Entra MFA
Last updated:
AZUREENTRA
- Passwords on their own are bad
- MFA is from [[202404011414 Authentication and Authorization]] 2 or more items
- I know
- I have
- I am
- Example:
- Password + SMS/Phone
- Password + Auth app
- You want to prompt sparingly otherwise it becomes muscle memory and they don’t read the message/ they will keep saying yes
- Requires P1 license or use Security defaults (Ideally want to use conditional access if you don’t have P1) or global admin
Authentication context and number matching
- In auth app, shows location and asks to enter the number
- not phishing attack proof
Phishing resistant
Provided by machine so considered phishing resistant
- Hello for business
- FIDO2
- CBA (Certificate based authentication)
Passwordless
Above 3 + MFA app.
Temporary access pass
For new users/to bootstrap onboarding