Guidance for Microsoft Intune app protection policies (MAM) — protecting corporate data inside mobile apps with or without device enrollment. Covers MAM-WE for BYOD vs APP on managed devices, data-relocation controls (cut/copy/paste, Save As, encryption), app PIN/biometric and offline grace, selective wipe of…
Guidance for governing and managing Microsoft 365 collaboration sprawl — Teams/group lifecycle, sharing and guest access governance, and SharePoint Advanced Management — to keep the data estate secure and Copilot-ready. WHEN: Microsoft 365 governance, Teams sprawl, group lifecycle, guest access governance, external…
Guidance for remediating oversharing across Microsoft 365 (SharePoint, OneDrive, Teams, Exchange) using the Secure & Governed Data Foundation blueprint - a three-pillar program (remediate oversharing, set up guardrails, meet regulations) built on SharePoint Advanced Management data access governance, sensitivity and…
Guidance for hardening macOS endpoints managed by Microsoft Intune — automated device enrollment via Apple Business Manager (ABM), platform single sign-on (PSSO) with Entra ID, FileVault disk encryption escrow, security configuration profiles (Gatekeeper, XProtect, system extensions allowlist, firewall, login window…
Guidance for managing AI agents at enterprise scale with Microsoft Agent 365 - the control plane that lets admins observe, govern, and secure every agent (Microsoft, Copilot Studio, and third-party) from a single registry, using Microsoft Entra Agent ID for identity, Microsoft Purview for data security, and Microsoft…
Guidance for Microsoft Priva — privacy risk management and subject rights requests. Covers Priva Privacy Risk Management and Priva Subject Rights Requests to find privacy risks and fulfill data subject requests (GDPR/CCPA). WHEN: Microsoft Priva, privacy risk management, subject rights request, DSAR, data subject…
Guidance for rolling out passkeys (device-bound and synced) and FIDO2 security keys in Microsoft Entra ID as the primary phishing-resistant authentication method. Covers passkey types (device-bound in Microsoft Authenticator, synced passkeys via platform providers, hardware security keys), Conditional Access…
Guidance for designing Privileged Access Workstations (PAW) and the Microsoft privileged access strategy (enterprise access model, clean source principle, tiered admin isolation). Covers when to use Enterprise vs Specialized vs Privileged device profiles, hardening (Entra-join, Intune, app allowlisting, Credential…
Guidance for designing public key infrastructure (PKI) and certificate management on Azure and hybrid environments. Covers CA strategy (offline root + issuing CAs, AD CS vs managed/third-party vs public CA), Azure Key Vault certificates, HSM key protection, Entra certificate-based authentication (CBA), certificate…
Guidance for securing and governing AI agents (Microsoft 365 Copilot agents, Copilot Studio agents, and Security Copilot agents) with Microsoft Purview - applying DSPM for AI, DLP, sensitivity labels, Communication Compliance, and audit to agent data interactions and identities. WHEN: secure AI agents, govern Copilot…
Guidance for Microsoft Purview AI Hub (now part of Data Security Posture Management for AI) — discover, govern, and protect sensitive data flowing into AI applications (Microsoft 365 Copilot, Copilot Studio agents, ChatGPT, Gemini, third-party generative AI). Covers AI app discovery via Defender for Cloud Apps +…
Guidance for Microsoft Purview Audit (Standard and Premium) - logging and searching user/admin activity across Microsoft 365 for investigations and compliance. Covers tier differences, default and extended retention, high-value events, audit search UX, Office 365 Management Activity API / Microsoft Graph audit API…
Guidance for Microsoft Purview Communication Compliance — detecting and remediating policy violations and risky/inappropriate messages across Exchange, Teams, Viva Engage, and connected platforms, including AI prompt risks. Covers policy design, privacy controls, and remediation workflow. WHEN: communication…
Guidance for assessing and remediating oversharing before and during Microsoft 365 Copilot adoption, using SharePoint Advanced Management (SAM), sensitivity labels, restricted content discovery, and DLP for Copilot so Copilot only surfaces content users should access. Covers data access governance reports, EEEU…
Guidance for Microsoft Purview Customer Key and Double Key Encryption (DKE) — customer-controlled encryption for service-side data (Customer Key for Exchange/SharePoint/OneDrive/Teams/Purview) and client-side double encryption for highly sensitive documents (DKE via sensitivity labels and a customer-hosted key…
Guidance for the Microsoft Purview Unified Catalog (data catalog) — business-friendly discovery, governance domains, data products, glossary terms, and data quality on top of the Data Map. Covers governance domains, data products, and curation. WHEN: Purview data catalog, unified catalog, data products, governance…
Guidance for Microsoft Purview data classification and sensitivity labels - sensitive information types (SITs), trainable classifiers, exact data match, and sensitivity label taxonomy with auto-labelling. Covers building a label taxonomy, picking detection methods, and rolling out auto-labelling in simulation. WHEN…
Guidance for Microsoft Purview Data Lifecycle Management and Records Management - retention labels and policies to retain and delete content across Microsoft 365, plus declaring records. Covers retention strategy, adaptive vs static scopes, principle of precedence, disposition review, and regulatory records. WHEN…
Guidance for the Microsoft Purview Data Map - the foundation that scans and maps data sources across multicloud and on-premises estates to power cataloging and governance. Covers source registration, integration runtimes (managed vs self-hosted), scan rule sets, classifications, collections, and cost control. WHEN…
Guidance for designing baseline Microsoft Purview Data Loss Prevention (DLP) policies across Exchange, SharePoint, OneDrive, Teams, and Endpoint. Covers locations, conditions (SITs/labels/classifiers), severity-tiered actions, simulation mode, exception handling, Endpoint DLP onboarding, and tuning. WHEN: Purview DLP…
★not rated 173▲
+2 2mo agoA120 tokens
originalMIT
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: