S33D Technology
S33D
Technology | Engineering | Consulting
When you had the experts at S33D prepare you for your CMMC assessment.
CMMc is here to stay and so are the bad guys. Protect your data and feel prepared going into your assessment.
05/05/2025
๐ก Did you know: The DoD publicly published a configuration guide to Microsoft Entra. Link in the Comments
The Defense Information Systems Agency (DISA) released, in February 2025, their first revision of their Microsoft Entra ID Security Technical Implementation Guide (STIG). Is it fantastic and will solve all of your problems? No. But it does push out some basic items that can secure your organization.
As is typical, they included the NIST SP 800-53 revision 4 and revision 5 references. These are great for everyone that need a reference of how to do something, and you don't know where to start for your CMMC/NIST compliance program.
STIGs are great resources that someone that is advanced and someone that is a novice can benefit from. Just like CIS Benchmarks.
Happy compliance. Reach out if you want to implement this or other security configurations in your organization and just need someone to speak to you about it before you start clicking buttons and brick a computer.
04/25/2025
๐๐๐ผ๐ ๐ง๐ผ: Managing App Protection Policies for Unmanaged Devices in Microsoft Intune
If youโre setting up an App Protection Policy (MAM) in Intune and want it to apply only to unmanaged devices (think personal phones or laptops that access corporate apps like Outlook, Teams, or OneDrive), youโll notice that the old method of selecting 'Unmanaged Devices Only' is no longer available.
๐ Instead, Microsoft now requires you to:
Set Target to apps on all device types = Yes (๐ฏ๐ฐ ๐ธ๐ข๐บ ๐ข๐ณ๐ฐ๐ถ๐ฏ๐ฅ ๐ต๐ฉ๐ช๐ด).
Create and assign a MAM Assignment Filter where:
๐ฑ๏ธ Property: deviceTrustType
๐ฑ๏ธ Operator: Equals
๐ฑ๏ธ Value: Azure AD registered
โ
Azure AD registered devices are typically personal BYOD devices, not fully managed corporate assets.
By filtering this way, you can tightly control which apps and devices are protected โ without over-enforcing restrictions on corporate-managed devices that already meet compliance standards.
Key takeaway:
Donโt look for โ๐๐ฆ๐ท๐ช๐ค๐ฆ ๐๐ข๐ฏ๐ข๐จ๐ฆ๐ฎ๐ฆ๐ฏ๐ต ๐๐บ๐ฑ๐ฆโ when filtering MAM policies anymore โ use Device Trust Type and target Azure AD registered devices instead.
Security is constantly evolving, and small changes like this have a big impact when you're scaling secure access in hybrid environments.
Click here to claim your Sponsored Listing.
Category
Website
Address
10 E North Ave
Baltimore, MD
21202