Azure provides an overwhelming number of security features, recommendations, and best practices. But if you had to make your Azure environment significantly more secure, where would you start? In this session, I will share the ten security controls I would prioritize first. Whether you are building a new Azure or improving a tenant, the challenge remains the same: identifying the measures that deliver the greatest reduction in risk with the highest impact. We will explore key areas such as identity protection, privileged access management, governance, segmentation, Defender for Cloud, workload protection, and operational readiness. You will leave the session with a practical roadmap that can be applied to both new and existing Azure environments.
After years of Azure security assessments, incident investigations, and cloud transformations, one question keeps coming up: Where should organizations start? If I had to secure a new Azure environment today, these are the ten controls I would implement first—and why.
Gregor is awarded with the Microsoft MVP for Microsoft Azure and Security. He works as Chief Azure Technologist for adesso SE and is lead for Azure . His main areas are Microsoft Azure, Enterprise scale architectures, Cloud Security, Governance, Hybrid and Migration. Gregor is an active member of the global Microsoft community and regularly attends community conferences, runs his own Azure blog (www.reimling.eu) and the Cloud Inspires (www.cloudinspires.me) podcast. He is the founder of the Azure Bonn Meetup with more then 1000 members, a local Azure user group near Cologne and co-founder of the Cloud Identity Summit, an annual conference focusing on identity management and security. Gregor is also a Microsoft Certified Trainer.