Overview
Join Bob Salmans as he explores the Microsoft Cybersecurity Reference Architecture. We'll look at individual areas of the architecture and review many of Microsoft's security related services and their purposes.
Recommended Experience
- 2 to 5 years of devops or cloud experience
Related Job Functions
- Cloud Engineer
- Solutions Architect
- DevOps Engineer
When it comes to cybersecurity, you’d be hard pressed to find an instructor with the experience and knowledge that Bob Salmans brings to his training.
Intro to the Microsoft Cybersecurity Reference Architecture (MCRA)
In this nugget, we're going to talk about the MCRA, what it is and why we would want to use it.
Knowledge Check
The MCRA outlines Microsofts cybersecurity capabilities. True or false?
Security Operations
In this nugget, we're taking a look at many of Microsoft's cybersecurity capabilities related to security operations.
Knowledge Check
If our organization struggles with incident response, which Microsoft resource would help us to have better incident response capabilities?
SaaS & Identity Protection
In this nugget, we're taking a look at many of Microsoft's cybersecurity capabilities related to protecting SaaS applications as well as our identities.
Knowledge Check
Which tools does Azure AD provide us with to protect our identities?
Endpoints and Devices
In this nugget, we're taking a look at many of Microsoft's cybersecurity capabilities related to endpoints and devices.
Knowledge Check
Which Microsoft solution would we use to manage mobile devices?
Hybrid Infrastructure
In this nugget, we're taking a look at many of Microsoft's cybersecurity capabilities related to securing hybrid infrastructures.
Knowledge Check
If we had VMs in AWS and on-premises and we wanted to manage them with Azure's ARM, what Microsoft product would we use to make that happen?
Information Protection
In this nugget, we're taking a look at many of Microsoft's cybersecurity capabilities related to protecting our information.
Knowledge Check
Microsoft Purview is a tool used to help us with what?
IoT and Operational Technology (OT)
In this nugget, we're taking a look at many of Microsoft's cybersecurity capabilities related to IoT and operational technology.
Knowledge Check
Which Microsoft solution provides us with the tools we need to provide a secure end-to-end IoT solution?
People Security
In this nugget, we're taking a look at many of Microsoft's cybersecurity capabilities related to people security.
Knowledge Check
The attack simulator tool lets us run realistic attack scenarios against our users in order to measure the effectiveness of our security training. True or false?
Other Resources
In this nugget, we're taking a look at some additional resources that didn't quite fit into the other categories.
Knowledge Check
Which Microsoft feature allows us to build and integrate an application into our security data within our Microsoft security services?
Conclusion
I hope this has been informative for you and I would like to thank you for consuming.
View Transcript
Intro to the Microsoft Cybersecurity Reference Architecture (MCRA)
0:00[AUDIO LOGO]
0:06All right.
0:06It's time for us to examine the Microsoft Cybersecurity
0:11Reference Architecture.
0:12Now, the first question out of your mouth
0:14is probably, what is it?
0:15Well, it is a tool for security architects and security
0:19professionals dealing with Microsoft products
0:21like Office, 365, Azure, and others.
0:25Well, it's a tool for us.
0:26Basically it kind of outlines what tools
0:29we have at our disposal that Microsoft provides to us.
0:32And yes, we might need to buy licensing for them,
0:34but it's there if we might want to use it.
0:37So it kind of outlines a toolbox that we
0:39can use to address problems to, as a security architect,
0:44to design a solution that would meet our goals
0:47or would help us to solve a problem.
0:51So that's what the Microsoft Cybersecurity Reference
0:54Architecture is.
0:55Wow, it's a mouthful.
0:56So now, let's jump in and take a look at it.
0:59All right, here we are in the Microsoft documentation.
1:02And we're just going to look at this really briefly before we
1:04look at the architecture itself, which
1:06is a PowerPoint by the way.
1:08So what is this?
1:09Well, basically, this describes, if we look at here,
1:12describes Microsoft Cybersecurity capabilities.
1:16So really, those capabilities are services that we could use,
1:19they are tools for us as security professionals
1:23and security architects to use to address problems and create
1:27solutions.
1:28So basically it outlines a toolbox for us.
1:30And it helps us to identify, in certain situations,
1:33which tools are best to use.
1:35So it's really nice.
1:37And you should be familiar with it.
1:38Download it.
1:39Man this is really cool.
1:40They put a lot of work into this.
1:41And it is pretty darn awesome.
1:44So what it does is it talks about different capabilities.
1:47And I'm not going to read through this, because we're
1:49actually going to look at it.
1:50But if you scroll down here, it's
1:53got lots of different diagrams in the architecture for us
1:57to look at for things like attack chain.
2:00So during the attack chain-- we're going to go over this,
2:03don't worry--
2:03but during the attack chain there
2:05are different steps that occur.
2:06What tools can you use to address different steps?
2:09We're also going to outline all the capabilities, all
2:11those tools that we can use.
2:12And that's what we're going to cover in this set of Nuggets,
2:15it's all those different capabilities.
2:17Now, we're not going to dive deep
2:18into them because you should be familiar with most of them.
2:21But we are going to talk about what they're used for.
2:24And of course, when we might want to use them.
2:27Also going to look at People.
2:28How do you deal with People and the risk associated with them?
2:32And of course, Zero Trust.
2:33Now let's say Zero Trust is paramount when
2:36it comes to cloud security.
2:38You don't trust anyone or anything.
2:41And you always assume breach.
2:43That is our Zero Trust.
2:44And also, we're going to take a look at some native controls.
2:47Those are things that exist natively
2:49within Azure and the Microsoft Cloud,
2:52like the Azure firewall for instance.
2:54It's already there, we can use it.
2:56And then we're going to talk about security operations
2:58and operational technology, and IoT, all those cool things.
3:02But what do you say we jump in and take a look at the MCRA
3:05itself.
3:06And so what we're going to do here is bring it up.
3:08Here we go.
3:09And if I scroll to the top here, this
3:10is the first slide and that's what we just saw in that image.
3:13But as you see here on the left, I'm
3:15going to scroll all the way down,
3:16there are 65 slides in this deck.
3:20That's a lot of information.
3:22But what we're going to start focusing on,
3:24let's scroll back up here, is we're
3:26going to start focusing right here on slide
3:289, the Cybersecurity Reference Architecture.
3:32And here, we're looking at our tools.
3:34These are the different services and solutions
3:37that Microsoft provides to us so that we can use.
3:40So this is kind of like our inventory
3:41for our toolbox of security tools
3:44that we can use in the Microsoft environment.
3:46So you need to be familiar with all these tools.
3:48Know what they are and when we might want to use them.
3:51And that's what we're going to start talking about
3:53in the next Nugget.
3:54So I will see you there shortly.
3:55I hope this has been informative for you.
3:57And I'd like to thank you for viewing.
Security Operations
0:00[AUDIO LOGO]
0:06We're starting off with security operations
0:09in the Microsoft Cybersecurity Reference Architecture.
0:12Now, when it comes to security operations,
0:14we need to identify what tools do we have
0:17that Microsoft provides at our disposal
0:20that we can use as part of our security operations.
0:23Because the goal of security operations
0:25is to quickly identify and address any security incidents
0:29that might come up because we need
0:31to do this in order to minimize impact to our organization.
0:34So let's jump in and take a look at some of the tools
0:37that we have.
0:38All right, we're starting off here,
0:39of course, security operations, as I just mentioned.
0:42And this is the slide from the Microsoft Cybersecurity
0:46Reference Architecture that shows all the different tools
0:49that we have.
0:50And they're grouped according to their uses, where they belong.
0:54We're focusing here on security operations right there.
0:59That's what we're going to be discussing, those tools
1:01that we have at our disposal.
1:02So let's get started.
1:03Here we go, threat experts--
1:05Now, threat experts is basically a managed hunting service.
1:12And by hunting, we mean threat hunting.
1:15That's right.
1:16They're looking at our organization.
1:18They're going through, and they're
1:19monitoring what's going on within our data,
1:22in our sign-ins, in our authentications.
1:25And they provide us with expert-level monitoring
1:29and analysis to help ensure that the critical threats
1:32in our environment don't get missed.
1:35Because again, when we're dealing
1:37with threats in our environment, all of our environments
1:39are different when it comes to different customers and such.
1:42But what threat experts do is, they come in,
1:45and they hunt in our environment.
1:47They look for those threats that are out there.
1:50And they help us identify them.
1:52So the idea here is, if we don't have skilled personnel that
1:55can do the hunting for us, if we don't have a team for this,
1:59well, guess what?
2:00We can outsource it to the Microsoft threat experts.
2:03Or maybe we have a small team, and we
2:06want to implement threat experts to help us be more robust.
2:11So just think about that.
2:12That's where those threat experts are
2:14and where they come to play.
2:15Next up, we have DART, Detection And Response Team.
2:20That is our DART.
2:21Now, that DART team provides assistance
2:24with incident response, recovery, and hunting.
2:30So if we run into a problem and we need assistance
2:36with incident response and/or recovery or even hunting,
2:40well, guess what?
2:41We can reach out to the DART team.
2:43And of course, it's not free.
2:44You have to pay for it just like you do with the threat experts.
2:47But they're out there.
2:49And this is basically incident response
2:53on retainer for customers with premium and unified support.
2:58So if you need assistance with your incident response
3:01recovery your hunting, reach out to the DART team.
3:05That's your detection and response team.
3:07Next up, Microsoft Sentinel.
3:09Now, Microsoft Sentinel is a SIEM
3:12or "seem" and SOAR solution.
3:15Now SIEM, you should be familiar with.
3:18Basically, collects a bunch of logs from all over the place
3:20and analyzes them, looks for things
3:22that are out of the ordinary or threats and whatever it finds.
3:24And then SOAR provides us Orchestration and Automated
3:27Response to the alerts.
3:29So when SIEM sends off an alert saying,
3:32hey, there's something going on here-- warning.
3:34You know, what we can do is kick off
3:36an automated response via the SOAR capabilities of Microsoft
3:40Sentinel.
3:41So again, this is going to be collecting all of our logs
3:45from various locations to identify threats
3:48in our organization and also allows us to do hunting.
3:52So if we wanted to do threat hunting
3:54through our organization ourselves,
3:57our own team, well, we would most likely
3:59use Microsoft Sentinel to do that.
4:01Next up, is Microsoft Defender.
4:03Now, Microsoft Defender is a unified detection and response
4:08platform.
4:10And what it does, it provides us a dashboard or a portal.
4:14And within that portal, we have different things along the side
4:17here and things like hunting.
4:20So we can go in and do hunting through logs and such.
4:22We can also take a look at endpoints,
4:26and we have cloud applications, and other types
4:32of Defender products.
4:33But the idea behind Microsoft Defender
4:35is there are several products that we have.
4:38And we're going to touch on some of those here shortly,
4:40things like Defender for Endpoint, Defender for Cloud,
4:43Defender for Office 365, Defender for Identity,
4:45Defender for Cloud Apps.
4:46All of these things they're going to be lining up in here.
4:50And Microsoft Defender really is a unified detection
4:53and response platform.
4:54The idea being-- unified means it
4:57takes all of these different Defender products over here,
5:01and it helps us to kind of put them into one dashboard
5:03that we can begin working with.
5:05Now, this is still in the works, I want to say,
5:07because as I jump back in from time to time and work with it,
5:10I see that there are more of the Defender apps
5:12that are showing up in here.
5:14So the idea, though, is Microsoft Defender, as a whole,
5:17has a bunch of subapplications or services or tools.
5:20And the idea is, we want to put those into a single portal
5:23here.
5:24So let's talk about some of these individual Defender
5:25tools.
5:26First off, we have Defender for Cloud.
5:29I like that Defender.
5:30Defender.
5:31So Defender for Cloud provides us XDR capabilities.
5:37And XDR, this part here, the DR is Detection and Response.
5:42The idea is, we can use it to detect something and send off
5:45an alert.
5:46You know, something's going on here.
5:48And then response is, it allows us
5:50to use the portal to respond to things, to do certain actions.
5:54This X just means whatever you can come up with thing.
5:57So XDR.
5:59So that could be Cloud Detection response, Endpoint Detection
6:02and Response, Office Detection and Response.
6:04The list goes on and on and on.
6:06But the idea with Defender for Cloud
6:09is that it allows us to provide detection and response
6:14for Azure resources.
6:16So we're really focused on Azure here.
6:19That Azure resources, things like Azure Active Directory
6:23and Azure VMs, and other Azure services.
6:28So this could be Linux and Windows VMs, networks,
6:31Kubernetes, containers, SQL, storage, IoT.
6:34We're really focused on Azure services.
6:38So if you've got Azure services you're wanting to protect,
6:40take a look at Defender for Cloud.
6:42Next up, Defender for Endpoint.
6:46Now, when it comes to endpoints, of course,
6:47we're talking about our endpoints
6:49our users are using out there.
6:51This is formerly known as Defender ATP.
6:55So this provides Endpoint Detection and Response,
6:58which is EDR.
7:01So that's our detection and response again for endpoints.
7:04It provides us some threat and vulnerability management,
7:07automated incident investigation or remediation,
7:10which is really cool, and more for Windows, Linux, iOS,
7:15and Android.
7:15So there you go.
7:16So you've got your Windows, you've got your Linux,
7:20you've got Android, and, of course, iOS.
7:25So you can use Defender for Endpoint
7:27on all these operating systems.
7:29Next we have Defender for Office 365.
7:32So again, this is detection and response services
7:34for Office 365.
7:37So this includes capabilities such as sandbox detonation.
7:42So sandbox detonation-- if there is a suspicious file that
7:47comes in maybe, well, what it can do
7:49is it puts that file into a sandbox,
7:51detonates it, and analyzes to see if that file is malicious
7:55or not.
7:55It does that for us automatically.
7:57It also provides integrated threat intelligence,
8:00attack simulation and more.
8:02And this is across our email, our SharePoint-- so let's
8:05put up there email, SharePoint, OneDrive,
8:09all of those services there.
8:12So that's where that Defender for Office 365
8:14really comes into play.
8:16So next we have Defender for Identity.
8:20So this is Microsoft Defender for Identity formerly Azure
8:24ATP.
8:25This detects on-premise identity attacks.
8:28So and, of course, not just on premise but in cloud as well.
8:31But either way, on-prem--
8:33so I'm going to put that up here.
8:34That's really important because that's on prem and, of course,
8:37in cloud.
8:38But what we're looking for is identity attacks.
8:41Because we know that we have adopted the zero trust.
8:45And we know that the identity is the new edge of our networks
8:49and our services.
