Doug Does Tech
Doug Does Tech
  • 31
  • 66 913
How to setup Defender for Cloud Apps Session Control
Welcome to Doug Does Tech! In this video, Doug takes you step-by-step through setting up session control policies and conditional access in Microsoft Defender for Cloud Apps. If you're looking to enhance security and control access to your organization's cloud applications, this guide is for you.
We'll start with a demo of session control, showing you how users on unmanaged devices can access Web Based resources and encounter conditional access policies that prevent the download of data.
Then, Doug guides you through setting up Defender for Cloud Apps sessions, configuring conditional access policies, and onboarding Microsoft 365 apps.
Finally, we'll delve into creating custom session control policies tailored to your organization's specific needs.
Don't forget to like, share, and subscribe for more tech tutorials and cybersecurity tips from Doug Does Tech!
00:00 Introduction
00:21 Demo of Session Control
02:43 Setting up Defender Cloud Apps Session
04:10 Setup Conditional Access Session controls
05:59 Onboard M365 Session Control
09:34 Custom Session Control Policy
14:06 Onboard Custom App
มุมมอง: 970

วีดีโอ

Unlocking Defender for Cloud Apps: Your Swiss Army Knife of Cloud Security
มุมมอง 4842 หลายเดือนก่อน
Hey everyone, it's Doug from Doug Does Tech! I'm thrilled to introduce a new video series where we explore various Defender technologies by Microsoft. Today, we're kicking off with Defender for Cloud Apps. I like to think of this tool as the Swiss Army Knife of Microsoft security. In this video, I'll delve into its placement within the Microsoft security stack, highlight its top-level features,...
Is MFA Enough? Implementing FIDO Keys with Microsoft 365
มุมมอง 1.5K3 หลายเดือนก่อน
Traditional MFA may no longer suffice as a robust security measure to safeguard your crucial accounts. Hackers have devised new methods to breach your sign-in process, even with MFA in place. Hence, we require stronger forms of authentication. In this video, I delve into the array of options supported by Microsoft for robust authentication and demonstrate precisely how to implement FIDO Keys. L...
Welcome Back
มุมมอง 1173 หลายเดือนก่อน
After a little break, I'm back and ready to dive into some exciting new content. Get ready for deep dives into Microsoft 365 security, Defender, and Purview. Don't worry, I'll keep it relaxed and easy to understand, even for beginners. Thank you for your patience and support. If you have content or questions you would like me to cover put them into the comments and I will do my best to make a v...
Microsoft 365 Security Basics: Password Protection
มุมมอง 1Kปีที่แล้ว
Weak and easily guessable passwords 🗝️ have been a common pain for an organization's security. We all have tried to add password complexity, but users just think of easy ways to bypass it with things like CompanyName1! 😝 Or worse helpdesk uses passwords like the common Winter2023! or Fall2019! 🤢 Well in this video I will show you how you can ban those passwords from use in your environment whet...
Build a website using Azure Static Web Apps and Authenticate with AAD
มุมมอง 9Kปีที่แล้ว
Docusarus, Azure Static Web Apps, Github and Azure Active Directory, Oh MY! In this video, I'll introduce you to some exciting new technologies for building and hosting your own website for documentation. We'll start by creating a local site using Node JS and Docusaurus, followed by deploying it on Azure Static Web Apps. To enable seamless updates, we'll use GitHub's pull feature. Lastly, we'll...
Practical Conditional Access: The Secure Endpoint
มุมมอง 792ปีที่แล้ว
In this final video on Practical Conditional Access, we'll be sharing our favorite set of policies designed to ensure secure access to your organization's environment. Specifically, we'll be focusing on the "The Secure Endpoint" policy, which is a customizable template that addresses a variety of scenarios. The main goal of which is to limit access from non-managed devices and ensure that our B...
Create a Conditional Access Policy Design: The Castle Bypass
มุมมอง 765ปีที่แล้ว
In the second video in our series on Practical Conditional Access, we are talking about requiring MFA except when you are in a trusted location. This type of policy is common but increases an organization's risk due to the bypass. So in this video, we will walk through a design called "The Castle Bypass" which fixes some of the issues with using a trusted location. In this video, we will be foc...
Create a Conditional Access Policy Design: The Baseline
มุมมอง 571ปีที่แล้ว
Creating a set of Conditional Access policies on your own without ever seeing how other orgs do it can be hard. In this series, we will be showcasing different policy designs and providing examples of practical deployments to meet various organizational requirements. These policies are designed to be templates that can be easily customized to fit the unique needs of your organization. In this v...
