I'd also recommend creating a Continuous Access Policy to require MFA if the network changes. This helps protecting against session token theft
@bearded365guy9 ай бұрын
Yep, another good one.
@paulmckenna94779 ай бұрын
Can you provide any details on how to go about accomplishing this? Sounds like a useful policy to implement.
@jdm9153 ай бұрын
Anyone have an idea of how to setup the policy these guys are talking about?
@DhavalBrahmbhatt26272 ай бұрын
Pls provide details, been dying to set something like that up but can't figure it out.
@smittayy2 ай бұрын
@@DhavalBrahmbhatt2627 it’s “continuous access evaluation” my bad on the incorrect name. Conditions you include everything but mobile since they would be prompted every time they get a new IP on cellular. Session is set to “Use continuous access evaluation” Hope that helps direct
@HammadAli-eb1jc21 сағат бұрын
Hay can you please make video on channel creation for external sharing without switching Domains / Tenant ?
@GregThomson4 ай бұрын
@Jonathan Edwards. A nice bunch conditional access policies. My understanding is that the device platform filter only looks at the device string as reported by the device. This can be spoofed. A better control for managed devices are device filters. e.g. Where the device platform is not a managed Windows device, require an app protection policy.
@alexandrecarreirapt9 ай бұрын
I work supporting 365 and i love your videos. Thanks!
@bowersza9 ай бұрын
Thanks, Jonathan - what a great overview! I cannot stress enough the importance of implementing these important controls in your tenant. well done!
@bearded365guy9 ай бұрын
Thank you 🙏
@patrick__0079 ай бұрын
As always very informative! Though I've some questions about 2FA. 1. What will be the impact for users when disabling SMS from Entra when they've already enabled/using SMS using the Per user MFA? 2. Do you need to disable Per user MFA when 2FA forced using a CA? 3. You've excluded the Admin from any CA. How would you enforce 2FA for this one? Greetings from overseas, the Netherlands.
@bearded365guy9 ай бұрын
Hi to the Netherlands! Firstly, it’s all about communication. This video was easy for me because it’s a test tenant with no real users 😀 Within Entra, you can see which users are using which form of 2FA, so you can contact those users who are using SMS and get them to convert. The Microsoft documentation says that you need to disable MFA on each user account in the 365 portal. I have also seen some powershell scripts which do the same thing. The recommendation for admin. Have two admin accounts. One is part of the CA policy which has MFA enabled. The second admin account is known as the ‘break glass’, it has no MFA but a really long and complex password. We set these to be about 30 characters. Hope that helps.
@ValerieDelgado-d1mАй бұрын
@@bearded365guy1:16
@gregfyn9 ай бұрын
Thanks Jonahan, I like your straight forward communication style.
@bearded365guy9 ай бұрын
Thank you
@whoamigodknows90206 ай бұрын
Brilliant. No BS. straight to the point.
@TechTailsАй бұрын
You are good at explaining this stuff. I already know some of this but doesnt hurt to check again.
@djr357x3 ай бұрын
This is fantastic. thanks so much for putting this together.
@ScottMillar6 ай бұрын
you would'nt believe how many dont do any of this! very helpful
@GFloGG5 ай бұрын
Thank you for this video! Really great insight to the CA policies and really set a great foundation for me! Love what you're doing!
@bearded365guy5 ай бұрын
Thanks!
@ggoben9 ай бұрын
Great Vid. Was wondering if you could do a video on Intune device licenses. There is practically no info out there on this. Specifically enrolling Win10/11 devices using Intune device licenses for shared workstations? What are the best ways to do this? What are the limitations? Lots of businesses use shared workstations for healthcare or factory workers that use the same workstations when on shift as others. We want them in Intune without paying per user license. Thanks!
@bearded365guy9 ай бұрын
I’ll be doing some of these videos very soon
@easy-tech35358 ай бұрын
Thanks Jonathan, this insight was really helpful. May I know what license type is required to create new policies?
