Posted by: kurtsh | May 1, 2026

INFO: Microsoft Defender for Cloud Apps resources

Customers that licensed “Microsoft 365 E5/G5” or the “Defender Suite” for their organization’s users have access to a very powerful solution to monitoring & controlling the use of cloud services.

Microsoft Defender for Cloud Apps P2 is a SaaS-based security platform that provides a comprehensive Cloud Access Security Broker, SaaS Security Posture Management & Extend Detect & Respond integration. It delivers the following:

  • Native Cloud Access Security Broker
    Shadow IT discovery, visibility into cloud app usage, protection against app-based threats & information protection and compliance assessments – native to both Microsoft & 3rd party services
  • SaaS Security Posture Management (SSPM)
    Not just monitoring—continuous configuration assessment + recommendations
  • Deep Integration with Microsoft Security (XDR + Entra + Defender)
    Native platform integration vs. “standalone CASB”
  • Advanced Threat Detection via XDR Correlation
    Cross-domain threat detection – not just isolated CASB alerts
  • App-to-App (OAuth) Governance
    Manages 3rd‑party app risk (API / OAuth)
  • Native Integration with Microsoft 365 Data Protection (Purview)
    Unified data governance and DLP across SaaS apps
  • Unified Shadow IT Discovery at Scale
    Deep discovery tied to endpoint + network telemetry
  • Granular Real-Time Session Control
    “Inline” conditional access policies

Here are resources for those licensed for Microsoft Defender for Cloud Apps P2:

Note: For US Government customers using GCC cloud instances of Microsoft 365, the URL to access the service is: https://portal.cloudappsecuritygov.com/ and has a adjusted set of capabilities.

Unleash the power of AI agents. Start simple. Scale fast. Innovate at enterprise level. At no cost to you or your organization,

At each level, follow a guided pre‑learning course with Founderz to build essential skills upfront, increase confidence, and maximize hands‑on impact during the live, virtual agent‑a‑thon. Build with confidence thanks to AI Voice agents (“Fellows”) and live human expert Q&A throughout the event challenge.

Each level aligns to different agent tools and build depths, helping you choose what’s right for you—and build solutions you can use right away at work. Registration is free. To ensure the best experience, please review each Agent-a-Thon level and register for the live virtual session that best matches your experience and access:

Choose one of the following levels:

Level 1: Explorer – Build your first AI agent
Wednesday, May 06, 2026 – 8:00AM-11:00AM
Register: https://msevents.microsoft.com/event?id=3610636897
Use Agent Builder in Microsoft 365 Copilot and learn the fundamentals of agent creation. Discover how simple, no code tools can unlock productivity and help you turn ideas into working AI agents.

  • Learn how to create an AI agent: Via our guided step-by-step demonstration on our early access learning platform (hosted by Founderz).
  • Get support in real time: With Dedicated AI Voice Agents (‘Fellows’) and human expert Q&A during the build challenge.

Level 2: Commander – Build powerful AI agents
Wednesday, May 06, 2026 – 8:00AM-11:00AM
Register: https://msevents.microsoft.com/event?id=4269974222
Use Microsoft Copilot Studio to automate work, connect systems, and streamline processes. Learn how to create scalable, no code agents that solve real challenges and accelerate impact across your organization.

  • Learn how to build and extend agents with Microsoft Copilot Studio via a guided step-by-step demonstration on our early access learning platform (hosted by Founderz). 
  • Get support in real time: with dedicated AI Voice Agents (‘Fellows’) and human expert Q&A during the build challenge.

Level 3: Master – Build scalable agents with Microsoft technologies
Wednesday, May 06, 2026 – 8:00AM-11:00AM
Register: https://msevents.microsoft.com/event?id=4277171142
Use Microsoft Foundry and explore orchestration, multi agent capabilities, and secure enterprise workflows to innovate at speed and scale.

  • Learn how to build advanced AI Agents within Microsoft Foundry, via a guided step-by-step demonstration on our early access learning platform (hosted by Founderz).
  • Get support in real time: with dedicated AI Voice Agents (‘Fellows’) and human expert Q&A during the build challenge.

Today we are introducing the Legal Agent in Microsoft Word. Whether you are generating redlines or reviewing counterparty changes, the agent handles tedious work, so legal professionals can focus on high-impact decisions.

The Legal Agent was built in close collaboration with legal engineers to reflect how contracts are reviewed and negotiated. Instead of relying on general AI models to interpret commands, the agent follows structured workflows shaped by real legal practice, managing clearly defined, repeatable tasks like reviewing contracts clause by clause against a playbook.

The agent applies edits in the document through a purpose-built insertion algorithm to drive consistency regardless of how each edit was introduced. The agent’s redlining engine understands the structure of a Word document, not just visible text. It understands and structures Microsoft 365 document format into a representation that preserves formatting, lists, tables, and tracked changes. From there, the agent applies a deterministic resolution layer over the edits, including author-specific changes, instead of relying on an LLM to generate every revision directly. This provides a more reliable foundation for handling complex contracts while helping reduce latency and cost.

Read more about the new Legal Agent for Word for Microsoft 365 Copilot subscribers at:

Posted by: kurtsh | April 30, 2026

INFO: Group Membership Management (GMM) tool

Group Membership Management (GMM) is a service that dynamically manages the membership of AAD Groups. Groups managed by GMM can have their membership defined using existing AAD Groups and/or custom membership sources.

Organizations routinely use groups with large number of members for executive communications, company townhalls and other collaboration scenarios. Keeping the membership rosters of such groups current is critical to ensure the right audience is included. Stale rosters have consequences – imagine how a team that was recently moved into an organization feels when they are excluded from their VP’s townhall because the townhall community member roster was not updated?

Group owners spend countless hours, manually reconciling with spreadsheets or existing security groups to keeping the group membership accurate. It is much more efficient to have individuals maintain sub-group memberships (with <50 members) and automatically assemble the parent group roster as an aggregation of sub-groups.

We want to share with you a tool that we have developed and used at Microsoft which makes it easy to manage a large group roster by taking advantage of existing security groups and/or smaller groups kept up to date by teams within the larger org.

Introducing the GMM tool
This is a .NET service that generates a parent group membership roster by regularly synchronizing it with memberships from specified Security or Microsoft 365 groups. Deploying the tool requires experience in building, deploying, and managing Azure services. Group owners can then work with the admins to help manage the membership of their groups.

(The tool is being shared as an open-source project in the hopes of helping with similar opportunities in your organization. The solution is provided “as-is” and Microsoft is not providing additional support. Code contributions are not being accepted at this point, but there are plans to allow code contributions in the near future. The GMM Support team will be watching the forum and answering any questions you may have with the installation/set up or use of the tool.)

Accenture is leveraging Microsoft’s secure, governed & compliant Artificial Intelligence – Microosft 365 Copilot – for their entire workforce:

Deploying Microsoft 365 Copilot to 20,000 employees might sound like a big undertaking, but Accenture was just getting started.

The global professional services firm is rolling out Copilot across its workforce to around 743,000 people – the equivalent of a city roughly the size of Denver. It’s the largest enterprise Copilot deployment to date, according to Microsoft, and Accenture says it’s paying off.

Ninety-seven percent of employees reported completing routine tasks 15 times faster with Copilot and 53% reported significant improvements in productivity and efficiency, according to 2025 company data involving 200,000 users.

“Copilot is a personal digital colleague,” says Tony Leraris, Accenture’s chief information officer. “It changes the way our people work, the way they research, ideate, analyze and execute many daily activities.”

The scale of Accenture’s Copilot deployment is striking – as is how the company has approached it. Accenture moved intentionally, starting with a large group, then extending that deployment even wider. Every step of the way was an opportunity to learn, set guardrails and understand how Copilot was changing the way people worked before continuing further.

Read the full article here:

I was recently asked if Microsoft had training available for Executive Assistants/Administrators. 

————————————–
LIVE: Executive Office Team Experiences with Copilot and Agents
There is a one-hour, no-cost virtual event coming up on June 8th, 2026 specifically for the Executive Office team interested in harnessing the power of Microsoft 365 Copilot & Agents:

  • Monday, June 8, 8:00 AM – 9:00AM
    Executive Office Team Experiences with Copilot and Agents
    Through real-world scenarios and “day‑in‑the‑life” examples, you’ll see how Copilot and role‑aligned agents help Executive Office teams move beyond task execution to strategic enablement—anticipating needs, reducing friction, and accelerating outcomes across the executive agenda.

    What You’ll Learn
    • How Copilot supports Executive Office workflows across scheduling, inbox management, meeting orchestration, briefings, communications, and follow‑through
    • Role‑specific use cases for Chiefs of Staff, Executive Admins, Executive Operations, and Executive Communications
    • How prebuilt agents (Researcher, Analyst, Writing Coach, PowerPoint Agent, and others) support executive readiness, decision framing, and leadership communications
    • How agents can automate and assist with repeatable executive-office processes, such as:
      • Agenda and briefing preparation
      • Action item tracking and follow‑ups
      • Executive updates and recurring reports
      • Communication drafting and refinement
    • Best practices for using Copilot and Agents while maintaining security, confidentiality, and consistency in executive-facing work
  • Date/Time:
    • Monday, June 8, 8:00 AM – 9:00 AM
  • Registration:

————————————–
ON-DEMAND: How Executive Admins get more done with Microsoft 365 Copilot
Additionally, the following quick video is specifically for those Admins – orated by 2 of Microsoft Executive Assistants that support a couple of our Corporate Vice Presidents:

  • On-demand
    How Executive Admins get more done with Microsoft 365 Copilot
    The final session brings everything together through the lens of an Executive Assistant’s workday. You’d learn how they use Microsoft 365 Copilot to manage busy schedules and keep their boss’s day organized and on track.

    You’ll see real examples of how Copilot helps with:
    • Preparing for meetings
    • Drafting and refining emails
    • Planning travel and events
    • Summarizing emails and meetings
    • Finding information across files, chats, and sites
  • (Part of the “Microsoft 365 Copilot app learning series: Real‑world scenarios for your workday” at https://aka.ms/M365CopilotAppSeries.)
  • View recording:

————————————–
WRITTEN: Empower your Workforce with Microsoft 365 Copilot: Executives Use Case
Lastly, we have some training modules that people in executive leadership roles can go through that may be useful for their administrators as well.

This module enables students to perform a series of Use Case exercises that build their Microsoft 365 Copilot skills in Executive-related business scenarios.

Learning objectives
By the end of this module, you should be able to:

  • Synthesize communication insights using Microsoft 365 Copilot across Microsoft Teams.
  • Use Copilot in Word to create an executive briefing report.
  • Use Copilot in Excel to perform budget forecast analysis.
  • Use the AI Project Manager agent in Planner to create a new project plan.
  • Create an agent that provides performance metrics, monitors key indicators, and flags emerging issues.

Try it at: Empower your Workforce with Microsoft 365 Copilot: Executives Use Case – Training | Microsoft Learn

Posted by: kurtsh | April 23, 2026

RELEASE: Microsoft Entra Backup and Recovery

Microsoft Entra Backup and Recovery (Preview) is a native service inside the Entra admin center (in preview) that provides “identity resilience” for those concern about unintentional or unauthorized modifications to Entra. 

Entra Backup & Recovery provides:

  1. daily backups with 5-day rolling retention
  2. object-level restore
  3. reporting that provides insight into what will change when a restore is executed. 
  4. recovery audit logs for compliance  

Entra Backup & Recovery comes at no additional cost for either the service or the storage of Entra backups.

For more information on Entra Backup & Recovery, visit:

Microsoft acquired Fintool, an AI agent company to aid finance professionals with qualitative analysis.

Fintool builds AI-powered research tools for finance professionals. They specifically have a set of AI agents that specifically analyze company filing, do company research & read earnings call transcripts. Popular amongst investors & analysts, the company just announced a set of autonomous agents that builds earnings PowerPoint presentations, builds cash flow models in Excel, etc.

How does it work?
Fintool’s interface is just like any other AI & previously provided users with 5 free questions a month. Beyond that, it was a subscription service that cost $100/mo that among other things, would scrape the SEC.gov Edgar database for answers to your prompts, making it useful to track performance of publicly traded companies. For example, here are some example prompts that a user could use with Fintool: (taken from Journalist’s Toolbox)

  • $GSK – How did GSK’s stock price perform in Q3 in 2023?
  • $NVS – What was NVS price earnings ratio during Q1 2024?
  • $PFE – How much has Pfizer’s stock price increased since the start of the COVID-19 pandemic?

How does this differ from general AI? Yes, part of this is crafting the logic to accurately accomplish the things that all qualitative analysts do, however, much of the time, the data posted to the web & ingested by the model is garbage or non-verifiable. We’ve all seen numbers & charts shown in traditional AI conversation that are completely wrong or fabricated. Fintool addresses this.

How can this impact investors? Listen to Nicolas Bustamante’s interview on YAV Podcast about how AI is transforming investment workflows, from memo creation to screening and qualitative analysis.

Where’s the announcement? Read more about the acquisition here:

The world of work is undergoing a profound transformation. reshaping how organizations operate, innovate, and compete. In this landscape, Desktop as a Service (DaaS) is emerging as a strategic enabler, not just a technical solution. It’s redefining how businesses empower their people, secure their data, and adapt to constant change.

Microsoft is at the forefront of reimagining DaaS, extending beyond virtual desktops to deliver a platform for business agility, resilience, and human-centric innovation. Our Leader position in the Gartner Magic Quadrant™ for Desktop as a Service for three consecutive years, we believe, reflects our commitment to driving this evolution.

DaaS is about enabling new business models, supporting sustainability goals, unlocking talent across borders, and delivering seamless productivity for every organization. With Windows 365 and Azure Virtual Desktop, organizations can more easily embrace digital transformation rethink processes, reduce costs, build resilient operations, and empower their teams to work securely and efficiently – anytime, anywhere.

To read about what differentiates Microsoft’s Desktop as a Service offering, what the Gartner Magic Quadrant for DaaS has to say about it & download the full report, visit:

For decades, Active Directory administrators have labored to determine the causes of Group Policy issues in their networks.

From corruption of Registry.pol, to not knowing the full network path for policy objects, to not knowing when there are locks on critical sections of GP – and what was causing them, Active Directory administrators have often spent days with Microsoft Support, often resorting to unnatural acts to find a resolution.

Recently, there have been major improvements introduced to Windows 11 24H2 (26.02D) & Windows Server 2022/2025 (26.06B – coming soon) that will help ease the work required to figure out Group Policies issues:

Six amazing new changes to Group Policy

Troubleshooting Group Policy has always been about one thing: visibility. Recent Windows releases introduce six meaningful improvements to Group Policy that make troubleshooting faster, clearer, and far less frustrating.

All six changes are enabled by default in Windows 11 24H2 and 25H2 (26.02D). For Windows Server 2022 and 2025, these changes are expected to be enabled by 26.06B.

Here is a closer look at the six updates and why they matter.

Now, if you’re not celebrating some of their GP improvements, you’re probably not a Active Directory admin. 😁 All that said, read about the updates at Andrea’s newsletter below:

Older Posts »

Categories