User Profile
fabs73514
Copper Contributor
Joined 5 years ago
User Widgets
Recent Discussions
Re: Require MFA for AAD Hybrid joined devices
OECM_SupportUsing this logic, you also have the same problem if a smartphone is stolen and the PIN (which is even easier than a strong password) is known. The attacker would then have access to the MFA app and all M365 passwords, which are probably stored in the device's password manager. I would put the likelihood of someone stealing a smartphone and finding out the PIN higher than someone stealing the computer. The moral of the story: users can lose either a device or its password without being hacked right away. But once they lose both at the same time, there's a real security problem. It would be best to instruct users not to write passwords on a sticker on the device :).13KViews1like0Comments
Recent Blog Articles
No content to show