SlideShare a Scribd company logo
1 of 46
Ravikumar Sathyamurthy @shakthiravi
Microsoft MVP | Office Apps & Services
Understanding Microsoft Teams Security &
Compliance features and Plan for Governance
09/02/2019 www.anywherexchange.com
• Microsoft Teams Overview
• Understanding Security and Compliance for Teams
• Planning for Microsoft Teams Governance
• Learning Resources
• Demo
• Q&A
DIGITAL
TRANSFORMATION
The Modern
Workplace
The Classic
Workplace
work-life
blur
more
mobile
tech
savvy
multiple
devices
digital
generation
fast
paced
A complete, intelligent solution that empowers
everyone to be creative and work together, securely
Unlock
creativity
Built for
teamwork
Integrated
for simplicity
Intelligent
security
Microsoft 365
Office 365 + Windows 10 + Enterprise Mobility + Security
Microsoft 365: Universal Toolkit for Teamwork
Hub for TeamworkCo-AuthorConnect Across
the Organization
Intranets &
Content Management
Email & Calendar
TeamsOffice AppsYammerSharePointOutlook
Office 365 Groups
Single team membership
across apps and services
Microsoft Graph
Suite-wide intelligence
connecting people and content
Security and Compliance
Centralized policy management
Office 365 Groups
Microsoft 365 Teamwork: Where to start a
conversation
Outer LoopInner Loop
Files
Sites
Content
SharePoint
Email
Chat for today’s
teams
Communicate in the moment and
keep everyone in the know
Customizable for
each team
Tailor your workspace to include
content and capabilities your team
needs every day.
A hub for
teamwork
Give your team quick access to
information they need right in
Office 365
Security teams
trust
Get the enterprise-level security
and compliance features you
expect from Office 365.
Communicate
through chat, meetings & calls
Collaborate
with deeply integrated Office 365 apps
Customize& extend
with Office 365 apps, 3rd party apps,
processes, and devices
Work withconfidence
enterprise level security, compliance,
and manageability
Teams clients
Teams Services Skype Infrastructure
Office 365 platform
and services
Azure
Teams and Skype for Business
Admin Tools
Controls for managing
communications and Teams specific
features
M365 and Azure AD Admin
Tools
Controls for Groups,
Identity, Licenses, Access
Security & Compliance
Admin Tools
Controls for managing
Security & Compliance
across M365
https://admin.teams.microsoft.com/
PrivacySecurity
Security by design
• Data Encryption at rest and in transit
• Dedicated security professionals
• Threat models, Security Reviews, Automated
Security Tools
• Penetration testing with regular rotation of
3rd party penetration testers
• All keys stored in Azure Key Vault
• Admin: Screening, training, access control
• Host: Access control, anti-malware, patch
management, AAD Modern Authentication
• Network: Firewalls, edge routers
• Facility: Physical controls, video surveillance,
access control
• Bug Bounty Program (We pay friends, hackers
and researchers to find security bugs)
Privacy by design
• Data stored in-region based on tenant affinity
• No customer content accessible in logs or
telemetry
• Grant least privilege required to complete task
• Dedicated Privacy professionals
• Adhere to Office 365 data classification and
data handling standards
• Access to Production environments is locked
down
• GDPR
How compliant is Microsoft Teams? http://aka.ms/STP is where you can
download the audit reports
https://aka.ms/MicrosoftComplianceStan
dards for Microsoft Compliance
Standards Download
More than 950 Office 365 controls
• Access control
• Auditing and logging
• Identification and authorization
• Awareness and training
• Continuity planning
• Incident response
• Risk assessment
• Communication protection
• Information integrity
• Deployment Approvals and management
Ongoing compliance processes
• Recurring audits like SOC, FEDRAMP, ISO+
independent verification
Microsoft Teams Certification
Microsoft Cloud Services Verified with
International, Regional and Industry
specific standards and terms
Strong Privacy and Security Commitments
• ISO 27001
• ISO 27018
• EU Model Clauses (EUMC)
• GDPR
• HIPAA Business Associated Agreement
• SSAE 16 SOC 1 & SOC 2 Reports
• FedRAMP Moderate and High
• IRS 1075, UK Official (IL2)
• Health Information Trust Alliance
(HITRUST)
Contractual commitment to meet US and EU
data residency requirements
Controls
Capability Description
Archive Any content stored in any Teams related workload needs to be preserved immutably
Compliance Content search
Any content stored in any workload can be search through rich filtering capabilities and be exported to a specific container for
compliance and litigation support​.
eDiscovery – Messaging/Files
Rich in-place eDiscovery capabilities including case management, preservation, search, analysis and export to help our customers
simplify the eDiscovery process to quickly identify relevant data while decreasing cost and risk.
Legal hold
When any team or individual is put on In-Place Hold or litigation hold, the hold is placed on both the primary and the archive messages
(No edits or deletes).
Auditing and reporting All Team activities and business events must be captured and available for customer search and export.
Conditional Access and Intune MAM
Ensure that access to Microsoft Teams is restricted to devices that are compliant with IT Admin or Corporate Organization set policies
and security rules both for the Teams Apps and the services it uses under the hood. Includes MAC Support for Conditional Access as well.
Moderator support
The ability to have a moderator (owner of team) of a Team delete data from any user in the team that is inappropriate and mute users in
a team/channel.
Windows Information Protection
Windows Information Protection (WIP), previously known as enterprise data protection (EDP), helps to protect against this potential data
leakage without otherwise interfering with the employee experience. WIP also helps to protect enterprise apps like MS Teams.
Allowed List of Apps An Admin can control the list of 3P apps (bots, connectors, tabs) that can be used by end users within a tenant.
Retention / Preservation
Help organizations reduce the liabilities associated with messaging. The Customer can configure their tenant to retain data for a fixed
period of time or retain it with unlimited storage for different Teams workloads.
eDiscovery – Calling/Meetings
Rich in-place eDiscovery capabilities including case management, preservation, search, analysis and export to help our customers
simplify the eDiscovery process to quickly identify relevant data while decreasing cost and risk.
Data loss prevention (DLP)
Identify any sensitive data stored being transferred within or outside of Customer Organization in Teams to intercept and prevent
leakage​ for Files and Chat/Channel Messages.
Advanced Threat Protection
Support for safe files and safe links in Microsoft Teams to protect your organization from malicious attacks with the power of Office 365
Advanced threat protection
Business information Barriers Prevent exchanges or communication that could lead to conflicts of interest. (a.k.a. Ethical walls)
VDI Virtual Desktop support for Teams to serve requirements of regulated industries and users with virtual desktops
AvailableToday
Data Residency
Our Promise
If Customer provisions its tenant
in Australia, Canada, the
European Union, India, Japan,
the United Kingdom, or the
United States, Microsoft Teams
will store the following Customer
Data at rest only within that geo:
• Microsoft Teams chats,
channel messages, images,
voicemail, and contacts
• SharePoint Online site
content and the files stored
within that site
• Files uploaded to OneDrive
for Business
Canada east
North Central US
Dublin
East Asia
Southeast Asia
Amsterdam
UK West
AMERICAS EMEA APAC
181 countries | 40 languages
(NOTE: Hebrew and Arabic RTL languages now supported)
East USUS Gov Arizona
US Gov Texas
Canada central
UK South
West India
Central India
Japan East
Japan West
Australia East
Australia Southeast
In region In country US Gov
The compliance boundary is where Microsoft can manage the security and privacy of customer data
User Browser,
Desktop ,Mobile
compliance boundary
Microsoft
Teams
Guest user
Anonymous join to a
meeting
Federation
communication
Email a channel
Connectors
Apps/Bots
Tabs
Calling Plan (PSTN)
Push Notifications
(Mobile
Other Cloud
storage (3rd party)
Graph API
Giphy
2-way communication Inbound data Outbound data
Data posted to a channel
Data posted to a channel
Query to Giphy
Push notifications to Apple or Google to
notify mobile client
Optional Box, Dropbox, Google drive, Citrix
Fileshare
Any third-party tab is hosted outside the
compliance boundary
Any third-party App/bot or line of business app is
hosted outside the compliance boundary
Graph APIs can be exposed to line of
business apps or 3rd party apps
Enables inbound/outbound calling outside
the organization
Standard Teams
user
Guest added
via AAD B2B
Anonymous user
joining a meeting
Communication between
multiple tenants
Key
URL Preview
Get a preview of a URL that is posted to a
message
Image
Files
Voicemail
Message
Recording
Calendar
meeting
Contacts
Media service on Azure (using Blob storage)
Team files  SharePoint
Chat files  OneDrive for Business
Individual mailbox in Exchange
Chat service table storage (moving to Cosmos DB)
Media service on Azure (using Blob storage) (<24
hours)
Individual mailbox in Exchange
Exchange
Ingested to Exchange to enable compliance
Ingested to Exchange to enable compliance
Encoded to Stream
Telemetry Microsoft Data warehouse (No customer content)
Entity Storage Storage
Key data entities and location where data is stored at rest
How Teams Enables Information Protection
Ingestion flow of Teams data to both Exchange and SharePoint for Teams Files and Messages
Ingestion flow of Teams Meetings and calling data to Exchange
For the full Microsoft Teams experience, every user should be enabled for Exchange Online,
SharePoint Online, OneDrive for Business and Office 365 Group creation.
https://docs.microsoft.com/en-us/microsoftteams/exchange-teams-interact
Exchange Online
✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓
Exchange Online
Dedicated vNext
✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓
Exchange Online
Dedicated –
Legacy
Yes (must
be on
allowed
list)
✕ ✕
Yes (must
be on
allowed
list)
✓ ✕ ✕ ✓ ✓ ✕
Yes
(Exchange
2013+)*
✕ ✓ ✓
Exchange on-
premises
Yes (must
be on
allowed
list)
✕ ✕
Yes (must
be on
allowed
list)
✓
Exchange
2016 CU3
or later
✕ ✓ ✓ ✕
Yes
(Exchange
2013+)*
✕ ✓ ✓
Retention Policies for Microsoft Teams
Features Available
Retention Policies for
Teams Chat and Channel
Messages
Note: includes ability to target specific
Teams for channel messages and Users
for 1xN chat
Now
Support for retention
policies for Teams Files
Now
Support for Preservation
and Deletion policies >
30 days
Now
Support for Deletion
Policies under 30 days
Coming soon …
Support for Advanced
Retention settings
Future
DLP Mode
- Passive
- Intercept
Sharing of data
- Internal
- External
DLP Provider
- Microsoft
- 3rd Party
Protection
- Messaging
- Files
Top Scenarios:
 Files Protected through Onedrive and SharePoint DLP
 Support for Office 365 DLP (80 sensitive types supported)
 Support for 3rd Party DLP providers through:
 Graph Webhook (an event API) to listen to all Teams
messages via admin approved 3rd Party app
 Graph API to update message with DLP Violation
Information barriers are designed
to properly control the flow of
information from one part of the
organization (IB group) to another
(IB group) to avoid conflicts of
interest
Workloads involved:
• Teams
• OD4B, SPO
• Exchange
Proposed Scope
Scenarios
 Group A cannot communicate with Group B
 Group C cannot communicate outside of its group
Events that require IB policy evaluation
 Add member to a Team (or underlying group)
 New 1xN Chats
 Join team meeting/call/screen sharing
Retroactive scenarios for IB Policy changes
 Existing chat threads
 Membership in a Team
• RBAC ( Role Based Access
Control)
• Teams Settings
• Messaging Policies
• Meeting Settings
• Live Event Policies
• External Access
• Guest Access
• Ability to create teams
• Naming of teams
• Classification of teams
• Retention Policies
• Expiration Policies
Feature Set Controls Where to find them New roles
Meeting TeamsMeetingPolicy
TeamsMeetingConfiguration
TeamsGuestMeetingConfiguration
TeamsMeetingBroadcastPolicy
TeamsMeetingBroadcastConfiguration
MS Teams & Skype for Business Admin Center/Skype for Business
PowerShell Module
TSA/TCA
Messaging TeamsMessagingPolicy
TeamsGuestMessagingConfiguration
ExternalAccess (Federation configuration)
MS Teams & Skype for Business Admin Center/Skype for Business
PowerShell Module
TSA
Calling TeamsCallingPolicy
TeamsGuestCallingConfiguration
MS Teams & Skype for Business Admin Center/Skype for Business
PowerShell Module
TSA/TCA (TCA no guest config)
Teams core
configuration
TeamsClientConfiguration
TeamsUpgradePolicy
Skype for Business PowerShell Module TSA
Team Collab GuestAccess
ExternalSharing
Naming Policy
Expiry Policy
Classification
Who can create groups
Azure Active Directory Admin Center/Azure Active Directory Preview
PowerShell Module
n/a
Security &
Compliance
Conditional Access Policies
Safe Attachments
eDiscovery
Content Search
Retention Policy
AAD Admin Center
O365 Security & Compliance Center
n/a
Feature Set Tools Where to find
Meeting/Calling Call analytics
Conference bridge/telephone number
management/voice routing
configurations*
Call quality dashboard (linked)
Manage users – audio conferencing, policy
assignment
Microsoft Teams & Skype for Business Admin
Center/Skype for Business PowerShell Module
Team Collab Manage teams (preview) Microsoft Teams & Skype for Business Admin
Center and Microsoft Teams PowerShell Module
Security &
Compliance
Content search
Audit log
Office 365 Security and Compliance Center
BRK2159: What's new in Microsoft Teams,
BRK3118: Microsoft Teams Architecture Update
BRK3135: Learn more about security and compliance for Teams
BRK3140: Microsoft Teams in the Government Cloud
BRK3170: Driving Teams Adoption: Enabling the modern workplace
with O365 & Microsoft Teams
BRK4012: How to manage Microsoft Teams effectively
Admin training for Microsoft Teams
Coffee in the Cloud Series
 Foundations - Core Components of Microsoft Teams
 Governance, management and lifecycle in Microsoft Teams
Microsoft Service Adoption Specialist Course and Certification
http://aka.ms/teamscommunity
https://aka.ms/Teamsblog
Microsoft Ignite Sessions
Learning / Training
Official Documentation
Microsoft Tech Community
Microsoft Teams technical documentation
Plan for governance in Teams
Governance quick start for Microsoft Teams
Overview of security and compliance in Microsoft Teams
Roadmap
Microsoft 365 Roadmap
Skype for Business to Microsoft Teams Capabilities Roadmap
Q&A

More Related Content

What's hot

Microsoft Teams Preview - Technical Overview
Microsoft Teams Preview - Technical OverviewMicrosoft Teams Preview - Technical Overview
Microsoft Teams Preview - Technical OverviewOlivier Carpentier
 
Securing Team, SharePoint, and OneDrive in Microsoft 365 - M365VM
Securing Team, SharePoint, and OneDrive in Microsoft 365 - M365VMSecuring Team, SharePoint, and OneDrive in Microsoft 365 - M365VM
Securing Team, SharePoint, and OneDrive in Microsoft 365 - M365VMDrew Madelung
 
Introduction to Microsoft 365 Enterprise
Introduction to Microsoft 365 EnterpriseIntroduction to Microsoft 365 Enterprise
Introduction to Microsoft 365 EnterpriseRobert Crane
 
Microsoft 365 Enterprise Security with E5 Overview
Microsoft 365 Enterprise Security with E5 OverviewMicrosoft 365 Enterprise Security with E5 Overview
Microsoft 365 Enterprise Security with E5 OverviewDavid J Rosenthal
 
Extending your Information Architecture to Microsoft Teams
Extending your Information Architecture to Microsoft TeamsExtending your Information Architecture to Microsoft Teams
Extending your Information Architecture to Microsoft TeamsChristian Buckley
 
Microsoft 365 business presentation
Microsoft 365 business presentationMicrosoft 365 business presentation
Microsoft 365 business presentationGordon Pong
 
TeamsNation 2022 - Governance for Microsoft Teams - A to Z.pptx
TeamsNation 2022 - Governance for Microsoft Teams - A to Z.pptxTeamsNation 2022 - Governance for Microsoft Teams - A to Z.pptx
TeamsNation 2022 - Governance for Microsoft Teams - A to Z.pptxJasper Oosterveld
 
IRMS UG Principles of Retention in Microsoft 365
IRMS UG Principles of Retention in Microsoft 365IRMS UG Principles of Retention in Microsoft 365
IRMS UG Principles of Retention in Microsoft 365Joanne Klein
 
Azure Security Overview
Azure Security OverviewAzure Security Overview
Azure Security OverviewAllen Brokken
 
Innovation morning power platform
Innovation morning power platformInnovation morning power platform
Innovation morning power platformClaudia Angelelli
 
Microsoft Teams Governance and Security Best Practices - Joel Oleson
Microsoft Teams Governance and Security Best Practices - Joel OlesonMicrosoft Teams Governance and Security Best Practices - Joel Oleson
Microsoft Teams Governance and Security Best Practices - Joel OlesonJoel Oleson
 
Governance, Risk and Compliance and you | CollabDays Bletchley Park 2022
Governance, Risk and Compliance and you | CollabDays Bletchley Park 2022Governance, Risk and Compliance and you | CollabDays Bletchley Park 2022
Governance, Risk and Compliance and you | CollabDays Bletchley Park 2022Nikki Chapple
 
SharePoint and Teams Integration Better Together Webinar
SharePoint and Teams Integration Better Together WebinarSharePoint and Teams Integration Better Together Webinar
SharePoint and Teams Integration Better Together WebinarJoel Oleson
 
Microsoft Azure Security Overview
Microsoft Azure Security OverviewMicrosoft Azure Security Overview
Microsoft Azure Security OverviewAlert Logic
 
Labelling in Microsoft 365 - Retention & Sensitivity
Labelling in Microsoft 365 - Retention & SensitivityLabelling in Microsoft 365 - Retention & Sensitivity
Labelling in Microsoft 365 - Retention & SensitivityDrew Madelung
 
Proactive Governance & Adoption In Microsoft 365 - M365Ottawa
Proactive Governance & Adoption In Microsoft 365 - M365OttawaProactive Governance & Adoption In Microsoft 365 - M365Ottawa
Proactive Governance & Adoption In Microsoft 365 - M365OttawaRichard Harbridge
 

What's hot (20)

Microsoft Teams Preview - Technical Overview
Microsoft Teams Preview - Technical OverviewMicrosoft Teams Preview - Technical Overview
Microsoft Teams Preview - Technical Overview
 
Securing Team, SharePoint, and OneDrive in Microsoft 365 - M365VM
Securing Team, SharePoint, and OneDrive in Microsoft 365 - M365VMSecuring Team, SharePoint, and OneDrive in Microsoft 365 - M365VM
Securing Team, SharePoint, and OneDrive in Microsoft 365 - M365VM
 
Introduction to Microsoft 365 Enterprise
Introduction to Microsoft 365 EnterpriseIntroduction to Microsoft 365 Enterprise
Introduction to Microsoft 365 Enterprise
 
Microsoft 365 Enterprise Security with E5 Overview
Microsoft 365 Enterprise Security with E5 OverviewMicrosoft 365 Enterprise Security with E5 Overview
Microsoft 365 Enterprise Security with E5 Overview
 
Extending your Information Architecture to Microsoft Teams
Extending your Information Architecture to Microsoft TeamsExtending your Information Architecture to Microsoft Teams
Extending your Information Architecture to Microsoft Teams
 
Microsoft 365 business presentation
Microsoft 365 business presentationMicrosoft 365 business presentation
Microsoft 365 business presentation
 
Microsoft Enterprise Voice
Microsoft Enterprise VoiceMicrosoft Enterprise Voice
Microsoft Enterprise Voice
 
TeamsNation 2022 - Governance for Microsoft Teams - A to Z.pptx
TeamsNation 2022 - Governance for Microsoft Teams - A to Z.pptxTeamsNation 2022 - Governance for Microsoft Teams - A to Z.pptx
TeamsNation 2022 - Governance for Microsoft Teams - A to Z.pptx
 
Modern Workplace with Microsoft 365
Modern Workplace with Microsoft 365Modern Workplace with Microsoft 365
Modern Workplace with Microsoft 365
 
Microsoft Teams Usage
Microsoft Teams UsageMicrosoft Teams Usage
Microsoft Teams Usage
 
IRMS UG Principles of Retention in Microsoft 365
IRMS UG Principles of Retention in Microsoft 365IRMS UG Principles of Retention in Microsoft 365
IRMS UG Principles of Retention in Microsoft 365
 
Azure Security Overview
Azure Security OverviewAzure Security Overview
Azure Security Overview
 
Innovation morning power platform
Innovation morning power platformInnovation morning power platform
Innovation morning power platform
 
Microsoft Teams Governance and Security Best Practices - Joel Oleson
Microsoft Teams Governance and Security Best Practices - Joel OlesonMicrosoft Teams Governance and Security Best Practices - Joel Oleson
Microsoft Teams Governance and Security Best Practices - Joel Oleson
 
Governance, Risk and Compliance and you | CollabDays Bletchley Park 2022
Governance, Risk and Compliance and you | CollabDays Bletchley Park 2022Governance, Risk and Compliance and you | CollabDays Bletchley Park 2022
Governance, Risk and Compliance and you | CollabDays Bletchley Park 2022
 
Microsoft Azure Overview
Microsoft Azure OverviewMicrosoft Azure Overview
Microsoft Azure Overview
 
SharePoint and Teams Integration Better Together Webinar
SharePoint and Teams Integration Better Together WebinarSharePoint and Teams Integration Better Together Webinar
SharePoint and Teams Integration Better Together Webinar
 
Microsoft Azure Security Overview
Microsoft Azure Security OverviewMicrosoft Azure Security Overview
Microsoft Azure Security Overview
 
Labelling in Microsoft 365 - Retention & Sensitivity
Labelling in Microsoft 365 - Retention & SensitivityLabelling in Microsoft 365 - Retention & Sensitivity
Labelling in Microsoft 365 - Retention & Sensitivity
 
Proactive Governance & Adoption In Microsoft 365 - M365Ottawa
Proactive Governance & Adoption In Microsoft 365 - M365OttawaProactive Governance & Adoption In Microsoft 365 - M365Ottawa
Proactive Governance & Adoption In Microsoft 365 - M365Ottawa
 

Similar to Understanding Microsoft Teams Security & Compliance features and plan for Governance

Securely Harden Microsoft 365 with Secure Score
Securely Harden Microsoft 365 with Secure ScoreSecurely Harden Microsoft 365 with Secure Score
Securely Harden Microsoft 365 with Secure ScoreJoel Oleson
 
Microsoft 365 | Modern workplace
Microsoft 365 | Modern workplaceMicrosoft 365 | Modern workplace
Microsoft 365 | Modern workplaceSiddick Elaheebocus
 
Office 365 Security, Privacy and Compliance - SMB Nation 2015
Office 365 Security, Privacy and Compliance - SMB Nation 2015Office 365 Security, Privacy and Compliance - SMB Nation 2015
Office 365 Security, Privacy and Compliance - SMB Nation 2015Robert Crane
 
Solvion Trendwerkstatt - Microsoft Teams
Solvion Trendwerkstatt - Microsoft TeamsSolvion Trendwerkstatt - Microsoft Teams
Solvion Trendwerkstatt - Microsoft TeamsHolzerKerstin
 
Primend praktiline konverents - Office 365 turvalisus
Primend praktiline konverents - Office 365 turvalisusPrimend praktiline konverents - Office 365 turvalisus
Primend praktiline konverents - Office 365 turvalisusPrimend
 
Microsoft Azure Rights Management
Microsoft Azure Rights ManagementMicrosoft Azure Rights Management
Microsoft Azure Rights ManagementDavid J Rosenthal
 
Agile IT EMS webinar series, session 1
Agile IT EMS webinar series, session 1Agile IT EMS webinar series, session 1
Agile IT EMS webinar series, session 1AgileIT
 
One name unify them all
One name unify them allOne name unify them all
One name unify them allBizTalk360
 
Pitching Microsoft 365
Pitching Microsoft 365Pitching Microsoft 365
Pitching Microsoft 365Robert Crane
 
Getting started with Microsoft Office 365 by Vignesh Ganesan
Getting started with Microsoft Office 365 by Vignesh GanesanGetting started with Microsoft Office 365 by Vignesh Ganesan
Getting started with Microsoft Office 365 by Vignesh GanesanVignesh Ganesan I Microsoft MVP
 
2018 11-29 - Future Of SharePoint - SharePoint Keynote and Security
2018 11-29 - Future Of SharePoint - SharePoint Keynote and Security2018 11-29 - Future Of SharePoint - SharePoint Keynote and Security
2018 11-29 - Future Of SharePoint - SharePoint Keynote and SecurityCreate IT
 
B2 - The History of Content Security: Part 2 - Adam Levithan
B2 - The History of Content Security: Part 2 - Adam LevithanB2 - The History of Content Security: Part 2 - Adam Levithan
B2 - The History of Content Security: Part 2 - Adam LevithanSPS Paris
 
Stay Productive, Collaborative, and Secure with Microsoft 365
Stay Productive, Collaborative, and Secure with Microsoft 365Stay Productive, Collaborative, and Secure with Microsoft 365
Stay Productive, Collaborative, and Secure with Microsoft 365Chris Bortlik
 
Azure-Casestudy.pptx
Azure-Casestudy.pptxAzure-Casestudy.pptx
Azure-Casestudy.pptxssuser2ae8bb
 
Emma Aubert | Information Protection
Emma Aubert | Information ProtectionEmma Aubert | Information Protection
Emma Aubert | Information ProtectionMicrosoft Österreich
 
Protect your data in / with the Cloud
Protect your data in / with the CloudProtect your data in / with the Cloud
Protect your data in / with the CloudGWAVA
 
Fundamentals of Microsoft 365 Security , Identity and Compliance
Fundamentals of Microsoft 365 Security , Identity and ComplianceFundamentals of Microsoft 365 Security , Identity and Compliance
Fundamentals of Microsoft 365 Security , Identity and ComplianceVignesh Ganesan I Microsoft MVP
 
Value Microsoft 365 E5 English
Value Microsoft 365 E5 EnglishValue Microsoft 365 E5 English
Value Microsoft 365 E5 EnglishGuillaume Lagache
 
MSFT Cloud Architecture Information Protection
MSFT Cloud Architecture Information ProtectionMSFT Cloud Architecture Information Protection
MSFT Cloud Architecture Information ProtectionKesavan Munuswamy
 
What is Microsoft Enterprise Mobility Suite and how to deploy it
What is Microsoft Enterprise Mobility Suite and how to deploy itWhat is Microsoft Enterprise Mobility Suite and how to deploy it
What is Microsoft Enterprise Mobility Suite and how to deploy itPeter De Tender
 

Similar to Understanding Microsoft Teams Security & Compliance features and plan for Governance (20)

Securely Harden Microsoft 365 with Secure Score
Securely Harden Microsoft 365 with Secure ScoreSecurely Harden Microsoft 365 with Secure Score
Securely Harden Microsoft 365 with Secure Score
 
Microsoft 365 | Modern workplace
Microsoft 365 | Modern workplaceMicrosoft 365 | Modern workplace
Microsoft 365 | Modern workplace
 
Office 365 Security, Privacy and Compliance - SMB Nation 2015
Office 365 Security, Privacy and Compliance - SMB Nation 2015Office 365 Security, Privacy and Compliance - SMB Nation 2015
Office 365 Security, Privacy and Compliance - SMB Nation 2015
 
Solvion Trendwerkstatt - Microsoft Teams
Solvion Trendwerkstatt - Microsoft TeamsSolvion Trendwerkstatt - Microsoft Teams
Solvion Trendwerkstatt - Microsoft Teams
 
Primend praktiline konverents - Office 365 turvalisus
Primend praktiline konverents - Office 365 turvalisusPrimend praktiline konverents - Office 365 turvalisus
Primend praktiline konverents - Office 365 turvalisus
 
Microsoft Azure Rights Management
Microsoft Azure Rights ManagementMicrosoft Azure Rights Management
Microsoft Azure Rights Management
 
Agile IT EMS webinar series, session 1
Agile IT EMS webinar series, session 1Agile IT EMS webinar series, session 1
Agile IT EMS webinar series, session 1
 
One name unify them all
One name unify them allOne name unify them all
One name unify them all
 
Pitching Microsoft 365
Pitching Microsoft 365Pitching Microsoft 365
Pitching Microsoft 365
 
Getting started with Microsoft Office 365 by Vignesh Ganesan
Getting started with Microsoft Office 365 by Vignesh GanesanGetting started with Microsoft Office 365 by Vignesh Ganesan
Getting started with Microsoft Office 365 by Vignesh Ganesan
 
2018 11-29 - Future Of SharePoint - SharePoint Keynote and Security
2018 11-29 - Future Of SharePoint - SharePoint Keynote and Security2018 11-29 - Future Of SharePoint - SharePoint Keynote and Security
2018 11-29 - Future Of SharePoint - SharePoint Keynote and Security
 
B2 - The History of Content Security: Part 2 - Adam Levithan
B2 - The History of Content Security: Part 2 - Adam LevithanB2 - The History of Content Security: Part 2 - Adam Levithan
B2 - The History of Content Security: Part 2 - Adam Levithan
 
Stay Productive, Collaborative, and Secure with Microsoft 365
Stay Productive, Collaborative, and Secure with Microsoft 365Stay Productive, Collaborative, and Secure with Microsoft 365
Stay Productive, Collaborative, and Secure with Microsoft 365
 
Azure-Casestudy.pptx
Azure-Casestudy.pptxAzure-Casestudy.pptx
Azure-Casestudy.pptx
 
Emma Aubert | Information Protection
Emma Aubert | Information ProtectionEmma Aubert | Information Protection
Emma Aubert | Information Protection
 
Protect your data in / with the Cloud
Protect your data in / with the CloudProtect your data in / with the Cloud
Protect your data in / with the Cloud
 
Fundamentals of Microsoft 365 Security , Identity and Compliance
Fundamentals of Microsoft 365 Security , Identity and ComplianceFundamentals of Microsoft 365 Security , Identity and Compliance
Fundamentals of Microsoft 365 Security , Identity and Compliance
 
Value Microsoft 365 E5 English
Value Microsoft 365 E5 EnglishValue Microsoft 365 E5 English
Value Microsoft 365 E5 English
 
MSFT Cloud Architecture Information Protection
MSFT Cloud Architecture Information ProtectionMSFT Cloud Architecture Information Protection
MSFT Cloud Architecture Information Protection
 
What is Microsoft Enterprise Mobility Suite and how to deploy it
What is Microsoft Enterprise Mobility Suite and how to deploy itWhat is Microsoft Enterprise Mobility Suite and how to deploy it
What is Microsoft Enterprise Mobility Suite and how to deploy it
 

Recently uploaded

Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoffsammart93
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusZilliz
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProduct Anonymous
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...apidays
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...Zilliz
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxRustici Software
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...apidays
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Orbitshub
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdfSandro Moreira
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingEdi Saputra
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Victor Rentea
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsNanddeep Nachan
 
WSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering DevelopersWSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering DevelopersWSO2
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobeapidays
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century educationjfdjdjcjdnsjd
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWERMadyBayot
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAndrey Devyatkin
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...apidays
 
Platformless Horizons for Digital Adaptability
Platformless Horizons for Digital AdaptabilityPlatformless Horizons for Digital Adaptability
Platformless Horizons for Digital AdaptabilityWSO2
 

Recently uploaded (20)

Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
Understanding the FAA Part 107 License ..
Understanding the FAA Part 107 License ..Understanding the FAA Part 107 License ..
Understanding the FAA Part 107 License ..
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
WSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering DevelopersWSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering Developers
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Platformless Horizons for Digital Adaptability
Platformless Horizons for Digital AdaptabilityPlatformless Horizons for Digital Adaptability
Platformless Horizons for Digital Adaptability
 

Understanding Microsoft Teams Security & Compliance features and plan for Governance

  • 1. Ravikumar Sathyamurthy @shakthiravi Microsoft MVP | Office Apps & Services Understanding Microsoft Teams Security & Compliance features and Plan for Governance 09/02/2019 www.anywherexchange.com
  • 2. • Microsoft Teams Overview • Understanding Security and Compliance for Teams • Planning for Microsoft Teams Governance • Learning Resources • Demo • Q&A
  • 4.
  • 5.
  • 6.
  • 9.
  • 10. A complete, intelligent solution that empowers everyone to be creative and work together, securely Unlock creativity Built for teamwork Integrated for simplicity Intelligent security Microsoft 365 Office 365 + Windows 10 + Enterprise Mobility + Security
  • 11. Microsoft 365: Universal Toolkit for Teamwork Hub for TeamworkCo-AuthorConnect Across the Organization Intranets & Content Management Email & Calendar TeamsOffice AppsYammerSharePointOutlook Office 365 Groups Single team membership across apps and services Microsoft Graph Suite-wide intelligence connecting people and content Security and Compliance Centralized policy management
  • 12. Office 365 Groups Microsoft 365 Teamwork: Where to start a conversation Outer LoopInner Loop Files Sites Content SharePoint Email
  • 13.
  • 14. Chat for today’s teams Communicate in the moment and keep everyone in the know Customizable for each team Tailor your workspace to include content and capabilities your team needs every day. A hub for teamwork Give your team quick access to information they need right in Office 365 Security teams trust Get the enterprise-level security and compliance features you expect from Office 365.
  • 15. Communicate through chat, meetings & calls Collaborate with deeply integrated Office 365 apps Customize& extend with Office 365 apps, 3rd party apps, processes, and devices Work withconfidence enterprise level security, compliance, and manageability
  • 16.
  • 17. Teams clients Teams Services Skype Infrastructure Office 365 platform and services Azure Teams and Skype for Business Admin Tools Controls for managing communications and Teams specific features M365 and Azure AD Admin Tools Controls for Groups, Identity, Licenses, Access Security & Compliance Admin Tools Controls for managing Security & Compliance across M365
  • 19.
  • 20. PrivacySecurity Security by design • Data Encryption at rest and in transit • Dedicated security professionals • Threat models, Security Reviews, Automated Security Tools • Penetration testing with regular rotation of 3rd party penetration testers • All keys stored in Azure Key Vault • Admin: Screening, training, access control • Host: Access control, anti-malware, patch management, AAD Modern Authentication • Network: Firewalls, edge routers • Facility: Physical controls, video surveillance, access control • Bug Bounty Program (We pay friends, hackers and researchers to find security bugs) Privacy by design • Data stored in-region based on tenant affinity • No customer content accessible in logs or telemetry • Grant least privilege required to complete task • Dedicated Privacy professionals • Adhere to Office 365 data classification and data handling standards • Access to Production environments is locked down • GDPR
  • 21. How compliant is Microsoft Teams? http://aka.ms/STP is where you can download the audit reports https://aka.ms/MicrosoftComplianceStan dards for Microsoft Compliance Standards Download More than 950 Office 365 controls • Access control • Auditing and logging • Identification and authorization • Awareness and training • Continuity planning • Incident response • Risk assessment • Communication protection • Information integrity • Deployment Approvals and management Ongoing compliance processes • Recurring audits like SOC, FEDRAMP, ISO+ independent verification Microsoft Teams Certification Microsoft Cloud Services Verified with International, Regional and Industry specific standards and terms Strong Privacy and Security Commitments • ISO 27001 • ISO 27018 • EU Model Clauses (EUMC) • GDPR • HIPAA Business Associated Agreement • SSAE 16 SOC 1 & SOC 2 Reports • FedRAMP Moderate and High • IRS 1075, UK Official (IL2) • Health Information Trust Alliance (HITRUST) Contractual commitment to meet US and EU data residency requirements Controls
  • 22. Capability Description Archive Any content stored in any Teams related workload needs to be preserved immutably Compliance Content search Any content stored in any workload can be search through rich filtering capabilities and be exported to a specific container for compliance and litigation support​. eDiscovery – Messaging/Files Rich in-place eDiscovery capabilities including case management, preservation, search, analysis and export to help our customers simplify the eDiscovery process to quickly identify relevant data while decreasing cost and risk. Legal hold When any team or individual is put on In-Place Hold or litigation hold, the hold is placed on both the primary and the archive messages (No edits or deletes). Auditing and reporting All Team activities and business events must be captured and available for customer search and export. Conditional Access and Intune MAM Ensure that access to Microsoft Teams is restricted to devices that are compliant with IT Admin or Corporate Organization set policies and security rules both for the Teams Apps and the services it uses under the hood. Includes MAC Support for Conditional Access as well. Moderator support The ability to have a moderator (owner of team) of a Team delete data from any user in the team that is inappropriate and mute users in a team/channel. Windows Information Protection Windows Information Protection (WIP), previously known as enterprise data protection (EDP), helps to protect against this potential data leakage without otherwise interfering with the employee experience. WIP also helps to protect enterprise apps like MS Teams. Allowed List of Apps An Admin can control the list of 3P apps (bots, connectors, tabs) that can be used by end users within a tenant. Retention / Preservation Help organizations reduce the liabilities associated with messaging. The Customer can configure their tenant to retain data for a fixed period of time or retain it with unlimited storage for different Teams workloads. eDiscovery – Calling/Meetings Rich in-place eDiscovery capabilities including case management, preservation, search, analysis and export to help our customers simplify the eDiscovery process to quickly identify relevant data while decreasing cost and risk. Data loss prevention (DLP) Identify any sensitive data stored being transferred within or outside of Customer Organization in Teams to intercept and prevent leakage​ for Files and Chat/Channel Messages. Advanced Threat Protection Support for safe files and safe links in Microsoft Teams to protect your organization from malicious attacks with the power of Office 365 Advanced threat protection Business information Barriers Prevent exchanges or communication that could lead to conflicts of interest. (a.k.a. Ethical walls) VDI Virtual Desktop support for Teams to serve requirements of regulated industries and users with virtual desktops AvailableToday
  • 23. Data Residency Our Promise If Customer provisions its tenant in Australia, Canada, the European Union, India, Japan, the United Kingdom, or the United States, Microsoft Teams will store the following Customer Data at rest only within that geo: • Microsoft Teams chats, channel messages, images, voicemail, and contacts • SharePoint Online site content and the files stored within that site • Files uploaded to OneDrive for Business Canada east North Central US Dublin East Asia Southeast Asia Amsterdam UK West AMERICAS EMEA APAC 181 countries | 40 languages (NOTE: Hebrew and Arabic RTL languages now supported) East USUS Gov Arizona US Gov Texas Canada central UK South West India Central India Japan East Japan West Australia East Australia Southeast In region In country US Gov
  • 24. The compliance boundary is where Microsoft can manage the security and privacy of customer data User Browser, Desktop ,Mobile compliance boundary Microsoft Teams Guest user Anonymous join to a meeting Federation communication Email a channel Connectors Apps/Bots Tabs Calling Plan (PSTN) Push Notifications (Mobile Other Cloud storage (3rd party) Graph API Giphy 2-way communication Inbound data Outbound data Data posted to a channel Data posted to a channel Query to Giphy Push notifications to Apple or Google to notify mobile client Optional Box, Dropbox, Google drive, Citrix Fileshare Any third-party tab is hosted outside the compliance boundary Any third-party App/bot or line of business app is hosted outside the compliance boundary Graph APIs can be exposed to line of business apps or 3rd party apps Enables inbound/outbound calling outside the organization Standard Teams user Guest added via AAD B2B Anonymous user joining a meeting Communication between multiple tenants Key URL Preview Get a preview of a URL that is posted to a message
  • 25. Image Files Voicemail Message Recording Calendar meeting Contacts Media service on Azure (using Blob storage) Team files  SharePoint Chat files  OneDrive for Business Individual mailbox in Exchange Chat service table storage (moving to Cosmos DB) Media service on Azure (using Blob storage) (<24 hours) Individual mailbox in Exchange Exchange Ingested to Exchange to enable compliance Ingested to Exchange to enable compliance Encoded to Stream Telemetry Microsoft Data warehouse (No customer content) Entity Storage Storage Key data entities and location where data is stored at rest
  • 26. How Teams Enables Information Protection Ingestion flow of Teams data to both Exchange and SharePoint for Teams Files and Messages Ingestion flow of Teams Meetings and calling data to Exchange
  • 27. For the full Microsoft Teams experience, every user should be enabled for Exchange Online, SharePoint Online, OneDrive for Business and Office 365 Group creation. https://docs.microsoft.com/en-us/microsoftteams/exchange-teams-interact Exchange Online ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ Exchange Online Dedicated vNext ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ Exchange Online Dedicated – Legacy Yes (must be on allowed list) ✕ ✕ Yes (must be on allowed list) ✓ ✕ ✕ ✓ ✓ ✕ Yes (Exchange 2013+)* ✕ ✓ ✓ Exchange on- premises Yes (must be on allowed list) ✕ ✕ Yes (must be on allowed list) ✓ Exchange 2016 CU3 or later ✕ ✓ ✓ ✕ Yes (Exchange 2013+)* ✕ ✓ ✓
  • 28. Retention Policies for Microsoft Teams Features Available Retention Policies for Teams Chat and Channel Messages Note: includes ability to target specific Teams for channel messages and Users for 1xN chat Now Support for retention policies for Teams Files Now Support for Preservation and Deletion policies > 30 days Now Support for Deletion Policies under 30 days Coming soon … Support for Advanced Retention settings Future
  • 29. DLP Mode - Passive - Intercept Sharing of data - Internal - External DLP Provider - Microsoft - 3rd Party Protection - Messaging - Files Top Scenarios:  Files Protected through Onedrive and SharePoint DLP  Support for Office 365 DLP (80 sensitive types supported)  Support for 3rd Party DLP providers through:  Graph Webhook (an event API) to listen to all Teams messages via admin approved 3rd Party app  Graph API to update message with DLP Violation
  • 30. Information barriers are designed to properly control the flow of information from one part of the organization (IB group) to another (IB group) to avoid conflicts of interest Workloads involved: • Teams • OD4B, SPO • Exchange Proposed Scope Scenarios  Group A cannot communicate with Group B  Group C cannot communicate outside of its group Events that require IB policy evaluation  Add member to a Team (or underlying group)  New 1xN Chats  Join team meeting/call/screen sharing Retroactive scenarios for IB Policy changes  Existing chat threads  Membership in a Team
  • 31.
  • 32.
  • 33.
  • 34.
  • 35.
  • 36. • RBAC ( Role Based Access Control) • Teams Settings • Messaging Policies • Meeting Settings • Live Event Policies • External Access • Guest Access • Ability to create teams • Naming of teams • Classification of teams • Retention Policies • Expiration Policies
  • 37.
  • 38.
  • 39. Feature Set Controls Where to find them New roles Meeting TeamsMeetingPolicy TeamsMeetingConfiguration TeamsGuestMeetingConfiguration TeamsMeetingBroadcastPolicy TeamsMeetingBroadcastConfiguration MS Teams & Skype for Business Admin Center/Skype for Business PowerShell Module TSA/TCA Messaging TeamsMessagingPolicy TeamsGuestMessagingConfiguration ExternalAccess (Federation configuration) MS Teams & Skype for Business Admin Center/Skype for Business PowerShell Module TSA Calling TeamsCallingPolicy TeamsGuestCallingConfiguration MS Teams & Skype for Business Admin Center/Skype for Business PowerShell Module TSA/TCA (TCA no guest config) Teams core configuration TeamsClientConfiguration TeamsUpgradePolicy Skype for Business PowerShell Module TSA Team Collab GuestAccess ExternalSharing Naming Policy Expiry Policy Classification Who can create groups Azure Active Directory Admin Center/Azure Active Directory Preview PowerShell Module n/a Security & Compliance Conditional Access Policies Safe Attachments eDiscovery Content Search Retention Policy AAD Admin Center O365 Security & Compliance Center n/a
  • 40. Feature Set Tools Where to find Meeting/Calling Call analytics Conference bridge/telephone number management/voice routing configurations* Call quality dashboard (linked) Manage users – audio conferencing, policy assignment Microsoft Teams & Skype for Business Admin Center/Skype for Business PowerShell Module Team Collab Manage teams (preview) Microsoft Teams & Skype for Business Admin Center and Microsoft Teams PowerShell Module Security & Compliance Content search Audit log Office 365 Security and Compliance Center
  • 41.
  • 42.
  • 43.
  • 44. BRK2159: What's new in Microsoft Teams, BRK3118: Microsoft Teams Architecture Update BRK3135: Learn more about security and compliance for Teams BRK3140: Microsoft Teams in the Government Cloud BRK3170: Driving Teams Adoption: Enabling the modern workplace with O365 & Microsoft Teams BRK4012: How to manage Microsoft Teams effectively Admin training for Microsoft Teams Coffee in the Cloud Series  Foundations - Core Components of Microsoft Teams  Governance, management and lifecycle in Microsoft Teams Microsoft Service Adoption Specialist Course and Certification http://aka.ms/teamscommunity https://aka.ms/Teamsblog Microsoft Ignite Sessions Learning / Training Official Documentation Microsoft Tech Community Microsoft Teams technical documentation Plan for governance in Teams Governance quick start for Microsoft Teams Overview of security and compliance in Microsoft Teams Roadmap Microsoft 365 Roadmap Skype for Business to Microsoft Teams Capabilities Roadmap
  • 45.
  • 46. Q&A

Editor's Notes

  1. 9
  2. Recently Microsoft introduced Microsoft 365 to help foster a new culture of work. It’s a complete, intelligent solution that empowers everyone to be creative and work together, securely. It brings together the best of Microsoft with Office 365, Windows 10 and Enterprise Mobility + Security. We think this is an offering that can truly help you transform customer’s business. Microsoft 365 delivers on 4 key promises: • Unlocks creativity by enabling people to work naturally with ink, voice and touch, all backed by tools that utilize AI and machine learning. • Provides the broadest and deepest set of apps and services with a universal toolkit for teamwork, giving people flexibility and choice in how they connect, share and communicate. • Simplifies IT by unifying management across users, devices, apps and services. • Helps safeguard customer data, company data and intellectual property with built-in, intelligent security.
  3. Objective: Reinforce our teamwork position - Microsoft 365 meets the diverse needs of teams with an integrated solution that is secure We’ve designed Microsoft 365 to meet the unique needs of every group. For each of those categories of teamwork, Microsoft 365 includes a purpose-built application. Teams as the hub for teamwork where groups that actively engage and are working on core projects can connect and collaborate Yammer for people to connect across their company, sharing ideas on common topics of interest Outlook where teams can communicate in a familiar place, and can easily create modern distribution list with groups in Outlook SharePoint for keeping content at the center of teamwork, making files, sites and all types of content easily shareable and accessible across teams Office Apps – enabling co-authoring in familiar apps like Word, Excel, and PowerPoint With these tools coming together in Microsoft 365 – teams get a holistic solution. What’s unique about teamwork in Microsoft 365 is that all of these applications are built on an intelligent fabric - suite-wide membership service with O365 Groups; suite-wide discovery and intelligence with Microsoft Graph, and suite-wide security and compliance. Office 365 Groups - A membership service providing a single identity for teams across Office applications and services Microsoft Graph - Suite-wide intelligence that maps the connection of people and content to surface insights Security and Compliance - Proactive security that simplifies IT management with intelligence built-in
  4. Talk Track: When deciding how best to leverage our toolkit for your team needs, think about the type of work that needs to get done and the type of conversations your team needs to have. The inner loop includes people you work with regularly, actively communicating and working on projects to deliver against important goals and deliverables. For this type of interaction Microsoft Teams is the best tool, allowing you to actively engage with your team in a shared work space where you can work on files, chat, and even host meetings. Your outer loop includes people across your company who provide valuable information, that you openly connect with on common topics of interest. Yammer is the best tool for your outer loop, letting you openly connect across the company to solicit ideas, and share best practices on broader initiatives. Outlook remains a tried and true tool for conversations, and is useful for teams that want to quickly share and communicate in a familiar place Of course content and creativity is at the center of every team – the very reason teams come together to connect, whether it is collaboration on a new product strategy, a sales presentation or a key company initiative. SharePoint is the tool that keeps content at the center of teamwork, making files, sites and content easily shareable and accessible across teams and organizations.  SharePoint is tightly integrated with Teams, Yammer and Outlook in order to enable seamless content collaboration across conversation experiences. And it’s all connected through a suite-wide membership service with O365 Groups With these tools, and more, in our universal toolkit, the breadth, depth and integration across our portfolio is something that competitors just cannot match!
  5. Speaker notes: The workshop leader should stop the presentation at this point. Request a volunteer to share their screen and be the driver for the rest of the audience in the room. Lead a conversation that walks attendees through the checklist on the following slides. The audience should not see the checklist. They should just participate by actually using Teams. After the checklist is completed and the audience has had their first experience with Teams, you can return to the workshop to complete a deeper dive. Note: If the organization is brand new to Office 365 and has not enabled any other Office 365 workloads, some pre-work may be needed. The presenter will know this from the completed pre-engagement questionnaire, and this workshop should have been modified to account for any prerequisites. Run through the environmental checklist ahead of time, to be sure you understand your environment limitations before you do a live walkthrough. ***** Alternative workshop order: If workshop attendees are familiar with Teams, it may be beneficial to hide slides 9-12. This will allow you as the workshop lead to skip the introduction and engage the attendees in a live working session with the product. The decision on where to execute this portion of the workshop should be made prior to the workshop starting, if possible.
  6. Slide objective: Introduce Teams as part of the Office 365 collaboration portfolio Talking points: Teams fits in the Office 365 collaboration portfolio by giving teams easy access to the information they need in a dedicated hub for teamwork. Here, people find their team chat, content, people and tools living together in Office 365. There are four key attributes of Teams that help close-knit teams to perform at their best: The modern-day chat keeps everyone in the know with chat history, whether across the team or in a private chat It’s a dedicated hub for teamwork, where people have easy access to everyday apps such as Word, Excel, PowerPoint, websites, and OneNote – the apps teams rely on daily for getting work done Teams is customizable for the way different teams work, including publicly available APIs and bot frameworks Lastly, Teams is designed to provide a great collaboration experience while upholding our commitments to safeguard customer and user data, to protect their right to make decisions about that data, and to be transparent about what happens to that data
  7. 23
  8. Reference Microsoft Ignite session : Learn more about Security and Compliance for Microsoft Teams (BRK-3135)
  9. 29
  10. Reference: Microsoft Ignite session - How to manage Microsoft Teams effectively (BRK-4012)
  11. Reference: Microsoft Ignite session - How to manage Microsoft Teams effectively (BRK-4012)
  12. Reference: Microsoft Ignite session - How to manage Microsoft Teams effectively (BRK-4012)
  13. Reference : Governance, management and lifecycle in Microsoft Teams session from Coffee in the Cloud Series Link: https://www.youtube.com/watch?v=cOCWDYc_HLs
  14. Reference : Governance, management and lifecycle in Microsoft Teams session from Coffee in the Cloud Series Link: https://www.youtube.com/watch?v=cOCWDYc_HLs
  15. Reference: https://techcommunity.microsoft.com/t5/Microsoft-Teams/Microsoft-Teams-Resource-cheat-sheet/td-p/270796