Lab: Configuring Rights Management and compliance
Exercise 1: Configuring Rights Management in Office 365
Task 1: Activate Rights Management in Office 365
- On LON-CL1, open Microsoft Edge, and then connect to https://portal.office.com.
- Sign in to the Microsoft Office 365 portal as Beth@Adatumyyxxxxx.onmicrosoft.com, where yyxxxxx is your unique Adatum number with the password you created in Module 1.
- In the app launcher, select the Admin icon.
- In the Microsoft 365 admin center, select Settings and then select Services & add-ins.
- Select Microsoft Azure Information Protection.
- On the Microsoft Azure Information Protection page, select Manage Microsoft Azure Information Protection settings.
- On the rights management page, verify that rights management is activated.
NOTE: If rights management is not activated:
- Select activate.
- When prompted with Do you want to activate Rights Management?, select activate.
Task 2: Verify Rights Management settings for Exchange Online
- On LON-CL1, in the search box on the taskbar, type PowerShell.
- In the search results, right-click Windows PowerShell, and then select Run as administrator.
- When the User Account Control dialog box appears, provide the following credentials and select Yes:
- User name: Administrator
- Password: Pa55w.rd
- Type the following commands, and then press Enter after each command to connect to remote Exchange Online with remote PowerShell. Use Beth’s credentials to connect.
$Cred = Get-Credential
$Session = New-PSSession -ConfigurationName Microsoft.Exchange -ConnectionUri https://outlook.office365.com/powershell-liveid/ -Credential $Cred -Authentication Basic -AllowRedirection
Import-PSSession $Session -DisableNameChecking
- Type the following command, and then press Enter to view the IRM configuration.
Get-IRMConfiguration
- In the result, verify that values for the first nine variables are set to True (except for TransportDecryptionSetting which can have value Optional).
- Type the following command, replacing yyxxxxx with your unique Adatum number, and then press Enter to test the configuration.
Test-IRMConfiguration -Sender [email protected]
- Verify that you receive OVERALL RESULT: PASS message at the end of the test results.
- Type the following command, press Enter, and then close Windows PowerShell.
Remove-PSSession $Session
Task 3: Configure Rights Management for SharePoint Online
- In Edge, open the Microsoft 365 admin center.
NOTE: If the Microsoft Azure Information Protection page is open, select Close.
- Under Admin centers, select SharePoint then Classic SharePoint admin center.
- Select settings.
- Next to Information Rights Management (IRM), select Use the IRM service specified in your configuration.
- Select Refresh IRM Settings, then select OK.
Task 4: Validate the Azure Rights Management functionality
- On LON-CL1, open Word.
- In the Word window, at the top right corner, select Switch account.
- In the Accounts dialog box, select Add Account.
- Verify you are signed in as Beth@Adatumyyxxxxx.onmicrosoft.com, where yyxxxxx is your unique Adatum number with the password you created in Module 1.
- Close Word.
- Open Outlook.
- Create a new email with Christie Thomas as the recipient.
- Type a subject, and then type some text in the message body.
- On the Options tab, select the down arrow below Permission, and then select Connect to the Rights Management Server and get templates. If Windows Security window appears, select OK and sign in with Beth’s credentials.
- Select the down arrow below Permission again, and then select Do Not Forward.
- Send the message.
- In Microsoft Edge, connect to https://adatum*yyxxxxx*.sharepoint.com/sites/marketing, where yyxxxxx is your unique Adatum number.
- Select Documents, select the settings icon (the gear at the upper-right corner of the window), and then select Library settings.
- On the Settings page, under Permissions and Management, select Information Rights Management.
- On the Information Rights Management Settings page, select the Restrict permissions on this library on download checkbox.
- In the Create a permission policy title box, type Marketing Policy.
- In the Add a permission policy description box, type Marketing policy for downloads.
- Select SHOW OPTIONS.
- Under Configure document access rights, select the Allow viewers to write on a copy of the downloaded document checkbox.
- Select OK.
- Close Microsoft Edge.
- Open Microsoft Edge, and then connect to https://portal.office.com. Sign in as Christie@Adatumyyxxxxx.hostdomain.com, where yyxxxxx is your unique Adatum number, with the password you created on Module 1.
- In the Office 365 portal, in the App launcher, select Outlook.
- On the Outlook page, if prompted, select your time zone and select Save.
- Verify that you received an email from Beth that is IRM protected. Select the message.
You may need to wait for Outlook Web Access to update with the IRM template.
