Laura Kokkarinen
Sulava
Software Architect
Finland
Closing the Loop: How a Small Security Team Refined an Enterprise-grade DLP solution with Graph API

Session Abstract

Managing an enterprise-grade DLP solution tends to mean getting buried under an endless mountain of audit logs, scrambling to apply exclusions and refinements to controls based on sporadic incident tickets, end-user complaints and assorted dumpster fires. For example, when users are constantly uploading files to an ever-changing array of cloud services, keeping your Endpoint DLP authorised domain list accurate to exclude approved services from file upload controls can rapidly overwhelm a small security team. This session introduces a practical, automated approach to solving this issue, based on a solution adopted successfully by real security teams in the field. We will explore how to set up a continuous refinement loop that does the heavy lifting for you, leveraging smart Endpoint DLP audit rules, the Graph API runHuntingQuery endpoint and Azure Logic Apps to bring actionable intelligence directly to security responsibles, right in the flow of everyday work in Teams. In this session, you will learn how to: - Set up dedicated Endpoint DLP rules and other prerequisites to silently monitor file uploads against your baseline of approved domains. - Use Logic Apps to automatically query the Graph API runHuntingQuery endpoint and gather audit events of unauthorised file uploads. - Filter weekly audit findings into a clean, concise and actionable report, supported by a more comprehensive CSV dataset. Deliver these insights straight into a Teams channel so admins can effortlessly review and update allowed domains in minutes. - The proven pattern explained and demonstrated in this session is one you can apply to countless other security and governance scenarios going forward, helping manage sprawl and helping keep your organisation secure with less friction. This session is well-suited for security responsibles and admins, IT pros, as well as anyone interested in effectively operationalising security solution refinement with limited resources.


Laura Kokkarinen

Laura is a software architect and developer passionate about application security and software development best practices on the Microsoft Cloud platform. She has been doing full-stack software development with Microsoft technologies professionally since 2011 and has focused entirely on Microsoft cloud services since 2017. She has a Bachelor's and a Master's in Computer Science (grad 2012). In addition to designing software architectures, writing code, and performing tasks related to application security, Laura blogs about technologies related to her work at https://laurakokkarinen.com and regularly speaks at international conferences. Sharing her knowledge comes naturally to her, and Laura has received the Microsoft Most Valuable Professional (MVP) award annually since 2019.


Back to speaker profile
Laura can deliver sessions in
English
Finnish
Relevant industries
Computer Software
Connect with Laura
d480faf6-f6a5-4b53-946d-c959edaa376b
82c6464f-8628-4cf3-992d-6d5840d6b7b0
2272e666-bf0d-4c17-9153-9f43661fe841

Report speaker profile

Reason for reporting this profile (multiple options possible)


Please select at least one option.

Please select at least one option.

Please select at least one option.

Please select at least one option.

Please select at least one option.
Please complete this required field.
Please complete this required field.

Thank you for reporting this profile, we are going to review it as soon as possible.