April Microsoft 365 Webinar resources

image

The slides from this month’s webinar are available at:

https://github.com/directorcia/general/blob/master/Presentations/Need%20to%20Know%20Webinars/202404.pdf

If you are not a CIAOPS patron you want to view or download a full copy of the video from the session you can do so here:

http://www.ciaopsacademy.com.au/p/need-to-know-webinars

Watch out for next month’s webinar.

Recap from Copilot for Microsoft 365:

Generated by AI. Make sure to check for accuracy.

Meeting recap notes:

  • Robert talked about various topics in the meeting, including the need to know webinar for April 2024, Microsoft 365 cloud news, and Loop. He also provided information on how to keep up to date with Microsoft’s announcements and how to troubleshoot and assist in Intune using Copilot for Security.

    • Robert hosted a webinar on the need to know for April 2024. He thanked everyone for joining and confirmed that the sound and video checks were done, and the recording had started. He advised that the recording would be available afterward.

    • Robert discussed two topics in the meeting. Firstly, he talked about Microsoft’s plan to introduce an external recipient rate limit from January 2025.

    • Robert discussed Microsoft’s Loop product and its components, including task listing. He advised that it is important to learn how to use the tools before putting production information in them.
  • Robert talked about Microsoft licensing changes due to the European Union’s anti-competitive requirements. Teams will no longer be included in the suite and will need to be purchased as an add-on license. Microsoft Mesh, a virtual reality style world connected to teams, is now fully available but requires a premium license.

    • Robert discussed the changes in Microsoft licensing due to the European Union’s anti-competitive requirements. Teams will now be detached from new sales of Microsoft 365 and will need to be purchased as an add-on license. Existing licenses are not affected.

    • Robert discussed the wider environment and the premium license required to access it. He also talked about the Apple Vision Pro reports and its low adoption rate. Robert then moved on to talk about Teams, which is Microsoft’s major focus.

    • Robert discussed the challenges of using SharePoint and how Microsoft Teams can help. Teams leverages existing services like exchange online, SharePoint, planner chat, and more. By default, most users can create a team without needing any particular permissions.

    • Robert discussed the modern approach of using multiple social media accounts and how Teams is a combination of chat conversations, calls, chats, meetings, and video conferences. He also mentioned that Teams integrates with Office 365 apps and has customization extensibility.

    • Robert discussed the capabilities of Microsoft Teams, including the ability to set meetings on various platforms, integrate with telephony systems, and apply policies and compliance.
  • Robert talked about the benefits of using Teams for developing apps at zero or very little cost. He also discussed the integrations available to the administrator to control permissions and licenses. Robert explained how files work inside a team and how every team created creates a dedicated SharePoint site in the background.

    • Robert discussed the capabilities of Teams, including the ability to develop your own apps at zero or very little cost, and the various integrations available. He also explained how files work inside a team, with each team creating a dedicated SharePoint site.

    • Robert discussed the benefits of using Power Automate to create automated processes in Teams. He emphasized the importance of breaking up teams by department or function and highlighted the enterprise security compliance and manageability features available in Microsoft 365.

    • Robert discussed the benefits of using Microsoft Teams for work collaboration. He mentioned that the new Teams client is faster and better than the old one and allows for easy switching between different teams.

    • Robert discussed the benefits of using the new teams and encouraged everyone to start using it. He also highlighted the challenges of allowing remote access or group access and suggested using teams to collaborate with people inside and outside the organization.

    • Robert explained the limitations of guest users in external teams. They cannot be an administrator of a team or create channels.
  • Robert talked about enabling guests in teams, integrating phones into teams, and the premium features of Microsoft Teams. He emphasized that Microsoft is encouraging collaboration and making it possible out of the box, but users can restrict it with policies.

    • Robert discussed various aspects of Microsoft Teams, including enabling guests, integrating phones, and the premium offering. He emphasized that Microsoft is encouraging collaboration and making it possible out of the box.

    • Robert provided an overview of the capabilities of Teams Premium. He discussed the intelligent recap feature, which allows users to search for specific words or ideas mentioned in a meeting.

