kevin_lane Posted September 20, 2022 Posted September 20, 2022 I don't know if this just affects us or not but when new users are created I want the MFA status to be enforced automatically upon account creation for new members of staff, as at the moment I have to enforce it through office 365 is there a better way of managing this? we use salamander to create the accounts which do get placed into an MFA group as part of the conditional access but just wondering if there was another way.
FN-GM Posted September 20, 2022 Posted September 20, 2022 Maybe enforce it for all users and have exclusions on those that need it?
kevin_lane Posted September 20, 2022 Author Posted September 20, 2022 is that something you have tested ?
FN-GM Posted September 20, 2022 Posted September 20, 2022 Yes. We had this in my previous employer and my current. Both on the test and production networks.
kevin_lane Posted September 20, 2022 Author Posted September 20, 2022 I presume you just created a group and stick the accounts in there. I think I’m just worried about getting locked out lol we have another account that in the event of being locked out we can get back in - this was based on Microsoft security recommendations Thanks
FN-GM Posted September 20, 2022 Posted September 20, 2022 we have another account that in the event of being locked out we can get back in - this was based on Microsoft security recommendations Thanks We also have a break glass account. A randomly generated password. Sealed in an envelope that is signed by IT staff. Then it’s laminated so it’s sealed around each side to make it tamper proof. Then it’s placed in the safe. We also have notifications if that account is used.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now