diff --git a/windows/security/book/cloud-services-protect-your-work-information.md b/windows/security/book/cloud-services-protect-your-work-information.md index b60212b493..7f7c6b180a 100644 --- a/windows/security/book/cloud-services-protect-your-work-information.md +++ b/windows/security/book/cloud-services-protect-your-work-information.md @@ -53,14 +53,9 @@ Every Windows device has a built-in local administrator account that must be sec ### Microsoft Entra Private Access -:::row::: - :::column span="1"::: -:::image type="content" source="images/microsoft-entra-private-access.png" alt-text="Logo of Microsoft Entra Private Access." border="false"::: - :::column-end::: - :::column span="3"::: - Microsoft Entra Private Access provides organizations the ability to manage and give users access to private or internal fully qualified domain names (FQDNs) and IP addresses. With Private Access, you can modernize how your organization's users access private apps and resources. Remote workers don't need to use a VPN to access these resources if they have the Global Secure Access Client installed. The client quietly and seamlessly connects them to the resources they need. - :::column-end::: -:::row-end::: +:::image type="icon" source="images/microsoft-entra-private-access.svg" border="false"::: + +Microsoft Entra Private Access provides organizations the ability to manage and give users access to private or internal fully qualified domain names (FQDNs) and IP addresses. With Private Access, you can modernize how your organization's users access private apps and resources. Remote workers don't need to use a VPN to access these resources if they have the Global Secure Access Client installed. The client quietly and seamlessly connects them to the resources they need. [!INCLUDE [learn-more](includes/learn-more.md)] @@ -68,14 +63,9 @@ Every Windows device has a built-in local administrator account that must be sec ### Microsoft Entra Internet Access -:::row::: - :::column span="1"::: -:::image type="content" source="images/microsoft-entra-internet-access.png" alt-text="Logo of Microsoft Entra Internet Access." border="false"::: - :::column-end::: - :::column span="3"::: - Microsoft Entra Internet Access provides an identity-centric Secure Web Gateway (SWG) solution for Software as a Service (SaaS) applications and other Internet traffic. It protects users, devices, and data from the Internet's wide threat landscape with best-in-class security controls and visibility through Traffic Logs. - :::column-end::: -:::row-end::: +:::image type="icon" source="images/microsoft-entra-internet-access.svg" border="false"::: + +Microsoft Entra Internet Access provides an identity-centric Secure Web Gateway (SWG) solution for Software as a Service (SaaS) applications and other Internet traffic. It protects users, devices, and data from the Internet's wide threat landscape with best-in-class security controls and visibility through Traffic Logs. > [!NOTE] > Both Microsoft Entra Private Access and Microsoft Entra Internet Access requires Microsoft Entra ID and Microsoft Entra Joined devices for deployment. The two solutions use the Global Secure Access client for Windows, which secures and controls the features. @@ -96,14 +86,9 @@ Available to any organization with a Microsoft Entra ID Premium[\[4\]](conc ## Azure Attestation service -:::row::: - :::column span="1"::: -:::image type="content" source="images/azure-attestation.png" alt-text="Logo of Azure Attestation service." border="false"::: - :::column-end::: - :::column span="3"::: - Remote attestation helps ensure that devices are compliant with security policies and are operating in a trusted state before they're allowed to access resources. Microsoft Intune[\[4\]](conclusion.md#footnote4) integrates with Azure Attestation service to review Windows device health comprehensively and connect this information with Microsoft Entra ID[\[4\]](conclusion.md#footnote4) Conditional Access. - :::column-end::: -:::row-end::: +:::image type="icon" source="images/azure-attestation.svg" border="false"::: + +Remote attestation helps ensure that devices are compliant with security policies and are operating in a trusted state before they're allowed to access resources. Microsoft Intune[\[4\]](conclusion.md#footnote4) integrates with Azure Attestation service to review Windows device health comprehensively and connect this information with Microsoft Entra ID[\[4\]](conclusion.md#footnote4) Conditional Access. **Attestation policies are configured in the Azure Attestation service which can then:** @@ -119,14 +104,9 @@ Once this verification is complete, the attestation service returns a signed rep ## Microsoft Defender for Endpoint -:::row::: - :::column span="1"::: -:::image type="content" source="images/defender-for-endpoint.png" alt-text="Logo of Microsoft Defender for Endpoint." border="false"::: - :::column-end::: - :::column span="3"::: - Microsoft Defender for Endpoint[\[4\]](conclusion.md#footnote4) is an enterprise endpoint detection and response solution that helps security teams detect, disrupt, investigate, and respond to advanced threats. Organizations can use the rich event data and attack insights Defender for Endpoint provides to investigate incidents. - :::column-end::: -:::row-end::: +:::image type="icon" source="images/defender-for-endpoint.svg" border="false"::: + +Microsoft Defender for Endpoint[\[4\]](conclusion.md#footnote4) is an enterprise endpoint detection and response solution that helps security teams detect, disrupt, investigate, and respond to advanced threats. Organizations can use the rich event data and attack insights Defender for Endpoint provides to investigate incidents. Defender for Endpoint brings together the following elements to provide a more complete picture of security incidents: @@ -174,14 +154,9 @@ Windows 11 supports the Remote Wipe configuration service provider (CSP) so that ## Microsoft Intune -:::row::: - :::column span="1"::: -:::image type="content" source="images/microsoft-intune.png" alt-text="Logo of Microsoft Intune." border="false"::: - :::column-end::: - :::column span="3"::: - Microsoft Intune[\[4\]](conclusion.md#footnote4) is a comprehensive cloud-native endpoint management solution that helps secure, deploy, and manage users, apps, and devices. Intune brings together technologies like Microsoft Configuration Manager and Windows Autopilot to simplify provisioning, configuration management, and software updates across the organization. - :::column-end::: -:::row-end::: +:::image type="icon" source="images/microsoft-intune.svg" border="false"::: + +Microsoft Intune[\[4\]](conclusion.md#footnote4) is a comprehensive cloud-native endpoint management solution that helps secure, deploy, and manage users, apps, and devices. Intune brings together technologies like Microsoft Configuration Manager and Windows Autopilot to simplify provisioning, configuration management, and software updates across the organization. Intune works with Microsoft Entra ID to manage security features and processes, including multifactor authentication and conditional access. @@ -207,14 +182,9 @@ With Windows enrollment attestation, Microsoft Entra and Microsoft Intune certif ### Microsoft Cloud PKI -:::row::: - :::column span="1"::: -:::image type="content" source="images/microsoft-cloud-pki.png" alt-text="Logo of Microsoft Cloud PKI." border="false"::: - :::column-end::: - :::column span="3"::: - Microsoft Cloud PKI is a cloud-based service included in the Microsoft Intune Suite[\[4\]](conclusion.md#footnote4) that simplifies and automates the management of a Public Key Infrastructure (PKI) for organizations. It eliminates the need for on-premises servers, hardware, and connectors, making it easier to set up and manage a PKI compared to, for instance, Microsoft Active Directory Certificate Services (AD CS) combined with the Certificate Connector for Microsoft Intune. - :::column-end::: -:::row-end::: +:::image type="icon" source="images/microsoft-cloud-pki.svg" border="false"::: + +Microsoft Cloud PKI is a cloud-based service included in the Microsoft Intune Suite[\[4\]](conclusion.md#footnote4) that simplifies and automates the management of a Public Key Infrastructure (PKI) for organizations. It eliminates the need for on-premises servers, hardware, and connectors, making it easier to set up and manage a PKI compared to, for instance, Microsoft Active Directory Certificate Services (AD CS) combined with the Certificate Connector for Microsoft Intune. Key features include: @@ -231,14 +201,9 @@ With Microsoft Cloud PKI, organizations can accelerate their digital transformat ### Endpoint Privilege Management (EPM) -:::row::: - :::column span="1"::: -:::image type="content" source="images/endpoint-privilege-management.png" alt-text="Logo of Endpoint Privilege Management." border="false"::: - :::column-end::: - :::column span="3"::: - Intune Endpoint Privilege Management supports organizations' Zero Trust journeys by helping them achieve a broad user base running with least privilege, while still permitting users to run elevated tasks allowed by the organization to remain productive. - :::column-end::: -:::row-end::: +:::image type="icon" source="images/endpoint-privilege-management.svg" border="false"::: + +Intune Endpoint Privilege Management supports organizations' Zero Trust journeys by helping them achieve a broad user base running with least privilege, while still permitting users to run elevated tasks allowed by the organization to remain productive. [!INCLUDE [learn-more](includes/learn-more.md)] @@ -349,14 +314,9 @@ By utilizing hotpatching through Windows Autopatch, the number of system restart ## OneDrive for work or school -:::row::: - :::column span="1"::: -:::image type="content" source="images/onedrive.png" alt-text="Logo of Onedrive." border="false"::: - :::column-end::: - :::column span="3"::: - OneDrive for work or school is a cloud storage service that allows users to store, share, and collaborate on files. It's a part of Microsoft 365 and is designed to help organizations protect their data and comply with regulations. OneDrive for work or school is protected both in transit and at rest. - :::column-end::: -:::row-end::: +:::image type="icon" source="images/onedrive.svg" border="false"::: + +OneDrive for work or school is a cloud storage service that allows users to store, share, and collaborate on files. It's a part of Microsoft 365 and is designed to help organizations protect their data and comply with regulations. OneDrive for work or school is protected both in transit and at rest. When data transits either into the service from clients or between datacenters, it's protected using transport layer security (TLS) encryption. OneDrive only permits secure access. @@ -375,8 +335,6 @@ There are several ways that OneDrive for work or school is protected at rest: ## Universal Print -:::image type="content" source="images/universal-print.svg" alt-text="Logo of Universal Print." border="false"::: - :::image type="icon" source="images/universal-print.svg" border="false"::: Universal Print eliminates the need for on-premises print servers. It also eliminates the need for print drivers from the users' Windows devices and makes the devices secure, reducing the malware attacks that typically exploit vulnerabilities in driver model. It enables Universal Print-ready printers (with native support) to connect directly to the Microsoft Cloud. All major printer OEMs have these [models][LINK-23]. It also supports existing printers by using the connector software that comes with Universal Print. diff --git a/windows/security/book/images/azure-attestation.png b/windows/security/book/images/azure-attestation.png deleted file mode 100644 index 0f2aa5aa89..0000000000 Binary files a/windows/security/book/images/azure-attestation.png and /dev/null differ diff --git a/windows/security/book/images/azure-attestation.svg b/windows/security/book/images/azure-attestation.svg new file mode 100644 index 0000000000..f37806a6ac --- /dev/null +++ b/windows/security/book/images/azure-attestation.svg @@ -0,0 +1,25 @@ + + + + + + + + + + + + + + + + + + + + + + + + + diff --git a/windows/security/book/images/defender-for-endpoint.png b/windows/security/book/images/defender-for-endpoint.png deleted file mode 100644 index 5436972929..0000000000 Binary files a/windows/security/book/images/defender-for-endpoint.png and /dev/null differ diff --git a/windows/security/book/images/defender-for-endpoint.svg b/windows/security/book/images/defender-for-endpoint.svg new file mode 100644 index 0000000000..ca634299dc --- /dev/null +++ b/windows/security/book/images/defender-for-endpoint.svg @@ -0,0 +1,10 @@ + + + + + + + + + + diff --git a/windows/security/book/images/endpoint-privilege-management.png b/windows/security/book/images/endpoint-privilege-management.png deleted file mode 100644 index 1b57dded9f..0000000000 Binary files a/windows/security/book/images/endpoint-privilege-management.png and /dev/null differ diff --git a/windows/security/book/images/endpoint-privilege-management.svg b/windows/security/book/images/endpoint-privilege-management.svg new file mode 100644 index 0000000000..ac2daa7e6a --- /dev/null +++ b/windows/security/book/images/endpoint-privilege-management.svg @@ -0,0 +1,46 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + diff --git a/windows/security/book/images/microsoft-cloud-pki.png b/windows/security/book/images/microsoft-cloud-pki.png deleted file mode 100644 index 15b14c6e7a..0000000000 Binary files a/windows/security/book/images/microsoft-cloud-pki.png and /dev/null differ diff --git a/windows/security/book/images/microsoft-cloud-pki.svg b/windows/security/book/images/microsoft-cloud-pki.svg new file mode 100644 index 0000000000..7e6d6340b9 --- /dev/null +++ b/windows/security/book/images/microsoft-cloud-pki.svg @@ -0,0 +1,19 @@ + + + + + + + + + + + + + + + + + + + diff --git a/windows/security/book/images/microsoft-entra-id.png b/windows/security/book/images/microsoft-entra-id.png deleted file mode 100644 index 4158a866f3..0000000000 Binary files a/windows/security/book/images/microsoft-entra-id.png and /dev/null differ diff --git a/windows/security/book/images/microsoft-entra-internet-access.png b/windows/security/book/images/microsoft-entra-internet-access.png deleted file mode 100644 index bb05dbfefd..0000000000 Binary files a/windows/security/book/images/microsoft-entra-internet-access.png and /dev/null differ diff --git a/windows/security/book/images/microsoft-entra-internet-access.svg b/windows/security/book/images/microsoft-entra-internet-access.svg new file mode 100644 index 0000000000..5a203802ae --- /dev/null +++ b/windows/security/book/images/microsoft-entra-internet-access.svg @@ -0,0 +1,23 @@ + + + + + + + + + + + + + + + + + + + + + + + diff --git a/windows/security/book/images/microsoft-entra-private-access.png b/windows/security/book/images/microsoft-entra-private-access.png deleted file mode 100644 index 6dbecc415b..0000000000 Binary files a/windows/security/book/images/microsoft-entra-private-access.png and /dev/null differ diff --git a/windows/security/book/images/microsoft-entra-private-access.svg b/windows/security/book/images/microsoft-entra-private-access.svg new file mode 100644 index 0000000000..71d51f7d56 --- /dev/null +++ b/windows/security/book/images/microsoft-entra-private-access.svg @@ -0,0 +1,49 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + diff --git a/windows/security/book/images/microsoft-intune.png b/windows/security/book/images/microsoft-intune.png deleted file mode 100644 index 9e70c4f99c..0000000000 Binary files a/windows/security/book/images/microsoft-intune.png and /dev/null differ diff --git a/windows/security/book/images/microsoft-intune.svg b/windows/security/book/images/microsoft-intune.svg new file mode 100644 index 0000000000..1b032a2ba4 --- /dev/null +++ b/windows/security/book/images/microsoft-intune.svg @@ -0,0 +1,28 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + diff --git a/windows/security/book/images/onedrive.png b/windows/security/book/images/onedrive.png deleted file mode 100644 index 187abfefe1..0000000000 Binary files a/windows/security/book/images/onedrive.png and /dev/null differ diff --git a/windows/security/book/images/onedrive.svg b/windows/security/book/images/onedrive.svg new file mode 100644 index 0000000000..050feb09b8 --- /dev/null +++ b/windows/security/book/images/onedrive.svg @@ -0,0 +1,24 @@ + + + + + + + + + + + + + + + + + + + + + + + + diff --git a/windows/security/book/images/universal-print.png b/windows/security/book/images/universal-print.png deleted file mode 100644 index 0f8bd831fd..0000000000 Binary files a/windows/security/book/images/universal-print.png and /dev/null differ diff --git a/windows/security/book/images/windows-security.png b/windows/security/book/images/windows-security.png deleted file mode 100644 index 558b4790e0..0000000000 Binary files a/windows/security/book/images/windows-security.png and /dev/null differ diff --git a/windows/security/book/images/windows-security.svg b/windows/security/book/images/windows-security.svg new file mode 100644 index 0000000000..b0dc8912d6 --- /dev/null +++ b/windows/security/book/images/windows-security.svg @@ -0,0 +1,29 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + +