News

Microsoft Updates Cloud App Security Service for GDPR

Microsoft's Cloud App Security solution this week became the company's latest service to be optimized for the European Union's General Data Protection Regulation (GDPR) privacy law.

Cloud App Security is designed to track the use of Software-as-a-Service (SaaS) applications by end users in organizations, including so-called "shadow IT" scenarios. It also has a scoring feature that will indicate SaaS app risk. The scoring system is based on "regulatory certifications, industry standards and best practices."

To align with the requirements of the GDPR, which came into legal force on May 25, Microsoft has added "13 new components" to the Cloud App Security's risk assessment feature. The service tracks GDPR compliance across data protection and Data Subject Access Rights criteria.

The GDPR levies stiff penalties for organizations or individuals found to violate the privacy of EU residents, even for entities located outside the EU. For instance, individuals in EU countries (known as "Data Subjects") can request information about themselves and ask that it be modified, deleted or moved to another organization. Organizations, in this case, are known as "Data Controllers."

Consequently, organizations that hold such information will likely need to have a means of tracking it, and they'll need to respond to requests from individuals.

The updated Cloud App Security service can spot SaaS apps that are deemed to be noncompliant with the GDPR, according to Microsoft's announcement.

"In cases where a cloud provider is listed as not GDPR ready, you will also be able to see which GDPR controls have not been implemented by the cloud service provider," the announcement indicated.

In a future update, Microsoft plans to add a "pre-built query" in the Cloud App Security service for finding "GDPR-ready cloud apps." It will show all of the GDPR-compliant SaaS apps that are used in an organization.

The Cloud App Security service uses Adallom technology that Microsoft acquired a few years back, and Microsoft's service has been commercially available for a couple of years. The Cloud App Security service can track 16,000 SaaS apps across "60 different parameters," according to Microsoft's announcement.

In addition to the Cloud App Security service, Microsoft has multiple tools that can be used for GDPR compliance tracking. Last week, Microsoft noted that most of them had reached commercial availability status.

About the Author

Kurt Mackie is senior news producer for 1105 Media's Converge360 group.

Featured

  • Windows 365 Cloud Apps Now Available for Public Preview

    Microsoft announced this week that Windows 365 Cloud Apps are now available for public preview. This aims to allow IT administrators to stream individual Windows applications from the cloud, removing the need to assign Cloud PCs to every user.

  • Report: Security Initiatives Can't Keep Pace with Cloud, AI Boom

    The increasingly fast adoption of hybrid, multicloud, and AI systems is easily outgrowing existing security measures, according to a recent global survey by the Cloud Security Alliance (CSA) and exposure management firm Tenable.

  • World Map Image

    Microsoft Taps Nebius in $17B AI Infrastructure Deal To Alleviate Cloud Strain

    Microsoft has signed a five-year, $17.4 billion agreement with Amsterdam-based Nebius Group to expand its AI computing capabilities through third-party GPU infrastructure.

  • Microsoft Brings Copilot AI Into Viva Engage

    Microsoft 365 Copilot in Viva Engage is now generally available, extending Copilot's AI-powered assistant capabilities deeper into the Viva platform.