Microsoft 365 / Azure AD – Exploring Identity Protection service – Exploring Security continues – study material for MS-500

fig : Microsoft Entra admin center - Identity Protection blade
fig : Microsoft Entra admin center - Identity Protection blade

Hi All

Greetings for the day!!!

Exploring security concepts continues… Today we will discuss – Identity Protection service in Azure AD

What is Identity Protection

  • Identity protection is the service which enables us to view the security posture of any account
  • With Identity Protection service we can do
    • Automate the detection and remediation of identity-based risks.
    • Investigate risks using data in the portal.
    • Export risk detection data to third-party utilities for further analysis.

Detect RISK

As per MICROSOFT Identity Protection can detect following types of RISKS

  • Anonymous IP address use
  • Atypical travel
  • Malware linked IP address
  • Unfamiliar sign-in properties
  • Leaked credentials
  • Password spray
  • and more…

RISK signal also triggers respective remediation actions as

  • Enabling Multi Factor Authentication (MFA)
  • Reset users password using self-service password reset
  • Block users access until admin takes any action

Navigating Identity Protection in Azure AD

fig : Microsoft Entra admin center - navigating - Identity Protection
fig : Microsoft Entra admin center – navigating – Identity Protection
fig : Microsoft Entra admin center - Identity Protection blade
fig : Microsoft Entra admin center – Identity Protection blade

Identity Protection – OVERVIEW tab – TRENDS and TILES

  • On “Overview” tab of Identity Protection we have two sections
    • Trends
    • Tiles
  • TRENDS
    • Provides timeline of RISKS in our organization
    • Trends for new risky user detected
    • Trends for new risky sign-ins detected
fig : Microsoft Entra admin center - Identity Protection - Trends
fig : Microsoft Entra admin center – Identity Protection – Trends
  • TILES
    • Highlights the issues and respective actions to be taken
    • High risk users
    • Medium risk users
    • Unprotected risky sign-ins
    • Legacy authentication
fig : Microsoft Entra admin center - Identity Protection - Tiles
fig : Microsoft Entra admin center – Identity Protection – Tiles

License requirement for Identity Protection

  • Azure AD Premium P2 licenses

    Roles requires to access Identity Protection

    • Global Administrator – full access to Identity Protection
    • Security Administrator
      • Full access to Identity Protection
        • But can not reset password for user
      • Security Operator
        • View all Identity Protection reports and Overview
        • Dismiss user risk, confirm safe sign-in, confirm compromise
        • Can not configure or change the policies (RISK based policies – will discuss in next article)
        • Can not reset password for user
        • Can not configure alerts
        • Can not access security sign-in reports
      • Security Reader
        • View all Identity Protection reports and Overview
        • Can not configure or change the policies (RISK based policies – will discuss in next article)
        • Can not reset password for user
        • Can not configure alerts
        • Can not give feedback on detection
      • Global Reader
        • Read-only access to Identity Protection

        REFERENCES

        Thanks for reading the article !! Please feel free to discuss in case any issues / suggestions / thoughts / questions !

        HAVE A GREAT TIME AHEAD !!! LIFE IS BEAUTIFUL 🙂

        Prasham Sabadra

        LIFE IS VERY BEAUTIFUL. ENJOY THE WHOLE JOURNEY :) Founder of Microsoft 365 Junction, Speaker, Author, Learner, Developer, Passionate Techie. Certified Professional Workshop Facilitator / Public Speaker. Believe in knowledge sharing. Around 20+ years of total IT experience and 17+ years of experience in SharePoint and Microsoft 365 services Please feel free me to contact for any SharePoint / Microsoft 365 queries. I am also very much interested in behavioral (life changing) sessions like motivational speeches, Success, Goal Setting, About Life, How to live Life etc. My book - Microsoft 365 Power Shell hand book for Administrators and Beginners and 100 Power Shell Interview Questions - https://www.amazon.in/Microsoft-Administrators-Beginners-Interview-Questions/dp/9394901639/ref=tmm_pap_swatch_0?_encoding=UTF8&qid=1679029081&sr=8-11

        You may also like...

        Leave a Reply

        This site uses Akismet to reduce spam. Learn how your comment data is processed.

        Discover more from Microsoft 365

        Subscribe now to keep reading and get access to the full archive.

        Continue reading