WEBVTT

00:00:11.139 --> 00:00:13.199
Hello, and welcome to another episode of the

00:00:13.199 --> 00:00:15.380
Everyday Defender podcast. I'm your host, Chris

00:00:15.380 --> 00:00:17.980
Goosen. It's episode nine, and I'm joined as

00:00:17.980 --> 00:00:19.980
always by my friend from the Netherlands, Kos.

00:00:20.199 --> 00:00:22.739
How are you, sir? Hey, Chris. How are you doing?

00:00:22.859 --> 00:00:26.039
Howdy. We're approaching the end of the season,

00:00:26.120 --> 00:00:28.899
I think already, right? Yeah, well, we're getting

00:00:28.899 --> 00:00:32.079
there. And, you know, it's my most exciting time

00:00:32.079 --> 00:00:34.560
of the month is when I get to, when I know that

00:00:34.560 --> 00:00:36.609
I'm... going to be recording with you in the

00:00:36.609 --> 00:00:38.310
afternoon and you know we're going through the

00:00:38.310 --> 00:00:40.850
the prep and all that type of stuff it's a super

00:00:40.850 --> 00:00:43.369
exciting time so um you know really really excited

00:00:43.369 --> 00:00:45.390
to be back again and uh and talking to you today

00:00:46.060 --> 00:00:49.039
Also, I should say congratulations. MVP renewals

00:00:49.039 --> 00:00:51.520
have just happened a few weeks ago and congrats

00:00:51.520 --> 00:00:54.619
for your renewal and continuing to be here. I

00:00:54.619 --> 00:00:56.280
think it's obviously very well deserved given

00:00:56.280 --> 00:00:59.280
all the great work you do in the community and

00:00:59.280 --> 00:01:03.460
elsewhere. Thanks Chris, appreciate it. And to

00:01:03.460 --> 00:01:05.799
you as well, you finally got into the Dutch category,

00:01:06.000 --> 00:01:09.120
right? Finally got into the Dutch category, security

00:01:09.120 --> 00:01:11.739
MVP. Yes, I'm very, very happy about that. It's

00:01:11.739 --> 00:01:13.980
been a lot of hard work over the last few years

00:01:13.980 --> 00:01:16.780
to get there. Unfortunately, the Dutch benefit

00:01:16.780 --> 00:01:19.659
hasn't kicked in just yet. But I hope any day

00:01:19.659 --> 00:01:21.840
now I'll wake up and be fluent. People shouldn't

00:01:21.840 --> 00:01:24.700
expect you handing out stroopwafels at MVP Summit

00:01:24.700 --> 00:01:28.260
next year. No, but I will consume stroopwafels

00:01:28.260 --> 00:01:31.260
as many as possible. I'll help you out on that.

00:01:31.340 --> 00:01:35.840
I'll get you covered. Before we get too sidetracked.

00:01:35.959 --> 00:01:39.379
That's right. I always have tin tams at Summit.

00:01:40.680 --> 00:01:44.310
Before we get carried away. today's episode.

00:01:44.829 --> 00:01:47.390
Let's see what we've got. So I'm going to continue

00:01:47.390 --> 00:01:50.689
talking a little bit about EntraSuite and some

00:01:50.689 --> 00:01:53.390
components of EntraSuite, specifically the global

00:01:53.390 --> 00:01:56.290
secure access component. There's a lot to unpack

00:01:56.290 --> 00:01:58.349
there. And so I'm excited to kind of dig into

00:01:58.349 --> 00:02:00.709
that one a little deeper. And then, Kost, what

00:02:00.709 --> 00:02:03.609
have you got for us? Yeah, I was working on a

00:02:03.609 --> 00:02:07.750
project recently for a customer where I got my

00:02:07.750 --> 00:02:11.830
hands on Defender for External Attack Service

00:02:11.830 --> 00:02:16.280
Management, so EASM. And I know people at Microsoft

00:02:16.280 --> 00:02:20.699
call it MDEASM, like Microsoft Defender for External

00:02:20.699 --> 00:02:22.860
Attack Service Management. It's quite a mouthful.

00:02:22.879 --> 00:02:25.840
It's a mouthful. Say that 10 times fast, right?

00:02:26.620 --> 00:02:29.379
But it was really interesting. I knew about the

00:02:29.379 --> 00:02:32.860
product from a more theoretical standpoint. It

00:02:32.860 --> 00:02:35.300
was great to get my hands on. And, well, obviously,

00:02:35.379 --> 00:02:38.120
that's why I thought it was a nice topic for

00:02:38.120 --> 00:02:40.340
today's episode, because I have some tips, some

00:02:40.340 --> 00:02:42.099
practical tips for the people who are listening.

00:02:42.560 --> 00:02:45.740
And I think... people should really look into

00:02:45.740 --> 00:02:48.159
it. Yeah, awesome. Well, I can't wait to hear

00:02:48.159 --> 00:02:49.939
all about that. It's something I'm not super

00:02:49.939 --> 00:02:53.259
familiar with, so we'll get there. But if we

00:02:53.259 --> 00:02:55.939
continue our sort of IntraSuite journey from

00:02:55.939 --> 00:02:59.580
last episode, sort of two of the components or

00:02:59.580 --> 00:03:01.099
two of the things that we talked about as part

00:03:01.099 --> 00:03:06.460
of IntraSuite was what we know as Microsoft Intra

00:03:06.460 --> 00:03:08.900
Private Access. and another component, which

00:03:08.900 --> 00:03:10.979
is Microsoft Intra Internet Access. And together,

00:03:11.120 --> 00:03:13.460
those things are often referred to as GSA or

00:03:13.460 --> 00:03:15.800
Global Secure Access, which is really the sort

00:03:15.800 --> 00:03:17.960
of Microsoft Zero Trust Network Access stuff,

00:03:18.180 --> 00:03:23.180
right? So, you know, I love these products. I

00:03:23.180 --> 00:03:25.400
think these things are there's a lot of potential

00:03:25.400 --> 00:03:28.400
here. And I wanted to kind of dig into them just

00:03:28.400 --> 00:03:29.979
a little bit more to get folks sort of across

00:03:29.979 --> 00:03:32.900
sort of the nuances of it, right? There are some

00:03:32.900 --> 00:03:35.319
things, some little nuances here. And again,

00:03:35.439 --> 00:03:37.780
it's going to be one of those things where If

00:03:37.780 --> 00:03:41.580
you're a large, complex organization, chances

00:03:41.580 --> 00:03:43.259
are you're probably going to look at something

00:03:43.259 --> 00:03:46.259
like Zscaler for your internet access stuff anyway,

00:03:46.379 --> 00:03:48.580
and this isn't going to be for you. But I do

00:03:48.580 --> 00:03:50.240
think that there's a lot of potential here for

00:03:50.240 --> 00:03:52.759
some of the smaller orgs who are dipping their

00:03:52.759 --> 00:03:54.879
toe in the water there and wanting to start securing

00:03:54.879 --> 00:03:59.819
some of those internet access scenarios. hybrid

00:03:59.819 --> 00:04:02.240
work from home type fleets where you've got a

00:04:02.240 --> 00:04:04.740
lot of assets that are all over the place i think

00:04:04.740 --> 00:04:06.960
this is a really good solution for you know securing

00:04:06.960 --> 00:04:09.719
inbound and outbound right so um on the one hand

00:04:09.719 --> 00:04:12.719
we're replacing vpns um you know for that traditional

00:04:12.719 --> 00:04:15.340
connectivity back on prem and then on the other

00:04:15.340 --> 00:04:17.579
hand we're protecting our sort of internet access

00:04:17.579 --> 00:04:21.939
on on connections and networks that we don't

00:04:21.939 --> 00:04:23.839
own, right? So if you think about grandma's house

00:04:23.839 --> 00:04:26.600
where you've just got grandma's Wi -Fi and you're

00:04:26.600 --> 00:04:29.680
using your corporate asset connecting into M365

00:04:29.680 --> 00:04:33.160
or any other SaaS application, being able to

00:04:33.160 --> 00:04:35.920
apply protection to that connection and also

00:04:35.920 --> 00:04:37.839
maybe filter and block things that you don't

00:04:37.839 --> 00:04:40.620
want your folks using your corporate assets to

00:04:40.620 --> 00:04:43.180
access, right? Think about gambling and stuff

00:04:43.180 --> 00:04:46.980
like that. So, Chris, before you continue, I'm

00:04:46.980 --> 00:04:50.699
a big noob on this topic. I hear the term SSE,

00:04:50.899 --> 00:04:54.040
Secure Service Edge, coming along quite a few

00:04:54.040 --> 00:04:57.000
times as well. Is that the old name for the product?

