Want the full phishing-resistant MFA baseline – Conditional Access, authentication strengths, and the policies that actually enforce …

32 COMMENTS

  1. How prevalent is sim swapping?

    Too bad their own authenticator app doesn't backup to work/school accounts or backup passkeys even with with attestation disabled and shared passkeys enabled.

    Everyone will just backup their passkeys to personal icloud instead.

    Hope they put that sms saving to hiring more staff in the Data Protection Team that will have to deal with the account lockout tsunami

  2. I am curious on how we tackle personal devices? We allow our users to use their own personal device for MFA, but when using the passkey inside MS AUTHENTICATOR, it requires a sign in which gets blocked by Conditional Access.

  3. So, what is the point of 2FA (something you know and something you have) when Microsoft are essentially replacing it with 1FA (password + Authenticator app becomes passcode via Authenticator App, something you have)?

  4. I get why MS wants to do this, but there are legitimate situations where this is going to be a huge PITA. I see a lot of orgs implementing 3rd party SMS/telephony service and continuing on business as usual because the alternative is a mountain of work and business process change.

  5. this initiative took my whole august. i just hope September is not a mess with the start of this transition. Technically the full retirement is feb but the actual change will already be obvious by then.

  6. We have SMS and Voice disabled in the Authentication Methods Policies and running the script to find user shows no action required. However, when I check the Activity I do see some users have registered SMS and Mobile. I assume those were registered before we disabled them. Right now we only have MS Authenticator, TAP, and Hardware OATH Tokens. For the users who have a phone number listed in their User authentication methods, what do we do? Do we delete those phone numbers as a usable authentication method?

  7. So every service that accepts physical keys has a different "key characteristic" that is both a strength and weakness:
    Microsoft(retail)-One key per windows device, resets/re-PINs allowed, PIN not entered on every use
    Google-Multiple keys allowed, no resets, pin required every use (must match previously registered PIN if used on other services)
    Sony-Key is binded to only be used with the physical device it was registered with, multiple key/device combos allowed, no resets (must match previously registered PIN)

LEAVE A REPLY

Please enter your comment!
Please enter your name here