Loading…
Type: Security clear filter
Wednesday, April 15
 

1:30pm PDT

Role Alchemy: Forging Least-Privilege Roles from Cloud Logs with PowerShell
Wednesday April 15, 2026 1:30pm - 2:15pm PDT
Stop guessing at custom cloud roles and start deriving them from data. In dynamic environments like Azure, permission sprawl is a significant risk, where users and services accumulate excessive privileges in overly broad roles, such as "Contributor." This creates a massive, unnecessary attack surface that manual audits can't keep pace with. This session introduces a practical, PowerShell-driven pipeline that transforms this guesswork into a repeatable, data-driven security practice. We will demonstrate how to turn raw cloud activity logs into precise, least-privilege RBAC roles, all using code that works on both PowerShell 7 and Windows PowerShell 5.1. We will walk through the entire workflow: ingesting and shaping data into a user-action matrix, applying K-Means clustering to discover natural usage patterns, and using our custom "auto-k" algorithm to determine the optimal number of roles intelligently. This technique prevents both unmanageable "role explosion" and overly permissive mega-roles, producing a ready-to-deploy JSON role definition that reflects how your users *actually* work. To accelerate the final steps, we also showcase a strictly optional AI assistant that suggests business-friendly role names and descriptions—all while keeping a human firmly in the loop. You will leave with a blueprint to shrink your organization's attack surface and all the code needed to adapt this methodology for Azure, AWS, and Google Cloud.
Speakers
avatar for Frank Lesniak

Frank Lesniak

Sr. Cybersecurity & Enterprise Technology Architect, West Monroe
Frank Lesniak is a Sr. Cybersecurity & Enterprise Technology Architect at West Monroe with 20+ years of experience leading consulting engagements involving Microsoft infrastructure technology. His expertise spans modern cloud platforms such as Azure, Microsoft 365, and Entra ID, as... Read More →
avatar for Danny Stutz

Danny Stutz

Cybersecurity & Enterprise IT Architect, West Monroe
I am passionate about technology, learning new things, and working with computers! I love PowerShell and any automation tools I can use to help streamline my work and personal projects I work on. I specialize in Microsoft 365, Entra ID (Azure AD), AD, AWS, Azure and other cloud platforms... Read More →
Wednesday April 15, 2026 1:30pm - 2:15pm PDT
Meydenbauer Center - Room 405 11100 NE 6th St, Bellevue, WA 98004, USA
 
  • Filter By Date
  • Filter By Venue
  • Filter By Type
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.