S6E14 - Securing M365 with ScubaGear: A Deep Dive into CISA’s Assessment Tool

S6E14 - Securing M365 with ScubaGear: A Deep Dive into CISA’s Assessment Tool

In this episode, we dive deep into ScubaGear, an open-source tool developed by the Cybersecurity and Infrastructure Security Agency (CISA) as part of the Secure Cloud Business Applications (SCuBA) project. Designed to assess Microsoft 365 (M365) tenant configurations, ScubaGear helps organizations align with CISA’s Secure Configuration Baselines (SCBs) to prevent costly misconfigurations. From setup to real-world applications, we unpack how ScubaGear strengthens M365 security and share practical tips for IT admins and security teams. What You’ll Learn:

  • Why ScubaGear Matters: Learn how ScubaGear addresses the growing threat of cloud misconfigurations, which accounted for 30% of cloud attacks in early 2024. We discuss its origins in CISA’s SCuBA project, and its value for US federal agencies, private organizations, and critical infrastructure.
  • How ScubaGear Works: A technical breakdown of ScubaGear’s PowerShell-based workflow, using Microsoft Graph APIs and Open Policy Agent (OPA) to compare tenant settings against SCBs. We cover setup requirements.
  • Common Misconfigurations: Examples like disabled MFA or weak DLP policies, and how ScubaGear’s HTML, JSON, and CSV reports provide actionable remediation steps.
  • Best Practices: Tips for integrating ScubaGear into security workflows, including regular scans, policy customization, and combining with tools like Microsoft Secure Score.
  • Real-World Insights: Sam shares experiences from consulting.

What did you think of this episode? Give us some feedback via our contact form, Or leave us a voice message in the bottom right corner of our site.

Read transcript

Episoder(156)

S6E21 - Protecting Data within Storage Accounts with Microsoft Defender for Storage

S6E21 - Protecting Data within Storage Accounts with Microsoft Defender for Storage

In this episode, we dive into Microsoft Defender for Storage, a key component of Microsoft Defender for Cloud. We break down its features for threat detection and malware scanning, discuss real-world ...

29 Aug 202544min

S6E20 - Unified SecOps Platform - Sentinel integration

S6E20 - Unified SecOps Platform - Sentinel integration

Alan and Sam discuss the integration of Microsoft Sentinel into the Defender XDR portal. Alan goes through the benefits of the integration and thing to watch out for when starting the migration. Here ...

22 Aug 202546min

S6E19 - Microsoft updates July - new products and features released

S6E19 - Microsoft updates July - new products and features released

This week, Alan and Sam talk about new features and services that have gone into Public Preview or General Available status in the last month. We dive into a couple of these updates that peaked our in...

8 Aug 202537min

S6E18 - Securing Access to Your Virtual Machines with Azure Bastion

S6E18 - Securing Access to Your Virtual Machines with Azure Bastion

In this episode, we explore Azure Bastion, Microsoft’s fully managed Platform-as-a-Service (PaaS) solution designed to provide secure Remote Desktop Protocol (RDP) and Secure Shell Protocol (SSH) acce...

18 Jul 202555min

S6E17 - Microsoft updates June - new products and features released

S6E17 - Microsoft updates June - new products and features released

This week, Alan and Sam talk about new features and services that have gone into Public Preview or General Available status in the last month. We dive into a couple of these updates that peaked our in...

4 Jul 202544min

S6E16 - Monitor and Protect Generative AI services using Microsoft Tooling

S6E16 - Monitor and Protect Generative AI services using Microsoft Tooling

Alan and Sam discuss the topic of Generative AI usage and it should be monitored by organisations. Alan talks about some of the Microsoft tooling that can help monitor these services and protect data ...

20 Jun 202555min

S6E15 - Microsoft updates May - new products and features released

S6E15 - Microsoft updates May - new products and features released

This week, Alan and Sam talk about new features and services that have gone into Public Preview or General Available status in the last month. We dive into a couple of these updates that peaked our in...

13 Jun 20251h 8min

Populært innen Teknologi

lydartikler-fra-aftenposten
romkapsel
tomprat-med-gunnar-tjomlid
energi-og-klima
nasjonal-sikkerhetsmyndighet-nsm
teknisk-sett
elektropodden
fornybaren
shifter
rss-impressions-2
smart-forklart
teknologi-og-mennesker
rss-ai-forklart
rss-polypod
rss-alt-vi-kan
rss-ki-praten
rss-heis
pedagogisk-intelligens
rss-forenklingspodden
rss-alt-som-gar-pa-strom