The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/The Azure Security Podcast
The Azure Security Podcast artwork

Episode 120: The Zero Trust Workshop (and so much more!)

The Azure Security Podcast · 2025-10-29 · 59 min

0:00--:--

Key moments - from our scoring

Substance score

66 / 100

Five dimensions, 20 points each

Insight Density14 / 20
Originality11 / 20
Guest Caliber16 / 20
Specificity & Evidence13 / 20
Conversational Craft12 / 20

Meryl Fernando, a PM on Microsoft's Entra customer experience team, shares the evolution of the Zero Trust Workshop - a practical tool born from recognizing that customers need clear sequencing and guidance when deploying identity-first security practices. The workshop originated as a simple question-and-answer framework to help enterprises understand prerequisites and dependencies before implementing best practices like conditional access, device compliance, and MFA enforcement. Rather than a simple checklist, it's a comprehensive assessment covering identity modernization (moving from legacy protocols like Kerberos and NTLM to modern auth like OpenID Connect), application architecture, and the broader zero trust strategy. The discussion contrasts the simplicity and developer experience of older authentication methods with the superior security posture and flexibility of modern protocols - examining why companies struggle to move away from legacy approaches despite their inherent limitations in conditional access enforcement. The workshop has evolved from an identity-focused tool into a cross-pillar framework that incorporates knowledge from 100+ SMEs across Microsoft's global security organization, now addressing device compliance, network security, and other zero trust pillars beyond pure identity management.

Key takeaways

  • →The Zero Trust Workshop evolved from Microsoft Entra teams recognizing that customers need sequenced, prerequisite-aware guidance - not just best practice recommendations - when implementing security changes at scale (e.g., hybrid join requires Azure AD Connect sync configuration before conditional access policies can work).
  • →Modern authentication protocols like OpenID Connect enable conditional access policies to evaluate device compliance, IP location, and other context before granting access, while legacy protocols like Kerberos only pass basic credentials with zero policy enforcement capability.
  • →Zero trust is not a single product deployment but a company-wide strategy requiring application modernization, protocol upgrades, and organizational changes such as procurement policies that eliminate legacy authentication apps from vendor selection.
  • →The workshop framework embeds collective knowledge from 100+ geographically distributed Microsoft SMEs across multiple security pillars, evolved from a PowerPoint deck and Excel spreadsheet into a structured assessment tool used in formal customer workshops.
  • →Identity and access management is a niche career domain with no formal training paths or degrees - most practitioners fall into the role accidentally (from Exchange or AD admin positions) - making peer knowledge-sharing and community resources critical for skill development.

Guests

Meryl Fernando

Topics in this episode

IntuneConditional accessMicrosoft EntraZero Trust WorkshopOpenID ConnectKerberosAzure AD ConnectDevice ComplianceHybrid Entra JoinLegacy Authentication Protocols

Questions this episode answers

What is the difference between legacy authentication protocols like Kerberos and modern protocols like OpenID Connect in terms of security policy?

Kerberos and other legacy protocols (NTLM, basic auth) only pass user credentials to the server with no context about device, IP location, or compliance status, preventing policy enforcement. Modern protocols like OpenID Connect and SAML enable web-based authentication flows where Entra can evaluate conditional access policies - checking device compliance, firewall status, antivirus, BitLocker encryption, and IP location - before granting access.

What prerequisites must be in place before organizations can enforce device compliance policies through conditional access?

Devices must first be enrolled into management (Intune) or domain-joined with hybrid Entra join configured, which requires Azure AD Connect sync setup to synchronize devices from on-premises to Entra ID - a process that can take six months to a year for enterprises with 100,000+ devices.

Why did Microsoft create the Zero Trust Workshop and what problem does it solve?

Microsoft Entra teams found that customers were paralyzed by the number of sequential steps required for security deployments and didn't understand prerequisites or dependencies (e.g., you can't implement conditional access policies before devices are enrolled). The workshop provides structured assessment and sequencing to help customers understand what must be done first and in what order.

What makes OpenID Connect and SAML better for zero trust than Kerberos?

OpenID Connect and SAML are modern protocols that use tokens valid for an hour without requiring repeated authentication server contact, enable web-based authentication flows for policy evaluation, and work across devices and platforms. Kerberos requires constant communication between the user, domain controller, and application server - creating dependency failures and latency issues in internet-scale environments.

How has the Zero Trust Workshop evolved beyond identity?

The workshop started as an identity-focused tool but has expanded into a cross-pillar framework incorporating knowledge from 100+ Microsoft SMEs globally, now covering device compliance, network security, application modernization, and other security pillars beyond just identity and access management.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

14 / 20

The episode contains substantive technical content on Zero Trust implementation, legacy vs. modern authentication protocols, and SFI learnings, but is significantly diluted by extended tangents about the host's prior work on Kerberos/IIS, career advice, and podcast creation philosophy. The core Zero Trust Workshop material is valuable but compressed into perhaps 20 minutes of a 59-minute episode.

if you tell one of the best practice we tell is you need to do device compliance, right? When someone is signing into your application, signing into your tenant, you need to say, okay, are they coming from a known device?
With Kerberos, I didn't have to do anything. I just wrote my ASP, classic ASP or ASP.NET app, threw it on IIS, and suddenly when someone came to my site, I knew who the user was. I wrote zero code.

Originality

11 / 20

The Zero Trust Workshop itself represents practical original work - translating SME knowledge into a sequenced, customer-tested assessment tool. However, the underlying frameworks (Zero Trust pillars, modern vs. legacy auth trade-offs, SFI learnings) are industry-standard. The episode largely explains existing Microsoft strategy rather than introducing novel thinking.

It didn't even start off as zero trust. We in identity saw that when we go to customers and we tell them to do things, there are certain things that need to be done like in a sequence.
We've taken that essence of that knowledge of everyone and put them into this sort of workshop that you can run.

Guest Caliber

16 / 20

Meryl Fernando is a strong guest - a customer experience PM at Microsoft Entra with direct responsibility for large enterprise deployments, hundreds of practitioners across regions, and involvement in SFI strategy. However, he is a career PM/internal advocate rather than a line-of-business operator who has independently built or scaled something at a large organization outside Microsoft's structure.

My name is Meryl Fernando. I work in the Microsoft Entra customer experience team. My role, my day job is to help customers deploy Microsoft Entra, secure their environments.
I'm sort of like the voice of the customer in the product feature reviews and giving early feedback and involving our customers in new features

Specificity & Evidence

13 / 20

The episode includes some concrete examples (McDonald's managing 1M users, SFI removing millions of unused apps, 90-day tenant lifespan, conditional access policy collapsing) but relies heavily on abstract descriptions of frameworks and processes. The Zero Trust Workshop is described conceptually rather than with actual before/after metrics from named customers. Missing are specific numbers on remediation time, cost, or risk reduction from implementations.

one with the McDonald's identity architect, George, and they manage like 1 million users in their tenant, right?
Like you have NIST and others who have published the Zero Trust Pillars. So the first one is identity, which relates to Entra and mostly about users and groups

Conversational Craft

12 / 20

The host allows the conversation to meander significantly (Kerberos tangent spans ~10 minutes) without firmly redirecting back to the stated topic until explicitly acknowledging they are 'so far away from the Zero Trust Workshop.' Questions are generally open-ended and permissive rather than probing. Some productive follow-ups exist (e.g., 'why does OpenID Connect enable conditional access but Kerberos doesn't?'), but many opportunities to push back on vague claims or request specifics are missed. The episode reads more as a friendly catch-up than a rigorous practitioner interview.

So let me bring ourselves back in and say, okay, now we've gone through the origin story.
It's funny you should bring that up. That was the security PM for IIS 5, the web server.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

microsoft42security32identity32access31workshop26zero24trust24entra22different22azure21customers21podcast19whole19back16device16pillars15

Episode notes

In this episode Michael talks with guest Merill Fernando about the Zero Trust Workshop, but we also spend time talking about all things identity! Merill's final thought is pure gold, too! The only bit of news is about Azure SQL DB and how TDE key management during restore,

Full transcript

59 min

Transcribed and scored by The B2B Podcast Index.

Welcome to the Azure Security Podcast, where we discuss topics relating to security, privacy, reliability, and compliance on the Microsoft Cloud Platform. Hey everybody, welcome to episode 120. This week it's just myself, Michael, with a guest that we had on a few months back now, Meryl, who's here to talk to us about the Zero Trust Workshop. But before we get to Merrill, I have one little news item to talk about.

As many of you know, many because I keep talking about it, I was in Azure Data before joining the Red team, and that includes products like Azure SQL Database, Cosmos DB, and so on. And I mainly worked on, well, obviously I worked on the security side of things, but a big part of what I worked on was cryptography. And Peter Van Hover, who's a security PM over in the Azure data team, has written a blog post called Everything You Need to Know About Transparent Data Encryption Key Management for Database Restore.

We were asked many times for sort of some of the minutiae around cryptography in SQL Server and Azure SQL Database and Cosmos DB for that matter. So it's really great to see Peter writing this blog post explaining. basically all the minutiae of cryptography in transparent data encryption key management when doing a database restore. All right, that's all the news I have.

I said it would be short. So let's turn our attention to our guest. As I mentioned, our guest this week is someone we've had on the podcast before, Meryl. Meryl, welcome back to the podcast.

We'd like to take a moment and introduce yourself to our listeners. Hey, Michael. It's good to be here. My name is Meryl Fernando.

I work in the Microsoft Entra customer experience team. And I'm from Melbourne, Australia. So very excited to be here. My role, my day job is to help customers deploy Microsoft Entra, secure their environments.

And identity is something that takes a long time because you need, it impacts people. So it's not like an Azure feature you just turn on or deploy in the backend. It really impacts people, you know, the sign -in experience, how they get. to their applications or how they're blocked from their app.

So when everything's working fine, people don't even see us. It's single sign -on, it's all hidden. But when things go wrong, everyone in the world knows. You'll see newspapers and articles written and it'll come on the news saying there's a Microsoft outage and all of that.

So it's a very critical, important piece of the world. But Entra is not just sign -in. There's a lot happening there. So I help big enterprise customers deploy Entra.

And the key in my role as customer experience PM is to bring that feedback. into Microsoft. I'm sort of like the voice of the customer in the product feature reviews and giving early feedback and involving our customers in new features and things that we work on. And these days, there's a lot happening in AI and all of that space.

So it's a very busy time leading up to Ignite. Hey, so before we get on to the topic, which is the Zero Trust Workshop, You have a weekly podcast, right? So why don't you spend a little bit and just talk about that, like what sort of objectives you're trying to achieve with it? Yes, yeah.

So like everything that I do and I like create a lot of tools on my website, you can go to merrill .net and see some of the ones that I've created. It's something where I wanted it and it didn't exist. So I sort of like, yeah, I'll go ahead and create it.

So I'm new to security. It's about like five or eight years since I came into security. I started as like a VB, VB5, VB3 programmer and been a dev my whole life. But there are a lot of dev podcasts.

There's a lot in that space. You have a lot of choice to pick from. So when I came onto nTribe, it was like, okay, I need to learn from people, learn from the experts, and hear what they see as the problems they are solving and so on. And I didn't really find anything on security.

And Azure Security was one that I was like, oh, yeah, there's something now, at least on security. And I was very excited when you launched. Was it five? About four years?

Yeah, man. I think it's about five years ago. It's crazy. Look, I'm going to be honest.

I'm really kind of pretty impressed that we've been going this long. Actually, I'll make a comment. There was a comment that was made before we started this podcast where someone, I'm not going to name who it was, said, you won't have enough content to do it. And I'm like, have you been in the security space at all?

It's like, really? There's going to be plenty of content. We have no problems getting people on the podcast who want to talk about security. And it's a case of just, honestly, the big impediments, if anything else, is just our time.

That's all. It's a lot of work, editing and coming up with what to talk about and so on. But yeah, no problems at all. But thank you for bringing that up.

Yeah, it's been about five years now. It's been crazy. So I was very keen. And so the Azure Security Podcast really filled the gap, bringing on different...

pms feature teams and i love learning about all the different spaces but i come from identity and entra and there is very little to like no content you might get like one episode in you know over over a 12 month 10 month period on identity so i was like i need to bring in and my uh i had a selfish goal i wanted to talk to very interesting people. And it's a way to build up a lot of friendships and, you know, connect with people. So I've had a lot of fun. I made it a weekly one.

