Showing posts with label Exchange Online. Show all posts
Showing posts with label Exchange Online. Show all posts

Saturday, November 1, 2025

What's New in M365 Copilot in Oct 2025

There were a lot of new interesting new capabilities being released into M365 Copilot in the month of Oct 2025.  Here are the ones that caught my eye:

  • New Session Persistence Enhancements: Ensures users can seamlessly continue conversations when navigating away from a chat session.
  • Chat GPT-5 will become the new default model for Copilot Chat.  Currently, you must select it.
  • Microsoft Teams Audio Recap is being released.  This gives users the ability to get pod-cast style audio recaps of meetings they select in newscast, executive or casual formats.  You no longer have to sit there and read tons of recaps, you can now listen to the recaps on your drive home!
  • Have Copilot draft meeting agendas based on when the meeting is, the attendees, title and users meeting inputs.  Copilot will leverage all your M365 Copilot data in email, chat, and documents and then create an agenda for you.
  • Copilot Chat Capabilities with Exchange Online Calendar: 
    • Search a calendar based on meeting organizers making it super easy to get all meeting information and summaries.
    • Seach calendars that you have been delegated access to which is great for executive assistants to pull information about meetings.
    • Search calendars based on meeting categories like title, date, time and location.
  • When opening an Office file on a mobile device, you can use Copilot Chat in the file “preview” which streamlines the user experience to ask questions.
  • The new Surveys Agent has been rolled out.  This is an agent that automates the workflow of creating surveys.
  • Copilot in PowerPoint speaker notes generation.
  • Bing web cards will now be appearing in Copilot Chat with quick visualizations of weather, stocks, sports, new, current events, etc.
  • New simple Copilot Chat APIs allows users to simply sent prompts to the API and get back results.
  • M365 Copilot Usage reports is being rolled out to GCC cloud!
  • New M365 Copilot usage reports that provide detailed metrics on the total prompt submissions at both organizational and user levels.
  • New Agent ownership reassignment enables administrators to transfer ownership of agents within the organization with an employee leaves or changes roles.
  • Administrators can export their agent inventory along with metadata to perform independent review and analysis of all agents.
  • Administrators can pin M365 Companion Apps (People, Files and Calendar) in all user taskbars.  These apps give users real time information integrated with Copilot.

Reference: https://techcommunity.microsoft.com/blog/microsoft365copilotblog/what%E2%80%99s-new-in-microsoft-365-copilot--october-2025/4464046


Friday, August 16, 2024

Microsoft 365 Backup GA

A new solution called Microsoft 365 Backup and Backup Storage recently went GA.

This is a really cool new capacity that assists organizations in protecting themselves from disaster recovery and security scenarios when you need to recover your data.  Microsoft 365 has tons of data protection services built natively into the service.  Microsoft 365 Backup helps protect you against ransomware attacks and gives you the ability to have self-service recovery capabilities.

Microsoft 365 Backup is currently scoped to OneDrive, SharePoint and Exchange data.  With Microsoft 365 Backup you have the ability to mass backups and recovery points for your most critical business data.

For more information, read here: https://techcommunity.microsoft.com/t5/microsoft-365-backup-blog/microsoft-announces-general-availability-of-microsoft-365-backup/ba-p/4205300

Friday, September 30, 2022

Exchange Online Client Access Rules (CAR) Planned Depreciation

Today I saw that Exchange Online Client Access Rules (CAR) plan to be deprecated in about 12 months.  Customers are encouraged to start leveraging AAD Continuous Access Evaluation (CAE) in its place.  I have seen customers extensively leverage CAR policies as way to control access to email.  Please see article for additional information.

https://techcommunity.microsoft.com/t5/exchange-team-blog/deprecation-of-client-access-rules-in-exchange-online/ba-p/3638563 


Sunday, April 11, 2021

Microsoft Teams and Exchange Server On-Prem Calendars

This is actually a really interesting three part blog series on how to configure Microsoft Teams (in the cloud), with Exchange Server on-prem.  Microsoft Teams can only be delivered in the cloud and draws huge dependencies on Exchange Online and SharePoint Online.  However there are still organizations that for various reasons still have Exchange Server on-premises.  This article focuses specifically on how you can integrate your Exchange Server on-prem Calendar with Microsoft Teams.

Part 1 - https://techcommunity.microsoft.com/t5/microsoft-teams-community-blog/microsoft-teams-and-on-premises-mailboxes-part-1-how-do-teams/ba-p/2229851 

Part 2 - https://techcommunity.microsoft.com/t5/microsoft-teams-community-blog/microsoft-teams-and-on-premises-mailboxes-part-2-teams-calendar/ba-p/2232602

Part 3 - https://techcommunity.microsoft.com/t5/microsoft-teams-community-blog/microsoft-teams-and-on-premises-mailboxes-part-3-calendar-based/ba-p/2235211 


Monday, January 4, 2021

Microsoft Search and Exchange Online

This week, I had to go into Microsoft Outlook to find an old HR benefit email I had gotten some time ago.  This case, as Microsoft employee get a benefit of free Xbox Game Pass subscription.  I had some old emails on it, and wanted to find the link.  When I found the old emails, none of the links worked because there old.

Then all of a sudden a message came up saying, “Link from your organization”, here is the correct link.  I clicked it, it took me straight to the internal benefit site.  This was awesome and I was totally surprised I did not even know about this feature.


I then did some additional investigation.  I put in some other Microsoft corporate terms into Outlook search and got back tons of other result “Link from your organization” section which gave me links within the Microsoft intranet to webpages that had the information for me.

Well, there was a simple reason for this.  Many folks may not have seen this but Outlook and Office are now integrated with Microsoft Search.  This all started about a year ago.  Basically, whenever you put in a search in Outlook, there is a search in your email however additional resources available to you will be searched.  If you organization has set up Microsoft Search appropriately, you will get items in your mailbox plus items across the organization that you have access to. 

