Sami Lamppu

Sami Lamppu

Principal Cloud Security Lead | Microsoft Security MVP | Elisa

Kauniainen, Finland

Actions

Principal Cloud Security Lead at Elisa and Microsoft Security MVP with expertise in cloud security. He is the author of the Entra ID Attack & Defense Playbook, a MITRE ATT&CK-aligned open-source resource, and of two security books. His current focus is identity security, Microsoft Sentinel, Defender XDR, AI agent security, and posture management.

Area of Expertise

  • Information & Communications Technology

Topics

  • Microsoft Defender XDR
  • Microsoft Defender for Cloud
  • Microsoft Defender for Endpoint
  • Microsoft Defender for Identity
  • Microsoft Defender for Cloud Apps
  • Microsoft Defender for Office 365
  • Microsoft sentinel
  • Microsoft Security Exposure management
  • Entra ID
  • Microsoft Security Copilot
  • Blue Teaming
  • M365
  • Active Directory
  • Azure Security

Exploring Common Attack Scenario(s) in Microsoft Cloud Services

This demo-driven session will explore some common attack scenarios in Microsoft cloud services. We’ll demonstrate different stages of the attack, from initial compromise to lateral movement, and discuss effective mitigations.

Entra ID Attack & Defense - Insights and learnings from the playbook project

Over the past six years, a group of community members has built the Entra ID Attack & Defense Playbook: an open-source, MITRE ATT&CK-aligned resource elaborating real-world identity threats on Microsoft Entra and pairing them with mitigation and detection strategies.

In this deep-dive session, we are skipping the high-level basics and going straight into the insights from our learnings. We will share the findings from the research and investigation of the playbook contributors.

We will walk you through the most critical attack paths, including:
- Adversary-in-the-Middle (AiTM) & Token Replay: How attackers steal and abuse Primary Refresh Tokens (PRTs) on Windows devices, and how to detect and contain the threat.
- On-prem to cloud privilege escalation: Weaponizing Microsoft Entra Connect Sync for high-impact lateral movement.
- Targeting Non-Human & Agentic AI Identities: Demonstrating how established attack techniques are repurposed against traditional machine identities, alongside emerging vectors specifically engineered to exploit Agentic AI integrated within Microsoft Entra.
- Proactive Posture Management: Using the Entra ID Security Config Analyzer (EIDSCA) to surface vulnerabilities before they are exploited.

You will leave this session with actionable mitigation strategies, ready-to-use KQL queries for Microsoft Sentinel and Defender, and a clear understanding of where native capabilities shine and where your custom detections need to fill the gaps.

If you are a cloud architect, security engineer, or Entra administrator, this session gives you the insights to shut down these attack paths before they're exploited.

Demystifying Microsoft Security Copilot

Join this demo-driven deep dive into Microsoft Security Copilot and see it in action! This session goes beyond the basics, showcasing incident response, threat hunting, and automation scenarios. Learn how Security Copilot integrates with SIEM and XDR to enhance the Blue Team approach. I'll explore practical use cases, best practices, and advanced capabilities to maximize efficiency and decision-making in security operations. Whether you're an SOC analyst, security engineer, or incident responder, this session will provide hands-on insights to elevate your SecOps strategy.

The Modern Security Playbook: Microsoft Sentinel Data Lake, Graph-Powered Hunting, and MCP

Recent Microsoft Sentinel innovations, including the Sentinel Data Lake and graph-powered investigation capabilities, enable security teams to explore long-term security telemetry and entity relationships in ways that were previously impractical with query-only workflows. These capabilities allow security teams to investigate attack paths, blast radius, and exposure using historical data and contextual relationships across identity, endpoint, and cloud signals.

This demo-focused session shows how Sentinel Data Lake and Sentinel graph capabilities can be combined with modern investigation tooling (including Sentinel MCP server tools and other AI-assisted capabilities) to support scalable, context-aware investigations.

Through demos, we’ll walk through several security scenarios that leverage graph-powered investigations, long-term data exploration, and AI-assisted workflows to perform blast radius and exposure analyses, using Microsoft security data as a unified investigation foundation.

The session focuses on practical workflows showing how modern security teams can investigate faster and hunt deeper at a data lake scale.

Entra ID Attack & Defense

Identity is the new perimeter — and attackers know it. Over the past four years, a community of security researchers has built and continuously expanded the Entra ID Attack & Defense Playbook: an open, structured, and MITRE ATT&CK-aligned resource that dissects real-world attack scenarios against Microsoft Entra ID and pairs each one with practical detection and mitigation guidance using the Microsoft security stack.

In this deep-dive session, we share the story behind the project: how a geographically distributed team collaborated almost entirely remotely, running attack simulations, building KQL detections, and stress-testing findings across hundreds of lab iterations — all as a community effort outside of regular working hours.

We'll walk you through the playbook's most critical scenarios, including:
- Adversary-in-the-Middle (AiTM) phishing attacks and replay of token artifacts on Windows devices — how attackers steal and abuse them, and how to detect and contain the threat
- Privilege escalation via Microsoft Entra Connect Sync - a high-impact lateral movement path from on-premises AD to the cloud
- Illicit Consent Grant and OAuth phishing - how attackers weaponize registered applications to silently harvest data
- Entra ID Security Config Analyzer (EIDSCA) - proactive posture management to surface weak configurations before attackers exploit them

For every scenario, you'll leave with actionable mitigation strategies, ready-to-use KQL detection queries, and a clear understanding of where native Microsoft Defender and Sentinel capabilities cover you - and where custom detections fill the gap.

Whether you're an identity architect, security engineer, or SOC analyst, this session gives you the playbook of the adversary so you can build a stronger defense.

Workplace Ninjas Norway 2026 Sessionize Event

May 2026 Oslo, Norway

Swiss Microsoft Security Summit 2026 Sessionize Event

March 2026 Zürich, Switzerland

Purple Elbe Security User Group User group Sessionize Event

May 2023 Hamburg, Germany

Sami Lamppu

Principal Cloud Security Lead | Microsoft Security MVP | Elisa

Kauniainen, Finland

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top