@bearded365guy8 ай бұрын
Business Premium
@JuanDiazSilvermyst3 ай бұрын
I love these. Do you have more videos of these policies? tips/tricks and why its good to use them?
@bearded365guy3 ай бұрын
@@JuanDiazSilvermyst There is just what is on my channel at the moment.
@JRashid909 ай бұрын
Another great video! Too many organisations rely on Microsoft Baseline or defaults
@orlandom-c3r8 ай бұрын
I just wanted to join the group and let you know that your videos are amazing. Straight to the point and very informative. Due to this video, I created a little script in PowerShell using Microsoft Graph that will configure all these conditional access policies and one more that block access to all Azure Admin Portals. I just want to share the script as a little contribution to all the effort and good things that you put on your videos. What is the best way to share it? Thanks again for all your good work
@bearded365guy8 ай бұрын
That’s fantastic. Can you send me a link to jonathan@integral-it.co.uk and I’ll share it on the channel somehow
@smarqus47205 ай бұрын
@@bearded365guy I would love to see that powershell
@sohail-khanPaki5 ай бұрын
Thanks for Knowledge sharing. Very informative 👍
@shellpie12 ай бұрын
Thank you SO MUCH.
@GabrielJIsaza6 ай бұрын
Amesing explanation. Question, do I need to assign an Entra P1 license for each user in my organization if I want to implement those essential security policies?
@bearded365guy6 ай бұрын
Good question! Microsoft Licensing says - yes, each user should have a license. But it will let you use the policies even if there is just one license in the tenant. I always try to be honest and add the licenses.
@ggates58592 ай бұрын
@@bearded365guyHonesty, esp for Global Admins, is always the best policy.
@xspance9 ай бұрын
Firstly love the videos thanks so much learnt a bunch. Set this up as a lab. I had issues launching outlook and any other app. I wasn’t sure how to configure the intube app policy for mobile and desktop. I watched the other vid but it still just kept looping for login credentials.
@bearded365guy9 ай бұрын
Can you access if you disable the app protection conditional access policy?
@xspance9 ай бұрын
@@bearded365guy Hey Johnathan! Yes, I excluded myself from the policy and gained access. The config wasn't complete, I couldn't set the intune app policy.
@paulmckenna94779 ай бұрын
At the start of the video you created a conditional access policy requiring MFA for all users. Why is a second policy required MFA for Entra join. Isn't that redundant? Great video, Thanks!
@bearded365guy9 ай бұрын
The second policy is specifically to join devices to Entra
@justinpascarella8 ай бұрын
Thanks again Jonathan! The video I've been waiting for. Question, for those already enrolled in SMS/Phone call MFA, once you enable/enforce these policies, what happens? Will they be prompted/forced to enroll or change their MFA method to using the MS Authenticator?
@bearded365guy8 ай бұрын
If we disable those ways to authenticate, then yes
@jimmyroels76049 ай бұрын
Thank you Jonathan, this will help me secure the tenants of my customers.
@bearded365guy9 ай бұрын
Good luck Jimmy
@vibhubhatnagar6331Ай бұрын
loved this video thanks looking forward for more such videos
@sonny.eblacas8 ай бұрын
Very straightforward. I love it ♥ Thanks!!! 💯
@gregoryigbinoba47784 ай бұрын
@Jonathan Edwards. Thanks for the knowledge. On which M365 service do we test/validate the 'Disable persistent browser session' after setting up the Conditional Access Policy?
@msmacthankQ6 ай бұрын
Brilliant Video, thank you so much. With CA01 do you turn this on after you have communicated to everyone to download the App and set it up? If you have users working all over the world is it still good to set up CA02?
@andrewenglish38103 ай бұрын
In the Entra ID Conditional Access -> Policies -> new Policy settings there is now "Newtwork" do we need to change anything there for any of these policies you are creating? And when you do the exclusion for CA02 if the we are on P1 license with Business Standard will this work or do we need to add a different set of options?
@DoughBoy20249 ай бұрын
Great vid. Speaking of global admin, how about a video talking about how to manage/removing local admin privileges on workstations?
@bearded365guy9 ай бұрын
Stay tuned….
@JamieSneddon-t9e8 ай бұрын
Great video, already had some of these set up but others were missing. It was a very easy video to follow, cheers!
@MarceloMedeirosInfo7 ай бұрын
Hey Jonathan, how you doing my friend? My name is Marcelo, I'm from Brazil and you videos are super helpfull! Thank you so much for your work! 😊👍
@bearded365guy7 ай бұрын
Thank you
@fbifido26 ай бұрын
@14:24 - can we just create a policy for each of the templates and be secured ????
@jimbozo039 ай бұрын
What is the minimum licensing required to enable conditional access (365 business premium?) ? And what if you have a mixed licensing environment? Do policies apply to basic users if setup ?
@jimbozo039 ай бұрын
Copilot tells me the basic users wouldn’t be evaluated against the policies due to not being licensed, so essentially any MFA or geo blocking policy for all users would not apply to them. To me this also become a bigger problem if you’re using sensitivity labels, where those labels do not apply to basic users so as long as they can access the document any encryption or sharing restrictions would not apply to that basic plan user
@bearded365guy9 ай бұрын
Business Premium.
@gnuttz19728 ай бұрын
Great video but there are plenty of dangers associated with many of these which i think need mentioning. For example blocking legacy applications could have many negative side effects especially in a large tenant running in hybrid mode with ad connect back to a sizeable mature on prem environment. There would need to be an audit phase to identify the effect. Is there a way to test an environment for side effects? Sadly not many 365/Azure environments are ‘blue sky’ and therefore will likely be legacy apps.
@ACBCallahan7 ай бұрын
Yes, using the “Report Only” mode is helpful for an audit period like that.
@maltbycentre33946 ай бұрын
Is it possible to disable external guest downloads of OneDrive shared files via CA? Thank you.
@bearded365guy6 ай бұрын
Yes it is.
@maltbycentre33946 ай бұрын
@@bearded365guy Could you please show me a video you made before about it or the options I need to select to make it work? Thank you.
@bearded365guy6 ай бұрын
I’ll be making one soon
@jonathanmatthew5631Күн бұрын
Will vpn bypass conditional access location?
@samarthverulkar45296 ай бұрын
I want to disable access outside my Virtual desktop Workspace i tried to ip block but not able to see public range
@chrisbattiston9 ай бұрын
Thankt!!! Great video ! And what do I do with the scanner email and the MFA? without using a gmail (I have already seen your other video)
@bearded365guy9 ай бұрын
You could exclude from MFA policy. Or… add an IP address in trusted MFA. I didn’t show it on video, but it’s on same screen as approved countries
@chrisbattiston9 ай бұрын
@@bearded365guy Thank you ! you're the best! I've been in IT for 30 years and I've only been working on security issues at Microsoft for a few months (which I didn't know anything about) and your videos are extremely helpful!
@barcoproductions6 ай бұрын
Very helpful video!
@markrichter75045 ай бұрын
Great video, Thanks!
@danpowell74216 ай бұрын
Some great tips here! thanks for sharing
@smarqus47205 ай бұрын
Place you mentioned not recommended to use Microsoft authenticator app ? I don’t know how the authentication will the work without the app or MSS ? Please if hacker use VPN, for UK can he success pass the location policy?
@bearded365guy5 ай бұрын
The authenticator app is OK for MFA, SMS less so.
@smarqus47205 ай бұрын
@@bearded365guy Thank you, what about my question about VPN ?
@mihaneman31299 ай бұрын
thank you so much the content is excellent and helps a lot
@Zak.889 ай бұрын
Well done Jonathan, loves all your videos. thanks
@themikerennie9 ай бұрын
For the whitelisting countries bit, when you filter to compliant devices outside of approved counties, would approved apps (like Outlook or Teams) on unmanaged iPhones still work?
@bearded365guy9 ай бұрын
No, what we’d also need to do is actually manage the smartphones in MDM, rather than app protection
@themikerennie9 ай бұрын
I guess we could scope the allowed countries policy to Windows / Mac devices then use app protection policies to lock down the iOS / android devices differently.
@tri.taminh5 ай бұрын
Hi do i need the license Microsoft 365 Premium for all users so that the Conditional Access to take effect or I just need to assign Premium license to Global Admin and others user can still use Basic and Standard license?
@bearded365guy5 ай бұрын
There is a license loop hole that means you just need one Business premium license in the tenant. With our clients, we always license each user properly for what features they’ll be using.
@tri.taminh5 ай бұрын
@@bearded365guy thank you very much, that helps alot.
@Manavetri8 ай бұрын
Only can say... brilliant
@thaksdaone19 ай бұрын
very helpful,,thanks a lot sir
@andrewenglish38108 ай бұрын
Which Entra ID do you have for this video? P1 or P2?
@bearded365guy8 ай бұрын
P1 is ok.
@daelra9 ай бұрын
Does the order matter with these policies? I kind of have a few basic general purpose CA policies and a few I want for special cases. Do I put the special cases first or last or does the order not matter and I have fiddle with exclusions for each policy to stop one of them stomping on the others where it shouldn't? Also, for licencing purposes, if I set up a 'break-glass' admin account, do I need to have a Business Premium licence attached to it or will one with no licenses be acceptable (providing that is literally its only purpose)? Any technical pros or cons for doing it this way?
@bearded365guy9 ай бұрын
No, the order doesn’t matter. It just has to make sense to you or whoever is administering the system. I think the advice is that any admin accounts shouldn’t have a license attached at all.
@crocaliph6 ай бұрын
Did exactly like you on CA02 : Block access from other countries, whitelisted the countrie we work in, but i had a case yesterday when someone traveled to Spain, he was not able to login, yet Intune says his laptop is compaint, any Ideas? When i go to sign in logs, CA02 did block them, 2 of them had the same issue.
@bearded365guy6 ай бұрын
What device were they using? Laptops? Phones?
@crocaliph6 ай бұрын
@@bearded365guy laptops
@crocaliph6 ай бұрын
@@bearded365guy laptops, when i whitelisted spain, all was good
@crocaliph6 ай бұрын
@@bearded365guy Laptops, after i whitelisted Spain, all was good.
@crocaliph6 ай бұрын
@@bearded365guy Laptops, after i whitelisted Spain all was good!
@badda_boom80178 ай бұрын
PERFECT VIDEO !
@christophermckissick20899 ай бұрын
If I have MFA enabled, I cannot setup our software to send emails. It is a housing software that emails our tenants.
@bearded365guy9 ай бұрын
That’s worrying. I would speak to the software company about that…. It’s 2024!
@davidasplund70888 ай бұрын
Thanks for the video
@Bjeurn19909 ай бұрын
Great video ! Thanks!
@itmaster19004 ай бұрын
Nice videos
@marcushutchinson70579 ай бұрын
If I am using Business Standard this doesn't apply to me and I'm not secured, correct?
@LimitlessHorizonAdventure6 ай бұрын
I'm interested to know the major ramifications of staying with Business Standard for most business around 10 endpoints. Unless controlling endpoints with Intune and really locking them down are they not still safe with Standard if MFA is enforced on all users?
@dougOptics9 ай бұрын
Dude. I love you.
@nazerbor3i9 ай бұрын
beautiful
@alan333089 ай бұрын
Jonathan you are a God sent! Thank you so much for these great videos! 🙏🙏🙏
@johnthompson35309 ай бұрын
GREAT VIDEO
@rehman20179 ай бұрын
I'm professional thumbnail designer on fiver I really want to design your thumbnails more eye catching
@bearded365guy9 ай бұрын
Thanks for your comment. But we’re ok
@rehman20179 ай бұрын
@@bearded365guy I really want to design your thumbnails dear sir only in $10 in 1 hour
@rehman20179 ай бұрын
@@bearded365guy can give you in 1 hour let's try my example thumbnail for free