Free YouTube Transcribe

Video transcript

DevSecOps: Developing Secure Ai-Enabled Applications in .NET and Azure

Microsoft Zero to Hero Community · 10,332 words · 47 min read

Want to search this transcript, jump the video from any line, or download it as TXT, SRT, or VTT?

Open in the transcript tool

Full transcript

0:00Heat.

0:17[music]

0:20Heat.

0:25Heat.

0:39Heat. [music]

1:01Hello everyone, welcome to another

1:03session of Microsoft 02 hero community.

1:06This is another weekend, another

1:07Saturday and we will have another

1:10session with a community speaker uh that

1:12is going to talk about uh developing

1:15secure AI enabled applications in net

1:17and Azure which security is important.

1:19But before getting there let me share uh

1:22some news and like uh about the

1:24community. This is a community built by

1:26the community for the community. We have

1:28only a simple code of conduct and it is

1:30to be respectful to each other and

1:32listen to each other. If you want to uh

1:35follow us uh on social medias, you could

1:37go to microsoft hero.com and there you

1:39could follow the news and uh what's

1:41going on in our community, we are part

1:44of microsoftlearn.com

1:45and uh in the calendar you could also

1:48see what are the sessions that already

1:50been held and what are the upcoming

1:51sessions. Uh then uh without further

1:54ado, I would like to invite uh Jonah

1:57Anderson, our guest for tonight's

1:59session. Hi Jonah.

2:02Hi Shahab and everyone that's watching

2:04us live today on uh on YouTube and also

2:08on LinkedIn live. I think we are on

2:10LinkedIn live as well.

2:11>> We are on LinkedIn, we are on

2:12Streamyard, we are on YouTube and we are

2:14also on Twitterly.

2:15>> Yeah. All right. Okay. Yes. It's good to

2:18be back and nice to see you because I

2:20remember we met uh in person uh in uh

2:23one of uh the conferences in Germany uh

2:26as well and it's my second time for uh

2:29for this uh meetup to join I remember

2:32when the community just started I I was

2:35one of the speaker and chair about cloud

2:36migration like I think that was like two

2:39two years ago and now the the community

2:41has grown a lot and you're also one of

2:43the organizers and host so it's great to

2:46work with you. Yeah, thank thanks great

2:48to have you back and uh stage is yours.

2:51Uh I'm sharing the slides now. So yes uh

2:54and uh let's let's get let's get it

2:57started.

2:58>> Yes. Uh so let's go ahead everybody. So

3:01I hope everyone are sitting comfortably

3:03in your couch uh car or wherever you're

3:07watching this mobile or your TV or or

3:10your or or your phone. But uh I'm live

3:13actually right now. I'm alive and

3:15kicking and moving and I'm in my home

3:17office. It's Saturday evening and I'm so

3:20glad uh to be able to sit here and share

3:23my knowledge about uh dev sec ops and

3:26how we can develop securing uh secured

3:29AI enabled apps innet and also in ashure

3:34uh technologies and I remember I I

3:37yesterday uh it was Friday of course I

3:39did share an internal learning session

3:41from my to my colleagues about how to

3:45build uh AI agents using MCP servers and

3:49Microsoft foundry. But today I'm like uh

3:52uh doing another level where I share to

3:55the community in public about DevSec

3:58Ops. So I I look forward that you will

4:00find this uh presentation very useful in

4:04whatever you are building or planning uh

4:07to build. So before that I would like to

4:10share a bit about myself. So I'm uh just

4:14to keep it short, you see everything

4:16here. Uh I'm a Microsoft MVP uh MCT as

4:19well or community lead uh author but uh

4:23I used to work as a a consultant uh for

4:27the last uh 10 years working with uh

4:30system development uh focus innet

4:33and uh now focus a lot on Azure and uh

4:37also putting on a hat as a uh cloud

4:41infrastructure uh team lead uh leading

4:44with our DevOps and uh cloud uh platform

4:49and part of my work is actually the

4:51topic that we're talking about securing

4:54our DevOps pipeline uh from code to

4:58production uh workloads but uh a little

5:01bit about me uh I work for myself now uh

5:04as a independent conso consultant uh so

5:07I have one client I work with uh I I am

5:11the author of learning Microsoft Ashure

5:14uh first edition was released three

5:15years ago and I'm currently writing the

5:17second edition this year and also think

5:21uh writing uh a self-published book on

5:23the side which I will share later. Um I

5:26also am the founder of Asher user group

5:29Sweden which is like the sister like a a

5:32a collaborator of uh this community as

5:36well. So I founded Asher user group Swit

5:38Sweden and we also have uh sessions uh

5:42there uh every Saturday and I'm glad

5:44that this session that I'm delivering

5:46right now doesn't conflict with the one

5:48that I'm I'm hosting. So I have a lot of

5:52a lot of things to share. You can talk

5:53to me of the things that I listed here.

5:56uh feel free to connect with me on

5:58LinkedIn or ask questions later uh if

6:01you want to reach out or collaborate or

6:04have uh questions related to this topic

6:06and uh just uh just to give smile to you

6:09this weekend that is not an AI photo by

6:12the way that is a photo of me and my dog

6:15Lawrence uh last new year uh in his

6:18tuxedo so I'm a dog lover I have a lot

6:20of interest but I'm very proud to to say

6:23I'm a dog mom to this uh cute but large

6:26labradoodle named Lawrence. And if you

6:29follow me on LinkedIn, you probably have

6:31seen uh fun photos of him and me

6:34together sometimes.

6:36So what are we uh uh uh talking actually

6:41uh today? So what we're going to do is

6:44that uh we're going to try to uh discuss

6:47about uh a net application which is can

6:51be very uh v can vary depending on what

6:55kind of architecture that you have but

6:58in this session or talk it will be a

7:00combination a bit of theory uh or de

7:04presentation that you see here and also

7:07some uh uh code examples and how it

7:10looks on VS code if you had uh the code

7:14both the front end back end and how the

7:16YAML pipelines works and then you will

7:19also see uh a bit of uh Azure DevOps and

7:23how it looks the infrastructure on

7:26Azure. So uh what we're trying to uh

7:30protect today is a net uh uh stack. uh

7:34it is actually a realistic kind of

7:36application where of course you have the

7:38front end you have the back end and in

7:41this case since we're talking about

7:43protecting the f uh the the uh the the

7:47back end with AI and one of the tools

7:51that is available today when it comes to

7:53using MCP servers or Microsoft Foundry

7:56for AI integration at least in the net

7:59and Microsoft Ashure stack it is the

8:02Ashure functions MCP tool to trigger and

8:05if you have not tried uh working or

8:08building uh agents uh using Azure

8:12functions if that's your like kind of

8:14field because there are different ways

8:16to build uh agents today but MCP tools

8:20uh tool extension for Ashure functions

8:23is one good way to self-host your agents

8:26uh on uh on Microsoft Foundry. So, we're

8:30going to have that in our like example

8:34uh application and it has a back end of

8:36Blazer. Uh there's a chat UI assuming

8:40it's a it's uh an AI feature chat that

8:44uh an application might be enterprise or

8:47a small one and it has a u a chat UI

8:51that talks to the agent and uh it has

8:54net 10 as its uh as it as its language

8:58and then it uses ashure function MCP

9:02server and flex consumption and it has

9:05an integration with Microsoft boundary

9:08and a GPT model. So in this uh use case

9:11example that I'm going to show you at

9:13least for demo wise is just uh using one

9:17of the GPT models for a demo purposes.

9:20So if you're expecting me to do toggle

9:23with different uh different models then

9:26then I didn't uh made that yet. it's

9:29more like focus a lot on uh dev sec ops

9:32and then if you have questions later uh

9:34feel free to ask it later on at the end

9:37we'll have a a special time at after

9:39that demo so what we're going to I mean

9:43in this uh scenario that we have we do

9:46we do have like we're going to wrap in

9:49our devs sec ops I think most of you are

9:51familiar what it is about it's just like

9:53basically you're injecting security in

9:56your dev ops processes

9:59uh regardless if you're using Azure

10:01DevOps or GitHub or whatever is the uh

10:04tools that you and your team are using

10:07to deploy code to to the environment or

10:10to cloud or to to production. So we're

10:13going to wrap it in with like using

10:15intra ID with arbback roles uh that is

10:18uh intended to protect the identity

10:21regardless if it's a manage identity or

10:23a service principle or identity of the

10:26person that's accessing the application.

10:29Uh the reason why ID identity is number

10:32one because identity is the number one

10:34thing that that is being targeted uh

10:37when it comes to security risk. And then

10:40we're going to also try to to mention or

10:44include Microsoft Defender for cloud. So

10:46the defender for cloud is not just for

10:48Azure Ashure stuff, Ashure resources

10:51that you hosted on Azure. You can

10:53actually uh use it as well regardless if

10:56you're using GitHub for your GitHub

10:58actions or pipelines or you can also use

11:01Azure DevOps for your enterprise uh

11:04deployments uh or release management.

11:07And then there's going to be like

11:09extensions that will be mentioned

11:11depending on what kind of codes that

11:13you're trying to protect uh for code

11:15scanning for example I'm going to share

11:17a few that I have implemented in my demo

11:21and then uh there's uh key vault as well

11:24and manage uh identity uh for that. So

11:30before we start I want to like share a

11:33bit. So that was like the prototype of

11:35example net technologies that are very

11:38close to applications

11:40uh today. Uh so when we talk about

11:44security and also the AI innovation that

11:49we have today uh our applications is not

11:53like the good old days where you have

11:55the monolithic I mean you switch from

11:58monolithic to microervices to serverless

12:02and now they still exist those things uh

12:05we're still having challenges handling

12:07technical depth but now we al have to

12:10add the layer of AI into the

12:13integration. So now we do have uh more

12:16challenges when it comes to uh building

12:19applications regardless if it's .NET or

12:21any other uh languages. And there are

12:25three uh shifts that shows up when AI

12:29features or using MCP server uh tools as

12:35uh as as as part of the integration of

12:39any code base or source code regardless

12:42if it's a new one or it's an existing

12:46source code or applications that are

12:49being modernized or integrated into an

12:53AI kind of solution. So

12:58if you notice, I think I'm guilty myself

13:00as well. Uh I think all of us developers

13:03are trying to use or adopt at least AI

13:06today. And one of the tools that we try

13:08to utilize of course is to do copilot or

13:11pair programming with uh cloud code or

13:15any tools that we have and probably our

13:18companies pro provide it. Of course we

13:20need to use it. Some enterprises are

13:23taking it slow. Some enterprise

13:26enterprises have adopted it that they're

13:29allowing their developers to use AI

13:32tools as their pair programmer.

13:35And regardless of any scenarios or

13:38situation you are into in your project

13:40right now, it is a fact that these three

13:43ships that I'm showing you right now uh

13:45that sometimes you with AI coding with

13:49you, you might have code that you didn't

13:52write because AI or co-pilot suggested

13:56you how to solve it. And that's not a

13:59problem because AI is very smart. It can

14:01out outsmart us as well. But if you

14:04didn't get into the loop of the logical

14:07thinking and uh reviewing that code then

14:11there's a risk that AI took over and if

14:14there is no security inside it or there

14:16wasn't any security devs sec ops

14:19implemented from code to the deployment

14:22to production then we see a possible

14:25risk for that and then now that we have

14:30um MCP servers and AI tools coming in.

14:35We're still adopting of course in the

14:37learning but then we do have a new layer

14:41of attack surface on top of what we

14:44already have before the AI we have to

14:47deal with database in SQL injections. We

14:50have to think how we protect our uh

14:53connection strings configs on uh

14:56configurations sensitive uh data uh out

15:01of the code and make sure that they're

15:03not pushed to a public repository and do

15:06the best practice as pos as much as

15:09possible in the dev sec parts. But now

15:12we also have to have this new layer and

15:14then we have uh wider wider integration

15:18involved right now. a wider uh blast of

15:21radius when it comes to a security. So

15:26uh if a developer or an infra engineer

15:29make a mistake such as like one

15:31misconfigured

15:33information or secret in the

15:37infrastructures code the back end or any

15:40uh nougat packages which is external

15:44that has been implemented in any layers

15:46of your code that can be uh a risk uh as

15:51well.

15:52So I think in all of this like uh all

15:56all of this shift lift uh like uh like

16:00answers I mean shift lift wouldn't be uh

16:03possible unless it is done into uh

16:07practice.

16:09So uh

16:10>> sorry Jonah just to to wrap up my my

16:13brain around what you already said. I

16:16think uh we we have like all the

16:19software engineering practices and then

16:21we are adding an AI layer on top of them

16:23but still we need to make sure that the

16:25AI is sticking to those software

16:27engineering practices and the same thing

16:30applies for security practices right we

16:33had the SQL injection and now we have

16:34prompt injection and then we need like

16:36to be aware of these kind of new

16:39surfaces that are emerging and apply

16:42again like the best security practices

16:44when we are developing the application

16:46Right.

16:47>> Yes. Exactly. So we have the prompt

16:50inject injection uh like I mean before

16:52we only have uh SQL injection and other

16:55stuff right now we have to have new

16:58layers of things we have to learn. I

17:00mean like uh I mean if you're not

17:02working in a security uh as a security

17:05engineer in a project then probably if

17:08you're just a developer you wouldn't

17:09know about all these things unless

17:11you're informed right because in the

17:13good old days as a developer probably

17:15you're still catch up catching up with

17:17AI you're used to oh I'm this one this

17:20this code I'm going to pro I'm going to

17:22write it very well because I know XSQL

17:26injection exists

17:28>> but if you're a developer who's not even

17:30adopted to how AI works or doesn't even

17:33understand it and didn't even know that

17:35prompt injection exists then you

17:37wouldn't even think about writing a good

17:40prompt to avoid it and all these other

17:42practices right uh so that makes that is

17:46uh that's that's very true anything you

17:48want to add in this

17:50>> oh no no just just wanted like to to

17:53review to for my understanding

17:56>> yes and I also want to highlight to

17:58everyone Maybe we can share Shahab and

18:01and us can share also uh I mean you can

18:04also search um you can take a look at

18:07about this like OAPS uh LLM top uh 10 uh

18:12wrist for for this. I mean uh this is a

18:15good security like uh list of things to

18:19think about and I know one of the new uh

18:22new lists item there is like uh attack

18:26services is on MCP and all this prompt

18:29injection uh today. So there's new layer

18:32that we need uh to uh to think about uh

18:36and I myself is actually not just

18:38talking uh talking uh this like for

18:43presentation I am actually dealing with

18:45uh with security remediation all the

18:48time because we're using Microsoft

18:50defender for cloud in our project and we

18:52thought that our application is secure

18:54but there is still the small things list

18:57of things we always have to do to avoid

19:00our application to be uh to be at risk

19:04because of this new layer of attack

19:06surface that probably

19:09uh the applications were not prepared

19:11for before AI evolution has arrived and

19:14I think uh there are many of us that are

19:16still in in the challenge. So uh to move

19:21[snorts] forward

19:23um we're going to we we need to change

19:26our mindset actually that what uh dev

19:30sec ops is really about. I mean before I

19:33mean when I was a developer uh I mean

19:36I'm a developer I could do the coding

19:38and then when I was asked by my client

19:41Jonah do you want to be the lead of the

19:43devs devops team and then of course I

19:47did agree because I I like I like

19:50learning new things. I I like

19:51understanding the flow from code to to

19:54production but I we always see this

19:56misconception of what dev ops is or what

19:59dev secc ops is. uh for me I mean as I I

20:03wrote here DevSec Ops it's uh it's it

20:07it's it's it tool it's how our teams

20:12work in our enterprise in our projects.

20:16So to me the the the three top three

20:19principles that I think uh I think all

20:22of us needs to shift when it comes to

20:24dev sec ops that it's not just the

20:26responsibility of a security engineer to

20:29secure the applications. It's everyone's

20:31responsibility. It's a shared uh

20:34responsibility uh from code uh to CI/CD

20:38pipelines to like quality assurance even

20:41when you're monitoring and doing

20:43reliability uh like preparation and

20:46governance into uh when it's in

20:49production. So both shift and right

20:52shift left not just shift left now but

20:55it's also shifting shifting uh right

20:58meaning catch the issues that you may

21:00face or security risk early uh as much

21:03as possible like in your uh IDE when

21:06you're coding with copilot uh when you

21:09are doing pull requests uh there are a

21:12lot of tools at GitHub right now that

21:14allows you to do code scanning and it's

21:16part of my demo uh by the way but there

21:19there There are tools already in the CI

21:22that can prevent or stop any risk of

21:26security threat from the code before it

21:28even gets to production. And then of

21:31course with the help of Microsoft

21:33Defender for cloud you can also like

21:36keep watching the production uh

21:38applications by remediating what are

21:42already are at risk and uh the tool for

21:45that on Azure is uh very good and if

21:48possible uh we do have AI now why not

21:50use AI also to build something that can

21:53automate uh the things that you want to

21:56protect. So automation of the gates. So

21:59if it uh if it's possible to build an

22:02agent that helps you with the security

22:05whatever is the the gates that you have

22:07to secure your pipelines uh utilize

22:10utilize that but the point I'm sharing

22:13is that dev sec ops is a teamwork uh

22:16just like any in anything in any project

22:19because if if we point fingers at point

22:23fingers that it's just a security

22:25engineer's job then I don't think I

22:28don't think it will be a successful kind

22:30of security we're doing in our

22:32applications.

22:34>> This is very interesting today.

22:36>> Yeah. What's your input on that?

22:38[laughter]

22:38>> Like a couple of days ago, I I read like

22:41in one product that now building is a

22:43team work and I was like it was always a

22:46teamwork. It's not just like for the AI

22:48age. But yeah.

22:49>> Yes. And I I think also I think uh it's

22:52not just actually the engineering team.

22:54It's not just the developer, the DevOps

22:56engineer or infrastructure platform

22:58engineers and security team and the

23:01admins but I think it's also good I

23:04think uh there's also uh a non-technical

23:07perspective here. We also need to

23:09involve uh the business team which is

23:12often uh has a different perspective

23:15when it comes to application right uh

23:18they the business team only wants

23:20features but we the the teams that are

23:24really handson they know what are the

23:27possible risk but it when you are able

23:29to communicate to everybody

23:33technical or non-technical kind of teams

23:36that security is a shared responsibility

23:40then I think it will be clear but I

23:43don't know how is it in your uh

23:44perspective or your project um

23:46>> absolutely agree like we need to involve

23:48like like everyone is part of the team

23:51it's not like like the technical and

23:53nontechnical separation is kind of like

23:55to me looks technical or mechanical

23:58>> but it's like the business people and

24:00like we have like this

24:02>> collaborative modeling that I I really

24:04like like which is the goal is like to

24:07involve everyone in in the understanding

24:10of what we are about to build and what

24:12are the the the challenges there. So I I

24:17consider also like uh like um you know

24:20we we we I mean I I've been in the

24:23consulting industry and I see different

24:26layers in different projects and also

24:28different kind of like communication uh

24:31and I think I mean it's different when

24:33you're like learning from a conference

24:35learning from from a community it's good

24:37we're learning the basic but you really

24:39learn a lot for in action when you do it

24:42in a real projects I think you can also

24:44relate. I can relate. But uh one of the

24:47things that I I do I do see and in my

24:51perspective [clears throat]

24:52is that I consider security risk uh as

24:57like kind of like a priority in a way

24:59that it is also as important as

25:02technical depth something deprecated and

25:05if you don't do it then this

25:07applications will stop. But let's just

25:09say if your uh SSO login or your login

25:12feature in your app is is at risk for

25:15security and it's live in production,

25:18there's a risk also that the identity of

25:21your users are being threatened and if

25:23your uh entire website is getting hacked

25:27because it there's no dev sec ops

25:29implemented to it then everything will

25:32be affected including the business

25:34aspect of it. So I think it's very

25:36important.

25:37Yeah, absolutely.

25:39>> Yeah. So, let's proceed. I want to sh I

25:42have a few things more things. It's very

25:43interesting discussion. So, that's

25:45that's good that you are [laughter]

25:48joining in. So, I'm not uh I'm not

25:50alone.

25:52Okay. Yes, that's that's a great idea.

25:54Okay. So, as in continuation also of

25:58what we're talking about uh you know

26:00just like in in in application

26:04development, I'm I'm a developer myself

26:06also. I'm familiar with like you do the

26:08coding you you just dep you push it

26:11there but we are in a different layer

26:13now we're talking about uh security and

26:16if we think about security perspective

26:18at every stage of uh life cycle of uh of

26:23it. So usually you have the same way

26:27like you do the dev sec obviously you

26:29have to to plan uh the threat model you

26:32have the design review you have your

26:34code you you you

26:37have your security can be in uh in in

26:40the IDE itself uh when you code it and

26:43push it the CI/CD

26:46it can be uh a threat protection also

26:49using Microsoft uh defender for cloud uh

26:53that gives us the the information what

26:56needs to be handled and then also during

26:59the build uh you can do SAS uh secret

27:03scan uh when when that is on the build

27:06process and then uh test uh DAS and then

27:11container scan infrastructures code

27:13scanning and then when it comes to

27:15deployment we also have to check that

27:18the manage identity that you're using

27:20for your serviceto-service integration

27:22or service uh service identities that

27:26you have has this rolling updates uh

27:28from time to time uh as well. How are

27:30you handling tokens if it has a service

27:33principle tokens or client uh tokens

27:36that needs to be recycled? So sometimes

27:39you do a forever client token and you

27:42didn't know that that token is already

27:45at risk. So sometimes it's good to have

27:47a rolling updates and using secondary

27:50keys or primary keys option kind of uh

27:54strategy as well and then also uh

27:57operation uh part which is includes the

27:59posture management and that is actually

28:02a continuous loop in the cycle. So if

28:05you take a look at the dev sec ops like

28:08symbol, it's actually a loop uh in all

28:11of this cycle, but we're injecting or in

28:14integrating security inside it just like

28:17the normal application. But this time we

28:19need to be mindful of like any

28:22integration related to AI can also needs

28:25to be uh considered uh as well.

28:29So, so when it comes to uh AI and MCP,

28:35so we do have uh different tools that we

28:40can uh utilize where we can do shift uh

28:44lift. So when it comes to IDE for

28:47example like regardless if you're using

28:49BS code uh you can consider using like

28:54copilot GitHub copilot in chat to do a

28:57security like check on your entire

29:00source source code like depending of

29:02course you need to be the leader and the

29:04pilot of your prompting but uh you can

29:08use actually AI within your IDE to to to

29:12make sure to catch any security issues

29:16before you commit that to your feature

29:19branch or your merge and do a PR

29:21request. Um, and then make sure you can

29:24utilize like Azure function skills MCP

29:27servers that's available uh for you

29:29already in the local environment using

29:32your IDE and then of course when you

29:34push the code there might be few things

29:36that AI or copilot or you have missed.

29:40So do another layer uh do the PR review

29:44and during the PR review process uh

29:46there's the copilot autofix uh there's

29:49codeql uh in github there's dependabot

29:53and then if you're using uh uh ashure

29:57devops uh enterprise ashure devops

30:00instead of github they even though g uh

30:03the github advanced security is kind of

30:05like already default and built in into

30:09github you can actually integrate that

30:12feature into your Azure DevOps uh as

30:15well. So uh do that also in your PR and

30:19then when it comes to pipeline uh

30:21depending on where you are uh hosting it

30:25there's actually Microsoft uh security

30:27devops there's

30:30uh the check off uh which is part

30:32actually of my demo. I'm going to show

30:34you how at least it looks in the YAML uh

30:37pipeline and then when it's in

30:39production uh Microsoft Defender for

30:42Cloud Security Copilot uh and then the

30:45Foundry IQ as well or use AI uh to also

30:50help uh help you uh with that when it

30:53comes to security and having an

30:56oversight of your uh platform.

31:00So uh defender for cloud

31:04uh this is actually a new feature that

31:07were announced uh in May. Uh so if you

31:12have Azure for example or you already

31:14have a Microsoft defender for cloud you

31:16can actually use uh Azure DevOps

31:20connector or GitHub uh connector uh to

31:24set it up so that you can see the the

31:28the post the existing status of this

31:32environment in a security uh

31:35perspective. So I'm going to like show

31:37at least how it looks on Asher where you

31:41can build that connector. Of course

31:43there are step by step uh for that. So

31:46that would be good. And I think it's

31:49time for me to do a bit of demo soon. So

31:52what we're going to do is I'm going to

31:54show you at least how how the how it

31:58looks in a in a code and how I you can

32:01implement different kinds of security

32:06um like what do you call that a gates

32:09within your pipeline uh in in in your

32:13application and the application was the

32:15one that I shared to you uh earlier. So

32:18let me just uh switch screens here.

32:22Stop screen. Present a new one.

32:26Uh let me do the this first.

32:34>> So so far we we have like tools and

32:37capabilities to check for various

32:39security issues for different target

32:42levels, right? where like scanning for

32:46uh for I don't know for example the

32:47connection string is not like pushed to

32:49our git repository or or at runtime we

32:53have like the Microsoft defender to

32:55check for security problems that might

32:56be in the application

32:59>> yes that's right and uh yeah and I think

33:03I think moose I mean I don't know I mean

33:05in your project you use Microsoft

33:06defender for cloud

33:10>> that's a very good question but u I like

33:13discussing

33:14>> [laughter]

33:15>> like I'm I'm having a conversation.

33:18>> Yeah. Yeah. No, no, that's a very good

33:20question. But but I don't know actually

33:22what the security engineering team is

33:24doing there. Uh

33:25>> yes, you need to have the shared

33:27responsibility more. You can tell them

33:30>> yes [laughter]

33:32Monday questions and responsible like go

33:34and

33:35>> save it for Monday because you learned

33:36something new from Jonah on on the user

33:39group. Anyway, um so uh I want to share

33:45uh at least an example Ashure DevSec Ops

33:48demo I have. So this is uh I I am I'm

33:51skipping the live demo because there's a

33:53lot of things I have a dry I did a dry

33:56run uh where I could plant issues and

33:59things but I can try that. Uh so what

34:02I'm trying to do actually is I'm going

34:04to just give you a tour of the project

34:07how it looks and how most especially the

34:10YAML pipeline is is is structured to

34:14protect uh the code both infer wise

34:19front end and back end. And then how are

34:22the possibilities within the code like

34:25which part of the code can this Ashure

34:28functions that uses MCP

34:31uh and C can be a risk and how the tool

34:36uh that I have implemented here will

34:39stop uh stop that if there's a risk

34:42within uh the pipeline. So I'm not going

34:45to do the full demo but uh I if you want

34:47a copy of the the entire like YAML that

34:50I did I can uh share the repo later on

34:54but basically uh the flow the the

34:57example that I have is uh an app uh so I

35:02have my infrastructures code I have my

35:05source code uh use ACD here Ashure

35:08developer CLI uh to deploy this to Azure

35:11so I love it uh it's easy But you see

35:14here that in my source code I do have a

35:18front end which is a blazer app that

35:22probably is non none of the things that

35:25we need to go through because we're

35:27focusing on how we are securing the

35:29applica securing the applications right

35:32and then here we do have uh our uh

35:36functions aure functions app that has an

35:40integration to

35:43Microsoft

35:46foundry.

