CIA Brief 20260124

image

Exchange Online Public Folder Data and Retention Questions –

https://techcommunity.microsoft.com/blog/exchange/exchange-online-public-folder-data-and-retention-…

Inside the takedown of RaccoonO365: How Phishing-as-a-Service fuels ransomware’s engine –

https://www.microsoft.com/en-us/corporate-responsibility/topics/cybersecurity/stories/raccoono365/

Inside the takedown of RaccoonO365: How Phishing-as-a-Service fuels ransomware’s engine –

https://www.microsoft.com/en-us/corporate-responsibility/topics/cybersecurity/stories/raccoono365/

Ford builds trust across global operations with Microsoft Defender –

https://www.youtube.com/watch?v=55tcTDO1Sbw

Microsoft and Mercedes-AMG PETRONAS F1 Team unite to drive innovation from factory to circuit –

https://news.microsoft.com/source/2026/01/22/microsoft-and-mercedes-amg-petronas-f1-team-unite-to-d…

Microsoft Security success stories: Why integrated security is the foundation of AI transformation –

https://www.microsoft.com/en-us/security/blog/2026/01/22/microsoft-security-success-stories-why-int…

Message Trace Support Using Graph API is now in Public Preview –

https://techcommunity.microsoft.com/blog/exchange/message-trace-support-using-graph-api-is-now-in-p…

Automating Microsoft Sentinel: A blog series on enabling Smart Security –

https://techcommunity.microsoft.com/blog/microsoftsentinelblog/automating-microsoft-sentinel-a-blog…

Microsoft OneDrive, a year in review: AI-powered file management and smarter collaboration –

https://techcommunity.microsoft.com/blog/microsoft365insiderblog/microsoft-onedrive-a-year-in-revie…

After hours

Free climbing in Greenland – https://www.youtube.com/watch?v=ep-xRQDTiOg

Editorial

If you found this valuable, the I’d appreciate a ‘like’ or perhaps a donation at https://ko-fi.com/ciaops. This helps me know that people enjoy what I have created and provides resources to allow me to create more content. If you have any feedback or suggestions around this, I’m all ears. You can also find me via email director@ciaops.com and on X (Twitter) at https://www.twitter.com/directorcia.

If you want to be part of a dedicated Microsoft Cloud community with information and interactions daily, then consider becoming a CIAOPS Patron – www.ciaopspatron.com.

Watch out for the next CIA Brief next week

CIA Brief 20260118

image

Demystifying Exchange Online Mailbox Quotas –

https://techcommunity.microsoft.com/blog/exchange/demystifying-exchange-online-mailbox-quotas/44864…

Inside RedVDS: How a single virtual desktop provider fueled worldwide cybercriminal operations –

https://www.microsoft.com/en-us/security/blog/2026/01/14/inside-redvds-how-a-single-virtual-desktop-provider-fueled-worldwide-cybercriminal-operations/

Turn Complexity into Clarity: Introducing the New UEBA Behaviors Layer in Microsoft Sentinel –

https://techcommunity.microsoft.com/blog/microsoftsentinelblog/turn-complexity-into-clarity-introdu…

After hours

The AI coding boom hits software – https://www.youtube.com/watch?v=FkmuyUTZvXU

Editorial

If you found this valuable, the I’d appreciate a ‘like’ or perhaps a donation at https://ko-fi.com/ciaops. This helps me know that people enjoy what I have created and provides resources to allow me to create more content. If you have any feedback or suggestions around this, I’m all ears. You can also find me via email director@ciaops.com and on X (Twitter) at https://www.twitter.com/directorcia.

If you want to be part of a dedicated Microsoft Cloud community with information and interactions daily, then consider becoming a CIAOPS Patron – www.ciaopspatron.com.

Watch out for the next CIA Brief next week

CIA Brief 20260112

image

Microsoft OneDrive, a year in review: AI-powered file management and smarter collaboration –

https://techcommunity.microsoft.com/blog/microsoft365insiderblog/microsoft-onedrive-a-year-in-revie…

Add links to text faster in Word –

https://techcommunity.microsoft.com/blog/microsoft365insiderblog/add-links-to-text-faster-in-word/4…

Determine Defender for Endpoint offboarding state of Windows machines using PowerShell –

https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/determine-defender-for-e…

From awareness to action: Building a security-first culture for the agentic AI era –

https://www.microsoft.com/en-us/microsoft-cloud/blog/2025/12/10/from-awareness-to-action-building-a…

Always‑on Diagnostics for Purview Endpoint DLP: Effortless, Zero‑Friction troubleshooting for admins –

https://techcommunity.microsoft.com/blog/microsoft-security-blog/always%E2%80%91on-diagnostics-for-…

Explore the latest Microsoft Incident Response proactive services for enhanced resilience –

https://www.microsoft.com/en-us/security/blog/2026/01/07/explore-the-latest-microsoft-incident-resp…

Exchange Online canceling the Mailbox External Recipient Rate Limit –

https://techcommunity.microsoft.com/blog/exchange/exchange-online-canceling-the-mailbox-external-re…

Introducing the Microsoft Defender Experts Suite: Elevate your security with expert-led services –

https://www.microsoft.com/en-us/security/blog/2026/01/06/introducing-the-microsoft-defender-experts…

Phishing actors exploit complex routing and misconfigurations to spoof domains –

https://www.microsoft.com/en-us/security/blog/2026/01/06/phishing-actors-exploit-complex-routing-an…

Announcing public preview: Uncovering hidden threats with the Dynamic Threat Detection Agent –

https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/announcing-public-preview-un…

After hours

Dawn of Cyberwarfare | Full Award-Winning Documentary – https://www.youtube.com/watch?v=BIEOB2jIr_o

Editorial

If you found this valuable, the I’d appreciate a ‘like’ or perhaps a donation at https://ko-fi.com/ciaops. This helps me know that people enjoy what I have created and provides resources to allow me to create more content. If you have any feedback or suggestions around this, I’m all ears. You can also find me via email director@ciaops.com and on X (Twitter) at https://www.twitter.com/directorcia.

If you want to be part of a dedicated Microsoft Cloud community with information and interactions daily, then consider becoming a CIAOPS Patron – www.ciaopspatron.com.

Watch out for the next CIA Brief next week

My podcasts 2026

desk-music-headphones-earphones

You can find the previous year’s selection here:

My podcasts 2025

I do spend a lot of time listening to podcasts, generally in between things, like travelling. However, there is a limit to how many you can consume in a week and that’s why I need to be very discerning about what I listen to.

Regulars

These podcasts are ones that I generally won’t miss an episode of.

Windows Weekly

The latest Microsoft news with some fun and entertainment along the way. Paul Thurrott’s musing make this podcast alone something worth listening to. I still miss Mary Jo Foley as a co-host I will admit and the show just isn’t as good or enjoyable. I still have no interest in the whiskey part of this show, which I now just fast forward through. I still also find that the show is more ‘ranty’ than informational which can get a bit much at times.

The Tim Ferriss Show

Some really great advice, business insights and strategy. Also lots of life lessons that I have found work really well for me. A weekly must listen for me. Some, I do skip through and some can be quite tough to get through because they are so long, but a worthwhile investment of my time. I am finding these shows are getting longer and longer making them hard to squeeze in but I do try and listen to them all.

Hardcore History

These tend to be quite long, like reading a book, but a very good and very interesting. Luckily, they are not that frequent, so it can make a nice change from all the tech stuff. There hasn’t been much content here of late which is disappointing. If you love history and an interesting story, then this is the podcast for you.

The Intrazone

All the latest news and information about SharePoint, OneDrive for Business, Teams and more directly from Microsoft. Pretty short, which makes it easy to consume. Can try a bit hard to be ‘funky’ at times but good way to stay up to date with the Microsoft collaboration news.

Sync Up

A podcast focused on the Microsoft files experience around OneDrive from Microsoft. More content has dropped but they seems to spend so much time at the beginning of the ‘learning’ about the guests and what do they like etc. I’d really prefer they just get into the content. I’m here for that not, not to take a deep dive into the personalities.

Darknet Diaries

Really well produced cybersecurity focused podcast. Has a nice variety of topics and the content is good and well researched. If you enjoy the security side of IT you’ll love these episodes. Seems to me that Jack has run out of content for these for the time being. recent episode have deviated away from main theme in my opinion. Less regular episodes and the topics are becoming broader, which isn’t necessarily a bad thing but the context has changed.

Microsoft Threat Intelligence Podcast

Has some interesting content but tried to be a too ‘whacky, zany and trendy’ at times. Rather high level security information but give good information on the whole threat landscape and interesting personalities and technologies there. Generally around 20 minutes at double speed, so easily digestible.

Once off podcasts

Think of these more of a book you’d read or a TV show you’d watch.

The Lazarus Heist

Another well produced podcast from the BBC that follows the trails of and attempt to steal and launder billions of dollars. Apparently, additional episodes are coming later this year. If you like Darknet Diaries, you’ll like this.

I churn through these mostly at 2x speed to allow me to get through as much content as possible. I do have a few other podcasts on my current podcasting app. I am always on the lookout for good podcasts business, technology, history, whatever. So if you can recommend something you like, I’m all ears. These days, if you have a topic of interested, you’ll find many podcasts you can listen to. Don’t be shy to try them and throw away ones that don’t suit you until you find what you like.

I’ve found that many podcasts have disappeared over the last year and I have been more judicious on what I spend my time listening to. It has to provide valuable information or be enjoyable to listen to and I have become much stricter on those criteria. I have a tried quite a few new podcast in the last year but none of them really stood out for me.

I have struggled to find a ‘good’ podcast on AI. Like most things AI these days, most podcasts I have listened to on the topic are rather ‘fluffy’ and don’t go deep enough into the topic. Luckily, there is still an infinite amount of AI podcast to try but if you have found a good one please let me know.

Finally, of course, there is my own podcasting effort:

Need to Know podcast

which covers the Microsoft Cloud (typically Microsoft 365 and Azure) as well as business topics. I encourage you to have a listen and me know what you think. 2026 will be the sixteenth year that it has been available.

Hopefully, there is something of interest to you in what I listen to. Feel free to let me know as well as any recommendations you may have, as I said, I’m all ears! All of these I listen to directly on Spotify these days, which annoyingly now seems to have ads in between episodes.

CIAOPS Need to Know Microsoft 365 Webinar – January

laptop-eyes-technology-computer_thumb

Now in our tenth year!

Join me for the free monthly CIAOPS Need to Know webinar. Along with all the Microsoft Cloud news we’ll be taking a look at Vibe coding.

Shortly after registering you should receive an automated email from Microsoft Teams confirming your registration, including all the event details as well as a calendar invite.

You can register for the regular monthly webinar here:

January Registrations

(If you are having issues with the above link copy and paste – https://bit.ly/n2k2601 )

The details are:

CIAOPS Need to Know Webinar – January 2026
Friday 30th of January 2026
11.00am – 12.00am Sydney Time

All sessions are recorded and posted to the CIAOPS Youtube channel.

Also feel free at any stage to email me directly via director@ciaops.com with your webinar topic suggestions.

I’d also appreciate you sharing information about this webinar with anyone you feel may benefit from the session and I look forward to seeing you there.

CIAOPS AI Dojo 008

bp

What’s the session about?

This month we will be focusing on new Copilot features and updates as well as optimising AI for Small Business.

Who should attend?

This session is perfect for:

  • IT administrators and support staff
  • Business owners
  • People looking to get more done with Microsoft 365
  • Anyone looking to automate their daily grind

Save the Date

Date: Friday the 30th of January 2026

Time: 9:30 AM Sydney AU time

Location: Online (link will be provided upon registration)

Cost: $80 per attendee (free for Dojo subscribers)

Register Now

CIA Brief 20260103

image

Managing Microsoft Sentinel and Microsoft Defender XDR permissions in Microsoft Defender portal –

https://techcommunity.microsoft.com/blog/MicrosoftSentinelBlog/managing-microsoft-sentinel-and-micr…

Microsoft Sentinel Platform: Audit Logs and Where to Find Them –

https://techcommunity.microsoft.com/blog/MicrosoftSentinelBlog/microsoft-sentinel-platform-audit-lo…

Get ready for the new year with Microsoft 365 –

https://techcommunity.microsoft.com/blog/microsoft365insiderblog/get-ready-for-the-new-year-with-mi…

After hours

The Truth About the Moon Landings– https://www.youtube.com/watch?v=fMHLvoWZfqQ

Editorial

If you found this valuable, the I’d appreciate a ‘like’ or perhaps a donation at https://ko-fi.com/ciaops. This helps me know that people enjoy what I have created and provides resources to allow me to create more content. If you have any feedback or suggestions around this, I’m all ears. You can also find me via email director@ciaops.com and on X (Twitter) at https://www.twitter.com/directorcia.

If you want to be part of a dedicated Microsoft Cloud community with information and interactions daily, then consider becoming a CIAOPS Patron – www.ciaopspatron.com.

Watch out for the next CIA Brief next week

My software and services – 2026

startup-photos

Here’s last year’s post for comparison:

My software and services – 2025

My PC’s are either running the latest version of Windows 11 (24H2) without any issues. I no longer run any Windows Insider builds as I had trouble backing out of these when I needed to. I still have Office Insider builds happening in my environment.

All Windows machines are directly joined to Entra ID and managed via Intune and Microsoft Endpoint Manager, except for one that remains stand alone for use with my IoT projects.  The Entra ID connected configurations are based on the Windows MDM security baseline settings. All machines only use  Windows Defender for local security monitoring and management. Thanks to Microsoft E5 on my production tenant, I am also using Microsoft Defender For Endpoint at the back end for monitoring and investigation of endpoint threats.

My two main tenants are Microsoft 365 E5 demo and Microsoft 365 E5 production environments. The production Microsoft 365 tenant has Microsoft 365 Business for all users except myself. I have a Microsoft 365 E5 license on which I have configured all the services including integrated PSTN calling via Switch Connect.

I use Microsoft Sentinel to monitor threats across my environments via a single pane of glass. I have also now added Defender EASM for monitoring security threats. Failed login attempts by country in the last 30 days from sentinel look like:

Screenshot 2026-01-03 080936

I use the following major browsers:

Edge – my primary browser across all my devices including iOS and Android. I have it locked down with baseline policies via Microsoft Endpoint Manager.

Brave – I have become increasingly concerned about the surreptitious tracking that many sites perform, especially when it comes to social media sites. I therefore now do all my ‘random browsing’, searching and viewing of social media sites using Brave. I also like that Brave allow me easy access to Tor browsing for anonymous security work.

I have now cranked Edge up to the maximum security level but wanted to isolate the most likely tracking culprits into another browser that was security focused. After some evaluation, I have chosen Brave to be this browser. This is now where I do all the stuff that is more likely to be tracked and now hopefully blocked or at least minimised. I have also set this browser up to use Duck Duck Go for search, otherwise I use Bing for my production Edge browser. I have completely eliminated Google Chrome from all my machines without any issues and recommend those who are becoming more concerned about their privacy, like me, do the same.

Services like SharePoint Online and OneDrive I use regularly both in the demo and production tenant. I have the OneDrive sync client installed, running and connected to various locations on my production and demo tenants. I can now sync across all my different tenants as well as my consumer OneDrive storage. I have common places pinned to my Windows Explorer Quick access, which I find to be a real time saver.

I regularly use Microsoft Teams which is now my main messaging application and I’m using the new Teams client. All the CIAOPS Patron resources like the intranet, teams, etc all reside in the Microsoft 365 E5 demo tenant but I connect to it on my desktop normally via an Azure B2B guest account from my production tenant. Thus, I can admin the Patron resources in a browser if need be but I get the same experience on my desktop as any Patron would. Handy to know what works and doesn’t work with Microsoft Teams guest access. Thanks to Microsoft E5 and Switch Connect, I also have Teams connected as a phone.

I use Lastpass to keep my passwords and private information secure. It allows me to do things like generate and store unique passwords for each website that I sign up for. It is also available across all browsers on my machine (including Microsoft Edge). I also now also use Lastpass to store secure notes. I accept recent security breaches with Lastpass generate concerns but after some investigations I believe the risk for myself is minimal and as yet don’t feel a need to switch. If I am going to change at any point I think I’d be going with Bitwarden but that hasn’t been necessary as yet.

The extensions I run in all my browsers are:

LastPass

Duck Duck Go Privacy Essentials

I use Microsoft Power Automate for automation as well as Azure Functions.

For my email newsletters I use Mailchimp.

My preferred public social networks for business, in order are:

1. X

2. Linkedin

I would suggest that no matter what social media service you elect to use that you should spend time customising what you see. Unfiltered content is distracting but you can get good results if you spend just a little time telling the service what you do want to see I have found. Thus, don’t accept the defaults. You CAN customise what is presented to you.

I consume a lot of content from YouTube both for business and personal interest. I also also use YouTube extensively for my publicly available training video training.

Microsoft Office desktop software is still part of my everyday workday via applications such as Outlook, Word, Excel, PowerPoint, etc. I use the desktop version of Outlook on my Surface Pro 7 which lives on my desk but I only use Outlook Web App on my travelling Surface Pro 9 device. I could happily not use Outlook on the desktop any more I believe but I still use so I understand the experience for most users. However, I do see the day when Outlook on the desktop begins to lose its appeal.

Currently, I use both classic Outlook and New Outlook on various desktops without too much issues. I prefer classic Outlook but New Outlook has come a long way and added many of the capabilities I use in Classic Outlook. The missing piece for me still is the way to customised New Outlook to see emails, calendar and tasks all on a single page, which I don;t believe New Outlook supports just yet. I appreciate that Microsoft will soon be forcing everyone to New Outlook and I believe my soul is prepared for this transition when it comes.

