Microsoft Defender now unifies SIEM and XDR

Microsoft Security Logo

At #Ignite2020 (September 2020), Microsoft announced a change to their Security and threat protection with a new, unique approach designed to “empower security professionals to get ahead of today’s complex threat landscape” with fully integrated SIEM and XDR (eXtended Detect and Response) tools from a single vendor so you get the best of both worlds. – much of the summary below is taken from the wider Microsoft Blog.

As part of this, Microsoft are unifying their XDR tech under the Microsoft Defender brand.

“The new Microsoft Defender is now the most comprehensive XDR in the market and prevents, detects, and responds to threats across identities, endpoints, applications, email, IoT, infrastructure, and cloud platforms”.

With Microsoft Defender, Microsoft are both rebranding our existing threat protection portfolio and adding new capabilities, including additional multi-cloud (Google Cloud and AWS) and multi-platform (Windows, Mac, Linux, Android, and iOS) support.

Microsoft Defender is delivered in two main areas,

  • Microsoft 365 Defender for end-user environments and
  • Azure Defender for cloud and hybrid infrastructure.

Microsoft 365 Defender

This delivers XDR capabilities for identities, endpoints, cloud apps, email, and documents, using AI to reduce the SOC’s work items. Microsoft claims this can consolidated 1,000 alerts to just 40 high-priority incidents and that built-in self-healing technology fully automates remediation with a success rate of over 70%, ensuring the SOC can focus on “other tasks” that better leverage their knowledge and expertise.

An image of the Microsoft 365 Defender dashboard.

As part of this, the following branding changes have also been made to the Microsoft 365 security services:

  • Microsoft Threat Protection is now Microsoft 365 Defender

  • Microsoft Defender ATP is now Microsoft Defender for Endpoint

  • Office 365 ATP is now Microsoft Defender for Office 365

  • Azure Advanced Threat Protection is now Microsoft Defender for Azure

As well as the name change, several new features are now also available or coming:

  • New mobile for Apple iOS (now in Preview) and Android support now released. As a result, Microsoft now delivers endpoint protection across all major OS platforms.
  • Extension of the current macOS support with addition of threat and vulnerability management.
  • Priority account protection in Microsoft Defender for Office 365 will help security teams focus on protection from phishing attacks for users who have access to the most critical and privileged information. 

Azure Defender

Azure Defender is an evolution of the Azure Security Center threat protection capabilities and is accessed from within Azure Security Center and delivers XDR capabilities to protect multi-cloud and hybrid workloads, including VMs, databases, containers, IoT, and more. 

An image of Defender.

Aligned with the Microsoft 365 brand changes, there are also new name changes as well as some new features naturally!

  • Azure Security Centre Standard is now Azure Defender for Servers
  • Azure Security Centre for IoT is now Azure Defender for IoT 
  • Advanced Threat Protection for SQL is now Azure Defender for SQL 

Along with the name change, these new features were also announced: 

  • New unified experience for Azure Defender that makes it easy to see which resources are protected and which need protection.
  • Added protection for SQL servers on-premises and in multi-cloud environments
  • Added protection for virtual machines in multi-cloud
  • Improved protections for containers, including Kubernetes-level policy management and continuous scanning of container images in container registries.
  • Support for operational technology networks with the integration of CyberX into Azure Defender for IoT.

The video below from Microsoft shows how it all works

Video from Microsoft Mechanics on the New Microsoft Defender

 

And finally…. let’s not forget Azure Sentinel

Whilst the XDR capabilities of Microsoft Defender delivered through Azure Defender and Microsoft 365 Defender provides rich insights and prioritised alerts, to gain visibility across your entire environment and include data from other security solutions such as firewalls and existing security tools, we connect Microsoft Defender to Azure Sentinel, Microsoft cloud-native SIEM.

Azure Sentinel is deeply integrated with Microsoft Defender so you can integrate your XDR data in only a few clicks and combine it with all your security data from across your entire enterprise.

An image of Azure Sentinel.

You can read the full Microsoft Blog on this here:

Microsoft Ignite ‘flooded’ with these incredible new #MicrosoftTeams enhancements

Day one of Ignite yesterday (Sept 22 2020), was full of many new announcements across Microsoft 365, Azure and Power Platform but day 1 was certainly dominated by a new stack of updates coming now or very soon to Microsoft Teams, with the list including well-being tools for employees, calling enhancements, new webinar features and breakout rooms and a whole lot more.

Here’s my review of the key new features. There’s also a quick video I recorded from the main Teams session…

Virtual Commute

With the virtual commute feature, Teams users will be able to schedule a virtual commute to structure their day so they can have a productive start in the morning and mindfully disconnect in the evening.

As part of Virtual Commute, Microsoft has partnered with Headspace to bring a curated set of mindfulness experiences and science-backed meditations into Teams based on the user’s day, and how busy their day appears from their activity across Teams and Office 365. This is designed to help make it easier for employees to find time to relax and recover and therefore better focus.

There’s a lot of activity happening in Teams, we can see that. We also hear people telling us that there are adverse effects and that leads us to product strategy and what you’re seeing at Ignite,” said Microsoft executive Jared Spataro.

The sudden transition to working from home during the pandemic has completely upended the lives of workers around the world.”

While many employees used to use their morning commute as a chance to relax or reflect on the day ahead of them, the switch to remote working has taken this personal time from them. To make matters worse, many organisations now expect their workers to begin their jobs right at the start of the day since they no longer need to travel to and from the office.

According to a study from Microsoft Research, commutes can serve as meaningful transitions at the beginning and end of the workday and in fact, the reflection done during this time can increase productivity by 12 to 15 percent.

New Well-being tools

New Insights in Teams powered by MyAnalytics and Workplace Analytics

With rollout starting in October and with new enhancements coming over the new few months, is a new set of well-being features and productivity insights for Microsoft Teams.

This will be powered by a combination of MyAnalytics and a new Workplace Analytics experience designed for Teams, Microsoft said that this aims to will gives individuals, managers, and business leaders powerful insights which are personalised about their roles and their teams within work and to ensure employees and employers can focus more effort and energy into their people (the heart of their business) helping everyone to focus on their work, and be their best.

Teams users will see recommended actions to help them  make changing their work habits and improving their productivity and well-being easier. Examples include suggested tasks for the day, reminders to have breaks and taking time away from the screen which will be delivered to your Outlook inbox.

In addition, a new stay connected experience will also help individuals strengthen relationships with their colleagues by making it easy to praise top collaborators for key achievements and to schedule one-on-ones to catch up.

Finally, there will be new insights tab in Teams that allow leaders to ask natural questions like, “Are employees at risk for burnout? Are people maintaining strong internal connections? Are relationships with customers being maintained?”

Webinar Registration and reporting

For more structured meetings and events such as customer webinars, meeting and event organisers will soon be able to use powerful event registration with automated emails to make it easier to manage attendance. Ater the meeting, you’ll be able view a detailed reporting dashboard that will help understand attendee engagement. These new features are expected to begin to roll out by end of 2020 – and i suspect the Advanced Communications license will be needed to use these features (just a hunch).

News Teams Webinar Experience – Coming Q4 2020

Teams Templates

Teams templates, which are now in the rollout phase, are designed to help teams get started faster and be more effective. Teams owners can now choose from common business scenarios, such as event management or crisis response, and industry-specific templates, like a hospital ward or bank branch. Each template comes with pre-defined channels, apps, and guidance and admins can create their own for your organisation.

New Teams Templates – Rolling out now

New backgrounds for Together mode

New Backgrounds to Together Mode coming Q4 2020

Promised between now and the end of 2020, Together Mode feature will see some improvements with new Together mode scenes which will include conference rooms and a coffee shop and later, the ability to add your own such as meetings rooms from your own office. Microsoft hopes these features can help people feel connected and engaged from anywhere and reduce fatigue caused by regular grid view meetings.

With these improvements, like custom backgrounds in video chats, presenters will soon be able to select a scene from the gallery as the default scene for all together mode meeting attendees. Microsoft said they will also be enhancing the feature further to automatically scale and center participants in their virtual seats, regardless of how close or far they are from their camera.

Additionally, custom layouts in Teams meeting (not just Together mode) will allow presenters to customise how meeting content is displayed for participants during the meeting.

Similar to a weather forecast or the news, participants will be able to see the presenter’s video feed transposed onto the foreground of the content being presented on screen making for a more professional presentation.

Breakout Rooms

New Breakout Rooms – Coming October 2020

Already in preview for education, Teams meetings is getting a much-anticipated breakout room feature.

This highly requested feature will allow meeting organisers to split participants into smaller groups (manually or automatically) so they can have their own discussions. It’s ideal for brainstorming and workgroup discussions or for running event with multiple streams or optional sessions for example.

This means presenters will then be able to hop between different breakout rooms and make announcements to all breakout rooms, and close the rooms to return everyone to the main meeting room. Participants will still be able to access the notes, chat, files and whiteboards from the breakout session after the breakout rooms close.

Collaborative Calling

Starting rollout from the end of this month, is a new set of calling improvements for Teams.

One of these is Collaborative Calling, which enables users better collaborate and share information from within the channel while taking calls from employees or their customers in the queue.

Also included are a host of improvements to transcription, live captions, recording, and the ability to transfer between Teams mobile and desktop apps when doing one-on-one calls seemlessly.

Microsoft also said that their new  live captions with speaker attribution is now generally available (though I don’t see it yet). This provides a live and recap service for the meeting which includes the recording, an online transcript, chat, shared files, and more.

New Microsoft Teams panels

As employees begin to return to the office, part time, occasionally or permanently, meeting rooms will provide a welcome change to their work from home setups and will likely be at a premium.

To make it easier for workers to know when a meeting room is occupied, Microsoft has unveiled a new category of devices called Microsoft Teams panels that can be mounted outside of a meeting space.

These devices are essentially small tablets that can also use information from other connected certified Teams devices such as cameras to show room capacity information and help workers follow their organisation’s social distancing guidelines.

OK.. There is more…

In addition to these main announcements yesterday, Microsoft also announced several new smaller enhancements to Teams which include:

  1. New Search Experience
  2. Ability to create tasks directly from a team’s chat or channel
  3. New Cortana powered hands-free meeting controls in Teams Rooms

Let me know what I missed….

6 new countries added to Microsoft Cloud Calling Plans

Microsoft made a big announcement today as it announced an additional 6 countries that it is adding to its coverage of Microsoft provided calling plans which will be available from the 1st October 2020.

This is big news seeing Microsoft has not added a country since May 2018 so adding 6 countries is a big deal!

What countries are being added?

  • Austria
  • Denmark
  • Italy
  • Portugal
  • Sweden
  • Switzerland

The addition of these 6 countries in to the already available list of countries that support the Calling Plans Microsoft increases the total number of counties to 16, with the total list now being

  • Austria
  • Australia (via local telco)
  • Belgium
  • Canada
  • Denmark
  • France
  • Germany
  • Ireland
  • Italy
  • Japan (via local telco)
  • Netherlands
  • Portugal
  • Puerto Rico
  • Spain
  • Sweden
  • Switzerland
  • United Kingdom
  • United States

Microsoft is adding the following countries to its list of countries in which customers can consume callimg plans directly from Microsoft or their license/CSP partners.

Direct Routing is also an option for customers wishing to keep their own SBCs, their own SIP provider/carriers or where callings plans are not available is specific counties.

Official notice on the Microsoft 365 Public roadmap



A new world of possibilities comes to SurfaceHub2S

In Brief

  • The Surface Hub 2S now supports the installing of Windows 10 Pro or Enterprise.
  • Switching to Windows 10 Pro or Enterprise transforms the Surface Hub 2S into a more traditional PC with all the benefits such as any app and support for Windows ATP
  • The Surface Hub 2S users can also continue to use the device with its current version of Windows which is still fully supported for collab and Microsoft Teams only uses.

The detail…

Microsoft has just announced that it is making available Windows 10 Pro and Windows 10 Enterprise as an OS install option for the 50-inch Surface Hub 2S.

The device currently runs Windows Team edition, a flavour of Windows 10 (not too dissimilar from Windows 10 mobile) tailored for the collaboration displays such as Hub.

Why run Windows 10 Pro/Ent?

By installing Windows 10 Pro or Enterprise on the Surface Hub 2S, organisations will be able to install and run any app they choose, plug in and use and use Windows 10 compatible accessory, and even use Windows Hello Biometrics with a new dedicated Surface Hub 2 Fingerprint reader coming later in September (not seen pricing yet).

In comparison, the Windows 10 Team OS that ships on the Surface Hub 2S was purposely restricted to Microsoft Store apps (a bit like Windows 10 Mobile and event Windows 10 in ‘S’ mode) , and it supports inbuilt custom drivers only. In summary the native Windows 10 Team OS is a version of Windows that was indeed designed and optimised for multi-use and immersive collaboration experiences, but the ability to run full Windows 10 has been a big ask, especially from enterprise organisations.

Organisations can now choose whether to remain with the native SurfaceHub experience or install Windows 10 Pro or Enterprise.


Microsoft said in their blog announcement that “The Windows 10 Pro and Enterprise on Surface Hub 2 configuration enables customers to break the monotony of sitting at one’s desk all day and allows them to stand, move around and meet with remote participants more naturally and invitingly” said Yoav Barzilay, Senior Program Manager, Surface Engineering.

Microsoft released a chart showing the what get and what you loose by making the switch to full Windows 10

Remind me again.. Surface Hub is…?

The Surface Hub 2S is Microsoft’s giant collaboration display which comes with a huge massive 4K multitouch 50” screen, muti touch pen, ink and finger and is optimised for meetings in Teams, even supporting the new companion mode within Microsoft Teams.

You can read my previous blog here.

The ability to now use regular Windows 10 on it was a big ask and should be quite an experience. (I’ll let you know when I’m back in the office!)

The Surface Hub 2S costs from around £8.5k but has add on accessories such as Steel Case Roam Stand and a dedicated 2-3hr battery pack allowing it to be used wire free. Great for phsycial breakout rooms and of course education classrooms and training rooms.

How do I install Windows 10?

Microsoft have kindly published detailed instructions on how to install Windows 10 Pro or Enterprise on it on this page.

What’s new in Teams for August 2020? – Spotlight, Call Merge, and more

Teams Aug 2020 Update logo

Microsoft has posted its August monthly wrap-up to look back at all the new features and capabilities added (or announced) in Microsoft Teams as part of the August 2020 update.  One thing to note (as my commenters often point out) is that, as with all these updates, as that Microsoft announce, the rolling out of these features and due to the gradual rollout, not all customers will get these at the same time!

Meetings and Calling Enhancements

With Teams Calling and Meetings being a constant area of innovation, demand (COVID and post COVID) and of course immense competition from the likes of Zoom in the meetings space, it won’t surprise you to hear there are tons of new improvements coming.  All these features have been designed of course to enhance the user experience in Microsoft Teams and include: –

  • The addition of Spotlight mode,
  • Enhancements to Meeting Recordings
  • New Call Merge option
  • Chat and Presence enhancements
  • Updated transcribe service (Speaker Attribution)
  • Teams Education Specific Enhancements

Spotlight mode

Said to be going live in the next couple of months (Sept to October), and not to be confused with the “Pin participant” feature, spotlight mode will provide presenters and meeting organisers the ability to lock an individual video feed for all attendees to see during a Teams meeting. This will mean presenters will be able to put someone in the spotlight by heading to the meeting video grid or directly from the Participants panel.

Teams Spotlight video window

Meeting Recording Improvements

Until now, Teams records meetings in Stream which is fine so long as Stream is available within the customers geographic region.  Until such time that Stream is available in all Office 365 Teams regions, a new admin setting is rolling out to let users to store meeting recordings in the Office 365 data centre closest to their region. In addition,

In addition, Microsoft have announced that Microsoft Teams is now fully supported with their “optimised experience” with VMWare Horizon 8, in additional to Citrix and of course, Windows Virtual Desktop, helping meet the increasing demand for collaboration tools to support remote workers and work across Virtual Desktop environments.

Enhancements to Teams Voice (Calling)

Microsoft announced new features for calling in Teams including a new call merge option for both Teams VOIP and PSTN calls which lets users merge several separate calls into a bigger group call.

Another new feature announced was new devices designed that will further enhance the collaboration and meeting experience. The list announced by Microsoft includes a new Windows collaboration displays from Avocor as well as various new Microsoft Teams Rooms setups powered by Yealink, Logitech, and HP.

Merge Calls in Teams

Chat and Presence Enhancements

After two years, Microsoft have finally “fixed” presence, although they announced this as a new feature since the tech behind it was rebuilt based on the updated and new communications APIs. 

Called “real-time presence”, this means that Teams will be able to provide a much more reliable and faster status updates.

Microsoft also announced that they are bringing enhanced Visio integration into Microsoft Teams to make it easier to access, managed and edit Visio files directly through a dedicated Visio tabs within a channel or chat.

Speaker Live Translation with Speaker Attribution

Microsoft is bringing a new Live Transcription with speaker attribution capabilities to Microsoft Teams which rolling out this month (September 2020)

The new Live Transcription feature will give users a new way to follow and review meeting conversations. Once rolled out, users will see two options in the meeting control bar – Recording and Transcription.

Transcripts will be viewed in real-time using the desktop client, or at the end of the meeting on the web application and will be attributed, in line with the speaker rather than the current simple subtitle / closed caption view today.

Teams Education – Enhancements

Teams in Education is different from Teams Commercial as has many discrete and dedicated features that empowers education establishments to use Team to deliver whole class teaching whether it’s for Academy, Adult Ed, Primary, Secondary, or Further/High Education.

There are new Education Insights that have been rolled out in public preview which allows “administrators to monitor digital engagement through system-level engagement monitoring reports which has been designed to provide enhanced visibility into educator best practices in remote instruction” – according to Microsoft. 

Microsoft Teams Edu Insights

Thirsty for more detail?

For the full details, refer to the wider Microsoft Blog here: 

https://techcommunity.microsoft.com/t5/microsoft-teams-blog/what-s-new-in-microsoft-teams-august-2020/ba-p/1619717