Mandatory MFA (Microsoft Azure, Entra and Intune)

preview_player
Показать описание
As cyberattacks become more frequent, sophisticated, and damaging, protecting identities has never been this crucial. This aligns with Microsoft Zero Trust and their pledge to invest $20 billion dollars in security over the next 5 years.

On 15th August 2024, Microsoft announced they would introduce mandatory MFA for all user accessing Azure starting the second half of 2024.

Phase 1: Will begin with sign-in’s into the Azure portal, Entra portal and Intune admin centre.

(User executing Create, Read, Update. Or Delete will be affected)

Phase 2: Will extend MFA to Azure CLI, Azure Powershell, Azure Mobile App, and IaC. This will begin early 2025.

Notifications about MFA enforcement will be sent to Global Admins 60 days in advance (This will be sent via email and displayed in the admin portals).
A grace period between 15th August and 15th October 2024 will be available, allowing global admins to postpone enforcement. This requires elevated access to all resources.

External MFA providers can be used as long as there federated and can send an MFA claim to Entra ID.

If you’ve got service accounts, they need to be migrated to workload identities.
Рекомендации по теме
Комментарии
Автор

Very informative and helpful. Thank you.

kabookeo
Автор

This notification is not available for my tenant.
I am using CAP Tto manage mfa for users..
Will it be gradually rolled out?

.
Автор

Cheers Rio, thanks for highlighting 👍

mattgifford