Forum Discussion

dario_r's avatar
dario_r
Copper Contributor
Apr 10, 2019

MCAS pre and post authentication

Hi guys,

I've got a couple of questions related to the authentication flow and when MCAS takes actions:
1. As far as I understand, all the proxy sessions get applied AFTER the user authentication and AFTER the Conditional Access policies: is this correct?
2. Is there any scenario where MCAS can do actions (policies, alarms, etc...) before the user authentication? If not, is it correct to assume that to use MCAS the users must be logged to Azure AD?

Many thanks,
Dario

7 Replies

  • Hi Dario,

     

    1. Correct. MCAS apply the session controls after authentication and initial risk assessment of the session.

    2. Is there a specific pre-authentication scenario you have in mind?
    In general, as a CASB, MCAS focus on the user activity within the apps, hence, after the authentication.

     

    Thanks,

    Niv

      • Niv Goldenberg's avatar
        Niv Goldenberg
        Former Employee

        The pre-authentication controls you can use are the control provided by AAD. 

    • dario_r's avatar
      dario_r
      Copper Contributor

      Hi Niv,

      First of all, thanks for the answer.

       

      Related to point 2, I would like to know which are the controls or the capabilities I can use pre-authentication. 

       

      Thanks,

      Dario