Video: Microsoft 365 End-to-End Cyber Resilience | Duration: 2876s | Summary: Microsoft 365 End-to-End Cyber Resilience | Chapters: Welcome and Introduction (6s), Introductions and Agenda (133.485s), M365 Security Challenges (257.52s), Rubrik Security Cloud (570.16s), Backup Process Explained (895.39496s), Threat Detection Features (1280.67s), Data Discovery and Classification (1664.47s), Rubrik's End-to-End Protection (2167.31s)
Transcript for "Microsoft 365 End-to-End Cyber Resilience":
Hey, folks. Welcome in. Welcome in. We appreciate you joining us today. You know, good morning, good afternoon, good evening wherever you are in the world. Thanks for spending some time with us here for this Rubrik workshop covering Microsoft three sixty five end to end cyber resilience. Again, appreciate you making the time for us. You know, your time's very valuable, and so we're gonna try to make the most of it here over the next hour. We've got some folks from our team here on stage with me. We've got Alpico. We've got Ryan. We're gonna walk through some slides. We're gonna walk through a a guided lab and get you guys get you folks into, Rubrik for Microsoft three sixty five protection. So, again, appreciate you joining us. Couple quick notes here about Goldcast, the platform we're using today. Over to, your right here on the screen, you'll see, like, a couple different tabs there. There'll be a chat tab where where we'll post some messages, but the docs tab is one we we should pay a little closer attention to. It has several resources there for you to check out, including a link to the lab as well as a technical white paper covering some of the things we'll talk about today, linked upcoming webinars, you know, other details about Rubrik for Microsoft 365 backup. So definitely click over there and check out some of those resources. And the q and a tab is also really helpful. That'll help you get the most out of this session. Obviously, we we want you to, you know, spend this time in in the best way possible. So if you have questions for us, shoot them on over. You really get the most out of it as we as we kind of engage together and make sure we're covering the things that you're interested in hearing about here today. So given all those things, I'm gonna step off stage, hand it over to Alpika and Ryan to introduce themselves and get in the session. Thank you again for joining us, folks. Thank you so much, Chase. Again, good morning, good afternoon, afternoon, good evening, depending on where you're joining us from. Welcome to this Rubrik workshop session, featuring your Microsoft 365 workload. It's going to be a technical session, so we, you know, want you to ask us questions. Like Chase said, like, make the most out of it. We have the people who know the product in the room, so, you know, please do ask us questions. And I'm thanking you in advance for spending the hour with us. With that quick introductions. My name is Altika Singh, and I'm a senior technical marketing manager here at Rubrik. Just, completed my four years at Rubrik, and I cover everything which is, technical content and customer facing goes on the web, demos, white papers, webinars, etcetera. And I have Ryan here with me. Ryan, why don't you introduce yourself? Yeah. I'm Ryan Garrett. I'm the lead SaaS engineer focused on how we protect our SaaS applications. Been with Rubrik for three years. Before that, I was actually on the customer side for the last twenty years supporting on prem exchange into Microsoft 365 identity infrastructure, you name it, but actually implementing engineering and architecting these solutions. And I'll just be hanging out in the background, fielding your guys' q and a. So feel free to drop me questions, and I'll answer them in the background. Great to meet everybody. Thank you, Ryan. And, you know, with his extensive background, you know, he has the the knowledge and experience to answer any of your questions. So, even if the question is very specific to your environment, please, do put it in. Ryan will be answering and, them. And if if there are a lot of questions, he would just pause. He'll ask me to pause and, you know, we can start answering questions live as well. We will do that at the end, but we want to make this more interactive. So, we'll go back and forth between presentation as well as q and a. So quick agenda. I'll go through the technical deep dive, of the solution itself, 20, and then we'll leave you with the guided lab. We'll hang out here if you have any questions, with the guided lab. So, you know, just wait with us and, let us know if you have any questions. With that, let's get started. So we all know Microsoft 365 is under attack. You know, usually, it used to be the databases or certain web applications, but Microsoft 365, you know, has evolved from this on prem, solution to this ever available SaaS solution. Right? So it has all of your company, documents to your customer information, your, employee information to all the company trade secrets, right, in the various form of Excel sheets or PowerPoint presentations, everything. All your planning is done on, using the Microsoft 365 application. So attackers will, find it, you know, informational and, lucrative to get all of your data and, essentially hold you hostage for the data, during a ransomware attack. What we've seen is that, Microsoft 365 also has, you know, certain identity component associated with it, beat your on prem AD hybrid solution. It can be a gateway to your other applications. Right? So getting hold of your identity plus Microsoft, three sixty five, essentially gives all the attackers the lay of the land, and they can, you know, enhance their permissions and get into your on prem, objects, on prem data, different applications, all