Microsoft Azure Archives - Inside Track Blog http://approjects.co.za/?big=insidetrack/blog/tag/microsoft-azure/ How Microsoft does IT Wed, 22 Jul 2026 22:14:38 +0000 en-US hourly 1 https://wordpress.org/?v=7.0.2 137088546 Streamlining business operations at Microsoft with an AI toolkit http://approjects.co.za/?big=insidetrack/blog/streamlining-business-operations-at-microsoft-with-an-ai-toolkit/ Thu, 23 Jul 2026 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=24720 At Microsoft, we manage one of the world’s largest global corporate operations. Our operations teams process hundreds of billions in revenue and millions of transactions while adapting to fast-changing business demands. Much of that work flows through Business Process Outsourcing (BPO) operations, where vendors support workflows such as order and agreement processing. As these processes […]

The post Streamlining business operations at Microsoft with an AI toolkit appeared first on Inside Track Blog.

]]>
At Microsoft, we manage one of the world’s largest global corporate operations. Our operations teams process hundreds of billions in revenue and millions of transactions while adapting to fast-changing business demands. Much of that work flows through Business Process Outsourcing (BPO) operations, where vendors support workflows such as order and agreement processing.

As these processes grew in scale and complexity, it became clear that improving something highly manual and already operating at massive scale would require a fundamentally different approach.

“With BPO, we’re dealing with high-volume, high-touch processes that are core to how the business runs,” says Jonathan d’Orgee, an AI transformation lead for Microsoft Business Operations.

For many organizations, the idea of overhauling a core business process can feel like a daunting step. At Microsoft we act as our own first customer, which gives us a way to test, refine, and de-risk that transformation in our own operations before bringing those proven patterns to customers. We call this approach Customer Zero.

In this case, that meant rethinking how high-volume operations could run better with AI directly embedded into day-to-day tasks, including building solutions using tools like Microsoft Dynamics 365 and Azure AI.

A photo of d'Orgee.

“We looked at manual steps, broken workflows, and disconnected systems as opportunities for AI transformation.”

Jonathan d’Orgee, AI transformation lead, Microsoft Business Operations

Identifying manual inefficiencies

On top of the complexity of handling so many transactions across the globe, Business Operations sometimes experienced periodic surges that could exacerbate inefficiencies. During these surges, the team would see a high volume of complex, time-critical transactions— especially at the end of the month or the quarter—and manual processes were too slow to keep up.

As we reviewed these inefficiencies, we looked for the most impactful use cases—places where we could integrate AI into workflows. To do this, we asked two important questions:

  • What types of transactions have the highest volume?
  • What parts of the process take the longest time or consume the most resources?

It was a classic case of the 80/20 rule—finding the 20% of the processes that required 80% of the work.

“We looked at manual steps, broken workflows, and disconnected systems as opportunities for AI transformation,” d’Orgee says.

An example might be where we receive an email asking to have a contract updated. In the former process, the email might sit there until a human could review it manually. Then someone would review it, direct it to the right queue, and assign it to the right person.  

“With AI in the workflow, emails and attachments are analyzed right when they arrive, and immediately assigned to the right queue and person,” d’Orgee says.

Taking these kinds of steps dramatically increased efficiency and reduced costs overall.

A photo of Venkata.

“With deep knowledge of our Business Operations ecosystem, we targeted high-volume, repeatable workflows across globally distributed operations. These were processes where AI could break traditional location and labor constraints, unlocking scalable automation and measurable business impact.”

Shashidhar Lanka Venkata, partner group engineering manager, Business Commerce Platforms

Configuring an AI toolkit

Once we’d identified the areas that were ripe for transformation, we set about developing an AI-driven solution on top of our existing critical workflow systems.

“With deep knowledge of our Business Operations ecosystem, we targeted high-volume, repeatable workflows across globally distributed operations,” says Shashidhar Lanka Venkata, a partner group engineering manager in the Business Commerce Platforms team. “These were processes where AI could break traditional location and labor constraints, unlocking scalable automation and measurable business impact.”

The BPO AI Toolkit is our AI operating system for business process operations. Its job is to help us with decision making. Built on Microsoft Dynamics 365 and Azure AI, it brings process mining, Microsoft 365 Copilot, Windows 365, and the Azure Marketplace together into AI-native workflows that can be reused by different vendors.

The toolkit is built on a handful of capabilities that work together:

Agentic memory turns tribal knowledge into structured operational intelligence that agents can access on demand.

Prebuilt agents provide enterprise-ready capabilities that teams can reuse instead of rebuilding workflows.

An agentic UI reduces context-switching time, helping operators focus on decisions and exceptions.

Digital Twins measures real end-to-end process performance and continuous improvement.

Agent Desktop provides secure access anywhere.

“It’s just part and parcel of working with AI, which is much different than working with more traditional ways of automating,” says d’Orgee.

He explains that because the AI is configurable, our teams are able to move faster. “The lead time is a lot shorter, and we’re able to make changes a lot more quickly.”

At the core of everything during this effort was the drive to constantly assess “the human buy-in:” How are people using this technology in a way that solves real problems at a global scale?

Keeping humans in the loop and measuring AI transformation

Integrating AI into existing workflows and processes isn’t just about the technology—it also should entail a cultural shift within an organization.

We wanted to ensure that our operations team was adopting the AI tools in the right way. That meant understanding which processes must still be human-led, such as areas where the handling of exceptions requires more discernment.

Rather than removing humans from the process, the team redefined the human role. AI now handles tasks such as data validation, case creation, and compliance checks, while our team members focus on judgment, exceptions, and continuous improvement.

“It’s really exciting for us, because operations has always been about trying to be efficient. With AI, it’s allowed for breakthroughs that we haven’t been able to achieve before.”

Jonathan d’Orgee, AI transformation lead, Microsoft Business Operations

That balance helped the team scale automation without losing the oversight and expertise needed to maintain quality.

The impact of this Frontier model has been significant. So far, we’ve been able to transform roughly a quarter of our BPO processes with AI. This has led to an 80% improvement in process quality and a 33% reduction in cost per transaction, d’Orgee says.  

More than 75% of the cases our teams work on are processed utilizing the AI toolkit. These gains are measured with Digital Twins, a process-mining model that monitors each workflow live, allowing teams to continuously track and improve. Building on this momentum, the team has plans to transform 80% of the BPO process with AI by fiscal year 2028.

A pie chart showing that more than 75% of our business-process cases are now assisted by an AI agent.

D’Orgee urges organizations that want to apply our Customer Zero learnings to their own workflows to look for high-volume, high-effort, highly manual work. This will lead you to the best opportunities for automating your processes at scale and deliver the most benefit.

From finance to sales operations, teams across Microsoft have turned to the BPO AI toolkit to prove how reusable AI capabilities can drive enterprise-wide transformation.

“It’s really exciting for us, because operations has always been about trying to be efficient,” d’Orgee says. “With AI, it’s allowed for breakthroughs that we haven’t been able to achieve before. I’ve just been thrilled to come to work on that front.”

Key takeaways

You can use these lessons and insights from our AI transformation of BPO to guide your own workflow transformation:

  • Identify inefficiencies and find processes with repeatability and scale. Look for highly manual workflows that could benefit from AI integration.
  • Use workflow capabilities that can be configured across different scenarios. An AI toolkit that spans multiple stages can form the foundation for significant improvements and time savings.  
  • Test and iterate, following up on improvements as you learn. This enables adaption of the development process beyond traditional automation.
  • Keep humans in the loop and leading the way. Identify workflows where human judgment and handling of edge cases must take precedence.

Try it out

Related links

The post Streamlining business operations at Microsoft with an AI toolkit appeared first on Inside Track Blog.

]]>
24720
Taming software licensing sprawl at Microsoft with an AI-driven solution http://approjects.co.za/?big=insidetrack/blog/taming-software-licensing-sprawl-at-microsoft-with-an-ai-driven-solution/ Thu, 09 Jul 2026 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=24605 It’s a common challenge at any large enterprise—important, related data scattered across the organization, residing in disconnected silos. If only there was an efficient way to pull them together into a single system to aid transparency and business decision making. Enter the power of sophisticated data tools and agentic AI.  A great example of this […]

The post Taming software licensing sprawl at Microsoft with an AI-driven solution appeared first on Inside Track Blog.

]]>
It’s a common challenge at any large enterprise—important, related data scattered across the organization, residing in disconnected silos. If only there was an efficient way to pull them together into a single system to aid transparency and business decision making.

Enter the power of sophisticated data tools and agentic AI. 

A great example of this came when our Microsoft Digital engineers and product managers were trying to get a handle on our sprawling software licensing landscape—thousands of third-party tools that our employees rely on in their work.

“We realized there were all these fragmented, scattered repositories of licensing data across many teams, all with different ownership,” says Ahmed Musa, a senior software engineer in Microsoft Digital, the company’s IT organization. “There was no visibility into what contracts existed or how they were being used. We needed a single solution.”

The answer was IntelLicense, an enterprise-wide intelligence platform that collects product information, licensing contracts, cost data, employee usage telemetry, and supplier details in one system. This all comes together in our Software Asset Management (SAM) portal, where we deliver enterprise-grade governance through a modern user experience.

A photo of Musa.

“IntelLicense is a game-changer for us. Before, internal software licensing was manual and labor-intensive—it could take months to make sense of the data. Now, an answer that used to take up to six months for us to track down can be generated immediately using this platform we’ve created.”

Ahmed Musa, senior software engineer, Microsoft Digital

Our IntelLicense platform uses the advanced capabilities of agentic AI to answer queries and generate insights on the data, giving us much greater understanding and visibility while enabling us to reduce license duplication, simplify procurement, and cut spending.

This benefits our employees who need to license software, our software asset managers, and our Procurement team, which manages the process on our back end to make sure the company isn’t wasting money and resources—especially considering the company makes significant annual investments in third-party software licensing.

This solution shows how at Microsoft we’re constantly looking for ways to apply AI to help solve enterprise-level challenges at scale—the hallmark of a Frontier Firm.  

“IntelLicense is a game-changer for us,” says Musa, the principal architect for the project. “Before, everything around internal software licensing was manual and labor-intensive,—it could take months to make sense of the data. Now, an answer that used to take up to six months for us to track down can be generated immediately using this platform we’ve created.”

Uncovering the challenge

With more than 200,000 employees working across over 100 countries worldwide, attempting to centralize information at an organization the size of Microsoft is never easy. The state of our third-party software licensing system was no different.

A photo of Chandra Pydimarri.

“As we looked beyond just employees finding software and deeper into the process, we began to see the challenge was also about purchasing, how we dealt with suppliers, and how we managed the licenses at a higher level. That’s where we saw the big opportunity.”

Revanth Chandra Pydimarri, senior product manager, Microsoft Digital

We began this journey nearly three years ago. The first big need we identified came from employee feedback that indicated it was difficult to figure out how to identify and license third-party software tools. But as we began to analyze the larger picture, we realized that the problem was much more layered and complex.

“As we looked beyond just employees finding software and deeper into the process, we began to see the challenge was also about purchasing, how we dealt with suppliers, and how we managed the licenses at a higher level,” says Revanth Chandra Pydimarri, a senior product manager in Microsoft Digital. “That’s where we saw the big opportunity.”

But by expanding the scope of the project, we were setting off on a long and technically daunting quest.

A photo of Selveraj.

“I think we counted 19 different systems that contained relevant licensing data. Working with all the different teams to pull that data together was the first big challenge we had to go after.”

Jay Selveraj, principal software engineering manager, Microsoft Digital

Tackling the data first

The first step was to gain visibility into all our third-party software contracts, our suppliers, and the actual product usage across the company. But our teams were operating in silos, each maintaining their own agreements and data about software licenses.

“This was fundamentally a data problem,” says Jay Selveraj, a principal software engineering manager in Microsoft Digital. “The enterprise data for license management is highly distributed, non-standard, and spread across the company. I think we counted 19 different systems that contained relevant licensing data. Working with all the different teams to pull that data together was the first big challenge we had to go after.”

A screenshot showing sample data from the IntelLicense Software Asset Management portal.
The Software Asset Management (SAM) portal gives our asset managers and procurement agents rich data insights into our third-party software licensing across the enterprise.

To fully understand the software asset management process, Selveraj and Chandra Pydimarri were charged with creating a journey map to show the steps, dependencies, and stakeholders involved.   

“It was a very daunting task for us,” Selveraj says. “We identified so many different bottlenecks. And that’s when we decided we can’t just troubleshoot the existing process—we needed to build a new platform that would span the enterprise.”

To accomplish this, they turned to Microsoft Fabric, which at the time was a relatively new product. Fabric provided the power and flexibility needed for this kind of project.

A photo of Ararso.

“Microsoft Fabric was designed as a unified data platform for engineers, making it an ideal fit for this project.”

Misrak Ararso, senior software engineer, Microsoft Digital

And as Customer Zero for Microsoft, we were excited to be early adopters of Fabric (it had just gone into public preview). The fact that we were able to try it out on a real enterprise challenge we were facing was both a strategic advantage and a bonus.

“Microsoft Fabric was designed as a unified data platform for engineers, making it an ideal fit for this project,” says Misrak Ararso, a senior software engineer in Microsoft Digital, who also worked on IntelLicense. “It has great features like Data Wrangler, which allowed us to drill down on the data and clean it up quickly. We also used Microsoft OneLake, which meant we avoided having to duplicate data before working on it.”

Ararso appreciates how Microsoft Fabric continues to evolve with new AI capabilities, making it an increasingly powerful and beneficial tool for data engineering.

“Early adoption wasn’t always smooth,” she says. “We encountered challenges, sharing feedback when we did, and we benefited from improvements as the platform matured alongside our implementation.”

Reducing waste and saving money in procurement

Before we developed IntelLicense, our Procurement team at Microsoft also struggled to answer basic questions about our software licenses.

A photo of Amiri.

“It was very difficult to gauge usage, consolidate agreements, and do cost optimization. And when we tried to audit our contracts and move licenses around, it all had to be done manually and took a lot of time and effort. IntelLicense addresses that.”

Rasa Amiri, senior sourcing manager, Financial Operations

The Procurement team is responsible for negotiating contracts, pricing, and terms and conditions with thousands of different suppliers. However, it can be difficult to negotiate volume discounts and manage the other aspects of licensing if you don’t have a holistic view across the enterprise.

In a typical example, one group at Microsoft might purchase 20 software licenses from a particular supplier, but then only use 15 of them. Another team needs 5 licenses, but they have no idea that there are unused licenses they could tap from the other group, so they purchase their own. And when an employee moves teams or leaves the company, their software licenses often go unused rather than get reassigned.

