The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/The Azure Security Podcast
The Azure Security Podcast artwork

Episode 122: Microsoft Ignite 2025 Wrap-up

The Azure Security Podcast · 2025-12-15 · 33 min

0:00--:--

Key moments - from our scoring

Substance score

53 / 100

Five dimensions, 20 points each

Insight Density12 / 20
Originality10 / 20
Guest Caliber11 / 20
Specificity & Evidence11 / 20
Conversational Craft9 / 20

Microsoft Ignite 2025 delivered substantial security announcements across the product portfolio, reflecting the company's Secure Future Initiative to embed security throughout non-security products. Sarah attended the 20,000-person event at San Francisco's Moscone Center and reported extensive security news alongside traditional keynotes and breakouts. The hosts identified several critical themes: Agent 365 (an IT admin and security visualization tool integrating signals from Entra, Defender, and Purview for agent lifecycle and compliance management), post-quantum cryptography now GA in Windows and .NET 10 with emphasis on crypto agility, and expanded Purview data security controls for AI governance. Additional highlights include Security Copilot SCU inclusion in E5 licenses for broader enterprise access, hardware-accelerated BitLocker launching early 2025, Zero Trust DNS blocking unauthenticated name resolution, passkey sync support in Windows 11, Attack Disruption extended to AWS, Proof Point, and Okta, and policy enforcement for prompt injection protection and agent governance across managed and unmanaged AI applications. The discussion emphasizes that security controls for AI are arriving at an unusually rapid pace compared to previous technology generations.

Key takeaways

  • →Post-quantum cryptography APIs are now GA in Windows and .NET 10, addressing harvest-now-decrypt-later threats and requiring organizations to plan crypto agility strategies.
  • →Agent 365 visualizes agent communication, data sources, risks, and compliance across Entra, Defender, and Purview in a single portal, positioning it as a de facto security tool despite official IT admin classification.
  • →Security Copilot SCUs are being included in E5 licenses with gradual rollout, enabling broad enterprise experimentation with AI-powered security without additional licensing commitments.
  • →Hardware-accelerated BitLocker launching early 2025 maintains encryption keys in hardware rather than memory, reducing performance concerns around full-volume disk encryption adoption.
  • →Zero Trust DNS blocks DNS resolution unless validated by privileged DNS infrastructure over TLS, forcing attackers to resolve real-world domains rather than hiding behind IP-to-IP command and control.

Guests

MarkSarah

Topics in this episode

Microsoft DefenderAgent 365Post-quantum cryptographyEntraSecurity CopilotBitLocker hardware accelerationZero Trust DNSPurview data securityPasskey syncPrompt injection protection

Questions this episode answers

What is Agent 365 and what does it do?

Agent 365 is an IT admin tool in private preview that visualizes agent communication and ingests signals from Entra, Defender, and Purview to display risks, compliance status, and data source interactions in one portal, positioning it as a practical security tool despite its official classification.

Why is post-quantum cryptography important now?

Quantum computers will break current asymmetric algorithms like RSA and elliptic curve cryptography, and adversaries are already conducting harvest-now-decrypt-later attacks to steal encrypted data for future decryption, making post-quantum crypto migration urgent.

How does Zero Trust DNS improve security?

Zero Trust DNS blocks DNS name and IP resolution unless validated by privileged DNS servers over TLS, preventing malware command-and-control channels that rely on DNS or IP-to-IP communication from functioning.

What's changing with BitLocker in Windows?

Hardware-accelerated BitLocker launching early 2025 moves encryption keys into hardware rather than memory, improving performance and security while removing a key barrier to full-volume disk encryption adoption.

Will Security Copilot cost extra in E5 licenses?

Security Copilot SCUs are being included as part of E5 licenses with gradual rollout already underway, allowing enterprises to experiment with AI-powered security without additional licensing costs.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

12 / 20

The episode covers genuine technical announcements from Ignite 2025 with some substance - post-quantum cryptography APIs, Agent 365, Zero Trust DNS, passkey sync, and hardware-accelerated BitLocker are all real features with brief explanations. However, much of the value is surface-level summarization rather than deep exploration of implications or trade-offs. The hosts occasionally dig into mechanics (e.g., harvest-now-decrypt-later attacks, JWT parsing vulnerabilities with LLMs), but large sections veer into tangential discussion (Australian accents, personal anecdotes about MVP friends, Grok memes) that dilute insight density. For a technical audience, this reads more like a highlight reel than a deep-dive.

There is an attack against symmetric algorithms called Grover's attack, but it's not as serious as the attacks against asymmetric algorithms.
harvest now, decrypt later. So you may actually have your data harvested and not even realize it. And then if it's super sensitive stuff, then the bad guys will then decrypt it later on.

Originality

10 / 20

The episode recycles well-known industry frameworks and themes without significant pushback or contrarian insight. The 'left of bang / right of bang' framework is presented as novel but is now mainstream security vernacular. Discussions of AI security, supply chain risks (via third-party integrations), and zero-trust principles repeat established positions. The most original observation - comparing LLM performance on JWT vulnerability detection versus static analysis - is underdeveloped and used primarily as a personal anecdote rather than explored as a broader insight. No genuinely counterintuitive claims emerge.

bang being an incident or breach or an attack actually happening. Left of bang is all the stuff you do ahead of time to try and prevent that and block it from happening.
As a longtime security person, you always notice is like, hey, a new thing came out. Did you secure it?

Guest Caliber

11 / 20

The three hosts (Michael, Sarah, and Mark) appear to be Microsoft security practitioners with domain credibility - Sarah attended Ignite in person, the hosts reference hands-on experience with tools and research. However, the episode is primarily a self-contained roundtable among internal Microsoft voices, not interviews with external practitioners, vendors, or customers implementing these features at scale. There are no external guests or varied perspectives from different organizations facing these problems. This limits the episode's ability to validate claims against real-world deployment challenges.

Yes, I was there.
I've actually been following that for a couple of years. And I've been really excited about this technology

Specificity & Evidence

11 / 20

The episode names specific Microsoft products and features (.NET 10, Windows 11, Entra, Defender, Purview, Agent 365, Security Copilot E5 inclusion) and occasionally references concrete technical mechanisms (TLS-based DNS validation, hardware key storage, digital signature enforcement). However, specificity is thin on metrics and outcomes. No data on adoption rates, performance improvements from BitLocker acceleration, or concrete evidence of LLM superiority for JWT detection beyond anecdote. The passkey sync feature is mentioned but not quantified. The third-party integration extensions (AWS, Proof Point, Okta) are named but not detailed.

post-quantum crypto, if you're not aware, is basically when quantum computers become mainstream. they're going to break a lot of the asymmetric algorithms. So RSA, elliptic curve, Diffie-Hellman, they're all going to get completely broken.
hardware accelerated BitLocker in Windows. We'll start to see this early next year.

Conversational Craft

9 / 20

The hosts demonstrate camaraderie and domain knowledge, but questioning is soft and rarely pushes back on claims. When topics are introduced, follow-ups tend to affirm rather than challenge. Mark's correction from 'Agent 360' to 'Agent 365' is treated as a light correction rather than an opportunity to verify. The long tangent about Australian vs. New Zealand accents (fish and chips / flush and chips) and stories about MVP friends and Grok images are padding that consume real estate without advancing inquiry. There are no moments of productive disagreement or skeptical probing of whether these features will actually solve stated problems.

So you actually slipped in heaps on purpose?
Mark, I actually had a conversation with a lot of folks about that topic.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

security37windows19agent16different15agents14microsoft12bang11secure10quantum10code10technology10first9prompt9part8cool8deterministic8

Episode notes

In this episode Michael, Sarah and Mark discuss security-related topics from the recent Microsoft Ignite 2025 event. Lots of AI-related security topics, including using AI for security and defending AI systems. Bitlocker, Windows and so much more! This is the last episode of 2025! It was a blast, and thanks for listening! We hope you find this material useful! @AzureSecPod See you in 2026!

Full transcript

33 min

Transcribed and scored by The B2B Podcast Index.

Welcome to the Azure Security Podcast, where we discuss topics relating to security, privacy, reliability, and compliance on the Microsoft Cloud Platform. Hey everybody, welcome to episode 122. This week is myself, Michael, with Sarah and Mark. And in this episode, we actually have no news whatsoever, because we're going to talk about the Microsoft Ignite conference that was just a couple of weeks ago, and some other things that sort of took our interest.

So Sarah, you were actually there. So why don't you give us a lowdown on what you saw? Okay. Yes, I was there.

