Encryption in Microsoft 365 - ExpertsLive Netherlands 2024

appie1701 231 views 53 slides Jun 04, 2024
Slide 1
Slide 1 of 53
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14
Slide 15
15
Slide 16
16
Slide 17
17
Slide 18
18
Slide 19
19
Slide 20
20
Slide 21
21
Slide 22
22
Slide 23
23
Slide 24
24
Slide 25
25
Slide 26
26
Slide 27
27
Slide 28
28
Slide 29
29
Slide 30
30
Slide 31
31
Slide 32
32
Slide 33
33
Slide 34
34
Slide 35
35
Slide 36
36
Slide 37
37
Slide 38
38
Slide 39
39
Slide 40
40
Slide 41
41
Slide 42
42
Slide 43
43
Slide 44
44
Slide 45
45
Slide 46
46
Slide 47
47
Slide 48
48
Slide 49
49
Slide 50
50
Slide 51
51
Slide 52
52
Slide 53
53

About This Presentation

In this session I delve into the encryption technology used in Microsoft 365 and Microsoft Purview. Including the concepts of Customer Key and Double Key Encryption.


Slide Content

Albert Hoitingh Encryption in Microsoft 365 Start 7:45

Encryption in Microsoft 365

Principal consultant Microsoft Security MVP Albert Hoitingh

Today’s agenda

Encryption in Microsoft 365 and Purview

Different scopes

Short side note…

Short side note…

Licensing considerations

Data at rest Per-file encryption (SPO) BitLocker – on many levels Data Encryption Policies ( DEPs ) SharePoint Online and OneDrive Exchange Online All other Microsoft 365 services, incl. Microsoft Purview Information Protection

Data in transit Secure Real-Time Transport Protocol (SRTP) (Mutual) Transport Layer Security (MTLS/TLS) Exchange IRM – s/MIME – OME https://www.adaptivedigital.com/secure-rtp/

Key management

Key management

Microsoft managed SharePoint Online, OneDrive Exchange Online

Customer key Access by Microsoft Organization in control Different DEPs , including multi-geo Azure Key Vault Hardware Security Modules

Customer Key SharePoint Online, OneDrive Exchange Online

Customer Key per DEP https://learn.microsoft.com/en-us/purview/customer-key-set-up

Customer Key per DEP https://learn.microsoft.com/en-us/purview/customer-key-set-up

Customer Key status

Double Key Encryption Tenant key and organizational key Office Apps | Sensitivity labels Impairs specific functions

Double Key Encryption

Sensitivity labels

Items and labels Encryption | Visual markings | Offline availability Label stays with item Hierarchy is important

Encryption standards

How it works

Filetypes are important Microsoft Purview Information Protection Viewer client Native clients | Microsoft Edge Watch out for the file extension | some types only support classification

Identities are important Microsoft Live | Guest | RMS Entra ID accounts Set- SPOTenant -EnableAzureADB2BIntegration

Identities are important Microsoft Live | Guest | RMS Entra ID accounts Set- SPOTenant -EnableAzureADB2BIntegration

Consequences eDiscovery | content search Co-authoring | auto-save Microsoft 365 Copilot

Consequences eDiscovery | content search Co-authoring | auto-save Microsoft 365 Copilot

Consequences eDiscovery | content search Co-authoring | auto-save Microsoft 365 Copilot

Microsoft Purview Message Encryption

Secure e-mail in Microsoft 365

Microsoft Purview Message Encryption

Advanced message encryption Mail rules using sensitive information types Revocation and expiration Information Protection and Governance Compliance E5 Microsoft 365

Encapsulated e-mail message Outlook: opens natively . pmsg file MPIP viewer does not work Secure web-portal

E-mail attachments Do not forward | Encrypt only Non-protected Office document Protected Office document Mind the Entra ID account Set- IRMConfiguration - DecryptAttachmentForEncryptOnly <$true|$false>

Run-through Message Encryption

Things to think about

Tips and tricks Sharing encrypted files Older metadata model (MPIP_) Decrypt documents from SPO: Unlock- SensitivityLabelEncryptedFile Super User role eDiscovery (Premium) Encrypted/Signed PDFs Guaranteed SharePoint Permissions

What about migrating? https://learn.microsoft.com/en-us/microsoft-365/enterprise/microsoft-365-tenant-to-tenant-migrations?view=o365-worldwide

THANK YOU Are there any questions? Please evaluate this session in the App.

Next session 10:10 – 11:00 The Graph API StarterKit for AVD and W365 automation