<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>rss.livelink.threads-in-node</title>
    <link>https://techcommunity.microsoft.com/t5/microsoft-security/ct-p/microsoft-security</link>
    <description>rss.livelink.threads-in-node</description>
    <pubDate>Wed, 29 Jul 2026 07:52:03 GMT</pubDate>
    <dc:creator>microsoft-security</dc:creator>
    <dc:date>2026-07-29T07:52:03Z</dc:date>
    <item>
      <title>Graph API Endpoint for the Vulnerability Profile</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr/graph-api-endpoint-for-the-vulnerability-profile/m-p/4541551#M2741</link>
      <description>&lt;P&gt;I can use this endpoint to get threat reports via the graph api&amp;nbsp;&lt;/P&gt;&lt;P&gt;GET&amp;nbsp;&lt;/P&gt;&lt;P&gt;https://graph.microsoft.com/beta/security/threatIntelligence/article&lt;/P&gt;&lt;P&gt;but threat Analytics reports that come in from defender that are category: vulnerability, aren't in there However they are written up in an article style. What endpoint do I need to hit to get these types of reports.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2026 12:02:06 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr/graph-api-endpoint-for-the-vulnerability-profile/m-p/4541551#M2741</guid>
      <dc:creator>scottholland</dc:creator>
      <dc:date>2026-07-28T12:02:06Z</dc:date>
    </item>
    <item>
      <title>Verifying domain name issue</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/verifying-domain-name-issue/m-p/4541541#M10423</link>
      <description>&lt;P&gt;We're trying to verify our custom domain in Entra ID, but it turns out the domain is already claimed on another tenant that we have no access to (unknown account, no admin credentials). Because of that, verification on our own tenant fails.&lt;/P&gt;&lt;P&gt;Normally the fix for a claimed-domain conflict is to open a support request so Microsoft can help release it. The problem: doing that requires a support plan, and purchasing one doesn't work for us. "payment" always succeeds and we dont get an error, but we don't get charged and the account status doesn't change, we have nothing more to go on.&lt;/P&gt;&lt;P&gt;So we're stuck in a loop: we need support to release the domain, but we can't buy the support plan needed to reach support.&lt;/P&gt;&lt;P&gt;Has anyone dealt with a domain claimed on an inaccessible tenant? And is there another route to Microsoft support when the support plan purchase itself fails?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2026 11:34:53 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/verifying-domain-name-issue/m-p/4541541#M10423</guid>
      <dc:creator>I-Leadership</dc:creator>
      <dc:date>2026-07-28T11:34:53Z</dc:date>
    </item>
    <item>
      <title>Microsoft Fabric metadata in Microsoft Purview</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-purview/microsoft-fabric-metadata-in-microsoft-purview/m-p/4541393#M2888</link>
      <description>&lt;P&gt;I’ve been mapping how &lt;STRONG&gt;Microsoft Fabric metadata is surfaced in Microsoft Purview through Data Map scanning&lt;/STRONG&gt;, and I’ve created this visual to make the relationship easier to understand.&lt;/P&gt;&lt;img /&gt;&lt;P&gt;The diagram separates:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Documented mappings&lt;/STRONG&gt; – such as Fabric items, Lakehouse tables, schema and item-level lineage.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Metadata known to be scanned, but where the exact Purview UI location needs confirmation.&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;? Areas still needing validation&lt;/STRONG&gt; – particularly Lakehouse table/column descriptions and tags.&lt;/P&gt;&lt;P&gt;The principle I’m exploring is:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Microsoft Fabric → Purview Data Map Scan → Purview Data Asset → Purview governance enrichment&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Importantly, a Fabric asset does &lt;STRONG&gt;not&lt;/STRONG&gt; automatically become a Purview Data Product. It is first represented as a Data Asset, which can then be governed, enriched and associated with a Data Product.&lt;/P&gt;&lt;P&gt;I’d really appreciate feedback from anyone working hands-on with &lt;STRONG&gt;Microsoft Fabric and Microsoft Purview&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Does this mapping match what you are seeing in your environment?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I’m particularly interested in confirming:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Lakehouse table descriptions → Purview Asset Description?&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Lakehouse column descriptions → Purview Schema → Column Description?&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Lakehouse table/column tags → where exactly are these surfaced in Purview?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Corrections, screenshots or practical experience would be very welcome.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2026 07:18:33 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-purview/microsoft-fabric-metadata-in-microsoft-purview/m-p/4541393#M2888</guid>
      <dc:creator>sashakorniakUK</dc:creator>
      <dc:date>2026-07-28T07:18:33Z</dc:date>
    </item>
    <item>
      <title>Rescheduled Webinar: What's New in Azure Firewall</title>
      <link>https://techcommunity.microsoft.com/t5/azure-network-security/rescheduled-webinar-what-s-new-in-azure-firewall/m-p/4541265#M216</link>
      <description>&lt;P&gt;Hi everyone!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The webinar "What's New in Azure Firewall" that was originally scheduled for August 6th, has been rescheduled to August 26th. You can find more details on our &lt;A class="lia-external-url" href="https://securitycommunity.microsoft.com/VirtualEvents/Webinar-Details/?id=96d39a8e-bc5e-f111-a826-6045bd023cfc" target="_blank"&gt;Community Home.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We apologize for the inconvenience, and hope to see you there!&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2026 18:38:07 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/azure-network-security/rescheduled-webinar-what-s-new-in-azure-firewall/m-p/4541265#M216</guid>
      <dc:creator>emilyfalla</dc:creator>
      <dc:date>2026-07-27T18:38:07Z</dc:date>
    </item>
    <item>
      <title>Securing AI Agents at Runtime: Real-Time Protection and Threat Detection for Microsoft Agent 365</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/securing-ai-agents-at-runtime-real-time-protection-and-threat/ba-p/4541255</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Organizations are rapidly adopting AI agents to automate workflows, access enterprise data, invoke tools, and take actions on behalf of users. This autonomy creates a fundamentally new security challenge.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Unlike traditional AI applications, agents&amp;nbsp;operate&amp;nbsp;across dynamic execution flows, interacting with external content, calling tools, and accessing sensitive resources. These interactions create new attack paths that traditional security controls were not designed to address.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Today,&amp;nbsp;we're&amp;nbsp;announcing two major milestones for Security for AI in Microsoft Defender for Microsoft Agent 365:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Threat&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;d&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;etection for Microsoft Agent 365 agents —&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;now in&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;public preview&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Real-&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;t&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;ime&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;p&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;rotection for&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/microsoft-agent-365/developer/tooling?tabs=python" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Agent 365 tooling servers&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;—&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;now&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;generally available&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Together, these capabilities help security teams detect, investigate, and block attacks targeting AI agents, extending Microsoft Defender's threat protection capabilities into the&amp;nbsp;agent&amp;nbsp;runtime.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Threat&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;d&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;etection for&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Microsoft&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;A&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;gent&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;365&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;A&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;gents (Public Preview)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:480,&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Threat&amp;nbsp;detection provides SOC teams with&amp;nbsp;detailed&amp;nbsp;visibility into attacks and suspicious activity targeting AI agents.&amp;nbsp;By analyzing runtime signals across agent interactions, tool usage, and execution patterns, Microsoft Defender&amp;nbsp;identifies&amp;nbsp;suspicious and malicious behavior&amp;nbsp;throughout&amp;nbsp;the&amp;nbsp;agent&amp;nbsp;execution lifecycle and surfaces actionable security alerts for SOC teams.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Threat&amp;nbsp;detection supports cloud agent types that emit observability logs to&amp;nbsp;Microsoft&amp;nbsp;Agent&amp;nbsp;365, including:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Microsoft Copilot Studio&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="4" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Microsoft Foundry&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="5" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Microsoft 365 Copilot Agent Builder&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="6" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Agents integrated through the Microsoft Agent 365 SDK&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;This provides consistent&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;threat&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;visibility across supported Microsoft Agent 365 agent experiences, regardless of how the agent was built.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Fig. 1. Microsoft Security for AI alerts in Microsoft Defender XDR (Preview)&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559685&amp;quot;:720,&amp;quot;335559731&amp;quot;:720}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-center"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Defender&amp;nbsp;identifies&amp;nbsp;a broad range of AI-specific threats, including:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="7" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Indirect prompt injection (XPIA)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;— malicious instructions embedded in external content designed to manipulate agent behavior.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="8" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Evasion techniques&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;—&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;attempts&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;to bypass agent instructions or security controls.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="9" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Malicious content propagation&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;—&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;attempts&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;to use agents to generate or distribute malicious content.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="10" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Secret leakage&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt; — exposure&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;of&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;credentials, API keys, or other sensitive information through agent interactions.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="11" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;LLM reconnaissance&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;—&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;attempts&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;to probe agent capabilities, instructions, or security boundaries.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="12" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Suspicious IP access&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;— agent access originating from anonymized or suspicious IP addresses.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Alerts are surfaced directly in Microsoft Defender, enabling SOC analysts to investigate and respond using familiar workflows, Advanced Hunting queries, and the Defender XDR investigation experience.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Real-&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;t&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;ime&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;p&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;rotection for WorkIQ and Custom MCP servers&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;&amp;nbsp;(General Availability)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:480,&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Real-time protection moves beyond detection by blocking threats inline when AI agents interact with WorkIQ and custom MCP servers (see&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/microsoft-agent-365/developer/tooling?tabs=python" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Agent 365 tooling servers)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;When an agent invokes a registered tool or receives a tool response, Defender evaluates the interaction against configured security policies and&amp;nbsp;determines&amp;nbsp;whether to allow or block it directly within the agent's execution flow.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This helps prevent malicious actions and data leakage in real time, without requiring agent developers to implement custom security logic.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Fig. 2. Microsoft Security for AI Real-Time Protection policy in Defender&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559685&amp;quot;:720,&amp;quot;335559731&amp;quot;:720}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Real-time&amp;nbsp;protection&amp;nbsp;currently guards against high-impact threats, including:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="13" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Evasion techniques&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;—&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;attempts&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;to bypass agent guardrails or security controls.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="14" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Malicious content propagation&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;— preventing agents from spreading&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;malicious&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;content through tool actions.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="15" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Secret leakage&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;— blocking agents from inadvertently exposing credentials or sensitive data through tool calls.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="16" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Communication with untrusted domains&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;— preventing agents from sending email or data to high-risk or untrusted email domains.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Better Together: Detection&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;and&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;&amp;nbsp;Protection&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:480,&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Threat&amp;nbsp;detection and&amp;nbsp;real-time&amp;nbsp;protection address complementary parts of the&amp;nbsp;agent&amp;nbsp;security lifecycle.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Real-time&amp;nbsp;protection provides inline enforcement to block malicious interactions during execution, while&amp;nbsp;threat&amp;nbsp;detection gives SOC teams the visibility and investigation context needed to&amp;nbsp;identify&amp;nbsp;attack patterns, assess impact, and respond to suspicious activity.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Together, they provide a defense-in-depth approach that combines runtime enforcement with SOC-driven detection and investigation, purpose-built for AI agents.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Getting Started&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:480,&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Both capabilities are available through&amp;nbsp;Microsoft Defender,&amp;nbsp;using&amp;nbsp;a dedicated&amp;nbsp;Security for AI workload&amp;nbsp;experience that brings together AI threat detections, investigations, and runtime protection policies.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To learn more:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-xdr/security-for-ai/get-started-defender-security-for-ai" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Enable security for AI agents using Microsoft Defender&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-xdr/security-for-ai/ai-agent-detection-protection" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Detect and investigate threats to AI agents using Microsoft Defender (Preview)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="3" data-aria-level="1"&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-xdr/security-for-ai/ai-agent-real-time-protection" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Protect AI agents in real time using Microsoft Defender&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;As AI agents become more autonomous and gain access to enterprise data and tools, securing their runtime behavior becomes critical. With Threat Detection and Real-Time Protection, Microsoft Defender helps organizations adopt AI agents with security controls designed for how agents&amp;nbsp;actually operate—detecting attacks, enabling SOC investigation, and blocking malicious interactions at runtime.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2026 17:37:49 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/securing-ai-agents-at-runtime-real-time-protection-and-threat/ba-p/4541255</guid>
      <dc:creator>llevy</dc:creator>
      <dc:date>2026-07-27T17:37:49Z</dc:date>
    </item>
    <item>
      <title>Level Up Your Security Skills This August with the Microsoft Defender Challenge and Learn Live</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/level-up-your-security-skills-this-august-with-the-microsoft/ba-p/4541235</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Security teams face an increasingly complex landscape. Threats span identities, endpoints, email, cloud workloads, and emerging AI environments. The best defenders aren't just reacting to threats—they're continuously building the skills needed to stay ahead.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;That's why we're inviting security practitioners to build practical security operations expertise while working toward their next certification goal. Running from July 20 through August 21, 2026, and focused on skills across Microsoft Defender XDR, Microsoft Sentinel, and Microsoft Defender for Cloud, this hands-on learning experience is the &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/security/challenge/defender-challenge" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;Microsoft Defender Challenge.&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5 aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Build Skills That Matter to the Modern SOC&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:480,&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/security/challenge/defender-challenge" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;The Microsoft Defender Challenge&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; isn't about memorizing content for an exam. It's designed to help you develop real-world security skills you can apply immediately in your organization. Through curated Microsoft Learn content, you'll strengthen your ability to:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="994" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559683&amp;quot;:0,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Detect, investigate, and respond to threats across Microsoft Defender XDR&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="994" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559683&amp;quot;:0,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Manage incidents and automate workflows with Microsoft Sentinel&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="994" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559683&amp;quot;:0,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Triage and remediate security alerts in Microsoft Defender for Cloud&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="994" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559683&amp;quot;:0,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="4" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Secure cloud and AI workloads using modern security practices&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="994" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559683&amp;quot;:0,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="5" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Improve operational readiness for today's evolving threat landscape&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Whether you're a SOC analyst, security engineer, cloud security practitioner, or IT professional looking to expand your security expertise, the challenge is an opportunity to sharpen skills that map directly to modern security operations.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5 aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Complete the Challenge and Enter the Sweepstakes&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:480,&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Learning is the real reward, but there's an added incentive. Participants who complete the Microsoft Defender Challenge and submit the official sweepstakes entry form by August 21, 2026 will have the opportunity to win one of 500 certification exam vouchers worth 50% off one of the following Microsoft Certifications:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="993" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559683&amp;quot;:0,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;A href="https://learn.microsoft.com/en-us/credentials/certifications/security-operations-analyst/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;SC-200: Microsoft Security Operations Analyst&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="993" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559683&amp;quot;:0,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;A href="https://learn.microsoft.com/en-us/credentials/certifications/cloud-and-ai-security-engineer-associate/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;SC-500: Microsoft Cloud and AI Security Engineer&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;How to Enter&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:200,&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="992" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:720,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Complete the &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/security/challenge/defender-challenge" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Defender Challenge&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; on Microsoft Learn.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="992" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:720,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Before the entry period closes, submit the &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/security/challenge/defender-challenge" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;official sweepstakes entry form.&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="992" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:720,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;If selected, you'll receive instructions for redeeming your certification discount voucher.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Challenge window: July 20 – August 21, 2026. Sweepstakes entry deadline: August 21, 2026 at 11:59 PM UTC.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;No purchase necessary. See&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/credentials/support/microsoft-defender-challenge-sweepstakes-terms-and-conditions" target="_blank" rel="noopener"&gt; official rules&lt;/A&gt; for eligibility and sweepstakes details.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Join Learn Live: Remediating Threats Using Microsoft Defender&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:480,&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Want a guided walkthrough of the skills featured in the challenge? Join a live, interactive event where you can learn directly from Microsoft experts, ask questions in real time, and explore security operations scenarios together. Save your spot for our August &lt;/SPAN&gt;&lt;A href="https://aka.ms/LearnLive819/b" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;Learn Live session.&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Date: Wednesday, August 19, 2026&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp; Time: 12:00 PM PT / 3:00 PM ET&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;You'll be guided by Scott Landry, Microsoft Security Customer Experience Engineering, as you explore practical approaches to investigating security incidents, managing and remediating threats across the Microsoft Defender ecosystem, automating investigations and response actions, strengthening security operations processes, and applying Microsoft Defender capabilities to real-world scenarios.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5 aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Start Building Your Skills Today&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:480,&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Ready to level up? Sign up today to take the &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/security/challenge/defender-challenge" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Defender Challenge&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, then join us for the &lt;/SPAN&gt;&lt;A href="https://aka.ms/LearnLive819/b" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Learn Live session&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; on August 19. Your skilling journey doesn't end here—keep learning, keep growing, and keep building beyond August at the &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/security/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;Security Hub on Microsoft Learn.&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2026 16:47:02 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/level-up-your-security-skills-this-august-with-the-microsoft/ba-p/4541235</guid>
      <dc:creator>ShirleyseHaley</dc:creator>
      <dc:date>2026-07-27T16:47:02Z</dc:date>
    </item>
    <item>
      <title>Prioritize exposure resolution with a new dashboard experience (public preview)</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-exposure/prioritize-exposure-resolution-with-a-new-dashboard-experience/ba-p/4540163</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Cut Through the Noise and Focus on What Matters Most&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Security teams face a constant challenge: too many findings, too many dashboards, and not enough clarity on where to act first.&lt;/P&gt;
&lt;P&gt;Organizations today are managing vulnerabilities, internet-facing assets, misconfigurations, code weaknesses, exposed secrets and more &amp;nbsp;across an increasingly complex environment. While each signal is valuable on its own, security teams often spend significant time switching between tools and reports to determine where risk is concentrated and what actions will have the greatest impact.&lt;/P&gt;
&lt;P&gt;Today, we're excited to announce the &lt;STRONG&gt;public preview of the redesigned Exposure Management dashboard&lt;/STRONG&gt;, helping analysts to quickly identify the risks that matter most, act with confidence, and follow a clear path toward zero critical issues.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;STRONG&gt;From Visibility to Action&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Exposure management is most effective when it helps security teams move beyond visibility and into remediation. Every insight is designed to support decision-making and accelerate remediation.&lt;/P&gt;
&lt;P&gt;The redesigned dashboard consolidates critical&lt;STRONG&gt; &lt;/STRONG&gt;signals across:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Validated internet-exposed assets&lt;/LI&gt;
&lt;LI&gt;Business critical assets&lt;/LI&gt;
&lt;LI&gt;Vulnerabilities&lt;/LI&gt;
&lt;LI&gt;Security misconfigurations&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The dashboard prioritizes findings based on risk and directly connects them to remediation workflows. Security analysts can immediately understand:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Where exposure is highest&lt;/LI&gt;
&lt;LI&gt;Which risks require immediate attention&lt;/LI&gt;
&lt;LI&gt;What actions will reduce risk fastest&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Resolve Risk Faster with Resolve Now&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;At the center of the new experience is &lt;STRONG&gt;Resolve Now&lt;/STRONG&gt;, a focused set of prioritized recommendations designed to help reduce exposure on internet-exposed and business-critical assets. Resolve Now organizes work into three action categories, with items within each category prioritized based on the remediation approach:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;STRONG&gt;Patch: &lt;/STRONG&gt;Identify software updates that address known vulnerabilities, with prioritization based on exploitability and internet exposure.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;STRONG&gt;Mitigate: &lt;/STRONG&gt;Address risks that cannot be immediately patched, including zero-day vulnerabilities, through compensating controls and mitigation guidance.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;STRONG&gt;Fix:&lt;/STRONG&gt; Reduce attack surface risk by addressing security misconfigurations and code weaknesses, particularly those affecting internet-exposed cloud assets.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;This approach helps teams focus on meaningful risk reduction instead of chasing long lists of findings.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Understand Your External Attack Surface&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Internet-exposed assets remain one of the most common paths attackers use to gain access to environments. The new dashboard provides a consolidated view of internet-facing resources across:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Cloud assets&lt;/LI&gt;
&lt;LI&gt;Devices&lt;/LI&gt;
&lt;LI&gt;Shadow resources&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Security teams can quickly understand where exposure exists across the environment and prioritize remediation efforts based on risk.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Measure Progress Across Critical Security Domains&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Exposure management isn't only about fixing today's risks. It's also about driving continuous improvement. The redesigned dashboard introduces visibility into security initiatives across five key domains:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Code&lt;/LI&gt;
&lt;LI&gt;Endpoint&lt;/LI&gt;
&lt;LI&gt;Cloud&lt;/LI&gt;
&lt;LI&gt;Identity&lt;/LI&gt;
&lt;LI&gt;SaaS apps&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Domain initiative scores help organizations measure progress toward target security outcomes, identify gaps, and track improvements over time. &amp;nbsp;Teams gain a clearer path toward reducing organizational exposure by combining tactical remediation with strategic posture improvement,&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Get Started Today&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The redesigned Exposure Management dashboard is now available in &lt;STRONG&gt;public preview&lt;/STRONG&gt; through the Microsoft Defender portal. Navigate to: &lt;STRONG&gt;Exposure Management → Overview&lt;/STRONG&gt; to explore the new experience and begin prioritizing risk across your environment.&lt;/P&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://aka.ms/exposuredashboardocs" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Learn more about using the new dashboard here&amp;nbsp;&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2026 13:30:43 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-exposure/prioritize-exposure-resolution-with-a-new-dashboard-experience/ba-p/4540163</guid>
      <dc:creator>liorarviv</dc:creator>
      <dc:date>2026-07-27T13:30:43Z</dc:date>
    </item>
    <item>
      <title>How Nationwide stays ahead of attackers with Project Perception</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/how-nationwide-stays-ahead-of-attackers-with-project-perception/ba-p/4540534</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Nationwide, the world’s&amp;nbsp;largest&amp;nbsp;building&amp;nbsp;society,&amp;nbsp;is among the first&amp;nbsp;organizations&amp;nbsp;to&amp;nbsp;put Microsoft’s new agentic security system to work. Facing adversaries who now&amp;nbsp;regularly&amp;nbsp;weaponize AI, the society is using Project Perception’s coordinated multi-agent defense&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;—&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;red, blue, and green agents working alongside its analysts&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;—&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;to find and remediate threats faster, while its security experts stay firmly in command.&amp;nbsp;Their&amp;nbsp;team has already seen work that once took weeks compressed into hours.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;div data-video-id="https://youtu.be/ACx7NxQW9uo/1784922766209" data-video-remote-vid="https://youtu.be/ACx7NxQW9uo/1784922766209" class="lia-video-container lia-media-is-center lia-media-size-large"&gt;&lt;iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FACx7NxQW9uo%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DACx7NxQW9uo&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FACx7NxQW9uo%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" allowfullscreen="" style="max-width: 100%"&gt;&lt;/iframe&gt;&lt;/div&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Defending against AI-driven threats&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Nationwide Building Society is a member-owned mutual&amp;nbsp;serving&amp;nbsp;19&amp;nbsp;million&amp;nbsp;members&amp;nbsp;across the UK, and that responsibility is becoming increasingly complex as AI reshapes the threat landscape. Attackers can now scale campaigns faster&amp;nbsp;and&amp;nbsp;automate more of their operations. "AI is giving attackers a real advantage over defenders in&amp;nbsp;terms of pace and scale," says David Boda, Chief Security and Resilience Officer.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For its security teams, the mission is clear: protect the&amp;nbsp;customers&amp;nbsp;who trust the organization with some of the most important aspects of their lives. "The things that matter most are protecting their money, protecting their livelihoods." says Tim Russell, Cybersecurity Director.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For Nationwide Building Society, keeping pace means human-led, agent-driven defense that helps its team act faster,&amp;nbsp;together and stay ahead.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Coordinated multi-agent defense, built on Microsoft Security&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Nationwide&amp;nbsp;Building Society’s response is to&amp;nbsp;get ahead of&amp;nbsp;the change in the threat landscape&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;—&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;identifying&amp;nbsp;potential risks faster and accelerating response across its environment. Building on Microsoft Defender, which its teams have run for years, the society adopted Project Perception to bring coordinated multi-agent defense into its existing operations. "This solution for multi-agent defense allows us to move to a more proactive way of working," says Boda.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The system puts specialized agents to work as a team. "Red agents are offensive cyber agents used to explore the vulnerabilities and the attack paths in our environment. Blue agents are the defensive agents and&amp;nbsp;reflect&amp;nbsp;the work that a security operation center analyst might do," Boda explains, while green agents remediate and harden&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;—&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;with people in command throughout. "The power of the solution is it brings those agents together to achieve a better cybersecurity posture."&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For analysts, that coordination removes long-standing friction.&amp;nbsp;"We're able to use agentic workflows to identify threats and then track them through into remediation, which previously we would've had to have engaged with a number of different tools to achieve," says Russell.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Human-led,&amp;nbsp;agent-driven defense&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The&amp;nbsp;impact is already tangible. "My team came to me and said, look, we've just taken four weeks of threat intelligence analysis and collapsed that down into four hours&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;—&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;and for me, that was the moment that really brought this to life," Boda recalls. Just as important to Nationwide Building Society is what the technology does for its people. "This technology helps to amplify their skill sets, not&amp;nbsp;to replace&amp;nbsp;them," says Russell.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For&amp;nbsp;Nationwide&amp;nbsp;Building Society, the future is humans and agents working as one. "Agents can work twenty-four-seven, but as humans, we can't do that. So,&amp;nbsp;by harnessing humans and agents&amp;nbsp;operating&amp;nbsp;together, we can achieve so much more collectively," says Boda. And the ambition reaches further than the society itself: "Being able to develop this solution together with Microsoft allows us not just to protect Nationwide Building Society, but also to protect&amp;nbsp;wider&amp;nbsp;society&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;—&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;and&amp;nbsp;that feels really positive."&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2026 12:30:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/how-nationwide-stays-ahead-of-attackers-with-project-perception/ba-p/4540534</guid>
      <dc:creator>julievanloef</dc:creator>
      <dc:date>2026-07-27T12:30:00Z</dc:date>
    </item>
    <item>
      <title>Does this Unity Catalog → Purview guidance make sense?</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-purview/does-this-unity-catalog-purview-guidance-make-sense/m-p/4541072#M2887</link>
      <description>&lt;P&gt;I’ve been working through how Azure Databricks Unity Catalog metadata surfaces in Microsoft Purview after a scan, and I’ve created the attached visual to make the relationship easier to understand.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The principle I’m trying to communicate is simple:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maintain Databricks-native technical metadata in Unity Catalog → scan supported metadata into Microsoft Purview → use Purview for the wider enterprise governance, discovery and business context.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The short guidance accompanying the visual would be:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;In Azure Databricks:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Navigate to Catalog Explorer → Catalogue → Schema → Table/View. From here, maintain metadata such as table comments, column comments and Unity Catalog tags. Some comments can also be AI-generated as a starting point and reviewed before saving.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;After the Microsoft Purview scan:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Find the corresponding Data Asset in Purview and review the surfaced metadata:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Table Comment → Data Asset → Description&lt;/P&gt;&lt;P&gt;Column Comment → Data Asset → Schema → Column Description&lt;/P&gt;&lt;P&gt;Table Tag → Data Asset → Properties → Tags&lt;/P&gt;&lt;P&gt;Column Tag → Data Asset → Schema → Tags&lt;/P&gt;&lt;P&gt;Column Name / Data Type → Data Asset → Schema&lt;/P&gt;&lt;P&gt;Table/View and Column Lineage → Data Asset → Lineage, subject to the relevant prerequisites.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The distinction I’m trying to reinforce is that this is not Purview vs Unity Catalog, and it is not about manually duplicating technical metadata.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unity Catalog remains the Databricks-native governance and technical metadata layer, while Purview can consume supported metadata through scanning and place it into the wider enterprise governance context.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I’d be interested in feedback from people implementing Purview + Azure Databricks Unity Catalog:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does the visual and navigation guidance make the relationship clear?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In particular, are the field mappings and terminology intuitive enough for Data Engineers, Data Stewards and Data Owners, or is there anything you would simplify, rename or clarify?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2026 08:25:08 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-purview/does-this-unity-catalog-purview-guidance-make-sense/m-p/4541072#M2887</guid>
      <dc:creator>sashakorniakUK</dc:creator>
      <dc:date>2026-07-27T08:25:08Z</dc:date>
    </item>
    <item>
      <title>Microsoft Purview, Databricks Unity Catalog and Medallion Architecture</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-purview/microsoft-purview-databricks-unity-catalog-and-medallion/m-p/4541063#M2886</link>
      <description>&lt;P&gt;Microsoft Purview, Databricks Unity Catalog and Medallion Architecture three different responsibilities, one governed data ecosystem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created this visual because these concepts are often mixed together.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;img /&gt;&lt;P&gt;🔵 Microsoft Purview = Enterprise Data Governance &amp;amp; Discovery&lt;/P&gt;&lt;P&gt;Purview provides the enterprise-wide governance layer across Databricks and other platforms — Governance Domains, Data Products, glossary, Critical Data Elements, ownership, stewardship, metadata, data quality and discovery.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;🔴 Databricks Unity Catalog = Databricks Data &amp;amp; AI Governance + Access Control&lt;/P&gt;&lt;P&gt;Unity Catalog is not simply an access-management tool. It governs Databricks data and AI assets, including catalogs, schemas, tables, permissions, technical metadata, lineage, auditing and discovery.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;🥉🥈🥇 Medallion = Data Engineering&lt;/P&gt;&lt;P&gt;Bronze → Silver → Gold describes how data is progressively refined.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is not a governance hierarchy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That distinction is important:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Governance Domains answer:&lt;/P&gt;&lt;P&gt;👉 Who owns and governs the data?&lt;/P&gt;&lt;P&gt;Bronze / Silver / Gold answer:&lt;/P&gt;&lt;P&gt;👉 What stage of engineering and refinement is the data in?&lt;/P&gt;&lt;P&gt;And Gold does not automatically equal Data Product.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My preferred enterprise model is therefore:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Purview → Enterprise Governance &amp;amp; Discovery&lt;/P&gt;&lt;P&gt;Unity Catalog → Databricks Governance &amp;amp; Access&lt;/P&gt;&lt;P&gt;Medallion → Data Engineering &amp;amp; Refinement&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The goal isn't Purview vs Unity Catalog.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is clearly defining which platform is authoritative for which responsibility and connecting the metadata and lineage into a coherent governance model.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The distinction between governance domains (who owns the data) and Medallion layers (what stage of refinement) is one that trips up many implementation teams. In practice, when Microsoft Fabric is the analytics platform, Purview becomes the authoritative governance layer across both Fabric OneLake and Databricks, with Unity Catalog handling Databricks-internal access. Connecting lineage metadata across both is what creates a truly coherent governance model.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2026 08:14:09 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-purview/microsoft-purview-databricks-unity-catalog-and-medallion/m-p/4541063#M2886</guid>
      <dc:creator>sashakorniakUK</dc:creator>
      <dc:date>2026-07-27T08:14:09Z</dc:date>
    </item>
    <item>
      <title>Device Code Flow: The Gift That Keeps on Giving — To Attackers</title>
      <link>https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/device-code-flow-the-gift-that-keeps-on-giving-to-attackers/ba-p/4540949</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Tags:&lt;/STRONG&gt; Microsoft Entra ID, Conditional Access, Device Code Flow, OAuth, Azure Arc, Azure Migrate, Identity Security, Zero Trust&lt;/P&gt;
&lt;H2 id="introduction"&gt;Introduction&lt;/H2&gt;
&lt;P&gt;Device Code Flow was built for a good reason: helping users sign in on devices that cannot easily show a browser or accept a password. Smart TVs, consoles, kiosks, command-line tools, and headless systems all benefit from that design.&lt;/P&gt;
&lt;P&gt;But the same design that makes it convenient also creates a serious enterprise risk. Attackers can initiate the flow themselves, send the user a legitimate Microsoft sign-in URL and code, and receive valid tokens once the user completes authentication. No password theft. No fake login page. MFA may still succeed. From the identity platform’s point of view, the protocol worked exactly as designed.&lt;/P&gt;
&lt;P&gt;This post explains how Device Code Flow works, how it is abused in real attacks, why some Azure workflows still depend on it, and how administrators can reduce risk without treating it as a recommended authentication pattern for Azure services and tools.&lt;/P&gt;
&lt;P&gt;Allow Device Code Flow only for documented constrained scenarios. Everything else should move to Managed Identity, brokered interactive sign-in, or certificate-based Service Principal authentication.&lt;/P&gt;
&lt;P&gt;Let’s start with the version of Device Code Flow most people have already used, even if they did not know its name.&lt;/P&gt;
&lt;P&gt;You may have experienced this. At night, you’re in a hotel room after surviving back-to-back meetings, and you just want to relax and watch something mindless on Netflix.&lt;/P&gt;
&lt;P&gt;You grab the remote and navigate to the Netflix app on the room’s smart TV.&lt;/P&gt;
&lt;P&gt;Now you need to log in.&lt;/P&gt;
&lt;P&gt;You stare at the on-screen keyboard. It’s one of those alphabetical grids — not even QWERTY, which would be bad enough — and your password is something like &lt;CODE&gt;C0llH0rs3@tt3ry&amp;amp;!&lt;/CODE&gt; because you read the right security blogs and you take this stuff seriously. You’re going to be clicking that remote for the next 10 minutes, and almost certainly making at least two typos.&lt;/P&gt;
&lt;P&gt;But then the TV does something clever. It shows you a short alphanumeric code — let’s say &lt;CODE&gt;ABCD-1234&lt;/CODE&gt; — and tells you: &lt;EM&gt;Go to netflix.com/activate on your phone or laptop, type in this code, and you’re done.&lt;/EM&gt;&lt;/P&gt;
&lt;FIGURE&gt;&lt;IMG style="width: 3.71579in; height: 4.38947in;" src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAWEAAAGhCAYAAACwFwVjAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsIAAA7CARUoSoAAAAGHaVRYdFhNTDpjb20uYWRvYmUueG1wAAAAAAA8P3hwYWNrZXQgYmVnaW49J++7vycgaWQ9J1c1TTBNcENlaGlIenJlU3pOVGN6a2M5ZCc/Pg0KPHg6eG1wbWV0YSB4bWxuczp4PSJhZG9iZTpuczptZXRhLyI+PHJkZjpSREYgeG1sbnM6cmRmPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5LzAyLzIyLXJkZi1zeW50YXgtbnMjIj48cmRmOkRlc2NyaXB0aW9uIHJkZjphYm91dD0idXVpZDpmYWY1YmRkNS1iYTNkLTExZGEtYWQzMS1kMzNkNzUxODJmMWIiIHhtbG5zOnRpZmY9Imh0dHA6Ly9ucy5hZG9iZS5jb20vdGlmZi8xLjAvIj48dGlmZjpPcmllbnRhdGlvbj4xPC90aWZmOk9yaWVudGF0aW9uPjwvcmRmOkRlc2NyaXB0aW9uPjwvcmRmOlJERj48L3g6eG1wbWV0YT4NCjw/eHBhY2tldCBlbmQ9J3cnPz4slJgLAABoGElEQVR4Xu3dd3wUdf4/8Nds30120wg1oZdAIBQREEQpSrVQPI/uCYoiYr2T8yyHh6hnv7OigKLYFQtyNKUJ0jsBAqGEEGqy2d5nPr8/vjOf3+wmNCWZCO/n47EPyLSdmZ15zWc+85kZIT09nYH8ITAAQmLH30mSxMROhJBqJFAIX9kEQZfYiRBSjSiEr3CM6RM7EUKqEYXwFU6nkxI7EUKqEYXwFY6qIwjRFoXwFU6noxAmREsUwlc4xujnJ0RLFMKEEKIhOhclhBANUQgTQoiGKIQJIURDFMKEEKIhCmFCCNEQhTAhhGiIQpgQQjREIUwIIRqiECaEEA1RCBNCiIYohAkhREMUwoQQoiEKYUII0RCFMCGEaIhCmBBCNEQhTAghGqIQJoQQDVEIE0KIhiiENSIIAkRRTOxMCLnCUAgTQoiGKISrmVICZoxBr9cn9iaEXGEohKsZhS8hRI1CmBBCNEQhTAghGqIQJoQQDVEIE0KIhiiECSFEQxTChBCiIQphQkiNoLShT7yT9HK/u5RCmBBSIyht6BPb0V/ubesphAkhREMUwoQQoiEKYUII0RCFMCGEaIhCmBBCNEQhTIgG1M2xLvcmWOTcKIQJ0YC6Odbl3gSLnBuFMCGEaIhCmJDzONudXIRcChTChJzH2e7kIuRSoBAmhBANUQgTQoiGKIQJIURDFMKEEKIhCmFCCNEQhTAhhGiIQpgQQjREIUwIIRqiECaEEA1RCBNCiIYohAkhREMUwoQQoiEKYUII0RCFMCGEaIhCmBBCNEQhTAghGqIQJoQQDVEIE0KIhiiECSFEQxTChBCiIQphjShv8CWEXNkohAkhREMUwtVMKQErr1EnhFzZKISrGYUvIUSNQpgQQjREIUwIIRqiECaEEA1RCBNCiIYohAkhREMUwoQQoiEKYUII0RCFMCGEaIhCmFx2lLsSRVGkZ3SQGo9CmFx2lLsS9Xo93aFIajwKYUII0RCFMNGUuuqAkCsRhTDRlLrqgJArEYUwIYRoiEKYEEI0RCFMCCEaohAmhBANUQgTQoiGKIQJIURDFMKEEKIhCmFCCLkIl/p5JBTChBByES7180gohAkhREMUwoQQoiEKYULIZedS19tWJQphQshl51LX21YlCmFCiCb+SKXVqkQhTAjRxB+ptFqVKIQJIURDFMKEEKIhCmFCCNEQhTAhhGiIQpgQQjREIUwIIRqiECaEEA1RCBNCiIYohAkhREMUwjUU3dJJyJWBQriGols6CbkyUAgTQoiGKIQJIURDFMKEEKIhCmFCCNEQhTAhhGiIQpgQQjQkpKens8SOhNQ0oihCkqS4bkajMe7vK1k0Go37W6fTURPHPwgKYQ0wduGrXBAExGIxGAyGxF5XDFEUYTabYbfbIQgCGGMQRRFlZWUUxHIA16pVKy50/X4/AoEABfEfAIVwNWOMoby8PLHzedlsNlgslsTOF0Ud/oIgxPWrKZR5VM+f0+nE+PHj8dRTT/FuBQUFGDBgANLS0mrsslQXp9OJlStXolGjRoC87mbNmoVnn30W6enpiYOTGobqhKtZeXk5vF4vRFG8oE8sFkNZWRmaNWuGcDicOLkLpoS/8nE6nQiFQomDacbpdMLpdMbNnyRJPJTtdjsaN26MRo0aolGjRqhXr17iJK5IyvqpX7++vH4aITs7G2lpaYmDkhqKQlgDkiRBp9Nd0Eev10MQhN9d2isvL8eHH37IPx988AHat29fI4LY6XRizJgxmDt3Lj788EPMnTsX//jHPxCNRuNKxpIkQRB0v3tdXK4YYxAEATodraM/EgrhP5CLqUuuzNixYzFu3DiMGzcOf/nLX9CwYcMKF3Sqm7JMHTt2xLhx43DHHXdg3LhxuPHGG8EY+93LfDm41OuAArpmoRDWGGMMx48fx4wZM876eeWVV1BeXg6dTodgMIhgMIhwOIxIJAIACIVCCAQC8Pl88Hg8FUqQZ6vGYIwhGo3y6ajFYjH4/X6Ul5fD5/PB7XYjHA7HtVBQnvQWjUb5fAWDQcRiMUiShFAodN5qD2V6SuCqgzcQCFQ6b2rRaBQ+nw8+nw9er7fSg4r6iXSiKCIYDMLtdsPn8/ELWJWNdy7qaYbDYfj9fni9Xni9Xv77CPJF1cRxRFEEYwzBYBB+vx8+n4+vJ2U+lGkzxmAwGCCKIgRBQDQaRSgU4t+l/LbnO2Cpf6vy8nIEAgF4vV74/X5EIpFzjkuqFl2Yq2ZOpxNutxsOhwOQQ2jXrl3o0KFD4qBxLBYLsrKyUKdOHd6trKwM+/btQ6tWrdCsWTOYzWaEw2EUFhaisLAQycnJYIyhfv36kCQJBQUFgOq0ddKkSVi7di38fj9KS0thNBrB5LrjOnXqICcnB6mpqdDpdIhGozhx4gS2bNmCpKQkmM1mCIKAUCiE7OxsZGRk8Pk6duwYioqKcN1116FWrVooLS3F5s2bK1xYlCQJer0etWvXxl//+leMHz+ez9uGDRswYcIESJKEvXv34sEHH8Srr74Kne7/yg07d+5E+/bt0axZM+Tk5MBkMiEYDKKgoACHDx+u9IJUIBCA0WhE27ZtUatWLRiNRh5KO3fuRCgUQnJycuJoZyWKItxuN9q0aYOGDRvCarWCMQav14uDBw/iyJEjyMzMRCwWiyt9KgfNq6++GrVr14bZbIYkSXC5XCgsLMSxY8f4/CtBrgSwIAjo1KkT0tPTwRjDiRMnsHHjRhQUFKB58+Z8/bz22mt45JFHkJGRwQ8EbrcbLVu2RJMmTWC1WiEIAnw+H4qKirB//366yKkRCuFqlhjCjDHs3LkTHTp0qDQ4lBKQy+XCtGnT8MADD/AdZcGCBdi1axceeughZGZmwmg0IhaL4fjx43jiiScwb948AMCiRYvQvn171K1bN67E43a7EYlE8MEHH+Dxxx9HamoqXC4Xxo4di6effhp16tSB3W7n81FWVob8/HxMnDgRR44cQVJSEtxuN9555x2MHDmSl8amT5+OFi1aYPTo0XA4HPj111/Ro0ePuJ1cEAR4PB706dMHc+fORXJyMmw2G5+3SCQCt9uNU6dOoWvXrrj77rvx2muvxYXwv//9bzz33HNo0KAB9Ho9X/Zp06bhww8/5OtTObBcddVVeOutt9CiRQs4HA4YDAZIksRD85FHHsGqVasq/R0SRaNReL1efPDBB+jfvz8Pdchhf+bMGbzxxht45ZVX+IEM8u/foUMHvP3222jZsiXvxxhDIBDAyZMn8fLLL2PmzJlISUmBwWBALBZDJBJBrVq18PnnnyM3NxfJycnQ6/VwOp2YN28eBg4ciObNm/P1q4Rweno6YrEYPB4P3nvvPQwaNAgZGRn8gBiJRHD69Gl88skn+Pvf/46UlBRq1lbNqDpCY+pQVFoIqD9ut5sPY7PZkJaWhpSUFKSkpGDQoEF45plnUK9ePej1ejDGoNPpkJWVhQ8++AA9e/YEAGRkZKBevXq8lKlITU1FnTp1eOnP5XJh8uTJmD17Npo2bYrk5GTeQkGn0yEzMxO9evXCt99+i4yMDH7KbLVa4XA4kJqairS0NEyePBmTJk2KC/DKiHL731q1asFms8WtC5PJhMzMTGRkZCAYDAJycCtB37RpU8ybNw8NGzbkoaHX69GwYUPMmjULN910E3w+Hxhj8Pv9uOmmm7B27Vp06dIFaWlp0Ov18oU+AXa7HR07dsS3336Lfv36wel08vlIpJRIvV4vvvrqK9xxxx2oW7cuX/+MMVitVjRs2BAvvfQSnnvuObhcLkiShEAggNzcXHz77be45pprkJ6eHndQSkpKQtOmTfHuu+9ixowZcVUFdrsd3333Hbp3786DUpIkpKWlYcqUKWjSpEnirALy2YbH48GXX36Ju+66C/Xq1eMlbyZXdTRo0ABTp07Fp59+inA4fNbfi1QNCuEaoE6dOnj11Vfx2muvVfjceeedcLvdiaMAANLS0mCxWCDIV8SVEBMEAXq9Hvfddx9QyYUdJczUAQAAN9xwA15++eW4kpA6tJXpKEHi8/l4P7WmTZvygINc2krEGIPRaIwbTumuXg7IIZ/IZrPFjYeE5Ro+fDgikQgkSYLFYsELL7wAk8lUYXi11NRUzJw5EzjHgYPJ1Q3PPPMMhg0bxrspJV1lHhRTp07FkCFDeBAvXLgQjRo14sspyC1f1OOJooiHHnoI/fv3hyiK8Hg8GDNmDNq1a8enq4yrjKP+/dVcLhdmzJjB51VZZmV45W9JkvDnP/8ZEyZMOOv2RqoGhXANkJmZiYcffhgPPvhg3EfZEc/G5/Nh8uTJaNGiBfr164dDhw7F9W/WrBlsNhsGDx7Md3SFXq/HmDFjUKdOHX4TxMiRI3ldryAIOHjwIAYMGICWLVvizjvvjLvJpFOnTrjxxhv532pMPrXevHkz1q1bh7179wIJoScIAkwmE9auXYuMjAy8+eabvGmVIAhYs2YNTCYT2rdvj2AwGDcuk0u399xzD1q1aoXu3btj06ZNfBhBEHD11VcDcpXLn//8Z7Ru3ZqP7/f7MXnyZDRr1gxDhgzB0aNHeb/GjRvjkUceqTSIBPkiZ5MmTXDPPffEfd/cuXPRtm1bXHPNNdi5c2dcOPbt2xcAcNddd/EbKiAfnJ544gnk5OSgX79+2LdvHwT5gGq1WjFlyhQEAgEAwD333MMPjowxFBQUoH///mjXrh1ef/31uEBVa9asGSZPnswPEgCwZMkSdOnSBW3atMGsWbP4OhcEAaNGjYKQcCAhVYtCuAZQNnr1zqDulkjpf/LkSbzzzjsoKSnBsmXL8Mknn8SNb7VakZycDL/fD6hKT4Lc5jYajeL06dOQ5BYKSqgqO+CcOXOwdOlSFBYWYu7cufj555/5/BiNxriSmZrL5ULv3r1x4403ol+/fnjqqaeQkpISNwxTlYRdLhc/7VbPn06n4y0r1OtBEAQcOnQI7733Ho4fP47169dj/vz5vFQtCAJq1arFh3/ggQd4wDPG8Msvv+Cdd97B4cOH8cMPP+CNN97g4zHG0K9fPz6PakxuTdK+fXs4HA4+TmlpKaZMmYLDhw9j/fr1mDNnDv8+yEEIAL169Ypbxp9//hnPP/88jh07hmXLluHNN98EVL9v7969kZWVhY4dO6JZs2Z8/gDgnXfewbJly1BUVIRHHnkk7kCi1q1bN37WIAgCysrKMGjQIGzatAkFBQV44YUX4tZbp06dAFWrFVL1KIRrgEgkgj179lT47Nu3DyUlJYmDc8oOqTxXwuPxxAWHIJeqzvV8BaVuMSsrC1lZWXHBn5aWhjvvvBMTJkzAHXfcgVq1avHpC4KApk2bAglhxRjD6tWrsXnz5riqhrNd7FGfxifSJTyERpk3pqqyUJbN5/PxaTA54CEvQ6tWrfg0BEGA2+3GX/7yF4wfPx533nknXw5l3Nq1ayM1NbXSIIpEIqhbty7MZjPvduLECXi9XphMJtjtdixZsgSjR4/GmDFjMGbMGLz22msAgOzs7Lh53LBhAyDXf9vtdqxZs4ZPE/Lv2qlTJzRu3LjC+luzZg2SkpJ498qqfACgSZMmcc8d8Xg8GDt2LMaPH48JEyagb9++cevebDajT58+Z23WSC49CmGN6XQ6FBYWom3btujdu3fcp1evXnjuuecqlCITqS9MqU87UUkdZWWi0ShatmwJqIZnjOFvf/sb5syZg1mzZuHDDz9E7969eYlJEAR+QU+9Eyv9lP+bTKYK8/R7CfLBpTLq74ccfInDjhgxArNnz8bs2bMxZ84cXncO1TybTKYK602Zbu3ateO6+/1+Xqo3Go04ceIEPv30U3zyySf45JNPsHr1akA+ICgYYygtLQVUy1NYWMj7KzIzM5GUlJTYGfv27YPBYOABm7iMisR5bdKkCebOnYvZs2dj1qxZmDlzZtz6gnwh92LbTZPfrvJfjlQr5SJQKBSq8IlGo2fdwRSJYfFbqE+fE3dKhaAKaKVUinN8v9Ji4FKrbP4q66ZI7MdUF9KU/soyIWFdqCn9lWaDatFolB8MjUYj0tLS+Ee5sFhZyRqq71dak6hJqudnqCkhWVk/tcRtJ3H4s/2mpPqce+8m1Uqv1/PSjfJJPA2tCkajMa4UpoTUM888gyFDhmDo0KFxnyFDhmDYsGF444034qZTE5WUlFQIno8//hgDBw6sdLmGDh2KKVOmIBKJVAgwxalTp+ICVTkjUL5H/SCi8vJyuFwu3l0hCAIvpUajUYiiiMaNG/P+ilOnTqG8vDxuGQRBQF5eXlxpNXEZFWfOnIn7+8iRIxg8eHDc7zps2DAMGTKEd9uwYUOlpW9SNSrfyki1UZd0lKeHJX7UrRLO5WylJjVlGJ1Ox2+HFUURR44cwaFDh3hpiDGGxo0b4/vvv8d3333HP7/++iv0ej2+++477NmzB6ikpPl7MMZ4wCm3//4eZWVl2Lp1a1xp7+qrr8aKFSviluv7779Heno6Fi5ciLVr10IUxUpD2GQy4fjx43G3YmdnZ6NOnToIBoNwOp249957EYlE+K3lP/zwAwDg0KFDfP0LgoDrrrsOkEvWfr8fvXr14tOEfNPH+vXrsXfv3rjbnxlj6Nu3LwKBAG9DXVkzPsjVFrFYjC97VlYWDAZDhd81HA7j+PHj+O6771BWVnZFP7+6ulXcyki1a9q0KVauXIlVq1ZV+KxcuRILFy5EgwYNEke7aMrzDCDvyCNGjEDPnj2Rm5sLAPjuu+948DDGMHr0aPz444+4/vrr0bZtWzz00EPYvn07Pv30U/Tv3583n7oU/H5/3Klxbm4u/vSnP6Fbt24wGAznPbicjcFgwIwZMwBVabFVq1b45ZdfcPPNN6Nt27YYOXIktmzZgvfffx8PP/wwQqHQWS9mWiwWbN68Oe7A6HA48M033+Cqq65C7969cf/990Ov18NoNMJgMKC4uBgA8PPPP0Mnt8+VJAm9evXCnDlz0Lp1a4wcOTLubkjGGBYtWgSn04nDhw/HNcEDgClTpmDYsGHo2LEjlixZctbtY8WKFfyCLZMvWH7xxRd47rnn0LZtW1x77bX4z3/+g6+//hqLFi1Cs2bN+DyS6kG3LVcz5S449W3LispKlEy+5TYjIwMvvPACHnvsMT5cQUEBcnJykJKSArfbjUcffRQvvfQS75+fn48bbrgBgUAAHo8Hu3bt4oGrEAQBS5YswYABA5Cbm4vFixejQYMGYKqmVEpoqEuG5eXl6NmzJ/bs2YMPP/wQ48aN48N+9913GDZs2AU/i8DpdOKOO+7A7Nmz4w4Cyv/T09MxduxYftuyJEnIz89HXl4ev9V68uTJcdUjLpcL6enpSElJQSQSwddff42BAwfyaSvLplBK34wxDBgwAKtXr67wHAlBfo6D2+3GPffcg//+979xYa1MT90qRJIk3HTTTfjpp58Qi8Xwyy+/oEePHnwc9XIq65gxBrfbjSFDhmDjxo0IBoMYNWoU5syZw79PPf/KNqQsF+Tblh999FEAwJ/+9Cd88MEHcXclnm38jz/+GH/5y18u6NZtcmlQSVgDyo6mDoMLCavzUaappjRBA8CfJYGEHU/5f35+Pnr06IFTp07xQFU+St20Mq8LFizAwYMH46alUJblQpcpOTkZ69evR1lZGe+mfL8kSSgvL+cBpf5XGU4t8W+d/Fzm22+/Hfv374egalmhXj6dfDFu7dq1WL9+fVwTtETp6emYOXMm3n//fUD1nep1qcz/fffdh8WLF8NutyM5ORk9e/ZEfn4+n5ayLEpwK9UVTzzxBFatWgWj0YjU1FR8+umnWLduHZ9P5buU8YqLiyssO+R5/eqrr/D000+DJRx81POrrIOlS5dWOh1SdfRWq3VaYkdSdYLBIAYOHIjS0lIcP378vJ8TJ07g6NGjWLFiBRo0aIDMzEze7+DBg/j6669hNpsRCoXQvHlzNGzYkPcvLCzEggULIMm37m7ZsgUGgwG1a9dGSkoKdPLNEBs2bMD333+P1NRUnDp1Cv/73/9gMBj4zR5msxnRaBRlZWVYt24dpk+fjmnTpiE5ORnhcBidOnVCcnIyn9/t27dj6dKl/Jbq89Hr9Th27Bh27NiBrKwspKen8+cbnDx5Eh9//DHq16+P7OxslJSU4Pjx4ygoKMD8+fNhtVoRjUb5WyWOHTuGkpISFBUV4aOPPoLVaoVBfgjOa6+9Br1eH7dckNvObt++He+88w4mTJgAo9FY4RZnhRLgRqMR3377LQKBAJKTk+FwOPg4ZWVlWLNmDf7xj3/g448/5mcESh384sWLodPpkJSUBKvVCovFwpf1l19+wdSpUzFv3jykpKTENX37+uuvkZaWhtq1a8Nut0MURezfvx9PPvkkVqxYgfr16+PYsWM4fvw4fv31V6xfv55Pf8WKFdixYwd/V5/FYoHBYEAkEkFxcTH+97//4d5778WiRYv4tkGqB1VHVDNJvkPsYtnt9rhnCEMOL5vNBqP8CMpwOBxXT2swGJCUlMRLT8rTtADw7pJ855yyU0L1qEX1cJCv4isXpJRgkeTnBqsvVFksFlgslovekX0+HyKRCCwWC4xGIwRBQCAQgNVqhSRJ/M4/hfIgGybfyZb4LIvEJ4KJ8qMnIc+jcmqvXq7Ecc7lfNPT6XRITU1NGOv/bqxQ5lX9+/j9foiiCIvFEvdEOUVUfnCQ0WjkF+KU31N5jKnCarXCbDbHlfq9Xi9i8ktjlX7q9Xop3mNILh6FsAaUU84LpT6FVE7Dle7qoFNOT9X91eNWNowyXGJgVjYczjLNxOWpbHoXKnFaUJU+E5ftfMte2TwkDqemhOHFUE7pE+f5bN+vONt8VLZ+1Sob70LWj6Ky9YvfuOzk0qAQJoQQDVU8VBJCCKk2FMKEEKIhCmFCCNEQhTAhhGiIQriGq+xKNiHk8nHFhbAgCBBFEZIk8UdIKt0q66/8rUXzHSa/iFF55bnysJ3LTeI6J+RKcsU2UavsjbqJr0iHfEOEw+GAKIqaPFlKuYFB7XK6r7+y5UtNTQVT3SpNao7femamFGISxz9f4eZih/8juiJD2Ol0Yvz48Wjbti3/kUtLS/H888/D4XDA4/FgxIgRyMvLw/bt2/Hll18iIyMDUsKbgauaz+fDgAEDcP311/Nup0+fxr///e8/fBAL8muGBgwYwN/YAQDFxcWYM2cOPwsgNYP6bsvfwmazVfrUPYfDcdbfubKC0uV4V98VF8JKKffbb7/FkCFDePf9+/ejVatWMBqNePPNNzFx4kRAvsPo+eefx5NPPnnBTwW7FJT5fOmll/DII4/wu5/27t2LNm3aVOu8VBWn04nnnnsOjz/+OO+2YcMG/oZpKglrTxAERCIRpKSkYMKECYm9L4ggCFi6dCmuueaauPf5SZKEZ555Ju6tJMrwZWVlmDBhAjp37hx3J+Dnn3+OLVu2XFZBTCEsU0I4MzMTy5cvR25uLpj8ZKk9e/YgNze3Wkufyny++OKLePTRRymEiWYikQiaNm2Kbdu2xW1zlVUxnK3bAw88gPr16+Pvf/877y8IAiZMmIA5c+ZU2LecTifWrFkT99jPaDSKjIwM6BJeAPtHd8VdmDsbZaPx+XwoLCyEoHqWrvKixsT6qUtBUF0UJKQmYvLzKpTgVO8bF9pNr9djyZIlCAQCvGTLGMOf//xnCPLDpZQAV/aHvLw8Pj0A+OWXX+Dz+Sp9JsYf2eW1NL+DsgHodDrccccd+PDDD7F792689957eOyxx2C32/kwl4ogn+pd6ukScikpQRoKheDz+eDz+eD1euH3+yu8506SJD6M8lFeU7Vnzx44nc647f2GG26AzWaDXq/n03K73fjLX/4S91B9URSxfPnyKikIae2yrY4Q5McsVvaIQwAVqiOUt1SkpaVV+k439SMOlekmPloRqsdHqk+XPB5P3DvCcI4LFervcTqd562OYGd5jKMiKSkJJpMJgiDEPaJSTX0q6Pf7K32vmzKMJElnffeb0WjkO1Qi9eMb1X5PdQSr5PGdag6HA3q9nu/0UiWPEbVardDr9ZXO24U81rKyi0d2u50/1pKpWtqoqVviRCKRSrclyNMyGAxxwVXZd6p/w3P1T+ynPFNZ/Xuqp6UUFAwGA9q0acO7K4H7wgsv8AvHjDGcOXMGN998c9wbRyBfcD169CjmzZuH0aNH8zAVBAHDhg3DggUL+NtmnE4nli9fjl69evFSdSwWw6BBgyp948kf3WVZEhYEAeFwGB6PB7Vr18Ynn3wCt9uNcDiMbdu2oW/fvkAlj/6D/NqeRYsWQZLfdiBJEubOnQu32w3GGGKxGFwuF5o0aYIZM2Zg48aNOHz4MHbv3o158+bh1ltvhSAIfGP3eDwYMmQIdu7ciR07dmDHjh347LPP0LJlS6xatQrRaBSSJGHPnj0YO3Ys3G43ovLbd89FEAQevrVr18aMGTOQn58Pv9+PSCSCw4cP47///S+ys7NRXl6OQCCA9u3bw+l08uVijGH69OlwOp0QRRGBQAC9evWK6y9JEiZNmgSn04lwOAyXy4Vrr70W8+fPx6lTpyDKz9RdtWoVBg0ahFAohGAwWCE0ateujVmzZqG0tBTRaBQ7duzATTfdBPzGah5RFFFeXo7WrVvj/fffx9GjR3kg5+fn469//SuMRiMP11gshnA4jJdffhlLlizBkiVLsHjxYlx11VXIzMzk8xaJRLBv3z7cfffdCAaDiEQilf4Wym+8fPnyuG2FMYaMjAz+G5aXl2Pt2rVx/X/66Sc4nU7EYjGUl5ejUaNGeP3113H48GFEIhGEQiHs3bsXzzzzDGw2G/x+Pz+IO51OPPTQQ3jzzTfx1ltv4a233sJ9993HS5hOpxMTJkzA22+/zfu/8MILcMovjX3xxRexePFiLF68GEuWLMG1116L6667jr9M9Pnnn48Laia/l44xhm3btvHP9u3bsX79ev48ZWWdxGIxbNq0KW7Ybdu2weVywWKxYNasWbzqQSlEdOnShS9fLBZDrVq1+EtQdfJbaJxOJ37++edKn7P8h5eens4ux4/RaGR//vOfmcvlYpIkMVEUmSiKTJIk5nK52JEjR5gkSUxRUFDAADAAbNGiRbw7Y4x99NFHDABLSUlhJpOJvfTSS8zlcvHpKR/GGIvFYmzbtm1s0KBBfHr33HMPE0WRT8/pdLLi4mLGGOPTUPq///77DABL/78zFPbSSy/Fjbtnzx4GgNntdmY0Gtnf//53duLECT4N9fyIosjKysrY008/zaxWKwPAtm7dyqclSRI7ePAgA8AcDgcDwL766qu4/qIosubNmzOLxcLS09PZF198wfx+f6XfF4lE2MKFC1mjRo1YUlISX4aBAweyo0ePVhgnFAqxAwcO8HXHGGPr169nKSkpLCUlpcJvmp6ezjIyMpjdbmcA2KuvvsrKysoYS1iPyvQOHjzIbrnlFr6+LBYLW758Of8uURTZRx99xIqKihiTl1f5MMbYvHnzmN1uZ6mpqRXmIz09nZnNZjZ48OC430cURTZ69Gj+nWazmXk8Ht4/Fouxv//973zbePzxx9mZM2f4uMoyKNM8evQoGzVqVNw28dNPPzGmmt8ffvgh7jf86KOP4vofP36cCYLAALCff/6Z92OMsQULFrBIJMKHfeWVVxgAlpaWVmF5Ez8A2Pfffy8v2f8pKSlhgiBUGDY9PZ2lpaUxACw/Pz9unEWLFjFBEJjD4WBms5ndfPPNLBaL8f6SJLFp06YxQRAuaL7+aJ/LsiQsydUFzz77LD/FUY68kE8zs7OzE8Y6P7fbjTFjxuDhhx+Gw+GAIFd5KDccKKdO7du3x1tvvYX69esDqFjSS0lJQVZWFh8equqT8ePHY/To0bw0kjiuIhqNolevXpg2bRrq1KkDyNMIhUIIh8N82qmpqXjsscfQrVs3AMCXX34ZN52mTZuiY8eOiEajSE1NxQ033BDXf/ny5SgsLEQoFML06dNx++23w2q1gqleUKkwGAwYNGgQZsyYwUtvtWrVwosvvsiXV81sNqNZs2Zx3c5HkiR4vV48/PDDePjhh5GWlgZJ1X5bJ78tgjGGpk2bYs6cOWjQoAEk1R2QCkEQMGbMGDRs2DDut4C83m+77Ta0b98+7q0hCkEQYLFYsHDhQhQVFcX169KlCwDA6/Vi/PjxcafP4XAYv/zyCwDg7rvvxnPPPYf09PQKy6BsD1lZWfjwww/RrVs3/np7yPOn3qahqlqAvJ6U/lLCQ+CV30GSX0JqkN9mLSTcOVpVli5dGrcttG7dmpdww+Ew8vLy4r4/FArh5ZdfrpLrMjXBZRnCLpcLf/vb39C8efO4H3vRokV46qmnsHz58goBcqEef/xxvpMIgoB33nkHgwYNwsSJE/kpIQA0atQIo0ePBlQ7jEIQBGzduhWPPfYYnnvuOX5BQie/lPK5557jO+7ZNrpQKITHH38cZrOZD7N7927cfvvtGDduHI4ePQrI00xKSsKDDz4IAHjnnXfiXoEOANdffz2CwSC6detWYUd++umnAQDNmzfHmDFj4nboVatW4emnn8aHH37Ip8UYw4gRIzBw4EB4PB706tULOTk5gLwsjDEsXboU06ZNw/fff8+ndaGU73/44Yfjfts9e/bgmWeewdtvv82HkSQJGRkZmDdvHr+IlHggYIzxF2F+9dVXcXX3ZrMZffr0qTSEmepmEnX1lSAfhBWTJk2KG6e4uBhr166FyWTClClT4raNgwcP4rnnnsOrr74Kl8vFuxuNRrzyyitxv01l24Uy78p2VBllu1X+r8yzMrxy92JlVTC/l/Idq1evRjgc5ussOzsbeXl5fD/o1KlT3Pxv2rQJfr//vPXzf1SV/1J/YMpONmnSJL4zMsZQUlKCwYMHY8aMGejbty8OHDhQYYe8EE2bNuUbMWMMs2bNwpo1a/DRRx9h5cqVOHToEAoLC3Hw4EG0atUqcXRAHm/s2LF4+eWX8eSTT+K+++6Lm5fMzEx06tSJD3s2Ho8HK1aswIoVK7B69Wq8++67+PHHH/HVV19h6dKlccN27twZkEvzP//8c9wydO3aFQDQvn37uB29sLAQ69atA+SDj91u5/3KysowfPhwPPvssxg/fjxee+013k+n02Hy5MkAgKFDh0IvvwcOAA4cOIDRo0fjX//6F4YMGYIvv/yyQkntbJj8Kvj7778f2dnZYKpXC40fPx7PPPMMJk+ejLvuugtQhUynTp146TTRp59+ittvvx3PPvssbr/99rg3ITPG0KJFC/7/RJL8AtVVq1bFlSDbtm0LAMjJyUFubi6gOhC/8cYbAICePXvy4SC/APauu+7Ck08+iUcffRQjRoxALBbjy9e2bdu4C2O/l3JADIfDeO+993DTTTehf//++Prrr2Gz2c56F9vvwRiDw+HA1q1b+UFGOQD86U9/4iV9ZdtXxlm5cqVqKpefyy6EY7EYmjRpgrp16/IfWRAEzJw5E5BfUAn59e6VlSbOx+VyQVK1mXz//fcxceJEtGrVCrfddhuaN2+Oli1bokWLFrjnnnsSRwfkDcvn88FutyM1NRWzZ8+Ou8BhNBrRpEmTuHESpaenY8iQIejTpw/69OmD2267DQcOHMCoUaMwevRo1K1bN2549QWNRYsWxZ2aK0HRvXt3fiGEqdpHA8Dw4cMBVQnsm2++iXtF/Y8//hi3Plu2bAkAuOaaawDVeFu3bkVZWRn/HQ4dOnTRJZzbb7+d/18QBBw4cAAbN25EWloaUlJS8NFHH+HEiROAfECwWq08TNUEQeCtJZT5KS8vj9tuMjIyEsb6/wRBgNFoxLp163gLDSZfmBs6dCg6deoUt06cTifeeustAMCwYcP4NCDfNr9x40akpKTAbrdjz549OHLkCO/vcDjiQvtSmTt3Lu655x4sXboUq1atwoEDB2CxWCo96PxeyrIUFRVh7dq1vLskSRgxYgQEQUCXLl149RCTLwyvWbPm8rwgJ7vsQlgURaSlpfHTGSUst27dWuE15uod5EK9/fbbfANljKFz58545513sGfPHhQUFGDq1Klo3rw5kBB8lRFU9XXqQBMEIa7UWZlYLAaj0Yirr74a//vf/3DixAksXboU8+bNw7x583DzzTfH7UjKstpsNmzatCnuOQBKQF177bV84xcEAatWrQLkqpWUlBQ+PGMM99xzD0RRRCwWQywWw4oVK/jBCar6yXr16vFxBDkw8RvXvSInJ4dPDwC2bNkCJEzz2LFj/G+DwcDnI1Fi2CSWys92Wq8wGAwoLi7G0qVL4w5g9957L7p16wZBLnFCrl9XtG/fvsL8BoNB6PV66HQ6eDyeCq0ULrb+/EIo211ycjKSkpLizoQuNSZX4ZjNZsycOZOva0EQUK9ePXTq1AkjR47k64XJZz4//fQTdJfxi0jPvYX9QalPpZSdwOPx/O5TLLvdjueffx4vvfRSXCN1QS41tWjRAs8//zxWr16Nf/7zn/B6vXHjV0aZp8oCM/H/auFwGNdffz0WLFiAAQMG8FN+9U5f2bgmkwnbt2/ndwVCDswlS5bEBW0oFMKSJUviXq+upnyXXq+HXq/ndYvKNJXwUpZPJ18wq6zN7MVKDIpTp07F/Q1V/aiismW4FARBgM1mw4svvsjXAWMM1113Hfr168e7SZIUd1qdeIBObCfMGKtwITGxEJGost+7JrLZbFi2bBkOHToEyMvKGMM111yD2267jQ8nCALeffddQD47vFxddiEsyC0EEqWlpSEUCsWVkNXBdyGUHePxxx9Hx44dMW/ePBQWFlYIlrp16+Lxxx/HtddeG9ddTUi4XVld8pUkqdJlUAuHw3jrrbdQp04dvvNt2bIFnTt3hk6nw0svvZQ4CqDaUd9777244OzXrx+/sUEQBHzyyScoLS2FxWKpMC+C/ICV/fv3Y+/evdi7dy/279+PgoICFBQUYP/+/Th8+DCSk5MRCAT4uhYEgZ/2K0RRvOjfIfFpXkorFLXEkFNX91xqFosFmzdv5lVcOp0OFosFrVq14ttbLBbDypUrkZSUBMjVHur1orTiUbYJo9EIk8kUVzJXB3Vl60wZV5IveJ2PVqGtfO/ixYv59iYIAkaNGoXatWvz4UKhEF599dXznhX+0V12IaycHqoDTjnKSpLEr/4KqhLjhapVqxZatWqF9u3bIxwOY9y4cejSpQsGDRqEBx54IO5uLJPJhJEjR8aNryZJEsLhMJxOJ/Ly8lCrVi3eTxRFHD9+HDjLzga5rlV9esoYw7Rp0/ipuXJqnEiQqzqUmxMqEw6H8e9//xvJyckwGAw4cuQISktL46Z38OBB5OTkoE2bNmjTpg1at27NPzk5Objpppvg8/lw5MgRPo4gCGjXrh3wO6++79ixIy5AlINdLBZDNBqFIAhxTRCj0ShOnjzJ/77UlPWyZMmSStc5AB7SSml2/fr1gGo7zMrKQnp6OkRRRCgUQkpKCjIzM3l/QRD4RcPE76jsDE+rgL1QBoMBa9eu5fsjYwxXXXVV3LJs3rwZTqfzoq8Z/NFcdiGs0+lQXl6OrVu38m6CIODee+9F06ZN4fV6kZOTg2uuueaiN9TRo0djx44d/HT+22+/hcvlwoYNG/Dmm2/yFgnKTnK2ekhlflq2bIl27dph9uzZcRuacteXMmxl0tPTK/RT33qblZUV11+94yqls8QWFIrdu3fjwIEDMKhul3333Xfj6kc7duzIH/cJuYqgV69eOHLkCPr06cNLq8uWLYs7++jcuTM6deoEv9+PBg0axD0r+XwE+ULYzJkz45anQYMGuP3223mV0/Tp0+NK3F6vF7t37+bTuNSU+Vq7dm2FahDIB9x///vfMBqNEOTqi6+//jquyVytWrUwePBghMNhWK1W9OvXjx9IBEFAaWkpCgoKAHl51PLy8pCZmQm3243s7Gx+oKupBEGA2WzGli1b4s5qEqsclIt3VfGb1SSXXQgLggCTyYTp06fzOjVBvmnhp59+wvr16/Hzzz+jdu3aFUoU5zN//nzEYjF+AWrgwIGYPXs2br/9dkyZMgXXXXcdn6YgCLx5V2WmTp2Kn3/+GStWrODNx5h8Nfijjz6qcANAogMHDvB6VuU73333XbzzzjtYtmwZhg4dGje8OuSV0sZPP/3EbzJRMMb4zQTKxp+SkoJp06ahsLCQl8rMZjNee+017NixA+vWrcOmTZuwcOFCNGzYEO+//z6ys7NhMpkwf/58eDwe/jtkZWVh/vz5WLNmDdasWYOePXte1O+QnJyMBQsW8BI/k0/p33nnHWzcuBG//PILfxaFsj5/+OEH7Nmzh3erCjabDT///DN/Spjyu0iShKNHj2LBggW8KsJoNGLbtm08ZBhjMJlM+O9//4tff/0VK1aswOuvvw5Bdba2bt06XrDYunVr3HLUq1cP69atw/r167Fq1Srk5eXxfjURYwxmsxmFhYXYsGFDXMgqF+CY3DonMZgvR5ddCEN+aM3SpUvx888/841VEAQ0atQIXbp0Qb169eLuPrpQe/fuxbRp03g9ptFoxJ133okvvvgC//nPf3izOJ1Oh71792LWrFmJk4hTp04dpKWl8SBhjCE/Px8PPfQQUlNTEwePs3//fnz22Wd8gxUEAS1btsS9996Lvn37Vth4bTYb7HY7L30lJydj48aNlT64ZunSpXEXsvR6PURRxL/+9a+4ekmr1Yp27dqha9euyM3NhcVigSAIyMzMRJ8+fRCJRLBjxw7eygLyTtawYUN07doVjRs3rnAQOB9Bvhj4/PPPIxQK8R04NTUVnTt35qVApfuOHTsq3LV2qSnf5fV68fnnn/MDDuTlVS7IKWcEer0eJpMJzz//PMrLy3nwpKSkoHPnzmjfvj1MJhOYfFfikSNHMGXKFNhsNiQlJeHTTz+NazkhCAKaNGmCLl26oEmTJghX8nClmoTJj7bU6/V488034woSivLycixevLjKLqjWJJdlCEO+0PXoo4/i0KFDvGSi7BxFRUW48847eUmysosYSiiq+zscDsyYMQPTp09HJBLhO4+aIAhYuXIlRo8efdadgTGGt99+G1DtmDqdDps2bcKYMWNgs9n4dJUdUUq47dZut+OBBx7A//73Pz4fOrkeOBaL4Y033oAgBzSTmwZdf/31vA7OaDRi79692L59O/8eSZJw+vRpLF68mD95TZGWloaPP/4YQ4cORX5+Pl8nyjpV5qGoqAhjx47F3LlzkZKSAkEQMGnSJH5Dg3LAYIzB5XLh6aef5kGsLOv56osdDgfmz5+PIUOG8La06t9C+f/KlSvx5z//GVarlZf+1etE2SaU7grlN1dvF+r+iZRQsdvteOGFF/hyMjlY1AchRVJSEpYtW4Zbb70Ve/fujZu+enk2btyIYcOGoaioCFarFUajEYcOHcL9998Pp9PJ16fyOXLkCF588cW45VSfBTH54rJ62X8v9fq8EIL8oB+Hw4HFixejqKiI7wfKtJR2/Ur3y9ll+ShLQX7CmCiK8Pv9+Otf/4revXvDaDTiwIEDePnll3H48OG417V4vV58+eWXsNvtSE9Ph81m4xu41+vl9Y2i/NSwli1bYty4ccjLy0NycjJCoRCOHj2KhQsXYsGCBbDZbDCbzSgvL8fdd9+NmTNn8o1eaePbrl07XH/99fzq+sqVK2G1WvnRPxQKoUOHDsjJyeE7Znl5Ob777js4HA5Eo1F4vV6MHj0at9xyCzIyMlBaWopPPvkECxYswIgRI/i0GGMoKCjA9u3b+bMfysvL8cknn2DUqFGQJAk6nQ5PPfUUnn322QqPM4zFYtDpdAgEAgiHw/jLX/6C3r17o379+hAEAWfOnMGKFSvw3nvvAXKdtSSXcERRhM/nw+TJk3HjjTfCbrejoKAAr732GrxeL2688UZ+waqsrAwrV66EJEmVXnBSKPOfnp6OkSNHomfPnqhVqxa/qDl//nwsWLAAycnJMJvNvD3zjTfeiLp16/KA3LdvHzZt2gSLxQKfz4eBAwfG3ehy/PhxLFmy5IJK0tFoFLFYDKdOnUJSUhIE+TGQOTk5KCsrizs7UbZR5alpEyZMQN++fXk12fHjx7Fo0SJ8/vnnsMnvVRNULWpcLhfatGmDu+++G61btwYAbN++HW+//TaSkpIwZswY/j1erxfPP/88TCYTXz5l21ae7ncxrwtStodwOIy+ffsiKyuLd/f7/fj4448rvCnjbHw+H/r27RtX/y0IAn744Qf4fL5zbgOXi8syhNWkSp4hqzzvN7GpU2pqKnQ6XdwFEyUMBPk0WBE6y7N5dTodLwFCvkuqshBu3rx5XL2vUsoxyo8NVFT2PcoGruzIicuhzIPL5YqbVlJSEgwGA0LyQ37y8vKwfPlyfhErEAigRYsW8Pv9FaozoNr5BNWdZokSd75zjWOz2WA0GuOaj5nNZpjN5grroTKCHHKJF6ogNxszq56rAXm9eL3euDbeyjwozfNcLldcSVyv18e1n66McjAEgE8++YTf/QX5gUkjRow46+uozrUMBoMBtoRbiJX1qdfrEankGc1K+Cd2V56NrDxsSqE+6F8oZR4MBgPcbneFi5GJ28D5BAKBCs0gk5OTeZXF5e6yD2GtVRbCoiiiadOmcLlc1X6k9/v9uPHGGzF16lS0bt2a35bL5Ofc9uvXjx+MfgulhKUl4Tc0P/ytotEo0tPT8fbbb6N58+Zo0aIFX/5QKISuXbuisLDwokqa5Mry2/Y0cklUV1CohcNh1K5dGz169IgrsUiShM8++wz4nfVwWgcwqnm9MsZgtVrRq1cvNG/enC8/YwzLly/Hzp07K9zhR4jab9/byAUT5HoulnChRKvAUuYHcli43W68++67+OCDDy76VJL8f8pvLIoiCgoK+JsxtPqdyR8DVUdUsWAwiGuuuYY/Wxhy8D3xxBMIBAKV1r1WpVAohJycHNx1110wmUw4deoUFi9ejF9++QV2ux26y+x14lVNFEWYTCbcc889aNy4MUKhEDZt2oQlS5agvLyctw0m5GwohKtBMBis0C5ZudijReCFw+G49r7KxZ8LuRhGKlJazKglJyef94E7hIBC+MpWEy6iEXKlozrhKxgFMCHaoxAmhBANUQgTQoiGKIQJIURDFMKEEKIhCmFCCNEQhTAhhGiIQpgQQjREIUwIIRqiECaEEA1RCBNCiIYohAkhREMUwoQQoiEKYUII0RCFMCGEaIhCmBBCNEQhTAghGqIQJoQQDVEIE0KIhiiECSFEQxTChBCiIQphQgjREIUwIYRoiEKYEEI0RCFMCCEaohAmhBANUQgTQoiGKIQJIURDFMKEEKIhCmFCCNGQkJ6ezhI7VjXGGCRJSuxcZQRBgE5HxxtCSM1T7SHMGIPX60VmZiYEQYAgCImDnJUS3nq9PrHXOXm9Xuh0OgpiQkiNU60hzBhDeXk57r77bphMJoRCoQsORkmSkJWVhdq1a2PLli3Q6/VgjJ03xBljsFqteOONN5Cenp7YmxBCNFVtIcwYg8FgwJkzZzB79mxMmDABAC64VCuKIsaOHYvrr78ed911F/R6PURRPO/4oiji7rvvxvvvv08hTAipcS6sGHoJCIKAWCwGyIEMAOnp6XA4HBf0UaahcDgc5x0/JSWFf59SciaEkJqk2kL4bJR64fN9ziZxuMQPIYTUZJqHMCGEXMkohAkhREMUwoQQoiEKYUII0RCFMCGEaIhCmBBCNEQhTAghGqIQJoQQDVEIE0KIhiiECSFEQxTChBCiIQphQgjREIUwIYRoiEKY1EiCIEAUxcTOhFx2KIRJjaQ8A9rpdP7uj9/vT5w8ITVGtb1ZA6rXG82aNQt33XXXRb3pwul0Yty4cbjuuutw1113IS0t7bzPCxYEAWVlZbjrrrvwwQcfwOFwnHccUnM4nU7ccccdaNasWWKvi7Jq1Sr8+uuvsFqtib0I0RyVhEmN1qxZM/Tr1w89e/a86M+1116L6667DhkZGYhGo4mTJqRGoBAmNZogCIhGo2CMXfRHkiT+lm16tRWpqag6gtRIjDGEQiHccMMNaNCgwe/63bZt24adO3fCYrEk9iJEcxTCpMZijMHv9yMSiST2uig2m40CmNRYVB1BaixBEJCcnIz09PTf9aEAJjUZhTAhhGiIQpgQQjREIUwIIRqiECaEEA1RCBNCiIYohAkhREMUwoQQoqE/VAgLgkA3WxBCLit/mBC22WzYs2cPFi5cCKPRSGFMCLks/GFC2GKxID8/HwsWLIDdbk/sTQghf0h/mBCGHMQUwISQy8kfKoQJIeRyo+lT1FJSUhIHuaQEQYDL5TrrU9QkSar258zq9frETtX+LjVBEKDTVTz+1pT50EJ1bwtnW/aa8Bsoz2KuTjVlPnQ6XbVfb9IkhGfPno0JEyYgOTk5cZBLzufz4e6778b7778f9/jLWCwGyDtfdTIYDHEbmyiKmux4er1e8/lAJetDC5Ik8e2hOiUue034DZTgq+75UB6+r54PURSrff8UBAEGg6Fag7haQxjyc4G//fZbFBcXV8uCMsaQlpaGsWPHIl1+frEkSQiHw3jwwQfRoEGDxFGqDGMMDzzwAJ8PyOvjv//9LyBvANVh+/btmD17Np8P5eD4xhtvgDFWLfMhCAI2bdqEuXPnxq0PLTidTjz00ENo1qxZtS1/IBDA1KlTK2wLb7zxRtxwVUVZzsOHD+PVV1/lBRRRFCEIAp599tlqPTNYtWoVvv/+e37NJxwOo1mzZpg4cWK1zse8efOwa9euan38abWFsCC/psbj8eDbb79FnTp1qmXlCoKAM2fO4NZbb+UbmiRJiEQi+Pe//428vLxqOeozxhAMBnHTTTdV2PF+/PFHWK3Watn5DQYDFi9ejOeee07T+TAajfj222/x6quv1ogQfu6559CjR49q2RYEQcCpU6cwYsSICr/BwoULq+WFpIwxGAwGbNy4EX/729/iQliv1+PTTz+FyWRKHK1KGI1GzJs3DzNnzuTrIxQKoW3btnjhhRcSB68yBoMBzzzzTLW/FLbaQhjyxufz+dC7d2907dq12k5DCwsLMW/ePKSlpQHyBhiLxdC5c+dqb22xePHiuGoYn8+HAQMGxA1T1U6fPh33uh8mv0roxhtvTBy0Sp08eRK7d++u1lJHZUKhEK666iq+fVSHaDSK5cuXIykpiXerzm1BEAQwxuByubB582b+Gyin/9ddd13CGFXr6NGjOHDgAMxmMyBXF6ampqJDhw6Jg1ap3bt348yZMzAajYm9qky1hbAgCIjFYjAYDPD5fAiHw4mDVBlBEOBwOOIuiinBUx0lH7XK6sF9Pl9ipyplMBgqBB+TXyVUnSqbD62EQqFqrRcWBCEugBU1YVuQJAmBQCCuW1UzGo08gBWxWAyhUCiuW1Uzm83VGsCozhCGKoiVMFROfS62WkI5bUqkTCuxf2UtEgghpCao1hAmhBASr3oqZQkhhFSKQpgQQjREIUwIIRqiECaEEA1RCBNCiIYohAkhREMUwoQQoiEKYUII0RCFMCGEaIhCmBBCNEQhTAghGqIQJoQQDVEIE0KIhiiECSFEQxTChBCiIQphQgjREIUwIYRoiEKYEEI0RCFMCCEaohAmhBANUQgTQoiGKIQJIURDFMKEEKIhIT09nSV2vNQEQUAsFgNjDLFYLLE3IYTUCIIggDEGo9EIvV6f2LtKVHkIC4KAcDgMSZJQr149ZGZmQqfTgbEq/VpCCLloSl6dOHECbrcbZrM5cZBLrkpDWBAERKNR6HQ6NGrUCGlpabw0XF1HGUIIuRCiKMJgMIAxBkEQcOTIETidThiNxsRBL6kqDWEAkCQJVqsVLVu2hCRJfAGpJEwIqUmUXBIEAQCg1+uxfft2AIBOV3WXz6puyjJRFOFwOOJClwKYEFLTKLmk/CtJEpKTk6s8r6o8hCEfRagemBBCKqqWEKbwJYSQylVLCBNCCKkchTAhhGiIQpgQQjREIUwIIRqiECaEEA1RCNdQSoPx3yJx3MS/LwV1o3bI36F8fgvG2O9uRfNbv1uhnv/EZbtUlO9QllWZ9u9ddvLHRSFcQ/n9foTDYYRCobjP+R6AJMgPS1KHifrvS4ExBp1Ox+dRFEXEYjH+78V+F2MMwWAQwWAQ4XA4sfcF+b3LqYwfi8UQjUbh9/sRjUYB4HdNV039HUajEYJ8W38wGEQoFPrNy07+2PRWq3VaYsdLSZIkOBwOJCcnQ5KkxN4kAWMM0WgUderUQVJSEpKTk5GcnAybzYbk5GQAQCQSOedtlHq9Hj6fD6FQCIwx6PX6cw5/sYLBICKRCOrUqQObzYZIJIJAIACLxQK9Xn/RpTq/349evXqhXbt2KC0tRSAQuKhnizDG4PP5EA6Hf9eyiqKIUCiE1NRUpKSkQKfToby8HCaT6ZKEMABEo1F+QNXr9RBFEbm5uejYsSPcbje8Xi8MBkPiaKSaKWcs5eXl593ffi8K4RqGMYZIJIJbbrkFLVq0QKtWrdCiRQu0bNkSbdq0QSQSwdGjR3kwqEu8yr8ejwddu3ZFt27dEA6HKzyERB0o6mmona2b2+1GdnY2hg4dipycHLRo0QK5ubmwWCwoKCiA2WyGTqc76/iJ3QVBQCgUQocOHZCZmYn9+/cjGAxWOr+J4yv/DwQC6N+/P/Ly8lBcXMwfGpX4XeeiHLBuvvlmdOrUCS1atEDr1q3RoEED7NmzB4IgnPPAoJ63yr5XWc769evjhhtuQHp6Oo4cOQIAyMvLQ6NGjVBSUgKXy1UhhAXVMw3UH3X/xP9XNg/kwinrmEL4CsTkp8y1atUKRqMRmzdvRnFxMY4fP46SkhKcOnUKXq+Xl6YikQjC4TCCwSAAwGAwwOl0onnz5mjevDkKCwtRUlICk8kEnU6HUCjES43KM54hl57dbjdCoRBEUYTP54Ner+fBIwgCAoEA0tLS0L9/f1gsFuzatQslJSWwWq1o2rQpIpEITp48CUEQEIlEEAqFeKlZkiQIggBJkqDX6xGNRhEIBOD3+xEMBtGuXTtYLBbs37+fB6KyXIFAAKIo8jDS6/UQ5FP7SCSCEydOoHv37rDb7di8eTOi0SjMZjOv4lDPg8FgqBBQoihCkiTccsstyM7Oxr59+3D48GFEIhG0atUKKSkpOHjwIA/HQCDAq06i0Sh/8lYsFuNnIMpwyrIAgM/nQ2pqKvLy8uB2u7Ft2zakpKQgPz8fhw4dwtGjR+PmW5IkhEIh+P1+QP5tRVGE1+tFIBCATqeD0WiE3+9HIBBANBqFXq+HwWDg01C2kbMtO6kchfAVTNmZ27RpA8YYVq1ahSNHjuDUqVM4duwYAoEAkpKSMGrUKLRo0QIWiwX9+vVDbm4uysrKcOzYMfTv3x8dOnRAWVkZcnNzkZ2djb179yIYDKJ58+bo168funTpgvr16+Pw4cMQRRF+vx933nknOnXqBFEUceutt6K4uBg+nw9GoxGxWAyhUAgDBgyAw+HA2rVrsXbtWpw8eRJOpxOtW7eG3W7H7t27IYoizGYz+vTpg549e6JNmzYQRRHFxcWw2WwIBAIwGo0YOHAgevToAbvdDpPJhOTkZBw4cACRSAR+vx+5ubl8XtPT01FYWBhX3SCKIux2O+69914e8Ndccw1OnjyJoqIipKamol+/fujZsydatWqFYDCIY8eOwWKxxIVRMBhEXl4ecnJyUFBQgPnz58PpdKKoqAgNGjRA7dq1cfDgQQQCAbhcLnTt2hV9+/ZFx44dkZmZyQPbaDRi3LhxaNGiBZxOJ2655RZ07twZwWAQhw4dQs+ePdG7d294PB5kZWWhZcuWWLNmDW6++WZcd911cLvdKC0txeDBg3HNNdcgGAyiT58+6NKlC5KSklBYWIhoNIqbbroJvXv3xvHjx3H8+HE0btwYt99+O7Kzs5Gfn49AIIDk5GT069cPPXr0QOvWrREIBHD8+HF+pkLOrTpDuOqmTH43vV6PunXrokmTJmjcuDGaNm3KN4ZIJILU1FRkZ2fj9OnTSElJQc+ePZGWloaSkhKUlJQgOTkZBw8exJEjRxAOh9GmTRv07t0bjDEUFRUhOzsbt912Gy8hKSW7Ll26QJIfOwrVlXur1YrU1FREIhHs3r0bmZmZSElJQXl5OZYtW4bNmzdDkp88NXToUDRu3BjFxcWIxWK49tprcdVVV8Hj8YAxhsGDB6Nhw4Y4c+YMGjRogKysLH6Q9vv9uPrqq9GzZ08Eg0EcOXIEubm5GD58OCRJ4qViZT3s2L4dkiTBaDQiPz8fHo8HTZo0wW233Ya6devi8OHDEAQBffr0QW5uLi+pqpctMzMTkUgEhw8fRq1atZCcnAxBELBp0yasXLkSkiRBkiQMHjwYXbt2hdvtxunTp5GTk4MBAwZAFEWIoohIJAKbzYZevXrh9OnTMJvN6NKlC2rVqoUTJ05g//79sFqtOHPmDPbv3w+LxcIvBqovDBoMBlxzzTVwOp1gjCEnJwfNmzdHOBxGJBLh1RNKvbIkSYhGoxBFEcnJyRg0aBAaNmyIo0ePgjGGXr16oUmTJvwMiErENQeFcA0mCAIGDhyIm266CQMHDkSfPn2g1+v5TlReXo5vvvkG8+fPx/Hjx2EymWC327Fr1y6cOXMGer0eR48exZYtW6DT6dC+fXtEo1F88803mDNnDtauXQuHw4GWLVvyK/MWiwVLly7FzJkzUV5ezt8sIEkSLBYLmHzhUBRFXio1m804evQoiouLIQgC8vLykJycjF9//RU//vgjvv76a4RCIbRv3x6MMTRr1gypqakoKirCnDlzMGfOHJSXl0Ov1/OQzc3NRTAYxLx58/D6669j06ZNyMjIQKNGjRCJRAD5ICWKIlauWsVP37ds2QKn04k2bdrAZDJh9erV+OGHH7Bs2TLEYjG0a9eOt3qAHMLKKTzkA4ByMEhKSsKJEydQVFSEQCCAOnXqICsrC8eOHcPXX3+Nzz77DMXFxahTpw6vjlHOZGbOnInPP/8chYWFsFgsaNiwIfbt24f9+/dDp9OhrKwMmzZtgtVq5fOSaNGiRfjqq6+wc+dOGAwG1KpVi8+7IFfNMLmlisLj8aBz585IT0/HqlWr8MEHH2D27NkIh8O45pprEA6HefUJqRkohGu4FStWYMWKFVi1ahXWrl0LSZLidjqr1QqHwwFJrnNljMFqtfLTKZ1OB5PJBIfDAavVClEUcfPNN+ORRx5BXl4edDodbDYbDx5RFHkp2mKx8O8RBAGiKPL/K8NDDmilBGc0GmGz2RAKhVBaWgq73Y5oNAqn0wm9Xo/MzEykpqZCr9ejqKgI9evX56VrJcDq16/P6z9HjhyJadOmoVmzZjAYDEhKSooroev1ethsNv63yWSC2WyG2WxGKBSCy+VCrVq1cOrUKYRCIdhsNhiNRj4NZVmUQDMYDNDpdPyAEJOb3kUiEVgsFhgMBrjdblgsFmRmZmLfvn3Q6XSoW7cuYnLzQaWapFatWggGg/y7DAYDTCZThflOpMyTXq9HamoqotFo3DKfC2MM6enpiEQiaNOmDR588EGMGTMGJpMJSUlJMBqNiEajVBKuQSiEazBRFHHs2DEcOHAABw8exKFDh4BzXPlm8imqKIrQ6XS8VKlLeJbzgQMHUFJSggMHDmD9+vU4ffp0XGsE5SWH6nEMBgO8Xi8kSYLJZEJaWhq/kMcYw4ABAzBw4EB4vV4+f4LcDlY5GECeRyWElFK9El7KOMr4oiji4MGDOH78OPbs2YP169fzMFcCMzGUlNNy9TIzOdx1uv9rMcEYgyhXaSjrKyQ3GXM4HAiFQohGo/B4POjRowcGDhxYoRQKubmZMk3loKReTvWwib+Z8tskdldTplvZNJT1qCybehyd/PzuwsJCHDt2DCdOnMCmTZuwe/fuKn9VD7l4FMI1nBJySmlNFMUKwaOmBBzkQLBYLLwVgsfjgclkQiAQwMKFC7Fr1y5ej6qcjldGCSqdToeCggJYLBb06tULSUlJEAQB7dq1Q4sWLQA5OF0uF2w2Gxo1aoRQKITatWsjPT0doVAIZ86cwenTpxEOh9GkSRPEYjFYrVbYbDYerGfOnEE4HIbFYkFZWRl+/PFHHDp0CIIg4ODBgzCZTMBZSoXKOnK73UhOTkZWVhacTidatWoFi8WC8vJyHp4Ko9GIwsJCQG4uVqdOHUQiETRu3BgtWrRAeno6b2kQjUaRnp7OD3ItW7aEKIooKiri83UuykHAYrEgLL8A92IoQazX65GWlga/3486derE/eYlJSUwGAxIS0vD8uXLsXTpUkiShI0bNwLy8la27og2qHVEDaOUbNq2bQuLxYIOHTqgY8eOyMvLQ+fOnWE0GlFUVIQOHTpAFEUUFBQAAFq0aMFbF3i9XjgcDjRq1AiNGzdG48aNkZ+fj1AohMaNG6NVq1bo0qULOnbsiLp168Lr9aK0tBQdOnSA0WjErl27eIlKoZebhR04cADZ2dmoX78+cnNz0bZtWzRu3Bgulwtr165FJBJBaWkpmjRpgiZNmqB9+/Zo06YNdDod1q1bx7+rcePGqF27Ntq3b4+OHTtCEAQYDAYcOHAAHo8HkiShYcOGyMnJQZcuXXg4njp1Cn6/n4cO5DvasrOzUadOHbRr1w4ejweHDx9G06ZN0bRpU3To0AE5OTlgjOHXX3+F3+/n1Q6QS/nHjx+HzWZD/fr10bp1a+Tl5aFVq1aQJAn5+fk4evQo/H4/0tLSkJ2djby8PHTo0AHp6ek4fPgwdu7cCZPJhLy8PDDG+Dps1KgR6tevj6KiIpSVlUEUReTk5CAjIwOtW7fG+vXrkZOTg8zMTBw8eBAulyuuWZzL5UK9evXQrFkznDx5EkeOHIHNZkPDhg3RuHFjdO7cGfXq1YNevkGnqKgIxcXFaNy4MRo1aoSrrroK3bp1Q/PmzeFwOHDw4EHo5OoWcnZCNbaOoBCugURRREZGBtxuN8rLy+FyueB2u+HxeHD69Gl4PB6kpqbC6/Xi2LFjYIwhIyMDPp8PJSUlEAQBJ06c4O1sT506hfLycpSWluL06dMIhUIIBAIoKSnBhg0bcOTIERiNRmRmZsLn8+HIkSPQV3LnmV6+gHX48GEEAgEEAgF4vV4UFhZi06ZNKC0thcPhQDgcxsGDBxEOhxEOh3HmzBls27YNR48ehdFohMlkwsGDByFJEvx+P/bt24czZ85AFEUcP34cAHDq1CmUlpbyeS0uLsaGDRtw6tSpuLpUpWRZVlYGAHA6nSgpKcGJEydw7NgxhOTbgY8fP44tW7bg2LFjsNlsFapbLBYLDh06xHc6r9eL48ePY+vWrdi/fz+Sk5NhNpuxb98++P1+xGIxeDwe7Nu3Dzt27ODVEikpKfB4PCgqKuLVG5FIBKdPn4bX6+W/STQaxZkzZ3Ds2DHUqlULoVAIJ0+ehN/v5yXvkpIShEIhOBwOiKIIp9MJj8fDD0ThcBilpaXYvn079Ho9XC4Xjh07BqvVikOHDvHSu8vlws6dO7Fp0ybYbLZKq3FIvOoM4Sp/23I0GkWDBg3iLlyQc2OMwe/3x+0oglw/aDAYeIN+ALDZbBDkGymU01ylFBsMBiHKrRhMJhOMcsN+5ZRdKd0qF7t8Ph8AwGw2w2QyIRaLVbrDiqLIv5/JV+eVcBXkqgulBUUsFuOBbjabeQlMaWolyU3LRPmin9FohMFggF6vh1++SUGUX0WuXNiqTES+OUQv1zVbrVbeHEuZB6PRCKP8zAY1Qa67NplM8Pv9EOUqH6V0bjab+TiMMYTkG1ogn/4rLUiUfgB4EzePxwODwQBJkmC32/kyh0IhvjzKulJ+J6WaQrnI6PP5+PwohRn1POjlunWdTodk+dZ2pb9S8NHr9dRG+CIoIXzo0CF4vV6+3VYFCuE/EHUQnIugekpXYrez/XuuYStzvn5QXSisbDhlGCQMV9m4SrezHRQUZ5tv5W/1tBIJCRfBLpZ6vhO7S3KLFuX7E/9WxjnXNBKHPZ+LGZZUJFRjCNNh8Q9ECZLzqWwYpdvZ/lU7Vz/F+fqdbxrKMInDnavbuQIY55hv5e9zBSw7R0BfCPV8J3ZXB2Jlf6uHPds01P9eiIsZlmiLQpj8YVCwkMsRhTAhhGiIQpgQQjREIUwIIRqiECaEEA1VSwj/nqvOhBByOauWEKY75QghpHLVEsJ0lw4hhFSuytNRkN83ptyNRFUThJCaSMkmQfXs7Oq4y7fKb1tWqiJyc3Oh0+n4PfKEEFKTKLfFQ37Wht/vx969eyt93silVOUhDHnhlEcrKg+NobufCCE1ld/vR0FBQdwjT6tKlYewIL+aXGG32/lj/wghpCZh8jsUXS5XtT11rspDWI3Jb4gghJCarDqrTKs1hAkhhMSr+rI2IYSQs6IQJoQQDVEIE0KIhiiECSFEQxTChBCiIQphQgjREIUwIYRoiEKYEEI0RCFMCCEaohAmhBANUQgTQoiGKIQJIURDFMKEEKIhCmFCCNEQhTAhhGiIQpgQQjREIUwIIRqiECaEEA1RCBNCiIYohAkhREMUwoQQoiEKYUII0RCFMCGEaIhCmBBCNEQhTAghGqIQJoQQDVEIE0KIhiiECSFEQxTChBCiIQphQgjREIUwIYRoiEKYEEI0RCFMCCEaohAmhBANUQgTQoiGKIQJIURDFMKEEKIhCmFCCNEQhTAhhGiIQpgQQjREIUwIIRqiECaEEA1RCBNCiIYohAkhREMUwoQQoiEKYUII0RCFMCGEaIhCmBBCNEQhTAghGqIQJoQQDVEIE0KIhiiECSFEQxTChBCiIQphQgjREIUwIYRoiEKYEEI0RCFMCCEaohAmhBANUQgTQoiGKIQJIURDFMKEEKIhCmFCCNEQhTAhhGiIQpgQQjREIUwIIRqiECaEEA1RCBNCiIYohIkmBEFALBZDMBhEOBxGJBKBKIoQRTFx0CqnnpdYLKbJPJArF4VwNQiHw/D7/ZAkKbEXPB5PYqdLTpIkMMYSO1+QUCgEv99fYXxJkuD1euO6nUviPESjUcRiMbRu3RodO3ZEkyZNoNfref9QKHRBYcgYQygUgtfrRSgUqnQdQx5OFEU4nU7+CYVCYIxBkiR4PB706NEDdru9wrISUpWE9PR02uKqUCQSQYsWLZCVlYXFixcjKSkJOt3/Hfs8Hg+GDx+OL774Aunp6Ymj/m6CICASiUAQBACAXq/n/78QoVAIubm5qFOnDn788Uekp6dDFEXodDqIooj+/fvju+++g91uTxw1jiRJiEQiMBqN0Ov1iEajAIBJkyahVatW8Hg8sFqtYIxh0qRJsFgs6NatG/bt24dgMBgXzmqSJMHlcuHqq69Go0aNUFZWhnXr1sFsNseNwxiDx+NBUlIShg8fjlatWsHv9+PHH3/Etm3bAACTJ0/Gm2++iUWLFmHQoEFIS0u7qHVFyG9FJeEqJAgCgsEgsrOzMWrUKAwZMgQulwuMMTDGEIvF0KtXL0AOCuVf5bRcFEU+rPJ/hSiKcaW+yk7lldLq448/jrS0NB5+SulPGedspcdoNIqGDRtizJgxuOWWW+B0OmEwGBCLxWAwGNC7d29eooX8feppKvPucrnw9NNPo0GDBggGg2CMoUGDBmjSpAlefPFFPPzww5gzZw6fTigUQvv27VGnTh2IoohoNFph2UVRhMvlwqRJk3DrrbfCarXi2muvxX333Qe32x23Pr1eL2677Tbs3r0bc+bMwdSpU/Gvf/0LGzZswH//+18AwO7du/Hrr79i5cqVgPzbiaKIWCzGqyii0Sj/HdTdY7EY71cZ9biJf1c2rXNViajHVX+vev1IksT7xWIx/vuebT4S+59teyBVg0K4CjHGYDAYAACBQACDBw9GXl4ewuFw3DAAeOkyGAzCaDTCbDYDchBKksTDjzGGaDQKnU4HSZJ48AmCAL1ez3cwJQBtNhtSU1NhMplgNBrjdkSj0Qij0YhoNIqoHNCVCQQCGDJkCHJychAMBiEIAph8YADA500p7ZrNZh4SAGCz2ZCSkgKLxcKXKykpCYwxFBQUIDk5GbFYjJ8hOBwOzJo1C3v37oUgCLBYLBDl4A2Hw9DpdDAYDLBYLGjatCmefPJJfPzxx5g+fTqys7PRsGFDPm+SJMFsNmPKlCnIzs7GW2+9BZvNhiFDhkAQBEyZMgX9+/fHqlWr0KNHD7zzzjtITU1FMBhEKBRCUlISrFYrIpEI7HY7jEYjQqEQrFYrrFYrfD4frFYr7HY7nz81URRhMplgt9uh0+n4mYndbofZbEYoFILFYkFSUhJEUYz7vkgkUmFaer2ef5cyXUEQEAgEwBhDJBKBy+WC2WyG3W6HyWSCy+VCJBKBwWDgw0ciETDGYLfbEQ6HEYvF+LQFQaAgrkYUwlVMCdmjR49i8+bNGDhwIN9h1P1FUYTb7cYdd9yBBx54ABMnTsTf/vY3NG3aFLFYDJMmTcK1114Lv98PyKfPY8eOhcvl4uONHDkSbrcbkMM7KysLEydOREpKCm677Tb07NkTbrcbzZo1w1//+ldMmjQJ999/P+677z7YbLYKOz3kEmFBQQF27tyJAQMGIBAIQKfTxZ2qKyWu8ePHY8qUKbjnnnvw17/+FQ0aNEBaWhomTpwIh8OBwYMHo3///mjfvj0GDx6M1NRUPPTQQ+jcuXNc3bjH48FTTz2FVq1awWAwYPLkyRg+fDjcbjfS09Mxbdo09OzZE4wxzJgxAykpKUhOTgbk0I0mlJx1Oh2MRiMkScKGDRsQDAbx/fffY+LEiXjmmWfg9/sxduxYMMbw0UcfweVyoVGjRli+fDmKi4tx7Ngx/PTTTygpKcEXX3wBvV6PPXv24MCBA1i6dCmKiopQUlKCH3/8kdf9KwcBt9uN//znPygpKcGoUaPg8/kwbNgwlJSU4P3330cwGMSCBQtQXFyMDRs2oKSkBEVFRfjyyy+Rmpoad3B0u92YOnUqSkpKsHTpUuzZswclJSXYtWsXhg4divLycqSnp2P+/Pk4dOgQSkpKUFBQgLlz5yIajaJjx44oKSnBhx9+CJ/PhwcffBAlJSUYMWIEPB4PlixZgpKSEtSvX/+cB2VyaVEIVwNBvvr+5ptvolatWhg0aBBcLlfcMD6fD2PHjkVycjKefvppPPvss1i3bh0GDx4Mv9+PY8eOIS8vD5FIBA6HA2lpacjKykJmZiZSU1ORkZGBHTt2wGq1AgDMZjMOHTqE119/HWVlZZg3bx5++OEHAMDIkSOxfv16TJ8+HdOmTYPb7cbEiRPh8/ni5kkhiiJef/11ZGdn44YbbuBVKkoQe71ejBo1CgDwz3/+E9OnT8fOnTsxaNAgPg8ulwtff/01vvjiC6xduxZfffUVysrK8Prrr2PlypVITU2N+05JkiAIArxeL9566y107NgRtWrVQvfu3REKhfDdd9/BZrMB8oHM5/NhypQpKC4uxokTJ3idsE6ng9frxapVq6DT6fDRRx/hk08+Qffu3fHBBx9g2rRpWLNmDV8WJbzffPNNdO/eHfv27cP06dPRoEEDMLkax+fzIRaLwW63Izk5GS+99BJcLheuv/56jBw5Ei6XC3q9vsKBVn1gUP8tSRL0ej28Xi+eeuoplJWV4aabbsKQIUMqvfjJGEPz5s3x5ptvYvXq1cjKysKECRMAAA888ACGDh2Kw4cPY+rUqSgtLcW4cePw5JNP4qeffoLT6cR1110HQRBw5513AgAmTpwIAOjQoQOKioqwZ88efsZCqh6FcDVRdrgFCxZg+PDhaNOmDSAHNOTT8+7du+Pw4cPo2rUrunXrhv3796NevXoAgP379yMzMxMZGRlo0aIFNm7cCJ1Oh4yMDCQnJ8NisWDHjh1852GMwWKx8O83GAwwm83o1q0bLxEqJchff/0V2dnZaNWqVYXTabVly5bhT3/6E5o1a4by8nI+7xkZGejYsSMKCwvRpUsXdOnSBUePHkXjxo35PDDGYDQakZSUhOTkZBiNRj6+zWaLK1mrWSwWnDlzBitWrMDkyZPRqVMnvPHGG7Db7ZAkCTqdDh6PB2PHjkXdunXxzTffwOFw8KoNQRDgcDjw2GOPYdy4cVi3bh1GjRqFtWvXYuPGjRg6dGjc9zHGULduXbRo0QIulwsjR47Ev/71L0yfPj1uOKUK4Oabb8ZTTz2F77//HowxNGnShE/nbMuUSKkeePrppzFjxgy88sorAIAbbrghcVA+3c8++4zPl3JgBoDhw4cD8pnSiy++iMcffxyxWAw9e/YEAGzfvh1paWkYMGAAmjRpgmAwiKuvvhoDBw6EwWDA5s2b+feQ6kEhXE0EQYDRaMTq1atRWFiI/v37x/VPTU2FTqdDnz59MHToUAwdOhR33XUXgsEgateujX379sFsNiMpKQk9evTArl27sHXrVjRt2hQpKSk4ceIEvF4vDx81JQyi0SgyMzPh8/kgyvXIAOD3+xGJRJCSkpIwZrzFixejpKSEz7uyo6akpECv12PQoEEYPnw4hg8fjj/96U8IBoO85YTyXYKqvvFCQ8rhcGD9+vWoU6cOCgoKcOzYMQiCAIPBAEmSYLPZ0K1bNzzxxBP84qGCyXXjdrsdH3/8Mbp3747OnTvj22+/xdVXX40vv/wSTZs2jQudkydPIikpCaWlpbyaRCmZqzHGeIk7FApBEASYTCZAVcefOPzZqOe5oKAAAPgBWD2eMg/qaatbvdSvXx8AsHXrVlgsFhQXF4MxhoyMDAiCgO3btwPy2RAAfP/99xAEAaNHjwYAbNu27aIOIOT3q7jHkipjsViQnJyMd999F3Xr1sUNN9zAdzClBPr555/j73//O6ZOnco/4XAYTqcThw4dQps2bZCRkQGv14tNmzYhLy8PnTp1Qn5+Pr8gdi5utxsWiwV6vZ5fOLNYLDAajQgEAufc+ex2O9599100a9YMffv25d2DwSAA4IMPPuDz/Nhjj/F5/718Ph+uuuoquN1utGzZErVr1wYAPv9paWlYuHAhrFYrD0GFKIpISUnB4sWLsWTJEtSrVw9btmzBsGHDsGbNGhgMBgwePDgu6DIzMxEOh2G32+PC8UKcK2gVlV30Ui66AkCDBg0AAGfOnAEu4GCl7l9eXg4AaN68OUKhEA9fr9cLxhh27NgBALj11lshSRL+85//QKfT4eabb4YkSdizZw+vPxcTWl2QqkEhXMUSdyCdTodAIICffvqJ18lBLn0dOnQInTp14t1q1aqFa6+9FpFIBElJSdiyZQuGDx+O06dPo7i4GG63GzabDbm5uTh27BhMJlOlbWqVko3FYsHmzZvhcDiQnZ2NSCQCn8+HNm3awOPxID8/v9LQUXZEg8GA8vJy/PLLL5gwYQLvfuLECRw9ehRXX301H6dBgwbo3r07D0ql6sDn8/HSunoHZ3J9q5okX2RLSUlBv379MHPmTOzcuRP33XcfPB4PdDodGGNwOp1Yt25dXBWHQpCrDRwOB/r164dnnnkG3bp1w4gRI9C1a1cAQElJSdzB68yZMzhy5Ajq1KmDf/zjH+jcuTNGjx4NJpeqoSphK8siyS1VlGWIyc34AKCsrAwA0KdPH7Ru3ZpXGainZTKZMHjwYLRv355vF2vXrsXZqNedet4XL14MAHjsscfQpk0b3HvvvTAYDNiyZQsgN8WLxWJwOBxYvnw51q9fj/z8fNjtdkQiEezZs4cfyKxWa9zBgVQNCuEqJMgX5BRKMyCr1Yq1a9di9+7dPDTsdjtmz57NL8w9+OCDePjhh1GvXj2EQiHodDoUFhYiHA5j27ZtvOR68uRJMMZQWlpaaVUEABQXF2PixIm8dcPXX3+NcePG4f7778ff/vY3dOzYETNnzoy7kURNXb9qs9mwbNky7N27l3dPSkrCvHnzUK9ePTzxxBN48MEHcd999yEzM5Mv/6FDhzBmzBiMHj0aPp+PHxjU1AcQpZ/JZML999+P/Px8HDlyBKtXr0bt2rUxePBgfptxo0aN8OCDD8Lj8cStb6gOeg8++CB27dqFu+++G+vWrcNnn30GnU6HN998E/Pnz69w8Hr00UdRUlKC8ePHY9OmTcjJyQFU86XT6fhBQKFLaDXCGIPVasV3332HcDiM2267DXv27EHnzp3jpgU5SO+66y5s374d3bp1w+7du/HZZ5/x6pyzEeRqLuW3ePHFF7Fz506MGjUK+fn5uPXWW7FixQq8/PLLsNls2Lp1Ky8tK22k3333XQiCgKKiIuzfvx+xWAzdu3fHo48+itTU1POeXZHfh+6Yq2JKU7H09HTs2LEDJpOJn+bp9Xp07doVK1euRFJSEn+GQseOHeFwOPhOkZ6eDia3y+3YsSO2b98OQRAQjUaRnZ2NzMxMbN68mbeMUAjyBR+j0YiOHTvyEp5yISc3NxexWAy7du1CNBqtcEU8Go2iUaNGsNvt2LFjB7/IFo1GkZSUhLy8PKxevRpJSUkIhUKIRqPo1KkT7HY7Dh06hIMHD/K77GKxGDp37gyfz4f8/HxkZGSgbdu2+PXXXyEIAlJSUtC6dWusWbMGANC1a1fs27cPRqMRrVu3Rn5+PjweD4LBINq2bQuHw4FNmzbBYrEgGAyiXbt22LVrF2w2W4WSG2MMgUAA4XAYN954I1q3bo1wOIz169djx44dsNlsaNGiBW644QYcPHgQCxcuRDQaRdOmTdG7d2+UlpaiWbNmeOWVV/DNN9/gtttuw6RJk2A0GvHxxx/D7/ejb9++yM3Nxfr163l9rHIQDgQCyMjIwLBhw+Dz+bBlyxYMGDAAhw8fxvz587F+/Xp07NgRzZs3x8CBAxEOhzF37lwkJSXF/SbBYBDdunVDp06dsH37dqxduxZZWVkYNGgQysvL8f333yMajSIYDGLo0KFo2LAhCgsLsXDhQtjldsp+vx/Dhg1D/fr18frrryMlJQVutxuPPPIICgoKsGzZMt7uuUmTJtiyZQvMZnOFAya5dCiEq0FUvjkicWMW5cb9SlMrqG7xZfKNHkajkfdjjCEcDsMo3/4L1bTVLSESiaKISCQCvV7PT9lF+aYNAHHTS3S26V/svCvfJwgCr7sOh8OwWq18ftR/h0IhPr5yIFFO78PhMJiq9YeyXhLnMZE6jCG3ylDGCcvP91C+59prr8VLL72E559/HrFYDC+99BKaNGmCO++8Ex9++CGfpnJR0u/38/VR2XxEo1He3CwpKYm393Y4HFi6dCm6dOmCAQMGYOnSpYBquomCwSCCwSCsVissFgtisRifrnJxl8lN9qLRKEwmE5KSkuK2O7fbDVEU+a3ZotxG3WQy8fbWyu+VuM2SS49CmBCZcvA4c+YMJk+ejOnTpyMtLQ2Qw2/JkiW48847Icp3G/4eylmKIAj46aefcPXVV2PAgAH8rIhcOSiECVFR6qqdTifatm2LZs2awWQyoaysDJs3b4YkSRVaYPxWTH5uRPfu3WG327Fhwwa43e5KL46SyxeFMCGVYPJzGNTVK+aEp7NdCkoViSiKsNlsFMBXIAphQgjRUMX2SIQQQqoNhTAhhGiIQpgQQjREIUwIIRqiECaEEA1RCBNCiIYohAkhREMUwoQQoiEKYUII0RCFMCGEaIhCmBBCNEQhTAghGqIQJoQQDf0/MAdvbmMQitUAAAAASUVORK5CYII=" alt="Device Code Flow image" /&gt;
&lt;FIGCAPTION aria-hidden="true"&gt;
&lt;P&gt;Device Code Flow image&lt;/P&gt;
&lt;/FIGCAPTION&gt;
&lt;/FIGURE&gt;
&lt;P&gt;So you do. You grab your phone, navigate to the URL, enter the code, authenticate normally (biometrics, password, MFA, whatever your setup requires), and within seconds — without touching that remote again — the TV lights up with your profile.&lt;/P&gt;
&lt;P&gt;This is defined in &lt;STRONG&gt;RFC 8628&lt;/STRONG&gt; — the &lt;STRONG&gt;OAuth 2.0 Device Authorization Grant&lt;/STRONG&gt;, colloquially known as &lt;STRONG&gt;Device Code Flow&lt;/STRONG&gt;.&lt;/P&gt;
&lt;H3 id="whats-actually-happening-under-the-hood"&gt;What’s Actually Happening Under the Hood&lt;/H3&gt;
&lt;P&gt;Device Code Flow exists to solve a genuinely hard problem: some devices don’t have a practical way to run a full browser-based authentication experience. Smart TVs. Streaming sticks. Gaming consoles. IoT devices. CLI tools. Printers. The kind of hardware that has a network connection and a purpose, but whose input methods were clearly designed by someone who has never had to type an email address using a D-pad.&lt;/P&gt;
&lt;P&gt;Here’s the flow:&lt;/P&gt;
&lt;OL type="1"&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;The TV (the “device”)&lt;/STRONG&gt; contacts the authorization server — in this case, the identity provider — and says, &lt;EM&gt;“Hey, I’d like to get an access token on behalf of a user, but I can’t do a full browser login. Help me out.”&lt;/EM&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;The authorization server&lt;/STRONG&gt; responds with two things: a &lt;STRONG&gt;device code&lt;/STRONG&gt; (a long, opaque string used internally) and a &lt;STRONG&gt;user code&lt;/STRONG&gt; (that short, human-readable &lt;CODE&gt;ABCD-1234&lt;/CODE&gt; you saw on screen). It also provides a &lt;STRONG&gt;verification URI&lt;/STRONG&gt; — the URL you go to on your other device.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;The TV starts polling.&lt;/STRONG&gt; It repeatedly asks the authorization server, &lt;EM&gt;“Has the user authenticated yet? What about now? Now?”&lt;/EM&gt; — at a defined interval, patiently waiting.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;You, on your trusted device&lt;/STRONG&gt;, navigate to the verification URI, enter the user code, and complete a full, normal authentication flow — browser, password, MFA, the works.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;The authorization server connects the dots.&lt;/STRONG&gt; It sees that the user code has been satisfied by an authenticated session, and the next time the TV polls, it gets back a shiny access token.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;The TV is now logged in.&lt;/STRONG&gt; You watch your show. Everyone is happy.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;The authentication burden is shifted entirely to a device that &lt;EM&gt;can&lt;/EM&gt; handle it — your phone, your laptop, something with a proper browser and a keyboard. The TV never sees your password. The TV never needs to. It just waits, politely, for the authorization server to say &lt;EM&gt;“yes, that user is who they say they are, and they consented to this.”&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Device Code Flow solves a real usability problem. It lets a constrained device complete sign-in through a second device that has a proper browser and keyboard.&lt;/P&gt;
&lt;P&gt;And it is being weaponized against your users &lt;EM&gt;right now&lt;/EM&gt;.&lt;/P&gt;
&lt;H3 id="but-what-happens-when-youre-the-tv"&gt;But What Happens When &lt;EM&gt;You’re&lt;/EM&gt; the TV?&lt;/H3&gt;
&lt;P&gt;Here’s where I need you to shift your mental model — because this is the pivot that makes Device Code Flow so dangerously exploitable.&lt;/P&gt;
&lt;P&gt;In the legitimate hotel TV scenario, &lt;EM&gt;you&lt;/EM&gt; initiated the flow. You sat down in front of the TV. You opened Netflix. You decided you wanted to authenticate. The device code appeared because &lt;EM&gt;you asked for it&lt;/EM&gt;, and the verification URI was presented &lt;EM&gt;in context&lt;/EM&gt;, on a screen in a room you were physically occupying.&lt;/P&gt;
&lt;P&gt;Now imagine this instead:&lt;/P&gt;
&lt;P&gt;You receive a Teams message, or an email, or a LinkedIn DM from someone claiming to be from IT, or a vendor, or a colleague. They say they need you to help verify something, or access a shared resource, or complete an onboarding step. They send you a URL and a code. They ask you to go to — and here’s the thing — a &lt;STRONG&gt;completely legitimate Microsoft URL&lt;/STRONG&gt;, enter the code, and sign in.&lt;/P&gt;
&lt;P&gt;The URL is real. The sign-in page is real. Your MFA prompt fires and you approve it, because you’re authenticating to a genuine Microsoft identity endpoint. Everything &lt;EM&gt;looks&lt;/EM&gt; exactly like a normal authentication flow.&lt;/P&gt;
&lt;P&gt;Except you didn’t initiate it. &lt;EM&gt;An attacker did.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;The attacker has the same role as the TV in the legitimate scenario: it starts the device authorization request and waits for the authorization server to return tokens. When the victim completes the sign-in, those tokens go to the attacker-controlled session.&lt;/P&gt;
&lt;P&gt;No malware. No credential theft. No password phishing. Your MFA fired and &lt;EM&gt;you approved it&lt;/EM&gt;. From the identity provider’s perspective, everything went exactly according to spec.&lt;/P&gt;
&lt;P&gt;You just authenticated someone else’s session. You were the TV.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Welcome to Device Code Phishing.&lt;/EM&gt;&lt;/P&gt;
&lt;H2 id="the-attackers-who-love-your-tv-how-device-code-flow-was-weaponized"&gt;The Attackers Who Love Your TV (How Device Code Flow Was Weaponized)&lt;/H2&gt;
&lt;P&gt;Remember that elegant, user-friendly device code flow we just finished praising? Turns out, the same properties that make it perfect for your Xbox also make it a gift-wrapped attack vector for threat actors. The absence of a browser on the &lt;EM&gt;authenticating&lt;/EM&gt; device. The deliberate separation of code generation from authentication. The real Microsoft sign-in page that victims visit. Every single one of these “features” is a weapon in the right — or rather, wrong — hands.&lt;/P&gt;
&lt;P&gt;Let’s walk through exactly how this works, because the mechanics are genuinely diabolical in their simplicity.&lt;/P&gt;
&lt;H3 id="the-anatomy-of-a-device-code-phish"&gt;The Anatomy of a Device Code Phish&lt;/H3&gt;
&lt;P&gt;&lt;STRONG&gt;Step one&lt;/STRONG&gt;: The attacker initiates a device code flow. Not on some sketchy custom app — on a legitimate, trusted client application like Azure CLI, Microsoft Graph PowerShell, or even the Microsoft Teams client. They call the device authorization endpoint and receive back two things: a &lt;CODE&gt;device_code&lt;/CODE&gt; (which stays server-side) and an &lt;CODE&gt;user_code&lt;/CODE&gt; — that friendly eight-character alphanumeric string like &lt;CODE&gt;FPQR7WXT&lt;/CODE&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Step two&lt;/STRONG&gt;: The attacker packages that user code into a phishing lure. An email. A Teams message. A LinkedIn DM. The lure is engineered to look like a legitimate IT notification, an MFA re-enrollment prompt, a SharePoint access request — anything that provides plausible context for why the recipient should navigate to &lt;CODE&gt;microsoft.com/devicelogin&lt;/CODE&gt; and type in a code.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Step three&lt;/STRONG&gt;: The victim visits &lt;CODE&gt;microsoft.com/devicelogin&lt;/CODE&gt;. This is the actual, legitimate Microsoft authentication endpoint. The victim enters the code, authenticates with their credentials, satisfies MFA, clicks Approve, and goes about their day feeling completely fine about what just happened.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Step four&lt;/STRONG&gt;: The attacker’s polling loop — which has been calling the token endpoint at the interval returned by the authorization server since step one — suddenly gets a 200 OK response. It receives a fully formed OAuth access token and may also receive a refresh token, depending on the client, scopes, tenant policy, and session controls. The attacker now has authenticated access to whatever Microsoft 365 services that token covers. No credentials were stolen. The user-facing authentication step may appear to originate from the victim’s normal device and location, while later token use may show different infrastructure depending on how the attacker operates.&lt;/P&gt;
&lt;P&gt;Microsoft Entra guidance treats Device Code Flow as a high-risk flow that should be blocked unless users have a documented need to sign in to shared or input-constrained devices.&lt;/P&gt;
&lt;H3 id="storm-2372-when-nation-states-discovered-the-phish"&gt;Storm-2372: When Nation-States Discovered the Phish&lt;/H3&gt;
&lt;P&gt;This isn’t theoretical. A threat actor tracked as &lt;STRONG&gt;Storm-2372&lt;/STRONG&gt; operationalized device code phishing at scale against high-value targets.&lt;/P&gt;
&lt;P&gt;The Storm-2372 campaign followed the playbook described above — crafting contextually relevant lures delivered via email and messaging platforms, directing targets to the legitimate Microsoft device code authentication page, and harvesting the resulting tokens. Once armed with valid access tokens, and in some cases refresh tokens, the actors conducted reconnaissance across Microsoft 365 environments, accessed email, Teams conversations, SharePoint documents, and pivoted laterally through organizational infrastructure. Refresh tokens are particularly valuable when issued because they can be used to obtain new access tokens, subject to token lifetime, tenant policy, Conditional Access, Continuous Access Evaluation, revocation, sign-in risk, and downstream access patterns.&lt;/P&gt;
&lt;H3 id="ai-in-the-loop-dynamic-code-generation-and-the-15-minute-problem"&gt;AI in the Loop: Dynamic Code Generation and the 15-Minute Problem&lt;/H3&gt;
&lt;P&gt;Device code flow has a natural defense built in: the user code expires after fifteen minutes. For manual phishing operations, this creates operational pressure — the attacker needs the victim to act quickly. The campaign solved this problem elegantly and unsettlingly.&lt;/P&gt;
&lt;P&gt;Using automation and AI-assisted tooling, the campaign deployed phishing pages capable of &lt;STRONG&gt;dynamic code generation&lt;/STRONG&gt;. Rather than embedding a static user code in the phishing lure, the infrastructure generated fresh device codes on demand as victims interacted with the page. A victim who hesitated, navigated away, or took longer than expected to authenticate would receive a freshly generated, fully valid code — the fifteen-minute clock reset transparently in the background. The victim experienced a seamless interaction. The attacker maintained a continuously valid polling session.&lt;/P&gt;
&lt;P&gt;The campaign also employed &lt;STRONG&gt;role-aligned phishing lures&lt;/STRONG&gt; — AI-generated pretexts tailored to the apparent role or organization of the target. An IT administrator received a message consistent with a service health alert. A finance employee received something that looked like an approval workflow notification. This contextual alignment dramatically increased conversion rates and reduced the likelihood of targets pausing to question the request.&lt;/P&gt;
&lt;P&gt;The result was compromise of organizational accounts at scale, with the automation layer removing the human operational bottleneck that had previously limited the throughput of device code phishing campaigns.&lt;/P&gt;
&lt;P&gt;Device Code Flow is not a new problem, but the risk has changed. Automation now makes these attacks easier to run at scale, and Conditional Access policies that ignore the flow leave a clean path for token theft.&lt;/P&gt;
&lt;H2 id="the-azure-reality-security-guidance-and-operational-constraints"&gt;The Azure Reality: Security Guidance and Operational Constraints&lt;/H2&gt;
&lt;P&gt;The Microsoft Entra guidance is clear: organizations should get as close as possible to a unilateral block on Device Code Flow, allowing it only in well-documented and secured use cases. In practical terms, Microsoft does not recommend Device Code Flow as the standard authentication pattern for Azure services, administration, automation, or onboarding workflows.&lt;/P&gt;
&lt;P&gt;The nuance is that some Azure tools still expose or require Device Code Flow in constrained situations: Server Core, Linux terminals, headless appliances, remote shells, and migration or onboarding workflows where a local browser is not available. That is a compatibility reality, not a security recommendation. The presence of a Device Code Flow path in a tool should be read as an exception mechanism, not as guidance to prefer it over Managed Identity, brokered interactive sign-in, or certificate-based Service Principal authentication.&lt;/P&gt;
&lt;P&gt;This is the Azure reality. Security guidance pushes administrators to block or tightly restrict Device Code Flow; some product workflows still need it in edge cases. The operational answer is not to normalize Device Code Flow across Azure, but to document the few cases that truly require it and move everything else to stronger identity primitives.&lt;/P&gt;
&lt;H3 id="azure-arc-enabled-servers-dcf-in-constrained-onboarding-scenarios"&gt;Azure Arc-Enabled Servers: DCF in Constrained Onboarding Scenarios&lt;/H3&gt;
&lt;P&gt;Let’s start with &lt;CODE&gt;azcmagent connect&lt;/CODE&gt;, the command you run to onboard a server to Azure Arc-enabled servers. This is a core hybrid infrastructure workflow — the kind of thing organizations run at scale across hundreds or thousands of servers.&lt;/P&gt;
&lt;P&gt;The official CLI reference documentation notes that Device Code Flow is the authentication method for &lt;CODE&gt;azcmagent connect&lt;/CODE&gt; on Windows Server Core editions and on Linux distributions.&lt;/P&gt;
&lt;P&gt;The reasoning is understandable: Server Core has no browser. Linux servers in an automated pipeline may have no interactive session at all. The arc agent needs &lt;EM&gt;some&lt;/EM&gt; way to authenticate a human operator (or a service) during the initial onboarding handshake, and Device Code Flow conveniently sidesteps the need for a graphical environment. But “understandable” and “consistent with your Conditional Access policy” are two very different things.&lt;/P&gt;
&lt;P&gt;When a Conditional Access policy blocks the Device Code Flow grant type — which aligns with the recommended security posture for most tenants — infrastructure teams may see onboarding failures for Linux servers or Windows Server Core nodes unless they have planned an alternate authentication path. This creates a real operational tension between strong tenant-level controls and some constrained onboarding workflows.&lt;/P&gt;
&lt;H3 id="azure-migrate-known-registration-constraints"&gt;Azure Migrate: Known Registration Constraints&lt;/H3&gt;
&lt;P&gt;Azure Migrate’s standard appliance-registration experience still depends on Device Code Flow. The appliance Configuration Manager requires an operator to copy a device code, open a browser-based Azure sign-in prompt, and authenticate with an Azure user account. As a result, a Conditional Access policy that blocks Device Code Flow for the registering user and relevant resources prevents the default registration path.&lt;/P&gt;
&lt;P&gt;Azure Migrate documentation identifies Device Code Flow restrictions as a common sign-in challenge and states that disabling DCF can block appliance registration. This is notable because our Entra guidance also recommends blocking Device Code Flow wherever possible, except for well-documented and secured use cases.&lt;/P&gt;
&lt;FIGURE&gt;&lt;IMG style="width: 5.83333in; height: 5.10216in;" src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAtYAAAJ7CAYAAADHktb2AAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsMAAA7DAcdvqGQAAP+lSURBVHhe7P33tzVXla4J9n/Qt6p+7RopiTvu7YK8Vd11q0dD9s28kAWZ3dWdmMwLyJFAQoISSORwiTdKQEAihxMgIYwsXgKEPHIgb5EXQhLyFuSQBNLu8cSneTTPu+eKHfuc2Oc75l1jPOOcWLHMXHOtiHhjxYrY/6c/+ZM/mRhjjDHGGGNWx/9JI4wxxhhjjDHzY2FtjDHGGGPMCFhYG2OMMcYYMwIW1sYYY4wxxoyAhbUxxhhjjDEjYGFtjDHGGGPMCFhYG2OMMcYYMwIW1sYYY4wxxoyAhbUxxhhjjDEjYGG9hjz/+c+fvOUtb5m8+MUvntpnjFn/PPe5z53ssccek5e+9KVT+4zZDJx11lmTp59+ehLhkUcemeyzzz6THXbYYSot7LzzzpPXv/71zf3GbDUsrNeII488cvL44493J6o//OEPkx/96EfdRVrTGWPWJ5/97GcnDz30UHcMIzzOO++8yUte8pKpdMZsZIYK67//+7+f3HjjjUtp77jjjsnee+89lc6YrcZChPU555yzdFDOCk888cTk3nvvnZxxxhmTN73pTVNlbQbe/va3T377298ua/djjz022W+//abSmsXw/ve/v7tAaLjoooum0pr1wXXXXafd1QX6kf7U9POw//77L93oauD8peLg5S9/+eQ3v/nNsnR//OMfJ4cddthUWmM2MkOF9SmnnLIsHeHyyy+f7LjjjlNlGrOV2O7COgcO0iuvvHLy6le/eqrMjcxBBx00efLJJ6fayiy2pjWL4YQTTljm/wjc8HDjo+nN9qclrAmnnXba1IV+HphtboVKWDMT9/DDD2vSyZlnnjmV1piNzFBhfe211y47FgjMWnP91rTGbCXWlbCOwMH52te+dqrcjcrb3va2yYMPPrisjWPMug2BtaDf+ta3Jr/61a+6GbdddtllKs1mh9nG2267bZn/I3ABOfbYY6fymO1Pn7CmP1/xildM5RkCN1J6POZQCWvG0C233LIsHUu6vvCFL0yl3cpw3v7ud787uf322yfXXHONfbMBGSqsTzrppMlTTz217Ji44IILPGNttjxrIqw5SFn6wAGaYRlIK3BS3kwv+R1wwAFLy0H4yyNkTTMmr3zlKyc33XTTshPknXfeuSWFdd9jfwI3HS984Qun8pntS5+wDlGreYZwzDHHTD3CzqES1vDOd76zO4bifPb9739/8rznPW8q3VbkrW99a7ekL/v1+uuvL/1o1jdDhTXX5wsvvLA7FlkWdcUVV3QvMmo6Y7YaayKsWQbBcghNB8za6kwQYTUXTvMnnYBGBOSwVYX1+eefv8wPd911Vze+Ijz66KOTD37wg1P5zPZFhbXOjv3yl7+cW9hyA8ULVxEYB1puS1ibNnvttdfUUhkL643JUGFtjKnZ7sIaeHzI8g8NrLfWtGYYFtbbeMMb3jC57777lnyAiPrxj388JQJYs6t5zfZFhfXdd9+9TASvZDmVPr1gbHBjlYOF9fxYWG8eLKyNWR3rQlgD64B15gixzZIGTWtmY2G9DR1XLMPhRTQVbazZZR2t5jfbD+0jZqizeOPi/8Mf/nCuC76+tMhXDHRJmoX1/FhYbx4srI1ZHetGWLN+UT+HthWF4FhYWG/7MQ/EWA5sE88Li/ni4aVH6w8V1ueee+5Uf87zEqO+tMj55nvf+97UF3ssrOfHwnrzYGFtzOpYN8KaWcSVCGt+zfDoo4+e/PrXv578/ve/X8qLUOJlmp/+9KeT17zmNVP5+uB72nxG64EHHuheyiBwouGizJKB+BwgL0Hl0NdOLjI5zGob4u+Tn/xk90LI7373uyU7CLSNmVf28VJk5Kk+6zcr0Fdad7bh85//fGc7fRMnW2zBN2effXbXb5pP6Ws7bWTNM2UDLxKO9at2+u1qZq6ZwWZf9W1x1mJrGYr2+bwBX0RZ1ZjP+1uoPymj6oeq/Ohvjpvjjz9+aT99yhIZLSPgGOJb8xxTeX06xxx99vWvf70rU/OtBhXW2M7NT65/nhuiH/zgB8sEAyL94IMPnjpmWsKa8Z5DCA5Np8w6n/DCF+k4j2X7sAv7KlvUNxxTu+66a7fvE5/4xNJLlnFMvexlL5sqA7v4DCXnTpbD5Lrj9wXYH/Ypau+QwA1t1R7gfPO5z32ua1vrfLMogceLeIcffnh3TuW8kMcY9XMO5pv3//Iv/zKzfv0MXfQN+ThGjjrqqO4LTVEH7aS9V1999eRf//Vft3v5Q4X1gQceOPW0h/7t+ypI+JknRYvw82677dble9WrXtWdz+6///6lY46/jGm+WvNnf/ZnU+X1wdjkuMLu6npMPRdffHH32xSz3vvgJpRrTbYt9xHH/J/+6Z9O5TMbh3UjrPlVMz1Iecmo79cJ+bJG/BJaX2BNJW/w95UFnJQQD/lgrwIHAIJWRVZfO1UM9Qnrj33sY8vWBfeFLMTGFNZDbcBXXPD6vuBStR2hRp/kE1Tsa/llXvTb1fmb1dVs9pBvWmufzxvWg7BmyQtf3dFQjQX6lf6ddUwQGC+MGy1jpah4xD7Ghr6PMeQlRv2BlxDk1TEzlrDmfHL66afP9B3lIFL0ayXzCmt+CY8Z+OqYCtENvKiLmB4qirl5OuKII6bsGFNYf/SjH+1Ez6wQ55uxfvGSSZKf//znU2OgFWjvrF/crAQf/n/f+97XvSfQFyj/kksu2a7lL0JYI3Txs6ZvBepHfP7VX/3VVFlB5QeENceMPj3RwDmkalPFF7/4xUHXQkIW91oOPkCY65JXDbT95ptvHmyfWX+sG2HNzI2Gk08+eSodIIp+8pOfTF1A+gKDlVmjlrhGQFx22WWDLxTctSLCc+hrp4qhloBkxqbv03AaFiGsmX2cxwZ8xp12S1xXbedCXdXR8su8VN+u1pdhdf11ntFusRphjSj4yle+slRWJXwXLaxZToEwqca5jgVExw033KDJegMijAub2rISVDzSbi40p5566rJ4boj23HPPqfwZREA+NhBxr3vd68pjZgxhzbFw6aWXln6uQut8Mo+w5pjKT+3yviystR1DAscqT6+yLWMJ65bdrRDnmz5xOJRKHM4K1M8Yad3MVYLvU5/61NQTsr7AjW+rfWOV3xKtixDWVdpZIfzcmr2t/MC1a+hY4nO0+EDbFaAV+HXJWTfGObSENecnnRCYFXiixVPXyp9mfbMuhPVHPvKRqZlnDubWG//f+c53pkQ121x4edzLox7uylW4YQcXBy0PmD2t7iQ5uLlb5UTEgZjL1PR97VQxVAnI6odkCPiGu33aBSxvYTYfW7IQY8aCR5nYyoVXTzBsE8/+QH/9sRL2+ACRygww9WOLCjZ8gQ+13VXb77nnnqmfh45Q+WUl6NcfsI+Tbk5TLQeZ9U1rnlRk/7Xg0XUO+BBBk2/sKuG7aGGNbRoXIQtrhCFpNfD9ZmbsGAeMB/1WOoGlPWP8wJOKxxDWusSH+me9xKgvLcYvN6rgJowhrJk51vMDYd7zyVBhPeuYaglrRAOfO+VmJc4v1bmTcOutty5bz85TxhjvnI9UgDBrqMcF/s7tOeSQQ6bOU0PPN5zrK9/MQxZ80Tf8yEn4Ar9U52Rs5hxT1a+Cj0f+ecaTtjCWSUfZevwQ+tq36PIXLaxbftZzJmEeP3Mu5waVgB5AyDLmGN86Ngn4gOtfZS/naSbi9JiMwHmQ4zfKj7ZVwponSTrJQ+C6/rOf/Wzpmo692lf0Y5/4N+uT7SqseVSK2NGTJoOLk6qmhw9/+MNTn8fiYCJe077xjW+cukvkYNCZ1fe85z1LB2QOPC5F7KrNrE3VizGh1U5QMVQJSH2hjsAsutobcPC/5S1vmYqHlby8yJpLfeTFBZZHYZq2Wk5AXsrQtNp2TnKcsGgrs8ix/IK8P/rRj0b5Eox+u5oLTOUr6s+h74ZuKNXNCaJEvzpSCd9FC+u4AGAfxxjr2RlHn/nMZ7oZyMjLPh2L9Le2ARgfub1x/K72YqDiMYQ19mq/9b3EWL20+IEPfKDbtwhhzflEb9gInE/++Z//eVlazifcFKgNhHmEtR5TzJCRL44pHkPndtBfJ554YtNnnDv59cQcGDvcWFb2rOTlxX/8x3+cWv6BXV/60pem8jHumKXOgfPNm9/85qm080D/I94ouxKPQB8xJlRkIUCr9Cr4IjAmqE9nut/73vdO+YEQT1W0jkWXvyhhPcTPjM3Kz1WZLT9wzecYzHXw2dVK3DJGqxnxQw89tDwmEdEspVL7OSdxk8hTqiysieemPvuT/7lZ1HXepEVk55sA/mfJa9V+s35ZE2HNQKp+ebG6iyQtB1frRSgVTJyIETKaLtCXnUjPHXBOUy1D4cLVErRQzZqvVlir3yiPg1XLGsJKhDUX+HwCoH20U9MFOnPYWkqhbY+03KC0luasBv12NUGXgQTc2OmJvLUEaQjM1DJjmwM3bVzcNG0lfBctrAnMlPCUSNMHtEEvxFys+mah9bjsE7pDUfGYhZoe17FmWi94UL20GOJjEcJal6oQaEvr0T58+9vfLs8nQ4U1IY4pFVYKF2qEcFVu5pvf/OaUTVz4q3wrEdb0Sz72qKtVPvBELtcRM46t9ENAJOkSlwpuiHTmmln6SpRVgo9zAPa36uFlPb0Zo33f+MY3pvIsuvxFCOt5/Kwz1/P4mXPv61//+rKeD33oQ1NjlD5l8iyn50Vf1jhroL55Z4/pE30a31fOf/2v/7U7brL/r7rqqsl/+k//aSqtWb+sibAeGhiAX/va15piixlHPbnF59M0bbD77rtPvdCRZ8OZsdNHqJX4VlguwLKBHFYrrBF0GlgT29e+FvMK68oPs77tjF35V+wIvNGt6bTthOrJwVjo2mlE15e//OWpdFCJ8FntblEtn0AscLHRtFAJ30UL676nQYHebLRumDLcAGaBOsavWap4zEJNX0YkIO71YqXpVICPLaw5jng6kQPnE9bAVmUG+ouQhHmFNcdUn3ifF2b1dfy0fDOvsK78NOtmjPONrvnnfNOqY0zoH/ybQyyx0fpV8HHM8dRA0yl6o0H4xS9+MSVUF13+IoT1UKrrarW8AtQPcaPVqr8qm/MUT7tz2UzU6TmhT7D3wRKP7EvOBZ/+9KebNsJxxx23LA/XJ57uzFu32X6sC2GNoGYWpTVLHSCO8iwVg0/XCFeoEMnir/p+No9s+9bZBvrVidUKa52FI9BGHp/xaEvL7GNeYY0I0iU2rDHTdIr2deU7bfsQobZSuPiq6ODEhIDWtAHjIYe+fuxD1+nH05fWjVElfBctrId8+eTCCy9clofjc1YeravvZmYo2o8q1HQmunqJkVmyfEzF4+/YP7aw5nyiApNj4kUvetFUeQqzzTnMI6xXM3vLOYEnKryYy7pXBCRt0NlqQss38wrrSrRzvmmlD7QPhvp2KNwcM9a5HvHkAfHGGmYVkIShwhq/vOMd75hKp1Q+qWZrF13+Wghr/Mzs9Fe/+tVBfh4irDlPzXoSo22LYyzbzEvEOQ3/c2wOaVeG2WcV8jz546XwPhtZbpWX1oX4n7d+s/1YF8KawIDjoNCyMixLGCNk8VJ9FYD1T1p3hX4hok+QqRiqRC6CVNcRRuDgRjjwNZT4jnYf8wprnXFcaajq0LZzokaAqA1joMtTCNUseqa6oRnyTetMta561vIJFaOERQvrWZ+wrGYFVxo4PrT8eVDxqEJN+5pjJL/EWK3FjpcWo4yxhXUlNjifVOUp+pWNeYQ1trzrXe8q01ZwrmU9qI7ZWaHlm3mFNe1SP60khLjV8ueBpxpMknB+zf6fFYYK61Y65R/+4R+mlmBVeRddvorPsYQ1Syzwc+uFylYYKqxb6TLatkpY89Qxp6lmtYeALXoNXknARq7PLb+a9ceaCOssOLnYse5IBy+BA65ai9oqd6UhixcVx4RZj8pbeVcrrAHRzEVTfZMDIhDh1/fDN/MKa23LSkNVh7adpTks0VEbxkCfIqw0tF52rEA860uyzJ4wzjVtphK+ixbWs24aq3Gz0rBoYV0JZ5Z9xI+h7LvvvsvWN+KLeGkxGFtYI441DH2RczXCmmOq73wQ4LN5PyGWQ8s38wprbetKw2qFNV82qV5cHxIqUQqV4KvSKfwQj55HqryLLl/F5xjCerV+rgRz5YcqXUbbpsL6v/23/zb1kiPHFl/26Cu3gmNC11evJFhYbzzWXFgHnOCrb1H3zfJpuSsNs4T1UEGgeat2BiqGKgEa4BsekfForC9w0OZfXsxUAqmvTm3LSkNVxzxtXw3Vt6tXGoYuV2mtq+576TOohO+ihTXHkKbLVONmpWHocdRCxWMl1PRpQ34/QpeKVD8ksxbCGj9U5SkqNucR1kMFJi9JqqimTm4kGcesCWUZBMsheOFNxXLLNxtRWFcv9BHiU2r0N33HZA/HRcvn2sZK8FXpFEShvvhc5V10+So+Vyush/qZiQj8XLWvEsxD02W0bSqsufnQr+EMKbfCwnrrst2ENSAg+SUiDazxrB5X68t9XCBYV4iAmAdeQogyK0E5ZG0x6NKUVjtBxdAQcYkP+CU7fNR6ZMsJq1pWUQmkvjr1hTUCF1n13Sz22GOPqb5bSdtXQrWsZzWBC6m2Ram+DtMavwr+UuG7vYV19RIra9T5ZTzt61ms9qfpVchUQk1fTiTwNIeX4PSlRdZ8a/61ENZD1g4DojeHsYV19WULPh/27ne/u6yjEsst31Rpq/4K+FEYPW5OOumkzp86jvqozjdDqJ520J/YpTdfQSXkVJTOk05hnbT6sFoDvejyVXyuRljjZ35bQcub18+VsB2aLqNtU2FdzVhjL0+/+sqt+Kd/+qepyTG+NkI/6Djug5tcXkqet36z/diuwhqqH0XhIph/oS5AROssx5CZwT4qMdb6NJsyz0tvKobmFZfxze/qDrgSS/MK6+on5WctGxjKats+FP3kG2Ol+sxjC73QE9f3TWt9yYTQ98RFqb5yM2sNNOvweWErB+zkBKxpiWNfDtVYUXSdP2VUN2+LRsVjS6jpzDQ3AjzxyX2jLy0GYwvrSmxwPqnKU/Sl0bGFtX4th2ODG6aqfPj4xz/epcmh5Zt5hfW//du/TR07Q9eijwE3Gbo0ge96t+qvvmLSErQq+GKZjqZTqm8nc43Rmcoxy7/44ounylfxGeNcy6/Gugpr/Kyz1fhZ6wz+5m/+prvZy6ElmNUPrXQZbZsKa+DJVk4TeqRlc4tKpK90WYnZWGx3YQ0cjCpqqh8bqb5cMeuX8mZRfRVkyJcTqh9T6WvnWOKy+i5mJcbmFdbVZ+cQI0NFYh9jtb2Pyv551kmD3igRWuvtq3XV/ADCJz/5yam0Lao+mvUFE31hjzC2sNZ16lxkeClQ0y0aFY8toaY/AMOFUPtGX1oMxhbW1VdBqq+VKJxP9MWysYW12j9rXXb1ebaWb+YV1oxxbW/rB0sWgYpCfM0LyK269RvahKHCesjnFmNmN4fWd6YXXb6Kz9UIa00zxM96fWsJZvVDK11G21YJa/09BwJ1/eVf/uVUebNgskdFOj+ANK9INxuLdSGsWaeqFwqCPlKvHlMPXc/aopoBJGjdGeK5SOnB19fOIeKSJSqtOgNmrqtP+OivFVaibdZLg/polPb1fS5uKEPavlp0No4w9MlDoOt1CdU3rauvt6xkHOJX/XZx39pu0uusJmFsYf2JT3xi6memWz9ys0j0nNAn1FQ05IAP9KXFYGxhXX3vmEC/tR590696wScsWlj3faaNG0c9fxBavqmENWO71WbQPovzTV+esVDBR918P7hqG/1Du7V/hgprwqxvjCM2VaTGDdnQ8vnRES13JeXrWBxTWIefK2HZuq62BLP6oZUuo22rhHUl7jm/c6Opy2Zmwe9y6KQh1+uVfBPbbBzWhbCG6qfKycd3aHM6xIsKKNLxncnWd7A5YJlJ5BEPSx50f1UmBx/fdFVRxbbehUboa+cQcclJhTVYfcsPeDyrfqoE5EpuQqplMeThR2rUDxm+sc1Pr7NURffBkLavBvpXhQb92bKnRfWLg9WPBVXrqnnxayU/eKPvDRA4qfMT4zld37gbW1gjDvWFTALrBftm5Gk/7ywgmMboX+3TPmFd3RRFqF5aDMYW1sBa6db5RH8AhX7VnzyOMLaw1u9kUyfH9gte8IJl6fg58+rmgNDyDetJ9RfzOHb6fm1PRRchzjfqpwxrwvlUIMd3q+xZVN90RvDoD3FwTTn99NPLsTWPsMbXjF9dBsC5i/XGuuSGgB8qAbro8lV8rkZYt/zMExr1M0+VWn6uBLP6oZWur22VsG4JfLY5l3Cd0Dqw/4tf/OLUT5pXL0MSWO6iP7ueedWrXtX96A835DvttNPUfrO+WTfCGvgMlA5m3mLOyxGqrzBE4ETOBYEPzvPTuBwcbMdJpWUHFzddPxchHitTJ3/jwOcCoDPHrfJhiLgMv+EDRAz20w7g8TzfF9YTT2s9OlRLGyibumkPBzcXjUjfOqEQqIf0YRM+pk3MUkX61lcghrR9NVTLI+ZdBhLo2CXkb1ojLHU2F98wFvDpLHghNNdX2U7ApywLIQ9jONajUpdeJMcW1sDstK5BJWAXM11cYBiTzOJwMcnHxlj9q+KxT1hXLzESsKl6aTFYhLDGFl0nGmHe88mYwroau3Gu4XimP/Fx+IMbvKG+ac3U0y58Ee3lZ9Ijf2umnjDkfIOIq2wZQmu8cGxdcsklXZ2cP2PmkuNPZ+SHCmvaEjda0S78QbrWt7O57rWWxSy6fO2T1QhrPn1ZXVvn9XMlmNUPrXR9bauENXCDouujI5Cf6wv1x7gOP1Q2UL6es6MczvGcPzmPcvwxKcHkTkzccM23sN54rCthjYDWzwEx+HQ5QrW+dUjos6MlJKqATSwFGPurIOq3WaHyTaZvFi+CCq2+G5dZYXsJa10TTKhm8YdQzdrHuueVjrsc8IXWyVcjqoufhuhv/QGXRQhrqH70ZkgYq39VPPYJa9CXGAmtlxaDRQhr4HyiL221Qt/5ZExhzXmCJ0tDAv2OPdX4qeyBak22BhXDnG90WdXQoGXNCzO5s86PBPqHdutxN1RYc01DPOrYbAVEJjdBWu5ala/iczXCGlgOsVo/q1it/NBK19e2lrAGlsnMe75v2cDylyE+0GBhvTFZV8IamH3VAchJXr/XzA+pIJ6GnkxIx6CvBEjA2qp77rlHsy4LlMOj23jsnUNfO4eIS/VbX8An/IR2S1QD+2aJtkpo0TZEhPZDX0BE8AKNlgVD2r5Sqm9Xr2QZyKzyWPeML1cbKmGNv5m96esn9pGGtOrPRQlr4HOP+lJoX2CmhceXq3mhOFDxOEtY60uMhNZLi8GihDVwPuG9hr4Q5xPW3+q3nccW1sB5E0HSN9ZoFzdVjB+dPWz5BhibV111VW/ZlRgmH4Jn3vPNpz/96amy5oHzIzfl2v85MJ5/9rOfdctlWj5XGyrBx80dbZx148H1h6dYWuZalq/ic7XCGj+zDGmIn//sz/6sbF8lVoem62tbn7AGZty5aRk6Nrl2tH6yHG0zdPKOgG08xbew3nisO2HNQVh925o7x0qMsU6JCx6PM/Pg5+BhLTL5WMdKOs1bwVopLnAcIFEeZXFy4fF3Xv+s62P72qliqBKX1M2aRB4HceGo2sPjYt7knmc9L7MT5MsnQcpmNo/Pkmn6gHVwLF0gnb6AwqMt4vE94qtP4A9p+0qpZphXugwkQIxpoO9/8YtfaPTcoRLWwX777dddvPPjevxO37HmOnys/lyksIYYl8wsUl6+MDGOmAHDJm40uaho/pWiQmaWsAZEagRsbb20GCxSWAO+O+qoowadT/iOcw6LENZh0+GHHz5lE/1IG3kMTrrqhcSWbwLGKAKCZRb5/MU4pr6+mVLWN/MptlnnG46T1pr5lcANEJM0+XE9xyA+/td//dcleyshN1RYRzrOlezP7aMujnE+h6fr3SsWXb6Kz9UK62A1fq4E89B0GW3bLGEdMDZZNsmNSW4zNwSIZa7ZPCGe5d///X//37snJbzYix+yLZTLdZ+ySMPLqH1tMeuXhQjrrYKuYeYEtD2+92uM2fjoF184n7zrXe/yxXWDUQm+SoCvlEWXb4xZHRbWK2Qln7MzxpgKzie6nnPWd6bN+mTRwnfR5RtjVoeF9QphDa9+cm2lL8wZY7Y21U98D/3FRrO+WLTwXXT5xpjVYWG9AqoviPT9sIcxxrSoviDC+eTII4+0WNqALFr4Lrp8Y8zqsLB+Br4l+fOf/7x7waL1Ih4vDPIWefUJMr7V2fcjKsaYrQNfcBlyPuFrCa3zSd+PpJj1y6KF76LLN8asDgvrZ8hfWogvZuQf9sgfbddQfQ7QGLN1yV/tWMn5hC8uWChtTBYtfBddvjFmdVhYP4N+wmxo4HNBfGZHyzPGbF30c3hDA+cTfhrZImnjsmjhu+jyjTGrw8L6Geb9tUG+P8lP+PI5LC3LGLO1mffXBON88u53v9sCaYOzaOG76PKNMavDwvoZWAfJx/X5AQI+e8WPseSPt8ePFLCPH03hx1O0DGOMAZ9Pti6LFr6LLt8YszosrI0xxhhjjBkBC2tjjDHGGGNGwMLaGGOMMcaYEbCwNsYYY4wxZgQsrI0xxhhjjBkBC2tjjDHGGGNGwMLaGGOMMcaYEbCwNsYYY4wxZgQsrI0xxhhjjBkBC2tjjDHGGGNGwMLaGGOMMcaYEbCwNsYYY4wxZgQsrI0xxhhjjBmBLSusn/vc50722GOPyUtf+tKpfcaY7QPH5ec///nJr371q8kTTzwxicD/F1544WSHHXZYSsuxyzFMHi3HrA922WWXyR133LHUj4Trr79+WT9uNnbeeefJ61//+k3dxs3K7rvvPvnZz342eeCBByZPP/10N175y/a//uu/TnbcccepPMYoW1JYH3DAAZOHHnpo6aA577zzJi9+8Yun0hlj1o43vvGNk5tuumnpgqYhBBnH6sUXX7yU7re//e3kE5/4xFR5ZvuzlYT13//9309uvPHGpXFJu/fee+9N2dbNBjfnRx555OT3v//9srEa4cknn5wccsghFtZmEFtOWL/85S+f3HbbbcsOmj/+8Y+Tww47bCqtMWZteO1rXzslwDSEIPvmN785eeqpp5btu/nmmycve9nLpso125dFCuvrrrtuWbkRHnnkkckHPvCBVdXxyU9+simyzj333LLsU089deqm8LLLLrMY2wAcd9xxkz/84Q/L+i4HC2szD1tOWDODwIlXw5lnnjmV1hizNvDUSAMi5b777ptcc801k1tuuWVy9dVXd4Lm7LPP1qTdE6g999xzqlyzfdkewppw+umnr6qOajxGaAnra6+9VpN2bX/Vq15Vpjfrg/e9731LT7BzePzxx7snaPTrPffcMznwwAMtrM0gtpywZsb61ltvXXYAcaf6hS98YSqtMWbxvOUtb5k8+OCDy45JLmpf/OIXp9LCEUcc0T1lyoE12S960Yum0prty/YS1jyVfMUrXjGVZwj//M//PDUec2gJ65NPPnnqScoFF1xgMbbO+elPfzr1pAEx/bd/+7dlP2ee//znTz7+8Y93S9NYh33wwQe7v83WE9bwzne+c3LXXXd1B9Njjz02+f73v+8XoIzZThx00EHdo9Yczj///OZFjWMVEUMejmFmlfbaa6+pdGb7s72ENZMl3JitpJ5jjjlmSiDn0BLWrP2/6KKLups+uPzyy7sXGau0Zv3AE7EsrHmi/cEPfnBmv5100knLzlteLmKCLSmsjTHrB4SMBuJmXdjM+mcthbWK4V/+8peT5z3veVP5+njhC1/YvYAYAYGu5baEtdl4cONz++23L+vfO++8c7LbbrvN7OOzzjprmSC3sDaBhbUxZrtiYb15WUthfffddy8TwSt5iVFfWmSN/6OPPrq0TbCw3jxYWJtFYGFtjNmuWFhvXtZSWDND/fDDDy9tI3qOP/74uerSlxZZzpG/p06wsN48WFibRWBhbYzZrlhYb17WUlgjeBHXOczzEqO+tMiMN+/fWFhvXiyszSIYXVifc845ywYpg42XkzRdpnp5iXI0XebVr3715IQTTuhO2vnRXbyQSPyJJ57YpdO8aiMnUD7Dp+mqT/Nlu97znvd03yklTRxgnIT5QgGPFLW8Pni7+Etf+lKXN7cnyvvMZz7TvbTFhYoDPwcuVFreSsEO+oOXcO6///5lFxXaSFv57BntG/OFT9qQA22krezDpqOPPrq7SMa3RrMt++2331R5Sl+fv+td7+pegIsvTfBppTe96U1TZUD8MiD25n4nL2+F8ym4aizNIvpfyyXQB/fee2/3SUjGnOZVSENa8lT9Rx3f+MY3Bv0oUnVsInrZhy8YBwicPGY5/hA4+FXLC1QUzQqMh1133bXLi3/zzCSB/p11IZznGBsiBis7qnSKtp0+2WeffabS8XkvFXXHHntsVz5fN+LCztdTCPTRV7/61WbdvNzJC6GM0Rjn+Riin+dZj4yfPve5z5W+5KtLfGWJ8ob6ciWoHxkD1JvH6zwvMf7gBz9YtpSEMYxQ0j5oCeu+/tK0Cp/kY3a9dT379a9/Pfne97439TIk/apjEPsQd4z3H/7wh0v76fef/OQnTeGHDd/97ne7cyF15nMQNmEbL+y9+c1vHtSmXC5tQ8BWbaNcvsyhbavgnPX1r3+96/vWeZLj4l/+5V+aZfEDcdpPswL9yPlHRfisMFSkm83FhhPWHFiIl76PuUdo1a02ziusOWGdccYZU5/8yoEDfugvOvIdTcRcX6A8RDyCbxHCGjs56XKiGxKwh5NbdeOyElrCeqhvLrnkkl5ft/qci26IE92nZXzsYx/r1lzOCoxNxmifPQEC5Tvf+c7UOGuFvr6OG4R8sekLfLv1a1/7Wu8NUnVsIqwRdozHvrrww49+9KOyfBVFs8JqhfXQcUSbEA5DxGBlR5VO0bbPK6z5hcrqAl+JOI7PK664orefCOznR3aG/FIg3wuv6s9hXl+uBPUjY4AxovUNeYmR8fyb3/xmKU8Icsa/9sGYwhrRyafahlzPCFpeS1gzS88Nk4YQ3dkGflgJMaq2twK24mvq6Gsb5z/K1fNHFUjDp+pa5XHN5cZH17u3AuOPfueHp7RMC2uzaDaUsOZA5dM4Q0OrbrWxJaQqYc2JCdE060JFIA2z6lpuhoNc62gFymMmmU8F5tAntoZStXVIoD+GCMhZVMJ6//33n/zud79bFt8X+myp+pzZrar8ajwwS6ICvC/QV1zYWvYA+2aJUw2tvkYgt34pri9QN7PblfiF6tjkRmDocchF+Ctf+cpUuSqKZoXVCOuxjjEtv7KjSqdo2+cR1n2+V9GFANab8FmBpRDchLTawEwgPyE/JMzjy5WgfqRcRKP+AiL24ou+OtXXzHy+7nWvW6iwfsc73tHVM0/Q8iph/fOf/7y7RunXTAgqrIfcJLUCTxDxUdU+zm1XXXWVZmmGPmHNzYd+Em9oYDy///3vX1auhbVZNBtKWJ9yyilTBxezxszSIWB5jAV8lJ+ZRYRQVbfaWAkpqMQmsyExuxC/zMRBT31qG4GT+tvf/vapsoG7ab3oRGiVzV89YbbE1jzktlIHdiP6mCXApzyq4yShbcT/iE4tb15UWLMMJc8OYxtp+HA/J0u1g4BfWBOpZUPV59UvpRF0PPDIW0U19XNhiXHHxUzHSp89fTeJlM3FkvaSJo+5qq8r+6IcfEU7dRzlQB8i2LRcqI5NHvVHOblfGDNV+dU6V5ZpYVO0TwNxsR8QCi996Uu7vJWgbQlrjrGWuJz3GNPyKzuqdIoKwnmE9aWXXtqc3cyii3ZXIoCnFDxt6zumse8lL3nJlD2tMgk86VqNL1eC+jGENTcG877EqC8txi83Vn0whrDuu0HheERw40s932l5lbAmn56LImRh/fd///eD+pNfPW2NOfb/1V/91VT7WDKi/R7Xap5iVdfqSliHQNcxSsDX2IYNlFudAwmcS17/+tcvlf3e9763eymVfLqMjcA28fn8Q98ys88kRMRxjcqB9vLUR89bPA3RdpnNzYYR1tXaYg7+f/u3f5sqL/i7v/u7cqmC2qhCKqiENYGDnPWKHDA5fbWsgLScDLXsyg4Cfvj2t7/dPfrKaXnMz0mkCpXYmpcQCdTRWrPMrCZCUZfAcALRtPOiwjoCFx9mGHRGlYtntSyDCxICQMtXX3MS5GJB/3Ay/PCHP9zVwXjhxB9rrPmr9bR+FZDxgC9yIG+1XhtBrhcLtrmIVOkZD8cdd1w37nJ8ZR+BfqzWOJMeX2vdjHNmdjR9dWwS8B3iOI/T1viYdQ6Y9+XFStC2hHX18+dxjL3gBS9YlhZ/MRaqUInByo4qnaKCcB5hHdsI5G9+85udAKYP+DVKfEzd9AOCJQf6G1GlbSYta3dzn9G31XrtypccC0cdddRUuW9961s7sVOFIT4agvoxhDVtuvLKK5ftq27uguqlxfhMX9UHqxXWiEXWpmtgXHLuqW5qdt999078M4kxS1iHDfQN5SEI8cmnP/3p7l2VGCOcS6rzAGNJl85gM8e7ngvipiXPglcvBHKt/uxnPzvli4BfOeTcq/tZI64CHRs4f/7Zn/3ZsrQcBxwT1XLG1i9gVrYOnWX2y4umxYYR1pXI5UP+KriGoDbOK6w5sbbqrQQTJ3lNxyy2zljgA16M07QBgrGa3RtDWCO4eKGt1a4A8chFKge+H8uJX9POQyWsWabB7IKmDdinSzk4CVcz6NrnEbhY6U1MhhN77s++2V1AnOYxgz3f+ta3lqV529veNvWTydSBcJnlf0XtIzBGqpuLoDVbftppp02lrY7Nvpn4StQR+KXE1oVqUcKaY0z9HMeYpg1as7KVGKzsqNIpKgjnEdYEjrd//Md/nEof6Iwtgf6uBBvoj6IQdF2yik8CvmQ5Vau98/hyJagfQ1izjz7O47bvJcbqpcVoe9UHqxXWCFedAUYE943LFpWwJnDj9dGPfrRZXjVGhtjAzb3azvUg//w3NlF/DoyvP/3TP50qrw9m1BnrOXD+Zaa7T7wy862z0FxrsUvbZmFtFsGGEdZvectbpk7sHLycILS8WaiN8wjrvqUdwE+h6gsWvNHNxSunQ/zpnTgn9FnCiguZntjGENbzwLrJHFr+mwcV1pywZq1Ph0pYsixD02mfE1qzyQFLD/ILTQQuIvqkIkP/qUjBXzlNZTMioW89dkVlHxdH1qZrWoU0+nQlXhjN6apjc5YPvvzlL0+NUXzQulAtSlgjYKpjTGfjFMSF2l+JwcqOKp2ignAeYd2aTc7wGD4H+vlTn/pUbx5m8POY5NjgJcnYjy/1ScRQX+r4GeKjIagfs7DWlxEJzNBqvZpOBXjVB6sR1tVNDGMUcV+VOYtKWNOPzFT3CTyWAek5iOUvfXmA2W+WguVA/+ZlHP/0T/80tUyCa7WudZ4F743omOOJ3iyBzjlYX9jlf24KtH0W1mYRbBhhzQmpenzGActFYR5Roja2hGElrGcte6iWrFSCBfGXAyd0BImWp7zhDW+YevS/CGHNLC4zq6zf5STMCY1lFjoTQGj5bx5UWHOx2HfffafSKdWNTPUkQ/ucUM3QziqbNXaaTtG69MZKZ4vpe26YtJxZVPZpXS1IQ9ocKIsyc7rq2Jzlg+q46RNTixLWCKAc4hjTdArHmL5UVtlf2VGlU1QQziOs+5Y0AP2qSzB4gsELYJq2ry7Gwoc+9KGltlS+5KXUWW0d6suVoH7Mwhp0Jrp6iVGFf7y0GGnUL4TVCGtm/vUpm9Y5D5WwrtqZqa6l2t99VBMDWchT/g033LBsP4FrNU/7Wk9OFJ585XpizA0RrnxWU89bfH1F81pYm0WwYYQ1sNZWZ9kicNBxoh3yfWW1sSUMK4FQ2ZUZKqxVSFLPO9/5zqnylKr8sYR1fC+az5LpibMvtPw3D+qPymcV1Y1GlVf7PE6CWl6G/TouVxKyPVX/YT/t0PpnUdk3a3xm9OauOlarYzO+Y92iOm76xNSihLUKL2yq1p0rQ7+9XNlRpVMqu4YKa/qsr3yWZLVeiJ4n6Cxky+Y+W2CoL1eC2qTCWpc7cE7LLzFWa7HjpcUoo+qD1QjrKg1Pc1YqxiphPWvZBaJRx8hQMQmMC22Dfm2E9dTVJAwhrtU8NWs98aBv9JrAmGOyZYiNfHFFl6Mg9nfaaadl6SyszSLYUMIahnxWDKHCTERLYKuNLWFYCYSWXUElnFToVWmGiqsq7xjCGlE/6zu/rdDy3zzoSVR91qLyR5W36vNZNzKV4FtJyPawjEhP+NUM+xAq+/rWfyvqk+pYrY7NjSCsK0GnyxtaVHkr+ys7qnSKCsJ5hDX921d+JbRWErKwrvzB2tfXvOY1U/UrVd4hPhqC+lGFdSWcWfbBcgb24/N8LNIP8dJilFH1wWqENe9b6PIk1gxX5Q2h6u9f/OIXveKuyjNLjGeqdqqwhsMPP7x8kTAHjsn4MaGctxK8jDnWXQ/xVbXO28LarBUbTlgDJ/S+z04RGPCtHw1RG1vCsBIIfXbBEKE3JE2LKu9qhXXrpUhOnnxdgkdyLLfhZRg+WzTUf/OwUmHNDJ2+4FLlXYnNleBbScj2VGNqpf1X2TdL9GbUJ9WxWh2bs+potbF1oWq1o5W+ErRDhDX9EN/C7qPKW9lf2VGlU1QQziOsVagplWhaSZglrMf25UpQP6qwBl3qkdeb61KRas141QerEdY8EdSngZpmHqr+rkTurDyV71pU7WzVyfmZ67CeQ3LAH1zP82f7ViN4wcLabE82pLAO+DwPn4pqLV0grloPqja2RFYlEGbZVQlfFXpVGk4CfS9FBpWQXKkwC1hrnAN9wSPT1tcyhvpvHlYqrJl11j6qZoBXYnP1ginrzck3D3vssceSPdWM9dC2KpV9s8ZnZjMvBakEHX5n7amWp1TLKSr7KzuqdIoKwjGFNS9587PlOfAJQR6h67jsg3EakxKvfOUrp8RH+LLPFqj6YYiPhqB+rMShvpxI4CVG1qnrS4vVmvGqD1YjrKsZ65YoHUIlkmeVx8uFOkaGikkYshREiZ9L59rVulYjVKOMv/mbv5n6vCzHiZeCmI3A6MKaz2rlEINN02WqrwjMIxCArzvw2E8PWk46+hLcUJFVCYRZdlWiuRJOKiRZ3vKJT3xiqjylemFtNcKai6Ze+JhhUGGa0cerLf/Ng/pj6Cf8qrGjX+GAoX2eYZ2gXkCqL47MQ+Xv6qXBITBedFnUal5erG7uNqqwBhVe8xxjQ+yvRCw3dTrrmaleLhxTWFcieOiyjT7Ul3lGW9NmWFoxxJcrQW2qhDXozDTLDw477LBlx07rBcKqD1YjrPndBX1PiOPwRS960VR5Q1iJsOZrQipaV/PyIv/zLfO+OjN8KpKvdugNBu1goiRs4Edccj2rfXkxC/fAwtosgtGFdXWRnPXZNGYQNMwSsBWIQU4qOVTCfqjIqgTCLLuGCmudLSTM+koFVN/JXo2wrtrYt06XZSP6ln/Lf/OgwnrIZ+Pobx7f5jD0O9ZDbK5ejGz9AM086OcKCbPGVUXVF4gFXuDVtAo/iKM3aJUo38jCWs8FBI4xTafwtKY6xjRfNRs7ax03nxxT28cU1nDhhRcuy6OfkFsJ1Y/DDPWlCqjKlythqLDWb3DjD+03fWkxqPpgNcL6H/7hH6aO2aE3KRUrEdbAOmwVx/wU/Kx8PMXQzwXOI8oDzt2MKRWmfIUqyuFb+Tp2EOSz1oJTtv74TUuUW1ibRTC6sK6+VND33dvqAk9QocEBXf2KoqLfeWbgH3nkkcvSDBVZlUBQu5ShwrqaacUP+EPLDKofRCGMLaz72lid7Fr+mwcV1gRm9qo18oGunyS0vjM+tM8VnZ1nPK3kh1wyOkYJrV9znIW2i4AvW8cbVD8QQ7uYidK0G1lYH3rooVN+5hj7yEc+MlVmwDGmP9xEqOxnDOhnxTg2eNyvaSN99eM5Ywvr6pvTCElmZDXtUPCljoPwZcue1s92V75cCUOFNSDIWgH/60uLQdUHqxHWoKKWQP8wk6tpZ7FSYV3ZyhOrvh+VgeoHYvh031/+5V8upYlrdV85oOdvnfl+97vfPfXbFaTn2tnXvuoHYriZyT9rHowtrGlTn21mazC6sK5+yIXBxwVFL/af+cxnyhMvQcUdF1M+Os+MbUtssSaYb1XmUD3+VTHSElmVQFC7lKHCukpH4OSGX7TcPl+tRlhXs7KIdxX4iAIuEnpxJbT8Nw+VsGbcEK+PsbGFWWk9eRJa/TO0z5VKWCJauHjpeM685z3vmVx22WXl7DnjV0UBgQsWor0qlzy8QKo/ac6j02pctH7SHF/i0+rCrmMUqvZvFGFdzSgTVnqMafmgP8ZCoHwe+ef09Cm/8ql+J4wtrFvtZkwgVlr5EUM//vGPuxlvTdMqE39pW4Gfz9brQISWL+dFj6E+Ya0iLofqpcWg6oPVCuvWBAnjpvo5cUB0D/1J8yHCmidT+rSPwFisbODa+pOf/GTKh0wI0G61iWtK6+fZozzGWT4e4mlbLuuMM86YmsjBhuonzbku8NUw/RIJ5+vqx2FgNcK6+pGda6+9tnsJc1Zes7kZXVhDtbSDwEHILCSzZRx4MSg5EPQuWAVSvlhzYHES5eDihQhAkFQn8mrWc6jIqgSC2qVUgrkS1sBJUmeWCPiFkyVtBP4PX3Fzoe1cjbCullMQ8PHVV1/drU/Et9SLDdir60pb/psHFdaMhzih8j+igHHDiYuLuZ7QCLxw1lqmMbTPleqRZYSwi/2MQR6lan+1RGjr4krAx8yw0F7g/zg+qr5m6U5rHDFW8FmUU6XjuOQRrJYLG1lYQzV7S1jJMVaVXy3tIFAW5zj8zjko1tXSj3rhH1tYA08OqxvPsIuvMHBscw7lqUweG622Vj/FHWVyTDLO9Picx5fzMo+wrl5iJMQSgZY9VR+sVlgDN8mVLwmUEec72oTgDn9qeSsV1tB6okBgjMa1Glu0XQRs4rjTpRn5ixyta7VeQwjUl78MAnxejyfeVch+Iq8eVxH6xO5qhHW1jptA26mTdvNEa0hZZnOxEGHdmkWrAuKCg00HqArY6mI9K1A2AkbtGyqyqjrVLmUeYd0n2qrAhZJvg2r5ldiaB2YJqotwFTiJMXOSQ8t/86DCGpHMWuShvuFkpk8mMkP7vKJaOjE09IlQ7NU312eFqq8ZR3wdp3Wh7gv0O49OtcxgowtrfKOPbPtC3zFWlQ8/+9nPBpVPGo53XT6yCGENfeKtL7TauhJfMoOoM92t8udlHmEN+hIjofXSYlD1wRjCGl/ydGDe/tHyViOsgbXRlcidFRgDjAUV1WHTvOc1rtWtnzznqWp1UzQrYCPn7ZaohtUIa0S/fqFLw9CyzOZiIcIa+JXEWQcX+0lXXbxVwFYX61bggOITUxzgahcMFVlVnWqXMo+wBh6J8bhr1gmWGxWEWFV+JbbmZdYP7+BTljYw8zPUf/Ogwpo2Mvs85MaDzy3yK2taZma1NiOusWVWP+VAn/HNXC0rw4turFGc1cYIPEXQMgJukHRZTyvEMVItF8lUx+ZGEtbAMcbLabP6jv7Ch9Wyhz77GRssQevrQ/bxtR0ejasgXJSwhq9+9avNJyNVoK/5slOrjkX7ch7Uj7OEtb7ESGi9tBhUfTCGsA64qVWbWoExxPtCYwpr4OtLrEHvG7859C1ZCZtmXfsjxHmIY7rPT/yoD5/O1XNRK/CEqFouoqxGWAN9Xr0jFmGesszmYWHCGhBhrLPijjgeM3IgcSLhjfJ4GbG6eFcClk/qsa6JEzWPffKJgBMajx0RP6xv1byZoSKrEgiVXZlK+PYJ61wXM7T5kTQXL2ZUmNGP5SzVGvYxhDXgX9bCZxvw66233rrslyyH+m8eKmEdPttvv/26i2i+aHETgCDlcVzre9uZsWyOMUi/ZHvwF2OSeMbgxz72sblecGTM4nvGcBYt/E8cY2NImexH0HChRFDlZRBR1pBjJKiOzY0mrHO+oceYzuL12R/EOM03qIwRxinrt0OIqCBcpLAG2sWyM+yozpuIYMYLN9etNbEK4ok1spUv+RII34km3XoS1pCftuH31kuLQdUHYwpr4PzFi8u0B5ty/zCW8B/nnDe/+c1TZY0hrAPWcXOjUZ3bsIubel68fsELXjCVV6GsE088sROt1ZjjPMQxy3IUbVMffA+b8UW5+TiL8y9j/Jvf/GY3joeUu1phDdyYMK7ykh3+sk0bebFzaFlmc7BQYW3Gp/qO9Wq/rbwe6BPWxqwl1XesOcZ8cTTGGDMLC+sNBjMg+siu77vTGwULa7NeYLa8OsYsrI0xxszCwnoDwdIalmXkUH1OcCNiYW3WAxxj+qt01WfAjDHGmAoL6w1C6wsifT++s5GwsDbbm9ZXLzjGYs2wMcYY04eF9Xbks5/9bPeyBb/U9tKXvnRqf8BniHhzWi/4vJhW/QDJRsTC2iyCsY4xz1YbY4wZgoX1diR/cSHevI6P8s/66D2Bt7T5BS0tdyNiYW0WAV9qWO0x9qIXvWiqXGOMMabCwno7Un3KbEhAIHDB3wxLQAILa7MIsrCeJ8Qx5iUgxhhj5sHCejvCY2r97umswOwa3/Ec8u3mjYSFtVkEqznGhnyv1xhjjMlYWG9n+JEcPu/FY2l+qEFFAD+6ED/gwI+0bDZBHVhYm0XhY8wYY8xaYWFtjDHGGGPMCFhYG2OMMcYYMwIW1sYYY4wxxoyAhbUxxhhjjDEjYGFtjDHGGGPMCFhYG2OMMcYYMwIW1sYYY4wxxoyAhbUxxhhjjDEjYGFtjDHGGGPMCFhYG2OMMcYYMwIW1sYYY4wxxoyAhbUxxhhjjDEjYGFtjDHGGGPMCFhYG7MJOeeccyY5PPLII5O99957Kl3w0pe+dLLHHntMnvvc507t2yrssssuk9e//vVT8cYYY8xQLKyN2YQMFdYvfvGLJ5dccsnk6aef7tL99re/nXziE5+YSreZee1rXzu58cYbl3xwxx13lL4yxhhjZrEQYa0X9XkCebU8Mz4HHXTQ5Mknnxzs++uvv35Z2lb44x//2Im4e++9d3LBBRdMPve5z3WzoVqeWSx6DLaE9be+9a3JU089tSztzTffvKX67NRTT13WfsJll1022WGHHabSGmOMMX1YWG9RFiWsq4DY/vWvfz3Zb7/9pso1i0GPwZaw1nSEhx56aPL2t799Ku1m5brrrlMXdLPWr3rVq6bSGmOMMX1YWCeYpWMG71e/+tXkN7/5TbfmUtNsFtZSWEfgUftNN900eeMb3zhVvhkXPQZbwvrrX/96d+OTA+P/hS984VTajcLzn//8bjkLS1weeOCBbqz3zT6ffPLJS8tAIpx//vm9eYwxxpgKC+s/+ZPJK1/5yk7w5YvrnXfeaWGdGENYR9iK63jXGj0GW8KalxVPOeWUbizEjc9ee+01lW6jgEj+wx/+sNRu2jVLWLPO/KKLLupuMODyyy+f7LzzzlPpjDHGmFmsibCOi5umWy8goBHSOVhYL0eFdUuoAV9WYCaUPDobGuF3v/vd5L3vfe9UXjMOegz29ddm4uyzz17W7iHC2hhjjBkLC2sL66UwlrDOvOY1r5lcddVVU4/aCbfeeuvk5S9/+VQes3r0GBzaXxsdC2tjjDHbEwtrC+ulsAhhDSw3QPCouOZrFN/5znem0pvVo8fgPP21kbGwNsYYsz2xsLawXgqLEtbAOtZrrrlmWRmE2267zbPWC0CPwXn7a6NiYW2MMWZ7siGEdSUCjznmmG4fs6Gf/OQnu09m/f73v1/a/9hjj01++ctfTt71rndNldcqc1ZQ4antzOKFenkRLNYY33PPPZM3velNU3YgOL/2ta9Nrrjiiu6lvvziFXlZi8yLVe95z3um8q6Gqv3avsxqhTV8+MMfnjz66KPLynn88ccn+++//1TalcDXIGgX/rr//vsnTzzxxFI9zJZj89VXX92Nl1m/MNjXt+T9/Oc/3309I9fB+COOfeu5/Axx7Muhbxxk4thj7DJO83p6xjF9QF987GMfa9q72vHPzS+fxpsncNO86667LpVx4IEHTh0LnF+GiHHsOvPMM7vvtlfjjePmG9/4xuQlL3nJVF6Fvnj44YeX2UFfhB3vfve7J5deemlXbjz9oU7GBP0wxF5jjDGLZUMLa2Y6+SEHXWKQAxfqH/3oR1MX9qrMWUEFh7YzxMsXv/jFTjBW+yLvq1/96skvfvGLwTbQxvPOO68TIuqflVC1X9uXGUNY0wfVN4NPOOGEqbTzgE9+8pOfdDdTQwK+xA76QMsKWn3LpwL1CzIa2IfY4Rf9tNztXb6mW6mwPvTQQzvhPCRUT39WOv5VoG4vYc2NM33Q10858G1wbiCe97znTZUVtIT1C17wgsnpp5/efBGY0PKPMcaYtWXDCmvW5lZLC6qAuP7KV74ys8xZQQWHthOB8oUvfKGbZdOgwmYl9XPx5FG33iSshKp+bV9mDGENiGgNV1555VS6eajE4ZDA+GndqFR9+/GPf3wuEUfalvjdHuVX/VX5rm8cMPZOO+20XpGnoRLW1fibFWL8Z3G6PYT14Ycfvuzp2NCA/cxut8R1JazPPffc8v2EKpCG46tltzHGmMWzYYU1X5SIiw3CAOF37bXXdo+Tq4uQruV93/ve1z1+RlzpMhIC28SzPzjyyCOX2aXtxA5sqIIKm9wm7L3vvvu6nwD/7ne/28HPLD/44INaTGcXj33VR/NS+bRPUI0lrA855JCpem+88cZV3SxkcYgvGQM8yfjBD37Q+fKnP/1pJ6Z0XCAO+Syglgfatyxh4UeDIvBEgpllxgXLAFpCE2FUtW2ty2/11zzCuvUSagSeGITNt9xyy9LSiFnCejXjnx91wqY4RnUWnRdk+Yn2fByT/mUve9lSGfMIa8avPo0i0Abs5finDtpT+Yl+ZFKgKrsS1tw0xPKYPCZa5TP299xzz7J8Y4wxi2dNhPXQUF2AoRKBBC44J554Yre2NtJy8f/+978/JUT6xP1KX17UdnIRxyYueFzMWVOMPTz2ZjlKXmONLVwoWfNbCR6gXQgnvYAy66Vp56XyaUtQwVjCmh+G0ZuYIb7uIwQJYq71s+mtcYFI0bSgfRsB2/l1zjzmgCUc/Gy7Bvz0/ve/f7uX3+qveYQ1T33yGugI+L2yIdaKc5Oj/Tt0/GNLNf5bwnElLy8OFdYcv9zkaKD9rH/WcknPzbnaj78/8IEPTKWvhDWB/PwS5Cte8Ypl6Xk6pscSaY877rgp240xxqwNG1ZYI2IRSpoWuKBfeOGFy9IT+FU2TQtjCesIrHVUYaR86EMf6kSHxitvf/vbu1moHFY7wwuVT1uCCsYS1pWQG+LrPhAwvCA2yyc8seDJRQ533333ZPfdd59KW/UtQvBzn/vcVNqAZRnVsoRq3K11+a3+qvqjGgf4jqdEGvqW0/Qxz/jXmWvGf2s5xSKFNU9AVCTTH6973eumygzwDTcPGlhOo+W3hDU31632Hn/88VM2sbRKyzbGGLM2bFhhrUs7lC9/+ctTs2t8XUDTwZjCmke01dc/VsoLX/jCqZnKIbbNovJpJaiC9Sys54ExkEOrHVXfcrM2S7wzi6jjrroRWuvyW+2s+qMaB1W9d911V3ON91gw/ln+kIOukc4sSliz5ERvLLgR+tSnPtVbNrB0RWeWqzZUwjqWdmiZATPf2n+cL170ohdNpTXGGLN4NqywnrUcohIMiENNB2MKa2aiNN0QmNlidu6www7r1pdee+21U5+MizDEtllUPq0EVTCWsK7qRQggoDTtSuFpwdve9rZu9pf11fzyI4/wVdwQWu3Qvu1bSpR5wxve0N1c5VDNiq91+a12VsdJNQ443nJglvSHP/zhVLqVMu/4V1EaLEpYf/CDH5zy01ABW90csKaeWftcRyWseSLQZzvnAX2K0ecfY4wxi2VNhPVQ0dCiEmPxHesWlWBYtLDGRl5u0nQtmHFn7XXrhctWGGLbLCqfVoIqGEtY87Igy3hyWO1XQQAxffTRR3ffC5/Hl612aN+20inVE4Yq73opvzpOqnGgn0lEGCI2Nd08rGb8t4TjooT1wQcfPCXy8VNfuRmWc+RAfZQ5S1jPqsPC2hhj1hcW1iMKa+p75zvfOZWu4oADDui+bbuSMMS2WVQ+rQRVMJawVp8RVvsda3yOoF5JaLVD7Wylqxjiq/VSfnWc6Dh45StfOSXeqlnyeVjt+G8Jx0UJa27aNLS+7lFR2WVhbYwxmw8L65GFdSVelPe+973lt67jc2VchGkf6bBBhdQQ22ZR+VQFVUZtGNrWDOtx9asKLM/gSyGadiitF/qYXeRrDXzC7dvf/vbkox/96OT1r3/94D4bmk5hrTNrnmflXS/lV8eJjoOVHh8t5h3/OlveJxwrAbsoYa1p+qjssrA2xpjNh4X1KoSDtrMlXjIII35qXfPxq2z6AlqgonaIbbOofKqCKqM2DGmrwgyfLgPh2828GKZph8Ka9hxoE19KaH2VZWifDU2nMIvLbG4O1ezueim/Ok50HFQz1q3yZsEYZ+mPltU3/teDsD7iiCOmxu4s0ZvxUhBjjNkaWFivsbDmBS19BM7PcWu6ANGZfziEMMS2WVQ+VUGVWa2wrmYp+36gZQiV4LvkkkuaAg0qUVe1o+rbIct8WHfM+uMcqpczt0f5VTur46QaB/rJOL4Qwpd3NN0sWuO/JR6rr3H0CcdFCWt+FZMZ9RxW8/IiPtCvfVhYG2PMxsfCeo2FtbaF//teeOSHN7QdQ2ybhdpBqARVsBphvddee3WfZtPATORKvoEcVH3MrLimC6qlKK12aN8yW8kPt2g6RWfQCUO+M73o8lvtrHxYjYPqp+j5YoUK+lnouFvp+G8Jx0UJa8aOruNnGdP+++/fWzbw9Q9tQyXKLayNMWbjY2HdENbV43VF29kSLxltC19DOPbYY6fSATOv+giZsFGENfbziF9nKAnMXjOLrXnmoerjvjbwg0L6OL/VDu1bwqxvlL/vfe+baivfOkZ8adq1Lr/VzqE+rAQuTxzwad8TAkXH3azxr+0g9AnHSlgj3PvE6RBhXZVN4LjQX0TMVD8QE58q1PItrI0xZuNjYd1YboFo6Jv9BG1nS7xkqkf5XBj5yeqcjjXCZ5xxxtRPcBPWs7DG7ne9613d96P1F/MiMNPH+lLNOy/VN50R7PyUfE6HQEO8aXsJrXZo30agr2ifpv/MZz4z9QuZhNas7lqX32pndZxU46B1k4dIZHnNa17zmqk8jIUvfelLy37SfJ7xf/rppzfHf0s4nnTSSZq889FLXvKSqbTBUGHNUp1qTLd+0hyfVD9pTnsr+y2sjTFm47MmwnqeUInwSgSOKaxBf5GPwAWRixQXZi6eXOhzHm1nS7xkqp/VJrB+k/XB3/3udztbYmaSGUm92K4HYb3SgDhczVdAMtWLoATaxSwhP0HNLCM/NEJfItIeeOCBZWlbfaZ9y0x3/PIg5SBmGBeAuFfxRKAPmWXWsrdH+a12VsdJaxy0vsBCwD5E57XXXtvZTLr47nMer4x/vYklzDv+W8Lx0EMPnfqFSALlYRvj+IYbbliWf6iwBr4wU4l9bT9Ljqp0tIefcq/KtrA2xpiNj4X1M1Q/2axBBYe2syVeFF7Yqy66GrhYIwwRAjlsRGHdN7O5Gqqfi24FBM955523LK7VZ1Xftp4gVAEB1fdi5vYov2pndZz0jYPWevm+oON1jPHfEo7VWmgNmn8eYc3NHOJ/1rmiCozTvmUpFtbGGLPxsbB+Bi6Y/GxzNTMYQQWHtrMlXhTq4hfn+i7OCA+EFo/EVdSqUFkJlU+1fRm1YWigHczisUZXyxwL1nH3iWv6lOUIzJYO7bMq3b777jv53ve+19tvBGZH+17I217lV+2sjpO+cQD4kdnlIeKYwBMavuAS+ecZ/y94wQvm+tweMLb7xoPmn0dYBzx10WVIrcD4u/nmm8vlIhkLa2OM2fhYWAvMgP7qV79a9vPFCAAe7X71q19dllbb2RIvLRCbLGXIn/FCECAk9ttvv6V0KmrXq7BGQNAWll4gZHkKsJqvfswDL/3xYzAIk7g5og/5VBuP3uMFu6F91peOv7Qv9xt1ISAZl0PavD3Lz1THSd84yOBzxC/HRj5eEMWsdb/iiis637e+KT50/M8rrIEnIzoe+MtNCbPg+YscKxHWwJjifEE7aW++0eCcwXFAXe95z3um8lZYWBtjzMZnIcLamI3OUGG6UhZdvjHGGGPWHgtrYwoWLXwXXb4xxhhj1h4La2MKFi18F12+McYYY9YeC2tjChYtfBddvjHGGGPWHgtrYwoWLXwXXb4xxhhj1h4La2MKFi18F12+McYYY9YeC2tjChYtfBddvjHGGGPWHgtrYwoWLXwXXb4xxhhj1h4La2MKFi18F12+McYYY9YeC2tjjDHGGGNGwMLaGGOMMcaYEbCwNsYYY4wxZgQsrI0xxhhjjBkBC2tjjDHGGGNGwMLaGGOMMcaYEbCwNsYYY4wxZgQsrI0xxhhjjBkBC2tjjDHGGGNGwMLaGGOMMcaYEbCwNsYYY4wxZgQsrI0xxhhjjBkBC2tjjDHGGGNGwMLaGGOMMcaYEbCwNsYYY4wxZgQsrI0xxhhjjBkBC2tjjDHGGGNGwMLaGGOMMcaYEbCwNsYYY4wxZgQsrI0xxhhjjBkBC2tjjDHGGGNGwMLaGGOMMcaYEbCwNsYYY4wxZgQsrI0xxhhjjBkBC2tjjDHGGGNGwMLaGGOMMcaYEbCwNsYYY4wxZgQsrI0xxhhjjBkBC2tjjDHGGGNGwMLaGGOMMcaYEbCwNsYYY4wxZgQsrI0xxhhjjBkBC2tjjDHGGGNGwMLaGGOMMcaYEbCwNsYYY4wxZgQsrI0xxhhjjBkBC2tjjDHGGGNGYMMK67/+67+e7L///pMTTzxxcumll06uuOIKY9YMxhxjjzHIWNTxaYwxxpitx4YU1oiZ0047bbLPPvtM/uIv/mKy0047TaUxZpEw5hh7jEHGImNS0xhjjDFma7HhhPURRxwx+fSnP20xbdYNjEXGJGNT9xljjDFm67ChhDWzgggYjTdmPcDY9My1McYYs3XZMMKadaw8cvdMtVmvMDYZo15zbYwxxmxNNoywZiaQ9awab8x6gjHqWWtjjDFma7JQYf2i/+1vJm/+249P/sO//5+m9s0LX2DgZTGNN2Y9wRhlrGq8McYYYzY/CxPWO+240+Rdr/7C5KvvuXzy4v/y6qn988LnzbwMxKx3GKOMVY03xhhjzOZnYcL6+f/phZND//ncyWH/csVkr9d+cbLjjqsTxXw7WOOMWY94rBpjjDFbk9GF9f/yH/7XyeteuPfksDefMzlin0u7GesvfejKyQf3OWHykhe/ZvLv//1/nMozhKFi5dBDD53ccccdHTfeeONkjz32mEqznjj33HMnxx9//FT8aqFcfKHx+OPqq6+e7LffflP7xoQ2YYPGB9hx+eWXz90/lEnfLsJnYzF0rBpjjDFmczGqsP7Tf/8/T778yuMnx/7jRZMj33rx5Ov7XDY57D1XTA790C8nn//XqycHfebayT+86aCpfEMYIlYQi4jGEGtsH3DAAVPpNiMqpHV70eDrCy+8cPK3f/u3U/sqViKs561jezFkrBpjjDFm8zGqsN7hT3aY/H//1/82OWDnb0++9daLl2asEdYHf+yKyVvefOjkf/m//dlUviEMESsIyb5Z0s2MCmndXjTzil4La2OMMcZsNkYV1pm/+n/83eTwvS7q1lh/7O0nTP70ef95Ks08DBEriDSWf1TLBFRo5m3+P+6447q8LDMgnjL4/5ZbbllaNkHcSSed1AnCWI6Ql55EeQi/SAMh9kNMnnHGGUvlhh1RX7WMJZY/tJZA5P2UT/3aJrWBv+EvbWcm26U24QvyXXTRRd3f7AfyZVu1DSqsqTvKqJbw5P1ha8vPap/6LAQ6+8Nn7373u6d8pfVWdlUMGavGGGOM2XwsTFg/Z8d/P3nfLl/tZqz/9v/91qX4//y/vXDyqtd+dPKcf/8fpvL0MVSsZLHVEtK6zf8hmkJIhRjLa4X5P0RdiNLYR1khatUeRFzOo4JTZ5bVtizYo6ycXtPFdrQJYl11FrQqfmeR01N+bq/OJue02YdBtkPz0g5Nr3VEP6svW/ZpObmPW74aapcydKwaY4wxZnOxMGENL/+Lf5gc8PYzJv/5f/4v3fZznvMfJq99w2cmn/jCtZP/11/+3WSHHXaYytNiXrESIrYSqLqd/9eZ1CymslhUkVuJsJhJDZGvZWvdkS/XkWdkc1mRvlVOazvbEDZW5QXhR50V1vK1/eEr9VMuV+3IVKI410E+bMhp8n61r1VOtpX/s71D7VLmHavGGGOM2RwsVFhn/q//8T9N3v8vJ04+c/D1k/0PvXGy39dumrzyLZ+aStdiJWIli2IVWosU1uTJAqwStZUdKvi0jj762jfEhmopCGnyF0T6/Km2h6+q+qLsLKyj3D62h7AeYpeykrFqjDHGmI3PmglrZqf/1//7X0z23PfoyScPvWHyd6//yOQ//k//81S6FkPECkIoiynEUhbF8X/Mwi5KWLfq0rJz3dW+2D9E3KmQbG236sltC2hT/spKtkXL7xOrVRuyHeTFRyrslVwHkD/bTB25ztUK66F2KUPGqjHGGGM2H2smrIM/+y9/M9nnwz+e/Mfn/i9T+/oYIlZCbFWP7UPgEs9f9i1KWLfq0rJz3fzNSw5aL+i1XqCjjNxmFZaVsKYtla8y2a4+YZ3tJF59ldtAvPoi7M9p1BYVxNnPYZ+2V8uoylFbc78OsUsZMlaNMcYYs/lYc2G9UixWzEbBY9UYY4zZmmwYYX3ppZdOdtppdT+LbsyiYYwyVjXeGGOMMZufDSOsTzzxxMlf/MVfTMUbs55gjDJWNd4YY4wxm58NI6z333//yT777DMVb8x6gjHKWNV4Y4wxxmx+Noyw/uu//uvJaaed5uUgZt3C2GSMMlZ1nzHGGGM2PxtGWAMzgZ/+9Ken4o1ZDzA2PVttjDHGbF02lLCGI444ohMwnrk26wXGImOSsan7jDHGGLN12HDCGpgV5JE761l5Wcwi26w1jDnGHmOQseiZamOMMcZsSGENrGNFzPAFBj5vxreDjVkrGHOMPcag11QbY4wxBjassDbGGGOMMWY9YWFtjDHGGGPMCFhYG2OMMcYYMwIW1sYYY4wxxoyAhbUxxhhjjDEjYGFtjDHGGGPMCFhYG2OMMcYYMwIW1sYYY4wxxoyAhbUxxhhjjDEjYGFtjDHGGGPMCFhYG2OMMcYYMwIW1sYYY4wxxoyAhbUxxhhjjDEjYGFtjDHGGGPMCFhYG2OMMcYYMwIW1sYYY4wxxoyAhbUxxhhjjDEjYGFtjDHGGGPMCFhYG2OMMcYYMwIW1sYYY4wxxoyAhbUxxhhjjDEjYGFtjDHGGGPMCFhYG2OMMcYYMwIW1sYYY4wxxozAdhPWu+yyy+TOO++cEK6//vqp/RsV2kK7aJ/uM+sT91k/1113XeejHXbYYWnb/tq+RB/suuuuU/syBx544OSJJ56YHHvssUv9Z5bDOL7jjju6Mb7jjjtO7R8T98fW4oADDpg8/vjjXX8vemythKOOOmry8MMPT/bdd991ad9GZWHCmpPUI488Mtl7772n9sX+zSSog80m0uIGaL23iXHGeOsbc3DOOed0N3PHHHPMUtxm67OxsbBef1hYj4eF9bNce+213Tl0n332WZf2bTQsrLcmCxHWBx100JLIyQImCLGGyIm4EEZV+u1Nyzbs3+wCgzZHX9Kvun+9QB/df//9ZT8F+SlJK82iCX/2if/1hgprs3EJEcm5y/25cTnrrLOWbqzG6kdEPyKL89N6Ff5BFoTr2c552GuvvSYPPfTQwkR45TML68WwEGHNSZsLcUt4WlhvHKIf1/sThuijBx54oNkn9B/iG7Qv1woLa7M9sbDeHCxCWFNmvm7vtttuo5U9NpVI3OhYWG8eRhfWIZoREDGLmGc6+f/JJ5/sZg0j3HTTTcu2CfqoPgJ5c3kh+CJNFusZrVfFV6sO7NBwxhlnLM18RojyVIDGdixBIFTCKu+n/lNOOaV3lrjyba6P//MNzKz6K3IdwP85X+UbQvgiBHkuM55mZP+yTXtz3mhLBO13JYQ15VR+ifIuuuiipfGZ49XOXHeUm/3WsrtvnOUyCbk8zaf2KNHeqqxsH7NQOV0+PoaODxXWuq2267EV6fvqCJtzCOEQ7eUCUO2rOProo5vtD7tjH32I/fzPI3D2nX322Ut5CNi22nxVO2LshT/Zf999900OPvjgZfnU57pNe59++ull5bIvZiEpj35iGUIO2R+UGYF2qQ0tQqxrW/FF7qdYBhFB+1B9l2dNaR/twOe0M/JW7W4JhFb9rZsNlkVEoI9PPfXUzoZYJsH+GNdhQ4yFlt9yf+T+oa15XJx77rllO3beeefO1hyiHZSHOMvlDO1Hyr399ts7O7Bfx6CWq+XT99iVxbgKxagjzsGE2Kd909ePuV8I+DzEYtQZIexrlQUhLunfGFvRjmuuuWapbynrkEMOWVYWNyN5f4yRSMdSEOyJ7fBBto99+C+PY0L4RtuU7cMGbIxzCGUwdnbaaadlbcztIITP4riiLpasRDjuuOOWlRFLWiLccMMNk+c85zlTvjTbGF1Y64xcdHhOky/oERdCIQueKj/7s8hiH0HzZbRs6ufgzoKnrw7NH8SdvQr0XFbYF22Ntuc07Ms+i/r6xCRpKgGZ64+6cv2RJtfXIrev6jNF+36osCZoOvWj9omS+6hVL/766Ec/2rUj96XWxf+5X0M45ra17L7wwguX0lR9rT6K8rNPqnwKAiP7Qm0O+3Jd0Q4dizo+EFg5n4o43b7gggvKNuf0UQdxVRpEVe7ffIxSNid/2pTLpIyWuOaCEe0P0cvFO9ofooZtLaclCKP+2J43X7QjC7gQk+EL0qioifaqT2NbxRoXYvqk2oc/KxGp5eM/bFc7KqLM3D/RtvBHtD3EMnk4VsJXLd9F+hDQ2UZtW2632hjCsKq/8gniLewJP2JPjCfiQuAhZNgO0YuNLSGnNlflDvF9NWMdZWVRHn6btbQjBJbeNLTakf1JGsTpUGGtYl99Eun66q9mXxF/2n7SRfv7yiINYjGLyRCsEUc6yg+RTB9kG6K9WYCrsNYyf/rTny4Jf/UX+6s4yqDvVfwjhlttDPvVZ8Q99dRTXXm77757F3/mmWcupavaQP/cdtttXTssrmtGF9Y4G2K7EhKVSMvCKOJCDPXlpS62Q1BUqHDRfbPqqGyDLDwjTttf2Zd90iq7z2Yg31Bhne2JvFWdGfUBVO0NQrTlMlsCN7eL9CqYh/SJkttU5ScfRDnZzuwztS/QcVzZXaE+03Kifm1Xla4PTd+yL9szdHyo6NJtJURStDlE8JBjoCqT8rS+Vj8FCIVof86XBVwes5EGWxC2mk+FbBbMQ/OpeKzSRDkqqtTneTtm56uZUhUt9IGKSNJQZ85fpWsRabX/1NfZjpwf8TCrzZXYVDGodmXUD3mftrWVVutT8V2lmWWH3kCQJgQ69rSEUiWsW2K4Fd+Xpq8dlfCdR1irLdStba1EYKbar6I1aMXnsrJgJg4xyZjM5Yf9CHf8ooI38mURmrfpq8hf2aL+Ig6Rq7ZrHSq0tdyg8lnV9j333HPJDuqlfPon23DkkUcuE99a11ZnVGGtF+RWXCWSqnT83wqRl0EHaotCGoKmHVJHZRuoaIp6ch26HXWGqKhEIMwSDqQfKqxVtLXiM1X9VVwuT9tJ+RqnZaggjLhWaNmsfUS9uf/CV7OENfHap5Wdup2JsRYhl6f5wp4qtMoPaF8rvdYT5PjWOND4PlEXeWJWOkJuc5V+yDHQKjtCdeMQZLHZis9jMWwLoVOFaANpVpKPdoR40/ZFGnwwS2TqdghDgpavQk5FZPhEH0NH0PIqhgjrsJmgY2GI7yqh19fuiphhpswsBtQn1MV2Fq2gNqgYrdKoDdofuk2alQjryFPNTLfaE+hsfisu161tnEdY53bp0ogcOMaGCuu8lEV9Vtmm+yvB2TomEMb0lwpvUNGr21Fu1Tb1F3G6hCNCnhWfdeMwq50qkLOwZswwO12FaIP624wsrPVCn0O+0OqFG1QYQUvkZLIomkUWMZFnSB2VbYD9mlft0e2oc5aoUAGqZLGY43N9lZ/74rWcVtD2VH6IeE2r7aoE4JA+UbSPKP+WW27pyiBOfZL7MvusVbfaqdtRJye83Gb1jear7JlFtLWvXN0OcnxrHGh8n6jLbY791Yx13q92tI6BoCVI+1iNsMYWzZdpCetZ+VrtWK2wjjTk5SJJiHpUuNEnlbCmv3QmfShRJn2a7VFhndPGeSRs1BlzpU+whgjM7db8rfoRBeqTlhBVGzaLsM7rhDVQRxaklb1QiVcVin3CuhLEfahI7Cunsk33V4KzL081ox3xfcI60jETrQJb/UW6arZYWQthHbPXWqapGU1Y68U4wwlX109qWhVGoCKsIouioehFfVYdlW2gognUHt2u6tclFJGmb0ausin8GvVVfoZZba7KDigrbJ9VVuUfbVclAPvKbFHZjB+OP/74TmDr2NN04TO1L9B2V3ZX7dW4Kl81RvqoytA43a7qGjo+VMTlbW0fzCusc99VF7FKoM2iJayzLZVAxhYuNC1bYKX5qFvbEaIubKrK0TTaDq2nbwmGishoTyWWhlKVCVV7gyxAo82VKKzSt9LMM05yeWo/+3TZSZQfY4r49SSsiavs6YufVZf6oRLGQSXa4klEn7CeZV+Lqr6WwGzF95WFII5+qexqfZ+asvLSipawBhXSuk0aBHifwIdZ7cu2aTtnCetYCkL5Xk89nNGEtV6MM3oB1+1ZcXrhzi+I0eGgdWawiZe9Yjtf1IfUUdmm5USc2qPbVT725+0QGpXAy5Av2419hKgv7CaEkGy1t8++TBZB8b/6JcD2fNNQtauqq2Vj7hMl2xVxUfaVV145VXZOl/uoqjvake2s7Na4yKdl6XFCvtxHkS6P2YyWEW1X+2LGKerWeoaODxVxeXtImzV/2JLzIVr05jteXowys3AjH+OhdbFBFET7Q2hFHHWHqAk/5nKwl/gsyk8++eSldKvJx0U3t4N2xzGb/ZvtbqWJbdoVbYr0kZ+6Vbhpf+BjLt65TuBFwBCI1Tr3jIpObGJGLtvBeI78KkCz7yJN9p2mjzJa7Vb78H2r/mh/9EuIzSiLuOi7bGMlCCs71Y4xhHVVT9ioLy9WNwkte/I+FcK0F59UIi9EYdSdl3jMEtaxPCILSuyi/1vtr4Rv6+XFaH+rrEpwhq3a3vPOO2/J5whOxoPOOOdlGrrGmmMqylMhHXXmNdgh4HMc+c4///yl7aHCuhL5Q4Q166l5wTF/KYSy6J9ZdW5VRhPWKvIUDqa4kMbFWwVZXPirC30OOV8WRS3iwhwhX9CH1DHEtmi72qPbUZbaQJoI7Is0WYApIagiYHOuL+zLnzci9PVT5FGbM9HXrbVXufwQ+4SqXZUvsh05aJ9kKmEdZcyK0z7Suvmfme9sZ8vu3I/Z99nfkUbLy6EqO6N+nfU5wAiVL2aNDxVi1XbOq23W9Nm+3MYQkBGyANVjeNZNJ4Ki1f4sRGIsqlDIbSJk+1eaL/Lm9cT5mI10+ISLXV8aFdb5UT6+D3FZCadsQ/iYvkLM5aD7su8UzY9t5A9b8FVuN/5T8dnnu0pI9rVbUb/n+sP2PN5C3OayOQdkG7ansM72RbujvFY7tQwIsZxnvjOxnhpBWS0X4TgM20MgRzzCjLwqHKt25bwE7NZlFgq2a9oQ1/OUUwlryDcHEfQziHkNNHVFm1vCWsurZryjvNgX4jpCFu5hA+NwiMgNe8MvMV77hDVxIa4jRH7tR7ON0YS1GRcuRHHx1n1DCeHUJ0jNMCohuJ4ZYu9mHh8hrBEVum+9Ud14rCeYIUPE9Qm0rcAs0WxMNStsth4W1uuUmO3JM4fzspmF01oTM4Yav16xsLawHgtmQVlOtV7tWyuqGWpjMkPWRJvNj4X1OoCLVp6ZjmUB+bH9StjMwmlR4DMunlmQ4r9ZSw/WGxbWFtZmZbAEgD7JM9PxDkC1FtlsTS677LJla7erteJma2JhvQ5A2GhYraiGzSycFgkiJ4eNJqrBwtrC2qycWL+bzwEW1SZTfabQotqAhbUxxhhjjDEjYGFtjDHGGGPMCFhYG2OMMcYYMwIW1sYYY4wxxoyAhbUxxhhjjDEjYGFtjDHGGGPMCFhYG2OMMcYYMwIW1sYYY4wxxoyAhbUxxhhjjDEjYGFtjDHGGGPMCFhYG2OMMcYYMwIW1sYYY4wxxozAhhXW119/fQf/77LLLpM777xzaXszcNBBB02efPLJyTHHHDO1L5P9YNYO+oX+oZ9031YlH4c77LDD1P71wnXXXbfubdzMHH300ZOHH354ss8++6y4Dw488MCujIMPPrgrQ7c1/UZh5513ntxxxx3d+Nxxxx2n9q+GzeKjRXPNNdd057HddtttoX6ir2+//faur3faaaep/WbjYmG9TtnowhqbHnnkkcnee+89tW89gZ2EPj9HX2Q/W1hPs72FNfUjSlqB8YiYi2Nme9hoLKz72OjC+qijjpo8/fTTk2OPPXZ0+9cKC2uzWjaFsN4KhGg555xzlsWvRz8gNhEx0CdY1wP47oEHHuj1IT4n9KVZJNycbARfjg3tRgjQ7pVc4Foz0614szZYWC+eyseL9lEIxTifblRhvZk488wzuxu1Rd8kmOVYWG8QNpKwxkZs4i82Y7umWS9gZ9wEVLPPiLv7779/csstt2w3P1tYW1hvJirRNy8qEnVb0281Kh8v2keUf99993Wz1YusxwzHwnr7MKqwDgGQH73mpQBcIInjAMzpsliM2c7DDjusE2URVNRkQVmJznh8HyELvJyeMqo02eYcchqtQ21s2ZttyHEh4ig3/BD/53oI0dYoN2ZVCer3itxuQhZtUXf0VwQV9RXRLvLm9sR+HSMRYlkF+bQfVFiGfaecckqXL7c3+4EwS4yG/8KHuj/sueiii5b1Vfgm+znXjV3YlwV7y271SS5Xxx8htyn346ylKUOOreg/2htpoj61U+vLx1WcxDWP9i1oG0lzxhlnLIsjzCuwWwI64vWYQYTkdGefffbc9WueXH/cKETAf1l8hPCJ8UEIu6ibR+w5LupERMW4ioAPd91112X2RFy2d6+99hpkU4ilCLmPW2BX2EyI+kP0UeYTTzyxtJ/tXKb6MtepIlG3I00un76IWdRYNlRdA7Ax23Httdcu7cfPp556ailaW3VpGQRtaxBLQbCL/C3/n3vuuc0ZYa0rxgvH6pCydEzgkyHC7KyzzlpqNzZEG6JdzGZXAXuw7957750S45QTZUYZ+dwUS06w+aGHHloqc5bNag/j/pBDDunKYikIdeblGcTl4y/GwL777tvVwRKY1phu9VPYgP+p64ADDujaUPVP31IR8j3++ONL6Wn7xz/+8Sl/E7/77rt39mqeG264YamOsONrX/vasqV1pHnOc54zVb+ZZlRhzYk9X2gZnPlCGhfQLBxCNIaoie180Y6LcxYAIYb4vxLWF1544VIdKmJjm6CiIZfB/9kO8nFQ8zdESt6X61BUiEU7VUTFdqt8FX9xUYj4WXZE3fRVti23s2WbCqkKbWfup4rwe/QDf/OYqdKEfZoOH+S4SJeFqBL2kZabgLAbwpfkjwtw7NN2sj9vh82VX9XuWceNtl9tzzb19VHU33dsRZu1nMibx18cz2FXHqOcvCu7EbW5bYin1jFGfi4w5G9dIPvoE9ZxzLCPumJda6TFLuwMIRrCqc8WyqW9IXqxn/NQCD/yZ3GIwAz/5TRRb9hF0LhsawjYiMvCSONy/S2bYo1stinaRRxpiFMRlIl+jTTYjS9CWFNH9i/pcx3Ye8EFF0zZmu3qE9a6nf2G0Mm+jTIrHyHsws6WP7QuXSeN4Mxl0P7WOKqEtdY3xP+tGetZZYUPsvAPH/QJ1RC2ISRDaIbw1PQhKqOd5B8qrGNchWDVuombtU5axfNJJ520VKbu07JClOLHLKxjTEc6ZouH+CAL66pc+idEv5ahbadMjptsg85Yh3COMslz2223LbU57MDPkWbPPffs8pDG4no2owprRcVH68KfBVFLDGlZWVTkC7raUNUR6bMo0TSVKMiQV+tTGzPE5dnbqEvjwibiKCsLjqqNpA+bh9hRoW2t+qBVv5L7BfpsqfqB9NqeIfapf1v2KLE/bMllUhZLQNiX+wZyu9S+nD/3YWV3hfqsKp+yWjcCrT5q1Z/ry32SLwZ9IjXic/1sI5Y0T/ZJ1a4M+xclrLEzz97GrC+Cg3p5pI2NQ3wAiBbyqzCYlTfHq0ALu7JAVVt1O9KoUI243O6hNmVBy/4QpVmAZipxllExNySP1qm+0u2YMc1lZbEZ5dHOLFiyj+h/7Q8tZ0hd4c9KGCktYZ39omm0DK0/8g0pK886R1nqW60LVEir4NP0KtbnEdZqX9icZ3URh2Gz1q+iXm3LwrpVjra3EsCzfNAS1jm9ptEyVCTr/kpY0z7ansvL7aG/seO4445blubII49cSlPVZZ5ldGFNh+WQBYIKhiDHqxgJNJ6BD/zfEhTszyEEWys925GmEi5B5K9C1b7KRmyj3fwlToWdtlfzB9kPQcvPmRBZObTq7qs/UwmlKi6gLLWTdNEHrTIq+6r2RFD/ZLL/tO7om7A1l6NjthoraqduZ/qOG21/1N8KrT5q1Z/jq37WsZnJPst5OYnHzLCGuLlu+S0gnhM5dbQu6H0MEY4Rl8UpdnGRrILmy/lpuy61gBBxVTtyPupVAaMiuoprCWu1J8etxqbIG/2c8wIXZm5Msj1avoq+SljnmfcIUaeKvbwd9lUh/NRqQ/YRdpImZpor+4fUFeNJb5AqVOhqO6s0WobaGPmGlIWQrcIs27MA7ouDEKF6YzVUWGu7Z9ms9YcNzDDTRzqjnIU16VSYRn4V1nk72jSvsFaRrGm0jLCXtuTlHIEK65idrkL4gnGidkBln6kZTVjHxT8LExV4uh2oSJl18Wc7CyIVA6ThoMpCiH2VAMh15DR9F/0+odFHlP/Rj360+0vZIUxY95rr0/a2bM5+CFp+znnykwMVblp3X/0Z9rVCHhetOkDF7VD7+vqrDx1HzFBTFuVEH7GPti1CWA85brT9kUb9NIuqfo2v+rlvvGc7cl5O4ghYFS5ab+W3gPjtJayxK4vZWVhYP8sYwjrWV8e21qkisRLWrdnvvjasVFj31ZXzIYD6RKoKXW1nlUbLiLrUx0PKQqT2lVsRM+FV0La2xOZqhbXGDYXZbhXYG01Y53SELLBbwrplE1R29MWbaUYT1ioGqjjdDrK4aV38OXCykFBBlMWAptU4TV+lqcRMphK0s4gLNmtqI28IuBwXabMfWjZXdrT8HPVpuzRO6+6rf8h+ys1CflZatZ18eQlDZZ+2YSjqP/KzjW3ZPv7XdGGn2pfT5HZXdlft1biqbVVZs2jlGXJsVGJU43NetkOk5OMwU7VL928PYb2SehEX5Fdh0FenxlfCR0V0FbcSYa11z2NTS5QGKpJ1fyX6ch7s0/K1TrVLt7Mg0/qr8iJehbXOrEaa7O9ZdWVUyM7ar+2q0mgZUPl4SFmxHlyFZB+tPCEs88uRLV9VIjTEYqRvCetW/UPRulVY6xKPqHM9CetA7VBhTRpdQ65UdkCUFS9Aaj7zLKMJa71ox0UzCwQuVIR8sY24LJoQIzlfxOWLPQMjhI6KARUmkX+WeMgCI7ZVEMaLVWp31JNfClSi3pwvx2V71J+Q29wXp+2vbFBfah9o3VW+TJWnlZf6sp8zMW4ibeWzVl2Uq+3WFwMV9R95ufmhzlwO9uR06mOtO9oxS1hrXHXcqP9ynPoxv7SrUMesY6uqq0oH+ECPj8jLiTfniRMx9cYLfWwjUrSMOMZAxU+UOUT0DhGOEadilTR5G04++eSufi0vl5vz5LbGrF5uC3XSlpY4rOyq4lYqrFs2ZTFZ2VT1ixL9GvnIk19eVNGnYlz7KGawo061S7djdjiLe9JwPgh7qjZUs/qxHfXgn+zvWXWdf/75S2lVyKrfdL+2q0qjZUT9mq+K07KifVkM0ze8EFfV1RK7QRa9+FbFZwbRHWnZH7PJjIM+YY0QnNfm/IKfCuAsPKPObFfrJUNtm5Zb2bFaYU0ezkuxT+3Q7Ujz1FNPdWuoo55cjraPNBHXssMsZzRhDQz4CHRKfG4sLuIhRvJnoQgqTiMNJ+YI+YIOWRBVYiDEIoF98YmeuGBr+rBfhUpuk9oR4jpCbmsL8ms64rK4ABVcERc+CTtUGIKKPiWXQ4h+6hOuLZ8FfWIZot3nnXde8tizIbc/+zVE1Cz7sh05qG+Uyn/YOiuu8nGuO+zNdrbsnnXcRH0Rwg/RJzm0+ifX33ds9fWzjhu1UYV1lUfHOYRoipDzI1oi0O4ob9HCOtLloHkqNE+2M0RLBK2vEj6VXRq3UmHdZ1O2WW1qiVKl1a9DhHVsR4jzd5Shdul2+CV/7i+3rdWG7CPiQ3hGYN/xxx8/ZX9fXQjGHLIAVCqhq+3SNFpGEPWGLRw7Q8rSMZFvkLSOar10Jsr65S9/uew8kEMIzxCiEfBTnJ/7hDWEuI4QNmu6aHMsm4iQxa/O6Gp6xsAJJ5wwU8CulbDOn82jr7MN2XbsjtnmENeaL0Q0dvBJwezTlg1mmlGF9SwqMaK0xIcxG431NpYXbU8I63yjbMxmo7oxMFuLSkhvFiqBb+bDwtqYBcHMSt8s/lqz6GMrlrFYWJvNDDPBMYuq+8zWQGe1NxMW1qvHwtqYEbjyyiuXjdlYurGeROaij631diNhzGrgMTpLe3SJTd/SCLO5YAxwI5Vnpln7Xb3QuFmwsF49FtbGjEBeJx1hPYlqWNSxFeuKZx3bxmw0dH20RfXWI/+ceYyBzSw6LaxXz5oKa2OMMcYYYzYrFtbGGGOMMcaMgIW1McYYY4wxI2BhbYwxxhhjzAhYWBtjjDHGGDMCFtbGGGOMMcaMgIW1McYYY4wxI2BhbYwxxhhjzAhYWBtjjDHGGDMCFtbGGGOMMcaMgIW1McYYY4wxI2BhbYwxxhhjzAiMKqyvv/76yZ133jnZZZddpvathGOOOWbyyCOPTPbee++pffOAPdh1zjnnTO0zxhhjjDFmDCysjTHGGGOMGYFRhfXYWFgbY4wxxpiNgoW1McYYY4wxIzCqsGYpCOg2gjZCJZQR0DnEchIV1pSTy4eDDjqoS8PfHPfkk08ulXfRRReVwpqyIpA+yqA+ytT0xhhjjDHGtFi4sCaEQI2Z45yGfVnUkgYhvFJhHaKavC07KltJH3ZYWBtjjDHGmHlZuLDWlxmzWA4Bm0VwZiXCWm0AXQpC2vvvv3/ZzLmmMcYYY4wxZh4WLqxV5GaxXAncVlq2ZwnrEMcq1FU069KTHCysjTHGGGPMStiywlpn0o0xxhhjjFkN21VYr2QpiArivDa6WsMNumZal48YY4wxxhizWrarsGZ7npcX9cXEEMw5fyzzyGIdG/IyjxDgKtIvvPDCZYLfy0KMMcYYY8xQtruwBgRstc55VtqY7dbZ5xDXEY4//vipFxNDXOcQ+y2sjTHGGGPMvIwqrI0xxhhjjNmqWFgbY4wxxhgzAhbWxhhjjDHGjICFtTHGGGOMMSNgYW2MMcYYY8wIWFgbY4wxxhgzAhbWxhhjjDHGjICFtTHGGGOMMSNgYW2MMcYYY8wIWFgbY4wxxhgzAhbWxhhjjDHGjICFtTHGGGOMMSNgYW2MMcYYY8wIWFgbY4wxxhgzAhbWxhhjjDHGjICFtTHGGGOMMSNgYW2MMcYYY8wIWFgbY4wxxhgzAhbWxhhjjDHGjICFtTHGGGOMMSNgYW2MMcYYY8wIWFgbY4wxxhgzAhbWxhhjjDHGjICFtTHGGGOMMSNgYW2MMcYYY8wIWFgbY4wxxhgzAhbWxhhjjDHGjICFtTHGGGOMMSNgYW2MMcYYY8wIWFgbY4wxxhgzAhbWxhhjjDHGjICFtTHGGGOMMSNgYb1g3vjGN05uvPHGyR//+MfJQw89NHn7298+ee5znzs5+uijJ4888siEcOaZZ3Y89dRTk+9973tTZSi77LLL5I477pg8/PDDk/e+971T+7cyxx577OQPf/jD5LzzzpvaNw9jlWMWw957792N/zvvvHOy6667Tu1fBIuoM84D++yzz9S+zUqcv84555zJDjvsMLV/pRx44IFd/xx88MGjlUuZTzzxRHc+GKvMeVhEm9aao446qmvDvvvu27WBbXy6kdvUItp2yCGHTHbcccep/RUHHHBApw3mydNCfa3752HnnXee3HbbbZNzzz13stNOO03tN222hLC+/vrrJ08++eTkoIMOmtq3SF74whdOrrnmmsnTTz89ue666yannXba5E1velNnB/ZwQT3jjDO6i+vPfvazLu6YY46ZKkfhwvSb3/xm8sADD0ze+c53Tu3fyuA//Ig/dd88jFWOWQyLELmzmKfOEI+tEGKacWZhPZ1mJSxChFpYrx4VexbWy7Gw3nxYWC+Q3XfffXL33XdP7rvvvskb3vCGpfjvfOc73cX1hBNOmMqzveEgv/feey0oNxBD++z1r3/95Nprr53ccsstnbjR/euBl770pZMLL7xwcs8993RCVvcH84jcsVhNndxYcx7Si51nrFd38c9sdBG61157dfZnEb/R2wRjir3NyBBhjci9/fbbZ4rcMX1tYb1yLKwXCBdiLppciLOQ4YJCGDI7vdZgEwEbdZ9Znwzts9Z4XE+E6JolNlcjclfKauq0sH4WC+saC+utiYX15mNdC+tvfOMb3UUH+F/3D0WFdRYYXNh++9vfdsKEvwzyyHfooYd2M2cs5QAGGbN+LYGS6wmxkwP5yZNDpK/E9mte85rJ5Zdf3j1aIvD3Rz/6UVcn5WBDntX75Cc/Obnrrrs6W1nTfdNNN3Un66Ftxn4NLbEW9n7/+9+fXHLJJV191JvrhJe//OWTs88+e/L444936bGBPKwzz+VccMEFnS3qD9rLGnXKZh/biBDqibhTTjllqTwVma9+9as7+6J+/lL/rH1aDrzrXe/qlvaw9jrSk59y2J/75bDDDlsaO4899tjkyCOPXCqnr94Kxn4ehw8++GBXPvuG9lk1HmP8Pv/5z58cf/zxnd0E7GHN/4tf/OJleVlvTjw+xw765bWvfe0gO4FxQKAuxjVjBi6++OKurlgilUNLdFYil7F21llnTY215z3veZOTTjqpizv//POXLjiMGWbw6c8vfOELXfwnPvGJqWMojjGtM7aHCMRZwjqWHkXQpQexJCFCVVYQwpUycxr8n/2lZeoNQ/RXhGwTdtN2jr0qb0brueiii7r06jd8FAFfZDEZ/qNN9E2VphKhIVarclsCPwtcxmQuM9rNvtymWf2V21yJJ8qNduUyo37+z+1A7ORytJ3RH60xAoz9HCpBf/jhhy9b0kQf5HopgzjytvpFxZ5uYzvCMgLHQxaGkb7yufoglxN2RJpYllntU7gmUuepp566VGfYlfuqZWuO45yZ66VM0oSQDmFd9TGClv1xTtN9andVf2434bjjjpvpN2xj/Kiwvvrqq7uyKKOq32xj3QprLtIaViquW8KaCyrrlBnov/rVr7oBwyN1xAIi9fe//30nDn7605923HrrrV3eIcKagc3FnAMCwciyj29961ud0ECQEBBXDFBecFRhzdppbMMmLu7kR4xwIauE9ec+97muLpadkDYEECdF0g9p8+c///nOJgI2fve73+2EhvoTwt7f/e53XTk//vGPu7ooDz8hchBLIUS5sPzgBz/o1oYjWDiJ5HKw/Ytf/OJU+diM8CI/5dAm/Em50cYQRuTLghjhFALuyiuv7NrDX5ZM9O3TctjmJVHaSl2kw8fRXmyhrdEvlMnJDftIyzbteP/73z+z3gpOZtSB/6LNUd7QPqvGI2Px//g//o9OQPHiLHWQHxHDNnVlX3A83HzzzZOTTz65Oy4ICNWo46qrrmrayf4Qao8++miXjvcL+B8f/vCHP+yOA/JiH3ZiLzckjCVtj4pc/I+fWmMNG3L68AkXFC4er3jFK3qPoSykxxbWhGwXfso3FCoYQxBW5cEQYR22RxrysAQn21CJ8BBfIS5aNgSaj7gQ0Nlv6h/Kz+twI09Og41ZxKmfou5cT9gd9mg7Iw3l4P9KWJM/C9fcX7ne3OYQsSqIM60Za8rK5atvqnzU1yeuKZdrSdiiZUa92b9RTxbX0a4cx81tLkvFnm5znGchHrbvtttuS+nD5xFHHbkMxCd1Zv9GuWxzvsHGEIN5nXfVHyFmo06OD2aM41jNcVputotzSN4OERviNYQ1dWWRrmu1VzpjTdmcr7XdWncuF62DX1RY57ZUPjPPsm6FNYNMA3GabggtYc1F/cMf/nAXF6II8YAw4YLOwXzZZZd1M3qk4S/CaIiwzvVoOhXRVRyChfo5acdsbKDCmpckEbcIEr46EulCjH75y18e1GbiVFC2CHt/+ctfLtmHAOJAjPIQu9TPS5uR74Mf/GBnw69//evO7igHW6vyEY1RPmkItJW8OR0nD7X/la98ZScwmDHOYpO8ffu0HLajP/K6+Ghv9Hn4kzZ/5Stf6dJgewjVr3/96zPrrdB9+CHKq2xtUY1HBCdxuR95HwBxGe8GRPnc4MUsdswuI15ZF13ZiVDLdoawJp5ZZOJipoubCy4EIQqzsKxQkZvHWlygGWuUw1jj6Q83HtFXpInZT/K86EUv6vZzDO25557L2pCPoVyn2tSHCscAQZPFC3Eqesmr4j1muisfDRHWKhhzfi7+9L3uy21QIaY2VHnUvmgTIo76QjhWaShH/a5pVFjHbKqKgBxftZX9rTKrdquwrepFGIWtak+g5RBXiXQtC5Gp9andWpeidVf1Qgi36CsVwWEfIjDsU7Gn22qL7q9EcAjUmLUOn1eiE/FIH+f61MYqT/gv9qsobdka2xzH2cZcdl76EeI2p1Mhrdtqb6D26H71m95wZPJSEPykbTdttrSwVsGb0/H1Dh5rR71clLg4D83fly7EYEtYI1QQLAhQxIG2R4U1Yjo/ytFAmS1b1OahIq1qA/z85z/vxAo3JtzhtkLY0Sqnio+4LG7VXt1m6UgsOcCnzPCGgOzbVwl0/KdfYcl2ar9UaWbVW7Hffvt1N3j3339/d9MSIcrTNreoxkDcQFYh2lGVX5U1y84Q1rlPQ6CH+FqpsJ411kjDEyOEPkIaYc/FmHo+8IEPdMcQTyRaIY6hXKfa1EclMKESyFlYhz+qoPmCIcI6bCKoXSGqqpCFdRZYakOfHSqIq2UQESJNy385PovJqEOFIVAf+8IPWUir0FaBWrU7i1LKrOpVMay+0nIir9ZflYX9VdAbNqXq5yystd7KnuomAnK8ij3dJj03B3kMMLb70meBiM8RnSpgA/K3xlfrCUJLWKsdGpe3ObepoI+yVVjrGmsV0rqt9ua2qo3VUhKelMeMdMtvIax5wp1n2DWdmWbdCuu1WAoyS2QyO8dFgYODA5MLL0sChuZvpVOhpXFZoKmQAxVwUQ83AsxGR1yAUG/ZojZXIqqiagMw8xgzfJEGIak27bHHHp2YbJVTxVdxaq9uw3ve855O8NFOfQrQ2pfLGVtY99Wby4Y4KcaSJJYrMIuay6vaXFGNgchLmdpHb3vb27qnNFX5WtYQOxcprIeMNcQz9nGx4DjhYsZMPSI7yuMY+shHPjJVRhxDuU61qY+WMBwqrPlf87Zo5VFhndMSskDVGWSlEphKy45KWKtdSst/YwjrvM3/WSiqkKzavR6EdV+5FeTJwlvrruqt7FmtsGascxzS/3npRyt99vk8whp/5Vn1WWwWYc2MdJ5pVr8NEdacnxgrXlc9nHUrrGEtXl5siUxEdSwB4aLMelACSw7iM3p5RjlE1ZB6KqGlcQhUXXoQqICLGW7qZvZT0/fZor6pRFRF2It4CkHILD8nEuphiQFLAJgh5OIXSwgUbXdffBWn9uZt7Prrv/7rpbRcDHnUj7ji/9a+t7zlLVPl0h+0Jb9kSJtYc4yg3H///af6pbK7zybqjfgqL9uxtCTHqa0tqjHAchRml3lhL7+ImKnK17IqO7m45rhFCus81l7ykpdMpQ8Yr7T3F7/4RffEgFls6uUY4t2AOIaqC7DWqfv7aAnDWcKa9K28LVS4Zhtatmc7on4Vh5qeNEOEtdoeIi7sU7Gm5UDlg1licIjoCzs5jslHPeF39mmZVbsrYa315jarPZpmXmHNbG/0a8t/s+rRuKpeiLpCpKovo6y83EDFXt4Ofw4Vq9neeZaCRFtavleqPJUdGqfCWpd4RB5d57wIYR03Lbl+9dvQpSCk5/xqcT2MdS2sx0LFo4qCKl3MYiBsgcfbXIh54QvRwEwXgTTM0PGXgTekHhUhVVy8PIm4vuGGGzobeDmr9fIiAx/7OJD5egMvobE++dJLL+21RX3DTDMzzqTl8TovgUXaTNgbL/PhA3xECLEdF1baEL4kHWteP/vZz5bt1vL7fAQq+vJ2XDDDH7wEiY+Ie9/73tfch8jSchGg3Ejpy4v0OTPP0V7tF7W7z6ZYq5zhRo6A8KUvOBGyPjv7YWifxdpp6qNe0iIQGFcE+o/+oW2sp/7mN7855dMoS8fTEDuHCGvWaccXXxA55MnvDeT6uYCEoMAGLjx9Yw0QzeErXtp93etet7QPu1rHELZpnbGtAraiEoYwRFiThnap4OJcoOUF+kJdlBG24/ecP9tBHPbmbdLQx+SL8rCxT1hHuWp73BiG3+I8oaKfLwVle3KeKCfbqGIwljrkPNija6TDXxzX2JDbpGVW7VZRWrU5bjJbSw9ABXNVf5Uu2pnLxib8V9Wl+bN9WVhTpvpX66naRRz5KrGp24yn3L4Qfn35o31ZICJO1bZ4eTFmtPMNAft5b6Y1fscQ1mxzHsxtCbs5580jrInrE8FBrj/OiVoGYzO+DBJPGnOa1suLLBu0uB6GhXVDZAIziQxC4H9+2CVmZzlA8iffECm8VDeknkogVnEf+9jHlr5sQD0cMMzMVQIOuxj42WbS87WOPlvUN8zChtiDyK+EvVxssx+4QOWvOPClh/haA4G/iMiwu2p3K76KU9GXtxGqiKJcNycW+q5vn5YTdeX+IOBP1uvGbHzVL2r3rHoVPs3H/ugP+gbRF+WRZmifAWMEwUt/MV6xh/7iIhPr8CiDJzJ9L7TqeBpi5xBhTRwn+/gcJEsz3vzmN0+1Q0UucYw1vkzSGmsQIi7aky+qHEPMYFfHEOm0zrUS1pEOeyJoHiW3k0Dd2JmFdV5fqyI6bM4h218JzBZqOzc92JH9pvYS8v7wH0RQmysRGmKwlSeoRHhVZtVuFdaz2lyJ3SDnozwVnqSphLG2k2NKbx4ymj4+Aacz1vlzcwS9MUBEV/0yj/jM66vJG7a00lOmCmviQlxHyEI6hGoO2pbMWMKaNCFmCbQPm0kzr7AOERy2V+JW6895CLmfs99yGvzGU3mOSf3cXnw6kMm+5zznOVP1m21sCWFtxqcSucYYswhaNyZjoQJa96+WSgyvZ4b6I4T1RmjTeqES0mZzYWFtVoSFtTFmrVi0sM4vdi6ijqFCdb0w1F4L6/lh1pebrHlepjQbCwtrsyIsrI0xa8UihXW1lGM1sJwjz0xH+RtJgFpYjwPv3+hyEpZS5KUYZvNhYW1WhIW1MWatWJSwRhgSdG31atD1y4SNJj4trMch1iTnYFG9+bGwNsYYY4wxZgQsrI0xxhhjjBkBC2tjjDHGGGNGwMLaGGOMMcaYEbCwNsYYY4wxZgQsrI0xxhhjjBkBC2tjjDHGGGNGwMLaGGOMMcaYEbCwNsYYY4wxZgQsrI0xxhhjjBkBC2tjjDHGGGNGwMLaGGOMMcaYEbCw3mDssssukzvvvHNyzjnnTO1bFMccc8zkkUcemey9995T+9YrBx100OTJJ5/sbNd983D99dd3/sbvum+rEGMOX+ywww5T+1fLRhxfLa677rrOV7vuuuvUvs3K0UcfPXn44Ycn++yzTzc+2H7iiScmBx988ELGC6wHPx944IFdO4899tiFtbOPtfDzmFx77bUTAv222267bQibjVkJFtYbDAvrYVhYj4eF9XDWg+BbayysVyesQ3D2lRN1cQzuuOOOXdxa+HkszjrrrBUJ6r322mvy0EMPdf7JIfthe0Pb7rjjjqW2HXDAAZPHH39cTe7Ocfvuu+9c7Tcbky0hrNf7hXse+yyszWZj1vhizHPhYsxvpovS2Wefvd3F4RiosNb9q2Gz9n0GYf3AAw/0ikXE29NPP92bZj1DG7PtO++88+T222/v+rWvPSGsuenoS9fH0LpWSiWssfmQQw5ZVt+ZZ57Z9eG555472WmnnabKMZsHC+t1wDz2WVibzcas8bVZxZWF9Ww2a99nEJ2Mf6hmnxGX99133+SWW26xsC7SzGJoXStlqLCGo446qnvKUO0zm4dNL6w5mPVxTFzA+ct2hPzIPwvYXIYuC4glB6395AXKiZBt6LOvoiWscznYg125/llltPLDLOFDWvYfdthhXbkRtN6h9Zxyyindfsrab7/9ur8XXXTRsrJJq/2Xl32ETbl89XWkD39EmOW/3JcE3R/t4G8eG9m+vjqVaAt+IV3uC7Ul1xF5sw3hx+h7yrn//vun6uZRO+3iQqHjJbZzn0S9Wl+UoWVHiHa1xpeWR8giC1GXA/b0CdUQamo75cXj9ghqO/YhIPP+INJlv1X2sQ/7sCGHbDeCO4e8RAAbsSGPBQSttrMqJ/styjn88MOnjtnc5mgPPmK2jUC9WQCqsNbtSBP5CX3tDTu1P/I+9fOsOrKd+DOXm/2LCMt9o23NhA9jf2xTXh4nzFD2iagQnVCJP+yOMUua2D+Pn8O2U089tWt7jJvoL82jSzZiuUqELHQRv7m92WfVUo5bb7116phu+WiWsEbE9vmc/TqGYt8111yz5PeYSSY+ng5oeq07mEdYh8j3rPXmZtMLa6iEYYiyLEQ4wDipcPHNwifSRJ4sSC+88MKlciMP5eQyCSpKcprKvhYqcqIOLS+EWlW2xvXlr9IrIX5ynvCV+mJWPYScJtqb04WY1Lhsowpr9kffRl3Rr2oXoqUlrPk/1xP2admEHKf2abm5TiX8m8uLMnNcpIt26XbUm8fjaoR19n/Ul32ex3pcpGNtrNrcN75IW81aIsjUBsrvE5tRVuSL8hAeYXu0mXRhe4jqbEMIQm1fbKvwogzOFzk/vsjiT+NCXNKHUSbbmk9BkFxwwQXL2pfXA8e2iiDs1fZoG8PvkU8Fnm5renyLH7Afn/TZ2ep7FdZaB3ExE6wCMvuOfDmNzqyefPLJy8ZJRvs3bNc6Z62DjjpJw8x0Fsoh9PEHPsi2qZ8ReLku8oafddxE+Zqn8puuj2bWlfGIHVFuFp/sx89ZDKtfh84iDxHW4fNYvxyzwrSJPK26ENZqZxw3IXpjvXSrfphHWEe9+MLCevOyZYV1nKRyuiwMsijIaVTMKLqf/Jpe7dHtPlTkYCvCKOfNaULgqriKds3Kz/Ys+yoBp/mG1qNCSdNAtKmKy6Iy+pLt3OZMVX5GfZXLDDS+ake2b1adSuVfyqsEcba3arPW3SpniLCO/TkPaXKcjoHKf7PGVyWuSIuoCMEZaVvxWtYQ2xEu2IXAiONaxawKvLyd86sdoCIa2xFWKsJUrGehrWW2UB+qgI10KtbiRii3W8vSPHk7+kPraaFl63akyz6JGwKtQ+MrkZvTxJMEratFS1hnO0IYU2YlsiBEZ9Sf81PmzTff3O1jvJCuEtaz/FzZpv6JtBqvoriyXfdpvG63xK5SzXgTQuiGsM7CV8vW7SgbgcvY1tn5TJ5hbtk5r7BmrTW+sLDevGxZYc3ArkIIIhUTQVxg2d8qK+9nH/TZo9sRV5Wpdmm6HCINf8MGFVJD8lf2ZVqCKcevtB5tb7QhRGorTm0KcaqCN+olaN2Q+4902vfZxqi7aofa11enom2JONpSBexVm9TW8KeOh2CIsM59EnFViDa2/Ff5S21WwYO9eqOWbc9pZ5UVcVXALoRLq8w+YZ3LrfKqsA7xU4UoU8Wcti+jj+gJYUerHI3X9gV6A9ES1vSTzsIqfXZW/aX1Y3OrDgRd5FU7c91ZfDOLGf2u5WXUV7pNmnmENfupn/Qxqxz2sw8BF+nIN4+fK9uG+I26YlzqE4EQndVsLrPGWWyuVlhXdUAsBYnZ6aps3Y68rZnjSsyPKaxb9ZrNw5YW1lkYKJV4ALZDHIS4CeGl+6OevB/UHt3uQ+1qiZVMFiGaXrcrZtlXCT+NX2k92l5QkVrFtWwKQVsJbOogZBty/7XaEDZG3VU71L6+OpWqLX3CEtQmjQ9/kn9MYa31ZVr+q/yVIb2Kq772t0Rwq6yIw44qT1+ZKjx1G7AxhGMuoxLWIXS0/qASSBWxTCUEo7a7VY7GV+2BsYT1LDt1u6p/iEBUuyKdCuts1yyBrb7SbdLMK6xJzww1ZTBuyBv1by9hHXGxxCMENuN2swnrWF8d9Y09Y913M2I2D1tWWHOQVRf5oBIPmq8qQ+MWLawr0aVk0YMtuU1D8s+yr1VG9kUrzax6tL1QiVSN66uvKrNVTu6/VpkaX7VDy+2rU9Hyh+SJNurYi3zR9qqcnDfETfaXbgctERZQR3VDE+tcW+OrElek5YKqYrgV31cWzLKd/VkE57Jyvr5yVEjr9izboRJIStVGjWuVozZV7VExqoJ16BIFtamK0+3Im+1Se4baWaXJ9vXtA/WhbpNmXmHNNnbGeTrn6xPWfX6ubCWu1b5WPKhIVdtbbdJtLUftzbaslbCuRHQVp8wjrFkGktNqWWZzsCWEdSVM+J+LfBYHnJx42YP/W+KB7RCLKqCizHmFdWVfC7UrtnOdkF+qjDojXY4fkl/tVaLd2qbs35XWo+0F9qsY1Dj1afWSKWXyP2/bh01ajvYf/2cbo6ycpmpHLndWnYq2pWUL5JcgKY+QyyVPzJzmuNwv7CMQH+KmGnN6bFT1YQs25XJyXdXYqagEXrywlv1SCeAM9VZCDZEStkc8YiRsj8fhOV/Mtma7dCY3l6eilf20O89Qk1/j8gt0lUCqUH+FrWF/tCfqarWRcnI+tTHamQWrbkc/hc30QbxUN8vOqi1VnNZBHGJO/d0nrEkXdrG/T2CC9oVuk2Ylwpp6mUnG9mxrn7Amjb6ISN355UW1LcrUdefhtxB/559//lIdKlJjzOjLi1WZ2fZWnDKGsCZORfTQuJjBXq2wDps4bvKPxCC0sd8/HLO52BLCGjhYCPkCHhf1CPki3RIPbGdhEOUSiI/PeOX9kMuohFdlX0VlV8TloHaHeFNbhuSv7M2E8ItPgFVlrLSeqr2VENU4FaO5n3K9lU0qRNVnrbKCqh0qrPvqVLQtfbaorSF2Ixx//PFNf0ZgX7Sbk732gW731ad+0LbzPzZpOiUfq9QbF6EQYhHCZs2f66+ENYS4joBNWeCGiIigfiKNCuscaGs14637QsxGyOW3BJISojBC/swi+aKc6pjN5UZ78jgLv0Q6FXi6TRrtp6hnlp3q94hXYV3Vwf4shiq7VFhHf0RoieqwaxHCGlREV3FVe0IIRghBWNmWy815tF7sy0FFph4XjA8VilUbcz4tMwhhrSHq4LwwRFjnz+7p5/aysNb6Lr744m48tuyDSlhXv7xYfWLPwnpzsmWEtVkcfcLPrC/6RLGZn0rgbQT6hFZmo7bPGGO2FxbWZtVYWG8cLKzHgxl2xGle7rFRsLA2xpjFYGFtVo2F9cbBwnplIESvvPLKJYEZyzh0ecdGwcLaGGMWg4W1WTUW1hsHC+uVEbPTOWxUUQ0W1sYYsxgsrI0xxhhjjBkBC2tjjDHGGGNGwMLaGGOMMcaYEbCwNsYYY4wxZgQ2vbD+P/+XbxhjjDHGGDOTP9lh+Q/5zIuFtTHGGGOMMRbWs1GHGWOMMcYYU2FhPQN1mDHGGGOMMRUW1jNQhxljjDHGGFNhYT0DdZgxxhhjjDEVFtYzUIcZY4wxxhhTYWE9A3WYMcYYY4wxFRbWM1CHLZqX7nnK5La7H5387pEnJ3t/5ryp/RuFN3/snMlDjz45uePex7o26f4xWIs6zHicesEdk6eeenpyzE9/NbVvKG/7xM8nDz70+OTOex+b/Ld3nDq132wuOK5vv+exyTW//u3k3/35N6f2j8ERx98wefyJpyafOuLyyb/78+n925Mjjr++uxbssd+5nW1sj2XrVb96sPPrf/cXbb9+8vDLu/rHqG8t+NoPwz9XTP67BY2XRfPLG7f1y3//Xxdj/ycOu2zy20eemHwaH/X0/Vblb95+8uQ3dz3a9cH/8MJvTe0fgoX1DHASDs7h6acnk4cffXJy8dX3duJOnboauJDccucjk/t/+3gnInT/mPxPr/hOd6K+677HJn986umubfyl/le+87Sp9PMwhuglH/mr8PUTbhiljtXw4jefOLn5jocnt9/z6OTv3nFqZ5OGx5/4Y5fm37555eT/8ldHT5Uxqw/6fHDUib+aXHLNfZPfPvTEhrgJO/m82ydPPPlU5yfdNxSOCY4N/POy7dDns7j6puXnCsbnHvuNe47YSlhYb3xhfdoFd3TXTA2z6l4Jaymsf/mrByfarG/86MZVt2kMYU0Z6nPORf/0r+dOPvm1y7ebsEbU//7xP06++aMbu/Pigw8/sdzIyaS7Rnz6623boowcmGh5xT6ndueIK298oGz7T87+TXc9pu7/vlE2WFivATgJBzPTdtNtD01+eeMD3TYnGzrvD398anLkT26ccux6ByF4428e6gYdQg5xSNt+ffvDk3seeGzVNwxjiN4QlU/+4anJdTf/trMv+Phhl41Sx2o48ZxtB+r+X7u82w5hfe8Dv1+y854Hft/5l7Fy5Q0PTP6fu/9wKf+QPpjlg3/40FmTB373eCewK+G+aLjQUz8XNN23Wmgf/jvlvNsn/67Yv55YLgCfjf/5ZXev+lgy44GI3iZUz1mxUFxLVFjr/tWwlsKac9jL90L4bIv7m7efMrntnkc7EbWt7LYN641PHH7Z5PdP/HHys4vvXOY7zoFnXHRnr2gbwljCulXG9pqxps9/c/ejnd+w6x8/enYnrFXoHv7D6ydPPf305Nqbfzv5H/7rcmGLaP7do09O3vKv5y7dOCGEucnhpoE40nSiWPJG2bQ9518EFtYzwEl0EieAEFCAiPnq96/tDrBHHvvD5N0HXjDl3PUKtiPECIg17vQ0zWoZQ/SGqKScSpyMUcdKCUF7+XX3LwnaENacXHPat33y590dNeL6e6fd3MUN7YNZPoCTfn5bNw4/8qVLpvYtGtpKWM0sdIvsz/UurJkFuu/B33t2ep1jYf0s21NYB9jQ2rceedNHz5n89uEnJt/40Q29flsNfaJ4KH1lbC9hTb333P/YkqhtCetIGzPbse+U8+/oJi9esfe2mWktP+gT1jEbjbj/HwrfjMWmFtbf+MY3Jo888kgH/+v+IeCkSlgHiBoCjxkiDiF1w62/W5qpRFS995ALJy/6x590j7CZfTzgW79cSv+Wj5/bnbyYnfvwly4uhRRlXn/L77oZcsKjv//D5HPHXN3tY0nCGRfe2YkrAstUjj3ppuYM5ge/cPHkscf/0NnFrKnuz1D2yb+4rSuTEMsUaE+koZ6v/fC67oRDoC3fP/3mKdE7r52zRGUlrFlawRpe1uHie7j7/t9PDj76qm4/fUhfImaj3kOOvqrz669ue2jyn3f5QRf33VN/3T2l+PL3rpmqF4gnz2E/uG4priWsAdFLu/Ed42BoH8zyAbzzsxd0N3dVvUHYdsX19y+J/BDDH/rixUtx9C9jlwsI+/ARS07Cn+xn5n2ffzu/s0sDZbbqqkQ4NxTcYDDzT+AvY4djTgP5c5/HUpC+Pg9BfsQzNp1z6d3dhZ4xQDrGQV6rfdDRV3V5o5xb73pk8qp3nbY0brC9EgAI6779AfZzfEToZuy+dvmSnZ2QefTJ7mkI+wixnISy4wlntcSEvDwGj6Cz5xUIzfzUtPPrXs/epIawCnuiXuw9/cJt/UlgH2nYn0VYTkPobpKe2Rdlf+OEG7o2L0+z7aIXTwKIwy7+rwJCh3LVB7k9V9304LI82a8qthn/U/2U2rVk+4+25Y3ws4vuXDYTpnVus7N9QUdoRsC+n57zm843eSlIFtp1e0/t+qdvX9TFGMH/8ei81U6N03HWJ9D6hPUnD78slb+tDOLifJDL35b2iW6ZR/bh157xyT/td+7SjRP/575ESEbY1sZtS0VCKEfo7OyE23Q7oi23z0gTaNndEgdZovKmj569LA2ztLRXRTHvp0QfERCcfT6fV1jHbHIOIWp1ppn0IYpzXCecH3hsaeZY6z31/DueEbzLy6iENWSBPCttK5/ugyWB/szSEd2v4psnp/QRdedx9LOL72rWsWmFNUJaw0rENU7qE9asBWIfadhmrStrXumIH599awcnSC76rA/99ik3dQdIFkGcbIlDpFdC6l+/elknwhByLAFA9FEfM+YsLSCOfeddcffkuJNv6sQbAohy1V5g6Qoh3wxURNnYxguV1HvZdfd3deV1vYhM6kM4IlwAe8kXoncldla+yKiwRgQi3KmX2cMTzry1swW74DPfuHLy6nef3h38zDa/9gNnduVgDyHHXXXjg90JmpserTfycGOQ18H3CeuX73VKt4462jK0D2b5AP4/bz2pW0YSol33Q9iGv/PNDD7BN/iE/g3RSX9Td/Qt5bP/5F/c3olRLuxfPO6a7n/CBb+8Z3L0T3/V+atV1+kirGO9NP3FkhjKR2Qj0FiTTpkE6qBsbkZUWFM24q2vz6krhDXjkiVd+J3+Jpx72V3dRfLDX7pk8ujjf+jiKQdYH7/Hx86ZKay79j0jIrN4zCC+H3/yqWX7EQLhkyWh9ORTS4IwhCVB47JwDkEeAqhKo2CvCinWiGfxHCJKBTd5c7o3PXPDkMsjjqUwKsgQckttfWK5WNf1zllY60Ww2vfzy+5aEsjZB3Ghr2asNS7syuV2NyBPTwv4Jds70bvc9tMu3CYoQ8wiirf18/TFHBDhlTDeVse0sN52k7Zt9pQy/2bPUya/uPzurp/Iz7gO29jHMZxFcIj4HIfNjL9ogwpr3Y4lHX3iuk9Yh+jtZoD/PMTzs0I7l09+zkv0SxaEOY7lGFlYs2wDkZ6Xbfz4rFu7m1n8p7PPLCloieuoq7t5arQ1yMtFQghi29NPc73bJopDVOc0IaAR2CFYictivpvNfeKPveu55xHWiFbsyKI3ZoxDOCOKn50tfna5Br6KOE2T6wxxjs3R1lliOZfHzdPQJRyzhPWs5SCVsMYXHIdc3/DZ4T+4votD/1W2b1phzSy1BuI03SxwUp+wjgtuCGtOZvpYHsFA4O++nz2/E2RZDF5904NLeVRIMYPKTDUihZlDrZ+Zb2bAEeURFzOYeQY2U80cVkTZiJ68Njhm6SmH8qmHdDGDDvxPXLRzJXaGLzSEb1RYh28Ribu994ylcphVZvYZP+NvRHE3e/D1K5bqAOKYvQ7xjd8ruygDsRf1RnyfsNZ+HdoHs3wQ6Rh/+cZACduyr2NscdP3xo+cvZQW/3ADhC+4KBIQmSGQmSGO/6t2VHWBCutzLrtr203mhXeWTy2yP2OWTYV1q8+/mvr8f/zro5eENWP5+a/ZNpbj2OWG5C/f9JPuqQv2XHTVvZPn/u13pto6hBDPS3anCwyitRK6OX5JIDOLnYRfJ1glLkRdlKH15TS6lCaEsN4oRLyK39iu0kReFV25PlguhOuyVSzrdi6Pvt0mRNvLwE5fErfb0qiIruIQuFmMBzl+yfZnhDb7Q7x2Iu/Pv9ksp6LlO52hztuM3ypPCxX6sQwjz2KHkI02qF3kiX0tG6fq7RHWUV8I66Xyk1jJM9Lc0HVlPSPe8iw2+VVYI5Q7gVmIH+zSfQjiXN6UrZ04nL0MpFVvjlfBvJQmiWLEN8sndNlGn3CO/XmGmxBiXYV1Z0chiLOwZRzk2egrb3ywexeIyYwcR99VNiGi76Yd6aXEWcIaAczxFMI6/tfzgFK9vJjXa8cMdEsUt4T1N39841LblqeZFvAW1jPASX3COpYRMJMbM4etwKDjIs263BDSsQwkRJwKMIQSgolBjeDT+kP4VEGFX8BsHQGhr/uqsvXlzHwzgSBjkDIby6xspFHRuxI7wxf64h4zmXwxQ+sIYXTWJXctK0fTMQuL6MIPzILif5YS8Jc4nhAwy9HyTxbjQ4W1zpQP7YNZPoh01KliO1PZFn3XCuRhyQ9+wa8IcJZpsKQn1xtpq7qyoMvCOpZFcWPFDZba2ypHhXXu81xXN5uX0i0r65mLh6ZBmN913++7dIh1BH9r7fssQmBvEy7PzjKrkAWEXaTrxFIhrLOI1rgouwotYc2F8t5n1oTrvizSVVgt5X1gOm+VNkR4Dn1lq5DW7dz+PDuc7dflF+HbyLdNBNbCOurTm4ZIhxBa6iexXYV1iG99KlCBON1W9rMiN+KzaNXtatY5k5eWPOuLZ4V1lS/H5z7iGEEEV2HbOJtfWOcZa/zaVz5imWOW82jMaIc4jjZkYU1f9gnh6qsehGrJBgydse4T4NjH+EJMx02EirssmmN2ugp5VlvpE94qrElbCeK8tAO/I4KZcWb8MEHxpW9f24132smxU90ABCsR1ouasc62VPVWwlqF+JYV1muxFASRzKM3RBqzoiGCuCgjzmJWNQgRFjOozN4yKJmNjrW6UUaIpBASKlyDEDYIHq3vNe/7WTnbFjcDPObOIkkZIqyz0MkiU+NXYqf6QvdrHUOFddzMIFR5mTC+wIHQY5b1hz+7pVsygOjWOrNd2uZKvAYxgx8vOw7tg1k+CFYirMMvrCnm5Vvtl1hW8v/755M7n4QIj88LRr2EeYV1PlZan5Wsysl9ObawJo4nM6RlTFAuS572WeGnDLvyn5kVDsG2SGFdld1iLYR1LI2JWd2ws6/s5WlqYR3rn1X8hpDthNYzaeedsY76tOxIN4+wfjYfSwCm1y8vL3tlwjrXS8iCeMkXz4iBasZ6JcI6lp5oG1r0CWtmnLeNpWeEcJq91nKCEKS0Y0nAPpN+XmHd9VWxr0VrJjoztrAOcTuPz8cW1jEjTZnM5nOdRPDGjQ1tfXZGedqelQhrBHLY1dn8jLhVnyoW1gtmkS8v8oiYx+OI4liPSjwz14hm1paqs4OYvUTI8aJYfhSvQiq/8JiXWgQx+8pj0bxco4/4/jIn+59ffndT2LXKRmQRuDGIWXpd/hI3DyE+W2X1ob7Q/SqYWy8Efunb2140DFEby1fwOy+n0Wek4yBmRpm7cRXNmcivaSrxCvt95dLuwMRHnzh82xga2gezfBAwRqkjL+nIVLbF2GJss6ZZ88CfvfaEZUtAeHExv9RJeSGWq7pawprtS6+7v2t/fClFqcpRYZ37PL+E+MXU53kpSIi6KCsLa8YlbWQfbT7p57d3eXi6UF0sZqFCcjVLQfqEtZahdlTMsxREBWSINhWf3SzyM+JR285+javKViGt26ThHLKtrcsviiqiq7hZwpq41hIOXQqitreE9ax922yov0+NGN7Wz21hncuIfbFkIgv1IcJ6203Ls+u2tZ1Vnlm0hPWyZSfPlDek/G3LAh7rzuuI8vyi4rxLQaqlGH3Ed7KrGe1Mq94cX63nDlHepXlmKYiuAx/CPMJ6yFIQ4rctzXhscv4Vdy8TvFwLWT4YcVofzCusdR10rNGmTZWQzcwS1pVQzlhYrwE4iU7S71jHVzIQyHnGDeGEgIrlIbx0xWwaL8NlEcZabNKQlv8jvhJS8QJZlMnyAQQ5Ly/GXTkCJV4wRPAz2Jk11w4P4iVLAuWyXoq2cfKPGVzEHuXksuPlRU5ofHKOsnjZjDQ81ufltnMuvasrO6+xXomdlS8yKqwRQ/xoD3Xoi2zYlmegqZ909CsnLeJiFjkEmNaX6Xt5cfl3rLfNfCJeufDlMob0wSwfwDwvL2q74okJPsJXjFeWmVx41b3dfi4+PHLkZdN4EZcv0rzvcxd1++P9AfxNWnxYCWJQYc3LgvGSK3VQFsKd8US+6A/qPPX82zsbVFjT5xcN6PMhwpr+ibEJlIdveElz1suLLP3o7BahubQ2Oi0PyTZMpVmhsGabx9pZ7FKW2pRpvbyYhagKq8irLzlWLy+qANaXO6uyVUjrNkJ5qd4pYVm/hDirPa18Wcx3Nw1J+FblqHiuXh5sCevYn4Vv2NES1oxJ+jfKy/sY71mAL/fFs8KakL9kQlyuT9sZs+951jrGWdUuqIT1ti9/LJ9RB0RzlB/lkfYnlL8kak7prhucL7Mo7/LP8fIi/tN93FjwAmwluHJ7ttm4/OXB/B3r1suL1BeivEpTvbyISKZP8qz1j2jDEZc3xfY8wrrv5cUsekMId0tlnhHIEUeoBHIwz8uLCOPu5kVmpyM9YymvtZ7nO9agol33W1ivATiJTsqBiy2fxvvOqb8uZxoR1/HJLgJC5OxL7lr2IldcqHUmvCWk+HRY/gwYF/2PHrpthniX95zRCZIQhfzlJqAlxALWjyKisC8CQodZvrgJYBkAaWKdF2VzkxCfYwNm+jjZ0BZsw07ESBa9K7Gz5YtAhXXYwkx63+cBIWY68xrfWM+OXYg6rS8TgjR/ji8EZQR8wUkeEV7ZD7P6YJYPIF4CzTdoSktYI0xZTpE/VYfNPzhj2yzyt35845Ivo2/j04XAkwGW1MTNA09VhgproF/i6zBRd/iUvjz/ynu6fYBNKqwj3aw+HyKsOQ6zH/ifF4b/x786epCwZn8OKoYjXbzcWKVZqbCOuLxmNAtftTfQz+FtE8LJ3kJABvlXJqkrPpsXaXV9NccBvl6psN4mhJb7OEIsN8nrq6kr6syz2JEm/EOfZmEd7c51Lfky7VfbVTzrWm/9FJ+Sl3QQsJsbvCyQVVhP2/js7G1eX73cF8tnrPP1Tcuo2hniupVHCSGaw7M3YNP+CHEdgfLzrHSUue1GRz69J8KauBDXETqRH1/YkH2daJwxGx1l6trnzs5O/NZpnt3/bNmaBqEWfZJFsb6M2Le+OtJrGUt1Fp/bC3EdIYvnnJflIM8K22fjaFtLqOa8WbxnUZ5D9cMwy8uZfjkxRHDs7xPWK/3cnoX1iKjDjAGWXCC88g/EbC+25w/EGBNUIswYY2DWTPFaoKJZ94+FhfUM1GHGBPqT5tuD+AVIngRUnwY0Zq14dl1v/W6CMWbrEstBuqUvCxS1fayVuLewnoE6zJgg1o3nr2SsJcyU84Mq+cd6jFkLLr32/u6G8tnlAc+s8U7fdTbGmEy1dnutWPoe9RrUbWE9A3WYMcZsdXRtNkG/EmKMMVsRC+sZqMOMMcYYY4ypsLCegTrMGGOMMcaYCgvrGajDjDHGGGOMqbCwnoE6zBhjjDHGmAoL6xmow4wxxmwt/uRPdpi6NhhjzCKwsDbGGLOpsbA2xqwVFtbGGGM2NRbWxpi1wsLaGGPMpsbC2hizVlhYG2OM2dRYWBtj1goLa2OMMZsaC2tjzFphYW2MMWZTY2FtjFkrLKyNMcZsaiysjTFrhYV1D18/4YbJE08+Ndn/a5dP7VuPYC9hI9m80bjm17/t0PjMPOOGNA89+uSgtMFL9zxlcse9j03OuOjOqX0Z7KDsN3/snKl9K+XqZ9r/74p965mrb3rG7j/f5r/b73lsaVvTbgU+efjlk8efeGryjRNu2O4+yP3x3/35N6f2j4GFtTFmrdgSwhoBQugTIogPRAiChRM9cfMIpO3NSgQaRLs1zBKPa4m2rWXzWvSVhbWF9WbAwtoYYxbDlhHWCIxf3/7wkmhWYrY3C+uNRCWiaPes9oRIJb/um4chda0UFZ8tm6MPZwnf1TBEWM+Dtm0IFtbzk4W17jP9HHH8DZPfPfrkZI/9zll1v7/po+dMfvfIk2su6C2sjTFrxZYS1swiqhiDECpceBclDhdNJaKGiN2WSJ2XIXWtFBWffTaTptXPY2BhbWG91bCwNsaY4WwZYY0QOe+Ku0tRhKi578HfT0485zdTS0FUmOgyhHjkH2KHOvhLCHHXypNtwK4csjCclV/z3vfg4117cmiJ3j6RClnE5XqivNhf1RUiNPKFEAzxq+m17kDF5yybh4pfLRcoU/0bbc9lx/Iigo6RatzEbLq2OWyIPBH6RHPuk3ntmDWWcvk5hK9VWJ+ellkRp+3sE7NqC//vkWw94hn7P/mMjyJ0dT1TZvjvi8dds8xmrbdaCpLLoQ4dky/ba9uYzOn1GIg0SzYff8Pk6aUUy9N0yy9SHWqjEjbn4yfSsy8Cdn/qiMuXlXX6hc+OC/ZzbsNPkQ5bELixHW3UMunvHLo+2u+czu/kp1zSRjx9Srymp47ON9k5k8nkGz+6YfKyZf2xbSmI2hNpcxuvuunB8liM+rIvLayNMWvFlhLW/3LwhZ3gVCERJ2dEQRZ5KkxCEGbRw4UlC2sVKlWeEB8hVsK+XG/sG5K/srUqt2KWSM0iK9JEnmxTVVcIAi37F5ffvWRnlN8nhFUAz7K5sqUiC9SIyyKmStPan+3XviBtHhfk4QaMv9G/OT35dRxVdmc7wjYtZ9b41bEUvs3iOY/HLKzVzqqf6GsVOcFPnjl2Yhux2AnRZ/oNYU3oxFLRBsqN7bADu0LcZeE6S1j//LLlYzKvwY7t8BNxUUcuAzHbCVLseCYf7UdYYxuzvnnfrHXeIZ51dldn3xGsCPYQydixJDCZJX7G1hDLpFFh/WyZ24TtT87e1jfsq2asY4223lzkfNtsfXBZmmrGenl/fHMpDfbEmuuoL9IQh7Am/OyZuOxTXattYW2MWSu2lLDmxMtJNwsLLpDs4y8XTRW4WZiQNwuoTCWw+vLk+Faavn0ar7bCEIEZQkpDCKlWu7Rs3QbyaFxFlTdTCbY+Ya392Ad1R9solxsv1uJrXNRdtUl9n7dn2RrCMO8Pn+dxmmn1idaldumYCXI8M9DavkwIa8rO46Sqb14if4hohHV1g4Fw7MRaujEhb16mgBgMccn2LGGtLNWx17anMpUIzmlCaHd2FGVSv9anNipLNxpJuCIw733w98tEbm4PvlPhGvmykM7bs/zRJ6y1HmVZ3j8fJqxPv/COqXaDxiOsNV1X3yPTs9YW1saYtWLLCWsuxAiluPhnYaWCLAuFEDMtgVSJob48uS6ddZs3f2yrqJklWEHFmFK1qypbt6El5GJfDpo3M6+wrmxpkf1G+YhqlhXEGFE/V21S32uZebwp2jZo+XzWfo0fOn5zG2lbJ3CKegFhTZl6MxD1355m0ltlZGIpSQQV1nk7yPGV/yCWjxCPHUOEdV5eQcAnWVhr+iyso58rkRz5q9C1o8gT9qiY16UmOWAfdtz7wHLhDX3Cmu0oN+zRm5RKWOf82W4EcA5LZQ4U1gjm+D+X291URNv+/NmlIHl22sLaGLO92XLCmu2YcWMbIRUXZRVRQ4VJXBxU7PTl0boijhACe578Ku5A210xS6RW7arK1m2oRGjcROT4Kq/myeJpls0hDjW+IpdFHsh+17KqNqnv8/ZmFtatdOHTEHt9aag3ln6EvWstrGN9dRax1Yx1pI865hXWtE9FaB8tYR11anpYJj4lvk9YR7pYm93595kyhgrrWHKS7VvJjLWFtTFmI7MlhTUXQQT1d0799TKRNEusVqIqUFETtPK04rWcVjqNV1tB210xS6SqPa2ydRvUxla6Ki6j4qnP5soPs8BG1jznmyxs0rhIq23SOvN2n62gbYOWz2ft17LUrsp2jR+6FIQ6+sR1LiuEc0Zty3GzhHUWnNrmpbqT6NU8KpQ1rebX9FUa2oGga4nnSiTPospTCdpMa4mGrsPuKycEcpQxVFiriK7ihghrXfIRaLyFtTFmPbIlhTV/EUz3//bxZRfkWcI6i4nIoy8vVmJH81BuXvZRvcwX6Yfkr2xtxSmzhJ/aE6hPq7oqIafpon19Yk7FU8tm6lK/kLZ6YTVDOQRtT8zczdsm3cZX2S7qyC8vqjBs+Vz3E8IHEadtqHzdN5bCt52gS2minvzyYi6P7ZwO+oS1tjvqhSyso1/0hUbqyTbkfDEDnYVwn7BGjHX5n5ltJj8iNEScpl9qnwjyvpcXsZelFllQIk45f6iwDSphHbbkeoGXL2l/zM5He9ie9fJitpOyVFhXInpIXIjoJVumfL/8CyAR1/fyYv4yyCxhHTc7lLvDDjtOXRuMMWYRbElhDVzoZsWpMIG4kEeI9H1iSPNomVwcctAyZuVv2ZoFmLY1CEGjIcpqtUt9WtVViVDI7SVtfKKwsg9aIkxDVZf2aUWUl9uYBWZOW7VJfa/bQNk5RF3aNmj5XPfnTzsStJ2VHUPGkvo3p9HP7VFH1H3yL25fyhNxlagO8vpq6ohPwumMNfE5hKiO9kSa3C4VwX3COvZHyL6dR1hHXA45j66P7tpaLB2pbM7xYU8OaltuD/UgkruvkjSEtZann7bj6x5RFjbjdxXW29r/7PrqZX0qs9jx2b3W5/ZCXEfINwVRl4W1MWY9siWEtdm6cFFtCVSzvmktBclUNyZmGp1N1v2bHS8FMcasFRbWZlNz2XX3W3RtUCysx6OaXd9KWFgbY9YKC2tjzLrEwnplXHrttptJXYKiLzRuJSysjTFrhYW1MWZdYmG9MnSdN2Eri2qwsDbGrBUW1sYYYzY1FtbGmLXCwtoYY8ymxsLaGLNWWFgbY4zZ1FhYG2PWCgtrY4wxmxoLa2PMWrHphbUxxhhjjDFrgYW1McYYY4wxI2BhbYwxxhhjzAhYWBtjjDHGGDMCFtbGGGOMMcaMgIW1McYYY4wxI2BhbYwxxhhjzAhYWBtjjDHGGDMCFtbrhDe+8Y2TG2+8cfLHP/5x8tBDD03e/va3T6Ux25+999578sgjj0zuvPPOyS677DK1fzVQ3h133DF5+OGHJ+9973un9q9HPG43DnvttVc3thi7u+66azfebr/99i7ufe9732SHHRbzIyrveMc7Jg8++ODkrrvumrzuda+b2m/G4eijj5488cQTk4MPPnhhfTkmRx111Nz2HnDAAd14Jc+OO+44tX+9QRuffvrpyZNPPjk55JBDNoTNZvVsemHNxYMLCWIIUTR031rywhe+cHLNNdd0B+B11103Oe200yZvetObptIdc8wxkxxI/9vf/nbyve99b/L85z9/Kv0iOP/887u6qXcriqghwjr30y9/+cvJc5/73Kk0+A4fEqIs+M1vfjN54IEHJu985zun8qw3ho7bFjqeI4Tw0/TbCwQL4ZxzzlkSALQ3B3zAuLjssssm++yzz1QZLd7//vd3QoGA/4YKjJVQCetbb721G2/vete7FlY3wvr+++/vxvZ66le49tprl/UjgX6kDxflj0VhYb2+wFYmGyyotx4W1o19a8nuu+8+ufvuuyf33Xff5A1veMPU/iCECBcpBM31118/efzxx7uL+imnnDKVfmxe+9rXTu69997JU0891fHDH/5wKs1mZ15hTVrEk6bBd/Qboa+s9Uxr3HJBYZz87Gc/671g6ngOzj777MlLX/rSqfQtuEAzI8rfvvpWSktYcwzcfPPNS8ciF3z69A9/+MPkO9/5ziBbfvCDHywdT/hskTO6Kqx1/xh89rOfndxzzz0z+369gLCm71YjfBiv4dON0OaNzBBhvfPOO3dPYjheW2nWAs5H2LrvvvuOPi4WWbZZPRbWjX1ryRCxBiFEOGFE3Ic//OHJo48+OiVuFsG3vvWtTgBccMEFXZ2/+tWvullLTbeZGdJX0U/MBCK0TjjhhGX7EY3M3lEOjwj7ylrPtHyRx2nfSX9oulkgbAiUt5pyWrSENX2XZ9t4MvGNb3yju9nl+PjIRz7Sa8/LX/7ybhxw7CLOEeRf/OIXe/OshrUQ1viKMb/aPl0rLKw3FhbW21hk2Wb1rGthzUWKCzfwv+4fQp94rvZx8YmLHIF9n//855fyfPKTn+zWCnLxYF3pTTfd1OXRegOWaLBUg8f+5AFmdA499NBuf/U4nBO9lpPTZmGtbYg0V1111ZKdxJGWx73Yi93Es/9jH/vYVD0ViAbExO9///vJZz7zmcmvf/3rTkDsv//+pS0IhKgfAXLmmWdOXvziF3fpsiD72te+trQk4rHHHpt8//vfX1o6QTsJCHnSUM5BBx0006dvectbuhlMnS0mL2XEDQHChosi7SCQPtfP3yOPPLJ7nEfgRPajH/2oFJOZ6IMrrriis/G2227r6or9+Iw6L7nkkmVlaV9GevoNm2NM4qevfOUrS35kppP+pl9j7JAnj+Oo79WvfvVSufgLv4UPsfP1r399t2+Wj1vjFjS0RNYsYR2C9rzzzuvGD32HHazp5ukJ/mJNugbKbR0H9ANl4TfCkGN4qLAOTj311C79ySefPLUvc+CBB3aPwq+88srJl7/85a48lg4973nPW1Y3tv/85z/vloqED+iL/fbbb6n8uLlgBpx+jmOctjFOSKfCOvyHL/LSB5Yh4eM83r761a92+7/+9a8vGzMcZ4cffni3T5fHEPAZZaugZ3x997vfnRpf+CHsiLZX/c/MfqT70pe+1D05yeP4H/7hH7rjHf8ee+yxzX7oE9YINPxDG/K4Vv/lkAV29G+EXA/78AljhTTRB7SZeGznb4Rzzz13cN7oS61fxX9eBqNjOcRpa38mRB724P+oa7fdduvGpcZFGZU4POuss5bSUydlZiEdwpo+rfzD/tzmvK9ld5+vww8XXXRRZz+BuqOuuHYQbrjhhslOO+3U5YslchFy2/M+XXsdT7+ANNgSZQZaNv0fPuQYj+tVVX4Fxxb15Xp0GQt+4LhqlUsZ2abjjjtuyu6txLoV1ghpDSsR1y2xUu3josuaQwYNa4m5SCFoOGGR/nOf+1x3IDHDxCxknOw5uVYiC2EWJxYed//0pz/tLhKUAZTHAXHSSSd121xkKDcL+UwlrJmlxh4ucAjKSMOFNYtEXob73e9+1x0sXPCBdlPnkPW8CFTSM8PGjCt2ErjYR5rwJxdk6sKHZ5xxRpcPH8RylRCEiHTqJ034Bbu5eJMuhDXxCHXihviUdNRNGk6CYR/lMePOzDsiP4QnJ036mrZRf+TBDrYplzoAmyl3iLCmPuygji984QtL+4mj/QiCWcKaR+vUSRnYi985CX7zm99c8iOBfSHeo6/Jg2gjD2MUu0lH27lBpFzGDT4Exj5lDvFxa9wCwo6AAEI8feITn5jykfqpumCHoMVOllwwZrGXgA9f9KIXTQ477LCuHgL1Uh+26XEQYpX24QuEKmkRg7ST45zy1IZsx1BhTRwXd/pJ92XwKeORccZxzA0Svtxzzz2X1Y19XPix+8c//nF3AScOX/zzP/9zly6ENf1OW0gXfU6/vuIVr+jaPktY/9u//VsnpKvxxn5uVIjneInzH/k/8IEPNPte62V8hYCqxhflUFe0vdX/pKF87NVxTHvGEtaEKCNuTvJYqGasQ/zG+Iiyoq4QvZov2pz7JNKG4OvLG8I6fB52U/+FF164lF7bTd683ln3c6zjz8qP8YJepM/iTuOyaFVhzZjI25EnjrMsnLOYzGu1QwQOmbEOu3NZIZbDzihLhaTOnEe6LFC1fcSFcM5psD3KDtEc4l1tzrZr2dn2XD7nGIRuq7whwjrsfs5zntPt5ziLtpOfsc3SwOzDrSyu162wDsGQA3GabhaVWGnt44UyBhMn+7e97W1dGi4CzK4ww8kFS1/aQ5RxEWKmResOMYrwzS91xZIKLs6Un2dwW2INVFgz+8jJkgPx8ssv78qKNMwo52UaXIgY7HmGOcSxLlWoQEATuLixzQWNCx5igNlD4sKfIV4jb8zQhiiP9qo94RfEINshrPFxpBnqU4Qs/RLbYVv0X+zPNwYf/OAHu0f4+I6TBH9Jw+xwpOF/4vr6KvdTtD1eYoyXFtnmpNgnrGPMIQ5Zs6v1hB+xGdsjPm4qcr8iuplx4ALBBZKZeNLwsl28+MpfbBziY4Rqa9zOEsyaTkPkC0HLrOtLXvKSLk88dWAsvexlL+viqqUgkZc+zII5jufYDkGLMHvrW986ZWMua6iwDuHTJ6wZB9SZ6+UJB33C+vvcDuLoO8QxcbSBY4S+YLKBtOGDPOMdS004TrmRUoGrwprxFl94QRRXtuvSL84/2Y6wN/tKZ8rjhU3G15vf/OaldIh36o7xFWXl/g/fRv/HmGQcv+AFL+jSxDhW2yuqlxdDDKoYjjwqpHU7ylVhl4VvS/SrwI14RGfUET6o8ubys7DPbSY/vs9PKbIYpY4hwjSoRJ6K5NyGmLnN+RibXHtVUOYblCysczoV0rqt9ma7syCPeOyk37GTY0QFMyA0tXz1g25jO37PPglbQwxTbvaR2tyqK2xSO/vig1nCmvHA+aeaPWcSgPOnzopfffXVy4T4VmPTC+u8nlVnZlXIcDJm2QEn8xBlPG4lbYjuVuCirnWHeGF2LMerINFtLSdoCREGfYhbFd/wyle+cuqRZQ6kDV/kEG0KUZaFcPg131SoP6P+eMktPsfWai/9Qzy2YnMI6+zboT4Nm0NIhyBDdJKek0krUAazstiL3djfqifbEOQ+CHFMHgQFogk7EPZalvovlrS01s9rfuKir6vxnv2JYObRO4G0iIPXvOY1XbqhPtbtqv19F4dIpy8vUj/5KkGr4pC4PmGtNiC62IeApH9juQPtQGioja2y+oQ1y2XYh/jVfQEiEkGYhfARRxzRCct8M1AJVfj2t7/d2cQ4Jj58oGKLiyH5uRCr71RYM954L4DxxmcU1WZg6dill17a9RmCPULUW9mrwjrEMOMr26rphpTFOOYYjT7ED3//93/f9LuiM7OZvBQkl6dCWrfzTLeG8HVL+GZx3IofmjduGrR94dcqxExtpAl7+/xZiTwV0VVczkebVHRCJazzNmlUSOu22ttnt8aHsK6Wh1QBf7WENdt9fg9hrSK3QssOm/TGJNLmGWUta5awpjzOyRyz0b6oQ5fD5MCTNQvrdcZYS0GAQVPNKoeQy8IAcc3sDnm4yMVsYYgIxAgvDLKdqb5isFqBoqgQYf1ZrDnWNFlYZ8HG0gK1nf0IQB6rM1MVcACRP2Z3WyFmY1UYRv0qEFvtjVnwmG1fjbAmjtnomD2nrHxjEGWzZlr9sccee0ze8573TJXXqkfRPgghweNUxH6suday1H+xX8V9ny1DhTXbLAnhf/oFn7KMgGUkQ32s21X7qxP50HSVoKXOLKyIm0dY87UK+oKbHcY4FwaOadoxhrCOm/MYd1W7Yma4FRinn/rUp7q8lbgExhKBpxLEt4Q1s+Dx1EV9R59lYR37GW9xk5WJZUmx7IKbT2asc72VvSqGxxTWxDGOScvMWYzjod/lXqSw1r7I6FKRiFdxXMUPFda5DYRoJ+mIC3vVtkws2YkxUqVXkRf58MlmFtaViO0rPwRu32z0ehXWOW2MB+qmfzjustg261hYwxgvL0IIilhfShwXwJ/85CfdIAlhiECN/RB3Y8zMclLhLxfT1hpoJYQiL0/FjDLwsg8Xu6i3JVAUFWwVrTTx6Jj1pppnFizFICBA8sxivOCUT0K0obV8Il4ajPayhIGblEiHSKA/YlZZhSAM9SlxsbSDkwZ25ZcIWdcayxpynwchUFvLVfr6SvsgPlPI2MHG+Eyh9rsK6/xUIPsz0PwRX/U1bWSdarSH7bghw1+scyew1Geoj1v1zxLMQ9NVglbFIXFDhbUKSeIYt1xAxhDW+PPEE0/sbsZDuGhZwHpk6iM/szr5mOKmOdcV4jIvh6Dv4mXW+IpI+AChGzPgzOYy7qiLOtV36g/GG+uTKTdeVsx2q3hnDMSs6DzCOtZF6w/GcGOPT2IWf0hZOo5PP/30Lg/vc6j9FYsQ1rPKhXmFdS5v3ry6ryXMW4TPK9EGKvKIUxFdxamw1iUeUXZerrEWwjqL2yhLX4AcIoC1/JZYzQwptyq7L28rPtA10sQxucK1orKV5R+xbIfxFP+3yt+KrGthPRbxMheBQcBJigsYJ2AGDwOedFx4OPARGfnFJtbvsZ/Bk19mIw0v6/BoVOsETvTkpQx9SQfBFy91tQSKooKtopUmbhK4aCK8sJ0ZIw66vjpjTbAKTIhlDrQPsRjCMO5o80uJWRxGexF/PHrGL9hEmiy2K2E91KfZvqg/f3c7RAXl8BdRT1nMljMzRxouzuynXNqC4I+XAvv6quqDWKNOu+NLJdrvKqxJEy9QRr9hJyIrv7yotuADbM55aGOsRcWHMWvFPsCX1IO4GerjVv08GaJu9nHS5kU39VH2ky4F4Zji6ySV8FZxSNzxxx+/VA71UX+VN4Qj7eKdBNpNOWHrvMIaf+bvWFMGgZk3vsqi5QTx1RD9Aghw0464jG9a0w7spW/0pcQstkP0Rp/TZyHSQ2yr71RY0zaWo1BGNd646SIgiOlT2o1AJoSwjmUwue+1XsYX58zW+OKJIWUNEdYxG6fjmJvA1jrmTJ8AHiqsK0Ebtue6EcQh+PvEMfm0/FxWX94snqkr2pX3Rb/nOkjD+S325xcd10JYs01fMG5iu/Xy4ixhTdwsMRl2h6+zTeHrLNJVWGs64rCNYyS2tX1RlvqFsR9jZ4jdUZeK9LjG68uL+eVILSfni5cNQzjj91hjzVO4sDkLa9Kznpp+44egoo78cqPWtxXYEsIa9JNl/OUimz83x8U8PkdHYLDlT5RxQeBOLn8iigOHi53WFzCjgqiKiy5lMwuZ620JFKUSbEpfmnjsjd0ELoq/+MUvpl5IysQPmbS+WR0zuMwGMysWwhCxg58I/OWzejGTHO3lAs0jbeygDmzjohplV8Iahvg04OCPfuIEl/exjpSTQh4TCKUQtdQTXz4I+xCes/qq6oN4ITDPqGu/V8Ia9LN4iAeWCmj+bAO+iK+cEEiHz2J2ngtvHsf8z5KnsG2Ij1v1k/fiiy9eWkrF8ZEFQBB+0kCZXGgqcawijThm1Xl6QjvoK27gqrzATUHcVMfnHcPn8wrrHGgnYphxHy8ZVmArfclYq75ZHS8cckxxrglhjdDhZiB8iuhlLXHkC2HNhZ1zWPiC+LBHRWklrEmnn6/DX5/+9Ke78yDHS9hAHyMKCCH66HuecEUangpWfUY6bjB0fOVPCA4R1oxjlqbkccykATcSrZf8MjHjroE8lD9EWOflFjk+7I+Q/TxLHOdP14U9kW5W3hDWtL2qm7TZ5gj6JYwcWqIaVEASpyK6iqvy5f7AZurNQnqosCZdtF9Fsdpd+VrLrsoIcZ3tzW2p2lf5NgvhocI60lJ/rjdEcsumFvlzednv+eXFHPSLH5wXsi+28vpq2DLC2iyeljBUWoLMGLOcSlxW6DIN3W82BtXs91ZG11jr/tVQCV9jxsDC2oyGhbUx42JhvbWwsF6OznLr/tVgYW0WhYW1GQ0La2PGxcJ6a7GVhTVLnfLylmod85hYWJtFYWFtRsPC2phxsbDeWmxlYR2f9sthUaIaLKzNorCwNsYYY4wxZgQsrI0xxhhjjBkBC2tjjDHGGGNGwMLaGGOMMcaYEbCwNsYYY4wxZgQsrI0xxhhjjBkBC2tjjDHGGGNGwMLaGGOMMcaYEbCwNsYYY4wxZgQsrI0xxhhjjBkBC2tjjDHGGGNGwMLaGGOMMcaYEbCwnsEuu+wyufPOOyfXX3/91L4hrDa/WX9En55zzjlT+1bLQQcdNHnyyScnxxxzzNS+9Qh2ErAZ23W/WXuuu+667nyzww47LG0zXnfdddeptGPA8XDHHXcsq3O9ELZxrG5v23beeeclW3bcccelbfzGtqbfnlx77bXdmNltt92afjvqqKMmDz/88GSfffZpplFo8+23374u2zwP0fZ99913cNvXigMOOGDy+OOPT4499tgN7eONjIX1DFYrjFeb36w/hghr9hH60uy9996TRx55pCuLMonbSMIaW7F/XkEd7dawnoTZgQceuNQ2bMJmLqQa6KuDDz543dgNFtbPYmG9Miys+7GwNn1YWI/IEMFlNj5D+pl9CLNbbrllSTQrMdubhfVGAvtpI6Iz4s4+++yZ7Qlhvdqbh6hrEYKxJayxOV9Ijz766K4P15OoVGE9JnvttVfnBy7aiyh/NVS2jSWs6ed5RaSiwlr3r2fOOuusKaG9EmG9Uqr6tyfrWVib7Y+F9YgMEVxm4zOkn0NYt2af85OMWUJ0vWJh/WzaJ554oty3PbCwtrAem0rYWlhbWJuaLSOs49F8hLiox6P3LJLy4/hKRHHR0rIiTw7k0fx5O5dTiZG8n4v8KaecMiVk+iA/xMwoQdfCxuN8ymZfLr/ls8o+3R/lHnbYYV3bIuiSmCE2hoDDRkL2ldqYy6+EX+TpK0PbqX170UUXTY0JJeogrbY5yrz//vu7NmVbquUVunQi/BNjKezJtrfyZBuyzwlZjEXZOWS/IN5yoC2QQzWms23q5yCLIT1GENGxX+tiXzVWiNc+jHitO5hHWMMQMas+y2Uh3KK+vOQkC8LslzxmyYe4admi28BNSQ6aPocQqtj49NNPT+3Dj5V47asj21W1JdLFTUuEVr8Nsa0aS5G/VQ92sCwiB7Ux01eOCmvdJn/cHESI8yNEGuwJv0WbZ9lEmXnJEv7CzhyHeI16og5sZ+lGDrQJgRs3G/g5t7lvCUIsBYk2h23kye0+99xzl3zUqh+7sTn3e66bJRGUeeqpp3b24SOEcB532X9ZJNMPDz300FK5un+WsKZu8lft2mmnnZbSnXnmmcvsz/uj7fn8TqBM+jrbp+1m3yGHHNLFha3aT8cdd9yyfoolJBEuvvjibnyqzWY2W0JYq5DKwpntLMD6hHBVFnmjHE1bxWXBoiIo5+PAr2wOO3P7WsSFhL8RRx1ZZEW5ua5IV9UfNrONeIn0xFfl5rhoZ7ZniI0hAHOayJv9Eb4NuysBp3FD2pm3s825v5Qo96Mf/WgnOFXUxomdcrX+EFi5/lwXfic+2quiucoTPsztyvXglwsvvLC7SOR+iotGq0wdj2PMWJM3hDNpwiYuDtQfNlUz1q2lGRdccMGycRJrW6uLIswrrCtbtDz6LQsb/BnCJuymzhDJIdKizdkv2Q8IhchHnArpajunR0TgH/6v7MwCbOissNYRabKPQsBr+8JWrYv9jNGWjzV9to0Q8ZEu20v7w9Zq7fPQGevzzz+/WY4Kad3OdkW9IRyzLSH0s/hUezNaT6uMLHhDWGc76Dudsca2HE+6PsGp9cQYZ6xEHsqtRL/Wr3EIQ/KFyIxtzXfNNdd0dmvbaW8IyJNOOqmrP9pPnlzOEGGNSK3aFYI3jruoU9dGh12cJyJPCHGNy7ZUwvqpp57q7N999927NFUe6kZshz3ZTxbW87HphTUXxJawAf4PgcLBDlkY5H2aT9G0VVxsaxm5XhU9QSVk+qCO3BZQeyrhOMRnioqlqlzQNgyxkTyVeKx8pPFqc65/SDs1f2VfRe5P8ue01Ms+/s4S1lX9aofub+XJ8doPGT0GWvFVGfMIaw0hWslbCV8Vr7oNIVhDEGvdrbKUeYU19faVp2h5KrQjXbaz5RctqxLSsV3NXvahYlW3SRN2MT766tB47FKfZQGL76tyWvTZRvuz6JzV/3l/9E/YNcSWIMRf7r8QlSp4c9pch4pctjXdLPvybDR+uu+++7r3PzQufK11qoglrhLAMdPbmrVuCeucXtNU9VPPvffeu0z8AmIQuxGCKrRzmqotfUJZ9+u2pleRnNvVEqq6X7dJE/6t4vINhQrrLOirPNlv2Z7bbrutaa9ps+mFdQi8KmTxEelUwKmIaqWr0lZxuh1k0aJiK6iETB9DBJYKuYibx2c5ZGGt5VbxQ2ys2t3yUfg324F4zkJe+7IKpNOytA7tw0zuT7WBfbltuR3ZP636++zoy5PrinQEbQeCR+NA21H1yzzCurIRyKszoLnsWcKasvPSiECXOGjezLzCurJF0WUChCysK7tzfMsvGt8nrIfcAFR2ziOsW3VEutYNQLQ3C8ToM01XMcS2SFv1V8ziRoj90aY+4ZpplZNtQcyosCZf/K/l0f6I122YZZ/esNx8882Tww8/vBPTxLEfW0Jsah0qbImr1lirYFM7VDTrzVaVpqo/RHMVbrjhhiVhHWWrsKZtWSxWQlmXmXAcziOss7jN7apEcQ5DhHX2r8Zp3ZWtOQ9jEwHN/xbW47AlhHUWAy3iYq+CuRIvwMWBkNNXaTVOtwO2Q5Co2Mp1qpDpY4hoVaEbcbN8Rv7cdhVLVblV/BAbq3a3fBT+DTvyNvnzDPWsdmpZGq99mMn9yTZtoRy2mSkKG7Qd2T+t+vvs6MujdUH0GyHK2WzCmos3YzWLsypvZl5hHT6r9sX+PCOt5VV2w1oLa7VTxapuV/W36oh00Wa1M9qrYi3yETR9ZohtkTb3P32MSKPsECsrmbGOG5Jczjwz1osU1tk31AHYRP3Exfht1aHClrjtLay5KWgJW1ipsObYpA25PhWnul3VPUtYx7KO8JXu123KqPyrcVp3ZauF9WLZ9MJ61kU84ECLE04WBpV4CXSfbldxuh3kerFVBX6kUSHTRxangfpDhW6VRqn2a1xVLqh/h9hYCbhW+VU8dVKHCkutR4m+atmnfZjRdmIPgvr4449fVp7apPZX/glaY6mVpxUP2V61vUrDdtUv61FYV+mquMw8wrqqM1Pl1bhWGVl8tvyi4kQFa97WtLmuSphqnG6TRu1q1aHxaif0CcS+fZWtlW2RNve/imjdT9ysuqs8xM0rrDV/pMFPLdELQ+wjHy/CcR6KPsA+javqUGFL3PYU1rPqgZUK6/BlFqIqTnW7qrtPWNMOFc0qpHWbNFW7NU7rrmythLX6ZM899+zSWFjPz6YX1sCAUQEQL4DxPwdw7FfRpOKFl2eiHN0XdWXxoml0O8iiJdLENvuxFbGd20GellAKW/JMZMTlMlTItdKBvjSn5RKysFZ7I67Kp3E5XyXgqnRhl/qE/eFPFXNaBuSxQfrcrsijNiu5P9nmLxevBx54YJmvZwnrymd9/dDKQz35Zo3t3KZsbxwDtDNOxFFmzlP1SxWnRPnaF8EQMcR2JUaHxMUMdi5LGSqsdYZXy4GqPbHEIQtrgrYvZrRIE+UQNC7nU8FabYc/QqTwEhX5W3ZqfTlNFad1RBq1I29Hm0Os4Xt9kVKF3Cw/V3GQx5KWGzPPsT/iVAAqs8rJtlTCOtIjZLKgrF5ezNtV3WpbpImXDfMNA3G5r6o6qvLXUlhX4hAbsTvH5ZcOVyqsGXc5X7Qp11XZk1Fxm9sVQlXtiBnstRbWkYYXHP3y4jhsCWENIYYihPiqhFOOU/Gi5bRETezT/LodsK1CjO0I/M9sZ4iW2N8SJ2FrEEFFjwo5zZ9D+CzyRTsJ8SnAsCfKjc/4RdB2D7GxT6ypjVp+Tje0jNzOqD8H+qHqw4z2Z5QzK67qD/V1pG+NpSqPtl3bpHaF+I1QPUGp+iWPWy2zVXaEuLgPEUNRVwjNiA+bsrCGEIiRNj5hNa+w1sBYqS6sSoimCPl4CYETx0sO1eyrfn5L26GCVbcjrqqnZWe2I8RY5KsEeVVHtV/tUmGdbYl+7fP3UNt0LCHSIuj4iHyRps+OvnLyuEbMqLAmv/ofURPnx9UK65jRz/VFnJandYTIi3Yx41rVqYJNbVDRPFRYV/WTPvubEOurybNSYU25eX01/c0n+/J+Ta/tVHGb2xBCNXwVgc/b0bbtIayJO/LIIztxHeGEE07oxqeF9fxsGWG9GchCBjgIK6EYxAlZ49eCSiBWbE8bjVkvhLDWG4JM64bDbG5U5BqzFiDsvcZ6ZVhYbyCyCEWwXnnllVNpWunXGgtrY4ZjYW0qYkY5PzEwZi3QmW/db9pYWK9DuIAiNvNsNBfT6nF8H9tTtFpYGzMcC2vDsogrrrhi2dIB+luXpBgzNiwXYXlUzEzHi4tcmz1bPT8W1usUBnQO84rqKGN7iVYLa2OGY2FtYnY6B4tqsxYwO51/zpyQ16ub+bCwNsYYY4wxZgQsrI0xxhhjjBkBC2tjjDHGGGNGwMLaGGOMMcaYEbCwNsYYY4wxZgQsrI0xxhhjjBkBC2tjjDHGGGNGwMLaGGOMMcaYEbCwNsYYY4wxZgQsrI0xxhhjjBkBC2tjjDHGGGNGwMLaGGOMMcaYEbCw3gQcc8wxkyeffHJy0EEHTe3bDNCuRx55ZMO2b5dddpnceeedk3POOWfZ9vXXXz+VdjOS27/DDjt0/ch4ZdxqWoW8d9xxR+cr8ur+9UrYHW3W/WvBgQceOHn44YcnBx988HazocXRRx/d2bbPPvt0tum2ph+Da6+9thuHu+6669S+tWAt2rho8CHH4o477jjZeeedJ7fffvvStqY1ZqtiYb0JsLBe31hYW1jr/rXAwno5Ftarx8LamNlYWG8wECOIzL333ntq32ZlswnrrYYKa92/0eFYRDBxbEb71lpYVzZYWG8/zjrrrCURH+3ZDG3Mwlr3rVeOOuqozu/77rvvhvX7mWee2Z1Pdttttw3bhq2EhfUGw8J6ev96x8LawlrzjE1lg4X19sPCev1gYW3Wmi0jrLng5MBJj4sf++LCn0N+TJ2FAScVLaMlnLjYIQijrNjW/EPqIE2OJ4TArsS21qVLRUKsRt4I2gb1W9/yhXjEHyHbHvYDdURQuyHvp7xTTjllkLDO+QjZ1qH+oK5oQ/ZvBLU3/IeIaflRx4duV7a38rfGRquc7APd17cUI9c5q79m+VaFdXWj1DoGia8E6nXXXdesj77QcTjk8X/UddFFFy3ZEkI115fjEUsa1G7tM7VF25KFMOXHuGzlJ83TTz+9VAbh2GOP7XwSYlvHZvbl2WefvSxv3j9POxT1GTa1RKZuV+3KdVY3DaR/4oknlsXRthCCKgpjW8e3Cl/KCDvon1NPPXWq7oDlEfgrh7A72ogfsDNC9ku0Le+fJWT32muvrtwI2oaoN8ZDhHPPPXep3PDn4Ycfvsx+rbtaCoL/cjnZdtoeYjCn17GkghExrH0faQ444IDB/rnmmmuWlYNvQmCHPTnQF62yAvz90EMPLeVhTBxyyCGdf4lnfGBfrgubH3/88aU8N9xww2SnnXZaKhPhnO2kb9hf2Zh9ofmOO+64XvvVDsrafffdp8ZxcOSRRy6N2ZyPerL9e+655+R3v/vdVLmcP2677bal9uS0OQ677r333sk73vGOXvs3CltCWHMg54svnc3Fk78hCrIACYEY4iZf9FUkRxr+kiYLnRynIhuoM/YPqQMqEa1xan+kyWVHmpyPfdlPKoBId+GFFy6VqbAvyor2ZL/GyVT9quIv2xQ+UPGkUIbmC1vn8UfVHxqX7Y1y+vwf+Vrb6tfIH7YNHRt9PtDxqXUouc5cB2Kpr62gvs3t5QRejas4BrMYID95VVhjg6aN8UFZISbZT358MEsEhp3UpeIWsYCw1foijdaZywo/5HRD2hJlh7jMaSoqG0Lk4NssYLP4RCRccMEFU3lC7OV2RFwIudwOpfJZrleFtG4jZrUfYuyRpjUuYrxm22O7EtZV+pwGO7L/ou1qm9KasaYvczzpcvl6wxBCvU88nnTSSd3Yj3poV64j6tV66I8Q17Gd2xVtVZ/FdiWszz///KU6dA12FokhYEOkZpGPT/JYIR/HMGIy+yeXSR1Z6GWqGeuoN+cL0ZltUao0+B976AP24ft8o0Ae6kJ8VzbHMah2ZJFfzVhrXJVPOe+885bdWCB6+3yHsH7qqae6NoUAp97wJ/UglGkf9UY5V1999VIe+hM7I3+rzJxG7dhobHphHRftloBQwVHFhzDIgkrTqFjIYiLSav6cZ0gdbNOOLGyqOMrQcjS+ElZqs5Y7L2o7dauvcx2tvlLfKrP2D/WHloEdKujVJ1UaqMZP+FW3Fd0/ZGxU9gfYev/990/ta/lF68wnOu0jFYZBjs/tYVttRbzouMh2ZHFEHtqSx2ROk8tWm2YR5VTtyaiI1e2+sqKtiJ5oC0JEbYj2qtBWW1o2EaciuSpfy9H9Q9qhZVSESAtbVEjn7WiLzuRqGTEbzf/su++++ya33HJLFxeijbjwXSWstQ1D7FDxq22FlrDWGXVtEzbh+yyM1Fdal6Lpq3rVxmqsVGXNEtZK1IH4YyxVLzvmNPg8RFpVZuWfSjhnqv25TvWJCtgMM+DYXwnRlrAlDzbnPJVNQfg1z+iqiGbcMMMbYn2IfRWzBC0imDblelRIUwZ1Puc5z1nKl28mOM9hawhxRDfHKee+HKc+2shsemFdXYgzDIhK4OR8KnSCLGy0LK2XfVUIUTa0DhV2GhflqDiNdFGWihtQG2KboHa10Haqf0BtCtvVZ0Flq5aR68msxh+zfF1tV+lafs0+JR3pc+hLD3ls9PmANjHOqqD9EbTqzPFDfZvzcPJWXyPCY5+WQ14Vmq0QaWLmUsXgLLSuvE8fcRNCxFaitlVWFqSkb4XcXnyVxXdFZUMlACu7dClBrr9Kr+1QW4LKZ0OENeMCQVwJyTxWNM/NN9/cLWWIvPgC28PGSliryNMyKzsqvyotYa0COQtr0mJvFWIM9NWnSx4q3+b82taqTdrWIcKaNDnghyysNX0WudSHz/sEZxVob5UHKhEbYlfFO4JwVv0qnHPePDM9j826vITQJ6x1SUcOusxE0eUx+L5PWIfvWsIaUaxL0Qhcc/AF44ulHywfwf6bbrppackRZbC/uknYyFhYjyiss5hgXxYtrXqCeepQIVeJuFliR8VNnw1Z9Om+IMRbbrPabmFdC2X+EsJG3a/bQfZvnw9afu2jVWeOH+rbnIeTt/p6XmFNWX2CLucjDBXYWlfEY1/f0g/d7itLhfWstixaWMf66hC8ul+3o75Zwlp9pjOzKvZU5FWCNsoNW3KZxEGIU+LinBtlqJDWbRhiR+VXZTXCWmeN+4j8uS6tR7cjr7a1apO2tU9Yx41U9mk1Yx3po455hXVL2LZYD8K6lQdinXSkGTJjHWuSKztbhBjPwnvIjHX4rk9Y48s+MU8axgXj6Ne//vXSEhHiKKfPho3IphfWIQqriz8wICpBkuNbIkPzUhcC5rDDDpsSHJpWGVpHJeQ0rhKwGq/ips+Gli2z9mlcZVe2PcS59hXb1XKLoGpLpqpX46sy1K9VnG5XZatf87bu0/3VdpD9W9kfzDoGKlp1aj3bYylIq50VQ4UpaF3EVYJV43S7VRboUpBKzGSG2l/ZoKJI7Qohl21Uu3U76usT1iqiqzgVe3k72qICU8sgjnHG+zI8Wo52YpvGkVaFtG6Dis3W8ohqaUVmJcKauMqmPqoyNU63I2+uqxoruR0h6PqEtabV/IylWcKavp+1FGQe/0AlrCtbIz4LWC2rb6lFJaxn5alEdBWnwjpmuFt+qqhEdBWXGSKsZ5UR5ZDm4osv7vqffPgLkc2xGnGab6Oy6YU10GlZmHGAD3l5MYRIS2RkYZPjOKFDjo8ycxnUHS+XDa2jEhYq7qq6VJxW5agN5MliTG3JtGzI6bPYbOVjf96O/ukT1q18s15enOUPta2KY5uQ2xlxrfGj2+oX4vPTAU2f06l/Wz7QfcDLZS2fRp1VO3Q8zvJttp8Tr/o6H4NZHFAOeSuhR3lZ1PHyD+VQpr40R9kh2JiNIk11AdC6WnGx1AT7sk2z8kEWpH1tCSE9VFhX9VViSdPpjVHMYKu/+9oxxJbw2RBhzTbl5xnvKEPrJN//v72z2ZGqerv4pbyoNwXoPSjoFRgdAzKWmYAmTnCC4ATBRAETxUQFExMShYFiIjBQEq1/VpnV7+pVz97nVPep7qqutZNf4OyP52vv7rPqcLrRHwjUPtaN612U+TXXahyYo3YohD02x+20+lxYM3YV89hHnOlKQPke057G7DWq/PBps65jn/6gXk9Yu4DlevgdK6yxDtetH17UuGkDAu3atWtlfTjOGnEOhakK3tY70m6r98OLlbDmbzipYoZvF958gq3C2muLPqzDfmnf1atXd+WpuA3mgtq3RPEYYa01YbyYgx9k1Wu8DoKvG9ZHf5OI/5aRTWcrhDXAF7M2FQK8sbO5iFNh4DZVZIBKaPhY5WcZH/giRKNQcrFX+arGVdxUMVAgsnkcDuPiXP7aMq5xAUkfHpvawRjntERgtQ6NghDspR5VbN7Ha/46tMq319Wv/fyxbq35pHc2qjh8zPdCoU/91XNo7g8M1VbjxzfvqtZeA/wdN/hKpLFPG8dxM/dYVKQijkoMql31BSgQ2PjrHymsaZut+kBAWy5Ie7nQrubQg6IDDTc91HdIWPv71Xr2MO7zW3k4rZqNFdb0oU0/ABDGr/Gxz0WzC2m/BlUcmMfGHLyuDsQg95V1qmy7sGYMrfel3Q/Q96sxl78O0GuLfrXr4p1zdN/8N2T0hLXXSr9/LCOsPSePw38VH3IeeiWC7xXrXIprNhV9vl7x95sZO2pYCeuhmD0OPNWFzeoptvrDWn9fepn3q3V/9iOsq5pUtdTfFEJf6IP9o/Jr9sjWCOsQVoEL7aNCS8xvMhBqLhBDWBZ/Suzj60Yl6J1NyymEdSbCOoR9EGG9Ody7d2/+FDfCIewHfVq/CWcpwjqEgyXCOoR9EGEdwtHl22+/3SU2/d1kn7+ORFiHcLBEWIewDyKsQzi64Om0vsOKtkmiGkRYh3CwRFiHEEIIIYQwARHWIYQQQgghTECEdQghhBBCCBMQYR1CCCGEEMIERFiHEEIIIYQwARHWIYQQQgghTECEdQghhBBCCBMQYR1CCCGEEMIERFiHEEIIIYQwARHWIYQQQgghTECEdQghhBBCCBMQYR1CCCGEEMIERFh3uHz58uzFixezc+fOLYytI4gXbZNiDkeXEydOzB4/fjx78ODB7NixYwvjy3Lp0qXZ8+fPZ6dPn55f379/fzLbIYQQwhRshbC+devWXHDiTx8jp06dmt+0IQQgCNC3ScIaMSL+ZWNl3t4gWHzuYeG5tWLelL3aFiKsQwghbBtbI6xxQ3748OGOaHb4tFeF9SaB+JEjRCf7kPdQPhSpWO9jyzDG115pCWuPmXu4Th8KVgEFa++D4kHT2pMpibAOIYSw7myVsMYTzerGr0/WViUOV02E9f/Pbe3zUSHCOsI6hBDCerI1whpC5O7du+XTTIixJ0+ezK5fv77wKoiLVX8Nga8fUOzAB/5Eo8hordEYEJc2FShD630tcgHaWqJ3SBCpiFM/tMfxyhfmEzQKQYpfn+++yTLCGtCn9xOvp+8x9/3s2bO75qmQZUzvv//+rvx7fglfTarswrfXQ/P12lXrtbktxo2zTjvMX9d6TQCErDbW331yTM8OxW91XvTr5NmzZzv9iIEiGvSEdSWy4evRo0e7/IcQQgirZKuE9dtvvz0XnJWoxRwXNS6sKWpUyECgqLB20VutoRChoPCnvejn2Jj1VayV3YohkapCSAUQ1mhMlS8Kard9586dnThpvydIlxXWVSwK94zX8O31p7Br7T2vdb8ZVy8XzEH+vKYd5uJnUO1yjgpWtY1rP3+IpcqDPnR/vU+FKtahbrSLWKrcdU80TtjR+tCunvVr167tih1iGetPnjw5v+4Jax8D/GAEmxHWIYQQDoKtEta40VNEcww3e4zhTxc1LlZ7T0JbArG1Rvtbc3pj3u+xgiGBCSh2vLmI8xjctl8DrPG+imqtsqyw9n0cwmvnopFonC6IW7aGUPHJ9R675+trqjmtfq8lfXq+Q3m4Xb8GLqxv3ry5kFsPF8t+rcIaNvF0Gv4pouGP4247hBBCWAVbJ6whHvDUmoIBYxSNLmpUXFAkuHAhldjprVFfFGkubsau57ULoSHBCipBpFR5Vbb9Grj4V9CvzdcqLgaHYq5icTBHmwtrr6X3e0yk1a8wfm37FdZ+rhXUmnOr+Kp8qz6eU22MyWP0OPm6Bv/uMRKIYW2wOUZYc21PaIcQQgirZuuENa5x88UNF9f4TSEUGS5qVFz0RC6oxE5vjftiHxoF9jLrKyHkeVdUgkip8qps+zWohDXFmfZXa32NisGhmFVIOlzbq51fE+33mEirn1DQM3avr+8r8Hx9Df2uUlhDxPZe/fBrj3NIWOu+tF798GsX1qwBxvF3fG3TVgghhHAQbKWw5k33ypUruwSeixoXF5VQJJXY6a1p9bud1jzv91iB511RCSLF42nZ9mvgMbbmVX2Ki8FezFUdhsa9z6+J5uMxkV4uVS29r/INH/raia8BrZp4fxV35VP73EZl1689zqFXQeiv98OKfu3Cmn2wBZ8tER9CCCGsiq0U1vgTwvqPP/5YEBg9YU2Bo4LGf3jRBWi1Bnb16V/1w3ycP2Z9FWurz6kEkeLxEK9p5asS1j6P+bUEF+eoGGzFDF9eF6dlS2OCXTTPT580M+4qF6+V4jXBXDSuYTy8Zv3Vd2WHtjx/zNE8PH/ge+J91RngbwhhTC6iqz7mpmIY64HHhbn4DSHoW0ZYYw6+tvkvURzDDzLyw0nEdgghhFWxlcIa4AY71FcJDoonNs6vxEdrjduEONDmNobWt2JVUea5Eoodbz1RBbymla9K/AHNF3P5Kwqr+EAluqqYK18VFLNosIMPR1o71hL92lTYMib9tXVoXifHY2fuuo4iHo1iEGvcP/3qWs0NzWvitaQ/Pzve52eQNdOYNG783YU15nj+6kPfr9Z9WUZYU5B7f4R1CCGEg2ArhHUIy+CisqISqOHwobCOgA4hhHAYRFiHYERYby7+VDuEEEI4SCKsQzAirDcTvHqS/2kxhBDCYRJhHYIRYb158P1sf7c6hBBCOEgirEMIIYQQQpiACOsQQgghhBAmIMI6hBBCCCGECYiwDiGEEEIIYQIirEMIIYQQQpiACOsQQgghhBAmIMI6hBBCCCGECYiwDiGEEEIIYQIirEMIIYQQQpiACOsQQgghhBAmIMI6hBBCCCGECYiwDiGEEEIIYQIirEMIIYQQQpiACOsQQgghhBAmIMI6hBBCCCGECYiwDiGEEEIIYQIirEMIIYQQQpiACOsQQgghhBAmIMI6hBBCCCGECYiwDiGEEEIIYQIirEMIIYQQQpiACOsQQgghhBAmIMI6hBBCCCGECYiwDiGEEEIIYQIirEMIIYQQQpiACOsQQgghhBAmIMI6hBBCCCGECYiwDiGEEEIIYQK2XlifOHFi9vjx49mDBw8WxpTLly/Pnj9/Pjt16tTC2KoZG+PUHJZfBb4P0/9+YQ1v3bo1vz537tzsxYsX8/Pkc7cF1ABfS/jTx0JYJZcuXZo9e/Zsdvr06dmxY8cWxteBs2fPzmN87733mjEeP3589ujRo/n3lZdeemlhfF348ccf59+/DzrGH374Ye735ZdfXhhbZ86cOTN7+vTp7Pz583uuGc7Gr7/+Ovviiy/m+fu1zw/TM5mwxiFuNQiJdb2JjhWPEdaL4wdBhPXRI8L6/2b379+fn4mWcAqrIcL6YImwXo4I66PBZMJawRc7xAREhY9tKocprJfBhdym0Ir7qAnrEGEN1l1Y49xSuE0Z482bN+dfDydPnlwYOwiGhLUK1mr8INhEYU3x5vFEWC9HhPXRIMJ6JBHWq6UVd4T10SPCOsI6wrpNhPX+ibCOsD5MDlRYo1/bGMHkayhQWoIFwhc3bf5TO+dp03+Gb9lBbGywd/369a6wpljAPPxTv871HPw1AL4ewHb37t1dMVUxwoY2xOt20HRNLw5+cED8aPD3zjvvNOPQ+lR7vUz9enFTWGvslZ1ebhXu03OgX62zv9LEmuFGiD/ZtOa+d5Wo9Nh1PefTVzWnZUe/vnysVx/U9smTJwvCF2IQNnGzX+YsQEyxoYY8C2rf94N+MEaRx68LNMRfiQ7she9rT8QhNvVFG4yPucI/G+yr6NH80DQ2iiT9vgBR53FA8GnzmBz3qfPfeOONuU82j5cxVWcKczD+999/7/TrWOX7ww8/nI/RbxXLd999t/B9uLc37kP9q+j3s+f2IOzY9PtQJayrvCFGOA979O+//+6M0Z/b6dms1nz++ec7drFXn3322YKwdjt6j4AAo9DWrxHui69FzVS0eV46rvVDg00XfG4fDXXDPAprxEkfqP+bb77ZrAFa5UeBAPW6vvrqqzs2KaxhR2uLmqpdik5t9K2CVNfgTEP8ch6v2TyWCl+D2CCm8T2HtvVr2EXxjRs3dtVLx11I+3XlHzG/9tprC/Wr9k1roXHo2dUPBtirv/76a8fXTz/9NHvllVd2bHzwwQezf/75pzm+iRyYsMYmqSDijdnnKZh7586dnWvefCkKKj/aR5GtAoM2KExc+DBWtcs1laBzu714dB5z8Gv6R2vF6OJM6+Rzx8ZBAam1clu8RuM61ni/9XNfaquqhcY5lFsF6uVnUW3Sr/uBXdadNdO8hs5Xb+90vZ8P9YExjYPx6hy1u2x9lhHWrbOgIszjwrXG7zWBbYgE9YVrz7ni9u3bu/ZV7fhcxufjLqw1b4xfu3ZtZ8yfwFJkUFzzWuc4/oQS8SOPVsyIB/FRoOt8+tM9oHByoUUb6MMc9DEG1k7tgFa+altz8dr5+grc9DV/98HY0FzUa7wQdVWsmrf7bj2xRtw4fyp2Yb9nC3z11Vc747SNelB0QFCqDeahvjx/+kaj6KNtj9H3w2PwcdYeY4gN9aNIvHjx4vxcV4K398Ta48Q8r4H60XwrX1VdaZPCEcIQZx4ijX3wwzOugljXUQQyXqxBvVQoax++9lRk07fm47GrD/q9evXqPC58X8EYzgQ/fKDuiJtiFXEjf4+5+kBQCWv/YKAxU1yzfmrjl19+mdeKoheiGmeHYvv111+f/fnnn/MzyFj9Cbzb8XHYQG4R1gXVjVxvnKTV32JIpPi4x0G039e4TcKnOy1hiPkuVloCBYeKgk3/Tjwmv+7F4nPHxlGJNbfFa49X67nX+rkvAl++h2prTG5j8LNS+fUYq5q5LV/Tqk/LR3Wuqjktm3upT2tNJax5zTkUThiniHYB7/FWr0VA6FFwwNaQQG4xJOSGhDV9e3wA+f3+++/zeTqmdXKh7f6B5upjjgshH3chW/VXQs3z9GvMwQ0Z+bpv98lr5IxYVXgO7UeFx9I6D2obe1LVaS+vglDsar16/T0oIhEjzk+13vcY4hS5qsjUOClYXLQDrOUc9mkNevWo/LboCWvkqyITQpGCDDX47bffFvZpGd/AxXklbj1GX6O2KJx1L1y00gbi1KfJLhY91t5rKi6SNW5/ak18fOgagtj9e8wutDEHT5Z13yjOe3a+//77eb11DuxgzltvvTU/f/x7VatN5UCENb7B6jXhzdlvvApvztooKAAOiAoMCAKKNx1TdJ6LlFasQ8LQxQL7IIqqhtha+XtMrWs0z8/njokDc6r83JZfE93vvdavZRvxMcbK1pjcWmBcm8Zd+fX+Vk7a73lV56R3xqv5brNVc65ftj7LCGvfLxXW/vWoMalw5Vn25sIavvzmX4E4tcF+S8gNCWv08zUNF78UqFWjTRdJ7h8wP7ShHBFLKx/aqUS8rkNeHpPX2K8xZ0y+mEfBieaicaywVhtsvdjcNvLFHPfTE5KgEtbIGx8oqjUUrt7vc7QxxpZdPTOYh3i8ji1hzWudUzX/2kKjWNQ4sN/+FLzCRavmjrOhfSqscRZ7Z6ontqq6qrDGehei2o+/e7wA4hD7wifGOq8a01cy2PSprdpmnVpP412Y6preqxxoLSHt12NiruqnwhpnAx+I/NUQjR9nF0+nq4bzBzGN88c5rQ8Om8haC2vYQeN4dTNX2+hXsYC/61yiN3y32Yq1JaLUpguglrAgrfw9Jr8mKsh6c4fiAFV+bsuvie73XuvXsl0JXBfWQ7k5FJtq189s5df7WzktI6yHzrjPr+a0as71y9bnMIS1fw0omONip0L3lfOGhNwYYa1zeVOAKGF+vSfNY4Q1QZ0oJlu5HrawroSgw7VoLgiH9oNzdK3H4teV7XUQ1hSmKhD1iXXL7tTC2tdW6AcZF9ioGYRYT2DvR1irUHW7FXy/uqrrKoQ14kUdYdufULdstJhCWPO95rGvfvg1Y/baKFX99iqs/al2BV8j4fkbmr/uHIiwrsRBrx9UN+6qjyLg/fffX7hBexxVv9vE+tY/71ciilS5UPi2RAN9u4DjOsbkMTq9fMbEASqR6Lb8uvK/1/q1bFcCV2Mdk5tTnQvvq/y6r6pmvtbzqkSl5ux91bkaM6cV8xiqNXpWKW48duDC2l9jAX5G/FUCB7Zc7FRUoq3qG1oDIdESERS/yEH/7vPIMsKaVDGNtdeqpb8K4ja8xn6NOWNffeCHFdTFRWwvtyqOqs+v1S9tYw/1nXGdg7PtYpZUwrqVd6ufqIjmuAtrfyUHaOwU1qinChh9p7wlrEElbHu4QGV/SzgPjVf+/VUQf993iCpG76uEob9b7GvUPoU0+rEOIvLChQs7H1RU0Otcj7Wiio0MCWv48afXLpyHriHMEbO+5uFUMbqwxisrH3300cIc9OurILAz9p3pMbFtAgcirAGKqyJEb9S+XtfoOOzq01ntf/jw4Rz1SYGgNvxm7wKB1xo/11QiSu1W4sbzBvjJdM5DHPrEkms0T48Rc3W+19vrNjYOH3e/fl3532v9GGMVt/d5rEO5Ob6e8XkN/ay5H+6drvP99Jr5OfH8/Iz7/MpmFRv+5A8v+hjo1QdAiGlejAu28A2vigGosKYdjwvXKqy1ZvxmijHESF8udiogSGCbT5DxzZ/72hJynEPfiA83Dwpr+EYduZ7jnM/89Km1/nBjJWIdxK25D4lP94mYhn54UUVmFVNV40qkq2/2a77qizbVxtAT48ovn2AztipWzmPdOEfryNp4/E4lBmHbP2xhHu1XtjxX+tc1sKHxUDCrLz4xVgGOdWh8utwS1tVaxIGvLczzs6diE2eKcbWEs1LVrepTYa010KfWn376afNrxtfzCTbjRh9fd9Cn7+hTPxTaiI/isHrHGaAu1BgqojlfhS7sonaVcG6t0R9e7AlrzHfRyyfYLSHt15V/xKw/EOk+gAprimbWE9fVDy/yN36oAId/fM/ANcZx/jQXCmv+S8EmiuwDE9aAYoXNb8oOb8Js/mvoCIWR91c2/GlqJRDYx4a/X7lyZUGceAwYr8SK561CClBYsMGXxuQx+nyvNeuBpnn14nCxWfn1a+L7vZf6gSpuxFjVy231cqvQ+YiPZ4s50K/Oc5+Mg7+ikI2iGnjN/Jz4+fQz7vMrm1VOHoePDdXH44Iv1gPf5FoxuLAG+s4zbLJumpOfaYxTOLaEVIX60n1tiVRA4Ua/Gh99a1Mh4j7RWCOMVSLWgbjRNhRv5dOFk763ylr2YqpqrHa0330z30rUe5/Ws5Wnv1+tXxNqw8+DfyDxveP3oSFhr3lDfHAe7Ou7qci7JTIJBTD963mkXZ2DvcJe+v5QILN98sknu4R0S1hXa/U8+Bhio3DUuNBUpFZ43TB3jLD2GqD5GqdVV39iDZgf8vZXTvxdZRWF6k/FaGtsyEZvDWNHDYeEtcf89ddfz9e3hLRfV/495jHCGn0Q11pfnl215b9OD/P4w4o+hjwopKsffNwUViKsw/5oiZZNphLD6wy/KXu/smk5hRBCCKuiepVlL+DDwM8//7xvO4dFhPUaUj2l3HTGCNV1Yky8EdYhhBDCf0z1jjReK8G/SuzXzmERYX3IQJzpk2n+E/yQqFtX8LQdsavYRH7+Cs66E2EdQggh1HzzzTfz15X8lQ//gcZtJML6kNH3itmGBN26g/i1bZqoBhHWIYQQQo3/t+poEdX/EWEdQgghhBDCBERYhxBCCCGEMAER1iGEEEIIIUxAhHUIIYQQQggTEGEdQgghhBDCBERYhxBCCCGEMAER1iGEEEIIIUxAhHUIIYQQQggTEGEdQgghhBDCBERYhxBCCCGEMAER1iGEEEIIIUxAhHUIIYQQQggTEGEdNoLLly/P0F68eDH7+OOPZ48fP549ePBgYd46ce7cudnz58/nf/rYfkE9UItV2F4Fun+bEvNR5/79+/OvoWPHjs1OnDgxe/To0c61z52Cs2fPzv7+++/Zhx9+uDIfCnNCQ14vvfTSwpxNAHV79uzZ7L333pvX7aDruI78+OOP83vAq6++eug1uHjx4nw/zp8/v7FnLExLhHVYe1yg4oZ5VIT1rVu35jd+/Olj5NSpU3M7yBm5o2+ThPWYOlQgbwgKb6sUf8ty8+bN+b6cPHlyfk3R4w35nz59emH9YXLUhTXE1yYLahJhvUiEdVhnIqzD2gMRCWECoeVj68wYQQlBjTkPHz7cEc0On/aqsN4kqv2jIO3lQ2GN9Xu9eVIwos57tdGjEtYqgnQe2qri2AsqrH1sv7zxxhvzOhyW+Fv1vh8krTMVxvH5559PJsJhC+dqClvh6BJhHdaeSphtAssIazx9Rp4+rk/nh4ToulLt37YJa3Dp0qX5Pldjh0GE9WbQO1NhmAjrcNBMJqzxDdr/aZ6iQP+Zm//0zaZrON8FBtYM3YS5Vhvt8J/S2fwmz9g1Np/jwLbHRD8aP+xq0zEILtxo2bx+zlAejta/lxvzZ6zcL/fn+QI+Ta3m+Hp/dUHj0zqpDa8fxt55552Fc+Vz4ff69es7uY49WxSBWEt/VSyeC23pOP37PF8DH3fv3i33H2ufPHkyt1XFqfvYqjcFPmygT9f19o9AgGnTGrZ8ttYiF6Ct8knbPWHNvFgLNoopCBL9+tIxiko98+jnk2Wf777JMsIaOQ6JPebMhrz0FRLGjZz//fff+RwX64zhwoUL89jYsE79Vq+CeGxeD86ncGZjnBjDBwjGxgaBjf3y2tCvz/Xx6nsEa+5Ur+PQpsfttTt+/PjcH74eWbvWhwP3w5gwl3b4vZf10DrBBmqFeFgbti+++GLntQI/U36NOXg1QpvGzPnoa/lg7r/++mvTDkSl7ivGWq8+0JbXEfO9bthXtYM9evr06a5xwnn+ms+ZM2cW9uLdd99dOFvohyjmeoCcWAvY+euvvxbm4xx6bTjGPXzzzTd3aoXXQ7RWnMtx+EGO1Z68/PLLC/UMm8Vkwrq60fsTOxxinUOxwxvrWPHj8OauwgQ2aAeCQm/2mKf29Oaqcak9Z4yw9rg1Jq/NGJ9DeTi0qblxne4D868Ek/a5P9hUIYV+fCPFn+jDmPqliKNNjY999OvrqnPjOWls9M91Y88WY/R94DdhjUlzhx2NkXm40HTo/+23354LTp8Ln5jj581rUtWb54VjflZ8/wDEltqt6qNn2H36HlexgimeWOseU3zyqTDGsAb2K8FIwa+24e/OnTu7BAlu1i3/YBlhTb/Y02oMXLt2bSd2zlf7jFttIAYViIxb+ygodd2QsOZZoBCEjdu3b8//PhRn9cTaa1PFxNgZB+NCc3Hse6pU+bht9PFDAG1TELvgrvjqq692asN1yAUCjddoKmAh6LSm9K99jJPrvG7VNb7W6QM2sd7Pg/vVOboXaodn35/60mZLXFNYex09ds6jX4pqrRkFvcamwpprGAts4pwyVo8d63/44Yedfdf4v/zyy117ytgodqsn1hDRKqxv3Lix8M41/KH+nEMBr315V/voMJmwroQLvoFRjOCbMA6RCwftr2zQTu8mPDTu+I0eMfp6n+O40AEuRl2MKRRMbrPn0xmaz3p6DFWcnovuHdG9chtOK3ftb8Xn++l5ch3r1zpbum7s2cK4i038HaJX66wxtGrRiqvl388E7GIMf/p585q06s04kJPG14rZ+3tCsDXm/R4rWEZYe4M92Na86Av2VFD5tcYI/62nnpUtHwfLCmvMr2rWAuIGteMHhypuj1NFj/pRW+jvCeuhPBw+tVMRPiSsvXZE+xmX16y1lng+6FMxpnO13wWy2+3RilvteF1c4HIexSBsed382uNwH9V50CfqiK8Sn2rv999/X/DXqiftq2DWNfTJPhWmrKHH4b70GiKV9ahiqXKD0PW+ChfSfu3x43uWinzacfFPYa3zWLM8td58JhPWQMWYCxkXBkTn+Rq1W60l8KmCpALj2oZESSUGfNxjclHCG78LNeZZtZ5P0MvDoR+vjfdX+eO6asylEptu3/cRaN08DuL77Xvh66q98HWtmIZ8sa/VsL5Vi2WFtdvRryfPcUxuvTjclwLBxdoOneHKZy9WzllGWGN9dfOr8oK9scIatXW79Ol77POIC7wh0dPy6za1ubCu1mt/Kwbv7wlrCD7Nq6IVJ9a7uGv5r2qLeRBysOVxqe9efL6O1/5hAyBXjKkgdn8tIPC0MSa1owLLBa1/INGY2I/zPSSsKZ61qbD2+R5HJXhJZZvNhbPmCZGoNqtXTdhwdiBMeSbcZk9Y8xpPoH/66acFUdoS1ljvcznWeo1jSFhjr3B29bUQtYvc4JOvgujT6Qjro8Okwlpv1vi7/qYDv9kSvUG3btY4jNVa0hPWFLu9G30lLH2OU+VDXx4/hRnFSSvPHmPycOjHa+P9Vf69moKeMOvlp3XzOIjvt+fp66q98HWtmIZ89eyTVi0q4ee4f9Qd/nCNrx+u9RjG5NaLoxUzUGFNljnDvVg5Zx2FNYUi/bXWKi7wKhHjsbXyYb5qr3pi7XF7fysG79+rsKZo9jhVIB51YU2xqeKuemINO6sW1hCV1Ws/Uwpr7kevJkpPWPvTXKUVRyWk9Vrto6nAHius+RRZ+11I+zXmRFgHZ1JhDSgMcIAA+6uboPfzZq3raLN3E8b81nh1U/e+Slj6HKcaRw7+T+7Ec6t89qj8VX2K+yS+F1UsvZoC+ISNKteWTe9vxee+PU9fh3F/oko7Lj7dl58t9wW8Xk5r31txKZ4r5kJQX7lyZVf9YKsXZ6vetOnxt/av1Q+8hmNEHq49VrBuwrqaV/U5LvAqEdOa67iIrvo8buB1asXg/nvCumWDMbkY9D4Xd5jjNj2eKk6Pq5qja0m1rhJj3q+C0/NW1D/nteJWf14Dr1sVk6/Ra+691tlr7+sxx4V1JT6J2vPataiEteflazjucVSvlfTs+DvPVW6VsK5Es/f5tfvDfox9FSTC+ugyubDGN3cIA33aRnCQK4GkgkDFEO3xn2NaN2GKAbWDdcBvvpw7JEoqMVD5pMhgLnzihT78IJTnyvnMSwUMYsQPobgvjg3l4R+sjvYAAAOTSURBVFQxsU/rWeVPsch46RM58RpjKhxhb+iHF32+1kTtany+F76uyon+dd2Ys+W+WvaB7q+fbe7PssIaf+Jr548//ti1DnH14qzqrT+8qGdHfXt8EFvqBz8E1Kp75dP3uIq11edgDDcszPWbPf17XojRhVElRsf08Qm22nJc4FUihjEhVhXNjq9l/roOMXpM6OMc9PFpatXn65hvq25qA+IA5wH11jgpvHRuZc/z4zqtOeOkKKzsVHV3qnVVDfwd57HC2gUxbTMm+kdjLrTNOeiDHbx2UPW1hLFeY40LeIhO9evrMceFte4F7SAOfu3Bpu4vxj/99NP5Wajq1BLW/G0ZKjwRH34Ylh8iUMdlfngRIpXr6UOFtV9jTiWsfR6fYGNvKKR9TrWu9cOLameMsIYd9xU2g8mFNQWFCzWCfm16Uwa8ebNhPua4qHHol01v2liv/fpr2BiTxzvmxk9hhsYnllhDETuUq65HG/I3lIfDWuqvPELzWlb5AwonNhdMHhOa5ujrPVYXamqzJyKrdX5u8Hc89a3WsVVny3217KN53LrfPAf402umuH/GMNRXxen15vxKgKp/bSpyAIUcm+fsPj2mVqxaT8+VUFh6gy3+E7nnBTsujHCzZozsdxFd+ePXjdpyXOBRGHjr2XB7bPo17k+s/aypYKeQ4q9XZPMYhoQ152ijWOvFyfUUiFznghxzKOjYEG/1ocTj8ro7rXW+Px7zWGENKGDREAvPiwrr6nuvPuWmQP/ss88WfpUd57gwrq41J9jC+DLCGn2+F14bzRcNZ0dFs9IS1sB/FR38qHj0fCA0eeZbwtr3VO3pKyKoP8Qt1/uTYX2/WveUgriyxT1UnxDFmqO/+x1hfbRZmbCmuAyHRyVAt4lK0IWwyVQfCJxKSIWDpRKuFf7k28fDf6iQ9rEQ1o3JhXXEzPqw7cK69SQ+hE0lwnoziLCeDn8/2cdDWDcmFdbbLuTWjW3ZD+QJsaEf5pBz9epKCJtMhPVmEGG9N3B27927t/B6hL6O4WtCWDcmE9b4BoKWJ4Trw7YIa6DvnKJFVIejSIT1ZhBhvTf4dFpbRHXYNCYT1iGEEEIIIWwzEdYhhBBCCCFMQIR1CCGEEEIIExBhHUIIIYQQwgREWIcQQgghhDABEdYhhBBCCCFMQIR1CCGEEEIIExBhHUIIIYQQwgREWIcQQgghhDABEdYhhBBCCCFMwP8AZQaZdWRBVhMAAAAASUVORK5CYII=" alt="Azure Migrate Official doc" /&gt;
&lt;FIGCAPTION aria-hidden="true"&gt;
&lt;P&gt;Azure Migrate Official doc&lt;/P&gt;
&lt;/FIGCAPTION&gt;
&lt;/FIGURE&gt;
&lt;P&gt;The alternative is not simply a Conditional Access exclusion or an additional user permission. It is a separate, certificate-based authentication model: an organization preconfigures a Microsoft Entra application and service principal, grants that principal Contributor access to the Azure Migrate project’s resource group, installs a certificate on the appliance, and completes registration using the application identity rather than an interactive user sign-in.&lt;/P&gt;
&lt;P&gt;This removes the user-context Device Code Flow dependency, but it does not remove the appliance-registration process itself. It also introduces operational overhead: the application is effectively dedicated to one appliance, its certificate must be protected and rotated, and the approach does not apply to the Azure Site Recovery replication appliance.&lt;/P&gt;
&lt;H3 id="azure-cli-and-powershell-when-dcf-appears-as-a-fallback"&gt;Azure CLI and PowerShell: When DCF Appears as a Fallback&lt;/H3&gt;
&lt;P&gt;The Azure CLI and Azure PowerShell modules are more nuanced cases because they support multiple authentication paths. Both tools prefer modern, platform-integrated authentication flows — browser-based interactive login, Integrated Windows Authentication, managed identity — when those options are available. The operative phrase is “when those options are available.”&lt;/P&gt;
&lt;P&gt;In headless environments, restricted execution contexts, containerized build agents with no browser dependency, or remote SSH sessions on machines that are not domain-joined, the preferred authentication hierarchy can become harder to use. In those cases, Device Code Flow may appear as a fallback when stronger approaches are not available or have not yet been implemented.&lt;/P&gt;
&lt;P&gt;For individual developers this may be a minor inconvenience. For enterprise teams running automated pipelines in tightly controlled environments, it can become a recurring source of breakage that traces back to the gap between DCF-blocking Conditional Access policies and workflows that still rely on DCF as an exception path.&lt;/P&gt;
&lt;H3 id="the-real-world-fallout-exception-requests-and-operational-friction"&gt;The Real-World Fallout: Exception Requests and Operational Friction&lt;/H3&gt;
&lt;P&gt;Security-mature enterprises that implement tenant-level blocks on Device Code Flow can discover this tension through production failures. An infrastructure engineer attempts to onboard a batch of Azure Arc servers. The &lt;CODE&gt;azcmagent connect&lt;/CODE&gt; command fails. A ticket is raised. The security team investigates. The root cause is identified: DCF is blocked, as intended, by policy.&lt;/P&gt;
&lt;P&gt;Now the organization has a decision to make: create a tightly scoped policy exception for the onboarding workflow, pre-provision service principal credentials and reconfigure the process, or pause the rollout while the right risk decision is made. None of those options is free. Each has security, operational, and ownership implications.&lt;/P&gt;
&lt;P&gt;This is where guidance, product behavior, and customer operations need clearer alignment. Until that alignment is complete, customers need a practical operating model: block DCF by default, document the constrained cases, and move repeatable workflows to stronger identity primitives wherever possible.&lt;/P&gt;
&lt;H2 id="the-clean-path-forward--a-five-tier-authentication-hierarchy"&gt;The Clean Path Forward — A Five-Tier Authentication Hierarchy&lt;/H2&gt;
&lt;P&gt;The Azure authentication model has a clear order of preference: use platform-managed identity where possible, use certificate-based service principals where you need external automation, and reserve Device Code Flow for cases where no stronger option is available.&lt;/P&gt;
&lt;P&gt;Here’s a five-tier decision framework for authenticating to Azure — ordered from preferred and durable to “only if you absolutely must.” This is also the practical interpretation of the guidance: Device Code Flow may exist in the toolbox, but it should sit at the bottom of the toolbox, not on the workbench.&lt;/P&gt;
&lt;H3 id="tier-1-managed-identity--the-gold-standard"&gt;Tier 1: Managed Identity — The Gold Standard&lt;/H3&gt;
&lt;P&gt;If your workload runs inside Azure — a virtual machine, an App Service, a Function App, an AKS workload using Microsoft Entra Workload ID, or an Azure Arc-enabled server — use the platform identity model wherever possible. There is no serious debate here.&lt;/P&gt;
&lt;P&gt;Managed Identity works by giving the Azure platform itself the responsibility of credential issuance and rotation. The workload requests a token from the Instance Metadata Service (IMDS) endpoint (&lt;CODE&gt;http://169.254.169.254/metadata/identity/oauth2/token&lt;/CODE&gt;), and Azure handles everything behind the scenes: certificate lifecycle, token signing, rotation. You never see a secret. You never store a secret. There is no secret to leak, rotate, audit, or accidentally commit to a GitHub repository.&lt;/P&gt;
&lt;P&gt;System-assigned Managed Identities are scoped to the lifecycle of the resource itself — they live and die with the VM or service. User-assigned Managed Identities give you reuse across multiple resources and more fine-grained RBAC control. For Azure Arc-connected machines, the Arc agent provisions a Managed Identity backed by a locally managed certificate in a protected directory, giving even on-premises and multi-cloud workloads access to this same zero-secret model.&lt;/P&gt;
&lt;P&gt;The operational rule: &lt;STRONG&gt;if your code or process runs on a platform that supports Managed Identity, using anything else is a conscious downgrade that requires justification.&lt;/STRONG&gt;&lt;/P&gt;
&lt;H3 id="tier-2-service-principal-with-certificate--the-right-tool-for-scale"&gt;Tier 2: Service Principal with Certificate — The Right Tool for Scale&lt;/H3&gt;
&lt;P&gt;ManagedIdentity isn’t available for every scenario. If you’re building a CI/CD pipeline in GitHub Actions, running an onboarding script from an on-premises orchestration platform, or automating Azure Arc server registration at scale across thousands of machines, you need a Service Principal — and you should be using &lt;STRONG&gt;certificate-based authentication&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;Here’s why certificates are usually stronger than secrets in the Service Principal world: certificates are easier to govern through a managed issuance and rotation process, and they avoid long-lived shared strings being copied across scripts, repositories, and build systems. Microsoft Entra Conditional Access for workload identities can also apply to selected service principals, subject to licensing and feature scope, with controls such as location-based restrictions and risk-based blocking. That is not the same policy surface as user Conditional Access, and managed identities are not covered by those workload identity policies.&lt;/P&gt;
&lt;P&gt;For Azure Arc onboarding specifically, scope your Service Principal to the minimum viable role: &lt;CODE&gt;Azure Connected Machine Onboarding&lt;/CODE&gt;. This built-in role grants exactly what the &lt;CODE&gt;azcmagent connect&lt;/CODE&gt; process needs — nothing more. It cannot read your Key Vault secrets, enumerate your subscriptions, or touch your production workloads. Least privilege isn’t just a best practice checkbox here; it’s your blast radius control.&lt;/P&gt;
&lt;P&gt;Certificates should be issued from a managed PKI, stored in protected certificate stores (never in flat files on shared drives), and rotated on a defined schedule. Integrate certificate lifecycle management with your existing PKI or use Azure Key Vault-backed certificates where possible.&lt;/P&gt;
&lt;H3 id="tier-3-service-principal-with-secret--the-acceptable-compromise"&gt;Tier 3: Service Principal with Secret — The Acceptable Compromise&lt;/H3&gt;
&lt;P&gt;Sometimes certificates are genuinely impractical. Legacy tooling, third-party integrations, or constrained environments may force your hand toward client secrets. This tier isn’t forbidden — but it carries an explicit operational contract.&lt;/P&gt;
&lt;P&gt;Client secrets &lt;STRONG&gt;must&lt;/STRONG&gt; be treated with the same discipline as passwords: stored in secrets management systems (Azure Key Vault, HashiCorp Vault, your CI/CD platform’s native secrets store), never hard-coded, never logged, and &lt;STRONG&gt;rotated on a defined cadence&lt;/STRONG&gt;. Microsoft Entra ID lets you set expiration periods — use them. Ninety-day rotation is a reasonable baseline; shorter is better for high-sensitivity workloads.&lt;/P&gt;
&lt;P&gt;Client secrets remain bearer credentials. If a secret is copied, an attacker can use it until it expires or is revoked, subject to workload identity controls and any other enforcement points in the environment.&lt;/P&gt;
&lt;H3 id="tier-4-interactive-browser--brokered-authentication--for-human-admins"&gt;Tier 4: Interactive Browser / Brokered Authentication — For Human Admins&lt;/H3&gt;
&lt;P&gt;When a human being is sitting at a keyboard performing administrative tasks — deploying resources, running &lt;CODE&gt;az&lt;/CODE&gt; CLI commands, executing PowerShell modules against Azure Resource Manager — the right authentication pattern is interactive browser or brokered authentication.&lt;/P&gt;
&lt;P&gt;The Azure CLI (&lt;CODE&gt;az login&lt;/CODE&gt;), Azure PowerShell (&lt;CODE&gt;Connect-AzAccount&lt;/CODE&gt;), and the Azure Portal all support this flow. On modern Windows workstations with the Web Account Manager (WAM) broker enabled, authentication is handled through the broker, which integrates directly with Windows Hello, device compliance state, and Primary Refresh Token (PRT) infrastructure. This means your Conditional Access policies — require compliant device, require MFA, require specific named locations — all apply and are enforced at login time.&lt;/P&gt;
&lt;P&gt;This is authentication that knows &lt;EM&gt;who&lt;/EM&gt; the user is, &lt;EM&gt;what device&lt;/EM&gt; they’re on, and &lt;EM&gt;whether that device meets your security baseline&lt;/EM&gt;. It’s the complete picture. Never suppress this flow with automation flags when a human is the actor.&lt;/P&gt;
&lt;H3 id="tier-5-device-code-flow--the-last-resort"&gt;Tier 5: Device Code Flow — The Last Resort&lt;/H3&gt;
&lt;P&gt;Device code flow (&lt;CODE&gt;az login --use-device-code&lt;/CODE&gt;, &lt;CODE&gt;Connect-AzAccount -UseDeviceAuthentication&lt;/CODE&gt;) should be treated as the last resort for Azure services and tools. It exists for a specific, narrow set of scenarios: headless Linux terminals, Windows Server Core deployments without a GUI, SSH sessions into remote systems where a browser genuinely cannot be launched, or constrained appliance and migration workflows where the product has no stronger supported option yet.&lt;/P&gt;
&lt;P&gt;In these cases, the operator signs in on a separate device and the initiating workload receives the token after authorization completes. That separation creates a control gap: Conditional Access evaluates the sign-in context of the device used for authentication, not necessarily the posture of the headless server, appliance, or remote shell that initiated the request.&lt;/P&gt;
&lt;P&gt;If you permit device code flow in your environment, do it deliberately: create a scoped Conditional Access exception, document the justification, and treat each use as a compliance event worth auditing. And ask yourself seriously whether Managed Identity or a Service Principal could solve the problem instead.&lt;/P&gt;
&lt;P&gt;Put plainly: if a workflow can use Managed Identity, brokered interactive authentication, or a certificate-based Service Principal, that is the route Microsoft customers should prefer. Device Code Flow is the exception path for constrained environments, not the recommended operating model for Azure.&lt;/P&gt;
&lt;H3 id="quick-decision-table"&gt;Quick Decision Table&lt;/H3&gt;
&lt;P&gt;When in doubt, consult this table before typing a single auth flag:&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Scenario&lt;/th&gt;&lt;th&gt;Recommended Pattern&lt;/th&gt;&lt;th&gt;Avoid&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;Azure VM / App Service&lt;/td&gt;&lt;td&gt;System-assigned or user-assigned Managed Identity&lt;/td&gt;&lt;td&gt;Service Principal with secret; Device Code Flow&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Azure Arc server process&lt;/td&gt;&lt;td&gt;Managed Identity via the Azure Arc agent identity model&lt;/td&gt;&lt;td&gt;Interactive login; hardcoded credentials&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Azure Arc onboarding at scale&lt;/td&gt;&lt;td&gt;Service Principal with certificate and the &lt;CODE&gt;Azure Connected Machine Onboarding&lt;/CODE&gt; role&lt;/td&gt;&lt;td&gt;Service Principal with secret; Global Administrator credentials&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Azure Migrate registration&lt;/td&gt;&lt;td&gt;Preconfigured Microsoft Entra application with certificate-based authentication&lt;/td&gt;&lt;td&gt;Device Code Flow as the default path; over-privileged roles&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Human admin task&lt;/td&gt;&lt;td&gt;Interactive browser or WAM brokered authentication with Conditional Access&lt;/td&gt;&lt;td&gt;Shared service accounts; suppressed MFA&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Linux / Server Core / headless CLI&lt;/td&gt;&lt;td&gt;Managed Identity where available, or Device Code Flow with a scoped Conditional Access exception&lt;/td&gt;&lt;td&gt;Persistent CLI sessions with cached tokens and no expiry&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;The hierarchy is deliberate. Every tier down represents a trade-off — more operational burden, less platform-enforced security, more human discipline required to compensate. The goal is to push as many of your workloads as possible to Tier 1, use Tier 2 for what Managed Identity can’t reach, and treat everything below that as a documented exception rather than a default pattern.&lt;/P&gt;
&lt;P&gt;Authentication choices are architectural decisions. Make them intentionally.&lt;/P&gt;
&lt;H2 id="hardening-your-tenant--what-administrators-must-do-today-and-why-your-cloud-is-not-a-hotel-tv"&gt;Hardening Your Tenant — What Administrators Must Do Today (And Why Your Cloud Is Not a Hotel TV)&lt;/H2&gt;
&lt;P&gt;The hardening work starts with visibility. Before blocking or allowing Device Code Flow, administrators need to know where it is already being used, which workflows depend on it, and which of those workflows can move to stronger authentication.&lt;/P&gt;
&lt;H3 id="action-1-inventory-current-usage--find-where-dcf-is-active-right-now"&gt;Action 1: Inventory Current Usage — Find Where DCF Is Active Right Now&lt;/H3&gt;
&lt;P&gt;You cannot harden what you cannot see. Start in &lt;STRONG&gt;Entra ID Sign-In Logs&lt;/STRONG&gt; and filter for authentication protocol equals &lt;CODE&gt;deviceCode&lt;/CODE&gt;. This will surface every user, application, and IP address currently relying on Device Code Flow across your tenant. Pay close attention to service accounts, unattended scripts, and any sign-ins originating from datacenter IP ranges — those are your highest-risk signals.&lt;/P&gt;
&lt;P&gt;If you haven’t already, flip your Conditional Access policies targeting DCF clients into &lt;STRONG&gt;report-only mode&lt;/STRONG&gt; first. This gives you a real-world blast radius assessment before you enforce a block. Surprises in production are exciting exactly once.&lt;/P&gt;
&lt;H3 id="action-2-classify-every-use-case--automation-or-genuine-terminal-fallback"&gt;Action 2: Classify Every Use Case — Automation or Genuine Terminal Fallback?&lt;/H3&gt;
&lt;P&gt;Not every Device Code Flow invocation is malicious, or even wrong. Walk through what you find in the logs and ask one honest question for each entry: &lt;EM&gt;Is this a human logging into a device with no keyboard, or is this a script pretending it has no other option?&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Genuine headless terminal scenarios — a shared kiosk, a network appliance with a PIN pad, a restricted industrial device — are legitimate. Everything else, especially recurring automated sign-ins from servers or pipelines, is a Service Principal waiting to be born.&lt;/P&gt;
&lt;H3 id="action-3-replace-repeatable-workflows-with-the-right-identity-primitive"&gt;Action 3: Replace Repeatable Workflows With the Right Identity Primitive&lt;/H3&gt;
&lt;P&gt;This is the most impactful action on the list. Every server onboarding script, appliance registration routine, and CI/CD pipeline that currently uses Device Code Flow should be migrated to one of two things:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Managed Identities&lt;/STRONG&gt; — for anything running inside Azure. Zero credentials. No rotation. No excuses.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Certificate-based Service Principals&lt;/STRONG&gt; — for workloads running outside Azure where Managed Identity isn’t available. Certificates are auditable, rotatable, and are not susceptible to this specific device-code phishing pattern.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If a team finds that migration difficult, treat it as an implementation gap to close, not as a reason to keep a weaker authentication pattern in place.&lt;/P&gt;
&lt;H3 id="action-4-scoped-exceptions-only--no-tenant-wide-free-passes"&gt;Action 4: Scoped Exceptions Only — No Tenant-Wide Free Passes&lt;/H3&gt;
&lt;P&gt;If you must allow Device Code Flow for a specific use case after completing Actions 1 through 3, then scope it surgically. Target specific named users, restrict to compliant or named network locations, and limit to the exact application that requires it. Attach strict sign-in monitoring alerts so that any deviation from the expected pattern pages someone immediately.&lt;/P&gt;
&lt;P&gt;Granting tenant-wide exceptions because one team has a legacy appliance is the organizational equivalent of leaving the front door of your office building unlocked because the mailroom needs early access. Scope it. Monitor it. Review it quarterly.&lt;/P&gt;
&lt;H3 id="action-5-improve-error-clarity--make-failures-actionable"&gt;Action 5: Improve Error Clarity — Make Failures Actionable&lt;/H3&gt;
&lt;P&gt;When Device Code Flow is blocked by a Conditional Access policy, the error experience can be difficult for operators to act on. If the message is opaque, teams either open a ticket without enough context or look for a workaround. Neither outcome helps the customer.&lt;/P&gt;
&lt;P&gt;Internal scripts and tooling should catch Conditional Access block errors and surface clear, prescriptive guidance. Suggested runtime error wording:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;EM&gt;“Device Code Flow authentication was blocked by your organization’s security policy. This workflow requires an identity with delegated permissions in an interactive session. For automated workloads, use a Managed Identity or a Service Principal with certificate-based authentication. Contact your identity platform team for migration assistance.”&lt;/EM&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;For product and documentation improvements, language like the following would help customers make safer choices:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;EM&gt;“Device Code Flow (RFC 8628) is designed for input-constrained devices such as smart TVs and kiosks. It is not recommended for automated scripts, CI/CD pipelines, or server-side processes. For unattended authentication scenarios, use Managed Identities for Azure-hosted workloads or certificate-based Service Principals for external workloads. Enabling Device Code Flow in enterprise environments without Conditional Access restrictions significantly increases phishing risk.”&lt;/EM&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Clear documentation prevents the next engineer from making the same mistake and helps customers choose the right authentication pattern earlier.&lt;/P&gt;
&lt;H3 id="the-hotel-tv--a-final-word"&gt;The Hotel TV — A Final Word&lt;/H3&gt;
&lt;P&gt;Let’s go back to where we started: you, in a hotel room, staring at a television that doesn’t have a keyboard, trying to log into Netflix. You pull out your phone, navigate to a short URL, type an eight-character code, and thirty seconds later you’re watching something you’ll regret staying up for. It is, genuinely, a delightful piece of user experience engineering. RFC 8628 solved a real problem elegantly, and for that use case — a constrained device, a human present in the room, a low-stakes personal account — Device Code Flow is perfectly appropriate.&lt;/P&gt;
&lt;P&gt;The problem is not Device Code Flow. The problem is transplanting a mechanism designed for hotel televisions into environments where a compromised token can exfiltrate production databases, pivot across subscriptions, and trigger regulatory breach notifications at three in the morning.&lt;/P&gt;
&lt;P&gt;Your enterprise Azure tenant is not a hotel TV. The stakes are not whether someone watches an extra episode before sleep. The stakes are your customers’ data, your company’s reputation, and in regulated industries, your legal exposure. Authentication mechanisms must be matched to the environment they protect — and an environment with that much at risk deserves better than a flow designed for leisure viewing.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Block Device Code Flow by default. Do not recommend it as the normal way to use Azure services or tools. Migrate automation to proper identity primitives. Grant exceptions only where the use case genuinely demands it, and monitor them relentlessly.&lt;/STRONG&gt; The elegance of the original protocol is not a reason to leave the door open. It is simply a reason to appreciate it on the television where it belongs — while you protect everything else with something far more serious.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2026 00:46:16 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/device-code-flow-the-gift-that-keeps-on-giving-to-attackers/ba-p/4540949</guid>
      <dc:creator>akyamaza</dc:creator>
      <dc:date>2026-07-27T00:46:16Z</dc:date>
    </item>
    <item>
      <title>Windows Forwarded Events connector with Windows Security Events NRT rules</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-sentinel/windows-forwarded-events-connector-with-windows-security-events/m-p/4540749#M12958</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We are testing Microsoft Sentinel using the official Windows Forwarded Events connector.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Environment&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;- Windows Server WEC&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;- Windows Event Forwarding&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;- Azure Arc&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;- Azure Monitor Agent&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;- Windows Forwarded Events connector&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Everything works correctly.&lt;/P&gt;&lt;P&gt;Forwarded security events are successfully ingested into the WindowsEvent table.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;- Event ID 1102&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;- Event ID 4732&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, the built-in Windows Security Events NRT Analytics Rules (Content Hub version 1.0.1) query only the SecurityEvent table.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;NRT Security Event log cleared&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-text-color-8"&gt;SecurityEvent&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-text-color-8"&gt;| where EventID == 1102&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As a result, forwarded events received through the Windows Forwarded Events connector never trigger these NRT rules.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Question:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this expected behavior?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should Windows Forwarded Events customers use a different set of analytics rules (ASIM or other templates), or should these built-in NRT rules also support WindowsEvent?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jul 2026 00:07:11 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-sentinel/windows-forwarded-events-connector-with-windows-security-events/m-p/4540749#M12958</guid>
      <dc:creator>enescalban</dc:creator>
      <dc:date>2026-07-26T00:07:11Z</dc:date>
    </item>
    <item>
      <title>What's New in Microsoft Entra: July 2026</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/what-s-new-in-microsoft-entra-july-2026/ba-p/4534631</link>
      <description>&lt;P&gt;Welcome to the July edition of our monthly newsletter, summarizing the latest news and developments in the exciting, ever-evolving world of Microsoft Entra.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;What went into General Availability (GA) since June 2026?&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/backup/overview" target="_blank"&gt;&lt;STRONG&gt;Microsoft Entra Backup and Recovery&lt;/STRONG&gt;&lt;/A&gt; - A&amp;nbsp;capability that helps organizations restore a tenant after accidental or malicious changes. On by default, it automatically backs up critical directory objects, including users, groups, applications, Service Principals, managed identities, Conditional Access policies, named locations, agent IDs, and authentication and authorization policies, so admins can return&amp;nbsp;to a known good state. The service takes daily backups of supported objects and retains them for 7 days with Microsoft Entra ID P1 or P2 licenses. Admins can view snapshots, compare changes, and run recovery jobs. This feature is a reliable safety net to minimize downtime and strengthen protection against misconfigurations and security incidents.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/id-governance/entitlement-management-access-package-assignments#directly-assign-any-identity" target="_blank"&gt;&lt;STRONG&gt;Direct admin assignment to external users using email address&lt;/STRONG&gt;&lt;/A&gt;&amp;nbsp;- Entitlement management admins can assign external users, not in the directory, to an access package with the user's email. Users are invited into the tenant as Guest users and are governed when Microsoft Entra ID Governance is configured.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/global-secure-access/concept-bring-your-own-device" target="_blank"&gt;&lt;STRONG&gt;Bring your own device (BYOD) support for the Global Secure Access Windows client using Microsoft Entra‑registered devices&lt;/STRONG&gt;&lt;/A&gt; - Enable&amp;nbsp;users and partners&amp;nbsp;to access corporate resources from their own devices. Administrators can assign the&amp;nbsp;Private Application&amp;nbsp;traffic profile to users with internal accounts, including&amp;nbsp;internal guest users. This removes the previous requirement for Windows devices to be domain‑joined.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/authentication/kerberos-server-key-rotation" target="_blank"&gt;&lt;STRONG&gt;Microsoft Entra Kerberos key rotation&lt;/STRONG&gt;&lt;/A&gt; - Improves reliability for environments by using incoming trust referral flows. The update enhances authentication resiliency during key rollover by validating referral tickets with primary and secondary Kerberos keys. This combination reduces the likelihood of authentication failures and minimizes disruption during rotation events.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/external-id/direct-federation#domainless-saml-idp-federation-preview" target="_blank"&gt;&lt;STRONG&gt;Domainless SAML federation with a SAML identity provider&lt;/STRONG&gt;&lt;/A&gt; - Enable external users to sign in to applications or workforce resources using their Identity Provider (IdP)-managed credentials, regardless of their email domain. With no need to match user email domains with preconfigured identity provider domains, this capability simplifies onboarding and access for external users, streamlines invitation redemption, and improves flexibility for cross-organization collaboration in Microsoft Entra.&lt;/P&gt;
&lt;H2&gt;New in Public Preview&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/conditional-access/howto-target-agent-identities" target="_blank"&gt;&lt;STRONG&gt;Strengthen AI agent security with Conditional Access&lt;/STRONG&gt;&lt;/A&gt; - Microsoft Entra Conditional Access has broader controls to secure AI agents that leverage&amp;nbsp;user&amp;nbsp;accounts. Administrators can target agent user accounts more precisely by including, or excluding, agents, or by using custom security attributes for dynamic grouping. Organizations can apply Conditional Access policies, based on agent risk, require compliant devices for agents running on managed endpoints, including Windows 365 for Agents, and enforce device, network, and platform-based access conditions. These enhancements extend Zero Trust protections to agent user accounts while using the familiar Conditional Access policy experience.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/hybrid/cloud-sync/how-to-ad-group-enforcement" target="_blank"&gt;&lt;STRONG&gt;Restrict AD group changes to Microsoft Entra provisioning&lt;/STRONG&gt;&lt;/A&gt; - Designate specific Active Directory (AD) groups so all modifications are managed through the Microsoft Entra provisioning service. This capability helps maintain consistency between Microsoft Entra ID and AD by ensuring group changes are centrally controlled. Reduce configuration drift and improve alignment across identity systems.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-10"&gt;&lt;SPAN class="lia-text-color-21"&gt;&lt;STRONG&gt;Generate unique aliases with custom call-outs&lt;/STRONG&gt;&lt;/SPAN&gt; &lt;/SPAN&gt;- Use custom call-outs with Azure Logic Apps during user provisioning to perform advanced attribute transformations that meet your organization's requirements. Custom call-outs can generate values such as unique employee aliases and are supported for create events in HR inbound, SaaS outbound, and cross-tenant synchronization provisioning flows in Microsoft Entra.&lt;/P&gt;
&lt;H2&gt;Announcements&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://support.microsoft.com/en-US/authenticator/jailbreak-root-detection-in-microsoft-authenticator" target="_blank"&gt;&lt;STRONG&gt;Jailbreak/root detection in Microsoft Authenticator&lt;/STRONG&gt;&amp;nbsp;&lt;/A&gt;- This feature strengthens security by preventing Microsoft Entra credentials from being added or used on jailbroken or rooted devices. Users move to compliant devices to continue using work or school accounts in Authenticator.&amp;nbsp;It is secure by default, requires no admin configuration, and applies to iOS and Android. Personal and third-party accounts are not affected.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Starting August 2026, Microsoft Authenticator on iOS will offer an improved backup and restore experience&lt;/STRONG&gt; - Users can back up account names securely by using iCloud and iCloud Keychain with end-to-end encryption. This experience includes work or school accounts, Microsoft personal accounts, and non-Microsoft accounts like Amazon or Google, also third-party time-based one-time password (TOTP). No other credentials are included in the backup. This update removes the need for a Microsoft personal account and simplifies device setup by automatically restoring account names on new iOS devices. Users manage the feature through iCloud settings&lt;/P&gt;
&lt;H2&gt;New guidance and information&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/app-provisioning/enable-scim-api" target="_blank"&gt;&lt;STRONG&gt;SCIM APIs available in U.S. Government Cloud&lt;/STRONG&gt;&lt;/A&gt; -&amp;nbsp;Microsoft Entra SCIM 2.0 APIs, which went into GA, in the public cloud, earlier in 2026, are available in Microsoft U.S. Government Cloud. Organizations can use standards-based SCIM operations to provision and manage users and groups in Microsoft Entra ID from external SCIM-compatible identity sources. Enable scalable identity lifecycle management, while you reduce the need for custom integrations.&lt;/P&gt;
&lt;H2&gt;Tell us what you think!&lt;/H2&gt;
&lt;P&gt;If you have feedback on this newsletter, fill out the dedicated &lt;A href="https://forms.office.com/Pages/ResponsePage.aspx?id=v4j5cvGGr0GRqy180BHbR3tZ6taaY2dAnA0rWwJeTkRUM1BUWjM5TjI5Sk1HME45TVVYOEdBNkJRNy4u" target="_blank"&gt;Microsoft Form&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;Blogs&lt;/H2&gt;
&lt;P&gt;Check out the latest blog posts on our &lt;A href="https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/bg-p/Identity" target="_blank"&gt;Microsoft Entra Blog&lt;/A&gt; and our &lt;A href="https://aka.ms/devblog/ms-entra" target="_blank"&gt;Microsoft Entra Identity Developer Blog&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;What's new in Microsoft Entra?&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/fundamentals/whats-new" target="_blank"&gt;Learn what is new with Microsoft Entra&lt;/A&gt;, such as the latest release notes, known issues, bug fixes, deprecation functionality, and upcoming changes. You can find &lt;A href="https://learn.microsoft.com/entra/fundamentals/whats-new-sovereign-clouds" target="_blank"&gt;releases specific for Sovereign Clouds&lt;/A&gt; on a dedicated release notes page.&lt;/P&gt;
&lt;H2&gt;Become a certified Microsoft Identity and Access Administrator&lt;/H2&gt;
&lt;P&gt;Check out the &lt;A href="https://learn.microsoft.com/credentials/certifications/exams/sc-300/" target="_blank"&gt;certification&lt;/A&gt; and related &lt;A href="https://learn.microsoft.com/credentials/certifications/identity-and-access-administrator/" target="_blank"&gt;training&lt;/A&gt; for the Microsoft Identity and Access Administrator available for customers and partners.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Martin Coetzer&lt;/P&gt;
&lt;P&gt;Principal Product Manager, Identity and Network Access, Customer Experience Engineering (CXE)&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/company/microsoft-entra" target="_blank"&gt;Microsoft Entra Community | LinkedIn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;⁠&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Fri, 24 Jul 2026 17:47:47 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/what-s-new-in-microsoft-entra-july-2026/ba-p/4534631</guid>
      <dc:creator>Martin_Coetzer</dc:creator>
      <dc:date>2026-07-24T17:47:47Z</dc:date>
    </item>
    <item>
      <title>Data Product Lineage not automatic</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-purview/data-product-lineage-not-automatic/m-p/4540343#M2882</link>
      <description>&lt;P&gt;Hi all i am new in Purview and I am trying to create a lineage with a Report--&amp;gt; Dataset--&amp;gt; Tables in Data Products however after adding report only dataset is shown, how can I view all tables of this dataset.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Only when I press open in fabric the Dataset the table list appears, how can I give permissions&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jul 2026 09:29:46 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-purview/data-product-lineage-not-automatic/m-p/4540343#M2882</guid>
      <dc:creator>davidfombella</dc:creator>
      <dc:date>2026-07-24T09:29:46Z</dc:date>
    </item>
    <item>
      <title>RestrictedTrafficInstall.ps1 Fails on Windows 10 IoT Enterprise LTSC 2021 with SKU Detection Error</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-baselines/restrictedtrafficinstall-ps1-fails-on-windows-10-iot-enterprise/m-p/4540340#M554</link>
      <description>&lt;P&gt;I am encountering an issue while deploying the&amp;nbsp;&lt;STRONG&gt;Restricted Traffic Limited Functionality Baseline&lt;/STRONG&gt; on a &lt;STRONG&gt;Windows 10 IoT Enterprise LTSC 2021&lt;/STRONG&gt; device and would like to confirm whether this OS edition is supported or if this is a known issue with the baseline script.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Operating System:&lt;/STRONG&gt; Windows 10 IoT Enterprise LTSC 2021&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;EditionID:&lt;/STRONG&gt; IoTEnterpriseS&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;DisplayVersion:&lt;/STRONG&gt; 21H2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;...\RestrictedTrafficInstall.ps1 : Could not get SKU of current running OS.&lt;/P&gt;&lt;P&gt;CategoryInfo&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : NotSpecified: (:) [Write-Error], WriteErrorException&lt;/P&gt;&lt;P&gt;FullyQualifiedErrorId : Microsoft.PowerShell.Commands.WriteErrorException,RestrictedTrafficInstall.ps1&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jul 2026 09:27:57 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-baselines/restrictedtrafficinstall-ps1-fails-on-windows-10-iot-enterprise/m-p/4540340#M554</guid>
      <dc:creator>NiteshK</dc:creator>
      <dc:date>2026-07-24T09:27:57Z</dc:date>
    </item>
    <item>
      <title>Modernize SAP Identity Management with Microsoft Entra</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/modernize-sap-identity-management-with-microsoft-entra/ba-p/4528596</link>
      <description>&lt;P&gt;Many organizations are rethinking how they manage identity across their SAP landscape as they move away from on-premises identity management systems and adopt a more unified cloud strategy. That shift often starts with a practical question: how do you connect SAP identity processes with the rest of your application estate without introducing more complexity?&lt;/P&gt;
&lt;P&gt;That is where the ongoing work between Microsoft Entra and SAP can help. Over the past several years, we have continued to expand integration points that help organizations automate lifecycle changes, apply access policies more consistently, and strengthen governance across SAP and non-SAP applications.&lt;/P&gt;
&lt;P&gt;If you are transitioning from SAP Identity Management (SAP IDM), modernizing an existing SAP identity architecture, or looking for better access governance across business-critical systems, the &lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/scenarios/migrate-from-sap-idm" target="_blank" rel="noopener"&gt;latest integrations&lt;/A&gt; in Microsoft Entra can help.&lt;/P&gt;
&lt;P&gt;In this post, I’ll highlight what’s new, recap the key integration points, and explain how these capabilities can support your identity modernization journey.&lt;/P&gt;
&lt;H2&gt;What’s new in Microsoft Entra and SAP integrations&lt;/H2&gt;
&lt;P&gt;Over the &lt;A href="https://techcommunity.microsoft.com/discussions/microsoft-entra/new-blog--sap-identity-management-to-microsoft-entra-id-migration-guidance-now-a/4164406" target="_blank" rel="noopener"&gt;past two years&lt;/A&gt;, Microsoft Entra and SAP have continued to deepen interoperability and support more deployment models. Key updates include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;More flexible provisioning patterns between Microsoft Entra and SAP Cloud Identity Services&lt;/LI&gt;
&lt;LI&gt;Support for custom extension attributes on Microsoft Entra users for SAP-specific scenarios&lt;/LI&gt;
&lt;LI&gt;Account discovery to identify accounts in SAP Cloud Identity Services that are not yet correlated with users in Microsoft Entra&lt;/LI&gt;
&lt;LI&gt;OAuth 2.0 client credentials support to secure service-to-service communication between Microsoft Entra and SAP Cloud Identity Services&lt;/LI&gt;
&lt;LI&gt;Integration between Microsoft Entra ID Governance and SAP Identity Access Governance (SAP Identity Access Governance), so organizations can request and govern SAP business roles alongside other access rights&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Together, these capabilities help organizations create a more unified identity control plane across SAP and the rest of the enterprise.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;“This partnership brings together the best of both worlds: Microsoft Entra’s identity-first foundation and SAP Access Governance’s (SAP Identity Access Governance and SAP Access Control) deep business and access risk context, enriched with AI to transform access governance into a continuous, intelligent trust model.”&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Swetta Singh, Strategic Product Manager for Access Governance solutions, SAP&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;A centralized identity control plane for SAP and beyond&lt;/H2&gt;
&lt;P&gt;Microsoft Entra provides a centralized identity layer that integrates with SAP applications and platforms. With it, organizations can automate joiner, mover, and leaver processes, apply access policies more consistently, and strengthen governance across a broader set of systems.&lt;/P&gt;
&lt;P&gt;That kind of consistency matters in complex environments. For example, &lt;A href="https://www.microsoft.com/en/customers/story/26155-cenibra-celulose-nipo-brasileira-sa-microsoft-entra-id-governance" target="_blank" rel="noopener"&gt;Cenibra&lt;/A&gt; used Microsoft Entra ID Governance to modernize identity management across more than 80 systems, including SAP as a core platform. That approach helped reduce manual work, improve audit readiness, and create a more scalable foundation for managing access.&lt;/P&gt;
&lt;H2&gt;SAP Cloud Identity Services: More flexible provisioning&lt;/H2&gt;
&lt;P&gt;SAP Cloud Identity Services centralizes authentication and provisioning across SAP applications. It provides single sign-on and helps organizations provision users and groups more consistently to downstream SAP systems.&lt;/P&gt;
&lt;P&gt;The latest integration improvements with Microsoft Entra give organizations more flexibility in synchronizing users and groups across both environments through standards-based approaches. This flexibility helps teams maintain consistent identity data between Microsoft Entra and SAP environments while using SAP Cloud Identity Services to distribute identities to downstream cloud-hosted and on-premises SAP applications.&lt;/P&gt;
&lt;P&gt;Some of the recent updates include:&lt;/P&gt;
&lt;H3&gt;Custom extension attributes for SAP-specific scenarios&lt;/H3&gt;
&lt;P&gt;Many SAP environments depend on attributes tied to business processes, regions, or organizational structures. Microsoft Entra now supports provisioning custom extension attributes on users in those scenarios, making it easier to align identity data with the needs of SAP applications.&lt;/P&gt;
&lt;H3&gt;Account discovery for SAP Cloud Identity Services&lt;/H3&gt;
&lt;P&gt;Microsoft Entra account discovery retrieves accounts from SAP Cloud Identity Services so you can identify accounts that are not yet correlated with users in Microsoft Entra. This visibility can help teams reduce manual investigation and strengthen governance.&lt;/P&gt;
&lt;H3&gt;OAuth 2.0 client credentials for connector authentication&lt;/H3&gt;
&lt;P&gt;We have also updated connector authentication to use OAuth 2.0 client credentials. This change helps secure service-to-service communication between Microsoft Entra and SAP Cloud Identity Services and supports a more modern integration approach.&lt;/P&gt;
&lt;H2&gt;SAP Identity Access Governance integration&lt;/H2&gt;
&lt;P&gt;SAP Identity Access Governance is SAP’s cloud-based access governance solution. The integration between Microsoft Entra ID Governance and SAP Identity Access Governance connects SAP role governance to a broader access strategy, allowing users to request or receive SAP business roles through Microsoft Entra access packages alongside non-SAP access rights.&lt;/P&gt;
&lt;P&gt;This integration matters because access governance often spans applications: employees, contractors, and partners may need coordinated access across SAP and non-SAP resources. Organizations can use the integration to manage those requests consistently across applications.&lt;/P&gt;
&lt;P&gt;When a user requests assignment to an access package with an SAP business role through Microsoft Entra, the request is sent automatically to SAP Identity Access Governance. SAP Identity Access Governance then enforces approvals and additional checks within its own governance process. This approach helps organizations connect enterprise-wide access packages in Microsoft Entra with the business role and risk context available in SAP Identity Access Governance.&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Microsoft Entra integrates with SAP Cloud Identity Services and SAP Identity Access Governance to support authentication, user provisioning, and identity governance across SAP applications.&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;Migration projects move faster with the right partner support&lt;/H2&gt;
&lt;P&gt;A successful transition from legacy IAM products such as SAP IDM often depends on practical experience across both SAP environments and enterprise identity platforms. Many organizations work with partners who can support SAP system integration, Microsoft Entra identity and governance capabilities, and identity strategies that connect SAP with the rest of the application estate.&lt;/P&gt;
&lt;P&gt;If you are planning a migration and want to involve a partner, review the partner list in &lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/scenarios/migrate-from-sap-idm" target="_blank" rel="noopener"&gt;Migrate identity management scenarios from SAP IDM to Microsoft Entra&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;Beyond identity: Microsoft Security for SAP&lt;/H2&gt;
&lt;P&gt;Identity establishes the foundation for securing SAP in your security environment. In addition to Microsoft Entra, Microsoft delivers SAP-aware capabilities aligned with the NIST Cybersecurity Framework:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Identify&lt;/STRONG&gt;: Microsoft Purview discovers and classifies sensitive SAP data—including data mirrored into Microsoft Fabric through SAP Datasphere—helping organizations apply more consistent data security policies.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Protect&lt;/STRONG&gt;: Microsoft Defender safeguards the endpoints, servers, and cloud resources surrounding SAP applications with continuous, adaptive controls.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Detect&lt;/STRONG&gt;: &lt;SPAN data-teams="true"&gt;Microsoft Sentinel connects SAP signals across your estate to detect incidents, with built-in analytics rules in an SAP-certified solution that cover known threats. Through strategic partnership with SAP, organizations can also incorporate security telemetry from SAP Enterprise Threat Detection (ETD) and SAP LogServ, providing broader visibility into SAP-specific threats and activities alongside the rest of the enterprise security estate&lt;/SPAN&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Respond&lt;/STRONG&gt;: Microsoft Security Copilot accelerates investigation and guides response, helping teams contain SAP incidents faster.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Together with the identity investments described above, these capabilities advance an identity-first Zero Trust strategy across the SAP environment. Microsoft uses these same capabilities across its global SAP estate.&lt;/P&gt;
&lt;H2&gt;Get started&lt;/H2&gt;
&lt;P&gt;If you are evaluating your SAP identity strategy, now is a good time to review how your current architecture maps to the latest integration options in Microsoft Entra.&lt;/P&gt;
&lt;P&gt;Start with these resources:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/MigrateFromSAPIDM" target="_blank" rel="noopener"&gt;Read the SAP IDM to Microsoft Entra migration guidance&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/sap" target="_blank" rel="noopener"&gt;Manage access to your SAP applications&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://demos.microsoft.com/Microsoft/play/6373/securing-sap-workloads-end-to-end-protection-with-microsoft-security#/0/0" target="_blank" rel="noopener"&gt;Watch a demo of Securing SAP Workloads: End-to-End Protection with Microsoft Security&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;As always, I would love to hear about your SAP identity modernization journey and the topics you would like us to cover next.&lt;/P&gt;
&lt;P&gt;Thanks for reading,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Mark Wahl&lt;BR /&gt;Product Architect, Microsoft Entra&lt;BR /&gt;&lt;A href="https://www.linkedin.com/in/mawahl/" target="_blank" rel="noopener"&gt;Mark Wahl | LinkedIn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en/customers/story/26155-cenibra-celulose-nipo-brasileira-sa-microsoft-entra-id-governance" target="_blank" rel="noopener"&gt;Microsoft ID Governance Case Study&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/app-provisioning/plan-sap-user-source-and-target" target="_blank" rel="noopener"&gt;Plan deploying Microsoft Entra for user provisioning with SAP | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;⁠&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jul 2026 17:54:07 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/modernize-sap-identity-management-with-microsoft-entra/ba-p/4528596</guid>
      <dc:creator>Mark_Wahl</dc:creator>
      <dc:date>2026-07-24T17:54:07Z</dc:date>
    </item>
    <item>
      <title>Understanding Microsoft 365 Copilot Risk Surface and Mitigations</title>
      <link>https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/understanding-microsoft-365-copilot-risk-surface-and-mitigations/ba-p/4538712</link>
      <description>&lt;P&gt;It’s a shift that carries important security implications organizations should understand&amp;nbsp;before scaling deployment.&amp;nbsp;Customers with Microsoft 365 E5 licensing may already have access to many of the tools that can help identify and reduce Copilot-related risk, but licensing alone does not reduce exposure.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What’s often missing during early Copilot deployments is a clear understanding of the risk surface itself: &lt;EM&gt;what data is exposed, who can access it, and &lt;/EM&gt;t&lt;EM&gt;hrough which vectors&lt;/EM&gt;.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Organizations beginning their Zero Trust journey can use the Zero Trust Workshop to assess their current posture, identify gaps, and better understand how existing permissions and governance impact Copilot readiness. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;In this post, we take a broader look at the types of risks Copilot can amplify and how those risks align to key Zero Trust pillars.&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Why Copilot changes the risk conversation&lt;/H2&gt;
&lt;P&gt;Before assessing specific risks, it's worth understanding why AI solutions like Copilot introduce a different risk conversation than traditional Microsoft 365 applications.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Most enterprise applications operate within a bounded context. A user opens a file, reads an email, or searches a SharePoint one item at a time. The time and effort required to manually locate, connect, and synthesize information across systems creates a natural friction layer. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;While that friction was never designed as a formal security control, it did create a practical limit on how quickly users could surface and act on organizational data at scale.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Microsoft 365 Copilot removes much of that friction entirely. It operates at the speed of a prompt across the full scope of a user's access rights, synthesizing information from emails, files, meetings, chats, and other Microsoft 365 data sources into a single response.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The exposure is not the result of new permissions; it comes from how quickly and easily existing access can be discovered and aggregated. In short, Copilot makes data once hidden by volume discoverable by intent.&lt;/P&gt;
&lt;H2&gt;Use Zero Trust to assess Copilot risk&lt;/H2&gt;
&lt;P&gt;Zero Trust rests on three principles: &lt;STRONG&gt;verify explicitly&lt;/STRONG&gt;, &lt;STRONG&gt;use least-privileged access&lt;/STRONG&gt;, and &lt;STRONG&gt;assume breach&lt;/STRONG&gt;. Rather than trusting users or devices by network location, it requires continuous validation of every user, endpoint, and request. This analysis focuses on the four pillars most directly involved in Copilot deployments.&lt;/P&gt;
&lt;P&gt;Together, these pillars answer three questions: who can access Copilot; from which endpoints and applications; and what data Copilot can surface once access is granted.&lt;/P&gt;
&lt;H2&gt;The two-layer Copilot risk model&lt;/H2&gt;
&lt;P&gt;The foundation is simple: Copilot acts as a force multiplier for whatever access a user already has. If that access is governed well, Copilot improves productivity; if not, it amplifies exposure. Risk is therefore examined in two layers — access to the Copilot service itself, and access to the data Copilot can ground on and surface.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;MICROSOFT 365 COPILOT&amp;nbsp; ·&amp;nbsp; TWO-LAYER RISK MODEL&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 70.2778%; border-width: 1px;"&gt;&lt;colgroup&gt;&lt;col style="width: 43.6545%" /&gt;&lt;col style="width: 56.3455%" /&gt;&lt;/colgroup&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td colspan="2"&gt;&lt;STRONG&gt;Layer-1 Access Risk&lt;/STRONG&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;Identity&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;&lt;STRONG&gt;Device&lt;/STRONG&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Who can access copilot&lt;/td&gt;&lt;td&gt;From which devices&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Under what conditions&lt;/td&gt;&lt;td&gt;Device compliance posture&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="2"&gt;&lt;STRONG&gt;Layer-2 Data &amp;amp; Governance Risk&lt;/STRONG&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;Apps&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;&lt;STRONG&gt;Data&lt;/STRONG&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;What copilot can access and surface&lt;/td&gt;&lt;td&gt;Sharing and permissions&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Connected data sources&lt;/td&gt;&lt;td&gt;Labeling, classification, output context&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Table-1:&lt;/STRONG&gt; Two-layer model for Microsoft 365 Copilot risk&lt;/EM&gt;&lt;/P&gt;
&lt;H1&gt;Risk Layer-1: Who can access Microsoft 365 Copilot?&lt;/H1&gt;
&lt;P&gt;The first layer of risk begins at the point of entry: the conditions that determine whether a user can access Copilot. Organizations don’t need to address every potential exposure point at once. Think of the following table as a map of where exposure &lt;EM&gt;can&lt;/EM&gt; exist across identity and device controls. For details of how remediation works for this layer of risks; you may refer to the blog post: &lt;A href="https://techcommunity.microsoft.com/blog/fasttrackblog/mitigating-microsoft-365-copilot-access-risk-identity-and-device-controls-for-ze/4534574" target="_blank" rel="noopener"&gt;Mitigating Microsoft 365 Copilot access risk: Identity and device controls for Zero Trust.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The following risks are primarily governed by the Identity and Devices pillars of Zero Trust and define whether Copilot is being accessed by the right person, from a trusted device, under appropriate authentication and access conditions.&amp;nbsp;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 948px; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Risk&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Pillar&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Description&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;R1&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Unmanaged identity access&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Identity&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;A compromised, shared, or former employee account can authenticate to Microsoft 365 and access Copilot. Because Copilot operates across the full scope of a user’s permissions, compromised accounts expose a much larger&amp;nbsp;risk surface than before Copilot existed. Strong account hygiene and identity lifecycle management therefore directly reduce Copilot exposure.&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;R2&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Weak or absent multi-factor authentication&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Identity&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;If organizations do not enforce MFA, or if legacy authentication bypasses modern sign-in controls, users can start Copilot sessions using only a password. In environments with inconsistent MFA coverage, attackers may need only&amp;nbsp;stolen credentials to gain access. Because Copilot synthesizes data across services, compromised accounts create significantly greater risk than access to a single application.&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;R3&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Unmanaged or non-compliant devices&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Devices&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Users can access Copilot through browsers and native applications from any device where they can authenticate. Unmanaged devices without EDR coverage, disk encryption enforcement, or compliance posture evaluation can expose Copilot sessions and allow attackers or unauthorized users to store or exfiltrate outputs locally.&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;R4&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;License sprawl without role-based scoping&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Identity &amp;amp; Apps&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Enterprise Copilot pilots often start with broad license assignments across departments, floors, or business units instead of deliberate, security-reviewed pilot groups. When organizations assign licenses without reviewing each user’s access rights, permission posture, and role sensitivity, Copilot can amplify risk across both highly governed and minimally governed users. Broad pilot enrollment without access review is itself a risk factor.&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;R5&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Missing real-time risk evaluation at sign-in&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Identity &amp;amp; Devices&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;If Conditional Access does not evaluate sign-in and user risk signals—such as impossible travel, anomalous token activity, or identity protection alerts—high-risk sessions may still gain access to Copilot. Without real-time risk gating, controls respond only after access is granted, by which point Copilot may already have surfaced and synthesized sensitive content.&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;R6&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;App protection gap on mobile devices&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Devices &amp;amp; Apps&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Users can access Microsoft 365 Copilot mobile—and the broader Microsoft 365 mobile surface that exposes Copilot—from personal devices that are not enrolled in MDM or MAM. Without an application protection policy, organizations cannot prevent users from copying Copilot outputs into unmanaged apps, remotely wipe organizational data from lost devices, or restrict screenshots and screen recordings during Copilot sessions containing sensitive data.&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 101px" /&gt;&lt;col style="width: 236px" /&gt;&lt;col style="width: 155px" /&gt;&lt;col style="width: 456px" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Table - 2: &lt;/STRONG&gt;&lt;/EM&gt;Risks in Layer-1: Who can access Microsoft 365 Copilot&lt;/P&gt;
&lt;H2&gt;Key observations from Layer 1:&amp;nbsp;&lt;/H2&gt;
&lt;P&gt;Identity appears most frequently across Layer 1 risks, reflecting how tightly Copilot access depends on authenticated user permissions and sign-in conditions. Device-related risks also play a major role because unmanaged or non-compliant endpoints can expose Copilot sessions and outputs beyond the organization’s trusted environment.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Together, these risks highlight a central theme: securing Copilot access is not just about controlling who can sign in, but also validating the devices, conditions, and access patterns associated with every session.&amp;nbsp;&lt;/P&gt;
&lt;H1&gt;Risk layer 2: What data can Microsoft 365 Copilot reach?&amp;nbsp;&lt;/H1&gt;
&lt;P&gt;The second layer of risk assumes that the user is already authenticated and actively using Copilot.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At this stage, the focus shifts from who can access Copilot to what data Copilot can surface on the user’s behalf.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These risks reflect the full scope of data exposure created by existing permissions, overshared content, connected systems, and governance gaps. &amp;nbsp;Layer 2 risks are governed primarily by the Apps and Data pillar, with Identity playing a secondary role in defining the scope of data each user can access.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For mitigating risks in this layer, you may refer to the blog post: &lt;A href="https://techcommunity.microsoft.com/blog/fasttrackblog/limiting-microsoft-365-copilot-data-exposure-risk-with-zero-trust-apps-and-data-/4534642" target="_blank" rel="noopener"&gt;Limiting Microsoft 365 Copilot data exposure risk with Zero Trust apps and data controls.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 939px; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Risk&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;Pillar&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Description&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;R7&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Overshared SharePoint and OneDrive content&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Apps &amp;amp; Identity&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Content shared with "Everyone," "Everyone except external users," or broad groups becomes part of Copilot’s query able surface for any licensed user, even if that user would never have found those files manually. Years of SharePoint oversharing, combined with Copilot’s ability to traverse and synthesize content in a single prompt, can turn long-standing governance debt into immediate exposure. Copilot makes data once hidden by volume, discoverable by intent.&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;R8&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Sensitivity label gaps&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Apps &amp;amp; Data&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Microsoft Purview sensitivity labels tell Copilot how to handle content, including whether it can summarize, cite, or include that content in responses. Leaving content unlabeled, mislabeling, or miss inheriting labels across containers such as SharePoint sites and Teams, Copilot treats the content as unclassified and may surface it freely. Many enterprise tenants still contain large volumes of unlabeled legacy content, and Copilot cannot infer classification on its own.&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;R9&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Excessive user permissions&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Identity &amp;amp; Apps&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Like overshared content, Copilot follows each user’s existing Microsoft Graph permissions and does not surface content users cannot access. In many enterprise environments, however, users accumulate access far beyond their current role through leftover project permissions, broad temporary group memberships, and inherited rights from outdated organizational structures. Copilot does not create this overprovisioning, but it makes the full scope of that access immediately visible and usable.&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;R10&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;No DLP coverage on Copilot-generated outputs&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Apps &amp;amp; Data&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Copilot outputs—including summaries, drafts, and synthesized answers—are generated content, and traditional DLP policies do not always preserve links to original source data.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Users may receive Copilot responses containing aggregated PII, financial data, or confidential project details and paste that information into emails, Teams messages, or external documents without triggering DLP policies designed to detect the original source files. As content shifts from source material to generated output, organizations often lose the underlying sensitivity context.&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;R11&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Plugin and connector data surface expansion&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Apps &amp;amp; Identity&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Organizations can extend Microsoft 365 Copilot through plugins and Microsoft Graph connectors that pull external data from CRM systems, ITSM platforms, HR applications, and custom line-of-business tools. Each connector expands the data surface Copilot can query on a user’s behalf and often reaches into systems whose access control models do not align natively with Microsoft 365 permissions.&amp;nbsp;As organizations add connectors, each connected source introduces governance and audit risk that expands alongside the broader Copilot data surface.&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;R12&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Audit and visibility gap&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Apps &amp;amp; Data&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Organizations need visibility into what users asked Copilot, what data Copilot accessed, , and what responses it generated to maintain an effective security posture for both incident response and risk monitoring. Disabling Copilot interaction logging, retaining audit logs for too short a period, or failing to forward logs to a SIEM, obscures the organization’s visibility into how users interact with Copilot, whether Copilot surfaces unexpected content, and whether activity may indicate compromise. Without audit data, organizations cannot reliably detect misuse or investigate incidents.&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;R13&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Privileged user data amplification&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Identity, Apps &amp;amp; Data&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Administrators, senior IT staff, and other privileged users often hold access that spans organizational boundaries, including mailboxes, site collections, security groups, and configuration data that most users never access.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A compromised admin account with Copilot access gives adversaries an organization-wide view of data that far exceeds the exposure associated with a compromised end-user account. Organizations therefore need to apply the strictest Copilot access governance to privileged identities.&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 101px" /&gt;&lt;col style="width: 213px" /&gt;&lt;col style="width: 183px" /&gt;&lt;col style="width: 441px" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Table – 3:&lt;/STRONG&gt;&lt;/EM&gt; Layer-2 Risks: What data can Microsoft 365 Copilot reach?&lt;/P&gt;
&lt;H2&gt;Key observations from Layer 2:&amp;nbsp;&lt;/H2&gt;
&lt;P&gt;Apps-related risks appear throughout Layer 2 because Microsoft 365 Copilot depends heavily on connected systems, accessible data sources, and governance over generated outputs. The Data pillar further emphasizes the need to protect not only sensitive source content but also AI-generated responses that aggregate and surface information across systems.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The table above maps each identified risk to its primary and secondary Zero Trust pillars. Primary pillars represent control areas that most directly govern a given risk, while secondary pillars represent contributing dimensions.&amp;nbsp;&lt;/P&gt;
&lt;H1&gt;Conclusion &amp;amp; next steps&lt;/H1&gt;
&lt;P&gt;Copilot typically does not grant broader access than a user already has — it makes existing access easier to discover, connect, and use across Microsoft 365. Organizations that successfully scale Copilot are the ones that understand and govern that access first.&lt;/P&gt;
&lt;P&gt;Reducing Copilot data exposure is not a one-time cleanup; it is a continuous governance posture. Oversharing accumulates, labels drift, permissions grow, and connectors are added. Together, the Layer 1 and Layer 2 controls in this guide create the feedback loops that keep the risk surface governed as the organization and its use of Copilot evolve — governing not only who can access the service, but what it can reach on their behalf.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;WHERE TO GO NEXT&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Assess your current posture: &lt;/STRONG&gt;Zero Trust Workshop — &lt;A href="http://zerotrust.microsoft.com" target="_blank" rel="noopener"&gt;http://zerotrust.microsoft.com&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Understand the framework: &lt;/STRONG&gt;Zero Trust Overview on Microsoft Learn (&lt;A href="http://learn.microsoft.com/security/zero-trust" target="_blank" rel="noopener"&gt;http://learn.microsoft.com/security/zero-trust&lt;/A&gt;)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2026 15:37:20 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/understanding-microsoft-365-copilot-risk-surface-and-mitigations/ba-p/4538712</guid>
      <dc:creator>AtilGurcan</dc:creator>
      <dc:date>2026-07-23T15:37:20Z</dc:date>
    </item>
    <item>
      <title>Best practices: Open OneDrive/SharePoint sharing but restrict Teams guest access by domain</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/best-practices-open-onedrive-sharepoint-sharing-but-restrict/m-p/4540110#M10414</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;Since SharePoint Online and OneDrive moved fully to Microsoft Entra B2B for external sharing, we've run into a policy conflict and would like to hear how others are handling it.&lt;/P&gt;&lt;H4&gt;Our requirements&lt;/H4&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Enable OneDrive and SharePoint file sharing with external users, regardless of their email domain.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Restrict Microsoft Teams guest access to a predefined list of approved partner domains.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Continue allowing Teams external access (federated chat and meetings) for all domains.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;H4&gt;The problem:&lt;/H4&gt;&lt;UL&gt;&lt;LI&gt;Teams guests, SharePoint guests, and OneDrive guests are now governed by the same Microsoft Entra B2B invitation framework and the single&amp;nbsp;&lt;STRONG&gt;Collaboration restrictions&lt;/STRONG&gt; allow/deny list under:&lt;BR /&gt;&lt;STRONG&gt;External Identities → External collaboration settings&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;As a result, restricting guest invitations by domain also restricts OneDrive and SharePoint sharing for domains not on the allowlist.&lt;/LI&gt;&lt;LI&gt;According to Microsoft's response in the following Q&amp;amp;A, this behavior is currently &lt;STRONG&gt;by design&lt;/STRONG&gt;:&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/answers/questions/5954975/onedrive-external-sharing-no-longer-working-with-a" target="_blank"&gt;OneDrive external sharing no longer working with "Allow invitations only to the specified domains" - Microsoft Q&amp;amp;A&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;H4&gt;Questions to the community&lt;/H4&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;Has anyone implemented a solution where OneDrive/SharePoint sharing remains open to all domains while Teams guest access is restricted to approved domains only?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Are there recommended approaches using Entitlement Management, Access Packages, Connected Organizations, or other Entra capabilities?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;Is there any roadmap item for workload-specific collaboration restrictions (e.g., separate policies for Teams guest invitations and SharePoint/OneDrive sharing)?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Any real-world experience or best practices would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Bejhan&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jul 2026 05:49:11 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/best-practices-open-onedrive-sharepoint-sharing-but-restrict/m-p/4540110#M10414</guid>
      <dc:creator>Bejhan</dc:creator>
      <dc:date>2026-07-24T05:49:11Z</dc:date>
    </item>
    <item>
      <title>Should You Use the New Microsoft Entra Tenant Governance or Azure Lighthouse? (part 3 of 3)</title>
      <link>https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/should-you-use-the-new-microsoft-entra-tenant-governance-or/ba-p/4532297</link>
      <description>&lt;P&gt;In&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/implementing-azure-lighthouse-a-technical-guide-for-service-providers-and-enterp/4490592" target="_blank" rel="noopener"&gt;Part 1&lt;/A&gt;&amp;nbsp;we built Azure Lighthouse the technical way. In&amp;nbsp;Part 2,&amp;nbsp;&lt;EM&gt;"&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/azure-lighthouse-bring-your-partner-in-without-letting-their-identities-in-part-/4529852" target="_blank" rel="noopener" data-lia-auto-title="Bring Your Partner In, Without Letting Their Identities In" data-lia-auto-title-active="0"&gt;Bring Your Partner In, Without Letting Their Identities In&lt;/A&gt;,"&lt;/EM&gt; we made the security case for it: let a service provider operate a customer's Azure resources without creating any identity in the customer's tenant.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This third part introduces another, newly available delegation model&amp;nbsp;&lt;STRONG&gt;Microsoft Entra Tenant Governance&lt;/STRONG&gt;&amp;nbsp;and helps you to answer the question:&amp;nbsp;&lt;EM&gt;which one do I use, and when?&lt;/EM&gt;. If you already know Lighthouse, you have everything you need to follow along - If not, catch up on the previous two articles. While most of the focus will be on Microsoft Entra Tenant Governance, we will compare and contrast it with Azure Lighthouse.&lt;/P&gt;
&lt;P&gt;There's one idea that makes the whole comparison click:&amp;nbsp;&lt;STRONG&gt;the two models project access in opposite directions.&lt;/STRONG&gt;&lt;/P&gt;
&lt;H2 class="lia-linked-item"&gt;&lt;a id="community--1-One" class="lia-anchor"&gt;&lt;/a&gt;1. Azure Lighthouse, and its boundary&lt;/H2&gt;
&lt;P&gt;As a brief refresher, &lt;SPAN class="lia-text-color-21"&gt;Azure&lt;/SPAN&gt; Lighthouse lets a service provider manage a customer's Azure resources (subscriptions and resource groups) from the provider's own tenant. The provider's users never get an account in the customer's directory and never become guests there; instead, the customer's subscriptions and resource groups are &lt;EM&gt;delegated&lt;/EM&gt;&amp;nbsp;to the provider through Azure Resource Manager, and the provider operates them with their&amp;nbsp;home credentials&amp;nbsp;(&lt;A href="https://learn.microsoft.com/en-us/azure/lighthouse/concepts/architecture" target="_blank" rel="noopener"&gt;Azure Lighthouse architecture&lt;/A&gt;). No identity sprawl, no extra license, no charge (&lt;A href="https://learn.microsoft.com/en-us/azure/lighthouse/overview" target="_blank" rel="noopener"&gt;Azure Lighthouse overview&lt;/A&gt;).&lt;/P&gt;
&lt;P class="lia-align-left"&gt;Lighthouse is&amp;nbsp;scoped to the Azure Resource Manager control plane. It delegates&amp;nbsp;&lt;EM&gt;resources from subscriptions or resource groups such as&lt;/EM&gt; virtual machines, storage, networking, policy, and Sentinel workspaces. It does not grant Microsoft Entra directory roles, it does not reach resource data planes such as Storage blob data or Key Vault secrets, and it doesn't reach Microsoft 365 (&lt;A href="https://learn.microsoft.com/en-us/azure/lighthouse/concepts/cross-tenant-management-experience" target="_blank" rel="noopener"&gt;cross-tenant management experience&lt;/A&gt;).&lt;/P&gt;
&lt;P&gt;But it leaves a real question open. What happens when the partner (or an enterprise with multiple tenants) legitimately needs access to the directory, to read identity configuration, run security operations, administer users, or govern identities, and not just the resource estate? Lighthouse, by design, can't take you there. That's the gap the second model fills.&lt;/P&gt;
&lt;H2 class="lia-linked-item"&gt;&lt;a id="community--1-Two" class="lia-anchor"&gt;&lt;/a&gt;2. Two directions of projection&lt;/H2&gt;
&lt;P&gt;The easiest way to keep the two models straight is to consider the following:&lt;/P&gt;
&lt;img&gt;Fig 1 - Access delegation direction of trust&lt;/img&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Azure Lighthouse projects the customer's&amp;nbsp;&lt;EM&gt;resources up&lt;/EM&gt;&amp;nbsp;into the provider's tenant.&lt;/STRONG&gt;&amp;nbsp;The provider manages those resources from its&amp;nbsp;own&amp;nbsp;context. The customer's subscription is, in effect, presented inside the provider's Azure portal.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft Entra Tenant Governance projects the provider's&amp;nbsp;&lt;EM&gt;identity down&lt;/EM&gt;&amp;nbsp;into the customer's tenant.&lt;/STRONG&gt;&amp;nbsp;A principal from the provider tenant becomes usable&amp;nbsp;inside the customer, and a provider&amp;nbsp;user or service principal&amp;nbsp;uses it there to do the work.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Each delegate cross-tenant access without local accounts, but the&amp;nbsp;&lt;EM&gt;thing that moves&lt;/EM&gt;&amp;nbsp;is opposite. And&amp;nbsp;who moves strongly shapes whose rules apply.&amp;nbsp;When the customer's resources come&amp;nbsp;&lt;EM&gt;up&lt;/EM&gt;&amp;nbsp;to the provider, the work happens in the provider's context. When the provider's identity goes&amp;nbsp;&lt;EM&gt;down&lt;/EM&gt;&amp;nbsp;to the customer, the work happens in the customer's context.&lt;/P&gt;
