Educause Security Discussion mailing list archives

Re : [SECURITY] M365 Users' Group -August 13th: Microsoft Cloud App Security


From: Ghassan Salem <gs37 () AUB EDU LB>
Date: Wed, 11 Aug 2021 06:40:56 +0000

Dear John:
Where can we find the recording of the previous session?

Best,
 Ghassan Salem


-------- Message original --------
De : John Ramsey <000001cd0b5a1098-dmarc-request () LISTSERV EDUCAUSE EDU>
Date : mar. 10 août 2021 à 23:54
À : SECURITY () LISTSERV EDUCAUSE EDU
Objet : [SECURITY] M365 Users' Group -August 13th: Microsoft Cloud App Security
Good afternoon,
Friendly reminder that there is a M365 Users’ Group session scheduled for this Friday, August 13th from 1:00-3:00pm 
EST.  This third session will cover Microsoft Cloud App Security (located at  
https://studentclearinghouse.portal.cloudappsecurity.com/#/dashboard<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fstudentclearinghouse.portal.cloudappsecurity.com%2F%23%2Fdashboard&data=04%7C01%7Cgs37%40AUB.EDU.LB%7C7f9e0cbb8aa54bdb993708d95c40fb14%7Cc7ba5b1a41b643e9a1206ff654ada137%7C1%7C1%7C637642256444449557%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=3buOKD7BgDPFCYz1YJC8aPDIhwxQ6UMgLAiqYMhhOiU%3D&reserved=0>
   -Replace NSC’s domain with your domain.)  This provides feedback on where users connect and how you can quickly via 
automation not allow access to high risk areas or apps.  I will record this session, similar to what we did last month 
for anybody that can’t make it.  Location is 
https://studentclearinghouse.webex.com/meet/joramsey<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fstudentclearinghouse.webex.com%2Fmeet%2Fjoramsey&data=04%7C01%7Cgs37%40AUB.EDU.LB%7C7f9e0cbb8aa54bdb993708d95c40fb14%7Cc7ba5b1a41b643e9a1206ff654ada137%7C1%7C1%7C637642256444449557%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=%2BRTCJYaqMhu6x%2BXz6FBk2ajwiUuDInnRjAnmW3%2FNzu0%3D&reserved=0>.
  As a warning order, there is a lot to cover here so there is a good chance we won’t finish and might conclude in a 
second future session.  We’ve had about 700 attendees so far since the first session in January.  Please feel free 
invite key staff that might benefit from the demonstrations.
High level agenda is below.

  *   Microsoft Cloud App Security and what it accomplishes.  
https://docs.microsoft.com/en-us/cloud-app-security/what-is-cloud-app-security<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fcloud-app-security%2Fwhat-is-cloud-app-security&data=04%7C01%7Cgs37%40AUB.EDU.LB%7C7f9e0cbb8aa54bdb993708d95c40fb14%7Cc7ba5b1a41b643e9a1206ff654ada137%7C1%7C1%7C637642256444459517%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=xAyqKUS3RTwylr38L1eClQ3Eej4XA4HOzEjMkE559ok%3D&reserved=0>
  *   Dashboard
  *   Discover
     *   Cloud Discovery Dashboard
     *   Continuous Report
     *   Discovered Apps
     *   Cloud App Catalog
     *   Create Snapshot Report (important for Win 10 users)
  *   Investigate
  *   Control
  *   Alerts
  *   Settings.  We’ll dive into each and what they accomplish.
  *   Conditional Access to Sanction/Unsanctioned Apps or locations
  *   Q&A


Please don’t hesitate to reach out with any questions at any time.  If you wish to join the M365 Users’ group, send a 
subscription request from a .edu email address to m365-sec-join () lists ren-isac net<mailto:m365-sec-join () lists 
ren-isac net>.  You should receive notification of your approval within a few days of the request.   While REN-ISAC is 
hosting this email list, you do not have to be a member to participate. All interested parties with a valid .edu email 
address are invited. Please note, list participants are not considered members of REN-ISAC and are not vetted in the 
traditional manner, and acceptance into the mailing list does not confer REN-ISAC membership status. 

