Skip to content
Artwork for RunAs Radio
TechnologyBusinessCareers

RunAs Radio

Richard Campbell

RunAs Radio is a weekly Internet Audio Talk Show for IT Professionals working with Microsoft products.

Play
  • 27 episodes
  • weekly
  • Avg 35 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • #1056
    Yesterday · 33 min

    AI and Penetration Testing with Paula Januszkiewicz

    How is artificial intelligence changing cybersecurity and penetration testing? Richard talks to Paula Januszkiewicz about how her team now uses large language models throughout the security workflow, from vulnerability research and data analysis to penetration testing and incident response. Paula explains that AI hasn't replaced security professionals, but it has dramatically accelerated the work, making it possible to analyze more data, build better tools, and identify attack paths faster than

  • #1055
    September 23 · 39 min

    Building Agents with Andrew Connell

    Microsoft offers a surprising number of ways to build agents in Microsoft 365. Which one should you choose? Richard talks to Andrew Connell about the evolving Microsoft 365 Copilot landscape and the four major approaches to building agents. Starting with SharePoint Agents for document-focused scenarios, Andrew walks through Agent Builder inside Microsoft 365 Copilot, the increasingly popular Copilot Studio in the Power Platform ecosystem, and the often-overlooked Agents Toolkit for VS Code. Alon

  • #1054
    September 16 · 35 min

    Patching in 2026 with Susan Bradley

    How has patching changed in 2026? Richard chats with patching goddess Susan Bradley about what she's seeing in vendor patches and how they're affecting consumers and businesses. On one hand, you have the security risk of unpatched servers, which puts a lot of pressure on sysadmins to deploy patches immediately. And, at the same time, the number of patches has grown massively as tools like Anthropic's Fable have revealed far more vulnerabilities. Then there are the vendors that are slow to get fi

  • #1053
    September 9 · 28 min

    State of WSUS with Adam Marshall

    Windows Server Update Services (WSUS) was deprecated in Sept 2024 - when does it go away? Richard talks to Adam Marshall about how WSUS is still an essential service for Configuration Manager, included with Server 2025 and V.Next - it's not going anywhere! Adam talks about the use cases WSUS covers that no other update solution does, especially granular control of updates and offline scenarios. And while Microsoft is still feeding updates into the WSUS stack, no new code is going into the soluti

  • #1052
    September 2 · 36 min

    Reimagining Intranets with Susan Hanley

    How does AI change the intranet? Richard chats with Susan Hanley about her work helping organizations build great intranets and how tools like M365 Copilot are changing the intranet. Susan talks about the new reality of an intranet, where some users no longer go to the intranet directly but use an agent to retrieve the information they need. This impacts search statistics, but also means it's important to write pages that an agent can easily understand. The conversation also dives into the bane

  • #1051
    August 26 · 31 min

    Security Features of PowerShell 7 with Mike O'Neill

    How secure are your PowerShell scripts? Richard talks to Mike O'Neill about the powerful security features introduced with PowerShell 7.3 and above, including session configuration files and clean blocks. Mike talks about how some organizations are strict about installing anything on servers, including the latest version of PowerShell - which is one of the reasons 5.1 has persisted so long. But that ends with 26H2 and opens the door to securing your PowerShell with strict controls over accounts,

  • #1050
    August 19 · 38 min

    Automatic Attack Disruption with Liz Tesch

    What if Microsoft Defender not only detected attackers - but also fought back? Richard talks to Liz Tesch about Microsoft Defender Automatic Attack Disruption and Predictive Shielding. Liz talks about how attacks are often detected before the payload executes, but by the time humans can respond, far more damage has been done. Automatic Attack Disruption acts immediately on detection to limit the attacker by locking accounts, restricting access on a compromised server, and more. Predictive Shield

  • #1049
    August 12 · 40 min

    The Content Management System Landscape with Matt Garrepy

    What is the state of content management systems today? Richard chats with Matthew Garrepy of CMS Critic about his views on how the CMS market continues to evolve. Matt digs into the build-vs-buy conversation that has been going on since the web first emerged - now made more complex with the power of the large language model to generate code. The evolution toward headless CMS brings up the idea of the explosion of different places that a CMS needs to touch now - not just web pages. The landscape

  • #1048
    August 5 · 37 min

    Ransomware Readiness with Heather Renze

    The risk of ransomware is real - are you ready? Richard talks with Heather Renze about her experiences dealing with a ransomware attack and how to get prepared when it happens to you. Heather talks about how ransomware has evolved into a business that has operators, affiliates, and even tech support. Making a plan is essential - involving finance, legal, and IT. Cyberinsurance plays a big role, as do regulatory bodies - it depends on the business you're in. But your plan needs to know three esse

  • #1047
    July 29 · 34 min

    Azure Virtual Desktop Hybrid with Travis Roberts

    More ways to use Azure Virtual Desktop! Richard chats with Travis Roberts about how Azure Virtual Desktop continues to evolve and provides more options for remote users. Travis talks about how AVD grew out of Terminal Services and so is still very much an IaaS offering - as opposed to Windows 365, which is more PaaS, with less flexibility, but easier deployment. But when you need control, AVD is the way to go, and today will operate in Azure, on-premises via Azure Local. And if you've got an exi

  • #1046
    July 22 · 37 min

    Security Begins at Procurement with Jessie Schofer

    Bringing new software or SaaS into your organization is a security risk - how do you assess it? Richard chats with Jessie Schofer about her experiences in HR software acquisition, which led to the creation of secureless.ai. Jessie tells the story of evaluating various SaaS and other software products and realizing that, while the website says they are compliant with GDPR and/or SOC 2, are they really? This leads to a conversation about the product procurement process and about actually understan

  • #1045
    July 15 · 38 min

    Finding Security Vulnerabilities using AI with Sami Laiho

    How are large language models changing the way security vulnerabilities are found? Richard chats with Sami Laiho about the rapidly changing landscape in security exploits. Certain LLM models like Anthropic's Mythos and Microsoft MDASH are optimized to find software vulnerabilities - and potentially fix them. And so there is an arms race of sorts, repairing old vulnerabilities before LLMs in the hands of black hats can exploit them. But what about everyone else? Sami talks about getting LLMs work

  • #1044
    July 8 · 35 min

    Implementing Azure Policies with Barbara Forbes

    How can Azure Policies help you? While at Techorama in Belgium, Richard sat down with Barbara Forbes to discuss how Azure Policies have evolved and the techniques sysadmins are using to improve security, cost controls, efficiency, and more. Barbara talks about how the default policies are designed to get folks started in Azure quickly - not necessarily optimally. And there are plenty of policy templates out there, but before you implement them, it's worthwhile to review each policy and ask the q

  • #1043
    July 1 · 36 min

    AI-Accelerated Supply Chain Attacks with Mackenzie Jackson

    How are supply-chain attacks evolving? Richard chats with Mackenzie Jackson about his work helping companies protect their software supply chains from malware attacks. Mackenzie discusses the vulnerability of developers to attacks, since their accounts are often highly privileged and invariably contain access to exploitable secrets. The conversation digs into the challenges of securing various code distribution mechanisms like npm and how you can protect your organization - starting with, don't

  • #1042
    June 24 · 34 min

    Securing Developers with Tanya Janca

    How can sysadmins help software developers work securely and make more secure applications? While at NDC in Toronto, Richard sat down with Tanya Janca of SheCodesPurple to discuss what admins can do to help address the security challenges software developers face. Tanya talks about securing development environment and pipelines - developers routinely work from high privilege accounts because their tools require it, and as a result, have become the targets of black hats to get access to accounts,

  • #1041
    June 17 · 37 min

    47 Day Certificates with Todd Gardner

    The 47-day certificate is coming! While at NDC in Toronto, Richard received an update from Todd Gardner about his show last year: certificate authorities are moving toward SSL certificates that last only 47 days! Todd talks about the first decrease in duration that has already passed - as of March 2026, the longest duration certificate you can buy from certificate authorities is 200 days. At the core of these changes is the problem that certificate revocation just isn't working properly, so a sh

  • #1040
    June 10 · 36 min

    How Machine Learning Fails with Megan Robertson

    What can go wrong with machine learning? While at NDC in Toronto, Richard chatted with Megan Robertson about her experience with machine learning projects, often using retail datasets, and where they can go wrong. Megan talks about getting clear expectations and metrics for projects, so you know when you succeed, but then digs into the specifics of problems in machine learning, such as overfitting on test data. Your results are only as good as the data you put in, so a lot of focus goes into bui

  • #1039
    June 3 · 36 min

    Data API Builder and SQL MCP with Jerry Nixon

    How do you intelligently surface access to your database? While at NDC Toronto, Richard spoke with Jerry Nixon about Data API Builder, Microsoft's tool that enables data professionals using Microsoft databases, including SQL Server, Postgres, CosmosDB, and MySQL, to provide an API layer with security, schema extraction, and governance policies. You can expose the API as a REST interface, a GraphQL interface, and an MCP server! This is a powerful tool for providing controlled access to data while

  • #1038
    May 27 · 35 min

    Team Productivity using Loop with Karinne Bessette

    How can Microsoft Loop make your team more productive? Richard chats with Karinne Bessette about the role that Loop components can play in making meetings where the agenda is live, generating work items in Microsoft Planner, and keeping key information up to date. Karinne talks about how Loop components can be connected to any M365 document, including Outlook, Word, Excel, and OneNote, but only for members of the M365 tenant. Loop is a powerful tool for productivity within the organization!

  • #1037
    May 20 · 37 min

    UEFI Secure Boot with Richard Hicks

    The original Secure Boot certificate expires in June 2026! Richard talks to Richard Hicks about how Secure Boot works and how the expiration of the master certificate can leave PCs vulnerable to boot-related malware, such as rootkits. Richard discusses recent Microsoft communications on SecureBoot and how to check which certificate your machines have. Workstations using managed updates are likely already up to date, but servers are a different issue. When the certificate expires, you'll no longe

Showing 1–20 of 27 episodes