Need to Know podcast–Episode 355

In this episode of the Need to Know Podcast, we explore the evolving landscape of learning in the Microsoft Cloud ecosystem, with a spotlight on the SMB market. From the latest in Microsoft 365 Copilot innovations to critical cybersecurity updates and the end of CIAOPS Academy, this episode delivers essential insights for IT professionals and business leaders navigating the modern digital workplace.

Brought to you by www.ciaopspatron.com

you can listen directly to this episode at:

https://ciaops.podbean.com/e/episode-355-learning-reboot/

Subscribe via iTunes at:

https://itunes.apple.com/au/podcast/ciaops-need-to-know-podcasts/id406891445?mt=2

or Spotify:

https://open.spotify.com/show/7ejj00cOuw8977GnnE2lPb

Don’t forget to give the show a rating as well as send me any feedback or suggestions you may have for the show.

Resources

Explore the tools, communities, and content mentioned in this episode:

Announcements

Flight School: Mastering Copilot for IT Pros – https://blog.ciaops.com/2025/11/14/flight-school-mastering-copilot-for-it-pros/
Disabling Office Macros via ASR to Meet Essential Eight Requirements – https://blog.ciaops.com/2025/11/13/disabling-office-macros-via-asr-to-meet-essential-eight-requirements/
ASD OWA settings check script – https://blog.ciaops.com/2025/11/13/asd-owa-settings-check-script/
ASD Mailflow settings check script – https://blog.ciaops.com/2025/11/12/asd-mailflow-settings-check-sript/
CIAOPS Academy deprecation notification – https://blog.ciaops.com/2025/11/10/ciaops-academy-deprecation-notification/

Show Notes

The next chapter of the Microsoft–OpenAI partnership –

https://blogs.microsoft.com/blog/2025/10/28/the-next-chapter-of-the-microsoft-openai-partnership/

Automate with Workflows Agent in Microsoft 365 Copilot (Frontier) –

https://www.youtube.com/watch?v=Vvk1ScZT-lo

Introducing Researcher with Computer Use in Microsoft 365 Copilot –

https://techcommunity.microsoft.com/blog/microsoft365copilotblog/introducing-researcher-with-comput…

Build apps in minutes with App Builder agent in Microsoft 365 Copilot (Frontier) –

https://www.youtube.com/watch?v=v27H_R1ltB0

Microsoft 365 Copilot now enables you to build apps and workflows –

https://www.microsoft.com/en-us/microsoft-365/blog/2025/10/28/microsoft-365-copilot-now-enables-you

Introducing Teams Mode for Microsoft 365 Copilot –

https://techcommunity.microsoft.com/blog/microsoft365copilotblog/introducing-teams-mode-for-microso…

Introducing MAI-Image-1, debuting in the top 10 on LMArena –

https://microsoft.ai/news/introducing-mai-image-1-debuting-in-the-top-10-on-lmarena/

Building human-centric security skills for AI –

https://techcommunity.microsoft.com/blog/microsoftlearnblog/building-human-centric-security-skills-…

GenAI vs Cyber Threats: Why GenAI Powered Unified SecOps Wins –

https://techcommunity.microsoft.com/blog/microsoft-security-blog/genai-vs-cyber-threats-why-genai-p…

What’s new in Microsoft 365 Copilot | October 2025 –

https://techcommunity.microsoft.com/blog/Microsoft365CopilotBlog/what%E2%80%99s-new-in-microsoft-36…

The 5 generative AI security threats you need to know about detailed in new e-book –

https://www.microsoft.com/en-us/security/blog/2025/10/30/the-5-generative-ai-security-threats-you-n…

SharePoint Showcase highlights: Smarter Copilot responses using metadata with the Knowledge Agent –

https://techcommunity.microsoft.com/blog/microsoft365insiderblog/sharepoint-showcase-highlights-sma…

Work smarter with Copilot in the People, Files, and Calendar apps –

https://techcommunity.microsoft.com/blog/microsoft365insiderblog/work-smarter-with-copilot-in-the-p…

