Jump to content

Recommended Posts

Posted (edited)

Hi all I have received this email twice so far today...

 

[TABLE=width: 100%, align: center]

[TR]

[TD][TABLE=width: 100%]

[TR]

[TD]Protect your organisation, with Azure AD security defaults

 

There are over 300 million fraudulent attempts to sign in to our cloud services every day. All it takes is one compromised credential or one legacy application to cause a data breach. One of the best things you can do to prevent these attacks is to turn on multifactor authentication, which can block over 99.9 percent of account compromise attacks.

Enable security defaults to adopt security best practices, such as requiring multifactor authentication and disabling insecure protocols. Security defaults will ensure that your security settings stay up-to-date until you decide to manage them yourself. There is no additional cost.

Starting the week of March 22, 2023, we’ll make it easier for you to enable security defaults by presenting you with a message when you sign in to your Azure Active Directory (Azure AD) account through your web browser.If you don’t take action per the message, security defaults will be enabled after 14 days. If you’d like to get started, you can enable security defaults today.[/TD]

[TD][/TD]

[/TR]

[/TABLE]

[/TD]

[/TR]

[/TABLE]

 

 

[TABLE=width: 100%, align: center]

[TR]

[TD][TABLE=width: 100%]

[TR]

[TD]When you enable security defaults:

· You as a Global Administrator will be asked to register for multifactor authentication using the Microsoft Authenticator app and your phone number.

· Everyone else in your organisation will be asked to register with the Microsoft Authenticator app for multifactor authentication.

If you have other questions, read our documentation. If you need more support, create a support request in the Azure portal.

 

 

Anyone else getting it? Not a chance I want MFA turned on as the kids aren't allowed phones and it states they will force the policy in 14days.[/TD]

[TD][/TD]

[/TR]

[/TABLE]

[/TD]

[/TR]

[/TABLE]

Edited by cheekycharly
Posted (edited)

Anyone else getting it? Not a chance I want MFA turned on as the kids aren't allowed phones and it states they will force the policy in 14days

 

This is where you use Conditional Access to ensure that they don't need to multi-factor while on-site. Schools are increasingly becoming targets and groups are being successful in getting in, due to schools typically having legacy products, lack of knowledge of remote access, or just slack security. You are potentially setting yourself up for a big problem down the road if you maintain this stance.

 

I live in a rural area where some people still have dial-up or a limited connection, or no mobile phone at all. The security implications for not having MFA in 2023 are huge, and the value of having it outweighs the minority who may be unable to access externally, and even then we can do a case-by-case basis such as physical tokens. Students are not allowed mobile phones on-site, but they don't need them as long as they're either using a school computer or our school WiFi.

Edited by Mako
Posted
REK20 thanks for a great first post. I have followed the link and checked it is saying disabled. I have no way of knowing if they are going to try auto-enabling it like they say they will. Once we are using our tenant a little more later this year I plan on turning on conditional access so it can only be accessed behind the school IP's.
Posted
This is where you use Conditional Access to ensure that they don't need to multi-factor while on-site. Schools are increasingly becoming targets and groups are being successful in getting in, due to schools typically having legacy products, lack of knowledge of remote access, or just slack security. You are potentially setting yourself up for a big problem down the road if you maintain this stance.

 

I live in a rural area where some people still have dial-up or a limited connection, or no mobile phone at all. The security implications for not having MFA in 2023 are huge, and the value of having it outweighs the minority who may be unable to access externally, and even then we can do a case-by-case basis such as physical tokens. Students are not allowed mobile phones on-site, but they don't need them as long as they're either using a school computer or our school WiFi.

 

Hey Mako so what I wrote above is the correct way of doing it at a school then is it? Only allowing the IP of the school to get access to the tenant.

Posted

You could try creating a conditional access policy now, even if you only scope it to include one dummy user.

 

Conditional access should trump Security Defaults in precedence, so might stop them being enforced on you. The fact that it's trying to enforce those, though, says maybe some part of Microsoft isn't happy with your current security settings.

Posted
Hey Mako so what I wrote above is the correct way of doing it at a school then is it? Only allowing the IP of the school to get access to the tenant.

 

What you're describing is to completely eliminate access off-site, which is one way of doing it and could be perfect for your requirements. It's not for me to say whether that is right or wrong as that's up to your environment.

 

What we generally do is employ MFA, implement conditional access so that it's not required on-site, and then allow people to access from home, providing they follow MFA. This allows staff and students to work at home while maintaining security and preventing unauthorised access.

Posted

Mako sounds a great way of doing it to be fair. I didnt know you could have the best of both worlds/

 

I will look into how I implement both of those ways in our portal. I guess when students and staff use the system under the school IP address they don't get bugged by any 2FA messages?

  • 2 weeks later...
Posted
Don't you need either P1 or A3 licenses to do conditional access?

 

I seriously hope not as I'm looking at Enterprise Mobility + Security E3 and not 365 A3 licensing.

 

It's the difference of about £1.59 to £5.30

Guest Guest
Posted
I seriously hope not as I'm looking at Enterprise Mobility + Security E3 and not 365 A3 licensing.

 

It's the difference of about £1.59 to £5.30

 

According to https://m365maps.com/files/EMS-E3.htm EMS E3 includes all functionality of Azure AD P1 and so you should be ok

  • 8 months later...
Posted
After doubting myself this afternoon Enterprise Mobility + Security A3 does include Azure AD Premium P1

 

Hi,

 

I hope you don't mind me starting this thread again.

We have asked staff to register MFA using Ms Authenticator app, but a lot of staff still haven't done that and a few can't be bothered and not even try.

My question how do ensure that everyone registers with MFA for O365 and remote desktop?

 

Thanks in advance.

Posted
My question how do ensure that everyone registers with MFA for O365 and remote desktop?

Thanks in advance.

 

Depends how it's set up. If you're using conditional access with known location exceptions, then I'm pretty sure you can set it that they can't login externally without completing MFA setup.

And if they don't want to use those services from outside the school network then it's no biggie. Give maybe a week or so's grace and then block MFA setup from outside the school network and leave them to it. If they change their minds they can sign up, if not their accounts can't login from outside the school's network so they're not a massive security weakness (as long as you've got it set so MFA can only be set up from your school network).

 

Aside from that, it's about getting SLT on side so they can mandate it.

  • Thanks 1
Posted
We have conditional access already set up, it should only ask to use MFA externally, but it asks me to authenticate with MFA when I try to log in to O365 via browser at school. I don't get asked when using Outlook client at school
Posted
Sounds like you need to tweak your "known locations". Maybe you've missed an external IP address, or you've not got them set on the right policy or something.
Posted
Sounds like you need to tweak your "known locations". Maybe you've missed an external IP address, or you've not got them set on the right policy or something.

 

I've checked but I couldn't spot anything, but I will check again as it sounds like it could be that

Thanks

Posted

FWIW, if you've got MFA set, there are some occasions where, even with the conditional access, that you'll get an MFA prompt whether in or out of school.

 

Usually only stuff like changing your account details etc. So MFA, is protecting MFA settings, if you like.

 

You shouldn't be prompted for day-to-day usage though.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...