Barbara Forbes

Barbara Forbes

Azure Architect @ Zure | Azure MVP | GitHub Star

Actions

Barbara Forbes is an Azure Architect & consultant at Zure in the Netherlands, a Microsoft Azure MVP, Microsoft Certified Trainer (MCT), and a GitHub Star. She works at the intersection of technology, strategy, education, and development. Her focus is on the Microsoft Cloud Adoption Framework, Generative AI, Infrastructure as Code, PowerShell, and GitHub.
Barbara loves explaining things in an accessible manner; in person, as a teacher for LinkedIn Learning and as a frequent speaker at conferences and user groups. She is actively involved in the tech community, including being part of the organization of European events

Badges

Area of Expertise

  • Information & Communications Technology

Topics

  • Cloud
  • Cloud & DevOps
  • Cloud Architecture
  • Cloud Security
  • Cloud Computing
  • Cloud & Infrastructure
  • Azure
  • GitHub
  • Developer
  • Developer Tools

Trust, don't store: how WIF changes your deployment security

Does your deployment pipeline authenticate with a client secret? Then this session is for you. In the best case scenario, secrets live in a vault, get rotated on a schedule nobody loves, and occasionally expire at exactly the wrong moment. In the worst case they are stored somewhere unsecured or never rotate at all. Let's take away the risk with a far better option.

Workload Identity Federation replaces stored credentials with a trust relationship. No secrets that can leak, no expiration at the wrong time, nothing stored outside of Azure.

In this session we'll explore the systems behind WIF and OpenID Connect and how the two relate. We set up WIF from scratch in both GitHub Actions and Azure DevOps, connecting to Azure. You'll see how the trust model works and what configuration is important. We'll also cover the current limitations and what that means for your specific setup.
By the end you will understand exactly how WIF works, have the steps to migrate your existing pipelines and a clear answer if anyone asks you if WIF is the most secure form of authentication

One Size Fits None: Make Azure best practices work for your organization

The Microsoft Cloud Adoption Framework promises a solid foundation. Azure Verified Modules promise consistent, reusable infrastructure. The Azure Security Benchmark will make sure your resources are protected and secured. And they deliver, but not without making them your own.

With flexibility comes complexity. In this session we look at where Microsoft Azure best practices are strong, and where they might start working against you. Not because they are wrong, but because the average company is hard to find. We look through what the standards are and why they will or will not work for you. Maybe your company doesn't need the flexibility of AVM, which can be a pain to update. Maybe developers at your company don't want the freedom that comes with the Cloud Adoption Framework. And some policies in the Azure Security Benchmark can actually block built-in Azure resources. With these and more examples from the field we will pinpoint how you can make these standards work for your company. You will walk away with a clearer vision on what to adopt and what to adapt.

Secure access to your Azure environment: Let's count the ways

Azure's web-based access is incredibly convenient, allowing you to enter the portal from any device, anywhere. But this convenience isn't exclusive to you; it's also a potential gateway for those with malicious intent, trying to exploit your resources, data and budget. The consequences from a security breach can be huge.

In an era where digital protection is needed more than ever, navigating the security tools can be overwhelming. Some tools might slow down your processes. Is the added security worth the potential decrease in speed? Is it necessary?

This session is your guide through the security options available to cloud engineers. We'll explore MFA, PIM, JIT, VPN, PAW, and other three-letter abbreviations that stand between you and your Azure environment intruders. Discover modern tools that not only secure your Azure space but could also be used for on-premises access through Azure.

By the end of our journey, you'll have a blueprint for creating the most secure environment. You'll leave equipped to make informed decisions about which security measures are right for your setup. Let's secure your Azure landscape together.

The Microsoft Cloud Adoption Framework: What the Docs don’t tell you

The Microsoft Cloud Adoption Framework for Azure promises a flexible environment where developers have the freedom to innovate while keeping data and resources secure. Sounds great right? It is, but real life implementations can often come with some challenges. Including the first world problem of too much documentation.

In this session, we'll look at the Cloud Adoption Framework and how you can use it effectively. I will take your through each step of the Framework and the challenges that came with them in the real world implementations. Spoiler alert: It’s often not the technology that’s the problem! By the end of this talk you will have actionable knowledge to shape your own Azure journey to its fullest potential

Deploying to Azure: Azure DevOps Pipelines vs GitHub Actions

When using Infrastructure as Code, it’s crucial to maintain the highest possible quality and security of your code. Automated tests and deployments help us achieve a consistent and stable Azure environment.

But which tool should you use? Both Azure DevOps and GitHub Actions are professional tools to achieve this goal, but how do they compare? In this session, we will explore the similarities and differences between these two tools. How much time does it take to learn them, how much management do they require, and how do they integrate with Azure? Together, we’ll discover which of the two best fits your situation.

No cartoons in Azure: Creating a solid naming- and tagging strategy

Working with Azure brings a very familiar challenge: the naming convention. Who remembers inheriting servers named after cartoons, vegetables, scientists or random jokes? It's always funny until it starts scaling. With Azure, you reach this point very fast and it pays to get it right directly.
In this talk, we will look at the choices to make, the technical and strategical challenges and some tips & tricks from the field. Last but not least, let's see how we can integrate that naming- and tagging convention in our Infrastructure as Code to help get the most consistent environment. You will thank yourself later!

Implementing Azure Policies: Before the Portal

As your Azure environment grows, you'll need to find ways to keep everything organized. Especially with structures like the Microsoft Cloud Adoption Framework, it's important to set boundaries to manage the endless possibilities that Azure has to offer. So you create policies to help maintain control, security, and compliance in your environment.

But where do you begin? The options seem endless. Should you use all of them?
In this talk, we'll look at the starting point. Guess what; it isn't the Azure portal. We'll see how to determine the policies you need and how to simplify your Azure experience rather than complicate it.
We'll also address common challenges and mistakes in Azure policy as seen from the field. At the end, you will have a clearer understanding that will help you make the best choices and make Azure policy work for you.

Kickstart your secure Azure environment with Microsoft Defender for Cloud

In today's world, securing your cloud environment is more important than ever. We all need to find our way, but did you already explore what Microsoft Defender for Cloud has to offer? You get a suite of tools designed to protect your resources, detect threats, and respond to incidents swiftly. So many options, where do you start?

Join me in this session as I guide you along the different options of Microsoft Defender for Cloud. We'll start with an overview of its key features and capabilities, including threat detection, vulnerability management, and security posture assessment. Then, we'll explore practical scenarios and real-world examples to demonstrate how Defender for Cloud can help you create workflows to enhance security without compromising efficiency.

This session will provide insights and strategies to help you safeguard your Azure environment. Let's unlock the power of Microsoft Defender for Cloud together and ensure your cloud infrastructure stands strong against evolving threats.

Coding smarter with GitHub Copilot

AI is changing the way we work. But how do we actually create more value with it?
You've seen what GitHub Copilot can do. But in this session, we will focus on what matters: how to get consistently better results, instead of feeling like you’re explaining your code to a toddler.

Through live demos, we’ll explore how GitHub tools can be customized and managed to become your (slightly annoying) coworker. One that actually saves time, comes up with options you might miss, and occasionally surprises you in a good way.
You’ll walk away with a clear overview and practical tips on which tools and models to use.
Let's find out how we can make AI work for us to bring our ideas to life.

This title was written by AI — and that’s only the beginning

What happens when you let AI write your code, your posts, and your plans? Only one way to find out.
In this talk, I share what happened when I let AI take over my workflow: writing full coding projects, managing my LinkedIn presence, scheduling my time, creating videos, and even teaching me new frameworks.

From hallucinated pull requests to surprisingly useful insights, each experiment revealed how much (and how little) we can delegate to machines. I will tell you my experiences and if I could have predicted them beforehand. You’ll leave with real examples, honest takeaways, and a new sense of how you can let AI help shape your life, without losing the human logic behind it.

Let AI run your life: what could possibly go wrong

What happens when you let AI write your code, your posts, and your plans? In this talk I share what happened when I put AI to work across everything: shipping apps to production, managing my LinkedIn presence, automating my planning, even learning new frameworks.

Each experiment showed the same pattern: AI gives back exactly as much as you put into managing it. I will tell you what worked, what failed, and how you can improve your own results based on my lessons learned.
You'll leave with real examples, an honest cost/benefit breakdown, and a clear sense of how to get more value out of your new artificial friend, without losing the human logic behind it.

Azure Policy as Code: Lessons from the Field

In this session, I take you through everything I learned building a fully automated Azure Policy deployment. We start at the basics: what the Azure Policy structure actually looks like, and what building blocks are available to you. From there we go into Infrastructure as Code, and how you turn those building blocks into something that's actually yours: definitions, assignments, exemptions, all deployed and managed through code instead of clicked together by hand.
Then, let's talk about all the things I didn't see coming. The assumptions that turned out wrong, the parts I had to rebuild, the design choices that looked fine until they didn't. You get the mistakes so you don't have to make them yourself.
By the end of this session, you'll have a clear blueprint for automating Azure Policy in your own Landing Zone, and you'll know exactly which pitfalls to avoid.
Should you automate your policy setup? Absolutely, it's worth it. This session just saves you the time I spent finding that out the hard way.

Barbara Forbes

Azure Architect @ Zure | Azure MVP | GitHub Star

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top