# Episode 109: Securing GenAI Applications with Entra (2 of 4) - Overpermissioning Page: https://stenobird.com/podcast/the-azure-security-podcast-993243/episode-109-securing-genai-applications-with-entra-2-of-4-overpermissioning Text version: https://stenobird.com/podcast/the-azure-security-podcast-993243/episode-109-securing-genai-applications-with-entra-2-of-4-overpermissioning.md Podcast: [The Azure Security Podcast](https://stenobird.com/podcast/the-azure-security-podcast-993243) Published: 2025-02-19T04:15:04+00:00 Episode link: https://rss.com/podcasts/azsecpodcast/1902670 Audio file: https://content.rss.com/episodes/8411/1902670/azsecpodcast/2025_02_17_22_51_13_0c186138-dc4d-45cd-9118-17d45fa6892c.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/the-azure-security-podcast-993243/episodes/episode-109-securing-genai-applications-with-entra-2-of-4-overpermissioning Duration seconds: 2277 ## Resource In this episode, Michael, Gladys and Mark talk to guest Bailey Bercik about the problem of overpermissioning and how to use Microsoft Entra Permissions Management to identify and manage over-permissioned identities in multi-cloud environments to reduce security risks, especially for AI apps. We also cover the latest security news about AI red teaming, Azure SQL DB logging, Azure Confidential Ledger, Star Blizzard spear-phishing campaign and CISA Zero Trust Maturity Model. https://aka.ms/azsecpod ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/the-azure-security-podcast-993243/episodes/episode-109-securing-genai-applications-with-entra-2-of-4-overpermissioning/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/the-azure-security-podcast-993243/episode-109-securing-genai-applications-with-entra-2-of-4-overpermissioning.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.