Explore the latest Lead with Microsoft Security agenda and speaker information in one place. Use the buttons below to view speaker details, agenda tracks, session information, and key timings to help you plan your event experience.

Please note: Agenda details, speakers, and timings are subject to change.

Monday, 7 September

Where you see “WHAT WE’LL COVER”, click the dropdown for more information.

13:30-15:00

Lunch (optional, for those who pre-registered)

Isola

15:00-16:00

Registration and check-in

Reception

16:30-17:00

Mingle & snacks

Bar de Lola

17:00-17:15

Welcome, set the scene and introduce the teams
Mailen LozdanArrow

Mar

17:15-17:45

CVC

Franck DauchéMicrosoft

KeynoteMar

17:45-18:15

Panel – The Future of Cybersecurity: What will define the near future?
Mailen LozdanArrow
Sophie DavalArrow
Kate LongArrow
Franck DauchéMicrosoft

Mar

18:15-18:45

Partner Keynote | Security & AI

Jonas AxelssonCAG

KeynoteMar

18:45-19:00

Arrow’s strategy and priorities for FY27
Mailen LozdanArrow

Mar

19:00-19:05

Wrap-up

Mailen LozdanArrow

Mar

19:05-20:00

Cocktails at the beach

Azure beach bar

20:00-23:00

Dinner at the beach

Azure beach bar

Tuesday, 8 September

Where you see “WHAT WE’LL COVER”, click the dropdown for more information.

07:00-09:00

Breakfast

08:45-09:00

Welcome

09:00-09:45

Current attack patterns and Microsoft’s exposure-driven defense approach

Shachaf LevyMicrosoft

OverviewMar

WHAT WE’LL COVER

We will review the latest attack trends and how they are shaping customer security priorities. The session will connect these patterns to Microsoft’s exposure-driven defense approach and show how partners can help customers identify and reduce risk before attacks progress

09:45-10:30

Defend with AI: Agentic SOC

Maayan MagenheimMicrosoft

OverviewMar

WHAT WE’LL COVER

We will introduce the Agentic SOC concept and how Security Copilot works across Defender XDR and Sentinel. The session will show how AI can accelerate triage, investigation, and response while helping analysts work more consistently and efficiently.

10:30-11:00

BREAK

11:00-12:30

Intune – device & app management lab
Steven DeQuinceyMicrosoft Engineering

Hands-onMar

XDR Lab
Chris AyresMicrosoft Defender XDR CXE

Hands-onFlora

WHAT WE’LL COVER

This hands-on lab will cover practical device and application management scenarios with Intune. Participants will work through controls that help secure endpoints, enforce compliance, and support broader E5 security outcomes.

12:30-13:30

LUNCH

13:30-15:00

Intune – device & app management lab
Steven DeQuinceyMicrosoft Engineering

Hands-onMar

XDR Lab
Chris AyresMicrosoft Defender XDR CXE

Hands-onFlora

WHAT WE’LL COVER

This hands-on lab will cover practical device and application management scenarios with Intune. Participants will work through controls that help secure endpoints, enforce compliance, and support broader E5 security outcomes.

15:00-15:20

BREAK

15:20-16:00

Entra Suite – deep dive
Peter LenzkeMicrosoft

Deep diveMar

WHAT WE’LL COVER

We will go deeper into Entra Suite capabilities and how they support identity security across users, workloads, and emerging non-human identities. The session will cover identity governance, access controls, and how Entra strengthens Zero Trust architecture.

16:00-18:30

Chill at the beach

18:30-19:30

Free time

19:30-20:00

Cocktails and group photo

Bar de Lola

20:00-23:00

Dinner

Isola

Wednesday, 9 September

Where you see “WHAT WE’LL COVER”, click the dropdown for more information.

07:00-09:00

Breakfast

09:00-09:45

Sentinel + Defender XDR + Attack Disruption: end-to-end investigation and response

Ofer SchreiberMicrosoft

OverviewMar

WHAT WE’LL COVER

We will show how Sentinel and Defender XDR work together to support investigation, automation, and response. The session will highlight attack disruption and how Microsoft Security helps reduce time from detection to containment.

09:45-10:30

Multi tenancy and role-based access – deep dive

Ofer SchreiberMicrosoft

Deep diveMar

WHAT WE’LL COVER

We will cover how partners can manage access, permissions, and operational separation across multi-tenant customer environments. The session will focus on RBAC, delegation, and governance models that support secure partner operations.

10:30-11:00

BREAK

11:00-11:45

Safely enable AI
OverviewMar
WHAT WE’LL COVER

We will cover the technical controls needed to help customers adopt AI securely across identities, apps, data, and endpoints. The session will highlight the role of Entra, Defender, Purview, A365, and Defender for AI in reducing AI-related risk.

11:45-12:30

Trust AI with your Data
Thibault MartinMicrosoft

OverviewMar

WHAT WE’LL COVER

We will focus on how Purview helps customers protect, classify, and govern sensitive data in the AI era. The session will cover DLP, sensitivity labels, and data security controls that enable responsible AI adoption.

12:30-13:15

LUNCH

13:15-13:45

Get ready for AI (Secure now & MDASH)
OverviewMar
WHAT WE’LL COVER

We will walk through a practical technical readiness checklist for AI adoption. Partners will learn what to validate across identity, data, devices, apps, and SOC capabilities before customers scale AI usage. We will introduce MDASH and how it helps identify security gaps through code and configuration scanning. The session will show how partners can use these insights to prioritize remediation and strengthen customer environments.

13:45-14:45

Red and Blue team – Truesec (2 groups)
David Lilja and Viktor HedbergTruesec

Hands-onMar

WHAT WE’LL COVER

This hands-on session will simulate attacker and defender scenarios to reinforce real-world detection and response skills. Participants will see how Microsoft Security capabilities can be used to investigate,
contain, and respond to active threats.

14:45-15:15

BREAK

15:15-15:45

Multi-cloud posture + exposure management deep dive

Deep diveMar
WHAT WE’LL COVER

We will cover how Microsoft Security helps customers understand and reduce risk across multi-cloud environments. The session will connect cloud posture, exposure management, and prioritization of the most critical remediation actions.

16:00–16:30

Closing session – panel discussion, key takeaways, thank you’s and what’s next:
Arrow

Joint session EVERYONEMar

16:30-19:00

Snack time at the beach bar
Azure beach bar

20:00-20:30

Time to start our evening by the pool area
Pool area

20:30-02:00

Dinner and afterparty

Pool area