THE PROMPT for Microsoft Security - Issue #78
Renewed MVPs: Still smarter than most AI agents (and twice as helpful)
Things from Me
Happy Friday everyone!
Welcome to Rod’s Blog, the new home for the delivery of THE PROMPT for Microsoft Security newsletter – your weekly (or near-weekly) dose of focused Microsoft Security insights, practical guidance, and forward-looking analysis.
For years I’ve run several separate Substack publications to cover different angles of the Microsoft security ecosystem: deep dives on Defender, Purview, Sentinel, AI agents, KQL, zero-trust strategies, and more. While that structure served its purpose, it also created fragmentation for readers who just want the most relevant, high-signal content in one place.
So, I decided it was time to consolidate.
Rod’s Blog is now the central hub for THE PROMPT newsletter and all the related Microsoft Security content I produce. You’ll still get the same timely, actionable intelligence you’ve come to expect — whether it’s breaking down new Defender XDR capabilities, exploring real-world AI agent hardening techniques, sharing KQL query patterns that actually save time during investigations, or surfacing the latest Purview compliance advancements. The difference is everything lives together cleanly under one roof.
What to Expect Going Forward
THE PROMPT newsletter delivered directly to your inbox with the best of the week’s Microsoft Security developments.
Regular blog posts with deeper technical walkthroughs, architecture recommendations, and lessons learned from the field.
Quick-hit summaries, tool roundups, and practical tips that busy security professionals can put to use immediately.
Occasional guest perspectives and community spotlights from the Microsoft MVP and security community.
If you were subscribed to any of my previous Substack sites, you don’t need to do anything — your subscription will carry over seamlessly to this new location.
I’m excited about this next chapter. Consolidating allows me to focus more energy on quality and depth rather than juggling multiple platforms. Thanks for being part of the journey. Whether you’re a long-time reader or just joining us, I appreciate you stopping by.
Let’s get to work making Microsoft Security simpler, stronger, and more effective — one prompt at a time.
…
On Wednesday this week, the renewal notification emails went out to Microsoft MVPs who successfully completed the renewal process.
Many of us on the MVP team spent the last couple of months carefully reviewing each and every candidate — examining contributions, community impact, knowledge sharing, and ongoing engagement with Microsoft technologies. It’s a thorough, thoughtful process designed to recognize those who consistently deliver value to the broader technical community.
If you received that email, congratulations! Your hard work, expertise, and dedication have once again been recognized. Being a Microsoft MVP is more than a title — it’s a continued commitment to learning, sharing, and lifting others up in the ecosystem.
…
Speaking of MVP-related contributions. My good friend and renewed MVP, Alan Cox, just released a book on Mastering Microsoft Purview in an AI World. This is a super timely book and if you’re planning on deploying (or are already deploying) AI in your organization, this topic should be top of your list.
Book description: Microsoft Purview has quietly become the operating system for AI governance. It is where sensitivity labels protect a document long after Copilot has summarized it. It is where DSPM for AI surfaces every Copilot and third-party prompt your employees send. It is where Data Loss Prevention stops a payroll spreadsheet from being pasted into a chat agent. It is where Insider Risk Management flags an employee feeding sensitive data into a public large language model. And it is where eDiscovery and Audit hold a Copilot conversation to exactly the same evidentiary standard as an email. Every chapter in this book is framed against that AI throughline, and the chapters that are most directly about AI are flagged in the contents so you can find them at a glance.
Get it on Amazon: https://amzn.to/4wCP3qX
…
BIG NOTE: I am out of the office on vacation next week, in an effort to prepare for a very busy Black Hat, so this newsletter will not deliver for that week.
That’s it from me for this week.
Talk soon.
-Rod
Things that are Related
One Wrong Click by an Admin: Why Every Microsoft 365 Tenant Is Exposed, and Why Fixing It Is Easier Than You Think - The security industry has found its next product cycle, and it is “securing your AI.” You will be told you need an AI security posture platform, an AI firewall, an AI red team, before Copilot eats your company.
