Getting Started with Azure/O365 Auditing

Read this:

https://cloudblogs.microsoft.com/industry-blog/en-gb/government/2021/04/14/updated-office-365-security-and-compliance-guidance-for-the-uk-public-sector/

Create your own audit based on MS500 and AZ500 training guide primary topics.

https://www.skylinesacademy.com/resources

Expand on your audit by learning each security feature in depth and adding tips/references to your audit sheet.

Good luck!

Azure Logic Apps can automate so much of your Microsoft Security world..

I’ve spent a lot of time in Azure Logic Apps over the past few months.

Give me a reason and I’ll put together a vlog on getting started with Azure Sentinel and Logic Apps.

In the meantime here are some good references:

https://docs.microsoft.com/en-us/azure/logic-apps/quickstart-create-first-logic-app-workflow

https://docs.microsoft.com/en-us/azure/logic-apps/

Azure Sentinel webinar: Unleash the automation Jedi tricks & build Logic Apps Playbooks like a Boss

https://docs.microsoft.com/en-us/azure/logic-apps/logic-apps-examples-and-scenarios

Functions Reference Guide

https://docs.microsoft.com/en-us/azure/logic-apps/workflow-definition-language-functions-reference

Microsoft Cloud Training and Education

new links for 2022 (that I didn’t find in 2021…)

lots of new training here (2022):

https://msuspartners.eventbuilder.com/microsoftsecurityandcompliance

https://demo.microsoft.com

Full list of study guides!!!

https://www.skylinesacademy.com/resources

Tips for Architects

Sample Architectures (LOTs here):

CyberSecurity Reference Architecture

https://docs.microsoft.com/en-us/security/cybersecurity-reference-architecture/mcra

Cloud for IT Architect Illustrations

https://docs.microsoft.com/en-us/microsoft-365/solutions/cloud-architecture-models?view=o365-worldwide#identity-and-device-protection-for-office-365

Steps on moving to a ‘modern’, Zero Trust architecture

  1. Moving away from VPN by publishing the apps via Azure AD App Proxy (per-app vpn)
  2. Modernize the app by moving the data/process to SaaS products
  3. Isolate the app/data by implementing Windows Virtual Desktop (running in Azure) – useful for when you don’t own the endpoint
  4. Isolate the data using DLP on Windows, Office, MCAS, and anywhere else (MIP integration)
  5. Monitor all user app/data access via Azure AD Auth with MCAS session controls (includes AWS, SaaS, etc)

Microsoft Well Architected Framework

https://www.microsoft.com/azure/partners/well-architected

https://www.microsoft.com/en-us/us-partner-blog/2021/04/23/azures-well-architected-framework-pillar-5-security/

Well Architected Assessment Tool