How to Use Restricted SharePoint Search and Data Access Governance Reports
Restricted SharePoint Search and data access governance reports help you control Copilot exposure while you fix oversharing. Here is how to use them.
Insights
Articles in Microsoft 365.
Restricted SharePoint Search and data access governance reports help you control Copilot exposure while you fix oversharing. Here is how to use them.
Use this checklist to remediate oversharing before and during Copilot rollout.
The short version: In September 2024, Microsoft expanded Copilot with new features — and new tools to fix the "oversharing" problem that stalled many...
On April 2, 2024, the US Cyber Safety Review Board (CSRB) published its report on the Storm-0558 intrusion, in which Chinese state actors used a stolen...
Cloud provider security failures can affect your data — but your contract often gives you little recourse. Here are security terms to negotiate or verify...
Use this checklist to review each major cloud provider's security each year.
The short version: In April 2024, a US government review board concluded that a Chinese hack of Microsoft's email systems "should never have happened" and...
Midnight Blizzard got into Microsoft through a forgotten test tenant and a legacy OAuth app with production access. Here is how to find similar risks in...
OAuth application abuse lets attackers access mailboxes and data with app-level permissions that bypass user MFA. These detections focus on privilege...
The short version: In January 2024, Russian state hackers read email of Microsoft's senior leaders. They got in through an old test account that didn't...
Copilot surfaces any content a user can access. Before broad rollout, fix the SharePoint and OneDrive permissions that would expose sensitive data. Here is...
Use this checklist before expanding Microsoft 365 Copilot beyond a pilot.
The short version: Microsoft 365 Copilot, available since late 2023, can find and summarize anything an employee has access to — instantly. In most...
On August 2, 2023, Microsoft reported that Midnight Blizzard — the Russian state actor also known as APT29 or Nobelium, linked to SolarWinds — was using...
Microsoft Teams external access lets users chat with people in other organizations. Attackers use it for phishing. Here is how to restrict it to what your...
Teams chat phishing arrives outside email defenses. These detections help spot suspicious external chats and their consequences.
The short version: In 2023, Russian state hackers used Microsoft Teams chat — not email — to trick people into approving login requests. Companies have...
Storm-0558 was detected because a customer had detailed mailbox access logs. Here is how to make sure your Microsoft 365 audit logging captures what you'd...
Forged or stolen tokens let attackers access mailboxes without normal sign-ins. Mailbox access audit events are often the only evidence.
The short version: In 2023, Chinese hackers read US government email by forging digital keys in Microsoft's systems. A government agency caught it — because...
On March 28, 2023, Microsoft announced Microsoft Security Copilot, a generative AI assistant for security teams built on OpenAI's GPT-4 and Microsoft's...
AI assistants for security operations can speed up triage and investigation — or add cost and noise. Here is a practical way to evaluate them.
Use this checklist before and during a pilot of an AI security assistant.
The short version: In 2023, Microsoft launched Security Copilot, an AI assistant for security teams. Many vendors followed. AI can make security analysts...