@@DhavalBrahmbhatt2627 it’s “continuous access evaluation” my bad on the incorrect name. Conditions you include everything but mobile since they would be prompted every time they get a new IP on cellular. Session is set to “Use continuous access evaluation” Hope that helps direct
@Jonathan Edwards. A nice bunch conditional access policies. My understanding is that the device platform filter only looks at the device string as reported by the device. This can be spoofed. A better control for managed devices are device filters. e.g. Where the device platform is not a managed Windows device, require an app protection policy.
As always very informative! Though I've some questions about 2FA. 1. What will be the impact for users when disabling SMS from Entra when they've already enabled/using SMS using the Per user MFA? 2. Do you need to disable Per user MFA when 2FA forced using a CA? 3. You've excluded the Admin from any CA. How would you enforce 2FA for this one? Greetings from overseas, the Netherlands.
Hi to the Netherlands! Firstly, it’s all about communication. This video was easy for me because it’s a test tenant with no real users 😀 Within Entra, you can see which users are using which form of 2FA, so you can contact those users who are using SMS and get them to convert. The Microsoft documentation says that you need to disable MFA on each user account in the 365 portal. I have also seen some powershell scripts which do the same thing. The recommendation for admin. Have two admin accounts. One is part of the CA policy which has MFA enabled. The second admin account is known as the ‘break glass’, it has no MFA but a really long and complex password. We set these to be about 30 characters. Hope that helps.
Great Vid. Was wondering if you could do a video on Intune device licenses. There is practically no info out there on this. Specifically enrolling Win10/11 devices using Intune device licenses for shared workstations? What are the best ways to do this? What are the limitations? Lots of businesses use shared workstations for healthcare or factory workers that use the same workstations when on shift as others. We want them in Intune without paying per user license. Thanks!
@Jonathan Edwards. Thanks for the knowledge. On which M365 service do we test/validate the 'Disable persistent browser session' after setting up the Conditional Access Policy?
Amesing explanation. Question, do I need to assign an Entra P1 license for each user in my organization if I want to implement those essential security policies?
Good question! Microsoft Licensing says - yes, each user should have a license. But it will let you use the policies even if there is just one license in the tenant. I always try to be honest and add the licenses.
In the Entra ID Conditional Access -> Policies -> new Policy settings there is now "Newtwork" do we need to change anything there for any of these policies you are creating? And when you do the exclusion for CA02 if the we are on P1 license with Business Standard will this work or do we need to add a different set of options?
@@bearded365guy Thank you ! you're the best! I've been in IT for 30 years and I've only been working on security issues at Microsoft for a few months (which I didn't know anything about) and your videos are extremely helpful!
Brilliant Video, thank you so much. With CA01 do you turn this on after you have communicated to everyone to download the App and set it up? If you have users working all over the world is it still good to set up CA02?
What is the minimum licensing required to enable conditional access (365 business premium?) ? And what if you have a mixed licensing environment? Do policies apply to basic users if setup ?
Copilot tells me the basic users wouldn’t be evaluated against the policies due to not being licensed, so essentially any MFA or geo blocking policy for all users would not apply to them. To me this also become a bigger problem if you’re using sensitivity labels, where those labels do not apply to basic users so as long as they can access the document any encryption or sharing restrictions would not apply to that basic plan user
For the whitelisting countries bit, when you filter to compliant devices outside of approved counties, would approved apps (like Outlook or Teams) on unmanaged iPhones still work?
I guess we could scope the allowed countries policy to Windows / Mac devices then use app protection policies to lock down the iOS / android devices differently.
Thanks again Jonathan! The video I've been waiting for. Question, for those already enrolled in SMS/Phone call MFA, once you enable/enforce these policies, what happens? Will they be prompted/forced to enroll or change their MFA method to using the MS Authenticator?
Place you mentioned not recommended to use Microsoft authenticator app ? I don’t know how the authentication will the work without the app or MSS ? Please if hacker use VPN, for UK can he success pass the location policy?
Hi do i need the license Microsoft 365 Premium for all users so that the Conditional Access to take effect or I just need to assign Premium license to Global Admin and others user can still use Basic and Standard license?
There is a license loop hole that means you just need one Business premium license in the tenant. With our clients, we always license each user properly for what features they’ll be using.
Firstly love the videos thanks so much learnt a bunch. Set this up as a lab. I had issues launching outlook and any other app. I wasn’t sure how to configure the intube app policy for mobile and desktop. I watched the other vid but it still just kept looping for login credentials.
@@bearded365guy Hey Johnathan! Yes, I excluded myself from the policy and gained access. The config wasn't complete, I couldn't set the intune app policy.
At the start of the video you created a conditional access policy requiring MFA for all users. Why is a second policy required MFA for Entra join. Isn't that redundant? Great video, Thanks!
I just wanted to join the group and let you know that your videos are amazing. Straight to the point and very informative. Due to this video, I created a little script in PowerShell using Microsoft Graph that will configure all these conditional access policies and one more that block access to all Azure Admin Portals. I just want to share the script as a little contribution to all the effort and good things that you put on your videos. What is the best way to share it? Thanks again for all your good work
Did exactly like you on CA02 : Block access from other countries, whitelisted the countrie we work in, but i had a case yesterday when someone traveled to Spain, he was not able to login, yet Intune says his laptop is compaint, any Ideas? When i go to sign in logs, CA02 did block them, 2 of them had the same issue.
Does the order matter with these policies? I kind of have a few basic general purpose CA policies and a few I want for special cases. Do I put the special cases first or last or does the order not matter and I have fiddle with exclusions for each policy to stop one of them stomping on the others where it shouldn't? Also, for licencing purposes, if I set up a 'break-glass' admin account, do I need to have a Business Premium licence attached to it or will one with no licenses be acceptable (providing that is literally its only purpose)? Any technical pros or cons for doing it this way?
No, the order doesn’t matter. It just has to make sense to you or whoever is administering the system. I think the advice is that any admin accounts shouldn’t have a license attached at all.
Great video but there are plenty of dangers associated with many of these which i think need mentioning. For example blocking legacy applications could have many negative side effects especially in a large tenant running in hybrid mode with ad connect back to a sizeable mature on prem environment. There would need to be an audit phase to identify the effect. Is there a way to test an environment for side effects? Sadly not many 365/Azure environments are ‘blue sky’ and therefore will likely be legacy apps.
I'm interested to know the major ramifications of staying with Business Standard for most business around 10 endpoints. Unless controlling endpoints with Intune and really locking them down are they not still safe with Standard if MFA is enforced on all users?
I'd also recommend creating a Continuous Access Policy to require MFA if the network changes. This helps protecting against session token theft
Yep, another good one.
Can you provide any details on how to go about accomplishing this? Sounds like a useful policy to implement.
Anyone have an idea of how to setup the policy these guys are talking about?
Pls provide details, been dying to set something like that up but can't figure it out.
@@DhavalBrahmbhatt2627 it’s “continuous access evaluation” my bad on the incorrect name.
Conditions you include everything but mobile since they would be prompted every time they get a new IP on cellular.
Session is set to “Use continuous access evaluation”
Hope that helps direct
@Jonathan Edwards. A nice bunch conditional access policies. My understanding is that the device platform filter only looks at the device string as reported by the device. This can be spoofed. A better control for managed devices are device filters. e.g. Where the device platform is not a managed Windows device, require an app protection policy.
Thanks, Jonathan - what a great overview! I cannot stress enough the importance of implementing these important controls in your tenant. well done!
Thank you 🙏
Thanks Jonahan, I like your straight forward communication style.
Thank you
I work supporting 365 and i love your videos. Thanks!
Thanks Jonathan, this insight was really helpful. May I know what license type is required to create new policies?
Business Premium
As always very informative!
Though I've some questions about 2FA.
1. What will be the impact for users when disabling SMS from Entra when they've already enabled/using SMS using the Per user MFA?
2. Do you need to disable Per user MFA when 2FA forced using a CA?
3. You've excluded the Admin from any CA. How would you enforce 2FA for this one?
Greetings from overseas, the Netherlands.
Hi to the Netherlands!
Firstly, it’s all about communication. This video was easy for me because it’s a test tenant with no real users 😀
Within Entra, you can see which users are using which form of 2FA, so you can contact those users who are using SMS and get them to convert.
The Microsoft documentation says that you need to disable MFA on each user account in the 365 portal. I have also seen some powershell scripts which do the same thing.
The recommendation for admin. Have two admin accounts. One is part of the CA policy which has MFA enabled. The second admin account is known as the ‘break glass’, it has no MFA but a really long and complex password. We set these to be about 30 characters.
Hope that helps.
@@bearded365guy1:16
You are good at explaining this stuff. I already know some of this but doesnt hurt to check again.
