Overview
Join James Conrad as he introduces security, compliance, and identity concepts.
Recommended Experience
- None
Related Certifications
- Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900)
Related Job Functions
- IT Security Professionals
- Microsoft Cloud Operations Professionals
- Microsoft Security Compliance Managers
James Conrad has been a CBT Nuggets trainer since 2020 and holds a variety of certifications including Microsoft Certified Professional, Microsoft Certified Solutions Associate, Microsoft Certified Solutions Expert, Microsoft Certified Technician, Certified Ethical Hacker, and CompTIA A+.
Zero-Trust Methodology
We begin our exploration of this methodology with: Always verify, least privilege, assume breach, identity, endpoint health and compliance, and data elements.
Knowledge Check
In an organization that requires security ID name badges, you should raise a challenge when someone is not wearing one. True or false?
Foundational Elements
Let's continue the discussion of security foundational elements!
Knowledge Check
How many "signals" does Microsoft receive per day?
The Shared Responsibility Model
In this Nugget, we discuss the shared responsibility model, which becomes increasingly important as we migrate to the cloud.
Knowledge Check
When you use SaaS, Microsoft is 100% responsible for all aspects of the service. True or false?
Security and Compliance Pop Quiz
Time for a pop quiz!
Conclusion
I hope this has been informative for you and I would like to thank you for consuming.
View Transcript
Zero-Trust Methodology
0:05In the first Indiana Jones movie that came out years and years
0:08ago, one of my favorite movies, someone told Indiana Jones,
0:12don't trust anyone.
0:14And that was good advice in the movie.
0:16That's something that we have here in IT as well.
0:19We all like to be nice people, and we all
0:21want to be able to trust people.
0:23But when it comes to IT related topics,
0:25it's really important that you really don't trust anyone,
0:28and that's why it's called a zero-trust methodology.
0:31This means that we always assume that everything has not
0:34been verified, everything is insecure,
0:37and we have to verify that everything gets properly
0:40authenticated, and that anybody that's
0:43trying to access a resource has to prove that they
0:45are who they say they are.
0:47Now I think we generally think of this in terms
0:48of the internet, right?
0:49I mean, all the bad people are on the internet
0:51trying to get into my network, trying to steal stuff,
0:53trying to hack in, all of that kind of stuff.
0:56Even nation states sometimes might
0:58be trying to hack into our networks and steal our data,
1:02or compromise us, or something like that.
1:04But it doesn't always just apply to the internet.
1:07It could also and very often also does
1:09apply to internal networks and person.
1:13So you might have an internal network
1:15where there's file transfers taking place,
1:18and when you audit that, you might find out
1:20those files should not be transferred between those two
1:23locations.
1:24They are in different departments.
1:25They don't have anything to do with each other maybe.
1:27Or one of those is classified, but it's
1:30being transferred to another network that
1:32is not a classified network.
1:34So this is the kind of thing that we have to look out for.
1:37It's not just the internet.
1:38Sometimes it's internal.
1:40There might be something going on that is insecure.
1:42It also might have to do with person.
1:44So, for example, this might be your cubicle buddy over here
1:47on the right above my head here.
1:49And so this might be you and you've
1:50got your name badge on with your little picture
1:53on it and everything.
1:54And then your buddy should also have probably
1:57the same kind of a name badge with his picture on it.
2:00In most organizations where we are required to wear those,
2:04there's a high security priority there.
2:06And they not only identify who you are, some of them
2:09will identify which departments or areas of a building you're
2:13allowed to be in.
2:15And they can also very often open doors or access systems.
2:19So these name badges could be pretty important.
2:21So if I see that my buddy over here
2:24does not have a name badge on and his ID,
2:28I have to consider that to be a potential security threat even
2:32if this is the guy that's been working in the cubicle
2:34next to me for the past 10 years.
2:36You also have to identify where they are.
2:38That's what I was kind of saying earlier.
2:40Some of these name badges that you'll see,
2:42and I've worked in places like this,
2:43they will have-- they will identify on
2:45there somewhere which buildings, departments, areas
2:48that you're allowed to work in.
2:50And if you see somebody that's not part of your department
2:53walk over and they're in your-- they're physically in the area,
2:56then in some organizations you're
2:58required to do what they call challenge that person.
3:00You're required to challenge them.
3:02What are you doing here?
3:03You know, what's your business here?
3:05Do they have a meeting with somebody
3:07that they're authorized to be there?
3:09So, that all has to be looked into sometimes and, again,
3:12really just depends upon the level of security
3:14that you need for your organization.
3:16You may also have to confirm that their device itself
3:18is healthy.
3:19Some devices may have some kind of malware,
3:22or a bug, or a security vulnerability--
3:25security vulnerability, there's supposed to be a V there--
3:29on them.
3:30And with everybody bringing their own devices
3:32into organizations nowadays, that could potentially
3:35be a security threat.
3:36In some organizations I've worked at-- a nuclear lab,
3:39for example, in particular--
3:41there are departments where people are not even
3:43allowed to possess a cell phone in that department.
3:47They cannot walk in to work with a cell phone on their person.
3:50If they have one, they'll have to leave it in their car
3:52or just not bring-- one of the employees I know,
3:55has never owned a cell phone.
3:56Can you believe that in this day and age?
3:58He'd never own one because he's at work so much,
4:01and he can't have a cell phone that it wouldn't make
4:03any sense for him to pay for.
4:04But in most organizations, we do have
4:06devices such as that or tablets or something,
4:09and we have to make sure that they're healthy.
4:11Many of these devices, of course, we
4:13could use these to use the camera on them
4:17and snap a photograph of something confidential,
4:19and then they're usually connected to the internet
4:21as well that could be sent out to our own personal cloud,
4:24to anybody else, really the sky's the limit.
4:26It could go anywhere.
4:27So we have to be careful that we have a policy in place that
4:32manages these devices.
4:35Some organizations can even set something
4:37up so that if they have a camera, you can disable it.
4:40There are certain products that can feature or defeature
4:44certain parts of a cellular device, for example.
4:46But we have to make sure that it's healthy.
4:48That it's properly patched, properly
4:50upgraded, that it doesn't have security vulnerabilities.
