profile

Microsoft 365 Management Tips and Tricks

Microsoft 365 Management Tip: How Secure is MFA?

Published about 2 months ago • 2 min read

Hello Reader,

I just returned home from the annual Microsoft MVP Summit and had a great time! Unfortunately, most of what was discussed is under NDA, so I’m not allowed to share it, but I was able to have some good conversations with old friends and new friends, as well as with individuals working on the various products at Microsoft. I’m looking forward to the next several months and what’s coming down the road!


💡A Microsoft 365 Management Tip:

For our Microsoft 365 management tip today, we’re going back once more to Microsoft Entra ID and conditional access. Multifactor Authentication (or MFA) has always been key in securing identities, with Entra ID (or Azure AD) being no exception. However, did you know there are various levels of MFA when it comes to Microsoft Entra ID? There is what I’ll call “standard” MFA, but then there is also the phishing-resistant MFA.

I’ve started recommending that people implement these phishing-resistant MFA prompts, especially when it comes to admin accounts or simply when accessing the various admin portals. This involves requiring Windows Hello for Business, a FIDO2 security key, or Microsoft Entra certificate-based authentication. These methods will help protect against phishing attacks again, especially man-in-the-middle attacks and token stealing.

In fact, Merill Fernando has a great video about this, diving into more details. He also discusses another option: using device compliance to help protect against these phishing attacks.

video preview


Would you like to become the irreplaceable Microsoft 365 resource for your organization? Let me know!


📝 Intelligink Updates


🗞️ Microsoft 365 news highlights

Thank you all, and have a great day!

Ben Stegink

Helping you become a Microsoft 365 Expert!

Microsoft 365 Management Tips and Tricks

We focus on Microsoft 365 and Azure, so you can focus on your job!

Ben is the owner and chief cloud consultant and architect at Intelligink, where he focuses on the Microsoft Cloud – Microsoft 365 and Azure. He is a Microsoft MVP and Microsoft Certified Trainer (MCT) and brings with him 20+ years of experience with SharePoint and 10+ years of experience with Microsoft 365. He is a Certified Azure Solutions Architect Expert, Cybersecurity Architect Expert, and Microsoft 365 Certified: Administrator Expert.

Read more from Microsoft 365 Management Tips and Tricks

Hello Reader, Day 1 of the Microsoft 365 Community Conference in Orlando just wrapped up, and I'm hanging out in my hotel room writing this email. It was a great day of discussing Microsoft 365 with various people in the Ask the Expert room, a couple of keynotes, and just hanging out with old friends and meeting new ones. If you're down here too, and I haven't seen you, let me know! I would love to meet up! 💡A Microsoft 365 Management Tip: 🎉 News from the Microsoft 365 Community Conference in...

8 days ago • 2 min read

Hello Reader, I hope you're doing well and looking forward to this weekend. If you will be at the Microsoft 365 Community Conference in Orlando next week, maybe you're even looking forward to next week more than the weekend? This isn't my usual Microsoft 365 Tips and Tricks newsletter, but one will be delivered right to your inbox next week, maybe even with some "hot off the press news" from the conference. I did want to shoot over a quick email with a couple of late-breaking things this...

14 days ago • 1 min read

Hello Reader, We're getting close to summer (it's sort of already here in Florida...I'm writing this as the kids are swimming in the pool). It's also getting close to the Microsoft 365 Conference in Orland (it's only about two weeks away)! Regardless of whether you're going or not, there will also be some announcements around that time, so keep an eye on the Microsoft blogs at the end of this month! 💡A Microsoft 365 Management Tip: Auditing Exchange Online Mailboxes Auditing Microsoft 365...

21 days ago • 2 min read
Share this post