{"podcast":{"title":"Microsoft Mechanics Podcast","slug":"microsoft-mechanics-podcast-54050","podcast_index_feed_id":54050,"rss_url":"https://microsoftmechanics.libsyn.com/rss","website_url":"http://microsoftmechanics.libsyn.com/podcast","image_url":"https://static.libsyn.com/p/assets/a/2/c/8/a2c88acc220e584927a2322813b393ee/MM-Logo-Gradient.png","author":"Jeremy Chapman","episode_count":100,"summary":"Made for tech enthusiasts and IT professionals. Expanded coverage of your favorite technologies across Microsoft; including Office, Azure, Windows and Data Platforms. We'll even bring you broader topics such as device innovation with Surface, machine learning, and predictive analytics.","last_synced_at":"2026-07-15T04:17:11.768823+00:00","page_url":"https://stenobird.com/podcast/microsoft-mechanics-podcast-54050"},"episode":{"title":"Agent 365 | Security Operations in Defender","slug":"agent-365-security-operations-in-defender","published_at":"2026-05-29T01:20:00+00:00","page_url":"https://stenobird.com/podcast/microsoft-mechanics-podcast-54050/agent-365-security-operations-in-defender","show_page_url":"https://stenobird.com/podcast/microsoft-mechanics-podcast-54050","url":"https://microsoftmechanics.libsyn.com/agent-365-security-operations-in-defender","audio_url":"https://traffic.libsyn.com/secure/microsoftmechanics/Agent_365___Security_Operations_in_Defender.mp4?dest-id=411333","summary":"Surface every AI agent in your tenant and expose the ones throwing security signals — across both the IT and SOC view. Triage high-severity alerts as IT in the Microsoft 365 admin center, then pivot into the full incident graph as a SOC analyst in Microsoft Defender. Block malicious tool invocations the instant they fire and catch jailbreak attempts on Copilot Studio agents before they take hold. Trace a compromised user back to suspicious agent activity, then trigger Microsoft Entra conditional access to revoke the session and force a password reset straight from the incident. Hunt overpermissioned agents with pre-built advanced hunting templates — including one that exposes every agent running MCP tools on the maker's standing credentials — and pull risky builds from the Agent Store using the Agent Registry. Spencer Berg, AI & Security Product Manager, shares how to turn agent risk signals into coordinated remediation across Defender, Entra, and the Microsoft 365 admin center. ► QUICK LINKS: 00:00 - Stay in control with Agent 365 00:40 - Gain visibility with unified control plane 01:48 - Unified IT & SOC agent view 02:54 - Real-time blocking and jailbreak detection 04:08 - Auto-revoke via Entra conditional access 04:32 - Prevent future incidents 05:28 - Advanced hunting for AI agents 06:43 - Block risky agents 07:15 - Wrap up ► Link References Check out https://aka.ms/Agent365SecOps ► Unfamiliar with Microsoft Mechanics? As Microsoft's official video series for IT, you can watch and share valuable content and demos of current and upcoming tech from the people who build it at Microsoft. • Subscribe to our YouTube: https://www.youtube.com/c/MicrosoftMechanicsSeries • Talk with other IT Pros, join us on the Microsoft Tech Community: https://techcommunity.microsoft.com/t…","meta_description":"Surface every AI agent in your tenant and expose the ones throwing security signals — across both the IT and SOC view. Triage high-severity alerts as IT i…","key_points":[],"chapters":[],"topics":[],"duration_seconds":470,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/microsoft-mechanics-podcast-54050/episodes/agent-365-security-operations-in-defender/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/microsoft-mechanics-podcast-54050/agent-365-security-operations-in-defender.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}