SlideShare una empresa de Scribd logo
1 de 27
aOS 2017Tournée Canadienne
Fueled by
Québec
Montréal
Ottawa
Toronto
6 Février
7 Février
8 Février
10 Février
From classification
to protection of your
data, secure your
business with Azure
Information
Protection Joris Faure
Joris FAURE – MVP Enterprise
Mobility
Microsoft Solution Manager at SII
CANADA
ca.linkedin.com/in/jorisfaure
@faurejoris
Thank you !
faurejoriswww.It-channels.com
Identity Overview
Introduction to Azure Information Protection
• Conceptually…
• RMS
• Azure Information Protection
Live Demonstration
• Azure Information Protection
SUMMARY
faurejoriswww.It-channels.com
Identity at Microsoft
Forefront Microsoft
Identity Manager
Identity Management
Automatisation, based on rules, of identities (accounts, groups, access)
Azure Active
Directory Connect
Identity Management between Active Directory and Azure Active Directory
Azure Information
Protection
RMS
Classification and Protection of documents
Apply persistent protection within company documents: Messaging,
SharePoint, Office
AD Federation
Services
Identity Federation
Allows the SSO application in web mode for the services supporting the SAML
protocol
faurejoriswww.It-channels.com
Introduction
challenge
• You have a perimeter
• You have devices to manage
• Your business requires sharing sensitive data out of
your control for B2B / B2C
Reduce leakage of shared data with others (B2B
collaboration)
Isolation of sensitive data from unauthorized
users
Prevention of malicious workers from leaking
secrets
Comply with regulatory requirements
96%
94%
89%
87%
Source -Microsoft
faurejoriswww.It-channels.com
Azure Information Protection
Locating RMS in my information systems security project
DRM : Digital Rights
Management
VS DLP : Data Loss Prevention
Digital signature of documents (Encryption)
Example :
AD RMS : Active Directory Rights Management
Services / Azure RMS
Consists of monitoring the events of the
infrastructure
Example :
Digital Guardian
Document classification is the important requirement of a DRM or DLP project ! ! !
faurejoriswww.It-channels.com
Azure Information Protection
• Information Technology Protection
• Data Encryption
• Transport of the right of use within the document
• Prevents -> Protects against information leakage
• Based on security policies
• AD RMS is an infrastructure
 Leverages Active Directory for identities and groups
 Integration with the Microsoft environment
• SharePoint
• Exchange
• Office
• Azure RMS is a cloud service offered in Office 365
• Azure Information Protection is a cloud service offered in Office 365
faurejoriswww.It-channels.com
Azure Information Protection
Microsoft – RMS Offer
AD RMS (Active Directory Rights Management Services) Azure RMS
Infrastructure On-Premise – Windows Server 2012 R2
(Office, PDF… Gigatrust)
Infrastructure Cloud – Office 365
(Multiple extensions - protected file [pfile])
Windows Vista SP2 minimum Windows 7 minimum (SP1) / Some version of Linux
(Ubuntu 14.04 / OpenSUSE 13.2 / CentOS 7)
Compatible with a minimum version of Office 2007 Compatible Office 2010 minimum throught RMS / AIP
sharing application
Mobility: Windows RT / iOS / Android / Windows Phone Mobility: Windows RT / iOS / Android / Windows Phone
Classification : File Classification Infrastructure (FCI) Classification : Azure Information Protection (AIP)
faurejoriswww.It-channels.com
Azure Information Protection
Important : Using the Azure RM service with a local infrastructure ( Exchange,
SharePoint …) requires deploying the RMS connector on the target infrasturcure
The RMS Connector– Hybrid Infrastrcture
faurejoriswww.It-channels.com
Azure Information Protection
RMS Connector
Windows
Azure Active
Directory
Synchronization Tool
Exchange
2010/2013
Azure RMS
Microsoft RMS
Connector
SharePoint
2010/2013
Active
Directory
faurejoriswww.It-channels.com
YOUR
Authandcollab
Topology
Source -Microsoft
faurejoriswww.It-channels.com
Sensitive data is never sent to Rights
Management
Noneprotectedcontent
RMS
Source -Microsoft
faurejoriswww.It-channels.com
Azure Information Protection
Protection of
Documents and Emails
Data Encryption
Decryption of Data by
Authorized Persons
Rights:
- Reading/modification
- Printing
- Transfer
Protects source :
- User
- Automatic
Centralized Safety
Policy
Workflow RMS
faurejoriswww.It-channels.com
Azure Information Protection
Based on security policies
Manual mode Automatic mode Integrated mode
 Use a template : « Reading for all
the employees »
 Specify manually rights
 Administration of templates since
the server RMS or Azure RMS
(centralization of the
administration)
 Use of FCI (File Classification
Infrastructure) for the application
of the automatic templates (local)
 Use of Azure Information
Protection (cloud)
 Deployment of templates on the
applications (Office, Exchange)
and/or Azure Information
Protection
 SharePoint :
 The protection RMS is
automatically applied
 Rights RMS Rights
SharePoint
 Use of the application Microsoft Sharing App  Use of Azure Information Protection
faurejoriswww.It-channels.com
Azure Information Protection
Supplying a platform of holistic, agile, complète and flexible data
protection for the enterprise of today 
Classification Labelling Protection
Orchestration
faurejoriswww.It-channels.com
Azure Information Protection
Integration with Microsoft Office apps
• By a plug-in (current version) : Microsoft Azure Information Protection
• Will be integrated in the SDK RMS (Azure IP SDK) in the future to benefit to all integrated applications (enlightened)
• Classification of the data based on the sensibility and the addition of labels – manually or automatically – at the time of the creation or
at the time of the modification.
• Encryption of critical data and definition of rights of user if necessary.
• Simple application of the protection without interrupting the normal course of work.
Take advantage of policies for the set of the controls to be applied
• You can define a set of policies through the Azure Information Protection
• Policies define if a model RMS must be applied
• Encryption of the data + rights of user for the persons concerned
• Policies applied to the information by Azure Information Protection can be automatically applied to the data or as recommendation
which the users decide to apply or not.
Follow-up of the use of the information and the revocation of so necessary data
• You have access to a detailed follow-up and reports to see what takes place with the data shared for some more of control.
faurejoriswww.It-channels.com
Automatic classification based
on content
• Policies applied to information by Azure Information Protection
can be automatically applied to data or as a recommendation
for users to apply it to data
• You can replace a classification and may be required to provide
justification
User-initiated content
classification
• Conversely, with Azure Information Protection, a user can
choose to apply a label himself to the document, hence a
classification. This allows it to apply visual marks and control
who has access to content through RMS templates as defined
in the policy.
SECRET
CONFIDENTIAL
INTERNAL
NON RESTRICTED
PERSONAL
Labels(setofkeysandvalues)areaddedasmultiplemetadataentriestofiles(insidefilesandin
thefilesystem)
ThelabelsareinplaintextsothatothersystemslikeaDLPenginecanreadit
Authentification
Retrievepolicies(occurswheneveranOfficeinstanceisstarted)
.RetrievesRMScertificatesand
templates,theURLoftheURLserviceis
referencedinthepolicy
Azure Information Protection
faurejoriswww.It-channels.com
DEMO
• Review of Azure RMS
• Azure Information Protection
• Tracking
• …
faurejoriswww.It-channels.com
Azure Information Protection
https://portal.aadrm.com/home/download
Minimum compatibility
Work station
 Windows 7 (SP1)
 OS X 10.6.6
Mobile Devices
 Windows Phone
 iOS (iPhone / iPad / iPad Touch)
 Android
faurejoriswww.It-channels.com
Azure Information Protection
… by defining directly a protection selected by the user.
The application allows to protect documents based on
company policy security or ...
faurejoriswww.It-channels.com
Azure Information Protection
Live document's activity report
XXX
faurejoriswww.It-channels.com
Azure Information Protection
Stay in control !
 Document's activity report
 List of authorized people
 Opening date of the document
 Geographic location of document
opening
 Alert when opening is denied…
faurejoriswww.It-channels.com
Azure Information Protection
Limitations
faurejoriswww.It-channels.com
Any Questions ?
Thank you !
faurejoriswww.It-channels.com
Technical Blog
To go further…
Technical Blog – Azure section / RMS available
http://it-channels.com
MicrosoftTechNetDocumentation
http://technet.microsoft.com/en-us/dn175751
MicrosoftMSDNDocumentation
http://msdn.microsoft.com/en-
us/library/windows/desktop/dn223672(v=vs.85).aspx
BlogsGroupeproduitMicrosoftRMS
http://blogs.technet.com/b/rms/
http://blogs.msdn.com/b/rms/

Más contenido relacionado

La actualidad más candente

EMS Diagram Click Through Web
EMS Diagram Click Through WebEMS Diagram Click Through Web
EMS Diagram Click Through Web
Eric Inch
 
Enterprise Mobility+Security Overview
Enterprise Mobility+Security Overview Enterprise Mobility+Security Overview
Enterprise Mobility+Security Overview
Chris Genazzio
 
SCOM 2007 & Audit Collection Services
SCOM 2007 & Audit Collection Services SCOM 2007 & Audit Collection Services
SCOM 2007 & Audit Collection Services
OlivierMichot
 
Security As A Service
Security As A ServiceSecurity As A Service
Security As A Service
guest536dd0e
 

La actualidad más candente (20)

NIC 2017 Did you like Azure RMS? You will like Azure Information Protection e...
NIC 2017 Did you like Azure RMS? You will like Azure Information Protection e...NIC 2017 Did you like Azure RMS? You will like Azure Information Protection e...
NIC 2017 Did you like Azure RMS? You will like Azure Information Protection e...
 
Cloud Based Rights Management with Azure RMS
Cloud Based Rights Management with Azure RMSCloud Based Rights Management with Azure RMS
Cloud Based Rights Management with Azure RMS
 
Information protection & classification
Information protection & classificationInformation protection & classification
Information protection & classification
 
Azure security and Compliance
Azure security and ComplianceAzure security and Compliance
Azure security and Compliance
 
EMS Diagram Click Through Web
EMS Diagram Click Through WebEMS Diagram Click Through Web
EMS Diagram Click Through Web
 
Microsoft 365 Security and Compliance
Microsoft 365 Security and ComplianceMicrosoft 365 Security and Compliance
Microsoft 365 Security and Compliance
 
Azure information protection_datasheet_en-us
Azure information protection_datasheet_en-usAzure information protection_datasheet_en-us
Azure information protection_datasheet_en-us
 
Secure Your Cloud Environment with Azure Active Directory (AD)
Secure Your Cloud Environment with Azure Active Directory (AD)Secure Your Cloud Environment with Azure Active Directory (AD)
Secure Your Cloud Environment with Azure Active Directory (AD)
 
One name unify them all
One name unify them allOne name unify them all
One name unify them all
 
Overview of Microsoft Enterprise Mobility & Security(EMS)
Overview of Microsoft Enterprise Mobility & Security(EMS)Overview of Microsoft Enterprise Mobility & Security(EMS)
Overview of Microsoft Enterprise Mobility & Security(EMS)
 
Enterprise Mobility+Security Overview
Enterprise Mobility+Security Overview Enterprise Mobility+Security Overview
Enterprise Mobility+Security Overview
 
SPS Geneva - Azure information protection
SPS Geneva - Azure information protectionSPS Geneva - Azure information protection
SPS Geneva - Azure information protection
 
Securing your Azure Identity Infrastructure
Securing your Azure Identity InfrastructureSecuring your Azure Identity Infrastructure
Securing your Azure Identity Infrastructure
 
Secure Productive Enterprise from Microsoft and Atidan
Secure Productive Enterprise from Microsoft and AtidanSecure Productive Enterprise from Microsoft and Atidan
Secure Productive Enterprise from Microsoft and Atidan
 
SCOM 2007 & Audit Collection Services
SCOM 2007 & Audit Collection Services SCOM 2007 & Audit Collection Services
SCOM 2007 & Audit Collection Services
 
