Home
%3CLINGO-SUB%20id%3D%22lingo-sub-1032441%22%20slang%3D%22en-US%22%3EOffice%20365%20ATP%20%E2%80%93%20Ignite%20Recap%20and%20Product%20Updates%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1032441%22%20slang%3D%22en-US%22%3E%3CH1%20id%3D%22toc-hId-355677792%22%20id%3D%22toc-hId-355677792%22%3E%3CFONT%20size%3D%225%22%3EOffice%20365%20ATP%20%E2%80%93%20Ignite%20Recap%20and%20Product%20Updates%3C%2FFONT%3E%3C%2FH1%3E%0A%3CP%3EFollowing%20an%20incredible%20Ignite%20conference%20in%20November%2C%20I%E2%80%99d%20like%20to%20share%20a%20short%20summary%20of%20the%20product%20enhancements%20we%E2%80%99ve%20announced.%20Below%20you%E2%80%99ll%20find%20links%20to%20the%20full%20Ignite%20sessions%20as%20well%20as%20a%20few%20other%20helpful%20links%2C%20so%20please%20take%20a%20look!%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId-1046239266%22%20id%3D%22toc-hId-1046239266%22%3E%3CFONT%20size%3D%224%22%3EMisconfiguration%20causes%2020%25%20of%20phishing%20emails%20to%20be%20delivered%20to%20users%E2%80%99%20inboxes%3C%2FFONT%3E%3C%2FH2%3E%0A%3CP%3EAcross%20the%20Office%20365%20service%20we%20see%20that%20tenant-specific%20configurations%20cause%20discrepancy%20between%20potential%20effectiveness%20of%20our%20defenses%20and%20the%20realized%20effectiveness%20by%20organizations.%20Your%20security%20posture%20requires%20regular%20tuning%2C%20as%20historical%20settings%20become%20ineffective%2C%20new%20attack%20scenarios%20develop%2C%20and%20new%20controls%20need%20to%20be%20enabled.%20At%20Ignite%20we%20announced%20new%20recommended%20settings%20in%20both%20a%20standard%20and%20strict%20variant%2C%20so%20your%20organization%20can%20decide%20which%20configurations%20are%20best%20for%20your%20users.%20Check%20out%20the%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmicrosoft-365%2Fsecurity%2Foffice-365-security%2Frecommended-settings-for-eop-and-office365-atp%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Erecommended%20settings%20we%20just%20published%3C%2FA%3E%2C%20or%20try%20out%20the%20%3CA%20href%3D%22https%3A%2F%2Faka.ms%2Fgetorca%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3EO365%20ATP%20Recommended%20Configuration%20Analyzer%3C%2FA%3E%20(ORCA)%20in%20your%20environment.%20Be%20sure%20to%20watch%20our%20%3CA%20href%3D%22https%3A%2F%2Fmyignite.techcommunity.microsoft.com%2Fsessions%2F79719%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ebest%20practices%20breakout%20session%20at%20Ignite%3C%2FA%3E%20for%20plenty%20more.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId--761215197%22%20id%3D%22toc-hId--761215197%22%3E%3CFONT%20size%3D%224%22%3EReduce%20the%20burden%20on%20security%20operations%20teams%20by%20leveraging%20Automated%20Incident%20Response%3C%2FFONT%3E%3C%2FH2%3E%0A%3CP%3EToday%E2%80%99s%20security%20operations%20teams%20are%20drowning%20in%20alerts%20and%20need%20help%20responding%20to%20incidents%20in%20a%20rapid%20and%20efficient%20way.%20Office%20365%20ATP%20Automated%20Incident%20Response%20can%20dramatically%20improve%20the%20effectiveness%20of%20your%20organization%E2%80%99s%20security%20teams%20by%20addressing%20some%20of%20the%20most%20common%20threats%20through%20advanced%20automation.%20In%20September%2C%20we%20announced%20general%20availability%20of%20AIR%2C%20and%20at%20Ignite%20we%20showcased%20this%20capability%20and%20demonstrated%20its%20power.%20Read%20the%20%3CA%20href%3D%22https%3A%2F%2Fwww.microsoft.com%2Fsecurity%2Fblog%2F2019%2F09%2F09%2Fautomated-incident-response-office-365-atp-now-generally-available%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Eblog%20post%20from%20September%3C%2FA%3E%2C%20or%20watch%20the%20full%20%3CA%20href%3D%22https%3A%2F%2Fmyignite.techcommunity.microsoft.com%2Fsessions%2F79722%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ebreakout%20session%20from%20Ignite.%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId-1726297636%22%20id%3D%22toc-hId-1726297636%22%3E%3CFONT%20size%3D%224%22%3EGet%20a%20clear%20picture%20of%20users%20that%20may%20have%20been%20compromised%3C%2FFONT%3E%3C%2FH2%3E%0A%3CP%3EUtilize%20alerts%20and%20the%20investigation%20graph%20to%20identify%20suspicious%20user%20activity%20and%20possible%20compromise.%20View%20the%20Compromised%20Users%20report%20in%20the%20Security%20and%20Compliance%20center%20or%20take%20proactive%20measures%20such%20as%20outbound%20spam%20sending%20limits%20to%20curb%20post-compromise%20actions.%20Leverage%20the%20automatic%20investigation%20of%20compromise%20user%20alerts%20to%20assess%20the%20%E2%80%9Cblast%20radius%E2%80%9D%20of%20the%20compromise%20and%20reduce%20further%20impact.%20Read%20the%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FSecurity-Privacy-and-Compliance%2FSpeed-up-time-to-detect-and-respond-to-user-compromise-and-limit%2Fba-p%2F977053%22%20target%3D%22_blank%22%20rel%3D%22noopener%22%3Eblog%20post%3C%2FA%3E%20we%20released%20in%20November%20announcing%20the%20preview%20of%20this%20feature%2C%20and%20watch%20the%20%3CA%20href%3D%22https%3A%2F%2Fmyignite.techcommunity.microsoft.com%2Fsessions%2F79728%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Etheater%20session%20on%20account%20compromise%20from%20Ignite.%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId--81156827%22%20id%3D%22toc-hId--81156827%22%3E%3CFONT%20size%3D%224%22%3EEvaluate%20the%20effectiveness%20of%20Office%20365%20ATP%20in%20your%20own%20environment%3C%2FFONT%3E%3C%2FH2%3E%0A%3CP%3EThe%20full%20Office%20365%20ATP%20stack%20analyzes%20your%20mail%20traffic%20through%20a%20rigorous%20multi-step%20process%20to%20thoroughly%20assess%20and%20block%20malicious%20intent.%20This%20is%20why%20we%20firmly%20believe%20this%20is%20the%20best%20protection%20for%20your%20O365%20email%20and%20collaboration%20and%20we%20have%20data%20to%20prove%20it.%20Watch%20the%20%3CA%20href%3D%22https%3A%2F%2Fmyignite.techcommunity.microsoft.com%2Fsessions%2F79720%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3ESuperlative%20Protection%2C%20Unparalleled%20Intelligence%20breakout%20session%20from%20Ignite%3C%2FA%3E%20to%20learn%20more.%3C%2FP%3E%0A%3CP%3EWe%20also%20appreciate%20the%20desire%20to%20evaluate%20our%20stack%20for%20yourselves%20and%20encourage%20you%20to%20do%20so.%20Do%20not%20fall%20prey%20to%20inferior%20evaluation%20strategies%20(whether%20via%20a%20journaling%20rule%20or%20other%20methods%20that%20do%20not%20use%20real%20email%20traffic%20between%20real%20senders%20and%20recipients)%20that%20negate%20most%20of%20the%20Office%20ATP%20stack.%20We%20explain%20more%20in%20the%20session%20above.%20We%20understand%20the%20challenge%20involved%20with%20effectively%20evaluating%20the%20ATP%20suite%2C%20and%20so%20we%E2%80%99ve%20created%20a%20simple%20process%20to%20help%20address%20this%20problem.%20ATP%20evaluation%20mode%20can%20be%20set%20up%20using%20a%20quick%20four%20step%20wizard%20and%20is%20configurable%20to%20work%20with%20most%20routing%20scenarios.%20Watch%20the%20session%20above%20to%20learn%20more.%20This%20is%20currently%20in%20a%20private%20preview%2C%20but%20you%20can%20get%20access%20to%20this%20by%20contacting%20your%20account%20manager.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAs%20always%2C%20please%20check%20out%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmicrosoft-365%2Fsecurity%2Foffice-365-security%2Fwhats-new-in-office-365-atp%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3EWhat%E2%80%99s%20new%20in%20Office%20365%20ATP%3C%2FA%3E%20for%20the%20latest%20updates.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-1032441%22%20slang%3D%22en-US%22%3E%3CP%3EFollowing%20an%20incredible%20Ignite%20conference%20in%20November%2C%20I%E2%80%99d%20like%20to%20share%20a%20short%20summary%20of%20the%20product%20enhancements%20we%E2%80%99ve%20announced.%20Below%20you%E2%80%99ll%20find%20links%20to%20the%20full%20Ignite%20sessions%20as%20well%20as%20a%20few%20other%20helpful%20links%2C%20so%20please%20take%20a%20look!%26nbsp%3B%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F161527iCCA59D923267A5A1%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22atp.png%22%20title%3D%22atp.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1032441%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EMicrosoft%20Threat%20Protection%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%20ATP%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESecurity%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Microsoft

Office 365 ATP – Ignite Recap and Product Updates

Following an incredible Ignite conference in November, I’d like to share a short summary of the product enhancements we’ve announced. Below you’ll find links to the full Ignite sessions as well as a few other helpful links, so please take a look!

 

Misconfiguration causes 20% of phishing emails to be delivered to users’ inboxes

Across the Office 365 service we see that tenant-specific configurations cause discrepancy between potential effectiveness of our defenses and the realized effectiveness by organizations. Your security posture requires regular tuning, as historical settings become ineffective, new attack scenarios develop, and new controls need to be enabled. At Ignite we announced new recommended settings in both a standard and strict variant, so your organization can decide which configurations are best for your users. Check out the recommended settings we just published, or try out the O365 ATP Recommended Configuration Analyzer (ORCA) in your environment. Be sure to watch our best practices breakout session at Ignite for plenty more.

 

Reduce the burden on security operations teams by leveraging Automated Incident Response

Today’s security operations teams are drowning in alerts and need help responding to incidents in a rapid and efficient way. Office 365 ATP Automated Incident Response can dramatically improve the effectiveness of your organization’s security teams by addressing some of the most common threats through advanced automation. In September, we announced general availability of AIR, and at Ignite we showcased this capability and demonstrated its power. Read the blog post from September, or watch the full breakout session from Ignite.

 

Get a clear picture of users that may have been compromised

Utilize alerts and the investigation graph to identify suspicious user activity and possible compromise. View the Compromised Users report in the Security and Compliance center or take proactive measures such as outbound spam sending limits to curb post-compromise actions. Leverage the automatic investigation of compromise user alerts to assess the “blast radius” of the compromise and reduce further impact. Read the blog post we released in November announcing the preview of this feature, and watch the theater session on account compromise from Ignite.

 

Evaluate the effectiveness of Office 365 ATP in your own environment

The full Office 365 ATP stack analyzes your mail traffic through a rigorous multi-step process to thoroughly assess and block malicious intent. This is why we firmly believe this is the best protection for your O365 email and collaboration and we have data to prove it. Watch the Superlative Protection, Unparalleled Intelligence breakout session from Ignite to learn more.

We also appreciate the desire to evaluate our stack for yourselves and encourage you to do so. Do not fall prey to inferior evaluation strategies (whether via a journaling rule or other methods that do not use real email traffic between real senders and recipients) that negate most of the Office ATP stack. We explain more in the session above. We understand the challenge involved with effectively evaluating the ATP suite, and so we’ve created a simple process to help address this problem. ATP evaluation mode can be set up using a quick four step wizard and is configurable to work with most routing scenarios. Watch the session above to learn more. This is currently in a private preview, but you can get access to this by contacting your account manager.

 

As always, please check out What’s new in Office 365 ATP for the latest updates.