security
614 TopicsForce users to "entra register" their devices
Hi, is it possible to force user to register their devices when they log in with their company account to any other device than company owned? I tested on my private smarthphone. Logged in as normal user with company account and my device did not show up in entra as "Microsoft Entra registered" Any ideas? Thanks31Views0likes1CommentCompliance licenses at tenant level
Hi, We are a small organization of about 200 employees, and we have following requirements. DLP policies configuration at Exchange, OneDrive, SharePoint BYOD security Users should not be able to send files outside the org And so on as we evaluate We already have M365 Business Premium. However, after researching we figured out that M365 Business premium will alone not solve our requirements. May be compliance license will. We want to apply security policies at tenant level in our organization but definitely do not want every user to get licenses as this will be expensive for us and there is no requirement at all for our users. The question is, Is there a way to solve the above scenario?51Views0likes2CommentsHidden Group and Hidden Group Membership
Hi everyone! I have come across a requirement where the client would like to use an excel spreadsheet, a service account and application registration to manage group membership for a confidential group. They would like to create a group from which the members cannot leave, see other team members and cannot see the group itself. Now, I have the concept of the flow with me but for the life of me, I cannot get around to finding/configuring a group that meets the requirement. Have you guys come across this sort of scenario? Group Configuration: Users should not be able to view the group Users should not be able to view members of the group Users should not be able to leave the group Thanks in advance.57Views0likes2CommentsOffice 365 Backup
Iam Looking For: Find a backup solution for our Office 365 data such as SharePoint/OneDrive content, e-mails, calendars, contacts, notes, tasks etc. ! The harddrives of the machine definitly need to be encrypted. Not sure of synology can do that reliably (LUKS?). Synology had some security issues in the past, but they might have been only relevant if they are exposed to the internet. I think we have two options: Backup in the office on encrypted drives with very restricted access (SSH?) Encrypt backup and upload it to S3 (not sure if there's a tool for that) I'm fine with both. Is there an open source tool that can mirror Office 365 on a local machine? (Linux) is the Synology tool proprietary?3KViews0likes5CommentsAzure Sentinel Incident Severity Mapping
Hi, So Sentinel categorizes its incidents as "Low, Medium or High". However, a typical SOC might have incidents ranging from P1-P5. I'm curious how have other organizations mapped the 3 Sentinel severitys to the a typical incident priority rating of P1-P5 (so 5 categories). We'd like to automate the logging of Sentinel tickets in our ISMS system, but how to map 3 into 5 priorities? Thank you, SK7.4KViews0likes3CommentsEncryption confusion
I do light Office 365 admin for a number of clients, always under Office 365 Business Premium subscriptions. I'm confused about encryption, that either does exist, or not, and where it does and doesn't. I read the following link, and as is often the case, there's plenty about the technology, but nothing about where it is implemented, namely, which subscription level you need to get it. https://docs.microsoft.com/en-us/microsoft-365/compliance/email-encryption So bottom line: if a small business under Office 365 Business Premium asks the question: "Is our email encrypted?", I find myself unable to be certain 100%. I do know it is encrypted in transit between email servers, and presumably it is encrypted from sender to the Office 365 servers, due to Outlook having that Security tab under Account Settings with a (greyed out) checkmark saying "encrypt data between Microsoft Outlook and Microsoft Exchange". If so, this means we're good from the sender, through to the far end of the Office 365 infrastructure, leaving only the recipient server and client end in question. Is that all correct? Any pointers to a real description of this stuff and not the confusing (yet technically interesting) type of link as the one I put in above would be appreciated! 🙂 Thank you.Solved3.6KViews0likes7CommentsOffice 365 Home DKIM Configuration
Hi, I have an Office 365 home account and have configured a personalised email address using GoDaddy. I have configured SPF on the GoDaddy Domain that appears to work. Is it possible to setup DKIM too for my configuration? All online instructions I have seen refer to Office 365 Business accounts and in particularly using the Admin Centre to configure this, (which Office Home doesn't have access to). Any help you can provide would be appreciated. Thanks in advance. Regards, Simon20KViews4likes30CommentsO365 - EU and China
Hi Worldwide Org - based in EU - they have a Tenant - and are about to migrate all users personal files from fileservers to OD4B - (into the EU data center) However there's a subset of users that resides in China - and apparently there's some China regulations saying data "must" reside inside China - (china users connection to the EU Tenant/OneDrive are very slow) so how do I solve this "architecture" in the best way possible? Multi-geo is not an option as China aren't supported. Does the Company create a SharePoint Farm in China and let the users in China have their OD4B on that - what about collaboration on documents, ediscovery etc. etc. between EU/China users in those scenarios? Does the company create a separate Tenant inside China and initiate the B2B capabilities in the EU tenant? How have others solved this?4KViews0likes2CommentsEmail alert when roles are adjusted
Hi all, I've had a look around but can't find anything up to date that would help my issue. What we're after is an email alert whenever a 365 role is changed (user added or removed). Looking in Defender, there's only an alert for an Exchange Administrator change. Is there anyone who has something in production that would do this job? Kind regards Tom92Views0likes4CommentsRestricted Content Discovery
SharePoint Advanced Management includes a feature called "Restricted Content Discovery" aka RCD. The FAQs mention that: Restricted Content Discovery only affects tenant-wide search (SharePoint home, Office.com, Bing) and Microsoft 365 Copilot But then it goes on to mention: Restricted Content Discovery doesn't remove content from the tenant search index. and: Restricted Content Discovery is a site-level property. I completely understand that its intended use is to give organisations time to review and/or audit permissions and deploy access controls while onboarding Copilot in a safe manner. My focus is custom search solutions and custom apps that use search and should respect the RCD property. Being a property and the content remains in the index, it could be interpreted that RCD feature only works in the named services i.e. SharePoint Home, Office.com, Bing and Microsoft Copilot and it does not apply in Micrsoft Search, custom organisation-wide Search solutions e.g. using PnP-Search, API calls using the Graph etc. Is that the case? Also can the property be queried and retrieved using the Search API or is it limited to PowerShell?279Views0likes2Comments