Entra.News - Your weekly dose of Microsoft Entra
Entra.Chat
Find Your Tenant's Hidden Flaws in Minutes
0:00
-44:08

Find Your Tenant's Hidden Flaws in Minutes

Microsoft's Zero Trust Assessment: Breach Origin, Sankey Secrets, and more

This week, I’m so excited to share the inside story of a project I’ve been working on for over a year: the new Zero Trust assessment. I’m joined by some of the key folks from the team: Tarek, who’s leading the charge; Sarah and John, who are crushing docs; and Ravi, who’s owning Intune.

We unpack the wild breach that sparked it all, geek out over those Sankey charts that spotlight sneaky unmanaged devices and privileged access landmines, and tease why even “expired” app creds could be your silent killer. If you’re tired of silos between identity and endpoints, this is your wake-up call—tune in to see how to make Zero Trust practical before the next attack hits.

Subscribe with your favorite podcast player or watch on YouTube 👇

About Our Guests

Sarah Lipsey

Sarah Lipsey has been with Microsoft for almost four years and writes about monitoring and health, ID Protection, and Security Copilot in Microsoft Entra. Sarah has worked as a technical writer and instructional designer for around 20 years, and for a university, a telecommunications firm, and a railroad. She lives in the woods with her family where she loves to knit, play video games, hike, and ski. Yes, she spends way too much time trying to close out every dot on a video game map. Still working on the Skellige map for The Witcher 3.

LinkedIn - https://www.linkedin.com/in/sarah-lipsey-b53b746/

John Flores

John is a Senior Content Developer at Microsoft, where he has worked for over eight years. He specializes in creating high-impact technical content for identity security within Microsoft Entra, focusing on areas like Conditional Access, MFA, ID Protection, and device identity. John also leads the documentation efforts for Zero Trust content across Microsoft 365 and Identity teams. He actively collaborates with engineers and PMs to test pre-release features and engages with customers to refine technical guidance.

LinkedIn - https://www.linkedin.com/in/johnbflores/

Ravi Kalwani

Ravi is a Senior Program Manager at Microsoft, based in Sydney, Australia. With over 14 years of IT experience spanning technical training, support, consulting, and program management, his focus for the past five years has been on Enterprise Client and Mobility, specifically Microsoft Configuration Manager and Intune. Ravi is also an experienced public speaker, having presented at numerous technical conferences and delivered a wide range of workshops for both internal teams and enterprise customers.

LinkedIn - https://www.linkedin.com/in/rkalwani/

Tarek Dawoud

Tarek Dawoud is a long-time veteran at Microsoft, having been with the company for over 18 years. Tarek currently leads the architecture team within the customer engineering (CXE) organization, where he helps customers deploy Entra, gathers insights for the product group, and works to solve the hardest identity problems.

LinkedIn - https://www.linkedin.com/in/tarekdawoud/


🔗 Related Links

Zero Trust Assessment - Five minute walkthrough

Zero Trust Assessment Report

Sample report generated by the Zero Trust Assessment tool. Try aka.ms/zerotrust/demo for an interactive demo.

ZeroTrustAssessmentReport

📗 Chapters

00:00 Intro

01:11 The Origin Story: A Customer Breach

05:59 A New Way to Write Docs

08:55 Bringing Intune into the Story

11:07 How This Compares to Secure Score

14:46 Uncovering Insights with Sankey Charts

21:55 Behind the Scenes: How a Test is Built

36:18 Why We Target Privileged Access (AI Attackers)

39:59 The Myth of “Safe” Expired Credentials

42:35 Final Thoughts: “Please Run It”


Podcast Apps

🎙️ Entra.Chat - https://entra.chat

🎧 Apple Podcast → https://entra.chat/apple

📺 YouTube → https://entra.chat/youtube

📺 Spotify → https://entra.chat/spotify

🎧 Overcast → https://entra.chat/overcast

🎧 Pocketcast → https://entra.chat/pocketcast

🎧 Others → https://entra.chat/rss


Merill’s socials

📺 YouTube → youtube.com/@merillx

👔 LinkedIn → linkedin.com/in/merill

🐤 Twitter → twitter.com/merill

🕺 TikTok → tiktok.com/@merillf

🦋 Bluesky → bsky.app/profile/merill.net

🐘 Mastodon → infosec.exchange/@merill

🧵 Threads → threads.net/@merillf

🤖 GitHub → github.com/merill

Discussion about this episode

User's avatar