Follow me on Twitter @AntonioMaio2

Saturday, March 12, 2016

Vulnerability: SharePoint 2010 and 2013 - Security Bulletin MS16-029 IMPORTANT - Mar 2016 CU

This week Microsoft released an important security bulletin related to vulnerabilities in Microsoft SharePoint 2010 and 2013, as well as Microsoft Office versions 2007, 2010, 2013, 2013RT, 2016 and 2011 & 2016 for Mac.  Full details on the vulnerabilities can be found here: https://technet.microsoft.com/en-us/library/security/ms16-029.

The following services within the listed versions of SharePoint are specifically affected:

1. Microsoft SharePoint 2010
    • Word Automation Services on Microsoft SharePoint Server 2010 Service Pack 2


    2. Microsoft SharePoint 2013
      • Word Automation Services on Microsoft SharePoint Server 2013 Service Pack 1


      3. Microsoft Office Web Apps Server 2010 Service Pack 2
      • Microsoft Office Web Apps 2010 Service Pack 2

        4. Microsoft Office Web Apps Server 2013 Service Pack 1
        • Microsoft Web Apps Server 2013 Service Pack 1

        Background Summary (from Microsoft's Bulletin)

          Full details on the vulnerabilities can be found here: https://technet.microsoft.com/en-us/library/security/ms16-029. According to the official Microsoft Bulletin the following is a summary of the vulnerability:

          The most severe of the vulnerabilities could allow remote code execution if a user opens a specially crafted Microsoft Office file. An attacker who successfully exploited the vulnerabilities could run arbitrary code in the context of the current user. Customers whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

          A security feature bypass vulnerability exists in Microsoft Office software due to an invalidly signed binary. An attacker who successfully exploited the vulnerability could use a similarly configured binary to host malicious code. A defender would then not be able to rely on a valid binary signature to differentiate between a known good and a malicious binary. To successfully exploit this vulnerability, an attacker would have to have write access to the target location that contains the invalidly signed binary. The attacker could then overwrite the original file with their own malicious file and wait for an application, or user, to trigger the malicious binary.

          The security updates provided by Microsoft address the vulnerabilities by:
          • Providing a validly signed binary
          • Correcting how Office handles objects in memory

          Security Resources



          • WORKAROUND: There is a workaround available for the Microsoft Office Memory Corruption Vulnerability.  Details of the workaround involve disabling the OLE Package function in Outlook and available at the Microsoft link provided.  The workaround would likely only assist with protecting Microsoft Office installations on desktops and not SharePoint installations from this vulnerability.

          • REPORTED EXPLOITS: According to Microsoft, at this time there are no reported exploits that have occurred using these vulnerabilities.

          Additional details regarding the SharePoint related vulnerabilities are available at the National Vulnerability Database at the following links:

          Friday, February 12, 2016

          Vulnerability: SharePoint 2007, 2010 and 2013 - Security Bulletin MS16-015 CRITICAL - Feb 2016 CU

          This week Microsoft released a critical security bulletin related to vulnerabilities in several versions of Microsoft Office (2007, 2010, 2013, 2013RT, 2016, 2011 for Mac, 2016 for Mac).  In addition, SharePoint 2007, 2010 and 2013 are also affected.  Full details on the vulnerabilities can be found here: https://technet.microsoft.com/library/security/MS16-015.

          The following services within the listed versions of SharePoint are specifically affected:
          1. Microsoft Office SharePoint Server 2007 (MOSS)
          • Excel Services in SharePoint Server 2007 Service Pack 3 (32 bit edition)
          • Excel Services in SharePoint Server 2007 Service Pack 3 (64 bit edition)

          2. Microsoft SharePoint 2010
          • Excel Services in SharePoint Server 2010 Service Pack 2

          3. Microsoft SharePoint 2013
          • Excel Services in SharePoint Server 2013 Service Pack 1
          • Word Automation Services in SharePoint Server 2013 Service Pack 1

          4. Microsoft Office Web Apps Server 2010 Service Pack 2
          5. Microsoft Office Web Apps Server 2013 Service Pack 1

          Background Summary (from Microsoft's Bulletin)

            Full details on the vulnerabilities can be found here: https://technet.microsoft.com/library/security/MS16-015. According to the official Microsoft Bulletin the following is a summary of the vulnerability:

            The most severe of the vulnerabilities could allow remote code execution if a user opens a specially crafted Microsoft Office file. An attacker who successfully exploited the vulnerabilities could run arbitrary code in the context of the current user. Customers whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

            In addition, a cross-site scripting (XSS) vulnerability exists in SharePoint Foundation 2013 SP1 which could allow remote attackers to inject arbitrary web script or HTML via a specially crafted request.

            The security updates provided by Microsoft address the vulnerabilities by:
            • Correcting how Office handles objects in memory
            • Providing a validly signed binary
            • Helping to ensure that SharePoint Server properly sanitizes web requests

            Security Resources

            • VULNERABILITY DETAILS: All the information you need about this vulnerability and links to the required security patch can be found here:  https://technet.microsoft.com/library/security/MS16-015
            • SECURITY UPDATES: Links to the security updates addressing all of these issues can be found at the link above, however a more direct link to the updates page for these security patches is the following: https://support.microsoft.com/en-us/kb/3134226.
            • REPORTED EXPLOITS: According to Microsoft, at this time there are no reported exploits that have occurred using these vulnerabilities.

            Additional details regarding the SharePoint related vulnerabilities are available at the National Vulnerability Database at the following links:

            Security Strategy for Vulnerabilities

            This bulletin reminds us that a comprehensive security strategy is needed for managing our server applications to ensure that we are alerted to critical security updates and we can make informed decisions about updating our servers to ensure that they are protected.  This is especially true when enterprises rely on SharePoint to store and manage sensitive corporate data. Sometimes these are managed through automatic updates.  In other circumstances, automatic updates are turned off on Production environments so that patches and updates can be tested in Staging environments prior to deployment to Production systems.  In many cases a mix of strategies is used, where critical security updates are automatically installed but other updates are not, so that they can be first tested in staging.  Which ever strategy your organization chooses, its important to identify one, ensure that its comprehensive and documented, and that it includes active periodic review of security updates on all server applications.

            Personally, I'm not a fan of automatic updates.  I like to know what is getting installed on my systems, especially my servers - even when it comes to security updates.  But not having updates applied automatically requires active research or alerts so that we are informed when vulnerabilities are found and security updates are available.  I don't want to criticize automatic security updates - depending on your comfort level they are a viable strategy for managing security and protecting our servers from vulnerabilities.  I am a big fan of Microsoft's technical security notification service, which you can register for here:




            Once again, for the vulnerabilities discussed here, please refer to Microsoft's official bulletin for all details and required security patches which is located here:  https://technet.microsoft.com/library/security/MS16-015

            Wednesday, January 27, 2016

            eBook: Protecting Corporate Information from Insider Threats in Office 365

            Enterprises face ever increasing and evolving threats to their internal corporate information every day.   The “insider threat” is just one of those threats, where risks come from internal employees exposing, stealing, destroying or over-sharing sensitive corporate data.  A threat from an insider presents unique challenges based on the fact that employees require legitimate access to data and systems in order to accomplish day to day work.  Some require privileged administrative access due to the nature of their role.  As well, employees typically have a need to know which information is most sensitive or valuable to the business.  Given that such access and knowledge is required to keep a business and its employees productive, how do we solve this problem in modern businesses today so that sensitive corporate information is protected, even from insiders?

            Microsoft Office 365 provides an exceptional environment for hosting a corporate Enterprise Content Management (ECM) system, allowing all corporate information, both sensitive and non-sensitive, to be stored, managed and accessed in one place.  Microsoft has implemented excellent security measures, practices and assurances to protect organizations from external threats to their data.  It also provides useful tools to help organizations protect against internal threats.  Understanding the real challenges with internal threats will help enterprises make best use of those tools and put the most effective practices in place to protect the business from internal threats.

            Click here to learn more and download the eBook:

            Protecting Corporate Information from Insider Threats in Office 365





            Monday, January 25, 2016

            Webinar: What's New in SharePoint 2016

            Thank you to everyone that attended our webinar on Thursday July 21 on What's New in SharePoint 2016!  We had a great turn out and some good questions.  There are a lot of new features and improvements in SharePoint 2016 and the ones I specifically spoke about in my webinar were:
            1. MinRoles - Improving and simplifying SharePoint server deployments
            2. Zero Downtime Patching - Improving how SharePoint is managed and kept up to date
            3. Hybrid Search - Improving the end user experience when searching content in hybrid Office 365 and SharePoint Server environments
            4. Other Hybrid Scenarios - Hybrid Sites, Hybrid OneDrive for Business, Hybrid Delve
            5. User Experience Enhancements - Adding ease of use features such as the App Launcher, new library toolbar, new sharing capabilities
            6. On Premise Compliance Center - Enforcing DLP policies and improved eDiscovery on SharePoint content
            7. Removing and Improving Limits
              • Improving List View Threshold Limits with Automatic Indexed Columns
              • Improved Maximum File Size
              • Removing File Name Character Limitations
              • Site Collections per Content Database increases to 100,000
              • Search Index Supports up to 500 Million Items

            What Do We Lose with SharePoint 2016

            Finally, we spoke about the features or capabilities which we lose in SharePoint 2016:
            1. No new SharePoint Designer - but SharePoint Designer 2013 will work with SharePoint 2016
            2. New SharePoint Foundation release
            3. No SQL Express installed with single server deployments
            4. No built in Forefront Identity Manager as part of the User Profile Synchronization
            5. STSADM is officially deprecated
            6. Excel Services is no longer part of SharePoint - it is installed with Office Online Server 2016 (the new name for the Office Web Apps product)

            Questions

            A few questions we answered during and after the webinar are:
            • When is SharePoint 2016 expected to release?
            Microsoft just released the RC (Release Candidate) build of SharePoint 2016 on Wednesday Jan 20th which is now available for free download and testing.  The RTM release is expected to release towards the end of the first half of 2016.

            • Do you expect people to use the MinRoles feature when deploying SharePoint?
            I think the MinRoles feature is a very useful feature for new SharePoint deployments which are straightforward.  However, but many complex SharePoint environments have been deployed with a variety of services for various reasons, many of which are specific to the client's specific needs.  I do suspect that many existing and complex deployments will use the Custom role and continue to customize the services deployed to their particular needs.

            • Is InfoPath supported in SharePoint 2016?
            Yes, Microsoft is still supporting InfoPath 2013 with SharePoint 2016.  Microsoft tells us that it will be supported into the early to mid 2020s.

            • Since SharePoint 2016 no longer includes the Forefront Identity Manager as part of its installation to support the user profile synchronization process, what are our options here?
            You essentially have 2 options here: 
            1. You can use AD Import, which will be unidirectional (from AD to SharePoint) and will not right data back to AD
            2. You can install the new Microsoft Identity Manager (MIM) yourself, which replaces Forefront Identity Manager, which will support 2 way synchronization as user profile synchronization currently does.

            You can find the presentation deck from our webinar here: Webinar: What's New in SharePoint 2016.



            Please let me know if there you have any other questions about this topic.

               -Antonio

            Monday, January 11, 2016

            My Reasons For Upgrading to SharePoint 2016

            Excitement is brewing for the upcoming commercial release of Microsoft SharePoint 2016, which is expected to RTM in the first half of 2016. It’s already in its 2nd beta release with many users downloading it, installing it, providing feedback to Microsoft and providing the community with information about what’s new through blogs and articles.  Microsoft has provided some great new features that improve how SharePoint is managed, how we integrate with cloud services in a hybrid model and how we collaborate. 

            It’s important to consider why we should upgrade a perfectly functioning SharePoint environment to this new major release.  Upgrading SharePoint is never just an upgrade.  We’re often looking at a migration, which can be a significant amount of work depending on the state of the current environment. Sometimes upgrades are driven by wanting access to some cool new features, but often the reasons are much more significant.  I'd like to share my favorite reasons for considering such a significant upgrade of SharePoint.

            Hybrid Cloud Search

            Hybrid search was introduced in SharePoint 2013 which would allow you to search across both your SharePoint on premise and your SharePoint Online environments through one interface.  It worked relatively well, but there were some caveats – most notably, search results from on premise sources and online sources appear separate and not integrated.  By default, search results are not merged and this can cause issues with determining which result is more relevant, paging of search results, etc.
            SharePoint 2016 now provides a unified search experience for hybrid cloud search.  Essentially, the way this works is that the office 365 search functionality will consume the on-premise search index so that it can provide integrated results from both sources for the same query.  An Office 365 tenant and Office 365 search are required for this to work.  If users search using the SharePoint 2016 on premise search, only search results from local sources will be presented. There are other improved hybrid scenarios as well with SharePoint 2016, including:

            • Hybrid Sites – Users can follow sites on both SharePoint on premise and in SharePoint Online and have them displayed in one unified list; users can also have a single profile in Office 365 where all their profile information is stored and kept up to date, and use that profile for both SharePoint on premise and SharePoint Online.
            • Hybrid One Drive for Business – Users can sync files with Office 365; users can also access files directly through Office 365 on any device they might have.