“It was very difficult to gauge usage, consolidate agreements, and do cost optimization,” says Rasa Amiri, a senior sourcing manager in our Financial Operations group. “And when we tried to audit our contracts and move licenses around, it all had to be done manually and took a lot of time and effort. IntelLicense addresses that.”

IntelLicense structure

UX layer

Role-based portal and embedded Copilot that surfaces software insights, recommendations, and actions for employees, software asset managers, and procurement specialists

AI layer

Multi-agent orchestration system that interprets user intent, calls plug-ins and APIs, and executes workflows

Data layer

Built on a unified Fabric/OneLake foundation that includes entitlement (contracts), provisioning (users/devices), and usage data

The IntelLicense solution consists of three parts: a UX layer, an agentic AI layer, and a data layer.

According to Amiri, one helpful feature of IntelLicense is the ability to see if a software license is not being used, and then directly contact that employee (or license owner) to say, “Hey, it looks like you’re not using this license. Can we reallocate it?”

“We have a real-time dashboard called the SAM portal that we can now use for that, focused on our top 200 suppliers,” Amiri says. “Now, every time we negotiate a deal, it’s uploaded into IntelLicense with all the details—the cost, the contract, the number of licenses. Not only does it help us with reallocation, it helps us quickly resolve issues we have with suppliers who want to charge us for overuse.”

Musa agrees.

“The IntelLicense platform can identify overlapping tools already in use and surface relevant alternatives, enabling more informed, cost-efficient decisions across the organization,” he says.

Introducing these kinds of efficiencies can quickly generate significant cost savings at an organization the size of Microsoft. Our internal data shows that IntelLicense drove substantial savings in software licensing fees over the last fiscal year. And we have greater ambitions for the future—Chandra Pydimarri cited industry studies that show up to 20% of third-party software spending is unnecessary. That’s huge potential savings for an enterprise organization.

A photo of Sengar.

“As we evolved the platform, we realized that users don’t want just another dashboard—they need decision intelligence. They need a system that can connect signals across datasets, surface actionable insights, and guide decisions in real time, so they can move faster and act with confidence.”

Urvi Sengar, senior software engineer, Microsoft Digital

Adding an AI layer

The Software Asset Management portal was a strong foundation for centralizing licensing data, but we wanted to take the solution further.

It was one thing to centralize and surface data with all the relevant data about third-party software licenses. It was a whole different challenge to build a system that helped the user understand the data, ask the right questions, and turn insights into decisions.

“As we evolved the platform, we realized that users don’t just want another dashboard—they need decision intelligence,” says Urvi Sengar, a senior software engineer in Microsoft Digital. “They need a system that can connect signals across datasets, surface actionable insights, and guide decisions in real time, so they can move faster and act with confidence.”

So Sengar and her fellow engineers set to work adding an agentic layer to IntelLicense that could provide those AI-driven insights. They used Microsoft Foundry to create a multi-agent solution that could handle all the various needs users of the system might have.

“With the multi-agent architecture that we followed, we have a workflow manager that delegates any user query to specialized agents,” Sengar says. “One agent handles license management, another deals with supplier management, another can support audit scenarios. Each agent understands the user’s intent and can call any deterministic workflows when needed.”

Sengar sees the agentic layer as the transformation of IntelLicense from a reporting tool into an intelligent system that can deliver contextual, on-demand insights and help users take action through workflows. It also aligns with the growing expectations for a more conversational, Copilot-like AI experience, where users can ask questions naturally and receive meaningful, actionable responses in real time.

“The platform delivers proactive insights through the portal while also enabling users to explore them on-demand, in the context of their work,” Sengar says.

She goes on to describe a scenario where a software asset manager is in the middle of negotiating a contract with a supplier. If they have a new idea, question, or strategy they want to validate, the portal can surface relevant recommendations and insights right away. If they want to go deeper, they can use the chat interface to ask questions and get instant access to the latest context-aware information in a dynamic way, without having to leave the flow of their work.

“That’s where we see the future of AI-driven work going,” Sengar says. “It’s using AI not only to surface insights, but to help people explore them further, act on them, and make better decisions faster.”

Applying intelligence across the enterprise

Large enterprise organizations like Microsoft face this kind of challenge in many areas: how to maximize efficiency by centrally managing a process that is scattered across many different teams and systems, with data that is often inaccessible or systems that are incompatible. Teams have often developed different ways of accomplishing the same task and are reluctant to change.

A photo of Selveraj.

“We want to make the biggest difference for the company—that’s the ultimate goal. At the end of the day, we want to make sure there is plenty of cost savings produced. Beyond that, we want to apply as much intelligence as possible to the problem, so that AI is impacting all aspects of the process.”

Senthil Selveraj, principal group product manager, Microsoft Digital

Our approach is to apply AI where it makes sense, using continuous improvement principles to guide us. We also look to our AI councils to make sure that we’re following best practices.

This ensures that when we at Microsoft Digital tackle something like software licensing, we’re going to achieve a transformational result that will pay big dividends across the company.

“We want to make the biggest difference for the company—that’s the ultimate goal,” says Senthil Selveraj, a principal group product manager in Microsoft Digital. “At the end of the day, we want to make sure there is plenty of cost savings produced. Beyond that, we want to apply as much intelligence as possible to the problem, so that AI is impacting all aspects of the process. That’s where we’ll see the largest, most impactful benefits.”

Key takeaways

If you are interested in ways to address third-party software licensing management at your organization, keep in mind these learnings from our own experience:

  • The more fragmented and complex the data problem, the stronger the case for agentic AI. Microsoft Digital used AI to unify disconnected licensing data and turn a sprawling challenge into a scalable solution.
  • Centralizing data was the foundation for this solution. By consolidating nearly 20 separate data systems into a single platform, IntelLicense gave us the visibility we needed to drive smarter decisions.
  • Agentic AI transforms static dashboards into dynamic decision-making systems. Instead of manually analyzing reports, our users can now query the system and receive real-time, context-aware insights.
  • Enterprise-wide visibility unlocks immediate cost savings and efficiency gains. IntelLicense reduced redundant licenses, improved reallocation, and saved over $16 million in a single year.
  • Embedding AI across workflows delivers impact at every level of the organization. From individual employees to procurement leaders, intelligent automation improves outcomes, speed, and user experience across the board.

Try it out

Related links

The post Taming software licensing sprawl at Microsoft with an AI-driven solution appeared first on Inside Track Blog.

]]>
24605
Digitally transforming Microsoft: Our IT journey http://approjects.co.za/?big=insidetrack/blog/digitally-transforming-microsoft-our-it-journey/ Thu, 18 Jun 2026 16:00:33 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=18521 The digital transformation of Microsoft spans the entire personal computing revolution, from the days of DOS and early Windows desktops, through our journey to the Azure cloud and into the era of AI and agents. Today, the company has grown into a global organization with more than 200,000 employees. They all rely on Microsoft Digital—the […]

The post Digitally transforming Microsoft: Our IT journey appeared first on Inside Track Blog.

]]>
The digital transformation of Microsoft spans the entire personal computing revolution, from the days of DOS and early Windows desktops, through our journey to the Azure cloud and into the era of AI and agents.

Today, the company has grown into a global organization with more than 200,000 employees. They all rely on Microsoft Digital—the company’s IT organization—to provide the tools, technologies, and solutions that empower them to accomplish more every day.

The need for digital transformation

The history of information technology is one of constant evolution, and the pace of change has never felt greater than it does right now. The AI capabilities and other groundbreaking innovations unveiled in the last few years show the potential to radically transform our world and change the way we think about and operate all IT services.

When the world pivoted to remote online work and collaboration because of the COVID-19 pandemic, it was just one example of how digital transformation doesn’t always happen in a straight line or on a predictable schedule. Our company’s history of shaping and adapting its IT organization to the latest challenges faced by employees and partners is no different; marked by big bets and strategic shifts that reflect our ever-changing world.

Mapping our IT journey

Timeline graphic shows the four eras of Microsoft IT (On-Premises IT, Cloud and Culture, Modern Engineering, and AI) along with major milestones in each era.
The four eras of digital transformation of IT at Microsoft : On-Premises IT, Cloud and Culture, Modern Engineering, and the Era of AI.

Today, Microsoft Digital is the team that powers, protects, and transforms the digital employee experience across all devices, applications, and hybrid infrastructure at the company. Using our deep knowledge and experience in enterprise IT, we’re pivoting to help lead the company’s AI transformation while also sharing our journey with customers so they can take advantage of this generational opportunity to reshape their businesses and IT operations.

To understand where we’re going, it helps to take a look at where we’ve been. This article explores the details of the major eras of our IT history and then shifts to examine the trendlines and technological innovations that are shaping Microsoft now.

On-Premises IT (founding to 2009)

It’s useful to break the history of our IT operations into different eras. For the first three decades or so from its founding in 1975, Microsoft operated with on-premises IT systems. This era was characterized by the setup, operation, and maintenance of onsite physical technology—servers, datacenters, and other hardware infrastructure.

During this time, IT roles were narrowly defined. IT team members functioned primarily as “order-takers,” with limited influence over strategic decisions.

Because funding was inconsistent, our IT organization had limited growth opportunities and relied on vendors for development work. Gaps were filled in with “shadow IT,” where internal teams would sometimes procure their own hardware or software without formal IT approval or standards.

We established security as an early priority for the company. Cofounder Bill Gates launched the Trustworthy Computing initiative more than two decades ago, an effort emphasizing the importance of security, privacy, and reliability across Microsoft products and services both internally and externally.

Our On-Premises IT era established the foundation that would become crucial to the company’s future digital transformation.

All in on the cloud: The Cloud and Culture era (2010-2018)

Image showing Ballmer presenting at an event, with Windows Azure and Azure DevOps logos overlaid on the photo.
Former Microsoft CEO Steve Ballmer led the shift to the cloud that began in the early 2010s.

Cloud computing marked the next significant shift in the history of IT at Microsoft. It began in 2010 under the leadership of CEO Steve Ballmer, signaling a major break with the previous era of physical IT infrastructure and an important step toward today’s distributed-computing world.

The launch of the cloud computing platform then known as Windows Azure heralded this new era, as we transitioned away from an IT philosophy focused on the Windows desktop client toward a more platform-agnostic view. Cloud computing offered extensive advantages for customers and for our own IT environment, in terms of cost, performance, security, and scalability.

We started our journey by moving productivity workloads (Exchange and SharePoint) to the cloud. Then, we shifted new development to Azure and optimized modern applications to run in the cloud. We also moved existing applications targeted for migration to virtual machines. Today, more than 98% of our IT workloads run on Azure.

Cultural transformation

Another important shift during this era was the profound cultural transformation at Microsoft sparked by new CEO Satya Nadella, who rose to the top job at the company in 2014. Nadella had previously run the Microsoft cloud computing and enterprise group, so he was already steeped in the idea of transformational change at the company.

A photo of Nadella.

“Achieving our mission requires us to evolve our culture. It all starts with a growth mindset—a passion to learn and bring our best every day to make a bigger difference in the world.”

Satya Nadella, CEO, Microsoft

Before Nadella’s ascension, Microsoft had long been known for its extremely competitive, “know-it-all” culture. Employees succeeded by showcasing their own individual achievements and how their accomplishments exceeded their peers.

Nadella changed this ethos by championing a growth mindset, encouraging employees to be “learn-it-alls” rather than “know-it-alls.” The shift included placing new importance on how employees contributed to the success of others, a value that was incorporated into individual performance reviews. Nadella made this transformation his personal mission and directed leadership to propagate the new philosophy at all levels across the organization.

“Achieving our mission requires us to evolve our culture,” Nadella says. “It all starts with a growth mindset—a passion to learn and bring our best every day to make a bigger difference in the world.”

The combination of the shift to cloud computing infrastructure and overhauling the company culture helped set the stage for the major technological innovations to come.

A new vision: The Modern Engineering era (2018-2023)

For years, IT at Microsoft had been order takers, doing what the business requested with limited ability to impact strategic priorities. That changed as we shifted to become a modern engineering organization. With support from our executive leadership, IT was elevated to become a peer engineering function at Microsoft.

Rather than simply taking orders, the team was empowered to lead with a strong vision for the future. In fact, leading with vision is the primary hallmark of our Modern Engineering era. As we moved into this era, we needed a clearly articulated view of our goals as an IT organization aligned to the needs of our business partners, as well as the resources needed to achieve them.

Role transformation

Transitioning to become a modern engineering organization required Microsoft Digital to adapt our legacy approach to IT.

Operating an engineering organization in a cloud environment meant new roles, new skills, and a new mindset. With no need to manage physical hardware, our modern IT professionals were freed to work more closely with business partners, requiring greater strategic acumen. The team was now focused on DevOps, Agile program management, and user-centric design principles.

User-centric, coherent design

Our design philosophy puts the user—an employee or guest—at the heart of every decision we make at Microsoft Digital.

The goal of this approach is to make tasks that might have previously caused friction to become simpler. Instead of dealing with disconnected systems, user-centric design introduces consistent and logical flow between services. This makes it easier for people to access services, learn how to use them, and then put them to good use.

Microsoft also embraces coherent design across all our products. A familiar look and feel, along with consistent usage patterns, accelerates employee usage and adoption. 

Embracing work-from-anywhere capability

During the pandemic, when our workforce was still fully remote, our organization was already starting to think about what the new hybrid workplace would look like when people started returning to the office. We identified three key dimensions of the employee experience:

  • Physical spaces: We partner with Global Workplace Services to plan and deploy meeting spaces with amazing digital capabilities that support an inclusive approach to hybrid productivity.
  • Digital capabilities: We keep employees productive and their digital environment safe and secure, no matter where they’re located or how they connect.
  • Culture: A strong partnership with HR ensures that digital experiences support our company culture.

Managing shadow IT with a culture of trust

Shadow IT is the unknown and unmanaged set of applications, services, and infrastructure that are developed and managed outside standard IT policies. Shadow IT typically crops up when engineering teams are unable to support the needs of non-engineering partners, a situation that could arise from a lack of available capacity or the need for specialized domain solutions. 

While earlier eras of our IT history focused on trying to prevent shadow IT, we are now concentrating on managing it. We use Azure best practices to optimize shadow IT and Microsoft 365 governance policies to ensure that our corporate security, privacy, and accessibility standards are met. We empower our employees to create whatever they need within our tenant, including PowerApps, SharePoint sites, Teams channels, or agents, mitigating the need for “shadow” solutions while also providing visibility into how our employees are using our own technology.

Learn how optimizing our Microsoft Azure usage is helping us manage our Shadow IT.

