home.social

#conditionalaccess โ€” Public Fediverse posts

Live and recent posts from across the Fediverse tagged #conditionalaccess, aggregated by home.social.

  1. ๐Ÿ”’ Blocking Device Code Flow in M365, full mini-toolkit now on GitHub:

    1๏ธโƒฃ Audit script => verify zero legitimate usage before blocking (all 4 Entra sign-in log types)
    2๏ธโƒฃ CA policy JSON => ready to import, just replace your break-glass group ID

    ๐Ÿ”— github.com/Bluewal/m365-intune

    #infosec #Microsoft365 #EntraID #ConditionalAccess #BlueTeam #PowerShell

  2. ๐Ÿ”’ Blocking Device Code Flow in M365, full mini-toolkit now on GitHub:

    1๏ธโƒฃ Audit script => verify zero legitimate usage before blocking (all 4 Entra sign-in log types)
    2๏ธโƒฃ CA policy JSON => ready to import, just replace your break-glass group ID

    ๐Ÿ”— github.com/Bluewal/m365-intune

    #infosec #Microsoft365 #EntraID #ConditionalAccess #BlueTeam #PowerShell

  3. ๐Ÿšจ EvilTokens / AiTM attacks are actively abusing Device Code Flow to bypass MFA in M365 tenants.

    Before blocking it via Conditional Access โ€” verify it's actually unused in your environment.

    Script queries all 4 Entra sign-in log types via Microsoft Graph:
    โœ… No results โ†’ safe to block immediately
    โš ๏ธ Results found โ†’ review before deploying

    ๐Ÿ”— github.com/Bluewal/m365-intune

    #infosec #Microsoft365 #EntraID #ConditionalAccess #BlueTeam #PowerShell

  4. ๐Ÿšจ Entra ID External MFA (old name was External Authentication Methods) is now Generally Available.

    Custom Controls is being deprecated on 30 Sept 2026.

    Here's how to check your usage.

    thedxt.ca/2026/03/microsoft-en

    #Entra #MFA #M365 #Microsoft #Microsoft365 #ConditionalAccess

  5. ๐‡๐จ๐ฐ ๐‚๐จ๐ง๐๐ข๐ญ๐ข๐จ๐ง๐š๐ฅ ๐€๐œ๐œ๐ž๐ฌ๐ฌ ๐๐จ๐ฅ๐ข๐œ๐ข๐ž๐ฌ ๐€๐ซ๐ž ๐„๐ฏ๐š๐ฅ๐ฎ๐š๐ญ๐ž๐ ๐ข๐ง ๐Œ๐ข๐œ๐ซ๐จ๐ฌ๐จ๐Ÿ๐ญ ๐„๐ง๐ญ๐ซ๐š ๐ˆ๐ƒ

    Understanding how Conditional Access policies are evaluated in Microsoft Entra ID is absolutely essential if you are involved in their creation or management.

    I often encounter fundamental misunderstandings regarding how the evaluation of Conditional Access policies takes place. Many administrators are accustomed to systems like firewalls, where there is an order or priority for evaluating created rules. However, it does not work this way with Conditional Access policies in Microsoft Entra ID. Applying the same principle to Conditional Access policies will very likely lead to significant security risks.

    Read my blog post bellow ๐Ÿ‘‡ ๐Ÿ‘‡
    cswrld.com/2026/02/how-conditi

    #cswrld #entraid #securitytips #conditionalaccess

  6. ๐‡๐จ๐ฐ ๐‚๐จ๐ง๐๐ข๐ญ๐ข๐จ๐ง๐š๐ฅ ๐€๐œ๐œ๐ž๐ฌ๐ฌ ๐๐จ๐ฅ๐ข๐œ๐ข๐ž๐ฌ ๐€๐ซ๐ž ๐„๐ฏ๐š๐ฅ๐ฎ๐š๐ญ๐ž๐ ๐ข๐ง ๐Œ๐ข๐œ๐ซ๐จ๐ฌ๐จ๐Ÿ๐ญ ๐„๐ง๐ญ๐ซ๐š ๐ˆ๐ƒ

    Understanding how Conditional Access policies are evaluated in Microsoft Entra ID is absolutely essential if you are involved in their creation or management.

    I often encounter fundamental misunderstandings regarding how the evaluation of Conditional Access policies takes place. Many administrators are accustomed to systems like firewalls, where there is an order or priority for evaluating created rules. However, it does not work this way with Conditional Access policies in Microsoft Entra ID. Applying the same principle to Conditional Access policies will very likely lead to significant security risks.

    Read my blog post bellow ๐Ÿ‘‡ ๐Ÿ‘‡
    cswrld.com/2026/02/how-conditi

    #cswrld #entraid #securitytips #conditionalaccess

  7. ๐‡๐จ๐ฐ ๐‚๐จ๐ง๐๐ข๐ญ๐ข๐จ๐ง๐š๐ฅ ๐€๐œ๐œ๐ž๐ฌ๐ฌ ๐๐จ๐ฅ๐ข๐œ๐ข๐ž๐ฌ ๐€๐ซ๐ž ๐„๐ฏ๐š๐ฅ๐ฎ๐š๐ญ๐ž๐ ๐ข๐ง ๐Œ๐ข๐œ๐ซ๐จ๐ฌ๐จ๐Ÿ๐ญ ๐„๐ง๐ญ๐ซ๐š ๐ˆ๐ƒ

    Understanding how Conditional Access policies are evaluated in Microsoft Entra ID is absolutely essential if you are involved in their creation or management.

    I often encounter fundamental misunderstandings regarding how the evaluation of Conditional Access policies takes place. Many administrators are accustomed to systems like firewalls, where there is an order or priority for evaluating created rules. However, it does not work this way with Conditional Access policies in Microsoft Entra ID. Applying the same principle to Conditional Access policies will very likely lead to significant security risks.

    Read my blog post bellow ๐Ÿ‘‡ ๐Ÿ‘‡
    cswrld.com/2026/02/how-conditi

    #cswrld #entraid #securitytips #conditionalaccess

  8. ๐‡๐จ๐ฐ ๐‚๐จ๐ง๐๐ข๐ญ๐ข๐จ๐ง๐š๐ฅ ๐€๐œ๐œ๐ž๐ฌ๐ฌ ๐๐จ๐ฅ๐ข๐œ๐ข๐ž๐ฌ ๐€๐ซ๐ž ๐„๐ฏ๐š๐ฅ๐ฎ๐š๐ญ๐ž๐ ๐ข๐ง ๐Œ๐ข๐œ๐ซ๐จ๐ฌ๐จ๐Ÿ๐ญ ๐„๐ง๐ญ๐ซ๐š ๐ˆ๐ƒ

    Understanding how Conditional Access policies are evaluated in Microsoft Entra ID is absolutely essential if you are involved in their creation or management.

    I often encounter fundamental misunderstandings regarding how the evaluation of Conditional Access policies takes place. Many administrators are accustomed to systems like firewalls, where there is an order or priority for evaluating created rules. However, it does not work this way with Conditional Access policies in Microsoft Entra ID. Applying the same principle to Conditional Access policies will very likely lead to significant security risks.

    Read my blog post bellow ๐Ÿ‘‡ ๐Ÿ‘‡
    cswrld.com/2026/02/how-conditi

    #cswrld #entraid #securitytips #conditionalaccess

  9. Last week #Microsoft published #MC1123830 where they announced #Entra #ConditionalAccess updates indicating that #AzureDevOps (ADO) will be separated from Azure Resource Manager (ARM). This means that you might have to update your policies in order to allow access to #ADO.

  10. Last week #Microsoft published #MC1123830 where they announced #Entra #ConditionalAccess updates indicating that #AzureDevOps (ADO) will be separated from Azure Resource Manager (ARM). This means that you might have to update your policies in order to allow access to #ADO.

  11. Last week #Microsoft published #MC1123830 where they announced #Entra #ConditionalAccess updates indicating that #AzureDevOps (ADO) will be separated from Azure Resource Manager (ARM). This means that you might have to update your policies in order to allow access to #ADO.

  12. Last week #Microsoft published #MC1123830 where they announced #Entra #ConditionalAccess updates indicating that #AzureDevOps (ADO) will be separated from Azure Resource Manager (ARM). This means that you might have to update your policies in order to allow access to #ADO.

  13. ๐—›๐—ผ๐˜„ ๐˜๐—ผ ๐—ฏ๐—น๐—ผ๐—ฐ๐—ธ ๐˜‚๐—ป๐—ธ๐—ป๐—ผ๐˜„๐—ป ๐—ฝ๐—น๐—ฎ๐˜๐—ณ๐—ผ๐—ฟ๐—บ๐˜€ ๐—ถ๐—ป ๐— ๐—ถ๐—ฐ๐—ฟ๐—ผ๐˜€๐—ผ๐—ณ๐˜ ๐—˜๐—ป๐˜๐—ฟ๐—ฎ ๐—œ๐——

    Under conditional access policies, it is possible to block individual device platforms. In general, it is a good idea to eliminate all ways that a potential threat actor could use to compromise the environment. In other words, block everything that is not needed.