Great Vid. Was wondering if you could do a video on Intune device licenses. There is practically no info out there on this. Specifically enrolling Win10/11 devices using Intune device licenses for shared workstations? What are the best ways to do this? What are the limitations? Lots of businesses use shared workstations for healthcare or factory workers that use the same workstations when on shift as others. We want them in Intune without paying per user license. Thanks!
I’ll be doing some of these videos very soon
This is fantastic. thanks so much for putting this together.
Thank you for this video! Really great insight to the CA policies and really set a great foundation for me! Love what you're doing!
Thanks!
you would'nt believe how many dont do any of this! very helpful
Brilliant. No BS. straight to the point.
@Jonathan Edwards. Thanks for the knowledge. On which M365 service do we test/validate the 'Disable persistent browser session' after setting up the Conditional Access Policy?
Is it possible to disable external guest downloads of OneDrive shared files via CA? Thank you.
Yes it is.
@@bearded365guy Could you please show me a video you made before about it or the options I need to select to make it work? Thank you.
I’ll be making one soon
Amesing explanation. Question, do I need to assign an Entra P1 license for each user in my organization if I want to implement those essential security policies?
Good question! Microsoft Licensing says - yes, each user should have a license. But it will let you use the policies even if there is just one license in the tenant. I always try to be honest and add the licenses.
@@bearded365guyHonesty, esp for Global Admins, is always the best policy.
In the Entra ID Conditional Access -> Policies -> new Policy settings there is now "Newtwork" do we need to change anything there for any of these policies you are creating?
And when you do the exclusion for CA02 if the we are on P1 license with Business Standard will this work or do we need to add a different set of options?
Thankt!!! Great video !
And what do I do with the scanner email and the MFA? without using a gmail (I have already seen your other video)
You could exclude from MFA policy. Or… add an IP address in trusted MFA. I didn’t show it on video, but it’s on same screen as approved countries
@@bearded365guy Thank you ! you're the best! I've been in IT for 30 years and I've only been working on security issues at Microsoft for a few months (which I didn't know anything about) and your videos are extremely helpful!
Brilliant Video, thank you so much. With CA01 do you turn this on after you have communicated to everyone to download the App and set it up? If you have users working all over the world is it still good to set up CA02?
What is the minimum licensing required to enable conditional access (365 business premium?) ? And what if you have a mixed licensing environment? Do policies apply to basic users if setup ?
Copilot tells me the basic users wouldn’t be evaluated against the policies due to not being licensed, so essentially any MFA or geo blocking policy for all users would not apply to them.
To me this also become a bigger problem if you’re using sensitivity labels, where those labels do not apply to basic users so as long as they can access the document any encryption or sharing restrictions would not apply to that basic plan user
Business Premium.
@14:24 - can we just create a policy for each of the templates and be secured ????
Another great video! Too many organisations rely on Microsoft Baseline or defaults
I want to disable access outside my Virtual desktop Workspace i tried to ip block but not able to see public range
For the whitelisting countries bit, when you filter to compliant devices outside of approved counties, would approved apps (like Outlook or Teams) on unmanaged iPhones still work?
No, what we’d also need to do is actually manage the smartphones in MDM, rather than app protection
I guess we could scope the allowed countries policy to Windows / Mac devices then use app protection policies to lock down the iOS / android devices differently.
Thanks again Jonathan! The video I've been waiting for. Question, for those already enrolled in SMS/Phone call MFA, once you enable/enforce these policies, what happens? Will they be prompted/forced to enroll or change their MFA method to using the MS Authenticator?
If we disable those ways to authenticate, then yes
Place you mentioned not recommended to use Microsoft authenticator app ? I don’t know how the authentication will the work without the app or MSS ?
Please if hacker use VPN, for UK can he success pass the location policy?
The authenticator app is OK for MFA, SMS less so.
@@bearded365guy
Thank you, what about my question about VPN ?
Hey Jonathan, how you doing my friend? My name is Marcelo, I'm from Brazil and you videos are super helpfull! Thank you so much for your work! 😊👍
Thank you
Hi do i need the license Microsoft 365 Premium for all users so that the Conditional Access to take effect or I just need to assign Premium license to Global Admin and others user can still use Basic and Standard license?
There is a license loop hole that means you just need one Business premium license in the tenant. With our clients, we always license each user properly for what features they’ll be using.
@@bearded365guy thank you very much, that helps alot.
Firstly love the videos thanks so much learnt a bunch.
Set this up as a lab. I had issues launching outlook and any other app. I wasn’t sure how to configure the intube app policy for mobile and desktop. I watched the other vid but it still just kept looping for login credentials.
Can you access if you disable the app protection conditional access policy?
@@bearded365guy Hey Johnathan! Yes, I excluded myself from the policy and gained access. The config wasn't complete, I couldn't set the intune app policy.
Thanks for Knowledge sharing. Very informative 👍
Thank you Jonathan, this will help me secure the tenants of my customers.
Good luck Jimmy
At the start of the video you created a conditional access policy requiring MFA for all users. Why is a second policy required MFA for Entra join. Isn't that redundant? Great video, Thanks!
The second policy is specifically to join devices to Entra
I just wanted to join the group and let you know that your videos are amazing. Straight to the point and very informative. Due to this video, I created a little script in PowerShell using Microsoft Graph that will configure all these conditional access policies and one more that block access to all Azure Admin Portals. I just want to share the script as a little contribution to all the effort and good things that you put on your videos. What is the best way to share it? Thanks again for all your good work
That’s fantastic. Can you send me a link to jonathan@integral-it.co.uk and I’ll share it on the channel somehow
@@bearded365guy I would love to see that powershell
I love these. Do you have more videos of these policies? tips/tricks and why its good to use them?
@@JuanDiazSilvermyst There is just what is on my channel at the moment.
Did exactly like you on CA02 : Block access from other countries, whitelisted the countrie we work in, but i had a case yesterday when someone traveled to Spain, he was not able to login, yet Intune says his laptop is compaint, any Ideas? When i go to sign in logs, CA02 did block them, 2 of them had the same issue.
What device were they using? Laptops? Phones?
@@bearded365guy laptops
@@bearded365guy laptops, when i whitelisted spain, all was good
@@bearded365guy Laptops, after i whitelisted Spain, all was good.
@@bearded365guy Laptops, after i whitelisted Spain all was good!
Very straightforward. I love it ♥
Thanks!!! 💯
Great video, already had some of these set up but others were missing. It was a very easy video to follow, cheers!
loved this video thanks looking forward for more such videos
Which Entra ID do you have for this video? P1 or P2?
P1 is ok.
Does the order matter with these policies? I kind of have a few basic general purpose CA policies and a few I want for special cases. Do I put the special cases first or last or does the order not matter and I have fiddle with exclusions for each policy to stop one of them stomping on the others where it shouldn't?
Also, for licencing purposes, if I set up a 'break-glass' admin account, do I need to have a Business Premium licence attached to it or will one with no licenses be acceptable (providing that is literally its only purpose)? Any technical pros or cons for doing it this way?
No, the order doesn’t matter. It just has to make sense to you or whoever is administering the system.
I think the advice is that any admin accounts shouldn’t have a license attached at all.
Thank you SO MUCH.
Great video but there are plenty of dangers associated with many of these which i think need mentioning. For example blocking legacy applications could have many negative side effects especially in a large tenant running in hybrid mode with ad connect back to a sizeable mature on prem environment. There would need to be an audit phase to identify the effect. Is there a way to test an environment for side effects? Sadly not many 365/Azure environments are ‘blue sky’ and therefore will likely be legacy apps.
Yes, using the “Report Only” mode is helpful for an audit period like that.
If I am using Business Standard this doesn't apply to me and I'm not secured, correct?
I'm interested to know the major ramifications of staying with Business Standard for most business around 10 endpoints. Unless controlling endpoints with Intune and really locking them down are they not still safe with Standard if MFA is enforced on all users?
Some great tips here!
thanks for sharing
thank you so much the content is excellent and helps a lot
Great vid. Speaking of global admin, how about a video talking about how to manage/removing local admin privileges on workstations?
Stay tuned….
Well done Jonathan, loves all your videos. thanks
If I have MFA enabled, I cannot setup our software to send emails. It is a housing software that emails our tenants.
That’s worrying. I would speak to the software company about that…. It’s 2024!
Very helpful video!
Great video, Thanks!
very helpful,,thanks a lot sir
Only can say... brilliant
PERFECT VIDEO !
Great video ! Thanks!
Thanks for the video
Jonathan you are a God sent!
Thank you so much for these great videos! 🙏🙏🙏
Nice videos
beautiful
Dude. I love you.
GREAT VIDEO
I'm professional thumbnail designer on fiver I really want to design your thumbnails more eye catching
Thanks for your comment. But we’re ok
@@bearded365guy I really want to design your thumbnails dear sir only in $10 in 1 hour
@@bearded365guy can give you in 1 hour let's try my example thumbnail for free