Security and AI
Details
SAVE THE DATE! - October 12th 2026, 8:00 pm -9:40pm
AGENDA
8:00 pm - Welcome and House Keeping
Speakers - Santhoshkumar Anandakrishnan | Sr.Cloud Architect
IT professional with 17 years of dedicated experience in Cloud & Infrastructure with globally reputed organizations backed up by a bachelor's degree in computer science engineering. I specialize in Infrastructure, mainly focusing on public & hybrid cloud, and working extensively in designing and implementing cloud models that host Business solutions.
Session: Azure Bastion & PIM: Eliminating Standing Privileged Access to Cloud Resources
Shows how Azure Bastion and PIM eliminate standing privileged access by enabling browser-based RDP/SSH without public IPs and JIT, approval-gated admin access with a live demo.
Two of the most persistent findings in cloud security assessments are public management ports (RDP/SSH exposed to the internet) and standing administrative access (accounts that are always "admin," whether they need to be or not). This session tackles both problems together, since they're frequently two sides of the same risk.
We'll start with Azure Bastion: how it provides browser-based, SSL-secured RDP/SSH access to VMs without ever assigning a public IP to the VM itself, and how it fits into a broader network architecture (including cost and scaling considerations for large environments — Bastion SKUs, session limits, and native client support). From there, we shift to identity: Privileged Identity Management (PIM), and how it transforms admin access from an always-on standing privilege into a just-in-time, time-bound, and optionally approval-gated activation.
We'll walk through configuring PIM for both Azure AD roles and Azure resource roles, setting up approval workflows, and configuring access reviews to catch privilege creep over time.
The session closes with a live demo combining both controls — an administrator activating PIM for a limited window and connecting to a VM via Bastion, with no public IP and no standing access involved at any point.
Speaker 2: Konstantinos Lianos | Cloud Security Specialist - Microsoft Regional Leader & Senior Microsoft Student Ambassador
Cybersecurity professional specializing in Research & Development, Multi-Cloud Security, and SecDevOps, currently working across two complementary roles as a Senior SecDevOps Engineer and Cloud Security Specialist.
My expertise spans Microsoft Azure, AWS, Oracle Cloud Infrastructure (OCI), and Google Cloud Platform (GCP), with a strong focus on cloud security architecture, SIEM/XDR, threat detection and response, IAM, security automation, DevSecOps, and cloud-native defense.
With an MBA, MSc in Information Security & Digital Forensics, and BSc in Computer Science, I combine technical depth, security research, and business understanding to design and improve secure, scalable multi-cloud environments and translate complex cybersecurity challenges into effective security solutions.
Session: See Your Attack Surface: Mapping Azure with an MCP Server
Build an MCP server to map Azure resources, identify exposed connections and blast radius, and safely analyze security coverage with Defender for Cloud and Sentinel.
####
Most breaches start with something nobody knew was exposed. If you cannot see your environment clearly, you cannot defend it.
In this session I build an MCP (Model Context Protocol) server that scans an Azure subscription and renders it as an interactive graph, then I turn that graph into a security tool. We look at how resources actually connect, where the exposed edges are, and how to reason about blast radius when one resource is compromised.
I cover the practical safeguards that matter when you point AI at a real tenant. Keeping the scan strictly read-only, handling large subscriptions without noise, and building in leak-detection so sensitive data never lands in a prompt. I also share the precision rule I enforce throughout: every security finding has to come from actual scan data, with gaps marked unknown rather than inferred from a resource name or tag. No guessing your way to a false sense of safety.
I close on where this goes next, using the same map to reason about Defender for Cloud coverage and which logs are actually flowing into Sentinel.
You will leave understanding what MCP is, why it fits security tooling so well, and how to start building an Azure-aware assistant that helps you see what you are actually exposing.
Who it is for: security and cloud engineers who want a clearer, defensible picture of their Azure attack surface.
