12/1/2018 10:04 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Threat Protection with Microsoft Advanced Threat Protection 12/1/2018 10:04 AM BRK2086 Threat Protection with Microsoft Advanced Threat Protection © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Session objectives Meet Azure Advanced Threat Protection (=Azure ATP) 12/1/2018 10:04 AM Session objectives Meet Azure Advanced Threat Protection (=Azure ATP) See a bunch of demos Enjoy! © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
IT is changing Identity Devices Apps Data On-premises
“Hybrid” is changing the security perimeter OPPORTUNITY On-premises
The Microsoft Security Model Combined Microsoft Stack: Maximize detection coverage throughout the attack stages Office 365 ATP Windows ATP ATA Email End Point User
The Microsoft Security Model Combined Microsoft Stack: Maximize detection coverage throughout the attack stages Office 365 ATP Windows ATP ATA Email End Point User User receives an email Opens an attachment Clicks on a URL Exploitation Office 365 ATP Email protection User browses to a website User runs a program
The Microsoft Security Model Combined Microsoft Stack: Maximize detection coverage throughout the attack stages Office 365 ATP Windows ATP ATA Email End Point User User receives an email Opens an attachment Clicks on a URL Exploitation Installation C&C channel Office 365 ATP Windows Defender ATP Email protection End Point protection User browses to a website User runs a program
The Microsoft Security Model Combined Microsoft Stack: Maximize detection coverage throughout the attack stages Office 365 ATP Windows ATP ATA Email End Point User User receives an email Opens an attachment Clicks on a URL Exploitation Installation C&C channel Reconnaissance Lateral Movement Domain Dominance Brute force an account Office 365 ATP Windows Defender ATP Email protection End Point protection User browses to a website User runs a program
The Microsoft Security Model Combined Microsoft Stack: Maximize detection coverage throughout the attack stages Office 365 ATP Windows ATP ATA Email End Point User User receives an email Opens an attachment Clicks on a URL Exploitation Installation C&C channel Reconnaissance Lateral Movement Domain Dominance Brute force an account Office 365 ATP Windows Defender ATP Email protection End Point protection Azure ATP Identity protection User browses to a website User runs a program
Introducing Detect advanced attacks in your on-premises, cloud and hybrid environments Azure ATP APPS APPS
! 1 Collect Analyze & Learn 2 Detect 3 Alert & Investigate 4 12/1/2018 10:04 AM 1 Collect Port Mirroring or Sensor on DC L7 Deep Packet Inspection (DPI) Hybrid data sources 2 Analyze & Learn Self-learning and profiling technology Patented IP resolution mechanism Unlimited scale powered by Azure ! Detect 3 Abnormal behavior and suspicious activities Real-breach oriented research Microsoft Intelligence Alert & Investigate 4 Intuitive attack timeline Quick triaging of alerts Investigate via the dedicated Profile Page or Windows Defender ATP Azure ATPSENSOR PROXY VPN AD HR APPS ADFS SIEM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Demo #1 Azure ATP Deployment and Configuration 12/1/2018 10:04 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Demo #1 recap Create Workspace Connect to Active Directory 12/1/2018 10:04 AM Demo #1 recap Create Workspace Connect to Active Directory Install first Sensor Setup e-mail notifications Schedule a summary report Configure Honeytoken user Tag Sensitive users and groups Windows Defender ATP integration Other recommended steps? Yes! SIEM and VPN data integration. © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
The new Sensor Gateway Sensor New parsing platform 12/1/2018 10:04 AM The new Sensor Gateway Sensor New parsing platform Performance improvement x10 CPU Memory © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Demo #2 Attack Simulations and Azure ATP Detections 12/1/2018 10:04 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Demo #2 recap Realtime Detections 12/1/2018 10:04 AM Demo #2 recap Realtime Detections “Password Spray” Brute Force Abnormal Sensitive group modifications Investigating with Windows Defender ATP Reports Sensitive group modifications © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Azure ATP Detect advanced attacks in your on-premises, cloud and hybrid environments Detect advanced attacks in your on-premises, cloud and hybrid environments Azure ATP APPS APPS
Announcing the Limited Preview! 12/1/2018 10:04 AM Announcing the Limited Preview! Easy to deploy and get running Minimal impact - new Sensor & Azure service Start using Windows Defender ATP integration immediately http://aka.ms/azureatp Looking for your feedback! © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
12/1/2018 10:04 AM Q&A © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
12/1/2018 10:04 AM Thank You! © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
12/1/2018 10:04 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.