Flows and Defender Suites Flashcards
(12 cards)
Flow 1
NMCI Machine connected in office (NVD is considered Flow 1)
Flow 2
NMCI Machine is connected at home via VPN, (uses) RSA tools/PulseSecureAzure VPN)
Flow 3
Personal Device on Home IE (Connected through VPN)
MDCA restricts Flow 3 from downloading.
MDC (Cloud)
monitors Cloud native resources like VM’s, and VNETS
MDE (Endpoint)
Monitors endpoints like the NMCI devices & NEPs
MDI (Identity)
Monitors identity services via sensors on domain controllers/active directory
MDO (office)
works with exchange online protection to manage spam/malware filters
MDA (Applications)
Monitors apps and used to block or allow apps.
Where to find CA policies?
Microsoft ExtraID —> Security —> Conditional Access Policies —> Policies
MDCA (Cloud Applications)
restricts Flow 3 from downloading.
Users in IA policy Violators can’t login due to CA
Breakglass Account
Emergency account used if all other accounts lose access. It’s a global account that is exempt to CA.
What are the the Microsoft Defender Suites?
MDC (Cloud)
MDE (Endpoint)
MDI (Identity)
MDO (office)
MDA (Applications)
MDCA (Cloud Applications)