Denny Cherry & Assoc · @dcac
58 followers · 203 posts · Server techhub.social

buff.ly/3n0GNCT 5 Great Reasons to Use Azure Conditional Access for Azure Active Directory by @mrdenny was recently published to show people what the benifits are Azure Conditional Access are.

#azuread #conditionalaccess

Last updated 1 year ago

's protection is an important part of a strategy and I thought sharing some learning on the topic could be interesting 😊

What better place than the authentication to start this tour: medium.com/raphaël-pothin/powe

#powerplatform #governance #security #azuread #conditionalaccess

Last updated 1 year ago

HcInfosec · @HcInfosec
28 followers · 932 posts · Server defcon.social

Is anybody out there using this feature in practice?
Let me know if you do

Using Authentication Context to Secure SharePoint | Practical365 practical365.com/using-authent

#conditionalaccess

Last updated 1 year ago

Hagen Deike :verified: · @samurai
45 followers · 30 posts · Server sueden.social
Luke Murray · @lukemurray
75 followers · 167 posts · Server aus.social

Merill Fernando, a Microsoft Product Manager for AAD has done it again! idpowertoys.com - with the ability to now export your
- straight to PowerPoint!

#identitypowertoys #azuread #conditionalaccess

Last updated 1 year ago

F0rm4t · @F0rm4t
41 followers · 43 posts · Server infosec.exchange

Integration of Authentication Context in PIM is a great addition for implementing . It allows to trigger a policy when an eligible , or Group membership will be requested. I like to share some of my notes from the field...

ℹ️ Auth. Context will not enforce re-authentication. There is no step-up if you are already satisfied conditions/controls by token claim (e.g. previously Passwordless sign-in will not re-prompt for PIN or Biometric). It would be great to combine the feature with SIF Everytime.

💡 I experimented with following step-up: FIDO2/WHfB is already enforced in CA policy (Auth. Strength). Auth. Context is requesting GPS-based Location from Auth. App to verify access from allowed countries. User will be prompted for Number Match + GPS during role activation.

⚠️ Owner and User Access Administrator can change or remove assignment to Authentication Context from PIM role settings:
learn.microsoft.com/en-us/azur

But also Classic Administrators (e.g., from EA Portal) are able to modify PIM role settings. Keep this in mind!

#azuread #conditionalaccess #azure

Last updated 1 year ago

rodtrent :verified: · @rodtrent
468 followers · 792 posts · Server infosec.exchange

Duplicate Azure Active Directory Conditional Access policies rodtrent.com/b1z

#azure #conditionalaccess

Last updated 1 year ago

Fabian Bader · @fabian_bader
867 followers · 319 posts · Server infosec.exchange

Does your company have external IPv6 addresses and you use ?
Then better update your named locations.

learn.microsoft.com/en-us/trou

#azuread #cap #conditionalaccess

Last updated 2 years ago

F0rm4t · @F0rm4t
22 followers · 25 posts · Server infosec.exchange
rodtrent :verified: · @rodtrent
413 followers · 415 posts · Server infosec.exchange

New blog post: "Securing privileged user access with and "

Overview and considerations to enforce security controls for using , strong authentication and manage access for privileged roles based on tiering levels.

cloud-architekt.net/securing-p

#azuread #conditionalaccess #identitygovernance #paw

Last updated 2 years ago

New blog post: "Securing privileged user access with and "

Overview and considerations to enforce security controls for using , strong authentication and manage access for privileged roles based on tiering levels.

cloud-architekt.net/securing-p

#azuread #conditionalaccess #identitygovernance #paw

Last updated 2 years ago

Paul Sanders · @paulsanders
105 followers · 120 posts · Server infosec.exchange

It’s great seeing people start to see the benefit and power of conditional access policies. A friend is deploying them for their org, and they have well and truly fell down the rabbit hole. First it was MFA for all, then device profiles… now full on passwordless, TAP and strong authentication types.

#aad #azuread #conditionalaccess #iam

Last updated 2 years ago

Renate van Stigt · @renatevanstigt
621 followers · 1551 posts · Server mastodon.social
Renate van Stigt · @renatevanstigt
718 followers · 2542 posts · Server mastodon.social

I've started to work on the next part of the blog series about securing privileged access in and . Designing policies and configuring (in consideration of Enterprise Access/Tiering Model) will be the focus of the upcoming article.

#azuread #azure #conditionalaccess #accesspackages

Last updated 2 years ago

I‘m very looking forward to talk about 🚀 PoC at M365 Security & Compliance User Group next week! Join this demo-driven session to learn more about automated deployment and management of with

Free registration and more details: meetup.com/m365sandcug/events/

#aadops #azuread #conditionalaccess #azuredevops

Last updated 2 years ago

@zimmergren I am very much a "in the weeds" director. Lead from the front so to speak. I took over this position a year ago from my predecessor that had the mentality of: "we are in the cloud, I don't have to worry about security."

So I was going through and setting up and it had been a few years since I configured that, so I looked up the docs. If you are using , you get pointed to Security Center to configure it. But Microsoft centralized that in a new interface and asks if you want to move your legacy policies into the new location. Anyway, what they don't tell you is that you must first set up Conditional Access in , then set up application specific policies in O365. None of the docs explain that. CA covers your azure environment and establishes the parameters for CA in O365, but the policies define how it's used. So if you didn't set up the policies you get partial CA.

Another obscurity is DLP in that the training/learning group doesn't work like you would think it does. But that's a book on it's own.

I left out a lot of details, but I hope that kind of covers it.

I agree the docs have gotten better over time, but I feel like the security based docs are lagging behind general IT docs.

#conditionalaccess #o365 #azuread #aad

Last updated 2 years ago

ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online