6/26/2018 5:24 AM THR1083 Enabling Advanced Security Capabilities: Drive consistent authorization across multiple applications Bryan Bolling Solution Architect,

Slides:



Advertisements
Similar presentations
MIX 09 4/15/ :14 PM © 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
Advertisements

Session 1.
© 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or.
© 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or.

© 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks.
© 2008 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or.

Azure on Steroids: Full Automation with PowerShell
6/5/2018 1:30 PM THR1029 Spend less time managing data and more time with customers: Quick tour of Outlook Customer Manager Welly Lee
Azure Cloud Shell Magic of Modern Command-line Management
6/19/2018 2:57 AM THR3092 Monitor and investigate actions on your user and data with alerts, insights and reports Binyan Chen Program Manager II, Office.
Azure SDKs and Tools for You
Optimizing Microsoft OneDrive for the enterprise
What a Real, Functioning DevOps Team Looks Like
“Enable, Invent & Adopt, Transform”
Protect sensitive information with Office 365 DLP
SQL Server on Linux on All-Flash Arrays
Excel and Power BI Better Together Democratization of data
Workflow Orchestration with Adobe I/O
Customize Office 365 Search and create result sources
How we got a traditional bank collaborating across boundaries
The utility belt for managing security and compliance in Office 365
Find, try and get line-of-business apps on Microsoft AppSource
User Group Best Practices
Build advanced PowerApps that work offline!
Automate all things! Microsoft Azure continuous deployment
Agile Planning with Visual Studio Team Services (VSTS)
Seamlessly add video into O365 app or other apps with Microsoft Stream
9/22/2018 3:49 AM BRK2247 Learn from MVPs: Panel discussion on all things SharePoint and OneDrive © Microsoft Corporation. All rights reserved. MICROSOFT.
Confidence at speed: Visual Studio 2017 and your CI pipeline
Azure PowerShell Aaron Roney Senior Program Manager Cormac McCarthy
Seamlessly add video into O365 app or other apps with Microsoft Stream
Continuous Delivery with Visual Studio Team Services
Azure Advisor: Optimization in the best way
Accelerate Office 365 Adoption Through Microsoft FastTrack Services
Microsoft products for non-profits
Automating security for better, continuous compliance in the cloud
Introduction to ASP.NET Core 1.0
Five cool things you can do with Windows PowerShell on Office 365
Microsoft To-Do Preview
Securely pass passwords into your deployment
Yammer for IT Tom Kretzmer Solutions Developer, Westinghouse THR1016
Microsoft Exchange: Through the eyes of MVPs (Panel discussion)
MDM Migration Analysis Tool (MMAT)
Overview: Dynamics 365 for Project Service Automation
Understand your Azure cloud assets dependencies with BMC Discovery
Surviving identity management in a hybrid world
Sami Laiho AMA - Ask Me Anything
Breaking Down the Value of A Yammer Post: 20 Things to Do
8/04/2019 9:13 PM © 2006 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
Cool Microsoft Edge Tips and Tricks
When Bad Things Happen to Good Applications
Getting the most out of Azure resources with Azure Advisor
Manage your App Service resources using Command line tools
“Hey Mom, I’ll Fix Your Computer”
Windows 8 Security Internals
4/21/2019 7:09 AM THR2098 Unlock New Opportunities with Nintex Hawkeye Process Intelligence and Workflow Analytics Sr. Product.
4/28/2019 3:30 AM THR1061 Learn how Dynamics 365, Office 365 and related applications work together to transform the workplace Donna Edwards Solution Architect.
Виктор Хаджийски Катедра “Металургия на желязото и металолеене”
Consolidate, manage, backup, and secure your cloud content
Designing Bots that Fit Your Organization
Ask the Experts: Windows 10 deployment and servicing
Passwordless Service Accounts
Шитманов Дархан Қаражанұлы Тарих пәнінің
Digital Transformation: Putting the Jigsaw Together
WCF and .NET Framework Microservices in Containers
Diagnostics and troubleshooting in Azure App Service Support Center
Optimizing your content for search and discovery
Presentation transcript:

6/26/2018 5:24 AM THR1083 Enabling Advanced Security Capabilities: Drive consistent authorization across multiple applications Bryan Bolling Solution Architect, Microsoft Steve Lewis Senior Consultant, Microsoft © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

6/26/2018 5:24 AM Business Case Application data access is tightly coupled to application platforms Business needs must drive access across platforms in a consistent manner Application data access requirements must drive granular controls for data protection in business terms It is time for the business needs to drive the way content is protected with terms business users and systems understand. © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Approach Provide a centralized authorization model 6/26/2018 5:24 AM Approach Provide a centralized authorization model Accessible via enterprise applications Accessible via an API © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Policy Management Components 6/26/2018 5:24 AM Policy Management Components Data Classification Management Tool User Users with attributes Rules Policies defining access privileges and obligations Resources Securable items User Attributes Employee Type Office Citizenship Resource Tags Document Type Creation Office Releasability Controls Rule 1: User.EmployeeType = Resource.Document Type Rule 2: User.Office Contained In Resource.Creation Office Rule 3: User.Citizenship Contained In Resource. ReleasabilityControls OR Resource.ReleaseabilityControls = UNKNOWN © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Successful User Access 6/26/2018 5:24 AM Successful User Access Resource Tags Document Type = Engineer Creation Office = Flight Controls Releaseability Controls = UNKNOWN User Attributes Employee Type = Engineer Office = Aerospace, Flight Controls Citizenship = USA Rule 1: User.EmployeeType = Resource.Document Type Rule 2: User.Office Contained In Resource.Creation Office Rule 3: User.Citizenship Contained In Resource. ReleasabilityControls OR Resource.ReleaseabilityControls = UNKNOWN © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Failed User Access User Attributes Resource Tags 6/26/2018 5:24 AM Failed User Access User Attributes EmployeeType = Engineer, FTE Office = Aerospace, Flight Controls Citizenship = USA Resource Tags Document Type = Engineer Creation Office = Avionics ReleasabilityControls = UNKNOWN Rule 1: User.EmployeeType = Resource.Document Type Rule 2: User.Office Contained In Resource.Creation Office Rule 3: User.Citizenship Contained In Resource. ReleasabilityControls OR Resource.ReleaseabilityControls = UNKNOWN © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

High Level Solution Overview Authorization Policy Enforcement for: Access Control Data Filtering Redaction Masking Encryption Dynamic SoD Controls Data Segregation Data Residency Data Classification Data Loss Prevention Rights Protection Document Quarantine Document Control User Activity 1 Authorized Access 8 2 Intercept Event 7 Enforce Decision AuthZ Request 3 Decision 6 Attribute Sources LDAP Get Attributes 5 4 Evaluate Policies Services

Key Takeaways Consistent Data Categorization and Classification 6/26/2018 5:24 AM Key Takeaways Consistent Data Categorization and Classification Aligning data tagging with user attributes Defined processes to manage attribute life cycle User Attributes must be kept up to date Leverage user attributes from HR or other systems of record Service accounts have identities and need to be managed just like people Provide attributes for service accounts Or Exclude service accounts from policies © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Please evaluate this session Tech Ready 15 6/26/2018 Please evaluate this session From your Please expand notes window at bottom of slide and read. Then Delete this text box. PC or tablet: visit MyIgnite https://myignite.microsoft.com/evaluations Phone: download and use the Microsoft Ignite mobile app https://aka.ms/ignite.mobileapp Your input is important! © 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

6/26/2018 5:24 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.