Doug Does Tech
Doug Does Tech
  • Видео 34
  • Просмотров 89 321
Control USB Devices using Defender for Endpoint and Intune (Device Control)
Do you need to design a Device Control Policy to block all but a few select USBs from being written to or read from? If that is you, this is the video to help!
I recently needed to create a policy to manage USBs. We wanted to block people from writing to USBs unless the devices were in our approved list. In this video, I'll show you how to build out USB device controls using Intune and Defender for Endpoint.
We'll start by discussing the need for such policies and then dive into the step-by-step process of designing and implementing them. You'll learn how to:
- Create policies to control which USB devices can be plugged in and used in your environment.
- Block the ability to write to any USB ...
Просмотров: 385

Видео

Deploy Defender for Identity Using the New MDI PowerShell Module
Просмотров 3452 месяца назад
In this video, I am deploying Microsoft Defender for Identity (MDI), one of my favorite security products from Microsoft. MDI is a powerful tool designed to secure on-premises Active Directory environments by detecting and responding to advanced threats. It helps protect user identities and provides insights into suspicious activities, making it an essential component of any robust security str...
Setup a Hyper-V Demo Lab: Server 2022, Domain Controller, DHCP, DNS - Oh My!
Просмотров 5743 месяца назад
Welcome to my channel! In this video, I will walk you through the process of rebuilding my home lab environment using Hyper-V. We'll cover everything from setting up the server, installing Windows Server 2022, configuring the network, setting up a Domain Controller, and configuring DHCP and DNS. Whether you're setting up your own lab or just curious about the process, this video has got you cov...
How to setup Defender for Cloud Apps Session Control
Просмотров 4,6 тыс.7 месяцев назад
Welcome to Doug Does Tech! In this video, Doug takes you step-by-step through setting up session control policies and conditional access in Microsoft Defender for Cloud Apps. If you're looking to enhance security and control access to your organization's cloud applications, this guide is for you. We'll start with a demo of session control, showing you how users on unmanaged devices can access W...
Unlocking Defender for Cloud Apps: Your Swiss Army Knife of Cloud Security
Просмотров 1,5 тыс.8 месяцев назад
Hey everyone, it's Doug from Doug Does Tech! I'm thrilled to introduce a new video series where we explore various Defender technologies by Microsoft. Today, we're kicking off with Defender for Cloud Apps. I like to think of this tool as the Swiss Army Knife of Microsoft security. In this video, I'll delve into its placement within the Microsoft security stack, highlight its top-level features,...
Is MFA Enough? Implementing FIDO Keys with Microsoft 365
Просмотров 2,1 тыс.8 месяцев назад
Traditional MFA may no longer suffice as a robust security measure to safeguard your crucial accounts. Hackers have devised new methods to breach your sign-in process, even with MFA in place. Hence, we require stronger forms of authentication. In this video, I delve into the array of options supported by Microsoft for robust authentication and demonstrate precisely how to implement FIDO Keys. L...
Welcome Back
Просмотров 2898 месяцев назад
After a little break, I'm back and ready to dive into some exciting new content. Get ready for deep dives into Microsoft 365 security, Defender, and Purview. Don't worry, I'll keep it relaxed and easy to understand, even for beginners. Thank you for your patience and support. If you have content or questions you would like me to cover put them into the comments and I will do my best to make a v...
Microsoft 365 Security Basics: Password Protection
Просмотров 1,4 тыс.Год назад
Weak and easily guessable passwords 🗝️ have been a common pain for an organization's security. We all have tried to add password complexity, but users just think of easy ways to bypass it with things like CompanyName1! 😝 Or worse helpdesk uses passwords like the common Winter2023! or Fall2019! 🤢 Well in this video I will show you how you can ban those passwords from use in your environment whet...
Build a website using Azure Static Web Apps and Authenticate with AAD
Просмотров 12 тыс.Год назад
Docusarus, Azure Static Web Apps, Github and Azure Active Directory, Oh MY! In this video, I'll introduce you to some exciting new technologies for building and hosting your own website for documentation. We'll start by creating a local site using Node JS and Docusaurus, followed by deploying it on Azure Static Web Apps. To enable seamless updates, we'll use GitHub's pull feature. Lastly, we'll...
Practical Conditional Access: The Secure Endpoint
Просмотров 970Год назад
In this final video on Practical Conditional Access, we'll be sharing our favorite set of policies designed to ensure secure access to your organization's environment. Specifically, we'll be focusing on the "The Secure Endpoint" policy, which is a customizable template that addresses a variety of scenarios. The main goal of which is to limit access from non-managed devices and ensure that our B...
Create a Conditional Access Policy Design: The Castle Bypass
Просмотров 940Год назад
In the second video in our series on Practical Conditional Access, we are talking about requiring MFA except when you are in a trusted location. This type of policy is common but increases an organization's risk due to the bypass. So in this video, we will walk through a design called "The Castle Bypass" which fixes some of the issues with using a trusted location. In this video, we will be foc...
Create a Conditional Access Policy Design: The Baseline
Просмотров 717Год назад
Creating a set of Conditional Access policies on your own without ever seeing how other orgs do it can be hard. In this series, we will be showcasing different policy designs and providing examples of practical deployments to meet various organizational requirements. These policies are designed to be templates that can be easily customized to fit the unique needs of your organization. In this v...
Microsoft 365 Security Basics: Exchange Online
Просмотров 2,1 тыс.2 года назад
In this video, we'll cover some key points you need to know to secure your Exchange Online environment. We'll discuss topics such as disabling legacy authentication, identifying risky email overrides, enabling audit logging, blocking outbound forwarding, help users quickly identify external emails, and enabling an easy way for your users to report phishing attacks. By the end of this video, you...
Conditional Access 101: Understanding and Implementing This Powerful Security Feature
Просмотров 8302 года назад
In this video, we'll be discussing the importance of MFA and how you can use conditional access to ensure that your organization's accounts are properly secured. Did you know that only 26.64% of Azure AD accounts use MFA? This means that a large number of accounts are not adequately protected against unauthorized access. By implementing conditional access, you can require MFA for certain types ...
Microsoft Purview DLP report Using Power Bi
Просмотров 4,8 тыс.2 года назад
The Built-in reporting engine for Purview DLP is pretty limited. However, with Power Bi, we can create custom reports that really help extend the functionality of our reporting. In this video, I do my best impression of a Power Bi Report designer and show how you can get started with PowerBi reporting. L I N K S Sample Report app.powerbi.com/view?r=eyJrIjoiN2Q3ODRhNDgtMWY1OS00MzQ3LWI4NzAtMTcxZG...
Microsoft 365 Security Basics: SharePoint & One Drive Security
Просмотров 1,6 тыс.2 года назад
Microsoft 365 Security Basics: SharePoint & One Drive Security
Set up Microsoft Exact Data Match - Sensitive Info Type Setup
Просмотров 1,6 тыс.2 года назад
Set up Microsoft Exact Data Match - Sensitive Info Type Setup
Microsoft 365 Security Basics: Separate & Cloud Gapped Admin accounts
Просмотров 6722 года назад
Microsoft 365 Security Basics: Separate & Cloud Gapped Admin accounts
Set up Microsoft Exact Data Match - Hash and Upload your Data
Просмотров 1,9 тыс.2 года назад
Set up Microsoft Exact Data Match - Hash and Upload your Data
Set up Microsoft Exact Data Match - Build your data Schema
Просмотров 1,7 тыс.2 года назад
Set up Microsoft Exact Data Match - Build your data Schema
Set up Microsoft Exact Data Match - Overview
Просмотров 1,9 тыс.2 года назад
Set up Microsoft Exact Data Match - Overview
Microsoft 365 Security Basics: Enterprise Application Admin Consent Workflows
Просмотров 2,5 тыс.2 года назад
Microsoft 365 Security Basics: Enterprise Application Admin Consent Workflows
Microsoft 365 Security Basics: MFA Fraud Alert
Просмотров 2,1 тыс.2 года назад
Microsoft 365 Security Basics: MFA Fraud Alert
Microsoft 365 Security Basics: Secure Azure AD Directory Access
Просмотров 4382 года назад
Microsoft 365 Security Basics: Secure Azure AD Directory Access
Microsoft 365 Security Basics: Deploy MFA (4 Options)
Просмотров 1,6 тыс.2 года назад
Microsoft 365 Security Basics: Deploy MFA (4 Options)
Automatically Apply Sensitive Labels: 3 Options
Просмотров 7 тыс.2 года назад
Automatically Apply Sensitive Labels: 3 Options
Deploy MIP Sensitivity Labels
Просмотров 3,1 тыс.2 года назад
Deploy MIP Sensitivity Labels
MIP - Sensitivity Label Overview
Просмотров 1,6 тыс.2 года назад
MIP - Sensitivity Label Overview
Exchange Online DLP Advanced Options
Просмотров 2,3 тыс.2 года назад
Exchange Online DLP Advanced Options
DLP Next Steps - User Education Mode
Просмотров 1,5 тыс.2 года назад
DLP Next Steps - User Education Mode

Комментарии

  • @hattorihanzo997
    @hattorihanzo997 19 дней назад

    Great Video! Very informative I'm subscribed and can't wait to watch your other vids. I have a question about DNS. In your example, you want your lab to use Google's DNS, but what if I'm building a lab that I don't want to access the internet? Do I have to build my own DNS as far as creating a list of IP = FQDN. Then instead of using 8.8.8.8 i would replace that with the IP of the virtual machine that I'm installing the DNS role on? Thank you for your content and I look forward to your reply.

  • @StringsAndLife
    @StringsAndLife 26 дней назад

    Hi, Thank you. Noticed that in 10.26, mentioned that internal credit card transfers were not picked by Microsoft. So how do we do that?

    • @DougDoesTech
      @DougDoesTech 26 дней назад

      You can change the conditions to look at content shared internally. Or just remove that condition entirely and it will see all credit cards in motion.

  • @patrick__007
    @patrick__007 29 дней назад

    Great video Doug! Have a nice weekend.

  • @kshaeta
    @kshaeta Месяц назад

    Ah yes, MIcrosoft 365. In the magical "Cloud". Want to make a change!? Go ahead! Then wait ten minutes to 24 hours for the change to take effect. Then realize you changed something incorrectly, and have to wait another 10 minutes to 24 hours. Nothing like having your servers 6000km away, to give you that extra bit of wasted man hours in your day.

  • @slaweknos748
    @slaweknos748 Месяц назад

    Absoluty brillant content,

  • @supremecy187
    @supremecy187 Месяц назад

    Thank you very much for the course. This helped me land a role focusing on Purview.

    • @DougDoesTech
      @DougDoesTech Месяц назад

      That is fantastic! Congrats on the new role!

  • @danaknox3395
    @danaknox3395 Месяц назад

    You're the best thing since Matt Sosaman :) I miss Matt's content!!

  • @danaknox3395
    @danaknox3395 Месяц назад

    Please create content for Windows Hello!! Love your videos

  • @danaknox3395
    @danaknox3395 Месяц назад

    Would love if you covered using the managed Edge browser feature! Great job on the content!

  • @proaxiomcyber
    @proaxiomcyber Месяц назад

    Great series Doug! Defender for Cloud Apps is such a versatile tool-looking forward to seeing how you break down its features and setup process!

  • @sandrazimmerli1483
    @sandrazimmerli1483 2 месяца назад

    Where did you get these amazing slides from? I'd love to present them at our company.

    • @DougDoesTech
      @DougDoesTech Месяц назад

      Some I made/modified, some I got from MSFT, shoot me a DM on x and I can share them. @Dougsbaker

  • @zaisaifi7470
    @zaisaifi7470 2 месяца назад

    Excellent video Doug. It just helped me start with Purview.

  • @sielfis9601
    @sielfis9601 2 месяца назад

    Thank you for this video, it really helpful. But i have questioned of Block Downloads, on section Files matching all of the following that have sensitivity labels filter. Is that filter to specific prevent user to block download files that applied those sensitivity labels?

  • @ahmedszone14
    @ahmedszone14 2 месяца назад

    welcome back master!

  • @bolarinwayoade7313
    @bolarinwayoade7313 2 месяца назад

    Hey Doug! This is such a great video.

  • @WovenThorns
    @WovenThorns 2 месяца назад

    I don't know why, but during troubleshooting of custom auth I got stuck and added a whole loginparameters section and forgot about it, and after a week of nothing working, your functional staticwebapp.config.json and specific custom app settings got my app working, thanks!

  • @samv5876
    @samv5876 3 месяца назад

    hey mate, do you have any templates for use on this sort of stuff ? i am using MPARR to ingest data into log analytics then firing out a powerbi template do display the information. Sam

  • @josephngwatezeh1672
    @josephngwatezeh1672 3 месяца назад

    Thanks so much for this vids. My company uses Bitdefender for endpoint security. How can i enable that within Cloudapps settings?

  • @almothanaalhamoud5697
    @almothanaalhamoud5697 3 месяца назад

    thanks this is really so helpful but when I run the auto labeling policy in simulation mode if found the files contain U.S financial information but not any of the Email with U.S financial information in users outlook mail box I have MS E3 license is there a need to have an MS E5 license to have the auto labeling works for the Emails

  • @almothanaalhamoud5697
    @almothanaalhamoud5697 3 месяца назад

    Hi thanks for this Demo it's really useful I have a questions how can I scan data in rest if it contains credit card info or financial information Like old emails already in sent or receive folders in outlook and if I can delete it Do you have Demo for that

    • @DougDoesTech
      @DougDoesTech 3 месяца назад

      Check out the video I have on auto applying sensitivity labels. It will scan the data and tag it.

  • @sistemasfbm1617
    @sistemasfbm1617 3 месяца назад

    excelente video! muchisimas gracias por la ayuda, muy didáctico

  • @icedutah
    @icedutah 4 месяца назад

    Why not require a FIDO2 key for all users? Since any user in the company is a very bad thing. Not just the admins.

  • @nazerbor3i
    @nazerbor3i 4 месяца назад

    This is perfect. I’m looking forward to this. Security with M365

  • @Fideska1
    @Fideska1 4 месяца назад

    Hi, Doug thanks fo your video. Do you know which license i need for option 2 and 3?

    • @DougDoesTech
      @DougDoesTech 4 месяца назад

      All auto labeling options require an advance license. Option 1,2 requires aip plan2 which is in E5. Option 3 requires MDCA which can be standalone or as part of the security bundle.

  • @perezdeandarandyuriel2664
    @perezdeandarandyuriel2664 4 месяца назад

    Hi, thanks for the video. I'm having some trouble understanding DLP in general. What exactly is the role of Microsoft Purview in DLP? From what I understand, the features and capabilities are largely determined by the types of licenses a client has, correct? For example, let's say a client wants to implement DLP in Outlook and SharePoint across their organization. In this case, we need to know which tier they have on Exchange Online and Microsoft 365 licenses. So, where does Purview fit into all of this? I know Microsoft Purview is a governance solution and doesn't have any compute power (I think). Is it simply the platform where these features can be enabled? Do I need an Azure Purview solution to utilize the features available through the licenses? Thanks

    • @DougDoesTech
      @DougDoesTech 4 месяца назад

      It’s confusing because MSFT took and combined multiple product all under the hood of purview. All DLP is now purview, and the old azure purview solution is now also Purview. 🤷🏻‍♂️. Think of the Old azure purview solution as the way to track structured data in your systems. The compliance purview solution, whats included in your m365 license, is all about unstructured data. Ye should are correct that what feature you get is due to your license sku. But almost all but the very basic license gets dlp for exo and spo. Best place to compare features is m365maps.com

  • @SA-hu9sp
    @SA-hu9sp 4 месяца назад

    would this work for apps like Slack or Google Workspace? for example, if I’m trying to restrict a non compliant device (managed via intune) from being able to access corp apps like the ones mentioned + 365 apps, are session policies or access control policies the solution?

    • @DougDoesTech
      @DougDoesTech 4 месяца назад

      Yes it would work for slack and google workspace. For that use case if you are using defender for cloud apps use the access policy. As that will cover the largest scenarios for those.(slack thick client) session policy would only work on web access. However, the best way to handle this is probably a ca policy that requires the device to be compliant. Look up my Secure Endpoint video on CA. May give you some ideas.

  • @Viya_the_cool
    @Viya_the_cool 5 месяцев назад

    Thanks Doug. Please create detailed video on Defender for Cloud Apps

  • @michaelbirt9131
    @michaelbirt9131 5 месяцев назад

    I really really wish this would have worked for me.i have sent me a credit card number 25 times, everyone gets through

  • @simple-security
    @simple-security 5 месяцев назад

    Anything in the works for the new purview portal? How about the purview scanner, on-prem file shares, azure blob storage, azure sql server, and what dlp features will work with all of that. Thanks!

  • @NDSLAB
    @NDSLAB 5 месяцев назад

    Good Stuff! Keep doing all the MS Security stuff.

  • @PazGorbiz
    @PazGorbiz 5 месяцев назад

    Amazing! I have been looking for this guidance for a long time! :)

  • @tarishiverma
    @tarishiverma 5 месяцев назад

    Is the block and encrypt available to all users with E3 license or only for users with E5 license?

    • @DougDoesTech
      @DougDoesTech 5 месяцев назад

      I believe it is available for all E3 users. But there are probably some caveats like customs ome templates are for E5 or application of customs labels are.

  • @kjhgliuguiug
    @kjhgliuguiug 5 месяцев назад

    I haven't been able to get Device Exclusions to work in the CA policy. When trying to exclude Compliant devices, specifically, the Conditional Access App Control policy is applied regardless. As a result, I'm getting stumped trying to allow downloads from Exchange Online on compliant devices. We're not hybrid and it's looking the only solution is going to be with certificates. Have you seen this issue?

    • @DougDoesTech
      @DougDoesTech 5 месяцев назад

      If you are using chome make sure you have the Microsoft sso extension installed. Also make sure you are signed into the machine as an entra if user.(not a local machine user) if none of those work check the dsregcmd status.

  • @atulpathare2775
    @atulpathare2775 5 месяцев назад

    Thanks a bunch for this Video, Really you explain very well

  • @fernandofischer3725
    @fernandofischer3725 5 месяцев назад

    Awesome video, Thanks!! Would definitely love seeing a B2C walkthrough.

  • @rlee431
    @rlee431 6 месяцев назад

    This was incredibly helpful!!

  • @cloudengineersacademy
    @cloudengineersacademy 6 месяцев назад

    Excellent Video, Helped a lot.

  • @aadilkarolia
    @aadilkarolia 6 месяцев назад

    Thank you for this video, it was really helpful. I was struggling to find an end-to-end guide in a single video/article. Appreciate this 🙂

  • @danaknox3395
    @danaknox3395 6 месяцев назад

    I'm not seeing any exceptions in my my policy?

    • @DougDoesTech
      @DougDoesTech 6 месяцев назад

      They changed the portal since making this video. In the rule section create a group then use the “not” toggle. And add all the exceptions you need to that.

    • @danaknox3395
      @danaknox3395 6 месяцев назад

      @@DougDoesTech Thank you! Yes, I added a group and chose NOT for the exceptions. I also added encryption after the approval to enforce the sensitive data to be encrypted. This guide really helped me!!

    • @danaknox3395
      @danaknox3395 6 месяцев назад

      @@DougDoesTech I have another question. If I block sensitive data stored in Office 365. How would I go about marking them as false positives or not sensitive? I'm in the content explorer console and it only calls out "Not a Match". Is there a way to handle those files vs using the override feature?

  • @angelcardenas4266
    @angelcardenas4266 7 месяцев назад

    Me fue de mucha utilidad, gracias! Nuevo suscriptor

  • @ehabgalal9181
    @ehabgalal9181 7 месяцев назад

    Hi, What is the value of adding the admin user in onboarding page ? I don’t have one configured and I was able to onboarding the app

    • @DougDoesTech
      @DougDoesTech 7 месяцев назад

      Many times you don’t need it. But if something doesn’t go right or work you have some of the diagnostic tools you need to fix the app. learn.microsoft.com/en-us/defender-cloud-apps/proxy-deployment-any-app

    • @ehabgalal9181
      @ehabgalal9181 7 месяцев назад

      @@DougDoesTech Thank you for your clarification. One more point please We have custom mobile app that using azure ad for authentication. We have tried to onboard it to MCAS but it seems it didn’t So, is the MCAS support only web not mobile app

    • @DougDoesTech
      @DougDoesTech 7 месяцев назад

      As far as I know session policy’s like blocking download can only be applied to web based sessions. You can use access policy to control access to mobile and desktop apps. But it won’t do the block download type controls.

  • @lasolution365
    @lasolution365 7 месяцев назад

    Thank you very much for these videos, it has been really helpful. You are one of the best instructor I watch. Thanks again.

    • @DougDoesTech
      @DougDoesTech 7 месяцев назад

      Hey so glad it was helpful! and thank you for the compliment!

  • @slartibartfastlunkwill5790
    @slartibartfastlunkwill5790 7 месяцев назад

    Good to see you're back to making videos.

  • @christopherpeterson6004
    @christopherpeterson6004 8 месяцев назад

    Thank you. Very helpful to tell us the evaluated options. I was terrified of activating it and potentially losing access. Would you recommend multiple devices for Domain Admins?

    • @DougDoesTech
      @DougDoesTech 8 месяцев назад

      Yes I have 2 keys for my admin account just in case. But if you are supporting passwordless via Authenticator app it should be fine.

  • @jg-365
    @jg-365 8 месяцев назад

    About time =)

  • @mannykhan7752
    @mannykhan7752 8 месяцев назад

    Amazing video. Just what I was looking for. This helped me in a big way. Thanks.

  • @zol95
    @zol95 8 месяцев назад

    This is exactly what I needed, a straight to the point comparison between all the options. I spent several hours figuring out the difference based on the documentation and random Yt videos, even spend a couple of bucks on Udemy courses which all lack this info. Great content and style subscribed!

  • @zol95
    @zol95 8 месяцев назад

    Just found your channel thanks to your MFA rollout video. I really like the clean straightforward explanation style you use. I will check your previous videos and I'm looking forward to your new videos! Best of luck to your channel!

    • @DougDoesTech
      @DougDoesTech 8 месяцев назад

      Hey so glad you found it helpful!

  • @gvdlaarse
    @gvdlaarse 8 месяцев назад

    Appreciate the demo thank you! Like many I need this data to be real-time, or even be updated once a month. Any idea if an API is available? Or how to update the data source with a script for instance.

  • @tancouver
    @tancouver 8 месяцев назад

    Thanks, Doug. This really helped me. For some reason, the manifest.json linked in the index.html causes unintentional redirects whenever I try to add any type of authentication. I just removed it and that helped me for now. Weird how this doesn't come up in your example, making me think this could be something specific to my organizational tenant.