
Season 1
Endpoint Security and Privileged Access
James and Emma examine endpoint security across devices, servers, and privileged administration. This episode covers secure baselines, Microsoft Defender for Endpoint, local administrator controls, Active Directory protection, privileged access workstations, credential isolation, secrets, and the architectural decisions that limit lateral movement. Guest incident responder Owen Price shares the rule that privileged credentials should never visit lower-trust devices.Security Posture and Attack Paths
James and Emma explore how security architects measure and improve an organization's real security posture. Topics include attack paths, Microsoft Defender for Cloud, Secure Score, cloud security posture management, landing zones, prioritization, and turning findings into meaningful risk reduction. Guest cloud-risk architect Lena Ortiz explains why risk lives in paths rather than isolated findings. Includes recall pauses and exam-focused review.Regulatory Compliance and Security Architecture
James and Emma connect regulatory requirements to practical security architecture. This episode explains why compliance and security are related but different, how to map obligations to controls, collect useful evidence, apply Azure Policy, prioritize remediation, and reason about data residency and sovereignty. Guest compliance auditor Marcus Vale offers a memorable rule for treating compliance as a floor rather than a ceiling. Includes recall pauses and exam-focused review.Identity as the Control Plane
James and Emma examine identity as the primary control plane for modern security architecture. This episode covers authentication, authorization, Conditional Access, identity protection, workload identities, privileged access, emergency accounts, hybrid identity, and the design choices behind an identity-first Zero Trust strategy. Guest identity engineer Dr Priya Shah shares a memorable way to connect authentication, authorization, and telemetry. Includes recall pauses and exam-focused review.Security Operations: From Signals to Response
James and Emma explore how a modern security operations function turns signals into effective response. This episode covers Microsoft Sentinel, Defender XDR, SIEM and SOAR, automation, incident handling, threat intelligence, and the architectural choices that help analysts focus on the work that matters. Guest SOC lead Noah Patel explains why analyst attention is a finite defensive resource. Includes recall pauses, exam-focused explanations, and a lighter conversational review.