Security

Office 365 – Advanced Threats Protection, Safe Links is coming to Office documents

As you may already know Safe Links is a security feature on Office 365 which rewrites URL’s embedded into emails to check if these URL’s are safe which comes with Office 365 E5 (or if you have bought the add-on Advanced Threats Protection). Now, Safe Links is coming to Office documents, performing the same ‘on […]

Office 365 – Advanced Threats Protection, Safe Links is coming to Office documents Read More »

Office 365 – RMS encrypted messages can now be decrypted on the fly with eDiscovery

A new functionality for eDiscovery is now available and enabled by default to automatically decrypt RMS encrypted messages when you are exporting the search result.   The decryption capability is automatically added to the eDiscovery Manager group. RMS encrypted messages are decrypted ONLY when exported as individual message; if you export your search result to

Office 365 – RMS encrypted messages can now be decrypted on the fly with eDiscovery Read More »

Office 365 – Script to automate Office 365 Role membership

UPDATE: script update to enable Azure MFA and correct a bug in the Office 365 role update function Office 365 Role membership management is one of the few workload you can not manage using groups. To automate the membership of these roles I have created a script. The script is comparing Active Directory group membership

Office 365 – Script to automate Office 365 Role membership Read More »

Office 365 – Secure Score is now in preview

Security is a key point when moving / using a cloud service. Microsoft has made (and still making) lot of investment to ensure data and account security and help customers to get the most of it. A new step has just been done with the release in preview of Secure Score; a toolset integrated with

Office 365 – Secure Score is now in preview Read More »

ADFS 4 – Enable device authentication method

With ADFS 4, you can easily enable device authentication as authentication method. This authentication method was already available in ADFS 3 but only as additional authentication method; with ADFS 4 this becomes also available as primary authentication method.   Upgrade Active Directory Federation schema This step is required if already have deployed a previous version

ADFS 4 – Enable device authentication method Read More »

ADFS 4 – Enable Azure MFA as authentication method and/or multi factor authentication for ADFS

One of the improvements with ADFS 4 (on Windows Server 2016) is the integration of Azure MFA as multi factor authentication method as well as primary authentication method; you can still use the certificate based or the Azure MFA Server (see http://blog.hametbenoit.info/2014/08/18/azure-use-windows-azure-multi-factor-authentication-to-secure-your-on-premises-application-and-with-your-adfs/) for the multi factor methods. If you want to enable Azure MFA with

ADFS 4 – Enable Azure MFA as authentication method and/or multi factor authentication for ADFS Read More »

Windows Server 2016 – ADFS 4 idpinitiatedsignon is disabled by default

As you may know, a quick way to test your ADFS deployment is to access the idpinitiatedsignon sign page. As usual, I tried it after deploying my new ADFS 4.0 server and… got this error message The resource you are trying to access is not available. Contact your administrator for more information.   And the

Windows Server 2016 – ADFS 4 idpinitiatedsignon is disabled by default Read More »

Windows Server 2016 – ADFS 4.0 now support certificate authentication on port 443

You may already know that ADFS 3.0 (on Windows Server 2012 R2) already supports certificate authentication BUT using a different communication port than 443 (in fact 49443). With ADFS 4.0 (on Windows Server 2016), the certificate authentication can now use the 443 communication port, making thing easier to implement multi factor authentication using user certificate.

Windows Server 2016 – ADFS 4.0 now support certificate authentication on port 443 Read More »

Windows 10 – BitLocker Recovery Key for Azure AD Joined devices

This procedure applies only for Windows 10 devices which have been configured as Azure AD Joined. From time to time, you may need to access advanced recovery options for your Windows 10 device but these options may failed to work because you are using BitLocker to encrypt your drive. You may already know the procedure

Windows 10 – BitLocker Recovery Key for Azure AD Joined devices Read More »

Azure – Azure Information Protection Public Preview

UPDATE:  In general availability in Sept. 15 th Microsoft is providing a new security features set using Azure RMS called Azure Information Protection. The idea is to help securing and classifying your data; making things easier for end-user. Don’t forget one the advantages of Azure RMS is you can share RMS protected documents/emails with the

Azure – Azure Information Protection Public Preview Read More »