Florian Lenz
Fractional Principal Architect · Microsoft Azure MVP · Building Azure platforms .NET teams actually love
Fractional Principal Architect · Microsoft Azure MVP · Building Azure platforms .NET teams actually love
Köln, Germany
Actions
Florian Lenz is a Microsoft Azure MVP and Cloud Architect with over 10 years of experience building secure, scalable cloud platforms on Microsoft Azure. He specializes in Azure Landing Zones, DevSecOps, Infrastructure as Code, and cloud-native architectures, and has worked across industries including energy, finance, retail, and software.
As a speaker, author, and content creator, Florian shares practical lessons from real-world projects through conference talks, articles, and his YouTube channel—helping engineers and teams design systems that are secure, maintainable, and built for long-term success.
Florian Lenz ist Microsoft Azure MVP und Cloud-Architekt mit über 10 Jahren Erfahrung in der Entwicklung sicherer, skalierbarer Cloud-Plattformen in Microsoft Azure. Er ist spezialisiert auf Azure Landing Zones, DevSecOps, Infrastructure as Code und Cloud-native Architekturen und hat in verschiedenen Branchen gearbeitet, darunter Energieversorgung, Finanzdienstleistung und Einzelhandel.
Als Redner, Autor und Content Creator teilt Florian praktische Erkenntnisse aus realen Projekten in Konferenzvorträgen, Artikeln und auf seinem YouTube-Kanal und hilft Softwareentwicklern und Teams dabei, sichere, wartungsfreundliche und auf langfristigen Erfolg ausgelegte Systeme zu entwickeln.
Area of Expertise
Topics
Your APIs Are Already AI Tools! You Just Don't Know It Yet en
Everyone wants AI agents that can work with real business data. Most teams assume that this requires new services, AI-specific endpoints, or a backend rewrite. It doesn't!
In this session, you will see a plain REST API—an Azure Function with zero AI code—become a complete toolset for an AI agent live on stage. The entire transformation occurs at the gateway. Azure API Management exposes the API's operations as MCP (Model Context Protocol) tools.
In the end, a chatbot will answer questions such as "Where is order ORD-2026-0142, and when will it arrive?" by autonomously selecting the appropriate tools and accessing the live API.
You will leave knowing what MCP is and why it's popular, how API Management turns operations into tools while maintaining governance, rate limits, and observability, why tool descriptions are the new API contract, and how to determine which of your existing APIs are AI-ready.
Securing Your Supply Chain Without Slowing Down Your Dev Team en de
This session is not just a theoretical warning.
Over the past year, npm has evolved from a place where supply chain attacks occur to a place where they occur on a schedule. S1ngularity in August: Then, in September, there was Chalk and Debug, which affected 18 packages and involved billions of weekly downloads. Then came Shai-Hulud, a self-replicating worm that scans machines for secrets and publishes them to a public repository.
Security researchers no longer call this a spike. They call it the new baseline.
In nearly every one of these attacks, nothing appeared to be wrong. The pipeline stayed green. The tests passed. Developers had no idea that their CI secrets, cloud credentials, and deployment tokens had already been exfiltrated. Many still don't know if a compromised version is sitting in their lockfile right now.
Every day, millions of developers run npm install without a second thought. It's muscle memory. That's how modern software is built. It's also how attackers get in.
This talk will show you exactly how, with a live demo of a single malicious package silently draining secrets while everything appears normal. Then, we break down the attack vectors.
Finally, Florian present the part that most security talks skip: a practical, actionable playbook for securing an Azure DevOps pipeline using existing tools, with no additional budget and no measurable impact on your team's velocity.
Securing Your Supply Chain Without Slowing Down Your Team en de
Jeden Tag führen Millionen von Entwicklern „npm install“ aus, ohne darüber nachzudenken. Es ist reine Routine. Es geht schnell. So wird moderne Software entwickelt. Und genau so verschaffen sich Angreifer zunehmend Zugang.
Angriffe auf die Software-Lieferkette sind zu einem der effektivsten und am wenigsten beachteten Angriffsvektoren in der Branche geworden. Nicht weil sie besonders ausgeklügelt sind, sondern weil wir unseren gesamten Entwicklungs-Workflow darauf aufgebaut haben, Code zu vertrauen, den wir nicht geschrieben haben, der von Leuten stammt, die wir nie getroffen haben, und der automatisch von Tools installiert wird, die wir kaum konfigurieren.
Diese Session ist keine theoretische Warnung. Es ist eine Live-Demonstration, wie ein einziges bösartiges npm-Paket still und leise Ihre CI-Geheimnisse, Ihre Cloud-Anmeldedaten und Ihre Deployment-Token abzieht, während Ihre Pipeline grün bleibt und niemand etwas bemerkt.
Und dann ist es ein praktischer, sofort umsetzbarer Leitfaden, um das Problem zu beheben.
Azure Landing Zones Without the Overwhelm: A Simple Platform Foundation for .NET Teams en
Most Azure environments weren't designed. They piled up over time. The result is slow deployments, unclear costs, and infrastructure nobody dares to touch. Companies know they need a proper landing zone, but getting started is where most of them get stuck. Azure Verified Modules and the official accelerators are powerful, but for teams at the beginning of the journey they're overwhelming: hundreds of parameters, deep module hierarchies, and architecture decisions nobody is ready to make yet.
Microsoft Azure MVP Florian Lenz has led landing zone and migration projects for companies in energy, finance, and SaaS. In every project he saw the same thing: the hardest part was getting started. So he built a simpler way in. In this session he introduces an open-source GitHub repository with an Azure landing zone platform that is easy to read and easy to adapt. You can clone it, understand it in an afternoon, and shape it to fit your organization.
In the first part, you'll see how to build the foundation:
- Management groups, policies, networking, and identity, without drowning in complexity
- Subscription vending, so new teams and projects get compliant environments in minutes instead of weeks
- Treating the platform as a product that grows step by step as your company matures
In the second part, the view switches to the developers. Using a .NET team as the example, you'll see what daily work looks like on the platform: requesting a new environment, deploying a .NET application through ready-made pipelines, and using managed identities and shared services without opening a ticket.
You'll leave with a working repository, a clear picture of how the platform and the application teams fit together, and a path you can start on the week you get home.
.NET Developer Conference '26 Sessionize Event Upcoming
Techorama 2026 Netherlands Sessionize Event Upcoming
InfoDays: Software-Architektur Upcoming
.NET Assemble! 2026 Sessionize Event Upcoming
DWX 26 Sessionize Event
CodeBuzz 2026 Sessionize Event
Techorama 2025 Netherlands Sessionize Event
DWX - Developer Week '25 Sessionize Event
Experts Live Germany 2025 Sessionize Event
Tech passion day 2025 Sessionize Event
WeAreDevelopers World Congress 2024 Sessionize Event
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top