331 - Breaking into Microsoft security as a career
50m 58s
In this podcast episode, the hosts open by sharing recent vacation experiences, highlighting a preference for dynamic trips that involve moving between locations to enrich the holiday. They then delve into their extensive IT careers, starting from early hands-on roles to becoming consultants, entrepreneurs, and working at companies like Microsoft. Both emphasize that work is a passion driven by innovation and problem-solving, not merely a job. The discussion shifts to cybersecurity's evolution: historically, security relied on firewalls and on-premise perimeters with slow change cycles. Today, the paradigm has shifted to an identity-first, zero-trust model in a cloud-heavy, hybrid environment where AI is utilized by both attackers and defenders. Security is now seen as an enabler rather than a blocker, requiring professionals to grasp risk, compliance, and architecture holistically. The episode sets the stage for a deeper exploration of skills needed for Microsoft security roles in the AI era.
[MUSIC] Hey there and welcome to another episode of Control Out, Azure. This is a show where we talk about all things, Microsoft technology. I'm Tobias and I'm back again with UC. What's up? Hey Toby, I'm back from Spain. I think I mentioned I'm having a vacation briefly in Spain. It was great. We did a road trip to Granada, to Seville, and back to the tourist areas near Porta Banners, and Marbella, and Gibraltar. The usual things sort of the kids wanted to see as well. Going from -15 Celsius, that was the temperature in Helsinki when we left, which is about 5 Fahrenheit, 2 plus 22 Celsius, which is about 71 Fahrenheit. It was much needed. Food was great, and I found some very decent. I would even say very nice gyms near the places we stayed in. Put in some proper sessions, had the great food to offset those sporting activities. Perhaps the one quick reflection that I will learn when planning for family holidays is that you need to switch places a few times. Because then it feels like three weeks. Every second day or every third day, you sort of traverse to a different location. You may be changed to a different Airbnb, a different hotel, different city, and everything is new again. It makes the holiday feel longer and you experience a little bit more. But now, super glad to be back home. Regular routines, homemade food, my own home office. That is an unbeatable combination. It is good to be back home when you've been traveling. What I love about this, first of all, Spain is amazing, but also like you mentioned, going to different places during the one trip, not just to get stuck in one location. That's something we've experienced in the last couple of trips as well that, you know, previously, we might have wanted to have one week in one location so we don't have the stress of going anywhere, but then realized we can just get a hurts rental car for, you know, it doesn't cost that much. Get one that fits the entire family. We don't even book a hotel these days. We just go, we jump on the plane with a family and then we go somewhere and wherever we are, we're like, okay, let's pick up a car. If there's no car, there's going to be a tax. It doesn't like, we'll figure it out. We get a car and then we jump around different towns or different small villages and just have a great time and use Airbnb or hotels.com or something like that on the way. That's how we've done some of the most amazing vacations with our family. So hopefully that can inspire someone to be bold. Don't book. Just go. Speaking of good vibes, I've been vibing. During the weekend, I finished building a feature complete, fully compliant, which means ISO 27001 GDPR, SOC2 tool for something in the cloud space. I cannot really say what it is right now, but it's exciting. It's pretty amazing what you can get done these days by just knowing the market, knowing the customer, and more importantly, perhaps knowing the design principles that you need to adhere to. So I'm hoping I can share a little bit more about that soon, but until then, it may the vibes be with you. But also don't forget to keep tight rains on your AI agents so they don't run too loose. A final reflection on this after spending a couple of weekends here and there and also every single day at my current current job in our startup is we're living in the future. If you don't embrace the agentec wave working, I am very confident you'll get left behind and that's not FOMO, you know, I'm not trying to spread fear or cause fear of missing out. But honestly, what I see from the front row in the trenches here, if you don't get on the agentec AI train one way or the other, you're going to get left behind. We did have a conversation not too long ago in one of my executive roundtable groups where we talked exactly about this. Like is outsourcing dead? Do we need outsourcing? Do we even need consultants or software engineers the same way we did a couple of years ago? The answer is no, we don't. It's kind of look different. We need these people critical thinkers, but it's kind of look different. But that's for another time. I just wanted to leave those thoughts there. Exciting times for sure. I'm anxious to hear more once you progress with that y-being in terms of AI agents and everything you can produce with them. So today we have a slightly different topic in mind. The idea is to focus on what it takes in 2026 to work with Microsoft security capabilities as a carrier, being a specialist with Microsoft security related work. I think the plan for us is to share our mutual insights from the past a little bit, but also to reflect on what the future holds and what should you be capable of doing? What things to consider whether you're just breaking into IT and cybersecurity or if you're transforming as a more seasoned professional, like perhaps you've been working in IT pro with a different viewpoint, now you want to work more with security related work. But first, let's perhaps do a brief history on each other, on how we arrived here, what we've each done in the past and what do we actually do today? And I know we've sort of mentioned casual things here and there, but maybe good to reflect in one go. Perhaps somebody's listening on this who hasn't listened on previous episodes on what do we both actually have been doing and what do we do today? So please go ahead. Yeah, I'm just sitting here smiling now. It's like, where do I even start? I know we I know you have at least 10 years ahead of me in the IT industry, because you also started early and you've been working in that industry a long time. So I'm going to try to summarize this in like one or two minutes, but it's 25 years in the IT industry. It's a long time. So I'm just going to try to bullet point this down for you as you tune in. So this for me, it started like the IT era of my career started because I was working on the floor as a 16 year old in an industry where I was putting resistors and components on circuit boards manually. Repeat that until the end of day. You put them on one of these things that it goes into a machine. It puts soldering iron underneath it being bang boom. You put the thing on a you know, whatever. On another thing, it goes away. So like this kind of serial supply chain kind of thing, you know, a circuit board ended up in front of you. You put the components. It left another one came in and I did maybe 200 of those every day. That's what I did. The same circuit board come in every day exactly the same. That's where I started, you know, because my friends they were at the beach, but I wanted to work. So this was like a summer type of gig that I landed because I went around knocking doors on every company in town and I said, Hey, do you have summer job for me? You know, I'll work for free because I wanted to learn how to work. You know, what does it mean to work? Maybe I can work here in the future. If I work for free during one summer, maybe I can come back and actually get paid. You know, I've always had that you create your own luck kind of attitude. The company Creek really, they realized I had an act for computers because I fixed all their issues in their production floor system. So out in the production next to this soldering board thing, there was a computer and you had to check in things and he never worked. Everything was just glitchy. You know, I'm like, oh, hold on, this is easy. I can fix this. So I fixed that and then they realized, because everything was running Windows systems, which is what I had at my home as well. They thought that was magic. So they connected me with the IT department and then I was super excited. I didn't have to put anymore resistors onto circuit boards anymore manually because next summer, I was now working in their IT department. So now we're at 2001 or something like that. So when the Millennium Bug did not hit the computers, they still worked in 2001. I started my first web development business, went on to become a consultant then in the SharePoint and Dunette field later in 2006. Then I started my own business again in 2008. Then I joined a startup in 2015. Then I joined Microsoft in 2022. Then I left Microsoft and I joined another startup, which I'm now working in since 2025 in the age of AI. We're building an end-to-end platform for law firms and legal teams to become more efficient now in the age of AI. So I know you also ask, "What does work mean to us?" For me, work always meant a lot to me, not because it is work, but because it's my passion. This is how I live. I love technology, people, innovation. And that's a perfect blend, I think, for me. I get so much energy from figuring out very complex problems, kind of navigating down certainty, leading people along the way, asking for help when I need it, like the people connection is really important to me. Then of course, challenging status quo with new innovative ideas. When I started my first business, everyone was like, "Why would you do that? It's a recession. It's the financial crisis in 2008. Everything is crashing." I'm like, "That's perfect because everyone is kicking out their consultants right now." So if I become an MCT, a trainer, everyone is going to train their in-house staff. I made a load of money. I made a fortune with my first company just doing trainings. Then when they kicked out the trainers, I was a consultant. You have to dare to do what you love. Don't give a crap about what others say. People will always want to place you in a box and say, "Well, you can probably be a senior software engineer. You can probably be this or you can do what you love." If you do what you love, success typically follows, as opposed to chasing success and doing something that is expected by someone else. So for me, work has always been my passion. I don't go to work. I just crank on, I get things done, I build, I innovate, I lead people, I get led by people. This is every day life for me and I absolutely love it. But what about for you? Where did you start? Where are you now? So these were really wise words and a lot of reflection in there. I'll try to match this in a reasonable way. So I got started, that was in 1991. So it's been a while now. And I got started with my brother. We set up a company to sell a dial-up connectivity to businesses. And through there, we were able to offer email addresses to small businesses. And eventually, if you still remember NNTP, they used it news and everything else. So we would provide those as well and eventually internet access. And we lasted in that business for I think about three years. But then all the major players, meaning the ISPs and telephone companies, they really just took over the whole market here in Scandinavia. So we had to figure something else out. And from there, I went more into consultancy. And I bounced between different companies throughout the 1990s. And then in early 2000, I also got more involved with SharePoint and.NET was just coming out. And Windows Server, everything in there was of course the basic type of work you will work on. So I continued as a consultant, as an architect, as a trainer, I sort of switched my roles based on the demands of the current fiscal year perhaps. And I continued until 2006. And then I figured, okay, I think I've seen quite a bit by that time in how businesses operate. I want to work at Microsoft. So I applied, I got hired in early 2007. And I moved to Dublin, Ireland to work again as a consultant and in pre sales. And a little bit of marketing. Windows, we started just coming out. So that was something interesting that you sort of go to customers and try to convince them that well Windows, we start will give you more productivity. At the time, it felt like that may be reflecting back on those times. It wasn't maybe about productivity that much with Windows, with the.NET. And I continued there, I transferred back to Finland, continued with Microsoft. And just like Utobi, in 2009, when the economy took a downturn, I figured, okay, maybe it's time to try again building my own business. So again, with my brother, he's two years older than I am, we figured, okay, let's try to build something. And we spent about eight years building a training slash consulting company. We had small products, but more like offerings. And then we merged with a competitor of ours and eventually that allowed us to not really run the business anymore. And that gave me some time to reflect back before COVID. What do I want to do next? So for me, for the past five years, my life has been sort of balancing between running businesses and doing the actual deliverables with customers. So for me, I split my time mainly between two companies that I own partially. And there's a third company as well, but they have different people running it. So they don't need me messing around in there, but I sort of keep an eye on them, or they keep an eye on me, whichever you like to like to look at it. So for me, it's majority of the times I'm spending with people, with projects, with challenges, with actual deliverables, with the primary goal of Microsoft platforms and Microsoft security capabilities. And it's the same for me. Work has always been a passion. It hasn't felt like work. It has felt like a hobby. As far back as I can remember, when I got access to the first computer that was a week 20 in 1982, it was a fun thing. I wanted to learn everything about this. It didn't feel like I have to sit in front of the display and do something. So I joked maybe a couple of years ago that if I didn't have any obligations in life, maybe no kids, maybe no family, maybe no house to maintain, nothing else to worry about. I would happily work 18 hours a day, not because I would have to, but because I enjoy learning the new things, meeting people, cracking the challenges and finding new innovations. That's what work is for me. And maybe for somebody that sounds super sad, is there nothing else in your life sitting in front of a black terminal? Well, yeah, there's quite a bit. But at the same time, coffee terminal. Yes, but I like the sort of the mental Ikeido you get from this that you have to stop working around five o'clock to do dinner for the family and everything else. And then you're anxious the next morning to get started again because there's so much stuff you want to learn and to work on. So perhaps this is sort of setting the scene for us on what we're going to be discussing now on the security landscape then versus the security landscape now. And obviously in the age of AI, I feel AI is changing and has changed quite a bit. But at the same time, I feel none of the fundamentals have really shifted at all without or with AI in that sense. But if you reflect a little bit on the security landscape then whatever it is then was but before today and the security landscape now and perhaps how it looks in the future. So what would be your reflection on between the history and today? Yeah, I think I think this is a really interesting point to talk about because I recently had a conversation with someone who was looking for a security intern job or like the first security job and they're like, well, what do I need to learn? What are the technologies? What are the concepts? Who are the people I need to understand? What are the adversaries I need to understand? That can be thinking about how do I reply to that today? Two years ago, five years ago, I would have a different answer than I have today. So if I just look at and I think this is like a critical reflection, you know, before diving into what's needed for getting into security, perhaps it's good to reflect a bit on where are we coming from and where are we today? And perhaps that will give us an indication where we're headed. You know, one warning here, these are opinions based on my real experiences, but these are opinions. It's not a fact sheet saying this is exactly how the world is, but this is my experience. Back then, in terms of security, you had 80, GPO, firewall, antivirus. And when you had that, we have secured it, you know, that's your perimeter. That's how that's the mind, you know, mindset we had back in the day, you had an on-prem data center, you had a firewall, you're secure. We had patch two stays. Our security strategy was essentially every Tuesday, we will patch all the machines and servers. That's it. We had a firewall already in place. So I think here's the biggest mind shift, like the perimeter mindset. This is the biggest shift from then to now where the perimeter is. The perimeter was always protected with a DMZ or firewall and we're good. Everything inside of it might have full control, but nobody can get in on the inside, because we have a firewall. You know, identity first mindset is that identity is your perimeter. And as you know, we've talked about this so many times in the podcast, attackers today mostly do not break in. They log in because of compromised credentials or they compromised your machine and they have a token and they can just sign in because you're already bypassing the firewall because your machine is trusted. Identity being, you know, as we talk about zero trust, least privilege, super important. You know, back then we had a security guy. It was a technical specialist sitting in a corner somewhere often with two computers or even, you know, if we're fast forward a bit to laptops, it looked amazing. And that was the person we went to and say, Hey, can we get access to something he's like, All right, let me right click over here. You have now access to the firewall. No problem. We made an exception