Protect Microsoft Admin Portals with SIF + (Phishing resistant MFA Or Compliant Device)
Source: Microsoft The memo 22-09 utilizes Microsoft Entra ID as the centralized identity management system when implementing Zero Trust principles and requires employees using enterprise-managed identities to authenticate through multifactor authentication through the means of FIDO2 security keys or Windows Hello for Business to protect against phishing related online attacks. There are multiple options for meeting phishing-resistant multifactor authentication requirements with Microsoft Entra ID. However, the trajectory should be towards implementing modern credentials. Some of the modern approaches are - 1. FIDO2 security keys which according to the Cybersecurity & Infrastructure Security Agency (CISA) is the gold standard of multifactor authentication. 2. Microsoft Entra certificate authentication without dependency on a federated identity provider. 3. Windows Hello for Business as phishing-resistant multifactor authentication Access to Microsoft admin portals like Microsof...