The weakest link: Stolen staff passwords now the biggest cyber threat to workplaces –

https://www.smh.com.au/politics/federal/the-weakest-link-stolen-staff-passwords-now-the-biggest-cyb…

Cyber security priorities for boards of directors 2025-26 –

https://www.cyber.gov.au/business-government/protecting-business-leaders/cyber-security-for-busines…

Secure external attachments with Purview encryption –

https://techcommunity.microsoft.com/blog/azurepurviewblog/secure-external-attachments-with-purview-…

What’s New in Microsoft Intune: October 2025 –

https://techcommunity.microsoft.com/blog/microsoftintuneblog/what%E2%80%99s-new-in-microsoft-intune…

Custom detections are now the unified experience for creating detections in Microsoft Defender –

https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/custom-detections-are-now-th…

10 ways Microsoft Intune supports a smooth upgrade to Windows 11 –

https://techcommunity.microsoft.com/blog/microsoftintuneblog/10-ways-microsoft-intune-supports-a-sm…

How Windows 11 and AI are transforming the future of work –

https://techcommunity.microsoft.com/blog/windows-itpro-blog/how-windows-11-and-ai-are-transforming-…

Security Copilot Agents: The New Era of AI, Driven Cyber Defense –

https://techcommunity.microsoft.com/blog/microsoft-security-blog/security-copilot-agents-the-new-er…

6 truths about migrating Microsoft Sentinel to the Defender portal –

https://techcommunity.microsoft.com/blog/microsoftsentinelblog/6-truths-about-migrating-microsoft-s…

Microsoft named a Leader in the 2025 Gartner® Magic Quadrant™ for SIEM –

https://www.microsoft.com/en-us/security/blog/2025/10/16/microsoft-named-a-leader-in-the-2025-gartn…

Extortion and ransomware drive over half of cyberattacks –

https://blogs.microsoft.com/on-the-issues/2025/10/16/mddr-2025/

Microsoft 365 Insider Round-Up: October 2025 –

https://www.linkedin.com/pulse/microsoft-365-insider-round-up-october-2025-microsoft-365-insider-ub…

Making every Windows 11 PC an AI PC –

https://blogs.windows.com/windowsexperience/2025/10/16/making-every-windows-11-pc-an-ai-pc/

Microsoft raises the bar: A smarter way to measure AI for cybersecurity –

https://www.microsoft.com/en-us/security/blog/2025/10/14/microsoft-raises-the-bar-a-smarter-way-to-…

Building a lasting security culture at Microsoft –

https://www.microsoft.com/en-us/security/blog/2025/10/13/building-a-lasting-security-culture-at-mic…

Satya – My annual letter: Thinking in decades, executing in quarters –

https://www.linkedin.com/pulse/my-annual-letter-thinking-decades-executing-quarters-satya-nadella-7…

Flight School: Mastering Copilot for IT Pros

image

Join us for an immersive 5-day virtual training designed exclusively for IT Professionals and Managed Service Providers from the 12 – 16 January 2026. This isn’t just another webinar—it’s a hands-on, deep dive into how Microsoft Copilot can transform the way you manage, automate, and secure your IT environment.

What you’ll gain:

* Master Copilot’s capabilities for IT operations, security, and automation.

* Learn practical workflows that save time and boost efficiency.

* Explore advanced scenarios for troubleshooting and compliance.

* Future-proof your skills with insights into emerging Copilot integrations.

Why attend?

* Live, interactive sessions with real-world demos.

* Expert-led guidance tailored for IT Pros and MSPs.

* Actionable takeaways you can implement immediately.

Format:

* 5 consecutive days

* 2 hours per day

* Delivered remotely via Microsoft Teams. Recording available after session.

Your Copilot journey starts here—are you ready to take off If so, register your interest here – http://bit.ly/ciaopsroi. Early bird discounts until 12 December 2025.

Prices


Patron level RRP GST ex GST Saving
None $399.00 $36.27 $362.73
Bronze $199.00 $18.09 $180.91 $200.00
Silver $99.00 $9.00 $90.00 $300.00
Gold $49.00 $4.45 $44.55 $350.00

CIAOPS AI Dojo 005–MCP Servers

bp1

What’s the session about?

Empower attendees to design, build, and deploy intelligent chat agents using MCP servers, with a focus on real-world automation, integration, and user experience

Who should attend?

This session is perfect for:

  • IT administrators and support staff
  • Business owners
  • People looking to get more done with Microsoft 365
  • Anyone looking to automate their daily grind

Save the Date

Date: Friday the 31st of October 2025

Time: 9:30 AM Sydney AU time

Location: Online (link will be provided upon registration)

Cost: $80 per attendee (free for Dojo subscribers)

Register Now

Unlock Anthropic AI in Microsoft Copilot: Step-by-Step Setup & Crucial Warnings!

In this video, I walk you through how to enable Anthropic’s powerful AI models—like Claude—inside Microsoft Copilot. I’ll show you exactly where to find the settings, how to activate new AI providers, and what features you unlock in Researcher and Copilot Studio. Plus, I share an important compliance warning you need to know before turning this on, so you can make informed decisions for your organization. If you want to supercharge your Copilot experience and stay ahead with the latest AI integrations, this guide is for you!

Video link = https://www.youtube.com/watch?v=Gxa9OrI6VJs

Get a copy of my Comparing AI Services Report

bp1

I’ve bundled up all my research into different AI services and had Copilot Research generate a report which you can now request via email by filling in this form:

https://forms.office.com/r/tGK2GZPLc1

The report covers my findings from a recent series of blog posts I wrote that culminated with:

https://blog.ciaops.com/2025/09/12/comparing-ai-services-an-objective-analysis/

but the downloadable report brings all The articles nicely together with some additional insights.

Improved Windows Defender script

Recently, Microsoft updated Visual Studio code and Github Copilot to include the ability to auto detect which AI is best model to use when coding:

Screenshot 2025-09-15 081243

I therefore thought I’d take it for a spin and elected to use it to improve the script:

https://github.com/directorcia/Office365/blob/master/win10-def-get.ps1

which you now see the results for yourself. The script require escalation to local administrator to gather the information it needs.

Screenshot 2025-09-15 081733

Tests include:

– Attack Surface Reduction Rules

– Defender Settings

– Scanning Settings

– Latest Signature / Engine Versions

– Platform Security

and more. You will find the documentation at:

https://github.com/directorcia/Office365/wiki/Windows-Security-Audit-Script

which was also generated thanks to Github Copilot.

Let me know what you think and if you feel anything should be added.

Prompts to use to get PowerShell scripts from your ASD Agent

Here are 10 tailored prompts you can use with your ASD Secure Cloud Blueprint agent to address common Microsoft 365 Business Premium security concerns for SMBs, with a focus on automated implementation using PowerShell:


🔐 Identity & Access Management

  1. “What are the ASD Blueprint recommendations for securing user identities in M365 Business Premium, and how can I enforce MFA using PowerShell?”
  2. “How does the ASD Blueprint suggest managing admin roles in M365 Business Premium, and what PowerShell scripts can I use to audit and restrict global admin access?”

📁 Data Protection & Information Governance

  1. “What ASD Blueprint controls apply to protecting sensitive data in M365 Business Premium, and how can I automate DLP policy deployment with PowerShell?”
  2. “How can I implement ASD Blueprint-compliant retention policies in Exchange and SharePoint using PowerShell for M365 Business Premium tenants?”

🛡️ Threat Protection

  1. “What are the ASD Blueprint recommendations for Defender for Office 365 in Business Premium, and how can I configure anti-phishing and safe links policies via PowerShell?”
  2. “How can I automate the deployment of Microsoft Defender Antivirus settings across endpoints in line with ASD Blueprint guidance using PowerShell?”

🔍 Auditing & Monitoring

  1. “What audit logging standards does the ASD Blueprint recommend for M365 Business Premium, and how can I enable and export unified audit logs using PowerShell?”
  2. “How can I use PowerShell to monitor mailbox access and detect suspicious activity in accordance with ASD Blueprint security controls?”

🔧 Configuration & Hardening

  1. “What baseline security configurations for Exchange Online and SharePoint Online are recommended by the ASD Blueprint, and how can I apply them using PowerShell?”
  2. “How can I automate the disabling of legacy authentication protocols in M365 Business Premium to meet ASD Blueprint standards using PowerShell?”

10 ready-to-use prompts you can ask your ASD-aligned security agent

Here are 10 ready-to-use prompts you can ask your ASD-aligned security agent to tackle the most common SMB security issues in Microsoft 365 Business Premium tenants.
Each prompt is engineered to:

  • Align with the ASD Secure Cloud Blueprint / Essential Eight and ACSC guidance
  • Use only features available in M365 Business Premium
  • Produce clear, step-by-step outcomes you can apply immediately
  • Avoid E5-only capabilities (e.g., Entra ID P2, Defender for Cloud Apps, Insider Risk, Auto-labelling P2, PIM)

Tip for your agent: For each prompt, request outputs in this structure: (a) Current state(b) Gaps vs ASD control(c) Recommended configuration (Business Premium–only)(d) Click-path + PowerShell(e) Validation tests & KPIs(f) Exceptions & rollback.


1) Identity & MFA Baseline (ASD: MFA, Restrict Privilege)

Prompt:
Assess our tenant’s MFA and sign-in posture against ASD/ACSC guidance using only Microsoft 365 Business Premium features.
Return: (1) Conditional Access policies to enforce MFA for all users, admins, and high-risk scenarios (without Entra ID P2); (2) exact assignments, conditions, grant/ session controls; (3) block legacy authentication; (4) break-glass account pattern; (5) click-paths in Entra admin portal and Exchange admin centre; (6) PowerShell for disabling per-user MFA legacy and enabling CA-based MFA; (7) how to validate via Sign-in logs and audit; (8) exceptions for service accounts and safe rollback.”


2) Email Authentication & Anti-Phishing (ASD: Email/Spearphishing)

Prompt:
Evaluate and harden our email domain against phishing using Business Premium capabilities.
Cover: (1) SPF/DKIM/DMARC status with alignment recommendations; (2) Defender for Office 365 (Plan 1) policies—anti-phishing, Safe Links, Safe Attachments, user and domain impersonation; (3) external sender tagging and first-contact safety tips; (4) recommended policies per ASD/ACSC; (5) step-by-step config in Security portal & Exchange admin centre; (6) test plans (simulated phish, header eval, URL detonation); (7) KPIs (phish delivered, click rate, auto-remediation success).”


3) Device Compliance & Encryption (ASD: Patch OS, Restrict Admin, Hardening)

Prompt:
Create Intune compliance and configuration baselines for Windows/macOS/iOS/Android aligned to ASD/ACSC using Business Premium.
Include: (1) Windows BitLocker and macOS FileVault enforcement; (2) OS version minimums, secure boot, tamper protection, firewall, Defender AV; (3) jailbreak/root detection; (4) role-based scope (admins stricter); (5) conditional access ‘require compliant device’ for admins; (6) click-paths and JSON/OMA-URI where needed; (7) validation using device compliance reports and Security baselines; (8) exceptions for servers/VDI and rollback.”


4) BYOD Data Protection (App Protection / MAM-WE)

Prompt:
Design BYOD app protection for iOS/Android using Intune App Protection Policies (without enrollment), aligned to ASD data protection guidance.
Deliver: (1) policy sets for Outlook/Teams/OneDrive/Office mobile; (2) cut/copy/save restrictions, PIN/biometrics, encryption-at-rest, wipe on sign-out; (3) Conditional Access ‘require approved client app’ and ‘require app protection policy’; (4) blocking downloads to unmanaged locations; (5) step-by-step in Intune & Entra; (6) user experience notes; (7) validation and KPIs (unenrolled device access, selective wipe success).”


5) Endpoint Security with Defender for Business (EDR/NGAV/ASR)

Prompt:
Harden endpoints using Microsoft Defender for Business (included in Business Premium) to meet ASD controls.
Return: (1) Onboarding method (Intune) and coverage; (2) Next-Gen AV, cloud-delivered protection, network protection; (3) Attack Surface Reduction rules profile (Business Premium-supported), Controlled Folder Access; (4) EDR enablement and Automated Investigation & Response scope; (5) threat & vulnerability management (TVM) priorities; (6) validation via MDE portal; (7) KPIs (exposure score, ASR rule hits, mean time to remediate).”


6) Patch & Update Strategy (ASD: Patch Apps/OS)

Prompt:
Produce a Windows Update for Business and Microsoft 365 Apps update strategy aligned to ASD Essential Eight for SMB.
Include: (1) Intune update rings and deadlines; (2) quality vs feature update cadence, deferrals, safeguards; (3) Microsoft 365 Apps channel selection (e.g., Monthly Enterprise); (4) TVM-aligned prioritisation for CVEs; (5) rollout waves and piloting; (6) click-paths, policies, and sample assignments; (7) validation dashboards and KPIs (patch latency, update compliance, CVE closure time).”


7) External Sharing, DLP & Sensitivity Labels (ASD: Data Protection)

Prompt:
Lock down external sharing and implement Data Loss Prevention using Business Premium (no auto-labelling P2), aligned to ASD guidance.
Deliver: (1) SharePoint/OneDrive external sharing defaults, link types, expiration; (2) guest access policies for Teams; (3) Purview DLP for Exchange/SharePoint/OneDrive—PII templates, alerting thresholds; (4) user-driven sensitivity labels (manual) for email/files with recommended taxonomy; (5) transport rules for sensitive emails to external recipients; (6) step-by-step portals; (7) validation & KPIs (external sharing volume, DLP matches, label adoption).”


8) Least Privilege Admin & Tenant Hygiene (ASD: Restrict Admin)

Prompt:
Review and remediate admin privileges and app consent using Business Premium-only controls.
Provide: (1) role-by-role least privilege mapping (Global Admin, Exchange Admin, Helpdesk, etc.); (2) emergency access (‘break-glass’) accounts with exclusions and monitoring; (3) enforcement of user consent settings and admin consent workflow; (4) risky legacy protocols and SMTP AUTH usage review; (5) audit logging and alert policies; (6) step-by-step remediation; (7) validation and KPIs (admin count, app consents, unused privileged roles).”


9) Secure Score → ASD Gap Analysis & Roadmap

Prompt:
Map Microsoft Secure Score controls to ASD Essential Eight and generate a 90‑day remediation plan for Business Premium.
Return: (1) Top risk-reducing actions feasible with Business Premium; (2) control-to-ASD mapping; (3) effort vs impact matrix; (4) owner, dependency, and rollout sequence; (5) expected Secure Score lift; (6) weekly KPIs and reporting pack (including recommended dashboards). Avoid recommending E5-only features—offer Business Premium alternatives.”


10) Detection & Response Playbooks (SMB-ready)

Prompt:
Create incident response playbooks using Defender for Business and Defender for Office 365 for common SMB threats (phishing, BEC, ransomware).
Include: (1) alert sources and severities; (2) triage steps, evidence to collect, where to click; (3) auto-investigation actions available in Business Premium; (4) rapid containment (isolate device, revoke sessions, reset tokens, mailbox rules sweep); (5) user comms templates and legal/escalation paths; (6) post-incident hardening steps; (7) validation drills and success criteria.”


Optional meta‑prompt you can prepend to any of the above

“You are my ASD Secure Cloud Blueprint agent. Only recommend configurations available in Microsoft 365 Business Premium. If a control typically needs E5/P2, propose a Business Premium‑compatible alternative and flag the limitation. Return exact portal click-paths, policy names, JSON samples/PowerShell, validation steps, and KPIs suitable for SMBs.”