Session

One Pull Request, Seven Places It Could Go Wrong: Securing AI-Enabled .NET Applications on Azure

One pull request. A new feature that calls a hosted model, backed by an Azure Function that exposes tools to an agent. Some of the code was written by AI. It has four security problems in it, and it looks completely normal.

We'll follow that PR from a laptop to production, live, and stop at seven places it could have gone wrong. A hardcoded key gets blocked at push. CodeQL finds an injection flaw in the C#. A vulnerable NuGet package shows up on the PR. One pipeline step scans the Bicep and the container image together. Copilot Autofix proposes a patch — and we read it critically before accepting. Azure Policy refuses the deployment. Then, after deploy, Defender for Cloud catches something none of the earlier checks could: a prompt injection hitting the live model.

At each stop, three questions: what could an attacker do here, what control catches it, and who is accountable for the answer.

This is mostly demo. It's .NET and Azure, but the stops are the same if you build in Python on AWS or Java on-prem — you'll recognise your own equivalents. No prior security or AI background needed; every term gets defined the first time it appears.

You'll leave with the reference pipeline in a public repo, and a mental model of where the gaps usually are.

Jonah Andersson

Principal Cloud Engineer Architect • Microsoft MVP • Microsoft Certified Trainer • Author of Learning Microsoft Azure

Sundsvall, Sweden

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top