<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Authentication on JanBakker.tech</title><link>https://janbakker.tech/tags/authentication/</link><description>Recent content in Authentication on JanBakker.tech</description><generator>Hugo</generator><language>en-US</language><copyright>Jan Bakker</copyright><lastBuildDate>Sun, 14 Apr 2024 09:47:00 +0000</lastBuildDate><atom:link href="https://janbakker.tech/tags/authentication/index.xml" rel="self" type="application/rss+xml"/><item><title>Prepare for passkeys in Entra ID!</title><link>https://janbakker.tech/prepare-for-passkeys-in-entra-id/</link><pubDate>Sun, 22 Oct 2023 13:27:28 +0000</pubDate><guid>https://janbakker.tech/prepare-for-passkeys-in-entra-id/</guid><description>&lt;p&gt;&#10;&lt;a href="https://learn.microsoft.com/en-us/azure/active-directory/fundamentals/whats-new#public-preview---device-bound-passkeys-as-an-authentication-method" rel="noopener"&gt;Only a few months&lt;/a&gt; until Microsoft Entra ID will support device-bound passkeys stored on computers and mobile devices as an authentication method in preview, in addition to the existing support for FIDO2 security keys. This enables your users to perform phishing-resistant authentication using the devices that they already have.&lt;/p&gt;</description></item><item><title>Manage user-preferred multi-factor authentication method in Microsoft Entra ID</title><link>https://janbakker.tech/manage-user-preferred-multi-factor-authentication-method-in-microsoft-entra-id/</link><pubDate>Tue, 11 Jul 2023 18:58:26 +0000</pubDate><guid>https://janbakker.tech/manage-user-preferred-multi-factor-authentication-method-in-microsoft-entra-id/</guid><description>&lt;p&gt;This post is all about setting the preferred multi-factor authentication method using Graph API. We already know the &#10;&lt;a href="https://janbakker.tech/system-preferred-multifactor-authentication-in-azure-ad-dont-settle-for-less/"&gt;system-preferred multi-factor authentication method&lt;/a&gt;, where Microsoft Entra ID will use the strongest method of all the registered methods, but this time we take a look a the default method set by the user.&lt;/p&gt;</description></item><item><title>Authenticator Lite - Approve Azure MFA prompts with the Outlook app</title><link>https://janbakker.tech/authenticator-lite-approve-azure-mfa-prompts-with-the-outlook-app/</link><pubDate>Tue, 14 Mar 2023 12:28:09 +0000</pubDate><guid>https://janbakker.tech/authenticator-lite-approve-azure-mfa-prompts-with-the-outlook-app/</guid><description>&lt;p&gt;Microsoft &#10;&lt;a href="https://www.microsoft.com/en-us/microsoft-365/roadmap?filters=&amp;amp;searchterms=122289" rel="noopener"&gt;released&lt;/a&gt; a new feature where the Outlook mobile app now has some of the Microsoft Authenticator App features onboard. Users can now enroll for Azure MFA using just their Outlook mobile app. No additional installation of the Microsoft Authenticator app is needed. This preview brings both push notifications and TOTP to the Outlook mobile app. Users are prompted for enrollment or can manually register their app to work with a Microsoft 365 account once this feature is enabled.&lt;/p&gt;</description></item><item><title>System-preferred multifactor authentication in Azure AD. Don't settle for less.</title><link>https://janbakker.tech/system-preferred-multifactor-authentication-in-azure-ad-dont-settle-for-less/</link><pubDate>Fri, 03 Mar 2023 14:39:38 +0000</pubDate><guid>https://janbakker.tech/system-preferred-multifactor-authentication-in-azure-ad-dont-settle-for-less/</guid><description>&lt;p&gt;A new feature has popped up in Azure AD: &lt;strong&gt;System-preferred multifactor authentication (MFA)&lt;/strong&gt;. This will allow administrators to enforce the most secure method for Azure MFA. For example, if a user has multiple methods registered, the most secure method will be prompted first. How do I know what method is the strongest, you may ask? Here is the current order from most to least secure methods, currently supported in Azure Active Directory:&lt;/p&gt;</description></item><item><title>What admins should know about the combined registration portal for Azure MFA and Self Service Password Reset</title><link>https://janbakker.tech/what-admins-should-know-about-the-combined-registration-portal-for-azure-mfa-and-self-service-password-reset/</link><pubDate>Sat, 02 May 2020 12:06:20 +0000</pubDate><guid>https://janbakker.tech/what-admins-should-know-about-the-combined-registration-portal-for-azure-mfa-and-self-service-password-reset/</guid><description>&lt;h4 id="this-post-is-outdated-there-is-a-new-way-to-manage-authentication-methods"&gt;&lt;strong&gt;This post is outdated.&lt;/strong&gt; There is a &#10;&lt;a href="https://janbakker.tech/goodbye-legacy-sspr-and-mfa-settings-hello-authentication-methods-policies/"&gt;new way&lt;/a&gt; to manage authentication methods&lt;a class="anchor" href="#this-post-is-outdated-there-is-a-new-way-to-manage-authentication-methods" aria-label="Link to this section"&gt;#&lt;/a&gt;&lt;/h4&gt;&#10;&lt;p&gt;&#10;&lt;a href="https://janbakker.tech/goodbye-legacy-sspr-and-mfa-settings-hello-authentication-methods-policies/"&gt;Learn more&lt;/a&gt;&lt;/p&gt;&#10;&lt;p&gt;The (long) title pretty much reveals the purpose of this blog post. This one was on my to-do list for a while now, and now the &#10;&lt;a href="https://techcommunity.microsoft.com/t5/azure-active-directory-identity/combined-mfa-and-password-reset-registration-is-now-generally/ba-p/1257355" rel="noopener"&gt;combined registration portal is General Available&lt;/a&gt;, the time was there. In my previous MFA-related blogs, I always encouraged my readers to turn on the combined registration portal, even when it was in public preview. But if you start using this portal, there are quite some settings that can change the user experience of the registration. And that&amp;rsquo;s mainly what this blog post is about. Let&amp;rsquo;s see how each setting reflects to the end user.&lt;/p&gt;</description></item><item><title>Microsoft Secure Score Series – 06 – Enable policy to block legacy authentication</title><link>https://janbakker.tech/microsoft-secure-score-series-06-enable-policy-to-block-legacy-authentication/</link><pubDate>Wed, 08 Apr 2020 19:15:37 +0000</pubDate><guid>https://janbakker.tech/microsoft-secure-score-series-06-enable-policy-to-block-legacy-authentication/</guid><description>&lt;p&gt;In this series, I&amp;rsquo;ll be covering the Microsoft Secure Score improvement actions. Although Microsoft does a great job on telling you what to do, some actions have a much bigger impact and need to be balanced against business needs. Some actions might not even have value for your organization. In the end, Microsoft Secure Score is meant to strengthen your security, not a contest to reach the highest score possible. In this series, I&amp;rsquo;ll pick out random actions and try to make it as simple as possible, backed with notes from the field.&lt;/p&gt;</description></item></channel></rss>