150
Enterprise Mobility + Security

Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

  • Upload
    lammien

  • View
    217

  • Download
    2

Embed Size (px)

Citation preview

Page 1: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

Enterprise Mobility + Security

Page 2: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

AssumeBreach

Page 3: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

• Identity

• Data

• Flexible Workforce

Page 4: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 5: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

18+ billion420 million

35 billion messages/month

250 million Millions

Billions700 million

40 billion

Millions

Page 6: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

United Kingdom

Page 7: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

Apps and Data

SaaS

Microsoft’s Security Approach

Malware Protection Center Cyber Hunting Teams Security Response Center

DeviceInfrastructure

CERTs

Identity

INTELLIGENT SECURITY GRAPH

Cyber Defense

Operations Center

Digital Crimes Unit

Antivirus NetworkIndustry Partners

PaaS IaaS

Page 8: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 9: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 10: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 11: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

Azure ComplianceThe largest compliance portfolio in the industry

HIPAA / HITECH

FedRAMP JAB P-ATO

FIPS 140-2 FERPA DISA Level 2 ITAR-readyCJIS21 CFRPart 11

IRS 1075 Section 508 VPAT

ISO 27001 PCI DSS Level 1SOC 1 Type 2 SOC 2 Type 2 ISO 27018Cloud Controls

Matrix

Content Delivery and

Security Association

Shared

Assessments

European Union

Model Clauses

United Kingdom

G-Cloud

Singapore

MTCS Level 3

Australian

Signals

Directorate

Japan

Financial Services

China Multi

Layer Protection

Scheme

China

CCCPPF

New

Zealand

GCIO

China

GB 18030

EU Safe

HarborENISA

IAF

Page 12: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

• Azure AD Authentications?

• 15,000 authentications• Per Day?

• Per Hour?

• Per Minute?

• 34 data centres – inc. UK South and UK West

Page 13: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

Global opportunity with Azure infrastructure34 Azure regions worldwide

100 + datacenters

One of 3 largest networks in the world

*Operated by 21 Vianet

**German data trustee services

provided by T-systems

Central US

East US

North Central US

Brazil South

West Europe

Japan East

South India

Southeast

Asia

Australia Southeast

Australia East

Central India

West India

Japan West

East Asia

China West*

North Europe Germany

Northeast**Canada East

Canada Central

South Central US

China East*

Germany Central**

Korea South

East US 2

Korea Central

United Kingdom West

United Kingdom

South

West Central US

US Gov

US Gov

US DoD East

US DoD

West

Page 14: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

Protect your data

Enable your users Unify your environment

People-centric approach

Devices Apps Data

Page 15: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

Enterprise Mobility +Security

Microsoft

Intune

Azure Information

Protection

Protect your users, devices, and apps

Detect threats early with visibility and threat analytics

Protect your data, everywhere

Extend enterprise-grade security

to your cloud and SaaS apps

Manage identity with hybrid

integration to protect application

access from identity attacks

Microsoft

Advanced Threat Analytics

Microsoft Cloud App Security

Azure Active Directory

Premium

A HOLISTIC SOLUTION

Page 16: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

Enterprise Mobility + Security

Identity and access

management

Azure Active Directory

Premium P1

Secure Single-Sign on to cloud

and On-premises apps. MFA,

Conditional Access and

advanced security reporting

Microsoft

Intune

Mobile device and app

management to protect

corporate apps and data on any

device.

Managed Mobile

Productivity

Azure Information Protection

Premium P1

Encryption for all files and

storage locations. Cloud based

file tracking

Information Protection

Microsoft Advanced

Threat Analytics

Protection from advanced

targeted attacks leveraging

user and entity behavioral

analytics

Microsoft

Cloud App Security

Enterprise-grade visibility,

control, and protection for

your cloud applications

Identity Driven Security

Azure Active Directory

Premium P2

Identity and Access

Management with advanced

protection for users and

privileged identities (includes all capabilities in P1)

Azure Information Protection

Premium P2

Intelligent classification, &

encryption for files shared

inside & outside your

organization(includes all capabilities in P1)

EM

S E

5

EM

S E

3

Page 17: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

Self-service Singlesign on

•••••••••••

Username

Integrated Identity as the control plane

Simple connection

Cloud

SaaSAzure

Office 365Publiccloud

Other Directories

Windows ServerActive Directory

On-premises Microsoft Azure Active Directory

One common identity

Page 18: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

Sensitivity: Internal

Page 19: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

Sensitivity: Internal

Mini Exercise

Page 20: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

IdentityTraditional Systems and Applications, MS Cloud Services, Other Cloud Services

IdentityDevices

Authentication

Office

365

Azure

Intune

CRM

Service

Now

Condec

o

Twitter

Finance

System

Citrix

File

Shares

Print

Servic

e

HR

Syste

m

Page 21: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 22: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 23: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 24: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 25: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 26: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 27: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 28: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 29: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 30: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 31: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

User attributes

• User identity

• Group memberships

• Auth strength (MFA)

Application

• Business sensitivity

Other

• Inside corp. network

• Outside corp. network

• Risk profile

Conditional

access control in

Active Directory

Devices

• Known to organization

• MDM Managed (Intune)

• Compliant with policies

• Not lost/stolen

Conditional Access Control

Page 32: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

MDM beyond email

Page 33: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

iOS

Supported Platforms

macOS Windows

Page 34: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

Microsoft IntuneBuilt-In

Device Management

Conditional Access

Selective Wipe

Built-In Microsoft Intune

LoB

app

User-centric approach

Page 35: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

Before mobile devices can access Office 365 data, they must be enrolled and healthy.

1. A user downloads the public OneDrive app on a personal iPad

2. The user is shown a page that directs them to enroll the iPad

3. The user steps through the enrollment process

4. The OneDrive app is now MDM enabled

5. The user is able to access their OneDrive data

Page 36: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

Device Polices• Control what mobile devices can connect to Office

365 Data

• Set device configuration policies such as pin lock

• Enforce data encryption on devices

Admin Controls• Built-In management in Office 365 Admin Center,

and PowerShell

• Configure device policies by groups

• Product level granular control

Device Reporting• Device compliance reports

• Mobile usage and trends in our organization

• API support

Page 37: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

1. An employee uses Office 365

apps and data on a mobile device. The employee leaves the company.

2. The IT admin logins into Office 365

Admin Center to perform a selective wipe

3. The Office 365 data is removed from the

Office applications leaving personal information intact

Page 38: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

Corporate

Complete mobile application management

• Securely access corporate information using Office mobile apps, while preventing company data loss by restricting actions such as copy/cut/paste/save in your managed app ecosystem

• Extend these capabilities to existing line of business apps using the Intune app wrapper

• Enable secure viewing of content using the Managed Browser, PDF Viewer, AV Player, and Image Viewer apps

Manage all of your corporate apps and data with Intune’s mobile device and application management solution

Personal

Managed Browser & Viewer Apps

Page 39: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

Maximize mobile productivity and protect corporate resources

with Office mobile apps – including multi-identity support

Extend these capabilities to your existing line-of-business apps

using the Intune App Wrapping Tool

Enable secure viewing of content using the Managed Browser,

PDF Viewer, AV Player, and Image Viewer apps

Managed apps

Personal appsPersonal apps

Managed apps

ITUser

Corporate data

Personaldata

Multi-identity policy

Page 40: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 41: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 42: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 43: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 44: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 45: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 46: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 47: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 48: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 49: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 50: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 51: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 52: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 53: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 54: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 55: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 56: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 57: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 58: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 59: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 60: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 61: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 62: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 63: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 64: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 65: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 66: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 67: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 68: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 69: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

http://blocked.com

Page 70: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 71: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 72: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 73: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 74: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 75: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 76: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

[email protected]

••••••••|

Page 77: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

[email protected]

••••••••|

Page 78: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 79: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 80: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 81: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 82: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

Brian Shiers

Page 83: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

Device Successfully Enrolled

Return to e-mail

Brain Shiers

Enroll your device

For added security, we need to verify your account. We have

sent a text message with the verification code.

Allan Myers(xxx) xxx-xx12

Please enter the code to continue

Other security verification options

Sign in with another account

Sign in Cancel

ContosoCorporation

Brian Shiers

Contoso Corporation

Page 84: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

Device Successfully Enrolled

Return to e-mail

Brain Shiers

Enroll your device

For added security, we need to verify your account. We have

sent a text message with the verification code.

Allan Myers(xxx) xxx-xx12

Please enter the code to continue

Other security verification options

Sign in with another account

Sign in Cancel

ContosoCorporation

Brian Shiers

Contoso Corporation

XYZZY

Page 85: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 86: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 87: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 88: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 89: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 90: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 91: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 92: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 93: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 94: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 95: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 96: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 97: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 98: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 99: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 100: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 101: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 102: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

[email protected]

••••••••

Page 103: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

[email protected]

••••••••

Page 104: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 105: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 106: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 107: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 108: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 109: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 110: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 111: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

Brian Shiers

Page 112: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

Device Successfully Enrolled

Return to e-mail

Brain Shiers

Enroll your device

For added security, we need to verify your account. We have

sent a text message with the verification code.

Allan Myers(xxx) xxx-xx12

Please enter the code to continue

Other security verification options

Sign in with another account

Sign in Cancel

ContosoCorporation

Brian Shiers

Contoso Corporation

Page 113: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

Device Successfully Enrolled

Return to e-mail

Brain Shiers

Enroll your device

For added security, we need to verify your account. We have

sent a text message with the verification code.

