Posts

Showing posts with the label macos

Microsoft Entra makes passwordless registration easier, but what does this mean for Zero Trust?

Image
Microsoft Entra makes passwordless registration easier, but what does this mean for Zero Trust? Let's discuss.. Microsoft recently  published  a message in the message center that covers details on Windows Hello for Business and macOS Platform SSO supporting standalone MFA factors. It is well established that Passwordless authentication is becoming the default approach for modern identity security. Windows Hello for Business (WHfB), passkeys, FIDO2 and macOS Platform SSO (PSSO) all provide stronger authentication while reducing our dependency on passwords. And with this new change, Microsoft has now made passwordless registration in Entra ID easier, including bringing register security information further into the conditional access model. However, this does raise an interesting question: If passwordless authentication is strong enough to authenticate the user, do we still need MFA? In my personal opinion, it is still necessary, but not necessarily in the way we traditionally ...

Enable compliant network compliance using conditional access & Global Secure Access client for macOS - Putting it all together!

Image
Back in January, 2024, when I first wrote about my experience working with Global Secure Access (GSA) for Android OS, GSA was still in preview. Since then, most of the configuration in GSA has been moved into GA, including support for macOS, and this is what I will be covering in this blog. First a quick refresher on what GSA is really all about. Global Secure Access (GSA) is Microsoft’s unified Security Service Edge (SSE) solution that combines Microsoft Entra Internet Access and Microsoft Entra Private Access, giving identity-aware access control (for internet, SaaS, and private resources) without relying solely on VPNs. Using GSA one can guard against threats like token replay by leveraging a combination of compliant network and conditional access policies. A compliant network check is a conditional access control that one can configure so that access to resources is only allowed when the client is connected via the Global Secure Access infrastructure (i.e. traffic is routed throug...

Microsoft Purview DLP Domain Restrictions for macOS

Image
While scoping for a project for a customer involving the features of Microsoft Purview for Windows devices, it got me thinking about other OS platforms like macOS and what all Purview had to offer. As it turns out, there is a lot. From real-time file inspection across different file types & classification to robust policy protection controls, Microsoft Purview DLP offers a rich set of capabilities.  As of writing this blog, here is a complete list of features supported on macOS. Source: Microsoft Once devices are onboarded into the Microsoft Purview solutions, the information about what users are doing with sensitive items is made visible in the Purview portal. There is a bit involved in getting the macOS devices onboarded and creating policies in Purview, so let's get started. What are the pre-requisites? 1. If you are using Intune, then make sure the device is enrolled in Intune. 2. Device is onboarded to Microsoft Defender for Endpoint with a minimum version of 101.95.07.x 3...