Posts mit dem Label AIP werden angezeigt. Alle Posts anzeigen
Posts mit dem Label AIP werden angezeigt. Alle Posts anzeigen

Montag, 21. September 2020

Secure your environment by Conditional Access & App Controls

With the Azure AD Conditional Access feature, rules for access to Microsoft Cloud Services and other apps registered in Azure AD can be bound to conditions.

An example is the rule: When accessing with an unmanaged device, the user is prompted to use multi-factor authentication.

With the feature "Use Conditional Access App Control" as an option in the Session Controls area within Azure AD Conditional Access, advanced scenarios can be setup.

Options:

  • Prevent data exfiltration
  • Protect on download
  • Prevent upload of unlabeled files
  • Block potential malware
  • Monitor user sessions for compliance
  • Block access
  • Block custom activities

Example:

  • Automatically assign a sensitivity label when a file is downloaded.
  • Filter based on regular expressions: “Include Files that match a custom expression
  • Block Upload if Maleware is detected.
  • This is can be done because the Cloud App Security service then acts as a proxy for accessing the application:

Setup Conditional Access App Control

The options listed above affect all resisted apps under https://portal.cloudappsecurity.com/#/connected-apps?tab=proxy.  By default, this list is empty:

To register an app, the wizard can be used in Cloud App Security via Investigate -> Connected Apps -> Conditional Access App Control Apps. Another and much simpler way is to use a conditional access policy as an easy start:

  • Azure AD Security -> Conditional Access

  • New Policy

  • Section „Access controls“ -> „Session“

  • Use „Use Conditional Access App Control“

  • Use „Use custom policy to set an advanced policy in Cloud App Security“



Configure the policy in the menus "Users and Groups" etc. that it will be applied the next time the app to be registered is started. This then results in apps that are authenticated via Azure AD being automatically registered in Cloud App Security under „Conditional Access App Control“:

The above method works for the so called featured apps. In order to make this option work for the Office 365 Featured Apps, Office 365 must be registered under "Connected Apps" in Cloud App Security:

Once an app is registered, session policies can be created that will take effect when the app is used.

Example: If the user Oliver Hardy tries to download a document from Microsoft Teams (SharePoint) that contains the term "confidential", the download is blocked.

Further scenarios

  • Monitor / block activities based on file conditions like Classification Label, File Name, Files Size or File Extension
  • Monitor / block activities like Cut/Copy Item, Paste Item, Print Item, Send Item
  • Block downloads based on conditions
  • Apply classification label to downloads
  • Apply rules based on Maleware detection

Impact from the user's perspective

When opening the app, the user is notified that access is monitored by Cloud App Security. The fact that a proxy is involved can also be recognized by the URL. This now has the addition access-control.cas.ms:

If the user Oliver Hardy now tries to download a document he gets the following message:










Montag, 17. Februar 2020

Microsoft Information Protection and the Preview Programs

Overview

Since several month the new unified labeling feature in Office 365 is available. We can easily migration AIP labels from Azure to unified labeling in Office 365. For more details and a step-by-step guide see here: LINK
Since unified labels are rollout out Microsoft is in the middle of its journey to “Microsoft Information Protection”. This new solution combines Azure Information Protection and Labels in Office 365. It integrates DLP features and even new capabilities like “Site and group settings” focusing to Office 365 Groups / Teams and SharePoint:
And also other new feature like auto-classification with sensitivity Labels in SharePoint Online and OneDrive for Business which is a separate preview:
This new feature includes a Policy Simulation to test a policy bevor it is deployed in your Office 365 Tenant.
Selecting the policy opens the overview containing the Policy Simulation results

Available Public Preview Programs

Donnerstag, 16. Januar 2020

New Unified Labeling AIP client


The AIP Team announced details about the new Unified Labeling AIP client
A new public preview version is available:  http://aka.ms/aipclient.
There are a couple of new things in this version:
  • Dynamic content marking
  • Per app content making
  • Offline policy support
  • Protection removal for pst, msg and archive files

But still some to-dos left on to close the gaps between classic and UL client
  • Event log support. This is planned for Q2 2020
  • HYOK – customers using HYOK can contact Microsoft Support to join the private preview for new HYOK release.
  • New flow will be released later this year to enable end users to revoke protected documents and admins to track protected documents.
All the new features are shipped in Unified Labeling client only:
  • Improvements for migrations from 3rd party labeling solutions to MIP
  • Scanner improvements
    • Easier SharePoint on-premises and subsite discovery. Setting each specific site is no longer required.
    • Optimizations or SQL DB used by the scanner
    • Ability to stop scans


Montag, 6. Januar 2020

Goodbye Azur Information Protection

Deprecation of AIP Classic client and Label Management in Azure portal

Microsoft announced the deprecation of label management in Azure portal and AIP classic client: http://aka.ms/aipclassicsunset
What does it mean for you?
  • Label management in Azure portal will not be supported after March 31, 2021.
  • Customers should activate unified labeling and move to Microsoft 365 Security and Compliance Center.
  • AIP Classic client will not be supported after March 31, 2021.
  • Customers should use the built-in labeling in Office ProPlus as the preferred option or upgrade to AIP Unified Labeling Client. More Information about built-in sensitivity labels support in Office ProPlus here: LINK

Features not planned to be in the Azure Information Protection unified labeling client

Azure Information Protection unified labeling client is still under development, the following features from the classic client will not be available in future releases for the unified labeling client:
  • Custom permissions as a separate option that users can select in Office apps: Word, Excel, and PowerPoint
  • Track and revoke from Office apps and File Explorer
  • Information Protection bar title and tooltip
  • Protection-only mode (no labels) using templates
  • Protect PDF document as .ppdf format
  • Display the Do Not Forward button in Outlook
  • Demo policy
  • Justification for removing protection
  • Confirmation prompt Do you want to delete this label? for users when you don't use the policy setting for justification
  • Separate PowerShell cmdlets to connect to a Rights Management service
  • Features that Microsoft do not plan to ship for Unified Labeling are deprecated from March 31, 2021.

What should customers do if they use an AIP features that will not be available in Unified Labeling?

If a customer is using or waiting for features that are planned to ship like HYOK, Track and Revoke, Event Log for AIP Client etc. These customers can file a File for extended support. The form allows customers to ask for extended support. Details:
  • Customer must specify the reason for extended support and provide Microsoft with number of impacted users.
  • Customer must activate unified labeling before 3/31/2020 to be able to ask for extended support.
  • Customer must file the request for extended support before 3/31/2020.

Samstag, 5. Oktober 2019

Microsoft Security Stack - When to use what


When to use what – Azure Sentinel, CASB, Azure Security Center, Security & Compliance Center in Office 365, etc.

Many customers using Microsoft Cloud Services in the context of collaboration und communication often asked the “When to use what” question. Meanwhile we had several really good methods and tools to answer this question like the Periodic Table of Office 365. At the end it is not about when to use what, it is about “what do you want to do” or “what is your business case”? And this is the same with the Microsoft Security Features & Services.

Features & Services

Microsoft Azure Sentinel is a cloud-native SIEM solution with advanced AI and security analysis capabilities.

Microsoft Cloud App Security is a multimode Cloud Access Security Broker (CASB). It provides rich visibility, control over data travel, and sophisticated analytics to identify and combat cyberthreats across all your cloud services. Further infos about CASB

Azure Security Center provides unified security management and advanced threat protection across hybrid cloud workloads.

Office 365 Security & Compliance Center is designed to manage security & compliance features across Office 365. Links to existing SharePoint and Exchange compliance features bring together compliance capabilities across Office 365.

Microsoft Intune is a management solution that provides mobile device, endpoint and operating system management. It aims to provide Unified Endpoint Management for corporate devices and BYOD.

Azure Active Directory (Azure AD) is Microsoft’s cloud-based identity and access management service. It covers resources, such as Microsoft Office 365, the Azure portal, and thousands of other SaaS applications along with any cloud apps developed by your own organization.

Microsoft Information Protection helps an organization to classify and protect its documents and emails by applying labels. It helps you discover, classify, label and protect your sensitive information – wherever it lives or travels. Further infos about Information Protection

Protect your enterprise from threats in the cloud and on-premises with Azure Advanced Threat Protection. ATP is a cloud-based security solution that leverages your on-premises Active Directory signals to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions directed at your organization.

