Speaker

Mika Vilpo

Mika Vilpo

IT geek building clouds, MVP

Turku, Finland

Actions

Mika is an expert in public cloud solutions, specializing in modern, cloud-native architectures and security. With a keen focus on helping customers navigate their cloud journey, he designs and implements strategies for roadmaps, cloud security, application modernization, and infrastructure automation. His passion lies in making complex cloud challenges manageable and scalable.

In addition to his work in cloud, Mika is deeply involved in humanitarian efforts. He serves as Head of Disaster Management for his local Red Cross branch and has been deployed as an information management delegate during natural disasters in Finland and abroad. His expertise in crisis response and data coordination plays a crucial role in emergency operations.

When he’s not securing cloud environments or managing disaster response, you’ll likely find him enjoying craft beer. Mika also holds nearly all Microsoft certifications related to Azure and Security, reinforcing his deep expertise in the field. Mika is awarded as Microsoft Most Valuable Professional in Security.

Badges

Area of Expertise

  • Government, Social Sector & Education
  • Health & Medical
  • Information & Communications Technology

Topics

  • Azure
  • Azure Active Directory
  • Azure Functions
  • Azure AD
  • Azure Logic Apps
  • Low Code
  • Power Automate (Flow)
  • Power Platform - Low Code
  • Humanitarian
  • emergency response
  • Information Management
  • Primary Data Collection
  • ODK
  • Volunteer Management
  • Team Awareness
  • Security
  • Azure PaaS
  • Azure IaaS
  • Azure Sentinel
  • Azure Security
  • Bicep
  • Azure Bicep
  • Cloud Security
  • Azure DevOps
  • Cloud landing zone
  • Cloud Adoption Framework
  • Microsoft 365 Security
  • Azure Service Bus
  • Patch Management
  • Microsoft 365
  • PowerShell DSC
  • MS Entra ID
  • EntraID
  • Infrastructure as code (IaC) security and policy-as-code
  • IaC
  • CI/CD
  • Automation with PowerShell
  • Power Automate
  • Cloud Automation
  • Humanitarian Aid
  • Azure AI
  • Azure AI Foundry
  • Process Development
  • Search and Rescue
  • api security

Microsoft Defender for Cloud: What Do You Actually Get When You Pay?

Discover insights into Microsoft Defender for Cloud as a CNAPP that combines CSPM (posture, recommendations, inventory) and CWPP (workload protection) — and learn what is truly free vs what unlocks with paid plans.

Learn the practical difference between Foundational CSPM and Defender CSPM, including attack path analysis, Cloud Security Explorer, Data & AI posture (DSPM / AI-SPM), and how risk-based prioritisation changes the way you act on findings.

Understand what the CWPP modules actually catch in real life (not marketing terms): examples like MITRE ATT&CK-style App Service threats, SQL injection/anomalous logins, storage exfiltration patterns, Kubernetes runtime threats + CI/CD image gating, Key Vault misuse, suspicious ARM control-plane operations, OWASP API threats, and GenAI risks like prompt injection and wallet abuse.

Uncover a decision framework for “what’s worth paying for” in your environment by mapping protections to business risk and tooling overlap (e.g., WAF vs App Service signals, Foundry guardrails vs Defender for AI Services, XDR integration value, and when log-based DIY monitoring is enough). This is a conference-first session: we’ll run quick audience-driven scenarios and do live walk-through style demos where participants choose the attack path, workload, and budget constraints.

I’m excited about this topic because I keep seeing organisations either enable everything blindly or avoid the platform entirely due to cost uncertainty. My goal is that you leave with a clear, actionable “starter pack” of modules, a prioritised upgrade path, and the confidence to explain the spend to both engineers and decision-makers — without turning security into a licence guessing game.

Passwordless 2025: Navigating the Present, Sunset Paths, and Future-Ready Authentication

Discover the evolving landscape of passwordless authentication as we explore what’s available today, what’s on the way out, and how to design future-ready identity strategies. In this technically-focused session, we’ll break down the current state of authentication solutions across Microsoft Entra ID and beyond, including FIDO2, biometrics, passkeys, and mobile-based MFA methods. We’ll clarify what’s being deprecated (like SMS-based MFA), examine what’s gaining traction, and highlight preview features to watch.

You’ll gain real-world insights into deployment architectures, security trade-offs, and how to drive user adoption in hybrid or cloud-native environments. We’ll also cover key considerations for firstline workers, legacy app access, and compliance implications. Expect architectural diagrams, live demos, and war stories from actual rollouts—making this session highly practical for architects and identity specialists planning their next move in modern authentication.

When AI Goes Rogue: Real-World Security Lessons from the Trenches

Discover insights into the pitfalls of deploying AI solutions through four real-world case studies, each drawn from diverse customer environments. In this session, you'll learn what not to do—from securing the end-user interface to establishing a robust overall cloud security posture, and even detecting "rogue" AI deployments. Attendees will gain actionable strategies to fortify AI infrastructures and safeguard sensitive data while avoiding common security missteps. Designed exclusively for IT professionals in a conference setting, this engaging presentation promises live demos and practical takeaways that empower you to build more resilient AI systems. Join me as I share the lessons I’ve learned on the front lines, fueled by a genuine passion for creating secure, innovative AI solutions.

Information Management in Emergencies - How you can use your skills for good

Understanding the scale and needs of an emergency is pivotal for successful response planning when a crisis occurs. Whether it's a natural disaster, a health crisis, or an armed conflict, information management plays a crucial role in operations. It involves collecting, cleaning, processing, analyzing, and visualizing data to make informed decisions. This field can encompass technical roles or focus on developing processes and capabilities.

Mika, who has been deployed multiple times in various emergencies for the Red Cross, will share his experiences in aiding those most in need. Attendees will learn through real-life examples how IT professionals can leverage their skills for humanitarian aid and make a positive impact in the world.

Azure ARGh! What can you do with Azure Resource Graph

Azure Resource Graph gives you access to all your cloud estate but how to leverage it for your needs? In this session we discuss how you can use Azure Resource Graph to get insights and valuable information about your resources, security state and more. And we will demonstrate how you can extend that to other clouds and on prem assets as well.

How infra admins can move from scheduled tasks to cloud and event based activities

Modernizing the management of infrastructure is a key goal for many organizations that want to improve efficiency, security and scalability. One of the challenges in this process is how to replace old server bound scheduled tasks with more flexible and reliable cloud-based solutions. In this session, we will explore how to leverage Azure Automation account and Azure Functions to consolidate automations to cloud and trigger them based on events rather than schedules. We will also demonstrate how Azure Arc can help you manage servers that are hosted outside of Azure and integrate them with your cloud automations.

By the end of this session, you will have a better understanding of how to migrate from legacy server bound scheduled tasks to modern cloud-based automations using Azure services.

MSUG #15: Kotisohva Edition

Defender for Cloud – mitä saan, jos maksan?

April 2026

CloudBrew 2025 - A two-day Microsoft Azure event Sessionize Event

December 2025 Mechelen, Belgium

ESPC25 Sessionize Event

December 2025 Dublin, Ireland

CollabDays Finland 2025 Sessionize Event

September 2025 Helsinki, Finland

MSUGFI Meetup

In my session “Current State of Passwordless Solutions”, I explored the evolution of identity authentication, focusing on Microsoft Entra ID and phishing-resistant methods like FIDO2, Windows Hello for Business, certificate-based authentication, and Temporary Access Pass. I presented both available and sunsetting methods (e.g., SMS, Authenticator push) and upcoming features like SMS login for frontline workers. The session emphasized secure user onboarding, real-world implementation models, and governance with Conditional Access, Entra ID PIM, and Identity Protection. I highlighted the risks of legacy MFA and the importance of aligning passwordless strategies with Zero Trust principles.

June 2025 Helsinki, Finland

Elisa Cloud Day

At Elisa Pilvipäivä 2025, I delivered two sessions focused on building and securing AI platforms on Microsoft Azure:
* "Building Blocks of a Secure and Scalable AI Platform on Azure"
* "Securing the AI Platform on Azure: Defender for Cloud and AI Security Posture"

Together, these sessions provided a comprehensive look at how organizations can move from experimentation to production-grade AI on Azure while embedding security, cost control, and governance from day one. The first session focused on architectural best practices, including modular design, zone-level redundancy, FinOps-aware choices, and the use of Azure Landing Zones and AVM modules. The second session covered practical deployment of Defender for Cloud, Defender for AI, and Purview for CSPM and ASPM, including sensitive data classification, alert enrichment, and identity-based protection for AI services. The audience gained actionable insights into building compliant, resilient, and secure AI platforms aligned with Microsoft’s Zero Trust and responsible AI principles.

April 2025 Helsinki, Finland

IFRC ERU Induction

Information Management in Emergencies session for ERU Induction training. I shared my experiences from my deployments and discussed how information should be managed in humanitarian context in emergencies

January 2025 Tampere, Finland

Azure and Friends #23

Azure ARGh! - What can you do with Azure Resource Manager

September 2024 Helsinki, Finland

Elisa Cloud Day

I talked 1 hour session about how to protect AI applications in cloud. Session covered External Attack Surface Management, Web Application Firewall, CSPM, CWP with live demos on all. Presented session with Markus Lintuala.

April 2024 Helsinki, Finland

IT student external speaks

Developing to the cloud - native approach. I talk to university students what to take in consideration when developing application to the cloud. We discussed about all pillars of well architected framework.

January 2024 Turku, Finland

CloudBrew 2023 - A two-day Microsoft Azure event Sessionize Event

December 2023 Mechelen, Belgium

EvRe - Evacuation Exercise

I spoke in exercise seminar about evacuation registration system and how Power Platform can help you manage information flow in accident response.

September 2023 Haapsalu, Estonia

Microsoft Partner Architect Summit

Howto replace management servers with services. Deep dive on Azure Arc, Azure Functions and Azure Automation and how used event based triggering on these.
Level 300

May 2023 Helsinki, Finland

Elisa Cloud Day

April 2023 Helsinki, Finland

Elisa Cloud Day

April 2023 Tampere, Finland

Preparedness seminar for Red Cross branches

Session about preparedness planning and the role of Red Cross branch in the larger scale emergency

January 2023 Turku, Finland

Microsoft Partner Architect Summit

Managing your infrastucture with Azure Arc

November 2022 Helsinki, Finland

Volunteers in Oil Spill Response

Session about "Managing and Organizing volunteers in Finland" .. our experiences about volunteer management and data management for supporting hr functions in the large oil spill accident.

May 2022

IFRC Data and Digital Week

Automating your dataflow from KoBo to Database and more (with Logic Apps)

April 2021

Arctic Guardian 2021

Session about data management in large scale maritime accident using Azure and Power Platform

April 2021

Microsoft Partner Architect Summit

How infra admin should use Logic Apps to automate their life.

November 2019 Helsinki, Finland

Mika Vilpo

IT geek building clouds, MVP

Turku, Finland

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top