{"id":2493,"date":"2015-09-19T16:12:53","date_gmt":"2015-09-19T16:12:53","guid":{"rendered":"https:\/\/thebeagle.itgroove.net\/?p=2235"},"modified":"2023-02-24T21:39:40","modified_gmt":"2023-02-24T21:39:40","slug":"the-cloud-and-trust","status":"publish","type":"post","link":"https:\/\/regroove.ca\/archive\/2015\/09\/19\/the-cloud-and-trust\/","title":{"rendered":"The Cloud and Trust"},"content":{"rendered":"<p>We were having a discussion in the office yesterday that was triggered by a discovery we made about our Office365 backup solution (we use SkyKick).\u00a0 In a nutshell we discovered that the backup vendor has to make a few manipulations with provided credentials in order to back up site collections inside SharePoint Online.\u00a0 The provided creds have to be assigned site collection admin privileges in order to back up all site contents and I know that I didn\u2019t assign the creds explicitly.\u00a0 Sean surmised the backup vendor has to be doing something in the backend via PowerShell to make the assignment.<\/p>\n<p>Now all of this is not necessarily a bad thing, after all, you do want to be able to backup your data otherwise why would you contract with an O365 backup vendor?\u00a0 But it does raise some interesting questions and it means all of us have to re-evaluate how we look at security in the new Cloud-enabled world.<\/p>\n<p>By definition, any of us that sign up for an O365 tenancy are entering into a tacit and implied \u201csecurity agreement\u201d with Microsoft.\u00a0 Our data is being stored inside Microsoft\u2019s cloud and we are \u201ctrusting\u201d Microsoft to not pry into our private data.\u00a0 Microsoft has made many public statements about how they have layers of protection in place so that Microsoft employee\u2019s and contractors cannot \u201csee\u201d into any given organization\u2019s or user\u2019s data.\u00a0 And most of us have heard about Microsoft\u2019s efforts to deflect various American government agencies requests for access to customer data (which also raises interesting questions about those layers of security that prevent \u201cprying\u201d eyes).\u00a0 My point being that there are security layers in place to protect the privacy of customer data, at least at the\u00a0 Microsoft level.<\/p>\n<p>But what about the levels that are not under direct Microsoft control?<\/p>\n<p>A very common example that most organizations may not be aware of is the level of access that a \u201cpartner\u201d may have to data in the tenancy.\u00a0 Many organizations that use O365 contract with a Microsoft partner to help manage their tenancy, this is referred to as \u201cdelegated administration\u201d.\u00a0 itgroove, as an example, helps to manage over 40 tenancies at time this article is being written.\u00a0 In order to be able to manage inside O365 our \u201cdelegated admin\u201d accounts have certain rights that allow us access to a lot of data inside a given tenancy.\u00a0 Delegated admin does not give us 100% \u201cgod rights\u201d inside a tenancy but it does give us considerably more rights than you might think.\u00a0 So, by definition, there is also a tacit and implied security contract between us, the partner as delegated admin and you, as the O365 tenant.\u00a0 Again, there is not necessarily anything wrong with this but it is something that you as a tenant and we as a delegated admin have to agree on.<\/p>\n<p>In the \u201cold days\u201d your IT staff would have had certain rights across your systems, admins always need elevated access rights.\u00a0 You would have had explicit, internal security controls that would have defined who had what access and, normally, this would be pretty tightly controlled.\u00a0 Now, with the advent of the Cloud, your IT staff has expanded to include vendors, such as Microsoft, and partners, such as us.\u00a0 The security \u201cagreement\u201d, therefore, has tacitly and silently expanded to include these groups.\u00a0 But the active understanding of this security agreement probably has <em>not<\/em> been expanded or updated at the tenant organization level.<\/p>\n<p>I think a frank discussion is called for between the tenancy holder and the various partners so that all of the security concerns and issues are clearly understood by all.\u00a0 The tenancy holder needs to have a clear understanding of what access the partner needs and\/or has while the partner needs to be very clear and transparent about what the rules and boundaries are as far as the tenancy holder is concerned.\u00a0 And it is incumbent on the partner to inform the tenancy holder about the access that <em>other<\/em> services might have or require in order to implement a particular service, such as backup.<\/p>\n<p>As Cloud services and offerings expand, the inter-related connections between tenancy, partner and services vendor are going to grow and become very entangled.\u00a0 The tenancy holder really will need to have a good understanding of who can access what in order to stay on top and in control of their overall security.\u00a0 This means that tenant organizations will have to start asking more and more questions of their primary partners such as Microsoft and their Delegated Admins and organizations such as mine (itgroove) will have to expand scrutiny over the things that partnered service vendors do within a customer\u2019s tenancy in order to be able to answer those questions.<\/p>\n<p>The single biggest thing to keep in mind is that everyone\u2019s security role is changing and will continue to change and evolve as more services and offerings come online as part of the overall massive shift of services from on-prem to the Cloud.\u00a0 Scrutiny and oversight needs to \u201camp up\u201d to keep pace with the changes.\u00a0 So, go ahead and start having those conversations with your various partners, security of your data ultimately resides in your hands.\u00a0 In this case knowledge truly is power and ignorance becomes a security breach.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We were having a discussion in the office yesterday that was triggered by a discovery we made about our Office365 backup solution (we use SkyKick).\u00a0 In a nutshell we discovered that the backup vendor has to make a few manipulations with provided credentials in order to back up site collections inside SharePoint Online.\u00a0 The provided &hellip; <a href=\"https:\/\/regroove.ca\/archive\/2015\/09\/19\/the-cloud-and-trust\/\"><\/a><\/p>\n","protected":false},"author":10,"featured_media":2109,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[220,247],"tags":[494,150,607,629],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.0 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>The Cloud and Trust - Archive<\/title>\n<meta name=\"robots\" content=\"index, nofollow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/regroove.ca\/archive\/2015\/09\/19\/the-cloud-and-trust\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The Cloud and Trust - Archive\" \/>\n<meta property=\"og:description\" content=\"We were having a discussion in the office yesterday that was triggered by a discovery we made about our Office365 backup solution (we use SkyKick).\u00a0 In a nutshell we discovered that the backup vendor has to make a few manipulations with provided credentials in order to back up site collections inside SharePoint Online.\u00a0 The provided &hellip;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/regroove.ca\/archive\/2015\/09\/19\/the-cloud-and-trust\/\" \/>\n<meta property=\"og:site_name\" content=\"Archive\" \/>\n<meta property=\"article:published_time\" content=\"2015-09-19T16:12:53+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-02-24T21:39:40+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2014\/11\/halt-clipart-halt-man-md-e1442701865399.png\" \/>\n\t<meta property=\"og:image:width\" content=\"200\" \/>\n\t<meta property=\"og:image:height\" content=\"184\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Sean Wallbridge\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sean Wallbridge\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/regroove.ca\/archive\/2015\/09\/19\/the-cloud-and-trust\/\",\"url\":\"https:\/\/regroove.ca\/archive\/2015\/09\/19\/the-cloud-and-trust\/\",\"name\":\"The Cloud and Trust - Archive\",\"isPartOf\":{\"@id\":\"https:\/\/regroove.ca\/archive\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/regroove.ca\/archive\/2015\/09\/19\/the-cloud-and-trust\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/regroove.ca\/archive\/2015\/09\/19\/the-cloud-and-trust\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2014\/11\/halt-clipart-halt-man-md-e1442701865399.png\",\"datePublished\":\"2015-09-19T16:12:53+00:00\",\"dateModified\":\"2023-02-24T21:39:40+00:00\",\"author\":{\"@id\":\"https:\/\/regroove.ca\/archive\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77\"},\"breadcrumb\":{\"@id\":\"https:\/\/regroove.ca\/archive\/2015\/09\/19\/the-cloud-and-trust\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/regroove.ca\/archive\/2015\/09\/19\/the-cloud-and-trust\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/regroove.ca\/archive\/2015\/09\/19\/the-cloud-and-trust\/#primaryimage\",\"url\":\"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2014\/11\/halt-clipart-halt-man-md-e1442701865399.png\",\"contentUrl\":\"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2014\/11\/halt-clipart-halt-man-md-e1442701865399.png\",\"width\":200,\"height\":184},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/regroove.ca\/archive\/2015\/09\/19\/the-cloud-and-trust\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Blog Archive\",\"item\":\"https:\/\/regroove.ca\/archive\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"The Cloud and Trust\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/regroove.ca\/archive\/#website\",\"url\":\"https:\/\/regroove.ca\/archive\/\",\"name\":\"Archive\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/regroove.ca\/archive\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/regroove.ca\/archive\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77\",\"name\":\"Sean Wallbridge\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/regroove.ca\/archive\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g\",\"caption\":\"Sean Wallbridge\"},\"url\":\"https:\/\/regroove.ca\/archive\/author\/swallbridge\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"The Cloud and Trust - Archive","robots":{"index":"index","follow":"nofollow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/regroove.ca\/archive\/2015\/09\/19\/the-cloud-and-trust\/","og_locale":"en_US","og_type":"article","og_title":"The Cloud and Trust - Archive","og_description":"We were having a discussion in the office yesterday that was triggered by a discovery we made about our Office365 backup solution (we use SkyKick).\u00a0 In a nutshell we discovered that the backup vendor has to make a few manipulations with provided credentials in order to back up site collections inside SharePoint Online.\u00a0 The provided &hellip;","og_url":"https:\/\/regroove.ca\/archive\/2015\/09\/19\/the-cloud-and-trust\/","og_site_name":"Archive","article_published_time":"2015-09-19T16:12:53+00:00","article_modified_time":"2023-02-24T21:39:40+00:00","og_image":[{"width":200,"height":184,"url":"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2014\/11\/halt-clipart-halt-man-md-e1442701865399.png","type":"image\/png"}],"author":"Sean Wallbridge","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Sean Wallbridge","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/regroove.ca\/archive\/2015\/09\/19\/the-cloud-and-trust\/","url":"https:\/\/regroove.ca\/archive\/2015\/09\/19\/the-cloud-and-trust\/","name":"The Cloud and Trust - Archive","isPartOf":{"@id":"https:\/\/regroove.ca\/archive\/#website"},"primaryImageOfPage":{"@id":"https:\/\/regroove.ca\/archive\/2015\/09\/19\/the-cloud-and-trust\/#primaryimage"},"image":{"@id":"https:\/\/regroove.ca\/archive\/2015\/09\/19\/the-cloud-and-trust\/#primaryimage"},"thumbnailUrl":"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2014\/11\/halt-clipart-halt-man-md-e1442701865399.png","datePublished":"2015-09-19T16:12:53+00:00","dateModified":"2023-02-24T21:39:40+00:00","author":{"@id":"https:\/\/regroove.ca\/archive\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77"},"breadcrumb":{"@id":"https:\/\/regroove.ca\/archive\/2015\/09\/19\/the-cloud-and-trust\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/regroove.ca\/archive\/2015\/09\/19\/the-cloud-and-trust\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/regroove.ca\/archive\/2015\/09\/19\/the-cloud-and-trust\/#primaryimage","url":"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2014\/11\/halt-clipart-halt-man-md-e1442701865399.png","contentUrl":"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2014\/11\/halt-clipart-halt-man-md-e1442701865399.png","width":200,"height":184},{"@type":"BreadcrumbList","@id":"https:\/\/regroove.ca\/archive\/2015\/09\/19\/the-cloud-and-trust\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog Archive","item":"https:\/\/regroove.ca\/archive\/"},{"@type":"ListItem","position":2,"name":"The Cloud and Trust"}]},{"@type":"WebSite","@id":"https:\/\/regroove.ca\/archive\/#website","url":"https:\/\/regroove.ca\/archive\/","name":"Archive","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/regroove.ca\/archive\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/regroove.ca\/archive\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77","name":"Sean Wallbridge","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/regroove.ca\/archive\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g","caption":"Sean Wallbridge"},"url":"https:\/\/regroove.ca\/archive\/author\/swallbridge\/"}]}},"_links":{"self":[{"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/posts\/2493"}],"collection":[{"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/comments?post=2493"}],"version-history":[{"count":1,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/posts\/2493\/revisions"}],"predecessor-version":[{"id":2781,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/posts\/2493\/revisions\/2781"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/media\/2109"}],"wp:attachment":[{"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/media?parent=2493"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/categories?post=2493"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/tags?post=2493"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}