Microsoft 365 Security Basics: Exchange Online
มุมมอง 1.8Kปีที่แล้ว
In this video, we'll cover some key points you need to know to secure your Exchange Online environment. We'll discuss topics such as disabling legacy authentication, identifying risky email overrides, enabling audit logging, blocking outbound forwarding, help users quickly identify external emails, and enabling an easy way for your users to report phishing attacks. By the end of this video, you...
Conditional Access 101: Understanding and Implementing This Powerful Security Feature
มุมมอง 689ปีที่แล้ว
In this video, we'll be discussing the importance of MFA and how you can use conditional access to ensure that your organization's accounts are properly secured. Did you know that only 26.64% of Azure AD accounts use MFA? This means that a large number of accounts are not adequately protected against unauthorized access. By implementing conditional access, you can require MFA for certain types ...
Microsoft Purview DLP report Using Power Bi
มุมมอง 3.6Kปีที่แล้ว
The Built-in reporting engine for Purview DLP is pretty limited. However, with Power Bi, we can create custom reports that really help extend the functionality of our reporting. In this video, I do my best impression of a Power Bi Report designer and show how you can get started with PowerBi reporting. L I N K S Sample Report app.powerbi.com/view?r=eyJrIjoiN2Q3ODRhNDgtMWY1OS00MzQ3LWI4NzAtMTcxZG...
Microsoft 365 Security Basics: SharePoint & One Drive Security
มุมมอง 1.4Kปีที่แล้ว
SharePoint and OneDrive leave a lot to be desired in the way of default security configs. in this video, I walk through the basic options of locking down your environment so you make sure your data is protected. C H A P T E R S 00:00 Video Intro 01:28 Sharing Controls 07:41 Security Controls 12:14 Access Controls 16:58 Wrap UP L I N K S Sharing Controls learn.microsoft.com/en-US/sharepoint/turn...
Set up Microsoft Exact Data Match - Sensitive Info Type Setup
มุมมอง 1.3Kปีที่แล้ว
This is the final video in the series on building an EDM solution using Microsoft Purview. In this video, we will set up the Sensitive Info Definition that uses EDM. I will cover creating the SIT using XML, and cover the key decisions/items that go into your policy design. L I N K S MSFT Doc learn.microsoft.com/en-us/microsoft-365/compliance/sit-get-started-exact-data-match-create-rule-package?...
Microsoft 365 Security Basics: Separate & Cloud Gapped Admin accounts
มุมมอง 556ปีที่แล้ว
I am back with another M365 Security Basic, this one isn't a setting but a change in methodology. Separating your Standard user account and Admin account, and mastering your cloud admin accounts in M365. Let me know in the comments if you separate your accounts and if you use cloud-only admins. C H A P T E R S 00:00 Video Intro 00:58 Separate Admin Accounts 05:17 Cloud Only Admin Accounts 06:53...
Set up Microsoft Exact Data Match - Hash and Upload your Data
มุมมอง 1.5Kปีที่แล้ว
Set up Microsoft Exact Data Match - Hash and Upload your Data
Set up Microsoft Exact Data Match - Build your data Schema
มุมมอง 1.4Kปีที่แล้ว
Set up Microsoft Exact Data Match - Build your data Schema
Set up Microsoft Exact Data Match - Overview
มุมมอง 1.5Kปีที่แล้ว
Set up Microsoft Exact Data Match - Overview
Microsoft 365 Security Basics: Enterprise Application Admin Consent Workflows
มุมมอง 1.9Kปีที่แล้ว
Microsoft 365 Security Basics: Enterprise Application Admin Consent Workflows
Microsoft 365 Security Basics: MFA Fraud Alert
มุมมอง 1.8Kปีที่แล้ว
Microsoft 365 Security Basics: MFA Fraud Alert
Microsoft 365 Security Basics: Secure Azure AD Directory Access
มุมมอง 394ปีที่แล้ว
Microsoft 365 Security Basics: Secure Azure AD Directory Access
Microsoft 365 Security Basics: Deploy MFA (4 Options)
มุมมอง 1.3Kปีที่แล้ว
Microsoft 365 Security Basics: Deploy MFA (4 Options)
Automatically Apply Sensitive Labels: 3 Options
มุมมอง 6K2 ปีที่แล้ว
Automatically Apply Sensitive Labels: 3 Options
Deploy MIP Sensitivity Labels
มุมมอง 2.8K2 ปีที่แล้ว
Deploy MIP Sensitivity Labels
MIP - Sensitivity Label Overview
มุมมอง 1.4K2 ปีที่แล้ว
MIP - Sensitivity Label Overview
Exchange Online DLP Advanced Options
มุมมอง 1.8K2 ปีที่แล้ว
Exchange Online DLP Advanced Options
DLP Next Steps - User Education Mode
มุมมอง 1.2K2 ปีที่แล้ว
DLP Next Steps - User Education Mode
Design a Custom Sensitive Info Type (SIT) in Microsoft Purview
มุมมอง 3K2 ปีที่แล้ว
Design a Custom Sensitive Info Type (SIT) in Microsoft Purview
Exploring Sensitive Info Types
มุมมอง 2.2K2 ปีที่แล้ว
Exploring Sensitive Info Types
Build your first Microsoft Purview DLP Policy
มุมมอง 14K2 ปีที่แล้ว
Build your first Microsoft Purview DLP Policy

ความคิดเห็น

  • @kjhgliuguiug
    @kjhgliuguiug 2 วันที่ผ่านมา

    I haven't been able to get Device Exclusions to work in the CA policy. When trying to exclude Compliant devices, specifically, the Conditional Access App Control policy is applied regardless. As a result, I'm getting stumped trying to allow downloads from Exchange Online on compliant devices. We're not hybrid and it's looking the only solution is going to be with certificates. Have you seen this issue?

  • @atulpathare2775
    @atulpathare2775 3 วันที่ผ่านมา

    Thanks a bunch for this Video, Really you explain very well

  • @fernandofischer3725
    @fernandofischer3725 10 วันที่ผ่านมา

    Awesome video, Thanks!! Would definitely love seeing a B2C walkthrough.

  • @rlee431
    @rlee431 13 วันที่ผ่านมา

    This was incredibly helpful!!

  • @cloudengineersacademy
    @cloudengineersacademy 16 วันที่ผ่านมา

    Excellent Video, Helped a lot.

  • @aadilkarolia
    @aadilkarolia หลายเดือนก่อน

    Thank you for this video, it was really helpful. I was struggling to find an end-to-end guide in a single video/article. Appreciate this 🙂

  • @danaknox3395
    @danaknox3395 หลายเดือนก่อน

    I'm not seeing any exceptions in my my policy?

    • @DougDoesTech
      @DougDoesTech หลายเดือนก่อน

      They changed the portal since making this video. In the rule section create a group then use the “not” toggle. And add all the exceptions you need to that.

    • @danaknox3395
      @danaknox3395 หลายเดือนก่อน

      @@DougDoesTech Thank you! Yes, I added a group and chose NOT for the exceptions. I also added encryption after the approval to enforce the sensitive data to be encrypted. This guide really helped me!!

    • @danaknox3395
      @danaknox3395 หลายเดือนก่อน

      @@DougDoesTech I have another question. If I block sensitive data stored in Office 365. How would I go about marking them as false positives or not sensitive? I'm in the content explorer console and it only calls out "Not a Match". Is there a way to handle those files vs using the override feature?

  • @angelcardenas4266
    @angelcardenas4266 หลายเดือนก่อน

    Me fue de mucha utilidad, gracias! Nuevo suscriptor

  • @ehabgalal9181
    @ehabgalal9181 หลายเดือนก่อน

    Hi, What is the value of adding the admin user in onboarding page ? I don’t have one configured and I was able to onboarding the app

    • @DougDoesTech
      @DougDoesTech หลายเดือนก่อน

      Many times you don’t need it. But if something doesn’t go right or work you have some of the diagnostic tools you need to fix the app. learn.microsoft.com/en-us/defender-cloud-apps/proxy-deployment-any-app

    • @ehabgalal9181
      @ehabgalal9181 หลายเดือนก่อน

      @@DougDoesTech Thank you for your clarification. One more point please We have custom mobile app that using azure ad for authentication. We have tried to onboard it to MCAS but it seems it didn’t So, is the MCAS support only web not mobile app

    • @DougDoesTech
      @DougDoesTech หลายเดือนก่อน

      As far as I know session policy’s like blocking download can only be applied to web based sessions. You can use access policy to control access to mobile and desktop apps. But it won’t do the block download type controls.

  • @lasolution365
    @lasolution365 หลายเดือนก่อน

    Thank you very much for these videos, it has been really helpful. You are one of the best instructor I watch. Thanks again.

    • @DougDoesTech
      @DougDoesTech หลายเดือนก่อน

      Hey so glad it was helpful! and thank you for the compliment!

  • @slartibartfastlunkwill5790
    @slartibartfastlunkwill5790 2 หลายเดือนก่อน

    Good to see you're back to making videos.

  • @christopherpeterson6004
    @christopherpeterson6004 2 หลายเดือนก่อน

    Thank you. Very helpful to tell us the evaluated options. I was terrified of activating it and potentially losing access. Would you recommend multiple devices for Domain Admins?

    • @DougDoesTech
      @DougDoesTech 2 หลายเดือนก่อน

      Yes I have 2 keys for my admin account just in case. But if you are supporting passwordless via Authenticator app it should be fine.

  • @jg-365
    @jg-365 2 หลายเดือนก่อน

    About time =)

  • @mannykhan7752
    @mannykhan7752 2 หลายเดือนก่อน

    Amazing video. Just what I was looking for. This helped me in a big way. Thanks.

  • @zol95
    @zol95 3 หลายเดือนก่อน

    This is exactly what I needed, a straight to the point comparison between all the options. I spent several hours figuring out the difference based on the documentation and random Yt videos, even spend a couple of bucks on Udemy courses which all lack this info. Great content and style subscribed!

  • @zol95
    @zol95 3 หลายเดือนก่อน

    Just found your channel thanks to your MFA rollout video. I really like the clean straightforward explanation style you use. I will check your previous videos and I'm looking forward to your new videos! Best of luck to your channel!

    • @DougDoesTech
      @DougDoesTech 3 หลายเดือนก่อน

      Hey so glad you found it helpful!

  • @gvdlaarse
    @gvdlaarse 3 หลายเดือนก่อน

    Appreciate the demo thank you! Like many I need this data to be real-time, or even be updated once a month. Any idea if an API is available? Or how to update the data source with a script for instance.

  • @tancouver
    @tancouver 3 หลายเดือนก่อน

    Thanks, Doug. This really helped me. For some reason, the manifest.json linked in the index.html causes unintentional redirects whenever I try to add any type of authentication. I just removed it and that helped me for now. Weird how this doesn't come up in your example, making me think this could be something specific to my organizational tenant.

