Not just anyone has this
If you've set up a Microsoft environment in your company, you almost certainly have the admin side configured too.
If you've set up a Microsoft environment in your company, you almost certainly have the admin side configured too. But it's unlikely you have everything set up — and even less likely that everything you do have is set up correctly, because nobody does. In today's article I'll introduce a few interesting settings that should help you secure the company.
Where do I start?
First, find out which licences you actually have. Business Basic gives you fairly limited options for any deep security work, but you can still do something. Business Premium is where the "fun" begins — it unlocks, among other things, CAP (Conditional Access Policies), which give you direct control over who can sign in, where, how, into what, and what they need to do it.
What should I watch out for?
A really, really important thing: with CAP you can "lock yourself out" (block your own access to the admin environment). So ALWAYS create a so-called break-glass account that's exempt from every CAP! Also, when implementing a new CAP, set it to Report Only — at least for the first few days.
I have Premium — where do I start?
The first thing is creating a CAP for administrators. For these I always recommend setting MFA as required and a sign-in lifetime of max 24h (more like 8h). The same for Azure management (Microsoft has rebuilt templates for this). Then it's a good idea to block Legacy Authentication and require MFA for all users.
I have CAPs — what's next?
From there the sky's the limit, but it's worth heading into Intune and, on top of standard Compliance Policies, looking at filters too. They actually work well today.
This is too much for me.
Don't blame you. That's why people like us exist! If you're stuck configuring your Microsoft environment, book a free no-obligation 30-minute meeting with us HERE.