<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>intune Archives - Erjen Rijnders</title>
	<atom:link href="https://erjenrijnders.nl/tag/intune/feed/" rel="self" type="application/rss+xml" />
	<link>https://erjenrijnders.nl/tag/intune/</link>
	<description>Microsoft Azure/EMS blog</description>
	<lastBuildDate>Tue, 23 Oct 2018 14:33:18 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.6.2</generator>
	<item>
		<title>Microsoft Ignite day 4</title>
		<link>https://erjenrijnders.nl/2018/09/27/microsoft-ignite-day-4/</link>
					<comments>https://erjenrijnders.nl/2018/09/27/microsoft-ignite-day-4/#respond</comments>
		
		<dc:creator><![CDATA[Erjen]]></dc:creator>
		<pubDate>Thu, 27 Sep 2018 21:07:19 +0000</pubDate>
				<category><![CDATA[Ignite 2018]]></category>
		<category><![CDATA[ignite 2018 day 4]]></category>
		<category><![CDATA[password-less]]></category>
		<category><![CDATA[external sharing]]></category>
		<category><![CDATA[sharepoint]]></category>
		<category><![CDATA[onedrive]]></category>
		<category><![CDATA[androind management api]]></category>
		<category><![CDATA[intune]]></category>
		<category><![CDATA[intune data warehouse]]></category>
		<category><![CDATA[azure blueprints]]></category>
		<category><![CDATA[ignite-2018]]></category>
		<guid isPermaLink="false">http://erjenrijnders.nl/?p=75810</guid>

					<description><![CDATA[<p>At first, I was a little sceptical about day 4 as I didn&#8217;t receive that much announcements in day 3 [&#8230;]</p>
<p>The post <a href="https://erjenrijnders.nl/2018/09/27/microsoft-ignite-day-4/">Microsoft Ignite day 4</a> appeared first on <a href="https://erjenrijnders.nl">Erjen Rijnders</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>At first, I was a little sceptical about day 4 as I didn&#8217;t receive that much announcements in day 3 so I thought of combining day 4 and 5. But what a day, so many announcements! Especially, check chapter 5 &#8220;Integrated Information Protection in external sharing SharePoint and OneDrive&#8221;, it&#8217;s fabulous. Here is Ignite day 4.</p>
<h1>Index:</h1>
<ol>
<li><a href="#azure-blueprints">Azure Blueprints</a></li>
<li><a href="#intune-data-warehouse">Intune Data Warehouse</a></li>
<li><a href="#intune-and-android-enterprise-management">Intune and Android Enterprise Management</a></li>
<li><a href="#android-management-api">Android Management API</a></li>
<li><a href="#integrated-information-protection-external-sharing-sharepoint-onedrive">Integrated Information Protection in external sharing SharePoint and OneDrive</a></li>
<li><a href="#experiences-password-less">Experiences with going password-less</a></li>
</ol>
<h1><a id="azure-blueprints"></a>Azure Blueprints</h1>
<p>With Azure Blueprints, announced very recently, you will get a blueprint that if you spin up a new subscription, you deploy the same policies, templates, security etc. In larger organizations, this is very helpful, you have your exact company policies spinned up in minutes! To activate this, go to the Azure Portal &gt; Policy &gt; Blueprints – Blueprint Definitions.</p>
<p><img fetchpriority="high" decoding="async" class="alignnone wp-image-75812" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/Azure-Blueprints.png" alt="" width="607" height="257" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/Azure-Blueprints.png 1020w, https://erjenrijnders.nl/wp-content/uploads/2018/09/Azure-Blueprints-300x127.png 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/Azure-Blueprints-768x325.png 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/Azure-Blueprints-600x254.png 600w" sizes="(max-width: 607px) 100vw, 607px" /></p>
<h1><a id="intune-data-warehouse"></a>Intune Data Warehouse</h1>
<p>At some point, if you are using Intune, you will face the problems generating reports in Intune. Fortunately, we have Intune Data Warehouse. I visited a session today at the Ignite Expo where I saw some great reports so let’s see how we actually start using Intune Data Warehouse. Go into the Azure Portal &gt; Intune and on the right, Click “Set up Intune Data Warehouse” and click “Download Power BI file”.</p>
<p><img decoding="async" class="alignnone wp-image-75813" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/download-powerbi-file.png" alt="" width="604" height="290" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/download-powerbi-file.png 2070w, https://erjenrijnders.nl/wp-content/uploads/2018/09/download-powerbi-file-300x144.png 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/download-powerbi-file-768x369.png 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/download-powerbi-file-1024x492.png 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/download-powerbi-file-600x288.png 600w" sizes="(max-width: 604px) 100vw, 604px" /></p>
<p>If the data is processed, you can directly start creating custom reports in Power BI. It’s just that easy. I know this is not new, but really, we should start using this a lot more so that we can get in-depth reports about our devices in the organization.</p>
<p><img decoding="async" class="alignnone wp-image-75814" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/intune-power-bi.png" alt="" width="655" height="434" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/intune-power-bi.png 1692w, https://erjenrijnders.nl/wp-content/uploads/2018/09/intune-power-bi-300x199.png 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/intune-power-bi-768x509.png 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/intune-power-bi-1024x678.png 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/intune-power-bi-600x398.png 600w" sizes="(max-width: 655px) 100vw, 655px" /></p>
<p>&nbsp;</p>
<h1><a id="intune-and-android-enterprise-management"></a>Intune and Android Enterprise Management</h1>
<p>In this session, some really great features are announced! Android Enterprise is evolving for sure. In Android Nougat (Android 7.0), we had the availability for Work Profiles in Android Enterprise, which we used a lot and worked great. Android Oreo (Android 8.0) took this even to a next level. Here you have a great overview of the new features each version.</p>
<p><img decoding="async" class="alignnone wp-image-75818" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/android-enterprise-evolving.jpg" alt="" width="714" height="405" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/android-enterprise-evolving.jpg 3749w, https://erjenrijnders.nl/wp-content/uploads/2018/09/android-enterprise-evolving-300x170.jpg 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/android-enterprise-evolving-768x436.jpg 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/android-enterprise-evolving-1024x581.jpg 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/android-enterprise-evolving-600x340.jpg 600w" sizes="(max-width: 714px) 100vw, 714px" /></p>
<p>Google discourages non-Work Profile as well because it requires Device Admin for the Intune App. that means that if we use the android App Managed mode, the user needs to give Device Admin rights to the Intune app and it needs to go through a lot of &#8220;Accept&#8221; screens as well. That scares of the user and we want the opposite. So you should use the &#8220;Work Profile&#8221; in Android Enterprise in my opinion if you use BYOD. You can separate apps from personal in this mode, you even create containerized apps which means that you could prohibit copying work information to personal owned apps.</p>
<p><img decoding="async" class="alignnone wp-image-75823" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/google-discourage-device-admin.jpg" alt="" width="619" height="351" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/google-discourage-device-admin.jpg 4321w, https://erjenrijnders.nl/wp-content/uploads/2018/09/google-discourage-device-admin-300x170.jpg 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/google-discourage-device-admin-768x435.jpg 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/google-discourage-device-admin-1024x581.jpg 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/google-discourage-device-admin-600x340.jpg 600w" sizes="(max-width: 619px) 100vw, 619px" /></p>
<p>Now if you have corporate owned devices, you have three options and later this year, you have four. The third is Dedicated mode (it’s basically a kiosk mode). With Kiosk Mode, the user has no flexibility at all. It can only open the apps provided by the company. This is, however, very functional in certain security related scenario&#8217;s. The last one, Fully Managed, will be available for preview this year. This gives you great user experience and manageability, integrated with the Androind Management API (see next chapter).</p>
<p><img decoding="async" class="alignnone wp-image-75817" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/androind-enterprise.jpg" alt="" width="656" height="406" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/androind-enterprise.jpg 4108w, https://erjenrijnders.nl/wp-content/uploads/2018/09/androind-enterprise-300x186.jpg 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/androind-enterprise-768x475.jpg 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/androind-enterprise-1024x633.jpg 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/androind-enterprise-600x371.jpg 600w" sizes="(max-width: 656px) 100vw, 656px" /></p>
<p>&nbsp;</p>
<h1><a id="android-management-api"></a>Android Management API</h1>
