Security

ADFS – Resolve authentication issue faster

Authentication is a key to access corporate resources, hosted either on-premises (you can use ADFS to authenticate against Exchange to access your mailbox) or in the cloud (Office 365, Azure, Salesforce…). While Microsoft is working hard to make authentication process to his services a little bit easier for end-users (password synch, seamless single sign-on…), you […]

ADFS – Resolve authentication issue faster Read More »

Azure – Azure DDoS Protection Service

A new security feature has been added to Azure called Azure DDoS Protection Service. This new service is integrated with Virtual Networks to protect you against DDoS attacks. It comes into 2 service levels: Azure DDoS Protection Basic Service with no additional cost associated and does not requires any configuration or application changes Azure DDoS

Azure – Azure DDoS Protection Service Read More »

Azure – New version of the Azure Information Protection Client

A new version (1.10.56.0) of the Azure Information Protection Client has been released and is available for download at https://www.microsoft.com/en-us/download/details.aspx?id=53018. As part of this new release, you can now: enable recommended classification also for Outlook hide the Do Not Forward button in Outlook hide the custom permission options to end-user integrates with Office 365 DLP

Azure – New version of the Azure Information Protection Client Read More »

Windows 10 – Windows Defender Advanced Threat Protection

Windows Defender Advanced Threat Protection (ATP) is a security functionality built in Windows 10 to help detecting, investigating and protecting against threats, introduced with Windows 10 build 1607 (or known as Anniversary Build). In this post, I’m going to implement ATP integrated with SCCM Current Branch (you can request a trial for ATP here http://aka.ms/register-wdatp)

Windows 10 – Windows Defender Advanced Threat Protection Read More »

Azure – RMS Protection Tool is reaching the end of life

The Azure RMS Protection tool is reaching his end of life (and support) on February 10th, 2018 If you are still using it, start upgrading your RMS client to Azure Information Protection client (current GA version available when writing this post is 1.7.210 available at https://aka.ms/aipclient)

Azure – RMS Protection Tool is reaching the end of life Read More »

Azure – Just In Time Virtual Machine access (preview)

A new security feature has been made available in preview on Azure: Just In Time Access for virtual  machine. While access and behavior of resources hosted on Azure are monitored by Microsoft to avoid malicious activities, there is still risks to get your resources, and in this case your virtual machines, being vulnerable. The Just

Azure – Just In Time Virtual Machine access (preview) Read More »

Azure – Do not configure Enhanced Protected Mode by GPO to get Azure AD Seamless SSO to work

A colleague of mine shared his experience while trying to make Azure AD Seamless SSO to work. As reminder Azure AD Seamless SSO is still under preview; Azure Active Directory Seamless Single Sign On (Azure AD Seamless SSO) provides single sign-on for users signing in on their corporate desktops connected to the corporate network. When

Azure – Do not configure Enhanced Protected Mode by GPO to get Azure AD Seamless SSO to work Read More »

Office 365 – You can mark actions from Secure Score as managed by third party

As you may know Office 365 Secure Score is a tool to help you securing your Office 365 tenant by checking your configuration and compare against best practices and recommendations. Microsoft has updated the Secure Score to allow you define recommended/proposed actions as managed by third party. This will help by keeping the recommended action

Office 365 – You can mark actions from Secure Score as managed by third party Read More »

Azure AD Connect – You need to upgrade your Azure AD Connect if using password write-back

Microsoft has released a security bulletin related Azure AD Connect. If you are using password write-back you need to upgrade it to the version 1.1.553.0 (released this June) urgently as you are vulnerable to a vulnerability which could allow attackers to reset passwords. Details about the security bulletin here: https://technet.microsoft.com/library/security/4033453.aspx?f=255&MSPPError=-2147217396 Download the latest version of

Azure AD Connect – You need to upgrade your Azure AD Connect if using password write-back Read More »

Azure – Azure AD Privileged Identity Management approval workflow now in preview

Microsoft has released a new features for Azure AD Privileged Identity Management (Azure AD PIM). This feature is currently in preview. You can now define an approval workflow before any role privileges are granted. To do so you need to edit the role you want to enable the approval workflow; to do so Access the

Azure – Azure AD Privileged Identity Management approval workflow now in preview Read More »