1
00:00:06,680 --> 00:00:10,360
Welcome to the Blue Security 
Podcast, a weekly podcast for 

2
00:00:10,360 --> 00:00:13,600
information security defenders 
where we bring you discussions 

3
00:00:13,600 --> 00:00:16,960
on best practices, tools, and 
implementation for enterprise 

4
00:00:16,960 --> 00:00:19,200
security. 
Now here are your hosts for 

5
00:00:19,200 --> 00:00:21,760
today's show, Andy JA and Adam 
Brewer. 

6
00:00:22,360 --> 00:00:25,080
Welcome to this week's episode 
of the Blue Security Podcast. 

7
00:00:25,360 --> 00:00:28,440
I'm Andy, your host. 
I'm Adam, your Co host. 

8
00:00:29,160 --> 00:00:32,680
We have two topics that we 
wanted to talk about today. 

9
00:00:32,680 --> 00:00:39,560
The first one is Agent 365. 
This is the new dashboard that I

10
00:00:39,560 --> 00:00:43,880
will monitor all the agents in 
the Microsoft estate. 

11
00:00:44,320 --> 00:00:46,960
So we'll dive into that because 
it's generally available now. 

12
00:00:47,480 --> 00:00:51,680
And then also we want to talk 
about M Dash, which is a new 

13
00:00:51,680 --> 00:00:54,960
vulnerability scanner that's 
actually multi model from 

14
00:00:54,960 --> 00:00:58,480
Microsoft. 
And so two really cool things 

15
00:00:58,480 --> 00:01:01,560
that are coming out, but both AI
based and fueled by AI. 

16
00:01:01,560 --> 00:01:05,160
So before we get started, since 
we are going to be talking about

17
00:01:05,160 --> 00:01:08,000
Microsoft, we'll go through our 
standard disclaimer. 

18
00:01:08,680 --> 00:01:11,560
Andy and I both work for 
Microsoft in our field security 

19
00:01:11,560 --> 00:01:13,600
sales. 
We record the show outside of 

20
00:01:13,600 --> 00:01:15,880
work. 
As I say this, it's a Sunday 

21
00:01:15,880 --> 00:01:19,280
night, it's almost 8:00 at 
night, so definitely outside of 

22
00:01:19,280 --> 00:01:21,320
work hours. 
And we saw fun the show. 

23
00:01:21,320 --> 00:01:24,280
Everything from our domain to 
our recording platform and 

24
00:01:24,280 --> 00:01:26,920
everything in between comes out 
of our pockets. 

25
00:01:26,920 --> 00:01:29,920
We don't take sponsorship. 
We don't have any ad revenue. 

26
00:01:30,000 --> 00:01:33,280
Truly a labor of love. 
And so the opinions and 

27
00:01:33,680 --> 00:01:36,400
attitudes you're about to hear 
expressed are those of Adam 

28
00:01:36,400 --> 00:01:39,520
Brewer and Andy Jaw, and do not 
necessarily reflect those of 

29
00:01:39,520 --> 00:01:42,560
Microsoft Corporation. 
All right, and with that, let's 

30
00:01:42,680 --> 00:01:46,560
dive into it here. 
So I'm sure you've heard about 

31
00:01:46,640 --> 00:01:49,800
AI agents because that's the new
buzzword. 

32
00:01:49,800 --> 00:01:53,720
Last year was all about just 
LLMS and AI, and this year it's 

33
00:01:53,720 --> 00:01:56,920
about these agents. 
And so we have agents in 

34
00:01:56,920 --> 00:02:02,280
Microsoft Copilot and Teams and 
M365, but also there's other SAS

35
00:02:02,280 --> 00:02:05,720
agents that are getting 
connected to sensitive data, 

36
00:02:06,160 --> 00:02:10,400
local autonomous agents that are
running directly on devices. 

37
00:02:10,400 --> 00:02:13,880
You know, we did a whole show on
Open Claw and why those, you 

38
00:02:13,880 --> 00:02:16,040
know, and that's just one 
example. 

39
00:02:16,040 --> 00:02:18,960
There's, there's a bunch of them
that people are running as well.

40
00:02:18,960 --> 00:02:23,760
And so the core problem for 
defenders is that these agents 

41
00:02:24,200 --> 00:02:28,280
proliferate really fast, and 
they span across apps and points

42
00:02:28,320 --> 00:02:32,720
and the cloud, and they often 
operate completely outside of 

43
00:02:32,720 --> 00:02:36,160
the visibility of the teams that
are responsible for managing 

44
00:02:36,160 --> 00:02:40,880
that risk, the security teams. 
Microsoft Agent 365 is really 

45
00:02:40,880 --> 00:02:42,960
designed specifically for that 
purpose. 

46
00:02:42,960 --> 00:02:46,680
It's to help organizations take 
control and visit, see that 

47
00:02:46,680 --> 00:02:50,680
visibility of that agent sprawl.
It serves as that control plane 

48
00:02:51,040 --> 00:02:55,640
to observe, govern and secure 
agents and their interactions. 

49
00:02:55,680 --> 00:03:00,040
And that includes agents built 
with Microsoft AI and agents 

50
00:03:00,040 --> 00:03:02,480
from eco partner systems as 
well. 

51
00:03:02,760 --> 00:03:06,520
So using the admin and security 
flows that teams are already 

52
00:03:06,520 --> 00:03:13,760
using within C5 S, Some of the 
key capabilities of Agent 365 is

53
00:03:13,760 --> 00:03:19,120
that they cover agents, whether 
they act on behalf of the user 

54
00:03:19,120 --> 00:03:22,840
with delegated access. 
Like for example, an agent that 

55
00:03:22,840 --> 00:03:26,960
helps employees organize their 
inbox, but it also does it with 

56
00:03:26,960 --> 00:03:30,000
agents that operate with their 
own credentials and scope of 

57
00:03:30,000 --> 00:03:34,920
work, such as like an agent that
autonomously triages like 

58
00:03:34,920 --> 00:03:36,600
support tickets or something 
like that. 

59
00:03:37,520 --> 00:03:43,320
One of the main focuses of Agent
365 is shadow AI, unmanaged 

60
00:03:43,320 --> 00:03:45,120
agents that are quietly 
spreading. 

61
00:03:45,240 --> 00:03:49,440
Users are installing agents 
like, you know, open claw clawed

62
00:03:49,440 --> 00:03:53,720
code on their devices and then 
adapting SAS agents built on 

63
00:03:53,720 --> 00:03:57,320
these platforms. 
Many of these run unmanaged and 

64
00:03:57,320 --> 00:04:01,640
outside of traditional 
governments, and they're doing 

65
00:04:01,640 --> 00:04:05,920
things like autonomously 
executing tasks, modifying code,

66
00:04:05,920 --> 00:04:08,000
accessing confidential 
information. 

67
00:04:08,800 --> 00:04:12,960
And so to address this, 
Microsoft Defender and Intune 

68
00:04:12,960 --> 00:04:16,320
will be able to discover and 
manage local AI agents running 

69
00:04:16,320 --> 00:04:20,079
on Windows devices, starting 
with open Claw agents and then 

70
00:04:20,079 --> 00:04:26,400
expanding to other widely used 
agents like GitHub Copilot, CLI 

71
00:04:26,400 --> 00:04:29,360
and Claw code. 
And then security teams will be 

72
00:04:29,360 --> 00:04:33,120
able to see which devices these 
agents are running on, get like 

73
00:04:33,120 --> 00:04:37,920
an asset context map showing 
connected MCP servers and cloud 

74
00:04:37,920 --> 00:04:40,080
resources those identities can 
reach. 

75
00:04:40,120 --> 00:04:43,920
And then you can apply policy 
based controls to block those 

76
00:04:43,920 --> 00:04:48,120
unmanaged agents And then beyond
like the local agents that we're

77
00:04:48,120 --> 00:04:52,200
talking about here, Agent 365 
can also extend network controls

78
00:04:52,240 --> 00:04:56,120
to Microsoft Copilot Studio 
agents and agents running on 

79
00:04:56,120 --> 00:04:58,120
endpoints, including local 
agents. 

80
00:04:58,280 --> 00:05:03,400
So these controls can help you 
identify unsanctioned AI usage 

81
00:05:04,000 --> 00:05:07,400
and then restrict connections to
only the approved web 

82
00:05:07,400 --> 00:05:12,200
destinations, filter like any 
type of risky foul movements, 

83
00:05:12,280 --> 00:05:15,760
and also you can help block 
malicious prompt base attacks 

84
00:05:15,760 --> 00:05:19,280
before they lead to like any 
harmful actions for your 

85
00:05:19,320 --> 00:05:22,720
organization. out-of-the-box, 
there's going to be a few 

86
00:05:22,720 --> 00:05:25,160
integrations and I'm sure 
there's going to be more coming,

87
00:05:25,280 --> 00:05:27,520
right. 
So right from the start, Agent 

88
00:05:27,520 --> 00:05:31,600
365 registry will be able to 
sync with AWS Bedrock and Google

89
00:05:31,600 --> 00:05:33,760
Cloud connections is entering 
private preview. 

90
00:05:33,760 --> 00:05:37,360
And then it also allows IT teams
to automatically discover 

91
00:05:37,880 --> 00:05:42,360
inventory and perform basic life
cycle governance like stopping, 

92
00:05:42,480 --> 00:05:45,800
starting and deleting agents 
across these multi cloud 

93
00:05:45,800 --> 00:05:48,440
platforms. 
And then on the SAS side, 

94
00:05:49,200 --> 00:05:52,000
there's a whole eco partner 
agents that are going to be 

95
00:05:52,440 --> 00:05:56,880
fully configured to be managed 
by Agent 365 like Genspark. 

96
00:05:57,120 --> 00:05:58,480
I haven't heard of some of these
before. 

97
00:05:58,480 --> 00:06:04,800
So Zensai Ignite and Zendesk, 
which I've heard of of course, 

98
00:06:05,520 --> 00:06:11,200
and then agents that are built 
on platforms like Core, NAN 8 N 

99
00:06:12,360 --> 00:06:15,600
Casto, yeah, just to just to 
name a few, like. 

100
00:06:16,040 --> 00:06:17,280
Where to try? 
Yeah. 

101
00:06:17,680 --> 00:06:21,080
And then organizations can also 
observe and govern these agents 

102
00:06:21,120 --> 00:06:24,520
in this Agent 365 control plane 
with no integration work 

103
00:06:24,520 --> 00:06:26,520
required from IT or security 
teams. 

104
00:06:27,080 --> 00:06:31,440
Another thing is that Windows 
365 for agents is also entering 

105
00:06:31,440 --> 00:06:34,720
public preview, and that 
provides a secure managed 

106
00:06:34,720 --> 00:06:37,200
environment for agents to carry 
out work. 

107
00:06:37,200 --> 00:06:43,120
It's a new class of cloud PCs 
purposely built for agentic 

108
00:06:43,120 --> 00:06:46,800
workloads, managing Intune and 
allowing agents to run in a 

109
00:06:46,800 --> 00:06:49,760
policy controlled environment 
with the same identity, security

110
00:06:49,760 --> 00:06:52,640
and management controls that are
already being used for your 

111
00:06:52,640 --> 00:06:54,920
employees from a licensing 
standpoint. 

112
00:06:54,920 --> 00:06:59,320
It's available in the new M365 
that Adam and I talked about a 

113
00:06:59,480 --> 00:07:02,680
few weeks back, so if you missed
that, go and review that show. 

114
00:07:03,400 --> 00:07:08,000
You can also purchase it as a 
stand alone product at $15 per 

115
00:07:08,000 --> 00:07:10,960
user per month. 
That's the retail price and then

116
00:07:10,960 --> 00:07:15,240
it's per user or an individual 
who manages and sponsors an 

117
00:07:15,240 --> 00:07:18,880
agent specifically or uses 
agents to do the work on their 

118
00:07:18,880 --> 00:07:21,840
behalf. 
So any agent activity is going 

119
00:07:21,840 --> 00:07:24,880
to be covered as long as your 
licensing per user. 

120
00:07:25,160 --> 00:07:28,280
So yeah, this is now all 
generally available. 

121
00:07:28,440 --> 00:07:31,640
And you know, one of the things 
again, kind of near and dear to 

122
00:07:31,640 --> 00:07:34,080
my heart, if you work in the 
government, a lot of things are 

123
00:07:34,080 --> 00:07:36,680
slower. 
And this was one of the things 

124
00:07:36,680 --> 00:07:40,680
that that is slower. 
So road map wise, we are, you 

125
00:07:40,680 --> 00:07:45,840
know, hopefully getting this at 
sometime in FY20 7, Microsoft's 

126
00:07:45,840 --> 00:07:48,480
fiscal year is kind of where 
engineering is. 

127
00:07:48,480 --> 00:07:53,200
It's kind of looking at that. 
So hopefully sometime very soon 

128
00:07:53,200 --> 00:07:56,680
in the future the the Gov cloud 
with Microsoft will also get 

129
00:07:56,680 --> 00:07:59,360
this so. 
Fingers crossed, maybe sometime 

130
00:07:59,360 --> 00:08:05,480
in the next 1314 months, Yes. 
OK, So Agent 365, Microsoft 

131
00:08:05,480 --> 00:08:08,640
really has a strong point of 
view on agent security. 

132
00:08:08,640 --> 00:08:13,800
And I think a lot of security 
vendors are having to put a 

133
00:08:13,800 --> 00:08:15,760
point of view out there into the
world. 

134
00:08:16,360 --> 00:08:19,320
And Microsoft says that you 
should secure agents like 

135
00:08:19,560 --> 00:08:22,760
humans, like human identities, 
like human behavior. 

136
00:08:23,480 --> 00:08:27,880
And I think that sounds right 
because how we've typically 

137
00:08:27,880 --> 00:08:33,120
secured machine based workloads 
up until this point has not at 

138
00:08:33,120 --> 00:08:35,080
all been like how we secure 
humans. 

139
00:08:35,640 --> 00:08:38,799
And that's partly because 
machines up until this point 

140
00:08:39,320 --> 00:08:42,159
only ran in a deterministic 
nature. 

141
00:08:42,760 --> 00:08:46,360
They only did what they were 
directly programmed to do and 

142
00:08:46,360 --> 00:08:49,320
that's it. 
There wasn't any randomness or 

143
00:08:49,320 --> 00:08:52,440
creativity to them. 
The same input delivered the 

144
00:08:52,440 --> 00:08:55,880
same output every time. 
Well, agents aren't like that. 

145
00:08:55,880 --> 00:08:58,680
We know all of AI is non 
deterministic. 

146
00:08:58,920 --> 00:09:02,520
You can give the same input, the
same prompt and you'll get a 

147
00:09:02,520 --> 00:09:05,520
different output. 
That's much closer to how humans

148
00:09:05,520 --> 00:09:08,720
behave. 
So the way to think about Agent 

149
00:09:08,720 --> 00:09:10,800
365, Andy, you'd spend a lot of 
time talking about the 

150
00:09:10,800 --> 00:09:14,320
dashboard, but I really want to 
open your aperture on this a 

151
00:09:14,320 --> 00:09:16,000
little bit. 
As you think about it, if 

152
00:09:16,320 --> 00:09:22,240
Microsoft 365 E 5 is the 
security platform to secure all 

153
00:09:22,240 --> 00:09:26,760
your human users, Agent 365 is 
the platform to secure all your 

154
00:09:26,760 --> 00:09:30,040
agents. 
So it's not just a dashboard in 

155
00:09:30,040 --> 00:09:33,640
the Microsoft 365 admin center. 
It actually unlocks a whole 

156
00:09:33,640 --> 00:09:37,240
bunch of capabilities across 
ENTRA purview and the defender 

157
00:09:37,240 --> 00:09:40,440
suites that are agent specific 
capabilities. 

158
00:09:40,960 --> 00:09:44,600
So one example, Andy and I love 
talking about conditional 

159
00:09:44,600 --> 00:09:46,960
access. 
We talked about on the show all 

160
00:09:46,960 --> 00:09:48,760
the time. 
It's a feature of ENTRA. 

161
00:09:48,760 --> 00:09:52,880
ID think of it like an if this 
then that model where you're 

162
00:09:52,880 --> 00:09:55,600
building a policy that says if 
this happens then take this 

163
00:09:55,600 --> 00:10:00,840
action for each login. 
Well you can do that for agents,

164
00:10:00,840 --> 00:10:03,880
but it is specifically tuned in 
and designed for agent 

165
00:10:03,880 --> 00:10:06,520
behaviour. 
Agents move a lot faster than 

166
00:10:06,520 --> 00:10:11,120
humans, so if we applied a human
based conditional access policy 

167
00:10:11,120 --> 00:10:14,040
to an agent they would almost 
certainly flag it. 

168
00:10:14,560 --> 00:10:18,080
It would look suspicious because
humans don't work that way. 

169
00:10:18,440 --> 00:10:20,480
But for an agent it could be 
very normal. 

170
00:10:20,560 --> 00:10:22,720
There's nothing unusual about 
it. 

171
00:10:23,240 --> 00:10:25,760
And so there are conditional 
access like risk based 

172
00:10:25,760 --> 00:10:29,280
conditional access policies 
tuned for agents and the way you

173
00:10:29,280 --> 00:10:33,120
unlock that capability is by 
purchasing Agent 365. 

174
00:10:33,360 --> 00:10:37,240
So it's not just a dashboard, 
it's a whole suite of 

175
00:10:37,240 --> 00:10:40,040
capabilities, security 
capabilities to secure agents 

176
00:10:40,320 --> 00:10:43,680
across the Entre, Purview and 
Defender suites. 

177
00:10:44,560 --> 00:10:46,600
The other thing I want to point 
out because there's been a 

178
00:10:46,600 --> 00:10:50,240
little bit of, I wouldn't say 
confusion, but maybe help me 

179
00:10:50,240 --> 00:10:53,640
understand kind of questions 
from customers on the licensing 

180
00:10:53,640 --> 00:10:55,800
model. 
Andy mentions the licensing 

181
00:10:55,800 --> 00:10:58,320
model is human based. 
That's correct. 

182
00:10:58,920 --> 00:11:03,400
You license per human heartbeat 
and any human that interacts 

183
00:11:03,400 --> 00:11:07,640
with agents in any way, whether 
you are sponsoring them, whether

184
00:11:07,640 --> 00:11:11,000
you manage an agent, whether you
just interact with them and use 

185
00:11:11,000 --> 00:11:14,560
them to help get your work done,
needs an agent 365 license. 

186
00:11:15,040 --> 00:11:18,240
Here's why, in my opinion, 
again, not speaking on behalf of

187
00:11:18,240 --> 00:11:21,080
Microsoft, as the disclaimer 
said, speaking on behalf of 

188
00:11:21,080 --> 00:11:25,760
Adam, if you made the licensing 
model per agent, what you are 

189
00:11:25,760 --> 00:11:28,640
now doing is creating a tax on 
creativity. 

190
00:11:29,000 --> 00:11:33,280
You're creating a tax on users 
trying to find ways agents can 

191
00:11:33,280 --> 00:11:35,320
help improve their work, speed 
up their work. 

192
00:11:35,840 --> 00:11:41,000
If you do it per human, then it 
scales as many agents as you can

193
00:11:41,240 --> 00:11:42,840
theoretically do. 
Now, there are, of course, 

194
00:11:42,840 --> 00:11:44,640
service limits. 
You know, there's going to be a 

195
00:11:44,640 --> 00:11:47,440
high end where you may get a 
note from your Microsoft account

196
00:11:47,440 --> 00:11:50,120
and that says, hey, we need to 
talk, but you're doing too many 

197
00:11:50,120 --> 00:11:51,880
agents here. 
But for the most part, the idea 

198
00:11:51,880 --> 00:11:55,800
is, if Andy thinks of a great 
idea for a new agent, there 

199
00:11:55,800 --> 00:11:57,920
shouldn't be an organizational 
tax that says, well, that's 

200
00:11:57,920 --> 00:12:00,160
another 15 bucks. 
You know, the Microsoft tax man 

201
00:12:00,160 --> 00:12:02,640
shows up and says, pay me more 
money because Andy thought of a 

202
00:12:02,640 --> 00:12:04,240
great idea and wants to try it 
out. 

203
00:12:04,720 --> 00:12:08,200
So that's not the model. 
The model is Andy's already got 

204
00:12:08,200 --> 00:12:10,520
a license. 
Whether he has five agents or 15

205
00:12:10,520 --> 00:12:14,880
agents working on his behalf, 30
agents, it's the same per user 

206
00:12:14,880 --> 00:12:16,960
fee. 
We pay for Andy's heartbeat, not

207
00:12:16,960 --> 00:12:20,200
the heartbeat of the agents. 
So that's why that exists. 

208
00:12:20,200 --> 00:12:24,880
It's actually designed to enable
organizations to have 

209
00:12:24,880 --> 00:12:28,800
predictable pricing even as we 
fully expect their agent 

210
00:12:28,800 --> 00:12:33,080
populations to proliferate. 
Like that fight in the Matrix 

211
00:12:33,080 --> 00:12:35,720
where all the agents myths came 
at NEO. 

212
00:12:35,920 --> 00:12:38,560
Hopefully they're not doing that
to your security defenses, but 

213
00:12:38,880 --> 00:12:40,840
you see how the agents can 
proliferate. 

214
00:12:41,600 --> 00:12:44,080
We don't want to prevent that. 
We want to allow those to grow 

215
00:12:44,080 --> 00:12:46,320
in your environment and help you
get things done and be more 

216
00:12:46,320 --> 00:12:48,440
productive. 
And so that's, I think that's 

217
00:12:48,440 --> 00:12:50,800
the philosophy and why the 
pricing model is the way it is 

218
00:12:50,800 --> 00:12:53,520
because of the, the things I 
talked about and, and wanting to

219
00:12:53,520 --> 00:12:55,240
encourage that innovation and 
growth. 

