Search for: conditional access policies

181 Results

Why Separate Microsoft 365 Administrator Accounts are Critical to Security Posture

There’s a lot of debate around the need to separate Microsoft 365 administrator accounts, especially when controls such as Privileged Identity Management exist within an organization. However, even with PIM there are remaining security concerns which necessitate the operation of separate accounts. This article explains the importance of using separate accounts; details how to target different Conditional Access policies for admin and user accounts and highlights how this approach increases your security posture and limits potential attack vectors against administrator accounts.

Continue Reading Why Separate Microsoft 365 Administrator Accounts are Critical to Security Posture

Lifeline or Liability: Managing Emergency Accounts in Hybrid Environments

In this blog, we explore why break-glass accounts are your lifeline when identity systems fail. Microsoft’s updated guidance calls for two cloud-only Entra ID accounts with phishing-resistant MFA and restricted AD Administrator accounts limited to domain controllers. Excluding them from Conditional Access, storing credentials offline, and testing regularly ensures your emergency access is a lifeline — not a liability.

Continue Reading Lifeline or Liability: Managing Emergency Accounts in Hybrid Environments

Entra Agents are Promising but Could do More

Microsoft's Alex Simons came to the TEC 2025 conference to talk about the future of Entra ID, a lot of which hangs on the use of AI in components like the Entra agents that are now in preview. The idea of using agents to relieve hard-pressed human administrators is great, but only if those agents do more than a skilled human administrator can do, and that's not the case so far.

Continue Reading Entra Agents are Promising but Could do More

Practical Protection: Controlling OneDrive Personal Sync

In this installment of Practical Protection, we look at Microsoft’s new OneDrive feature that prompts users to sync personal accounts on managed devices. While intended to reduce shadow IT, it risks exposing corporate data. With no option for admins to opt-out, we provide some advice on what you should do to prepare.

Continue Reading Practical Protection: Controlling OneDrive Personal Sync