Nền tảng kiến thức về bảo mật, tuân thủ và quản lý danh tính trên nền tảng Microsoft — điểm khởi đầu cho mọi hành trình trong lĩnh vực Microsoft Security.
Confidentiality ensures that information is accessible only to authorized individuals. Mechanisms include encryption, access control lists, and role-based permissions. A breach of confidentiality means unauthorized parties can read sensitive data — for example, an attacker reading encrypted health records after intercepting unprotected network traffic.
Integrity guarantees that data has not been altered without authorization. It is enforced through hashing algorithms (SHA-256), digital signatures, and audit trails. A breach of integrity means data has been tampered with — for example, an attacker modifying a financial transaction record in transit.
Availability ensures that systems and data are accessible to authorized users when needed. It is protected by redundancy, disaster recovery, load balancing, and DDoS mitigation. A breach of availability is a Denial-of-Service attack that prevents a hospital from accessing patient records during an emergency.
The Zero Trust security model operates on the principle "never trust, always verify." Unlike the traditional perimeter model (trust everything inside the corporate network), Zero Trust assumes breach and verifies every request explicitly, regardless of whether it originates inside or outside the network. It replaces implicit trust based on network location with explicit, continuous trust based on identity, device, and context.
Verify explicitly — always authenticate and authorize using all available data points: identity, location, device health, service or workload, data classification, and behavioral anomalies. No request is trusted by default, even from inside the corporate network or from a previously trusted device.
Use least privileged access — limit user access with just-in-time (JIT) and just-enough-access (JEA), adaptive risk-based policies, and data protection. Users get only the permissions they need, only when they need them, and access is revoked when the task is complete.
Assume breach — design with the assumption that the perimeter is already compromised. Minimize blast radius by segmenting access so that a compromised account or endpoint cannot move laterally across the entire network. Encrypt end-to-end. Use analytics for visibility and to drive threat detection and response.
Defense-in-depth applies multiple layers of security so that if one layer is breached, subsequent layers continue to provide protection. The layers from outer to inner are: Physical, Identity & Access, Perimeter, Network, Compute, Application, and Data. Microsoft aligns its products to these layers — for example, Microsoft Entra ID protects the Identity layer, Azure Firewall protects the Perimeter layer, and Microsoft Purview Information Protection protects the Data layer.
Bảo mật (Confidentiality) đảm bảo thông tin chỉ những người được ủy quyền mới có thể truy cập. Các cơ chế bao gồm mã hóa, danh sách kiểm soát truy cập (ACL) và phân quyền theo vai trò. Vi phạm bảo mật xảy ra khi kẻ tấn công có thể đọc dữ liệu nhạy cảm — ví dụ: đọc hồ sơ y tế được mã hóa sau khi chặn lưu lượng mạng không được bảo vệ.
Toàn vẹn (Integrity) đảm bảo dữ liệu không bị thay đổi mà không có ủy quyền. Được thực thi qua thuật toán băm (SHA-256), chữ ký số và nhật ký kiểm tra. Vi phạm toàn vẹn xảy ra khi dữ liệu bị giả mạo — ví dụ: kẻ tấn công thay đổi bản ghi giao dịch tài chính trong quá trình truyền.
Tính sẵn sàng (Availability) đảm bảo hệ thống và dữ liệu luôn có thể truy cập khi người dùng được ủy quyền cần. Được bảo vệ bằng dự phòng, khôi phục thảm họa, cân bằng tải và giảm thiểu DDoS. Vi phạm tính sẵn sàng là tấn công từ chối dịch vụ ngăn bệnh viện truy cập hồ sơ bệnh nhân trong trường hợp khẩn cấp.
Mô hình bảo mật Zero Trust hoạt động theo nguyên tắc "không bao giờ tin tưởng, luôn luôn xác minh." Khác với mô hình vành đai truyền thống (tin tưởng mọi thứ bên trong mạng doanh nghiệp), Zero Trust giả định bị xâm phạm và xác minh mọi yêu cầu một cách rõ ràng, bất kể xuất phát từ trong hay ngoài mạng. Nó thay thế tin tưởng ngầm định dựa trên vị trí mạng bằng tin tưởng rõ ràng, liên tục dựa trên danh tính, thiết bị và ngữ cảnh.
Xác minh rõ ràng (Verify explicitly) — luôn xác thực và ủy quyền bằng tất cả dữ liệu có sẵn: danh tính, vị trí, tình trạng thiết bị, dịch vụ hoặc khối lượng công việc, phân loại dữ liệu và bất thường hành vi. Không yêu cầu nào được tin tưởng mặc định, ngay cả từ trong mạng doanh nghiệp hoặc từ thiết bị đã được tin tưởng trước đây.
Sử dụng đặc quyền tối thiểu (Least privileged access) — giới hạn quyền truy cập người dùng với just-in-time (JIT) và just-enough-access (JEA), chính sách thích ứng dựa trên rủi ro và bảo vệ dữ liệu. Người dùng chỉ nhận quyền họ cần, chỉ khi họ cần, và quyền truy cập bị thu hồi khi nhiệm vụ hoàn thành.
Giả định bị xâm phạm (Assume breach) — thiết kế với giả định vành đai đã bị xâm phạm. Giảm thiểu bán kính thiệt hại bằng cách phân đoạn quyền truy cập để tài khoản hoặc endpoint bị xâm phạm không thể di chuyển ngang qua toàn bộ mạng. Mã hóa đầu cuối. Sử dụng phân tích để có tầm nhìn và thúc đẩy phát hiện và phản hồi mối đe dọa.
Bảo vệ theo lớp (Defense-in-depth) áp dụng nhiều lớp bảo mật sao cho nếu một lớp bị xâm phạm, các lớp tiếp theo vẫn cung cấp bảo vệ. Các lớp từ ngoài vào trong: Vật lý, Danh tính & Truy cập, Vành đai, Mạng, Tính toán, Ứng dụng và Dữ liệu. Microsoft căn chỉnh sản phẩm theo các lớp này — ví dụ: Microsoft Entra ID bảo vệ lớp Danh tính, Azure Firewall bảo vệ lớp Vành đai, Microsoft Purview Information Protection bảo vệ lớp Dữ liệu.
Authentication (AuthN) is the process of proving that a person is who they claim to be. It answers the question "Who are you?" Modern authentication uses credentials such as passwords, PINs, biometrics, smart cards, or one-time codes. Strong authentication combines multiple factors from different categories: something you know (password), something you have (phone/security key), and something you are (fingerprint).
Authorization (AuthZ) is the process of determining what an authenticated user is allowed to do. It answers the question "What are you allowed to do?" Authorization occurs after authentication. For example, a user may authenticate to Microsoft 365 but only be authorized to read emails — not to access SharePoint sites or manage user accounts. Role-based access control (RBAC) is the most common authorization model.
Identity as the security perimeter: In the modern cloud-first world, the traditional network perimeter has dissolved. Employees work from home, use personal devices, and access corporate SaaS apps from everywhere. Identity has become the new security perimeter — every access request must be validated against the user's identity, device health, location, and the sensitivity of the resource being accessed.
Identity providers (IdP) create, maintain, and manage identity information. Microsoft Entra ID is Microsoft's cloud-based identity provider. Social providers (Google, Facebook, Apple) are external identity providers. An IdP issues security tokens after successful authentication — these tokens contain claims (user attributes) that downstream applications use to make authorization decisions without re-authenticating the user.
Federation establishes a trust relationship between two identity domains, allowing users authenticated in one domain to access resources in another domain without a separate account. For example, a company can federate with a partner organization so that partner employees can access shared resources using their own corporate credentials. Single Sign-On (SSO) extends this so that a user authenticates once and gains access to multiple systems without re-entering credentials for each application.
Xác thực (AuthN) là quá trình chứng minh một người là ai họ tự xưng. Nó trả lời câu hỏi "Bạn là ai?" Xác thực hiện đại sử dụng thông tin xác thực như mật khẩu, PIN, sinh trắc học, thẻ thông minh hoặc mã dùng một lần. Xác thực mạnh kết hợp nhiều yếu tố từ các danh mục khác nhau: thứ bạn biết (mật khẩu), thứ bạn có (điện thoại/khóa bảo mật), và thứ bạn là (vân tay).
Ủy quyền (AuthZ) là quá trình xác định những gì người dùng đã xác thực được phép làm. Nó trả lời câu hỏi "Bạn được phép làm gì?" Ủy quyền xảy ra sau xác thực. Ví dụ: người dùng có thể xác thực với Microsoft 365 nhưng chỉ được ủy quyền đọc email — không được truy cập SharePoint hay quản lý tài khoản người dùng. Kiểm soát truy cập dựa trên vai trò (RBAC) là mô hình ủy quyền phổ biến nhất.
Danh tính là vành đai bảo mật mới: Trong thế giới cloud-first hiện đại, vành đai mạng truyền thống đã biến mất. Nhân viên làm việc tại nhà, dùng thiết bị cá nhân và truy cập ứng dụng SaaS doanh nghiệp từ mọi nơi. Danh tính đã trở thành vành đai bảo mật mới — mọi yêu cầu truy cập phải được xác nhận dựa trên danh tính, tình trạng thiết bị, vị trí và mức độ nhạy cảm của tài nguyên.
Nhà cung cấp danh tính (IdP) tạo, duy trì và quản lý thông tin danh tính. Microsoft Entra ID là nhà cung cấp danh tính đám mây của Microsoft. Các nhà cung cấp xã hội (Google, Facebook, Apple) là nhà cung cấp danh tính bên ngoài. IdP phát hành token bảo mật sau khi xác thực thành công — các token này chứa claims (thuộc tính người dùng) mà ứng dụng downstream sử dụng để đưa ra quyết định ủy quyền mà không cần xác thực lại.
Liên kết (Federation) thiết lập mối quan hệ tin cậy giữa hai miền danh tính, cho phép người dùng được xác thực trong một miền truy cập tài nguyên ở miền khác mà không cần tài khoản riêng. Ví dụ: công ty có thể liên kết với tổ chức đối tác để nhân viên đối tác truy cập tài nguyên dùng chung bằng thông tin xác thực doanh nghiệp của họ. Đăng nhập một lần (SSO) mở rộng điều này để người dùng xác thực một lần và truy cập nhiều hệ thống mà không cần nhập lại thông tin xác thực cho mỗi ứng dụng.
The Shared Responsibility Model defines what Microsoft is responsible for securing and what the customer is responsible for. In an on-premises deployment, the customer is responsible for everything. In the cloud: Microsoft is always responsible for the physical datacenter, network infrastructure, and hypervisor. The responsibility for identity, applications, and data shifts depending on the service type: in IaaS, customers manage OS and apps; in PaaS, Microsoft manages the OS; in SaaS, Microsoft manages nearly everything except data governance and access configuration.
Data residency refers to the physical location where data is stored. Organizations — especially in regulated industries — must ensure that personal or sensitive data stays within specific geographic boundaries to comply with local regulations. For example, the European Union's GDPR restricts transfer of personal data outside the EU/EEA unless adequate protections are in place. Microsoft allows customers to choose their Azure region and provides data residency commitments for most services.
Data sovereignty is related but broader: it refers to the concept that data is subject to the laws of the country or region in which it is stored. A company storing data in Germany must comply with German and EU law, even if the company is headquartered in the US. Microsoft's data center locations and contractual commitments help organizations meet sovereignty requirements.
Data privacy is about giving individuals control over how their personal information is collected, used, and shared. Key regulations include GDPR (EU), CCPA (California), LGPD (Brazil), and PDPA (Thailand). Microsoft provides tools like Microsoft Priva and the Service Trust Portal to help organizations understand and demonstrate their compliance with privacy regulations.
Mô hình trách nhiệm chia sẻ xác định Microsoft chịu trách nhiệm bảo mật gì và khách hàng chịu trách nhiệm gì. Với triển khai on-premises, khách hàng chịu trách nhiệm mọi thứ. Trên đám mây: Microsoft luôn chịu trách nhiệm về trung tâm dữ liệu vật lý, hạ tầng mạng và hypervisor. Trách nhiệm về danh tính, ứng dụng và dữ liệu thay đổi tùy loại dịch vụ: IaaS — khách hàng quản lý OS và apps; PaaS — Microsoft quản lý OS; SaaS — Microsoft quản lý hầu hết mọi thứ ngoại trừ quản trị dữ liệu và cấu hình truy cập.
Lưu trú dữ liệu (Data residency) đề cập đến vị trí vật lý nơi dữ liệu được lưu trữ. Các tổ chức — đặc biệt trong ngành được quản lý — phải đảm bảo dữ liệu cá nhân hoặc nhạy cảm nằm trong ranh giới địa lý cụ thể để tuân thủ quy định địa phương. Ví dụ: GDPR của EU hạn chế chuyển dữ liệu cá nhân ra ngoài EU/EEA trừ khi có biện pháp bảo vệ đầy đủ. Microsoft cho phép khách hàng chọn vùng Azure và cung cấp cam kết lưu trú dữ liệu cho hầu hết dịch vụ.
Chủ quyền dữ liệu (Data sovereignty) liên quan nhưng rộng hơn: đề cập đến khái niệm dữ liệu phải tuân theo luật của quốc gia hoặc vùng nơi nó được lưu trữ. Công ty lưu trữ dữ liệu ở Đức phải tuân thủ luật Đức và EU, ngay cả khi công ty đặt trụ sở tại Mỹ. Vị trí trung tâm dữ liệu và cam kết hợp đồng của Microsoft giúp tổ chức đáp ứng yêu cầu chủ quyền.
Quyền riêng tư dữ liệu (Data privacy) là việc trao cho cá nhân quyền kiểm soát cách thông tin cá nhân của họ được thu thập, sử dụng và chia sẻ. Các quy định chính: GDPR (EU), CCPA (California), LGPD (Brazil), PDPA (Thái Lan). Microsoft cung cấp các công cụ như Microsoft Priva và Service Trust Portal để giúp tổ chức hiểu và chứng minh sự tuân thủ với quy định về quyền riêng tư.
Microsoft Entra ID (formerly Azure Active Directory) is Microsoft's cloud-based identity and access management service. It provides identity services for Microsoft cloud applications (Microsoft 365, Azure, Dynamics 365) and thousands of third-party SaaS applications. Unlike traditional on-premises Active Directory Domain Services (AD DS) which uses Kerberos/NTLM and LDAP, Entra ID uses modern protocols: OAuth 2.0, OpenID Connect, SAML, and WS-Federation. It is a multi-tenant, globally distributed service with 99.99% availability SLA.
Cloud identities are users created and managed entirely within Entra ID — no on-premises AD required. Their UPN ends in the tenant's onmicrosoft.com domain or a verified custom domain. Any attribute change is made directly in Entra ID and takes effect immediately.
Directory-synchronized identities are on-premises Active Directory users synchronized to Entra ID via Microsoft Entra Connect. The source of authority remains on-premises AD — attributes changed in the cloud are overwritten at the next sync cycle. Password changes must originate in on-premises AD unless password writeback is configured.
Guest users are external partners, vendors, or customers invited to the tenant via B2B collaboration. They authenticate using their home organization's identity (or a Microsoft account) and appear in the directory with a #EXT# suffix in their UPN. Guest access permissions are configurable separately from member user permissions.
Service principals and Managed Identities are non-human identities for applications, services, and automation scripts. A system-assigned managed identity is tied to the Azure resource lifecycle and deleted when the resource is deleted. A user-assigned managed identity exists independently and can be shared across multiple resources — both eliminate the need to manage credentials in code.
Hybrid identity connects on-premises Active Directory with Microsoft Entra ID, giving users one identity for both on-premises and cloud resources. Microsoft Entra Connect synchronizes user accounts, group memberships, and password hashes from on-premises AD to Entra ID. Microsoft Entra Cloud Sync is a newer, lightweight alternative using a small provisioning agent — it supports multi-forest synchronization without a full Entra Connect server installation.
Free tier is included with any Microsoft cloud subscription. It provides basic user and group management, SSO for up to 10 apps, self-service password change for cloud users, and basic security reports.
Microsoft 365 Apps is included with M365 commercial subscriptions. It adds Identity Protection signals for Microsoft 365 apps, self-service password reset (SSPR) for cloud-only users, and two-way sync for Teams and SharePoint group membership.
P1 (Premium 1) unlocks Conditional Access policies, hybrid identity with Entra Connect, dynamic groups, group-based licensing, SSPR with on-premises password writeback, and Microsoft Entra application proxy for publishing on-premises apps.
P2 (Premium 2) includes all P1 features and adds Identity Protection with risk-based Conditional Access, Privileged Identity Management (PIM) for just-in-time access, Entitlement Management, Access Reviews, and Lifecycle Workflows.
Microsoft Entra ID (trước đây là Azure Active Directory) là dịch vụ quản lý danh tính và truy cập trên đám mây của Microsoft. Cung cấp dịch vụ danh tính cho các ứng dụng đám mây Microsoft (Microsoft 365, Azure, Dynamics 365) và hàng nghìn ứng dụng SaaS bên thứ ba. Khác với Active Directory Domain Services (AD DS) on-premises truyền thống sử dụng Kerberos/NTLM và LDAP, Entra ID sử dụng giao thức hiện đại: OAuth 2.0, OpenID Connect, SAML và WS-Federation. Đây là dịch vụ đa tenant, phân tán toàn cầu với SLA 99,99%.
Cloud identities là người dùng được tạo và quản lý hoàn toàn trong Entra ID — không cần AD on-premises. UPN của họ kết thúc bằng tên miền onmicrosoft.com của tenant hoặc tên miền tùy chỉnh đã xác minh. Mọi thay đổi thuộc tính được thực hiện trực tiếp trong Entra ID và có hiệu lực ngay lập tức.
Directory-synchronized identities là người dùng Active Directory on-premises được đồng bộ lên Entra ID qua Microsoft Entra Connect. Nguồn thẩm quyền vẫn là AD on-premises — các thuộc tính thay đổi trên đám mây bị ghi đè vào chu kỳ đồng bộ tiếp theo. Thay đổi mật khẩu phải xuất phát từ AD on-premises trừ khi password writeback được cấu hình.
Guest users là đối tác, nhà cung cấp hoặc khách hàng bên ngoài được mời vào tenant qua B2B collaboration. Họ xác thực bằng danh tính của tổ chức nhà (hoặc Microsoft account) và xuất hiện trong thư mục với hậu tố #EXT# trong UPN. Quyền truy cập của guest có thể cấu hình riêng biệt so với quyền của member user.
Service principals và Managed Identities là danh tính phi con người dùng cho ứng dụng, dịch vụ và tập lệnh tự động hóa. Managed Identity được gán hệ thống gắn với vòng đời tài nguyên Azure và bị xóa khi tài nguyên bị xóa. Managed Identity được gán người dùng tồn tại độc lập và có thể chia sẻ trên nhiều tài nguyên — cả hai đều loại bỏ nhu cầu quản lý thông tin xác thực trong code.
Hybrid identity kết nối Active Directory on-premises với Microsoft Entra ID, cho người dùng một danh tính duy nhất cho cả tài nguyên on-premises và đám mây. Microsoft Entra Connect đồng bộ tài khoản người dùng, thành viên nhóm và băm mật khẩu từ AD on-premises lên Entra ID. Microsoft Entra Cloud Sync là giải pháp thay thế nhẹ hơn mới hơn sử dụng agent cấp phép nhỏ — hỗ trợ đồng bộ đa forest mà không cần cài đặt máy chủ Entra Connect đầy đủ.
Gói Free được kèm theo bất kỳ gói đăng ký đám mây Microsoft nào. Cung cấp quản lý người dùng và nhóm cơ bản, SSO cho tối đa 10 apps, thay đổi mật khẩu tự phục vụ cho người dùng đám mây và báo cáo bảo mật cơ bản.
Microsoft 365 Apps được kèm theo gói đăng ký M365 thương mại. Thêm tín hiệu Identity Protection cho workloads Microsoft 365, đặt lại mật khẩu tự phục vụ (SSPR) cho người dùng chỉ trên đám mây, và đồng bộ hai chiều cho thành viên nhóm Teams và SharePoint.
P1 (Premium 1) mở khóa chính sách Conditional Access, hybrid identity với Entra Connect, dynamic groups, group-based licensing, SSPR với password writeback on-premises và Microsoft Entra application proxy để xuất bản app on-premises.
P2 (Premium 2) bao gồm tất cả tính năng P1 và thêm Identity Protection với Conditional Access dựa trên rủi ro, Privileged Identity Management (PIM) để truy cập just-in-time, Entitlement Management, Access Reviews và Lifecycle Workflows.
Entra ID supports multiple authentication methods: Password (traditional, weakest — vulnerable to phishing and credential stuffing); Multi-Factor Authentication (MFA) — requires a second verification factor: Microsoft Authenticator push notification, OATH hardware token, SMS/voice call (least preferred, SMS is vulnerable to SIM swapping), or email OTP. MFA dramatically reduces the risk of account compromise — Microsoft reports that MFA blocks 99.9% of automated identity attacks.
Passwordless authentication replaces the password entirely with a phishing-resistant credential. Windows Hello for Business uses biometric recognition (fingerprint, facial) or a PIN tied to a specific device. The credential is protected by the device's TPM chip and never transmitted across the network — even the PIN never leaves the device.
FIDO2 security keys are hardware devices (such as YubiKey, Feitian, or Identiv) that use public-key cryptography for passwordless sign-in. During registration, the key generates a key pair and stores the private key securely on the hardware — it never leaves the device. Authentication requires physical possession of the key and, depending on configuration, a PIN or biometric.
Microsoft Authenticator passwordless sign-in lets users approve a sign-in on their phone using biometric or PIN instead of a password. As of 2024, Authenticator also supports Passkeys — FIDO2-compliant credentials stored within the Authenticator app itself, synchronized across all registered devices via the Microsoft account, enabling phishing-resistant authentication without a hardware key.
Self-Service Password Reset (SSPR) allows users to reset their own passwords without calling the help desk, reducing IT support costs. Users must pre-register at least one verification method (email, phone, authenticator app, security questions). Admins configure SSPR for all users, a selected group, or no users. In hybrid environments, password writeback ensures that when a cloud user resets their password, the change is written back to on-premises AD in real time via Entra Connect — without writeback, on-premises authentication would still use the old password.
External authentication methods allow organizations to use a third-party MFA provider (such as Duo or RSA) as a primary MFA option within Entra ID Conditional Access, satisfying Authentication Strength requirements without migrating users to Microsoft Authenticator.
Entra ID hỗ trợ nhiều phương thức xác thực: Mật khẩu (truyền thống, yếu nhất — dễ bị lừa đảo và credential stuffing); Xác thực đa yếu tố (MFA) — yêu cầu yếu tố xác minh thứ hai: thông báo đẩy Microsoft Authenticator, token phần cứng OATH, SMS/cuộc gọi thoại (ít được ưu tiên — SMS dễ bị SIM swapping), hoặc OTP qua email. MFA giảm đáng kể nguy cơ tài khoản bị xâm phạm — Microsoft báo cáo MFA chặn 99,9% các cuộc tấn công danh tính tự động.
Xác thực không mật khẩu (Passwordless) thay thế mật khẩu hoàn toàn bằng thông tin xác thực kháng lừa đảo. Windows Hello for Business sử dụng nhận dạng sinh trắc học (vân tay, khuôn mặt) hoặc PIN gắn với thiết bị cụ thể. Thông tin xác thực được bảo vệ bởi chip TPM của thiết bị và không bao giờ được truyền qua mạng — ngay cả PIN cũng không bao giờ rời thiết bị.
FIDO2 security keys là thiết bị phần cứng (như YubiKey, Feitian hoặc Identiv) dùng mật mã khóa công khai để đăng nhập không mật khẩu. Khi đăng ký, key tạo cặp khóa và lưu trữ khóa riêng an toàn trên phần cứng — không bao giờ rời thiết bị. Xác thực yêu cầu sở hữu vật lý của key và, tùy cấu hình, PIN hoặc sinh trắc học.
Đăng nhập không mật khẩu Microsoft Authenticator cho phép người dùng phê duyệt đăng nhập trên điện thoại bằng sinh trắc học hoặc PIN thay vì mật khẩu. Từ năm 2024, Authenticator cũng hỗ trợ Passkeys — thông tin xác thực tuân thủ FIDO2 lưu trữ trong app Authenticator, đồng bộ qua tất cả thiết bị đã đăng ký qua tài khoản Microsoft, cho phép xác thực kháng lừa đảo mà không cần hardware key.
Đặt lại mật khẩu tự phục vụ (SSPR) cho phép người dùng đặt lại mật khẩu mà không cần gọi helpdesk, giảm chi phí hỗ trợ IT. Người dùng phải đăng ký trước ít nhất một phương thức xác minh (email, điện thoại, app xác thực, câu hỏi bảo mật). Admin cấu hình SSPR cho tất cả người dùng, nhóm được chọn, hoặc không có người dùng. Trong môi trường hybrid, password writeback đảm bảo khi người dùng đám mây đặt lại mật khẩu, thay đổi được ghi lại vào AD on-premises theo thời gian thực qua Entra Connect — không có writeback, xác thực on-premises vẫn dùng mật khẩu cũ.
External authentication methods cho phép tổ chức sử dụng nhà cung cấp MFA bên thứ ba (như Duo hoặc RSA) làm tùy chọn MFA chính trong Entra ID Conditional Access, đáp ứng yêu cầu Authentication Strength mà không cần di chuyển người dùng sang Microsoft Authenticator.
Conditional Access is Entra ID's policy engine that brings signals together from identity, device, location, and application to make real-time access decisions. Every sign-in is evaluated against all active CA policies. A CA policy has two components: Assignments (the conditions that trigger the policy — who, which apps, what conditions) and Access controls (what happens when the policy is triggered — grant with requirements, or block). Requires Entra ID P1 or higher.
Identity and risk signals Conditional Access evaluates: user and group membership, directory roles assigned, sign-in risk (elevated when Entra's ML model detects anomalous behavior such as atypical travel or anonymous IP use), and user risk (elevated when credentials may be compromised, as detected by Entra ID Protection — risk policies require P2).
Device and location signals: device platform (Windows, iOS, Android, macOS, Linux); device compliance state (managed and marked compliant by Intune); named locations (defined corporate IP ranges, or country/region lists); client application type (modern authentication browser or app vs legacy authentication client vs Exchange ActiveSync); and real-time session context via Continuous Access Evaluation (CAE).
Require MFA for all admins — any user holding a privileged role (Global Administrator, Exchange Administrator, etc.) must complete MFA at every sign-in. This is the highest-priority CA policy in most organizations and should always be in Report-only mode before enforcing.
Block legacy authentication — blocks Basic Auth, SMTP Auth, and other legacy protocols that do not support modern MFA challenges. This is critical: legacy authentication clients completely bypass MFA, and the majority of password-spray attacks target legacy auth endpoints.
Require compliant device for sensitive apps — only devices managed by Intune and marked compliant (correct OS version, encryption enabled, no jailbreak) can access Exchange Online, SharePoint Online, or other sensitive workloads. Drives device enrollment adoption.
Block access from untrusted countries — named locations define allowed countries; access attempts originating outside these locations are blocked. Combined with sign-in risk, this significantly reduces exposure to credential attacks from high-risk regions.
Global Administrator has unrestricted access to all Entra ID and Microsoft 365 admin features. This role should be held by fewer than 5 accounts, all of which must be cloud-only, MFA-protected, and monitored via PIM.
User Administrator can create and manage users and groups, reset passwords for non-admin users, and manage licenses. Security Administrator can manage security policies, configure Conditional Access policies, and read security reports and alerts. Conditional Access Administrator can create and modify CA policies without needing the full Security Administrator role. Assign the narrowest role that allows the person to complete their task.
Conditional Access là công cụ chính sách của Entra ID tập hợp tín hiệu từ danh tính, thiết bị, vị trí và ứng dụng để đưa ra quyết định truy cập theo thời gian thực. Mỗi lần đăng nhập được đánh giá dựa trên tất cả chính sách CA đang hoạt động. Chính sách CA có hai thành phần: Assignments (điều kiện kích hoạt chính sách — ai, ứng dụng nào, điều kiện gì) và Access controls (điều gì xảy ra khi chính sách được kích hoạt — cấp quyền với yêu cầu, hoặc chặn). Yêu cầu Entra ID P1 trở lên.
Tín hiệu danh tính và rủi ro Conditional Access đánh giá: thành viên người dùng và nhóm, vai trò thư mục được gán, sign-in risk (tăng khi mô hình ML của Entra phát hiện hành vi bất thường như di chuyển không điển hình hoặc sử dụng IP ẩn danh), và user risk (tăng khi thông tin xác thực có thể bị xâm phạm, được phát hiện bởi Entra ID Protection — chính sách rủi ro yêu cầu P2).
Tín hiệu thiết bị và vị trí: nền tảng thiết bị (Windows, iOS, Android, macOS, Linux); trạng thái tuân thủ thiết bị (được quản lý và đánh dấu tuân thủ bởi Intune); named locations (dải IP doanh nghiệp đã xác định, hoặc danh sách quốc gia/vùng); loại ứng dụng khách (trình duyệt xác thực hiện đại hoặc app vs client xác thực legacy vs Exchange ActiveSync); và ngữ cảnh phiên theo thời gian thực qua Continuous Access Evaluation (CAE).
Yêu cầu MFA cho tất cả admin — bất kỳ người dùng nào giữ vai trò đặc quyền (Global Administrator, Exchange Administrator, v.v.) phải hoàn thành MFA ở mỗi lần đăng nhập. Đây là chính sách CA ưu tiên cao nhất ở hầu hết tổ chức và nên ở chế độ Report-only trước khi thực thi.
Chặn xác thực legacy — chặn Basic Auth, SMTP Auth và các giao thức legacy khác không hỗ trợ thách thức MFA hiện đại. Điều này rất quan trọng: client xác thực legacy hoàn toàn bỏ qua MFA, và phần lớn các cuộc tấn công password-spray nhắm vào endpoint xác thực legacy.
Yêu cầu thiết bị tuân thủ cho app nhạy cảm — chỉ thiết bị được quản lý bởi Intune và được đánh dấu tuân thủ (phiên bản OS đúng, mã hóa bật, không jailbreak) mới có thể truy cập Exchange Online, SharePoint Online hoặc workload nhạy cảm khác. Thúc đẩy việc đăng ký thiết bị.
Chặn truy cập từ quốc gia không tin cậy — named locations xác định các quốc gia được phép; các lần đăng nhập từ ngoài các vị trí này bị chặn. Kết hợp với sign-in risk, điều này giảm đáng kể nguy cơ từ các cuộc tấn công thông tin xác thực từ khu vực rủi ro cao.
Global Administrator có quyền truy cập không hạn chế vào tất cả tính năng admin Entra ID và Microsoft 365. Vai trò này nên được nắm giữ bởi ít hơn 5 tài khoản, tất cả phải là cloud-only, được bảo vệ MFA và được giám sát qua PIM.
User Administrator có thể tạo và quản lý người dùng và nhóm, đặt lại mật khẩu cho người dùng không phải admin và quản lý giấy phép. Security Administrator có thể quản lý chính sách bảo mật, cấu hình chính sách Conditional Access và đọc báo cáo và cảnh báo bảo mật. Conditional Access Administrator có thể tạo và sửa đổi chính sách CA mà không cần vai trò Security Administrator đầy đủ. Gán vai trò hẹp nhất cho phép người đó hoàn thành nhiệm vụ.
Identity Governance helps organizations ensure the right people have the right access to the right resources, at the right time, and for the right reasons — while also providing audit evidence of these access decisions. It balances security and productivity: too little access blocks users from doing their jobs; too much access (access accumulation over time) creates security risk.
Privileged Identity Management (PIM) provides just-in-time privileged access. Instead of permanently assigning powerful roles (Global Administrator, Exchange Administrator), users are made "Eligible" — they must request activation, provide justification, optionally get approval, and the role activates for a limited time (1–24 hours). This reduces the standing attack surface: a compromised account that only has eligible assignments cannot be used for privilege escalation without going through the activation workflow.
Entitlement Management automates access request, approval, and removal workflows. Admins define access packages — bundles of groups, applications, and SharePoint sites — with policies governing who can request them and how long access lasts. Users visit the My Access portal to discover and request packages. When an assignment expires, access to all included resources is revoked automatically. This eliminates the manual process of provisioning and deprovisioning access.
Access Reviews enable periodic, structured reviews of access to ensure it remains appropriate. A resource owner or manager reviews which users still need membership in a group or access to an application, approves or denies continued access, and results are automatically applied. This addresses the common problem of "access accumulation" — employees who move between roles accumulate access from previous jobs that is never removed.
Lifecycle Workflows (Entra ID Governance feature) automate identity lifecycle tasks using a no-code workflow designer. Workflows are triggered either on a schedule or by attribute changes — for example, a workflow can fire automatically when the employeeHireDate attribute matches the current date. Each workflow calls built-in or custom tasks (add to group, generate TAP, send email, call Logic App).
Joiner scenario — when a new employee is hired, Lifecycle Workflows can automatically: generate a Temporary Access Pass (TAP) for first-day passwordless sign-in, add the user to the appropriate department groups and distribution lists, assign licenses, and send a welcome email to the user and manager before the first day of work.
Mover scenario — when an employee changes roles or departments, workflows update group memberships (removing old team groups, adding new team groups), reassign licenses appropriate to the new role, and notify stakeholders of the transfer — ensuring access reflects the current job, not the previous one.
Leaver scenario — when an employee leaves the organization, workflows disable the account, remove all group memberships and licenses, forward the manager a list of revoked access, archive the mailbox, and schedule account deletion after a configurable number of days (to allow recovery if the departure is reversed). This fully automated offboarding eliminates manual deprovisioning steps that are easily missed.
Quản trị danh tính (Identity Governance) giúp tổ chức đảm bảo đúng người có đúng quyền truy cập vào đúng tài nguyên, vào đúng thời điểm và vì đúng lý do — đồng thời cung cấp bằng chứng kiểm tra về các quyết định truy cập này. Nó cân bằng bảo mật và năng suất: quá ít quyền truy cập ngăn người dùng làm việc; quá nhiều quyền truy cập (tích lũy truy cập theo thời gian) tạo ra rủi ro bảo mật.
Privileged Identity Management (PIM) cung cấp truy cập đặc quyền đúng lúc (JIT). Thay vì gán vĩnh viễn các vai trò mạnh (Global Administrator, Exchange Administrator), người dùng được đặt là "Eligible" — họ phải yêu cầu kích hoạt, cung cấp lý do, tùy chọn được phê duyệt, và vai trò kích hoạt trong thời gian giới hạn (1–24 giờ). Điều này giảm bề mặt tấn công thường trực: tài khoản bị xâm phạm chỉ có gán eligible không thể được dùng để leo thang đặc quyền mà không qua quy trình kích hoạt.
Entitlement Management tự động hóa quy trình yêu cầu, phê duyệt và xóa quyền truy cập. Admin xác định access packages — gói nhóm, ứng dụng và site SharePoint — với chính sách quy định ai có thể yêu cầu và quyền truy cập kéo dài bao lâu. Người dùng truy cập cổng My Access để khám phá và yêu cầu gói. Khi gán hết hạn, quyền truy cập vào tất cả tài nguyên bao gồm được thu hồi tự động. Điều này loại bỏ quy trình thủ công cấp phát và thu hồi quyền truy cập.
Access Reviews cho phép xem xét định kỳ, có cấu trúc về quyền truy cập để đảm bảo nó vẫn phù hợp. Chủ sở hữu tài nguyên hoặc quản lý xem xét người dùng nào vẫn cần thành viên trong nhóm hoặc quyền truy cập ứng dụng, phê duyệt hoặc từ chối tiếp tục truy cập, và kết quả được tự động áp dụng. Điều này giải quyết vấn đề phổ biến "tích lũy truy cập" — nhân viên chuyển giữa vai trò tích lũy quyền truy cập từ công việc trước đây không bao giờ bị xóa.
Lifecycle Workflows (tính năng Entra ID Governance) tự động hóa các tác vụ vòng đời danh tính bằng trình thiết kế workflow không cần code. Workflow được kích hoạt theo lịch hoặc bởi thay đổi thuộc tính — ví dụ, workflow có thể tự động chạy khi thuộc tính employeeHireDate khớp với ngày hiện tại. Mỗi workflow gọi các tác vụ có sẵn hoặc tùy chỉnh (thêm vào nhóm, tạo TAP, gửi email, gọi Logic App).
Kịch bản Joiner — khi nhân viên mới được tuyển dụng, Lifecycle Workflows có thể tự động: tạo Temporary Access Pass (TAP) để đăng nhập không mật khẩu ngày đầu tiên, thêm người dùng vào các nhóm bộ phận và danh sách phân phối phù hợp, gán giấy phép và gửi email chào mừng đến người dùng và quản lý trước ngày làm việc đầu tiên.
Kịch bản Mover — khi nhân viên thay đổi vai trò hoặc bộ phận, workflow cập nhật thành viên nhóm (xóa nhóm team cũ, thêm nhóm team mới), gán lại giấy phép phù hợp với vai trò mới và thông báo cho các bên liên quan về việc chuyển — đảm bảo quyền truy cập phản ánh công việc hiện tại, không phải công việc trước đó.
Kịch bản Leaver — khi nhân viên rời tổ chức, workflow vô hiệu hóa tài khoản, xóa tất cả thành viên nhóm và giấy phép, chuyển cho quản lý danh sách quyền truy cập đã thu hồi, lưu trữ hộp thư và lên lịch xóa tài khoản sau số ngày có thể cấu hình (để cho phép khôi phục nếu việc rời đi bị đảo ngược). Quy trình offboarding tự động hoàn toàn này loại bỏ các bước hủy cấp phép thủ công dễ bị bỏ sót.
Azure DDoS Protection defends Azure resources against Distributed Denial-of-Service attacks. DDoS Network Protection (Basic, free) is automatically enabled for all Azure services and provides always-on traffic monitoring and mitigation of common network-layer attacks. DDoS IP Protection (paid) adds adaptive tuning, attack analytics, telemetry, and SLA guarantee with cost protection. DDoS protection works at layers 3 and 4 (network and transport) of the OSI model.
Azure Firewall is a managed, cloud-native, fully stateful network firewall service with built-in high availability and unrestricted cloud scalability. Unlike NSGs (which are basic packet filters on subnets and NICs), Azure Firewall is a centralized network security service deployed in a hub VNet and inspects all traffic flowing through the hub in hub-spoke architectures.
Network traffic filtering supports FQDN (fully qualified domain name) rules — allowing or blocking traffic to external domains like storage.azure.com — in addition to IP address and port rules. Threat Intelligence-based filtering automatically blocks outbound traffic to known malicious IPs and domains, updated continuously from Microsoft's global threat intelligence feed.
DNS proxy and TLS inspection allow Azure Firewall to decrypt HTTPS traffic (using a certificate) so that FQDN rules and Threat Intelligence can be applied to encrypted web traffic — not just metadata. The Premium SKU adds IDPS (Intrusion Detection and Prevention System), which uses signature-based detection to identify and block attack patterns in network traffic in real time.
Web Application Firewall (WAF) protects web applications from common exploits and vulnerabilities — specifically OWASP Top 10 attacks such as SQL injection, cross-site scripting (XSS), and command injection. Azure WAF can be deployed on Azure Application Gateway (regional, for apps within a region), Azure Front Door (global, for apps served worldwide), and Azure CDN. WAF uses managed rule sets that are automatically updated as new threats emerge.
