Loading…
Session selection is underway. What you currently see now is what has been approved so far. More coming! Actual schedule with days and dates won’t come until early October.
Type: Security clear filter
arrow_back View All Dates
Monday, October 26
 

8:00am PDT

Access Management is Hard - And Attackers Love It
Monday October 26, 2026 8:00am - 8:15am PDT
Description:
Active Directory. Entra ID. B2B guests. Service accounts. Shared mailboxes. Legacy groups nobody owns. Admins with permanent Global Admin. Access reviews nobody reads. Attackers don't break in anymore; they log in and pivot through the cracks between those silos. Walk through how Microsoft identities get compromised today with live demos. Rebuild the model using Privileged Identity Management (PIM) and Entra Access Packages to see what 'good' looks like: Just-In-Time, time-bound, reviewed, and governed. Leave with a clear blueprint to implement it.

What you will learn:
  • Attackers don't break in; they log in through the seams.
  • Standing privilege is the root cause of access issues.
  • Governance is a business process, not an IT ticket.
  • Gain practical steps to implement governance and access reviews effectively.
Speakers
avatar for Jordan Benzing

Jordan Benzing

Director, Security & IT, Patch My PC
Jordan has been working in the Industry since 2009. Since starting he’s worked with Active Directory, Group Policy, ConfigMgr, SCOM and PowerShell. Jordan has also had the opportunity to work in the healthcare industry as a ConfigMgr Infrastructure Team lead supporting over 150,000... Read More →
avatar for Sergey Chubarov

Sergey Chubarov

Ethical Hacker
Sergey Chubarov is a Security and Cloud Expert, Instructor with 15+ years' experience on Microsoft technologies.

His day-to-day job is to help companies securely embrace cloud technologies.

He has certifications and recognitions such as Microsoft MVP: Security, OSCP, OSEP, eCPPT, e... Read More →
Monday October 26, 2026 8:00am - 8:15am PDT
TBD

8:00am PDT

Achieve Zero Trust Objectives with Defender for Cloud and Defender EASM Integrated with Defender XDR
Monday October 26, 2026 8:00am - 8:15am PDT
Description:
Every shop needs insight into misconfiguration issues and compliance risks in the cloud—an extension of Zero Trust policies. Learn how Defender for Cloud continuously monitors Azure, AWS, and GCP cloud infrastructure for gaps in security policy enforcement. Use agentless vulnerability scanning, secrets scanning, and Security Copilot plug-ins. Understand how Defender EASM discovers and maps your digital attack surface for an external view of your online infrastructure.

What you will learn:
  • Achieve effective prioritization of cross-platform security recommendations in the Defender XDR portal.
  • Connect GitHub repositories for code supply scanning, surface findings, remediate them, and increase security score.
  • Seed Defender EASM with known legitimate assets to infer relationships and uncover unmonitored artifacts.
  • Leverage Microsoft Security Store agentic solutions with your M365 E5 SCU entitlement.
Speakers
avatar for Morten Knudsen

Morten Knudsen

Triple Microsoft MVP (Security, Azure, Security Copilot) | MCT | Security & Cloud Architect | Co-Founder Experts Live De, 2LINKIT
Morten is a Triple Microsoft MVP (Security, Azure, and Security Copilot), a Microsoft Certified Trainer, and holds over 17 active Microsoft certifications.

As a Cloud and Security Architect, he focuses on Azure infrastructure, Microsoft 365, automation, security, AI, and hybrid cl... Read More →
avatar for John Joyner

John Joyner

Senior Director, Technology, Corsica Technologies

Monday October 26, 2026 8:00am - 8:15am PDT
TBD

8:00am PDT

AI-Ready Data: Field-Tested Best Practices for Preparing Your Organization with Purview
Monday October 26, 2026 8:00am - 8:15am PDT
Description:
You don't have an AI problem. You have a data problem that AI is about to expose. Years of oversharing, forgotten file shares, weak permissions, and sensitive content become impossible to ignore once Copilot can find everything in seconds. Use Microsoft Purview and Microsoft Defender to uncover risk, reduce data exposure, and secure your AI journey. Based on real-world deployments, get practical guidance for finding oversharing, deploying labels and DLP, and building governance that keeps pace with today’s—and tomorrow’s—AI tools.

What you will learn:
  • Find out what Copilot will expose before your users do.
  • Identify your biggest AI data exposure risks in under 30 days using DSPM and SharePoint Advanced Management.
  • Know exactly what to fix first with a prioritization framework that targets the 20% of issues eliminating 80% of AI-related data security risk.
  • Deploy labels and DLP without creating a helpdesk nightmare by learning common mistakes and ensuring user adoption.
Speakers
avatar for Kent Agerlund

Kent Agerlund

Global Technology Director | Microsoft MVP & Regional Director | twoday, MMS Staff
A Microsoft Regional Director and multi-award Microsoft MVP — now recognized in Identity & Access and Microsoft Purview, on top of 15 years as a Microsoft Security MVP — Kent Agerlund bridges boardroom strategy and hands-on execution across security, identity, and modern management... Read More →
Monday October 26, 2026 8:00am - 8:15am PDT
TBD

8:00am PDT

Conditional Access Masterclass
Monday October 26, 2026 8:00am - 8:15am PDT
Description:
Learn everything about Conditional Access, from the basics and limitations to complex policy design and various integrations with other controls. Gain a full understanding of its capabilities and how to implement policies effectively without disrupting operations.

What you will learn:
  • Understand all of the capabilities of Conditional Access.
  • Learn how to implement policies with minimal operational impact.
  • Discover lesser-known controls to round out policies and cover gaps.
  • Explore integration strategies with other security and compliance controls.
Speakers
avatar for Jan Ketil Skanke

Jan Ketil Skanke

MVP Security, Principal Cloud Architect, COO, CloudWay


avatar for Nathan McNulty

Nathan McNulty

Microsoft MVP, Sr. Security Solutions Architect, Patriot Consulting
I am currently a Senior Security Solutions Architect for Patriot Consulting primarily helping our clients securely implement Azure, Entra, Defender, and Intune. I started my career on helpdesk for a civil engineering firm and quickly became the Enterprise Desktop Administrator. After... Read More →
Monday October 26, 2026 8:00am - 8:15am PDT
TBD
  Security, Security
  • format csv

8:00am PDT

Defender for Endpoint Internals
Monday October 26, 2026 8:00am - 8:15am PDT
Description:
Sure, Defender for Endpoint has a lot of cool features, but how exactly does it all work? Look at how Defender AV and MDE operate under the hood, from scanning engines to cloud services, to understand how to optimize both security and performance on devices.

What you will learn:
  • Understand the capabilities of Defender AV and EDR.
  • Learn techniques to improve performance without sacrificing security.
  • Discover how to extend MDE with automation.
  • Identify best practices for ensuring robust protection while maintaining system efficiency.
Speakers
avatar for Nathan McNulty

Nathan McNulty

Microsoft MVP, Sr. Security Solutions Architect, Patriot Consulting
I am currently a Senior Security Solutions Architect for Patriot Consulting primarily helping our clients securely implement Azure, Entra, Defender, and Intune. I started my career on helpdesk for a civil engineering firm and quickly became the Enterprise Desktop Administrator. After... Read More →
Monday October 26, 2026 8:00am - 8:15am PDT
TBD

8:00am PDT

Empowering SOC Teams: How Claude, Copilot, ChatGPT, MCP Servers, and Agents Drive Efficiency
Monday October 26, 2026 8:00am - 8:15am PDT
Description:
Security Operations Centers (SOCs) are overwhelmed by alerts. Junior analysts spend most of their time on manual triage, log correlation, enrichment, and investigations. Learn how GenAI tools (Claude, Copilot, ChatGPT, etc.), MCP Servers, and AI Agents transform SOCs by autonomously handling triage, enrichment, and disposition—reducing alert fatigue and mean time to triage. Turn junior analysts into power users focused on threat hunting and proactive defense.

What you will learn:
  • Connect GenAI tools (Claude, Copilot, ChatGPT, etc.) to MCP Servers and build production-ready SOC agents.
  • Automate repetitive triage, enrichment, and investigation workflows with practical steps.
  • Implement best practices for secure, human-in-the-loop agent deployments that maintain control and compliance.
  • Develop strategies for measuring ROI and scaling agentic SOC capabilities across any environment.
Speakers
avatar for Rod Trent

Rod Trent

Senior Product Manager, Microsoft
Rod Trent is a Senior Product Manager and Security MVP Lead for Microsoft where he focuses on the intersection between Security and AI. In his spare time, Rod writes KQL queries, authors fiction and non-fiction books, tells proud stories about his grandkids, brags about his Six Million... Read More →
Monday October 26, 2026 8:00am - 8:15am PDT
TBD

8:00am PDT

Every Device Is a Security Boundary: Secure It by Design
Monday October 26, 2026 8:00am - 8:15am PDT
Description:
This hands-on, demo-driven session shows how to own your identity control plane with Microsoft Entra ID, focused on devices. Break down real-world security profiles (ENT, SAW, PAW) and understand why strong authentication matters across device types. Secure PAW/SAW across Windows 365 Cloud PCs, VMs, and physical devices with phishing-resistant FIDO2 and Windows Hello. Redesign Intune with tags and filters, then hunt to remediate non-compliant devices at scale. Automate everything—including conditional access. Leave with ready-to-use scripts.

What you will learn:
  • Learn how devices define trust and security boundaries.
  • Enforce phishing-resistant authentication across all device types.
  • Simplify Intune using device tags and filters.
  • Automate conditional access for consistent identity control.
Speakers
avatar for Morten Knudsen

Morten Knudsen

Triple Microsoft MVP (Security, Azure, Security Copilot) | MCT | Security & Cloud Architect | Co-Founder Experts Live De, 2LINKIT
Morten is a Triple Microsoft MVP (Security, Azure, and Security Copilot), a Microsoft Certified Trainer, and holds over 17 active Microsoft certifications.

As a Cloud and Security Architect, he focuses on Azure infrastructure, Microsoft 365, automation, security, AI, and hybrid cl... Read More →
avatar for Simon Skotheimsvik

Simon Skotheimsvik

Microsoft MVP | Senior Cloud Consultant at CloudWay, CloudWay
Simon is a Microsoft MVP and Senior Cloud Consultant at CloudWay, recognized globally as a leading voice in modern endpoint management, Microsoft Intune, and security in Entra ID.

As an international speaker, Simon is recognized for delivering engaging sessions that combine in-depth technical expertise with practical guidance, inspiring IT professionals to rethink how they manage and secure endpoints in today’s cloud-first world. His expertise and thought... Read More →
Monday October 26, 2026 8:00am - 8:15am PDT
TBD
  Security, Security
  • format csv

8:00am PDT

From Activity Logs to Defensible Least-Privilege Roles
Monday October 26, 2026 8:00am - 8:15am PDT
Description:
Entra and Azure admins inherit broad roles, audit pressure, and little proof of what access people actually need. This 400-level session uses Azure RBAC and Entra activity logs as evidence of what admins, apps, and service principals actually did. A custom PowerShell role-mining tool normalizes and clusters those actions into proposed least-privilege custom roles and a review packet showing current access, used actions, rare actions, and how to structure a pilot.

What you will learn:
  • Build a role-mining pipeline from Azure RBAC and Entra activity logs.
  • Use actual admin, app, and service-principal activity to derive data-driven custom roles and show which permissions can be safely removed.
  • Test proposed custom roles before rollout: confirm normal work still succeeds, risky actions stay blocked, and admins have a temporary fallback through Entra PIM.
  • Understand how role mining can also be used as part of access reviews and attestation processes.
Speakers
Monday October 26, 2026 8:00am - 8:15am PDT
TBD

8:00am PDT

Modern Windows Security Bypassed
Monday October 26, 2026 8:00am - 8:15am PDT
Description:
Attackers try to slip past today's Windows defenses, including EDR tools, Attack Surface Reduction rules, Sysmon logging, and Credential Guard. Learn how they identify gaps in monitoring and exploit features organizations forget to disable. A practical guide for defenders to see where Windows security can break down today and how to stay ahead of those gaps.

What you will learn:
  • Modern Windows defenses like EDR, ASR, etc. are not foolproof.
  • Attackers rely heavily on stealth techniques.
  • Defenders must actively close security gaps.
  • Understand the methods for evading Credential Guard and bypassing ASR rules.
Speakers
avatar for Sergey Chubarov

Sergey Chubarov

Ethical Hacker
Sergey Chubarov is a Security and Cloud Expert, Instructor with 15+ years' experience on Microsoft technologies.

His day-to-day job is to help companies securely embrace cloud technologies.

He has certifications and recognitions such as Microsoft MVP: Security, OSCP, OSEP, eCPPT, e... Read More →
avatar for Morten Knudsen

Morten Knudsen

Triple Microsoft MVP (Security, Azure, Security Copilot) | MCT | Security & Cloud Architect | Co-Founder Experts Live De, 2LINKIT
Morten is a Triple Microsoft MVP (Security, Azure, and Security Copilot), a Microsoft Certified Trainer, and holds over 17 active Microsoft certifications.

As a Cloud and Security Architect, he focuses on Azure infrastructure, Microsoft 365, automation, security, AI, and hybrid cl... Read More →
Monday October 26, 2026 8:00am - 8:15am PDT
TBD

8:00am PDT

Using AI for Modern Threat Detection
Monday October 26, 2026 8:00am - 8:15am PDT
Description:
Traditional threat hunting relies on queries, dashboards, and time-consuming log review. AI changes the game. Explore how security teams can use AI to surface anomalies, accelerate investigations, and uncover patterns SIEM rules may miss. Cover practical workflows, validation techniques, and guardrails to reduce false positives and avoid blind trust. Learn where AI enhances hunting — and where human judgment remains critical.

What you will learn:
  • Latest tools and information in AI security.
  • Prompt patterns that produce reliable investigative outputs.
  • Guardrails to prevent data leakage and prompt injection risks.
  • Understanding the balance between AI enhancements and human judgment in threat detection.
Speakers
avatar for Chris Sires

Chris Sires

Engineer
With more than 30 years of software development experience, including 25 years at Microsoft, Chris Sires brings deep engineering perspective to the world of AI. After leaving Microsoft, he went all-in on applied AI, built a successful SaaS business from the ground up with AI tools... Read More →
avatar for Rod Trent

Rod Trent

Senior Product Manager, Microsoft
Rod Trent is a Senior Product Manager and Security MVP Lead for Microsoft where he focuses on the intersection between Security and AI. In his spare time, Rod writes KQL queries, authors fiction and non-fiction books, tells proud stories about his grandkids, brags about his Six Million... Read More →
Monday October 26, 2026 8:00am - 8:15am PDT
TBD

8:00am PDT

Zero Trust Fundamentals: Turning Microsoft Security into Action
Monday October 26, 2026 8:00am - 8:15am PDT
Description:
Zero Trust is a strategy—not a product—built on 'never trust, always verify.' Learn to operationalize Microsoft’s Zero Trust framework across identities, devices, apps, data, and network segmentation using Entra ID, Intune, Defender, Azure, and M365. Assess your current state, define a target architecture, and build a prioritized roadmap with real-world, risk-based controls.

What you will learn:
  • Map Zero Trust principles to Microsoft pillars and technologies.
  • Perform an As-Is assessment and define a realistic To-Be state.
  • Prioritize initiatives into a practical, phased roadmap.
  • Implement risk-based access using Conditional Access and device compliance.
Speakers
avatar for Andreas Sobczyk

Andreas Sobczyk

Global Principal Architect, Twoday
Andreas is a Global Principal Architect at Twoday, focusing Azure adoption, platform engineering and DevOps helping global customers accelerating there cloud journey and maximize the potential of the platform. Also being co-founder of Cloud and Datacenter User Group Denmark, Andreas... Read More →
avatar for Kent Agerlund

Kent Agerlund

Global Technology Director | Microsoft MVP & Regional Director | twoday, MMS Staff
A Microsoft Regional Director and multi-award Microsoft MVP — now recognized in Identity & Access and Microsoft Purview, on top of 15 years as a Microsoft Security MVP — Kent Agerlund bridges boardroom strategy and hands-on execution across security, identity, and modern management... Read More →
Monday October 26, 2026 8:00am - 8:15am PDT
TBD
  Security, Security
  • format csv

8:00am PDT

Zero Trust Meets AI: Securing Copilot and Every Other AI Your Users Found First
Monday October 26, 2026 8:00am - 8:15am PDT
Description:
AI is the next step in your Zero Trust journey. You've secured identities and devices, but what happens when users feed data into Copilot and other AI tools? Learn how Microsoft Defender and Purview help discover and control shadow AI, prevent sensitive data leaks with DLP, sensitivity labels, and endpoint DLP, and gain visibility with Data Security Posture Management (DSPM) for AI. Enable AI innovation without losing control of your data.

What you will learn:
  • Leave with a concrete plan for protecting your data in every AI interaction, whether you sanctioned the tool or not.
  • Gain a solid understanding of how Defender and Microsoft Purview can assist your organization.
  • Receive ready-to-use policy examples deployable the week after MMS.
  • Understand how to leverage DLP and sensitivity labels to enhance your Zero Trust security posture.
Speakers
avatar for Kent Agerlund

Kent Agerlund

Global Technology Director | Microsoft MVP & Regional Director | twoday, MMS Staff
A Microsoft Regional Director and multi-award Microsoft MVP — now recognized in Identity & Access and Microsoft Purview, on top of 15 years as a Microsoft Security MVP — Kent Agerlund bridges boardroom strategy and hands-on execution across security, identity, and modern management... Read More →
Monday October 26, 2026 8:00am - 8:15am PDT
TBD
 
MMS 2026 Midway Edition
From $100.00
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -