Demystifying Microsoft 365 MFA: Security Defaults & Conditional Access

  Рет қаралды 6,677

Jonathan Edwards

Jonathan Edwards

Күн бұрын

Пікірлер: 17
@mattsnider5704
@mattsnider5704 4 ай бұрын
As usual, a wonderfully precise, straight to the point video. Thank you.
3 ай бұрын
dude i am binging on all of your videos - i learned so much man - keep it up.
@James-sc1lz
@James-sc1lz 11 ай бұрын
Enforced means the user has completed the MFA registration. Enabled means they have not and have 14 days by default or will be forced. I’d you don’t want MFA you simply don’t click enable MFA. You should never click enforce unless they have previously registered according to MS. Good video
@networkn
@networkn 8 ай бұрын
Enjoyed this. What is frustrating is that some parts of 365 can show MFA not configured, but it IS configured, under Conditional Access.
@Finchwizard
@Finchwizard 3 ай бұрын
So the new method that they're trying to migrate people to. If that's done. Do you still need to come into this 'legacy' section and click 'enable' or 'enforce' for people. It seems like this is still needing to be done, it's just the service settings part that is moving or shifting.
@bearded365guy
@bearded365guy 3 ай бұрын
No, take a look at this more recent video - My 7-Step Guide to Better MFA in Microsoft 365 kzbin.info/www/bejne/eGXOmH6Yaa1sn9k
@Finchwizard
@Finchwizard 3 ай бұрын
@@bearded365guy that’s my point. Unless you have P1 or Premium licenses. The new MFA method is purely just to configure what’s available, not the actual enablement. (For these companies that don’t like premium costs and use standard) seems like you still need to click “per MFA” button in Entra to kick them on.
@SilesianWarrior
@SilesianWarrior 10 ай бұрын
I've enabled MFA for half my users using per user method. If i was to enable it now for everyone, via defaults, will the previous, already enrolled users be affected as well? I'd love to get 50% less phone calls about forgotten passwords during deployment.
@davidadams421
@davidadams421 9 ай бұрын
If MFA is already setup for a user then, in theory, they shouldn't be asked to set it up again when security defaults is enabled, however, Microsoft does actually recommend that all exiting tokens are deleted and all users are set to re-register MFA when enabling security defaults (they recommend doing this via powershell). Google 'Security defaults in Microsoft Entra ID' for further info.
@davidadams421
@davidadams421 9 ай бұрын
If MFA is already setup for a user then, in theory, they shouldn't be asked to set it up again when security defaults is enabled, however, Microsoft does actually recommend that all exiting tokens are deleted and all users are required re-register MFA when enabling security defaults. Google 'Security defaults in Microsoft Entra ID' for further info.
@theoyiorkas
@theoyiorkas 11 ай бұрын
If only the administrator has the Premium license and has set Conditional Access, then the regular users who have Basic or Standard license, what policy do they follow?
@davidadams421
@davidadams421 9 ай бұрын
Security Defaults mandates that normal users must *setup* MFA (within 14 days) but *does not* mandate its use, except when the system determines the sign-in as 'risky' e.g. last sign-in was from UK, then suddenly the next is from Africa, or if the user is resetting their own password. Security Defaults mandates MFA registration *and use* for all administrative roles e.g. Global Admin, User Admin etc. Google 'Security defaults in Microsoft Entra ID' for further info. I think this is a nice balance between security and user convenience, imho.
@GoreGamer
@GoreGamer Жыл бұрын
You and Andy are my Hero's!!!! This video is absolutely amazing, and I'm actively implementing the strategies outlined here. However, I'm facing a challenge in my environment. Somehow, the 'Verify by Phone' feature got activated for my users. We're planning a full rollout in the 2nd or 3rd week of January, and I need this phone verification feature turned off temporarily until we complete our user migration. My plan is to enable all multi-factor authentication (MFA) and phone verification after 90+ days post-migration. Any advice on how to manage this would be greatly appreciated!
@bearded365guy
@bearded365guy Жыл бұрын
Thanks! Can you use an MFA campaign?
@mussaabdi
@mussaabdi 2 ай бұрын
Hey buddy kindly create a tutorial on insider risk management
@SeiferAlmasy21
@SeiferAlmasy21 Жыл бұрын
Per User is deprecated..
@hunterx1191
@hunterx1191 10 ай бұрын
It's not though.
Lock Down Your Microsoft 365: Your Essential Security Policies
22:09
Jonathan Edwards
Рет қаралды 60 М.
Каха и дочка
00:28
К-Media
Рет қаралды 3,4 МЛН
VIP ACCESS
00:47
Natan por Aí
Рет қаралды 30 МЛН
Microsoft 365 Entra: An Overview for Complete Beginners
19:08
Jonathan Edwards
Рет қаралды 12 М.
Microsoft 365 Fundamentals for Admins
23:43
New 2 Microsoft 365
Рет қаралды 383
Microsoft 365 SPF, DKIM and DMARC; Improve Your Email Security!
17:37
Jonathan Edwards
Рет қаралды 77 М.
Phishing Resistant MFA How it Works!
15:26
Andy Malone MVP
Рет қаралды 16 М.
Azure Active Directory Multi Factor Authentication and Security defaults
15:42
How to Manage Personal Smartphones in Microsoft 365
14:12
Jonathan Edwards
Рет қаралды 24 М.
The New Outlook is TERRIBLE
20:19
Chris Titus Tech
Рет қаралды 175 М.
Introducing Microsoft Global Secure Access - No More VPN's!
18:33
Jonathan Edwards
Рет қаралды 125 М.
Learn Conditional Access in just 25 Mins
25:47
Andy Malone MVP
Рет қаралды 39 М.