Mika Vilpo

Mika Vilpo

Cloud security architect and CAIO @ Netox. Microsoft MVP in Cloud Security and Azure Ops.

Turku, Finland

Actions

Mika is a dual-category Microsoft MVP (Cloud Security, and Azure Operations & Management) and Chief AI Officer at Netox, a Finnish Microsoft partner. He works where identity, cloud security and AI meet, on a problem that arrived faster than the governance for it: software that authenticates, holds real permissions, and acts on its own. Most organisations cannot name what is already running in their tenant, let alone who owns it or what it can reach. Mika spends his time answering those questions, from agent identity and permission design in Microsoft environments through to ServiceNow AI Control Tower as the enterprise register that tracks every agent an organisation runs, whichever platform built it. Around that he designs Azure AI landing zones, and still spends plenty of time on the unglamorous parts: policy as code, and PowerShell that has to run correctly at three in the morning.

In addition to his work in cloud and AI, Mika is deeply involved in humanitarian efforts. He serves as Head of Disaster Management for his local Red Cross branch and has been deployed as an information management delegate during natural disasters in Finland and abroad. His expertise in crisis response and data coordination plays a crucial role in emergency operations.

When he is not securing cloud environments, building AI solutions, or managing disaster response, you will likely find him enjoying craft beer.

Badges

Area of Expertise

  • Government, Social Sector & Education
  • Health & Medical
  • Information & Communications Technology

Topics

  • Cloud Security
  • Azure
  • Entra ID
  • Agentic AI
  • Azure AI
  • AI Security
  • Azure Security
  • Zero Trust AI
  • Cloud Adoption Framework
  • Cloud Automation
  • IaC
  • Microsoft 365 Security
  • PowerShell
  • Security
  • Humanitarian Aid
  • Information Management
  • ODK
  • Primary Data Collection
  • Volunteer Management
  • Search and Rescue
  • ServiceNow

Information Management in Emergencies - How you can use your skills for good

Understanding the scale and needs of an emergency is pivotal for successful response planning when a crisis occurs. Whether it's a natural disaster, a health crisis, or an armed conflict, information management plays a crucial role in operations. It involves collecting, cleaning, processing, analyzing, and visualizing data to make informed decisions. This field can encompass technical roles or focus on developing processes and capabilities.

Mika, who has been deployed multiple times in various emergencies for the Red Cross, will share his experiences in aiding those most in need. Attendees will learn through real-life examples how IT professionals can leverage their skills for humanitarian aid and make a positive impact in the world.

Level 100-200
45 minutes

After this session, participants can:
* Describe how data moves through an emergency response, from primary collection in the field to decision-ready analysis.
* Identify which of their existing skills (data engineering, integration, visualisation, platform operations) transfer directly to humanitarian information management.
* Find a concrete route into volunteering with a national society or an international response roster.

Microsoft Defender for Cloud: What Do You Actually Get When You Pay?

Discover insights into Microsoft Defender for Cloud as a CNAPP that combines CSPM (posture, recommendations, inventory) and CWPP (workload protection) — and learn what is truly free vs what unlocks with paid plans.

Learn the practical difference between Foundational CSPM and Defender CSPM, including attack path analysis, Cloud Security Explorer, Data & AI posture (DSPM / AI-SPM), and how risk-based prioritisation changes the way you act on findings.

Understand what the CWPP modules actually catch in real life (not marketing terms): examples like MITRE ATT&CK-style App Service threats, SQL injection/anomalous logins, storage exfiltration patterns, Kubernetes runtime threats + CI/CD image gating, Key Vault misuse, suspicious ARM control-plane operations, OWASP API threats, and GenAI risks like prompt injection and wallet abuse.

Uncover a decision framework for “what’s worth paying for” in your environment by mapping protections to business risk and tooling overlap (e.g., WAF vs App Service signals, Foundry guardrails vs Defender for AI Services, XDR integration value, and when log-based DIY monitoring is enough).

I’m excited about this topic because I keep seeing organisations either enable everything blindly or avoid the platform entirely due to cost uncertainty. My goal is that you leave with a clear, actionable “starter pack” of modules, a prioritised upgrade path, and the confidence to explain the spend to both engineers and decision-makers — without turning security into a licence guessing game.

Level 200-300
45 minutes + questions

After this session, participants can:
* Separate Foundational CSPM from Defender CSPM in terms of what each actually unlocks, and decide which subscriptions need which.
* Map individual CWPP plans to the attack paths they realistically catch, and spot where they overlap with WAF, Foundry guardrails or existing log-based monitoring.
* Build a prioritised enablement plan with a cost story that holds up in front of both engineers and budget holders.

Azure Copilot Agents: Hype, Reality, and What’s Next

Discover what Azure Copilot agents actually are today, which agent scenarios are available now, and where they already provide real value. This session focuses on Azure Copilot agents themselves: what they can do today in areas like migration, observability, optimization, resiliency, and troubleshooting, and how Microsoft is starting to bring more agentic operations into Azure.

Learn where Azure Copilot agents are genuinely useful today, where they are still evolving, and how to separate practical value from marketing noise. We will look at how these agents can reduce manual work, support investigations, and help teams operate Azure more effectively, while also being honest about current limitations and maturity.

The goal is to give attendees a clear and realistic understanding of Azure Copilot agents: what exists now, what is worth paying attention to already, and what is likely coming next as Azure continues moving toward more intelligent and agent-driven operations.

I’m excited about this topic because Azure Copilot agents represent a real change in how cloud environments can be understood, operated, and improved. This session cuts through the hype and focuses on the capabilities that actually matter.

Level 200-300
45 minutes

After this session, participants can:
* Name which Azure Copilot agent scenarios are generally available today and which are preview or roadmap only.
* Judge where agent-driven operations remove real toil (migration assessment, cost optimisation, incident investigation) and where doing it manually is still faster.
* Set realistic expectations with their teams and leadership about what Azure agents can be trusted to do without supervision.

Who is your agent, really?

Your tenant already has agents in it. Some came from Copilot Studio, some from Azure AI Foundry, some from code nobody reviewed. Each one authenticates, holds permissions and touches data, and nobody can name most of them. So who is your agent, really?

This session answers that by following three agents through Microsoft Agent 365 and the Microsoft Entra Agent ID model. Reconciler is an autonomous Foundry agent that reads invoices from Storage and posts to an ERP overnight, no user in sight. Inbox assistant lives in Teams and summarizes your mail, acting on your behalf and never beyond it. Deskmate has its own mailbox and answers when you @mention it. Same identity machinery underneath, three very different tokens.

Live demos carry the session: we discover the agents already in a tenant, run Reconciler end to end from managed identity to blueprint to token to data, watch Inbox assistant act for a signed-in user under Conditional Access, and finish with the kill switch: one shared identity, every agent exposed, one switch to stop them all.

You leave able to inventory your agents, design blueprints per trust boundary, put permissions on the agent identity instead of the blueprint, and explain why publishing is a security boundary. With EU AI Act obligations now in force, this is not a someday problem

Level 300
45 mins + questions.

After this session, participants can:
Inventory the agents already in their tenant and treat each one as a non-human identity.
Design Entra Agent ID blueprints per trust boundary and scope agent permissions before deploying.
Tell on-behalf-of from own-identity access, and budget agents as identities, not seats.

Shadow Automation 2.0: When User-Created AI Agents Get the Keys

Someone in sales built an agent last Tuesday. It reads their mailbox, looks up customer records, and answers questions in chat. They shared it with the team because it was useful. It runs on their credentials, with their permissions, and nobody in IT knows it exists.

This is not the shadow IT we know. That was a subscription outside the tenant that did nothing until someone clicked. This one holds an identity, holds live access to business data, and acts on its own.

We follow that agent on stage. We find what is already running in a tenant, watch a second person pull data out of the builder's mailbox, find the wrong name in the audit log, and see what happens when the content it reads contains instructions. Then we fix it: separating where people build from where things run, making the agent act as the person asking rather than the person who made it, and deciding who owns it the day its builder leaves.

The examples are Microsoft. The failure modes are not. Any platform that lets non-specialists attach real permissions to a language model breaks the same way.

You leave with a decision table for agent capabilities, and a way to run the inventory in your own tenant on Monday.

Level 300, ~60 minutes, live demos throughout.

After this session, participants can:
* Inventory the agents running in their tenant and identify which ones hold access that belongs to an individual rather than to the organisation.
* Choose an appropriate identity model for a given agent, and explain what each choice does to the audit trail and to offboarding.
* Apply permission boundaries, sharing limits and approval gates so that safe agent creation is the default path rather than an exception process.

Passwordless, Practically: What Ships, What Sunsets, What to Build For

Passwordless stopped being a project and became a moving target. Methods you rolled out two years ago are on sunset paths, new ones arrived without a clean migration story, and the honest answer to "are we passwordless yet" is usually "for some people, on some devices, for some apps."

This session is a working map of the current state in Microsoft Entra ID and what to build against next. We cover what is production ready today (passkeys in Microsoft Authenticator, FIDO2 security keys, Windows Hello for Business, certificate-based authentication, Temporary Access Pass), what is being retired and on what timeline, and which preview features are worth designing around versus waiting out.

The hard parts get most of the time: bootstrapping a credential for a new hire who has nothing yet, frontline and shared-device scenarios where nobody has a personal phone, legacy applications that still insist on a password field, break-glass accounts, and the Conditional Access authentication strength policies that make any of this enforceable rather than aspirational. We walk through real rollout architectures, where they broke, and what the recovery path looked like.

You leave with a method inventory mapped to your own user segments, a sequencing plan that does not strand anyone mid-migration, and enough detail on authentication strength and registration policy to write the Conditional Access rules on Monday.


Level 200-300
45 minutes + questions

After this session, participants can:
Map available and sunsetting authentication methods to their own user
segments, including frontline and shared-device workers.
Design a credential bootstrap and recovery path using Temporary Access Pass
and authentication strength policies.
Enforce phishing-resistant authentication through Conditional Access
instead of relying on voluntary adoption.

CloudBrew 2026 - A two-day Microsoft Azure event Sessionize Event Upcoming

December 2026 Mechelen, Belgium

ESPC26 Sessionize Event Upcoming

November 2026 Amsterdam, The Netherlands

Build//Localhost:London

Who is your agent, really?

June 2026 London, United Kingdom

MSUG #15: Kotisohva Edition

Defender for Cloud – mitä saan, jos maksan?

April 2026

CloudBrew 2025 - A two-day Microsoft Azure event Sessionize Event

December 2025 Mechelen, Belgium

ESPC25 Sessionize Event

December 2025 Dublin, Ireland

CollabDays Finland 2025 Sessionize Event

September 2025 Helsinki, Finland

MSUGFI Meetup

In my session “Current State of Passwordless Solutions”, I explored the evolution of identity authentication, focusing on Microsoft Entra ID and phishing-resistant methods like FIDO2, Windows Hello for Business, certificate-based authentication, and Temporary Access Pass. I presented both available and sunsetting methods (e.g., SMS, Authenticator push) and upcoming features like SMS login for frontline workers. The session emphasized secure user onboarding, real-world implementation models, and governance with Conditional Access, Entra ID PIM, and Identity Protection. I highlighted the risks of legacy MFA and the importance of aligning passwordless strategies with Zero Trust principles.

June 2025 Helsinki, Finland

Elisa Cloud Day

At Elisa Pilvipäivä 2025, I delivered two sessions focused on building and securing AI platforms on Microsoft Azure:
* "Building Blocks of a Secure and Scalable AI Platform on Azure"
* "Securing the AI Platform on Azure: Defender for Cloud and AI Security Posture"

Together, these sessions provided a comprehensive look at how organizations can move from experimentation to production-grade AI on Azure while embedding security, cost control, and governance from day one. The first session focused on architectural best practices, including modular design, zone-level redundancy, FinOps-aware choices, and the use of Azure Landing Zones and AVM modules. The second session covered practical deployment of Defender for Cloud, Defender for AI, and Purview for CSPM and ASPM, including sensitive data classification, alert enrichment, and identity-based protection for AI services. The audience gained actionable insights into building compliant, resilient, and secure AI platforms aligned with Microsoft’s Zero Trust and responsible AI principles.

April 2025 Helsinki, Finland

IFRC ERU Induction

Information Management in Emergencies session for ERU Induction training. I shared my experiences from my deployments and discussed how information should be managed in humanitarian context in emergencies

January 2025 Tampere, Finland

Azure and Friends #23

Azure ARGh! - What can you do with Azure Resource Manager

September 2024 Helsinki, Finland

Elisa Cloud Day

I talked 1 hour session about how to protect AI applications in cloud. Session covered External Attack Surface Management, Web Application Firewall, CSPM, CWP with live demos on all. Presented session with Markus Lintuala.

April 2024 Helsinki, Finland

IT student external speaks

Developing to the cloud - native approach. I talk to university students what to take in consideration when developing application to the cloud. We discussed about all pillars of well architected framework.

January 2024 Turku, Finland

CloudBrew 2023 - A two-day Microsoft Azure event Sessionize Event

December 2023 Mechelen, Belgium

EvRe - Evacuation Exercise

I spoke in exercise seminar about evacuation registration system and how Power Platform can help you manage information flow in accident response.

September 2023 Haapsalu, Estonia

Microsoft Partner Architect Summit

Howto replace management servers with services. Deep dive on Azure Arc, Azure Functions and Azure Automation and how used event based triggering on these.
Level 300

May 2023 Helsinki, Finland

Elisa Cloud Day

April 2023 Helsinki, Finland

Elisa Cloud Day

April 2023 Tampere, Finland

Preparedness seminar for Red Cross branches

Session about preparedness planning and the role of Red Cross branch in the larger scale emergency

January 2023 Turku, Finland

Microsoft Partner Architect Summit

Managing your infrastucture with Azure Arc

November 2022 Helsinki, Finland

Volunteers in Oil Spill Response

Session about "Managing and Organizing volunteers in Finland" .. our experiences about volunteer management and data management for supporting hr functions in the large oil spill accident.

May 2022

IFRC Data and Digital Week

Automating your dataflow from KoBo to Database and more (with Logic Apps)

April 2021

Arctic Guardian 2021

Session about data management in large scale maritime accident using Azure and Power Platform

April 2021

Microsoft Partner Architect Summit

How infra admin should use Logic Apps to automate their life.

November 2019 Helsinki, Finland

Mika Vilpo

Cloud security architect and CAIO @ Netox. Microsoft MVP in Cloud Security and Azure Ops.

Turku, Finland

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top