            If you are considering a hybrid ECM environment, with portions of SharePoint content stored on premise and portions stored in Office 365, the hybrid search experience available through SharePoint 2016 will certainly provide significant benefit to end users.

            Zero Downtime Patching

            Today, installing patches in a SharePoint environment can be a time consuming and disruptive process.  It requires the deployment of large 2GB+ cumulative updates on a somewhat regular basis.  All patches are currently distributed within 1 large update file which contains all patches up until that point in time including bug fixes, feature modifications and even schema updates.  In this form, all patches are applied at once, and results in some form of downtime to the environment.antonio1.13.162.png

            SharePoint 2016 introduces a new concept for patching called Zero Downtime Patching, where patches are distributed through smaller packages (~100 MB) which may have some dependencies on one another so that certain patches are required before other patches can be installed.  This dependency model in fact already exists with cumulative updates.  The concept here is that patches contain smaller, more targeted changes so that, dependencies aside for a moment, administrators have some choice about which patches are needed and which they can skip, and so that patching with zero downtime is possible.

            Applying patches on a regular basis is an important part of maintaining a healthy functioning SharePoint environment.  Doing so with more choice about which patches get applied and without downtime to the environment and its end users is an enormous improvement in the manageability of the overall SharePoint environment.


            DLP Capabilities through the On Premise Compliance Center

            SharePoint 2016 has directly integrated the fantastic DLP capabilities from Office 365 into its on premise version.  Traditionally we’ve had to look to third party tools to enforce DLP policies on SharePoint content, but with SharePoint 2016 this is now available through it’s out of box capabilities.  As well, SharePoint 2016 includes an improved eDiscovery Center which also allows you to query for content which do not conform to an organizations DLP policies.

            SharePoint 2016 now allows administrators to create both a Compliance Center site collection and an eDiscovery Center site collection.  The Compliance Center site collection, much like the Office 365 Compliance Center, allows administrators to configure DLP policies which are automatically enforced on content within SharePoint.  Using the search service application, DLP policies will automatically identify content that is sensitive or confidential and flag that content so that it is not accessible by unauthorized users. These policies then provide some notification and remediation capabilities, like automatically notifying administrators and/or content authors by email of policy violations, and allowing overrides to policy warnings with documented justifications when needed.  In addition, like Office 365 the DLP capabilities come with 51 built in policy templates for identifying sensitive information.  These templates include a large number of regular expressions like credit card numbers and social security numbers, as well as regulatory compliance standards such as the PCI Data Security Standard and HIPAA related data.  The eDiscovery Center can now be used to run DLP queries to discover content which is sensitive or relates to industry regulations and export a report of the identified documents.

            Most organizations use SharePoint to store and manage sensitive information in one form or another.  SharePoint 2016 now allows you to do so in a much more secure manager, and use the out of box capabilities to ensure that end users conform to corporate and industry regulations.

            5000 List View Threshold Improvements

            A common limitation we’ve had in SharePoint for some time is the 5000 threshold for the “List View Threshold” setting.  This is a limit (which can be configured, so it’s really a threshold) which determines how many items can be displayed in a single view.  This helps to ensure that performance of SharePoint overall is not adversely affected by users storing and displaying more that this number of items in a single view.  It ensures that queries to the SharePoint database for items in a list or library do not result in SQL database locks which will affect performance of the entire SharePoint farm.  Although this setting is configurable, we’ve always been recommended to stay away from increasing this past 5000 items.  One method of supporting large lists and libraries is to configure indexed columns on such lists.

            Storing 5000 items in a list or libraries may sound large, but more and more organizations store a lot more content than this across many lists and libraries throughout their SharePoint portal.  Over time, it’s extremely easy to accumulate large numbers of lists which contain large numbers of items far beyond this 5000 limit.

            SharePoint 2016 provides greater ability to manage large lists and libraries by now automatically creating indexed columns on these lists.  As content grows in our lists and libraries, which it inevitability will do, it’s important to ensure that the proper mechanisms are in place to efficiently manage that content, and SharePoint 2016 now automates more of that for us.

            Large File Support

            SharePoint 2016 now increases the recommended limit for storing single files from 2 GB to 10 GB.  This is a welcome change, as more and more businesses look to work with large files and large videos, for example presentations with large videos embedded within them, it’s important that the collaboration portal where such files are stored evolve with this changing need.

            Microsoft Product Support

            If you are currently running Microsoft Office SharePoint Server 2007 (MOSS) or Microsoft SharePoint 2010, Microsoft is no longer providing product support for either product. More specifically, Microsoft ended regular product support for SharePoint 2010 in October 2015. 

            If you are in the situation where you are running either of these SharePoint versions, I would strongly recommend you consider planning your upgrade to SharePoint 2016.


            In closing, there are many welcome additions and capabilities in Microsoft SharePoint 2016.  For me, the most compelling changes which will make me want to upgrade to SharePoint 2016 are those which improve SharePoint in broad ways from a management perspective, from an end user perspective and from a security perspective, which are those which we’ve outlined here:

            1. Hybrid Cloud Search, allowing us to better support hybrid scenarios by providing better search results and ultimately a better user experience,
            2. Zero Downtime Patching, enabling simpler management of the overall infrastructure and reducing downtime for users,
            3. DLP Capabilities, allowing us to better secure the SharePoint environment and protect information containing sensitive information,
            4. List View Threshold Improvements, allowing us to better support large lists and libraries through automatic indexed columns,
            5. Large File Support, allowing us to better serve the needs of our end users as the files they work with get larger.

            Tuesday, December 29, 2015

            SharePoint Basics: MailTo Link with New Lines in the Email Body

            I was recently asked about how to implement a MailTo link on a SharePoint site page, which is pretty straight forward.  The challenge for the person asking was about how to pre-populate the email body, so that it provided a template for users to fill out when sending that email, and how to have that email body contain multiple lines of text, with carriage returns and new lines between the lines.

            There are several methods of doing this which do not work because SharePoint will actually remove the carriage returns and new lines.  There are other methods which do work. 

            So, here is a quick post describing one method for accomplishing this.  I'm going to use JavaScript to setup the link so that the script is centralized in one place.

