<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Mfa on JanBakker.tech</title><link>https://janbakker.tech/tags/mfa/</link><description>Recent content in Mfa on JanBakker.tech</description><generator>Hugo</generator><language>en-US</language><copyright>Jan Bakker</copyright><lastBuildDate>Wed, 06 Sep 2023 07:58:50 +0000</lastBuildDate><atom:link href="https://janbakker.tech/tags/mfa/index.xml" rel="self" type="application/rss+xml"/><item><title>Enforce FIDO2 PIN complexity with Microsoft Entra Conditional Access Authentication Strengths.</title><link>https://janbakker.tech/enforce-fido2-pin-complexity-with-microsoft-entra-conditional-access-authentication-strengths/</link><pubDate>Wed, 06 Sep 2023 07:58:50 +0000</pubDate><guid>https://janbakker.tech/enforce-fido2-pin-complexity-with-microsoft-entra-conditional-access-authentication-strengths/</guid><description>&lt;p&gt;As you may or may not know, most FIDO2 security keys can be set up with easy PINs like 1111 or 123456. Just like passwords, users tend to come up with easy-to-remember PINs.&lt;/p&gt;&#10;&lt;p&gt;Token2 recently &#10;&lt;a href="https://www.token2.com/site/page/blog?p=posts/70" rel="noopener"&gt;announced&lt;/a&gt; their PIN+ series, a line of FIDO2 Security keys. These security keys feature advanced PIN complexity rules that set a new standard for security. PIN+ keys implement specific complexity rules for both numeric and alphanumeric PINs, which can be found &#10;&lt;a href="https://www.token2.com/site/page/blog?p=posts/70" rel="noopener"&gt;here&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Manage user-preferred multi-factor authentication method in Microsoft Entra ID</title><link>https://janbakker.tech/manage-user-preferred-multi-factor-authentication-method-in-microsoft-entra-id/</link><pubDate>Tue, 11 Jul 2023 18:58:26 +0000</pubDate><guid>https://janbakker.tech/manage-user-preferred-multi-factor-authentication-method-in-microsoft-entra-id/</guid><description>&lt;p&gt;This post is all about setting the preferred multi-factor authentication method using Graph API. We already know the &#10;&lt;a href="https://janbakker.tech/system-preferred-multifactor-authentication-in-azure-ad-dont-settle-for-less/"&gt;system-preferred multi-factor authentication method&lt;/a&gt;, where Microsoft Entra ID will use the strongest method of all the registered methods, but this time we take a look a the default method set by the user.&lt;/p&gt;</description></item><item><title>Send an email on a new Azure MFA method registration</title><link>https://janbakker.tech/send-an-email-on-a-new-azure-mfa-method-registration/</link><pubDate>Fri, 02 Jun 2023 09:50:08 +0000</pubDate><guid>https://janbakker.tech/send-an-email-on-a-new-azure-mfa-method-registration/</guid><description>&lt;p&gt;I&amp;rsquo;ve done quite some Azure MFA projects over time (and counting), and as we mainly focus on the technical side, there are also practical sides to consider. Every project has its own approach and challenges, and more importantly: the user is impacted more or less, and that asks for some guidance.&lt;/p&gt;</description></item><item><title>Report Suspicious Activity &amp; Fraud Alert for Azure MFA</title><link>https://janbakker.tech/report-suspicious-activity-fraud-alert-for-azure-mfa/</link><pubDate>Thu, 04 May 2023 12:41:33 +0000</pubDate><guid>https://janbakker.tech/report-suspicious-activity-fraud-alert-for-azure-mfa/</guid><description>&lt;p&gt;A new feature popped up in Azure AD. Well, not entirely new, I must say. Reading from the &#10;&lt;a href="https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-mfasettings#report-suspicious-activity" rel="noopener"&gt;docs&lt;/a&gt;, Report Suspicious Activity is an enhancement of the Fraud Alert feature that has existed for quite some time.&lt;/p&gt;&#10;&lt;p&gt;Until now, administrators could enable &lt;em&gt;Fraud Alert&lt;/em&gt; for Azure MFA so that users could report when suspicious MFA prompts are received. Users who reported fraud could be automatically blocked so they could no longer sign in. As this is a good feature, it kills productivity, as the intervention of an admin can only remediate the user. This admin would then need to unblock the user and ensure the user&amp;rsquo;s identity was secured.&lt;/p&gt;</description></item><item><title>Authenticator Lite - Approve Azure MFA prompts with the Outlook app</title><link>https://janbakker.tech/authenticator-lite-approve-azure-mfa-prompts-with-the-outlook-app/</link><pubDate>Tue, 14 Mar 2023 12:28:09 +0000</pubDate><guid>https://janbakker.tech/authenticator-lite-approve-azure-mfa-prompts-with-the-outlook-app/</guid><description>&lt;p&gt;Microsoft &#10;&lt;a href="https://www.microsoft.com/en-us/microsoft-365/roadmap?filters=&amp;amp;searchterms=122289" rel="noopener"&gt;released&lt;/a&gt; a new feature where the Outlook mobile app now has some of the Microsoft Authenticator App features onboard. Users can now enroll for Azure MFA using just their Outlook mobile app. No additional installation of the Microsoft Authenticator app is needed. This preview brings both push notifications and TOTP to the Outlook mobile app. Users are prompted for enrollment or can manually register their app to work with a Microsoft 365 account once this feature is enabled.&lt;/p&gt;</description></item><item><title>System-preferred multifactor authentication in Azure AD. Don't settle for less.</title><link>https://janbakker.tech/system-preferred-multifactor-authentication-in-azure-ad-dont-settle-for-less/</link><pubDate>Fri, 03 Mar 2023 14:39:38 +0000</pubDate><guid>https://janbakker.tech/system-preferred-multifactor-authentication-in-azure-ad-dont-settle-for-less/</guid><description>&lt;p&gt;A new feature has popped up in Azure AD: &lt;strong&gt;System-preferred multifactor authentication (MFA)&lt;/strong&gt;. This will allow administrators to enforce the most secure method for Azure MFA. For example, if a user has multiple methods registered, the most secure method will be prompted first. How do I know what method is the strongest, you may ask? Here is the current order from most to least secure methods, currently supported in Azure Active Directory:&lt;/p&gt;</description></item><item><title>Azure MFA authentication method analysis. Share the results with Power Automate!</title><link>https://janbakker.tech/azure-mfa-authentication-method-analysis-share-the-results-with-power-automate/</link><pubDate>Tue, 08 Sep 2020 20:34:51 +0000</pubDate><guid>https://janbakker.tech/azure-mfa-authentication-method-analysis-share-the-results-with-power-automate/</guid><description>&lt;p&gt;You might have seen the &#10;&lt;a href="https://docs.microsoft.com/en-us/samples/azure-samples/azure-mfa-authentication-method-analysis/azure-mfa-authentication-method-analysis/" rel="noopener"&gt;sample script&lt;/a&gt;, created by the Microsoft community, to run some analysis on your Azure MFA authentication methods. This script can be used to make recommendations on how to improve each user&amp;rsquo;s MFA configuration.&lt;/p&gt;&#10;&lt;p&gt;You can run the script against your tenant, and the results can be exported to a CSV file. Wouldn&amp;rsquo;t it be cool to share those results with your users straight away? With the use of Power Automate (Flow), we can easily send recommendations to each of our end users. Today I&amp;rsquo;ll show you how this can be done in a few clicks.&lt;/p&gt;</description></item><item><title>Prepopulate phone methods using a Custom Connector in Power Automate</title><link>https://janbakker.tech/prepopulate-phone-methods-using-a-custom-connector-in-power-automate/</link><pubDate>Thu, 30 Jul 2020 07:30:00 +0000</pubDate><guid>https://janbakker.tech/prepopulate-phone-methods-using-a-custom-connector-in-power-automate/</guid><description>&lt;p&gt;This blog post shows the custom connector that is built on top of the Microsoft Graph API. With this connector, you can do bulk actions on Azure AD and provision phone numbers for your users. They can be used for MFA and SSPR. To understand how the connector works, please also read the first part of the blog where I explain the API in detail. In the second part, I have added a step-step-guide on how to create the custom connector and use it in an automation flow.&lt;/p&gt;</description></item><item><title>Prepopulate phone methods for MFA and SSPR using Graph API</title><link>https://janbakker.tech/prepopulate-phone-methods-for-mfa-and-sspr-using-graph-api/</link><pubDate>Thu, 30 Jul 2020 07:29:00 +0000</pubDate><guid>https://janbakker.tech/prepopulate-phone-methods-for-mfa-and-sspr-using-graph-api/</guid><description>&lt;p&gt;This blog post shows the custom connector that is built on top of the Microsoft Graph API. With this connector, you can do bulk actions on Azure AD and provision phone numbers for your users. They can be used for MFA and SSPR. To understand how the connector works, please also read the first part of the blog where I explain the API in detail. In the second part, I have added a step-step-guide on how to create the custom connector and use it in an automation flow.&lt;/p&gt;</description></item><item><title>A first look at Administrative Units and My Staff in Azure Active Directory</title><link>https://janbakker.tech/a-first-look-at-administrative-units-and-my-staff-in-azure-active-directory/</link><pubDate>Sat, 20 Jun 2020 07:47:15 +0000</pubDate><guid>https://janbakker.tech/a-first-look-at-administrative-units-and-my-staff-in-azure-active-directory/</guid><description>&lt;p&gt;Recently, Microsoft introduced &#10;&lt;a href="https://docs.microsoft.com/en-us/azure/active-directory/users-groups-roles/directory-administrative-units" rel="noopener"&gt;Administrative Units&lt;/a&gt; in Azure Active Directory. At the time of writing, this feature is in preview. Today we take a first look at how this is going to help organizations managing users and groups in Azure Active Directory. But to understand why this feature is such a big deal, we need to know what the difference is between the &amp;ldquo;classic&amp;rdquo; Active Directory and the &amp;ldquo;modern&amp;rdquo; Azure Active Directory structure.&lt;/p&gt;</description></item><item><title>Sure, keep me signed in! And don't prompt for MFA!</title><link>https://janbakker.tech/sure-keep-me-signed-in-and-dont-prompt-for-mfa/</link><pubDate>Fri, 22 May 2020 13:40:49 +0000</pubDate><guid>https://janbakker.tech/sure-keep-me-signed-in-and-dont-prompt-for-mfa/</guid><description>&lt;p&gt;Today a short blog about MFA prompts, session lifetime, and cookies. This will give you an idea of how you can tune the end-user experience and where to configure these settings.&lt;/p&gt;&#10;&lt;p&gt;Session lifetime in Azure AD is often mistaken. When you start working with Azure AD, Conditional Access, and Multi-factor authentication, there are a couple of things you should know. The Azure AD defaults are pretty loose. When you leave every setting to default, the user experience is pretty good. Once you logged in to Office 365, your session can be re-used for &lt;strong&gt;90 days&lt;/strong&gt;. During that time, you are not prompted for your password, assuming that is it not changed over time.&lt;/p&gt;</description></item><item><title>What admins should know about the combined registration portal for Azure MFA and Self Service Password Reset</title><link>https://janbakker.tech/what-admins-should-know-about-the-combined-registration-portal-for-azure-mfa-and-self-service-password-reset/</link><pubDate>Sat, 02 May 2020 12:06:20 +0000</pubDate><guid>https://janbakker.tech/what-admins-should-know-about-the-combined-registration-portal-for-azure-mfa-and-self-service-password-reset/</guid><description>&lt;h4 id="this-post-is-outdated-there-is-a-new-way-to-manage-authentication-methods"&gt;&lt;strong&gt;This post is outdated.&lt;/strong&gt; There is a &#10;&lt;a href="https://janbakker.tech/goodbye-legacy-sspr-and-mfa-settings-hello-authentication-methods-policies/"&gt;new way&lt;/a&gt; to manage authentication methods&lt;a class="anchor" href="#this-post-is-outdated-there-is-a-new-way-to-manage-authentication-methods" aria-label="Link to this section"&gt;#&lt;/a&gt;&lt;/h4&gt;&#10;&lt;p&gt;&#10;&lt;a href="https://janbakker.tech/goodbye-legacy-sspr-and-mfa-settings-hello-authentication-methods-policies/"&gt;Learn more&lt;/a&gt;&lt;/p&gt;&#10;&lt;p&gt;The (long) title pretty much reveals the purpose of this blog post. This one was on my to-do list for a while now, and now the &#10;&lt;a href="https://techcommunity.microsoft.com/t5/azure-active-directory-identity/combined-mfa-and-password-reset-registration-is-now-generally/ba-p/1257355" rel="noopener"&gt;combined registration portal is General Available&lt;/a&gt;, the time was there. In my previous MFA-related blogs, I always encouraged my readers to turn on the combined registration portal, even when it was in public preview. But if you start using this portal, there are quite some settings that can change the user experience of the registration. And that&amp;rsquo;s mainly what this blog post is about. Let&amp;rsquo;s see how each setting reflects to the end user.&lt;/p&gt;</description></item><item><title>Microsoft Secure Score Series – 07 – Turn on sign-in risk policy</title><link>https://janbakker.tech/microsoft-secure-score-series-07-turn-on-sign-in-risk-policy/</link><pubDate>Mon, 13 Apr 2020 14:17:04 +0000</pubDate><guid>https://janbakker.tech/microsoft-secure-score-series-07-turn-on-sign-in-risk-policy/</guid><description>&lt;p&gt;In this series, I&amp;rsquo;ll be covering the Microsoft Secure Score improvement actions. Although Microsoft does a great job on telling you what to do, some actions have a much bigger impact and need to be balanced against business needs. Some actions might not even have value for your organization. In the end, Microsoft Secure Score is meant to strengthen your security, not a contest to reach the highest score possible. In this series, I&amp;rsquo;ll pick out random actions and try to make it as simple as possible, backed with notes from the field.&lt;/p&gt;</description></item><item><title>Use Power Automate for your custom "dynamic" groups</title><link>https://janbakker.tech/use-power-automate-for-your-custom-dynamic-groups/</link><pubDate>Wed, 01 Apr 2020 19:52:46 +0000</pubDate><guid>https://janbakker.tech/use-power-automate-for-your-custom-dynamic-groups/</guid><description>&lt;h2 id="azure-ad-dynamic-groups"&gt;Azure AD Dynamic Groups&lt;a class="anchor" href="#azure-ad-dynamic-groups" aria-label="Link to this section"&gt;#&lt;/a&gt;&lt;/h2&gt;&#10;&lt;p&gt;Dynamic groups in Azure AD are awesome. I use them a lot. Dynamic groups can create groups based on attributes. For example, you can create a group that includes all the users from the Sales Team. The query for the group would look like this:&lt;/p&gt;</description></item><item><title>Microsoft Secure Score Series – 04 – Ensure all users can complete multi-factor authentication for secure access</title><link>https://janbakker.tech/microsoft-secure-score-series-04-ensure-all-users-can-complete-multi-factor-authentication-for-secure-access/</link><pubDate>Fri, 27 Mar 2020 21:19:07 +0000</pubDate><guid>https://janbakker.tech/microsoft-secure-score-series-04-ensure-all-users-can-complete-multi-factor-authentication-for-secure-access/</guid><description>&lt;p&gt;In this series, I&amp;rsquo;ll be covering the Microsoft Secure Score improvement actions. Although Microsoft does a great job on telling you what to do, some actions have a much bigger impact and need to be balanced against business needs. Some actions might not even have value for your organization. In the end, Microsoft Secure Score is meant to strengthen your security, not a contest to reach the highest score possible. In this series, I&amp;rsquo;ll pick out random actions and try to make it as simple as possible, backed with notes from the field.&lt;/p&gt;</description></item><item><title>How to publish on-premises applications and protect them with MFA</title><link>https://janbakker.tech/how-to-publish-on-premises-applications-and-protect-them-with-mfa/</link><pubDate>Fri, 13 Mar 2020 18:56:31 +0000</pubDate><guid>https://janbakker.tech/how-to-publish-on-premises-applications-and-protect-them-with-mfa/</guid><description>&lt;p&gt;Using Azure Application Proxy you can publish your on-premises web applications in a secure way. Combining this with Conditional Access, you can configure MFA for example. Now Coronavirus is hitting us hard, you might have to take a look at this feature.&lt;/p&gt;</description></item><item><title>Microsoft Secure Score Series – 02 – Require MFA for administrative roles</title><link>https://janbakker.tech/microsoft-secure-score-series-02-require-mfa-for-administrative-roles/</link><pubDate>Wed, 11 Mar 2020 20:25:28 +0000</pubDate><guid>https://janbakker.tech/microsoft-secure-score-series-02-require-mfa-for-administrative-roles/</guid><description>&lt;p&gt;In this series, I&amp;rsquo;ll be covering the Microsoft Secure Score improvement actions. Although Microsoft does a great job on telling you what to do, some actions have a much bigger impact and need to be balanced against business needs. Some actions might not even have value for your organization. In the end, Microsoft Secure Score is meant to strengthen your security, not a contest to reach the highest score possible. In this series, I&amp;rsquo;ll pick out random actions and try to make it as simple as possible, backed with notes from the field.&lt;/p&gt;</description></item><item><title>Require trusted location for MFA and SSPR registration</title><link>https://janbakker.tech/require-trusted-location-for-mfa-and-sspr-registration/</link><pubDate>Sat, 22 Feb 2020 20:02:48 +0000</pubDate><guid>https://janbakker.tech/require-trusted-location-for-mfa-and-sspr-registration/</guid><description>&lt;p&gt;This article shows how you can block MFA and SSPR registrations from untrusted locations using Azure AD Conditional Acces.&lt;/p&gt;&#10;&lt;p&gt;When you want to enable MultiFactor Authentication and Self Service Password Reset for your users, they need to register their security settings first. Since the &#10;&lt;a href="https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-registration-mfa-sspr-combined" rel="noopener"&gt;combined portal&lt;/a&gt; arrived, users can do this easily in just one place. Using this combined portal is also a requirement in order to make this possible. Although this portal is still in preview, it has great user experience and wizards run smoothly.&lt;/p&gt;</description></item></channel></rss>