    • Robert introduced an app called Meet that gives a summary of all meetings and allows users to jump between them quickly. He recommended it for those who spend a lot of time in Teams meetings.

    • Robert discussed the capabilities of SharePoint in Teams. He explained how to search for SharePoint, launch a meeting inside a channel, control notifications, and pin conversations to the top. He also mentioned that each channel has a unique email address and a link.

    • Robert explained the features of Teams, including the ability to receive notifications for new updates and changes, chat with individuals or groups, share files and gifts, and escalate to audio or video calls.
  • Robert talked about Microsoft Teams and its capabilities. He explained how it is a different approach to collaboration and how it can help provide advanced productivity and save time in businesses. He discussed the integration with the phone system and OneDrive for Business.

    • Robert discussed the features and capabilities of Microsoft Teams in a meeting. He explained how to schedule a meeting, use the phone system, and work with personal and shared files.

    • Robert demonstrated the features of the Meet app and how it can be integrated with other apps. He emphasized the benefits of using Teams for collaboration, including the ability to search for data quickly and easily.

    • Robert demonstrated how to automate processes using Power Automate in Teams. He showed examples of automations such as dad joke of the day, space picture of the day, and chat GPT.

    • Robert discussed the benefits of using Teams for collaboration, highlighting its features such as working out loud, sharing, searching, and putting information and control in users’ hands.

    • Robert provided an overview of Microsoft Teams and its capabilities. He emphasized the importance of moving from one-to-one collaboration using email to working out loud.

Follow-up tasks:

  • Teams licensing: Review the changes in Teams licensing and pricing due to the EU decision and the new Teams premium option (Teams resellers and customers)

  • Copilot for security: Explore the benefits of Copilot for security, especially for Intune and Defender integration and troubleshooting (Teams admins and security managers)

  • Loop: Learn how to use Loop and its new task list component and compare it with other tools like OneNote and Planner (Teams users and collaborators)

  • Teams shared channel: Set up the required permissions to join the Teams shared channel and send an email to Robert to request access (Anyone interested in joining the Teams shared channel)

  • Teams premium features: Try the new Teams client and the new features like intelligent recap, branding, and mesh (Teams users and meeting organizers)

Need to Know podcast–Episode 318

I’ve now had a chance to play with Copilot for Security and can recommend it but to ensure that costs don’t spiral out of control for SMB, it needs to used in an ad hoc manner. Listen along for my thoughts and a walk through of resources available for you. Also news of updates of Exchange email threshold limits being changed as well as improvements for Microsoft Mesh, Loop and more. Listen in for the latest updates.

You can listen directly to this episode at:

https://ciaops.podbean.com/e/episode-318-copilot-for-security-in-the-flesh/

Subscribe via iTunes at:

https://itunes.apple.com/au/podcast/ciaops-need-to-know-podcasts/id406891445?mt=2

Don’t forget to give the show a rating as well as send me any feedback or suggestions you may have for the show.

Brought to you by www.ciaopspatron.com

Resources

@directorcia

Join my shared channel

CIAOPS merch store

Become a CIAOPS Patron

CIAOPS Blog

CIAOPS Brief

CIAOPSLabs

Support CIAOPS

Microsoft Copilot for Security

Microsoft Copilot for Security Intune Plugin Overview

How to Become a Microsoft Copilot for Security Ninja: The Complete Level 400 Training

Copilot for Security – The low down for SMB

Public Preview: High Volume Email for Microsoft 365

Exchange Online to introduce External Recipient Rate Limit

Hunting for QR Code AiTM Phishing and User Compromise

Microsoft Mesh: A new way to connect

Realigning global licensing for Microsoft 365

Improved task list components in Loop

Bringing the latest capabilities to Copilot for Microsoft 365 customers

Updates to Clipchamp that make video editing a breeze

Introducing “What’s New” in Microsoft Entra

Summary of podcast episode straight from Copilot for Microsoft 365:

Main ideas:

