st. louis sharepoint user group - security and compliance in o365 for sharepoint & onedrive for...

42
Information Security & Compliance in O365 for SharePoint Ajay Iyer Sr. Consultant (Microsoft)

Upload: ajay-iyer

Post on 22-Jan-2018

113 views

Category:

Technology


2 download

TRANSCRIPT

Page 1: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business

Information Security & Compliance in O365 for SharePoint

Ajay Iyer

Sr. Consultant (Microsoft)

Page 2: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business

Ajay Iyer

Sr. SharePoint Consultant (Microsoft)

Dabbling with SharePoint for over 10 years

SharePoint Online, OneDrive for Business, Search, Security &

Compliance, Migrations, Enterprise Content Management

Speaker at SharePoint Saturdays in Minneapolis, Nashville, Chicago,

Cincinnati & St. Louis

Twitter: @shankarajay1

[email protected]

Page 3: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business

Objectives

Simplify and protect access

Allow collaboration and prevent leaks

Stay compliant

Secure administrative access

Page 4: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business

Requirement(s)

E3 or E5 Plan in Office 365

On-Prem AD synchronization with Azure Active Directory

(AAD)

Azure Subscription (if using Azure Information Protection)

Page 5: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business

Requirement(s)

E3 Plan E5 Plan (includes E3 features plus)

eDiscovery Legal Hold Advanced eDiscovery

eDiscovery export & case management Advanced Data Governance

IRM, DLP & Encryption

Page 6: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business
Page 7: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business

Security & Compliance

Legal

Medical/HIPAA

Intellectual Property

Medical/HIPAA

Office 365

Page 8: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business

Why Security & Compliance?

Establish Information Protection Priorities

Set Organization Minimum Standards

Find & Protect Sensitive Data

Protect High-Value Assets

Page 9: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business
Page 10: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business

Security & Compliance Center

or browse to https://protection.office.com

Page 11: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business

Security & Compliance Center

Page 12: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business

Security & Compliance Center

Data Classifications

Data Loss Prevention

Data Governance

Search & Investigation

Page 13: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business
Page 14: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business

Data Classifications

Labels

Labels are just like the old Content-Type Retention Policies in SharePoint On-Premises

Retention Policies can be applied Tenant-wide or specific mailboxes, sites, OneDrive users

and groups

Labels can be applied automatically to new & existing content, per document library in

SharePoint Online

Page 15: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business

Data Classifications

Labels

Auto-Apply Labels are AWESOME

• You don’t need to train your users on all of your classifications.

• You don’t need to rely on users to classify all content correctly.

• Users no longer need to know about data governance policies – they

can focus on their work.

Page 16: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business

Data Classifications

Labels

You can choose to apply labels to content

automatically when that content contains:

• Specific types of sensitive information.

• Specific keywords that match a query you create.

Page 17: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business

Data Classifications

Labels

Manage lifecycle of Emails & Documents using Retention Features

Retention Tags & Policies

Document Deletion Policies

Preservation Policies

Page 18: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business

Data Loss Prevention (DLP)

Page 19: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business
Page 20: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business

Data Loss Prevention (DLP)

• Policies can span all locations in O365 including

Exchange Online (EXO), SharePoint Online (SPO) and

OneDrive for Business (ODfB) or you can choose

specific payloads

• Detect when this content is shared outside your

organization

• Ability to test the policy, while it's being created

• Can customize tool tip messages & email text

Page 21: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business
Page 22: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business

Search & Investigation

Search for sensitive content in your tenant & create saved searches

Review O365 audit logs

Create activity alerts for "specific users"

Create & manage eDiscovery cases

Page 23: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business
Page 24: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business

Security & Compliance in SharePoint Online

Page 25: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business

Security & Compliance in SharePoint Online

Recommended to set Default Link Type to “Direct” or “Internal”

Page 26: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business

Security & Compliance in SharePoint Online

Recommended to limit sharing to specific domains, if possible

Page 27: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business

Security & Compliance in SharePoint Online

Recommended to set expiry on Anonymous links

Page 28: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business

Security & Compliance in SharePoint Online

If needed, restrict access to your sites based on certain IP subnets

Page 29: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business

Security & Compliance in SharePoint Online

Restrict access from apps that don’t support modern auth’n

Page 30: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business

Security & Compliance in OneDrive for Business

Restrict access from apps that don’t support modern auth’n

Page 31: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business

Security & Compliance in OneDrive for Business

Restrict access from apps that don’t support modern auth’n

Recommended to limit sharing to specific domains, if possible

Recommended to set expiry on Anonymous links

If needed, restrict access to your sites based on certain IP subnets

Page 32: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business
Page 33: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business
Page 34: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business
Page 35: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business

Cloud App Security

Page 36: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business

Cloud App Security

Enterprise-grade security for Cloud Apps like O365, Google, AWS,

Salesforce, ServiceNow, Dropbox, etc.

Provides App Discovery, Data Control & Threat Protection (e.g.

Ransomware)

Available with Enterprise Mobility + Security E5 subscription or

standalone at $5/user/month

Page 37: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business

Objectives

Simplify and protect access

Allow collaboration and prevent leaks

Stay compliant

Secure administrative access

Page 38: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business

Summary

Encourage users to set permissions on documents

Configure External Sharing policies

Configure Device Access policies

Use Labels to implement Classification-based protection

Stay compliant with retention policies on labels

Configure DLP to protect unauthorized access

Separate duties of administrators by role — SharePoint Online,

Exchange Online, and Skype for Business Online

Page 39: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business
Page 40: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business

https://support.office.com/en-gb/article/Overview-of-labels-af398293-c69d-465e-a249-d74561552d30?ui=en-

US&rs=en-GB&ad=GB#howlong

https://technet.microsoft.com/library/dn876574.aspx

Real Life Application by MSIT (Case Study) - https://msdn.microsoft.com/en-us/library/mt718319.aspx

Advanced e-Discovery in O365 (Channel 9) - https://channel9.msdn.com/Shows/Mechanics/Office-365-Advanced-

eDiscovery

Plan for Security & Information Protection in O365 - https://support.office.com/en-us/article/Plan-for-Office-365-

security-and-information-protection-capabilities-3d4ac4a1-3920-4ff9-918f-011f3ce60408?ui=en-US&rs=en-

US&ad=US

What is Cloud App Security? - https://docs.microsoft.com/en-us/cloud-app-security/what-is-cloud-app-security

Anonymize Cloud User Discovery Data - https://docs.microsoft.com/en-us/cloud-app-security/cloud-discovery-

anonymizer

Page 41: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business
Page 42: St. Louis SharePoint User Group - Security and Compliance in O365 for SharePoint & OneDrive for Business

Thank You

Ajay IyerSr. SharePoint Consultant

[email protected]