Lock Down Your Microsoft 365: Your Essential Security Policies

  Рет қаралды 50,959

Jonathan Edwards

Jonathan Edwards

Күн бұрын

Пікірлер: 119
@smittayy
@smittayy 9 ай бұрын
I'd also recommend creating a Continuous Access Policy to require MFA if the network changes. This helps protecting against session token theft
@bearded365guy
@bearded365guy 9 ай бұрын
Yep, another good one.
@paulmckenna9477
@paulmckenna9477 9 ай бұрын
Can you provide any details on how to go about accomplishing this? Sounds like a useful policy to implement.
@jdm915
@jdm915 3 ай бұрын
Anyone have an idea of how to setup the policy these guys are talking about?
@DhavalBrahmbhatt2627
@DhavalBrahmbhatt2627 2 ай бұрын
Pls provide details, been dying to set something like that up but can't figure it out.
@smittayy
@smittayy 2 ай бұрын
@@DhavalBrahmbhatt2627 it’s “continuous access evaluation” my bad on the incorrect name. Conditions you include everything but mobile since they would be prompted every time they get a new IP on cellular. Session is set to “Use continuous access evaluation” Hope that helps direct
@HammadAli-eb1jc
@HammadAli-eb1jc 21 сағат бұрын
Hay can you please make video on channel creation for external sharing without switching Domains / Tenant ?
@GregThomson
@GregThomson 4 ай бұрын
@Jonathan Edwards. A nice bunch conditional access policies. My understanding is that the device platform filter only looks at the device string as reported by the device. This can be spoofed. A better control for managed devices are device filters. e.g. Where the device platform is not a managed Windows device, require an app protection policy.
@alexandrecarreirapt
@alexandrecarreirapt 9 ай бұрын
I work supporting 365 and i love your videos. Thanks!
@bowersza
@bowersza 9 ай бұрын
Thanks, Jonathan - what a great overview! I cannot stress enough the importance of implementing these important controls in your tenant. well done!
@bearded365guy
@bearded365guy 9 ай бұрын
Thank you 🙏
@patrick__007
@patrick__007 9 ай бұрын
As always very informative! Though I've some questions about 2FA. 1. What will be the impact for users when disabling SMS from Entra when they've already enabled/using SMS using the Per user MFA? 2. Do you need to disable Per user MFA when 2FA forced using a CA? 3. You've excluded the Admin from any CA. How would you enforce 2FA for this one? Greetings from overseas, the Netherlands.
@bearded365guy
@bearded365guy 9 ай бұрын
Hi to the Netherlands! Firstly, it’s all about communication. This video was easy for me because it’s a test tenant with no real users 😀 Within Entra, you can see which users are using which form of 2FA, so you can contact those users who are using SMS and get them to convert. The Microsoft documentation says that you need to disable MFA on each user account in the 365 portal. I have also seen some powershell scripts which do the same thing. The recommendation for admin. Have two admin accounts. One is part of the CA policy which has MFA enabled. The second admin account is known as the ‘break glass’, it has no MFA but a really long and complex password. We set these to be about 30 characters. Hope that helps.
@ValerieDelgado-d1m
@ValerieDelgado-d1m Ай бұрын
​@@bearded365guy1:16
@gregfyn
@gregfyn 9 ай бұрын
Thanks Jonahan, I like your straight forward communication style.
@bearded365guy
@bearded365guy 9 ай бұрын
Thank you
@whoamigodknows9020
@whoamigodknows9020 6 ай бұрын
Brilliant. No BS. straight to the point.
@TechTails
@TechTails Ай бұрын
You are good at explaining this stuff. I already know some of this but doesnt hurt to check again.
@djr357x
@djr357x 3 ай бұрын
This is fantastic. thanks so much for putting this together.
@ScottMillar
@ScottMillar 6 ай бұрын
you would'nt believe how many dont do any of this! very helpful
@GFloGG
@GFloGG 5 ай бұрын
Thank you for this video! Really great insight to the CA policies and really set a great foundation for me! Love what you're doing!
@bearded365guy
@bearded365guy 5 ай бұрын
Thanks!
@ggoben
@ggoben 9 ай бұрын
Great Vid. Was wondering if you could do a video on Intune device licenses. There is practically no info out there on this. Specifically enrolling Win10/11 devices using Intune device licenses for shared workstations? What are the best ways to do this? What are the limitations? Lots of businesses use shared workstations for healthcare or factory workers that use the same workstations when on shift as others. We want them in Intune without paying per user license. Thanks!
@bearded365guy
@bearded365guy 9 ай бұрын
I’ll be doing some of these videos very soon
@easy-tech3535
@easy-tech3535 8 ай бұрын
Thanks Jonathan, this insight was really helpful. May I know what license type is required to create new policies?
@bearded365guy
@bearded365guy 8 ай бұрын
Business Premium
@JuanDiazSilvermyst
@JuanDiazSilvermyst 3 ай бұрын
I love these. Do you have more videos of these policies? tips/tricks and why its good to use them?
@bearded365guy
@bearded365guy 3 ай бұрын
@@JuanDiazSilvermyst There is just what is on my channel at the moment.
@JRashid90
@JRashid90 9 ай бұрын
Another great video! Too many organisations rely on Microsoft Baseline or defaults
@orlandom-c3r
@orlandom-c3r 8 ай бұрын
I just wanted to join the group and let you know that your videos are amazing. Straight to the point and very informative. Due to this video, I created a little script in PowerShell using Microsoft Graph that will configure all these conditional access policies and one more that block access to all Azure Admin Portals. I just want to share the script as a little contribution to all the effort and good things that you put on your videos. What is the best way to share it? Thanks again for all your good work
@bearded365guy
@bearded365guy 8 ай бұрын
That’s fantastic. Can you send me a link to jonathan@integral-it.co.uk and I’ll share it on the channel somehow
@smarqus4720
@smarqus4720 5 ай бұрын
@@bearded365guy I would love to see that powershell
@sohail-khanPaki
@sohail-khanPaki 5 ай бұрын
Thanks for Knowledge sharing. Very informative 👍
@shellpie1
@shellpie1 2 ай бұрын
Thank you SO MUCH.
@GabrielJIsaza
@GabrielJIsaza 6 ай бұрын
Amesing explanation. Question, do I need to assign an Entra P1 license for each user in my organization if I want to implement those essential security policies?
@bearded365guy
@bearded365guy 6 ай бұрын
Good question! Microsoft Licensing says - yes, each user should have a license. But it will let you use the policies even if there is just one license in the tenant. I always try to be honest and add the licenses.
@ggates5859
@ggates5859 2 ай бұрын
@@bearded365guyHonesty, esp for Global Admins, is always the best policy.
@xspance
@xspance 9 ай бұрын
Firstly love the videos thanks so much learnt a bunch. Set this up as a lab. I had issues launching outlook and any other app. I wasn’t sure how to configure the intube app policy for mobile and desktop. I watched the other vid but it still just kept looping for login credentials.
@bearded365guy
@bearded365guy 9 ай бұрын
Can you access if you disable the app protection conditional access policy?
@xspance
@xspance 9 ай бұрын
@@bearded365guy Hey Johnathan! Yes, I excluded myself from the policy and gained access. The config wasn't complete, I couldn't set the intune app policy.
@paulmckenna9477
@paulmckenna9477 9 ай бұрын
At the start of the video you created a conditional access policy requiring MFA for all users. Why is a second policy required MFA for Entra join. Isn't that redundant? Great video, Thanks!
@bearded365guy
@bearded365guy 9 ай бұрын
The second policy is specifically to join devices to Entra
@justinpascarella
@justinpascarella 8 ай бұрын
Thanks again Jonathan! The video I've been waiting for. Question, for those already enrolled in SMS/Phone call MFA, once you enable/enforce these policies, what happens? Will they be prompted/forced to enroll or change their MFA method to using the MS Authenticator?
@bearded365guy
@bearded365guy 8 ай бұрын
If we disable those ways to authenticate, then yes
@jimmyroels7604
@jimmyroels7604 9 ай бұрын
Thank you Jonathan, this will help me secure the tenants of my customers.
@bearded365guy
@bearded365guy 9 ай бұрын
Good luck Jimmy
@vibhubhatnagar6331
@vibhubhatnagar6331 Ай бұрын
loved this video thanks looking forward for more such videos
@sonny.eblacas
@sonny.eblacas 8 ай бұрын
Very straightforward. I love it ♥ Thanks!!! 💯
@gregoryigbinoba4778
@gregoryigbinoba4778 4 ай бұрын
@Jonathan Edwards. Thanks for the knowledge. On which M365 service do we test/validate the 'Disable persistent browser session' after setting up the Conditional Access Policy?
@msmacthankQ
@msmacthankQ 6 ай бұрын
Brilliant Video, thank you so much. With CA01 do you turn this on after you have communicated to everyone to download the App and set it up? If you have users working all over the world is it still good to set up CA02?
@andrewenglish3810
@andrewenglish3810 3 ай бұрын
In the Entra ID Conditional Access -> Policies -> new Policy settings there is now "Newtwork" do we need to change anything there for any of these policies you are creating? And when you do the exclusion for CA02 if the we are on P1 license with Business Standard will this work or do we need to add a different set of options?
@DoughBoy2024
@DoughBoy2024 9 ай бұрын
Great vid. Speaking of global admin, how about a video talking about how to manage/removing local admin privileges on workstations?
@bearded365guy
@bearded365guy 9 ай бұрын
Stay tuned….
@JamieSneddon-t9e
@JamieSneddon-t9e 8 ай бұрын
Great video, already had some of these set up but others were missing. It was a very easy video to follow, cheers!
@MarceloMedeirosInfo
@MarceloMedeirosInfo 7 ай бұрын
Hey Jonathan, how you doing my friend? My name is Marcelo, I'm from Brazil and you videos are super helpfull! Thank you so much for your work! 😊👍
@bearded365guy
@bearded365guy 7 ай бұрын
Thank you
@fbifido2
@fbifido2 6 ай бұрын
@14:24 - can we just create a policy for each of the templates and be secured ????
@jimbozo03
@jimbozo03 9 ай бұрын
What is the minimum licensing required to enable conditional access (365 business premium?) ? And what if you have a mixed licensing environment? Do policies apply to basic users if setup ?
@jimbozo03
@jimbozo03 9 ай бұрын
Copilot tells me the basic users wouldn’t be evaluated against the policies due to not being licensed, so essentially any MFA or geo blocking policy for all users would not apply to them. To me this also become a bigger problem if you’re using sensitivity labels, where those labels do not apply to basic users so as long as they can access the document any encryption or sharing restrictions would not apply to that basic plan user
@bearded365guy
@bearded365guy 9 ай бұрын
Business Premium.
@gnuttz1972
@gnuttz1972 8 ай бұрын
Great video but there are plenty of dangers associated with many of these which i think need mentioning. For example blocking legacy applications could have many negative side effects especially in a large tenant running in hybrid mode with ad connect back to a sizeable mature on prem environment. There would need to be an audit phase to identify the effect. Is there a way to test an environment for side effects? Sadly not many 365/Azure environments are ‘blue sky’ and therefore will likely be legacy apps.
@ACBCallahan
@ACBCallahan 7 ай бұрын
Yes, using the “Report Only” mode is helpful for an audit period like that.
@maltbycentre3394
@maltbycentre3394 6 ай бұрын
Is it possible to disable external guest downloads of OneDrive shared files via CA? Thank you.
@bearded365guy
@bearded365guy 6 ай бұрын
Yes it is.
@maltbycentre3394
@maltbycentre3394 6 ай бұрын
@@bearded365guy Could you please show me a video you made before about it or the options I need to select to make it work? Thank you.
@bearded365guy
@bearded365guy 6 ай бұрын
I’ll be making one soon
@jonathanmatthew5631
@jonathanmatthew5631 Күн бұрын
Will vpn bypass conditional access location?
@samarthverulkar4529
@samarthverulkar4529 6 ай бұрын
I want to disable access outside my Virtual desktop Workspace i tried to ip block but not able to see public range
@chrisbattiston
@chrisbattiston 9 ай бұрын
Thankt!!! Great video ! And what do I do with the scanner email and the MFA? without using a gmail (I have already seen your other video)
@bearded365guy
@bearded365guy 9 ай бұрын
You could exclude from MFA policy. Or… add an IP address in trusted MFA. I didn’t show it on video, but it’s on same screen as approved countries
@chrisbattiston
@chrisbattiston 9 ай бұрын
@@bearded365guy Thank you ! you're the best! I've been in IT for 30 years and I've only been working on security issues at Microsoft for a few months (which I didn't know anything about) and your videos are extremely helpful!
@barcoproductions
@barcoproductions 6 ай бұрын
Very helpful video!
@markrichter7504
@markrichter7504 5 ай бұрын
Great video, Thanks!
@danpowell7421
@danpowell7421 6 ай бұрын
Some great tips here! thanks for sharing
@smarqus4720
@smarqus4720 5 ай бұрын
Place you mentioned not recommended to use Microsoft authenticator app ? I don’t know how the authentication will the work without the app or MSS ? Please if hacker use VPN, for UK can he success pass the location policy?
@bearded365guy
@bearded365guy 5 ай бұрын
The authenticator app is OK for MFA, SMS less so.
@smarqus4720
@smarqus4720 5 ай бұрын
@@bearded365guy Thank you, what about my question about VPN ?
@mihaneman3129
@mihaneman3129 9 ай бұрын
thank you so much the content is excellent and helps a lot
@Zak.88
@Zak.88 9 ай бұрын
Well done Jonathan, loves all your videos. thanks
@themikerennie
@themikerennie 9 ай бұрын
For the whitelisting countries bit, when you filter to compliant devices outside of approved counties, would approved apps (like Outlook or Teams) on unmanaged iPhones still work?
@bearded365guy
@bearded365guy 9 ай бұрын
No, what we’d also need to do is actually manage the smartphones in MDM, rather than app protection
@themikerennie
@themikerennie 9 ай бұрын
I guess we could scope the allowed countries policy to Windows / Mac devices then use app protection policies to lock down the iOS / android devices differently.
@tri.taminh
@tri.taminh 5 ай бұрын
Hi do i need the license Microsoft 365 Premium for all users so that the Conditional Access to take effect or I just need to assign Premium license to Global Admin and others user can still use Basic and Standard license?
@bearded365guy
@bearded365guy 5 ай бұрын
There is a license loop hole that means you just need one Business premium license in the tenant. With our clients, we always license each user properly for what features they’ll be using.
@tri.taminh
@tri.taminh 5 ай бұрын
​@@bearded365guy thank you very much, that helps alot.
@Manavetri
@Manavetri 8 ай бұрын
Only can say... brilliant
@thaksdaone1
@thaksdaone1 9 ай бұрын
very helpful,,thanks a lot sir
@andrewenglish3810
@andrewenglish3810 8 ай бұрын
Which Entra ID do you have for this video? P1 or P2?
@bearded365guy
@bearded365guy 8 ай бұрын
P1 is ok.
@daelra
@daelra 9 ай бұрын
Does the order matter with these policies? I kind of have a few basic general purpose CA policies and a few I want for special cases. Do I put the special cases first or last or does the order not matter and I have fiddle with exclusions for each policy to stop one of them stomping on the others where it shouldn't? Also, for licencing purposes, if I set up a 'break-glass' admin account, do I need to have a Business Premium licence attached to it or will one with no licenses be acceptable (providing that is literally its only purpose)? Any technical pros or cons for doing it this way?
@bearded365guy
@bearded365guy 9 ай бұрын
No, the order doesn’t matter. It just has to make sense to you or whoever is administering the system. I think the advice is that any admin accounts shouldn’t have a license attached at all.
@crocaliph
@crocaliph 6 ай бұрын
Did exactly like you on CA02 : Block access from other countries, whitelisted the countrie we work in, but i had a case yesterday when someone traveled to Spain, he was not able to login, yet Intune says his laptop is compaint, any Ideas? When i go to sign in logs, CA02 did block them, 2 of them had the same issue.
@bearded365guy
@bearded365guy 6 ай бұрын
What device were they using? Laptops? Phones?
@crocaliph
@crocaliph 6 ай бұрын
@@bearded365guy laptops
@crocaliph
@crocaliph 6 ай бұрын
@@bearded365guy laptops, when i whitelisted spain, all was good
@crocaliph
@crocaliph 6 ай бұрын
@@bearded365guy Laptops, after i whitelisted Spain, all was good.
@crocaliph
@crocaliph 6 ай бұрын
@@bearded365guy Laptops, after i whitelisted Spain all was good!
@badda_boom8017
@badda_boom8017 8 ай бұрын
PERFECT VIDEO !
@christophermckissick2089
@christophermckissick2089 9 ай бұрын
If I have MFA enabled, I cannot setup our software to send emails. It is a housing software that emails our tenants.
@bearded365guy
@bearded365guy 9 ай бұрын
That’s worrying. I would speak to the software company about that…. It’s 2024!
@davidasplund7088
@davidasplund7088 8 ай бұрын
Thanks for the video
@Bjeurn1990
@Bjeurn1990 9 ай бұрын
Great video ! Thanks!
@itmaster1900
@itmaster1900 4 ай бұрын
Nice videos
@marcushutchinson7057
@marcushutchinson7057 9 ай бұрын
If I am using Business Standard this doesn't apply to me and I'm not secured, correct?
@LimitlessHorizonAdventure
@LimitlessHorizonAdventure 6 ай бұрын
I'm interested to know the major ramifications of staying with Business Standard for most business around 10 endpoints. Unless controlling endpoints with Intune and really locking them down are they not still safe with Standard if MFA is enforced on all users?
@dougOptics
@dougOptics 9 ай бұрын
Dude. I love you.
@nazerbor3i
@nazerbor3i 9 ай бұрын
beautiful
@alan33308
@alan33308 9 ай бұрын
Jonathan you are a God sent! Thank you so much for these great videos! 🙏🙏🙏
@johnthompson3530
@johnthompson3530 9 ай бұрын
GREAT VIDEO
@rehman2017
@rehman2017 9 ай бұрын
I'm professional thumbnail designer on fiver I really want to design your thumbnails more eye catching
@bearded365guy
@bearded365guy 9 ай бұрын
Thanks for your comment. But we’re ok
@rehman2017
@rehman2017 9 ай бұрын
@@bearded365guy I really want to design your thumbnails dear sir only in $10 in 1 hour
@rehman2017
@rehman2017 9 ай бұрын
@@bearded365guy can give you in 1 hour let's try my example thumbnail for free
Introducing Microsoft Global Secure Access - No More VPN's!
18:33
Jonathan Edwards
Рет қаралды 116 М.
Getting Things Done; The Microsoft Outlook Productivity System
19:17
Jonathan Edwards
Рет қаралды 94 М.
This Game Is Wild...
00:19
MrBeast
Рет қаралды 140 МЛН
How Much Tape To Stop A Lamborghini?
00:15
MrBeast
Рет қаралды 205 МЛН
How To Activate Nomad eSIM On Android & iPhone
3:28
Geo Statology
Рет қаралды
How to Protect against Token Theft | Conditional Access
26:48
T-Minus365
Рет қаралды 4,6 М.
Microsoft Ignite 2024: Everything Revealed in 15 Minutes
15:03
Phishing Resistant MFA How it Works!
15:26
Andy Malone MVP
Рет қаралды 15 М.
Why Unreal Engine 5.5 is a BIG Deal
12:11
Unreal Sensei
Рет қаралды 1 МЛН
How to Update Your Devices in Microsoft 365 Using Intune
20:25
Jonathan Edwards
Рет қаралды 20 М.
Exploring the Future: Microsoft Ignite 2024 Insights VLOG
9:51
Jonathan Edwards
Рет қаралды 2,2 М.
7 HIDDEN Apps in Microsoft 365 that will EXPLODE Productivity
28:35
Jonathan Edwards
Рет қаралды 317 М.
OneNote as a Second Brain (What You're Missing)
32:32
Tiago Forte
Рет қаралды 323 М.
This Game Is Wild...
00:19
MrBeast
Рет қаралды 140 МЛН