            When including carriage returns and new lines in a link, we need to escape those characters so that web browsers can interpret them correctly. 
            • The carriage return is escaped with %0D
            • The new line is escaped with %0A
            • If you want to have text start on one line, then move to the next line, you need to include: %0D%0A
            • If you want to have an empty line between two lines of text, you would simply double the pattern: %0D%0A%0D%0A

            In order to create a MailTo link which includes a pre-populated email subject, email addresses and body pre-populated with multiple lines, you can do the following:
            • Create a JavaScript file which contains the following:
            Click <a class="email" title="My Link Title" href="#" onclick="javascript:window.location='mailto:emailaddress@company.com?subject=Here Is My Subject Line&body=Here is the start of the email body %0D%0A%0D%0A email body continuing after a new line %0D%0A%0D%0A email body continuing after a second new line %0D%0A%0D%0A email body continuing after a third new line %0D%0A%0D%0A email body continuing after a forth new line %0D%0A%0D%0A email body continuing after a fifth new line.' + window.location;">here</a> to send an email template using a predefined template.

            Notice how the link title field, email subject, email addresses and email body are populated.  Notice also how the carriage return and line feed characters are included in the email body.
            • Upload the JavaScript file to the Site Assets SharePoint library
            • On the site page add a Content Editor web part
            • Edit the web part you just added
            • In the Content Link property in the web part editor, add the path to the JavaScript file that you just uploaded to your Site Assets library.
            Refresh your page and test your link.

               -Enjoy.

            Monday, October 12, 2015

            Securing Office 365 with Activity Monitoring

            Thanks to everyone that attended my webinar last week on Securing Office 365 with Activity Monitoring.  We had a great turn out and the slides presented can be found here:

            Securing information systems is a very broad topic.  Monitoring and auditing these systems, and in particular the activities of users, is just one important aspect of securing our corporate IT environments. 

            In July of this year, Microsoft announced some new capabilities around this within Office 365 – these are new Activity Monitoring and Reporting features.  These capabilities are designed to help organizations that are continually facing challenges with security, privacy and compliance.  In running and supporting the Office 365 service themselves, Microsoft has found that that they're capturing large amounts of data on which activities end users and administrators are performing.  They typically refer to this data as telemetry, and they've built great mechanisms into Office 365 to allow them to efficiently capture (and now share) this telemetry data.

            These new capabilities provide greater visibility for administrators, and ultimately compliance and risk officers, into the actions taken by users on corporate content. They also allow us to apply greater access control over data, and if needed, they give us the capability to now investigate (at a very detailed level) user actions that might be against corporate or regulatory policies.

            Why is Monitoring Activity and Auditing our Systems Important?

            Monitoring user activity and auditing our information systems is important for many reasons.  

            Regulatory Compliance

            Regulatory compliance requirements are one key driver.  For example, many financial institutions often deal with MNPI, or Material Non-Public Information. Generally, this is information that’s not distributed to the public that an investor would likely consider important in making an investment decision.  Many institutions must put up Compliance walls to ensure that specific aspects of the business don’t communicate with each - this helps to avoid conflicts of interest and helps to ensure that they don’t inappropriately exchange MNPI.  

            In particular, this is required in institutions which have both a corporate-advisory unit and a brokering unit, in order to separate those people giving corporate advice on takeovers from those advising clients about buying shares.  The wall is thrown up to prevent leaks of internal corporate information, which could influence the advice given to clients making investments

            Detailed monitoring and auditing of user activity allows us to have a detailed view into which users are accessing sensitive content along who they’re sharing it with, and it provide assurances that our regulatory compliance obligations around in these business scenarios are being met.

            Investigating Data Breaches
            We've heard a lot about data breaches in recent years.  Data breaches can be small or they can be very large. They can be malicious or they can be accidental.   As well, data breaches can be caused by external actors like cyber criminals, or by insiders like system administrators or employees with broad levels of access.  Generally, we tend to see data breaches caused more often by external actors, but we see data breaches by insiders to involve larger quantities of data or more significant data. When data breaches do occur, it’s important for organizations to investigate and find the root cause so that they can both measure the scale of a breach (ie. how much data was leaked) but also to put in place measures to prevent these breaches in the future.  

            When data breaches occur as a result of an insider threat, monitoring user activity at a detailed level allows us to perform investigations and root cause analysis to determine exactly who accessed data, when was it accessed and which actions were taken on that data - like who it was shared with.

            Audit Access to Sensitive Information
            In many organizations it’s important to audit the current access controls in place for sensitive content. This is sometimes referred to re-certifying permissions, or getting data owners to review and sign off that permissions are accurately set for data that they are responsible for.  In large organizations with large diverse information systems it can be really difficult to identify who is responsible for different data repositories.  

            Monitoring user activity at a detailed level allows us to gain insight into who is accessing data on a regular basis, along with the level of access that they have.  This can greatly help us in identifying data owners to ultimately review and re-certify permissions.


            Office 365 Activity Monitoring and Reporting

            The new activity monitoring and reporting capabilities include:
            • Office 365 Activity Report (built into the Office 365 experience)
            • Comprehensive Event Logging
            • Search PowerShell Cmdlet
            • Management Activity API (in preview)

            1. Office 365 Activity Report

            You can access and run the Activity Report by:

            • Logging into your Office 365 tenant
            • Navigating to Admin in the App Launcher > Compliance Center > Reports > Office 365


            [Activity Report Screen Shot]

            You can use the Office 365 activity report to view detailed user and administrator activity in your tenant.  It contains data across SharePoint Online, One Drive for Business, Exchange Online and Azure Active Directory.  You can use this report to search and investigate user activities by searching for a user, a file or folder or even a site.  You can filter based on a date range or type of activity.  And within the report window you can view details of each activity in the Details Pane. The report is available to run on demand as needed.

            When you find what you're looking for, you can either review activities and details right within this window or you can download the list of activities to a CSV file.

            With each event captured there are up to 37 different properties logged.  Not all properties apply to all Office 365 services.  Some only apply to SharePoint Online and OneDrive for Business, whereas others only apply to Exchange.  The list of properties captured is shown here, with my favorites highlighted in red – my favorites are data like:

            • Actor - The user that performed the action; can be a service principle
            • ClientIP - The IP address of the device that was used when the activity was logged. The IP address can be either IPv4 or IPv6.
            • EventSource – Identifies that an event occurred in SharePoint, OneDrive for Business or the ObjectModel.
            • LogonType – Applies to Exchange only; this is the type of user who accessed an Exchange mailbox: mailbox owner, administrator, delegate, the Exchange Transport Service, a service account or a delegated administrator.
            • Subject – Applies to Exchange only; this is the subject line of the message that was accessed.
            • UserSharedWith – The user that a resource was shared with.
            • UserType - The type of user that performed the operation: a regular user, an administrator in your Office 365 tenant or a Microsoft data center administrator.

            You can see documentation on the full list of properties here:
            2. Comprehensive Event Logging
            In order to enable the Activity Report and make it really useful, events related to user and administrator activities are logged as users work across SharePoint Online, One Drive for Business, Exchange Online and Azure Active Directory.  

            Currently there are over 150 events that are logged, and these are divided into 9 categories:

            • Exchange admin events
            • Exchange mailbox events
            • File and folder events (SharePoint and OneDrive for Business)
            • Invitation and access request events (SharePoint and OneDrive for Business)
            • Sharing events (SharePoint and OneDrive for Business)
            • Site administration events (SharePoint and OneDrive for Business)
            • Synchronization events (SharePoint and OneDrive for Business)
            • Azure Active Directory events (Admin Activity and User Login)


            You can view documentation on the full list of events here:

            The events logged are diverse and very comprehensive, with Microsoft continually working to log more events.  When it comes to investigating data leaks, this gives administrators very detailed investigation capabilities to determine how leaks occur and how to prevent them.

            3. Search Powershell Cmdlet

            You can also search for events in the activity logs that we’ve been looking at using Powershell.  This is a new Powershell cmdlet to search all the event logs based on date range, the user who performed an action, the type of action, or the target object.

            Examples of using this cmdlet are:

            Search-UnifiedAuditLog -StartDate September 1, 2015 -EndDate September 30, 2015

            Search-UnifiedAuditLog -StartDate 9/1/2015 -EndDate 9/30/2015 -RecordType SharePointFileOperation -Operations FileViewed -ObjectIds docx

            With this capability we can script our searches of the event logs.  We can also have these searches output the results to a file.  And ultimately, this can allow us to schedule our reports to occur automatically on a regular basis so that administrators or infosec people can get insight into specific activities either every morning, every week or whenever the business schedule demands.


            4. Management Activity API (in limited preview)
            The final capability provided with this release is a new Management Activity API, which allows developers to integrate Office 365 activity and event data with either internal tools or with 3rd party monitoring and reporting solutions.

            Full documentation on the Management Activity API can be found here:

            There are a couple of important points about the API:

            • This API is in limited preview now, and during the preview anyone can use the API, but only those registered with Microsoft will be able to actually retrieve data from Office 365.
            • Actions and events are stored in content blobs in a database, and they are gathered across multiple servers and datacenters. As a result of this distributed collection process, the actions and events contained in the content blobs will not necessarily appear in the order in which they occurred. One content blob could contain actions and events that occurred prior to the actions and events contained in an earlier content blob.


            Enjoy.
               -Antonio

            Friday, October 9, 2015

            Data Visualization Options in SharePoint and Office 365

            A big thank you to everyone that attended my recent presentation last week in Houston on Data Visualization Options in SharePoint 2013 and Office 365.  We had a great turn out for our round table presentation with a lot of great dialog and questions.

            You can view the presentation deck from our session here:


            To summarize a few points from the session, Microsoft has several great data visualization tools available for SharePoint, including:

            • Excel Services
            • PowerPivot
            • SSRS
            • PowerView
            • PowerBI
            • Custom code with JavaScript
            • PowerBI
            • Datazen
            • Performance Point
            • Visio Services

            Our presentation did not cover Performance Point or Visio Services due to the relatively low usage we see of those components.

            Knowing which tool to use in which scenario can be really challenging.  So as part of the presentation we talked about the 3 questions you need to ask your self when choosing a tool, and we went through following use cases to help you decide the best tool for the job.  To recap that information...

            The 3 questions to ask yourself when selecting a SharePoint data visualization tool:

            • What do you want to do with your data? Do you want to create reports, create dashboards, data analysis, data discovery?
            • Which devices are users consuming data on?  Are they using desktops, tablets, smart phones?
            • Where is your data located?  Is your data on premise or in the cloud?


            The various use cases we went through were the following, with our recommended data visualization tool.


            Use Case 1

            I am an Excel pro.  I have a lot of data. I have SharePoint on-prem… and I need to provide and share info to many users on Intranet

            Recommended tool: Power Pivot


            Use Case 2

            I have SharePoint on-prem.  I want users to do data analysis and discovery on the intranet (SharePoint 2010/2013) on their own.

            Recommended tool: PowerView


            Use Case 3

            I have SharePoint on-prem, and need to provide reports to business users on my intranet  which they will print.  I would like power users to be able to create reports.

            Recommended tool: SQL Server Reporting Services (SSRS)


            Use Case 4

            I have both Office 365 and SharePoint on-prem, do not have Power View, cannot use my on-prem data in the cloud, but still need to do some kind of Visualization.

            Recommended tool: Javascript code using standard Javascript libraries (D3.js, chart.js)


            Use Case 5

            I am using Office 365, have my data on-prem and want users to be able to use different devices to do data discovery on the data.  I want the users to do create these “reports”.

            Recommended tool: Power BI


            Use Case 6

            I have on-prem SharePoint, the data is in lists and need to create responsive dashboards that work on many different devices.  I want my users to create and consume these.

            Recommended tool: Datazen


            Please let me know if you have any questions.
               -Antonio

            Wednesday, October 7, 2015

            How does Microsoft Protect Our Data in Office365?

            I’ve received this question many times over the last year – clients who are considering Office 365 to store their corporate data asking:

            How does Microsoft really protect our data as it sits within their data center?

            Given the nature of my past security work, this is always a question that I’m happy to share the details about.  I often start by telling people that Microsoft has implemented an extremely robust, multi-layered security strategy for protecting data at rest in Office 365.  That sounds great, but what does that really mean?

            Well, specific to SharePoint, OneDrive for Business and other solutions, Microsoft uses a multi-leveled encryption strategy with keys that are rotated (ie. regenerated) on a regular basis.  Actually the strategy is broader than that – it uses a combination of multiple levels of encryption, automatic key rotation, random distribution of data, drive level encryption and data spread across multiple systems each with their own network, OS, malware and physical protection.

            In the on premise world, SharePoint data sits within content databases inside SQL Server.  You can certainly configure SSL communication between clients and SharePoint and between SharePoint and SQL to secure data in motion.  You can even enable Transparent Data Encryption (TDE) within SQL to secure your SharePoint data while at rest within the SQL Server database.  However, in the online world how exactly does Microsoft use encryption and other techniques to protect our corporate information?

