SlideShare una empresa de Scribd logo
1 de 21
Office 365 Advanced Security Hardening with
cFocus Software
May 20, 2017
Welcome! Here’s the Agenda:
• Introduction
• The Best Way to Protect Your Data
• WannaCry & Office 365
• Office 365 Security Overview & Configuration
Recommendations
• Q&A
Office365AdvancedSecurityHardeningwithcFocusSoftware
Hi! My name is Jasson Walker, Jr.
• President of cFocus Software Incorporated
• I have a few certifications:
 Microsoft Certified Solutions Expert (MCSE) – Cloud Platform
 Microsoft Certified Professional - SharePoint
 Certified Information Systems Security Professional (CISSP)
 Certified Ethical Hacker (CEH)
 Certified Penetration Tester (CPT)
Office365AdvancedSecurityHardeningwithcFocusSoftware
cFocus Software Incorporated specializes in:
• Microsoft Cloud Consulting Services
 Office 365
 SharePoint Online
 Microsoft Azure
• Risk Management Framework compliance
Check out our blog at https://cfocussoftware.com/blog/
Office365AdvancedSecurityHardeningwithcFocusSoftware
Question:
What’s the best way to protect your data?
Office365AdvancedSecurityHardeningwithcFocusSoftware
Answer:
Shut everything off!
Office365AdvancedSecurityHardeningwithcFocusSoftware
Question:
What’s the second best way to protect your data?
Office365AdvancedSecurityHardeningwithcFocusSoftware
3-Part Answer:
#1: User Education
#2: Defense in Breadth (not Depth)
#3: Continuous Monitoring
Office365AdvancedSecurityHardeningwithcFocusSoftware
Let’s apply these principles to mitigate WannaCry
• What is WannaCry?
 Ransomware, infected 230,000+ computers in 130 countries
 Encrypts hard disk, demands $300 in Bitcoin
 Virtually all unpatched Windows OSs are vulnerable
 Microsoft released a patch for it (MS17-010)
 Threat disabled on 5/15/2017, but can always resurface
 Go to cFocus blog for more info: http://bit.ly/2qCkRhl
Office365AdvancedSecurityHardeningwithcFocusSoftware
#1: User Education mitigates human vulnerabilities
 Educate yourself first!
 Educate user community about threats like WannaCry
 User Quarterly security refresher courses
 Anti-phishing simulators (SecurityIQ by InfoSec Institute which is free):
https://securityiq.infosecinstitute.com
 91% of cyberattacks start with a phishing email
Office365AdvancedSecurityHardeningwithcFocusSoftware
#2: Defense In Breadth mitigates product vulnerabilities
 Secure Score
 Security & Compliance Center
 Data Loss Prevention
 Threat Management
 Reporting
 Advanced Security Management
 Advanced Threat Protection
Office365AdvancedSecurityHardeningwithcFocusSoftware
#3: Continuous Monitoring shortens the attack time…
 Secure Score
 Security & Compliance reporting
 Data Loss Prevention
 Threat Intelligence
Because at some point, you will be attacked! 
Office365AdvancedSecurityHardeningwithcFocusSoftware
The default Office 365 configuration is not enough.
Therefore, you must configure it yourself.
Office365AdvancedSecurityHardeningwithcFocusSoftware
OK, so here are some config. recommendations:
• Secure Score
 Weekly performance of activities to increase Secure Score is highly
recommended
 Multi-factor authentication for global/non-global admins is a must!
 Recommended weekly report checks also a must
 Increase the target score slider to include a few more defense in breadth
activities
Office365AdvancedSecurityHardeningwithcFocusSoftware
OK, so here are some config. recommendations:
• DKIM/DMARC/SPF
 Ensure that all three are enabled for the default domain not the
onmicrosoft.com domain
 Also, check Spoof mail report weekly (requires E5 or Advanced Threat
Protection SKU)
Office365AdvancedSecurityHardeningwithcFocusSoftware
OK, so here are some config. recommendations:
• Exchange Online
 Weekly checks on all mailboxes with last login date (PowerShell script)
 Enable common attachments type filter & notifications for
protectionmalware
 Verify list of allowed/blocked IPs under protectionconnection filter
 Verify block/allow list in spam filter policy
Office365AdvancedSecurityHardeningwithcFocusSoftware
OK, so here are some config. recommendations:
• Threat Management (requires E5)
 Check the dashboard and individual reports weekly
Office365AdvancedSecurityHardeningwithcFocusSoftware
OK, so here are some config. recommendations:
• Advanced Security Management
 Set up policies for anomaly detection, admin activity from a non-admin IP,
& mass downloads by a single user
 Verify App permissions
 Check Activity Log
Office365AdvancedSecurityHardeningwithcFocusSoftware
OK, so here are some config. recommendations:
• Data Loss Prevention
 At minimum, set up a DLP policy for mitigating access to documents that
have Personally Identifiable Information (PII)
Office365AdvancedSecurityHardeningwithcFocusSoftware
OK, so here are some config. recommendations:
• SharePoint Online
 Always use groups!
 Produce document that lists all SharePoint users and permissions assigned
to each user
Office365AdvancedSecurityHardeningwithcFocusSoftware
Thank you!
• Any Questions?
Office365AdvancedSecurityHardeningwithcFocusSoftware