You can also use LON-CL3 to check mail using Outlook.
- Select More actions (…) beside Reply all, and then verify that you do not have the option to forward or print the message.
- In Microsoft Edge, connect to https://adatum*yyxxxxx*.sharepoint.com/sites/marketing, where yyxxxxx is your unique Adatum number.
- Select Documents, and then select Document.docx.
- After the document opens, try to edit it in Word Online. Verify that you get a message that the document is read-only.
- Close Microsoft Edge.
Result: After completing this exercise, you will have configured Rights Management for Exchange Online and SharePoint Online.
Exercise 2: Configuring compliance features
Task 1: Configure Security & Compliance Center permissions and audit logging
- On LON-CL1, open Microsoft Edge, and then connect to https://portal.office.com.
- Sign in to the Office 365 portal as Beth@Adatumyyxxxxx.onmicrosoft.com, where yyxxxxx is your unique Adatum number with the password you created in Module 1.
- Select Admin.
- Expand Admin centers and then select Security & Compliance.
- In the Security & Compliance Center, select Permissions.
- Select Compliance Administrator.
- On the Compliance Administrator page, next to Members, select Edit.
- Select Choose members, select Add, select both instances of Beth Burke, select Add, and then select Done.
- Select Save, and then select Close.
- Next to To assign permissions for archiving, auditing and retention policies select go to the Exchange admin center.
- Select Compliance Management, and then select Edit.
- On the Compliance Management page, under Members, select Add.
- In the Select Members window, select both instances of Beth Burke, select add, and then select OK.
- Select Save.
- Select Recipient Management, and then select Edit.
- On the Recipient Management page, under Members, select Add.
- In the Select Members window, select both instances of Beth Burke, select add, and then select OK.
- Select Save.
- Close the Role Groups window.
- On the Security & Compliance page, select Permissions.
- On the Permissions page, select eDiscovery Manager.
- Next to eDiscovery Manager, select Edit, select Choose eDiscovery Manager, select Add, select Christie Thomas, select Add, and then select Done.
- Select Save, then select Close.
- On the Office 365 Security & Compliance page, select Home and then under Search & investigation, and select Search for admin and user activity.
- On the Audit log search page, select Turn on auditing.
- In the Activities drop-down, select User administration activities, and then select Search.
NOTE: In production you would enter a search string, such as a user name, to find specific activities.
- Close Microsoft Edge.
Task 2: Configure archive mailboxes
- On LON-CL1, open Microsoft Edge, and then connect to https://protection.office.com.
- Sign in to the Security & Compliance Center as Beth@Adatumyyxxxxx.onmicrosoft.com, where yyxxxxx is your unique Adatum number, with the password you created in Module 1.
NOTE: Beth is a member of the Compliance Administrator role, so she can connect to the protection website.
If you are signed in to Office 365 already, you may not need to sign in again.
- Select Data governance, and then select Archive.
- In the Archive window, select Christie Thomas, and then Ctrl + select Catherine Richard.
- Under Bulk Edit, select Enable. In the warning message, select Yes, and then select Close.
- Select Refresh, and then verify that Christie and Catherine have been enabled for an archive mailbox.
- Close Microsoft Edge.
Task 3: Configure retention tags and policies
- On LON-CL1, open Microsoft Edge, and then connect to https://portal.office.com.
- Sign in to the Office 365 portal as Beth@Adatumyyxxxxx.onmicrosoft.com, where yyxxxxx is your unique Adatum number, with the password you created in Module 1.
- Select Admin.
- Expand Admin centers, and select Exchange.
- Select compliance management, then select retention tags.
- Select New tag, and then select applied automatically to entire mailbox (default).
- Type Research User 1 year move to archive as the name..
- Select Move to Archive as the Retention action.
- Type 365 as the Retention period.
- Select Save.
- On the toolbar, select New tag, and then select applied automatically to entire mailbox (default).
- Type Default 2 years move to Deleted Items as the name.
- Select Delete and Allow Recovery as the Retention action.
- Type 730 as the Retention period.
- Select Save.
- On the toolbar, select New tag, and then select applied automatically to a default folder.
- Type Purge Deleted Items 30 days as the name.
- Under Apply this tag to the following default folder, select Deleted Items.
- Select Permanently Delete as the Retention action.
- Type 30 as the Retention period.
- Select Save.
- On the toolbar, select New tag, and then select applied by users to items and folders (personal).
- Type 2 Year Delete as the name.
- Select Delete and Allow Recovery as the Retention action.
- Type 730 as the Retention period.
- Select Save.
- On the toolbar, select New tag, and then select applied by users to items and folders (personal).
- Type Never archive as the name.
- Select Move to Archive as the Retention action.
- Select Never as the Retention period.
- Select Save.
- Select retention policies.
- On the toolbar, select New.
- On the new retention policy page, type Research MRM Policy as the name.
- Select Add below Retention tags.
- In the select retention tags window, Ctrl+select the following retention tags:
- Research user 1 year move to archive
- Never delete
- 2 year delete
- Select add, and then select OK. Select Save.
- In the left-hand menu, select recipients.
- On the mailboxes page, select Christie Thomas, and then select Edit.
- Select mailbox features and under Retention policy select Research MRM Policy, and then select Save.
- Close Microsoft Edge.
Task 4: Configure content deletion and preservation policies
- On LON-CL1, open Microsoft Edge, and then connect to https://protection.office.com.
- Sign in to the Security & Compliance Center as Beth@Adatumyyxxxxx.onmicrosoft.com, where yyxxxxx is your unique Adatum number, with the password you created in Module 1.
- Expand Data governance, and then select Retention.
- Select Create.
- On the Name your policy page, enter Marketing Document Policy in the Name textbox and select Next.
- On the Settings page, under Do you want to retain content? select No, just delete content that’s older than, type 7 and verify that years is selected.
- Next to Delete the content based on, verify that when it was created is selected, and select Next.
- On the Choose locations page select Let me choose specific locations.
- Turn off the option for Exchange email.
- Next to the SharePoint sites option select Choose sites.
- On the Edit locations page select Choose sites.
- In the search box, enter https://adatum*yyxxxxx*.sharepoint.com/sites/marketing, replacing yyxxxxx with your unique Adatum number, and select the Search icon.
- Select the Marketing site and select Choose and then select Done. Select Next.
- On the Review your settings page, verify all settings and note any warnings, and then select Create this policy.
- Verify that the Status is On (Pending), and then select Close.
- Select Create.
- On the Name your policy page, enter Retain contract details in the Name textbox and select Next.
- On the Settings page, under Do you want to retain content? select Yes, I want to retain it, type 7 and verify that years and when it was created are selected.
- Select Use advanced retention settings.
- Verify that Detect content that contains specific words or phrases is selected, and select Next.
- In the Keywords query editor box, type Contract and select Next.
- On the Choose locations page, select Let me choose specific locations.
- On the Choose locations page, next to Exchange email, select Choose recipients.
- On the Edit locations page, select Choose recipients.
- Select Francisco Chaves, select Choose, and then select Done.
- On the Choose locations page, next to the SharePoint sites option, select Choose sites.
- On the Edit locations page, select Choose sites.
- In the search box, enter https://adatum*yyxxxxx*.sharepoint.com/sites/Acctsproj, replacing yyxxxxx with your unique Adatum number, and then select the Search icon.
- Select the Accounts Project site, select Choose, and then select Done.
- On the Choose locations page, turn off OneDrive accounts and Office 365 groups, and then select Next.
- On the Review your settings page, verify all settings and note any warnings, and then select Create this policy.
- Verify that the Status is On (Pending), and then select Close.
- Close Microsoft Edge.
Task 5: Configure data loss protection policies
- Open Microsoft Edge, and then browse to https://protection.office.com.
- Sign in to the Security & Compliance Center as Beth@Adatumyyxxxxx.onmicrosoft.com, where yyxxxxx is your unique Adatum number, with the password you created in Module 1.
- In the navigation pane, select Data loss prevention and then select Policy.
- Select Create a policy.
- On the Start with a template or create a custom policy page, verify that Custom is selected, and then select Next.
- On the Name your policy page, type Test DLP in Name textbox, and then select Next.
- On the Choose locations page, select Protect content in Exchange email, Teams chats and channel messages and OneDrive and SharePoint documents and select Next.
- On the Customize the types of content you want to protect page, select Use advanced settings, and select Next.
- On the Customize the types of content you want to protect page, select New rule.
- On the Create a new rule page, in the Name field, type Scan for IP address.
- Under Conditions, select the Add a condition drop-down, select Content contains, and in the Add drop-down select Sensitive info types.
- In Sensitive info types window, select Add. Scroll down in the list and select IP Address, select Add, and then select Done.
- Select the Add a condition drop-down, and select Content is shared.
- Under Content is shared, select with people outside my organization.