And so, yeah, if someone said it's a challenge for security, I'm doing just on Entra. It's called Entra chat, Entra .chat. I got the domain as well.

So it was really good. So if you head over to entra .chat, I'm at week 25 now. So it's like 25 episodes.

It's a baby compared to the Azure Security Podcast. But there are people who are in the space, identity, IAM experts. For me, I'm not looking for like a big audience, but people who are really in this space for them to see what others are doing, learn from them. And especially IAM is not a...

field where you go and train for it it's an it's an area where people actually fall into this domain by accident like they're they're just put in as the m365 admin or they're an exchange admin most of the time it's an exchange or ad admin And this whole space is new to them. They learn on the go. There are no like courses that you can follow to become an identity or IAM, access management expert. There are some vendor related things.

There is no like a degree, et cetera, even that you do. So it's a very unique space, but it's like I see people share on Twitter and so on. It does pay well because it's a very niche space as well. So from a career perspective, it's really good.

Because every company needs identity. You can take out other products and services, but every org needs identity. And it's now at the forefront of a lot of the security initiatives. And I'll talk about the Zero Trust Workshop and the SFI initiatives we have.

If you see the pillars that Microsoft has from SFI, a lot of the work that we're doing to fix things is at the identity layer and the control plane. very central to every organization. There is no clear -cut path to learn from it. And that's the whole reason I started the IntraChat to bring, and I bring a mix of lots of MVPs and customers.

My two, like the very popular episodes, one with the McDonald's identity architect, George, and they manage like 1 million users in their tenant, right? So this is like a global thing, 1 million tenants, challenges. they face are unique, but at the same time, there's a lot that every identity admin faces the challenges some of that, you know, the folks at McDonald's face with the same, you know, Entra suite that everyone is using, Entra ID. Whether you're like 1 million users in your tenant or whether you have 10 to 100 users in your tenant, you're using the same portal to manage all of this.

So there's a lot of knowledge that we can learn from each other and so on. So it's been very fun doing that on a weekly basis, getting feature PMs, talking about their products, getting MVPs who have lots of experience coming in and sharing. yeah so I've had a lot of fun it's never a challenge to find people I have people like a lot of people asking me to come on the podcast because they have stories to tell and I try to focus more on that because it's a podcast We just talk and share stories.

You know, how do you learn? Because I don't want them to sit through like just a feature description about how a particular feature works. But, you know, how they think that happened, like, you know, the stories, the water cooler stories, because those are areas I feel people can learn and relate to as well to what they're doing in their day job. Let's finish bringing that up.

When we recorded the episode with Mark Racinovich, we had an agenda to go through. We didn't stick even closely to it. Mark started meandering off into things and then I helped meander even further. I found a couple of rabbit holes to go down.

Mark Simons was the one who sort of pulled us back up into reality. It was actually kind of funny, but it was a great episode because it was just a couple of nerds. you know, talking about post -quantum cryptography, it was really a good episode. But you're right.

I mean, you also get to meet a lot of good people. And I think that's critically important too. All right, so let's get back. Talking about going down a rabbit hole.

So let's get to the actual topic of this podcast, which is the Zero Trust Workshop. So why don't you tell us the origin story for the Zero Trust Workshop? And hopefully on the way, you explain kind of Zero Trust as well. Yes, yeah, absolutely.

So the origin story is it didn't even start off as zero trust. We in identity saw that when we go to customers and we tell them to do things, there are certain things that need to be done like in a sequence. So, for example, if you tell one of the best practice we tell is. you need to do device compliance, right?

When someone is signing into your application, signing into your tenant, you need to say, okay, are they coming from a known device? Does it have the firewall turned on? Does it have antivirus deployed? Is it compliant?

Does it have BitLock encryption turned on? So there are all those things that you need to do. So we tell them, look, you must have a conditional access policy that knows whether you're coming from a device that is secure, it doesn't have malware on it, et cetera, versus something you have from somewhere else. And that would include the Linux and Mac analogs to all of those things as well, right?

Yes, absolutely, yeah. It's like cross -platform as well. So our best practice is, yeah, just do this, turn on this policy. But before you can even get to that, you need to make sure that the device is managed, is the device enrolled into Intune.

If you're doing a domain join device, there is something you need to do called intra -hybrid join. And intra -hybrid join, you can't just flick one switch. You need to do things like in the intra -connect sync, you need to configure the connect sync, make sure the devices are synced from on -premiere to intra -ID. So there's a whole bunch of steps you need to do before you can turn it on.

And I've been in customer projects where it's taken like six months, sometimes even a year to do that. that one thing to get the devices inter -joint when you're talking like 100 ,000 devices across the company. So what might be like a simple activity is it takes a lot of time to do it. And a lot of people don't know that.

Like my role is to help customers, you know, walk them through these plans and we have SMAs who, you know, help in that flow. But what we realized is there's always like a sequence of things you need to do. And customers are very paralyzed. I don't even know where to start.

There's so much to do. Even if you take something as simple as rolling out MFA to everyone, there's a lot you need to do. You need to make sure that they're using devices that are capable of doing. If you want to enforce authenticator, what version of the mobile are people using?

There's a lot of work that they need to do to plan for those. So that's how it started out as just identity. All of our, like my team, we have like 100 plus people spread out across the globe. And each region has different challenges from Germany, having European challenges to the US folks and in Australia as well.

So we sort of took our collective knowledge and we were like, how do we... communicate this to people. It started as like a PowerPoint deck, like Mark would know, Mark Syvers would. We had this PowerPoint slide which said, you know, these are the things you need to do.

And there were all these slides that were there. And then what we did is we moved into like an Excel sheet. So I came up with the idea, like let's make people flick, like we do a way where we ask questions from customers. we can say what state they are in.

So we came up with the idea of creating a spreadsheet. So we have the Zero Trust Workshop now where you can go download the spreadsheet. It has the knowledge of lots of different SMEs. It's evolved from identity to lots of other pillars and we'll get into them.

And what you do is... You can set up a workshop with a customer and you can go through a sequence of these questions with them. Have you done this? Have you done this?

Like one of the first things we ask is, have you stopped acquiring apps that have legacy authentication? Like we consider like Kerberos and LDAP legacy because you can't apply conditional access on them. Like they're just network level protocols. There's no way to have.

checks in in the middle whereas with the modern auth like oidc and open id open id connect saml with the modern authentication you can actually have policies that do the device checks that can do a lot more things in between before we allow the user to access the application so one big question is have you stopped procuring those products like have you in your organization so it's not even a technology thing It's like you go to the procurement team and tell them, like, this is one of the criteria, like don't acquire apps that are not working on modern authentication.

So that workshop embodies a lot of all of our knowledge and best practices that we poured into that. And I can talk a lot more about, you know, what we've done in that space. And it's now evolved. to a lot more than just Entra.

And it's growing. We have some big plans for it. You bring up Kerberos. So what is it about OpenID Connect that makes it conditional, accessible, and Kerberos not?

What is it that, I'm not going to say unique to it, but what is it that we look for? Yes, that's a really good question, right? When we say legacy protocols with Kerberos, NTLM, basic authentication, the ones we were used to from the 90s, and people, if you're in legacy, in enterprise today, it's still used heavily, right? You go to some website, most of the time it just works, but suddenly you see a Windows pop -up dialog asking you for the username and password, then you need to fill that in.

So those are using... what we call chatty protocols, because they were created for the world, which was for a different era, right? Like the 80s, 90s eras, when the LANs and servers just first came into being. And they all connected over local network.

They would keep talking back to the server whenever the user tried to do anything. So there's a lot of traffic going back and forth. It works really well when you're on the LAN. But once you move to the internet and you have people from all over the world and the whole latency of doing things, it becomes really unusable.

So those protocols don't really work well in the internet era and especially like with mobiles, right? your battery would just die with all the pinging that happens because every time you do something, there are three parties in the old protocol. There is the Windows Domain Controller, there is the Windows Server that you are using, and the actual application server you're accessing. There are all these three, and if the Domain Controller goes down, you lose access to your application, right?

And you can't really do a lot there. With Entra and the new protocols, we have this, we moved to tokens. Like there is this MS Build TikTok I keep seeing all the time where they ask people tokens or passwords. And Mark, Mark, like they ask everyone and they go, like everyone goes tokens.

Because the new identity world is built on these modern protocols. We realized like. Kerberos and all of that's not going to work. So the whole world came up with these protocols where you get a token and for one hour, usually an hour, you don't need to go back to the identity provider.

So even if, for example, Intra goes down, you can still be using your application for that one hour, however long that token that you have. You don't need all three parties involved in that mix. One of the key things it does is it does a web -based authentication. So there's a flow there where there's a web -based auth, which allows Entra to do a lot of things in the browser.

Like it can check for certs on the device. It can check what IP location you're coming from. There are all these activities that are happening with conditional access being as a policy engine for Microsoft. that can go and evaluate all these things before saying, okay, I'm now going to let you access the application so you are allowed to go, which you can't do with Kerberos.

All it does is when it comes to the server in that protocol, it just says these are the user's credentials, like the basic username, password, or the Kerberos token that it has, a ticket that comes with it. It has no context about... the IP address of the user, where they're coming from, what sort of device they're coming from. Not even whether I would say if it's a Mac or Windows.

As long as the protocol was meeting the requirements, it was let through. So that was a huge change from the old world to the new world. And almost everything today is built on the new protocol. But most people are...

I wouldn't say lazy, but they sort of stick to the old things and they're like, yeah, let's just use Kerberos. Like, it's there, so let's keep using it. But if you want to do zero trust, especially, you need to stop using those legacy apps and legacy protocols. Microsoft, we're actively trying to kill some of those older ones, like, you know, relying on things like Samba and so on.

It's funny you should bring that up. That was the security PM for IIS 5, the web server. And that was the version of the web server that integrated Kerberos for the first time. So you're saying that all my work I did back then is now, well, it's all for nothing.

That is tight at the time. It was really, really cool. It was awesome. I mean, we could make a connection to, we could actually flow the identity through the environment.

It was really, really, really nice. I mean, for me, it is still awesome to this day, especially when it comes to as a developer. With Kerberos, I didn't have to do anything. I just wrote my ASP, classic ASP or ASP .

NET app, threw it on IIS, and suddenly when someone came to my site, I knew who the user was. I wrote zero code. I just write one line and say user .identity, and it lets me know who the user's details are.

That flexibility hasn't come to... the the modern auth it's very complicated like even i keep i struggle with oidc and the protocol and the tokens and id token and oauth and like it's a very complex subject on its own and devs struggle a lot like as a dev i'm building an application you know building it on azure i'm worried about the business story and the business scenario authentication always always gets in the way And it's such a complex thing that it's a huge beast. Devs don't really understand it.

It took me a long time to understand it, even as a dev. And even now I keep forgetting like, oh, ID token, refresh token, and the audience claim and this claim. Like you can do the wrong thing and like the code will still work. It's a less secure product.

So that simplicity of Kerberos hasn't come to the dev side. Like today, if you're going to do modern auth, you need to write like hundreds of lines of code. With Microsoft, we try to simplify it. We create this library called msal.

And we say, yeah, put this in, follow this pattern and everything will just work because we have a whole team building that library and they keep updating it with all of, you know, we find new vulnerabilities, they fix that library. It's a complex topic. You need to know a lot about the OIDC protocol and all of that. But Kerberos, and that's why they're still popular because...

The vendors, all of them, they just like it because you don't really even need to think about it. There is no certificates. There is no configuration needed. So it's an amazing experience for devs from that side of it.

You can thank me later. We need to crack the nut on that one. I agree with you. When I wrote with Heimlich and Simone, when I wrote Designing and Developing Secure ASI Solutions, I wrote the identity chapter.

And it was hard to write because the stuff is so complex. And I hark back to when I wrote a book on Windows 2000 and included Kerberos and IIS. It was easy. It was really, really easy.

But anyway, why don't we get back to the topic at hand? I think you and I, we should just, you know, if we start talking about something else, we should just like pull ourselves back out of the rabbit hole. This is one thing I love about podcasts, right? Is that some things like that are really, really interesting.

And I think we need to make things like that more public. Some things are not as easy as perhaps they used to be, but they're more secure and they're more flexible and like you say, with conditional access and so on. And the rationale and the reasons why they are the way they are are sometimes lost. And so I think that's great that you bring those topics up, but we are so far away from the Zero Trust Workshop at this point.

