Things from Me
Happy Friday everyone! Just a Quick NOTE about the newsletter delivery next week!
I’ll be delivering two technical sessions with my co-speaker Sergey Chubarov (Microsoft MVP and Cloud Security Architect) next week at MMS at MOA.
THE PROMPT for Microsoft Security is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.
Due to all the community busyness of the week, this newsletter will not deliver next week. However, as a consolation prize, all slide decks, demo scripts, narrated walkthrough videos, and supporting materials are in the GitHub repo: https://github.com/rod-trent/MMSMOA.
Session 1: 🛡️ Agentic Threat Hunting with Microsoft Sentinel: From MCP Server to Graph Insights
We’ll dive into building a modern threat-hunting strategy that combines the Model Context Protocol (MCP) Server for natural-language analysis with powerful graph-driven investigations in Microsoft Sentinel. You’ll see how to turn KQL queries into reusable MCP tools, integrate with Copilot or custom agents, leverage entity relationships and UEBA, and walk through realistic incident scenarios.
Key takeaways:
• Operationalizing agentic hunting and Copilot integration
• Moving from tables to graphs (Account ↔ Device ↔ IP ↔ App) for faster triage
• Ingestion pipelines, ASIM normalization, enrichment, cost control, and rollout checklists
Demos include building an MCP server, running natural-language hunts, and full graph investigations with ready-to-use Python scripts.
Session 2: 🔒 Governing GenAI: Monitoring and Securing Copilot with Microsoft Purview
This session focuses on the security and compliance challenges of Microsoft 365 Copilot and GenAI. We’ll use Microsoft Purview as the central control plane, mapping real risks (sensitive prompts, data exfiltration, insider threats) to practical controls like sensitivity labels, DLP, Insider Risk, Audit, and eDiscovery.
Key takeaways:
• A clear blueprint linking GenAI risks to Purview capabilities
• Building strong monitoring views with Audit logs
• Policy patterns and a phased rollout plan (including simulation mode and metrics)
Demos feature PowerShell scripts for creating Copilot-aware labels, deploying DLP policies, analyzing audit logs, and testing enforcement — all starting safely in simulation mode.
Both slide decks (44 and 49 slides) have embedded videos, and every demo folder includes full MP4 walkthroughs.
I’ll also be on-hand throughout the event for lively discussions around the MVP program and the Security Advisors program at Microsoft. Come find me if you want to chat about community contributions, security best practices, or anything in the Microsoft ecosystem.
The event runs May 3–7, 2026, at the Radisson Blu in Bloomington, MN (right by the Mall of America). Looking forward to seeing you there and having great conversations!
Materials are all here: github.com/rod-trent/MMSMOA. Let’s make it a great week! 🚀
…
Talk soon!
-Rod
Things that are Related
Log Sources Your SOC Needs for Detection, Forensics, and Hunting- MUST-HAVE - This article covers the 20 log sources that form the core of your detection architecture — 14 must-have and 6 should-have. These are the sources that cover the attack chains that matter most: credential theft, BEC, ransomware lateral movement, privileged access abuse, and AI agent threats.
Securing Your AI Agents Before They Ship: Red Teaming with Microsoft PyRIT - As AI engineers, we’re shipping agents that reason, call tools, and act on behalf of users — but most of us haven’t security-tested them. Microsoft’s PyRIT framework gives you 53+ adversarial datasets, 70+ prompt converters, and 6 attack strategies out of the box. But PyRIT is a toolkit — it gives you the building blocks, not the pipeline. In this post, I walk through how to wrap PyRIT into a config-driven scanner with OWASP mapping, release gating, and CI/CD integration — so your team can start red-teaming AI agents in an afternoon, not weeks.
Enterprise Security Assessment: A Strategic Lens for Mission Critical Environments - Understanding security posture at scale requires more than isolated control reviews or point‑in‑time assessments. The Enterprise Security Assessment (ESA) helps organizations understand their security posture across Azure, Microsoft 365, and hybrid environments from a true enterprise perspective. Instead of assessing individual services or workloads in isolation, ESA provides a single, enterprise‑wide view of security.
IRQL: Incident Response Query Language - I’m excited to share IRQL — a collection of Kusto functions designed to abstract away the chaos of disparate security logs and deliver a clean, intention-revealing query experience. Created by Saar Ron, John Lambert, and Diana Damenova, IRQL turns verbose, brittle KQL walls-of-text into readable, reusable pipelines that both humans and LLMs can understand and compose effectively.
Microsoft Sentinel Things
Sentinel Playbook Manager - If you have ever tried to move a Microsoft Sentinel playbook from one tenant to another or from the portal into a Git repository you will know the pain. The out-of-the-box "Export Template" button gives you something almost useful: a JSON file stuffed with hardcoded subscription IDs, tenant IDs, resource group names, a region buried in every API path, connector names with designer suffixes like azuresentinel-3, and a $connections block that the ARM deployment engine is unhappy with.
Seven Queries to Audit the Sentinel Detections Your SOC May Have Missed. - Every Sentinel workspace I’ve worked with has rules that nobody remembers setting up. Sometimes just a few, sometimes a lot. They might have come from a content hub solution years ago, copied from a template during testing or created by someone who’s no longer around. They keep running, use up compute and no one checks what they produce.