John


John Ramsey, Chief Information Security Officer
National Student Clearinghouse
Certified: CISSP, CISM, PMP, CSSLP, CRISC, CGEIT
2300 Dulles Station Blvd., Suite 220
Herndon, VA 20171
703.742.4428 | 
studentclearinghouse.org<https://eur03.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.studentclearinghouse.org%2F&data=04%7C01%7Cgs37%40AUB.EDU.LB%7C7f9e0cbb8aa54bdb993708d95c40fb14%7Cc7ba5b1a41b643e9a1206ff654ada137%7C1%7C1%7C637642256444459517%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=TjCoyXdqzr3cmyvX96yXpAB9e3Lb%2FnsvrQxoWnw0aVk%3D&reserved=0>
LinkedIn<https://eur03.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fnational-student-clearinghouse&data=04%7C01%7Cgs37%40AUB.EDU.LB%7C7f9e0cbb8aa54bdb993708d95c40fb14%7Cc7ba5b1a41b643e9a1206ff654ada137%7C1%7C1%7C637642256444469467%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=ZdTafo3VhDlMSvw5d42EpBXCkKnbNYPxPL9ofNFpaYA%3D&reserved=0>
 | 
Twitter<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Ftwitter.com%2Fnsclearinghouse&data=04%7C01%7Cgs37%40AUB.EDU.LB%7C7f9e0cbb8aa54bdb993708d95c40fb14%7Cc7ba5b1a41b643e9a1206ff654ada137%7C1%7C1%7C637642256444469467%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=4nFnF%2BYQg%2BQPJwPuoV8sQ2Bhw%2F%2FT6M1KCowNR3ccl3A%3D&reserved=0>
 | 
Facebook<https://eur03.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.facebook.com%2FNSClearinghouse&data=04%7C01%7Cgs37%40AUB.EDU.LB%7C7f9e0cbb8aa54bdb993708d95c40fb14%7Cc7ba5b1a41b643e9a1206ff654ada137%7C1%7C1%7C637642256444469467%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=g8%2BEyGg49uut8vJ45j0xhLx1Ovlc77g4kl4Q%2F955dek%3D&reserved=0>
 | 
Blog<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.studentclearinghouse.org%2Fnscblog%2F&data=04%7C01%7Cgs37%40AUB.EDU.LB%7C7f9e0cbb8aa54bdb993708d95c40fb14%7Cc7ba5b1a41b643e9a1206ff654ada137%7C1%7C1%7C637642256444479421%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=VCZnv%2FsafSefzRMMga2SviVdi2J9jZ7CHl5Ax3bOk6Y%3D&reserved=0>
 | 
Instagram<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.instagram.com%2FNSClearinghouse%2F&data=04%7C01%7Cgs37%40AUB.EDU.LB%7C7f9e0cbb8aa54bdb993708d95c40fb14%7Cc7ba5b1a41b643e9a1206ff654ada137%7C1%7C1%7C637642256444479421%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=vpL%2FeFU2EeNgAPQ7%2F%2BA%2BzTsQHnmo6%2Fosy0nIglnmzns%3D&reserved=0>

Serving Education Since 1993

This message is proprietary to the National Student Clearinghouse, is intended only for the addressee and may contain 
confidential or privileged information. If you receive this message in error, please contact the sender and delete all 
copies.



 Future sessions:
2021

  *   June 11th.  Microsoft 365 Security Center.  This is an overview of Windows Defender, settings, and most widely 
used components with the “biggest bang for the buck.”  
https://security.microsoft.com/homepage<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsecurity.microsoft.com%2Fhomepage&data=04%7C01%7Cgs37%40AUB.EDU.LB%7C7f9e0cbb8aa54bdb993708d95c40fb14%7Cc7ba5b1a41b643e9a1206ff654ada137%7C1%7C1%7C637642256444479421%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=aykEOGPxIN6U19C8%2FSYrUN4nJ%2B4Q%2FDhh60bnU%2FJjG%2B8%3D&reserved=0>
  *   July 16th . Microsoft Defender for Identity (aka Azure ATP).   
https://www-nslc-org.atp.azure.com/<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww-nslc-org.atp.azure.com%2F&data=04%7C01%7Cgs37%40AUB.EDU.LB%7C7f9e0cbb8aa54bdb993708d95c40fb14%7Cc7ba5b1a41b643e9a1206ff654ada137%7C1%7C1%7C637642256444489392%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=QBjZ0cogVO0JQZ1r3ks9qbWU9gwHCMENpoFJck4SOWI%3D&reserved=0>
  (Replace NSC’s domain with your domain.)  This touches on the automated security and reporting of the domain 
controllers, AKA the “keys to the kingdom”.
  *   August 13th.  Microsoft Cloud App Security.  
https://studentclearinghouse.portal.cloudappsecurity.com/#/dashboard<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fstudentclearinghouse.portal.cloudappsecurity.com%2F%23%2Fdashboard&data=04%7C01%7Cgs37%40AUB.EDU.LB%7C7f9e0cbb8aa54bdb993708d95c40fb14%7Cc7ba5b1a41b643e9a1206ff654ada137%7C1%7C1%7C637642256444489392%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=5WDkw9w844%2F7bxzTmmHJPJG1YW2FfsWECmP%2FHnkXa90%3D&reserved=0>
   (Replace NSC’s domain with your domain.)  This provides feedback on where users connect and how you can quickly via 
automation not allow access to high risk areas.
  *   September 10th.   Azure Security (which comes with Microsoft 365.)  
https://portal.azure.com/#home<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fportal.azure.com%2F%23home&data=04%7C01%7Cgs37%40AUB.EDU.LB%7C7f9e0cbb8aa54bdb993708d95c40fb14%7Cc7ba5b1a41b643e9a1206ff654ada137%7C1%7C1%7C637642256444499340%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=mWxaUy5Vbt1wWLD1D4TngqHT5JFzBsrNrHYcft4OJms%3D&reserved=0>
  We will look at policies for risky users, risky sign ins, and how to automate access control to counter High risks.
  *   October 8th.  Microsoft Compliance Manager and DLP
  *   November 12th.   Deep Dive into Microsoft Defender for Endpoint, presented by John Taylor, Deputy CISO, JHU and 
JHM.
  *   December 10th.

2022

  *   January 21st (this is deviation from second Friday.)
  *   February 11th.
  *   March 11th.
  *   April 8th.
  *   May 13th.

 Difference between E3/A3 and E5/A5 licensing:

  *   Microsoft 365 Enterprise | Microsoft Licensing 
Resources<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.microsoft.com%2Fen-us%2Flicensing%2Fproduct-licensing%2Fmicrosoft-365-enterprise%3Factivetab%3Dm365-enterprise%3Aprimaryr5&data=04%7C01%7Cgs37%40AUB.EDU.LB%7C7f9e0cbb8aa54bdb993708d95c40fb14%7Cc7ba5b1a41b643e9a1206ff654ada137%7C1%7C1%7C637642256444499340%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=vVC6tePRgYnmqmzAJKpdLb%2BX2ZcZ7beCtA%2BIccDcUSs%3D&reserved=0>
  *   Enterprise Mobility and Security Pricing Options 
(microsoft.com)<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.microsoft.com%2Fen-us%2Fmicrosoft-365%2Fenterprise-mobility-security%2Fcompare-plans-and-pricing&data=04%7C01%7Cgs37%40AUB.EDU.LB%7C7f9e0cbb8aa54bdb993708d95c40fb14%7Cc7ba5b1a41b643e9a1206ff654ada137%7C1%7C1%7C637642256444499340%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=p7ytJnmG7FnNDYFi9%2Bg3ONnl3AamSm3jvt0yJpf66Bc%3D&reserved=0>
  *   Compare Office 365 Enterprise | 
Microsoft<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.microsoft.com%2Fen-us%2Fmicrosoft-365%2Fenterprise%2Fcompare-office-365-plans%3Fef_id%3Dad1fb9ae3053173c2bbbd908aa2e3e45%3AG%3As%26OCID%3DAID2100137_SEM_ad1fb9ae3053173c2bbbd908aa2e3e45%3AG%3As%26lnkd%3DBing_O365SMB_Brand%26msclkid%3Dad1fb9ae3053173c2bbbd908aa2e3e45&data=04%7C01%7Cgs37%40AUB.EDU.LB%7C7f9e0cbb8aa54bdb993708d95c40fb14%7Cc7ba5b1a41b643e9a1206ff654ada137%7C1%7C1%7C637642256444509297%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=fiYdaP426ifRyQexpX0i4n%2FLd0utFxYHrYWN7MxmoQ8%3D&reserved=0>
  *   Enterprise Mobility and Security | Microsoft 
Security<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.microsoft.com%2Fen-us%2Fsecurity%2Fbusiness%2Fenterprise-mobility-security&data=04%7C01%7Cgs37%40AUB.EDU.LB%7C7f9e0cbb8aa54bdb993708d95c40fb14%7Cc7ba5b1a41b643e9a1206ff654ada137%7C1%7C1%7C637642256444509297%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=BBUZxxwJB4eu6qD5ZftUzfEjnzRcoE5rL7Btl3r8lwE%3D&reserved=0>


-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-
- Do not delete or change any of the following text. -

Join my Webex Personal Room meeting.
Join 
meeting<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fstudentclearinghouse.webex.com%2Fmeet%2Fjoramsey&data=04%7C01%7Cgs37%40AUB.EDU.LB%7C7f9e0cbb8aa54bdb993708d95c40fb14%7Cc7ba5b1a41b643e9a1206ff654ada137%7C1%7C1%7C637642256444509297%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=aQY199v0tmpsjyp%2Bn8%2Bu5S%2B9UOXcbyDydEnoD0wz37I%3D&reserved=0>

Meeting link: 
https://studentclearinghouse.webex.com/meet/joramsey<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fstudentclearinghouse.webex.com%2Fmeet%2Fjoramsey&data=04%7C01%7Cgs37%40AUB.EDU.LB%7C7f9e0cbb8aa54bdb993708d95c40fb14%7Cc7ba5b1a41b643e9a1206ff654ada137%7C1%7C1%7C637642256444519254%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=Q8rPCTzElUNB1jD9NQUJGlg%2BYFge%2Fet7Onx%2BhWma8Qo%3D&reserved=0>

Meeting number (access code): 790 211 691

Join by phone

Tap to call in from a mobile device (attendees only)

1-866-469-3239<tel:1-866-469-3239,,*01*790211691##*01*> USA Toll Free

+1-650-429-3300<tel:+1-650-429-3300,,*01*790211691##*01*> USA Toll
Global call-in numbers 
<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fstudentclearinghouse.webex.com%2Fstudentclearinghouse%2Fglobalcallin.php%3FserviceType%3DMC%26eventID%3D895104342%26tollFree%3D1&data=04%7C01%7Cgs37%40AUB.EDU.LB%7C7f9e0cbb8aa54bdb993708d95c40fb14%7Cc7ba5b1a41b643e9a1206ff654ada137%7C1%7C1%7C637642256444519254%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=s3t7zjgpAMRgBzBf%2BpIKoulK94WXA22VN0N1X0a%2FgMQ%3D&reserved=0>
 | Toll-free calling 
restrictions<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.webex.com%2Fpdf%2Ftollfree_restrictions.pdf&data=04%7C01%7Cgs37%40AUB.EDU.LB%7C7f9e0cbb8aa54bdb993708d95c40fb14%7Cc7ba5b1a41b643e9a1206ff654ada137%7C1%7C1%7C637642256444529209%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=KMXxzzk9V71%2BiBhUzv7cPOLglsRT6vrYL5Rrlwjh5Rk%3D&reserved=0>

Join from a video conferencing system or application

Dial joramsey () studentclearinghouse webex com<sip:joramsey () studentclearinghouse webex com>

Skype joramsey.studentclearinghouse () lync webex com<sip:joramsey.studentclearinghouse () lync webex com>

You can also dial 173.243.2.68 and enter your meeting number.

© 2021 Cisco Systems, Inc. and/or its affiliates. All rights reserved. 2.4.0.0





**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://www.educause.edu/community<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&data=04%7C01%7Cgs37%40AUB.EDU.LB%7C7f9e0cbb8aa54bdb993708d95c40fb14%7Cc7ba5b1a41b643e9a1206ff654ada137%7C1%7C1%7C637642256444529209%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=w3AoJeq2T%2F7kNM7UO4mDB1jfspH9j%2FqfM36Mamos%2Fbk%3D&reserved=0>

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community

Current thread: