Microsoft Ignite 2019: Insider Risk Management and the Microsoft Defender Rebrand
At Microsoft Ignite in November 2019, Microsoft announced Insider Risk Management in preview as part of Microsoft 365 compliance, alongside updates across...
Insights
Articles in Microsoft 365.
At Microsoft Ignite in November 2019, Microsoft announced Insider Risk Management in preview as part of Microsoft 365 compliance, alongside updates across...
Microsoft Purview Insider Risk Management can detect data theft and leaks by insiders, but it needs careful setup and governance. Here is how to run a pilot.
Insider risk monitoring touches employee privacy. This checklist helps make sure policies have the right sign-off before you enable them.
The short version: In 2019, Microsoft introduced tools to detect when employees might be taking or leaking company data — for example, downloading large...
In September 2019, Microsoft announced that it would turn off Basic Authentication in Exchange Online for Exchange ActiveSync, POP, IMAP, Exchange Web...
Legacy (basic) authentication bypasses MFA. Even after Microsoft's retirement of basic authentication in Exchange Online, many organizations still find...
Use this checklist to find every remaining dependency on legacy authentication in Exchange Online and Microsoft 365.
The short version: In 2019, Microsoft announced it would switch off older sign-in methods for its cloud email because they couldn't use multi-factor...
In April 2019, Microsoft notified some users of its consumer email services — Outlook.com, Hotmail and MSN — that a support agent's credentials had been...
Help desk and support staff can reset passwords, change MFA methods and see user data. Here is how to scope those roles tightly in Microsoft 365 and Entra ID.
A compromised help desk account — or a manipulated help desk agent — can reset credentials across your organization. Detecting unusual support activity...
The short version: In 2019, attackers got into Microsoft's consumer email support systems by compromising a single support agent's account. Help desks are...
In March 2019, Citrix disclosed that the FBI had informed it of a breach of its internal network. The FBI's assessment, according to Citrix, was that...
Entra ID includes two built-in defenses against password spraying: smart lockout and Identity Protection. Here is how to configure both.
Password spray attacks distribute attempts to avoid detection. Combining Entra ID's built-in detections with your own queries gives you the best chance of...
The short version: In 2019, Citrix — a company that sells remote access technology to enterprises — was breached, likely through attackers trying common...
On May 25, 2018, the European Union's General Data Protection Regulation (GDPR) became enforceable. It applied to any organization processing personal data...
Privacy laws such as GDPR require you to know where personal data lives and to control it. In Microsoft 365, Microsoft Purview provides the tools. Here is a...
A data inventory is the foundation of GDPR compliance and of any serious data protection program. Use this checklist to build one for Microsoft 365.
The short version: GDPR, enforceable since 2018, made organizations legally responsible for knowing where personal data lives and protecting it — with fines...
In March 2018, reporting by The Observer and The New York Times revealed that the political consultancy Cambridge Analytica had obtained data on up to 87...
By default, Microsoft 365 users can grant third-party apps access to their data. Malicious apps use that to steal mail and files without ever needing a...
OAuth apps with excessive permissions can read mail and files across your tenant without a password. Detecting risky consent grants is a core identity...
The short version: Cambridge Analytica obtained data on tens of millions of Facebook users through an app most of them never used. The same mechanism — apps...