May 4, 2025
Trending News

Microsoft is providing SOC teams with more security tools to prevent attacks

  • May 7, 2024
  • 0

Microsoft has added new features to its Insider Risk Management tool, including a preview of risk management context in Microsoft Defender and the general availability of Copilot features

Microsoft is providing SOC teams with more security tools to prevent attacks

Ransomware

Microsoft has added new features to its Insider Risk Management tool, including a preview of risk management context in Microsoft Defender and the general availability of Copilot features in Microsoft Purview.

Microsoft Purview Insider Risk Management gives organizations the ability to correlate various signals such as unusual access patterns and data exfiltration to identify potential insider risks. These include IP theft, data breaches and security breaches.

Last year saw an increase in identity attacks, with an average of 4,000 password attacks per second, some of which resulted in compromised user credentials, leading to internal risks.

The tool allows companies to create data policies that meet their internal policies and requirements, while pseudonymizing users by default. Additionally, there are role-based access controls and audit logs to ensure user-level data protection.

Improved features for SOC teams

Recent updates include a public preview of Risk Management Context on the Microsoft Defender XDR user page. This allows SOC analysts with appropriate permissions to access an overview of users’ risk activities, helping them prioritize incidents and make more informed decisions during investigations.

Adaptive protection in Microsoft Purview dynamically adjusts security measures based on data insights and user behavior. This integration streamlines the application of preventative controls by embedding risk levels directly into data loss prevention and conditional access policies.

Expanding opportunities and visibility

Microsoft also announced the launch of new insider risk management features aimed at simplifying investigations and improving the user experience for data security teams. This includes enriching risk management with communications-related indicators and extending data security to Microsoft Fabric and other SaaS applications such as DropBox, GitHub, Box and AWS.

New features will be made available to customers in the coming months, including customizations to email insight notifications and the public preview of Adaptive Scopes, which allows administrators to dynamically assign members of users or groups based on attributes such as location or department define.

Source: IT Daily

Leave a Reply

Your email address will not be published. Required fields are marked *