Unemployable Graduate
Advertisement
  • Home
  • Education
  • Economics
  • Public Policy
  • Workforce
  • Videos
  • Privacy Policy
  • Contact Us
No Result
View All Result
Unemployable Graduate
  • Home
  • Education
  • Economics
  • Public Policy
  • Workforce
  • Videos
  • Privacy Policy
  • Contact Us
No Result
View All Result
Unemployable Graduate
No Result
View All Result
Home Public Policy

Addressing data security challenges in shared tenant

September 19, 2023
in Public Policy
0
Addressing data security challenges in shared tenant
190
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

Related articles

The policy impact of dissension within the Violence Against Women and Girls Movement – Policy & Politics Journal Blog

The policy impact of dissension within the Violence Against Women and Girls Movement – Policy & Politics Journal Blog

April 11, 2024
Never Worry about Home Security Again: Discover SFR’s Revolutionary Solution

Never Worry about Home Security Again: Discover SFR’s Revolutionary Solution

April 10, 2024


This is a common architecture we see throughout State and Local Government customers (figure 1). This scenario also exists in many multi-national organizations, as well as very large organizations with a centralized structure. For the public sector, agencies (or companies) are typically managed centrally by the State, City, or County’s central IT team: 

 

Leo_Ramirez_0-1695071816624.png

Figure 1

 

 

The operations or central IT team manages the tenant on behalf of the hosted agencies. This often presents challenges for both the tenant provider (central IT/Operations) and for the agencies, especially when it comes to data security policies.  For example, only central IT typically has access to the Microsoft Purview portal. What this means is that only central IT can: 

 

  • Create/manage data loss prevention policies 
  • Create/manage information protection label policies 
  • View data loss prevention alerts 
  • View audit events 

Often times this creates a lot of administrative overhead for central IT admins as they have responsibility for not only creating/managing policies, but also triaging alerts related to the agencies in the shared tenant. This can be very cumbersome, especially in centralized organizations that host 40, 50, 60, 70 or more agencies in the tenant. 

 

In addition, many times government agencies have specific regulatory requirements they need to comply with (for example – HIPAA, CJIS, IRS Pub 1075). Without the ability to create and manage data loss prevention and data protection policies, this can hinder their progress in ensuring they are meeting regulatory requirements. Moreover, without access to audit events and alerts, agencies are limited on demonstrating the effectiveness of their data protection / data privacy program. 

 

Administrative Units with RBAC scoping can help! Admin units allow you to subdivide your organization into distinct units and then assign specific admins that can manage only the members of that unit. 

 

Essentially, this helps solve use cases for central IT and agency admins!  

 

Here’s how: 

  • Central IT Admins can define granular user scopes in the Purview portal role permissions workflow and ring-fence roles to a specific set of users based on agency, department, geo, etc. 
  • Agency admins with granular user scopes can create and manage policies only for users within their scoped permissions. (without impacting other agencies/companies) 
  • Agency admins with granular user scopes can access dashboards to manage alerts and view audit events for ONLY their users. 

In Figure 2, think about the IT admins from each of these agencies: DOH, DHS, and DOT. With RBAC scoping and Admin Units, these admins can create policies for data loss prevention and information protection for their user groups, without impacting other agency users. In essence, they can ONLY see the policies they create and scope these policies to their users groups.  

 

Leo_Ramirez_1-1695071816627.png

Figure 2 

 

RBAC scoped permissions can also be uses for different role groups depending on the level of access you want to provide for the administrator. As depicted in Figure 2, you can assign the Information Protection Admin role to the “Data Protection Lead”, the Information Protection Investigator role to the “SOC Lead, and Information Protection Analyst role to a “SOC Analyst”. Each of these have different role-based permissions.  

 

To see which Purview Role groups can be assigned to Admin Units please see:  

Permissions in the Microsoft Purview compliance portal | Microsoft Learn 

 

While this blog is primarily focused on the data security solutions in Purview as they relate to Admin Units, below is a list of all the Purview solutions that currently support Admin units: 

 

Leo_Ramirez_2-1695071816630.png

Figure 3 

 

In order to configure administrative units, your organization needs to meet the below licensing prerequisites: 

Leo_Ramirez_3-1695071816631.png

Figure 4 

 

Let’s now see how you can create and use Admin Units based on a common use case in State and Local Government (multiple agencies hosted in a shared tenant managed by central IT): 

 

Use Case 

  • Contoso has 2 agencies in the tenant – DOH and DOT​ 
  • Contoso Compliance Administrators should be able to administer DLP policies entire Contoso tenant​. 
  • DOH Compliance Administrators should be able to administer DLP policies for ONLY users in DOH agency​. 
  • DOT Compliance Administrators should be able to administer DLP policies for ONLY users in DOT agency​. 

 

Leo_Ramirez_4-1695071816632.png

Figure 5  

 

 

Steps: 

  Step 1 – Create Administrative Units in Azure Portal​ for DOH and DOT – To be executed by Central IT: 

  1. Contoso Central IT signs in to the Microsoft Entra admin center as at least a Privileged Role Administrator. 
  2. Browse to Identity > Roles & admins > Admin units. 
  3. Select Add. 
  4. In the Name box, enter the name of the administrative unit “DOH Org”. Optionally, add a description of the administrative unit. 
  5. Click “Review+Create” and create the Admin unit. 
  6. Open the Admin unit that you just created and click on “Properties.” 
  7. Select “Membership Type” as “Dynamic User”. 
  8. Select Add dynamic query. 
  9. Use the rule builder to specify the dynamic membership rule as below. Here we have used the department attribute and set it to “DOH”. 

    Leo_Ramirez_5-1695071816633.png

    Figure 6  

  10. Follow steps 1 to 9 to create an admin unit for DOT.  
  11. We now have 2 admin units that we can start leveraging in the MS Purview portal. 

 

Reference links for creating admin units: 

Permissions in the Microsoft Purview compliance portal | Microsoft Learn 

 

Step2: Scope Purview Roles to Admin Units – To be executed by Central IT 

  • As per requirement in Figure 5, let’s assign Purview Role group Compliance Administrator to DOH IT admin to manage policies for DOH agency and assign Purview Role group Compliance Administrator to DOT IT admin to manage policies for DOT agency. 

For this: 

  1. Contoso Central IT navigates to Home – Microsoft Purview-> Roles & scopes-> Permissions. Use global admin or Contoso Compliance Administrator credentials. 
  2. Under “Microsoft Purview solutions”-> Click “Roles” 
  3. Select “Compliance Administrator”. 
  4. Click on “Choose Users” and add both the DOH and DOT admins. 
  5. Select the DOH Admin and then assign the “DOH Org” admin unit. 
  6. Similarly, select the DOT Admin and then assign the “DOT Org” admin unit. 
  7. So, we have now assigned both the departmental admins to their corresponding agency admin units. 
    1. Leo_Ramirez_6-1695071816635.png

       

       Figure 7  

Refer steps here add users or groups to a Microsoft Purview built-in role group. 

 

 

Step 3: Agency administration for DLP Policies 

  • DOH Admin to create DLP policy to protect content containing ePHI and Medical Terms for DOH employees. DOH Admin can check Activity Explorer for DLP rule matches of DOH users. 
  1. Login to Home – Microsoft Purview using DOH Admin credentials.  
  2. Go to “Data Loss Prevention” -> Click “Create policy”. 
  3. Choose “Medical and health” category-> Select “U.S. Health Insurance Act (HIPAA) Enhanced” template. 
  4. Give the name to the policy as “DOH DLP Policy”. 
  5. Then click “Add or Remove admin units”. 
  6. Select the admin units “DOH Org”. 
    1.  

      Leo_Ramirez_13-1695072410473.png

       

       Figure 8  

       

       

  7. Select all Exchange, OneDrive accounts and Teams and click Next. 
  8. Choose all default settings and finish creating your policy. 
  9. If you want to test the DLP action, make sure you selected “Turn it on right away” as the DLP Policy mode. 
  10. Now, if any DLP policy match for a user in DOH admin unit, the corresponding alert will be generated “Data Loss Prevention”->Alerts. 
  11. The DOH IT admin will be able to see DLP alerts only for their admin unit. Contoso IT admin will be able to see alerts for all users in the tenant. 
    1.  

      Leo_Ramirez_14-1695072470041.png

       

       Figure 9  

  12. The DOH IT admin will be able to see the Activity “DLPRulematches” for users in DOH Org within the Ms Purview Activity explorer. 
    1. Leo_Ramirez_9-1695071816639.pngFigure 10  

 

 

 

Please refer to the steps below to create and deploy DLP policies. 

Create and deploy a data loss prevention policy | Microsoft Learn 

 

 

  • Similarly, DOT admin can follow steps 1 to 12 above, to create DLP policy to protect content containing PII for DOT employees. DOT Admin can check Activity Explorer for DLP rules matches of DOT users. 

    Leo_Ramirez_10-1695071816640.png

     

     Figure 11  

     

     

    Leo_Ramirez_11-1695071816642.png

     

    Figure 12  

 

 

Similarly, agencies can also create & manage Information protection and Data lifecycle management policies for their own agencies. They can also check Audit logs, just for their own agencies. 

 

CONCLUSION: 

As you can see, administrative units and RBAC user scoping is quite simple to configure and deploy. This is a powerful feature that can be leveraged to solve for the most common use case we see in State and Local Government as it applies to shared tenants. Admin units with RBAC scoping can reduce administrative burden for central IT, while providing agencies with access to deploy policies and manage their alerts and audit events. In addition, central IT does not lose visibility into what agencies are deploying and they retain full control and visibility over all policies and audit events. Central IT can still see ALL policies that have been deployed in the Purview portal and can assist agencies when needed, instead of managing and creating all data security policies and triaging ALL alerts on behalf of the agencies. 

 

For more information on how central IT admins and agency admins can use admin units with RBAC scoping, please see the recording: https://youtu.be/69i4Cy2mdEg?si=ucybUvtAXAG1TbPTW 

 

Are you interested in giving Admin Units/RBAC scoping a try, but do not currently meet the licensing requirements? Well, you can easily request an in-product trial directly from the Purview portal (see figure 5). This trial will give you 90 days to try all G5/E5 Compliance solutions. 

 

Leo_Ramirez_12-1695071816643.png

Figure 5 

 

NOTE – Admin units with RBAC is currently available for Commercial customers and is scheduled to be available for GCC customers in October 2023 for Data Loss Prevention/Information Protection and Audit: 

 

DLP/MIP – Microsoft 365 Roadmap | Microsoft 365 

Audit – Microsoft 365 Roadmap | Microsoft 365 

 

If you like to learn more about SLG use cases for Microsoft Purview, please feel free to Join the Microsoft Purview Customer Community for SLG! (office.com).  

 

When you join this community, you will receive invitations for webinars that cover topics related to Microsoft Purview and answers to the #1 question government customers have - “What are other customers doing?” We cover use cases learned from the field and we share it back with the community. We also invite customer, industry, and Microsoft experts to have discussions covering topics related to data security, privacy, risk, data governance, and compliance.  





Source link

Share76Tweet48

Related Posts

The policy impact of dissension within the Violence Against Women and Girls Movement – Policy & Politics Journal Blog

The policy impact of dissension within the Violence Against Women and Girls Movement – Policy & Politics Journal Blog

April 11, 2024
0

By Leah McCabe Women’s movements often play a crucial role in highlighting the problem of violence against women and girls...

Never Worry about Home Security Again: Discover SFR’s Revolutionary Solution

Never Worry about Home Security Again: Discover SFR’s Revolutionary Solution

April 10, 2024
0

Leading telecommunications company SFR has partnered with Europ Assistance to introduce a brand new self-monitoring offer, “Maison Sécurisée”. This innovative...

Public Knowledge Responds to MPA Chairman and CEO Charles Rivkin on Site-blocking

Public Knowledge Responds to MPA Chairman and CEO Charles Rivkin on Site-blocking

April 10, 2024
0

By Shiva StellaApril 9, 2024 Today, Motion Picture Association Chairman and CEO Charles Rivkin delivered remarks confirming the organization is...

Discover VerifEye, the App That Sees Through Your Lies

Discover VerifEye, the App That Sees Through Your Lies

April 9, 2024
0

Free app VerifEye, developed by Converus, purports to detect dishonesty with an impressive 80% success rate, already making waves in...

AI Gone Rogue: Sparks of War from Fake News

AI Gone Rogue: Sparks of War from Fake News

April 9, 2024
0

April 5, 2024, marked a significant incident in the realm of digital misinformation when a fake news story about an...

Load More
  • Trending
  • Comments
  • Latest
Hilarious video explains principles of economics

Hilarious video explains principles of economics

August 21, 2022
HVAC Maintenance Checklist Templates: Download & Print for Free!

HVAC Maintenance Checklist Templates: Download & Print for Free!

May 18, 2023
Public Knowledge Responds to MPA Chairman and CEO Charles Rivkin on Site-blocking

Public Knowledge Responds to MPA Chairman and CEO Charles Rivkin on Site-blocking

April 10, 2024
Policy & Politics Journal Blog

Policy & Politics Journal Blog

August 14, 2022
Policy & Politics Journal Blog

Policy & Politics Journal Blog

0
Spotlighting interpretive approaches to public policy scholarship – Dr Tiffany Manuel on intersectionality – Policy & Politics Journal Blog

Spotlighting interpretive approaches to public policy scholarship – Dr Tiffany Manuel on intersectionality – Policy & Politics Journal Blog

0
Policy & Politics Highlights collection on policy and regulation August 2022 – October 2022 –free to access – Policy & Politics Journal Blog

Policy & Politics Highlights collection on policy and regulation August 2022 – October 2022 –free to access – Policy & Politics Journal Blog

0
Special issue blog series on Transformational Change through Public Policy. – Policy & Politics Journal Blog

Special issue blog series on Transformational Change through Public Policy. – Policy & Politics Journal Blog

0
Bernstein, The greatest 5 min. in music education

Bernstein, The greatest 5 min. in music education

April 11, 2024
The policy impact of dissension within the Violence Against Women and Girls Movement – Policy & Politics Journal Blog

The policy impact of dissension within the Violence Against Women and Girls Movement – Policy & Politics Journal Blog

April 11, 2024
Economic Surprises Could Fuel Fed Deja Vu for the 2010s – The Wall Street Journal

Economic Surprises Could Fuel Fed Deja Vu for the 2010s – The Wall Street Journal

April 11, 2024
Building a Standout Employer Brand:Strategies for HR Teams

Building a Standout Employer Brand:Strategies for HR Teams

April 11, 2024

Recent News

Bernstein, The greatest 5 min. in music education

Bernstein, The greatest 5 min. in music education

April 11, 2024
The policy impact of dissension within the Violence Against Women and Girls Movement – Policy & Politics Journal Blog

The policy impact of dissension within the Violence Against Women and Girls Movement – Policy & Politics Journal Blog

April 11, 2024

Categories

  • Economics
  • Education
  • Public Policy
  • Videos
  • Workforce

Newsletter

© 2022 All right reserved by unemployablegraduate.com

No Result
View All Result
  • Home
  • Education
  • Economics
  • Public Policy
  • Workforce
  • Videos
  • Privacy Policy
  • Contact Us

© 2022 All right reserved by unemployablegraduate.com

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
Cookie SettingsAccept All
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT