📍 Live from Times Square, New York City 🇺🇸 This was the first edition of Experts Live in the United States, and we couldn’t be more proud to be part of it!

We wrap up Season One with a special in-person recording from Microsoft’s office in NYC during Experts Live US.
No planning, no script – just good conversation, best practices, and bad Sentinel acronyms. 😉 Chris and Koos will both be talking about their sessions they gave at the event. Chris will discuss securitu baseline best-practices. And Koos will be sharing Sentinel tips from the field.




🔐 Security Baselines in Microsoft 365

Chris brought a fresh look at building, maintaining, and automating security baselines in M365 environments.

Why Baselines Matter

Not all security risks come from attackers—some come from insecure defaults and configuration drift. Chris explains the difference between:

“Most users don’t go in and change things. They just assume someone smarter than them chose the settings that are best for them…”

“The tyranny of the default” - Steve Gibson

The Security Baseline Lifecycle

Chris walked through his five-step model:

  1. Assess – Understand where your current security posture stands (warts and all)
  2. Define – Choose a framework (CIS, NIST, ISO) and define your secure baseline
  3. Implement – Put the controls and processes in place
  4. Monitor – Watch for drift and misconfigurations over time
  5. Improve – Feed real-world lessons back into your process

Tools & Demos

Chris demoed several tools including:

Start small. Focus on one domain (e.g., identity) and iterate.

Check out Chris’ slidedeck with a lot of valuable links here!


🌊 Getting the Most Bang for Your Logs – Again!

Koos couldn’t help himself—he brought more Sentinel content, including some very practical demos and updates on data lake, MCP Server, and cost-saving strategies.

Sentinel Cost Optimization

Koos shared a story from that very morning where a customer accidentally enabled Sentinel on an operational Log Analytics workspace—leading to an unnecessary €2,000/month bill. That’s why it’s important to really understand the pricing model and be aware of the different discounts that are available.

Automate Commitment Tier Management

Koos a plethora of practical tips and tricks from the field he gathered during the last years.

Sentinel data lake

Not just that Scooby-Doo meme but an actual game-changer: Sentinel data lake.

GitHub Copilot + data lake = Magic?

Koos previewed how GitHub Copilot can now query the Sentinel data lake using natural language KQL via MCP Server in VS Code:

“Give me all Graph activity from an app with this display name…”
Copilot brute-forced the AppId collection based of a DisplayName and generated a working query, pretty wild.

Some caveats:

Check out Koos’ slidedeck with embedded pre-recorded demos here!


🛠️ Community Project: Experts Live US: Vibes & Gratitude


🎙️ Finalizing our first season

It’s been a great year of podcasting! This unscripted episode was a fun way to wrap up Season One. Thanks for listening! Hope you see you again next year! 👋🏻