MFA That Works Every Time
The registration step most people skip Turning on multi-factor authentication feels like the job is finished. For almost every account, it is.
The registration step most people skip Turning on multi-factor authentication feels like the job is finished. For almost every account, it is.
A conditional access policy is the rule in Microsoft Entra that decides who gets in, to what, under which conditions, and what they must prove first.
For the security leader who owns the risk Somewhere in your files is a form with your name on it. An insurance application, a customer questionnaire, a board attestation. One line says MFA is enforced.
You get the ticket. A user’s blocked and they need in now. You open the policy that caught them, and it’s doing five things at once.
In cybersecurity hiring, two signals mislead us. A certificate proves someone studied, and tenure proves they showed up for years. Neither proves craft, the skill to apply the work when an incident goes off-script.
A Conditional Access exclusion is any user, group, role, or app you leave out of a policy, so that policy’s control doesn’t apply to them.
Conditional Access is Microsoft Entra’s policy engine for sign-in decisions. It gathers signals about a sign-in, who it is, what app, what device, where from, how risky, then matches them against your rules and enforces…
A USB storage block targets mass-storage devices. FIDO2 security keys use the Human Interface Device protocol, so they require separate endpoint and Entra ID policy design.
Most MFA registration problems are not really MFA problems. One user is brand new and needs to register their first method. Another already has MFA, Windows Hello for Business, FIDO2, etc. and just wants to update…
Are business users still relying on insecure authentication methods like SMS, voice calls, or email one-time passwords? At DTS, we strongly recommend moving away from these vulnerable options toward stronger, more secure methods that meet the…