The Era of AI (2023 to present)

The latest chapter in the history of our organization’s digital transformation is defined by the integration of AI and agents into IT operations. AI is revolutionizing how Microsoft does IT at enterprise scale, driving efficiency and innovation across the board. From the apps, workflows, and services that power our employee experience to the network, infrastructure, and devices that enable employee productivity, our AI-focused investments provide a solid foundation for the innovations that we are constantly implementing. As we look at the future of Microsoft Digital, we’re focused on four key priorities: security, service fundamentals, acting as Customer Zero, and AI-powered innovation. We’re working to excel in all four domains with the help of our industry-leading AI capabilities.  

A photo of Fielder.

“Our mission is to power and protect Microsoft, and that starts with an unwavering commitment to the Secure Future Initiative.”

Brian Fielder, vice president, Microsoft Digital

Securing our future

Security is our highest priority. The Microsoft Secure Future Initiative aligns every team with a shared approach, common priorities, and consistent milestones to harden our security posture across all products and services.  

“Prioritizing security above all else is critical to our company’s future,” Nadella says. “Every task we take on—from a line of code to a customer or partner process—is an opportunity to help bolster our own security and that of our entire ecosystem. If you’re faced with a tradeoff between security and another priority, your answer is clear: Do security.”

The Secure Future Initiative is built on three core principles: Secure by design, secure by default, and secure operations. As the company’s IT organization, we work relentlessly to fulfill the key pillars of the Secure Future initiative across all our systems, including:

  • Safeguarding identities and secrets
  • Protecting tenants and isolating production systems
  • Securing networks and engineering systems
  • Enhancing threat detection
  • Expediting response and remediation

“Our mission is to power and protect Microsoft, and that starts with an unwavering commitment to the Secure Future Initiative,” says Brian Fielder, vice president of Microsoft Digital.

Secure Future Initiative | Microsoft

Foundations: Service fundamentals

The second pillar is to maintain the highest standards of service fundamentals. These are the essential capabilities and practices that enable us to deliver reliable, secure, and compliant services companywide. Adhering to the highest standards of service fundamentals ensures that our organization continues to play a critical role in running the company’s business and enabling innovation, agility, and resilience in a fast-changing and competitive environment.

Customer Zero

The third pillar is acting as Customer Zero for Microsoft’s most important products and services, like Copilot Studio, Microsoft Teams, and Agent 365. In Microsoft Digital, we take pride in being the first customer for a wide variety of Microsoft products and services, relentlessly focusing on our own employee experience to create products that enable every person on the planet to achieve more.

Being Customer Zero means forging a deep partnership between our IT organization and product engineering groups to envision the right experiences, co-develop innovative solutions, and then listen to and act on insights gathered from our employees. We work together to stay grounded in the way our employees use our products every day, so your employees can benefit from our insights prior to external product launches.

Read about how we’re improving our employee experience through our Customer Zero focus.

AI-powered innovation

The final pillar of this era is innovating with AI to transform the digital experience at Microsoft. By doing all the fundamental work detailed above—security, foundations, and Customer Zero—extremely well, we gain the confidence and earn the trust necessary to embed AI across our full portfolio of services. We do this over three key dimensions: core IT services, employee experiences, and corporate functions.

Core IT services: Transforming and securing our network and infrastructure

We’re focused on using AI to infuse data-driven intelligence into every part of our infrastructure and network operations. This allows us to optimize operations and increase security while simultaneously improving outcomes.

Examples include:

  • Network observability and governance: Ensuring data accuracy, eliminating non-compliant hardware and software, and real-time updates
  • Securing endpoints: Device management, asset management, and patching
  • Zero Trust networking: Isolating device classes and limiting attacker’s movements across the network
  • Network access: Azure VPN, identity management, and Secure Access Workstation (SAW) infrastructure security

Learn how we’re transforming our enterprise IT operations at Microsoft.

Core IT services: Tenant management

We manage one of the most complex tenants anywhere. Governance today is a somewhat fragmented experience, with no clear mechanism for IT to safely enable self-service asset creation for sites, Teams, groups, Power Apps, and so on. These unmanaged assets increase the risk of over-sharing sensitive data and compromise the health and security of our IT environment.

In the world of AI, security through obscurity is no longer a viable option. This means data hygiene, permission management, and data protection are essential to providing trustworthy AI tools that don’t overexpose sensitive content, while still providing quality responses.

Read about one way we’re improving security by protecting elevated-privilege accounts at Microsoft.

Core IT services: Support

We’re using generative AI to transform the way our employees interact with our support services. IT issues will be either auto-remediated or resolved remotely and instantly through conversational, personalized, and contextualized solutions, often without a human agent’s intervention.

We’ll accomplish this with a focus on the following:

  • User experience: Our employees are using the AI-powered Employee Self-Service Agent to access personalized, accurate, and cost-effective issue resolution. Future goals include implementing a seamless transition to a human agent while the user stays within the agentic Copilot experience.
  • Human agent experience: Operational efficiency and automation are being integrated into the Service Operations Workspace. The service includes chat and incident summarization that recommends best next actions and drafts contextual answers to queries.

Find out how we’re transforming IT support at Microsoft with AI and the Employee Self-Service Agent.

Defragmenting the employee experience

The second dimension where we’re implementing our AI vision to make a difference is our employee experience. Our vision is to deliver a unified, connected, and personalized experience where users can access employee data, tools, and insights from one place.

A photo of Alaparthi

“We see AI as the key to unlocking the full potential of our employees, delivering personalized experiences that empower us to work smarter, faster, and happier—unleashing the innovation and collaboration necessary for our success.”

Vijaya Alaparthi, principal group product manager, Microsoft Digital

One of the key ways we’re doing this is with Microsoft 365 Copilot, which functions as a “UI for AI” across our employee tools and services. An example is our Employee Self-Service Agent, an AI-driven tool based on Copilot that helps employees more efficiently find context-specific answers to their questions using natural language queries.

“We see AI as the key to unlocking the full potential of our employees, delivering personalized experiences that empower us to work smarter, faster, and happier—unleashing the innovation and collaboration necessary for our success,” says Vijaya Alaparthi, a principal group product manager in Microsoft Digital.

To achieve our vision, we’re building a workplace where AI defragments the employee experience by:

  • Providing contextual support in the flow of work
  • Reducing the number of sites and apps an employee must remember
  • Using Microsoft 365 Copilot as the “UI for AI,” making it simple for employees to find information, take action, and even fully automate certain repeatable tasks

Corporate functions growth

Our third major priority in Microsoft Digital is to improve how we support the company’s corporate functions organizations, including legal and real estate and facilities.

A photo of West.

“With AI, we have so many new ways to innovate. From optimizing building occupancy, to streamlining commute services, to automating contract and document management, we have incredible potential to make our corporate functions more efficient and impactful.”

Becky West, principal group product manager, Microsoft Digital

This is a particular challenge, as these teams are being asked to do more with less today; Microsoft can no longer afford to grow operational costs at the same rate as in the past.

AI is playing a fundamental role in transforming the business workflows of our corporate functions partners while improving operational efficiency, user productivity, regulatory and corporate compliance, and data-driven decision making. It’s revolutionizing the way they operate by automating repetitive and time-consuming operational tasks.

“With AI, we have so many new ways to innovate,” says Becky West, a principal group product manager in Microsoft Digital. “From optimizing building occupancy, to streamlining commute services, to automating contract and document management, we have incredible potential to make our corporate functions more efficient and impactful.”

Some of the corporate functions taking advantage of AI capabilities and related increased efficiencies include:

  • Real estate and facilities: In supporting the technology needs for more than 500 company buildings worldwide, we are poised to use AI and related innovations to implement cost savings in the areas of workspace systems, facilities management, and space management.

Find out how we’re transforming facility operations at Microsoft with AI maps.

  • Travel and expense: Our plan is to work for near-elimination of the traditional expense reporting process through AI-based and touchless experiences, driving simplification and productivity gains.

Check out how OneExpense transformed our employee expense reporting.

  • Legal: Our vision for integrating AI into Corporate, External, and Legal Affairs (CELA) includes more discoverable legal findings, better corporate document management with the Docufy platform, enhanced engagement with Microsoft Philanthropies, and accelerated support for business-critical functions such as immigration, contracting, and insider trading compliance.

Read how AI is revolutionizing the way we support corporate functions at Microsoft.

Agentic AI: Becoming a Frontier Firm

This era of AI in IT has quickly morphed into a world in which agents are having major impacts across the enterprise. Microsoft Digital plays a central role in helping the company embrace this change and transform into a Frontier Firm: an organization that has deeply embedded AI and agents into its operations, products, and culture

As a Frontier Firm, we go beyond simply adopting AI as a discrete tool or additional technology. We’re actively integrating intelligent systems, rich data platforms, and human knowledge into a unified operating model, where automation, decision making, and innovation combine to spark acceleration at scale. Agentic AI is a core enterprise capability for us, powering everything from employee productivity to customer experiences and strategic decisions.

As Microsoft progresses into this agentic AI future—where autonomous or semi-autonomous AI agents understand context, take actions, and collaborate alongside humans—Microsoft Digital has played a lead role in deploying these capabilities internally. We’ve led the early adoption of tools like Microsoft 365 Copilot, Azure AI services, and custom-built agents that help us automate repetitive tasks, surface insights, and orchestrate workflows across systems while enforcing strict governance policies. Examples include AI-powered agents that assist in IT service management, network monitoring, and enterprise knowledge retrieval, which allow employees to focus on higher-value work and maximize their individual impact.

As AI agents continue to grow in power and functionality and become more deeply integrated into the daily workflows of knowledge professionals, Microsoft IT will maintain our leadership role and operate at the bleeding edge of this technological revolution. 

A catalyst for change and growth

Microsoft’s digital transformation is a story of evolutionary change, resilience, and adaptation across multiple eras of information technology. From our origins as a traditional IT organization to becoming a modern engineering organization focused on driving AI-powered innovation, we in Microsoft Digital remain a catalyst for change within the company and our industry.

With our insights born from customer and employee obsession, we’re committed to streamlining IT operations while prioritizing security, revolutionizing user services, and facilitating corporate functions growth and development. All with the overarching goal of making Microsoft employees everywhere more productive while showing our customers and partners what’s possible as we move forward together into the future of IT.

Key takeaways

Our IT digital transformation story offers valuable lessons for organizations in the midst of their own IT journey. They include:

  • Be vision-led: A clear, articulated vision is crucial for driving transformation.
  • Foster a growth mindset: Encourage continuous learning and adaptability among employees (“learn-it-all” culture).
  • Invest in people: Upskill and reskill your workforce to keep pace with technological advancements and emphasize diversity of skills and experience.
  • Insist on security: Prioritize security in all aspects of operations to safeguard data and maintain trust.
  • Focus on collaboration and partnership: Create successful hybrid work environments to foster strong partnerships across functions.
  • Seek continuous improvement: Learn from the past and use those lessons to shape the future.
  • Embrace AI: Take advantage of AI tools and technologies to drive efficiency, innovation, and security.

Try it out

Related links

The post Digitally transforming Microsoft: Our IT journey appeared first on Inside Track Blog.

]]>
18521
Microsoft CISO advice: Securing AI with full stack red teaming http://approjects.co.za/?big=insidetrack/blog/microsoft-ciso-advice-securing-ai-with-full-stack-red-teaming/ Thu, 04 Jun 2026 15:30:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=23971 At Microsoft, we approach security for AI systems holistically using a full stack red teaming that goes beyond just testing an AI model. Corporate Vice President of red teaming at Microsoft Craig Nelson describes what he looks for with this method, “I’m interested in the model, but I’m also interested in how that model connects […]

The post Microsoft CISO advice: Securing AI with full stack red teaming appeared first on Inside Track Blog.

]]>
At Microsoft, we approach security for AI systems holistically using a full stack red teaming that goes beyond just testing an AI model.

Corporate Vice President of red teaming at Microsoft Craig Nelson describes what he looks for with this method, “I’m interested in the model, but I’m also interested in how that model connects with underlying additional data. And then how that model also executes automation from the back end.”

In this video, Nelson explains why securing AI requires more than testing the model alone.

Watch this video to see Craig Nelson describe how Microsoft approaches full stack red teaming. (For a transcript, please view the video on YouTube: https://www.youtube.com/watch?v=68MmP084rXA.)

Key takeaways

When you apply full stack red teaming to AI, here are some key questions to answer:

  • How are AI models connecting to data sources?
  • What backend automation do we allow AI to execute?
  • What security credentials do we require?
  • Do we have logs you need to understand how the model works with our backend infrastructure?

The post Microsoft CISO advice: Securing AI with full stack red teaming appeared first on Inside Track Blog.

]]>
23971
Transforming our approach to sensitivity labels at Microsoft with Microsoft Entra http://approjects.co.za/?big=insidetrack/blog/transforming-our-approach-to-sensitivity-labels-at-microsoft-with-microsoft-entra/ Thu, 28 May 2026 17:30:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=22681 Security groups serve as the backbone of our approach to access control across the Microsoft corporate tenant. These groups determine who has access to different resources across our network, including Azure subscriptions, Power BI reports, SharePoint sites, and more. For years, our security groups operated without consistent, policy‑based guardrails. As a result, we couldn’t uniformly […]

The post Transforming our approach to sensitivity labels at Microsoft with Microsoft Entra appeared first on Inside Track Blog.

]]>
Security groups serve as the backbone of our approach to access control across the Microsoft corporate tenant. These groups determine who has access to different resources across our network, including Azure subscriptions, Power BI reports, SharePoint sites, and more.

For years, our security groups operated without consistent, policy‑based guardrails. As a result, we couldn’t uniformly control guest access to sensitive resources or apply governance consistently across different group types.

Addressing this required a complex, coordinated effort by our team here in Microsoft Digital, the company’s IT organization, and the Microsoft Entra product team.

A photo of Johnson.

“Because IT security is our highest priority at Microsoft, we knew we needed a better approach to limiting access to groups within our tenant. And we realized that Microsoft Entra was a powerful in-house solution that represented our best path forward to solve for this challenge.”

David Johnson, principal product manager architect, Microsoft Digital

The result is a new approach to sensitivity labels across the organization that strengthens our security posture, which benefits Microsoft and our customers.

“Because IT security is our highest priority at Microsoft, we knew we needed a better approach to limiting access to groups within our tenant,” says David Johnson, a principal product manager architect in Microsoft Digital. “And we realized that Microsoft Entra was a powerful in-house solution that represented our best path forward to solve for this challenge.”

Closing the security gap

Sensitivity labels for Microsoft 365 groups are labels that govern join and access restrictions for membership and sharing. They have been a product feature since 2020. But sensitivity labels for security groups—labels that enforce rules about who can join a group—had no equivalent.

This meant that organizations that wanted to govern who could join a security group or determine if guests are permitted and how group membership is managed had to either lock down the group creation process entirely, or rely on reactive scanning after the fact.