  • Podcast overview: The podcast provides news and information on the Microsoft Cloud, with a special focus on the SMB market. The host, Robert Crane, invites listeners to contact him via email, blog, YouTube, or shared channel.
  • New Azure service for security analysis: Microsoft copilot for security is an Azure service that leverages AI to assist security analysts and investigators. It uses a consumption billing model and can be turned on and off as required. It also supports plugins and custom documents to extend its capabilities.
  • Public preview of high volume email feature: Microsoft 365 customers can sign up for a public preview of high volume email, which allows them to send more emails than the existing mailbox limits. This feature is useful for SMBs who need to send newsletters or marketing campaigns to their customers.
  • Detection of QR code phishing attacks: QR code phishing is a technique that uses malicious QR codes to trick users into giving away their credentials. Microsoft provides some KQL queries that can be used in Defender for endpoint and Sentinel to detect and alert on these attacks.
  • Virtual reality platform for collaboration: Microsoft Mesh is a virtual reality platform that enables users to connect and collaborate in immersive 3D spaces. It requires a Teams premium license and a compatible device. It can be used for various purposes, such as training, events, or meetings.
  • Licensing changes for Microsoft 365 in the European Economic Area: Microsoft has agreed to separate Teams from the Microsoft 365 suite in the European Economic Area, to comply with competition rules. This means that Teams will be a separate add-on that needs to be purchased separately. Existing customers are not affected by this change.

CIAOPS Brief 20240420

image

Get started with reporting | Microsoft Defender Experts for XDR –

https://www.youtube.com/watch?v=Ymm6g_Eis34

Updates to Clipchamp that make video editing a breeze –

https://insider.microsoft365.com/en-us/blog/updates-to-clipchamp-that-make-video-editing-a-breeze

Get started with onboarding | Microsoft Defender Experts for XDR –

https://www.youtube.com/watch?v=eLEXPZ1mUwQ

AI study guide: The no-cost tools from Microsoft to jump start your generative AI journey –

https://azure.microsoft.com/en-us/blog/ai-study-guide-the-no-cost-tools-from-microsoft-to-jump-start-your-generative-ai-journey/

New Microsoft guidance for the DoD Zero Trust Strategy –

https://www.microsoft.com/en-us/security/blog/2024/04/16/new-microsoft-guidance-for-the-dod-zero-trust-strategy/

Microsoft Intune Makes It Possible –

https://www.youtube.com/watch?v=DFG7JbR-Eyc

Evolving the Meeting Details experience across Microsoft 365 apps and services –

https://insider.microsoft365.com/en-us/blog/evolving-the-meeting-details-experience-across-microsoft-365-apps-and-services

Accelerated Vulnerability Assessment with Copilot –

https://www.youtube.com/watch?v=JGpKZ1Bj6ew

Rapid Threat Intel Analysis with Copilot –

https://www.youtube.com/watch?v=nkIQb0ksaW4

Enhancing Security with MDEASM and Copilot: Streamlining External Attack Surface Management –

https://www.youtube.com/watch?v=UEb-PtKLO6Y

Enhancing Security with Script Analysis using Copilot –

https://www.youtube.com/watch?v=9BBok6bWFuk

Introducing “What’s New” in Microsoft Entra –

https://techcommunity.microsoft.com/t5/microsoft-entra-blog/introducing-quot-what-s-new-quot-in-microsoft-entra/ba-p/3796389

Exchange Online to introduce External Recipient Rate Limit –

https://techcommunity.microsoft.com/t5/exchange-team-blog/exchange-online-to-introduce-external-recipient-rate-limit/ba-p/4114733

7 ways AI makes life easier on the go –

https://news.microsoft.com/source/features/ai/7-ways-ai-makes-life-easier-on-the-go/

Microsoft Copilot for Security Intune Plugin Overview –

https://techcommunity.microsoft.com/t5/microsoft-security-copilot-blog/microsoft-copilot-for-security-intune-plugin-overview/ba-p/4114040

Leverage Custom Promptbooks to Optimize your Security Workflows –

https://techcommunity.microsoft.com/t5/microsoft-security-copilot-blog/leverage-custom-promptbooks-to-optimize-your-security-workflows/ba-p/4113221

Your Microsoft Security test automation framework! –

https://maester.dev/

https://maester.dev/docs/intro

What is Maester?
Maester is a PowerShell based test automation framework to help you stay in control of your Microsoft security configuration.

How to Become a Microsoft Copilot for Security Ninja: The Complete Level 400 Training –

https://techcommunity.microsoft.com/t5/microsoft-security-copilot-blog/how-to-become-a-microsoft-copilot-for-security-ninja-the/ba-p/4106928

After hours

New Electric Atlas Robot Revealed by Boston Dynamics – https://www.youtube.com/watch?v=raYWbqbZbmc

Editorial

If you found this valuable, the I’d appreciate a ‘like’ or perhaps a donation at https://ko-fi.com/ciaops. This helps me know that people enjoy what I have created and provides resources to allow me to create more content. If you have any feedback or suggestions around this, I’m all ears. You can also find me via email director@ciaops.com and on X (Twitter) at https://www.twitter.com/directorcia.

If you want to be part of a dedicated Microsoft Cloud community with information and interactions daily, then consider becoming a CIAOPS Patron – www.ciaopspatron.com.

Watch out for the next CIA Brief next week.

CIAOPS Brief 20240413

image

A wave of AI innovation is overtaking Australia and New Zealand –

https://www.microsoft.com/en-us/microsoft-cloud/blog/2024/04/10/a-wave-of-ai-innovation-is-overtaking-australia-and-new-zealand/

Maximizing Data Protection with Copilot: Unveiling Hidden Risks and Prioritizing DLP Alerts –

https://www.youtube.com/watch?v=g9AqA3EVEvs

Microsoft Entra and Copilot for Security | Microsoft Security –

https://www.youtube.com/watch?v=yW7EAShfkRQ

Unleashing the Power of Copilot: Security Investigations from Defender XDR to Standalone Copilot –

https://www.youtube.com/watch?v=Sf_eRd45tko

Microsoft Copilot Dashboard Overview –

https://www.youtube.com/watch?v=ae6Ov_QBXaI

How to transform your workplace with AI –

https://www.youtube.com/watch?v=mk-I8xdj1qI

How Microsoft discovers and mitigates evolving attacks against AI guardrails –

https://www.microsoft.com/en-us/security/blog/2024/04/11/how-microsoft-discovers-and-mitigates-evolving-attacks-against-ai-guardrails/

Trim videos in PowerPoint for the web –

https://insider.microsoft365.com/en-us/blog/trim-videos-in-powerpoint-for-the-web

Efficient Device Troubleshooting with Microsoft Copilot | IT Solutions Simplified –

https://www.youtube.com/watch?v=pMYdjZmChx8

What are Copilot prompts and how to write them –

https://www.youtube.com/watch?v=bWAqW3aEXbc

Get Started with Microsoft Teams Premium – The smart place to work –

https://www.youtube.com/watch?v=jnkXIdNmng0

Toward greater transparency: Adopting the CWE standard for Microsoft CVEs –

https://msrc.microsoft.com/blog/2024/04/toward-greater-transparency-adopting-the-cwe-standard-for-microsoft-cves/

Strategies to monitor and prevent vulnerable driver attacks –

https://techcommunity.microsoft.com/t5/microsoft-security-experts-blog/strategies-to-monitor-and-prevent-vulnerable-driver-attacks/ba-p/4103985

How to protect your organization with AI and Microsoft Security –

https://www.youtube.com/watch?v=gdCy5ruhQKw

After hours

The Ocean Cleanup’s System 03 Captures Record Amounts of Plastic From the Pacific – https://www.youtube.com/watch?v=P8drUT_cZy8

Editorial

If you found this valuable, the I’d appreciate a ‘like’ or perhaps a donation at https://ko-fi.com/ciaops. This helps me know that people enjoy what I have created and provides resources to allow me to create more content. If you have any feedback or suggestions around this, I’m all ears. You can also find me via email director@ciaops.com and on X (Twitter) at https://www.twitter.com/directorcia.

If you want to be part of a dedicated Microsoft Cloud community with information and interactions daily, then consider becoming a CIAOPS Patron – www.ciaopspatron.com.

Watch out for the next CIA Brief next week.

Copilot for Security – The low down for SMB

image

The bottom line is that Copilot for Security is a very beneficial tool for SMB. The approach, as always with SMB, is going to be that it needs to used in a specific manner to unlock the best ROI for smaller businesses.

I want to make it clear that I have no special inside information about Copilot for Security in any way. Everything here my own experience, summation and projection of how Copilot for Security can work for SMB customers.

Copilot for Security is going to give SMB customers access to expertise, in an on demand capacity, that most would simply not be able to afford otherwise. It is also going to be able to provide this expertise when and where is required, without the need of employing additional skilled specialised staff. Thus, the best way to think of Copilot for Security is that, it is an on demand experienced and skilled cyber security specialist consultant that can be employed when required for around $4 per hour. I however would suggest that probably a better way to budget for Copilot in Security is to allocate around $100 per month for the capabilities that Copilot for Security can provide in an ongoing basis. At $100 per month for what can be done to improve your cybersecurity environment is a worthwhile investment for an SMB serious about security.

Importantly, you need to understand that Copilot for Security is not a stand alone service. It is a service from which you only get the most from if you already have appropriate security services and signals enabled in your environment. It is this data that feeds Copilot for Security and produces the quality analysis you desire. In short, a lack of signals will mean a lacks of results with Copilot for Security. So the starting point, before you invest a penny in Copilot for Security is to ensure you have everything turned on and enabled in your environment that can help Copilot for Security do its job.

You are also going to be get more from Copilot for Security the more Microsoft security services you have. I feel that Microsoft 365 Business Premium is the minimum license SMB should have if they are serious about cybersecurity. This is because Microsoft 365 Business Premium is going to give you important tools like Intune and EntraID P1 that help Copilot for Security really shine. However, I suggest you need to go beyond just Microsoft 365 Business Premium and look at additional services like Sentinel and Defender EASM to provide even greater benefit and more signals for Copilot for Security to work with.

The next step to implementing Copilot for Security is to ensure you have an Azure subscription enabled in your environment, because this is how Copilot for Security will be billed. Another important asset needed is a familiarity and comfort using the pricing tools that Azure provides, like budgets and assigning resources. These Azure skills are going to help ensure costs are monitored and you don’t end up with bill shock. Just adding an Azure subscription without knowing how to manage an Azure environment effectively will result in spending much more money that is necessary.

Copilot for Security works best out of the box with the Microsoft Security stack. Integrating with things like Defender for Endpoint (Business), Intune, Sentinel and the like are quite straight forward assuming they have been enabled prior to on boarding Copilot for Security. Also, given the on-demand approach that should be taken with SMB, it means the integrations with Microsoft Security services will largely automatically light up when the service is re-enabled as required. Yes, you can and will be able to integrate third party security services but these will typically require some reconfiguration after re-enabling the service, while the Microsoft stuff will typically just be enabled. This means less to do after re-enabling Copilot for Security when you need it.

Unfortunately, Copilot for Security in SMB will not be a set and forget proposition. Doing so will rack up enterprise size charges that are unsustainable for SMB. This means Copilot for Security in SMB will be a service that needs to be turned on and off as required. At the moment , there is no simple way to achieve this but there will be. I have already seen solutions with Azure Logic Apps Azure Functions, PowerShell, etc that automate this on demand process already. However, none yet are a simple button press. This means that, for the time being, some manual intervention is required every time that Copilot for Security is enabled or disabled. Yes, there is a cost to this manual switching approach but it is a small price to pay when compared to the cost of leaving Copilot for Security running 24/7.

Another important point to appreciate on billing is that the fact that even though you would only configure the smallest SCU of 1 initially, this scales on the demand placed on Copilot for Security. In my testing, when I have been placing load on Copilot for Security, say for investigating an incident, I have seen the SCU in use jump up as high as 4. This means you are actually paying 4 SCUs x $4 = $16 per hour with Copilot for Security. Now, if you are in the middle of major investigation I feel that sort of investment is more than justified but it is important to remember, in all aspects, Copilot for Security is a service based on consumption. That is, you pay for what you use, per hour. This is very different from the flat fee per month billing that Microsoft 365 uses.

The way that I see Copilot for Security being used effectively will be that it is enabled and set up in the tenant and then de-provisioned. Then once a week someone will come in, re-provision Copilot for Security, run some checks, ask some questions, for an hour or so and the de-provision the service. Where Copilot for Security will really shine for SMB will be by bringing security information from all the services together in one place and generating report and ‘plain english’ emails and communications for the management of a business. If you asks for a summary, Copilot for Security will generate one for you in a matter of moments which you can copy and paste and send on. Doing that alone will save hours when it comes to effectively monitoring a Microsoft 365 security environment.

image

The other place that I see Copilot for Security providing the business benefit in SMB will be in device management, that is, in Intune. I have been working to understand all the new settings in the updated Windows 10 Security Baseline policy and the integration with Copilot for Security has been magic. It allows me to quickly query individual settings to understand what they do rather than having to dig through granular documentation. This is a huge time saver and really helps expose the value that Intune provides because Copilot for Security can analyse, report and summarise policies as well as provide a wealth of information at your finger tips. As with most AI, the biggest benefit will come from its use with people who know the least about the service it integrates with. Intune is a great case in point here. Most IT Professionals I know have very low experience and understanding with Intune and what it can do. They are intimidated by the interface and all the settings. Copilot for Security helps overcome this and makes even a unskilled Intune operator far more effective and efficient with it. That in a nutshell is the bottom line about how SMB should look at ANY AI. It is not yet something that removes the need to do the work, it does however mean you can complete the work required without needing high levels of skill and experience with the service much faster than without it.

Another other typical place I see Copilot for Security coming into its own is during a security incident. Unfortunately, most SMBs are not prepared or experienced in dealing with a cybersecurity incident. Luckily, Copilot for Security can be called on, as needed, to provide skilled cybersecurity services. Again, Copilot for Security will not resolve or investigate the issue automatically for you, however its capabilities are going to provide the business with the skills they need to solve the issue rather than having to deploy additional human resources. Thus, when an incident is detected, Copilot for Security is provisioned to assist with the investigation. At the end of the shift, it is de-provisoned to either be used tomorrow or the next time there is an incident. Of course, the usage costs of Copilot for Security will escalate with any type of intense usage, but again having access to the capabilities of Copilot for Security in a time or need for SMB will be priceless. Most importantly, these skills can be deployed almost immediately to help resolve the issue.

We need to remember that it is still early days for Copilot for Security. That means the service will continue to improve over time. This is great for SMB because it means even while the service is de-provisioned it is improving for the next time that it is needed. Another significant different is the shift from scripts to playbooks. Without AI you largely need to use PowerShell to achieve detailed incident investigations. However, with Copilot for Security you simply ask it a number of standard questions in English to get the same result. When these standard questions are combined together you get a playbook. Thus, there will be a playbook for ransomware attack, one for business email compromise and so on. This frees the responder from having to be a PowerShell expert and have access to the right PowerShell scripts to simply running and playbook inside Copilot for Security. Many of these playbooks already exist inside Copilot for Security now and they will just keep growing. A whole community will emerge providing playbooks for Copilot for Security. Many will be incorporated directly in the product. Best of all you’ll be able to add your own based on previous situation and interactions with Copilot for Security. SMB has the most to benefit from not re-inventing the wheel and simply providing what others provide already largely for free.

There is nothing Copilot for Security does that can’t already be achieved by a skilled operator. The challenge in SMB is having access to such skilled operators and having access pretty much immediately when required. I see Copilot for Security becoming more and more integrated with the security settings we see in the Microsoft 365 security admin console. Imagine when Copilot for Security is integrated with Exchange Online threat policies and can actually adjust these automatically to make your environment more secure. I can see a day when Copilot for Security can configure a complete environment to any security framework of your choice by simply (say Essential 8) using an inbuilt playbook. The possibilities are endless and should be very exciting for those in SMB since, rarely, are their jobs to be skilled cybersecurity anaylsis and operators. Copilot for Security brings those skills down to being applied on demand, for what I would suggest is a very small investment.

In summary then, is Copilot for Security a benefit to SMB? Yes, without doubt. Does Copilot for Security need to be implemented differently in SMB? Yes, without doubt. It is all about using the tools effectively for the job and from what I see. Copilot for Security is a highly effective tool when used correctly. However, as I have talked about before, Copilot for Security has pre-requisites to make it an effective tool. The greatest of these is ensuring that signals are already in place for Copilot for Security to use. You really shouldn’t be thinking about using Copilot for Security anywhere until all that is in place purely and simply because that is what feeds Copilot for Security. Poor input leads to poor output and this Copilot for Security should not be seen as a stand alone saviour of the lack of cybersecurity skills in SMB. It should be seen as the icing on the cake of what is already a amazing stack of services from Microsoft to protect the SMB customer.

CIAOPS Need to Know Microsoft 365 Webinar – April

laptop-eyes-technology-computer_thumb

Join me for the free monthly CIAOPS Need to Know webinar. Along with all the Microsoft Cloud news we’ll be taking a look at Microsoft Teams.

Shortly after registering you should receive an automated email from Microsoft Teams confirming your registration, including all the event details as well as a calendar invite.

You can register for the regular monthly webinar here:

April Webinar Registrations

(If you are having issues with the above link copy and paste – https://bit.ly/n2k2404

The details are:

CIAOPS Need to Know Webinar – April 2024
Friday 26th of April 2024
11.00am – 12.00am Sydney Time

All sessions are recorded and posted to the CIAOPS Academy.

The CIAOPS Need to Know Webinars are free to attend but if you want to receive the recording of the session you need to sign up as a CIAOPS patron which you can do here:

http://www.ciaopspatron.com

or purchase them individually at:

http://www.ciaopsacademy.com/

Also feel free at any stage to email me directly via director@ciaops.com with your webinar topic suggestions.

I’d also appreciate you sharing information about this webinar with anyone you feel may benefit from the session and I look forward to seeing you there.

Copilot for Security–The day after

Having set up Copilot for Security yesterday,

A day with Copilot for Security

and having an initial look around I decided to de-provision it after I was done for the day.

image

I returned the following day and set it all back up again using the same process as before. No issues.

image

I had a quick look at the billing in my Azure portal and noticed that some charges had appeared as shown above. They seem to however lag actual usage by at least 24 hours or more, so keep that in mind if you are trying to track costs closely

image

Because I also have Intune in the environment I took a look at where Copilot for Security is surfaced there. As you can see you get a big message in the homepage of the Intune portal when you navigate there reminding you that Copilot for Intune is available to you as part of Copilot for Security.

image

If you visit the Intune Tenant Admin area you’ll find a Copilot area as shown above. My check icon was green so I knew everything was working as expected.

image

I then opened a policy and found a Summarize with Copilot button which I used to generate the summary you see on the right hand side of the policy. Very handy.

image

I also found a Copilot button when I looked at individual devices. As you can see above, I can use Copilot to give me a comparison between the apps installed on devices. Nice.

image

I then generated some security ‘incidents’ on a device and checked the device in the Microsoft Security portal to see how Copilot would be surfaced. You’ll see it appears as a pane on the right, as shown above.

image

You’ll see in the above screen shot, I got Copilot to draft and email to send to the user of the problem machine. Very handy.

image

After playing around some more I went and looked at the Copilot for Security usage and you can see above, my unit usage was significantly higher than I initially provisioned. I assume I will be billed for those 3.7 units at US$4ph x the time I was actually playing around (about 1 hour). Let’s see when the costing make their way into the Azure portal.

image

I then went off and asked Copilot for Security about how to make my environment Essential 8 compliant, and you can see the response above.

image

I also found where you can upload you own company files to the environment to give it even more information you can use in your investigations.

image

I found an area where there was an option to allow Copilot for Security to access my Microsoft 365 data, shown above.

image

However, for whatever reason, it did not allow me enable this option as you can see from the error above. I’ll try that again during my next session.

So today’s session has shown me that you can de-commission and re-commission Copilot for Security on demand. At the moment that is a manual process via the GUI, but I expect that I’ll be able to script that with something PowerShell soon enough.

Without Copilot for Security being re-enabled I found that most Copilot menu items in places like Intune remained but failed to operate, not unexpectantly. However, when I re-provisioned Copilot for Security again on the second day, all those options worked again. Some took and little while to ‘refresh’, but they all started working again as on the first day.

I also noticed that all my previous chat sessions where all still available and accessible. This is thanks to retention that is part of Copilot for Security. I just need to find out how long that retention is.

So the main thing I learnt from day 2 with Copilot for Security is that you can utilise it on demand. It doesn’t seem that you actually need to have it running 24/7, which is great new for smaller businesses on a budget. I’m sure you get more out of it if you do indeed leave an SCU running 24/7 but seems to me, so far, that you don’t lose much just enabling it as you need.

I also learned that the cost reporting seems to take at least 24 hours to start appearing which can make budgeting a little butt clenching until the actual cost figure appear in the Azure portal. I also learned that after you enable Copilot for Security the menu option remain in the various portals, even after your de-provision the service. Now, these may indeed disappear after a period time if you don’t re-provision but I’d find any of the disable menu items presented any errors, they just didn’t do anything any more. Which is understandable.

In short, I think Copilot for Security will work in an SMB environment but currently, you’ll need to a bit of manual labour to enable and disable the service but I expect that can be improved with automation down the track.

I’ll be playing with Copilot for Security for another day and I’ll then share my overall thoughts and feedback on what I’ve seen and the ROI it provides. However, I will certainly be implementing this, in an on demand capacity, in my production environment.

More updates soon from day 3.

A day with Copilot for Security

Given that Copilot for Security has just been released, I thought I’d spin it up in my tenant and see what it looks like.

To get the most from Copilot for Security you’ll first need to have an Azure subscription. You’ll get more out of the service if you also have Intune and Sentinel as well as aggregation of your logs, but an Azure subscription is all you need to get started.

image

The easiest way to commence the set up process is to visit:

https://securitycopilot.microsoft.com

where you’ll be greeted with the set up wizard shown above.

Prior to setting up Copilot for Security, as I mentioned, you need an Azure subscription and I’d also recommend setting up a dedicated Azure Resource Group to help monitor and manage costs.

It is important to under what this will cost you in the default configuration. That is detailed on this page:

image

Yup, you read right $2,880 per month is the minimum! That is basically $4 per hour over 730 hours in a month. So, ensure you turn all this OFF once you have finished testing!

Once you complete all the listed fields you can continue.

image

You’ll need to wait a moment or two as the service is set up.

image

Since the Azure Resource Group into which I’m placing Copilot for Security is in Australia, my data will also be in Australia.

image

You’ll then be asked whether you wish to help Copilot improve as shown above. Make your choice and continue.

image

Next, you get the option to set up any permissions. As this is simply a test and I’ll be the only one using it I didn’t make any changes and just continued.

image

You should be all good to go as shown above.

image

If you now return to the initial starting point:

https://securitycopilot.microsoft.com

you should see the above, where you can input your query.

image

If you look in the Azure back end you will see a new item called Copilot inside your Azure portal, which looks like the above.

image

Selective the resource displayed the above.

image

You’ll also notice that you can’t adjust the Security Compute Units (SCU) below 1.

By clicking this button in the prompt

image

you’ll see all the plugins that can be configured in your environment

image

So, I went off and had a play to see what results it would give me.

image

I asked for some summaries.

image

and I had a look at some inbuilt playbooks.

image

I them dug around into the Usage monitoring which you’ll find the menu at the top left of the page.

image

In here I could change the Security compute units and delete them as well. Which I did eventually after play around a bit more.

Clearly, most smaller businesses are not going to justify running this full time. It is therefore VERY important to delete the SCU when you have finished playing around. After doing that and running Copilot for Security I was interested to see my bill, but as yet no amounts have appeared in my Azure portal. I’ll share these when they appear.

I still however believe this can be an effective security tool for SMB, PROVIDED, you enable and disable it as required, kind of on demand. I’m playing with doing that for myself to better understand any limitations on that approach and I’ll report back.

I have more to share on my findings so far so stay tuned.