Your MFA Is On. Is It Actually Covering You?
MFA can be switched on and still fail the test that matters. Learn how phishing-resistant MFA, token protection, risk-based controls, and provable evidence separate “on” from truly covered.
Use to show article snippet on Know the Security Risks page.
MFA can be switched on and still fail the test that matters. Learn how phishing-resistant MFA, token protection, risk-based controls, and provable evidence separate “on” from truly covered.
The registration step most people skip Turning on multi-factor authentication feels like the job is finished. For almost every account, it is.
For the security leader who owns the risk Somewhere in your files is a form with your name on it. An insurance application, a customer questionnaire, a board attestation. One line says MFA is enforced.
A Conditional Access exclusion is any user, group, role, or app you leave out of a policy, so that policy’s control doesn’t apply to them.
Picture it. It’s a Tuesday. A good client is on the line and their voice is a little off. “Quick question. Why did your bank details change on the last invoice?” You didn’t change anything. That’s the moment it lands.
LDAP security is three separate jobs: encrypt the connection, strengthen the authentication method, and secure the account. Enabling LDAPS completes only the first job.
Cleartext or unsigned LDAP simple binds expose reusable passwords. Event IDs 2887 and 2889 identify the affected volume, clients, and accounts before enforcement.
SASL with Kerberos replaces a reusable LDAP password with a short-lived ticket. Signing and channel binding then protect that authentication from tampering and relay.
gMSA and dMSA reduce service-account risk through automatic password management and machine-bound use. They still require protected LDAP transport and least privilege.
A complete LDAP migration starts with auditing, then secures the channel, bind, and account before enforcing signing and channel binding and validating the result.