Reader small image

You're reading from  Microsoft 365 Security and Compliance for Administrators

Product typeBook
Published inMar 2024
PublisherPackt
ISBN-139781837638376
Edition1st Edition
Right arrow
Authors (2):
Sasha Kranjac
Sasha Kranjac
author image
Sasha Kranjac

Sasha Kranjac has been recognized as a Microsoft Regional Director (RD), Microsoft Most Valuable Professional (MVP) in two categories (Azure and Security), he is Microsoft Certified Trainer (MCT), MCT Regional Lead, Certified EC-Council Instructor (CEI), a CompTIA Instructor, speaker at international conferences, user groups, and events, and a book author on cloud security, Microsoft Azure, Microsoft 365, and Windows Server. Sasha is the CEO of Kloudatech, an IT training and consulting company, a Microsoft Partner, an AWS Partner, and a CompTIA Authorized Delivery Partner, specialized in cybersecurity, cloud security architecture and IT training. They deliver high quality vendor and custom IT training and PowerClass Workshops internationally. He is also the CEO of Kranjac Consulting and Training, a consulting, training, and engineering company, specialized in civil engineering and CAD design.
Read more about Sasha Kranjac

Omar Kudović
Omar Kudović
author image
Omar Kudović

Omar Kudovic works as a Senior System Engineer in SYS Company d.o.o. Sarajevo. He has a few professional Microsoft certifications, such as Security Expert: Cybersecurity Architect and Azure Enterprise Expert. For the last 12 years, he has been awarded the Microsoft Most Valuable Professional (MVP) in the Office 365 Apps and Services category. For the past few years, he has been actively working on the application of Microsoft Security and Compliance solutions in government and business organizations. Participated as a lecturer at hundreds of IT conferences in the world. In private life, passionate music collector and audiophile.
Read more about Omar Kudović

View More author details
Right arrow

The Role of Microsoft Entra ID in Microsoft 365 Security

As organizations embrace cloud-based productivity solutions, the need for robust identity and access management (IAM) becomes increasingly important. Microsoft 365, a comprehensive suite of productivity tools, leverages Microsoft Entra ID to provide a secure and efficient IAM framework. Microsoft Entra ID plays a vital role in managing user identities, enforcing access controls, and ensuring the integrity of data within the Microsoft 365 ecosystem.

Microsoft Entra ID is Microsoft’s cloud-based IAM service; or, in short, IAM establishes the basis for the identification of Microsoft’s public cloud services. Microsoft Entra ID encompasses a wide range of objects and related services, and it is a rather complex and wide topic; it deserves a whole book for itself alone. In this chapter, we will focus on the Microsoft Entra ID functionalities and features that are more tightly connected to, or more directly connected...

Technical requirements

Microsoft 365 is a subscription-based service and to try and experience the functionality of each product and service, a user must have an appropriate license. It does not matter whether a user has a trial license, a “regular,” or a paid license – if they have a license assigned, they can enjoy the full scope of the licensed product, its benefits, and functionalities.

Microsoft Entra ID plans and features

Microsoft Entra ID is available in five editions:

  • Microsoft Entra ID Free: This edition provides the basic but still very important IAM functionality to several online services such as Azure, Intune, Power Platform, Dynamics 365, and Microsoft 365.
  • Office 365: This edition is like Microsoft Entra ID Free, but it includes some additional functionalities on top of Microsoft Entra ID Free, such as a customizable sign-in page, self-service sign-in activity and reporting, and features available and included with Office 365 E1, E3, E5, F1, and F3 subscriptions.
  • Microsoft Entra ID P1: This is available for purchase for Azure and Office 365 subscribers and is included with Office E3 and Enterprise Mobility + Security E3 plans.
  • Microsoft Entra ID P2: This is available for purchase for Azure and Office 365 subscribers and is included with Office E5 and Enterprise Mobility + Security E5 plans.
  • Microsoft Entra ID Governance: You can...

Microsoft Entra ID roles and groups

As Microsoft Entra ID is the identity provider for Microsoft services it is used to define roles not only for Microsoft 365 but for other cloud products and services as well. Some services, such as the following, have their specific roles and role assignments stored in their respective, different role-based access control (RBAC) systems:

  • Microsoft Entra ID
  • Microsoft 365 and Microsoft 365 Defender family of services
  • Microsoft Intune
  • Microsoft Exchange
  • Compliance
  • Cost management

What does this mean? From an administrative point of view, it means that you still have a very granular control mechanism available, but to control access to a resource, you have different categories and different service portals where you can perform these administrative tasks, but not a unified portal to do that. It also means that separate RBAC systems will control different resource categories.

The following diagram illustrates the...

Microsoft Entra ID Protection

While Microsoft Entra ID Protection is not categorized as a Microsoft 365 security feature, it is a security capability worthy of your attention and a bit of a deeper understanding.

The way we work and collaborate today has drastically changed compared to just a few years ago. Work has become increasingly digital and online; with the COVID-19 pandemic, enterprises adapted to a new reality by adopting new tools, and cloud computing has become a standard in almost every business and enterprise worldwide. Traditional perimeter-based security has changed, and the new reality is that identity has overtaken the new security perimeter and become the standard. It is imperative that we use solid products and policies that define efficient risk-based access controls.

In the past, internal networks defined security boundaries on closed systems, in on-premises systems, but today’s reality is something completely different. Most workloads and data today...

Summary

In this chapter, we addressed an important part of any tenant’s security – Microsoft Entra ID, its plans, features, and most notably, roles and groups, which are an essential and one of the foundational elements in organizational security posture. Not only are Microsoft 365 groups important, but so are Azure groups since choosing group types wisely and correctly assigning them to the right employees will significantly impact security in an organization.

The next chapter will focus on Microsoft Defender for Office 365, a product that protects email, specifically Exchange Online, against malicious attacks and threats such as malware or phishing messages.

lock icon
The rest of the chapter is locked
You have been reading a chapter from
Microsoft 365 Security and Compliance for Administrators
Published in: Mar 2024Publisher: PacktISBN-13: 9781837638376
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
undefined
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $15.99/month. Cancel anytime

Authors (2)

author image
Sasha Kranjac

Sasha Kranjac has been recognized as a Microsoft Regional Director (RD), Microsoft Most Valuable Professional (MVP) in two categories (Azure and Security), he is Microsoft Certified Trainer (MCT), MCT Regional Lead, Certified EC-Council Instructor (CEI), a CompTIA Instructor, speaker at international conferences, user groups, and events, and a book author on cloud security, Microsoft Azure, Microsoft 365, and Windows Server. Sasha is the CEO of Kloudatech, an IT training and consulting company, a Microsoft Partner, an AWS Partner, and a CompTIA Authorized Delivery Partner, specialized in cybersecurity, cloud security architecture and IT training. They deliver high quality vendor and custom IT training and PowerClass Workshops internationally. He is also the CEO of Kranjac Consulting and Training, a consulting, training, and engineering company, specialized in civil engineering and CAD design.
Read more about Sasha Kranjac

author image
Omar Kudović

Omar Kudovic works as a Senior System Engineer in SYS Company d.o.o. Sarajevo. He has a few professional Microsoft certifications, such as Security Expert: Cybersecurity Architect and Azure Enterprise Expert. For the last 12 years, he has been awarded the Microsoft Most Valuable Professional (MVP) in the Office 365 Apps and Services category. For the past few years, he has been actively working on the application of Microsoft Security and Compliance solutions in government and business organizations. Participated as a lecturer at hundreds of IT conferences in the world. In private life, passionate music collector and audiophile.
Read more about Omar Kudović