CRM Audio
CRM Audio

CRM Audio

George Doubinski

Overview
Episodes

Details

CRM Audio is a network of podcasts about Dynamics 365, Dynamics CRM, personal productivity, and Power BI hosted by Microsoft Business Solutions MVP's Joel Lindstrom, George Doubinski, Shawn Tabor, Mark Smith, and Scott Sewell and productivity expert Matthew C. Anderson. We are the original CRM MVP Podcast. Podcasts in the feed: CRM Audio - a roundtable discussion of all things CRM, including what's new, best practices, and answers to your CRM questions and Power BI. Power BI and More - Microsoft Business Solutions MVP Scott Sewell teaches you how to learn Power BI and effectively use it with Dynamics 365. Prodcast - All about personal productivity. We get deep into productivity and cut through the hype around productivity tools, and tell you what's not productive.

Recent Episodes

End Of The World As We Know It: Security Leaks In Power Pages
AUG 17, 2025
End Of The World As We Know It: Security Leaks In Power Pages

In this episode, we take a close look at the history of security issues in Power Pages. We start with the early days — when simple misconfigurations like unchecked table permissions and enabled OData feeds led to major data exposures. These weren't bugs, but they showed how easy it was to set things up the wrong way. We talk about how Microsoft responded and what lessons we've learned about secure defaults and clear documentation.

We then move on to more serious vulnerabilities introduced by newer features like the Web API. We explain how some of these flaws allowed access to restricted data using filters and sort clauses, and how those issues were eventually patched. These were real product-level bugs, and some were even exploited in the wild.

We also share our thoughts on external authentication providers like Google, and the risks that come with delegating authentication — including phishing techniques that can bypass protections. Finally, we reflect on how Power Pages compares to platforms like WordPress, especially when it comes to architecture and the potential for plugin-related vulnerabilities. Despite recent issues, we think the original design of Power Pages deserves credit for holding up well over time.

References
Get in touch
play-circle icon
34 MIN
Cache Me If You Can: The Power Pages Wishlist
MAY 31, 2025
Cache Me If You Can: The Power Pages Wishlist
play-circle icon
31 MIN
What's Really Coming in Release Wave 1 2025: AI Hype And A New Security Threat
MAR 10, 2025
What's Really Coming in Release Wave 1 2025: AI Hype And A New Security Threat

In the first episode of 2025, Nick and George break down Release Wave 1 2025 for Power Pages, separating real improvements from underwhelming updates. AI features take center stage, but do they actually add value? Discussion covers AI-assisted forms, web agents, and natural language queries, questioning their usefulness in real-world applications.

Modern lists get long-awaited updates, including JavaScript event support and metadata filters, finally closing gaps with classic lists. The ongoing file upload saga resurfaces, and the new virus scanning feature raises questions about effectiveness. A streamlined Microsoft Entra ID setup wizard promises easier authentication setup, but handling failed logins remains tricky.

A surprising security threat in social logins also comes up — cross-IdP impersonation —where external authenticator can let attackers register an account with someone else's corporate email.

With event portals moving from outbound marketing to Power Pages, the clock ticks toward a July 2025 deadline for migration. Anyone still using the old Angular-based event sites needs to start planning now.

Want to know what's missing from this release? A wishlist of features Power Pages actually needs is coming next time. Don't miss it!

Credits

Cover image by chatGPT (inspired by terrible prompts)

References
Get in touch
play-circle icon
36 MIN