UAE’s University of Sharjah is blazing the TechEd trail, keeping sensitive research projects, student records, and online classes highly secure while also saving on manpower and system downtime. In a game-changing cybersecurity move, the University transitioned from a cumbersome manual platform to Microsoft Sentinel. When correlated with Defender and Azure, it covered 70 percent of threat vectors overnight and automated 20 percent of security use cases within 48 manhours. With AI-driven defense against thousands of daily alerts, the University has swiftly moved from complexity to confidence, handling 80 percent of security operations with a standard system administrator.
Founded in 1997, the University of Sharjah ranks among the best academic institutions in the Middle East and Africa (MEA) region. As an innovative world-class teaching, learning, and research institution, University of Sharjah provides a distinctive, inspirational, creative, and supportive environment. Home to over 19,000 students across 13 colleges and two campuses that operate 24/7, it embraces digitization as a cornerstone of its vision, one that was jumpstarted by COVID and the subsequent leap in online programs and users.
“Education has experienced a dramatic shift from pens and notebooks to online classes, cloud applications, and blockchain-authenticated exam certificates,” notes Mohammed Al-Saidat, the Director of IT Technology. “Our goal is to ensure that all students and academics can work safely with the heavy use of sensitive data such as student records and online exams, while complying with University’s and state-wide regulations.”
Overnight shift to fortified cybersecurity
Once COVID hit, more than 70,000 users ramped up their use of the university’s online system—students, professors, researchers, and alumni around the world. The University's IT Security team, led by Pradeep Nair, was confronting escalating cybersecurity threats by continuously enhancing security measures to monitor vast amounts of data. But they were hampered by their previous cybersecurity platform, which lacked both unified real-time dashboards and automation. That meant manual efforts, significant downtime, and constant attention. “The biggest challenge was the visibility of incidents and telemetry and their correlation to specific sources,” Nair says.
To address this, the University transitioned to Microsoft Sentinel, a cloud-native security information and event management platform (SIEM). “Within a few clicks, Sentinel ingested data from major log sources like Microsoft 365, Azure Identity Protection, and Defender for Cloud, covering 70 percent of our IT estate threat vectors,” Nair reveals. “Onboarding 138 servers through Azure for third-party vendors took only two weeks.”
AI-driven defense against daily cyberattacks
The transition to Microsoft Sentinel brought a notable enhancement in incident visibility and real-time tracking for the University's IT team, offering unique capabilities like synchronizing threat intelligence with content hub and logic apps. “No peer industry SIEM can offer that,” Sami Hammad, Acting Head IT Infrastructure at the University of Sharjah compliments. “The real-time dashboards offer comprehensive insights into leaked documents, compromised data, and other key metrics.”
Unlike its predecessor, Sentinel introduces powerful artificial intelligence (AI)-driven automation, handling approximately 400 daily alerts related to malicious IP addresses and multi-stage attacks. “Investigating each alert is extremely laborious, so in the past, we would ignore many of them,” admits Hammad. “Now, Sentinel's automated identification, labeling, and blocking of alerts based on preset rules significantly reduce the need for human intervention.”
Correlated with Sentinel, Microsoft Defender for Cloud provides a powerful isolation engine to instantly block network access for infected machines. The AI capabilities also help deal with email threats. “The AI algorithm tells whether a given message is phishing mail, SPAM, or standard email,” Nair mentions.
Automation for better security, faster
Capitalizing on Microsoft Sentinel, Nair's team swiftly developed 120 security use cases in 48 hours, automating one-fifth of them. The solution also addressed staffing challenges posed by the lack of automation on the previous IT security platform. “Complex security infrastructure required assembling a qualified team of 10 or 20 expert professionals,” says Al-Saidat. “The unified stack eliminates this issue and allows experienced analysts to focus on critical alerts rather than mundane tasks.” Currently, 80 percent of security operations at the University can be handled by a standard system administrator, reserving the expertise of an IT security professional for the remaining 20 percent.
Empowering the University of Sharjah’s IT security teams with automation and intelligent threat detection, Sentinel has made an impact on their daily lives. “The support team’s efforts of identifying malicious user IPs globally have been reduced by more than half,” discloses Nair. “Meanwhile, alerts decreased by up to 70 percent. I feel more confident now.” This newfound confidence stems from enhanced visibility, expanded reach, and increased flexibility in responding to events. “In the dynamic realm of digitized academia, this is a pivotal advantage,” Nair closes.
“Within a few clicks, Sentinel ingested data from major log sources like Microsoft 365, Azure Identity Protection, and Defender for Cloud, covering 70% of our IT estate threat vectors.”
Pradeep Nair, Assistant Director of IT Security & Governance, University of Sharjah
Follow Microsoft