Too bad their own authenticator app doesn't backup to work/school accounts or backup passkeys even with with attestation disabled and shared passkeys enabled.
Everyone will just backup their passkeys to personal icloud instead.
Hope they put that sms saving to hiring more staff in the Data Protection Team that will have to deal with the account lockout tsunami
Hi Jonathan, nice video. What will happen when we have 500+ users enabled for mobile but all of them are also registered the Microsoft Authenticator app?
I am curious on how we tackle personal devices? We allow our users to use their own personal device for MFA, but when using the passkey inside MS AUTHENTICATOR, it requires a sign in which gets blocked by Conditional Access.
I don't use SMS for authenticating for sign ins, but do use it as a backup MFA alongside the Authenticator App for Password Resets unfortunatelyβ¦uhhh.
So, what is the point of 2FA (something you know and something you have) when Microsoft are essentially replacing it with 1FA (password + Authenticator app becomes passcode via Authenticator App, something you have)?
I get why MS wants to do this, but there are legitimate situations where this is going to be a huge PITA. I see a lot of orgs implementing 3rd party SMS/telephony service and continuing on business as usual because the alternative is a mountain of work and business process change.
this initiative took my whole august. i just hope September is not a mess with the start of this transition. Technically the full retirement is feb but the actual change will already be obvious by then.
We have SMS and Voice disabled in the Authentication Methods Policies and running the script to find user shows no action required. However, when I check the Activity I do see some users have registered SMS and Mobile. I assume those were registered before we disabled them. Right now we only have MS Authenticator, TAP, and Hardware OATH Tokens. For the users who have a phone number listed in their User authentication methods, what do we do? Do we delete those phone numbers as a usable authentication method?
So every service that accepts physical keys has a different "key characteristic" that is both a strength and weakness: Microsoft(retail)-One key per windows device, resets/re-PINs allowed, PIN not entered on every use Google-Multiple keys allowed, no resets, pin required every use (must match previously registered PIN if used on other services) Sony-Key is binded to only be used with the physical device it was registered with, multiple key/device combos allowed, no resets (must match previously registered PIN)
What accounts should be excluded like BreakGlass, Service accounts etc?
How prevalent is sim swapping?
Too bad their own authenticator app doesn't backup to work/school accounts or backup passkeys even with with attestation disabled and shared passkeys enabled.
Everyone will just backup their passkeys to personal icloud instead.
Hope they put that sms saving to hiring more staff in the Data Protection Team that will have to deal with the account lockout tsunami
Hi Jonathan, nice video. What will happen when we have 500+ users enabled for mobile but all of them are also registered the Microsoft Authenticator app?
You are amazing, thanks for headsups and great explanations Jon!
Thank you sooo much sir, you are amazing
This is going to be fun for my users in Chinaβ¦
So this doesn't affect local accounts so why should i worry and i don't use SMS MFA so it don't affect me
Can you just use Windows Hello for Business only, and not enable other passkeys?
Phone number is so convenient though, I administer MS 365 for many, many, different SMB customers⦠it's incredibly annoying as there is sooooo many.
Thank you sir! Can you please share the link of GitHub script as well?
I am curious on how we tackle personal devices? We allow our users to use their own personal device for MFA, but when using the passkey inside MS AUTHENTICATOR, it requires a sign in which gets blocked by Conditional Access.
opt out microslop, so easy
I don't use SMS for authenticating for sign ins, but do use it as a backup MFA alongside the Authenticator App for Password Resets unfortunatelyβ¦uhhh.
Great presentation as always Jonathan. Thank you.
Hello, thanks for the video and information on this, will this affect all SMS i.e. WhattApp or just the old style SMS texts that we're used too? Tim.
Wish heβd drop this obsession to do drag comedy. It adds nothing to the video.
Passkeys will be switched on by βdefaultβ by Microsoft from Sept.
I love the MacBook Pro in the image of the guy with his feet up on the desk. At least he doesn't have to worry about Microsoft!
So, what is the point of 2FA (something you know and something you have) when Microsoft are essentially replacing it with 1FA (password + Authenticator app becomes passcode via Authenticator App, something you have)?
I get why MS wants to do this, but there are legitimate situations where this is going to be a huge PITA. I see a lot of orgs implementing 3rd party SMS/telephony service and continuing on business as usual because the alternative is a mountain of work and business process change.
this initiative took my whole august. i just hope September is not a mess with the start of this transition. Technically the full retirement is feb but the actual change will already be obvious by then.
We have SMS and Voice disabled in the Authentication Methods Policies and running the script to find user shows no action required. However, when I check the Activity I do see some users have registered SMS and Mobile. I assume those were registered before we disabled them. Right now we only have MS Authenticator, TAP, and Hardware OATH Tokens. For the users who have a phone number listed in their User authentication methods, what do we do? Do we delete those phone numbers as a usable authentication method?
Does this change have any impact on Teams Call? Thanks ππΎππΎππΎππΎ
β€β€β€β€β€β€ππππ’
Good bhai
πππ
ππ
ππ
ππ
ππ
ππ
So every service that accepts physical keys has a different "key characteristic" that is both a strength and weakness:
Microsoft(retail)-One key per windows device, resets/re-PINs allowed, PIN not entered on every use
Google-Multiple keys allowed, no resets, pin required every use (must match previously registered PIN if used on other services)
Sony-Key is binded to only be used with the physical device it was registered with, multiple key/device combos allowed, no resets (must match previously registered PIN)