Full transcript
0:00Heat.
0:17[music]
0:20Heat.
0:25Heat.
0:39Heat. [music]
1:01Hello everyone, welcome to another
1:03session of Microsoft 02 hero community.
1:06This is another weekend, another
1:07Saturday and we will have another
1:10session with a community speaker uh that
1:12is going to talk about uh developing
1:15secure AI enabled applications in net
1:17and Azure which security is important.
1:19But before getting there let me share uh
1:22some news and like uh about the
1:24community. This is a community built by
1:26the community for the community. We have
1:28only a simple code of conduct and it is
1:30to be respectful to each other and
1:32listen to each other. If you want to uh
1:35follow us uh on social medias, you could
1:37go to microsoft hero.com and there you
1:39could follow the news and uh what's
1:41going on in our community, we are part
1:44of microsoftlearn.com
1:45and uh in the calendar you could also
1:48see what are the sessions that already
1:50been held and what are the upcoming
1:51sessions. Uh then uh without further
1:54ado, I would like to invite uh Jonah
1:57Anderson, our guest for tonight's
1:59session. Hi Jonah.
2:02Hi Shahab and everyone that's watching
2:04us live today on uh on YouTube and also
2:08on LinkedIn live. I think we are on
2:10LinkedIn live as well.
2:11>> We are on LinkedIn, we are on
2:12Streamyard, we are on YouTube and we are
2:14also on Twitterly.
2:15>> Yeah. All right. Okay. Yes. It's good to
2:18be back and nice to see you because I
2:20remember we met uh in person uh in uh
2:23one of uh the conferences in Germany uh
2:26as well and it's my second time for uh
2:29for this uh meetup to join I remember
2:32when the community just started I I was
2:35one of the speaker and chair about cloud
2:36migration like I think that was like two
2:39two years ago and now the the community
2:41has grown a lot and you're also one of
2:43the organizers and host so it's great to
2:46work with you. Yeah, thank thanks great
2:48to have you back and uh stage is yours.
2:51Uh I'm sharing the slides now. So yes uh
2:54and uh let's let's get let's get it
2:57started.
2:58>> Yes. Uh so let's go ahead everybody. So
3:01I hope everyone are sitting comfortably
3:03in your couch uh car or wherever you're
3:07watching this mobile or your TV or or
3:10your or or your phone. But uh I'm live
3:13actually right now. I'm alive and
3:15kicking and moving and I'm in my home
3:17office. It's Saturday evening and I'm so
3:20glad uh to be able to sit here and share
3:23my knowledge about uh dev sec ops and
3:26how we can develop securing uh secured
3:29AI enabled apps innet and also in ashure
3:34uh technologies and I remember I I
3:37yesterday uh it was Friday of course I
3:39did share an internal learning session
3:41from my to my colleagues about how to
3:45build uh AI agents using MCP servers and
3:49Microsoft foundry. But today I'm like uh
3:52uh doing another level where I share to
3:55the community in public about DevSec
3:58Ops. So I I look forward that you will
4:00find this uh presentation very useful in
4:04whatever you are building or planning uh
4:07to build. So before that I would like to
4:10share a bit about myself. So I'm uh just
4:14to keep it short, you see everything
4:16here. Uh I'm a Microsoft MVP uh MCT as
4:19well or community lead uh author but uh
4:23I used to work as a a consultant uh for
4:27the last uh 10 years working with uh
4:30system development uh focus innet
4:33and uh now focus a lot on Azure and uh
4:37also putting on a hat as a uh cloud
4:41infrastructure uh team lead uh leading
4:44with our DevOps and uh cloud uh platform
4:49and part of my work is actually the
4:51topic that we're talking about securing
4:54our DevOps pipeline uh from code to
4:58production uh workloads but uh a little
5:01bit about me uh I work for myself now uh
5:04as a independent conso consultant uh so
5:07I have one client I work with uh I I am
5:11the author of learning Microsoft Ashure
5:14uh first edition was released three
5:15years ago and I'm currently writing the
5:17second edition this year and also think
5:21uh writing uh a self-published book on
5:23the side which I will share later. Um I
5:26also am the founder of Asher user group
5:29Sweden which is like the sister like a a
5:32a collaborator of uh this community as
5:36well. So I founded Asher user group Swit
5:38Sweden and we also have uh sessions uh
5:42there uh every Saturday and I'm glad
5:44that this session that I'm delivering
5:46right now doesn't conflict with the one
5:48that I'm I'm hosting. So I have a lot of
5:52a lot of things to share. You can talk
5:53to me of the things that I listed here.
5:56uh feel free to connect with me on
5:58LinkedIn or ask questions later uh if
6:01you want to reach out or collaborate or
6:04have uh questions related to this topic
6:06and uh just uh just to give smile to you
6:09this weekend that is not an AI photo by
6:12the way that is a photo of me and my dog
6:15Lawrence uh last new year uh in his
6:18tuxedo so I'm a dog lover I have a lot
6:20of interest but I'm very proud to to say
6:23I'm a dog mom to this uh cute but large
6:26labradoodle named Lawrence. And if you
6:29follow me on LinkedIn, you probably have
6:31seen uh fun photos of him and me
6:34together sometimes.
6:36So what are we uh uh uh talking actually
6:41uh today? So what we're going to do is
6:44that uh we're going to try to uh discuss
6:47about uh a net application which is can
6:51be very uh v can vary depending on what
6:55kind of architecture that you have but
6:58in this session or talk it will be a
7:00combination a bit of theory uh or de
7:04presentation that you see here and also
7:07some uh uh code examples and how it
7:10looks on VS code if you had uh the code
7:14both the front end back end and how the
7:16YAML pipelines works and then you will
7:19also see uh a bit of uh Azure DevOps and
7:23how it looks the infrastructure on
7:26Azure. So uh what we're trying to uh
7:30protect today is a net uh uh stack. uh
7:34it is actually a realistic kind of
7:36application where of course you have the
7:38front end you have the back end and in
7:41this case since we're talking about
7:43protecting the f uh the the uh the the
7:47back end with AI and one of the tools
7:51that is available today when it comes to
7:53using MCP servers or Microsoft Foundry
7:56for AI integration at least in the net
7:59and Microsoft Ashure stack it is the
8:02Ashure functions MCP tool to trigger and
8:05if you have not tried uh working or
8:08building uh agents uh using Azure
8:12functions if that's your like kind of
8:14field because there are different ways
8:16to build uh agents today but MCP tools
8:20uh tool extension for Ashure functions
8:23is one good way to self-host your agents
8:26uh on uh on Microsoft Foundry. So, we're
8:30going to have that in our like example
8:34uh application and it has a back end of
8:36Blazer. Uh there's a chat UI assuming
8:40it's a it's uh an AI feature chat that
8:44uh an application might be enterprise or
8:47a small one and it has a u a chat UI
8:51that talks to the agent and uh it has
8:54net 10 as its uh as it as its language
8:58and then it uses ashure function MCP
9:02server and flex consumption and it has
9:05an integration with Microsoft boundary
9:08and a GPT model. So in this uh use case
9:11example that I'm going to show you at
9:13least for demo wise is just uh using one
9:17of the GPT models for a demo purposes.
9:20So if you're expecting me to do toggle
9:23with different uh different models then
9:26then I didn't uh made that yet. it's
9:29more like focus a lot on uh dev sec ops
9:32and then if you have questions later uh
9:34feel free to ask it later on at the end
9:37we'll have a a special time at after
9:39that demo so what we're going to I mean
9:43in this uh scenario that we have we do
9:46we do have like we're going to wrap in
9:49our devs sec ops I think most of you are
9:51familiar what it is about it's just like
9:53basically you're injecting security in
9:56your dev ops processes
9:59uh regardless if you're using Azure
10:01DevOps or GitHub or whatever is the uh
10:04tools that you and your team are using
10:07to deploy code to to the environment or
10:10to cloud or to to production. So we're
10:13going to wrap it in with like using
10:15intra ID with arbback roles uh that is
10:18uh intended to protect the identity
10:21regardless if it's a manage identity or
10:23a service principle or identity of the
10:26person that's accessing the application.
10:29Uh the reason why ID identity is number
10:32one because identity is the number one
10:34thing that that is being targeted uh
10:37when it comes to security risk. And then
10:40we're going to also try to to mention or
10:44include Microsoft Defender for cloud. So
10:46the defender for cloud is not just for
10:48Azure Ashure stuff, Ashure resources
10:51that you hosted on Azure. You can
10:53actually uh use it as well regardless if
10:56you're using GitHub for your GitHub
10:58actions or pipelines or you can also use
11:01Azure DevOps for your enterprise uh
11:04deployments uh or release management.
11:07And then there's going to be like
11:09extensions that will be mentioned
11:11depending on what kind of codes that
11:13you're trying to protect uh for code
11:15scanning for example I'm going to share
11:17a few that I have implemented in my demo
11:21and then uh there's uh key vault as well
11:24and manage uh identity uh for that. So
11:30before we start I want to like share a
11:33bit. So that was like the prototype of
11:35example net technologies that are very
11:38close to applications
11:40uh today. Uh so when we talk about
11:44security and also the AI innovation that
11:49we have today uh our applications is not
11:53like the good old days where you have
11:55the monolithic I mean you switch from
11:58monolithic to microervices to serverless
12:02and now they still exist those things uh
12:05we're still having challenges handling
12:07technical depth but now we al have to
12:10add the layer of AI into the
12:13integration. So now we do have uh more
12:16challenges when it comes to uh building
12:19applications regardless if it's .NET or
12:21any other uh languages. And there are
12:25three uh shifts that shows up when AI
12:29features or using MCP server uh tools as
12:35uh as as as part of the integration of
12:39any code base or source code regardless
12:42if it's a new one or it's an existing
12:46source code or applications that are
12:49being modernized or integrated into an
12:53AI kind of solution. So
12:58if you notice, I think I'm guilty myself
13:00as well. Uh I think all of us developers
13:03are trying to use or adopt at least AI
13:06today. And one of the tools that we try
13:08to utilize of course is to do copilot or
13:11pair programming with uh cloud code or
13:15any tools that we have and probably our
13:18companies pro provide it. Of course we
13:20need to use it. Some enterprises are
13:23taking it slow. Some enterprise
13:26enterprises have adopted it that they're
13:29allowing their developers to use AI
13:32tools as their pair programmer.
13:35And regardless of any scenarios or
13:38situation you are into in your project
13:40right now, it is a fact that these three
13:43ships that I'm showing you right now uh
13:45that sometimes you with AI coding with
13:49you, you might have code that you didn't
13:52write because AI or co-pilot suggested
13:56you how to solve it. And that's not a
13:59problem because AI is very smart. It can
14:01out outsmart us as well. But if you
14:04didn't get into the loop of the logical
14:07thinking and uh reviewing that code then
14:11there's a risk that AI took over and if
14:14there is no security inside it or there
14:16wasn't any security devs sec ops
14:19implemented from code to the deployment
14:22to production then we see a possible
14:25risk for that and then now that we have
14:30um MCP servers and AI tools coming in.
14:35We're still adopting of course in the
14:37learning but then we do have a new layer
14:41of attack surface on top of what we
14:44already have before the AI we have to
14:47deal with database in SQL injections. We
14:50have to think how we protect our uh
14:53connection strings configs on uh
14:56configurations sensitive uh data uh out
15:01of the code and make sure that they're
15:03not pushed to a public repository and do
15:06the best practice as pos as much as
15:09possible in the dev sec parts. But now
15:12we also have to have this new layer and
15:14then we have uh wider wider integration
15:18involved right now. a wider uh blast of
15:21radius when it comes to a security. So
15:26uh if a developer or an infra engineer
15:29make a mistake such as like one
15:31misconfigured
15:33information or secret in the
15:37infrastructures code the back end or any
15:40uh nougat packages which is external
15:44that has been implemented in any layers
15:46of your code that can be uh a risk uh as
15:51well.
15:52So I think in all of this like uh all
15:56all of this shift lift uh like uh like
16:00answers I mean shift lift wouldn't be uh
16:03possible unless it is done into uh
16:07practice.
16:09So uh
16:10>> sorry Jonah just to to wrap up my my
16:13brain around what you already said. I
16:16think uh we we have like all the
16:19software engineering practices and then
16:21we are adding an AI layer on top of them
16:23but still we need to make sure that the
16:25AI is sticking to those software
16:27engineering practices and the same thing
16:30applies for security practices right we
16:33had the SQL injection and now we have
16:34prompt injection and then we need like
16:36to be aware of these kind of new
16:39surfaces that are emerging and apply
16:42again like the best security practices
16:44when we are developing the application
16:46Right.
