{"id":4416,"date":"2024-07-11T11:00:00","date_gmt":"2024-07-11T16:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/cloud-security\/microsoft-melds-identity-sse-entra-suite"},"modified":"2024-07-11T11:00:00","modified_gmt":"2024-07-11T16:00:00","slug":"microsoft-melds-identity-sse-with-entra-suite","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/07\/11\/microsoft-melds-identity-sse-with-entra-suite\/","title":{"rendered":"Microsoft Melds Identity &amp; SSE With Entra Suite"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt0e0016b5ca0459e4\/668f0f3d86ce3f0ff143178d\/NicoElNino-digital-lock-shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/microsoft-melds-identity-sse-with-entra-suite.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/microsoft-melds-identity-sse-with-entra-suite.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Microsoft has begun delivering on an enterprising plan to provide unified conditional access to enterprise and software-as-a-service (SaaS) resources, releasing network-based security service edge (SSE) offerings that have been integrated into its flagship Entra Identity portfolio.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The new Microsoft Azure-based SSE offerings, which provide perimeterless secure access to cloud and enterprise applications, became commercially available today as core components of what the tech giant has dubbed the Entra Suite.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Specifically, the Entra Suite SSE offerings include <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/identity-access\/microsoft-entra-internet-access\" rel=\"noopener\">Entra Internet Access<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, which provides secure access to SaaS-based applications, and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/identity-access\/microsoft-entra-private-access\" rel=\"noopener\">Entra Private Access<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, designed to replace virtual private networks (VPNs) with more granular access to enterprise resources. Both use Entra ID&#8217;s (formerly Azure AD) <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/decoding-identity-and-access-management-for-organizations-and-consumers\" rel=\"noopener\">least-privilege access<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> policies.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The Entra Suite also integrates Entra Identity with network security controls to provide what Microsoft calls a &#8220;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/frontdoor\/front-door-overview\" rel=\"noopener\">front door perimeter<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.&#8221; It includes Microsoft&#8217;s new Entra Identity Governance, Entra Verified ID, and Entra Identity Protection offerings, including the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/identity-access-management-security\/microsoft-adds-face-check-to-entra-verified-id\" rel=\"noopener\">recently launched Face Check<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Entra Internet Access &amp; Private Access: The Details\">Entra Internet Access &amp; Private Access: The Details<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Entra Internet Access is a secure Web gateway (SWG) that provides secure access to SaaS applications, including Microsoft 365 apps. According to Microsoft, Entra Internet Access combines conditional access policies with network conditions, which can defend against malicious traffic and threats.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Specific to Microsoft 365 applications, Entra Intranet Access offers Universal Tenant Restrictions, which Microsoft says will prevent data exfiltration to other tenants or personal accounts.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Microsoft&#8217;s Entra Private Access provides secure access to enterprise applications regardless of where the application is hosted. It enables attribute-based conditional access policies, which lets administrators create policies based on risks and conditions, such as device compliance, location, and sensitivity of data.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Joy Chik, Microsoft&#8217;s president of identity and network access, says that with Entra Suite, all of the components, including Entra ID Governance, Entra ID Protection, and Entra Verified ID, are integrated with conditional access.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Everything is under the Entra administration experience,&#8221; she says. &#8220;All the policy settings, everything is a fully integrated end-to-end scenario.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Streamlining: A Unified Approach to Conditional Access\">Streamlining: A Unified Approach to Conditional Access<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Microsoft believes that enterprise security teams want to rely on one provider for identity and secure network access so they can all share the same policies and conditions.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;It will help us unify conditional access, which is the security policy engine for doing secure access, with both the identity signals and network signals together,&#8221; Chik says. &#8220;Customers are longing for the capability to integrate identity and network signals together into one place with Entra conditional access.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">During a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/microsoft-expands-entra-into-secure-service-edge\" rel=\"noopener\">briefing last year that previewed today&#8217;s launches<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, Chik made the case for Microsoft&#8217;s one-stop approach to integrating identity into the mix.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Neither identity nor network security controls alone can protect all access points,&#8221; she says. &#8220;But if you&#8217;re using disconnected tools, some of the critical integration points can be missed. Skilled adversaries often exploit seams between solutions.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"One Suite to Rule Them All?\">One Suite to Rule Them All?<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The jury is still out on how many organizations will embrace Microsoft&#8217;s approach of converging their identity and network access platforms, says Forrester principal analyst Geoff Cairns. Even if they do, it remains to be seen whether they will fall in line behind Microsoft&#8217;s suite approach.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;I&#8217;ve been talking with clients, grappling with whether or not to put all their identity access management [IAM] security infrastructure eggs in the Microsoft Entra basket given the concentration risk,&#8221; he says, referring to the idea that having the proverbial &#8220;single throat to choke&#8221; in order to subvert the whole system could be risky.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Cairns anticipates that those most likely to make that move will be organizations that have embraced Microsoft-centric environments already and are in the process of modernizing their security stacks.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Scale and complexity of the organization and its IT environment will be a critical decision factor,&#8221; he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">According to Omdia senior analyst Don Tait, the convergence of IAM and network security may be inevitable over time.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;I definitely think that network security, while it remains critically important overall, must now move aside as identity security comes to the fore,&#8221; Tait says. &#8220;Note, for instance, the growing importance of IDR\/ITDR [intrusion detection and response\/identity threat detection and response] technology in this context.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It should be noted that Entra won&#8217;t be all-Microsoft, all the time, for long: Later this year, Microsoft will reveal plans to partner with third-party network and SSE providers, Chik says. Among the leading SSE providers are Cisco, Cloudflare, Netskope, Palo Alto Networks, and Zscaler.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cloud-security\/microsoft-melds-identity-sse-entra-suite\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft has begun delivering on an enterprising plan to provide<\/p>\n","protected":false},"author":12,"featured_media":4417,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4416","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/microsoft-melds-identity-sse-with-entra-suite.jpg?fit=1800%2C1013&ssl=1",1800,1013,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/microsoft-melds-identity-sse-with-entra-suite.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/microsoft-melds-identity-sse-with-entra-suite.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/microsoft-melds-identity-sse-with-entra-suite.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/microsoft-melds-identity-sse-with-entra-suite.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/microsoft-melds-identity-sse-with-entra-suite.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/microsoft-melds-identity-sse-with-entra-suite.jpg?fit=1800%2C1013&ssl=1",1800,1013,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/microsoft-melds-identity-sse-with-entra-suite.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/microsoft-melds-identity-sse-with-entra-suite.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/microsoft-melds-identity-sse-with-entra-suite.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/microsoft-melds-identity-sse-with-entra-suite.jpg?fit=1800%2C1013&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4416","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4416"}],"version-history":[{"count":1,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4416\/revisions"}],"predecessor-version":[{"id":4418,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4416\/revisions\/4418"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4417"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4416"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4416"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4416"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}