And if any of you watch the live stream, you might have seen me look far more glamorous than I usually do day to day because I have professional help. And I was there. It was in San Francisco. It was at the Moscone Center.

It was about 20 ,000 people, I believe, in person. So pretty big. It certainly felt big to me. And it was, as usual, it's sort of Tuesday to...

friday midday the week before thanksgiving and there were a ton of announcements and you know there's keynotes breakouts uh then we have the big expo hall and there's labs and kind of everything if anyone's ever been to an ignite i guess you you know what to expect uh but it was it was good uh very busy i needed to sleep a lot afterwards And I'm going to have to quote you, Sarah, on this one, because I remember one of the opening lines that you made during the sort of interview segments was, there's heaps of security news.

I use that on purpose. I mean, heaps is a very Aussie, Kiwi thing to say, rather than lots. I can't remember what the original word was in the script I've been given. We are allowed to change it a little bit.

So you actually slipped in heaps on purpose? twice in like the first minute that's hilarious again that is like you say that's such an Australian and New Zealand thing to say I can't remember what the original word was but we are allowed we don't have to read it verbatim as long as everyone understands one of the funniest things I saw a presentation by Catherine Holdsworth who's from New Zealand and we've known each other for a long time and she was talking about butt locker Again, for anyone who doesn't know, here's how you tell an Australian accent from a New Zealand accent.

Get them to say fish and chips. And if it's flush and chips, then they're from New Zealand. And if it's fish and chips, then they're from Australia. There you go.

Now you know. This is correct. Thank you. Because people from New Zealand shift their vowels out by one.

Shuft their vowels. Shuft. Shuft, yeah. They shuft their vowels.

I think until you've - I know I couldn't tell the difference between Australian and Kiwi accents until I lived down here and listened to them all the time. But I definitely can now. There's also a chap - we digress massively. If you watch the keynote, there's a chap - called Scott Woodgate, who does some of the threat protection demos in the keynote at Ignite.

And he's also a Kiwi. And so you can listen to him talk with his vowel shift as well. Actually, it's funny you say that. I was watching the video.

I'm like, I know that guy. Then I heard him speaking. Oh, I do know that guy. Yeah.

Let's get back to what we're actually here for, which is talk about the Microsoft Unite book of news. So like any big conference at Microsoft, there's always a book of news that gets released. And Mark, we've all been going through it, but what were your first thoughts when you went through it? The themes that really jumped out for me is that, and this is really in the spirit of the SFI, the Secure Future Initiative from Microsoft to make sure everything's secure.

There's a whole lot of security in a lot of non -security products. And so I was just sort of struck by the number of different security sort of features and capabilities and reviews and whatnot that were part of all these non -security products. That was the first thing that jumped out at me. There's a lot of AI protections and making sure that as AI is integrated in all the different Microsoft products that there's prompt injection protections here and there and the security overlays and the intercepts, but also in the products themselves.

And of course, some dedicated features around security, quite a few. we'll cover. And then the big one that I picked up on that was just a really nice kind of feature set or a bunch of things was the Agent 360, I believe it's called, which is really kind of that security lifecycle being applied to the posture side as well as the threat protection side, kind of left of bang, right of bang, for the lifecycle of agents and, of course, managing the identity of it, et cetera. So I think it's primarily like an identity feature.

but then making sure that over the lifecycle of the agent that we're able to do all that stuff. And I think I might have stolen some from Sarah's thunder based on that reaction. What do you mean by left of bang, right of bang? Oh, so that's an expression I use to describe the security lifecycle.

Bang being an incident or breach or an attack actually happening. Left of bang is all the stuff you do ahead of time to try and prevent that and block it from happening. Sometimes, you know, called posture management. And then right of bang is, you know, what do you do when the bad stuff happens?

And how do you handle it? And, you know, sort of detection being the turning point between them and that your spawn recover. And the NIST cybersecurity framework terminology is your security operations or SOC. And then the identify, prevent, and detect, the first part of detect, setting them up in the first place, is left of bang.

So it's a markism, it's not a nistism? It's becoming a more -ism. It's in some of the open group work and some of the Microsoft stuff. And it's a really good, simple way to explain stuff because it's the same as any other risk, right?

You want to keep the bad stuff from happening and you want to deal with the bad stuff when it happens. And it just tends to break it down in a proactive versus reactive way. And if you don't invest in both, well, you're either unprepared for the bad stuff or you're dealing with a bunch of bad stuff you could have prevented. So, Mark, I'm going to, first of all, it's Agent 365.

Oh, I'm sorry. I was five short. My bad. It's Agent 365.

But you're right. I was going to talk about it. But I think there's lots to say about it because, you know what, based on my chats with people when I was at Ignite, and obviously this is entirely non -scientific. The Agent 365 was the thing that a lot of people were talking about.

So if you didn't see it, it's very cool. It's very visual. Officially, we're calling it a IT admin tool, but I believe that it will end up being used much more widely than that by a lot of different... types of people in different roles because it visualizes how will your agents talk to each other.

It also sucks up signals from Entra, Defender, Purview. So you can have a look at what data sources it's talking to. You can have a look at the risks and the compliance piece all in one portal. So it isn't an officially in a security tool, but I foresee it being.

used a lot as one when it comes out properly. I believe it's in private preview at the moment, so it's a bit limited, but I can't believe that lots of people won't use it. That's my gut feel. Yeah, even if it's not a security tool, it's definitely welcome to the security table at Thanksgiving.

Well, sorry, that's a US reference. It's welcome to family dinner. Yeah, I think a lot of people will use it for a variety of different things. Yeah.

So, hey, Michael, what about you? What did you see that was exciting? Yeah, well, let's sort of round robin this. There's a whole bunch of things that took my fancy, but the first one, which should be of absolutely no surprise to absolutely nobody whatsoever, is we have now GA'd post -quantum cryptography APIs in Windows, and they're also now surfaced actually in .

NET 10. So post -quantum crypto, if you're not aware, is basically when quantum computers become mainstream. they're going to break a lot of the asymmetric algorithms. So RSA, elliptic curve, Diffie -Hellman, they're all going to get completely broken.

There is an attack against symmetric algorithms called Grover's attack, but it's not as serious as the attacks against asymmetric algorithms. For those who want to know, basically the reason why is because quantum computers are very good at breaking algorithms, whereas symmetric stuff like AES and SHA -256 and so on, they're all just bit twiddling. you know, shifting, exclusive warring, bitmasking, all that sort of stuff. So it's not like an algorithm per se, whereas the algorithmic side of things, quantum computers are very good at breaking that.

So basically RSA, elliptic curve, Diffie -Hellman, they're all going to get completely busted wide open when quantum computers come online. And the real attack that's going on now is a thing called harvest now, decrypt later. So you may actually have your data harvested and not even realize it. And then if it's super sensitive stuff, then the bad guys will then decrypt it later on.

And it may still hold some value, even though it may be 10 years from now. So really people should start moving across to these post -quantum crypto algorithms, especially with things like key wrapping. So they're available now in GA, on Windows and in .NET 10.

And it's an evolving area. Things will change, but these algorithms that we have in there have been pretty much solidified. The thing that sort of is a precursor to all of this, though, is if you are looking at post -quantum crypto, which you should, you really need to consider crypto agility. Like if you're not building cryptographic solutions with agility in mind, be in a world of hurt when these post -quantum crypto algorithms are sort of forced upon you.

So if you're not familiar with crypto agility, go and look it up, read a few things about it. There's a couple of books I know of that explain it pretty well, but it's a big deal. So that's my first one that I had, post -quantum crypto. Huge, huge.

Nice to see that it's in GA in Windows and .NET 10. The other thing that was... Quite interesting was, well, quite interesting and necessary.

So many purview announcements. I don't know. I don't even know. There's just so much more.

We're really building out the data security piece for obvious reasons because of AI. I'm just going to, I won't even dig into them in any specific detail because you can go and read up about them. But just there is more. There is way more controls for data.

Purview is getting, there are some blades that are getting completely revamped. And the whole idea is that we're making it easier and easier and easier for folks to be able to get control of their data. particularly now, you know, everyone's using AI and agents. I mean, a big theme that came through, and again, if you watch the keynote, you'll see it, is this observability piece.

And I think we're going to hear the word observability a lot more. Now, in terms of security, of course, we've cared about observability and security for a long time. But this whole observability concept that I think you'll hear a lot about from Microsoft going forward is Not just security, right? It's wider than that, although security is a big piece of it.

So, yeah, that's the other thing that I think is interesting. Plus, we announced, well, it was already announced, it was announced a build, but now it's actually... you can go and use it, at least in preview, is Agent ID. So Agent ID is actually a completely separate, it's part of Entra, but it's a completely separate store and it stores other bits of information about the agent, like the metadata, et cetera.

If you create a first -party agent, it's just going to be in there straight away. And you'll be able to onboard third -party agents into it. And if you can, if you do, then you get that full observability piece. And Agent Idea will be using the A2A protocol to go and discover agents in your environment.

So again, this is a security thing, absolutely. But I think it'll be wider than that to make sure everybody knows where these agents are, what they're doing, blah, blah. And I think we'll see more and more on that. That was kind of a rambling update that went through identity and purview, but I think it's two themes that are pretty important that we'll just hear more about.

Actually, I want to kind of just riff off that because it's actually a comment that I want to make is one thing that we're doing in Windows is working on isolation for agents as well. And I think that's incredibly important, right? Because if you essentially don't, let's just, don't read too much into what I say next, which is, you know, Let's just say you don't want to trust the AI agent for whatever reason. You need to really isolate that.

And a big part of the Secure Future Initiative actually is isolation. And so if you can isolate code that's running on Windows, agent code that's running on Windows, in case it decides to go running away from you. You can, you know, contain the damage. So there's actually a lot of work going on in that area right now.

We've actually blogged about it a little bit. It's still relatively early in the works, but I've been doing a lot of research into it, you know, as an old Windows guy, both literally and figuratively. especially Windows security, that's something of great interest to me. So it's good to see that work going on too, is recognizing that we need to isolate this code, not just say, hey, that's like a security agent.

We need to isolate it to any agent, not just security -related agents. And one of the things that I picked up on... that was, I'm not sure if it's actually in the book, I was kind of looking for it, but it was announced at the same time, was that Security Copilot is actually going to be included as part of the E5 license, which I know a lot of enterprise organizations have. And so it's going to be a gradual rollout that's already started.

But I thought this was pretty cool because it allows a lot more folks to have access to use this AI technology to benefit security. Because you need to secure the AI. you're using, but AI is actually a technology you can use for security also. And so I thought that was really cool and I'm really looking forward to that.

I also did notice there's a bunch more agents as well that were announced for all sorts of different products, you know, across Intune and Defender and Purview and whatnot. So that was also kind of similar to that. Yeah, Mark, I actually had a conversation with a lot of folks about that topic. I know many people are pretty excited to have security co -pilot SCUs included in E5 so they can go and experiment with security co -pilot and see what they can do with it without having to commit to buying something.

So I think that's a big one for sure. On a totally different topic, next item that really took my fancy was hardware accelerated BitLocker in Windows. We'll start to see this early next year. Makes absolute sense to have hardware acceleration.

People just think it's just acceleration, and that's true. I mean, acceleration is obviously a big deal. Anything that can speed up disk IO is always a good thing. But there's more to it than that.

And the big one is the fact that the keys are right there. They're in hardware. That's really cool because that way they're never outside in normal memory. They're maintained within the hardware, so that's really good to see as well.

So yeah, there'll be some new systems on the chip coming out early next year, especially on laptops, and this will be great to see. Again, just removing that one little barrier that some people have against the potential performance impact of... full -volume disk encryption. So another thing that caught my eye, and I'm always a big fan of the...

everybody runs a bunch of different technology, not just Microsoft technology. And so I really love it to see like when there's a integrations, like the third party, the attack disruption capability, the feature that is part of the sort of defender Sentinel capability. And that it was extended to, you know, stuff from AWS proof point and Okta. And so that was pretty cool.

It's sort of a, if I recall correctly, this capability is sort of, it's sort of like a, And kind of using that right of bang, left of bang analogy from earlier, it's sort of like after you see something going on, it can actually do some stuff that kind of edge you a little bit to the left of bang to sort of block what's going on and contain the attack. And so seeing that go beyond just the Microsoft data sets into additional third parties is pretty cool. Our next one is Zero Trust DNS.

This is a new update to the DNS client in Windows. So without going into all the horrible icky details, because it's actually pretty technical, when I was reading through the description of this, being on the red team, what's interesting about it is it basically blocks DNS. which means that names don't resolve and IP addresses don't resolve unless they are actually validated by specific DNS servers, for example, over TLS and so on. So it's a whole sort of privileged DNS infrastructure.