Things to Watch/Listen To
Things to Have
Kql Detection Of The Week: Nice Costume, Wrong Address - This week’s seven briefs produced 27 KQL candidates across a Vidar-plus-XMRig malvertising wave hiding behind a forged code-signing certificate and a 491 MB null-byte suit, device-code phishing that sails straight past URL filters, an SMB session quietly upgraded into Meterpreter, a Peyara Remote Mouse RCE, Armored Likho’s BusySnake Python stealer, a GigaWiper destructor cosplaying as ransomware, HTML phishing from first-time external senders, and a brand-new unauthenticated RCE in an AI agent framework where the whole exploit ships as a spreadsheet.
Microsoft Sentinel Things
Sentinel as Code Toolkit - The VS Code extension that used to be SentinelCodeGuard shipped its biggest release: coverage of every Sentinel content type, first-class Defender XDR authoring, and a connector catalogue rebuilt from Microsoft's own source data.
Building toward an Agentic SOC: A Portable, Autonomous Malware Investigation Agent - Modern Security Operations Centers are not short on tools. They are short on continuity. Analysts jump from alert consoles to data exploration, from enrichment to investigation, and from evidence gathering to response—often across multiple interfaces and disconnected workflows.
Announcing the ASIM Parser Creation Agentic Experience - Creating high-quality ASIM parsers has always required deep knowledge about source data and ASIM schemas, careful KQL design, and repeated validation cycles. That process is meaningful to understand the whole Sentinel ecosystem, but it can be slow when you are starting from raw source data and trying to get to a production-ready parser. Today, we are introducing a new agentic experience available now as open source that helps security teams move faster: an AI-guided workflow for creating ASIM parsers end to end.
You Assume Your Logs Are Flowing. - A detection that never fires looks exactly like a peaceful night. The only way to tell the difference between “nothing is wrong” and “we can no longer see” is to watch the four places where logs can quietly fail on their way into Sentinel.
Defender for Endpoint Things
Hunting Local AI Tools on macOS with Microsoft Defender for Endpoint - The power of Microsoft’s XDR platform provides the capability to look at our endpoint telemetry and gather data from your existing environment today…. MDE already captures enough process, file, and network telemetry to start hunting for this activity with Advanced Hunting KQL.
Microsoft Security Exposure Management Things
Getting Started with Codename MDASH - Microsoft Security Exposure Management - The docs for MDASH are now public.
Defender Experts Things
Turning threat intelligence into decisive action with Defender Experts - Security teams have never had more visibility, yet rarely have they felt more uncertain. Signal pours in from endpoints, identities, cloud workloads, and a sprawling mix of third-party tools. Dashboards are full, alerts keep coming, but the hardest question of the day remains unanswered: of everything happening right now, what actually matters to us, and what do we do about it?
Defender Threat Intelligence Things
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery - On July 14, 2026, Microsoft Threat Intelligence identified a coordinated supply chain compromise of the @asyncapi npm organization, a widely used set of packages for the AsyncAPI specification and code generation. Five package versions across four package names were republished within roughly ninety minutes, each carrying the same maliciously injected loader: @asyncapi/specs (in both the 6.11.2-alpha.1 prerelease and 6.11.2 stable release), @asyncapi/generator@3.3.1, @asyncapi/generator-components@0.7.1, and @asyncapi/generator-helpers@1.1.1.
Microsoft Entra Things
Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID - As identity attacks grow more sophisticated in the AI era, organizations need stronger authentication methods that protect users from phishing, credential theft, and social engineering. To address these evolving threats, Microsoft Entra ID is updating its authentication experience by making passkeys the default phishing-resistant authentication method, helping customers reduce reliance on phishable methods such as SMS and voice.
Least privilege for AI agents: Identity, access, and tool binding - AI agents aren’t only smarter API callers. They plan, chain actions across systems, and invoke tools in sequences while no single human explicitly approves each step. The architectural reality may introduce identity and authorization challenges that organizations are still evolving to address.





