Sessions
Showing 69 of 69 session(s).
-
Test Master Class
Master Class 420 min Room 16-Floor 1-Max 32-MC Security Expert (400)Tue 09 Feb, 09:00–16:00this is a fantastic master class, don't miss !
-
Microsoft 365 Master Class
Master Class 420 min Room 17-Floor 1-Max 48-MC Microsoft 365 Advanced (300)Tue 09 Feb, 09:00–16:00This Microsoft 365 masterclass digs into the real state of your M365 data estate: where Purview classification and DLP strategies quietly fall apart, and what Copilot and the agents built on top of it can actually see. We'll look at the real benefits we're seeing as Microsoft 365 Copilot lands inside Word, Excel, Outlook, PowerPoint and Teams, the Teams governance and Teams AI decisions that haunt admins years later, and the most recent SharePoint governance features worth knowing about. We'll close the day by looking at the latest and greatest across Microsoft 365 and Microsoft 365 Copilot, the lessons learned we wish someone had told us first, and an open AMA to put your own tenant's questions to all of us.
-
Data Compliance & Security Master Class (Purview)
Master Class 420 min Room 18-19-Floor 1-Max 90-MC Data Compliance & Security Expert (400)Tue 09 Feb, 09:00–16:00Microsoft Purview Data Security - Securing Data in the Age of AI Join this Data Security Master Class for a deep dive into protecting your organization's data in the era of AI using Microsoft Purview and the broader Microsoft Security stack! As AI adoption accelerates - from sanctioned enterprise tools like Microsoft 365 Copilot to unsanctioned Shadow AI - data security has become the critical control plane. This master class equips you with the strategies, configurations, and architectural patterns needed to discover, classify, protect, and govern your data across the full AI landscape. Participants will gain deep technical insight into why and how to implement these technologies to prevent data oversharing, control AI interactions with sensitive data, and maintain compliance with regulatory standards while enabling productive AI adoption. Throughout the day, we'll highlight what's achievable at each licensing tier - from Microsoft 365 Business Premium and E3 foundations to E5 best-in-class capabilities.
-
Engineering Autonomous AI Agents Master Class
Master Class 420 min Room 20-Floor 1-Max 54-MC AI for Engineers/Developers (Build Your Own AI) Advanced (300)Tue 09 Feb, 09:00–16:00With Jannich Ibsen, Thomas Martinsen, Ulrich BodentienMost AI solutions today assist humans. The next generation of systems will execute work independently. This masterclass provides a deep dive into how to engineer autonomous AI agents that can reason, plan, and take action across real business processes. In this hands-on masterclass, you will learn how to build AI agents capable of reasoning, planning, and acting autonomously across complex business processes. Through demos and practical exercises, you will create agents that can discover information, gather and evaluate data from multiple sources, build knowledge, and dynamically determine the best path toward achieving a goal. Unlike traditional automation, autonomous agents are not limited to predefined workflows. They can adapt to changing conditions, identify knowledge gaps, seek out the information they need, and continuously refine their approach while executing tasks on behalf of users and organizations. By the end of the masterclass, you will have built and operated autonomous AI agents yourself and gained a practical understanding of how to create systems that move beyond assisting people to actively performing work. The future of AI is not smarter chat interfaces—it is autonomous digital workers capable of turning objectives into outcomes. This is not a low-code agent builder session. The masterclass uses a code-first engineering stack for creating autonomous AI systems, covering large language models, agent orchestration, tool use, retrieval, memory, APIs, data integrations, evaluation, and observability. Participants will work across modern AI engineering environments including VS Code, GitHub Copilot, Claude Code, and Codex—using both IDE-based and CLI-based workflows. The focus is on understanding the technical building blocks required to move from AI demos to autonomous agents that can operate reliably in real enterprise contexts.
-
Azure Master Class
Master Class 420 min Room 5-7-Floor 1-Max 122-MC Azure Expert (400)Tue 09 Feb, 09:00–16:00Getting workloads into Azure is the easy part. The hard part is running a platform that stays secure, scales predictably, controls cost, and still lets developers move fast. This full day masterclass is about Operational Excellence in Azure - how leading organizations build a platform foundation where governance and developer agility coexist instead of competing. We'll work through the disciplines that make or break an Azure platform at scale: governance and landing zones, architecture, identity and access, network security, platform operations, observability, DevOps, and developer self-service. We'll also show where AI is already changing the game - GitHub Copilot in development and Infrastructure as Code, AI-assisted security insights, automated operations, and smarter platform management. Expect concrete examples, not slideware: how AI speeds things up without losing control or compliance. The day is built for cloud architects, platform engineers, IT operations and security professionals, and technical decision makers who want practices they can take home and use - not just theory. Key takeaways A landing zone and governance model you can actually operate at scale. A secure-by-default platform: identity, network, compliance, and resilience built in, not bolted on. Developer self-service backed by DevOps automation, Infrastructure as Code, and GitHub workflows. Where Copilot and AI actually improve operations, security, and engineering productivity today. An operating model that holds governance, security, and business agility together at enterprise scale.
-
Security Master Class: Lessons from the Field - Hacking and Securing Windows Infrastructure.
Master Class 420 min Room A2-Floor 0-Max 350-MC Security Expert (400)Tue 09 Feb, 09:00–16:00With Paula JanuszkiewiczThis is a deep dive course on infrastructure services security, a must-go for enterprise administrators, security officers and architects. It is delivered by one of the best people in the market in the security field – with practical knowledge from tons of successful projects, many years of real-world experience, great teaching skills and no mercy for misconfigurations or insecure solutions. In this workshop you will investigate the critical tasks for a high-quality penetration test. We will look at the most efficient ways to map a network and discover target systems and services. Once it has been done, we will search for vulnerabilities and reduce false positives with manual vulnerability verification. At the end we will look at exploitation techniques, including the use of authored and commercial tools. In the attack summary we will always go through the securing techniques.
-
Identity Master Class
Master Class 420 min Room A3-Floor 0-Max 250-MC Identity Advanced (300)Tue 09 Feb, 09:00–16:00Identity Masterclass will be BACK for a V2 of last year's success at Experts Live DK in February 2027! You can expect a full day masterclass in workshop style of all things Identity Security, Governance, Management and Agents in Microsoft Entra towards 2027 led by renowned Identity experts Merill Fernando, Ex-Microsoft Entra PM, Thomas Naunheim, Klaus Bierschenck, Pim Jacobs, and Jan Vidar Elven, all Microsoft MVPs in Security and the Identity & Access area! Whether you attended the Identity Master Class in 2026 or not, where we covered key IAM scenarios, including Identity Governance & Lifecycle Workflows, Access Control, Privileged Access, Monitoring, Insights & Recovery, Agent ID & Security Exposure, we will not directly repeat, but enforce and build on last years success, and introduce news and announcements so you are updated on important concepts to make you a true Identity Master! Same as last year, the Identity Masterclass will be interactive and with labs so you can practice and do yourself, either on the day or take home with you! We hope to see you (again or as a new attendee) for another fully signed-up Identity Masterclass at Experts Live Denmark 2027!
-
Intune Master Class
Master Class 420 min Room Auditorium A15-Floor 0-1-Max 582-MC Intune Expert (400)Tue 09 Feb, 09:00–16:00Join this intensive Master Class designed for endpoint administrators, architects, and security professionals who want to stay ahead of the rapidly evolving Microsoft endpoint management landscape. Dive deep into the latest features across Microsoft Intune, Intune Suite, Windows Security, Security Copilot, and cloud-native device management. Through expert-led sessions, real-world customer scenarios, and extensive live demos, you'll learn how organisations are modernising endpoint management, strengthening security, automating operations, and embracing AI-powered administration. Explore new capabilities, best practices, product innovations, and roadmap updates covering modern provisioning, application management, endpoint security, Zero Trust, privilege management, automation, and operational excellence at scale. If you want practical insights, technical deep dives, and real-world guidance you can apply immediately, this Master Class is for you.
-
Master Class: AI low code
Master Class 420 min Room TreeHouse South-Floor 1-Max 57-MC AI for Makers (Copilot & Agents) Advanced (300)Tue 09 Feb, 09:00–16:00We're putting the final touches on the agenda. Worth the wait, we promise!
-
How to deploy Azure Local into Azure Landing Zone design framework
Technical Session 60 min Room 20-Floor 1-Max 118 Azure Advanced (300)Wed 10 Feb, 08:25–09:25With Christoffer JakobsenAzure Local has introduced a new way to design landing zones with the Local Management Group, changing how we approach governance, subscription boundaries, and workload isolation. In this session, you'll learn how Microsoft's updated guidance enables Azure Local clusters to host workloads across multiple subscriptions while maintaining clear separation between platform and application resources. We'll walk through the recommended management group hierarchy, explain the role of Custom Locations, and discuss how to apply Azure Policy and RBAC in this new architecture. Using practical examples and lessons learned from real deployments, we'll cover the key design decisions, common pitfalls, and scenarios where the new model works well—and where it doesn't. Whether you're planning a new Azure Local deployment or modernizing an existing one, you'll leave with a clear understanding of Microsoft's recommended landing zone architecture and the confidence to design it correctly.
-
ELDK27 Welcome
Technical Session 60 min Room A1 Keynote-Floor 0-Max 1500 Security Advanced (300)Wed 10 Feb, 09:00–10:00Welcome Keynote ELDK27
-
AVD Hybrid: Vibe Coding Your Way Off Legacy VDI
Technical Session 60 min Room 16-Floor 1-Max 44 Azure Black Belt (500)Wed 10 Feb, 10:00–11:00With Adam NicholsEUC teams everywhere are re-evaluating their VDI stack. This session skips the slideware and live-builds a real AVD Hybrid toolkit using AI-assisted "vibe coding" and free, existing accelerators. Bring your questions and real-world scenarios and leave with tools to kick-start your own transition.
-
Test Session
Technical Session 60 min Room 16-Floor 1-Max 44 Security Expert (400)Wed 10 Feb, 10:00–11:00Don't miss this session, first time shown worldwide !
-
An Entra ID admin’s guide to user states in Identity Governance
Technical Session 60 min Room 17-Floor 1-Max 49 Identity Expert (400)Wed 10 Feb, 10:00–11:00User states are the engine behind intelligent identity governance, but most organizations only scratch the surface of what's possible. In this session, discover how to harness user attributes and states in Microsoft Entra to automate complex access scenarios and streamline lifecycle management, whether it’s using the built-in attributes or custom extensions. We'll walk through real-world automation patterns, show you how to build dynamic governance workflows that respond to changing user states, and demonstrate a complete end-to-end flow using Lifecycle Workflows and Access Packages. Learn how to turn static identity data into actionable automation that adapts to your organization's unique needs. Perfect for Entra admins ready to unlock smarter, more responsive identity governance.
-
Beyond Intune: The macOS Community Toolbox
Technical Session 60 min Room 19-Floor 1-Max 106 Intune Advanced (300)Wed 10 Feb, 10:00–11:00Microsoft Intune has come a long way in managing macOS - but sometimes the best solution isn’t built into Intune. In this follow-up to our community tools session, Simon and Ugur return to explore the tools, scripts, and open-source projects that make macOS management with Intune even better. We’ll look at real-world challenges around application management, onboarding, configuration, inventory, automation, and troubleshooting - and show how the macOS community helps fill the gaps. Expect live demos, practical examples, GitHub projects you’ll want to bookmark, and an honest look at where native Intune ends and the community takes over. When you leave this session, you’ll have a to-do list full of community tools you’ll want to try in your own macOS environment.
-
Hardening GitHub: From Default to Defended
Technical Session 60 min Room 4-Floor 1-Max 49 Security Black Belt (500)Wed 10 Feb, 10:00–11:00With Pierre ThoorGitHub ships with sensible defaults. The problem is that sensible defaults aren't security controls - and the gap between them is where real attacks land. In this demo-heavy session, we go hands-on with the security decisions that most organizations either skip, misconfigure, or misunderstand. Through live demonstrations, we'll trace how attackers exploit workflow triggers, overly permissive tokens, unpinned Actions, and bypassed secret protection - then close each gap in real time. We'll also connect GitHub security to the broader Microsoft security stack - how Defender for Cloud surfaces DevOps posture findings, how Entra workload identity federation replaces long-lived secrets in pipelines, and how to get GitHub audit signals into your existing detection and response workflows. This isn't a product overview. Every demo is rooted in attack patterns being used right now, with fixes you can apply the same week.
-
Breaking Identity at Scale: From DPAPI & TBAL Secrets to Full Domain Compromise
Technical Session 60 min Room A1 Keynote-Floor 0-Max 1500 Security Expert (400)Wed 10 Feb, 10:00–11:00With Paula JanuszkiewiczModern enterprise environments continue to rely on implicit trust within identity and credential protection mechanisms such as DPAPI, DPAPI-NG, and token-based authentication layers. While these technologies are designed to safeguard secrets, they also introduce powerful attack surfaces when combined with misconfigurations, weak privilege boundaries, and overlooked trust relationships. This session presents a deep technical exploration of how attackers extract and abuse protected credentials at scale, moving from local access to full domain compromise. We demonstrate novel techniques for decrypting DPAPI-protected data, abusing TBAL-related key material, and chaining these with authentication protocol weaknesses such as NTLM and Kerberos to achieve lateral movement and privilege escalation. Unlike traditional approaches that focus on single techniques, this research connects multiple layers of identity abuse into a cohesive attack path observed in real-world environments. Attendees will see how seemingly isolated weaknesses: credential storage, token handling, and protocol trust, combine into high-impact attack chains. The session also provides defensive strategies, including detection opportunities, hardening approaches, and architectural changes to reduce reliance on implicit trust. The goal is to shift defenders from reactive detection to proactive identity security design.
-
Global Secure Access Deep Dive: Following the Sign-In, Not the Packet
Technical Session 60 min Room A3-Floor 0-Max 250 Identity Expert (400)Wed 10 Feb, 10:00–11:00With Christopher BrummGlobal Secure Access is usually run as a network project. But the moment the first client is enrolled, things show up in the tenant that nobody registered: enterprise applications you did not create, sign-in entries for resources that are not web apps, and a network attribute Conditional Access suddenly has something to say about. This session stays on the Entra side and follows a sign-in from the client to the policy decision. It starts with the applications Global Secure Access brings into the tenant, what an access to each of them actually represents, and why the split between forwarding profile and application is the thing to understand before writing a policy against them. That split is also where the surprises come from: a sign-in frequency on the wrong object, and internal name resolution starts producing MFA prompts. Then the network condition itself: what the compliant network check proves that a named location cannot, why source IP restoration matters, and where the check sits relative to device compliance. The difference only becomes obvious in the cases that matter. A replayed token, or an intercepted authorization code redeemed by someone who was never near the device that started the flow — in both, the device conditions no longer describe the party presenting the artifact. What is left is the network condition, and only if it cannot be spoofed. Then the other direction: Universal Tenant Restrictions, for when the identity is not one of yours. And the part that gets people hurt: requiring a compliant network tenant-wide is a lockout in waiting. Break-glass accounts, unenrolled devices, guests and platforms without a client all need an answer before the policy goes into report-only, let alone on. Demos and log evidence where it matters — Global Secure Access traffic logs and Entra sign-in logs side by side, including the cases where only one of the two tells you what happened.
-
Beyond the Sync Button: Inside Windows and Intune Device Management
Technical Session 60 min Room Auditorium A15-Floor 0-1-Max 582 Intune Black Belt (500)Wed 10 Feb, 10:00–11:00What actually happens when a Windows device synchronizes with Microsoft Intune? Windows management is no longer based on a single protocol or configuration channel. Traditional OMA-DM and SyncML coexist with the Intune Management Extension, Policy CSP, ADMX-backed policies, security baselines, and the emerging Declarative Device Management model. Each channel has its own processing logic, reporting behavior, troubleshooting methods, and potential failure points. In this Level 500 session, Mattias Melkersen and Rudy Ooms will take you deep inside the communication between Windows and Intune. We will follow policies from assignment and delivery through local processing, enforcement, and status reporting, exposing what happens behind the green check marks and generic error messages in the Intune portal. We will examine why some policies apply immediately while others remain pending, conflict, fail silently, or report success without producing the expected result. We will also challenge some of the assumptions administrators make when working with imported ADMX templates, settings catalog policies, configuration profiles, and Microsoft security baselines. As Windows gradually moves from command-based SyncML processing toward declarative configuration, the management architecture is changing. We will explore how declarative management differs from the traditional request-and-response model, what problems it is intended to solve, and why it could make device management more reliable and predictable. Expect protocol-level explanations, real-world failures, log analysis, and live troubleshooting. No introductory portal tour. No “click here to create a policy.” This session is about understanding what Windows and Intune are actually doing, so you can diagnose configuration problems instead of repeatedly pressing Sync and hoping for the best.
-
Panel Discussion 1
Panel Discussion 60 min Room TreeHouse North-Floor 1-Max 96 Security Advanced (300)Wed 10 Feb, 10:00–11:00Panel Discussion 1
-
Data In, Secrets Out: Building Secure, Compliant AI Systems
Technical Session 60 min Room 16-Floor 1-Max 44 AI for Engineers/Developers (Build Your Own AI) Expert (400)Wed 10 Feb, 11:30–12:30With Saurabh MhaisekarAI systems process sensitive data at every layer — from user prompts containing PII to RAG pipelines retrieving access-controlled documents. Most architectures treat compliance as an afterthought, leaving personal data unfiltered in prompts, retrieval results leaking across authorization boundaries, and no auditable record of what the model saw or said. In this demo-driven session, we'll trace the full lifecycle of data through an AI system and fix every point where compliance breaks. You'll see PII detected and sanitized before it ever reaches the model using Azure AI Language and Presidio. You'll watch a RAG pipeline leak confidential documents across users — then lock it down with Azure AI Search security filters and Entra ID scoping. You'll see how API Management and Application Insights create a regulator-ready audit trail of every prompt and response. And you'll walk away with an Azure Workbooks dashboard that answers any auditor's question before they finish asking it. No slides-only theory. real problems, live demos, one architecture you can implement the next day.
-
Your Cloud, Your Rules: Azure Sovereignty in Action
Technical Session 60 min Room 20-Floor 1-Max 118 Azure Advanced (300)Wed 10 Feb, 11:30–12:30With Andreas SobczykExplore Azure's comprehensive sovereignty solutions designed for regulated industries and sensitive workloads. Learn how to architect and implement robust governance using Well-Architected Landing Zones, secure data with Confidential Compute and Customer-managed Keys, leverage Data Guardian and Regulated Environment Management for compliance automation, and deploy Azure Local in both connected and disconnected modes for true sovereignty across hybrid scenarios.
-
Infrastructure as code in the age of AI agents
Technical Session 60 min Room 5-Floor 1-Max 89 Azure Advanced (300)Wed 10 Feb, 11:30–12:30With Erwin StaalHave you ever stared at a Terraform module and wondered: why am I writing this? If an AI agent can provision infrastructure directly, what's the point of hand-crafting HCL files? It's a question the entire IaC industry is wrestling with right now. Pulumi shipped a fully agentic infrastructure agent. Spacelift provisions infrastructure from natural language with no configuration files at all. Meanwhile, LLMs struggle with DSL syntax but somehow still generate working infrastructure. In this session, we'll explore what's actually happening in the Infrastructure as Code space. We'll examine how AI agents are changing the way we provision cloud resources and whether traditional tools like Terraform and Bicep still have a place in this new world. Apart from declaring our infrastructure there's also the safety mechanisms we've built into IaC: state management, governance, idempotency, and rollback. These things become more important, not less, when AI is making the changes. We'll look at how leading vendors are solving this challenge and what it means for your infrastructure practice. You'll walk away understanding why DSLs are becoming the assembly language of infrastructure: still essential, rarely hand-written, and more critical than ever.
-
MCP and it's application in the real world
Technical Session 60 min Room 5-Floor 1-Max 89 AI for Makers (Copilot & Agents) Expert (400)Wed 10 Feb, 11:30–12:30With Tobias FensterIntegrating backends, tools and resources into AI solutions was a challenge that needed a lot of different answers until MCP, the Model Context Protocol arrived. In this session, we will take a look at the general concepts and idea and then take a deep dive into the protocol and practical applications, using Microsoft Dynamics 365 Business Central as the real-life example, but those learnings will be transferrable to other technologies. After this session, you will have an understanding of how MCP works, where you can use and why you should start to integrate it into your AI offerings.
-
What’s in Your Logs? - Expert Edition
Technical Session 60 min Room A1 Keynote-Floor 0-Max 1500 Security Black Belt (500)Wed 10 Feb, 11:30–12:30With Bert-Jan PalsThreat hunters, Detection Engineers, SOC/IR analysts and other security specialists all depend on logs. Yet one of the biggest challenges in remains surprisingly fundamental: Do you actually know what is in your logs? Most security teams know which data sources they have onboarded. They know the tables, schemas, and products. But knowing that a log source exists is not the same as understanding the full security value hidden within it. This Level 500 Black Belt session goes beyond the traditional discussion of log sources and telemetry. We will explore using demo's how to systematically discover, validate, classify, and operationalize the data available in your environment. After this session, attendees will have: - A repeatable methodology for exploring unfamiliar log sources. - Techniques for discovering security-relevant telemetry hidden in existing data. - Azure native automation for log content and schema discovery. - Practical ways to connect log discovery with threat hunting and detection engineering. Audience: Experienced threat hunters, detection engineers, SOC analysts, incident responders, security architects, automation specialists and everyone who wants to get more value out of their logs
-
Edge Management Service - the modern way to manage Edge
Technical Session 60 min Room A2-Floor 0-Max 350 Intune Advanced (300)Wed 10 Feb, 11:30–12:30With more and more applications being web based, the most important application we have on our modern devices Microsoft Edge and browsers. Traditionally we have managed them using Group Policy and/or Intune. But with the introduction of the Edge management service in Microsoft Edge (and Google Chrome) we now have a modern way! Let users request their Extensions, manage extensions and settings in a modern way! We can also apply security settings to external users and users of BYOD devices. During this demo heavy session we will go through how to configure, secure and enforce a browser Edge, and more important what not to do!
-
Mastering Purview data security solution design: Lessons from years of deployments
Technical Session 60 min Room A3-Floor 0-Max 250 Data Compliance & Security Expert (400)Wed 10 Feb, 11:30–12:30With Tatu SeppäläIt is said a successful Purview data security solution is 80% adoption, 20% technology. This is more or less true, but ultimately your success hinges on getting that 20% *exactly* right! In practice, this means more than just reading documentation - you need a solid grasp of undocumented nuance and experience on a wide range of details Microsoft doesn't tell you about. There are plenty of hard-learned design patterns and common mistakes that are easy to make if you aren't prepared. Join this session to learn lessons from the speaker's years of experience and dozens of production design and deployment projects across industries. During the session, we cover technical topics including but not limited to: - Tenant-level technical preparations, incl. Powershell-only configurations - Sensitivity label and DLP policy gotchas and tricks - Encryption fine-tuning - Data-driven solution design w/ KQL - How to block the bad, without blowing up processes - Fatal solution design mistakes you'll want to avoid Simply put, this session helps you walk a smoother path with your technical Purview data security solution design and deployment. The session is especially well-suited for security architects, data security responsibles and anyone interested in understanding the do's and dont's of data security picked up during demanding projects across industries.
-
OAuth Flows in Entra ID: Fundamentals You Thought You Knew
Technical Session 60 min Room Auditorium A15-Floor 0-1-Max 582 Identity Expert (400)Wed 10 Feb, 11:30–12:30OAuth 2.0 and OpenID Connect are the foundation of every authentication and authorization decision Entra ID makes – yet which flows are actually still in use, what artifacts like tokens and credentials they produce, and where the real risk sits are details even people who work with Entra ID daily tend to get fuzzy on. In this session we take a genuinely deep look at these fundamentals: which flows exist and which ones you'll actually encounter in Entra ID today versus which are effectively legacy, what happens to tokens and credentials at each step, and why getting this "basic" mental model wrong is exactly what makes so many real-world attacks possible in the first place. We'll also cover which flows should make your alarm bells go off and the classes of attacks they enable – enough protocol-level detail to satisfy identity experts, without turning this into a dedicated attack showcase. Whether you're new to Entra ID or have been doing this for years, expect to leave with a sharper mental model of what's actually happening under the hood.
-
Panel Discussion: 2
Panel Discussion 60 min Room TreeHouse North-Floor 1-Max 96 Security Advanced (300)Wed 10 Feb, 11:30–12:30 -
Entra External ID Explained #ExpertFieldTips
Technical Session 60 min Room 18-Floor 1-Max 92 Identity Expert (400)Wed 10 Feb, 13:30–14:30With Erwin DerksenIn this session i will explain all about the new Entra External ID, Microsoft's successfor of B2C. Azure B2C was used but for me always remained in the background. What's new in this External ID 'B2C replacement' and how can you use it in your organization. What are the caviats? All #BulletPointFree, #Critical and #NoMarketing
-
Secure your Entra & Intune Automations with Managed Identities
Technical Session 60 min Room A3-Floor 0-Max 250 Intune Advanced (300)Wed 10 Feb, 13:30–14:30With Jan Ketil SkankeDitch app secrets and embrace the power of managed identities for your automation. Whether you use Logics Apps, Azure Functions or Azure Automation, managed identities should be in the core of what you do. Learn how to leverage Entra ID managed identities together with Microsoft Graph API to create secure, credential-free automation workflows and automation jobs. This session is demo heavy showing step by step how to setup and use managed identites and showcase real use cases.
-
Thanks for accepting the invite! I’m GA now
Technical Session 60 min Room Auditorium A15-Floor 0-1-Max 582 Security Black Belt (500)Wed 10 Feb, 13:30–14:30SESSION INFORMATION SHARED UNDER "NDA" - DO NOT SHARE OR DISCUSS WITH OUTSIDE PARTIES! With Entra ID governance you gain a lot of control over tenants in your enterprise. But with great power comes great responsibility and in this session we will discuss a novel lateral movement path introduced by this feature in every tenant. Moving from theory to defense, we will share real-world insights on how to design a secure, delegated access model using Entra ID Governance. We will cover how to protect access both from the managing and in the managed tenant, and why your Conditional Access design must specifically account for these cross-boundary access paths. Finally, we will demonstrate how to detect unauthorized modifications to trust relationships and hunt for these lateral movement paths using EntraOps, empowering you to protect your multi-tenant environment.
-
Panel Discussion: 3
Panel Discussion 60 min Room TreeHouse North-Floor 1-Max 96 SecurityWed 10 Feb, 13:30–14:30 -
Top security settings you must configure in Windows 11
Technical Session 60 min Room A1 Keynote-Floor 0-Max 1500 Intune Expert (400)Wed 10 Feb, 15:00–16:00Windows 11 is the most secure Windows version built so far and there are big differences in managing Windows 10 and Windows 11 from a security perspective, there are even differences between Windows 11 versions. In this session we will focus on new features and what we need to know when securing a Windows 11-26H2 device. In the times we live in with constant cyber threats we must learn and know about new security features to keep our devices protected, regardless if they are physical or virtual. During this session we will cover our top 10 configurations we must configure in Windows 11. We will have a look at what they do and how they affect our devices. Join for great tips on how to take your Windows security posture to the next level
-
Panel Discussion: 4
Panel Discussion 60 min Room TreeHouse North-Floor 1-Max 96 Security Advanced (300)Wed 10 Feb, 15:00–16:00 -
No Passwords, No Weak Links: Securing Microsoft Teams Devices the Right Way
Technical Session 50 min Room 4-Floor 1-Max 49 Microsoft 365 Expert (400)Thu 11 Feb, 07:20–08:10Microsoft Teams devices are becoming critical endpoints in the modern workplace. They sit in open spaces, boardrooms, project rooms, and shared collaboration areas—and they often hold the keys to meetings, calendars, identities, and business conversations. Yet many meeting rooms still rely on traditional room account passwords, manual sign-in processes, exceptions to MFA, and operational workarounds that can weaken the overall security model. This session explores how passwordless principles can change the way we deploy, secure, and manage Microsoft Teams Rooms and Teams devices. We will look at the move from “shared password thinking” toward device identity, modern authentication, cloud-based provisioning, conditional access, Intune management, Teams Rooms Pro Management, and automated sign-in patterns that reduce human handling of credentials. The focus is practical: what does passwordless really mean for a meeting room device? What is different between Windows-based Teams Rooms, Android-based Teams devices, panels, phones, and shared devices? Where do authentication flows still depend on room accounts, and where can administrators remove passwords from daily operations? We will discuss how Autopilot, Autologin, device registration, managed identities, compliance policies, and role-based administration can help create a more secure and repeatable deployment model. A key theme will be meeting room security. Passwordless is not only about convenience. It reduces the risk of leaked or reused passwords, limits the need for broad administrative access, makes device onboarding more predictable, and supports stronger control through Microsoft Entra ID, Intune, and Teams management portals. When implemented correctly, it can significantly raise the security baseline for meeting rooms while making life easier for IT operations and support teams. Attendees will leave with a clear understanding of the security challenges around Teams device sign-in, the passwordless concepts that apply to meeting rooms, and the practical decisions to consider when designing a secure Teams device strategy. The session is aimed at IT architects, Teams administrators, endpoint teams, security teams, and anyone responsible for deploying or operating Microsoft Teams Rooms and shared Teams devices in the enterprise.
-
DIY Intune Tools: PowerShell + Graph = Admin Superpowers
Technical Session 60 min Room A2-Floor 0-Max 350 Intune Advanced (300)Thu 11 Feb, 07:20–08:20In this session, you will learn how to create your own tools using PowerShell and Graph API. These tools can help you manage Intune, users, devices, and security tasks more easily. We will show real examples that you can use in your daily work. This session is made just for ExpertsLive Denmark and will help you save time, work smarter, and improve how you manage your environment. Advanced understanding for Graph API and coding in general will help a lot.
-
The two sided race: How AI Reshaped Both the Attack and Defense
Technical Session 50 min Room A3-Floor 0-Max 250 Security Expert (400)Thu 11 Feb, 07:20–08:10With Jeroen NiesenWe have spent thirty years quietly putting AI to work in security. Spam filters, anomaly detection, malware classifiers. Nobody called it AI back then. What changed isn't that defenders finally got smart tools. It's that the attackers got the exact same ones, at the same time. In this session I'll walk you up the curve I have watched both sides climb, from machine learning to assistant to agent and now to autonomous, and I'll show you where each tool is already being used against you. We'll look at the deepfake video call that moved USD 25 million. We'll look at the malware that writes a fresh payload every time it runs, so your signatures never catch it. And we'll look at the intrusion campaign where the AI did roughly 90 percent of the work on its own. Then I'll flip it, because the defense is climbing just as fast. You'll see attack disruption cut a live attack in minutes. You'll see a portfolio of security agents (Security Copilot) that investigates a serious attack. And you'll see the frontier research that flushed out ten thousand real vulnerabilities in its first weeks. Expect real incidents, learn about both sides (attack perspective and defence perspective) what works and what blows up, demo's and room for questions.
-
From Copilot to USB: Protecting Sensitive Data Across Every Endpoint
Technical Session 60 min Room 18-Floor 1-Max 92 Data Compliance & Security Advanced (300)Thu 11 Feb, 10:00–11:00With Kasper NorregaardSensitive data does not stay in Microsoft 365. It is downloaded, copied, printed, synced, uploaded to cloud services, and increasingly pasted into AI tools. In this session, we follow the data from Microsoft 365 to Windows and macOS endpoints and show how Microsoft Purview Endpoint DLP builds on Defender for Endpoint onboarding to monitor and control how sensitive information is used. Through technical demos, we configure advanced classification, application and browser restrictions, USB and printer controls, network share protection, Policy Tips, and user overrides. We then extend the strategy to Copilot and generative AI by controlling sensitive prompts and content, using Data Security Posture Management, and exploring AI-assisted investigations of risky data movement. You’ll leave with a practical blueprint for designing, testing, and operating endpoint data protection across platforms, balancing effective controls with a productive user experience.
-
From Code to Agents: Building Production MCP Servers on Azure Functions with .NET
Technical Session 60 min Room 20-Floor 1-Max 118 Azure Expert (400)Thu 11 Feb, 10:00–11:00With Jonah AnderssonEvery enterprise team building with AI agents hits the same wall: your agents are smart, but they’re isolated. They can’t access your internal tools, your DevOps pipelines, your ticketing systems, or your customer data — not without fragile, custom integrations that break every time something changes. The Model Context Protocol (MCP) solves this by giving agents a universal way to discover and call tools. But the question developers keep asking is: how do I take MCP from a local prototype to a production-grade, scalable service my entire organization can rely on? This question hits differently depending on who you are. Enterprise developers are blocked by security and compliance requirements and need to prove ROI to leadership. AI developers are drowning in agent orchestration complexity while trying to balance cost, latency, and quality. Elite developers need scale and reliability at the frontier and can’t afford slow innovation cycles — time is their scarcest resource. This session answers that question with a live, end-to-end build. We’ll construct production MCP Servers using Azure Functions and .NET — turning serverless functions into discoverable, secure tool endpoints that any AI agent can call. Attendees will see two real-world scenarios come to life: • DevOps Automation Agents: A multi-agent system that monitors deployments, triages incidents in Azure DevOps, runs diagnostics via MCP tool calls, and auto-creates remediation PRs — all orchestrated by agents that discover capabilities at runtime. • Multi-Agent Customer Service: A customer-facing system where specialized agents each expose their domain tools as MCP servers, and a routing agent dynamically selects the right specialist based on context.
-
Transforming Software Development with Agentic AI
Technical Session 60 min Room A2-Floor 0-Max 350 AI for Engineers/Developers (Build Your Own AI) Advanced (300)Thu 11 Feb, 10:00–11:00With Rasmus HaldReimagining the SDLC through intelligent agents and GenAI The age of Agentic AI is here—and it comes with a promise of reshaping how we build software. In this talk, we’ll explore how intelligent agents, large language models, and context-aware automation are transforming the software delivery lifecycle from a manual, tool-centric process into a fluid, AI-augmented system of collaboration and execution. You’ll learn how engineering teams are integrating Agentic AI to: • Accelerate requirements gathering, design, and implementation • Automate low-value tasks while elevating human creativity • Improve flow efficiency using AI-augmented value stream mapping • Rethink roles, workflows, and developer experience in an AI-native future Whether you’re a developer, tech leader, or transformation driver, this session will equip you with the language, models, and strategic insights to bring Agentic AI into your own software development practice.
-
Context Is the New Prompt: Building Enterprise AI with Work IQ
Technical Session 60 min Room TreeHouse South-Floor 1-Max 90 Microsoft 365 Advanced (300)Thu 11 Feb, 10:00–11:00With Kamal ShreeAs AI moves beyond prompt engineering, context has become the foundation of intelligent enterprise applications. In this session, explore how Work IQ enables Microsoft 365 Copilot and AI agents to deliver more accurate, relevant, and secure responses by grounding them in organizational knowledge and business context. Through practical demonstrations and real-world scenarios, you'll learn how to build context-aware AI solutions that leverage enterprise data, semantic understanding, and Microsoft 365 extensibility to create more intelligent and trustworthy experiences.
-
Gone in 180 minutes – From social engineering to domain dominance
Technical Session 60 min Room 19-Floor 1-Max 106 Security Expert (400)Thu 11 Feb, 11:30–12:30With Hasain AlshakartiIn just 180 minutes, a determined attacker moved from a convincing social engineering call to full control of a corporate domain. This session unpacks that incident in detail, showing how a blend of human manipulation, overlooked identity gaps, and misconfigured systems opened the door to rapid escalation. We’ll walk through the attack step by step—illustrating the tactics used, the decisions that accelerated compromise, and the warning signs that were missed along the way. Alongside the technical trail, we’ll highlight the organizational lessons: why culture, processes, and training matter just as much as tools. By the end, attendees will walk away with a clear view of how modern attackers operate and concrete actions any team can take to strengthen resilience and shorten response times.
-
From Rollout to Black Belt: What Karate Taught Me About Microsoft 365 Adoption
Technical Session 60 min Room 5-Floor 1-Max 89 Microsoft 365 Advanced (300)Thu 11 Feb, 11:30–12:30With Gitta BleijendaalYou don’t become a black belt by attending a single training. You don’t master a technique by seeing it once. And you definitely don’t build discipline without repetition, feedback, and consistency. Yet somehow… this is exactly how we approach Microsoft 365 adoption. We roll out the tools. We schedule a training. We send a few communications. And then we’re surprised when nothing really changes. In this session, we’ll take an honest look at what actually happens when organizations try to drive adoption and why so many well-intended approaches fall short. Through real stories from the field, we’ll explore: Why combining key users and ambassadors seemed efficient… until no one wanted (or understood) the role How a simple decision around Microsoft Authenticator created distrust instead of adoption What happens when “adoption teams” exist, but no one knows who’s responsible for what And why “just one training” continues to fail, despite everyone knowing better Along the way, we’ll connect these experiences to an unexpected source: karate. Because the gap between knowing and doing, between rollout and adoption, isn’t a technology problem. It’s a behavior problem. From white belt to black belt, progress doesn’t come from tools or intentions. It comes from: Repetition over one-time effort Habits over knowledge Reinforcement over announcements And visible practice over invisible expectations No abstract frameworks. No perfect-case scenarios. Just honest lessons about what works, what doesn’t, and what actually helps people change the way they work. Because if people don’t use it…it doesn’t exist.
-
Hello Passkey, Bye Password: Phishing-Resistant MFA Made Simple
Technical Session 60 min Room 6-7-Floor 1-Max 99 Intune Expert (400)Thu 11 Feb, 11:30–12:30With Lee SchlipphakPasswords are history - modern authentication is passwordless, phishing-resistant and user-friendly. Windows Hello for Business (WHfB) delivers exactly that. Combined with Microsoft Intune it enables centralized management and seamless integration into endpoint and identity strategies. This session shows how to configure and deploy WHfB with Intune, from prerequisites to best practices, while exploring the benefits of passwordless authentication and phishing-resistant MFA.
-
Every Agent Is a New Identity: Securing the Non-Human Workforce
Technical Session 60 min Room TreeHouse South-Floor 1-Max 90 Identity Expert (400)Thu 11 Feb, 11:30–12:30With Tracy LeeEvery production agent acts on behalf of a person, team, or business process. That makes it a new identity with credentials, permissions, tool access, data boundaries, and an accountability trail. Yet many agent deployments still rely on shared secrets and broad service accounts, making least privilege, attribution, and revocation nearly impossible. This session provides a practical security architecture for the non-human workforce. Drawing on the agent-control patterns we are implementing at This Dot, I will show how to inventory agents, establish workload identity, constrain tools and data, preserve the initiating user’s authority, record decision and action trails, and require human approval for sensitive operations. We will also examine the hard cases: agent-to-agent delegation, ephemeral workers, conflicting policy layers, and shutting down one compromised agent without stopping the business. Attendees will leave with a threat model and a staged plan for replacing shared credentials with governed agent identities.
-
Battle for the Multi-Cloud: Managing AWS, GCP, and Beyond with Azure Arc
Technical Session 60 min Room 18-Floor 1-Max 92 Azure Expert (400)Thu 11 Feb, 13:30–14:30With Wim MatthyssenAs more organizations adopt a multi-cloud strategy, many struggle with maintaining consistent visibility, governance, and security across Azure, AWS, GCP, and on-premises environments. In this demo-driven session, I'll show how Azure Arc simplifies multi-cloud management by providing a unified approach to managing and governing AWS EC2 instances, Google Compute Engine VMs, and on-premises resources. Using Azure Arc Multicloud Connectors, you'll see how automated onboarding, centralized policy enforcement, inventory management, and seamless integration with Azure services simplify operations, strengthen governance, and provide clear visibility across your entire estate. Join me to discover how Azure Arc enables you to manage all your resources using the same tools and processes, helping you regain control, reduce operational complexity, and simplify day-to-day management. Let the battle begin.
-
Building Trusted Data for Microsoft 365 Copilot: Reducing Oversharing and Information Risk
Technical Session 60 min Room 19-Floor 1-Max 106 Data Compliance & Security Expert (400)Thu 11 Feb, 13:30–14:30Microsoft 365 Copilot does not create new permissions, but it can make existing data access problems far more visible. Years of overshared, inactive and sensitive content across SharePoint, Teams and OneDrive can become part of the information surface available through Copilot, turning longstanding governance weaknesses into immediate business risk. This Level 400 session presents a practical architecture for building Trusted Data for Microsoft 365 Copilot using the Trusted Data framework of Visibility × Governance × Evidence. Governance is operationalised through three control outcomes: Reduce, Restrict and Protect, while Measure provides the evidence needed to validate that these controls are working. Rather than treating Copilot readiness as a single security configuration, attendees will learn how to reduce the information surface available through AI, restrict access to high-risk workspaces, protect sensitive information through classification and policy enforcement, and measure whether governance controls are operating effectively. The session brings together Microsoft 365 Archive, SharePoint Advanced Management, container-level governance controls, Microsoft Entra permissions, Microsoft Purview sensitivity labels, encryption, DLP and data security insights into a unified governance architecture. Using real-world scenarios, we will examine the architectural decisions behind each control, where controls complement and overlap with one another, and which risks cannot be solved through Copilot configuration alone. Attendees will learn how to prioritise remediation based on risk rather than attempting to remediate the entire Microsoft 365 estate before enabling AI. Attendees will leave with a practical roadmap for assessing their Microsoft 365 environment, reducing oversharing, strengthening information governance, and building the evidence required to confidently scale Microsoft 365 Copilot and AI adoption. Key Takeaway: Trusted Data for Microsoft 365 Copilot is not a Copilot configuration problem. It is an information governance challenge addressed through Reduce + Restrict + Protect + Measure, underpinned by Visibility, Governance and Evidence.
-
Copilot Agent Management: Regain control before agents run wild
Technical Session 60 min Room 19-Floor 1-Max 106 Microsoft 365 Advanced (300)Thu 11 Feb, 13:30–14:30With Daniel RohreggerAgents are everywhere: are you ready to manage them? This session gives you a clear model of Microsoft 365 agent technologies and a practical blueprint to inventory, secure, monitor, and govern them without slowing adoption. Copilot Agents are moving from POC to production fast, and admins need to know which controls live where, how to prevent oversharing, and how to show usage and value to leadership. While Agent 365 surfaces the different agents from platforms like Agent Builder, Copilot Studio, Foundry and more, we need to understand that there is more to it. Agents using existing data on SharePoint, querying MCP servers, having their own permissions and exchanging information with other agents. Finally, we look at cost, environment, and access strategies so you can scale safely, including when pay-as-you-go for agent chat makes sense before full licensing. You will leave with a realistic approach to inventory, risk reduction, monitoring, and lifecycle management you can apply in your tenant the next day.
-
Supercharging Modern Endpoint Management
Technical Session 60 min Room 20-Floor 1-Max 118 Intune Advanced (300)Thu 11 Feb, 13:30–14:30With Peter DaalmansCombining the strengths of Intune, Entra ID and other Microsoft solutions, this session delivers practical strategies to make endpoint administration in 2027 simpler, faster and more secure. Packed with (live) demos, it highlights upcoming capabilities, essential tools, and actionable governance tips to help keep your environment clean, compliant and confidently under control.
-
Azure Virtual Desktop – Unlocking High Performance & Great User Experiences
Technical Session 60 min Room TreeHouse South-Floor 1-Max 90 Azure Expert (400)Thu 11 Feb, 13:30–14:30With Marcel MeurerAzure Virtual Desktop can deliver an amazing user experience — but only if you know where to tune it. Many AVD environments feel slower than they should, leaving users frustrated and admins wondering where the bottlenecks really are. In this practical and insight-packed session, we’ll explore how to unlock the full performance potential of your AVD hosts using simple but often overlooked techniques. You’ll learn how to analyze and optimize the most critical performance factors in an AVD environment — from Windows 11 internals to profile processing, storage performance, and resource management. We’ll dive into how Windows behaves in multi-user and single-user scenarios, what really impacts login times, and where hidden performance drains often occur. We’ll cover topics such as: - How Windows 11 behaves in AVD multi-session vs single-session environments - Identifying and monitoring performance bottlenecks in your AVD hosts - Optimizing storage and disk performance for faster sessions - Why profile handling can make or break the user experience - Smart host warm-up techniques to eliminate slow first logins - Practical scripts and tools you can take home and use in your own environment Along the way, we’ll uncover the small adjustments and hidden tuning options that can dramatically improve responsiveness and user satisfaction. If you want your Azure Virtual Desktop environment to feel fast, smooth, and reliable, this session will give you the practical knowledge and real-world tricks to make it happen.
-
From concept to a productive application - How AI can support you
Technical Session 60 min Room TreeHouse South-Floor 1-Max 90 AI for Engineers/Developers (Build Your Own AI) Expert (400)Thu 11 Feb, 13:30–14:30With Jannik ReinhardIn today’s rapidly evolving digital landscape, artificial intelligence (AI) is no longer just a futuristic concept but a powerful tool that can transform ideas into productive applications. This session will guide you through the journey of leveraging AI from the initial concept phase to the deployment of a functional and efficient application. We will explore how AI can enhance your project development by automating complex tasks, providing insights through data analysis, and creating smarter, more responsive applications. Whether you're a developer, project manager, or business leader, this session will equip you with practical strategies to integrate AI into your workflows, helping you to innovate and stay ahead of the competition.
-
Securing AI Agents: From Identity Control to Runtime Defense
Technical Session 60 min Room TreeHouse South-Floor 1-Max 90 Identity Advanced (300)Thu 11 Feb, 13:30–14:30With Pim JacobsAs organizations scale automation and agentic AI, AI agents become privileged actors—embedded deep in business critical workflows, data flows, and decision chains. But what happens when an agent is misconfigured, compromised, or starts consuming malicious resources? In this session, we unpack the security architecture of AI agents and expose the often overlooked risks hiding behind autonomous behavior. We walk through how to secure agents end to end using Agent 365’s security stack—from identity and access controls, to policy enforcement, to runtime threat protection. Expect real world examples of common agent misconfigurations, attack paths targeting agent identities and tools, and practical mitigation strategies. You’ll leave with a clear security blueprint to build a trustworthy, resilient agent ecosystem—designed to withstand real world threats, not just theoretical risks.
-
Demystifying AVD and Windows 365 Networking, Azure Private Link, RDP Shortpath, and MHN Explained
Technical Session 60 min Room 18-Floor 1-Max 92 Azure Expert (400)Thu 11 Feb, 15:00–16:00In this session, we demystify the networking options behind Azure Virtual Desktop and Windows 365. We break down how traffic flows work in real world deployments and explain when and why to use Azure Private Link, RDP Shortpath (over managed and unmanaged networks), and Microsoft Hosted Network (with or without VPN). Through practical examples and field experience, you will learn the impact of each option on performance, security, and connectivity. Expect clear explanations, common pitfalls, and guidance to help you choose the right networking model for your environment with confidence.
-
When Agents Go Rogue: Threat Protection for Agentic AI Systems
Technical Session 60 min Room 18-Floor 1-Max 92 AI for Engineers/Developers (Build Your Own AI) Expert (400)Thu 11 Feb, 15:00–16:00With Saurabh MhaisekarAI agents are no longer simple chatbots responding to prompts. They plan, reason, use tools, hold memory, and make autonomous decisions — often running with overprivileged identities and unchecked access to production systems. This introduces an entirely new class of security threats that traditional AI safety measures don't cover. In this demo-driven session, we'll walk through the agentic threat surface — tool misuse and exploitation, identity and privilege abuse, memory and context poisoning, cascading failures across multi-agent workflows, and rogue agent behavior that drifts silently from intended goals. You'll see how agents get tricked into calling APIs with malicious parameters, how poisoned context persists across sessions, and how one compromised agent corrupts an entire chain. Then we fix it — using Prompt Shields, Task Adherence, scoped identities, and inter-agent trust boundaries to systematically close each attack vector. Your agents are already in production. The question is — who else is using them?
-
The Art of Killing Local Admin
Technical Session 60 min Room 19-Floor 1-Max 106 Intune Expert (400)Thu 11 Feb, 15:00–16:00Local administrator rights remain one of the most common ways attackers gain control of Windows devices. While many organizations want to remove local admin access, doing so without impacting productivity has always been a challenge. In this session, I'll share a practical methodology for eliminating local administrator rights in Microsoft Entra ID–joined environments using Microsoft Intune. We'll start with the foundations, including Entra ID security controls, settings in Windows Autopilot, and Microsoft LAPS, before building a privilege management strategy with Microsoft Endpoint Privilege Management (EPM). Now that EPM is available to more organizations through Microsoft 365 E5, IT teams finally have a license to kill local admin rights at scale. Through demonstrations, real-world lessons learned, and proven implementation approaches, you'll learn how to reduce attack surface, support end users, and successfully move toward a modern least-privilege model.
-
Unlocking the Power of Microsoft Sentinel with MCP Server and Sentinel Graph
Technical Session 60 min Room 20-Floor 1-Max 118 Security Expert (400)Thu 11 Feb, 15:00–16:00With Rod TrentExplore the next evolution of Microsoft Sentinel through the MCP Server (Desktop MCP Server) and Sentinel Graph capabilities. Learn how to extend Sentinel beyond traditional SIEM boundaries with custom connectors, unified data querying via Graph, and seamless integration with AI agents for automated triage and enrichment. This session covers architecture, deployment best practices, real-time analytics, and building resilient detection pipelines. Perfect for Sentinel administrators looking to modernize their environment and leverage graph-based relationships for deeper threat intelligence.
-
Extending Tier 0 into Microsoft Entra ID
Technical Session 60 min Room 4-Floor 1-Max 49 Security Expert (400)Thu 11 Feb, 15:00–16:00With Kasper NorregaardClassic AD tiering is still relevant, but Tier 0 no longer stops at the domain controllers. In a hybrid Microsoft environment, privileged access also lives in Microsoft Entra ID, Microsoft 365, Conditional Access, PIM, and cloud-based admin roles. In this session, we will look at how to extend the traditional Tier 0/1/2 model into the cloud using Entra ID Administrative Units, PIM, strong authentication, and Privileged Access Workstations. The goal is a practical admin model that reduces attack paths, limits lateral movement, and makes delegated administration safer across both on-prem AD and Microsoft 365.
-
Sheep herding with Agent 365
Technical Session 60 min Room 5-Floor 1-Max 89 Data Compliance & Security Advanced (300)Thu 11 Feb, 15:00–16:00You've fully accepted our agentic overlords. You've built the agents. You've taught your colleagues to build agents. You even have third party agents. Now you have 7753 agents and there's only 1000 people in your company! What do you do now? Can you handle 67 agents called Policy Agent? Can you trust people to connect to the sources they should be using? What happens if someone shares their Agent Builder Agent with all 1000 people? Do you just panic and leave? Or do you let Agent 365 become your sheepdog? Microsoft's answer to this is Agent 365, the "single solution" to manage your agents. Through Microsoft 365, Power Platform, Purview and more, Microsoft has brought together many different stories into a more aligned story that can help you bring control and understanding to your tenant. Pipe and shepherd's crook optional. This session will outline more of the horror stories that you could face when not keeping your agents in a sheep pen, show you what Agent 365 is and what you need to do about it. You will learn: How to get observability across all your agents, regardless of platform Control what agents have access to Control who has access to agents Analyse what agents are doing Identify how to manage costs and ensure value Enable makers to use the right tools and build safely We will look at how Agent 365 can help you from agents from SharePoint, Agent Builder, Copilot Studio, Microsoft Foundry and even beyond. Get ready to hear agent an awful lot.
-
What's new in Active Directory 2025 & How to smoothly upgrade?
Technical Session 60 min Room 5-Floor 1-Max 89 Identity Expert (400)Thu 11 Feb, 15:00–16:00With Erwin DerksenFinally Microsoft has put some effort in adding new features to Active Directory. In this session i show you all the relevant new features and how you can use them in your organizaion. Maybe they discovered that AD does not dissapear as soon as they would hope... A new functional level sinds 2016, how nice!
-
Welcome, CEO! Build Your AI Company
Technical Session 60 min Room 6-7-Floor 1-Max 99 AI for Makers (Copilot & Agents) Advanced (300)Thu 11 Feb, 15:00–16:00Congratulations. You are now the CEO of an AI company. The budget is approved, the pressure is high, and every department suddenly wants an agent. HR wants one. Sales wants three. Marketing has already promised something to the board. And IT would really like everyone to stop for five minutes. So, what do you do? In this interactive session, the audience takes over the company. You decide where Copilot belongs, which processes really need an agent, where simple automation would do the job, and where replacing human judgement would be a spectacularly bad idea. Two speakers will guide you through the chaos, challenge your decisions and, very likely, disagree with each other along the way. Because there is no perfect AI company and there is definitely no single correct answer. The provocation is intentional: companies are rushing to build agents before they have even decided which problems are worth solving. You will leave with a clearer way to question AI ideas, compare possible solutions and make better decisions around value, risk, adoption and the human role. Your company may survive. Your AI strategy might not.
-
Ten(-ish) learnings from ten years of Windows Autopilot
Technical Session 60 min Room A3-Floor 0-Max 250 Intune Advanced (300)Thu 11 Feb, 15:00–16:00With Michael NiehausWindows Autopilot was first announced in 2017, so it's now 10 years old. We've all learned a lot about it in the time since the it was originally introduced. In this session, we'll look at some of those "learnings" (as Microsoft is found of this plural noun), best practices that have been developed as a result, and the still-present challenges that we all face when using it. And yes, there's even new stuff to talk about for the first time in over two years...
-
APIOps CLI - The new way of working with API Management
Technical Session 60 min Room TreeHouse South-Floor 1-Max 90 Azure Black Belt (500)Thu 11 Feb, 15:00–16:00With Erlend RushfeldtIn the late summer of 2026, Microsoft announced version 1.0.0 of the new APIOps CLI. A CLI tool for Azure API Management configuration-as-code. In this session we will deepdive into how this tool is used to handle development and deployment of APIs, Products, Policies, MCP servers, and Named Values. This isn't just a tool for platform teams, but also for developers. We will spend most of the session inside of Visual Studio Code and GitHub, looking at real scenarios like how to handle multiple teams developing without conflicts, linting API definitions against custom quality policies, and multi-environment deployment-flows. This session will help you reduce time from development to published API version, while increasing the quality and documentation of your organizations APIs.
-
Personas, Not People: Designing an Authoritative Identity Store for Joiner-Mover-Leaver at Scale
Technical Session 60 min Room TreeHouse South-Floor 1-Max 90 Identity Expert (400)Thu 11 Feb, 15:00–16:00Every organization has more than one source of truth about people — HR for employees, a supplier portal for consultants, a student system, a service desk for shared and privileged accounts. Most identity projects fail not at authentication, but at the boring middle: deciding who is authoritative for which attribute, and what happens on day 1, day 300 and day 0. In this session we build an identity store end to end. We define personas, map multi-source authority and precedence, drive attributes through a managed transformation layer, and let lifecycle events push provisioning and access — with governance attached from the start. We will do this using built-in support in Microsoft Entra for SCIM 2.0 and Inbound Provisioning API, own integration logic and store definitions, and best practice workflows from working with this right now at customers. We show what works and what breaks: conflicting sources, re-hires, persona transitions, orphaned accounts, and the deprovisioning that silently never happened. Expect lots of demos, real failure cases, and 5–10 minutes of questions throughout.
-
We spent 30 Years Learning Infrastructure. AI Learned It Over Lunch.
Panel Discussion 60 min Room TreeHouse South-Floor 1-Max 90 Azure Advanced (300)Fri 12 Feb, 10:00–11:00With Anders Ravnholt, Klaus Gjelstrup NielsenFor decades, infrastructure professionals built careers on expertise. We learned operating systems, networking, virtualisation, cloud platforms and automation. Experience was measured in years. Then AI arrived. Today, an AI can generate scripts, explain architectures and answer technical questions in seconds. The skills we spent decades acquiring are becoming instantly accessible. So where does that leave us? Two Microsoft infrastructure architects with 60 years of combined experience explore the uncomfortable question many IT professionals are asking themselves but few talk about openly: How do I stay relevant? This is not a session about AI features or Copilots. It's a session about people. We'll discuss how our roles are changing, why experience still matters, which skills are becoming more valuable, and how technical professionals can continue to thrive when knowledge is no longer the scarce resource it once was. Because perhaps the future isn't about competing with AI. It's about becoming better at using AI and the things only humans can do. For most of our careers, people paid us for what we knew. Increasingly, they'll pay us for how we think.
-
Agent Sprawl Is Coming: A Governance Model for Copilot Studio and Microsoft 365 Copilot
Technical Session 60 min Room 17-Floor 1-Max 49 AI for Makers (Copilot & Agents) Advanced (300)Fri 12 Feb, 11:30–12:30Copilot Studio and Microsoft 365 Copilot have made it possible for any maker to publish an agent that reads company data, calls tools, and acts under someone's identity. That same ease is what makes agents dangerous to leave ungoverned: unlike a Power App, an agent decides what to do next. This session lays out a governance model built for that reality. It covers environment strategy and Managed Environments, DLP and connector policy for agent-specific risk, a zoned approach that separates citizen, partnered, and professional development, Entra Agent ID and lifecycle ownership from pilot to retirement, and the Center of Excellence structure that keeps all of it running without slowing makers down. Takeaways: - How to structure environments and DLP policy specifically for agent workloads, not just apps and flows - What belongs in a tenant settings decision register before your first agent reaches production - How to run a Center of Excellence operating model that scales oversight without killing maker velocity
-
May the Sync Be with You
Technical Session 60 min Room 17-Floor 1-Max 49 Identity Advanced (300)Fri 12 Feb, 13:30–14:30With Klaus BierschenkThe era of a single synchronization engine is over. Modern identity environments have become a galaxy of synchronization, provisioning, and lifecycle management technologies and keeping them aligned is no small feat. Hybrid identity has evolved far beyond simply synchronizing Active Directory with Microsoft Entra ID. Organizations today combine multiple identity flows and provisioning mechanisms, including: * Entra Connect Sync / Entra Cloud Sync * Lifecycle Workflows * HR-driven provisioning * Application provisioning * Cross-tenant synchronization But how do these technologies fit together? Where does each approach make architectural sense? And how can organizations avoid creating a complex web of disconnected identity processes? Instead of exploring these capabilities in isolation, this session follows the identity journey of a user in a realistic enterprise scenario — from hiring and organizational changes to privileged access, external collaboration, and finally offboarding. Along the way, we will explore how different Microsoft Entra capabilities contribute to a modern identity lifecycle and how they can be combined into a sustainable architecture. Attendees will leave with a practical mental model of the Microsoft Entra synchronization and provisioning landscape, a better understanding of where each technology fits, and guidance for designing identity architectures that connect lifecycle management, provisioning, and cross-tenant collaboration.
-
Tiering in Active Directory - Prevent exposure of sensitive credentials by going back to basics
Technical Session 60 min Room 17-Floor 1-Max 49 Security Advanced (300)Fri 12 Feb, 13:30–14:30With Viktor HedbergIn DFIR, we commonly see that the median hops needed to get access of Domain Admin credentials is three. Meaning that when compromised, a TA moves laterally up to three separate systems before getting DA. In this session, we will talk about how we must get back to basics and protect our sensitive privileges via Tiering and how Authentication Policy Silos provides locking effects on your Domain Administrators.
-
Cut Costs, Not Data: How to Optimize SharePoint Online Storage
Technical Session 60 min Room 17-Floor 1-Max 49 Microsoft 365 Expert (400)Fri 12 Feb, 15:00–16:00The rapid growth of digital content is driving up storage costs in SharePoint Online. In many organizations, document versions, legacy content, and unused data generate avoidable expenses without delivering real business value. In this session, we will explore how to optimize storage using the latest Microsoft 365 capabilities. We will look at how SharePoint Online Intelligent Versioning can automatically reduce unnecessary document versions, how Microsoft Archive enables long-term content retention at a lower cost, and how Microsoft 365 Backup supports an effective and sustainable data protection strategy. We will also examine the role of AI-powered insights and administrative tools in identifying storage waste, uncovering optimization opportunities, and enabling data-driven decision-making. A practical session featuring real-world scenarios, best practices, and actionable recommendations to help organizations reduce storage costs without compromising security, compliance, or productivity.