{"id":17732,"date":"2020-02-13T18:52:06","date_gmt":"2020-02-14T02:52:06","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2020\/02\/13\/news-11467\/"},"modified":"2020-02-13T18:52:06","modified_gmt":"2020-02-14T02:52:06","slug":"news-11467","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2020\/02\/13\/news-11467\/","title":{"rendered":"Changing the Monolith\u2014Part 4: Quick tech wins for a cloud-first world"},"content":{"rendered":"<p><strong>Credit to Author: Todd VanderArk| Date: Thu, 13 Feb 2020 18:00:25 +0000<\/strong><\/p>\n<p>You may have heard that <a href=\"https:\/\/www.microsoft.com\/en-us\/itshowcase\/security\" target=\"_blank\" rel=\"noopener noreferrer\">identity is the \u201cnew\u201d perimeter<\/a>. Indeed, with the proliferation of <a href=\"https:\/\/www.microsoft.com\/securityinsights\/Phishing\" target=\"_blank\" rel=\"noopener noreferrer\">phishing attacks<\/a> over the past few years, one of the best ways to secure data is to ensure that identity\u2014the primary way we access data\u2014can be trusted.<\/p>\n<h3>How do we secure identity?<\/h3>\n<p>Start by evaluating <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2018\/12\/17\/zero-trust-part-1-identity-and-access-management\/\" target=\"_blank\" rel=\"noopener noreferrer\">how users are authenticating to all applications inside and outside the organization<\/a>. I say <strong>all applications,<\/strong> because it doesn\u2019t take much effort for a hacker to pivot from a low-value, non-sensitive application to a high-value and highly-sensitive application, quickly gaining access to confidential or restricted data.<\/p>\n<p>Similarly, Multi-Factor Authentication (MFA) must be enforced for <strong>all users<\/strong> as well, not just highly privileged users. Remember that it is simple for bad actors to pass-the-hash, run a Golden Ticket Attack, or use other techniques to elevate their privileges and gain access to sensitive data.<\/p>\n<p>Modern authentication encourages us to reduce vulnerable legacy authentication methods, including <a href=\"https:\/\/docs.microsoft.com\/en-us\/windows-server\/security\/kerberos\/kerberos-authentication-overview\" target=\"_blank\" rel=\"noopener noreferrer\">Kerberos<\/a> and <a href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/desktop\/SecAuthN\/microsoft-ntlm\" target=\"_blank\" rel=\"noopener noreferrer\">NTLM<\/a>. Additionally, modern authentication requires that we rely on <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/authentication\/concept-authentication-methods\" target=\"_blank\" rel=\"noopener noreferrer\">more than one factor of authentication for all users<\/a>. These factors range from something you know (password or one-time password), something you have (<a href=\"https:\/\/techcommunity.microsoft.com\/t5\/Azure-Active-Directory-Identity\/Hardware-OATH-tokens-in-Azure-MFA-in-the-cloud-are-now-available\/ba-p\/276466\" target=\"_blank\" rel=\"noopener noreferrer\">hardware token<\/a> or soft token), or something you are (<a href=\"https:\/\/www.microsoft.com\/en-us\/security\/technology\/identity-access-management\/passwordless\" target=\"_blank\" rel=\"noopener noreferrer\">biometrics<\/a> like 3D facial recognition or fingerprint matching).<\/p>\n<p><a href=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/02\/Changing-the-Monolith-Part-4-Quick-Tech-Wins-for-a-Cloud-First-World-1.jpg\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-90607 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/02\/Changing-the-Monolith-Part-4-Quick-Tech-Wins-for-a-Cloud-First-World-1.jpg\" alt=\"Image of a worker approving a sign-in from his phone.\" width=\"1679\" height=\"1120\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/02\/Changing-the-Monolith-Part-4-Quick-Tech-Wins-for-a-Cloud-First-World-1.jpg 1679w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/02\/Changing-the-Monolith-Part-4-Quick-Tech-Wins-for-a-Cloud-First-World-1-300x200.jpg 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/02\/Changing-the-Monolith-Part-4-Quick-Tech-Wins-for-a-Cloud-First-World-1-1024x683.jpg 1024w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/02\/Changing-the-Monolith-Part-4-Quick-Tech-Wins-for-a-Cloud-First-World-1-768x512.jpg 768w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/02\/Changing-the-Monolith-Part-4-Quick-Tech-Wins-for-a-Cloud-First-World-1-1536x1025.jpg 1536w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/02\/Changing-the-Monolith-Part-4-Quick-Tech-Wins-for-a-Cloud-First-World-1-293x195.jpg 293w\" sizes=\"auto, (max-width: 1679px) 100vw, 1679px\" \/><\/a><\/p>\n<p><em>Start with MFA.<\/em><\/p>\n<p>Requiring <a href=\"https:\/\/www.microsoft.com\/en-us\/itshowcase\/using-azure-multi-factor-authentication-at-microsoft-to-enhance-security\" target=\"_blank\" rel=\"noopener noreferrer\">MFA for all applications<\/a>, whether on-premises or in the cloud, is a great start. When using MFA, consider enforcing an <a href=\"https:\/\/www.microsoft.com\/en-us\/account\/authenticator\" target=\"_blank\" rel=\"noopener noreferrer\">authenticator app<\/a> or a <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/12409\/microsoft-account-app-passwords-and-two-step-verification\" target=\"_blank\" rel=\"noopener noreferrer\">one-time password<\/a> mechanism as they are typically not as susceptible to <a href=\"https:\/\/en.wikipedia.org\/wiki\/Man-in-the-middle_attack\" target=\"_blank\" rel=\"noopener noreferrer\">man-in-the-middle attacks<\/a>, compared to text-back codes or phone calls that may be intercepted with spoofing.<\/p>\n<p>The least vulnerable MFA mechanisms include <a href=\"https:\/\/www.microsoft.com\/en-us\/microsoft-365\/blog\/2018\/11\/20\/sign-in-to-your-microsoft-account-without-a-password-using-windows-hello-or-a-security-key\/\" target=\"_blank\" rel=\"noopener noreferrer\">FIDO2<\/a>, which utilizes a biometric device or USB hardware token like <a href=\"https:\/\/www.yubico.com\/2018\/04\/yubico-and-microsoft-introduce-passwordless-login\/\" target=\"_blank\" rel=\"noopener noreferrer\">YubiKey<\/a>, and machine learning systems that can provide conditional access based on <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2018\/12\/17\/zero-trust-part-1-identity-and-access-management\/\" target=\"_blank\" rel=\"noopener noreferrer\">Zero Trust<\/a> and time-of-authentication context.<\/p>\n<p>Here is the context commonly evaluated by machine learning authentication systems:<\/p>\n<ul>\n<li>Can an authentication token be obtained?<\/li>\n<li>Does the user have a valid username, password, and a second form of authentication (MFA), like a biometric validation (fingerprint or 3D facial recognition) through an authenticator app?<\/li>\n<li>What is the risk score of the user?<\/li>\n<li>Is the user authenticating from two places at nearly the same time (<a href=\"https:\/\/blog.networkats.com\/office-365-impossible-travel-the-security-control-your-network-is-missing\" target=\"_blank\" rel=\"noopener noreferrer\">Impossible Traveler<\/a>)?<\/li>\n<li>Has the user\u2019s password been discovered on the Dark Web because of an account and password database breach?<\/li>\n<li>Is this a reasonable time for the user to be signed in based upon past behavior?<\/li>\n<li>Is the user signing-in from an anonymous source like a Tor exit node?<\/li>\n<li>What is the risk score of the device?<\/li>\n<li>Has the device experienced unresolved risk in the last several days?<\/li>\n<li>Has the machine been exposed to <a href=\"https:\/\/www.microsoft.com\/securityinsights\/Malware\" target=\"_blank\" rel=\"noopener noreferrer\">malware<\/a>?<\/li>\n<li>Is the machine running a high-risk application?<\/li>\n<li>Are the antimalware signatures up to date?<\/li>\n<li>Are all the critical and high software patches applied?<\/li>\n<li>Are there sensitive documents on the device?<\/li>\n<\/ul>\n<p>With the enforcement of MFA, a single, unified MFA reduces the success of phishing attacks due to password reuse or <a href=\"https:\/\/medium.com\/microsoft-cybersecurity\/getting-smart-on-social-engineering-8922c59ae3c8\" target=\"_blank\" rel=\"noopener noreferrer\">social engineering.<\/a> With web-based Authentication-as-a-Service (AaaS) applications, MFA is easy to implement across the enterprise. Modern operating systems now enforce multifactor authentication by default, including <a href=\"https:\/\/www.microsoft.com\/en-us\/windows\/windows-hello\" target=\"_blank\" rel=\"noopener noreferrer\">Windows 10 Hello<\/a>, macOS, iOS, and Android. Most modern on-premises and cloud applications should be able to consume SSO authentication standards like SAML or OpenID and OAth2 authorization.<\/p>\n<h3>Moving toward a secure SSO posture<\/h3>\n<p>Implementing a single identity source for all applications leads the organization to a better and less time-consuming and complicated user experience, and an arguably more secure <a href=\"https:\/\/azure.microsoft.com\/en-us\/resources\/videos\/overview-of-single-sign-on\/\" target=\"_blank\" rel=\"noopener noreferrer\">SSO<\/a> posture by:<\/p>\n<ul>\n<li>Reducing the number of passwords that users need to remember or save\u2014quite often insecurely\u2014to access their applications.<\/li>\n<li>Introducing pass-through authentication and authorization, so that once a user authenticates to an operating system, they have unprompted access to both on-premises and cloud apps, using the same security token created when they signed in to the operating system using MFA.<\/li>\n<li>Reducing the threat of untimely termination\/missed identity decommissioning by decreasing &#8220;<a href=\"https:\/\/cloudblogs.microsoft.com\/opensource\/2019\/04\/04\/tutorial-identify-eliminate-secrets-sprawl-hashicorp-vault-azure\/\" target=\"_blank\" rel=\"noopener noreferrer\">identity sprawl<\/a>,&#8221; which is what you encounter when your organization has multiple identities in multiple applications per user. That is sometimes the result of non-integrated entities or not yet integrated entities and affiliates. B2B approaches to SSO can be explored to solve the problems associated with not integrating a business unit or operating group into the organization\u2019s core directory.<\/li>\n<\/ul>\n<p><a href=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/02\/Changing-the-Monolith-Part-4-Quick-Tech-Wins-for-a-Cloud-First-World-2.jpg\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-90608 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/02\/Changing-the-Monolith-Part-4-Quick-Tech-Wins-for-a-Cloud-First-World-2.jpg\" alt=\"Image of a hand hovering over a keyboard.\" width=\"1486\" height=\"992\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/02\/Changing-the-Monolith-Part-4-Quick-Tech-Wins-for-a-Cloud-First-World-2.jpg 1486w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/02\/Changing-the-Monolith-Part-4-Quick-Tech-Wins-for-a-Cloud-First-World-2-300x200.jpg 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/02\/Changing-the-Monolith-Part-4-Quick-Tech-Wins-for-a-Cloud-First-World-2-1024x684.jpg 1024w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/02\/Changing-the-Monolith-Part-4-Quick-Tech-Wins-for-a-Cloud-First-World-2-768x513.jpg 768w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/02\/Changing-the-Monolith-Part-4-Quick-Tech-Wins-for-a-Cloud-First-World-2-293x195.jpg 293w\" sizes=\"auto, (max-width: 1486px) 100vw, 1486px\" \/><\/a><\/p>\n<p><em>Considering user satisfaction is critical.<\/em><\/p>\n<p>MFA and SSO together <a href=\"https:\/\/medium.com\/microsoft-cybersecurity\/changing-the-monolith-part-2-building-alliances-whose-support-do-you-need-7ab03a889832\" target=\"_blank\" rel=\"noopener noreferrer\">increases user satisfaction, making the CISO a business enabler rather than a productivity and collaboration roadblock<\/a>. Cloud-based MFA and SSOP directory systems have been shown to be more available than on-premises directory or federation services with many cloud providers providing 99.9 percent uptime. A three-nines Service Level Agreement (SLA) is challenging to achieve on-premises with <a href=\"https:\/\/medium.com\/microsoft-cybersecurity\/changing-the-monolith-part-3-whats-your-process-6d13788c8c65\" target=\"_blank\" rel=\"noopener noreferrer\">limited IT staff and budget<\/a>!<\/p>\n<h3>Stay tuned<\/h3>\n<p>Stay tuned for the next installment of my Changing the Monolith series. In the meantime, check out the first three posts in the series:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.microsoft.com\/security\/blog\/2020\/01\/09\/changing-the-monolith-part-1-building-alliances-for-a-secure-culture\/\" target=\"_blank\" rel=\"noopener noreferrer\">Part 1: Building alliances for a secure culture<\/a><\/li>\n<li><a href=\"https:\/\/www.microsoft.com\/security\/blog\/2020\/01\/16\/changing-the-monolith-part-2-whose-support-do-you-need\/\" target=\"_blank\" rel=\"noopener noreferrer\">Part 2: Whose support do you need?<\/a><\/li>\n<li><a href=\"https:\/\/www.microsoft.com\/security\/blog\/2020\/01\/30\/changing-the-monolith-part-3-whats-your-process\/\" target=\"_blank\" rel=\"noopener noreferrer\">Part 3: What\u2019s your process?<\/a><\/li>\n<\/ul>\n<p>Also, bookmark the\u00a0<a href=\"https:\/\/www.microsoft.com\/security\/blog\/\" target=\"_blank\" rel=\"noopener noreferrer\">Security blog<\/a>\u00a0to keep up with our expert coverage on security matters and follow us at\u00a0<a href=\"https:\/\/twitter.com\/@MSFTSecurity\" target=\"_blank\" rel=\"noopener noreferrer\">@MSFTSecurity<\/a>\u00a0for the latest news and updates on cybersecurity.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/www.microsoft.com\/security\/blog\/2020\/02\/13\/changing-the-monolith-part-4-quick-tech-wins-for-a-cloud-first-world\/\">Changing the Monolith\u2014Part 4: Quick tech wins for a cloud-first world<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/www.microsoft.com\/security\/blog\/\">Microsoft Security<a>.<\/p>\n<p><a href=\"https:\/\/www.microsoft.com\/security\/blog\/2020\/02\/13\/changing-the-monolith-part-4-quick-tech-wins-for-a-cloud-first-world\/\" target=\"bwo\" >https:\/\/blogs.technet.microsoft.com\/mmpc\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Todd VanderArk| Date: Thu, 13 Feb 2020 18:00:25 +0000<\/strong><\/p>\n<p>Transformation is a daunting task. In this series, I explore how change is possible when addressing the components of people and technology that make up an organization.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/www.microsoft.com\/security\/blog\/2020\/02\/13\/changing-the-monolith-part-4-quick-tech-wins-for-a-cloud-first-world\/\">Changing the Monolith\u2014Part 4: Quick tech wins for a cloud-first world<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/www.microsoft.com\/security\/blog\/\">Microsoft Security<a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10759,10378],"tags":[21872,3924,22063],"class_list":["post-17732","post","type-post","status-publish","format-standard","hentry","category-microsoft","category-security","tag-identity-and-access-management","tag-phishing","tag-zero-trust"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17732","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=17732"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17732\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=17732"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=17732"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=17732"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}