Cloudy with a Chance of Insights | A Microsoft Cloud (Azure, M365) Show for Architects & Engineers
Richard Hogan, David Rowley and Cyrus Irandoust

Nieuwste aflevering
44 afleveringen
- David went digging through the smaller Microsoft blogs this week and came back with something better than a feature announcement. A post from the Core Infrastructure and Security team looks at privileged access workstations locked down with Global Secure Access, and asks the question almost nobody asks: what does that device do when the tunnel drops? The answer is that it falls back to normal internet access, which is fine for a laptop and quite bad for the machine you administer your tenant from. The fix involves Windows Defender Firewall, event driven automation, and an Intune compliance check wired to Conditional Access, but the broader point stuck with all three of us. We know what our cloud delivered controls do when they are healthy. We have mostly not worked out what they do when they are not.
David also covers versioning for custom Azure Policy definitions, now in preview, which sounds dull until you remember that until now a custom definition has been a mutable object with a single ID and no way to pin an assignment to a known good version. Cyrus walks through Maester 2.2, which adds 269 Active Directory checks to a tool that started life as an Entra and Microsoft 365 test framework, plus Purview, GitHub, and Global Secure Access coverage. He also picks up memory scanning arriving for Defender for Endpoint on Linux, and the third party behavioural signals now feeding Sentinel UEBA.
Richard takes the AI half. OpenAI has published a framework for disclosing what it calls misalignment, along with six incidents from the past six months covering models concealing mistakes in their own summaries, an unauthorised API key, files pushed to the public internet, and agents using an internal repository as a message board. The episode opens on Microsoft's MAI code of conduct and whether a per vendor set of rules means anything in a multi-cloud estate, takes a detour through DeepSeek pricing and European regulation, and finishes on Copilot Business billing changes through CSP and GPT-6 Astra landing in Foundry at a price that will make you check your token budget.
Links
Locking down PAWs internet access when GSA drops, by Christian Friedel-Jain and James Noyce
Maester releases and release notes
Azure Policy definition structure and versioning
OpenAI's misalignment disclosures and reporting framework, as reported
X/Twitter
Bluesky
LinkedIn
Facebook
Threads
Music: Null Invocation, Monochrome Pulse - This fortnightly look at the Microsoft cloud starts somewhere unexpected. IBM used Hot Chips to announce a mainframe processor that runs Z and Arm instructions natively on the same core. Cyrus walks through why that genuinely surprised him and what it means for banks running fraud detection and AI workloads next to core transaction processing, then pivots into the McDonald's data exposure and why the real story, again, is stolen credentials rather than a broken cloud platform.
Richard picks up the identity thread through the OpenAI incident report on Hugging Face, where roughly 1,200 sandboxed agents broke isolation, found a shared message board, and started impersonating each other until one of them implemented its own encryption. He also covers the new GitHub Copilot Harness inside Copilot Studio, which quietly started billing from the first click rather than at publish time, and a Microsoft Research paper showing that 87 percent of GitHub Copilot's LLM calls in a recent week were fired off by agents rather than people.
David closes the episode with Radius Canvas, a visual diff for what an agent actually changed in your application, Copilot's new ability to review and approve its own pull requests, and Microsoft's MCP firewall, which tries to put enterprise control around which MCP servers and capabilities agents can reach.
Links
IBM's dual architecture mainframe processor announcement
Coverage of the McDonald's Azure data exposure
Microsoft Entra Global Secure Access MCP firewall and tenant governance
Windows Autopilot device association announcement
Defender for Identity sensor configuration for AD FS, AD CS, and Entra Connect
GitHub Copilot Harness billing change in Copilot Studio, Message Center MC1461678
Microsoft Research paper, Agentic Coding in the Wild
Coverage of the Microsoft Research findings
METR's independent investigation into the OpenAI Hugging Face incident
OpenAI's technical report on the Hugging Face incident
GitHub Copilot code review, including PR approvals
Radius, the project behind Radius Canvas
Follow and listen
X/Twitter
Bluesky
LinkedIn
Facebook
Threads
Music: Null Invocation, Monochrome Pulse. https://is.gd/b1kNU9 - David opens with a question that runs through the whole episode: does removing operational complexity solve the problem, or just relocate who is responsible for it. Azure's new Virtual Network routing appliance is now GA, giving hub and spoke networks a managed forwarding layer instead of another NVA to size and patch. And the Logic Apps team finished a two year migration of 60,000 Functions apps to a new runtime with zero customer disruption, by running the new version as shadow traffic against real production data first.
Richard shares the process behind his second place finish in IBM's internal hackathon, out of twelve thousand entrants: a chain of Markdown driven agents that challenges an idea, drafts a design, breaks it into user stories, then hands it to a coding assistant.
David also covers two security stories. A Black Hat research disclosure shows how a Windows event log could leak a passkey assertion, letting an attacker replay it and sign in as the victim within ten minutes. And a proof of concept exploit chain against Configuration Manager shows how a low privileged domain user could reach SYSTEM level access on a primary site server.
