Fixing a Multi-Protocol Exchange Server Vulnerability

Exchange hack problem
Exchange hack problem

No fix is available yet for the Exchange vulnerability reported by Dirk-jan Mollema and described in CVE-2018-8581. Apart from deploying a split permissions model, no out-of-the-box mitigation exists today. Microsoft is working actively to fix the problem and in the meantime, the brains of the Exchange community are hard at work to come up with possible solutions.

The post Fixing a Multi-Protocol Exchange Server Vulnerability appeared first on Petri.

Continue reading Fixing a Multi-Protocol Exchange Server Vulnerability

All Versions of On-Premises Exchange Server Vulnerable to New Attack


A newly-discovered vulnerability in Exchange potentially allows attackers to gain control over Active Directory. Since Exchange 2000, Exchange has been a highly-privileged server that’s tightly connected to Active Directory. Add in some NTLM weakness, Exchange Web Services push notifications, and everything comes together for the bad guys.

The post All Versions of On-Premises Exchange Server Vulnerable to New Attack appeared first on Petri.

Continue reading All Versions of On-Premises Exchange Server Vulnerable to New Attack

Encrypted Office 365 Content is a Wake-Up Call for ISVs


The signs are that Office 365 will store more encrypted content as time goes by. But ISV products might not be able to process that content because they cannot decrypt it. All of which creates the prospect that you might archive or move data somewhere only to discover later that it is inaccessible. And that’s a bad thing.

The post Encrypted Office 365 Content is a Wake-Up Call for ISVs appeared first on Petri.

Continue reading Encrypted Office 365 Content is a Wake-Up Call for ISVs

Using Document IDs with SharePoint Online


Most Office 365 users might be unaware of SharePoint’s Document ID service, which generates unique document identifiers for documents in a site. That’s OK, because records management is not the kind of subject that turns everyone on. But business situations do occur when document IDs might be useful, which is why I went looking at how this SharePoint feature works.

The post Using Document IDs with SharePoint Online appeared first on Petri.

Continue reading Using Document IDs with SharePoint Online

Exchange 2010 Nears the End


Exchange 2010 will become unsupported on January 14, 2020. It’s time to decide whether to move to Office 365 or Exchange 2016/2019. Exchange 2010 was a really big and important release in the 23-year history of the product, so it’s sad to see it heading to the software scrapyard.

The post Exchange 2010 Nears the End appeared first on Petri.

Continue reading Exchange 2010 Nears the End

Conditional Access Blocks Downloads of Office 365 Attachments and Documents

SPO blocks conditional access
SPO blocks conditional access

Azure Conditional Access policies are pretty powerful, especially when applications accommodate their controls. OWA and SharePoint Online can co-operate with conditional access policies to block the ability of Office 365 users to download email attachments and documents. Although not a perfect solution, it’s a good start.

The post Conditional Access Blocks Downloads of Office 365 Attachments and Documents appeared first on Petri.

Continue reading Conditional Access Blocks Downloads of Office 365 Attachments and Documents

New OWA Makes Categories into Favorites


Microsoft is still building out the new OWA (for Exchange Online) interface. One new feature is the ability to make categories into Outlook favorites. This seems like a small thing, but it’s really quite useful if you make an effort to use categories. Some people will love it. Some will say “blah.”

The post New OWA Makes Categories into Favorites appeared first on Petri.

Continue reading New OWA Makes Categories into Favorites

Microsoft Plans to Launch Automatic Email Encryption for Office 365 Tenants


Microsoft plans to create an automatic policy to encrypt outbound email containing sensitive data for all Office 365 tenants. It sounds like a good idea until you begin looking at the operational consequences of such an action. For instance, how to insert a new transport rule into a complex set of existing rules. All in all, this is not a good plan.

The post Microsoft Plans to Launch Automatic Email Encryption for Office 365 Tenants appeared first on Petri.

Continue reading Microsoft Plans to Launch Automatic Email Encryption for Office 365 Tenants

MyAnalytics – Open to All with Teams and SharePoint Insights Coming


Microsoft announced that the MyAnalytics app is available to any Office 365 user with an Exchange Online license. Also, Teams and SharePoint signals are soon to be included in the MyAnalytics analysis and dashboard. Expanding the user base is a good idea, but the really big news is the expansion of MyAnalytics to cover a much wider breadth of Office 365 activity.

The post MyAnalytics – Open to All with Teams and SharePoint Insights Coming appeared first on Petri.

Continue reading MyAnalytics – Open to All with Teams and SharePoint Insights Coming