Search This Blog

Saturday, January 27, 2018

Creating DLP Policies In Office 365

Many organizations and large-scale companies are now making their way to Office 365, leveraging various services offered by Microsoft such as SharePoint, Exchange, Project Online, Microsoft Dynamics etc. Definitely, moving to the cloud is a great step for the future and also there are many advantages to it, such as, lower maintenance cost, guaranteed up-time, timely back up of our data by Microsoft and access to services from anywhere.
With all these benefits, there are certain threats associated with our resources/data and we should not consider this as a downside to the cloud technologies. Because, whether we are relaying on on-premise or online, there are chances of certain risks and threats.
However, there are many ways to secure our data. So, today, in this article, we will look at creating DLP policies for SharePoint, Exchange and OneDrive.
DLP stands for Data Loss Prevention. It detects threats from the content and allows us to take certain actions on it when a specific kind of risk is detected from data. Using Microsoft’s “Security and Compliance” center, we can create DLP polices to protect our data. So far, there should be one question and that is - "From what kind of risk are we protecting our data?"
DLP policies are used to fulfill compliance requirements for securing sensitive information, such as that related to the U.S. Health Insurance Act (HIPAA), U.S. Gramm-Leach-Bliley Act (GLBA), or U.S. Patriot Act. More information on this can be found from here.
In today’s article, we will create DLP policies to detect US credit card numbers, bank account numbers, and driver license numbers.
  1. So, login to https://protection.office.com and click on policy under Data loss prevention and then click on “Create a policy”.

    Office 365
  2. In the next dialog, we can select templates for detecting card numbers, bank account numbers, and drivers license numbers. There are many OOTB templates that we can use as per our requirement. If none of the templates fulfill our requirement, then, we can also create custom policies. For this article, we will use OOTB template.
  3. From dropdown, select “United States of America” as location and click on “Privacy”, then click on “U.S. State Breach Notification Laws”. Finally, click Next.

    Office 365
  4. Give name and description of the policy and click Next.
  5. By default, DLP policies applies to Exchange, SharePoint and OneDrive, but, we here we have some flexibility to exclude some SharePoint Sites and OneDrive accounts from DLP policies or else, we can apply DLP policies to few SharePoint sites and OneDrive accounts.
  6. For Exchange, we cannot change DLP policies to apply to specific email accounts.
  7. Select “All locations in Office 365. Includes content in Exchange email and OneDrive and SharePoint documents.” for all locations and select “Let me choose specific locations.” Option to modify locations for SharePoint and OneDrive.
  8. Choose first option and click next.

    Office 365
  9. In the next window, we need to select target audience that we want to monitor, whether it should be outside of our organization or inside of our organization. We can also use Advanced Settings to specify custom actions and rules.
  10. Select “Find content containing this type of sensitive info:”, check box for “Detect when this content is shared:”. This will apply DLP rules when content is shared across/outside of the organization and click Next.

    Office 365
  11. In the next screen, we can select whether we want to send notifications to user when sensitive information is detected with some tips to avoid such scenarios in future.
  12. Leave this page as it is and click Next.
  13. Now, we have the option of whether we want to test it, activate it, or if we want to activate it later.
  14. So, select “Yes, turn it on right away” and click Next.

    Office 365
  15. Finally, on the next screen, click on "Create" to activate our policy.
  16. Policy is now available under “Policy”.

