Cross-tenant access focusing
By implementing GDAP-integrated security mechanisms in a cloud computing environment, monitoring and tracking cross-tenant access policies and role assignments, the problems of authorization scope expansion and fraudulent access in cross-tenant access are resolved, improving security and incident response efficiency.
Patent Information
- Application Number
- CN202480047384.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-11-24
- Filing Date
- 2024-10-21
- Publication Date
- 2026-02-13
AI Technical Summary
In cloud computing environments, security issues arising from cross-tenant access include the extension of authorized access to unauthorized access, the accidental closure or obstruction of authorized access, and the difficulty in detecting fraudulent roles and unexpected policy changes, leading to an increased risk of security incidents.
Implement a security mechanism that integrates Granular Delegated Management Privileges (GDAP) to ensure the security and controllability of authorized access by monitoring and tracking non-barrier access policies and cross-tenant role assignments, combined with auditing and access constraint mechanisms.
It effectively mitigates the impact of accidental or covert policy changes on cross-tenant access, detects and prevents fraudulent roles, improves the efficiency and speed of security incident investigations and response, and reduces the risk of unintentional interference with business-critical assets.
Smart Images

Figure CN121532767A_ABST
Abstract
Description
Background Technology
[0001] Attacks on computing systems can take many different forms, including some that are difficult to predict and can vary depending on the circumstances. Therefore, one of the guiding principles of cybersecurity is "defense in depth." In practice, defense in depth typically involves forcing attackers to encounter a variety of different security mechanisms at multiple different locations around or within the computing system. No single security mechanism can detect every cyberattack, determine the scope of an attack or vulnerability, or terminate every detected cyberattack. However, sometimes combining and layering a sufficient number and variety of defensive and investigative tools can prevent attacks, deter attackers, or at least help limit the scope of damage from attacks or vulnerabilities.
[0002] To achieve defense in depth, cybersecurity professionals consider the different types of attacks targeting computing systems and the various vulnerabilities the system may contain. They select defenses based on criteria such as: which attacks are most likely to occur, which attacks are most likely to succeed, which attacks, if successful, are most harmful, which defenses are in place, which defenses can be in place, and the costs, process changes, and training involved in implementing specific defenses or removing specific attack vulnerabilities. They investigate the scope of attacks and attempt to detect vulnerabilities before they are used in attacks. Some defenses or investigations may be impractical or not cost-effective for a particular computing system. However, improvements to cybersecurity are still possible and worth pursuing. Summary of the Invention
[0003] Some embodiments address the technical challenges arising from the possibility of authorizing user commands in one cloud tenant to execute operations in another cloud tenant. For example, secure cross-tenant access presents several challenges, such as how to technically constrain access to authorized scopes and how to technically prevent or mitigate attempts to impede authorized access. Sometimes, the operations performed involve cybersecurity, such as operations to reduce the attack surface, remove security vulnerabilities, or investigate security incidents. However, the teachings of this document are not limited to cross-tenant cybersecurity operations.
[0004] In some embodiments, the security mechanisms integrated with Granular Delegated Management Privileges (GDAP) focus on a specific tenant, one or more specific asset exclusions, one or more specific product-specific roles, or a combination thereof.
[0005] Other technical the activities and features related to the teachings herein will be apparent to those of ordinary skill in the art upon reviewing the present disclosure. The examples given are only illustrative. The summary is neither intended to identify key or essential features of the claimed subject matter, nor is it intended to be used in limiting the scope of the claimed subject matter. Rather, the purpose of the summary is to present some concepts of the technology in a simplified form as a prelude to the more detailed description of some technical concepts presented in the detailed description. The subject matter scope is defined by the claims taken in their proper context and full complement of equivalents, and in case of conflict between the summary and the claims, the claims control. BRIEF DESCRIPTION OF DRAWINGS
[0006] A more particular description will be rendered by reference to the appended drawings. These drawings are not fully to scale, as that would mislead no one skilled in the art. Rather, the drawings demonstrate selected aspects of the present technology and are therefore not to be considered limiting of its scope or range.
[0007] Figure 1 is a diagram showing aspects of a computer system and also showing a configured storage medium, including some aspects of a system generally suitable for providing secure cross-tenant access (SCTA) functionality; Figure 2 is a block diagram showing an enhanced system configured with SCTA functionality; Figure 3 is a block diagram showing aspects of a system enhanced with SCTA functionality; Figure 4 is a block diagram showing some additional aspects of a tenant; Figure 5 is a dataflow diagram showing aspects of some SCTA functionality; Figure 6 is a flow diagram showing steps in a method of secure cross-tenant access; Figure 7 is a flow diagram further showing steps in some methods of secure cross-tenant access and in connection with Figure 6 and Figure 5 ; Figure 8 is an architectural dataflow diagram showing a focused tenant (e.g., customer) architecture for defining asset exclusions; Figure 9 is an architectural dataflow diagram showing an assistant tenant (e.g., home) architecture for implementing asset exclusions; Figure 10 is an architectural dataflow diagram showing an architecture for establishing and using workload rules for role-based access control; Figure 11 is a dataflow diagram showing an architecture for establishing cross-tenant role assignments; Figure 12 is a dataflow diagram showing the obtaining and implementation of access control rules based on product-specific roles in an architecture; Figure 13 is a flow diagram further illustrating steps in a method for secure cross-tenant access utilizing asset exclusion groups; and Figure 14 is a flow diagram further illustrating steps in a method for secure cross-tenant access utilizing product-specific roles. DETAILED DESCRIPTION
[0008] SUMMARY Some of the teachings described herein are inspired by technical challenges faced during efforts to improve techniques for allowing network security experts to perform security operations in computing systems. In particular, challenges are faced during efforts to securely improve access for hosting service personnel, such as technicians, security operators, and information technology operators, to log into customer tenants to address and remediate issues in customer tenants, while maintaining the security and integrity of the customers' environments.
[0009] Multi-tenant cloud architectures allow multiple tenants to share computing resources in a public cloud, hybrid cloud, or private cloud. A tenant is a cloud computing construct at a level between users and the entire cloud. A given tenant typically has more than one user account. Cross-tenant access raises security issues in many cloud computing environments, so that users in one tenant do not automatically or easily receive access to user data, settings, hardware, applications, logs, and other resources in different tenants. One security issue is that access can be extended beyond authorized scope, and another security issue is that access can be shut down or blocked despite being authorized. These and other issues are some of the motivations for the present disclosure, but the teachings herein are not limited in scope or applicability to the particular motivating challenges.
[0010] Some embodiments described herein utilize or provide network security methods for secure cross-tenant access, including monitoring a non-hinder condition access policy focused on a tenant, the monitoring including checking for a hinder change in the non-hinder condition access policy, the monitoring further including checking for an addition of a hinder condition access policy, where the hinder change is a change in a hinder from a user of an assistant tenant to authorized access to the focused tenant, and the hinder condition access policy is a condition access policy that hinders authorized access to the focused tenant from the user of the assistant tenant.
[0011] In these embodiments, the policy monitoring function has the technical benefit of mitigating against accidental or surreptitious policy changes that would shut down or hinder authorized cross-tenant access. In some scenarios, the assistant tenant user activity is controlled by security experts working for a cloud service provider, the focused tenant is a customer tenant of the cloud service provider, and the cross-tenant access is authorized by a customer administrator in order to improve security of the customer tenant or investigate a security incident in the customer tenant, or both. The policy monitoring function makes it more difficult for an attacker to use access policy changes to prevent the customer tenant from receiving expert security assistance.
[0012] Some embodiments described herein utilize or provide a cyber-security method for secure cross-tenant access, including tracking cross-tenant role assignments focused on a tenant, the tracking including examining cross-tenant role assignments for changes to cross-tenant role assignments. This role monitoring function has the technical benefit of mitigating accidental or surreptitious role changes that would shut down or impede authorized cross-tenant access. Further, in some embodiments, the tracking includes detecting fraudulent roles. Authorized cross-tenant access is not necessarily impeded by fraudulent roles, but an attacker has exploited the authorized access to surreptitiously add additional roles that the customer did not consent to. Without detection of the fraudulent role, the attacker can later use the fraudulent role to maliciously access the customer tenant.
[0013] Some embodiments described herein utilize or provide a cyber-security method for secure cross-tenant access, including correlating focus tenant audits with assistant tenant audits, thereby producing correlated audits of user activity in the focus tenant and user activity in the assistant tenant. This audit correlation function has the technical benefit of allowing assistant tenant users to detect deviations from the set of operations authorized by the customer, and also has the technical benefit of demonstrating that assistant tenant users do or do not perform particular operations.
[0014] For example, in some scenarios, a customer tenant administrator approves access for a security investigator, and warns that the access is limited to the investigation event, and that the investigator will not make any changes to the customer tenant security controls during the access. The correlated audits link the security investigator’s access request, the administrator’s response granting the access without change warning, the security investigator’s login to the customer tenant and activity during the access, the security investigator’s logout from the customer tenant, and the subsequent revocation of the access authorization. The correlated audits can thus be used to answer questions such as whether the security investigator changed any security controls, how the administrator described the purpose of the access authorization, and whether the security investigator was logged in when the security controls were changed if no security control changes are demonstrated in the logs.
[0015] Some embodiments described herein utilize or provide a cyber-security method for secure cross-tenant access, including receiving a command from a user in a focus tenant, where the command is in at least one of the following command categories: a security investigation command, a security modification command, or a managed service command. This command function has the technical benefit of extending secure cross-tenant access to include any managed service command in addition to or instead of security commands. For example, to install or perform adjustments to a particular service, a security access can be granted to a government regulator, a court-appointed expert, a SaaS vendor, or a review consultant.
[0016] Some embodiments described herein utilize or provide network security methods for secure cross-tenant access, including receiving a constraint of authorized access by users from an assistant tenant to a focus tenant to be only via logins from authorized managed devices. Additionally or alternatively, some embodiments constrain authorized access by users from an assistant tenant to a focus tenant to be only via logins from a specific IP address range. This access constraint functionality has the technical benefit of making authorized cross-tenant access even more secure. In some embodiments, it is an optional supplement to, rather than a replacement for, the monitoring, tracking, detection, alerting, and other functionality described herein.
[0017] Some embodiments described herein utilize or provide network security methods for focused secure cross-tenant access, including receiving or intercepting an attempted access to an asset during a remediation action; determining whether the asset is or includes an excluded asset based on at least an exclusion group; and in response to determining that the asset is or includes an excluded asset, prohibiting or imposing additional access requirements on cross-tenant access to the excluded asset. This access constraint functionality has the technical benefit of preventing inadvertent disruption of business-critical assets during cross-tenant incident mitigation or other managed response activities. Inadvertent actions such as isolating business-critical servers or resetting credentials of an actor account can have adverse business impact.
[0018] Some embodiments described herein utilize or provide network security methods for focused secure cross-tenant access, including creating or modifying a product-specific cross-tenant role, and enforcing cross-tenant access to an asset based on at least the product-specific cross-tenant role. This access constraint functionality has the technical benefit of providing granularity that limits the scope of cross-tenant asset access on a per-product-per-role basis rather than only on a per-role basis, thereby providing improved focus that reduces the risk of inadvertent impact on access to products other than the intended product.
[0019] Some embodiments described herein utilize or provide network security methods for focused secure cross-tenant access, including providing or utilizing cross-tenant built-in (no additional login required) access to an asset. This access constraint functionality has the technical benefit of reducing response time during managed response to a security incident, thereby improving damage reduction and risk reduction.
[0020] These and other benefits are not limited to method embodiments, and will be apparent to those of skill in the art in light of the teachings provided herein.
[0021] Operating Environment Reference Figure 1The operating environment 100 of embodiments includes at least one computer system 102. The computer system 102 can or can not be a multi-processor computer system. The operating environment can include one or more machines in a given computer system, which can be clustered within a cloud 136, client-server networked, and / or peer-to-peer networked. A single machine is a computer system, and a network or other group of cooperating machines is also a computer system. A given computer system 102 can be configured for an end user, e.g., with applications, for an administrator, as a server, as a distributed processing node, and / or otherwise.
[0022] A human user 104 sometimes interacts with a computer system 102 user interface 328 via typed text, touch, voice, movement, computer vision, gestures, and / or other forms of I / O using a display 126, keyboard 106, and other peripherals 106. In some embodiments, virtual reality or augmented reality or both functionality is provided by the system 102. The screen 126 is in some embodiments a removable peripheral 106, and in some embodiments is an integral part of the system 102. The user interface supports interaction between embodiments and one or more human users. In some embodiments, the user interface includes one or more of the following: a command-line interface, a graphical user interface (GUI), a natural user interface (NUI), a voice command interface, or other user interface (UI) representation presented or integrated as different options.
[0023] System administrators, network administrators, cloud administrators, security analysts and other security personnel, operations personnel, developers, testers, engineers, auditors, and end users are each a particular type of human user 104. In some embodiments, automated agents, scripts, playback software, devices, and the like that run or otherwise serve on behalf of one or more humans also have user accounts, e.g., service accounts. Sometimes, user accounts are created or otherwise provisioned as human user accounts, but in practice are primarily or only used by one or more services; such accounts are actual service accounts. Although a distinction can be made, “service account” and “machine-driven account” are used interchangeably herein without limitation to any particular vendor.
[0024] In some embodiments, storage devices or networking devices or both are considered peripherals, and in other embodiments are considered part of the system 102, depending on their removability from the processor 110. In some embodiments, for example, Figure 1 Other computer systems not shown in FIG. 1 use one or more connections via network interface devices to the cloud 136 and / or other networks 108 to interact with the computer system 102 or with another system embodiment in a technical manner.
[0025] Each computer system 102 includes at least one processor 110. Like other suitable systems, computer system 102 also includes one or more computer readable storage media 112, also referred to as computer readable storage devices 112. In some embodiments, tools 122 include secure tools or software applications, editors, compilers, debuggers, and other software development tools on mobile devices 102 or workstations 102 or servers 102, as well as APIs, browsers or web pages, and corresponding software for protocols such as HTTPS. Files, APIs, endpoints, and other resources can be accessed by accounts or collections of accounts, users 104 or groups of users 104, IP addresses or groups of IP addresses, or other entities. Access attempts can present passwords, digital certificates, tokens, or other types of authentication credentials.
[0026] Storage media 112 comes in different physical types. Some examples of storage media 112 are volatile memory, non-volatile memory, media fixed in place, media that is removable, magnetic media, optical media, solid-state media, and other types of physical, persistent storage media (as opposed to signals that are merely propagated or energy that is merely carried). In particular, in some embodiments, storage media 114 that is configured, such as a portable (i.e., external) hard drive, CD, DVD, memory stick, or other removable non-volatile storage media, functionally becomes a technological part of the computer system when plugged in or otherwise installed, such that its contents are accessible to and used by processor 110. Removable configured storage media 114 is an example of computer readable storage media 112. Some other examples of computer readable storage media 112 include built-in RAM, ROM, hard disks, and other memory storage devices that are not easily removed by users 104. To comply with current U.S. patent requirements, computer readable media, computer readable storage media, computer readable memory, and computer readable storage devices are not signals per se, nor are they merely energy that is carried by a wave.
[0027] The storage devices 114 are configured with binary instructions 116 that are executable by the processors 110; "executable" is used in a broad sense herein to include, for example, machine code, interpretable code, bytecode, and / or code that runs on a virtual machine. The storage media 114 are also configured with data 118 that is created, modified, referenced, and / or otherwise used for technical effect by execution of the instructions 116. The instructions 116 and data 118 configure the memory or other storage media 114 in which they reside; when that memory or other computer-readable storage media is a functional part of a given computer system, the instructions 116 and data 118 also configure that computer system. In some embodiments, a portion of the data 118 represents real-world items such as events manifested in the system 102 hardware, product characteristics, inventory, physical measurements, settings, images, readings, volumes, and the like. Such data is also transformed by backup, restore, commit, abort, reformat, and / or other technical operations.
[0028] Although embodiments are described as being implemented as software instructions executed by one or more processors in a computing device (e.g., a general purpose computer, server, or cluster), such description is not meant to exhaust all possible embodiments. Those skilled in the art will appreciate that the same or similar functionality can also be implemented in whole or part in hardware logic directly, to provide the same or similar technical effects. Alternatively or in addition to software implementation, the technical functionality described herein can be performed at least in part by one or more hardware logic components. For example, some embodiments include one or more of the following: chiplets, hardware logic components 110, 128 such as field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-chip components (SOCs), complex programmable logic devices (CPLDs), and similar components, without excluding other implementations. In some embodiments, components are grouped into interacting functional modules based on, for example, their inputs, outputs, or technical effects.
[0029] In addition to the processors 110 (e.g., CPUs, ALUs, FPUs, TPUs, GPUs, and / or quantum processors), the memory / storage media 112, the peripherals 106, and the display 126, some operating environments also include other hardware 128 such as batteries, buses, power supplies, wired and wireless network interface cards. The terms "screen" and "display" are used interchangeably herein. In some embodiments, the display 126 includes one or more touchscreens, screens that respond to input from a pen or tablet computer, or screens that operate only for output. In some embodiments, the peripherals 106 (such as human user I / O devices (screens, keyboards, mice, tablets, microphones, speakers, motion sensors, etc.)) will be in operable communication with the one or more processors 110 and the memory 112.
[0030] In some embodiments, the system includes multiple computers connected by wired and / or wireless networks 108. Networking interface devices 128 can use network components (such as packet-switched network interface cards, wireless transceivers, or telephone network interfaces present in some computer systems) to provide access to the network 108. In some embodiments, there is also virtualization of networking interface devices and other network components (such as switches or routers or firewalls), for example in software-defined networks or sandboxes or other secure cloud computing environments. In some embodiments, one or more computers are partially or completely “air-gapped” due to being disconnected or only intermittently connected to another networking device or remote cloud. In particular, the secure cross-tenant access function 204 can be installed on an air-gapped network and then updated periodically or occasionally using removable media 114, or not at all. Some embodiments also transfer technical data or technical instructions or both by direct memory access, removable or non-removable volatile or non-volatile storage media, or other information storage retrieval and / or transfer methods.
[0031] Those skilled in the art will appreciate that the foregoing aspects and other aspects presented herein under “Operating Environment” form part of some embodiments. The headings of this document are not intended to provide a strict categorization of features as sets of embodiment and non-embodiment features.
[0032] One or more items are shown in outline form or listed within brackets in the figures to emphasize that they are not necessarily part of the illustrated operating environment or all embodiments, but are interoperable with items in the operating environment or some embodiments as discussed herein. This does not mean that any item not in outline or brackets form in any figure or any embodiment is necessarily required. In particular, Figure 1 are provided for convenience; inclusion of an item in Figure 1 does not mean that the item or use of the item was known in the art prior to this disclosure.
[0033] In any subsequent application claiming priority to the present application, reference numerals can be added to designate items disclosed in the present application. Such items can include, for example, software, hardware, steps, processes, systems, functions, mechanisms, data structures, computing resources, programming languages, tools, workflows or algorithm implementations, or other items in a computing environment that are disclosed herein but not associated with a particular reference numeral in the text. Corresponding figures can also be added.
[0034] More information about the system Figure 2A computing system 102 configured with one or more secure cross-tenant access enhancement teachings herein is shown, resulting in an enhanced system 202. In some embodiments, the enhanced system 202 comprises a single machine, a local network of machines, machines in a particular building, machines used by a particular entity, machines in a particular data center, machines in a particular cloud, or another computing environment 100 as appropriate for enhancement. Figure 2 Items of are discussed at various points herein, and additional details regarding them are provided in the discussion of the list of reference numbers later in this disclosure document.
[0035] Figure 3 Some aspects of some enhanced systems 202 are shown. This is not a comprehensive overview of all aspects of enhanced systems 202 or all aspects of secure cross-tenant access functionality 204. This figure is also not a comprehensive overview of all aspects of environment 100 or system 202 or other contexts of enhanced system 202, or any aspects of potential use of functionality 204 in or with system 102. Figure 3 Items of are discussed at various points herein, and additional details regarding them are provided in the discussion of the list of reference numbers later in this disclosure document.
[0036] Figure 4 Some additional aspects of cloud tenant 124 are shown. This is not a comprehensive overview of all additional aspects of tenant 124 or cloud 136. Figure 4 Items of are discussed at various points herein, and additional details regarding them are provided in the discussion of the list of reference numbers later in this disclosure document.
[0037] Figure 5 Some aspects of data flow to, from, or between items including directory service 506, permissions service 514, and AOBO (stands for action, also known as stands for management) service 508 are shown. This is not a comprehensive overview of all additional aspects of assistant tenant 214, 124 or focus tenant 212, 124 or cloud 136. Figure 5 Items of are discussed at various points herein, and additional details regarding them are provided in the discussion of the list of reference numbers later in this disclosure document.
[0038] Other figures are also relevant to system 202. Along with Figure 5 together, Figure 6 and Figure 7 Methods of operation of functionality 204 in system 202 are shown.
[0039] In some embodiments, the augmentation system 202 is networked through an interface 328. In some embodiments, the interface 328 includes hardware such as a network interface card, software such as a network stack, API, or socket, a combination item such as a network connection, or a combination thereof.
[0040] Some embodiments include a computing system 202 configured for secure cross-tenant access. The computing system includes a digital memory 112 and a set of processors 110 including at least one processor in operable communication with the digital memory. The set of processors is configured to execute a secure cross-tenant access method 700 including at least one of detecting 602 a conditional access policy 402 blocking change 444 and alerting 306 in response to the conditional access policy blocking change detection, detecting 602 a blocking conditional access policy addition 446 and alerting 306 in response to the blocking conditional access policy addition detection, or detecting 602 a cross-tenant role assignment 408 blocking change 444 and alerting 306 in response to the cross-tenant role assignment blocking change detection. The conditional access policy blocking change is a change 310 that blocks authorized access 308 to a focus tenant 212 from a user of an assistant tenant 214. The blocking conditional access policy addition is an addition of a conditional access policy that blocks 310 authorized access to the focus tenant from the user of the assistant tenant. The cross-tenant role assignment blocking change is a change 310 that blocks authorized access to the focus tenant from the user of the assistant tenant.
[0041] Some embodiments include a case management subsystem 312 that resides in the assistant tenant and includes an interface 328 configured to receive 722 a request 432 for authorized access to the focus tenant.
[0042] Some embodiments include an audit correlation subsystem 316 configured to correlate 314, when executed, an assistant tenant request 432 for authorized access to the focus tenant with a focus tenant login event 132 and a focus tenant resource 438 access event 132.
[0043] In some embodiments, the list 320 of authorized roles 318, 134 resides in the digital memory and the detection 602 of a cross-tenant role assignment blocking change includes detection of a different role 413, 134 that is not in the access control list of authorized roles.
[0044] Some embodiments include a security group 326 that resides in the assistant tenant and corresponds 714 to a non-blocking cross-tenant role assignment 408 in the focus tenant.
[0045] Some embodiments include a scenario analysis subsystem 324 configured to, upon execution, perform a scenario analysis 322 based at least on the conditional access policy scope 404 and the authorized access scope 436 of the authorized access 308 to the focused tenant 212.
[0046] Other system embodiments are also described herein, either directly or as system versions of the described processes or configured media, as properly informed by the extensive discussion herein of computing hardware.
[0047] Although specific secure cross-tenant access architecture examples are shown in the drawings, embodiments can depart from those examples. For example, in embodiments, items shown in different figures can be included together, items shown in the figures can be omitted, functions shown in different items can be combined into fewer items or a single item, items can be renamed, or items can be connected to each other differently than shown.
[0048] Examples are provided in this disclosure to aid in the explanation of aspects of the technology, but the examples given within this document do not describe all possible embodiments. For example, given embodiments can include additional or different kinds of cross-tenant access functionality, as well as different technical features, aspects, mechanisms, software, expressions, sequences of operations, commands, data structures, programming environments, execution environments, environmental or system characteristics, or other functionality consistent with the teachings provided herein, and can depart from the specific examples provided in other ways.
[0049] Processes (also called methods) Processes (also called “methods” in the legal sense of the word) are shown herein in various ways in the text and in the drawings. Figure 5 、 Figure 6 and Figure 7 A series of methods 500, methods 600, and methods 700 are shown, respectively, that are performed or assisted by some enhanced system, such as some system 202 or another secure cross-tenant access functionality enhanced system as taught herein. The method series 500 and 600 are proper subsets, respectively, of the method series 700.
[0050] Figure 5 Three stages are shown: an onboarding stage 524, an on-demand access stage 526, and an offboarding stage 528. Figure 5 Some variations on the above include at most one of these stages, without necessarily excluding Figure 5 other steps not shown in the above. Figure 5 Some variations on the above include at most two of these stages, without necessarily excluding Figure 5other steps not shown. Exclusion in this sense does not require non-performance; an excluded stage is sometimes performed by a different party, for example, and thus is not included in a given embodiment. Figure 5 Items of Figure 5 are discussed at various points in this document, and additional details regarding them are provided in the discussion of the list of figure references later in this disclosure document.
[0051] Figure 6 Some variations of Figure 6 exclude the monitoring step 302 or exclude the tracking step 304. Some variations include the warning 306 instead of the modification, and some variations include both the warning 306 and the modification 604. These are just examples of variations; as described elsewhere, any operable combination of the steps disclosed herein can be part of a given embodiment.
[0052] Figures 1 to 5 A secure cross-tenant access system 202 architecture is shown with implicit or explicit actions, e.g., giving an administrator consent, creating or providing or using or invalidating access tokens, reading and enforcing access policies, comparing role assignments, or otherwise processing data 118 including, e.g., security tokens, access policies 138, roles 134, security groups 326, access requests 423 and responses 516, and directory service 506 data, among other examples disclosed herein.
[0053] Unless otherwise noted, the technical processes shown in the figures or otherwise disclosed will be performed automatically, e.g., by the augmentation system 202. Related unclaimed processes can also be performed partly automatically and partly manually to the extent that they involve human action, e.g., in some cases a human 104 typing data in response to tool 122 execution or kernel 120 execution. But the processes contemplated herein as embodiments are not entirely manual or purely mental; none of the claimed processes can be performed solely in a human mind or on paper. Any contrary claim interpretation is wholly inconsistent with this disclosure.
[0054] In a given embodiment, zero or more of the illustrated steps of a process can be repeated, can be operated on with different parameters or data. Steps in embodiments can also be completed in a different order from the top-to-bottom order of layout in Figure 7 Figure 7 Figure 7 Figure 7
[0055] Arrows in a process or data flow diagram indicate permissible flows; arrows pointing in more than one direction indicate flows can occur in more than one direction. Steps can be performed serially, partially overlapping, or completely in parallel within a given flow. In particular, the order of actions traversing flowchart 700 to indicate steps performed during a process can vary from one execution instance of the process to another. The flowchart traversal order can also vary from one process embodiment to another. Steps can also be omitted, combined, renamed, regrouped, performed on one or more machines, or otherwise removed from the flow shown, provided the performed process is operable and conforms to at least one claim of an application or patent that includes this disclosure or claims its priority. Figure 7 If a given sequence S of consistent steps is inoperable, then sequence S is not within the scope of any claim. Otherwise, any assertion is contrary to this disclosure.
[0056] Some embodiments provide or utilize a network security method 700 for secure cross-tenant access methods; the method is performed by a computing system 202. The method includes at least the following: monitoring 302 a non-obstruction conditional access policy for a focused tenant, the monitoring including checking 702 an obstruction change 444 in the non-obstruction conditional access policy, the monitoring also including checking 702 the addition of an obstruction conditional access policy 446. An obstruction change is a change that obstructs 310 authorized access to the focused tenant by a user from an assistant tenant. An obstruction conditional access policy is a conditional access policy that obstructs 310 authorized access to the focused tenant by a user from an assistant tenant. In this example, the method also includes tracking 304 cross-tenant role assignments for the focused tenant, the tracking including checking 704 cross-tenant role assignments for changes in cross-tenant role assignments. In this example, the method also includes detecting 602 at least one of the following: an obstruction change to a non-obstruction conditional access policy, the addition of an obstruction conditional access policy, or a change in cross-tenant role assignments. In this example, the method also includes modifying at least one of the following in response to the detection result: a non-obstructive access policy, an obstructive access policy, a cross-tenant role assignment, or the scope of authorized access for a focused tenant by a user from an assistant tenant.
[0057] In some embodiments, the method includes relating focused tenant audits to assistant tenant audits 314, thereby generating 314 related audits 130 of user activity 406 in focused tenants and user activity 406 in assistant tenants.
[0058] In some embodiments, the method includes receiving a 708 command 412 from a user in a focused tenant, wherein the command is in at least one of the following command categories: security investigation command 410, security modification command 410, or management service command 418.
[0059] In some embodiments, monitoring 302 the non-obstructed conditional access policy includes performing 322 a scenario analysis 322. In some embodiments, the scenario analysis includes a hypothetical analysis adapted from the tool 122 that identifies potential impacts of policy changes without considering the cross-tenant access 308 scope 436.
[0060] In some embodiments, tracking 304 the cross-tenant role assignments includes detecting 706 fraudulent roles.
[0061] In some embodiments, the method includes constraining 712 authorized access by users from the assistant tenant to the focus tenant to zero persistent 420 time-limited 422 access 424. In some variations, the access 424 is constrained to zero persistent but not to time-limited, or vice versa. Not being constrained to a time limit 422 does not imply permanence; non-time-limited access can be terminated on demand by a command from an administrator.
[0062] In some embodiments, the method includes constraining 712 authorized access by users from the assistant tenant to the focus tenant to access only via login from authorized managed devices 426. In some embodiments, the method includes constraining 712 authorized access by users from the assistant tenant to the focus tenant to access only via login from a specific IP address range 442. In embodiment variations, one, two, or more of the following constraints 712 are not implemented, implemented: zero persistent, time-limited, managed device, or IP address range.
[0063] In some embodiments, the method includes defining 716 cross-tenant role assignments in the focus tenant using at least 716 granular delegation management privilege groups 430.
[0064] Configured storage medium Some embodiments include a configured computer-readable storage medium 112. Some examples of storage medium 112 include (magnetic, optical or other) disks, RAM, EEPROM or other ROM, and other configurable memory, including in particular computer-readable storage media (not just propagating signals). In some embodiments, the configured storage medium is in particular removable storage medium 114, such as a CD, DVD or flash memory. According to embodiments, items such as security groups 430, 326, directory service 506 data, services 508, 514, access requests 432 and responses 516, role assignments 408, access policies 138, audit events 132, subsystems 312, 316, 324 and SCTA software 216 (in the form of data 118 and instructions 116, read from removable storage medium 114 and / or another source such as a network connection) can be used in embodiments to configure general-purpose memory, removable or non-removable and volatile or non-volatile, to form a configured storage medium. Configured storage medium 112 is capable of causing computer system 202 to perform technical process steps for providing or utilizing SCTA functionality 204, as disclosed herein. Thus, the figures help to show configured storage medium embodiments and process (also called method) embodiments, as well as system and process embodiments. In particular, Figure 5 , Figure 6 or Figure 7 Any of the method steps shown in FIGS. 7-9 or otherwise taught herein can be used to help configure storage medium to form a configured storage medium embodiment.
[0065] Some embodiments use or provide computer-readable storage devices 112, 114 configured with data 118 and instructions 116 that, when executed by processor 110, cause computing system 202 to perform security cross-tenant access method 700. The method 700 includes alerting 306 in response to detecting 602 to a conditional access policy impedes change, an impedes conditional access policy addition, or an impedes cross-tenant role assignment change, where the conditional access policy impedes change is a change that impedes authorized access to a focus tenant by a user from an assistant tenant, the impedes conditional access policy addition is an addition of a conditional access policy that impedes authorized access to a focus tenant by a user from an assistant tenant, and the impedes cross-tenant role assignment change is a change that impedes authorized access to a focus tenant by a user from an assistant tenant.
[0066] In some embodiments, the method further includes correlating 314 focus tenant audits with assistant tenant audits, resulting in 314 a correlated audit of activity of the user in the focus tenant and activity of the user in the assistant tenant.
[0067] In some embodiments, the method further includes restricting 712 authorized access from users of the assistant tenant to the focused tenant to zero-resident-time access via logins from authorized managed devices.
[0068] In some embodiments, the method further includes restricting 712 authorized access from users of the assistant tenant to the focused tenant to zero-resident-time access via logins from a specific IP address range.
[0069] In some embodiments, the method further includes restricting 712 authorized access from users of the assistant tenant to the focused tenant to access only via logins from authorized managed devices and from a specific IP address range.
[0070] Some embodiments provide or utilize built-in 942 (no additional login needed) analyst access to M365 Defender. Some embodiments provide or utilize cross-tenant built-in 942 access 308 to assets in the focused tenant after authorization in the assistant tenant, without additional login in the focused tenant. In some embodiments, GDAP enables partners to manage access and perform workloads with least privilege. Using internal tools within the service provider (e.g., security service provider or cloud service provider), analysts can authenticate via GDAP and see a list of devices and users that have been excluded from participating in managed response. Analysts can then take remediation actions through an API (e.g., ActionProvider, an API layer provided by M365 Defender) without having to log in again from the M365 Defender portal or other authorized security tool portals. This allows analysts or other experts to respond to security threats more quickly.
[0071] Additional observations regarding secure cross-tenant access Additional support for the discussion of the SCTA functionality 204 in this document is provided under various headings. However, all are intended to be understood as integral and integral parts of the present disclosure discussion of contemplated embodiments.
[0072] Those skilled in the art will recognize that not every part of the present disclosure or any particular detail therein need meet legal standards, such as enablement, written description, best mode, novelty, non-obviousness, inventive steps, or industrial applicability. Any apparent conflict with any other patent disclosure, even from the owner of the present subject matter, has no effect in interpreting claims presented in this patent disclosure. With this understanding involving all parts of the present disclosure, examples and observations are provided herein.
[0073] In this disclosure, the customer tenant is an example of a focus tenant 212. The teachings also apply to other focus tenants. For example, in some scenarios, there are focus tenants that are not customer tenants because there is no customer-provider business relationship between the focus tenant entity that manages, operates, controls, or owns the focus tenant and the assistant tenant entity that manages, operates, controls, or owns the assistant tenant.
[0074] Some embodiments provide or enhance the ability of a managed service technician to act as an administrator on behalf of a customer to mitigate incidents on the customer’s tenant in a secure, compatible, auditable, and timely manner. This ability helps keep the customer tenant and its assets secure.
[0075] Some embodiments provide or utilize the ability to monitor and alert of any changes to the CA policy intended for the customer tenant that do not allow the authorized technician to log into the customer’s product portal.
[0076] Some embodiments provide or utilize the ability to monitor and alert in cases where cross-tenant role assignments are extended beyond their intended purpose.
[0077] Some embodiments provide or utilize the ability to provide relevant audits for all actions involving a technician across different systems. In some embodiments, this includes case management audit events, AAD or other directory service 506 login logs, and product audit events.
[0078] Some embodiments provide or utilize the ability to request time-limited, on-premises access to a secure technician within the context of a case management system. Some embodiments provide or utilize the ability to request time-limited, on-premises access to a secure technician within the context of a case management system.
[0079] Some embodiments provide or utilize the ability to provide time-limited, cross-tenant role assignments in a focus tenant.
[0080] Some embodiments provide or utilize the ability to reduce the attack surface by only allowing a technician to access a focus tenant from a secure and restricted device registered in the MEM of an assistant tenant.
[0081] Some embodiments provide or utilize the ability for a technician to log into a customer’s product portal and perform actions that enhance the security, reliability, performance, or usability of the customer’s product.
[0082] Some embodiments provide or utilize the ability to provide relevant audits for all actions involving a technician across different systems. In some cases, these include case management audit events, directory service login events, and product audit events.
[0083] Some embodiments provide or utilize the ability to monitor and alert on any changes to the CA policy intended for a customer tenant that do not allow a technician to log into the customer’s product portal.
[0084] Some embodiments provide or utilize the ability to establish a trust model where customers can agree to create cross-tenant access policies and conditional access policies on their tenants.
[0085] Some embodiments provide or utilize the ability to extend the scope of the approver for time-limited, guest access for technicians beyond the MSE tenant.
[0086] Some embodiments provide or utilize the ability to monitor and alert in cases where cross-tenant role assignments are extended beyond the intended purpose.
[0087] Some embodiments provide or utilize a case management subsystem (e.g., an enhanced dynamic 365 integrated case management system) to obtain guest access utilizing access management (e.g., cross-tenant access management for AAD) in order to remediate security incidents and perform mitigation actions. Some of many examples of remediation or mitigation include isolating devices, running antivirus scans, and retiring devices. In some embodiments, authorized access includes activity on a secure portal such as the MEM or MSE portal. Some embodiments use secure and restricted Windows 365® devices registered in Microsoft Endpoint Manager (MEM) (a trademark of Microsoft Corporation) for the Microsoft Expert (MSE) tenant. Some embodiments also provide the ability to correlate the audit of all actions that a technician will engage in the aforementioned system. Some embodiments also provide monitoring of conditional access (CA) policies in the customer tenant to prevent customers or intruders from blocking access to authorized technicians.
[0088] Some embodiments utilize or adapt Azure® AD login security features, for example, where a customer tenant 212 trusts X-TAP policy trust settings from a compatible device 101 of an assistant tenant 214, inbound conditional access (external user type and tenant scope determination) to a customer tenant with granular targeting, and constraints on technicians accessing a customer tenant via a Windows 365® device registered in MEM in an assistant tenant 214. Some embodiments utilize or adapt Azure® AD cross-tenant role assignments for authorization. Some embodiments utilize or adapt Azure® AD Entitlement Management (ELM) for technician just-in-time (JIT) access provisioning (a trademark of Microsoft Corporation).
[0089] In some embodiments, the customer global administrator is involved in a one-time process to set up the assistant tenant AOBO artifacts, such as X-TAP and inbound conditional access. In some embodiments, whenever an administrator authorizes a managed service that involves SCTA, the AOBO artifacts specific to the managed service 416 will be enabled.
[0090] Some embodiments provide or utilize enhancements with respect to security, auditing, and integration with case management systems to make the solution robust and secure, and to improve usability. Some embodiments fill gaps by providing one or more of the following: a one-stop solution for technicians in which they can request JIT access from the case management system; an audit trail that correlates JIT requests and approvals with technician login logs in the customer tenant, and with audit logs that show changes in the customer tenant; a tracking system to notify technicians if any attacker or customer administrator changed an existing CA policy or created a more restrictive CA policy that can prevent the technician from logging into the customer tenant; a tracking system to notify customer administrators if any technician-operated service has created cross-tenant role assignments beyond what was agreed upon between the supervising administrator or technician of the assistant tenant and the managed service customer.
[0091] Figure 5 The diagram of FIGURE 1 involves two tenants (assistant tenant and focus tenant) shown in vertical channels and three stages of AOBO shown horizontally, but the steps can be divided differently. An alternative division of the stages has four stages of AOBO: join 524, access 526, access expiration (not shown in FIGURE 1) and leave 528. Join 524 and leave 528 involve one-time setup triggered by the customer or other focus tenant global administrator. Figure 5
[0092] In some embodiments, during the join stage 524, the customer’s global administrator joins 502a the managed service and creates X-TAP and inbound conditional access in their tenant 212. Subsequently, the AOBO service 508 creates 504 security groups in the assistant tenant and establishes 512 cross-tenant role assignments in the customer tenant. In some cases, the security groups are defined by each customer’s role, e.g., for the role of security administrator and customer Contoso, the group contoso_securityadmin is created. In some cases, the setup 512 includes configuring XTAP settings to allow the service provider. In some embodiments, to allow JIT access to these security groups, an ELM package 530 is configured 510 in the assistant tenant. The ELM package provides a policy that provides time-limited access to the groups and requires an approver (based on role) to approve the request.
[0093] In some embodiments, during the on-demand access phase 526, the technician goes to the assistant tenant's myaccess portal or similar and selects the package to access. The access request 432 goes through an approval process, resulting in a response 516 that either approves or disapproves the request. After approval, the technician is granted access to the customer tenant.
[0094] In some embodiments, during the access expiration phase, based on the ELM policy configuration, the membership of the technician in the security group is removed. In Figure 5 some embodiments, this is part of the leave phase.
[0095] In some embodiments, during the leave phase 528, the customer's global administrator has the option to unsubscribe from the hosting service. Then, the X-TAP is deactivated and the cross-tenant role assignment is deleted. The customer administrator is also advised to remove the X-TAP and the inbound CA from their tenant 212. In some embodiments, the leave 520 includes deleting the access package and deleting the security group. In some embodiments, the leave 522 includes setting the XTAP configuration to not allow the service provider, and deleting the cross-tenant role assignment.
[0096] Some embodiments provide policy monitoring. The conditional access policy is monitored so that if a changed policy or a stricter policy is detected in the customer tenant, a notification is sent to the assistant tenant technician and they can work with the customer's administrator to resolve the issue accordingly.
[0097] Some embodiments provide role tracking. The cross-tenant role assignment is tracked so that the system does not violate the contract by creating more role assignments between the assistant tenant provider and the customer than the contract.
[0098] Some embodiments provide reporting to track the AOBO activity using relevant audit logs. Some embodiments provide a set of relevant audit logs to track the AOBO request and approval audit logs in the hosting service and to track the activity in the customer tenant.
[0099] Some embodiments provide or utilize a cyber security method, comprising: receiving an approval of time-limited zero-residency access to a controlled resource of a cloud tenant by an external user, the external user not previously being a user of the cloud tenant; providing a time-limited cross-tenant role assignment to the external user in the cloud tenant; limiting the approved access to access from a security-restricted enrollment device; auditing actions of the external user within the cloud tenant during a duration of the approved access; and monitoring a conditional access policy of the cloud tenant during the duration of the approved access and alerting on attempted changes to the conditional access policy when the changes would impede the approved access.
[0100] Some embodiments include monitoring a cloud tenant’s conditional access policies during the duration of approved access and alerting on attempted changes to conditional access policies when the changes would impede approved access.
[0101] Some embodiments include monitoring a cloud tenant’s cross-tenant role assignments during the duration of approved access and alerting on attempted role assignments when the changes would impede approved access.
[0102] Some embodiments include correlating audit actions of external users within a cloud tenant with actions such as JIT requests, approvals, and activities during the duration of approved access.
[0103] Some environments include a flow for AOBO access in a customer tenant of a hosted service. In some embodiments, a customer join for AOBO includes these computing system steps or states in the listed sequence: executing a customer administrator initiated join start software, obtaining an allowed AAD role for the hosted service, obtaining a customer administrator approval for the role, creating an XTAP in the customer tenant with a management token, creating a CA policy 1 (policy 1 blocks devices outside of a cloud PC virtual network IP range) in the customer tenant with a management token, creating a CA policy 2 (policy 2 allows compatible hosted (e.g., Windows® 365) devices from a certain IP range (Microsoft’s designation) in the customer tenant with a management token. This customer join for AOBO is followed by a background join process that includes these steps or states in the listed sequence: a join API call, XTAP lock, AAD permissions package creation in the assistant tenant from the customer and role and security groups created by the hosted service, cross-tenant role assignment in the customer tenant, and AAD permissions package creation in the assistant tenant from the security groups.
[0104] Some environments include a background CA consistency checker that runs, for example, every hour or at another specified interval. In some embodiments, CA policy consistency check 702 includes these computing system steps or states in the listed sequence: obtaining a baseline CA policy, obtaining cross-tenant access policies in the customer tenant, comparing the CA policy and the hypothetical analysis, when the CA policy change validation result indicates pass, marking the payload as validated, or when the CA policy change validation result indicates fail, invoking an ICM connector API and creating an ICM, and starting an investigation, for example, with a customer administrator. An ICM is an intelligent communication manager that is used in some environments as an incident management service and an internal tracking tool.
[0105] Some environments include a background role assignment consistency checker that runs, for example, every hour or at another specified interval. In some embodiments, the cross-tenant role assignment consistency check 704 includes these computing system steps or states in the listed sequence: obtain customer administrator granted role assignments, obtain cross-tenant role assignments from customer tenant, compare role assignments, when role assignment validation results indicate pass, flag payload as validated, or when role assignment validation results indicate fail, invoke ICM connector API and create ICM and start investigation.
[0106] Some environments include a customer departure for AOBO that includes these computing system steps or states in the listed sequence: find all AOBO related artifacts in customer tenant, find all AOBO related artifacts in assistant tenant, flag XTAP for soft deletion, flag cross-tenant role assignments for soft deletion, flag CA policies for soft deletion, flag SCTA security groups in assistant tenant for soft deletion, and flag SCTA authorized access packs in assistant tenant for soft deletion. Variations change the order of flagging, or include flagging simultaneously, or both.
[0107] Some environments include a background departure phase after a customer departure for AOBO. This background departure includes these computing system steps or states in the listed sequence: disable XTAP in customer tenant, delete cross-tenant role assignments in customer tenant, delete SCTA security groups in assistant tenant, delete SCTA authorized access packs in assistant tenant, notify customer administrator of deletion of CA policies by email or other means.
[0108] Some environments include a process for automatic access with reader roles that includes these computing system steps or states in the listed sequence: assign case to SOC (security operations center), find customer granted AAD reader roles for managed services, find correct permission access packs for AAD roles in assistant tenant, request access on behalf of SOC, request is automatically approved, poll entitlement management API for remaining time for access.
[0109] Some environments include a process for requesting access to higher privilege roles that includes these computing system steps or states in the listed sequence: SOC request for specific role in customer tenant, if request is denied the process ends, otherwise case is assigned to SOC user, find correct permission access packs for AAD roles in assistant tenant, request access on behalf of SOC and perform audit process described below, pass control to AAD authorization management logic application, send notification to approver group and case management system, and pass control to approver process.
[0110] In the approver process, the approver receives a notification through a communication platform (e.g., the Microsoft Teams® platform (mark of Microsoft Corporation) or a case management system), and then approves or denies the access request in response to the notification via the platform or case management system or both. The request and response are recorded by the system for auditing.
[0111] In the requester customer tenant access process, the requester (e.g., the SOC) receives a notification. If the access is approved, the requester logs into the customer tenant, and the computing system performs actions on different resources in the customer tenant, e.g., via the System for Cross-domain Identity Management (SCIM), and then the customer tenant access process ends. The actions are recorded by the system for auditing.
[0112] Some environments include an audit log access process that includes these computing system steps or states in the listed sequence. In one path for a customer to view relevant 314 audit logs, software operating on behalf of the customer administrator performs role-based access control (RBAC) checks, filters the logs by customer ID and date, and feeds the results to a relevant query engine. In another path, software operating on behalf of the managed service administrator performs managed service RBAC checks, filters the logs by managed service and date, and feeds the results to a relevant query engine. The relevant query engine feeds a centralized audit store that also receives optionally audit-enriched log data from activities in the focus tenant and the assistant tenant.
[0113] Additional observations regarding asset exclusions Additional support for the discussion of the cross-tenant access asset exclusion (CTAAE) functionality 204 in this document is provided under various headings. However, all of it is intended to be understood as integral and integral part of the intended embodiments of the SCTA embodiments.
[0114] Some embodiments provide the CTAAE functionality 204 for a managed service role 940, such as an account 105 belonging to an analyst or other expert, to perform remediation actions on non-excluded assets 830 configured by the customer administrator 104.
[0115] A “remediation action” 908 is a computing activity in a computer system that involves reducing, preventing, or mitigating an identified or suspected cybersecurity risk (e.g., a risk to confidentiality, integrity, availability, or privacy), or that involves investigating the cause of a cybersecurity incident, or that involves identifying or mitigating an identified or suspected cybersecurity vulnerability or cybersecurity threat.
[0116] In some scenarios, providing a managed response 908 to the security incident includes taking remediation actions in the focused tenant 212, for example. Taking remediation actions without sufficient understanding of the focused tenant environment or processes can pose some level of risk. Unintentional actions such as isolating business critical servers or resetting credentials of performer accounts can have adverse business impact.
[0117] In some cases, for example, when no permissions are given that would allow more direct cross-tenant actions, the assistant tenant 214 personnel can provide a so-called “guided response” set of remediation actions to the focused tenant 212 personnel through step-by-step instructions. In some other cases, the assistant tenant 214 personnel do have sufficient permissions to directly perform remediation actions in the focused tenant 212 as part of a so-called “managed response”. For example, in some scenarios, the managed response includes direct remediation actions in the focused tenant customer’s M365 D (Microsoft 365® Defender TM ) portal via a GDAP relationship with an Azure® Active Directory® (AD) security operator role that has access to all focused tenant assets. In many cases, the managed response is a faster and more effective option. However, accessing all assets without any scope of excluded assets allows actions that can have adverse impact on the customer business, such as isolating business critical servers or resetting credentials of performer accounts.
[0118] Thus, in some embodiments, the asset 830 exclusion list 828 specifies assets, such as devices 101 and user accounts 105, that are excluded from being accessed via cross-tenant access capabilities (e.g., SCTA capabilities).
[0119] In some embodiments, granular delegated administration privileges (GDAP) are used as a mechanism for managing responses while respecting the exclusion list. GDAP enables two organizations to establish a relationship through cross-tenant access policies and cross-tenant role assignments (e.g., Azure® AD built-in roles).
[0120] In some embodiments, GDAP is enhanced to provide a means of establishing a scoped relationship, especially with respect to roles (e.g., Azure AD built-in roles) and specific levels of access to assets (e.g., M365 Defender assets).
[0121] In some embodiments, the CTAAE capability 204 enables a customer administrator to define groups 828 of excluded assets within the customer tenant (e.g., resource tenant) to prevent any actions by users of the owning tenant (e.g., assistant tenant) on those assets.
[0122] In some embodiments, the CTAAE capability 204 prevents non-tenant users with delegated privileges from accessing excluded assets. For example, in some scenarios, the CTAAE capability 204 prevents third-party administrator accounts that have delegated credentials to access a tenant environment for limited purposes from accessing assets (e.g., devices, accounts, etc.) on an exclusion list controlled by tenant administrators (e.g., using the Microsoft Defender for Endpoint group 810).
[0123] In a given embodiment, the excluded asset groups 828 include one or more of the following: excluded devices, e.g., defined using a security device group 810 such as a Microsoft Defender for Endpoint group for a group of endpoint devices; excluded users, e.g., defined using a security group 818 such as an Azure AD security group; or excluded mailboxes, e.g., defined using a security group 326 such as an Azure AD security group.
[0124] Figure 8 The CTAAE architecture 800, 204 is shown configured to perform computing activities that allow a customer administrator to set up excluded asset groups and assign assets to the groups. Asset exclusion groups 828, such as groups implemented with device groups 810 or user account groups 818 or both, are created 806 and populated 808 as needed or on an active basis (e.g., during or after onboarding).
[0125] In an example of the architecture 800 in operation, a customer administrator 104 utilizes an administrative portal 802, such as a Microsoft Defender Experts (DEX) customer management portal. Upon command from the portal, an embodiment creates 806 one or more asset exclusion groups 828 and adds 808 one or more assets 830 to the group. In an example, the group creation 806 and asset addition 808 are accomplished via calls to routines in a managed response customer API 804, which can be implemented, for example, as a Microsoft Graph TM API (a mark of Microsoft Corporation). Although not shown, in some embodiments one or more other operations are also supported via the API 804, such as removing assets from a group, moving assets to a different group, duplicating a group, merging two groups, or splitting a group into two groups. Some embodiments also support a permissions verification step, e.g., communicating with a provisioning store such as a DEX provisioning store, to verify relevant permissions such as DEX permissions.
[0126] In an example, the API layer 804 routines verify 836 membership 838 of assets in an exclusion group (e.g., with Microsoft Defender Experts). For example, some embodiments use a DEX GDAP relationship store 840 to verify 836 DEX GDAP relationships 838.
[0127] In an example, the API layer 804 routine creates 814, 806 one or more device asset exclusion groups 810, 828 and adds 816, 808 one or more device assets 101, 830 to the device exclusion groups 810. This is implemented in some embodiments using a device group API 812 (e.g., the Microsoft Defender Endpoint (MDE) device group API).
[0128] In an example, the API layer 804 routine creates 822, 806 one or more user asset exclusion groups 818, 828 and adds 824, 808 one or more device assets 101, 830 to the user identity exclusion groups 818. This is implemented in some embodiments using a user group API 820 (e.g., the Microsoft Azure AD security group API) implemented as a Microsoft Graph API. TM
[0129] In an example, the API layer 804 routine stores 826 the exclusion groups 828 in an asset exclusion database 842.
[0130] In some embodiments, a managed service role 940 (such as the Assistant Tenant Analyst role) is implemented by embodiments to allow action only on assets 830 that are not excluded from access by its presence in the exclusion groups 828. For example, in some scenarios, a managed role performing a managed response can act only on Microsoft Defender for Endpoint 365 assets if the asset is not identified in any exclusion list.
[0131] However, in some embodiments and scenarios, a human is given access to any non-excluded assets (e.g., Microsoft Defender for Endpoint 365 assets) within a specified group of security assets of a focused tenant without logging into the focused tenant. This allows an analyst in the owning tenant 214 (e.g., a Microsoft Defender for Experts) to take remediation actions (e.g., as part of a managed response) from internal tools without having to log into the customer 212 portal, but only for non-excluded assets. In some embodiments, the API layer 804 integrates with a remediation action API (e.g., the Microsoft 365 Defender for Experts remediation action API), verifies 836 membership of the asset in the exclusion groups (e.g., with Microsoft Defender for Experts) and generates 832 an authorization error 834 if the asset belongs to any exclusion group.
[0132] Figure 9 A CTAAE architecture 900, 204 configured to supplement the architecture 800 is shown. However, given embodiments can employ only architecture 800, only architecture 900, both architectures 800 and 900, or other architectures that provide the CTAAE functionality discussed herein, e.g., a GDAP with exclusion groups 828 in an SCTA architecture.
[0133] In an example of the operation of the architecture 900, an analyst 104 (e.g., an XDR SOC analyst) utilizes an analyst portal 902 (e.g., a DEX analyst portal). XDR stands for extended detection and response, SOC stands for security operations center, and DEX stands for defender expert. The example embodiment obtains a GDAP token 904 from an identity provider 906 (such as a customer tenant Azure AD service). The analyst portal sends a managed response 908 command and data to a managed response expert API 910, which uses an asset API 912 to obtain 914 relevant assets 830, e.g., all assets 830 involved in the incident. In this example, the managed response expert API 910 also obtains 916 asset exclusions from an asset exclusion database 842, e.g., one or more exclusion groups 828 for the customer tenant. In this example, the managed response expert API 910 also verifies 918 device membership in, or lack thereof, any device exclusion groups 810, and filters assets accordingly to prevent access to excluded devices using a device group API 812 (e.g., a MDE device group API). MDE stands for Microsoft Endpoint Defender. In this example, the managed response expert API 910 also verifies 920 user membership in, or lack thereof, any user exclusion groups 818, and filters user accounts and other user-specific assets (e.g., mailboxes) accordingly to prevent access to excluded user assets using a user group API 820 (e.g., an Azure AD security group membership API).
[0134] In this example, the identity of the filtered 938 assets 830 are sent to a security tool 922, such as a Microsoft 365 Defender API. In some embodiments, the filtering 938 produces an allow list of assets 830 that are allowed access, and in embodiments, the filtering 938 produces a deny list of assets 830 that are denied access. Thus, in some embodiments, the exclusion groups 828 have as members the identities of assets 830 that are allowed access, and if an asset is not identified in such an allow list, access by the analyst is denied (i.e., the analyst’s sought remediation operations are denied). In other embodiments, the exclusion groups 828 have as members the identities of assets 830 that are not allowed access, and if an asset is not identified in such a deny list, access by the analyst is allowed (i.e., the analyst’s sought remediation operations are allowed).
[0135] Continuing the example of the operation of the architecture 900, the security tool 922 attempts to cause one or more remediation actions 936, such as a device action 930 by an endpoint security tool 924 (e.g., MDE), an identity action 932 by an identity security tool 926 (e.g., Microsoft Identity Defender (MDI)), or an application action 934 by an application security tool 928 (e.g., Microsoft Application Defender (MDA) or Microsoft Office Defender (MDO)).
[0136] In some scenarios, the customer global administrator must explicitly turn on the CTAAE feature 204 via API or UI; in the given embodiment, the CTAAE feature 204 is not necessarily turned on by default.
[0137] Accordingly, some embodiments utilize or provide an enhancement including a managed response API that integrates with the Microsoft 365 Defender API or other security tool APIs for remediation actions and validating device group and identity security group membership. In some scenarios, the assets subject to the exclusion controls described herein include registered devices, user accounts, mailboxes, or combinations thereof. Some embodiments utilize or provide a method for a customer administrator to establish an exclusion list for assets from a separate tenant for a managed service role. Some embodiments utilize or provide a method for a customer administrator to establish an exclusion list per external tenant. Some embodiments utilize or provide a system for a managed service role (e.g., analyst) to perform remediation actions (e.g., managed responses) on the customer’s security tool assets from the analyst’s tool without requiring the analyst to log into the customer’s security tool portal. For example, in some embodiments, the managed service role has an authentication token or another persistent authentication that is limited to security tool access authentication. Some embodiments utilize or provide a system for a managed service role (e.g., analyst) to perform remediation actions only on customer authorized assets and not on any other assets.
[0138] Some embodiments are suitable for utilization by experts (e.g., in a cloud service provider SOC) or by customers (also referred to as clients, e.g., tenants) of security services managed by such experts. For example, in some Microsoft environments, the Defender expert for XDR: Managed Response is a feature that provides customers with the ability to enhance their security operations center (SOC). In some scenarios, the feature is part of the Microsoft Defender expert for XDR (XDR expert) managed detection and response service that extends beyond endpoints to provide detection and response across Microsoft 365 Defender data.
[0139] While Microsoft technology is used in this example, similar technology from other providers can also be optimized by applying the teachings presented herein.
[0140] In the case of managed response, customers are able to list the devices and users they want to exclude via settings during onboarding or later. This allows the Defender expert analyst to take remediation actions on behalf of their customers and mitigate threats. For excluded devices and users, the analyst will continue to provide the necessary guidance that the customer SOC analyst or CISO can act upon, unless otherwise configured for the scenario’s tool.
[0141] In this example, the customer can exclude devices or users by adding them to the defender for an endpoint device group or Azure Active Directory user group. The customer can also automatically exclude (a) any devices that they have identified as high-value devices on the defender for endpoints or another security tool, or (b) any users identified as sensitive on the defender for identity or another security tool, or (c) any user accounts identified as priority accounts on the defender for Office 365 or another security tool.
[0142] In some embodiments, the user interface shows an explanation such as “Remediation Exclusions: These devices and users will be excluded from remediation actions taken by the defender expert.” In some embodiments, the user interface also provides one or more of the following: buttons, checkboxes, search term input boxes, device group name lists, device group size counts, user group name lists, user group size counts, and similar user interface mechanisms and content to facilitate creating or modifying the exclusion list.
[0143] In some embodiments, the customer can consult with the defender expert or other expert or SOC personnel via a live chat feature of the user interface to discuss a particular incident or alert during specified hours (e.g., 24 / 7 / 365).
[0144] In some embodiments, the hosted response that the defender expert or other expert or SOC personnel has completed or at least provided as guidance to the customer can be viewed from the portal interface (e.g., the M365D portal) by clicking on a view hosted response link on the incident home page.
[0145] For example, in some scenarios, upon invoking the hosted response side panel, the customer will have access to an investigation summary, a list of completed actions, and a list of any pending actions waiting for the customer to take action or authorization (e.g., customer CISO role actions or authorizations). CISO stands for Chief Information Security Officer. The customer CISO can then follow the instructions for the pending actions and complete them accordingly to mitigate the threat and resolve the incident. The actions can be one-click (1-click) actions (e.g., isolate device actions in some tools) that can be completed by clicking a button or more complex actions (e.g., reset user password in some tools).
[0146] In some scenarios, all actions are completed by the defender expert or other expert or SOC personnel. Thus, the customer will be informed via the user interface that there are no pending actions. In some cases, the user interface also informs the customer that they can obtain a summary of the investigation and completed actions, e.g., via a hosted response invocation on an actions button.
[0147] In short, for XDR Defender experts: hosting responses and similar functionality in conjunction with the teachings provided herein provide customers with the ability to have managed security services that extend beyond endpoints. This allows for a more holistic view of their security operations, as well as the ability to respond to incidents more effectively. Additionally, in some embodiments, the scope of these actions extends across various workloads, such as office productivity software assets and identity assets in addition to endpoint assets. The security functionality 204 enhanced in accordance with the teachings herein is a valuable addition to the security operations of any organization. Among other benefits, it provides customers with the ability to have managed security services that extend beyond endpoints, allowing for a more holistic view of their security operations, as well as the ability to respond to incidents more effectively.
[0148] Some embodiments provide or utilize a GDAP with an asset exclusion list. In some embodiments, device exclusions are implemented as group-based exclusions or high-value asset tags or both. In some embodiments, customers can create group-based exclusions in a security tool (e.g., the M365 Defender portal), allowing them to specify which device and / or user groups to exclude. In some embodiments, high-value asset tags from M365 Defender or other security tools are repurposed to define exclusion groups.
[0149] When an analyst is attempting to remediate an incident involving a particular asset or user, the GDAP is used to query a device API (e.g., a machine API) for devices and / or query an identity API (e.g., a graph API) for users in order to map the asset or user to any known groups. This information is then compared to exclusion groups that the customer has defined as exclusions.
[0150] Additional observations regarding product-specific roles Additional support for the discussion of the cross-tenant access product-specific role (CTAPSR) functionality 204 in this document is provided under various headings. However, all are intended to be understood as integral and integral parts of the discussion of the present disclosure that encompasses contemplated embodiments of the SCTA embodiments.
