#entraid

10 posts · Last used 15d

Replying to
@14mission@sfba.social @morgan@sfba.social Microsoft (and Entra ID) is retiring SMS soon, so this won't be an option for a large number of orgs and folks in the near future. SMS is also not secure and does not meet the higher security standards that many organizations are now attempting to meet. #MFA #SMS #EntraID #Microsoft
0
1
0
0
Replying to
@14mission@sfba.social @morgan@sfba.social for reference: "From February 1, 2027, Microsoft-provided telecom delivery for SMS and voice will be retired for all users except Global Administrators and external users. For Global Administrators and external users, Microsoft-provided SMS and voice authentication will be retired on July 1, 2027." https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sms-voice-retirement #Microsoft #EntraID #MFA #Passkeys #SMS
0
0
0
0
Part 2 of our series on token theft in Microsoft Entra ID is live, accompanying ERNW White Paper 80. This one puts Continuous Access Evaluation to the test empirically. Of 740 first-party resources we checked for the CAE claim, 33 carried it. Revocation timing ranged from 0 seconds for network-based policies to around 5 minutes at Exchange Online. In exchange for that, CAE tokens may live up to 28 hours rather than the usual 90 minutes. https://insinuator.net/2026/09/token-theft-in-microsoft-entra-id-part-2-of-4-continuous-access-evaluation/ by Niklas Kerner #EntraID #CAE #ZeroTrust #InfoSec
0
0
0
0
Microsoft to Stop Providing Telephony-Based Authentication Methods for MFA in February 2027 In an important announcement for all tenants, Microsoft revealed that Entra ID will no longer provide SMS one-time codes or voice calls for MFA challenges after February 1, 2027. Tenants can continue to use telephony-based authentication methods after that date, but only by purchasing a service from a telecom provider. This is arguably the biggest change in Entra ID authentication since mandatory MFA for administrative interfaces – and we have a PowerShell script to help identify the affected accounts. https://office365itpros.com/2026/07/14/entra-sms-one-time-code/ #EntraID
1
0
0
0
RE: https://infosec.exchange/@CDubbs/116847680945065797 Create a group called "Device Code Users" and a CA policy that blocks the use of the Device Code authentication flow except for those in the group. #cybersecurity #entraID
Quoting
EntraID PSA: Disable OAuth Device Code flow in your default conditional access policy. You can search sign-on logs for people using this method to baseline and manage exceptions where appropriate.
Open quoted post
2
0
0
0
heise+ | POSIX-Attribute für Entra ID mit Himmelblau anlegen Werden vor einer Entra ID-Umstellung Linux-Clients und -Fileserver genutzt, gelten dort POSIX-Berechtigungen. Ein eigenes ID-Mapping kann sinnvoll sein. https://www.heise.de/ratgeber/POSIX-Attribute-fuer-Entra-ID-mit-Himmelblau-anlegen-11316718.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon #EntraID #IT #Linux #Unix #news
1
0
12
0
You've seen all posts