Sign in

Ru Campbell

@campbell.scot
845 followers 128 following 110 posts

Microsoft Security MVP + Microsoft Security Practice Lead at Threatscape Mostly: Entra, Defender, Intune, Purview, and Microsoft 365 Also: dad, metal, lifting, wrestling, cars Mostly on Twitter rather than here: @rucam365

PostsRepliesMedia
Ru Campbell @campbell.scot · 16/02/2026
New webinar THIS WEDNESDAY. If you want to really know what really secures the (blank) out of Entra in an hour, here's how. Big thanks to my marketing friends at @Threatscape for GenAI'ing me some hair back in this thumbnail too. REGISTER: www.threatscape.com/...
020
Ru Campbell @campbell.scot · 16/01/2026
Who wants to join my support group for losing sleep over token theft?
010
Ru Campbell @campbell.scot · 26/11/2025
Catching up with the AI Ignite news is like learning a new language. "Microsoft Badaboop is part of Microsoft Zublebeep, which you can find in Microsoft Talahoo, the Microsoft Ziggledeep for AI." (I do love it though.)
022
Ru Campbell @campbell.scot · 26/11/2025
Join me, @WillTheFrenchie, and @WelkasWorld TONIGHT, 1800-2000 UTC for the latest Microsoft security news and two awesome speakers: • @RyanJohnMurphy4 – The new Microsoft eDiscovery UI and UX • @sfennah – The Oversharing Solution Blueprint REGISTER: www.meetup.com/m365s...
000
Ru Campbell @campbell.scot · 18/11/2025
Actual screenshot from the Ignite Book of News.
100
Ru Campbell @campbell.scot · 31/10/2025
New video: 5 common Entra ID guests mistakes (Entra B2B) • excessive directory visibility • ignored cross-tenant defaults • untrusted MFA & device states • open SharePoint sharing • no guest lifecycle There's tons more! But here's a starter WATCH: youtu.be/AXuj-U9p3jU
041
Ru Campbell @campbell.scot · 29/10/2025
ICYMI: Microsoft Authenticator for iOS + Android will detect, prevent, then wipe Entra creds on rooted devices (MC1179154). • Phase 1 (warn mode) begins February '26 • followed by Phase 2 (block mode) • then Phase 3 (wipes Entra creds) • expected to be completed ~April '26
021
Ru Campbell @campbell.scot · 23/10/2025
The unified Defender for Identity sensor as part of Defender for Endpoint is now generally available :-) Docs: learn.microsoft.com/...
040
Ru Campbell @campbell.scot · 20/10/2025
Next M365 S&C UG - Oct 29, 18:00 UTC - @JoanneCKlein & Anna Bordioug: Two Sides of the Data Coin: Data Protection vs. Data Retention in Practice - @brand_gefahr: How Much is the Phish? An End-to-End Perspective on Phishing Operation REGISTER: www.meetup.com/m365s...
010
Ru Campbell @campbell.scot · 17/10/2025
New video: new Defender detections for jailbreaks + prompt injection in Microsoft 365 Copilot • recap on what jailbreaks and prompt injections are (examples) • how they show up in Defender for Cloud Apps/hunting and Purview WATCH: youtu.be/iCRYJ32fwro
010
Ru Campbell @campbell.scot · 10/10/2025
New video: deep dive on building Intune security baselines that actually work with legend of the game @SkipToEndpoint • why so many baselines are just plain bad • balancing security / usability • when to customise • how OIB makes it practical WATCH: youtu.be/Xe32TzHgueA
141
Ru Campbell @campbell.scot · 08/10/2025
Still time to sign up at aka.ms/EntraZeroTrust for the rest of the Entra Zero Trust Practitioner series. On 9 October, I'm joining @merill, @nathanmcnulty, and more for a live Q+A on everything Entra identity and network access.
010
Ru Campbell @campbell.scot · 02/10/2025
Among others in the Microsoft 365 stack, there is a new Defender icon! See them all: microsoft.design/art...
020
Ru Campbell @campbell.scot · 30/09/2025
New video: deep dive into Entra ID Governance with MVP @MattChatt42. • why identity is the front door • sources of authority (HR vs AD) • joiner/mover/leaver workflows • PowerShell scripts vs governance at scale WATCH: youtu.be/VVU2UhYaGzk
010
Ru Campbell @campbell.scot · 30/09/2025
Running in-person only (Edinburgh) ‘Mastering Microsoft Entra ID Security’’ on 6 Nov. 2hr Entra security deep dive for blue teams. Note this is exclusively for in-house security teams rather than other partners, MSSPs, etc. REGISTER: www.eventbrite.ie/e/...
000
Ru Campbell @campbell.scot · 24/09/2025
Folks, join us TONIGHT for the M365 Security & Compliance User Group Two killer sessions and lots of prizes: Denis Mutlu - Optimizing Log Management for Sentinel & MDXDR @ThomasVrhydn - Proactive Exposure Hunting with Enterprise Exposure Graph REGISTER: www.meetup.com/m365s...
100
Ru Campbell @campbell.scot · 04/09/2025
New video: an honour to join @HeikeRitter's Virtual Ninja Show discussing MDE policy management and deploying at scale: • personas + policy merge • rings and “critical time delay” • Live Response + RBAC • Effective settings WATCH: youtu.be/IvLNLcXRlrY
010
Ru Campbell @campbell.scot · 27/08/2025
Your scientists were so preoccupied with whether or not they could, they didn't stop to think if they should.
030
Ru Campbell @campbell.scot · 27/08/2025
Convenient reminder to stop what you’re doing and enforce browser extension allow listing.
042
Ru Campbell @campbell.scot · 19/08/2025
Heads up. Spotted by a colleague this morning: deception capabiliites in MDE are not making it past public preview.
000
Ru Campbell @campbell.scot · 18/08/2025
New video: Why your Defender update settings are risky - update types: engines, platforms, intelligence - what is Microsoft’s 'Safe Deployment Practices' (SDP)? - update rings in Defender (not just Windows) - balancing rollout risk vs. protection WATCH: youtu.be/trQv__-Z9-8
011
Ru Campbell @campbell.scot · 14/08/2025
Folks, working on two Defender books out this year and want to feature the best community tips. Defender for Endpoint In Depth 2nd Ed (w/ @Threatzman) Mastering Defender XDR 2nd Ed (w/ @Headburgh) So, drop your great MDE, MDO, MDI, MDA, and XDR tips here. Best get featured.
021
Ru Campbell @campbell.scot · 08/08/2025
New video: deep dive into Defender for Endpoint/Antivirus settings. - what every one really does - what “good” looks like - gotchas - nuances And why some of the important ones are “hidden”. Watch: youtu.be/R8btJ_SjwVk
131
Ru Campbell @campbell.scot · 07/08/2025
TIL that Purview parent sensitivity labels are being replaced by label groups (MC1111778). You can migrate using a wizard and by default it'll convert the parent label into both a group and a label within that group (to not risk removing an in-use label).
010
Ru Campbell @campbell.scot · 06/08/2025
I don’t think that’s the incentive LinkedIn thinks it is…
000
Ru Campbell @campbell.scot · 06/08/2025
TIL Entra ID Governance for guests is PAYG. Example: access review for inactive guests charged based on # guests in scope. So, charged on API events that include guests separate to usual 50K allowance. Max 1 charge guest/month even if multiple events. learn.microsoft.com/...
000
Ru Campbell @campbell.scot · 05/08/2025
TIL about Purview on-demand classification for Windows to discover + classify files at rest on devices (MC1106875). On-demand classification (PAYG) was previously limited to SPO + ODfB. Partially addresses a gap a lot of my customers ask about... will auto labelling follow? 🤔
000
Ru Campbell @campbell.scot · 31/07/2025
New video: 1hr of advanced Conditional Access deep dives with @NateHutch365 at @Threatscape. Covering nuanced scenarios like app allow listing, missing app management, and really stretching CA into some cool and uncommon uses. WATCH: youtu.be/DkCq8wWN9Sc
020
Ru Campbell @campbell.scot · 25/07/2025
New video: 5 best practices for Conditional Access. Kind of an inverse on my 5 common mistakes video. Point being: know what to avoid doing; while knowing what good looks like. Watch: youtu.be/drO5YFxZDyU
040
Ru Campbell @campbell.scot · 22/07/2025
More art than science.
050
Ru Campbell @campbell.scot · 17/07/2025
New video: understanding Copilot Studio, MCP, and generally the state of play for securing AI in Microsoft 365 with Microsoft's Graham Hosking. Watch: youtu.be/9JrBswGsUSw
010
Ru Campbell @campbell.scot · 10/07/2025
A hidden gem in MDE’s new effective settings page is revealing which admin-set values are ignored by tamper protection's enforcement of known good ones. For example, threat actions (quarantine, etc) are protected by TP which enforces response based on Defender definitions.
010
Ru Campbell @campbell.scot · 09/07/2025
News about Microsoft Authenticator backing up MFA to iCloud hit the message centre today, but if I'm reading this correctly, it doesn't apply to Entra MFA? >"Only account names and third-party TOTP credentials will be backed up"
010
Ru Campbell @campbell.scot · 07/07/2025
Trying so hard to use new Oulook as daily driver but it's honestly just brutal with no upside except the 'Quote' format button is neat.
010
Ru Campbell @campbell.scot · 24/06/2025
I can not and will not be stopped.
120
Ru Campbell @campbell.scot · 24/06/2025
Live only, no recordings, don't ask.
010
Ru Campbell @campbell.scot · 22/06/2025
In the process of writing two books on Defender and using dictation via @WisprFlow has really changed everything. It's more accurate than Windows' native transcribe feature (at least with my accent) and includes smart formatting like bullets and paragraphs.
100
Ru Campbell @campbell.scot · 20/06/2025
New video: Had a cool run through with @lukasberancz into the kind of gaps DART identify commonly in incident response, then a deeper dive on hardware based credential providers like macOS Platform SSO. WATCH: youtu.be/qZV3IeWsRd0
071
Ru Campbell @campbell.scot · 16/06/2025
Huge M365 news: “… powered by Azure Local, Microsoft 365 Local enables customers to deploy Microsoft productivity workloads like Exchange Server and SharePoint Server in their own datacenters or sovereign cloud environments…” Full announcement: blogs.microsoft.com/...
172
Ru Campbell @campbell.scot · 13/06/2025
Making sure I understand: It used to be Device Guard Configurable Code Integrity then Windows Defender Application Control then Application Control for Business but that's only when managed using Intune otherwise it's now Application Control for Windows. Have I got this right.
130
Ru Campbell @campbell.scot · 11/06/2025
Had a great discussion with Directions on Microsoft's @maryjofoley and @getwired.com on Security Copilot - strengths, weakness, hype, and reality. Directions does incredible work on Microsoft license guidance, so check it out. LISTEN: www.directionsonmicr...
154
Ru Campbell @campbell.scot · 05/06/2025
New video: As I've learned from a few incidents, app-to-app access is an attack path few teams monitor. Keith Fleming from the Defender for Cloud Apps team joined me to break down OAuth risks, SaaS security, and how app governance helps defenders. Watch: youtu.be/AcneWgWPp4Y
001
Ru Campbell @campbell.scot · 02/06/2025
New video: deep dive with David Mallet from Microsoft into new Defender for Cloud Apps capabilities that let you hunt (KQL) then control unknown gen AI use ('shadow AI') in your org. Watch: youtu.be/CMRmgj3o-r0
000
Ru Campbell @campbell.scot · 15/05/2025
Finding a great song late is both joy and regret, and makes me wonder what else I'm missing.
000
Ru Campbell @campbell.scot · 14/05/2025
New video: deep dive into Purview Insider Risk Management architecture (1 hour step by step guide) with @WelkasWorld • policy design and best practices • minimising false positives • Adaptive Protection integration with Conditional Access Watch: youtu.be/n1ll4UN32-s
000
Ru Campbell @campbell.scot · 30/04/2025
New video: 1 hour of Conditional Access design deep dive. I always get asked to share Conditional Access templates, so I roped @NateHutch365 into the first of a few long forms on thinking about robust, scalable, and customizable CA architecture. Watch: www.youtube.com/watc...
040
Ru Campbell @campbell.scot · 28/04/2025
Folks, hope you can join us on Wednesday for this month's user group - these speakers are absolute experts in what they do and you will learn a ton. It's not recorded, so join us live or miss out. REGISTER: www.meetup.com/m365s...
110
Ru Campbell @campbell.scot · 24/04/2025
New video: awesome interview with Shiva P of Microsoft DART (Incident Response) • learnings and advice for blue teamers based on real-world breach experience • four fundamental security weak spots • getting into an IR career Watch: www.youtube.com/watc...
030
Ru Campbell @campbell.scot · 16/04/2025
New video: continuing a super deep dive into Purview sensitivity labels with @WelkasWorld, covering almost every single label setting, their implications, and design decisions. Watch: youtu.be/6TaVptqv_V8
010
Ru Campbell @campbell.scot · 15/04/2025
How it feels watching cybersecurity vendors demoing their GenAI product.
010