Steve Endow's Business Central Podcast

I Need Coffee - Episode 219 - Weekly BC Review!

Steve Endow Episode 219

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 1:00:33

I Need Coffee - Episode 219 - Weekly BC Review! (August 7, 2026)


1. Utah Trip & Home Maintenance (1,600+ miles / ~2,575 km)
   - Primary trigger: misbehaving sprinklers. Turned out to be a reset timer + unplugged wires; only one physical valve issue. Avoided digging 1-inch residential PVC.
   - Saw Tanya; worked from dining table, strategic planning, fresh cherries.
   - Temporary folding desk + daughter’s old IKEA chair at Airbnb proved uncomfortable → designing a sturdier, larger, closet-folding desk in SketchUp.
   - Utah “data center” upgrade: retired paint-bucket server rack; installed proper shelf/mounting plate. Also installed a clean two-zone radon abatement system (common in high-radon areas; excellent local install that preserves future basement finishing).
   - Family dinner at YGF Malatang (Chinese-style hot-pot buffet) after an 11-hour drive.

2. Marketing & SEO / AIO Progress (with Daniela)
   - Full-time marketing associate is driving accountability (“chop chop”).
   - Claude-drafted SEO + AIO project plan after scanning the site against best practices.
   - Key insight: modern SEO is mostly housekeeping (proper structure, meta tags, structured data) rather than keyword stuffing. Search engines already detect pricing but flag missing frequency (one-time / monthly / annual).
   - Set up Google Search Console and Bing Webmaster Tools; submitted sitemap.
   - Built monthly scorecard: 10 questions run across top AI search engines (Perplexity, Claude, Copilot, Gemini, GPT, etc.) and results matrixed.
   - Host presenting “Marketing Without a Marketing Team” (low-budget guerrilla approach that avoids ~$60k cash outlay) at Partner Vibe 2.0.

3. Azure Artifact Signing
   - Organization identity verification finally approved after 14 calendar days.
   - Certificate profiles are ephemeral (create → use once → expire in ~3 days), similar to Let’s Encrypt model.
   - $10/month; strongly recommended for anyone in US / Canada / UK / EU who needs code signing. Cleaner and far cheaper than traditional providers.

4. Business Central Web API Key Incident (Security)
   - Third party was given BC web API keys / app registration credentials with essentially zero security practices (keys at high risk of exposure to crawlers/bots).
   - Host treated it as a cybersecurity incident, pushed the partner to inform the customer, revoke keys, and delete the app registration.
   - Creating a formal incident report + standardized Web API Authorization form (customer + third party must sign; security procedures required before keys are issued).
   - Blog post published: “Reducing the risk of Business Central web API secrets through education” (includes the form and process).
   - Goal: document everything so the host cannot later be accused of negligence for failing to escalate.

5. Azure DevOps Quirk
   - Variable groups linked to Key Vault stopped working in one old project.
   - Root cause buried deep in Azure Resource Manager service connections at the project level. “Rotate secret” instantly fixed it. Reminder that Azure DevOps still has obscure corners.

6. Internal Tooling – Blue Dragonfly Bulk Data Import
   - Consulting team exhausted by Configuration Packages (slow, error-prone, painful corrections) and only partially satisfied with Insight Works power tool.
   - Decision: build an in-house general-journal-focused bulk import utility (will expand to master data, fixed assets, etc.).
   - Claude produced a combined ~14-page FRD/PRD. Franklin to vibe-code v1 once feedback arrives.
   - Classic “reinventing the wheel” calculus has flipped in the AI era: low cost to try building something better tailored to exact needs.

7. Claude Language Degradation / AI Slop
   - Extended rant on current Claude output: dense, unnatural phrases (“ground truth loadbearing first-class feedback-instrumented auto-enriched permissions posture,” “dormant schema,” “seed-free graceful degradation,” etc.).
   - Non-native English speakers often find it completely opaque; some others claim it “makes sense.”
   - Explanation circulating (Kungchen / Guidedon): shift from RLHF (human preference) to RLVR (Reinforcement Learning with Verifiable Rewards). Models are optimized for verifiable correctness by other models and are actually penalized for human-likable language (“alignment tax”).
   - Growing discussion that agents may develop an internal language subset separate from human-facing output.
   - Real-world example: public PR from a multi-billion-dollar software company full of unreadable AI-generated text that no human appears to have reviewed.

8. Entra ID / MFA Neglect
   - Partner still using SMS/voice verification (Microsoft has been pushing to disable this since before Sept 2025).
   - Microsoft blocks SMS and voice MFA to El Salvador numbers by default.
   - Passkeys become the default experience; Microsoft-provided SMS/voice authentication retires 1 Feb 2027.
   - Red flag on the partner’s overall security hygiene.

9. Other Observations
   - GitHub relative dates (“two weeks ago”) instead of actual timestamps remain terrible UX (must hover to see the real date).
   - Context switching across multiple Claude sessions / projects is still cognitively expensive.
   - Hand-coding is increasingly “supervising” AI-generated change requests and development plans.
   - People regularly burning through $200/month Claude Max plans are almost certainly using tokens inefficiently; deterministic scripts + smaller models (Haiku etc.) should handle bulk work.

10. Cybersecurity – Hardware Wallet RNG Failure
    - Popular “high-security” Bitcoin hardware wallet shipped firmware that replaced its RNG with a flawed open-source Python library (pseudonymous author). Fell back to deterministic test RNG.
    - Foundation of the security pyramid (true entropy) was sand. Wallets were pre-identified, sorted by balance, and swept starting hours before public disclosure.
    - Attacker appears unsophisticated (funds sent to traceable wallets rather than properly laundered). Classic lesson: cryptography is only as strong as its random-number generation.

11. Team Updates
    - Joselyn: Financials / GL work; continuing MB-800 study.
    - David: Passed MB-800; fighting customer/contact/vendor import and posting-group issues.
    - Ronald: New cohort for Berlin English Academy + ongoing ERP Academy curriculum (quizzes, enrichment, Monday calls).
    - Franklin: PTE bug fix (classic pattern: internal testing misses what a consultant/customer finds in five minutes).
    - Fatima: Experimenting with Claude + Teams Planner + VTT transcripts to auto-generate meeting notes and project docs.
    - Daniela: SEO/AIO execution and preparing first marketing campaign.
    - Eloar Christmas festival planning kicked off with local organizers.

12. Upcoming Events
    - Partner Vibe 2.0 — Provo, Utah, 21–23 September. Host presenting on marketing without a marketing team. Contact via steveendo.com for possible discount code.
    - Summit NA — Nashville, 11–15 October (summitna.com).
    - Dynamics Con Regionals: Columbus (Aug), Montreal (Sept), Frankfurt (Oct), Houston (Nov) — verify exact dates as some listings are inconsistent.