Adam Brewer
Adam Brewer
  • 8
  • 27 476
Azure Active Directory Identity Protection and Risk-Based Conditional Access discussion and demo
Azure Active Directory Identity Protection assigns a risk score to every sign-in to your organization. You can use this risk score as one component of a Conditional Access policy in order to prompt users for Multi-Factor Authentication (MFA), deliver a Limited Session, block the sign-in entirely, or any other control you want to implement.
In this video, we walk through the concepts of Azure AD Identity Protection, build a simple Conditional Access policy, and walk you through a demo of the user experience.
Переглядів: 641

Відео

Microsoft Intune App Protection Policies demo and discussion
Переглядів 21 тис.3 роки тому
Most people know that Microsoft Intune is a full-featured modern/mobile device management (MDM) solution across iOS, iPadOS, macOS, Android, and Windows 10. But what many people don't know is that Intune also offers the ability to manage *just* the applications on an iOS, iPadOS, or Android device through the use of Mobile Application Management (MAM). The policies that make MAM possible are ca...
Microsoft Defender for Endpoint and Microsoft Cloud App Security integration -- demo and discussion
Переглядів 8853 роки тому
Adam Brewer walks you through the integration between two Gartner Magic Quadrant and Forrester Wave leading solutions: Microsoft Cloud App Security and Microsoft Defender for Endpoint (formerly Microsoft Defender ATP). Microsoft Defender for Endpoint can act as your discovery agent on client devices, helping Microsoft Cloud App Security to ingest your user behavior and understand what kinds of ...
Microsoft Endpoint Data Loss Prevention (DLP) discussion and demo
Переглядів 1,1 тис.3 роки тому
Microsoft has entered into the Endpoint Data Loss Prevention (Endpoint DLP) category, with a new product that's built right in to the Windows 10 operating system. There's no new agent to install, no conflicts to resolve, and minimal performance impact. Plus, it leverages all of the work and investments you've made into the Microsoft 365 Data Loss Prevention service that you're already using to ...
Microsoft Information Protection demo and discussion
Переглядів 2773 роки тому
Microsoft has a long heritage of protecting sensitive documents, dating back to technologies like Active Directory Rights Management Service, moving to the cloud as Azure Rights Management Service, adding visual marking and classification of all documents as Azure Information Protection, and finally, to today's Microsoft Information Protection. Microsoft understands that today's organizations a...
Azure Active Directory and Device-Based Conditional Access demo and discussion
Переглядів 5243 роки тому
Azure Active Directory and Microsoft Endpoint Manager (including ConfigMgr and Intune) practically grew up together. From the beginning, Microsoft has understood that the interplay of device and identity will deliver the most powerful security control plane as we move to a Zero Trust model. In this video, I discuss the two models of device management that can be used by Azure Active Directory: ...
Microsoft Passwordless with Azure Active Directory: FIDO2, Windows Hello for Business, and more
Переглядів 2 тис.3 роки тому
Learn about Microsoft's trio of Passwordless technologies that are available for use with Azure Active Directory and Windows 10: FIDO2 security keys, Windows Hello for Business, and the Microsoft Authenticator app. I walk through the use cases and benefits of all three technologies, why passwords can never be truly secure, and demonstrate all of them in action.
Microsoft Cloud App Security - Conditional Access App Control demo and discussion
Переглядів 9373 роки тому
Microsoft Cloud App Security enables enterprises to add additional monitoring and control of first-party Microsoft and third-party SaaS apps through the use of Conditional Access App Control. This feature puts a cloud proxy between the user and their application, allowing Microsoft Cloud App Security to inspect traffic, and if needed, take corrective action. Azure Active Directory's powerful Co...

КОМЕНТАРІ

  • @alzain55a
    @alzain55a Місяць тому

    I just notest that this video 3 years back - we just start to use MDM and MAM we are very late 😂😂 many thanks

  • @thomasamenya3532
    @thomasamenya3532 8 місяців тому

    Concise! Thanks Adam. 🇰🇪

  • @tharagz08
    @tharagz08 9 місяців тому

    Would the reverse proxy URL also be used for managed/company owned devices accessing the federated cloud app? Is it possible to only utilize that when it is an unmanaged device accessing the federated cloud app?

  • @AdamBrewerTech
    @AdamBrewerTech 10 місяців тому

    Yes, it is me

  • @joblearn1014
    @joblearn1014 11 місяців тому

    what licnses i need to enable to be able to use MAM?

  • @AdamBrewerTech
    @AdamBrewerTech Рік тому

    Daddy, it’s you

  • @TheDogtag2336
    @TheDogtag2336 Рік тому

    hey, we are facing an issue where we need to have an app before we can make a session/access policy in the cloud app defender portal. How do we add this? can we add a generic one so we are able to create the policies? we simply need the policy to reference in a CA policy to use the Certificate for authentication towards Sharepoint.

  • @massiellazo6354
    @massiellazo6354 Рік тому

    Hi, can I install personal software in my laptop even thoug is connected to intune?

  • @MIUAT
    @MIUAT Рік тому

    Why would you need biometric or pin for Outlook? Are Access Requirements really necessary?

    • @shwethanayak
      @shwethanayak Рік тому

      Yes. At least on Personal device if some one who knows device password can be stopped from reading corporate data.

  • @gunasekhar7480
    @gunasekhar7480 Рік тому

    On intune installed mobile, if we add multiple accounts to outlook or office or ms teams --- will this info be captured ? Thanks in advance.

  • @thesweetestbittercandy
    @thesweetestbittercandy Рік тому

    Love this adam ❤️ thanks for the info

  • @shabeelaboobacker352
    @shabeelaboobacker352 2 роки тому

    Who has the permission to label a document? How it’s controlling to prevent data classification labeling?

  • @samnnamani
    @samnnamani 2 роки тому

    Im from 2 years into the future and this is the right way to do it.

  • @ororosso9615
    @ororosso9615 2 роки тому

    i cannot understand, maybe you can help, if you can still use normal password autentication(key icon in 5:38) mfa turn useless right?

  • @sarahal-harbi5241
    @sarahal-harbi5241 2 роки тому

    👍🏼

  • @bilalashraf9371
    @bilalashraf9371 2 роки тому

    can anyone let me know about the Screenshot?? Is it possible that we can block screenshots through app protection policy in iOS devices like Android devices

  • @lojim596
    @lojim596 2 роки тому

    Hi Adam, If i have created a conditional access policy for blocking high risky sign-in user. my question is 1) if this policy is enabled, high risky sign-in user would see what notification screen. 2) It is a false positive case, how to resume that accounts. thanks

  • @miketheinsurancecoach
    @miketheinsurancecoach 2 роки тому

    Adam can this help my employees log into website URL's without having to log into the site with a user name and password? We sell insurance. So I log into my insurance company(ies) websites. How can this help me instead of using a password manager?

  • @tharagz08
    @tharagz08 2 роки тому

    The video is missing where you talk about assigning the application policy to a user or device, and what requirements there are for it to go into effect on the device. Some discussions around devices already signed into apps that will have the controls applied, vs. Net new devices, would also be helpful I mention that because I'm working through testing MAM-WE on an Android device and it seems like the Company Portal app might be required, though I am not positive.

    • @Schnitzer325ci
      @Schnitzer325ci 2 роки тому

      You create a policy for unmanaged devices first, then you assign to a group with users in it as MAM works at application level, not device level. You then build a configuration for managed apps. If you need to troubleshoot something, go to Apps>Monitor>Application Controls and download a report and filter in Excel. Start small and note, it can take up to 8 hours for MAM to sync changes.

  • @MisterCaution
    @MisterCaution 2 роки тому

    Let’s say there was someone with criminal intent and admin-level privileges on my employer’s IT staff…. What type of damage, hacking, or spying can they do with Intune on iOS/iPadOS? Can they screen capture, remote access my device’s cameras/microphones, keylog an iPad keyboard, read personal texts/emails, access non-work app data (like AppleID/iCloud, banking, medical records, non-work notes)? What type of Big Brother stuff does Intune enable under the worst of circumstances? 🙏

    • @Schnitzer325ci
      @Schnitzer325ci 2 роки тому

      Endpoint Manager is not a spying tool. Yes an admin can enable remote access to a device and depending upon the circumstances, monitor and control. But you'd be well aware of this on an iPad. That being said, what exactly convinced you of criminal intent and theft was to follow?

    • @MisterCaution
      @MisterCaution 2 роки тому

      @@Schnitzer325ci I’ve been paranoid since being at an employer who had a system admin who used their privileges to spy and harass a female colleague. He’s in prison now (for later crimes).

  • @sagarrastogi2647
    @sagarrastogi2647 2 роки тому

    Superb!!!

  • @amualla
    @amualla 2 роки тому

    Thank you. It’s been long since you posted, I haven’t been on YT for a long time too. I hope everything is fine. Stay safe

  • @MikeSmith-iv5vv
    @MikeSmith-iv5vv 3 роки тому

    Why does this not have more thumbs up? This short video gives me more useful info about Intune then the same repetitive "sales pitch" info on the MS website and other YT vids. Thanks Adam.

  • @E_holms
    @E_holms 3 роки тому

    Hey, really awesome demo was super helpful!

  • @martinschlenker6145
    @martinschlenker6145 3 роки тому

    Thanks Adam ! Great video that points the attendee to the most important points. Would be great to have one or two other videos that show "hoe to set up" the policies.

  • @donaldsimmons6880
    @donaldsimmons6880 3 роки тому

    Hi Adam, I'm in the process of testing the app protection policies using the public apps under Microsoft office. However, none of the controls seem to be working. Are there other profiles or policies required?

    • @marvinnerio9931
      @marvinnerio9931 3 роки тому

      Check if the device is enrolled with intune and if the user has the required licence.

    • @Sto79Be
      @Sto79Be 10 місяців тому

      @@marvinnerio9931That’s literally the opposite of what MAM only is for.

  • @Lewis01Brown
    @Lewis01Brown 3 роки тому

    Could you still screenshot the corporate data and share that image elsewhere?

    • @marvinnerio9931
      @marvinnerio9931 3 роки тому

      Hello, I've been working with these policies and no, you can't take a screenshot and share it. You can configure a policy so you can't take a screenshot of any kind of content inside the protected applications.

  • @zakieliyas7638
    @zakieliyas7638 3 роки тому

    Great video

  • @racheljusseaume8953
    @racheljusseaume8953 3 роки тому

    This is a great overview!

    • @thiagokareem7045
      @thiagokareem7045 3 роки тому

      i dont mean to be so off topic but does someone know a way to log back into an Instagram account?? I was dumb forgot my account password. I would love any help you can give me!

    • @samueldwayne6899
      @samueldwayne6899 3 роки тому

      @Thiago Kareem Instablaster =)

    • @thiagokareem7045
      @thiagokareem7045 3 роки тому

      @Samuel Dwayne I really appreciate your reply. I got to the site thru google and I'm in the hacking process now. Seems to take a while so I will get back to you later when my account password hopefully is recovered.

    • @thiagokareem7045
      @thiagokareem7045 3 роки тому

      @Samuel Dwayne it did the trick and I now got access to my account again. Im so happy! Thank you so much, you saved my account !

    • @samueldwayne6899
      @samueldwayne6899 3 роки тому

      @Thiago Kareem glad I could help :D

  • @TechSimplifiedAI
    @TechSimplifiedAI 3 роки тому

    Great demo!

  • @TechSimplifiedAI
    @TechSimplifiedAI 3 роки тому

    Thanks for sharing this video!

  • @vidanaweer1662
    @vidanaweer1662 3 роки тому

    Hi Adam, Thanks for the video. I have set up the endpoint DLP on my tenancy but it wont kick in. I have my pc domain joined with endpoint management. Are there anything else that I have to check? Thanks.