Episode Details
Back to Episodes
Securing Identities at Scale: Conditional Access, Azure Security & Infrastructure as Code with Jonathan Hope [MVP]
Season 2
Published 1 month, 3 weeks ago
Description
Identity has become the new security perimeter. As organizations continue moving workloads to Microsoft 365, Azure, and cloud-native platforms, traditional security models are no longer enough. In this episode of the M365 FM Podcast, Mirko Peters is joined by Microsoft MVP Jonathan Hope to explore how modern organizations can secure identities at scale using Conditional Access, Azure Security, Infrastructure as Code, and Zero Trust principles.Jonathan shares lessons learned from more than a decade working with enterprise infrastructure, virtualization, Azure architecture, and identity management. From his early VMware days to designing cloud-first security architectures, he explains why identity protection is now the most critical component of any modern cybersecurity strategy.
UNDERSTANDING WHY IDENTITY IS THE NEW PERIMETER
The conversation explores how the shift to remote work, cloud applications, and hybrid environments transformed security. Traditional firewalls and network boundaries no longer provide sufficient protection when users, applications, and data are accessible from anywhere.Jonathan explains why attackers increasingly focus on identities instead of infrastructure and how compromised accounts can become the entry point for lateral movement, privilege escalation, and data breaches.Topics discussed include:
One of the central topics of the episode is Microsoft Entra Conditional Access. Jonathan explains why he considers Conditional Access one of the most powerful security capabilities available in Microsoft 365 today.The discussion covers:
AZURE SECURITY, ZERO TRUST AND GOVERNANCE
Security is no longer limited to identity teams. Jonathan explains why Azure infrastructure, identity management, governance, and compliance must work together as a unified security strategy.The conversation dives into:
INFRASTRUCTURE AS CODE WITH BICEP
Jonathan shares his journey from manual Azure deployments to Infrastructure as Code using Bicep. He explains how automation improves consistency, security, and operational efficiency while reducing human error.Key topics include:
AI, PASSKEYS AND THE FUTURE OF IDENTITY SECURITY
The episode also explores how artificial intelligence is changing both offensive and defensive security practices. While attackers increasingly leverage AI to create sophisticated phishing
UNDERSTANDING WHY IDENTITY IS THE NEW PERIMETER
The conversation explores how the shift to remote work, cloud applications, and hybrid environments transformed security. Traditional firewalls and network boundaries no longer provide sufficient protection when users, applications, and data are accessible from anywhere.Jonathan explains why attackers increasingly focus on identities instead of infrastructure and how compromised accounts can become the entry point for lateral movement, privilege escalation, and data breaches.Topics discussed include:
- Identity-first security strategies
- Modern authentication challenges
- Cloud-native access controls
- Reducing organizational attack surfaces
One of the central topics of the episode is Microsoft Entra Conditional Access. Jonathan explains why he considers Conditional Access one of the most powerful security capabilities available in Microsoft 365 today.The discussion covers:
- How Conditional Access works
- Real-time authorization decisions
- Device compliance integration
- Defender and risk signal integration
- Country-based access controls
- Blocking legacy authentication
- Protecting privileged administrator accounts
AZURE SECURITY, ZERO TRUST AND GOVERNANCE
Security is no longer limited to identity teams. Jonathan explains why Azure infrastructure, identity management, governance, and compliance must work together as a unified security strategy.The conversation dives into:
- Zero Trust architecture principles
- Least privilege access models
- Break-glass account strategies
- Security monitoring and alerting
- Log Analytics and Microsoft Sentinel
- Azure Policy enforcement
- Governance versus compliance realities
INFRASTRUCTURE AS CODE WITH BICEP
Jonathan shares his journey from manual Azure deployments to Infrastructure as Code using Bicep. He explains how automation improves consistency, security, and operational efficiency while reducing human error.Key topics include:
- Why manual deployments create risk
- Desired state configuration concepts
- Repeatable Azure deployments
- Azure Policy as Code
- Version control and Git integration
- Security standardization at scale
- Building secure Azure environments through automation
AI, PASSKEYS AND THE FUTURE OF IDENTITY SECURITY
The episode also explores how artificial intelligence is changing both offensive and defensive security practices. While attackers increasingly leverage AI to create sophisticated phishing