“Security groups are a key piece of our efforts to secure sensitive resources,” says Mohit Bhargava, a principal product manager on the Microsoft Entra team, which manages the Entra family of identity and network access products. “We wanted to apply policies to protect who could be in security groups so that the sensitive resources in those groups would remain secure.”

A photo of Kakumani.

“Whoever gets into an Azure security group can have access to all the resources associated with the Azure subscription. That’s a potential high-severity threat.”

Basanth Kakumani, software engineer II, Microsoft Digital

The security risk is real. If an unauthorized guest account ends up as a member of a security group that governs access to an Azure subscription, that guest gains access to every resource inside that subscription.

“Whoever gets into an Azure security group can have access to all the resources associated with the Azure subscription,” says Basanth Kakumani, a software engineer II in Microsoft Digital. “That’s a potential high-severity threat.”

Another priority was the need for consistency across experiences.

“Microsoft 365 groups have supported labeling for a very long time,” Bhargava says. “Customers have an expectation that there’s parity across group types, so that they can govern them uniformly. That was another driving factor for this work.”

Security groups reuse the same sensitivity labels already configured for Microsoft 365 groups and SharePoint sites in Microsoft Purview—so admins don’t need to create or manage a separate set of labels. This reuse reduces configuration overhead and supports a more consistent governance model across group types.

Security workarounds, and why they fell short

Without sensitivity label support, we had to make do with alternative solutions. The most common one was simply preventing certain users from creating any security groups at all.

In the Microsoft tenant, this meant that employees who needed a security group had to fill out a form that had custom business logic behind it.

“We had on-premises, Active Directory, synchronization, tooling, and customization,” Johnson says. “This caused latency, from the time you created your group to the time it would show cloud membership. If you wanted to manage your membership, you had to do it on premises, AD, and then wait for it to sync to Entra.”

Neither centralized control nor reactive governance was a satisfying solution to prevent policy violations.

“This is really about making reactive things more proactive. We want to catch problems before they occur.”

John Begley, principal software engineer, Microsoft Digital

Typically, IT is going to manage this in one of two ways: Either we turn off self-service and manage everything on behalf of users, or we do reactive governance, which includes scanning groups and looking for policy violations.

Those aren’t super effective at preempting violations.

“This is really about making reactive things more proactive,” says John Begley, a principal software engineer in Microsoft Digital. “We want to catch problems before they occur.”

A collaborative solution

Coming up with a solution to this challenge required a genuine partnership.

We at Microsoft Digital approached the Entra product team and explained the problem we were trying to solve. Rather than simply handling this as a feature request, the two teams agreed to a co-development arrangement.

“Having access to a very large customer who cares deeply about security was extremely helpful. If it works for Microsoft, which is so complicated and huge, it’s going to work for smaller-sized tenants too.”

Mohit Bhargava, principal product manager, Microsoft Entra

Microsoft Digital team members would work alongside Entra engineers as the feature was built, serving simultaneously as implementation partner, design critic, and test environment—what we like to call our Customer Zero role.

Bhargava found the partnership equally illuminating from the product side.

“Having access to a very large customer who cares deeply about security was extremely helpful,” he says. “If it works for Microsoft, which is so complicated and huge, it’s going to work for smaller-sized tenants too.”

For Begley and his team, working closely with the product team revealed how complex the solution actually was.

“Both the product team and Microsoft Digital walked into this thinking a fix was going to be simpler than what it turned out to be,” Begley says. “It’s been eye-opening to see how the product is built, how it runs, what all the moving parts are. We learned early on that there was significant co‑development happening within Entra itself, across teams with very different areas of expertise.”

That dynamic played out in specific feature decisions. The team’s original plan did not include support for agent access controls and didn’t include the ability to prevent AI agents from joining sensitive security groups. This is something the product group quickly addressed and resolved after our team in Microsoft Digital raised it as a concern.

“One of the first customers who raised it was Microsoft Digital,” Bhargava says. “They said we needed need to start thinking about it ahead of time to get ahead of the problem.”

Sensitivity labels for Microsoft Entra cloud security groups are now in public preview. The same labels you publish in Microsoft Purview for Microsoft 365 groups and sites now apply to Entra security groups. Visit Microsoft Learn for scope, supported scenarios, and current preview behaviors.

Changes afoot for IT admins and employees

The practical impact of this solution lands on both sides of the relationship between Microsoft Digital and the company’s employees.

“Now I can’t accidentally have guests in an internal-only group, which changes the dynamic. Employees can create their own Entra security groups now, without us having to worry that they’ll be inviting guests where they shouldn’t be.”

David Johnson, principal product manager architect, Microsoft Digital

For IT admins, the shift is from reactive remediation to proactive prevention. For employees, it means self-service action with security groups become viable again, without the security risks that made organizations reluctant to enable it before.

“Now I can’t accidentally have guests in an internal-only group, which changes the dynamic,” Johnson says. “Employees can create their own Entra security groups now, without us having to worry that they’ll be inviting guests where they shouldn’t be.”

Johnson underscores the broader ambition behind the shift, which is to allow employees to create and manage groups directly in Entra.

“A company that can unblock self-service action by its employees with confidence, knowing that there’s an additional level of protection—that’s very important,” he says.

Looking ahead: AI and the expanding policy surface

Labeling support for security groups is already being extended across the organization, with AI governance in mind.

Adding the ability to block agents from joining sensitive security groups is our next logical step. Guest membership is enforced via allow-to-add guest policy, but agents won’t join in the same way. Rather, we will set policies in Purview and then use labels to control if an agent can join a group.

The longer-term vision involves extending oversharing prevention beyond Entra itself. This will make it impossible (not just detectable) to accidentally assign a highly confidential resource to an unlabeled or inappropriately scoped security group. The foundation we’ve built with labeling in Entra is what makes this vital step possible.

“We want to get into the preventative aspect,” Johnson says. “The goal is to make it so it’s not possible to overshare in the first place.”

Key takeaways

Here are some tips as you consider ways to address how you manage your own security labeling practices:  

  • Reuse existing labels—no extra setup required. Security groups reuse the same sensitivity labels already configured for Microsoft 365 Groups and SharePoint sites in Microsoft Purview, eliminating duplicate configuration and helping admins apply a consistent governance model across group types.
  • Understand label immutability at launch. Unlike Microsoft 365 Groups, sensitivity labels on security groups are initially immutable—a deliberate design choice to ensure protections are enforced from the moment a group is created. Controlled label mutability will be introduced in a subsequent update.
  • Know what’s in scope today. Labeling currently applies to static, non–mail-enabled security groups. Dynamic membership groups, mail-enabled security groups, and distribution lists aren’t supported at launch, so admins should plan accordingly.
  • Shift from reactive cleanup to proactive protection. Label-driven membership controls prevent policy violations—such as unintended guest access—before they occur, reducing the need for post-creation audits and remediation.
  • Enable safe self-service with guardrails. With labels enforcing access rules automatically, employees can create and manage security groups without increasing risk, restoring self-service without sacrificing control.
  • Lay the foundation for future governance scenarios. Using sensitivity labels as the backbone of access policy creates a scalable framework that can extend to additional protections over time, including broader enforcement and emerging governance needs.

The post Transforming our approach to sensitivity labels at Microsoft with Microsoft Entra appeared first on Inside Track Blog.

]]>
22681
Reinventing hybrid cloud integration at Microsoft—from months to one day http://approjects.co.za/?big=insidetrack/blog/reinventing-hybrid-cloud-integration-at-microsoft-from-months-to-one-day/ Thu, 28 May 2026 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=23843 For years, network engineering teams at Microsoft have faced a paradox: They can spin up a full Microsoft Azure cloud environment in a matter of hours but connecting that environment to on-premises labs and private networks can take up to nine months. Now, a team in Microsoft Digital—the company’s IT organization—is working to shrink that […]

The post Reinventing hybrid cloud integration at Microsoft—from months to one day appeared first on Inside Track Blog.

]]>
For years, network engineering teams at Microsoft have faced a paradox: They can spin up a full Microsoft Azure cloud environment in a matter of hours but connecting that environment to on-premises labs and private networks can take up to nine months.

Now, a team in Microsoft Digital—the company’s IT organization—is working to shrink that lengthy nine-month timeline to a single day.

The problem is architectural.

As our cloud footprint has grown, it has evolved into something richly segmented, tightly secured, and increasingly automated—a far cry from the relatively flat, monolithic corporate network that we originally extended into the cloud.

Getting those two worlds—on-premises and the cloud—to talk to each other securely and efficiently has become one of our most stubborn infrastructure challenges.

The solution we’re building is a fundamentally new operating model for hybrid cloud integration. It’s powered by AI-driven intake, end-to-end automation, and a set of repeatable patterns that treat the cloud as the new core of the network, rather than a distant branch of the old one.

The gap between cloud speed and network complexity

To understand the problem our team in Microsoft Digital set out to solve, it helps to understand how our company’s network architecture evolved over the past decade. When Microsoft first embraced Azure, the cloud was conceived as an extension of the existing corporate network.

A photo of McCleery.

“We have a development assembly line, and our goal is to give engineers the most efficient, frictionless experience doing software development for the company. Every day we delay solving this issue systemically is another day for the problem to get bigger.”

Tom McCleery, principal group cloud network engineering manager, Microsoft Digital

But the cloud grew faster than anyone anticipated.

Product engineering teams, drawn by the speed and flexibility of cloud-native tooling, began self-organizing their systems in Azure. They built segmented, purpose-built environments optimized for security and automation that looked nothing like the sprawling on-premises network they were supposed to connect to.

This shift had real consequences for Microsoft developers.

A software engineer sitting in building 32 on campus, for example, might have her Azure environment provisioned in half a day. But if she needed network connectivity to a physical Azure Stack lab down the hallway, getting that connection established—through firewalls, virtual routing frameworks, access control lists, and cross-team coordination—could take weeks or months.

“We have a development assembly line, and our goal is to give engineers the most efficient, frictionless experience doing software development for the company,” says Tom McCleery, principal group cloud network engineering manager in Microsoft Digital. “Every day we delay on solving this issue systemically is another day for the problem to get bigger.”

Why on-premises networks aren’t going away

Why not simply move everything to the cloud?

For Microsoft, the answer comes in many forms. As a company we build physical hardware, requiring hundreds of on-premises labs for software and hardware testing. We operate conference rooms, badge readers, thermostats, and wireless access points that will always require a physical network presence.

More fundamentally, Microsoft as a company hosts the cloud itself. If Azure were ever to go offline, our engineers responsible for recovery would need robust on-premises access that doesn’t rely on the very infrastructure they’re trying to restore.

Compounding all of these challenges are security requirements introduced by our Secure Future Initiative (SFI). The drive to reduce lateral threat movement across our network—limiting how far an attacker could reach if they compromised a single identity or device—has pushed our teams toward increasingly segmented environments. For our developers, that segmentation has meant navigating multiple networks, maintaining multiple identities, and juggling Yubikeys, smart cards, and authenticator apps just to move from one system to another.

The challenge, in short, is not that our network has too many pieces to be easily connected, it’s that those pieces weren’t designed to talk to each other efficiently.

This is what we had to fix.

Automation, patterns, and the path to ‘A Customer a Day’

Raghavendran Venkatraman is the principal engineering manager in Microsoft Digital who first pitched the vision of delivering a hybrid infrastructure in a single day.

A photo of Venkatraman.

“If we are not fast enough, our customers are going to outpace us and do it themselves—and they may not be adhering to all our enterprise security standards. The faster we deliver reliable infrastructure, the higher their confidence in us.”

Raghavendran Venkatraman, principal engineering manager, Microsoft Digital

The concept, which the team calls “A Customer a Day,” is built around the idea that it’s possible to deliver hybrid connectivity within 24 hours of finalizing requirements. Gathering, validating, and completing those requirements is where the team had to put their focus.

“If we are not fast enough, our customers are going to outpace us and do it themselves—and they may not be adhering to all our enterprise security standards,” Venkatraman says. “The faster we deliver reliable infrastructure, the higher their confidence in us.”

Three sequential domains of opportunity were identified, each a distinct bottleneck in the process. They all boasted impressive potential for improvement:

AI-driven unified intake

Customer describes requirements once. AI interprets and routes to the right pattern—no human coordination needed.

Replaces: Weeks of cross-team meetings before any build begins.

Predefined network patterns

A catalog of validated blueprints matches each request to a proven solution—no custom work from scratch.

Replaces: One-off negotiations restarted for every customer engagement.

End-to-end automation

A single workflow deploys from Azure all the way to the on-premises endpoint—no manual handoffs between teams.

Replaces: Days or weeks of manual steps after the cloud build is finished.

The result of these three innovations was the ability to make hybrid infrastructure live in one day, not months.

AI-driven unified intake. Today, when an engineering team needs hybrid connectivity, they become the conduit between multiple groups—networking teams, architecture teams, program managers, and security reviewers—that each have their own requirements, timelines, and vocabularies. The intake process alone can consume weeks of meetings before any actual implementation begins. The new model replaces that with an AI-powered interface that captures requirements directly from the customer, interprets them, and routes them to a predefined deployment pattern.

Predefined network patterns. Most hybrid workloads map to a small set of repeatable architectures. Rather than treating each onboarding as a custom engagement, the team has catalogued the most common hybrid connectivity scenarios and translated them into repeatable, validated patterns. The patterns drive both the AI intake and the automation layer, creating a system where the right solution can be identified and deployed without starting from scratch each time.

“The long pole in the tent used to be just getting the infrastructure up and running, but we are now able to do that pretty fast,” McCleery says. “Now, the challenge is sitting down with our customers, figuring out their requirements, and interpreting those into tasks that we can go implement in a matter of hours.”

End-to-end automation. On-premises, transport, and cloud network automation operate separately, but one-day delivery requires unified, pattern-aware orchestration. An AI orchestration agent manages sequencing, dependencies, and exceptions, enabling the hybrid stack to deploy as a single pipeline instead of in fragmented steps.

“The key architectural insight we reached is that any code touching device configuration should come from the service lines that own those devices. That’s a DevOps boundary—you own the customer experience, you specify the requirements, and then you call upon what we’ve built to interact with the back end. That’s a fundamentally different way of thinking about hybrid automation, and it’s what makes the end-to-end build possible.”

Juan Jimenez, principal cloud network engineer, Microsoft Digital

This is the work that Juan Jimenez, a principal cloud network engineer on the team, has been driving with multiple engineering cohorts.

“The key architectural insight we reached is that any code touching device configuration should come from the service lines that own those devices,” Jimenez says. “That’s a DevOps boundary—you own the customer experience, you specify the requirements, and then you call upon what we’ve built to interact with the backend. That’s a fundamentally different way of thinking about hybrid automation, and it’s what makes the end-to-end build possible.”

