Session
Your AI, their Attack Path: Securing Azure AI workloads with Microsoft Defender for Cloud
Azure AI services are being deployed rapidly - often without the same security guardrails as traditional workloads. Public endpoints, API key authentication, excessive RBAC permissions, and missing network isolation can quietly expand the attack surface and introduce new attack paths.
In this technical, demo-driven session, we approach Azure AI security from a purple team perspective - combining attacker simulation with defensive detection and investigation.
We begin with Defender CSPM, examining how Azure AI resources are inventoried, assessed, and incorporated into attack path analysis. We demonstrate how seemingly minor misconfigurations can be chained together into realistic compromise scenarios across identities, control plane permissions, and AI resources.
Next, we simulate AI-focused attacks, including prompt injection attempts and abuse of exposed API access, against a deliberately misconfigured Azure AI deployment. We then analyze how the Defender for AI Services plan detects suspicious activity, how alerts surface in Microsoft Defender XDR, and how to investigate them using live KQL queries.
This session connects technique to telemetry - showing not only how Azure AI can be abused, but how defenders can detect, validate, and reduce that exposure in real environments.
Pierre Thoor
Microsoft Security MVP · Senior Cloud Security Architect @ Onevinn · Author
Helsingborg, Sweden
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top