ITGuyNW Posted March 2, 2024 Posted March 2, 2024 (edited) Hi all I am wanting to roll out MFA in stages to staff and completely exclude pupils (at this point at least). I've been enabling staff on a per user basis however It's migrating over to the one catch all policy. Has anyone got security defaults enabled in their domain and been able to exclude accounts from having MFA enabled? If I can run a targeted campaign instead of going per user, that would save a lot of time. I assume it won't be this easy though. We're currently A1, with a view of moving to A3 in September... Thanks Edited March 2, 2024 by ITGuyNW
CrootUK Posted March 2, 2024 Posted March 2, 2024 (edited) If your on about this https://learn.microsoft.com/en-us/entra/fundamentals/security-defaults to my knowledge there is no “excluding” this is where conditional access is used as you can apply the same policies in “Security Defaults” but more granularly eg to different groups, some such as block legacy auth can also be applied to students for example.. Just make sure you have and exclude a break glass account from some of these policies. you’ll need atleast one A3 or Entra ID P1 licence to get started. Edited March 2, 2024 by CrootUK
ITGuyNW Posted March 4, 2024 Author Posted March 4, 2024 Yeah I feared that trying to do a "catch all" type approach instead of per-user may not be possible on A1. I might have to do it manually for now (which really pains me) and then when we get A3, re-evaluate.
TheRobins Posted March 4, 2024 Posted March 4, 2024 I do it by giving all staff P1 licences, works very well by using an Office365 group and policy with the required details.
ITGuyNW Posted March 19, 2024 Author Posted March 19, 2024 How much are you paying for P1 licences for all staff? We're hoping to go A3 in September
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now