Get Security Done (GSD) - Microsoft Security & M365 Defender - quick wins to improve Security using existing entitlements
David Caddick
Senior Security Specialist at Microsoft - aka.ms/gsd = Get Security Deployed
Updates - added MDO, MDE & MDCA (was MCAS)...
Ideally this page will be highlighting how to get the best out of your M365 E5 security and compliance entitlements
Most of the focus here is more on the M365 SaaS Security platform elements, not necessarily on Sentinel or Azure, but there will be plenty of crossover.
Core reference material:
For those wanting to keep up with all the latest developments as they become available (or even before then) then we'd strongly suggest you sign up to the Team Channels. Both of these below are covered by your NDA with Microsoft from either a Partner or Customer perspective. This is where you can get early access to the latest features in Private Preview so long as you're prepared to provide feedback as to what works and what doesn't.
Defender M365 Console:
Evaluate Defender 365: https://learn.microsoft.com/en-gb/microsoft-365/security/defender/eval-overview?view=o365-worldwide a good step by step guide to getting everything turned on - but it is aimed at folks just starting
Test Use Cases: https://learn.microsoft.com/en-gb/microsoft-365/security/defender/integrate-microsoft-365-defender-secops-use-cases?view=o365-worldwide
SOC Maint Tasks: https://learn.microsoft.com/en-gb/microsoft-365/security/defender/integrate-microsoft-365-defender-secops-tasks?view=o365-worldwide
MDI:
?Troubleshooting:
MDCA (was MCAS):
MDE:
MDO:
领英推荐
Conditional Access:
The?#Microsoft?content:
NOTE: please be aware there is no inherent "BLOCK" by default
You need to make sure you are BLOCKING by default unless explicitly allowing access
Walk through the 14 default Policies to better understand this
To make sure that you are fully covered please use this?PowerBI based tool https://github.com/AzureAD/AzureADAssessment
Here is a great companion for Sentinel: https://danielchronlund.com/2022/04/21/a-powerfull-conditional-access-change-dashboard-for-microsoft-sentinel/
Automation of "CA-as-Code"
He also points out the others that have done great work in this space:
One important point – don’t get caught up trying to manage GUID’s:
Hardening Guidance from ACSC:
Ninja Security Training:
Inspired by Mark Simos ’s “Mark’s List” and a discussion after an “In to the Breach” training exercise with Dylan J. over a few beers it was discussed that there should be a local ANZ version focused more around “Getting Security Done” (hence the short link to GSD) with a specific focus on the M365 Security platform, but not restricted to just that as we'd like to adopt a very customer centric view point on this. (of course here in Australia we might typically refer to this as "Get Shit Done")
So with that planning got under way to create https://aka.ms/GSD, and of course we could always refer to this as Global Security Deployment?
Please note this will be a mix of both Microsoft & non-Microsoft content, if it is of value and can help you with said mission of GSD for Security in the Microsoft Platform, then we'd like to include it - having said that, please feel free to provide feedback on the good, the bad and the ugly as we'd like to improve this over time.
While this will start off as a LinkedIn Article - it may well transition to either GitHubPages.io or to a hosted Worpress sometime early next year, as Jeff Beckitt keeps telling me - don't let perfect be the enemy of good - please keep that phrase in mind as you review the details below.
Feel free to provide suggestions
Co-Founder & Director
1 年Hi Dave, this is from over a year ago, have you done an updated version?
@Crayon supporting partners and their end clients to improve cyber security posture improvement
1 年Great information David
Great at asking "dumb" questions...Never the smartest person in the room.
2 年Great list David! Jonathan Zee Chris Gerke
Senior Security Specialist at Microsoft - aka.ms/gsd = Get Security Deployed
2 年added MDO, MDE & MDCA (was MCAS)...
Practice Manager Ops | Microsoft Security | Azure Security | Azure AD | AVD | Skype4B | Microsoft Teams
2 年Great S ??