Loading…
This event has ended. Visit the official site or create your own event on Sched.
Venue: Room 2 clear filter
arrow_back View All Dates
Wednesday, April 22
 

10:00 CEST

Improve your resilience with cybersecurity table-top exercises
Wednesday April 22, 2026 10:00 - 11:00 CEST
This session will provide a comprehensive introduction to table-top cybersecurity exercises, focusing on their importance, design, and execution. Participants will gain insights into the benefits of conducting table-top exercises, including improved incident response readiness, enhanced communication and coordination among stakeholders, and identification of gaps in policies and procedures. Practical guidance will be provided on structuring exercises to align with organizational objectives, selecting relevant scenarios, and engaging participants effectively.
Speakers
avatar for Stefan Schörling

Stefan Schörling

Cloud Security and Infra Geek - Onevinn AB, Onevinn
Stefan Schörling has over 25 years of experience from working with Cybersecurity.

Today Stefan is helping customers to be successful with implementing and adopting Cloud Security with a focus on Azure and Microsoft 365.

For the last 15+ years he has been awarded as a Microsof... Read More →
avatar for Mattias Borg

Mattias Borg

Cyber security Researcher
Cybersecurity Researcher, Penetration Tester, and Incident Response geek - short description "like to break stuff, and then fix it sometimes"
One of the persons in the duo DefenderBoys - Defenderboys.com

With a strong focus on threat hunting within the Microsoft security ecosystem... Read More →
Wednesday April 22, 2026 10:00 - 11:00 CEST
Room 2

11:15 CEST

Scaling Intune Across Tenants with Microsoft Graph API: Automate the Chaos
Wednesday April 22, 2026 11:15 - 12:15 CEST
If you’ve ever managed multiple Intune tenants, you know the feeling:different policies, different apps, different baselines… and the same tasks repeated over and over — just with a slightly different logo each time.

In this session, Scaling Intune Across Tenants with Microsoft Graph API, we’re going to show you how to take back control.

We’ll start with a simple introduction to Microsoft Graph API — what it is, why it matters, and how it can become your best friend when you're juggling multiple environments. No heavy theory, just the essentials you need to understand how it works under the hood and why it’s so powerful.

From there, we’ll look at real multi-tenant challenges:
✔️ Keeping configurations consistent
✔️ Onboarding new tenants without spending your entire weekend on it
✔️ Fixing drift before your phone blows up
✔️ Getting insights across all your customers without checking 20 portals

Using PowerShell and Graph API, we’ll walk through practical examples that show how automation can turn hours of manual work into a couple of seconds. You’ll see how you can standardize setups, deploy apps and policies across tenants, and pull reporting — all from one place.

This session is built on real-world experience, not theory. Expect honest explanations, clear code samples, and tips you can use the moment you get back to work. And of course, plenty of demos — because seeing it in action is half the magic.

Whether you’re an MSP, part of an enterprise with multiple tenants, or simply tired of doing the same tasks repeatedly, you’ll walk away with strategies that actually make your day easier.
Speakers
avatar for Joery Van den Bosch

Joery Van den Bosch

Microsoft MVP | Modern Workplace Architect at Arxus | Tech Blogger | Microsoft Cloud | Intune | Autopilot, IntuneStuff
My name is Joery Van den Bosch, and I am currently working as a Modern Workplace Architect at Arxus (part of the Cronos Group), voted Microsoft Cloud Partner of the Year 2022 and again in 2023, also Arxus won Microsoft Partner of the Year Western Europe. The Azure Expert MSP Gold... Read More →
avatar for Maxime Guillemin

Maxime Guillemin

Modern Workplace Architect at Arxus | Founder & Blogger at CloudFlow || Microsoft Cloud | Intune | Autopilot | GraphApi, CloudFlow
Hi, I’m Maxime. I’m a freelancer focused on endpoint management, Intune, and modern workplace solutions. Along the way, I’ve been recognized as a Microsoft Intune MVP and I’m also a co-organizer of Workplace Ninjas Belgium.Through my blog, I share practical guides, real-world... Read More →
Wednesday April 22, 2026 11:15 - 12:15 CEST
Room 2

14:00 CEST

Mastering KQL: A Guide for Endpoint Admins
Wednesday April 22, 2026 14:00 - 15:00 CEST
Kusto Query Language (KQL) is a powerful tool for endpoint admins managing Windows environments.

This beginner-friendly session demystifies KQL, breaking down its syntax and demonstrating its use in data analysis. Through practical examples using tools like Intune’s Single and Multi Device query, Intune data within Log Analytics, ConfigMgr's CMPivot, and Microsoft Defender’s Advanced hunting, you'll learn to craft queries that provide insights, troubleshoot issues, and enhance management capabilities. By the end, you'll have the foundational skills to confidently use KQL in your IT operations.
Speakers
avatar for Maurice Daly

Maurice Daly

Microsoft MVP, Senior Security Architect, Patch My PC
Maurice has been working in the IT industry for the past 25 years. His focus is on the areas of Windows deployment, device management, Entra ID security, and secure productivity. Maurice has been an MCSE since 2008 and received his first MVP award in Enterprise Mobility (now Security... Read More →
avatar for David Brook

David Brook

Managing Consultant & Microsoft MVP, CloudXP Ltd
David, a distinguished Microsoft MVP in the Security category, brings a wealth of expertise in Microsoft Intune and Device Management capabilities. _x000D_
_x000D_
Beyond his specialisation, David's versatility shines as he navigates the breadth of the Microsoft ecosystem, seamle... Read More →
Wednesday April 22, 2026 14:00 - 15:00 CEST
Room 2

16:00 CEST

The Ransomware that never was
Wednesday April 22, 2026 16:00 - 17:00 CEST
When companies are affected by a breach, usually they contact an Incident Response provider to get help eradicating the threat actor from their environment.

This procedure generally speaking takes place when all computers and servers are encrypted and the only thing that matters is the RTO and RPO.

This session however, will look at one case where the threat actor was unable to execute their end goal.

Join this session to learn a number of hardening settings you must have in place, tips and tricks on monitoring, and last but not least the importance of end user awareness.
Speakers
avatar for Viktor Hedberg

Viktor Hedberg

Senior Technical Architect @ Truesec AB, Truesec
Security consultant with a focus on Microsoft Security either on-prem or in the cloud, and a blueteamer at heart. Viktor has worked within IT for the past 10 years always within Cyber Security. Working for public sector in Sweden for years but now as a specialist at Truesec AB focusing... Read More →
Wednesday April 22, 2026 16:00 - 17:00 CEST
Room 2
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -