Not every scenario is created equal! I am THRILLED to announce Authentication strengths, which allow you to use Azure AD Conditional Access to specify exactly what authentication methods are needed for your zero trust policies - read on! https://t.co/F3XEPC8Rxx
Authentication strength helps our customers to require the right authentication method for their most sensitive resources. It is so exciting to ship the work from the team to customers and see their reaction 💛https://t.co/9rAXSpPUym
@TruBluDevil@dean144@markmorow@_nitika_gupta But, if you want a more secure strength (passwordless or phishing-resistant MFA), I would start with report only mode as suggested by Libby.
@TruBluDevil@dean144@markmorow@_nitika_gupta Great question!The built-in MFA auth strength is equivalent to the current MFA grant control (for internal users). If you have such policy, you can consider switching over to the auth strength control.
@merill@adamUCF@TruBluDevil Auth strength except federated single factor and federated multifactor claims from the IdP. You can use it as part of the built-in MFA strength or in a custom strength.
Probably the coolest Ignite session by @inbarck & @cybertarek. It's a great 45 min whiteboarding session on passwordless. Definitely recommend watching it https://t.co/LfnExiOY4L
@kevinpking@Alex_A_Simons Hi Kevin, you can consider providing the user a Temporary Access Pass - that would satisfy the MFA requirements (if you have CA policy to require MFA on the registration flow). More details here: https://t.co/n212THbzEM
So you don't enforce MFA on all Azure admin roles? Not really sure where to start?
Looks like Microsoft has added a nice doc (and script in the doc) to help discover and assess your privileged users so you can minimize potential impacts ;)
https://t.co/MwpH7CShX0
Todays #blueprintFiles session at #MSIgnite is how phishing resistant authentication works. I was SO EXCITED when the passwordless team stepped up. @inbarck & @cybertarek were awesome at breaking things down.
Add it to your schedule!
https://t.co/cQOLLO888X
#azops#itpro
@cybertarek and I are talking about phishing resistant authentication methods at #MSIgnite. You can add it to your schedule now https://t.co/kq5hT1yVfi