microsoft defender for cloud apps
85 TopicsMy learning path to the Microsoft Certified: Identity and Access Administrator Associate (SC-300)!
Dear Microsoft 365 / Azure Security Friends, I thought that I have already done so much in Azure on the subject of identity and access, this test can not be so difficult! Wrong, absolutely wrong setting Tom! With exactly such a view it just does not work for me. So back to field 1! What was a big challenge for me, among other things, was to understand the different roles in Azure. For example; Application Administrator, Application Developer, Cloud Application Administrator are all familiar to me! BUT, what can one role do but not the other? That's where the challenge lies and that's one of the things I had to face. Now this is just an example, but it should show you that it's the details that matter! In this exam you will be quizzed on topics in Azure Apps, Azure Identity, Azure Identity Governance, etc. This spectrum is huge, please take enough time to "explore" all the topics described in the Skills measured! This was among other things my way to success! Now to my preparations for the exam: 1. First of all, I looked at the Exam Topics to get a first impression of the scope of topics. https://docs.microsoft.com/en-us/learn/certifications/identity-and-access-administrator/ Please take a close look at the skills assessed: https://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE4Mr7Z 2. So that I can prepare for an exam I need an Azure test environment (this is indispensable for me). You can sign up for a free trial here. https://azure.microsoft.com/en-us/free/ 3. Now it goes to the Microsoft Learn content. These learn paths (as you can see below, all 4) I have worked through completely and "mapped"/reconfigured as much as possible in my test environment. https://docs.microsoft.com/en-us/learn/paths/implement-identity-management-solution/ https://docs.microsoft.com/en-us/learn/paths/implement-authentication-access-management-solution/ https://docs.microsoft.com/en-us/learn/paths/implement-access-management-for-apps/ https://docs.microsoft.com/en-us/learn/paths/plan-implement-identity-governance-strategy/ 4. Register for the exam early. This creates some pressure and you stay motivated. https://docs.microsoft.com/en-us/learn/certifications/identity-and-access-administrator/ 5. Please also have a look at Thomas Maurer's website! https://www.thomasmaurer.ch/2021/03/new-microsoft-security-certification-exams-in-beta/ 6. I have compiled a list of links which were very helpful for me! https://github.com/tomwechsler/Microsoft_Cloud_Security/blob/main/Links.txt I know you've probably read and heard this many times: read the exam questions slowly and accurately. Well, that was the key to success for me. It's the details that make the difference between success and failure. One final tip: When you have learned something new, try to explain what you have learned to another person (whether or not they know your subject). If you can explain it in your own words, you understand the subject. That is exactly how I do it, except that I do not explain it to another person, but record a video for YouTube! I hope this information helps you and that you successfully pass the exam. I wish you success! Kind regards, Tom WechslerMy learning path to the Microsoft Certified Information Protection Administrator Associate (SC-400)!
Dear Microsoft 365 / Azure Security Friends, When I read the skills measured, I immediately thought this will not be easy. Of course, I have already configured several retention policies, labels, etc. But when I took a closer look at the skills measured, I immediately noticed that it would take more time to learn. Let me give you an example of this. Let's take a look at the different terms: 1. sensitive information types 2. trainable classifiers 3. sensitivity labels 4. implement encryption for email messages 5. data loss prevention policies 6. Microsoft Endpoint data loss prevention 7. retention policies and labels 8. data retention in Microsoft 365 9. records management in Microsoft 365 I don't know about you but there are so many similar words, label here and label there! Really a challenge. The skills measured do not seem so hugely extensive, but this is extremely deceptive from my point of view! Let's look at the item "encryption for email messages", which immediately means that Exchange Online is also in play. I don't know exactly how it is with you, but when was the last time you created a "mail flow rule"? Or how much have you spent in the Cloud App Security Portal lately? As I have often experienced (this is referring to me), success is in the details. Take enough time to work with the following portals and explore the