As part of their overall security and compliance strategy, aerospace and defense contractors supporting the Department of Defense (DoD) who are leveraging the Microsoft 365 E3 need to consider moving from the Microsoft 365 E3 to an E5 license. In part 2 of this blog, we're going to:
If you haven't already, check out Part 1 of this two-part blog before reading any further.
As a short recap, let's go over a few of the benefits when performing the E5 Uplift. It allows contractors to:
Now, let's get specific with what each workload is capable of and how you can leverage them.
Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that provides visibility, data flow control, and analytics to identify and mitigate threats across all Microsoft and third-party cloud services. Utilizing this product allows organizations to:
Microsoft Defender for Endpoint Plan 2 (part of the M365 E5) is an enterprise endpoint security platform designed to help enterprise networks prevent, detect, investigate, and respond to advanced threats. Microsoft Defender for Endpoint Plan 2 uses the combination of technology built into Windows 10/11 and Microsoft's robust cloud service to provide:
Microsoft Privileged Identity Management (PIM) provides organizations with the capabilities to limit time and access capabilities for privileged accounts. Controlling access allows the organization to limit privileged access to an authorized time frame (e.g., 2 days, 2 weeks, 2 months) instead of permanent role assignments seen in normal Azure AD elevated privileged roles. This allows organizations to reduce the risk of permanently privileged accounts becoming compromised and amplifying incidents.
With Microsoft Privileged Identity Management, accounts that wish to elevate rights to perform administrative functions must be approved with time-bound constraints attached to the request. Organizations may also incorporate IT Service Management (ITSM) software into the mix to track these changes with service tickets using an automated process.
Azure AD Identity Protection is a tool in the Microsoft 365 E5 that allows organizations to accomplish three key tasks:
With Azure AD Identity Protection organizations can:
Azure Information Protection and Auto-labeling helps organizations proactively counter potential users’ errors which may lead to unauthorized data access and distribution. When appropriately leveraged, organizations using the Azure Information Protecting Auto-labeling client can:
Customer Lockbox ensures that Microsoft cannot access your content to do service operations without your explicit approval. Customer Lockbox brings you into the approval workflow process that Microsoft uses to ensure only authorized requests allow access to your content. Lockbox offers:
As you've seen, performing an E5 uplift and looking into the workloads within the E5 benefit organizations looking to leverage the Microsoft platform, and help prepare contractors in the Defense Industrial Base for specific compliance requirements such as CMMC 2.0.
You can begin your licensing journey by downloading our M365 licensing guide here.
Important note for your licensing strategy - organizations can now leverage Microsoft 365 GCC High to collaborate with other versions of the cloud.
To discuss the Microsoft 365 E5 in greater detail about how your organization can leverage the platform, or to speak with a member of the Summit 7 team about Microsoft licensing, you can take action via: