Posts

Showing posts with the label Apple

Enable compliant network compliance using conditional access & Global Secure Access client for macOS - Putting it all together!

Image
Back in January, 2024, when I first wrote about my experience working with Global Secure Access (GSA) for Android OS, GSA was still in preview. Since then, most of the configuration in GSA has been moved into GA, including support for macOS, and this is what I will be covering in this blog. First a quick refresher on what GSA is really all about. Global Secure Access (GSA) is Microsoft’s unified Security Service Edge (SSE) solution that combines Microsoft Entra Internet Access and Microsoft Entra Private Access, giving identity-aware access control (for internet, SaaS, and private resources) without relying solely on VPNs. Using GSA one can guard against threats like token replay by leveraging a combination of compliant network and conditional access policies. A compliant network check is a conditional access control that one can configure so that access to resources is only allowed when the client is connected via the Global Secure Access infrastructure (i.e. traffic is routed throug...

Microsoft Purview DLP Domain Restrictions for macOS

Image
While scoping for a project for a customer involving the features of Microsoft Purview for Windows devices, it got me thinking about other OS platforms like macOS and what all Purview had to offer. As it turns out, there is a lot. From real-time file inspection across different file types & classification to robust policy protection controls, Microsoft Purview DLP offers a rich set of capabilities.  As of writing this blog, here is a complete list of features supported on macOS. Source: Microsoft Once devices are onboarded into the Microsoft Purview solutions, the information about what users are doing with sensitive items is made visible in the Purview portal. There is a bit involved in getting the macOS devices onboarded and creating policies in Purview, so let's get started. What are the pre-requisites? 1. If you are using Intune, then make sure the device is enrolled in Intune. 2. Device is onboarded to Microsoft Defender for Endpoint with a minimum version of 101.95.07.x 3...