details: 1. Microsoft 365 Compliance 2. Exchange Online (incl. PowerShell) 3. Cloud App Security (especially file policy) 4. Microsoft 365 Security (Endpoint section) 5. Azure Portal (Azure Information Protection) Now to my preparations for the exam: 1. First of all, I looked at the Exam Topics to get a first impression of the scope of topics. https://docs.microsoft.com/en-us/learn/certifications/information-protection-administrator/ Please take a close look at the skills assessed: https://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE4Myp6 2. So that I can prepare for an exam I need an Azure test environment (this is indispensable for me). You can sign up for a free trial here. https://azure.microsoft.com/en-us/free/ Next, I set up a Microsoft 365 test environment. You can sign up for a free trial here. https://www.microsoft.com/en-us/microsoft-365/business/compare-all-microsoft-365-business-products I chose the "Microsoft 365 Business Premium" plan and added the Microsoft 365 E5 Trial as well for my testing. 3. Now it goes to the Microsoft Learn content. These learn paths (as you can see below, all 3) I have worked through completely and "mapped"/reconfigured as much as possible in my test environment. https://docs.microsoft.com/en-us/learn/paths/implement-information-protection/ https://docs.microsoft.com/en-us/learn/paths/implement-data-loss-prevention/ https://docs.microsoft.com/en-us/learn/paths/implement-information-governance/ 4. Register for the exam early. This creates some pressure and you stay motivated. https://docs.microsoft.com/en-us/learn/certifications/information-protection-administrator/ 5. Please also have a look at Thomas Maurer's website! https://www.thomasmaurer.ch/2021/03/new-microsoft-security-certification-exams-in-beta/ 6. I have compiled a list of links which were very helpful for me! https://github.com/tomwechsler/Microsoft_Cloud_Security/blob/main/SC-400/Links.txt 7. A really great resource with video courses is Virtual Training Series from Microsoft! https://partner.microsoft.com/en-US/training/virtual-training-series I know you've probably read and heard this many times: read the exam questions slowly and accurately. Well, that was the key to success for me. It's the details that make the difference between success and failure. One final tip: When you have learned something new, try to explain what you have learned to another person (whether or not they know your subject). If you can explain it in your own words, you understand the subject. That is exactly how I do it, except that I do not explain it to another person, but record a video for YouTube! I hope this information helps you and that you successfully pass the exam. I wish you success! Kind regards, Tom WechslerMy learning path to become a Microsoft Certified: Security Operations Analyst Associate (SC-200)!
Dear Microsoft 365 / Azure Security Friends, To be completely honest, I really had the absolute greatest respect for this test. Why, quite simply Kusto Query Language (KQL) was not necessarily my strength until now. But since this is exactly a big part of this exam, there was already some "discomfort" with it. But exactly this "discomfort" was the motivation to take on KQL to acquire the knowledge. In this exam you will be quizzed on topics in Azure Sentinel, Azure Security Center, Microsoft 365 Defender. This spectrum is huge, please take enough time to "explore" these "portals" deeply. This was among other things my way to success! Now to my preparations for the exam: 1. First of all, I looked at the Exam Topics to get a first impression of the scope of topics. https://docs.microsoft.com/en-us/learn/certifications/security-operations-analyst/ Please take a close look at the skills assessed: https://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE4Myp4 2. So that I can prepare for an exam I need an Azure test environment (this is indispensable for me). You can sign up for a free trial here. https://azure.microsoft.com/en-us/free/ Next, I set up a Microsoft 365 test environment. You can sign up for a free trial here. https://www.microsoft.com/en-us/microsoft-365/business/compare-all-microsoft-365-business-products I chose the "Microsoft 365 Business Premium" plan for my testing. 3. Now it goes to the Microsoft Learn content. These learn paths (as you can see below, all š I have worked through completely and "mapped"/reconfigured as much as possible in my test environment. https://docs.microsoft.com/en-us/learn/paths/sc-200-mitigate-threats-using-microsoft-defender-for-endpoint/ https://docs.microsoft.com/en-us/learn/paths/sc-200-mitigate-threats-using-microsoft-365-defender/ https://docs.microsoft.com/en-us/learn/paths/sc-200-mitigate-threats-using-azure-defender/ https://docs.microsoft.com/en-us/learn/paths/sc-200-utilize-kql-for-azure-sentinel/ https://docs.microsoft.com/en-us/learn/paths/sc-200-configure-azure-sentinel-environment/ https://docs.microsoft.com/en-us/learn/paths/sc-200-connect-logs-to-azure-sentinel/ https://docs.microsoft.com/en-us/learn/paths/sc-200-create-detections-perform-investigations-azure-sentinel/ https://docs.microsoft.com/en-us/learn/paths/sc-200-perform-threat-hunting-azure-sentinel/ 4. Register for the exam early. This creates some pressure and you stay motivated. https://docs.microsoft.com/en-us/learn/certifications/security-operations-analyst/ 5. Please also have a look at Thomas Maurer's website! https://www.thomasmaurer.ch/2021/03/new-microsoft-security-certification-exams-in-beta/ 6. The Azure Sentinel book from the Microsoft Press Store has also been super helpful to me! https://www.microsoftpressstore.com/store/microsoft-azure-sentinel-planning-and-implementing-9780136485452 I know you've probably read and heard this many times: read the exam questions slowly and accurately. Well, that was the key to success for me. It's the details that make the difference between success and failure. One final tip: When you have learned something new, try to explain what you have learned to another person (whether or not they know your subject). If you can explain it in your own words, you understand the subject. That is exactly how I do it, except that I do not explain it to another person, but record a video for YouTube! I hope this information helps you and that you successfully pass the exam. I wish you success! Kind regards, Tom WechslerUnsanctioned cloud apps generates constant alerts
When I mark a cloud app as unsanctioned it created a URL based indicator to block the site. However, it also by default enables the Generate Alert option on the indictor. This causes my SOC to bet inundated with garbage alerts. Now normally if I'm just unsanctioning one Cloud App a could go and turn of the alert. However, I use cloud app policy that will identify any new Cloud Apps in an entire category and then unsanction it. But it enables Generate Alert on the URL indicator. Then if someone accesses that new one the generate alert kicks off. I don't want to have to go into every new app and untick generate alert manually that's just too time consuming. Is there a way to change the default behaviour when adding an indicator to not enable the generate alert? Of is there some other way to do this? I could consider using power automate or something but I'd rather the default behaviour be the fix as automation can break. I don't have time to babysit it.New Blog Post | The New Microsoft Security Customer Connection Program (CCP)
Read the full blog post: The New Microsoft Security Customer Connection Program (CCP) - Microsoft Community Hub The security community is constantly growing, changing, and learning from each other in order to better position the world against cyber security threats. For years, Microsoft has driven a customer-obsessed development process by hosting two private communities for end-users of Microsoft security products: the Microsoft Cloud Security Private Community and the Microsoft 365 Defender Customer Connection Program. Under a strict confidentiality framework, our engineering teams get direct community feedback and insights for our roadmap plans, new user experience designs, private preview features, and more. Today, we are happy to announce that these two communities have now come together under one team ā The Microsoft Security Customer Connection Program.New Blog Post | Microsoft Defender Weekly Wrap ā Issue #50
Microsoft Defender Weekly Wrap ā Issue #50 - Azure Cloud & AI Domain Blog (azurecloudai.blog) Happy Friday all! This newsletter is 50! I just want to make it a quick point to thank you all for tuning in and continuing to tune in. This newsletter - and this community - continues to grow by leaps and bounds. Who knew 50 weeks ago that a simple idea like this could swell into something so far reaching and valuable to many of you. I receive commentary frequently from folks that count on this newsletter weekly and participate heavily in the associated LinkedIn group. Your community patronage is amazing and always appreciated. Remember, if you see something you like in the newsletter content donāt keep it to yourself. Share it with someone that needs it. Thatās how we continue to grow. ⦠GitLab Survey - Defender for DevOps GitLab Integration The Defender for DevOps team is looking to broaden the Microsoft Defender for Cloud ecosystem by offering customers the ability to onboard their GitLab resources into Defender for DevOps. If your DevOps team uses GitLab in any capacity, we request your feedback to better