00:04:57.459 --> 00:05:01.220
Yeah, that is interesting. It is often referred

00:05:01.220 --> 00:05:05.000
to as SSE. And I actually think that when they

00:05:05.000 --> 00:05:07.920
first launched private access and internet access,

00:05:08.019 --> 00:05:11.579
they referred to it as SSE. I think SSE is the

00:05:11.579 --> 00:05:14.540
capability. The Secure Service Edge is their

00:05:14.540 --> 00:05:18.439
capability. And GSA is really the product sort

00:05:18.439 --> 00:05:20.600
of category or name of the product. That's at

00:05:20.600 --> 00:05:24.360
least how I understand it. That's a good question,

00:05:24.420 --> 00:05:26.000
though, because I think there's a lot of terminology

00:05:26.000 --> 00:05:28.079
floating around everywhere and different customers.

00:05:29.160 --> 00:05:32.800
That's right. That's right. So a couple of things,

00:05:32.839 --> 00:05:35.019
I guess, from a requirements perspective for

00:05:35.019 --> 00:05:38.430
GSA. We talked about... Licensing, licensing

00:05:38.430 --> 00:05:41.610
is always a thing, right? And so there's some

00:05:41.610 --> 00:05:43.970
nuances here. So number one, you're going to

00:05:43.970 --> 00:05:48.449
need an EntraID P1 to begin with, right? And

00:05:48.449 --> 00:05:52.089
then once you have the P1, you could either get

00:05:52.089 --> 00:05:54.129
just the private or the internet access license

00:05:54.129 --> 00:05:57.269
as an add -on, or you can get the EntraSuite

00:05:57.269 --> 00:05:58.850
license, which includes all those other things

00:05:58.850 --> 00:06:02.089
that we talked about in the last episode as well.

00:06:03.540 --> 00:06:05.339
Depending on which way you want to go, I think

00:06:05.339 --> 00:06:07.339
there's a lot of value in getting the intra -suite

00:06:07.339 --> 00:06:09.199
licensing, but you're going to need the licensing.

00:06:09.339 --> 00:06:10.920
Now, there is one component that doesn't require

00:06:10.920 --> 00:06:12.720
licensing, and we'll get to that in just a second.

00:06:12.800 --> 00:06:14.879
But that's the first thing to know. Secondly,

00:06:15.199 --> 00:06:19.019
you're going to need the GSA client installed

00:06:19.019 --> 00:06:23.430
on your clients for this, right? One of the things

00:06:23.430 --> 00:06:25.810
that I found when I was sort of tinkering and

00:06:25.810 --> 00:06:27.529
messing around with this a little bit more deeply

00:06:27.529 --> 00:06:30.250
was that obviously the GSA client works just

00:06:30.250 --> 00:06:33.089
great if you're using Windows or a Mac or if

00:06:33.089 --> 00:06:35.250
you have iOS and Android, but there's no Linux

00:06:35.250 --> 00:06:37.009
support. So don't think you're going to get,

00:06:37.189 --> 00:06:40.629
you know, you're going to be running your Debian

00:06:40.629 --> 00:06:42.949
or your Ubuntu Linux and installing the GSA client.

00:06:43.050 --> 00:06:45.589
That doesn't exist just at the moment. So I'm

00:06:45.589 --> 00:06:48.250
not sure what the plans are for that. And I think,

00:06:48.269 --> 00:06:50.230
you know, Kosa and I were talking earlier about

00:06:50.230 --> 00:06:53.699
this. For most organizations, probably not a

00:06:53.699 --> 00:06:55.860
big deal. I think it's only the really hardcore

00:06:55.860 --> 00:06:57.560
geeky folks that are probably going to miss this,

00:06:57.639 --> 00:07:01.100
but something to be aware of, I guess, as well.

00:07:02.040 --> 00:07:04.480
But the good thing, at least with private access,

00:07:04.579 --> 00:07:07.680
you can at least access into your Linux servers

00:07:07.680 --> 00:07:12.399
over the secure server, right? Well, if you have

00:07:12.399 --> 00:07:17.860
a device... inside your network that has the

00:07:17.860 --> 00:07:20.660
private connector installed, then yes, you can

00:07:20.660 --> 00:07:22.939
access those services. But that private connector,

00:07:23.040 --> 00:07:25.060
and this is the second thing, the private connector

00:07:25.060 --> 00:07:28.040
that you have to install will also only run on

00:07:28.040 --> 00:07:31.100
Windows. So essentially, it's an outbound only.

00:07:31.180 --> 00:07:35.060
So if you think about segmenting your applications.

00:07:36.540 --> 00:07:39.300
and your services you instead of punching holes

00:07:39.300 --> 00:07:40.779
in your firewall for everything that you want

00:07:40.779 --> 00:07:42.920
to access you have these connectors that you

00:07:42.920 --> 00:07:45.860
install that talk outbound to to the the sse

00:07:45.860 --> 00:07:48.279
once those connections are then made the gsa

00:07:48.279 --> 00:07:50.699
client handles all the routing smarts and and

00:07:50.699 --> 00:07:52.819
the policies that you set up uh to be able to

00:07:52.819 --> 00:07:55.240
access those applications so you can make that

00:07:55.240 --> 00:07:56.800
work but you can't you're not going to be able

00:07:56.800 --> 00:07:59.060
to install the the private network connector

00:07:59.930 --> 00:08:02.889
on a Linux machine or something that isn't Windows

00:08:02.889 --> 00:08:05.310
Server. So that's the other thing to be very

00:08:05.310 --> 00:08:08.410
much aware of there. Another thing to think about

00:08:08.410 --> 00:08:11.310
is that your devices that you're going to use

00:08:11.310 --> 00:08:15.250
for this, they need to be known in some way,

00:08:15.310 --> 00:08:16.930
right? So they need to be either intra joined

00:08:16.930 --> 00:08:20.870
or hybrid joined or sort of in tune managed or

00:08:20.870 --> 00:08:23.410
something like that. And that's for conditional

00:08:23.410 --> 00:08:25.529
policy, conditional access policy enforcement.

00:08:25.949 --> 00:08:29.800
So this kind of limits, you know, those pure

00:08:29.800 --> 00:08:32.080
BYOD environments where you have these unknown

00:08:32.080 --> 00:08:36.000
clients. And we're going to talk a little bit

00:08:36.000 --> 00:08:38.919
later about something called Entra App Proxy,

00:08:39.019 --> 00:08:42.639
which, you know, is something is very similar.

00:08:42.720 --> 00:08:44.779
And if you've been around long enough, you probably

00:08:44.779 --> 00:08:48.360
have used or heard of Entra App Proxy. And that's

00:08:48.360 --> 00:08:51.269
where sort of App Proxy. This builds on AppProxy,

00:08:51.370 --> 00:08:53.309
but there are still some really good scenarios

00:08:53.309 --> 00:08:56.250
where AppProxy is probably the better tool. And

00:08:56.250 --> 00:09:00.629
I do want to dig into that a little bit as we

00:09:00.629 --> 00:09:05.350
talk through this. So when we talk about GSA,

00:09:05.509 --> 00:09:08.299
we have this sort of concept of... forwarding

00:09:08.299 --> 00:09:10.379
profiles or traffic forwarding profiles and we're

00:09:10.379 --> 00:09:13.460
three profiles right um and this is a really

00:09:13.460 --> 00:09:15.860
nice sort of interesting thing to to to kind

00:09:15.860 --> 00:09:18.840
of be aware of so um the first one is your microsoft

00:09:18.840 --> 00:09:21.340
traffic profile and the microsoft traffic profile

00:09:21.340 --> 00:09:25.139
is is um available to you even if you don't have

00:09:25.139 --> 00:09:29.289
licenses for um private or internet access. You

00:09:29.289 --> 00:09:32.330
don't need a specific or an additional license

00:09:32.330 --> 00:09:35.029
for it. So as long as you have either business

00:09:35.029 --> 00:09:39.830
premium or you have E3 or E5, the Microsoft traffic

00:09:39.830 --> 00:09:42.789
profile is actually included in those. And really

00:09:42.789 --> 00:09:44.870
what that does is it intercepts the traffic that

00:09:44.870 --> 00:09:48.210
is specifically for Microsoft services, right?

00:09:48.830 --> 00:09:50.929
And I really like this because I think there's

00:09:50.929 --> 00:09:53.549
some benefit here. So for one, one of the things

00:09:53.549 --> 00:09:55.149
you can be doing is you can be applying those

00:09:55.149 --> 00:09:57.570
conditional access policies to... folks that

00:09:57.570 --> 00:09:59.990
are actually accessing your, those Microsoft

00:09:59.990 --> 00:10:02.389
services from your, your, your corporate devices.

00:10:03.090 --> 00:10:05.190
But more importantly, what you can do is you

00:10:05.190 --> 00:10:07.330
can, you can combine this with something called

00:10:07.330 --> 00:10:10.389
UTR, which is universal tenant restrictions to

00:10:10.389 --> 00:10:12.690
actually start locking down the types of tenants

00:10:12.690 --> 00:10:15.389
or the, the tenants that your, your clients can

00:10:15.389 --> 00:10:18.289
connect to. And if you think about one of the

00:10:18.289 --> 00:10:22.250
gaps in, it has always been, you know, from an,

00:10:22.269 --> 00:10:25.129
from an X fold perspective is if someone were

00:10:25.129 --> 00:10:29.500
to, were to, uh sort of compromise a device in

00:10:29.500 --> 00:10:32.679
your fleet on your network right and your firewall

00:10:32.679 --> 00:10:36.100
allows access to startup microsoft .com or startupoffice

00:10:36.100 --> 00:10:38.659
.com or one of those things well an easy way

00:10:38.659 --> 00:10:41.259
for them to exploit data is to just go to another

00:10:41.259 --> 00:10:43.779
tenant right log into a different tenant it's

00:10:43.779 --> 00:10:45.740
still microsoft's environment which your firewall

00:10:45.740 --> 00:10:48.320
which doesn't really you know isn't really inspecting

00:10:48.320 --> 00:10:50.879
the stuff is is allowing well when you when you

00:10:50.879 --> 00:10:54.500
combine this with um utr you can now start locking

00:10:54.500 --> 00:10:59.120
down what tenants or tenant your clients are

00:10:59.120 --> 00:11:00.659
actually allowed to connect to. So I think there's

00:11:00.659 --> 00:11:03.080
some real power there, especially if you have

00:11:03.080 --> 00:11:05.340
some really sort of lockdown environments where

00:11:05.340 --> 00:11:08.820
you maybe have, I don't know, a dev tenant and

00:11:08.820 --> 00:11:11.840
a production tenant, and you only want those

00:11:11.840 --> 00:11:14.659
two tenants to be accessed from your devices,

00:11:14.720 --> 00:11:17.220
no other tenants. So some really powerful stuff,

00:11:17.279 --> 00:11:20.399
and that's the Microsoft Traffic Profile. It's

00:11:20.399 --> 00:11:22.240
part of the product, and there's no additional

00:11:22.240 --> 00:11:24.669
licensing, so you can play with this. and the

00:11:24.669 --> 00:11:27.370
GSA client sort of now without additional licensing.

00:11:27.950 --> 00:11:30.870
The next profile to talk about is, I guess, is

00:11:30.870 --> 00:11:35.289
the private access profile. And private access,

00:11:35.389 --> 00:11:39.110
as you would expect, is really as a way to provide

00:11:39.110 --> 00:11:43.570
access to apps and systems and things that you

00:11:43.570 --> 00:11:48.690
own within your data center. So think about traditionally

00:11:48.690 --> 00:11:51.889
you have a VPN client installed on your machines.

00:11:52.700 --> 00:11:55.700
Once the user fires up the VPN, they land on

00:11:55.700 --> 00:11:58.259
a subnet that typically then allows them to access

00:11:58.259 --> 00:12:01.019
whatever that subnet is open to. It could be

00:12:01.019 --> 00:12:02.779
one app. It could be 10 apps that are all on

00:12:02.779 --> 00:12:06.240
that subnet. And that's how folks work. And folks

00:12:06.240 --> 00:12:07.879
still work like that today. I mean, this is not

00:12:07.879 --> 00:12:11.580
that uncommon. It's a pretty common scenario.

00:12:12.039 --> 00:12:14.720
So what private access does, it allows you to

00:12:14.720 --> 00:12:18.340
actually grant access to applications like that

00:12:18.340 --> 00:12:22.750
without the use of a VPN. but doing it on a per

00:12:22.750 --> 00:12:25.450
app basis as well, right? So you can register

00:12:25.450 --> 00:12:28.710
these apps individually within your tenant and

00:12:28.710 --> 00:12:33.250
you can provide and apply conditional access

00:12:33.250 --> 00:12:36.789
to these applications specifically as a workflow

00:12:36.789 --> 00:12:40.110
to your tenant. So really, really powerful stuff.

00:12:40.289 --> 00:12:42.909
The great thing about it is it supports sort

00:12:42.909 --> 00:12:46.889
of all TCP and UDP protocols. So you can do IDP

00:12:46.889 --> 00:12:50.269
across this. You can do SSH across this. You

00:12:50.269 --> 00:12:52.529
can do SSH across this if you're not SSH into

00:12:52.529 --> 00:12:57.370
a Linux server. That is a scenario that I myself

00:12:57.370 --> 00:13:01.330
have tried. Obviously, you cannot install the

00:13:01.330 --> 00:13:03.990
client onto the Linux server, so it doesn't work

00:13:03.990 --> 00:13:06.409
so well. But I'm sure there are ways to get around

00:13:06.409 --> 00:13:09.549
it. And it'll probably follow soon in the future,

00:13:09.710 --> 00:13:12.909
right? I would imagine. Now, the thing is that

00:13:12.909 --> 00:13:16.490
the private network connector, it's been around

00:13:16.490 --> 00:13:18.629
for a long time because it's actually part of...

00:13:19.639 --> 00:13:21.740
what used to be called Azure App Proxy was now

00:13:21.740 --> 00:13:24.059
called Entry App Proxy, right? So it's the same

00:13:24.059 --> 00:13:26.360
concept as you installing the client on a Windows

00:13:26.360 --> 00:13:28.960
server, it's connecting out and making, it's

00:13:28.960 --> 00:13:30.360
been around. I mean, I think that thing supports

00:13:30.360 --> 00:13:33.360
anything from server 2012 onwards, right? So

00:13:33.360 --> 00:13:35.159
it's been around for a little while. They've

00:13:35.159 --> 00:13:37.279
never done anything to make it sort of, you know,

00:13:37.279 --> 00:13:41.690
Linux compatible. You know, who knows? I mean,

00:13:41.710 --> 00:13:43.509
I'm sure you don't need to have, you could probably

00:13:43.509 --> 00:13:46.690
SSH to, if you had a Windows server with that

00:13:46.690 --> 00:13:48.570
running, you could probably have a Linux server

00:13:48.570 --> 00:13:51.350
that has, that's on the same subnet that, you

00:13:51.350 --> 00:13:53.590
know, you connect to. I'm sure there will be

00:13:53.590 --> 00:13:57.149
ways to make that work. So, but like I said,

00:13:57.169 --> 00:14:00.429
you know, be aware of that, right? Yeah, good

00:14:00.429 --> 00:14:03.769
to know. So we talk about, we talk about AppProxy

00:14:03.769 --> 00:14:07.799
a fair bit. And really, private access is that

00:14:07.799 --> 00:14:11.259
sort of evolution of what Entry App Proxy is

00:14:11.259 --> 00:14:15.000
and was. But App Proxy isn't dead because there

00:14:15.000 --> 00:14:17.720
are things and there are scenarios where you

00:14:17.720 --> 00:14:19.759
may actually still want to use App Proxy instead

00:14:19.759 --> 00:14:23.240
of private access, right? So App Proxy works

00:14:23.240 --> 00:14:27.519
really well with web apps and HTTP, HTTPS applications,

