Practical 365 Podcast - Microsoft 365, Copilot & Cybersecurity News & Discussions · Practical 365

On-Premises Pain, Copilot Curiosity, and a Glimpse into Global Secure Access: Practical 365 Podcast S04E38

·1 hr 3 min·4 clips
Published attacks against MCP tooling include stealing credentials and WhatsApp messages from a local machine.
1. Practical 365 Podcast S04E38 covers on-premises pricing, Copilot Studio, Microsoft Purview, and global secure access. 2. Steve Goodman hosts with Paul Robichaud, and Janice Ricketts joins as Microsoft product manager for global secure access. 3. The episode asks what Microsoft is changing for legacy on-prem products and how new AI and security controls are supposed to work. 4. Steve and Paul discuss Microsoft's 10% price increase for on-premises products and compare it with support costs for legacy software. 5. Paul says he was surprised to learn there are still substantial numbers of customers using Skype on-premises. 6. The hosts describe on-prem Exchange and Skype as products that stay supported while Microsoft's engineering footprint shrinks. 7. They argue that customers are paying for continued support, not major new feature development. 8. Steve and Paul shift to Copilot Studio support for model context protocol, which they describe as middleware for large language models. 9. They name Claude, OpenAI products, Llama, Azure, and desktop tools such as Klein and root code as MCP contexts. 10. Steve gives an example of one MCP tool that returns the state of current backups for connectors and items. 11. They explain that an LLM can combine MCP tools, such as using graph data from Meryl Fernando's Loca tool with backup actions in Keepit. 12. The discussion highlights that a user can ask for tasks like backing up all users in the Krakow office by combining multiple data sources. 13. Steve and Paul then move to MCP security concerns, including local code that runs with the user's permissions. 14. They mention published attacks that can steal credentials and even WhatsApp messages from the desktop client. 15. Paul notes that MCP lacks a Windows-style security model and that source-code review remains important for trust. 16. The hosts say Microsoft's Copilot Studio support is for the remote interaction model, not the local one. 17. They discuss Microsoft Purview inline protection controls for AI apps in Edge for Business and how Intune and Office Cloud Policy Service manage it. 18. Janice Ricketts describes her path from the Waterbleet Arsenal and Microsoft certification work to Microsoft product manager for global secure access. 19. The interview style is conversational and practical, with both hosts pressing on security, adoption, and operational reality. 20. Listeners who manage Microsoft 365, Copilot, security, or on-prem Exchange will get the most value, while people avoiding Microsoft platform details may skip it.

As heard by us

Practical Microsoft 365 discussion of Copilot, external services, and admin risk.

A Practical 365 episode keeps its focus on the awkward edge of modern Microsoft work: what happens when Copilot-style systems meet external services, user workarounds, and admin controls.

Read the full review in PlayNext →

Why you'd press play

Press play for a grounded Practical 365 episode 38 on Copilot Studio risk, external service connections, and the controls around them.

Read the full recommendation in PlayNext →
Listen to the show on