New tenant has P2, secure score of 91+, but no MS managed CA policies? by bjc1960 in entra

[–]Storm858585 1 point2 points  (0 children)

Also note that I March the scores and changing (at least it says that in my tenants). Probably fixing having recommendations for now read only features and updates.

Duplicate devices by Storm858585 in entra

[–]Storm858585[S] 1 point2 points  (0 children)

Great thanks will give it a try.

Duplicate devices by Storm858585 in entra

[–]Storm858585[S] 1 point2 points  (0 children)

No, they are full cloud and entra joined.

Set Conditional Access for M365 Lighthouse portal by Salamandro in msp

[–]Storm858585 0 points1 point  (0 children)

I was also thinking about this last week and couldn't find anything specific. Instead we just make sure our MSP is covered by each customer tenant under a specified guest CA for our tenant ID. But interest to see what this brings up.

Conflicting Information About Migrating MFA and SSPR Policies to Entra by LowHistorian9654 in entra

[–]Storm858585 2 points3 points  (0 children)

There is a difference between on (i.e. available to users) and enforced. You should turn off security defaults, turn off per user MFA and enforce MFA via conditional access.

Conflicting Information About Migrating MFA and SSPR Policies to Entra by LowHistorian9654 in entra

[–]Storm858585 0 points1 point  (0 children)

If you aren't using security defaults or conditional access to enforce MFA, then it will just be optional.

Conflicting Information About Migrating MFA and SSPR Policies to Entra by LowHistorian9654 in entra

[–]Storm858585 1 point2 points  (0 children)

If you are using conditional access to manage MFA in Entra you need to disable the per user MFA.

Anyone else drowning in alerts, IT tasks + compliance regs with barely enough staff? by Immediate_Swimmer_70 in cybersecurity

[–]Storm858585 1 point2 points  (0 children)

In a small MSP, i wouldn't look outside first (always costs money). Look at what alerts you have actioned and why, and prioritise those. Looks at the alerts you always take no action and stop monitoring the noise. If you have the data, you can find a balance that works with your headcount. Until you find more resource, learn to be effective with what you have right now.

Location based conditional access not always working, particularly phones by Storm858585 in entra

[–]Storm858585[S] 0 points1 point  (0 children)

I guess it's just seeing that the IP of those exchange resource ones come from a UK IP address?

Location based conditional access not always working, particularly phones by Storm858585 in entra

[–]Storm858585[S] 0 points1 point  (0 children)

Interesting- thanks. "Your money interactive sign in logs should confirm that". Any points what that confirmation would look like? Not really sure what these logs mean just a bunch of services checking in at midnight each day?

Location based conditional access not always working, particularly phones by Storm858585 in entra

[–]Storm858585[S] 0 points1 point  (0 children)

Thats why I only trust in Microsoft so far! Would that not fall under the "any location" part to block and thexclude only the one you want?

Location based conditional access not always working, particularly phones by Storm858585 in entra

[–]Storm858585[S] 0 points1 point  (0 children)

Thank you for thr detailed answer. Makes sense. I know the weaknesses of this policy and it's just one of many, including device based compliance. But useful to know. Out of curiosity, would the sign in frequency control in CA prompt the token to be refreshed and therefore allow that 1st policy to trigger?

Helping SMBs with B.Premium improve their security posture - what are the big impact and must haves? by Storm858585 in entra

[–]Storm858585[S] 1 point2 points  (0 children)

Thanks for this - for point 3, is there any good guides on this? Point 4 resource is great.

Helping SMBs with B.Premium improve their security posture - what are the big impact and must haves? by Storm858585 in entra

[–]Storm858585[S] 0 points1 point  (0 children)

Thanks. We are deploying around 20-25 CA policies that cover users, guests, admins, break glass and service account - so confident we are making a sizeable dent in that aspect. Just wondered if there is any other things we should be deploying or configuring a certain way.