MCAS | Conditional Access App Control | Block download on Untrusted Devices

Поділитися
Вставка
  • Опубліковано 31 жов 2020
  • #Microsoft #CASB #Microsoft_Cloud_App_Security #ConditionalAccessAppControl
    What is CASB?
    What is Microsoft Cloud app Security?
    Conditional Access App Control
    Session Control Policy - Block download on Untrusted Devices
    What is Microsoft Cloud app Security? • What is Microsoft Clou...
    Getting Started with Microsoft Cloud App Security? • Getting Started with M...
    Microsoft Cloud app security | Shadow IT Discovery • Microsoft Cloud App Se...
    Microsoft Cloud app Security | All the setting covered in less that 30 minutes • Microsoft Cloud App Se...
    Microsoft Cloud app Security | Conditional Access App Control • Microsoft Cloud App Se...
    MCAS | Conditional Access App Control | Session Policy - Block Cut/Copy/Paste • MCAS | Conditional Acc...
    MCAS | Conditional Access App Control | Block download on Untrusted Devices • MCAS | Conditional Acc...
    MCAS | Block download based on Real Time Content Inspection • MCAS | Block download ...
    Microsoft Article - docs.microsoft.com/en-us/clou...
    docs.microsoft.com/en-us/clou...
    Regards,
    ConceptsWork
  • Наука та технологія

КОМЕНТАРІ • 29

  • @nadeerbabu872
    @nadeerbabu872 3 роки тому +1

    Thanks, good content 👍

  • @ehabgalal9181
    @ehabgalal9181 7 місяців тому

    Hi,
    We have LOB APP that has redirect url for ios and android and we don’t have web. Does the MCAS can work with it

  • @soydlm8658
    @soydlm8658 3 роки тому +1

    the session control rules that you explain in the last two videos. Is it applicable for the heavy outlook client or only for web access?

    • @ConceptsWork
      @ConceptsWork  3 роки тому +2

      The session rules are for browser based sessions only.

    • @soydlm8658
      @soydlm8658 3 роки тому +1

      @@ConceptsWork Thanks, If I need to block the outlook client on unmanaged computers, could it be done with a conditional access rule?

  • @maciejdiakow6231
    @maciejdiakow6231 3 роки тому

    Great job :) Maybe a video regarding DLP ? :)

  • @SupertecRacing
    @SupertecRacing 2 роки тому

    Is there a way to block access to the portal on all untrusted devices such as personal machines and only allow on AZ hybrid joined machines?

  • @bijukumarbarik3259
    @bijukumarbarik3259 3 роки тому

    Sir, I need some information regarding the Azure Active Directory.
    One of my client requirement. They want to implement an NTP server in Azure Active Directory. Is this possible or not?

    • @ConceptsWork
      @ConceptsWork  3 роки тому

      Feel free to reach me at learnconceptswork@gmail.com

  • @amanjha2289
    @amanjha2289 3 роки тому +1

    bro please make video on azure atp pleeese

  • @Obayd
    @Obayd 2 роки тому

    Hi first of all i like to say this is briallant video and was very helpful. I am having an issue though when I create this block policy from unmanaged devcies for any O365 apps it still allows me to download from Onedrive on edge chromium browser and also I can download from Teams desktop app. This on my personal windows 10 suface laptop.
    The policy however blocks me downloading from Outlook (OWA) in Edge chromium browser. Also it blocks download from onedrive and outlook (OWA) when using Google chrome from the same surface laptop.
    i cant understand why it allows me to download files from Onedrive web portal on the new edge browser and also on the teams desktop app. Any help on this is much appreciated.
    Many Thanks

    • @ConceptsWork
      @ConceptsWork  2 роки тому

      Thanks for sharing this observation, to begin with Conditional access app control is only applied to browser based session, it is not applicable for rich client. If you want to block rich client's, create a CA policy to block rich clients on unmanaged devices.
      For the other issues where the access is provided to just one browser and for every other browser policy is working as expected.
      I would suggest take a fiddler trace and see, if the traffic is getting routed to MCAS endpoints.

    • @Obayd
      @Obayd 2 роки тому

      @@ConceptsWork hi thanks for the reply it is not routing through MCAS when I open OneDrive in edge chromium web browser as it doesn’t show the page where it says you are being monitored. Also on the url I can see the traffic is not directed via MCAS. But when I open Outlook in edge chromium browser on the same device I can see traffic is being routed via mcas as I get the page to say you are being monitored and can see on the url that I have been directed through MCAS.
      I can try fiddler but I think I know what the answer will be when seeing how the traffic is routing in edge chromium browser when opening OneDrive via the web.
      Let me know your thoughts and your help is much appreciated.

  • @asithahttp
    @asithahttp 3 роки тому

    very familiar voice, may i know the name of the speaker ?

  • @amitbahuguna3270
    @amitbahuguna3270 2 роки тому

    can i get ppt of this video

  • @ishwariyaiyer5381
    @ishwariyaiyer5381 3 роки тому +1

    Is it possible to allow edit but block download using MCAS

    • @ConceptsWork
      @ConceptsWork  3 роки тому +1

      Users will be able to edit documents with online applications.

    • @ishwariyaiyer5381
      @ishwariyaiyer5381 3 роки тому

      Thank you for your reply. Also what’s the difference between block save option and allow edit doc in AIP with custom permissions and block download in MCAS

    • @ConceptsWork
      @ConceptsWork  3 роки тому

      When you assign a permission through AIP, its a doc level permission, but when you enable a control in MCAS, like wise block download, any type of information from that particular session will be blocked.

  • @ronald0122
    @ronald0122 3 роки тому +1

    what license do you need for cloud app security

    • @ConceptsWork
      @ConceptsWork  3 роки тому

      License - query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2NXYO
      Getting started with MCAS - ua-cam.com/video/cmcsIwKb--A/v-deo.html

    • @ronald0122
      @ronald0122 3 роки тому

      @@ConceptsWork thanks to bad i only have E3 and EMS. great work. love your videos.

  • @amitmanolkar
    @amitmanolkar 10 місяців тому

    What about the apps that are not listed in the connected apps? What can be done there and how?

    • @ConceptsWork
      @ConceptsWork  10 місяців тому

      Application's authentication must be done with Azure AD. If the application is doesn't have IDP as Azure AD, then conditional access app control will not work.

    • @amitmanolkar
      @amitmanolkar 10 місяців тому

      @@ConceptsWork what all can be done with data residing in such application?

    • @ConceptsWork
      @ConceptsWork  10 місяців тому

      Where ever you have hosted application.