<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Conditional Access on JanBakker.tech</title><link>https://janbakker.tech/tags/conditional-access/</link><description>Recent content in Conditional Access on JanBakker.tech</description><generator>Hugo</generator><language>en-US</language><copyright>Jan Bakker</copyright><lastBuildDate>Wed, 29 Nov 2023 08:12:43 +0000</lastBuildDate><atom:link href="https://janbakker.tech/tags/conditional-access/index.xml" rel="self" type="application/rss+xml"/><item><title>Prevent AiTM with Microsoft Entra Global Secure Access and Conditional Access</title><link>https://janbakker.tech/prevent-aitm-with-microsoft-entra-global-secure-access-and-conditional-access/</link><pubDate>Wed, 29 Nov 2023 08:12:43 +0000</pubDate><guid>https://janbakker.tech/prevent-aitm-with-microsoft-entra-global-secure-access-and-conditional-access/</guid><description>&lt;p&gt;Microsoft Entra Global Secure Access brings a new control to Conditional Access. By installing the Global Secure Access Client on (hybrid) Entra joined devices and enabling Global Secure Access signaling for Conditional Access, admins can now work with a new condition: &lt;em&gt;&lt;strong&gt;All Compliant Network locations (Preview)&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;</description></item><item><title>Enforce FIDO2 PIN complexity with Microsoft Entra Conditional Access Authentication Strengths.</title><link>https://janbakker.tech/enforce-fido2-pin-complexity-with-microsoft-entra-conditional-access-authentication-strengths/</link><pubDate>Wed, 06 Sep 2023 07:58:50 +0000</pubDate><guid>https://janbakker.tech/enforce-fido2-pin-complexity-with-microsoft-entra-conditional-access-authentication-strengths/</guid><description>&lt;p&gt;As you may or may not know, most FIDO2 security keys can be set up with easy PINs like 1111 or 123456. Just like passwords, users tend to come up with easy-to-remember PINs.&lt;/p&gt;&#10;&lt;p&gt;Token2 recently &#10;&lt;a href="https://www.token2.com/site/page/blog?p=posts/70" rel="noopener"&gt;announced&lt;/a&gt; their PIN+ series, a line of FIDO2 Security keys. These security keys feature advanced PIN complexity rules that set a new standard for security. PIN+ keys implement specific complexity rules for both numeric and alphanumeric PINs, which can be found &#10;&lt;a href="https://www.token2.com/site/page/blog?p=posts/70" rel="noopener"&gt;here&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Step-up authentication with Defender for Cloud Apps and Authentication Context</title><link>https://janbakker.tech/step-up-authentication-with-defender-for-cloud-apps-and-authentication-context/</link><pubDate>Wed, 07 Jun 2023 06:58:07 +0000</pubDate><guid>https://janbakker.tech/step-up-authentication-with-defender-for-cloud-apps-and-authentication-context/</guid><description>&lt;p&gt;In this post, I will show you how you can integrate Azure AD&amp;rsquo;s Authentication Context with Defender for Cloud Apps to require step-up authentication for specific scenarios. Step-up authentication allows you to re-evaluate Azure AD Conditional Access policies when users take sensitive actions during a session.&lt;/p&gt;</description></item><item><title>Close the gap. Azure AD Identity Protection &amp; Conditional Access.</title><link>https://janbakker.tech/close-the-gap-azure-ad-identity-protection-conditional-access/</link><pubDate>Tue, 14 Jul 2020 17:34:22 +0000</pubDate><guid>https://janbakker.tech/close-the-gap-azure-ad-identity-protection-conditional-access/</guid><description>&lt;p&gt;This blog is about Azure AD Identity Protection and Conditional Access, and how these two features are working together. This is not my first article on this subject. (neither my last) In previous blogs, I covered the &#10;&lt;a href="https://janbakker.tech/microsoft-secure-score-series-07-turn-on-sign-in-risk-policy/"&gt;sign-in risk&lt;/a&gt; and &#10;&lt;a href="https://janbakker.tech/microsoft-secure-score-series-11-turn-on-user-risk-policy/"&gt;user risk&lt;/a&gt; policies as part of the Secure Score Series, and in my blog, about &#10;&lt;a href="https://janbakker.tech/microsoft-secure-score-series-04-ensure-all-users-can-complete-multi-factor-authentication-for-secure-access/"&gt;Azure Multifactor Authentication&lt;/a&gt; I talked about Azure AD Identity Protection, and how it can be used to roll out MFA in your organization.&lt;/p&gt;</description></item><item><title>Use Power Automate as your Conditional Access Police Department</title><link>https://janbakker.tech/use-power-automate-as-your-ca-police-department/</link><pubDate>Sat, 04 Jul 2020 07:10:42 +0000</pubDate><guid>https://janbakker.tech/use-power-automate-as-your-ca-police-department/</guid><description>&lt;p&gt;Last week, I was working on a &#10;&lt;a href="https://janbakker.tech/microsoft-secure-score-series-14-designate-more-than-one-global-admin/"&gt;new blog for the Secure Score Series&lt;/a&gt; regarding global admin and break glass accounts. I came to the point where I was thinking of possible scenarios that could go wrong with these accounts. What if someone accidentally added these users to a certain group? What if that group would be triggered in some policy or maintenance tasks? A lot of these actions can be discovered using Microsoft Cloud App Security and Azure Monitor. This way, you will be alerted when someone touches the accounts in any way, or if the account is used to sign-in.&lt;/p&gt;</description></item><item><title>Microsoft Secure Score Series – 06 – Enable policy to block legacy authentication</title><link>https://janbakker.tech/microsoft-secure-score-series-06-enable-policy-to-block-legacy-authentication/</link><pubDate>Wed, 08 Apr 2020 19:15:37 +0000</pubDate><guid>https://janbakker.tech/microsoft-secure-score-series-06-enable-policy-to-block-legacy-authentication/</guid><description>&lt;p&gt;In this series, I&amp;rsquo;ll be covering the Microsoft Secure Score improvement actions. Although Microsoft does a great job on telling you what to do, some actions have a much bigger impact and need to be balanced against business needs. Some actions might not even have value for your organization. In the end, Microsoft Secure Score is meant to strengthen your security, not a contest to reach the highest score possible. In this series, I&amp;rsquo;ll pick out random actions and try to make it as simple as possible, backed with notes from the field.&lt;/p&gt;</description></item><item><title>Require trusted location for MFA and SSPR registration</title><link>https://janbakker.tech/require-trusted-location-for-mfa-and-sspr-registration/</link><pubDate>Sat, 22 Feb 2020 20:02:48 +0000</pubDate><guid>https://janbakker.tech/require-trusted-location-for-mfa-and-sspr-registration/</guid><description>&lt;p&gt;This article shows how you can block MFA and SSPR registrations from untrusted locations using Azure AD Conditional Acces.&lt;/p&gt;&#10;&lt;p&gt;When you want to enable MultiFactor Authentication and Self Service Password Reset for your users, they need to register their security settings first. Since the &#10;&lt;a href="https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-registration-mfa-sspr-combined" rel="noopener"&gt;combined portal&lt;/a&gt; arrived, users can do this easily in just one place. Using this combined portal is also a requirement in order to make this possible. Although this portal is still in preview, it has great user experience and wizards run smoothly.&lt;/p&gt;</description></item></channel></rss>