Srinivas L
Technology Specialist – Security | Microsoft
Srinivas.L@microsoft.com
Agenda
• Business and IT Challenges
• Business Ready Security
• Secure Messaging
• Customer Testimonial
• The Road Ahead
• Solution Resources and Tools
• Summary
Business Needs and IT Challenges
Secure access to messaging
from virtually anywhere
Multiple locations and devices
Prevent sensitive information
from leaking
Difficulty in discovering and
securing sensitive information
Protection from advanced
threats
Financially motivated evolving
threats
Receive messaging free of
spam
Advanced spam technologies
bypassing scanners
BUSINESS Needs
Agility and Flexibility
IT Needs
Control
Business Ready Security
Help securely enable business by managing risk and empowering people
Protect everywhere,
access anywhere
Identity
Simplify the security
experience,
manage compliance
Highly Secure & Interoperable Platform
Integrate and extend
security across the
enterprise
from:
Block
Cost
Siloed
to:
Enable
Value
Seamless
Business Ready Security Solutions
Integrated Security
Secure Messaging
Secure Collaboration
Secure Endpoint
Information Protection
Identity and Access Management
Secure Messaging
Enable more secure business communication from virtually any location or device,
while preventing unauthorized use of confidential information
PROTECT everywhere
ACCESS anywhere
INTEGRATE and
EXTEND security
SIMPLIFY security,
MANAGE compliance
• Best-in-class anti-malware
on premises / in cloud
•
Built-in Information
Protection
•
Enterprise-wide visibility
and reporting
• Protect sensitive
information in email
•
Extend secure email with
partners
•
Unified management
• Provide more secure,
always-on access
Protect Messages from Malware
Single Engine
Multiple Engines
38 times faster
An AV-Test of consumer antivirus products
Automatic Engine Updates
revealed:
• On average, Forefront engine sets
provided
a response
in 3.1
or
On
premises
or in
thehours
cloud
less.
• Single-engine vendors provided
responses
in 5 days,
4 days, and 6 days
99% spam
detection*
respectively.
* With premium antispam services
“Forefront Security for Exchange Server can support up to five scanning engines at the same time. Thus, it
offers a more secure environment, compared with products that support using only a single engine.”
– Akihiro Shiotani, Deputy Director of the Infrastructure Group, Astellas Pharma Information Systems Department
Protect Sensitive Information in E-mail
• Automatically protect sensitive
e-mail with Active Directory
RMS
• Filter message body and subject
based on content criteria
• Policy based restricted usage of
email attachments
Outlook Web
Access
Provide More Secure, Anywhere Access
• Simplified always on access
• Consolidated secure portal to
simplify remote access
• Restricted, policy-based access
to messaging servers
“
Deep Integration with Exchange
• Information protection built-into and
managed within Exchange
• Automatically decrypt protected e-
mail for virus scanning and e-discovery
• Unique in-memory malware scanning
to optimize Exchange performance
Simplify Security Management
• Unified policy management for all
messaging servers
• Enterprise-wide visibility through a
centralized security console
• Easy investigation process with
automatic data collection
• Enable compliance with detailed log
analysis and easy-to-use reports
Current Situation
Multiple Products for secure messaging
Virus threats from internal senders
Separate SMTP virus scanner
to detect and remove spam
and malware
Spam Spam
Spam Spam Spam
External websites sending
spam and malware
Remote access solution w/
separate identities
Separate gateway to detect
sensitive content
Separate gateway to enable
remote access
Internal users sending
sensitive information to
partners in email
Secure Messaging
Simple and easy
Internal mail protected with
Forefront Protection for Exchange
Always-on access built into
platform
Malware and spam cleaning
in the cloud with FOPE
Information Protection built
into the platform
Customer Testimonial
“With Forefront Security for Exchange Server, our
comfort level is higher because the mail server and the
security product are tightly integrated, and they’re both
offered by the same vendor.”
Akihiro Shiotani | Section Chief of the Infrastructure Group
Astellas Pharma Information Systems Department
CUSTOMER BUSINESS
CHALLENGE
• Managing security
solutions from multiple
vendors
• Allowing employees to
exchange e-mail from
outside the office more
easily
• Improving monitoring
and reporting capabilities
CUSTOMER
SOLUTION
• Microsoft Forefront line
of business security
products
• Microsoft System Center
family of IT management
solutions
CUSTOMER
RESULTS/BENEFITS
• Improved security and
reliability
• Simplified deployment,
monitoring, and reporting
• Increased user and IT
productivity
• Simplified publishing and
pre-authenticated access
to the servers
Secure Messaging – The Road Ahead
Management Consoles
Solution Resources & Tools
Hands-on Labs and VMs
Evaluation Guides
Proof of Concepts
Architecture, Planning and
Design Guides
Infrastructure Planning
Guide
Data Protection Using Rights
Management Services
Operations Guides
Administrator Guides
Troubleshooting Guides
Secure Remote Application
Publishing Services
Application Server Protection
Secure Messaging
Enable more secure business communication from virtually any location or device,
while preventing unauthorized use of confidential information
PROTECT everywhere
ACCESS anywhere
INTEGRATE and
EXTEND security
SIMPLIFY security,
MANAGE compliance
• Best-in-class anti-malware
on premises / in cloud
•
Built-in Information
Protection
•
Enterprise-wide visibility
and reporting
• Protect sensitive
information in email
•
Extend secure email with
partners
•
Unified management
• Provide more secure,
always-on access
Learn more at: www.microsoft.com/forefront
© 2007 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries.
The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market
conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation.
MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
© 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be
registered trademarks and/or trademarks in the U.S. and/or other countries.
The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of
this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a
commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of
this presentation.
MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Better Together Protection
Integrated Defense in Depth
Exchange 2010
Encryption
Default Intra-Org
∙
Inter-Org mTLS
support
∙
IRM support
Forefront
Anti-Spam
Anti-Virus
Premium
Multiple
Engine AntiMalware
Detection
Unified Management
Hosted, Hybrid Protection
Premium Anti-Spam
Functional Highlights
Exchange
2010
Connection
Filtering
Content
Filtering
Benefits
Forefront DNS Block
List
• Aggregates DNS data from multiple providers
• No configuration required
Unified management
• Consolidates Sender/Recipient/Sender ID filtering for
simplified management
Anti-Backscatter
• Blocks NDR backscatter spam
Cloudmark Filter
• Option of alternative 3rd party content filter
• 99% detection rate; 0.04% false positive
• No configuration required
Forefront True File Type
Filtering
• Inspects the real file type, not just extension
• Can also spot and delete files within ZIP
Global Exception Lists
• Single access point to sender and recipient exception
lists (allow and block actions)
Streamlined SCL
• Less ambiguous ratings for less false positives
Forefront Unified Management
Protocol
Filtering
+ Forefront