S6E14 - Securing M365 with ScubaGear: A Deep Dive into CISA’s Assessment Tool

S6E14 - Securing M365 with ScubaGear: A Deep Dive into CISA’s Assessment Tool

In this episode, we dive deep into ScubaGear, an open-source tool developed by the Cybersecurity and Infrastructure Security Agency (CISA) as part of the Secure Cloud Business Applications (SCuBA) project. Designed to assess Microsoft 365 (M365) tenant configurations, ScubaGear helps organizations align with CISA’s Secure Configuration Baselines (SCBs) to prevent costly misconfigurations. From setup to real-world applications, we unpack how ScubaGear strengthens M365 security and share practical tips for IT admins and security teams. What You’ll Learn:

  • Why ScubaGear Matters: Learn how ScubaGear addresses the growing threat of cloud misconfigurations, which accounted for 30% of cloud attacks in early 2024. We discuss its origins in CISA’s SCuBA project, and its value for US federal agencies, private organizations, and critical infrastructure.
  • How ScubaGear Works: A technical breakdown of ScubaGear’s PowerShell-based workflow, using Microsoft Graph APIs and Open Policy Agent (OPA) to compare tenant settings against SCBs. We cover setup requirements.
  • Common Misconfigurations: Examples like disabled MFA or weak DLP policies, and how ScubaGear’s HTML, JSON, and CSV reports provide actionable remediation steps.
  • Best Practices: Tips for integrating ScubaGear into security workflows, including regular scans, policy customization, and combining with tools like Microsoft Secure Score.
  • Real-World Insights: Sam shares experiences from consulting.

What did you think of this episode? Give us some feedback via our contact form, Or leave us a voice message in the bottom right corner of our site.

Read transcript

Avsnitt(155)

S6E28 - Automate Your Security Baseline with Microsoft’s Open-Source Assessment Tool

S6E28 - Automate Your Security Baseline with Microsoft’s Open-Source Assessment Tool

In this episode, we dive into Microsoft’s Zero Trust Assessment - an open-source, automated tool that scans hundreds of Entra ID and Intune settings against NIST, CISA, CIS, and Microsoft’s own intern...

14 Nov 202531min

S6E27 - Microsoft updates October- new products and features released

S6E27 - Microsoft updates October- new products and features released

This week, Alan and Sam talk about new features and services that have gone into Public Preview or General Available status in the last month. We dive into a couple of these updates that peaked our in...

7 Nov 202546min

S6E26 - Classify and protect your data using Purview sensitivity labels

S6E26 - Classify and protect your data using Purview sensitivity labels

In this episode, Alan and Sam drive into the importance of classifying data in an organisation. Alan goes through the capability in Purview to tag files and encrypt them. Here are a few things we cove...

31 Okt 202540min

S6E25 - Securing Azure's Core: Microsoft Defender for Resource Manager, Key Vault, and APIs

S6E25 - Securing Azure's Core: Microsoft Defender for Resource Manager, Key Vault, and APIs

In this episode, we dive into three key Cloud Workload Protection Platform (CWPP) offerings within Microsoft Defender for Cloud: Defender for Resource Manager, Defender for Key Vault, and Defender for...

24 Okt 202557min

S6E24 - Microsoft updates September - new products and features released

S6E24 - Microsoft updates September - new products and features released

This week, Alan and Sam talk about new features and services that have gone into Public Preview or General Available status in the last month. We dive into a couple of these updates that peaked our in...

3 Okt 202537min

S6E23 - Unified DLP Platform - Monitor, alert and protect data using Purview DLP

S6E23 - Unified DLP Platform - Monitor, alert and protect data using Purview DLP

Alan and Sam discuss the topic of DLP and how Purview can help audit policy matches and provide preventions. Aland goes though the range of capability and data sources that can be integrated with Purv...

19 Sep 202548min

S6E22 - Microsoft updates August - new products and features released

S6E22 - Microsoft updates August - new products and features released

This week, Alan and Sam talk about new features and services that have gone into Public Preview or General Available status in the last month. We dive into a couple of these updates that peaked our in...

12 Sep 202544min

S6E21 - Protecting Data within Storage Accounts with Microsoft Defender for Storage

S6E21 - Protecting Data within Storage Accounts with Microsoft Defender for Storage

In this episode, we dive into Microsoft Defender for Storage, a key component of Microsoft Defender for Cloud. We break down its features for threat detection and malware scanning, discuss real-world ...

29 Aug 202544min

Populärt inom Teknik

uppgang-och-fall
elbilsveckan
bilar-med-sladd
market-makers
rss-elektrikerpodden
rss-technokratin
skogsforum-podcast
har-vi-akt-till-mars-an
rss-veckans-ai
rss-laddstationen-med-elbilen-i-sverige
developers-mer-an-bara-kod
gubbar-som-tjotar-om-bilar
bli-saker-podden
rss-powerboat-sverige-podcast
hej-bruksbil
rss-milpodden
natets-morka-sida
rss-en-ai-till-kaffet
rss-snacka-om-ai
rss-rapporterat