News: 1699379114

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft likens MFA to 1960s seatbelts, buckles admins in yet keeps eject button

(2023/11/07)


Microsoft is introducing three Conditional Access policies for sysadmins as it continues to promote the implementation of multi-factor authentication (MFA) in organizations.

The trio of optional policies will be automatically deployed to eligible customers' tenants in a report-only mode at first. Customers will have a 90-day window in which to review and if necessary opt out of them, otherwise they will be automatically enabled after this time.

This process will start next week but Microsoft will notify customers before it deploys policies on the orgs.

[1]

Of the three options, Microsoft is pushing the first one the strongest, which will apply to Entra ID Premium Plans 1 and 2. It mandates privileged admin accounts to complete MFA when accessing Microsoft admin portals such as [2]Azure , Microsoft 365 admin center, and Exchange admin center.

[3]

[4]

Admins can choose to opt out of the policy despite the warning, but Microsoft said in the future it will place an increasing number of MFA requirements on specific interactions regardless.

The other two policies apply to a smaller subset of customers. For those running the legacy per-user implementation of [5]MFA , logins to cloud apps will require MFA across the board.

[6]

Per-user MFA is not Microsoft's preference for customers and it said this policy aims to ease the transition away from a per-user deployment and toward using Conditional Access as standard.

Those on the [7]Microsoft Entra ID Premium Plan 2 also have their own policy, requiring MFA for all high-risk sign-ins – access attempts from accounts that have recently shown behavior outside of what is considered to be normal.

These policies represent the latest step taken by Microsoft to increase MFA uptake to an idealistic 100 percent of all customers. Currently, just 37 percent utilize MFA but the proportion of newer tenants adopting it is considerably higher.

[8]

The 2019 "security defaults" initiative from Microsoft, which involved the automatic application of basic security controls as standard for all new Microsoft customers – including MFA – has led to more than 80 percent of newbies since then keeping MFA enabled.

Microsoft started rolling security defaults out to pre-existing customers in 2022, starting with smaller, simpler customers that had never touched their security settings. Now, more than 94 percent of these SMEs have kept MFA enabled, we're told.

The overall uptake is still much lower than what Microsoft would want, though. It cited its own [9]research that showed MFA can reduce the risk of account takeover by more than 99 percent. It also claims that customers who have security defaults enabled experience 80 percent fewer compromises compared to those that don't.

"Today, many customers use security defaults, but many others need more granular control than security defaults offer," [10]said Alex Weinert, VP Identity Security at Microsoft.

"Customers may not be in a position to disable legacy authentication for certain accounts (a requirement for security defaults), or they may need to make exceptions for certain automation cases. Conditional Access does a great job here, but often customers aren't sure where to start. They've told us they want a clear policy recommendation that's easy to deploy but still customizable to their specific needs. And that's exactly what we're providing with Microsoft-managed Conditional Access policies.

[11]Microsoft unveils shady shenanigans of Octo Tempest and their cyber-trickery toolkit

[12]1Password confirms attacker tried to pull list of admin users after Okta intrusion

[13]CISA reveals 'Admin123' as top security threat in cyber sloppiness chart

[14]Scattered Spider traps 100+ victims in its web as it moves into ransomware

"Microsoft-managed Conditional Access policies provide clear, self-deploying guidance. Customers can tune the policies (or disable them altogether), so even the largest, most sophisticated organizations can benefit from them. Over time, we'll offer policies tailored to specific organizations, but we're starting simple."

Funnily enough, Weinert likened MFA to 1960s seatbelts, saying that before 1965, car owners had to install them manually but after they were made a legal requirement, traffic-related injuries plummeted.

Like whiplash and dashboard-induced head lumps, consumer account compromises also fell substantially when Microsoft turned MFA on by default in 2013, Weinert said. ®

Get our [15]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZUrBk62qdDVy6a2UIMJWxwAAAIQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://www.theregister.com/2023/06/12/comment/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZUrBk62qdDVy6a2UIMJWxwAAAIQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZUrBk62qdDVy6a2UIMJWxwAAAIQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2023/05/09/microsoft_authenticator_number_matching/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZUrBk62qdDVy6a2UIMJWxwAAAIQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2023/07/17/enra_azure_ad_opinion_column/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZUrBk62qdDVy6a2UIMJWxwAAAIQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RW166lD?culture=en-us&country=us

[10] https://www.microsoft.com/en-us/security/blog/2023/11/06/automatic-conditional-access-policies-in-microsoft-entra-streamline-identity-protection/

[11] https://www.theregister.com/2023/10/27/octo_tempest_microsoft/

[12] https://www.theregister.com/2023/10/24/1password_confirms_all_logins_are/

[13] https://www.theregister.com/2023/10/06/cisa_top_10_misconfigurations/

[14] https://www.theregister.com/2023/09/15/scattered_spider_snares_100_victims/

[15] https://whitepapers.theregister.com/



Anonymous Coward

After we forced MFA for all users, the number of hacked accounts. dropped by over 99%. (It wasn't quite 100% as we've had one hacked account due to social engineering)

Scott 26

I wish I could turn on MFA across the entire enterprise.... but OpSec still has this pre-cloud mentality that if the users are on-prem (physically or logically, via a VPN) then they don't need to do MFA..... I have strongly lodged my objections, and am now waiting for the first breach due to a compromised on-prem device.

Also the belief "we don't want to disrupt the C-suite" - ffs, who do you think is a richer target? The CxO or John at the callcentre?

Er MFA is merely one part of Conditional Access

Anonymous Coward

or it was when I was an Azure sysadmin.

You have the conditional access framework which in turn triggers one of the methods of MFA (SMS, email, authenticator, etc).

You turn *on* conditional access, then configure it to use MFA when a condition is tripped.

Re: Er MFA is merely one part of Conditional Access

43300

They are currently trying to phase out SMS - which wouldn't be such as issue if the authenticator app was less of a pain in the arse to set up for users who aren't very IT literate. And the user has to do it (unlike with SMS where the admins can set it up for them).

Expedience is the best teacher.