00:14:27.899 --> 00:14:33.399
especially when you're wanting to do some sort

00:14:33.399 --> 00:14:36.529
of authentication. on on the connection so uh

00:14:36.529 --> 00:14:39.330
imagine you have a web server or a web application

00:14:39.330 --> 00:14:42.029
of some sort the web app itself doesn't have

00:14:42.029 --> 00:14:44.549
any authentication but you want to publish that

00:14:44.549 --> 00:14:47.250
to the internet well absolute app proxy is really

00:14:47.250 --> 00:14:49.570
good for this because you can actually then handle

00:14:49.570 --> 00:14:53.269
all the authentication through entra um if a

00:14:53.269 --> 00:14:54.970
user had you know if the user is assigned to

00:14:54.970 --> 00:14:57.750
the app and they have an intro login you can

00:14:57.750 --> 00:14:59.529
then multi -factor them you can do all that cool

00:14:59.529 --> 00:15:01.190
stuff and enter before passing the connection

00:15:01.190 --> 00:15:04.110
through to to the app so for those web scenarios

00:15:04.110 --> 00:15:08.269
especially where you have unknown devices byod

00:15:08.269 --> 00:15:10.850
devices that are not known to you at all app

00:15:10.850 --> 00:15:12.990
proxy still works really really well right yeah

00:15:12.990 --> 00:15:16.409
i don't see it used being used that often to

00:15:16.409 --> 00:15:19.080
my surprise yeah that's true that's true and

00:15:19.080 --> 00:15:21.059
you know and again it's been around for a long

00:15:21.059 --> 00:15:24.000
time i mean i you know um when i was i've been

00:15:24.000 --> 00:15:26.360
digging through my lab recently with stuff and

00:15:26.360 --> 00:15:28.419
and you know i still had an app proxy connector

00:15:28.419 --> 00:15:32.320
group from uh from 2016 where i had published

00:15:32.320 --> 00:15:35.320
adfs in that way right back back when adfs was

00:15:35.320 --> 00:15:37.679
still a thing remember that so well it is still

00:15:37.679 --> 00:15:39.960
a thing spoiler alert a lot of customers but

00:15:39.960 --> 00:15:42.299
yeah they're using it probably not in the correct

00:15:42.299 --> 00:15:45.100
way so i think the takeaway here is is that and

00:15:45.100 --> 00:15:47.200
i've put a table in the in the show notes here

00:15:47.200 --> 00:15:48.799
for anyone who wants to kind of see a quick reference

00:15:48.799 --> 00:15:50.539
of this is like when should you use our proxy

00:15:50.539 --> 00:15:52.519
when should you use private access i think the

00:15:52.519 --> 00:15:54.679
takeaway really is is that um you know private

00:15:54.679 --> 00:15:56.360
access is good when you're using something that

00:15:56.360 --> 00:15:59.259
isn't http or https right or if you want that

00:15:59.259 --> 00:16:02.360
vpn replacement um and you're going to handle

00:16:02.360 --> 00:16:04.960
all your authentication stuff via the the global

00:16:04.960 --> 00:16:07.440
secure client then that's where you want to use

00:16:07.440 --> 00:16:09.539
private access but if you've got those unknown

00:16:09.539 --> 00:16:11.659
scenarios maybe you've got some b2b scenarios

00:16:11.659 --> 00:16:15.769
or legacy web app stuff um Entra App Proxy still

00:16:15.769 --> 00:16:18.450
works and is alive and well for you. And it's

00:16:18.450 --> 00:16:20.370
configured in a very similar way. So there shouldn't

00:16:20.370 --> 00:16:23.850
be too much drama for you there. Chris, how does

00:16:23.850 --> 00:16:26.669
licensing work for Entra App Proxy? I'm not familiar

00:16:26.669 --> 00:16:28.909
with that, to be honest. Oh, that's a good question,

00:16:28.990 --> 00:16:31.070
actually. I don't think it, well, it doesn't

00:16:31.070 --> 00:16:33.629
require the additional licenses that you need

00:16:33.629 --> 00:16:37.750
for private access. So it doesn't require the

00:16:37.750 --> 00:16:40.070
Intra Suite stuff. I believe it's included just

00:16:40.070 --> 00:16:43.090
with P1 or P2 licenses. So I think if you have

00:16:43.090 --> 00:16:46.779
a P1. which is the same as the Microsoft traffic

00:16:46.779 --> 00:16:50.840
profile. So just enter IDP1, which is included

00:16:50.840 --> 00:16:53.120
with E3 and E5s, right? So there's a lot of good

00:16:53.120 --> 00:16:57.149
value there and that would do it for you. So

00:16:57.149 --> 00:16:58.789
the last of the traffic profiles, and this one's

00:16:58.789 --> 00:17:02.590
pretty simple, right, is internet access. So

00:17:02.590 --> 00:17:04.309
think about, you know, we were talking about

00:17:04.309 --> 00:17:06.450
private access, which is granting access to applications

00:17:06.450 --> 00:17:09.609
that you own in your data center. Well, internet

00:17:09.609 --> 00:17:11.349
access is kind of the other way around. It's

00:17:11.349 --> 00:17:13.309
granting access to applications that maybe you

00:17:13.309 --> 00:17:15.029
used to learn it, maybe it's a SaaS application,

00:17:15.309 --> 00:17:17.970
but that application is actually in the cloud,

00:17:18.049 --> 00:17:21.049
so you're connecting outbound. Now, historically...

00:17:21.289 --> 00:17:24.390
you would have some sort of proxy server on your

00:17:24.390 --> 00:17:27.809
web proxy on your premises or in your office.

00:17:28.109 --> 00:17:30.490
Your connections go through that and get proxied

00:17:30.490 --> 00:17:33.549
outbound. Well, with the work from home scenarios

00:17:33.549 --> 00:17:36.589
these days, that doesn't really happen all that

00:17:36.589 --> 00:17:39.390
much anymore. And we've obviously mentioned scenarios

00:17:39.390 --> 00:17:42.170
like Zscaler, which kind of handles this type

00:17:42.170 --> 00:17:44.569
of thing really, really well. But that's really

00:17:44.569 --> 00:17:48.529
what this is. It's sort of that... uh web web

00:17:48.529 --> 00:17:51.150
secure web gateway if you will for for accessing

00:17:51.150 --> 00:17:55.130
public services and public sas uh um you know

00:17:55.130 --> 00:17:58.730
applications uh again being able to enforce conditional

00:17:58.730 --> 00:18:01.690
access um on those connections so making sure

00:18:01.690 --> 00:18:04.809
that if someone's going to access your m365 environment

00:18:04.809 --> 00:18:07.710
you want to make sure that they're using um you

00:18:07.710 --> 00:18:10.130
know maybe an intune enrolled device or a known

00:18:10.130 --> 00:18:13.670
device or that type of conditional access and

00:18:13.670 --> 00:18:17.150
granular uh control on on those outbounds but

00:18:17.150 --> 00:18:19.069
you can also do things like web content filtering

00:18:19.069 --> 00:18:21.549
right and and i'll say this is really really

00:18:21.549 --> 00:18:25.009
basic stuff but you know maybe your your your

00:18:25.009 --> 00:18:26.750
environment you you just want to filter really

00:18:26.750 --> 00:18:29.450
basic stuff you want to filter facebook and you

00:18:29.450 --> 00:18:32.690
know chat gpt and whatever else you don't want

00:18:32.690 --> 00:18:35.809
your users to be using um you can do that quite

00:18:35.809 --> 00:18:37.410
easily with this that's what it's made for right

00:18:37.410 --> 00:18:39.730
so you can do sort of filtering by by category

00:18:39.730 --> 00:18:43.000
or by by fgdn on this the categories i think

00:18:43.000 --> 00:18:45.460
are pretty limited um but it will give you a

00:18:45.460 --> 00:18:48.099
basic level of of web content filtering if that's

00:18:48.099 --> 00:18:50.460
what you're looking for um and you know that's

00:18:50.460 --> 00:18:53.380
a it's a good way to to protect your uh your

00:18:53.380 --> 00:18:55.759
assets if if someone has one of your devices

00:18:55.759 --> 00:18:59.099
and they're using a an internet cafe or you know

00:18:59.099 --> 00:19:00.900
their home connection or something at least you

00:19:00.900 --> 00:19:04.839
can provide some control right um so really that's

00:19:04.839 --> 00:19:07.599
kind of one of the the the the needs here is

00:19:07.599 --> 00:19:09.869
is to be able to enforce that really good control

00:19:09.869 --> 00:19:11.890
on the outbound connections, bit of filtering.

00:19:12.349 --> 00:19:16.410
And then there's some additional benefits as

00:19:16.410 --> 00:19:19.029
far as being able to tell the true source of

00:19:19.029 --> 00:19:21.109
the IP address from a logging perspective. So

00:19:21.109 --> 00:19:23.849
you're not looking in the logs and seeing only

00:19:23.849 --> 00:19:27.250
a single proxy server IP address on your connections.

