• TinyBreak@aussie.zone
      link
      fedilink
      arrow-up
      2
      ·
      5 months ago

      Absolutely bring that up. Fair to assume they are directory synced to the cloud. honestly conditional access is one of the coolest things Microsoft have done in the last 10 years!!

      For inside knowledge: Microsoft apparently working on enabling more complex passwords in entra id. I’m very excited about this because it’s stupid that you have to have an on premises active directory to be able to set minimum complexity requirements.

        • TinyBreak@aussie.zone
          link
          fedilink
          arrow-up
          2
          ·
          5 months ago

          Correct, mfa ain’t enough. Especially in sensitive settings like the courts. Government gets twitchy about data going out of the country. You might even find dealing with the courts the mandate IS on prem.

          But I’ve had clients/customers/whatever click on links and have their auth token stolen from the browser, allowed an attacker to come in totally bypassing mfa. I’ve also had customers have their phone number ported away to steal the sms auth. Shit is scary.