Microsoft Azure Sentinel

Microsoft Azure Sentinel

Microsoft Azure Sentiel is fasting becoming a very powerful SIEM and IMO, I think its going to take the lead for the following reasons;

For all of the above reason, I am going to learn Azure Sentinel in more depth, hopefully build a cyber range using my MSDN subscription.

Gaps

  • Certification
    • FIPS 140-2 Compliance
    • WCAG 2.1 (Section 508)
  • Multi-tenancy / MSSP
  • Local customer references
  • Transfer of logs from on-prem to Cloud is complicated networking, if you need to send SYSLOG via UDP to a Public cloud, its not going to work.
  • Assessing all your data sources and method to Azure Sentil is vital om-prem SIEM this isn’t as critical although you should do this as best practice, you can assumes experience SIEM vendor will support all obvious formats.
  • Encryption and Data Masking.
  • How do you get your Data out, priority lock is a huge problem for a SIEM platform, what happens to your data when if you decided to break the contract. Also, if you wish to access that data via a different platform
  • Datasources
  • Azure monitor and sentinel take up to 8 hours to populate a suspicious log.
  • I recall when everyone moved to Office 365 and didn’t bother to maintain a strong Email Security Gateway and just went with Office 365, allot of customers got hit with Crytolockers because of this decision. All for DX transformation. You need proper security experience people in your DX transformation or building SecOps as you will end up paying the price

Research

Azure Security Monitoring

Azure Security Monitoring

 

Monitoring Azure and or Cloud is not straight forward, you have to consider if logs are actually available via the cloud service and has security information. Its also necessary to consider, the Control Pane, Data Pane, Application and VM.

 

Sources

  • VMs
  • Azure Resources
  • Azure Office 365
  • Azure AD

Volume Licensing for Microsoft products and Online Services

Volume Licensing for Microsoft products and Online Services

https://www.microsoft.com/en-us/licensing/product-licensing/products.aspx

https://azure.microsoft.com/en-us/documentation/articles/remoteapp-officesubscription/

https://azure.microsoft.com/en-us/documentation/articles/remoteapp-o365/

Exchange Online using Outlook SPLA

Office 356 or Office SPLA

http://www.transparity.co.uk/blog/citrix/rolling-out-office-2016-365-on-citrix-hang-on-a-while/

Azure and Citrix Workspace Cloud

Azure and Citrix Workspace Cloud

 

Azure Cost Calculators

 

  • Demo platform to show capability with Azure and Citrix
  • Extend our own Citrix Platform and Infrastructure to Azure as first customer

Azure Constraints