Más contenido relacionado

La actualidad más candente

La actualidad más candente (16)

Adaptive RiskPro
Adaptive RiskProAdaptive RiskPro
Adaptive RiskPro
 
SQL Server: Security
SQL Server: SecuritySQL Server: Security
SQL Server: Security
 
Office 365 Saturday Europe 2014 - Microsoft Azure : Central component of your...
Office 365 Saturday Europe 2014 - Microsoft Azure : Central component of your...Office 365 Saturday Europe 2014 - Microsoft Azure : Central component of your...
Office 365 Saturday Europe 2014 - Microsoft Azure : Central component of your...
 
Prevent Hacking: 10 Steps to Secure your WordPress Site
Prevent Hacking: 10 Steps to Secure your WordPress SitePrevent Hacking: 10 Steps to Secure your WordPress Site
Prevent Hacking: 10 Steps to Secure your WordPress Site
 
DevSecOps - CrikeyCon 2017
DevSecOps - CrikeyCon 2017DevSecOps - CrikeyCon 2017
DevSecOps - CrikeyCon 2017
 
Securing the hybrid environment with Microsoft Cloud App Security
Securing the hybrid environment with Microsoft Cloud App SecuritySecuring the hybrid environment with Microsoft Cloud App Security
Securing the hybrid environment with Microsoft Cloud App Security
 
January 2020 Microsoft 365 Need to Know Webinar
January 2020 Microsoft 365 Need to Know WebinarJanuary 2020 Microsoft 365 Need to Know Webinar
January 2020 Microsoft 365 Need to Know Webinar
 
Msp saner 2.0
Msp saner 2.0Msp saner 2.0
Msp saner 2.0
 
Microsoft Teams - Governance A - Z
Microsoft Teams - Governance A - ZMicrosoft Teams - Governance A - Z
Microsoft Teams - Governance A - Z
 
Microsoft Next 2014 - Cloud platform session 4 - Transform the datacenter v. ...
Microsoft Next 2014 - Cloud platform session 4 - Transform the datacenter v. ...Microsoft Next 2014 - Cloud platform session 4 - Transform the datacenter v. ...
Microsoft Next 2014 - Cloud platform session 4 - Transform the datacenter v. ...
 
Add response headers policy
Add response headers policyAdd response headers policy
Add response headers policy
 
Chef Automating Everything-AWS-PubSec-SAO-WashDC_2018
Chef Automating Everything-AWS-PubSec-SAO-WashDC_2018Chef Automating Everything-AWS-PubSec-SAO-WashDC_2018
Chef Automating Everything-AWS-PubSec-SAO-WashDC_2018
 
SolarWinds Federal Webinar: Technical Update & New Feature Demo May 16, 2017
SolarWinds Federal Webinar: Technical Update & New Feature Demo May 16, 2017SolarWinds Federal Webinar: Technical Update & New Feature Demo May 16, 2017
SolarWinds Federal Webinar: Technical Update & New Feature Demo May 16, 2017
 
Best pratices reliability & scalability on Azure
Best pratices reliability & scalability on AzureBest pratices reliability & scalability on Azure
Best pratices reliability & scalability on Azure
 
WordPress Developers Recommend Sucuri Plugin For Security
WordPress Developers Recommend Sucuri Plugin For SecurityWordPress Developers Recommend Sucuri Plugin For Security
WordPress Developers Recommend Sucuri Plugin For Security
 
Intro to Puppet Enterprise Webinar 07.27.2017
Intro to Puppet Enterprise Webinar 07.27.2017Intro to Puppet Enterprise Webinar 07.27.2017
Intro to Puppet Enterprise Webinar 07.27.2017
 

Similar a SPS Baltimore 2017 - Office 365 Security Hardening with cFocus Software

00 - Microsoft 365 Business Secure Deployment Toolkit - Kickoff and Technical...
00 - Microsoft 365 Business Secure Deployment Toolkit - Kickoff and Technical...00 - Microsoft 365 Business Secure Deployment Toolkit - Kickoff and Technical...
00 - Microsoft 365 Business Secure Deployment Toolkit - Kickoff and Technical...
ssuser2bcf91
 

Similar a SPS Baltimore 2017 - Office 365 Security Hardening with cFocus Software (20)

Sol 03 - Office 365 Advanced Security Hardening with cFocus Software
Sol 03 - Office 365 Advanced Security Hardening with cFocus SoftwareSol 03 - Office 365 Advanced Security Hardening with cFocus Software
Sol 03 - Office 365 Advanced Security Hardening with cFocus Software
 
SmartProfiler for Active Directory Office 365 and Azure Virtual Desktop Asses...
SmartProfiler for Active Directory Office 365 and Azure Virtual Desktop Asses...SmartProfiler for Active Directory Office 365 and Azure Virtual Desktop Asses...
SmartProfiler for Active Directory Office 365 and Azure Virtual Desktop Asses...
 
Introduction to Apex Triggers
Introduction to Apex TriggersIntroduction to Apex Triggers
Introduction to Apex Triggers
 
Office 365 Security - Its 2am do you know whos in your office 365
Office 365 Security - Its 2am do you know whos in your office 365Office 365 Security - Its 2am do you know whos in your office 365
Office 365 Security - Its 2am do you know whos in your office 365
 
Rencore Webinar: Advanced Security Management within Office 365 with Liam Cleary
Rencore Webinar: Advanced Security Management within Office 365 with Liam ClearyRencore Webinar: Advanced Security Management within Office 365 with Liam Cleary
Rencore Webinar: Advanced Security Management within Office 365 with Liam Cleary
 
The Market Opportunity for Office 365 Data Protection
The Market Opportunity for Office 365 Data ProtectionThe Market Opportunity for Office 365 Data Protection
The Market Opportunity for Office 365 Data Protection
 
Microsoft Security Advice ISSA Slides.pptx
Microsoft Security Advice ISSA Slides.pptxMicrosoft Security Advice ISSA Slides.pptx
Microsoft Security Advice ISSA Slides.pptx
 
July 2021 Microsoft 365 Need to Know Webinar
July 2021 Microsoft 365 Need to Know WebinarJuly 2021 Microsoft 365 Need to Know Webinar
July 2021 Microsoft 365 Need to Know Webinar
 
00 - Microsoft 365 Business Secure Deployment Toolkit - Kickoff and Technical...
00 - Microsoft 365 Business Secure Deployment Toolkit - Kickoff and Technical...00 - Microsoft 365 Business Secure Deployment Toolkit - Kickoff and Technical...
00 - Microsoft 365 Business Secure Deployment Toolkit - Kickoff and Technical...
 
December 2019 Microsoft 365 Need to Know Webinar
December 2019 Microsoft 365 Need to Know WebinarDecember 2019 Microsoft 365 Need to Know Webinar
December 2019 Microsoft 365 Need to Know Webinar
 
October 2021 Microsoft 365 Need to Know Webinar
October 2021 Microsoft 365 Need to Know WebinarOctober 2021 Microsoft 365 Need to Know Webinar
October 2021 Microsoft 365 Need to Know Webinar
 
SharePoint Saturday Nashville: Microsoft 365 Certifications Overview
SharePoint Saturday Nashville: Microsoft 365 Certifications OverviewSharePoint Saturday Nashville: Microsoft 365 Certifications Overview
SharePoint Saturday Nashville: Microsoft 365 Certifications Overview
 
M365 Training + Certification Guide_081822.pdf
M365 Training + Certification Guide_081822.pdfM365 Training + Certification Guide_081822.pdf
M365 Training + Certification Guide_081822.pdf
 
Early adoption program guide
Early adoption program guideEarly adoption program guide
Early adoption program guide
 
O365Con18 - Compliance Manager - Tomislav Lulic
O365Con18 - Compliance Manager - Tomislav LulicO365Con18 - Compliance Manager - Tomislav Lulic
O365Con18 - Compliance Manager - Tomislav Lulic
 
Using the right tools to keep control of your Office 365 deployments
Using the right tools to keep control of your Office 365 deploymentsUsing the right tools to keep control of your Office 365 deployments
Using the right tools to keep control of your Office 365 deployments
 
March 2021 Microsoft 365 Need to Know Webinar
March 2021 Microsoft 365 Need to Know WebinarMarch 2021 Microsoft 365 Need to Know Webinar
March 2021 Microsoft 365 Need to Know Webinar
 
Assessing Your Salesforce DevOps Practices
Assessing Your Salesforce DevOps PracticesAssessing Your Salesforce DevOps Practices
Assessing Your Salesforce DevOps Practices
 
21.06.2017 - KYOS Breakfast Event
21.06.2017 - KYOS Breakfast Event 21.06.2017 - KYOS Breakfast Event
21.06.2017 - KYOS Breakfast Event
 
SharePoint Saturday Ottawa - How secure is my data in office 365?
SharePoint Saturday Ottawa - How secure is my data in office 365?SharePoint Saturday Ottawa - How secure is my data in office 365?
SharePoint Saturday Ottawa - How secure is my data in office 365?
 

Último

Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
soniya singh
 
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
@Chandigarh #call #Girls 9053900678 @Call #Girls in @Punjab 9053900678
 
Call Girls In Sukhdev Vihar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Sukhdev Vihar Delhi 💯Call Us 🔝8264348440🔝Call Girls In Sukhdev Vihar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Sukhdev Vihar Delhi 💯Call Us 🔝8264348440🔝
soniya singh
 
Hot Service (+9316020077 ) Goa Call Girls Real Photos and Genuine Service
Hot Service (+9316020077 ) Goa  Call Girls Real Photos and Genuine ServiceHot Service (+9316020077 ) Goa  Call Girls Real Photos and Genuine Service
Hot Service (+9316020077 ) Goa Call Girls Real Photos and Genuine Service
sexy call girls service in goa
 
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort ServiceCall Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
9953056974 Low Rate Call Girls In Saket, Delhi NCR
 
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Sheetaleventcompany
 

Último (20)

Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
 
Hot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night Stand
Hot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night StandHot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night Stand
Hot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night Stand
 
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
 
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
 
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
 
Russian Call Girls Pune (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
Russian Call Girls Pune  (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...Russian Call Girls Pune  (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
Russian Call Girls Pune (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
 
Call Girls In Sukhdev Vihar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Sukhdev Vihar Delhi 💯Call Us 🔝8264348440🔝Call Girls In Sukhdev Vihar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Sukhdev Vihar Delhi 💯Call Us 🔝8264348440🔝
 
Top Rated Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
Top Rated  Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...Top Rated  Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
Top Rated Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
 
Real Men Wear Diapers T Shirts sweatshirt
Real Men Wear Diapers T Shirts sweatshirtReal Men Wear Diapers T Shirts sweatshirt
Real Men Wear Diapers T Shirts sweatshirt
 
VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...
VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...
VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...
 
Pune Airport ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready...
Pune Airport ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready...Pune Airport ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready...
Pune Airport ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready...
 
Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...
Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...
Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...
 
Hot Service (+9316020077 ) Goa Call Girls Real Photos and Genuine Service
Hot Service (+9316020077 ) Goa  Call Girls Real Photos and Genuine ServiceHot Service (+9316020077 ) Goa  Call Girls Real Photos and Genuine Service
Hot Service (+9316020077 ) Goa Call Girls Real Photos and Genuine Service
 
Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...
Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...
Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...
 
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
 
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort ServiceCall Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
 
VVVIP Call Girls In Connaught Place ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Connaught Place ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...VVVIP Call Girls In Connaught Place ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Connaught Place ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
 
Russian Call Girls in %(+971524965298 )# Call Girls in Dubai
Russian Call Girls in %(+971524965298  )#  Call Girls in DubaiRussian Call Girls in %(+971524965298  )#  Call Girls in Dubai
Russian Call Girls in %(+971524965298 )# Call Girls in Dubai
 
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
 
WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)
 

SPS Baltimore 2017 - Office 365 Security Hardening with cFocus Software

  • 1. Office 365 Advanced Security Hardening with cFocus Software May 20, 2017
  • 2. Welcome! Here’s the Agenda: • Introduction • The Best Way to Protect Your Data • WannaCry & Office 365 • Office 365 Security Overview & Configuration Recommendations • Q&A Office365AdvancedSecurityHardeningwithcFocusSoftware
  • 3. Hi! My name is Jasson Walker, Jr. • President of cFocus Software Incorporated • I have a few certifications:  Microsoft Certified Solutions Expert (MCSE) – Cloud Platform  Microsoft Certified Professional - SharePoint  Certified Information Systems Security Professional (CISSP)  Certified Ethical Hacker (CEH)  Certified Penetration Tester (CPT) Office365AdvancedSecurityHardeningwithcFocusSoftware
  • 4. cFocus Software Incorporated specializes in: • Microsoft Cloud Consulting Services  Office 365  SharePoint Online  Microsoft Azure • Risk Management Framework compliance Check out our blog at https://cfocussoftware.com/blog/ Office365AdvancedSecurityHardeningwithcFocusSoftware
  • 5. Question: What’s the best way to protect your data? Office365AdvancedSecurityHardeningwithcFocusSoftware
  • 7. Question: What’s the second best way to protect your data? Office365AdvancedSecurityHardeningwithcFocusSoftware
  • 8. 3-Part Answer: #1: User Education #2: Defense in Breadth (not Depth) #3: Continuous Monitoring Office365AdvancedSecurityHardeningwithcFocusSoftware
  • 9. Let’s apply these principles to mitigate WannaCry • What is WannaCry?  Ransomware, infected 230,000+ computers in 130 countries  Encrypts hard disk, demands $300 in Bitcoin  Virtually all unpatched Windows OSs are vulnerable  Microsoft released a patch for it (MS17-010)  Threat disabled on 5/15/2017, but can always resurface  Go to cFocus blog for more info: http://bit.ly/2qCkRhl Office365AdvancedSecurityHardeningwithcFocusSoftware
  • 10. #1: User Education mitigates human vulnerabilities  Educate yourself first!  Educate user community about threats like WannaCry  User Quarterly security refresher courses  Anti-phishing simulators (SecurityIQ by InfoSec Institute which is free): https://securityiq.infosecinstitute.com  91% of cyberattacks start with a phishing email Office365AdvancedSecurityHardeningwithcFocusSoftware
  • 11. #2: Defense In Breadth mitigates product vulnerabilities  Secure Score  Security & Compliance Center  Data Loss Prevention  Threat Management  Reporting  Advanced Security Management  Advanced Threat Protection Office365AdvancedSecurityHardeningwithcFocusSoftware
  • 12. #3: Continuous Monitoring shortens the attack time…  Secure Score  Security & Compliance reporting  Data Loss Prevention  Threat Intelligence Because at some point, you will be attacked!  Office365AdvancedSecurityHardeningwithcFocusSoftware
  • 13. The default Office 365 configuration is not enough. Therefore, you must configure it yourself. Office365AdvancedSecurityHardeningwithcFocusSoftware
  • 14. OK, so here are some config. recommendations: • Secure Score  Weekly performance of activities to increase Secure Score is highly recommended  Multi-factor authentication for global/non-global admins is a must!  Recommended weekly report checks also a must  Increase the target score slider to include a few more defense in breadth activities Office365AdvancedSecurityHardeningwithcFocusSoftware
  • 15. OK, so here are some config. recommendations: • DKIM/DMARC/SPF  Ensure that all three are enabled for the default domain not the onmicrosoft.com domain  Also, check Spoof mail report weekly (requires E5 or Advanced Threat Protection SKU) Office365AdvancedSecurityHardeningwithcFocusSoftware
  • 16. OK, so here are some config. recommendations: • Exchange Online  Weekly checks on all mailboxes with last login date (PowerShell script)  Enable common attachments type filter & notifications for protectionmalware  Verify list of allowed/blocked IPs under protectionconnection filter  Verify block/allow list in spam filter policy Office365AdvancedSecurityHardeningwithcFocusSoftware
  • 17. OK, so here are some config. recommendations: • Threat Management (requires E5)  Check the dashboard and individual reports weekly Office365AdvancedSecurityHardeningwithcFocusSoftware
  • 18. OK, so here are some config. recommendations: • Advanced Security Management  Set up policies for anomaly detection, admin activity from a non-admin IP, & mass downloads by a single user  Verify App permissions  Check Activity Log Office365AdvancedSecurityHardeningwithcFocusSoftware
  • 19. OK, so here are some config. recommendations: • Data Loss Prevention  At minimum, set up a DLP policy for mitigating access to documents that have Personally Identifiable Information (PII) Office365AdvancedSecurityHardeningwithcFocusSoftware
  • 20. OK, so here are some config. recommendations: • SharePoint Online  Always use groups!  Produce document that lists all SharePoint users and permissions assigned to each user Office365AdvancedSecurityHardeningwithcFocusSoftware
  • 21. Thank you! • Any Questions? Office365AdvancedSecurityHardeningwithcFocusSoftware