Skip to content
Menu
ChrisOnSecurity
  • Blog
  • Microsoft Security portals
  • Presentations
  • GitHub
  • About me
  • Impressum
  • Disclaimer
ChrisOnSecurity

What’s new: Microsoft 365 Security & Compliance December 2022

Posted on 14. December 202222. December 2022

Note:

All information subject to change; might be incomplete
List reflects status as of writing (December 13th, 2022; no updates afterwards)

Timeframe: Mid-November – Mid-December

The intention of this series of posts is to give an overview about security & compliance news I find relevant without going into that much detail.

Azure Active Directory

  • Soft delete option for administrative units
  • New provisioning connectors: Keepabl / Uber
  • iOS Authenticator App (version 6.6.8+) now FIPS 140 compliant
  • (GA) Workload Identities: https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/microsoft-entra-workload-identities-now-generally-available/ba-p/3402815
  • (Public Preview) IPv6 support in Azure Active Directory: https://learn.microsoft.com/en-us/troubleshoot/azure/active-directory/azure-ad-ipv6-support
  • (Public Preview) Enhanced company branding (SSPR, new wizard)
  • (Public Preview) Processing of dynamic group rules can now be paused
  • (Public Preview) Machine Learning additions to access reviews to find users with low affiliation
  • (Heads up) Number matching to be enforced in Microsoft Authenticator app starting February 27th, 2023

Microsoft Defender

Defender 365 Defender

  • New “Query Resource Report” in Advanced Hunting

Defender for Office 365

  • (Public Preview) Threat Explorer version 3

Defender for Endpoint

  • (GA) Integration of Corelight’s “Zeek” to bring deep packet inspection: https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/new-network-based-detections-and-improved-device-discovery-using/ba-p/3682111
  • (GA) Built-in protection: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/built-in-protection?view=o365-worldwide
  • Improved event tracking for removable storage devices: https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/announcing-new-removable-storage-management-features-on-windows/ba-p/3678197
  • (Good read) Advanced deployment guide for Linux: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/comprehensive-guidance-on-linux-deployment?view=o365-worldwide
  • Firmware assessment reports (part of the vulnerability management add-on)

Defender for Identity

  • New health alert: Active Directory advanced auditing
  • Enhanced detections for honeytoken accounts should now work as intended
  • Integration with MDE is deprecated, now works via M365 Defender

Defender for Cloud Apps

  • n/a

Microsoft Defender Threat Intelligence

  • n/a

Microsoft Sentinel

  • Logstash support updated: data transformation, output schema, log forwarding
  • Health monitoring for automation rules and playbooks
  • (Preview) Azure Monitor Agent now supports Common Event Format (CEF)
  • (Preview) Incident tasks bringing checklists for standardized incident management

Microsoft Purview

  • Information Protection scanner now migrated to the compliance portal: https://compliance.microsoft.com/compliancesettings/scanner_onboarding
  • Trainable Classifiers now also applicable to auto-labeling policies
  • Office 2212 will deactivate the AIP add-in by default (but can be overwritten): https://learn.microsoft.com/en-us/microsoft-365/compliance/sensitivity-labels-aip?view=o365-worldwide#how-to-configure-newer-versions-of-office-to-enable-the-aip-add-in

Thanks for reading!

Chris

Note

Please note that all content on this blog is provided ‘as is’ without any warranty.

@ChrisOnSecurity@infosec.exchange

Recent posts

  • What’s new: Microsoft 365 Security & Compliance December 2022
  • What’s new: Microsoft 365 Security & Compliance November 2022
  • Counter MFA spam attacks with Azure Active Directory
  • Windows 11 security – a first look
  • Conditional Access – device identification using certificates

@ChrisOnSecurity

Tweets by ChrisOnSecurity

Recent posts

  • What’s new: Microsoft 365 Security & Compliance December 2022
  • What’s new: Microsoft 365 Security & Compliance November 2022
  • Counter MFA spam attacks with Azure Active Directory
  • Windows 11 security – a first look
  • Conditional Access – device identification using certificates

Tags

Administration Administrative Units Android AV Azure Active Directory Azure AD Azure Sentinel Client Security Conditional Access Conditional Access App Control Defender ATP Delegation EDR EMS Enterprise Mobility + Security Identity Protection Information Protection & Compliance Linux M365 M365 E3 Mail Security MCAS MDAPT MDATP MFA Microsoft 365 Microsoft 365 E3 Microsoft 365 Security Microsoft Cloud App Security Microsoft Defender ATP Microsoft Ignite Mobile Security Monitoring Network Control Office 365 Office ATP passwordless Perimeter Security Baseline Session Control Sysmon Unified Incidents User submissions Web Content Filtering Windows 10 Enterprise
©2023 ChrisOnSecurity | WordPress Theme by Superbthemes.com
We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT