Sami Lamppu
Principal Cloud Security Lead | Microsoft Security MVP | Elisa
Kauniainen, Finland
Actions
Principal Cloud Security Lead at Elisa and Microsoft Security MVP with expertise in cloud security. He is the author of the Entra ID Attack & Defense Playbook, a MITRE ATT&CK-aligned open-source resource, and of two security books. His current focus is identity security, Microsoft Sentinel, Defender XDR, AI agent security, and posture management.
Links
Area of Expertise
Topics
Exploring Common Attack Scenario(s) in Microsoft Cloud Services
This demo-driven session will explore some common attack scenarios in Microsoft cloud services. We’ll demonstrate different stages of the attack, from initial compromise to lateral movement, and discuss effective mitigations.
Entra ID Attack & Defense - Insights and learnings from the playbook project
Over the past six years, a group of community members has built the Entra ID Attack & Defense Playbook: an open-source, MITRE ATT&CK-aligned resource elaborating real-world identity threats on Microsoft Entra and pairing them with mitigation and detection strategies.
In this deep-dive session, we are skipping the high-level basics and going straight into the insights from our learnings. We will share the findings from the research and investigation of the playbook contributors.
We will walk you through the most critical attack paths, including:
- Adversary-in-the-Middle (AiTM) & Token Replay: How attackers steal and abuse Primary Refresh Tokens (PRTs) on Windows devices, and how to detect and contain the threat.
- On-prem to cloud privilege escalation: Weaponizing Microsoft Entra Connect Sync for high-impact lateral movement.
- Targeting Non-Human & Agentic AI Identities: Demonstrating how established attack techniques are repurposed against traditional machine identities, alongside emerging vectors specifically engineered to exploit Agentic AI integrated within Microsoft Entra.
- Proactive Posture Management: Using the Entra ID Security Config Analyzer (EIDSCA) to surface vulnerabilities before they are exploited.
You will leave this session with actionable mitigation strategies, ready-to-use KQL queries for Microsoft Sentinel and Defender, and a clear understanding of where native capabilities shine and where your custom detections need to fill the gaps.
If you are a cloud architect, security engineer, or Entra administrator, this session gives you the insights to shut down these attack paths before they're exploited.
Demystifying Microsoft Security Copilot
Join this demo-driven deep dive into Microsoft Security Copilot and see it in action! This session goes beyond the basics, showcasing incident response, threat hunting, and automation scenarios. Learn how Security Copilot integrates with SIEM and XDR to enhance the Blue Team approach. I'll explore practical use cases, best practices, and advanced capabilities to maximize efficiency and decision-making in security operations. Whether you're an SOC analyst, security engineer, or incident responder, this session will provide hands-on insights to elevate your SecOps strategy.
The Modern Security Playbook: Microsoft Sentinel Data Lake, Graph-Powered Hunting, and MCP
Recent Microsoft Sentinel innovations, including the Sentinel Data Lake and graph-powered investigation capabilities, enable security teams to explore long-term security telemetry and entity relationships in ways that were previously impractical with query-only workflows. These capabilities allow security teams to investigate attack paths, blast radius, and exposure using historical data and contextual relationships across identity, endpoint, and cloud signals.
This demo-focused session shows how Sentinel Data Lake and Sentinel graph capabilities can be combined with modern investigation tooling (including Sentinel MCP server tools and other AI-assisted capabilities) to support scalable, context-aware investigations.
Through demos, we’ll walk through several security scenarios that leverage graph-powered investigations, long-term data exploration, and AI-assisted workflows to perform blast radius and exposure analyses, using Microsoft security data as a unified investigation foundation.
The session focuses on practical workflows showing how modern security teams can investigate faster and hunt deeper at a data lake scale.
Entra ID Attack & Defense
Identity is the new perimeter — and attackers know it. Over the past four years, a community of security researchers has built and continuously expanded the Entra ID Attack & Defense Playbook: an open, structured, and MITRE ATT&CK-aligned resource that dissects real-world attack scenarios against Microsoft Entra ID and pairs each one with practical detection and mitigation guidance using the Microsoft security stack.
In this deep-dive session, we share the story behind the project: how a geographically distributed team collaborated almost entirely remotely, running attack simulations, building KQL detections, and stress-testing findings across hundreds of lab iterations — all as a community effort outside of regular working hours.
We'll walk you through the playbook's most critical scenarios, including:
- Adversary-in-the-Middle (AiTM) phishing attacks and replay of token artifacts on Windows devices — how attackers steal and abuse them, and how to detect and contain the threat
- Privilege escalation via Microsoft Entra Connect Sync - a high-impact lateral movement path from on-premises AD to the cloud
- Illicit Consent Grant and OAuth phishing - how attackers weaponize registered applications to silently harvest data
- Entra ID Security Config Analyzer (EIDSCA) - proactive posture management to surface weak configurations before attackers exploit them
For every scenario, you'll leave with actionable mitigation strategies, ready-to-use KQL detection queries, and a clear understanding of where native Microsoft Defender and Sentinel capabilities cover you - and where custom detections fill the gap.
Whether you're an identity architect, security engineer, or SOC analyst, this session gives you the playbook of the adversary so you can build a stronger defense.
Workplace Ninjas Norway 2026 Sessionize Event
Swiss Microsoft Security Summit 2026 Sessionize Event
Purple Elbe Security User Group User group Sessionize Event
Sami Lamppu
Principal Cloud Security Lead | Microsoft Security MVP | Elisa
Kauniainen, Finland
Links
Actions
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top