microsoft defender for office 365
74 TopicsExtremely Slow Performance Since Defender Was Pushed on Us
Compliance, Security, Protection, and Defender are all extremely slow, with responses from screen to screen ranging from 30 seconds to multiple minutes between clicking items and waiting for Microsoft cloud to return results. I have a GB link and speed test well over 600 Mbps so it's not on my end. It appears the cutover in late January to this new "Defender" platform has been extremely detrimental to the Office portal response times in these portals. What is being done to resolve this?21KViews2likes12CommentsQuarantine "finger print matching" false positive
Just done my regular quarantine check on our O365 tenant and was surprised to find a couple of legit messages from an external sender which were flagged as High Confidence Phish based on finger print matching, which I understand translates to a close match to a previously detected malicious message. I can see absolutely nothing wrong with the message and it was so very business specific in its content that I cannot see that it would closely match anything else that had ever gone before. The recipient tells me they regularly exchange business emails with the sender without any issue. When I run off a report and look at other recent messages caught by finger print matching on my tenant, they were the usual phishing emails that are probably doing the rounds globally and were correctly trapped. Questions are: 1. Anyone know why something so highly specific in its content would be trapped in this way? 2. I feel I can't trust O365 to correctly quarantine based on this example, but High Confidence Phish is currently set to have the AdminOnlyAccessPolicy applied on my tenant - and this doesn't notify. Is there any way for a sys admin (only) to be notified by email when something goes into quarantine? I can set up a custom policy to allow RECIPIENT notification but I don't really want to involve them when messages are being correctly quarantined almost all of the time. Ours is a non-profit tenant so I can't be sitting around watching it all day - I need it to tell me when something has happened! Thanks for any ideas!One Specific Email going to Junk Mail Folder after adding the IP in the Connection Filter Policy
We are receiving newsletters masking as our own domain which we are allowing via SPF. We use Barracuda for the primary filter and also added IP allow. Some are going to the Junk Mail folder so we added the IP in the Anti Spam Policy - Connection Filter in office 365. All is good except for one particular email. We don't want to add the specific email to be allowed as we don't want it to be spoofed. All the headers are the same (including the sending IP). How do you determine what's still causing that specific email to go to the Junk Mail folder?New Blog Post | Microsoft Defender Weekly Wrap – Issue #47
Microsoft Defender Weekly Wrap – Issue #47 - Azure Cloud & AI Domain Blog (azurecloudai.blog) Microsoft Defender Weekly Wrap - Issue #47 Happy Friday everyone! I hope your week has been a good one. This week was a busy one for me. Hey…did you know Microsoft Ignite happened this week? 🙂 If you peruse many of the articles and resources in this week’s newsletter edition, you’ll see a long list of per-product announcements. But, hey, here’s a tip: if you want a consolidated tome of all this week’s announcements, look instead to the Book of News. MICROSOFT IGNITE BOOK OF NEWS: https://rodtrent.com/5sk … One thing that was announced this week that I don’t believe got enough attention is that Microsoft is offering a 50% discount for Defender for Endpoint when you switch or renew. It’s a limited time offer that begins November 1, 2022. Details for this are in the offer FAQ: https://rodtrent.com/bp4 … Here’s something extra cool! Announced at Ignite 2022, get a sneak peek inside the upcoming Microsoft Defender for Cloud book and learn more about Defender for DevOps. Download a special Appendix from Microsoft Defender for Cloud written by George Wilburn, Principal PM, Defender for DevOps. Get it here: https://rodtrent.com/ry6 … It’s been such a busy week, that’s really it for me as there’s plenty to read in this issue. Some of it is Ignite-related, some of it is not. If you’ve already caught up on Ignite information, feel free to just read the great community content. I’m saving my personal Ignite observations until next issue. Talk soon. -RodSecurity Tutorial Blogs
With the most recent Email Protection Basics Blog just posted from the Microsoft Defender for Office 365 team, I wanted to get some opinions from you all on this type of Tech Community content. In the past, polls have shown that this type of how-to/tutorial content is what you all like to see most on this community. I just wanted to know if you have any favorite blogs of this type? Any that you return to regularly for reference in your work? I would love to hear stories about how our community makes your life easier. Comment below! ThanksNew Blog Post | Microsoft Defender Weekly Wrap - Issue #19
Microsoft Defender Weekly Wrap - Issue #19 | Revue (getrevue.co) Happy Friday everyone! Welcome to the 19th issue of this newsletter designed for the ever-growing Defender community. … I’ve heard from many of you who have daily workloads that are immense, making your opportunities for learning just an extra task. So, long blog posts, Microsoft Learn modules, and webinars just don’t fit into your schedule. So, I’ve been mulling over how best to approach that for a while. Everyone needs the opportunity to learn and grow. So, for that reason this week I’ve launched a new series of video shorts called Rodcasts. The name may sound silly, but there was actually quite a discussion about it when I originally wanted to call the series “Snuggies.” Snuggies was intended to be a word combination of Security Nuggets. But, as naive (apparently) as I am, I quickly found that the word snuggies has been taken over by some other definition in various parts of the globe. So, that was out. Then, I finally figured that I couldn’t go wrong just using my own name as part of it and using a play on words. So, Rodcasts was born. Rodcasts - or Security Rodcasts - are bite-sized nuggets of security information. The videos are around a minute or less long and focus on one very specific tip, trick, or new security feature. My intent is to deliver at least two of these a week. Each episode will premiere on YouTube, but will also be available on TikTok and Instagram. Check out the Security RodCasts Playlist on YouTube when you get a chance. There’s already a couple available. Happy to hear your thoughts, suggestions, and comments. … Have a wonderful weekend and week ahead! Talk soon. -RodNew Blog Post | Microsoft Defender Weekly Wrap - Issue #18
Microsoft Defender Weekly Wrap - Issue #18 | Revue (getrevue.co) Welcome to Friday! And, welcome to the 18th issue of the Microsoft Defender weekly newsletter. We have a lot of new subscribers this week - so welcome all! I hope this newsletter lives up to your expectations, hopes, and dreams. For many of you, though, you’ve been here along the way during this entire journey. I truly appreciate that, and I’m constantly floored by the folks that reach out to volunteer kudos for the effort. I wrote a blog post late last week on All the Ways to Read the Weekly Newsletters for Microsoft Sentinel and Microsoft Defender. If you’re one of those that truly love this weekly communication, please share this with someone. Obviously, the more the merrier, but you never know what sharing this valuable resource with a colleague, friend, or customer might do for their career and your relationship. … The Defender for Cloud in the field series is a rewarding and valuable effort put together and delivered by my colleague Yuri Diogenes. This video series really brings you closer to the Defender for Cloud product and the teams that work to make it such a great solution. If you’re not privy to this yet, or maybe you’ve watched this in the past but can never remember where to find it, there’s now a dedicated link on the Microsoft Docs platform. Defender for Cloud in the field | Microsoft Docs Bookmark this or add it to your Docs profile Collection so you don’t lose it. … I hope you agree with me that Microsoft Learn is a valuable resource. Microsoft Learn is an important part of my role here at Microsoft and I see the hard work that goes into developing this resource. As a security person focused on things like Microsoft Sentinel and Defender, I find it extra rewarding when I see Microsoft Learn content that highlights my areas of expertise and focus. So, imagine my delight this past week when the Microsoft Learn team spent some time highlighting all that I love. I think you’ll appreciate this too: The 2-Minute Recap: Everything new with Security, Compliance, and Identity on Microsoft Learn … That’s all I have to highlight this week. I hope your looking forward to the weekend and week ahead. Talk soon. -RodNew Blog Post | How to Read the Weekly Newsletters for Microsoft Sentinel and Microsoft Defender
All the Ways to Read the Weekly Newsletters for Microsoft Sentinel and Microsoft Defender – Azure Cloud & AI Domain Blog (azurecloudai.blog) The weekly newsletters for Microsoft Sentinel and Defender continue to skyrocket in subscribers. It’s amazing how far each of these resources have come and how dedicated and loyal the inbox subscribers are. But there are many out there that prefer not to receive yet another newsletter in their inbox, or who would like to sample and test the newsletter before jumping into a dedicated delivery. For those reasons, there are several different ways of reading the weekly newsletters without having it sit in an inbox.Defending Against Ransomware With Microsoft Security
Even if your organization has good backups, and has been affected by ransomware to a limited scope, it may take from a few days to weeks to fully recover from the attack. Most of the preparations for protecting against a successful ransomware attack happen before getting infected. Doing a threat-analysis for identifying possible threat actors who could potentially target your systems would be a nice start. But it is not possible to identify all threat actors. It is therefore important to analyze the steps, the kill-chain, attack-vectors, and proceed with possible defenses on strategic, tactical and operational level. Typical Ransomware Activities Flow An important factor in defending against any malware and specially against ransomware is to monitor all the domains (identities, emails, endpoints, applications etc.), both on-premises and in cloud. A malicious OAuth application can trick the user to log on to their cloud apps and encrypt, exfiltrate or destroy the data in cloud. Ransomwares incidents are occurring more often than before, and this trend seems to be continuing. Few reasons contributing to this are: Digitalization and cloud adoption - which in-turn has increased attack surface. Identity has become central perimeter. Lack of end-users training and awareness. MFA can be bypassed if legacy protocols are enabled The ease of deploying ransomware where no coding or technical knowledge is required to deploy ransomware. Attackers can rent ransomware as a service. Anonymous payment channels (crypto currencies) Dependency on legacy systems, unpatched / vulnerable systems, insider threats etc. Weak cyber security architecture and/ or management focus Target Assets: The easiest, cheapest and hence the most common attack method is through social engineering. Emails bypass all the traditional security choke-points at perimeters like firewalls. If crafted well enough, even the most security-aware users may fall victim to such attacks. Similarly, compromised identities, open vulnerabilities, misconfigurations can be exploited to deliver ransomware. Allowing identities to authenticate via legacy protocols, can bypass MFA. While users (being the weakest link and first line of defense) are targeted the most, system hardening is equally important so that attackers do not find an open way in via exploiting vulnerabilities. Encryption is the last layer of defense, and if the attack is successful, secure backup is our safest bet. The Importance of Having a Ransomware Policy: But before going deeper into attack vectors, a very important (and often missing) part of preparation is having an enterprise-wide policy for ransomware, before ransomware hits. It is important to decide as a policy if we are willing to pay the ransom or not. If we decide to pay as the last resort, we must be aware of the following: The decryption key we get after paying may actually not work. The attackers' businesses depend on these payments. They may ask for more money (after we have paid for decryption-key) for not leaking your sensitive data on internet - a phenomenon called double-extortion. If we plan not to pay the ransom, we must ensure a rock-solid backup strategy, a way to ensure business continuity and the ability to recover from the disaster. https://docs.microsoft.com/en-us/azure/backup/backup-overview can be considered, which cover both on-premises and cloud workloads. It also provides MFA capability for sensitive operations, in addition to policy management, access control, monitoring and reporting. A contact point in case crises happens should already be communicated in advance. It should be understood that once ransomware is deployed, it will be more than a usual incident response process. There has to be a way to communicate with employees when emails and other communication systems are infected, or rendered useless. It should ideally be out-of-band. There would most probably be a need for inclusion of cyber insurance (if we have one), legal counsel and public relations in addition. Time Between Infection and Detection: It can take some time (a few days) between initial foothold and deploying ransomware. During this time attackers look for interesting data, try to move laterally and stay dormant. Ransomware has become an industry, where threat actors deploy ransomware to make money. Just like normal companies, they need to show increase in yearly profits. Their hope is that victims pay. To increase the chances that victims will pay, the attackers look for most valued data, most critical systems, exfiltrate the data, delete or deny access to back-up data, remove volume shadow copies, delete restore points etc, before encrypting the data and leaving the note for end-users. However, deleting or rendering executables useless, encrypting DLL files or other files which critical for running the system like windows directory files defeats the purpose of deploying ransomware. This is because the user will be left with no choice other than to restore the system from scratch. Common IOCs that EDR looks for: To understand common Indicators of Compromise, we need to understand how a typical ransomware works. If ransomware needs to connect to a C&C-server to download encryption key, the chances of it failing increase. This is because the communication to C&C-server can be blocked before it can connect to the C&C-server. So it is more common for ransomwares to keep the encryption key stored locally on the system. To ensure that antivirus, anti-malware and other security solutions do not stop ransomware in its track, it tries to stop these services first. As mentioned earlier, ransomwares do not encrypt or otherwise destroy entire systems. It encrypts files that typically contain important data, like Microsoft office documents, pdf files, databases, zip-files etc. While it is the typical behavior, it can change based on attackers choice of files to encrypt. Some ransomwares also create temporary files with garbage information to fill up available space. To prevent system recovery, ransomware will typically delete volume shadow copies. This can be done using tools like "wmic", "vssadmin", powershell, or by resizing the amount of space used for shadow copy storage. Ransomwares also delete system restore points for similar purposes. During the process of infection, we typically see one process starting another process. Like a word document containing embedded macro spawning a powershell process. The Bigger Picture - Using Microsoft XDR: It is crucial to monitor all the domains (identities, emails, endpoints, applicaitons etc) for IOCs. This not only ensures that security professionals receive signals from all these domains, but it is equally important to be able to correlate all this information at machine speed. The power of Microsoft's XDR lies in the pre-integrated architecture, where security professionals do not need to scramble resources and manually check each system for detailed analysis. All the alerts can be aggregated in single view by https://azure.microsoft.com/en-us/services/azure-sentinel/. https://docs.microsoft.com/en-us/azure/security-center/security-center-introduction can help you harden the PAAS-workloads, machines, data services, and apps. An advanced machine learning based feature that ASC provides is called Adaptive Application Controls. How this maps to MITRE ATT&CK Framework, can be found here. The different building blocks of Microsoft XDR are as follows: Defender for Identity & Azure Identity Protection Defender for Endpoint Cloud Apps Security (MCAS) Email Security (Defender for O365) Data Loss Prevention SQL Servers Containers Network IoT Azure App Service Importance of Backup Strategy: Regular and effective backups are critical best practices. We need to regularly perform backups and restore to ensure that the service is running as expected. Using Azure backup as a storage service has multiple benefits, where backups are situated apart from primary networks. They are protected against ransomware.