threat protection
53 TopicsNew blog post | Correlating alerts in Microsoft Defender for Cloud
Alerts in Microsoft Defender for Cloud are notifications generated when potential security threats and anomalous activities are detected within your cloud environment. These alerts provide crucial information and insights, enabling SecOps teams to effectively identify, prioritize, and respond to potential malicious activity. Correlating alerts in Microsoft Defender for Cloud - Microsoft Community HubNew blog post | Microsoft Defender for DevOps Azure DevOps Connector - Microsoft Defender for Cloud
This article is a continuation of Microsoft Defender PoC Series which provides you guidelines on how to perform a proof of concept for a specific Microsoft Defender plan. For a more holistic approach where you need to validate Microsoft Defender for Cloud, please read How to Effectively Perform an Microsoft Defender for Cloud PoC article. There are two DevOps platforms currently covered by Defender for DevOps- GitHub and Azure DevOps. This article will go into detail about Azure DevOps Services. Microsoft Defender for DevOps Azure DevOps Connector - Microsoft Defender for Cloud PoC Series - Microsoft Community Hubmcas - malware detection policy
Hi all, just wondering whether or not the malware detection policy is just a "detection" policy 🙂 with no remediation or mitigation impact on the related findings. In other words, once the policy found suspicious files containing malware within SpO or OfB, it only alerts within mcas, but does nothing more on that file like moving to quarantine or similar. Am I right? Thank you ThomasMCAS keep triggering alerts for a whitelisted IP
We have the impossible travel alert policy in place. We get some users occasionally connecting from other countries for legitimate reasons (Ie VPN/Cross country Apps etc..). We have whitelisted these IP's (all the IP are static) as corporate but the policy keeps triggering. The alerts shows the whitelisted IP. The whitelist is performed in the "IP address ranges" from MCAS. Has anyone experienced this issue? Appreciate any insights on this. Thank you!New Blog Posts | Microsoft Cloud App Security
Successful Security Posture Management: control your SaaS apps via Microsoft Cloud App Security - Microsoft Tech Community A security posture management system should continuously report on and improve your organization’s security posture by focusing on disrupting any potential attackers from gaining a return on their investment. Specifically, security posture management in cloud applications should encompass two things-- cloud security posture management (CSPM) and SaaS security posture management (SSPM). Secure Access for applications with Microsoft Cloud App Security - Microsoft Tech Community Your cloud access security broker (CASB) should provide secure, easy and adaptive access to your organization’s apps depending on factors like location, device and user behavior. Adaptive access affirms the security measures your organization has put into place. This brief two-minute video demonstrates the flexibility of secure access in Microsoft Cloud App Security. Microsoft Information Protection and Microsoft Cloud App Security in 2021 Information protection is a key component of a CASB, and should deliver an integrated, nuanced understanding of your organization’s sensitive-labeled data as it's leveraged in your cloud environment. This brief two-minute video demonstrates the deep reach of information protection in Microsoft Cloud App Security. Cloud usage blind spots, how to uncover them and seamlessly control risks to your organization Rapid cloud adoption is a fact, and we believe any organization should adopt the cloud in a safe and monitored way to minimize risk of exposure. Shadow IT discovery should give immediate and clear feedback to your organization about which applications are being leveraged in your cloud environment. This brief two-minute video demonstrates the value of cloud shadow IT discovery in Microsoft Cloud App Security.O365 CAS - is there a way to duplicate or use as a template an Impossible Travel policy?
Is there a way to duplicate an Impossible Travel policy, or use it as a template (anomaly based policies are not listed as options for a template for me)? The goal is to have two separate policies: one that will record only successful impossible travel sing ins, and second one that will record failed impossible travel sing ins. This way an admin could configure related alerting, triage, and governance properly for each of these policies. (I'm aware that Multiple Failed Login Attempts policy could be used and tuned to alert for the failed sing ins, but this won't utilize the anomaly based capability given with this Impossible Travel policy.) So, I'm just curios if anybody had luck with a similar task? Thank you! 🙂Certificate Pinning in MCAS
Hello MCAS Team, is there any approach/configuration from MCAS perspective in regards of Certificate Pinning for trusting only certificates from a specific domain (activity related to devices, apps, identities, etc.) Any documentation available related to this? Thank you.1.1KViews0likes0Comments