Managing an enterprise-grade DLP solution tends to mean getting buried under an endless mountain of audit logs, scrambling to apply exclusions and refinements to controls based on sporadic incident tickets, end-user complaints and assorted dumpster fires. For example, when users are constantly uploading files to an ever-changing array of cloud services, keeping your Endpoint DLP authorised domain list accurate to exclude approved services from file upload controls can rapidly overwhelm a small security team. This session introduces a practical, automated approach to solving this issue, based on a solution adopted successfully by real security teams in the field. We will explore how to set up a continuous refinement loop that does the heavy lifting for you, leveraging smart Endpoint DLP audit rules, the Graph API runHuntingQuery endpoint and Azure Logic Apps to bring actionable intelligence directly to security responsibles, right in the flow of everyday work in Teams. In this session, you will learn how to: - Set up dedicated Endpoint DLP rules and other prerequisites to silently monitor file uploads against your baseline of approved domains. - Use Logic Apps to automatically query the Graph API runHuntingQuery endpoint and gather audit events of unauthorised file uploads. - Filter weekly audit findings into a clean, concise and actionable report, supported by a more comprehensive CSV dataset. Deliver these insights straight into a Teams channel so admins can effortlessly review and update allowed domains in minutes. - The proven pattern explained and demonstrated in this session is one you can apply to countless other security and governance scenarios going forward, helping manage sprawl and helping keep your organisation secure with less friction. This session is well-suited for security responsibles and admins, IT pros, as well as anyone interested in effectively operationalising security solution refinement with limited resources.
Laura is a software architect and developer passionate about application security and software development best practices on the Microsoft Cloud platform. She has been doing full-stack software development with Microsoft technologies professionally since 2011 and has focused entirely on Microsoft cloud services since 2017. She has a Bachelor's and a Master's in Computer Science (grad 2012). In addition to designing software architectures, writing code, and performing tasks related to application security, Laura blogs about technologies related to her work at https://laurakokkarinen.com and regularly speaks at international conferences. Sharing her knowledge comes naturally to her, and Laura has received the Microsoft Most Valuable Professional (MVP) award annually since 2019.