4:53So it's, of course, very important to make sure
4:55that the devices are healthy.
4:56Now, let's also take a look at another methodology,
4:59part of zero-trust methodology, called least privilege.
5:02This is where we try to restrict access to any kind of resource.
5:06We generally think of this as something like maybe a database
5:09access or accessing files that we
5:12don't want people to access if they're security sensitive.
5:15And for most organizations, just about everything
5:17you have is some level of security sensitive.
5:20One of the ways that can be kind of throttled down
5:23is to narrow the window of opportunity
5:26that someone could use to access that resource.
5:29So, for example, this is called just-in-time access.
5:33Number of different ways that this could happen.
5:35But it could be that only during a certain period of time
5:37between this time and this time, for example, there's
5:39the only window of opportunity that even someone
5:42with the right credentials can access
5:44that application, that data, that resource, whatever
5:48kind of a thing it is.
5:49You can also only allow someone to access administratively
5:52speaking, for example, if they've
5:54requested permission for it.
5:55So yes, they have the right username and password.
5:57Yes, they might be able to put their thumb on a fingerprint
6:00scanner and confirm their identity that way, or using
6:03a retinal scanner to identify their identity, or face ID.
6:07Like I have a camera.
6:08It's just right over there.
6:08It's not the one I'm recording with.
6:10There's one just to the left of it over here for me
6:12that logs me on to my computer every day.
6:14So yeah, sure.
6:15People can have something that can log them onto a computer
6:19or to a device, but there are certain things, especially
6:22that are more security sensitive that they're only
6:24allowed to log on during certain times of day.
6:26For example, even with user accounts,
6:28depending on your operating system and configurations,
6:31you may have the ability to log on
6:34only during certain times of day so
6:36that if you're trying to log on or at least
6:38your credentials are trying to log on at 3:00 in the morning
6:42when you usually start work at 8,
6:43then that's not going to be a normal behavior.
6:46That's going to be unexpected behavior,
6:48and it's going to be denied if you're only
6:50allowing that account to log on during certain hours.
6:54Another kind of just-in-time access--
6:56let me bring this over here for you.
6:58This is just a Microsoft document here
7:00that's just kind of showing you really to this article
7:03here for purposes of looking at the screenshot as much
7:06as anything.
7:06You can Google for this if you want to.
7:08But in this example, administrators
7:10could have an application that they've
7:13uploaded to the Microsoft Store, and they
7:15may want people to only use that application
7:18during certain times.
7:20That's just-in-time access, JIT.
7:22OK?
7:23So this just kind of gives administrators
7:25instructions on how to do it.
7:26They have to code it in.
7:27And then once they've done that, we
7:29can enable then just-in-time access
7:32for whatever this application is that we're
7:34trying to make available.
7:36So if that gets check marks, then what we can do
7:39is to set it up so that if someone
7:40wants to access that resource, they have to request access.
7:44And you can see down here--
7:45I'm trying to zoom in again here--
7:46we can activate that capability.
7:48And then further down here, you'll
7:50see that this is where it gets to be
7:52where you can identify the specificity
7:55of this kind of a log on.
7:56Notice that they can only log on during certain dates and times,
8:01and then also for a certain duration as you see down here.
8:05Now, why do we want to do this?
8:07Why is it significant that we can throttle back
8:10the capability of someone to be able to log in?
8:13Well, the reason for that is because it
8:15narrows the window of time also for a hacker
8:18to be able to get in.
8:19Let's say that a hacker does have some compromise
8:21against our credentials.
8:22Well, they would have to actually make
8:24this request to log on at a specific period of time,
8:27for example.
8:27Could they possibly fake that they are you and do it?
8:29Yeah, possibly.
8:30But that's another hoop that they would have to go through.
8:33And if we can narrow down the scope of opportunity for them,
8:36that can be quite significant.
8:38And then the next thing we could limit
8:39is what we call just-enough-access or JEA.
8:43With just-enough-access, that's also kind of known
8:46as the principle of least privilege itself,
8:48we generally use that for certain types of resources
8:51like access to an application.
8:53But most of the time, that's going to be to something
8:55like files.
8:56Files and folders, network shares,
8:59where if somebody is supposed to be able to access it, sure,
9:02they can do that.
9:03But we don't want them to do more
9:05than they're allowed to do.
9:05For example, a good example would
9:07be if we have let's say some seriously important document
9:11here or some text in it, maybe this guy here can access that,
9:16but he should be able to only read that document.
9:19He should not be able to change anything in that document.
9:22This guy over here however, maybe he's a manager,
9:25he can have read and write access to that same document.
9:28And we can do that kind of thing with NTFS permissions,
9:31share permissions, and various things such as that.
9:34The mistake would be if we gave them both read write access
9:39when this guy doesn't really need that kind of access.
9:42That would be called over permissioning.
9:44You also have to assume that there is always
9:47a breach somewhere.
9:48Right now, there's a lot of conflict going on in the world.
9:52I won't date the video by saying what's going on,
9:54but it's extremely serious.
9:56And there's a lot of talk about nations hacking each other
10:00and are we prepared?
10:02That's what the headlines are.
10:03Are we prepared to defend ourselves against a hack?
10:07Friends, they're probably already in your network.
10:10They just have not yet flipped the switch
10:12to be able to actually do any damage.
10:14They've probably been in there for weeks or months, sometimes
10:17years, and it's just up to them whenever they decide
10:21to probably do some damage.
10:22This is true in probably all nations.
10:24Now, I hate to be negative about that.
10:26I used to be a Certified Ethical Hacker.
10:28I haven't really practiced for a long time.
10:31But that basically means that I was kind of licensed
10:34to kill, so to speak, in terms of security and everything
10:38like that.
10:39With someone's permission, I could access their resources
10:42to see if a hacker doing the same things that I'm doing
10:45would be able to access those resources.
10:47And the reason why that's a factor with assumed breach
10:50is because most hackers will know how to plant something
10:54called a rootkit, to plant some kind of malware
10:57in there that they can just trigger at any time
11:00and then be able to take something over.
11:02Or just hover there indefinitely spying on what
11:06that organization is doing.
11:07So that goes into this point even well-protected networks
11:11will usually have a continual breach somewhere
11:15within their organization.
11:16They just haven't found it yet.
11:18Now, again it sounds kind of fatalistic,
11:21but when you assume that that's always the case,
11:24you also don't get careless.
11:25You are always vigilant and you are always
11:28circumspect in terms of what's going on
11:29instead of just assuming that everything is probably all
11:32right.
11:33It's a totally different mentality that we have there,
11:36and that's why we need to have an assumption that there's
11:40a breach that's already taken place
11:41to help protect our resources.
11:43So the risk of a little bit of overlap,
11:45I'll cover these quickly.
11:46But in the foundational elements of all of this, one of those
11:48would be identity.
11:49We talked about things like name badge, strong authentication,
11:52things like this.
11:53A lot of these name badges, by the way, will have--
11:55Oh, you've seen it before--
11:56that little kind of gold pattern that appears
12:00down there that's for contact.
12:02You'll see that on credit cards and things, for example.
12:04That's going to be--
12:05that's going to contain a certificate in most cases,
12:08which will help to authenticate that person
12:11and which is very, very difficult to counterfeit.
12:15So that's going to give you some strong authentication there.
12:18The magnetic stripe that's on the back of a lot of these,
12:20not very good.
12:22That's not a very dependable kind of authentication
12:24because a magnetic stripe can be duplicated
12:28as you see with skimmers and other things
12:30like that that steal credit card numbers.
12:32The expected behavior is another significant factor there.
12:35In fact, I think I have it over here.
12:37I was opening it earlier today.
12:39So let me explain what goes on here.
12:41When I log on to say a Microsoft system
12:43or using my Microsoft account, I have to, of course,
12:46know username and password and I answer that in.
12:48But in addition, it will send a prompt
12:51to my phone that looks a little bit like--
12:53well, that's not what that is.
12:54That's just telling me my laundry is ready.
12:56Anyway.
12:57And so, usually I'll get a prompt here
12:59that will say you're trying to log in,
13:02do you want to approve or deny this request?
13:05Well, if I'm at dinner with my wife enjoying some Italian food
13:08and I'm not anywhere near my computer,
13:11it's not likely that that's me.
13:12So I will immediately deny that, and that
13:15has happened recently many times in February, for example.
13:18And I'm going to just bring over--
13:20this is my own login record, but look at all these.
13:22These are all log-in attempts, China, China, China, China,
13:26seeing a pattern there, right?
13:28Many attempts to log on my account.
13:30But anyway, yeah, then here's another one, Lithuania.
13:33It tells me it was from wherever that is,
13:35even shows me on the map.
13:36Anyway, there are two factors here
13:39that are immediate red flags.
13:41One was the prompt was trying to get
13:43me to log on when I wasn't even using my computer,
13:45and the second one was the location.
13:47I'm not in China.
13:48I'm not in Spain or Lithuania.
13:51So therefore, that's not expected behavior.
13:54I'm not expecting a log on request
13:55because I'm not trying to log on,
13:57and I'm not in the right location,
13:58so that's also unexpected when it's coming in from China.
14:02There's also endpoint health and compliance.
14:05We need to make sure that we can monitor our endpoint devices.
14:08This would be everything really.
14:11Your personal computers that are used at work,
14:13your laptop computers, your devices, your mobile phones,
14:17tablets.
14:19And these days with coronavirus having happened not too long
14:22ago, even people's home computers
14:25because most companies were requiring people
14:27to work at home at least to a certain point.
14:30So if they're going to use a home computer to log in
14:33to work, we kind of got to make sure
14:35that device is particularly healthy, because if it's
14:38got some kind of spyware on it and it's
14:40going to monitor what they're doing,
14:41it can capture their work log on credentials,
14:45access to work resources, to files, all that sort of thing.
14:48So that has to be monitored and enforced.
14:51So there are ways to do this within Microsoft products,
14:53for example, so that if this device here is not healthy,
14:57then Microsoft is able to detect that early on
15:00and then deny any further access into, for example, Azure.
15:05Also your data is for most organizations
15:08the most significant value that you have.
15:10It's your database, it's all your customers,
15:12it's credit cards, social security numbers,
15:14top secret information, all kinds of stuff,
15:17health information.
15:19So that's going to be highly valued,
15:20and you must secure that as I mentioned earlier
15:22with the appropriate permissions.
15:24All right.
15:25That's enough for this Nugget.
15:26Stick around for the next Nugget where
15:27we will continue our discussion of some
15:28of these foundational elements.
15:30I hope this has been informative for you,
15:32and I'd like to thank you for viewing.
Foundational Elements
0:06So in our last Nugget we talked about
0:08some foundational elements, we'll
0:09continue that discussion here.
0:11Foundational elements relating to security.
0:13Now this is really, again, conceptual broad
0:16based, kind of broad stroke discussion
0:19of these foundational elements.
0:21I'm not going to show you where to click to fix something
0:23or where to click to improve your security
0:26or anything like that.
0:27So it's really going to be a little bit of a broader scope.
0:30However, when we get started with this, one of the things
0:32that you're going to find in an organization
0:34where you run IT is that the applications really get out
0:39of control fast.
0:40It's amazing what happens with this.
0:42And that's one of the reasons why admins really
0:44have to implement something called discovery.
0:46And this applies to a lot of different things.
0:48But in terms of applications, you
0:50kind of wind up with more apps than you think you do.
0:52I'll talk about that coming up shortly here.
0:54Now one of the reasons why that happens
0:56is because of shadow IT.
0:59It's like sleeper spies or something, OK.
1:02So we have our IT department, that's probably you
1:05and me or somebody that you manage, maybe as an IT person.
1:08Well, when it comes to shadow IT,
1:11these are people who have appointed themselves
1:14as IT over areas where they're not really supposed to,
1:17or they don't truly have the authority.
1:18Let me give you an example.
1:20This is not really relating to apps but similar.
1:22So let's say that this is our building here
1:25and we all work in this big ice cube.
1:28Anyway, In this very back corner is our conference room.
1:32And whenever we have people meeting in this conference
1:35room, gee, they just cannot reach the Wi-Fi.
1:39OK, this is our Wi-Fi right here, all right.
1:41It just-- they get a very weak signal,
1:43they're constantly dropping things
1:45and file transfer just won't happen
1:47and their Zoom calls are horrible
1:49and kind of embarrassing, but that's the only Wi-Fi
1:52that they have.
1:53So somebody goes out and they buy one
1:55from the electronic store, Best Buy
1:56is what we have here in America, you know,
1:58or someplace else you might have something.
2:00Anyway, they buy their own Wi-Fi ordered on Amazon,
2:03and they set that up.
2:04They plug it into a wall jack here, that's an ethernet jack,
2:08now they've set up their own kind
2:10of ad-hoc unauthorized Wi-Fi connection.
2:13That is shadow IT.
2:16OK.
2:17The problem there is we don't know
2:20how they secured that or if they secured it at all.
2:22They might have said, let's just make it easy
2:23and not set a password on this.
2:24Well, remember it's connected into my corporate
2:26it and I might have some hacker out here
2:30in their little VW bug.
2:32Looks like an anteater, I don't know.
2:33But a little VW Bug out here, and they
2:36are spying on our Wi-Fi signals because we
2:39have an open Wi-Fi out there.
2:40So that's the kind of thing that could happen, we want to avoid.
2:43When it comes to applications, we
2:45have a lot of different vectors where
2:47you could wind up with apps you really don't
2:49want within your organization.
2:51And there's also a balance with this because, remember,
2:53a lot of times people are bringing their own devices,
2:55BYOD, as we call it.
2:57No, not BYOB, that's more fun.
2:59This is BYOD, bring your own devices, that's a B.
3:04And so their tablets, you know, everybody's
3:07got a cell phone on them, some people have two cell phones,
3:10it gets to be kind of out of control.
3:11But all of those can get cloud apps, right?
3:14The place, what is it?
3:15The Google Store, the Google Play store,
3:17the Microsoft Store, the App Store for Apple products.
3:22And it's supposed to be that products that are up
3:24on those sites have already been gone through
3:27and they're supposed to all be safe,
3:28but we don't know how they're going
3:30to interoperate with other products that we have,
3:33that we require them to have.
3:34Maybe something about that app that they downloaded,
3:37which kind of works fine for anybody
3:38else just out in the general public, maybe it
3:40collides with one of our apps.
3:42Or maybe it has a security vulnerability
3:45that is a little bit more acceptable
3:47in the general public but in our organization,
3:50it's not acceptable at all.
3:52So those cloud apps can be an issue.
3:54And, again, in Microsoft Azure and some other methods
3:57you can use, there are ways to control
3:59which apps users can download.
4:01You can disable the store altogether
4:02or you can control what they can download.
4:04That's going to be, again, the Microsoft
4:06Store or the Microsoft Store for Business, that's going
4:08to be changing its name soon.
4:10But the basic idea here though, is
4:13that you can come up with only the apps
4:15that you want to make available to your users, maybe a five
4:18apps.
4:18Well, the Microsoft Store has, I don't know how many they have,
4:22they have thousands and thousands of apps
4:23but we're only going to allow five of those apps
4:26to be available on the Business Store,
4:28and maybe even one app we did in house, we made in house.
4:32So that's the business.
4:33Now, anyway, what else we got?
4:36Oh, ad-hoc devices, already talked about Wi-Fi and tablets
4:39and things like that.
4:40So those kind of things can get out of control.
4:42There was a survey done recently among IT professionals.
4:45Most IT pros assumed that there were probably
4:4840 to 50 apps on various devices within their organization
4:52that were not truly authorized, something they downloaded
4:55on their phone or whatever.
4:57Turns out there's usually about 1,000 apps on larger
5:00organizations, there's about 1,000 apps
5:03that IT doesn't even know about and doesn't manage.
5:06OK, so that gets to be an issue in terms of security.
5:09Then there's the infrastructure.
5:11And this really has several vectors.
5:13The first vector that we have is this really giant diagram
5:16of what looks like--
5:17I don't know, it looks like machinery
5:19from Willy Wonka's chocolate factory or something.
5:21I don't know, anyway, what's going on there.
5:23But, anyway, the idea there is it's infrastructure.
5:26And we have security configuration
5:28that we have to make sure works well with this.
5:31So you might see, like here, this
5:32is supposed to be a firewall that you can see down here,
5:35my pen colors kind of too light for that.
5:36But there's a firewall, we might have other network devices
5:40that would be an intrusion prevention system
5:43or something like that.
5:44I'll give that in a moment.
5:45You might have patches that you have.
5:48So maybe this is an update server,
5:49I'll put a U for an update server there.
5:51I don't even know what that's supposed to be
5:52but we'll call it an update server right now.
5:54And it's supposed to have a list of acceptable patches
5:58that you've already tested, then you approve of,
6:00and that can then distribute those patches
6:02to all of the devices within your organization.
6:05So that's another thing you might have in there
6:06to help your security.
6:08There's also intrusion detection systems and intrusion
6:11prevention systems IDS, IPS.
6:13So the ideas is going to be a little less intrusive.
6:17What it's doing is it kind of hovers
6:19on the edge of your network and it watches,
6:22usually it's inbound traffic, could also
6:24be within your network but usually inbound traffic
6:26like from those evil internet users.
6:28And we're trying to see if we're getting
6:30suspicious traffic coming in, can even
6:32examine things like email messages and things like this.
6:35Anyway, if it sees it, usually just logs in.
6:38And then what it does is most of the products that
6:41are IDS will have some kind of a reporting mechanism
6:43that administrators can go to.
6:45And they say it's going to show maybe the top 10
6:47suspicious things that happened this week.
6:50Really, there's going to be thousands in a larger room
6:52and there's many, many thousands of things in that report
6:56so you kind of have to distill it down.
6:57An intrusion prevention system does
7:00what an IDS does, and it takes it one step further
7:02and then it will block anything that seems suspicious.
7:05But sometimes they're too aggressive
7:07and you might have traffic block that you really
7:10intended to receive.
7:11So you kind of have to strike a balance with that one.
7:14Then there's also the network itself.
7:16This diagram might make a little bit more sense.
7:18Anyway, with this we have segmentation and isolation, OK.
7:23So we might have all of these computers over here
7:26on the left connected to one of my routers,
7:30and then I might have a bunch of other--
7:31I'll put it out in the black area
7:33so you can see a little better, a bunch of other computers,
7:35all these circles are our other computers,
7:38connected to another segment in our network.
7:41And we may want to carefully control traffic,
7:44goes back and forth between them.
7:45Now, people that work with a classified networks and things
7:48like that, you're probably going to pipe up and scream at me
7:51here.
7:52But one thing we don't want to happen
7:54is to have traffic or maybe file transfers
7:57from a classified network to an unclassified network.
8:00Now, there shouldn't be any way for that to even happen
8:02in most of those organizations.
8:03But regardless, we wouldn't want it to happen.
8:05So you want to segment that traffic out,
8:08so you are isolating it.
8:10And there's even a deeper level of that
8:11called micro segmentation where you make really,
8:14really smaller segments of networks and VLANs,
8:17and things like this.
8:18There's also encryption.
8:20So in most organizations, when you're
8:22transferring traffic between a server and maybe your laptop
8:26or something like that at work, it's probably not
8:28encrypted in most of those cases but you
8:31can add encryption to networks using
8:32a number of different methods.
8:34You can use IPsec, you can use other kinds of encryption
8:37mechanisms on your network.
8:38The thing is it's going to have additional overhead.
8:40Whenever you encrypt something, it
8:42could potentially also slow down your network performance
8:44a little bit.
8:45But it might be worth it if you get more security out of it.
8:48There's also cloud migration.
8:49Maybe we've got servers locally--
8:51I'm going to talk about this coming up probably
8:53in the next Nuggets.
8:54Maybe we have servers here locally
8:56that have got to be very expensive, they're very big,
8:58they consume a huge amount of electricity.
9:01We're kind of tired of managing them and updating
9:04them and everything like that, and caring for them.
9:08We'd like to maybe put that into the cloud.
9:10And that can be done with a lot of different things.
9:12That's why the cloud is becoming such a big thing these days.
9:16Because people are taking things like local web servers,
9:19putting those in the cloud.
9:20It's very easy to do, you can do it very quickly, and really
9:23probably a lot cheaper than what you can do if you host
9:25those kinds of things locally.
9:27And then there's something else here called
9:29threat intelligence.
9:30This is a really giant topic on its own,
9:32might even be a-- if it's not yet,
9:33it probably will be, even an exam from Microsoft,
9:37you can probably take on this product called Azure Sentinel.
9:41Here's a little URL off to the side
9:42if you want to look at it some more.
9:44But it's pretty fascinating product.
9:46And the basic idea here is it inplants
9:48something called SIEM, S I E M, Security Information and Event
9:53Management.
9:53Wow, that's a mouthful.
9:55Anyway, what this SIEM does is it's not just
9:58kind of like an antivirus product.
10:00I mean, it's that but it's a lot more than that,
10:03it's a lot more analytics and intelligence.
10:05It uses machine learning and artificial intelligence.
10:09And it kind of has to because there's things called signals.
10:13And a signal is something that can be emitted from a computer
10:18and sent to, like say, Microsoft.
10:21And then Microsoft can take that signal and determine
10:24is that malicious or is that not malicious
10:26or is it ordinary file or ordinary network traffic
10:29or not.
10:30Is there any threat, in other words.
10:32Well, guess what, Microsoft actually
10:34does receive a lot of those, you wouldn't believe how many.
10:37They receive trillions of signals daily.
10:41Well, that's why they have to have machine learning
10:43and artificial intelligence.
10:44Even if someone as brilliant as me could not
10:47go through trillions of signals daily manually,
10:49I'd have to-- you'd have to use machine learning
10:51or artificial intelligence.
10:52And it's really a fascinating engine that they have,
10:55Microsoft does.
10:56If you want to read on it, there's good stuff there.
10:58In this article, in fact, will give you some of that.
11:01There are over a million new threats daily,
11:04I just learned that last week.
11:05A million new threats daily.
11:07And because of the morphic nature of them,
11:11meaning that they change and things like this,
11:1395% of those one million threats are never seen again.
11:17So they are one time events.
11:20That's, again, why you have to have artificial intelligence.
11:24So that it can look at something that could be a threat,
11:26and even though it's never seen it before
11:28and never fingerprinted it before,
11:29has to be able to determine that's suspicious, not
11:32suspicious, that's a significant threat, whatever.
11:35So that's the conclusion of our second part
11:37of our foundational elements.
11:39I hope this has been informative for you,
11:41and I'd like to thank you for viewing.
The Shared Responsibility Model
0:07For a lot of us folks that have been in the IT world
0:09for a long time, like me, it's kind of
0:11difficult to get your mind around the cloud.
0:14What's the cloud?
0:15When we set up servers in the old days, we would set them up.
0:18We would put hands on them.
0:19If they needed to be upgraded, we would open the case
0:21and put in more memory or another processor, whatever
0:24it is we needed to do.
0:25We could put our hands on all of the servers, all of the network
0:29equipment, that we would manage.
0:31Well, now stuff's in the cloud.
0:33Most administrators will never even see the data center
0:37where their servers are actually hosted.
0:40I've got some that are hosted, pretty
0:41sure it's in Des Moines, Iowa.
0:42I'm not even completely sure, because I have a big data
0:45center from Microsoft.
0:45I've got a lot of machines in Azure that I've run there.
0:49And I've never visited that data center.
0:52Even if I were to visit that data center,
0:54there's no way I could put my finger on which
0:57rack my servers were in.
0:59But, nevertheless, it's really important
1:01to get your mind around the cloud
1:03and a lot of the advantages that it does have.
1:06So let's take a look at an example here.
1:08Let's say that we've got a small toy company.
1:10And, of course, during the holiday season,
1:13our sales go up dramatically.
1:15This is all on premises.
1:17We just usually say on prem.
1:19So it's on premises.
1:21And these are our servers here.
1:23We've got a few servers in here.
1:24We've got some-- it looks like some hard drives there.
1:26Maybe there's some network equipment in here somewhere.
1:30All of this stuff, we put hands on, we installed it.
1:33It's all ours, right?
1:34Problem is, each year, out toy company's been doing better.
1:38And last year, maybe we were running at about 80%
1:42capacity for the servers that we have in here and everything.
1:46Well, in IT, that's cutting it close.
1:48You never want to, probably, get that high in the utilization
1:52because if we have an extremely high period of utilization,
1:55or maybe during our busiest hours,
1:58that could spike up to 90% or so, or maybe more.
2:01And then, people, when they're opening our web page,
2:03maybe one of these is our web server,
2:05when they open our web page, they're
2:06just going to get the spinning circle and say,
2:09unavailable or something like that.
2:11Well, then they're just going to go to a competitor.
2:13People don't have very much patience for that anymore.
2:15So what can we do if we kept everything on premises?
2:17Well, we might just install another server, another rack
2:20and everything like that.
2:22But the expense there, the upfront expense
2:24is extremely high there.
2:26Just the network equipment alone in one of these things,
2:28you can add up $100,000 pretty quick.
2:30A Cisco power cable that looks a lot like the one
2:33I could get at Home Depot or a home improvement store,
2:36it's $400 for a power cable, folks.
2:39So this stuff gets really expensive really fast.
2:42But if I kept everything on premises,
2:44I might have to do that.
2:45So now I have two servers.
2:47Oops.
2:47That's supposed to be a 45.
2:49One's running 45%.
2:51Let's say, at 90% now, total for our holiday season.
2:54And we're splitting it up between both
2:56of these servers and all the network equipment
2:58and everything.
2:58So now they're both running 45% capacity.
3:01I'm more comfortable with that, but that
3:03means that about this much of our total capacity on both
3:07of these is not being used.
3:09But I'm still paying for it.
3:10I'm still powering it.
3:12I still had to have the upfront costs.
3:13I still spent, maybe, $100k or more to do it.
3:16I still have to maintain the whole thing.
3:18I still have to update my servers.
3:20I still have to make sure that they have the latest patches
3:22and everything like that.
3:23And I have to make sure that they're all
3:25consistent with one another.
3:26So sometimes I might want to change that.
3:29Maybe I would rather than setting up an entirely new
3:33setup here on premises, what if I put that in the cloud
3:37instead, maybe Azure?
3:38And Azure is not the only game in town.
3:40That's Microsoft's solution.
3:41There's lots of other ones.
3:42Amazon Web Services has some, all kinds of other companies.
3:45But, anyway, of course, this is Microsoft.
3:47So we're looking at Azure here for this.
3:49Now what do we do?
3:50Well, let's say we just needed some more capacity.
3:53Maybe with this I don't have to install all of this at once,
3:58so to speak.
3:58And I'm just using this conceptually.
4:00Maybe we only need two or three more servers in Azure
4:04that we can stand up, and then, each one of those servers,
4:07maybe it runs us $50, $60 a month.
4:09That's a whole lot easier to swallow than, say, $100,000
4:13to stand up a new server rack and all the equipment
4:16that goes inside of it.
4:17And here's the other thing.
4:19Let's say that we had an unusually successful season,
4:22and it turns out that even these servers were not enough.
4:25You can even automate this so that it can scale up,
4:28so that during busiest periods of time,
4:30we can set a certain threshold.
4:32So we can say, well, when it gets
4:33to be 80%, whatever percent we decide,
4:36we're going to add more servers onto this.
4:39And it can happen automatically and based on demand.
4:42Then, when we're not using them, and it's February,
4:46and our season's done and everything,
4:48we can scale back down easily and save money.
4:51And that, ultimately, is where we come up
4:53with our concept of shared responsibility
4:55because we're still even if we use
4:57a lot of stuff on the cloud.
4:58We're still going to be responsible for certain things.
5:01We can't say it's Microsoft's fault that they misconfigured
5:04our user account because they don't configure it.
5:06We configure the user account still.
5:07We still have to do a lot of the configuration and management
5:11there, even though we might not have all of the hardware.
5:14And there are several different stages
5:15of this that you can work within.
5:17And a lot of companies will implement
5:20some form of all of these.
5:21We have Software as a Service, Platform as a Service,
5:25and Infrastructure as a Service, each
5:27of them involving more or less involvement from you
5:31as an administrator in terms of where the responsibility lies.
5:34So if you do decide to start implementing cloud services,
5:38and just about all of us probably are,
5:40then you're going to be using it in some form of Software
5:43as a Service, Platform as a Service,
5:45or Infrastructure as a Service.
5:47I'm going to define those here as we go, the first one being
5:50Infrastructure as a Service.
5:52And sometimes, the line, by the way, between these,
5:54becomes a little bit fuzzy, depending upon what kind
5:57of services you're using.
5:59But with Infrastructure as a Service,
6:00it's kind of the most fundamental level,
6:02kind of the starter level of this, if you will.
6:05With this, you're mostly getting the hardware from your cloud
6:08service provider.
6:09You're getting the storage.
6:10In other words, the hard drives or the SSDs,
6:12they're in a data somewhere that they have
6:15and that you're putting your data on.
6:17You're using their network resources
6:20to access them yourself, or for your customers
6:23to access anything that's necessary there.
6:26And you're using their compute power as well.
6:28So using, in other words, their CPU.
6:31In other words, we're really using their servers
6:34and their network services.
6:36Now, how is this typically charged?
6:37How do we pay for this stuff?
6:41It could be per user, depending upon the kind of service it is.
6:44In my case, I'm generally starting up
6:47servers that are going to be charged
6:48by the-- it could be by the hour, by the week,
6:51or by the month.
6:51With Azure, most of these are by the month.
6:54But it's also incremental.
6:55So if you used a server for only two weeks,
6:57and then you tore it down and you deleted it,
7:00then you're only going to be charged for those two weeks.
7:02There's not like a minimum, so to speak.
7:05Also, it's sometimes charged by storage.
7:08So I might even have servers that I'm already paying for,
7:10and they have some storage there.
7:12But maybe it's not enough.
7:13I can add storage, and it may or may not cost me very much.
7:17A lot of times, the storage really
7:19is a very good value for what you get there.
7:22Now, if you're using Infrastructure
7:24as a Service, which is our current topic here,
7:27a lot of common uses for this are
7:28something like testing or development,
7:31where we just need to have a server that's off prem.
7:33It's not something we use here.
7:35And we just want to put it in what
7:37we call a sandbox, where it's somewhere else, and it's safe.
7:41And if it blows up, it doesn't affect
7:43the rest of my organization, for example.
7:45Sometimes this could be customer websites or web apps.
7:48But, again, you'll also use websites and web apps probably
7:52in SaaS and PaaS.
7:53By the way, we call this IaaS, PaaS, and SaaS.
7:56Now, when you're using Platform as a Service, or PaaS,
7:59you're starting off with pretty much
8:01the same thing you had with IaaS.
8:03So we're going to add to the IaaS infrastructure there,
8:07software, and especially for application development.
8:11If you are also interested in working more
8:14with Microsoft servers, like Server 2022, Knox and I,
8:18Knox Hutchinson and I just finished
8:21a series that's the AZ-800.
8:24Ben Finkel also added some content to it.
8:26One of the things I taught there was Platform as a Service,
8:29where you can actually use containers.
8:31And that's another example here.
8:32You can get something called a container, such as one
8:35from Docker, for example.
8:37And what this is, normally, when we have a server here,
8:40we think about, well, we installed Windows on it--
8:43Windows Server 2022.
8:46And we installed the entire operating system on it.
8:49And then we started to install applications on top of it,
8:52app 1, or something like that.
8:54And then we had app 2.
8:55And pretty soon, we got a dozen apps on there.
8:57Well, when it comes to containers, just
8:59to be real brief about this, we don't really do that.
9:03I'll try to summarize this as best I can.
9:04We just get pieces of Windows Server 2022,
9:08or it could be Linux or something else as well.
9:10But we just get core components of the operating system,
9:14just enough to make the application run.
9:17That prevents us from having to install an entire operating
9:20system.
9:20Advantages of this, these containers
9:23can start up in mere seconds.
9:25Sometimes, it's just two or three seconds
9:27that they start up.
9:28And they're very, very fast.
9:29It's very fast and easy to add additional ones.
9:32So if we need more, like we're reaching our capacity,
9:34for example, we can just add a dozen of those in mere seconds.
9:39It's very quick and easy to do.
9:40We can also use this kind of thing
9:42for database integration and collaboration,
9:45just taking this to another level.
9:46For example, Salesforce is a product,
9:48which, I don't know if you're familiar with that or not,
9:50but many companies use Salesforce.
9:53It's a gigantic organization.
9:54It's used for keeping track of your customers
9:57and your sales, your whole sales process.
10:00We also have Software as a Service.
10:02Now, Software as a Service, or SaaS, this
10:04is where the software itself is served from a cloud provider.
10:08And, again, this is where it gets to be a little bit
10:10fuzzy because when we're working with PaaS,
10:13Salesforce is in PaaS, but it's also possibly in SaaS.
10:17So the line gets a little bit fuzzy there.
10:19But this is where we have an independent software
10:22vendor that contracts with someone in the cloud.
10:24So we may have a software developer that's put products
10:28in Azure, for example.
10:29Or the cloud provider itself is also the software vendor.
10:32That would be somebody like Microsoft Azure, where
10:35we might need to get some servers or a software product,
10:38and Microsoft is both the developer of that software,
10:41as well as hosting the product.
10:43This is typically going to be accessed via web browser.
10:46And, of course, again, it's usually a subscription.
10:49But then again, so is PaaS and so is IaaS.
10:52You can have a single installation on these.
10:55But you might have multiple customers.
10:57So in Microsoft land, this might be their server here.
11:02And I might install five installations of Windows
11:06here on their server.
11:07But there's other people that have also
11:09installed five installations of Windows on that same hardware.
11:13And they may also have other things involved in that.
11:16So I don't own that entire rack myself when I do that.
11:20It's shared with other people.
11:23But rest assured, all of my copies of Windows
11:25are segregated from this person's copies of Windows.
11:29And we should not have any spillover
11:31here between our data.
11:32And it's all protected.
11:34So in other words, that data is going to be segregated.
11:36Now, what are some examples of SaaS?
11:38Well, one of those, we use all the time, Netflix.
11:41Yeah, the Netflix engine and whatever
11:45it is that streams that video out
11:47to us, that's all Software as a Service.
11:49That's Netflix.
11:50We might be using Microsoft Office.
11:52Or I'm using PowerPoint here.
11:54This actually can be delivered from the cloud directly.
11:58In my case, I have PowerPoint installed locally.
12:00But if I want to, I can run the whole thing
12:02from a web browser connected to Microsoft.
12:05Google Docs, all of that stuff would be examples
12:07of Software as a Service.
12:09Now, as we move into the cloud infrastructure,
12:12depending upon which level we've chosen to use,
12:15we have varying levels of responsibility.
12:17So remember, when we were on premises,
12:20where I had everything, I had all of it.
12:22I had the data locally.
12:23I had all the devices, all the servers.
12:26I managed all the accounts locally.
12:28And all the rest of this was local here as well.
12:30And you can read down through the rest of these, clear down
12:33to the physical data center, the network, the host,
12:35meaning the servers.
12:36All of that stuff, I was in charge of all of it.
12:38I put hands on all of it.
12:40All my responsibility.
12:41However, if we decide to use something like Infrastructure
12:44as a Service, and we start to ease our way into the cloud,
12:47well, then, the servers might not be on my premises.
12:50They might be-- and, by the way, this
12:51is borrowed from Microsoft.
12:52And there's a link down here at the bottom.
12:54You can see there.
12:55But this lighter blue color means
12:57Microsoft has taken responsibility for that.
12:59They've taken responsibility for the server,
13:02for the network infrastructure, other than I have
13:04to have a network connection.
13:06I have an internet connection to be
13:07able to reach it because that's usually, again,
13:09done through a web browser.
13:11There's the physical data center.
13:12Microsoft has all of that.
13:13I don't have to install big expensive generators
13:17for backup power.
13:18I don't have to have a big data center that's
13:20worth bazillions of dollars, any of that kind of stuff.
13:24I just have to have my $100 a month internet connection.
13:28Although, if you're a corporation,
13:29you probably have a bigger pipe and more expensive
13:32internet than that.
13:33But anyway, so that's where we're at with IaaS.
13:35I have less responsibility, but I'm still
13:38responsible for all of the rest of this stuff
13:40right through here.
13:41Now, as we move forward, to Platform as a Service,
13:45we see that we relinquish more of our responsibility
13:48over to Microsoft.
13:49So now, when we have Platform as a Service,
13:51the operating system belongs to Microsoft.
13:55And I'm borrowing it for purposes
13:57of running whatever it is I need to do, my apps or whatever.
14:00And then some of these will then be shared.
14:02And that's why we have this split box here.
14:06All the network equipment is at Microsoft.
14:09The physical network equipment is there.
14:11But network controls, like Bastion or using
14:15something like a firewall, if I want
14:17to configure that sort of thing there, then I configure it.
14:20So it's my responsibility.
14:21But the physical stuff is still there
14:24at Microsoft's responsibility.
14:25And then, finally, if I go full out and use Software
14:28as a Service, and I give everything
14:30that I can over to Microsoft, then they
14:32have all of this stuff, like this--
14:35application, the network controls,
14:37all the physical aspects of it.
14:40And the Identity and directory infrastructure
14:42is shared because I might have a server installed in the cloud,
14:47but I still have to create the user accounts, for example.
14:51It exists on a Microsoft server.
14:53My accounts exist on a Microsoft server.
14:55But it's up to me to create the account.
14:56It's up to me to have the responsibility
14:58to determine what kind of password
15:00they have and stuff like that.
15:01And that really goes up to this level here as well.
15:03And these things up here at the top,
15:05I'm always going to be responsible for those.
15:07I'm responsible for my own information and data.
15:09I can store it on Microsoft servers,
15:11but I'm responsible for what that data is.
15:13Any of the additional devices that
15:15might connect to those cloud services,
15:17I'm also responsible for.
15:19So if we have mobile devices, company mobile devices,
15:21where people can log on and use those services,
15:24well, I'm still responsible for those,
15:25for my PCs that are still in the building that I own.
15:28We're responsible for that, and for how we create and identify
15:33our users.
15:34And to illustrate the whole point
15:35of using cloud services to offload our responsibilities,
15:40the server you're looking at right here,
15:42I don't know where that is.
15:44It's somewhere in the West.
15:45I chose the West region.
15:47I don't even know what data center it's in.
15:48I installed it during my lunch break.
15:50I ate lunch at my desk, and I ate a candy bar for lunch.
15:53In the time that it took me to eat that candy bar,
15:56I had configured this server, and it was ready to go.
15:59That's how fast you can set this up.
16:02And here's even the web page that I used to configure it.
16:05This is where it's running right now.
16:06If I wanted to stop it, I could stop it.
16:08If I needed to restart it, I could restart it.
16:10If I'm done with it, I can actually delete it,
16:12and it takes about maybe a minute to delete this thing.
16:15I'm on a Pay-as-you-go subscription.
16:17So I can't remember what it costs.
16:18I think it's $50 a month.
16:20No, this one's $35 a month to run this one.
16:24If it turns out that it's not powerful enough, look,
16:27over here on the left, I could go down to Size,
16:30and I can upgrade the size to some other version
16:34of the server.
16:35I can add processors, memory, hard disk, data disk,
16:38which you see right here.
16:39I can do whatever I need to to make sure
16:42that it meets my needs.
16:43So to sum it all up, we start to offload
16:45some of our responsibilities as we move further
16:47towards the cloud, but we're still responsible for some
16:49of those critical pieces of things, such as our accounts
16:52and our data itself.
16:53I hope this has been informative for you,
16:55and I'd like to thank you for viewing.
Security and Compliance Pop Quiz
0:06All right, folks.
0:07I thought it'd be a great idea if right here at the end,
0:10we would just have a quick little pop quiz.
0:13Didn't you just love it when you were in school,
0:15and your teacher would announce pop quiz?
0:18That's what this is.
0:19But I promise you, you should get 100 on this.
0:21Or it's not too hard.
0:22And I will not send a report card to your parents.
0:25OK, first question here is, as long
0:29as you are not aware of an active breach,
0:32you can assume that your network is safe and uncompromised.
0:36No, you can't.
0:37Remember, that's one of the things we always assume.
0:40Assume breach.
0:40That's the words we used, I think.
0:42Assume breach.
0:43We always must be vigilant and assume
0:46that there's very likely possibility that somebody's
0:48already in our network, or has already compromised
0:51our systems, or that we already have some computers that
0:54probably have viruses or spyware or some kind of malware
0:56on them, right?
0:57So we never assume that everything is safe.
1:00Question two-- an example of "Shadow IT"
1:04might be a person who is not in the IT department
1:07setting a Wi-Fi access point.
1:09Setting up.
1:10I should say, "setting up" a Wi-Fi access point
1:14or installing unauthorized software.
1:17Yes.
1:18Remember, that's what Shadow IT is, someone that's doing IT
1:21duties or responsibilities without really
1:24the authorization.
1:25And I might also add to that, that this
1:27could be somebody who does work in IT,
1:29but they're not doing something in the area of their expertise.
1:33So, for example, if somebody is an Active Directory expert,
1:37and they're really good with working with Microsoft
1:39accounts, resetting user's passwords,
1:42setting up group policies, some of the deeper things in Windows
1:46Server, but they're setting up networking
1:49that really our Cisco folks should be doing, or setting up
1:52a Wi-Fi that really our Cisco experts should be handling,
1:55that might also be considered Shadow IT.
1:58So question three-- as you move your IT resources
2:01into the cloud, you begin to transfer some responsibility
2:06to your cloud provider.
2:08And that might be somebody like Microsoft Azure, of course.
2:11And that also is a big yes.
2:15If we're starting to move into the cloud,
2:16then the servers that we want to use are no longer on-prem.
2:21They're not in our rack anymore.
2:22You can't put hands on them.
2:25You can't do any of that kind of stuff.
2:27They belong to Microsoft.
2:28And we're pretty much, more or less, leasing those servers.
2:32All right, so that's our first pop quiz.
2:35Hope you enjoyed it.
2:36More fun than the ones that we used to have in school, right?
2:38All right, I hope this has been informative for you,
2:40and I'd like to thank you for viewing.
Team training path
Turn this skill into assignable team training
This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.
$708
seat / year