8:50Whether, it's on prem or in the cloud, when
8:52we want to protect our identities,
8:54we need to look at Defender for Identity.
8:57And it uses behavioral analysis and specific detections
9:02for things like pass the hash, Kerberos tickets attacks,
9:06password attacks, golden ticket skeleton key,
9:09all kind of different attacks.
9:11So that's what it's good for.
9:13So if you're looking to protect your identities,
9:15whether on prem or in the cloud, look at Defender for Identity.
9:19And then we have Defender for Cloud Apps.
9:23Now, cloud apps are apps that reside in the cloud, right?
9:26Of course but not only Azure.
9:28We're talking everywhere.
9:31So whether your cloud apps are Salesforce--
9:34that's not Microsoft, right?
9:36Or maybe you got something that's
9:37out there that's an HR platform or another accounting
9:40platform somewhere in the cloud-- doesn't matter.
9:42If it's cloud-based, you can protect it
9:45with Defender for Cloud Apps.
9:46And Defender for Cloud Apps provides us
9:49that detection and response capabilities
9:51for all of our APPs that are out there, our SaaS applications.
9:56It also helps us to address shadow IT.
10:00Now, shadow IT is where the folks in our organization
10:04might try to sidestep IT and do their own thing-- sign up
10:07for applications, and use them outside of IT, management,
10:10and governance.
10:11Well, you know what?
10:11We can address that with Defender for Cloud Apps.
10:15And that's because Defender for Cloud Apps is actually a CASB.
10:19And that is a Cloud Access Security Broker
10:22which becomes kind of basically a proxy for all of our cloud
10:26apps.
10:26So the idea is we have users that are all over the world,
10:29possibly.
10:30But when they're using endpoints that
10:32have Microsoft Defender on them, then it actually
10:37sends that information through the proxy
10:39before it goes out to the various cloud apps
10:43so that we can see what's going on.
10:46And that's the kind of where the CASB becomes into play.
10:49But this way we can say, nope, you can't use that application.
10:54Absolutely not, that's not something we want to allow.
10:56That's how we address that shadow IT.
10:58But we can also set up policies around various applications
11:04that are out there, various SaaS applications, that is.
11:07So when you're looking to address SaaS application
11:10security, wherever it might be, look
11:12to Defender for Cloud Apps.
11:14And lastly, I want to just do a quick security operations
11:17and what security operations is all about.
11:20It's all about fast detection and response.
11:25So we're using all of those Defender products,
11:28and we're using Sentinel, and we might end up
11:30using a threat experts and our DART detection and response
11:34teams.
11:35And we're going to use all of those tools
11:38in our operations toolbox in order to provide fast detection
11:43and response.
11:43So we can minimize the impact that an incident
11:45has on our organization.
11:47And that's where security operations shines.
11:49And these are the tools that we use to do that.
11:51I hope this has been informative for you.
11:53And I'd like to thank you for viewing.
SaaS & Identity Protection
0:00[AUDIO LOGO]
0:06Within our cloud environments, our identity
0:09is now the edge of our networks.
0:12And it's not just our Azure environments, but also
0:14our SaaS applications wherever they may reside.
0:18And that's why it's so important that we
0:20protect those SaaS applications and our identities.
0:23So let's jump in and take a look and see
0:26what the Microsoft Cybersecurity Reference
0:28Architecture says about SaaS and Identity Protection.
0:32All right, here we are taking a look at the Cybersecurity
0:34Reference Architecture.
0:36And what we're going to be focusing on here
0:38is our SaaS environment, as well as
0:42some of our identity protection.
0:45So let's get started.
0:46First off, protecting our SaaS Defender for Cloud Apps.
0:49We've talked about Defender for Cloud Apps before,
0:51but I want to bring it back up because it's very important.
0:54When you're looking to protect your Software as a Service
0:58application-- your SaaS apps--
1:00then, you want to use Defender for Cloud Apps.
1:02So if you're charged with coming up with a solution
1:05to protect your SaaS applications,
1:08and you're in the Microsoft environment,
1:09you've already got a foothold in there,
1:11look to use Defender for Cloud Apps.
1:14And also, another thing I want to point out and bring up again
1:18about Defender for Cloud Apps is if you're
1:20looking to address shadow IT, well, guess what?
1:26This is going to help you do that when
1:28it comes to your application, specifically your cloud
1:31applications and controlling what applications
1:34your users can use.
1:35So Defender for Cloud Apps.
1:37Next up, identity and access.
1:39We need to protect our identities
1:41because they're the edge of our cloud environments.
1:44So how can we go about doing it?
1:46Well, when it comes to your Microsoft environments,
1:49we have a couple of options.
1:51Number one, conditional access policies.
1:54So we can use our conditional access
1:56because it provides centralized policy control for data
2:00and applications by enforcing conditions
2:03that we create based on account authentication, network
2:06location, device health, and compliance
2:08and various other risk factors.
2:10So we can use conditional access for the first part.
2:15The second part down here, well, we
2:17need to look at passwordless and MFA.
2:21So protecting identities, the first couple
2:23of things we want to address conditional access secondly
2:26passwordless and MFA.
2:28Now Azure MFA helps safeguard access to our data and our apps
2:33while making sure that it meets our user
2:36demand because it's simple sign on.
2:39So we can use the Azure application
2:44to provide that MFA.
2:45So it's just a button push, very simple.
2:48And of course, it delivers strong authentication
2:50because it provides us a range of verification methods
2:53like phone calls, text messages, and, of course, our mobile app
2:57that we discussed.
2:59All right, what about within Azure AD.
3:01So when we're wanting to protect our identity within Azure AD,
3:06so how can we go about doing this?
3:08Well, there's some tools that we can use.
3:10The first tool is Azure AD Privilege Identity Management,
3:17a.k.a.
3:18PIM.
3:19So we could use PIM, Privileged Identity Management.
3:22And this allows us to manage, control, and monitor
3:25privilege accessing using approval workflows.
3:30And those approval workflows allow
3:33us to provide that just-in-time access as well.
3:36So when we're using PIM, we can allow people
3:39to escalate their privileges.
3:41And it goes through a workflow, so a manager approves it.
3:44And that's only available for a certain amount of time,
3:46maybe two hours or something.
3:47That way, they don't have these elevated privileges
3:50at all times, very handy.
3:53Next up is identity governance.
3:56And Azure AD identity governance allows us to balance out
4:00our organizations need for security and productivity,
4:04which is really important because we cannot have security
4:07impacting productivity if we can help it.
4:10And what governance does, it helps
4:11us to make sure that the right people have the right access
4:15to the right resources.
4:17So identity governance, very important.
4:19And then we also have identity protection.
4:22And Azure IDs identity protection
4:25provides us with a consolidated view
4:27into risk events and potential vulnerabilities
4:31affecting our organization's identities.
4:34And this is how we go about protecting
4:38our identities within Azure AD.
4:42Now I do want to spend just a couple of minutes talking
4:45about Defender for Identity.
4:47Now we did discuss it earlier, but I just really want to hit
4:50home with the idea that when we're looking to protect
4:53our identity, whether it's on-prem or in the cloud--
4:59it doesn't matter, either one--
5:00basically, what happens is we have Defender
5:02for Identity over here.
5:04And we send those on-prem security event logs
5:08and our in cloud security event logs
5:10into Defender for Identity.
5:12And what it does is it actually analyzes that data.
5:16It takes a look at it, and it's looking for what's going on.
5:21It's looking for advanced threats.
5:22It's looking for compromised identities
5:24and malicious inside user actions.
5:28It's looking for all these things.
5:30And it uses threat intelligence and various other resources
5:33to find things that are threats in your organization associated
5:38with identities.
5:39And at that point, it can help you to address them and send
5:43off flags, alerts that something is going on
5:47and allows you to then investigate and address
5:50and respond to those events.
5:52So that's your Defender for Identity.
5:53So that covers our SaaS Protection with Defender cloud
5:56apps, and of course, identity and access
5:59protection with Defender for Identity,
6:01and then, also our conditional access, passwordless,
6:04and MFA, our Azure AD PIM, identity governance,
6:07and Identity Protection within Azure AD as some of those tools
6:12were.
6:12So just keep those in mind.
6:14And that's how we take care of our SaaS and Identity
6:16and access security protection using tools
6:19from the Microsoft Cybersecurity Reference Architecture.
6:21I hope this has been informative for you,
6:23and I'd like to thank you for viewing.
Endpoints and Devices
0:00[AUDIO LOGO]
0:06We're now on to endpoint and devices.
0:09So as we continue with our Microsoft cyber security
0:11reference architecture, we're going to take a look
0:13and see tools it says we have to use
0:15for Microsoft for our endpoints and our devices.
0:20So here we are, we're seeing the cybersecurity reference
0:22architecture here, and we're focusing
0:24on our endpoints and devices.
0:27So let's jump in.
0:28Here we go.
0:29So Microsoft Endpoint Manager or MEM.
0:33That's what we're starting off with.
0:34And this enables us to manage and monitor various devices.
0:39So we've got mobile devices, that's
0:41number one, mobile devices.
0:43Number two, we have desktop devices.
0:46So we've got our desktops there.
0:48What about number three?
0:50Well, how about VMs?
0:52Absolutely.
0:53VMs we could also have embedded devices.
0:57And lastly, five, our servers.
0:59So we can use MEM or Microsoft Endpoint Manager
1:03to help us manage all of these devices.
1:07So really it covers all of our devices, right?
1:09Not just servers, and not just endpoints, not just desktops.
1:13So think about using MEM for management of all
1:17of these different devices.
1:19But there's also Intune.
1:21So our Microsoft Intune.
1:23Now this is a cloud-based service out there
1:26in our clouds.
1:27And it focuses on mobile device management.
1:30So mobile is key word here, mobile.
1:34So we're not looking at servers, we're not
1:36looking at embedded devices, we're
1:38looking at our mobile devices.
1:40But not just our devices.
1:42So devices, yes, but also applications.
1:46So it helps us to manage our devices.
1:48And what apps can be used on those devices.
1:53And Intune also integrates with Azure AD,
1:57which is very handy because it allows
2:00us to implement conditional access to provide
2:05device security health signals.
2:08So what that means is when we use conditional access
2:12policies, if a device is not healthy,
2:15meaning it doesn't have Defender for Endpoint installed
2:18or it doesn't have its updates installed,
2:20well, it might be considered not healthy.
2:22Or if it's accessing applications
2:24from outside the company network, all of those signals
2:27can be sent to conditional access,
2:29and can require users to provide additional security,
2:33such as MFA, in order to access these things,
2:36or maybe not be able to access them at all.
2:39But that's the idea behind Intune
2:42and its integration into Azure AD and conditional access.
2:47Then we have Configuration Manager.
2:49Now this is a little bit different.
2:50This is dealing with specifically configuration.
2:54So it provides security updates and other management
2:59capabilities for various endpoints.
3:03But the idea is we're dealing with specific configurations.
3:07And that's Configuration Manager.
3:09Then we come across Defender for Endpoint once again.
3:12And again, this is providing us that detection and response
3:16capability for our endpoints.
3:19And also provides us with threat and vulnerability management.
3:23And automated incident response and remediation
3:28for our endpoints.
3:30And again, this runs on Windows, Linux, Android, iOS,
3:37all of these here.
3:38So that's our Defender for Endpoint.
3:40And then lastly, I want to talk about one more thing,
3:42and that's when we're dealing with Windows 10 and Windows 11,
3:45they have some additional security features
3:49built into them that helps us to protect
3:53against known and emerging threats
3:55across the spectrum of attackers and their attack vectors.
3:59Now the idea is if you're using your Windows,
4:03you want to make sure, of course, they are up to date.
4:07So they've got all their updates on them.
4:09And just remember that security is
4:12built into Windows 10 and 11.
4:14So the idea is in your environment,
4:16if you're really wanting to make sure that your endpoints are
4:19staying secure and you're deploying
4:21your Defender for Endpoint and you're doing your updates,
4:24you want to make sure that you are
4:25on a recent version of the desktop operating system.
4:30And that is the Microsoft cyber security reference
4:33architecture, and how it relates to endpoints and devices.
4:37I hope this has been informative for you,
4:38and I'd like to thank you for viewing.
Hybrid Infrastructure
0:06Now we're on to Hybrid Infrastructure.
0:09So we're talking about our Infrastructure
0:10as a Service, our Platform as a Service,
0:13and/or our On-Premise all working together
0:17as one infrastructure.
0:19That being said, we need to understand what the Microsoft
0:21Cybersecurity Reference Architecture says about what
0:24tools and services we can use to protect
0:27our hybrid infrastructures.
0:29So let's take a look.
0:30All right, here we are.
0:31We're looking at the cybersecurity reference
0:33architecture diagram about all the services
0:36and tools we can use.
0:37And we're looking here at the hybrid infrastructure piece
0:41right there.
0:42So let's get started.
0:43Starting off, Defender for Cloud.
0:45Now, we had talked about this briefly before.
0:47And again, Defender for Cloud is about protecting your Azure
0:52resources.
0:53So this isn't for protecting on-premise.
0:56It's protecting your Azure resources.
0:59So we're talking here about our virtual machines that we're
1:03protecting and various other services, our networks,
1:07all kinds of things like our Kubernetes clusters.
1:10We're talking about SQL and storage services.
1:14All these things and then our IoT even.
1:17We're looking at protecting all of these services
1:20with Defender for Cloud.
1:22Now, something else we can take a look at is Secure Score.
1:25Now, Secure Score is a security center tool that continually
1:31assesses our resources, our subscriptions,
1:34and our organization for any security issues,
1:36and then it aggregates all of that
1:38into a single secure score.
1:42And by looking at that score, at a glance
1:44you can tell how you're doing in your current security
1:48situation.
1:49And the higher, the score, the better you're doing.
1:52So that's Secure Score.
1:53It's just a quick, down and dirty grade
1:56of how you're doing with security in your environment.
2:00Next up, our Compliance Dashboard.
2:03Now, when it comes to our Compliance Dashboard,
2:05we're talking about regulatory compliances.
2:08So these could be things like NIST and CMMC
2:11and PCI and HIPAA and SOX and all kinds
2:15of different regulatory compliances.
2:17But it helps provide insight into your security compliance
2:22posture, and it provides a set of supported standards
2:26and regulations based on a continuous assessment
2:29of Azure environment.
2:31So basically you go in there and you tell it
2:33which regulatory compliances you're working with,
2:35and then it can help you to see how you're
2:39doing as far as compliance towards a specific standard
2:43or standards.
2:45And next up, we have Azure Firewall, the Firewall Manager,
2:49and Azure WAF.
2:50And I group these together.
2:52Now, these are what we would call native resources
2:56because they reside in Azure.
2:58They're tools that are there that we can use.
3:00Now, we may have to pay subscription fees
3:02for them or licensing, but they are there.
3:05Now, Azure Firewall is a managed cloud-based network security
3:09service, and it protects our Azure virtual networks.
3:13So when we've got our Azure environment
3:16and we've got our VMs and we've got our networks
3:19and we've got our various services we're using,
3:22we can use the Azure Firewall to help protect those.
3:27Now, the thing is this is a stateful firewall, which
3:30is very important because it watches
3:32the state of communications between endpoints.
3:35So if it sees a connection come in and it's allowed,
3:38it's going to allow the response to go back out.
3:41And that's what the stateful part of that means.
3:43Now, one of the great things about this,
3:46it has built-in high availability
3:49so the service is running in multiple instances.
3:53So you have your high availability there,
3:55but you also have unrestricted cloud scalability.
4:00So as you have more traffic coming through the firewall,
4:03it's going to automatically scale to address your needs.
4:07And you don't have a bottleneck--
4:08that's pretty darn cool.
4:10And that is also the Firewall Manager.
4:13That's how we manage the Azure Firewall.
4:15But then we have Azure WAF, and this is a Web Application
4:19Firewall.
4:20So that means it is a firewall specifically
4:24tuned to web applications, and that
4:27means the HTTP protocol and, of course, the secure version
4:31as well.
4:32[CHUCKLES] How about that?
4:33All right, so why would you want to use a WAF, or a Web
4:37Application Firewall?
4:38You want to protect a web application.
4:41And this provides centralized protection of your web apps
4:44for many of the common exploits, so we're
4:46talking like SQL injection, cross-site scripting attacks,
4:51and a whole bunch of other different types of attacks
4:54that are located in the OWASP set of rules.
4:59And so that's what that is for.
5:00So basically it's a firewall that speaks or understands
5:04HTTP protocol, and it will watch the different commands going
5:10back and forth between the application
5:12through the firewall.
5:13And if it sees something that's an attack,
5:15it's going to stop it.
5:17So there you go.
5:18That's your Azure Firewall and Azure WAF.
5:20Next up, we have DDoS Protection.
5:23Now, when it comes to DDoS Protection--
5:24these are Distributed Denial of Service Protection-- well,
5:27the idea is we want to prevent it
5:29from happening because it's going to eat up our resources
5:31and cause us outages.
5:32Now, Azure natively provides basic DDoS Protection
5:36for all of its public IP.
5:38So there is basic protection by default,
5:41and you don't have to pay extra for it.
5:44It's already there.
5:45However, you can't do any kind of tuning.
5:48So if you want to increase your protection by using tuning
5:54and things like real-time and historical telemetry
5:58and alerting and cost guarantee and more--
6:01so we'll say plus features because there's
6:03a lot of features-- well, then you're
6:05going to want to go ahead and purchase
6:08the standard version to get these additional features.
6:13The basic version is free, and it's just a very simple DDoS
6:17Protection.
6:17But if you're looking for advanced DDoS,
6:19you're going to need to purchase that standard protection.
6:22All right, next up, we have the Azure Key Vault.
6:25Now, Key Vault helps us to mitigate
6:27risk of compromised secrets.
6:30So those are when we have a secret that has,
6:33well, been compromised.
6:34It's been leaked or it's been figured out or found out
6:37where keys or secrets may have inadvertently been published
6:41to places like GitHub.
6:43And, well, what this does is it ensures
6:45that they're safeguarded by Hardware Security
6:48Modules, or HSMs, and readily available
6:53to various applications.
6:54So when you're looking to protect
6:55your secrets and your passwords and your certificates and keys,
7:00you're looking to protect them with Azure Key Vault.
7:04Next up, we have Azure Bastion.
7:06Now, Azure Bastion provides secure and seamless RDP/SSH
7:10connectivity-- so let's put that up there, RDP and SSH
7:14connectivity-- into Azure resources, specifically
7:18your Azure virtual machines.
7:20And it provides this RDP and SSH connectivity
7:23into your virtual machines directly
7:25from the Azure portal over TLS so it
7:30is encrypted communication.
7:32So when you connect to your Azure Bastion,
7:35your virtual machines don't have to have
7:36a public IP address on them or an agent or a special client
7:39or anything.
7:40So the idea is, in your virtual network in here,
7:45you may have an Azure Bastion host.
7:48And the idea is this Azure Bastion host
7:52allows you to connect from the outside.
7:54So you could be on-premise or something
7:56and you connect in via RDP or SSH
7:59into this Azure Bastion host.
8:02And then from there, you can connect
8:05to various other resources and virtual machines and such
8:10that you have running.
8:11And then you can RDP or SSH into those,
8:15whether they're Microsoft or Linux or whatever.
8:17But the idea is then your VMs do not need a public IP--
8:22they only need that private IP-- and you're connecting
8:24through this bastion host.
8:26And, of course, you're going to set up some security group
8:28rules around which IPs can connect to this bastion host.
8:31You don't want to leave that open to the world, of course.
8:34That would be bad.
8:35So that's your Azure Bastion host.
8:37Next up, Azure Lighthouse.
8:39Now, Azure Lighthouse enables cross-
8:42and multi-tenant management.
8:46So this allows for higher automation, scalability,
8:49and enhanced governance across resources and tenants.
8:53So when you are working with multiple tenants--
8:55maybe you are a service provider and you could provide,
8:59I don't know, security services, all kinds of services--
9:01but the idea is you have your tenant up here
9:04and you actually are able to manage other tenant's
9:08resources, well, you could use Azure Lighthouse in order
9:11to do that.
9:12So keep that in mind.
9:13Next up, Azure Backup.
9:15So with Azure Backup, we're protecting against disasters
9:19and ransomware attacks with simple and reliable
9:22cloud-integrated Backup as a Service.
9:25And that's what Azure Backup is.
9:27Its Backup as a Service, and it provides us
9:29with site recovery that can protect Hyper-V, VMware,
9:34and physical servers so you can use
9:36Azure as your secondary data center for your recovery site.
9:40So this is helpful for not only cloud
9:43but on-prem for disaster recovery services as well.
9:48Next up is Azure AD App Proxy.
9:51So this is something that's also referred to as Beyond VPN.
9:57So when we're looking to go beyond simply using VPNs
9:59to access resources, well, Azure Active Directories Application
10:05Proxy provides a secure remote access to on-premise web apps.
10:09So the idea is you may have-- let's put on-prem down here--
10:13on-prem and you've got a server that's
10:16running a web app on here.
10:19There we go.
10:20Excellent
10:20Now, what you can do is basically
10:22this app proxy lives up here in Azure,
10:25and you configure the app proxy to point to and connect
10:28to that web app on premise.
10:31So once you set all this up, then your users
10:34connect here to the cloud.
10:36So they can access it from anywhere,
10:39and you don't have to use a VPN.
10:40It's all done securely through the use of the Azure AD App
10:43Proxy.
10:44So again, if you're looking for security services to provide
10:47secure access to an on-premise web applications and you want
10:51it to be accessible from anywhere but you really want
10:53security-- you don't want to use VPNs--
10:55you're looking to use Azure AD App Proxy.
10:59Next up, we have Express Route and Private Link.
11:03Now, these are two different solutions.
11:06Express Route is designed to connect
11:08your on-prem environment into your Azure resources.
11:15So that's how that works.
11:17Basically, you go through and configure it.
11:19We're not going to get into the details.
11:20But if you're wanting to connect on-prem into your Azure
11:24resources with something other than a VPN,
11:27you want to look at Express Route.
11:29Now, Private Link is a bit different.
11:31Now, the idea behind a Private Link
11:34is that you have your virtual network here.
11:38There we go.
11:39And you've got some VMs spun up in there.
11:41Excellent.
11:42And you've got some PaaS services over here,
11:46like you've got maybe some SQL services or some storage,
11:51whatever it might be.
11:52When you have these PaaS services,
11:55they have a public IP address that you
11:59use to connect to them.
12:00So you would connect via the public IP into here.
12:03Well, that's not always the best because then you
12:06have a public IP involved, and there
12:08could be some misconfigurations so it's opened up and exposed
12:11to the world.
12:12We want to try to avoid that.
12:13So what can we do?
12:15Well, let's remove these here, we could use a private link.
12:19What that does, it gets rid of the public IP that
12:22provides a connection from your virtual network
12:26to your PaaS service over private IP addresses
12:32in the Microsoft backbone so that way there
12:35is no public IP addresses involved,
12:37keeping it more secure.
12:39And that's what Private Link does for us.
12:42Next up is Azure ARC.
12:44Now we're talking about hybrid infrastructure.
12:46So what if I have on-prem servers?
12:49There we go.
12:50This is my on-prem--
12:51hey, maybe I've got some AWS resources over here,
12:55maybe I've got some VM spun up, or over in GCP
12:59I got some VM spun up over there--
13:01and I want to integrate those into my management.
13:03Well, how can I do that?
13:05The answer is Azure ARC.
13:07That allows you to extend your management
13:09to resources in other cloud and your on-premise data centers,
13:13enabling consistent management and security across all
13:16these different platforms.
13:17And Azure ARC brings these resources into ARM
13:21so that you can use it to manage these various resources.
13:26So it connects everything in using Azure ARC.
13:30So if you're looking for hybrid infrastructure connectivity
13:32to manage with ARM, then you're going to want to use Azure ARC.
13:37Next up, Azure Stack.
13:39This is pretty cool.
13:40Now, the Microsoft Azure Stack is a hybrid cloud platform
13:44that lets you provide Azure services from your own data
13:47center.
13:48So if you have your own on-prem data center,
13:52or a data center that you have leased out
13:54space in so it's a "colo," then you
13:57can actually implement Azure services from within that data
14:02center using the Azure Stack.
14:05Pretty interesting.
14:07Next up is our Privileged Access Workstation, or PAWS.
14:13And PAWS is integral part of Privileged Access Security
14:17Strategy.
14:18Now, what is a PAWS?
14:19Well, it's a workstation that can
14:22be used by those with privileged access, so like admins,
14:26and these workstations do not allow for email--
14:30nope, no email-- or web access--
14:34nope, no web access.
14:35So basically it's like an internal-only workstation.
14:39It's very locked down, and it can only
14:42access your internal resources.
14:45So the idea is when you sign in here as an admin
14:48and do your work on the internal organizational asset,
14:52the idea is that we have greatly reduced
14:56the risk of this device being breached so that someone
15:01couldn't be sitting on there collecting credentials
15:04from admin.
15:05So the idea here is we're just really trying
15:07to reduce the risk of admin access being compromised.
15:12OK, next up, Microsoft Secure Score.
15:16And we have talked about secure score before.
15:18Again, this is a measurement of your organization's security
15:22posture.
15:24And it's designed to help you quickly
15:25see just how well you're doing within your Microsoft
15:30environment and security.
15:32It also provides recommendations on how to improve your score.
15:36And then lastly, Microsoft Compliance Score.
15:39Again, this is another way to help you quickly
15:43see how you're doing with compliance
15:46within your Microsoft environment.
15:48And this is done through the Compliance Manager,
15:51and you go in and you define which compliance
15:54you're dealing with.
15:55Is it something like NIST or CMMC or SOX or HIPAA or PCI
16:02or something else.
16:03Whatever it might be, define what
16:04it is that you're trying to comply with,
16:06and it will then help you assess your compliance.
16:09So it's pretty darn cool.
16:10So these have all been tools and services
16:12that we can use to help design security
16:15solutions as a security architect
16:17for our hybrid infrastructures according to the Microsoft
16:22Cybersecurity Reference Architecture.
16:23I hope this has been informative for you,
16:25and I'd like to thank you for viewing.
Information Protection
0:06As a security professional, one of the things
0:08we're always trying to do is protect information.
0:11And we can't protect it if we don't know that it's there.
0:14So oftentimes, we have to perform discovery
0:16to identify where certain types of information is located.
0:19And then, sometimes, we'll label that information
0:22with some type of classification or something
0:24to help us identify what type of data
0:26it is so we know how to treat it.
0:28Well, guess what?
0:30Microsoft's cybersecurity reference architecture
0:33covers information protection, and that's
0:35what we're going to look at right now.
0:37All right, here we are in the architecture.
0:39And we're looking at Information Protection, this area
0:43right here.
0:43So with no further ado, let's jump in
0:46and get started with Microsoft Purview Information Protection.
0:52Now Purview is a unified data governance service,
0:57and it provides us with some great features that
1:00help us manage and govern our on-prem,
1:03multicloud, and SaaS data.
1:05That is important.
1:07So we're talking on-prem, we're talking multicloud--
1:12so GCP, AWS, doesn't matter--
1:15and, of course, our SaaS services as well.
1:20So it protects all of those, which is really cool.
1:23And the idea is it's a tool for governance.
1:26That's what it is.
1:27So governance is our management of our information
1:30and it's protection.
1:32So the way it does it is it uses MIP.
1:35That's our Management Information Protection,
1:40which is a built-in intelligent solution
1:44to protect sensitive data in documents and emails
1:48across our organization.
1:49So it uses MIP.
1:50It also uses data governance, which really
1:54is what it is a tool for.
1:55It provides us with that data governance capabilities
1:59that allows us to manage the lifecycle of our data.
2:04So from data creation to discovery to labeling
2:08to destruction-- the whole life cycle--
2:11it allows us to manage that through Purview.
2:14And then, it also provides us with some eDiscovery features
2:20that helps us simplify that eDiscovery process
2:24and help us to analyze unstructured data within Office
2:27365 and review documents and to find those documents whenever
2:33we need to go out and identify what
2:36we have in our organization.
2:37So it will go out there and it will scan your organization
2:41and look for documents that contain certain types
2:44of sensitive data.
2:47And it will show you where it lives,
2:48and it will let you manage its life cycle.
2:51So that's what Purview is used for.
2:53Really, the idea is if you're wanting
2:55to implement some type of governance solution
3:00that protects on-prem, multicloud,
3:02and your SaaS applications' data,
3:04you're wanting to implement Purview.
3:09Next up is the Azure Information Protection-- that's the AIP--
3:14Unified Labeling Scanner.
3:16Now what this scanner does it helps
3:17you to discover, classify, and protect files
3:20on UNC paths for network shares over SMB
3:26and on SharePoint servers for on-premise data.
3:32So what we do-- in our on-prem network,
3:35we can deploy this Unified Labeling Scanner.
3:39And once we do that, it can go out
3:42over UNC paths and SharePoint servers and look at the data.
3:47And it scans the data and it looks
3:49for sensitive information.
3:51And then it provides you with a list
3:54of where this sensitive information resides
3:56in on-premise network.
3:58So that's really cool.
3:59And that actually feeds into Purview,
4:03which we just discussed was a governance solution.
4:06And this is how it helps identify
4:09where your sensitive data is located
4:11in your on-prem environments.
4:13And lastly, we have Compliance Manager,
4:16and this is another part of Microsoft Purview.
4:19And it provides a Compliance Manager dashboard
4:22that helps you to achieve your compliance goals.
4:24And it helps you to evaluate cloud workloads
4:27against your compliance requirements, whatever
4:29they might be, as well as protection standards.
4:32It allows you to assign, track, and record
4:37compliance and assessment-related activities.
4:41So if you have an assessment that's coming up,
4:43you can assign the assessment, and then
4:46the person can upload the information,
4:48and basically, you can track that process of the assessment
4:52or any other type of activities that you want
4:56to create towards compliance.
4:58So that is your Compliance Manager.
5:00So those are some of the tools we can
5:02use for information protection.
5:03And we really focused on governance
5:05with Microsoft Purview and its AIP Unified Labeling Scanner
5:09for identifying on-prem sensitive information
5:13and using Compliance Manager to help
5:15you maintain your compliance.
5:16I hope this has been informative for you,
5:18and I'd like to thank you for viewing.
IoT and Operational Technology (OT)
0:00[AUDIO LOGO]
0:06Now we're on to IoT and operational technology, which
0:11includes industrial control systems.
0:13Now, how can Microsoft help us protect these things?
0:17Well, that's what the Microsoft Cybersecurity Reference
0:19Architecture is going to help us figure out.
0:23So let's get started.
0:24All right.
0:25Here we are.
0:25We're in our architecture, and what we're doing
0:28is we're looking down here at IoT in this area right
0:34here, IoT and OT, which includes our Industrial Control
0:37Systems, or ICS.
0:40So let's see what we can do.
0:42First off, Azure Sphere.
0:45Pretty interesting here.
0:46Now, what this does, it provides us an end-to-end solution
0:49to secure new IoT devices.
0:52So we're really looking to secure IoT devices
0:57with Azure Sphere.
0:59And it does this with a special hardened Linux operating
1:05system.
1:06And that is the first part of the Azure Sphere.
1:10Now, the second part is certified microcontrollers.
1:14So let's put that over here.
1:16And these microcontrollers have been certified as to basically
1:20being securely built. And then Azure Sphere
1:23provides us with a security service
1:26because we have to have some type of service to communicate.
1:29So we have a secure service that will allow the communications
1:34between devices, and it provides us
1:37the seven properties of highly secure devices as a whole.
1:43So when you combine these three things, which
1:47are the Azure Sphere, or hardened Linux OS,
1:50and that's running on a certified secure
1:52microcontroller connecting to a secure service provided
1:56by Azure, then you have a secure IoT environment.
2:00And that's what we're looking to achieve.
2:02Next up, we have Azure defender for IoT.
2:06Now, this offers agentless.
2:10And that's pretty important here.
2:11Agentless, so we don't have to deploy agents
2:14to all of our IoT devices.
2:16And it provides an agentless network layer security
2:21service that is rapidly deploy, and it
2:24works in various industrial environments,
2:27and it interoperates with the Azure Sentinel and other SOC
2:30tools.
2:31So this is a network layer security service
2:33that runs and basically watches the communications that's
2:37taking place.
2:38And it's looking for oddities.
2:40And it's sending those events that it
2:44sees, it's sending those into other security services,
2:48such as Azure Sentinel and other SOC tools that you can use,
2:54to feed into your normal, everyday security operations.
2:59And that's what Azure Defender provides for us.
3:02It allows us to feed the IoT security information
3:06into our SOC tools.
3:08Pretty darn handy for protecting IoT.
3:11And lastly, Defender for Cloud, which we've
3:14talked about multiple times.
3:16And again, that is used to protect what?
3:19Think about it.
3:20Think about it.
3:20And that's right, Azure Resources.
3:23So we're talking about our Azure VMs, our networks, Kubernetes,
3:27containers, SQL storage, IoT.
3:30That's right.
3:30That's where it feeds into, our IoT,
3:34and helps us to protect it.
3:35So there you go.
3:37That's how we can protect our IoT and operational technology
3:41devices, according to the Microsoft Cybersecurity
3:44Reference Architecture.
3:45Hope it's been informative for you,
3:47and I'd like to thank you for viewing.
People Security
0:00[AUDIO LOGO]
0:06It's time for people security in the Microsoft cybersecurity
0:11reference architecture.
0:12Now, what could people security be?
0:14Well, it's security dealing with people.
0:16People are something we deal with every day in security.
0:20So we're talking about security training, maybe
0:22some phish testing, also insider risk
0:25is a big problem these days.
0:28So let's take a look and see what the Microsoft
0:30cybersecurity reference architecture has
0:32to say about people security.
0:35All right.
0:35Here we are in our architecture.
0:36What we're looking at down here in the bottom right.
0:39Down here.
0:40We're looking at people security.
0:43So let's get started.
0:43There's just a couple in here.
0:45So first off, Attack Simulator.
0:47This is really cool.
0:48And it is a tool within the Security and Compliance Center
0:54that helps us to run realistic attack
0:57scenarios against our users to see how they do.
1:04And oftentimes, this is done through phishing campaigns.
1:08So we do like to run phishing campaigns,
1:10and that's one of the tools that we
1:12can run when we're running these attack scenarios using
1:16the Attack Simulator.
1:18Pretty darn cool because we provide security training
1:20to our folks.
1:21Well, this is a way that we can then see how well
1:24that they absorb that training and we
1:26can provide additional learning through these simulated
1:30attacks.
1:31Next up, insider risk management.
1:35Now, this is within Microsoft 365.
1:39And what it does, it helps to minimize internal risks
1:42by enabling us to detect, investigate,
1:45and act on malicious and inadvertent activities
1:48in our organization.
1:49So what we can do, we can go into the Insider Risk
1:52Management, and we can set up rules
1:55to watch for certain types of things happening.
1:58Maybe, we create a rule that says,
2:00if anybody uploads more than 2 gigs of data
2:06within a 24-hour period, send off an alert.
2:10Raise the flag and say something's going on.
2:13So it's rules similar to that.
2:15So it just helps us to identify insider risks
2:19by certain types of activities that are happening.
2:22And it reports on them so that we can then investigate.
2:25And then lastly, we have communications compliance.
2:29Now, this is a little different.
2:30This is an insider risk solution within Microsoft 365,
2:34and it helps us to minimize communication risk.
2:38And it helps us to detect, capture,
2:41and act on inappropriate messages
2:44within the organization.
2:45Now, a lot of times, this comes down to dealing with HR
2:50because this is more about inappropriate communications
2:55between internal users.
2:58Such things as harassment and things like that.
3:01But it does feed into security as well
3:04because we can use it to help identify insider risk.
3:08So those are three tools according
3:10to the Microsoft cybersecurity reference architecture
3:12that Microsoft provides us with when
3:16working with people security.
3:18I hope this has been informative for you,
3:20and I'd like to Thank you for viewing.
Other Resources
0:00[AUDIO LOGO]
0:06All right, it's time to wrap up the Microsoft cyber security
0:09reference architecture series here that we're working with.
0:13And what we're doing is we're going
0:14to look at some of the other tools that
0:16are out there and available that don't really
0:18fall into a specific category.
0:21So let's get started.
0:23All right, we're starting off here with the GitHub Advanced
0:26Security.
0:28Now what this is, this is for your DevSecOps and application
0:34development security.
0:36And it integrates natively in the developer's workflow,
0:40including things like code scanning
0:43to make sure that there are not vulnerable code being used
0:47or vulnerable plugins or something
0:49being used within the code.
0:50It also provides secret scanning.
0:53So it's looking for any secrets or passwords
0:55or keys that might be left in the code left over
0:59from testing.
1:00It also provides alerting if it finds these things.
1:03So it didn't just record it, not notify.
1:06It also allows you to create security policies and much
1:10more.
1:10But the idea is it allows you to-- within your DevSecOps
1:14pipeline, introduce all of these additional features when
1:19you're integrating within GitHub's advanced security.
1:23So that's pretty handy for your development folks.
1:26Next up, threat intelligence.
1:28And of course, threat intelligence
1:29is intelligence about things that
1:31are going on out there in the cybersecurity world.
1:34And it provides things known as IOCs or Indicators
1:38of Compromise.
1:39These might be IP addresses, URLs, email addresses,
1:43file signatures, all these different things that have been
1:46known to be part of attacks.
1:48And Microsoft processes, believe it or not, over 8 trillion.
1:52I'm going to write that down.
1:53It's really impressive, 8 trillion signals every day.
1:58And it offers insight into what is
2:01a normal baseline of activity.
2:03And then potentially anomalous behaviors and verified attacks.
2:07And it help us provide high quality detection
2:10by filtering out those false positives, which
2:14take up too much of our time.
2:16And that's what threat intelligence does, provides us
2:19with all that intel, and it feeds into the Microsoft
2:23security services.
2:23So when you're using those security services,
2:25they are receiving this threat intelligence.
2:28Next up is a Service Trust Portal.
2:31Now what is this?
2:33Well, what it is, it allows you to go in and look
2:37at audit reports that were done against the Microsoft services
2:42and environments.
2:44And this way, you can see the audits
2:46that are taking place within the Microsoft environment
2:49to see just how secure they are within their environment
2:52and their practices.
2:54So when you're looking to select a cloud vendor,
2:57oftentimes you're looking at certain types of audits.
3:00Maybe it's a SOC 2 audit, or maybe it's
3:03some type of missed audit.
3:05Well, you go to the Service Trust Portal,
3:07and you're going to have access to all of those audit reports.
3:11Next up, SDLC.
3:13And this really isn't necessarily just Microsoft.
3:16It's within development everywhere.
3:18But the idea is you need to be aware of what the SDLC is.
3:22It's a security development lifecycle.
3:24And this is a development process.
3:27And it helps developers build more secure applications.
3:31That's the idea behind it.
3:33And within the SDLC, the whole life cycle, as you can see,
3:38it is a cycle here.
3:39And you go through various steps within the cycle
3:42to make sure that your development is
3:45following standards.
3:47And it helps us to address security compliance
3:49requirements while reducing development costs.
3:52So just be aware of the SDLC, and that you should be using it
3:55in your development lifecycle.
3:58Next up, Azure Confidential Computing.
4:01Now this service here, this feature
4:04is when data is processed in a hardware-based trust execution
4:09environment.
4:11So the unauthorized individuals cannot access the data during
4:16the processing.
4:17So this all takes place within the processor.
4:21It's really just a way to further guarantee
4:23confidentiality in a shared hardware environment.
4:27So that's what Azure confidential computing
4:30provides for us.
4:32All right, next up is Graph Security API.
4:35And this is really nice.
4:36And what this is, it's a unified interface and schema across
4:41all the Microsoft security products.
4:43So this allows you to build your own applications that
4:46directly integrate into your security efforts.
4:50So really, it just says that within all of those Microsoft
4:55security products, they all speak the same language.
5:00Just put it, it's kind of a generalized example of this.
5:04But the idea is they all speak the same language.
5:06So if you write your own app over here
5:09and you tell it how to speak this language,
5:12then you can integrate it.
5:13And you can access the data from various Microsoft tools
5:17that you're using.
5:18And that's what that Graph Security API does for us.
5:22Next up, we have shielded VMs.
5:25Now a shielded VM uses a virtual TPM--
5:29and a TPM is a Trusted Platform Module,
5:33and it's encrypted using BitLocker.
5:36And can run only on healthy and approved hypervisor hosts
5:42within the fabric.
5:43So really it's an extra layer of protection to ensure that
5:46your VMs cannot be run outside the environment.
5:49So if you have a VM that you've created within the Azure
5:54environment, and somehow it's compromised,
5:57and somebody tries to exfiltrate that out of the Azure
6:02environment, and then try to spin it up
6:04on their own hypervisor, well, guess what?
6:07It's just not going to work because of that virtual TPM
6:10chip provided by the shielded VMs feature.
6:15So there you go.
6:16And then we have SQL encryption and data masking.
6:20Now SQL encryption and data masking,
6:22what it provides us with is Transparent Data Encryption
6:25or TDE.
6:27And it protects Azure SQL and Synapse
6:31by encrypting the data at rest and in motion,
6:35along with its associated backups and logs.
6:38So when you have your data at rest
6:41in a table within your database.
6:44And then maybe it's being shipped somewhere else.
6:46So a service can read what's in that database and process
6:50it, well, guess what?
6:52All of this that's taking place is encrypted,
6:57so that your data remains confidential.
6:59So that's SQL encryption and data masking.
7:03Next up, we have Microsoft customer lockbox.
7:07Now this is pretty cool.
7:08And this applies to Office 365.
7:12And what a customer locks box does,
7:15it ensures that Microsoft can't access your content
7:18to do service operations without your explicit approval.
7:23So if the Microsoft engineers over here
7:27who are working on some things-- we'll
7:29put MSFT Microsoft engineers.
7:31They're working on something, and they
7:33need to access your Microsoft Office 365 content in order
7:38to do something, well, they can't do it.
7:41You have put a lock around your data
7:46through that Microsoft customer lockbox.
7:48And they cannot access that data without your approval.
7:52So what happens?
7:53Well, then they send you a message
7:55saying, hey, we need your approval in order
7:58to access this and fix this or do whatever it is.
8:01And that's what that Microsoft customer lockbox does for us.
8:05And there's one more type of lockbox down here.
8:08And I'm going to write that right here.
8:09This is the customer lockbox for Microsoft Azure.
8:18Now if you can imagine, this provides
8:21an interface for customers to review and approve or reject
8:25customer data access request by Azure support engineers.
8:29And this one is specifically for Azure.
8:32Just like this one was for Office 365,
8:34this lockbox is for Azure.
8:36And it just makes sure that the Microsoft support engineers
8:40cannot access your data without your approval.
8:43So they provide you with a portal
8:45to go in and approve and see what these requests are all
8:48about, or you could deny the request as well.
8:51But the idea is that Microsoft engineers cannot access
8:53your Azure resources without your approval.
8:56So these have been some various other security tools
9:00and resources we can use as security architects
9:04to create solutions to protect our environment
9:07and meet our goals.
9:08I hope this has been informative for you,
9:09and I'd like to thank you for viewing.
Team training path
Turn this skill into assignable team training
This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.
$708
seat / year