220
00:12:55,240 --> 00:12:59,120
And then finally closing thought
on Agent 365 before we move on. 

221
00:12:59,600 --> 00:13:02,600
I've been selling Microsoft 
security for over probably about

222
00:13:02,600 --> 00:13:05,480
9 1/2 years now. 
And one of the most common 

223
00:13:05,480 --> 00:13:09,160
misconceptions I fight is that 
Microsoft security is only good 

224
00:13:09,160 --> 00:13:11,640
for securing Microsoft. 
So it's only good if you're 

225
00:13:11,960 --> 00:13:15,720
Windows PCs and you're running 
workloads in Azure and you're in

226
00:13:15,720 --> 00:13:18,400
an M365 and it's not helpful 
outside of that. 

227
00:13:19,000 --> 00:13:22,000
Well, Agent 365 is completely 
designed around industry 

228
00:13:22,000 --> 00:13:25,120
standard capabilities, things 
like MCP servers, which is an 

229
00:13:25,120 --> 00:13:28,240
industry standard and there's an
observability standard that it 

230
00:13:28,240 --> 00:13:32,360
follows. 
And it has an open API that is 

231
00:13:32,400 --> 00:13:36,680
open to all other agentic 
vendors that can create 

232
00:13:36,680 --> 00:13:39,680
automatic registration of new 
agents created in their platform

233
00:13:40,080 --> 00:13:43,440
and registering them in Agent 
365 and Entra agent ID 

234
00:13:43,440 --> 00:13:46,760
automatically. 
It's intended to be open. 

235
00:13:47,200 --> 00:13:51,800
Our arms are open and welcome to
all comers because as we always 

236
00:13:51,800 --> 00:13:53,480
say, cybersecurity is a team 
sport. 

237
00:13:53,800 --> 00:13:56,240
And so the intent is not to 
create some closed off 

238
00:13:56,240 --> 00:13:58,080
proprietary platform. 
It's the opposite. 

239
00:13:58,080 --> 00:13:59,840
It wants to be the platform for 
all agents. 

240
00:13:59,840 --> 00:14:02,760
Now to be fair, if customers 
come up to me today and say, 

241
00:14:02,760 --> 00:14:07,320
well, does this do all my 
agents, It could if your other 

242
00:14:07,680 --> 00:14:11,440
companies wanted to play ball. 
Now of course, as anything in 

243
00:14:11,440 --> 00:14:13,560
technology, some people want to 
go it alone. 

244
00:14:13,880 --> 00:14:15,400
They don't want to play well 
with others. 

245
00:14:15,560 --> 00:14:17,120
They want to take their ball and
go home. 

246
00:14:17,920 --> 00:14:21,360
We can't make them not, but we 
can certainly open our arms and 

247
00:14:21,360 --> 00:14:24,600
our hearts and our door to them.
And there's an open API 

248
00:14:24,600 --> 00:14:27,960
published and allowing any and 
all to come play in the Agent 

249
00:14:27,960 --> 00:14:31,640
365 sandbox at any time. 
So that's my closing thoughts on

250
00:14:31,640 --> 00:14:34,120
that for today, but definitely 
something to start to look at 

251
00:14:34,120 --> 00:14:36,600
and evaluate. 
I'm sure you're getting your 

252
00:14:36,600 --> 00:14:38,760
leadership knocking on your door
saying, hey, what's your 

253
00:14:38,760 --> 00:14:39,760
strategy? 
What's our plan? 

254
00:14:39,760 --> 00:14:41,040
How are we going to secure 
agents? 

255
00:14:41,840 --> 00:14:43,520
I think it's a darn good 
solution. 

256
00:14:43,520 --> 00:14:45,480
I know there's a lot of other 
darn good solutions out there 

257
00:14:45,480 --> 00:14:47,520
too. 
And I know there's a lot of 

258
00:14:47,520 --> 00:14:50,080
innovation happening right now 
and it's an exciting space. 

259
00:14:50,080 --> 00:14:52,840
So stay tuned. 
More to come on this from 

260
00:14:52,840 --> 00:14:55,160
Microsoft and a lot of great 
competitors. 

261
00:14:55,160 --> 00:14:57,120
It's an exciting time in our 
industry. 

262
00:14:57,120 --> 00:15:00,320
I think we've talked about 
comparing this to the explosive 

263
00:15:00,320 --> 00:15:03,040
growth early days of the iPhone 
and and Android phones and 

264
00:15:03,040 --> 00:15:05,840
smartphones in general. 
It feels like we're in that next

265
00:15:05,840 --> 00:15:10,440
like hyper, hyper development 
phase of technology. 

266
00:15:10,440 --> 00:15:13,360
And those are fun times to live 
through, even if they're a 

267
00:15:13,360 --> 00:15:17,320
little stressful and a little 
tiresome as we pass through 

268
00:15:17,320 --> 00:15:19,440
them. 
But at the time, it's exciting 

269
00:15:19,440 --> 00:15:23,440
to be riding that tidal wave. 
All right, so our next story is 

270
00:15:23,440 --> 00:15:27,400
I want to talk about M Dash, 
which is Microsoft's new multi 

271
00:15:27,400 --> 00:15:31,040
model agentic scanning harness. 
And so you know, we've talked 

272
00:15:31,040 --> 00:15:34,360
about cloud mythos and I'm sure 
you've read some news on cloud 

273
00:15:34,360 --> 00:15:37,760
mythos as well. 
And then open AI came out with 

274
00:15:38,200 --> 00:15:42,040
GPT security, you know, and so 
the, and then cloud came out 

275
00:15:42,040 --> 00:15:45,280
with Opus, which the new Opus 
model also kind of implemented 

276
00:15:45,280 --> 00:15:47,000
some of the, the mythos stuff in
there. 

277
00:15:47,680 --> 00:15:49,880
And so these models are getting 
better and better. 

278
00:15:49,880 --> 00:15:54,000
And So what Microsoft has done 
is they've really announced a, a

279
00:15:54,000 --> 00:15:58,160
major step forward in this whole
scanning kind of vulnerability 

280
00:15:58,160 --> 00:16:01,680
scanning, code scanning. 
So the code name is called M 

281
00:16:01,680 --> 00:16:05,440
Dash and it's built by 
Microsoft's autonomous code 

282
00:16:05,440 --> 00:16:08,000
security team. 
What M-IS? 

283
00:16:08,000 --> 00:16:10,080
It's a source code vulnerability
scanner. 

284
00:16:10,080 --> 00:16:12,920
So it's not like a device or 
endpoint scanner like a 

285
00:16:12,920 --> 00:16:15,880
vulnerability, like looking at 
the vulnerabilities on my 

286
00:16:16,200 --> 00:16:18,080
endpoint or software. 
It's it's code. 

287
00:16:18,440 --> 00:16:21,400
And So what it's designed to 
scan like software code bases 

288
00:16:21,400 --> 00:16:24,560
and then find exploitable 
security bugs before attackers 

289
00:16:24,560 --> 00:16:26,480
do. 
It's an AI powered security 

290
00:16:26,480 --> 00:16:30,920
auditing really is what it is. 
What is particularly challenging

291
00:16:30,920 --> 00:16:34,840
for Microsoft is that there's a 
there's a large surface for 

292
00:16:34,840 --> 00:16:40,920
security auditing Windows Hyper 
V Azure device drivers, service 

293
00:16:41,000 --> 00:16:45,120
ecosystems, and all of them are 
private Microsoft code bases 

294
00:16:45,120 --> 00:16:48,400
that are not part of any 
commodity language model 

295
00:16:48,400 --> 00:16:52,960
training corpus or they're also 
like genuinely hard to reason 

296
00:16:52,960 --> 00:16:56,560
about, like kernel calling 
conventions, IRP and lock 

297
00:16:56,640 --> 00:17:00,760
invariants, IPC, trust 
boundaries, component internal 

298
00:17:00,760 --> 00:17:04,480
idioms that that there's no like
pattern to match. 

299
00:17:04,560 --> 00:17:09,599
And so on the surface, really a 
model has to actually reason 

300
00:17:09,599 --> 00:17:13,200
over this stuff. 
And unlike a single model 

301
00:17:13,200 --> 00:17:18,560
approach, orchestrates more than
100 specialized AI agents across

302
00:17:18,560 --> 00:17:22,839
an assembly of frontier and 
distilled models to discovered 

303
00:17:22,920 --> 00:17:27,560
and debate and improve 
exploitable bugs end to end. 

304
00:17:27,760 --> 00:17:31,320
The pipeline works in a 
structured stage in in just the 

305
00:17:31,320 --> 00:17:34,720
source code target and then 
builds language aware indices, 

306
00:17:34,720 --> 00:17:38,480
then draws attack services and 
threat models by analysing past 

307
00:17:38,480 --> 00:17:40,280
commits. 
A specialized auditor. 

308
00:17:40,280 --> 00:17:44,680
Agents then run over the 
candidate code path, emitting 

309
00:17:44,680 --> 00:17:47,960
candidate findings with 
hypothesis and evidence, and 

310
00:17:47,960 --> 00:17:51,800
then a second cohort of agents 
called debaters will then argue 

311
00:17:51,800 --> 00:17:56,560
for and against each finding 
reachability and exploitability,

312
00:17:56,840 --> 00:18:00,320
and then finally approve stage 
contracts, constructs and 

313
00:18:00,320 --> 00:18:04,360
executes triggering inputs where
the bug class admits it 

314
00:18:04,720 --> 00:18:08,280
dynamically validating the 
vulnerability is real and 

315
00:18:08,280 --> 00:18:12,000
trigger able. 
So that's pretty cool because 

316
00:18:12,080 --> 00:18:16,160
it's multiple different models 
and like as I'm reading this, 

317
00:18:16,160 --> 00:18:20,000
it's like it, it debates it 
amongst itself and then puts it 

318
00:18:20,000 --> 00:18:22,040
out and then proves it. 
And so I. 

319
00:18:22,040 --> 00:18:25,120
Like I like the language that 
there's auditor agents, there's 

320
00:18:25,120 --> 00:18:28,200
debater agents, there's prover 
agents. 

321
00:18:28,200 --> 00:18:31,400
That's very interesting. 
Yeah, the pipeline there. 

322
00:18:32,080 --> 00:18:35,520
And so the results really are 
pretty fascinating. 

323
00:18:35,560 --> 00:18:40,560
M Dash has found 21 of 21 
planted vulnerabilities with 

324
00:18:40,560 --> 00:18:44,480
zero false positives on a 
private test driver, achieved 

325
00:18:44,480 --> 00:18:51,640
96% recall against five years of
confirmed MSRC cases in the CLLS

326
00:18:51,880 --> 00:18:57,680
Dash Sys and 100% in the TCPIP 
dot Sys, and then scored an 

327
00:18:57,680 --> 00:19:03,480
industry leading 88.45% on the 
public Cyber Gym benchmark of 

328
00:19:03,560 --> 00:19:06,600
15107 real world 
vulnerabilities, which is the 

329
00:19:06,600 --> 00:19:12,120
top score on the leaderboard. 
Using M-ON, Microsoft's own 

330
00:19:12,120 --> 00:19:14,680
Windows networking and 
authentication stack, 

331
00:19:14,680 --> 00:19:19,400
researchers have found 16 new 
vulnerabilities, including four 

332
00:19:19,800 --> 00:19:24,280
critical remote code execution 
flaws in components such as the 

333
00:19:24,280 --> 00:19:29,120
Windows kernel, TCIP stack and 
the Ike V2 service. 

334
00:19:29,640 --> 00:19:35,320
These bugs were patched on the 
May 2026 Patch Tuesday, so M 

335
00:19:35,320 --> 00:19:38,040
Dash is already running in 
production, and it's already 

336
00:19:38,040 --> 00:19:41,560
feeding the vulnerabilities into
Microsoft's own remediation 

337
00:19:41,560 --> 00:19:43,560
pipeline. 
Let me jump in there real quick.

338
00:19:43,600 --> 00:19:46,040
And Andy, we talked about this 
in the pre show and we'll put a 

339
00:19:46,080 --> 00:19:49,320
link in the show notes. 
The Microsoft Security Research 

340
00:19:49,320 --> 00:19:54,120
Center, MSRC put out a blog post
that said, hey, this Patch 

341
00:19:54,120 --> 00:19:57,240
Tuesday looks a little different
May 2020 sixth than you've seen 

342
00:19:57,240 --> 00:20:00,280
in the past. 
First off, the number of fixes 

343
00:20:00,280 --> 00:20:04,080
is higher than typical for a hot
patch month, May as a hot patch 

344
00:20:04,080 --> 00:20:05,160
month. 
If you're running Windows hot 

345
00:20:05,160 --> 00:20:08,720
patch, no reboot required. 
And they fully admitted and 

346
00:20:08,720 --> 00:20:11,480
said, hey, and this was 
published around the same day as

347
00:20:12,040 --> 00:20:14,760
the article you're talking about
Andy, that talked about the new 

348
00:20:14,760 --> 00:20:18,720
M dash capability. 
It said yes, a lot of these 

349
00:20:18,720 --> 00:20:22,800
vulnerabilities are now coming 
from AI vulnerability scanners 

350
00:20:22,960 --> 00:20:28,120
and AI vulnerability findings. 
However, the good news is for 

351
00:20:28,120 --> 00:20:31,120
our listeners, we always talk 
about what's the take away for 

352
00:20:31,120 --> 00:20:34,400
listeners? 
The MSRC blog effectively says 

353
00:20:34,920 --> 00:20:38,600
the take away is keep doing what
you're doing, keep patching, 

354
00:20:38,640 --> 00:20:41,880
keep doing your timely patches, 
invest in Windows auto patch, 

355
00:20:41,880 --> 00:20:44,600
windows hot patch, make sure 
you're deploying them as quickly

356
00:20:44,600 --> 00:20:48,680
as you possibly can while 
validating them before you 

357
00:20:48,680 --> 00:20:51,840
deploy broadly. 
And and all the things that our 

358
00:20:51,840 --> 00:20:55,200
listeners already do well today,
nothing has changed in terms of 

359
00:20:55,520 --> 00:20:57,920
we're not moving away from the 
patch Tuesday cadence. 

360
00:20:57,920 --> 00:21:00,600
That's predictable, 
understandable, everyone knows 

361
00:21:00,600 --> 00:21:03,800
it. 
And the bar for out of band 

362
00:21:03,800 --> 00:21:06,400
patches has not changed either. 
And that's going to maintain the

363
00:21:06,400 --> 00:21:09,840
same bar as well. 
So although how they're 

364
00:21:09,840 --> 00:21:13,640
discovered may be changing and 
maybe more AI driven in the 

365
00:21:13,640 --> 00:21:18,560
future, human driven reporting 
will still really matter and how

366
00:21:18,560 --> 00:21:21,440
it gets fixed and deployed is 
staying exactly the same. 

367
00:21:22,000 --> 00:21:24,440
So that's the good news. 
The take away for our listeners 

368
00:21:24,440 --> 00:21:26,040
is you don't have to do anything
different. 

369
00:21:26,480 --> 00:21:29,080
You're just going to get patches
and, and maybe for the next 

370
00:21:29,080 --> 00:21:31,840
couple of months, there'll be 
more of them for a while. 

371
00:21:31,840 --> 00:21:37,400
I talked on the previous week 
about a a tidal wave of of 

372
00:21:37,400 --> 00:21:40,080
vulnerability fixes coming out 
and that may continue for a 

373
00:21:40,080 --> 00:21:43,040
while, but ultimately we will 
get to a better state. 

374
00:21:43,840 --> 00:21:47,960
So the good news is M-IS already
being run against the Windows 

375
00:21:48,120 --> 00:21:50,320
private code base. 
It's already finding 

376
00:21:50,320 --> 00:21:51,880
vulnerabilities and they are 
being patched. 

377
00:21:51,880 --> 00:21:57,440
And by the way, in the May 2026 
Patch Tuesday release, there 

378
00:21:57,440 --> 00:22:02,560
were no known actively exploited
vulnerabilities in the wild. 

379
00:22:03,160 --> 00:22:06,280
Now, there was an exchange 1-2 
days later we talked about on 

380
00:22:06,280 --> 00:22:09,520
last week's show. 
However, in Patch Tuesday with 

381
00:22:09,520 --> 00:22:13,560
the stuff M Dash found, it found
stuff that as far as we know, no

382
00:22:13,560 --> 00:22:16,280
one was actively exploiting. 
So you had the chance for it to 

383
00:22:16,280 --> 00:22:20,280
be found, discovered and patched
before there was any sign that 

384
00:22:20,280 --> 00:22:22,800
anyone was taking advantage of 
those vulnerabilities. 

385
00:22:22,800 --> 00:22:25,680
So that's the great news. 
We are currently moving faster 

386
00:22:25,760 --> 00:22:27,520
than attackers and hopefully 
that. 

387
00:22:27,960 --> 00:22:29,400
Anyhow, that's a little side 
note there. 

388
00:22:29,400 --> 00:22:32,680
But as you were talking about 
how M Dash contributed to 

389
00:22:32,680 --> 00:22:34,920
Maypatch Tuesday thought that 
was a great time to jump in. 

390
00:22:34,920 --> 00:22:38,400
And we will of course link that 
MSRC blog in the show notes. 

391
00:22:38,400 --> 00:22:41,040
It's worth your review. 
I just understanding what has 

392
00:22:41,040 --> 00:22:45,160
and hasn't changed. 
And as far as availability, this

393
00:22:45,160 --> 00:22:49,960
is not just an internal tool. 
Microsoft is making it available

394
00:22:49,960 --> 00:22:52,840
for organizations to scan their 
own code base. 

395
00:22:53,320 --> 00:22:56,640
It's right now being tested by a
small set of customers as part 

396
00:22:56,640 --> 00:23:00,120
of a limited private preview. 
And so I'll, I'll talk about 

397
00:23:00,120 --> 00:23:01,440
like how to get involved in 
that. 

398
00:23:01,440 --> 00:23:05,920
But what I do want to just touch
on is that's really important to

399
00:23:05,920 --> 00:23:08,600
highlight the fact that M-IS 
multi model. 

400
00:23:09,000 --> 00:23:12,720
And I don't know if I really 
hammered that point, but this is

401
00:23:12,720 --> 00:23:17,080
not just a single model like 
Claude Mythos or GPT security. 

402
00:23:17,080 --> 00:23:20,720
It's multiple models, multiple 
frontier languages, multiple 

403
00:23:20,720 --> 00:23:25,520
distilled models. 
And and that matters because 

404
00:23:25,520 --> 00:23:30,240
single models will miss things. 
You know, I, I kind of, I was 

405
00:23:30,240 --> 00:23:34,520
explaining this to someone, a Co
worker recently because they 

406
00:23:34,520 --> 00:23:36,640
asked, well, why does it, why 
does a multi model matter? 

407
00:23:36,640 --> 00:23:39,920
Why is this anything that to, to
really get excited about? 

408
00:23:39,920 --> 00:23:43,800
And you know, I kind of used the
example of maybe you have 

409
00:23:43,800 --> 00:23:48,440
someone who's using Proofpoint 
or Mimecast as their e-mail 

410
00:23:48,440 --> 00:23:50,400
security gateway. 
Well, guess what? 

411
00:23:50,400 --> 00:23:54,440
You can still use Defender for 
office behind that. 

412
00:23:54,440 --> 00:23:58,160
And defender for office will 
catch things that the initial 

413
00:23:58,160 --> 00:24:00,280
tool will miss. 
That's just part of it. 

414
00:24:01,480 --> 00:24:04,320
Same thing is that like some 
people I know customers use 

415
00:24:04,680 --> 00:24:07,480
Defender for office and then 
they use something like abnormal

416
00:24:07,480 --> 00:24:10,640
like an API security. 
And so, you know, like those two

417
00:24:10,640 --> 00:24:13,560
things work together. 
Or another example would be like

418
00:24:13,560 --> 00:24:17,000
Crowdstrike with MDE. 
You know, like you can use those

419
00:24:17,000 --> 00:24:20,160
side by side and kind of get 
more coverage and like kind of 

420
00:24:20,160 --> 00:24:22,560
peer review. 
And Speaking of peer review, I 

421
00:24:22,560 --> 00:24:25,480
think I don't know if I 
mentioned this on the show, but 

422
00:24:25,800 --> 00:24:29,440
like copilot researcher, when I 
used copilot researcher to write

423
00:24:29,440 --> 00:24:32,760
a paper today, if I need to 
write a white paper for 

424
00:24:32,760 --> 00:24:35,760
something, 'cause the military, 
the, the government's really big

425
00:24:35,760 --> 00:24:38,200
on white paper. 
So I have to generate these 

426
00:24:38,240 --> 00:24:41,360
white papers. 
I can just toss it into a 

427
00:24:41,360 --> 00:24:43,240
researcher. 
But what it does is it actually 

428
00:24:43,240 --> 00:24:49,160
uses GPT 5.5 to write the 
initial white paper and then it 

429
00:24:49,280 --> 00:24:52,920
peer reviews it using clawed, 
which is really cool. 

430
00:24:52,920 --> 00:24:55,440
So, and then like it kind of 
like reviews it and, and spits 

431
00:24:55,440 --> 00:24:56,800
it out. 
And so this is kind of that 

432
00:24:56,800 --> 00:25:00,000
thing where it's like there's 
multiple different models, some 

433
00:25:00,000 --> 00:25:02,960
of them review, some of them, 
you know, we'll look at the 

434
00:25:02,960 --> 00:25:06,760
initial vulnerability, the 
chaining of different 

435
00:25:06,920 --> 00:25:09,400
vulnerabilities together to get 
an exploit. 

436
00:25:09,920 --> 00:25:12,600
A single model may think of one 
thing, a different model may 

437
00:25:12,600 --> 00:25:14,680
think of another. 
And then they have this whole 

438
00:25:14,680 --> 00:25:19,800
like pipeline of auditor agents 
and reviewer agents and all 

439
00:25:19,800 --> 00:25:22,040
that. 
And so this is, there's a couple

440
00:25:22,040 --> 00:25:26,560
of concrete real world examples 
that are in the blog. 

441
00:25:26,840 --> 00:25:28,960
We'll link the blog for you to 
go and look at it 'cause 

442
00:25:28,960 --> 00:25:30,320
they're, they're really 
interesting. 

443
00:25:30,840 --> 00:25:33,520
But I just wanted to highlight 
the whole like multi model 

444
00:25:33,520 --> 00:25:36,680
because this is kind of a new 
thing that is evolving. 

445
00:25:37,000 --> 00:25:40,720
We're seeing it in certain 
things like copilot researcher 

446
00:25:41,040 --> 00:25:43,520
and we're seeing it now with 
specifically in security with 

447
00:25:43,520 --> 00:25:45,680
this M dash. 
And I think this is going to be 

448
00:25:45,680 --> 00:25:48,880
a growing thing because it's one
model is probably not going to 

449
00:25:48,880 --> 00:25:51,960
be the end all be all. 
Different models are trained in 

450
00:25:51,960 --> 00:25:54,040
different data. 
And so like having this kind of 

451
00:25:54,040 --> 00:25:56,920
peer review system of two 
different AIS or multiple 

452
00:25:56,920 --> 00:26:01,160
different AI systems is going to
be really critical for the 

453
00:26:01,160 --> 00:26:04,080
future in security. 
Yeah, I agree. 

454
00:26:04,440 --> 00:26:07,560
You keep provided 2 great 
examples of multi model use 

455
00:26:07,560 --> 00:26:12,080
cases in other scenarios. 
I I just think we're in a moment

456
00:26:12,080 --> 00:26:15,080
right now as we record this in 
May 2026. 

457
00:26:16,080 --> 00:26:19,640
Anthropics having a moment, 
right And and as I talked to a 

458
00:26:19,640 --> 00:26:23,280
lot of customers, they are the 
hotness right now. 

459
00:26:23,640 --> 00:26:26,440
But you think of it wasn't that 
long ago that open AI was 

460
00:26:26,440 --> 00:26:29,640
clearly the darling and everyone
else is playing catch up. 

461
00:26:30,360 --> 00:26:32,080
And the thought was, oh, Google 
is doomed. 

462
00:26:32,080 --> 00:26:33,720
They're too late. 
You know, the Google lost the 

463
00:26:33,720 --> 00:26:37,440
plot and then they came up with 
some amazing Gemini releases, 

464
00:26:37,440 --> 00:26:39,520
especially a lot of the Gemini 3
releases. 

465
00:26:39,520 --> 00:26:41,680
And Google was the hotness for a
minute. 

466
00:26:41,880 --> 00:26:46,680
The fact is, I think it's pretty
clear today that no one is 

467
00:26:46,680 --> 00:26:50,040
likely to develop an endearing 
Moat in models. 

468
00:26:50,600 --> 00:26:54,280
And so if you partner with a 
model provider, you're locking 

469
00:26:54,280 --> 00:26:59,200
yourself into that one that at 
the moment may be ahead, may 

470
00:26:59,200 --> 00:27:01,240
fall behind, maybe in the 
middle. 

471
00:27:01,800 --> 00:27:04,040
It's it's clearly a back and 
forth race. 

472
00:27:04,040 --> 00:27:08,240
So having a multi model 
experience where you can access 

473
00:27:08,240 --> 00:27:11,760
many of them all at once seems 
kind of like the right approach 

474
00:27:11,760 --> 00:27:14,200
moving forward. 
It's hard to predict and maybe 

475
00:27:14,200 --> 00:27:17,360
I'm going to sound stupid six 
months from now, but as it it 

476
00:27:17,360 --> 00:27:21,040
sits today in May 2020, sixth, 
my best sense of it has been 

477
00:27:21,040 --> 00:27:23,960
watching each of the horses gain
the lead for a bit and then 

478
00:27:23,960 --> 00:27:27,160
relinquish the lead. 
Just cause Anthropic has it at 

479
00:27:27,160 --> 00:27:30,640
the moment doesn't mean they 
won't give it up. 

480
00:27:30,680 --> 00:27:33,440
And you talked about Andy, it's 
not just whether the models the 

481
00:27:33,440 --> 00:27:36,880
most state-of-the-art are the 
best, it's just having them 

482
00:27:36,880 --> 00:27:39,440
reason over it from different 
pathways and different 

483
00:27:39,440 --> 00:27:43,400
perspectives and comparing notes
in the way this model works and 

484
00:27:43,400 --> 00:27:46,640
then leveraging distilled models
that are very specific and 

485
00:27:46,640 --> 00:27:49,480
bespoke. 
You're just going to find things

486
00:27:49,480 --> 00:27:52,760
a single model cannot. 
And so there's a lot of benefits

487
00:27:52,760 --> 00:27:54,960
to this approach. 
And so I think as you go 

488
00:27:54,960 --> 00:27:58,080
forward, not just for security 
use cases, but for your 

489
00:27:58,080 --> 00:28:01,560
productivity use cases. 
And, and of course, I'm biased, 

490
00:28:01,560 --> 00:28:02,920
you know, you know, who pays my 
paycheck. 

491
00:28:02,920 --> 00:28:06,360
We don't hide it on the show. 
I do think the most effective 

492
00:28:06,360 --> 00:28:10,600
solution is going to be who 
delivers the, the wrapper, the 

493
00:28:10,680 --> 00:28:14,680
harness, as we talked about with
M dash, the H and it stands for 

494
00:28:14,680 --> 00:28:17,240
harness. 
The harness is that's kind of 

495
00:28:17,240 --> 00:28:19,520
the cool part right now. 
That's where all the innovation 

496
00:28:19,520 --> 00:28:21,920
is, is how can you harness all 
these different models and 

497
00:28:21,920 --> 00:28:26,480
agents together and give them a 
scaffolding and a framework to 

498
00:28:26,480 --> 00:28:30,800
work within to deliver a result.
And that's where things get the 

499
00:28:30,800 --> 00:28:33,440
most interesting today. 
And, and we'll see how this 

500
00:28:33,440 --> 00:28:35,920
evolves over time. 
But yeah, this is very, very 

501
00:28:35,920 --> 00:28:37,800
cool stuff. 
Are you going to talk a little 

502
00:28:37,800 --> 00:28:41,600
bit more about the, the public 
or the private preview and and 

503
00:28:41,600 --> 00:28:44,320
the way to nominate yourself? 
Yeah, yeah. 

504
00:28:44,720 --> 00:28:48,120
OK. 
So yeah, just ending up a final 

505
00:28:48,280 --> 00:28:52,080
thought here on the M-IS that it
is in limited private preview. 

506
00:28:52,160 --> 00:28:58,480
You can go and sign up at AKA 
dot, MS/AI Dash Driven scanning 

507
00:28:58,600 --> 00:29:00,520
harness. 
And so when you go to that, 

508
00:29:00,560 --> 00:29:02,400
there's a form that you have to 
fill out. 

509
00:29:02,400 --> 00:29:05,400
Now this is part of the Security
Advisors program. 

510
00:29:05,640 --> 00:29:08,840
And I know that we've kind of 
briefly touched on that program,

511
00:29:08,840 --> 00:29:12,880
but it's actually a really cool 
program that any customer can 

512
00:29:12,960 --> 00:29:16,560
kind of be a part of. 
And you have to like apply and 

513
00:29:16,560 --> 00:29:19,760
and fill out something. 
But when you're in that program,

514
00:29:20,120 --> 00:29:24,280
you get like specific updates on
products and road maps. 

515
00:29:24,280 --> 00:29:27,040
You get to interact with 
engineering teams and you can 

516
00:29:27,360 --> 00:29:30,360
engage in like customer to 
customer learnings, provide 

517
00:29:30,360 --> 00:29:32,960
feedback to the engineering 
teams as well. 

518
00:29:33,280 --> 00:29:37,000
And then you get to learn about 
what's all upcoming, including 

519
00:29:37,000 --> 00:29:40,840
these private previews. 
And so you know, that's there's 

520
00:29:40,840 --> 00:29:43,000
a security advisors program in 
general. 

521
00:29:43,000 --> 00:29:46,920
And then this particular 1 is 
just for this M dash private 

522
00:29:46,920 --> 00:29:49,600
preview. 
But you know, it's worth looking

523
00:29:49,600 --> 00:29:51,800
at the whole program because 
there's other things that you 

524
00:29:51,800 --> 00:29:53,760
can be a part of within that 
program. 

525
00:29:53,880 --> 00:29:58,480
But yeah, you just go to that 
AKA dot Ms. short link again, 

526
00:29:58,480 --> 00:30:02,560
it's AKA dot MS/AI dash driven 
scanning harness. 

527
00:30:02,600 --> 00:30:05,720
Of course, we'll put it in the 
show notes with the blog article

528
00:30:05,720 --> 00:30:07,640
as well. 
And you can go and fill out the 

529
00:30:07,640 --> 00:30:11,240
form, nominate yourself and 
hopefully someone will reach out

530
00:30:11,240 --> 00:30:14,560
to you. 
And if you get approved and I'm 

531
00:30:14,560 --> 00:30:15,920
boarded into the private 
preview. 

532
00:30:16,320 --> 00:30:19,520
One thing we're pointing out 
with this private preview and 

533
00:30:19,520 --> 00:30:22,000
something to consider before you
race off and go put in your 

534
00:30:22,000 --> 00:30:24,880
application is Microsoft is 
looking for customers who want 

535
00:30:24,880 --> 00:30:28,120
to be design partners in 
designing the future of this 

536
00:30:28,120 --> 00:30:29,880
product. 
Obviously the intent is to 

537
00:30:29,880 --> 00:30:33,200
productize this and sell this 
moving forward, but right now we

538
00:30:33,200 --> 00:30:36,360
want to Co develop with our 
customers to make sure this hits

539
00:30:36,360 --> 00:30:39,040
the mark. 
And so the expectation is not 

540
00:30:39,040 --> 00:30:42,320
that you would be a passive 
tester where we just send you a 

541
00:30:42,320 --> 00:30:45,600
thing and you tested and don't 
ever provide any feedback, but 

542
00:30:45,600 --> 00:30:47,360
you are an active to design A 
partner. 

543
00:30:47,560 --> 00:30:51,120
And so there's a commitment of 
making available six or seven 

544
00:30:51,120 --> 00:30:54,880
people on your team joining 
regular hour long meetings 

545
00:30:54,880 --> 00:30:58,120
couple times a week to provide 
feedback and input and 

546
00:30:58,120 --> 00:31:00,400
development. 
So it's a big commitment on your

547
00:31:00,400 --> 00:31:05,600
part to participate in this. 
I I've been fortunate to test 

548
00:31:05,600 --> 00:31:09,040
some pre release hardware for 
Microsoft and it's a significant

549
00:31:09,040 --> 00:31:14,040
commitment to install new builds
and to provide bug test reports 

550
00:31:14,040 --> 00:31:16,800
and sentiment surveys and 
everything else we do this is 

551
00:31:16,800 --> 00:31:19,160
similar. 
There's there is an active 

552
00:31:19,160 --> 00:31:22,080
expectation to participate. 
And so if if you're up for the 

553
00:31:22,080 --> 00:31:24,520
challenge and you want to be 
part of bringing something to 

554
00:31:24,520 --> 00:31:28,640
market that's very rewarding, by
all means, please go throw in an

555
00:31:28,640 --> 00:31:29,920
app. 
But if you just want to get 

556
00:31:29,920 --> 00:31:32,720
access to the cool thing to say 
you have it before someone else 

557
00:31:32,720 --> 00:31:35,760
and not really sure how you 
tested or how it would fit in in

558
00:31:35,760 --> 00:31:39,000
your org, you may want to wait 
for this to enter public preview

559
00:31:39,000 --> 00:31:42,080
and in which case there won't be
that same commitment required to

560
00:31:42,080 --> 00:31:44,560
move forward with it. 
So I'm just want to call that 

561
00:31:44,560 --> 00:31:47,760
out and something to think about
in general, not just for testing

562
00:31:47,760 --> 00:31:51,400
this, but if you want to test 
anything, true testing is the 

563
00:31:51,400 --> 00:31:53,320
commitment. 
And it's, it's not all fun and 

564
00:31:53,320 --> 00:31:55,720
games and sometimes you're using
something that doesn't work 

565
00:31:55,720 --> 00:31:59,120
right and you got to get to the 
bottom of it and help reproduce 

566
00:31:59,120 --> 00:32:01,680
it and provide those 
reproduction steps so it can be 

567
00:32:01,680 --> 00:32:04,120
fixed and moving forward. 
Just something to think about. 

568
00:32:04,120 --> 00:32:07,960
But very, very cool. 
Amazing to get a chance to get 

569
00:32:07,960 --> 00:32:11,240
hands on with a product that is 
already impacting patch Tuesday.

570
00:32:11,640 --> 00:32:15,280
And you think of the over 1 
billion Windows devices that are

571
00:32:15,280 --> 00:32:17,680
getting those patches and 
getting those fixes and this is 

572
00:32:17,680 --> 00:32:20,600
helping influence that. 
That's pretty darn cool. 

573
00:32:20,720 --> 00:32:23,680
So I think really exciting times
ahead and and exciting to see 

574
00:32:23,680 --> 00:32:26,080
where this goes. 
And that's our show for this 

575
00:32:26,080 --> 00:32:28,080
week. 
Thanks for watching and 

576
00:32:28,080 --> 00:32:29,920
listening. 
As always, our contact 

577
00:32:29,920 --> 00:32:32,920
information will be in the show 
notes along with the links to 

578
00:32:32,920 --> 00:32:35,760
the articles that we used for 
our discussion. 

579
00:32:36,200 --> 00:32:38,960
If you have any questions or 
topics you want us to talk about

580
00:32:38,960 --> 00:32:41,760
in the future, just e-mail us. 
Thanks. 

581
00:32:41,760 --> 00:32:42,840
We'll talk to you guys next 
week. 

582
00:32:43,080 --> 00:32:45,560
Thank you for listening to the 
Blue Security Podcast. 

583
00:32:45,720 --> 00:32:48,360
Please check out the show notes,
catch up on episodes you may 

584
00:32:48,360 --> 00:32:50,960
have missed, and subscribe so 
you don't miss any future 

585
00:32:50,960 --> 00:32:53,880
episodes. 
Find Andy on Twitter at a Jaw 

586
00:32:53,880 --> 00:32:58,160
Zero and Adam at AJ Brewer. 
See you at our next episode.

