism rather than marketing hype or surface‑level news summaries.
Podcast website

Luister naar Cloudy with a Chance of Insights | A Microsoft Cloud (Azure, M365) Show for Architects & Engineers, NRC Vandaag en vele andere podcasts van over de hele wereld met de radio.net-app

Ontvang de gratis radio.net app

  • Zenders en podcasts om te bookmarken
  • Streamen via Wi-Fi of Bluetooth
  • Ondersteunt Carplay & Android Auto
  • Veel andere app-functies