Zero Trust Days 2026 – Tunis
The Zero Trust French Community is organizing an event dedicated to Microsoft 365 security with a Zero Trust approach:
Never trust, always verify applied concretely to identity, data, AI, and hybrid environments.
Objective
Deliver practical and actionable sessions, focused on real-world implementation, to help organizations secure Microsoft 365 and its ecosystem while accelerating cloud and AI adoption.
We are looking for content that goes beyond theory:
✔ Real-world experiences
✔ Architectures
✔ Best practices
✔ Common mistakes
✔ Demos
✔ Implementation recommendations
Tracks & Main Topics
1) IAM / Identity & Access (Microsoft Entra)
- Conditional Access (strategies, session controls, device compliance)
- MFA / Passwordless (FIDO2, WHfB), Authentication Strengths
- Identity Protection, PIM, Identity Governance, identity lifecycle (B2B/guests)
- Zero Trust identity for apps, APIs, workloads, and hybrid environments
2) Data Protection / DLP / Compliance (Microsoft Purview)
- Sensitivity Labels, encryption, auto-labeling, MIP Scanner
- DLP (Endpoint, Exchange, SharePoint/OneDrive, Teams): modes, exceptions, UX, tuning
- Insider Risk, eDiscovery, audit, retention, records management
- Data classification strategy: taxonomy, quick wins, adoption and change management
3) AI & Security (Copilot, agents, governance)
- Governance and control of AI usage (copilots/agents) in Microsoft 365
- Protection against data leakage via prompts, content exposure, and “oversharing”
- Access models, permissions, and security of connectors/data sources
- “Secure-by-design” approaches for enterprise AI
4) Data & Governance (Cross-cutting vision)
- Data governance strategy before AI: quality, access, exposure, sharing
- “Data security posture”: mapping, risks, prioritization, KPIs
- Aligning security / compliance / business needs (use cases, business impact)
5) Infrastructure & Endpoint Security (MDE / Intune / hybrid)
- Endpoint security (Defender for Endpoint, ASR, EDR, TVM)
- Intune, device posture, compliance, configuration baselines
- Hybrid security: resource access, segmentation, posture, SOC integration
Zero Trust Days 2026 – Tunis
La Zero Trust French Community organise un événement dédié à la sécurité Microsoft 365 avec une approche Zero Trust :
Never trust, always verify appliqué concrètement à l’identité, la donnée, l’IA et les environnements hybrides.
Objectif
Proposer des sessions pragmatiques et actionnables, orientées terrain, pour aider les organisations à sécuriser Microsoft 365 et son écosystème, tout en accélérant l’adoption du cloud et de l’IA.
Nous recherchons des contenus au-delà de la théorie :
✔ Retours d’expérience
✔ Architectures
✔ Bonnes pratiques
✔ Erreurs fréquentes
✔ Démos
✔ Recommandations de mise en œuvre
Tracks & Thématiques principales
1) IAM / Identity & Access (Microsoft Entra)
- Conditional Access (stratégies, session controls, device compliance)
- MFA / Passwordless (FIDO2, WHfB), Authentication Strengths
- Identity Protection, PIM, Identity Governance, lifecycle des identités (B2B/guests)
- Zero Trust identity pour apps, API, workloads, environnements hybrides
2) Data Protection / DLP / Compliance (Microsoft Purview)
- Sensitivity Labels, chiffrement, auto-labeling, MIP Scanner
- DLP (Endpoint, Exchange, SharePoint/OneDrive, Teams) : modes, exceptions, UX, tuning
- Insider Risk, eDiscovery, audit, rétention, records management
- Stratégie de classification de données : taxonomie, quick wins, adoption et conduite du changement
3) IA & Sécurité (Copilot, agents, gouvernance)
- Gouvernance et contrôle des usages IA (copilots/agents) dans Microsoft 365
- Protection contre fuite de données via prompts, exposition des contenus, “oversharing”
- Modèles d’accès, permissions, sécurité des connecteurs / sources de données
- Approches “secure-by-design” pour l’IA en entreprise
4) Data & Governance (Vision transverse)
- Stratégie de gouvernance de la donnée avant l’IA : qualité, accès, exposition, partage
- “Data security posture” : cartographie, risques, priorisation, KPI
- Alignement sécurité / conformité / métiers (use cases, business impact)
5) Infra & Endpoint Security (MDE / Intune / hybrid)
- Sécurisation des endpoints (Defender for Endpoint, ASR, EDR, TVM)
- Intune, posture device, compliance, configuration baselines
- Sécurité hybride : accès aux ressources, segmentation, posture, intégration SOC


.png&w=3840&q=85)