Security in SharePoint and Teams with DLP, IRM, and AIP

Slides:



Advertisements
Similar presentations
“ “ Accidental with attachment exposed hundreds of individuals’ names and Social Security Numbers… “ “
Advertisements

“ “ Accidental with attachment exposed hundreds of individuals’ names and Social Security Numbers… “ “
Compliance in Office 365 Edge Pereira Sandy Millar From Avanade Australia OSS304.
Microsoft Ignite /17/2017 2:11 PM
Thanks to our Sponsors!  Platinum:  Gold:  Silver:  Raffle:
Welcome to the Exchange 2013 Webcast Archiving, eDiscovery, & Data Loss Prevention.
© 2011 Autodesk Securing AutoCAD IP in the era of WikiLeaks Presenter: Rahul Kopikar Co-Founder, Seclore Technology.
“ “ Accidental with attachment exposed hundreds of individuals’ names and Social Security Numbers… “ “
“ “ Accidental with attachment exposed hundreds of individuals’ names and Social Security Numbers… “ “
Permissions No Permission, No SharePoint Callahan.
Module 9 Configuring Messaging Policy and Compliance.
Ankur Kothari Microsoft Corporation. In-Place Archive with secondary quota Access documents with SkyDrive Pro Site Mailboxes enable better collaboration.
Developing Policy and Procedure Management System إعداد برنامج سياسات وإجراءات العمل 8 Safar February 2007 HERA GENERAL HOSPITAL.
1 | SharePoint Saturday St. Louis 2015 EDISOVERY IN SHAREPOINT 2013 JODY SOCHA.
Enterprise Service Desk (ESD) Enterprise Service Desk for Notification / Knowledge Article Authors.
“ “ Accidental with attachment exposed hundreds of individuals’ names and Social Security Numbers… “ “
What’s New Data Loss Prevention 14. Information is Everywhere Brings Productivity, Agility, Convenience ……and Problems Copyright © 2015 Symantec Corporation.
One Drive for Business: More Than a File Share Erica Toelle
Information explosion 1.4X 44X Protect communications.
Microsoft Virtual Academy Chris Oakman | Managing Partner Infrastructure Team | Eastridge Technology Curtis Sawin | Technical Solutions Professional |
Protect communications Conditions Actions Exceptions Conditions Actions Exceptions.
SPEasyForms: The Free Forms Designer Solution for SharePoint Joe McShea Owner/Software Architect IntelliPoint Solutions LLC.
Data Loss Prevention and Information Rights Management in SharePoint Tim Beamer, Plus Consulting
OneDrive for Business: Administration, Security and Compliance
Intro to the Office 365 Security & Compliance Center
Microsoft Virtual Academy
ActiveSync & DLP management in Exchange Online
Intro to Data Loss Prevention In SharePoint 2016\Office 365
NON-COMPULSORY BRIEFING SESSION REQUEST FOR INFORMATION: ICT SECURITY SOLUTIONS RAF /2015/00019 Date: 29 September 2015 Time: 10:00.
9/12/2018 6:21 PM BRK2203 Protect and control your sensitive s with new Office 365 Message Encryption capabilities Praveen Vijayaraghavan Principal.
Azure Information Protection Strategy and Roadmap
Office Online title Mike Morton Partner Group Program Manager
Introducing Office UI Fabric
Microsoft /1/2018 5:38 PM Send secure to anyone with the power of Office 365 and  Azure Information Protection Gagan Gulati Ian Hameroff.
Managing onedrive for business
Protect sensitive information with Office 365 DLP
7/23/2018 6:01 PM BRK2282 Protecting complete data lifecycle using Microsoft’s information protection capabilities Gagan Gulati Alex Li Principal.
7/29/2018 4:45 PM Manage SharePoint and OneDrive in Office 365: A field guide for administrators Chris Bortlik Modern Workplace Technical Architect Microsoft.
9/4/2018 6:45 PM Secure your Office 365 environment with best practices recommended for political campaigns Ethan Chumley Campaign Technology Advisor Civic.
Protect your data in Office 365 with Data Loss Prevention
Extending classification ,labeling , and protection to 3rd party applications Kartik Microsoft Tony Digital Guardian Amit Cohen.
Rights Management Services (RMS)
9/14/2018 2:22 AM THR2026 Set up secure and efficient collaboration for your organization with Office 365 Joe Davies Senior Content Developer Brenda Carter.
Understanding best practices in classifying sensitive data
Data Loss Prevention in O365:The Basics
Microsoft Planner SharePoint Saturday Pittsburgh August 6, 2016
RMS with Microsoft SharePoint
Ochrana (nejen) poštovních zpráv pomocí AIP (Azure Information Protection) Miroslav Knotek MVP: Cloud and Datacenter Management, MCSE: Productivity IT.
Skyhigh Enables Enterprises to Use Productivity Tools of Microsoft Office 365 While Meeting Their Security, Compliance & Governance Requirements Partner.
Multi-Farm, Cross-Continent SharePoint Architecture
11/16/2018 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
Customize and Tune Microsoft Office 365 Data Loss Prevention
Top 10 Tips for GDPR Compliance in Office 365
Encryption in Office 365 Shobhit Sahay Technical Product Manager
Let’s Eat Our Own Dog Food Keeping Up to Date with Office 365 using Office 365 Justin Snyder | 09/15/2018.
Managing Content: You Need To Think About More Than Office 365
SPO Demos to Business Value Discussion Pillar Mapping
International Scholar Dossier Training
Microsoft Flow Approvals 101
IN THE PAST, THE FIREWALL WAS THE SECURITY PERIMETER devicesdata users apps On-premises.
4/9/ :42 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
OneDrive for Business: Administration, Security and Compliance
Microsoft Data Insights Summit
03 | Basic Admin Capabilities
Make it real: Help your customers comply with the GDPR
Microsoft Data Insights Summit
Comodo Dome Data Protection
SysKit Security Manager
Security in SharePoint and Teams with DLP, IRM, and AIP
Presentation transcript:

Security in SharePoint and Teams with DLP, IRM, and AIP Tim Beamer, Plus Consulting tim.beamer@plusconsulting.com

Thanks to our Sponsors! Platinum: Silver:

More Fun Stuff Raffle: Please join us in the Atrium at 5:15 PM for the raffle. We are raffling some exciting prizes (need to be present to win)!!! SharePint will be held at Beerhead Bar (110 Federal St, Pittsburgh, PA 15212). While it starts at 5:45 PM, there’s no end time!!!!  Pittsburgh Area SharePoint User Group Meets at the Microsoft office on the North Shore More Info: https://www.linkedin.com/groups/Pittsburgh-Area-SharePoint- User-Group-3769745/about

We do Request that… You fill out the Session Evals. These will also be your Raffle tickets. Print your name clearly if you intend to participate in the Raffle and drop the forms at the registration desk after the last session. You visit the sponsors. The event is possible due to their generous support and we request that you visit them and inquire about their products & services. Cell phones be kept on silent as a courtesy to other attendees and speakers

Agenda Introduction Identify Setup Monitor Block End User Education DLP vs IRM vs AIP Identify Engine Setup Emails Policies Monitor DLP Queries DLP Policies Block Permissions End User Education Policy Tips Limitations IRM AIP Q&A

The “good old days”…NOT Files in file shares (NTFS permissions) Move the file? Lose the permissions! E-mail the file? Lose the permissions! SharePoint “Secure” the doc library with permissions No notification of sensitive information Policies “I didn’t know…” A policy with no enforcement mechanism is useless!

What’s in the toolbox? DLP IRM AIP Inspect – Detect – Act Tooltips Define permissions Encrypt – regardless of destination AIP Define data classification Inspect content and act based on classification May include modifications of permissions

Introduction What is data loss prevention?

What is DLP? Data loss prevention (DLP) is a strategy for making sure that end users do not send sensitive or critical information outside your organization DLP software products use business rules to classify and protect confidential and critical information so that unauthorized end users cannot accidentally or maliciously share data whose disclosure could put the organization at risk

Data Loss Prevention in SharePoint Find that information before it’s too late! Search for sensitive content in your existing eDiscovery Center, keeping content in place and enabling you to search in real time. Credit Card Numbers, SSN, Bank Account Numbers, Passports (Over 80 total information types!) Define once and protect across Exchange, SharePoint and OneDrive! NOTE: If you have document libraries with Search disabled, DLP will NOT work in them

Data Loss Prevention in SharePoint Identify Monitor Protect End User Education

Identify How does SharePoint find this information?

DLP Processing in Sharepoint 2016 Content Sources Crawler Content Processing Index Query Unified Policy Processing Tasks Policy Definitions

Sensitive Information Evaluation 16 digits dddd-dddd-dddd-dddd dddddddddddddddd CVN, CVV2, CID Visa, MasterCard, Amex Expiration Date Card Holder

Sensitive Information Evaluation A DLP policy is 85% confident that it's detected this type of sensitive information if, within a proximity of 300 characters: The functionFunc_credit_cardfinds content that matches the pattern. One of the following is true: A keyword fromKeyword_cc_verificationis found. A keyword fromKeyword_cc_nameis found. The functionFunc_expiration_datefinds a date in the right date format. A DLP policy is 65% confident that it's detected this type of sensitive information if, within a proximity of 300 characters:

Sensitive Information Evaluation

Setup Requirements to make it work!

Prerequisites Configure the search service application Crawl the location of the conflicting documents Configure outgoing email Your users need to have an email address in their profile

Site Collections EDiscovery Center: Compliance Policy Center: A site to manage the preservation, search, and export of content for legal matters and investigations Compliance Policy Center: A site to manage compliance and deletion policies

Monitor

EDiscovery Center

EDiscovery Center

Found it!

EDiscovery Center Excel Reports

Block Minimize the Damage

Block Sensitive Information Create policy in policy center Assign policy to site collection Repeat for every site collection

Select the template of the information you want to find! Description of the template Select the number of occurrences before an alert is triggered. Also select who the alert gets sent to! Do they want to notify the user that they did something wrong? Do you want to block that document?

End User Education

In Context Information Blocked documents are visible directly in the document library

Policy Information Policy tips appear directly in the document library informing the users what they did wrong

Email Notification Users receive emails to know what they did wrong

Limitations Perfection doesn’t exist!

Information Rights Management IRM allow enterprises to define, implement & track information usage “policies”. A “policy” defines : WHO can use the information People & groups within and outside of the organization can be defined as rightful users of the information WHAT can each person do Individual actions like reading, editing, printing, distributing, copy-pasting, screen grabbing etc. can be controlled WHEN can they use it Information usage can be time based e.g. can only be used by Mr. A till 28th Sept OR only for the 2 days WHERE can they use it from Information can be linked to locations e.g. only 3rd floor office by private/public IP addresses

Configure RMS for Office 365

Configure RMS for Office 365

Configure RMS for Office 365

RMS Templates

Enable in SharePoint Online

Enable in a Document Library

Secure a document

Azure Information Protection

AIP AIP – P1 USER is responsible for applying the correct label AIP – P2 Combine the capabilities of DLP and IRM Content inspection can apply the label automatically

DEMO

Call to action Schedule a Security Focused CIE Hands-on session We can deliver at our house or yours (need Wi-Fi and Power) Engage with Security to define data classification, labels, risk, and required protections Come see more at Workplace Wednesday!