35:47So here uh we have uh so you know AI

35:50enabled app because uh there is foundry

35:53in here. So basically uh it has let's

35:57just say I have an application and I

35:58created a chat support for it. That's

36:00how you would see it in the big picture.

36:03And the front end has a chat client that

36:06has an integration to AI like for now it

36:10doesn't have real data but it's more

36:12like chatting to to AI as it's uh from

36:15end and then there are different risks

36:18where a developer can probably make a

36:20mistake and push the code uh

36:24accidentally

36:26and take uh I mean give a security risk

36:29to a production application if there's

36:32no dev tech ops like strategies

36:35implemented within the pipelines uh

36:37already. So one example that I see here,

36:40let's just say if you're if a developer

36:44kind of maybe a junior one or not using

36:48AI or AI is also stupid [laughter]

36:51model then uh there's a big risk that uh

36:54one risk like what you see here in line

36:5651 is the foundry API key. uh if you're

37:00if you're tackless as a developer, you

37:02can actually hardcode that key and that

37:05can be already uh a risk. So there is a

37:08of course best coding practices uh to

37:12secure whatever is uh secret in your uh

37:16application during the local development

37:18but uh uh one of the best practice I

37:21would recommend is using ashure key

37:23vault and uh coding it properly.

37:27Um, another way that a front end for

37:30example can also be at risk is like

37:33components such as Nougat packages for

37:36like front end uh like frameworks. So if

37:40you have a Nougat packages in the front

37:42end that probably are not supported or

37:47outdated uh somewhere uh that can be uh

37:51a risk uh as well. So what let's just

37:55say this one. So if you have package

38:00references that probably are at risk

38:02that can also be uh uh a threat somehow

38:06like outdated

38:07uh and those outdated can be uh can can

38:11uh can be scanned by our uh our tool.

38:17And then how does the infrastructure as

38:20code

38:21looks like? At least you see how the

38:24application

38:26is.

38:29So the application, let me see if I can

38:31zoom.

38:33So if you see here, so we have a web

38:36app. It has a a front end which is the

38:41chatbot. You can say chatbot that has

38:45integration with Microsoft Foundry. It

38:47has a back end and the function itself

38:50has the the the necessary uh ashure

38:53resources such as like hosting plan the

38:56blob the storage.

39:02It has app insights. uh it has an

39:04integration to foundry and the uh UI

39:09uh has a role of open AI user role and

39:13then it has uh some model and then

39:18and an

39:21identity here. So it's very uh very

39:24simple uh very simple apps in a way that

39:28for example on the infra code here

39:38uh let me see where can uh

39:43uh

39:46uh let's just say bicep main that bicep

39:50is

39:52is good but where can a DevOps engineer

39:55writing bicep module can give risk for

40:00security so one of the things that I see

40:03that has a risk like for example when

40:05you're creating a storage account

40:09usually if you use an ACD

40:12I mean if you're new then you do you

40:14don't really check on this specific

40:16details by default because it's just

40:18template but if you're really keen about

40:20the security and you're doing it in a

40:22real enterprise or production

40:24application, you would be mindful on

40:27this line or settings or component or

40:30properties for the storage account in

40:32line 37. So for example, you would if

40:35you want to I mean for demo purposes uh

40:39of course if I want to break it I can

40:41change it to like true allow block

40:44public access allow blob public access.

40:48If this is true then it is a security

40:52risk because you shouldn't allow your

40:54storage blob to be accessible to public

40:56it should be always uh false. And then

41:00in the network part if you want to like

41:04um if you want to tighten like your

41:08network settings here as well if you you

41:11make a mistake of not allowing or

41:13denying it then it could be uh a problem

41:16uh as well. Do you had something to say?

41:19>> No, no, I'm just listening.

41:21>> Yes. I hope we're the time is still

41:24okay.

41:25>> Uh yeah, we are like 40 minutes into the

41:28session. So we have like 20 25 minutes.

41:30>> Okay, that's that's fine. I'm think I'm

41:32almost done. I'm just like showing uh

41:34actually the possible risk here for like

41:38issues like I'm looking at the

41:40infrastructures code. I'm not sure if

41:42you're like do you do infra code in your

41:44work uh job?

41:47Sorry.

41:48>> Do you do a lot of infrastructures code

41:50in your line of work?

41:51>> I used to write like infrastructure code

41:54as well, but uh currently I'm not doing

41:56that but our teams like are writing a

41:59lot of like also the infrastructure

42:01code.

42:02>> Uh they're using but they're not using

42:04like bicep per se but other equivalent

42:08tools that that are in the market like

42:10depending on

42:11>> Yes.

42:12So what I'm actually sharing here to our

42:14audience or to everybody as a learning

42:16session is that like I mean I mean this

42:19is just one one resource that we're

42:21trying to like look at. It's just like

42:24when regardless if you're using bicev or

42:26terraform

42:28uh sometimes there are tools that are

42:29hey you can just say hey let AI do the

42:32templating for bicep or terraform but

42:36there are I mean AI gets the information

42:39from the data across the world right and

42:43there might be a risk that the default

42:45settings for example the allow blob

42:47access storage is not set to false which

42:50is the best practice and probably that

42:53is missed. And if you're not mindful

42:56about a few things, you don't really

42:58need to know all these things. But if

43:00you don't have a pipeline or or

43:03automation that checks on this small

43:06errors, then it could be uh a risk as

43:09well. And it can happen in uh in any

43:12kind of code like infrastructures code.

43:15It can be found in the the new get and

43:18everywhere

43:19>> like like I I have a question regarding

43:22for example

43:22>> yeah please to I like discussion go

43:25ahead

43:27>> all good regarding this specific example

43:30like to not allowing like public access

43:32to blobs right this is a setting you are

43:35setting to false in yeah your bicep

43:37files

43:38>> is if if by accident like someone set

43:42that to true like to to allow public

43:44access. Where do we catch this? Because

43:47I could use bicep. I could use

43:48terraform. I could use Palumi. And these

43:50days I could also use Azure uh sorry I

43:53could use also the Aspire right to to to

43:56be able also like to deploy like to to

43:58production.

44:01>> Yes, you can actually see this. I mean

44:04you're asking where is it caught in

44:06terms of security? Is it like in your

44:08pipeline or is it like in after the

44:11deployment and then it checks like the

44:13resources like what the settings are?

