CIAOPS Need to Know Microsoft 365 Webinar – March

laptop-eyes-technology-computer_thumb

Join me for the free monthly CIAOPS Need to Know webinar. Along with all the Microsoft Cloud news we’ll be taking a look at Purview (aka Compliance) in Microsoft 365.

Shortly after registering you should receive an automated email from Microsoft Teams confirming your registration, including all the event details as well as a calendar invite.

You can register for the regular monthly webinar here:

March Webinar Registrations

(If you are having issues with the above link copy and paste – https://bit.ly/n2k2503)

The details are:

CIAOPS Need to Know Webinar – March 2025
Friday 28th of March 2025
11.00am – 12.00am Sydney Time

All sessions are recorded and posted to the CIAOPS Academy.

The CIAOPS Need to Know Webinars are free to attend but if you want to receive the recording of the session you need to sign up as a CIAOPS patron which you can do here:

http://www.ciaopspatron.com

or purchase them individually at:

http://www.ciaopsacademy.com/

Also feel free at any stage to email me directly via director@ciaops.com with your webinar topic suggestions.

I’d also appreciate you sharing information about this webinar with anyone you feel may benefit from the session and I look forward to seeing you there.

CIA Brief 20250301

image

Disrupting a global cybercrime network abusing generative AI –

https://blogs.microsoft.com/on-the-issues/2025/02/27/disrupting-cybercrime-abusing-gen-ai/

Microsoft completes landmark EU Data Boundary, offering enhanced data residency and transparency –

https://blogs.microsoft.com/on-the-issues/2025/02/26/microsoft-completes-landmark-eu-data-boundary-offering-enhanced-data-residency-and-transparency/

Announcing Free, Unlimited Access to Think Deeper and Voice –

https://www.microsoft.com/en-us/microsoft-copilot/blog/2025/02/25/announcing-free-unlimited-access-to-think-deeper-and-voice/

Maximizing AI’s potential: Insights from Microsoft leaders on how to get the most from generative AI –

https://www.microsoft.com/en-us/microsoft-cloud/blog/2025/02/18/maximizing-ais-potential-insights-from-microsoft-leaders-on-how-to-get-the-most-from-generative-ai/

Move files to OneDrive –

https://www.youtube.com/watch?v=a2hq63Yfj3Y

Safeguarding AI against ‘jailbreaks’ and other prompt attacks –

https://news.microsoft.com/source/features/ai/safeguarding-ai-against-jailbreaks-and-other-prompt-attacks/

Focus on what matters most with Microsoft 365 Copilot –

https://www.youtube.com/watch?v=0-_xncOsEds

After hours

Gibberlink – https://www.youtube.com/watch?v=Z3yQHYNXPws

Editorial

If you found this valuable, the I’d appreciate a ‘like’ or perhaps a donation at https://ko-fi.com/ciaops. This helps me know that people enjoy what I have created and provides resources to allow me to create more content. If you have any feedback or suggestions around this, I’m all ears. You can also find me via email director@ciaops.com and on X (Twitter) at https://www.twitter.com/directorcia.

If you want to be part of a dedicated Microsoft Cloud community with information and interactions daily, then consider becoming a CIAOPS Patron – www.ciaopspatron.com.

Watch out for the next CIA Brief next week

Testing sensitive information types in Microsoft Purview

2025-02-25_07-45-21

To test a file for a sensitivity type navigate to the Microsoft Purview portal. From the solutions icon on the left hand side select Data Lifecycle Management. Expand the Classifiers option from the menu and select Sensitive info types as shown above. You can search for the an item via a search in the top right.

image

Here, I’ll located Credit Card Number as shown above.

image

On the right hand side you will find a Test icon as indicated above.

image

From the right will appear a window with an option to Upload file as shown above.

image

Once you have uploaded the file you wish to test, select the Test button at the bottom of the page as shown.

image

After a moment or two, you’ll see the results of the test as shown above.

This manual sensitive information testing process will allow you to verify whether your file content will be identified by services such as DLP in MIcrosoft Purview. This should make creating policies to ptotect your information easier.

Need to Know podcast–Episode 340

I take a look at something many overlook when it comes to security in their Microsoft 365 environment – Exposure score. In essence it is like a targeted Secure Score for a particular threat like Business Email Compromise. There is also news and updates from the Microsoft Cloud so listen along and review the show notes for more information.

Brought to you by www.ciaopspatron.com

you can listen directly to this episode at:

https://ciaops.podbean.com/e/episode-340-exposure-management/

Subscribe via iTunes at:

https://itunes.apple.com/au/podcast/ciaops-need-to-know-podcasts/id406891445?mt=2

or Spotify:

https://open.spotify.com/show/7ejj00cOuw8977GnnE2lPb

Don’t forget to give the show a rating as well as send me any feedback or suggestions you may have for the show.

Resources

@directorcia

Join my shared channel

CIAOPS merch store

Become a CIAOPS Patron

CIAOPS Blog

CIAOPS Brief

CIAOPSLabs

Support CIAOPS

The way to control EWS usage in Exchange Online is changing

New Microsoft-managed policies to raise your identity security posture

Storm-2372 conducts device code phishing campaign

Block malicious command lines with Microsoft Defender for Endpoint

Clipchamp: Elevating work communication with seamless video creation in Copilot

Sharing with Microsoft Whiteboard

AI agents at work: The new frontier in business automation

Copilot learning hub

New Certification for Microsoft information security administrators

What is Security Exposure Managenet?

CIA Brief 20250222

image

Quick Setup – Microsoft Entra Verified ID –

https://www.youtube.com/watch?v=YnukKchoN28

Talk and translate on-the-go with Copilot –

https://www.youtube.com/watch?v=P4lKB5Yz9Sg

Amtrak improve efficiency and safety with Microsoft Power Platform –

https://www.youtube.com/watch?v=292tyXQLie0

The way to control EWS usage in Exchange Online is changing –

https://techcommunity.microsoft.com/blog/Exchange/the-way-to-control-ews-usage-in-exchange-online-is-changing/4383083

Enhanced data control while submitting Microsoft 365 Copilot feedback –

https://techcommunity.microsoft.com/blog/Microsoft365InsiderBlog/enhanced-data-control-while-submitting-microsoft-365-copilot-feedback/4382668

New Microsoft-managed policies to raise your identity security posture –

https://techcommunity.microsoft.com/blog/microsoft-entra-blog/new-microsoft-managed-policies-to-raise-your-identity-security-posture/4286758

Clipchamp: Elevating work communication with seamless video creation in Copilot –

https://techcommunity.microsoft.com/blog/microsoft_365blog/clipchamp-elevating-work-communication-with-seamless-video-creation-in-copilot/4375660

With Copilot agents, Pets at Home unleashes an AI revolution –

https://news.microsoft.com/source/emea/features/with-copilot-agents-pets-at-home-unleashes-an-ai-revolution/

Majorana 1 Explained: The Path to a Million Qubits –

https://www.youtube.com/watch?v=wSHmygPQukQ

Sharing with Microsoft Whiteboard –

https://www.youtube.com/watch?v=RXAo9JGZS44

Facilitating sessions with Microsoft Whiteboard –

https://www.youtube.com/watch?v=UNqtsIqNK7s

Get help or support as an admin –

https://www.youtube.com/watch?v=0s1Cof06VfA

Seamless Security: Smartcard Logon from Entra-Only Machines to domain-joined Servers or AVDs –

https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/seamless-security-smartcard-logon-from-entra-only-machines-to-domain-joined-serv/4381789

Minimize email drafts in Outlook for Android and iOS to easily task switch –

https://techcommunity.microsoft.com/blog/microsoft365insiderblog/minimize-email-drafts-in-outlook-for-android-and-ios-to-easily-task-switch/4375165

How to protect against Device Code Flow abuse (Storm-2372 attacks) and block the authentication flow –

https://jeffreyappel.nl/how-to-protect-against-device-code-flow-abuse-storm-2372-attacks-and-block-the-authentication-flow/

After hours

Introducing Helix – https://www.youtube.com/watch?v=Z3yQHYNXPws

Editorial

If you found this valuable, the I’d appreciate a ‘like’ or perhaps a donation at https://ko-fi.com/ciaops. This helps me know that people enjoy what I have created and provides resources to allow me to create more content. If you have any feedback or suggestions around this, I’m all ears. You can also find me via email director@ciaops.com and on X (Twitter) at https://www.twitter.com/directorcia.

If you want to be part of a dedicated Microsoft Cloud community with information and interactions daily, then consider becoming a CIAOPS Patron – www.ciaopspatron.com.

Watch out for the next CIA Brief next week

Updated Windows for Endpoint Security Baseline

image

Microsoft has updated the Windows Security Baseline for Endpoint Security in Intune to 24H2 as shown above. Baselines are an easy way to set a vast array of best practice settings across your Windows devices in a single policy, already pre-configured by Microsoft.

I have extracted the policy to a JSON file and made it available at:

https://github.com/directorcia/bp/blob/main/Intune/Policies/Endpoint/Baselines/win.json

and the previous one is here:

https://github.com/directorcia/bp/blob/main/Intune/Policies/Endpoint/Baselines/Archive/win.json

You can now simply import that directly into your environment programmatically using something like PowerShell.

I will note that when I initially exported the templated and tried to import it back I got the error:

Invalid Reference id found in Policy

after a lot of troubleshooting (and I mean a LOT) I tracked down the issue to be related to id 241:

{
   “id”: “241”,
   “settingInstance”: {
     “choiceSettingValue”: {
       “value”: “device_vendor_msft_policy_config_deviceguard_machineidentityisolation_0”,
       “children”: [],
       “settingValueTemplateReference”: {
         “useTemplateDefault”: false,
         “settingValueTemplateId”: “6a208e4b-0e34-4d12-a821-3173e99f3ce0”
       }
     },
     “@odata.type”: “#microsoft.graph.deviceManagementConfigurationChoiceSettingInstance”,
     “settingDefinitionId”: “device_vendor_msft_policy_config_deviceguard_machineidentityisolation”,
     “settingInstanceTemplateReference”: {
       “settingInstanceTemplateId”: “1fa97457-2a1f-4e33-b3c2-9a4c8930510d”
     }
   }
}

removing that from teh template allowed the rest of the template to import. I’ll have to spend some more time working out the exact settings and hopefully by then Microsoft fixes the issue and I’ll update the JSON in my Best Practices repository. However, for now the JSON at the URL can be imported.

image