#azuread โ Public Fediverse posts
Live and recent posts from across the Fediverse tagged #azuread, aggregated by home.social.
-
What are your biggest Entra (AzureAD) Conditional Access questions or pain points? I'm working on a giant Conditional Access post for the #TrustedSec blog -- would welcome your inputs!
#Microsoft #Entra #AzureAD #Azure #ConditionalAccess #conditionalaccesspolicies -
I'd like to point out this really interesting article on the topic: ๐๐จ๐ค๐๐ง ๐๐ก๐๐๐ญ ๐๐๐ฅ๐ค.
Key points and topics covered:
- Primary Refresh Tokens (PRT) on all operating system platforms have been hardened against theft from day one. The level of protection depends on operated system capabilities, with Windows offering the strongest protection.
- First line of defense against token theft is protecting your devices by deploying endpoint protections, device management, MFA (and moving towards phishing-resistant credentials), and antimalware
You can reduce token theft by carefully orchestrating Entra ID security products:
โถAddressing token theft of sign-in session artifacts: Conditional Access: Token protection policy offers cryptographic protection against replay of stolen tokens.
โถAddressing token theft of app session artifacts: block usage of stolen access tokens and workload cookies outside of your corporate network by using Conditional Access.
โถDetecting token theft: enable risk detections with Microsoft Entra ID Protection to elevate user risk when token theft is suspected.
#microsoft #microsoftsecurity #entraid #azuread #azure #idp #token #tokentheft #cloudsecurity #identity #prt #cookies #identityprotection #mfa #cae #conditionalaccess #refreshtoken #token
-
#AzureAD #MFA is having a bad day right now, I can't sign-in into #Microsoft #EntraID with my admin accounts.
And since I messed up the #ConditionalAccessPolicy exclusions my #BreakGlass account is useless too.
-
๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐๐ป๐๐ฟ๐ฎ ๐ฃ๐ฟ๐ถ๐๐ฎ๐๐ฒ ๐๐ฐ๐ฐ๐ฒ๐๐: ๐๐ป ๐๐ฑ๐ฒ๐ป๐๐ถ๐๐-๐๐ฒ๐ป๐๐ฟ๐ถ๐ฐ ๐ญ๐ฒ๐ฟ๐ผ ๐ง๐ฟ๐๐๐ ๐ก๐ฒ๐๐๐ผ๐ฟ๐ธ ๐๐ฐ๐ฐ๐ฒ๐๐ ๐ฆ๐ผ๐น๐๐๐ถ๐ผ๐ป
Private Access in Microsoft's SSE solution offers secure, controlled access to private resources using Zero Trust principles, expanded from the existing Entra ID Application Proxy. It supports a range of protocols, authentication methods, and anomaly detection, all benefiting from Microsoft's extensive global network.
Find out more info:
Here's a summarized breakdown of the provided information:
1๏ธโฃPrivate Access in Microsoft's SSE Solution:
โ๏ธBuilt on Zero Trust principles.
โ๏ธVerifies every user and enforces least privilege.
โ๏ธGrants access only to needed private applications and resources.
2๏ธโฃExpansion of Entra ID Application Proxy:
โ๏ธPrivate Access extends capabilities of Entra ID Application Proxy in Microsoft Entra.
โ๏ธEvolves into a comprehensive Zero Trust Network Access (ZTNA) solution.
โ๏ธShares connectors but offers expanded functionalities.
3๏ธโฃAccess to Any Private Resource:
โ๏ธSimplifies and secures access to private resources on any port and protocol.
โ๏ธPolicies enable secure, segmented, and granular access to corporate network apps.
โ๏ธCovers on-premises, cloud-based applications, and more.
4๏ธโฃGranular Access Controls and Anomaly Detection:
โ๏ธConditional Access policies offer per-app, least privilege controls.
โ๏ธContextual information about users, devices, and locations enhances policies.
โ๏ธAnomalies or changes trigger session termination or stronger authentication.
5๏ธโฃSecure Access Across Ports and Protocols:
โ๏ธPrivate Access enables secure entry to applications, regardless of location.
โ๏ธWorks with various protocols, including RDP, SSH, SMB, FTP, TCP, and UDP.
6๏ธโฃDiverse Authentication Methods:
โ๏ธSupports single sign-on (SSO) via SAML, http headers, or legacy Kerberos.
โ๏ธNo need for application modifications.
7๏ธโฃMicrosoft's Global Network Advantage:
โ๏ธPrivate Access utilizes Microsoft's vast global network for delivery.
โ๏ธEnhanced security and faster access compared to traditional VPNs.
โ๏ธOptimized connection for hybrid and remote work scenarios.
#microsoft #entra #sse #ZTNA #ZeroTrustNetworkAccess #ZeroTrust #sso #saml #mfa #conditionalaccess #azuread #securityserviceedge #vpn #azure #cloud #cloudsecurity
-
#Token #revocation and #expiration in #AzureAD is important in terms of responding to #security #incidents affecting Azure AD. How and when do tokens expire or what are the revocation options?
#Access tokens typically have an expiration time of 60 minutes. And there is no way to manually invalidate an access token except by manually deleting the token in the cache on the device.
#Refresh tokens typically have a default expiration of 90 days. However, refresh tokens can be invalidated by an admin from the Azure portal or using PowerShell or the Graph API.
A Primary Refresh Token (#PRT) is invalidated when the Azure AD account is disabled or deleted, the user password is changed or reset, or the device where the PRT was issued is disabled or deleted.
-
A rich #training #offer at BSides Milano we have top-notch trainings, in some case for the first time in #Italy! All #in-person! The #event will be held from 4 to 8 July 2023. From 4 to 7 we will be focus on #learnitall on the 8 we will deep dive in our #amazing #conference. Ticket will be available from tonight for the trainings. We have an early bird rate until 30th April.
Are you ready? We are!! join our group SecurityBsidesItalia #linkedin or on #discord https://lnkd.in/dBu7wkJG for detailed info! #cyber #threatintelligence #threatintel #cloud #redteaming #redteam #blueteam #threathunting #exploitation #secureboot #TTE #multicloud #hybridcloud #voip #Linux #Windows #LTE #baseband #deception #detection #evasion #edr #BSML23 #AWS #Azure #AzureAD #GCP #devops #cicd #RTOS #FalseFlag #HoneyNet #IDAPro #Python #reverseengineering #Ghidra #network #MITRE #TTPs #persistence #commandandcontrol #lateralmovement #osint #obfuscation #malware #malwareanalysis .
Reserve your your spot!! https://lnkd.in/dZf-yyPv -
#Password #expiration for accounts no longer makes sense and is not recommended if multi-factor authentication (#MFA) is used. For this reason, it is recommended to disable password expiration in the #Microsoft365 environment as well.
But what if the company has synchronized identities in the Password Hash Sync (#PHS) scenario? In that case, the #AzureAD password expiration policy is not applied to the synchronized accounts. And such accounts passwords are always set to never expire. It is assumed that in such a case the policy in Active Directory handles this.
But what if the user never authenticates to the local AD? The computer has Azure AD Join and the user is only using cloud services. The password for his AD account has expired, but he doesn't even know about it, and Azure AD still authenticates the user because passwords for synchronized accounts never expire.
In this case, you need to configure the Azure AD Connect server to apply the Azure AD password expiration policy also to synchronized accounts. This can be done using PowerShell on the Azure AD Connect server: Set-MsolDirSyncFeature -Feature EnforceCloudPasswordPolicyForPasswordSyncedUsers