44:15>> Yeah, it will be in the pipeline

44:17actually. So basically this uh this is a

44:19code demo for now but I do have one more

44:22I'm going to show. So this is the front

44:23end. I hope you see that. So this is the

44:26front end. Let's just say this is Jonas

44:28uh Jonas like AI app where it has a

44:33blazer simple one and that's the front

44:35end. I don't it's just a simple one

44:37because uh we're not focusing on the

44:39front end now but I want to show like

44:41for example

44:43an introduction before I answer the the

44:46full picture. So here is the the we have

44:49the infrastructure as code right and in

44:52the infrastructure as code I mean

44:54currently it's built properly uh and

44:57what we're going to try to do in the

44:58demo is we're going to break that it

45:01won't go through because Jonah or a a

45:05developer that doesn't know so much

45:06about how things work because he or she

45:09is just dependent on AI or prompt

45:12engineering and not really like thinking

45:15about best practice. is we're going to

45:17try to flip this and

45:21break this like instead instead of this

45:24is false, we're going to set it as true

45:26and we're going to the repo and it

45:27should never push through or go through.

45:29It should break and it shouldn't even

45:31build. Um, and it should show in our

45:34DevOps pipeline. But before we do that,

45:36I want to see the big picture of this

45:39like so uh so let's just say I'm showing

45:42my Asher subscription ID, but it's okay.

45:45Let me just refresh one moment.

45:52So I have this resource group uh here.

45:54It it shows anyway but that's fine. Uh

45:56so um so we have let me zoom. So here

46:01you see that I have my back end which is

46:03the function app. Uh this is my manage

46:06identity the entire like infrastructure

46:09uh that I showed uh earlier. There's

46:12even an event grid here because it's a

46:14it's there's an integration for that.

46:17And then uh in foundry just to highlight

46:20if you really want to like um like like

46:25do things in the foundry way or AI way

46:28you can uh utilize of course going and

46:32do that for Microsoft foundry but uh

46:35since we're focusing because in foundry

46:37you can I mean the AI layer part I mean

46:39we're talking about devs sec ops in the

46:41code but if you also want your AI to be

46:46very like um very uh smart as well is

46:51you can actually use uh guard rails uh

46:54in in Microsoft Foundry as well. So let

46:56me just go pull that up. I have one

47:00example actually here.

47:04It's not the one that I have for this

47:07specific one, but I want to show that if

47:10you also want your AI to be protected or

47:13you follow compliance, uh you can use

47:16guard rail uh guard rails features of

47:20Microsoft Foundry and uh do some

47:24evaluations uh in terms of protecting

47:26the the AI or Foundry part. But to

47:30answer your questions, this is the

47:32pipeline. Uh so this is the Ashure

47:35DevOps

47:36and if you see

47:40I do have uh the repository here

47:44just exactly as what you you see in the

47:49the VS code and I have the infra I have

47:54the source code and uh and everything

47:58but in my pipeline for

48:02for uh for this uh integration where I

48:06have everything in one file. I I

48:09everything looks good. But if we go

48:12inside here,

48:15I do actually have some kind of like

48:19different

48:21like different ways to check. Uh so

48:25maybe it's better to show it here in the

48:28YAML file. So in my project

48:32I do have Ashure pipelines but already

48:36in my YAML file I do have several uh

48:38stages. So this is not the classic

48:42variation. So this YAML pipeline is not

48:45an ordinary pipeline that only pushes

48:48the code directly.

48:51It does actually have security gates. So

48:53aside from the schedule that you see

48:55here in line 16. So it has a monthly

48:58weekly scan. It also

49:02has

49:04um so after the PR goes goes through so

49:07it's going to do security scan after uh

49:11the PR has been approved and even it

49:13gets built. So there are different

49:15stages of the security scan. So the

49:18first job of the security scan is to

49:20scan for secrets using git gitlicks.

49:24So here you do see uh a reference

49:26there's a C a script that curls to that

49:30uh that tool and then it's going to run

49:34uh and it will uh check if there are any

49:38secrets that are being leaked on this uh

49:41PR merge or push of the code

49:44>> and then it's going to do a check

49:45because we have everything in one right

49:47it depends on the structure of the repo

49:50for for my project for example we have

49:52one repo for the back end one repo for

49:55the front end and if it's microservices

49:57there are different repos but for this

49:59code demo I have one repository I have

50:03infrastructures code I have front end I

50:06have back end so I have to do several

50:08mult uh security scan within this YAML

50:11pipeline so uh I have another job I mean

50:14I can edit this as much as I want and

50:17set conditions in the YAML file but I

50:19also have an a in uh infrastructure code

50:23scan which scans my uh bicep. So what it

50:27does is it's going to run uh the script

50:30and it's going to try to using the tool

50:32check off which is uh a third party tool

50:35that you can take a look as well. Uh

50:38it's going to check the infrastructure

50:40as code if there's any risk for uh

50:43security here as well. And then if you

50:47want to have another layer as well uh

50:49which is the code QL and secret scan and

50:52ASC. I mean I over I'm overprotecting my

50:55pipeline by the way for security

50:57purposes but you don't need to do all.

51:00[laughter]

51:01Go ahead.

51:03>> No I think that's a good practice like

51:05to do that.

51:06>> Yeah. Yeah. I know. But uh I want to

51:08show to everybody that you can utilize

51:11uh not just the Microsoft defender for

51:14cloud uh which has a feature of codeql

51:17sec secret scan and infrastructures code

51:20but you can also utilize other tools. So

51:22you're not just stuck to the default

51:25Microsoft products as well. There's a uh

51:27an open-source secret scan uh that you

51:31can also utilize maybe cheaper and then

51:34so I have three. I have the check off. I

51:37have the uh the Microsoft security for

51:39DevOps which has both the code secret

51:42scan uh for for that. But there are

51:45other things also that you can utilize

51:48like cred scan. There's a lot of tools

51:51actually that you can do but I'm only

51:54adding uh four uh three of them uh at

51:58least uh for for now. the secret scan

52:00gate links check off and then uh

52:03Microsoft defender for cloud for devops

52:07and then you might be wondering like

52:09Jonah how did you kind of like make sure

52:13that it will work in your Azure DevOps

52:17uh pipeline because for example like the

52:20non-Microsoft ones such as the gitlicks

52:23and the check off they are not Microsoft

52:27they're not built in for Ashure DevOps,

52:30right? So, in order for you to actually

52:32have your pipeline or YAML file to work,

52:36you need to have the extension actually.

52:38So, you need to ask uh if you're not the

52:41organization owner

52:43of your Ashure DevOps, probably you need

52:47to ask that person to go inside the

52:50organization settings. So, since I'm the

52:52the owner of my organization, I'm going

52:55to go inside my organization settings

53:00and also make sure that I have the

53:03extensions. So, the extension that you

53:06need for everything to work at least in

53:08this pipeline like security scans that I

53:11have built in in my demo, the YAML file

53:14for this uh application, it needs to

53:17have the uh Microsoft security devops.

53:21So if you want to know where it is, you

53:24can actually go to the marketplace.

53:28So So if you're familiar with ash,

53:31Ashure DevOps or GitHub, there are

53:34marketplaces that you can integrate. So

53:37this is the Microsoft uh security devops

53:40that you can you can add and then

53:43there's a documentation and guide

53:45actually how you can add it in your YAML

53:48pipelines and even do a publish option

53:52to do the logs cost analysis logs on

53:55what it found uh it found out during uh

53:59during the scan. But the most important

54:01thing is you need to have the extensions

54:03that are required uh for this. And how

54:09does it look like? Let's just say if I

54:12accidentally

54:15made changes to this. Let's see. I hope

54:18my my pipeline uh is going to because I

54:21did a test run on this before

54:23presentation. Otherwise, I have at least

54:25the one that worked before.

54:28So, what I'm going to do is I'm going to

54:31try to

54:34to make it fail

54:37and see if it it will detect that I made

54:40a mistake. So, I'm going to go ahead uh

54:44where is the foundry client?

54:47I think we have

54:50one one that

54:52[snorts] for the intro

54:55where

54:56I did.

55:00I want to flip it to true.

55:04Allow shared uh access.

55:07>> I I think it's line 37.

55:09>> Uh Titan to deny.

55:14>> Yeah, it did that already. So, it did

55:16that already. So what I'm going to do

55:19uh fake uh demo only

55:24open code for security

55:28wrist by adding

55:32by uh setting

55:35to true

55:38instead of false.

55:41Not really good

55:44but just a test. Okay, let's see if my

55:48pipeline runs.

55:50So, I'm going to sync.

55:59So, I

56:01have my YAML like pipelines integrated

56:04already. Let's go on my

56:08[snorts] project and see. I hope it

56:10triggers. uh otherwise like I I can show

56:13you the previous uh thing I had to do.

56:16Let's see.

56:17>> So we expect also like some misbehavior

56:19as well. So

56:23[laughter]

56:24>> yeah, I know. Uh but it should push

56:27something at least.

56:29It's still thinking.

56:33Did it commit?

56:35Let's see.

56:38[snorts]

56:39You see two hours ago I did a run on

56:41this one. So it did go through but if

56:46not then I have actually a backup how it

56:48looks at least. It

56:51>> still thinking.

56:53>> Mhm.

56:53>> H that takes time. But anyway while it's

56:56thinking and we're waiting for uh for

56:58the pipeline to build. I do have

57:00actually how it looks because I did test

57:03this uh earlier. So what I did is like

57:06uh there is a break. it's going to break

57:08somehow here where I have an example

57:14uh this one.

57:16>> So what I did is I did false break uh

57:19the pipeline where let's just say I I

57:22had a lot of security risk on my commit.

57:25So what it does is it's going to like

57:28kind of like tell you that hey your uh

57:32okay all went through like secret

57:34scanning you don't have a leak all went

57:37well uh you have the

57:41uh infrastructure scanned that looked

57:44well but when it comes to like container

57:47because I also added a feature where uh

57:50if you have a container in your because

57:51I do have container in this uh this

57:54source code I forgot to show you how the

57:56tri scan but try scan does the scanning

57:59if you have a container apps or

58:01containerization

58:02then it did actually tell you that uh

58:06that there's uh a risk that was found uh

58:11in in the uh in the container and it

58:15will not uh go through uh in in building

58:20uh the code uh itself and same goes with

58:24uh every step that you set up. But if

58:26you want if you don't want it to stop,

58:28then you can actually just like make

58:30conditions within your uh within your

58:32YAML uh file. So I think that's uh

58:36that's it. I have at least to show there

58:38are many ways to do that, but the main

58:40thing that I want to highlight is this

58:44the tools that we that we have. So let

58:48me just continue sharing my PowerPoint

58:50soon so we can have more questions and

58:52discussions when I'm almost done. Uh and

58:56conclusion of course um we have few

59:00almost done.

59:02So

59:04>> so that was the the demo. [laughter]

59:07I hope it's a bit clear at least I was

59:09toggling in between but that's how it

59:11looks like when you're working uh in

59:13action. Right. So, so what I'm trying to

59:16to show right now uh when it comes to

59:20like uh what we've learned uh so far is

59:23that uh is that it is important uh for

59:26us to like I mean you have this mental

59:30model of how at least

59:32um the different phases of dev sec ops

59:35uh it is a pra practice it is a shared

59:38responsibility

59:40um also there are different tools tools

59:44that you can use. You don't have to use

59:46all of them, but use the ones that you

59:48really need to protect uh if you don't

59:51have uh a layer uh for that. And also uh

59:56there's copilot Microsoft Defender for

59:58cloud uh as well. And then if you want a

1:00:02copy of this repo, you can also uh do

1:00:05that. But uh one more thing I I also

1:00:08want to like mention I I don't have to

1:00:10show but if you go to Microsoft Defender

1:00:12for cloud on Azure and then look for uh

1:00:16DevOps security

1:00:18maybe I should do that. Let me share

1:00:19again one more time. I think it's good

1:00:22to have uh one more clear like for

1:00:25people.

1:00:26>> Yeah I think so instead of just like

1:00:28talking and showing. So I have one thing

1:00:30I I missed actually sharing. So, I'm

1:00:33doing a

1:00:35I want to show you also. I wonder what

1:00:38happened to my pipeline because it

1:00:40didn't push it. Um,

1:00:43I'll take a look at it later, but I did

1:00:45show that it should fail. But what I

1:00:47want to show you is that so this is your

1:00:50Asher, right? But if you have Microsoft

1:00:53Defender for Cloud

1:00:57and Ashure, I'm just going to show you.

1:01:00>> Mhm.

1:01:02So there are different ways how you do

1:01:05the defend use defender for cloud right

1:01:07I mean this is like my my my

1:01:11personal one [laughter]

1:01:13but if in the real uh enterprise

1:01:15scenarios you do have your security

1:01:17posture here you have your ashure

1:01:19subscription but focusing only on the

1:01:22security part with cloud security is

1:01:24huge uh you need to have network

1:01:27security AI security this is also

1:01:30probably good uh to check uh so if you

1:01:33have sensitive data um this is also like

1:01:37very good to utilize AI discovery but

1:01:41talking about dev ops since we're doing

1:01:43devs sec ops if you want to so if you

1:01:47notice here I have integrated my ashure

1:01:51uh dev ops uh with uh Microsoft defender

1:01:57for cloud so you do see here that I

1:02:00don't have a very high security

1:02:02recommendations

1:02:04uh and it's it has uh an agentless scan

1:02:08protection. So all of my repos in GitHub

1:02:13are turned on. Meaning as long as I uh

1:02:17because of the connector to GitHub, I'm

1:02:21able to see the overall perspective of

1:02:24how my uh repositories uh looks like and

1:02:29I can also see my recommendations. For

1:02:31now, it's low, but if I get a high, then

1:02:34it's worth uh grabbing an an attention.

1:02:37So currently have GitHub integration but

1:02:40if you want to for example integrate

1:02:42Azure DevOps

1:02:44uh into your uh the uh Microsoft

1:02:48Defender for cloud to have this overall

1:02:50picture. You can actually use the that

1:02:53connector name and then uh set it up uh

1:02:56yourself here as well. So you have the

1:02:58overview just like how you you evaluate

1:03:01the risk for your uh resources within

1:03:04Ashure. And then you can set up security

1:03:06alerts. You can uh uh do workbooks and

1:03:10have uh a full picture of how uh it will

1:03:14look like uh in your uh resources. So

1:03:17here for example, I have a repo in

1:03:19GitHub and it's telling me it's low

1:03:22because it says that your GitHub repo

1:03:25doesn't have dependabot scanning uh

1:03:27enabled. So that's a low risk. But if it

1:03:30had more then it will uh give me and

1:03:33tell me that. And this is very good if

1:03:35you have a lot of projects uh or

1:03:37repositories in an enterprise level. For

1:03:40me I'm not an inter I mean I'm using my

1:03:43uh my ashure or defender for cloud. This

1:03:45is just for demo. But if I I worked with

1:03:47the real ones then it's a different a

1:03:50different case. So I'll stop sharing now

1:03:52and just finalize this up. So I'm not

1:03:55eating much of your time because

1:03:57probably dinner time for for many. So

1:04:01>> or breakfast time.

1:04:03>> Breakfast time. Yes. Yeah. For me

1:04:05dinner. And also for you. [laughter] But

1:04:07breakfast I hope you eat eggs. I I like

1:04:10eating eggs. Uh good good protein

1:04:13uh for that. So that's uh that's all I

1:04:16actually have to to share. Uh so I want

1:04:20to like share also that I have my book.

1:04:22If you're new to Azure, feel free to

1:04:24scan the QR code or go to this website

1:04:26learning microsoftasure.com.

1:04:29I'm still writing the second edition and

1:04:31if you want to read it or you want to be

1:04:33the early reader, I can acknowledge you.

1:04:36Feel free to just like uh reach out to

1:04:38me. If the QR code doesn't work, uh

1:04:42probably it I I share a lot of QR codes,

1:04:46but you can trust me that it's not a

1:04:49a spam QR code because you need to be

1:04:51careful what QR code you scan, but that

1:04:53one is from me and not uh something

1:04:56fishy fishy. [laughter]

1:04:57So uh if you want to access my learning

1:05:00course as well because I do share about

1:05:03how you can you can develop uh AI agents

1:05:07using Ashure or Ashure MCP Ashure

1:05:10functions MCP tool. So I built a course

1:05:13with uh LinkedIn. So, I think this QR

1:05:17code will direct you to access my course

1:05:20for free without signing up for a

1:05:23LinkedIn premium because LinkedIn

1:05:24premium I think you have to pay like 300

1:05:27or 400 uh Swedish crowns to to get their

1:05:31learning courses. But this one, if

1:05:33you're the author, then I could share a

1:05:35QR code to those uh that wants it for

1:05:38for free. But other than that, I think

1:05:41that's all I I have learning resources

1:05:44to share, but I think it's it's just

1:05:46good to just go to Microsoft learn as uh

1:05:50as your like like top level encyclopedia

1:05:53of everything Ashure or everything uh

1:05:56security. So just use Microsoft learn

1:05:59and I highly recommend you to check out

1:06:02also security related topics regardless

1:06:05if you're a developer, DevOps or you're

1:06:07an AI engineer. It's very relevant that

1:06:09you know how security works as well. I'm

1:06:12learning uh even though uh I use it

1:06:15daytoday there's so much to learn but

1:06:17other than that thank you so much uh for

1:06:19your time uh say tak in Swedish salamat

1:06:23because I'm from Philippines and thank

1:06:25you and I'm welcomed for any questions

1:06:28uh from you also shab if there's any and

1:06:31also from our audience um feel free to

1:06:34reach out uh on LinkedIn and also an ex

1:06:37and also email me at jonah jonah

1:06:39andersontech if you want to discuss or

1:06:42need help with your projects because I'm

1:06:44also a consultant now. So you can also

1:06:46hire me. [laughter]

1:06:48>> Yeah,

1:06:48>> perfect.

1:06:49>> That's all. Thank you.

1:06:51>> Uh I don't see any question in the in

1:06:53the comment section for now. Uh thanks

1:06:56again Jonah for sharing uh all this

1:06:58insightful uh knowledge with us. Uh I

1:07:01hope uh we are taking security more

1:07:04serious uh on our day-to-day job like on

1:07:06every day a little bit about it like

1:07:09>> maybe we need to use more something more

1:07:11secure uh in every

1:07:13>> how is it going in your project so far

1:07:15like do you do you feel like after

1:07:17reading or learning from my session do

1:07:20you think that your organization that

1:07:22you work for are there

1:07:24>> uh I think they are already there like

1:07:26they're already like most of the most of

1:07:29the uh the the things are also like

1:07:32developers on day-to-day they already

1:07:34like uh using Azure key and uh identity

1:07:38like managed identities and all of those

1:07:40things in in in every project that needs

1:07:43like configurations or secrets also like

1:07:46the pipelines and everything is over

1:07:47managed identities

1:07:49>> uh so uh like from developer perspective

1:07:52everyone is there but I'm pretty much

1:07:53sure like the infrastructure team and

1:07:55the platform engineering and because we

1:07:57have like all all all the things in

1:07:59place and we need to make sure that

1:08:01we're not exposing but every day there's

1:08:04new things that are coming up uh whether

1:08:06it's a threat or whether it's a best

1:08:08practice so we need all to to keep

1:08:11learning.

1:08:12>> Yeah, exactly. And I'm glad I could

1:08:14share what I know so far. I'm not like a

1:08:17expert security engineer. There must be

1:08:20some other people that are good at that.

1:08:22But I do know that the tools at least

1:08:26that we need to think about when it

1:08:27comes to like working with uh AI and

1:08:31utilize I highly recommend Microsoft

1:08:33Defender for cloud because they have uh

1:08:35cloud security protection for different

1:08:38kinds of res resources including DevOps

1:08:41and protecting your data and AI as well

1:08:44if you have it on Azure.

1:08:45>> Yep. Perfect. Uh there's another

1:08:47question popping up. Uh so I think uh

1:08:50that's it uh for this evening, morning,

1:08:53afternoon, wherever you are in this blue

1:08:55planet. Wish you all good things and

1:08:58thanks for joining us.

1:09:00>> Yes. And thank you Shahaba for for

1:09:02having me. It's been finally finally we

1:09:04made it. Our honor.

1:09:06>> Thanks for inviting me.

Recently added transcripts

Browse the whole transcript library

This transcript was generated from the captions YouTube publishes for this video. Get the transcript of any YouTube video atfreeyoutubetranscribe.com, free, unlimited, no sign-up.