Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
appie1701
231 views
53 slides
Jun 04, 2024
Slide 1 of 53
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
About This Presentation
In this session I delve into the encryption technology used in Microsoft 365 and Microsoft Purview. Including the concepts of Customer Key and Double Key Encryption.
Size: 12.05 MB
Language: en
Added: Jun 04, 2024
Slides: 53 pages
Slide Content
Albert Hoitingh Encryption in Microsoft 365 Start 7:45
Encryption in Microsoft 365
Principal consultant Microsoft Security MVP Albert Hoitingh
Today’s agenda
Encryption in Microsoft 365 and Purview
Different scopes
Short side note…
Short side note…
Licensing considerations
Data at rest Per-file encryption (SPO) BitLocker – on many levels Data Encryption Policies ( DEPs ) SharePoint Online and OneDrive Exchange Online All other Microsoft 365 services, incl. Microsoft Purview Information Protection
Data in transit Secure Real-Time Transport Protocol (SRTP) (Mutual) Transport Layer Security (MTLS/TLS) Exchange IRM – s/MIME – OME https://www.adaptivedigital.com/secure-rtp/
Key management
Key management
Microsoft managed SharePoint Online, OneDrive Exchange Online
Customer key Access by Microsoft Organization in control Different DEPs , including multi-geo Azure Key Vault Hardware Security Modules
Customer Key per DEP https://learn.microsoft.com/en-us/purview/customer-key-set-up
Customer Key per DEP https://learn.microsoft.com/en-us/purview/customer-key-set-up
Customer Key status
Double Key Encryption Tenant key and organizational key Office Apps | Sensitivity labels Impairs specific functions
Double Key Encryption
Sensitivity labels
Items and labels Encryption | Visual markings | Offline availability Label stays with item Hierarchy is important
Encryption standards
How it works
Filetypes are important Microsoft Purview Information Protection Viewer client Native clients | Microsoft Edge Watch out for the file extension | some types only support classification
Identities are important Microsoft Live | Guest | RMS Entra ID accounts Set- SPOTenant -EnableAzureADB2BIntegration
Identities are important Microsoft Live | Guest | RMS Entra ID accounts Set- SPOTenant -EnableAzureADB2BIntegration
Advanced message encryption Mail rules using sensitive information types Revocation and expiration Information Protection and Governance Compliance E5 Microsoft 365
Encapsulated e-mail message Outlook: opens natively . pmsg file MPIP viewer does not work Secure web-portal
E-mail attachments Do not forward | Encrypt only Non-protected Office document Protected Office document Mind the Entra ID account Set- IRMConfiguration - DecryptAttachmentForEncryptOnly <$true|$false>
Run-through Message Encryption
Things to think about
Tips and tricks Sharing encrypted files Older metadata model (MPIP_) Decrypt documents from SPO: Unlock- SensitivityLabelEncryptedFile Super User role eDiscovery (Premium) Encrypted/Signed PDFs Guaranteed SharePoint Permissions
What about migrating? https://learn.microsoft.com/en-us/microsoft-365/enterprise/microsoft-365-tenant-to-tenant-migrations?view=o365-worldwide
THANK YOU Are there any questions? Please evaluate this session in the App.
Next session 10:10 – 11:00 The Graph API StarterKit for AVD and W365 automation