Jump to content

Recommended Posts

Posted

Hi all,

 

Had an email from Microsoft this morning to migrate our MFA methods from legacy to the Authentication Methods in AAD.

 

Have successfully done this, but it now appears that MFA is enabled for all accounts. We have some accounts that we don't wish to enable this for but I'm struggling to see where I can exclude these. Does anyone have any ideas? I've looked in AAD > Properties > Manage Security Defaults and this is off...

 

Also, in the legacy MFA section we have some trusted IP's set up (I know this is debatable issue), and just wondering if these also need to be migrated elsewhere? Everything is currently working as expected but just don't want a sudden influx of users being asked for authentication on those IP ranges.

 

Thanks in advance for your help!

Posted
AAD >> Users >> Per user MFA

 

Thanks for that. Clicking per user MFA in there just takes me back to the legacy page. The accounts in here are still listed as disabled but are being prompted to set up when logging in...

Posted
We set MFA for our staff users using a conditional access policy. This allows us to assign the policy using groups and exclude accounts that we do not want to have MFA enabled for.

 

That’s the way I have done ours.

 

Created group called MFA_Users, put users in that group who needed to have MfA and then set conditional access so anyone one in that group has to use MfA

Posted (edited)
That’s the way I have done ours.

 

Created group called MFA_Users, put users in that group who needed to have MfA and then set conditional access so anyone one in that group has to use MfA

 

Have you considered doing this the other way around - MFA enabled for all users with an exception group for accounts you wish to exclude? This is "fail safe" - it doesn't rely on someone remembering to add an account to a group when creating the account, so is imo safer. This is good practice as you can't always control when and how accounts are created.

 

Additionally this gives you a very easy method to audit which accounts are not protected by conditional access/MFA and see if any unexpected accounts are not being protected, or even get an alert when this group is modified - https://janbakker.tech/act-on-group-membership-changes-in-azure-active-directory/

Edited by Roberto

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...