  • @akashnautiyal4490
    @akashnautiyal4490 3 หลายเดือนก่อน

    Hi Doug, could you please share the spreadsheet, it will be really helpful.

  • @akashnautiyal4490
    @akashnautiyal4490 3 หลายเดือนก่อน

    Great playlist Doug!

  • @MrAshwin283
    @MrAshwin283 4 หลายเดือนก่อน

    Cool video Doug. Very simply and clearly explained !!

  • @artorhemnnahs
    @artorhemnnahs 4 หลายเดือนก่อน

    I rarely post, but when I do, it's to say thanks. This helped a lot. Very clear.

  • @puduville1
    @puduville1 4 หลายเดือนก่อน

    Please show us how to connect to AAD B2c please!

  • @cacurazi
    @cacurazi 4 หลายเดือนก่อน

    Bro, how many times do you have to sneeze 🤧? Jesus Christ 😭 Anyway, this was wonderful. Keep it up!!

  • @Kinyo-ck6rf
    @Kinyo-ck6rf 5 หลายเดือนก่อน

    Thanks for the video Doug. When i try to Parse the "Sensitive Info type - metadata" column, I get a 97% error. The excel file is directly exported from Purview and hasnt been modified. Are you able to advise on this pls

  • @user-oe6pi8fu8g
    @user-oe6pi8fu8g 5 หลายเดือนก่อน

    Great Video, How can I get lab for testing

  • @chitchatvn5208
    @chitchatvn5208 5 หลายเดือนก่อน

    Thanks a lot. Great content and presentation.

  • @Elegant-Shanvi
    @Elegant-Shanvi 6 หลายเดือนก่อน

    Trust me your videos ae pretty much better than concept wise and practically.

  • @nazerbor3i
    @nazerbor3i 6 หลายเดือนก่อน

    Can you please make a long video and cover the best practices of secure a microsoft 365 Tenant? Such Conditional Access Policies, Defender Endpoint Protection, EOP, Endpoint Manager Deploying Apps and configuring Windows Security Policies, Data Labelling and Classification, DLP , Internal & External Sharing policies, MFA and SSPr etc ... Please make a Playlist or couple of long videos on that Thank you

  • @nazerbor3i
    @nazerbor3i 6 หลายเดือนก่อน

    You are the KING

  • @andreabovo5208
    @andreabovo5208 6 หลายเดือนก่อน

    Is it possible to test it on local? If not is going to be difficult to use in real scenarios. Maybe better use MSAL

  • @user-su8tw9nw5s
    @user-su8tw9nw5s 6 หลายเดือนก่อน

    Great vedio, thank you for sharing the knowledge about DLP I'm looking to build the Power BI report through MPARR scripts, can u please help to me how to build the report.

  • @user-tx4cc8tm1s
    @user-tx4cc8tm1s 7 หลายเดือนก่อน

    Very informative and very closer to real world situations..Thanks.

  • @user-tx4cc8tm1s
    @user-tx4cc8tm1s 7 หลายเดือนก่อน

    Amazing explanation. Thanks for your efforts 👍

  • @KapKen
    @KapKen 7 หลายเดือนก่อน

    Great video Doug. Very informative. You have a new subbie.

  • @cutebot3342
    @cutebot3342 7 หลายเดือนก่อน

    Any thoughts on how you connect this PowerBI template to your Purview data so it's using data in real-time?

    • @DougDoesTech
      @DougDoesTech 7 หลายเดือนก่อน

      I wrote a script to export the data the other day using powershell. Try it out and let me know if it helps. github.com/dougsbaker/Public-Toolbox/blob/main/o365%20Tools/Compliance/Reports/Get-DLPReportData.ps1

  • @JamesProvinciali
    @JamesProvinciali 7 หลายเดือนก่อน

    I'm confused, you deleted the supporting elements keyword list for both low accuracy patterns and the keywords still appeared for the first data set. For the 2nd data set with no keywords wouldn't the low accuracy patterns hit because you removed the key word list from them. Great video btw!

    • @DougDoesTech
      @DougDoesTech 7 หลายเดือนก่อน

      For SSN each primary match MSFT has is slightly different. Ex: XXX XX XXXX vs XXXXXXXXX vs XXX-XX-XXXX. So if you want the no keyword you may need to remove it from each definition.

  • @ScalarRon
    @ScalarRon 8 หลายเดือนก่อน

    I ran into all the same problems. The custom auth requirement definitely isn't straight forward. Thanks, Doug!

  • @1988alpesh
    @1988alpesh 8 หลายเดือนก่อน

    Great stuff :), happy to watch

  • @zyeuh2565
    @zyeuh2565 8 หลายเดือนก่อน

    3:09 FYI - user will not be able to reset their password until the unblock here is performed.

  • @grantbaxter5520
    @grantbaxter5520 9 หลายเดือนก่อน

    followed the video which yes it does work to a point and I have triple checked everything however, I now get the error AADSTS9002325: Proof Key for Code Exchange is required for cross-origin authorization code redemption.

  • @Above101
    @Above101 9 หลายเดือนก่อน

    Thanks for the video, Doug. Could you please share the spreadsheet with the label definitions? Thanks

  • @johndignum8561
    @johndignum8561 10 หลายเดือนก่อน

    it seemed inportant in my environment to redownload the schema even after creating and uploading your own schema from scratch, as when you download the schema it has extra things inside which are not necessarily added when manually creating a schema file. i was seeing errors about "The schema does not match with the definition file: The required attribute 'maximumNumberOfTokens' is missing." until i downloaded the schema where i saw extra information had been added and only then would the following commands work after exporting:- <DataStore name="testedm1209" description="Test Schema 12-09-2023" version="1" maximumNumberOfTokens="8"> <Field name="SSN" searchable="true" caseInsensitive="true" ignoredDelimiters="-,/,*,#,^" isMultiToken="false" /> before exporting (failing):- <DataStore name="testedm1209" description="Test Schema 12-09-2023" version="1"> <Field name="SSN" searchable="true" caseInsensitive="true" ignoredDelimiters="-,/,*,#,^" />

  • @johndignum8561
    @johndignum8561 10 หลายเดือนก่อน

    when i follow this video i hit problems running this command PS C:\Users\E1207878> $edmschemaxml = get-content "C:\temp\TestSchema.xml" -encoding Byte -readcount 0 I get the error:- Get-Content: Cannot process argument transformation on parameter 'Encoding'. 'Byte' is not a supported encoding name. For information on defining a custom encoding, see the documentation for the Encoding.RegisterProvider method. (Parameter 'name') Apparently "-Encoding Byte" is replaced by "-AsByteStream"

  • @kanishkaroychowdhury4050
    @kanishkaroychowdhury4050 10 หลายเดือนก่อน

    hi... great staff... please upload a video how to design the same

  • @user-fx6wx2fb3h
    @user-fx6wx2fb3h 10 หลายเดือนก่อน

    Your video help me a lot, even the official documentation confuses on how to configure SWA easily. You video did the trick. Thanks or creating this

  • @bazzalew2873
    @bazzalew2873 11 หลายเดือนก่อน

    Great Video thanks, is it possible to colloect this data via API? running this as a manual process is time consuming and being able to pull the data automatically will make this report live and much more efficient.

  • @arunzone4477
    @arunzone4477 11 หลายเดือนก่อน

    Plz smile.. Sir

  • @dominikmeyer8078
    @dominikmeyer8078 11 หลายเดือนก่อน

    I rarely if ever comment a TH-cam video (unthankful ass). But I have to: This video made my deployment work on the first run including AAD (tenant specific) authentication! Thank you, very on point!