I was almost scammed by AI, and it was terrifyingly convincing.

A few weeks ago, I received an email from someone claiming to work for ShareGate. If you’re not familiar with them, ShareGate is a well-known software company that builds tools for migrating, managing, and securing Microsoft 365 environments, SharePoint, Teams, OneDrive, and more. Their software is widely used by IT admins for tenant-to-tenant migrations and governance.

The email opened with a detailed summary of one of my blog posts, which covers migrating Exchange MRM policies to Purview DLM. It accurately captured the practical approach I’d laid out and even noted that the article highlighted pitfalls in the migration process that are often overlooked. On that point, the message was spot on.

Then came the ask: would I be interested in a paid placement where “we” (ShareGate) could demonstrate how ShareGate Migrate handles the policy assessment and transition piece of the workflow? Again, the details were precise and technically accurate.

Why I didn’t suspect anything at first

My first thought was whether this counted as sponsorship. Since I’m relatively new to this space, it hadn’t really occurred to me that I might be offered payment to cover expenses. At that point, nothing felt off, for a few reasons:

Continue reading “I was almost scammed by AI, and it was terrifyingly convincing.”

Periodic password resets, ancient myth or modern need?

At the time we began embracing the (public) cloud, we also started changing the way we safeguard our data. In the classic datacenter model, our data was buried deep within a datacenter that was separated from the outside world by using a firewall. It was your single entry point for accessing your companies data. Solutions to make your data accessible when away from the office was by using a VPN or other remote connection such as a Citrix or VDI environment.

Modern workplace environments don’t rely on the firewall anymore to protect data from being accessed by the outside world. We trust cloud providers to take care of the datacenter part and companies themselves are made responsible to safeguard their data. In this modern cloud approach the user account itself is at the center of accessing data. If anyone with bad intentions is able to get their hands on a username and password combination this gives them access to all the data the user has access to, for example in the Microsoft Cloud (Onedrive, Sharepoint, etc).

So we should make sure our users change their password periodically so bad people have a hard time guessing passwords right? Wrong.

Continue reading “Periodic password resets, ancient myth or modern need?”