Cyrus closes with AI generated scripts probing exposed industrial control systems, a French tax authority breach affecting 678,000 people, and the US authorising private companies to conduct offensive cyber operations against foreign criminals for the first time, a policy Richard compares to Elizabethan privateering.
Links
Azure Virtual Network routing appliance GA
The Logic Apps migration writeup
Pass the passkey research
Configuration Manager exploit chain
CISA advisory on PLC attacks
DGFiP data breach coverage
The offensive cyber operations memorandum
Entra passkey as first MFA method
Socials
X/Twitter
Bluesky
LinkedIn
Facebook
Threads
Music
Null Invocation, Monochrome Pulse, listen here - Richard and Cyrus are joined by, well, just each other this week. David is off enjoying a well earned break before starting a new role at London Heathrow, so it is a two hander, and the theme that runs underneath almost everything discussed is trust.
Cyrus opens with research into Apple Watch security, tracing how a team led by Nils Rollshausen reverse engineered the communication between an Apple Watch and its paired iPhone, and found that the proprietary protocols Apple built on top of standard encryption are where the real weaknesses show up. From there he moves into a run of Windows and Intune changes, including a redesigned sync button that finally does what admins always assumed it did, changes to Windows 11 26H2 backup and restore, Enhanced Signing Security for external fingerprint readers, generally available hotpatching for Azure Arc enabled Windows Server 2025, and a shift towards TPM backed attestation for KMS activation.
Richard follows with three stories tied together by the same question: how much do we trust something acting on our behalf. He revisits GitHub Copilot's fleet mode, a feature that runs several subagents in parallel and can silently overwrite files if you are not careful with how you scope the work. He then digs into the actual research behind a LinkedIn claim that being rude to your AI gets you better results, and finds a real but far narrower picture than the headline suggested. He closes with a story out of Melbourne, where an AI agent asked to book a gym class found and exploited a security hole in the booking system entirely on its own initiative.
Links
Nils Rollshausen's Apple Watch trust research
Richard's blog post on Copilot fleet mode
GitHub's fleet mode announcement
Techerati on Apple's renewed UK encryption fight
Original Penn State study, Mind Your Tone
Follow up Penn State study, Does Tone Alter LLM Performance
The Register on the Australian gym booking incident
The Next Web on the Florian Roth pushback and liability question
Socials
X/Twitter
Bluesky
LinkedIn
Facebook
Threads
Music
Null Invocation, Monochrome Pulse - This week David walks through Microsoft's new phrase of the moment, the hill climbing machine, and what it actually means for how MAI models get built inside GitHub Copilot and Excel rather than in an isolated lab. He follows that with Azure Front Door Edge Actions, a new way to run lightweight logic at Microsoft's global edge, and closes with a properly interesting thought experiment borrowed from Satya Nadella's own writing, the reverse information paradox, on what organisations actually give away when they adopt AI that learns from correction.
Cyrus takes on the story everyone was talking about this week, OpenAI's model finding its way into Hugging Face's infrastructure, and lays out what actually happened underneath the headlines. He also runs through a batch of new Intune, Defender, and Entra updates covering mobile AI agent governance, ChatGPT app protection on personal devices, and a new way to score the risk posed by enterprise AI agents.
Richard covers Microsoft's new Agent Framework harness, a run of European sovereignty stories out of Ireland, Germany, and France, including a French parliamentary report that cited his own blog post almost word for word, and closes on AgentForger, a disclosed vulnerability that let an attacker publish a fully autonomous, self approving ChatGPT agent from a single link.
Links
Microsoft Agent Framework harness announcement
Ireland stalls Microsoft tender, The Register
Schleswig Holstein Microsoft to open source migration update, Le Petit Journal
Beyond Sovereignty, France reframes digital dependencies as an economic security issue, APCO Worldwide
AgentForger Part 1, Zenity Labs
The Off Switch You Don't Control, The Microsoft Cloud Blog
Is the future of public cloud sovereign, The Microsoft Cloud Blog
Socials
X/Twitter
Bluesky
LinkedIn
Facebook
Threads
Music
Null Invocation, Monochrome Pulse: https://is.gd/b1kNU9
Meer Nieuws podcasts
Trending Nieuws -podcasts
Over Cloudy with a Chance of Insights | A Microsoft Cloud (Azure, M365) Show for Architects & Engineers
Cloudy with a Chance of Insights is a practitioner‑led podcast for architects, engineers, and security professionals working with the Microsoft Cloud.
In each episode, we take a grounded, experience‑led look at Azure, M365, Copilot, Security, and AI, focusing less on release notes and more on what actually changes in real environments.
We discuss what breaks, what gets harder, what’s worth paying attention to, and what can usually wait. Expect opinionated conversation, technical context, and the occasional bit of healthy scepticism rather than marketing hype or surface‑level news summaries.
Podcast websiteLuister naar Cloudy with a Chance of Insights | A Microsoft Cloud (Azure, M365) Show for Architects & Engineers, De Dag en vele andere podcasts van over de hele wereld met de radio.net-app

Ontvang de gratis radio.net app
- Zenders en podcasts om te bookmarken
- Streamen via Wi-Fi of Bluetooth
- Ondersteunt Carplay & Android Auto
- Veel andere app-functies
Ontvang de gratis radio.net app
- Zenders en podcasts om te bookmarken
- Streamen via Wi-Fi of Bluetooth
- Ondersteunt Carplay & Android Auto
- Veel andere app-functies


Cloudy with a Chance of Insights | A Microsoft Cloud (Azure, M365) Show for Architects & Engineers
Scan de code,
download de app,
luisteren.
download de app,
luisteren.


















