Merill Fernando πŸ’š

@merill.net

Product Manager @microsoft | Creator of bluesky.ms β€’ cmd.ms β€’ idPowerToys.merill.net β€’ Graph X-Ray β€’ πŸ‡¦πŸ‡Ί β€’ πŸ‡±πŸ‡° β€’ Posts my own http://youtube.com/@merillx Sign up to my newsletter https://entra.news

🚧 Folks, we’re planning a major architecture change for Maester 3.0: a native test model with structured metadata, simpler contributions, centralized prerequisite handling, and compatibility for existing Pester tests. We want your feedback before finalizing the design πŸ‘‡

RFC: A Maester-native test model for Maester 3.0 Β· maester365/maester Β· Discussion #2050

RFC: A Maester-native test model for Maester 3.0 Status: We have decided on the overall direction, but the design and migration experience are still open for community input. We are planning a sign...

github.com

I’ll be honest. Purview has always felt like someone else’s part of the Microsoft security stack. I’m an Entra person. Ray Reyes isn’t, and that’s why I wanted him on Entra.Chat The lines between our products and teams are disappearing.

Bild

I was explaining how Microsoft Entra Staged Rollout works and realised it would make a great video especially the under-the-hood details that aren’t in the docs. A quick 7-minute walkthrough is coming soon. What would you like me to cover? πŸ‘‡

Bild

The best time to set up security tests for your Entra tenant is when you create it The next best time is today πŸ˜‰ I'm spinning up Entra External ID tenants for maester.cloud (my SaaS solution), & every one gets Maester baked in from day one πŸ”₯ Maester monitoring Maester Cloud. As it should be 1/3

Bild

One compromised Agent ID blueprint can become a multitenant blast radius. That is the most important idea in my latest conversation with Katie Knowles, Senior Security Researcher at Datadog, about her three-part security analysis of Microsoft Entra Agent ID. Watch or listen: https://entra.chat

Bild

AI agent risk is not just attackers using AI. It is attackers targeting the agent ecosystem most orgs cannot see yet: MCP servers, skills, packages, API keys, tool calls, and prompts. I talked with Thomas Roccia about the new blind spot: 1/8

Bild

Tiny AI workflow hack that saves me every day Pin your top 3 active chats and give each one an emoji. Now you can switch contexts instantly without hunting through old threads. Works with ChatGPT, Codex, Claude, Cursor, GitHub CP or any tool where projects pile up. Simple, but underrated.

Bild

AI agents should not get a blank check to your tenant. I added experimental Guardrails to Lokka.dev so you can limit model-driven Microsoft Graph/Azure calls by HTTP method, API path, tenant, or specific resources. βž• When something is blocked, Lokka shows exactly why and where to fix it.

Bild

For years, "secure" meant MFA + a compliant device. AI agents just broke that. They decide and act faster than any human the split-second of latency that used to give you time to react is gone. An agent can run away with your data before you read the alert. 1/3

Bild

πŸ‘‹ Lokka Guardrails is a new feature coming to the MCP server πŸ™ This puts you in control of what the AI can do. The problem with Graph permission scopes is they are too broad. Now you can apply more precision to what is allowed even if it has a token with all the perms. 1/2

Bild