Book Image

Microsoft 365 Security, Compliance, and Identity Administration

By : Peter Rising
5 (1)
Book Image

Microsoft 365 Security, Compliance, and Identity Administration

5 (1)
By: Peter Rising

Overview of this book

The Microsoft 365 Security, Compliance, and Identity Administration is designed to help you manage, implement, and monitor security and compliance solutions for Microsoft 365 environments. With this book, you’ll first configure, administer identity and access within Microsoft 365. You’ll learn about hybrid identity, authentication methods, and conditional access policies with Microsoft Intune. Next, you’ll discover how RBAC and Azure AD Identity Protection can be used to detect risks and secure information in your organization. You’ll also explore concepts such as Microsoft Defender for endpoint and identity, along with threat intelligence. As you progress, you’ll uncover additional tools and techniques to configure and manage Microsoft 365, including Azure Information Protection, Data Loss Prevention (DLP), and Microsoft Defender for Cloud Apps. By the end of this book, you’ll be well-equipped to manage and implement security measures within your Microsoft 365 suite successfully.
Table of Contents (25 chapters)
1
Part 1: Implementing and Managing Identity and Access
7
Part 2: Implementing and Managing Threat Protection
13
Part 3: Implementing and Managing Information Protection
17
Part 4: Managing Compliance Features in Microsoft 365

Managing and monitoring MDI

You can now start managing and monitoring the MDI service. From a management perspective, this means configuring settings and features such as Entity tags and Excluded entities. From a monitoring perspective, it is important to review MDI regularly by looking at Health Issues from the General section of the MDI settings page.

Some of these capabilities are presented in greater detail next

Entity tags

MDI allows you to apply Entity tags to sensitive accounts. The status of the tags that you define enables MDI to detect things such as sensitive group modification and lateral movement. Additionally, honeytoken accounts may be configured to trap malicious actors and trigger an alert.

You can configure the three following types of entity tags in MDI:

  • Sensitive tags
  • Honeytoken tags
  • Exchange server tags

The following sections explain these tags in detail.

Sensitive tags

You can use the Sensitive tag to identify assets of...