Maple
Maple Fox is a Melbourne-based security engineer, researcher, and community organiser working across cloud and platform security, identity-first design, Zero Trust, SIEM/SOAR, security automation, and critical infrastructure cyber security.
Maple works hands-on with Microsoft Entra, Azure, AWS, Sentinel, Intune, Terraform, Go, Python, SAML/OIDC, FIDO2, firewall integrations, and secure access patterns. Their work spans identity baselines, detection engineering, secure cloud guardrails, Zero Trust access orchestration, and practical security evidence for audit and uplift programmes.
Maple is currently completing a Master of Cyber Security at Deakin University, with research focused on machine-readable security intent, policy compilation, and bounded reachability verification. They also have practical experience supporting SOCI- and AEMO-focused cyber security gap assessments for critical infrastructure and OT environments, including SCADA, communications, remote access, BESS-style infrastructure, and OT/cloud boundary controls.
Alongside industry work, Maple teaches cyber security at Deakin University and contributes heavily to the Australian cyber community. They founded Deakin University Cybersecurity Association, helped scale it into a large student community, and co-chair ACUCyS, supporting collaboration across Australian university cyber clubs.
Maple likes building practical labs, tools, diagrams, demos, and repeatable methods that turn security ideas into evidence. Their current interests include secure OT connectivity, identity-aware access control, Zero Trust engineering, detection-as-code, and proving when "policy" actually matches what systems can reach.
Session
Identity used to be the front door. Now it is the keys, the key cabinet, the floor plan, the alarm panel, and sometimes the weird emergency exit nobody has checked since 2021.
Most organisations have put serious effort into endpoint alerts, phishing workflows, firewall rules, and dashboards. But the thing that quietly decides who can access almost everything is often treated as setup work: turn on MFA, plug in SSO, add Conditional Access, connect SCIM, move on.
That is fine until someone uses a break-glass account, a privileged role lights up, a password manager owner gets added, a Conditional Access exclusion becomes the easiest path in, or SCIM decides to "help" by removing the wrong person from the wrong place.
This talk is about hunting the identity control plane before it becomes an incident. We will walk through realistic Entra, SCIM, PIM, and password-manager failure modes, then turn those messy admin events into useful detections, triage paths, and response actions.
Expect practical examples, awkward edge cases, noisy logs, bad assumptions, and the occasional reminder that "we logged it somewhere" is not the same thing as "someone can respond to it at 2am."