S6E14 - Securing M365 with ScubaGear: A Deep Dive into CISA’s Assessment Tool
In this episode, we dive deep into ScubaGear, an open-source tool developed by the Cybersecurity and Infrastructure Security Agency (CISA) as part of the Secure Cloud Business Applications (SCuBA) project. Designed to assess Microsoft 365 (M365) tenant configurations, ScubaGear helps organizations align with CISA’s Secure Configuration Baselines (SCBs) to prevent costly misconfigurations. From setup to real-world applications, we unpack how ScubaGear strengthens M365 security and share practical tips for IT admins and security teams.
What You’ll Learn:
Why ScubaGear Matters: Learn how ScubaGear addresses the growing threat of cloud misconfigurations, which accounted for 30% of cloud attacks in early 2024. We discuss its origins in CISA’s SCuBA project, and its value for US federal agencies, private organizations, and critical infrastructure.
How ScubaGear Works: A technical breakdown of ScubaGear’s PowerShell-based workflow, using Microsoft Graph APIs and Open Policy Agent (OPA) to compare tenant settings against SCBs. We cover setup requirements.
Common Misconfigurations: Examples like disabled MFA or weak DLP policies, and how ScubaGear’s HTML, JSON, and CSV reports provide actionable remediation steps.
Best Practices: Tips for integrating ScubaGear into security workflows, including regular scans, policy customization, and combining with tools like Microsoft Secure Score.
Real-World Insights: Sam shares experiences from consulting.
What did you think of this episode? Give us some feedback via our contact form, Or leave us a voice message in the bottom right corner of our site.Read transcript
-------- Â
45:32
S6E13 - Security Copilot - Your Security Analyst's Assistant
Alan and Sam discuss the benefits and use cases of Security Copilot. Alan Dives into how Security Pilot works and what some of the capabilities are. Here are a few things we covered:
What is Generative AI
What is Security Copilot
What are Agents
How much does it cost?
What did you think of this episode? Give us some feedback via our contact form, Or leave us a voice message in the bottom right corner of our site.Read transcript
-------- Â
1:08:04
S6E12 - Microsoft updates April - new products and features released
This week, Alan and Sam talk about new features and services that have gone into Public Preview or General Available status in the last month. We dive into a couple of these updates that peaked our interest.
Some of the Microsoft product features and update we covered:
Key Microsoft Entra, Intune and Defender features and updates
Lots of Azure changes and new features
What did you think of this episode? Give us some feedback via our contact form, Or leave us a voice message in the bottom right corner of our site.Read transcript
-------- Â
53:28
S6E11 - Insights into Microsoft Secure 2025
This week, Alan and Sam talk about new features and services that have been announced at Microsoft Secure 2025
Some of the Microsoft product features and update we covered:
Security Copilot Agents
Data Security Investigations
Innovations in Microsoft Entra
Detection and protection for emerging AI threats
What did you think of this episode? Give us some feedback via our contact form, Or leave us a voice message in the bottom right corner of our site.Read transcript
-------- Â
54:05
S6E10 - Microsoft updates March - new products and features released
This week, Alan and Sam talk about new features and services that have gone into Public Preview or General Available status in the last month. We dive into a couple of these updates that peaked our interest.
Some of the Microsoft product features and update we covered:
Key Microsoft Entra, Intune and Defender features and updates
Lots of Azure changes and new features
What did you think of this episode? Give us some feedback via our contact form, Or leave us a voice message in the bottom right corner of our site.Read transcript
Listen with Alan Armstrong and Sam Foot as we talk about all things Microsoft Azure!
We are both technical consultants working with Azure day in, day out. Alan focuses on Identity and Security automation while Sam is a .NET developer deploying PaaS and SaaS solutions on Azure.
Each episode we have a topic we cover and we highlight some key news that we are interested in. No fluff, sales or products here, just two technical people having a light hearted chat.
Listen to Let's Talk Azure!, The AI Daily Brief (Formerly The AI Breakdown): Artificial Intelligence News and Analysis and many other podcasts from around the world with the radio.net app