microsoft defender for office 365
74 TopicsExtremely Slow Performance Since Defender Was Pushed on Us
Compliance, Security, Protection, and Defender are all extremely slow, with responses from screen to screen ranging from 30 seconds to multiple minutes between clicking items and waiting for Microsoft cloud to return results. I have a GB link and speed test well over 600 Mbps so it's not on my end. It appears the cutover in late January to this new "Defender" platform has been extremely detrimental to the Office portal response times in these portals. What is being done to resolve this?21KViews2likes12CommentsDefault Anti-phishing with Office 365 ATP for all users ?
We are configuring the Anti-Phishing Policy in Security & Compliance Center . There is an option to "Add users to protect". Understand we could use this option to target VIP users. But if we need to target this policy to all users in the tenant (i.e. Default policy), can we leave ""Add users to protect"" option empty and configure "Add domains to protect" option and "Applied to" option to include all our domains. ? Would that apply Anti-Phishing protection to all our users and domains ? Otherwise we will require multiple policies to cover all users and there 30K mailboxes in the cloud. Thanks.SolvedQuarantine "finger print matching" false positive
Just done my regular quarantine check on our O365 tenant and was surprised to find a couple of legit messages from an external sender which were flagged as High Confidence Phish based on finger print matching, which I understand translates to a close match to a previously detected malicious message. I can see absolutely nothing wrong with the message and it was so very business specific in its content that I cannot see that it would closely match anything else that had ever gone before. The recipient tells me they regularly exchange business emails with the sender without any issue. When I run off a report and look at other recent messages caught by finger print matching on my tenant, they were the usual phishing emails that are probably doing the rounds globally and were correctly trapped. Questions are: 1. Anyone know why something so highly specific in its content would be trapped in this way? 2. I feel I can't trust O365 to correctly quarantine based on this example, but High Confidence Phish is currently set to have the AdminOnlyAccessPolicy applied on my tenant - and this doesn't notify. Is there any way for a sys admin (only) to be notified by email when something goes into quarantine? I can set up a custom policy to allow RECIPIENT notification but I don't really want to involve them when messages are being correctly quarantined almost all of the time. Ours is a non-profit tenant so I can't be sitting around watching it all day - I need it to tell me when something has happened! Thanks for any ideas!New Blog Post | Microsoft Defender Weekly Wrap - Issue #28
Microsoft Defender Weekly Wrap - Issue #28 | Revue (getrevue.co) Happy Friday everyone! This week marks the weekend just before the RSA conference kicks off. I’ll be there. I leave for an early flight on Sunday around 4am. I’m already kicking myself knowing how tired I’ll be when I arrive in San Francisco. But Sunday is big and a fully scheduled day for me. So, no rest for the weary - as they say. If any of you will be attending next week, feel free to hunt me down or look me up. I’ll be primarily in the Microsoft areas - the expo included. I won’t be hard to find. I’ll be the person sitting or standing next to a big stack of empty coffee cups. And, if you happen to bring along a copy of the Must Learn KQL book (paperback or hardcover), I’ll be happy to sign it and sit around to talk Microsoft security. … There’s a new book coming covering Defender for Cloud from Microsoft PMs, Yuri Diogenes and Tom Janetscheck, that you should keep tabs on. The listing is super new and not even available yet for pre-order, but here’s the link to bookmark for when it becomes available: https://cda.ms/4ps Amazon says it will release in November. … I’m really looking forward to the RSA conference next week. But even more than the conference itself, I’m really looking forward to connecting with this community there and I’d be sad and disappointed if you didn’t make the effort to at least say “Hi.” So, please, PLEASE look me up. I’ll be away from my family for the long week and your connection and conversation will help it go so much faster. Talk soon. -RodDefending Against Ransomware With Microsoft Security
Even if your organization has good backups, and has been affected by ransomware to a limited scope, it may take from a few days to weeks to fully recover from the attack. Most of the preparations for protecting against a successful ransomware attack happen before getting infected. Doing a threat-analysis for identifying possible threat actors who could potentially target your systems would be a nice start. But it is not possible to identify all threat actors. It is therefore important to analyze the steps, the kill-chain, attack-vectors, and proceed with possible defenses on strategic, tactical and operational level. Typical Ransomware Activities Flow An important factor in defending against any malware and specially against ransomware is to monitor all the domains (identities, emails, endpoints, applications etc.), both on-premises and in cloud. A malicious OAuth application can trick the user to log on to their cloud apps and encrypt, exfiltrate or destroy the data in cloud. Ransomwares incidents are occurring more often than before, and this trend seems to be continuing. Few reasons contributing to this are: Digitalization and cloud adoption - which in-turn has increased attack surface. Identity has become central perimeter. Lack of end-users training and awareness. MFA can be bypassed if legacy protocols are enabled The ease of deploying ransomware where no coding or technical knowledge is required to deploy ransomware. Attackers can rent ransomware as a service. Anonymous payment channels (crypto currencies) Dependency on legacy systems, unpatched / vulnerable systems, insider threats etc. Weak cyber security architecture and/ or management focus Target Assets: The easiest, cheapest and hence the most common attack method is through social engineering. Emails bypass all the traditional security choke-points at perimeters like firewalls. If crafted well enough, even the most security-aware users may fall victim to such attacks. Similarly, compromised identities, open vulnerabilities, misconfigurations can be exploited to deliver ransomware. Allowing identities to authenticate via legacy protocols, can bypass MFA. While users (being the weakest link and first line of defense) are targeted the most, system hardening is equally important so that attackers do not find an open way in via exploiting vulnerabilities. Encryption is the last layer of defense, and if the attack is successful, secure backup is our safest bet. The Importance of Having a Ransomware Policy: But before going deeper into attack vectors, a very important (and often missing) part of preparation is having an enterprise-wide policy for ransomware, before ransomware hits. It is important to decide as a policy if we are willing to pay the ransom or not. If we decide to pay as the last resort, we must be aware of the following: The decryption key we get after paying may actually not work. The attackers' businesses depend on these payments. They may ask for more money (after we have paid for decryption-key) for not leaking your sensitive data on internet - a phenomenon called double-extortion. If we plan not to pay the ransom, we must ensure a rock-solid backup strategy, a way to ensure business continuity and the ability to recover from the disaster. https://docs.microsoft.com/en-us/azure/backup/backup-overview can be considered, which cover both on-premises and cloud workloads. It also provides MFA capability for sensitive operations, in addition to policy management, access control, monitoring and reporting. A contact point in case crises happens should already be communicated in advance. It should be understood that once ransomware is deployed, it will be more than a usual incident response process. There has to be a way to communicate with employees when emails and other communication systems are infected, or rendered useless. It should ideally be out-of-band. There would most probably be a need for inclusion of cyber insurance (if we have one), legal counsel and public relations in addition. Time Between Infection and Detection: It can take some time (a few days) between initial foothold and deploying ransomware. During this time attackers look for interesting data, try to move laterally and stay dormant. Ransomware has become an industry, where threat actors deploy ransomware to make money. Just like normal companies, they need to show increase in yearly profits. Their hope is that victims pay. To increase the chances that victims will pay, the attackers look for most valued data, most critical systems, exfiltrate the data, delete or deny access to back-up data, remove volume shadow copies, delete restore points etc, before encrypting the data and leaving the note for end-users. However, deleting or rendering executables useless, encrypting DLL files or other files which critical for running the system like windows directory files defeats the purpose of deploying ransomware. This is because the user will be left with no choice other than to restore the system from scratch. Common IOCs that EDR looks for: To understand common Indicators of Compromise, we need to understand how a typical ransomware works. If ransomware needs to connect to a C&C-server to download encryption key, the chances of it failing increase. This is because the communication to C&C-server can be blocked before it can connect to the C&C-server. So it is more common for ransomwares to keep the encryption key stored locally on the system. To ensure that antivirus, anti-malware and other security solutions do not stop ransomware in its track, it tries to stop these services first. As mentioned earlier, ransomwares do not encrypt or otherwise destroy entire systems. It encrypts files that typically contain important data, like Microsoft office documents, pdf files, databases, zip-files etc. While it is the typical behavior, it can change based on attackers choice of files to encrypt. Some ransomwares also create temporary files with garbage information to fill up available space. To prevent system recovery, ransomware will typically delete volume shadow copies. This can be done using tools like "wmic", "vssadmin", powershell, or by resizing the amount of space used for shadow copy storage. Ransomwares also delete system restore points for similar purposes. During the process of infection, we typically see one process starting another process. Like a word document containing embedded macro spawning a powershell process. The Bigger Picture - Using Microsoft XDR: It is crucial to monitor all the domains (identities, emails, endpoints, applicaitons etc) for IOCs. This not only ensures that security professionals receive signals from all these domains, but it is equally important to be able to correlate all this information at machine speed. The power of Microsoft's XDR lies in the pre-integrated architecture, where security professionals do not need to scramble resources and manually check each system for detailed analysis. All the alerts can be aggregated in single view by https://azure.microsoft.com/en-us/services/azure-sentinel/. https://docs.microsoft.com/en-us/azure/security-center/security-center-introduction can help you harden the PAAS-workloads, machines, data services, and apps. An advanced machine learning based feature that ASC provides is called Adaptive Application Controls. How this maps to MITRE ATT&CK Framework, can be found here. The different building blocks of Microsoft XDR are as follows: Defender for Identity & Azure Identity Protection Defender for Endpoint Cloud Apps Security (MCAS) Email Security (Defender for O365) Data Loss Prevention SQL Servers Containers Network IoT Azure App Service Importance of Backup Strategy: Regular and effective backups are critical best practices. We need to regularly perform backups and restore to ensure that the service is running as expected. Using Azure backup as a storage service has multiple benefits, where backups are situated apart from primary networks. They are protected against ransomware.Is there a way to allow URLs that have been detonated and determined as malicious?
Hi folks, I'm attempting to run a phishing simulation using a non-Microsoft vendor (i.e. I'm not using the out-of-the-box Threat Simulator) and, during my test campaign, the phishing emails were being delivered to my chosen recipients' junk mail folders. Is there a way to put URLs on an allow list to prevent M365 from junking my phishing simulation emails? Otherwise, I fear my test will only show that M365 will junk the emails rather than help me provide education to customers and strengthen our email security posture. I'd be immensely grateful for any feedback you can provide. I've attached screenshot from Threat Explorer below:SolvedSubmission and notification for 3rd Party Phishing Simulations
Hi folks, we are currently using a 3rd party phishing simulation tool which works fine and Advanced Delivery is activated so the emails are tagged correctly as "Phish simulation". Also we have implemented the "Report Phishing" button so we see the reported emails in the User Submission in M365 Defender Security Center and can notify the user from there. The problem is now when a user reports an email from the phishing simulation tool we are unable to notify the user that this email is phishing. So if we click the "mark and notify as" phishing we get the message "The selected items contain phish simulation training mail, please unselect them.". I found out that by manipulating the response from the server I can still inform the user, however it does not save what category it was tagged into. Is there a solution or workaround to also use the notify function in case the email is a phishing simulation? Thank you!2.6KViews0likes6CommentsNew Blog Posts | Security and Compliance
Announcing new Microsoft Information Protection capabilities to know and protect your data. - Microsoft Tech Community We are announcing the general availability of 49 new and 12 improved sensitive information types, covering key regulations in Europe and Asia Pacific. We are also announcing new features that improve the accuracy of sensitive information types and enable you to customize them to suit your organization’s unique needs. Compliance Ecosystem Growth (microsoft.com) By expanding MISA and including Microsoft Compliance, we are making it a holistic program across Security, Compliance, and Identity. Specifically, for Microsoft Compliance, we are adding the following five solutions to MISA portfolio. Don’t get caught off guard by the hidden dangers of insider risks! - Microsoft Tech Community We are excited to announce the public preview of additional features that make it easier to get started with Insider Risk Management and detect potential insider risk activities with enhanced machine learning models. Announcing co-authoring on Microsoft Information Protection-encrypted documents and labeling updates - Microsoft Tech Community The updates we announced bring the Microsoft 365 Apps’ built-in labeling client one step closer to feature parity with the Azure Information Protection client, and they allow administrators to deploy advanced capabilities easily and securely as part of the Microsoft 365 deployment. Microsoft commitment to close security skills gap - Microsoft Tech Community We strive to ensure customers have the skilling and learning resources they need to keep up in our world of complex cybersecurity attacks. By empowering our customers to increase their skilling knowledge, we enable customers to get up and running faster with Microsoft security and compliance solutions. We are excited to announce three new ways Microsoft is supporting skilling cyber security professionals. Announcing new assessment templates and enhanced capabilities in Compliance Manager - Microsoft Tech Community We are now excited to announce new capabilities and assessment templates that will increase regulation visibility, further enrich the user experience, and save organizations valuable time. Microsoft Further Extends Unified Data Loss Prevention - Microsoft Tech Community We are pleased to announce a continued investment in DLP with three new capabilities that further extend and expand the scope of DLP to a third-party browser and on-premises file repositories, and the introduction of a new DLP management and workflow experience. Announcing the Public Preview of features in Microsoft Information Protection unified analytics - Microsoft Tech Community In Public Preview, Microsoft 365 Compliance Center’s enhanced unified labeling and analytics experience now offer support for the most awaited ‘Azure Information Protection (AIP) audit logs’ including exploration of all activities. Harnessing Advanced Audit to power your forensic investigations in 5 steps (microsoft.com) Advanced Audit can help organizations scope data compromise and respond to regulatory obligations by providing access to audit events that are important for forensic investigations, and by extending audit log retention for up to a year. Here’s 5 steps to quickly get started with Advanced Audit within Microsoft 365 compliance center out of the box. Protect your infrastructure with Secured-core server - Microsoft Tech Community Given the many incentives motivating these attacks, raising the bar for attackers is a clear and urgent need for Windows Server and Azure Stack HCI. Using our learnings from the Secured-core PC initiative, we are now bringing these innovations to Windows Server and Azure Stack HCI. In collaboration with our OEM partners and hardware ecosystem, we expect this effort to bring your devices advanced hardware-based protection, while maintaining ease of management. Information protection strategies and roadmap to address issues around sensitive data This podcast features the leaders, program managers from Microsoft and experts from the industry to share details about the latest solutions and processes to help you manage your data, keep it safe and stay compliant. If you prefer to listen to the audio of this podcast instead, please visit: aka.ms/voicesofdataprotection