Cybersecurity Expert Reacts To M365 Defaults [Detailed Breakdown]

  Рет қаралды 908

Threatscape

Threatscape

Күн бұрын

Пікірлер: 6
@ikazimirs
@ikazimirs 26 күн бұрын
Great video Ru - while secure by default is a great concept it will always be contextual. What i would really like to see is an onboarding permissions run through rather than have defaults at all. Dont let someone create a tenant until they review and set a default of their own before the tenant spins up. I know easy create is great, but if an admin/user was asked to provide a bunch of config before tenant creation in the form of some sort of submission form or flow through window - a) they would be aware of what the current setting is and that it exists in the first place and b) they might consider looking for advice to get it secure from get go.
@elementdude814
@elementdude814 25 күн бұрын
Great video Ru! Thank you for going through out of the box security defaults.
@chrisrossneely
@chrisrossneely 26 күн бұрын
Default tenant config needs to span from Azure Free all the way through to E5, hence favouring Security Defaults rather than CA, and as you said, they aren’t compatible. I agree though, I’d much rather see MFA for all users, MFA for Admins and block Legacy Auth called out as specific Conditional Access Policies if your licensing supported it. Email authentication- from memory- is only available for Self Service Password Reset- not as a MFA challenge (even though it’s listed in Auth Methods). I could be wrong, that mightn’t be the default. Great content. Keep it up!
@rucam365
@rucam365 26 күн бұрын
Correct, agree, and thanks! Though I don’t like email for SSPR either as you can’t verify the security of the unmanaged mailbox. But, accept the trade off can be worth it (eg coupled with other methods enforced during reset). IMO, CA, or at least some conditions and controls, should trickle down to Entra ID Free. As time goes and what’s considered adequate security does too, that’s my hope (won’t bet the farm on it though).
@KarolynaABCMultiserviciosB
@KarolynaABCMultiserviciosB 8 күн бұрын
yesss WTH?? I CAN NOT access my emails
@0xcalmaf976
@0xcalmaf976 26 күн бұрын
Magneto relogin please
Ozoda - Alamlar (Official Video 2023)
6:22
Ozoda Official
Рет қаралды 10 МЛН
-5+3은 뭔가요? 📚 #shorts
0:19
5 분 Tricks
Рет қаралды 13 МЛН
Why Your Entra ID MFA Is Failing You [5 Major Pitfalls]
12:51
Threatscape
Рет қаралды 1,4 М.
Netflix Removed React?
20:36
Theo - t3․gg
Рет қаралды 43 М.
How Can I Get the Most Out of Purview eDiscovery?
44:00
Threatscape
Рет қаралды 474
Phishing 2.0 - Detecting Evilginx, EvilnoVNC, Muraena and Modlishka
46:05
Threat Hunting Explained By Microsoft's Elite Hunter
38:06
Threatscape
Рет қаралды 1,5 М.
Job losses at Europe’s car parts suppliers skyrocket as European crisis grows
13:24
Why Privileged Identity Management Falls Short [5 Key PIM Mistakes]
14:02
How Microsoft Graph API Simplifies Admin Tasks [Expert Insights]
29:27