Jump to content

Recommended Posts

Posted

Hi,

 

I work for a medium size MAT, I've just completed a migration of all of our schools individual O365 tenants to a single MAT tenant. This has made management much easier for me working at the centre however it has highlighted some bad practice around password security for a small number of staff. Currently I only have the default MFA enforced for administrators policy enabled, but i'm now looking to possibly roll this out to all users. I'm leaning more towards azure conditional access rather than just the default MFA enabled/disabled in O365, however there's an additional licencing cost to consider with this option.

 

Has anyone gone through this process before? How did it go for you and what policy did you implement on MFA?

 

For those who have enabled MFA by default for all users, were there any unexpected issues you've had to overcome?

Posted

I've done a lot of work with CA and MFA. Enforcing MFA via CA Policy and not just enabling users for it is a recommended option. That said, if you are focussed on your 'secure score' it marks you down for doing this, will be updated soon. Also note if you are using old versions of outlook they will not work if MFA is enabled on the account.

 

Where I've done it we focussed on concept of trust and needing something other than password. So, if you're coming from a trusted IP thats considered a second factor, as is a machine that's not azure Ad hybrid domain joined, otherwise you need MFA. Depending on license you can also escalate authentication requirements if something looks dodgy.

 

Also be aware of using activesync via MDM which will still want to use legacy auth (= doesnt work with MFA)

 

The audit log and CA actions is now very useful - I'd get familiar with it before any changes.

 

 

Also you mentioned dodgy passwords, be sure to be using password hash sync as MS will flag compromised passwords even without extra licenses.

  • Thanks 1
Posted

Thanks for the reply, i like the trust concept. Using other factors to show a secure login would definitely cut down on the amount of user support required from putting MFA in-place.

 

Can i ask, for your users what was the uptake on the authenticator APP compared to other authentication methods like mobile number & secondary email?

Posted

People 'get' the text-message-to-the-phone approach as it's increasingly used elsewhere but there's no doubt the app is better... for me, it's the main reason I got an apple watch. I don't think it's possible to get stats out of AzureAD as to what strong methods are in use but gut feels is that adoption of app is low.

 

There was a definite resistance to secondary email address from some people who though the company was insisting on provision of a personal email address.

 

I am also aware that the MFA signup process isn't the slickest and MS are just about to roll out a better process, combined with password reset (SSPR). However, I have heard this message for some time now and not seen anything public.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...