Skip to main content

9MlyH3LAIZL1FCwDtE8-4BdsKBogV8us3Pkh7VXmdpid3laMtYYiJcgLIxVv7CH0ZJ0lOqB0Fh2A5ptB386qXBXRt9fTCcusySuN2dv4zdPxpdjD2ev7eqXHZSSTx1hq-AxfzshnntIshcCG2NuUvH8

Netskope Global Technical Success (GTS)

Use Case – Differentiating Microsoft OneDrive Instances: Business vs Personal

 

Netskope Cloud Version - 113

 

Objective

Identifying Microsoft OneDrive Instances: Differentiating Between Business and Personal instances

 

Prerequisite

Netskope CASB Inline licensing is required

 

Context

The customer requires guidance on distinguishing between Microsoft OneDrive Business and Personal instances. Additionally, they seek assistance in identifying which Personal instance the end-user is utilizing

 

Do you Know?

  • Microsoft OneDrive is classified into three distinct types -
  1. MS GCC Office 365 OneDrive for Business

GCC is Government Community Cloud. This is for Government customers. It is designed to comply with stringent government regulations and security requirements, ensuring data sovereignty and protection for government agencies and their stakeholders. 

  1. Microsoft Office 365 OneDrive for Business

This is intended for commercial customers. In other words, all Microsoft OneDrive Business instance traffic will be routed to this

  1. Microsoft OneDrive

This is intended for personal use. Traffic from domains *@live.com, *@outlook.com, and *@hotmail.com will be routed to this.

 

  • Does the Netskope CASB inline engine have the capability to detect which flavor of Microsoft OneDrive (GCC, Business, or Personal) the traffic belongs to?

The answer is YES

mZw-qiC4IpWQOy60ymUDD1gnDjKZkF7u6GTvRMw6MNh5Nn80DuK8uSwNDPFQPRmurJ6Wl9YXMSegMeFXNMYXvcx1zPNPFe9vN2FFPPmWblqjmZu7pluw3AcrPBScm91mdIshKqB3oR86DPg-sr6gHzk

  • What logic Netskope uses to identify the Microsoft OneDrive (GCC, Business, or Personal)?
  1. The answer is ‘Domains’
  2. Any traffic destined to the highlighted domains will be considered as Microsoft Office 365 OneDrive for Business traffic
  3. Netskope recognizes all three flavors of Microsoft OneDrive as cloud applications and offers a pre-defined cloud app connector with the highlighted activity controls

Sample

H0_VfZ0Ib9ddiqaIhc_zpYnLhS0VrBcVUd6jeNChz2put0qxonR_NiaDVBYO1T75qtJRTGRn5mjSBxJUowzn-4_KCpYSGoreBDvrpP430w6G7HXrzSejDl0X1RQwEYMwc8DgVW0l7OSvUlLLdOfaRrg

 

Configuration

  • Identify the instance type

Path: Netskope Tenant UI >>> Skope IT >>> Application Event >>> Filter Application name >>> OneDrive

The personnel and corporate logs can be differentiated here based on the application

Wz-csU9ge-rv7g9KZ8Hg-P9ri8ycTpUZK3rzofhp2V5tY1taZCUVSoLMcJZlyqVpau6gS4wlzbQzHUqoi5MhzSqaOiuJRYNN6oOjr28M3LpJK2bO1SugxskWwv-rfQHYxVGMsNQ-IY5DYmeEBRpP0Hw

When clicking on the magnifying glass, you can view the event details:

We can observe that the log on the left side pertains to a Business OneDrive application (corporate instance), while the log on the right side corresponds to a Personal OneDrive application (non-corporate instance)

14ZmeGJCpezpltcjXBzmu-G06xjBAAKGHUAR2yD3aXegl1Xw9cHbqTX3Quje_oHSv3j0_WrfovmGcpllJ-ISJ7EcGRNCtJ4BKjqh-ygkP2GGCMWk-_qXDmcOx1jpSb31kRhgj9sGfOEidOngr34OlkI 

 

  • Lets setup a Real-time protection policy to monitor transaction for Microsoft OneDrive Personal and Corporate

Path: Netskope Tenant UI >>> Policies >>> Real-time Protection >>> New Policy>> Cloud App Access

The below policies are designed to alert on any supported Microsoft OneDrive activity

A screenshot of a computerDescription automatically generated

__________________________________________________________________

 

A screenshot of a computerDescription automatically generated

Author Notes

  • With the current Netskope product design, App instances are exclusively available for Microsoft Office 365 OneDrive for Business. This feature enables granular control instances specifically for OneDrive for Business.

_1eCo0HMheHuWqEJLG0F53EQIoXujFbGq1noHCvAWG1hQcmptYoSkTyNpRADi7O8qFxxfHgGTtbjldT1DJ9--3ndY4h_SygYM-DwBxUt35uwuZBkzLZqbpIznCuKfa7wUUdfvKRIu3cGiDHF6QLmay4

 

Terms and Conditions

  • All documented information undergoes testing and verification to ensure accuracy.
  • In the future, the application's functionality may be altered by the vendor. Additionally, Netskope Engineering is continuously working on product enhancements. It is possible that additional controls may become available to address some of the limitations mentioned earlier. If any such changes are brought to our attention, we will promptly update the documentation to reflect them.

 

Notes

  • This article is authored by Netskope Global Technical Success (GTS).
  • For any further inquiries related to this article, please contact Netskope GTS by submitting a support case with 'Case Type – How To Questions'.

 

Be the first to reply!