Office 365 Security and Beyond
Part 2 of 2
Is Microsoft Office 365 security enough or can more be done to secure data in and outside of O365
By Paul Rummery, Securenet Consulting
Summary
Microsoft have been working hard to build and integrate security features to help customers secure data and meet industry compliance for data protection. However, these features are not free and do not come bundled with base package offerings, they are license and cost extras.
Athough controls exist within Office 365, some customers deem these features slightly limited and not granular enough to satisfy the data protection requirements of say, the financial sector.
There is also the added complexity to consider that not all O365 customer have migrated all their data under the 'protection' of Microsoft, for obvious security concerns, and that leaves a very large chunk of consideration, management and securing of external users, mobile devices and data traveling to and from organisations on-premise data repositories, users and multiple cloud platforms.
The overall aim of this blog was to examine the key areas of concern for data security and look at what easy to bolt on solutions should be considered in order to give you the extra peace of mind data protect, not only in Office 365 also incorporating the realistic bigger picture.
...continued from Office 365 security blog part 1
Authentication
Tighten access control with two-factor authentication (2FA) OR multi-factor authenticationMicrosoft do provide a 2FA service, but centralising your authentication to the same platform as the App hosting provider is risky – putting your eggs in one basket - you need to consider the impact of a breach.
Audit
Authentication solutions enabling hybrid platform management, provide the ability to track audit and report on user access, roles and policies.
Two Factor, Multi Factor Authentication
Extend simple username and password with an extra two-factor / one-time generated authentication layer. Manage Passwords Across All Your Platforms
Automate and ensure only strong dynamic passwords are used. Synchronise user passwords from local Active Directory to Office 365 (hybrid deployments).Single-Sign (SSO)
- Authentication service solutions offer additional convenience and increased productivity by enabling Single-Sign On for all web-based applications which support SAML.
- Active Directory-based single sign-on, user provisioning and mobility management for Office 365.
- Hybrid deployments with secure cloud and on-site components. Linking the cloud and on-site components by deploying Active Directory Federation Services (ADFS) running on a load balancer, operating as an ADFS proxy, provides single sign-on and directory sync across the hybrid cloud.
Bolstering Office 365 Encryption
Ensure your Data is Secure in Use and in Transit and at RestMicrosoft isn’t immune to government summons. Even when a cloud provider encrypts data, government agencies can demand the encryption key.
One way companies are beginning to combat this is by using third-party cloud encryption providers that make it possible for customers to use their own encryption keys, so that no third parties have the ability to read the data stored in Office 365.
Encrypt Office 365 content immediately when sensitive information is identified. Encryption permissions are applied at the individual file level, sensitive content can be stored, shared and collaborated on from any site or library in Office 365. Business rules and policies can be applied to an Office 365 or hybrid environment to centrally manage content security, reducing the administrative burden of managing content across multiple locations.
Benefits of Reverse Proxy for Hybrid SharePoint and Exchange Deployments
SharePoint Hybrid, when configured properly, can provide almost seamless coexistence between SharePoint Online and your on-premises SharePoint environment. Part of this concept is that while you technically have two separate SharePoint organisations, the file flow between these organisations appears “internal” so that a file from a cloud user looks no different than a file from an on-premises user.
Search results from both sources can be combined to present users with a unified view of SharePoint resources in both locations. However, enabling this unified view requires inbound SSL/TLS connectivity from Office 365 to on-premise SharePoint servers.
Secure these connections by adopting an inbound SSL/TLS scanning endpoint (typically a proxy device) in your DMZ – authenticating, and decrypting traffic before passing it to SharePoint servers on the internal network.
A proxy is a termination point, where deep inspection for malware and policies can be deployed against traffic
Note: Direct (non-proxied) inbound connections from Internet resources should not be allowed to reach internal resources.
Logging & Reporting
Monitoring, Security Intelligence, Audit, Track & Analyse File Sharing and Enforce Collaboration Policies, (SIEM).
Audit collaboration activity and visualise usage, sharing events within the organisation (with partners, personal emails, and via untraceable shared links).
Detect & Identify Account Breaches and Malicious Use
Regardless of whether you have systems on-premise, in the cloud or a hybrid of the two, security monitoring is absolutely critical if you're serious about security.
According to a recent Ponemon Institute study, the average cost of a data breach has risen to $4 million. These costs can include litigation, the effects of brand or reputation damage, potential lost sales, and in some cases, complete business closure. Organisations that are prepared for a breach by spending on appropriate staffing, security training and security products can ultimately reduce their long-term costs.
Although Microsoft 365 provide a tool, it is a touch on the light side, and users have commented on Microsoft’s typically either meaningless or ambiguous error messages - basically not as intuitive or granular as many of the specialist solution providers who will give you visibility of your on-premise systems and all other cloud platforms (not just 365), providing an easy to plugin API for features like security event information from all cloud services, threat intelligence, log admin, user, policy actions and data activity, gain forensic insight into events, map and visualise events and trends …to name but a few.
Monitor all inbound and outbound document flows to and from endpoints accessing Office 365 cloud storage (OneDrive, SharePoint) and Apps
All geared towards helping with security decision making and compliance with standards that require log retention and log review.
- Monitor who is uploading, downloading and sharing files and folders
- Restrict editing to online documents only, prevent document downloads
Investigate
Investigate incidents to satisfy legal, compliance, HR & security to quickly understand the complete incident picture.
Certificate Verification
Microsoft, due to their size and user based volume across the world, they are a common target for certificate attacks. In fact, Microsoft certificate compromises known to the public have occurred in 2001, 2008, 2012 and 2015.Verify the status of Office 365 certificates in real-time. If a certificate has been compromised and revoked, you will want to block the request and alert your users.
Stop Advanced Threats
Sandboxing, Anti Malware, Anti Spam, Anti-Virus Scanning
Scan, Sandbox and uncover content / files for analysis to detect zero-day, non-signature malware, malicious code and prevent threats from migrating over from or to Office365 SharePoint, Office applications (Word, Excel, etc.), PDFs, Outlook Web App (OWA), and Exchange ActiveSync (for mobile email) – a common tactic in targeting attacks.
Hackers and attacks still rely on these techniques in order to phish for personal data that might build a profile to hack an employee account (data or applications). Therefore the volume and frequency of malware, virus and spam attacks are high – putting a significant load on any network, security edge equipment / infrastructure.
This also improves your visibility for compliance and data loss prevention.
This can be particularly valuable in environments where mobile devices are not protected by client virus software, are uploading and downloading files. Malware scanning also provides protection against compromising Office 365 infrastructure. For example, login credentials can be phished from employees or the Office 365 infrastructure itself can be hacked. By enabling malware scanning, you can prevent malware posted by attackers from spreading to other systems and identify which files need to be removed from Office 365 servers.
Sandboxing technologies also extend URL sandboxing for any device, including smartphones and tablets.
Microsoft do provide an additional service for malware detection (not sandboxing), but is it advanced and the best in the market? Can you afford that risk?
Cloud / Web Application Control
Control cloud-based / web 2.0 applications like Office 365, social media, webmail, etc..
These controls not only give you control over which users can access which Office 365 applications, but extend to all accessible cloud apps via the Internet, ad determine which operations within the application are available / allowed.
For example, you could meet least privilege access requirements by allowing a contractor to access SharePoint files but deny Exchange email. You could further allow that contractor to download files, but prevent a SharePoint infection from an unmanaged contractor device by blocking uploads.
These controls secure Office 365 as a collaboration tool and ensuring the integrity of your infrastructure.
Data Backup & Archiving - Data Protection
Backup Office 365 email and file data
Restore Office 365 email, calendars, and contacts
Have completely migrated to Office 365, or have a hybrid Exchange and Office 365 deployment?
Just because your data is in the cloud, it does not mean that traditional risks like the underlying equipment could fail, and data can get deleted (deliberately or accidentally).
Your business objectives remain the same. You must remain in control of your data and you need Office 365 backup and recovery at your fingertips.
If you reply on Office 365 for backup and recovery, and you need to recover data or access email, as an IT admin, you will need to submit a support ticket and wait.
Be in control of your own data – merge data protection across all your platforms
Like your security approach and strategy, you should implement a solution that can span all your data endpoints (multiple cloud platforms, on-premise storage locations, laptops, mobile smartphones, tablets).
- Track and audit files (comply with PCI, SOX HIPAA) from your cloud locations, shadow IT and mobile.
- Empower your IT staff to take control of your organization’s Office 365 data
- Reduce the time and effort needed to find and restore email data
- Protect against data loss scenarios that are not covered by Microsoft
- Facilitate the migration of email data between Office 365 and on-premises Exchange
eDiscovery of Office 365 email and file data archives
Without a local copy of your data, retrieving emails and files data for regulatory or compliance reasons can be costly and time consuming.
Leverage advanced capabilities, recovery and export options for Microsoft Exchange to perform eDiscovery on Office 365 email archives - just as easily as you would today with your on-premises Exchange server backup.
Mobile Device Access & Management to O365 - MDM
Although Office 365 offers baseline security settings for mobile devices connecting to 0365, it is critical to monitor the status of all mobile devices receiving corporate email around your organisation (on-premise, in the field and in the cloud). Utilising controls from an MDM solution expands overall capability and benefits of Exchange Online and minimises security risks, enforce security standards prior to email delivery from or to O365, and enable you to take action on a lost or compromised devices.
Exchange Online provides access and synchronisation of corporate email, contacts, calendars, and tasks to mobile devices. MDM controls for mobile devices;
- Single view of all devices syncing email
- Automatic compliance enforcement
- Selective wipe, lock and unlock actions
- Device-level view of installed apps, jail-broken or rooted devices
Securely share and manage documents on mobile devices
- Document life-cycle management
- Document-specific sharing restrictions
- Users are alerted when new or updated content appears
Regulatory Compliance
SecureNet Consulting security and data protection solutions enable the use of Microsoft's productivity tools anywhere while meeting data security, compliance, and governance requirements.
- Ensure compliance with regulations such as PCI DSS, HIPAA, HITECH, GLBA, SOX, CIPA, FISMA, and FERPA by applying comprehensive data loss prevention capabilities to new or existing content within Office 365.
- Cloud application delivery (traffic / application optimisation).
- Exchange to Office 365 Cloud data migration.
- e-Discovery (identify and finger print documents and files).
- Track the entire lifecycle of Office 365 documents (read, emailed, or printed and by whom).
- Secure email storage and archiving in ISO27001, EU Safe Harbor, SSAE Type 2 Certification.
- Address PCI-DSS, HIPAA, and GLBA. Protect data from improper disclosure, and includes pre-built and customisable checks of structured data to accurately detect sensitive information and make it easier to comply with regulatory requirements.
- Enforce retention policies and perform supervisory review of email to ensure that the organisation is in compliance with these regulatory policies.
Solutions that have cloud application and Office 365 security integrated
VPN Connectivity
Secure (encrypt) connection from Microsoft Office
365 to your office, branches and mobile users.
Enable per applicaiton
VPN protection of data in transit between the cloud and the internal
enterprise datacentre or network.
Web Application Firewall
Cloud Application protection –
centralising cloud application access, authentication and SSO.
|
Intrusion Prevention (IPS)
Protection for cloud-based apps, web apps, web 2.0 and cloud
databases.
URL Protection
Destination
website scanning to protect users from spear-phishing attacks.
Suspicious links
are inspected at the time of click (from any device, including smartphones
and tablets).
|
Microsoft Office 365 Professional Services / Engineering
Also see solutions to control and protect
Provide enterprises with the flexibility to determine how and where users store files.
SharePoint
OneDrive
File Share
Exchange
|
Office 365 Overview
Data Discovery and Control
Take care not to bypass existing security controls
Email Security
Email Encryption
Email Management, Availability & Continuity
Email Archiving
Email Migration to Office 365 service
Data Loss Prevention (DLP)
Document File DLP
Email DLP
Prevent User Experience and Performance Latency
Linking & Securing Hybrid Cloud Environments
Secure Access, Identity Management and Privileged Users
|
Office 365 Security Blog Part 2
Multi Factor Authentication
Data Encryption
Secure Hybrid Environments
Logging, Audit, Reporting and Security Intelligence
Protect against advance threats, malware, viruses, spam
Verify Application Certificates
Cloud Application Control
Data Backup & Archiving – Data Protection
MDM – Mobile Device Management
Address Regulatory Compliance
Secure VPN Connectivity
Web Application Firewall
Intrusion Prevention
Microsoft Office 365 Professional Services & Engineering
|
Contact us today to discuss your requirements in more detail.
|
|
Telephone
|
+44(0)7714 209927
+44(0)1273 329753
|
|
|
|
|
|
|||
|
|