            Let’s look at how the strategy is applied in detail to your content within SharePoint and OneDrive for Business:

            • Files within SharePoint Online and OneDrive for Business are shredded into fragments and each fragment is encrypted with a different key, using AES 256 bit crypto.  When files are modified, each delta is encrypted with a different key.
            • Encrypted fragments are randomly distributed and stored across multiple Azure storage accounts.  These storage accounts are generated on demand and stored in separate systems.
            • The keys used to encrypt fragments are regenerated once per day (key rotation).
            • These keys are themselves encrypted using a master key that is specific to the customer.
            • The master key is stored in a highly secured and monitored “key store” which is completely separate from SharePoint content databases.  The key store is the most secured asset in the Microsoft data center.
            • The keys used to encrypt fragments, which are themselves encrypted with the master key, are stored in the SharePoint & OneDrive content databases along with a map to the fragments.
            • Microsoft also uses BitLocker to encrypt all of the disks on all systems.

            So let’s consider scenarios where the data center is attacked:

            • If a content database is attacked, the attacker only gets access to a bunch of keys, which are encrypted and therefore unusable, and a map to the encrypted chunks that are stored in a different system with its own protections (the Azure storage accounts).  
            • If the Azure Storage Accounts are attacked, the attacker only gets access to a bunch of random fragments, which are encrypted… and did I mention that the distribution of those fragments is random.  Even if they could decrypt the fragments, they will not be able to put a file back together due to the random distribution.
            • Again, the key store is the most secure asset in the Microsoft data center.  Even if an attacker could get to the key store and attack it, at most they can get a key.  
            • If the physical environment is attacked, and drives are physically removed and stolen, none of the data on the disk will be accessible due to BitLocker drive encryption.

            Keep in mind all of the physical, network level, malware protections and internal procedures which strictly limit access to internal employees in the data center which are also in place.  In addition, Microsoft works every day to improve the security of their Office 365 offering by attacking and defending their own environments:

            • They have a dedicated RED team, which sits outside of the Office 365 environment whose job it is to constantly attack the Office 365 environment looking for vulnerabilities and holes.
            • They have a dedicated BLUE team which sites within the Office 365 environment whose job it is to constantly defend the Office 365 environment looking for ways to better protect our data from would be attackers.


            Don’t those sound like the coolest jobs in the world?!

            In The Future…

            The next thing that Microsoft is working on to further enhance this strategy is to allow customers to bring their own master key, so that even if an insider wanted to access your data or a government request is made to Microsoft to access your data, Microsoft will not be able to retrieve it themselves.

            You can find a great video on this topic here:  http://www.microsofttrends.com/2014/05/26/technical-details-on-office-365-fort-knox-encrypted-storage/.

            As well, there was a great session at the Microsoft Ignite conference on this topic here:  https://channel9.msdn.com/Events/Ignite/2015/BRK3182.

            Enjoy.
               -Antonio

            Friday, October 2, 2015

            UPDATED: Changing the SharePoint 2013 Farm Administrator Password

            I wrote this post earlier this year regarding how to change the SharePoint 2013 farm admin password, and today I found an interesting situation that required a couple of extra steps.  You can find these extra steps below in red.  Big thanks to Doug Hemminger (@DougHemminger) for his assistance in finding a solution.

            When setting up a new SharePoint 2013 farm, as a best practice we typically create service accounts for very specific purposes. The idea here is that we deploy SharePoint 2013 using a least privileged model, where very specific service accounts are created for very specific purposes and those accounts are only granted the permissions required to fulfill that purpose. That way, if such a service account is compromised by a malicious user, that user does not gain access to the entire farm. One such account is the SharePoint 2013 farm account.

            When creating these service accounts, for various reasons, we typically create a domain account in Active Directory and configure it such that the passwords do not expire. As well, we find that the passwords for these service accounts typically are not changed often. However, there are circumstances in which the password for the SharePoint 2013 farm account must be changed.
            • One example of such a circumstance is if we suspect that the farm account has been compromised by a malicious user.
            • Another example is when consultants, such as myself, are brought in to deploy new SharePoint 2013 environments. Once that deployment process is complete and the client is happy with the environment, rightfully so, the client typically wants to take complete control of the environment and restrict farm admin level access to only a small set of internal employees - essentially they want to prevent the consultants that deployed the environment from continuing to have farm administrative level access.

            Changing the SharePoint 2013 farm account is a manual process.  Its not something that is done often, so people often aren't sure which steps are required to ensure that it has been changed in all required locations.  Always be sure to test this process in a TEST SharePoint 2013 environment and monitor that environment for a period of time before performing this process in a PRODUCTION environment.  Your SharePoint 2013 farm may be configured differently that other standard configurations and your process may require extra steps.


            For a standard SharePoint 2013 farm, the following are the steps required for modifying the SharePoint 2013 farm account:


            1. Navigate to SharePoint 2013 Central Administration interface, click Security in the left hand menu, and click ‘Configure Managed Accounts’.  Select the farm administrators account in the account list shown, click the Edit icon and change the password.

            I recently found that if the Central Administration application is running on a server in your farm which is not hosting the distributed cache service, this step will fail.  Luckily it fails early in the process and you get a "Sorry Something Went Wrong" message with a correlation ID.  If you look into the ULS logs you'll find that there is an Unexpected Error with the Distributed cache saying the SPDistributedCacheServiceInstance is not valid.  To resolve this, you can do the following:

            • Launch a SharePoint Command Shell window as an administrator
            • Run the following PowerShell command to temporarily enable the Distributed Cache service on this server:  Add-SPDistributedCacheServiceInstance.  The command should take a few seconds to run and completely successfully without any feedback on the command prompt.  Once the process is complete below, you'll remove the Distributed Cache service from this server.
            • Repeat step 1.  This step should now complete successfully.  Leave the SharePoint management console running.
            • You may find that this step stops the User Profile Synchronization Service on the server on which it is running.  At this point, check whether this service is still running in the 'Manage Services on Server' page and if not, start it now on the same server on which it was previously running.


            2. Manually change the User Profile Synchronization Service password.  As required by SharePoint, this service uses the farm administrator account, however SharePoint 2013 does not treat this account as a managed account so it must be changed manually.
            • The farm administrator account must be made a local administrator on the server hosting the user profile service during the password change. 
            • Once that step is complete, launch SharePoint Central Admin, navigate to System Settings and click ‘Manage Services on Server’.  This page is used to start and stop services on each machine in the farm.  Select the machine hosting the user profile service and find that service.  It should say started. 
            • Stop the service.
            • Start the service again – when starting the script you’ll be asked for the new password
            • Ensure that you monitor the user profile service and ensure that the service starts correctly.
            • Once started, you may remove the farm administrator account as a local administrator.  However, we often recommend leaving it as a local admin on the server for simplicity of making such changes in the future.


            3. Check if any applications in the Secure Store service use the farm administrator account, and if they do change the password there.
            • Launch SharePoint Central Admin, click Application Management in the left hand menu, click Manage Service Applications, click the Secure Store Application and click Manage Target Applications.
            • Select a single Target Application from the list.
            • In the Credentials group on the ribbon, click Set. This opens the Set Credentials for Secure Store Target Application dialog box.  If any target application uses the farm administrators account, change the password here. 
            • Repeat this process for all secure store applications.
            • Note: Be cautious when entering the password. If a password is entered incorrectly, no message will be displayed about the error. Instead, you'll be able to continue with configuration. However, errors can occur later, when you attempt to access data through the BCS.  If the password for the external data source is updated, you have to return to this page to manually update the password credentials.

            At this point, if you added the Distributed Cache service as part of step 1, now we should remove this service.  In the SharePoint management console we previously opened running the following command:  Remove-SPDistributedCacheServiceInstance.

            4. Reboot all the servers in the SharePoint farm, except for SQL server.  SQL Server does not need to be restarted.


            Please let me know if you have any questions or comments about this process.  There may be other services that have been configured with the farm administration account, so your process may vary somewhat, but typically the farm administrator account is reserved for specific purposes.  As a best practice, due to its high level of access, the farm administrator account should not be used widely other than for the purposes in which it was designed.

               -Antonio


            Thursday, September 17, 2015

            Security Controls - External Sharing of Sites in Office 365

            In our SharePoint deployments in the past, we've often had the need to share content with external users, which are people that are not part of our company or organization.  Setting this up in an on premise environment often required a significant deployment of a SharePoint extranet, with some complex network configuration.

            Office 365 makes sharing with external users very easy and gives administrators some great controls over it to ensure that its both secure and enables collaboration between internal and external users.

            External Users
            External users might be partners, customers, auditors, or generally those that cannot login to our corporate network.  From a technical standpoint we often think of them as people that do NOT have an account in our corporate Active Directory.  In Office 365, you can also think of an external user as one which does not have a license to your SharePoint Online sites or Office 365 subscription.

            • From a governance and security standpoint, we typically do not want to give external users an AD account or Office 365 license, so this makes sense.

            If a SharePoint Online site is shared with an external user, that user inherits the rights of the SharePoint Online customer that's inviting them to access the site.  So, if you have an E3 Enterprise Plan with Office 365, any external users that you share a site with will also have the rights that are granted with an E3 Enterprise license.  That said, there are some capabilities that are NOT available to external users, which are:
            • Cannot be a site collection administrator or access any of the site collection administrator capabilities.
            • Cannot create their own personal One Drive for Business library.
            • Cannot search against everything, cannot search across site collections and cannot access the Search Center.
            • Cannot create their own personal sites, or a My Sites site.
            • Cannot access or view the company newsfeed.
            • Cannot change their user profile (things like their picture or contact information).
            • Cannot access site mailboxes
            • Cannot access PowerBI capabilities: PowerView, PowerPivot
            • Cannot use eDiscovery
            • Cannot open downloaded documents which are IRM protected (Information Rights Management).
            • Cannot use Excel Services features
            • Cannot access SharePoint Online data connection libraries
            • Cannot use Visio Services features
            There are of course many other capabilities that external users can access, including viewing, editing and collaborating on content.  As described below, you can control the permission levels assigned to external users so that they can only view content, or so they can view and edit content.

            We typically talk about 2 types of external users:
            • Authenticated User - this user is required to login with a user name and password
            • Anonymous User - this user is NOT required to login

            Administering and Controlling External Sharing

            Global Admin Controls
            External sharing can be turned on and off globally, and individually for each site collection.  You turn it on or off globally by logging into your Office 365 tenant as a tenant administrator and doing the following:

            • Click the App Launcher and select Admin
            • In the menu at the left click the External Sharing option
            • Within External Sharing menu, click the Sharing Overview option
            • There are several options available on this page, including options for Sites, Calendars, Skype for Business and Integrated Apps.  We're focus on Sites for this article.

            • Under sites, you'll see a global ON and OFF switch for External Sharing - ensure that it is ON.
            • Click on the Go to detailed settings for sites link or in the left menu click on Sites

            • From this page, through the controls at the top, you can control the External Sharing settings for all site collections in the tenant.  The Let external people access your sites check box reflects the same state as the global ON and OFF switch mentioned above.
            • Selecting either the No anonymous guest links. Only allow sharing with authenticated users or Allow sharing with anonymous guest links for your sites and documents radio button will select whether only authenticated user access is permitted for external users, or if both authenticated users and anonymous users are permitted.
            Security Note: This control allows me to turn ON and OFF anonymous access to all site collections (and leave authenticated access ON) all at once if needed.  In a situation where you detect that sensitive content may have been shared in appropriately through an anonymous link, this control can be extremely useful as it disables all previously shared anonymous access.  If I turn this off in the global Admin Center then it will be disabled (and I cannot turn it back on) in the SharePoint Admin Center:


            Note: Each site collection remembers its previous setting, so if you have some site collections with only authenticated access and others with both authenticated and anonymous access, changing this radio button will change all site collections back and forth between their current settings or only allowing authenticated access.  

            • From this page you can select individual site collections, click the pencil icon to edit their settings and determine if external user access is permitted and if only authenticated users or if both authenticated and anonymous users are permitted.  Again, this can be done individually for each site collection here.

            • In the global Administration Center, you may also control the external users which have access to each site collection by selecting the site collection and clicking the Manage external users for this site link on the right, which will allow you to simply select and delete users:



            SharePoint Admin Controls
            From within the SharePoint Admin Center you may also manage sharing by selecting a site collection from your list::


            ...and then clicking the Sharing button in the ribbon:


            However, these controls provide the same capabilities as those listed above at the global administration level.  If I modify the settings here in the SharePoint Admin Center for a site collection, the same change is reflected in the global Admin Center.

            One advantage of the SharePoint Admin Center's sharing controls is that it allows me to edit the settings for more than 1 site collection at a time - I can select more than one, click the Sharing button in the ribbon and modify the sharing settings for all the selected site collections at one time:


            Other than this, I can control external sharing settings for each site collection either at the global level or at the site collection admin level.  There are 2 advantages to controlling these settings at the global level:

            • View and delete the external users that sites are currently shared with
            • Turn sharing ON and OFF, or anonymous access ON and OFF for all site collections at once

            See below for the administrative role needed to control external sharing.


            Defaults for New Site Collections and Administrative Roles
            The default External User settings for SharePoint Online is to have External Sharing turned ON at the global level.

            However, external user sharing is turned OFF for new site collections - it must be explicitly turned ON for each site collection.  This is a good security feature, helping to ensure that you do NOT accidentally share sites externally.

            In order to control External Sharing options, you must have either the Office 365 global administrator role or a SharePoint Administrator role.

            • You cannot control whether a site is share-able externally simply as the site collection administrator or from within the site settings.  Once you configure a site collection to be share-able in the global Admin Center and/or SharePoint Admin Center, then you select which external users a site is shared with from within the site collection, as discussed below.
            Security Note: From the Office 365 Administrative interface it appears that a global administrator role would have the ability to control the global and SharePoint administrative settings for external sharing, whereas the SharePoint administrator role would only be able to control the SharePoint Admin Center settings for external sharing.  However, in testing I have found that this is NOT the case.  It appears that even if a user that has ONLY the SharePoint Administrator role they can control these particular settings in both the global Admin Center and the SharePoint Admin Center.  So, although some settings can be disabled at the global admin level and enforced automatically on all site collections, like turning anonymous access OFF on all site collections at once, a SharePoint administrative role can simply navigate to the global Admin Center and turn them back ON (even though they are not a global administrator).

            Even if my user account is the site collection administrator on only 1 site collection, if I have the SharePoint administrator role in the Office 365 tenant settings, I can change external sharing settings for all site collections, both in the global Admin Center and the SharePoint Admin Center.


            Sharing a Site with Authenticated Users
            If you require that external users login with a username and password when accessing an Office 365 site that's been shared with them, then you must share with an authenticated user.

            An authenticated user in this case must be a user with either a Microsoft account or an account assigned to them from Office 365, or what is sometimes referred to in Microsoft articles as a school or work account.

            • A Microsoft account is what used to be called a Windows Live ID, and can actually be any account used to access Outlook.com, OneDrive, Windows Phone, or Xbox LIVE.  If you have an account to access any of these services, then you already have a Microsoft account.  For example, my Microsoft account is still my @hotmail.com account.  So, if I want to share a site with an external user that has a Microsoft account named bob@outlook.com then I can simply share the site with that email address.  The user will receive an email invitation and when they click the link within, they'll need to login using their existing bob@outlook.com username and password.  Office 365 will authenticate them against their Microsoft account.
            • A school or work account in this context is a user account that has been created for users within the Office 365 tenant.  For example, when creating my Office 365 tenant I can optionally register and verify other domain names that I own.  Once that step is complete, I can create accounts within Office 365 which use that domain name.  So, if I register and validate the domain CONTOSO.COM in my Office 365 tenant, I can then create an account called bob@contoso.com.  In this case, if I need to share a site with an external user that does not already have a Microsoft account (and is not interested in getting one, even though they're free and really easy to register) I can simply create an account for them in my tenant.  I can then send that user an email invitation to access their new account with the username and password that I choose for them.  Finally, I can share a site with that user account and they'll be able to access the site even though they do not have an Office 365 license.  Please see below for some interesting controls (or lack of) about this scenario.

            Sharing a Site
            You may share a site with external users at the site collection level only.  So, if you share a top level site collection external users will gain access to all subsites, lists and libraries below that as well.  this is accomplished by clicking the Share button in the top right corner of the Office 365 page.


            The following window will then appear where you can enter either the email address to their Microsoft account or the user name from the Office 365 tenant which represents the user's account.


            Notice on the left side of the window you can also see who the site is currently shared with by clicking none other than Shared with.

            If I access this same Share button from a subsite, I can share the site collection with an external user from there as well, but notice the message which appears at the top of the new window letting us know that sharing the subsite will also give the external user access to the site collection.


            Once I enter the user name or email address and an email invitation message for the external user, they will receive an email with a link to the site. When they click that link, they will be taken to a page that allows them to choose how they wish to login, where they can choose either an organizational account or their Microsoft account:


            Security Note: When you share a site collection with an external authenticated user and you select to give them the ability to view and edit content, that user is made a member the Members group within the site collection.  This means they have Contribute rights on the entire site collection.  It also means that they are now able to share the site collection with other authenticated users.  That can be a useful feature for them, and it can pose security risks.  

            • Fortunately, if they try to share a site with another external user, they will be prevented from doing so and the following error will appear:

            • If they try to share with other internal authenticated users, they are permitted to do this, but a request is first sent to the site owners group for approval, before those internal users are actually given access.

            Its typically recommended that if you're going to share sites in this way that you create a separate site collection within your Office 365 tenant specifically for sharing with external users and you ensure that no sensitive content is placed within that site collection.

            Sharing a Document
            You may also share individual documents with external users, however I do find the experience for the user is not ideal.  When a user receives a sharing invitation to a document, clicking the link in the sharing email invitation received simply opens the document in the web browser.  The user does not get to navigate through SharePoint site to access the document.  Once again, to do this you must select the document and then click Share as shown in the following;


            You can also share a document by clicking the ... on a document and selecting Share from the window that appears.  Once Share in either location is clicked, the following window will then appear:


            Notice the extra options available in the dialog: 
            • Require sign-in option
            • Get a Link option
            The Require sign in option does just that, requires a user to sign in when they access a document through a shared link.

            See below for more information on the Get a link option.


            Sharing a Site with Anonymous Users
            Sites can only be shared with authenticated users.  They cannot be shared anonymously with external users.

            Only documents can be shared anonymously with external users.  Once anonymous access is enabled for a site collection, as shown above, sharing a document anonymously is accomplished through the process shown above to share a document.

            Once in the Share window, click the Get a link option and the following dialog will appear:


            Clicking CREATE LINK either within the View Only section or the Edit section will then display links that you can email to users in order to enable them to access this document without having to login:


            If you wish to only enable external users to view a document without logging in, then you may only email them the link under View Only.  If you wish to enable external users to view and edit a document without logging in, then email them the link under Edit.  A few other capabilities within this window are:

            • In this window, you can also click the Mobile phone icon beside each link, which will give you a QR code that you can send to users enabling them to easily open this document on the mobile phone.
            • Finally, you can also disable links to specific documents within this window through the disable link.


            Security Note:  Its important to understand that by sharing documents anonymously through links like this, any external user that has the link can access the document.  So, if an external user inadvertently or maliciously forwards an email with such a link to another external user, that user will also be able to view or edit the document without having to login.  As a result, it is important to limit the external users with which documents are shared, and to ensure that these anonymous links to get reviewed on a regular basis and disabled once external users no longer have a need to access documents.  This should be part of your information governance policies.

            Overall, sharing sites and information with external users is much simpler in Office 365 than its ever been, and Microsoft has provided some great security controls around this capability to ensure that sharing occurs in a secure and controlled way.

               -Antonio