The nice thing about that is if you have some malware on the box that tries to open up a command and control back channel, it doesn't work. So this is fantastic to see. And it's all sort of in compliance with some of the NIST standards around zero trust. So always good to see.

Yeah, I've actually been following that for a couple of years. And I've been really excited about this technology because a lot of times the attackers just say, oh, I'm going to get lazy and just do a C2 and it keeps me to an IP address and it keeps me stealthy and whatnot. But this basically forces them to get into the real world resolvable DNS world. And so it forces them to be a lot more visible.

And so they don't get to hide in the shadows of just IP to IP stuff. They actually do have to show up in a registry. Otherwise, we're not talking to you. All right, I got another one.

Passkey sync. For those of you not familiar with Passkey, basically passwords are dead. You shouldn't be using passwords at all. I mean, we've known that for, you know, who knows how long.

Passwords are just such a weak link. They're convenient, but they're just lousy. So Passkey seems to be the sort of... de facto standard around credentials.

It's a public -private key pair. They're phishing resistant. They're bound to hardware and that sort of stuff. The problem is it can be sometimes hard to get them to roam across different devices.

Well, now we have that support built into Windows 11. And you can actually also choose your passkey manager in Windows 11 too. And Windows Hello can be one of those pass... passkey managers if you want so this really helps you know if you're using a windows laptop with windows hello it really helps to sort of smooth out and make it really easy to handle handle passkeys really good to see i'm a big fan of passkeys you know multi -factor authentication is one thing but passkeys just take it to the next level So another one that caught my eye, and this kind of fits the theme of just AI and security showing up in all sorts of places, is the Microsoft Internet Access has some prompt injection protections that essentially allow it to work across pretty much all the generative AI apps, whether sanctions, unsanctioned custom, et cetera.

And then in looking deeper at the network traffic as well to look for unsanctioned AI usage. So really kind of just applying that policy. over sort of otherwise uncontrolled, unmanaged types of connections. That's an important point.

I was actually going to talk about that too, but I'm actually glad you did. It's really cool to see policy around, enforceable policy around how AI operates in the environment being rolled out into our products. It sort of feels a little bit like the wild, wild west right now with agents and MCP and so on. We're already seeing rogue MCP agents.

Surprise, surprise. So yeah, it's really good to see policy rolling out around what agents can be used and that sort of stuff. So that's really great to see. And in fact, if I look at some of this work that's going on right now in Windows, without talking about...

Without going into all the details about the isolation, a big part of it is only allowing digitally signed agents to operate, which is great. I love that. I'm a big fan of digital signatures on absolutely everything because you can really control what can run rather than running just rogue software. Yeah, and one of the themes, as a longtime security person, you always notice is like, hey, a new thing came out.

Did you secure it? I don't know, right? And the thing that I like about this generation of technology, essentially the apps and the agents for AI, is the technology to secure the new technology is actually coming out. at a pretty good clip.

So as AI is coming out, of course, in the beginning, it almost always starts with, here's a great capability, and there's a limited amount of ability to secure it. But just the sheer comprehensiveness and the thoughtfulness of how it's integrated. Just the ability to secure this generation is happening a lot faster than previous generations of apps in terms of you look at cloud or enterprise or whatever before that. It feels like it's much more rich, more thoughtful types of controls that are available to secure this generation of technology.

Perhaps I'm more cynical than you are. I don't disagree with you. I mean, it's also really hard technology to secure, to be fair, right? Because the non -deterministic thing of like, let's ask it a question and let's see how many answers we can get from the same question.

That's why I said before, I'm not saying you don't trust the agent, but you can't really trust the agent, right? Because it's non -deterministic. And that's why you've got to isolate it. Well, I think trust is too binary in terms of it is or it isn't.

It's not a black and white question. It's how do you scope it? The biggest thing I've seen is a lot of the bad habits we've sort of accrued through the deterministic era, we're going to have to deal with. If you don't document your code in a deterministic thing, yeah, you can reverse engineer it, even if someone didn't document it or didn't write the design down or whatever.

But when it's non -deterministic, asking the question of what is this actually supposed to do becomes a lot harder without documentation. And so I just think it's really interesting that we're having to go back to basics again, but just in a new way. Because if you don't scope this thing and constrain it and say it should do this, well, let's make sure it can only do that. I feel like there's definitely some new challenges on this.

