In the Know Your Stack series, Jazzy Khaneja and Redouan Bulaid explore the full range of security capabilities available in Microsoft 365 Business Premium and the add‑ons available to extend it, showing how Microsoft has become a complete, enterprise‑grade security platform for SMBs.
In this episode, find out what “good” Entra ID security actually looks like and how to standardise it at scale. From misconfigured MFA to risky legacy authentication and policy drift, we’ll highlight the common gaps we see across tenants - and how to close them. Learn how to harden Entra ID environments efficiently, reduce risk across your customer base, and build a repeatable identity security baseline you can rely on.
Jazzy: Hello and welcome everyone. Good afternoon depending on where you are in the world though. Good morning, good afternoon, good evening. We cover all of whatever, whichever, whichever part of the country or the world you guys are in. Love that. I'm guessing that it's not night for someone in the world right now or in this meeting. Well, hopefully not. If if it is night, they absolutely love uh uh these webinars, wanted to join during this time. Absolutely love it. Absolutely love it. Well, good to have you all. Um, thank you for for being part of our webinar, part one of our Know Your Stack series, a four-part webinar, uh where we'll talk about a few things, uh Microsoft world and and the things we love doing every day, each day. Um, I I think uh I think, I mean it's 2 3 red one. What you think? Should we get, should we get cracking? Should we get started? Hopefully uh people can see.
Red: I guess so. It's uh already 2 minutes past 4. So I'm guessing that most people have joined so far. Do we um do we have like a Q&A section or do we just use the chat within uh Teams? I'm guessing we're using the chat then, right?
Jazzy: Yeah. Yeah. Let's use the chat. Anyone that wants to, some questions.
Red: Greetings from Switzerland. Greetings from South Africa. Actually, I'm in South Africa right now for some on-site engagements for Inforesters. I've been here for like a week now. So, greetings from South Africa, but I'm actually based in the Netherlands, but we'll jump into intros uh in a bit, I guess. We've got, we've got someone from UAE as well.
Jazzy: I mean, right now it feels like UAE in the UK. I'm I'm I'm based in Richmond, United Kingdom. It's almost 100° here. Uh not really, but that's what it feels like. I am melting slightly. Um, but I think I think we'll be okay, mate. We have people from all over the world right now. We got Haiti in the house.
Red: Yeah, as well, bro. What? Greece. Are you guys making like making things up? They're just putting in countries right now. Well, Netherlands is not going anywhere in terms of football, but yeah, otherwise Netherlands is in the house, too, boys.
Jazzy: Someone says 100 degrees in USA. Man, we we measure in Celsius, man. 37. Yeah. Yeah. 37. I mean, that is what it feels like to be fair. I really need an AC. Cries hearts, actually. Awesome. Let's get going. I'll move over to the next slide. So, a little bit about about us and and who we are. Um, welcome guys. I'm Jazzy. I'm part of the Microsoft 365 solutions architect team here. Um, I'm a Microsoft fanboy first of all. That's that's all I love. That's all I talk about. Even even with my misses. Uh somehow, someway I managed to bring Microsoft in the conversation. Um, I am also the official IT support for my parents, without a doubt. Anything that ever goes wrong it's it's a phone call straight to me. Uh somehow I I know everything about phones and TVs and the the fan that sometimes doesn't work and and swivels in the wrong direction, even though there is no right direction for a fan to realistically swivel. Um, and my whole IT career has been MSP. That's all I've ever done guys. I've only ever worked on MSP. Uh I've been uh heavily involved with with the Microsoft ecosystem, things like Intune, Entra, Exchange, a little bit of your virtual desktop here and there. Uh and and that's a little bit about me and and nice to have you all. We're 134 big right now on this webinar. So, thank you for joining. Uh I did create this slide like 10 minutes ago, so I didn't get—
Red: Yeah, I was going to ask you like what did you put under my name? Like what? At least—
Jazzy: Over here for no reason. You're not going to have time to add anything.
Red: I will, I will introduce myself as well. So, my name is uh Rayon Bulite. I'm actually based in the Netherlands. As I said, right now I'm in South Africa, so that's really fun. I'm here for some on-site engagements. I used to work for an MSP as well, just like Jazzy. I used to work for an MSP that is based in the Netherlands, in Anto. For all of the people from the Netherlands right now, they they probably know where it is. Um, I was the lead consultant there for the model work team. So I did a lot of project work around Microsoft, the Microsoft ecosystem. We were really focused um on the Microsoft ecosystem. So defend office, defend the cloud apps, all all of that, all of those shenanigans within Microsoft 365. We we configured it and we were really focused on it. And since uh, I want to say a month or two right now, I um I'm a solutions architect here at Inforcer. So uh yeah, thank you all for joining, man. I mean, we have a, we have a good group today, Jazzy.
Jazzy: Absolutely. I think I think we're we're ready to to hopefully inspire some knowledge that that wasn't already there and and maybe we we learned some from from all the other experts in in the call as well. And happy, happy for all of your inputs and questions in the chat. So, feel free to go. Um, I am controlling the slides. So, Redon, whenever whenever you need me to go to the next one, you can tell me as well and and we'll do, we'll do this together. Um, FYI guys, none of this is rehearsed. We're doing it on the fly as we always do. Um, so we we we'll make it work as as we always do. Um, things will cover. So we'll cover some of the stack that you already own. Um, and talk about some of the foundation work that we can harden that sometimes gets missed in um, obviously conditional access, can't can't speak about ID without speaking about conditional access. Uh and some external and cross tenant collaboration that we may have missed about guest, um type of security and infrastructure that we have available uh inside Entra ID, and making sure that we we configure things and make sure they they stay enforced, right? Because configuring a policy, turning it on and not applying means, means nothing, does it? How many times have we deployed something and forgot to assign someone to it? I've made that mistake once or twice myself. What about you, red one?
Red: Yep, I know exactly what you're talking about.
Jazzy: Awesome. Awesome. So, stack you already own guys. You you've you've paying for business premium. Hopefully, all of you are, um, and that includes Entra ID P1 uh that is included um with the licensing. And and sometimes where we struggle with is when we have too many subscriptions, we already have an identity platform that we're using. We're using HR uh P1. We've got the business premium licensing under under our wings and that's where it's brilliant to be able to configure it, but are we configuring it to its extent? And sometimes we we find, we don't find things we're looking for within Entra ID, uh and that covers other workloads as well like Defender and antivirus and um Exchange email security gateway and things like that. And you, it starts stacking up, right? You start having more portals to cover, uh more, more work for the invoicing team to to ask for money for other products that you're covering uh and just more consoles ultimately.
Red: Yeah, I mean you're hopping from portal to portal enough within the Microsoft ecosystem and now you have like other third party applications that also have portals that you have to hop to. I'm I'm guessing that for a lot of people that this is making sense. Um, I've been on some on-site engagements here in South Africa as well. I will see a lot of MSPs that will utilize like third party applications where uh they don't really know that it's already included within business premium actually, or or it might even be cheaper to move to business premium and then leave some of those tools, cuz nowadays Microsoft technologies, I mean uh you can check the Gartner quadrant um charts, right? I mean Microsoft is in in top of the charts. So I guess that the the goal of this series is to like really focus on what you already have within that Microsoft ecosystem, since it makes so much sense to consolidate into that, if if that makes sense.
Jazzy: Yeah, absolutely. No, absolutely does. You're spot on. And and what that also sometimes means is that you only need one type of expert within your MSP, right? Someone who knows the Microsoft ecosystem. You're not looking for people with other skills because they know Microsoft. We live and breathe Microsoft. It's easier to manage and configure uh because we we we know and we've been trained on it. Um, and ultimately, who wants to jump between more portals when we already have so many Microsoft pools to jump from, right? You said that spot on. Um, wasn't it also recently that Microsoft announced price rises and the only thing that wasn't raised was business premium in terms of licensing? Anything else changed?
Red: Yeah. Yeah, that is correct. So, that is a very good argument for an MSP to actually move towards business premium since it is the only SKU that is not being raised in price and business standard is being raised. So yeah, makes more sense, even more sense to to move towards business premium.
Jazzy: Absolutely. So what do we get? We get Entra ID P1 in business premium. Uh we've got things that we can configure such as conditional access that we'll talk about uh in a minute. We've got SSPR in there, self-service password reset. We we even got password protection in there where we can um apply certain words that are refrain from being used as passwords, like a banned user password list. Um, we've got named locations where we can decide which IP addresses are part of the allow/block list. Could be, could be your office uh uh IP address or could be the customers uh offices of the world where they are. So we could, you know, block certain countries from being accessed into their Entra tenant environment and and just allow certain countries. And you've got proper security reporting that comes out of Entra. There's so many reports, especially with with workbooks as well, isn't there? Uh when you do the diagnostic settings and there's lots of reporting that can be pulled out, uh if I'm not wrong, with by standard in Entra ID you get 30 days of uh history in terms of sign-in logs as well that we can export out, and that's already all paid for, it's part of your Entra ID P1. So things like built-in MFA, we've got you know pass keys that we can use, we've got um lots of authenticate, we've got the Microsoft Authenticator app we can use on our phones, we don't necessarily need third party vendors to to help us with MFA. So that approach there for us as well. Um, we do have an add-on, right? P2 um which can be purchased on top of your business premium, uh is part of some suites as well. I think uh the Defender suite and the Purview suite comes with P2. And you can have standalone P2 licenses as well that gives you things like risk based protection um and privileged identity management as well. So the just in time, just enough access protocol uh to make sure that we're covering that framework. So with PIM, you can elevate up to uh a certain role and only have it for certain hours, assign them to specific users, so we're not sprawling out with all of the uh roles to everyone. Give everyone GA, because that's what turns out to be happening.
Red: Um, it does still happen though. I mean, I've seen it. Unfortunately, it does.
Jazzy: Absolutely. I've seen it too. We we should, we should really rein that in and start controlling. I mean, it was like that in my MSP as well. We did tend to give out a lot of global admins across the board and and have to rein that in as much as we can. I mean, I'm not going to go deep into GDAP and PIM GP there as well, but for for people that don't know—
Red: You want to make this a two-hour webinar, Jess.
Jazzy: All right. All right. Like I said, slight— I could talk about— Microsoft fanboy out here.
Red: Yeah. I mean, we we usually had to revert to like P2 licenses for our administrative accounts whenever GDAP wasn't— when we weren't able to do specific things within GDAP. I know that at the time, this was only a couple of months ago, you couldn't manage Teams within GDAP. I'm pretty sure that is still the case. And then we'd still have to like have a P2 uh license if we were to like properly configure the the uh the roles with uh with PIM. So, yeah.
Jazzy: Yeah. Yeah. And and making sure that every user gets that P2 license. Yeah. Not just the one to unlock it in the tenant, like like like some people have been doing. Every user benefiting from that should be having a P2 license, but we're not going to go into deep licensing talk either.
Red: That's fine. No. No. Please no.
Jazzy: Uh, awesome. Talking about the the foundation site. So obviously there's conditional access as well that we'll cover uh later on. But there's a few basic settings that some, sometimes do end up getting missed uh within Entra, and and uh standard users and their privilege with the default user role permissions uh being being one of them. Right.
Red: Yeah. If I could even add to that, um please just realize that Microsoft 365 was built for enterprise. It wasn't built for MSPs. So all of the default values of all of the tenant-wide settings are always like enterprise-based settings. So it doesn't make sense for MSPs out of the box. A lot of these settings are forgotten about by MSPs, like we see that a lot that these MSPs will focus on conditional access for instance, or they will focus on Intune policies, but when it comes to the tenant-wide settings within Entra they're just forgotten about. So a couple of them right here, and I I'm pretty sure that the next slides we're going to discuss some more. By default users can actually register uh app registrations within within the tenant. So not sure why that is. That is really for like uh enterprise um enterprise environments where you have like in-house developers. They need to be able to register applications and stuff like that. For MSPs, nine times out of 10, it doesn't make sense that users are able to do that. And the same goes for restricting uh non-administrative users from creating tenants. Most MSPs are managing like SMB type environments, sometimes enterprise, but usually there's like no good reason a a normal user should be able to create a tenant. Like again, this is really for like in-house developers that are creating tenants, maybe testing stuff out before going to, before going to a production. So, please just have a look at these tenant-wide settings and make sure that you baseline that correctly once and then try to apply them uh all of them correctly. And the same goes for uh security groups. Sorry for taking over, Jazzy, by the way.
Jazzy: No, no, please. Yeah, go for it. Of course.
Red: And the same goes for security groups. So security groups and Microsoft 365 groups are like two different toggles. And I'm pretty sure that the M365 one will be shown in one of the the following slides. But in most scenarios, you don't want users to be like creating security groups. That's what we as an MSP are doing. There might be some like shared administrative scenarios where the um the the users of the tenant or your client are actually also managing the environment. So there might be scenarios, but generally speaking like from an MSP perspective, normal users should be able to create security groups, if that's making sense so far. I am really curious though for everyone who is in the webinar right now, if you have an edge case where you as an MSP actually need that toggle to be turned the other way around. I'm really curious if you could drop that in the chat because I'd love, I'd love to hear the edge case here.
Jazzy: You're you're spot on. I completely agree. So, in terms of the M365 groups, I still feel like there may be some uh relevance as to why that should be enabled, right? Security groups really comes down to, you know, we control things like in policies, who they apply to, conditional access policies, app access, you know, we realistically, where are we looking for for security groups to be enabled? And exactly like you said, it's it's really an enterprise-heavy setting, isn't it? When it comes to restricting non-admins from creating tenants as well. So although, I mean I think the only, the only tenant you can create is the external, external tenant view, and whoever creates it becomes the owner and they have to connect it to an Azure subscription anyway. There is a few things you have to do before you can create that tenant. But why have that setting there in the first place, and we can just control it from here and say no, if you need a tenant we we'll we'll think about it, right? Um yeah, so there's someone in the chat, Martine, thank you, thank you for uh sending it. If a customer needs to do it themselves we give them, we give the user PIM with a role.
Red: So that was exactly what I wanted to add, is all of these things, if you actually block it then a certain role within ID can still do it. So you can have a process around that and it's way more uh controllable instead of just having every user being able to register applications or create groups. So makes perfect sense.
Jazzy: Exactly. We've got that audit term. We've got the role that we can apply. I mean things like user administrator or groups administrator. We can even create custom roles, can't we? That have specific rules, allow where they can create just security groups and they automatically become the owner and they can go from there if they want to. Uh if there is any reason for that. Um but yeah, I think I think these default settings can definitely be changed, especially with default user role permissions. Um, and exactly, um with with another setting around that is the user settings that, you know, talk about restricting access to the Microsoft Entra admin center as well, if they don't need access to review. Yeah, we were talking about that.
Red: Yeah. Yeah, we were talking about that. So, so I do want to emphasize for everybody listening in, the toggle "restrict access to the Microsoft Entra admin center" is not a security toggle, like not at all. That toggle is meant for users who are like clicking around into portals and then happen to go to the Entra portal for some reason. So the overview page of the Entra portal will be blocked, but any deep links or any API access is still accessible for those users. So for instance, if you allow users to create security groups and then you block access to the Entra admin center, they are still able to create security groups in the Entra admin center through like a deep link. So if they go to the direct link for creating groups, they're still able to go there. So you do want to like to toggle this to blocking those users, but this is not a security toggle at all. So please please make note of that and uh don't forget that.
Jazzy: That was insanely funny, right? Because because we we were able to copy and paste the link from from what we knew from one of the blades that existed. Even though restrict access was set to yes, and when we jumped onto the link with a normal user, we were still able to access that page and review some details. So it's it's safer to to have it, yes. But then use conditional access to properly control it if we can, um to to the Windows Service Management API and and PowerShell and Graph-based uh resources where we can completely block them, so non-admin users and only administrators can access that. Um, then we have the LinkedIn account connections as well. So that basically surfaces LinkedIn data. Uh if if that is set to yes uh inside Microsoft 365 environment, like Outlook cards and Teams cards you can see LinkedIn uh information, but from from what the privacy data I read, it also shares a lot of data to LinkedIn. Um, so like things about your meetings, things about your calendar. There's a lot of privacy data in there that that goes out to, to either way, right? You're bringing some stuff in, you're taking some stuff out. If there's no reason to be to have LinkedIn data within Microsoft's environment, that can be set to no as well, right? Um, although from from memory, I do remember that if this is set to yes, uh and you do try and connect it, you, the end user does get prompted, you're, you're about to share this data kind of thing and do you accept, they do get a consent prompt. But having no data being shared across both environments and an external environment, it's just safer to have that as no. And then lastly, we've got the lovely "show keep user signed in" button. Um, and if you're not properly controlling that, especially if you've got security defaults enabled on your tenancies and not, you're not using conditional access, that will issue a persist— persistent cookie that will only, you know, drop you out of sign in or ask you to sign in again after 90 days of inactivity. But it does keep rolling. So if you were to access something on on the 88th day, that that resets, right? It goes back to the to the uh to the 90-day rolling window. Um, and realistically, we want to control that. We we we don't want someone to stay logged in at all times. Laptops can be left open, unlocked, um, as as Red did about a week ago. Uh, but anyway, um—
Red: I don't know what you're talking about.
Jazzy: Especially on unmanaged devices as well, if if there's you know kids play on that, falls into the wrong hands, uh we want to have that prompt being, you know, with with persistent browser session policies with conditional access, um that is covered later, where where we can control how long uh we we can have those sessions active, uh hopefully 24 hours is the number I'm going for, but um what do you think uh Red, what's a good uh session policy to have for for persistent browser sessions?
Red: Oh, that's a really good one. I've seen MSPs do a variety of things. So, I've seen some that will um scope it specifically to global admins as well and then give that like a a smaller amount of time, so maybe an hour or two hours. And then for regular administrative accounts, it's like four hours or something like that. And for just regular users, it can be 24 hours for instance. And usually unmanaged devices is, it's never a persistent browser session. That that that's usually why. Yeah. What I see, um I do see a question from Luke though. "Will the slide deck be available to us?" I don't see an issue with with sharing the slide deck.
Jazzy: Absolutely. We can get those out to you. Yeah, absolutely. Okay. Perfect. Awesome. And then lastly talking about groups themselves. So, so far we've covered uh some of the user settings which are available in in Entra ID. I believe they fall under users and then user settings. Uh, and then we had the uh, we we have this group section here which falls under groups and group settings. I think it falls under general, if I'm not wrong, red one.
Red: Uh, yeah. Yeah. Talking about the blades uh takes me back to my AZ-104 exam where I had to think about every single blade that existed and that drove me nuts. But somehow we end up remembering some of these now. But um you see the same toggle here as well. So the security groups that we spoke about in the previous slide, which which is the exact same toggle here. Uh where we can set that to no, um for some reason I'm not, I'm not sure why they show that exact toggle in two different places.
Jazzy: That, for you, really?
Red: Yeah, very easy, because Microsoft loves to make— exactly, they love, they love to double up and give you more options in the same settings.
Jazzy: Why, why do it in one place?
Red: For the sharp people in the webinar, it it is exactly the same toggle. And if you toggle it in this place to like yes or no, it will actually be toggled to yes or no in the other place as well. So, for some reason, Microsoft shows it in in in two different ways within the Entra admin center. And then after that comes the interesting one, Microsoft 365 groups. Like that that's where it gets interesting. Like I'd be, I'd be really interested to hear some arguments from MSPs in the call right now, like what they do with this toggle, since Jezzy and I had a discussion about it. I mean ideally you would have like a good process around creating Microsoft 365 groups because there's like a bunch of different places within the ecosystem where users can create these groups, but then on the other side you need like a proper good process as an MSP to like have control over creating these groups because you don't want to like create every group for for normal end users. So I'm really interested to see like what most MSPs do with this specific toggle, like how did you guys do that in your MSP, Jazz?
Jazzy: So I mean it it it's it's a balance of productivity and somewhat security as well at the same time. It's, well, is that, is that the right thing to say? Probably not. I mean in terms of M365 groups, right? What we, what we noticed that a lot of end users in different customers when we were at an MSP end up spinning up their own M365 groups, right? They've created a new SharePoint site because they're not controlling site creation settings for example, or or they're controlling planner groups because they've gone in ahead and created a new planner and they've associated to four or five custom members and and they've uh probably wanting to share that planner plan with them specifically, and all of these things, even Teams channels as well by the way, all of these things end up creating new Microsoft 365 groups. So 6 months down the line when one of the end users asks, "Hey, uh, can I be added to this group, or or or I need to have access to this site?" And there's three finance sites with three different groups. And if we had just blocked the group creation or the Teams channel creation in terms of Microsoft 365 groups as well, you're— we know where we're going.
Red: You're forgetting to mention that the group naming will probably be like test 01, test 02, test everything. Like the amount of times that I I've done a tenant to tenant migration. We do like an indexation of all of the SharePoint sites and all the team sites and then we uh discuss what we would actually migrate and then that, that were always the times where we would see that there's like 50 SharePoint sites called like test 01, test 02, test zero, whatever it is. And yeah, it was insane.
Jazzy: Yeah. So, so this would give you way more control over that, like Microsoft 365 um groups and the the process around it essentially. But you do have to think about it though. So, so yeah, ultimately Red and I went with this should be set to no so you can control exactly what groups exist. You can control the naming conventions. And if, I mean sometimes they do end up with a vague error. So, for example, if you were to create a Teams uh channel and it needs a Microsoft 365 group on the end, it just says you need to own a group. So, either they're an owner of a group and they try and associate to that, or if they're not owner of any groups, it just tells them to to own a group. That can obviously end up with a ticket to the help desk. Uh, and then a human can actually review with some technical knowledge if that group or if that site already exists, that team chat already exists, and add them to the right group instead of creating 15 new ones every single month because they can't find the old one. I forgot that they created it. Um, but then again, you can also reduce your amount of tickets that get sent to the help desk by by switching that to yes, I suppose, right? Um, which which will let them create— let anyone create any resource that requires a 365 group on the back end. Um, I mean the the other argument is control it on the other side. So block site creation, don't allow Teams channel creation, things like that, and only allow admins to do it. Um, then then I guess the middle ground could be uh giving some people access to to create 365 group, uh trusted members within an organization. Uh well, could be managers and who have all the other groups. Yeah. Give them a custom role.
Red: Is that, is that still a PowerShell cmdlet? Because that used to be a PowerShell cmdlet to give like a specific group access to creating Microsoft 365 groups. I'm guessing that—
Jazzy: I'm sure you can do that within Entra custom roles now. So you can literally tick that, says— yeah I think there was one where I saw one of the custom permissions was uh allow the ability to create a M365 group and the person that creates it becomes the owner. Um, so you can give those roles out. Um, but then it it depends on on how we allow them to create the group ultimately as well, right? So if it's done via the the actual app itself, then great. When they spin it up, they hopefully with the custom role, they have the ability to create it. Um, and and we can move on that way. And and we we don't have a sprawl of a hundred different groups being spun up every every couple of weeks and help desk doesn't run out of ideas of who to add where, right?
Red: It's funny cuz we um we solved it in a different way by creating a security group and then I'm pretty sure you had a PowerShell cmdlet. I'm not, I'm not sure what it was again, but uh if you look it up, it's probably the like the first article that pops up, but with that PowerShell cmdlet, you could just give that security group and the members of it uh access to creating Microsoft 365 groups. And that's how we solved it for like most our customers cuz we didn't really want to be bothered with creating most of those groups. And then the customer, like the IT manager or whatever, they could create the Microsoft 365 groups for that environment. So yeah, makes sense.
Jazzy: So the middle ground is the best ground here, right? Give, give some trusted people access. Keep this to no, uh hopefully less tickets and they have overview of what exists, uh and then at least you'll have less groups being spun up constantly. And and I like that, the middle ground is the best, best ground. Um, that that brings us to self-service group management, right? Um, we've got two settings that that they live in the same place. I believe they live in the group uh, the groups and and general page. I believe on the group settings, um where we can manage group memberships where owners can manage their own group memberships in the the My Groups portal. Uh and turning that off um basically stops that flow from happening. If someone owns a group, they can't approve someone requesting access or not. And it's deliberately controlled by an administrator.
Red: Um, yeah, I was, I was laughing because I saw an article by Daniel in the chat by managing who can create those Microsoft 365 groups, and yes, it is still a PowerShell cmdlet from what I can see here.
Jazzy: There we go. There we go. Taking it back. Thank you, Daniel. Um, I mean the appeal is is obviously if we do set that to yes, um owners can manage their own approval flows and they don't have to wait for an administrator. Uh but ultimately if we, if we set that to no, someone can from the help desk can actually review uh what that is doing, what that group is is responsible for allowing access to, you know we can have a control process behind it so that when someone wants to access it they can go through it, make sure that it's verified and allowed to access the resources that are bounded by that group, um and it stays with with the help desk, stays with an administrator.
Red: And to be honest, when I saw these toggles again like a couple of weeks back when I was looking at these toggles, I was thinking like what does this actually change from like the end user perspective, because I actually forgot about that. So for the people that are thinking about that as well, when you go to like myaccount.microsoft.com, if you, if you block everything from these uh from these toggles, you do not have like an extra blade that says groups. But then if you don't block it, the user will have like an extra blade that that's called groups. And then within that blade, users can go ahead and um request access uh as membership to security groups, or create security groups, or or um uh they'd like to join them. [Reading chat] "Someone outside of your organization should reopen it." I saw that it was a learn.microsoft.com article. So yeah, I did open it.
Jazzy: I mean, if you want to phish me, send me a Microsoft Learn documentation link and I will click on it. I need to send— a few clicks on that would be the best phishing for me. First thing we do. Um, but yeah, so so the My Groups portal is what this is controlling, with within, within the exact blade that that red one just mentioned. Um, and we can have the ability to to also restrict them from uh viewing anything. So they only have read only access um when you're, when you're a group or a user admin. Um, and everything else is restricted from from the groups features, which, yeah, I mean, is is a setting that I still think is a, is a setting I'd probably configure to yes and leave it at that. Um, we want to be able to control as much as we can, but that also does end up sometimes meaning uh more help desk tickets to be able to help out with, but everything should be a control process in my opinion, and as much as we can.
Red: Um, favorite topic of everyone. I just put it in the chat as an example. If you go to that, to that link, then the the group blade will be shown there and that's where end users can actually go ahead and then manage groups themselves. So if that blade is not shown in your account, that means it's blocked from uh Entra ID. Unless you're an admin or a user admin, that then the read only right still applies. So I think they can still, the group section.
Jazzy: Um, favorite topic of everyone, right? Conditional access framework. We we we get a very high and granular security with with uh with business premium, and and we get Entra ID P1 and we can configure conditional access with that. Um, security defaults or conditional access, for me that answer is always going to be conditional access. Um, in terms of security defaults it's it's on by default. Uh it comes included I believe in in all aspects of things. Uh in terms of licensing, uh it's free of charge. Uh and it does three main things. It it provides MFA for everyone. Uh you have admin protection as well. Uh it protects administrators, and legacy authentication is blocked. And it's a, it's a all or nothing situation, right? Everyone, if it's on, everyone gets it. If it's off, no one gets it.
Red: To be honest, I am pretty sure that we did make a mistake in this slide because it says it enforces MFA. Um, one of our Intune MVPs, Luis Barry, just made an article about this as well, why business premium is like a good value proposition, and he dove into it, and um in his article I read that security defaults will force users to register MFA, but then when it comes to like actually forcing them to like provide MFA, yeah, that is based on some metrics in the background by Microsoft and some mistakes that have been made. So there's been some serious cases of uh, of breach that security defaults will not force you to like provide uh MFA. So it will force you to register but not necessarily always force you to like actually perform multifactor.
Jazzy: I guess it depends on the uh on the signals in the background, right? What what is triggering an MFA policy and that could be, well that is Microsoft, right? So we don't necessarily have the advantage of knowing when and where we're expecting it. Whereas with conditional access, we absolutely know exactly when it's going to happen because we're targeting those apps, we're targeting those device states and locations, and um we're making sure that depending on the action that the end user is taking, that that requires either the authentication strengths or, so MFA or or additional authentication method to be to be uh prompted for, uh and maybe even block access for certain things. Right? Coming back to our country of of usage where we can block access depending on what country you're signing in from. So conditional access allows us to be very granular in those state of mind, and ultimately if you do have a tenant that's got security defaults on, you can absolutely still deploy conditional access policies and absolutely still run them in report only mode to find out where people will get tripped up and and find out the issues that will happen beforehand, rather than turning security defaults on and just chucking conditional access in them. We can have a phased approach. Um, in the beginning, one of my, one of the mistakes I made was security defaults have to be turned off and then you can deploy conditional access policy. But actually, no, that's not true. After various testing of re-reading how Microsoft displays it, it was more about the fact that you can create CAs so long they're in report only mode or turned off, right? They just don't, can't be on if if security defaults are, are on.
Red: I actually did not know that to be honest. I thought you had to turn them off and then create— I always turned it off and then really created the the policies really quickly. Right. Since the security— or I didn't know you could create them in report only.
Jazzy: Yeah. And that's exactly where it helps, right? You can, you can find out where your gaps are and find out where users are going to be triggered before, before it happens. Um, and talking about some of the conditional access policies that should be as part of our of our standard or or minimum uh requirements. Um, we we put together a few, few CAs that are definitely going to be helpful. Um, which is, you know, MFA for internal users, MFA for B2B guests, and MFA for guests excluding B2B. Um, but I mean, identity front door of Microsoft 365. Um, someone, someone calls it the new perimeter, someone calls it the perimeter that always existed. Um, right. Um, in terms of it just having MFA process allows us to block more than 99% of account takeovers. Um, we've seen lots of reports, we've seen cyber security defense reports from Microsoft and it's a very high number by just having MFA turned on and actually making sure they get triggered at the right places. Um, right, uh you can you can uh associate users to it. You can have your authentication methods that are applying to it. Uh and and make sure that if you, before you do deploy, you can have this in report only mode and have all of our authentication methods selected that we still deem fit for today's date, which is hopefully not text codes and phone codes and SMSs. Um, and the good news is that obviously ultimately this is an uh inforcer presentation, so we will talk about inforcer a little bit, not just Microsoft, uh but we do have these policies also available in our tier one blueprint baseline that you can review, the exact settings that we have, um and and and have it turned on and configured based, based on our recommendations and our uh best practices. Have you, have you seen the chat?
Red: I have not.
Jazzy: "Security defaults is like a chocolate fire guard." I'm going to incorporate that in my, in my own presentations. I'm taking that, James. I'm sorry, but I'm taking that.
Red: Do we have to credit James underneath it as well? Little smile somewhere in in the slide.
Jazzy: White on white text. Uh, one, one font size and that should do it, right? Love that. Absolutely love that. Someone said "security defaults is worthless for MFA. Have to combine with per user MFA." I'll be very honest, I am not a fan of per user MFA. It's uh really legacy type of way of managing MFA. So, I would definitely move towards conditional access for for um going there. But yeah, security defaults is worthless indeed. You are 100% correct. Absolutely right. Um, luckily down there is management access um for for administrators. Right. We should, exactly what what you said in the beginning uh that we discussed, the red one, about uh making sure that, you know, if you have a, have a "keeping signed in" sort of turned on and the session for administrators also lasts longer, uh we can control that here where where for administrators we have a more stricter control, right, where where they can't be signed in for longer than let's say four hours, and and we can have a persistence where where where the session um signs them out and has to— they have to re-MFA uh when they're using um administrative tasks within the portal. And we don't have to target all the resources, right, for administrators as well, we can, we can target specific endpoints that are related to to the Microsoft administrator uh centers. So like your Azure portal or the Intune admin center or things like PowerShell and CLI and Azure DevOps. So we we can target different resources and have different settings for administrators specifically when it comes to conditional access. Uh and and like it says in in in the slide there, I mean they are the the crown jewels, where the administrator accounts are crown jewels. So first of all separate the administrative accounts. Um, people shouldn't be uh using their daily driver accounts for administrative accounts as well. And again, these policies are available in in our tier one blueprints uh baseline and you can reuse these. Um, I reckon this might be a good time to add as well that you could probably configure token protection as well if if if you wanted to and make sure that uh if an administrator is logging in that they're coming in from the same device, um where where that was uh, where that was signing in from, right? So cookies aren't hijacked and they they stay bound to the same device where they signed in from. Um, I think in terms of using this, these policies in report only mode, it might be a good, good time to highlight that you've also got the um workbooks that you can can use within within Entra ID to look at the sign-in logs. Um, you can first of all use the sign-in logs themselves and filter, filter by that uh to see if there's any report only mode policies that have been triggered. Uh you can also click on the actual conditional access policy within it. And I believe there's a report only uh tab there that you can have a look at. Uh that shows you the history of the last few days um of of what's happened with that conditional access policy. And ultimately uh if you configure diagnostic settings um you have access to a bunch of workbooks as well uh that you can use to to filter against these, um I think I think specifically is the conditional access insights or reporting workbook that we can use, um and we can talk about those, I think I think there's a slide for that anyway.
Red: Uh, talking specifically about workbooks and and managing the the sign-in logs and reading those, I've actually encountered some MSPs that will uh either forget about the report only mode or don't really understand what the report only mode does. So um, yeah, we do have a slide on that, right? So we'll talk about that in a bit then. Yeah. Yeah. And I'd say that um the policies that we've discussed so far, security defaults do something around them. So um requiring MFA for internal users for instance, or for admins as well. I'd say that this is where really gets interesting since you actually get functionalities that you just don't have within security defaults. So for instance, blocking authentication transfer and blocking unsupported platforms like the uh second on the bottom, or the uh two policies on the bottom. Uh that's just not available in security defaults. I'm pretty sure it only does uh the legacy authentication one and device uh device code flow, but then the other ones, security defaults just doesn't do. And then there's a bunch of other policies as well that security defaults just doesn't do at all. So this is where a lot of added value comes in when you uh when you have that P1 functionality of conditional access.
Jazzy: Yeah, absolutely spot on. Um, in terms of how many policies that we can absolutely have in our in our baseline uh for all of our customers is is humongous, and just using security defaults uh seems to be not required and moving to conditional access is is the way forward, right? Uh and again even with these policies, uh exactly like uh uh we said previously, that that there are lots of workbooks that we can use. There may not be a specific workbook for each one of these policies, but uh using the workbooks and having diagnostic settings configured while you're pushing those policies out is a brilliant way, way to keep track of all of these.
Red: Yeah, definitely. And I'd say that specifically for these types of policies, like if we're talking about device code flow, for instance, I've seen some organizations or MSPs that will uh tell me like, we we don't know if this is being used, right? We're not entirely sure if it's being used. And that is where that reporting or report only mode comes into play where you can just have that policy in report only mode for a couple of weeks or maybe two months or whatever, and then see if that policy had been impacting some of the sign-in logs. So that, that's really important to uh take note of when it comes to like um configuring new policies in general.
Jazzy: Yeah. Yeah. Agreed. Um, we have some questions in the chat though.
Red: I'm having some technical difficulties here. My internet's just dropped out. Oh, I thought it was— not my internet, cuz I'm in a hotel. Turns out it's my internet. My, my laptop's probably too hot. I can't handle the heat.
Jazzy: Your laptop is too hot. I mean, don't you have a good laptop?
Red: Clearly not. Clearly I need air conditioning specifically just, just for this. Um, I think, I think I'm back though. I think I'm back.
Jazzy: Yeah. Yeah. Yeah. I can hear you. I can hear you just fine now. Excellent. Uh and and some, some other policies uh that we're hoping to to also have um included as part of your baselines is browser sessions for unmanaged devices. Uh the Intune enrollment, sign-in frequency and token protection as well. Uh coming back to specifically it being Windows, uh is is GA only and iOS and macOS are still, still in preview. Um, but we would love for you to have all of these baseline policies configured uh and make sure that there is good use being put to them and you're not relying on on just security defaults again, available as as part of our um policy stack, aren't they? In our blueprint baselines, a lot of these.
Red: We um we had a question in the chat about what's the best way to handle phishing resistant MFA for administrators. Uh James already answered it, but yes, definitely use the temporary access pass. Uh that that's what we utilized as well. So that's just like a one-off um like onboarding procedure where you're allowed to log in, but then after that you can actually register the the pass key. And it can be quite buggy when it comes to phishing resistant MFA. That's also what I've, I've concluded in the last like couple of uh couple of years using that specific setting.
Jazzy: Yeah. And uh seeing the gaps with Entra ID workbooks, right? So within Entra ID the logs are stored there for 30 days. Uh you can configure diagnostic settings where you can send those out to log analytics workspace uh and and store the the data there and the logs there for as long as you decide on those log analytics workspace um resource. Uh you do need an Azure subscription for this. So it's not included in terms of business premium. Uh and it is done separately. Uh but we wanted to let you know that this does exist. Uh especially because it comes with built-in workbooks that you can access within Entra ID, monitoring and health, and and then workbooks is the blade you're looking for. And there's like, I don't know, a couple dozen at least or a couple thousand workbooks.
Red: I have forgotten about these workbooks so many times cuz I would only go into like insights and reporting and go to like the report only results for conditional access policies. That's like the the place, my my go-to place to go to whenever I needed to know like what impact does a specific policy have. But please don't forget that under— is it, is it there at the audit log and sign-in logs as well? Is it under monitoring and health?
Jazzy: It is, right. Yeah, it's in monitoring and health and there's a workbooks tab there I think that you can select uh within within Entra ID itself. So we have it on the slide actually. What am I even— monitoring and health, diagnostic settings— oh yeah, workbooks. Yeah.
Red: Yeah, please don't forget about that.
Jazzy: Yeah, lots of good workbooks to choose from. You know, you've got the uh conditional access gap analyzer in there. You've got multifactor authentication gaps. And you know, no one wants to learn another language, right? We we don't want to run— learn KQL. So, it's there for you to run KQL on if you want to, but the workbooks just make life slightly easier.
Red: I'm already struggling learning English and and and running uh PowerShell. I don't want to add another one to to my list. Too many languages in my head at this point.
Jazzy: You should have, you should have learned English by now, man.
Red: I am struggling to learn English. I'm from the Netherlands, man. I mean, I'm, I'm having all of these, like you, I'm having all of these US influences and then UK influences. I'm making my own accents in English.
Jazzy: I mean, it creates your own personal accent. I mean, that's what ends up happening, though, isn't it? You watch TV shows and stuff like that, and they're all in US English or or British English, and you, and you end up confusing your own accent sometimes. And and I don't mean to do this, when I'm speaking to someone and when they speak in their own accent, I accidentally end up mimicking it. I'm like, crap, that's not what I was supposed to be doing. I was just trying to have a normal conversation. I look like an idiot trying to, trying to act like I'm copying your accent or or making fun of it. Promise, my brain just does this automatically. Copy and paste. Um, now we've got, we've got internal users. We we've got conditional access to protect us from uh internal users. We've got lots of stuff that we always think about when it comes to our internal users, but sometimes we forget our lovely guests. Now, we don't want them in our environment. I I I I always feel like uh guests should stay out, but you know, we need to collaborate with with guests and we need to make sure that that we're working with them. So, we want to talk a little bit about the guests as well. So, uh the four main guest types that that I could think of in here was, was B2B collaboration guest. So uh any any Entra ID guest you sign in with or social identity you sign in with, uh and you share a resource with them, or or you manually invite them, they they can create their own guest account uh and it will show up as as a user type guest uh within your Entra ID environment. Um, the good news is that most of their own authentication and and guest account access is controlled within their own identity uh within their own tenant, but it does show up in your identity and the footprint is is there. Um, then we've got the B2B collaboration member, similar to B2B guest but the user type is member uh instead of guest realistically. Uh we've also got B2B direct connect that we can do. Uh and that's when two Entra organizations explicitly allow each other to have access to the shared uh channel in in Teams, uh where where they can sort of um be signed into their own home environment, home tenant directory, and still communicate on on channels that exist within a different Entra ID environment. So they're not switching uh directories at the top. Uh and ultimately is the cross tenant sync option that we have where we can synchronize our users into other directories and bring other users over into our directories, which is, which is good for if you, if you got mergers and acquisitions, or or it's a multi— enterprise and it almost seems, uh seamlessly uh it works in in things like Teams and stuff where you can chat with each other. Um, we we we did used to set up MTOs, multi-tenant organizations, which is a slightly separate section uh that lives under Microsoft 365 admin center uh and not the cross tenant access blade within Entra ID. Well, it uses the underlying infrastructure of cross tenant access setting and Exchange relationships and things like that, but the MTO, the multi-tenant organization specific uh lives in— it lives in the uh Microsoft 365 admin center. Um, and what what can we do with those guests, right? So, we've got guest permissions that we can set up as well with it within user settings in the Entra ID portal. So, I think by default um it's it's limited access. So, guests can't enumerate users or directory objects but can still see membership of every non-hidden group. I mean, the guests for me, that that is more about restricted to an object. They need to be able to see the groups they're a part of um and they can see their own profile and not really enumerate everyone else within the environment. And they should really see what they've been added to. So even if guests are added to specific uh groups like Teams and uh the Microsoft 365 group there, at least they can enumerate that, right, they can look through the Microsoft 365 group um that they have access to. Um, what what would you think uh red one? I think I think restricted to an object is is probably what I'd go for on this slide.
Red: I always went with the default option here. That, that's what I did. I mean, it was a good balance of of uh letting guests be like productive in an environment but not let them, let them access too much. So, the the the default setting here was the— my go-to.
Jazzy: Yeah. Yeah. And James pointed a really good point out. I mean, this will become more important now that SharePoint adds guests when sharing files externally. So absolutely, when you, when you're sending out those files to to share externally, they are also a guest in your own environment, right? That was a—
Red: Isn't that because SharePoint now switched to B2B collaboration like underwater, from from from Entra ID?
Jazzy: Yeah. Yeah. That is correct. We actually had, we had some issues there because if your SharePoint settings and then your B2B settings didn't really match in the correct way, you, you'd have issues with guest users not being able to to access files. So yeah, that has happened and I hope you got that right by now. Yeah, absolutely. Um, and and and yeah, absolutely. So there is, there is some, some settings within um uh the Entra ID that we can, we can also set up. So uh who can invite guests, right? By default, any user can invite someone. Um, we can restrict that to only users assigned to specific admin roles that can invite guest users. So there, there are guest invite settings that we can control as well. So we can make sure that the right people have access um uh in terms of who can invite guests. Uh and then we've also got the restrictions in collaboration. So which domains can we uh, are allowed to access uh and become as part of our invited guest users. So we can restrict it further and and actually have an approved white list of of who's allowed to jump into our, our environment. Uh, and we're really close to time, so I'm slightly jumping through, through these a little bit quickly. Um, and then lastly, we've also got the enable guest self-service sign up via user flows as well. So, they can't sign up to um your Entra ID tenant uh by themselves. There, there's no self-service signup. Um, to be really honest, uh, the self-service signup flow that you see here, you can set it to no. Uh but even if it is yes, unless you actually have that flow set up and maybe associated to an app or a service principal, it's not really doing anything. But again, coming back to our point of why have it in the first place if there was no self-service signup flow required, and set that to no, right?
Red: Something funny in the chat that uh Rooney Pot said: "Microsoft has changed the default for new tenants to most restrictive." I'm guessing he's talking about the fact that the guest—
Jazzy: Yeah. Yeah. The guest property adoption of of what they can do.
Red: I didn't know that to be honest. Excellent. I mean that, that's good to know.
Jazzy: Um, we've, we've also got the the trust other tenants liberty setting. So this is the cross tenant access setting we have in Entra ID uh for B2B collaboration and B2B direct connect. Um, so in terms of that, if there, there is a, there is a tab here that that I wanted to point out. So there's the organizational settings and the default settings. Those are the two important tabs you'll notice. And the default settings, they apply to all external Entra IDs uh when when they are invited to your environment, whether you block them or allow access to certain apps. Uh and and that can be defined in the default settings, right? What resource are they allowed? Do we trust their MFA claim if they're coming from their own environment? Do we trust their compliant device states uh and things like that to even satisfy our CA? So if I have a CA that says require uh, uh to guests to have conditional access for MFA for example, we can specify that default settings and say we trust the other environments have done their job. So they don't have to double set up MFA as well within your own tenant. Uh and ultimately no matter what is set in default settings, if you have an organizational specific setting, that will apply, that will uh fall over uh the the default settings, and they're more explicit in that way. And you can set those settings up um to make sure that your communication with other inter-orgs is is restricted in the way you want it to be restricted. And ultimately going back to, exactly, don't forget about this one. Don't forget about the external sharing and the limit external sharing by domain for SharePoint or OneDrive. Exactly what we mentioned a few minutes ago. Um, where we can trust uh, uh where we can have SharePoint sites as a default not to allow any new and existing guests and have it to existing guests only.
Red: I am realizing again that when it comes to like guest management you have like five different places to go through within the Microsoft ecosystem. So the one we're looking at right now is in the SharePoint admin center, and then we have some tenant wide settings, and we have a dedicated guest uh guest section within the Entra portal. So yeah, nailing the guest management is so so important, and doing, doing it correctly once so you can just deploy that at scale if you'd like to, like especially as an MSP.
Jazzy: Yeah, control the settings within Entra ID, your cross tenant access settings, control those. Control your guest settings uh in terms of who can invite and who can't. Um and and obviously in terms of the trust settings for for um cross tenant access as well. We need to make sure we, we've looked at all of those. Uh and like Daniel said, don't forget the Teams. Teams.
Red: Yeah, I I almost forgot about it, but I don't, I don't even want to talk about guest settings in Teams, because that, that—
Jazzy: Yeah, let's not go into that. We only have two more minutes left. Do, do we have some more slides? What, what are we looking at?
Jazzy: Yeah, so I mean it's it's just making sure that what we've discussed today uh you, you make sure it stays true over time and across every tenant, right? So, uh in terms of um having this in in our environment is great. Having, having the policy switched on is absolutely great, but if it doesn't apply to anyone, if the users aren't assigned, that's a problem. Uh and and making sure that if things are changed, uh they're alerted upon, right? If there might be times where, uh help desk has changed something or we've got a co-managed IT environment and someone's changed something, use inforcer. We can help you manage all of these. We can help you deploy them. We can help you, give you baselines. We've got policies that you can make use of. You can make sure that the user assignment uh, the group assignments remain the way they should be, matching your baseline, and that if anything ever trips we're alerted upon.
Red: Yeah, exactly. And please reach out to us with any Microsoft 365 questions because we love talking about it and diving into Microsoft Learn. I actually still enjoy it some days. Not, not every day though, but some days I do enjoy it.
Jazzy: Guys, it was awesome to have you all here. The chat's been amazing. You guys have been amazing. Thank, thank you for all of you that came through. Uh hope, hopefully you, you nerded out like us and we really appreciate all of your times, taking the time to join us.
Red: What is the next webinar about? Because we— this is a series for everybody who's in the, in the webinar right now. So this is a series and the next—
Jazzy: Oh, it's in the slide again. There we go. There I go again. It's in the slide again. So next webinar is actually about Defender for Office 365 where we'll uh, we'll dive into that. So, thank you so much everybody for joining. I mean, this was a great, great amount of people that joined the webinar. So, that, that's awesome.
Red: Thanks guys. Have a great time wherever you are and enjoy your weather. Hopefully, it's as bad and good as as us, if if you like it hot. But again, what's the weather now in the UK?
Jazzy: I'm, I'm at 33 degrees at the moment. I'm sweating everywhere. Seriously. Hopefully— hopefully, it hasn't shown on my face, but I am sweating everywhere. I think it's like— definitely send the slides. A lot of people have asked to send the slides. We will absolutely do that guys.
Red: Yeah. Yeah. Yeah. Yeah. 100%. I think it's like 22 degrees or something like that here in South Africa. I mean, so it's way way hotter in in in the UK right now. UK— come, come to the UK.
Jazzy: I'll see you next week.
Red: Yes, I will be there next week. Yeah. A lot of traveling on my side, man.
Jazzy: Awesome. Well, we'll go ahead and end the event. Have a great time and the slides will hopefully be emailed across to everyone that came through.
Red: Yes, we will email the slides. Thank you so much everyone. Bye-bye.
In this session, Jazzy and Redouan dive into how to properly configure, standardise, and manage Defender for Office 365 across your customer base. From anti-phishing policies to Safe Links and Safe Attachments, we’ll uncover the most common misconfigurations leaving tenants exposed - and how to fix them at scale.
Jazzy: Look at that. We've got 50 people in here. Hello everyone. Welcome to Stack.
Redouan: Afternoon. Good afternoon. Let me present in Teams real quick.
Jazzy: How we doing? How's everyone feeling today? We are absolutely close to the weekend.
Redouan: There we go. Oh, Tim's here. We got Tim. Let's see. There we go. Are you able to see the slide deck just fine?
Jazzy: Yeah, looks good.
Redouan: Okay, we got a morning. We got a morning. Well, luckily it's 3:00 for us. It's almost over for us.
Jazzy: Not for everyone by the looks of it. See, I feel like I want to say hello ladies and gentlemen, and all the notetakers that are about to join us. There's a lot of notetakers out there trying to join the live session, notetakers joining us as well.
Redouan: We're going into a different era, man, right? We have to be inclusive. We've got to start saying hello to notetakers as well. In a year from now, we're probably going to do webinars for just AI agents.
Jazzy: Could you imagine that? Welcome, agent 007, to our meeting.
Redouan: Uh-huh. I guess we'll just wait for maybe one more minute and then we'll just start off.
Jazzy: I mean, the one thing I do definitely want to say is, everyone that's joined us from our last series, part one, thank you for coming with us, along with episode two as well. We appreciate you being here and clearly we were entertaining enough and knowledgeable enough to bring you back over to episode two as well. That's a win in my books.
Redouan: That is a big win for my book as well.
Jazzy: Excellent. Okay. Yeah, I think we can get going.
Redouan: I am actually really curious: if I make some notes with the pencil here, do they disappear? Because we tested this and they did not disappear when we tested it. So let's see. Does that go away for you, Jazzy?
Jazzy: Yes, it did. Yes, sir.
Redouan: Okay. Well, that's good news, because this didn't work for us just a couple of minutes back when we tested it. Perfect. Okay. So I guess we are just starting then. It's already 1 minute past 4, so there's probably some more people that will join in, but that is fine. What are we discussing today? First, intros. So Jazzy was really kind to me and he actually filled in my intro. I didn't care to change it from the last episode, so it's still "same as Jazzy". So I guess Jazzy can introduce himself and then that also applies to me.
Jazzy: Absolutely. We keep it simple. Saving time is what we do here at Inforcer. Thank you. Thank you for being here, guys. I'm Jazzy. Microsoft fanboy, as you know. Absolutely love to talk Microsoft, do Microsoft, everything related to the admin portals. I probably touch every button even though I have no reason being in that pane. Still enjoy doing it. Still have my own demos at home. Talk to myself whilst I'm looking at admin portals. Still the official IT support for my parents. My parents did ring me a couple of days ago asking to help them set up their phones, because you know, calendars be calendaring, and it sometimes is a tough thing to do for parents, but I am on speed dial for my parents, as always. And my IT career is always with MSPs. That's all I've ever done, work for MSPs. I know how to manage multiple tenants at a time. If you ever ask me to be internal IT and how to manage one tenant, I may struggle. I only succeed when I have multiple tenants to manage at the same time. But hey, being Inforcer, that's what we do. We manage multiple tenants at the same time. And yeah, like Redouan already explained, I was too lazy to ask him for his details. So I did what every good colleague does and did his work for him and filled out his little intro there.
Redouan: Yeah. And then just fill it up with "same as Jazzy", right? What a good colleague you are, Jazzy.
Jazzy: Thank you. I appreciate that.
Redouan: But actually my intro is quite the same as yours. I worked for an MSP as well. I worked in a modern work team for an MSP in the Netherlands. We were mainly concerned with a lot of enterprise customers. And I basically just configured all components of Microsoft 365 for the past few years, and since a month or two now I'm a solutions architect here at Inforcer. Also official IT support for not only my parents but my whole family, who chipped in by now. I think mine is actually worse, my support, because I have some people in my family that still use dodgy extensions in the browser and stuff like that. Don't get me started on that, please. But yeah, let's dive into it.
Jazzy: Awesome.
Redouan: There we go. So what are we going to cover today? The stack that you might already own: what is already included within Microsoft 365 when it comes to email security? Because when we're talking about Defender for Office, of course, we're talking email security. The baseline you already have: Exchange Online Protection is always included, so that's a baseline that you always have. What does Business Premium add on top of Exchange Online Protection? When we say Business Premium, we mean Defender for Office P1, since that is included in Business Premium. But we'll dive into that in a bit. The settings that get missed easily. And then last but not least, from configured to enforced: the fact that you just made a policy doesn't mean it's actually enforced. Let's dive into the first one, the stack you already own. There we go. Oh, excuse me. So, stack you already own. There are multiple layers to email protection within the Microsoft ecosystem. The first layer of protection is Exchange Online Protection. It's always included. Every online mailbox within Microsoft 365 has Exchange Online Protection. There are already quite some things going on there, so it's, I would say, a very good layer of defence, a first layer of defence. As you can see on the slide: anti-malware, anti-spam, anti-spoofing. I'm actually missing the connection filtering there as well. That's also included within Exchange Online Protection. I can see that Tim included a screenshot over. Is that, oh, I think they're referring to the registration page for scoring. Yeah. Okay. Perfect. Perfect. So Exchange Online Protection, the basic security defence that you already have. Then what does Business Premium add on top of that? Defender for Office P1: safe links, safe attachments, more anti-phishing capabilities. And then last but not least, P2. So P2 will include some more proactive capabilities, automated investigation and response. Maybe you don't want to investigate those emails, so let Microsoft do it with their runbooks and their playbooks, and then also attack simulation training. So that's the security awareness training where you can do some phishing simulations. Anything you have to add, Jazzy, to those three layers?
Jazzy: Yeah, you're absolutely right. It makes sense. I mean, every mailbox that you ever get, if it's a cloud mailbox within Microsoft, you end up getting EOP, especially with the built-in protection. Exchange Online Protection adds a lot of value to it from the get-go. It's just that Business Premium does add a lot more layers to it. You get so much more out of your Defender for Office 365 Plan 1 for a proper enterprise-grade email security solution, competing with those bigger competitors, should I say, and other email security solutions out there. And having all of that in house, you know, when it comes to Business Premium and having Defender for Office 365 Plan 1, it just lets you become an expert on one platform, and keeping the tooling in house helps you with that strategy as well. So you've already got it, right? Most of our customers hopefully are on Business Premium, and if we can leave them on there, and if not find a way to get them on there, it will give us so much more security and so much more ease of use than having to look at so many other solutions out there on the market. So we highly recommend the use of Business Premium out here. We love it. Both Redouan and I have heavily used Business Premium tooling. Enterprise E5 and E3 is great as well.
Redouan: I know for a fact that you have been in Microsoft Learn a lot, because I heard you say enterprise-grade email security and that is straight from Microsoft Learn. You've been in that documentation a lot, on any Microsoft Learn page, sitting there like that and that's all you need to know. I recommend this. So you can see the screenshot, in the bottom right corner you can see m365maps.com. It's a really good resource when it comes to licensing. And if you're asking yourself what capabilities are included within certain licenses, please go to m365maps.com. It's a great resource. You can see, so let's see if that pen is still working. Yeah, there we go. Exchange Online Protection is always included, but P1 builds on top of that. So that's with the advanced anti-phishing, real-time reports, safe attachments, safe links. We'll dive into that in a bit. And then P2 builds on top of P1, so everything in P1 is included, but then also the simulation training that we talked about, AIR and some other things. Now, we're talking about P1 and P2, but when do you actually get P1 and when do you actually get P2? Because usually they're included in other licenses, right? So there we go again. Next screenshot, also from m365maps.com. Forgive me if you can't really read it all that well. I think it should be fine for you guys. But as you can see over here, P1 is included in E3 and Business Premium. And there we go, E3 as well. So if you have Business Premium and E3, you have P1, so Defender for Office P1. Everything below that, Exchange Online Protection, is included. So you get that for any mailbox. E3, Business Premium, P1. And then anything above those licenses is Defender for Office P2. So for instance an E5, or maybe an E7 that you can see over here, you get the Defender for Office P2 functionalities. And also with the Defender suite and Purview add-on, you also get P2 included as well. So that's a little bit around licensing. I know licensing can be an issue when it comes to Microsoft. I've never seen someone smile when we talk about licenses. Sometimes it feels like it's a whole job role dedicated to just learning licensing.
Jazzy: Yep. Yep. Definitely, definitely.
Redouan: So the most logical step for us to take, or the first step to take, is Exchange Online Protection. What is actually included in that baseline that you already have for all of your mailboxes? So there you go. Jazzy, you want to take it? Am I taking it?
Jazzy: Yeah, let's go for it, man. Let's do it together. Go for it.
Redouan: Yeah, you start. Go for it. Perfect. Okay. So Exchange Online Protection, this is the basic foundational security that you always get: anti-malware, anti-spam, and some anti-phishing, but it's some basic anti-phishing capabilities. Anti-malware, there's not a lot of things you can configure there. Most of it is heuristics in the background, some engines that Microsoft runs. We can configure some things there, but I guess the main thing I want to say here is that these three components are already included, because we're actually deep diving into every single one of these components in the next slides. You already have a default policy for each of these, so it's already configured in some way. It's not always configured in the best way though, so we'll discuss that as well. Do you have anything to add?
Jazzy: Yeah, I mean it also includes ZAP as well within there. And it basically is the scanner that makes sure that if the email does get delivered, even afterwards, it's the pulling mechanism for email that gets delivered in case new signatures get released and Microsoft realises that there was malware in already delivered emails. So I think in terms of ZAP, I'm glad that that's included in Exchange Online Protection as well. So you get that extra added benefit of being able to pull out emails that are already delivered. An excellent inclusion in terms of the basic protection that you get.
Redouan: Yeah. Yeah. Perfect. Everybody forgive me for the next screenshot, but I promise you it will make sense. Just bear with me here. So we are looking at the actual Defender portal and where we are configuring Microsoft Defender for Office, right? So on the left hand side you can see email and collaboration, that's where you configure most of Defender for Office's configuration. At the top you can see that the colours are actually bound to the licenses. So this is a Business Premium tenant that we're looking at right now. The top two ones, so investigations and export, they're not included. This is a P2 functionality. If you click on it you just basically get an upsell, so we cannot configure those. That's not a possibility. This is really small on my screen by the way, so I might have issues making proper X's. Let's see if we can get that. Next one, real-time detections. That is a specific P1 functionality, so that is included if you have Business Premium. Review is where you review your quarantined messages or your blocked senders, for instance. It's always included, also in Exchange Online Protection, so you also get that. Next two, upsell again, only P2 functionality, so you cannot actually utilise those if you have Business Premium. Not able to configure that. And then the message trace is always included, so also if you have Exchange Online Protection you can configure that. If you click on policies and rules, you can click on threat policies. I'm pretty sure you have the option alert policies and threat policies. And then this is where you can configure most of the policies within Defender for Office. So at the top here we have templated policies. These are the presets that you can configure. These are preset policies made by Microsoft. We will dive into those in a bit. If you utilise those, it depends on what license you have: if you have P1 and you're enabling the presets, you actually get more capabilities in those preset policies. And if I go down a bit, so in the actual policy section, there we go. Policy section: the first three policies are already included in Exchange Online Protection. Those are the ones that we just discussed. So anti-malware, anti-spam, and anti-phishing are included in Exchange Online Protection. So you get this for every cloud mailbox. But as you can see, anti-phishing is also in an orange box, because you get more advanced anti-phishing capabilities if you have P1. So if you have a Business Premium tenant, you actually get more capabilities in that anti-phishing section, if that makes sense. And then most of the things that you see in the section below, so that's rules, that's included in every mailbox. You can configure most of that with any license. So this is from the administrator's perspective, what is included and what is not included in Defender P1. Jazzy was telling me, like, I'm not sure if you need to show this with all of the colours and stuff, but I hope it made sense in the end.
Jazzy: Ultimately, if that screenshot was far too small, log into the portal, security.microsoft.com, have a look at it, compare it against what you were showing. You may be able to see some of the boxes and make it make sense, right?
Redouan: Yep. Yep. Definitely. Definitely. You taking presets?
Jazzy: Yeah, I mean, presets or custom policies. Ultimately Microsoft does great work for us. They give us a lot of help. They bring preset policies out there for us and they're essentially templates that Microsoft have brought out for us. So they include different types of presets. We've got the standard preset, the strict preset, and if I'm not wrong, correct me on this, Redouan, but there's also built-in protection that's always on as well, which is the lowest tier that's always on in terms of some of our policies in there, but it doesn't contain a lot. But think about it this way. If you've got presets, why would you need custom policies, right? There's different reasons to have different aspects enabled. So if we've got a Microsoft preset that does some of the standards for us already, do we really need custom policies? For me, the answer always would be yes. But if you've got tenants that are quite small, or they're not going to benefit from having customised policies and you want to work with Microsoft's best practices, we can absolutely go for the presets that are already in there. Now, think about it this way. When it comes to presets, there's only certain things that we can edit, right? Because they're a template in there. And having those standardised policies does mean that things will also get updated. So if Microsoft decides to change some of their reasoning behind the way things are set, we can continue to use those. But then with custom policies, you fully own it. However, that does mean that you have to make sure that you edit your own policies to the way that it's usually secure and productive for the end users as well, because you don't want to have the ultimate security in there where no email goes through and all you've got is 100% of help desk tickets coming through, of each email needing to be reviewed by absolutely everyone, right? So, scenario one: you've got a few small tenants. You enable the presets for standard users, and then you can have some strict presets for execs as well. You can limit that to the types of user there are within the business. The catch is, though, some things you cannot enable within the preset that you still need a custom policy for. Whereas scenario two, you want more control over that. You can tune how you want the bulk email threshold to be. You want to tune what the quarantine policies are, or which part of the anti-phishing policy or the anti-spam policy does what, based on the thresholds there, and quarantines certain results of certain emails for user-releasable quarantine policies or admin only. So if you've got an anti-malware policy in there and you define an email to have malware in there, you don't want an end user to be able to release that. That's going to be an admin-only release. You can have a look at it, show the end user a preview of the message if you want to, but ultimately an admin is responsible for making sure that that email is actually clean and doesn't contain things that it shouldn't contain. So that's where scenario two comes in. And if you do have custom policies that you've created, whether using our Inforcer baselines, because we have email protection blueprints already that help you get going, which include all of your anti-malware, anti-phishing, anti-spam both inbound and outbound, that you can use from our email protection blueprints and align them across all your tenants. But what you can also do is you can adjust them in your baseline. Use ours as a recommendation, a starting point, and go from there. And we'll talk more about these in a minute as well, what these specific policies are. We'll do some deep dives. But then we've also got the configuration analyzer built in, that basically compares your live policies and grades them against what they think is part of their preset, what they think is a better option or what they think is a better setting. And you can help identify your gaps. Maybe there's a couple of settings that you don't like from us, or maybe you've configured your own baselines, and you can use the configuration analyzer to see what Microsoft thinks of those policies.
Redouan: Yeah, makes perfect sense. And just like you said, I'd say the main argument for an MSP to not utilise the custom policies is that now you have to update those policies by yourself. And if you don't have some sort of a multi-tenant platform that can help you maintain those in a baseline, it makes perfect sense to go with the presets. If you do utilise Inforcer, you can just define those custom policies once and then keep on monitoring them and configuring them for all of your clients at once. And you also get that more control. And I'm pretty sure we also show that in a little screenshot. So you were able to see it in the previous one as well, but the presets are pretty simple. You've just got a toggle: standard, strict, turn them on, turn them off. And then the configuration analyzer is really on a setting level, and it's just in comparison to the actual standard preset policy in the presets from Microsoft, or the strict ones. So you have standard recommendations in the configuration analyzer and strict ones, and they just basically adhere to the preset policies in the presets. So, if that makes sense. There we go. That's the actual configuration of the presets. Not a lot to do there. It's just turning them on or turning them off. Basically, if you want more control, definitely go for the custom policies. Let's see what is there.
Jazzy: We've got a question here in the chat from Josh: do you recommend using those blueprints if you have other anti-spam services in front of Exchange Online? So we're thinking other security solutions that live before Exchange Online, before the connectors in there. Redouan and I had this chat earlier, of how we think it works well for an MSP. The bad point there, at least the con that I think we have there, and Redouan chime in here, is ultimately when you have more than one product doing the same thing, you have more than one place to manage quarantines. You've got more than one place to find where that email got stuck, and having to release it is just a little bit more time and effort from the help desk. You have to look in multiple places. Personally, I would say maybe use the built-in protection or one of the presets and don't use the custom policies, if you want to do that. Or maybe tweak them in a certain way where you keep both of them aligned, but it's more tough. If you can move that customer over to get Business Premium or get Defender for Office P1, move them over that way and use one solution. But there is realistically not a right or wrong way to do this. What do you think, Redouan?
Redouan: I am with you on your arguments, to be honest. You would have to ask yourself, if they are doing exactly the same things, why not utilise one instead of both of them? But that can be a very specific edge case, why you are still utilising the other service. So yeah, I'm with you on that one. So, next one, first deep dive actually: anti-malware policy. So we're still discussing Exchange Online Protection. Not a lot of things that you can configure here. It's pretty basic stuff that you can configure here. So there are like 50-ish attachments that are already blocked out of the gate if you enable that within the policy. And then you can also add attachments and you can also remove attachments. So that's based on the business context of that specific client. We had some big clients that needed to utilise some of those attachments. The next question that you can ask yourself is, should they be sharing those folders or files in the email in the first instance? Shouldn't they be utilising OneDrive links, for instance? So that can be something you need to discuss with your clients as well. So these attachments will be blocked by the anti-malware policy. Zero-hour auto purge is also something that is configured here. It's a pretty small checkbox, not a lot to do there. So you either turn it on or turn it off. The recommendation is turning it on. There is one really interesting one though, and I want to discuss this with you, Jazzy. I think we just discussed it as well. So, this one: what should happen if one of those attachments or malware is found within that specific message that is sent? So I'll actually go ahead and go to the next slide, or the screenshot. And it's specifically this setting over here. The Microsoft recommendation in standard and strict is actually not to quarantine the message. It's reject with an NDR. And our own blueprint also does that, reject with an NDR, since it's a Microsoft best practice. So it kind of makes sense, right? I have implemented E5 security for one of our enterprise customers back when I was working for the MSP, and I was working with a managed SOC and SIEM service that they were already utilising, and they basically told me, like, hey, if you are rejecting that with an NDR, you're basically informing a threat actor, for instance, that their message has not been delivered, and now they're probably going to tweak their message in multiple ways. And when they don't receive that NDR, they actually know, hey, our malware was actually sent. So I will leave this open. You can configure it either way. There's no real right or wrong. We did actually change this to quarantine the message, so we're not sending that NDR to the people that send the message. But this is something that you need to configure yourself. If you do want to go with the Microsoft best practice, go with reject with an NDR, because that is the Microsoft best practice essentially. Anything you have to add there?
Jazzy: Yeah, I fully hear you. I mean, for me it's the same thing, right? If we don't want to let the threat actor know that we're rejecting these, because how it basically works, the common attachment filter literally looks at exactly what's in the files, right? It's blocking it based on file type extension, but the common attachment filter also has true type matching. So if someone edits the file extension that you've blocked and changes it to txt or whatever, it will read the characteristics of the file and determine if there's an executable, and it will still block it. So ultimately you are using the common attachment filter to block the email right from the get-go. No one's sharing executables. No one's sharing DLLs via email. Why do you need to bring that in, right? So considering that fact, if you are quarantining it, you still have the ability to look at the email afterwards, but at least you know it's been blocked from the get-go. You're not worried about it. No one should be sharing those files via email. You're sorted. The NDR scenario, absolutely, you're constantly telling the threat actor, listen, you can't get through, keep changing that file type, keep changing the way you're getting into us, and they're just going to keep trying, right? And you won't even know it's happening unless you do proactive research and figure out what's going on there, what's being rejected. So I think pump the common attachment filter with the file types. Customise them if you have more that you want to put in. ZAP's using it in case it does get through for other stuff that you're not specifically blocking in it and Microsoft does realise and it can pull it out. And make sure you turn notifications on, right? Have these notifications being sent to an admin when a message is quarantined, or when these emails are coming through, whether that's internal or undelivered from external senders, because we get a toggle to set the notifications up for both email types. So I definitely think quarantine might be the way forward.
Redouan: Okay, perfect. I agree, of course. How about spam? What can we configure here? So the first thing is, when it comes to forwarding there are two settings there. So auto-forwarding off, system controlled, and you actually have a third one, I think it's auto-forwarding on. Just know that auto-forwarding off and system controlled are actually exactly the same. Microsoft Learn now also notifies you in that specific article, because system controlled now is secure by default, so auto-forwarding is basically turned off. You can configure some limits there. So how many emails can a sender send before they are actually blocked? And what is important there is you have two options when it comes to blocking. You can block them immediately and keep on blocking them until you review that, so you as an admin need to review, do I actually want to allow this sender to send mails again? Or you can block it until tomorrow. If this were a threat actor and you're not on top of those instances immediately, tomorrow is actually another chance for that threat actor to start sending out mails again. So it makes perfect sense to just block them and keep on blocking them until you actually review that. Do you have anything to add, Jazzy? I think I'm missing out on something.
Jazzy: Yeah. No, absolutely. So the outbound spam policy isn't configured by default. So even if you've got the preset policies, when you've got the standard or strict policies, they don't configure your outbound spam policy. Now, think of outbound spam as your other sort of policy where you're blocking and containing what's already happened, right? So let's say a threat actor does get in, they achieve it via a phishing page or somehow they've managed to get in. What they're going to try and do, the usual case, is BEC, right? Business email compromise. They're going to try and utilise that account, because it's a domain that's, you know, it's whitelisted across lots of other places. It's got authority. It's not been blocked by other email gateways or email providers. So they're going to use that to try and phish other customers, or other users, sorry, should I say. They're going to try and email out as much as they can and make the most use out of a hacked email address, or a compromised email address. And that's where I think it should be part of the standards as well: your strict preset or your standard preset should be part of those preset policies, but it isn't today. And I think we should configure that, to be able to contain what can happen once, unfortunately, someone does get breached. Now, those recommended values there are 500 to 1,000. Those can be changed depending on what your customers are mainly doing throughout their email journey. How many are they realistically sending? Is 500 a good number? That could be lowered, if no one's sending more than 100 emails per hour, you know, if they're not a marketing agency, or depending on what your industry verticals are. Your outbound spam policy can help you a lot. And in terms of restricting the user from sending mail, I think it should be a manual step to verify, hey, why have you sent this many? We have a hard limit, and let that be notified across to your admins as well, so you can review what's happening. And especially sending a copy of a suspicious outbound message, you can clearly find out if this was a BEC. So I think it's easily missed out, and it's good to have these set up as part of your baseline.
Redouan: Yeah, makes perfect sense. And when it comes to the limits set there, so 500 and 1,000, I'm pretty sure that the strict presets define 400 and 800 as the values there, but other than that, yeah, spot on, and nothing to add on my side. Love it. Okay, so this one is an interesting one: allow and block list hygiene within Defender for Office. Since emailing is such a core component of almost every organisation there is, right, allow listing and block listing is something that probably needs to be done at some point. And I've seen some organisations that have a really big allow and block list, and some that almost have nothing there. There are, I want to say, like five different places where you can configure allow and block lists within Microsoft 365. You can do it in the actual anti-spam or anti-phishing policy. You can do it in the tenant allow and block list. You could do it in Outlook, with safe senders and blocked senders. And then you can also use transport rules for that. So there are a lot of different places where you can configure allow and block lists. Then the main thing that I want to point out here is that the tenant allow and block list is virtually always the preferred way to go. That is always the preferred way to go, and you're only going to one of the other options if the tenant allow and block list for some reason will not resolve this specific edge case. And then there are also two different ways of submitting something in the tenant allow and block list, because there's a way...
Jazzy: I mean, we're talking Microsoft, right?
Redouan: There's two different ways. So one way is going directly to the actual tenant allow and block list, which makes perfect sense, and then you can go ahead and put in domains or senders, whatever, there, and you can allow or block them. The other way is you go to the investigation and response section on the left hand side in the security portal. You have, I think it's submissions, and then under emails you can actually submit emails to Microsoft for analysis, and then the next step is also sending it to the tenant allow and block list. But now you're also sending it to Microsoft and putting it into the allow and block list on the tenant side. If you have a good reason not to submit it to Microsoft, then it's fine, put it directly in the tenant allow and block list. But other than that, submit it to Microsoft so they can actually change their heuristics and whatever, and their rule sets that apply. If you put something in one of the allow and block lists, what does it actually bypass? It will never bypass the malware checks and high confidence phishing. Those will always stay blocked and those will always quarantine. So you're not able to bypass those. And yeah, just some basic hygiene: if you know a domain is bad, don't just block the specific sender. Block the whole domain. Makes way more sense, of course. And then the hygiene is way easier to maintain.
Jazzy: Yeah, spot on. Completely agree. I mean, let's be good Samaritans and push it out to Microsoft and report it to Microsoft to always have a look at, so we can help others as well, right?
Redouan: Yep. Yep. Definitely. This is actually straight from Microsoft Learn. So Microsoft actually shows you the different ways to allow senders and to block senders. And as you can see, there are multiple ways of doing it, but the most recommended one is always the tenant allow and block list. So always go with that one if you can configure it. These are the two different ways of putting something in the tenant allow and block list. So on the left hand side, you can see you can do it directly in the tenant allow and block list under threat policies as well. And then on the right hand side you can see that you can also submit it to Microsoft, and then the next step here is actually putting it into the tenant allow and block list as well. Yeah, perfect. Let's see. Okay. Everything we have discussed so far is actually already included in Exchange Online Protection. So now we're going to discuss what does Business Premium add, or what does Defender for Office P1 add, because you also get P1 with an E3 license, for instance. Safe attachments. I know this is Jazzy's favourite subject, so he can do this one.
Jazzy: Absolutely love it. So with Defender for Office 365 P1, which is a mouthful, but we always get there at the end, we've got safe attachments, which basically means the attachment is checked in a sandbox and detonated right there, rather than just looking at the signature. It catches zero day malware as well, because it's running in that sandbox. Now the beauty is that if you do have the ability to configure safe attachments based on your licensing, we've got multiple options for what we can do with the delivery of that email, right? So we can block the email until it's been checked and considered safe, and then it gets sent out once the attachment's been checked. And I think that's a good way of doing it. You do have another option, which is a dynamic delivery option, where the message is delivered before the attachment is actually fully completed and checked. So the body arrives and there's a placeholder for the attachment. Now the only thing here is that your end user could see a text that says, "Hey, I've sent the attachment, please see the attachment attached and let me know what you think about it", whatever the email is, but they don't see one. That could lead to a ticket to your help desk, or that could lead to an email being sent back to the sender of that email saying, "Hey, I don't see an attachment. Please can you send it again?" But in fact it was actually still being scanned and just the body was being delivered at first. Now, if I'm not wrong, you do see a message that says the attachment is being scanned, please wait, blah blah blah. But it's a small box that can be easily missed. So I think having block is a better way of doing it, because the end user isn't confused. It delays the delivery for up to, what, about 15 or so minutes, or however long it takes to scan that email and the attachment, and then it gets delivered. But if you're in a high paced environment where that body needs to be delivered, and you're happy to maybe slightly confuse the end user a little bit, then we end up sending it as a dynamic delivery. Now this is obviously all the attachments being scanned in email. And block is Microsoft's default and is what's set, I believe, in standard and strict as well, if you have the ability to configure safe attachments. And I'd probably leave it at block as well, but you do have both options. It's just a cleaner look, or a cleaner delivery mechanism for me, where there aren't multiple deliveries happening. The only other thing I will add here is that safe attachments can also apply to SharePoint, OneDrive, and Teams, being sent across and being scanned there as well. It's just a toggle that lives within the same policy area, where you can press the settings cog at the top and it'll show you the global settings to enable it for those locations as well. That's the only other thing I'd like to add there.
Redouan: Yeah, and I think that's a screenshot to show what the options are for the detection response. Yeah, you cannot configure a lot in safe attachments. It says dynamic delivery here. We configured this as dynamic delivery. Jazzy and I actually had a talk about it, that they utilise block and we use dynamic delivery. We actually got tickets because people sent an email and then had to wait for like 10 minutes before the actual receiver got the email. So the receiver knew, I am about to get an email in about a minute, but it took like 10 minutes or 15 minutes, and people would already be calling like, hey, I didn't receive this email, whereas it was just taking too long, or taking some time to scan the attachment. And with dynamic delivery it does get sent immediately, but just the attachment will be put there later. Yeah. So we actually utilise dynamic delivery, but I do know that the Microsoft best practice is block, and we also block in our blueprints if I'm not mistaken, because we adhere to the Microsoft best practices a lot. So yeah, that's my take on it. We actually use dynamic delivery for this. Safe links. Okay, there we go. So, another P1 functionality within Defender for Office. You can rewrite links. You probably know it, I think it's always like email protection, safe links, it says something like that. It's always the same thing that it says. So it actually rewrites the links that you click on in messages or in emails. You are shown that for a couple of seconds and then it scans it and then it opens up the link. So this is a real-time scan. Let's say someone sends a link in an email and that link, or that website behind the link, is actually a good site at first. There's nothing wrong with it, but that site then later, maybe two weeks later, is changed and it's actually malicious. That was one of the things that used to happen. So this is actually a real-time scan. So whenever somebody clicks on the link, it can be two weeks after the message has been delivered, it gets scanned again. So that's a really important one. It already says it on the slide: built-in protection here is not best practice. It's not configured as best practice. So please do use the standard or strict preset, or make your own custom policy, because the built-in protection is not enough here. Like it says here, click-through is allowed and it does not rewrite some URLs. So that does make a lot of sense. So please make a custom policy or use the standard preset. I'm sorry that the screenshot is not that good quality, but there's way more to configure here in safe links. And again, something that you configure once with a platform like Inforcer and then just deploy at scale. Don't think about it too much after that. Yeah, perfect. So yeah, let's see what we have after that: anti-phishing. So this one is included in Exchange Online Protection, but once you have P1 you actually get more capabilities. So if you create a policy when you have P1, you have way more options to choose from. Most of them are around impersonation. So that can be user impersonation, as you can see on the slide, and domain impersonation. These you always have to configure yourselves. Even if you're going with the standard preset or the strict preset, user impersonation is still something that you need to configure, since it's so tenant specific. It's specific to your client. And think of VIPs, think of C-level management. That's the type of person that you will probably put into user impersonation. I think I have a slide here that shows the difference. Don't mind looking at the actual settings. I know the quality is not good enough, but just to give you a reference: on the left hand side it's an anti-phishing policy, all of the things that you can configure if you have Exchange Online Protection. Right hand side, you have P1, you can actually configure way more within that policy as well. Yeah. Anything to add, Jazzy?
Jazzy: The only thing I'd probably add is maybe that, once you get this PowerPoint deck, everyone, you can zoom into the pictures a little bit.
Redouan: Good point. Let's see, the settings that get missed. Of course, quarantine policies. We need to talk about quarantine policies. So if you click on threat policies, you can also configure some quarantine policies. You have some default ones. Some default ones are default full access, for instance. You also have an admin only one. There are some policies that will always default to the admin only policy. So that's anti-malware and high confidence phishing, for instance. They will always go to the admin quarantine. Only the admin can see it and they could release it. But I'm not even sure if they can release it for anti-malware, if I'm being honest. They can for high confidence phishing, if I'm not mistaken. But you can make your own quarantine policies and then you assign those quarantine policies to the threat policies that you configure. So if you want to give users the ability to go to the quarantine and actually release messages themselves, you can do that, in order to not get a lot of tickets about messages being put in quarantine. The compromise here, I want to say, is go for limited access. Like it says on the right hand side, users can go to the quarantine, they can see the message, but they can request a release, and you get sent a notification that someone wants a message released. So you can still look at that message and see if it's a malicious message or not, and you can actually investigate that.
Jazzy: Yeah. The beauty of this is that it's highly customisable, isn't it? Like for high confidence phishing or high confidence spam, you can have different policies for your quarantining. For your lower risk stuff, you can have different quarantine policies. So we can allow you to, well, not we, Microsoft allow you to sort of have your own customisation where you trust the user a little bit, not saying you should, but maybe sometimes we have to trust the user a little bit to make their own decision and say, okay, this is a low-risk email that we can possibly let you view and probably release from quarantine if you want to. But for the high-risk stuff, sorry, leave it to the admins to release and even the admins to maybe preview. It's safer that way.
Redouan: Definitely. Definitely. For the next slide, again, I'm sorry, but it's going to make sense. I promise.
Jazzy: Trust the process.
Redouan: Trust the process, boys and girls. And the agents, trust. Of course. Of course. So, we have discussed Exchange Online Protection. We have discussed Defender for Office P1, right, and all the capabilities there. So an email gets sent by an external sender to an organisation and it goes through all of this filtering, right? And there are a couple of things that can happen, but let's say an email actually does get delivered and it's in the inbox. What then happens? What happens after that? So like I said, trust the process. Here we go. So, left hand side, preparation. An email gets sent. It goes through Exchange Online Protection first. If it is blocked by the connection filtering or the URL and domain block list, it gets rejected, right? If it is seen as malware, or maybe safe attachments rings a bell, it will probably go to quarantine. So this is quarantine, this is quarantine, this will most likely also be a quarantine, or might also be the junk folder. There are three things that can happen to an email: it can either be fully rejected, it can go to quarantine, and this can be a user or admin quarantine, and it can be delivered in the actual inbox, and this can be the inbox or the junk folder, right? What happens after that? There are three things that can happen. The first thing is the user sees the email and then reports it. So you have the report button. You actually have to configure that in the settings in Defender XDR, that the report button can be used. An admin can see that a message has been delivered and they can also proactively then do something with that message. And then we've already discussed ZAP. ZAP is configured in the anti-malware policy, and this is basically Microsoft helping you with messages that have been delivered but then they retroactively actually remove a message from the inbox. So that's also a possibility. Let's say that you as an admin actually find an email that is malicious and it has been delivered, or the user reports it. So if a user reports it, what happens is you will see it in the submissions section on the left hand side of the security portal. You have investigation and response, submissions, and then user reported. So that's a little tab there. In the user reported section, you can actually see all of the emails that have been reported by users. And then you can go ahead and start the analysis of that specific message. So what can we do? We can look at the metadata. Metadata, actually "metadata" is a strange way of saying it. We just had a colleague from Australia that says "data" and I'm saying "data" as well. So that was one of the very difficult things over the last week.
Jazzy: So last week, as Redouan said, we had an Australian colleague of ours come over, an excellent M365 engineer, and there were a lot of words mentioned that we're not used to hearing, "data" being one of them. "Data" was one of them. So every single time "data" or "data" was mentioned, we'd lose all track of what we're doing and just die in laughter, and then it'd take another couple of minutes to revert back to what we were actually talking about and reset. Just like now.
Redouan: Just like now, basically. Case in point.
Jazzy: Case in point. Shal, if you're listening, we love you. Thank you for giving us this banter.
Redouan: What else can we do? We can look at the actual content of the email as well. You do need a specific preview role, and that is a Purview role. So that's the only way that you can look at the actual content of the email. You might actually want to discuss that with your client, because they might not like it that you can actually look at the content of the emails. You can use the threat explorer, so you can actually explore all of the emails that have been sent and you can map them to specific indicators of compromise. You want to see if any other emails have been sent by that specific sender, and you can see that throughout the whole organisation. And you can of course also always call the user, because the user might have some more context around that specific mail. Is the email malicious? You will have some procedure in place. Maybe you need to notify some people. The next question is, how can I eradicate this specific email? What actions can I take as an admin? So, two things here. The first thing is, if you have P2, you can let AIR do the work for you. You can let AIR actually investigate the email, and AIR can also then perform some eradication steps. If you're doing it yourselves, these are basically the actions that you can perform. You can move the email yourself. So you can move it to the inbox, you can move it to the deleted folder, you can hard delete it as well. You can block some indicators of compromise. You can even isolate a device if you know that the device has been compromised because of the email, but that's a pretty strong eradication step, so that won't happen a lot. I mean, I hope that doesn't happen a lot. And of course some user actions that you can also perform. So that really depends on every scenario, of course, that you're investigating. Last but not least, recovery and lessons learned. You can actually notify the end user of the result. So you can let them know, so there's a feedback loop: hey, this message was actually phishing, or it was not phishing for instance, or it was clean. And of course you can also then tweak some of your policies. So you've configured all of your policies, you've configured your allow entries for instance, but you might need to change something there because of the investigations that you've performed. So maybe one of your policies needs to be fine-tuned. Anything you would add?
Jazzy: The beauty of Inforcer, I would add here: if you do need to fine-tune your policies, you change it once and it gets sent across all of your tenancies, doesn't it? So I don't know how many of you in the chat here are using Inforcer today, but we've recently released align by policy instead of align by tenant. So before, with align by tenant, you were looking at all of the policies configured for one tenant and then making your changes. And then we've also got align by policy now. So within there we have the ability to essentially look at one policy and see how it fares against all of our tenancies. A little bit of a better process, I would say. But I'm glad it's here now. And that's probably the only thing I'd have to add extra on top of that. That was an excellent explanation. And again, once you get the deck, you guys can read that. There was a whole heap of lovely flows that we can review and make notes of.
Redouan: Yeah, Jazzy told me I should have put some animations there so it's not everything at once. But I think I did fine. I think I did fine.
Jazzy: I think you did great, mate. You've got your red pen. You did absolutely fine.
Redouan: I love the pen. Just wait until I take the laser out. There we go. Laser. There, precedence. So, something to note here: there is actually a precedence when it comes to policy. So we've discussed the presets that you can configure. We've discussed the custom policies that you can configure. And there's also the built-in protection. If a strict preset policy is applied to a user, nothing else will apply. Nothing else will apply, since that has precedence over all of the other policies. So that's a very good thing to know. You can have some sort of a catch-all system where a custom policy has all the users in there, and then for instance C-level is only in the strict preset, but then if for some reason a C-level executive is removed from that policy, they still are in that catch-all policy, the standard policy that you always use. So it's good to know: preset policies first, then custom policies. They have a priority system themselves that you can configure, and then comes the built-in protection and the default policies.
Jazzy: This is probably a good thing to note, because you know, the trap here is that if we have sent all of our custom policies to our tenancies and we're maintaining those, the strict preset button or the standard preset buttons are probably taking effect on top of your custom policies. So if you've configured your email protection properly across the board using custom policies, toggle those presets off and make sure that your custom policies win, absolutely. And the configuration analyzer is mentioned here again, which I think is still a great place to see how we fare against Microsoft's best practices with our custom policies as well.
Redouan: Yeah, definitely. Some last slides. So, we need more, Defender P2. We've already discussed some of it. You do get some extra capabilities, AIR for instance, so that's the automated investigation. You can let that investigate all of the submitted phishing emails and stuff like that, and it can also notify end users. So if you are investigating emails a lot and you're putting in a lot of time, it might actually be worth looking at it. And then also the attack simulation and training. If you don't have a third party application that does it for you now, you might actually want to utilise MAST, as we call it, so that's Microsoft Attack Simulation and Training. Yeah, that's it. I mean, those are the main capabilities that you get out of P2.
Jazzy: So I want to say that Business Premium is actually very good value with P1 already. It always has been. I feel like Business Premium, over the years they've made it even better. They've made it stronger. There are so many more capabilities in Business Premium, for all of your other aspects as well. I know we're focused on Defender for Office 365 P1 here, but even for things like Defender for Business and Defender for Endpoint stuff that goes on, Business Premium is at such a good level. And being the only license that wasn't increased in price recently, I really feel it's like the best license you can get currently.
Redouan: Yeah, that's bang for your buck. Absolutely. And I'm sure Louis will be really happy, one of our colleagues saying business for the win.
Jazzy: Barry, our MVP, please never mention Business Standard in his presence.
Redouan: Oh, if you want an MVP on your side, you say Business Premium only. And I do want to shout out to him though. He has a very good blog. He posted it recently, just a couple of days ago if I'm not mistaken: the difference between Business Standard and Business Premium, and why you would want to go for Business Premium. Also how to go about that when it comes to your customers and how you would discuss that with your customers. So maybe you can find that and put it in the chat, because I love that.
Jazzy: I'm going to put the whole blog in there, first of all. And the second thing I do want to also shout out is another one of our Entra ID and security MVPs, John Hope as well. He's got another excellent blog which I'll put in the chat here. Feel free to do some reading, whether that's toilet reading or not. I mean, read where you want to. I do that myself. Bath time reading.
Redouan: Please stop. Please stop. We will stop talking.
Jazzy: But read, that's the motto here.
Redouan: So this slide, basically what we're trying to tell you here is, let's say you've thought about these policies, you've thought about the correct settings for these policies, you've configured them once. That doesn't mean you have structurally applied them. So you still have to monitor these settings, you still have to look at the allow and block list and stuff like that. So you need to have procedures in place. And also, let's say an engineer changes one of the settings because of an incident that comes in, right, because incidents always come in all the time. Let's say he changes it. Do you now have that change, that accepted deviation? Do you have it noted somewhere? Can you still look back at it? Are you looking back at those changes every six months or so? So it's not just about applying the policies once. It's actually about proactively monitoring them, because otherwise you won't be in control in a year from now, or not even a year maybe. And then the question is, who are you going to call?
Jazzy: Inforcer. We can help you with all of that, guys. Absolutely. All of it. Help you configure it, help you deploy it, help you stay effective, get you those drift alerts, make sure that things remain the way they are, and manage multiple tenants at scale with ease.
Redouan: Last but not least, checklists. What have we discussed today? As you can see on the left hand side, lock them in. So that's the common attachments filter and ZAP in the anti-malware policy, outbound auto-forwarding in the anti-spam policy, please don't forget that. Safe attachments, don't forget the toggle that Jazzy was talking about. It's one of the global settings. Safe links: the built-in protection is not really safe links. It's not safe. It's more of a "meh" links maybe.
Jazzy: I like that. From now on, every call.
Redouan: So don't go with the built-in protection. Please use the standard preset or go for your own custom policy. And yes, also do it for the internal ones. I saw a question like, do you also want to go for the internal one? Yeah, I think it was already answered in the chat. Anti-phishing impersonation list, something that you will always have to configure yourself. Even if you go for the presets, you still have to configure the impersonation list. Quarantine policies, think about that. Are users able to release messages themselves? Can they put in a request, or can only the admin see it? And then the allow and block list hygiene: use the tenant allow and block list if you can. And then use the report button. What happens after the user reports? It goes to the user reported section in submissions. So you need to have a procedure in place so that someone actually looks at those emails, and confirm the presets aren't overriding the custom ones. And then on the right hand side, of course, Inforcer can help you with that. Just like Jazzy mentioned, most of those things are already defined in our baselines. We do configuration backups and stuff like that, so you can actually restore to a known good state. So yeah, we can help with that, definitely. Anything to add, Jazzy?
Jazzy: You're a superstar, mate. You absolutely covered it all. I think that's a good bit of homework to give to everyone. Hopefully they can utilise our baselines and reach out to your PSMs and your AEs if you're having any issues. We're always happy to help.
Redouan: Definitely. We will go into some of the last questions that we had in the chat. I do think there were one or two questions that we didn't answer, if I'm not mistaken. There is one quick last shout out that we'll be doing. There's a partner of ours. They're really focused on the reselling part of Microsoft licenses. You might be eligible for some funding from Microsoft, so you can actually go ahead and scan the QR code and you can get like a free check on whether you're eligible for that funding. So you can scan the QR code and see if you're eligible for that funding from Microsoft. There are a lot of benefits actually that you can get from the Microsoft partnerships, and a lot of MSPs don't really utilise that to the maximum that is possible. So please do scan the QR code. The deck will also be shared, so you can still scan that QR code. Last but not least is the last slide. Thank you very much. Please don't forget that the next part in the series is about Defender for Cloud Apps. So we will be discussing Defender for Cloud Apps P1, P2, what is included, what is not included, what can you configure or can you not configure. I have actually configured Defender for Cloud Apps quite some time, so I'm really happy that we're going to be doing that one. And let's see if there are any more questions that have been asked that we didn't answer.
Jazzy: Actually, what we can do is we can look through the questions later and maybe reply back after the webinar. Seeing as we're very close to time, we'd love to give you guys all the time we have here. But it's been a pleasure to have you guys here. Thank you for sticking with us and joining us for our second part. Looking forward to seeing you guys on part three. All of you, including all the AI agents that are sitting here, please come back. We love doing these for you guys. Thank you.
Redouan: We're going to look back on these days in a year and we're going to say, like, the good old days when we actually had physical people in our webinars. You remember those days, Jazzy?
Jazzy: Absolutely. It's not fun. It's not fun. See you all on the next one. Thank you again.
Redouan: Thank you very much, guys. I'm not sure if Short has a question, because he does have his hand up. Short, if you have a question, then please let us know.
Jazzy: It was a clap.
Redouan: Yeah, people always mix up the hand up and the clap.
In this session, Jazzy and Redouan break down how to operationalize Defender for Cloud Apps across customer environments, moving beyond basic visibility to real-time control and automated protection. You’ll learn how to uncover risky app usage, enforce policies at scale, and protect sensitive data - without adding complexity to your workflows.
Jazzy: And we're back at it again. Hello. Hello. Welcome to Defender for Cloud Apps, part three of our lovely Know Your Stack series.
Red: Exactly. Good afternoon everybody, depending where you're calling in from. Let's see if I can present here, because it's not letting me present at the moment.
Jazzy: How's everyone doing? How are we all? We have a broad range of countries visiting us today.
Red: Oh, there we go.
Jazzy: We got someone from your neck of the woods, Red.
Red: Nah. Oh, really? Oh, that's cool. That's cool. So in the first part of the webinar series, we had people from all over the world. So please let us know where you are from. I can see some people from the Netherlands already, Switzerland, Denmark. That's cool to see. Reykjavik, Iceland. Wow. Also cool.
Jazzy: Oh, I love that. I love that we got Icelandics in here.
Red: We got someone joining us from the airport.
Jazzy: Yeah. What airport is that? Kalonia. Where is that? Is that Cyprus or Greece?
Red: Bro, I wouldn't even try to guess with that many people watching you, man.
Jazzy: Maybe not worth it. Maybe stay quiet and get all my countries wrong. But Kalonia, I'm really intrigued where that is. Oh, it is Greece. Yeah, it is Greece. I was right. Look at that. I know a bit of Microsoft and I know a bit about countries. Maybe that's going on my CV now: I know where Kalonia is.
Red: "I feel boring being in the US."
Jazzy: The US is just as fun. I've never been, probably that's why I'm saying that.
Red: Ireland as well. Cool. Cool. Love that. Well, thank you all for joining us, especially the people that have stuck around since episode one and episode two as well. Clearly we're not that much of people that put you to sleep, so thank you for staying on. We love it. We absolutely love it. Should we get going? Start it off.
Jazzy: Yes. Yes.
Red: Intros. Jazzy, you always go first, so be my guest.
Jazzy: It's probably because I am on the left hand side, and I'm never right, as my MS always tells me. Microsoft fanboy, absolutely love everything about Microsoft. I have been working with Microsoft for a very long time now. Love configuring it, love doing it. And the good news is I'm no longer the unpaid IT department for my parents. If you've been around since episode one and episode two, you know that that's what I've had to do for so long. But that's because my parents have a new neighbour who's an IT support engineer, and he's been helping them out, believe it or not. They actually knocked on the door and asked them for help configuring a phone setting, and that actually did work out. So hey ho, here we go.
Red: They knocked on their door.
Jazzy: Yeah, they had a chat outside and they figured out that he's in IT. I don't believe he's an IT support engineer. He may be someone that mentioned it once and my parents just decided that's it, he knows computers, he can help us out. My career has always been MSPs. I know how to manage many tenants at a time. I don't know how to manage the one. Never been internal. Maybe one day. Maybe one day.
Red: Imagine going to live in a new neighbourhood and your parents just knocking on your door saying, "Hey, can you help me with this IT question real quick?" That's the best use case. So I have been upgraded to the official managed service provider for my whole family plus in-laws. So Jazzy's doing a better job than I am, because I'm not really getting paid for it. So I'm a pretty shitty MSP as well. Apart from that, I've also worked at an MSP for the past couple of years, just like Jazzy. Also a Microsoft fanboy. I just love configuring Microsoft and everything around it. So that's why we're here as well, right? That's why we're discussing Defender for Cloud Apps today. Clearly you adjusted the last bottom bit, because I wrote down episode three. Still hasn't sent me anything, so I haven't updated it. I've just stopped asking at this point.
Jazzy: You're doing a great job by editing your own bio. I have put in one line there.
Red: So that's great. Love it. Let's see. Defender for Cloud Apps. So we are going to discuss what Defender for Cloud Apps is, what you can use it for, and what it replaces. So maybe you already have some third party tooling, third party applications in place that do some things that Defender for Cloud Apps also does, or it has some overlap. So you might not need those third party applications. And then we're going to discuss the actual inner workings of Defender for Cloud Apps: how do you configure it, what are the possibilities, what are the catches when it comes to Defender for Cloud Apps?
Jazzy: And last but not least, what gets missed, and when would you reach for it? We're also going to give you a quick checklist as well, just like we did in the last webinar. Now obviously I don't want to promise everything, because we like to underpromise and overdeliver, but if we have any time left over we'll try and give you a little demo of what Cloud Apps looks like and what you can do with it.
A few things that we've seen, starting off with, I guess, the app problem. Now, the numbers that you see here on your screen are directly from Microsoft and it may not be the case for absolutely everyone, but whenever you ask an IT admin how many apps a user or an estate of a business uses, it's usually what, 30 or 40 apps, with five or 10 of them being Microsoft 365? And then it turns out, if you actually start looking at the applications that people have logged into, used, browsed on, any SaaS application, it's thousands and thousands of applications that they've touched upon and we have absolutely no idea what they're doing with them. And usually 80% of those employees are using unsanctioned apps that we probably don't want them to be using. But realistically, I completely understand that in a 40 seat client it's not that high, but the estimations remain the same. You're thinking they're using tens or 20s, but in actual fact it's hundreds. And it's nice to know what people are using and to be able to monitor and control them. But that opens up a whole other can of worms, right? Once you find out what they're doing, that's a bigger problem. Now you have to solve it.
Red: Exactly. I also want to emphasise the amount of cloud applications being used. I have a tenant of my own that I've just set up a couple of weeks ago. I've been working in it for a couple of weeks. I already have 66 cloud applications there, and I'm just by myself for a couple of weeks. So I can assure you, if you have an organisation that you're managing, even if it's just, like Jazzy said, 30 people, 40 people, there's probably hundreds of cloud applications in use right now, and if you have no visibility over them you cannot fix anything either. So that's the main premise of getting that discovery in first when it comes to your cloud applications.
Jazzy: Definitely.
Red: What is Defender for Cloud Apps? Microsoft actually frames it quite similarly to how we're framing it right now. Most of it starts with discovery. So we need to know what's there in order to actually enforce something and to monitor something. So discovery is first when it comes to Defender for Cloud Apps. Posture management is usually connecting in external applications and being able to manage the posture for external applications. We'll dive into that in a bit, but you can actually connect those applications and get an overview of how they're configured. Protecting data: Defender for Cloud Apps does have some visibility into actual files being uploaded and stuff like that. It can also work with classifications, or labels and classifications of data, and you can also put in some actions there, or actually enforce some actions. Detecting threats: Defender for Cloud Apps does alert and does have UEBA, for instance, in it as well. We'll dive into that as well. OAuth apps, which is a really important one. Of course the OAuth apps reside within Entra ID, so you have all of your enterprise applications there. But when it comes to governing those apps and the API permissions, that's something that's done from within Defender for Cloud Apps more easily than within Entra ID, and you guys will be able to see that as well. And then controlling in real time: you can configure some session policies that will give you, yeah, what's the correct way of phrasing it, Jazzy? How would you phrase it?
Jazzy: In terms of session policies, they are what you allow them to do once they're in. You can help with blocking and deleting, and blocking copy and pasting, things like that. Whereas an access policy helps you stop them accessing an app completely. And we'll talk about access policies and session policies shortly. But the idea behind all of this is you want to know what your cloud apps are doing and you want to discover them to begin with, and then you want to start protecting the data and apply governance actions against them. Especially apps where Entra ID provides you with a list, but not necessarily what each of the permissions are doing without you having a look. And if you guys remember episode one, Entra ID hardening, if the consent policies for app registrations haven't been followed properly, you may have an app sprawl. And if that is the case, well, you can use Defender for Cloud Apps to rein some of that stuff back in in case it was misconfigured to begin with.
Red: Exactly. Of course, we can't talk about anything Microsoft related without talking about licensing, so we will have to talk about licensing. And there is a big difference in this webinar in comparison to the last couple of webinars we did, because in the last couple of webinars we talked about it already being included within Business Premium and that you should configure it since you have it. You probably have it. Whereas with Defender for Cloud Apps, it's actually really limited what you have within Business Premium, and if you want to have all of the capabilities you would need to have the actual license. So that can be the Defender suite add-on, for instance, or a full-fledged E5 license. So if I just hop back one slide, to put it in simple words, the first one, discovery, is really included. That's actually included within Business Premium, but the rest of it usually is not. So discovery is really the only thing that you get within Business Premium. We will discuss the other functionalities as well though. Like it says in the slide, Business Premium is all about discovery, so we can only see what is actually going on but we cannot enforce anything. And then within the Defender suite for Business Premium, that's where you get the full Defender for Cloud Apps and all the full functionalities. And of course we're going to talk about licensing, so m365maps.com is going to be included as well. Unfortunately the slide is not working. Yes, of course. Why would it? So in the bottom right corner there, it should say m365maps.com. So I'm really sorry for the guys there, but I always like to do a shout out for them. Just to emphasise, it says enterprise. So this is included within Business Premium, the cloud app discovery one. I'm sorry, wrong again with the pencils. Thank you, Don Bes.
Jazzy: Yeah, thank you.
Red: You're a lifesaver. Don Bes in the chat. So you can see that only cloud app discovery is actually included within Business Premium. For all the other functionalities you need the full Defender for Cloud Apps license.
Jazzy: What everyone's now realised by this point is that although we love Microsoft, we're not great PowerPoint guys out here. We do apologise.
Red: Hey man, I'm Microsoft 365, not Office 365. So, love that.
Jazzy: Yeah, in terms of what it replaces, a lot of us, even in my old place, my old MSP, we tend to use a lot of third party tools. We had tools that were doing some shadow IT discovery, third party tools. We had CASB and SaaS access control, things like SaaS scanner, and then other protection apps that we have that are looking at the endpoints and the edge nodes to figure out what's going on and control some of the web browsing, content filtering, things like that. Now ultimately the idea behind this is: how can we manage less tooling, right? How can we bring it all in? So there are a lot of third party apps that you may be currently using, and some categories that you already purchased and have a subscription for, where we can bring it back into the Microsoft house. So ultimately there's a couple of things: yes, we're giving Microsoft a little bit more of our money, but then it allows us to be proficient and experts in one sort of vendor, which is not always the best thing, but it does help us with the integration between other applications like Defender for Endpoint, and having identity, Entra ID, pushing into it, having Defender XDR. It just allows you to bring it all in one, I hate saying this, but one pane of glass, right? It makes it a lot easier. The sales guys are getting to me.
Red: Yeah, one pane of glass. And in Microsoft terms.
Jazzy: Yeah, in Microsoft terms absolutely, one tenant.
Red: Yeah, pretty sure that Microsoft says one pane of glass about Lighthouse as well, but I won't dive into that.
Jazzy: That's the one thing that does slightly worry me: nowadays these buzzwords are getting to me, and I realise that actually when I'm speaking to people I'm using them more and more, and inside me little Jazzy is just getting a little bit upset with myself. Maybe I should stop using those buzzwords.
Red: Let's dive into how Defender for Cloud Apps actually works. And of course, like I said, it all starts with the discovery. So how do we actually get visibility into those cloud apps that are being utilised within the organisation? There are multiple routes of ingesting logs within Defender for Cloud Apps just in order to get that visibility, and once you have the visibility then you can act on it. But that's a step after this. So for now, when it comes to ingesting logs, for, I want to say, probably 85% of MSPs or 90% of MSPs, you will always go for the Defender for Endpoint integration, since all of the other ones are more enterprise based. If you have some firewalls in place, for instance, and everything is routed through the firewalls or stuff like that, you can use that and you can ingest those logs. But if you are utilising Defender for Endpoint it makes way more sense to just ingest those logs into it, and we will dive into the process of actually enabling that integration. But that is the most simple way, and I also want to say the most reliable way, that just works out of the box. Anything that you wanted to add as well, Jazzy?
Jazzy: No, that makes absolute sense. I mean, the idea behind some of this is also that you don't necessarily need to stop using any existing apps that you already have that have collected all that data already. You can use the existing secure web gateways to bring data back into Defender for Cloud Apps as well, in the cloud discovery. You can use it to connect existing gateways. So it is insanely helpful to even run side by side for a little while before you decide if you want to move into Microsoft completely.
Red: I saw in the chat that Nick says the data flags for shadow AI is scary. Yes, it is. I've had so many organisations where I configured a project, Defender for Cloud Apps was not in place, and I configured just the cloud discovery, so that's the integration with Defender for Endpoint. And I can guarantee you there will be tens, maybe 20 applications that the organisation is just not aware of. Dropbox, for instance: people are moving files to Dropbox. They're using all kinds of AI applications. They're using unsanctioned AI applications. So yes, it does give you the visibility that you need in order to start the conversation to go to full Defender for Cloud Apps where you can actually enforce stuff. So yes, definitely.
Jazzy: Hopefully we can show you some of the stuff in the portal as well later on, to show you what the cloud discovery looks like.
Red: As a screenshot here. Anyway, yeah, so I did include a little screenshot. So if you've configured the cloud discovery prerequisites, it will show up in this dashboard over here. It's in the Defender XDR portal under Cloud Apps and Cloud Discovery, and it will show you all of the cloud apps that have been monitored, or that you have visibility of.
Jazzy: Discovered.
Red: Yeah, that's a way better word. Yeah, cloud discovery. It already says it in the title. Why am I making it so difficult?
Jazzy: Look at me. Geography, literature and Microsoft, on the full.
Red: Oh, yeah. Yeah. Yeah. On the full package.
Jazzy: Don't ask me any more questions. That's it. That's done. That's as far as my expertise goes for today. I think I've peaked. I have peaked by giving you the word discovered.
Red: I'm gonna have to step up my game in the next webinar.
Jazzy: Learn about me so that I can add it into your introduction. That would be the best start. Perfect. Did you want to take it, or am I doing blocking as well?
Red: Perfect. Okay. So the step from discovery to actually blocking applications is really important, of course. So this is actually where Business Premium does not, where this functionality is not included. There are three different options when it comes to doing something with a cloud application within Defender for Cloud Apps. You can monitor them, you can unsanction them and you can sanction them. Unsanctioning is basically the only tag that you can give that actually enforces something, that actually blocks the cloud application. It's also blocked on the network level, so it doesn't matter if you go through Google Chrome or if you go through Edge or whatever, the cloud application will be blocked. Also really important: what actually does the blocking? That's something that didn't click with me for maybe six months, up until I configured it multiple times. But Defender for Cloud Apps just talks back to Defender for Endpoint. So whenever you tag an application as unsanctioned that doesn't necessarily mean the cloud application is blocked, because Defender for Cloud Apps still needs to have the integration with Defender for Endpoint, and Defender for Endpoint actually has the indicators that block the cloud application. So you can unsanction a cloud application in the portal, but that doesn't mean that the application will be blocked, because you need to have all of the prerequisites in place. And I think that's also exactly the same thing that is in the third point: tagging is not necessarily enforcing. So that's something that you do need to realise. You need to have all the prerequisites in place, and it takes some time in order to actually block the application. So even if you have all of the prerequisites in place, it takes a couple of hours usually before the applications are blocked. It also works the other way around, actually. So I've had situations where I've had a tagging policy that just unsanctions applications automatically based on some categories, for instance, or some other things I've set. If you block an application by accident and then remove the indicators, it can take a couple of hours, and your client might get angry about it. So be aware of the fact that that also takes some time. Last but not least, which is really important, is this is limited to the cloud applications included in the cloud app catalog by Microsoft. So in Defender XDR, in Defender for Cloud Apps, you have a section called Cloud App Catalog, and that's all of the cloud apps that Microsoft has in their catalog. So you cannot block an application that's not in that catalog. It is limited to those applications. Most applications are there, but it is still limited. I've run into some situations where, yeah, that limitation unfortunately meant they didn't have the cloud application there.
Jazzy: A lot of this is in terms of what we're talking about with the tagging and the unsanctioned bit, where it does block and uses Defender for Endpoint to deploy the custom network indicator and all of that good stuff. But we do have conditional access app control, where it will work for unmanaged devices, where you pass the session over for that specific app into Defender for Cloud Apps using conditional access, which we'll show you in a bit. That can work on unmanaged devices, where it uses the built-in protection for Edge and it shows you the native URL, whereas for other browsers like Chrome it will use a reverse proxy basically, to define or govern what an access policy does and what a session policy does. Which again we'll show in a few minutes in the next few slides.
Jazzy: But we do have app connectors as well. So there are two things about this, right? You've discovered your apps and everything available. You're either managing with access policies or session policies, and you're doing certain things to let that user do what they want within that app. But what you can also do is you can connect some apps into Defender for Cloud Apps to find out what is currently configured in there. So we can have a look at all the users in there. We can have a look at the audit trail of the sign-ins. We can even use app governance and suspend a user or remove them from the OAuth token, from the app itself that's registered within Entra ID. And best of all, which I really think is amazing, is that some of these apps feed directly into Secure Score and actually show you some recommendations of what you can do inside that app. So for example, if you connect Box to it, I think Box is one of them or Dropbox is one of them, it tells you what could be configured better within the app directly in the admin portals, for a separate third party app, which I think is absolutely amazing. So imagine that: cloud discovery monitors all the traffic, it sees what people are using into the outside world, whereas with app connectors you bring it back in. So you look at the governance, you look at the settings configured, and it helps you increase the posture of that connected app, which I think we'll show in a couple of seconds on a different slide of what we have available.
So I think I overexplained on the previous one probably, but exactly that: SaaS posture helps grade your connected apps. It shows you what's available to fix. You can cover some apps within it. It gives you a lot of data in terms of making sure that apps that don't even live within Microsoft 365 directly are at a better state than they were before you connected it.
Red: And I'm guessing that the next natural question to ask is what applications are actually included in these app connectors, or what can you actually configure? Not every app connector is the same. So Jazzy discussed, for instance, SSPM, so that's the security posture management for those SaaS applications, doing the OAuth governance for it or user governance, for instance. Not every app connector is the same. So for instance Microsoft 365 and Google Workspace: everything is included. So if you do utilise it then of course you've got to connect it. Microsoft 365, always connect it, please. You also have an Azure one, also connect that as well. There's not really a good reason not to do that. But you can see that some of these app connectors are limited. So if you are utilising one of the applications on the right hand side here, that was a really shitty, there we go, if you do utilise one of those applications, you might want to think about connecting them into Defender for Cloud Apps so you get all of those possibilities that Jazzy just discussed.
Jazzy: Yeah. And especially with things like Box and Dropbox, considering their collaboration services and their old files that may be private to the company itself. We can also have things like Purview and file policies that are looking for labelling and auto labelling and data classification. Even though they're a connected app and the files live elsewhere, we can still use Microsoft to extend those capabilities.
Red: There's a really interesting question from Martine in the chat. He's asking: when rolling out Defender for Cloud Apps discovery, how do you handle the employee privacy side? Do you enable username and device anonymisation by default, and how do you communicate the monitoring to staff? So, interesting one. The way that we did it within our MSP, usually within one of the projects that we did when we configured Defender for Cloud Apps, we left anonymisation off so we actually had the visibility. We could actually discuss it with the IT manager or the CISO so they knew what was going on. So for the first couple of weeks, first couple of months maybe, we had that visibility and they could actually act upon it. But then after that we turned on the anonymisation, and then after that we could act upon it differently. But for the first couple of weeks definitely, we actually need that visibility. We need to know what everybody is doing. But this is really different for every MSP, right? It depends on what kind of relationship you have with your clients as well, and with the customers.
Jazzy: Exactly, right. So for us it was always be open and upfront about what we're trying to do and what we're trying to achieve with it. So if we were enabling any of these settings it would be defined in their IT policy, the internal IT policy for the customer side, and the employees sign that IT policy of what we are capable of and what we're not capable of, in terms of making sure that all of our boxes are covered and checked and we're not breaching any laws. Usually it would be a direct communication with the customer, whether or not they've signed something like that. Sometimes I feel like the internal IT policy that they've created is quite generic and it generally covers some of this using the clauses, because realistically, if someone installs an application, or we look at network logs in the firewall or in discovered apps, things like that, some of this stuff is already covered. But I would 100% say discuss it with the customer, your IT contact, and see if they already have something that covers it.
Red: "I think because you like this insight as a manager, but sometimes we forget this part." Do you mean the wrong way around, as in having that visibility at first and after that not? So I'm not getting the point that you're making. Ah, yes. Okay. Well, like Jazzy said, and me as well, basically do whatever works for you and your client. That's just the way that we did it within our MSP. One very similar example to this is within email and collaboration. Whenever you go to emails, you have a role that gives you access to the actual content of the email. That's also a very specific example: please discuss that with your client, because there are some clients that will tell you definitely no, we don't give you access to preview those emails, and some clients won't mind since you need it for your investigation. And I think I would dare to say that this is quite similar to that. So it depends on the client and their regulatory requirements as well.
Jazzy: Yeah, for us it was always discuss with the customer and then make sure that we're covering whatever they have decided upon within their own employees.
Red: Conditional access app control. So we did discuss some of the real time policies and real time functionalities that you have within Defender for Cloud Apps. This is what we're basically referring to. So you have two options here: you have access policies and session policies. The way that you should think about this, in the corner you can already read it, so let's say a user goes to SharePoint Online from an unmanaged home PC and they try to download something, they try to copy something, you can block those actions or you can monitor those actions. So this is actually a really strong control that you can configure. You do need to realise that it works together with conditional access. So you need to configure a conditional access policy. Within that conditional access policy you can already configure 99% of it if you go for the top two options. So that basically gives you the option to just configure it from within conditional access. You can also use a custom policy, and that means that you actually define the policy within Defender for Cloud Apps, and that's where you actually configure all of the different components of that specific policy. Access policy means basically outright blocking or allowing access to it. Also very important: this is for cloud applications. So this is not for desktop applications. So this won't block downloads from any desktop applications whatsoever, only cloud applications.
Jazzy: In a classic use case like that, you'd probably end up blocking them from using desktop apps when they're at home, like OneDrive and things like that, and allow only web access and use the session policy, whether that's custom or the block downloads one only, that is shown in that screenshot, for them to be able to control what someone can do on an unmanaged device. And coming back to bringing it all in house in terms of it being a Microsoft native stack, it's where you get to see whether or not the device is enrolled. Is it compliant? You have so many more controls you can do now that we have a tool like Defender for Cloud Apps living inside the same ecosystem where our Defender for Endpoint is deployed, where our compliance policies are, where our MDM policies are. So it's quite nice to have this all in one tool set.
Red: Yeah, exactly. Perfect. Let's see. OAuth apps. Also a very interesting one. And there we go.
Jazzy: You want to take it? Go for it.
Red: Okay. So I'd say the core message of OAuth apps and app governance within Defender for Cloud Apps is that it basically gives you visibility into the enterprise applications within Entra ID and the API permissions, but then in an actionable way, so you can actually do something with it. We've had a lot of issues getting visibility into all of the enterprise applications, but then also the API permissions, that's actually pretty hard to get visibility into. Whereas within Defender for Cloud Apps, with app governance, it's already baked into it and there's already a lot of logic there as well. You can turn it on really quickly. So it's just in the settings, Cloud Apps, go to App Governance and you can just enable it. It does take up to 10 hours, yeah, 10 hours before you can actually see it. But then it's actually presented in a way that you can do something with it, and you can actually also perform all the actions from within the app governance portal. So this is, I want to say, one of the most important things that you have within Defender for Cloud Apps, since it links back to Entra ID and you can actually do something actionable with those enterprise applications and API permissions. So I'm pretty sure that we have a little screenshot here as well. So you can see you get a dashboard of all the enterprise applications. Are any applications overprivileged? Are they not used at all? Are they highly privileged? And you can also see what users are actually using those applications, for instance. So we can see 16 unused applications already. So we can already ask the question, hey, do we need to revoke those API permissions or delete those enterprise applications altogether? And when it comes to risky apps, there's a very big chance you're going to see a random enterprise application that has API permissions that don't match, that shouldn't have those API permissions, because usually, or a lot of the time, enterprise applications will ask for consent for more API permissions than they actually need. So if we're talking control over enterprise applications, I would rather go to app governance within Defender for Cloud Apps than go to Entra ID. Would you add anything to that, Jazzy?
Jazzy: I think you explained it very well.
Red: Perfect. Perfect. So, policy engine. From within Defender for Cloud Apps you can configure multiple policies. You have some baked-in policies already that might be turned on or turned off. Go through the, I think it's called, let me see, policy templates, if I'm not mistaken. Yes, policy templates. Go through them. Turn on the policies that are there by default, but you also get a lot of control yourself. So we've already discussed the access policies and session policies. These were the policies that work with conditional access. App discovery policies are just a way of tagging applications automatically. So that can be the unsanctioned applications, for instance, so that's blocking applications if you've configured that correctly. Wow, I shouldn't have done this. I should not have done this. OAuth app policy, we've just discussed that in the previous slide. So you can create your own policies around that app governance. And file and activity policies, we've already discussed those as well in one of the previous slides. So you have that freedom yourself. You can actually configure policies and then also bind actions to those policies. So whenever a specific policy is alerted for some reason, you can then put in governance actions as well, depending on the applications you have connected. So for instance, Microsoft 365 is one of those applications that you can connect into Defender for Cloud Apps. If you do that, you get a lot of governance actions that you can actually bake into your own policy. So you have a lot of granularity and a lot of control over what you actually configure when it comes to the policies. Especially the app discovery policy with tagging, that's something that we always configured. So Defender for Cloud Apps has a risk score for every single cloud application. It's a risk score ranging from 1 to 10, one being very bad, 10 being very good. We usually always configure the app discovery policy that blocks all applications with a risk score from one to three. Before you actually configure that policy, you can hop to the cloud discovery page, so that's the dashboard with all of your cloud applications already discovered, and then just filter on those applications so you actually know what you're blocking, instead of blocking an application that is in use by the organisation. We will see if we have some time at the end of the webinar to do a little demo and actually show that.
Jazzy: Yeah, I really did like the app discovery policy, because it's a good way to find new apps that we haven't seen before or haven't necessarily looked at before. You can tag it with a custom tag and review at a later date when it does come time to it. You can get alerts on it when it does happen and something new is found and it matches the conditions that you apply to it and the filter, exactly like Red said. If it was a risk score of X, then let's get a look at that, right? It's a really good way to discover new apps, because it's hard to stay on top of what people are already using, let alone what new stuff they're going to be using.
Red: So I saw some questions that you already answered within the chat, people not being able to actually go through to the recordings on the website. I'm pretty sure it's a cookie thing, because I had the same issue. But in the bottom corner on the left, you can consent to cookies again. You need to consent to the marketing cookies. I think that is the issue, because I had the same issue actually. But I didn't even know they were on YouTube as well, but I think you already linked to it.
Jazzy: Yep. All done. Perfect. Unsanctioned on its own blocks nothing. Absolutely right, unless you have the MDE integration. So we're talking about things that sometimes we forget about, right? I mean, to me, unsanctioned in my brain says if I mark something as unsanctioned it should stop working across the board. It does really help in terms of knowing that without an MDE integration, so without the Defender for Endpoint integration, or a gateway sitting behind it, unsanctioned won't do anything, right? Because unsanctioned is the bit that sends off the Defender for Endpoint custom indicators to block you from accessing it. So you definitely need that. App governance doesn't get switched on automatically, you do have to enable it within the settings. Hopefully Red can show us that in a minute when he does do a lovely demo of the platform. I think we have some time left if we can get through the lovely PowerPoint slides that we all love. It's way more fun looking inside the tools. And a lot of predefined policies are alerting. So there are lots of out of the box policies that have been created by Microsoft and they're all already in there. If you'll notice, most of them either say disabled next to them or they're just alerting. Have a look at the templates that are in there. Have a look at the pre-existing policies. Enable the ones you need. Don't enable the ones you don't need. But there's so much stuff in there already that helped me out when I started off with Defender for Cloud Apps. I didn't have to think too much and too long about it. But my journey was quite helpful for seeing all those predefined policies that are already in there. And then I think lastly, let's maybe jump into the demo, right? Let's show certain things and maybe a checklist at the end of what we need to do.
Red: Let me just get everything up and running. Give me a quick minute and then we'll dive into it.
Jazzy: So this is where I should probably need to be filling the gap until Red is ready. Otherwise you just hear Red go the whole way through, filling in the blank noise here. But I'm sure you have it all up and running. There were some things that we discovered while creating the slide deck, because obviously when you're defining these decks, Red, you have to redo it yourself and live it all again. And as we were configuring certain things, like, oh yeah, this setting lives here, we forgot all about this setting. But that's the best part of doing these demos as well, is you end up remembering your own stuff that you did a gazillion years ago.
Red: Exactly. Can you see my screen?
Jazzy: Absolutely, sir.
Red: Perfect. Perfect. So right now I am on an unmanaged device for this tenant. So this is my Inforcer device. I'm in a private browser. I just logged into a different tenant. So I'm on an unmanaged device. There is a certain document within that SharePoint library. If I try to download it, let's see if the demo gods are willing, guaranteed going to fail, right? Yeah. So you can see that the download is blocked. So this is one of those conditional access app control policies. This is a session policy, and the session policy defines that within SharePoint Online, if I'm on an unmanaged device, I am not able to download documents. So you can see that's actually blocked. And the only thing that is downloaded is actually a little document that just tells me again it's been blocked. There we go: file was blocked since it contained data that is not allowed to be downloaded. So this is an example of one of those session control policies. What I can also show is what happens if you unsanction an application within cloud discovery and it's actually blocked. So you do have the Defender for Endpoint integration in place, and what does it look like from the user's perspective if they try and go to a cloud application. I'll actually show that first in the portal, excuse me. So if we go to cloud discovery, I can see all of the applications that have been discovered within this tenant. If I hop over to discovered apps, I can filter on applications here in the top banner. If I filter on unsanctioned applications, I can actually see that I unsanctioned YouTube, for instance. So just unsanctioning this app doesn't mean anything. It just means that it's unsanctioned within Defender for Cloud Apps. How do you actually know that it's enforced? If you go to settings within Defender XDR and you hop over to endpoints, you have something called indicators, and Defender for Cloud Apps should have made some indicators. And you can see here that for a certain application, YouTube, there are a couple of indicators that have been made. And who made those indicators? If I hop over to the right, you can see that Defender for Cloud Apps has made those indicators. So yes, you can make them yourself, but if you unsanction, Defender for Cloud Apps will actually make them here in Defender for Endpoint. So if I now hop back to that cloud PC which is enrolled in this tenant and I try to go to YouTube.com, for instance, YouTube is blocked. If I try to do it from within my own browser it should also be blocked. So this is in Edge. So in Edge you can also see that YouTube is actually blocked. So this is an example of unsanctioning cloud applications, having the correct prerequisites met, and then from the user's perspective, what does it actually look like? So you can give users the control to actually bypass it, but by default it's just blocked and users cannot go there.
Jazzy: Just to add, there are some prerequisites as well to make sure that this stays disabled, like enable network block mode and other prerequisites for Defender for Endpoint policies that you have to deploy out. I don't remember all of them off the top of my head, but in order for this to work it is defined what you need to deploy out. So enable EDR in block mode, custom network indicators there, and some endpoint specific settings that you can push out through Intune and stuff as well. If I'm not wrong, it has to be the active AV and things like that.
Red: Yeah. Yeah. So there are some things within Intune or endpoint security policies that you need to configure, depending on where you configure them, in Intune or Defender for Endpoint. Network protection, for instance, is one of them, and there are a couple of others as well. Microsoft Learn is really granular about that. So it's really easy to configure. That can be configured in one policy, if I'm not mistaken. And there are some toggles here as well, just like Jazzy said: custom network indicators, block mode, and the Defender for Cloud Apps integration. Please don't forget the toggle from within Defender for Cloud Apps. So if you hop back to settings,
Jazzy: The one that gets missed.
Red: Yeah, exactly. You can go to cloud apps, and within the cloud discovery page or section you have Defender for Endpoint, and there's a toggle here, enforce app access. So this is actually enforcing, or giving Defender for Cloud Apps the possibility to actually go back to Defender for Endpoint and tell it to make those indicators, or actually make the indicators within Defender for Endpoint. So yes, that is one that you shouldn't miss. So that is a way of unsanctioning cloud applications. But as you can see, if you go to your discovered apps, unsanctioning applications from within here is manual labour. So I'm not sure if you want to go ahead and do that. So like I said, what we usually did within our projects is make one of those policies. So if we hop to policy management on the left hand side, you can create a policy yourself and you can make that tagging of applications really easy. So, app discovery policy. If we create one, we can make a couple of filters. We can give it a name. So this could be block unsanctioned AI apps, for instance, since AI needs to be mentioned somewhere, anywhere nowadays.
Jazzy: How do you have a webinar without mentioning AI?
Red: Exactly. It took us way too long to mention AI. So I want to unsanction all of the AI applications that are not sanctioned already. So I can filter here by category. So if I hop over to categories, equals, and let's search for AI. So we have generative AI, AI MCP service, and model providers. These bottom two are actually added just, if I'm not mistaken, a couple of weeks ago, a couple of months ago maybe.
Jazzy: I haven't even played with the AI MCP or model providers just yet.
Red: And then you just basically stack these on top of each other. So right now all of the AI applications are in scope, but I only want the AI applications that equal no value probably. So, does not equal sanctioned. So that means that all of the AI applications that are not sanctioned, we can give that a specific action. And one of those actions is tag app as unsanctioned. So you would first sanction the AI applications that you do want to use within that organisation. So for instance Copilot, and maybe Claude if they use Claude in that organisation, or ChatGPT, depending on the organisation of course. And after that you can make this policy and then Defender for Cloud Apps just unsanctions those applications automatically and you don't have to think about it yourself. There is one more thing that I want to show here though when it comes to creating policies, and that is the activity policy and the governance action. So I will not dive into the actual activities and all the different filters that you can put here, but if you scroll down to the bottom you can see governance actions, Microsoft 365. The reason why you can actually link actions to this specific alert is because you connected Microsoft 365 using one of those app connectors. So if you connect different applications and it is supported, you can actually have multiple actions within different platforms or different applications that you connected within Defender for Cloud Apps. So it's not just alerting, you can actually automate it to also have a certain action in place, if that makes sense. Now that we're talking about connecting applications anyway, let me show you real quickly where you do that. So it's in settings, cloud apps. If you scroll down a bit, I think it's literally called app connectors. So there we go, app connectors. And you can see that Microsoft 365 and Azure are already connected within my environment. And this is also where you would connect one of those other applications. To be honest, as an MSP you probably won't use this very often since it's really an enterprise thing. Within our MSP, I think I've configured this once or twice: one time for GitHub and one time for Dropbox. But that's it, basically.
Jazzy: We do have a question, and probably a perfect place for you to be in. Is the OAuth apps discovery automatic, or does it also require settings to report back to the portal? So it might be worth showing the app governance section here as well, where you can enable that.
Red: Oh yeah. So, when it comes to app governance, on the bottom of the page, app governance service status, you have a little toggle here, turn on app governance when it becomes available. You can submit, but this does take about 10 hours, and I just did it a couple of hours ago in this tenant, so unfortunately on the left hand side here I cannot show you app governance as of yet. OAuth apps does have some overlap with it though. So OAuth apps is, I want to say, the little brother of app governance. It basically just shows you the enterprise applications that are in place in the tenant. I just put in some enterprise applications and you can see the permission levels. As you can see, this is already more than Entra ID shows you in the overview, but then app governance shows you even more and way more actionable things. Anything in the checklist that I'm missing right now that we had in the checklist? Maybe some other things that we can look at.
Jazzy: Some of the predefined policies that we have, which are exactly in the right place. If you can go to policy management as well, there are lots of predefined policies in there that usually say disabled next to them.
Red: Yeah. So only a couple of them are active by default. So please go through these policies. That's also what we usually did within our projects. We went to the customer and basically told them, hey, these policies, we want to turn them on, and let the customer decide if that's something that they also agree with. This was for organisations that were a bit bigger. They had internal IT. They had their own CISO. So they did have to say something about it. But for smaller clients, you might want to just enable the things that you see fit for that organisation. So these are the template ones that you can enable. So you don't have to figure out what policies to configure and then enable yourself. You can actually use the templates provided.
Jazzy: Should we show where the tick box is for the conditional access policy, for having the session being delivered to Defender for Cloud Apps?
Red: Actually I think I do have one policy in place already, so I can show that real quick. Let's hop over to conditional access. So I made a real quick demo policy. Search for that. There we go, demo Office 365. Click on edit real quick. So you define the users that it applies to. You can have specific resources applied to it. A lot of the time it's just the cloud applications within Office 365. And then under session controls you have use conditional access app control, and this is where you can monitor only, block the download. So this is what I actually configured in order to block those downloads in SharePoint that I just showed. And when you go for use custom policy, the policy is defined within Defender for Cloud Apps. So if I hop back to Defender for Cloud Apps and I create a policy, I could create a session policy from within here, and then this session policy actually applies to that specific session of those users, if that makes sense.
Jazzy: Yeah. And then I think lastly is making sure you've got all the licenses to get all of this to work, where we can see some of the licensing stack.
Red: Definitely. Let's see if I can hop back to the slide deck. Let's see. We have the checklist over here. Present. Any questions? Please feel free to put them in the chat, because we have about 5 minutes left. We are moving towards the end. Let's see. We have the checklist at the very end. See where it is. There we go. Can you see that as well, Jazzy? The checklist.
Jazzy: Yeah, all good.
Red: Yeah, perfect. So we've discussed some things in the checklist. We might have skipped over a couple of these things. Please let us know or give us some feedback if you want to have a webinar about one of the other components within Defender. I'd really love to hear that. Maybe one of the components within Entra ID. Don't forget that the next webinar that is scheduled is about Defender for Endpoint. That's something that a lot of organisations might not use, or might not fully use, or they have some third party AV in place for some reason, or for some legacy reason maybe, because a lot of the time MSPs don't realise how far Defender for Endpoint has come in the last couple of years. So yeah, I'd love to hear the feedback. Do you have any closing words, Jazzy? Anything that I left out?
Jazzy: Thank you for sticking by us, that's probably the best thing I can say. We absolutely do enjoy having you guys here and sharing our knowledge of what we've done so far and our ability to keep it inside the Microsoft ecosystem. And we would love for you to continue using Microsoft the way you do. Ultimately, if there are any people here that don't make use of Inforcer yet, please do. We absolutely can deploy conditional access policies using Inforcer to help you with those cloud app controls. We can help. We have things like TDR now as well that can help you secure your environment even further. And we'd love for you to partner up with us if we already haven't.
Red: So we do have a question in the Q&A which is quite interesting. So Dominic asks, how do you differentiate between the different Defender products? So for example, when do you block access to websites with Cloud Apps and when with Defender for Endpoint web filters? So I'm guessing you're pointing to the web content filtering policy. There are so many products that can do the same. So yes, you are definitely right. You can have the same outcome with different products. So within Intune you can configure some policies as well to block domains. Within Defender for Endpoint you can put in custom indicators yourself, or you can do it within Defender for Cloud Apps.
Jazzy: I would say content filtering ultimately ends up being categorisations, right, rather than being very specific and granular as to what you're deploying, what you're blocking and also discovering. You're doing a lot of that manually. Defender for Cloud Apps helps you discover and deploy custom indicators with ease. You could probably do that yourself, it just requires a lot of manual activity.
Red: Yeah, definitely. And please don't forget that when it comes to web content filtering and Defender for Cloud Apps, Defender for Cloud Apps is really about cloud applications that could be sanctioned. These are good cloud applications that are probably in use for good reasons. Whereas web content filtering is usually to block explicit content, to block gambling, to block illegal software and stuff like that. So I'll give you one example, Dominic. Within Defender for Cloud Apps I cannot block free proxies, something that is utilised a lot within some organisations. You do want to block that, and we lost some visibility over cloud applications since users were using proxies. So within web content filtering, that is where you can block those illegal routes that people take, so illegal or explicit content, for instance. And to be honest, they live perfectly with each other, so you would actually configure them both. So we configure the web content filtering by default with just Defender for Endpoint. You can configure it already. And then with Defender for Cloud Apps that's a little bit of a step up, since it's not just about blocking, it's about those session policies, getting those secure score recommendations in. So web content filtering is just blocking based on categories, whereas Defender for Cloud Apps is way more, I want to say, intricate or way more complex, and you have more control over what you can configure there.
Jazzy: Absolutely. I hope that answers the question. We also have a question from Seabir here as well: which three checklist items would I prioritise in a brand new M365 tenant?
Red: Oh, good question. So definitely, licensing would be number one.
Jazzy: Yeah, licensing.
Red: If you don't have the license, you're not going to come very far. No, I would say turn on cloud discovery is definitely number one for me, because that's where it all starts when it comes to Defender for Cloud Apps, right? It all starts with that discovery, and from the discovery you actually build upon it. But Jazzy is going to interrupt me.
Jazzy: I mean, no, I completely agree with you. But then there's a prerequisite there, right? If you're turning cloud discovery on for the Defender for Endpoint route, you need Defender.
Red: There we go. Okay. So actually, Defender for Endpoint: you need to actually have Defender for Endpoint rolled out with the right prerequisites, and after that, yeah, turn on cloud discovery and turn on that integration. So now we have two of them. I would say the third, oh, okay, that's interesting, the third one. I'm thinking about doing the app discovery policy first, or actually connecting in Microsoft 365 since that's really important as well. What would you say?
Jazzy: Yeah, I would probably go with confirm licensing, deploy Defender for Endpoint, even though that's not in that list, let's call that step 1.5, turn on cloud discovery and write the app discovery policies. That's probably what I would do. I would do everything that I already discover and not manage whatsoever, just in the beginning.
Red: Yeah, fair enough. Fair enough. Very good point. Very good point. Well, everybody, thank you so much for sticking by. We will see you hopefully on the next webinar. I think it's in two weeks.
Jazzy: Like you said, Defender for Endpoint. So thank you very much for listening in and staying with us for the questions as well. Cheers everyone.
In this session, Jazzy and Redouan show you how to turn Defender for Endpoint into a scalable, high-impact security layer for your customers. From onboarding and configuration to threat detection and response, you’ll learn how to move from reactive alert handling to proactive endpoint security.