Jump to content

Recommended Posts

Posted

Morning all,

 

Received several Azure Authentication emails this morning (thanks Microsoft). As per usual, unnecessarily complicated -

 

Azure Auth.png

 

Which then sends you here yet my settings already appear as per the MFA screenshot, so do I need to do anything?

 

SSRP - Self Service Password Reset - don't use.

 

Authentication Methods Policy - don't use, as far as I can tell.

 

Coupled with the new Teams 2, which is absolute garbage. I've had several users now who can't use it or experiencing issues with it.

Posted

The legacy MFA settings (https://account.activedirectory.windowsazure.com/UserManagement/MfaSettings.aspx) are going away, replaced by Authentication policies (https://entra.microsoft.com/#view/Microsoft_AAD_IAM/AuthenticationMethodsMenuBlade/~/AdminAuthMethods/fromNav/Identity)

 

Authentication Methods Policy - don't use, as far as I can tell.

You need to - use the table on the page you linked to setup auth policies that match your legacy MFA policies.

 

We don't use SSRP so i've not looked at that yet, but I suspect the same applies - you need to make sure the new policies match your old settings.

Posted

They're moving away from the old separate places (where to be frank the UI is Win 95'ish, and you have buttons and tabs on the top menu bar that nobody can ever find) to the centralised modern workflow where everything is on the left hand menu.

 

The bottom of the page that's linked shows you how to set your migration progress, ie "only use old", "use both whilst I migrate" or "I'm done, use the new settings".

Posted
Why do I get the feeling that when the legacy settings are shuttered, I'll lose the ability to enforce MFA for certain users only (i.e. staff) without needing a premium license?
Posted
Why do I get the feeling that when the legacy settings are shuttered, I'll lose the ability to enforce MFA for certain users only (i.e. staff) without needing a premium license?

 

Also interested in this, as we only use A1 licencing

Posted
They're moving away from the old separate places (where to be frank the UI is Win 95'ish, and you have buttons and tabs on the top menu bar that nobody can ever find) to the centralised modern workflow where everything is on the left hand menu.

 

The bottom of the page that's linked shows you how to set your migration progress, ie "only use old", "use both whilst I migrate" or "I'm done, use the new settings".

 

That's fine, but why does the new page change a whole new set of the same options? You can have a new view on the same data

Posted
That's fine, but why does the new page change a whole new set of the same options? You can have a new view on the same data

 

Oh, oh, I know! Because the codebase is garbage and written by a different team in a different language?

Posted (edited)

Does anyone know whether the new settings will allow me to dictate whether certain users/groups can be allowed to not have MFA, and also whether MFA can be enforced for certain other users/groups? I want to ensure that our staff users have MFA in place, whilst also allowing students to merrily get by without it for now.

 

It really isn't clear (typical for MS IMHO). I get the feeling that there are policies elsewhere in the M365 shanty town of admin centers that determine such things.

 

EDIT:

It's looking like everything ultimately runs back to Conditional Access policies? If so, no dice for non-premium tenancies.

Edited by jthompson

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...