I'm not doubting that. I'm just saying at least we have tech to work with. Yeah, another aspect of that is the fact that we're kind of model agnostic. I don't know if that's the official line we use.

I don't know. I'm just looking at it from a lay perspective. But, you know, we can use different LLMs for different jobs and we can route the prompt to the appropriate LLM at the back end. The reason why I'm saying this is you can get better quality results from different types of LLMs for specific tasks.

And I like that. I like the fact that we'll choose a better LLM based on what you're doing. So for example, just recently I've been using different... Like Gemini 3, I've been using Claude 4 .

5, I think, for AI work. And it seems to work very, very well compared to other LLMs. Now, I'm not saying that that is our official stance on anything. That's just my personal experience in Visual Studio Code where I can select the LLM that I want.

And again, I found that from a security perspective, I've been doing quite a bit of experimentation around how can GitHub co -pilot do a code review, a security code review, and how good is that code review based on the backend LLM. And again, because we're agnostic, I can choose the LLM that I want. I found that things like Claude are actually very good at doing security code reviews. In fact, there was a class of vulnerabilities, and this is something that does terrify me, to be honest with you, is JOT token parsing, JWT parsing issues.

And we found actually that, static analysis is actually not very good at it, but LLMs are actually very, well, they're better than static analysis tools at doing it. And as long as you have the correct prompt or a good prompt, you can actually find these issues in code. So again, because we're... essentially LLM agnostic, we can choose the best LLM for the task.

Again, I've found that certain LLMs are better at finding these class of vulnerabilities than other LLMs. The reason why I'm talking about this, it sounds like I'm being completely random. I'm actually really not. It was the fact that you just said the word non -deterministic.

Yes, LLMs are non -deterministic, at least today they are, but you can also choose a better LLM for the task that you want to actually perform. Even though it's non -deterministic, it may give you... better results than something that's not really tuned for that kind of workload. Does that make sense?

Or did I just ramble? Absolutely. At the end of the day, there's a lot on the AI stuff. I've been spending a lot of time on it lately.

But I think the models themselves are going to become more specialized. Because a general purpose model will get you a certain amount of things. But I think as the application architectures evolve, you're going to need something that does a particular task well. you don't necessarily need a model that also knows how to give you, you know, knows how to play chess and knows how to, you know, recommend tourist spots in Rome or whatever it is, right?

Like you're going to want something that is focused on a particular task. It understands the language and the task. But, you know, I feel like we're going to end up having to sort of evolve that architecture from a, I'm going to ask one thing of one general purpose model and hope. and some of them are biased in different directions, but I think we're going to start to see more specific models that are focused on other things, or at least that's my hope.

Like sort of, I think they were called SLMs at one point. Yeah, small language models. Yeah, I just feel like, you know, there's a certain... Because you have to constrain it to do the only thing you want to do and not the other things.

It's like an intern that won't pay attention to instructions sometimes. How do you keep them focused on the task at hand? I often quibble about this, but if I'm asking an LLM about Rust, I can guarantee it's not about iron oxide. It's not about the video game.

It's not about the movie. It's about a programming language. I don't want you to give me stuff about the atomic composition of, iron oxide i don't really care um but i do want to know you know how to solve specific problems in the programming language that we call rust yeah and you're going to get some of that through you know it knows you and it has a profile on you and it has your history and whatever and then there's a certain amount that like hey if this is like super sensitive we want this thing to do like you know mental health recommendations or whatever you know for your application then you may want to have something that's tuned in a very, very different way or just simply doesn't have access to certain things.

And so I just feel like there's more to evolve in that space. It's funny you should bring that up. Have you ever seen that thing that's on X, on Grok, where you can actually say, do an image of me based on my tweets? I've heard about it.

I haven't heard of that. And it's hilarious. For me, it came back with a guy in scuba gear and a laptop with some locks on the table or something. It was hilarious, yeah.

AI knows way too much about me. I know, yeah. It really does. Someone sent me a prompt, actually, when I was at Ignite.

An MVP friend sent me a prompt, and it was, I paraphrase, but it said, based on what you know about me, to put into co -pilot, based on what you know about me, act as my career coach and tell me where I'm good, where I'm bad. And it was pretty good, actually. It was the whole thing. And I was like, wow.

It told me that I broke my focus too much, responded to emails too quickly, et cetera, and it might affect my focus and I should be aware of it, et cetera, et cetera. There were quite a few of them, but it was interesting. That sounds accurate, though. Oh, yeah, it does.

I mean, I was like, yeah, you're not inaccurate. It's an interesting prompt. Maybe I'll put the prompt in the show notes if you want to use it for yourself. All right, I have one more news item that took my fancy.

I'm very happy to see this. The Windows Endpoint Security Platform API is now available in preview to our Microsoft Virus Initiative partners. This is huge because this API is a user mode set of APIs. And the whole point is we want to try and pull as much out of the kernel.

The kernel in Windows is just getting too big, and we're loading too many third -party components into the kernel. Not to cast any dispersions on that, but... You really want the kernel to be as small as possible. I think we all know what the trigger was to this.

We've known this was a problem that could happen, and it did happen when there was an update from a large, well -known company that went out and shut down thousands of Windows machines, just blue -screened them. This is really, really cool. Now we're opening up this API. for anti -malware vendors so they can call into this API and then provide their own value add on top.

And that way it's actually in user mode and not down in the kernel. Really great. Bring a lot more stability and reliability and resilience to the OS, which is always a good thing. Kind of it.

Well, for this year, right, guys? I just want to back up just a minute. It is it in terms of this year, but I just want to point something else out. The items that the three of us brought up from the Book of News are just some items, right?

There's so much more in there around security. These are just the ones that, A, took our fancy, and B, we could squeeze in in 30 minutes. Yeah, so definitely go check out the Book of News. And of course, you can also, if you want to actually watch the...

If you want to watch the sessions, most of them are recorded. They're now on YouTube or they're on the Ignite website. So you can go and actually watch any of them if they take your fancy. Obviously, we'll see you in the new year.

Some of you might have noticed this year, we probably haven't managed to get out two episodes a month quite as consistently as we have before. That's just because... We live and breathe this stuff and we do do it on the side of our jobs. We try our best.

So apologies that we might not have quite hit that as well this year as in previous years. We try our best, but it isn't our day jobs. And that's an important point. I mean, all of us love this topic so much, the area of cybersecurity so much.

And it's our day jobs, right? That's what we do. This is something that we don't do as part of our day jobs. We do it after hours.

But with that said, we will never, at least never knowingly, sacrifice quality over quantity. Like we don't want to just get an episode out just to, hey, we've got to make two weeks. Let's just, you know, pump out some junk. We don't want to do that.

So we'll always try to keep the quality as good as possible. All right. So let's bring this episode to an end. As Sarah said, this is going to be our last for 2025.

We'll see you guys in the new year. There's always a lot to talk about. We thoroughly enjoy doing this podcast. It really is a labor of love, but we do enjoy doing it.

So with that, stay safe and we'll see you in 2026. for listening to the Azure Security Podcast. You can find show notes and other resources at our website, azsecuritypodcast .net.

If you have any questions, please find us on Twitter at AzureSecPod. Background music is from ccmixter .com and licensed under the Creative Commons license.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Evolution vs Revolution: how is AI changing legal practice and legal education?Future Ready Lawyer · features Mark74 / 100
  • How We Scale YouTube Ads to $500K/Month (Without Getting Crushed by Compliance)The Scaling Lab · features Mark69 / 100
  • From Complexity to ClarityMegadeals Podcast · features Sarah66 / 100
  • New Strategies for Achieving a Billion Dollars in SalesRemarkable Marketing Podcast · features Mark65 / 100
  • Best of CoCreate 2025: Words of Wisdom from Lori Greiner, Simu Liu, and More!B2B Breakthrough Podcast · features Sarah61 / 100
  • #91: The Elephant in the Room: Institutional Resilience & Quiet CrackingStepsero · features Mark57 / 100

More from The Azure Security Podcast

All episodes →
  • Episode 129: John Savill's Top of Mind67 / 100
  • Episode 128: Post Quantum Cryptography87 / 100
  • Episode 127: Threat intel update and AI87 / 100
  • Episode 126: Microsoft Baseline Security Mode80 / 100
  • Episode 125: Origins of MITRE ATT&CK84 / 100
Explore the best B2B Engineering & DevTools podcasts →
All The Azure Security Podcast episodes →