Explore the latest Lead with Microsoft Security agenda and speaker information in one place.
Use the buttons below to view speaker details, agenda tracks, session information, and key timings to help you plan your event experience.
| TIME | SESSION | SPEAKER | TYPE | VENUE | WHAT WE’LL COVER |
|---|---|---|---|---|---|
| 13:30-15:00 | Lunch (optional, for those who pre-registered) | Isola | |||
| 15:00-16:00 | Registration and check-in | Reception | |||
| 16:30-17:00 | Mingle & snacks | Bar de Lola | |||
| 17:00-17:10 |
Welcome & set the scene |
Mailen Lozdan – Arrow | Mar | ||
| 17:10-17:40 |
Arrow’s strategy and prio for FY27+ introducing the MS & Arrow teams |
Mailen Lozdan – Arrow | Keynote | Mar | |
| 17:40-18:00 | CVC | Franck Dauché – Microsoft | Keynote | Mar | |
| 18:00-18:30 |
What do we see at Arrow? |
Keynote | Mar | ||
| 18:30-19:00 |
Partner keynote | Security & AI |
CAG | Keynote | Mar | |
| 19:00-19:05 | Wrap-up | Mailen Lozdan – Arrow | Mar | ||
| 19:05-20:00 | Cocktails at the beach | Azure beach bar | |||
| 20:00-23:00 | Dinner at the beach | Azure beach bar |
| TIME | SESSION | SPEAKER | TYPE | VENUE | WHAT WE’LL COVER |
|---|---|---|---|---|---|
| 07:00-09:00 | Breakfast | ||||
| 09:00-09:45 |
Current attack patterns and Microsoft’s exposure-driven defense approach |
Shachaf Levy – Microsoft | Overview | Mar | We will review the latest attack trends and how they are shaping customer security priorities. The session will connect these patterns to Microsoft’s exposure-driven defense approach and show how partners can help customers identify and reduce risk before attacks progress |
| 09:45-10:30 |
Defend with AI: Agentic SOC |
Maayan Magenheim – Microsoft | Overview | Mar |
We will introduce the Agentic SOC concept and how Security Copilot works across Defender XDR and Sentinel. The session will show how AI can accelerate triage, investigation, and response while helping analysts work more consistently and efficiently. |
| 10:30-11:00 | BREAK | ||||
| 11:00-12:30 |
Intune – device & app management lab/Steven DeQuincey |
Chris Ayres – Microsoft – XDR lab |
Hands-on | Mar/Flora |
This hands-on lab will cover practical device and application management scenarios with Intune. Participants will work through controls that help secure endpoints, enforce compliance, and support broader E5 security outcomes. |
| 12:30-13:30 | LUNCH | ||||
| 13:30-15:00 |
Intune – device & app management lab/Steven DeQuincey |
Chris Ayres – Microsoft – XDR lab |
Hands-on | Mar/Flora |
This hands-on lab will cover practical device and application management scenarios with Intune. Participants will work through controls that help secure endpoints, enforce compliance, and support broader E5 security outcomes. |
| 15:00-15:20 | BREAK | ||||
| 15:20-16:00 | Entra Suite – deep dive | Peter Lenzke – Microsoft | Deep dive | Mar |
We will go deeper into Entra Suite capabilities and how they support identity security across users, workloads, and emerging non-human identities. The session will cover identity governance, access controls, and how Entra strengthens Zero Trust architecture. |
| 16:00-18:30 | Chill at the beach | ||||
| 18:30-19:30 | Free time | ||||
| 19:30-20:00 | Cocktails and group photo | Bar de Lola | |||
| 20:00-23:00 | Dinner | Isola |
| TIME | SESSION | SPEAKER | TYPE | VENUE | WHAT WE’LL COVER |
|---|---|---|---|---|---|
| 07:00-09:00 | Breakfast | ||||
| 09:00-09:45 |
Sentinel + Defender XDR + Attack Disruption: end-to-end investigation and response |
Ofer Schreiber – Microsoft | Overview | Mar | We will show how Sentinel and Defender XDR work together to support investigation, automation, and response. The session will highlight attack disruption and how Microsoft Security helps reduce time from detection to containment. |
| 09:45-10:30 |
Multi tenancy and role-based access – deep dive |
Ofer Schreiber – Microsoft | Deep dive | Mar | We will cover how partners can manage access, permissions, and operational separation across multi-tenant customer environments. The session will focus on RBAC, delegation, and governance models that support secure partner operations. |
| 10:30-11:00 | BREAK | ||||
| 11:00-11:45 | Safely enable AI | Overview | Mar | We will cover the technical controls needed to help customers adopt AI securely across identities, apps, data, and endpoints. The session will highlight the role of Entra, Defender, Purview, A365, and Defender for AI in reducing AI-related risk. | |
| 11:45-12:30 | Trust AI with your Data | Thibault Martin – Microsoft | Overview | Mar | We will focus on how Purview helps customers protect, classify, and govern sensitive data in the AI era. The session will cover DLP, sensitivity labels, and data security controls that enable responsible AI adoption. |
| 12:30-13:15 | LUNCH | ||||
| 13:15-13:45 |
Get ready for AI (Secure now & MDASH) |
Overview | Mar | We will walk through a practical technical readiness checklist for AI adoption. Partners will learn what to validate across identity, data, devices, apps, and SOC capabilities before customers scale AI usage. We will introduce MDASH and how it helps identify security gaps through code and configuration scanning. The session will show how partners can use these insights to prioritize remediation and strengthen customer environments. | |
| 13:45-14:45 |
Red & Blue team – Truesec (2 groups) |
David Lilja & Viktor Hedberg – Truesec | Hands-on | Mar | This hands-on session will simulate attacker and defender scenarios to reinforce real-world detection and response skills. Participants will see how Microsoft Security capabilities can be used to investigate, contain, and respond to active threats. |
| 14:45-15:15 | BREAK | ||||
| 15:15-15:45 |
Multi-cloud posture + exposure management deep dive |
Deep dive | Mar | We will cover how Microsoft Security helps customers understand and reduce risk across multi-cloud environments. The session will connect cloud posture, exposure management, and prioritization of the most critical remediation actions. |
|
| 15:45–16:15 | Closing session | Overview | Mar | ||
| 16:30-19:00 | Optional snacks |
Azure beach bar |
|||
| 20:00-20:30 | Cocktails by the pool | Pool area | |||
| 20:30-02:00 | Dinner + afterparty | Pool area |