Resources



Saturday, January 12, 2019

Microsoft Teams Support when user mailbox is in Exchange On-Premises

I have been asked a lot lately, it is possible to use Microsoft Teams while still having your mailbox located on Exchange On-Premises.

The answer is yes, this is a supported scenario.  Microsoft Teams has a strong dependency on Exchange Online because all of your personal discusses are stored in Exchange Online.  If the user’s mailbox is still on-premises, a cloud-based storage area will be created for that user called a “cloud-based mailbox for on-premises user”.  This solution will only store Teams conversations and the user cannot directly log into this mailbox.

To support this, you must have Exchange Hybrid configured and you must be using AAD Sync.
To enable this, there is a request process you must go through, defined in the references below.

Additionally, if the on-prem mailbox is ever migrated to Exchange Online later, the Teams chat data will not be lost, the data will be migrated over to the primary mailbox in the cloud.

https://docs.microsoft.com/en-us/MicrosoftTeams/exchange-teams-interact
https://docs.microsoft.com/en-us/office365/securitycompliance/search-cloud-based-mailboxes-for-on-premises-users

Tuesday, September 11, 2018

Office 365 Data Delete

I receive lots of questions about how to remove data from Office 365.  There can be lots of business scenarios: for instance, someone leaves the organization and you no longer want to retain data another instance is critical business or mission data needs to be deleted.  If you are looking to build procedures for data deletion, recommend that you review these:

Deleting Personal Data - https://docs.microsoft.com/en-us/microsoft-365/compliance/gdpr-dsr-office365#deleting-personal-data

eDiscovery solution series: Data spillage scenario - Search and purge - https://docs.microsoft.com/en-us/office365/securitycompliance/data-spillage-scenariosearch-and-purge?redirectSourcePath=%252fen-us%252farticle%252fediscovery-solution-series-data-spillage-scenario-search-and-purge-d945f7dd-f62f-4ca7-b3e7-469824cfd493

Tuesday, November 1, 2016

Office 365 Business-to-Business (B2B) Capabilities

Introduction

This has come up a lot lately and I want to write something about this.  Business-to-business (B2B) capabilities are available in Office 365 and here are some features can consider turning on.
Skype for Business Online

Federation

Skype for Business Online external connectivity (federation) enables a Skype for Business Online user to connect with users in other organizations that use Skype for Business (as well as those that host their own Skype for Business Server on-premises). Federated contacts can see presence, communicate by using IM, and make Skype-to-Skype audio and video calls.

Skype for Business Online external connectivity requires the consent and correct configuration of both parties of the federation relationship. After the federation is set up by the administrators of both sides, users in each organization can see presence and communicate with users in the other agencies.

References

Public IM Connectivity


Additionally, Skype for Business Online can be configured to allow communications to consumer Skype.  This can enable communications scenarios with citizens and constituents.  Presence, instant messaging and video conversations is supported.

References

Exchange Online

Federated Sharing


Federation refers to the underlying trust infrastructure that supports federated sharing, a method for Microsoft Exchange Online users to share free/busy calendar data and contact information with recipients in other external federated organizations or with users that have Internet access. These include organizations that are also hosted by Exchange Online, or external Microsoft Exchange Server 2010 or Exchange Server 2013 organizations. Using organization relationships and sharing policies, Exchange Online administrators can enable users to send calendar-sharing invitations from Microsoft Outlook Web App or Microsoft Outlook 2010 or later.

Once configured, an organization will have the ability to coordinate schedules with people in different agencies or with friends and family members so that you can work together on projects or plan social events. With Office 365, administrators can set up different levels of calendar access in Exchange Online to allow businesses to collaborate with other businesses and to let users share their schedules with others. Business-to-business calendar sharing is set up by creating organization relationships. User-to-user calendar sharing is set up by applying sharing policies.

References

Exchange Online Protection

Trusted Partner Messaging


Organizations can set up secure mail flow with a trusted partner by using Office 365 connectors. Office 365 supports secure communication through Transport Layer Security (TLS). Agencies can create a connector to enforce encryption via TLS for business-to-business emails. Additionally, there is the ability to apply other security restrictions such as specifying domain names or IP address ranges from which your partner organization sends mail. TLS is a cryptographic protocol that provides security for communications over the Internet. Using connectors, you can configure both forced inbound and outbound TLS using self-signed or certification authority (CA)-validated certificates.
Note - this solution does not impact the actual end user experience of sending email between organizations, however it adds an additional level of security if desired for sending email between agencies.

References

SharePoint Online and OneDrive for Business


Guest Access


If an organization performs work that involves sharing documents or collaborating directly with vendors, clients, partners, or customers, it is possible to use SharePoint Online sites to share content with people outside your organization who do not have licenses for your organization’s Microsoft Office 365 subscription. When a site is shared in SharePoint Online, an email message is sent to the external user containing the invitation to join the site.
  • If the external user is already associated to an Office 365 tenant, that user can use that identity to access SharePoint Online sites and documents that are shared. 
  • If the external user does not have an Office 365 account, they can access SharePoint Online using Microsoft Account (Your Microsoft account is the one that you use for personal services like Xbox Live, Outlook.com, Windows 8, Windows Phone, and more).  Invitations can be sent to people with any type of email address, such as user@gmail.com, user@contoso.com, or user@Comcast.net. External users sign in to the shared site via a one-time association of their email address with a Microsoft account.
Additionally, site users can generate a Guest Link (an anonymous link to a document) to share documents stored in SharePoint Online with external users without requiring the external user to sign in. Site users can create a Guest Link right from where the document is stored, such as in OneDrive for Business or a team site library, by using the “Get a link” button.

Finally, there is solution called Restricted Domain sharing that you can consider using.  This allows for an Allow/Deny List based on email domain.  At the tenant level, administrators can limit sharing invitations to a limited number of email domains.  This is a powerful feature that will allow you to set-up controlled external sharing with your partners.

References

What is Office 365 Groups?


Office 365 Groups is the next generation of collaboration solution available in Office 365 that brings together “best of breed” collaboration experiences.  Office 365 Groups bring together Exchange Online, SharePoint Online, OneDrive for Business, Office Online, and Skype for Business Online into a unified end user experience.  When a group is created:
  • A mailbox is created for the group for shared email
  • A shared calendar is created for group meetings and events
  • A shared library is created to store files and documents
  • A OneNote notebook is created to share project information and meeting notes
  • A planning tool is available to organize and assign tasks

Note that Office 365 Groups is a “suite” feature requiring the acquisition of an Office 365 E3 (or higher) Suite.

Guest Access for Business-to-Business Collaboration


Office 365 Groups supports the ability to invite guests in a similar manner as SharePoint Online and OneDrive for Business.  Office 365 Groups has been available for time and this is a new feature that US Federal agencies should consider leveraging for cross-business collaboration.

Monday, September 5, 2016

Office 365 MDM or Microsoft Intune?

Introduction
I have been asked several times, what are the MDM capabilities available in Office 365 versus what additional capabilities do you get with Intune?

In this quick article I will explore the differences.

What is Office 365 MDM?
In Office 365 there are several native MDM capabilities.

First there is Exchange ActiveSync (EAS) which is part of Exchange Online.  With EAS you:
  • Have the ability to manage an inventory of mobile devices that are connected to Exchange Online. 
  • Have the ability to remotely wipe email from a device.
  • Have the ability to enforce mobile device configuration settings, such as PIN requirements, PIN lengths, etc.
Second with E1, you also get Office 365 MDM.  With this you:
  • Can prevent access to both email and documents based on device enrollment and compliance policies.
  • Protect against root and jail broken devices.
  • Have reporting on devices that do not meet IT policy.
  • Have selective wipe capability that allows you to wipe Office 365 data without impacting personal data.
Behind the scenes, Office 365 MDM leverages Microsoft Intune to help deliver these solutions.

What is Intune?
Microsoft Intune is Microsoft’s cloud mobile and PC management platform.  Sometimes customers will want to add this to help them manage devices and applications beyond what Office 365 natively provides.  With Intune you:
  • Have the ability to manage traditional PCs MACs; not just mobile devices.  Plus you can manage Linux and UNIX servers.
  • Have a full Mobile Device Management (MDM) platform available to you to protect enterprise assets beyond Office 365.
  • Have the ability to create profiles for certificates, VPN, email profiles and Wi-Fi settings.
  • Have the ability to enroll and manage corporate owned devices.
  • Can deploy and protect customer built line of business apps using Mobile Application Management.
  • Can securely protect access to corporate data using Office mobile and custom line of business apps by using Mobile Application Management by restricting such actions as copy, cut, paste, save as to only applications managed by Intune.
  • Can enable more secure web browsing.
As you can see, this is a much more comprehensive solution you have access to.

Why do you need both? 
All depends on your approach.  Microsoft Office 365 has the ability to integrate with many third-party MDM providers.  Customers do have the power of choice.  Intune does provide unique capabilities for Mobile Application Management (MAM) to protect data on mobile devices without compromising the end user experience.  However, the big value sell of Intune is the expanded set of solution to manage PCs and MACs.

What are these new plans?
Intune is bundled into EMS.  EMS used to stand for Microsoft Enterprise Mobility Suite.  Now, EMS stands for Enterprise Mobility + Security.

Plus, the new EMS Suite has taken very similar plan structures as Office 365.  For instance:
  • EMS E3 includes Azure AD Premium P1, Intune, Azure Information Protection Premium P1 (Azure Rights Management (RMS)), and Advanced Threat Analytics
  • EMS E5 includes Azure AD Premium P2, Azure Information Protection Premium P2 (Intelligent classification) and Cloud App Security.
As you can see Intune, lands in the EMS E3 bundle or you can purchase it a-la-carte.  See references below.

References

Exchange ActiveSync - https://technet.microsoft.com/en-us/library/aa998357(v=exchg.150).aspx
Overview of Mobile Device Management (MDM) for Office 365 - https://support.office.com/en-us/article/Overview-of-Mobile-Device-Management-MDM-for-Office-365-faa7d8e5-645d-4d59-839c-c8d4c1869e4a
Controlling Access to Office 365 and Protecting Content on Devices - https://www.microsoft.com/en-us/download/details.aspx?id=53317
Capabilities of built-in Mobile Device Management for Office 365 - https://support.office.com/en-us/article/Capabilities-of-built-in-Mobile-Device-Management-for-Office-365-a1da44e5-7475-4992-be91-9ccec25905b0
Choose between MDM for Office 365 and Microsoft Intune - https://support.office.com/en-us/article/Choose-between-MDM-for-Office-365-and-Microsoft-Intune-c93d9ab9-efb2-4349-9b93-30c30562ee22
Create and deploy device security policies - https://support.office.com/en-us/article/Create-and-deploy-device-security-policies-d310f556-8bfb-497b-9bd7-fe3c36ea2fd6
Enroll your mobile device in Office 365 - https://support.office.com/en-us/article/Enroll-your-mobile-device-in-Office-365-c8ac722d-dcaf-4135-8345-3e6327f5d3c5
Introducing Enterprise Mobility + Security - https://blogs.technet.microsoft.com/enterprisemobility/2016/07/07/introducing-enterprise-mobility-security/

Sunday, August 21, 2016

Azure Information Protection with Office 365

Introduction
If you are a reader of my blog, you know for the past few years I have been very focused on discussing Office 365 services.  I recently decided to some catching-up on EMS and how it relates to Office 365.  Well as it turns out there have been several recent changes.  One thing that caught my attention very quickly was Azure Information Protection.  In this blog I will explore this solution.

I will say I am super excited to see the vision of this feature given I work with customers who have the most complex security and information protection policies out there.

Note that Azure Information Protection services is currently in Public Preview.

What is the new Azure Information Protection solution?A major challenge that organizations face is protection of their data.  Data loss prevention is constantly on customers’ minds.

With Azure Information Protection we can protect data at the lowest common denominator.  Instead of solely relying on the data storage systems to classify and protect data, we now protect the data directly at the source as email and documents move from place-to-place.

With Azure Information Protection:

  • Classify, label and protect data at the time of creation or modification.
  • Persistent protection travels with the data with rights management.
  • Provide users simple intuitive controls help users make the right decisions and stay productive.
  • Enable safe sharing of data both internally and externally.
  • Ability to create organizational enforceable policies to protect data.
  • Visibility and control over the shared data.
  • Deployment and management flexibility through the cloud.

What is the difference between Azure Information Protection and Azure RMS?
Simply put, Azure Rights Management Services (RMS) got a bunch of new features added to it.  Azure Information Protection building upon RMS with several new capabilities that have been introduced as part of the Secure Islands acquisition.

The new capability that should catch your attention is the intelligent classification and labeling solution that has been integrated with Azure RMS.  This is super exciting capability.

With the new labeling capability in Azure Information Protection services, you have the ability to be able to create enforceable policy to classify and protect your more important critical data.  You have the ability to create labels (classifications) like Personal, Public, Internal, Confidential, Secret, etc.  Then you have the ability to create policies define how data should be tagged with these classifications.  Once data is classified, that data can visual indicators applied to it, RMS protection policies pro-actively applied to the data, and DLP rules (like Exchange transport rules) can watch for this data and take action.

Additionally, there are new reports available to you that allow you to see how the most critical data in your organization is being accessed and managed.  This provides an audit trail for your most critical data.

How can an organization use Azure Information Protection?
Let’s look at Azure Information Protection a little closer.

When a user is in Office, they will see a new ribbon item (Protect) along with new labeling mechanism in the ribbon.  Users have the ability to tag any document or email on the spot.


Administrators have the ability to create the labels that customers see.

Within each label you can:

  • Associate RMS policies you want to apply (if any) to a specific label.  For instance, if you have a Confidential or Secret label, you may want to associate that label to an RMS policy.
  • Create visual markings that would be applied to the email or document once the label is applied.  For instance, add headers, footers, watermarks, etc.
  • Define conditions that could automatically label email and documents.  For instance, if you see data patterns within the content, a label can be auto applied.
There are numerous ways these labels can actually be applied.
  • Automatic – Labels can be applied by IT based on information it can see in the documents and emails.  This means as the user is creating the content, the label can be applied for them. 
  • User Drive – Users have the ability to choose to apply sensitive labels to email or file as they work on it.
  • Recommendation – Instead of automatically applied the label, you can make recommendations to the user on how classify/label.
  • Reclassification – Depending on your policy, you can allow users the ability to re-classify email and documents.  You can even require them to enter a justification which will be logged.
I see endless opportunity for organizations to use Azure Information Protection services to protect their data.  For instance:
  • An organization could create a policy that all documents are automatically classified as Internal.  The Internal does not have to have a RMS policies associated to it, but doing this will set a baseline that all content in the organization has been tagged.
  • As data needs to be become public, the data can be re-classified (labeled) as public by the end user.
  • For documents as classified as Secret or Confidential, an RMS policy could automatically be applied.
  • Re-classification can be allowed without justification for Internal and Public, but for any re-classifications of Secret or Confidential a justification must be provided.
  • I really think there are endless opportunities here with Azure Information Protection services.
How does this relate to Office 365?
As part of the Preview, Azure Information Protection services can be integrated with Office 365 ProPlus.  This means files that you author in Word, Excel, PowerPoint, etc. as well as emails in Outlook will have this user experience.  This will expand with time.

I thought Office 365 already had DLP, where does this play in?
Yes, Office 365 already has DLP capabilities within Exchange Online, SharePoint Online and OneDrive for Business.  Azure Information Protection services provides another layer of protection to data protection along with labeling solution.

For instance, SharePoint Online DLP will identify sensitive documents that were put in a location that has too broad access.  That file can be locked down and then remediated with SharePoint Online DLP by the user or an administrator.  However, what if the end user made a mistake (or worse was malicious) and then tried to send a file tagged as secret outside of the organization?  Azure Information Protection could protect that data tagged as Secret based on your policies.  For instance, you can automatically apply an RMS policy to Secret data and not allow users to re-classify that data.  There are several other mitigations you can take such as watch for documents tagged as secret being emailed externally.

From what I have observed, a challenge customers have had with RMS is educating users on how they should use it.  With Azure Information Protection services classification and labeling solution, the decision has just been super simple for end users.  End users do not need to know complex RMS policies and rule sets; all they need to know are organization contextual tags and the RMS policy is applied for them.

How is Azure Information Protection related to the EMS Suite?
There are two plans, there is Azure Information Protection Plan 1 and Plan 2. 

Plan 1 provides the encryption for files and cloud based file tracking.  From a legacy perspective, this is what you know of as Azure RMS as part of the EMS suite.

Plan 2 adds the new intelligent classification and labeling policies.

There are as well EMS Suites (E3 and E5).  Azure Information Protection Plan 2 is part of the EMS Suite 5.

If you are an Office 365 E3 suite customer, you already get access to Azure RMS service.  However, having Office 365 E3 does not give you access to all the EMS E3 or E5 capabilities.  So to get access to Azure Information Protection Plan 2, to get this new classification and labeling solution, you will need acquire some additional EMS plans.

References
Announcing Azure Information Protection - https://blogs.technet.microsoft.com/enterprisemobility/2016/06/22/announcing-azure-information-protection/
Azure Information Protection Public Review Announcement- https://blogs.technet.microsoft.com/enterprisemobility/2016/07/12/azure-information-protection-public-preview-available-now/
Introducing Enterprise Mobility + Security - https://blogs.technet.microsoft.com/enterprisemobility/2016/07/07/introducing-enterprise-mobility-security/
Acquisition of Secure Islands - http://blogs.microsoft.com/blog/2015/11/09/microsoft-to-acquire-secure-islands-a-leader-in-data-protection-technology
Azure Information Protection product page - https://www.microsoft.com/en-us/cloud-platform/azure-information-protection
What is Azure Information Protection (good video) - https://docs.microsoft.com/en-us/rights-management/information-protection/what-is-information-protection 
Azure Information Protection FAQs - https://docs.microsoft.com/en-us/rights-management/information-protection/faq
Azure Information Protection Quick Start for Preview - https://docs.microsoft.com/en-us/rights-management/information-protection/infoprotect-quick-start-tutorial

Saturday, August 20, 2016

Office 365 Secure Score and Information Security Planning

Introduction
Office 365 customers are provided a highly security solution for business productivity.  Microsoft ensures that the Office 365 service is secure and demonstrates this commitment through many of the third-party accreditations it receives.  Yet that is only half the battle as the customer who manage the Office 365 tenant shares in that security responsibility.  There are a tremendous amount security features and capabilities that are available to Office 365 customers that require configuration and management.  Customers frequently miss they too have a security responsibility to manage and continuously monitor their tenant.  In this blog I will discuss:
  1. The new Office 365 Secure Score analytics tool.
  2. Office 365 Information Security Planning.
Microsoft is invested in providing a safe and secure productivity cloud solution for your end users.  A clear differentiator for Microsoft is that they provide you plans, frameworks and tools that help you plan and continually monitor your security risk with Office 365.

Office 365 Secure Score
Microsoft has released “in preview” a new capability called Office 365 Secure Score.  This is a new analytics tool that can review the configuration of your tenant and make recommendations (based initially on 77 different factors).  Think of it as a “credit score”.  The higher the score, the more controls you have configured into your tenant.  The goal is to create a score that is aligned to your business requirements which do not impact your user experience.

Features of this capability are:
  • There is a summary panel that provides you your score and when you last ran it.
  • There is a modeling tool that allows you to do analysis to determine if you introduce more controls how those new controls will impact your score.
  • There is detailed information about each control it evaluates and the risk that it mitigates.
  • There are remediation instructions for each control that you introduce and how it would impact your end users.
  • There is a score analyzer that allows you to measure your performance over time.  You can download the scores from the reports and make them part of continuous monitoring program.
  • New controls will be introduced into the tool as new features are added to the service.
Plan for Office 365 Information Security
Since I have discussed this new Office 365 Secure Score tool that helps you continuously evaluate your security position, it is also worth mentioning there are several new Office 365 Information Planning worksheets you should review (see references below).
What these references will do is provide you direction on how you can utilize and configure all of the Office 365 security features (several new ones). 

Here are features I talk about a lot:
  • Federated Authentication (ADFS) and ADFS Client Access Policies.
  • Two-factor Authentication with Office 365 MFA and integration with third-party 2FA (smart cards, PIV, CaC).
  • Data Loss Prevention for Exchange Online, SharePoint Online, OneDrive for Business and Skype for Business Online.
  • Rights Management Service (RMS) Exchange Online, SharePoint Online, OneDrive for Business and Office 365 ProPlus.
  • Office 365 Message Encryption (OME) and S/MIME support.
  • eDiscovery, Legal Hold and Retention policies for Exchange Online, SharePoint Online, OneDrive for Business and Skype for Business Online.
  • Advanced eDiscovery with text analytics, machine learning and predictive coding.
  • Exchange Online Inactive Mailboxes.
  • Data spillage and deletion methods.
  • Permissions management.
  • Service usage reports.
  • Customer Lockbox
  • Office 365 MDM and Exchange ActiveSync policies.
  • Intune MDM advanced features for Exchange Online, SharePoint Online, OneDrive for Business and Skype for Business Online.
  • Office on the Web (OWA) client policies for data sync and attachment downloads.
  • Exchange Online Protection.
  • Advanced Threat Protection for Exchange Online.
  • Office 365 Advanced Security Management.
  • Azure AD usage and audit reports.
  • Exchange Online mailbox auditing and administrator auditing reports.
  • SharePoint Online usage audit reports.
  • Rights Management Service (RMS) audit reports.
  • External sharing policies for SharePoint Online, OneDrive for Business and Skype for Business Online.
There are a lot of features available to customers and planning is required.


In Closing
It can be daunting to see the amount of information security features that a customer has available to them in Office 365.  Customers need to plan and develop continuous monitoring plans to evaluate their risk in the Office 365.  Microsoft, unlike many of the cloud vendors out there, provide comprehensive solutions to help you plan and measure your risk.


Monday, August 1, 2016

New Office 365 Exchange and SharePoint User Experiences Coming

New User Experiences
There are some important new user experiences that are being released for Office 365 that you should be aware of:
  1. SharePoint Online Modern Lists
  2. Outlook Focused Inbox
  3. Outlook Mentions
Modern SharePoint Lists are coming
A new user experience is coming to SharePoint Lists.  It will be referred to as Modern SharePoint lists and many of the changes are consistent with the user experience changes you have been seeing with SharePoint modern document libraries.  You will many new features such as:
  • Simplified user experience to add columns to lists.
  • Ability to elevate (pin) list data for viewing.
  • Ability to edit data in an information panel without having to leave the list view.
  • Improved bulk editing.
  • Simplified automation with versions, approvals and alerts.
  • New user experience for view and edit lists in mobile browsers and SharePoint mobile app.
  • Integration with PowerApps and Microsoft Flow.  This will allow you to build new workflow applications connected to cloud data and then expose these workflows via PowerApps.


Transition over this user experience can be managed as well so that end users are no disrupted:
  • By default, classic list will automatically inherit the new modern list experience.
  • If there is a compatibility blocker to move to the modern list experience, the classic list experience will stay as is.
  • Users will have the ability to revert to the classic experience at any time.
  • Administrators will have the ability to configure classic list experience as the default at the list, site, site collection or tenant level.  This allows for lots of flexibility for user transition.

Outlook Focused InboxThis is a new experience that is called Focused Inbox that is being released for Outlook.  It was initially release on Outlook for iOS but will be release to all versions of Outlook.

The Focused Inbox will prioritize email that is important to you based on such things as who you interact with the most often, while other email (newsletters, DLs, generated emails, etc.) will land in the Other Inbox.  All the data is staying in your primary mailbox, just the email that most important to you is being prioritized.

Focused Inbox will be replacing the Clutter feature that was introduced awhile back.  Clutter was different in that it actually moved email data to a different email folder.  With Focused and Other Inbox, these are just views into the primary Inbox folder.  Clutter will stop moving mail as the Focused Inbox feature is rolled out.

From a transition perspective, again you have control.  Admins will have mailbox and tenant level control of this feature to do a staged rollout to your end users.

Outlook Mentions

This is a really neat feature that I find super exciting.  This features will help you write emails so much quicker.

As you type an email, you can simple type the @ symbol anywhere in the body of a message.  Once you do that, a people picker will appear, which you can select a person’s name.  Once you pick the person, their name will he highlighted in the message calling out action to them.  Additionally, if the person’s name is not yet on the TO line, their name will be automatically added to the TO line for you.  This is very much like a user experience you have in Facebook when writing a message.

Saturday, July 23, 2016

Certificate Based Authentication for Exchange Online

Exchange Online now has Certificate Based Authentication (CBA) in Preview.  I have been waiting for this for a while.  CBA will be supported with Microsoft mobile Outlook apps and it will be supported with Exchange ActiveSync (EAS).  This is a really important release for organizations who more complex security and authentication requirements when accessing Exchange Online data.  Typically organizations that use Smart Cards for all their log-in and access applications have required CBA.

For more information, review this - https://blogs.technet.microsoft.com/exchange/2016/07/19/preview-of-certificate-based-authentication-cba-for-exchange-online/  

Sunday, February 21, 2016

Office 365 Unified Audit Logging with SharePoint Online and OneDrive for Business

Introduction
SharePoint Online and OneDrive for Business audit logging as received an overhaul.  For the longest time, there were the following challenges:
  • View/down log events were not possible in SharePoint Online.
  • To turn on user event logs, you had to go to each site collection and turn it on.
  • Getting user event logs out of SharePoint Online was not easy, especially if you wanted to do it in an automate fashion.
These issues were a problem over and over again for enterprise customers who needed access to these logs for compliance scenarios.
 
I am happy to say, this gap is now gone.  This has been on the public roadmap for some time and it is now rolling out.  I am really impressed with the solution that been put in place.
 
Unified Audit Logging
We not have a Unified Audit Logging solution across Office 365.  SharePoint Online and OneDrive for Business provide a rich logging experience and is no longer second class to something like Exchange Online (which always had mailbox audit logging and Exchange admin logs).  With the new Unified Audit Logging solution in Office 365, you have both a user interface and APIs to go obtain user event logs from:
  • Exchange Online
  • SharePoint Online
  • OneDrive for Business
  • Azure AD
For SharePoint Online and OneDrive for Business logs, you now have access to event logs on view, create, edit, upload, download and delete; sharing actions like invitation and access requests; and synchronization activity.  You now can see who has accessed or had had potential access to data which has been a big deal for enterprise organizations when they are performing compliance investigations.  Cannot underscore how big of a deal this is.  See reference below to a detailed listing of the events captured Unified Audit Logging.
 
Search Audit Log User Experience
Gaining access to these logs is super simple.  You do not have to be a super technical person to gain access to these logs and you do not have to go to multiple places.  All you need to do is go the Office 365 Compliance Center, and go to the audit log site.
 
 
From there all you need to do is identify the types of logs you are looking for, in what day range, for what users and where in Office 365.  It could not be any simpler than that.


Once you have the search results, you can filter them down to specific log events that you are looking for.  You have an export button right there to dump out that set of logs.  Having that easy to use export button makes life so easy if you have been asked to turn over user logs.

And remember this is Unified Audit Logs.  This means you are getting user event logs across Exchange Online, SharePoint Online, OneDrive for Business and Azure AD all at one time.  I am just happy to see this feature.

Other Things You Should Know
Here are some important facts that you should know:
  • Exchange Online, SharePoint Online and OneDrive for Business audit logs are retained for 90 days.  Azure AD audit logs are retained for 180 days.
  • SharePoint Online / OneDrive for Business corresponding logs start to appear in 15 minutes after the event.  Exchange Online and Azure AD logs appear after 12 hours.
  • If you require longer term retention for audit logs, that are APIs and Web Services available (references below) which can be used to export that data and then retain that data for a longer period of time.  Microsoft ISV partners are building rich solutions around these APIs.
  • You have the ability to create your own more complex reporting and analysis solutions using these APIs as well.

Detailed listing of all the available log events across Exchange Online, SharePoint Online, OneDrive for Business, and Azure AD - https://support.office.com/en-US/article/Search-the-audit-log-in-the-Office-365-Protection-Center-0d4d0f35-390b-4518-800e-0c7ec95e946c#auditlogevents

Monday, February 15, 2016

Office 365 Groups is Expanding

Introduction
Office 365 Groups was a feature released some time ago.  Initially I had not played around with it too much because at the time as there were two things lacking:
  1. It was not integrated into my rich Outlook experience which is where I do all my group messaging and group calendars.
  2. It was lacking several of the enterprise capabilities I wanted to see.
These two issues have now been addressed and I see immense possibilities for Office 365 Groups for enterprise business. 

The game has changed and organizations should be taking a long, hard look at Office 365 Groups to change the way their users collaborate with each other.
What are Office 365 Groups?
In my personal opinion, Office 365 Groups is the replacement for distribution groups / lists with enhanced capabilities.  It brings together best of breed user experiences with email, calendar, OneDrive, and OneNote into a single unified user experience.  In the past:
  • If you wanted to share files with a group of people, you could create a SharePoint site but there was not true integrated email capability.  SharePoint had alerts and discussion boards yet the messaging experience was not integrated.
  • If you wanted a shared calendar SharePoint Online had one and its integration with the user’s Outlook calendar experience was ok, however the Outlook calendar capabilities were not available in SharePoint.  On the other side of the coin, you could create a shared group with an Outlook calendar yet all you had was a great calendar capability that was not integrated with messages and files.
  • Distribution groups were not effective way for collaborating on files as you could email attachments to a group of people, however if you were trying to create a work product together there was no place to manage the files.
  • Sharing thoughts and ideas with a group was limited to just what you could capture in an email message, or attach to a message.
  • Even if you cobbled together a solution, access rights management always became a challenge across all the feature solutions.  You need to make sure the distribution group, shared calendar and SharePoint site were all using the same permissions.
  • Etc.
This all changes with Office 365 Groups.  When you create a group you get unified experience across Exchange, SharePoint, OneDrive, Office, Office Online, OneNote, etc. built specifically to cater to the needs for productivity collaboration.

In Office 365, the Office 365 Groups feature is considered to be a suite feature.  It is only available if you purchase a suite because all of Office 365 is used to deliver this experience.

I see this as a true trend for Microsoft and Office 365.  We are going to continue to see best of bread features brought together to deliver “solutions” versus just stand alone applications.

I highly recommend you review some of the links below and some of the videos to learn more about Office 365 Groups.
What has changed?

So what changed that got me completely hooked on Office 365 Groups?  1) integration with Outlook 2016, 2) Enterprise compliance feature integration and 3) the list of features coming down stream.  Let’s look at each one.

Outlook 2016 Integration with Office 365 Groups
What I was waiting for was deep integration with Outlook rich client.  Outlook on the Web (OWA) had deep Office 365 Groups integration, however I prefer to work in Outlook rich client.  When the integration was announced publically I was ecstatic to talk about it.

Creating an Office 365 Group is super simple.  I just create a new Office 365 Group right there inside of Outlook 2016.  I do not need to navigate away to a browser to create a group.


When I am in an Office 365 Group, I have the ability to:
  • Create new conversations or interact with existing ones.  Underneath the hood a mailbox was created for all users to access.
  • Click over to the shared calendar.  Underneath the hood a shared calendar was dynamically created.
  • Collaborate on files by clicking the Files button.  Underneath the hood a OneDrive for Business site was created and associated to the group.
  • A OneNote book was created for everyone to collaborate thoughts and information through.  Underneath the hood, a OneNote book was created in the OneDrive for Business site.
  • I have the ability to manage membership of the group right in Outlook and I have the ability to edit information about the group too.
The usage of this is endless.  You have the ability to quickly bring together groups of people to collaborate.  An experience SharePoint person may counteract by saying why not use a SharePoint Team Site?  My response would be SharePoint Team sites are great and still needed.  I would say if you know the level of communication and collaboration is more than file sharing, but needs to bring together email and calendar Office 365 Groups is the right feature.  Office 365 Groups are not a type of site that should I would use to bring in hundreds of users to access files and web content; in that case I would use a SharePoint Site.

What I find truly exciting about Office 365 Groups is that aligns to how I need to work in enterprise.  I am constantly working with tactical teams of people.  Everyone has specialties and we cross matrix with each other to complete critical timely tasks.  Office 365 Groups is a wonderful solution.  I can quickly create an Office 365 Group with a broad range of co-workers and we have an area where we can effectively work with each other.  I no longer have dig through email for that one-off conversation or file as I can quickly find it in the Office 365 Group.

Enterprise Compliance Integration with Office 365 Groups
Office 365 Groups when first released focused purely on the features and capabilities.  It was a rich solution but not all of the enterprise compliance features were available.  Now they are.  For instance:
  • eDiscovery and litigation hold is now available on Office 365 Group mailbox and calendar stored in Exchange Online.
  • eDiscovery and litigation hold is also now available on the Office 365 Group files that are stored in OneDrive for Business.
  • IRM messages and files is not integrated into Office 365 Groups.
  • Auditing events to group management events such as creation, updates, membership changes, etc. are available to see changes to the Office 365 Group over time.
Other Features Recently Added or being added soon
There are other recent features added to Office 365 Groups such as:
  • Dynamic Group Membership was added such that rule-based membership can be used to manage access to an Office 365 Group.  For instance, maybe there are directory based attributes that dictated whether a user can have access.
  • File quota management is now available.  Office 365 Groups utilize the shared storage of SharePoint Online and you have the ability monitor and control the size of Office 365 Group content.
  • Multi-domain support is being added.  This is needed when organizations have multiple email domains associated to a single tenant.  With this new feature, you have the ability to control what domain the Office 365 Group is associated to.
  • Office 365 Groups will comply with naming policies for emails alias set by the tenant administrators.
  • There is now PowerShell available to manage Office 365 Groups (see link below).
  • The ability to browse and join Office 365 Groups from Outlook 2016.
  • Yammer integration with Office 365 Groups.
  • Office 365 Admin app that will assist with central administration of Office 365 Groups.
  • Ability to limit the creation of Office 365 Groups to a specific group of people.  This will be controlled through policy by the tenant administrators.
  • Data Classification and customizable classification will be available for Office 365 Groups in the future.  This will allow you to create policy for groups that may be internal, unclassified, classified, corporate confidential, etc. and then allow you to manage policy to that content as appropriate.
  • Office 365 Groups will soon have a deletion recovery feature which will allow end users and administrators to undelete an Office 365 Group in a single action.
  • There will be a future feature to allow inactive Office 365 groups to be expired based on a configurable inactivity period.  This will be good for getting rid of stale groups no longer utilized.
  • General Office 365 Groups admin reporting will be expanded to allow for analysis to determine how they are being utilized.
  • Guest support will be added soon to Office 365 Groups to allow external users and team members to collaborate.
  • Hidden membership is being added to soon to Office 365 Groups as sometimes it is not appropriate to share the members of group to end users who do not have access to the Office 365 Group.
  • New Intune feature are being created to help with management of Office 365 Groups.
  • Office Delve will soon be integrated with Office 365 Groups so you can see activity occurring within groups you are associated to.
  • A new Office 365 Groups mobile app is being created to allow for rich mobile experiences.
  • Usage guidelines will be added soon to Office 365 groups.  This will allow administrators to educate end users on how they should be used in the organization.
  • There is a new project called Hummingbird which will help organizations migrate all of their distribution lists over to Office 365 Groups (see link below).
  • Integration with Office 365 Planner is now available so you can do project management with Office 365 groups (see link below).
To read more about these features coming out, just go to the Office 365 public roadmap (http://fasttrack.office.com/roadmap) and search on the word “Groups”. 
The future is bright for Office 365 Groups.  I recommend that if you are not using them
Resources
Office 365 Roadmap - http://fasttrack.office.com/roadmap
Announcement – Outlook 2016 now has Office 365 Groups Integration - https://blogs.office.com/2015/09/22/introducing-availability-of-office-365-groups-in-outlook-2016/
TechNet – Outlook 2016 Integration with Office 365 Groups - https://support.office.com/en-us/article/What-s-new-in-Outlook-2016-for-Windows-51c81e7a-de25-4a34-a7fe-bd79f8e48647?ui=en-US&rs=en-US&ad=US
Announcement - Office 365 Compliance features being added to Office 365 Groups - https://blogs.office.com/2015/12/09/office-365-groups-now-supports-ediscovery-litigation-hold-dynamic-membership-and-more/
Office 365 Service Description for Office 365 Groups - https://technet.microsoft.com/EN-US/library/office-365-suite-features.aspx
Office 365 Groups Introduction - https://support.office.com/en-us/article/Learn-about-Office-365-groups-b565caa1-5c40-40ef-9915-60fdb2d97fa2
PowerShell to Manage Office 365 Groups - https://support.office.com/en-US/article/Use-PowerShell-to-manage-Office-365-Groups-aeb669aa-1770-4537-9de2-a82ac11b0540
Hummingbird Project - https://github.com/Microsoft/hummingbird
Office 365 Planner - http://www.astaticstate.com/2015/12/new-office-365-planner.html

