Thibault CHÂTIRON

Cybersecurity

Azure Sentinel – Watchlist Enhancements

Azure Sentinel Watchlists provides the ability to quickly import IP addresses, file hashes, etc. from csv files into your Azure Sentinel workspace. Then utilize the watchlist name/value pairs for joining and filtering for use in alert rules, threat hunting, workbooks, notebooks and for general queries. Watchlist Updating Functionality The new watchlist UI encompasses the following …

Microsoft Cloud App Security – Release 203

Expose verified publisher indicating in O365 OAuth appsCloud App Security now surfaces whether a publisher of an Office 365 OAuth app has been verified by Microsoft to enable higher app trust. This feature is in a gradual rollout. For more information, see Working with the OAuth app page. Azure Active Directory Cloud App Security adminA Cloud …

Microsoft Cloud App Security – Release 200, 201, and 202

Authentication Context (Step-Up Authentication) in public previewMicrosoft has added the ability to protect users working with proprietary and privileged assets by requiring Azure AD Conditional Access policies to be reassessed in the session. For example, if a change in IP address is detected because an employee in a highly sensitive session has moved from the …

Microsoft Defender for Office 365: Introducing Advanced Delivery for Phishing Simulations and SecOps Mailboxes

Microsoft is introducing a new capability, Advanced Delivery, for the configuration of third-party phishing simulation campaigns and delivery of messages to security operations (SecOps) mailboxes. Admins will now be able to explicitly configure for the following scenarios and ensure messages configured as part of these scenarios are handled correctly across product experiences: Third-Party Phish simulation …

Microsoft Graph privacy controls to fully replace the classic Office Delve control in May

In August 2020, Microsoft announced that Microsoft Graph privacy controls would be available in the fourth quarter. These Microsoft Graph privacy controls allow administrators to more granularly configure the visibility of Graph-derived insights which includes documents and sites across Microsoft 365 apps and services. Microsoft also announced a six-month transition period before the new controls …

Azure AD Default access token lifetime Variation

Microsoft is making some changes to the default lifetime of Access Tokens. The default lifetime of Access Tokens issued by Azure AD will change from a static value of 60 minutes to a value between 60-90 minutes (75 minutes on average). Microsoft is making this change to provide a smoother experience across the service. When …

Support for viewing MIP protected PDF files protected in other business tenants [Public Preview]

Microsoft has introduced additional support for MIP protected PDF’s in Microsoft Edge. This is currently in preview. What is the feature? If your organization has Microsoft Information Protection enabled, Microsoft Edge could open MIP protected PDF files which were protected in the same tenant seamlessly; across Windows and Mac. The support is now extended to …

Microsoft Cloud App Security – Release 199

Service Health Dashboard availabilityThe enhanced Cloud App Security Service Health Dashboard is now available within the Microsoft 365 Admin portal for users with Monitor service health permissions. Learn more about Microsoft 365 Admin roles. In the dashboard, you can configure notifications, allowing relevant users to stay updated with the current Cloud App Security status. To learn how to configure email …

Microsoft Cloud App Security – Release 198

Exclusion of Azure Active Directory groups entities from discoveryMicrosoft has added the ability to exclude discovered entities based on imported Azure Active Directory groups. Excluding AAD groups will hide all discovery-related data for any users in these groups. For more information, see Exclude entities. API connector support for ServiceNow Orlando and Paris versionsMicrosoft has added support …

New release (2.11.58) of AIP UL [General Availability]

AIP UL client 2.11.58 is now GA and available to download https://aka.ms/AIPClient What’s new ? This version includes the following new features, fixes, and enhancements for the unified labeling scanner and client: Scanner usage logging in the Windows event log Scanner diagnostics tool improvements Improved scanner details output Updates for the scanner’s supported information types …

New release (2.11.57) of AIP UL [General Availability]

Today, Microsoft announced that AIP UL client 2.11.57 is now GA and available to download https://aka.ms/AIPClient What’s new ? This version includes the following new features, fixes, and enhancements for the unified labeling scanner and client: Scanner usage logging in the Windows event log Scanner diagnostics tool improvements Improved scanner details output Updates for the …

License check for Advanced eDiscovery

Starting April 16, 2021, all customers using Advanced eDiscovery must have the appropriate licensing in order to continue creating new cases in the solution.  You have to maintain an Advanced Compliance or E5 license. Key points: Timing: We will begin rolling this April 16, 2021 Action: review and ensure you have the appropriate licensing How …

New Endpoint DLP features [Public Preview]

Prerequisites Licensing Microsoft 365 E5 Microsoft 365 A5 (EDU) Microsoft 365 E5 compliance Microsoft 365 A5 compliance Microsoft 365 E5 information protection and governance Microsoft 365 A5 information protection and governance Hardware/software Your devices must be running Windows 10 x64 build 1809 or later. The device must have Antimalware Client Version is 4.18.2101.9 or later …

Microsoft Cloud App Security – Release 197

Status page deprecation noticeOn April 29, Cloud App Security will deprecate the service health status page, replacing it with the Service Health Dashboard within the Microsoft 365 Admin portal. The change aligns Cloud App Security with other Microsoft services and provides an enhanced service overview.  Only users with Monitor service health permissions can access the dashboard. For more information, …

Microsoft Cloud App Security – Release 195 and 196

Enhanced Shadow IT discovery with Microsoft Defender for EndpointMicrosoft has further improved the Defender for Endpoint integration by leveraging enhanced signals for the Defender agent, providing more accurate app discovery and organizational user context. To benefit from the latest enhancements, make sure your organizational endpoints are updated with the latest Windows 10 updates: KB4601383: Windows …

Temporary Access Pass [Public Preview]

Temporary Access Pass is a game-changer that completes the end-to-end passwordless onboarding experience for your users. Microsoft created Temporary Access Pass to address many of your passwordless account onboarding and recovery scenarios. For a user to truly be passwordless, they shouldn’t know or use their password, and instead use passwordless authentication methods and recovery if …

Update your Apple Configurator profile if Enrollments are Failing with Setup Assistant

Note : This only impacts the iOS/iPadOS device enrollment using Apple Configurator. Only setup assistant workflow is impacted – all other iOS/iPad enrollment workflows are not affected. There was a certificate mismatch between Apple Configurator profiles and the Intune certificate issuing service for iOS/iPadOS enrollment through this setup experience. Existing devices remain enrolled as they …

Audit log improvements introduced in AIP Unified Labeling client 2.8.85

Clarification about audit log improvements introduced in AIP Unified Labeling client 2.8.85, that allow clearer visibility and alignment with Office native audit logs: Audit logs for access events from the unified labeling client are now sent only when users open labeled or protected files, providing a clearer indication of user access. Information types are no …

Microsoft Cloud App Security – Release 192, 193, and 194

Updates to Policies pageMicrosoft has updated the Policies page, adding a tab for every policy category. Microsoft also added an All policies tab to give you a complete list of all your policies. For more information about the policy categorization, see Policy types. Enhanced Office 365 OAuth apps exportMicrosoft has enhanced the Office 365 OAuth …

New release (2.9.116) of AIP UL [General Availability]

Microsoft released AIP UL version 2.9.116 This is maintenance release that includes bug fixes only. It will correct bug that I talked about on a previous post : https://thibaultchatiron.fr/2021/02/03/problem-on-the-latest-version-2-9-111-of-the-aip-client/ For reminder, the issue was for the scenarios where users were not able to view protected files as expected in the following scenarios: When protected files …