Stephan van Rooij
Software architect at Smartersoft
's-Hertogenbosch, The Netherlands
Actions
A blogger, a speaker but mainly a software architect with a strong focus on security, identity and automation. My day job is all .NET core and single-sign-on. If I have some spare time, I'm mostly working on one off my home automation projects (with over half a million combined downloads)
I'm also an occasional contributor to @azure/msal, azure/microsoft docs and Azure pipeline tasks
Check my blog or github profile for more details
Area of Expertise
Topics
Protect your API with Entra - from zero security to security hero
Security should be top priority in any application these days. In this interactive demonstration I'll show you how to go from an API without security to an API that is secured with Microsoft Entra ID.
Join this sessions so you never have to worry about the security of your API ever again.
- Protecting the API
- What are JWTs (Json Web Tokens)?
- Scopes vs Roles?
- Getting a token as application
- Getting a token as user
These principals are not Microsoft Entra specific and can be applied to other Identity Providers as well, the exact implementation might be slightly different.
You're using Azure Key Vault incorrect
We all seen the samples where you put your secret keys in Azure Key Vault and think you're now completely secure. I'll show you how to exfiltrate those certificates and what you should do about it.
- Exfiltrate certificates
- Protect multi tenant application
- Managed identity misuse
Packaging apps for Intune is hard
How hard can it be to package apps for Intune? We will take you on our journey where we explain how we developed an open-source application that packages any application for Intune. We will show you all the challenges and how this app can help you setup a full company portal in seconds.
We can even decrypt existing intunewin files.
Experts Live Netherlands 2024 Sessionize Event
WorkplaceDudes NL User group Sessionize Event
Dutch Microsoft Security Meetup User group Sessionize Event
Microsoft Security User Group 2024 User group Sessionize Event
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top