    Office 365

Understanding Office 365 And Directory Synchronization

There will be several occasions where we might come across the need for Active Directory synchronization with Office 365 or Azure Active Directory for enabling Single Sign On (SSO).
There is one thing that we need to keep in mind: Azure Active Directory is not a replacement of the On-Premise Active Directory server, but it provides a way to organizational entities to access cloud resources with remembering additional accounts and passwords.
Now, this scenario can be cumbersome if we are not aware of different aspects of this integration/ synchronization. There are many people out there talking about,
  1. DirSync Tool
  2. Azure AD Connect
Both of the above tools might be confusing to someone regarding which one to choose. So, let’s make it simple, Azure AD Connect is the latest tools used to synchronization while DirSync tool is the older version of the same.
There are Different Options by which we can configure SSO,
  1. Cloud users
  2. Password synchronization
  3. Pass-through Authentication
  4. Federated Identity (ADFS)
Cloud users
  • This the basic option and default option available to use, where all the users are created in cloud (Office 365) as different identities.
Pass-through Authentication
  • With this authentication method we can enable SSO. We can configure Pass-through authentication using latest version of Azure AD Connect.
  • This method uses secure outbound communications so there is no need of DMZ. After configuring this option, Office 365 logons are authenticated with On-Premise Active Directory.
  • The system works by passing the password entered on the Azure AD login page down to the on-premises connector. That connector then validates it against the on-premises domain controllers and returns the results.
Password Synchronization
  • With passwords synchronization, hash store of password is stored in Azure AD. We can use passwords synchronization in conjunction with Pass-through Authentication method.
  • In Pass-through Authentication method, passwords are not stored anywhere in the cloud, users are authenticated through On-Premise active directory and if local AD is down then, users may face some issues with authentication.
  • But, if we are enabling Password Synchronization with Pass-through Authentication, passwords hashes are stored in Azure AD. So, if in case, local AD is down, then also, user can login to portal as Azure AD has password hashes for all user. These passwords hashes are secure and safe in Azure AD.
Federated Identity (ADFS)
  • Active Directory Federation Service offers best overall SSO experience to users.
  • For configuring ADFS, we require additional servers for ADFS service in out on-premise network. ADFS deployment would be a two-server farm at separate sites. Two additional servers are needed in a DMZ to securely publish ADFS to the internet.
  • In ADFS, whenever user attempts to login, they are redirected to ADFS server to complete their authentication process.
  • Using ADFS, we can also restrict access Microsoft services based on IP address. With ADFS, we also have capabilities of enabling multi factor authentication.

    Overview Of SharePoint Communication Site

    Site template is one of the main components that defines the structure for managing content within SharePoint. SharePoint keeps on updating the existing site templates and introducing the new templates to the business needs for those times. Now, the web technology is a lot improved and SharePoint is also catching up with introducing new features to it. Communication Site is one of these new site template features to the SharePoint online to support the latest UI trend.
    What is SharePoint Communication Site?
    A place where we can view or share the data in a rich UI experience across different devices with minimal efforts from the team. It has modern UI features with highly customizable OOT web parts. The page designs enable the flexible responsive designs.
    Publish dynamic, beautiful content to people in your organization to keep them informed and engaged on topics, events, or projects” – Communication template description.
    Team Site vs Communication Site
    Team site is used to share the information among the users of a team and limited to the team; whereas Communication site shares the information to a broader audience and keeps them informed about news, events, and topics within the organization.
    Team SiteCommunication Site
    Modern UIModern UI
    Subsite creation availableSubsite creation unavailable
    Web part page, wiki page, site page and Link content types are available by default in Pages librarySite page, Link content types are available by default in Pages library
    Left navigation is available on site pageThere is no left navigation present in Site Page
    Web Template : 64Web Template: 68
    Privacy Settings & member details will be asked during site creationThere is no security details will be asked during site creation
    One design available3 sets of designs available
    Communication site Assets
    Site Designs
    There are three different designs available within the Communication site. For now, you must choose any one of the designs to create a communication site.
    Topics
      Topic site design template helps to share the information such as news, events, and other content.

      SharePoint

      Home page has,
      • Hero web part
      • New web part
      • Events web part
      • Highlighted Content web part
      • Quick Links web part
      • People web part
      Available Lists & Libraries include - 
      • Documents
      • Form templates
      • Style Library
      • Events
      • Site Pages
      Option to select Page Template is available on creating new page from home page.
      Showcase
        Showcase site design template uses the photos or images to showcase a product, team, or event.

        SharePoint

        Home page has,
        • Hero web part
        • Image Gallery web part
        Available Lists & Libraries include - 
        • Documents
        • Form templates
        • Style Library
        • Events
        • Site Pages
        Option to select Page Template is also available on creating new page from home page.
        Blank
          Blank site design template is used to create our own design.

          SharePoint

          Home page has plain page and you can add any web part available for modern UI.
          Available Lists & Libraries include - 
          • Documents
          • Form templates
          • Site Assets
          • Style Library
          • Events
          • Site Pages
          Page Templates
          Site Page has three different built-in page templates for creating a new modern page.

          SharePoint
          Page Templates
          1. Multiple Columns – Creates a new page with a single section with two columns. And each column contains text web part and Quick links respectively.
          2. Single Column – Creates a new page with a single section with single column.
          3. Blank – Creates a new page without any section. After the creation, we can add sections based on our requirement.
          Section Layouts
          Each page can have multiple sections and each section can have up to three columns. Within each column, we can add multiple web parts vertically. Section is equivalent to a web part manager and column in a section is equivalent to a web part zone.

          SharePoint

          Section Layouts
          Web parts
          Office 365 team has rolled out some of the web parts to the site pages with rich and responsive UI.

          SharePoint
          Web parts
          How to create Communication Site
          So far, we have learned the basics and overview of communication sites and its inner pieces. Now, we will see how to create a new communication site.
          Note
          At present (July’17), it is available only for first release tenant users.
          • Click on “App Launcher” and then select “SharePoint” button, that redirects to the SharePoint Modern home page
            Or
            Directly type your SharePoint Tenant root site with sharepoint.aspx as shown below in the address bar,

            https://mytenant.sharepoint.com/_layoyts/15/sharepoint.aspx

            SharePoint
            SharePoint from App Launcher
          • From the SharePoint page, click “Create Site” button. This opens the Panel with two options - Team site and Communication Site.

            SharePoint
            Create Site
          • Select Communication site in the panel. It asks us to select the Site Design and Title along with the URL and description.

            SharePoint
            Modern Site Templates
          • Select the Site Design and enter Site name, address (auto generated), and description. Then, click "Finish" button to create a new communication site.

            SharePoint
            Create Communication Site
            By using this new template, we can easily create Single Page Applications. For now, we can’t have this site as a subsite, and customization of components is also limited for the developers. In coming days, we can expect more new features related to this communication site template.

            SharePoint Online / Office 365 - Exporting All the Terms from Particular TermSet In .CSV File Using CSOM And Console Application

            There are multiple approaches to exporting the terms from given TermSet, such as - using PowerShell + CSOM or using CSOM in console application. In one of my previous articles, “SharePoint Online / Office 365 : Exporting All The Terms From Particular TermSet In .CSV File Using CSOM & PowerShell”, I explained how to export the TermSet using CSOM + PowerShell.
            In this article, I’ll go through step by step procedure for exporting TermSet using CSOM in console application.
            There is no big difference in both the approaches but if we want to make it more configurable (like configuration in .config file, for ex. – TermStore name or specific TermSet name etc. ), then Console Application approach is preferable.
            I have my trial Office 365 account and Term Store Manager page looks like the below images, where three terms (IT, HR and Finance) are created in OOB termset “Department” under “People” group,

            TermStore
            Figure 1 - My TermStore – Created three different terms – IT, HR and Finance
            So, in our console application, we will export the above three terms created under “Department” termset in “People” group, in default Term Store (since there is only one Term Store).
            Step 1
            Get the required details from config file (App.config) and connect to Office 365.
            In last article “Office 365 / SharePoint Online - Connecting Office 365 / SharePoint Online Site Using CSOM (Client Object Model)” I have given detailed steps to connect Office 365 through CSOM and Console Application. Please have a look once. Following is the code snippet for this step.
            1.        #region Site Details - Read the details from config file  
            2.             string siteURL = ConfigurationManager.AppSettings["siteURL"];  
            3.             string userName = ConfigurationManager.AppSettings["userName"];  
            4.             string password = ConfigurationManager.AppSettings["password"];  
            5.             //Path where we need to create the .CSV file  
            6.             string csvFilePath = ConfigurationManager.AppSettings["csvfilepath"];  
            7.        #endregion  
            8.  
            9.     #region Connect To O365  
            10.   
            11.             //Create the client context object and set the credentials  
            12. //Create the client context object and set the credentials  
            13.     ClientContext clientContext = new ClientContext(siteURL);  
            14.        SecureString securePassword = new SecureString();  
            15.   
            16. foreach (char c in password.ToCharArray())       
            17.     securePassword.AppendChar(c);  
            18.   
            19.                      clientContext.Credentials = new     
            20.                      SharePointOnlineCredentials(userName, securePassword);  
            21.         #endregion  
            Step 3
            Get the Terms from respective TermSet : To read the Terms from respective TermSet, we need to get the reference for the following objects. 
            1. TaxonomySession 
              This object is the initial point for all taxonomy operations. Get reference to the TaxonomySessionobject as -
              1. TaxonomySession taxonomysession = TaxonomySession.GetTaxonomySession(clientContext);  
            1. TermStoreGet reference to default TermStore. Once we have TaxonomySession class, we will get the default term store as -
              1. TermStore termStore = taxonomysession.GetDefaultSiteCollectionTermStore();  
            1. TermGroupCollectionWe will fetch all the groups (TermGroupCollection) from TermStore object as -
              1. TermGroupCollection groupCollection = termStore.Groups;  
              2. clientContext.Load(groupCollection);  
              3. clientContext.ExecuteQuery();  
            1. TermGroupThen, get the reference to the TermGroup object in which our TermSet is created. Here, we are fetching the terms from the term set which is created under group “People” as -
              1. TermGroup termGroup = groupCollection.GetByName("People");  
              2. clientContext.Load(termGroup);  
              3. clientContext.ExecuteQuery();  
            1. TermSetFrom termGroup object we will read our “Department” term set as -
              1. TermSet termSet = termGroup.TermSets.GetByName("Department");  
              2. clientContext.Load(termSet);  
              3. clientContext.ExecuteQuery();  
            1. TermCollectionWe have our term set ready, get all terms in it using TermCollection object as -
              1. TermCollection departmentTerms = termSet.Terms;  
              2.               clientContext.Load(departmentTerms);  
              3.        clientContext.ExecuteQuery();  
            Step 4
            Write terms to .CSV file : As now we have all “Department” terms, we will write them to .CSV file. To write into .CSV file, we need array of string and we will use Syste.IO.File object as -
            1. ArrayList termsArrayList = new ArrayList(departmentTerms.Count);  
            2.   
            3.               foreach (Term term in departmentTerms)  
            4.               {  
            5.                  termsArrayList.Add(term.Name);  
            6.               }  
            7.   
            8.         //Writing to .CSV file as path specified in .config file.  
            9. System.IO.File.WriteAllLines(csvFilePath,           (string[])termsArrayList.ToArray(typeof(string)));  
            Complete Code
            1. using Microsoft.SharePoint.Client;  
            2. using Microsoft.SharePoint.Client.Taxonomy;  
            3. using System;  
            4. using System.Collections;  
            5. using System.Configuration;  
            6. using System.Security;  
            7.   
            8. namespace CSOM_ExportTermSets  
            9. {  
            10.     class Program  
            11.     {  
            12.         static void Main(string[] args)  
            13.         {  
            14.             #region Site Details - Read the details from config file  
            15.             string siteURL = ConfigurationManager.AppSettings["siteURL"];  
            16.             string userName = ConfigurationManager.AppSettings["userName"];  
            17.             string password = ConfigurationManager.AppSettings["password"];  
            18.             //Path where we need to create the .CSV file  
            19.             string csvFilePath = ConfigurationManager.AppSettings["csvfilepath"];  
            20.             #endregion  
            21.  
            22.             #region ConnectTo O365  
            23.   
            24.             //Create the client context object and set the credentials  
            25.             ClientContext clientContext = new ClientContext(siteURL);  
            26.             SecureString securePassword = new SecureString();  
            27.   
            28.             foreach (char c in password.ToCharArray()) securePassword.AppendChar(c);  
            29.   
            30. clientContext.Credentials = new SharePointOnlineCredentials(userName, securePassword);  
            31.  
            32.             #endregion  
            33.  
            34.             #region Get the Terms  
            35.   
            36. TaxonomySession taxonomysession = TaxonomySession.GetTaxonomySession(clientContext);  
            37.        
            38.             if (taxonomysession != null)  
            39.             {  
            40.  TermStore termStore = taxonomysession.GetDefaultSiteCollectionTermStore();  
            41.                 if (termStore != null)  
            42.                 {  
            43.                     TermGroupCollection groupCollection = termStore.Groups;  
            44.                     clientContext.Load(groupCollection);  
            45.                     clientContext.ExecuteQuery();  
            46.   
            47.                     TermGroup termGroup = groupCollection.GetByName("People");  
            48.                     TermSet termSet = termGroup.TermSets.GetByName("Department");  
            49.   
            50.                     clientContext.Load(termGroup);  
            51.                     clientContext.Load(termSet);  
            52.                     clientContext.ExecuteQuery();  
            53.   
            54.                     TermCollection departmentTerms = termSet.Terms;  
            55.                     clientContext.Load(departmentTerms);  
            56.                     clientContext.ExecuteQuery();  
            57.   
            58.                     ArrayList termsArrayList = new ArrayList(departmentTerms.Count);  
            59.   
            60.                     foreach (Term term in departmentTerms)  
            61.                     {  
            62.                         termsArrayList.Add(term.Name);  
            63.                     }  
            64.   
            65.                     //Writting to .CSV file as path specified in .config file.  
            66. System.IO.File.WriteAllLines(csvFilePath, (string[])termsArrayList.ToArray(typeof(string)));  
            67.   
            68. Console.WriteLine("Terms are written in .CSV file. Please hit the any key to exit the console");  
            69.                     Console.ReadKey();  
            70.                 }//if (termStore != null)  
            71.             }//if (taxonomysession != null)  
            72.             #endregion  
            73.         }//main  
            74.     }//cs  
            75. }//ns