
Secure-by-Design AI: Protecting MLOps in the Microsoft Cloud with Martin Dimovski [MVP-MCT]
Get every episode summarized
Each time M365.FM - Modern work, security, and productivity with Microsoft 365 publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
About this episode
WHY AI SECURITY MATTERS NOW MORE THAN EVER
One of the strongest themes throughout this episode is the speed at which organizations are deploying AI systems without fully understanding the security implications behind them. Martin explains that many companies are currently:
- Deploying AI solutions rapidly
- Experimenting with LLM integrations
- Building AI agents
- Creating cloud-native AI workloads
- Using open-source AI models
- Integrating APIs into production environments
WHAT “SECURE-BY-DESIGN” REALLY MEANS
A major focus of the episode is understanding the concept of secure-by-design architecture. Martin explains that security should never be added after development is complete. Instead, security conversations must begin at the very first design phase of any application or AI project. The discussion covers:
- Threat modeling
- Architectural reviews
- Identity security
- Authentication planning
- Secure pipelines
- Infrastructure protection
- Secure APIs
- Data governance
Security teams should not become blockers for innovation — they should become partners in building secure systems.
UNDERSTANDING MLOPS & DEVSECOPS
For listeners newer to AI infrastructure topics, Martin breaks down the differences between:
- DevOps
- DevSecOps
- MLOps
- Secure AI pipelines
- Large Language Models
- AI agents
- Cloud AI services
- AI APIs
- AI orchestration pipelines
THE REAL DANGER OF PROMPT INJECTION
One of the most fascinating parts of the episode is Martin’s explanation of Prompt Injection attacks. Using simple real-world analogies, Martin explains how attackers manipulate Large Language Models by overriding or bypassing original system instructions. The conversation explores:
- Direct Prompt Injection
- Indirect Prompt Injection
- AI manipulation
- LLM instruction abuse
- Malicious prompts
- Unsafe AI agents
- Context hijacking
- Data extraction risks
THE HIDDEN RISK OF OPEN-SOURCE MODELS
Another major topic is the increasing use of publicly available AI models. Martin shares concerns around:
- Downloading unverified models
- Compromised Hugging Face repositories
- Malicious AI packages
- Unsafe dependencies
- Supply-chain attacks
- API key exposure
- Secret leakage
- Public model poisoning
WHY IDENTITY SECURITY IS EVERYTHING
Identity and access management become another core theme throughout the episode. Martin strongly emphasizes the importance of:
- Microsoft Entra ID
- Privileged Identity Management
- Just-In-Time access
- Least privilege
- Identity governance
- Access reviews
- Role separation
- Conditional Access
MICROSOFT DEFENDER & AI SECURITY
The episode also dives deeply into the Microsoft security ecosystem and how Microsoft Defender is evolving to protect AI workloads. Martin discusses:
- Microsoft Defender for Cloud
- Defender XDR
- AI workload monitoring
- Real-time scanning
- Azure AI Foundry protection
- Threat visibility
- Security telemetry
- Cloud-native protection
Become a supporter of this podcast: https://www.spreaker.com/podcast/m365-fm-a-microsoft-mvp-podcast-by-mirko-peters--6704921/support.
Get every episode summarized
Each time M365.FM - Modern work, security, and productivity with Microsoft 365 publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Know when Martin Dimovski turns up
Follow Martin Dimovski and once a week we email you every new episode they appeared on — including guest spots the show notes never mention, because we read the transcript.
Follow Martin DimovskiFree. Pick your own day and time.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from M365.FM - Modern work, security, and productivity with Microsoft 365

Constraint-Based Scheduling: The Architecture That Makes Production Plans Real
M365.FM - Modern work, security, and productivity with Microsoft 365

A Machine Goes Down. How Should Your Production Plan React?
M365.FM - Modern work, security, and productivity with Microsoft 365

Can Value Stream Mapping Become a Live Data Model?
M365.FM - Modern work, security, and productivity with Microsoft 365

How Finite Capacity Scheduling Actually Works in Manufacturing
M365.FM - Modern work, security, and productivity with Microsoft 365