Jump to content

Recommended Posts

Posted (edited)

Hi all

 

I am wanting to roll out MFA in stages to staff and completely exclude pupils (at this point at least). I've been enabling staff on a per user basis however It's migrating over to the one catch all policy.

 

Has anyone got security defaults enabled in their domain and been able to exclude accounts from having MFA enabled? If I can run a targeted campaign instead of going per user, that would save a lot of time. I assume it won't be this easy though.

 

We're currently A1, with a view of moving to A3 in September...

 

Thanks

Edited by ITGuyNW
Posted (edited)

If your on about this https://learn.microsoft.com/en-us/entra/fundamentals/security-defaults

 

to my knowledge there is no “excluding” this is where conditional access is used as you can apply the same policies in “Security Defaults” but more granularly eg to different groups, some such as block legacy auth can also be applied to students for example..

 

Just make sure you have and exclude a break glass account from some of these policies.

 

you’ll need atleast one A3 or Entra ID P1 licence to get started.

Edited by CrootUK
Posted

Yeah I feared that trying to do a "catch all" type approach instead of per-user may not be possible on A1.

 

I might have to do it manually for now (which really pains me) and then when we get A3, re-evaluate.

  • 3 weeks later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...