Everyday Defender

Everyday Defender

by Chris & Koos
Season 2
02x07-b2c_you_later.auth
In this episode: Koos recently had to help a customer getting their Entra ID External ID connected to the SOC and discovered that it wasn't as straightforward as you might think. Let's revisit what Entra ID External ID is in the first place, and how it differs from the former B2C it replaced. Chris talks about why it's never been more important to patch your stuff and digs into the relationship between patch management and vulnerability management. Full show notes available on our blog: https://df3ndr.io/episodes/2026/08/01/02x07-b2c_you_later.auth.html Follow us on your favorite podcast platform or check us out at https://df3ndr.io
02x06-silence_of_the_logs.kql
In this episode Chris takes a look at Exchange-attribute Source of Authority (SOA) transfer - could this finally be the answer to removing that last Exchange server we've all been waiting for? Koos has spent years deep in Microsoft Sentinel, and a big chunk of that has been log ingestion and keeping the ingestion bill under control: getting the right data in, keeping the noise out. He promised this wouldn't turn into the Sentinel show, but when Microsoft ships two genuinely new log-ingestion features, he has to talk about them. There are two Azure Monitor previews worth talking about. The first, 'multi-stage transformations', lets you filter and aggregate logs before they're ingested. The second brings platform logs into the Data Collection Rule model, the same way he already collects everything else. He'll cover what's genuinely new, and why he thinks Microsoft perhaps highlighted the wrong features in their blogs. Full show notes available on our blog: https://df3ndr.io/episodes/2026/07/01/02x06-silence_of_the_logs.kql.html Follow us on your favorite podcast platform or check us out at https://df3ndr.io
02x05-maester_of_puppets.ps1
Live and face-to-face again, this time recorded from Experts Live Netherlands. Chris previews his EL:NL session on practical SecOps for Microsoft 365: how to automate the boring-but-critical parts of M365 security operations, continuously assess tenant posture, detect configuration drift, and respond to common issues using native Microsoft tools you already own. Koos recently went on a hunt for a compact FIDO2 security key and discovered there are a lot more options out there than you'd think. He'll walk through what he found, what the trade-offs are between form factor, protocols, and price, and which keys ended up making the shortlist. Full show notes available on our blog: https://df3ndr.io/episodes/2026/06/06/02x05-maester_of_puppets.ps1.html Follow us on your favorite podcast platform or check us out at https://df3ndr.io
02x03-azure_fridays_but_its_us.now
In this episode Koos discusses the Odido data breach in The Netherlands by hacker group Shinyhunters, one of the largest public data leaks in Dutch history. Touching on vishing, misconfigurations, and the importance of blocking Device Code Flow. Chris was inspired by a fellow MVP to take a look at common AD security mistakes and provides some detail on how to look for these in your environment. Full show notes available on our blog: https://df3ndr.io/episodes/2026/04/02/02x03-azure_fridays_but_its_us.now.html Follow us on your favourite podcast platform or check us out at https://df3ndr.io
02x02_you_shall_not_pass.key
In this episode, Chris take a look at PowerShell modules and how managing M365 and Entra ID has changed over the years. And Koos likes to re-visit Passkeys. This is not new and we covered it earlier in our very first episode in December of 2024. But quite a few things have changed since then and he believes now is the time to start onboarding at scale. Full show notes available on our blog: https://df3ndr.io/episodes/2026/03/01/02x02_you_shall_not_pass.key.html Follow us on your favourite podcast platform or check us out at https://df3ndr.io
02x01_scu_later_alligator.json
In this episode, Chris explores Agent 365 while Koos takes another look at Security Copilot. Since our last episode, several new announcements have dropped, making this a great time to dive in and see how these tools can help streamline the work of security teams. Full show notes available on our blog: https://df3ndr.io/episodes/2026/02/01/02x01_scu_later_alligator.html Follow us on your favourite podcast platform or check us out at https://df3ndr.io
02x04-terminal_velocity.tui
In this episode Chris covers some common Intune deployment mistakes he's come across while working with various customer environments. Koos has become a full-time Claude (Code) user over the past months and wants to share why he's blown away. A few real-world stories where an AI agent saved the day. Or actually MULTIPLE days worth of work. ;). There's been a lot of talk lately about different models and multiple AI services seem to have been offering multiple different models to pick from. And even then; the same model can feel completely different depending on which "harness" it runs inside. Koos will explain what that is and why the right harness for the work you do matters more than the model sitting underneath it. Full show notes available on our blog: https://df3ndr.io/episodes/2026/05/01/02x04-terminal_velocity.tui.html Follow us on your favorite podcast platform or check us out at https://df3ndr.io
02x00_insert_disk_2.img
Trailer
Not your regular episode but an announcement for our upcoming second season. Chris and I share what we've been working in preparations for season 2, and what you can expect from us during the upcoming year. Follow us on your favorite podcast platform or check us out on [YouTube](https://www.youtube.com/@CloudArchitects/podcasts)
Season 1
01x12_df3ndr.eof.01.tar.gz
📍 Live from Times Square, New York City 🇺🇸 This was the first edition of Experts Live in the United States, and we couldn't be more proud to be part of it! We wrap up Season One with a special in-person recording from Microsoft’s office in NYC during Experts Live US. No planning, no script – just good conversation, best practices, and bad Sentinel acronyms. 😉 Chris and Koos will both be talking about their sessions they gave at the event. Chris will discuss securitu baseline best-practices. And Koos will be sharing Sentinel tips from the field. Full show notes available on our blog: https://df3ndr.io/episodes/2025/11/01/01x12_df3ndr.eof.01.tar.gz.html Follow us on your favourite podcast platform or check us out at https://df3ndr.io
01x11_trust_me_im_a_keyboard.hid
In this episode Chris asks "To block or not to block?" as he looks at geo blocking in Conditional Access, while Koos explores the human element in cybersecurity. Full show notes available on our blog: https://df3ndr.io/episodes/2025/10/01/01x11_trust_me_im_a_keyboard_hid.html Follow us on your favourite podcast platform or check us out at https://df3ndr.io
1 of 3