12/1/2018 10:04 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.

Slides:



Advertisements
Similar presentations
Microsoft Ignite /16/2017 4:54 PM
Advertisements

Marin Frankovic Datacenter TSP
Enabling the Modern Workstyle with Windows 10 & Azure Active Directory Venkatesh Gopalakrishnan 2016 Redmond Summit | Identity Without Boundaries May 25,
Identity; What you need to know to be in the Microsoft Cloud
Active Directory Modernization Technical competitive comparison
Microsoft 365 Security and Compliance: Training and Resources
Deployment Planning Services
Deployment Planning Services
Azure Active Directory - Business 2 Consumer
Now, let’s implement/trial Windows Defender Advanced Threat Protection
Deploy and get started with Microsoft Advanced Threat Analytics
“Introduction to Azure Security Center”
Emanuele Bianchi | EMEA Security GBB
Secure Windows 10 with Intune, Azure AD and Configuration Manager
5/31/2018 3:40 PM BRK3113 How Microsoft IT builds Privileged Access Workstation using Windows 10 and Windows Server 2016 Jian (Jane) Yan Sr. Program Manager.
Journey to Microsoft Secure Cloud
Simplifying Hybrid Cloud Protection with Azure Security Center
O365 & AZURE ADDS Mladen Baranek, Miadria
Microsoft /4/ :15 PM THR2219 How Microsoft IT enables modern mobility with Windows 10 security and productivity features Rekha Nair IT Program.
Azure Information Protection Strategy and Roadmap
Conduct a successful pilot deployment of Microsoft Intune
6/10/2018 5:07 PM THR2218 Deploying Windows Defender AV and more with Intune and Configuration Manager Amitai Senior Program Manager,
SaaS Application Deep Dive
6/17/2018 5:54 AM OSP322 Getting the best of both worlds, making the most of SharePoint hybrid search solutions Shyam Narayan Microsoft © 2013 Microsoft.
Azure AD for the client management guy (or gal!)
Microsoft /20/2018 9:26 AM BRK1037 Win the IT security battle: automate password changes, privileged access & Minimize Cyber Losses Christopher.
Plan and deploy Microsoft Advanced Threat Analytics the right way
Microsoft Virtual Academy
The power of common identity across any cloud
Examine common architectures for hybrid identity
Building an effective ATA solution
9/4/2018 6:45 PM Secure your Office 365 environment with best practices recommended for political campaigns Ethan Chumley Campaign Technology Advisor Civic.
Microsoft Ignite /31/ :08 AM
Master Modern PaaS for the Enterprise with Azure App Service
Automated Response with Windows Defender ATP
9/13/2018 4:54 PM BRK How to get Office 365 to the next level with Azure Active Directory Premium Brjann Brekkan Program Manager Lead – Customer.
9/14/2018 2:22 AM THR2026 Set up secure and efficient collaboration for your organization with Office 365 Joe Davies Senior Content Developer Brenda Carter.
Welcome! Microsoft Tech Talks - Charlotte, NC
The Microsoft 365 Powered Device
Azure Active Directory
11/15/2018 3:42 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
11/17/2018 9:32 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
Microsoft Ignite /20/2018 2:21 PM
Microsoft Ignite NZ October 2016 SKYCITY, Auckland.
11/29/ :53 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
Microsoft Ignite NZ October 2016 SKYCITY, Auckland
12/5/2018 2:50 AM How to secure your front door with real-time risk assessments of your logons Jan Ketil Skanke COO and Principal Cloud Architect CloudWay.
Modern Windows 10 device 12/2/2018 E3 E3 P E3 P P P P E3 E3 P P P P P
Analyze the anatomy of advanced attacks
Secure once, run anywhere Simplify your security with Sophos
12/25/2018 5:11 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
What’s new in the Fall Creators Update for Windows Defender ATP
Microsoft Ignite /18/2019 7:21 AM
Surviving identity management in a hybrid world
Microsoft Connect /25/2019 1:20 PM
4/3/2019 3:20 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS.
Protecting your data with Azure AD
4/9/2019 5:05 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS.
4/9/ :42 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
Simplify the management of your M365 workplace with analytics
Empower your users with Azure Active Directory Premium
Bob Duffy 27 years in database sector, 250+ projects
Microsoft Data Insights Summit
7/2/2019 8:03 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS.
<offer name> with Microsoft 365 Business Secure Deployment
Windows Client Assessment Results
Active Directory Security Assessment Results
Microsoft Virtual Academy
7/28/ :33 PM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or.
11/19/2019 4:08 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
Presentation transcript:

12/1/2018 10:04 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Threat Protection with Microsoft Advanced Threat Protection 12/1/2018 10:04 AM BRK2086 Threat Protection with Microsoft Advanced Threat Protection © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Session objectives Meet Azure Advanced Threat Protection (=Azure ATP) 12/1/2018 10:04 AM Session objectives Meet Azure Advanced Threat Protection (=Azure ATP) See a bunch of demos Enjoy!  © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

IT is changing Identity Devices Apps Data On-premises

“Hybrid” is changing the security perimeter OPPORTUNITY On-premises

The Microsoft Security Model Combined Microsoft Stack: Maximize detection coverage throughout the attack stages Office 365 ATP Windows ATP ATA Email End Point User

The Microsoft Security Model Combined Microsoft Stack: Maximize detection coverage throughout the attack stages Office 365 ATP Windows ATP ATA Email End Point User User receives an email Opens an attachment Clicks on a URL Exploitation Office 365 ATP Email protection User browses to a website User runs a program

The Microsoft Security Model Combined Microsoft Stack: Maximize detection coverage throughout the attack stages Office 365 ATP Windows ATP ATA Email End Point User User receives an email Opens an attachment Clicks on a URL Exploitation Installation C&C channel Office 365 ATP Windows Defender ATP Email protection End Point protection User browses to a website User runs a program

The Microsoft Security Model Combined Microsoft Stack: Maximize detection coverage throughout the attack stages Office 365 ATP Windows ATP ATA Email End Point User User receives an email Opens an attachment Clicks on a URL Exploitation Installation C&C channel Reconnaissance Lateral Movement Domain Dominance Brute force an account Office 365 ATP Windows Defender ATP Email protection End Point protection User browses to a website User runs a program

The Microsoft Security Model Combined Microsoft Stack: Maximize detection coverage throughout the attack stages Office 365 ATP Windows ATP ATA Email End Point User User receives an email Opens an attachment Clicks on a URL Exploitation Installation C&C channel Reconnaissance Lateral Movement Domain Dominance Brute force an account Office 365 ATP Windows Defender ATP Email protection End Point protection Azure ATP Identity protection User browses to a website User runs a program

Introducing Detect advanced attacks in your on-premises, cloud and hybrid environments Azure ATP APPS APPS

! 1 Collect Analyze & Learn 2 Detect 3 Alert & Investigate 4 12/1/2018 10:04 AM 1 Collect Port Mirroring or Sensor on DC L7 Deep Packet Inspection (DPI) Hybrid data sources 2 Analyze & Learn Self-learning and profiling technology Patented IP resolution mechanism Unlimited scale powered by Azure ! Detect 3 Abnormal behavior and suspicious activities Real-breach oriented research Microsoft Intelligence Alert & Investigate 4 Intuitive attack timeline Quick triaging of alerts Investigate via the dedicated Profile Page or Windows Defender ATP Azure ATPSENSOR PROXY VPN AD HR APPS ADFS SIEM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Demo #1 Azure ATP Deployment and Configuration 12/1/2018 10:04 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Demo #1 recap Create Workspace Connect to Active Directory 12/1/2018 10:04 AM Demo #1 recap Create Workspace Connect to Active Directory Install first Sensor Setup e-mail notifications Schedule a summary report Configure Honeytoken user Tag Sensitive users and groups Windows Defender ATP integration Other recommended steps?  Yes! SIEM and VPN data integration. © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

The new Sensor Gateway  Sensor New parsing platform 12/1/2018 10:04 AM The new Sensor Gateway  Sensor New parsing platform Performance improvement x10 CPU Memory © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Demo #2 Attack Simulations and Azure ATP Detections 12/1/2018 10:04 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Demo #2 recap Realtime Detections 12/1/2018 10:04 AM Demo #2 recap Realtime Detections “Password Spray” Brute Force Abnormal Sensitive group modifications Investigating with Windows Defender ATP Reports Sensitive group modifications © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Azure ATP Detect advanced attacks in your on-premises, cloud and hybrid environments Detect advanced attacks in your on-premises, cloud and hybrid environments Azure ATP APPS APPS

Announcing the Limited Preview! 12/1/2018 10:04 AM Announcing the Limited Preview! Easy to deploy and get running Minimal impact - new Sensor & Azure service Start using Windows Defender ATP integration immediately http://aka.ms/azureatp Looking for your feedback! © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

12/1/2018 10:04 AM Q&A © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

12/1/2018 10:04 AM Thank You! © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

12/1/2018 10:04 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.