00:19:27.390 --> 00:19:28.809
You can actually tell where the connections are

00:19:28.809 --> 00:19:32.250
coming from that using the source IP restoration

00:19:32.250 --> 00:19:36.390
stuff. So again, this is probably not going to

00:19:36.390 --> 00:19:39.200
be a solution for every single customer. um but

00:19:39.200 --> 00:19:41.180
i i'm a strong believer that there are a lot

00:19:41.180 --> 00:19:42.880
of customers that will actually see some really

00:19:42.880 --> 00:19:45.759
good benefit from this and even if you know remember

00:19:45.759 --> 00:19:49.029
we talk about this all the time that um Yeah,

00:19:49.089 --> 00:19:51.930
in our sort of security world, things have to

00:19:51.930 --> 00:19:53.589
be iterative, right? You've got to constantly

00:19:53.589 --> 00:19:58.089
kind of mature your offerings. And even if this

00:19:58.089 --> 00:20:00.730
isn't your final long -term solution, this may

00:20:00.730 --> 00:20:02.609
be a really good stepping stone solution for

00:20:02.609 --> 00:20:05.289
you to just get into the habit of like, how do

00:20:05.289 --> 00:20:07.589
we monitor and restrict our outbound access?

00:20:07.829 --> 00:20:09.750
Well, here's a good place to start before you

00:20:09.750 --> 00:20:13.599
start looking into other. bigger tools for the

00:20:13.599 --> 00:20:16.140
job. So definitely worth checking out. There

00:20:16.140 --> 00:20:19.059
is a trial available as well. So as with a lot

00:20:19.059 --> 00:20:21.960
of things in sort of the M365 ecosystem, if you

00:20:21.960 --> 00:20:23.619
just want to just kick the tires on this, you

00:20:23.619 --> 00:20:26.319
can sign up for a 25 user trial. I think it's

00:20:26.319 --> 00:20:30.140
for like one month. And interestingly, what I've

00:20:30.140 --> 00:20:32.619
noticed with the trial workflow, especially on

00:20:32.619 --> 00:20:36.420
this one is you actually get the option of once

00:20:36.420 --> 00:20:39.549
the trial ends, actually subscribing. or just

00:20:39.549 --> 00:20:42.109
letting it die which is great i i had not seen

00:20:42.109 --> 00:20:44.670
that before in in the microsoft billing engine

00:20:44.670 --> 00:20:46.910
which you know as we know can be quite complex

00:20:46.910 --> 00:20:50.630
so um yeah very very cool stuff i i i definitely

00:20:50.630 --> 00:20:53.500
think uh it's worth with taking a look at Yeah,

00:20:53.539 --> 00:20:56.039
a lot of development is going into this product.

00:20:56.099 --> 00:20:58.759
Probably a lot of additional features will be

00:20:58.759 --> 00:21:03.180
added to it in the future. Do you know, Chris,

00:21:03.339 --> 00:21:06.220
because last time I looked at that, at the internet

00:21:06.220 --> 00:21:08.980
access part, I was actually looking for a way

00:21:08.980 --> 00:21:12.420
to redirect internet traffic for a group of people

00:21:12.420 --> 00:21:16.059
over a very fixed outbound IP address. Do you

00:21:16.059 --> 00:21:18.240
know if that is possible by now? It wasn't back

00:21:18.240 --> 00:21:22.200
then, but... So instead of doing it by individual

00:21:22.200 --> 00:21:26.019
users, you want to direct it or do it by... Yeah,

00:21:26.019 --> 00:21:29.079
for example, if a service requires me coming

00:21:29.079 --> 00:21:32.039
in from a set IP address, for example, some companies

00:21:32.039 --> 00:21:35.519
and I work for an MSSP and we have a lot of companies

00:21:35.519 --> 00:21:38.619
still wanting to limit our access into their

00:21:38.619 --> 00:21:40.759
environment coming from a set IP address, for

00:21:40.759 --> 00:21:44.180
example. You can do that with a VPN client, VPN

00:21:44.180 --> 00:21:48.549
box. So I was kind of hoping that private access

00:21:48.549 --> 00:21:51.190
would be able to provide me this somewhere in

00:21:51.190 --> 00:21:54.549
the future. I don't know that it, I mean, you

00:21:54.549 --> 00:21:56.990
could probably do it using what they call remote

00:21:56.990 --> 00:21:59.710
networks. So if you set up a remote network,

00:21:59.990 --> 00:22:03.329
you could probably do it that way. It will cut,

00:22:03.410 --> 00:22:05.329
you know, everything that flows through that

00:22:05.329 --> 00:22:08.990
network path comes from a known IP. But no, that's

00:22:08.990 --> 00:22:11.549
not a scenario that I've come across. So that's

00:22:11.549 --> 00:22:17.470
interesting. Lastly, I think just a quick worth

00:22:17.470 --> 00:22:19.509
mentioning, and I have put it in the notes as

00:22:19.509 --> 00:22:22.309
well is, and I literally learned about this like

00:22:22.309 --> 00:22:26.589
two days ago. There's a preview currently of

00:22:26.589 --> 00:22:29.450
something called private access for domain controllers.

00:22:30.049 --> 00:22:33.329
And it's, like I said, it's in preview. And essentially

00:22:33.329 --> 00:22:35.609
what it is, it's again, it builds on private

00:22:35.609 --> 00:22:39.970
access and allows you now to layer in applications

00:22:39.970 --> 00:22:42.940
that use. sort of legacy Kerberos environments,

00:22:43.279 --> 00:22:45.380
right? So if you think about things that today

00:22:45.380 --> 00:22:47.519
would still need to use a domain controller for

00:22:47.519 --> 00:22:49.700
authentication, well, you don't want to be putting

00:22:49.700 --> 00:22:51.119
your domain controllers on the internet and you

00:22:51.119 --> 00:22:52.980
certainly don't want to be opening those things

00:22:52.980 --> 00:22:56.819
up. This is now a way where you can install a

00:22:56.819 --> 00:22:59.279
private access sensor on the domain controllers

00:22:59.279 --> 00:23:03.420
and then using SPN configurations, you can actually

00:23:03.420 --> 00:23:05.640
now enforce things like multi -factor auth and

00:23:05.640 --> 00:23:07.920
all sorts of conditional access on those legacy

00:23:08.519 --> 00:23:11.700
um kerberos applications this looks really promising

00:23:11.700 --> 00:23:13.700
i've i've not messed with it yet because it's

00:23:13.700 --> 00:23:16.559
it's pretty new um but like i said you know this

00:23:16.559 --> 00:23:19.000
was kind of announced very very recently and

00:23:19.000 --> 00:23:21.359
is currently in preview so you know if you've

00:23:21.359 --> 00:23:24.579
if you're in your environment have uh still have

00:23:24.579 --> 00:23:27.039
some legacy you know kerberos type applications

00:23:27.039 --> 00:23:28.940
this might be something that you want to look

00:23:28.940 --> 00:23:33.700
at as well um so check that out uh coast over

00:23:33.700 --> 00:23:37.549
to you to talk about um The very, very big mouthful,

00:23:37.569 --> 00:23:39.950
Defender for External Attack Service Management.

00:23:40.650 --> 00:23:44.250
Yes, let's call it MDEASM, but that's still a

00:23:44.250 --> 00:23:47.309
mouthful as an acronym, right? So I'll try not

00:23:47.309 --> 00:23:49.930
to fumble over my words in the next couple of

00:23:49.930 --> 00:23:54.029
10, 15 minutes too much. Yeah, so Defender for

00:23:54.029 --> 00:23:56.789
External Attack Service Management is a tool

00:23:56.789 --> 00:24:00.490
designed to help organizations discover, monitor

00:24:00.490 --> 00:24:03.190
and secure everything that's internet facing.

00:24:03.559 --> 00:24:07.339
And the most important part of this is even the

00:24:07.339 --> 00:24:11.119
ones they didn't know existed. So you have to

00:24:11.119 --> 00:24:15.079
think of this as some kind of automated reconnaissance

00:24:15.079 --> 00:24:18.119
tool. You just fill in your domain names, your

00:24:18.119 --> 00:24:21.819
IP blocks, your ASNs, who is information, that

00:24:21.819 --> 00:24:23.960
kind of stuff. And Microsoft will automatically

00:24:23.960 --> 00:24:29.640
crawl across all of those assets and try to find

00:24:29.640 --> 00:24:33.920
other linked assets to it. It has built an entire

00:24:33.920 --> 00:24:37.400
inventory. It will also do a lot of port scanning

00:24:37.400 --> 00:24:40.160
stuff and finding out what kind of services are

00:24:40.160 --> 00:24:43.579
behind those IP addresses. If maybe there are

00:24:43.579 --> 00:24:45.799
some certificate issues, maybe some potential

00:24:45.799 --> 00:24:48.779
exploits available on certain services. And it

00:24:48.779 --> 00:24:51.519
will all give you those insights for your entire

00:24:51.519 --> 00:24:57.519
publicly facing tech service, so to speak. And

00:24:57.519 --> 00:25:01.279
I think companies grow larger. They acquire other

00:25:01.279 --> 00:25:03.700
companies. They move to the cloud, spin up new

00:25:03.700 --> 00:25:06.819
environments. Their attack servers become so

00:25:06.819 --> 00:25:09.319
much harder to track what they all have running

00:25:09.319 --> 00:25:13.059
over there and what they actually have. And I

00:25:13.059 --> 00:25:16.579
think that's why this is really key to get back

00:25:16.579 --> 00:25:19.960
the visibility of all the stuff you're actually

00:25:19.960 --> 00:25:24.349
handing out to the public Internet. So again,

00:25:24.470 --> 00:25:30.289
I used a large online retailer in the Netherlands

00:25:30.289 --> 00:25:34.089
on board this. So they have a lot of public facing

00:25:34.089 --> 00:25:37.609
assets because they have web shops and all kinds

00:25:37.609 --> 00:25:42.190
of other internet services running. So I was

00:25:42.190 --> 00:25:46.339
kind of amazed to see how much... EASM was able

00:25:46.339 --> 00:25:49.339
to discover purely by just entering initially

00:25:49.339 --> 00:25:53.099
their primary domain name. So what it will do,

00:25:53.099 --> 00:25:55.980
it will also pull in who is information. For

00:25:55.980 --> 00:25:59.539
example, if your email address is the contact

00:25:59.539 --> 00:26:03.240
name for that domain, it will also look up for

00:26:03.240 --> 00:26:06.339
who is information on that same email address

00:26:06.339 --> 00:26:09.140
to find other domains you might have registered,

00:26:09.319 --> 00:26:12.170
which might have. It might be related to that

00:26:12.170 --> 00:26:16.950
one. So you just initially create what they call

00:26:16.950 --> 00:26:19.710
a discovery group. And within a discovery group,

00:26:19.829 --> 00:26:22.170
you can, well, like I said earlier, add domains,

00:26:22.410 --> 00:26:25.630
IP blocks, ASNs, who is information, a lot of

00:26:25.630 --> 00:26:29.230
stuff. Not everything is required. You can just

00:26:29.230 --> 00:26:32.970
start with a domain name, for example. Periodically,

00:26:32.990 --> 00:26:35.869
a default is a week, I believe. It will scan

00:26:35.869 --> 00:26:42.710
and try to find new assets. I was already confronted

00:26:42.710 --> 00:26:45.710
with a lot of assets not being owned by this

00:26:45.710 --> 00:26:48.990
company. So this company had a certain domain

00:26:48.990 --> 00:26:53.029
name, but that same domain name with a .br for

00:26:53.029 --> 00:26:56.569
Brazil was apparently a new site in Brazil. And

00:26:56.569 --> 00:26:58.970
Microsoft thought it was related because it had

00:26:58.970 --> 00:27:01.250
the same domain name, right? But then with a

00:27:01.250 --> 00:27:03.549
different... extension at the end of it so you

00:27:03.549 --> 00:27:06.309
really have to regularly check what kind of assets

00:27:06.309 --> 00:27:10.930
Microsoft is discovering because you pay per

00:27:10.930 --> 00:27:14.349
asset so even if you fill in a single domain

00:27:14.349 --> 00:27:17.849
name if Microsoft will discover 100 domains and

00:27:17.849 --> 00:27:22.490
20 IP addresses you pay for the 120 assets discovered

00:27:22.490 --> 00:27:26.970
and you pay 10 cents per asset per day And this

00:27:26.970 --> 00:27:31.289
might not sound like much company like this retailer

00:27:31.289 --> 00:27:34.690
ended up with, I believe, 3000 something assets.

00:27:34.970 --> 00:27:39.690
Then it quickly adds up, of course. And that's

00:27:39.690 --> 00:27:43.009
also why you need to keep an eye on it after

00:27:43.009 --> 00:27:46.069
you set it up to make sure that everything that

00:27:46.069 --> 00:27:49.410
is discovered incorrectly or not related, you

00:27:49.410 --> 00:27:51.549
have to exclude yourself in the device group.

00:27:51.670 --> 00:27:56.180
And Microsoft will also discover assets with

00:27:56.180 --> 00:28:00.200
a state they call requires investigation. And

00:28:00.200 --> 00:28:03.559
until you acknowledge that this is indeed your

00:28:03.559 --> 00:28:06.819
assets, they will not do any scanning on it or

00:28:06.819 --> 00:28:09.900
incorporating it into the dashboard. So you really

00:28:09.900 --> 00:28:12.279
have to go in and say, okay, this is mine or

00:28:12.279 --> 00:28:15.259
this is not mine. So there's a little bit of

00:28:15.259 --> 00:28:17.960
work initially to get it started, but it's not

00:28:17.960 --> 00:28:19.880
too bad, I believe, especially with everything

00:28:19.880 --> 00:28:25.000
that's discovered automatically. It is a bit

00:28:25.000 --> 00:28:27.680
weird. Microsoft is nowadays putting all the

00:28:27.680 --> 00:28:30.299
Defender stuff in the security portal, right?

00:28:30.400 --> 00:28:33.480
Even Sentinel is now there. And Microsoft even

00:28:33.480 --> 00:28:35.940
recently did an announcement that they will stop

00:28:35.940 --> 00:28:39.819
Sentinel from being an Azure resource one year

00:28:39.819 --> 00:28:42.180
from now. So they're now really forcing everything

00:28:42.180 --> 00:28:44.759
in the security portal. But Defender for external

00:28:44.759 --> 00:28:48.200
attack service management is still a... azure

00:28:48.200 --> 00:28:51.140
resource so i think this is maybe uh the last

00:28:51.140 --> 00:28:54.359
one or something i don't know So you have to

00:28:54.359 --> 00:28:56.420
deploy it through the Azure portal, but once

00:28:56.420 --> 00:29:00.079
the instance is set up, you can connect it to

00:29:00.079 --> 00:29:03.319
your Defender XDR by going into the security

00:29:03.319 --> 00:29:05.960
portal. I've put it in the show notes where you

00:29:05.960 --> 00:29:09.519
should go exactly because it's a little bit hidden,

00:29:09.579 --> 00:29:13.539
to be honest. But there you can select the instance

00:29:13.539 --> 00:29:15.759
you've deployed in Azure and then the insights

00:29:15.759 --> 00:29:18.019
and recommendations will show up there as well.

00:29:18.539 --> 00:29:21.099
But the initial setup and configuration is still

00:29:21.099 --> 00:29:24.150
done all in Azure. Well, I was also happy to

00:29:24.150 --> 00:29:27.069
see that there is log analytics integration by

00:29:27.069 --> 00:29:30.049
default, which obviously makes it very useful

00:29:30.049 --> 00:29:33.710
to connect into Sentinel. Microsoft does not

00:29:33.710 --> 00:29:36.529
have any content available for Sentinel. I was

00:29:36.529 --> 00:29:38.450
kind of surprised to see that. So they don't

00:29:38.450 --> 00:29:41.710
have any content up package or any detections

00:29:41.710 --> 00:29:45.490
or whatnot. So actually, I had to create a couple

00:29:45.490 --> 00:29:48.769
of my own. I shared these in the show notes as

00:29:48.769 --> 00:29:51.390
well. So I think it's very useful to trigger

00:29:51.390 --> 00:29:53.809
a security incident in Sentinel, for example,

00:29:53.829 --> 00:29:58.390
if EASM discovers an asset with a high critical

00:29:58.390 --> 00:30:00.829
vulnerability, for example, you want to know

00:30:00.829 --> 00:30:02.769
about that. And then you can imagine that people

00:30:02.769 --> 00:30:05.869
are not looking in the dashboards every day constantly.

00:30:06.269 --> 00:30:08.309
So you want to pop up an incident. You can do

00:30:08.309 --> 00:30:12.990
that. Unfortunately, I discovered that the new

00:30:12.990 --> 00:30:15.980
assets discovered which require investigation

00:30:15.980 --> 00:30:19.380
could not be triggered in Sentinel and this is

00:30:19.380 --> 00:30:23.750
due to the fact that the state The state property

00:30:23.750 --> 00:30:26.769
of an asset is for some reason not synced to

00:30:26.769 --> 00:30:30.390
Log Analytics right now. So I'm already in touch

00:30:30.390 --> 00:30:33.150
with the engineering team behind the product

00:30:33.150 --> 00:30:36.309
and I filed a feature request. I'm hoping that

00:30:36.309 --> 00:30:39.390
they will add that in the future. Your external

00:30:39.390 --> 00:30:42.230
attack service is not changing that frequently,

00:30:42.609 --> 00:30:46.569
I can imagine. But it is something to keep in

00:30:46.569 --> 00:30:49.069
mind. It's an interesting concept, though, because

00:30:49.069 --> 00:30:52.210
you... if you do an external pen test of your

00:30:52.210 --> 00:30:54.109
environment like one of the things i guess that

00:30:54.109 --> 00:30:56.470
most pen testers are going to use is they're

00:30:56.470 --> 00:30:59.849
going to start looking at certificate revocation

00:30:59.849 --> 00:31:02.690
lists and certificate logs and all these types

00:31:02.690 --> 00:31:05.430
of things to find where you've maybe generated

00:31:05.430 --> 00:31:07.569
services over the years right because like especially

00:31:07.569 --> 00:31:09.589
those like crt logs those things don't go away

00:31:09.589 --> 00:31:12.730
and you can see you know any certificate that

00:31:12.730 --> 00:31:15.789
was ever generated for a domain um and there

00:31:15.789 --> 00:31:19.269
may be a service there uh so it's i'm sure there's

00:31:19.930 --> 00:31:22.150
for many organizations doing this, there's going

00:31:22.150 --> 00:31:24.049
to be that sort of shock, initial shock of like,

00:31:24.170 --> 00:31:27.289
oh, I forgot about that. Or we didn't realize

00:31:27.289 --> 00:31:29.150
that this was still there. We thought this was

00:31:29.150 --> 00:31:32.630
gone a long time ago, right? Because no one ever

00:31:32.630 --> 00:31:34.470
cleans up everything perfectly all the time.

00:31:34.959 --> 00:31:38.160
No, that's true. And initially I was kind of

00:31:38.160 --> 00:31:40.740
surprised that when I set it up in my lab environment,

00:31:40.920 --> 00:31:43.680
I was able to add any domain I wanted. And I

00:31:43.680 --> 00:31:45.960
was like, shouldn't I prove that this domain

00:31:45.960 --> 00:31:48.359
is mine? And then I was like, no, of course not.

00:31:48.420 --> 00:31:50.500
This is all public information, right? And an

00:31:50.500 --> 00:31:53.599
attacker can also scan those domains and look

00:31:53.599 --> 00:31:56.779
for open ports and whatnot. It's fine. You can

00:31:56.779 --> 00:31:58.819
add everything you want. Except if you use this,

00:31:58.880 --> 00:32:00.279
you're going to be paying 10 cents for every

00:32:00.279 --> 00:32:03.700
one you scan. Which I guess is probably a little

00:32:03.700 --> 00:32:06.440
bit of a deterrent for someone versus the Python

00:32:06.440 --> 00:32:08.640
script that they downloaded off GitHub that's

00:32:08.640 --> 00:32:10.880
doing the same thing for them, right? Yeah, that's

00:32:10.880 --> 00:32:14.779
true. And also for people listening, when you

00:32:14.779 --> 00:32:18.220
deploy your first EASM instance, it automatically

00:32:18.220 --> 00:32:21.579
activates a 30 -day trial. So you can add your

00:32:21.579 --> 00:32:25.700
environment, see what comes up. you don't think

00:32:25.700 --> 00:32:27.640
it's useful, you just remove the instance and

00:32:27.640 --> 00:32:31.140
you're not charged anything. To keep a track

00:32:31.140 --> 00:32:35.180
on costs, I also created the detection in Sentinel

00:32:35.180 --> 00:32:39.319
for this customer to alert when new assets were

00:32:39.319 --> 00:32:42.960
found and the total amount increased more than

00:32:42.960 --> 00:32:46.460
10 % because you can imagine the discovery will

00:32:46.460 --> 00:32:49.799
rerun weekly and it might eventually discover

00:32:49.799 --> 00:32:53.319
assets who are yours or maybe not and then like

00:32:53.319 --> 00:32:55.880
the example with the brazilian website if it

00:32:55.880 --> 00:32:58.900
if it suddenly discovers a completely new domain

00:32:58.900 --> 00:33:01.720
with a lot of assets you will pay for them at

00:33:01.720 --> 00:33:03.119
the end of the month and you want to know up

00:33:03.119 --> 00:33:05.059
front right so that's why i created the detection

00:33:05.059 --> 00:33:08.480
to periodically on a weekly basis compare the

00:33:08.480 --> 00:33:11.039
amount of assets with last week and if there's

00:33:11.039 --> 00:33:13.839
a more than 10 increase you get a security incident

00:33:13.839 --> 00:33:16.279
in sentinel and then you know that you have to

00:33:16.279 --> 00:33:19.240
look for something perhaps to either clean up

00:33:19.240 --> 00:33:21.549
or just accept fact that you had more assets

00:33:21.549 --> 00:33:24.289
now but at least now you know there's nothing

00:33:24.289 --> 00:33:27.230
like this in the product but you can build solutions

00:33:27.230 --> 00:33:30.529
like this through log analytics oh that's very

00:33:30.529 --> 00:33:32.029
nice i'm sure that's going to be very helpful

00:33:32.029 --> 00:33:34.269
um for folks but yeah that's this sounds really

00:33:34.269 --> 00:33:36.049
cool this sounds like something i want to mess

00:33:36.049 --> 00:33:38.910
around with pretty quick pretty soon i like the

00:33:38.910 --> 00:33:41.339
idea Yeah, and it's really cool when you see

00:33:41.339 --> 00:33:43.839
all the domains and IP addresses pop up. You

00:33:43.839 --> 00:33:46.299
can, for example, this customer also had a VPN

00:33:46.299 --> 00:33:50.059
endpoint with a VPN specific name, DNS name,

00:33:50.119 --> 00:33:52.319
of course. And when you click on it, you can

00:33:52.319 --> 00:33:54.200
see what kind of services they're running. They're

00:33:54.200 --> 00:33:57.299
running a Cisco service. So Microsoft is already

00:33:57.299 --> 00:34:00.660
warning me about potential exploits with outdated

00:34:00.660 --> 00:34:03.000
firmware versions. They were not able to check

00:34:03.000 --> 00:34:05.079
that over the open port. But since they know

00:34:05.079 --> 00:34:08.099
it was Cisco Firepower, for example, I believe

00:34:08.099 --> 00:34:11.119
then they know, okay, there are known vulnerabilities.

00:34:11.440 --> 00:34:14.260
Please check that you have your firmware up to

00:34:14.260 --> 00:34:17.820
this version. Really useful stuff. Really informational

00:34:17.820 --> 00:34:21.860
stuff. Yeah, that's awesome. At Cisco, I think

00:34:21.860 --> 00:34:24.400
I've had a couple of pretty nasty ones over the

00:34:24.400 --> 00:34:26.679
last month or so. So yeah, that's a particular

00:34:26.679 --> 00:34:29.380
instance too. Very nice. That's awesome. And

00:34:29.380 --> 00:34:32.559
this customer had their head of firmwares in

00:34:32.559 --> 00:34:35.440
check. So they were able to acknowledge the alert

00:34:35.440 --> 00:34:39.019
coming in and close it down and make sure that

00:34:39.019 --> 00:34:42.579
acknowledges that. that they saw that and they

00:34:42.579 --> 00:34:44.639
are up to date already. But at least now you

00:34:44.639 --> 00:34:47.159
know, right? And like you said, a lot of stuff

00:34:47.159 --> 00:34:50.800
you don't know still existed and was probably

00:34:50.800 --> 00:34:54.780
outdated and vulnerable for attacks. So I think

00:34:54.780 --> 00:34:57.739
especially when you're running publicly facing

00:34:57.739 --> 00:35:01.599
assets, you really should look into this. Yeah,

00:35:01.639 --> 00:35:05.119
no, 100%. Very cool. It's very, very, very nice.

