Posted by: kurtsh | April 30, 2026

INFO: Group Membership Management (GMM) tool

Group Membership Management (GMM) is a service that dynamically manages the membership of AAD Groups. Groups managed by GMM can have their membership defined using existing AAD Groups and/or custom membership sources.

Organizations routinely use groups with large number of members for executive communications, company townhalls and other collaboration scenarios. Keeping the membership rosters of such groups current is critical to ensure the right audience is included. Stale rosters have consequences – imagine how a team that was recently moved into an organization feels when they are excluded from their VP’s townhall because the townhall community member roster was not updated?

Group owners spend countless hours, manually reconciling with spreadsheets or existing security groups to keeping the group membership accurate. It is much more efficient to have individuals maintain sub-group memberships (with <50 members) and automatically assemble the parent group roster as an aggregation of sub-groups.

We want to share with you a tool that we have developed and used at Microsoft which makes it easy to manage a large group roster by taking advantage of existing security groups and/or smaller groups kept up to date by teams within the larger org.

Introducing the GMM tool
This is a .NET service that generates a parent group membership roster by regularly synchronizing it with memberships from specified Security or Microsoft 365 groups. Deploying the tool requires experience in building, deploying, and managing Azure services. Group owners can then work with the admins to help manage the membership of their groups.

(The tool is being shared as an open-source project in the hopes of helping with similar opportunities in your organization. The solution is provided “as-is” and Microsoft is not providing additional support. Code contributions are not being accepted at this point, but there are plans to allow code contributions in the near future. The GMM Support team will be watching the forum and answering any questions you may have with the installation/set up or use of the tool.)

Accenture is leveraging Microsoft’s secure, governed & compliant Artificial Intelligence – Microosft 365 Copilot – for their entire workforce:

Deploying Microsoft 365 Copilot to 20,000 employees might sound like a big undertaking, but Accenture was just getting started.

The global professional services firm is rolling out Copilot across its workforce to around 743,000 people – the equivalent of a city roughly the size of Denver. It’s the largest enterprise Copilot deployment to date, according to Microsoft, and Accenture says it’s paying off.

Ninety-seven percent of employees reported completing routine tasks 15 times faster with Copilot and 53% reported significant improvements in productivity and efficiency, according to 2025 company data involving 200,000 users.

“Copilot is a personal digital colleague,” says Tony Leraris, Accenture’s chief information officer. “It changes the way our people work, the way they research, ideate, analyze and execute many daily activities.”

The scale of Accenture’s Copilot deployment is striking – as is how the company has approached it. Accenture moved intentionally, starting with a large group, then extending that deployment even wider. Every step of the way was an opportunity to learn, set guardrails and understand how Copilot was changing the way people worked before continuing further.

Read the full article here:

I was recently asked if Microsoft had training available for Executive Assistants/Administrators. 

————————————–
LIVE: Executive Office Team Experiences with Copilot and Agents
There is a one-hour, no-cost virtual event coming up on June 8th, 2026 specifically for the Executive Office team interested in harnessing the power of Microsoft 365 Copilot & Agents:

  • Monday, June 8, 8:00 AM – 9:00AM
    Executive Office Team Experiences with Copilot and Agents
    Through real-world scenarios and “day‑in‑the‑life” examples, you’ll see how Copilot and role‑aligned agents help Executive Office teams move beyond task execution to strategic enablement—anticipating needs, reducing friction, and accelerating outcomes across the executive agenda.

    What You’ll Learn
    • How Copilot supports Executive Office workflows across scheduling, inbox management, meeting orchestration, briefings, communications, and follow‑through
    • Role‑specific use cases for Chiefs of Staff, Executive Admins, Executive Operations, and Executive Communications
    • How prebuilt agents (Researcher, Analyst, Writing Coach, PowerPoint Agent, and others) support executive readiness, decision framing, and leadership communications
    • How agents can automate and assist with repeatable executive-office processes, such as:
      • Agenda and briefing preparation
      • Action item tracking and follow‑ups
      • Executive updates and recurring reports
      • Communication drafting and refinement
    • Best practices for using Copilot and Agents while maintaining security, confidentiality, and consistency in executive-facing work
  • Date/Time:
    • Monday, June 8, 8:00 AM – 9:00 AM
  • Registration:

————————————–
ON-DEMAND: How Executive Admins get more done with Microsoft 365 Copilot
Additionally, the following quick video is specifically for those Admins – orated by 2 of Microsoft Executive Assistants that support a couple of our Corporate Vice Presidents:

  • On-demand
    How Executive Admins get more done with Microsoft 365 Copilot
    The final session brings everything together through the lens of an Executive Assistant’s workday. You’d learn how they use Microsoft 365 Copilot to manage busy schedules and keep their boss’s day organized and on track.

