Freitag, 15. März 2019

Focusing Cloud App Security Policies to dedicated Objects


In CAS we can focus policies to dedicated object. For example, you have a SharePoint Online Site with sensitive content, and you will get informed if a user is doing a mass download.
We can use the “Mass download by a single user” template to set up a policy:

In the filter section if the policy select “edit and preview results”:

In the shown activities list search for the location or event ion which you will filter. In my demo I take https://sharepointtalk.sharepoint.com/teams/SearchDemo2:

Selecting “Activity Objects” opens a report with all objects and its ID´s. To filter on the SharePoint SiteCollection URL we need the second one:

Now we can use this ID as a filter:

2 Kommentare:

  1. The article provides a practical example of using Cloud App Security policies to focus monitoring on a specific SharePoint Online site. The “Mass download by a single user” policy template is especially useful for detecting unusual download activity when sensitive content is involved.

    The approach of using “edit and preview results” to identify the relevant activity objects makes the filtering process much clearer. Using the SiteCollection object ID as a filter also provides a precise way to limit the policy to the intended SharePoint environment.

    This type of object-level monitoring is closely related to Cloud Security Projects, particularly when designing controls for protecting cloud-hosted data and detecting suspicious user activity.

    AntwortenLöschen
  2. The focus on protecting sensitive SharePoint content and controlling access activity also connects naturally with Information Security Projects, where identifying and responding to potentially unauthorized data movement is an important consideration.

    AntwortenLöschen