Make your Azure PaaS Deployment More Safe
Make your Azure PaaS Deployment More SafeMake your Azure PaaS Deployment More Safe
Make your Azure PaaS Deployment More Safe
 
Microsoft EMS Enterprise Mobility and Security Architecture Poster
Microsoft EMS Enterprise Mobility and Security Architecture PosterMicrosoft EMS Enterprise Mobility and Security Architecture Poster
Microsoft EMS Enterprise Mobility and Security Architecture Poster
 
NIC 2017 Azure AD Identity Protection and Conditional Access: Using the Micro...
NIC 2017 Azure AD Identity Protection and Conditional Access: Using the Micro...NIC 2017 Azure AD Identity Protection and Conditional Access: Using the Micro...
NIC 2017 Azure AD Identity Protection and Conditional Access: Using the Micro...
 
Security As A Service
Security As A ServiceSecurity As A Service
Security As A Service
 
Intro to Office 365 Security & Compliance Center
Intro to Office 365 Security & Compliance CenterIntro to Office 365 Security & Compliance Center
Intro to Office 365 Security & Compliance Center
 

Similar a From classification to protection of your data, secure your business with azure information protection - Ottawa

Spca2014 navigating clouds sp_con14_mackie
Spca2014 navigating clouds sp_con14_mackieSpca2014 navigating clouds sp_con14_mackie
Spca2014 navigating clouds sp_con14_mackie
NCCOMMS
 
EMS-HPT Template-v.1.0
EMS-HPT Template-v.1.0EMS-HPT Template-v.1.0
EMS-HPT Template-v.1.0
Huy Pham
 

Similar a From classification to protection of your data, secure your business with azure information protection - Ottawa (20)

Agile IT EMS webinar series, session 1
Agile IT EMS webinar series, session 1Agile IT EMS webinar series, session 1
Agile IT EMS webinar series, session 1
 
Azure in education (office365 summit)
Azure in education (office365 summit)Azure in education (office365 summit)
Azure in education (office365 summit)
 
Azure Cloud Services
Azure Cloud ServicesAzure Cloud Services
Azure Cloud Services
 
Securely Harden Microsoft 365 with Secure Score
Securely Harden Microsoft 365 with Secure ScoreSecurely Harden Microsoft 365 with Secure Score
Securely Harden Microsoft 365 with Secure Score
 
Understanding Microsoft Teams Security & Compliance features and plan for Gov...
Understanding Microsoft Teams Security & Compliance features and plan for Gov...Understanding Microsoft Teams Security & Compliance features and plan for Gov...
Understanding Microsoft Teams Security & Compliance features and plan for Gov...
 
Azure Compute, Networking and Storage Overview
Azure Compute, Networking and Storage OverviewAzure Compute, Networking and Storage Overview
Azure Compute, Networking and Storage Overview
 
Prestashop and Azure
Prestashop and AzurePrestashop and Azure
Prestashop and Azure
 
Spca2014 navigating clouds sp_con14_mackie
Spca2014 navigating clouds sp_con14_mackieSpca2014 navigating clouds sp_con14_mackie
Spca2014 navigating clouds sp_con14_mackie
 
EMS-HPT Template-v.1.0
EMS-HPT Template-v.1.0EMS-HPT Template-v.1.0
EMS-HPT Template-v.1.0
 
Securing Sensitive Data in Your Hybrid Cloud
Securing Sensitive Data in Your Hybrid CloudSecuring Sensitive Data in Your Hybrid Cloud
Securing Sensitive Data in Your Hybrid Cloud
 
MMS 2015: What is ems and how to configure it
MMS 2015: What is ems and how to configure itMMS 2015: What is ems and how to configure it
MMS 2015: What is ems and how to configure it
 
Security Features of different Cloud Service Models: A Review
Security Features of different Cloud Service Models: A ReviewSecurity Features of different Cloud Service Models: A Review
Security Features of different Cloud Service Models: A Review
 
I1 - Securing Office 365 and Microsoft Azure like a rockstar (or like a group...
I1 - Securing Office 365 and Microsoft Azure like a rockstar (or like a group...I1 - Securing Office 365 and Microsoft Azure like a rockstar (or like a group...
I1 - Securing Office 365 and Microsoft Azure like a rockstar (or like a group...
 
What is Microsoft Enterprise Mobility Suite and how to deploy it
What is Microsoft Enterprise Mobility Suite and how to deploy itWhat is Microsoft Enterprise Mobility Suite and how to deploy it
What is Microsoft Enterprise Mobility Suite and how to deploy it
 
CSS17: Houston - Azure Shared Security Model Overview
CSS17: Houston - Azure Shared Security Model OverviewCSS17: Houston - Azure Shared Security Model Overview
CSS17: Houston - Azure Shared Security Model Overview
 
June 2020 Microsoft 365 Need to Know Webinar
June 2020 Microsoft 365 Need to Know WebinarJune 2020 Microsoft 365 Need to Know Webinar
June 2020 Microsoft 365 Need to Know Webinar
 
IDT Replaces On-Premises Appliances with Primary Backup on AWS
 IDT Replaces On-Premises Appliances with Primary Backup on AWS IDT Replaces On-Premises Appliances with Primary Backup on AWS
IDT Replaces On-Premises Appliances with Primary Backup on AWS
 
MTUG - På tide med litt oversikt og kontroll?
MTUG - På tide med litt oversikt og kontroll?MTUG - På tide med litt oversikt og kontroll?
MTUG - På tide med litt oversikt og kontroll?
 
Why Power BI is the right tool for you
Why Power BI is the right tool for youWhy Power BI is the right tool for you
Why Power BI is the right tool for you
 
CIO Forum June Microsoft.pdf
CIO Forum June Microsoft.pdfCIO Forum June Microsoft.pdf
CIO Forum June Microsoft.pdf
 

Más de Joris Faure

Microsoft Identity Protection -- MITPro Montreal
Microsoft Identity Protection -- MITPro MontrealMicrosoft Identity Protection -- MITPro Montreal
Microsoft Identity Protection -- MITPro Montreal
Joris Faure
 

Más de Joris Faure (20)

Comment réussir sa gouvernance dans office 365 - SPS Montréal 2019
Comment réussir sa gouvernance dans office 365 - SPS Montréal 2019Comment réussir sa gouvernance dans office 365 - SPS Montréal 2019
Comment réussir sa gouvernance dans office 365 - SPS Montréal 2019
 
Office 365 : Collaborez en toute sécurité - Collab Montréal 2018
Office 365 : Collaborez en toute sécurité - Collab Montréal 2018Office 365 : Collaborez en toute sécurité - Collab Montréal 2018
Office 365 : Collaborez en toute sécurité - Collab Montréal 2018
 
Microsoft Identity Protection -- MITPro Montreal
Microsoft Identity Protection -- MITPro MontrealMicrosoft Identity Protection -- MITPro Montreal
Microsoft Identity Protection -- MITPro Montreal
 
Vous avez dit identite hybride ! -- SharePoint saturday montreal 2017
Vous avez dit identite hybride ! -- SharePoint saturday montreal   2017Vous avez dit identite hybride ! -- SharePoint saturday montreal   2017
Vous avez dit identite hybride ! -- SharePoint saturday montreal 2017
 
La fédération d'identité, quels avantages pour mon SharePoint -- Montreal
La fédération d'identité, quels avantages pour mon SharePoint -- MontrealLa fédération d'identité, quels avantages pour mon SharePoint -- Montreal
La fédération d'identité, quels avantages pour mon SharePoint -- Montreal
 
De la classification à la protection de vos données, sécurisez votre entrepri...
De la classification à la protection de vos données, sécurisez votre entrepri...De la classification à la protection de vos données, sécurisez votre entrepri...
De la classification à la protection de vos données, sécurisez votre entrepri...
 
Configuration de mim pour la synchronisation des profils avec microsoft share...
Configuration de mim pour la synchronisation des profils avec microsoft share...Configuration de mim pour la synchronisation des profils avec microsoft share...
Configuration de mim pour la synchronisation des profils avec microsoft share...
 
Configuration de MIM pour la synchronisation des profils avec Microsoft Share...
Configuration de MIM pour la synchronisation des profils avec Microsoft Share...Configuration de MIM pour la synchronisation des profils avec Microsoft Share...
Configuration de MIM pour la synchronisation des profils avec Microsoft Share...
 
Protéger vos données grâce à microsoft rms - Marocco SharePoint Days 2016
Protéger vos données grâce à microsoft rms - Marocco SharePoint Days 2016Protéger vos données grâce à microsoft rms - Marocco SharePoint Days 2016
Protéger vos données grâce à microsoft rms - Marocco SharePoint Days 2016
 
Office 365 hybride - Marocco SharePoint Days 2016
Office 365 hybride - Marocco SharePoint Days 2016Office 365 hybride - Marocco SharePoint Days 2016
Office 365 hybride - Marocco SharePoint Days 2016
 
La fédération d'identité, quels avantages pour mon SharePoint - Marocco Share...
La fédération d'identité, quels avantages pour mon SharePoint - Marocco Share...La fédération d'identité, quels avantages pour mon SharePoint - Marocco Share...
La fédération d'identité, quels avantages pour mon SharePoint - Marocco Share...
 
Office 365, retour client ! - 2SeeU
Office 365, retour client ! - 2SeeUOffice 365, retour client ! - 2SeeU
Office 365, retour client ! - 2SeeU
 
Office 365 hybride, et si on parlait retour d’expériences ! - Global Azure Bo...
Office 365 hybride, et si on parlait retour d’expériences ! - Global Azure Bo...Office 365 hybride, et si on parlait retour d’expériences ! - Global Azure Bo...
Office 365 hybride, et si on parlait retour d’expériences ! - Global Azure Bo...
 
Retour d'expérience environnement hybride - Groupe d'usagers SharePoint Montréal
Retour d'expérience environnement hybride - Groupe d'usagers SharePoint MontréalRetour d'expérience environnement hybride - Groupe d'usagers SharePoint Montréal
Retour d'expérience environnement hybride - Groupe d'usagers SharePoint Montréal
 
MDM & RMS une protection totale, sortez couvert! - SPS Montréal
MDM & RMS une protection totale, sortez couvert! - SPS MontréalMDM & RMS une protection totale, sortez couvert! - SPS Montréal
MDM & RMS une protection totale, sortez couvert! - SPS Montréal
 
Découvrez les concepts de MDM Office 365 & Intune - Evoluday
Découvrez les concepts de MDM Office 365 & Intune - EvoludayDécouvrez les concepts de MDM Office 365 & Intune - Evoluday
Découvrez les concepts de MDM Office 365 & Intune - Evoluday
 
Osez faire le premier pas vers office 365 hybridez vous! - yOS Tour Lyon
Osez faire le premier pas vers office 365 hybridez vous! - yOS Tour LyonOsez faire le premier pas vers office 365 hybridez vous! - yOS Tour Lyon
Osez faire le premier pas vers office 365 hybridez vous! - yOS Tour Lyon
 
La protection des données avec microsoft rms
La protection des données avec microsoft rmsLa protection des données avec microsoft rms
La protection des données avec microsoft rms
 
Office 365 hybride - Swiss SharePoint Club
Office 365 hybride - Swiss SharePoint ClubOffice 365 hybride - Swiss SharePoint Club
Office 365 hybride - Swiss SharePoint Club
 
Présentation de la protection des données dans SharePoint - Global Conférence...
Présentation de la protection des données dans SharePoint - Global Conférence...Présentation de la protection des données dans SharePoint - Global Conférence...
Présentation de la protection des données dans SharePoint - Global Conférence...
 

Último

Último (20)

The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
 
Tech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdfTech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdf
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Evaluating the top large language models.pdf
Evaluating the top large language models.pdfEvaluating the top large language models.pdf
Evaluating the top large language models.pdf
 

From classification to protection of your data, secure your business with azure information protection - Ottawa

  • 1. aOS 2017Tournée Canadienne Fueled by Québec Montréal Ottawa Toronto 6 Février 7 Février 8 Février 10 Février
  • 2. From classification to protection of your data, secure your business with Azure Information Protection Joris Faure Joris FAURE – MVP Enterprise Mobility Microsoft Solution Manager at SII CANADA ca.linkedin.com/in/jorisfaure @faurejoris
  • 4. faurejoriswww.It-channels.com Identity Overview Introduction to Azure Information Protection • Conceptually… • RMS • Azure Information Protection Live Demonstration • Azure Information Protection SUMMARY
  • 5. faurejoriswww.It-channels.com Identity at Microsoft Forefront Microsoft Identity Manager Identity Management Automatisation, based on rules, of identities (accounts, groups, access) Azure Active Directory Connect Identity Management between Active Directory and Azure Active Directory Azure Information Protection RMS Classification and Protection of documents Apply persistent protection within company documents: Messaging, SharePoint, Office AD Federation Services Identity Federation Allows the SSO application in web mode for the services supporting the SAML protocol
  • 6. faurejoriswww.It-channels.com Introduction challenge • You have a perimeter • You have devices to manage • Your business requires sharing sensitive data out of your control for B2B / B2C Reduce leakage of shared data with others (B2B collaboration) Isolation of sensitive data from unauthorized users Prevention of malicious workers from leaking secrets Comply with regulatory requirements 96% 94% 89% 87% Source -Microsoft
  • 7. faurejoriswww.It-channels.com Azure Information Protection Locating RMS in my information systems security project DRM : Digital Rights Management VS DLP : Data Loss Prevention Digital signature of documents (Encryption) Example : AD RMS : Active Directory Rights Management Services / Azure RMS Consists of monitoring the events of the infrastructure Example : Digital Guardian Document classification is the important requirement of a DRM or DLP project ! ! !
  • 8. faurejoriswww.It-channels.com Azure Information Protection • Information Technology Protection • Data Encryption • Transport of the right of use within the document • Prevents -> Protects against information leakage • Based on security policies • AD RMS is an infrastructure  Leverages Active Directory for identities and groups  Integration with the Microsoft environment • SharePoint • Exchange • Office • Azure RMS is a cloud service offered in Office 365 • Azure Information Protection is a cloud service offered in Office 365
  • 9. faurejoriswww.It-channels.com Azure Information Protection Microsoft – RMS Offer AD RMS (Active Directory Rights Management Services) Azure RMS Infrastructure On-Premise – Windows Server 2012 R2 (Office, PDF… Gigatrust) Infrastructure Cloud – Office 365 (Multiple extensions - protected file [pfile]) Windows Vista SP2 minimum Windows 7 minimum (SP1) / Some version of Linux (Ubuntu 14.04 / OpenSUSE 13.2 / CentOS 7) Compatible with a minimum version of Office 2007 Compatible Office 2010 minimum throught RMS / AIP sharing application Mobility: Windows RT / iOS / Android / Windows Phone Mobility: Windows RT / iOS / Android / Windows Phone Classification : File Classification Infrastructure (FCI) Classification : Azure Information Protection (AIP)
  • 10. faurejoriswww.It-channels.com Azure Information Protection Important : Using the Azure RM service with a local infrastructure ( Exchange, SharePoint …) requires deploying the RMS connector on the target infrasturcure The RMS Connector– Hybrid Infrastrcture
  • 11. faurejoriswww.It-channels.com Azure Information Protection RMS Connector Windows Azure Active Directory Synchronization Tool Exchange 2010/2013 Azure RMS Microsoft RMS Connector SharePoint 2010/2013 Active Directory
  • 13. faurejoriswww.It-channels.com Sensitive data is never sent to Rights Management Noneprotectedcontent RMS Source -Microsoft
  • 14. faurejoriswww.It-channels.com Azure Information Protection Protection of Documents and Emails Data Encryption Decryption of Data by Authorized Persons Rights: - Reading/modification - Printing - Transfer Protects source : - User - Automatic Centralized Safety Policy Workflow RMS
  • 15. faurejoriswww.It-channels.com Azure Information Protection Based on security policies Manual mode Automatic mode Integrated mode  Use a template : « Reading for all the employees »  Specify manually rights  Administration of templates since the server RMS or Azure RMS (centralization of the administration)  Use of FCI (File Classification Infrastructure) for the application of the automatic templates (local)  Use of Azure Information Protection (cloud)  Deployment of templates on the applications (Office, Exchange) and/or Azure Information Protection  SharePoint :  The protection RMS is automatically applied  Rights RMS Rights SharePoint  Use of the application Microsoft Sharing App  Use of Azure Information Protection
  • 16. faurejoriswww.It-channels.com Azure Information Protection Supplying a platform of holistic, agile, complète and flexible data protection for the enterprise of today  Classification Labelling Protection Orchestration
  • 17. faurejoriswww.It-channels.com Azure Information Protection Integration with Microsoft Office apps • By a plug-in (current version) : Microsoft Azure Information Protection • Will be integrated in the SDK RMS (Azure IP SDK) in the future to benefit to all integrated applications (enlightened) • Classification of the data based on the sensibility and the addition of labels – manually or automatically – at the time of the creation or at the time of the modification. • Encryption of critical data and definition of rights of user if necessary. • Simple application of the protection without interrupting the normal course of work. Take advantage of policies for the set of the controls to be applied • You can define a set of policies through the Azure Information Protection • Policies define if a model RMS must be applied • Encryption of the data + rights of user for the persons concerned • Policies applied to the information by Azure Information Protection can be automatically applied to the data or as recommendation which the users decide to apply or not. Follow-up of the use of the information and the revocation of so necessary data • You have access to a detailed follow-up and reports to see what takes place with the data shared for some more of control.
  • 18. faurejoriswww.It-channels.com Automatic classification based on content • Policies applied to information by Azure Information Protection can be automatically applied to data or as a recommendation for users to apply it to data • You can replace a classification and may be required to provide justification User-initiated content classification • Conversely, with Azure Information Protection, a user can choose to apply a label himself to the document, hence a classification. This allows it to apply visual marks and control who has access to content through RMS templates as defined in the policy. SECRET CONFIDENTIAL INTERNAL NON RESTRICTED PERSONAL Labels(setofkeysandvalues)areaddedasmultiplemetadataentriestofiles(insidefilesandin thefilesystem) ThelabelsareinplaintextsothatothersystemslikeaDLPenginecanreadit Authentification Retrievepolicies(occurswheneveranOfficeinstanceisstarted) .RetrievesRMScertificatesand templates,theURLoftheURLserviceis referencedinthepolicy Azure Information Protection
  • 19. faurejoriswww.It-channels.com DEMO • Review of Azure RMS • Azure Information Protection • Tracking • …
  • 20. faurejoriswww.It-channels.com Azure Information Protection https://portal.aadrm.com/home/download Minimum compatibility Work station  Windows 7 (SP1)  OS X 10.6.6 Mobile Devices  Windows Phone  iOS (iPhone / iPad / iPad Touch)  Android
  • 21. faurejoriswww.It-channels.com Azure Information Protection … by defining directly a protection selected by the user. The application allows to protect documents based on company policy security or ...
  • 23. faurejoriswww.It-channels.com Azure Information Protection Stay in control !  Document's activity report  List of authorized people  Opening date of the document  Geographic location of document opening  Alert when opening is denied…
  • 27. faurejoriswww.It-channels.com Technical Blog To go further… Technical Blog – Azure section / RMS available http://it-channels.com MicrosoftTechNetDocumentation http://technet.microsoft.com/en-us/dn175751 MicrosoftMSDNDocumentation http://msdn.microsoft.com/en- us/library/windows/desktop/dn223672(v=vs.85).aspx BlogsGroupeproduitMicrosoftRMS http://blogs.technet.com/b/rms/ http://blogs.msdn.com/b/rms/