    You’ll see real examples of how Copilot helps with:
    • Preparing for meetings
    • Drafting and refining emails
    • Planning travel and events
    • Summarizing emails and meetings
    • Finding information across files, chats, and sites
  • (Part of the “Microsoft 365 Copilot app learning series: Real‑world scenarios for your workday” at https://aka.ms/M365CopilotAppSeries.)
  • View recording:

————————————–
WRITTEN: Empower your Workforce with Microsoft 365 Copilot: Executives Use Case
Lastly, we have some training modules that people in executive leadership roles can go through that may be useful for their administrators as well.

This module enables students to perform a series of Use Case exercises that build their Microsoft 365 Copilot skills in Executive-related business scenarios.

Learning objectives
By the end of this module, you should be able to:

  • Synthesize communication insights using Microsoft 365 Copilot across Microsoft Teams.
  • Use Copilot in Word to create an executive briefing report.
  • Use Copilot in Excel to perform budget forecast analysis.
  • Use the AI Project Manager agent in Planner to create a new project plan.
  • Create an agent that provides performance metrics, monitors key indicators, and flags emerging issues.

Try it at: Empower your Workforce with Microsoft 365 Copilot: Executives Use Case – Training | Microsoft Learn

Posted by: kurtsh | April 23, 2026

RELEASE: Microsoft Entra Backup and Recovery

Microsoft Entra Backup and Recovery (Preview) is a native service inside the Entra admin center (in preview) that provides “identity resilience” for those concern about unintentional or unauthorized modifications to Entra. 

Entra Backup & Recovery provides:

  1. daily backups with 5-day rolling retention
  2. object-level restore
  3. reporting that provides insight into what will change when a restore is executed. 
  4. recovery audit logs for compliance  

Entra Backup & Recovery comes at no additional cost for either the service or the storage of Entra backups.

For more information on Entra Backup & Recovery, visit:

Microsoft acquired Fintool, an AI agent company to aid finance professionals with qualitative analysis.

Fintool builds AI-powered research tools for finance professionals. They specifically have a set of AI agents that specifically analyze company filing, do company research & read earnings call transcripts. Popular amongst investors & analysts, the company just announced a set of autonomous agents that builds earnings PowerPoint presentations, builds cash flow models in Excel, etc.

How does it work?
Fintool’s interface is just like any other AI & previously provided users with 5 free questions a month. Beyond that, it was a subscription service that cost $100/mo that among other things, would scrape the SEC.gov Edgar database for answers to your prompts, making it useful to track performance of publicly traded companies. For example, here are some example prompts that a user could use with Fintool: (taken from Journalist’s Toolbox)

  • $GSK – How did GSK’s stock price perform in Q3 in 2023?
  • $NVS – What was NVS price earnings ratio during Q1 2024?
  • $PFE – How much has Pfizer’s stock price increased since the start of the COVID-19 pandemic?

How does this differ from general AI? Yes, part of this is crafting the logic to accurately accomplish the things that all qualitative analysts do, however, much of the time, the data posted to the web & ingested by the model is garbage or non-verifiable. We’ve all seen numbers & charts shown in traditional AI conversation that are completely wrong or fabricated. Fintool addresses this.

How can this impact investors? Listen to Nicolas Bustamante’s interview on YAV Podcast about how AI is transforming investment workflows, from memo creation to screening and qualitative analysis.

Where’s the announcement? Read more about the acquisition here:

The world of work is undergoing a profound transformation. reshaping how organizations operate, innovate, and compete. In this landscape, Desktop as a Service (DaaS) is emerging as a strategic enabler, not just a technical solution. It’s redefining how businesses empower their people, secure their data, and adapt to constant change.

Microsoft is at the forefront of reimagining DaaS, extending beyond virtual desktops to deliver a platform for business agility, resilience, and human-centric innovation. Our Leader position in the Gartner Magic Quadrant™ for Desktop as a Service for three consecutive years, we believe, reflects our commitment to driving this evolution.

DaaS is about enabling new business models, supporting sustainability goals, unlocking talent across borders, and delivering seamless productivity for every organization. With Windows 365 and Azure Virtual Desktop, organizations can more easily embrace digital transformation rethink processes, reduce costs, build resilient operations, and empower their teams to work securely and efficiently – anytime, anywhere.

To read about what differentiates Microsoft’s Desktop as a Service offering, what the Gartner Magic Quadrant for DaaS has to say about it & download the full report, visit:

For decades, Active Directory administrators have labored to determine the causes of Group Policy issues in their networks.

From corruption of Registry.pol, to not knowing the full network path for policy objects, to not knowing when there are locks on critical sections of GP – and what was causing them, Active Directory administrators have often spent days with Microsoft Support, often resorting to unnatural acts to find a resolution.

Recently, there have been major improvements introduced to Windows 11 24H2 (26.02D) & Windows Server 2022/2025 (26.06B – coming soon) that will help ease the work required to figure out Group Policies issues:

Six amazing new changes to Group Policy

Troubleshooting Group Policy has always been about one thing: visibility. Recent Windows releases introduce six meaningful improvements to Group Policy that make troubleshooting faster, clearer, and far less frustrating.

All six changes are enabled by default in Windows 11 24H2 and 25H2 (26.02D). For Windows Server 2022 and 2025, these changes are expected to be enabled by 26.06B.

Here is a closer look at the six updates and why they matter.

Now, if you’re not celebrating some of their GP improvements, you’re probably not a Active Directory admin. 😁 All that said, read about the updates at Andrea’s newsletter below:

The following is online recorded security breakouts & sessions from 2 Microsoft Windows virtual conferences:

WINDOWS 11/INTUNE:  RECORDINGS FROM THE MICROSOFT TECHNICAL TAKEOFF 2026: (aka the Windows 11 & Intune Conference) – MARCH 2026
These are online recordings from this year’s Windows 11 & Intune conference, known as the Microsoft Technical Takeoff.  The following are a listing of all the endpoint security-focused sessions only.  To view all the sessions for Windows Management, user experience, virtual desktops, deployments, AI & agentic features, quick machine recovery & more, visit https://aka.ms/technicaltakeoff.

Security Sessions:

WINDOWS SERVER: RECORDINGS FROM THE MICROSOFT WINDOWS SERVER SUMMIT 2025 – APRIL 2025
These are online recordings from last year’s Windows Server Summit 2025, Microsoft’s annual online conference for Windows Server administrators.  These are the security-centric sessions.  Each recording is about 30min.  To see all the recordings, including those for core services, server upgrades, server management, training, etc. visit Windows Server Summit 2025.

Keynote

Security & Identity

To independently assess Microsoft’s security, privacy, and compliance controls, refer to the following official Microsoft resources:

  1. Microsoft Trust Center – https://www.microsoft.com/en-us/trust-center
    Overview of Microsoft’s data security, privacy commitments, and compliance standards across our cloud services.
  2. Microsoft Service Trust Portal * – https://aka.ms/STP
    Downloadable audit reports (SOC 1/2/3, ISO 27001, FedRAMP, etc.), certifications, whitepapers, and privacy documentation. Docs on using the STP are available at https://learn.microsoft.com/en-us/compliance/assurance/stp-get-started
  3. Microsoft Compliance Manager Build and manage assessments in Microsoft Purview Compliance Manager
    Compliance management tool with 360+ regulatory assessment templates to help evaluate compliance against standards such as NIST CSF, FedRAMP, and HIPAA. (The use of regulatory assessment templates may require additional subscriptions.)
  4. Microsoft Compliance Offerings Compliance offerings for Microsoft 365, Azure, and other Microsoft services
    Complete directory of Microsoft’s compliance certifications organized by US Government, Global, Industry, and Regional categories.

* Note that publications from the Service Trust Portal are not public documents & anonymous access to these reports & assessments may not be permitted.  Authorized Entra accounts assigned the appropriate admin roles may download the audit reports & attestations published online.

For specific security or compliance questions, leverage your organization’s Unified Enterprise agreement for support engineering advisory cases.  This can be done through https://serviceshub.microsoft.com or 800-936-3100, through an authorized contact for your organization’s Unified Enterprise agreement.

For broader security or compliance assistance, work through your Unified Enterprise Customer Success Account Manager to discuss funding an engagement with a Security Architect through Unified Enterprise proactive services.

For organizations without Unified Enterprise agreements, if you require direct assistance, work with a Microsoft Partner with expertise in compliance & risk assessments to discuss a professional services engagement. Government organizations I’ve worked with in the past have engaged Bridewell, Epiq Global & Patriot Consulting. If you are a customer of mine that requires a direct contact, reach out & I can provide one.

GitHub Copilot CLI is an AI-powered assistant that runs directly inside your terminal. Instead of manually writing commands, scripts, or debugging issues, you can simply describe what you want — and Copilot executes it.

Here’s the shift:

Traditional CLICopilot CLI
You write commandsYou describe intent
You debug manuallyAI suggests fixes
You search docsAI brings context


For Cloud and DevOps engineers, this becomes extremely powerful because most of our work already happens in:

  • CLI (Azure CLI, Bash, PowerShell)
  • Infrastructure as Code (Terraform)
  • Pipelines (CI/CD)

Copilot CLI sits right in the middle of all this.

For example:

Instead of:

az group create --name my-rg --location eastus


You can say:

Create a resource group in Azure named my-rg in East US


Licensing:
GitHub Copilot CLI is available with all GitHub Copilot plans. If you receive GitHub Copilot from an organization, the GitHub Copilot CLI policy must be enabled in the organization’s settings.

Read more at:

Older Posts »

Categories