Skip to content
Security NinjasGermany · 2026

Agenda

20 October 2026 · Munich · All times CEST

  • 08:00 – 09:00
    DoorsRegistration & Welcome Coffee
  • 09:00 – 09:45
    KeynoteThe Evolution of Cyber Defense: From Human-Led Security to Agentic AI
    Eugene PiricEugene PiricSales Director for Microsoft Cloud and Enterprise Advanced Solutions and Workloads, Microsoft
  • 10:00 – 10:40

    Hive · 10:00 – 10:40

    Master your Hybrid IGA Story: Permissions Without Borders

    Tim Wolf

    Speaker

    Tim Wolf

    Stop managing identities in isolation. In a landscape of hybrid clouds and multi-tenant architectures, your security posture is only as strong as your most disconnected directory.

    This 45-minute, high-velocity session is packed with live demos designed to unify your Identity Governance and Administration (IGA) strategy. We will bridge the gap between legacy on-premises Active Directory and complex, multi-tenant Entra ID environments using the full Microsoft security stack.

    Washington · 10:00 – 10:40

    The Modern SecOps Playbook: Microsoft Sentinel Data Lake, Graphs, and Agentic Tools

    Sami Lamppu

    Speaker

    Sami Lamppu

    Microsoft security solution innovations, including Sentinel Data Lake, Sentinel Graph, and agentic tools, enable security teams to examine telemetry and entity relationships as native graph structures instead of reconstructed query results.

    This demo-focused session shows how the Sentinel Data Lake and graphs, combined with the Sentinel MCP server and other AI-assisted capabilities, support scalable, context-aware investigations. Across several scenarios, we'll trace attack paths for human and non-human identities, map blast radius, and assess exposure using graph-powered investigation and agentic workflows.

    The session focuses on hands-on research and evaluation of these modern SecOps tools, turning them into practical workflows that security teams can use to investigate faster and hunt deeper at data lake.

  • 10:40 – 10:55
    BreakCoffee & Cake
  • 10:55 – 11:35

    Hive · 10:55 – 11:35

    Beyond Secrets – Securing Workload Identities in Entra ID

    Daniel Fraubaum

    Speaker

    Daniel Fraubaum

    App registrations and service principals are everywhere in your tenant – but how well are they actually secured? In most environments, the answer is: not well enough.

    This session takes you on a journey through the identity lifecycle of non-human identities in Entra ID. We'll start with the fundamentals – how app registrations, service principals, and managed identities relate to each other and where the security boundaries lie. From there, we'll dive into a commonly overlooked attack vector: client secrets on service principals that can be added via Graph API but are completely invisible in the Entra admin center.

    You'll learn how to use App Management Policies to block secret creation at the tenant level and per-application, why federated credentials and managed identities should be your default, and how Conditional Access for Workload Identities adds a critical policy layer to control how and from where your non-human identities authenticate.

    Expect real-world scenarios, live demos, and actionable takeaways you can implement in your tenant the same week.

    Washington · 10:55 – 11:35

    Incident investigations and threat hunting with Microsoft Sentinel Graph

    Uros Babic

    Speaker

    Uros Babic

    This session focuses on real-world incident investigation and proactive threat hunting using Microsoft Sentinel, with a deep dive into the Identity Sentinel Graph and incident investigation Sentinel Graph and entity relationships. We will walk through how security teams can pivot from alerts to incidents, understand attacker behavior through graph-based investigations, and move seamlessly between investigation and hunting scenarios.

    Through live demos, you will see how Sentinel correlates signals across users, devices, identities, and resources, enabling faster root-cause analysis and more effective threat hunting. We will cover practical investigation workflows, advanced hunting techniques, and how to leverage graph context to uncover hidden attack paths and related activity.

    Attendees will leave with actionable guidance on how to operationalize Sentinel for day-to-day SOC investigations and improve detection confidence and response speed using graph-driven insights.

  • 11:45 – 12:25

    Hive · 11:45 – 12:25

    If I Had to Secure Azure from Scratch Today

    Gregor Reimling

    Speaker

    Gregor Reimling

    Azure provides an overwhelming number of security features, recommendations, and best practices. But if you had to make your Azure environment significantly more secure, where would you start?

    In this session, I will share the ten security controls I would prioritize first. Whether you are building a new Azure or improving a tenant, the challenge remains the same: identifying the measures that deliver the greatest reduction in risk with the highest impact.

    We will explore key areas such as identity protection, privileged access management, governance, segmentation, Defender for Cloud, workload protection, and operational readiness.

    You will leave the session with a practical roadmap that can be applied to both new and existing Azure environments.

    Washington · 11:45 – 12:25

    You've got Detection Rules but will they spot a real attacker?