<p>another great feature is that the Android Enterprise devices now communicate with the Android Management API. this means that Android and Intune can now provide updates and new functionalities at a speed that was never possible before.</p>
<p><img decoding="async" class="alignnone wp-image-75820" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/android-management-api.jpg" alt="" width="592" height="336" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/android-management-api.jpg 4098w, https://erjenrijnders.nl/wp-content/uploads/2018/09/android-management-api-300x170.jpg 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/android-management-api-768x435.jpg 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/android-management-api-1024x580.jpg 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/android-management-api-600x340.jpg 600w" sizes="(max-width: 592px) 100vw, 592px" /></p>
<p>I am getting a little bored if I read my blog again for readability if I keep saying: another great feature! But how do I say this else, here is another great feature, Managed Google Play! This provides mobile app management in Android Enterprise, including silent installs for required apps. We can also now control over what apps ends users can install in work context. In addition to this, we have the possibility to fully configure, for example the Outlook app, before it gets installed on the client device. The Managed Google Play will be available through the Intune Portal. No separate login necessary.</p>
<p><img decoding="async" class="alignnone wp-image-75821" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/managed-google-play.jpg" alt="" width="681" height="368" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/managed-google-play.jpg 4375w, https://erjenrijnders.nl/wp-content/uploads/2018/09/managed-google-play-300x162.jpg 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/managed-google-play-768x415.jpg 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/managed-google-play-1024x553.jpg 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/managed-google-play-600x324.jpg 600w" sizes="(max-width: 681px) 100vw, 681px" /></p>
<p>&nbsp;</p>
<p>Google developed zero-touch with Intune. This is available with any Android Enterprise corp-owned deployment. This already works today with the dedicated device scenario and Android 8. This has some great feature updates however. If you go to <a href="https://partner.android.com">https://partner.android.com</a>, you can automatically assign a device to corporate policy and assigning a device to your company is going very smoothly. Check the screenshots below.</p>
<p><img decoding="async" class="alignnone wp-image-75824" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/android-zero-touch.jpg" alt="" width="558" height="334" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/android-zero-touch.jpg 4161w, https://erjenrijnders.nl/wp-content/uploads/2018/09/android-zero-touch-300x180.jpg 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/android-zero-touch-768x460.jpg 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/android-zero-touch-1024x613.jpg 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/android-zero-touch-600x359.jpg 600w" sizes="(max-width: 558px) 100vw, 558px" /> <img decoding="async" class="alignnone wp-image-75825" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/android-zero-touch-0.jpg" alt="" width="558" height="305" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/android-zero-touch-0.jpg 3928w, https://erjenrijnders.nl/wp-content/uploads/2018/09/android-zero-touch-0-300x164.jpg 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/android-zero-touch-0-768x420.jpg 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/android-zero-touch-0-1024x560.jpg 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/android-zero-touch-0-600x328.jpg 600w" sizes="(max-width: 558px) 100vw, 558px" /> <img decoding="async" class="alignnone wp-image-75826" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/android-zero-touch-1.jpg" alt="" width="561" height="306" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/android-zero-touch-1.jpg 4653w, https://erjenrijnders.nl/wp-content/uploads/2018/09/android-zero-touch-1-300x164.jpg 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/android-zero-touch-1-768x419.jpg 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/android-zero-touch-1-1024x558.jpg 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/android-zero-touch-1-600x327.jpg 600w" sizes="(max-width: 561px) 100vw, 561px" /> <img decoding="async" class="alignnone wp-image-75827" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/android-zero-touch-2.jpg" alt="" width="560" height="556" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/android-zero-touch-2.jpg 2289w, https://erjenrijnders.nl/wp-content/uploads/2018/09/android-zero-touch-2-150x150.jpg 150w, https://erjenrijnders.nl/wp-content/uploads/2018/09/android-zero-touch-2-300x298.jpg 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/android-zero-touch-2-768x763.jpg 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/android-zero-touch-2-1024x1017.jpg 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/android-zero-touch-2-600x596.jpg 600w, https://erjenrijnders.nl/wp-content/uploads/2018/09/android-zero-touch-2-100x100.jpg 100w" sizes="(max-width: 560px) 100vw, 560px" /></p>
