Karl-Johan Spiik, Microsoft MVP

Action is the most beautiful form of speech

Do You Need a Custom Agent to Detect Anomalies?

No — you usually don’t. Power Platform and Dataverse already include built‑in mechanisms for detecting abnormal or unexpected usage. Whether you need a custom solution depends entirely on what you mean by “anomalous behavior.” 1. Detecting Anomalous Behavior Inside Dataverse… Continue Reading →

Play it (w)right — Automating End‑to‑End Tests in the Power Platform

At CollabDays Bremen 2026, I attended the session “Play it (w)right: automate your end-to-end tests in the Power Platform.” held by Arjan Rijsdijk (slides). This was one of the most practical, demo-rich experiences of the entire event, and it completely… Continue Reading →

Oops!…I Vibe Coded Again

At CollabDays Bremen, I joined a session titled “Oops!…I Vibe Coded Again: AI-Assisted Development in Power Platform & M365.” prented by MVP Timo Pertilä. Going in, I already had a good sense of what vibe coding is in theory, but… Continue Reading →

From Likes to Insights: Measuring Real User Experience in Conversational AI

At CollabDays Bremen this year, one session stood out for its clarity, practicality, and truth‑telling about a challenge many AI teams quietly struggle with. Katerina Chernevskaya delivered a deeply insightful talk on a topic that is easy to overlook in… Continue Reading →

Power Platform Governance & Security Architecture

I attended CollabDays Bremen last weekend. Session led by Stalin Ponnusamy, MVP provided a comprehensive and practical deep dive into Power Platform governance, breaking down the layered security model that organizations must understand to protect sensitive data in a world… Continue Reading →

You are ready for AI! But are your users?

I attended CollabDays Bremen last weekend. I attended Leo Visser’s session without any expectations as I just arrived at the venue.  Internal Reflection: Key Takeaways From Leo Visser’s Presentation Leo Visser’s session took a broad and sometimes chaotic landscape —… Continue Reading →

Fixing Prompt Injection Vulnerability

I’ve been building agents a while and after CollabDays Portugal I had the idea of hacking my own Copilot Studio agent. Other MVPs discussed how important and hot topic security is and I had an idea. I realised that if… Continue Reading →

Copilot Studio Agent Security

Below are the mitigations that significantly reduce exfiltration risk. These should be in place before deploying any Copilot Studio agent to a production environment. 1. Apply Least‑Privilege Access Only grant the agent permissions it absolutely needs — nothing more.If the… Continue Reading →

Obfuscated request patterns and rapid‑fire multi‑turn scripts

There was still couple tests to run for my agent before thinking how to fix problems. Like in any testing, it is important to run all tests, then analyse before starting to fix anything when first bug is revealed. Many… Continue Reading →

Copilot Studio Agent Data Exfiltration

I wanted to test how easy it was hacking my own agent created in July. I seems prompt injection was quite easy. I did not know how to hack the agent other means, I needed to ring my old pall… Continue Reading →

« Older posts

© 2026 Karl-Johan Spiik, Microsoft MVP — Powered by WordPress

Theme by Anders NorenUp ↑