    This also applies to device platforms within Microsoft Entra ID. For example, if your organization only uses Windows, iOS, and Android, it's a good idea to disable all other platforms. If you also use macOS, you need to add macOS as well, of course.

    What I would definitely recommend blocking is Windows Phone and other unknown platforms. Unrecognized / unknown platforms are usually spoofed User Agents, which is mainly used by threat actors.

    ๐Ÿ“บ Watch my YouTube video bellow ๐Ÿ‘‡ ๐Ÿ‘‡
    youtu.be/vFhQgwXmqTo

    #cswrld #videotutorial #entraid #conditionalaccess #platforms #blocking

  14. ๐—›๐—ผ๐˜„ ๐˜๐—ผ ๐—ฏ๐—น๐—ผ๐—ฐ๐—ธ ๐˜‚๐—ป๐—ธ๐—ป๐—ผ๐˜„๐—ป ๐—ฝ๐—น๐—ฎ๐˜๐—ณ๐—ผ๐—ฟ๐—บ๐˜€ ๐—ถ๐—ป ๐— ๐—ถ๐—ฐ๐—ฟ๐—ผ๐˜€๐—ผ๐—ณ๐˜ ๐—˜๐—ป๐˜๐—ฟ๐—ฎ ๐—œ๐——

    Under conditional access policies, it is possible to block individual device platforms. In general, it is a good idea to eliminate all ways that a potential threat actor could use to compromise the environment. In other words, block everything that is not needed.

    This also applies to device platforms within Microsoft Entra ID. For example, if your organization only uses Windows, iOS, and Android, it's a good idea to disable all other platforms. If you also use macOS, you need to add macOS as well, of course.

    What I would definitely recommend blocking is Windows Phone and other unknown platforms. Unrecognized / unknown platforms are usually spoofed User Agents, which is mainly used by threat actors.

    ๐Ÿ“บ Watch my YouTube video bellow ๐Ÿ‘‡ ๐Ÿ‘‡
    youtu.be/vFhQgwXmqTo

    #cswrld #videotutorial #entraid #conditionalaccess #platforms #blocking

  15. ๐—›๐—ผ๐˜„ ๐˜๐—ผ ๐—ฏ๐—น๐—ผ๐—ฐ๐—ธ ๐˜‚๐—ป๐—ธ๐—ป๐—ผ๐˜„๐—ป ๐—ฝ๐—น๐—ฎ๐˜๐—ณ๐—ผ๐—ฟ๐—บ๐˜€ ๐—ถ๐—ป ๐— ๐—ถ๐—ฐ๐—ฟ๐—ผ๐˜€๐—ผ๐—ณ๐˜ ๐—˜๐—ป๐˜๐—ฟ๐—ฎ ๐—œ๐——

    Under conditional access policies, it is possible to block individual device platforms. In general, it is a good idea to eliminate all ways that a potential threat actor could use to compromise the environment. In other words, block everything that is not needed.

    This also applies to device platforms within Microsoft Entra ID. For example, if your organization only uses Windows, iOS, and Android, it's a good idea to disable all other platforms. If you also use macOS, you need to add macOS as well, of course.

    What I would definitely recommend blocking is Windows Phone and other unknown platforms. Unrecognized / unknown platforms are usually spoofed User Agents, which is mainly used by threat actors.

    ๐Ÿ“บ Watch my YouTube video bellow ๐Ÿ‘‡ ๐Ÿ‘‡
    youtu.be/vFhQgwXmqTo

    #cswrld #videotutorial #entraid #conditionalaccess #platforms #blocking

  16. ๐—›๐—ผ๐˜„ ๐˜๐—ผ ๐—ฏ๐—น๐—ผ๐—ฐ๐—ธ ๐˜‚๐—ป๐—ธ๐—ป๐—ผ๐˜„๐—ป ๐—ฝ๐—น๐—ฎ๐˜๐—ณ๐—ผ๐—ฟ๐—บ๐˜€ ๐—ถ๐—ป ๐— ๐—ถ๐—ฐ๐—ฟ๐—ผ๐˜€๐—ผ๐—ณ๐˜ ๐—˜๐—ป๐˜๐—ฟ๐—ฎ ๐—œ๐——

    Under conditional access policies, it is possible to block individual device platforms. In general, it is a good idea to eliminate all ways that a potential threat actor could use to compromise the environment. In other words, block everything that is not needed.

    This also applies to device platforms within Microsoft Entra ID. For example, if your organization only uses Windows, iOS, and Android, it's a good idea to disable all other platforms. If you also use macOS, you need to add macOS as well, of course.

    What I would definitely recommend blocking is Windows Phone and other unknown platforms. Unrecognized / unknown platforms are usually spoofed User Agents, which is mainly used by threat actors.

    ๐Ÿ“บ Watch my YouTube video bellow ๐Ÿ‘‡ ๐Ÿ‘‡
    youtu.be/vFhQgwXmqTo

    #cswrld #videotutorial #entraid #conditionalaccess #platforms #blocking

  17. This week there are a lot of changes coming down to Windows 11 and Entra. You know, the foundation of everything.

    link.publicate.it/pub/05c7133d
    #M365 #Entra #windows11 #conditionalaccess

  18. Authentication Strengths in Microsoft Entra ID allows you to granularly define authentication requirements for different situations.

    Before authentication strengths were available, authentication requirements were defined globally for the entire tenant, and then conditional access policies could just say that multi-factor authentication was required, for example. But it was not possible to define what type of multifactor authentication was required. So anything that was available globally could be used by all users in all situations.

    Which was not optimal. There are situations where a less secure authentication method like SMS or TOTP might be enough. But there are situations where we only want to use very secure authentication methods like FIDO2 when someone is logging into a global admin account for example.

    Such granularity was not possible before. If SMS authentication was enabled for a given tenant, even the global admin could use SMS for authentication.

    Watch my YouTube video bellow for more details ๐Ÿ‘‡ ๐Ÿ‘‡
    youtu.be/8sIX19pbdho

    #cswrld #cybersecurity #entraid #authentication #authenticationstrength #conditionalaccess

  19. RECOMMENDED CONDITIONAL ACCESS POLICIES IN MICROSOFT ENTRA ID

    Conditional access policies in Microsoft Entra ID allow for very granular security management. The problem is that organizations usually do not have conditional access policies properly defined. There tend to be blind spots, policies donโ€™t cover all applications, all users, and all scenarios.

    Many organizations have conditional access policies defined but do not think about them properly. This is because they often target only specific applications or specific users. And when I ask them why the MFA policy only targets Office 365 for example, they tell me they donโ€™t use anything else. Or when I ask why they only target one group of users, they tell me that other users donโ€™t use cloud services.

    But thatโ€™s just the wrong approach. You are not primarily protecting the services from your users, but from attackers. And just because you donโ€™t use anything other than Office 365 doesnโ€™t mean an attacker will not use it. Or just because some users donโ€™t use cloud services doesnโ€™t mean those accounts canโ€™t be exploited by an attacker. If those apps or accounts exist in the cloud, they need to be protected whether regular users use them or not. Attackers are looking for the most insecure places, the weakest links.

    ๐Ÿ“บ Watch my YouTube video bellow where I talk about the conditional access policies that I recommend implementing ๐Ÿ‘‡ ๐Ÿ‘‡
    youtu.be/LtIgFBDJzXs

    #cswrld #videotutorial #entraid #conditionalaccess #recommendation

  20. Conditional Access is hard - gaps can exist and you wonโ€™t even know.

    Never mind trying to keep on top of all the different policies and apps you have in place due to changing requirements over the years.

    Thatโ€™s why, aligning your policies to user personas is a great way to simplify your setup.

    learn.microsoft.com/en-us/azur

    #conditionalaccess #iam #entraid

  21. What are your biggest Entra (AzureAD) Conditional Access questions or pain points? I'm working on a giant Conditional Access post for the #TrustedSec blog -- would welcome your inputs!
    #Microsoft #Entra #AzureAD #Azure #ConditionalAccess #conditionalaccesspolicies

  22. What are your biggest Entra (AzureAD) Conditional Access questions or pain points? I'm working on a giant Conditional Access post for the #TrustedSec blog -- would welcome your inputs!
    #Microsoft #Entra #AzureAD #Azure #ConditionalAccess #conditionalaccesspolicies

  23. What are your biggest Entra (AzureAD) Conditional Access questions or pain points? I'm working on a giant Conditional Access post for the #TrustedSec blog -- would welcome your inputs!
    #Microsoft #Entra #AzureAD #Azure #ConditionalAccess #conditionalaccesspolicies

  24. What are your biggest Entra (AzureAD) Conditional Access questions or pain points? I'm working on a giant Conditional Access post for the #TrustedSec blog -- would welcome your inputs!
    #Microsoft #Entra #AzureAD #Azure #ConditionalAccess #conditionalaccesspolicies

  25. What are your biggest Entra (AzureAD) Conditional Access questions or pain points? I'm working on a giant Conditional Access post for the #TrustedSec blog -- would welcome your inputs!
    #Microsoft #Entra #AzureAD #Azure #ConditionalAccess #conditionalaccesspolicies

  26. Whatโ€™s you biggest #conditionalaccess configuration pet peeve?

    Mine is not having a policy to manage guest accounts - especially as the default in #ms365 is to allow guests to invite guests ๐Ÿคฏ

  27. Looking for this magic crowd knowledge! I seem to recall news somewhere (here, LinkedIn, newsletter, maybe?), that #EntraID would support #Passkeys during the MFA registration prompt when signing in. Like the experience to enroll your Authenticator app. Sadly, I can't rediscover this :sad_panda: Would anybody have an idea or pointer? Maybe @merill

    Any pointers, boosts, etc welcome! Thaks!

    Edit: OF COURSE one finds what one searchs less than an hour after asking other people. Well, thanks for reading anyways!
    mc.merill.net/message/MC718260

    (Caveat is, I'm not sure if this is really what I thought it meant originally).

    #Passkey #microsoft #ConditionalAccess

  28. Anybody having weird issues with Microsoft CAP policies? We have a CAP that is supposed to enforce MFA on the Admin Portals and for some reason today it it's hitting all Microsoft like Office 365. We just started getting bombarded with users not being able to log in because we enforce stricter MFA for Admins. #microsoft #azure #entraID #conditionalaccess #cap

  29. Authentication Strengths in Microsoft Entra ID allows you to granularly define authentication requirements for different situations.

    Before authentication strengths were available, authentication requirements were defined globally for the entire tenant, and then conditional access policies could just say that multi-factor authentication was required, for example. But it was not possible to define what type of multifactor authentication was required. So anything that was available globally could be used by all users in all situations.

    Which was not optimal. There are situations where a less secure authentication method like SMS or TOTP might be enough. But there are situations where we only want to use very secure authentication methods like FIDO2 when someone is logging into a global admin account for example.

    Such granularity was not possible before. If SMS authentication was enabled for a given tenant, even the global admin could use SMS for authentication.

    ๐Ÿ“บ ๐–๐š๐ญ๐œ๐ก ๐ญ๐ก๐ž ๐ซ๐ž๐œ๐จ๐ซ๐๐ข๐ง๐  ๐จ๐ง ๐ฆ๐ฒ ๐๐š๐ญ๐ซ๐ž๐จ๐ง patreon.com/posts/microsoft-en

    The recording is also available in Czech language on
    ๐…๐จ๐ซ๐ž๐ง๐๐จ๐ซ๐ฌ forendors.cz/p/646afdb06ee2fa1
    ๐‡๐ž๐ซ๐จ๐ก๐ž๐ซ๐จ
    herohero.co/cswrld/post/bcerox

    ๐Ÿ‘Share, like, comment!

    #entraid #authentication #authenticationstrengths #conditionalaccess #cybersecurity #recommendations #tips #videotutorial

  30. One of the most popular posts on my blog is an article about recommended conditional access policies in Microsoft Entra ID cswrld.com/2024/02/recommended

    In this article, I describe the most important conditional access policies that every organization should have implemented.

    I have received a lot of positive feedback on the article, for which I am very grateful! However, people also wrote that they would like more details about the configuration of each policy if possible, and that they would like more details about the configuration of other conditional access policies as well.

    So I made a very detailed video of over an hour, describing in detail a total of 28 conditional access policies that I recommend to consider deploying in all organizations, regardless of their size.

    Cloud identity security is absolutely critical, and unfortunately I regularly see security gaps in conditional access policies.

    ๐Ÿ“บWatch the recording on my Patreon patreon.com/posts/recommended-

    The recording is also available in Czech language on
    Forendors forendors.cz/p/d4210cfb79de8b0
    Herohero herohero.co/cswrld/post/bcerox

    ๐Ÿ‘Share, like, comment!

    #conditionalaccess #entraid #cybersecurity #recommendations #tips

  31. Microsoft Entra ID Token Protection is a security feature within Microsoft Entra's Conditional Access that aims to mitigate token theft by ensuring that a token can only be used from the device it was issued to. This is achieved through a process called token binding, which creates a cryptographically secure link between the token and the device.

    If a threat actor were to steal a token, without the corresponding client secret from the device, the token would be rendered useless.

    This protection is particularly important because token theft, while relatively rare, can lead to significant security breaches if the threat actor impersonates the victim until the token expires or is revoked.

    Do you want to learn more about token protection and how to enforce it in Microsoft Entra ID? Read my latest blog post! ๐Ÿ‘‡๐Ÿ‘‡

    cswrld.com/2024/04/microsoft-e

    #entraid #authentication #tokenprotection #tokentheft #conditionalaccess #cybersecurity #tips

  32. Microsoft Entra ID Token Protection is a security feature within Microsoft Entra's Conditional Access that aims to mitigate token theft by ensuring that a token can only be used from the device it was issued to. This is achieved through a process called token binding, which creates a cryptographically secure link between the token and the device.

    If a threat actor were to steal a token, without the corresponding client secret from the device, the token would be rendered useless.

    This protection is particularly important because token theft, while relatively rare, can lead to significant security breaches if the threat actor impersonates the victim until the token expires or is revoked.

    Do you want to learn more about token protection and how to enforce it in Microsoft Entra ID? Read my latest blog post! ๐Ÿ‘‡๐Ÿ‘‡

    cswrld.com/2024/04/microsoft-e

    #entraid #authentication #tokenprotection #tokentheft #conditionalaccess #cybersecurity #tips

  33. Microsoft Entra ID Token Protection is a security feature within Microsoft Entra's Conditional Access that aims to mitigate token theft by ensuring that a token can only be used from the device it was issued to. This is achieved through a process called token binding, which creates a cryptographically secure link between the token and the device.

    If a threat actor were to steal a token, without the corresponding client secret from the device, the token would be rendered useless.

    This protection is particularly important because token theft, while relatively rare, can lead to significant security breaches if the threat actor impersonates the victim until the token expires or is revoked.

    Do you want to learn more about token protection and how to enforce it in Microsoft Entra ID? Read my latest blog post! ๐Ÿ‘‡๐Ÿ‘‡

    cswrld.com/2024/04/microsoft-e

    #entraid #authentication #tokenprotection #tokentheft #conditionalaccess #cybersecurity #tips

  34. Microsoft Entra ID Token Protection is a security feature within Microsoft Entra's Conditional Access that aims to mitigate token theft by ensuring that a token can only be used from the device it was issued to. This is achieved through a process called token binding, which creates a cryptographically secure link between the token and the device.

    If a threat actor were to steal a token, without the corresponding client secret from the device, the token would be rendered useless.

    This protection is particularly important because token theft, while relatively rare, can lead to significant security breaches if the threat actor impersonates the victim until the token expires or is revoked.

    Do you want to learn more about token protection and how to enforce it in Microsoft Entra ID? Read my latest blog post! ๐Ÿ‘‡๐Ÿ‘‡

    cswrld.com/2024/04/microsoft-e

    #entraid #authentication #tokenprotection #tokentheft #conditionalaccess #cybersecurity #tips

  35. Microsoft Entra ID Token Protection is a security feature within Microsoft Entra's Conditional Access that aims to mitigate token theft by ensuring that a token can only be used from the device it was issued to. This is achieved through a process called token binding, which creates a cryptographically secure link between the token and the device.

    If a threat actor were to steal a token, without the corresponding client secret from the device, the token would be rendered useless.

    This protection is particularly important because token theft, while relatively rare, can lead to significant security breaches if the threat actor impersonates the victim until the token expires or is revoked.

    Do you want to learn more about token protection and how to enforce it in Microsoft Entra ID? Read my latest blog post! ๐Ÿ‘‡๐Ÿ‘‡

    cswrld.com/2024/04/microsoft-e

    #entraid #authentication #tokenprotection #tokentheft #conditionalaccess #cybersecurity #tips

  36. Microsoft has rolled out so-called Microsoft-managed conditional access policies in November 2023. The policies will be automatically enabled very soon. Do you know what is the impact of the policies on your tenant?

    These managed policies are intended to cover the most important identity security scenarios within Microsoft Entra ID. But obviously can negatively impact existing users and administrators if the company if not ready for the rollout.

    Check my today's blog post to see the impact of the policies. ๐Ÿ‘‡๐Ÿ‘‡

    cswrld.com/2024/04/microsoft-m

    #conditionalaccess #entraid #microsoft #identitysecurity #tips

  37. Authentication Strengths in Microsoft Entra ID allows you to granularly define authentication requirements for different situations.

    It is possible to define different groups of authentication methods and then associate them with conditional access policies.

    Do you want to know more about authentication strengths in Microsoft Entra ID, how to use it and what are the recommended authentication methods to allow? Read my article bellow ๐Ÿ‘‡๐Ÿ‘‡

    cswrld.com/2024/03/microsoft-e

    #entraid #conditionalaccess #policies #mfa #authenticationstrength

  38. Evaluation of Conditional Access Policies in Microsoft Entra ID is relatively simple and straightforward. But what many administrators don't realize are the background dependencies between different services, called service dependencies.

