FB pixel

Microsoft makes MFA mandatory for Azure sign-ins

Microsoft makes MFA mandatory for Azure sign-ins
 

In response to the escalating threat of cyberattacks, Microsoft has made multi-factor authentication (MFA) mandatory for Azure sign-ins. Through its Secure Future Initiative, the company states its focus on safeguarding digital identities and secrets, aiming to thwart unauthorized access to resources, even in the event of compromised credentials.

For businesses utilizing Microsoft Entra, Microsoft offers various options to enable MFA for users. These include Microsoft Authenticator, which facilitates sign-in approvals through biometrics, one-time passcodes, FIDO2 security keys, certificate-based authentication, passkeys, and SMS or voice approval.

According to Microsoft, the critical signing and platform keys will be protected using hardware security modules and confidential computing. These measures include automatically rotating the keys to prevent unauthorized access. Additionally, the company will enforce MFA methods that are resilient against phishing attacks to protect user accounts.

These mandatory security measures are designed to help businesses comply with various industry standards and regulations, such as the General Data Protection Regulation (GDPR) and the National Institute of Standards and Technology (NIST).

Microsoft’s internal survey revealed that multi-factor authentication can block over 99.2 percent of account compromise attacks. The company initially deployed MFA across its Entra ID tenants, including development, testing, demo, and production environments, with plans to extend this to all Azure customers.

MFA will be implemented in phases for Azure users. The initial phase, which begins in October 2024, will make MFA mandatory for accessing key administrative portals such as Azure Portal, Entra Admin Center, and Intune Admin Center.

Subsequently, the second phase will extend MFA requirements to additional Azure clients and tools, including Azure CLI and Azure PowerShell. Microsoft states that customers with complex environments will be given additional time to comply with the MFA requirements.

Earlier this week, Microsoft announced the general availability of its Face Check selfie biometrics as part of Entra Verified ID.

Related Posts

Article Topics

 |   |   |   |   |   | 

Latest Biometrics News

 

Philippines plans ID verification for healthcare with PhilSys integration

The Philippines is planning to modernize its healthcare delivery system with an integration of the Philippine Identification System (PhilSys). An…

 

Inaugural Age Assurance Industry Awards crown winners at gala

The age assurance industry has its Oscars. In a posh ceremony hosted by BBC presenter Charlie Stayt, the first-ever Age…

 

Corsight revealed as facial recognition supplier for Canadian police bodycam trial

The face biometrics algorithms used by police in Edmonton, Alberta, Canada on body-worn cameras during a recent trial is supplied…

 

Regula improves consistency in complex document forensics with 4308M spectral comparator upgrade

Regula has significantly upgraded its 4308M dual‑video spectral comparator. The hardware and software changes should perk up decision makers at…

 

Kazakhstan adopts palm‑vein biometrics for banking in national deployment

Palm biometrics is getting a big boost in Central Asia as one of the world’s largest countries sees major implementation…

 

GAO warns federal AI procurement is repeating the same mistakes

While U.S. government agencies are buying more AI tools across government, a new Government Accountability Office (GAO) report says key…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events