Today we’re excited to bring OpenAI’s GPT-5.2 to Microsoft 365 Copilot and Microsoft Copilot Studio.
The post Available today: GPT-5.2 in Microsoft 365 Copilot appeared first on Microsoft 365 Blog.
In this episode guest host Greg Cochran from the GitHub Secure Open Source Fund brings together four maintainers who are helping secure the open source projects we all depend on: Christian (Log4j/Log4Shell), Carlos (GoReleaser), Michael (EVCC), and Camila (ScanAPI) to unpack what it really looks like to level up security in critical OSS.
They share how the Fund’s three-week security sprint, ongoing check-ins, and tight-knit community helped them move from “we don’t know what we don’t know” to concrete wins: hardened GitHub Actions pipelines, incident response plans, better reporting processes, and SBOMs that actually include dependency licenses. They also talk candidly about asking “dumb” questions in a trusted space and the ripple effect when one project’s security posture improves across its dependents. Finally, the group dives into AI security: using fuzzing, GitHub Copilot, and tools like the Secure Code Game both to find vulnerabilities faster and to keep up with attackers who now have AI on their side too.
Links mentioned in the episode:
GitHub Secure Open Source Fund overview
Announcing GitHub Secure Open Source Fund
Inside the breach that broke the internet: The untold story of Log4Shell
Log4j / Log4Shell video (castle interview with Christian)
EVCC – open source EV charging & energy management
GoReleaser – release engineering automation
ScanAPI – automated API testing & live documentation
Secure Code Game (GitHub Security Lab)
GitHub Copilot – AI coding assistant
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
1142. This week, we look at the history of the phrase "pride and prejudice," which was used frequently before Jane Austen’s 1813 novel. Then, we look at whether Parson Brown from “Winter Wonderland” was a real person, and why his name is sometimes replaced with a “circus clown.”
Links to Get One Month Free of the Grammar Girl Patreon (different links for different levels)
🔗 Share your familect recording in Speakpipe or by leaving a voicemail at 833-214-GIRL (833-214-4475)
🔗 Watch my LinkedIn Learning writing courses.
🔗 Subscribe to the newsletter.
🔗 Take our advertising survey.
🔗 Get the edited transcript.
🔗 Get Grammar Girl books.
🔗 Join Grammarpalooza. Get ad-free and bonus episodes at Apple Podcasts or Subtext. Learn more about the difference.
| HOST: Mignon Fogarty
| Grammar Girl is part of the Quick and Dirty Tips podcast network.
| Theme music by Catherine Rannus.
| Grammar Girl Social Media: YouTube. TikTok. Facebook. Threads. Instagram. LinkedIn. Mastodon. Bluesky.
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
This episode of Armchair Architects, featuring Uli, Eric, and David, focuses on the integration of AI agents within enterprise environments. The discussion explores how to connect, govern, and secure multiple agents, emphasizing protocols, identity management, and practical frameworks for architecting safe and effective agent-based systems.
Three Important Things You Will Learn
- Agent Identity Management: Why traditional human-centric identity systems are insufficient for agents, and how tailored agent identity solutions improve security and control.
- Protocols for Integration: The role of Model Context Protocol (MCP) and Agent-to-Agent (A2A) communication in enabling agents to interact safely and effectively, including architectural decisions around guardrails and business logic.
- Best Practices for Agent Design: The importance of building agents with limited, well-defined scopes, implementing least privilege, and using observability tools like OpenTelemetry for monitoring and safety.
Recommended Next Steps
- Evaluate Agent Use Cases: Assess whether your business problem truly requires an agent, and define its scope and success metrics.
- Implement Secure Identity and Protocols: Adopt agent-specific identity solutions and integration protocols (MCP, A2A) with strong authorization and minimal privilege.
- Plan for Observability and Safe Deployment: Instrument agents with OpenTelemetry, use ring releases or canary deployments, and monitor cost, performance, and safety before scaling.
Resources
- Build Agents using Model Context Protocol on Azure https://learn.microsoft.com/azure/developer/ai/intro-agents-mcp
- Introduction to Application Insights - OpenTelemetry observability https://learn.microsoft.com/azure/azure-monitor/app/app-insights-overview
- Microsoft Entra https://learn.microsoft.com/entra/
- Microsoft Agent Framework https://learn.microsoft.com/agent-framework/overview/agent-framework-overview
- Terminator https://wikipedia.org/wiki/The_Terminator
Related Episodes
- Watch more episodes of Armchair Architects https://aka.ms/ArmchairArchitects
- Watch more episodes of the Azure Essentials Show https://aka.ms/AzureEssentialsShow
Connect
- David Blank-Edelman https://www.linkedin.com/in/dnblankedelman/
- Uli Homann https://www.linkedin.com/in/ulrichhomann/
- Eric Charran https://www.linkedin.com/in/ericcharran/
Chapters
00:00 Introduction
01:22 Agent identity management
03:51 Model Context Protocol (MCP)
06:15 Knowledge and memory
07:15 Observability and OpenTelemetry
08:18 MCP considerations
09:53 Agent-to-agent (A2A)
11:10 Should you build an agent?
12:10 Determine architectural components
14:35 Similarities to services
15:22 Watch Terminator