Book Image

Microsoft 365 Security, Compliance, and Identity Administration

By : Peter Rising
5 (1)
Book Image

Microsoft 365 Security, Compliance, and Identity Administration

5 (1)
By: Peter Rising

Overview of this book

The Microsoft 365 Security, Compliance, and Identity Administration is designed to help you manage, implement, and monitor security and compliance solutions for Microsoft 365 environments. With this book, you’ll first configure, administer identity and access within Microsoft 365. You’ll learn about hybrid identity, authentication methods, and conditional access policies with Microsoft Intune. Next, you’ll discover how RBAC and Azure AD Identity Protection can be used to detect risks and secure information in your organization. You’ll also explore concepts such as Microsoft Defender for endpoint and identity, along with threat intelligence. As you progress, you’ll uncover additional tools and techniques to configure and manage Microsoft 365, including Azure Information Protection, Data Loss Prevention (DLP), and Microsoft Defender for Cloud Apps. By the end of this book, you’ll be well-equipped to manage and implement security measures within your Microsoft 365 suite successfully.
Table of Contents (25 chapters)
1
Part 1: Implementing and Managing Identity and Access
7
Part 2: Implementing and Managing Threat Protection
13
Part 3: Implementing and Managing Information Protection
17
Part 4: Managing Compliance Features in Microsoft 365

Implementing Azure AD dynamic group membership

Before diving into the principles of Azure AD dynamic groups, it is important to take a step back and ensure you have an overall appreciation of the methods available for assigning access rights to your users in Azure AD. These methods are as follows:

  • Direct assignment: Permissions to Azure AD resources are granted by manually assigning access for the resource to an Azure AD object that has a credential.
  • Group assignment: Permissions to Azure AD resources are granted by manually assigning access for the resource to an Azure AD group containing a set of Azure AD user objects. These objects are added or removed from the group manually.
  • Rule-based assignment: Permissions to resources are granted by dynamically assigning users to a group. The rules for membership are defined based on specific user object attributes (such as the department field).
  • External authority assignment: Permissions to resources are granted by creating...