Get Security Done (GSD) - Microsoft Security & M365 Defender - quick wins to improve Security using existing entitlements

Get Security Done (GSD) - Microsoft Security & M365 Defender - quick wins to improve Security using existing entitlements

Updates - added MDO, MDE & MDCA (was MCAS)...

Ideally this page will be highlighting how to get the best out of your M365 E5 security and compliance entitlements. Yes, there is the ninja training series (full set of links below), but what is the best way to step lightly thru this and gain maximum benefit for the least effort?

Most of the focus here is more on the M365 SaaS Security platform elements, not necessarily on Sentinel or Azure, but there will be plenty of crossover.

Core reference material:

For those wanting to keep up with all the latest developments as they become available (or even before then) then we'd strongly suggest you sign up to the Team Channels. Both of these below are covered by your NDA with Microsoft from either a Partner or Customer perspective. This is where you can get early access to the latest features in Private Preview so long as you're prepared to provide feedback as to what works and what doesn't.

No alt text provided for this image
aka.ms/PrSecCom

Defender M365 Console:

Evaluate Defender 365: https://learn.microsoft.com/en-gb/microsoft-365/security/defender/eval-overview?view=o365-worldwide a good step by step guide to getting everything turned on - but it is aimed at folks just starting

Test Use Cases: https://learn.microsoft.com/en-gb/microsoft-365/security/defender/integrate-microsoft-365-defender-secops-use-cases?view=o365-worldwide

SOC Maint Tasks: https://learn.microsoft.com/en-gb/microsoft-365/security/defender/integrate-microsoft-365-defender-secops-tasks?view=o365-worldwide

MDI:

No alt text provided for this image
MDI Welcome page

?Troubleshooting:

MDCA (was MCAS):

MDE:

MDO:

Conditional Access:

The?#Microsoft?content:

NOTE: please be aware there is no inherent "BLOCK" by default

You need to make sure you are BLOCKING by default unless explicitly allowing access

Walk through the 14 default Policies to better understand this

To make sure that you are fully covered please use this?PowerBI based tool https://github.com/AzureAD/AzureADAssessment

Here is a great companion for Sentinel: https://danielchronlund.com/2022/04/21/a-powerfull-conditional-access-change-dashboard-for-microsoft-sentinel/

Automation of "CA-as-Code"

He also points out the others that have done great work in this space:

One important point – don’t get caught up trying to manage GUID’s:

Hardening Guidance from ACSC:

Ninja Security Training:

Inspired by Mark Simos ’s “Mark’s List” and a discussion after an “In to the Breach” training exercise with Dylan J. over a few beers it was discussed that there should be a local ANZ version focused more around “Getting Security Done” (hence the short link to GSD) with a specific focus on the M365 Security platform, but not restricted to just that as we'd like to adopt a very customer centric view point on this. (of course here in Australia we might typically refer to this as "Get Shit Done")

So with that planning got under way to create https://aka.ms/GSD, and of course we could always refer to this as Global Security Deployment?

Please note this will be a mix of both Microsoft & non-Microsoft content, if it is of value and can help you with said mission of GSD for Security in the Microsoft Platform, then we'd like to include it - having said that, please feel free to provide feedback on the good, the bad and the ugly as we'd like to improve this over time.

While this will start off as a LinkedIn Article - it may well transition to either GitHubPages.io or to a hosted Worpress sometime early next year, as Jeff Beckitt keeps telling me - don't let perfect be the enemy of good - please keep that phrase in mind as you review the details below.

Feel free to provide suggestions

Steve Parsonage

Co-Founder & Director

1 年

Hi Dave, this is from over a year ago, have you done an updated version?

回复
Michael Brooke

@Crayon supporting partners and their end clients to improve cyber security posture improvement

1 年

Great information David

Richard B.

Great at asking "dumb" questions...Never the smartest person in the room.

2 年

Great list David! Jonathan Zee Chris Gerke

David Caddick

Senior Security Specialist at Microsoft - aka.ms/gsd = Get Security Deployed

2 年

added MDO, MDE & MDCA (was MCAS)...

David Taig

Practice Manager Ops | Microsoft Security | Azure Security | Azure AD | AVD | Skype4B | Microsoft Teams

2 年

Great S ??

要查看或添加评论,请登录

David Caddick的更多文章

社区洞察

其他会员也浏览了