So let me bring ourselves back in and say, okay, now we've gone through the origin story. By the way, I love the idea of the fact that it was, you know, basically necessity being the mother of invention, right? There's something that was needed and you invented it. And I think that's always great when things are sort of built from the grassroots upwards.

So what is the Zero Trust Workshop and how is it sort of delivered to customers? How can people use it? You know, give us a scoop. Yeah, so essentially what we did is I'm an SME on Entry and Identity.

And in Microsoft security, it's a huge stack. It's a huge business at Microsoft as well under Charlie Bell. And there are lots of different services and products. So when you say zero trust.

Most people think of, oh, if I just do a zero trust network access, I deploy it and yay, now I'm zero trust. But it's actually a lot more than all of that, right? Like there's a lot we need to do. Like we took the example of legacy protocols and legacy apps.

Like you need to modernize your apps and that's no product you can buy that can fix it. You need to do this whole work to go and get rid of all these legacy apps in your environment or, you know, wrap them. into a way that they're more secure it's a whole company strategy on moving to newer modern ways of doing things that you can secure it so it's not just about getting a product and deploying it it's a whole thinking around how you would do zero trust where you don't trust anything just because it comes with a you know token or credential so What we did with the Zero Trust Workshop is we started with identity and our customers loved it.

What we do is we run a workshop. We bring everyone in from identity and the security team and various other teams, the security operations team, and we go through this blueprint that we've created. And we ask them questions like, have you done this? Have you deployed conditional access?

Have you, not even before you deploy, do you have a design for conditional access? What is your conditional access strategy, right? Should everyone be able to come into your network or do you have a policy that says maybe when you're accessing Azure, you need to be only on a fixed device, like a known device, or whether you come from a particular network. you need to come up with your strategy for that.

So we walk them through these questions from, are you using legacy apps? Are you doing this? Are you still using things like access reviews? Like are people, do you regularly review who has access to your Azure environment, right?

Every three months, has someone moved roles and do they still have access to a Cosmos DB that they shouldn't have access to? They are no longer in HR, they move to something else, but they still have access to maybe, you know, payroll and other information which they don't need. So all of that's part of identity governance. And we go through all these questions.

It's typically a two to three hour workshop that we run just on identity because we want to give them like a full picture of what is their current state. And as we go through the workshop, we made this very visual. So there's like a roadmap with swim lanes. There are boxes for each thing.

And every box or question, you have a dropdown and you can say, yeah, we haven't thought about it. Or you can say, yes, we are in the process of planning or we actually have a project that's running that's doing this. We are deploying a solution. Or you can say things like we are using a third -party solution.

Like it doesn't need to be a Microsoft solution if you're using like SailPoint for identity governance or Jam for device management. The workshop is very like we try to make it platform agnostic so it's more usable to everyone because... Every enterprise in reality has a mix of different security solutions. So it's not going all in with Microsoft.

So we try to make this very pragmatic about being able to call those things out. So once you finish that, you end up with a neat roadmap of, oh, these are gaps. We haven't thought of this before. And we need to do these things.

And it gives you a sequence. this is a better way to do it because we've taken the knowledge of hundreds of our practitioners who have done like thousands of customer deployments where we've gone through and done these deployments. So we've taken that essence of that knowledge of everyone and put them into this sort of workshop that you can run. And a lot of customers, like we've done this now for a few years, some of our early customers who went through this exercise, they've come back saying, This has been amazing.

We went to our business stakeholders. We showed them the plan and we got funding to do this because some of these are like multi -year projects that you need to run. So they got extra funding from the business. They were able to use the workshop as a artifact for this.

gone ahead and then deployed you know mfa across the board and device compliance and various other projects and initiatives and they've improved their posture from where they were to before and they can clearly show okay this year last year two years ago we were at this state now we've come so far in in the space and they've moved on and we've also been updating the workshop because We learn things at Microsoft, like SFI happened and there are new breaches happening. We learn new things and we have new capabilities to address these different things.

So we also keep updating the workshop to include the new things we learn. And so they're able to say, okay, we've come this far, but there's also more that we need to do over time. So the Zero Trust Workshop, covers a number of pillars. We now have three, six pillars in there all together.

For the Azure folks, we have one of the new ones we introduced is an infrastructure roadmap, and there's also a network roadmap. So the infrastructure roadmap is all about how you go about, you know, doing all of the Azure side, looking at things from servers, you know, all of the different things you need to consider. for all the servers and VMs you're running? How do you set up Azure governance?

How do you set up SIEM? There's a whole streamline on containers. How do you do the various Kubernetes containers, whether you're following the zero trust practices when it comes to that, and various services like Azure Arc. And there's a lot of SFI learnings that Microsoft had, and we've taken and put those in as well.

So SFI is really interesting because we at Microsoft, and Michael, you'll know, we've been doing a lot of things internally at Microsoft based on SFI learnings. And just to make sure everyone who's listening knows, SFI is a secure future initiative. It's a big initiative that started quite some time ago now. basically because of some attacks that have happened on our network.

There's some big changes that we're making across the board. So, for example, a really simple example is apps that are registered that have not been used in N months are basically deleted because they could be a pivot point for an attack. So, yeah, millions of unused registered apps have been removed from the environment. Other things like cleaning up passwords to use managed identities and enter ID in general, but for applications using managed identities, lots and lots of other things.

I could keep going forever, but just so everyone's aware, SFI is Secure Future Initiative. Yeah, and everyone, Satya said, security is job number one for everyone at Microsoft. So if we are assigned a ticket that's related to security, we have to drop everything else and make that the first priority and make sure we address it. before we go on to the other things.

So there's a lot of learnings that we've had and a lot of things that Microsoft is doing internally, which a lot of people don't see outside. Like we do publish a quarterly report of all of Microsoft's progress in this. So we're very transparent about what we've done. A good example is like one of the attacks.

the attackers used like a test tenant and then they pivoted to a corporate tenant from there. We've gone ahead and we've been shutting down all of the tenants, like millions of tenants have been deprovisioned. Now, if you need a tenant, you can't even get a dev tenant easily. You need to go through a whole process and the tenant that you get even for dev work is like, it's short -lived, like it has a...

90 -day lifetime, then the tenant is completely deleted and wiped. So you need to now, you can get a trial tenant, but you need to create it every 90 days so that it makes sure there is no lingering access. And there's a whole bunch of policies that are pushed to it as well, right? I've noticed that network security groups, for example, have some strict policies on them.

I mean, and you get that for free. Congratulations. But that's just it, though. It has to be the default, right?

If it's not the default, then people won't... err on the side of security, and if it's the default, look, I'm going to be honest, some defaults can be painful, right? They can get in the way. But it's a secure default, and if you need to deviate from it, then so be it.

But at least that's the default to start off with. And I think that's such a critically important part of SFI because the second major pillar of SFI is secure by default. So, yeah, I've spun up a, like you said, gone through all the paperwork and, you know. whatever I have to get done to get a tenant.

And yeah, when I deployed it, I noticed there's a whole bunch of really good security faults, which is a good thing. Absolutely. And that's all based on our learning. And for me, fascinating thing, this is the first time I've been at Microsoft.

I haven't been here at Microsoft, you know, for the whole trustworthy computing and the other eras that Microsoft went through. I'm fascinated by Microsoft, like from the leadership down. like how relentless they are about going and making sure it's all fixed like i've worked in other enterprises before it's never been that like it's more like okay it's the security team's problem like they'll do it but here it's like relentless the way microsoft executes on going and fixing like even like years down the line making sure that these things get addressed we have features that take sometimes years to build and you'll see a new feature pop up which was because of what we learned during like even solarigate you know things that happens back five, six years ago, they went through and did the right thing, like, over time.

So that's been really fascinating to watch from the inside for me. And it's a story I don't think many people see outside. They just see, like, you know, the reports and, you know, other things. But it's a whole culture at Microsoft that I really like, you know.

I also want to pull on that a little bit. I've seen a lot of that where a feature... let's just say two years in the future. It was on the schedule for two years in the future.

I'm making numbers up, right? But they got pulled forward, right? They got bumped up the list because of secure future initiative, because it's a requirement. I've seen features that didn't have managed identity support that we're going to have eventually, but all of a sudden they have managed identity support.

Yes. because of SFI. Yeah, that's really good news. So really briefly, you said there are six pillars.

Can you just go through those six pillars really fast and give me a couple of examples of each one? Yes, yeah. So these zero trust pillars are based on industry standards. Like you have NIST.

and others who have published the Zero Trust Pillars. So the first one is identity. So in our workshop, we don't even use the product names. The first one is identity, which relates to Entra and mostly about users and groups and all of that side of things and access governance, access to apps.

Then we have devices. which is, you know, what are the devices that people are accessing their network from? Because when you use Zero Trust, they're using some device, right? So mobiles to laptops and so on.

So that in the Microsoft terminology is mainly about things on the Intune side of the house. So how do you enforce, like what I said, like BitLocker encryption on your device? And have you rolled that out? Have you rolled out Windows Hello for Business?

You know, the whole passwordless thing. And there's so much more from the Intune side, like Defender for Endpoint about securing the device on it and all of the various XDR capabilities there as well. So that's devices. Then the biggest one is data and the most complex one.

When you say data, it's like all over the place. Data from M365 in documents and emails to data in Cosmos DB, in your SQL DBs. An organization has data spread out across the board. And how are you governing the data?

How do you differentiate what's very business critical to the chats that people have on Viva Engage or Yammer? Some companies just treat everything the same and they end up having a weak posture because... they are trying to put all of it in one bucket. But actually, some things like your customer data needs a very different sensitivity and encryption and things compared to just a chat that you might have with someone.

So there is a whole pillar on data. And the Microsoft story there is the Purview side of the house and the capability that Purview has. Then we have network. So network is like the key, one of the big pillars.

And Microsoft now, we have our own zero trust network access solution as well with intra -private access and intra -internet access. So we cover all of what you should be doing in that space. Infrastructure is what I just told you about Azure. There's a whole lot on the Azure side of the house, what you would do.

And the final one is security operations. So it's a good combination of what people think about from an Azure security on an Azure security podcast. So the security operations is one of the newest pillars we added. They go into all of the Microsoft Defender suite of products and Sentinel because you need to really be seeing what's happening in your organization.

You need visibility. into what your users are doing and also be able to track attackers, threat actors, and so on. So that was one of the other newest pillars we added. There are lots of services there, all the MDA, MDI, MDO suite of things, which is very comprehensive once you go through all of that.

We also have some really cool new pillars that we are working on. Things like AI and agents. So that's the new thing that's going to be coming along. So we are working on adding all of those additional pillars as well.

It's nice that it's so complete, right? Because a lot of people think, oh, you know, just cover this one thing and we'll be golden. But that's never the case. Shall I give you an example of why I say that?

So my manager, Craig Nelson, who was on the podcast some weeks ago, he's the vice president of the red team at Microsoft. He makes a comment which is, you own your terrain. However, the terrain is different at different layers. Networking terrain is different than the identity terrain, which is different than the app terrain, which is different than the blah, blah, blah terrain.

They're all different. So it's fantastic that you guys are covering all these things at different layers. Even though they may all be at the application layer, they're all sort of different. So that's really great.

So how do Microsoft partners fit into all of this? Yeah, so that's one of the things like we can't do this just by Microsoft. You need a lot of SMEs. You know, you need people who have the knowledge you have done these and deployed successfully with customers.

And when a customer is doing it, they can get help from our partners. So what we've been doing is we've been training a lot of Microsoft partners on how to do these workshops. And what I love is those practitioners. They have done these things.

They have helped customers deploy these various solutions. They have their own learning and knowledge. With the workshop, they're able to take this blueprint and bring their knowledge and expertise and then scale it out to customers. So most of my team, we work with the large enterprise customers, but there are like hundreds and thousands.

Like the large enterprise customers are maybe like 10 % of Microsoft's overall customers when it comes to the... products that people use. 80 % you would see like small and medium businesses, you know, with 5 ,000 users, 10 ,000, even, you know, 1 ,000 and less. So we need to be able to go and help all of them deploy various things as well.

And that's where our partners come in and partners at, you know, different scales. So they are able to take these workshops and then run it. We've been training and scaling up all of our partners. on how to deliver these workshops.

And they've been sharing a lot of feedback and helping improve the workshop as well. Yeah, I mean, it's easy to be in the Microsoft ivory tower sometimes. So I think it's great to see other people chiming in as well. And I'm really glad that you guys have made it essentially technology agnostic as well, which is great.

So what's in the future? What are you guys looking at? I mean, I have no doubt, no doubt that AI has got some... It's somewhere involved in here somewhere.

Yeah, so there is an AI and apps that we have, new pillars that will come to the workshop. Another big part of the workshop is the assessment. We have a very basic assessment today, which tells you some things that you should do. But there's something we are working on.

We plan to launch it with the next SFI report that comes on. It's something I've been working on very closely with because internally at Microsoft, you've seen, right? We said, okay, apps shouldn't be using secrets. And people have had to go and remove all the secrets from their apps.

We have a way to track them and, you know, know what they need to do. And our customers have been telling us. look, it's good you are doing all these things to secure your environment, but we are also running Entra, we are also running Intune and other services. Tell us how we can secure, do the same things that Microsoft is doing.

So we've gone ahead and we've taken ISFI learnings and we've published them. But there are like 100 plus things you need to check as part of SFI that we are doing from, you know, the network zones to so much work happening at Microsoft. So what we are trying to do is give away for customers to run a script. We'll be sharing with them like a PowerShell module that they can run and they can get their own list of, look, you have these 100 apps that have secrets in them.

These apps have secrets that are valid for 10 years, which means anyone who's worked at the company, they will have access because if they have a copy of the secret and you don't rotate your secret, they will have access even if they are let go to connect to your environment from outside. So insiders who are insiders today, but they become outsiders and you have that threat. factor as well so we're building this assessment that will give you a neat list of these are the issues we found very similar way to how microsoft is running things internally with our internal tools where we look and monitor and we enforce you know the newer things based on our learning so the assessment is something people can look out for it's going to really help you you know overall assess the health of your environment and these pillars so that's happening another big part of it is we are building we're taking our product teams are taking these learnings and building it into the product so we today have things like we are building agents so using AI for security so we recently published a conditional access optimization agent in Entra because over time we see agents taking on this role.

You don't want to have a large identity or access team that is chasing up behind people to remove their secrets and so on. So we have plans where we can use agents that can do a lot of the heavy lifting for you. Ones that have come out are like Conditional Access Optimization Agent and there is an Identity Access Review Agent that launched as well. And there's a lot more coming.

So wait for Ignite where we will be sharing all of that. So we are taking these learnings. We want to build it into the product as well and make it a lot more easier to do these things where it doesn't have to be manual. You will have agents that will help you and guide you.

uh do a lot of that so that is like the long -term vision of uh of this right like you don't we want to move away from having experts like me being able to go and work with you know individual logs to having a lot more being done by agents that can help guide iams to you know improve that it's like it's like having an sme uh in this in each domain space that they can work with easily But humans have the final say though, right? On the agents? Yeah. Okay, fantastic.

I mean, I don't know. We'll have to see. But right now, the agent proposes things. It even says, okay, I've come up with, you have like 10 CA policies.

We can actually collapse this into one because they're doing a very similar thing. And it proposes a new CA policy. So today the human, like we need to say, yes, yeah, I approve that. You can go ahead and create that policy.

So that check is there today. Nice. Well, I think we covered a lot of ground, including a lot of ground that I never thought we would cover. But anyway, there it is, just the way it is.

So let's start to bring this episode to an end. I think since last time you were on, we added a new sort of section to the podcast episodes, which is, you know, what does a day in the life of Merrill look like? Yes. Yeah.

So for me, it's an interesting one and I love it. working at Microsoft and my role is sort of a remote role as well. So it's a fun role for me to balance my family and work life. I have four kids.

They are mostly still in school. My eldest just started uni. So it's been like a full hands -on for me with having a household with four kids and many of them teenagers. For me, the day starts really early because I'm in Melbourne.

And like today, my first meeting was at 6 a .m. And this is like my third meeting of the day. And it's only like 8 o 'clock, 8 .

50. So it starts early. But what I like is I can then go drop the kids off at school so I can take a break in between. go take them to school, and then I enjoy a nice walk and then come back and start my day.

So it's like the morning time is with all the Redmond folks and most of my team. I get to do that. Then I get to have a break. Then I work with some of my customers in Australia because their daytime starts, help them out and, you know, various projects and work that I do.

So for me, it's very neat because most of the people that ping me are away. because it's Redmond evening and they're off for the day. So I get done with all the meetings in the morning and I have the rest of the day for me to focus, do like focused work. So I get to enjoy that, go pick up the kids from school.

And like, it's a really good work -life balance that I have. And yeah, it's a lot of fun, enjoyable work at Microsoft. Yeah, it's a key thing, right? Enjoy yourself.

It's fun. Yeah. So, all right. So if you had one, you are familiar with this because we had it on the last podcast episode with you.

But if you had just one thought to leave our listeners with, what would it be? For them. One big thing I would say is in this day and age when I don't know if I'll have a job tomorrow because that's how the world is working, you might be let go for no reason of your own, right? It's not something your manager or anyone else can control.

It's to really do things that will accrue to your career, right? One of the easiest things is your access to writing blog, creating content on YouTube, sharing things, sharing your knowledge. And a lot of people are like, they do a lot, they learn a lot of things, but they never end up sharing it. And with my Entra chat, I do a weekly newsletter where I take all the blog posts and things about Entra.

And I post them in a weekly newsletter I send out. I have like 15, 16 ,000 subscribers to that newsletter today. And creating content, you know, showing your expertise, even if it's like you learned something new, sharing it on, you have your choice, right? Like you can pick from LinkedIn to Twitter, whatever it is, sharing that knowledge, writing blog posts on things you learned, but you can make it generic.

So it doesn't need to be a company specific thing. all of that accrues to your career, right? In the future, that's going to help you stand out when you are going to apply for a job. Because I learned this, I was working before, like for about 12 years in a company.

I got let go. I built a fantastic network within the company. But the day I was let go, I had to then apply for a job and do a resume. And there's no difference between me and someone who might be, you know, coming in new.

someone had to read my resume to know the difference and i was like there's a lot i put in and i i lost all of that when i left the company right like you lose complete access to things within the company so for your career you should try to build your profile outside of your work like this will accrue for the rest of your life like i'm towards the later end of my career but for everyone starting out new you have to have to get your sort of voice out write blog posts, share things with the community.

If you can, you know, when there are calls for speakers, apply and go and talk because you might think you don't know much, but the little that you know, the experience is something definitely that at least one or two other people can learn from. And just share that. It can be... It doesn't need to be a blog post or a long YouTube video.

People have different specialties. The way I got into social media is I created these small diagrams of things and people love images and diagrams. So I take some complex topic and I say, hey, this is how pasta -sync works. And I just do a very small visual and that helps people, you know, learn something, which in the day of, you know, micro -scrolling and so on, you get that.

my tip for everyone is this like do this work you the payback it's like you know depositing early into your savings account or in your bank because it'll stick with you for your entire career and it's something that will open new doors new friendships uh take that extra time your your work with companies there's not much you know loyalty anymore you might be told tomorrow like you know this is the end you you need to find your own way so do things that will accrue to your career.

So that's my tip. It's your portfolio, right? It's your portfolio of knowledge and expertise. And the other thing I want to point out, you raised something really interesting there.

You'd be surprised if you don't think you're an expert at something, but you put out there, hey, I did this thing today and I learned this and I didn't think about it this way. It's interesting how many people look at things from a different perspective. And sometimes you may read something where someone wasn't an expert and said, hey, you know, I did this thing today. And did you know it did A, B, and C, but only if X, Y, and Z are set?

And then you look at it, you're like, oh my God, that's why I'm having the problem because X, Y, Z are not set. I didn't realize that. You'd be amazed at how many times that kind of thing happens. So you don't have to be, I often joke that being an expert is just being one page ahead in the book.

There is some truth to that. And I agree a hundred percent. You need to be writing things and posting things and not being an idiot about things either. I mean, if you, you know, stay technical, stay professional, um, cause that stuff lasts forever.

So yeah, write things, book blog posts, come on, come on our blog, you know, on our, on our podcast, you know, it all, it all adds up. So feel free to reach out. Like I get people reaching out asking, Hey, can I come on your podcast? I asked him, you know, what's interesting story you have?

Like a lot of people fear that and rejection, but I mean, I do have to say no, because I can only have so many guests, but like shoot your shot, right? Like you have nothing to lose. You just need to keep reaching out to people and create your brand that then helps you. get get on to podcasts and people go like he's doing interesting stuff share your scripts uh you you're writing scripts today at work you know take that make it simple and just post it share it on a blog post you can spin up like your like there are so many free services from substack to uh you know wordpress and blogging and like you know notions uh you are like spoiled for choice pick something, pick just even LinkedIn without scrolling, like people consume content.

I like what Scott Hanselman says, right? Like you go from being a consumer to creator. So one of my New Year's resolutions like many years back was I'm going to create content more than, not more than, but I'm going to at least spend a little bit of effort. creating content well there's a lot to consume right there is a lot to consume and in fact you could spend all day consuming you can you could spend your entire life consuming yes and i i really like that we need more people like you and other people creating and you know rather than just consuming consuming is very passive exactly and you can find your own niche right like you don't need to have hundreds and thousands of followers right like that doesn't even need to be a thing But I focus only on Entra.

When I started on this journey, I was like, I'm only going to focus on Entra and I only focus on a very specific part of Entra as well. But it's so wide, right? You don't need to be very generic. The more you're focused on a specific area that you're working on daily, you will connect and you'll find others who are doing the same thing and you'll build these relationships.

I've now built so many relationships with people from like from Germany to Denmark to even in Alaska, like different parts of the globe that you wouldn't imagine. And we worked on projects on like we published open source tools, just pinging someone and saying, hey, I saw this and chatting with them. And you do amazing things. And it's a lot.

It's very rewarding and it stays with you. It's not. it's not your career or a job that you have and then when it suddenly ends you're like like you you lose your identity um this stays with you for a long time so that's that's my tip like a takeaway yeah like create content like i give this advice to everyone i see but i see very few people following through so the competition is really non -existent right For those who are creating content, you can just start today and you have a long career ahead.

It doesn't, you don't, it won't become like, like overnight sensation, which people do, right? If you do some really cool black hat presentations and so on, but you can start small and, you know, it will open doors that you cannot imagine. Like it's done for me. Yeah.

I mean, you can have like, it doesn't have to be in black hat, right? It could be like a local thing, you know, some local, bunch of people get together on a every month or so and talk about tech stuff you can talk about the thing that you know excites you and you're you know you're knowledgeable of you don't it doesn't have to be black hat or rsa or anything like that all right let's bring this to an end it was supposed to be all about the zero trust workshop but i think we actually covered a lot of ground um but i think a lot of good ground a lot of important ground so i'm very happy that we had this uh we had this time together So with that, let's bring this episode to an end.

Meryl, thank you again for joining us. It's always a pleasure having you on the podcast. And to all our listeners out there, we hope you found this episode useful. Stay safe and we'll see you next time.

Thanks for listening to the Azure Security Podcast. You can find show notes and other resources at our website, azsecuritypodcast .net. If you have any questions, please find us on Twitter at AzureSecPod.

Background music is from ccmixter .com and licensed under the Creative Commons License.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Rebooting Enterprise AI with MCP and KubernetesPractical AI · on Microsoft Entra88 / 100
  • AI Is Having Its Dropbox MomentAI Proving Ground Podcast · on Conditional access85 / 100
  • CMMC Is Basically an IRS Audit (Here's What We Learned)Trust Issues · on Intune78 / 100
  • Absolute Security Joins Pax8 (EP 1039)Uncle Marv's IT Business Podcast · on Intune63 / 100
  • Ep 118: A Dive into Multi-Factor Authentication with Sairam DurgarajuLevelUp Cyber · on Microsoft Entra49 / 100

More from The Azure Security Podcast

All episodes →
  • Episode 129: John Savill's Top of Mind67 / 100
  • Episode 128: Post Quantum Cryptography87 / 100
  • Episode 127: Threat intel update and AI87 / 100
  • Episode 126: Microsoft Baseline Security Mode80 / 100
  • Episode 125: Origins of MITRE ATT&CK84 / 100
Explore the best B2B Engineering & DevTools podcasts →
All The Azure Security Podcast episodes →