User Profile
araujotech
MVP
Joined 9 years ago
User Widgets
Recent Discussions
Re: Issues with setting up AiTM phish prevention using conditional access
AlexShxW1 Hi Alex, Register one the these methods: Windows Hello for Business or FIDO2 Security Key or Azure AD CBA Certificate-Based Authentication (Multi-Factor) Then you should choose Require Authentication Strength, and choose Phishing-resistant MFA. As an alternative option, you may Require Hybrid Azure AD Joined Device or Require device to be marked as compliant (this will require Intune, and intune will use a certificate to authenticate the device). Before creating a policy requiring phishing-resistant multifactor authentication, ensure your administrators have the appropriate methods registered. If you enable this policy without completing this step you risk locking yourself out of your tenant. Reference: https://learn.microsoft.com/en-us/azure/active-directory/authentication/concept-authentication-strengths https://learn.microsoft.com/en-us/azure/active-directory/authentication/concept-authentication-strengths2.3KViews0likes1Comment