Microsoft Defender Advanced Threat Protection (ATP) is a unified platform for preventative protection, post-breach detection, automated investigation, and response. Microsoft Defender ATP is built into Windows 10.


Typic discussions with customers

Azure Sentinel vs. Azure Security Center

Azure Security Center is focusing on Azure workloads. Azure Sentinel is used to for real-time event and detecting attacks covering your hole architecture.
Quote by Microsoft: To reduce confusion and simplify the user experience, two of the early SIEM-like features in Security Center, namely investigation flow in security alerts and custom alerts will be removed in the near future. Individual alerts remain in Security center, and there are equivalents for both security alerts and custom alerts in Azure Sentinel. Going forward, Microsoft will continue to invest in both Azure Security Center and Azure Sentinel. Azure Security Center will continue to be the unified infrastructure security management system for cloud security posture management and cloud workload protection. Azure Sentinel will continue to focus on SIEM. Source: Securing the hybrid cloud with Azure Security Center and Azure Sentinel


Azure Security Center vs. Security and Compliance Center in Office 365

The Office 365 Security & Compliance Center is designed to help you manage security & compliance features across Office 365. Links to existing SharePoint and Exchange compliance features bring together compliance capabilities across Office 365. Azure Security Center analyzes data from a variety of Microsoft and also partner solutions. To take advantage of this data, machine learning for threat prevention, detection, and eventually investigation. Both services are part of the Microsoft Service Trust Platform


Azure Sentinel vs. CASB

Azure Sentinel is a SIEM solution with advanced AI and security analysis capabilities. It integrates with third-party security platforms from vendors such as Fortinet, Symantec and Check Point, as well as Microsoft's Graph Security API. By connecting with Microsoft Cloud App Security, you will gain visibility into your cloud apps, get sophisticated analytics to identify and combat cyberthreats, and control how your data travels.


Office 365 Security Features vs. Intune

Microsoft Intune and built-in security features in Office 365 for MDM both give you the ability to manage security & compliance in your environment. You can manage security & compliance using both Intune and Office 365 in the same Office 365 tenant. If you have both options available, you can choose whether you manage security & compliance in Office 365 or the more feature-rich Intune solution for MDM and MAM scenarios.


Azure AD vs. Intune

Intune manages mobile devices and apps. It integrates closely with other EMS components like Azure Active Directory for identity and access control.


Azure Advanced Threat Protection vs. Microsoft Defender ATP

Azure Advanced Threat Protection enables you to integrate Azure ATP with Windows Defender ATP. While Azure ATP monitors the traffic on your domain controllers, Windows Defender ATP monitors your endpoints, together providing a single interface from which you can protect your environment. By integrating Windows Defender ATP into Azure ATP, you can leverage the full power of both services and secure your environment. Source & Details: Integrate Azure ATP with Windows Defender ATP


Roundup

As you can see all this features work together like for example Microsoft Defender Advanced Threat Protection integration with Microsoft Cloud App Security or Azure Information Protection integration with Cloud App Security So trying to find the best tool / solution for your enterprise only discussing the detailed features isn’t the best way.

How to get started

To get a solid Security & Compliance strategy based on the Microsoft Security Stack the best way is to start with your scenarios. Dealing with the Microsoft Security Stack a best practices approach is to separate the topics like this:

Next step is to map the scenarios:
  • Protect at the front door
  • Protect your data anywhere
  • Detect & remediate attacks
to those 4 categories / topics:
  • Identity and access management
  • Mobile device & app management
  • Information protection
  • Threat protection

Periodic table & mapping

Microsoft offers a good overview to tweak your scenarios in this article Top 10 Actions to Secure Your Environment. Based on this the following overview offers a blueprint to get started with your security strategy:

Architecture


Roundup

From a planning and architecture perspective the features and services must be separated in monitoring solution and solution used to natively setup regulations and policies.
For example: You can use Information Protection to protect you content and E-Mails and in addition you can integrate the Logs and Signals coming from Information Protection to Azure Sentinel. But natively you cannot use Azure Sentinel to protect you content and E-Mails.
So at the end it is all about your scenarios!

Montag, 12. August 2019

Don’t make me think about IT Security


This is what end-users say about IT-Security. If you are an Admin or Data Security Officer, you have to think about IT Security.
Microsoft provides super useful info and material about this topic. In real world scenarios we often had to find out where to start. And also, for this Microsoft offers a walkthrough:


I put all the stuff together in a small Excel workbook and extend it with some further licensing info.
All important information for your IT security strategy is summarized in this Excel. In column 1 you will find the respective scenario, column 2 gives you an overview and column 3 the details on the topic. Columns 4 and 5 contain further information and details on licensing.



DOWNLOAD Excel workbook!

Mittwoch, 7. August 2019

Updates & News around Microsoft Information Protection

In the last couple of weeks Microsoft release a bunch of new features / versions for Information Protection and Unified Labeling:
  • New features & functions with Microsoft Cloud App Security and Azure Information Protection
  • Azure Information Protection unified labeling client
  • Update to Unified labeling

Cloud App Security and Azure Information Protection

Cloud App Security and the integration with Azure Information Protection is not new. If you are already migrated to Office 365 unified sensitivity labels and if you did not migrate your existing classification labels you need to know:  Creating new labels in the Office 365 Security and Compliance Center, Cloud App Security will only use the preexisting labels configured in the Azure Information Protection portal.

Integrating Azure Information Protection into Cloud App Security you get the ability to:
  • apply classification labels as a governance action to files that match specific policies
  • view all classified files in a central location
  • investigate according to classification level, and quantify exposure of sensitive data over your cloud applications
  • create policies to make sure classified files are being handled properly
This integration is focusing to scenarios like:
  • Visibility on sensitive data in managed cloud apps
  • Compliance / Risk Enforcement
    • Apply label to documents in cloud apps repositories
    • Prevent storage of highly sensitive documents in the cloud
  • Sensitive data reporting in AIP analytics space
  • Detect anomalous access
  • Block download of sensitive document from specific locations or non-compliant device
  • Block upload of sensitive documents

You need both a Cloud App Security license and a license for Azure Information Protection. Then Cloud App Security syncs the labels from Azure Information Protection. This action is performed every hour.
Scanning the files:
  • Automatic scan: all new or modified files are added to the scan queue and will be scanned, classified and protected
  • File policy to search for classification labels: these files are added to the scan queue for classification labels

After you enable Azure Information Protection on Cloud App Security, all new files that are added to Office 365 will be scanned and you can create new policies within Cloud App Security that apply classification labels automatically.
More Details: How to integrate Azure Information Protection with Cloud App Security

Azure Information Protection unified labeling client

Highlights of version 2.2.19.0:
  • Support for labels that are configured for user-defined permissions for Word, Excel, PowerPoint, and File Explorer
  • Support for advanced settings with PowerShell for the Security & Compliance Center
  • New cmdlet New-AIPCustomPermissions to create an ad-hoc policy for custom permissions
  • New parameters added to Set-AIPFileClassification:-WhatIf and -DiscoveryInfoTypes so that this cmdlet can run in discovery mode without applying labels

Download and further information: Version 2.2.19.0

Actually, we have two management portals which are supported by different clients:
  1. Azure Information Protection:
    • Azure Information Protection client (classic)
    • Azure Information Protection scanner
    • Microsoft Cloud App Security

  1. Unified labeling in Office 365 Security & Compliance Center:
    • Azure Information Protection unified labeling client
    • Microsoft Cloud App Security
    • Office apps for MacOS, Android and iOS
    • Information Protection SDK and applications based on it like Adobe Acrobat
    • Coming Soon:
      • SharePoint Online
      • Office Online, Outlook Mobile for iOS and Android
      • Built-in labeling in Office for Windows
      • Azure Information Protection scanner

Update to Unified labeling

Unified labeling is not activated per default and Azure Information Protection labels can be used only by the Azure Information Protection client. To make labels available in the Office 365 Security & Compliance Center and to use the unified labeling client you need to Activate that integration:

Before you activate unified labeling, check in Office 365 that you don't have labels that have the same name or display name as your labels in Azure Information Protection. Note that Azure Information Protection labels will be automatically renamed so that migration can succeed. Once activated you cannot deactivate unified labeling for your tenant. Learn more about the migration process.

Unified labeling: Activated

Depending on how many labels do you have the updated takes some time. After it is done you can manage your labels from either the Azure portal or the Office 365 Security & Compliance Center. The labels can be used by the Azure Information Protection client and by unified labeling clients.

Note: you must use the Publish option after the migration to make the labels available in the unified labeling clients. Otherwise the client is showing an error like this:





Montag, 24. Juni 2019

Objectives, Doings and Limitations with Azure Information Protection and BYOK


Sources:
·         BYOK pricing and restrictions

Overview
Azure Rights Management enables BYOK according to a model that Microsoft calls customer-managed tenant keys. This requires a customer to create an RSA 2048-bit key in their HSM and then export the key to the HSM in Microsoft's data center. This RSA key is then used to encrypt the document encryption keys used by Azure RMS. RSA 2048-bit keys correspond to 112-bit AES keys. This means that the AES 256-bit encryption provided by Azure RMS is really only 112 bits. The US government has advised against the use of AES encryption keys below 256 bits.


Overview about the necessary steps:

  • Create an HSM-based Azure Key Vault for a specific Azure region.
  • Generate your own key according to your IT policies. This requires e.g. Thales HSM, smartcards and support software.
  • Transfer the key from an HSM in your possession to HSMs owned and managed by Microsoft as provided by Azure Key Vault for your vault. This process ensures that your key never leaves the hardware protection boundary.
  • When you transfer your key to Microsoft, it remains protected by Thales HSMs. Microsoft has worked with Thales to ensure that the key cannot be recovered from Microsoft HSMs, and certificates are provided to ensure this.
  • Configuring Azure Information Protection to use the HSM-based key
  • Azure Key Vault's real-time usage protocols are available as an option. These can also be applied to BYOK to see exactly how and when the key is used with Azure Key Vault. Blob storage is required to store the logs.


BYOK vs. HYOK

The two scenarios and implementation differ fundamentally. HYOK is a kind of Azure RMS hybrid scenario. More details: https://docs.microsoft.com/de-de/azure/information-protection/faqs-rms#whats-the-difference-between-byok-and-hyok-and-when-should-i-use-them


Prerequisites, Restrictions & Limitations

Support and SLA

  • Support for billing and subscription management is provided free of charge.
  • Technical support is available through various Azure support models from €24.456/month for Developer and €84.33/month in the Standard version.
  • SLA: Microsoft guarantees that in at least 99.9% of cases, Key Vault transaction requests will be processed within 5 seconds.

Call to Action

  • Evaluate the actual advantages and disadvantages of BYOK in the context of your requirements and specifications in detail with the data protection officer and the involved departments.
  • Calculate the costs for the implementation, the required services and hardware as well as the operating costs. Based on this, you create a cost-benefit analysis.
  • Do you have other services that are already using BYOK with Azure?Did you use your own key for other scenarios and therefore want to implement AIP BYOK as well?
  • Does HYOK meet your requirements better?

Sonntag, 25. November 2018

Office 365 Message Encryption (OME) vs. Azure Information Protection

Main difference from a security perspective is, that OME is encrypting the transport and not the attached content over its lifetime.
Details:
All feature like IRM, AIP and OEM are based on the Azure RMS Service. The overall architecture looks like this:

Comparison of OME, IRM, and new OME capabilities


OME vs AIP


  • If you want to protect documents attached to an E-Mail only on the transport layer or if you want to use the “Do not forward” feature OME is the way to do it.
  • If you want to protect the document also after the E-Mail is received and the document is downloaded etc. then you need AIP.

Bothe features are good to protect E-Mails and attachments for internal use and for sharing them with externals. In OME you can send protected E-Mails to external receptions with out configuring anything special. The recipients received an HTML message that they downloaded and opened in a browser or downloaded mobile app:
To make the functionally available with AIP you need to add the external domain to you AIP label:

Protecting an E-Mail with AIP or OME in Outlook


OME:

AIP: