Scott Schnoll Senior Content Developer Microsoft Corporation Securing Your Exchange Deployment.

Slides:



Advertisements
Similar presentations
Unified Communications Bill Palmer ADNET Technologies, Inc.
Advertisements

Unified. Simplified. Unified Communications Launch 2007.
Comprehensive protection Multi-engine antivirus Continuously evolving anti-spam protection Policy enforcement Enterprise class reliability Geographically.
Microsoft ® Exchange Online Advanced Security Name Title Microsoft Corporation.
Exchange Online Protection & Mail Flow
Used by many 100,000s of customers Used by many 10,000,000s of users Processing Billions of s a day Using Thousands of servers Across dozens of.
On-premises Exchange Online Protection Office 365 Directory Sync ADFS (optional) Single sign on Secure mail flow Existing environment.
Module 6 Implementing Messaging Security. Module Overview Deploying Edge Transport Servers Deploying an Antivirus Solution Configuring an Anti-Spam Solution.
Enterprise CAL Overview. Different Types of CALs Standard CAL base A component Standard CAL is a base CAL that provides access rights to basic features.
Curtis Parker | December 2010 | Microsoft Corporation.
Security and Organizational Governance Anand Lakshminarayanan Senior Product Manager Microsoft Corporation.
Unified. Simplified. Unified Communications Launch 2007.
Forefront Online Protection for Exchange Renato Francesco Giorgini Evangelist IT Pro
Fact check True or False: Over half of the messages received today in Exchange Online are spam True. About 67 % of all messages are spam True or False:
What’s New in WatchGuard XCS 10.0 Update 3 WatchGuard Training.
Understanding Microsoft Forefront Online Protection for Exchange Robert Gillies Solution Architect Microsoft Corporation EXL201.
Version 2.0 for Office 365. Day 1 Administering Office 365 Day 2 Administering Exchange Online Office 365 Overview & InfrastructureLync Online Administration.
Security challenges Used by many 100,000s of customers Used by many 10,000,000s of users Processing Billions of s a day Using Thousands of.
Exchange 2010 Overview Name Title Group. What You Tell Us Communication overload Globally distributed customers and partners High cost of communications.
Purpose Intended Audience and Presenter Contents Proposed Presentation Length Intended audience is all distributor partners and VARs This would be presented.
SIM334. Internet Comprehensive Protection Multi-Engine Antivirus and Multi layered continuously evolving Anti-spam In the Leader’s quadrant in the.
Protect communications Multi-engine anti-malware and enhanced spam filtering to help protect your environment from threats Enforce policy Flexible.
Configuring Hybrid Exchange the Easy Way
What’s New in Exchange Online. Disclaimer This presentation contains preliminary information that may be changed substantially prior to final commercial.
Belnet Antispam Pro A practical example Belnet – Aris Adamantiadis BNC – 24 November 2011.
Winter Consolidated Server Deployment Guide for Hosted Messaging and Collaboration version 3.5 Philippe Maurent Principal Consultant Microsoft.
Message Trace Office 365 May 2013.
Norman SecureTide Powerful cloud solution to stop spam and threats before it reaches your network.
SIM331 High-accuracy spam filtering Multiple virus-scanning engines Hub Transport Mailbox External About 90% of is junk Tuned for enterprise.
Srinivas L Technology Specialist – Security | Microsoft
What’s New in WatchGuard XCS v9.1 Update 2. WatchGuard XCS v9.1 Update 2  Introduce New Features WatchGuard XCS Outlook Add-in Secur Encryption.
Office 365 Message Encryption – Encrypt messages to any SMTP address Personal account statement from a financial institutions Information Rights Management.
SHASHANK MASHETTY security. Introduction Electronic mail most commonly referred to as or e- mail. Electronic mail is one of the most commonly.
Managing Client Access
Module 4 Managing Client Access. Module Overview Configuring the Client Access Server Role Configuring Client Access Services for Outlook Clients Configuring.
Copyright© Microsoft Corporation Speaker:Engagement consultant Title of presentation:Assessment of the Environment Length of presentation: 45 minutes Audience:Customer.
Partnering For Profitability Growing your business with Microsoft Forefront Security Solutions Mark Hassall Director Security & Access BG Microsoft Corporation.
Overview Presentation Robert Gorbahn Emerging Server Sales Manager München – Frankfurt/Berlin/Munich - May 2006.
CensorNet Ltd An introduction to CensorNet Mailsafe Presented by: XXXXXXXX Product Manager Tel: XXXXXXXXXXXXX.
SIM309. Connection Analysis (IP-based edge blocks) Reputation Analysis Connection Filtering Protect businesses from receiving –borne viruses.
Securing Microsoft® Exchange Server 2010
Module 6: Manage and Configure Messaging. Configuring Internet Mail Using Small Business Server (SBS) 2008 Console Configuring Protection Configuring.
Client X CronLab Spam Filter Technical Training Presentation 19/09/2015.
Exchange Online Protection. About Speaker Prabhat Nigam Microsoft MVP: Exchange Server MCSE: Messaging 2013, MCITP 2010/2007, MS Ex – Microsoft Exchange.
Module 9 Configuring Messaging Policy and Compliance.
Module 6 Planning and Deploying Messaging Security.
Norman Protection Powerful and flexible Protection Gateway.
…. PrePlanPrepareMigratePost Pre- Deployment PlanPrepareMigrate Post- Deployment First Mailbox.
Virtual techdays INDIA │ august 2010 virtual techdays INDIA │ august 2010 Moving/Co-existing your messaging platform to the cloud with Exchange.
Module 9 Configuring Messaging Policy and Compliance.
Module 12 Integrating Exchange Server 2010 with Other Messaging Systems.
Module 7 Planning and Deploying Messaging Compliance.
“SaaS secure web and gateways frequently provide efficiency and cost advantages, and a growing number of offerings are delivering an improved.
Understanding Microsoft Forefront Online Protection for Exchange Nathan Winters Microsoft Corporation EXL201.
Copyright ©2015 WatchGuard Technologies, Inc. All Rights Reserved WatchGuard Training WatchGuard XCS What’s New in version 10.1.
Unified. Simplified. Unified Communications Launch 2007.
Implementing Microsoft Exchange Online with Microsoft Office 365
MCSE Guide to Microsoft Exchange Server 2003 Administration Chapter One Introduction to Exchange Server 2003.
Securing Tomorrow’s World Microsoft Security Roadmap Ed Gibson & Steve Lamb Microsoft Ltd.
Dell SonicWALL Security Series 2/14. Confidential 2 Dell SonicWALL Security solutions Product overview Agenda About threats Protecting.
BE-com.eu Brussel, 26 april 2016 EXCHANGE 2010 HYBRID (IN THE EXCHANGE 2016 WORLD)
Information explosion 1.4X 44X Protect communications.
On-premises Exchange Online Protection Office 365 Directory Sync Secure mail flow Existing environment.
Exchange Online Advanced Threat Protection
TMG Client Protection 6NPS – Session 7.
9/14/2018 2:22 AM THR2026 Set up secure and efficient collaboration for your organization with Office 365 Joe Davies Senior Content Developer Brenda Carter.
Exchange Online Advanced Threat Protection
Demo Advanced Threat Protection
06 | Planning Exchange Online and Configuring DNS Records
Office 365 Security & Compliance: Exchange Online Protection
Presentation transcript:

Scott Schnoll Senior Content Developer Microsoft Corporation Securing Your Exchange Deployment

Agenda Anti-spam and anti-malware Policy and Reporting Encryption Exchange Online Protection

Inspirirani ljudima. Anti-spam and Anti-malware

~2.9 million messages per second ~300 billion messages per day ~100 trillion messages per year

1.3 billion messages per day 740 million Spam messages per day

Multi-layered anti-spam protection Connection filtering Blocks up to 80% of all spam based on IP block/allow lists Sender-Recipient Filtering Blocks up to 15% of all spam based on internal lists and sender reputation Content Filtering Blocks up to 5% of all spam based on internal lists and heuristics

Granular anti-spam filtering controls Connection filtering Static IP allow/block list Opt-in to Microsoft-maintained reputable sender list Content spam categories Obvious spam High confidence spam Content Filtering Actions Delete Quarantine Add X-Header Modify Subject Redirect

Improved spam blocking Bulk Mail control Mark all bulk messages as spam Block external threats quickly Advanced fingerprinting technologies that identify and stop new spam and phishing vectors in real time.

International spam Block unwanted based on language or geographic origin Block based on language Block based on geography

Junk mail management Recommendation: Send suspected junk mail to the Outlook junk mail folder Users can manage safe senders and block lists through Outlook Spam quarantine managed by administrators

End User Spam Notification Set Frequency from 1-15 days Localized ESN

Reporting False Negatives & False Positives Outlook Junk Mail Reporting Tool for missed spam us/download/details.aspx?id=18275 Send spam as an attachment to Send false positive messages to

Simple configuration Delete messages Delete attachments Robust, customizable notifications Sender notifications Admin notifications

Simple configuration Delete messages Delete attachments Robust, customizable notifications Sender notifications Admin notifications

Inspirirani ljudima. Policy and Reporting

Simple Policy Management Built on Exchange transport rules engine Conditions Actions Exceptions Conditions Actions Exceptions

Flexible rule conditions The sender…IP matches any of these addresses Attachment scanning Any attachment…has executable content The message…size exceeds

Flexible rule actions Block or redirect messages Modify messages Apply additional security Route messages through specific connectors

Rule options Rules can be configured to run for a specific time period time Rules can be run in Test Mode

Built-in granular reporting options Provides a clear view on spam filtering and malware attacks

Reporting O365 Reports Page

Reporting Received Mail

Reporting Sent Mail

Reporting Received Spam

Reporting Malware Detections

Reporting Rule Matches

Excel mail protection reports Excel Workbook available to enable self-service analysis Connects to the reporting web service Data can be refreshed from within the workbook at any time Drill through from recent summary data to the underlying detailed information

Message tracing Powerful troubleshooting tools for mail flow issues Simple search interface (no required fields) EOP keeps 7 days of data Subject text provided for each message Top 1000 of the last 48h of message results Wildcard support for multiple addresses or domain names Results include date, from, to, subject, summary status

Inspirirani ljudima. Encryption

TLS Network Encryption Opportunistic TLS enabled by default Forced inbound/outbound transport layer security (TLS) can be set up to secure all routing channels with business regulated partners Message-level Encryption Policy-based encryption from sender to recipient with no end-user training or software installation provided through Microsoft Exchange Hosted Encryption (EHE)

Exchange Hosted Encryption Send Encrypted to any recipient without prior setup Encryption is performed via policy rules and enforced in the EOP cloud Encrypted s are not saved by EHE Identity-Based Encryption (IBE) uses address as ID for public key EHE saves public keys so users should use strong passwords as their credentials No cost for recipient non-licensed user All replies and forwards remain encrypted for any mail recipient

Data protection at rest Information protection using RMS Data Protection in motion Information can be protected with RMS at rest or in motion Data protection at rest

RMS over standard approaches FunctionalityRMS in Office 365 S/MIMEACLs (Access Control Lists) BitLockerCloud Encryption Gateways (CEGs) Data is encrypted in the cloud Encryption persists with content Protection tied to user identity Protection tied to Policy (edit, print, do not forward, expire after 30 days) Secure collaboration with teams and individuals Native integration with my services (Content Indexing, eDiscovery, BI, Virus/Malware scanning) Lost or stolen hard disk *RMS can be applied to Office documents and PDF using FOX IT pro.

Enable RMS RMS can be activated right inside Office 365 Admin console Enable Rights Management in the tenant admin

Enable RMS RMS can be applied to s RMS can be applied to SharePoint libraries RMS can be applied to any Office documents Apply RMS to content Files are protected if they are viewed using Webapps or downloaded to a local machine

How do I know my data and private information are safe? To learn more about the steps we’ve taken to ensure the safety of your data and private information, go to the Office 365 Trust Center – All of the Office 365 Trust Center promises apply to EOP

Inspirirani ljudima. Exchange Online Protection

Protect communications Multi-engine anti-malware and enhanced spam filtering to help protect your environment from threats Enforce policy Flexible tools for policy enforcement that provide the right level of control Streamlined management Flexible administration of anti-spam, anti-malware and policy rules

EOP Service Level Agreements EOP SLAs 100% known virus detection 99% spam detection rate False positive ratio of less than 1:250,000 messages EOP Standalone Customer SLAs % uptime* Average delivery time of less than 1 minute*

EOP Connection to Exchange

EOP Deployment scenarios Works with any SMTP platform! Every Office 365 customer is an EOP customer Easy transition from EOP stand-alone to Office 365 On-premises server - Inbound and Outbound filtered through EOP On Premise Corporate Network EOP O365 Exchange Online

Inspirirani ljudima. EOP Architecture

EOP Inbound Filtering is routed to EOP DC’s based on MX record resolution (mail.messaging.microsoft.com) IP-based edge blocking Reputation blocking Virus scanning AV Engine 1 AV Engine 2 AV Engine 3 SPAM protection Safe Sender/Recipient Policy enforcement Custom Rules Content scanning and Heuristics Bulk Mail filtering SPF & Sender ID Filter Quarantine *International Spam* Advanced SPAM management Customer feedback False +ve / -ve Customer feedback False +ve / -ve Spam analysts Corporate network Regular expressions URL block lists Envelope blocks Forefront blocks Allows/Rejects

Outbound Pool EOP Outbound Filtering High Risk Delivery Pool High Score Outbound Pool Low Score SPAM protection Content scanning and Heuristics Advanced SPAM management Virus scanning AV Engine 1 AV Engine 2 AV Engine 3 Policy enforcement Custom Rules Quarantine Spam Analysts Corporate network Bulk Delivery Pool Bulk Mail Internet Encryption

Directory Synchronization On-premises Exchange Online Protection Office 365 Directory Sync Secure mail flow Existing environment

Management console Anti-spam, anti-malware, and policy controls accessed through the Office 365 Admin Center

Inspirirani ljudima. Summary

Exchange provides multi-layered anti-spam and anti- malware protection with granular filtering controls Exchange supports encryption of messages and Office documents in transit and at rest Exchange Online includes built-in granular reporting that provides a clear view on spam filtering and malware attacks Exchange Online Protection can work with any SMTP platform and provide robust inbound and outbound message filtering

Inspirirani ljudima. Pitanja i odgovori. Scott Schnoll Blog: