It's Time to Hang Up on Phone Transports for Authentication

This article is contributed. See the original author and article here.

In my blog Your Pa$$word doesn’t matter, I laid out the key password vulnerabilities, and in response to a gazillion “but other creds can be compromised, too” DMs and emails, I wrote All our creds are belong to us, where I outlined vulnerabilities in credentials other than passwords and highlighted the promise of passwordless, cryptographically protected creds like FIDO, Windows Hello, and the Authenticator App.


Today, I want to do what I can to convince you that it’s time to start your move away from the SMS and voice Multi-Factor Authentication (MFA) mechanisms. These mechanisms are based on publicly switched telephone networks (PSTN), and I believe they’re the least secure of the MFA methods available today. That gap will only widen as MFA adoption increases attackers’ interest in breaking these methods and purpose-built authenticators extend their security and usability advantages. Plan your move to passwordless strong auth now – the authenticator app provides an immediate and evolving option.


It bears repeating, however, that MFA is essential – we are discussing which MFA method to use, not whether to use MFA. Quoting an earlier blog, “Multi-factor Authentication (MFA) is the least you can do if you are at all serious about protecting your accounts. Use of anything beyond the password significantly increases the costs for attackers, which is why the rate of compromise of accounts using any type of MFA is less than 0.1% of the general population.”


The Usual Suspects



It’s worth noting that every mechanism to exploit a credential can be used on PSTN – OTP. Phish? Check. Social? Check. Account takeover? Check. Device theft? Check. Your PSTN account has all the vulnerabilities of every other authenticator and a host of other issues specific to PSTN.


Not Adaptable



Because so many devices rely on receiving PSTN messages, the format of the messages is limited – we can’t make the messages richer, or longer, or do much of anything beyond sending the OTP in a short text message or a phone call. One of the significant advantages of services is that we can adapt to user experience expectations, technical advances, and attacker behavior in real-time. Unfortunately, the SMS and voice formats aren’t adaptable, so the experiences and opportunities for innovations in usability and security are very limited.


Transmitted in the Clear



When SMS and voice protocols were developed, they were designed without encryption. From a practical usability perspective, we can’t overlay encryption onto these protocols because users would be unable to read them (there are other reasons too, like message bloat, which have prevented these from taking hold over the existing protocols). What this means is that signals can be intercepted by anyone who can get access to the switching network or within the radio range of a device. As I said in the earlier “All Your Creds” blog, “an attacker can deploy a software-defined-radio to intercept messages, or a nearby FEMTO, or use an SS7 intercept service to eavesdrop on the phone traffic.” This is a substantial and unique vulnerability in PSTN systems that is available to determined attackers.


Easy to Social Engineer



It’s worth noting that most PSTN systems are backed by online accounts and rich customer support infrastructure. Sadly, customer support agents are vulnerable to charm, coercion, bribery, or extortion. If these social engineering efforts succeed, customer support can provide access to the SMS or voice channel. While social engineering attacks impact email systems as well, the major email systems (e.g. Outlook, Gmail) have a more developed “muscle” for preventing account compromise via their support ecosystems. This leads to everything from message intercept, to call forwarding attacks, to SIM jacking.


 


Subject to Mobile Operator Performance



Unfortunately, PSTN systems are not 100% reliable, and reporting is not 100% consistent.  This is region and carrier dependent, but the path a message takes to you may influence how long it takes to get and whether you get it at all. In some cases, carriers report delivery when delivery has failed, and in others, delivery of messages can take a long enough time that users assume messages have been unable to get through. In some regions, delivery rates can be as low as 50%! Because SMS is “fire and forget,” the MFA provider has no real-time signal to indicate a problem and has to rely on statistical completion rates or helpdesk calls to detect problems. This means signal to users to offer alternatives or warn of an issue is difficult to provide.


 


Subject to Changing Regulations



Due to the increase in spam in SMS formats, regulators have required regulations on identifying codes, transmit rates, message content, permission to send, and response to messages like “STOP.” Unfortunately, however, these regulations change rapidly and are inconsistent from region to region and can (and have) resulted in major delivery outages. More outages, more user frustration.


Limited Context



In practical terms, the text or voice mediums limit how much information can be communicated to a user – SMS carries 160 characters, 70 if not using GSM, and once we get into languages which require encoding, the practical limit without message splitting is only around half that. Phishing is a serious threat vector, and we want to empower the user with as much context as possible (or, using Windows Hello or FIDO, make phishing impossible) – SMS and voice formats restrict our ability to deliver the context under which authentication is being requested.


Authentication Evolved



Ok, to recap: you’re GOING to use MFA. Which MFA? Well, for most users on their mobile devices, we believe the right answer is app-based authentication. For us, that means the Microsoft Authenticator. The Authenticator uses encrypted communication, allowing bi-directional communication on authentication status, and we’re currently working on adding even more context and control to the app to help users keep themselves safe. In just the last year, we’ve added app lock, hiding notifications from the lock screen, sign-in history in the app, and more – and this list will have grown by the time you plan your deployment, and keep growing while SMS and voice keep sitting still.


Hang up on PSTN and pick up the Microsoft Authenticator – your users will be happier and more secure because you did.

Stay safe out there,


Alex (Twitter: @alex_t_weinert)

Leveling Up Your Azure SQL Database Deployments | Data Exposed: MVP Edition

This article is contributed. See the original author and article here.

The Basic, Standard, and Premium service tiers fulfill a lot of customers’ needs. For some customers, though, the General Purpose, Business Critical, and Hyperscale service tiers offer additional performance and ability that is required for certain workloads. Even if you don’t require those abilities, the technology and infrastructure behind these are worth learning about! In this episode with Matt Gordon, we’ll discuss those service tiers as well as discussing the differences between Provisioned and Serverless deployments on the General Purpose tier. Come learn how to ramp up your Azure SQL Database experience!


 


Watch on Data Exposed 


 


Resources:


 

View/share our latest episodes on Channel 9 and YouTube!

[Guest Blog] Why We Use Microsoft for Our CMMC Managed Service Customers

[Guest Blog] Why We Use Microsoft for Our CMMC Managed Service Customers

This article is contributed. See the original author and article here.

 


 


In January of this year, the Department of Defense (DoD) released the Cybersecurity Maturity Model Certification or CMMC. This new maturity model defines five levels of increasing maturity and will require all defense contractors, both Primes and Subs, to comply with one of the five levels and attain independent verification of compliance prior to contract award. In an ongoing effort to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI), CMMC is a significant change for DoD acquisition, cybersecurity, and policy. For small businesses in the defense industrial base, the challenge is potentially insurmountable.  


 


Having partnered with the DoD as part of the Defense Industrial Base Cybersecurity Initiative since its inception, first as a Chief Information Security Officer with one of the largest DoD contractors and now as CEO of CyberSheaththe foremost Managed CMMC compliance provider, I have seen every side of this compliance problem and understand what works and what doesn’t. Because of this, I am often asked, “How can I meet CMMC requirements?” My answer is always the same, “Hire a great Managed Compliance partner and use Microsoft technologies.” If you only use internal resources, you will inevitably fall short somewhere on the security, technical, or policy expertise required. If you try to use multiple technologies from different vendors, you will have more tools than you can support, possibly achieving compliance and assuredly weakening security. This blog details what Managed Compliance looks like in the context of CMMC. 


 


So, why Microsoft for CMMC? 


Microsoft has a deep and long history of supporting government customers and their unique mission requirements; in fact, about a year ago, Richard Wakeman  wrote this blog specific to the Microsoft Cloud Service Offerings. Suffice it to say Microsoft uniquely understands the U.S. Government’s mission in a way that only decades of experience working alongside one another will allow. Microsoft understands the required people, processes, and technologies to support the DoD mission from both a compliance and operational perspective so well that it can often be difficult for anyone to lay it all out in one succinct communication. Microsoft has done more for the United States Government than any other cloud provider. Their decades of successful partnership with DoD have enabled them to provide resources that will enable your journey to CMMC compliance.  


 


Here are three resources to get you started on your journey to CMMC compliance: 


 


Shared Responsibility Model 


CMMC compliance for many, if not most, companies will undoubtedly rely on the cloud at some point in the journey. When in the cloud, and frankly, on-premise, it is important to understand the concept of shared responsibility. When relying on cloud services, understanding the shared responsibility model is foundational to meeting and maintaining compliance. For an excellent blog on shared responsibility in the cloud start here and as you read think about which CMMC security tasks are handled by your cloud provider and which tasks are handled by you. Now for the many companies that rely on Managed Service Providers, or otherwise defined Third-Party Providers, how are you extending the shared responsibility to those entities?  


 


Very few MSSPs understand CMMC in the context of the shared responsibility model. To my knowledge, CyberSheath is one of the few to build our entire CMMC management platform around Microsoft Azure technology, which is detailed here along with a breakdown of how CMMC has been 13 years in the making. 


 


CMMC compliance isn’t a “go it alone” model and requires an understanding of the shared responsibility model, regardless of your CMMC compliance level. Rare is the company that does everything in-house without exception. 


 


Azure Blueprints 


Azure Blueprints enable customers to easily create, deploy, and update compliant environments and leverage the enormous Microsoft investment in data security and privacy. Microsoft invests more than USD 1 billion annually on cybersecurity research and development, employs more than 3,500 security experts entirely dedicated to your data security and privacy and Azure has more certifications than any other cloud provider. View the comprehensive list. 


 


Blueprints simplify largescale Azure deployments by packaging key environment artifacts, such as Azure Resource Manager templates, role-based access controls, and policies, in a single blueprint definition. Customers can easily apply the blueprint to new subscriptions and environments and fine-tune control and management through versioning. Specific to CMMC, blueprints present a tremendous advantage for customers who want to quickly address the majority of the CMMC Maturity Level 3 requirements. 


 


The NIST SP 800-171 R2 blueprint sample provides governance guard-rails using Azure Policy that help you assess specific NIST SP 800-171 R2 requirements or controls. This blueprint helps customers deploy a core set of policies for any Azure-deployed architecture that must implement NIST SP 800-171 R2 requirements or controls. As many readers know, approximately 85% of the CMMC Maturity Level 3 requirements are essentially the NIST SP 800-171 security requirements, so this blueprint can be a force for progress in your CMMC compliance efforts.  


  


Office 365 GCC High and DoD 


As many defense contractors already know, CMMC was, in part, created to address the security of CUI, and Microsoft has long been a partner with DoD working to protect this information. 


 


To meet the unique and evolving requirements of DoD and contractors holding or processing DoD controlled CUI or subject to International Traffic in Arms Regulations (ITAR), Microsoft offers GCC High and DoD environments. Microsoft GCC High and DoD meet the compliance requirements for the following certifications and accreditations: 



  • The Federal Risk and Authorization Management Program at FedRAMP High, including those security controls and control enhancements as outlined in the National Institute of Standards and Technology (NIST) Special Publication 800-53. 

  • The security controls and control enhancements for the United States Department of Defense Cloud Computing Security Requirements Guide (SRG) for information up to Impact Level 5 (L5). 


 


DoD Office 365 subscribers will receive services provided from the DoD exclusive environment that meets DoD SRG L5. Non-DoD subscribers will receive services from the U.S. Government Defense environment, which is assessed at L5, but has L4 equivalency. 


 


There is much debate and often confusion on whether CMMC requires GCC high, and it is one of many issues that highlight the need for a Managed Compliance Partner, but the point is that Microsoft has long been the partner of choice for the DoD in addressing this challenge. 


 


CMMC mandates minimum cybersecurity standards for 300,000 plus commercial defense contractors around the globe and makes compliance part of the acquisition process, preventing contract award until an independent third-party has verified compliance. Given the magnitude of this change and the revenue impacting consequences of non-compliance, we choose Microsoft for our CMMC Managed Services Customers. 


 


Additional information  


For additional information on Microsoft’s CMMC acceleration, join Microsoft’s Richard Wakeman, Senior Director of Aerospace & Defense for Azure Global, on November 18th at CMMC Con 2020.  Mr. Wakeman will host a Technology Spotlight session dedicated to discovering how Microsoft solutions are assisting the DIB in government compliance.   Visit www.cmmccon2020.com to learn more. 


 


 


About the Author


 


cybersheath_0-1605025345048.jpeg


 


 


Eric is Chief Executive Officer (CEO) for CyberSheath Services International, LLC (CyberSheath) and is a respected cybersecurity expert having testified before the House Armed Services Committee (HASC) Subcommittee on Emerging Threats and Capabilities and served on the Council on Cyber Security expert panel to review and update the Critical Security Controls. Prior to founding CyberSheath, Eric was the Global Chief Information Security Officer for BAE Systems plc, based in London. Concurrently Eric served as Vice President and General Manager of North American IT operations, overseeing engineering, architecture, and IT operations support for approximately 39,000 employees. Eric has an MBA from the University of Maryland and a B.S. with honors in Information Technology Management from Daniel Webster College. He holds numerous technical and professional certifications including Certified Information Systems Security Professional (CISSP) and Project Management Professional (PMP). 


 

SAP Releases November 2020 Security Updates

This article is contributed. See the original author and article here.

Original release date: November 10, 2020

SAP has released security updates to address vulnerabilities affecting multiple products. An attacker could exploit some of these vulnerabilities to take control of an affected system. These include missing authentication check vulnerabilities affecting SAP Solution Manager (JAVA stack).

The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the SAP Security Notes for November 2020 and apply the necessary updates.

This product is provided subject to this Notification and this Privacy & Use policy.

Why you should select an integrated platform for MarTech needs

Why you should select an integrated platform for MarTech needs

This article is contributed. See the original author and article here.

When building a marketing technology (MarTech) stack, both the best-in-breed and single vendor approaches have their benefits and drawbacks. Today’s business realities has marketing operations teams and business leaders re-examining the best way to get necessary tasks accomplished: “one-for-each” or “one-for-all”.

A changing landscape

Digital transformation is driving marketing leaders to make decisions between two competing approaches to building a marketing technology stack. On one side is best-of-breed, defined by Technopedia as “the best system in its referenced niche or category. Although it performs specialized functions better than an integrated system, this type of system is limited by its specialty area.” That second sentence contains the key appeal of best-of-breed (BoB), the belief that selecting individual vendors for essential functions delivers better performance than an integrated system. Many companies have bought into that view.

A survey of more than 300 marketing, sales, and advertising professionals by business-to-business (B2B) marketing agency Walker Sands reports that the best-of-breed strategy has been gaining popularity over the last decade and commands more than 40 percent of their respondents’ marketing stack. That tilt is in some ways caused by the BoB message that single-vendor solutions do not offer superior quality appsan assertion that is now being challenged.

The single-vendor solution

Today’s integrated enterprise solution is focused on the capabilities and usability of its apps, as well as the advantages of choosing a single vendor. Usually offered as a comprehensive, integrated software suite that uses one data mart, this approach provides the implementation, operational, and training advantages of single-source integration as well as features and capabilities of specific products that are competitive with a BoB offering. The question of whether the ease of use, capabilities, and business value of its individual products can equal the value of their best-of-breed counterparts is the key consideration when deciding which path to follow.

The power of the single-vendor shared platform

TPC Logistica Inteligente (TPC), one of the main logistics operators in Brazil, depends on a complex corporate sales process with cycles that last on average eight months and involve several areas of customers. When the company’s main need was the implementation of a robust customer relationship management (CRM) tool, after a detailed analysis of the main solutions on the market, TPC opted to implement Microsoft Dynamics 365 Marketing and Microsoft Dynamics 365 Sales, which share a common platform.

Following a thorough implementation plan presented by Microsoft and its partner Inove, TPC completed the adoption in less than two months. For a company that makes approximately three million deliveries a year, the implementation aspect of the product “was important and decisive,” says Silas Faria, Innovation Manager, TPC.

A semitruck with a white cab and blue container with T P C in white letters. The truck is emerging from a tunnel.

The speed and smoothness of the implementation was the beginning of fast-tracking impact of Dynamics 365 on TPC. With Dynamics 365 Marketing in operation, TPC was able to instantly start tracking mail and phone and qualify its customers. This breakthrough enabled TPC to improve customer relationships and increased the company’s visibility in its market.

With Dynamics 365 Marketing and Dynamics 365 Sales natively aligning with each other and the engineering advantage of an adaptable shared platform, TPC saw how it could readily integrate additional Microsoft solutions, creating, in effect, a “best-of-breed” solution that shared a common data model and the Dynamics 365 customer engagement platform. The best of both approaches.

Building out to build business

Choosing Dynamics 365 Marketing and Dynamics 365 Sales created opportunities to smoothly integrate additional Microsoft solutions as well as an array of ISV third-party solutions. TPC now feeds its data into Microsoft Power BI dashboards to acquire insights to support decision-making. The company used Microsoft Power Apps to create an application that combines business data with information on available storage space in its distribution centers.

For TPC Group, Dynamics 365 is a “best-of-the-best” solution. Dynamics 365 Marketing and Dynamics 365 Sales have transformed its understanding of its customers. Power BI and Power Apps improved how information is gathered, analyzed, and used to grow business. “We have gained speed, process quality, and strategic management,” observes Eduardo Leonel, Commercial and Marketing Director, TPC. All accomplished with the single-vendor Dynamics 365 solutions and platform. Further, TPC has an easy path to adding other Dynamics 365 applications for customer engagement, such as Microsoft Dynamics 365 Consumer Insights and Microsoft Dynamics 365 Customer Service.

