Secure Azure application platform services for security engineer - Part 1
Details
Containers and Kubernetes provide organizations with speed, portability, and scalability, but they also introduce new attack surfaces across container images, registries, cluster configuration, identities, networking, secrets, and runtime workloads.
In this session, participants will learn how to detect container security risks and implement layered security controls across Azure Kubernetes environments.
About the Session
Securing Kubernetes requires more than protecting the underlying virtual machines.
Cloud Security Engineers must consider the entire container lifecycle, including:
- Container images
- Azure Container Registry
- Cluster configuration
- Kubernetes API access
- Identities and permissions
- Network connectivity
- Secrets
- Pods and workloads
- Runtime behavior
- Vulnerability management
- Threat detection
This session will explore how Microsoft security technologies can help organizations build a stronger security posture for containerized applications running on Azure.
What You Will Learn
By the end of the session, participants should understand how to:
- Explain the security risks associated with containerized workloads
- Enable Microsoft Defender for Containers
- Assess vulnerabilities in container images
- Review security recommendations affecting AKS
- Detect suspicious container runtime activity
- Secure access to the Kubernetes API
- Integrate Microsoft Entra ID with AKS
- Apply Kubernetes RBAC
- Use private cluster access to reduce external exposure
- Configure network security controls
- Use workload identity instead of embedded application credentials
- Strengthen secrets management
- Apply pod security standards
- Reduce the attack surface of containerized workloads
- Build a defense-in-depth security model for AKS
Who Should Attend?
This session is ideal for:
- Participants in the Cloud and AI Security Bootcamp
- Cloud Security Engineers
- Azure Security Engineers
- Kubernetes Administrators
- AKS Engineers
- DevOps Engineers
- DevSecOps Engineers
- Platform Engineers
- Security Architects
- Cloud Architects
- SOC Analysts
- Application Security Engineers
- Professionals preparing for the SC-500 certification
- Anyone interested in container and Kubernetes security
Why You Should Attend
Containers and Kubernetes have become foundational technologies for modern cloud applications, microservices, and increasingly AI-enabled workloads.
But with that flexibility comes additional security responsibility.
Security professionals need to understand:
- Whether deployed container images contain exploitable vulnerabilities
- Who can access the cluster
- Whether Kubernetes workloads are excessively privileged
- How workloads authenticate to Azure services
- Whether the cluster is unnecessarily exposed to public networks
- How suspicious runtime behavior can be detected
- How security recommendations can be prioritized and remediated
This session will help participants understand how Microsoft Defender for Containers, Microsoft Entra ID, Kubernetes RBAC, AKS network controls, workload identity, and pod security standards work together to create a stronger container-security architecture.
Come ready to learn, ask questions, and strengthen your practical understanding of securing Azure Kubernetes workloads.
Learn. Build. Protect. Secure the Cloud.