<p>&nbsp;</p>
<h1><a id="integrated-information-protection-external-sharing-sharepoint-onedrive"></a>Integrated Information Protection in external sharing SharePoint and OneDrive</h1>
<p>Wow, I never saw so many new features on such a relatively small part of a product. The session was 75 minutes but it didn&#8217;t bore me a minute! They received a big applause as well, so let&#8217;s start.</p>
<h2>Smart People Picker and sharing</h2>
<p>The first new feature we have this year is the Smart People Picker. If you share a link, you will be presented with suggestions of people that SharePoint thinks you want to share the document with. Machine learning is behind this so it will take some time to present you with the right results, but it will get there (if it&#8217;s not there already). This sharing experience will be exactly the same on mobile and the same experience is built in Microsoft Teams. Sharing capabilities supports branding now which is integrated with the Azure AD branding functionality. So if you already configured that, it will work right away, as soon as this feature is rolled-out globally.</p>
<h2>Link Reminders</h2>
<p>Another feature that we were actually missing (but didn&#8217;t realize I did miss it till now) is that if someone opens a link, we can get a confirmation email that the link is clicked. If you share a link, it&#8217;s possible that the receiver didn&#8217;t open the link yet. There is a 95% change that if the link isn&#8217;t opened in 7 days, it will never be opened. So now we can configure automatic reminders that tells you if the link is not opened yet. Another new feature is that you can set a custom message on the &#8220;request access&#8221; page if you are trying to access a specific site or document.</p>
<h2>One-time passwords on link sharing</h2>
<p>Link sharing has further improved security. You can configure a one-time password for opening a document. It&#8217;s great for reviewing and for making sure that the recipient can only watch it once. Also, we can set per site specific sharing setting. Currently, if you disable the &#8220;Anyone&#8221; sharing setting, it&#8217;s effective for your whole tenant. So now it&#8217;s possible to configure this per site.</p>
<h2>Block file downloads</h2>
<p>The next feature is in my opinion the best feature. We can block downloads on a file and make it read only. With this new &#8220;Information Protection&#8221; possibility, we can fully control our documents and still collaborate in that same document. If you enable this setting, the file cannot be downloaded, printed, copied etc. Before, this was only possible if we classify documents and apply encryption. There was no other way of keeping control of your files. Now it&#8217;s possible without Azure Information Protection.</p>
<p><img decoding="async" class="alignnone wp-image-75833" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/block-downloads.jpg" alt="" width="621" height="409" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/block-downloads.jpg 4169w, https://erjenrijnders.nl/wp-content/uploads/2018/09/block-downloads-300x198.jpg 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/block-downloads-768x506.jpg 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/block-downloads-1024x675.jpg 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/block-downloads-600x395.jpg 600w" sizes="(max-width: 621px) 100vw, 621px" /></p>
<h2>Collaboration improvements</h2>
<p>Collaboration is an important part of our job every day and I am happy to tell you that collaboration in SharePoint and OneDrive is extended big time. For example if you are working in a PowerPoint presentation and you like having someone else checking your slide, you just mention someone at the side of the slide like you are used to be now. Use the @name format and the person will be notified by email immediately. This works for Office apps on Windows soon and will come later this year for MacOS as well.</p>
<p>In Microsoft Teams, we also have a new functionality. If we are uploading new files, we have the possibility to notify team members that you uploaded files.</p>
<h2>Admin control settings enhancements</h2>
<p>For the admin, we have more settings now we can control.</p>
<p><img decoding="async" class="alignnone wp-image-75832" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/20180927_131039.jpg" alt="" width="659" height="495" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/20180927_131039.jpg 4160w, https://erjenrijnders.nl/wp-content/uploads/2018/09/20180927_131039-300x225.jpg 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/20180927_131039-768x576.jpg 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/20180927_131039-1024x768.jpg 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/20180927_131039-600x450.jpg 600w" sizes="(max-width: 659px) 100vw, 659px" /></p>
<h2>Expiring links for external access</h2>
<p>And last but not least, we can set expiring links for external access! I think this is a really good feature because I get the question a lot: how can I keep control of shared files externally. Of course there are ways like Cloud App Security, make a person responsible for checking shared links etc. But why not just let the link expire? For example after 6 months? Sounds totally reasonable to me. If there is access needed after that time, you can just re-share the link.</p>
<h1><a id="experiences-password-less"></a>Experiences with going password-less</h1>
<p>Well, this one gave some new insights about the password-less world. Microsoft wants to get rid of passwords with good reasons, but it&#8217;s not that easy. Microsoft presents you with 4 simple steps:</p>
<ol>
<li>Implement Windows Hello For Business</li>
<li>Reduce user-visible password surface area</li>
<li>Transition into password-less deployment</li>
<li>Eliminate password from identity directory</li>
</ol>
<p>And this is all assuming that you can even make it to step 4. The biggest problem is with your on-premises apps. It can be very hard to transform these apps to password-less sign in so keep that into account. The non-marketing way of achieving this is a lot harder.</p>
<p>The post <a href="https://erjenrijnders.nl/2018/09/27/microsoft-ignite-day-4/">Microsoft Ignite day 4</a> appeared first on <a href="https://erjenrijnders.nl">Erjen Rijnders</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://erjenrijnders.nl/2018/09/27/microsoft-ignite-day-4/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Microsoft Ignite day 3</title>
		<link>https://erjenrijnders.nl/2018/09/27/microsoft-ignite-day-3/</link>
					<comments>https://erjenrijnders.nl/2018/09/27/microsoft-ignite-day-3/#respond</comments>
		
		<dc:creator><![CDATA[Erjen]]></dc:creator>
		<pubDate>Thu, 27 Sep 2018 02:18:03 +0000</pubDate>
				<category><![CDATA[Ignite 2018]]></category>
		<category><![CDATA[cloud app security]]></category>
		<category><![CDATA[Azure AD]]></category>
		<category><![CDATA[intune]]></category>
		<category><![CDATA[conditional access]]></category>
		<category><![CDATA[microsoft secure score]]></category>
		<category><![CDATA[identity protection]]></category>
		<guid isPermaLink="false">http://erjenrijnders.nl/?p=75777</guid>

					<description><![CDATA[<p>Azure AD Conditional Access We have some great new features in Azure AD Conditional Access, they are really taking it [&#8230;]</p>
<p>The post <a href="https://erjenrijnders.nl/2018/09/27/microsoft-ignite-day-3/">Microsoft Ignite day 3</a> appeared first on <a href="https://erjenrijnders.nl">Erjen Rijnders</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h1><a id="azure-ad-conditional-access"></a>Azure AD Conditional Access</h1>
<p>We have some great new features in Azure AD Conditional Access, they are really taking it to a next level. Conditional Access has now tight integration with Cloud App Security. It’s now possible to fully control and secure our data and information when you collaborate with a partner (B2B) or within your own tenant.</p>
<h1>Index:</h1>
<ol>
<li><a href="#azure-ad-conditional-access" rel="noopener">Azure AD Conditional Access</a></li>
<li><a href="#cloud-app-security-defender-atp" rel="noopener">Cloud App Security integration with Windows Defender ATP</a></li>
<li><a href="#microsoft-secure-score" rel="noopener">Microsoft Secure Score</a></li>
<li><a href="#identity-protection">Identity Protection</a></li>
<li><a href="#intune-updates">Intune Updates</a></li>
</ol>
<p>As you might probably now, Cloud App Security has tight integration with SharePoint already but now we can control on file level if a download for example is allowed or not. Check this screenshot below from the Ignite presentation:</p>
<p><img decoding="async" class="alignnone wp-image-75780" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/cloud-app-security-download-blocked.png" alt="cloud-app-security-download-blocked" width="627" height="335" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/cloud-app-security-download-blocked.png 1996w, https://erjenrijnders.nl/wp-content/uploads/2018/09/cloud-app-security-download-blocked-300x160.png 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/cloud-app-security-download-blocked-768x410.png 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/cloud-app-security-download-blocked-1024x546.png 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/cloud-app-security-download-blocked-600x320.png 600w" sizes="(max-width: 627px) 100vw, 627px" /></p>
<p>Another great update is that we can now enable Conditional Access App Control for Office applications. Before this was only possible with SAML-based apps. Based on the risk level of a user’s session, information can be accessed or blocked. Also risky OAuth applications can now be blocked with Cloud App Security. These updates make Cloud App Security even more powerful. If you aren’t using it right now, you should! It makes your organization a lot more secure.</p>
<p>Well, enough updates around Conditional Access right? It goes even further. We can not only control Exchange, but specific mailboxes within an account. The command runs as follows to enable this feature:</p>
<div class="codecolorer-container text twitlight" style="overflow:auto;white-space:nowrap;border:1px solid #9F9F9F;width:435px;"><table cellspacing="0" cellpadding="0"><tbody><tr><td style="padding:5px;font:normal 12px/1.4em Monaco, Lucida Console, monospace;white-space:nowrap;text-align:center;color:#888888;background-color:#EEEEEE;border-right: 1px solid #9F9F9F;"><div>1<br /></div></td><td><div class="text codecolorer" style="padding:5px;font:normal 12px/1.4em Monaco, Lucida Console, monospace;white-space:nowrap;">Set-OwaMailboxPolicy –Identity user –ConditionalAccessPolicy $true</div></td></tr></tbody></table></div>
<p>This command does not work yet and to be honest, I am not sure what it will actually do as I cannot test it yet. But I expect we will have some sub-commands in the near future to further control this.</p>
<h1><a id="cloud-app-security-defender-atp"></a>Cloud App Security integration with Windows Defender ATP</h1>
<p>Cloud App Security is now integrated with Windows Defender ATP! At first, we needed to install a Cloud App Security client which was too much because we had already so many clients installed. So they came up with the Cloud App Security broker which was an improvement on the client side, but then we needed to proxy all our traffic through it. We now we have the best solution, integration with Windows Defender ATP! I personally love this because configuring a separate gateway is no longer necessary. All traffic can be routed through Defender ATP (and the Defender client is installed by default with Windows 10). This is a great way of securing your information and it makes controlling your devices very easy. Here you can see information is being fed from Windows Defender ATP.</p>
<p><img decoding="async" class="alignnone wp-image-75781" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/cloud-app-security-defender-atp.png" alt="cloud-app-security-defender-atp" width="656" height="307" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/cloud-app-security-defender-atp.png 2563w, https://erjenrijnders.nl/wp-content/uploads/2018/09/cloud-app-security-defender-atp-300x140.png 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/cloud-app-security-defender-atp-768x359.png 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/cloud-app-security-defender-atp-1024x479.png 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/cloud-app-security-defender-atp-600x281.png 600w" sizes="(max-width: 656px) 100vw, 656px" /></p>
<p>In Windows Defender ATP, you only have to enable this.</p>
<p><img decoding="async" class="alignnone wp-image-75782" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/cloud-app-security-defender-atp-settings.png" alt="cloud-app-security-defender-atp-settings" width="581" height="362" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/cloud-app-security-defender-atp-settings.png 1407w, https://erjenrijnders.nl/wp-content/uploads/2018/09/cloud-app-security-defender-atp-settings-300x187.png 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/cloud-app-security-defender-atp-settings-768x478.png 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/cloud-app-security-defender-atp-settings-1024x637.png 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/cloud-app-security-defender-atp-settings-600x373.png 600w" sizes="(max-width: 581px) 100vw, 581px" /></p>
<p>After enabling this setting, it will Cloud App Security feed traffic and device information from Windows Defender ATP.</p>
<h1><a id="microsoft-secure-score"></a>Microsoft Secure Score</h1>
<p>We have heard in almost every session that we should enable Microsoft Secure Score. I do agree that we should enable it on all our tenants (so I am telling you again now :)) and it is also enabled now through Azure Active Directory (you can go to <a href="https://securescore.microsoft.com/">https://securescore.microsoft.com/</a> as well). It looks like this:</p>
<p><img decoding="async" class="alignnone wp-image-75783" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/laborie-secure-score.png" alt="laborie-secure-score" width="619" height="408" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/laborie-secure-score.png 2219w, https://erjenrijnders.nl/wp-content/uploads/2018/09/laborie-secure-score-300x198.png 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/laborie-secure-score-768x506.png 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/laborie-secure-score-1024x675.png 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/laborie-secure-score-600x395.png 600w" sizes="(max-width: 619px) 100vw, 619px" /></p>
<p>It looks good and it will only show the score that you have access too. Like if you don’t have EM+S E5, you won’t see identity protection related security scores.</p>
<h1><a id="identity-protection"></a>Identity Protection</h1>
<p>Identity Protection does now have integration with Azure ATP. Azure ATP is a security service based on DNS checks. Risky sign-ins from these two products can now be viewed from a single panel. And of course, we can apply conditional access on this. If Azure ATP feeds Identity Protection with a risky sign-on, it can be blocked, based on your Conditional Access settings. Combining these two sources, you have a very powerful solution. You see all high risk devices and users and all items that needs attention are presented through one combined interface.</p>
<p><img decoding="async" class="alignnone wp-image-75802" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/Identity-protection-azure-atp.png" alt="Identity-protection-azure-atp" width="582" height="423" /></p>
<h1><a id="intune-updates"></a>Intune updates</h1>
<p>As you might know by now is that my main focus is within the &#8220;Information Protection&#8221; field which includes parts of Cloud App Security and Intune as well. So I wanted to post some updates around Intune, Windows Information Protection (which is part of Intune) and device management. That&#8217;s why I visited the session &#8220;What’s new in Windows 10 mobile device management (MDM)&#8221; . But right from the start I thought: Are we really going to do this for 75 minutes? I barely heard anything new and I love to share new stuff to the world. For example the presenter said that we should focus on co-management, 1 of 3 points she gave as a call-to-action. Isn&#8217;t this already possible for years now?</p>
<p>Also, we were presented slides like this:</p>
<p><img decoding="async" class="alignnone wp-image-75778" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/intune-slide1.png" alt="intune-slide1" width="573" height="314" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/intune-slide1.png 1644w, https://erjenrijnders.nl/wp-content/uploads/2018/09/intune-slide1-300x164.png 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/intune-slide1-768x421.png 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/intune-slide1-1024x561.png 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/intune-slide1-600x329.png 600w" sizes="(max-width: 573px) 100vw, 573px" /></p>
<p>Really? I want to see what’s NEW. Anyway, a little good news however, Kiosk mode control is now generally available and we will get better security baselines for Microsoft Intune. Maybe you have another opinion about this session, I would love to hear from you through comments below.</p>
<p>So this is basically it. We saw a lot of sessions but a lot of sessions presented content already covered in day 1 and 2. I don’t expect much more announcements in day 4 and 5. Maybe I will wrap them together in one blogpost, depending on the content of tomorrow.</p>
<p>But still, Ignite brought me definitely the sessions above expectations!</p>
<p>&nbsp;</p>
<p>The post <a href="https://erjenrijnders.nl/2018/09/27/microsoft-ignite-day-3/">Microsoft Ignite day 3</a> appeared first on <a href="https://erjenrijnders.nl">Erjen Rijnders</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://erjenrijnders.nl/2018/09/27/microsoft-ignite-day-3/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