The key application from the suite for me is OneNote. OneNote is my go to Swiss Army knife for just about everything digital. I use it to capture all sort of data. I even use it as a diary as I have detailed previous here:

One of the ways I use OneNote

The reason OneNote is key is because:

1. Just about everything I put in there us searchable

2. It is freely available across all platforms.

3. All my information is synced and accessible on all devices.

4. It is available on the web or offline if needed.

I am a big user of OneNote on my mobile devices. This combination has allowed me to totally eliminate my paper notebooks for things such as journaling.

I am now a big Microsoft To-Do user. I use it to keep many tasks and items that I need to follow up including when bills are due. I love how it is available on all my devices and syncs across them all as well.

I use Windows terminal now for things like PowerShell execution and Microsoft Whiteboard for demonstrations and training.

Another key service I use everyday along with Microsoft 365 and OneNote is Azure. Typically, I use it for running up virtual machines that I test various things with but I also use it with my IoT projects.

There is just so much that can be done with Azure and I pretty much use it everyday.

All of my data now lives in Microsoft 365 protected with things like Windows Information Protection and other Microsoft information protection options. All my Windows machines run with full disk encryption thanks to Bitlocker.

I have implemented Windows Defender Application Control (WDAC) to provide application control to improve security in my environment.

To capture my desktop for my online training academy or my YouTube channel I use Camtasia. I use SnagIt to capture screen shots and add highlights and emphasis to these. Snagit allows me to capture complete screens or specific areas quickly and easily. I will admit that I am using this software less and less now. It is simply too slow to get running. We’ll see. The standard Windows apps are much faster and tend to be what I use to capture screen information.

I use Microsoft Teams to record my podcasts, which I then produce with Camtasia. These are uploaded to Podbean where they syndicated across various network.

To compose and publish blog articles I use Open Live Writer. My blog lives on WordPress.com.

My web site and Battlefields site live on Squarespace.

The majority of images I now generate directly using Microsoft Copilot.

I use Visual Studio Code in which I do most of my PowerShell editing and publishing. I also use it now for my IoT projects. The end result typically is my GitHub repository where you will find a range of scripts and other resources that I maintain regularly. With Visual Studio Code I can edit publish and sync all my machines and my GitHub repository no matter where I am. Very handy.

Here are also a few of the other items I use regularly that are not for business:

Amazon Prime Video – Most of this viewing is now on my iPad mini and I am looing forward to the next series of Clarkson’s Farm.

Audible – Probably the most used app on my iPhone. I listen everyday, especially when I am travelling interstate or even in the car. I can highly recommend my last read – Mr Wilman’s Motoring Adventure: Top Gear, Grand Tour and Twenty Years of Magic and Mayhem

NetFlixCurrently watching Mark Rober’s Crunchlabs

Duolingo – language, maths and music learning, Japanese and Italian at the moment but most of this access is now on my iPad mini.

WaniKani – Helping me learn Japanese characters

Kindle app – for typically reading books on my iPad

I try and keep my production machines as ‘clean’ and free of unused software as possible. I ensure that they are updated regularly. Any software testing that I need to do is typically done on a virtual machine in Azure.

A new section I thought I’d add is the AI that I use. The common Ai I use by far is GitHub Copilot. i use this daily to assist with coding tasks like creating PowerShell scripts and writing KQL queries amongst other things. Even though I have a paid version of GitHub Copilot I am happy to say there is also a free version that you can take advantage of and the details are here.

I have a subscription to Microsoft 365 Copilot which I have had now for about 2 years. I use this every day, but especially with Teams and Stream to summarise videos and other content. I also use Copilot Studio to create custom agents which I and others use inside the Microsoft Teams I manage.

The main non-Microsoft AI that I use is Perplexity even though there are some ‘ethical’ challenges around this service. I signed up for Gemini Enterprise because i wanted access to an AI that is separate from GPT models. Gemini also doesn’t run on NVIDIA chips so it give me a counterpoint to the ‘standard’ most people use. I use Claude regularly when working with code and ChatGPT is also something that I use now and again as I have found it to be the poorest of all the consumer AI services.

I think I’ll have to start doing an annual post on what AI services I use and why.

So there you have it, the major software and services that I use regularly. I continue to search out additional software that will improve my productivity. If you use something that you’ve found really handy, please let me know and I always keen to explore what works for others.