What the Required MFA announcement really means.

  Рет қаралды 27,002

John Savill's Technical Training

John Savill's Technical Training

Күн бұрын

Пікірлер: 71
@NTFAQGuy
@NTFAQGuy 6 ай бұрын
Hey everyone, lets look at what the required MFA update really means! Please make sure to read the description for the chapters and key information about this video and others. ⚠ P L E A S E N O T E ⚠ 🔎 If you are looking for content on a particular topic search the channel. If I have something it will be there! 🕰 I don't discuss future content nor take requests for future content so please don't ask 😇 🤔 Due to the channel growth and number of people wanting help I no longer can answer or even read questions and they will just stay in the moderation queue never to be seen so please post questions to other sites like Reddit, Microsoft Community Hub etc. 👂 Translate the captions to your native language via the auto-translate feature in settings! kzbin.info/www/bejne/rGbFZmZjhcx4o6s for a demo of using this feature. Thanks for watching! 🤙
@Adam-su4re
@Adam-su4re 6 ай бұрын
Clear explanation of the MFA announcement. Thanks John 👍
@NTFAQGuy
@NTFAQGuy 6 ай бұрын
Very welcome
@MrFirsito
@MrFirsito 6 ай бұрын
congrats Microsoft, accomplish to yet again making things more complicated edit: thanks for the video! great way to explain a rather obscure change
@MarkGibson85
@MarkGibson85 6 ай бұрын
Great video, thanks as always John. For the KQL, I had to change: | where AuthenticationDetails has "SingleFactorAuthentication" to | where AuthenticationRequirement has "SingleFactorAuthentication" i.e. SigninLogs | where UserDisplayName != "" | where UserPrincipalName != "" | where (AppDisplayName == "Azure Portal" or AppDisplayName == "Microsoft Azure PowerShell" or AppDisplayName == "Microsoft Azure CLI") | where AuthenticationRequirement has "SingleFactorAuthentication" | project TimeGenerated, UserDisplayName, UserPrincipalName, AppDisplayName, AuthenticationDetails
@adamr4654
@adamr4654 6 ай бұрын
Fantastic stuff John thanks for the reply in MS blog post, you have provided more clarity than Microsoft!
@renatojrestorque6150
@renatojrestorque6150 6 ай бұрын
Thank you, Chief. This is a great update. 👍👍😉
@NTFAQGuy
@NTFAQGuy 6 ай бұрын
You bet
@NZScottie
@NZScottie Ай бұрын
Nice. I’ll be better prepared with this understanding if something unexpected happens. Thanks John.
@VirtualPackets
@VirtualPackets 6 ай бұрын
Thanks for the clarification John, makes perfect sense in today world. Already doing all of this :-) so not going to have much of an impact, will keep an eye out for announcement in the portal.
@ajayshankasringh
@ajayshankasringh 6 ай бұрын
Easy to understand, sir, you are a Great teacher 🙏
@NTFAQGuy
@NTFAQGuy 6 ай бұрын
So nice of you. Thanks!
@jakeindalecio
@jakeindalecio 6 ай бұрын
Our problem is with Entra SSPR not supporting the external preview. Moving away from the CA custom control for Duo, any verification methods set up for SSPR show up in the list with Duo meaning a user can bypass our policy to use Duo by choosing a voice call or SMS for example. Our MSFT rep is looking into it but hasn't found anything so far.
@Bhushimal
@Bhushimal 4 ай бұрын
You are really a good Teacher,.Love from India 🎉
@NTFAQGuy
@NTFAQGuy 4 ай бұрын
Thank you!
@tony6626
@tony6626 6 ай бұрын
Great video John. Only problem i see here is with our break glass accounts - only accounts excluded from MFA as it stands anyway.
@NTFAQGuy
@NTFAQGuy 6 ай бұрын
Yep talked about those in the video.
@butztanx
@butztanx 6 ай бұрын
Fantastic content, thanks for taking the time to do these videos. They're very much appreciated.
@NTFAQGuy
@NTFAQGuy 6 ай бұрын
My pleasure!
@jonsmallwood1657
@jonsmallwood1657 6 ай бұрын
Thanks John. I appreciate your breakdown of their announcement.
@NTFAQGuy
@NTFAQGuy 6 ай бұрын
You bet
@dgthekiller
@dgthekiller 6 ай бұрын
I missed that announcement, great video! I find Entra very confusing when it comes to licensing. Especially in mixed entra license environments. It is quite hard to stay license compliant. I also wish they would add a entra p2 license step up from p1. Especially those for business premium users.
@Lethal83
@Lethal83 6 ай бұрын
Great video John. Made it very clear and easy to follow as always.
@lukebrennan5780
@lukebrennan5780 6 ай бұрын
Thanks, Mr NTFAQ. (time flies!). This should have come from the PM's. heh! Really appreciate this.
@NTFAQGuy
@NTFAQGuy 6 ай бұрын
lol. Hey stranger :)
@AHumanMale
@AHumanMale 6 ай бұрын
"That's wrong... don't do that." Good advice! 🙂
@jonkilner8816
@jonkilner8816 6 ай бұрын
So, Microsoft are releasing a feature in July that affects authentication, you can't opt out of, with a half baked attempt at communicating the change in a blog post.....and they're still gathering feedback. I know you say it won't happen all at once. But what if my tenant is among the first batch to have the change applied. Then it's happening in just over a month and we' don't know the full scope of the change. Seems to me like something's happening in the background and there's a big rush to get this change out. We've only recently had the Microsoft managed conditional access policy rollout, which had better communication and planning wrapped around it, so you could measure its impact and deploy your own version of the policy if required
@GavinPeters
@GavinPeters 6 ай бұрын
I'm surprised to hear that the break glass fido recommendation is 2 years old. 6 months ago, I set up PIM with BG accounts and ms documentation definitely still had the two safes method.
@twistedaus
@twistedaus 5 ай бұрын
Great video as usual. Microsoft have really sh*t the bed with this one....
@yulaw3289
@yulaw3289 6 ай бұрын
enjoying this video for today learning, thanks a lot!
@NTFAQGuy
@NTFAQGuy 6 ай бұрын
Glad you enjoyed it!
@suneed1989
@suneed1989 6 ай бұрын
Thank you - very well explained 👍
@NTFAQGuy
@NTFAQGuy 6 ай бұрын
Glad it was helpful!
@GavinPeters
@GavinPeters 6 ай бұрын
Hmm, i wonder how this affects resources. I need to check our Teams-room set up as we use CA to remove mfa need. I'm not sure if they're set up a user accounts or not.
@GavinPeters
@GavinPeters 6 ай бұрын
Oops, nevermind, I just realised that we don't manage anything using the room logins. This does not affect our resources, as per John's teachings.
@LifeisbetterwithaMalinois
@LifeisbetterwithaMalinois 6 ай бұрын
Thxs sir John😊
@NTFAQGuy
@NTFAQGuy 6 ай бұрын
Welcome 😊
@jlou65535
@jlou65535 6 ай бұрын
Clear explanation as usual !
@NTFAQGuy
@NTFAQGuy 6 ай бұрын
Glad it was helpful!
@jadan2000
@jadan2000 6 ай бұрын
Thanks for this. Currently if you turn on MFA in Azure, it also is turned on for o365, since its the same identity management. Does that change with this new feature?
@NTFAQGuy
@NTFAQGuy 6 ай бұрын
MFA requirement is based on the target service. Just because a user has setup MFA does not mean its now required for everything. This only applies to those services I talk about in the video.
@AzureCloudCowboy
@AzureCloudCowboy 6 ай бұрын
Awesome as always.
@NTFAQGuy
@NTFAQGuy 6 ай бұрын
Thank you! Cheers!
@GiovanniOrlandoi7
@GiovanniOrlandoi7 6 ай бұрын
Thanks for the video!
@NTFAQGuy
@NTFAQGuy 6 ай бұрын
You're welcome!
@timolean5846
@timolean5846 6 ай бұрын
So if you create service accounts as users to avoid mfa you’ll want to switch to using service principals? Currently we just exclude them from our CA policies.
@NTFAQGuy
@NTFAQGuy 6 ай бұрын
You shouldn't be creating user accounts for service accounts. Yes, use service principal.
@tajammulrizvi9504
@tajammulrizvi9504 6 ай бұрын
Really useful Session.
@NTFAQGuy
@NTFAQGuy 6 ай бұрын
Glad to hear that!
@markdriver8511
@markdriver8511 6 ай бұрын
Great video thanks :-)
@skatterbrainz
@skatterbrainz 6 ай бұрын
"carbon-based fleshy things" - lol!
@Timmy-Hi5
@Timmy-Hi5 6 ай бұрын
seems that Superman is angry today 😁or the mic is on max loudness 🤩 or MFA makes him angry 😎😁
@NTFAQGuy
@NTFAQGuy 6 ай бұрын
ROFL, didn't notice
@Timmy-Hi5
@Timmy-Hi5 6 ай бұрын
@@NTFAQGuy 😁 all good ...I was under the impression someone stole your doughnut allowance 😁
@NTFAQGuy
@NTFAQGuy 6 ай бұрын
I would pity that person :-D
@Timmy-Hi5
@Timmy-Hi5 6 ай бұрын
@@NTFAQGuy 😂
@robertsprouse8903
@robertsprouse8903 6 ай бұрын
Guess I need to buy stock in FIDO keys. Where I work no cell phones are allowed.
@NTFAQGuy
@NTFAQGuy 6 ай бұрын
ROFL
@ikennashonowo9250
@ikennashonowo9250 6 ай бұрын
Nice
@NTFAQGuy
@NTFAQGuy 6 ай бұрын
Thanks
@jadan2000
@jadan2000 6 ай бұрын
Also. If I'm using Conditional access policies for MFA and I have users in the exceptions list, will they now be required to use MFA?
@NTFAQGuy
@NTFAQGuy 6 ай бұрын
I address this in the video. Yes, its cumulative.
@jadan2000
@jadan2000 6 ай бұрын
@NTFAQGuy I must have missed that part. Thank you. Wow that's a bit painful.
@DavidWorthington
@DavidWorthington 5 ай бұрын
It’s a good thing. “Who moved my cheese” shouldn’t apply here.
@ZATennisFan
@ZATennisFan 6 ай бұрын
It was not the most clearly written post of all time. Especially if you are not an EntraID junkie…. 🤣🤣
@NTFAQGuy
@NTFAQGuy 6 ай бұрын
lol
@ZATennisFan
@ZATennisFan 6 ай бұрын
@@NTFAQGuyThere was a great deal of wailing and gnashing of teeth by some of my colleagues 🤣🤣
@NTFAQGuy
@NTFAQGuy 6 ай бұрын
hahahahaha
@shawndeggans
@shawndeggans 6 ай бұрын
I guess carbon-based fleshy things is better than meat-bags.
@NTFAQGuy
@NTFAQGuy 6 ай бұрын
💯
Microsoft Intune From Zero to Hero
39:08
Andy Malone MVP
Рет қаралды 250 М.
Clean Architecture with ASP.NET Core 8 | .NET Conf 2023
29:17
FOREVER BUNNY
00:14
Natan por Aí
Рет қаралды 34 МЛН
Чистка воды совком от денег
00:32
FD Vasya
Рет қаралды 4,1 МЛН
PASSKEYS - What they are, why we want them and how to use them!
1:10:42
John Savill's Technical Training
Рет қаралды 39 М.
Using the Well-Architected Framework
34:39
John Savill's Technical Training
Рет қаралды 40 М.
NVIDIA’s New AI: Stunning Voice Generator!
6:21
Two Minute Papers
Рет қаралды 110 М.
Where are the keys in passkeys?
22:36
John Savill's Technical Training
Рет қаралды 4 М.
Ollama on Kubernetes: ChatGPT for free!
18:29
Mathis Van Eetvelde
Рет қаралды 8 М.
How hackers are breaking into MFA enabled Microsoft 365 accounts
6:00
Microsoft Entra ID Governance
33:28
John Savill's Technical Training
Рет қаралды 25 М.
Do NOT Learn Kubernetes Without Knowing These Concepts...
13:01
Travis Media
Рет қаралды 326 М.
Microsoft Copilot for Security
48:36
John Savill's Technical Training
Рет қаралды 17 М.
Passkeys: The Future Of Authentication
31:22
Theo - t3․gg
Рет қаралды 87 М.
FOREVER BUNNY
00:14
Natan por Aí
Рет қаралды 34 МЛН