- Microsoft 365 Security Administration:MS-500 Exam Guide
- Peter Rising
- 415字
- 2021-06-18 18:57:34
Configuring MFA registration policies
We have already discussed MFA in Chapter 2, Authentication and Security, and Chapter 3, Implementing Conditional Access Policies, and illustrated how MFA can be enabled and enforced for your Microsoft 365 users via both the Office 365 Admin Center and by using Conditional Access policies. It is also possible to configure an Azure MFA policy for your cloud-based users from within the Azure AD Identity Protection pane.
In the context of Identity Protection, it is always preferable to require Azure MFA for your user sign-ins as it does the following:
- Provides strong authentication with a choice of verification methods
- Provides your users with the option to effectively take responsibility for their own risk detections and use self-remediation
In order to configure the MFA registration policy within Azure Identity Protection, we need to complete the following steps:
- From the Azure AD Identity Protection pane, navigate to the Protect section and select MFA registration policy:
Figure 5.10 – MFA registration policy
- Next, under Assignments, select Users:
Figure 5.11 – Assigning a policy to users
- Here, you can decide whether you want to apply the requirement for MFA to all your users or whether to select specific users or groups. You also have the option to explicitly exclude users from the policy. When you have made your selections, click Done:
Figure 5.12 – Including or excluding users
- Next, under Controls and Access, ensure that Require Azure MFA registration is selected:
Figure 5.13 – Access controls
- Click Select, and then ensure that Enforce Policy is set to On:
Figure 5.14 – Enforcing the policy
- Click Save.
The policy will be saved, and the affected users will be prompted to register for MFA the next time they sign in with their Microsoft 365 credentials. They will be able to bypass MFA registration and continue to log in for a period of 14 days. They will then be forced to complete the registration process, or they will be unable to gain access.
Important note
Once again, it is important to ensure that your break glass account is explicitly excluded from the requirement to register for Azure MFA.
So, with this, we have shown you how an MFA registration policy can be configured and deployed to your Microsoft 365 users with Azure AD Identity Protection. This will force your users to register for MFA. If you have Azure AD Premium P2 licenses available to you in your tenancy, it is highly recommended to deploy the MFA registration policy.
- 數(shù)字身份與元宇宙信任治理
- Kali Linux CTF Blueprints
- 腦洞大開:滲透測試另類實戰(zhàn)攻略
- Metasploit Penetration Testing Cookbook(Second Edition)
- Enterprise Cloud Security and Governance
- 計算機網(wǎng)絡(luò)安全技術(shù)研究
- 信息安全案例教程:技術(shù)與應(yīng)用(第2版)
- 安全防御入門手冊
- 數(shù)據(jù)安全與流通:技術(shù)、架構(gòu)與實踐
- INSTANT Apple Configurator How-to
- 黑客攻防實戰(zhàn)從入門到精通
- Mastering Python for Networking and Security
- 信息內(nèi)容安全管理及應(yīng)用
- 云計算安全技術(shù)與應(yīng)用
- 紅藍攻防:技術(shù)與策略(原書第3版)