Posts

Showing posts from May, 2023

Can Microsoft Authenticator Lite App and Named location based on GPS coordinates work together?

Image
On May 26, 2023, Microsoft moved Microsoft Authenticator Lite App to General availability . Authenticator Lite was introduced to help organizations adopt alternative tool of authentication for users who had still not downloaded the full Microsoft Authenticator application for MFA, in an endeavor to enhance the security by moving from text message (SMS) and voice-based authentication. This is to ensure that every user sign-in is done using modern strong authentication. Authenticator Lite is embedded in Outlook client for iOS and Android platforms allowing users to request authentication and receive Time Based One Time Password (TOTP) codes. The feature is currently in the state ‘Microsoft managed.’ until June 9 after which it will be turned on by default. Which bring me us back to the topic of this blog. If you already have users registered for Microsoft Authenticator app, then you don't have to do anything and this post may not apply to you, however, if you are planning to use Auth

Enable Additional context together with Number matching in Microsoft Authenticator Notifications using Entra

Image
Microsoft will be enabling number matching by default across all tenants starting May 8 2023 . "We will remove the admin controls and enforce the number match experience tenant-wide for all users of Microsoft Authenticator push notifications starting May 8, 2023. We highly recommend enabling number matching in the near term for improved sign-in security. Relevant services will begin deploying these changes after May 8, 2023 and users will start to see number match in approval requests. As services deploy, some may see number match while others don't. To ensure consistent behavior for all users, we highly recommend you enable number match for Microsoft Authenticator push notifications in advance." Number matching is a key security upgrade to traditional second factor notifications in Microsoft Authenticator. So it is a no brainer to have this enabled by default for all users. However, I will recommend enabling additional context together with number matching to improve sig

Configure CloudAPAuthEnabled to support Conditional Access in Google Chrome natively

Image
Starting with version 111 of Google Chrome, organizations can leverage conditional access policies natively using  CloudAPAuthEnabled . Before this release, Conditional access policies were only supported on Google Chrome by using additional extensions like Windows Accounts and Office Online . If you want to know more about the use of these extensions, then you can read all about it over here . Let's see the new policy involving  CloudAPAuthEnabled in a little detail and how can organization configure it using enterprise device management solutions. CloudAPAuthEnabled   is a setting that can be configured using the policy  Configures automatic user sign-in for accounts backed by a Microsoft® cloud identity provider .  By setting this policy to 1 (Enabled), users who sign into their computer with an account backed by a Microsoft cloud identity provider or who have added a work or school account to Microsoft Windows, can be signed into web properties using that identity automatical