Hi all,
I'm frustrated with trying to assess the security of Office 365 Apps. Can anyone provide some helpful tips for reviewing Office 365 Apps in a world where Microsoft is continuously changing the landscape all of the time?
My situation: we have users regularly asking for security reviews of Office 365 apps. Typically this comes in the form of a scenario like: "we'd like to add [Project Management App X] to Office 365 so everyone can use it..." From here, I now need to wade into the murky world of APIs and Azure permissions and Microsoft licensing allowances to determine exactly what risks we may be taking on. Unfortunately, a typical progression from here often involves quickly layering on complexity in the form of shifting APIs, vendors using differing terminology (sometimes even within the same document) to describe how their product works, sussing out the exposure risks of only delegate versus tacking on application-level permissions, properly integrating into CAS monitoring, whether or not the vendor's solution utilizes additional data storage/processing operations completely outside our 365 tenant, etc.
Add to this my previous mention that Microsoft is always changing the rules such that even an article from 6 months ago can't necessarily be trusted anymore because it references some feature or other that's either been deprecated, renamed and redesigned, or moved into a different licensing scheme, and it creates a cocktail of hassle for us to try and properly determine the risks to the business. If anyone has any guides, courses, other advice they've found helpful in negotiating this controls nightmare, I'd really appreciate a point in that direction. I'm trying to develop a standardized questionnaire template that I think will help streamline these sorts of reviews for us in the future, but I feel like I really need to understand this stuff first, and even Microsoft seems to suck at providing guidance here. Thanks!
[link] [comments]