Allan Myers(xxx) xxx-xx12

Please enter the code to continue

Other security verification options

Sign in with another account

Sign in Cancel

ContosoCorporation

Brian Shiers

Contoso Corporation

XYZZY

Page 114: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 115: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 116: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 117: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 118: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 119: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 120: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 121: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 122: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 123: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 124: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 125: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 126: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 127: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 128: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

Microsoft Advanced Threat Analytics

Page 129: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

DETECT ATTACKS BEFORE THEY CAUSE DAMAGE

Identifies advanced persistent threats

(APTs) on-premises using User and

Entity Behavioral Analytics

Detects suspicious user and entity

behavior with machine learning

Detects malicious attacks (i.e. Pass the

Hash, Pass the Ticket)

Provides a simple attack timeline with

clear and relevant attack information

Page 130: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

DETECT ATTACKS BEFORE THEY CAUSE DAMAGE

Detect threats fast with Behavioral

Analytics

Adapt as fast as your enemies

Focus on what is important fast

using the simple attack timeline

Reduce the fatigue of false positives

No need to create rules or policies,

deploy agents, or monitor a flood of

security reports. The intelligence

needed is ready to analyze and

continuously learning.

ATA continuously learns from the

organizational entity behavior (users,

devices, and resources) and adjusts

itself to reflect the changes in your

rapidly evolving enterprise.

The attack timeline is a clear,

efficient, and convenient feed that

surfaces the right things on a

timeline, giving you the power of

perspective on the “who-what-

when-and how” of your enterprise.

It also provides recommendations

for next steps

Alerts only happen once suspicious

activities are contextually

aggregated, not only comparing

the entity’s behavior to its own

behavior, but also to the profiles of

other entities in its interaction path.

Page 131: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

Analyze1 After installation:

• Simple non-intrusive port mirroring, or

deployed directly onto domain controllers

• Remains invisible to the attackers

• Analyzes all Active Directory network traffic

• Collects relevant events from SIEM and

information from Active Directory (titles,

groups membership, and more)

Microsoft Advanced Threat Analytics

Page 132: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

ATA:

• Automatically starts learning and profiling

entity behavior

• Identifies normal behavior for entities

• Learns continuously to update the activities

of the users, devices, and resources

Learn2

What is entity?

Entity represents users, devices, or resources

Microsoft Advanced Threat Analytics

Page 133: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

Detect3 Microsoft Advanced Threat Analytics:

• Looks for abnormal behavior and identifies

suspicious activities

• Only raises red flags if abnormal activities are

contextually aggregated

• Leverages world-class security research to detect

security risks and attacks in near real-time based on

attackers Tactics, Techniques, and Procedures (TTPs)

ATA not only compares the entity’s behavior

to its own, but also to the behavior of

entities in its interaction path.

Microsoft Advanced Threat Analytics

Page 134: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

Alert4

ATA reports all suspicious

activities on a simple,

functional, actionable

attack timeline

ATA identifies

Who?

What?

When?

How?

For each suspicious

activity, ATA provides

recommendations for

the investigation and

remediation

Microsoft Advanced Threat Analytics

Page 135: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

Abnormal resource access

Account enumeration

Net Session enumeration

DNS enumeration

Abnormal working hours

Brute force using NTLM, Kerberos or LDAP

Sensitive accounts exposed in plain text authentication

Service accounts exposed in plain text authentication

Honey Token account suspicious activities

Unusual protocol implementation

Malicious Data Protection Private Information (DPAPI) Request

Abnormal authentication requests

Abnormal resource access

Pass-the-Ticket

Pass-the-Hash

Overpass-the-Hash

MS14-068 exploit (Forged PAC)

MS11-013 exploit (Silver PAC)

Skeleton key malware

Golden ticket

Remote execution

Malicious replication requests

Reconnaissance

Compromised

credential

Lateral

movement

Privilege

escalation

Domain

dominance

Microsoft Advanced Threat Analytics

Page 136: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 137: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 138: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 139: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 140: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

Classify, Label, Protect

Automated classification

Page 141: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

Classify, Label, Protect

Recommended classification

Page 142: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

Classify, Label, Protect

Manual classification

Page 143: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

Classify, Label, Protect

Business justification required to re-classify

Page 144: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate

Classify, Label, Protect

Prevent edit, copy, print and save with Azure Rights Management integration

Page 145: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 146: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 147: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 148: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 149: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate
Page 150: Enterprise Mobility + Security - Microsoft Association Shared Assessments European Union Model Clauses United Kingdom G-Cloud Singapore MTCS Level 3 Australian Signals Directorate