Using Conditional Access with Authentication Flows

preview_player
Показать описание
Some authentication flows are more susceptible to phishing attacks and abuse like the device code flow. Now we can block them with conditional access.

🔎 Looking for content on a particular topic? Search the channel. If I have something it will be there!

▬▬▬▬▬▬ C H A P T E R S ⏰ ▬▬▬▬▬▬
00:00 - Introduction
00:30 - Device code flow
02:31 - Phishing the auth flow
03:47 - Authentication transfer
04:28 - Protecting with conditional access
05:16 - Where are authentication flows being used?
06:42 - Creating a CA policy
07:57 - Demo of block
10:18 - Summary

▬▬▬▬▬▬ Want to learn more? 🚀 ▬▬▬▬▬▬
📖 Recommended Learning Path for Azure
🥇 Certification Content Repository
📅 Weekly Azure Update
☁ Azure Master Class
⚙ DevOps Master Class
💻 PowerShell Master Class
🎓 Certification Cram Videos
🧠 Mentoring Content
❔ Questions? Maybe I answered it in my FAQ
👕 Cure Childhood Cancer Charity T-Shirt Channel Store

#microsoft #azure #johnsavillstechnicaltraining
Рекомендации по теме
Комментарии
Автор

Hey everyone, let's help protect when we are doing remote authentication! Please make sure to read the description for the chapters and key information about this video and others.

⚠ P L E A S E N O T E ⚠

🔎 If you are looking for content on a particular topic search the channel. If I have something it will be there!
🕰 I don't discuss future content nor take requests for future content so please don't ask 😇
🤔 Due to the channel growth and number of people wanting help I no longer can answer or even read questions and they will just stay in the moderation queue never to be seen so please post questions to other sites like Reddit, Microsoft Community Hub etc.

Thanks for watching!
🤙

NTFAQGuy
Автор

always a great place to learn most up-to-date Microsoft Cloud lessons . Thank for great work!

yulaw
Автор

Best Azure related content on Youtube.
Chapeau bas.

maciejpakulski
Автор

Thanks John, great video, really helpful!

Saqibss
Автор

Conditional access has to be one of the best features of entra

captoblivious
Автор

Thanks John… learning is fun watching your videos 😊

ardravyakar
Автор

Great content, John. Thanks for sharing.

_zrday
Автор

So is DCF something that we should consider blocking now (like sms for mfa)? Or is this just a new capability in case we need to do something with it? I know I've used device codes here and there for various things but can't recall what (my 1 month logs don't show anything).

MrMarcLaflamme
Автор

Is this still a private preview feature?? I'm not seeing authentication flows available...

oderbang
Автор

Is this on by default and needs to be locked down?

wmehboob