Microsoft promises end-to-end encrypted Teams calls for some, invites you to go passwordless with Azure AD
- Reference: 1614756246
- News link: https://www.theregister.co.uk/2021/03/03/microsoft_ups_security/
- Source link:
The Teams improvements, announced at the tech giant’s [1]Ignite conference this week, will be available "to commercial customers in preview in the first half of this year."
[2]
"In this first release, customers will have the ability to enable E2EE for 1:1 unscheduled Teams calls," Redmond [3]said . "Customers will be able to specify which members of their organization can use E2EE. Future updates will be made available to support customers’ evolving compliance needs, including expanding to scheduled calls and online meetings."
Among the large array of collaboration software, almost all of which had seen a massive increase in use thanks to the global pandemic, most services don’t provide a proper end-to-end encryption solution, instead relying on encryption of data in transit – typically TLS – and different encryption when stored on servers.
[4]
Microsoft fixes four zero-day flaws in Exchange Server exploited by China's ‘Hafnium’ spies to steal victims' data [5]READ MORE
That provides a goodish level of security but doesn’t ensure that communication is only visible and understandable to the people actually talking to one another. Video conferencing rival Zoom [6]offers end-to-end encryption with a few caveats and additional steps, and that appears to be more or less the approach Microsoft will take, too.
Microsoft also said passwordless authentication in Azure Active Directory is now [7]generally available . Thus, Azure AD users can ditch typed-in passwords altogether, and instead use things like biometrics (facial recognition and fingerprints) or separate authentication apps or hardware keys to log into accounts.
No matter how many times it is drilled into people that using non-complex passwords or reusing passwords is a security risk, people still do it, making life easier for miscreants to break into accounts. While it's relatively easy to phish someone's passphrase, it's more tricky – though not impossible – to do so if the target uses multi-factor authentication.
“When there’s passwords there is inherent risk to the organization,” Microsoft’s VP of security, compliance, and identity marketing Vasu Jakkal [8]told Yahoo ! . “It's a long journey but we do hope that passwordless is going to be a norm. It is a safer way to do things and so the more we can all embrace that I think the more we can protect ourselves and our organizations.”
[9]Microsoft touts Azure Percept development kits to those toying with AI on the edge
[10]Excel-lent: Microsoft debuts low-code Power Fx language... but it is not really new
[11]Microsoft previews Windows Server 2022: Someone took a spanner to core plumbing features
Microsoft supports a bunch of passwordless authentication solutions, such as its own Windows Hello facial recognition, fingerprint readers similar to many modern mobile phones, its Microsoft Authenticator app that provides a time-limited login authorization code, and physical things like USB fobs that use the FIDO security standard.
It also talked up something called [12]Temporary Access Pass , which will provide an Authenticator-style time-limited short code that sysadmins can send people for initial logins or for recovering access.
You can find a load of other security-related announcements [13]here .
This all follows the news of the mass hacking of government departments and Fortune 500 companies by suspected Russian-government hackers who [14]backdoored SolarWinds' network monitoring software. Some of Microsoft's own source code was [15]swiped by the cyber-spies during this espionage campaign. ®
[16]
PS: Microsoft also [17]made its enterprise-grade Power Automate Desktop tool free for Windows 10 users.
Get our [18]Tech Resources
[1] https://blogs.microsoft.com/blog/2021/03/02/ignite-2021-a-resilient-reimagined-future-and-next-big-whoa-moment/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YD9sSIHoFRCZFkwO@pLZbQAAAM0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://news.microsoft.com/ignite-march-2021-book-of-news/
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YD9sSIHoFRCZFkwO@pLZbQAAAM0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2021/03/03/hafnium_exchange_server_attack/
[6] https://www.theregister.com/2020/10/27/zoom_endtoend_encryption/
[7] https://techcommunity.microsoft.com/t5/azure-active-directory-identity/passwordless-authentication-is-now-generally-available/ba-p/1994700
[8] https://finance.yahoo.com/news/microsoft-exec-we-continue-to-see-140006130.html
[9] https://www.theregister.com/2021/03/02/microsoft_azure_percept/
[10] https://www.theregister.com/2021/03/02/microsoft_debuts_lowcode_power_fx/
[11] https://www.theregister.com/2021/03/02/microsoft_previews_windows_server_2022/
[12] https://techcommunity.microsoft.com/t5/azure-active-directory-identity/temporary-access-pass-is-now-in-public-preview/ba-p/1994702
[13] https://www.microsoft.com/security/blog/?p=92885
[14] https://www.theregister.com/2021/02/24/microsoft_solarwinds_congress_disclosure_law/
[15] https://www.theregister.com/2021/02/19/microsoft_source_code/
[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YD9sSIHoFRCZFkwO@pLZbQAAAM0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[17] https://flow.microsoft.com/en-us/blog/automate-tasks-with-power-automate-desktop-for-windows-10-no-additional-cost/
[18] https://whitepapers.theregister.com/
Re: "Microsoft", "cloud", "passwordless authentication"......................
If you have a firm grasp of the whole concept, it's actually a damn site secure than having people type passwords in. It's an order of magnitude more secure to use a hardware token or authenticator to avoid phishing and as an MSP, from a helpdesk perspective it would save the number of calls on a daily basis ten-fold if we didn't have to do password resets, locked out accounts, etc. I know there are solutions out there, e.g FastPass to work around this but they cost mega bucks.
I, for one, am looking forward to Azure passwordless auth becoming the norm as it'll reduce our workload and make things more secure for the end user.
Re: "Microsoft", "cloud", "passwordless authentication"......................
Lots of things... largely that replacing the secret component of authentication with a non-secret component is fundamentally stupid. Using facial recognition or fingerprints as an Identifier? That's fine, but as a replacement as a secret, such as a password? That never improves security.
Replacing my passwords...
...With bio-metrics just means that the bad actors will need to learn how to spoof bio-metrics. How would this compare to enforcing the managed use of lengthy, randomized that are changed on a regular basis?
One huge benefit of using bio-metrics is that over time it limits the amount of data that needs to be processed in order to authenticate a user. Another is that no one (to my knowledge) has come up with a quick way to spoof bio-metrics...yet. However, our finger prints rarely change. The same is true for our faces. Once a bio-metric measurement has been cracked it should be considered insecure for the foreseeable future. In my opinion if passwords are long enough, random enough, changed often enough, and are securely hashed they will remain superior to bio-metric authentication, but perhaps inferior to using bio-metrics as 2FA with strong passwords.
Instead of trying to chase this Holy Grail I think Microsoft would be better off spending it's money learning how to apply the Shannon Limit to Dev Ops in order to reduce the number of bugs in released code to something close to zero. I think that Grail is more Holy than passwordless authentication..
not for on-premises-only Active Directory... BOOOOOOOO :(
booooo....GTFO, MS.
"generally available" does NOT mean it's also available for on-premises Windows Servers who just want to deploy FIDO2 hardware keys for authentication in regular Active Directory systems, to get rid of passwords too.
If it has to be Azure-enabled... that means additional $$$$$, because Azure authentication management for hybrid Azure AD is not included with an on-prem Windows Server Standard license.
Azure Active Directory is a different kettle of fish than regular Active Directory.
It was so much easier
back in the day, when you just changed your password.
Now you need plastic surgery.
Once again ... (how many times do we have to shout this?)
" Azure AD users can ditch typed-in passwords altogether, and instead use things like biometrics (facial recognition and fingerprints) "
Biometrics should never be used as authenticators not least because:
[1] an authenticator is some form of shared secret but biometrics by definition are not secret as you carry them around in plain view and leave some of them behind wherever you've been;
[2] an authenticator must be amenable to being rescinded, but you can't rescind a biometric (short of "rubbing out" the party concerned);
[3] a single authenticator should not be used for multiple incompatible purposes, but you'll soon run out of alternatives for different purposes if biometrics are used.
The only valid use of a biometric is as an identifier . Authentication is the second phase after identification and should use something that complies with the above principles.
Quite apart from which, current "biometric authentication" systems don't actually use biometrics despite being tied to them. They use grossly simplified digests of them translated into numeric form. Such systems can be breached in many ways via compromise of the digest.
Re: Once again ... (how many times do we have to shout this?)
I continually despair at the barely trained monkeys at Microsoft, and other organisations, who, having no doubt been brought up on Hollywood movies, hold the utterly inexplicable belief that facial recognition or fingerprints are in any way a substitute for the secret component of authentication. They are not. As noted above, they are an adequate replacement for an identifier, but nothing else.
"Microsoft", "cloud", "passwordless authentication"......................
................what could possibly go wrong?