understand how you interact with the GitLab platform. Survey link: https://rodtrent.com/o9o ⦠The Must Learn KQL Christmas edition has been relaunched for the holidays! Know someone (or yourself) that lives KQL? Could be better than a Christmas Hallmark movie. https://must-learn-kql.creator-spring.com/listing/get-kql-for-christmas All proceeds go to St. Jude. ⦠Even with the purposeful effort to consolidate security portals I think youāll agree with me that Microsoft still has portal glut. I found the Microsoft Cloud command line this past week and thought Iād share with all of you. If youāve not seen this already, youāll thank me for the link: https://cmd.ms/ ⦠Thatās it from me for this week. Have a wonderful weekend and week ahead! Talk soon. -RodNew Blog Post | Microsoft Defender Weekly Wrap ā Issue #47
Microsoft Defender Weekly Wrap ā Issue #47 - Azure Cloud & AI Domain Blog (azurecloudai.blog) Microsoft Defender Weekly Wrap - Issue #47 Happy Friday everyone! I hope your week has been a good one. This week was a busy one for me. Heyā¦did you know Microsoft Ignite happened this week? š If you peruse many of the articles and resources in this weekās newsletter edition, youāll see a long list of per-product announcements. But, hey, hereās a tip: if you want a consolidated tome of all this weekās announcements, look instead to the Book of News. MICROSOFT IGNITE BOOK OF NEWS: https://rodtrent.com/5sk ⦠One thing that was announced this week that I donāt believe got enough attention is that Microsoft is offering a 50% discount for Defender for Endpoint when you switch or renew. Itās a limited time offer that begins November 1, 2022. Details for this are in the offer FAQ: https://rodtrent.com/bp4 ⦠Hereās something extra cool! Announced at Ignite 2022, get a sneak peek inside the upcoming Microsoft Defender for Cloud book and learn more about Defender for DevOps. Download a special Appendix from Microsoft Defender for Cloud written by George Wilburn, Principal PM, Defender for DevOps. Get it here: https://rodtrent.com/ry6 ⦠Itās been such a busy week, thatās really it for me as thereās plenty to read in this issue. Some of it is Ignite-related, some of it is not. If youāve already caught up on Ignite information, feel free to just read the great community content. Iām saving my personal Ignite observations until next issue. Talk soon. -RodNew Survey | Feedback on Network Protection for macOS and Linux
Feedback on Network Protection for macOS and Linux | Survey We would appreciate your feedback regarding our recent public preview of Network Protection for macOS and Linux. Network Protection enables web threat protection, custom indicators of compromise, web content filtering, and Microsoft Defender for Cloud Apps endpoint enforcement. Please take a few minutes to complete the short survey at https://aka.ms/NPandWPfeedback. If you would like to provide additional information or feedback, please contact us at xplatpreviewsupport@microsoft.com. We appreciate your help! Thank you!New Blog Post | Microsoft Defender Weekly Wrap - Issue #19
Microsoft Defender Weekly Wrap - Issue #19 | Revue (getrevue.co) Happy Friday everyone! Welcome to the 19th issue of this newsletter designed for the ever-growing Defender community. ⦠Iāve heard from many of you who have daily workloads that are immense, making your opportunities for learning just an extra task. So, long blog posts, Microsoft Learn modules, and webinars just donāt fit into your schedule. So, Iāve been mulling over how best to approach that for a while. Everyone needs the opportunity to learn and grow. So, for that reason this week Iāve launched a new series of video shorts called Rodcasts. The name may sound silly, but there was actually quite a discussion about it when I originally wanted to call the series āSnuggies.ā Snuggies was intended to be a word combination of Security Nuggets. But, as naive (apparently) as I am, I quickly found that the word snuggies has been taken over by some other definition in various parts of the globe. So, that was out. Then, I finally figured that I couldnāt go wrong just using my own name as part of it and using a play on words. So, Rodcasts was born. Rodcasts - or Security Rodcasts - are bite-sized nuggets of security information. The videos are around a minute or less long and focus on one very specific tip, trick, or new security feature. My intent is to deliver at least two of these a week. Each episode will premiere on YouTube, but will also be available on TikTok and Instagram. Check out the Security RodCasts Playlist on YouTube when you get a chance. Thereās already a couple available. Happy to hear your thoughts, suggestions, and comments. ⦠Have a wonderful weekend and week ahead! Talk soon. -Rod