Real World Advanced Threat Protection

Slides:



Advertisements
Similar presentations
Used by many 100,000s of customers Used by many 10,000,000s of users Processing Billions of s a day Using Thousands of servers Across dozens of.
Advertisements

On-premises Exchange Online Protection Office 365 Directory Sync ADFS (optional) Single sign on Secure mail flow Existing environment.
 Troy Hopwood Program Manager Microsoft Corporation BB53.
 Malicious or unsolicited mail sent to a mailbox without the option to unsubscribe  Often used as a catch-all of any undesired or questionable mail.
8.1 © 2007 by Prentice Hall 8 Chapter Securing Information Systems.
Version 2.0 for Office 365. Day 1 Administering Office 365 Day 2 Administering Exchange Online Office 365 Overview & InfrastructureLync Online Administration.
Security challenges Used by many 100,000s of customers Used by many 10,000,000s of users Processing Billions of s a day Using Thousands of.
What’s New in Exchange Online. Disclaimer This presentation contains preliminary information that may be changed substantially prior to final commercial.
SHASHANK MASHETTY security. Introduction Electronic mail most commonly referred to as or e- mail. Electronic mail is one of the most commonly.
CensorNet Ltd An introduction to CensorNet Mailsafe Presented by: XXXXXXXX Product Manager Tel: XXXXXXXXXXXXX.
 2:00 pm - 2:15 p.m. ◦ Intro, Welcome and Overview of Agenda  2:15 p.m. - 3:00 p.m. – Admin Training ◦ Introduction to Live at EDU and roadmap.
BUSINESS B1 Information Security.
“SaaS secure web and gateways frequently provide efficiency and cost advantages, and a growing number of offerings are delivering an improved.
Copyright ©2015 WatchGuard Technologies, Inc. All Rights Reserved WatchGuard Training WatchGuard XCS What’s New in version 10.1.
Strong Security for Your Weak Link: Implementing People-Centric Security Jennifer Cheng, Director of Product Marketing.
On-premises Exchange Online Protection Office 365 Directory Sync Secure mail flow Existing environment.
Windows Tutorial 5 Protecting Your Computer
Intro to the Office 365 Security & Compliance Center
Advanced Endpoint Security Data Connectors-Charlotte January 2016
BUILD SECURE PRODUCTS AND SERVICES
Your Office 365 Journey Prepare, Migrate, and Operate with Barracuda
ActiveSync & DLP management in Exchange Online
Exchange Online Advanced Threat Protection
Accelerate GDPR compliance with Microsoft 365
Information Security.
Journey to Microsoft Secure Cloud
What Is DMARC Brian Reid Microsoft Office Servers and Services MVP
Microsoft Ignite /20/2018 8:09 AM BRK3023
9/4/2018 6:45 PM Secure your Office 365 environment with best practices recommended for political campaigns Ethan Chumley Campaign Technology Advisor Civic.
Threat Management Gateway
The utility belt for managing security and compliance in Office 365
Simplified for business
Managing Exchange Online using Office 365 Admin Console
9/14/2018 2:22 AM THR2026 Set up secure and efficient collaboration for your organization with Office 365 Joe Davies Senior Content Developer Brenda Carter.
Find out Advantages of Outlook/Hotmail Account Outlook/Hotmail developed by Microsoft offers a great number of beneficial features and functions nevertheless.
Office 365 Enterprise Value
Office 365 with confidence: security features for Office 365
Securing Information Systems
Jon Peppler, Menlo Security Channels
Microsoft Intune MAM without Device Enrollment
Exchange Online Advanced Threat Protection
Demo Advanced Threat Protection
Call AVG Antivirus Support | Fix Your PC
BRK3277 Making the best of the cloud: How Exchange Online is different from Exchange on-premises Tony
Skyhigh Enables Enterprises to Use Productivity Tools of Microsoft Office 365 While Meeting Their Security, Compliance & Governance Requirements Partner.
Strong Security for Your Weak Link:
Securely run and grow your business with Microsoft 365 Business
Which is right for your business, Office 365 or Microsoft 365?
Get Enterprise-Grade Call Handling and Control for Microsoft Office 365 and Skype for Business with the Bridge Boss-Admin Executive Console OFFICE 365.
Managing Exchange Online using PowerShell
Which is right for your business, Office 365 or Microsoft 365?
Managing Exchange Online using Office 365 Admin Console
Encryption in Office 365 Shobhit Sahay Technical Product Manager
Office365 Exchange Online Risun Antony Technology Specialist
Office 365 Security & Compliance: Exchange Online Protection
Managing Exchange Online using Office 365 Admin Console
1/16/2019 4:44 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
Implementing Client Security on Windows 2000 and Windows XP Level 150
Managing Exchange Online using PowerShell
Protecting your data with Azure AD
4/9/ :42 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
Information Protection
Spear Phishing Awareness
Securely run and grow your business
Microsoft Data Insights Summit
How We Fight Against Scam
Managing Exchange Online using PowerShell
Information Protection
Cybersecurity Simplified: Phishing
Cybersecurity Simplified: Ransomware
Presentation transcript:

Real World Advanced Threat Protection Brian Reid Microsoft Office Servers and Services MVP Exchange Server Microsoft Certified Master brian@nbconsult.co | @BrianReidC7

Classifying Advanced Threats General Spam and Malware / Viruses = Threats Zero-Day, Phishing, Spoofing, Unsafe Links = Advanced Threats This, for the purpose of this presentation, is everything that classic Antivirus cannot detect! We will look at zero-day attacks, spoofing and other threats that we need to protect against

Email Malware Threats The most common source for all threats to enter a company Threats are typically not the same variant of the virus repeated time and again (as that is easy to spot) but variations and tweaks on the malware so it continually evolves and is typically always “zero-day” Use sandboxing, attachment blocking and quarantine tools A quick demo of Office 365 Advanced Threat Protection Safe Attachments

Email Link Threats Links to suspect content in email needs to be protected against Corporate proxies used to (still do) hold this role, but with the rise of mobile devices need something that can filter from anywhere Links in email, links to executable content, and links in Office documents A quick demo of Office 365 Advanced Threat Protection Safe Links

Advanced Threat Analytics Microsoft’s offering (there are others) which is licenced as part of Enterprise Mobility + Security (and standalone) Detection of the behaviours of the threat, rather than the threat itself as well as detection of advanced attacks and security risks For example, creds being passed around when this would not be expected; session enumeration; privilege escalation

Windows Defender ATP Not Office ATP Part of Microsoft 365 Licence (Windows E5 product), previously called Secure Productive Enterprise Requires Windows 10 Creators Edition or later Reports on activity, sources and impacts from “code” running on Windows devices, and utilises the Security Graph of learned info from across the globe

Spoofing Threats We will take a look at a sample, and then look at the protection of the end user Spoofing and phishing can start with a compromised account, but it can also have nothing to do with a company account – though it looks like it does! Are you pawned? And have you ever phished your users intentionally?

SPF, DKIM and DMARC (Sender Policy Framework) is a list of allowed email server sender SPF (DomainKeys Identified Mail) is encrypted headers done by authorized email server DKIM (Domain Message Authentication Reporting & Conformance) is reporting and telling receivers what your email quarantine policy is DMARC Why should I care and what can I do about implementing SPF and DMARC? And how easy is it to implement? That is the next session…

Safety Tips in Office 365 Notifications that are written into the email (rather than the client) Admin portal for spoof rules and reports Get-PhishFilterPolicy to export 30 days of spoof info or the Protection UI

Failed Sender Authentication Warnings Arriving now to Outlook Web App / Outlook.com Emails that fail authentication do not display the user photo or auto determined initials Implement SPF and/or DKIM to ensure your emails are authenticated

Call To Action Spin up a demo Office 365 E5 tenant and enable Office 365 ATP A few 2000 and 10,000 seat deployments turned it on without issue Its not just part of Office 365 E5 – it is also available as a standalone licence Requires Exchange Online Protection (EOP) as your email gateway