16:47>> Yes. Exactly. So we have the prompt
16:50inject injection uh like I mean before
16:52we only have uh SQL injection and other
16:55stuff right now we have to have new
16:58layers of things we have to learn. I
17:00mean like uh I mean if you're not
17:02working in a security uh as a security
17:05engineer in a project then probably if
17:08you're just a developer you wouldn't
17:09know about all these things unless
17:11you're informed right because in the
17:13good old days as a developer probably
17:15you're still catch up catching up with
17:17AI you're used to oh I'm this one this
17:20this code I'm going to pro I'm going to
17:22write it very well because I know XSQL
17:26injection exists
17:28>> but if you're a developer who's not even
17:30adopted to how AI works or doesn't even
17:33understand it and didn't even know that
17:35prompt injection exists then you
17:37wouldn't even think about writing a good
17:40prompt to avoid it and all these other
17:42practices right uh so that makes that is
17:46uh that's that's very true anything you
17:48want to add in this
17:50>> oh no no just just wanted like to to
17:53review to for my understanding
17:56>> yes and I also want to highlight to
17:58everyone Maybe we can share Shahab and
18:01and us can share also uh I mean you can
18:04also search um you can take a look at
18:07about this like OAPS uh LLM top uh 10 uh
18:12wrist for for this. I mean uh this is a
18:15good security like uh list of things to
18:19think about and I know one of the new uh
18:22new lists item there is like uh attack
18:26services is on MCP and all this prompt
18:29injection uh today. So there's new layer
18:32that we need uh to uh to think about uh
18:36and I myself is actually not just
18:38talking uh talking uh this like for
18:43presentation I am actually dealing with
18:45uh with security remediation all the
18:48time because we're using Microsoft
18:50defender for cloud in our project and we
18:52thought that our application is secure
18:54but there is still the small things list
18:57of things we always have to do to avoid
19:00our application to be uh to be at risk
19:04because of this new layer of attack
19:06surface that probably
19:09uh the applications were not prepared
19:11for before AI evolution has arrived and
19:14I think uh there are many of us that are
19:16still in in the challenge. So uh to move
19:21[snorts] forward
19:23um we're going to we we need to change
19:26our mindset actually that what uh dev
19:30sec ops is really about. I mean before I
19:33mean when I was a developer uh I mean
19:36I'm a developer I could do the coding
19:38and then when I was asked by my client
19:41Jonah do you want to be the lead of the
19:43devs devops team and then of course I
19:47did agree because I I like I like
19:50learning new things. I I like
19:51understanding the flow from code to to
19:54production but I we always see this
19:56misconception of what dev ops is or what
19:59dev secc ops is. uh for me I mean as I I
20:03wrote here DevSec Ops it's uh it's it
20:07it's it's it tool it's how our teams
20:12work in our enterprise in our projects.
20:16So to me the the the three top three
20:19principles that I think uh I think all
20:22of us needs to shift when it comes to
20:24dev sec ops that it's not just the
20:26responsibility of a security engineer to
20:29secure the applications. It's everyone's
20:31responsibility. It's a shared uh
20:34responsibility uh from code uh to CI/CD
20:38pipelines to like quality assurance even
20:41when you're monitoring and doing
20:43reliability uh like preparation and
20:46governance into uh when it's in
20:49production. So both shift and right
20:52shift left not just shift left now but
20:55it's also shifting shifting uh right
20:58meaning catch the issues that you may
21:00face or security risk early uh as much
21:03as possible like in your uh IDE when
21:06you're coding with copilot uh when you
21:09are doing pull requests uh there are a
21:12lot of tools at GitHub right now that
21:14allows you to do code scanning and it's
21:16part of my demo uh by the way but there
21:19there There are tools already in the CI
21:22that can prevent or stop any risk of
21:26security threat from the code before it
21:28even gets to production. And then of
21:31course with the help of Microsoft
21:33Defender for cloud you can also like
21:36keep watching the production uh
21:38applications by remediating what are
21:42already are at risk and uh the tool for
21:45that on Azure is uh very good and if
21:48possible uh we do have AI now why not
21:50use AI also to build something that can
21:53automate uh the things that you want to
21:56protect. So automation of the gates. So
21:59if it uh if it's possible to build an
22:02agent that helps you with the security
22:05whatever is the the gates that you have
22:07to secure your pipelines uh utilize
22:10utilize that but the point I'm sharing
22:13is that dev sec ops is a teamwork uh
22:16just like any in anything in any project
22:19because if if we point fingers at point
22:23fingers that it's just a security
22:25engineer's job then I don't think I
22:28don't think it will be a successful kind
22:30of security we're doing in our
22:32applications.
22:34>> This is very interesting today.
22:36>> Yeah. What's your input on that?
22:38[laughter]
22:38>> Like a couple of days ago, I I read like
22:41in one product that now building is a
22:43team work and I was like it was always a
22:46teamwork. It's not just like for the AI
22:48age. But yeah.
22:49>> Yes. And I I think also I think uh it's
22:52not just actually the engineering team.
22:54It's not just the developer, the DevOps
22:56engineer or infrastructure platform
22:58engineers and security team and the
23:01admins but I think it's also good I
23:04think uh there's also uh a non-technical
23:07perspective here. We also need to
23:09involve uh the business team which is
23:12often uh has a different perspective
23:15when it comes to application right uh
23:18they the business team only wants
23:20features but we the the teams that are
23:24really handson they know what are the
23:27possible risk but it when you are able
23:29to communicate to everybody
23:33technical or non-technical kind of teams
23:36that security is a shared responsibility
23:40then I think it will be clear but I
23:43don't know how is it in your uh
23:44perspective or your project um
23:46>> absolutely agree like we need to involve
23:48like like everyone is part of the team
23:51it's not like like the technical and
23:53nontechnical separation is kind of like
23:55to me looks technical or mechanical
23:58>> but it's like the business people and
24:00like we have like this
24:02>> collaborative modeling that I I really
24:04like like which is the goal is like to
24:07involve everyone in in the understanding
24:10of what we are about to build and what
24:12are the the the challenges there. So I I
24:17consider also like uh like um you know
24:20we we we I mean I I've been in the
24:23consulting industry and I see different
24:26layers in different projects and also
24:28different kind of like communication uh
24:31and I think I mean it's different when
24:33you're like learning from a conference
24:35learning from from a community it's good
24:37we're learning the basic but you really
24:39learn a lot for in action when you do it
24:42in a real projects I think you can also
24:44relate. I can relate. But uh one of the
24:47things that I I do I do see and in my
24:51perspective [clears throat]
24:52is that I consider security risk uh as
24:57like kind of like a priority in a way
24:59that it is also as important as
25:02technical depth something deprecated and
25:05if you don't do it then this
25:07applications will stop. But let's just
25:09say if your uh SSO login or your login
25:12feature in your app is is at risk for
25:15security and it's live in production,
25:18there's a risk also that the identity of
25:21your users are being threatened and if
25:23your uh entire website is getting hacked
25:27because it there's no dev sec ops
25:29implemented to it then everything will
25:32be affected including the business
25:34aspect of it. So I think it's very
25:36important.
25:37Yeah, absolutely.
25:39>> Yeah. So, let's proceed. I want to sh I
25:42have a few things more things. It's very
25:43interesting discussion. So, that's
25:45that's good that you are [laughter]
25:48joining in. So, I'm not uh I'm not
25:50alone.
25:52Okay. Yes, that's that's a great idea.
