Reality looks better in post

Proof we're not bluffing

Here’s the evidence. Brand pieces so bold they’ve been asked to tone it down, demos that could teach a goldfish cloud computing, and digital events that made audiences put down their @#$% phones. Every video here was built to grab attention, spark curiosity, and lodge itself in memory like a souvenir you’re strangely attached to. We’re talking craft, care, and the occasional flourish made purely to amuse ourselves. Proof we’re not bluffing—because who has time to fake this many good videos without winning an award or two?

March 2023
Microsoft Security
Microsoft Defender for Office 365: Workflow
Animations
Full playlist
Sandgate
A clear walkthrough of Microsoft Defender for Office 365 incident workflow—detect, investigate, remediate, and learn—keeping context unified to speed response.

Microsoft Defender for Office 365 doesn’t just detect threats—it’s built to move them through a full incident response workflow without dropping context along the way. This animation walks through how email-based threats are discovered and handled across Microsoft 365 Defender: attacks are identified through signals like user submissions, automated detections, and investigations, then analyzed to determine the scope and impacted users. From there, the workflow shows response actions (blocking senders, removing messages, updating policies, taking remediation steps), plus continuous learning—where intel from incidents feeds back into improved detections and protection. The goal is simple: reduce time to detect and time to respond by keeping everything connected inside a unified experience.

We produced this as a process-led explainer—because the story here isn’t one feature, it’s the flow. We shaped the narrative then designed visuals that keep the viewer oriented as the workflow moves between stages. Professional voiceover, steady music, and clean animation make the steps easy to follow at a glance, while sound design and timing help the key moments land without getting noisy. After streamlined review loops, we delivered the full package—closed captions, audio description, and thumbnails—ready to help audiences understand not just what the product does, but how it behaves when things go sideways.

false
March 2023
Microsoft Security
Microsoft Defender for Office 365: Using the Microsoft delisting service
Demo videos
Full playlist
Sandgate
Remove a blocked sending IP—verify the server isn’t compromised, submit the IP at sender.office.com, confirm by email, then delist and restore Microsoft 365 delivery.

This video walks through using the Microsoft Delisting Service to remove a mail server IP from Microsoft’s blocked-senders list when messages to Microsoft 365 users fail with an NDR like “Access denied. Banned sending IP.” It explains why an IP gets blocked (signals like high volumes of phishing/spam implying compromise or abuse), and strongly recommends checking the server for indicators of compromise and reviewing other deny lists before requesting delisting—otherwise you’ll boomerang right back onto the block list. The demo then shows the exact steps: open sender.office.com, enter the email address that received the error and the blocked IP, complete the captcha, confirm via the email you receive, and select Delist IP address—allowing up to 24 hours for changes to propagate across Microsoft’s infrastructure.

We produced this as a step-by-step “get unblocked safely” walkthrough—focused on the decision point that matters (verify you’re not compromised) and the few fields that must be correct for delisting to work. The video pacing is tuned for follow-along, with clean callouts around confirmation and expected propagation time, and final delivery includes closed captions, audio description, and thumbnails.

false
March 2023
Microsoft Security
Microsoft Defender for Office 365: The unified SecOps experience
Demo videos
Full playlist
Sandgate
Explore Defender for Office 365 in the unified Defender portal—investigate email threats through correlated incidents, richer email details, and faster pivots to containment and remediation.

This demo introduces Microsoft Defender for Office 365 inside the unified Microsoft 365 Defender portal, focusing on what changes when email security stops living on its own little island. It shows how email and collaboration threats now roll up into the same incident-driven workflow used across endpoints and identities—so alerts correlate into a single incident with shared context. The walkthrough highlights the improved investigation experience: richer email entity details (authentication checks, detection methods, policy overrides), easier pivots into mailbox and campaign views, and faster paths from “this looks bad” to “contain, remediate, and confirm.” The emphasis is on fewer disconnected alerts, better story-building across domains, and a simpler operational loop for SecOps teams.

We produced this as a platform shift explained like a workflow, not a press release. We choreographed the portal tour to follow how analysts actually investigate, kept the visuals tight on the new views and pivots that matter, and shaped the edit so the benefits land as practical outcomes—less context switching, clearer incidents, and smoother remediation. Final delivery includes closed captions, audio description, and thumbnails.

false
March 2023
Microsoft Security
Microsoft Defender for Office 365: Migration
Animations
Full playlist
Sandgate
A practical migration guide for Microsoft Defender for Office 365—pilot with passive and active protection, ramp SecOps early, and avoid risky MX “big bang” cutovers.

This animation explains a smarter way to migrate to Microsoft Defender for Office 365 without torching user trust on day one. It calls out the common “copy the old rules, flip the MX record, hope for the best” approach—and why it backfires in complex environments: teams carry over allow rules and overrides they don’t fully understand, and SecOps often gets pulled in too late, which slows remediation and raises risk. Instead, it recommends piloting Defender for Office 365 on real traffic using enhanced filtering for connectors plus scoped policies, putting users and groups into passive protection (verdicts only) or active protection (verdicts plus actions). Over time, you can move your legacy filtering system into passive mode, compare misses across both systems, ramp SecOps ahead of the MX change, and migrate at a pace the organization is comfortable with. It closes by pointing to a detailed guide covering three phases: preparing for migration, setting up Defender for Office 365, and onboarding.

We produced this as a clarity-first explainer that turns a high-stakes security change into a calm, repeatable process. We shaped the story around the two pitfalls and the safer alternative, then paced the visuals so each step—pilot, passive vs active, gradual transition, MX switch readiness—lands cleanly without requiring a pause button. Professional voiceover, supportive music, and disciplined motion keep it approachable, while sound polish makes every key term and product name unmistakable. Final delivery included closed captions, audio description, and thumbnails—ready to deploy wherever your audience is planning the migration.

false
March 2023
Microsoft Security
Microsoft Defender for Office 365: Evaluation and trials
Demo videos
Full playlist
Sandgate
Evaluate Defender for Office 365 on production mail flow—enable evaluation mode, choose audit or blocking, review detected threats in reports and Explorer, then convert to standard protection.

This demo shows how to evaluate Microsoft Defender for Office 365 using real production mail flow—with minimal impact on end users. It explains why synthetic testing and journaling fall short, then introduces evaluation mode, which automatically provisions Defender for Office 365 Plan 2 licensing and creates dedicated evaluation policies for anti-phishing, Safe Attachments, and Safe Links. The walkthrough starts from the Microsoft 365 Defender trial banners and the Trials page, then sets up the trial by choosing audit-only mode or active blocking (block is recommended) and selecting which users to include (ideally all users, though you can limit the scope). After setup, it points viewers to the trial user guide and playbook, shows where to view detected threats and manage evaluation settings, and explains how to convert an audit evaluation into standard protection using recommended policy templates. It also demonstrates opening chart details in the Threat protection status report and reinforces that you can use Explorer/Threat Explorer to hunt and investigate real threats during the evaluation, then wraps with the “buy a paid subscription” path in the Microsoft 365 admin center.

We produced this as a practical product trial walkthrough: we organized the story around the few decisions that matter (audit vs block, user scope, where to read results), captured clean portal navigation with precise callouts, and edited for clarity so admins can follow the setup once and replicate it confidently. The payoff is a smooth evaluation experience that shows Defender for Office 365 working on real mail—complete with reports, hunting, and investigation tooling—while keeping your production environment calm and your conclusions defensible. Final delivery includes closed captions, audio description, and thumbnails.

false
March 2023
Microsoft Security
Microsoft Defender for Office 365: Attack simulation training
Demo videos
Full playlist
Sandgate
Run Attack simulation training in Defender—launch credential-harvest sims, assign targeted training, review compromised trends, customize payloads and indicators, and automate recurring simulations at scale.

Attack simulation training in the Microsoft 365 Defender portal is a phish risk-reduction tool that helps you run realistic simulations, measure phishing awareness, deliver targeted training, and track behavior change over time. The video walks through the Attack simulation training dashboard (recent simulations, completion rates, compromised rate trends, repeat offenders by attack type), then demos how to launch a simulation using the Credential Harvest technique with the built-in “2 Failed Messages” payload—selecting target users, assigning training, customizing the training experience, and scheduling launch details. It also shows how to create custom payloads by copying an existing one, editing sender info, links, tags, language, and the email body, adding landing-page indicators, and setting up simulation automations (up to 10 payloads) plus payload automations that harvest real-world-style payloads from your mail flow.

We produced this as a streamlined product demo—from preproduction (nailing the goals, writing the script, and mapping every click) to production (clean screen captures, pro voiceover, and music that keeps the pace lively) to post (tight editing, clear callouts, and zero “demo tenant grime”). The result is a demo that’s easy to follow, suspiciously pleasant to watch, and optimized for retention—more key details, less onscreen flailing, and a story that makes your product feel confident, capable, and downright shiny.

true
March 2023
Microsoft 365
Microsoft Defender for IoT sizzle
Brand films
Full playlist
Lancaster
A fast sizzle on OT security—showing how Microsoft Defender for IoT discovers unmanaged devices, reduces risk, and integrates with Sentinel and Microsoft 365 Defender.

This brand film lays out the looming reality of connected operational technology (OT) and IoT in manufacturing: unmanaged devices, converging OT/IT networks, and a rapidly expanding attack surface. It cites analysts projecting roughly 41 billion OT devices could be internet-facing by 2025, and notes Microsoft found vulnerabilities in 75% of the most common industrial controllers used by customers. The solution centerpiece is Microsoft Defender for IoT—an agentless IoT/OT security platform you can deploy on-premises or in the cloud to discover devices across sites, map communications, and surface risks to crown-jewel assets in a single pane of glass. It also highlights threat intelligence powered by 65 trillion daily signals, plus integrations with Microsoft Sentinel and Microsoft 365 Defender to centralize workflows in the SOC and speed detection and response—wrapping with a CTA to aka.ms/OTGASecurityBlog.

We produced this as a full-spectrum Honeycutt brand film: preproduction to sharpen the story, script, and visual beats before any footage starts misbehaving; production that stays calm, organized, and properly fueled; and post-production where it all gets its shine. We start with a line cut to lock the narrative, then tighten pacing, polish the edit, apply color processing, and craft sound design that makes the message land with confidence. Finally, we deliver the whole launch-ready bundle—closed captions, audio description, and thumbnails—so your video ships cleanly and looks award winning everywhere it goes.

true
March 2023
Microsoft Security
Microsoft Defender for Identity: Remediation
Demo videos
Full playlist
Sandgate
Remediate Defender for Identity alerts—review the detection, identify impacted accounts and activity, apply recommended fixes, and verify the issue is resolved in the Defender portal.

This demo shows how to remediate an identity security issue flagged by Microsoft Defender for Identity, using a detection surfaced in the Microsoft 365 Defender portal. It walks through reviewing the alert details and related entities, then pivots into the recommended response actions—tightening configurations, reducing risky permissions, and addressing the specific condition that triggered the alert so it doesn’t keep firing. The video emphasizes closing the loop the right way: understand the detection, confirm scope (which accounts, which devices, what activity), apply the fix, and validate that the environment is healthier afterward.

This was produced as a remediation-focused walkthrough that keeps the steps grounded in real operator behavior. We structured the flow and captured the relevant portal views with clear narration and clean pacing, and post distilled the sequence so viewers can replicate the remediation approach even when the specific alert type changes. Final delivery includes closed captions, audio description, and thumbnails.

false
March 2023
Microsoft Security
Microsoft Defender for Endpoint: Unified IoCs
Demo videos
Full playlist
Sandgate
Create unified IoCs in Microsoft 365 Defender—add hashes, URLs, domains, or IPs, set allow/block actions, and apply threat intel consistently across Defender.

This demo introduces unified indicators of compromise (IoCs) across the Microsoft 365 Defender portal—so SecOps teams can manage indicators like file hashes, IPs, domains, and URLs in one place. It shows where to create and manage IoCs, how indicators can be set to allow, block, or warn, and how they apply across products like Defender for Endpoint and Defender for Office 365. The walkthrough also touches on tracking indicator status and using IoCs as a fast way to operationalize threat intel.

We produced this as a crisp “turn intel into enforcement” walkthrough: minimal theory, clear steps, and a flow that mirrors how analysts work when something urgent lands in their inbox. The edit focuses on the indicator decisions and their security impact, so viewers walk away with a repeatable pattern they can use immediately. Final delivery includes closed captions, audio description, and thumbnails.

true
March 2023
Microsoft Security
Microsoft Defender for Endpoint: Mobile Threat Defense best practices
Demo videos
Full playlist
Sandgate
Secure mobile access with MTD best practices—connect Defender and Intune, set a risk-based compliance policy, then enforce device compliance with Conditional Access.

This demo covers three Mobile Threat Defense best practices that turn the Microsoft Defender for Endpoint mobile app from “available” into “enforced.” It shows how to share device risk signals between Microsoft Defender for Endpoint and Microsoft Endpoint Manager (Intune), then use that risk level to drive compliance and access. The walkthrough enables the Microsoft Intune connection in the Microsoft 365 Defender portal (Settings > Endpoints > Advanced features) and turns on the Intune connector toggles in Endpoint Manager (Tenant administration > Connectors and tokens > Microsoft Defender for Endpoint). Next, it creates an iOS/iPadOS compliance policy that marks devices noncompliant when the Defender risk level exceeds a strict threshold—choosing Low or, ideally, Clear (and explicitly advising against Medium/High). Finally, it builds an Azure AD Conditional Access policy that requires devices to be marked compliant to access corporate resources, with a safety step to exclude the Global administrator role before switching the policy from report-only to On.

We built this as a “do these three things, win the day” walkthrough—sequenced so each step naturally unlocks the next (signal sharing → compliance → conditional access). The visuals stay close on the toggles and policy fields that matter, the narration calls out the gotchas before they bite (risk level choices, admin lockout), and the edit keeps the momentum so admins can follow once and implement immediately. Final delivery includes closed captions, audio description, and thumbnails.

false
March 2023
Microsoft Security
Microsoft Defender for Endpoint: Overview
Animations
Full playlist
Sandgate
Meet Microsoft Defender for Endpoint—prevent threats, investigate device activity with EDR, prioritize vulnerabilities, and respond faster from a unified security portal.

This overview introduces Microsoft Defender for Endpoint as an endpoint security platform that combines prevention, detection, investigation, and response. It highlights the core capabilities—endpoint protection, EDR visibility, threat and vulnerability management tie-ins, and centralized investigation in the Defender portal—positioning MDE as the place analysts go to understand what happened on a device and contain it quickly. The video frames the value as faster detection, richer context, and smoother response across a fleet.

We built this as a story-forward product overview: clean visuals, confident pacing, and an edit that connects capabilities to outcomes instead of listing features like a grocery receipt. The result is a quick, shareable explanation of what MDE does and why it matters, delivered with captions, audio description, and thumbnails.

false
March 2023
Microsoft Security
Microsoft Defender for Endpoint: Remediating the Log4j exploit
Demo videos
Full playlist
Sandgate
Assess Log4j exposure with Defender Vulnerability Management—identify affected devices, prioritize the biggest risks, and follow remediation guidance to reduce impact fast.

This video shows how Microsoft Defender Vulnerability Management helps you assess and remediate exposure related to Log4j. It walks through finding the relevant security recommendations, identifying affected devices and software, and using the vulnerability and weak-configuration views to understand where risk lives. The demo emphasizes prioritization—focusing on what’s exposed and high impact—then moving into remediation guidance to reduce risk quickly.

We shaped this as a “from headline vulnerability to concrete device list” walkthrough. The pacing is built around the key pivots, with screen time spent on the evidence that drives decisions, not on browsing. Final delivery includes closed captions, audio description, and thumbnails.

false
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.