    Jay Kerai

    Speaker

    Jay Kerai

    Effie Antoniadi

    Speaker

    Effie Antoniadi

    The blue team write queries to spot attacks happening but how do you know if these detections really work against a real threat actor's TTPs (tactics techniques and procedures)? In this session we will show you how you can evaluate your queries/security technology with open source attack simulation tooling.

  • 12:25 – 13:05
    BreakLunch

    Lunch sessions in both rooms during the break.

    Hive · 12:25 – 13:05

    Lunch session

    Beyond No Return: Preparing Your Organization for Cyber War

    Miska Kytö

    Speaker

    Miska Kytö

    Amidst global uncertainty, the distinction between cybercrime and state-sponsored cyber warfare is getting blurry. What will happen if your organization gets caught in the crossfire - or the crosshairs?

    Drawing on principles from conventional warfare and national-level cyber defense, this session breaks down how to survive when the stakes are the highest.

    Key takeaways

    • Learn to apply the CARVER model to your organizational assets to see through the eyes of the attacker, so you can prioritize resources where they matter the most.
    • Using honeytokens, tarpits and other digital landmines to turn your environment into a high-cost nightmare for attackers.
    • How to maintain operational security in a modern world where everything is out in the open for everyone to see.

    Washington · 12:25 – 13:05

    Lunch session

    Security AMA

    Fabian Bader

    Speaker

    Fabian Bader

    Christopher Brumm

    Speaker

    Christopher Brumm

    Bring your lunch and your questions. Fabian Bader and Christopher Brumm answer your Microsoft security questions live in an open Ask Me Anything session.

  • 13:05 – 13:45
    HiveSponsor Session
    WashingtonSponsor Session
  • 13:55 – 14:35

    Hive · 13:55 – 14:35

    Zero Trust in modern (hybrid) AI companies

    Tim Baumann

    Speaker

    Tim Baumann

    Identity is the foundation for everything organizations do across cloud and hybrid environments, and it should always be the starting point for any security, governance, or transformation strategy. Modern organizations operate across a rapidly growing mix of employees, guests, partners, technical accounts, workloads, and AI agents, each with different behaviors, risks, lifecycles, and access needs. This session explores how to govern these diverse identity types at scale using Zero Trust principles such as least privilege, continuous verification, consistent access controls, and lifecycle governance across both human and non-human identities.

    Washington · 13:55 – 14:35

    Normalize Once, Detect Everywhere: Inside Microsoft Sentinel's ASIM

    Jannis Langthaler

    Speaker

    Jannis Langthaler

    Marvin Rose

    Speaker

    Marvin Rose

    Normalization is the secret SIEM weapon hiding in plain sight and almost nobody is using it. This session pulls back the curtain on ASIM in Microsoft Sentinel: what normalization actually means, how it works under the hood, and why it changes the game for detection engineering. Expect concepts, technical mechanics, and the real-world implications - with some practical examples and notes from the field.

  • 14:45 – 15:25

    Hive · 14:45 – 15:25

    From Tenant Sprawl to Tenant Control: AI and Modern Governance in Microsoft Entra

    Klaus Bierschenk

    Speaker

    Klaus Bierschenk

    Every mature Microsoft Entra tenant evolves over time and with that evolution comes complexity: orphaned guests, expiring secrets and certificates, ownerless applications and groups, unused enterprise applications, stale devices, inactive PIM assignments, and many more forgotten objects.

    These abandoned resources increase security risks, but identifying and remediating them consistently is challenging in large and constantly changing environments.

    Microsoft Entra already provides powerful governance capabilities, including recommendations, usage insights, lifecycle management features, and privileged access controls. But a new capability is changing how administrators approach these tasks: Artificial Intelligence.

    Technologies such as Security Copilot, the MCP Server for Enterprise, and agents like the CA Optimization Agent can accelerate analysis and support decision-making. But where can AI truly help, and where must human validation remain essential?

    In this session, we will explore practical approaches for improving Microsoft Entra governance, reducing tenant risks, and combining built-in capabilities with AI assistance. You will learn where automation and AI add value, where caution is required, and how to build a secure governance model for your Entra environment.

    Washington · 14:45 – 15:25

    One Toolbox, No Coffee Breaks: Attacking and Defending with AI

    Gianni Castaldi

    Speaker

    Gianni Castaldi

    Tom Rolvers

    Speaker

    Tom Rolvers

    AI does not make security tools faster. An Nmap scan still takes time. A KQL query still has to run. What AI removes is the human pause between them.

    Tom takes red. He runs a local model with the guardrails ablated. No cloud, no logs, no billing and no abuse team to notice. It never refuses, never tires and never runs out of ideas. It fails constantly. It only has to work once.

    Gianni takes blue. He connects an agent to Defender XDR and Sentinel over MCP and puts it to work on the questions an analyst asks first.

    Same primitives on both sides. A failed attack costs the attacker nothing. A wrong investigation disables the wrong account.

    You will see what we built, what broke and what we will not run unattended. By October the tooling will have moved again. The trade-off will not.

    How much autonomy do you hand an agent when attacking is trivial to automate and a defensive mistake is an incident of its own?

  • 15:35 – 16:15
    HiveSponsor Session
    WashingtonSponsor Session
  • 16:15 – 16:30
    BreakCoffee & Cake
  • 16:30 – 17:10

    Hive · 16:30 – 17:10

    Shift-Left Is Great – Until Your App Owners Haven't Heard of It

    Pit Singert

    Speaker

    Pit Singert

    Central Code-to-Runtime Container Security with Microsoft Defender for Cloud:

    Containers carry modern cloud-native apps and increasingly the AI built on them, from assistants to autonomous agents. They also erase the line between build, deploy, and runtime: a morning commit can hit production by noon and be exploited by lunch. At that speed, with attackers using AI to find and exploit gaps faster than teams patch, point-in-time scanning protects nothing. Security has to run as a continuous loop.

    In a perfect world, every app owner runs that loop themselves. In the real world, adoption is uneven and some teams ship faster than they secure. This session is about the safety net you stretch under the entire SDLC - catching what shift-left missed, without ever touching an application owner's pipeline.

    We trace a single container finding through Microsoft Defender for Cloud's Code-to-Runtime chain from Source → CI/CD → Registry → Runtime, measure its blast radius across every affected workload via the Cloud Security Graph, and fix it once at the most effective point. Admission control turns posture findings into deploy-time prevention; binary drift detection and runtime protection from Defender for Containers catch what prevention misses, because attackers don't wait for your app team's sprint capacity.

    Then we close the loop: a finding becomes an owner-assigned GitHub issue carrying full SDLC context, a fix lands as a pull request, and "resolved" syncs back to Defender the moment it merges. All of it central-first: no pipeline rewrites, no sidecars, no per-team dependencies, so security scales independently of how fast each team adopts shift-left.

    Washington · 16:30 – 17:10

    Project Perception: From Red to Green with a lot of Blue in the middle

    Jaime Guimera Coll

    Speaker

    Jaime Guimera Coll

    Project Perception is the new Agentic Security capability inside the Microsoft Security ecosystem. It is not just a simple evolution from Security Copilot but a redefinition of how AI agents can plan, execute and validate security operations.

    This session will explain the main capabilities of the three agent types, Red, Blue, Green, by showcasing end to end playbooks that spins from exposure management to alert triage and code hardening.

    The audience will get a comprehensive overview and realistic uses cases that can improve and enhance their security operations.

  • 17:20 – 18:00

    Hive · 17:20 – 18:00

    How to utilize Purview to investigate and protect your AI work

    Oliver Sahlmann

    Speaker

    Oliver Sahlmann

    Everyone has secured their Copilot rollout. Far fewer can answer the harder question: what are people actually doing with AI, and what happens when you find something you don't like?

    This session covers the protection layer first; sensitivity labels, DLP for Copilot, oversharing controls, and blocking sensitive uploads to consumer AI tools. The bulk of the time goes to visibility: what DSPM for AI reveals about managed and shadow AI usage, what Communication Compliance catches inside prompts and generated responses, and how Insider Risk Management turns isolated signals into a pattern worth investigating.

    Then the part that usually gets skipped: how to handle a finding. Routing between security, HR and legal, escalating into cases and eDiscovery, responding automatically with Adaptive Protection.

    You leave knowing which Purview signal answers which question, and who should be reading it.

    Washington · 17:20 – 18:00

    Hidden gems in and around Defender XDR with Defender Boys

    Stefan Schörling

    Speaker

    Stefan Schörling

    Mattias Borg

    Speaker

    Mattias Borg

    Microsoft Defender XDR is packed with powerful capabilities, but many of the most valuable features often remain undiscovered, underutilized, or overlooked in day-to-day operations. In this session, the Defender Boys shine a spotlight on the hidden gems that can help security teams work smarter, gain deeper visibility, and improve their overall security posture.

    Drawing from real-world customer engagements, we'll showcase practical features, lesser-known capabilities, and useful integrations across the Defender ecosystem that can deliver immediate value. From investigation shortcuts and advanced hunting techniques to exposure insights, automation opportunities, and operational efficiencies, you'll learn how to get more out of the tools you already own.

    Whether you're a security analyst, engineer, or architect, you'll walk away with practical tips, proven use cases, and a list of features you'll want to enable the moment you return to your environment. Because sometimes the biggest security wins come from the features hiding in plain sight.

  • 18:00 – 20:00
    SocialClosing, Giveaway, Drinks & Bites