00:35:05.179 --> 00:35:08.610
Thank you for that one. Yeah. I think before

00:35:08.610 --> 00:35:12.230
we wrap up, just to talk about our community

00:35:12.230 --> 00:35:15.630
project for this month. This is an interesting

00:35:15.630 --> 00:35:20.250
one. And it's interesting because the person

00:35:20.250 --> 00:35:22.449
who's come up with this, and I'm probably going

00:35:22.449 --> 00:35:24.050
to butcher the name here, but I'm going to give

00:35:24.050 --> 00:35:29.590
it my best shot anyway. Mikael Carlson. created

00:35:29.590 --> 00:35:31.989
this tool called Intune Management. Don't repeat

00:35:31.989 --> 00:35:33.889
yourself, Chris. You're making it worse. You

00:35:33.889 --> 00:35:37.750
just stick to the initial pronunciation. Sorry

00:35:37.750 --> 00:35:40.369
for interrupting you, man. And he created this

00:35:40.369 --> 00:35:42.949
PowerShell tool called Intune Management, which

00:35:42.949 --> 00:35:46.309
is essentially like a user interface onto Intune.

00:35:46.889 --> 00:35:49.130
Now, the reason this is interesting is because

00:35:49.130 --> 00:35:52.010
I don't know Mikhail, and he's from Sydney, or

00:35:52.010 --> 00:35:55.349
at least he lives in Sydney as well. And I don't

00:35:55.349 --> 00:35:58.980
know him, and he doesn't... you know appear to

00:35:58.980 --> 00:36:01.119
be an mvp or anything like that it's just a cool

00:36:01.119 --> 00:36:04.539
tool that he created um randomly that that i

00:36:04.539 --> 00:36:07.960
came across and i really like the look of this

00:36:07.960 --> 00:36:11.940
it looks very very cool um And one of the reasons

00:36:11.940 --> 00:36:14.519
I think where I see the real benefit to this

00:36:14.519 --> 00:36:17.800
is it allows you to sort of copy and import,

00:36:18.019 --> 00:36:22.639
export, delete policies and profile information

00:36:22.639 --> 00:36:25.480
within Intune and Azure. And it's got a ton of

00:36:25.480 --> 00:36:29.780
sort of options as far as your app protection

00:36:29.780 --> 00:36:32.019
policies or your app configuration policies and

00:36:32.019 --> 00:36:34.119
compliance policies, conditional access, all

00:36:34.119 --> 00:36:36.840
that stuff that you configure either in Azure

00:36:36.840 --> 00:36:39.750
or in Intune. um it gives you an interface to

00:36:39.750 --> 00:36:42.590
to to obviously view and edit those things but

00:36:42.590 --> 00:36:45.750
also then if you wanted to clone or back up those

00:36:45.750 --> 00:36:48.010
policies which firstly i think is really cool

00:36:48.010 --> 00:36:51.610
to be able to have that like a backup of your

00:36:51.610 --> 00:36:54.269
policies in a way that you can very easily import

00:36:54.269 --> 00:36:56.489
them right i think that in itself is is of great

00:36:56.489 --> 00:36:58.929
benefit um but i could also see this working

00:36:58.929 --> 00:37:01.210
really well for folks like myself who are consultants

00:37:01.210 --> 00:37:04.889
who you know you probably have a base of of policies

00:37:04.889 --> 00:37:07.699
that maybe you build that you know is mostly

00:37:07.699 --> 00:37:09.699
the same for every customer right like you know

00:37:09.699 --> 00:37:12.719
most customers have apple and ios ios and android

00:37:12.719 --> 00:37:17.059
devices and they have some um uh sort of compliance

00:37:17.059 --> 00:37:19.179
policies or configuration policies for that and

00:37:19.179 --> 00:37:21.980
if you had a baseline set of policies um that

00:37:21.980 --> 00:37:24.300
you could then build and export and then re -import

00:37:24.300 --> 00:37:26.440
those into a different environment that's really

00:37:26.440 --> 00:37:29.119
powerful instead of having to either orchestrate

00:37:29.119 --> 00:37:32.300
them or recreate them from scratch so i you know

00:37:32.300 --> 00:37:34.739
the tool works great i i ran it up on a on a

00:37:34.739 --> 00:37:37.980
it only works on windows um i'll say that um

00:37:37.980 --> 00:37:40.739
because it i think it well it says wpf but i'm

00:37:40.739 --> 00:37:42.440
sure there's a little bit of windows forms and

00:37:42.440 --> 00:37:45.400
stuff in there as well um so the goo the gui

00:37:45.400 --> 00:37:49.449
anyway uh will only run on windows but um Yeah,

00:37:49.530 --> 00:37:51.789
I had a play with it earlier this morning. And,

00:37:51.789 --> 00:37:55.949
you know, it's very cool. It's very sort of functional,

00:37:56.090 --> 00:37:58.170
I think. And it's been around for a while. I

00:37:58.170 --> 00:38:00.329
think the first commits on GitHub were like four

00:38:00.329 --> 00:38:02.489
years ago. So he's been working on this for a

00:38:02.489 --> 00:38:04.329
while. And then there were some updates recently

00:38:04.329 --> 00:38:07.829
just a couple months ago. So, yeah. Great, great

00:38:07.829 --> 00:38:10.829
work, Mikhail. If you're interested in checking

00:38:10.829 --> 00:38:14.510
this out, there's a link to the GitHub repo in

00:38:14.510 --> 00:38:17.030
the show notes. And yeah, if you work in Intune

00:38:17.030 --> 00:38:19.010
a lot or you work with devices and autopilot,

00:38:19.030 --> 00:38:21.909
stuff like that, this might make your life easier.

00:38:22.210 --> 00:38:24.150
So go check it out. Thanks for hearing, Chris.

00:38:24.269 --> 00:38:27.590
Good find. Yeah, awesome. Well, I think with

00:38:27.590 --> 00:38:30.239
that, it's... Probably time to wrap up and say

00:38:30.239 --> 00:38:32.400
goodbye. Coast, I'm sure you've got a day job

00:38:32.400 --> 00:38:35.099
to get to today. Yes. It's 9 o 'clock in the

00:38:35.099 --> 00:38:39.199
morning now. Time to start my day. Absolutely.

00:38:39.239 --> 00:38:41.519
Yes. I'm going to kick back here now. I think

00:38:41.519 --> 00:38:42.900
it's time for me to go watch some Tour de France

00:38:42.900 --> 00:38:46.139
highlights. What are you going to watch? The

00:38:46.139 --> 00:38:48.500
Tour de France highlights from the stage. Well,

00:38:48.579 --> 00:38:51.199
it would be stage 15, I guess, highlights. Because

00:38:51.199 --> 00:38:54.920
of the time zone, I get to, like, I watch the

00:38:54.920 --> 00:38:58.550
highlights in my afternoon. so so the stay i

00:38:58.550 --> 00:39:00.570
mean the stage runs overnight right i think they

00:39:00.570 --> 00:39:03.909
start around eight o 'clock uh pm sydney time

00:39:03.909 --> 00:39:06.230
but i you know i'm not gonna stay up and watch

00:39:06.230 --> 00:39:08.710
the as much as i love the tour de france i can't

00:39:08.710 --> 00:39:11.210
stay up and watch a six hour stage so i uh you

00:39:11.210 --> 00:39:12.610
know i watch the highlights the next afternoon

00:39:12.610 --> 00:39:15.449
before the next stage kicks off it's okay okay

00:39:15.449 --> 00:39:18.010
okay enjoy the cycling highlights and see you

00:39:18.010 --> 00:39:20.760
next time Absolutely. We'll see you again. Thanks,

00:39:20.840 --> 00:39:23.139
everyone, for listening. Please feel free to

00:39:23.139 --> 00:39:25.639
like and subscribe or reach out to us on the

00:39:25.639 --> 00:39:28.219
socials as well. We have a LinkedIn page now

00:39:28.219 --> 00:39:32.519
also. So if you want to reach out to us with

00:39:32.519 --> 00:39:34.659
some, you know, if you have feedback or if there's

00:39:34.659 --> 00:39:36.639
something specifically that you want us to cover

00:39:36.639 --> 00:39:38.780
on the show, please reach out to us and we'll

00:39:38.780 --> 00:39:41.619
do our best to accommodate that. But until then,

00:39:41.699 --> 00:39:44.920
we'll see you for episode 10 and we will be back

00:39:44.920 --> 00:39:48.219
in a month. Until then, take care and see you.

00:39:48.960 --> 00:39:49.400
Bye -bye.
