security
950 TopicsHow much of your Microsoft 365 environment can you actually see at once?
Not how many users you have. Not how many sites, teams, apps or flows you have. How much of it can you actually see connected together? I've been working across Microsoft 365 environments for a while, and I kept running into the same thing. There is no shortage of information. If anything, there is probably too much of it. Users, groups, permissions, SharePoint, Teams, Power Apps, Power Automate, Power BI, Dataverse, OneDrive, Exchange, Intune, licensing, configuration... It's all there. But when you're actually trying to understand how everything fits together, it can be a different story. You open one blade. Find something. Open another. Cross-check it. Go back. Open something else. Before long, you're jumping between different parts of the tenant trying to build the bigger picture in your head. And if you're working with larger environments, that gets difficult pretty quickly. The information isn't necessarily missing. The relationships between the information are what can be difficult to see. That got me thinking about a slightly different question: Instead of "where do I find this information?" "Show me what's connected to this." That's where VisibleState started. Start anywhere. Follow the connections. Imagine starting with a single user. Instead of seeing that user simply as a record with a list of properties, imagine being able to explore the relationships around them: User → Groups → SharePoint → Teams → Power Apps → Power Automate → Power BI → Dataverse → OneDrive → Exchange → Intune Then the questions become different: What does this user have access to? Is that access direct or coming through a group? What resources are connected to them? What depends on something they're associated with? Which licenses are involved? Are there relationships that look unusual? If something changes, what else might be affected? Those questions aren't necessarily about finding another piece of information. They're about putting information that already exists into context. A report can tell you that something exists. A connected view helps you understand what it is connected to. Illustrative example below — not a real customer environment. I'm not suggesting Microsoft 365 doesn't already give us this information Quite the opposite. Microsoft 365 already gives administrators an incredible amount of information and tooling. The thing I've been thinking about is what happens when you want to look across those boundaries. Sometimes I don't want another export. I don't want another list. I don't necessarily want another dashboard. I want to start with something I'm looking at and ask: "What's connected to this?" And then keep following the trail. That's the idea I'm exploring with VisibleState. The interesting part is what happens when you change the viewpoint The same relationships can be useful for completely different reasons. For example: Administrators may want to understand access, permissions and dependencies. Security and governance teams may want to find unusual relationships or exceptions. Compliance teams may need to understand who can access something and why. People managing multiple environments may want a consistent way to understand what's there without rebuilding the picture manually every time. Leadership may not need to see the graph at all. They may simply want to know what's important, what's exposed and what could be affected. It's still the same underlying environment. You're just looking at it from a different angle. And that's where I think things get interesting. Where I'm at with it VisibleState started as something I was building to make my own work easier. I was spending a lot of time investigating environments, tracing access and putting information together for reports. The individual tasks weren't necessarily difficult. It was the jumping between different places and reconstructing the bigger picture that took the time. So I started building something that would let me approach the environment through the relationships instead. It's grown quite a bit from where it started, and I'm continuing to build it. I'm not posting this as a product launch, and I'm not looking for people to sign up. I'm genuinely interested in whether the problem I'm seeing is familiar to other people working with Microsoft 365. So I'm curious... If you could start with any object in your Microsoft 365 environment and immediately see what it's connected to, where would you start? Would it be: Users and access Groups and permissions SharePoint and Teams Power Apps, Power Automate, Power BI and Dataverse Licensing and resources Governance and unusual relationships Something completely different Maybe you've already got a good way of doing this. Maybe you still find yourself jumping between different services and piecing things together manually. Or maybe I'm looking at the problem from the wrong direction. What's the one relationship in your Microsoft 365 environment that you wish you could see instantly?15Views0likes0CommentsHow to properly redact a PDF?
I need to share a PDF that contains names, email addresses, and other confidential details that must be removed first. Simply placing black boxes over the text does not seem secure, since the original content may still be searchable, selectable, or recoverable, so I need a way to permanently redact a PDF. Because the document contains sensitive information, I would prefer not to upload it to an online tool. I’m looking for either a built-in option or professional third-party desktop software that can permanently redact both text and images while processing the file locally. It would also be useful to remove hidden information from a PDF before sharing, including comments, document metadata, and any other embedded details. What is the safest way to handle this, and how can I verify that a PDF is properly redacted before I send it?68Views0likes3CommentsWhy is Microsoft being a bully in regard to security defaults?
Hi, I received this email today: The security defaults setting for your domain.com tenant will be turned on by May 11, 2023 You’re receiving this email because you’re a global administrator for domain.com. To help protect your organization, we’re always working to improve the security of Microsoft cloud services. As part of this, we’re enabling the security defaults setting in your tenant that includes multifactor authentication, which can block more than 99.9 percent of identity attacks that attempt to compromise your accounts. When you log in to your account between April 27, 2023, and May 11, 2023, you’ll see a message prompting you to proactively enable security defaults. If you haven’t logged in or enabled this setting when that timeframe ends, we’ll enable it for you automatically. This is my subscription, I pay for it and Microsoft has no right to tell me what to do!!!! Angry I already disabled my security defaults in Azure admin centre a long time ago and do not want security defaults on because there may be situations where my mobile is unavailable, there is no signal or the battery is flat. Microsoft can suggest this, but cannot force their clients to enable this if they don't want to. There are many of my clients that don't want to authenticate a second time because it would cause a nightmare with their employees. Forcing someone is dictatorship. In a democratic society people get to choose what they want to do. I read that I can use conditional access policies but Microsoft is going to hit you with an additional Azure AD Premium subscription on top of what you are already paying. Many of my clients are small businesses who try to keep their costs down. Currently inflation is rampant and many small businesses are going bust. Thanks Microsoft for increasing our cost of living and running a business. This is my 2 cents worth on this subject.2.6KViews1like4CommentsSecurity Admin Center Tenant Allow/Block List Not Able to Block IPv4?
While using the Security Admin Center Tenant Allow/Block List we have been able to block specific email addresses and IPv6 IP addresses but are unable to block IPv4 IP addresses. We have tried both using the console and the CLI but have turned up unsuccessful both times when it comes to IPv4. A large majority of the phishing attempts that we encounter come from IPv4 addresses but we have been unable to block any of these. Will there ever be functionality for IPv4 within the Tenant Allow/Block list or is the only option to use conditional access policies? Also why is this enterprise tool only functional with IPv6 and without documentation stating that it does not work for IPv4?1.9KViews4likes6CommentsFile Sharing between licensed account holders
From a starting point of this year, we have been finding that any to most file shares that happened between licensed MS account users are being flagged and quarantined by the anti-malware policy. This should be, we are looking to resolve this issue. Has anyone else experienced this issue and what was your resolve. At the moment we have to monitor the quarantines and manually go in to release the share notifications.246Views0likes4CommentsHacked please help
My Microsoft account was hacked today. The attacker changed my sign-in alias to a random Outlook address, removed my phone number, added their own Authenticator app, and changed the recovery email. My original email now says the Microsoft account doesn’t exist. I have the Microsoft security emails proving the changes. I also have other forms of proof. If there is any moderator or anyone who can help me recover my account I had some important stuff on there I would like to get back. It wasn't this email but another one I made this so I can ask for help. When I tried to recover the email they changed it as provided in the screenshots down below. I tried to call support and fill out recovery stuff but since they changed the email for the account there is not much I can do.151Views0likes2CommentsStrange redirect when signing in - phishing?
I just restarted my Business Standard 365 license today and this afternoon got an email from email address removed for privacy reasons with the following content: But when I clicked on the 'Verify payment information' button I am redirected to a page with the following URL: https://admin.cloud.microsoft/Error/UnAuth?errorCode=100014 looking like this: This looks highly suspicious (Times New Roman font, URL with no top-level extension such as .com, unusual graphics). Is this legitimate or a phishing attempt? Now, when I try to login to admin.microsoft.com to check my account the same suspicious "Sign out and login with a different account" page pops up repeatedly.267Views0likes6CommentsAuthenticator não funciona
Tenho um e-mail corporativo (sou o adm único, nao tem ti) que faço login na conta do powerbi, contudo, meu celular com o authenticator foi perdido e já nao tenho mais acesso, por este motivo, nao consigo mais logar na conta pq ele sempre direciona para o authenticador que nao tenho mais acesso e não abre a possibilidade de receber o codigo por outro meio, (sms ou email). ja tentei vários recursos (chat, telefone do suporte) para recuperar a conta e nao consigo. Todas as opções direcionam para o autenticador. solicito a microsoft que dê uma solução, resetando o autenticador anterior para que eu possa acessar a conta e incluir métodos alternativos de desbloqueio, ou sugira outra solução.109Views0likes1CommentHow to target Azure VPN (Microsoft-Registered) app with Conditional Access Policies?
I have an Azure Point-to-Site VPN Gateway configured using the Microsoft-registered Azure VPN Client App ID (Audience value: c632b3df-fb67-4d84-bdcf-b95ad541b5c8). Everything is working correctly for our users. The issue I am having is that anyone with an Entra account can connect to the VPN and I want to restrict this with a blocking Conditional access policy. I do not want to create a custom app registration, because then I will have to change the 'audience' value on the app gateway and all user's will need to modify their VPN clients. The problem is I need to target the Microsoft-registered Azure VPN app in a Conditional Access policy but it does not appear in my Enterprise Applications list or in the CA app picker when searching. My questions: Why does the Microsoft-registered app not automatically create a service principal in my tenant the way other Microsoft apps do? Is there a supported way to make it appear in the CA app picker without creating a custom app registration or changing the gateway Audience value? Has anyone successfully targeted c632b3df-fb67-4d84-bdcf-b95ad541b5c8 in a CA policy while keeping it as the gateway Audience value? Thanks for the assistance here168Views0likes2CommentsAdd filters/ grouping to microsoft authenticator app accounts
Hello! Hope you are all well! I would like to see filters of personal/ Work and school accounts or by domain. Or even the ability to organise accounts manually into groups. Currently have a long list of personal accounts and work account.10KViews12likes11Comments