LevelBlue Completes Acquisition of Cybereason. Learn more
Get access to immediate incident response assistance.
Get access to immediate incident response assistance.
LevelBlue Completes Acquisition of Cybereason. Learn more
Being conscientious of SharePoint security is simple if you understand the basics. SharePoint is a Microsoft platform which is designed to integrate with Microsoft Office. Microsoft launched the product in 2001. SharePoint is useful for thousands of organizations worldwide because it facilitates sharing documents on private web servers.
SharePoint can be purchased as a separate product to deploy on your own intranet web servers, or you can use SharePoint Online as a component of many Office 365 packages. SharePoint Online is hosted on Microsoft’s own servers.. But poorly secured web servers and web applications can make organizations vulnerable to cyber-attack. Some of a company’s documents that are distributed through SharePoint may contain sensitive or proprietary information, and you don’t want them to fall into the hands of cyber attackers who could be either internal or external to your network! This quick guide will show you how to use and deploy SharePoint in a secure way so your organization can enjoy the convenience and functionality of SharePoint without introducing vulnerabilities to your corporate network.
There are various different types of permissions you can grant users in your SharePoint system.
With SharePoint security in mind, permissions can be granted to SharePoint users in a similar way that permissions are granted to Windows users. You can think about site collections being equivalent to volumes, sites being equivalent to folders, and documents being equivalent to individual files if you’re used to using Active Directory to administer NTFS permissions within your organization. Permission inheritance works according to that hierarchy. So for example, if you grant a user an Edit permission to a site collection, by default they also may edit within each site within the collection and all of the documents in all of those sites.
When it comes to SharePoint permissions and Office 365 security best practices, the key is to apply the cybersecurity concept of least privilege. That means that any user should only have the permissions that they require in order to do their jobs and no more. Only a limited number of users should have administrative access to any entity of your SharePoint site collection, and those users should be watched very carefully.
External sharing from your SharePoint sites should also be limited only to a select few users who are external to your network for the sake of better SharePoint security. Those external users should also only be able to access your SharePoint sites through a VPN in order to protect the overall security of your internal network from the public internet.
Within your SharePoint administration settings, you can edit authentication methods for all possible users. You can be very careful about which users and groups you grant which permissions to, but all of that work is pointless if you don’t have an effective way to authenticate users on your SharePoint web application.
It’s possible to allow users to have anonymous access to your SharePoint sites. The best practice is to disable anonymous access altogether because it makes it more difficult for security administrators to monitor your site’s security. Ideally administrators should know who all of the users are and be able to make all users accountable for their actions. That way, external cyber-attacks can be discovered more easily, and internal cyber-attacks can be traced to a specific user.
SharePoint sites in internal networks are run within Microsoft IIS web servers. Therefore, the best practice is to enable IIS authentication settings, which should be set to use Kerberos to encrypt authentication data. It’s possible to enable basic authentication, which sends passwords in cleartext. Don’t enable that feature; passwords should never be transmitted in cleartext anywhere in your network! While arguably difficult in many situations, Man-in-the-middle attacks are still one of the biggest cybersecurity issues - so the best practice is for all data transmitted in your network to be encrypted.
Keeping these simple user permission and authentication tips in mind are crucial to deploying SharePoint in a secure manner.
LevelBlue is a globally recognized cybersecurity leader that reduces cyber risk and fortifies organizations against disruptive and damaging cyber threats. Our comprehensive offensive and defensive cybersecurity portfolio detects what others cannot, responds with greater speed and effectiveness, optimizes client investment, and improves security resilience. Learn more about us.