1048 episodes
- The risk of ransomware is real - are you ready? Richard talks with Heather Renze about her experiences dealing with a ransomware attack and how to get prepared when it happens to you. Heather talks about how ransomware has evolved into a business that has operators, affiliates, and even tech support. Making a plan is essential - involving finance, legal, and IT. Cyberinsurance plays a big role, as do regulatory bodies - it depends on the business you're in. But your plan needs to know three essential things: what breaks first, how long your company can function with it broken, and who can decide on what to do next in the first hour of the event. The plan may or may not work perfectly, but not having a plan is far worse. Get ready!
Links
Ransomware Guidance from NIST
Recorded June 25, 2026 - More ways to use Azure Virtual Desktop! Richard chats with Travis Roberts about how Azure Virtual Desktop continues to evolve and provides more options for remote users. Travis talks about how AVD grew out of Terminal Services and so is still very much an IaaS offering - as opposed to Windows 365, which is more PaaS, with less flexibility, but easier deployment. But when you need control, AVD is the way to go, and today will operate in Azure, on-premises via Azure Local. And if you've got an existing virtual desktop infrastructure, AVD Hybrid opens the door to running in a hybrid environment across on-prem and cloud, or to providing a smooth migration path. Lots of choices!
Links
Terminal Services
Windows 365
Windows 365 Flex
Azure Virtual Desktop
Windows Enterprise Multi-Session
FSLogix
Azure Local
Azure Virtual Desktop on Azure Local
Azure Virtual Desktop Hybrid
AVD Personal Desktop Assignment
Recorded June 22, 2026 - Bringing new software or SaaS into your organization is a security risk - how do you assess it? Richard chats with Jessie Schofer about her experiences in HR software acquisition, which led to the creation of secureless.ai. Jessie tells the story of evaluating various SaaS and other software products and realizing that, while the website says they are compliant with GDPR and/or SOC 2, are they really? This leads to a conversation about the product procurement process and about actually understanding the security risk you take on every time a new product is added to your organization. At what point does security block an acquisition? And after being acquired, how often do you reassess? Supply chain security hygiene starts at procurement - are you part of the evaluation?
Links
Secureless.ai
GDPR Enforcement Tracker
Recorded June 23, 2026 - How can Azure Policies help you? While at Techorama in Belgium, Richard sat down with Barbara Forbes to discuss how Azure Policies have evolved and the techniques sysadmins are using to improve security, cost controls, efficiency, and more. Barbara talks about how the default policies are designed to get folks started in Azure quickly - not necessarily optimally. And there are plenty of policy templates out there, but before you implement them, it's worthwhile to review each policy and ask the question "why?" Keeping good documentation on policies makes it easier to know intent, especially when it comes to changing them - and you'll need to change them! There are a number of ways to apply policies, but in the end, they are just more Infrastructure-as-Code, and so easily repeatable. Azure Policies are there to help you provide freedom with guardrails if you implement them carefully!
Links
Azure Policy
Microsoft Cloud Security Benchmark
Azure Management Groups
Azure Bicep
Terraform on Azure
Recorded May 12, 2026 - How are supply-chain attacks evolving? Richard chats with Mackenzie Jackson about his work helping companies protect their software supply chains from malware attacks. Mackenzie discusses the vulnerability of developers to attacks, since their accounts are often highly privileged and invariably contain access to exploitable secrets. The conversation digs into the challenges of securing various code distribution mechanisms like npm and how you can protect your organization - starting with, don't install packages as soon as they are released! There are effective tools for detecting malware in code, but they take time. Waiting 48 hours can eliminate a lot of risk!
Links
Aikido Software
Trivy
Claude Mythos
OpenClaw
Shai-Hulud Guidance
ClawHub
Open Source Malware
Windows Update Management
Recorded June 15, 2026
More Business podcasts
Trending Business podcasts
About RunAs Radio
RunAs Radio is a weekly Internet Audio Talk Show for IT Professionals working with Microsoft products.
Podcast websiteListen to RunAs Radio, The Diary Of A CEO and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


RunAs Radio
Scan code,
download the app,
start listening.
download the app,
start listening.
RunAs Radio: Podcasts in Family


