25:54Okay. So, as in continuation also of
25:58what we're talking about uh you know
26:00just like in in in application
26:04development, I'm I'm a developer myself
26:06also. I'm familiar with like you do the
26:08coding you you just dep you push it
26:11there but we are in a different layer
26:13now we're talking about uh security and
26:16if we think about security perspective
26:18at every stage of uh life cycle of uh of
26:23it. So usually you have the same way
26:27like you do the dev sec obviously you
26:29have to to plan uh the threat model you
26:32have the design review you have your
26:34code you you you
26:37have your security can be in uh in in
26:40the IDE itself uh when you code it and
26:43push it the CI/CD
26:46it can be uh a threat protection also
26:49using Microsoft uh defender for cloud uh
26:53that gives us the the information what
26:56needs to be handled and then also during
26:59the build uh you can do SAS uh secret
27:03scan uh when when that is on the build
27:06process and then uh test uh DAS and then
27:11container scan infrastructures code
27:13scanning and then when it comes to
27:15deployment we also have to check that
27:18the manage identity that you're using
27:20for your serviceto-service integration
27:22or service uh service identities that
27:26you have has this rolling updates uh
27:28from time to time uh as well. How are
27:30you handling tokens if it has a service
27:33principle tokens or client uh tokens
27:36that needs to be recycled? So sometimes
27:39you do a forever client token and you
27:42didn't know that that token is already
27:45at risk. So sometimes it's good to have
27:47a rolling updates and using secondary
27:50keys or primary keys option kind of uh
27:54strategy as well and then also uh
27:57operation uh part which is includes the
27:59posture management and that is actually
28:02a continuous loop in the cycle. So if
28:05you take a look at the dev sec ops like
28:08symbol, it's actually a loop uh in all
28:11of this cycle, but we're injecting or in
28:14integrating security inside it just like
28:17the normal application. But this time we
28:19need to be mindful of like any
28:22integration related to AI can also needs
28:25to be uh considered uh as well.
28:29So, so when it comes to uh AI and MCP,
28:35so we do have uh different tools that we
28:40can uh utilize where we can do shift uh
28:44lift. So when it comes to IDE for
28:47example like regardless if you're using
28:49BS code uh you can consider using like
28:54copilot GitHub copilot in chat to do a
28:57security like check on your entire
29:00source source code like depending of
29:02course you need to be the leader and the
29:04pilot of your prompting but uh you can
29:08use actually AI within your IDE to to to
29:12make sure to catch any security issues
29:16before you commit that to your feature
29:19branch or your merge and do a PR
29:21request. Um, and then make sure you can
29:24utilize like Azure function skills MCP
29:27servers that's available uh for you
29:29already in the local environment using
29:32your IDE and then of course when you
29:34push the code there might be few things
29:36that AI or copilot or you have missed.
29:40So do another layer uh do the PR review
29:44and during the PR review process uh
29:46there's the copilot autofix uh there's
29:49codeql uh in github there's dependabot
29:53and then if you're using uh uh ashure
29:57devops uh enterprise ashure devops
30:00instead of github they even though g uh
30:03the github advanced security is kind of
30:05like already default and built in into
30:09github you can actually integrate that
30:12feature into your Azure DevOps uh as
30:15well. So uh do that also in your PR and
30:19then when it comes to pipeline uh
30:21depending on where you are uh hosting it
30:25there's actually Microsoft uh security
30:27devops there's
30:30uh the check off uh which is part
30:32actually of my demo. I'm going to show
30:34you how at least it looks in the YAML uh
30:37pipeline and then when it's in
30:39production uh Microsoft Defender for
30:42Cloud Security Copilot uh and then the
30:45Foundry IQ as well or use AI uh to also
30:50help uh help you uh with that when it
30:53comes to security and having an
30:56oversight of your uh platform.
31:00So uh defender for cloud
31:04uh this is actually a new feature that
31:07were announced uh in May. Uh so if you
31:12have Azure for example or you already
31:14have a Microsoft defender for cloud you
31:16can actually use uh Azure DevOps
31:20connector or GitHub uh connector uh to
31:24set it up so that you can see the the
31:28the post the existing status of this
31:32environment in a security uh
31:35perspective. So I'm going to like show
31:37at least how it looks on Asher where you
31:41can build that connector. Of course
31:43there are step by step uh for that. So
31:46that would be good. And I think it's
31:49time for me to do a bit of demo soon. So
31:52what we're going to do is I'm going to
31:54show you at least how how the how it
31:58looks in a in a code and how I you can
32:01implement different kinds of security
32:06um like what do you call that a gates
32:09within your pipeline uh in in in your
32:13application and the application was the
32:15one that I shared to you uh earlier. So
32:18let me just uh switch screens here.
32:22Stop screen. Present a new one.
32:26Uh let me do the this first.
32:34>> So so far we we have like tools and
32:37capabilities to check for various
32:39security issues for different target
32:42levels, right? where like scanning for
32:46uh for I don't know for example the
32:47connection string is not like pushed to
32:49our git repository or or at runtime we
32:53have like the Microsoft defender to
32:55check for security problems that might
32:56be in the application
32:59>> yes that's right and uh yeah and I think
33:03I think moose I mean I don't know I mean
33:05in your project you use Microsoft
33:06defender for cloud
33:10>> that's a very good question but u I like
33:13discussing
33:14>> [laughter]
33:15>> like I'm I'm having a conversation.
33:18>> Yeah. Yeah. No, no, that's a very good
33:20question. But but I don't know actually
33:22what the security engineering team is
33:24doing there. Uh
33:25>> yes, you need to have the shared
33:27responsibility more. You can tell them
33:30>> yes [laughter]
33:32Monday questions and responsible like go
33:34and
33:35>> save it for Monday because you learned
33:36something new from Jonah on on the user
33:39group. Anyway, um so uh I want to share
33:45uh at least an example Ashure DevSec Ops
33:48demo I have. So this is uh I I am I'm
33:51skipping the live demo because there's a
33:53lot of things I have a dry I did a dry
33:56run uh where I could plant issues and
33:59things but I can try that. Uh so what
34:02I'm trying to do actually is I'm going
34:04to just give you a tour of the project
34:07how it looks and how most especially the
34:10YAML pipeline is is is structured to
34:14protect uh the code both infer wise
34:19front end and back end. And then how are
34:22the possibilities within the code like
34:25which part of the code can this Ashure
34:28functions that uses MCP
34:31uh and C can be a risk and how the tool
34:36uh that I have implemented here will
34:39stop uh stop that if there's a risk
34:42within uh the pipeline. So I'm not going
34:45to do the full demo but uh I if you want
34:47a copy of the the entire like YAML that
34:50I did I can uh share the repo later on
34:54but basically uh the flow the the
34:57example that I have is uh an app uh so I
35:02have my infrastructures code I have my
35:05source code uh use ACD here Ashure
35:08developer CLI uh to deploy this to Azure
35:11so I love it uh it's easy But you see
35:14here that in my source code I do have a
35:18front end which is a blazer app that
35:22probably is non none of the things that
35:25we need to go through because we're
35:27focusing on how we are securing the
35:29applica securing the applications right
35:32and then here we do have uh our uh
35:36functions aure functions app that has an
35:40integration to
35:43Microsoft
35:46foundry.
35:47So here uh we have uh so you know AI
35:50enabled app because uh there is foundry
35:53in here. So basically uh it has let's
35:57just say I have an application and I
35:58created a chat support for it. That's
36:00how you would see it in the big picture.
36:03And the front end has a chat client that
36:06has an integration to AI like for now it
36:10doesn't have real data but it's more
36:12like chatting to to AI as it's uh from
36:15end and then there are different risks
36:18where a developer can probably make a
36:20mistake and push the code uh
36:24accidentally
36:26and take uh I mean give a security risk
36:29to a production application if there's
36:32no dev tech ops like strategies
36:35implemented within the pipelines uh
36:37already. So one example that I see here,
36:40let's just say if you're if a developer
36:44kind of maybe a junior one or not using
36:48AI or AI is also stupid [laughter]
36:51model then uh there's a big risk that uh
36:54one risk like what you see here in line
36:5651 is the foundry API key. uh if you're
37:00if you're tackless as a developer, you
37:02can actually hardcode that key and that
37:05can be already uh a risk. So there is a
37:08of course best coding practices uh to
37:12secure whatever is uh secret in your uh
37:16application during the local development
37:18but uh uh one of the best practice I
37:21would recommend is using ashure key
37:23vault and uh coding it properly.
37:27Um, another way that a front end for
37:30example can also be at risk is like
37:33components such as Nougat packages for
37:36like front end uh like frameworks. So if
37:40you have a Nougat packages in the front
37:42end that probably are not supported or
37:47outdated uh somewhere uh that can be uh
37:51a risk uh as well. So what let's just
37:55say this one. So if you have package
38:00references that probably are at risk
38:02that can also be uh uh a threat somehow
38:06like outdated
38:07uh and those outdated can be uh can can
38:11uh can be scanned by our uh our tool.
38:17And then how does the infrastructure as
38:20code
38:21looks like? At least you see how the
38:24application
38:26is.
38:29So the application, let me see if I can
38:31zoom.
38:33So if you see here, so we have a web
38:36app. It has a a front end which is the
38:41chatbot. You can say chatbot that has
38:45integration with Microsoft Foundry. It
38:47has a back end and the function itself
38:50has the the the necessary uh ashure
38:53resources such as like hosting plan the
38:56blob the storage.
39:02It has app insights. uh it has an
39:04integration to foundry and the uh UI
39:09uh has a role of open AI user role and
39:13then it has uh some model and then
39:18and an
39:21identity here. So it's very uh very
39:24simple uh very simple apps in a way that
39:28for example on the infra code here
39:38uh let me see where can uh
39:43uh
39:46uh let's just say bicep main that bicep
39:50is
39:52is good but where can a DevOps engineer
39:55writing bicep module can give risk for
40:00security so one of the things that I see
40:03that has a risk like for example when
40:05you're creating a storage account
40:09usually if you use an ACD
40:12I mean if you're new then you do you
40:14don't really check on this specific
40:16details by default because it's just
40:18template but if you're really keen about
40:20the security and you're doing it in a
40:22real enterprise or production
40:24application, you would be mindful on
40:27this line or settings or component or
40:30properties for the storage account in
40:32line 37. So for example, you would if
40:35you want to I mean for demo purposes uh
40:39of course if I want to break it I can
40:41change it to like true allow block
40:44public access allow blob public access.
40:48If this is true then it is a security
40:52risk because you shouldn't allow your
40:54storage blob to be accessible to public
40:56it should be always uh false. And then
41:00in the network part if you want to like
41:04um if you want to tighten like your
41:08network settings here as well if you you
41:11make a mistake of not allowing or
41:13denying it then it could be uh a problem
41:16uh as well. Do you had something to say?
41:19>> No, no, I'm just listening.
41:21>> Yes. I hope we're the time is still
41:24okay.
41:25>> Uh yeah, we are like 40 minutes into the
41:28session. So we have like 20 25 minutes.
41:30>> Okay, that's that's fine. I'm think I'm
41:32almost done. I'm just like showing uh
41:34actually the possible risk here for like
41:38issues like I'm looking at the
41:40infrastructures code. I'm not sure if
41:42you're like do you do infra code in your
41:44work uh job?
41:47Sorry.
41:48>> Do you do a lot of infrastructures code
41:50in your line of work?
41:51>> I used to write like infrastructure code
41:54as well, but uh currently I'm not doing
41:56that but our teams like are writing a
41:59lot of like also the infrastructure
42:01code.
42:02>> Uh they're using but they're not using
42:04like bicep per se but other equivalent
42:08tools that that are in the market like
42:10depending on
42:11>> Yes.
42:12So what I'm actually sharing here to our
42:14audience or to everybody as a learning
42:16session is that like I mean I mean this
42:19is just one one resource that we're
42:21trying to like look at. It's just like
42:24when regardless if you're using bicev or
42:26terraform
42:28uh sometimes there are tools that are
42:29hey you can just say hey let AI do the
42:32templating for bicep or terraform but
42:36there are I mean AI gets the information
42:39from the data across the world right and
42:43there might be a risk that the default
42:45settings for example the allow blob
42:47access storage is not set to false which
42:50is the best practice and probably that
42:53is missed. And if you're not mindful
42:56about a few things, you don't really
42:58need to know all these things. But if
43:00you don't have a pipeline or or
43:03automation that checks on this small
43:06errors, then it could be uh a risk as
43:09well. And it can happen in uh in any
43:12kind of code like infrastructures code.
43:15It can be found in the the new get and
43:18everywhere
43:19>> like like I I have a question regarding
43:22for example
43:22>> yeah please to I like discussion go
43:25ahead
43:27>> all good regarding this specific example
43:30like to not allowing like public access
43:32to blobs right this is a setting you are
43:35setting to false in yeah your bicep
43:37files
43:38>> is if if by accident like someone set
43:42that to true like to to allow public
43:44access. Where do we catch this? Because
43:47I could use bicep. I could use
43:48terraform. I could use Palumi. And these
43:50days I could also use Azure uh sorry I
43:53could use also the Aspire right to to to
43:56be able also like to deploy like to to
43:58production.
44:01>> Yes, you can actually see this. I mean
44:04you're asking where is it caught in
44:06terms of security? Is it like in your
44:08pipeline or is it like in after the
44:11deployment and then it checks like the
44:13resources like what the settings are?
44:15>> Yeah, it will be in the pipeline
44:17actually. So basically this uh this is a
44:19code demo for now but I do have one more
44:22I'm going to show. So this is the front
44:23end. I hope you see that. So this is the
44:26front end. Let's just say this is Jonas
44:28uh Jonas like AI app where it has a
44:33blazer simple one and that's the front
44:35end. I don't it's just a simple one
44:37because uh we're not focusing on the
44:39front end now but I want to show like
44:41for example
44:43an introduction before I answer the the
44:46full picture. So here is the the we have
44:49the infrastructure as code right and in
44:52the infrastructure as code I mean
44:54currently it's built properly uh and
44:57what we're going to try to do in the
44:58demo is we're going to break that it
45:01won't go through because Jonah or a a
45:05developer that doesn't know so much
45:06about how things work because he or she
45:09is just dependent on AI or prompt
45:12engineering and not really like thinking
45:15about best practice. is we're going to
45:17try to flip this and
45:21break this like instead instead of this
45:24is false, we're going to set it as true
45:26and we're going to the repo and it
45:27should never push through or go through.
45:29It should break and it shouldn't even
45:31build. Um, and it should show in our
45:34DevOps pipeline. But before we do that,
45:36I want to see the big picture of this
45:39like so uh so let's just say I'm showing
45:42my Asher subscription ID, but it's okay.
45:45Let me just refresh one moment.
45:52So I have this resource group uh here.
45:54It it shows anyway but that's fine. Uh
45:56so um so we have let me zoom. So here
46:01you see that I have my back end which is
46:03the function app. Uh this is my manage
46:06identity the entire like infrastructure
46:09uh that I showed uh earlier. There's
46:12even an event grid here because it's a
46:14it's there's an integration for that.
46:17And then uh in foundry just to highlight
46:20if you really want to like um like like
46:25do things in the foundry way or AI way
46:28you can uh utilize of course going and
46:32do that for Microsoft foundry but uh
46:35since we're focusing because in foundry
46:37you can I mean the AI layer part I mean
46:39we're talking about devs sec ops in the
46:41code but if you also want your AI to be
46:46very like um very uh smart as well is
46:51you can actually use uh guard rails uh
46:54in in Microsoft Foundry as well. So let
46:56me just go pull that up. I have one
47:00example actually here.
47:04It's not the one that I have for this
47:07specific one, but I want to show that if
47:10you also want your AI to be protected or
47:13you follow compliance, uh you can use
47:16guard rail uh guard rails features of
47:20Microsoft Foundry and uh do some
47:24evaluations uh in terms of protecting
47:26the the AI or Foundry part. But to
47:30answer your questions, this is the
47:32pipeline. Uh so this is the Ashure
47:35DevOps
47:36and if you see
47:40I do have uh the repository here
47:44just exactly as what you you see in the
47:49the VS code and I have the infra I have
47:54the source code and uh and everything
47:58but in my pipeline for
48:02for uh for this uh integration where I
48:06have everything in one file. I I
48:09everything looks good. But if we go
48:12inside here,
48:15I do actually have some kind of like
48:19different
48:21like different ways to check. Uh so
48:25maybe it's better to show it here in the
48:28YAML file. So in my project
48:32I do have Ashure pipelines but already
48:36in my YAML file I do have several uh
48:38stages. So this is not the classic
48:42variation. So this YAML pipeline is not
48:45an ordinary pipeline that only pushes
48:48the code directly.
48:51It does actually have security gates. So
48:53aside from the schedule that you see
48:55here in line 16. So it has a monthly
48:58weekly scan. It also
49:02has
49:04um so after the PR goes goes through so
49:07it's going to do security scan after uh
49:11the PR has been approved and even it
49:13gets built. So there are different
49:15stages of the security scan. So the
49:18first job of the security scan is to
49:20scan for secrets using git gitlicks.
49:24So here you do see uh a reference
49:26there's a C a script that curls to that
49:30uh that tool and then it's going to run
49:34uh and it will uh check if there are any
49:38secrets that are being leaked on this uh
49:41PR merge or push of the code
49:44>> and then it's going to do a check
49:45because we have everything in one right
49:47it depends on the structure of the repo
49:50for for my project for example we have
49:52one repo for the back end one repo for
49:55the front end and if it's microservices
49:57there are different repos but for this
49:59code demo I have one repository I have
50:03infrastructures code I have front end I
50:06have back end so I have to do several
50:08mult uh security scan within this YAML
50:11pipeline so uh I have another job I mean
50:14I can edit this as much as I want and
50:17set conditions in the YAML file but I
50:19also have an a in uh infrastructure code
50:23scan which scans my uh bicep. So what it
50:27does is it's going to run uh the script
50:30and it's going to try to using the tool
50:32check off which is uh a third party tool
50:35that you can take a look as well. Uh
50:38it's going to check the infrastructure
50:40as code if there's any risk for uh
50:43security here as well. And then if you
50:47want to have another layer as well uh
50:49which is the code QL and secret scan and
50:52ASC. I mean I over I'm overprotecting my
50:55pipeline by the way for security
50:57purposes but you don't need to do all.
51:00[laughter]
51:01Go ahead.
51:03>> No I think that's a good practice like
51:05to do that.
51:06>> Yeah. Yeah. I know. But uh I want to
51:08show to everybody that you can utilize
51:11uh not just the Microsoft defender for
51:14cloud uh which has a feature of codeql
51:17sec secret scan and infrastructures code
51:20but you can also utilize other tools. So
51:22you're not just stuck to the default
51:25Microsoft products as well. There's a uh
51:27an open-source secret scan uh that you
51:31can also utilize maybe cheaper and then
51:34so I have three. I have the check off. I
51:37have the uh the Microsoft security for
51:39DevOps which has both the code secret
51:42scan uh for for that. But there are
51:45other things also that you can utilize
51:48like cred scan. There's a lot of tools
51:51actually that you can do but I'm only
51:54adding uh four uh three of them uh at
51:58least uh for for now. the secret scan
52:00gate links check off and then uh
52:03Microsoft defender for cloud for devops
52:07and then you might be wondering like
52:09Jonah how did you kind of like make sure
52:13that it will work in your Azure DevOps
52:17uh pipeline because for example like the
52:20non-Microsoft ones such as the gitlicks
52:23and the check off they are not Microsoft
52:27they're not built in for Ashure DevOps,
52:30right? So, in order for you to actually
52:32have your pipeline or YAML file to work,
52:36you need to have the extension actually.
52:38So, you need to ask uh if you're not the
52:41organization owner
52:43of your Ashure DevOps, probably you need
52:47to ask that person to go inside the
52:50organization settings. So, since I'm the
52:52the owner of my organization, I'm going
52:55to go inside my organization settings
53:00and also make sure that I have the
53:03extensions. So, the extension that you
53:06need for everything to work at least in
53:08this pipeline like security scans that I
53:11have built in in my demo, the YAML file
53:14for this uh application, it needs to
53:17have the uh Microsoft security devops.
53:21So if you want to know where it is, you
53:24can actually go to the marketplace.
53:28So So if you're familiar with ash,
53:31Ashure DevOps or GitHub, there are
53:34marketplaces that you can integrate. So
53:37this is the Microsoft uh security devops
53:40that you can you can add and then
53:43there's a documentation and guide
53:45actually how you can add it in your YAML
53:48pipelines and even do a publish option
53:52to do the logs cost analysis logs on
53:55what it found uh it found out during uh
53:59during the scan. But the most important
54:01thing is you need to have the extensions
54:03that are required uh for this. And how
54:09does it look like? Let's just say if I
54:12accidentally
54:15made changes to this. Let's see. I hope
54:18my my pipeline uh is going to because I
54:21did a test run on this before
54:23presentation. Otherwise, I have at least
54:25the one that worked before.
54:28So, what I'm going to do is I'm going to
54:31try to
54:34to make it fail
54:37and see if it it will detect that I made
54:40a mistake. So, I'm going to go ahead uh
54:44where is the foundry client?
54:47I think we have
54:50one one that
54:52[snorts] for the intro
54:55where
54:56I did.
55:00I want to flip it to true.
55:04Allow shared uh access.
55:07>> I I think it's line 37.
55:09>> Uh Titan to deny.
55:14>> Yeah, it did that already. So, it did
55:16that already. So what I'm going to do
55:19uh fake uh demo only
55:24open code for security
55:28wrist by adding
55:32by uh setting
55:35to true
55:38instead of false.
55:41Not really good
55:44but just a test. Okay, let's see if my
55:48pipeline runs.
55:50So, I'm going to sync.
55:59So, I
56:01have my YAML like pipelines integrated
56:04already. Let's go on my
56:08[snorts] project and see. I hope it
56:10triggers. uh otherwise like I I can show
56:13you the previous uh thing I had to do.
56:16Let's see.
56:17>> So we expect also like some misbehavior
56:19as well. So
56:23[laughter]
56:24>> yeah, I know. Uh but it should push
56:27something at least.
56:29It's still thinking.
56:33Did it commit?
56:35Let's see.
56:38[snorts]
56:39You see two hours ago I did a run on
56:41this one. So it did go through but if
56:46not then I have actually a backup how it
56:48looks at least. It
56:51>> still thinking.
56:53>> Mhm.
56:53>> H that takes time. But anyway while it's
56:56thinking and we're waiting for uh for
56:58the pipeline to build. I do have
57:00actually how it looks because I did test
57:03this uh earlier. So what I did is like
57:06uh there is a break. it's going to break
57:08somehow here where I have an example
57:14uh this one.
57:16>> So what I did is I did false break uh
57:19the pipeline where let's just say I I
57:22had a lot of security risk on my commit.
57:25So what it does is it's going to like
57:28kind of like tell you that hey your uh
57:32okay all went through like secret
57:34scanning you don't have a leak all went
57:37well uh you have the
57:41uh infrastructure scanned that looked
57:44well but when it comes to like container
57:47because I also added a feature where uh
57:50if you have a container in your because
57:51I do have container in this uh this
57:54source code I forgot to show you how the
57:56tri scan but try scan does the scanning
57:59if you have a container apps or
58:01containerization
58:02then it did actually tell you that uh
58:06that there's uh a risk that was found uh
58:11in in the uh in the container and it
58:15will not uh go through uh in in building
58:20uh the code uh itself and same goes with
58:24uh every step that you set up. But if
58:26you want if you don't want it to stop,
58:28then you can actually just like make
58:30conditions within your uh within your
58:32YAML uh file. So I think that's uh
58:36that's it. I have at least to show there
58:38are many ways to do that, but the main
58:40thing that I want to highlight is this
58:44the tools that we that we have. So let
58:48me just continue sharing my PowerPoint
58:50soon so we can have more questions and
58:52discussions when I'm almost done. Uh and
58:56conclusion of course um we have few
59:00almost done.
59:02So
59:04>> so that was the the demo. [laughter]
59:07I hope it's a bit clear at least I was
59:09toggling in between but that's how it
59:11looks like when you're working uh in
59:13action. Right. So, so what I'm trying to
59:16to show right now uh when it comes to
59:20like uh what we've learned uh so far is
59:23that uh is that it is important uh for
59:26us to like I mean you have this mental
59:30model of how at least
59:32um the different phases of dev sec ops
59:35uh it is a pra practice it is a shared
59:38responsibility
59:40um also there are different tools tools
59:44that you can use. You don't have to use
59:46all of them, but use the ones that you
59:48really need to protect uh if you don't
59:51have uh a layer uh for that. And also uh
59:56there's copilot Microsoft Defender for
59:58cloud uh as well. And then if you want a
1:00:02copy of this repo, you can also uh do
1:00:05that. But uh one more thing I I also
1:00:08want to like mention I I don't have to
1:00:10show but if you go to Microsoft Defender
1:00:12for cloud on Azure and then look for uh
1:00:16DevOps security
1:00:18maybe I should do that. Let me share
1:00:19again one more time. I think it's good
1:00:22to have uh one more clear like for
1:00:25people.
1:00:26>> Yeah I think so instead of just like
1:00:28talking and showing. So I have one thing
1:00:30I I missed actually sharing. So, I'm
1:00:33doing a
1:00:35I want to show you also. I wonder what
1:00:38happened to my pipeline because it
1:00:40didn't push it. Um,
1:00:43I'll take a look at it later, but I did
1:00:45show that it should fail. But what I
1:00:47want to show you is that so this is your
1:00:50Asher, right? But if you have Microsoft
1:00:53Defender for Cloud
1:00:57and Ashure, I'm just going to show you.
1:01:00>> Mhm.
1:01:02So there are different ways how you do
1:01:05the defend use defender for cloud right
1:01:07I mean this is like my my my
1:01:11personal one [laughter]
1:01:13but if in the real uh enterprise
1:01:15scenarios you do have your security
1:01:17posture here you have your ashure
1:01:19subscription but focusing only on the
1:01:22security part with cloud security is
1:01:24huge uh you need to have network
1:01:27security AI security this is also
1:01:30probably good uh to check uh so if you
1:01:33have sensitive data um this is also like
1:01:37very good to utilize AI discovery but
1:01:41talking about dev ops since we're doing
1:01:43devs sec ops if you want to so if you
1:01:47notice here I have integrated my ashure
1:01:51uh dev ops uh with uh Microsoft defender
1:01:57for cloud so you do see here that I
1:02:00don't have a very high security
1:02:02recommendations
1:02:04uh and it's it has uh an agentless scan
1:02:08protection. So all of my repos in GitHub
1:02:13are turned on. Meaning as long as I uh
1:02:17because of the connector to GitHub, I'm
1:02:21able to see the overall perspective of
1:02:24how my uh repositories uh looks like and
1:02:29I can also see my recommendations. For
1:02:31now, it's low, but if I get a high, then
1:02:34it's worth uh grabbing an an attention.
1:02:37So currently have GitHub integration but
1:02:40if you want to for example integrate
1:02:42Azure DevOps
1:02:44uh into your uh the uh Microsoft
1:02:48Defender for cloud to have this overall
1:02:50picture. You can actually use the that
1:02:53connector name and then uh set it up uh
1:02:56yourself here as well. So you have the
1:02:58overview just like how you you evaluate
1:03:01the risk for your uh resources within
1:03:04Ashure. And then you can set up security
1:03:06alerts. You can uh uh do workbooks and
1:03:10have uh a full picture of how uh it will
1:03:14look like uh in your uh resources. So
1:03:17here for example, I have a repo in
1:03:19GitHub and it's telling me it's low
1:03:22because it says that your GitHub repo
1:03:25doesn't have dependabot scanning uh
1:03:27enabled. So that's a low risk. But if it
1:03:30had more then it will uh give me and
1:03:33tell me that. And this is very good if
1:03:35you have a lot of projects uh or
1:03:37repositories in an enterprise level. For
1:03:40me I'm not an inter I mean I'm using my
1:03:43uh my ashure or defender for cloud. This
1:03:45is just for demo. But if I I worked with
1:03:47the real ones then it's a different a
1:03:50different case. So I'll stop sharing now
1:03:52and just finalize this up. So I'm not
1:03:55eating much of your time because
1:03:57probably dinner time for for many. So
1:04:01>> or breakfast time.
1:04:03>> Breakfast time. Yes. Yeah. For me
1:04:05dinner. And also for you. [laughter] But
1:04:07breakfast I hope you eat eggs. I I like
1:04:10eating eggs. Uh good good protein
1:04:13uh for that. So that's uh that's all I
1:04:16actually have to to share. Uh so I want
1:04:20to like share also that I have my book.
1:04:22If you're new to Azure, feel free to
1:04:24scan the QR code or go to this website
1:04:26learning microsoftasure.com.
1:04:29I'm still writing the second edition and
1:04:31if you want to read it or you want to be
1:04:33the early reader, I can acknowledge you.
1:04:36Feel free to just like uh reach out to
1:04:38me. If the QR code doesn't work, uh
1:04:42probably it I I share a lot of QR codes,
1:04:46but you can trust me that it's not a
1:04:49a spam QR code because you need to be
1:04:51careful what QR code you scan, but that
1:04:53one is from me and not uh something
1:04:56fishy fishy. [laughter]
1:04:57So uh if you want to access my learning
1:05:00course as well because I do share about
1:05:03how you can you can develop uh AI agents
1:05:07using Ashure or Ashure MCP Ashure
1:05:10functions MCP tool. So I built a course
1:05:13with uh LinkedIn. So, I think this QR
1:05:17code will direct you to access my course
1:05:20for free without signing up for a
1:05:23LinkedIn premium because LinkedIn
1:05:24premium I think you have to pay like 300
1:05:27or 400 uh Swedish crowns to to get their
1:05:31learning courses. But this one, if
1:05:33you're the author, then I could share a
1:05:35QR code to those uh that wants it for
1:05:38for free. But other than that, I think
1:05:41that's all I I have learning resources
1:05:44to share, but I think it's it's just
1:05:46good to just go to Microsoft learn as uh
1:05:50as your like like top level encyclopedia
1:05:53of everything Ashure or everything uh
1:05:56security. So just use Microsoft learn
1:05:59and I highly recommend you to check out
1:06:02also security related topics regardless
1:06:05if you're a developer, DevOps or you're
1:06:07an AI engineer. It's very relevant that
1:06:09you know how security works as well. I'm
1:06:12learning uh even though uh I use it
1:06:15daytoday there's so much to learn but
1:06:17other than that thank you so much uh for
1:06:19your time uh say tak in Swedish salamat
1:06:23because I'm from Philippines and thank
1:06:25you and I'm welcomed for any questions
1:06:28uh from you also shab if there's any and
1:06:31also from our audience um feel free to
1:06:34reach out uh on LinkedIn and also an ex
1:06:37and also email me at jonah jonah
1:06:39andersontech if you want to discuss or
1:06:42need help with your projects because I'm
1:06:44also a consultant now. So you can also
1:06:46hire me. [laughter]
1:06:48>> Yeah,
1:06:48>> perfect.
1:06:49>> That's all. Thank you.
1:06:51>> Uh I don't see any question in the in
1:06:53the comment section for now. Uh thanks
1:06:56again Jonah for sharing uh all this
1:06:58insightful uh knowledge with us. Uh I
1:07:01hope uh we are taking security more
1:07:04serious uh on our day-to-day job like on
1:07:06every day a little bit about it like
1:07:09>> maybe we need to use more something more
1:07:11secure uh in every
1:07:13>> how is it going in your project so far
1:07:15like do you do you feel like after
1:07:17reading or learning from my session do
1:07:20you think that your organization that
1:07:22you work for are there
1:07:24>> uh I think they are already there like
1:07:26they're already like most of the most of
1:07:29the uh the the things are also like
1:07:32developers on day-to-day they already
1:07:34like uh using Azure key and uh identity
1:07:38like managed identities and all of those
1:07:40things in in in every project that needs
1:07:43like configurations or secrets also like
1:07:46the pipelines and everything is over
1:07:47managed identities
1:07:49>> uh so uh like from developer perspective
1:07:52everyone is there but I'm pretty much
1:07:53sure like the infrastructure team and
1:07:55the platform engineering and because we
1:07:57have like all all all the things in
1:07:59place and we need to make sure that
1:08:01we're not exposing but every day there's
1:08:04new things that are coming up uh whether
1:08:06it's a threat or whether it's a best
1:08:08practice so we need all to to keep
1:08:11learning.
1:08:12>> Yeah, exactly. And I'm glad I could
1:08:14share what I know so far. I'm not like a
1:08:17expert security engineer. There must be
1:08:20some other people that are good at that.
1:08:22But I do know that the tools at least
1:08:26that we need to think about when it
1:08:27comes to like working with uh AI and
1:08:31utilize I highly recommend Microsoft
1:08:33Defender for cloud because they have uh
1:08:35cloud security protection for different
1:08:38kinds of res resources including DevOps
1:08:41and protecting your data and AI as well
1:08:44if you have it on Azure.
1:08:45>> Yep. Perfect. Uh there's another
1:08:47question popping up. Uh so I think uh
1:08:50that's it uh for this evening, morning,
1:08:53afternoon, wherever you are in this blue
1:08:55planet. Wish you all good things and
1:08:58thanks for joining us.
1:09:00>> Yes. And thank you Shahaba for for
1:09:02having me. It's been finally finally we
1:09:04made it. Our honor.
1:09:06>> Thanks for inviting me.