- Under Actions, select Add an action, and then select Restrict access or encrypt the content.
- Under User notifications, enable the option to Use notifications to inform your users and help educate them on the proper use of sensitive info.
- Under User overrides, enable the option to Let people who see the tip override the policy and share the content.
Note the additional options.
- Under Incident reports, enable the option to Use email incident reports to notify you when a policy match occurs.
- Select Save.
- On the Customize the types of content you want to protect page, select Next.
- On the Do you want to turn on the policy or test things out first? page, select Yes, turn it on right away and then select Next.
- On the Review your settings page, verify your settings, and then select Create.
- On the Test DLP page, verify that the Status is On, and then select Close
- Close Microsoft Edge.
Task 6: Create compliance check content
- Open Microsoft Edge, and then connect to https://portal.office.com.
- Sign in to the Office 365 portal as Beth@Adatumyyxxxxx.onmicrosoft.com, where yyxxxxx is your unique Adatum number, with the password you created in Module 1.
- On the Office 365 home page, select Outlook.
- Select New message, type the new Microsoft account email address that you created for this course in the To line.
- Type Server IP address as the Subject, type My IP is 192.168.1.15 as the message body.
- Wait for the policy tip appears at the top of message.
It may take up to several hours for the policy to be applied and for it to detect the message.
You may want to leave and come back to this task later.
- At the top of the message, select Show details.
- Select Override, and then select Send.
- Close Microsoft Edge.
Task 7: Validate the configuration
- Open Microsoft Edge, and then connect to https://outlook.com. Sign in with the Microsoft account you created for this course.
- Select the message from Beth Burke with the subject Server IP address.
- Close Microsoft Edge.
- Open Microsoft Edge, and then connect to https://portal.office.com.
- Sign in to the Office 365 portal as Christie@Adatumyyxxxxx.hostdomain.com, where yyxxxxx is your unique Adatum number, with the password you created in Module 1.
- Select Outlook.
- Select your time zone, and then select Save.
- In the left pane of Christie’s mailbox, under Folders, select More.
- Verify that a folder named In-Place Archive -Christie Thomas has been created.
- Close Microsoft Edge.
- Open Microsoft Edge, and then connect to https://portal.office.com.
- Sign in to the Office 365 portal as Beth@Adatumyyxxxxx.onmicrosoft.com, where yyxxxxx is your unique Adatum number, with the password Pa55w.rd.
- Select Outlook.
- Verify that you have received notification about message you sent to your personal account. This message should have Rule detected words in the subject.
Exercise 3: Using Compliance Manager
Task 1: Launch and review Compliance Manager
- Open Microsoft Edge, and then connect to https://servicetrust.microsoft.com.
- Sign in Service Trust Portal as Beth@Adatumyyxxxxx.onmicrosoft.com, where yyxxxxx is your unique Adatum number, with the password you created in Module 1.
- At the top of the page, select Compliance Manager and then select Compliance Manager Classic.
- Review the Microsoft Non-Disclosure Agreement for Compliance Materials and select Agree.
- Select Take the Tour, review each page of the Compliance Manager Tour, selecting Next, until you reach the last page.
- Select Done and review the Assessments dashboard.
Task 2: Review GDPR compliance assessments and action items
- On the Compliance Manager dashboard, under Assessments select Office 365 – GDPR.
- Expand Microsoft Managed Controls, then expand and review each item.
- Under Customer Managed Controls, expand PII sharing, transfer, and disclosure.
- Under Assign User, select Assign.
- In the Assign To box type Beth and select Beth Burke.
- In the Select Priority drop-down select High, and select Assign.
- Scroll to the top of the page and select Back To Dashboard.
Task 3: Review HIPAA compliance assessments and action items
- On the Compliance Manager dashboard, select Add Assessment.
- In the Enter new group box, enter HIPAA group and select Next.
- Set Would you like to copy the data from the existing group to No and select Next.
- In the Select a product drop-down select Office 365.
- In the Select a certification drop-down select HIPAA and select Add to Dashboard.
- On the dashboard, select Office 365 – HIPAA.
- Expand Microsoft Managed Controls and review the entries.
- Under Customer Managed Controls, expand Access Authorization (Addressable).
- Under Assigned User, select Assign.
- In the Assign To box type Beth and select Beth Burke.
- In the Select Priority drop-down, select High, and select Assign.
- Close Edge.
- Leave the virtual machines running for the next lab.
Result: After completing this exercise, you will have implemented the Office 365 compliance features.