Reader small image

You're reading from  Microsoft 365 Certified Fundamentals MS-900 Exam Guide - Third Edition

Product typeBook
Published inNov 2023
PublisherPackt
ISBN-139781837636792
Edition3rd Edition
Right arrow
Authors (3):
Aaron Guilmette
Aaron Guilmette
author image
Aaron Guilmette

Aaron Guilmette is a Principal Architect at Planet Technologies, an award-winning Microsoft Partner focused on the Public Sector. As an author of over a dozen IT books, he specializes in identity, messaging, and automation technologies. Previous to Planet Technologies, Aaron was a Senior Program Manager for Microsoft focusing on Microsoft 365 Customer Experience. When he's not writing books or tools for his customers, Aaron can be found tinkering on cars.
Read more about Aaron Guilmette

Yura Lee
Yura Lee
author image
Yura Lee

Yura Lee is a security program manager at Microsoft, focusing on Microsoft Defender for Cloud. She has years of experience as a Microsoft 365 and Azure consultant and technical specialist in the field.
Read more about Yura Lee

Marcos Zanre
Marcos Zanre
author image
Marcos Zanre

Marcos Zanre is a seasoned IT professional with over a decade of experience specializing in Microsoft 365 and Office 365 services. With a strong background in these platforms, Marcos now applies his expertise as a Solutions Architect at Meta, where he's immersed in the development of cutting-edge virtual and mixed reality solutions with Quest headsets for enterprise customers. Marcos resides in São Paulo, Brazil, where he enjoys life with his wife and child.
Read more about Marcos Zanre

View More author details
Right arrow

Describe the Trust, Privacy, Risk, and Compliance Solutions of Microsoft 365

Most organizations have an assessment process, both from technical and compliance perspectives, that they must go through before authorizing the acquisition or the use of a cloud solution. Some questions that may arise during this process are the following:

  • Is Microsoft 365 safe?
  • Where is my data stored?
  • Who has access to my data?
  • What happens to my data if I decide to leave the service?

IT administrators, compliance administrators, legal representatives, and security officers typically have some or all the responsibility for providing these answers to businesses. It is imperative that everyone has a clear understanding of the principles by which Microsoft operates its data centers.

Furthermore, many organizations (especially in regulated industries) are accountable for maintaining compliance against a broad set of standards and regulations.

In this chapter, you will learn...

Describe compliance features in Microsoft 365

As organizations adopt new services, move through organizational changes such as mergers or divestitures, and conduct routine operations such as employee onboarding and offboarding, they need to make sure that they are managing their risk and compliance appropriately.

Microsoft Purview risk and compliance solutions

Microsoft Purview is an enterprise solution that unifies the Azure Purview and Microsoft 365 compliance products under a single family. Microsoft Purview includes the following broad features:

  • Unified access to compliance and risk solutions
  • Identification, classification, and protection of sensitive data
  • Regulatory compliance tracking and reporting
  • Insider risk management

Compliance features in Microsoft 365

Microsoft 365 includes many features to enable maintaining or improving compliance postures and tracking progress toward particular benchmarks or regulations. Compliance Manager, part of...

Describe how Microsoft supports data residency to ensure regulatory compliance

Many organizations have to comply with both industry regulations and procedures as well as government-mandated security controls surrounding topics such as privacy, record preservation, and data residency. In this section, you’ll learn about Microsoft’s Service Trust Portal where you can review the results of audits conducted against Microsoft data centers as well as whitepapers detailing how Microsoft supports industry and government regulations.

Service Trust Portal

Many organizations need to have some level of evidentiary data that confirms cloud service providers are adhering to the agreed-upon standards for security and data handling. The Microsoft Service Trust Portal (https://servicetrust.microsoft.com) is where all these critical documents are stored.

The core components of the Service Trust Portal include the following:

  • Certifications, regulations, and standards
  • ...

Describe information protection features

Microsoft 365’s information protection and governance features are built on the following principles:

  • Data classification
  • Data protection
  • Data lifecycle management

These principles build on each other to support a holistic approach to data governance.

Data classification

With Microsoft Purview solutions, data classification is accomplished by applying labels (or sensitivity labels) to content objects such as files, email messages, and chats. Labels are metadata that act like virtual sticky notes, providing additional information about the content. Labels themselves have no data protection features, as they are only a classifying mechanism.

Labels can be applied manually by end users in many ways—such as during content creation with Microsoft 365 apps such as Word or Outlook or through the SharePoint Online and OneDrive for Business web apps. Labels can also be applied automatically, using sophisticated...

Describe the capabilities and benefits of Microsoft Priva

Microsoft Priva is a new privacy solution that is part of the Microsoft Purview family of products. Priva solutions help organizations proactively identify and manage privacy risks such as problematic data transfers, data oversharing, and data hoarding across their data estate.

By applying machine learning and technologies such as sensitive information types, Priva helps both organizations and employees track privacy data throughout the organization.

Microsoft Priva contains two core solutions: Priva Privacy Risk Management and Priva Subject Rights Request. Let’s dig into each of those products.

Priva Privacy Risk Management

The risk management component is used to help identify problematic data storage and transfer scenarios. Specifically, it uses policies to identify the following behaviors:

  • Overexposed data
  • Personal data transferred between departments or regions
  • Storage of unused personal...

Describe insider risk management solutions to protect against internal threats

Microsoft 365 contains a set of policy tools to allow organizations to identify risky behaviors and activities as well as to act on those alerts. This feature is known as insider risk management (IRM). IRM is located inside the Microsoft 365 compliance portal at https://compliance.microsoft.com/insiderriskmgmt. IRM combines components from DLP, sensitivity labels, natural language processing (NLP), sentiment analysis, access-control signals, and triggering events to quickly alert organizations to risks such as potential data theft by a departing employee or sensitive information leaks.

Microsoft 365 IRM is designed to help mitigate various internal risks, such as the following:

  • Data theft by a terminated or departing employee
  • Intentional or unintentional leaking of sensitive information
  • Violations of internal corporate policy, such as offensive language, cyber-bullying, harassment, and...

Describe auditing and eDiscovery solutions

Sometimes, organizational operations will require proof that they are complying with certain industry regulations or legal rulings. Or, they may have to open an investigation into actions taken by a threat actor. The auditing and eDiscovery capabilities of Microsoft 365 can be used to fulfill these types of requests.

Audit

Compliance has been defined as being able to prove policy. One of the ways you can prove actions is through logs. In the Microsoft 365 platform, nearly every conceivable action generates some form of logging event—whether it’s signing in to the service, completing an MFA challenge, connecting to a mailbox, modifying permissions to a file stored in SharePoint, adding or removing a group member, resetting an account password, or creating a transport rule in Exchange Online.

These events are collected inside the Microsoft 365 Audit log, shown in Figure 10.13:

Figure 10.13 – Microsoft Purview Audit log

Figure 10.13 &...

Summary

In this chapter, you have learned about several compelling compliance and security features available with Microsoft 365, including the Service Trust Portal, Compliance Manager, and eDiscovery.

As part of the compliance solutions offering, you learned how Compliance Manager can help organizations achieve and maintain compliance with industry-based standards and regulatory controls. The Microsoft Purview compliance solutions also include information protection and data lifecycle management tools such as retention policies and DLP policies, as well as tools for identifying and managing risky behaviors. IRM has features that can be used to help mitigate and manage a variety of risk scenarios, such as data loss from terminated employees or exposure from internal communications. eDiscovery and audit capabilities complete the compliance solution portfolio.

The trust component of Microsoft 365 is focused on the features of the Service Trust Portal. The Service Trust Portal provides...

Exam Readiness Drill - Chapter Review Questions

Benchmark Score: 75%

Apart from a solid understanding of key concepts, being able to think quickly under time pressure is a skill that will help you ace your certification exam. That’s why, working on these skills early on in your learning journey is key.

Chapter review questions are designed to improve your test-taking skills progressively with each chapter you learn and review your understanding of key concepts in the chapter at the same time. You’ll find these at the end of each chapter.

Before You Proceed

You need to unlock these resources before you start using them. Unlocking takes less than 10 minutes, can be done from any device, and needs to be done only once. Head over to the start of Chapter 9, Describe the Threat Protection Solutions of Microsoft 365 in this book for instructions on how to unlock them.

To open the Chapter Review Questions for this chapter, click the following link: https://packt...

lock icon
The rest of the chapter is locked
You have been reading a chapter from
Microsoft 365 Certified Fundamentals MS-900 Exam Guide - Third Edition
Published in: Nov 2023Publisher: PacktISBN-13: 9781837636792
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
undefined
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at €14.99/month. Cancel anytime

Authors (3)

author image
Aaron Guilmette

Aaron Guilmette is a Principal Architect at Planet Technologies, an award-winning Microsoft Partner focused on the Public Sector. As an author of over a dozen IT books, he specializes in identity, messaging, and automation technologies. Previous to Planet Technologies, Aaron was a Senior Program Manager for Microsoft focusing on Microsoft 365 Customer Experience. When he's not writing books or tools for his customers, Aaron can be found tinkering on cars.
Read more about Aaron Guilmette

author image
Yura Lee

Yura Lee is a security program manager at Microsoft, focusing on Microsoft Defender for Cloud. She has years of experience as a Microsoft 365 and Azure consultant and technical specialist in the field.
Read more about Yura Lee

author image
Marcos Zanre

Marcos Zanre is a seasoned IT professional with over a decade of experience specializing in Microsoft 365 and Office 365 services. With a strong background in these platforms, Marcos now applies his expertise as a Solutions Architect at Meta, where he's immersed in the development of cutting-edge virtual and mixed reality solutions with Quest headsets for enterprise customers. Marcos resides in São Paulo, Brazil, where he enjoys life with his wife and child.
Read more about Marcos Zanre