SlideShare a Scribd company logo
1 of 26
David J Pileggi Jr.
SharePoint Evangelist
M@DSoft
Madsoft2004@yahoo.com
SharePoint Security:
Through the Looking Glass
was made possible by the generous
support of the following sponsors…
And by your participation… Thank you!
Be sure to fill out your eval
form & turn in at the end of
the day for a ticket to the
BIG raffle!
Join us for the raffle &
SharePint following the
last session
Resources
AD Rights ManagementServices:
http://www.microsoft.com/windowsserver2008/en/us/ida-information-
protection.aspx
Contact Information
David J Pileggi Jr.
Consultant at Insight
Email: dpileggi@portalsolutions.net
Blog: http://sharepoint.mindsharpblogs.com/davep
Twitter: @DavidPileggi
Thank You!
Please fill out and return your evaluations.
We want to know what you think.

More Related Content

What's hot

Social media new way of working
Social media new way of workingSocial media new way of working
Social media new way of working
Marc Den Held
 
SharePoint 2010 Web Content Management
SharePoint 2010 Web Content ManagementSharePoint 2010 Web Content Management
SharePoint 2010 Web Content Management
Allyis
 
SharePoint 2010: A Social Primer
SharePoint 2010: A Social PrimerSharePoint 2010: A Social Primer
SharePoint 2010: A Social Primer
Edgewater
 
Socializing the Enterprise
Socializing the EnterpriseSocializing the Enterprise
Socializing the Enterprise
Awareness Inc.
 

What's hot (20)

Social media new way of working
Social media new way of workingSocial media new way of working
Social media new way of working
 
Building Dynamic Applications on both Office 365 and On-Prem
Building Dynamic Applications on both Office 365 and On-PremBuilding Dynamic Applications on both Office 365 and On-Prem
Building Dynamic Applications on both Office 365 and On-Prem
 
How Social and the Cloud Impact Your Governance Strategy
How Social and the Cloud Impact Your Governance StrategyHow Social and the Cloud Impact Your Governance Strategy
How Social and the Cloud Impact Your Governance Strategy
 
Metadata Management In A Social Media World, Spsbos, 2 2010
Metadata Management In A Social Media World, Spsbos, 2 2010Metadata Management In A Social Media World, Spsbos, 2 2010
Metadata Management In A Social Media World, Spsbos, 2 2010
 
The Four Facets of SharePoint Productivity
The Four Facets of SharePoint ProductivityThe Four Facets of SharePoint Productivity
The Four Facets of SharePoint Productivity
 
5 Reasons Why SharePoint 2010 Will Revolutionize Your Organization
5  Reasons Why SharePoint 2010 Will Revolutionize Your Organization5  Reasons Why SharePoint 2010 Will Revolutionize Your Organization
5 Reasons Why SharePoint 2010 Will Revolutionize Your Organization
 
What Can IBM Connections do for my Business and How do i get Started
What Can IBM Connections do for my Business and How do i get StartedWhat Can IBM Connections do for my Business and How do i get Started
What Can IBM Connections do for my Business and How do i get Started
 
Exploring the SharePoint 2013 Community Site Template
Exploring the SharePoint 2013 Community Site TemplateExploring the SharePoint 2013 Community Site Template
Exploring the SharePoint 2013 Community Site Template
 
10 Ways SharePoint 2013 Empowers Corporate Communicators
10 Ways SharePoint 2013 Empowers Corporate Communicators10 Ways SharePoint 2013 Empowers Corporate Communicators
10 Ways SharePoint 2013 Empowers Corporate Communicators
 
Share conference 2013
Share conference 2013Share conference 2013
Share conference 2013
 
SharePoint 2010 Web Content Management
SharePoint 2010 Web Content ManagementSharePoint 2010 Web Content Management
SharePoint 2010 Web Content Management
 
Improving Business Communications with IBM Connections and Engagement Center
Improving Business Communications with IBM Connections and Engagement CenterImproving Business Communications with IBM Connections and Engagement Center
Improving Business Communications with IBM Connections and Engagement Center
 
SharePoint 2010: A Social Primer
SharePoint 2010: A Social PrimerSharePoint 2010: A Social Primer
SharePoint 2010: A Social Primer
 
SharePoint Intranet Governance Sample Outline - www.sharepointpmp.com
SharePoint Intranet Governance Sample Outline - www.sharepointpmp.comSharePoint Intranet Governance Sample Outline - www.sharepointpmp.com
SharePoint Intranet Governance Sample Outline - www.sharepointpmp.com
 
Socializing the Enterprise
Socializing the EnterpriseSocializing the Enterprise
Socializing the Enterprise
 
