Forum Discussion
Jason_Benway
Jan 08, 2020Copper Contributor
End users setting up MFA for the first time. Experience and security?
We are working on a plan to force MFA for none trusted IPs. But most of our users have not setup MFA yet. I'm concerned the setup process isn't simple enough and thinking about risk. How do you allow...
Jason_Benway
Jan 08, 2020Copper Contributor
Sorry I wasn't clear.
Our concern it when I user is going to setup MFA for the first time, if they do it themselves. How do you know its them setting it up?
That seems like a risk. Your enabling MFA to reduce risk and add security but you only have username/password when your first setting up MFA to confirm its them.
it would be better if I could use CA when setting the user sets up MFA to require the user to be on a trusted network or on a managed device.
Our concern it when I user is going to setup MFA for the first time, if they do it themselves. How do you know its them setting it up?
That seems like a risk. Your enabling MFA to reduce risk and add security but you only have username/password when your first setting up MFA to confirm its them.
it would be better if I could use CA when setting the user sets up MFA to require the user to be on a trusted network or on a managed device.
VasilMichev
Jan 08, 2020MVP
We can already do this: https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-registration-mfa-sspr-combined#create-a-policy-to-require-registration-from-a-trusted-location
- JonasBackJan 08, 2020Iron ContributorThis is also usually how we set it up, only allow MFA Registration from our own IPs or at least the countries we are active in.