Monday, February 5, 2018

Office 365 Security and Compliance



This blog is going to cover the basics of Office 365 security and governance and I will follow up with more blog with every feature. Feel free to stop by the Microsoft security & compliance online resource but you will see very soon realize that it is just overwhelming, since there is so much to it. The below options will help you secure your office 365 platform and give you a quick score on your security. Below is a screenshot of a widget which is available in the SCC (security & compliance center)


Moving to a cloud shouldn’t mean losing access to knowing what’s going on. With Office 365, it doesn’t. Microsoft aims to be transparent in operations so you can monitor the state of your service, track issues, and have a historical view of availability.

If you are responsible for the security of your office 365 services & data you will across SCC, this area is mostly for Office 365 admins to security the Office 365 data & services to meet organizational compliance requirements.




1.     Following are the categories to secure your office 365 services & data:
§  Alerts
§  Permissions
§  Classifications
§  Data Loss Prevention
§  Data Governance
§  threat Management
§  Search & Investigation
§  Reports

§  Service Assurance

Security & Compliance Center availability for different Office 365 plans

Security & Compliance Center availability for Business and Enterprise plans

Feature
Office 365 Business Essentials 
Office 365 Business 
Office 365 Business Premium 
Office 365 Enterprise E1
Office 365 US Government G1
Office 365 Enterprise E3
Office 365 US Government G3
Office 365 Enterprise E5
Office 365 Enterprise F1
Office 365 US Government F1
Yes
Yes
Yes
Yes
Yes
Yes
Yes
No
No
No
No
No
Yes
No
Threat management such as mail filtering and anti-malware
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Advanced threat management such as customer lockbox and threat explorer for phishing campaigns6
No
No
No
No
No
Yes
No
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Data loss prevention
No
No
No
No
Yes
Yes
No
Yes
Yes
Yes
Yes
Yes
Yes
Yes
No
No
No
No
No
Yes
No
Search and investigation
Yes
No
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Yes
No
No
No
No
Yes
Yes
No
No
No
No
No
No
Yes
No
Litigation Holds (including query-based Litigation Holds)
No
No
No
No
Yes
Yes
No
No
No
No
Yes3
Yes4
Yes4
No
Manual retention/deletion policies
No
No
No
No
Yes
Yes
No

Security & Compliance Center availability for Standalone plans

Feature
Exchange Online Plan 1
Exchange Online Plan 2
Exchange Online Kiosk
SharePoint Online Plan 1
SharePoint Online Plan 2
Skype for Business Online Plan 1
Skype for Business Online Plan 2
Yes
Yes
Yes
Yes
Yes
Yes
Yes
No
Yes
No
No
Yes
No
Yes
Threat management such as mail filtering and anti-malware
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Advanced threat management such as customer lockbox and threat explorer for phishing campaigns
No
No
No
No
No
No
No
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Data loss prevention
No
Yes
No
No
Yes
No
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Yes
No
No
No
No
No
No
No
Search and investigation
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Yes
No
No
No
Yes
No
No
Yes
No
No
No
No
No
No
No
No
No
Litigation Holds (including query-based Litigation Holds)
No
Yes
No
No
Yes
No
No
Yes
Yes
No
Yes
Yes
No
No
Manual retention/deletion policies
No
Yes
No
No
Yes
No
Yes

1.1 Alerts


Alerts is where an organization can configure and manage security alerts.
This is where a security admin can configure & manage alert policies, It has the following options:
§  Manage Alerts
§  View Security Alerts
§  Manage Advanced Alerts

Security Alerts can also be configured to be sent out an email notification.  
Alerting with Advanced Security Management also needs to be switched on
Advanced Security Management includes:
§  Threat detection—Helps you identify high-risk and abnormal usage, and security incidents.
§  Enhanced control—Shapes your Office 365 environment leveraging granular controls and security policies.
§  Discovery and insights—Get enhanced visibility into your Office 365 usage and shadow IT without installing an endpoint agent.

1. 2 Permissions 




Assign permissions to people in your organization so they can perform tasks in the Security & Compliance Center. Although you can use this page to assign permissions for most features in here, you'll need to use the Exchange admin center and SharePoint to set permissions for others.

Permissions in the Security & Compliance Center are based on the same Role Based Access Control (RBAC) permissions model that is used in Exchange Online. To access the Security & Compliance Center, users need to be a member of one or more Compliance Center role groups that are listed on the Permissions page.




Below is a list of Security & Compliance Center role groups:




1.3 Classification


This is where data can be classified using with labels, you can classify data across your organization for governance, and enforce retention rules based on that classification.
For example, you might have:
§  Tax forms that need to be retained for a minimum period.
§  Press materials that need to be permanently deleted when they reach a certain age.
§  Competitive research that needs to be both retained and then permanently deleted.
§  Work visas that must be marked as a record so that they can’t be edited or deleted.

With labels, you can:
§  Enable people in your organization to apply a label manually to content in Outlook on the web, Outlook 2010 and later, OneDrive, SharePoint, and Office 365 groups. Users often know best what type of content they’re working with, so they can classify it and have the appropriate policy applied.
§  Apply labels to content automatically if it matches specific conditions, such as when the content contains:
o   Specific types of sensitive information. This is available for content in SharePoint and OneDrive.
o   Specific keywords that match a query you create. This is available for content in Exchange, SharePoint, OneDrive, and Office 365 groups.

The ability to apply labels to content automatically is important because:
§  You don’t need to train your users on all your classifications.
§  You don’t need to rely on users to classify all content correctly.
§  Users no longer need to know about data governance policies – they can instead focus on their work.
§  Note that auto-apply labels require an Office 365 Enterprise E5 subscription.
§  Apply a default label to a document library in SharePoint and Office 365 group sites, so that all documents in that library get the default label.
§  Implement records management across Office 365, including both email and documents. You can use a label to classify content as a record. When this happens, the label can’t be changed or removed, and the content can’t be edited or deleted.
§  You create and manage labels on the Labels page in the Office 365 Security & Compliance Center.

1.4 Data Loss Prevention

for Organizations to protect sensitive information, prevent its disclosure organization need to comply with several standards and industry regulations.

Examples of sensitive information might be personally identifiable information (PII) like a medical record, social security information etc. DLP (data loss prevention) can be used to identify, monitor and protect sensitive information across office 365 platform.

Below is a list of things that DLP can do as per Microsoft Article:

§  Identify sensitive information across many locations, such as Exchange Online, SharePoint Online, and OneDrive for Business.
§  Prevent the accidental sharing of sensitive information
§  Monitor and protect sensitive information in the desktop versions of Excel 2016, PowerPoint 2016, and Word 2016.
§  Help users learn how to stay compliant without interrupting their workflow.
§  View DLP reports showing content that matches your organization’s DLP policies.



1.5 Data Governance 


Data governance is all about keeping your data around when you need it and getting rid of it when you don't. With data governance in Office 365, you can manage the full content lifecycle, from importing and storing data at the beginning, to create policies that retain and then permanently delete content at the end.

You can import email from other systems, enables archive mailboxes or set policies for
retaining email and other content within your organization
§  Import - Import PST files to Exchange mailboxes then you can use the Intelligent Import feature to filter the items in PST files that get imported to the target mailboxes.
§  Archive - Archive mailboxes to provide additional email storage for the people in your organization. Enable or disable a user's archive mailbox
§  Retention - Create a policy to retain what you want and get rid of what you don't. While your organization may be required to retain content for a period of time because of compliance, legal, or other business requirements, keeping content longer than required might create unnecessary legal risk.
§  Supervision - Supervision lets you define policies that capture email and 3rd-party communications in your organization so they can be examined by internal or external reviewers. Reviewers can then classify these communications, make sure they're compliant with your organization's policies, and escalate questionable material if necessary.  

1.6 Threat Management 


Threat management is used to
§  help control and manage mobile device access to your organization's data
§  help protect your organization from data loss
§  help protect inbound and outbound messages from malicious software and spam
§  to protect your domain's reputation and to determine whether senders are maliciously spoofing accounts from your domain

Options for creating threat management policies:

1.7 Search & Investigation 


This feature can be used to search through ALL the content of your organization. Everybody's email, documents, Skype conversation history, everything really.
few things that can be done here are

§  Content Search:
This is the neatly ordered and automated version of the admin power-trip. You can search through ALL the content of your organization. Everybody's email, documents, Skype conversation history, everything really.

§  Audit Log Search
You can view ALL actions in your Office365 organization. Who accessed what, who shared what, which admin deleted that group? Every action is taken within Office365 with a bunch of predefined result-filters.

§  eDiscovery
eDiscovery is the tool you use when you need to prove something. It does not just do the whole search all the contents!!!', it logs the actual search criteria so an investigator (read: non-it-admin, for instance, someone from the legal department) can not only produce the requested data, but also show how they acquired it. It also lets you delegate the searching for this data to a
specific group of users (so legal can do it themselves without granting them uber-admin rights) AND you can save the query so they can run it whenever they like (so no more 'hey all that boring search-work you did for us last Friday, can you do that again, every Friday for the next 12 months or so?').

·         Productivity app discovery

1.8 Reports

There are whole bunch of reports here that can be used to help you understand how your organization is using Office 365, including reports related to auditing, device management, Supervisory review, and data loss prevention. View user activity reports such as sign-ins for
SharePoint Online, Exchange Online, and Azure Active Directory


1.9 Service Assurance

Service assurance is used to access details of how Microsoft keeps office 365 customer safe and meets industry compliance requirements, some of the documents you can see here are:
§  Microsoft security practices for customer data that is stored in Office 365.
§  Independent third-party audit reports of Office 365.
§  Implementation and testing details for security, privacy, and compliance controls that Office 365 uses to protect your data.

You can also find out how Office 365 can help customers comply with standards, laws, and regulations across industries, such as the:
§  International Organization for Standardization (ISO) 27001 and 27018
§  Health Insurance Portability and Accountability Act of 1996 (HIPAA)
§  Federal Risk and Authorization Management Program (FedRAMP)





Friday, February 2, 2018

Power Apps - Customizing SharePoint List Forms & Implementing Role Based Security

This blog will show the steps for creating a role based SharePoint List form by customizing the form in PowerApps.

Microsoft recently made a General announced in Nov 2017 for using PowerApp to customize SharePoint forms like back in the days using InfoPath forms.

Customizing a SharePoint form to implement role based security involves the following two steps:
  1.                Configuration in Azure
    a.       Register an app with azure
    b.      Generate Keys
    c.       Allocate and Grant required permissions
      2.       Customizations in PowerApps
    a.       Create custom connector with swagger file
    b.      Create power app and utilize the custom connector 

     Step 1 : Configuration in Azure

     Register an app with Azure
·         Login to https://portal.azure.com site and click on Azure Active Directory on the left-hand side menu.


·         Click on App registrations and click on New Application Registration option.


·      Enter the details for Name, Application type, Redirect URI and click on Create button. Redirect URI value should be https://login.windows.net


·         Once the App got created, capture the Application ID and store it locally.


·         Click on settings icon and click on Reply URLs and add https://msmanaged-na.consent.azure-apim.net/redirect and save.


Generate Keys

·         Click on Settings icon, click on Keys.  Add Key Description, Duration and click on Save button. Once you save the key then then Value field will be visible. Copy this value somewhere locally. Once user away from this screen then value will not be visible. 


Allocate and Grant Permissions


·         Click on Settings icon and click on Required Permissions option. Click on Add to add select API as Microsoft Graph API and click on Select.






·         In next screen (Select Permissions), under Delegated permissions check the following items and click on Select button then Done button.
                                                               i.      View User’s basic profile
                                                             ii.      View user’s email address
                                                            iii.      Sign Users In
                                                           iv.      Access Directory As Signed In User
                                                             v.      Read Directory Data
                                                           vi.      Read All Groups
                                                          vii.      Read All User’s Basic Profile
                                                        viii.      Sign in and read User Profile


·         We have defined permissions for the MS Graph API. Now those permissions should be approved by the Administrator, because some of the permissions should be approved by administrator.

·         If you are an administrator then click on Grant Permissions option under Required Permissions.



·         If you are not an administrator then ask your administrator to gran the permissions by login into the azure portal and navigate to below location.
Azure Active Directory à App Registrations à Name of your appàSettingsàRequired Permissions.

Step2  : Customization in Power Apps:


Implementation idea:


From azure AD I am getting all the groups that current user is belongs to. If user is belonging to Test Managers Team, which I have already created as Office 365 group, then we will show the Stock option to edit otherwise it will be read-only. But any user can add stock but only manager will edit the stock value.

Create custom connector

·         Go to https://web.powerapps.com site and login. In the left had side navigation you can find option Custom Connectors. Click on that and click on Create custom connector option in the top right side. Click on Import an Open API file option.



·         I am using swagger file for this demo.
·         Provide custom connector title and upload the swagger file and click on Continue

·         Next screen leave as is and click on Continue
·         In the next screen provide the client id and client secret (Azure app application id and Secret value copied after Key was created) click on continue.


·         Click on Create connector.
·         Once connector created successfully then it will appear as below


·         Click on + symbol to create a new connection.


Create power app with Custom connector



·         Create list in SharePoint site with name Inventory and create below columns

                                                               i.      Stock – Single line of text
                                                             ii.      Category – Single line of text
                                                            iii.      Quantity – Number
·         Go to list settings and click on Form settings. Click on Customize in Powerapps option. This will open power app window to customize.

 ·         Click on SharePointForm1 in the left navigation. 


·         Click on Datasources under view option from ribbon.


·         Click on Add data source and select the newly added custom connector connection. Once we add the data source then it will display like below.


·         I have added some background color, heading and image to give more professional look.


·         Click on FormScreen1 in the left-hand side pane and select the OnVisible property. Apply ClearCollect(MyGroups, Graph.ListUserGroups(User().Email).value) formula to OnVisible property.


·         Above formula will store the retrieved content in MyGroups variable which we called as collection. To see the data which was retrieved by this formula, click on preview or F5 button on keyboard and close the form after form got loaded. Now click on File option then click on collections option.


·         Come back to earlier screen. Click on any field on SharePointForm1 in middle pane and select the required fields. I have selected as below.


·         Select the Stock data card in middle pane and see the properties. Under advanced option click on Unlock to change properties option.


·         Select the Textbox inside Stock field in middle pane and select Display Mode property then apply below formula.
If(IsBlank(Created_DataCard1.Default),Parent.DisplayMode,If("Test Manager Team" in MyGroups.displayName,Parent.DisplayMode,Disabled))


·         Save the form by Ctrl+S and click on Back to SharePoint option in the top left corner.

Friday, October 27, 2017

Office 365 Power Apps for creating a purchasing Mobile App

Guys Microsoft has been slowly but steadily improving Power apps & Microsoft Flow applications over the past 2 years. Recently they have released Rules for Power App. I have created an end to end basic power app for managing purchase orders and below is the video.


Friday, December 12, 2014

Finding the application pool for a sharepoint webapplication

found this awesome blog

http://www.sharepointchick.com/archive/2011/10/29/finding-the-application-pool-account-for-a-web-application.aspx

Tuesday, July 16, 2013

XSLTListview VS DataFormWebpart

Applies to SharePoint 2013

XSLTListview webpart was release with SharePoint 2010 to replace the Listview webpart which was used to display the list data in SharePoint 2007. It uses XSL and users can customize a lot of the XSLT and modify the look feel functionality which the LIisview webpart could not do. XSLTListview webpart works with lists and library but not with external lists.


Dataform webpart has always been around and is used to display data from list, library and external data sources as well.

Both dataform webpart and XSLT list view webpart can be customizable using XSLT for all sorts of things including Conditional formatting, sorting, filtering, grouping etc. SharePoint Designer is smart to user the right one depending on what you need it for and this is totally transparent to the user. When inserting a dataview in the page from Designer by selecting Dataview\ name of the list in the Ribbon, XSLT LIstview webpart is used whereas when Dataview\ Empty Dataview is selected from the ribbon in the designer, DataForm Webpart is used.

 

 

Check out my below posts on DataView Webpart, leave me a comment if you find them useful  

Using Dataview Webpart with SharePoint 2013
Difference between XsltListview webpart VS DataFormwebpart
Filtering XSLT List view web part with Text filter Web parts

Filtering XSLT List view webpart with Multiple SharePoint List filter webparts

Using Apply Filter Button webpart with multiple Filter webparts
Clearing filter selection on a DataView created by Filter Webparts

Clearing filter selection on a DataView created by Filter Webparts

Applies to SharePoint 2013

After using filter webparts with a dataview you will soon realize that if you want to clear the filter so that you can see all the records in the dataview it just does not work, i.e. you have to select all the filters all the time. There is not way to remove filter from one of the filters while applying filter on another one. With that being said I would also like to mention that this problem is with Empty Dataview webpart ( which is using data form webaprt ) only and not with the Dataview webpart from a list (which is making use of XSLTListview webpart )

Below is high level of what it takes to get it done and the rest of the post describes in detail :

· Create a row in the list with the value (Show All) in the column on which you want to apply filter , in my case this dummy row will contain (show All) for both first name and last name. This is key to the mechanism.

· Use XSLT Filtering instead of regular filter and do XPATH filtering. the problem with this approach is the filter is not applied in a CAML query but on the XML data after it retrieves all the data from the list which mean for larger lists it can be a performance issue. Below is code that I will be using in the advanced filtering window.

[

(

((@Title =$Param_Lastname or $Param_Lastname ='(Show All)') and @Title !='(Show All)') and

((@FirstName = $Param_FirstName or $Param_FirstName ='(Show All)') and @FirstName != '(Show All)')

)

]

Follow the above post to create a page with 2 list filter webparts, 1 apply filter button, 1 dataview and set the filtering based on parameter.

Create a row in the list with first name and last name value = (Show All). Now looking at the SharePoint list filter pop up page, it will show “(Show All)” as the first value. Users will select this to remove filter from that filter webpart.

image

Below I am deleting that filter that I created in my last post, if you don’t have it don’t bother deleting it.

image

click on the “Add XSLT Filtering “ to open the window

image

Add the following code in it, each line for

[

(

((@Title =$Param_Lastname or $Param_Lastname ='(Show All)') and @Title !='(Show All)') and

((@FirstName = $Param_FirstName or $Param_FirstName ='(Show All)') and @FirstName != '(Show All)')

)

]

The above code is just to either show the selected filter row OR if user has selected (show All) then show everything except for the (Show All) record. Looking deeper you will see one line of code for one filter webpart, so if you have more then add the same condition to every filter webpart.

Hit on Save, run the page and you will see that it lets you clear the filter on 1 filter webpart while the filter is applied on only the other. To run my test this is what I am filtering on step by step

Test 1 : First Name = Muzammil, Last Name = Mohammed

This will show the below 1 record

image

Now to see all people with Mohammed as the last name, remove the filter on First name by select (Show All) on the first name like below , hit on apply filter and Vola! All Mohammeds

image

 

Check out my below posts on DataView Webpart, leave me a comment if you find them useful  

Using Dataview Webpart with SharePoint 2013
Difference between XsltListview webpart VS DataFormwebpart
Filtering XSLT List view web part with Text filter Web parts

Filtering XSLT List view webpart with Multiple SharePoint List filter webparts

Using Apply Filter Button webpart with multiple Filter webparts
Clearing filter selection on a DataView created by Filter Webparts

Monday, July 15, 2013

Using Apply Filter Button webpart with multiple Filter webparts

Applies to SharePoint 2013

The good or bad thing about the filter webparts from the post above is that they do the filtering but instantaneously i.e as soon as I select firstname it applies the first name filter, then when I select lastname it does the last name filtering, at time this is not a good scenario specially in lists with a lot of data because it can cause the page to load real slow. And users want the filters to be applied only when they click on a button, the answer is the Apply Filter button.

ON the same page right below the list filter webparts lets add Apply Filters button.

image

The following tag is added

image

This single step just changes the behavior of the list filter webparts to now apply the filter only when this button is clicked. The Apply Filter button lightens up every time a filter selection is change.

image

 

Check out my below posts on DataView Webpart, leave me a comment if you find them useful  

Using Dataview Webpart with SharePoint 2013
Difference between XsltListview webpart VS DataFormwebpart
Filtering XSLT List view web part with Text filter Web parts

Filtering XSLT List view webpart with Multiple SharePoint List filter webparts

Using Apply Filter Button webpart with multiple Filter webparts
Clearing filter selection on a DataView created by Filter Webparts