Tags: cloud* + entreprise* + cybersécurité*

21 signet(s) - Classer par : Date ↓ / Titre / Vote /

  1. by default, user consent is permitted for all enterprise users. There are a few permissions that require the consent of an Administrator, but by default the user can give any 3rd party (friendly, hostile or malicious) full read-write permissions to most of the data he can reach in Office365. draw.io could abuse the user consent to copy all the users files down to to their webservers if they saw a benefit in doing so.

    A web app can ask for permissions to read-write OneDrive, SharePoint, Mail, Calendar, Contacts, Teams etc, and get offline-access. That means, that whenever the web app wants, it can access these services by using an access token that was handed over to it, by Microsoft, as a result of the user logon and consent. It can even ask for a list of all user identities in the directory, including all those secret Admin accounts with no email address.
    https://securityintheenterprise.blogs...rosoft-azuread-and-office365-not.html
    Vote 0
  2. -
    https://www.usinenouvelle.com/article...-leur-migration-vers-le-cloud.N894684
    Vote 0
  3. -
    https://www.zdnet.fr/actualites/le-cl...Echobox=1568779722#Echobox=1568779722
    Vote 0
  4. -
    https://www.zdnet.fr/actualites/du-mu...egal-les-pieges-a-eviter-39880945.htm
    Vote 0
  5. « Il y a une véritable prise de conscience autour de la souveraineté de la donnée. Les entreprises savent qu’il ne suffit plus de dire que les données sont localisées en France, ou en Europe. »
    https://www.lemagit.fr/actualites/252...-des-groupes-francais-sont-preoccupes
    Vote 0
  6. -
    https://www.silicon.fr/le-cloud-fait-...proportions-insoupconnees-207393.html
    Vote 0
  7. -
    https://www.techniques-ingenieur.fr/a...ite/articles/linux-informatique-48848
    Vote 0
  8. -
    http://www.itpro.fr/n/wifi-un-vrai-ri...-22048/#sthash.yTYR7tg4.USqWKds4.uxfs
    Vote 0

Haut de page

Première / Précédent / Suivant / Dernière / Page 2 de 3 Marque-pages / ESPITALLIER.NET: tagged with "cloud+entreprise+cybersécurité"

À propos - Propulsé par SemanticScuttle