Jump to content

Recommended Posts

Posted

One to keep an eye out for:

 

We'll create a new Conditional Access policy in your tenant on or after 09 November 2023

 

You’re receiving this email because you’re a global administrator for XXX.

 

In 2020, we introduced security defaults in Microsoft Entra ID, which significantly raised baseline security for organisations. Now, to build on those improvements, we’re introducing Microsoft-managed Conditional Access policies. Between 09 November 2023, and December 31, 2023, we’ll create a new Conditional Access policy in your XXX tenant.

 

This policy, Multifactor authentication for per-user multifactor authentication users, will be created in report-only mode. This means that it won’t block any access, but it will generate reports on how it will affect users when it’s switched to the On state.

 

After the policy has been created in your tenant, you’ll have 90 days to evaluate and configure it. Then, if you haven’t already moved it to the On or Off state, it’ll be automatically moved to On. Once the policy is enabled, users covered by it will need to have multifactor authentication.

Recommended action

 

To avoid any potential disruption to users’ access and to ensure this policy meets your organisation’s needs, take the following actions within 90 days of its creation, before it’s moved to the On state:

 

Review the effects and benefits of the new policy. If you don’t want us to enable it automatically, set it to Off. Or, you may set it to On at any time.

Customise this policy according to your specific needs, such as excluding emergency access accounts.

Verify that all users covered by this policy have enabled and registered at least one multifactor authentication method. If necessary, run a registration campaign to set up the Authenticator app.

  • Thanks 1
Posted
It would be nice if the location-based conditional access was available without having to pay for it. Then they'd have a significantly higher uptake of 2FA, since that's the only reason I haven't got it turned on for student accounts yet.
  • Thanks 2
Posted
It would be nice if the location-based conditional access was available without having to pay for it. Then they'd have a significantly higher uptake of 2FA, since that's the only reason I haven't got it turned on for student accounts yet.

 

This all over, In the same boat.

Posted
I'm at the starting block for launching full blown 2FA then Microsoft do something like this and I have to read into if what I'm doing is still the right thing!!
  • Thanks 1
Posted

Yes it's confusing to an old man like me.

 

We already have CA set up for staff (need an app) and no foreign logins for students. Can't see anything else on the page where they're set yet?

Posted
The extra MS rule isn't listed for us, but then we haven't received that email, either. Hopefully it's still going to be configurable to 'OFF' even with our licensing.
  • 3 weeks later...
Posted

testing MFA/authenticator using conditional access.

 

If it's set to apply to everything new outlook kicks out me when I try to write a new email.

 

If it's set to strength authentication it refuses to accept that my account is already linked to Microsoft authenticator (MA is enabled for all users in authentication methods)

 

Seems ok if I set it to cover admin access with multifactor authentication - not reliable for anyone else

  • 3 weeks later...
Posted
Now, to build on those improvements, we’re introducing Microsoft-managed Conditional Access policies. Between 09 November 2023, and December 31, 2023, we’ll create a new Conditional Access policy in your XXX tenant.

 

My Policy arrived 05/12.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...