ExploringConditional
Access to content storedin
Office365
Who am I?
Who am I?
What is this session about?
Access Layers in Microsoft 365
Encryption
RBAC
Conditional Access
Azure AD PIM
PAM in Office 365
Prevent unauthorized
illegitimateaccess
Govern
legitimate
access
Role & risk based
Standing access
(Permissions)
JIT & JEA
With Approval
(Elevationof Privilege)
RBAC & Conditional Access
RBAC
Conditional Access
Role & risk based
Standing access
(Permissions)
Authentication Versus Authorisation
Authentication Versus Authorisation
When are they accessing?
What do we mean by conditional access?
When are they accessing?
What do we mean by conditional access?
When are they accessing?
What do we mean by conditional access?
Additional options – EM+S E5
Additional options EM+S
What can be achieved with ADFS
What can be achieved with ADFS
What can be achieved with ADFS
What can be achieved with ADFS
What CAN’T be achieved with ADFS?
@tenant.onmicrosoft.com
What can be achieved with E1/E3/E5
What can be achieved with E1/E3/E5
What can be achieved with E1/E3/E5
What can be achieved with E1/E3/E5
What can be achieved with E1/E3/E5
What can be achieved with E1/E3/E5
What can be achieved with E1/E3/E5
What can be achieved with E1/E3/E5
What can be achieved with E1/E3/E5
What can be achieved with E1/E3/E5
What can be achieved with E1/E3/E5
MFA Pro Tip!
SharePointPerimeterBlocking&MFA
What can be achieved with EM+S E3
What can be achieved with EM+S E3*
SharePointSiteCollectionScoped
Policies
Site Classification Label
Central Admin Control
BRK3101 – Securing your SharePoint and OneDrive
content with access policies and labels – Sesha Mani
Watch the Ignite Session for Demos
What can be achieved with EM+S E5
What can be achieved with EM+S E5
RiskBasedPolicies,AIP&
CloudAppSecurity
Access Layers in Microsoft 365
Encryption
RBAC
Conditional Access
Azure AD PIM
PAM in Office 365
Prevent unauthorized
illegitimateaccess
Govern
legitimate
access
Role & risk based
Standing access
(Permissions)
JIT & JEA
With Approval
(Elevationof Privilege)
PIM & PAM
Azure AD PIM
PAM in Office 365
JIT & JEA
With Approval
(Elevationof Privilege)
Comparing PIM/PAM
Requires EM+S E5 (Or Azure AD P2)
Permits Role based control
Available for 32 Admin Roles
Available for Azure Resources
Ignite – BRK3248
Person Focussed
GA Announced 25/09 @ Ignite
Requires Office 365 E5 (or Advanced
Compliance Sku)
Permits TASK/ROLE based control
Only available for EXCHANGE
initially.
Ignite – BRK3222
Task Focussed
Azure PIM Office 365 PAM
PIMinaction
Configuring Office 365 PAM
Configuring Office 365 PAM
Configuring Office 365 PAM
Configuring Office 365 PAM
Configuring Office 365 PAM
Configuring Office 365 PAM
Configuring Office 365 PAM
Configuring Office 365 PAM
PAMinaction
Useful Resources
Access Control Policies
Access Control Policies
AD Risk Events
https://aka.ms/mfasetup
Docs
Docs
Thank you
O365Con18 - Exploring Conditional Access to content stored in Office 365 - Paul Hunt

O365Con18 - Exploring Conditional Access to content stored in Office 365 - Paul Hunt