Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.

Already on GitHub? Sign in to your account

Service Principal Security #1073

Open
5 tasks
schrolla opened this issue Apr 15, 2024 · 0 comments
Open
5 tasks

Service Principal Security #1073

schrolla opened this issue Apr 15, 2024 · 0 comments
Labels
epic A high-level objective issue encompassing multiple issues instead of a specific unit of work

Comments

@schrolla
Copy link
Collaborator

馃挕 Summary

Developing new policies around service principal security will lead to better security posture and outcomes for agencies implementing those policies. Investigate the impact of service principals on M365 service security and determine potential threats that could be addressed through new SCuBA M365 baseline policies. Compare security posture in the face of identified threats for tenants implementing proposed service principal policies to those without those policies.

Motivation and context

Implementation notes

Implementing service principal policy enhancements will include:

  • Identification of cyber threats that leverage service principal related vulnerabilities
  • Developing M365 configurations that address identified threats and vulnerabilities
  • Hands-on prototyping to determine the effects of service and policy changes on tenant security posture against those threats
  • Determining baseline changes to align policy with service principal improvements
  • Recommending baseline policy changes and updates based on investigation results

Acceptance criteria

  • Set of cyber threats considered in scope of this investigation has been defined
  • Tabletop or real-world attacks against tenant simulating these threats completed
  • Set of tenant configuration changes developed to mitigate vulnerabilities tested
  • New or updated baseline policies drafted for wider review
  • Decision to include/exclude draft policies in baselines has been made
@schrolla schrolla added the epic A high-level objective issue encompassing multiple issues instead of a specific unit of work label Apr 15, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
epic A high-level objective issue encompassing multiple issues instead of a specific unit of work
Projects
None yet
Development

No branches or pull requests

1 participant