No video

Microsoft Conditional Access - 7 New Features Admins MUST Know!

  Рет қаралды 13,527

Andy Malone MVP

Andy Malone MVP

Күн бұрын

Пікірлер: 26
@davidbrown8536
@davidbrown8536 20 күн бұрын
Thanks, well presented
@mikefus1
@mikefus1 2 ай бұрын
This is fantastic. Thank you for taking the time to show us. I`m going to spend my weekends with your videos :-)
@martinschlenker6145
@martinschlenker6145 2 ай бұрын
Thanks Andy. Great Video
@leomagallon1061
@leomagallon1061 2 ай бұрын
Can you do a video showcasing MFA whenever an eligible role is activated ?
@grahamelgie9281
@grahamelgie9281 2 ай бұрын
Great Video cheers 🙂
@nikkova2007
@nikkova2007 3 ай бұрын
Hey Andy this is great, thank you. I have a question: Isn't Network section in CA policy same as Named Locations IP ranges? Can we set private IP ranges in Network section?
@AndyMaloneMVP
@AndyMaloneMVP 3 ай бұрын
Not that I’m aware of
@frankmvabaza
@frankmvabaza 3 ай бұрын
Hi Andy, thank you for sharing the new features. Can the token protection protect users who are not using MFA due IOT device in the store that can't work with a user who is signing in with MFA on their profiles?
@AndyMaloneMVP
@AndyMaloneMVP 2 ай бұрын
A short answer is no. Token protection only works in a limited format at the moment but is currently being rolled out by Microsoft. At the moment you can use it on the Microsoft 365 portals and apps as well as the admin portals. The idea of being that it can protect admin accounts from token replay attacks. For more information visit Microsoft learn and take a look at the various documentation. Good luck and thanks for tuning in Andy
@moepskie
@moepskie 2 ай бұрын
Thanks for the informative content as always. Regarding the authentication methods: in the case for SSPR, what would be your recommendation? SSPR can be setup with either 1 or 2 factor MFA. 2-factor MFA sounds the most secure to me, but the 2nd factor for SSPR can only be a phone number (office phone or SMS) or a secondary emailadress. Both of those secondary SSPR methods are quite unsecure. So my question would be: Is it more secure to enable SSPR with just 1-factor MFA (which would be the Authenticator App), or would it be better to enable SSPR with 2-factor MFA (Authenticator App + Phone Number OR Emailaddress)?
@AndyMaloneMVP
@AndyMaloneMVP 2 ай бұрын
In my opinion, SSPR is a potential back door into your active directory. Personally, I’m not a fan of it and it encourages retaining passwords when really we want to get rid of them. Consider. Phishing resistant credentials instead instead for example pass keys.
@moepskie
@moepskie 2 ай бұрын
@@AndyMaloneMVP Thanks Andy, we're already working on going passwordless asap :)
@PrinceJohn84
@PrinceJohn84 2 ай бұрын
Hero!
@gdr1174
@gdr1174 3 ай бұрын
Thanks for the information. On a slightly separate note, does anyone know of a way admins can create a temporary sandbox tenant for exploring various features without using a production environment?
@AndyMaloneMVP
@AndyMaloneMVP 2 ай бұрын
That’s what trial accounts were for they were great. However, Microsoft are really cutting back on these and making it difficult to take trial subscriptions without the requirement of a credit card.
@JessieS
@JessieS 2 ай бұрын
I pay for two licenses just to test things out.
@lifeslooker
@lifeslooker 3 ай бұрын
Device Code Flow - is this the same as when you're logged into or using Safari on one device, then continue to use it on another? Authentication Flow - logged in onto O365 on one device, then use on another with the same creds? Have I understood this right?
@AndyMaloneMVP
@AndyMaloneMVP 2 ай бұрын
You got it 😊
@lifeslooker
@lifeslooker 3 ай бұрын
Risk related data activities - Timestamp 12:37 - what does this mean? under Insider Risk?
@AndyMaloneMVP
@AndyMaloneMVP 2 ай бұрын
For this to work, you need to set up an insider risk policy in Microsoft purview
@alexandrecarreirapt
@alexandrecarreirapt 2 ай бұрын
Hi Andy, is it possible with CA to block office apps like word, excel and outlook, but keep onedrive and teams working everywhere ?
@AndyMaloneMVP
@AndyMaloneMVP 2 ай бұрын
You can select the apps option on user account properties and deselect apps that you don’t want the user to see
@Bigapps1Z
@Bigapps1Z 3 ай бұрын
please i really want to join the class am really interested
@AndyMaloneMVP
@AndyMaloneMVP 2 ай бұрын
We’d love to have you just click on the book button and you’re all set
@Bigapps1Z
@Bigapps1Z 2 ай бұрын
@@AndyMaloneMVP where can i find the boook button please
@AndyMaloneMVP
@AndyMaloneMVP 2 ай бұрын
@@Bigapps1Zwww.quality-training.co.uk/book-online
Phishing Resistant MFA How it Works!
15:26
Andy Malone MVP
Рет қаралды 13 М.
Goodbye VPN! Hello Microsoft Global Secure Access
19:40
Andy Malone MVP
Рет қаралды 156 М.
Magic trick 🪄😁
00:13
Andrey Grechka
Рет қаралды 52 МЛН
Schoolboy Runaway в реальной жизни🤣@onLI_gAmeS
00:31
МишАня
Рет қаралды 3,7 МЛН
Get 10 Mega Boxes OR 60 Starr Drops!!
01:39
Brawl Stars
Рет қаралды 19 МЛН
❌Разве такое возможно? #story
01:00
Кэри Найс
Рет қаралды 3,4 МЛН
Microsoft Intune Amazing New Features You HAVE To Know!
28:19
Andy Malone MVP
Рет қаралды 26 М.
HTMX Sucks
25:16
Theo - t3․gg
Рет қаралды 120 М.
Microsoft Entra Global Secure Access Demo
18:45
Kocho
Рет қаралды 1,3 М.
Why are you not using these Amazing Office Features?
17:42
Andy Malone MVP
Рет қаралды 5 М.
Super Easy IPV6 In 10 Minutes
12:15
Andy Malone MVP
Рет қаралды 6 М.
Why Phishing Resistant Authentication is important
12:52
Microsoft Security
Рет қаралды 2,4 М.
Why are you NOT Using These 5 Microsoft 365 Apps?
25:27
Andy Malone MVP
Рет қаралды 39 М.
Lock Down Your Microsoft 365: Your Essential Security Policies
22:09
Jonathan Edwards
Рет қаралды 38 М.
Group Policy 5 Nuggets Every Admin MUST Know!
26:14
Andy Malone MVP
Рет қаралды 9 М.
Is Microsoft Loop the End of OneNote?
17:57
Jonathan Edwards
Рет қаралды 289 М.
Magic trick 🪄😁
00:13
Andrey Grechka
Рет қаралды 52 МЛН