The impact of choosing Dynamics 365 Marketing and Dynamics 365 Sales is impressive. TPC’s decision has triggered a significant increase in the company’s conversion rate: it added 16 new, highly-complex projects in 2019 compared to only two in the previous year.

Seeing the path forward clearly

The integrated solution promises quicker and smoother integration and deployment in a competitive business environment that doesn’t tolerate slow reactions or performance disruptions. And in the case of the Dynamics 365 solutions, it brings the same drive as a BoB company has to be the best in each product category.

Muddying the waters is the disruptive action of some larger single-vendor suite providers to augment their solutions by acquiring their BoB competitors. On the surface, this would appear to present a “best-of-both-worlds” option, but integration obstacles still exist within this hybrid approach, particularly in the challenge of seamlessly connecting applications that originated with different vendors.

While Dynamics 365 is a single-vendor solution that is easy to configure, use, and extend, it also offers BoB advantages. The Dynamics 365 applications are built upon an adaptable, expandable platform and a common data model that unifies data across all your business processes and enable interoperability among apps.

At the same time, each Dynamics 365 application teamincluding Dynamics 365 Marketing, Dynamics 365 Sales, Dynamics 365 Customer Insights, and Microsoft Dynamics 365 Financeis focused on engineering a best-of-breed level performance. For example, Dynamics 365 Marketing provides a powerful combination of marketing automation with events management, Dynamics 365 Customer Insights integration, a connector to LinkedIn, and AI-based capabilities. Aligned marketing and sales applications from Dynamics 365 can help companies understand customers better, collaborate remotely, optimize buying processes, and adapt to rapidly changing environment.

The choice for many companies, particularly those with ambitious growth plans, may be a single-vendor consistency that encompasses an array of best-of-breed products. Having to choose between the two alternative approaches could be a thing of the past.

Learn more

Learn more about how the combination of powerful, fully featured Dynamics 365 Marketing, Dynamics 365 Sales, and other Dynamics 365 solutions can meet these challenging times.

The post Why you should select an integrated platform for MarTech needs appeared first on Microsoft Dynamics 365 Blog.

Brought to you by Dr. Ware, Microsoft Office 365 Silver Partner, Charleston SC.

“Teamwork makes the dream work” – harnessing attention in the context of team collaboration

“Teamwork makes the dream work” – harnessing attention in the context of team collaboration

This article is contributed. See the original author and article here.

Co-authored by Claudia van der Velden, Emma Stephen, and Tony Crabbe

 


The workweek starts, your agenda looks tidy, you feel on top of your to do’s – you feel a sense of control. At the end of the day you look again and see tons of double bookings, meetings without an agenda, and no clarity on what is expected of you in that engagement. Do you find yourself wondering if colleagues make best use of your attention? Do you look at your diary with a sense that you own your time, or the reverse?



Our shift to teamwork, often on multiple teams, has driven some bad organizational habits¹. As our teams face multiple deadlines, working across multiple contexts, it can feel like a scramble for calendar space, focus time, and even a break.



As we often find ourselves in the above situation, instinctively we consider teamwork to be at the expense of our attention. But to become a high performing, innovative, and flourishing team, every team member’s attention is needed. So how can we harness attention at the team level?



It starts with our engagement in reaching a shared goal, learning from a diverse team, and building positive team relationships. To achieve great outcomes, team processes need to build on that engagement with a focus on trust, learning, team confidence, optimism, supportive leadership, and social support². Each section focuses on an aspect of teamwork from the foundation of purpose and connection through to collaboration and meetings. Tips and tricks throughout, following the MOCA framework, then outline how technology can support.



Team purpose and connection
Team engagement is the hook for attention in the team context. When the teams we work in have clarity on the team goals and we feel a sense of belonging, it’s easier to engage our attention.
The hybrid workplace has created an extra layer of complexity for creating clarity and belonging and employees report maintaining team cohesion as one of the top issues in the hybrid workplace³. To maintain this sense of purpose and connection, communication, open-mindedness, and clarity on who does what in contribution to which team goal are key. We need new ways of connecting.


1.png


 


Tips & Tricks:



  • Create a recurring Microsoft Teams call for three (3) hours which serves as an open ‘virtual co-working space’. This makes space for spontaneous conversations, while you are doing individual work and gives a sense that your work has purpose.

  • Schedule virtual coffee breaks, walking meetings, or ‘Happy Hours’ with your team. Check in on each other sometimes, even if nothing is scheduled.

  • Increase the internal network in your organization by enabling the Ice-breaker bot to connect random employees to have a virtual coffee together.

  • Be clear on intent, use Emoji’s, GIF’s and stickers to convey meaning and avoid misunderstandings which can lead to unnecessary worry.

  • Use Planner to organize team tasks that are meaningful chunks and can be completed by one person. Attach any documents, comments, or ideas to the task.



Collaboration rituals
Microsoft Teams have become the foundation of how most work gets done in today’s organizations with a 50% increase in collaboration in the last decade. What we can know, knowledge itself, is increasing and in organizations this is resulting in specialization. But the world is going in the other direction, becoming more networked and demanding more interconnected products and services. To develop these requires cross-domain expertise, placing the emphasis increasingly on teams and their performance as a crucial differentiator rather than the individual.



81% of us are multi-teaming – collaborating on more than one project, but how much of that time do we spend on discussing ‘How’ we collaborate? Are there collaboration rituals – clear rules of engagement – that create clarity on where we collaborate, working out loud, and when and about what we meet.



Tips & Tricks:



  • Set up a governance model for your Microsoft Teams environment, with a content architecture upfront to discuss which topics are discussed where.

  • Discuss where updates are posted, for instance in the General channel, and what the goal is of each channel in Microsoft Teams.

  • Use Group chat for quick questions and fun discussions.

  • Have a 5-minute learning review at the end of each meeting: What did we do well as a team? What could we do better?

  • Discuss people’s work rhythms, no-go times, and respect focus time. Why not try a hybrid work kick-off to get the discussion going and agree how you will work and connect?

  • Collaborate asynchronously using comments in documents and chat so people can contribute when they are at their best and have time. Meet to resolve the comments and discuss ideas.


 


Meeting effectiveness
We’ve seen an increase in meetings especially now in the hybrid workplace and as we craft this new virtual reality, it creates a great momentum to redefine the meeting culture in your organization.



At Microsoft, we took this the new hybrid reality as a chance to better understand how we meet. Workplace Analytics showed that weekly meetings increased 10%, which most likely replaced the ‘catch up meetings’ in the hallway, however the individual meetings shrank in duration. The 30 minute or less meeting increased with 22 percent and 11 percent fewer meetings of more than one hour.



How do you prepare for your meeting, how do you manage discussions, process ideas and take notes during the meetings and how do you follow up on meetings?


2.png


 


Before the meeting
To organize your team meetings, use the meeting chat window to publish the agenda, co-create the presentation, share the pre-reads, and include everyone to give input and feedback upfront. Appoint the meeting roles, note taker, parking guardian and the host (a role similar to a party host¹⁰), to ensure ideas are heard, learnings are captured, and actions can be followed up.


3.png


 


During the meeting


With a well-prepared agenda and pre-reads, use the white board functionality during the meeting for brainstorming to unlock creativity. Use a team OneNote to take digital notes in a pre-defined structure. Co-author in documents to create content in the Office Apps, which enables asynchronous work scenarios, making the best of use of everyone’s time and respecting everyone’s pace and schedule.


4.png


 


After the meeting
At the end of the meeting the tasks are divided within Planner, so everyone is aware of their follow up actions, and it is easy to track progress for the team activities. The meeting notes + Planner form the basis for the next meeting to make sure all topics are handled, and the decisions have been taken.


 


GO DO’s



  1. Analyze your meeting rhythm in your team and in your project teams, evaluate which meetings are necessary and check if they have a clear agenda and expectation. If not, be the one to start the change!

  2. Apply the “Before, During & After” process to improve your meetings and to make them more effective and more structured.

  3. Look at your Microsoft Teams environment and see how you can make this richer by integrating Whiteboard, OneNote, Planner, Power apps, and all the great apps available to really create that one-stop shop workplace

  4. Explore roadmap items for Microsoft Teams that can make your virtual meetings more inclusive to increase engagement in the meeting.


 



  1. The Overcommitted Organisation, Mark Mortensen and Heidi K. Gardner, HBR Sept-Oct 2017

  2. Dream Teams: A Positive Psychology of Team Working, Joanne Richardson and Michael A. West. Chapter 19, The Oxford Handbook of Positive Psychology at Work, Oxford University Press 2013

  3. The journey to the new normal – Driving innovation and productivity in a hybrid world

  4. We Work Harder When We Know Someone is Watching, Janina Steinmetz and Ayelet Fishbach, HBR May 2020

  5. Avoiding Miscommunication in a Digital World, Nick Morgan for HBR IdeaCast, Episode 655

  6. Harvard Business Review Analytic Services Report (2019) Meeting the challenges of developing collaborative teams for future success.

  7. Stefan Wuchty, Benjamin Jones and Brian Uzzi (2007) The increasing dominance of teams in production of knowledge. Science, Vol. 316, Issue 5827, pp. 1036-1039

  8. The Overcommitted Organisation, Mark Mortensen and Heidi K. Gardner, HBR Sept-Oct 2017

  9. Adjusting to Remote Work During the Coronavirus Crisis,

  10. Why Meetings Go Wrong (And How to Fix Them), Steven Rogelberg for HBR IdeaCast, Episode 708


 


This blog post is a part of our series on the Modern Collaboration Architecture, developed by @Rishi Nicolai, a Microsoft Digital Strategist with over 25 years of experience in leading organizations through change and improving employee productivity. Blogs one, two, and three can be found under these links.


 


About the authors:


Claudia van der Velden
Claudia a Customer Success Manager at Microsoft and enjoys exploring organizational cultures from an eco-system perspective. In a complex puzzle where all is interconnected, small changes can have a large impact. She believes in the importance of considering all elements for the eco-system to thrive, stay well balanced, and perhaps most importantly, letting go of control and trusting the natural course to find its way. Claudia is based in the Netherlands and studies for her Masters in Applied Psychology, Leadership Development.


 


Emma Stephen
Emma is a Customer Success Manager at Microsoft and is passionate about bringing the human element into the workplace. She believes technology both enables change and can catalyze wider change efforts if introduced in the right way. Emma is based in Zurich and currently studying for her Masters in Applied Positive Psychology and Coaching Psychology with a hope to leverage this in the organizational context.


 


Tony Crabbe
Tony Crabbe is a Business Psychologist who supports Microsoft on global projects as well as a number of other multinationals. As a psychologist he focuses on how people think, feel and behave at work. Whether working with leaders, teams or organizations, at its core his work is all about harnessing attention to create behavioral change.

His first book, the international best-seller ’Busy’ was published around the world and translated to thirteen languages. In 2016 it was listed as being in the top 3 leadership books, globally. His new book, ‘Busy@Home’ explores how to thrive through the uncertainties and challenges of Covid; and move positively into the hybrid world.

Tony is a regular media commentator around the world, as well as appearances on RTL, the BBC and the Oprah Winfrey Network.


 

Mozilla Releases Security Updates for Firefox, Firefox ESR, and Thunderbird

This article is contributed. See the original author and article here.

Original release date: November 10, 2020

Mozilla has released security updates to address a vulnerability in Firefox, Firefox ESR, and Thunderbird. An attacker could exploit this vulnerability to take control of an affected system.

The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the Mozilla Security Advisory for Firefox 82.0.3, Firefox ESR 78.4.1, and Thunderbird 78.4.2 and apply the necessary updates.

This product is provided subject to this Notification and this Privacy & Use policy.

New Sentry Connector for Microsoft Teams

New Sentry Connector for Microsoft Teams

This article is contributed. See the original author and article here.

Millions of people use Microsoft Teams to be productive across different workstreams, and the latest Sentry app in Microsoft Teams is here to keep you up to speed on emerging alerts and issues in your DevOps environment.



Sentry Connector in Microsoft Teams
Using rule-based configurations, the Sentry app in Microsoft Teams will automatically notify pre-defined channels of code errors, performance issues, or other events. Rule-based configurations allow customers flexibility in customizing which alerts generate notifications in Teams. Users can respond to the alert by ignoring, assigning, or resolving directly from Teams; they can also use channel messages and mentions to collaborate with others on response and next steps.


Sentry.png


 


How to use Sentry in Teams
Integrating Sentry into Teams for your DevOps practices takes two steps: install and configure. See Sentry’s step-by-step documentation for full details and instructions.



If you’re currently using the legacy Sentry integration, consider moving your notification configurations to use the latest integration.

New Dynamics 365 learning paths: October 2020 roundup

This article is contributed. See the original author and article here.

New role-based learning paths are being released every month on Microsoft Learn to help you build skills and prepare for a Microsoft Certification. Whether you’re beginning or continuing your skilling journey, take a moment to browse the learning paths that became available in October 2020. You can work through this free, online, modular training at your own pace. Choose a learning path and start it today. Before you know it, you’ll have a new set of skills you can demonstrate to employers or colleagues. Want help figuring out where to begin and which training to take when? Check out the landing page for Dynamics 365.


 


The following learning paths were released in October 2020. 


 


FastTrack for Dynamics 365


 
















Learning path



Role



Certification



Use Success by Design for Customer engagement apps solutions


Four modules (seven additional modules to be added by November 14)



Solution architect, functional consultant 



Not currently part of an exam



 


Business Central


  





















Learning path



Role



Certification



Use Power BI in Microsoft Dynamics 365 Business Central


Three modules



Developer, functional consultant 



Not currently part of an exam



Develop using Power Apps and Power Automate for Dynamics 365 Business Central


Five modules



Developer, functional consultant 



Not currently part of an exam



 


Guides


 
















Learning path



Role



Certification



Work with Dynamics 365 Guides


Three modules (one additional module about how to author guides to be published in November)



Functional consultant, business user, solution architect, administrator



Not currently part of an exam



 


 


Microsoft Cloud for Healthcare


 
















Module



Role



Certification



Get started with Microsoft Cloud for Healthcare solutions powered by Dynamics 365



Functional consultant, business user, app maker



Not currently part of an exam


“IT for the SMB” ? – The Intrazone podcast

“IT for the SMB” ? – The Intrazone podcast

This article is contributed. See the original author and article here.

It’s not easy to manage and maintain technology. And many small and medium business make do with a patchwork of services or defer investments altogether. Well, hold the Teams call? Microsoft 365 Business is the IT for SMB, built to deliver the tools and security businesses need in a single, simple-to-manage product. The outcome, a means to run and grow business.


 


In this episode, Chris and I talk with Jon Orton, Director of Microsoft 365 marketing focused on our small and medium business outreach. Throughout the discussion, we talk with Jon about the strains of COVID-19, offers from Microsoft to help ease change, and recent innovation for small and medium-sized businesses with up to 300 employees.


 


Listen to podcast inline below


 


https://html5-player.libsyn.com/embed/episode/id/16742972/height/90/theme/custom/thumbnail/yes/direction/backward/render-playlist/no/custom-color/247bc1/


 


Subscribe to The Intrazone podcast! And listen to episode 58 now + show links and more below.


 


Intrazone guest – Jon Orton (Director of Microsoft 365 marketing focused on our small and medium business outreach).Intrazone guest – Jon Orton (Director of Microsoft 365 marketing focused on our small and medium business outreach).


Links to important on-demand recordings and articles mentioned in this episode:  





 


Subscribe today!


Listen to the show! If you like what you hear, we’d love for you to Subscribe, Rate and Review it on iTunes or wherever you get your podcasts.


Be sure to visit our show page to hear all the episodes, access the show notes, and get bonus content. And stay connected to the SharePoint community blog where we’ll share more information per episode, guest insights, and take any questions from our listeners and SharePoint users (TheIntrazone@microsoft.com). We, too, welcome your ideas for future episodes topics and segments. Keep the discussion going in comments below; we’re hear to listen and grow.


 


Subscribe to The Intrazone podcast! And listen to episode 58 now.


 


Thanks for listening!


The SharePoint and Power Platform teams wants you to unleash your magic, creativity, and productivity. And we will do this, together, in small and medium steps at a time.



The Intrazone links



+ Listen to other Microsoft podcasts at aka.ms/microsoft/podcasts.


 


Left to right [The Intrazone co-hosts]: Chris McNulty, director (SharePoint, #ProjectCortex – Microsoft) and Mark Kashman, senior product manager (SharePoint – Microsoft).Left to right [The Intrazone co-hosts]: Chris McNulty, director (SharePoint, #ProjectCortex – Microsoft) and Mark Kashman, senior product manager (SharePoint – Microsoft).


The Intrazone, a show about the Microsoft 365 intelligent intranet (aka.ms/TheIntrazone)The Intrazone, a show about the Microsoft 365 intelligent intranet (aka.ms/TheIntrazone)