Episode Details
Back to Episodes
ENTRA PIM EXPLAINED: Securing Privileged Access with Mark Orr [MVP]
Season 2
Published 1 week, 1 day ago
Description
Mark Orr shares his extraordinary journey from serving three combat tours in Iraq as a United States Marine Corps radio and satellite communications specialist to becoming a Microsoft MVP, enterprise architect, and respected Microsoft security expert. He explains how military experience introduced him to networking, satellite communications, IP protocols, and infrastructure management before eventually leading him into Microsoft technologies, Microsoft Intune, Entra ID, automation, and cloud security. His career demonstrates how discipline, resilience, and continuous learning can create entirely new opportunities in enterprise IT.
WHY IDENTITY IS THE NEW SECURITY PERIMETER
Organizations often invest heavily in AI, Copilot, endpoint management, and advanced compliance while overlooking the single most important attack surface: identity. Mark explains why every security strategy should begin with protecting identities before implementing more advanced technologies. According to him, strong authentication, phishing-resistant credentials, and properly secured privileged accounts form the foundation upon which every modern Microsoft security solution depends. Without a secure identity layer, every additional security investment becomes significantly less effective.
WHY IDENTITY ATTACKS DOMINATE MODERN CYBERSECURITY
More than ever, attackers target identities instead of infrastructure. Mark explains that passwords remain one of the weakest links because people frequently reuse credentials across personal and business accounts. Once a password becomes compromised through another service, attackers often gain access to enterprise environments using the same credentials. This is why Microsoft continues pushing organizations toward passwordless authentication and phishing-resistant sign-in methods that dramatically reduce the attack surface.
PASSWORDLESS AUTHENTICATION SHOULD BE EVERY ORGANIZATION'S FIRST GOAL
Mark has been running passwordless authentication since long before it became mainstream. Drawing on years of practical experience, he strongly recommends moving organizations toward Windows Hello for Business, passkeys, Microsoft Authenticator passwordless sign-in, and hardware security keys such as YubiKeys. Besides improving security, passwordless authentication actually creates a better user experience by eliminating forgotten passwords while protecting users from phishing attacks and credential theft.
COMMON MISTAKES WITH PRIVILEGED ACCOUNTS
One of the biggest security mistakes Mark repeatedly encounters is administrators using the same account for both daily productivity and privileged administration. He explains why administrative identities should always be isolated cloud-only accounts without Exchange mailboxes, Teams licenses, or normal productivity workloads. Separating privileged identities dramatically reduces phishing exposure and prevents attackers from gaining administrative access through compromised user activities.
ZERO TRUST IS A JOURNEY, NOT A DESTINATION
Zero Trust is often treated as a final objective, but Mark argues that organizations never truly "finish" Zero Trust. Instead, security teams should focus on continuously improving their security posture rather than waiting for perfection. He recommends combining compliant devices, known networks, phishing-resistant authentication, Conditional Access policies, and trusted administrator workstations while continuously strengthening remaining gaps over time. Progress matters far more than chasing an impossible end state. HOW MICROSOFT INTUNE AND MICROSOFT ENTRA ID WORK TOGETHER Rather than viewing Microsoft Intune and Microsoft Entra ID as separate products, Mark explains how both platforms complement each other to create a unified security architecture. Entra ID protects identities through authentication, Conditional Access, and role-based acce
WHY IDENTITY IS THE NEW SECURITY PERIMETER
Organizations often invest heavily in AI, Copilot, endpoint management, and advanced compliance while overlooking the single most important attack surface: identity. Mark explains why every security strategy should begin with protecting identities before implementing more advanced technologies. According to him, strong authentication, phishing-resistant credentials, and properly secured privileged accounts form the foundation upon which every modern Microsoft security solution depends. Without a secure identity layer, every additional security investment becomes significantly less effective.
WHY IDENTITY ATTACKS DOMINATE MODERN CYBERSECURITY
More than ever, attackers target identities instead of infrastructure. Mark explains that passwords remain one of the weakest links because people frequently reuse credentials across personal and business accounts. Once a password becomes compromised through another service, attackers often gain access to enterprise environments using the same credentials. This is why Microsoft continues pushing organizations toward passwordless authentication and phishing-resistant sign-in methods that dramatically reduce the attack surface.
PASSWORDLESS AUTHENTICATION SHOULD BE EVERY ORGANIZATION'S FIRST GOAL
Mark has been running passwordless authentication since long before it became mainstream. Drawing on years of practical experience, he strongly recommends moving organizations toward Windows Hello for Business, passkeys, Microsoft Authenticator passwordless sign-in, and hardware security keys such as YubiKeys. Besides improving security, passwordless authentication actually creates a better user experience by eliminating forgotten passwords while protecting users from phishing attacks and credential theft.
COMMON MISTAKES WITH PRIVILEGED ACCOUNTS
One of the biggest security mistakes Mark repeatedly encounters is administrators using the same account for both daily productivity and privileged administration. He explains why administrative identities should always be isolated cloud-only accounts without Exchange mailboxes, Teams licenses, or normal productivity workloads. Separating privileged identities dramatically reduces phishing exposure and prevents attackers from gaining administrative access through compromised user activities.
ZERO TRUST IS A JOURNEY, NOT A DESTINATION
Zero Trust is often treated as a final objective, but Mark argues that organizations never truly "finish" Zero Trust. Instead, security teams should focus on continuously improving their security posture rather than waiting for perfection. He recommends combining compliant devices, known networks, phishing-resistant authentication, Conditional Access policies, and trusted administrator workstations while continuously strengthening remaining gaps over time. Progress matters far more than chasing an impossible end state. HOW MICROSOFT INTUNE AND MICROSOFT ENTRA ID WORK TOGETHER Rather than viewing Microsoft Intune and Microsoft Entra ID as separate products, Mark explains how both platforms complement each other to create a unified security architecture. Entra ID protects identities through authentication, Conditional Access, and role-based acce