Forum Discussion
madcat
Apr 18, 2020Copper Contributor
Did I accidentally provision Apple Internet Accounts with my own Azure AD user account
I was adding my O365 email account to my iPhone (Exchange Active-Sync) when I was prompted with the request below. I blindly tapped Accept (yes really should have read the fine print) and realised I ...
- Apr 18, 2020Azure Basic has functionality to keep a tenant secure, but it is, well... basic
First of all, I would recommend turning off User Application consent (like mentioned in the blog I added previously).
Secondly, I would really recommend configuring Multifactor Authentication.
MFA can be configured through two ways: Conditional Access and Security Defaults.
Security Defaults are a free option, check out this blog for more information:
https://365bythijs.be/2019/11/26/what-is-azure-ad-security-defaults-should-you-be-using-it/
I wouldn't worry about MDM and PIM during this time.
If you have configured MFA, you have a good baseline
madcat
Apr 18, 2020Copper Contributor
Thank you so much for your response and the blog links.
Do you think Azure Basic has sufficient functionality to secure our tenant against such threats?
We are only on Office 365 Essentials and trying to minimise costs at this difficult time (COVID) but I keep coming across documentation about elements such as conditional access policies, MDM, PIM etc. and wonder if they are necessary even for a small business.
Thijs Lecomte
Apr 18, 2020Bronze Contributor
Azure Basic has functionality to keep a tenant secure, but it is, well... basic
First of all, I would recommend turning off User Application consent (like mentioned in the blog I added previously).
Secondly, I would really recommend configuring Multifactor Authentication.
MFA can be configured through two ways: Conditional Access and Security Defaults.
Security Defaults are a free option, check out this blog for more information:
https://365bythijs.be/2019/11/26/what-is-azure-ad-security-defaults-should-you-be-using-it/
I wouldn't worry about MDM and PIM during this time.
If you have configured MFA, you have a good baseline
First of all, I would recommend turning off User Application consent (like mentioned in the blog I added previously).
Secondly, I would really recommend configuring Multifactor Authentication.
MFA can be configured through two ways: Conditional Access and Security Defaults.
Security Defaults are a free option, check out this blog for more information:
https://365bythijs.be/2019/11/26/what-is-azure-ad-security-defaults-should-you-be-using-it/
I wouldn't worry about MDM and PIM during this time.
If you have configured MFA, you have a good baseline
- AmJassimOct 14, 2020Copper ContributorSo a GA user granted consent (admin consent) but the app isn’t showing under enterprise apps (or app registration), any ideas?
Can we allow certain users or groups to be able to do that? - madcatApr 18, 2020Copper Contributor
Thank you so much for your time your responses have been invaluable.