@jhencinski While requiring MFA registration from a location marked as trusted prevents an attacker from registering a new device in MFA, it doesn't stop session cookie theft from happening. I would suggest adding device compliance policies in CA to combat that type of attack.
@BushidoToken@GossiTheDog Maybe not in this case, because links that contain both ncv[.]microsoft[.].com and ecv[.]microsoft[.].com domains take you to customervoice[.].microsoft[.]com, a legitimate Microsoft resource where several feedback forms are hosted (benign or otherwise)
@GossiTheDog I believe bad actors are just hosting phishing links in feedback forms created and hosted on a legitimate platform (Dynamics 365 Customer Voice).
New grant control in #AzureAD#ConditionalAccess called "Require authentication strength" in preview. Allows you to specify requirements for MFA strength, and f.e. exclude SMS as MFA factor in certain CA policies
@GossiTheDog not that fast! If you want to be ¨*really* protected for CVE-2022-21978, installing the SU is not enough. You'll also need to run the Exchange setup program from the cmd prompt, and use the /preparealldomains switch
@BancoNacion@kas027 A mí también me figura pago fallido con Previaje y QR desde BNA+, en varios comercios de la costa Atlántica. En atención al cliente me derivaron al 08104447827 y cuando llamo el número está fuera de servicio según Telecom...
@BancoNacion no da solución a mi problema con BNA+ y pagos con QR usando tarjeta Previaje. Horas hasta conseguir hablar con alguien de Atención al cliente, y luego "se corta" la comunicación. Y @TurDepAR me derivó a un 0810 de @BancoNacion que ni funciona.