Magnus Mårtensson
Microsoft Regional Director, Azure MVP, CEO Loftysoft
Avirag Jain
Director & CTO R Systems
Mahesh Chand
Founder C# Corner, CEO Mindcracker
Chris Gali
CEO & Co-Founder Graphite
Subinder Khurana
Chief Architect StoryProcess, Founder NASSCOM DeepTech Club
Bryan Rishforth
Investor, Chairman Graphite
Bryn Everson
Director Biz Dev Graphite
Raj Tiwari
Digital Transformation Leader, Futurist and Visionary
Joseph Guadagno
Microsoft MVP, Lead Quicken Loans
Nikita Sachdev
Entrepreneur, Blockchain Enthusiast & Advisor, Social Media Influencer
Doug Wagner
COO & Founder Adapt Technical Group
Ritesh Modi
Architect, Senior Evangelist, Cloud Architect
Crystal Wenrick
Director Communications Mindcracker
Allen O’Neill
Microsoft MVP, Consulting Engineer/Architect
Praveen Kumar
CEO MCN Solutions
Chris Love
Founder Love2Dev, Microsoft MVP, Author
Sanjay Vyas
Microsoft Regional Director, Microsoft MVP, Founder & CEO SkillLabs Technologies
Veena Sarda
Deep Learning Consultant, Author
Sekhar Srinivasan
C# Corner MVP, Microsoft Certified Trainer, Pluralsight Author
Lalit Bansal
Founder & CEO - EIY SYS
Navdeep Garg
CEO Revinfotech
Prakash Tripathi
Tech Manager/Leader, Microsoft MVP, Blogger
Bhavna Jain
Breakthrough Consultant
Naveen Sharma
Enterprise Architect, Leadership Coach, Author
Vidya Vrat Agarwal
Principal Architect, Microsoft MVP, Author
Sheetal Agarwal
Founder Clownselors, Medical Clown, Trainer
Abhishek Kant
Founder GTM Catalyst
Vishnu Saran
Founder & CEO VoiceQube
Sandeep Soni
Founder & CEO Deccansoft, Microsoft Certified Trainer
Parveen Malik
AVP InfoSec & Vulnerability Management, Information Security Expert
Nitin Pandit
Microsoft MVP, Developer Evangelist, Author
Niloshima Srivastava
C# Corner MVP, Tech Architect, Trainer, Blogger
Bala Chirtsabesan
Senior Software Engineer at Microsoft, Author
Manoj Mittal
Sr. Technical Architect, C# Corner MVP, Author
Chandni Di
Co-Founder Voice of Slum
Vithal Wadje
Technical Lead, Microsoft MVP, Author
Shivam Ahuja
Founder SkillCircle, Business Mentor
Chervine Bhiwoo
Solution Architect, Microsoft MVP, Author
Saurabh Jain
Vice President Paytm, Founder Fun2Do Labs, Author
Vinay Solanki
Head IoT at Lenovo, Founder IoT-NCR
Anshu kumari
Founder Blockchainkids, Inventor, Trainer
Amit Singal
CEO Startup Buddy
Dev Pratap
Co-Founder & CEO Voice of Slum
Amey Vartak
Technology Consultant, Full Stack Developer, C# Corner MVP, Author
Viswanatha Swamy
Principal Software Engineer, C# Corner MVP, Author
Sanket Verma
Research Engineer @ Ballistics (Forensics) and Chair, PyData Delhi
Sourabh Somani
Lead Developer, Microsoft MVP, Author
Abhishek Mishra
Software Architect, C# Corner MVP, Author
Siddharth Vaghasia
Technical Consultant, C# Corner MVP, Blogger
Bassam Alugili
Senior Software Specialist, Database Expert
S Ravi Kumar
Solution Architect, C# Corner MVP, Author
Sundaram Subramanian
Full Stack Developer, C# Corner MVP, Speaker
Deepesh Somani
Solution Architect, Microsoft MVP, Author
Debasis Saha
Technical Project Manager, C# Corner MVP, Blogger, Author
Vipul Jain
Software Architect, C# Corner MVP, Author
Akshay Patel
Technical Architect, Microsoft Certified Trainer, C# Corner MVP, Author
Stephen Simon
RPA Developer, Evangelist, Author
Vivek Sharma
Founder Kingster636, AR/VR Specialist
Jeetendra Gund
Technical Lead, C# Corner MVP, Author
Sujal Beniwal
AI Enthusiast, Student
M Viknaraj
Microsoft MVP, Azure Architect, Author
Prasham Sabadra
Software Architect, C# Corner MVP, Trainer, Author
Aakash Maurya
Senior Developer, C# Corner MVP, Speaker
Ankit Sharma
Senior Software Engineer, C# Corner MVP, Author
Mangesh Gaherwar
Team Lead, C# Corner MVP, Author
Viral Jain
Technical Consultant, C# Corner MVP, Author
Bhasker Das
Solution Architect, Evangelist
Manish Dwivedi
Associate Project Manager
Ck Nitin
Programmer, Author
Rohit Gupta
Technical Trainer, Author
Manish Tewatia
Full-stack Marketer, UX Designer
Bhavya Gaur
Technical Illustrator
Rohit Tomar
SEO/SMO Expert
Web Track
Cloud & Data Track
Dev Track
Registration & Breakfast
Future of Desktop Apps with JS (ElectronJs)
Nitin Pandit
Building Serverless Microservices Using Microsoft Azure
Vithal Wadje
Innovating RPA: A Robot for Every Person
Stephen Simon
Managing Cloud Storage Accounts using Logic Apps
Viknaraj Manogararajah
Data visualization using Python
Sekhar Srinivasan
Going Cross platform with AR Foundation
Vivek Sharma
Keynote
Managing your Azure dependencies in ASP.NET Core apps using VS
Bala Chirtsabesan
Securing Applications on Intelligent Azure
Abhishek Mishra
Getting started with Blazor the Framework of Future
S Ravi Kumar
Lunch
Build Progressive Web Apps using Angular 9
Debasis Saha
Build and deploy to any platform using Azure DevOps
Chervine Bhiwoo
Deep Dive in Azure Service Bus
Akshay Patel
Build a Native Mobile Application using React Native and JavaScript
Joseph Guadagno
Making sense of Web Job, Web Job SDK and Functions in Azure
Prakash Tripathi
CloudFront Distribution in AWS
Viral Jain
Tea Break
Introduction to PowerBI
Aakash Maurya
Build Advanced SPFx solutions with React and Graph API
Siddharth Vaghasia
Build Business Intelligence Analyst (BIA) Skills
Sundaram Subramanian
Deep dive of Power Platform – AI BUILDER
Prasham Sabadra
Panel 1
What's new in SharePoint development
Vipul Jain
Build a SSO (Single Sign On) based Native JavaScript application with Microsoft Identity within 10 minutes
Manoj Mittal
Panel 2
Applications and working of AI
Veena Sarda
Deploying serverless API's with .Net core 3.0 on AWS & Azure
Amey Vartak
Panel 3
Blockchain with .NET Core (Ark)
Anshu Kumari
Closing Note & Prize Distribution
Dev Track
Cloud Track
Architecture Track
Emerging Tech Track
Registration & Breakfast
Creating Full-Stack Web Apps Using Server-Side Blazor
Ankit Sharma
Real time face recognition with MS Cognitive Services
Niloshima Srivastava
Building Scalable APIs with GraphQL
Jeetendra Gund
Future of development with AI and Blockchain
Navdeep Garg
Debugging Tips and Tricks with Visual Studio 2019
Joseph Guadagno
Azure Containers
Abhishek Kant
Enterprise Architecture
Naveen Sharma
Bot Framework - learn it fast and look like a boss!
Allen O’Neill
Keynote
.Net Core & C# 8 Performance
David McCarter
Working with Azure kubernetes services
Ritesh Modi
Becoming an Architect
Vidyavrat Agarwal
Why Techies Need to Learn Product Management
Saurabh Jain
Lunch
Build a rules engine in .Net Core
Sanjay Vyas
Building CI and CD Pipeline using Azure DevOps
Sandeep Soni
Entity Framework Core - Tips and Tricks, Performance Optimization, and Tuning
Bassam Alugili
Hacking your way into Data Science
Sanket Verma
Speed up your .Net Core Website
Sourabh Somani
Azure
Magnus Mårtensson
Demystifying Open Distro for Elasticsearch
Suman Debnath
Future of Data
Shivam Ahuja
Tea Break
gRPC with C# and .Net Core
Mangesh Gaherwar
Panel 1
Essentials of Cloud security
Parveen Malik
Power platform and Dynamics 365
Deepesh Somani
Microservices - the gRPC Way
Viswanatha Swamy
Panel 2
Reserved
Reserved
Closing Note & Prize Distribution
Using Azure Policy to Enforce Security Standards for .NET Resources
Australian development teams operating in Sydney, Melbourne, Brisbane, and Perth have spent the last few years shifting .NET workloads into Azure regions such as Australia East and Australia Southeast. That migration brings speed and scale, but it also brings the question of how to keep every resource — from App Service plans to Storage accounts backing an API — aligned with security baselines. Azure Policy answers that question by turning written rules into automated guardrails, so that every .NET deployment, whether authored by a contractor in Parramatta or a permanent team in Docklands, is judged against the same controls.
The technology is essentially a policy-as-code engine built directly into the Azure control plane. Engineers can author definitions in JSON, group them into initiatives, and assign those initiatives at management group, subscription, or resource group scope. When a .NET developer spins up a new Azure SQL database, a Linux App Service, or a Key Vault instance, the platform evaluates the request against the assigned policies before the resource is created. Anything that violates a rule is denied, audited, or remediated, depending on the chosen effect.
Why governance matters for .NET workloads hosted in Azure
.NET applications rarely live in isolation. A modern solution typically weaves together App Service, Functions, API Management, Azure SQL, Storage, Key Vault, Application Insights, and sometimes Container Apps. Each of those components exposes its own configuration surface, and small mistakes compound quickly. A Storage account with public blob access enabled, or a Cosmos DB account without Entra ID-only authentication, can quietly create a path for data leakage. Azure Policy lets platform engineers encode these expectations once, then apply them across every subscription that hosts a .NET estate.
The regulatory environment in Australia adds weight to this conversation. Many enterprises fall under the Prudential Standard CPS 234 from APRA, the Notifiable Data Breaches scheme, or the Australian Privacy Principles enforced by the Office of the Australian Information Commissioner. Healthcare providers interact with the My Health Records Act, while government agencies follow the Australian Government Information Security Manual. Azure Policy initiatives can be tailored to mirror these obligations, mapping controls such as "audit VMs without managed identity" or "deny Storage accounts without private endpoints" to specific compliance frameworks.
There is also a practical engineering benefit. When teams in Adelaide or the Sunshine Coast onboard a new .NET microservice, the policy assignment already guarantees that resources comply with encryption, tagging, and diagnostic settings. Code reviewers stop arguing about infrastructure hygiene and focus on business behaviour. Time spent in pull-request discussions shrinks, and production incidents caused by misconfigured resources drop noticeably.
Core building blocks of Azure Policy for .NET deployments
The vocabulary of Azure Policy is small but precise. A definition describes a rule using JSON, with an if block that selects resources through Azure Resource Graph queries and a then block that declares what should happen. An initiative bundles several definitions into a single assignment, which is convenient when representing a complete standard such as the CIS Microsoft Azure Foundations Benchmark. An assignment binds the definition or initiative to a scope, and an effect determines the action: Deny, Audit, Append, Modify, DeployIfNotExists, or AuditIfNotExists.
For .NET workloads, the most common effects are Deny for hard guardrails (such as blocking public Storage blobs), Audit for visibility (such as reporting App Service instances without HTTPS only), and Modify for lightweight remediation (such as adding a missing tag or configuring minimum TLS version). DeployIfNotExists is valuable when a resource must always travel with a companion — for example, ensuring every App Service has Application Insights linked through a DeployIfNotExists rule that adds the instrumentation key.
| Effect | When to use it for .NET resources | Example scenario | Risk if misapplied |
|---|---|---|---|
| Deny | Hard guardrails that must never be bypassed | Blocking Storage accounts without supportsHttpsTrafficOnly: true |
Too many denies block legitimate work |
| Audit | Visibility without disruption | Reporting API Management instances without diagnostic logs | None — purely informational |
| Modify | Auto-correcting minor gaps | Adding environment tag to App Service plans |
Modifying wrong fields can break apps |
| DeployIfNotExists | Ensuring a companion resource exists | Attaching Defender for App Service to every plan | Slows deployment at scale |
Built-in definitions cover many scenarios out of the box. The "Audit Windows VMs without managed identity" rule, "Deny storage accounts without minimum TLS version 1.2", and "Append tag and its value to resources" definitions are useful starting points. Custom definitions extend these patterns, and the Azure Policy GitHub repository hosts community samples that can be cloned and adapted.
Authoring and assigning policies for .NET scenarios
Most teams start by running the Azure Policy compliance scan against a pilot subscription. The portal's Compliance blade surfaces non-compliant resources, which often include legacy App Service plans with managed identity disabled, classic Storage accounts, and older API Management SKUs. Once the baseline is understood, an initiative is authored that combines relevant built-in definitions with a small number of custom rules tailored to .NET realities.
A useful custom pattern is to enforce secure deployment practices for .NET APIs. A definition can use the Microsoft.Web/sites resource type, check kind equals api, and assert that httpsOnly is true, clientAffinityEnabled is false, and siteConfig.minTlsVersion is at least 1.2. Another definition can target Microsoft.Sql/servers and require an Azure AD administrator, which matters when .NET services connect using Microsoft Entra authentication. Yet another can target Microsoft.KeyVault/vaults and require that enableSoftDelete is true and enablePurgeProtection is enabled, since many .NET apps cache secrets in vault references.
Common custom patterns worth adding to a .NET initiative include:
- Deny App Service deployments without HTTPS only and minimum TLS 1.2
- Require an Azure AD administrator on every SQL server used by .NET data services
- Enforce Key Vault soft delete and purge protection on secret references
- Append standard tags such as environment, ownerEmail, and costCentre to new resources
Assignment is where the rules become real. Many Australian enterprises attach the initiative at the management group that covers their production landing zones, while leaving developer subscriptions in Audit mode so that experimentation is not blocked. A common pattern is to maintain two parallel initiatives — one strict assignment for production with Deny effects, and one advisory assignment for non-production with Audit and DeployIfNotExists effects. Exemptions can be granted through the policy exemption feature, with an expiry date and a business justification stored alongside it.
When teams adopt Infrastructure-as-Code using Bicep or Terraform, policy assignments can be co-deployed with the platform resources, ensuring that every new subscription comes with the governance baseline already attached. This reduces the chance of a well-meaning developer spinning up an environment that escapes review.
Operational workflow and tooling around Azure Policy
Policy work is never finished. Definitions need versioning, initiatives need revision histories, and assignments drift as subscriptions move. The recommended workflow is to store definitions in a Git repository, review changes through pull requests, and deploy them through a pipeline that uses the Azure CLI, PowerShell, or AzOps. This mirrors the same engineering discipline that .NET developers already apply to application code, and it keeps governance auditable.
Remediation tasks handle existing non-compliant resources. When a definition such as "Configure Azure Activity log to use a specified workspace" is assigned with DeployIfNotExists, Azure creates a remediation task that lists each non-compliant resource. Engineers can trigger remediation from the portal, run it through PowerShell with Start-AzPolicyRemediation, or wire it into a GitHub Actions pipeline that runs nightly against staging environments before promoting to production.
Monitoring closes the loop. Activity log events, compliance state changes, and remediation outcomes can be streamed into a Log Analytics workspace. A simple Kusto query such as PolicyStates | where IsCompliant == false | summarize count() by PolicyDefinitionName gives a quick view of which rules are firing most often. Many Australian platform teams ship a Power BI dashboard on top of Log Analytics, surfacing compliance percentages per business unit. This data also feeds internal risk reviews, which often include the chief information security officer and representatives from legal and finance.
A practical checklist for day-to-day operations looks like this:
- Review non-compliant resources weekly through the Compliance blade
- Triage remediation tasks before they age beyond thirty days
- Reassign expired exemptions or convert them into compliant resources
- Refresh built-in definitions quarterly to pick up new Microsoft releases
For teams adopting GitOps, the same repository that stores Bicep modules for .NET APIs can hold policy definitions. Pull-request reviewers can then validate that a new rule does not accidentally break production workloads by checking the assignment scope and exemption list before merge.
Scaling maturity across multiple Australian teams
Once a single subscription is governed, the next step is extending the model across the organisation. A federated model works well for distributed teams in places like Canberra, Hobart, and the Gold Coast. Platform engineering owns the canonical initiative, while individual business units can layer additional definitions through subscription-level assignments. This balance preserves central standards while allowing local flexibility, which is important when teams have different workloads and risk appetites.
Maturity shows up in concrete habits that are easy to observe:
- Every .NET service carries an ownerEmail tag, enforced by a Modify policy and audited monthly
- Non-compliance trends are reviewed in a recurring governance forum with finance and security representatives
- The policy codebase is versioned semantically, with deprecation notices and migration guides whenever behaviour changes
The long-term value of Azure Policy for .NET resources is that security standards become a property of the platform rather than a checklist that developers remember to follow. New services inherit compliance automatically, and the cost of maintaining a secure posture decreases over time. Australian organisations that combine Azure Policy with broader practices — defender for cloud, secure DevOps pipelines, and threat modelling — find that their .NET estates become measurably safer without slowing delivery.
1, CBD, Maharaj Surajmal Road, Near Yamuna Sports Complex, Delhi, 110032
GENERAL QUERIES
Manish Tewatia
manish@csharpcon.com
+91-9718-431-042
TICKET QUERIES
Atul Gupta
conference@csharpcon.com
+91-9910-125-804