&lt;P&gt;Think of the word "projection" as a way to reason about&amp;nbsp;trust direction, not a literal claim that objects are copied between tenants. Lighthouse is delegated management&amp;nbsp;&lt;EM&gt;from the provider's context&lt;/EM&gt;; Tenant Governance creates&amp;nbsp;&lt;EM&gt;a governed principal in the customer's context&lt;/EM&gt; that can hold directory roles&amp;nbsp;and&amp;nbsp;Azure RBAC.&lt;/P&gt;
&lt;H2 class="lia-linked-item"&gt;&lt;a id="community--1-Three" class="lia-anchor"&gt;&lt;/a&gt;3. What is Microsoft Entra Tenant Governance?&lt;/H2&gt;
&lt;P&gt;Microsoft Entra Tenant Governance&amp;nbsp;is the capability that lets one tenant securely administer another. The connection between a specific pair of tenants is called a&amp;nbsp;governance relationship: a&amp;nbsp;&lt;EM&gt;directional&lt;/EM&gt;&amp;nbsp;link in which one tenant, the&amp;nbsp;governing&amp;nbsp;tenant (the provider), administers another, the&amp;nbsp;governed&amp;nbsp;tenant (the customer) (&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/how-to-set-up-governance-relationship" target="_blank" rel="noopener"&gt;set up a governance relationship&lt;/A&gt;).&lt;/P&gt;
&lt;P&gt;Throughout, this article is written from the&amp;nbsp;provider's&amp;nbsp;vantage point: when it says&amp;nbsp;&lt;EM&gt;you&lt;/EM&gt;, it means the provider (governing) side, and the other tenant is always referred to explicitly as&amp;nbsp;&lt;EM&gt;the customer&lt;/EM&gt;. The topics discussed here apply equally to Enterprises needing to manage many of their own tenants as well as Service Providers who manage many customer tenants.&lt;/P&gt;
&lt;P&gt;You set it up in two steps:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;A&amp;nbsp;&lt;STRONG&gt;policy template&lt;/STRONG&gt;&amp;nbsp;in the provider tenant that declares&amp;nbsp;&lt;EM&gt;which principal&lt;/EM&gt;&amp;nbsp;will be projected and&amp;nbsp;&lt;EM&gt;which Entra roles&lt;/EM&gt; it should receive. Note that RBAC assignments are not part of the governance relationship and must be completed by the customer in their tenant.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;A&amp;nbsp;&lt;STRONG&gt;handshake&lt;/STRONG&gt;&amp;nbsp;between the two tenants that establishes the trust boundary and provisions the access.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Now let’s dive into the details:&amp;nbsp;&lt;EM&gt;what gets projected&lt;/EM&gt;, and&amp;nbsp;&lt;EM&gt;how it gets its powers&lt;/EM&gt;.&lt;/P&gt;
&lt;H2 class="lia-linked-item"&gt;&lt;a id="community--1-Four" class="lia-anchor"&gt;&lt;/a&gt;4. What actually gets projected: one proxy principal&lt;/H2&gt;
&lt;P&gt;In the provider tenant you start with something completely ordinary, a&amp;nbsp;security group&amp;nbsp;(say, your "Cloud Operators" group), or a custom&amp;nbsp;multitenant application. When you form the governance relationship, a&amp;nbsp;proxy of that principal is created in the customer tenant:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;A&amp;nbsp;&lt;STRONG&gt;security group&lt;/STRONG&gt;&amp;nbsp;is projected in as a&amp;nbsp;&lt;STRONG&gt;remote tenant group&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;An&amp;nbsp;&lt;STRONG&gt;application&lt;/STRONG&gt;&amp;nbsp;(a custom multitenant app) is projected in as a&amp;nbsp;service principal, when the relationship is established,&amp;nbsp;Tenant Governance automatically creates a service principal with the same permissions in the customer tenant&amp;nbsp;(no manual step on the customer's side):&amp;nbsp;&lt;EM&gt;"Tenant Governance creates a service principal with the same permissions in the governed tenant"&lt;/EM&gt; (&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/governance-policy-templates" target="_blank" rel="noopener"&gt;governance policy templates&lt;/A&gt;).&lt;/LI&gt;
&lt;LI&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI-SPOILER label="Note"&gt;
&lt;P&gt;Using a multitenant app registration with Tenant Governance requires an Entra ID Governance license.&lt;/P&gt;
&lt;/LI-SPOILER&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;Fig 2 - Provider principal is projected into the customer tenant&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It’s important to keep two things straight, neither&amp;nbsp;is a local account or a guest:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;The proxy&lt;/STRONG&gt;, the remote tenant group (or, for an app, the service principal), is a&amp;nbsp;new principal created in the customer tenant by the relationship. It is&amp;nbsp;&lt;EM&gt;not&lt;/EM&gt;&amp;nbsp;a copy of the provider's group,&amp;nbsp;&lt;EM&gt;not&lt;/EM&gt;&amp;nbsp;a local group created in the customer, and&amp;nbsp;&lt;EM&gt;not&lt;/EM&gt;&amp;nbsp;a guest. It exists only because the relationship projects it, and it is what the provider grants roles to.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;The people and apps that use it&lt;/STRONG&gt;, the provider's&amp;nbsp;users and service principals, stay in the&amp;nbsp;provider&amp;nbsp;tenant. They never receive a member account or a guest invitation in the customer; they reach the customer&amp;nbsp;&lt;EM&gt;through&lt;/EM&gt;&amp;nbsp;the proxy.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Here is what that provider&amp;nbsp;user or service principal&amp;nbsp;is and isn't, from the customer's point of view:&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;thead&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;The provider&amp;nbsp;user or service principal&amp;nbsp;is&amp;nbsp;NOT…&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;…it&amp;nbsp;IS…&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;A local member account created in the customer's directory&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;An identity that stays in the&amp;nbsp;&lt;STRONG&gt;provider&lt;/STRONG&gt;&amp;nbsp;tenant and authenticates with&amp;nbsp;&lt;STRONG&gt;provider&lt;/STRONG&gt;&amp;nbsp;credentials&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;A B2B guest invited into the customer&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Reachable only&amp;nbsp;&lt;STRONG&gt;through the projected proxy&lt;/STRONG&gt;, a signed-in user shows in the customer's logs as the provider tenant's name +&amp;nbsp;Technician&amp;nbsp;(e.g.&amp;nbsp;Contoso Technician)&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;A standing, permanent object listed among the customer's users&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Present only as a&amp;nbsp;&lt;STRONG&gt;governed session or principal&lt;/STRONG&gt;, scoped by the relationship and revocable by the customer&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;To work in the customer tenant, a provider user opens a supported admin portal (Entra or Azure) and&amp;nbsp;appends the customer's tenant ID, for example&amp;nbsp;https://entra.microsoft.com/{customer-tenant-id}, then&amp;nbsp;signs in with their provider-tenant credentials. The customer's logs then show them a directory display name of&amp;nbsp;user_{object-id}&amp;nbsp;(the provider object ID without dashes), and, in&amp;nbsp;sign-in and audit logs, the&amp;nbsp;provider tenant's name followed by&amp;nbsp;Technician, so for a provider tenant named Contoso the entry reads&amp;nbsp;Contoso Technician&amp;nbsp;(&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/how-to-delegated-administration" target="_blank" rel="noopener"&gt;use cross-tenant delegated administration&lt;/A&gt;). No local account, no guest object, the resource-plane property Lighthouse provides, now on the directory plane (&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/cross-tenant-delegated-administration" target="_blank" rel="noopener"&gt;cross-tenant delegated administration&lt;/A&gt;).&lt;/P&gt;
&lt;P&gt;A note on the two projection mechanics, because they differ in a way worth understanding. A&amp;nbsp;&lt;STRONG&gt;group&lt;/STRONG&gt;&amp;nbsp;projects as a&amp;nbsp;&lt;EM&gt;remote tenant group&lt;/EM&gt;, a cross-tenant reference back to the provider's group, with no new local membership stored in the customer. An&amp;nbsp;&lt;STRONG&gt;application&lt;/STRONG&gt;&amp;nbsp;projects as a&amp;nbsp;&lt;EM&gt;real service principal&lt;/EM&gt; that is actually created in the customer with the consented permissions. Same idea, a governed proxy of a provider principal, but a group is a reference, while an app is an instantiated object.&lt;/P&gt;
&lt;H2 class="lia-linked-item"&gt;&lt;a id="community--1-Five" class="lia-anchor"&gt;&lt;/a&gt;5. How the proxy gets its powers: roles attach to the one principal&lt;/H2&gt;
&lt;P&gt;The proxy is&amp;nbsp;one principal. You don't create separate identities for "directory access" and "resource access." Instead, you&amp;nbsp;grant roles to that single proxy, and the roles can come from&amp;nbsp;two different planes:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Directory roles&lt;/STRONG&gt;&amp;nbsp;govern the customer's Microsoft Entra directory. Think of&amp;nbsp;well-known&amp;nbsp;ones such as&amp;nbsp;Global Reader&amp;nbsp;(read-only across the directory),&amp;nbsp;Global&lt;STRONG&gt; &lt;/STRONG&gt;Administrator, or&amp;nbsp;User Administrator, selected as built-in roles in the policy template (&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/governance-policy-templates" target="_blank" rel="noopener"&gt;governance policy templates&lt;/A&gt;).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Azure RBAC roles&lt;/STRONG&gt; govern the customer's Azure resources. Think of the familiar Reader, Contributor, or a service-specific roles like Virtual Machine Contributor, assigned to the remote tenant group at a subscription or resource-group scope. This is not done as part of the governance relationship as the Entra directory role is. This must be assigned after the relationship is established likely by a privileged customer admin.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The bridge from directory to resources is the remote tenant group itself: because the projected group can be referenced by Azure RBAC, the same proxy that holds&amp;nbsp;Global Reader&amp;nbsp;in the directory can&amp;nbsp;&lt;EM&gt;also&lt;/EM&gt; hold&amp;nbsp;Reader&amp;nbsp;or&amp;nbsp;Contributor&amp;nbsp;on a resource group. Critically, these are&amp;nbsp;not separate identities, they are both&amp;nbsp;roles held by the one remote tenant group, as the diagram above shows. And the directory role grants&amp;nbsp;no&amp;nbsp;Azure access on its own; the resource rights come entirely from the explicit RBAC assignment you choose.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That single design choice, &lt;EM&gt;roles branch off one proxy&lt;/EM&gt;, is what lets one projected principal span both planes: the same remote tenant group can hold a directory role&amp;nbsp;and&amp;nbsp;a separate, explicit Azure RBAC grant, without ever issuing a local account.&lt;/P&gt;
&lt;P&gt;What do these identities actually look like in the customer tenant? The only place you will see the security group is in the governance relationship. You will not find it among your other Entra groups.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;Fig 3 - Governance relationship shows the projected principal in the customer tenant&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;Fig 4 - The projected principal does not appear in the customer tenant security groups&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For RBAC purposes, you can find the proxy security group under resource Access Control (IAM) as a foreign group.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;Fig 5 - The projected principal is available for RBAC assignments as a foreign group&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2 class="lia-linked-item"&gt;&lt;a id="community--1-Six" class="lia-anchor"&gt;&lt;/a&gt;6. The building blocks, and how they depend on each other&lt;/H2&gt;
&lt;P&gt;Now that the concept is in place, here's the assembly order. Each block depends on the one before it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;Fig 6 - Sequence of creating a governance relationship&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;A role-assignable security group&lt;/STRONG&gt;&amp;nbsp;in the provider tenant, the principal you intend to project.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;A policy template&lt;/STRONG&gt;&amp;nbsp;that selects which directory roles that group should receive when projected (&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/governance-policy-templates" target="_blank" rel="noopener"&gt;governance policy templates&lt;/A&gt;).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;A governance relationship&lt;/STRONG&gt;, established by a&amp;nbsp;handshake. In the standard three-step flow the customer&amp;nbsp;&lt;EM&gt;invites&lt;/EM&gt;, the provider&amp;nbsp;&lt;EM&gt;requests&lt;/EM&gt;&amp;nbsp;(carrying the template), and the customer&amp;nbsp;&lt;EM&gt;accepts&lt;/EM&gt;; a streamlined&amp;nbsp;two-step&amp;nbsp;flow (request → accept) applies when the two tenants already share a qualifying signal, such as a billing relationship or an existing governance relationship. At acceptance, the role assignments are provisioned in the customer (&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/how-to-set-up-governance-relationship" target="_blank" rel="noopener"&gt;set up a governance relationship&lt;/A&gt;). The template's role set is&amp;nbsp;projected&amp;nbsp;onto the relationship, so later template edits require a fresh request and re-approval, the customer always gets to review what changes.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;The projected proxy plus its role assignments&lt;/STRONG&gt;&amp;nbsp;in the customer, the remote tenant group (or service principal), now holding the directory and/or Azure RBAC roles you granted.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;Under the hood:&lt;/STRONG&gt;&amp;nbsp;this cross-tenant delegation is powered by&amp;nbsp;granular delegated admin privileges (GDAP), the same delegation technology behind Partner Center (&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/cross-tenant-delegated-administration" target="_blank" rel="noopener"&gt;cross-tenant delegated administration&lt;/A&gt;). You don't configure it directly; the relationship and the template do it for you. That's all you need to know about the plumbing.&lt;/P&gt;
&lt;P&gt;The whole flow is also scriptable through the&amp;nbsp;Microsoft Graph&amp;nbsp;Tenant Governance APIs (&lt;A href="https://learn.microsoft.com/en-us/graph/api/resources/tenantgovernanceservices-tenantgovernance-overview?view=graph-rest-beta" target="_blank" rel="noopener"&gt;API overview&lt;/A&gt;), and a default template can bring&amp;nbsp;new add-on tenants&amp;nbsp;under governance automatically at creation (&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/deployment-guide#configure-a-default-policy-template-optional" target="_blank" rel="noopener"&gt;deployment guide&lt;/A&gt;).&lt;/P&gt;
&lt;H2 class="lia-linked-item"&gt;&lt;a id="community--1-Seven" class="lia-anchor"&gt;&lt;/a&gt;7. Key Features&lt;/H2&gt;
&lt;P&gt;Because the proxy can hold both directory roles and Azure RBAC, Tenant Governance unlocks delegated administration across the&amp;nbsp;&lt;EM&gt;entire&lt;/EM&gt;&amp;nbsp;surface a partner might legitimately need:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Directory administration&lt;/STRONG&gt;, read or manage the customer's Microsoft Entra directory with least-privileged built-in roles, using home credentials, no local accounts.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Identity governance&lt;/STRONG&gt;, run access reviews, entitlement management, and lifecycle workflows across many customer tenants from one place.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Security operations&lt;/STRONG&gt;, operate security and compliance tooling centrally. Microsoft Defender XDR and Microsoft Sentinel multitenant management for MSSPs is&amp;nbsp;one&amp;nbsp;prominent example built on this model (&lt;A href="https://learn.microsoft.com/en-us/unified-secops/governance-relationships" target="_blank" rel="noopener"&gt;governance relationships for unified SecOps&lt;/A&gt;).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Azure resource management&lt;/STRONG&gt;, the remote tenant group can carry Azure RBAC for any Azure service, exactly the way a local group would. That covers the management (control) plane only; neither model delegates the resource data plane (for example, blob data or Key Vault secrets), so those operations still require an identity native to the customer tenant.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Application management&lt;/STRONG&gt;, project a custom multitenant app as a service principal with consistent, least-privileged permissions across tenants (&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/governance-policy-templates" target="_blank" rel="noopener"&gt;governance policy templates&lt;/A&gt;).&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The provider's&amp;nbsp;users and service principals&amp;nbsp;use their&amp;nbsp;provider-tenant identities, and no local or B2B account is ever planted in the customer. The one object the customer does gain is in the&amp;nbsp;application&amp;nbsp;case, a governed&amp;nbsp;service principal&amp;nbsp;of the projected app, created and maintained through the relationship rather than as a standing local login.&lt;/P&gt;
&lt;H2 class="lia-linked-item"&gt;&lt;a id="community--1-Eight" class="lia-anchor"&gt;&lt;/a&gt;8. Comparing Tenant Governance with Azure Lighthouse&lt;/H2&gt;
&lt;P&gt;Now that both models are understood, the comparison is straightforward. They operate on different planes and point in different directions.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;thead&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Dimension&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Azure Lighthouse&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Entra Tenant Governance&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Direction of projection&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Customer&amp;nbsp;&lt;STRONG&gt;resources → provider&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Provider&amp;nbsp;&lt;STRONG&gt;identity → customer&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Where the provider identity operates&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;From the&amp;nbsp;&lt;STRONG&gt;provider&lt;/STRONG&gt;&amp;nbsp;tenant (customer resources projected up; no customer sign-in)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;In the customer&lt;/STRONG&gt;&amp;nbsp;tenant, authenticated by the provider home tenant — as&amp;nbsp;{Provider} Technician&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Planes reached&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Azure resource (ARM) plane only&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Directory plane&amp;nbsp;&lt;EM&gt;and&lt;/EM&gt;&amp;nbsp;Azure resource plane&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Data-plane access (e.g., blob data, Key Vault secrets)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Not supported&lt;/STRONG&gt; (control/ARM plane only)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Not supported&lt;/STRONG&gt; (the proxy can hold a DataActions role, but cannot obtain a data-plane token)&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Identity footprint in customer&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;None&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;A&amp;nbsp;&lt;STRONG&gt;projected proxy&lt;/STRONG&gt;&amp;nbsp;principal, no local or guest object&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Conditional Access&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Only the&amp;nbsp;&lt;STRONG&gt;provider's&lt;/STRONG&gt;&amp;nbsp;policies apply (&lt;A href="https://learn.microsoft.com/en-us/azure/lighthouse/concepts/recommended-security-practices" target="_blank" rel="noopener"&gt;security practices&lt;/A&gt;)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;The&amp;nbsp;&lt;STRONG&gt;customer's&lt;/STRONG&gt;&amp;nbsp;policies apply, the customer is the resource tenant for the technician's sign-in (&lt;EM&gt;lab-verified; see below&lt;/EM&gt;)&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Where the privileged assignment lives&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Provider&lt;/STRONG&gt;&amp;nbsp;tenant (JIT approvers in the provider) (&lt;A href="https://learn.microsoft.com/en-us/azure/lighthouse/how-to/create-eligible-authorizations" target="_blank" rel="noopener"&gt;eligible authorizations&lt;/A&gt;)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Customer&lt;/STRONG&gt;&amp;nbsp;tenant (the role assignment is owned customer-side)&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Audit of provider actions&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Customer&amp;nbsp;&lt;STRONG&gt;Activity Log&lt;/STRONG&gt;&amp;nbsp;(&lt;A href="https://learn.microsoft.com/en-us/azure/lighthouse/how-to/view-service-provider-activity" target="_blank" rel="noopener"&gt;view activity&lt;/A&gt;)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Customer&amp;nbsp;&lt;STRONG&gt;audit log&lt;/STRONG&gt;&amp;nbsp;records the provider user’s&amp;nbsp;&lt;EM&gt;actions&lt;/EM&gt;; the&amp;nbsp;&lt;STRONG&gt;authentication sign-in is recorded provider-side,&lt;/STRONG&gt; it appears in the customer's sign-in log only when the customer's CA fires&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Role types&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Azure built-in roles only, &lt;STRONG&gt;no custom roles&lt;/STRONG&gt;;&amp;nbsp;&lt;STRONG&gt;Owner&lt;/STRONG&gt;&amp;nbsp;and roles with&amp;nbsp;&lt;STRONG&gt;DataActions&lt;/STRONG&gt;&amp;nbsp;excluded, and&amp;nbsp;Microsoft.Authorization/*&amp;nbsp;writes excluded except&amp;nbsp;&lt;STRONG&gt;User Access Administrator&lt;/STRONG&gt;&amp;nbsp;for managed-identity assignments (&lt;A href="https://learn.microsoft.com/en-us/azure/lighthouse/concepts/tenants-users-roles" target="_blank" rel="noopener"&gt;role rules&lt;/A&gt;)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Directory roles&amp;nbsp;and&amp;nbsp;Azure RBAC (including&amp;nbsp;&lt;STRONG&gt;custom&lt;/STRONG&gt;&amp;nbsp;RBAC) on the proxy&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Setup&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;ARM template / Marketplace offer (&lt;A href="https://learn.microsoft.com/en-us/azure/lighthouse/how-to/onboard-customer" target="_blank" rel="noopener"&gt;onboard&lt;/A&gt;)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Relationship handshake (invitation → request → acceptance)&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Revocation&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Remove the delegation, either party (&lt;A href="https://learn.microsoft.com/en-us/azure/lighthouse/how-to/remove-delegation" target="_blank" rel="noopener"&gt;remove&lt;/A&gt;)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Terminate the relationship, either party&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Operational view&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Single pane of glass&lt;/STRONG&gt;, every delegated customer's resources surface in the provider's&amp;nbsp;&lt;STRONG&gt;own&lt;/STRONG&gt;&amp;nbsp;portal&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Per-customer&lt;/STRONG&gt;, the admin signs in to each customer tenant individually&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Best for&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Scaled&amp;nbsp;&lt;STRONG&gt;Azure resource&lt;/STRONG&gt;&amp;nbsp;operations&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Directory / identity / security&lt;/STRONG&gt;&amp;nbsp;delegation&amp;nbsp;plus&amp;nbsp;resources&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;EM&gt;The sign-in, Conditional Access, footprint, and audit rows describe &lt;STRONG&gt;the&amp;nbsp;human delegated-administration&lt;/STRONG&gt;&amp;nbsp;path (a projected group). In the&amp;nbsp;application&amp;nbsp;case the customer instead gets a governed&amp;nbsp;service principal, so those rows read differently.&lt;/EM&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt; Direction of projection, the root cause. &lt;/STRONG&gt;Everything else in the table is a consequence of this one row. Lighthouse brings the customer's&amp;nbsp;&lt;EM&gt;resources &lt;/EM&gt;up to the provider; Tenant Governance places a governed proxy of the&amp;nbsp;&lt;EM&gt;provider's identity&lt;/EM&gt;&amp;nbsp;down in the customer. Decide which direction your scenario actually needs, and the rest mostly answers itself.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Conditional Access, the cleanest inverse. &lt;/STRONG&gt;With Lighthouse, provider users authenticate&amp;nbsp;in their own tenant, so the customer's Conditional Access never reaches them, &lt;EM&gt;"Only policies set on the managing tenant apply"&lt;/EM&gt;(&lt;A href="https://learn.microsoft.com/en-us/azure/lighthouse/concepts/recommended-security-practices" target="_blank" rel="noopener"&gt;recommended security practices&lt;/A&gt;). With Tenant Governance the provider actually&amp;nbsp;signs in to the customer tenant&amp;nbsp;(&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/how-to-delegated-administration" target="_blank" rel="noopener"&gt;use cross-tenant delegated administration&lt;/A&gt;), which makes the customer the&amp;nbsp;resource tenant&amp;nbsp;that evaluates Conditional Access, so the&amp;nbsp;customer's&amp;nbsp;policies govern the inbound provider login, not the provider's policies.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Two nuances to keep in mind: When the provider logs into the customer tenant, the authentication still happens with the provider’s tenant, but the conditional access policy applied to the login is in the customer tenant.&lt;/P&gt;
&lt;OL start="3"&gt;
&lt;LI&gt;&lt;STRONG&gt; Where privileged access lives. &lt;/STRONG&gt;Lighthouse offers just-in-time elevation through eligible authorizations, and the&amp;nbsp;approvers sit in the provider (managing) tenant, &lt;EM&gt;"up to 10 users or user groups in the managing tenant who can approve"&lt;/EM&gt;(&lt;A href="https://learn.microsoft.com/en-us/azure/lighthouse/how-to/create-eligible-authorizations" target="_blank" rel="noopener"&gt;create eligible authorizations&lt;/A&gt;). Tenant Governance inverts the ownership: the proxy's role assignment&amp;nbsp;lives in the customer tenant, so privileged-access governance over that assignment is anchored&amp;nbsp;customer-side. The useful contrast is simply&amp;nbsp;&lt;EM&gt;where the assignment lives and who governs it&lt;/EM&gt;, provider-side for Lighthouse, customer-side for Tenant Governance.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Audit and identity footprint. &lt;/STRONG&gt;With Lighthouse, provider actions land in the customer's Azure Activity Log under a named user, with no customer sign-in and no directory object (&lt;A href="https://learn.microsoft.com/en-us/azure/lighthouse/how-to/view-service-provider-activity" target="_blank" rel="noopener"&gt;view provider activity&lt;/A&gt;). Tenant Governance is more subtle. The provider user's authentication is handled and logged in the provider (home) tenant, so the bare sign-in appears&amp;nbsp;&lt;EM&gt;there&lt;/EM&gt;, not in the customer tenant. What does get logged in the customer directory is the provider user’s actions, in its audit log, where the actor shows as the &amp;lt;provider tenant's name +&amp;nbsp;Technician&amp;gt;&amp;nbsp;(e.g.&amp;nbsp;Contoso Technician) (&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/how-to-delegated-administration" target="_blank" rel="noopener"&gt;use cross-tenant delegated administration&lt;/A&gt;). A sign-in entry from the provider user only appears in the customer's logs when the customer's Conditional Access evaluates the session, for example, an MFA challenge. Without such a policy, that sign-in is only logged on the provider side. Either way, the customer keeps a full audit of what the technician does and gains no standing local or guest object (&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/cross-tenant-delegated-administration" target="_blank" rel="noopener"&gt;cross-tenant delegated administration&lt;/A&gt;).&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;Fig 7 - The providers activities on resources are logged in the customer's subscription activity log as "&amp;lt;provider name&amp;gt; Technician"&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;Fig 8 - When the provider logs into the customer tenant, their authentication is logged against the provider tenant while Conditional Access is logged against the customer tenant&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL start="5"&gt;
&lt;LI&gt;&lt;STRONG&gt; One console vs. many: Operational reach. &lt;/STRONG&gt;Because Lighthouse projects the customer's resources&amp;nbsp;&lt;EM&gt;up&lt;/EM&gt;, the provider works from a&amp;nbsp;single pane of glass, every delegated customer's subscriptions appear in the provider's&amp;nbsp;own&amp;nbsp;Azure portal, and cross-tenant tooling, Azure Resource Graph, Microsoft Sentinel, Azure Policy, Azure Monitor, can span all of them at once. Tenant Governance points the other way: the provider's identity projects&amp;nbsp;&lt;EM&gt;down &lt;/EM&gt;into each customer, so day-to-day administration is&amp;nbsp;per-customer, the admin signs in to each customer tenant in turn. (Service consoles such as Microsoft Defender XDR add their own aggregated multitenant views on top, but the underlying delegated-admin model is per-tenant.) When operating&amp;nbsp;many&amp;nbsp;customers' Azure estates from one console is the priority, that single-pane reach is a distinct Lighthouse strength.&lt;/LI&gt;
&lt;/OL&gt;
&lt;H2 class="lia-linked-item"&gt;&lt;a id="community--1-Nine" class="lia-anchor"&gt;&lt;/a&gt;9. Where the two models overlap&lt;/H2&gt;
&lt;P&gt;As is the case with other delegated access models, there is clear overlap between Azure Lighthouse and Tenant Governance:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Both eliminate local and B2B accounts&lt;/STRONG&gt;&amp;nbsp;in the customer. The partner's people stay in the provider tenant either way (&lt;A href="https://learn.microsoft.com/en-us/azure/lighthouse/concepts/architecture" target="_blank" rel="noopener"&gt;Lighthouse architecture&lt;/A&gt;,&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/cross-tenant-delegated-administration" target="_blank" rel="noopener"&gt;cross-tenant delegated administration&lt;/A&gt;).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Both can ultimately place Azure RBAC on customer resources&lt;/STRONG&gt;, Lighthouse directly through the delegation, Tenant Governance via the remote tenant group.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Both are limited to the control (management) plane&lt;/STRONG&gt;, neither delegates resource data-plane access (for example, blob data or Key Vault secrets); that still requires an identity native to the customer tenant.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Both keep the customer in control of the audit record&lt;/STRONG&gt;, provider actions are written to the customer's logs.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Both are revocable by either party&lt;/STRONG&gt;, remove the delegation, or terminate the relationship.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 class="lia-linked-item"&gt;&lt;a id="community--1-Ten" class="lia-anchor"&gt;&lt;/a&gt;10. What is complimentary with the two models?&lt;/H2&gt;
&lt;P&gt;Because they sit on different planes and point in opposite directions, you can use one or both.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;Fig 9 - Azure Lighthouse and Entra Tenant Governance compared&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Deciding between the two delegated access models:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Need only to operate the customer's Azure resources, especially across many customers?&lt;/STRONG&gt;&amp;nbsp;Choose&amp;nbsp;Azure Lighthouse, no extra license or charge, a broad set of Azure built-in roles (Owner and custom roles excluded), just-in-time elevation with provider-side approval, zero directory footprint, and a&amp;nbsp;single pane of glass: because customer resources project&amp;nbsp;&lt;EM&gt;up&lt;/EM&gt;&amp;nbsp;into the provider's tenant, the provider manages&amp;nbsp;every&amp;nbsp;customer's estate from their&amp;nbsp;own&amp;nbsp;portal, with cross-tenant tooling spanning all of them at once.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Need directory, identity, or security reach, not just resources?&lt;/STRONG&gt;&amp;nbsp;Choose&amp;nbsp;Microsoft Entra Tenant Governance, directory roles and Azure RBAC on one projected principal, with the customer's own sign-in controls in the loop. Because the provider's identity projects&amp;nbsp;&lt;EM&gt;down&lt;/EM&gt;&amp;nbsp;into each customer, administration is&amp;nbsp;per-customer: the admin signs in to each customer tenant in turn rather than from one aggregated console.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Need both on the same tenant?&lt;/STRONG&gt;&amp;nbsp;Use both. They coexist because they operate on different planes, Lighthouse for the resource estate, Tenant Governance for directory and security.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 class="lia-linked-item"&gt;&lt;a id="community--1-Eleven" class="lia-anchor"&gt;&lt;/a&gt;11. Key points to remember about Entra Tenant Governance&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Least privilege.&lt;/STRONG&gt;&amp;nbsp;A directory role grants&amp;nbsp;&lt;EM&gt;no&lt;/EM&gt;&amp;nbsp;Azure access, and an Azure RBAC role grants&amp;nbsp;&lt;EM&gt;no&lt;/EM&gt;&amp;nbsp;directory access. Each plane is an&amp;nbsp;explicit grant&amp;nbsp;to the proxy, start with read-only (e.g.,&amp;nbsp;Global Reader&amp;nbsp;in the directory,&amp;nbsp;Reader&amp;nbsp;on resources) and add only what's needed.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Directory ≠ resource.&lt;/STRONG&gt; The two planes are independent. If the partner needs to operate Azure resources, that comes from an explicit RBAC assignment on the remote tenant group, not from any directory role. That RBAC is control-plane only; neither Tenant Governance nor Lighthouse delegates the resource data plane (for example, blob data or Key Vault secrets), which still requires an identity native to the customer tenant.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Tenant discovery is irreversible.&lt;/STRONG&gt;&amp;nbsp;Enabling related-tenant discovery is&amp;nbsp;permanent&amp;nbsp;(&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/deployment-guide#phase-1-enable-related-tenant-discovery" target="_blank" rel="noopener"&gt;deployment guide&lt;/A&gt;). For a controlled pilot, run the handshake&amp;nbsp;by&lt;STRONG&gt; &lt;/STRONG&gt;tenant ID&amp;nbsp;and skip discovery. Azure&amp;nbsp;Lighthouse, by contrast, coexists with a governance relationship on the same customer, different mechanism, different plane.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Conditional Access is the customer's to enforce.&lt;/STRONG&gt;&amp;nbsp;Because the provider signs in to the customer tenant, the&amp;nbsp;customer's&amp;nbsp;Conditional Access governs that access.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 class="lia-linked-item"&gt;&lt;a id="community--1-Twelve" class="lia-anchor"&gt;&lt;/a&gt;12. Summary&lt;/H2&gt;
&lt;P&gt;Azure Lighthouse and Microsoft Entra Tenant Governance are two delegation models pointing in opposite directions. Lighthouse brings the customer's&amp;nbsp;resources up&amp;nbsp;to the provider and keeps the provider's Azure access clean and identity-free. Tenant Governance places a&amp;nbsp;governed proxy of the provider down&amp;nbsp;in the customer, extending the very philosophy from Parts 1–2, &lt;EM&gt;govern the relationship, not the people&lt;/EM&gt;, from the resource plane all the way into the&amp;nbsp;directory.&lt;/P&gt;
&lt;P&gt;Choose by the direction the trust needs to flow: bring the resources to you (Azure Lighthouse), or place a governed proxy of yourself in the customer (Microsoft Entra Tenant Governance). When you need both, use both.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2026 12:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/should-you-use-the-new-microsoft-entra-tenant-governance-or/ba-p/4532297</guid>
      <dc:creator>Preston_Romney</dc:creator>
      <dc:date>2026-07-23T12:00:00Z</dc:date>
    </item>
    <item>
      <title>Windows defender is having a lot of problems.</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-office/windows-defender-is-having-a-lot-of-problems/m-p/4539813#M1157</link>
      <description>&lt;P&gt;So I have a Microsoft 365 Family subscription, and&amp;nbsp;Dark Web Monitoring shows 0 monitored items.&amp;nbsp;SSN verification fails and advises you to contact support. I was also&amp;nbsp;unable to delete the monitored information. I’m&amp;nbsp;receive the error "Something went wrong, try again in a bit."&amp;nbsp;The issue occurs in the Microsoft Defender app, web portal, and across devices. Is there anyway that I can get help with this?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2026 18:00:20 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-office/windows-defender-is-having-a-lot-of-problems/m-p/4539813#M1157</guid>
      <dc:creator>LilNucleus</dc:creator>
      <dc:date>2026-07-22T18:00:20Z</dc:date>
    </item>
  </channel>
</rss>