DWCAU17: How to make all the components of Office 365 work for you
DWCAU17: How to make all the components of Office 365 work for youDWCAU17: How to make all the components of Office 365 work for you
DWCAU17: How to make all the components of Office 365 work for you
 
eSangathan Mumbai International Conference - CWE & Enterprise 2.0
eSangathan Mumbai International Conference - CWE & Enterprise 2.0eSangathan Mumbai International Conference - CWE & Enterprise 2.0
eSangathan Mumbai International Conference - CWE & Enterprise 2.0
 
Business aspects of social software and collaboration
Business aspects of social software and collaboration Business aspects of social software and collaboration
Business aspects of social software and collaboration
 
10 Worst Practices for SharePoint intranets
10 Worst Practices for SharePoint intranets10 Worst Practices for SharePoint intranets
10 Worst Practices for SharePoint intranets
 
SharePoint Information Architecture
SharePoint Information ArchitectureSharePoint Information Architecture
SharePoint Information Architecture
 

Recently uploaded

Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Victor Rentea
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Victor Rentea
 

Recently uploaded (20)

Vector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptxVector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptx
 
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
WSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering DevelopersWSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering Developers
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
 
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelMcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
Platformless Horizons for Digital Adaptability
Platformless Horizons for Digital AdaptabilityPlatformless Horizons for Digital Adaptability
Platformless Horizons for Digital Adaptability
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 

SharePoint Security: Through the Looking Glass

Editor's Notes

  1. You probably remember me from movies such asBoys with LasersMicrophone AssassinMy Pet Dinosaur
  2. The castThis refers to the different players I will be talking about that touches security at some level in SharePointThe goodThis will be about the good things that are associated with the “cast” membersThis section will point out several best practicesThe BadThis will deal with the negatives that may be associated with the cast memberThis section will point out bad practicesThe UglyI am not kidding there is uglyBuilding Security Schema’sFinal thoughtsQ&A: Self explanatory
  3. Speaking about security and SharePoint can be interesting. You can very easily be sucked into doing a session on how to do security vs. best practices surrounding security. You can find how to all over the internet when you Bing it. This session is going to have mainly theoretical thought around SharePoint security, however, there will be some demos to show exactly what I am speaking about to allow you to visually understand as well.Where there are best practices, there is not so great practices as well. We certainly want to look at these as well and the why behind themHopefully you will gain the Insight to go back to your environments to plan a solid security schema to achieve your goals using best practice techniques and methods.
  4. Read as an introduction
  5. AD plays the Cheshire cat. Its everywhere and nowhere at the same timeMost companies (should/think) they already have well defined security groups in their environment. (expound)AD is not changeable by the masses, its in a tightly controlled environment (expound)AD groups can give many people sweeping permissions in very little time (expound)
  6. SharePoint Security Groups get up and go… fast. As the white rabbit.High turnover rates in large project sites, specialty or novelty groups for fluff sites (expound)Large corporations have to be more mobile be lean and trim, at times (almost always) the IT team has its hands full, that being said, they will need to weigh which is better (expound)Can be created easily with side benefits, one being able to tie a custom permission set (foreshadow student example), when SharePoint is tied to AD creating Distribution lists is a nice plusIT can push the ownership responsibility to power users and still have AD safe
  7. Out of box permission sets have very clear lines of permissions with appreciable increases of responsibilitiesSpeak briefly on the ability to create custom permission setsUse the student example (no delete)
  8. It is rare that there is more than one resource in a company dedicated to just the AD. Larger the company, the more exaggerated it can be(expound)SharePoint is a window to your AD environment, when you run the import… is you’re AD maintained as good as you think? (expound)Is it a security group? Or Distribution list?
  9. The entire environment could potentially get out of the hand. (expound)Multiple groups due to lack of understanding by end usersGroups falling into disrepair because of employee turnover/movesWith end users introducing new groups to the environment this could counter the desired effects of the main security schemaIf your farm is email enabled to accept incoming email, your gal could potentially get out of control
  10. Just because you can do something doesn’t always mean it’s a good idea. The more permission levels, the harder it will be to decipher the security schema
  11. Use the white board to help visualize thisNote: There will be exceptions to the rule
  12. Story timeWhen there is no beginning for security, the end cant be goodExpound upon why security will deteriorate over time3rd party tools can combat this problem
  13. Do you know your data? What you are going to put into your farm is going to have a massive impact. Governance anyone?Best Practice. Use multiple site collections.Less likely to break inheritanceLoose the massive DBAble to get rid of ambiguous sites. Its our department site kindasortaDifferent kinds portal, department, team, community and project
  14. Most are not aware of this abilitySpeak on this at a high level to let them know its available to themGoing way of the DODO!
  15. For an Intranet, if you have AD as your LDAP it is a mixture of common sense/best practice to use AD (expound)Extranet/Internet: AD introduction of a Extranet AD to keep the primary domain safe, forms based works, but takes development time, ADFS takes some configuring lose functionality, anonymous… well. AD RMS Give a high level overview of what it can do.
  16. Make sure you show them about Limited Access
  17. *self note*Learn from the questions