@acjuelich@xenappblog@Microsoft@MSIntune You can still onboard servers to MDE with GPO without using Azure Arc. Then use direct onboarding in Defender for Cloud to cover the licensing. However, I would be cautious about recommending Azure Arc if the customer isn’t familiar with how to secure the deployment.
@IAMERICAbooted Add Application Administrator and Cloud Application Administrator to your list.
How many organizations actually audit when someone creates a new client secret for an app registration that already has granted privilege permissions? 😊
@NathanMcNulty If you use AVD, you can hide this prompt for your AVD-hosts. It might also be possible with Bastion if you consent and configure the service principal, but I’m not sure. However, it should not work in your case since you have Bastion in another tenant.
https://t.co/BgkrF6MLOP
@machadof1p@EricaZelic Yes. You should also add your external address for VPN (if it’s another one).
Assume that you work from home and connects to your company’s VPN with force tunneling. Then Entra IP would raise a risk/event for impossible travel. With the IP specified, no risk will be raised.
Updated guidance for emergency access accounts is to use FIDO2 or CBA.
This is part of the mandatory MFA requirement in Azure portals and clients.
FIDO2 has no dependency on the Azure MFA service; a common reason for break glass MFA exclusions.
ref: https://t.co/4DqGljXz3n
@merill Some new info around licensing for admin accounts? You and Alex Simons stated that it’s one license per human around 2021. But did Microsoft ever documented this?
@Investeraren@AntonIngman Det är 30$ extra för dem med M365 E3, E5, Business Standard eller Premium.
Många företag tampas fortfarande med att komma upp i ”rätt” licensnivå för ökad säkerhet. Jag tror att de kommer ta tid innan företag även adderar denna licens.
https://t.co/FWWnLgEQCC