Hardening GitHub: From Default to Defended
Wednesday 10 February 2027, 10:00–11:00
Speakers
- Pierre Thoor
About this session
GitHub ships with sensible defaults. The problem is that sensible defaults aren't security controls - and the gap between them is where real attacks land. In this demo-heavy session, we go hands-on with the security decisions that most organizations either skip, misconfigure, or misunderstand. Through live demonstrations, we'll trace how attackers exploit workflow triggers, overly permissive tokens, unpinned Actions, and bypassed secret protection - then close each gap in real time. We'll also connect GitHub security to the broader Microsoft security stack - how Defender for Cloud surfaces DevOps posture findings, how Entra workload identity federation replaces long-lived secrets in pipelines, and how to get GitHub audit signals into your existing detection and response workflows. This isn't a product overview. Every demo is rooted in attack patterns being used right now, with fixes you can apply the same week.