Enforcing Phishing-Resistant MFA: A Guide for Identity and Access Admins

Explore Our Microsoft Cloud Security Training →

Introduction

In today’s cybersecurity landscape, it’s essential to secure access to your organization’s resources by enforcing multi-factor authentication (MFA). In this guide, we will focus on phishing-resistant MFA methods, specifically FIDO2 and CBA, in Microsoft Azure Active Directory Conditional Access.

What are Authentication Strength policies?

Authentication Strength policies allow you to control the level of authentication required for users accessing your organization’s resources. They assign a strength value based on the authentication methods employed.

Configuring phishing-resistant MFA requirements

To enforce phishing-resistant MFA, configure an Authentication Strength policy requiring FIDO2 or CBA (Certificate-Based Authentication) and assign it to a Conditional Access policy.

FIDO2:

FIDO2 (Fast Identity Online 2) is a set of open authentication standards designed to improve the online sign-in experience while increasing security. FIDO2 devices include hardware security keys and mobile devices with built-in support for FIDO2 protocols.

CBA:

Certificate-Based Authentication (CBA) uses digital certificates to authenticate users, making it resistant to phishing attacks. Users need a smart card or other device that supports CBA and has been issued a valid certificate by your organization’s Certificate Authority (CA).

Common errors when enforcing Authentication Strength

When deploying new policies, users may encounter issues such as login failures due to incompatible devices or missing certificates. Test the policies thoroughly before enforcement and address any problems that arise.

Testing Authentication Strength policies

Test your new policies with a pilot group before enforcing them across the organization. This helps identify and fix any issues without affecting users’ productivity.

Excluding break-glass accounts from strict MFA policies

Break-glass accounts are used for emergency access when regular accounts fail. Exclude these accounts from strict MFA policies to ensure they can be used quickly in case of an incident. Monitor the usage of break-glass accounts and adjust your policies accordingly.

Conclusion

Enforcing phishing-resistant MFA using FIDO2 and CBA in Azure Active Directory Conditional Access strengthens your organization’s security posture against phishing attacks. Learn more about Microsoft Cloud Security Training to master these concepts and secure your environment effectively.

Key Takeaway: Apply the steps and concepts in this post to strengthen your Microsoft IT environment. Ready to go deeper? Explore our hands-on training below.

Explore Our Microsoft Cloud Security Training →

Written by Mohammed Akhter

Founder of ITP Training. 50,000+ students trained across 30+ countries in Microsoft endpoint and cloud security. Learn more →