In this episode of Entra.Chat, I dive into the critical world of app governance with experts Jay Gandotra and Sander Berkouwer, who unpack the hidden risks of non-human identities in Microsoft Entra.
From shocking real-world breaches like Midnight Blizzard to a hilarious tale of a theme park’s water supply mishap, we explore why securing your cloud apps is more urgent than ever. Tune in to discover practical tips and tools to safeguard your organization without losing your giraffes!
Subscribe with your favorite podcast player or watch on YouTube 👇
About Jay Gundotra
Jay is the CEO and technical founder of E-Now. He has a long history as an Exchange and Active Directory engineer, which led him to found his company and focus on solving complex identity and application governance challenges for enterprises.
LinkedIn - https://www.linkedin.com/in/jay-gundotra-19079a/
About Sander Berkouwer
Sander Berkouwer is a 17-year Microsoft MVP veteran and an accomplished identity architect. With deep expertise from being "in the trenches," he partners with Jay to educate the community and build solutions for managing non-human identities and service principals.
LinkedIn - https://www.linkedin.com/in/sanderberkouwer/
🔗 Related Links
AppGov Community - https://community.appgovscore.com/
Securing Workload Identities in Entra ID: A Practical Guide for IT and Security Teams
📗 Chapters
00:00 Intro
01:55 What is App Governance?
04:02 The Origin Story of Focusing on App Governance
08:35 Why App Security is Critical Today
14:15 The Dangers of Over-Privileged Apps
20:38 The Giraffe Story: When Cleanup Goes Wrong
24:42 What Should a Successful Organization Do?
30:22 The Full Application Lifecycle: Onboarding to Offboarding
35:38 Building the AppGov Community
45:04 The Importance of Education and Automation
Podcast Apps
🎙️ Entra.Chat - https://entra.chat
🎧 Apple Podcast → https://entra.chat/apple
📺 YouTube → https://entra.chat/youtube
📺 Spotify → https://entra.chat/spotify
🎧 Overcast → https://entra.chat/overcast
🎧 Pocketcast → https://entra.chat/pocketcast
🎧 Others → https://entra.chat/rss
Merill's socials
📺 YouTube → youtube.com/@merillx
👔 LinkedIn → linkedin.com/in/merill
🐤 Twitter → twitter.com/merill
🕺 TikTok → tiktok.com/@merillf
🦋 Bluesky → bsky.app/profile/merill.net
🐘 Mastodon → infosec.exchange/@merill
🧵 Threads → threads.net/@merillf
🤖 GitHub → github.com/merill