Ransomware Countermeasures – Windows Endpoints, Identity, and SaaS
In the previous chapter, we looked at how we can use different cloud-based services such as Microsoft Sentinel and Microsoft Defender for Cloud to provide us with security monitoring and vulnerability assessment capabilities.
In this chapter, we will focus in more depth on different countermeasures that can help us reduce the risk of ransomware attacks on some of the main attack vectors, namely endpoints, identity, email services, and network attacks.
In this chapter, we will cover the following topics:
- Securing Windows endpoints using Microsoft Intune with Azure AD endpoints
- Following attack surface reduction rules and protecting the browser using mechanisms such as SmartScreen and Application Guard
- Securing user identities in Azure AD and SaaS services
- Enhancing email security in Office 365 and reducing the risk of phishing attacks
- Other tips and tricks for securing Windows endpoints...