Building consensus across the network stack

Perhaps the hardest part of getting to “A Customer a Day” has been organizational. Bringing together cloud networking teams, on-premises network engineers, identity teams, security stakeholders, and program managers around a common framework requires a level of cross-disciplinary alignment that is extremely difficult.

What has helped is having a clear, human-scale goal that everyone can immediately understand and rally behind. When Venkatraman first named the initiative “A Customer a Day,” something shifted.

“You go over to the identity folks and say we’re trying to get a customer onboarded in a day—they’re like, ‘That would be great!’” McCleery says. “Same thing with on-premises networking. That message is easier to land than going in and saying, ‘Your engineers need to learn more about cloud.’ That’s when people start taking mental health days.”

One of the deeper mindset shifts the team has also been working to drive is a redefinition of what connectivity means. Historically, connectivity meant simply the network. In a cloud-first, AI-accelerated world, that definition is no longer sufficient.

“Connectivity means network and identity—together,” Venkatraman says. “That is the new definition, but it is not prevalent everywhere yet. Any CIO or CTO should pivot their entire organization to think about it that way. Don’t have two separate teams making decisions in silos and then trying to integrate. Get them in the room together from the start.”

Where we are today, and what comes next

Our Microsoft Digital team is candid about where we are in the journey: We’ve made meaningful progress, but we’re not yet at the finish line. The near-term goal is to complete the first customer launch scenarios within the next quarter, followed by broader adoption of the pattern framework in the quarter after that.

The goal isn’t 100% automation. The team is clear that a portion of hybrid networking will always require the custom work that complex or security-sensitive scenarios demand.

“We’re always going to have a longtail of scenarios that need human judgment,” McCleery says. “But for the 80% of common scenarios, if a customer is going down the compliant, paved path, things should happen a lot faster.”

For a team that’s spent years watching the gap between cloud and on-premises connectivity grow wider, the prospect of closing it—one customer, one day at a time—feels less like a moonshot and more like a welcome, needed correction.

Key takeaways

If your organization is wrestling with hybrid cloud integration, here are concrete steps you can act on today, informed by what we’ve learned on our journey:

  • Audit your hybrid integration timeline. If connecting a new cloud environment to on-premises networks takes more than a few weeks, map where the delays actually live—requirements gathering, cross-team handoffs, on-premises automation gaps, or other issue. You can’t fix what you haven’t measured.
  • Redefine connectivity to include identity. Bring your network and identity teams into the same room before any hybrid integration project begins. Treating these as separate workstreams is a primary source of rework, security gaps, and delay.
  • Identify your most common connectivity scenarios and document them as repeatable patterns. Even before you build automation, codifying your top five to ten hybrid connectivity use cases into standard blueprints gives every team a shared vocabulary and an accelerated starting point.
  • Set a single, human-scale goal your teams can align on. A unifying outcome (like “integrate a new environment in one day”) is more effective at driving cross-team alignment than a technical mandate. Find the shared aspiration before prescribing the solution.
  • Extend cloud tooling and automation frameworks to your on-premises teams. Don’t wait for on-premises engineers to independently upskill on cloud-native tooling. Invest in democratizing that capability deliberately, or the automation gap between your two environments will continue to widen.
  • Design intake around your systems, not your customers. Any hybrid integration process that requires an internal team to act as coordinator between multiple groups is a bottleneck by design. Use AI-assisted intake to make the requirements capturing self-service and the routing automatic.
  • Promote the framework before the tooling is finished. Publishing your architectural principles and patterns early (even when implementation is still in progress) aligns teams, accelerates buy-in, and gives other organizations a head start on their own journey.

The post Reinventing hybrid cloud integration at Microsoft—from months to one day appeared first on Inside Track Blog.

]]>
23843
Supercharging network operations at Microsoft with AI-based unified network intelligence http://approjects.co.za/?big=insidetrack/blog/supercharging-network-operations-at-microsoft-with-ai-based-unified-network-intelligence/ Thu, 21 May 2026 15:30:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=23737 At Microsoft, our network engineers work across multiple systems, including topology views, telemetry dashboards, logs, incidents, tickets, and fragmented tools. They piece together signals from these sources to understand what’s happening during an incident, often under considerable time pressure. But this kind of fragmentation slows down reasoning. Engineers spend more time navigating tools than diagnosing […]

The post Supercharging network operations at Microsoft with AI-based unified network intelligence appeared first on Inside Track Blog.

]]>
At Microsoft, our network engineers work across multiple systems, including topology views, telemetry dashboards, logs, incidents, tickets, and fragmented tools. They piece together signals from these sources to understand what’s happening during an incident, often under considerable time pressure.

But this kind of fragmentation slows down reasoning. Engineers spend more time navigating tools than diagnosing issues.

To address this, the Microsoft Infrastructure, Networking, and Tenant organization in Microsoft Digital, the company’s IT organization, is building Infrastructure Graph (IGraph), a unified platform that brings topology, real-time telemetry, and operational context into a single view.

On top of this foundation, agentic capabilities enable AI agents to reason across these signals, surfacing insights, explaining issues, and recommending next steps. This shifts the experience from exploring data to making decisions faster and with greater confidence.

A photo of Sinha.

“Engineers increasingly face fragmented visibility. We wanted to unify live telemetry, topology, and context into one single intelligent visualization experience and show engineers what’s really important, so they don’t have to dive into oceans of data.”

Astha Sinha, product manager, Infrastructure, Networking, and Tenant team, Microsoft Digital

This visualization layer and intelligence platform provides a view of our entire Microsoft enterprise network—including more than 20,000 on-premises devices across 900 sites worldwide—to instantly surface the most critical issues and offer proactive recommendations to our engineers.

“Engineers increasingly face fragmented visibility,” says Astha Sinha, a product manager in the Infrastructure, Networking, and Tenant team in Microsoft Digital. “We wanted to unify live telemetry, topology, and context into one single intelligent visualization experience and show engineers what’s really important, so they don’t have to dive into oceans of data.”

Network insight at speed

IGraph displays the following in a single pane-of-glass view for a given site:

  • Topology and dependency context: Visualizes routers, switches, access points, client devices, and their relationships, enriched with path and dependency awareness to localize impact areas
  • Real-time health and telemetry insights: Surfaces live performance signals (utilization, errors, abnormal behavior) correlates directly onto the topology to highlight where the network is degraded or “running hot”
  • Operational and incident context: Integrates incidents, tickets, and change signals into the graph, enabling engineers to understand what is happening and where and what systems are affected in a single view
A photo of Kumar Singh.

“Fragmentation across operational data sources was only part of the problem. The harder challenge was externalizing and structuring the implicit domain knowledge engineers rely on, then integrating it with real-time telemetry and topology to enable low-latency, context-aware reasoning in the agentic layer.”

Vinod Kumar Singh, principal software engineer, Infrastructure, Networking, and Tenant team, Microsoft Digital

On top of this visualization layer, the team is building an agentic layer using Azure Foundry that allows AI agents to discover and use external tools and data sources.

Without IGraph agent, accessing data involves pulling from multiple existing sources, including servers and logs, with mixed latency (from minutes to hours). This fragmentation makes near-real-time reasoning almost impossible, as agents lack a unified, low-latency view of topology and telemetry.

“Fragmentation across operational data sources was only part of the problem,” says Vinod Kumar Singh, a principal software engineer in the Infrastructure, Networking, and Tenant team in Microsoft Digital. “The harder challenge was externalizing and structuring the implicit domain knowledge engineers rely on, the integrating it with real-time telemetry and topology to enable low latency, context-aware reasoning in the agentic layer.”

How IGraph works

The user starts in context. Say they’re on the IGraph UI for Building 32. They can already see the building topology, recent incidents, support tickets, and live health and performance metrics.

The engineer can ask a natural language question such as, “The internet is not working in Building 32—what’s going on?”

The AI agent begins reasoning across UI context (location, devices, open incidents), topology (involved devices and neighbors), historical metrics, and real-time device calls. It works with specialized MCP servers and agents to identify impacted devices, test live responsiveness, measure neighboring impact, verify data flow, and flag abnormal utilization or error trends.

A photo of Vijay.

“Engineers spend a lot of time firefighting. The visualization layer gives them the view they need to quickly solve the incidents. It helps free up their time to engage in more systemic improvements on their applications.”

Abhijit Vijay, principal software engineer manager, Infrastructure, Networking, and Tenant team, Microsoft Digital

Using this context, IGraph pulls in the relevant logs, real-time telemetry, and incident history to complete the analysis.

Instead of raw metrics and hundreds of rows of data, the agent returns a clean summary that provides a view of the failing device, the health of neighboring devices, and the blast radius. It shows what’s broken, what’s still healthy, the likely causes, and next actions.

The engineer stays in one UI for all this, and isn’t forced to use different tools or manually correlate data.

“Engineers spend a lot of time firefighting,” says Abhijit Vijay, a principal software engineer manager on the team in Microsoft Digital. “The visualization layer gives them the view they need to quickly solve the incidents. It helps free up their time to engage in more systemic improvements on their applications.”

The impact of incident visibility

IGraph offers a new real-time telemetry layer that:

  • Uses a UI that surfaces telemetry and topology by correlating data from upstream systems
  • Decreases effective latency for users, enabling near-real-time insights (often within seconds)
  • Provides near-real-time signals in the UI on health, performance, routing state, and neighboring device relationships
A photo of Mallick.

“Our goal is to accelerate how network engineers understand what’s happening, enabling them to shift from reactive troubleshooting to proactive prevention—identifying and mitigating issues before they occur.”

Nevedita Mallick, principal product manager, Infrastructure, Networking, and Tenant team, Microsoft Digital

Combined, these capabilities give network engineers an up-to-the moment view of what’s happening across the network, before small issues can cascade into larger incidents.

By making live telemetry easier to access and interpret, IGraph helps teams move from reactive troubleshooting to proactive prevention.

“Our goal is to accelerate how network engineers understand what’s happening, enabling them to shift from reactive troubleshooting to proactive prevention—identifying and mitigating issues before they occur,” says Nevedita Mallick, a principal product manager for the Infrastructure, Networking, and Tenant team in Microsoft Digital.

That speed and clarity are especially important for new engineers.

A photo of Keskar.

“The tool delivers value right away, especially for newer engineers. Instead of having to piece things together, they get an instant view of the network that shows how devices are connected and displays the already-surfaced incidents directly on the graph.”

Manjiri Keskar, principal cloud network engineer, Infrastructure, Networking, and Tenant team, Microsoft Digital

Complex networks rely on unwritten knowledge and experience built up over time, which can slow onboarding and make troubleshooting harder than it needs to be. IGraph shortens that learning curve by making the network’s relationships and current state immediately visible.

“The tool delivers value right away, especially for newer engineers,” says Manjiri Keskar, a principal cloud network engineer in the Infrastructure, Networking, and Tenant team in Microsoft Digital. “Instead of having to piece things together, they get an instant view of the network that shows how devices are connected and displays the already-surfaced incidents directly on the graph.”

What’s next for IGraph Agent

Without IGraph Agent, network analysis is largely reactive.

Teams often address failures after customers have already felt the impact, instead of preventing issues by acting when early warning signs appear.

A photo of Munde.

“Agentic AI is transforming networking DevOps from manual, reactive operations into intelligent intent-driven systems that can provision, validate, and troubleshoot networks autonomously. Looking ahead, it will power self-healing networks and dramatically accelerate buildouts, allowing engineers to focus on architecture, strategy, and innovation.”

Sonika Munde, senior network engineer, Infrastructure, Networking, and Tenant team, Microsoft Digital

Teams often address failures after customers have already felt the impact, instead of preventing issues by acting when early warning signs appear.

“Agentic AI is transforming networking DevOps from manual, reactive operations into intelligent, intent-driven systems that can provision, validate, and troubleshoot networks autonomously,” says Sonika Munde, a senior network engineer in the Infrastructure, Networking, and Tenant team in Microsoft Digital. “Looking ahead, it will power self-healing networks and dramatically accelerate buildouts, allowing engineers to focus on architecture, strategy, and innovation.”

That unified network intelligence will let IGraph Agent communicate with multiple lightweight agents that continuously analyze network conditions, dramatically compressing response times.

“What used to happen in hours will happen in minutes,” Munde says.

Now, the team is pushing further. One example is layering in weather intelligence to help engineers anticipate issues before they materialize, as big storms can trigger power fluctuations that ripple through the network. By visualizing this data, engineers can proactively communicate with customers and take mitigation steps that protect operational workloads.

Overall, IGraph lets teams focus on prevention. Engineers spend less time navigating dashboards and cross-checking data and more time detecting patterns and surfacing emerging risks. Manual analysis is reduced as the agent highlights insights in real time.

A photo of Thompson.

“By bringing telemetry, topology, and AI together in one intelligent layer, we’re turning fragmented signals into real-time intelligence so teams can move faster, act earlier, and protect the critical workloads that power Microsoft.”

Jason Thompson, principal group product manager, Infrastructure, Networking, and Tenant team, Microsoft Digital

The technology is poised to go even further. IGraph will eventually help power self-healing networks and speed up network build-outs, freeing engineers to focus on architecture and innovation. The future vision for the tool includes fully automated predictive network intelligence across all Microsoft campuses, with agents that monitor, reason, recommend responses, and safely take action.

“By bringing telemetry, topology, and AI together in one intelligent layer, we’re turning fragmented signals into real-time intelligence so teams can move faster, act earlier, and protect the critical workloads that power Microsoft,” says Jason Thompson, a principal group product manager for the Infrastructure, Networking, and Tenant team in Microsoft Digital.

Key takeaways

To move from reactive operations to proactive AI-supported network management, we recommend starting with these steps:

  • Start consolidating real-time telemetry into a single view. Even a lightweight dashboard is enough to prepare for AI-driven insights later.
  • Identify high-frequency incident types to target for AI triage. Pick the most common or disruptive scenarios and map out what data engineers currently review for them.
  • Document the decision logic your engineers use today. Before implementing AI, capture the human reasoning steps to help guide your approach.
  • Pilot an agentic solution with one network segment or site. Start with one building, one lab, or a small testbed.

The post Supercharging network operations at Microsoft with AI-based unified network intelligence appeared first on Inside Track Blog.

]]>
23737
Microsoft CISO advice: Apply engineering fundamentals to securing AI http://approjects.co.za/?big=insidetrack/blog/microsoft-ciso-advice-apply-engineering-fundamentals-to-securing-ai/ Thu, 30 Apr 2026 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=23334 Agentic AI, like any software, is just one part of a business solution. It is not the only element that needs to be secured. Engineers need to approach securing agentic AI in the corporate IT ecosystem the same way they would consider any security problem—from end to end. Yonatan Zunger, CVP and deputy CISO for […]

The post Microsoft CISO advice: Apply engineering fundamentals to securing AI appeared first on Inside Track Blog.

]]>
Agentic AI, like any software, is just one part of a business solution. It is not the only element that needs to be secured. Engineers need to approach securing agentic AI in the corporate IT ecosystem the same way they would consider any security problem—from end to end.

Yonatan Zunger, CVP and deputy CISO for Microsoft, suggests focusing exclusively on hardening a piece of software to security threats may make it difficult to use and introduce a new risk when users get frustrated and try to bypass controls. This is why engineers need to consider not just individual components but how they work together to maintain productivity.

“Think of every system as a socio-technical system containing many parts, and all of them working together in unison have to be secured,” Zunger says.

Watch this video to see Yonatan Zunger explain why engineering fundamentals are critical to building resilient AI systems. (For a transcript, please view the video on YouTube: https://www.youtube.com/watch?v=YU-8lpwPtm0 )

The post Microsoft CISO advice: Apply engineering fundamentals to securing AI appeared first on Inside Track Blog.

]]>
23334
Reclaiming engineering time with AI in Azure DevOps at Microsoft http://approjects.co.za/?big=insidetrack/blog/reclaiming-engineering-time-with-ai-in-azure-devops-at-microsoft/ Thu, 16 Apr 2026 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=23161 At Microsoft Digital, the company’s IT organization, we’re reimagining how engineers, product managers, and program managers work. Microsoft Azure DevOps (ADO) is our company’s end-to-end software development lifecycle (SDLC) solution for planning, coding, testing, and delivery. It combines tools for work tracking, source control, pipelines, and artifacts so teams can manage the entire SDLC in […]

The post Reclaiming engineering time with AI in Azure DevOps at Microsoft appeared first on Inside Track Blog.

]]>
At Microsoft Digital, the company’s IT organization, we’re reimagining how engineers, product managers, and program managers work.

Microsoft Azure DevOps (ADO) is our company’s end-to-end software development lifecycle (SDLC) solution for planning, coding, testing, and delivery. It combines tools for work tracking, source control, pipelines, and artifacts so teams can manage the entire SDLC in one environment.

Although ADO excels at streamlining the development process, we found that users were still spending significant time performing repetitive administrative tasks, like creating and breaking down work items, writing and managing queries for reporting, and reclaiming lost permissions.

Our Engineering Systems Platform team successfully embedded AI into ADO, resulting in ADO experiences that replace manual workflows and free up our IT professionals to concentrate on work that makes a real impact.

Identifying the opportunity

The Engineering Systems Platform team supports 15,000 active users across one of the largest ADO platforms at Microsoft.

A photo of Panigrahy.

“We saw the toll these processes took on users, whether they were compiling information or performing manual tasks. Even with automation, there was still an opportunity to give time back to engineers.”

Gopal Panigrahy, principal product manager, Microsoft Digital

Three years ago, the team began exploring opportunities to automate repetitive ADO tasks like creating and updating work items, navigating project data, gathering statuses, and breaking large initiatives into sprint-ready work.

While they found ways to automate some of these tasks, they discovered decision-making and information synthesis still consumed valuable time and occasionally introduced some human errors.

“We saw the toll these processes took on users, whether they were compiling information or performing manual tasks,” says Gopal Panigrahy, a principal product manager in Microsoft Digital. “Even with automation, there was still an opportunity to give time back to engineers.”

Adding AI to ADO workflows

ADO spans a vast area at Microsoft, serving a wide range of enterprise use cases and personas. What these workers have in common is heavy workloads. With this in mind, different categories of ADO users expressed the desire for AI-powered experiences that could help streamline workflows and speed up day-to-day development tasks.

As generative AI matured, our team explored whether they could embed AI technology inside ADO to act as a real-time assistant, handling administrative work and answering contextual questions using natural language.

A photo of Sahoo.

“We saw it as a win-win experiment. If we could give engineers back in ADO, they could spend it building, not managing artifacts.”

Debashis Sahoo, principal group engineering manager, Microsoft Digital

The guiding principles of the experiment were simple: Stay in context and preserve user control while aligning with existing ADO permissions and processes.

That vision led to the creation of two complementary Microsoft Copilot agents: The DevOps Assistant and the AI Work Item Assistant.

“We saw it as a win-win experiment,” says Debashis Sahoo, a principal group engineering manager in Microsoft Digital. “If we could give engineers time back in ADO, they could spend it building, not managing artifacts.”

What makes this initiative distinctive is it brings AI closer to the core ADO product and its users. It allows for secure, confidential, and context-rich ADO data to be used safely for meaningful AI-powered experiences.

DevOps Assistant offers conversational, in-context support

DevOps Assistant is a chat‑based experience present in the ADO user interface (UI). It’s activated in a side panel where users can ask natural language questions to retrieve information, check project statuses, and run common DevOps actions without navigating away from their main ADO display.

The DevOps Assistant enables cross-source discovery, which reduces context switching and discovery time and helps lower the cognitive load for engineers and product managers. By reducing the time it takes to switch contexts and search for information, the DevOps Assistant helps ADO users move faster and stay focused on product delivery.

Under the hood, the DevOps Assistant is a constellation of specialized agents, each of which is focused on a different segment of the DevOps lifecycle:

  • Work Item Agent creates, refines, and scopes work into sprint-ready backlogs
  • Knowledge Board Agent surfaces the right DevOps knowledge at the right moment
  • Permission Agent handles access and permission requests
  • Bulk Complete Agent runs repetitive, large-scale updates
  • Sprint Board Agent summarizes sprint status and provides instant, prompt‑driven insights
A photo of Gupta.

“We didn’t just build a chatbot. We built a distributed system of agents that understands the intent of the DevOps user and acts on it securely and in context.”

Apoorv Gupta, principal software engineer, Microsoft Digital

Agents are built in Copilot Studio and coordinated by Orchestrator Agent, Copilot Studio’s front door.

For example, if a user asks to create or refine work items, the Orchestrator Agent routes the request to the Work Item Agent to handle. If the question is about permissions, then it delegates the work to the Permission Agent. It does this for each task.

“We didn’t just build a chatbot,” says Apoorv Gupta, a principal software engineer in Microsoft Digital. “We built a distributed system of agents that understands the intent of DevOps user and acts on it securely and in context.”

At present, the DevOps Assistant is available across all our internal ADO environments at Microsoft. The plan is to make it available to external customers soon.

AI Work Item Assistant provides inline assistance

The AI Work Item Assistant is a real-time embedded experience within ADO work items. Powered by Microsoft Foundry, it helps users create and refine work items using context and business requirements.

The assistant works immersively, keeping users focused and within ADO as they structure work items or generate child items from the parent.

For product and program managers who start with high‑level ideas, the assistant understands intent. It can automatically suggest logical, sprint‑ready breakdowns, helping to dramatically reduce the time spent on planning, sorting, and prioritizing work items.

Screenshot showing the “Use AI to edit this item” button in the Azure DevOps UI.
The AI Work Item Assistant is just a click away in Azure DevOps work items.

Turning newfound time into innovation

The key to reclaiming time for your workforce isn’t just the introduction of new AI-driven features. It’s using the technology to enforce structure and quality at the beginning, so that everything downstream moves faster.

Panigrahy describes the practice as three reinforcing feedback loops.

The first loop is upstream quality amplification. AI agents help consistently structure work items with clear acceptance criteria and templates. The structure then feeds other tools (such as GitHub Copilot), allowing them to generate higher-quality code and more predictable outcomes—shortening the overall software development lifecycle.

The second feedback loop is acceleration of execution. In a typical sprint planning session, a team of eight engineers might:

  • Take an hour (or more) to manually break user stories into more than 100 tasks
  • Create different tasks in their own style, introducing inconsistency and ambiguity
  • Generate uneven details, then spend time clarifying data later

With DevOps Assistant and AI Work Item Assistant, that same task breakdown turns into a prompt-driven action that no longer requires hours of work.

“It burns a lot of time for everyone to manually create each item in their own way, making sure they’re using the correct inputs from the product manager and confirming they aren’t missing anything,” Panigrahy says. “Now, with AI magic, it takes less than three minutes.”

The third feedback loop is capacity reinvestment. Instead of spending hours on tactical DevOps mechanics, teams can now spend more time on engineering judgment, resulting in better estimation, technical decisions, and design. They can use these reclaimed hours to learn new tools, experiment with new agents, and innovate on the SDLC.

“Capacity saving keeps giving back, in a loop,” Gupta says. “You get more capacity back. You innovate. You learn. You do better.”

What’s next on the AI-in-ADO journey

The DevOps Assistant and the AI Work Item Assistant can help change user behavior, shifting from time spent doing tactical DevOps tasks to performing higher‑value, judgment-based work. These tools can help teams increase work quality and reduce wasted time.

“Our next chapter is about making AI smarter, more action-oriented, and truly agentic,” Sahoo says. “The goal is to reduce cognitive load and allow the experience to live wherever users are—from Azure DevOps to Microsoft Teams and Microsoft 365—so the agent works seamlessly across their workflow.”

AI-driven productivity gains are arguably the biggest opportunity in the industry. It’s fundamentally redefining the engineering experience at an unprecedented pace.

“While we’ve made huge strides embedding AI into the everyday Azure DevOps experience, it still feels like we’re just getting started,” Sahoo says. “Staying relevant means continuously evolving to deliver ever-greater value and efficiency to engineers.”

Key takeaways

Keep these tips in mind as you get started on your own journey with AI and Microsoft ADO:

  • Treat AI as a strategic accelerator, not as an add-on. Identify where your engineering process can use AI to move from simple assistance to transforming your workflows.
  • Target high-effort, high-volume tasks first. Analyze where your teams are spending significant manual time, even if AI tools are already in place in those workflows.
  • Validate productivity with measurable data, not intuition. Track time reclaimed, workflow efficiency, reduction in manual steps, and user satisfaction. Tangible data can help your initiative earn trust and justify the expansion of AI tool use on your team.

The post Reclaiming engineering time with AI in Azure DevOps at Microsoft appeared first on Inside Track Blog.

]]>
23161
Olutunde Makinde: From Lagos to Redmond, a Microsoft IT engineer’s journey http://approjects.co.za/?big=insidetrack/blog/olutunde-makinde-from-lagos-to-redmond-a-microsoft-it-engineers-journey/ Thu, 02 Apr 2026 16:05:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=22855 A career in Microsoft Digital, the company’s internal IT organization, puts employees at the center of one of the world’s most complex and forward‑leaning enterprise environments. This is the team that runs Microsoft on Microsoft technology and services—maintaining more than a million computing devices, enabling global collaboration, and shaping the employee experience for more than […]

The post Olutunde Makinde: From Lagos to Redmond, a Microsoft IT engineer’s journey appeared first on Inside Track Blog.

]]>
A career in Microsoft Digital, the company’s internal IT organization, puts employees at the center of one of the world’s most complex and forward‑leaning enterprise environments. This is the team that runs Microsoft on Microsoft technology and services—maintaining more than a million computing devices, enabling global collaboration, and shaping the employee experience for more than 200,000 people.

To accomplish these huge tasks, it’s essential to cultivate a range of perspectives, expertise, and lived experiences.

Olutunde Makinde is an example of this.

A photo of Makinde.

“A friend once laughed at me back in college when I said I wanted to work at Microsoft, like it was impossible. But I knew I could achieve the impossible if I could just be focused. I never gave up.”

Olutunde Makinde, senior service engineer, Microsoft Digital

Makinde, a senior service engineer in Microsoft Digital, came to the company the long way around—roughly 7,000 miles away from the Redmond, Washington, headquarters, in fact. He’s originally from Lagos, Nigeria.

As a global organization, Microsoft builds teams where people with different experiences and life journeys actively influence how products, services, and internal platforms are designed. Makinde, commonly known around the office as “Tunde” (“rhymes with Sunday,” he notes), embodies that diverse approach, bringing his unique insights and experiences to critical work at the company.

“A friend once laughed at me back in college when I said I wanted to work at Microsoft, like it was impossible,” Makinde says. “But I knew I could achieve the impossible if I could just be focused. I never gave up.”

Launching an IT career in Nigeria

Makinde’s journey to Microsoft began with earning a degree in computer engineering in Lagos, after which he found work as a network engineer. He spent the next several years developing his skills through certifications and other learning opportunities.

“I did a lot of self-paced training, learning how to configure Cisco routers. Eventually I became a Cisco-certified network professional (CCNP),” Makinde says. “Around that time, I had a friend who was preparing for Windows Server 2008 certifications, and through his study materials I started learning more about Microsoft and its products.”

Makinde’s first direct encounter with Microsoft came in 2014, when the company he worked for received a contract to deploy the first Microsoft Azure cloud installation in Nigeria.  

“I spent the last day of 2014 and the first day of 2015 at the customer site, figuring out how to connect their on-premises network to Azure,” Makinde says. “It had never been done before in Nigeria, and taking up that challenge really propelled me into the world of Microsoft-specific technology.”

From there, Makinde set his sights on a career at Microsoft. He parlayed his initial exposure to cloud architecture into a focus on Azure, as well as Amazon Web Services. After spending some time in the United Kingdom, he achieved his goal when he was hired by the Microsoft Digital team in 2022. He moved to the United States in 2025.

He credits support from his family, especially his wife, with helping him achieve his dreams.

“My wife was a pillar of support through every career transition, from Nigeria to the UK to the United States,” Makinde says. “She believed in me when I faced rejections, celebrated with me when I finally got the offer, and now keeps me grounded whenever work gets intense. I couldn’t have made this journey without her.”

Making an impact from day one

Kathren Korsky, a principal technical program manager in Microsoft Digital and Makinde’s hiring manager, remembers the impression he made right away. It was clear that Makinde’s experience and technical background were major assets.

“What caught my attention was how well-prepared he was for the conversation and how well he communicated,” Korsky says. “The stories he shared about his work with Azure deployment in Nigeria really drew my interest. But I was also intrigued by how he was able to bridge technology with the business world, working with different banks across the continent to gather requirements, understand them, and build solutions.”

Upon being hired at Microsoft, he initially worked remotely from the UK on a Redmond-based device and application management team. The team was looking to deploy Cloud PC internally and needed a system in which employees could request access and get approvals to use Cloud PCs.

“He was able to stand up a full Power Automate workflow within a short period, and with a very high degree of quality,” Korsky says. “Rarely did anyone find any defects or bugs in his system.”

Makinde’s designs drove value moving forward as well, as the team made updates to his initial workflows.

A photo of Korsky

“His design was so strong that we were basically able to follow exactly what he had created in Power Platform and build that exact same design in ServiceNow. It really expedited that whole process.”

