Keen to check for 'abnormal' user behaviours? Microsoft talks insider risk, AWS imports and compliance at infosec shindig RSA

Before you remove the mote from thy hacker's eye, remove the beam from the eyes of your, er, Teams


RSA As IBM's crew cancels their hotel rooms, Microsoft's infosec staffers are still set to attend the decades-old RSA conference and pulled the covers off a raft of security releases and previews for the event today.

The clocks strike 13 as Insider Risk Management is released

We spoke to Microsoft 365 Senior Director, Alym Rayani, about compliance and insider risk at last year's Ignite event.

Four months on, and the company has decided the product is ready for prime-time with the release to general availability of Microsoft Insider Risk Management and Communication Compliance. For Microsoft 365, naturally.

The gimlet glare of Insider Risk Management will use the likes of Graph to gaze over Office, Windows and Azure, as well as casting an eye over non-MS services such as SAP SuccessFactors and Workday via connectors. File activity, "communications sentiment" and "abnormal" user behaviours will be detected by the vaguely creepy service and passed onto HR (or whoever the workflow reckons is most appropriate.)

The data will include a timeline to show trends, context and history for the identified user. By default, the display names are anonymised.

As with all these things, the devil is in the detail and to get the most out of the new Orwellian Monitoring Insider Risk Management tools companies will have to ponder their processes – just slapping on some software and expecting it to do a bandaid on secret seepage isn't going to fly. It is, however, relatively easy to get started on the platform; there are no pesky agents to install nor audit events to configure. There are also three new policy templates: "Departing employee data theft", "Data leaks" and the exciting "Offensive language in email."

The "machine learning" used to spot naughty words has found its way into the Communication Compliance functionality too, which was also made Generally Available. Monitoring corporate communications such as Teams Messages or Bloomberg chats, as well as email, the system will keep an ear out for offensive language and threats and trigger workflows accordingly.

We can think of at least one corporate that could probably have benefited from such a thing. Alas, that particular aircraft has long since left the runway before the departure gate could be closed.

Microsoft Loves Linux (Security)

As well as widening the preview of Microsoft Threat Protection, a system aimed at a more automated response to threats, the gang has also extended the cross-platform support for Microsoft Defender Advanced Threat Protection (ATP) to include a whole bunch of Linux distributions.

Teased at last year's Ignite (skip to around the 14-minute mark for the full "sneak peek" experience), RHEL 7+, CentOS Linux 7+, Ubuntu 16 LTS, or higher LTS, SLES 12+, Debian 9+, and Oracle EL 7 all get some loving from Microsoft's AV boffins. Users can expect a full command line experience as well as AV, while basic alerts and machine information will show up in the Defender Security Center.

The functionality remains in preview for the time being and will be joined by additional security capabilities for iOS and Android devices.

Azure Sentinel: Give us your tired, your poor, your AWS CloudTrail logs

Having nudged Azure Sentinel into the light at last year's RSA event Microsoft is giving its security information event management (SIEM) platform a buffing with some new toys.

First up are connectors for the likes of Forcepoint and Squadra as well as one for Azure Security Center for IoT. The latter is particularly interesting since it means IoT data workloads from Azure IoT Hub-managed deployments can be shovelled into Azure Sentinel. The information will allow those who have bought into the Microsoft worldview to have a decent chance of spotting threats in a converged network.

As well as adding resources (via GitHub, of course) Microsoft is will also not be charging customers for importing AWS CloudTrail logs from 24 February 2020 to 30 June 2020. AWS CloudTrail allows users of Amazon's cloud to track their AWS account. With customers using multiple clouds, Microsoft's hope is that its SIEM platform will become a one-stop shop for security monitoring. And if Madam decides that Madam prefers her cloud to be Azure, well, we doubt the Redmond gnomes would demur.

Azure activity logs, Office 365 audit logs and Microsoft 365 security alerts can already be ingested for free. ®

Broader topics


Other stories you might like

  • Azure issues not adequately fixed for months, complain bug hunters
    Redmond kicks off Patch Tuesday with a months-old flaw fix

    Updated Two security vendors – Orca Security and Tenable – have accused Microsoft of unnecessarily putting customers' data and cloud environments at risk by taking far too long to fix critical vulnerabilities in Azure.

    In a blog published today, Orca Security researcher Tzah Pahima claimed it took Microsoft several months to fully resolve a security flaw in Azure's Synapse Analytics that he discovered in January. 

    And in a separate blog published on Monday, Tenable CEO Amit Yoran called out Redmond for its lack of response to – and transparency around – two other vulnerabilities that could be exploited by anyone using Azure Synapse. 

    Continue reading
  • Start using Modern Auth now for Exchange Online
    Before Microsoft shutters basic logins in a few months

    The US government is pushing federal agencies and private corporations to adopt the Modern Authentication method in Exchange Online before Microsoft starts shutting down Basic Authentication from the first day of October.

    In an advisory [PDF] this week, Uncle Sam's Cybersecurity and Infrastructure Security Agency (CISA) noted that while federal executive civilian branch (FCEB) agencies – which includes such organizations as the Federal Communications Commission, Federal Trade Commission, and such departments as Homeland Security, Justice, Treasury, and State – are required to make the change, all organizations should make the switch from Basic Authentication.

    "Federal agencies should determine their use of Basic Auth and migrate users and applications to Modern Auth," CISA wrote. "After completing the migration to Modern Auth, agencies should block Basic Auth."

    Continue reading
  • Wi-Fi hotspots and Windows on Arm broken by Microsoft's latest patches
    Only way to resolve is a rollback – but update included security fixes

    Updated Microsoft's latest set of Windows patches are causing problems for users.

    Windows 10 and 11 are affected, with both experiencing similar issues (although the latter seems to be suffering a little more).

    KB5014697, released on June 14 for Windows 11, addresses a number of issues, but the known issues list has also been growing. Some .NET Framework 3.5 apps might fail to open (if using Windows Communication Foundation or Windows Workflow component) and the Wi-Fi hotspot features appears broken.

    Continue reading

Biting the hand that feeds IT © 1998–2022