Explore Our Microsoft Cloud Security Training →
Introduction
What are Authentication Strength policies?
Authentication Strength policies allow you to control the level of authentication required for users accessing your organization’s resources. They assign a strength value based on the authentication methods employed.
Configuring phishing-resistant MFA requirements
To enforce phishing-resistant MFA, configure an Authentication Strength policy requiring FIDO2 or CBA (Certificate-Based Authentication) and assign it to a Conditional Access policy.
FIDO2:
FIDO2 (Fast Identity Online 2) is a set of open authentication standards designed to improve the online sign-in experience while increasing security. FIDO2 devices include hardware security keys and mobile devices with built-in support for FIDO2 protocols.
CBA:
Certificate-Based Authentication (CBA) uses digital certificates to authenticate users, making it resistant to phishing attacks. Users need a smart card or other device that supports CBA and has been issued a valid certificate by your organization’s Certificate Authority (CA).
Common errors when enforcing Authentication Strength
When deploying new policies, users may encounter issues such as login failures due to incompatible devices or missing certificates. Test the policies thoroughly before enforcement and address any problems that arise.
Testing Authentication Strength policies
Test your new policies with a pilot group before enforcing them across the organization. This helps identify and fix any issues without affecting users’ productivity.
Excluding break-glass accounts from strict MFA policies
Break-glass accounts are used for emergency access when regular accounts fail. Exclude these accounts from strict MFA policies to ensure they can be used quickly in case of an incident. Monitor the usage of break-glass accounts and adjust your policies accordingly.
Conclusion
Enforcing phishing-resistant MFA using FIDO2 and CBA in Azure Active Directory Conditional Access strengthens your organization’s security posture against phishing attacks. Learn more about Microsoft Cloud Security Training to master these concepts and secure your environment effectively.
Explore Our Microsoft Cloud Security Training →
Written by Mohammed Akhter
Founder of ITP Training. 50,000+ students trained across 30+ countries in Microsoft endpoint and cloud security. Learn more →