Simplifying AWS defense with Microsoft Sentinel UEBA - With the expansion of Microsoft Sentinel UEBA (User and Entity Behavior Analytics) into new data sources, spanning multi-cloud (AWS, GCP), identity providers (Okta), and authentication logs (MDE DeviceLogon, Microsoft Entra ID Managed Identity, Service Principal sign-ins), defenders can now detect behavioral anomalies across hybrid environments from a single place.
Sentinel-As-Code: Wave 2 - Wave 1 was solid, but it had gaps. Wave 2 closes them and ships a lot more. The release adds a more robust framework, a substantially larger content library, and a set of operational capabilities that did not exist in Wave 1: a watchlist-driven DCR billing sync, a 111-rule community contribution from David Alonso, a daily drift detector that auto-PRs portal edits back into the repo, 28 new Defender XDR detections, a major playbook catalogue reshuffle, a Pester test suite for the drift functions, and a documentation reorganization.
Defending the AI Layer using Microsoft Sentinel’s Copilot Detection Use Cases - Every SOC has hardened its endpoints, tuned its identity detections, and mapped its network traffic. But there’s a new attack surface that most security teams are still figuring out how to monitor i.e. the AI layer. Microsoft Copilot is now embedded across Microsoft 365, Azure, and enterprise workflows. Users interact with it daily, prompting it, installing plugins, and in some cases, trying to misuse it.
Use Data Wrangler to Streamline Your Microsoft Sentinel data lake Notebook Development - As you create a Sentinel data lake notebook, sometimes you need to explore the data and refine it before moving to your next cell. Using the Data Wrangler extension in Visual Studio Code can help you visualize and shape your DataFrames more efficiently.
What’s new in Microsoft Sentinel: April 2026 - Welcome to the April 2026 edition of What's new in Microsoft Sentinel. April brings a broad set of updates, with RSAC 2026 announcements rolling out alongside new features. Highlights include cost limit enforcement to prevent runaway query costs, curated open-source intelligence in Threat Analytics, and new data connectors for CrowdStrike, Imperva, AWS, and Logstash. Together, these innovations help security teams control costs, stay ahead of emerging threats, and broaden visibility without added complexity.
Defender for Endpoint Things
Assess Secure Boot status with Microsoft Defender - Enterprise organizations are approaching a critical security milestone: Windows Secure Boot 2011 certificates, currently deployed across millions of devices, are scheduled to expire in June 2026. These certificates need to be replaced by the newer 2023 certificates. To help organizations prepare, Microsoft Defender is introducing a new tool that provides centralized visibility into Secure Boot 2023 certificate readiness across your device fleet.
Defender XDR Things
Microsoft Defender: New Advanced hunting enhancements - As a security analyst who actively hunts for critical threats, one of the most frustrating things that can happen is hitting a limit mid-query or encounter an experience that doesn’t behave as expected. The resulting friction and time spent troubleshooting or navigating takes valuable focus away from the investigation itself. To address this, we’ve made several enhancements across the experience to ensure investigations can scale seamlessly so analysts can stay focused on finding and stopping threats without interruption. These updates are based on your feedback and our commitment to continually improve the experience for analysts and customers alike.
Update to Microsoft SigninLogs - Understanding how applications authenticate is critical for securing identities, enforcing Conditional Access, and planning modernization. Previously, sign‑in logs have provided limited visibility into which authentication protocols and flows were actually used during authentication, often showing the protocol value as None.
Defender Experts Things
EDR coexistence by design: A practical starting point to Defender - Increasingly, organizations are finding that coexistence can deliver meaningful security outcomes. In addition, when designed with purpose, coexistence allows teams to being realizing the value of their existing Microsoft licensing, strengthen detection and response, and build confidence in Defender under real-world operating conditions.
Defender for Identity Things
We’re excited to share new Unified Identity Inventory (UII) capabilities, including the ability to define identity correlation rules that enable correlation at scale and extend coverage to SaaS and cloud identities. These enhancements provide broader identity visibility and deeper analysis across modern environments.
Enable Identity inventory integration - Microsoft Defender for Cloud Apps | Microsoft Learn
View the Identity inventory - Microsoft Defender for Identity | Microsoft Learn
Create custom account correlation rules (Preview) | Microsoft Learn
Defender for Office Things
Granular email content access with unified RBAC – now the default for new Defender tenants - Email investigations are a key part of detecting and responding to phishing and malware. As security workflows continue to evolve, there is an increasing need to align email content visibility more closely with specific roles and scenarios, such as Tier‑1 analysis or specialized workflows like user‑reported phishing triage. Today we’re announcing additional “read-only” controls for more granular email access in Microsoft Defender and that starting on May 30th, 2026, unified RBAC will become the new default for permission modeling for new tenants.
Entra Things
You can’t govern what you can’t see: Closing the identity visibility gap for apps - Most organizations inherit thousands of ungoverned application accounts. Account discovery helps you find them and bring them under control.
THE PROMPT for Microsoft Security is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.