for your entire subnet range. That's cool. It was a lot of on-prem heavy, slow-change cycles, blast radius was pretty local back then. And when we say blast radius is like, okay, we had to reach what happens back then it was, okay, one server was compromised or, you know, that's it. Unless if you remember Windows Blaster 32b, the B version, that's the one that it was infecting millions of servers and like all the Windows machines out there. If you know, know it, I'm not going to dive into details, but if you know, you know, I was working in the IT department of the previously said company when this happened and it was chaos. You know, so that's the, that was a big blast radius. Other than that was pretty local blast radius back then. Fast forward to today, identity is the perimeter, different training and mindset is required. You don't just enable a firewall and then think you're secure. Cloud first, sass heavy, hybrid realities, you know, it's less on-prem local data center still exist, but it's not the main focus for most people today. You have a continuous attack surface and that's also continuously growing as you expand your cloud footprint. So does your attack surface. You have AI on both sides now, attackers and defenders, both use AI. Security is now considered a security enabler, not a blocker or naysayer. You know, in the past many, many decades, security was always kind of the cost center and the naysayer security was a, no, that's not a good idea. And you had a fight between the CIO and the CISO versus the CTO and the CIO saying, hey, we need to drive innovation and CISOs or security experts who say, no, we cannot do that because X, Y and Z. That is now a better dialogue. They're still friction, you know, it's not frictionless between all these roles, which is a good thing because you need to take the hard conversations in order to really security harden things. What I think is one of the big things is you're expected to understand risk compliance and architecture, not just using tools. Back in the day, it was like, hey, I can use NetCat and I can do this. I can port scan, you know, I can do offensive security using these 11 tools. That's not what you need these days. So whether you're a attacker or defender offensive or defensive security or a blend, my honest opinion is you need to learn to be great at a tool if you want, but then you're missing out the future way of working. Any security engineer in the future needs to have a bigger picture mindset, especially now when AI and many of our tools are fully automated, you know, including end-to-end investigations, hunting signals, anomaly detections and so on. This is true also for attackers. So back then, we had script keys. That was a big thing. In the 90s, manual fishing attacks, noisy attacks, detection was based on signatures. It was human-led triage. Not too long ago, everything was human-led triage. Now it's AI-generated fishing. And those pass, typically pass all the SPF DKIM, D Mark record you have said on your domain. It's easy to bypass this these days because you can now infiltrate and exfiltrate data. You get access to an inbox and then you send legitimate emails from an inbox and then you create phishing emails. You have deep-fake voice and video impersonation of people. You have automated vulnerability discoveries. You have a tech chain automation. And I've seen this and I've actually run some of these offensive security AI tools because as I mentioned in a previous podcast episode, I am hacking boxes, penetration testing and penetrating boxes at hacktabox.com, which is an amazing way to get real vulnerable machines and systems and networks. And you have to break into game points. It's amazingly fun. So I've used AI offensive security tools. And it's, you prompt your way and say, here's an IP address. Find weaknesses. It goes and run MAP, NMAP, discovery, fuzzers, directory busters, BingBong Boom. Then it gets the results and say, I understand what to do with this output because I know these three ports are open. That means I need to run all of these tools. I'm also going to pivot over here and run these things. I'm also going to try to discover subdomains. I'm going to do that in parallel. All of this happens within two minutes. This is something an offensive security expert would have to spend a lot of time on. This is now fully automated. And that is really scary, exciting in one way because the innovation is top-notch. But it's also very scary because there's no way for a human to keep up with that pace. So if you're on the defensive security side, you also need to leverage AI, AI power detection, think co-pilot on the Microsoft side, behavioral analytics, you know, all these kind of things. So what does that mean for your skill? Well, that's perhaps discuss that. But the key point is you cannot memorize commands. That part of your career is dead. You don't need to know exactly which flags to put into which command. Prompt engineering is not a career. I want to say that as well because that's a discussion we had recently where someone said, well, I'm really good at prompting. So can I use that as a bill of career? Well, you can build prompts, but you have to understand compliance security, architecture, all these bigger pictures. So you must understand the attack chains, like the mature attack, understand identity of use, understand automation, know how to validate AI outputs, think in systems, not tickets. And what I mean by that is think about understanding the entire big picture and the entire system, rather than you get a ticket, oh, something happened over here, go investigate this one thing. Okay, maybe you mitigate, maybe you fix it, close that one thing, and then you have 200 new tickets, fix the underlying problem. Why did you get the ticket? What does the system look like? Anyway, I know I have a lot of reflections on this. I'm going to put a pause right there. Any reflections on this? Oh, I love the reflections for sure. And while you were talking about the then versus now, I'm looking, are we using zoom to record the audio for this one? And we're using video just to see it's other zoom has a new button. It says AI companion. And you were talking about AI attacks. And I'm like, I'm afraid to click this while we are recording because nobody knows what's going to happen. When you click a button that says AI companion, it will probably take over and just finish the episode for us. So I'm not clicking on that one. I love the reflections for sure. And fully, fully agree with the assessment is memorizing commands. It's definitely dead, but it's still super useful in understanding the base commands. This is reminding me this was quite some time ago. I have a sitting side by side with a customer. We were trying to build an integration. This was before fabric and logic apps and the cloud and everything else. And for one of the tests for the integration, we had a fairly complex CSV file. And we needed to parse that to do some sort of initial tests to understand what goes where and how. And I remember looking at the CSV and going, well, hold on, I can just parse this on the fly. Let's do a bit of Linux cell scripting. Let's do a little bit of visual basic scripting mostly because those were the only tools we had in that lockdown environment. So you didn't have partial. You couldn't open visual studio to do something fancy. And I remember typing up the logic by heart about 200 lines in about an hour. Like, yeah, I know how this is done. I've done this a gazillion times. And the customer sitting next to me goes, how do you know this? I'm like, well, I've done this 57 times. So this is just me reciting from memory something that I already know. There's nothing magical about this. But you don't really do it like that anymore. Obviously, for small bits, you know, and you memorize, but for a lot of other things, you look up stuff. And then you combine those findings to formulate something you need. But besides, technical bits, I feel the other skills they might sound boring, but you need soft skills. So not technical knowledge about a specific capability, but more about soft skills. And for me, this is probably my thinking has evolved quite a bit in the last 10 years or so. I've aged a little bit at the same time I've been exposed to the type of projects that have a lot going on besides just somebody deploying a virtual machine or Sentinel or Defender for Cloud or this or that. It's that the challenges in those projects have been more around people and schedules and budgets that affect the technical work. So the lessons I've taken with me from those projects is that you have to have skills and let me just go through a couple of these. You have to be able to lead a meeting. You have to be able to lead people. And by leading people, I do not say you have to bark orders to underlings or IT pros. You have to be able to say, okay, so we have 12 people gathering for an hour over teams. So the outcome of this should be X. So let me lead the discussion not by having the opinions, but by trying to extract the opinions and wisdom and knowledge and experience from those people attending and then formulating a sort of an outcome and agreement perhaps or a decision from that. And what I do every day with my colleagues who work with me in different projects, when we go to meetings, we always agree beforehand, which one of us is going to lead this? Is it going to be me? Probably not always. It could be somebody else depending on the topic, of course. So leading leading a meeting, leading people, troubleshooting, you have to be able to troubleshoot stuff on a higher level. So this is not about being able to open a Linux shell and typing up mystic commands in there, but more about, okay, so we built this solution, but that connection is failing. So how do we troubleshoot this? How do I instruct somebody remote who has access to the production environment to perform the troubleshooting and bring me back results that allow me to make a decision what should we do next? It might not be me who's at the keyboard. Coordination, task management, planning, light project management, following up on the tasks, understanding of responsibilities, keeping in touch with people, especially during COVID, I found a lot of people struggling because they couldn't see each other in the office setting. So they struggle quite a bit in coordinating things. And I still remember having so, so, so many meetings virtually during COVID that you would join the meeting, you have your camera on, you're sitting there ready to go. The counterpart would join eight minutes late. Oh, I had trouble joining teams. Sure, no problems. The camera is pointing to the ceiling. You can hear the click at the click of the keyboard, the microphone is in the other end of the room. You're like, why is it like this? Why cannot it be like properly done? So you have to be able to manage the priorities. You have to be able to construct the work in a way that stuff gets done. And for this, I often say, it's about understanding the business guardrails, the budgets, the time constraints, the schedule, what the project manager needs to achieve, what tasks are attached to the things that you're supposed to be doing. And for this listening and actually hearing people, and you could say it's empathy, but I feel it's about going into each meeting, be it virtual, be it in person, be it something assumed, crinous like a group chat, going into each one of those with this eagerness that I'm about to learn something. I'm about to push stuff forward in a good way. And I feel that's for me, at least for the past 10 years, that's been key in succeeding in the projects, not going through with tech, tech, tech stuff. That always follows, but going through in, let's see what we need to achieve. Let's try to align the requirements to the skills and to the people and to the tasks that we have at hand. Those would be sort of the soft skills in a real condensed way. Toby, am I missing anything from the soft skills you would add or do you fully agree with the assessment? I was going to say how much time do we have? I think you covered a lot of it. I did want to say that, I used to work at Microsoft on the Cloud adoption framework and there was a really good kind of mantra there, which is people, process and technology. And this is it, whether you work in security, whether you work in some else, if you understand people, if you understand process and you understand the technology, you will have no problems navigating the landscape. When it comes to security, I think that tools don't secure companies, right? They will help you stay secure, but discipline, execution and leadership do. So if you have the right leadership mindset or if you have the right leaders and you have discipline and execution in your teams, that's how you get security done the right way at scale. So yeah, final reflection on this is soft skills matter more than ever, perhaps, because security is no longer just technical, it's organizational. It's always been, but I think a lot of focus was on the technical aspects. A real impact comes from aligning those people, process and technologies and systems, especially under pressure. It's you most kind of translate the risk into business terms, then coordinate data cross teams and lead and decide in ambiguity, because there's a lot of ambiguity, especially in the security space and especially under pressure. Like we're under attack right now. We might have a breach. Someone might be on the inside. We have tangible evidence. What do we do? That's no time to be on defense and say, hmm, do we need to go look at some security policies and maybe read up on some, no, too late. Somebody might be on the inside. So discipline, execution and leadership, perhaps the two most important soft skills you need to have and all of the things you mentioned contributes to that as well. Yeah, no, great, really great reflections. Thank you for that. But looking at the soft skills is one thing, because we need to be people, persons to be able to communicate and lead things. But what about the technical skills today? What are the things? Because I know you work a lot with security hands on as well as secure leadership and bot leadership. What from your perspective would be the technical skills you need today? This is a really good question. I do have plenty of opinions on this one. And as you said before, this is not the only truth in the sense. This is a viewpoint that I've gathered over the experience that I have a recurring issue that I see, especially when it comes to technical skills is that people fall in love with a single thing. It's fine. It's perfectly fine. But don't forget to look around. So let's say somebody falls in love with Sentinel. They want to learn everything about Sentinel. And it's obviously, it's super useful. But if you don't look around, you sort of reduce your skills and your capabilities to a specific type of project, which typically is deploying Sentinel and then operating Sentinel. And once your clients or the organization you work for says, okay, Sentinel is done. We have the SOC operations outsourced to this company. They will take over the incidents and the alerts. There's not much for you to do after that from except to be second line reacting to something later on. But that's quite passive in terms of actually doing something. Your client or your organization might say, let's focus on Defender for Cloud and then application landing zones and then this and then that. It doesn't mean you have to be an expert in everything. But you have to have a wide enough area of interest to be like a Swiss Army knife. And I've been looking at Swiss Army knives lately because Victorinox that builds them, they came out with a new model range for this year. I really want one of those. And when I was a kid, I remember the super fancy Swiss Army knives that were super, super expensive. Now I'm looking at them and the really nice ones are like 25 euros. I'm like, okay, this is quite affordable if I really need one. So you have to be like a Swiss Army knife in the sense that they have a super strong blade. They also have a lot of useful additions that you don't really need every day. But you frequently use them. And when the time comes, you need those skills, those capabilities on an army knife, then you have to be able to operate it. So for cybersecurity, I feel be through consultancy engagements or as an in-house employer specialist or something in between. There's loads of must-haves in terms of technical skills. Let me start with a few. And Toby, you can, you can, you can then add a few and perhaps we'll find some new ones as well. Activity directory. You really have to know that group policy objects, networking, domain sites, trust scurbors, maybe not NClM, that much anymore. But the reason for this is that all enterprises operate with active directory. There are other things as well. But AD is still always there. And stuff still boils down to group policy objects or permissions or policies or domains or replication or what have you. You might not be operating on those. But you often experience the effects of those. And when you understand those different sediments in those deployments, it helps in your work because you can enable and fix stuff when you actually know, well, this looks like it's coming from the GPO. Can we find the person in charge of the GPO? Let's have a call. Let's look into this one. And when you understand what they do as specialists, you can then have a meaningful conversation saying, can we open this? Can we have a look? Could we, could we maybe exclude this or unlink or whatever in this one? And people typically go, yeah, sure, because you seem to understand what you're asking. But if you just go fix AD, I have no idea what's happening in there. You're not moving anything forward. And you're usefulness in that aspect is ready used quite drastically. So AD, Windows Server, Windows 11, obviously, stuff like Windows subsystem for Linux, Linux in general, networking, I would say more broadly, but also in depth, firewalls, proxy, traffic management, the understanding of routing, how does networking actually work? You don't really have to become a Cisco certified engineer in everything, but you cannot really go too deep in here because all of this you will experience with Azure, Microsoft 365, Power Platform, AWS, Google Cloud, on-premises hybrid. It's always about networking. DNS, obviously, that's a given. So besides this, to be any, any additional technical skills, I have learned in my head, but perhaps you can add something here. What technical skills would you add besides this? Yeah, I'm just listening in now. Like, yeah, this is a great training session actually. I agree. And especially what you said about networking, some people find it really boring with networking, but if you're into security, if you want to get into security, or if you want to broaden your security horizon, security, networking security, but also networking in itself is critical to understand. There's a lot of lateral movements happening because there was not a network security group with enabled rules to stop traffic between here and over there. So you have a compromised identity. Guess what? Now I can move to a different resource. Boom, that would have been prevented with proper networking, but it was not just as one example. So other things, technical, especially if we have the Microsoft lens, there's a bunch of tools, right? And I wouldn't recommend becoming an expert in Defender for Cloud. Become an expert in critical thinking. Become an expert in the security landscape. Think like an adversary. Think like a defender. Yes. Do not become an expert just in one tool. Understand all the tools and make sure you get acquainted with them. One thing that we need to talk about is authentication and authorization. Two different things. I see them often mixed up. You know, some especially junior developers or developers getting started. They're like, I added off. And I'm like, is that authentication or authorization? Yeah, I know I added off or, you know, I asked Cloud code to add off. I mean, yeah, but is it authentication or is it authorization? Because these are wildly different things. They go together, but there are different things authentication. That's how you say, I have, I can sign in, right? Here's a username and password or, you know, password list, whatever approach you get a claim saying, I am who I said I am. That's how you authenticate authorization. That's when you're already authenticated. You know, I am Tobias and the system knows I am Tobias. 100%. You have MFA on authentication. And you know, and the system know this is Tobias. Authorization is what does Tobias have access to? What access layer do we have? These things are critical to understand. And, you know, I've done a lot of a West top 10 exploits, hacked websites, hacked different boxes. And again, you know, as a disclaimer with hacked the box.com, that's where I do it. So I don't break into other things. I just wanted to mention that because someone did reach out in one of the other episodes. I said, Hey, you mentioned you hacked stuff. You know, just go around hacking. No, I don't. You know, I use secure labs for that. But authorization is so easy to exploit if it's poorly implemented. So if you do code security, if you do application layer security, if you build something, especially not in the times of vibe coding, if you just say, Hey, build me a web app and add an author layer, if you don't understand what that author layer does, it may or may not work as you think it does or as you think it should. So I think authentication and authorization super important to understand and read up on that a little bit. You know, how do you properly authenticate? How do you properly authorize? And how do you validate that? How do you ensure that this is implemented the right way from a security architecture perspective from a networking perspective, from a application standpoint? All of these things will matter more than you think. And the reason I'm so persistent on this point is when we talk, they were a trust, what we talked about in the beginning of this episode, same thing, identity is your new perimeter. If your identity is compromised, good night, right? Because and there's a study on that there's multiple studies on this. But it's something that keeps coming back in cybersecurity circles is attackers no longer breaking. They just log in using her credentials because they've been exposed. You know, whether that is from your machine, running a script or running some kind of backend process. But we back in the day used to call like a Trojan horse that you deployed on a machine. And you had a Trojan and then you could do things. And you know, that still exists not the same way. But if you have a compromised machine and someone else has access to that, they can execute commands with your identity. That means they will sign in or go they're authenticated. And whatever you have access to, they are now authorized to. Right. So understand authentication, authorization, because that will help you design for blast radius. So least privilege, zero trust, that will get you there. That will help you in critical design thinking for how to properly design those systems. I know that was a lot of thoughts on just authentication and authorization. But I know that you know, it's identity. It's how you sign in. It's how you get authenticated, how you define access and our back role-based access controls. Two things. Other than that, what else do we need to know? So that brings us to Entry Day obviously. So Entry Day as a whole, you need to understand, understand the aspects, the capabilities, a bit on the licensing, the features. I would put weight into areas that are needed and used. Usually conditional access policies, user and group management, access packages, governance in general, service principles. They all revolve around a typical deployment you would do in Azure. I would even argue that global secure access as an example is something you need to be familiar with by now because it ties back into everything we mentioned already. Besides just individual sort of services, I would say scripting and to a degree coding is the must have. You have to be able to do partial shell scripts, maybe a bit of Python, working with data files and structures like Yamel files, JSON, XML, CSV, and so on. And have this sort of a mindset of developing custom utilities and tools using code somebody else did understanding reposting its hub, pulling stuff from there and building something you need. And tooling, debugging, troubleshooting, digging information, that's probably the main skill that I seem to be utilizing every day. There's a problem, something is blocking us. Let's dissect this and try to agree on the next steps. It could be technical, it could be soft skills, it could be tooling, but you need to be able to understand it from the low level to the high level and then inject yourself or your team in between to work on something. So I know there's a lot of stuff in here. I don't think we have any links in the show notes for this one. It's more reflection on what we feel is necessary and a must have if you want to work with security on a Microsoft platform or as a Microsoft specialist to close up. I would just say persistent persistence. That's the only thing you need. You need to get up in the morning, have the sort of appetite for learning more, for meeting people in interacting within projects and customers to be able to get stuff done and then being able to move on. I would say my superpower has been being persistent and being ready to embrace the unknowns that I can push hard to learn the stuff that I should know. What would be your superpower? I just heard you say, so you have to get up in the morning and then you had a short pause. I'm like, you do have to get up in the morning. That's not unique to cyber security or security at all, but I also have to get up in the morning. But I agree persistent, keep pushing, learn, challenge, don't do what's expected. Don't go looking for opportunities from others, create your own opportunities. I mean that in the way that we spoke about do your own labs, do your own testing, do your own exploration. If you truly are excited about something, you will learn so much because you don't see it as, oh man, do I have to go and learn these things now to have a career? If that's your attitude, personally, I think that's going to be a challenge. If I have an attitude of, oh man, I can't wait to get up in the morning or stay up, you know, I'll put the kids to sleep, put the wife to sleep, you know, but shut down the house if you will, everyone is sleeping and then go back and say, okay, I'm just going to spend an hour and a half because there's this shiny new thing I need to learn everything about. I absolutely love that. Some friends would say, well, why would you open your laptop after 5 p.m.? Well, guess what? That's in my DNA. I get it. It's not for everyone to do that. I work in tech. I work with application development. I work with security. I work with architecture. I work with the cloud, you know, compliance. All these things go hand in hand with continuous learning and continuous learning is something I thrive doing. So if you find that, whether it's for career in security, cybersecurity, you know, red team, blue team, whatever you want, doesn't really matter which direction you want to go or if you're already in, you know, maybe you have 20 years of experience in something, you want to pivot into a different career path, perfectly fine. If you have the energy and the excitement about something, you will learn it. And if you have that excitement, that's how you become an expert. That's how you really dive in when you see it as an opportunity to learn, not a challenge to waste time. I think that's when you will excel at anything you want to do. I hope this was useful. Thanks again for tuning in. See you next week. All right. See you then. [Music]
Podcast Summary
Key Points:
The hosts discuss personal experiences with flexible, location-changing vacations and the benefits of spontaneous travel.
Both share their career journeys in IT, emphasizing passion, adaptability, and seizing opportunities during economic shifts.
They reflect on the evolution of cybersecurity from a perimeter-based, on-premise focus to an identity-centric, cloud-first approach with AI integration.
The future of security work requires understanding risk, compliance, and architecture, not just tools, with AI transforming both attack and defense landscapes.
Summary:
In this podcast episode, the hosts open by sharing recent vacation experiences, highlighting a preference for dynamic trips that involve moving between locations to enrich the holiday. They then delve into their extensive IT careers, starting from early hands-on roles to becoming consultants, entrepreneurs, and working at companies like Microsoft. Both emphasize that work is a passion driven by innovation and problem-solving, not merely a job.
The discussion shifts to cybersecurity's evolution: historically, security relied on firewalls and on-premise perimeters with slow change cycles. Today, the paradigm has shifted to an identity-first, zero-trust model in a cloud-heavy, hybrid environment where AI is utilized by both attackers and defenders. Security is now seen as an enabler rather than a blocker, requiring professionals to grasp risk, compliance, and architecture holistically.
The episode sets the stage for a deeper exploration of skills needed for Microsoft security roles in the AI era.
FAQs
The biggest shift is moving from a perimeter-based mindset, where firewalls protected on-premises data centers, to an identity-first mindset where identity is the new perimeter, emphasizing zero trust and least privilege principles.
Security is now considered a business enabler rather than just a cost center or blocker, fostering better dialogue between roles like CIO, CTO, and CISO to balance innovation and risk management.
Today, it's essential to understand risk, compliance, and architecture, not just tools. This includes cloud-first environments, hybrid realities, and how AI is used by both attackers and defenders.
Identity is critical because attackers often log in using compromised credentials or tokens instead of breaking through firewalls, making identity management and zero trust principles key to defense.
The attack surface is now continuous and grows as cloud footprint expands, requiring ongoing monitoring and adaptation beyond traditional on-premises perimeters.
AI is used by both attackers and defenders, changing the dynamics of threats and responses, and making it crucial for professionals to understand AI-driven security tools and tactics.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.