home.social

#azuread โ€” Public Fediverse posts

Live and recent posts from across the Fediverse tagged #azuread, aggregated by home.social.

  1. What are your biggest Entra (AzureAD) Conditional Access questions or pain points? I'm working on a giant Conditional Access post for the #TrustedSec blog -- would welcome your inputs!
    #Microsoft #Entra #AzureAD #Azure #ConditionalAccess #conditionalaccesspolicies

  2. I'd like to point out this really interesting article on the topic: ๐“๐จ๐ค๐ž๐ง ๐“๐ก๐ž๐Ÿ๐ญ ๐“๐š๐ฅ๐ค.

    Key points and topics covered:

    - Primary Refresh Tokens (PRT) on all operating system platforms have been hardened against theft from day one. The level of protection depends on operated system capabilities, with Windows offering the strongest protection.

    - First line of defense against token theft is protecting your devices by deploying endpoint protections, device management, MFA (and moving towards phishing-resistant credentials), and antimalware

    You can reduce token theft by carefully orchestrating Entra ID security products:

    โ–ถAddressing token theft of sign-in session artifacts: Conditional Access: Token protection policy offers cryptographic protection against replay of stolen tokens.

    โ–ถAddressing token theft of app session artifacts: block usage of stolen access tokens and workload cookies outside of your corporate network by using Conditional Access.

    โ–ถDetecting token theft: enable risk detections with Microsoft Entra ID Protection to elevate user risk when token theft is suspected.

    techcommunity.microsoft.com/t5

    #microsoft #microsoftsecurity #entraid #azuread #azure #idp #token #tokentheft #cloudsecurity #identity #prt #cookies #identityprotection #mfa #cae #conditionalaccess #refreshtoken #token

  3. #AzureAD #MFA is having a bad day right now, I can't sign-in into #Microsoft #EntraID with my admin accounts.

    And since I messed up the #ConditionalAccessPolicy exclusions my #BreakGlass account is useless too.

  4. ๐— ๐—ถ๐—ฐ๐—ฟ๐—ผ๐˜€๐—ผ๐—ณ๐˜ ๐—˜๐—ป๐˜๐—ฟ๐—ฎ ๐—ฃ๐—ฟ๐—ถ๐˜ƒ๐—ฎ๐˜๐—ฒ ๐—”๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€: ๐—”๐—ป ๐—œ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐˜๐˜†-๐—–๐—ฒ๐—ป๐˜๐—ฟ๐—ถ๐—ฐ ๐—ญ๐—ฒ๐—ฟ๐—ผ ๐—ง๐—ฟ๐˜‚๐˜€๐˜ ๐—ก๐—ฒ๐˜๐˜„๐—ผ๐—ฟ๐—ธ ๐—”๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€ ๐—ฆ๐—ผ๐—น๐˜‚๐˜๐—ถ๐—ผ๐—ป

    Private Access in Microsoft's SSE solution offers secure, controlled access to private resources using Zero Trust principles, expanded from the existing Entra ID Application Proxy. It supports a range of protocols, authentication methods, and anomaly detection, all benefiting from Microsoft's extensive global network.

    Find out more info:

    techcommunity.microsoft.com/t5

    Here's a summarized breakdown of the provided information:

    1๏ธโƒฃPrivate Access in Microsoft's SSE Solution:

    โœ”๏ธBuilt on Zero Trust principles.

    โœ”๏ธVerifies every user and enforces least privilege.

    โœ”๏ธGrants access only to needed private applications and resources.

    2๏ธโƒฃExpansion of Entra ID Application Proxy:

    โœ”๏ธPrivate Access extends capabilities of Entra ID Application Proxy in Microsoft Entra.

    โœ”๏ธEvolves into a comprehensive Zero Trust Network Access (ZTNA) solution.

    โœ”๏ธShares connectors but offers expanded functionalities.

    3๏ธโƒฃAccess to Any Private Resource:

    โœ”๏ธSimplifies and secures access to private resources on any port and protocol.

    โœ”๏ธPolicies enable secure, segmented, and granular access to corporate network apps.

    โœ”๏ธCovers on-premises, cloud-based applications, and more.

    4๏ธโƒฃGranular Access Controls and Anomaly Detection:

    โœ”๏ธConditional Access policies offer per-app, least privilege controls.

    โœ”๏ธContextual information about users, devices, and locations enhances policies.

    โœ”๏ธAnomalies or changes trigger session termination or stronger authentication.

    5๏ธโƒฃSecure Access Across Ports and Protocols:

    โœ”๏ธPrivate Access enables secure entry to applications, regardless of location.

    โœ”๏ธWorks with various protocols, including RDP, SSH, SMB, FTP, TCP, and UDP.

    6๏ธโƒฃDiverse Authentication Methods:

    โœ”๏ธSupports single sign-on (SSO) via SAML, http headers, or legacy Kerberos.

    โœ”๏ธNo need for application modifications.

    7๏ธโƒฃMicrosoft's Global Network Advantage:

    โœ”๏ธPrivate Access utilizes Microsoft's vast global network for delivery.

    โœ”๏ธEnhanced security and faster access compared to traditional VPNs.

    โœ”๏ธOptimized connection for hybrid and remote work scenarios.

    #microsoft #entra #sse #ZTNA #ZeroTrustNetworkAccess #ZeroTrust #sso #saml #mfa #conditionalaccess #azuread #securityserviceedge #vpn #azure #cloud #cloudsecurity

  5. #Token #revocation and #expiration in #AzureAD is important in terms of responding to #security #incidents affecting Azure AD. How and when do tokens expire or what are the revocation options?

    #Access tokens typically have an expiration time of 60 minutes. And there is no way to manually invalidate an access token except by manually deleting the token in the cache on the device.

    #Refresh tokens typically have a default expiration of 90 days. However, refresh tokens can be invalidated by an admin from the Azure portal or using PowerShell or the Graph API.

    A Primary Refresh Token (#PRT) is invalidated when the Azure AD account is disabled or deleted, the user password is changed or reset, or the device where the PRT was issued is disabled or deleted.

  6. A rich #training #offer at BSides Milano we have top-notch trainings, in some case for the first time in #Italy! All #in-person! The #event will be held from 4 to 8 July 2023. From 4 to 7 we will be focus on #learnitall on the 8 we will deep dive in our #amazing #conference. Ticket will be available from tonight for the trainings. We have an early bird rate until 30th April.
    Are you ready? We are!! join our group SecurityBsidesItalia #linkedin or on #discord lnkd.in/dBu7wkJG for detailed info! #cyber #threatintelligence #threatintel #cloud #redteaming #redteam #blueteam #threathunting #exploitation #secureboot #TTE #multicloud #hybridcloud #voip #Linux #Windows #LTE #baseband #deception #detection #evasion #edr #BSML23 #AWS #Azure #AzureAD #GCP #devops #cicd #RTOS #FalseFlag #HoneyNet #IDAPro #Python #reverseengineering #Ghidra #network #MITRE #TTPs #persistence #commandandcontrol #lateralmovement #osint #obfuscation #malware #malwareanalysis .
    Reserve your your spot!! lnkd.in/dZf-yyPv

  7. #Password #expiration for accounts no longer makes sense and is not recommended if multi-factor authentication (#MFA) is used. For this reason, it is recommended to disable password expiration in the #Microsoft365 environment as well.

    But what if the company has synchronized identities in the Password Hash Sync (#PHS) scenario? In that case, the #AzureAD password expiration policy is not applied to the synchronized accounts. And such accounts passwords are always set to never expire. It is assumed that in such a case the policy in Active Directory handles this.

    But what if the user never authenticates to the local AD? The computer has Azure AD Join and the user is only using cloud services. The password for his AD account has expired, but he doesn't even know about it, and Azure AD still authenticates the user because passwords for synchronized accounts never expire.

    In this case, you need to configure the Azure AD Connect server to apply the Azure AD password expiration policy also to synchronized accounts. This can be done using PowerShell on the Azure AD Connect server: Set-MsolDirSyncFeature -Feature EnforceCloudPasswordPolicyForPasswordSyncedUsers