    Do you know the difference between early-bound and late-bound dependencies? Read the details on my blog ๐Ÿ‘‡๐Ÿ‘‡
    cswrld.com/2024/02/service-dep

    #entraid #conditionalaccess #authentication #dependencies

  39. I'd like to point out this really interesting article on the topic: ๐“๐จ๐ค๐ž๐ง ๐“๐ก๐ž๐Ÿ๐ญ ๐“๐š๐ฅ๐ค.

    Key points and topics covered:

    - Primary Refresh Tokens (PRT) on all operating system platforms have been hardened against theft from day one. The level of protection depends on operated system capabilities, with Windows offering the strongest protection.

    - First line of defense against token theft is protecting your devices by deploying endpoint protections, device management, MFA (and moving towards phishing-resistant credentials), and antimalware

    You can reduce token theft by carefully orchestrating Entra ID security products:

    โ–ถAddressing token theft of sign-in session artifacts: Conditional Access: Token protection policy offers cryptographic protection against replay of stolen tokens.

    โ–ถAddressing token theft of app session artifacts: block usage of stolen access tokens and workload cookies outside of your corporate network by using Conditional Access.

    โ–ถDetecting token theft: enable risk detections with Microsoft Entra ID Protection to elevate user risk when token theft is suspected.

    techcommunity.microsoft.com/t5

    #microsoft #microsoftsecurity #entraid #azuread #azure #idp #token #tokentheft #cloudsecurity #identity #prt #cookies #identityprotection #mfa #cae #conditionalaccess #refreshtoken #token

  40. I'd like to point out this really interesting article on the topic: ๐“๐จ๐ค๐ž๐ง ๐“๐ก๐ž๐Ÿ๐ญ ๐“๐š๐ฅ๐ค.

    Key points and topics covered:

    - Primary Refresh Tokens (PRT) on all operating system platforms have been hardened against theft from day one. The level of protection depends on operated system capabilities, with Windows offering the strongest protection.

    - First line of defense against token theft is protecting your devices by deploying endpoint protections, device management, MFA (and moving towards phishing-resistant credentials), and antimalware

    You can reduce token theft by carefully orchestrating Entra ID security products:

    โ–ถAddressing token theft of sign-in session artifacts: Conditional Access: Token protection policy offers cryptographic protection against replay of stolen tokens.

    โ–ถAddressing token theft of app session artifacts: block usage of stolen access tokens and workload cookies outside of your corporate network by using Conditional Access.

    โ–ถDetecting token theft: enable risk detections with Microsoft Entra ID Protection to elevate user risk when token theft is suspected.

    techcommunity.microsoft.com/t5

    #microsoft #microsoftsecurity #entraid #azuread #azure #idp #token #tokentheft #cloudsecurity #identity #prt #cookies #identityprotection #mfa #cae #conditionalaccess #refreshtoken #token

  41. I'd like to point out this really interesting article on the topic: ๐“๐จ๐ค๐ž๐ง ๐“๐ก๐ž๐Ÿ๐ญ ๐“๐š๐ฅ๐ค.

    Key points and topics covered:

    - Primary Refresh Tokens (PRT) on all operating system platforms have been hardened against theft from day one. The level of protection depends on operated system capabilities, with Windows offering the strongest protection.

    - First line of defense against token theft is protecting your devices by deploying endpoint protections, device management, MFA (and moving towards phishing-resistant credentials), and antimalware

    You can reduce token theft by carefully orchestrating Entra ID security products:

    โ–ถAddressing token theft of sign-in session artifacts: Conditional Access: Token protection policy offers cryptographic protection against replay of stolen tokens.

    โ–ถAddressing token theft of app session artifacts: block usage of stolen access tokens and workload cookies outside of your corporate network by using Conditional Access.

    โ–ถDetecting token theft: enable risk detections with Microsoft Entra ID Protection to elevate user risk when token theft is suspected.

    techcommunity.microsoft.com/t5

    #microsoft #microsoftsecurity #entraid #azuread #azure #idp #token #tokentheft #cloudsecurity #identity #prt #cookies #identityprotection #mfa #cae #conditionalaccess #refreshtoken #token

  42. I'd like to point out this really interesting article on the topic: ๐“๐จ๐ค๐ž๐ง ๐“๐ก๐ž๐Ÿ๐ญ ๐“๐š๐ฅ๐ค.

    Key points and topics covered:

    - Primary Refresh Tokens (PRT) on all operating system platforms have been hardened against theft from day one. The level of protection depends on operated system capabilities, with Windows offering the strongest protection.

    - First line of defense against token theft is protecting your devices by deploying endpoint protections, device management, MFA (and moving towards phishing-resistant credentials), and antimalware

    You can reduce token theft by carefully orchestrating Entra ID security products:

    โ–ถAddressing token theft of sign-in session artifacts: Conditional Access: Token protection policy offers cryptographic protection against replay of stolen tokens.

    โ–ถAddressing token theft of app session artifacts: block usage of stolen access tokens and workload cookies outside of your corporate network by using Conditional Access.

    โ–ถDetecting token theft: enable risk detections with Microsoft Entra ID Protection to elevate user risk when token theft is suspected.

    techcommunity.microsoft.com/t5

    #microsoft #microsoftsecurity #entraid #azuread #azure #idp #token #tokentheft #cloudsecurity #identity #prt #cookies #identityprotection #mfa #cae #conditionalaccess #refreshtoken #token

  43. ๐— ๐—ถ๐—ฐ๐—ฟ๐—ผ๐˜€๐—ผ๐—ณ๐˜ ๐—˜๐—ป๐˜๐—ฟ๐—ฎ ๐—ฃ๐—ฟ๐—ถ๐˜ƒ๐—ฎ๐˜๐—ฒ ๐—”๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€: ๐—”๐—ป ๐—œ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐˜๐˜†-๐—–๐—ฒ๐—ป๐˜๐—ฟ๐—ถ๐—ฐ ๐—ญ๐—ฒ๐—ฟ๐—ผ ๐—ง๐—ฟ๐˜‚๐˜€๐˜ ๐—ก๐—ฒ๐˜๐˜„๐—ผ๐—ฟ๐—ธ ๐—”๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€ ๐—ฆ๐—ผ๐—น๐˜‚๐˜๐—ถ๐—ผ๐—ป

    Private Access in Microsoft's SSE solution offers secure, controlled access to private resources using Zero Trust principles, expanded from the existing Entra ID Application Proxy. It supports a range of protocols, authentication methods, and anomaly detection, all benefiting from Microsoft's extensive global network.

    Find out more info:

    techcommunity.microsoft.com/t5

    Here's a summarized breakdown of the provided information:

    1๏ธโƒฃPrivate Access in Microsoft's SSE Solution:

    โœ”๏ธBuilt on Zero Trust principles.

    โœ”๏ธVerifies every user and enforces least privilege.

    โœ”๏ธGrants access only to needed private applications and resources.

    2๏ธโƒฃExpansion of Entra ID Application Proxy:

    โœ”๏ธPrivate Access extends capabilities of Entra ID Application Proxy in Microsoft Entra.

    โœ”๏ธEvolves into a comprehensive Zero Trust Network Access (ZTNA) solution.

    โœ”๏ธShares connectors but offers expanded functionalities.

    3๏ธโƒฃAccess to Any Private Resource:

    โœ”๏ธSimplifies and secures access to private resources on any port and protocol.

    โœ”๏ธPolicies enable secure, segmented, and granular access to corporate network apps.

    โœ”๏ธCovers on-premises, cloud-based applications, and more.

    4๏ธโƒฃGranular Access Controls and Anomaly Detection:

    โœ”๏ธConditional Access policies offer per-app, least privilege controls.

    โœ”๏ธContextual information about users, devices, and locations enhances policies.

    โœ”๏ธAnomalies or changes trigger session termination or stronger authentication.

    5๏ธโƒฃSecure Access Across Ports and Protocols:

    โœ”๏ธPrivate Access enables secure entry to applications, regardless of location.

    โœ”๏ธWorks with various protocols, including RDP, SSH, SMB, FTP, TCP, and UDP.

    6๏ธโƒฃDiverse Authentication Methods:

    โœ”๏ธSupports single sign-on (SSO) via SAML, http headers, or legacy Kerberos.

    โœ”๏ธNo need for application modifications.

    7๏ธโƒฃMicrosoft's Global Network Advantage:

    โœ”๏ธPrivate Access utilizes Microsoft's vast global network for delivery.

    โœ”๏ธEnhanced security and faster access compared to traditional VPNs.

    โœ”๏ธOptimized connection for hybrid and remote work scenarios.

    #microsoft #entra #sse #ZTNA #ZeroTrustNetworkAccess #ZeroTrust #sso #saml #mfa #conditionalaccess #azuread #securityserviceedge #vpn #azure #cloud #cloudsecurity

  44. #ConditionalAccess in #EntraID should be a score skill if you are involved in securing MS cloud environments. More and more of their technologies are using it, and it provides such an extensive set of controls.