Network Security Groups (NSGs) are the basic network traffic filter for Azure. An NSG contains a list of security rules that allow or deny inbound or outbound traffic based on source/destination IP, port, and protocol. NSGs can be applied to subnets (affecting all VMs in the subnet) or individual network interface cards (NICs). Rules are evaluated in priority order (lower number = higher priority); if no rule matches, the default rules allow VNet-to-VNet traffic and deny all internet inbound.
Azure Bastion provides secure, browser-based RDP and SSH connectivity to VMs directly through the Azure portal, without exposing VMs to the public internet. Instead of opening port 3389 (RDP) or 22 (SSH) to the internet, admins connect through Bastion over HTTPS (port 443). Bastion is deployed in the virtual network and provides a managed jump host experience — no public IP is needed on the target VM.
Azure DDoS Protection bảo vệ tài nguyên Azure khỏi các cuộc tấn công Từ chối Dịch vụ Phân tán. DDoS Network Protection (Basic, miễn phí) tự động bật cho tất cả dịch vụ Azure và cung cấp giám sát lưu lượng liên tục và giảm thiểu các cuộc tấn công tầng mạng phổ biến. DDoS IP Protection (trả phí) thêm điều chỉnh thích ứng, phân tích tấn công, telemetry và đảm bảo SLA với bảo vệ chi phí. DDoS protection hoạt động ở tầng 3 và 4 (mạng và vận chuyển) của mô hình OSI.
Azure Firewall là dịch vụ firewall mạng đầy đủ trạng thái, native cloud được quản lý với tính sẵn sàng cao tích hợp và khả năng mở rộng đám mây không hạn chế. Khác với NSG (là bộ lọc packet cơ bản trên subnet và NIC), Azure Firewall là dịch vụ bảo mật mạng tập trung được triển khai trong hub VNet và kiểm tra tất cả lưu lượng qua hub trong kiến trúc hub-spoke.
Lọc lưu lượng mạng hỗ trợ quy tắc FQDN (tên miền đầy đủ) — cho phép hoặc chặn lưu lượng đến các tên miền bên ngoài như storage.azure.com — ngoài quy tắc địa chỉ IP và port. Lọc dựa trên Threat Intelligence tự động chặn lưu lượng ra đến IP và tên miền độc hại đã biết, được cập nhật liên tục từ nguồn thông tin tình báo mối đe dọa toàn cầu của Microsoft.
DNS proxy và kiểm tra TLS cho phép Azure Firewall giải mã lưu lượng HTTPS (bằng chứng chỉ) để quy tắc FQDN và Threat Intelligence có thể được áp dụng cho lưu lượng web được mã hóa — không chỉ metadata. SKU Premium bổ sung IDPS (Hệ thống Phát hiện và Ngăn chặn Xâm nhập), sử dụng phát hiện dựa trên chữ ký để xác định và chặn các mẫu tấn công trong lưu lượng mạng theo thời gian thực.
Web Application Firewall (WAF) bảo vệ ứng dụng web khỏi các khai thác và lỗ hổng phổ biến — đặc biệt là các cuộc tấn công OWASP Top 10 như SQL injection, cross-site scripting (XSS) và command injection. Azure WAF có thể triển khai trên Azure Application Gateway (khu vực, cho app trong một vùng), Azure Front Door (toàn cầu, cho app phục vụ trên toàn thế giới) và Azure CDN. WAF sử dụng tập quy tắc được quản lý, tự động cập nhật khi xuất hiện mối đe dọa mới.
Network Security Groups (NSGs) là bộ lọc lưu lượng mạng cơ bản của Azure. NSG chứa danh sách quy tắc bảo mật cho phép hoặc từ chối lưu lượng vào/ra dựa trên IP nguồn/đích, port và giao thức. NSG có thể áp dụng cho subnet (ảnh hưởng tất cả VM trong subnet) hoặc card mạng (NIC) riêng lẻ. Các quy tắc được đánh giá theo thứ tự ưu tiên (số nhỏ hơn = ưu tiên cao hơn); nếu không có quy tắc nào khớp, các quy tắc mặc định cho phép lưu lượng VNet-to-VNet và từ chối tất cả internet inbound.
Azure Bastion cung cấp kết nối RDP và SSH an toàn qua trình duyệt tới VM trực tiếp qua Azure portal, mà không cần để lộ VM ra internet công khai. Thay vì mở port 3389 (RDP) hoặc 22 (SSH) ra internet, admin kết nối qua Bastion qua HTTPS (port 443). Bastion được triển khai trong virtual network và cung cấp trải nghiệm jump host được quản lý — VM đích không cần IP công khai.
Microsoft Defender for Cloud (formerly Azure Security Center + Azure Defender) is a unified cloud security posture management (CSPM) and cloud workload protection (CWP) platform. It helps organizations prevent, detect, and respond to threats across Azure, on-premises, and multi-cloud environments (AWS and Google Cloud via Azure Arc). It provides two distinct capabilities: security posture assessment and workload threat protection.
Secure Score is Defender for Cloud's posture measurement tool. It aggregates security assessments across subscriptions and resources into a single percentage score (0–100%). A higher Secure Score means better security posture. Defender for Cloud provides prioritized security recommendations with remediation steps — for example, "Enable MFA for accounts with owner permissions on your subscription" or "Apply Just-In-Time access control to virtual machines." Each recommendation shows its impact on the Secure Score if remediated.
Regulatory compliance in Defender for Cloud maps your resources against industry standards and regulatory benchmarks: Microsoft Cloud Security Benchmark (MCSB), CIS Azure Foundations, PCI-DSS, ISO 27001, NIST SP 800-53, SOC 2, HIPAA, and others. The compliance dashboard shows which controls are passing and which are failing, providing audit-ready evidence for compliance assessments.
Cloud Workload Protection (enhanced security features) provides advanced threat detection for specific Azure resource types. Each plan is enabled per subscription and per resource type — organizations pay only for the workloads they protect.
Defender for Servers integrates Microsoft Defender for Endpoint on Azure VMs, providing EDR, just-in-time (JIT) VM access (open RDP/SSH only on demand to eliminate standing attack surface), file integrity monitoring, and adaptive application controls (allowlist for processes expected to run on a given VM).
Defender for Storage scans every blob uploaded to Azure Storage for malware using Microsoft Threat Intelligence and detects access from anomalous sources, sensitive data exfiltration patterns, and unusual geographic access. Defender for SQL monitors Azure SQL databases and SQL Server on machines for SQL injection attempts, unusual authentication patterns, and brute-force attacks against the database engine.
Defender for Containers provides threat detection at the Kubernetes cluster level (AKS and Arc-enabled clusters): detects runtime threats on nodes, suspicious container activity, privilege escalation, and cryptocurrency mining. It also includes registry vulnerability scanning and CI/CD pipeline integration via admission controllers. Additional plans — Defender for App Service, Defender for Key Vault, and Defender for DNS — extend coverage to PaaS services.
Microsoft Defender for Cloud (trước đây là Azure Security Center + Azure Defender) là nền tảng quản lý tư thế bảo mật đám mây (CSPM) và bảo vệ khối lượng công việc đám mây (CWP) thống nhất. Giúp tổ chức ngăn chặn, phát hiện và phản ứng với các mối đe dọa trên Azure, on-premises và đa đám mây (AWS và Google Cloud qua Azure Arc). Cung cấp hai khả năng riêng biệt: đánh giá tư thế bảo mật và bảo vệ khối lượng công việc khỏi mối đe dọa.
Secure Score là công cụ đo lường tư thế của Defender for Cloud. Tổng hợp các đánh giá bảo mật trên các subscription và tài nguyên thành một điểm phần trăm duy nhất (0–100%). Điểm Secure Score cao hơn có nghĩa là tư thế bảo mật tốt hơn. Defender for Cloud cung cấp các khuyến nghị bảo mật được ưu tiên với các bước khắc phục — ví dụ: "Bật MFA cho tài khoản có quyền owner trên subscription của bạn" hoặc "Áp dụng kiểm soát truy cập Just-In-Time cho máy ảo." Mỗi khuyến nghị hiển thị tác động lên Secure Score nếu được khắc phục.
Tuân thủ quy định trong Defender for Cloud ánh xạ tài nguyên của bạn theo các tiêu chuẩn ngành và tiêu chuẩn quy định: Microsoft Cloud Security Benchmark (MCSB), CIS Azure Foundations, PCI-DSS, ISO 27001, NIST SP 800-53, SOC 2, HIPAA và các tiêu chuẩn khác. Dashboard tuân thủ hiển thị kiểm soát nào đang qua và kiểm soát nào đang thất bại, cung cấp bằng chứng sẵn sàng kiểm tra cho các đánh giá tuân thủ.
Bảo vệ khối lượng công việc đám mây (enhanced security) cung cấp phát hiện mối đe dọa nâng cao cho các loại tài nguyên Azure cụ thể. Mỗi gói được bật theo subscription và loại tài nguyên — tổ chức chỉ trả cho các khối lượng công việc họ bảo vệ.
Defender for Servers tích hợp Microsoft Defender for Endpoint trên Azure VM, cung cấp EDR, truy cập VM just-in-time (JIT) (mở RDP/SSH chỉ theo yêu cầu để loại bỏ bề mặt tấn công thường trực), giám sát toàn vẹn file và kiểm soát ứng dụng thích ứng (allowlist cho các tiến trình dự kiến chạy trên VM cụ thể).
Defender for Storage quét mọi blob được tải lên Azure Storage để tìm phần mềm độc hại bằng Microsoft Threat Intelligence và phát hiện truy cập từ nguồn bất thường, mẫu đánh cắp dữ liệu nhạy cảm và truy cập địa lý bất thường. Defender for SQL giám sát cơ sở dữ liệu Azure SQL và SQL Server trên máy tìm các lần thử SQL injection, mẫu xác thực bất thường và tấn công brute-force vào engine cơ sở dữ liệu.
Defender for Containers cung cấp phát hiện mối đe dọa ở cấp cluster Kubernetes (AKS và cluster được kích hoạt Arc): phát hiện mối đe dọa runtime trên node, hoạt động container đáng ngờ, leo thang đặc quyền và khai thác tiền điện tử. Cũng bao gồm quét lỗ hổng registry và tích hợp pipeline CI/CD qua admission controller. Các gói bổ sung — Defender for App Service, Defender for Key Vault và Defender for DNS — mở rộng phạm vi bảo vệ sang dịch vụ PaaS.
Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. As a SIEM, it collects, aggregates, and analyzes security data from across the enterprise to detect threats. As a SOAR, it automates investigation and response to detected threats using playbooks. Sentinel is built on top of Azure Monitor Log Analytics and uses KQL (Kusto Query Language) for querying log data.
Data connectors are how Sentinel ingests data from different sources. Microsoft provides hundreds of built-in connectors for: Microsoft services (Microsoft 365, Entra ID sign-in logs, Defender products); Azure resources (Azure Activity logs, NSG flow logs); third-party security products (firewalls, endpoint protection from Palo Alto, Fortinet, CrowdStrike, etc.); custom sources via Syslog, CEF (Common Event Format), or REST API. Data is stored in a Log Analytics workspace, priced per GB ingested.
Analytics rules run continuously on ingested data to detect threats and create incidents — security alerts grouped into a single investigation case containing all related alerts, entities (users, IPs, hosts), and evidence. Sentinel offers five rule types, each suited to different detection scenarios.
Scheduled rules run a KQL query against the Log Analytics workspace on a configurable schedule (e.g., every 5 minutes, every hour). Analysts write these queries to define exactly what constitutes a threat — for example, "more than 10 failed sign-ins followed by a successful sign-in within 5 minutes from the same IP." This is the most flexible rule type and covers the majority of custom detection logic.
Near Real-time (NRT) rules run a single-table KQL query once per minute. They sacrifice scheduling flexibility for low-latency detection — useful for high-severity, time-sensitive threats where a 5-minute delay is unacceptable.
Fusion rules use ML to correlate low-fidelity signals across multiple data sources into high-confidence multi-stage attack incidents. Fusion detects attack kill chains (initial access → lateral movement → data exfiltration) that would generate too many false positives if each individual signal were treated as an alert.
Anomaly rules use ML to build a behavioral baseline per entity (user, host, IP) and fire when behavior deviates significantly — for example, a user downloading 10× their normal data volume, or a service account authenticating at an unusual hour.
Microsoft Security rules automatically forward alerts from connected Defender products (Defender for Endpoint, Defender for Office 365, Defender for Identity) into Sentinel as incidents. This provides a single investigation pane across all Microsoft security signals.
Playbooks (built on Azure Logic Apps) automate response actions when an incident is created. Common automated responses: send Teams/email alert to the SOC team; block a suspicious user in Entra ID; isolate a compromised VM; add an IP to a firewall block list; create a ServiceNow/Jira ticket. Playbooks can be triggered manually or automatically when an analytics rule fires. This is the SOAR capability that reduces mean time to respond (MTTR).
Microsoft Sentinel là giải pháp Quản lý Thông tin và Sự kiện Bảo mật (SIEM) và Điều phối, Tự động hóa và Phản hồi Bảo mật (SOAR) native cloud. Là SIEM, nó thu thập, tổng hợp và phân tích dữ liệu bảo mật trên toàn doanh nghiệp để phát hiện mối đe dọa. Là SOAR, nó tự động điều tra và phản hồi với mối đe dọa được phát hiện bằng playbooks. Sentinel được xây dựng trên Azure Monitor Log Analytics và sử dụng KQL (Kusto Query Language) để truy vấn dữ liệu nhật ký.
Data connectors là cách Sentinel tiếp nhận dữ liệu từ các nguồn khác nhau. Microsoft cung cấp hàng trăm connector tích hợp sẵn cho: dịch vụ Microsoft (Microsoft 365, nhật ký đăng nhập Entra ID, sản phẩm Defender); tài nguyên Azure (Azure Activity logs, NSG flow logs); sản phẩm bảo mật bên thứ ba (firewall, bảo vệ endpoint từ Palo Alto, Fortinet, CrowdStrike, v.v.); nguồn tùy chỉnh qua Syslog, CEF (Common Event Format) hoặc REST API. Dữ liệu được lưu trong Log Analytics workspace, tính phí theo GB được tiếp nhận.
Analytics rules chạy liên tục trên dữ liệu đã tiếp nhận để phát hiện mối đe dọa và tạo incidents — cảnh báo bảo mật được nhóm thành một trường hợp điều tra duy nhất chứa tất cả cảnh báo liên quan, thực thể (người dùng, IP, máy chủ) và bằng chứng. Sentinel cung cấp năm loại quy tắc, mỗi loại phù hợp với các kịch bản phát hiện khác nhau.
Scheduled rules chạy truy vấn KQL đối với Log Analytics workspace theo lịch có thể cấu hình (ví dụ: mỗi 5 phút, mỗi giờ). Analyst viết các truy vấn này để xác định chính xác điều gì cấu thành mối đe dọa — ví dụ: "hơn 10 lần đăng nhập thất bại theo sau đăng nhập thành công trong 5 phút từ cùng IP." Đây là loại quy tắc linh hoạt nhất và bao gồm phần lớn logic phát hiện tùy chỉnh.
Near Real-time (NRT) rules chạy truy vấn KQL một bảng mỗi phút một lần. Họ hy sinh tính linh hoạt lập lịch để phát hiện độ trễ thấp — hữu ích cho các mối đe dọa có mức độ nghiêm trọng cao, nhạy cảm về thời gian khi độ trễ 5 phút là không thể chấp nhận.
Fusion rules sử dụng ML để tương quan các tín hiệu độ tin cậy thấp trên nhiều nguồn dữ liệu thành các incidents tấn công đa giai đoạn có độ tin cậy cao. Fusion phát hiện kill chain tấn công (truy cập ban đầu → di chuyển ngang → đánh cắp dữ liệu) mà sẽ tạo ra quá nhiều false positive nếu mỗi tín hiệu riêng lẻ được coi là cảnh báo.
Anomaly rules sử dụng ML để xây dựng đường cơ sở hành vi cho từng thực thể (người dùng, máy chủ, IP) và kích hoạt khi hành vi lệch đáng kể — ví dụ: người dùng tải xuống 10 lần khối lượng dữ liệu bình thường, hoặc tài khoản dịch vụ xác thực vào giờ bất thường.
Microsoft Security rules tự động chuyển tiếp cảnh báo từ các sản phẩm Defender đã kết nối (Defender for Endpoint, Defender for Office 365, Defender for Identity) vào Sentinel dưới dạng incidents. Điều này cung cấp một cửa sổ điều tra duy nhất trên tất cả tín hiệu bảo mật Microsoft.
Playbooks (xây dựng trên Azure Logic Apps) tự động hóa các hành động phản hồi khi incident được tạo. Phản hồi tự động phổ biến: gửi cảnh báo Teams/email cho nhóm SOC; chặn người dùng đáng ngờ trong Entra ID; cô lập VM bị xâm phạm; thêm IP vào danh sách chặn firewall; tạo ticket ServiceNow/Jira. Playbooks có thể được kích hoạt thủ công hoặc tự động khi quy tắc analytics kích hoạt. Đây là khả năng SOAR giảm thời gian phản hồi trung bình (MTTR).
Microsoft Defender XDR (formerly Microsoft 365 Defender) is an integrated eXtended Detection and Response (XDR) solution that natively coordinates detection, prevention, investigation, and response across endpoints, email, identities, cloud apps, and data. XDR automatically correlates signals from multiple sources to surface high-confidence incidents, reducing alert fatigue compared to reviewing individual product alerts separately.
Microsoft Defender for Endpoint (MDE) is an enterprise endpoint security platform for Windows, macOS, Linux, iOS, and Android. It integrates multiple protection layers that work together across the attack lifecycle.
Threat and vulnerability management (TVM) continuously discovers software vulnerabilities, misconfigurations, and missing patches across enrolled devices. It prioritizes them by exploitability and business impact, giving security teams a ranked remediation backlog without running manual scans.
Attack surface reduction (ASR) rules block specific malicious behaviors before they execute — such as credential dumping from LSASS, Office application spawning child processes, macro-based payload execution, and executable content launched from email. ASR rules can run in audit mode for testing before enforcement.
Next-generation protection is an AI-based antivirus and behavior monitoring engine. It detects malware using file-based signatures, cloud-delivered ML models, and real-time behavioral analysis — catching fileless attacks and living-off-the-land techniques that signature-only engines miss.
Endpoint Detection and Response (EDR) records rich telemetry from devices and detects advanced post-breach activity — lateral movement, credential theft, persistence mechanisms — surfaced as alerts in the Defender XDR portal. Automated investigation and remediation (AIR) uses playbooks to automatically investigate alerts, determine scope, and remediate threats without requiring analyst intervention for every alert.
Microsoft Defender for Office 365 (MDO) protects email and collaboration from advanced threats — phishing, malware, business email compromise, and spam — that bypass standard Exchange Online Protection (EOP) filtering.
Safe Attachments detonates every email attachment in a cloud-hosted virtual sandbox before delivery. If the attachment triggers malicious behavior (drops a payload, contacts a C2 server, encrypts files), it is blocked and never delivered. This protects against zero-day malware and weaponized Office documents with no signature available yet.
Safe Links rewrites URLs in emails and Office documents at delivery time, then re-checks each link against Microsoft's threat intelligence at the moment the user clicks it. If the destination URL has been identified as malicious between delivery and click (a common tactic called "time-of-click URL detonation"), the user is blocked and warned.
Anti-phishing policies protect against impersonation attacks — domain spoofing, look-alike domains (m1crosoft.com vs microsoft.com), display name spoofing ("CEO Name" sent from an external address), and mailbox intelligence-based impersonation. MDO Plan 2 adds threat hunting with Advanced Hunting queries, Attack Simulator for running phishing simulations against your own users, and campaign view for understanding coordinated attack campaigns.
Microsoft Defender for Identity (MDI) uses on-premises Active Directory signals to detect advanced threats, compromised identities, and malicious insider actions. MDI sensors (installed on Domain Controllers) monitor AD authentication traffic — Kerberos, NTLM, LDAP — and detect attacks like pass-the-hash, overpass-the-hash, golden ticket, DCSync, and reconnaissance. Alerts are surfaced in the Defender XDR portal with investigation context.
Microsoft Defender for Cloud Apps (MDCA, formerly MCAS) is a Cloud Access Security Broker (CASB) that sits between users and cloud services to enforce security policies across sanctioned and unsanctioned apps.
Shadow IT discovery identifies all cloud apps in use by analyzing network traffic logs from firewalls or proxies. Each discovered app receives a risk score based on data handling practices, certifications, and regulatory compliance. Admins can sanction apps (allow), block apps, or tag them for monitoring — without requiring agents on user devices.
Session control uses a reverse proxy to enforce real-time policies during active sessions — for example, blocking file downloads from Salesforce on unmanaged devices, or restricting copy-paste of sensitive data in browser-based SaaS applications. Unlike traditional CASB that only blocks at the IP level, session control allows fine-grained in-session enforcement.
Information protection applies Microsoft Purview DLP policies to SaaS applications (Salesforce, Box, ServiceNow, and others). MDCA scans files stored in connected apps for sensitive content and can apply sensitivity labels, quarantine files, or alert administrators when policy violations are found — extending on-premises DLP coverage to the cloud.
Microsoft Defender XDR (trước đây là Microsoft 365 Defender) là giải pháp Phát hiện và Phản hồi Mở rộng (XDR) tích hợp, điều phối tự nhiên việc phát hiện, ngăn chặn, điều tra và phản hồi trên endpoint, email, danh tính, ứng dụng đám mây và dữ liệu. XDR tự động tương quan tín hiệu từ nhiều nguồn để hiển thị các sự cố có độ tin cậy cao, giảm mệt mỏi cảnh báo so với việc xem xét riêng lẻ từng cảnh báo sản phẩm.
Microsoft Defender for Endpoint (MDE) là nền tảng bảo mật endpoint doanh nghiệp cho Windows, macOS, Linux, iOS và Android. Nó tích hợp nhiều lớp bảo vệ phối hợp hoạt động qua toàn bộ vòng đời tấn công.
Quản lý mối đe dọa và lỗ hổng (TVM) liên tục khám phá lỗ hổng phần mềm, cấu hình sai và bản vá bị thiếu trên các thiết bị đã đăng ký. Ưu tiên chúng theo khả năng bị khai thác và tác động kinh doanh, cung cấp cho nhóm bảo mật danh sách khắc phục được xếp hạng mà không cần chạy quét thủ công.
Quy tắc giảm bề mặt tấn công (ASR) chặn các hành vi độc hại cụ thể trước khi chúng thực thi — như credential dumping từ LSASS, ứng dụng Office tạo tiến trình con, thực thi payload dựa trên macro và nội dung thực thi từ email. ASR rules có thể chạy ở chế độ audit để kiểm tra trước khi thực thi.
Bảo vệ thế hệ tiếp theo là công cụ antivirus và giám sát hành vi dựa trên AI. Phát hiện phần mềm độc hại bằng chữ ký file, mô hình ML do đám mây cung cấp và phân tích hành vi theo thời gian thực — bắt các cuộc tấn công fileless và kỹ thuật living-off-the-land mà các công cụ chỉ dùng chữ ký bỏ lỡ.
Phát hiện và Phản hồi Endpoint (EDR) ghi lại telemetry phong phú từ thiết bị và phát hiện hoạt động sau xâm phạm nâng cao — di chuyển ngang, đánh cắp thông tin xác thực, cơ chế duy trì — hiển thị dưới dạng cảnh báo trong cổng Defender XDR. Điều tra và khắc phục tự động (AIR) sử dụng playbook để tự động điều tra cảnh báo, xác định phạm vi và khắc phục mối đe dọa mà không cần analyst can thiệp cho mỗi cảnh báo.
Microsoft Defender for Office 365 (MDO) bảo vệ email và cộng tác khỏi các mối đe dọa nâng cao — lừa đảo, phần mềm độc hại, tấn công email doanh nghiệp và spam — vượt qua bộ lọc Exchange Online Protection (EOP) tiêu chuẩn.
Safe Attachments kích nổ mọi file đính kèm email trong sandbox ảo được lưu trữ trên đám mây trước khi giao. Nếu file đính kèm kích hoạt hành vi độc hại (thả payload, liên hệ máy chủ C2, mã hóa file), nó bị chặn và không bao giờ được giao. Điều này bảo vệ chống lại phần mềm độc hại zero-day và tài liệu Office vũ khí hóa chưa có chữ ký.
Safe Links viết lại URL trong email và tài liệu Office tại thời điểm giao, sau đó kiểm tra lại từng liên kết dựa trên thông tin tình báo mối đe dọa của Microsoft tại thời điểm người dùng nhấp. Nếu URL đích đã được xác định là độc hại giữa thời điểm giao và nhấp (chiến thuật phổ biến gọi là "kích nổ URL tại thời điểm nhấp"), người dùng bị chặn và cảnh báo.
Chính sách chống lừa đảo bảo vệ chống lại các cuộc tấn công mạo danh — domain spoofing, tên miền giống nhau (m1crosoft.com vs microsoft.com), giả mạo tên hiển thị ("Tên CEO" gửi từ địa chỉ bên ngoài) và mạo danh dựa trên thông tin hộp thư. MDO Plan 2 bổ sung threat hunting với Advanced Hunting queries, Attack Simulator để chạy mô phỏng lừa đảo với người dùng của bạn và chế độ xem chiến dịch để hiểu các chiến dịch tấn công phối hợp.
Microsoft Defender for Identity (MDI) sử dụng tín hiệu Active Directory on-premises để phát hiện các mối đe dọa nâng cao, danh tính bị xâm phạm và hành động nội bộ độc hại. Sensor MDI (cài trên Domain Controllers) giám sát lưu lượng xác thực AD — Kerberos, NTLM, LDAP — và phát hiện các cuộc tấn công như pass-the-hash, overpass-the-hash, golden ticket, DCSync và do thám. Cảnh báo được hiển thị trong cổng Defender XDR với ngữ cảnh điều tra.
Microsoft Defender for Cloud Apps (MDCA, trước đây là MCAS) là Cloud Access Security Broker (CASB) đặt giữa người dùng và dịch vụ đám mây để thực thi chính sách bảo mật trên các app được phê chuẩn và chưa được phê chuẩn.
Khám phá Shadow IT xác định tất cả ứng dụng đám mây đang được sử dụng bằng cách phân tích nhật ký lưu lượng mạng từ firewall hoặc proxy. Mỗi app được phát hiện nhận điểm rủi ro dựa trên thực hành xử lý dữ liệu, chứng nhận và tuân thủ quy định. Admin có thể phê chuẩn app (cho phép), chặn app hoặc gắn nhãn để theo dõi — mà không cần agent trên thiết bị người dùng.
Kiểm soát phiên sử dụng reverse proxy để thực thi chính sách theo thời gian thực trong các phiên đang hoạt động — ví dụ: chặn tải xuống file từ Salesforce trên thiết bị không được quản lý, hoặc hạn chế copy-paste dữ liệu nhạy cảm trong ứng dụng SaaS trên trình duyệt. Không giống CASB truyền thống chỉ chặn ở cấp IP, kiểm soát phiên cho phép thực thi chi tiết trong phiên.
Bảo vệ thông tin áp dụng chính sách Microsoft Purview DLP cho ứng dụng SaaS (Salesforce, Box, ServiceNow và các ứng dụng khác). MDCA quét file lưu trữ trong các app đã kết nối để tìm nội dung nhạy cảm và có thể áp dụng nhãn nhạy cảm, cách ly file hoặc cảnh báo admin khi phát hiện vi phạm chính sách — mở rộng phạm vi DLP on-premises sang đám mây.
Microsoft Purview is the unified data governance and compliance solution, consolidating what was previously split across the Microsoft 365 Compliance Center and Azure Purview. It covers information protection, data lifecycle management, insider risk, eDiscovery, audit, and data governance for the entire data estate.
Sensitivity labels (Microsoft Purview Information Protection, formerly AIP) classify documents and emails and enforce protection policies that travel with the content — inside or outside the organization. A label can apply three types of protection simultaneously.
Visual markings add headers, footers, and watermarks so users and recipients immediately know the sensitivity level of the content (e.g., "CONFIDENTIAL - Internal Use Only" stamped on every page of an exported document).
Encryption uses Azure Rights Management (ARM) to protect content cryptographically. Only authorized users can open the file, regardless of where it is stored — email attachments, SharePoint, USB drives, or third-party cloud storage. Permissions can be granular: some users may read-only, others may edit, and expiration dates can force the content to become inaccessible after a set date.
Access restrictions enforce behavioral controls on Office content: no forwarding of emails, no copy-paste from Word documents, no screenshots in Teams meetings. Labels can also trigger DLP policy enforcement automatically based on the label applied.
Labels can be applied manually by users, recommended by the client based on content detected, or applied automatically by the service when sensitive information types (credit cards, health records, custom patterns) are found in document content.
Data Loss Prevention (DLP) policies detect and protect sensitive information from being shared inappropriately. DLP scans content in Exchange Online (email), SharePoint Online, OneDrive, Teams chat, and endpoints (with Endpoint DLP — requiring an MDE-enrolled device). When a policy matches a sensitive information type (credit card numbers, Social Security numbers, health record identifiers, or custom regex patterns), DLP applies a configured response.
DLP response actions range from passive to blocking: alert the admin silently; notify the user with an inline policy tip explaining why the action is restricted; block the action outright (prevent the email from being sent, prevent the file from being uploaded); or require business justification — the user must type an override reason, which is logged for audit. This graduated approach balances protection with user productivity.
Retention labels and policies (Data Lifecycle Management) ensure data is kept for as long as required by regulation and deleted when it's no longer needed. A retention policy applies to an entire location (all Exchange mailboxes, all SharePoint sites); a retention label applies to individual items and can be applied manually or automatically. Retention is critical for organizations subject to regulations like FINRA (7 years for financial records), HIPAA (6 years for medical records), or SEC Rule 17a-4.
Microsoft Purview là giải pháp quản trị dữ liệu và tuân thủ thống nhất, hợp nhất những gì trước đây được tách biệt giữa Microsoft 365 Compliance Center và Azure Purview. Bao gồm bảo vệ thông tin, quản lý vòng đời dữ liệu, rủi ro nội bộ, eDiscovery, kiểm tra và quản trị dữ liệu cho toàn bộ bất động sản dữ liệu.
Nhãn nhạy cảm (Sensitivity labels) (Microsoft Purview Information Protection, trước đây là AIP) phân loại tài liệu và email và thực thi chính sách bảo vệ đi kèm nội dung — bên trong hoặc bên ngoài tổ chức. Nhãn có thể áp dụng đồng thời ba loại bảo vệ.
Đánh dấu trực quan thêm header, footer và watermark để người dùng và người nhận biết ngay mức độ nhạy cảm của nội dung (ví dụ: "BÍ MẬT - Chỉ sử dụng nội bộ" được đóng dấu trên mỗi trang tài liệu xuất).
Mã hóa sử dụng Azure Rights Management (ARM) để bảo vệ nội dung bằng mật mã. Chỉ người dùng được ủy quyền mới có thể mở file, bất kể nơi lưu trữ — file đính kèm email, SharePoint, ổ USB hoặc lưu trữ đám mây bên thứ ba. Quyền có thể chi tiết: một số người dùng chỉ đọc, người khác có thể chỉnh sửa, và ngày hết hạn có thể buộc nội dung trở nên không thể truy cập sau ngày cài đặt.
Hạn chế truy cập thực thi các kiểm soát hành vi trên nội dung Office: không chuyển tiếp email, không copy-paste từ tài liệu Word, không chụp màn hình trong cuộc họp Teams. Nhãn cũng có thể tự động kích hoạt thực thi chính sách DLP dựa trên nhãn được áp dụng.
Nhãn có thể được áp dụng thủ công bởi người dùng, được đề xuất bởi client dựa trên nội dung được phát hiện, hoặc áp dụng tự động bởi dịch vụ khi loại thông tin nhạy cảm (thẻ tín dụng, hồ sơ y tế, mẫu tùy chỉnh) được tìm thấy trong nội dung tài liệu.
Chính sách Ngăn chặn Mất dữ liệu (DLP) phát hiện và bảo vệ thông tin nhạy cảm khỏi bị chia sẻ không phù hợp. DLP quét nội dung trong Exchange Online (email), SharePoint Online, OneDrive, Teams chat và endpoint (với Endpoint DLP — yêu cầu thiết bị đã đăng ký MDE). Khi chính sách khớp với loại thông tin nhạy cảm (số thẻ tín dụng, số An sinh Xã hội, định danh hồ sơ y tế hoặc mẫu regex tùy chỉnh), DLP áp dụng phản hồi đã cấu hình.
Các hành động phản hồi DLP từ thụ động đến chặn: cảnh báo admin âm thầm; thông báo người dùng bằng policy tip nội tuyến giải thích tại sao hành động bị hạn chế; chặn hành động hoàn toàn (ngăn email gửi, ngăn file tải lên); hoặc yêu cầu lý do kinh doanh — người dùng phải nhập lý do ghi đè, được ghi lại để kiểm tra. Cách tiếp cận tốt nghiệp này cân bằng bảo vệ với năng suất người dùng.
Nhãn và chính sách lưu giữ (Data Lifecycle Management) đảm bảo dữ liệu được giữ lại theo quy định và xóa khi không còn cần thiết. Retention policy áp dụng cho toàn bộ vị trí (tất cả hộp thư Exchange, tất cả site SharePoint); Retention label áp dụng cho các mục riêng lẻ và có thể áp dụng thủ công hoặc tự động. Lưu giữ rất quan trọng cho các tổ chức tuân theo quy định như FINRA (7 năm cho hồ sơ tài chính), HIPAA (6 năm cho hồ sơ y tế) hoặc SEC Rule 17a-4.
Compliance Manager (in Microsoft Purview) helps organizations manage compliance posture by mapping Microsoft's built-in controls to regulatory requirements. It provides a compliance score (percentage of completed controls), pre-built assessment templates for over 350 regulations (GDPR, ISO 27001, NIST CSF, SOC 2, HIPAA, FedRAMP), and recommended improvement actions with implementation guidance. Compliance Manager tracks both Microsoft's responsibilities (what Microsoft handles as the cloud provider) and customer responsibilities.
The Service Trust Portal (servicetrust.microsoft.com) is Microsoft's central repository for transparency documentation — third-party audit reports, compliance guides, privacy principles, and data protection resources — that organizations can reference when demonstrating Microsoft's security and compliance posture to their own auditors and regulators.
Audit reports on the portal include independent third-party assessments: SOC 1, SOC 2, and SOC 3 reports; ISO 27001 and ISO 27018 certifications; PCI-DSS attestation; FedRAMP authorization packages; and regional and industry-specific certifications. Downloading and presenting these reports to regulators proves Microsoft meets its obligations without requiring customers to audit Microsoft's datacenters directly.
Insider Risk Management (Microsoft Purview) detects, investigates, and acts on potentially risky activities from within the organization — particularly around data theft, data leakage, and policy violations. Common risk scenarios: data theft by departing employees (correlates HR system termination data with file upload/download activity); email policy violations; sharing confidential data with competitors. Insider Risk Management uses ML to detect behavioral anomalies and creates alerts for security teams to investigate. It is privacy-preserving by design — sensitive user data is pseudonymized and investigators must have specific roles to view de-anonymized details.
eDiscovery (electronic discovery) supports legal and compliance investigations by allowing authorized personnel to search, hold, and export content from Microsoft 365 (email, Teams, SharePoint, OneDrive, Yammer). Microsoft Purview eDiscovery (Standard) provides basic hold and export capabilities. eDiscovery (Premium) (formerly Advanced eDiscovery) adds: near-duplicate detection, email threading, smart tags, predictive coding (ML-based relevance ranking), and attorney-client privilege detection — reducing the volume of data that legal teams must review.
Compliance Manager (trong Microsoft Purview) giúp tổ chức quản lý tư thế tuân thủ bằng cách ánh xạ các kiểm soát tích hợp sẵn của Microsoft với các yêu cầu quy định. Cung cấp điểm tuân thủ (phần trăm kiểm soát đã hoàn thành), các template đánh giá có sẵn cho hơn 350 quy định (GDPR, ISO 27001, NIST CSF, SOC 2, HIPAA, FedRAMP) và các hành động cải thiện được khuyến nghị kèm hướng dẫn triển khai. Compliance Manager theo dõi cả trách nhiệm của Microsoft (những gì Microsoft xử lý với tư cách nhà cung cấp đám mây) và trách nhiệm của khách hàng.
Service Trust Portal (servicetrust.microsoft.com) là kho tài liệu minh bạch trung tâm của Microsoft — báo cáo kiểm toán bên thứ ba, hướng dẫn tuân thủ, nguyên tắc quyền riêng tư và tài nguyên bảo vệ dữ liệu — mà tổ chức có thể tham khảo khi chứng minh tư thế bảo mật và tuân thủ của Microsoft cho kiểm toán viên và cơ quan quản lý của họ.
Báo cáo kiểm toán trên portal bao gồm các đánh giá bên thứ ba độc lập: báo cáo SOC 1, SOC 2 và SOC 3; chứng nhận ISO 27001 và ISO 27018; chứng thực PCI-DSS; gói ủy quyền FedRAMP; và chứng nhận khu vực và ngành cụ thể. Tải xuống và trình bày các báo cáo này cho cơ quan quản lý chứng minh Microsoft đáp ứng nghĩa vụ mà không yêu cầu khách hàng kiểm toán trực tiếp trung tâm dữ liệu của Microsoft.
Insider Risk Management (Microsoft Purview) phát hiện, điều tra và hành động đối với các hoạt động có thể rủi ro từ bên trong tổ chức — đặc biệt liên quan đến đánh cắp dữ liệu, rò rỉ dữ liệu và vi phạm chính sách. Kịch bản rủi ro phổ biến: đánh cắp dữ liệu bởi nhân viên sắp nghỉ (tương quan dữ liệu chấm dứt hệ thống HR với hoạt động tải lên/xuống file); vi phạm chính sách email; chia sẻ dữ liệu bí mật với đối thủ cạnh tranh. Insider Risk Management sử dụng ML để phát hiện các bất thường hành vi và tạo cảnh báo cho nhóm bảo mật điều tra. Được thiết kế bảo vệ quyền riêng tư — dữ liệu người dùng nhạy cảm được giả danh và điều tra viên phải có vai trò cụ thể để xem chi tiết được giải mã.
eDiscovery (khám phá điện tử) hỗ trợ các cuộc điều tra pháp lý và tuân thủ bằng cách cho phép nhân sự được ủy quyền tìm kiếm, giữ lại và xuất nội dung từ Microsoft 365 (email, Teams, SharePoint, OneDrive, Yammer). Microsoft Purview eDiscovery (Standard) cung cấp khả năng giữ lại và xuất cơ bản. eDiscovery (Premium) (trước đây là Advanced eDiscovery) thêm: phát hiện gần trùng lặp, phân luồng email, thẻ thông minh, mã hóa dự đoán (xếp hạng mức độ liên quan dựa trên ML) và phát hiện đặc quyền luật sư-khách hàng — giảm khối lượng dữ liệu mà nhóm pháp lý phải xem xét.