Saturday, January 2, 2016

Exchange Online Protection Advanced Threat Protection

Introduction

Exchange Online Protection (EOP) Advanced Threat Protection (ATP) has been available for the past few months.  ATP is a new high-end security feature that is part of the new E5 suite for Office 365.
Exchange Online Protection Advanced Threat Protection has three core capabilities.  They are:

  • Safe Attachments
  • Safe Links
  • URL Tracking/Reporting capabilities.
ATP was added as an option to the EOP service given the evolving sophisticated attacks that are occurring today in email.  Phishing, spear phishing and zero day threats are a real threat for enterprise customers and many organizations will seriously consider adding ATP to their Office 365 tenant.  ATP will provide organizations insight into users who are being targeted, attacked and compromised.

The new ATP capability is part of EOP service.  Email messages will continue to go through EOP and still go through malware and virus protection checks.  Once the message goes through the standard EOP protections, if an ATP policy applies to the email message it will go through the additional Safe Attachment and Safe Links checks.  ATP policies can be configured through the Exchange Admin Console (EAC) or through PowerShell.
It is worth noting that ATP can be used with Exchange Online, Exchange on-premises and in Exchange Hybrid scenarios.




Safe Attachments

Safe Attachments will help organizations protect against zero day exploits in email attachments by blocking messages.  Common unsafe attachments such as Office files, PDFs, executable file types, Flash files, etc. would be inspected.
Safe Attachments leverage sandboxing technology.  All attachments that do not have a known virus/malware signatures are routed to this special hypervisor environment where behavior analysis is performed using a variety of machine learning and analysis techniques to find malicious intent.  If a message’s attachment(s) is deemed unsafe, the email is blocked until the attachments have been detonated in the hypervisor.  Each attachment will be opened in a unique hypervisor which can result in an email delivery delay of 5 to 30 minutes while the attachment is being evaluated.

Here is the configure screen in EAC for the Safe Attachment Policy.  Here is where you can configure the behavior when unknown malware is discovered.  For instance, you can monitor message by allowing it to still go through and just get reporting.  You can completely block the message all together or allow the email to go through without the attachments.



Below is an example email that would be sent to an administrator based on the policy configuration you make.


Safe Links

Safe Links will help protect against malicious sites and content in phishing attacks.  A common threat is to try to hide malicious URLs in an email that seem to be safe but redirect users to unsafe sites. 
When Safe Links policy is configured, every time a user clicks a URL from an email message that click is inspected.  Specifically, URLs in the email are rewritten to proxy them through another server managed in ATP service.  If the URL is pointing to a good site, there is almost no latency in the click and the user go to the site.  If the URL points to a malicious site, a landing page will be presented to the user warning them are about to go to an unsafe site.

Here is the configuration screen for this policy in the EAC.  There is an option to track user clicks on malicious URLs.  You do have the option to not allow the user to click through to a known malicious URL.  You also have the ability to add your own custom list of blocked URLs.


The following is an example of what a user would see if they click a malicious URL in an email.  Depending on how you configured the policy, the malicious URL will not be presented to the end user so that they cannot click-through.



URL Tracking

Safe Attachments and Safe Links will provide organizations visibility to people who may be compromised.  With this reporting you can see how your organization is being targeted and whether you do need introduce new policies, more user training, etc. 
For Safe Attachments, you can see reporting of the unsafe attachments that were blocked. 

As part of Safe Links, you can also see who has been receiving malicious URLs and who has been clicking through to malicious URLs (if you allow it).


Resources
Advanced Threat Protection Service Description - https://technet.microsoft.com/en-us/library/exchange-online-advanced-threat-protection-service-description.aspx

ATP Overview - https://products.office.com/en-us/exchange/online-email-threat-protection

Announcement of ATP - https://blogs.office.com/2015/04/08/introducing-exchange-online-advanced-threat-protection/