[0151] Some embodiments allow external users (users outside of an organization) to access organization data in a secure and authorized manner. Some embodiments provide a solution for product-specific role-based access control (RBAC) support integration with granular delegated administration privileges (GDAP). In particular, some embodiments provide or utilize workload cross-tenant product role assignment for GDAP, some embodiments provide or utilize GDAP sign-in to customer tenants through workload tailored roles, compute permissions, and RBAC enforcement, and some embodiments provide or utilize cross-tenant product role assignment for GDAP and sign-in, permissions, and RBAC aspects. Some embodiments bring product-specific RBAC to a secure cross-tenant access solution via a token exchange mechanism.
[0152] Some embodiments with product-specific RBAC differ from more general RBAC in that different kinds or levels of access to different products are recognized and enforced even within a single role such as machine administrator, network administrator, global customer administrator, CISO, internal analyst, external analyst, SOC analyst, and so on.
[0153] Figure 10 A CTAPSR architecture 1000, 204 is shown that provides a solution for product 1020 to support GDAP workload rules using tailored roles for different products and using GDAP token claims (e.g., content security policy CSP or CSPV2 token claims). Some examples of product 1020 include Microsoft 365 Defender and other security tools, Microsoft Endpoint Manager (MEM) and other endpoint device management tools, Microsoft Teams® admin center and other video conferencing management tools. The shown architecture 1000 includes a GDAP cross-tenant workload role assignment portion 1004 and a GDAP sign-in portion 1012 with workload rules.
[0154] In one example of operation of CTAPSR architecture 1000, a user obtains 1018 a token 904 from an identity provider 906 (e.g., Azure AD identity provider). The user is a member 1006 of at least one security group. The user then signs in 1022 to a customer tenant using the token. A permissions computing software component 1010 obtains 1014 cross-tenant role assignments 1002 and obtains 1016 partner tenant group memberships, for example, from customer tenant storage or services, and computes user permissions 1008 accordingly. In some scenarios, the customer tenant has previously installed or otherwise configured cross-tenant access policies for partner tenants (also referred to as home tenants).
[0155] Some embodiments utilize or provide an API 1104 to create 512 or update 1116 workload cross-tenant role assignments. This API will allow role assignments between product-specific RBAC roles and security groups in partner tenants. For example, in some scenarios, the Microsoft 365 Defender unified RBAC role is assigned to a security group in the home tenant. In some embodiments, the role assignment is stored 1106 in the context of the customer tenant 212, but the security group 326 is from a partner tenant 214, as shown. Figure 10
[0156] With respect to validation, in some embodiments, cross-tenant role assignments are only allowed when the X-TAP policy is in place in the customer tenant for a given partner tenant. In some embodiments, only security groups (not users or other principals) of the home tenant are allowed to be assigned to roles of cross-tenant role assignments. In some embodiments, only security applications with special permissions can perform cross-tenant role assignments. Some embodiments provide or utilize a get cross-tenant role assignment API, which will allow role assignments between product-specific RBAC roles and groups of partner tenants (in some embodiments, the API consists of or in some embodiments includes one or more routines). Some embodiments provide or utilize a delete cross-tenant role assignment API.
[0157] In some scenarios, the customer global administrator 1102 must explicitly turn on this CTAP SR feature 204 via an API or UI; in a given embodiment, the CTAP SR feature 204 is not necessarily turned on by default.
[0158] Figure 11 The CTAP SR architecture 1100, 204 is shown, which in operation communicates 1108 the customer administrator’s consent to the AOBO service 508 to create cross-tenant role assignments. In some embodiments, the AOBO service 508 operates as part of or in conjunction with a SOC or security tool, such as the Microsoft Defender Experts Center or tool, or the Microsoft Defender Partner Center or tool. The consent 1108 is stored 1110 in storage 1112 (e.g., a database). Service-to-service communication between the AOBO service 508 and the workload cross-tenant role management service 1104 results in creating 512 cross-tenant role assignments. Validation 1114 is performed via communication with the identity provider 906 (e.g., the Azure® Active Directory® (AD) service 906). The validated cross-tenant role assignments are created 512 or updated 1116 in storage 1106 by the workload cross-tenant role management service 1104.
[0159] Figure 12 An operational diagram 1200 of the CTAP SR architecture 204 is shown, such as with respect to Figure 10 and Figure 11 An aligned CTAPSR architecture or another CTAPSR architecture 204 consistent with the teachings presented herein. External users from a home tenant are, for example, experts or analysts 105. A security token service is, for example, an Azure ESTS (Evolved Security Token Service) or similar security service. A product API is, for example, Microsoft 365 or other product API. A role assignment API is, for example, an AOBO service API or a cross-tenant role management API or a combination thereof. An API developer platform is, for example, Microsoft Graph TM or another platform for integrated services and devices. A product RBAC API is, for example, Microsoft 365 or other product RBAC API. In step 1202, an external user acquires a token, for example, a CSP version 2 token. In step 1204, the external user authenticates to the product API. In step 1206, the product API checks if there is a role assignment for the home tenant. In step 1208, the security token service obtains a representative (OBO) token. In step 1210, the product API checks the security group membership of the role assignment in the home tenant. In step 1212, the product API obtains the valid role membership. In step 1214, the product API implements role-based access accordingly.
[0160] Some embodiments verify that there is a cross-tenant role assignment and check if the token in the context is, for example, a CSPV2 token. If so, the embodiment checks if the partner-specific workload role assignment setting is turned on. If so, the cross-tenant role permissions are retrieved from the cross-tenant role assignment store.
[0161] Some embodiments compute the cross-tenant role permissions and scopes as follows. If the partner-specific workload role assignment setting is turned on, the embodiment uses the token of the logged-in external user (also known as GDAP or CSPV2 token) to obtain a representative (OBO) token in the context of the partner tenant. From the role assignment store, the embodiment finds the cross-tenant role assignments for the given customer tenant and the security groups of the partner tenant. The embodiment calls the integration platform (for example, Microsoft Graph MemberOf (cached for performance improvement)) to check if the logged-in user is a member of these groups using the OBO token obtained in the above steps. The embodiment computes the permissions based on the group memberships and roles found in the above steps.
[0162] In some scenarios, the embodiments provide a product-specific role-based access control functionality that extends the RBAC implementation of a product workload without the need to modify the code that implements the legacy (non-product-specific role) RBAC implementation.
[0163] Some embodiments utilize or provide a cyber-security method 1300 for centralized secure cross-tenant access, including: receiving 722 or intercepting 1302 an attempted access 432 to an asset during a remediation action; determining 1306 whether the asset is an excluded asset or includes an excluded asset based on at least an exclusion group; and in response to determining 1306 that the asset is or includes an excluded asset, prohibiting 1310 cross-tenant access to the excluded asset or imposing 1310 additional access requirements 944 on cross-tenant access to the excluded asset.
[0164] Some embodiments utilize or provide a cyber-security method 1400 for centralized secure cross-tenant access, including: receiving 722 or intercepting 1302 an attempted access 432 to an asset during a remediation action; determining 1406 a status of the asset according to a product-specific role 1002; and in response to determining 1306 that the asset is or includes an asset covered by the product-specific role 1002, implementing 1410 access to the asset based on the product-specific role 1002. Implementing 1410 includes prohibiting 1310 cross-tenant access to the covered asset, imposing 1310 additional access requirements 944 on cross-tenant access to the covered asset, or allowing access to the covered asset as specified by the product-specific role 1002, respectively.
[0165] Some embodiments utilize or provide a cyber-security method 700 for centralized secure cross-tenant access 308, including, computationally: receiving 722 or intercepting 1302 an attempted access 432 to an asset 830 during a remediation action 908; determining 1306 whether the asset is an excluded asset or includes an excluded asset based on at least an exclusion group 828; and in response to determining 1306 that the asset is or includes an excluded asset, prohibiting 1310 cross-tenant access to the excluded asset, or imposing 1310 additional access requirements 944 on cross-tenant access to the excluded asset, or both.
[0166] In some embodiments, the cyber-security method 700 includes, computationally: creating 806 an exclusion group for assets, or modifying 806 an exclusion group for assets.
[0167] In some embodiments, the cyber-security method 700 includes, computationally: creating 512 a product-specific cross-tenant role 1002, or modifying 512 a product-specific cross-tenant role 1002, and implementing 1410 cross-tenant access to assets based on at least the product-specific cross-tenant role.
[0168] In some embodiments, the computationally creating 512 or computationally modifying 512 the product-specific cross-tenant role includes at least one of: leveraging 512 the access service 508; or leveraging 512 the workload cross-tenant role management service 1104.
[0169] In some embodiments, the cybersecurity method 700 includes providing 900 or leveraging 900 cross-tenant built-in access 942, 308 to assets in the focused tenant 212 after the authorization 946 in the assistant tenant 214.
[0170] In some embodiments, the cybersecurity method 700 includes at least one of: obtaining 1018 the granular delegated management privilege token 904 from the identity provider 906; querying 918 the device API 812 using the granular delegated management privilege token; or querying 920 the identity API 820 using the granular delegated management privilege token.
[0171] Some embodiments provide or leverage a computing system 202 configured for focused security cross-tenant access 210, the system comprising: a digital memory 112; a set of processors 110 comprising at least one processor 110, the set of processors in operable communication with the digital memory, the set of processors configured to execute a focused security cross-tenant access method 700, the method 700 comprising: creating 512 or modifying 512 a product-specific cross-tenant role 1002, and enforcing 1410 cross-tenant access to assets 830 based at least on the product-specific cross-tenant role.
[0172] In some embodiments, the set of processors is further configured to provide or leverage cross-tenant built-in access functionality 942, 308 to assets of the focused tenant 212 after the authorization 946 in the assistant tenant 214.
[0173] In some embodiments, the set of processors is further configured to determine 1306 that an asset is or includes an excluded asset based at least on an excluded group 828, and in response to the determination, limit 1310 access to the excluded asset during the cross-tenant remediation action 908. In some of these embodiments, the excluded group includes at least one of: a device group 810, or a user account group 818.
[0174] Some embodiments include cross-tenant remediation action built-in access 942, 308 to at least one of: an endpoint security tool 924; an identity security tool 926; or an application security tool 928.
[0175] Some embodiments include a cross-tenant role assignment store 1106.
[0176] Some embodiments include a granular delegated administrative privilege token 904.
[0177] Some embodiments include a permissions computing software component 1010 that, when executed by the set of processors, obtains 1014 the cross-tenant role assignment 1002 and computes 1010 the user permissions 1008 based on at least the cross-tenant role assignment.
[0178] Some embodiments include a permissions computing software component 1010 that, when executed by the set of processors, obtains 1016 the partner tenant group membership 838 and computes 1010 the user permissions 1008 based on at least the partner tenant group membership.
[0179] Some embodiments provide or utilize a computer-readable storage device 112, 114 configured with data 118 and instructions 116 that, when executed by a processor 110, cause the computing system 202 to perform the focused security cross-tenant access method 700, the method 700 comprising: receiving 722 or intercepting 1302 an attempted cross-tenant access to an asset during a remediation action 908; and computationally limiting 1310 the attempted cross-tenant access based on at least one of: a product-specific cross-tenant role 1002 that encompasses the asset, or an exclusion group 828 that includes the asset.
[0180] In some embodiments, the second asset resides in the focused tenant 212, and the method includes at least one of: providing cross-tenant built-in access 942, 308 to the second asset based on authorization 946 in the helper tenant; or utilizing cross-tenant built-in access 942, 308 to the second asset based on authorization 946 in the helper tenant.
[0181] In some embodiments, the method 700 includes at least one of: determining 1306 an exclusion status 1308 of the asset based on at least the exclusion group; or determining 1406 a product-specific role status 1408 of the asset based on at least the product-specific cross-tenant role.
[0182] In some embodiments, the method 700 further includes obtaining 1018 the granular delegated administrative privilege token from an identity provider.
[0183] In some embodiments, the method 700 includes at least one of: querying a device API about the asset using the granular delegated administrative privilege token 904; or querying an identity API about the asset using the granular delegated administrative privilege token 904.
[0184] In short, some embodiments provide a solution for product-specific role-based access control (RBAC) support for granular delegated administration privileges (GDAP). Some embodiments allow workload cross-tenant product role assignment for GDAP, and leveraging workload tailored roles, compute permissions, and RBAC enforcement for GDAP login to customer tenants. Some embodiments verify the existence of cross-tenant role assignments, and compute product cross-tenant role permissions and scopes.
[0185] Additional observations regarding the Internet of Things In some embodiments, system 202 is an embedded system, such as an Internet of Things system. "IoT" or "Internet of Things" means any networked collection of addressable embedded computing or data-generating or actuator nodes. Individual nodes are referred to as Internet of Things devices 101 or IoT devices 101 or Internet of Things systems 102 or IoT systems 102. Such nodes are examples of computer systems 102 as defined herein, and can include or be referred to as, for example, "smart" devices, "endpoints," "chips," "tags," or "labels," and IoT can be referred to as "cyber-physical systems." In the phrase "embedded system," the embedding involved is embedding of a processor and memory in a device, as opposed to embedding of a debugging script in source code.
[0186] IoT nodes and systems typically have at least two of the following characteristics: (a) no local human-readable display; (b) no local keyboard; (c) primary input source is a sensor tracking non-linguistic data to be uploaded from the IoT device; (d) no local spinning-disk storage - RAM chips or ROM chips provide the only local memory; (e) no CD or DVD drive; (f) embedded in a home appliance or home fixture; (g) embedded in an implanted or wearable medical device; (h) embedded in a vehicle; (i) embedded in a process automation control system; or (j) focused in design on one of: environmental monitoring, city infrastructure monitoring, agriculture, industrial equipment monitoring, energy usage monitoring, human or animal health or fitness monitoring, physical security, physical transportation system monitoring, object tracking, inventory control, supply chain control, fleet management, or manufacturing. IoT communication can use a protocol such as TCP / IP, Constrained Application Protocol (CoAP), Message Queue Telemetry Transport (MQTT), Advanced Message Queuing Protocol (AMQP), HTTP, HTTPS, Transport Layer Security (TLS), UDP, or Simple Object Access Protocol (SOAP), for wired or wireless (cellular or otherwise) communication. IoT storage devices or actuators or data outputs or controls can be targets of attempted unauthorized access via the cloud, via another network, or via direct local access.
[0187] Technical characteristics The technical nature of the embodiments described herein will be apparent to those of ordinary skill in the art, and will also be apparent to readers of a wide variety of interests. Some embodiments address technical activities such as creating 504 security group data structures 326, creating 510 access rights package data structures 530, establishing 512 cross-tenant role assignments 408, and restricting 712 access based on IP address 440 or hosting device 426 status, each of which are deeply rooted in computing technology. Some of the technical mechanisms discussed include, for example, software 216 to monitor access policies 138 and track roles 134, audit 130 related subsystems 316, case management subsystems 312, and scenario analysis subsystems 324. Some of the technical effects discussed include, for example, detecting 602 cross-tenant access block changes or additions in conditional access policies 402, detecting cross-tenant access block changes in role assignments 408, detecting 706 fraudulent roles 414, 134, and focusing relevance 314 of activities in a tenant 212 to activities in an assistant tenant 214. Thus, purely mental processes and activities, limited to pen and paper, are obviously excluded. Other advantages of the technology according to the teachings, particularly as they relate to the speed, accuracy, memory capacity, and specific processing capabilities required to perform secure cross-tenant access as described herein, will be apparent to those of skill in the art in light of the
[0188] Those of skill in the art understand that cross-tenant access activities in a cloud computing environment are technical activities that cannot be performed mentally, as they require focusing on computing system activities in a tenant 212 or activities in an assistant tenant 214, or both. This includes, for example, creating, reading, modifying, or deleting data structures 402, 408, 326 in computer system memory. Moreover, mental or pen-and-paper activities cannot configure a computing system to perform secure cross-tenant access as described herein. Those of skill in the art also understand that attempting to perform secure cross-tenant access manually only would result in unacceptable delays in program execution, and would introduce a serious risk of human error, for example, human error could cause program crashes or expose systems to serious security risks. People obviously lack the speed, accuracy, memory capacity, and specific processing capabilities required to perform secure cross-tenant access as described herein.
[0189] In particular, secure cross-tenant access as described herein is part of computing technology. Thus, secure cross-tenant access improvements such as the functionality 204 described herein are improvements to computing technology.
[0190] In this document, a user's access or any other activity refers to the activity of a user device, or a user account, or software on behalf of a user, or hardware on behalf of a user. The activity is represented by digital data or machine operations in a computing system, or both. References to a user's activity within the scope of any claim based on this disclosure exclude the human action itself, and thus do not bring the human action itself within the scope of any embodiment or any claim.
[0191] Different embodiments provide different technical benefits or other advantages in different circumstances, but a person of skill in the art informed by the teachings herein will recognize that particular technical advantages will likely result from particular embodiment features or combinations of features, as noted at various points herein. Any general or abstract aspects are integrated into practical applications, such as the access control identification service 506 within a set of network security controls, the security or hosting service case management tool 312, or the audit tool 316.
[0192] Some embodiments described herein can be viewed by some people in a broader context. For example, concepts such as efficiency, reliability, user satisfaction, or waste can be considered relevant to particular embodiments. However, this does not follow the availability of the broader context, i.e., seeking exclusive rights for abstract ideas; they are not.
[0193] Instead, the present disclosure focuses on providing proper specific embodiments whose technical effects fully or partially solve particular technical problems, such as how to improve security of cross-tenant access, how to detect unauthorized activities during cross-tenant access, and how to detect unauthorized roles during cross-tenant access. Other configured storage media, systems, and processes involving efficiency, reliability, user satisfaction, or waste are outside the scope. Thus, under proper understanding of the present disclosure, obscuring, mere abstraction, lack of technical features, and accompanying proof problems are also avoided.
[0194] Additional combinations and variations Any of these combinations of software code, data structures, logic, components, communications, and / or functional equivalents of the same can also be combined with any of the above systems and variations thereof. Processes can include any of the steps described herein in any subset or combination or sequence operable. Each variation can occur alone, or in combination with any one or more other variations. Each variation can occur with any process, and each process can be combined with any one or more other processes. Each process or combination of processes (including variations) can be combined with any of the above configured storage media combinations and variations.
[0195] More generally, the skilled person will recognize that not every part of the present disclosure or any particular detail within it is necessarily a legal standard such as enablement, written description, or best mode. In addition, embodiments are not limited to a particular scenario, motivating example, operating environment, tool, peripheral, software process flow, identifier, data structure, data selection, naming convention, symbol, control flow, or other implementation option described herein. Any apparent conflict with any other patent disclosure, even from the owner of the present subject matter, has no effect in interpreting claims presented in this patent disclosure.
[0196] Acronyms, Abbreviations, Names, and Symbols Some acronyms, abbreviations, names, and symbols are defined below. Others are defined elsewhere herein, or need no definition here in order for one of skill to understand them.
[0197] AAD: Azure® Active Directory® (a trademark of Microsoft Corporation) ALU: arithmetic logic unit AOBO: on behalf of an action, also called on behalf of management API: application program interface BIOS: basic input output system CA: conditional access CD: compact disc CPU: central processing unit DVD: digital versatile disc or digital video disc ELM: AAD entitlement management FPGA: field programmable gate array FPU: floating point processing unit GDPR: general data protection regulation GPU: graphics processing unit GUI: graphical user interface HTTPS: hypertext transfer protocol, secure IaaS or IAAS: infrastructure as a service JIT: just in time LAN: local area network MEM: Microsoft Endpoint Manager MSE: Microsoft Expert OS: operating system PaaS or PAAS: platform as a service RAM: random access memory ROM: read only memory TPU: tensor processing unit UEFI: unified extensible firmware interface UI: user interface WAN: wide area network XTAP: cross-tenant access policy Some additional terminology Reference is made herein to exemplary embodiments such as shown in the drawings and specific language will be used herein to describe the same. Changes and further modifications apparent to one of ordinary skill in the relevant art, however, will be considered within the scope of the claims and the abstract principles shown by the specific embodiments herein disclosed.
[0198] The meanings of terms are set forth in this disclosure, and the claims should be read in light of these explications. Particular examples are given, but one of skill in the relevant art will understand that other examples can also fall within the meaning of the terms used and within the scope of one or more claims. The terms do not necessarily have the same meaning as they do in common usage (particularly non-technical usage), or in usage in a particular industry, or in a particular dictionary or set of dictionaries. Reference numerals can be used with various phrases to help illustrate the scope of the terms. Sharing reference numerals does not necessarily mean that every aspect, feature, or limitation of every item referenced by the reference numeral must be shared. Omitting reference numerals from a given text does not necessarily mean that the content of the drawing is not discussed by the text. This disclosure asserts and exercises a right to select and use a particular and selected dictionary compilation. The terms that are cited are explicitly defined, but the terms can also be implicitly defined without the use of quotation marks. The terms can be explicitly or implicitly defined in the detailed description and / or elsewhere in the application file.
[0199] A “computer system” (also referred to as a “computing system”) can include, for example, one or more servers, motherboards, processing nodes, laptop computers, tablet computers, personal computers (portable or non-portable), personal digital assistants, smartphones, smartwatches, smartbands, cell or mobile phones, other mobile devices having at least a processor and memory, video game systems, augmented reality systems, holographic projection systems, televisions, wearable computing systems, and / or other devices that provide one or more processors that are at least partially controlled by instructions. The instructions can be in the form of firmware or other software in memory and / or dedicated circuitry.
[0200] A "multithreaded" computer system is a computer system that supports multiple threads of execution. The term "thread" is to be understood to include code that is capable of or subject to scheduling and possibly synchronization. Outside of this disclosure, threads can also be known by another name, such as "tasks," "processes," or "coroutines." However, a distinction is made herein between threads and processes, as threads define execution paths within a process. Also, threads of a process share a given address space, while different processes have different respective address spaces. Threads of a process can run in parallel, sequentially, or in a combination of parallel and sequential execution (e.g., time-slicing).
[0201] A "processor" is a thread processing unit, such as a core in a simultaneous multi-threading implementation. A processor includes hardware. A given chip can host one or more processors. Processors can be general purpose, or they can be customized for a particular use, such as vector processing, graphics processing, signal processing, floating point arithmetic processing, encryption, I / O processing, machine learning, etc.
[0202] A "kernel" includes an operating system, a hypervisor, a virtual machine, BIOS or UEFI code, and similar hardware interface software.
[0203] "Code" denotes processor instructions, data (which includes constants, variables, and data structures), or both instructions and data. "Code" and "software" are used interchangeably herein. Executable code, interpreted code, and firmware are some examples of code.
[0204] A "program" is used broadly herein to include applications, kernels, drivers, interrupt handlers, firmware, state machines, libraries, and other code that is written by a programmer (also referred to as a developer) and / or generated by a compiler or other tool and that participates in the processing of an electronic device.
[0205] A "routine" is a piece of callable code that typically returns control to the instruction after the point in program execution at which the routine was invoked. Depending on the terminology used, sometimes a distinction is made between "functions" and "procedures": functions typically return a value, while procedures do not. As used herein, "routine" includes both functions and procedures. A routine can have code that returns a value (e.g., sin(x)), or it can simply return without providing a value (e.g., a null function).
[0206] A "service" refers to a consumable program offering in a cloud computing environment or other network or computing system environment that provides resources to multiple programs or provides access to resources to multiple programs, or both. A service implementation can itself include multiple applications or other programs.
[0207] “Cloud” refers to pooled resources for computation, storage, and networking that are flexibly available for measured on-demand services. Cloud 136 can be private, public, community, or hybrid, and cloud services can be provided in the form of infrastructure as a service (IaaS), platform as a service (PaaS), software as a service (SaaS), or another service. Unless otherwise noted, any discussion of reading from or writing to a file includes reading / writing a local file or reading / writing over a network, which can be a cloud network or other network, or both (local and networked read / write). Cloud can also be referred to as “cloud environment” or “cloud computing environment.”
[0208] “Access” to a computing resource includes a permission or other ability to read, modify, write, execute, move, delete, create, or otherwise utilize the resource. Attempted access can be explicitly distinguished from actual access, but “access” without the “attempted” qualifier includes both attempted access and actual performed or provided access.
[0209] In this document, activity of a user refers to activity of a user device or activity of a user account, or activity of software on behalf of a user, or activity of hardware on behalf of a user. Activity is represented by digital data or machine operations in a computing system, or both. Activity within the scope of any claim of this disclosure excludes human action itself. Thus, software or hardware activity “on behalf of a user” refers to software or hardware activity on behalf of a user device or on behalf of a user account or on behalf of another computing machine or computing artifact, and thus does not bring human action itself within the scope of any embodiment or any claim.
[0210] “Digital data” refers to data in a computing system, not data written on paper or ideas in a human mind, for example. Similarly, “digital storage” refers to non-living devices, such as computing storage hardware, not human or other biological memory.
[0211] As used herein, “comprises” or “comprising” allows additional elements (i.e., components).
[0212] “Optimization” means improvement, not necessarily perfection. For example, a program or algorithm that has been optimized can be further improved.
[0213] “Process” is sometimes used as a term in the field of computing science and encompasses, in that technical sense, a computing resource user which can also be included or referred to as, for example, a co-routine, thread, task, interrupt handler, application process, kernel process, process, or object method. Indeed, a “process” is a computing entity identified by a system utility such as Windows® Task Manager, Linux® ps, or similar utility in other operating system environments (marks of Microsoft Corporation, Linus Torvalds, respectively). “Process” can also be used as a patent law term, e.g., to describe a process claim rather than a system claim or an article of manufacture (configured storage medium) claim. Similarly, “method” is used herein primarily as a technical term in the field of computing science (a “routine”), but it is also a patent law term (similar to “process”). “Process” and “method” in the patent law sense are used interchangeably herein. Those skilled in the art will understand the intended meaning in a particular instance and will also understand that a given claimed process or method (in the patent law sense) can sometimes be implemented using one or more processes or methods (in the computing science sense).
[0214] “Automatically” means by use of automation (e.g., general computing hardware configured by software for the particular operation and technical effect discussed herein) as opposed to without automation. In particular, steps performed “automatically” are not performed by hand on paper or in a person’s mind, although they can be initiated by a human or interactively directed by a human. The automatic steps are performed with a machine in order to obtain one or more technical effects that would not be achieved without the technical interaction provided thereby. The steps performed automatically are presumed to include at least one operation that is performed proactively.
[0215] Unless otherwise stated, in all examples, a conditional access policy impediment change is a change that impedes authorized access by a user from an assistant tenant to a focus tenant, a conditional access policy impediment addition is an addition of a conditional access policy that impedes authorized access by a user from an assistant tenant to a focus tenant, and a cross-tenant role assignment impediment change is a change that impedes authorized access by a user from an assistant tenant to a focus tenant. Here, as elsewhere herein, “by a user” means by a user device, or by a user account, or by software on behalf of a user, or by hardware on behalf of a user. Also, as elsewhere herein, authorized access by a user from an assistant tenant to a focus tenant is also more simply referred to as “authorized access from an assistant tenant to a focus tenant.”
[0216] In all examples, unless otherwise stated, “impede” means block, slow, obstruct, hinder, or impede.
[0217] The terms“cross tenant” and“cross-tenant” are used interchangeably herein.
[0218] Those skilled in the art understand that technical effects are the putative purpose of technical embodiments. For example, the fact that computation is involved only in embodiments, and that some computation can also be performed without technical components (e.g., by paper and pencil, or even as mental steps), does not eliminate the existence of technical effects or change the specific and technical nature of the embodiments, especially in real-world embodiment implementations. SCTA operations (e.g., reading or modifying identity provider 506 entries, analyzing 322 policies 138 for access impediments 310 impact, and many other operations discussed herein whether or not shown in the drawings) are understood to be digital in nature. Even in the hypothetical prototyping case, human thought cannot directly interface with a CPU or other processor or with RAM or other digital storage to read and write the necessary data to perform the SCTA steps 700 taught herein, much less in real-world large computing environments of embodiments. These will be well understood by those of skill in the art in view of this disclosure.
[0219] “Computational ly” also means that a computing device (at least a processor plus memory) is being used, and excludes obtaining a result by human thought alone or by human action alone. For example, doing arithmetic with paper and pencil is not doing arithmetic computationally as understood herein. Computing results faster, more extensively, more deeply, more accurately, more consistently, more comprehensively, and / or otherwise providing technical effects beyond the range of human performance alone. A“computational step” is a step performed computationally. Neither“automatically” nor“computationally” necessarily means“immediately.”“Computationally” and“automatically” are used interchangeably herein.
[0220] “Proactively” means without a direct request from a user. In fact, a user can not even be aware that a proactive step of an embodiment is possible until the result of the step is presented to the user. Unless otherwise noted, any computational and / or automatic steps described herein can also be done proactively.
[0221] “Based on” means based on at least and not exclusively. Thus, a computation based on X depends on X at least and can also depend on Y.
[0222] Throughout this document, the optional plural“s” is used to mean that one or more of the indicated feature is present. For example,“processor(s)” means“one or more processors” or equivalently“at least one processor.”
[0223] “At least one of” in a list of items means one item of the list, or two items of the list, or three items of the list, and so on, up to including all N items, where the list is a list of N items. In embodiments, the presence of an item in a list does not require the presence of the item (or examination for the item). For example, if an embodiment of a system is described herein as including at least one of A, B, C, or D, a system that includes A but does not examine B or C or D is an embodiment, and a system that includes A and also includes B but does not include or examine C or D is also an embodiment. Similar understandings apply to items that are steps or step portions or options in a method embodiment. This is not a complete list of all possibilities; it is provided merely to help understand the scope of “at least one” as intended herein.
[0224] For purposes of United States law and practice, the use of the word “step” in this document, in a claim or elsewhere, is not intended to invoke 35 U.S.C. § 112, paragraph 6 / 35 U.S.C. § 112(f) claim interpretation. This is hereby expressly contradicted.
[0225] For purposes of United States law and practice, claims are not intended to be interpreted under the component-plus-function claim interpretation unless they use the phrase “means for.” Claim language that is intended to be interpreted as component-plus-function language, if any, will be expressly recited using the phrase “means for.” When a component-plus-function interpretation is applicable, whether by use of “means for” and / or by judicial interpretation of the claim language, the component for which a given noun or a given verb is recited in the specification shall be understood as being associated with the claim language, and linked together herein by virtue of any one of the following: occurrence within the same block in a block diagram of the drawings, representation by the same name, representation by the same reference number, functional relationship depicted in any drawing, functional relationship present in the text of this disclosure. For example, if a claim limitation recites “zac widget” and the claim limitation is subject to component-plus-function interpretation, then all structures identified anywhere in the specification that are any drawing block, paragraph, or example that refers to “zac widget,” or all structures linked together by any drawing reference number assigned to a zac widget, or all structures disclosed as having a functional relationship to a zac widget structure or operation, will be considered part of the structure identified in the application for a zac widget, and will help define the set of equivalents for a zac widget structure.
[0226] Those skilled in the art will recognize that the present disclosure discusses various data values and data structures, and recognizes that these items reside in memory (RAM, disk, etc.), thereby configuring the memory. Those skilled in the art will also recognize that the present disclosure discusses various algorithmic steps to be embodied in executable code in a given implementation, and that such code also resides in memory, and it effectively configures any general purpose processor executing it, thereby transforming it from a general purpose processor into a special purpose processor as functional hardware.
[0227] Thus, those skilled in the art will not consider the memory recited in (a) and the data structures or data values or code recited in (b) to be non-overlapping items. The data structures and data values and code are understood to reside in memory even when the recitation of the claim does not explicitly recite the residence of each data structure or data value or the recited code segment. Thus, no explicit recitation of such residence is required. However, they are not prohibited either, and one or both alternative references can exist to emphasize that all other data values and data structures and code are not excluded from residence. Likewise, the code functionality recited in the claim is understood to configure a processor regardless of whether the quality of the configuration is explicitly recited in the claim.
[0228] Throughout this document, unless explicitly stated otherwise, any reference to a step in a process assumes that the step can be performed directly by the interested party and / or indirectly by a party through intervening mechanisms and / or intervening entities and still be within the scope of the step. That is, unless direct performance is an explicitly stated requirement, the interested party is not required to perform the step directly. For example, a computing step (such as accessing, adding, alerting, analyzing, auditing, checking, comparing, constraining, correlating, creating, deleting, detecting, executing, improving, inspecting, investigating, mitigating, modifying, monitoring, moving away, joining, performing, receiving, requesting, responding, setting, tracking, using (as well as accessing, being accessed, adding, being added, etc.)) on behalf of the interested party with respect to a destination or other principal can involve intermediate actions such as the aforementioned actions by some other party or mechanism or such as forwarding, copying, uploading, downloading, encoding, decoding, compressing, decompressing, encrypting, decrypting, authenticating, invoking, etc., including any action recited in this document, still be understood as performed directly by the interested party or on behalf of the interested party. The example verbs listed here can overlap in meaning or even be synonyms; the separate verb names do not indicate separate functionality in each case.
[0229] For example, whenever a component (e.g., a computer-readable medium) is referenced which can be accessed by a processor, what is actually meant is a physical computer-readable medium, such as the physical computer-readable storage media described above. However, such a component is also to be understood as somehow being accessible by the processor, such as being accessible by the processor via one or more buses, network connections, physical connections to I / O components, etc. As an example, when the processor reads a component (e.g., when the processor reads a record from a database, when the processor reads a number from a register, when the processor reads a bit from a cache), the processor is accessing the component as the component is present in the computer-readable medium located in a computer memory (e.g., as presented by a physical computer-readable storage medium). Therefore, the computer-readable media, the computer-readable storage media, and the storage devices, as used in herein, are to be construed to cover a physical computer-readable medium (e.g., any physical computer-readable storage medium) that can be accessed by a processor, as opposed to being confined to a signal per se or an energy waver per se. Thus, the computer-readable media, the computer-readable storage media, and the storage devices as used herein can each additionally be construed as meaning only a non-transitory computer-readable medium. The term "non-transitory," as used herein with respect to a computer- readable medium, does not encompass a propagating signal per se (e.g., a modulated data signal), but instead encompasses a physical computer-readable storage medium.
[0230] Furthermore, and unless specifically stated otherwise in the claims, "computer-readable medium" refers to a physical computer-readable medium, as opposed to being confined to a signal per se or an energy waver per se. Moreover, and unless specifically stated otherwise in the claims, the phrase "computer-readable medium" does not include a transitory propagating signal per se (e.g., a modulated data signal).
[0231] An "embodiment" herein is an example. The term "embodiment" is not interchangeable with the term "invention." Embodiments can freely share or borrow aspects to create other embodiments (assuming the result is operable), even if the combination of resulting aspects is not explicitly described herein. It is unnecessary for every allowed combination to be explicitly described, and would be contrary to the strategy of recognizing that the patent specification is written for the skilled artisan. Formal combinatorial calculations and informal common sense regarding the number of possible combinations resulting from even a small number of combinable features will indicate that there are a large number of combinations of aspects described herein. Therefore, requiring explicit recitation of every combination would be contrary to the strategy of requiring the patent specification to be concise, as well as the reader being familiar with the relevant art.
[0232] List of Reference Numerals The following list is provided for the convenience and support of the drawings and as part of the specification text, which describes aspects of embodiments by reference to a number of items. Items not listed here can still be part of a given embodiment. For better readability of the text, some but not all references to items in the text are recited near the given reference numeral. The same reference numeral can be used to refer to different examples or different instances of a given item. The list of reference numerals is: 100 operating environment, also called computing environment; includes one or more systems 102 101 machine in system 102, e.g., any device having at least a processor 110 and memory 112 and also having a distinct identifier such as an IP address or MAC (media access control) address, can be a physical machine or a virtual machine implemented on physical hardware 102 computer system, also called "system of computation" or "computing system," and when in a network can be called a "node" 104 user, e.g., a user that enhances system 202 105 user account, as represented in a computing system 106 peripheral device 108 network, generally including e.g., LAN, WAN, software-defined network, cloud, and other wired or wireless networks 110 processor or processor group; includes hardware 112 computer-readable storage medium, e.g., RAM, hard disk 114 removable configured computer-readable storage medium 116 instructions that can be executed with a processor; can be on removable storage media or in other memory (volatile or non-volatile or both) 118 digital data in system 102; data structures, values, source code, and other examples are discussed herein 120 kernel, e.g., operating system, BIOS, UEFI, device drivers; also refers to execution engines such as language runtimes 122 software tool, software application, security control; of computation 124 tenant in a multi-tenant cloud computing environment; a collection of computing resources at a level between an individual user and the cloud as a whole 126 display screen, also called "display" 128 computing hardware, not associated with reference numerals 106, 108, 110, 112, 114 130 audit, as represented in a computing system; 130 refers to the keeping of log of audit events 132 and the computing activities of creating, maintaining, or analyzing such logged events 132 computing event, as represented in a computing system log 134 user role, as represented in a computing system 136 cloud, also called cloud environment or cloud computing environment 138 access policy, as represented in a computing system 202 enhanced computing system, i.e., system 102 enhanced with functionality 204 taught herein 204 a secure cross-tenant access function (also "SCTA function"), e.g., software or special-purpose hardware that performs or is configured to perform steps 302 and 602, or steps 304 and 602, or steps 302 and 304 and 602, or steps 602 and 604, or steps 602 and 306, or performs or is configured to perform the first disclosed novel method 700 or computing cross-tenant access protection activities, or any software or hardware that first disclosed herein that computes cross-tenant access activities.
[0233] 206 in computing protecting access, also referred to as security as a feature of a computing system, and security measures 208 cross-tenant (also "cross-tenant"), i.e., from or on behalf of one tenant to or on behalf of another tenant 210 access in or to a computing system; refers to a computing activity or instance of a computing activity or both per context 212 a focused tenant 124 in a cloud computing environment 214 an assistant tenant 124 in a cloud computing environment; in some cases, a given tenant can be a focused tenant in one scenario and also an assistant tenant in another scenario 216 an SCTA component in a computing system, e.g., services 506, 508 and other software that when executed provides function 204, data structures that support or implement function 204, such as 134, 138, 326, 402, 408, 430, 506, 530, streams 524, 526, 528 that support or implement function 204 302 in computing monitoring policy 138, e.g., by polling, by a callback or hook on a routine configured to access policy 138, by scanning logs for events corresponding to policy access, or via a policy management API 304 in computing tracking role 134, e.g., by polling, by a callback or hook on a routine configured to access role 134, by scanning logs for events corresponding to role access, or via a role management API 306 in computing alerting, e.g., by sending an email or text message, by modifying a GUI, or both 308 computing system access that is authorized in a given scenario 310 in computing impeding authorized access; a threat to the scope of authorized access that is identified is also an impeding, and a case where the scope of authorized access is reduced is also an impeding 312 a case management subsystem of a computing system; also referred to as a case management system or tool 314 in computing correlating events from logs of different tenants, also referred to as producing correlated audits 316 Audit-related subsystem of the computing system; also called an audit-related system or tool 318 Computing system roles 134 that are authorized in a given scenario 320 List (not necessarily ordered) of authorized roles; numeric 322 Computing analysis of role change or policy change or both to determine whether it involves a hindrance 310; 322 also refers to the numeric result of such computing activity; in some embodiments, including adaptation of assumptions analysis 324 Scenario analysis subsystem of the computing system; also called a scenario analysis system or tool 326 Security group data structure in the computing system, also called a security group 328 Interface generally in the computing system; computational, numeric 402 Conditional access policy in the computing system 404 Scope of a policy in the computing system, e.g., which activities are allowed or forbidden 406 User computing activity generally; excludes human behavior per se 408 Cross-tenant role assignment in the computing system 410 Security command in the computing system 412 Command in the computing system 414 Fraudulent (unauthorized) role 134 416 Managed service in the computing system 418 Managed service command in the computing system 420 Zero-residency characteristic of an access session, as opposed to a persistent access that involves a new request for each access session 422 Time-limited characteristic of an access session, as opposed to a permanent or unlimited time that automatically causes an access session to expire after a specified time has elapsed 424 Access session (also called an access) that is zero-residency or time-limited or both 426 Managed device 101, as opposed to an unmanaged device; managed devices are managed, e.g., as to what software they contain, what security controls they are subject to, and auditing 428 Granular delegated administration privilege (GDAP) characteristic of a security group 430 GDAP or DAP group in the computing system 432 Access request; computing activity or data structure 436 Access scope, as represented in the computing system 438 Resource in the computing system, e.g., hardware, software, data; excludes biological or intellectual 440 IP address, as represented in the computing system 442 a range or other collection of one or more IP addresses, as represented in a computing system 444 a change to a policy 138 or role 134, as represented in a computing system; content modification, priority modification, and content deletion are examples of changes 446 an addition of a policy 138 or role 134, as represented in a computing system 500 a dataflow graph; with Figure 5 dataflow Figure 1 system architecture 502 computationally joining to a managed service 504 computationally creating a security group 506 a directory service, also known as an identity service, for example, the Azure® Active Directory® service (a mark of Microsoft Corporation) or an LDAP (Lightweight Directory Access Protocol) service 508 an AOBO (i.e., action on behalf of, also action on behalf of management) service 510 computationally creating an access package or other access or enablement data structure 512 computationally establishing cross-tenant role assignments 514 an access or enablement service 516 an access request response data structure or computing activity 518 computationally adding a user to a security group 520 computationally leaving tenant access in an assistant tenant 522 computationally leaving cross-tenant access in a focused tenant 524 cross-tenant access join phase 526 cross-tenant access focused tenant resource access phase 528 cross-tenant access leave phase 530 an access package or other access or enablement data structure 600 a flowchart; 600 also relates to a cross-tenant access method, the method being Figure 6 flowchart of or any variant of Figure 6 the flowchart described herein 602 computationally detecting a hindrance 310 or another influence or potential influence on a change or addition to an access policy 138 or role assignment 408 in a computing system, for example, by detecting a removal or range reduction of an access token, access duration, or access package, or by detecting a role 414 that is not in a list 320 of authorized roles 604 computationally modifying another aspect of an access policy 138, role assignment 408, or cross-tenant access range 436, for example, an access duration 700 flowchart; 700 also refers to methods shown by Figure 7 flowchart shows or is consistent with Figure 7 flow Figure 1 cross-tenant access method that incorporates Figure 5 , Figure 6 , Figures 8 to 14 and information in other steps taught herein, or methods shown by any variant of the flowchart described herein Figure 7 flowchart shows or is consistent with methods shown by 702 computationally check for changes or additions to access policies 138, e.g., based on access timestamp, history, and current policy hash comparison, or other mechanisms 704 computationally check role assignments 408, e.g., via API 706 computationally detect fraudulent roles 414 that are not in the list of authorized roles 320 708 computationally receive commands 412, e.g., via user interface API or other API 710 computationally execute commands 412, e.g., via kernel 120, tool 122, or other software 712 computationally constrain authorized access, e.g., by denying or terminating access if constraints are not met, such as IP address or hosting device or access duration constraints 714 computationally use security groups, e.g., to constrain access 716 computationally use GDAP groups, e.g., to constrain access 718 computationally mitigate security vulnerabilities, e.g., by reducing attack surface, fixing damage caused by attacks, adding additional layers of defense against attacks, or closing security holes 720 computationally investigate security vulnerabilities, e.g., by analyzing logs or checking for vulnerability markers in the computing system 722 computationally receive access requests, e.g., via user interface API or other API; examples of access requests are identified 724 computationally perform activities in the tenant 726 computationally improve security of the tenant, e.g., by mitigating 718 security vulnerabilities, or by reducing attack surface regardless of any particular known vulnerabilities, or by increasing authentication requirements to access tenant resources 728 any step or item discussed in this disclosure that is not assigned some other reference number; thus, 728 can be explicitly shown as a reference number for various steps or items or both, and can be added as a reference number for various steps or items or both (in this disclosure or any subsequent patent application claiming priority to this disclosure) without adding new subject matter 800 architectural dataflow diagram; 800 also refers to methods shown byFigure 8 or any variant of Figure 8 the cross-tenant access method and structure shown or consistent with 802 management portal; computed 804 hosted response customer API; computed 806 create or modify one or more asset exclusion groups 828 on the compute 808 add one or more assets 830 to a group on the compute 810 security device group, as represented in the computing system 812 device group API; computed 814 create one or more device asset exclusion groups on the compute 816 add one or more device assets to a device exclusion group on the compute 818 security user account group, also referred to as a user group, as represented in the computing system 820 user group API; computed 822 create one or more user asset exclusion groups on the compute 824 add one or more user identity assets to a user identity exclusion group on the compute 826 store exclusion groups 828 on the compute, for example in an asset exclusion database 842 828 asset 830 exclusion list, as represented in the computing system; also referred to as an asset 830 exclusion group; for example, implemented using a security device group, a security user identity group, or a tag such as a high-priority device tag or a high-priority user tag 830 asset in the computing system; computed or digital or both; resource 438 is not necessarily an asset 830 to exclude 832 generate an authorization error on the compute 834 authorization error, as represented in the computing system 836 check, inspect for, or otherwise verify GDAP relationships on the compute 838 membership of assets in exclusion groups, as represented in the computing system 840 GDAP relationship storage in the computing system 842 asset exclusion database in the computing system 900 architecture data flow diagram; 900 also refers to the architecture data flow diagram shown in Figure 9 or any variant of Figure 9 the cross-tenant access method and structure shown or consistent with 902 analyst portal; computed 904 GDAP token; digital 906 digital identity provider in a computing system 908 managed response to a security incident (e.g., by an analyst or other security expert), as represented in a computing system; also referred to as a remediation action 910 managed response specialist API 912 asset API, e.g., for asset creation, modification, movement, status, or other asset management operations in a computing system 914 computationally obtaining an asset (e.g., by obtaining an asset identifier) 916 computationally obtaining an asset exclusion (e.g., by obtaining an asset exclusion group identifier or content) 918 computationally checking, inspecting for, or otherwise verifying device membership in a group 920 computationally checking, inspecting for, or otherwise verifying user membership in a group 922 generally security tool; computational 924 endpoint security tool; computational 926 identity security tool; computational 928 application security tool; computational 930 device action in a computing system 932 identity action in a computing system 934 application action in a computing system 936 remediation action in a computing system to provide or protect cybersecurity 938 computationally filtering a collection of assets; also refers to the digital result of such computational activity 940 managed service role in a computing system 942 built-in access that allows cross-tenant remediation actions without requiring additional logins after, e.g., analyst portal login 944 access requirements represented or implemented (or both) in a computing system, e.g., multi-factor authentication, activity logging, use of specific network protocols, avoidance of specific network protocols, redirection prohibitions, forwarding prohibitions, use of specific encryption protocols, avoidance of specific encryption protocols, authorized device usage, authorized locations, use of specific security tools or security protocols, etc. 946 authorizations represented or implemented (or both) in a computing system, e.g., authentication, permission compliance, or both 1000 architectural dataflow diagram; 1000 also refers to the cross-tenant access method and structure shown by Figure 10 or any variant of Figure 10 the cross-tenant access method and structure shown or consistent with 1002 cross-tenant product role assignments, as represented in a computing system Cross-tenant workload role assignment functionality in the 1004 computing system 1006 Security Group "Member" Routine 1008 User Permissions, as represented in the computing system 1010 Permission Calculation Software Workload rule function in 1012 computing system 1014 obtains cross-tenant role assignments computationally. 1016 calculates to obtain partner tenant group membership or membership status. 1018 obtains tokens computationally from the identity provider. 1020 Software products, such as software and Software as a Service 1022 logged into the computing system. 1100 architecture data flow diagram; 1100 also refers to the data flow diagram of the architecture. Figure 11 Or as described in this article Figure 11 Any variations thereof demonstrate or are consistent with cross-tenant access methods and structures 1102 Customer Global Administrator, as represented in the computing system 1104 Workload Cross-Tenant Role Assignment API 1106 Storage role allocation in computation 1108 Customer Administrator's Permissions, as indicated in the computing system 1110 is computationally permitted to store data. Permitted storage in 1112 computing systems 1114. Computationally validate cross-tenant role assignment. 1116 Computationally update workload cross-tenant role assignments 1200 architecture dataflow diagram; 1200 also refers to the dataflow of... Figure 12 Or as described in this article Figure 12 Any variations thereof demonstrate or are consistent with cross-tenant access methods and structures 1202 obtains tokens computationally. 1204 is a calculation method for product API certification. 1206 checks the role allocation in calculations. 1208 computationally obtains a representative (OBO) token. 1210 performs a computational check on the security group membership for role assignment. 1212 has obtained valid role membership in calculation. 1214 Implement role-based access control in computing. 1300 flowchart; 1300 also involves... Figure 13 Flowchart or the description in this article Figure 13Cross-tenant access methods shown by or consistent with any variant of the flowchart 1302 computationally intercept an access attempt, e.g., an access request, e.g., via an API, shim, or security control such as a firewall, packet inspection tool, leak detection tool, or intrusion detection tool; identify an example of an access request 1306 computationally determine an exclusion status of the asset, e.g., by checking membership of the asset in an exclusion group, or based on an exclusion flag or exclusion attribute or label stored in or associated with the asset 1308 an exclusion status of the asset, as represented in the computing system; indicates whether the asset is excluded from access by cross-tenant remediation activities 1310 computationally limit access to the asset by disallowing the requested access or by conditioning the requested access according to some additional requirement such as multi-factor authentication, increased logging, etc. 1400 flowchart; 1400 also refers to a method of cross-tenant access Figure 14 flowchart or described herein Figure 14 Cross-tenant access methods shown by or consistent with any variant of the flowchart 1406 computationally determine an inclusion status of the asset with respect to a product-specific role, e.g., by checking a catalog, manifest, or build file of associations between assets and products (tools, solutions) of which the asset is a part or for which the asset is supporting 1408 a role inclusion status of the asset, as represented in the computing system; indicates whether the asset is covered by a policy associated with a role that is relevant to being accessed by cross-tenant remediation activities 1410 computationally enforce access to the asset according to the role 1002, e.g., by allowing the requested access, by disallowing the requested access, or by conditioning the requested access according to some additional requirement such as multi-factor authentication, increased logging, etc., depending on the inclusion of the asset with respect to the role CONCLUSION Some embodiments in cloud computing environment 100 include monitoring 302 conditional access policies 402 for changes 444 or additions 446 that impede 310 or threaten to impede authorized access 308 from assistant tenant 214 users to focused tenant 212 resources. In some embodiments, cross-tenant access security 700 includes tracking 304 role assignment lists 320 to detect 706 fraudulent roles 414, or to detect 602 role changes 444 such as role deletions, or both. In some embodiments, focused tenant events 132 and assistant tenant events 132 are correlated 314 in audit 130. In some embodiments, authorized access 308 is zero-resident time limited access 424. In some embodiments, authorized access 308 is constrained 712 to IP address ranges 442, or to logins from hosting devices 426, or both. In short, security measures 206, 216, 500, 700 are described that mitigate 726 accidental or surreptitious role or policy changes that would shut down or impede authorized cross-tenant access 308.
[0234] Embodiments are understood to also include or benefit from tested and appropriate security controls and privacy controls, such as the General Data Protection Regulation (GDPR). Use of the tools and techniques taught herein are compatible with use of such controls.
[0235] Although Microsoft technology is used in some motivating examples, the teachings herein are not limited to use in Microsoft-provided or managed technology. For example, the teachings can be embodied in software or services provided by other cloud service providers, under suitable license.
[0236] Although specific embodiments are explicitly illustrated and described herein as processes, configured storage media, or systems, it will be appreciated that discussion of one type of embodiment is generally extended to the other embodiment types, as well. For example, description of processes in conjunction with the drawings also facilitates description of configured storage media, and facilitates description of technical effects and operations of systems and manufacture as discussed in conjunction with other drawings. This is not meant to imply that any limitations from one embodiment must be read into another embodiment. In particular, processes are not necessarily limited to data structures and arrangements presented in systems or manufacture discussed, such as configured storage media.
[0237] Those skilled in the art will appreciate that implementation details can involve specific code, such as specific thresholds, comparisons, specific kinds of platforms or programming languages or architectures, specific scripts or other tasks, and specific computing environments, and thus need not appear in every embodiment. Those skilled in the art will also appreciate that program identifiers and some other terminology used in discussing details are implementation-specific, and thus need not be involved in every embodiment. However, such details, although they need not necessarily be present here, can help some readers by providing context and / or can illustrate some of the many possible implementations of the technology discussed herein.
[0238] Note that the items provided herein, including technical processes, technical effects, technical mechanisms, and all illustrative but non-exhaustive technical details of the claimed or claimable embodiments, those skilled in the art will understand that the present disclosure and the embodiments described herein do not involve subjects outside the technical field, or any ideas of themselves, such as primary or original reasons or motivations, or only results themselves, or spiritual processes or spiritual steps, or business methods or general economic practices, or only methods of organizing human activities, or natural laws themselves, or naturally occurring things or processes, or biological or biological parts, or mathematical formulas themselves, or software alone, or only conventional computers, or any completely imperceptible or any abstract concepts themselves, or trivial post-solution activities, or any methods completely implemented on unspecified devices, or any methods that fail to produce useful and specific results, or any pre-emptive claims to all fields of use, or any other subject matter that does not qualify for patent protection under the laws of the jurisdiction in which patent protection is sought.
[0239] Reference herein to an embodiment having some feature X and reference elsewhere herein to an embodiment having some feature Y does not exclude an embodiment having both feature X and feature Y in the present disclosure, unless such exclusion is explicitly stated in the present text. All possible negative claim limitations are within the scope of the present disclosure in the sense that any feature stated as part of an embodiment can also be explicitly removed from inclusion in another embodiment, even if no specific exclusion is given in any example herein. The term "embodiment" is used herein only as a more convenient form of "process, system, article of manufacture, configured computer-readable storage medium, and / or other example of the teachings herein applied in a manner consistent with applicable law". Thus, a given "embodiment" can include any combination of features disclosed herein, provided that the embodiment is consistent with at least one claim.
[0240] Not every item shown in the figures is required in every embodiment. Rather, embodiments can include items not explicitly shown in the figures. Although some possibilities are shown in text and in the figures, embodiments can depart from these examples. For example, a particular technical effect or technical feature of an example can be omitted, renamed, differently grouped, repeated, differently instantiated in hardware and / or software, or a mix of effects or features appearing in two or more examples. In some embodiments, functionality shown as being performed at one location can also be provided at a different location; those skilled in the art recognize that functional modules can be defined in a variety of ways in a given implementation without omitting a desired technical effect from a collection of interacting modules viewed as a whole. Different steps can be shown together in a single block in the figures for reasons of space or convenience, but can still be performed separately, e.g., one step can be performed without the other in a given performance of a method.
[0241] Reference signs have been attached to the drawings. Any apparent inconsistencies in the phrasing associated with a given reference sign in the drawings or in the text should be understood as simply broadening the scope referenced by that reference sign. Different instances of a given reference sign can refer to different embodiments, even if the same reference sign is used. Similarly, a given reference sign can be used to refer to a verb, a noun, and / or respective instances of each, e.g., a processor 110 can process 110 instructions by executing the instructions.
[0242] As used herein, terms such as “a,” “an,” and “the” include one or more of the items or steps referenced. In particular, reference to items or steps using a singular verb form encompasses the possibility of there being plural of the referenced items or steps and reference to items or steps using a plural verb form encompasses the possibility of there being one of the referenced items or steps. Similarly, “is” and other singular verb forms are to be interpreted to cover the possibility of “are” and other plural forms, where the context so allows, to avoid grammatical errors or misinterpretations.
[0243] Headings are for convenience only; information on a given topic can be found outside the section whose heading indicates that topic.
[0244] All claims and the abstract filed with the application are part of the specification. The abstract is provided for convenience and compliance with patent office requirements; it is not intended to be limiting as to the scope of the claims. Similarly, the summary is provided for convenience and is not intended to limit the claims or other portions of the specification unless otherwise indicated. The claims should be interpreted as including what is specifically claimed as well as what is constructively claimed under 35 U.S.C. § 112 et seq. and 35 U.S.C. § 121; no admission is made that any portion of the specification other than the patent claims must be construed as constituting prior art.
[0245] To the extent any term implies or otherwise refers to an industry standard, and to the extent applicable law requires identification of a particular version of such standard, the present disclosure shall be understood to refer to the most recent version of that standard that had been published in at least draft form (if newer, final form prior) as of the earliest priority date of the present disclosure, in accordance with applicable patent law.
[0246] While exemplary embodiments have been shown and described above, it will be apparent to those having ordinary skill in the art that a number of changes, modifications, or alterations to the embodiments described herein can be made while remaining within the spirit of the principles and concepts expressed in the claims. Although the subject matter has been described in language specific to structural features and / or programmatic acts, it is to be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. Each of the hand means or aspects or technical effects identified in a given definition or example is not necessarily present or used in every embodiment. Rather, the specific features and acts described are disclosed as examples in providing for the claims.
[0247] All changes that come within the meaning and range of equivalency of the claims are to be embraced within their scope.
Claims
1. A network security method for focused secure cross-tenant access, the method comprising, computationally: During the remedial action (908), an attempt to access the asset (830) across tenants (308) is identified (722 or 1302); and The attempted cross-tenant access is computationally restricted (1310) based on at least one of the following: a product-specific cross-tenant role (1002) covering the asset, or an exclusion group (828) containing the asset.
2. The method according to claim 1, further comprising: Create an exclusion group for the asset described in (806) in computation, or modify the exclusion group for the asset described in (806) in computation.
3. The method according to claim 1 or 2, further comprising: Create (512) the product-specific cross-tenant role on a computational basis, or modify (512) the product-specific cross-tenant role on a computational basis.
4. The method of claim 3, wherein creating or modifying the product-specific cross-tenant role computationally comprises at least one of the following: Use (512) to represent accessing service (508); or Utilize (512) workload cross-tenant role management service (1104).
5. The method according to any one of claims 1 to 4, further comprising at least one of the following: providing (900) cross-tenant built-in (942) access (308) to assets in the focused tenant after authorization in the assistant tenant (214), or utilizing (900) cross-tenant built-in (942) access (308) to assets in the focused tenant after authorization in the assistant tenant (214).
6. The method according to any one of claims 1 to 5, further comprising at least one of the following: Obtain a (1018) granular delegation privilege token (904) from the identity provider; Use the granular delegation management privilege token (904) to query (918) the device API (812); or Use the granular delegation management privilege token (904) to query (920) the identity API (820).
7. A computing system (202) configured for focused secure cross-tenant access, the system comprising: Digital memory (112); A processor set, including at least one processor (110), operatively communicating with the digital memory, the processor set being configured to perform a focused security cross-tenant access method (700), the method (700) including: identifying (722 or 1302) an attempted cross-tenant access to an asset (830) during a remedial action (908) (308), and restricting (1310) the attempted cross-tenant access based on at least one of: a product-specific cross-tenant role (1002) covering the asset, or an exclusion group (828) containing the asset.
8. The system of claim 7, wherein the processor set is further configured to provide (900) or utilize (900) cross-tenant built-in (942) access (308) to the assets of the focused tenant (212) after authorization in the assistant tenant (214).
9. The system of claim 7 or claim 8, wherein the processor set is further configured to: determine (1306) that an asset includes an excluded asset based at least on the exclusion group; and, in response, restrict (1310) access to the excluded asset during a cross-tenant remedial action (908).
10. The system of claim 9, wherein the exclusion group includes at least one of the following: a device group (810) or a user account group (818).
11. The system according to any one of claims 7 to 10, further comprising built-in access to at least one of the following cross-tenant remediation actions: Endpoint security tools (924); Identity security tools (926); or Application security tools (928).
12. The system according to any one of claims 7 to 11 further includes cross-tenant role-allocated storage (1106).
13. The system according to any one of claims 7 to 12 further includes a granular delegation management privilege token (904).
14. The system according to any one of claims 7 to 13 further includes a permission calculation software component (1010), which, when executed, obtains (1016) a cross-tenant role assignment (408) and calculates (1010) user permissions (1008) at least based on the cross-tenant role assignment.
15. The system according to any one of claims 7 to 14 further includes a permission calculation software component (1010), which, when executed, obtains a partner tenant group membership (838) and calculates (1010) user permissions (1008) at least based on the partner tenant group membership.
16. A computer-readable storage device (114) configured with data and instructions, which, when executed by a processor (110), cause a computing system (202) to perform a focused secure cross-tenant access method (700), the method comprising: During the remedial action (908), identify (722 or 1302) the attempted cross-tenant access (308) to the asset (830); as well as The attempted cross-tenant access is computationally restricted (1310) based on at least one of the following: a product-specific cross-tenant role (1002) covering the asset, or an exclusion group (828) containing the asset.
17. The computer-readable storage device of claim 16, wherein the second asset (830) resides in a focused tenant (212), and the method further comprises at least one of the following: Based on the authorization in the assistant tenant (214), provide (900) cross-tenant built-in (942) access (308) to the second asset; or Based on the authorization in the assistant tenant (214), cross-tenant built-in (942) access (308) to the second asset is utilized (900).
18. The computer-readable storage device of claim 16 or claim 17, wherein the method further comprises at least one of the following: The exclusion status (1308) of the asset is determined (1306) at least based on the exclusion group; or The product-specific role status of the asset is determined (1406) at least based on the product-specific cross-tenant role (1408).
19. The computer-readable storage device according to any one of claims 16 to 18, wherein the method further comprises: Obtain a granular delegation privilege token (904) from the identity provider (906) (1018).
20. The computer-readable storage device according to any one of claims 16 to 19, wherein the method further comprises at least one of the following: Use the granular delegation privilege token (904) to query (918) the device API (812) for the asset; or Use the granular delegation privilege token (904) to query (920) the identity API (820) of the asset.