Kathren Korsky, principal technical program manager, Microsoft Digital

ServiceNow was more commonly used for systems that involved access requests and approvals, but when a platform update from Power Automate was initiated the team found Makinde’s original design was durable enough to weather the shift.

“His design was so strong that we were basically able to follow exactly what he had created in Power Platform and build that exact same design in ServiceNow,” Korsky says. “It really expedited that whole process.”

Driving efficiency and managing change

Since moving to the United States to work at company headquarters, Makinde has continued to push important projects forward—working with different stakeholders to deploy policy changes across Microsoft, managing the Change Advisory Board (CAB) intake process, and driving configuration updates for security and first-party product deployments.

“There’s a lot of diligence required to see the edge cases happening, to pay attention to them, and to watch out for potential problems. Tunde stops rollouts regularly to flag potential defects or risks, which prevents issues from interrupting our work and reducing productivity.”

Jeff Duncan, principal service engineering manager, Microsoft Digital

Makinde learned how to assess change requests and understand risk profiles, as well as enforce best practices for managing change within the security environment. Within about a year, he was able to take the lead in the space and own the deployment process.

A single misconfigured policy can cause major disruption. Makinde’s role puts him in position to be the checkpoint that prevents incidents before they happen.

“There’s a lot of diligence required to see the edge cases happening, to pay attention to them, and to watch out for potential problems,” says Jeff Duncan, principal service engineering manager in Microsoft Digital and Makinde’s manager. “Tunde stops rollouts regularly to flag potential defects or risks, which prevents issues from interrupting our work and reducing productivity.”

Softer skills like transparency, collaboration, and clear communication across levels and teams are key aspects of Makinde’s work as well.

“Tunde is thoughtful and detail-oriented, and he’s very good at explaining the decision-making process when he provides overviews for leadership,” Duncan says. “There’s rational, logical reasoning behind the decisions he makes.”

Makinde has implemented new efficiencies in how he manages the CAB and deployment service using AI. This includes CABBIE—an AI-powered agent that automates CAB communications. For Intune deployments, he uses AI to streamline deployment coordination and package reviews. These innovations reflect our Customer Zero approach to AI adoption here in Microsoft Digital.

“We run weekly CAB meetings to review change requests. That comes with a lot of communication work — status updates, follow-ups, coordination with stakeholders. It was all manual,” Makinde says. “CABBIE pulls the data from Azure DevOps, generates the emails, updates requests, and logs approvals automatically. It saves time and reduces errors.”

Success at Microsoft Digital: Aptitude and curiosity

As the organization at the center of the company’s own digital transformation, we in Microsoft Digital function as a living showcase of what’s possible with Microsoft technology. Our team tests new capabilities at enterprise scale as Customer Zero for Microsoft, identifying gaps and providing insights to ensure our customers benefit from what we’ve learned.

Because the impact of Microsoft Digital extends far beyond internal systems, team members have to set the standard for digital excellence. They must demonstrate what enterprise transformation looks like in practice and empower customers with the confidence to pursue their own modernization journeys.

 Hiring talented people like Makinde is essential to this mission.

“There are three core traits I look for when hiring—aptitude, attitude, and curiosity,” Korsky says. “Aptitude is not only what you currently know, but your propensity and desire to learn and grow those skills. Attitude goes hand in hand with that—are you willing to demonstrate grit and perseverance? And then curiosity, because so much of what we do from an innovation perspective requires a willingness to challenge assumptions and think of completely new ways of doing things.”

Makinde’s journey here at Microsoft Digital embodies and illustrates the company’s larger story: how technical expertise, innovative thinking, and a commitment to continuous learning combine to deliver world-class results.

“I’m now up to 25 certifications, and I continue to learn how to do more at Microsoft to positively impact the organization and protect our employees’ experience across applications and devices.”

Olutunde Makinde, senior service engineer, Microsoft Digital

That attitude of persistent curiosity and the willingness to keep learning continue to fuel Makinde’s experience at Microsoft. 

“Self-improvement is a way of life for me that has driven my career forward,” Makinde says. “At an early stage in my career, I did a lot of self-training—from learning how to configure Cisco routers and switches, to migrating on-premises workloads to Azure and managing cloud resources. I’m now up to 25 certifications, and I continue to learn how to do more at Microsoft to positively impact the organization and protect our employees’ experience across applications and devices.”

Key takeaways

Olutunde Makinde’s career experience here in Microsoft Digital offers some important insights that you can apply to your own organizational development:

  • AI adoption starts with practical problems. Makinde’s use of AI to streamline CAB communications and deployment coordination shows how Customer Zero teams find real-world applications for emerging technology.
  • Different experiences and perspectives contribute to business success. Achieving ambitious goals as an organization is dependent upon attracting talented people like Makinde from a range of backgrounds, disciplines, and lived experiences.
  • Strong technical skills paired with innovative thinking drives value. Makinde’s contributions to flexible cloud deployment workflows are an example of how this combination pays dividends.
  • Proactive risk management and attention to detail can prevent large-scale disruptions. By being willing to stop rollouts and flag risks before they become problems, Makinde’s approach to his work exemplifies how thoughtful decision-making safeguards productivity and security.
  • Persistence, curiosity, and continuous learning are critical career accelerators. Having a long and successful career at a company like Microsoft goes beyond just technical aptitude; it also requires perseverance and a passion for learning. Makinde’s self-driven training efforts and his refusal to give up have enabled him to achieve what once seemed impossible.

The post Olutunde Makinde: From Lagos to Redmond, a Microsoft IT engineer’s journey appeared first on Inside Track Blog.

]]>
22855
Protecting anonymity at scale: How we built cloud-first hidden membership groups at Microsoft http://approjects.co.za/?big=insidetrack/blog/protecting-anonymity-at-scale-how-we-built-cloud-first-hidden-membership-groups-at-microsoft/ Thu, 26 Feb 2026 17:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=22465 Some Microsoft employee groups can’t afford to be visible. For years, we supported email‑based communities internally here at Microsoft whose very existence depends on anonymity. These include employee resource groups, confidential project teams, and other sensitive audiences where simply revealing who belongs can create real‑world risk. Traditional distribution groups make membership discoverable by default. Owners […]

The post Protecting anonymity at scale: How we built cloud-first hidden membership groups at Microsoft appeared first on Inside Track Blog.

]]>
Some Microsoft employee groups can’t afford to be visible.

For years, we supported email‑based communities internally here at Microsoft whose very existence depends on anonymity. These include employee resource groups, confidential project teams, and other sensitive audiences where simply revealing who belongs can create real‑world risk.

Traditional distribution groups make membership discoverable by default. Owners can see members. Admins can see members. In some cases, other users can infer membership through directory queries or tooling.

That model doesn’t work when anonymity is a requirement.

A photo of Reifers.

“When the SFI wave hit, it was made clear to us that we needed to keep our people safe, and to do that, we needed to build a new hidden memberships group MVP. We needed to raise the bar with modern groups, and we needed to do it in six months or miss meeting our goals.”

Brett Reifers, senior product manager, Microsoft Digital

For over 15 years, we relied on a custom, on‑premises solution that enabled employees to send and receive messages through groups with fully hidden memberships.

The system worked, but we were deprecating the Microsoft Exchange servers that it ran on. At the same time, we were also deploying our Secure Future Initiative (SFI), which required us to reassess legacy systems that could expose sensitive data or slow incident response, including hidden membership groups.

The system wasn’t broken, but it represented concentrated risk simply by existing outside our modern cloud controls and monitoring.

“When the SFI wave hit, it was made clear to us that we needed to keep our people safe, and to do that, we needed to build a new hidden memberships group MVP,” says Brett Reifers, a product manager in Microsoft Digital, the company’s IT organization. “We needed to raise the bar with modern groups, and we needed to do it in six months or miss meeting our goals.”

The mandate was clear. Preserve anonymity, eliminate on‑premises dependencies, and do it quickly.

A photo of Carson.

“Our solution would enable us to deprecate our legacy on-premises Exchange hardware while maintaining the privacy of our employee groups, and it would do so in a cloud-first manner.”

Nate Carson, principal service engineer, Microsoft Digital

Instead of retrofitting hidden membership into standard Microsoft 365 groups, we asked a different question: What if the group lived somewhere else entirely? What if users interacted with a simple, secure front end, while all membership expansion and mail flow occurred in a locked‑down tenant built specifically for this purpose?

That idea became the foundation for Hidden Membership Groups: A new cloud‑first architecture that would separate user experience, leverage first‑party Microsoft services, and keep our group memberships hidden from everyone—including owners and administrators—by design.

“Our solution would enable us to deprecate our legacy on-premises Exchange hardware while maintaining the privacy of our employee groups, and it would do so in a cloud-first manner,” says Nate Carson, a principal service engineer in Microsoft Digital.

Once we settled on a solution, our next step was to get support for solving a problem not many people thought much about.

“Not everyone was aware of how serious of a situation we were in,” Carson says. “We had to show everyone what was at stake, and to share our solution with them.”

After taking their plan on the road, the team got the buy in it needed, and that’s when the real work started.  

Planning to solve business problems with security built-in

Before we designed anything, we had to be clear about what success meant.

Hidden Membership Groups aren’t just another collaboration feature. They support scenarios where anonymity wasn’t optional—it’s foundational. That reality shaped every requirement that we built into our solution, including:

1. Absolute privacy

Group membership couldn’t be immediately visible to users, group owners, or administrators–under any circumstances. That requirement immediately ruled out standard group models.

2. Cloud only

Any new solution had to live entirely in our cloud, use first‑party services, and align with modern identity, security, and compliance practices. On‑premises infrastructure wasn’t an option.

3. Scale

Some groups had a handful of members. Others had tens of thousands. Membership changed frequently, and those changes had to propagate safely and predictably without exposing data or degrading performance.

4. Separation of concerns

User interaction and membership truth couldn’t live in the same place. Employees needed a simple way to discover groups, request access, and manage participation, without ever interacting with the system that stored or expanded membership.

5. Self‑service with guardrails

The solution needed to reduce operational overhead, not introduce a new bottleneck. Group lifecycle management had to be automated, auditable, and secure, while still giving teams flexibility.

6. Simple to use

Employees shouldn’t need special training. They shouldn’t need to understand tenants, identity synchronization, or mail routing. The experience needed to be intuitive, consistent, and accessible—without compromising security.

Once those requirements were clear, our solution started to emerge. Incremental changes wouldn’t be enough. A traditional group model wouldn’t work. The solution required a new architecture—one designed around isolation, automation, and intentional limitation.

That’s when we started the engineering work.

Creating a cloud-first architecture

Designing for hidden membership meant eliminating ambiguity. If any surface could reveal membership, even indirectly, it didn’t belong in the design.

That constraint led us toward a model built on strict isolation, explicit APIs, and intentionally narrow interfaces. The result is straightforward to use, but deliberately difficult to interrogate.

Two tenants, with sharply separated responsibilities

At the foundation of the solution is a two‑tenant model.

Our primary Microsoft 365 tenant is where employees authenticate, discover groups, and initiate actions. A secondary, isolated tenant hosts the distribution lists and performs mail expansion for Hidden Membership Groups.

A photo of Mace.

“Tenant isolation is what makes the privacy guarantee real. By moving membership expansion to a tenant that users and owners can’t access, we removed the possibility of accidental exposure. The system simply doesn’t give you a place where membership can be seen.”

Chad Mace, principal architect, Microsoft Digital

That separation matters because the secondary tenant isn’t designed for interactive use. Only Exchange and the minimum directory constructs required for mail routing and expansion are enabled.

Operationally, when an employee sends email to a Hidden Membership Group, they send to a mail contact visible in the corporate tenant. That contact routes to the corresponding distribution group in the isolated tenant, where membership expansion occurs. Expanded messages are then delivered back in recipients’ inboxes in the corporate tenant, so sent and received mail lives where users already work.

“Tenant isolation is what makes the privacy guarantee real,” says Chad Mace, a principal architect in Microsoft Digital. “By moving membership expansion to a tenant that users and owners can’t access, we removed the possibility of accidental exposure. The system simply doesn’t give you a place where membership can be seen.”

Identity without interactive access

This isolated tenant only works if it can resolve recipients. To enable that, our development team used Microsoft Entra ID multi‑tenant organization identity sync to represent corporate users in the secondary tenant.

These identities are treated as business guest identities, and we disable sign‑in to prevent interactive access. The tenant can perform expansion, but nothing more.

However, complete isolation wasn’t technically possible. Privileged access always exists at some level. The design response was to minimize that exposure. Access to the isolated tenant is tightly restricted, and membership changes flow through automation rather than broad UI-based administration.

The goal: reduce exposure to the smallest viable operational group.

API-first automation as the control plane

With tenancy and identity model established, the team needed a single, consistent way to create groups, connect objects across tenants, and manage changes without introducing new administrative workflows. That’s where the APIs come in.

A photo of Pena II.

“We split the backend into multiple APIs so the system could scale without becoming fragile. That let us separate everyday operations from high-volume membership work and keep performance predictable.”

John Pena II, principal software engineer, Microsoft Digital

The backend is intentionally modular, split into three distinct APIs:

  • The control API handles group creation, configuration, and cross‑tenant coordination.
  • The membership API handles standard add and remove operations.
  • The bulk membership APIs handle large‑scale operations involving tens of thousands of users, with services designed to run long‑lived jobs, manage throttling, and recover from partial failures.

“We split the backend into multiple APIs so the system could scale without becoming fragile,” says John Pena II, a principal software engineer in Microsoft Digital. “That let us separate everyday operations from high-volume membership work and keep performance predictable.”

The APIs run as PowerShell-based Azure Functions and use managed identity patterns, including federated identity credentials, to securely connect across tenants.

Creating the user experience with PowerApps

For the front end, we built a Canvas app in Power Apps, backed by Dataverse. The goal was speed and flexibility, without compromising strict privacy boundaries.

By using Power Apps as the primary interaction layer, we deliver a secure, modern experience without unnecessary custom infrastructure. The Canvas app provides a single, focused surface for discovering, joining, and managing hidden membership groups, while all sensitive operations remain behind controlled APIs and tenant boundaries. This separation allows the team to iterate quickly on experience design without weakening the privacy guarantees that the solution depends on.

Power Platform also simplifies how security is being enforced across the solution. Dataverse enables fine‑grained, role‑based access, ensuring users only see data they’re entitled to see—while keeping sensitive membership information entirely out of the client layer. That reduces long‑term maintenance overhead and makes it easier to evolve the solution as requirements change.

“From the beginning, we designed everything with security roles and workflows in mind,” says Shiva Krishna Gollapelly, senior software engineer in Microsoft Digital. “Dataverse let us control who could see or change data without building additional APIs or storage layers, and keeping everything inside the Power Apps ecosystem saved us a lot of maintenance over time.”

Dataverse plays a precise role here: it maintains the datastore the app needs to function without becoming a secondary membership repository.

A photo of Amanishahrak.

“Using the Power Platform let us move fast, integrate deeply with Microsoft identity, and enforce security without building a full web stack from scratch.”

Bita Amanishahrak, software engineer II, Microsoft Digital

From a security posture perspective, Dataverse security is used intentionally to restrict what different users can see and do, and the Power App was developed with security roles and workflows in mind.

Short version: the app brokers intent, the APIs execute it, and all the pieces that need to stay separate do exactly that.

“Using the Power Platform let us move fast, integrate deeply with Microsoft identity, and enforce security without building a full web stack from scratch,” says Bita Amanishahrak, a software engineer in Microsoft Digital.

The architectural intent is consistent throughout—isolate the sensitive plane and ensure the user plane operates only through controlled interfaces.

Benefits and impact

The most important outcome of the new architecture is also the simplest: Hidden membership stays hidden.

Anonymity isn’t enforced by policy. It’s enforced by architecture. Membership data never appears in the user experience or administrative tooling, and it doesn’t surface as a side effect of scale.

“We’re no longer asking people to trust that we’ll handle sensitive membership carefully through process,” Reifers says. “The system makes exposure structurally impossible.”

The impact was immediate.

At launch, we migrated more than 2,200 hidden membership groups, representing over 200,000 users, from the legacy on‑premises system into the new cloud‑first architecture. Groups ranged from small, tightly controlled communities to audiences with tens of thousands of members, all supported without special handling.

“Some of these groups are massive,” Pena says. “We knew from the beginning we were dealing with memberships in the tens of thousands, which is why we designed bulk operations as a first‑class capability instead of an afterthought.”

The separation between routine APIs and bulk‑membership APIs proved critical, enabling large migrations and ongoing changes without degrading day-to-day performance.

Operationally, moving to a cloud‑only model reduced both risk and complexity. Decommissioning the on‑premises Exchange infrastructure eliminated specialized maintenance requirements and improved monitoring, auditing, and access controls alignment with our modern cloud standards.

Delivery speed also mattered. Driven by Secure Future Initiative urgency and strong executive sponsorship, the team designed and delivered a minimum viable product in less than six months.

“That timeline forced discipline,” Reifers says. “We focused on what mattered: Security, privacy guarantees, scale, and a UX that wouldn’t disrupt group owners and/or members that had relied on a 15-year old tool.”

Everything else was secondary.

A photo of Gollapelly.

“Most users never think about tenants or APIs. They just see a clean experience that does what they need, without exposing anything it shouldn’t.”

Shiva Krishna Gollapelly, senior software engineer, Microsoft Digital

From an employee perspective, the experience became simpler and safer. Users now interact through a Power Platform app consistent with the rest of Microsoft 365.

Discovering a group, requesting access, or leaving a group no longer requires understanding the architecture behind it.

“Most users never think about tenants or APIs,” Gollapelly says. “They just see a clean experience that does what they need, without exposing anything it shouldn’t.”

The result is sustainable. The platform protects anonymity at scale, simplifies operations, boosts resiliency, and can evolve without reopening core privacy questions.

Moving forward

Delivering the initial solution was only the beginning.

The team sees Hidden Membership Groups as more than a single solution. It’s a reusable pattern for sensitive collaboration in a cloud‑first world: isolate what matters most, automate everything else, and design experiences that don’t require trust to be safe.

As adoption grows, the team plans to support additional anonymity-sensitive scenarios while maintaining the same underlying model.

“We don’t want every sensitive scenario inventing its own workaround,” Mace says. “This gives us a pattern we can reuse confidently.”

Future priorities include improving lifecycle and ownership experiences, strengthening auditing and reporting for approved administrators, and enhancing self‑service workflows—without compromising membership privacy. If it risks exposing membership, it doesn’t ship.

With the legacy system fully retired, Reifers reflects on what the team accomplished to get here.

“We shipped a new enterprise pattern in six months using our first party tools,” Reifers says. “We achieved this because a stellar team cared about the mission. That’s the takeaway.”

Key takeaways

Use these tips to strengthen your privacy, simplify your operations, and future-proof your organization’s collaboration systems:

  • Prioritize privacy by design. Embed privacy considerations from the start to protect sensitive information in all collaboration scenarios.
  • Architect for scale. Treat bulk operations to support large groups efficiently as a first-class capability.
  • Automate and modernize workflows. Replace legacy systems with cloud-native solutions to reduce risk, improve transparency, and enable continuous improvement.
  • Streamline user experience. Provide intuitive, consistent interfaces that make it easy for users to access, join, or leave groups without requiring technical knowledge.
  • Enforce strict access and auditing controls. Align monitoring and administration with modern cloud standards to maintain security and accountability.
  • Create reusable patterns. Establish and share successful privacy patterns to avoid reinventing solutions for each new case.
  • Focus on operational simplicity and resilience. Design systems that are easy to maintain and improve, freeing up teams to concentrate on innovation rather than upkeep.

The post Protecting anonymity at scale: How we built cloud-first hidden membership groups at Microsoft appeared first on Inside Track Blog.

]]>
22465
Powering data governance at Microsoft with Purview Unified Catalog http://approjects.co.za/?big=insidetrack/blog/powering-data-governance-at-microsoft-with-purview-unified-catalog/ Thu, 05 Feb 2026 17:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=22272 Data fuels everything that we do here at Microsoft, from the daily operations that keep the business running to the innovations that shape the future. But as data sprawls across teams, systems, and borders, the task of ensuring that it remains secure, accurate, and well-governed is a daunting one. A sound approach to data governance […]

The post Powering data governance at Microsoft with Purview Unified Catalog appeared first on Inside Track Blog.

]]>
Data fuels everything that we do here at Microsoft, from the daily operations that keep the business running to the innovations that shape the future.

But as data sprawls across teams, systems, and borders, the task of ensuring that it remains secure, accurate, and well-governed is a daunting one. A sound approach to data governance is the backbone of responsible data use across the enterprise, creating clarity around data ownership and access.

In an organization the size of Microsoft, no single team can carry this responsibility on its own. Effective data governance must be a distributed effort across all departments and functions.

This story explains how our marketing organization uses the Microsoft Purview Unified Catalog to organize and standardize the data we rely on daily. By putting clear ownership, consistent definitions, and reliable governance in place, we’re turning fragmented, unreliable data into an advantage that supports faster decisions and more effective campaigns.

Data governance at scale

As companies grow, their data governance becomes increasingly complex, with different teams creating their own versions of key data concepts, often without realizing it. The complexity is most visible in the way users across an organization define foundational terms.

A photo of Doughty.

“We found adoption to be much easier when helping teams focus on building more value in their data instead of driving governance like a compliance effort.”

Nick Doughty, senior product manager, Microsoft Purview Unified Catalog

Examples in marketing include what counts as a customer (active vs. inactive, marketing- or sales-qualified), what constitutes sensitive data (personally identifiable information, behavioral data, partner data), and what a metric means (conversion, engagement, attribution windows).

When inconsistent practices take hold, ownership becomes murky. With the increasing demands that managing data quality and integrity put on our leaders and their teams, effective data governance becomes one more hurdle to productivity.

“We started off implementing data governance like an issue register,” says Nick Doughty, a senior product manager within Microsoft Purview Unified Catalog. “Then we progressed to more of an enforcement method, similar to how we were doing security at the time. We found that when we started to push really hard on teams, similar to how we drove other compliance efforts, it was difficult for them to justify or understand why they would want the added governance.”

The introduction of Microsoft Azure Purview in 2020 marked a turning point.

A united platform for data governance, security, and compliance, Purview helps organizations understand, protect, and manage data across environments. It also addresses fragmented data, lack of visibility into where sensitive data lives and how it moves, compliance complexity with regulations (including GDPR and HIPAA), and security risks.

A photo of Mathur

“Our marketing teams used to spend hours hunting for the right customer list because multiple versions lived in different locations, each with unclear owners and inconsistent labels. Now our marketers can trust they are working from current information, while avoiding compliance risks associated with incorrect or unauthorized data.”

Sourabh Mathur, principal engineering lead, Global Marketing Engines and Experiences

The Purview Unified Catalog serves as the AI-powered backbone, automatically discovering, classifying, and organizing information so users can easily find and trust the data they need.

By launching the unified catalog, we gave our users a consistent way to understand and use their data, while reinforcing strong governance and compliance practices. The result is data that’s more discoverable, reliable, and actionable. (The product was renamed Microsoft Purview in 2022 and became part of Microsoft 365 compliance tools.)

“Our marketing teams used to spend hours hunting for the right customer list because multiple versions lived in different locations, each with unclear owners and inconsistent labels,” says Sourabh Mathur, a principal engineering lead in Global Marketing Engines and Experiences, who helped set up Purview for our marketing organization.

With the unified catalog in place, Purview surfaces the dataset, shows its lineage, and applies the correct sensitivity classifications.

“Now our marketers can trust they are working from current information, while avoiding compliance risks associated with incorrect or unauthorized customer data,” Mathur says.

Powering marketing at Microsoft with Purview

With more than 200 Microsoft Azure subscriptions, our marketing organization manages one of the largest data estates at the company. The team faces the constant challenge of scattered data, unclear data ownership, and inconsistent governance practices that slow down campaigns and increase compliance risk.

A photo of Biswal.

“Marketing can now scale governance across hundreds of data products, support self-service data collection with guardrails, automate access decisions, and enable AI workloads on trusted data.”

Deepak Kumar Biswal, principal software engineering lead, Global Marketing Engines and Experiences

By adopting Purview, our marketing team gained unified visibility, clearer classification standards, and smoother collaboration with other departments, like IT and legal. This reduces friction while strengthening data protection.

The result is an organization that moves faster with greater confidence in how it handles customer and campaign data.

Instead of relying on legacy knowledge, forcing users to dig through different servers and SharePoint sites, or constantly sending queries to the engineering teams, our marketing professionals can now explore the curated Purview Unified Catalog, making streamlined, efficient data discovery possible.

“Marketing can now scale governance across hundreds of data products, support self-service data collection with guardrails, automate access decisions, and enable AI workloads on trusted data,” says Deepak Kumar Biswal, a principal software engineering lead in Global Marketing Engines and Experiences. “Purview turns responsible data use into everyday practice, not extra work.”

Data governance and security: Two sides of the same coin

For our marketing organization, data governance and security are inseparable concepts. As soon as you have customer information, you need to make sure it’s secure—sensitive data must be carefully defined, consistently managed, and protected from misuse or breach.

Purview supports this goal by combining governance capabilities with security and compliance controls that provide added layers of protection.

Within marketing, the governance and security teams work closely together. Good governance measures ensure our data is properly defined and standardized, while strong security policies ensure it’s handled with proper safeguards. By pairing governance with strong security practices, our marketing team can remain compliant with data privacy laws, prevent misuse of sensitive information, and foster trust across their organization.

When our marketing team began its Purview journey five years ago, it adopted a centralized governance model. Much like the structure of a government—where federal, state, and local entities each play a role—our approach allows both centralized standards and local autonomy. This creates consistency across the organization without stifling agility.

Our Data Governance team took on the role of steward, defining standards, onboarding systems, and collaborating with its IT partners to connect data environments. Existing assets like data dictionaries and process flows were used to seed the catalog, ensuring the team started from known ground rather than reinventing definitions from scratch.

This deliberate, incremental approach allowed our marketing team to thoughtfully build out healthy governance practices. By moving slowly, the team learned from each step on its journey, refining processes and establishing consistent practices as it moved along.

For example, working closely with our team in Microsoft Digital allowed them to experiment with different ways of discovering and cataloging their data. This involved taking learn and refine how Purview tuned their data before they rolled anything out broadly.

Our goal is to transition to a completely federated model in which responsibility shifts outward. Rather than the marketing governance team doing all the stewardship, individual groups will take ownership of their data within Purview. This shift distributes accountability, embeds governance deeper into daily operations, and makes it easier for teams to monitor data quality and enforce standards on their own.

Impact across the enterprise

Since adopting Purview Unified Catalog, we’ve seen tangible results across our data estate and our data governance practices in marketing and across all verticals within the company. Here are some companywide highlights:

  • Better consolidation: We’ve unified five catalogs into one.
  • Increased scale: We added 250 data sources onboarded in six months, representing roughly 10 million assets.
  • Higher internal adoption: We set up more than 50 governance domains, an effort we supported with reusable training assets, guides, and onboarding materials.

The benefits also include and extend beyond marketing:

  • Teams across the company are gaining increased confidence in their data definitions.
  • Compliance and privacy obligations are being met more effectively.
  • Business value is being generated through better, more trusted use of data.
  • Organizations are benefiting from faster time-to-insight.

Launching the marketing governance domain

We’re using Purview to combine essential capabilities like data governance, classification, and quality checks across our Microsoft services, which creates a unified foundation for our enterprise-wide metadata management. These unified capabilities make Purview an indispensable tool for us, and for large-scale enterprises.

A photo of Singh

“With various role types like data curator and data reader, we can add more visibility into our data—where it lives, how it’s being used, and who are its primary owners. Clearly defining these parameters helps us use the data governance framework as a starting point and improve our data governance capabilities.”

Vinny Singh, principal program manager, Global Marketing Engines and Experiences

As early adopters of Purview Unified Catalog, the group launched the Marketing Governance domain, registering more than 200 data products using the Unified Catalog’s data map.

The products, spanning various datasets, are aligned with strict internal governance standards. This gives marketing the ability to govern, classify, and track data across its ecosystem—ensuring adherence to GDPR and other regulatory compliance measures.

“With various role types like data curator and data reader, we can add more visibility into our data—where it lives, how it’s being used, and who are its primary owners,” says Vinny Singh, a principal program manager in Global Marketing Engines and Experiences. “Clearly defining these parameters helps us use the data governance framework as a starting point and improve our data governance capabilities.”

Key takeaways

Our journey with Microsoft Purview Unified Catalog has generated key insights that you can apply to your own data governance efforts. These include:

  • Start small: Don’t try to “boil the ocean.” Begin with three to five governance domains and scale from there.
  • Leverage what you have: Data dictionaries, glossaries, and existing documentation provide a strong starting point for a governance platform founded on the Purview Unified Catalog.
  • Focus on value, not enforcement: Governance resonates when teams see how it helps them, not when it’s mandated.
  • Adapt to your organization: Each team at your company will use Purview differently. Flexibility helps encourage adoption.
  • Build community: Data governance is not a solo effort. Collaboration among stakeholders produces stronger standards and better results.

The post Powering data governance at Microsoft with Purview Unified Catalog appeared first on Inside Track Blog.

]]>
22272