Learn Conditional Access in just 25 Mins

Поділитися
Вставка
  • Опубліковано 1 жов 2024

КОМЕНТАРІ • 51

  • @brandonw1604
    @brandonw1604 Рік тому +5

    With IPv6 you want to make sure you allow unnamed locations. IPv6 doesn't always give a location and you can accidentally lock out your CEO from the calendar when he's trying to plan his mother's funeral.

    • @BloomerzUK
      @BloomerzUK Рік тому +5

      Your comment made me laugh

    • @brandonw1604
      @brandonw1604 Рік тому +1

      @@BloomerzUK it wasn't a call I wanted at 6AM on a Sunday. Lol lesson never forgotten.

    • @BloomerzUK
      @BloomerzUK Рік тому +1

      @@brandonw1604 I thought you were joking.. you poor sod!

    • @brandonw1604
      @brandonw1604 Рік тому

      @@BloomerzUK nope, didn't know about IPv6 and locations.

    • @marcusm5127
      @marcusm5127 6 місяців тому

      Odly specific. Poor guy I wouln't want that call.

  • @AlBergstein
    @AlBergstein 6 місяців тому

    Just a mention: User Risk and Sign In Risk require P2 licensing. Many NGOs that I handle do not get that in their licensing. Conditional access appears with P1 licensing which my NGOs apparently all have by default. (sigh)

    • @AndyMaloneMVP
      @AndyMaloneMVP  6 місяців тому

      You’re right identity protection requires P2 conditional access P1

  • @audiodiwhy2195
    @audiodiwhy2195 2 місяці тому

    User interface at Entra has changed (of course). Still a good video.

  • @volkersahm
    @volkersahm Місяць тому

    well done. I want to suggest a more practical approach with examples in a real environment and with a specific set of policies that are basic best practice. not only showing the admin portal but also show a real result on a device. also a minimum security setup with a set of policies and settings would be nice as example. also we want to copy and paste a basic set of policies and settings from one tenant to another, to have best practice minimal settings for all clients. maybe one or more of those suggestions will lead to an update video on this neat features...thanks!

    • @AndyMaloneMVP
      @AndyMaloneMVP  Місяць тому

      Absolutely, come on one of my courses and I’ll show you

  • @alvarogomez5458
    @alvarogomez5458 5 місяців тому

    Hello, I just found your video.. it is really interesting and helpful, it solved a lot of my questions, I was recently tasked to use conditional access to block access to onedrive on non company devices, any ideas on how to block one drive only?

    • @AndyMaloneMVP
      @AndyMaloneMVP  5 місяців тому

      Look at the OneDrive settings in the sharepoint admin centre

  • @Abayomi-Munatech
    @Abayomi-Munatech Рік тому +1

    Pls,How can I get train from you?
    Thanks

    • @AndyMaloneMVP
      @AndyMaloneMVP  Рік тому

      Pay me lots of money🤣😂🤗

    • @Abayomi-Munatech
      @Abayomi-Munatech Рік тому

      @@AndyMaloneMVP I'm ready pls

    • @AndyMaloneMVP
      @AndyMaloneMVP  Рік тому

      @@Abayomi-Munatech please send me an email via my UA-cam channel or LinkedIn giving me details of where your located and what training your looking for. My schedule is very busy but I can see if I can fit you in.

  • @kareemck9479
    @kareemck9479 Місяць тому

    Thanks for the vedio.
    Could you please let me know what would be the ideal way to configure a policy if i wants to block all the countries and only allow users to login from the country where our office resides
    I know we can simply create this using named location and CA
    But what if any of my users travelling and i need to give them access to those countries as well.(only that user) i also dont want that user to get access to any other country than where she is travelling and office locations
    I tried multiple ways of creating polcies , but none seems to be fitting in.
    Some or the other flaws
    Can you please help me here

    • @AndyMaloneMVP
      @AndyMaloneMVP  Місяць тому

      I would probably create an allow only list which blocks all other countries using location based conditional access. For documentation on this please visit learn.microsoft.com or post a question to the Microsoft tech community 😊

    • @kareemck9479
      @kareemck9479 Місяць тому

      @@AndyMaloneMVPi beleive u probably misuderstood my question
      I will give you an example. My office resides in india. So i created a names location named office location and selected india .
      Created a policy excluding office location i.e india . Included any location . Grant acess block for all users.
      Now for eg if my CEO is travelling to UK , i want to allow him to login to all apps from india as well as UK. So if i exclude him from the main policy , he would be able to login from anywhere. But i only want him to login from uk and india.
      Secondly if i exclude him from main policy and create a new names location travel country and add UK. And create a new CA policy adding only my CEO and blocking any location excluding travel country.
      Would he be able to login only from uk or india and uk??
      Secondly everytime when user travels we have to add them to secuity group and remove later which is a lot manual work
      So what would you suggest
      You help would be much appreciated .
      Thanks again for the swift response

  • @soodshubham7671
    @soodshubham7671 Рік тому +1

    Andy, thank you sincerely for sharing such valuable knowledge. I genuinely appreciate it. I hope that one day, I will have the opportunity to meet you in person and express my gratitude personally :)

    • @AndyMaloneMVP
      @AndyMaloneMVP  Рік тому +1

      Aw that is so kind, thank you so much. I really do appreciate that 😊 and 👍

  • @MichaelToub
    @MichaelToub 4 місяці тому +1

    Great Video!

  • @moepskie
    @moepskie Рік тому

    Regarding the warning about the legacy authentication clients: disable legacy authentication by default (it's a recommendation documented by Microsoft somewhere). Either set a CA policy to block it entirely, or disable it through the Admin center (or both).

  • @Best111
    @Best111 4 місяці тому

    Great Videos! You Add a new Subscriber

  • @markokoning6697
    @markokoning6697 5 місяців тому

    Thanks alot Andy,
    a very informative video Thank you!

  • @richarddstephens
    @richarddstephens Рік тому

    Love your content. Been following for a while now. Question for you on MFA/CA policies. As an admin, my phone screen went out on me, leaving me basically without a phone. Couldn't receive calls or texts which is what my MFA was configured for. What's the best way to configure myself so that if I'm ever in this situation again, I can still authenticate and access M365?

    • @AndyMaloneMVP
      @AndyMaloneMVP  Рік тому

      This is easy. Go into Microsoft 365 and go into the users account. There is an option to reinforce MFA. This will then force the user to repeat the MFA registration process. It’s well documented, learn.microsoft.com. Good luck

  • @rollover36
    @rollover36 Рік тому

    Excelent vifdeo, 1.25 speed is the sweet spot for me but I appreciate the original speed

  • @sethb.9601
    @sethb.9601 Рік тому

    I don't have that many options under protect & secure, just authenticaton methods and password reset. How do I unlock conditional access?

  • @patrick__007
    @patrick__007 Рік тому

    You can now add some M365 admin portal in the CA. Thanks Andy!

    • @AndyMaloneMVP
      @AndyMaloneMVP  Рік тому +1

      You are quite correct, you always could👍

  • @patrick__007
    @patrick__007 Рік тому

    Perhaps for an future update on CA with Windows Defender Cloud for Apps?

    • @AndyMaloneMVP
      @AndyMaloneMVP  Рік тому

      If you take a look in my Microsoft defender and Microsoft per view playlists, there are sessions on cloud apps here that explain everything

  • @TN_HondaDad
    @TN_HondaDad Рік тому

    A great quick crash course, thank you!

  • @RameshKotha-n1r
    @RameshKotha-n1r 2 місяці тому

    Great explanation

  • @ManoElMacho
    @ManoElMacho 9 місяців тому

    well done mate :)

  • @mkelly01
    @mkelly01 Рік тому

    Perfect timing. I was just coming to your channel looking for info on this!

    • @AndyMaloneMVP
      @AndyMaloneMVP  Рік тому

      Hey that’s awesome😊I hope you’ll subscribe 👍

  • @moazzammahmood
    @moazzammahmood Рік тому

    Great video very informative Thanks!!!!

  • @millicentwright9359
    @millicentwright9359 Рік тому

    😞 Promo>SM

  • @DoubleA-ARon
    @DoubleA-ARon Рік тому

    Andy, as always, excellent content!

  • @MBudhwant
    @MBudhwant Рік тому

    Very helpful

  • @sreenathchandrakandham5309
    @sreenathchandrakandham5309 7 місяців тому

    Great learning, thank you

  • @edipocdf
    @edipocdf Рік тому

    tks a lot.

    • @AndyMaloneMVP
      @AndyMaloneMVP  Рік тому

      Hey thanks so much I appreciate that👍🤗😊