across your Azure cloud. So, we have, a lot of our existing customers or even, prospects we talk to, they have experience. Like, 90% of them have experienced identity related threat as well. Now if you see, you know, a lot of times you get emails about clicking password reset. So one overlook oversight can, get an attacker entry to your, to your environment and, then it's it's it's a matter of time when, you know, how they get hold of your data and your different applications. When it comes to Microsoft 365, we've seen, like, 275% year over year increase in, ransomware attacks as well. So it's it's no longer, a corner case where your applications were getting attacked. It's it's happening every day. So, what do you need? We do believe that you need a good cyber posture. Like, do you have an idea? Can you reduce your surface of attack? Do you know where your sensitive data is? Do you know who has access to it, any open access? Do you know how Copilot is deployed? Is it changing data? Does is it, you know, changing the permissions on the data? So, do you have an idea how do you even reduce the attack surface in case there's a cyber attack? Or do you have any idea how to recover your m three sixty fives quickly, the applications quickly? Now, everyone has terabytes, not terabytes, but we are talking hundreds of terabytes into the petabyte range of data, like, you know, generated over time. So if you need to recover all of this data, it could take weeks. It could take months. Do you have certain applications or certain type of data identified which can be recovered quickly, so you can, get your business up and running. Right? So, so for that, we do, suggest that customers have end to end cyber resilience. Right? Now when we talk about cyber posture, we are talking about sensitive data classification, overexposed data. So, essentially, data, classification of your Microsoft 365 data and then telling you where your sensitive data is, who has access to it, is the file available on the web, is it being accessed, is the access details changing over time? Right? Is the location changing? Those kind of details. It's really important to know that, before you have an attack so, you can tackle your cyber attack, with tactics. Right? And when it comes to cyber recovery, there has to be a prioritized recovery so you can get your Microsoft 365 applications up and running. And we are when when we say, prioritized recovery, it's it's about, getting x number of days worth of data quickly recovered for a particular group of users, and then you can continue with the mass recovery. But just getting people up and running is really important. And the precursor to that is always your Entra ID recovery. Because if the identities are compromised, no users will be allowed to, log in to your environment. Right? So it's important that you're able to, recover your identities quickly, making sure that the attackers don't, again, get access to it, and your actual users are able to get in. So, end to end cyber resilience means cyber posture plus cyber recovery. And this is where Rubrik comes into picture. So Rubrik Security Cloud offers the end to end cyber resilience, for your Microsoft 365 workload. And how do we do that? First, Rubrik offers a lot of security application inbuilt on the, inbuilt to the Rubrik security cloud that will do a lot of, data classification and tell you, where your sensitive data is, monitor it, tell you if there are any violations, and even lets you remediate those, risky behavior or risky identities. Right? Next would be to orchestrate Entra ID recovery. Like we talked about earlier, it's important to restore your a d or your Entra ID, across different environments. Right? So quickly that that's more like it. And with a few clicks rather than going through this entire 1,200 pages of a book, trying to figure out how do you get yourself up and running. Next would be the n three sixty five cyber recovery. Essentially, Rubrik offers, immutable backups, making sure that you are able to recover from your backup and also has tools to make sure that you're recovering from an infection free, backup. And you can use prioritize recovery to get yourself up and running quickly. With that, now m three sixty, this solution is actually designed with Microsoft. So it's co engineered solution, where Microsoft 365, let's gives you the, infrastructure, making sure that there is enough, protection so no outsiders can get in. Even if they do, Rubrik is there to help you, get your data backup and running and provide you with the cyber, recovery option, to ensure that, you mitigate the threats successfully. If you look at the architecture, there are three main components to it. First is the Rubrik Security Cloud. Now this is our global management plane, management plane for your on prem cloud and SaaS offering. So if you're protecting your databases which are on prem or if you're protecting your cloud workloads, you know, across multiple vendors or different SaaS application, Dynamics, be it, three sixty five, Microsoft 365, or if you have Salesforce. If you're using Rubrik to protect it, you don't need five different UIs for it. You can just do all your backup recovery access, your security applications, monitoring, alerting, everything through Rubrik's security cloud. The next component is the Rubrik hosted security sources. Now this is the Rubrik's Azure subscription, which actually hosts the actual compute and storage, and provides you with the scale out immutable backup infrastructure, where your backups are actually stored. And, this is, again, like I mentioned before, it's co engineered with Microsoft itself. So, you know, we know how to efficiently use the APIs to make sure that, we are able to back up and restore, at any given point of time. The third is obviously your m three sixty five subscription itself that hosts all the Exchange, OneDrive, SharePoint, and Teams data. And also another component is the on Friday and on prem AD, which you should be protecting with Rubrik to get all the benefits together. So, to start up, like, how do you even set up your m three sixty five? Very simple solution. You just need, your admin credentials. It's a one time usage and also the URL to your subscription. So you log in to, RSC or Rubrik Security Cloud, and then enter the URL to your subscription. Enter the username and password. Again, like, this is required only one time once. This is so that we can issue ourselves auth two dot o tick, auth two dot o tokens so that no, admin credentials are ever used. Now the one time credential usage, it's never stored. It's not stored in, any database temporary. Also, it's obviously in memory and it's purged as soon as the tokens are issued to Rubrik. So once the tokens are issued, essentially, an app, enterprise app, for each of the m two sixty five workloads. So for one for Exchange, one for OneDrive, SharePoint, and Teams, that is spun up in your subscription, your our customer subscription, which becomes the point of authentication going forward. Once that's completed, Rubrik will then spin up, the exocompute, the storage, and the Azure keyboard in the Rubrik Azure subscription to provide that, infrastructure needed, for your immutable backup. Now it's a scale out infrastructure, so we can start with four AKS cluster, and then we can scale all the way up to, 200 if needed, to get your backup completed and even for restore as well. Once that is completed, Rubrik will then, discover and inventory all the existing data you have for Exchange, OneDrive, Teams, and SharePoint. And then that, inventory will be available in Rubrik Security Cloud. One of our, most frequently asked questions like, does Rubrik support Multi Geo? Yes. We do. Essentially, as soon when you're onboarding your cluster, there's a simple checkbox, that you do need Multi Geo support. You know, if you just check that option while onboarding, Rubrik will identify all the preferred data location, which is, essentially group of users that do require the data to live where they are actually present. So for example, if, you know, there are GDPR laws in place for Europe. Now let's take UK that you have employees in UK. Their, SharePoint data, OneDrive data will live in Rubrik subscription that is specifically spun up in The UK region. It will not go to India or, US or for any other, country for that matter. Similar thing, for India as well. If you do have certain group of users, you know, we can enable that. We will call out central data location or CDL. And, usually, it's North America, but, again, that's an option you can choose, while onboarding and selecting your, preferred central data location. Yeah. With that, we'll talk about the backup option. So once the inventory is completed, Rubrik or rather the customers will log on to RSC and assign SLA domain to your, you know, the workloads. So it could be it actually defines the backup frequency, how long you want to, keep it for, if you want to archive it, those kind of things. Once, it's time to back up, Rubrik will instantiate the AKS nodes in the Rubrik subscription. And it will start off with the minimum set of AKS nodes required. And, again, like, it will scale if needed. Once that's completed, it will authenticate, using the enterprise applications, for whichever application, or which for whichever workload the backup is running. Once that's completed, it will use the graphic APIs to actually, backup the data or move the data from, your environment to, the blob storage, in the in the Rubrik hosted storage account. Now the first backup is always a full backup. The sub the the subsequent backups are always incremental backups. And with that, now Rubrik performs a lot of, data classification and threat analytics. And I'll get to the applications in just a little bit, what comes out of that. But once the backup is completed, it does a lot of, threat analytics and data classification, and the results are published on, Rubrik Security Cloud. But before that, we and make sure that we encrypt the data using envelope encryption. And then, we send the metadata, which is basically your index data, like, when the file was last accessed, when changed, so that you can do a lot of searches and recovery operation as well. Once all of that is completed, Rubrik will spin down the AKS nodes, and call it call the process complete. Once that is done, and you are in a restore operation, it's literally just the opposite, where if a user is, if if it's initiating a recovery operation, be it, prioritized recovery, mass recovery, single file recovery, the process remains the same. It's just the amount of data that's being restored differs. And we'll cover those recovery scenarios in just a little bit. So, once the restore operation is started, Rubrik will instantiate the AKS nodes, for the restore operation. It will do the authentication using the, enterprise applications. It will decrypt the data and then use the proper APIs to put the data back into your, M365 account. Once that is completed, the AKS clusters are spun down, and the process is, complete right there. So we talked about, or I mentioned a little bit that Rubrik performs, some post backup analysis. So one part of that is data threat analytics. And one of the security application is actually anomaly detection. Like the name suggests, it's actually looking for anomalies. Things like, you know, sudden encryption, millions of files getting deleted, folders getting deleted. Suddenly the users are getting deleted. Like, if if it's an expected event, great. But what Rubrik does is that it learns the pattern over time, and understands what is normal and what's what's the deviation it should look for to look for this these anomalies. Right? So to kick start the process, what happens is that, as part of the, backup process, we do generate, file metadata, which is what is sent to Rubrik Security Cloud. So after every backup, we actually compare the current file metadata of FMD with the previous, FMD and create, like, a diff file metadata or FMT. That is actually fed to our multistage anomaly detection, ML model. There's a lot of logic built into that so, you know, it can distinguish what is normal. Like I mentioned, it learns your environment and under tries to figure out if if, you know, this 1,000,000, file delete the files like, 1,000,000 files that were deleted are normal or not. Those kind of things. So, it will try to, get that output. If if it does find any anomalies, it will create the list of anomalies and then send it to the UI, which is in which lives in RSC. And the phase two of it is to figure out if there's encryption. Now, you you can see that your data is encrypted. Yeah. Sure. You can choose to encrypt your data at any point of time, but, the the the model itself is smart enough to understand what's normal encryption versus, a ransomware encryption. Right? So, essentially, it scans your data, looks for that entropy. If there are any entropies found, it updates the ransomware as a stable, which is fed to the encryption detection machine learning model, to call out to see if there are any false positives. Right? So we want to make sure that we send the right information to you. If there are any encryption, present, it will essentially collect all that in encryption result and then send it to the anomaly detection UI again, which lives, in RSC or Rubrik query cloud. So now why do we do that? Right? So this can be a sign of early detection of any, attackers present in your environment. So, since Rubrik is tracking so if there are small changes that's happening in your environment, Rubrik tracks that. And then before it becomes a full fledged ransomware attack, you can take actions if something does seem off to you. Next is threat monitoring. This is a very proactive use of Rubrik. Essentially, what Rubrik does is that it creates a threat intelligence feed, with curated insights from some of the third party, free third party vendors, Rubrik zero XeroLabs and, of course, Google threat analytics. Right? So, it will have one single feed that's really updated daily. And it's not looking for threats that's present that were present ten years ago. Right? It's looking for, the most recent, most prevalent threats that's, ongoing throughout the world. And, if there's a zero, attack found, like, for today, the threat feed is automatically updated with that zero attack, IOC or indicator of compromise, and your backups are then scanned, to look for those indicators of compromise or threats. We do use hashes for Microsoft 365, and it's supported for OneDrive and SharePoint data. After every backup, this happens, a threat monitoring tool just, gets in play and automatically scans your backup. And if there are any threats of, present, it will display it on the dashboard. And now this is a one time enablement thing, from your, UI or Rubrik security cloud. Once you enable it, you only come to this UI if if there are any alerts for any indicators of compromise. Otherwise, the UI is very boring. Like, there's, like, literally a blue screen with nothing on it, and that's what you ideally would want to happen. Next is threat hunting. Now this is, is obviously not a proactive but a reactive approach. If you do have, a cyber attack or a ransomware attack ongoing in your environment and you want to figure out, which objects are affected by it, like, when was this first started, which was a snapshot where Rubrik detected this first, you know, you can use threat hunting tool. Fill in all the hashes, of the IOCs you want to scan for, and Rubrik will get into action. It will, you know, depending on what your defined timeline is for snapshot, It'll scan all of them, for all of your data and then let you know if, and when the threat was first detected. You can do all sorts of things. Like, you can actually quarantine the file as well, from the UI. So, very interesting tools, available for you, pre attack and during attack as well. Next, we get into some data discovery and classification. You know, there's a lot of sensitive data available in your infrastructure, be it health care, be it financial, you know, even we have so much sensitive data, across our organization. Right? And and we want to keep it safe. And Rubrik does give you the tools for it. So, we have, again, like, a data classification data discovery and classification. It's a, it's an application in Rubrik Security Cloud. It has prebuilt analyzers to look for, certain data types. Right? Like, it can be your Social Security number, bank routing number that are then tied to policies. It could be HIPAA, PII, PCI, those kind of things. And if you have custom data, custom sensitive data types, custom, classification policies, you can always create them and assign it to your Microsoft applications. And boom, after every, backup Rubrik will actually look for sensitive data, and then tell you if anything has changed in the in the in terms of if the access has changed, if the location has changed, if things are looking good or not. On on a day to day basis, you can make, you know, you can use this information to make sure you're meeting all your compliance requirements, that all your data is locked and loaded. During a cyber attack, again, you can figure out what kind of data exposure you are looking at, so you can make your mitigation plan, work with authorities, inform them, and whatnot. So over summer, we introduced a new feature called DAG or data access governance, governance. Very cool feature, and it's it's essentially very essential and helpful for knowing your overall cyber posture, knowing where your sensitive data is and if there are any access violation, those kind of things. So for that, a, you do need to back up your active directory on try d. Windows file, if it's there, great. But, you know, since we do protect it, I have added it. And, of course, your Microsoft 365 applications. Once, the backups are completed, we gather some information. Like, we look at all the file system audit logs, the contents of the documents, all the ACLs, group membership, user, etcetera. And then we start evaluating. Basically, we classify the data if it's sensitive or not. We do the document classification. We basically tell you if if, document is mislabeled and it's a tax document mislabeled at something else, those kind of things. Right? So we are classifying those, sensitive document as well. We'll look at all the access, that's present on the file. We also start evaluating if there are any open permission, risky permissions, risky identities, like, basically, someone outside your organization having access to a lot of your sensitive data. So, we are evaluating on different, notes. And then once that's completed, we actually tell you if there are any violations present, in for that sensitive data, such as, if there are missing mid labels, if there are any overprivileged data, obsolete data, misplaced data, you know, misconfigured data as well. So, these violations come in very handy so that you can have a good cyber posture, and Rubrik also allows you to take action. So you can take all these violations or send it to your seam and sore, and then, the necessary team can take action. Or you can, do the public link removal. You can fix map labels. Those kind of things yourself from RSC itself. You can actually create a ticket, to get that fixed as well. So that way, Rubrik gives you a a platform, to know what your cyber posture, or what your sensitive data posture looks like so you can, be ready in case of any cyber attack and essentially reduce your, your your sensitive data, your data exposure as well. You know, that was lot of analytics, what we do with the data, but it's important that we talk about recovery. Right? We talk about getting back up and running fairly quickly. Now once you've done your analysis and you've figured out, like, what a clean recovery, what a clean snapshot, is and where you want to recover from, what you can kick start as prioritized recovery. Now, it's it's as the name suggests, like, you essentially start your recovery wizard. And instead of doing a mass recovery, which will recover all of your data intake, could take a lot longer, to get back up and running, what you can do is you can select prioritize recovery and, essentially recover few days worth of data. So it can be, you know, from the past seven days to all the way up to thirty days depending on, what time frame you are looking for, and it can be different for different SSO groups. So, you know, if you want to get your execs back up and running, you can, basically, recover one week of data and get them back up and running. And for certain employees, if ten days of data is required, you can essentially customize for each user group. Once you do that, you essentially select the snapshot, the clean snapshot you want to recover from, and then, boom. There you go. The recovery starts. You can also choose to do, the complete recovery that would, be that would mean, like, mass recovery after your prioritized recovery is complete and your user is able to get, into the environment and start accessing and start doing their job, basically. The other one is self-service restore. Now this is, this feature is super cool. This is to make sure that, you know, you can fast track, users to back get back up and running quickly. Like, if I'm a user and I've deleted a file accidentally, and I have nowhere to restore it, I have to open an IT ticket, wait for them to restore a single file. Now, it it might just sound like, oh, yeah. IT team can just go ahead and, recover a file. But in hindsight, I'm sure they are busy with much more bigger task than, you know, doing a single file recovery. Right? This is where you can enable your users or your, employees to do the restore. The only, file they will have or the only data they will have access to is their own. They can only do search search they can only search for data in their own dataset. They don't have access to any other application or any other user. And once they figure out what they want to recover, they simply click recovery, and then, it does do the recovery in a separate folder to make sure, like, no none of the original data is touched. Also, as an admin, you will be notified. And, of course, as a user, I'll be notified as well if I am doing the self-service restore. So it's, you know, essentially making sure that your IT team has enabled, users to, service themselves. So we talked about so many different applications. You know, I'm just going to end it on a note how Rubrik is helping you end to end. Right? So if you look at an attack timeline when it's happy, nothing is going on, essentially, pre attack, data security posture is helping you, to figure out where your sensitive data is, so that you can enforce least privilege and make sure that your data is safe and secure and low locked and loaded so, you can reduce your attack surface as well. Post attack, it helps you recover your data from a clean recovery point. You can identify your blast radius, using anomaly detection, threat monitoring, threat hunting, making sure that the backup you're using for recovery is free from any indicators of compromise, so you don't reinfect, your environment post recovery, and also identity recovery. Right? It's important to get your onshore ID back up and running. So Rubrik helps you with that and then always help you, get your data recovered quicker using prioritized recovery. So all three of them net to end to end will help you achieve a complete cyber resilience and making sure that you are safe before an attack, during an attack, and after an attack. Right? So you can get your business up and running quickly. With that, I will pause and see if there are any questions. Ryan, anything we want to take online or you've answered them all? I'm good. I answered all the questions. So Oh, perfect. I yeah. Awesome. I think we have some time then. I can, just quickly show you the guided lab as well, so that way you have an idea what you will see once you get access to the lab. Let me quickly share my screen. Okay. So, I covered a lot of different applications very quickly, but a lot of times you want to understand what I was talking about and you want to get a deeper dive, get a sense of how it comes together, in Rubrik's security cloud and which is what I've tried to do. We start by, giving you, an in giving you an introduction as to how you can protect your Entra ID, how you can recover it, same thing for AD as well. How do you onboard your Microsoft 365 subscription. It's it's literally five steps. So it's that easy to get your subscription onboarded. Then we talk about protection, different recovery options, even talk about integration with, backup storage. Again, like, talk about recovery to another subscription itself, self-service recovery, go in detail about data threat analytics. So I do cover, anomaly detection, threat hunting, threat monitoring, all the tools which you can use. And then, again, like data discovery and classification, which is, which is precursor to DSPM or data security posture management. So, all the things I talked about are actually there in this lab end to end. You know, you I can, Chase, if you don't mind, if you can share the link with everyone. You can try it out. I can, like, basically wait around here to see if you have any questions, and help you navigate through the lab if there are any questions. And then real quick, there was a question, around mass recovery capabilities. And so, ultimately, to kind of expand on what Pika had talked about when we talked about mass recovery, The way that mass recovery works is that we give you the capabilities to group users. So if you're restoring exchange or you're restoring, you know, think of OneDrive, we allow you to use Azure AD groups. And what we do is is we allow you to say, hey. For this entire group of users, we want to restore all the users in that group. So say there's, you know, a thousand users in that group, you have the capability to say, hey. I wanna restore all thousand of these users' mailboxes or one drives, things like that. And when we think of mass restore, it is literally like, hey. I need to restore the entire mailbox, all of the calendar invites, meetings, and things like that, and then the contacts. And then where Alpika really honed in is on prioritized recovery is, hey. I'm doing a mass restore, but I want to prioritize the last, you know, say, seven days or thirty days. And so what we're doing is is we're prioritizing, hey. Let's restore that most critical data first, and then let's restore the rest. But a lot of times, like, you may have a situation where a c suite says, hey. I wanna restore all enter my c suite, and you just send it all back. Right? So that's kinda how MAS works on that side. And then the same thing for SharePoint and Teams, What we use is we use a a group naming convention based on the it's a syntax based on the name of the site or the name of the team. And so, like, let's say all your teams start your, you know, sites or teams start with IT and then, like, operations, security, things like that. You could say, hey. I'm looking for all sites that have the name IT and then wild card afterwards. And what that allows you to do is group those sites and say, hey. I wanna restore all of these sites. Again, either en masse, mass recovery just means I want everything back. Or you can do a prioritized recovery to say, hey. I only want the last thirty days. Once we've completed the last thirty days, you can always go back in and say, hey. Now I'm ready to complete the mass recovery and kinda wrap everything up. Thank you, Ron. Yeah. And we do have some more resources which Chase has already shared with you. But, yeah, like, there's a deep dive on how Microsoft three sixty five protection works, even for more information for backup and recovery. And we have a brand new white paper coming, on recovery recommendations, best practices essentially, for your m three sixty five data. So, you know, please, have a lookout for that as well. Lot of great information coming your way as well. And with that, you know, thank you all for attending, and spending the time with us, asking us questions. We do run this very frequently. So if someone in your organization needs more information, send them there our way. Also, you know, there are other, avenues you can contact, you know, get more information. Again, like, go to our website, contact our sales, simple sales at, Rubrik dot com. You have our contact information. If we can help you in any way, you know, just let us know, and we if we cannot help, we can always get you in touch with the right people as well. With that, thank you so much, for taking your time and attending this session. I'll be hanging around if you have any questions. Thank you.